* fix(#1907): validate per-item shape in isValidReport so adapter garbage fails closed isValidReport checked only the container (items is-array, coverage scalars), so a report like {items:[{}]} sailed through runProbeCli and stringified as green output — despite the docstring promising it 'fails closed on adapter garbage'. Add a per-item Item-contract guard (requirement_id/category/status + typed nullable fields) so a future adapter that bypasses the analyzeCoverage merge and returns per-item garbage inside a well-shaped envelope fails closed (exit 2) instead of emitting it as valid coverage. analyzeCoverage always emits fully-populated, validated Items, so the 2 shipped adapters are unaffected (verified across the edge/prohibition suites). Refs #1907, epic #1904. * chore(changeset): Fixed fragment for #1910 (isValidReport per-item)
40 KiB
40 KiB