Skip to content

Release new version - #5

Merged
allxsmith merged 1 commit into
mainfrom
changeset-release/main
May 24, 2025
Merged

allxsmith merged 1 commit into
mainfrom
changeset-release/main

Conversation

@github-actions

Copy link
Copy Markdown
Contributor

This PR was opened by the Changesets release GitHub action. When you're ready to do a release, you can merge this and the packages will be published to npm automatically. If you're not ready to do a release yet, that's fine, whenever you add more changesets to main, this PR will be updated.

Releases

@allxsmith/bestax-lib@1.0.25

Patch Changes

@allxsmith
allxsmith merged commit 93a6db1 into main May 24, 2025
@github-actions

Copy link
Copy Markdown
Contributor Author

🎉 This PR is included in version 1.0.0 🎉

The release is available on:

Your semantic-release bot 📦🚀

allxsmith added a commit that referenced this pull request Aug 28, 2026
Fourteen findings, each reproduced before fixing. The two that could be
triggered by any outside author:

- A three-character denial of service. `#(?=\d)` left a `#` when the next
  char was not a digit, step 6 then wrote `@` after it, and invariant 6 -
  which strips entities before scanning - spliced the survivors into a
  reference nobody named, killing the run. `#@2x`, `##1` and `&##5` all did
  it. Every `#` in a field is now defanged, and the entity strip replaces with
  a space so the scanner cannot manufacture one either.
- Live links published under bestaxbot. `\b` does not fire after `_`, but
  GFM's www-autolink and issue shorthand both accept `_` as a delimiter, so
  `_www.host` and `_GH-999` went out undefanged - falsifying the claim this
  PR adds that titles are stripped of anything that could link.

Silent degradations, all now logged: the credential check skips a falsy
secret, so with both env vars absent it quietly fell back to shape-matching
and an encoded token passed; and `self` became '' on a 200 without a login,
so every run POSTed instead of refreshing with the log reading like a normal
first post.

Correctness and blast radius:

- MAX_PAYLOAD_BYTES is a byte cap while every limit the model is given is in
  characters, so a fully compliant CJK payload (3401 chars, 9801 bytes) was
  rejected before parsing. Sized to hold the character limits at worst-case
  UTF-8.
- MAX_ITEMS_HARD contradicted its own docstring: 51 well-formed entries
  returned null and failed the run, for a session that broke no instruction it
  was given. It bounds the work now. `cap: 0` was also ignored entirely.
- One bad payload out of a PR's two discarded the sibling's rendered comment
  while cleanup spent the label anyway - the same unrecoverable half-triaged
  state the publish step's `set -uo pipefail` exists to avoid. Only a run that
  renders nothing fails now.
- A skip is constrained to the four pre-check reasons. A post-search
  `skip (no credible duplicates)` published nothing with every job green,
  silently dropping a comment dedupe always owes.
- The item-type pin bound only the job that cannot write; it now binds the
  publish job too.
- The publisher had no Retry-After retry despite being the only PAT-authored
  write path in the repo, and the justification reasoned about call volume
  where GitHub's secondary limits key on write cadence.
- Marker selection matched any comment QUOTING a triage comment, including
  bestaxbot-reply.yml's un-sanitized replies. It now requires the marker to be
  the last non-empty line, which is what the renderer guarantees.
- An unchanged verdict on a legacy-identity comment no longer POSTs a
  superseding one: auto-close reads the objection veto and the reaction only
  from the newest marker comment, so that discarded a live veto for nothing.
- `AI_TRIAGE_AUTOCLOSE=dry-run` armed the 14-day notice while the closer only
  logs, so every comment promised a close that could not happen - in exactly
  the mode intended for rollout.

Docs and coverage: invariant I2 now describes both shapes that satisfy it
(claude-repro changes the identity, ai-triage changes the text); root
CLAUDE.md no longer says a separate job renders; U+061C joins the bidi set;
logins compare case-insensitively; and the two-command PR path - the
configuration used for every pull request - finally has end-to-end tests.
allxsmith added a commit that referenced this pull request Sep 19, 2026
…on rests on

Answering two of my own review steers rather than waiting for them.

The post-pass reads reference directives with a pattern of its own, since
exempting comment bodies would otherwise have hidden them. That pattern is
deliberately looser than the one TypeScript honours — not anchored to a line
start — so every directive TypeScript follows is a subset of what this checks.
Tightening it to match TypeScript exactly is the plausible future edit, so the
seven spellings that would start shipping if it were are now pinned. Verified by
making that edit: the case fails.

Nine dangling spellings, twelve hostile inputs and the offsets themselves were
checked by hand and are NOT all pinned, deliberately. Since the tokenising is
TypeScript's now, a test over BOM, CRLF, unterminated templates or private-field
`#` would be asserting TypeScript's correctness rather than ours. What is worth
recording is that the 2007 comment ranges in the built tree all begin at a
comment opener and end where the comment ends, which is the one thing that could
have been silently wrong about borrowing the scanner: the offsets answering a
different question than `inComment` asks.

The `closeBundle` note now also says what its refutation depends on, because it
rests on this config rather than on rollup: the typescript plugin emits
declarations with `this.emitFile`, so they are rollup's assets to write, and
`declarationDir` sits inside each output's `dir`, so they land in the tree the
pass walks. Move them out of the output directory or to a plugin that writes
them itself and the timing stops holding. It does not depend on the number of
outputs.

Refs #696
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant