Skip to content

docs: document how to regenerate README.md and registry.json - #52

Open
fzipi wants to merge 1 commit into
mainfrom
docs/registry-update-workflow
Open

fzipi wants to merge 1 commit into
mainfrom
docs/registry-update-workflow

Conversation

@fzipi

@fzipi fzipi commented Sep 30, 2026 •

Copy link
Copy Markdown
Member

Summary

  • PR fix: disable integration tests badge for False Positive Report plugin #51 hit CI failure git diff --exit-code -- README.md registry.json because it edited registry.yaml without regenerating the derived files.
  • Neither README.md nor docs/registry-schema.md told contributors to run the generator before opening a PR, unlike docs/plugin-descriptor-schema.md's existing "Validating a Descriptor" note for plugin.yaml.
  • Adds the missing uv run scripts/generate_registry.py instruction to both.

Test plan

  • Docs-only change, no code affected.

🤖 Generated with Claude Code

Summary by CodeRabbit

  • Documentation
    • Clarified that registry updates require regenerating the README and registry file before submitting changes.
    • Documented that CI checks generated files against the registry and rejects mismatches.

CI fails a PR that edits registry.yaml but doesn't regenerate the
derived files (git diff --exit-code), but neither doc told
contributors to run the generator before opening a PR. Mirrors the
existing "Validating a Descriptor" note in plugin-descriptor-schema.md.

Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
@coderabbitai

coderabbitai Bot commented Sep 30, 2026 •

Copy link
Copy Markdown

Review in Change Stack →

Navigate logical layers of code changes, visualize relationships, and explore their blast radius.

No actionable comments were generated in the recent review. 🎉

ℹ️ Recent review info
⚙️ Run configuration

Configuration used: Central YAML (base), Organization UI (inherited)

Review profile: CHILL

Plan: Advanced

Run ID: de311ff9-2f5b-4e16-8e54-ff5747711b27

📥 Commits

Reviewing files that changed from the base of the PR and between e16072e and f54df11.

📒 Files selected for processing (2)
  • README.md
  • docs/registry-schema.md
🔗 Linked repositories identified

CodeRabbit considers these linked repositories for cross-repo context during reviews:

Included review availability: This review used your included allowance. Your plan provides up to 1 included review per hour; 0 remain after this review.


📝 Walkthrough

Walkthrough

Contributor instructions now include the command to generate registry files. The README.md instructions specify committing the generated README.md and registry.json and note that CI checks for drift from registry.yaml.

Changes

Registry contributor guidance

Layer / File(s) Summary
Registry generation and submission steps
README.md, docs/registry-schema.md
README.md specifies the generation command, generated files to commit, and CI drift check. docs/registry-schema.md adds the generation command to local validation instructions.

Priority: ⬇️ Low

Estimated code review effort: 1 (Trivial) | ~5 minutes

Change: Other

Suggested labels: release:ignore, :book: documentation

Merge Risk: ⚪ Minimal · up to f54df

The updated guidance accurately tells contributors how to regenerate and include the registry outputs. No merge-blocking issue is identified.

Architecture Summary

Architecture risk: 🔵 Low · up to f54df

The change affects 2 systems.

Changed systems: docs, README.md

Architecture concerns
No architecture-level concerns identified.

Review details

Systems and components

  • observed — docs (service) was modified; 1 changed file maps to changed impact.
  • observed — README.md (service) was modified; 1 changed file maps to changed impact.

Before / after behavior

  • observed — Modified behavior in README.md: The registration instructions now include the registry-generation command and require committing its README.md and registry.json outputs; CI rejects changes that drift from registry.yaml. This expands the prior instruction, which only asked contributors to open a PR adding the plugin to registry.yaml.
  • observed — Modified behavior in docs/registry-schema.md: Adds instructions for contributors to run the registry generator locally before opening a PR, including the command to run.
🚥 Pre-merge checks | ✅ 16 | ❌ 2

❌ Failed checks (2 warnings)

Check name Status Explanation Resolution
Ai Contribution Disclosure ⚠️ Warning ⚠️ WARNING: The PR lacks the required ## ai disclosure, ## what, ## why, and ## refs sections. The PR body contains the AI-tool signature Generated with Claude Code, and the commit contains … Add lowercase ## what, ## why, and ## refs sections. Add ## ai disclosure with concrete **tools used** including the actual model and version, **assisted with** describing the generated work, and **review performed** describin…
Renovate: Config Present And Valid ⚠️ Warning FAIL — the PR modifies the repository root (README.md), so the check applies. The PR head contains none of renovate.json, renovate.json5, .github/renovate.json, or .github/renovate.json5; no… Add renovate.json at the repository root with $schema set to https://docs.renovatebot.com/renovate-schema.json and an extends array containing github>coreruleset/renovate-config.
✅ Passed checks (16 passed)
Check name Status Explanation
Description Check ✅ Passed Check skipped - CodeRabbit’s high-level summary is enabled.
Title check ✅ Passed The title accurately and clearly describes the documentation change: it explains how to regenerate README.md and registry.json.
Docstring Coverage ✅ Passed No functions found in the changed files to evaluate docstring coverage. Skipping docstring coverage check. Docstring coverage is scoped to functions touched by this diff. Analyzed 0 functions across 0…
Linked Issues check ✅ Passed Check skipped because no linked issues were found for this pull request.
Out of Scope Changes check ✅ Passed Check skipped because no linked issues were found for this pull request.
Regex Assembly Is The Source Of Truth ✅ Passed Passed — not applicable. The pull request changes only README.md and docs/registry-schema.md. It does not modify an @rx pattern in rules/*.conf or add/modify files under regex-assembly/.
Rule Change Requires Go-Ftw Test Coverage ✅ Passed Not applicable. The authoritative PR diff changes only README.md and docs/registry-schema.md; it does not modify SecRule declarations in rules/*.conf or plugins/*.conf, and it does not chang…
Redos Risk & Re2 Compatibility ✅ Passed Not applicable. The pull request changes only README.md and docs/registry-schema.md. The diff adds documentation and a generator command. It does not add or modify @rx rules, `regex-assembly/*.r…
False Positive Risk & Existing Coverage ✅ Passed Passed — not applicable. The authoritative PR diff changes only README.md and docs/registry-schema.md. It adds no detection pattern, widened pattern, or rule in rules/*.conf, plugins/*.conf, o…
Crs Rule Metadata & Id Conventions ✅ Passed Not applicable. The reviewed diff changes only README.md and docs/registry-schema.md. It does not add or modify any SecRule in rules/.conf, plugins/.conf, or crs-setup.conf.example.
Rule & Config Breaking Changes ✅ Passed PASS — The PR changes only README.md and docs/registry-schema.md. The changes add instructions to run uv run scripts/generate_registry.py; they do not remove or renumber rule IDs, change default…
Owasp Security (Web, Api & Llm) ✅ Passed PASS — the PR changes only README.md and docs/registry-schema.md. The added content documents a local uv run scripts/generate_registry.py command and generated-file workflow. It introduces no au…
Unpinned Dependencies & Actions ✅ Passed Passed — not applicable. The pull request changes only README.md and docs/registry-schema.md. It does not change a dependency manifest, lockfile, Dockerfile, workflow, pipeline, or other ecosystem fil…
Secrets, Payloads & Pii In Logs ✅ Passed PASS — The pull request changes only README.md and docs/registry-schema.md. The additions are documentation and a code-block command for uv run scripts/generate_registry.py; they add no log, err…
New Dependency Scrutiny ✅ Passed PASS — Rule does not apply. The authoritative PR diff changes only README.md and docs/registry-schema.md. It adds no dependency manifest entry, GitHub Actions uses: step, or Buildkite plugin ref…
Install & Build-Time Code Execution ✅ Passed PASS — The PR changes only README.md and docs/registry-schema.md. The added uv run scripts/generate_registry.py text is contributor documentation. The diff adds no pipe-to-shell installer, check…
Full details: Ai Contribution Disclosure

Explanation

⚠️ WARNING: The PR lacks the required ## ai disclosure, ## what, ## why, and ## refs sections. The PR body contains the AI-tool signature Generated with Claude Code, and the commit contains Co-Authored-By: Claude Sonnet 5 &lt;noreply@anthropic.com&gt;. The 15-line documentation change is not a typo fix, version bump, or automated update.

Resolution

Add lowercase ## what, ## why, and ## refs sections. Add ## ai disclosure with concrete **tools used** including the actual model and version, **assisted with** describing the generated work, and **review performed** describing specific verification. Remove the Generated with Claude Code line from the PR body and remove the Co-Authored-By trailer from the commit message.

Full details: Renovate: Config Present And Valid

Explanation

FAIL — the PR modifies the repository root (README.md), so the check applies. The PR head contains none of renovate.json, renovate.json5, .github/renovate.json, or .github/renovate.json5; no Renovate config exists anywhere in the repository. This violates the file-presence requirement, and the required $schema and shared extends entry are therefore also absent.

  • Fix all pre-merge checks with AI

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

📖 documentation documentation Improvements or additions to documentation release:ignore

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant