Files
summercms/.planning/phases/13-p-ytarium-api-wishlist-notifications-csv-credentials-public/13-REVIEW-DISPOSITION.md
2026-10-03 11:56:30 +02:00

3.2 KiB

phase, review, titles, findings, open, total, recorded
phase review titles findings open total recorded
13 13-REVIEW.md json
id severity disposition title
WR-01 warning open A surf overlap family's method-less pattern conflicts with any method-specific catch-all and fails boot
id severity disposition title
WR-02 warning open The CSV commit compare-and-swap is bypassed by mapping, row and cancel writes, which allows a second import job
id severity disposition title
WR-03 warning open A double-submitted "Kupione" (purchase) sends every purchase notification and mail twice
id severity disposition title
WR-04 warning open Token subscribers keep read and reserve access after the owner disables or regenerates the share, and the security review does not record this
id severity disposition title
IN-01 info open The conga unregistered-kind guard only covers a worker in the same process
id severity disposition title
IN-02 info open A panic between `Begin` and `done` leaks a pubfail slot for good
id severity disposition title
IN-03 info open Huge `page` values overflow the OFFSET computation on the new paginated routes
id severity disposition title
IN-04 info open The `householdPeerSQL` comment gives the wrong bind count
id severity disposition title
IN-05 info open `ResolveAIConfig` can return `(nil, nil)`, and `AIConfig` has no log redaction
id severity disposition title
IN-06 info open Uploaded CSV files are never removed
id severity disposition title
IN-07 info open The first credential store under concurrency answers 500
id severity disposition title
IN-08 info open The gate's required-test check matches test names without their package
id severity disposition title
IN-09 info open The case-status check accepts any status the route recorded in the fixture
13 13 2026-10-03T09:56:30.413Z

Phase 13: Code Review Disposition

Finding Severity Disposition Source
WR-01 warning open -
WR-02 warning open -
WR-03 warning open -
WR-04 warning open -
IN-01 info open -
IN-02 info open -
IN-03 info open -
IN-04 info open -
IN-05 info open -
IN-06 info open -
IN-07 info open -
IN-08 info open -
IN-09 info open -

Dispositions: open (recorded, not yet triaged), fixed, skipped, deferred. Set deferred by hand and put the reason in the Source cell; both are preserved. A | in the reason is kept as prose and escaped on the next run. Re-running the gate keeps every row it can. A row the current review no longer reports is kept and its Source cell flagged, so a finding does not leave this record silently. ONE exception: when a finding id is REUSED by a different finding, the earlier decision cannot keep a row — the id is taken — and it is dropped. A RECORDED decision (anything but open) is named on the console when that happens; a row still at open is replaced silently, because open records no decision to lose.