Skip to content

feat(vendor): vendor update/diff, archived-repo checks, component.yaml - #2715

Merged
Andriy Knysh (aknysh) merged 10 commits into
mainfrom
osterman/vendor-update-diff-component-yaml
Jul 12, 2026
Merged

Andriy Knysh (aknysh) merged 10 commits into
mainfrom
osterman/vendor-update-diff-component-yaml

Conversation

@osterman

@osterman Erik Osterman (Cloud Posse) (osterman) commented Jul 10, 2026 •

Copy link
Copy Markdown
Member

what

  • Add atmos vendor update — checks every Git-backed source in vendor.yaml (and standalone component.yaml/component.yml manifests) for a newer version, honoring each source's constraints (semver range, excluded versions, no_prereleases), and writes the new version in place using the format-preserving pkg/yaml engine. Supports --check (dry run), --pull (fetch after updating), --component, --tags, --outdated, and --component-manifests.
  • Add atmos vendor diff — shows the Git diff between two versions (tags, branches, or commits) of a vendored component with no local checkout.
  • Detect archived upstream GitHub repositories (pkg/github/archived.go, pkg/vendoring/archived.go) and surface that status during update checks.
  • Add a spinner/progress UI (cmd/vendor/update_spinner.go) and a tabular update report (cmd/vendor/update_report.go) for vendor update's output.
  • Fix vendor.base_path/--chdir resolution so vendor update/diff/get/set no longer fail to find vendor.yaml when atmos.yaml configures a non-default vendor.base_path.
  • Supporting changes: pkg/io/streams.go masking, cmd/version/formatters.go, pkg/toolchain/info.go, errors/errors.go, plus new pkg/vendoring/resolve.go and pkg/vendoring/component_files.go to unify component resolution across vendor.yaml and component.yaml sources.
  • Adds a blog post (website/blog/2026-07-09-vendor-diff-and-update.mdx) and roadmap milestone update.

why

  • Bumping a vendored component's pinned version previously meant three manual steps: checking upstream tags yourself, cloning the repo somewhere to diff two versions, and hand-editing the version field in vendor.yaml while risking a stripped comment or mangled YAML anchor.
  • These commands close that loop using the existing format-preserving pkg/yaml engine (the same one behind atmos config|stack|vendor get|set|delete), and extend it to repos that only use per-component component.yaml manifests.

references

  • Blog: website/blog/2026-07-09-vendor-diff-and-update.mdx

@atmos-pro

atmos-pro Bot commented Jul 10, 2026 •

Copy link
Copy Markdown
Contributor

Tip

Atmos Pro  

No affected stacks workflow was detected for this pull request.
If this is expected, no action is needed.
Learn More. Ask AI.

@osterman Erik Osterman (Cloud Posse) (osterman) added the minor New features that do not break anything label Jul 10, 2026
@github-actions github-actions Bot added the size/l Large size PR label Jul 10, 2026
@github-actions

Copy link
Copy Markdown

Dependency Review

✅ No vulnerabilities or license issues found.

Scanned Files

None

@coderabbitai

coderabbitai Bot commented Jul 10, 2026 •

Copy link
Copy Markdown
Contributor

Review Change Stack

📝 Walkthrough

Walkthrough

Vendor management now supports component manifests alongside vendor.yaml, expanded update and pull flows, archived-source reporting, terminal-aware progress UI, fixed-width tables, and updated CLI documentation.

Changes

Vendor management

Layer / File(s) Summary
Manifest resolution and diff integration
cmd/vendor/diff.go, cmd/vendor/edit.go, pkg/vendoring/*, pkg/schema/vendor_component.go, errors/errors.go, website/docs/cli/commands/vendor/vendor-diff.mdx
Component manifests are discovered and validated, vendor-file precedence is applied, component constraints and version persistence are supported, and vendor diff accepts --type.
Update engine and archived metadata
pkg/vendoring/update.go, pkg/vendoring/archived.go, pkg/github/archived.go, pkg/vendoring/*_test.go
Updates process vendor and extra sources with precedence, progress callbacks, configurable version setters, and archived-repository metadata.
Update command, report, and spinner
cmd/vendor/update.go, cmd/vendor/update_report.go, cmd/vendor/update_spinner.go, cmd/vendor/*_test.go, website/docs/cli/commands/vendor/vendor-update.mdx, website/blog/*
The CLI adds component-manifest and archived filters, separates component and repository-wide execution, renders filtered reports, and displays TTY progress.
Batched component pulls
internal/exec/vendor_component_utils.go, cmd/vendor/update.go, cmd/vendor/vendor_test.go, internal/exec/vendor_component_utils_test.go
Component-manifest results are batch-pulled where possible, while remaining results use isolated per-component pulls with joined errors.
Terminal capability and rendering behavior
pkg/io/streams.go, internal/exec/vendor_model.go, cmd/version/formatters.go, pkg/toolchain/info.go, tests/snapshots/*, go.mod
Masked streams expose safe terminal capabilities, progress output handles mixins and terminal widths, and indicator columns remain fixed-width.

