docs(11.1): record code review disposition

This commit is contained in:
Jakub Zych
2026-10-01 00:34:40 +02:00
parent 1b1132fa62
commit 8c4d02de0a

View File

@@ -0,0 +1,98 @@
---
phase: 11.1
review: 11.1-REVIEW.md
titles: json
findings:
- id: CR-01
severity: critical
disposition: open
title: "`src=` and Go fences inside blockquotes or callouts bypass snippet verification but are still published as \"verified source\""
- id: WR-01
severity: warning
disposition: open
title: "An Example without `// Output:` is a reachability root, so code go test never runs is accepted as \"run\""
- id: WR-02
severity: warning
disposition: open
title: "Go sources excluded by build constraints pass the \"compiled by go test\" check"
- id: WR-03
severity: warning
disposition: open
title: "The `go doc` fallback accepts identifiers with the wrong case"
- id: WR-04
severity: warning
disposition: open
title: "`golang` fences (and other Go aliases) bypass the \"go fence needs src=\" policy"
- id: WR-05
severity: warning
disposition: open
title: "The command checker skips common shell forms, so unknown commands are published unchecked"
- id: WR-06
severity: warning
disposition: open
title: "Heading IDs can collide with theme element IDs, which breaks search on that page and produces invalid HTML"
- id: WR-07
severity: warning
disposition: open
title: "The walkthrough's hand-written files carry \"Code generated … DO NOT EDIT\" headers"
- id: IN-01
severity: info
disposition: open
title: "A failed write leaves an unmarked output directory that the next build refuses to clean"
- id: IN-02
severity: info
disposition: open
title: "`scanFences` treats 4-space-indented backticks as fenced code, which gives false positives and differs from goldmark"
- id: IN-03
severity: info
disposition: open
title: "`data-href` from `source_url` is HTML-escaped but its URL scheme is not checked"
- id: IN-04
severity: info
disposition: open
title: "Dead error branch and a nil request in serve.go"
- id: IN-05
severity: info
disposition: open
title: "Search highlighting uses offsets from `toLowerCase()` on the original string"
- id: IN-06
severity: info
disposition: open
title: "The gate's forbidden sweep treats grep errors as \"no hits\""
- id: IN-07
severity: info
disposition: open
title: "The gate depends on GNU-only tools"
- id: IN-08
severity: info
disposition: open
title: "The identifier checker cannot see several span forms"
open: 16
total: 16
recorded: 2026-09-30T22:34:40.155Z
---
# Phase 11.1: Code Review Disposition
| Finding | Severity | Disposition | Source |
|---------|----------|-------------|--------|
| CR-01 | critical | open | - |
| WR-01 | warning | open | - |
| WR-02 | warning | open | - |
| WR-03 | warning | open | - |
| WR-04 | warning | open | - |
| WR-05 | warning | open | - |
| WR-06 | warning | open | - |
| WR-07 | warning | open | - |
| IN-01 | info | open | - |
| IN-02 | info | open | - |
| IN-03 | info | open | - |
| IN-04 | info | open | - |
| IN-05 | info | open | - |
| IN-06 | info | open | - |
| IN-07 | info | open | - |
| IN-08 | info | open | - |
Dispositions: `open` (recorded, not yet triaged), `fixed`, `skipped`, `deferred`.
Set `deferred` by hand and put the reason in the Source cell; both are preserved. A `|` in the reason is kept as prose and escaped on the next run.
Re-running the gate keeps every row it can. A row the current review no longer reports is kept and its Source cell flagged, so a finding does not leave this record silently. ONE exception: when a finding id is REUSED by a different finding, the earlier decision cannot keep a row — the id is taken — and it is dropped. A RECORDED decision (anything but `open`) is named on the console when that happens; a row still at `open` is replaced silently, because `open` records no decision to lose.