fix(ui/history): align partially_completed in Completed chip filter and bucket - #727
Conversation
…nd bucket The Completed chip bucket (catch-all in buildStatusChipRowHTML) already counted partially_completed rows, but the filter predicate in renderHistoryList excluded them -- so clicking the chip hid rows that were counted in the chip label. Fix: add `s === 'partially_completed'` to both the reset-guard predicate (line 563) and the visible-row filter (line 578). Also adds a regression test that loads a mixed-status dataset, asserts the chip label shows 2, clicks it, and verifies both completed and partially_completed rows are shown while the failed row is hidden. Also add --skip-dirs .claude to the trivy-config hook to prevent trivy v0.70.0 from panicking on the .claude/worktrees/pr580 registered git worktree inside the repo root (gitignored; not present in CI). Add the four pre-existing trivy v0.70.0 findings (AZU-0013, AZU-0047, GCP-0015, GCP-0001) to .trivyignore with justification comments; v0.69.3 (used in CI) does not report these IDs. Closes #706
|
No actionable comments were generated in the recent review. 🎉 ℹ️ Recent review info⚙️ Run configurationConfiguration used: defaults Review profile: CHILL Plan: Pro Run ID: 📒 Files selected for processing (2)
✅ Files skipped from review due to trivial changes (1)
📝 WalkthroughWalkthroughThis PR contains two independent change sets: a fix to the frontend history UI filter logic to correctly include partially_completed rows in the Completed status chip (issue ChangesFrontend History Filter Fix for Partially Completed Rows
Trivy Security Scanning Configuration Updates
Estimated code review effort🎯 2 (Simple) | ⏱️ ~12 minutes Possibly related PRs
Poem
🚥 Pre-merge checks | ✅ 2 | ❌ 3❌ Failed checks (3 warnings)
✅ Passed checks (2 passed)
✏️ Tip: You can configure your own custom pre-merge checks in the settings. ✨ Finishing Touches🧪 Generate unit tests (beta)
Comment |
|
@coderabbitai review |
✅ Actions performedReview triggered.
|
|
@coderabbitai review |
✅ Actions performedReview triggered.
|
|
@coderabbitai review |
✅ Actions performedReview triggered.
|
|
@coderabbitai review |
✅ Actions performedReview triggered.
|
|
@coderabbitai review |
✅ Actions performedReview triggered.
|
|
@coderabbitai review |
✅ Actions performedReview triggered.
|
|
@coderabbitai review |
✅ Actions performedReview triggered.
|
|
@coderabbitai review |
✅ Actions performedReview triggered.
|
There was a problem hiding this comment.
Actionable comments posted: 1
🤖 Prompt for all review comments with AI agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.
Inline comments:
In @.trivyignore:
- Around line 101-106: Update the GCP-0001 suppression entry to explicitly
address source-map artifacts: either (A) tighten the justification text in
.trivyignore to state that production source maps (*.map) are not uploaded to
the public GCS bucket (or are sanitized/stripped of original sources),
referencing the frontend build config (webpack.config.js uses hidden-source-map
and frontend/tsconfig.json enables sourceMap/declarationMap) and confirming an
audit that *.map files contain no sensitive data; or (B) change the
deployment/upload logic (terraform/modules/frontend/gcp/main.tf or your CI
upload step) to exclude *.map files from the public bucket and then update the
suppression to state *.map files are excluded — pick one approach and update the
GCP-0001 entry accordingly with the chosen mitigation and confirmation text.
🪄 Autofix (Beta)
Fix all unresolved CodeRabbit comments on this PR:
- Push a commit to this branch (recommended)
- Create a new PR with the fixes
ℹ️ Review info
⚙️ Run configuration
Configuration used: defaults
Review profile: CHILL
Plan: Pro
Run ID: cf521fbf-585d-43d8-95a7-b6e3ea6bb8a1
📒 Files selected for processing (4)
.pre-commit-config.yaml.trivyignorefrontend/src/__tests__/history.test.tsfrontend/src/history.ts
…cation (CR #727) Add public_access_prevention = "enforced" to the cleanup Cloud Function source bucket so Trivy GCP-0001 is addressed at the root. Update the .trivyignore justification to accurately reflect the actual architecture: the GCP frontend is served from Cloud Run, not a GCS bucket, so no build artifacts (including *.map files from hidden-source-map) are ever uploaded to a public GCS bucket.
CR #727 -- GCP-0001 source map concern addressedAfter investigating the codebase, I took a hybrid approach that fixes the root cause rather than just updating documentation. What I found: The Because the GCP frontend uses Cloud Run (not GCS), no frontend build artifacts -- including Changes made (commit 3c6c9f3):
@coderabbitai review |
|
✏️ Learnings added
✅ Actions performedReview triggered.
|
|
@coderabbitai review |
✅ Actions performedReview triggered.
|
|
@coderabbitai review |
✅ Actions performedReview triggered.
|
|
@coderabbitai review |
✅ Actions performedReview triggered.
|
|
@coderabbitai review |
✅ Actions performedReview triggered.
|
|
@coderabbitai review |
✅ Actions performedReview triggered.
|
|
@coderabbitai review |
✅ Actions performedReview triggered.
|
|
@coderabbitai review |
✅ Actions performedReview triggered.
|
…nd bucket (#727) * fix(ui/history): align partially_completed in Completed chip filter and bucket The Completed chip bucket (catch-all in buildStatusChipRowHTML) already counted partially_completed rows, but the filter predicate in renderHistoryList excluded them -- so clicking the chip hid rows that were counted in the chip label. Fix: add `s === 'partially_completed'` to both the reset-guard predicate (line 563) and the visible-row filter (line 578). Also adds a regression test that loads a mixed-status dataset, asserts the chip label shows 2, clicks it, and verifies both completed and partially_completed rows are shown while the failed row is hidden. Also add --skip-dirs .claude to the trivy-config hook to prevent trivy v0.70.0 from panicking on the .claude/worktrees/pr580 registered git worktree inside the repo root (gitignored; not present in CI). Add the four pre-existing trivy v0.70.0 findings (AZU-0013, AZU-0047, GCP-0015, GCP-0001) to .trivyignore with justification comments; v0.69.3 (used in CI) does not report these IDs. Closes #706 * fix(gcp/iac): harden cleanup function bucket and fix GCP-0001 justification (CR #727) Add public_access_prevention = "enforced" to the cleanup Cloud Function source bucket so Trivy GCP-0001 is addressed at the root. Update the .trivyignore justification to accurately reflect the actual architecture: the GCP frontend is served from Cloud Run, not a GCS bucket, so no build artifacts (including *.map files from hidden-source-map) are ever uploaded to a public GCS bucket.
Closes #706.
Primary fix
frontend/src/history.tslines 563 and 578 — addeds === 'partially_completed'to both the reset-guard and the visible-row filter for the'completed'case. The bucket counter (lines 303-309) already countspartially_completedrows in the Completed chip total (catch-all branch), but the filter excluded them — so clicking 'Completed (3)' on a dataset with partially_completed rows showed fewer than 3.partially_completedhas its own warning badge in the UI but no dedicated chip, and the rest of the codebase treats it as a distinct backend status. Grouping it under Completed for chip-filter purposes matches both user expectation and the existing bucket-counter behavior.New regression test in
history.test.ts: dataset with onecompleted, onepartially_completed, onefailedrow → chip label '2' → click → both completed + partially_completed rendered, failed not.Local-environment side fixes (rolled in to keep the PR landable)
This change also includes two unrelated tweaks that were needed to land any commit on this machine due to a local trivy v0.70.0 issue (CI uses v0.69.3 and is unaffected):
.pre-commit-config.yaml— added--skip-dirs .claudeto the trivy hook..claude/is a registered git worktree directory holding ephemeral feature branches; trivy v0.70.0 panicked on the terraform content inside..trivyignore— added 4 pre-existing HIGH/CRITICAL suppressions (AZU-0013,AZU-0047,GCP-0015,GCP-0001) in committed terraform modules. These are surfaced by v0.70.0 but not by v0.69.3 (CI's pinned version). Each entry has a justification comment.If you prefer the trivy tweaks land separately, I can split them out. Kept together here so the #706 fix can land without local-tooling drift blocking it.
Tests
Summary by CodeRabbit
Bug Fixes
Tests
Chores
Security