Skip to content

Community index - #46

Merged
ashwinkumargb merged 5 commits into
mainfrom
community-index
Sep 11, 2026
Merged

ashwinkumargb merged 5 commits into
mainfrom
community-index

Conversation

@ashwinkumargb

Copy link
Copy Markdown
Collaborator

Added a community index for Merlin-derived projects. It adds a community section where third parties can list work derived from Merlin.

@ashwinkumargb
ashwinkumargb requested a lite review from Copilot September 11, 2026 21:46
@ashwinkumargb
ashwinkumargb merged commit c7bfe4a into main Sep 11, 2026
7 checks passed
@ashwinkumargb
ashwinkumargb deleted the community-index branch September 11, 2026 21:46

Copilot AI left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

🟡 Changes recommended

Unresolved SSRF, validation, output-safety, and lockfile issues must be addressed.

Get a fresh assessment by requesting another Copilot review.

Pull request overview

Adds a community index for Merlin-derived projects, with YAML validation, generated listings, contribution guidance, and CI link checks.

Changes:

  • Adds community documentation, templates, contribution guidance, and a sample entry.
  • Adds validation, README generation, and link-check tooling.
  • Updates development dependencies, CI workflows, and formatting.
File summaries
File Summary and final review comments
README.md Links to the community index. nit (2 votes): Improve the ungrammatical call to action and link directly to the instructions.
pyproject.toml Adds PyYAML as a development dependency. moderate (2 votes): Regenerate and commit uv.lock.
merlin/utils/__init__.py Formatting-only update.
merlin/models/inflate.py Formatting-only update.
merlin/models/__init__.py Formatting-only update.
merlin/data/download_data.py Formatting-only update.
merlin/data/__init__.py Formatting-only update.
merlin/__init__.py Formatting-only update.
documentation/download.md Formatting-only update.
community/validate.py Validates entries and generates the index. moderate: Reject datetime values where dates are required (3 votes); validate malformed URLs or catch URL-construction errors (1 vote); escape HTML output (1 vote); prevent citations from breaking fenced code blocks (1 vote); escape Markdown/HTML control characters in rendered fields (1 vote); and robustly handle reserved splice markers (1 vote).
community/template.yaml Defines the community entry template.
community/README.md Provides the community project listing. nit (3 votes): Fix subject-verb agreement in the relative clause.
community/entries/merlin-nnunet.yaml Adds a sample project entry.
community/CONTRIBUTING.md Documents contribution requirements.
.github/workflows/ruff.yml Pins the Ruff version.
.github/workflows/community.yml Runs validation and link checks. critical (1 vote): Contributor-controlled URLs can cause SSRF through urlopen; restrict destinations or run checks only in trusted contexts.
Review details

Suppressed comments (5)

community/validate.py:54

  • URL_RE only checks the scheme and absence of whitespace, so malformed values such as https://example.org:bad or an unmatched IPv6 bracket can pass schema validation and cause urllib to raise a URL parsing error that probe_url does not catch. In --links-only, that aborts the workflow with a traceback instead of reporting the entry; validate the parsed scheme/netloc or catch URL-construction errors.
URL_RE = re.compile(r"^https?://\S+$")

community/validate.py:263

  • Contributor-controlled name values are inserted directly into an HTML <summary>, while validation permits arbitrary </> characters. A valid entry can therefore corrupt or inject markup into the generated README; escape values used in HTML/Markdown (or restrict the display fields to safe text) before rendering.
            f"<summary><b>{entry['name']}</b> — {entry['category']}</summary>",

community/validate.py:298

  • The citation is placed inside a fixed triple-backtick fence, but the schema accepts any string. A citation containing ``` closes this fence and makes the generated README malformed; reject fence markers or generate a fence longer than the citation's longest backtick run.
            block += ["", "```bibtex", entry["citation"].strip(), "```"]

community/validate.py:253

  • name and homepage come from community YAML, but escape_cell only escapes |; they are interpolated directly into Markdown here, and name is also inserted raw into the <summary> below. An entry such as a name containing ]( or HTML can break the generated link or inject deceptive markup into the committed README. Escape each value for its output context, or reject Markdown/HTML control characters before rendering.
            f"| [{name}]({homepage}) "

community/validate.py:312

  • splice_index selects the first occurrence of the closing marker, but citation and other entry text are copied into the generated region. A valid entry containing the literal marker can therefore make the next --write select the embedded occurrence and corrupt or truncate community/README.md. Match standalone markers robustly or reject the reserved marker text in entry fields.
    end = text.find(END_MARKER)
  • Files reviewed: 10/16 changed files
  • Comments generated: 5
  • Review effort level: Lite

💡 Add a code-review agent skill or configure MCP servers for context-aware, tailored reviews. Learn more in the docs.

python-version: '3.11'
- run: pip install pyyaml
- name: Check that every linked URL resolves
run: python community/validate.py --links-only
Comment thread community/validate.py
Comment on lines +178 to +179
if isinstance(added, datetime.date):
pass # PyYAML already parsed an ISO date for us
Comment thread pyproject.toml
"pre-commit",
"mdformat"
"mdformat",
"pyyaml", # used by community/validate.py
Comment thread README.md

## 🤝 Community

Models, datasets, and tools built on Merlin by the community are indexed in [`community/`](community). Please see here on [how to add yours](community/CONTRIBUTING.md).
Comment thread community/README.md
@@ -0,0 +1,33 @@
# Merlin Community Projects 🤝

Work built on top of Merlin, which include models, datasets, tools, benchmarks, and tutorials contributed by the community.
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants