Files
summercms/.planning/phases/11.1-summercms-documentation-for-humans-and-ai-agents/11.1-REVIEW-DISPOSITION.md
2026-10-01 09:25:15 +02:00

4.7 KiB

phase, review, titles, findings, open, total, recorded
phase review titles findings open total recorded
11.1 11.1-REVIEW.md json
id severity disposition title
CR-01 critical open `src=` and Go fences inside blockquotes or callouts bypass snippet verification but are still published as "verified source"
id severity disposition title
WR-01 warning open An Example without `// Output:` is a reachability root, so code go test never runs is accepted as "run"
id severity disposition title
WR-02 warning open Go sources excluded by build constraints pass the "compiled by go test" check
id severity disposition title
WR-03 warning open The `go doc` fallback accepts identifiers with the wrong case
id severity disposition title
WR-04 warning open `golang` fences (and other Go aliases) bypass the "go fence needs src=" policy
id severity disposition title
WR-05 warning open The command checker skips common shell forms, so unknown commands are published unchecked
id severity disposition title
WR-06 warning open Heading IDs can collide with theme element IDs, which breaks search on that page and produces invalid HTML
id severity disposition title
WR-07 warning open The walkthrough's hand-written files carry "Code generated … DO NOT EDIT" headers
id severity disposition title
IN-01 info open A failed write leaves an unmarked output directory that the next build refuses to clean
id severity disposition title
IN-02 info open `scanFences` treats 4-space-indented backticks as fenced code, which gives false positives and differs from goldmark
id severity disposition title
IN-03 info open `data-href` from `source_url` is HTML-escaped but its URL scheme is not checked
id severity disposition title
IN-04 info open Dead error branch and a nil request in serve.go
id severity disposition title
IN-05 info open Search highlighting uses offsets from `toLowerCase()` on the original string
id severity disposition title
IN-06 info open The gate's forbidden sweep treats grep errors as "no hits"
id severity disposition title
IN-07 info open The gate depends on GNU-only tools
id severity disposition title
IN-08 info open The identifier checker cannot see several span forms
id severity disposition title
WR-08 warning open Shell fences in any language other than the exact words sh, shell, bash and console are not command-checked
id severity disposition title
WR-09 warning open checkBuiltGo still accepts Go files go test ./... does not build
id severity disposition title
WR-10 warning open A trailing shell continuation is reported as the command name, and the real command on the next line is never checked
id severity disposition title
WR-11 warning open The acceptance scanner misses a list-item fence on the marker line, and it marks a normal indented fence as nested
id severity disposition title
IN-09 info open The identifier index still counts files the default build ignores
21 21 2026-10-01T07:25:00.000Z

Phase 11.1: Code Review Disposition

Finding Severity Disposition Source
CR-01 critical open -
WR-01 warning open -
WR-02 warning open -
WR-03 warning open -
WR-04 warning open -
WR-05 warning open -
WR-06 warning open -
WR-07 warning open -
IN-01 info open -
IN-02 info open -
IN-03 info open -
IN-04 info open -
IN-05 info open -
IN-06 info open -
IN-07 info open -
IN-08 info open -
WR-08 warning open -
WR-09 warning open -
WR-10 warning open -
WR-11 warning open -
IN-09 info open -

Dispositions: open (recorded, not yet triaged), fixed, skipped, deferred. Set deferred by hand and put the reason in the Source cell; both are preserved. A | in the reason is kept as prose and escaped on the next run. Re-running the gate keeps every row it can. A row the current review no longer reports is kept and its Source cell flagged, so a finding does not leave this record silently. ONE exception: when a finding id is REUSED by a different finding, the earlier decision cannot keep a row — the id is taken — and it is dropped. A RECORDED decision (anything but open) is named on the console when that happens; a row still at open is replaced silently, because open records no decision to lose.