docs(11): record code review disposition
This commit is contained in:
@@ -0,0 +1,108 @@
|
||||
---
|
||||
phase: 11
|
||||
review: 11-REVIEW.md
|
||||
titles: json
|
||||
findings:
|
||||
- id: CR-01
|
||||
severity: critical
|
||||
disposition: open
|
||||
title: "The search index syncs mid-transaction, before pivots are written, and diverges from committed data"
|
||||
- id: WR-01
|
||||
severity: warning
|
||||
disposition: open
|
||||
title: "Broadcast channel and payload callbacks get a handle that continues the write's statement after `WithContext`"
|
||||
- id: WR-02
|
||||
severity: warning
|
||||
disposition: open
|
||||
title: "Scheduled commands that open their own database fail inside a running worker"
|
||||
- id: WR-03
|
||||
severity: warning
|
||||
disposition: open
|
||||
title: "A nested `lagoon.Transaction` over the root handle is an independent transaction, but its callbacks wait on the parent"
|
||||
- id: WR-04
|
||||
severity: warning
|
||||
disposition: open
|
||||
title: "`websockets:generate-vapid-keys --update` writes the VAPID private key into the application's repository tree"
|
||||
- id: WR-05
|
||||
severity: warning
|
||||
disposition: open
|
||||
title: "Identifier connection tokens are authorized as user ids by the subscribe proxy"
|
||||
- id: WR-06
|
||||
severity: warning
|
||||
disposition: open
|
||||
title: "The default broadcast payload serializes the in-memory model: zero values on partial updates, and every exported field"
|
||||
- id: WR-07
|
||||
severity: warning
|
||||
disposition: open
|
||||
title: "The Centrifugo subscribe proxy shares an IP-keyed rate limit bucket with public traffic"
|
||||
- id: IN-01
|
||||
severity: info
|
||||
disposition: open
|
||||
title: "Parity tooling cannot detect key-order drift, and several payload maps are unordered"
|
||||
- id: IN-02
|
||||
severity: info
|
||||
disposition: open
|
||||
title: "The fallback to the in-memory album in `albumPayload` is unreachable"
|
||||
- id: IN-03
|
||||
severity: info
|
||||
disposition: open
|
||||
title: "The River scheduler and `schedule:run --once` disagree on DST days and sub-minute intervals"
|
||||
- id: IN-04
|
||||
severity: info
|
||||
disposition: open
|
||||
title: "`summer_jobs` rows can stay IN_PROGRESS forever"
|
||||
- id: IN-05
|
||||
severity: info
|
||||
disposition: open
|
||||
title: "The centrifugo and typesense `Config` structs do not redact their secrets"
|
||||
- id: IN-06
|
||||
severity: info
|
||||
disposition: open
|
||||
title: "`parity:broadcasts --api-key` puts a secret on the command line"
|
||||
- id: IN-07
|
||||
severity: info
|
||||
disposition: open
|
||||
title: "The removal harness leaves mutated security code behind on SIGTERM or SIGKILL"
|
||||
- id: IN-08
|
||||
severity: info
|
||||
disposition: open
|
||||
title: "`Service.Emit` drops the caller's context when `db` is nil"
|
||||
- id: IN-09
|
||||
severity: info
|
||||
disposition: open
|
||||
title: "The three modules detect a transaction in different ways"
|
||||
- id: IN-10
|
||||
severity: info
|
||||
disposition: open
|
||||
title: "`RecordBroadcasts` returns before the recorder has released its port"
|
||||
open: 18
|
||||
total: 18
|
||||
recorded: 2026-09-30T13:18:20.607Z
|
||||
---
|
||||
|
||||
# Phase 11: Code Review Disposition
|
||||
|
||||
| Finding | Severity | Disposition | Source |
|
||||
|---------|----------|-------------|--------|
|
||||
| CR-01 | critical | open | - |
|
||||
| WR-01 | warning | open | - |
|
||||
| WR-02 | warning | open | - |
|
||||
| WR-03 | warning | open | - |
|
||||
| WR-04 | warning | open | - |
|
||||
| WR-05 | warning | open | - |
|
||||
| WR-06 | warning | open | - |
|
||||
| WR-07 | warning | open | - |
|
||||
| IN-01 | info | open | - |
|
||||
| IN-02 | info | open | - |
|
||||
| IN-03 | info | open | - |
|
||||
| IN-04 | info | open | - |
|
||||
| IN-05 | info | open | - |
|
||||
| IN-06 | info | open | - |
|
||||
| IN-07 | info | open | - |
|
||||
| IN-08 | info | open | - |
|
||||
| IN-09 | info | open | - |
|
||||
| IN-10 | info | open | - |
|
||||
|
||||
Dispositions: `open` (recorded, not yet triaged), `fixed`, `skipped`, `deferred`.
|
||||
Set `deferred` by hand and put the reason in the Source cell; both are preserved. A `|` in the reason is kept as prose and escaped on the next run.
|
||||
Re-running the gate keeps every row it can. A row the current review no longer reports is kept and its Source cell flagged, so a finding does not leave this record silently. ONE exception: when a finding id is REUSED by a different finding, the earlier decision cannot keep a row — the id is taken — and it is dropped. A RECORDED decision (anything but `open`) is named on the console when that happens; a row still at `open` is replaced silently, because `open` records no decision to lose.
|
||||
Reference in New Issue
Block a user