Skip to content

feat(scripts): bind a published overlay to the CDP run that applied it - #17

Merged
afonsojramos merged 1 commit into
mainfrom
feat/bind-overlay
Sep 29, 2026
Merged

afonsojramos merged 1 commit into
mainfrom
feat/bind-overlay

Conversation

@afonsojramos

Copy link
Copy Markdown
Member

Summary

  • When the CDP report records cssMap.overlaySha256 (feat(scripts): verify a key's css-map overlay over CDP cli#3976), publish-key requires it to match the overlay being published, so a key can't ship an overlay the live run never applied.
  • Reports without the field (every CDP report before #3976) still publish. VERIFICATION.md then notes that the overlay's names weren't checked live.
  • Overlays must be in canonical form, like classmaps, so the digests compare byte for byte. flatten already writes that form.
  • The README passes --overlay to the CDP verifier for both inherited and derived keys.

Verification

pnpm check passes: tsc, index, validator, expose, and 59 tests. New tests cover a matching overlay digest, a mismatch, a report with no digest, and a non-canonical overlay.

A CDP report that records its overlay digest must match the overlay being published, and a run without one is noted in VERIFICATION.md. Overlays must be in canonical form so the digests compare.
@coderabbitai

coderabbitai Bot commented Sep 29, 2026

Copy link
Copy Markdown

Warning

Review limit reached

Next included review available in 3 minutes.

Check out review usage here.

View limit details

Limit details: You’ve used the included review currently available.

You've used all free OSS reviews for now. Wait for the free limit to reset to keep reviewing this public repository.

Learn how review limits work.

Review configuration:

⚙️ Run configuration

Configuration used: Organization UI

Review profile: CHILL

Plan: Advanced

Run ID: 74d4e9cc-f558-48c8-b843-b2ff825fab8e

📥 Commits

Reviewing files that changed from the base of the PR and between 2198fa6 and e15b789.

📒 Files selected for processing (3)
  • README.md
  • scripts/publish-key.test.mts
  • scripts/publish-key.ts

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

@afonsojramos
afonsojramos merged commit 8b954fa into main Sep 29, 2026
2 checks passed
@afonsojramos
afonsojramos deleted the feat/bind-overlay branch September 29, 2026 23:23
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant