From d5a8ef7834f26dcfc7780b64a1530917b07238cf Mon Sep 17 00:00:00 2001 From: Jakub Zych Date: Sun, 4 Oct 2026 08:13:17 +0200 Subject: [PATCH] docs(14): record code review disposition --- .../14-REVIEW-DISPOSITION.md | 22 ++++++++++--------- 1 file changed, 12 insertions(+), 10 deletions(-) diff --git a/.planning/phases/14-domain-jobs-and-external-integrations/14-REVIEW-DISPOSITION.md b/.planning/phases/14-domain-jobs-and-external-integrations/14-REVIEW-DISPOSITION.md index 595a441..de59c6f 100644 --- a/.planning/phases/14-domain-jobs-and-external-integrations/14-REVIEW-DISPOSITION.md +++ b/.planning/phases/14-domain-jobs-and-external-integrations/14-REVIEW-DISPOSITION.md @@ -13,7 +13,7 @@ findings: title: "A stale CSV match pass can cancel, advance or fork a remapped import (the race D-10 claims to close)" - id: WR-02 severity: warning - disposition: open + disposition: fixed title: "The anonymous feedback upload keeps an attacker-chosen file extension in public storage" - id: WR-03 severity: warning @@ -21,15 +21,15 @@ findings: title: "Credential-test routes are unthrottled oracles for third-party keys (parity security hole)" - id: WR-04 severity: warning - disposition: open + disposition: fixed title: "The \"write-only\" admin AI key can be redirected to any host by changing base_url" - id: WR-05 severity: warning - disposition: open + disposition: fixed title: "`golem:import-settings` silently drops models from a repeater saved with non-sequential keys" - id: WR-06 severity: warning - disposition: open + disposition: fixed title: "The G15Office sync job is not idempotent, and a retry files duplicate tasks" - id: IN-01 severity: info @@ -63,9 +63,9 @@ findings: severity: info disposition: open title: "`wishlistReleaseMatchRules` aliases `releaseMatchRules`' backing array" -open: 15 +open: 11 total: 15 -recorded: 2026-10-04T01:05:31.197Z +recorded: 2026-10-04T06:13:17.500Z --- # Phase 14: Code Review Disposition @@ -74,11 +74,11 @@ recorded: 2026-10-04T01:05:31.197Z |---------|----------|-------------|--------| | CR-01 | critical | open | - | | WR-01 | warning | open | - | -| WR-02 | warning | open | - | +| WR-02 | warning | fixed | 14-REVIEW-FIX.md | | WR-03 | warning | open | - | -| WR-04 | warning | open | - | -| WR-05 | warning | open | - | -| WR-06 | warning | open | - | +| WR-04 | warning | fixed | 14-REVIEW-FIX.md | +| WR-05 | warning | fixed | 14-REVIEW-FIX.md | +| WR-06 | warning | fixed | 14-REVIEW-FIX.md | | IN-01 | info | open | - | | IN-02 | info | open | - | | IN-03 | info | open | - | @@ -89,3 +89,5 @@ recorded: 2026-10-04T01:05:31.197Z | IN-08 | info | open | - | Dispositions: `open` (recorded, not yet triaged), `fixed`, `skipped`, `deferred`. +Set `deferred` by hand and put the reason in the Source cell; both are preserved. A `|` in the reason is kept as prose and escaped on the next run. +Re-running the gate keeps every row it can. A row the current review no longer reports is kept and its Source cell flagged, so a finding does not leave this record silently. ONE exception: when a finding id is REUSED by a different finding, the earlier decision cannot keep a row — the id is taken — and it is dropped. A RECORDED decision (anything but `open`) is named on the console when that happens; a row still at `open` is replaced silently, because `open` records no decision to lose.