From 8b4f03a36c8a2a6638472314013e3703a9174bc1 Mon Sep 17 00:00:00 2001 From: Jakub Zych Date: Sat, 3 Oct 2026 11:56:30 +0200 Subject: [PATCH] docs(13): record code review disposition --- .../13-REVIEW-DISPOSITION.md | 83 +++++++++++++++++++ 1 file changed, 83 insertions(+) create mode 100644 .planning/phases/13-p-ytarium-api-wishlist-notifications-csv-credentials-public/13-REVIEW-DISPOSITION.md diff --git a/.planning/phases/13-p-ytarium-api-wishlist-notifications-csv-credentials-public/13-REVIEW-DISPOSITION.md b/.planning/phases/13-p-ytarium-api-wishlist-notifications-csv-credentials-public/13-REVIEW-DISPOSITION.md new file mode 100644 index 0000000..e24b605 --- /dev/null +++ b/.planning/phases/13-p-ytarium-api-wishlist-notifications-csv-credentials-public/13-REVIEW-DISPOSITION.md @@ -0,0 +1,83 @@ +--- +phase: 13 +review: 13-REVIEW.md +titles: json +findings: + - id: WR-01 + severity: warning + disposition: open + title: "A surf overlap family's method-less pattern conflicts with any method-specific catch-all and fails boot" + - id: WR-02 + severity: warning + disposition: open + title: "The CSV commit compare-and-swap is bypassed by mapping, row and cancel writes, which allows a second import job" + - id: WR-03 + severity: warning + disposition: open + title: "A double-submitted \"Kupione\" (purchase) sends every purchase notification and mail twice" + - id: WR-04 + severity: warning + disposition: open + title: "Token subscribers keep read and reserve access after the owner disables or regenerates the share, and the security review does not record this" + - id: IN-01 + severity: info + disposition: open + title: "The conga unregistered-kind guard only covers a worker in the same process" + - id: IN-02 + severity: info + disposition: open + title: "A panic between `Begin` and `done` leaks a pubfail slot for good" + - id: IN-03 + severity: info + disposition: open + title: "Huge `page` values overflow the OFFSET computation on the new paginated routes" + - id: IN-04 + severity: info + disposition: open + title: "The `householdPeerSQL` comment gives the wrong bind count" + - id: IN-05 + severity: info + disposition: open + title: "`ResolveAIConfig` can return `(nil, nil)`, and `AIConfig` has no log redaction" + - id: IN-06 + severity: info + disposition: open + title: "Uploaded CSV files are never removed" + - id: IN-07 + severity: info + disposition: open + title: "The first credential store under concurrency answers 500" + - id: IN-08 + severity: info + disposition: open + title: "The gate's required-test check matches test names without their package" + - id: IN-09 + severity: info + disposition: open + title: "The case-status check accepts any status the route recorded in the fixture" +open: 13 +total: 13 +recorded: 2026-10-03T09:56:30.413Z +--- + +# Phase 13: Code Review Disposition + +| Finding | Severity | Disposition | Source | +|---------|----------|-------------|--------| +| WR-01 | warning | open | - | +| WR-02 | warning | open | - | +| WR-03 | warning | open | - | +| WR-04 | warning | open | - | +| IN-01 | info | open | - | +| IN-02 | info | open | - | +| IN-03 | info | open | - | +| IN-04 | info | open | - | +| IN-05 | info | open | - | +| IN-06 | info | open | - | +| IN-07 | info | open | - | +| IN-08 | info | open | - | +| IN-09 | info | open | - | + +Dispositions: `open` (recorded, not yet triaged), `fixed`, `skipped`, `deferred`. +Set `deferred` by hand and put the reason in the Source cell; both are preserved. A `|` in the reason is kept as prose and escaped on the next run. +Re-running the gate keeps every row it can. A row the current review no longer reports is kept and its Source cell flagged, so a finding does not leave this record silently. ONE exception: when a finding id is REUSED by a different finding, the earlier decision cannot keep a row — the id is taken — and it is dropped. A RECORDED decision (anything but `open`) is named on the console when that happens; a row still at `open` is replaced silently, because `open` records no decision to lose.