Repository navigation
Count diff content lines that look like ---/+++ headers - #17
Merged
VIVAAN-DHAWAN merged 1 commit intoAug 23, 2026
Merged
Conversation
Diffly verdict: BLOCK#17 · 3 files · 136 lines changed · checks: PENDING Risk flags: Risk flags and reasoning
Blast-radius summary
Deterministic triage is authoritative; any optional LLM explanation cannot change the verdict. |
VIVAAN-DHAWAN
force-pushed
the
fix/unified-diff-content-lines
branch
from
August 23, 2026 05:21
9629ad7 to
7d8bf4d
Compare
Header detection pattern-matched every line of a patch, so any added or deleted line whose own content begins with ++/-- (Markdown headings, CLI flags) was discarded as the file's +++/--- header. That under-counted additions/deletions, hid such lines from the secret scanner (a postgres:// credential on a '+++ ...' line no longer forced BLOCK), from dependency detection, and from the AST source feed. Add hunk_body_lines(): everything after the first @@ marker is body; bare patches without @@ stay unchanged; a full diff --git block with no hunks has its prelude stripped. Counting, redaction, dependency detection, and added_source now all iterate body lines only.
VIVAAN-DHAWAN
force-pushed
the
fix/unified-diff-content-lines
branch
from
August 23, 2026 05:57
7d8bf4d to
43cd358
Compare
VIVAAN-DHAWAN
changed the base branch from
main
to
fix/setup-double-update-check
August 23, 2026 05:57
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Why
Header detection pattern-matched every line of a patch:
not line.startswith("+++")/not line.startswith("---"). But any content line whose own text begins with++or--produces a diff line starting with+++/---, so real changes were silently discarded as the file's header line. Reproduced on currentmain:-- old bannerreportsdeletions=0.+++ postgresql://admin:hunter2@db.internal/prodhid the credential from_has_exposed_secret, so a PR that should be BLOCK came back clean.Downstream, the same filter fed dependency detection (
_added_dependency_names) and the AST source feed (added_source), so those lines were invisible to symbol analysis too.What users will see / Surface area
hunk_body_lines(patch)insrc/diffly_cli/diffparse.py: everything after the first@@marker is hunk body; patches with no@@(bare bodies from GitHub's files endpoint) pass through unchanged; a fulldiff --gitblock with no hunks has its prelude stripped.files_from_unified_diff,_has_exposed_secret,_added_dependency_namesintriage.py, andadded_sourceinastmap.py. Verdict policy is unchanged — this only stops real content from being dropped.Validation
tests/test_regressions.py: content lines that look like headers are counted; bare prelude-less patches still count; binary/truncated blocks with prelude count nothing; a connection string on a+ +++line now yieldsEXPOSED_SECRET→BLOCK; dependency names survive+ // +++ see docsnoise. Three of these fail on unfixedmain.pytest -q→ 58 passed.