Repository navigation
Release new version - #5
Merged
Merged
Conversation
Contributor
Author
|
🎉 This PR is included in version 1.0.0 🎉 The release is available on: Your semantic-release bot 📦🚀 |
7 tasks done
allxsmith
added a commit
that referenced
this pull request
Aug 28, 2026
Fourteen findings, each reproduced before fixing. The two that could be triggered by any outside author: - A three-character denial of service. `#(?=\d)` left a `#` when the next char was not a digit, step 6 then wrote `@` after it, and invariant 6 - which strips entities before scanning - spliced the survivors into a reference nobody named, killing the run. `#@2x`, `##1` and `&##5` all did it. Every `#` in a field is now defanged, and the entity strip replaces with a space so the scanner cannot manufacture one either. - Live links published under bestaxbot. `\b` does not fire after `_`, but GFM's www-autolink and issue shorthand both accept `_` as a delimiter, so `_www.host` and `_GH-999` went out undefanged - falsifying the claim this PR adds that titles are stripped of anything that could link. Silent degradations, all now logged: the credential check skips a falsy secret, so with both env vars absent it quietly fell back to shape-matching and an encoded token passed; and `self` became '' on a 200 without a login, so every run POSTed instead of refreshing with the log reading like a normal first post. Correctness and blast radius: - MAX_PAYLOAD_BYTES is a byte cap while every limit the model is given is in characters, so a fully compliant CJK payload (3401 chars, 9801 bytes) was rejected before parsing. Sized to hold the character limits at worst-case UTF-8. - MAX_ITEMS_HARD contradicted its own docstring: 51 well-formed entries returned null and failed the run, for a session that broke no instruction it was given. It bounds the work now. `cap: 0` was also ignored entirely. - One bad payload out of a PR's two discarded the sibling's rendered comment while cleanup spent the label anyway - the same unrecoverable half-triaged state the publish step's `set -uo pipefail` exists to avoid. Only a run that renders nothing fails now. - A skip is constrained to the four pre-check reasons. A post-search `skip (no credible duplicates)` published nothing with every job green, silently dropping a comment dedupe always owes. - The item-type pin bound only the job that cannot write; it now binds the publish job too. - The publisher had no Retry-After retry despite being the only PAT-authored write path in the repo, and the justification reasoned about call volume where GitHub's secondary limits key on write cadence. - Marker selection matched any comment QUOTING a triage comment, including bestaxbot-reply.yml's un-sanitized replies. It now requires the marker to be the last non-empty line, which is what the renderer guarantees. - An unchanged verdict on a legacy-identity comment no longer POSTs a superseding one: auto-close reads the objection veto and the reaction only from the newest marker comment, so that discarded a live veto for nothing. - `AI_TRIAGE_AUTOCLOSE=dry-run` armed the 14-day notice while the closer only logs, so every comment promised a close that could not happen - in exactly the mode intended for rollout. Docs and coverage: invariant I2 now describes both shapes that satisfy it (claude-repro changes the identity, ai-triage changes the text); root CLAUDE.md no longer says a separate job renders; U+061C joins the bidi set; logins compare case-insensitively; and the two-command PR path - the configuration used for every pull request - finally has end-to-end tests.
This was referenced Sep 6, 2026
allxsmith
added a commit
that referenced
this pull request
Sep 19, 2026
…on rests on Answering two of my own review steers rather than waiting for them. The post-pass reads reference directives with a pattern of its own, since exempting comment bodies would otherwise have hidden them. That pattern is deliberately looser than the one TypeScript honours — not anchored to a line start — so every directive TypeScript follows is a subset of what this checks. Tightening it to match TypeScript exactly is the plausible future edit, so the seven spellings that would start shipping if it were are now pinned. Verified by making that edit: the case fails. Nine dangling spellings, twelve hostile inputs and the offsets themselves were checked by hand and are NOT all pinned, deliberately. Since the tokenising is TypeScript's now, a test over BOM, CRLF, unterminated templates or private-field `#` would be asserting TypeScript's correctness rather than ours. What is worth recording is that the 2007 comment ranges in the built tree all begin at a comment opener and end where the comment ends, which is the one thing that could have been silently wrong about borrowing the scanner: the offsets answering a different question than `inComment` asks. The `closeBundle` note now also says what its refutation depends on, because it rests on this config rather than on rollup: the typescript plugin emits declarations with `this.emitFile`, so they are rollup's assets to write, and `declarationDir` sits inside each output's `dir`, so they land in the tree the pass walks. Move them out of the output directory or to a plugin that writes them itself and the timing stops holding. It does not depend on the number of outputs. Refs #696
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
This PR was opened by the Changesets release GitHub action. When you're ready to do a release, you can merge this and the packages will be published to npm automatically. If you're not ready to do a release yet, that's fine, whenever you add more changesets to main, this PR will be updated.
Releases
@allxsmith/bestax-lib@1.0.25
Patch Changes