Community index - #46
Merged
Merged
Conversation
There was a problem hiding this comment.
🟡 Changes recommended
Unresolved SSRF, validation, output-safety, and lockfile issues must be addressed.
Get a fresh assessment by requesting another Copilot review.
Pull request overview
Adds a community index for Merlin-derived projects, with YAML validation, generated listings, contribution guidance, and CI link checks.
Changes:
- Adds community documentation, templates, contribution guidance, and a sample entry.
- Adds validation, README generation, and link-check tooling.
- Updates development dependencies, CI workflows, and formatting.
File summaries
| File | Summary and final review comments |
|---|---|
README.md |
Links to the community index. nit (2 votes): Improve the ungrammatical call to action and link directly to the instructions. |
pyproject.toml |
Adds PyYAML as a development dependency. moderate (2 votes): Regenerate and commit uv.lock. |
merlin/utils/__init__.py |
Formatting-only update. |
merlin/models/inflate.py |
Formatting-only update. |
merlin/models/__init__.py |
Formatting-only update. |
merlin/data/download_data.py |
Formatting-only update. |
merlin/data/__init__.py |
Formatting-only update. |
merlin/__init__.py |
Formatting-only update. |
documentation/download.md |
Formatting-only update. |
community/validate.py |
Validates entries and generates the index. moderate: Reject datetime values where dates are required (3 votes); validate malformed URLs or catch URL-construction errors (1 vote); escape HTML output (1 vote); prevent citations from breaking fenced code blocks (1 vote); escape Markdown/HTML control characters in rendered fields (1 vote); and robustly handle reserved splice markers (1 vote). |
community/template.yaml |
Defines the community entry template. |
community/README.md |
Provides the community project listing. nit (3 votes): Fix subject-verb agreement in the relative clause. |
community/entries/merlin-nnunet.yaml |
Adds a sample project entry. |
community/CONTRIBUTING.md |
Documents contribution requirements. |
.github/workflows/ruff.yml |
Pins the Ruff version. |
.github/workflows/community.yml |
Runs validation and link checks. critical (1 vote): Contributor-controlled URLs can cause SSRF through urlopen; restrict destinations or run checks only in trusted contexts. |
Review details
Suppressed comments (5)
community/validate.py:54
URL_REonly checks the scheme and absence of whitespace, so malformed values such ashttps://example.org:bador an unmatched IPv6 bracket can pass schema validation and causeurllibto raise a URL parsing error thatprobe_urldoes not catch. In--links-only, that aborts the workflow with a traceback instead of reporting the entry; validate the parsed scheme/netloc or catch URL-construction errors.
URL_RE = re.compile(r"^https?://\S+$")
community/validate.py:263
- Contributor-controlled
namevalues are inserted directly into an HTML<summary>, while validation permits arbitrary</>characters. A valid entry can therefore corrupt or inject markup into the generated README; escape values used in HTML/Markdown (or restrict the display fields to safe text) before rendering.
f"<summary><b>{entry['name']}</b> — {entry['category']}</summary>",
community/validate.py:298
- The citation is placed inside a fixed triple-backtick fence, but the schema accepts any string. A citation containing ``` closes this fence and makes the generated README malformed; reject fence markers or generate a fence longer than the citation's longest backtick run.
block += ["", "```bibtex", entry["citation"].strip(), "```"]
community/validate.py:253
nameandhomepagecome from community YAML, butescape_cellonly escapes|; they are interpolated directly into Markdown here, andnameis also inserted raw into the<summary>below. An entry such as a name containing](or HTML can break the generated link or inject deceptive markup into the committed README. Escape each value for its output context, or reject Markdown/HTML control characters before rendering.
f"| [{name}]({homepage}) "
community/validate.py:312
splice_indexselects the first occurrence of the closing marker, but citation and other entry text are copied into the generated region. A valid entry containing the literal marker can therefore make the next--writeselect the embedded occurrence and corrupt or truncatecommunity/README.md. Match standalone markers robustly or reject the reserved marker text in entry fields.
end = text.find(END_MARKER)
- Files reviewed: 10/16 changed files
- Comments generated: 5
- Review effort level: Lite
💡 Add a code-review agent skill or configure MCP servers for context-aware, tailored reviews. Learn more in the docs.
| python-version: '3.11' | ||
| - run: pip install pyyaml | ||
| - name: Check that every linked URL resolves | ||
| run: python community/validate.py --links-only |
Comment on lines
+178
to
+179
| if isinstance(added, datetime.date): | ||
| pass # PyYAML already parsed an ISO date for us |
| "pre-commit", | ||
| "mdformat" | ||
| "mdformat", | ||
| "pyyaml", # used by community/validate.py |
|
|
||
| ## 🤝 Community | ||
|
|
||
| Models, datasets, and tools built on Merlin by the community are indexed in [`community/`](community). Please see here on [how to add yours](community/CONTRIBUTING.md). |
| @@ -0,0 +1,33 @@ | |||
| # Merlin Community Projects 🤝 | |||
|
|
|||
| Work built on top of Merlin, which include models, datasets, tools, benchmarks, and tutorials contributed by the community. | |||
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Added a community index for Merlin-derived projects. It adds a community section where third parties can list work derived from Merlin.