Estimated code review effort: 5 (Critical) | ~120 minutes

Sequence Diagram(s)

sequenceDiagram
  participant CLI
  participant Resolver
  participant VendorUpdater
  participant GitHub
  participant PullExecutor
  CLI->>Resolver: resolve vendor.yaml or component.yaml
  Resolver-->>CLI: return resolved sources
  CLI->>VendorUpdater: update filtered sources
  VendorUpdater->>GitHub: check archived status
  GitHub-->>VendorUpdater: return repository metadata
  VendorUpdater-->>CLI: return update report
  CLI->>PullExecutor: pull updated component sources
  PullExecutor-->>CLI: return pull results
Loading

Suggested reviewers: aknysh, MaxymVlasov

🚥 Pre-merge checks | ✅ 4 | ❌ 1

❌ Failed checks (1 warning)

Check name Status Explanation Resolution
Docstring Coverage ⚠️ Warning Docstring coverage is 77.11% which is insufficient. The required threshold is 80.00%. Write docstrings for the functions missing them to satisfy the coverage threshold.
✅ Passed checks (4 passed)
Check name Status Explanation
Linked Issues check ✅ Passed Check skipped because no linked issues were found for this pull request.
Out of Scope Changes check ✅ Passed Check skipped because no linked issues were found for this pull request.
Description Check ✅ Passed Check skipped - CodeRabbit’s high-level summary is enabled.
Title check ✅ Passed The title is concise and accurately reflects the main changes: vendor update/diff, archived checks, and component.yaml support.
✨ Finishing Touches
📝 Generate docstrings
  • Create stacked PR
  • Commit on current branch
🧪 Generate unit tests (beta)
  • Create PR with unit tests
  • Commit unit tests in branch osterman/vendor-update-diff-component-yaml

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

@coderabbitai coderabbitai Bot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Actionable comments posted: 4

Caution

Some comments are outside the diff and can’t be posted inline due to platform limitations.

⚠️ Outside diff range comments (1)
internal/exec/vendor_model.go (1)

437-465: 🎯 Functional Correctness | 🟡 Minor | ⚡ Quick win

Report failed mixins in the final summary.

A mixin-only failure produces “Failed to vendor 0 components” while the command exits unsuccessfully. Include failedMixins in both TTY and non-TTY failure summaries so the final status does not conceal the cause.

🤖 Prompt for AI Agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.

In `@internal/exec/vendor_model.go` around lines 437 - 465, Update the final
summary logic in modelVendor's View and the corresponding TTY summary to account
for failed mixins alongside failed packages. Include failedMixins in failure
detection and report counts, ensuring mixin-only failures do not display “Failed
to vendor 0 components” and remain accurately represented in both output modes.
🧹 Nitpick comments (1)
pkg/vendoring/update.go (1)

292-296: 🚀 Performance & Scalability | 🔵 Trivial

Archived check doubles per-component GitHub API calls.

Every checked source now makes an extra Repositories.Get call (on top of tag listing) purely for archived-status, even when the component is already up to date. For large vendor manifests this meaningfully increases API/rate-limit consumption per vendor update run. Worth confirming the CLI layer (cmd/vendor/update.go) exposes an opt-out for users on constrained rate limits.

🤖 Prompt for AI Agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.

In `@pkg/vendoring/update.go` around lines 292 - 296, Reduce redundant GitHub API
usage from the archived-status calculation in the update flow. Inspect
checkArchived and its callers, including the CLI wiring in cmd/vendor/update.go,
and add or expose an opt-out for archived checks that skips the extra repository
lookup when requested while preserving the current default behavior and status
handling.
🤖 Prompt for all review comments with AI agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.

Inline comments:
In `@cmd/vendor/update_spinner.go`:
- Around line 217-232: Ensure the terminal updateDoneMsg is always delivered: in
the goroutine around doWork and the progress callback, keep progress sends
best-effort but send updateDoneMsg through a guaranteed blocking path rather
than the non-blocking select. Update the message handling associated with
updateSpinnerModel/waitForUpdateMsg as needed so completion cannot be dropped
while a progress message occupies the buffer.

In `@cmd/vendor/update.go`:
- Around line 76-89: Guard the pull condition in the update flow against a nil
report: in the logic following renderUpdateReport and the err check, require
report != nil before calling report.UpdatedCount(). Preserve the existing pull
behavior for non-nil reports while preventing the runUpdateWithSpinner
early-quit path from dereferencing nil.
- Around line 211-214: Clear the update-only --stack and --tags flags before
delegating the single-component path in runVendorPull. Reset them on the command
flags, matching the repo-wide pull path, before calling
ExecuteVendorPullCmd(cmd, args).

In `@internal/exec/vendor_component_utils.go`:
- Around line 172-209: Wrap errors returned by
ReadAndProcessComponentVendorConfigFile and buildComponentVendorPackages inside
ExecuteComponentVendorPullBatch with fmt.Errorf using the current component name
and %w, distinguishing configuration resolution from package-building failures.
Ensure fmt is imported if needed while preserving fail-fast behavior.

---

Outside diff comments:
In `@internal/exec/vendor_model.go`:
- Around line 437-465: Update the final summary logic in modelVendor's View and
the corresponding TTY summary to account for failed mixins alongside failed
packages. Include failedMixins in failure detection and report counts, ensuring
mixin-only failures do not display “Failed to vendor 0 components” and remain
accurately represented in both output modes.

---

Nitpick comments:
In `@pkg/vendoring/update.go`:
- Around line 292-296: Reduce redundant GitHub API usage from the
archived-status calculation in the update flow. Inspect checkArchived and its
callers, including the CLI wiring in cmd/vendor/update.go, and add or expose an
opt-out for archived checks that skips the extra repository lookup when
requested while preserving the current default behavior and status handling.
🪄 Autofix (Beta)

Fix all unresolved CodeRabbit comments on this PR:

  • Push a commit to this branch (recommended)
  • Create a new PR with the fixes

ℹ️ Review info
⚙️ Run configuration

Configuration used: Path: .coderabbit.yaml

Review profile: CHILL

Plan: Pro

Run ID: 5e6023fb-750b-4764-9b9b-7ddc3119c2dd

📥 Commits

Reviewing files that changed from the base of the PR and between 708f70e and 1dcbfa2.

📒 Files selected for processing (35)
  • cmd/vendor/diff.go
  • cmd/vendor/edit.go
  • cmd/vendor/update.go
  • cmd/vendor/update_report.go
  • cmd/vendor/update_spinner.go
  • cmd/vendor/update_spinner_test.go
  • cmd/vendor/vendor_test.go
  • cmd/version/formatters.go
  • cmd/version/formatters_test.go
  • errors/errors.go
  • go.mod
  • internal/exec/vendor.go
  • internal/exec/vendor_component_utils.go
  • internal/exec/vendor_component_utils_test.go
  • internal/exec/vendor_model.go
  • internal/exec/vendor_model_test.go
  • pkg/github/archived.go
  • pkg/github/archived_test.go
  • pkg/io/streams.go
  • pkg/io/streams_test.go
  • pkg/schema/vendor_component.go
  • pkg/toolchain/info.go
  • pkg/vendoring/archived.go
  • pkg/vendoring/component_files.go
  • pkg/vendoring/component_files_test.go
  • pkg/vendoring/resolve.go
  • pkg/vendoring/resolve_test.go
  • pkg/vendoring/update.go
  • pkg/vendoring/update_test.go
  • website/blog/2026-06-27-yaml-editing-config-stack-vendor.mdx
  • website/blog/2026-07-09-vendor-diff-and-update.mdx
  • website/docs/cli/commands/vendor/vendor-diff.mdx
  • website/docs/cli/commands/vendor/vendor-update.mdx
  • website/docs/vendor/component-manifest/source.mdx
  • website/src/data/roadmap.js
💤 Files with no reviewable changes (2)
  • website/blog/2026-06-27-yaml-editing-config-stack-vendor.mdx
  • internal/exec/vendor.go

Comment thread cmd/vendor/update_spinner.go Outdated
Comment thread cmd/vendor/update.go
Comment thread cmd/vendor/update.go
Comment thread internal/exec/vendor_component_utils.go
coderabbitai[bot]
coderabbitai Bot previously approved these changes Jul 10, 2026
coderabbitai[bot]
coderabbitai Bot previously approved these changes Jul 10, 2026
@codecov

codecov Bot commented Jul 10, 2026 •

Copy link
Copy Markdown

Codecov Report

❌ Patch coverage is 91.32791% with 64 lines in your changes missing coverage. Please review.
✅ Project coverage is 81.33%. Comparing base (b8688aa) to head (d0c0888).

Files with missing lines Patch % Lines
cmd/vendor/update.go 76.47% 16 Missing and 12 partials ⚠️
internal/exec/vendor_model.go 84.50% 9 Missing and 2 partials ⚠️
pkg/vendoring/resolve.go 91.52% 7 Missing and 3 partials ⚠️
cmd/vendor/update_spinner.go 90.81% 5 Missing and 4 partials ⚠️
internal/exec/vendor_component_utils.go 85.71% 3 Missing and 1 partial ⚠️
pkg/vendoring/archived.go 89.47% 1 Missing and 1 partial ⚠️
Additional details and impacted files

Impacted file tree graph

@@            Coverage Diff             @@
##             main    #2715      +/-   ##
==========================================
+ Coverage   81.22%   81.33%   +0.11%     
==========================================
  Files        1635     1641       +6     
  Lines      154087   154729     +642     
==========================================
+ Hits       125157   125856     +699     
+ Misses      22025    21948      -77     
- Partials     6905     6925      +20     
Flag Coverage Δ
unittests 81.33% <91.32%> (+0.11%) ⬆️

Flags with carried forward coverage won't be shown. Click here to find out more.

Files with missing lines Coverage Δ
cmd/vendor/diff.go 88.37% <100.00%> (+17.91%) ⬆️
cmd/vendor/edit.go 87.50% <100.00%> (-0.74%) ⬇️
cmd/vendor/update_report.go 100.00% <100.00%> (ø)
cmd/version/formatters.go 88.42% <100.00%> (+0.08%) ⬆️
errors/errors.go 100.00% <ø> (ø)
internal/exec/vendor.go 60.82% <ø> (+17.39%) ⬆️
pkg/github/archived.go 100.00% <100.00%> (ø)
pkg/io/streams.go 91.30% <100.00%> (+2.11%) ⬆️
pkg/toolchain/info.go 61.51% <100.00%> (+0.27%) ⬆️
pkg/vendoring/component_files.go 100.00% <100.00%> (ø)
... and 7 more

... and 9 files with indirect coverage changes

🚀 New features to boost your workflow:
  • ❄️ Test Analytics: Detect flaky tests, report on failures, and find test suite problems.

@coderabbitai coderabbitai Bot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Actionable comments posted: 1

🤖 Prompt for all review comments with AI agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.

Inline comments:
In `@cmd/vendor/update.go`:
- Around line 225-278: partitionUpdatedResults currently groups
component-manifest updates without preserving their component type, while
pullBatchedComponentManifests accepts only one type. Refactor the batching flow
around partitionUpdatedResults and its caller to group updated components by
type, then invoke pullBatchedComponentManifests separately for each group using
that group’s type; retain fallback handling and error aggregation for every
batch.
🪄 Autofix (Beta)

Fix all unresolved CodeRabbit comments on this PR:

  • Push a commit to this branch (recommended)
  • Create a new PR with the fixes

ℹ️ Review info
⚙️ Run configuration

Configuration used: Path: .coderabbit.yaml

Review profile: CHILL

Plan: Pro

Run ID: e0df0512-2bb0-4f49-b20d-b314fffd6e8f

📥 Commits

Reviewing files that changed from the base of the PR and between cdbeeac and 9b620af.

📒 Files selected for processing (38)
  • cmd/vendor/diff.go
  • cmd/vendor/edit.go
  • cmd/vendor/update.go
  • cmd/vendor/update_report.go
  • cmd/vendor/update_spinner.go
  • cmd/vendor/update_spinner_test.go
  • cmd/vendor/vendor_test.go
  • cmd/version/formatters.go
  • cmd/version/formatters_test.go
  • errors/errors.go
  • go.mod
  • internal/exec/vendor.go
  • internal/exec/vendor_component_utils.go
  • internal/exec/vendor_component_utils_test.go
  • internal/exec/vendor_model.go
  • internal/exec/vendor_model_test.go
  • pkg/github/archived.go
  • pkg/github/archived_test.go
  • pkg/io/streams.go
  • pkg/io/streams_test.go
  • pkg/schema/vendor_component.go
  • pkg/toolchain/info.go
  • pkg/vendoring/archived.go
  • pkg/vendoring/archived_test.go
  • pkg/vendoring/component_files.go
  • pkg/vendoring/component_files_test.go
  • pkg/vendoring/resolve.go
  • pkg/vendoring/resolve_test.go
  • pkg/vendoring/update.go
  • pkg/vendoring/update_test.go
  • tests/snapshots/TestCLICommands_atmos_toolchain_info_raw_format_tool.stderr.golden
  • tests/snapshots/TestCLICommands_atmos_toolchain_info_shows_atmos-inline_registry.stderr.golden
  • website/blog/2026-06-27-yaml-editing-config-stack-vendor.mdx
  • website/blog/2026-07-09-vendor-diff-and-update.mdx
  • website/docs/cli/commands/vendor/vendor-diff.mdx
  • website/docs/cli/commands/vendor/vendor-update.mdx
  • website/docs/vendor/component-manifest/source.mdx
  • website/src/data/roadmap.js
💤 Files with no reviewable changes (2)
  • internal/exec/vendor.go
  • website/blog/2026-06-27-yaml-editing-config-stack-vendor.mdx
✅ Files skipped from review due to trivial changes (6)
  • tests/snapshots/TestCLICommands_atmos_toolchain_info_raw_format_tool.stderr.golden
  • tests/snapshots/TestCLICommands_atmos_toolchain_info_shows_atmos-inline_registry.stderr.golden
  • go.mod
  • website/src/data/roadmap.js
  • website/docs/cli/commands/vendor/vendor-diff.mdx
  • website/docs/vendor/component-manifest/source.mdx
🚧 Files skipped from review as they are similar to previous changes (21)
  • pkg/schema/vendor_component.go
  • errors/errors.go
  • pkg/vendoring/component_files_test.go
  • cmd/version/formatters_test.go
  • pkg/toolchain/info.go
  • cmd/vendor/diff.go
  • pkg/github/archived.go
  • cmd/version/formatters.go
  • pkg/github/archived_test.go
  • cmd/vendor/edit.go
  • internal/exec/vendor_component_utils.go
  • pkg/vendoring/archived.go
  • pkg/vendoring/resolve.go
  • cmd/vendor/update_report.go
  • pkg/io/streams.go
  • pkg/io/streams_test.go
  • pkg/vendoring/update.go
  • cmd/vendor/update_spinner.go
  • pkg/vendoring/component_files.go
  • internal/exec/vendor_model.go
  • internal/exec/vendor_model_test.go

Comment thread cmd/vendor/update.go Outdated
@mergify

mergify Bot commented Jul 11, 2026

Copy link
Copy Markdown
Contributor

💥 This pull request now has conflicts. Could you fix it Erik Osterman (Cloud Posse) (@osterman)? 🙏

@mergify mergify Bot added the conflict This PR has conflicts label Jul 11, 2026
…ent.yaml support

Closes the guess-and-hand-edit workflow for bumping vendored components: `atmos
vendor update` checks Git-backed sources for newer versions (honoring semver
constraints) and writes the new version in place via the format-preserving
pkg/yaml engine, and `atmos vendor diff` shows the diff between two versions
with no local checkout. Both now work against per-component component.yaml
manifests (not just vendor.yaml), detect archived upstream repos, respect
vendor.base_path/--chdir, and gained a spinner/progress UI with a tabular
update report.

Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
- Guard against a nil UpdateReport before calling UpdatedCount(): reachable
  when the user quits the spinner (keypress) before the background update
  finishes, which previously panicked with --pull set.
- Reset --stack/--tags before delegating to `vendor pull` on the
  single-component --pull path, matching the repo-wide path, so they don't
  trip validateVendorFlags' component/stack and component/tags exclusivity.
- Wrap ExecuteComponentVendorPullBatch's per-component resolution errors with
  the failing component's name so multi-component --pull failures are
  debuggable.
- Split the spinner's progress/done channel so a still-buffered progress
  message can no longer cause the terminal updateDoneMsg to be dropped,
  which hung the spinner forever waiting on a message that would never arrive.

Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
- atmos_vendor_pull: a PTY opened without Setsize (as the acceptance test
  harness's simulateTtyCommand does) reports size 0x0. maskedWriter.Fd()
  (this PR's own pkg/io/streams.go change) makes bubbletea's WindowSizeMsg
  reach the vendor-pull spinner again, and its handler was unconditionally
  adopting that 0x0, overwriting the already-correct fallback width and
  truncating "Pulling <name>" down to a bare ellipsis for the whole run.
  Guard both initialModelWidth and the WindowSizeMsg handler against
  non-positive widths, with a regression test reproducing the exact failure.
- atmos_toolchain_info_shows_atmos-inline_registry / raw_format_tool: this
  PR's indicator-column width fix (cmd/version/formatters.go,
  pkg/toolchain/info.go) legitimately changes table column widths;
  regenerate only the affected table rows in the two golden snapshots.

Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
…n-failure summary bug

Coverage additions target this PR's actual diff (verified against `git diff
origin/main` line ranges, not whole-file coverage):
- cmd/vendor/update_spinner.go: Init/Update/waitForUpdateMsg (0% -> 100%) and
  runUpdateWithSpinner's TTY branch (12% -> 88%), driven directly as a
  bubbletea tea.Model plus one real-PTY end-to-end test.
- cmd/vendor/update.go: single-component runVendorPull path, resetUnchangedFlag,
  and the typeChanged branch.
- pkg/vendoring/resolve.go: DefaultComponentDirResolver's real (non-fake)
  path, VendorFilePresent's remaining branches, notFoundError, and
  DiscoverComponentManifests/DiscoverAllComponentManifests error paths.
- internal/exec/vendor_component_utils.go: ExecuteComponentVendorInternal
  (previously untested directly) and buildComponentVendorPackages' template/
  mixin error branches.
- pkg/vendoring/update.go, archived.go, pkg/io/streams.go,
  cmd/vendor/update_report.go: remaining small diff-relevant gaps.

Also fixes a real bug found while extending vendor_model_test.go's mixin
coverage: a mixin-only failure (component itself succeeds) rendered as
"Failed to vendor 0 components" in both the TTY and non-TTY summaries,
indistinguishable from full success even though vendorFailureError still
fails the command. Both summaries now say so explicitly ("Failed to vendor N
mixins").

Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
…asename

partitionUpdatedResults grouped every component.yaml-declared update into one
ExecuteComponentVendorPullBatch call regardless of type, but
DiscoverAllComponentManifests' repo-wide sweep (no explicit --type) can mix
terraform/helmfile/packer updates in a single report. Forwarding a mixed
batch under one componentType resolved non-matching types under the wrong
components/<type>/<name> path.

Thread ComponentType through ResolvedSource and SourceUpdateResult (set by
ResolveComponentSource's component.yaml fallback and
DiscoverComponentManifests/DiscoverAllComponentManifests, empty for
vendor.yaml-declared sources) and group the batch by it, calling
ExecuteComponentVendorPullBatch once per type. Added a regression test
(TestRunVendorPull_BatchesByComponentType) that reproduces the wrong-path
failure without the fix and passes with it.

Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
coderabbitai[bot]
coderabbitai Bot previously approved these changes Jul 11, 2026
… CLAUDE.md

internal/exec/describe_affected_test.go's shared setup helpers
(setupDescribeAffectedTest, setupDescribeAffectedTestWithFixture) copy the
entire repo into a tempdir for each of 11 tests, and the copy's exclude
filter never accounted for this repo's own gitignored build output
(build/, custom-gcl, website/build - ~820MB combined), nor did these tests
respect the testing.Short() convention the rest of the package already uses
(introduced in #1605). Add a short-mode skip to both helpers and extend the
exclude filter to skip those three paths. Measured: `go test ./internal/exec/...`
178s (was ~600s), `go test -short ./internal/exec/...` ~60s.

CLAUDE.md's "Essential Commands"/"Testing"/"Pre-commit"/"Compilation" sections
were accidentally reverted from atmos custom commands back to the old, now-dead
`make ...` targets (which just print a migration notice and exit 1) by an
unrelated PR. Restore the correct `atmos build`/`atmos test`/`atmos test --full`/
`atmos test --coverage`/`atmos lint --changed` references (verified against
.atmos.d/test.yaml and .atmos.d/lint.yaml), and change the mandatory
post-change check from an unscoped `go test ./...` to short-mode `atmos test`.

Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
…vior

- TestRunUpdateWithSpinner_TTY_RunsSpinnerAndReturnsResult: creack/pty.Open()
  returns "unsupported" on Windows, matching the existing PTY-skip precedent
  in pkg/io/streams_test.go.
- TestDiscoverComponentManifests_BasePathIsAFile: os.ReadDir on a regular
  file path doesn't return an error on Windows (unlike ENOTDIR on Unix),
  so the test's premise doesn't hold there.

Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
examples/quick-start-advanced/README.md linked https://floci.io/ for Floci,
which now 404s. Every other Floci reference in the repo (docs/prd/emulators.md,
examples/terraform-tests/README.md, examples/emulator-aws/README.md) already
points at https://github.com/floci-io/floci; fix the one inconsistent link to
match.

Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
@mergify

mergify Bot commented Jul 11, 2026

Copy link
Copy Markdown
Contributor

💥 This pull request now has conflicts. Could you fix it Erik Osterman (Cloud Posse) (@osterman)? 🙏

@mergify mergify Bot added the conflict This PR has conflicts label Jul 11, 2026
…e-diff-component-yaml

# Conflicts:
#	CLAUDE.md

@coderabbitai coderabbitai Bot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

🧹 Nitpick comments (2)
internal/exec/describe_affected_test.go (2)

306-323: 📐 Maintainability & Code Quality | 🔵 Trivial | ⚡ Quick win

Extract duplicated copyOptions into a shared helper.

Both setup functions define an identical cp.Options struct. Extracting a helper eliminates this copy-paste and ensures future changes apply in one place.

♻️ Proposed refactor
+// repoCopyOptions returns copy.Options for copying the whole repo into a temp dir,
+// excluding build artifacts, caches, sockets, and symlinks.
+func repoCopyOptions() cp.Options {
+	return cp.Options{
+		PreserveTimes: false,
+		PreserveOwner: false,
+		OnSymlink:     func(string) cp.SymlinkAction { return cp.Skip },
+		Skip: func(srcInfo os.FileInfo, src, dest string) (bool, error) {
+			if shouldSkipRepoCopyPath(src) {
+				return true, nil
+			}
+			isSocket, err := u.IsSocket(src)
+			if err != nil {
+				return true, err
+			}
+			if isSocket {
+				return true, nil
+			}
+			return false, nil
+		},
+	}
+}

Then in both setup functions:

-	copyOptions := cp.Options{
-		PreserveTimes: false,
-		PreserveOwner: false,
-		OnSymlink:     func(string) cp.SymlinkAction { return cp.Skip },
-		Skip: func(srcInfo os.FileInfo, src, dest string) (bool, error) {
-			if shouldSkipRepoCopyPath(src) {
-				return true, nil
-			}
-			isSocket, err := u.IsSocket(src)
-			if err != nil {
-				return true, err
-			}
-			if isSocket {
-				return true, nil
-			}
-			return false, nil
-		},
-	}
+	copyOptions := repoCopyOptions()

Also applies to: 1224-1241

🤖 Prompt for AI Agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.

In `@internal/exec/describe_affected_test.go` around lines 306 - 323, Extract the
duplicated cp.Options construction into a shared helper, including the
PreserveTimes, PreserveOwner, OnSymlink, and Skip behavior currently shown in
the setup code. Update both setup functions to call this helper, including the
other occurrence noted in the review, so future copy-option changes are
centralized.

264-281: 📐 Maintainability & Code Quality | 🔵 Trivial | 💤 Low value

website/build is redundant here. The build check already matches it, so this branch can be removed.

🤖 Prompt for AI Agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.

In `@internal/exec/describe_affected_test.go` around lines 264 - 281, Remove the
redundant website/build condition from shouldSkipRepoCopyPath; the existing
build path checks already cover that case. Preserve all other skip-path checks
and return behavior unchanged.
🤖 Prompt for all review comments with AI agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.

Nitpick comments:
In `@internal/exec/describe_affected_test.go`:
- Around line 306-323: Extract the duplicated cp.Options construction into a
shared helper, including the PreserveTimes, PreserveOwner, OnSymlink, and Skip
behavior currently shown in the setup code. Update both setup functions to call
this helper, including the other occurrence noted in the review, so future
copy-option changes are centralized.
- Around line 264-281: Remove the redundant website/build condition from
shouldSkipRepoCopyPath; the existing build path checks already cover that case.
Preserve all other skip-path checks and return behavior unchanged.

ℹ️ Review info
⚙️ Run configuration

Configuration used: Path: .coderabbit.yaml

Review profile: CHILL

Plan: Pro

Run ID: 749954ea-942f-4e75-89ab-8542080fed0a

📥 Commits

Reviewing files that changed from the base of the PR and between 9b620af and ec9dd96.

📒 Files selected for processing (40)
  • CLAUDE.md
  • cmd/vendor/diff.go
  • cmd/vendor/edit.go
  • cmd/vendor/update.go
  • cmd/vendor/update_report.go
  • cmd/vendor/update_spinner.go
  • cmd/vendor/update_spinner_test.go
  • cmd/vendor/vendor_test.go
  • cmd/version/formatters.go
  • cmd/version/formatters_test.go
  • errors/errors.go
  • go.mod
  • internal/exec/describe_affected_test.go
  • internal/exec/vendor.go
  • internal/exec/vendor_component_utils.go
  • internal/exec/vendor_component_utils_test.go
  • internal/exec/vendor_model.go
  • internal/exec/vendor_model_test.go
  • pkg/github/archived.go
  • pkg/github/archived_test.go
  • pkg/io/streams.go
  • pkg/io/streams_test.go
  • pkg/schema/vendor_component.go
  • pkg/toolchain/info.go
  • pkg/vendoring/archived.go
  • pkg/vendoring/archived_test.go
  • pkg/vendoring/component_files.go
  • pkg/vendoring/component_files_test.go
  • pkg/vendoring/resolve.go
  • pkg/vendoring/resolve_test.go
  • pkg/vendoring/update.go
  • pkg/vendoring/update_test.go
  • tests/snapshots/TestCLICommands_atmos_toolchain_info_raw_format_tool.stderr.golden
  • tests/snapshots/TestCLICommands_atmos_toolchain_info_shows_atmos-inline_registry.stderr.golden
  • website/blog/2026-06-27-yaml-editing-config-stack-vendor.mdx
  • website/blog/2026-07-09-vendor-diff-and-update.mdx
  • website/docs/cli/commands/vendor/vendor-diff.mdx
  • website/docs/cli/commands/vendor/vendor-update.mdx
  • website/docs/vendor/component-manifest/source.mdx
  • website/src/data/roadmap.js
💤 Files with no reviewable changes (2)
  • website/blog/2026-06-27-yaml-editing-config-stack-vendor.mdx
  • internal/exec/vendor.go
✅ Files skipped from review due to trivial changes (5)
  • tests/snapshots/TestCLICommands_atmos_toolchain_info_shows_atmos-inline_registry.stderr.golden
  • tests/snapshots/TestCLICommands_atmos_toolchain_info_raw_format_tool.stderr.golden
  • go.mod
  • website/docs/vendor/component-manifest/source.mdx
  • website/src/data/roadmap.js
🚧 Files skipped from review as they are similar to previous changes (29)
  • errors/errors.go
  • pkg/schema/vendor_component.go
  • pkg/github/archived_test.go
  • pkg/toolchain/info.go
  • pkg/vendoring/component_files_test.go
  • pkg/vendoring/archived_test.go
  • cmd/vendor/diff.go
  • pkg/github/archived.go
  • cmd/vendor/edit.go
  • cmd/version/formatters.go
  • cmd/version/formatters_test.go
  • pkg/vendoring/archived.go
  • pkg/io/streams.go
  • internal/exec/vendor_component_utils_test.go
  • internal/exec/vendor_component_utils.go
  • cmd/vendor/update_report.go
  • website/docs/cli/commands/vendor/vendor-diff.mdx
  • pkg/vendoring/resolve_test.go
  • pkg/vendoring/component_files.go
  • cmd/vendor/update_spinner.go
  • pkg/vendoring/update.go
  • internal/exec/vendor_model.go
  • pkg/io/streams_test.go
  • cmd/vendor/update.go
  • pkg/vendoring/resolve.go
  • pkg/vendoring/update_test.go
  • cmd/vendor/update_spinner_test.go
  • cmd/vendor/vendor_test.go
  • internal/exec/vendor_model_test.go

@aknysh
Andriy Knysh (aknysh) merged commit 86edc83 into main Jul 12, 2026
80 checks passed
@aknysh
Andriy Knysh (aknysh) deleted the osterman/vendor-update-diff-component-yaml branch July 12, 2026 12:19
@atmos-pro

atmos-pro Bot commented Jul 12, 2026 •

Copy link
Copy Markdown
Contributor

Tip

Atmos Pro  

No affected stacks workflow was detected for this pull request.
If this is expected, no action is needed.
Learn More. Ask AI.

@github-actions

Copy link
Copy Markdown

These changes were released in v1.223.0-rc.9.

This branch was successfully deployed

1 active deployment
preview — d0c0888e Deployed Jul 12, 2026 by github-actions[bot]
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

minor New features that do not break anything size/xl Extra large size PR

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants