Repository navigation
chore: adopt Coherence - #5265
pauldambra wants to merge 16 commits into
Conversation
Add @posthog/coherence as a root dev dependency (exact-version cooldown exception for 1.7.0), its Claude Code hooks, config, lexicon, a spec per package and per nested unit, entrances, three refuted invariants, two candidate practices, and a PR workflow in comment mode. Spec files under src broke bundleless rslib builds, so rslib entries now skip markdown and core, mcp and node leave spec files out of their published src. rslib configs are Node build scripts, so oxlint's browser compat rule no longer applies to them. The autocapture value-stripping tests set the value property and read a key the code never writes, so they could not fail. They are now one parameterized test that sets the value attribute and checks attr__value. Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
The references folders hold 917 generated JSON snapshots, about 90% of the lines the lexicon reading walked. SessionStart and Stop hooks read the whole corpus, so they drop from about 17 s to about 4 s. Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
Codex Review SummaryThis comment shows the latest Codex review activity on this pull request.
ℹ️ About Codex in GitHubYour team has set up Codex to review pull requests in this repo. Reviews are triggered when you
Codex reacts with 👀 while any review is running, comments if it has suggestions, and reacts with 👍 once all reviews finish with no findings. |
pauldambra
left a comment
There was a problem hiding this comment.
Note
🤖 Automated comment by QA Swarm — not written by a human
QA Swarm review complete. See inline comments.
|
Note 🤖 Automated comment by QA Swarm — not written by a human Multi-perspective review: router (cheap-first pass) + delegated lenses (qa-team, paul-reviewer, xp-reviewer, security-audit, engineering-systems-thinking as warranted) Verdict: ✅ APPROVE (round 5 @ 13477eb)This round reviewed what changed since d7770b2: two replay test files added to the browser test command in Key findings
ConvergenceNone (router only). Reviewer summaries
Previous rounds (4)round 4 @ d7770b2 — ✅ APPROVE: coherence.config.json and invariant run records reviewed, no blocking findings. Automated by QA Swarm — not a human review |
Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
There was a problem hiding this comment.
Not approved yet — waiting on the conditions below.
Re-add the stamphog label to request another review once you have addressed this.
stamphog can't auto-review this pull request because three gates refused it. The branch has merge conflicts, so the prerequisites gate failed. The deny-list gate matched the dependency/toolchain category (package.json, pnpm-lock.yaml, pnpm-workspace.yaml, and the rslib.config.ts files) and the infrastructure/CI category (.github/workflows/coherence.yml and .claude/settings.json). The tier gate classified the change as never auto-reviewable because it is cross-cutting, touching 72 files and 893 lines.
The size gate passed, so size alone isn't the blocker. To move this forward, resolve the merge conflicts and ask a human reviewer to look at it. Splitting the dependency, CI and toolchain changes from the spec files and the autocapture test fix would also give reviewers smaller pieces to work with.
Gate mechanics and policy version
| Gate | Result | |
|---|---|---|
| prerequisites | ✗ | merge conflicts present |
| deny-list | ✗ | matches: deps_toolchain, infra_cicd |
| size | ✓ | 465L, 25F substantive, 893L/72F incl. docs/generated/snapshots — within ceiling |
| tier | ✗ | classified as T2-never: T2-never (893L, 72F, cross-cutting, chore) |
| stamphog 2.4.1 | .stamphog/policy.yml @ unknown · reviewed head 2c3641a |
There was a problem hiding this comment.
💡 Codex Review
Here are some automated review suggestions for this pull request.
Reviewed commit: 02f0fb0991
ℹ️ About Codex in GitHub
Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you
- Open a pull request for review
- Mark a draft as ready
- Comment "@codex review".
If Codex has suggestions, it will comment; otherwise it will react with 👍.
Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".
# Conflicts: # packages/browser/src/__tests__/autocapture.test.ts
|
📝 No Changeset FoundThis PR doesn't include a changeset. A changeset is required to release a new version. How to add a changesetRun this command and follow the prompts: pnpm changesetRemember: Never use |
Replay incident risk checkThis diff touches code involved in past incidents. This is a heads-up, not a verdict: read the matched sections of INCIDENTS.md and answer their review questions before merging. For a judgment on whether this diff has the same failure mode, run the |
Coherence0 spec problems · 0 failing chokepoints · 2 spec gaps · 0 guard failures 44 components, 5 bullets (5 invariants, 0 requirements), 0 problems Chokepoints: none declared. Spec gaps: 2 entrances with outside or unknown trust and no traced control, and 10 more held by the adoption baseline
Close one with |
Node SDK compliance v2Commit: 5e7fda0 Capture v0 — acceptance
Capture v1 — acceptance
Capture v0 — migration
Capture v1 — migration
|
|
Size Change: 0 B Total Size: 24.1 MB ℹ️ View Unchanged
|
posthog-js Compliance ReportDate: 2026-10-09 22:35:57 UTC ✅ All Tests Passed!26/26 tests passed Capture Tests✅ 26/26 tests passed View Details
|
Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
🦔 PostHog Review (flash) reviewed this pull requestNothing worth raising. |
|
PostHog Review alpha 🦔 If you find any issues helpful - please reply "valid", "invalid", etc., for evaluation purposes 🙏 |
On a clean checkout, collecting all of src imported tests that read dist at load, so invariant runs failed with ENOENT. Naming the files keeps them self-contained; a new invariant elsewhere fails the at-least-one-passed match instead of passing vacuously. Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
Two invariants for Replay, each from a sdk-specs requirement and an existing test: - an idle rotation sends no recording before interaction (session-replay-ingestion-controls, interaction hold) - replay redacts network bodies that may hold a password by default (session-replay-privacy, default body scrubbing) Both refutations witnessed. The browser test command now names their test files too. Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
pauldambra
left a comment
There was a problem hiding this comment.
Note
🤖 Automated comment by QA Swarm — not written by a human
QA Swarm review complete (round 5 @ 13477eb). See inline comments.
Use the public maskCapturedNetworkRequestFn option name, and narrow the idle-rotation invariant to what its test proves. Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
Invariants come from a PostHog/sdk-specs requirement, use an existing test, claim only what that test proves, and cite the requirement in because:. Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
…work Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
Problem
We want agents working in this repo to know its parts, its key words and the rules that matter most. Coherence gives them that through hooks, specs and checks.
Changes
Coherence set-up
@posthog/coherence@1.7.0as a root dev dependency. The 7-day cooldown held it at 1.1.1, which lacks the adoption command, sopnpm-workspace.yamlhas an exact-version exception. It is a root dev dependency only; no published package resolves it..claude/settings.json,coherence.config.json,lexicon.json(8 SDK terms), and the.coherence/journal and run records.packages/browser)packages/browser)packages/ai)session-replay-ingestion-controls, "Interaction hold")session-replay-privacy, "Default body scrubbing")because:. Every invariant now cites its sdk-specs requirement..github/workflows/coherence.ymlin comment mode: one report comment per PR, and the check fails only if Coherence itself breaks.harden-runneris its first step, per CONTRIBUTING.Fixes found along the way
src/broke the bundleless rslib builds. rslib entries now skip*.md, and core, mcp and node leavesrc/**/*.spec.mdout of their published files.src/entrypointshas no spec because the browser rollup config bundles every file there.packages/browser-common/rslib.config.tsfailed oxlint's browsercompat/compatrule. rslib configs are Node build scripts, so that rule is now off for them.autocapture never sends password valuesuses the tests frommain(test(browser): strengthen browser and React test coverage #5123), which fixed the old value-stripping tests that could never fail. Its failure was witnessed again by letting password inputs throughisSensitiveElement.Replay incident risk
check.mjsagainstorigin/mainmatched one class: Class 7, release and delivery channel integrity, because of.github/workflows/coherence.yml.pull_request, notpull_request_target. The analysis job checks out withpersist-credentials: falseand has onlycontents: read. Thepull-requests: writetoken lives in a separate job that runs no PR code.@posthog/coherencehas onlyprepare, which does not run for a registry install.Class 8 (masking, privacy and consent) did not match on paths, but this PR adds guards for it: the replay network-body redaction invariant and the browser password invariant.
Release info Sub-libraries affected
Libraries affected
None need a version bump. The
filesand rslib changes keep the new spec files out of builds and tarballs, so published output is unchanged.Checklist
🤖 Agent context
Autonomy: Human-driven (agent-assisted)
.coherence/journal/.pnpm turbo run build(39 tasks), the autocapture tests,pnpm test:dependency-cooldown, oxlint and oxfmt on changed files, andcoherence spec --check(0 problems).🤖 Generated with Claude Code