diff options
| author | Craig Jennings <c@cjennings.net> | 2026-07-23 08:25:40 -0500 |
|---|---|---|
| committer | Craig Jennings <c@cjennings.net> | 2026-07-23 08:25:40 -0500 |
| commit | 01356fa036847f9d216dd92a006049105c2d5461 (patch) | |
| tree | 4034b455c1a98a8b67e5ebb5ba8976e707055fc6 /playwright-py/scripts/safe_actions.py | |
| parent | 33949c50b7d2b3ab01af4fe91119cc290fae9f01 (diff) | |
| download | rulesets-01356fa036847f9d216dd92a006049105c2d5461.tar.gz rulesets-01356fa036847f9d216dd92a006049105c2d5461.zip | |
chore: file eight bug findings and stage four shared-asset proposals
Overnight hygiene sweep of this repo. Everything here is a finding or a staged proposal. No rule, workflow, script, or bundle file was modified.
The one that matters: the python and typescript language bundles ship no pre-commit hook, so a project installing either gets no credential scan on commit. Both bundles predate the hook rollout that swept go and bash, and install-lang skips missing components without a word, so it went unnoticed for two months. Live on two projects, one of them work. Filed [#A].
Seven more findings landed. The largest is a non-atomic write in the cross-project inbox tool, which can strand an empty handoff in another project's inbox and block a turn there. The rest are lint noise and two gaps in the Signal channel. An eighth was filed and then retracted the same night, once a retest showed I had compared two different files and read the difference as a bug.
Four proposals from other projects are staged under working/ with verified diffs, each behind a VERIFY task, waiting on a decision.
Diffstat (limited to 'playwright-py/scripts/safe_actions.py')
0 files changed, 0 insertions, 0 deletions
