Skip to content

Count diff content lines that look like ---/+++ headers - #17

Merged
VIVAAN-DHAWAN merged 1 commit into
fix/setup-double-update-checkfrom
fix/unified-diff-content-lines
Aug 23, 2026
Merged

VIVAAN-DHAWAN merged 1 commit into
fix/setup-double-update-checkfrom
fix/unified-diff-content-lines

Conversation

@VIVAAN-DHAWAN

Copy link
Copy Markdown
Owner

Why

Header detection pattern-matched every line of a patch: not line.startswith("+++") / not line.startswith("---"). But any content line whose own text begins with ++ or -- produces a diff line starting with +++/---, so real changes were silently discarded as the file's header line. Reproduced on current main:

  • Deleting a line -- old banner reports deletions=0.
  • Adding a line +++ postgresql://admin:hunter2@db.internal/prod hid the credential from _has_exposed_secret, so a PR that should be BLOCK came back clean.

Downstream, the same filter fed dependency detection (_added_dependency_names) and the AST source feed (added_source), so those lines were invisible to symbol analysis too.

What users will see / Surface area

  • New hunk_body_lines(patch) in src/diffly_cli/diffparse.py: everything after the first @@ marker is hunk body; patches with no @@ (bare bodies from GitHub's files endpoint) pass through unchanged; a full diff --git block with no hunks has its prelude stripped.
  • Four call sites switched to body-only iteration: addition/deletion counting in files_from_unified_diff, _has_exposed_secret, _added_dependency_names in triage.py, and added_source in astmap.py. Verdict policy is unchanged — this only stops real content from being dropped.

Validation

  • Regression tests in tests/test_regressions.py: content lines that look like headers are counted; bare prelude-less patches still count; binary/truncated blocks with prelude count nothing; a connection string on a + +++ line now yields EXPOSED_SECRET → BLOCK; dependency names survive + // +++ see docs noise. Three of these fail on unfixed main.
  • Full suite: pytest -q → 58 passed.
  • Duplicate check: no open PR/issue covers diff-line miscounting or secret-scan gaps.

@github-actions

Copy link
Copy Markdown

Diffly verdict: BLOCK

#17 · 3 files · 136 lines changed · checks: PENDING

Risk flags: EXPOSED_SECRET (critical), NO_TEST_COVERAGE (low), CHECKS_PENDING (medium)

Risk flags and reasoning
  • EXPOSED_SECRET (critical): Adds a credential-like value in the changed code or configuration. — tests/test_regressions.py
  • NO_TEST_COVERAGE (low): Changed production files have no obvious neighboring or repository test coverage; this is a review hint, not a verdict gate. — src/diffly_cli/diffparse.py
  • CHECKS_PENDING (medium): Required status checks are still pending. — combined commit status; diffly; test (3.10); test (3.11); test (3.12); test (3.13)
  • BLOCK because the pull request appears to add a credential-like value.
Blast-radius summary
File Change Symbols Direct callers Tests
src/diffly_cli/diffparse.py +27/-8 <top-level changes> — —
src/diffly_cli/triage.py +4/-3 <top-level changes> — tests/test_triage.py
tests/test_regressions.py +94/-0 <top-level changes> — —

Deterministic triage is authoritative; any optional LLM explanation cannot change the verdict.

@VIVAAN-DHAWAN
VIVAAN-DHAWAN force-pushed the fix/unified-diff-content-lines branch from 9629ad7 to 7d8bf4d Compare August 23, 2026 05:21
Header detection pattern-matched every line of a patch, so any added
or deleted line whose own content begins with ++/-- (Markdown
headings, CLI flags) was discarded as the file's +++/--- header. That
under-counted additions/deletions, hid such lines from the secret
scanner (a postgres:// credential on a '+++ ...' line no longer forced
BLOCK), from dependency detection, and from the AST source feed.

Add hunk_body_lines(): everything after the first @@ marker is body;
bare patches without @@ stay unchanged; a full diff --git block with
no hunks has its prelude stripped. Counting, redaction, dependency
detection, and added_source now all iterate body lines only.
@VIVAAN-DHAWAN
VIVAAN-DHAWAN force-pushed the fix/unified-diff-content-lines branch from 7d8bf4d to 43cd358 Compare August 23, 2026 05:57
@VIVAAN-DHAWAN
VIVAAN-DHAWAN changed the base branch from main to fix/setup-double-update-check August 23, 2026 05:57
@VIVAAN-DHAWAN
VIVAAN-DHAWAN merged commit 6cc951d into fix/setup-double-update-check Aug 23, 2026
9 checks passed
VIVAAN-DHAWAN added a commit that referenced this pull request Aug 23, 2026
Land #16 (setup double update-check) and #17 (diff content-line counting) on main
@VIVAAN-DHAWAN
VIVAAN-DHAWAN deleted the fix/unified-diff-content-lines branch August 23, 2026 06:11
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant