summaryrefslogtreecommitdiff
diff options
context:
space:
mode:
authorChristian Cleberg <[email protected]>2026-07-16 11:07:17 -0500
committerChristian Cleberg <[email protected]>2026-07-16 11:07:17 -0500
commit3854761b48d893ac4b5d8d9c257dd3cbdc7214d6 (patch)
treee69d79b86ad99e1416c2181903d66e61cfe2b402
parente93972f39150e5e590e49aaf46a369c463277c30 (diff)
downloadhutch-3854761b48d893ac4b5d8d9c257dd3cbdc7214d6.tar.gz
hutch-3854761b48d893ac4b5d8d9c257dd3cbdc7214d6.tar.bz2
hutch-3854761b48d893ac4b5d8d9c257dd3cbdc7214d6.zip
chore: record the SonarCloud + housekeeping pass, bump to 3.8.1
Update the roadmap's SonarCloud section to the live 53-issue / 10-rule reality and mark what v3.8.1 fixed, silenced-as-bug, and left Won't Fix. Bump MARKETING_VERSION on the app, widget, and Safari extension.
-rw-r--r--Hutch.xcodeproj/project.pbxproj12
-rw-r--r--ROADMAP.md82
2 files changed, 64 insertions, 30 deletions
diff --git a/Hutch.xcodeproj/project.pbxproj b/Hutch.xcodeproj/project.pbxproj
index 32da475..eba1ba7 100644
--- a/Hutch.xcodeproj/project.pbxproj
+++ b/Hutch.xcodeproj/project.pbxproj
@@ -614,7 +614,7 @@
"$(inherited)",
"@executable_path/Frameworks",
);
- MARKETING_VERSION = 3.8.0;
+ MARKETING_VERSION = 3.8.1;
PRODUCT_BUNDLE_IDENTIFIER = net.cleberg.Hutch;
PRODUCT_NAME = "$(TARGET_NAME)";
STRING_CATALOG_GENERATE_SYMBOLS = YES;
@@ -651,7 +651,7 @@
"$(inherited)",
"@executable_path/Frameworks",
);
- MARKETING_VERSION = 3.8.0;
+ MARKETING_VERSION = 3.8.1;
PRODUCT_BUNDLE_IDENTIFIER = net.cleberg.Hutch;
PRODUCT_NAME = "$(TARGET_NAME)";
STRING_CATALOG_GENERATE_SYMBOLS = YES;
@@ -724,7 +724,7 @@
"@executable_path/Frameworks",
"@executable_path/../../Frameworks",
);
- MARKETING_VERSION = 3.8.0;
+ MARKETING_VERSION = 3.8.1;
PRODUCT_BUNDLE_IDENTIFIER = net.cleberg.Hutch.HutchWidgetExtension;
PRODUCT_NAME = "$(TARGET_NAME)";
SKIP_INSTALL = YES;
@@ -753,7 +753,7 @@
"@executable_path/Frameworks",
"@executable_path/../../Frameworks",
);
- MARKETING_VERSION = 3.8.0;
+ MARKETING_VERSION = 3.8.1;
PRODUCT_BUNDLE_IDENTIFIER = net.cleberg.Hutch.HutchWidgetExtension;
PRODUCT_NAME = "$(TARGET_NAME)";
SKIP_INSTALL = YES;
@@ -782,7 +782,7 @@
"@executable_path/Frameworks",
"@executable_path/../../Frameworks",
);
- MARKETING_VERSION = 3.8.0;
+ MARKETING_VERSION = 3.8.1;
PRODUCT_BUNDLE_IDENTIFIER = net.cleberg.Hutch.HutchSafariExtension;
PRODUCT_NAME = "$(TARGET_NAME)";
SKIP_INSTALL = YES;
@@ -811,7 +811,7 @@
"@executable_path/Frameworks",
"@executable_path/../../Frameworks",
);
- MARKETING_VERSION = 3.8.0;
+ MARKETING_VERSION = 3.8.1;
PRODUCT_BUNDLE_IDENTIFIER = net.cleberg.Hutch.HutchSafariExtension;
PRODUCT_NAME = "$(TARGET_NAME)";
SKIP_INSTALL = YES;
diff --git a/ROADMAP.md b/ROADMAP.md
index 17072e4..8e32355 100644
--- a/ROADMAP.md
+++ b/ROADMAP.md
@@ -198,23 +198,54 @@ Labels and hints appear in 17 of 89 view files. Mechanical and low-risk, but it
cannot be verified from a build — it needs VoiceOver driven on a device.
Independent of every other bucket, so it can move if a device pass is convenient.
-### SonarCloud backlog — v3.8.1
-
-51 open issues: **0 bugs, 0 vulnerabilities, 51 code smells**, plus 3 security
-hotspots. The headline number is misleading, so trust the breakdown before
-budgeting:
-
-- **35× `swift:S1075` (hardcoded URI)** — 28 of them in
- `SourceHutWebDeepLinkMapperTests`, 5 in `Shared/HutchDeepLinkURLs`. A deep-link
- mapper's tests exist precisely to assert against literal URLs, and a client for
- one forge has fixed endpoints by definition. These want triaging as *Won't
- Fix* in SonarCloud, not refactoring. "Fixing" them would make the code worse.
-- **5× `swift:S1135`** — TODO comments. Two are in `HutchIntents` and name real
- gaps.
-- **3× `swift:S1186` (empty closure)** — all three CRITICAL, all three trivial:
- `Button("Cancel", role: .cancel) {}` needs no body. A comment settles it.
-- **2× `javascript:S4624`** in the Safari extension; **2× `swift:S1172`** unused
- parameters.
+### SonarCloud backlog — done in code (v3.8.1)
+
+The live count is **53 issues / 10 rules**, not the 51 / 5 an earlier pass
+recorded — a reminder that this section rots like everything else, so query the
+API before budgeting. **0 bugs, 0 vulnerabilities**; everything is a code smell
+or hotspot. What the code side of v3.8.1 actually did:
+
+Fixed (`e93972f`):
+
+- **`swift:S1871`** — `RootView` had byte-identical `.home` / `.recentActivity`
+ deep-link cases. Merged; recent activity is a *section* of Home, not a screen,
+ so both correctly land on the Home tab.
+- **3× `swift:S1186` (empty closure/function, CRITICAL)** — two are
+ `Button("Cancel", role: .cancel) {}` (dialog dismissal needs no body); the
+ third is an empty `URLProtocol.stopLoading()` override in a test. All three now
+ carry a nested comment. Note the earlier claim that "all three are Cancel
+ buttons" was wrong — only two are.
+- **`swift:S108`** — the expected-miss `catch` in `APICacheTests` is commented.
+- **`swift:S1172`** — the unused `url` in `mimeType(for:)` is now `_`.
+- **2× `javascript:S4624`** — the nested template literal in the deep-link
+ builders (`background.js`, `content.js`) is extracted to a `pathSegment` var.
+
+Fixed as a real bug instead (`65412ee`), not silenced:
+
+- **2× `swift:S1172` on `forceRefresh`** — `HomeViewModel.loadProjects` and
+ `loadSystemStatusSnapshot` took the flag and dropped it, so dashboard
+ pull-to-refresh returned cached projects and status. This is the trap named at
+ the top of this file. `ProjectsListView` carried the same defect via its own
+ `.refreshable`. Both fixed at the root in `ProjectService.fetchProjects`.
+
+Won't Fix, with reasons (resolve in SonarCloud's web UI, not in code):
+
+- **35× `swift:S1075` (hardcoded URI)** — 28 in `SourceHutWebDeepLinkMapperTests`,
+ the rest in `HutchDeepLinkURLs`. A deep-link mapper's tests exist to assert
+ literal URLs, and a one-forge client has fixed endpoints. "Fixing" them makes
+ the code worse.
+- **`swift:S107`** — `executeCached` has 8 params across **38 call sites**. A
+ param object would rewrite the hottest networking method for no behaviour or
+ correctness gain against an arbitrary 7-param line. Not worth the regression
+ surface.
+- **`swift:S1481`** — `ArtifactsView`'s `@Bindable var vm` is flagged unused, but
+ `$vm.error` is used at line 134; Sonar's Swift analyzer misses the projected
+ value. False positive — removing it breaks the build.
+- **`javascript:S7785`** — prefers top-level `await` for `injectBannerIfEnabled()`,
+ but `content.js` is a classic content script, not a module. Top-level `await`
+ would be a syntax error. Not applicable.
+- **5× `swift:S1135`** — TODO comments (INFO). Two in `HutchIntents` name real
+ gaps; leave them until those features land.
The 3 hotspots are the part actually worth thought:
@@ -234,10 +265,11 @@ The 3 hotspots are the part actually worth thought:
Query it with:
`https://sonarcloud.io/api/issues/search?componentKeys=zerolabsco_hutch&resolved=false`
-This is a patch because nothing executes differently afterwards. The 35 hardcoded-URI
-issues are resolved as *Won't Fix* in SonarCloud's web UI — not a commit at all — and
-the rest is three comments and one annotation. If it produces a diff that changes a
-runtime path, something has gone wrong.
+This was scoped as a patch on the assumption nothing executes differently — and
+that mostly held: the cosmetic fixes are comments, a merge, and a rename. The one
+exception earns the release its own line: the `forceRefresh` fix changes what
+pull-to-refresh does, so it needs a manual pass on a device before v3.8.1 ships,
+not just a green suite.
### Ingest "What's cooking on SourceHut?" — v3.9.0
@@ -309,7 +341,9 @@ which already consults the persistent cache before the memory layer.
Like Swift 6 above, this is internal and rides along with whatever release
already touches that area. Neither justifies a tag.
-## Housekeeping — v3.8.1
+## Housekeeping
-- `Hutch/Hutch/App/AccountSession.swift` sits in a stray nested directory;
- `Hutch/HutchTests/` is empty.
+- ~~`Hutch/Hutch/App/AccountSession.swift` sits in a stray nested directory;
+ `Hutch/HutchTests/` is empty.~~ Done (v3.8.1, `9834b78`). Moved beside the rest
+ of `App/`; both stray dirs removed. No pbxproj change — the target is a
+ synchronized root group, so the file compiled by path all along.