Fix pre-existing PII annotation debt and add pii_check to CI
Los mantenedores suelen responder en 1 día
Nadie ha tomado este issue todavía.
Evaluación
- Dificultad
- 4/5
- Tiempo estimado
- 3-5 días
- Aptitud para principiantes
- 68/100
Línea de trabajo
Start with .annotation_safe_list.yml, the model files under src/, and .github/workflows/ci.yml; run tox -e pii_check to reproduce the duplicate and uncovered-model failures. Review each listed model's data and add exactly one accurate annotation, remove the two redundant safelist entries, add pii_check to the CI matrix, and confirm the check passes with 100% coverage.
Escrito por el modelo de indexación a partir del texto del issue.
Descripción
Background
make pii_check runs code_annotations against every Django model in openedx-core's own
tree and requires each one to carry a .. no_pii: (or .. pii:) annotation, either inline in
the model's docstring or as an entry in .annotation_safe_list.yml. tox.ini's envlist
already includes a pii_check environment, but .github/workflows/ci.yml's test matrix lists
toxenv: ["django52", "package", "quality", "docs"], which does not include it. CI never runs
pii_check, so nothing currently blocks a merge that breaks it, and two problems have
accumulated on main as a result, confirmed by running tox -e pii_check directly:
Two models are double-covered, which is a lint error, not a coverage gap.
openedx_content.Draft and openedx_content.PublishableEntityVersion each carry an inline
.. no_pii: annotation in their own docstring (src/openedx_content/applets/publishing/models/draft_log.py
and .../models/publishable_entity.py), and each also has a now-redundant entry in
.annotation_safe_list.yml. code_annotations treats a model with both as annotated twice and
fails with a lint error rather than a coverage number:
openedx_content.Draft is annotated, but also in the safelist.
openedx_content.PublishableEntityVersion is annotated, but also in the safelist.
Twenty models are uncovered, confirmed by removing those two stale safelist entries and
re-running tox -e pii_check: 67 models total, 47 annotated, 20 uncovered, 70.1% coverage
against a 100% target. The twenty:
- Seven
oel_*backcompat shim models:oel_collections.Collection,oel_components.Component,
oel_publishing.Container,oel_publishing.DraftChangeLog,oel_publishing.DraftChangeLogRecord,
oel_publishing.LearningPackage,oel_publishing.PublishableEntity - Two
openedx_catalogmodels:CatalogCourse,CourseRun - Three
openedx_contentmodels:ComponentVersionMedia,ContainerType,Media - Two models from the installed
edx-organizationspackage:organizations.HistoricalOrganization,
organizations.HistoricalOrganizationCourse - Six test-only models in
test_django_app:ContainerContainer,ContainerContainerVersion,
TestContainer,TestContainerVersion,TestEntity,TestEntityVersion
None of these twenty are models that #613 (the CBE competency models) adds, and none of #613's
own PRs touch them. This debt predates #613 and is unrelated to it.
What to do
- Remove the
openedx_content.Draftandopenedx_content.PublishableEntityVersionentries
from.annotation_safe_list.yml; both are already covered by their own inline annotation. - Annotate each of the twenty uncovered models above as
.. no_pii:or.. pii:, whichever is
accurate, either inline in the model's own docstring (for a model defined in this repo's
src/) or in.annotation_safe_list.yml(for a model defined in an installed package, such
as the twoorganizations.Historical*models). - Add
pii_checkto thetoxenvlist in.github/workflows/ci.yml's test matrix, so a future
PR that breaks PII coverage or introduces a double-covered model fails CI instead of only
failing silently for whoever happens to runmake pii_checklocally.
Acceptance criteria
-
tox -e pii_checkpasses locally with no lint error and 100% coverage. -
.github/workflows/ci.yml's test matrix includespii_checkintoxenv, and the CI run
on the pull request shows apii_checkjob that passes. - No model's annotation is both inline and in the safelist at once.
- Every one of the twenty models listed above carries exactly one annotation, inline or in
the safelist, accurately describing whether it stores personal data.
Out of scope
Anything in #613, #641, or #642: the CBE competency models, their own PII annotations, and the
openedx-platform safelist entries for them. This issue is unrelated to that work and does not
block or get blocked by it.
- Lenguaje dominante
- Python
- Estrellas
- 10
- Forks
- 33
- Merge medio
- 2 d 16 h
- PR fusionados (30 d)
- 10
Preparar el entorno
- Sin Dockerfile ni archivo de Docker Compose
- Sin plantilla de pull request
- Leer la guía de contribución
Primeros pasos
- Lee el issue completo y luego la guía de contribución del proyecto.
- Comenta en el issue que vas a ocuparte — evita que dos personas hagan lo mismo.
- Haz un fork del repositorio y trabaja en una rama.
- Abre un pull request que haga referencia al número del issue.
Más de openedx/openedx-core
-
Dificultad 2/5 1-3 horas Aptitud para principiantes 75/100
openedx/openedx-core#831 ·
Los mantenedores suelen responder en 1 día
-
Dificultad 2/5 1-3 horas Aptitud para principiantes 85/100
openedx/openedx-core#827 ·
Los mantenedores suelen responder en 1 día
-
Dificultad 5/5 Más de una semana Aptitud para principiantes 25/100
openedx/openedx-core#855 ·
Los mantenedores suelen responder en 1 día
-
Dificultad 5/5 Más de una semana Aptitud para principiantes 25/100
openedx/openedx-core#843 ·
Los mantenedores suelen responder en 1 día
-
[BE] Course search: accept ISO 8601 datetimes in the start date filterPosiblemente ocupada @alezconsultant la tomó hace 9 días. Abierto
openedx/openedx-core#842 · 1 asignado ·
Los mantenedores suelen responder en 1 día
Todos los issues de openedx/openedx-core
Issues similares
-
HTML: <template> content is extracted as document textPosiblemente ocupada @ryanmeowy la tomó hoy. Abiertobug html
Dificultad 1/5 Menos de una hora Aptitud para principiantes 82/100
docling-project/docling#4714 · 2 comentarios ·
Los mantenedores suelen responder en 1 día
-
[BUG] Qdrant RAG client applies score_threshold to raw cosine similarity, not the 0-1 score it returnsPosiblemente ocupada @roydonsequeira la tomó hoy. Abiertobug
Dificultad 2/5 1-3 horas Aptitud para principiantes 70/100
Los mantenedores suelen responder en 1 día
-
Host test failure in core/direct_io.zig on Linux kernel 6.17: O_DIRECT open succeeds on procfs, so the test's 'plain' fd is not plainPosiblemente ocupada Un pull request vinculado a esta issue está abierto o ya se fusionó. Abierto
Dificultad 2/5 1-3 horas Aptitud para principiantes 72/100
ashhart/TensorFold#536 ·
Los mantenedores suelen responder en 1 día
-
area/install-update comp/cli duplicate P2 python:uv sweeper:risk-compatibility type/bug
Dificultad 1/5 Menos de una hora Aptitud para principiantes 62/100
NousResearch/hermes-agent#135440 · 1 comentario ·
Los mantenedores suelen responder en 1 día
-
bug
Dificultad 2/5 1-3 horas Aptitud para principiantes 85/100
Deepak3699/Ai_Mentor#244 ·
Los mantenedores suelen responder en 1 día