Repository navigation
[codex] Fix actionable rule requests and repo hygiene - #284
Conversation
Remove the obsolete rules/cursorrules-file-cursor-ai-python-fastapi-api rule set (deleted .cursorrules, README.md and multiple .mdc rule files) and clean up README.md by removing the duplicate Python (FastAPI) entry. This prunes deprecated/duplicated Cursor rules for FastAPI and reduces confusion in the rules index.
Restrict workflow permissions and run hygiene checks against a trusted base for pull requests: grant read-only contents permission, checkout the PR base to .trusted-base, and execute the trusted check-repo-hygiene script for PRs. Update the hygiene script to change README external-listing messaging and adjust its behavior; update tests to match the new expectations and add a new workflow-security.test.mjs to assert the workflow changes. Add/adjust many rule files (rules-new/*.mdc) to include globs/alwaysApply metadata and minor formatting fixes, and add several .cursorrules files (Rails, Solidity/Web3, Svelte5, Vue/Nuxt) to populate rule content.
Update README to document using .mdc Cursor rule files and monorepo setups. Adds TOC entries for “Method Three” and “Monorepos and Multiple Rule Files”, includes step-by-step guidance for placing .mdc files in .cursor/rules, keeping frontmatter, and scoping rules with globs. Also adds numerous new rules links under rules-new (e.g. React Router v7, Google ADK, HarmonyOS ArkTS, Blender Python Add-ons, GameMaker GML, Toss-Style Design System, Embedded STM32/HAL, ROS/ROS2, AutoML, Fortran, Rust, TensorFlow) to the rules index.
Introduce .github/CODEOWNERS to require @PatrickJS review for workflows, scripts, and the CODEOWNERS file itself. Update workflow-security.test.mjs to load the CODEOWNERS file and add assertions that those entries exist, ensuring sensitive automation and policy files require maintainer review.
Populate the frontmatter description in rules-new/cpp.mdc to instruct Cursor to produce modern C++ and CMake code with clear structure, RAII, const-correctness, and safe error handling. Also remove an extra trailing blank line at the end of the file.
|
No actionable comments were generated in the recent review. 🎉 ℹ️ Recent review info⚙️ Run configurationConfiguration used: defaults Review profile: CHILL Plan: Pro Run ID: 📒 Files selected for processing (15)
✅ Files skipped from review due to trivial changes (9)
🚧 Files skipped from review as they are similar to previous changes (6)
📝 WalkthroughWalkthroughAdds CODEOWNERS and tightens workflow permissions; implements a trusted-base checkout and new workflow tests; introduces ~30 new/updated ChangesRepository governance & workflow security
Repository hygiene tooling and tests
Documentation, examples, and rule catalog
New and standardized rules (.mdc / .cursorrules)
FastAPI rule consolidation / removals
Estimated code review effort🎯 4 (Complex) | ⏱️ ~50 minutes Possibly related issues
Possibly related PRs
Poem
✨ Finishing Touches📝 Generate docstrings
🧪 Generate unit tests (beta)
|
Refactor documentation and project rules across multiple files: - Beefree SDK: Replace external <script> usage with instruction to bundle @beefree.io/sdk, simplify auth payload to only send uid (remove client_id/client_secret), and update initialization to use the newer BeefreeSDK constructor + start API. - Cursor/README and Drupal notes: Fix extension link casing, prefer .cursor/rules over legacy .cursorrules, and update referenced Awesome CursorRules repo link. - Placeholder images: Replace placekitten.com guidance with recommendation to use local fixtures or a stable, project-approved image source; update rule description accordingly. - Project overview: Reword repository purpose to refer to configured @findhow package repositories. Also include minor formatting/newline fixes and other small doc clarifications.
Revise main README guidance for adding .cursorrules (use the VS Code command to create a rule and copy guidance, and link Cursor project rules for .mdc files). Update Beefree SDK example in its .cursorrules: remove client_id/client_secret from client-side auth payload, recommend bundling the official @beefree.io/sdk instead of loading a remote script, and switch initialization to instantiate BeefreeSDK and call start. Small wording tweaks in Deno integration and Rails rule README to generalize repository references and simplify the attribution to the Mawla cursor_rules project.
Update manifest prompt rules to recommend using a verified or project-shipped Manifest JSON Schema instead of hardcoding the public schema URL, and tighten wording/copy (e.g. "Strictly"). Update README guidance to advise verifying backend docs and schema for the project version. Replace hardcoded external image URLs in the momen ActionFlow examples with a generic "generated-image-url-from-actionflow" placeholder to avoid leaking or relying on specific static assets.
There was a problem hiding this comment.
Actionable comments posted: 2
🧹 Nitpick comments (6)
scripts/workflow-security.test.mjs (1)
8-10: ⚡ Quick winHarden the permission assertion to catch future write scopes.
This test verifies
contents: readexists, but it doesn’t explicitly fail if an additionalwritepermission is later introduced.Suggested hardening
test("repo hygiene workflow grants read-only contents permission", () => { assert.match(workflow, /^permissions:\n\s+contents:\s+read\s*$/m); + assert.doesNotMatch(workflow, /^\s+[A-Za-z-]+:\s+write\s*$/m); });🤖 Prompt for AI Agents
Verify each finding against current code. Fix only still-valid issues, skip the rest with a brief reason, keep changes minimal, and validate. In `@scripts/workflow-security.test.mjs` around lines 8 - 10, The test "repo hygiene workflow grants read-only contents permission" currently only checks for "contents: read" but won't fail if "contents: write" is later added; update the test around the existing assertion (the test function and the workflow variable) to both assert the positive match for /^permissions:\n\s+contents:\s+read\s*$/m and add a negative assertion such as assert.doesNotMatch(workflow, /contents:\s*write/) to ensure no write scope is present.rules-new/beefreeSDK.mdc (1)
555-555: ⚡ Quick winRemove trailing whitespace.
Line 555 has trailing whitespace after the closing backticks.
🤖 Prompt for AI Agents
Verify each finding against current code. Fix only still-valid issues, skip the rest with a brief reason, keep changes minimal, and validate. In `@rules-new/beefreeSDK.mdc` at line 555, Remove the trailing whitespace after the closing code fence backticks ("```") on the line that ends the code block (the closing backticks visible in the diff) so the line contains only the three backticks and no trailing spaces or tabs.rules/beefreeSDK-nocode-content-editor-cursorrules-prompt-file/.cursorrules (1)
550-550: ⚡ Quick winRemove trailing whitespace.
Line 550 has trailing whitespace after the closing backticks.
🤖 Prompt for AI Agents
Verify each finding against current code. Fix only still-valid issues, skip the rest with a brief reason, keep changes minimal, and validate. In `@rules/beefreeSDK-nocode-content-editor-cursorrules-prompt-file/.cursorrules` at line 550, Remove the trailing whitespace at the end of line containing the closing backticks (the triple backtick block terminator) in .cursorrules; locate the closing ``` on line 550 and delete any spaces or tabs after it so the line ends immediately with the backticks.rules-new/blender-python-addon.mdc (1)
53-53: ⚡ Quick winAdd a final newline at end of file.
The file should end with a newline character for POSIX compliance and better git diff behavior.
🤖 Prompt for AI Agents
Verify each finding against current code. Fix only still-valid issues, skip the rest with a brief reason, keep changes minimal, and validate. In `@rules-new/blender-python-addon.mdc` at line 53, The file blender-python-addon.mdc is missing a trailing newline; open the file and add a single newline character at the end of the file (ensure the EOF ends with '\n') so the file ends with a final newline for POSIX compliance and correct git diff behavior.rules-new/toss-style-design-system.mdc (1)
68-68: ⚡ Quick winAdd a final newline at end of file.
The file should end with a newline character for POSIX compliance and better git diff behavior.
🤖 Prompt for AI Agents
Verify each finding against current code. Fix only still-valid issues, skip the rest with a brief reason, keep changes minimal, and validate. In `@rules-new/toss-style-design-system.mdc` at line 68, The file toss-style-design-system.mdc is missing a trailing newline; open toss-style-design-system.mdc and ensure the file ends with a single newline character (add a final newline at EOF) so the file is POSIX-compliant and produces cleaner git diffs.rules-new/rust-general.mdc (1)
53-53: ⚡ Quick winAdd a final newline at end of file.
The file should end with a newline character for POSIX compliance and better git diff behavior.
🤖 Prompt for AI Agents
Verify each finding against current code. Fix only still-valid issues, skip the rest with a brief reason, keep changes minimal, and validate. In `@rules-new/rust-general.mdc` at line 53, Add a single newline character at the end of the Markdown file rust-general.mdc so the file ends with a final newline (POSIX-compliant EOF) — simply ensure the last line is terminated with “\n” and commit the change.
🤖 Prompt for all review comments with AI agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.
Inline comments:
In `@rules-new/react.mdc`:
- Line 79: Remove the trailing whitespace at the end of the line containing
"Document complex component logic" in rules-new/react.mdc so the line ends
immediately after "logic"; update the file to delete that extra space character
to prevent stray whitespace diffs.
In `@rules/deno-integration-techniques-cursorrules-prompt-fil/.cursorrules`:
- Line 3: The rule file contains an invalid `@https://` reference (e.g.,
`@https://github.com/denoland/automation`) which only works in Cursor chat, not
in .cursorrules; remove the leading `@` and replace the reference with a plain
URL (`https://github.com/denoland/automation`) or a markdown link
(`[denoland/automation](https://github.com/denoland/automation)`) so the rule
file uses a supported reference format.
---
Nitpick comments:
In `@rules-new/beefreeSDK.mdc`:
- Line 555: Remove the trailing whitespace after the closing code fence
backticks ("```") on the line that ends the code block (the closing backticks
visible in the diff) so the line contains only the three backticks and no
trailing spaces or tabs.
In `@rules-new/blender-python-addon.mdc`:
- Line 53: The file blender-python-addon.mdc is missing a trailing newline; open
the file and add a single newline character at the end of the file (ensure the
EOF ends with '\n') so the file ends with a final newline for POSIX compliance
and correct git diff behavior.
In `@rules-new/rust-general.mdc`:
- Line 53: Add a single newline character at the end of the Markdown file
rust-general.mdc so the file ends with a final newline (POSIX-compliant EOF) —
simply ensure the last line is terminated with “\n” and commit the change.
In `@rules-new/toss-style-design-system.mdc`:
- Line 68: The file toss-style-design-system.mdc is missing a trailing newline;
open toss-style-design-system.mdc and ensure the file ends with a single newline
character (add a final newline at EOF) so the file is POSIX-compliant and
produces cleaner git diffs.
In `@rules/beefreeSDK-nocode-content-editor-cursorrules-prompt-file/.cursorrules`:
- Line 550: Remove the trailing whitespace at the end of line containing the
closing backticks (the triple backtick block terminator) in .cursorrules; locate
the closing ``` on line 550 and delete any spaces or tabs after it so the line
ends immediately with the backticks.
In `@scripts/workflow-security.test.mjs`:
- Around line 8-10: The test "repo hygiene workflow grants read-only contents
permission" currently only checks for "contents: read" but won't fail if
"contents: write" is later added; update the test around the existing assertion
(the test function and the workflow variable) to both assert the positive match
for /^permissions:\n\s+contents:\s+read\s*$/m and add a negative assertion such
as assert.doesNotMatch(workflow, /contents:\s*write/) to ensure no write scope
is present.
🪄 Autofix (Beta)
Fix all unresolved CodeRabbit comments on this PR:
- Push a commit to this branch (recommended)
- Create a new PR with the fixes
ℹ️ Review info
⚙️ Run configuration
Configuration used: defaults
Review profile: CHILL
Plan: Pro
Run ID: 24a6222b-4889-4d24-93c0-59618130627d
📒 Files selected for processing (67)
.github/CODEOWNERS.github/workflows/main.ymlREADME.mdrules-new/automl-hyperparameter-optimization.mdcrules-new/beefreeSDK.mdcrules-new/blender-python-addon.mdcrules-new/clean-code.mdcrules-new/codequality.mdcrules-new/cpp.mdcrules-new/database.mdcrules-new/embedded-stm32-hal.mdcrules-new/fastapi.mdcrules-new/fortran.mdcrules-new/gamemaker-gml.mdcrules-new/gitflow.mdcrules-new/google-adk.mdcrules-new/harmony-arkts.mdcrules-new/kubestellar-console.mdcrules-new/medusa.mdcrules-new/nativescript.mdcrules-new/nextjs.mdcrules-new/node-express.mdcrules-new/python.mdcrules-new/react-router-v7.mdcrules-new/react.mdcrules-new/ros-ros2.mdcrules-new/rust-general.mdcrules-new/rust.mdcrules-new/svelte.mdcrules-new/tailwind.mdcrules-new/tensorflow-deep-learning.mdcrules-new/toss-style-design-system.mdcrules-new/typescript.mdcrules-new/vue.mdcrules/beefreeSDK-nocode-content-editor-cursorrules-prompt-file/.cursorrulesrules/beefreeSDK-nocode-content-editor-cursorrules-prompt-file/README.mdrules/cursorrules-file-cursor-ai-python-fastapi-api/.cursorrulesrules/cursorrules-file-cursor-ai-python-fastapi-api/README.mdrules/cursorrules-file-cursor-ai-python-fastapi-api/error-handling-priorities.mdcrules/cursorrules-file-cursor-ai-python-fastapi-api/fastapi-blocking-operations.mdcrules/cursorrules-file-cursor-ai-python-fastapi-api/fastapi-components-and-validation.mdcrules/cursorrules-file-cursor-ai-python-fastapi-api/fastapi-conditional-statements.mdcrules/cursorrules-file-cursor-ai-python-fastapi-api/fastapi-dependencies.mdcrules/cursorrules-file-cursor-ai-python-fastapi-api/fastapi-dependency-injection.mdcrules/cursorrules-file-cursor-ai-python-fastapi-api/fastapi-file-structure.mdcrules/cursorrules-file-cursor-ai-python-fastapi-api/fastapi-function-definitions.mdcrules/cursorrules-file-cursor-ai-python-fastapi-api/fastapi-middleware.mdcrules/cursorrules-file-cursor-ai-python-fastapi-api/fastapi-performance-metrics.mdcrules/cursorrules-file-cursor-ai-python-fastapi-api/fastapi-performance-optimization.mdcrules/cursorrules-file-cursor-ai-python-fastapi-api/fastapi-startup-and-shutdown-events.mdcrules/cursorrules-file-cursor-ai-python-fastapi-api/python-general-style.mdcrules/deno-integration-techniques-cursorrules-prompt-fil/.cursorrulesrules/deno-integration-techniques-cursorrules-prompt-fil/project-overview-rule.mdcrules/drupal-11-cursorrules-prompt-file/README.mdrules/manifest-yaml-cursorrules-prompt-file/.cursorrulesrules/manifest-yaml-cursorrules-prompt-file/README.mdrules/momen-cursurrules-prompt-file/momen-actionflow-gql-api-rules.mdcrules/nextjs-react-tailwind-cursorrules-prompt-file/.cursorrulesrules/nextjs-react-tailwind-cursorrules-prompt-file/placeholder-images.mdcrules/rails-cursorrules-prompt-file/.cursorrulesrules/rails-cursorrules-prompt-file/README.mdrules/solidity-react-blockchain-apps-cursorrules-prompt-/.cursorrulesrules/svelte-5-vs-svelte-4-cursorrules-prompt-file/.cursorrulesrules/vue-3-nuxt-3-typescript-cursorrules-prompt-file/.cursorrulesscripts/check-repo-hygiene.mjsscripts/check-repo-hygiene.test.mjsscripts/workflow-security.test.mjs
💤 Files with no reviewable changes (15)
- rules/cursorrules-file-cursor-ai-python-fastapi-api/fastapi-dependencies.mdc
- rules/cursorrules-file-cursor-ai-python-fastapi-api/fastapi-conditional-statements.mdc
- rules/cursorrules-file-cursor-ai-python-fastapi-api/fastapi-startup-and-shutdown-events.mdc
- rules/cursorrules-file-cursor-ai-python-fastapi-api/error-handling-priorities.mdc
- rules/cursorrules-file-cursor-ai-python-fastapi-api/python-general-style.mdc
- rules/cursorrules-file-cursor-ai-python-fastapi-api/fastapi-blocking-operations.mdc
- rules/cursorrules-file-cursor-ai-python-fastapi-api/README.md
- rules/cursorrules-file-cursor-ai-python-fastapi-api/fastapi-performance-metrics.mdc
- rules/cursorrules-file-cursor-ai-python-fastapi-api/fastapi-dependency-injection.mdc
- rules/cursorrules-file-cursor-ai-python-fastapi-api/fastapi-file-structure.mdc
- rules/cursorrules-file-cursor-ai-python-fastapi-api/fastapi-function-definitions.mdc
- rules/cursorrules-file-cursor-ai-python-fastapi-api/fastapi-performance-optimization.mdc
- rules/cursorrules-file-cursor-ai-python-fastapi-api/fastapi-components-and-validation.mdc
- rules/cursorrules-file-cursor-ai-python-fastapi-api/.cursorrules
- rules/cursorrules-file-cursor-ai-python-fastapi-api/fastapi-middleware.mdc
Summary
.mdcrules for actionable open requests: TensorFlow/deep learning, AutoML/HPO, React Router v7, Blender add-ons, GameMaker GML, general Rust, Harmony ArkTS, embedded STM32/HAL, ROS/ROS2, Google ADK, Fortran, and Toss-style design systems.rules/py-fast-apientry, and improve broken/placeholder legacy rule files for Rails, Solidity React, Svelte, and Vue/Nuxt..mdcrule files and monorepo usage, and strengthen repo-hygiene/workflow guardrails with maintainer-owned sensitive controls.Validation
node scripts/check-repo-hygiene.mjsnode --test scripts/*.test.mjsgit diff --checkCloses #12, closes #14, closes #20, closes #24, closes #30, closes #33, closes #36, closes #49, closes #57, closes #62, closes #84, closes #86, closes #93, closes #97, closes #98, closes #104, closes #148, closes #155, closes #238.
Summary by CodeRabbit
New Features
Documentation
Updates
Chores / Security
Tests