Files
summercms/.planning/phases/11.1-summercms-documentation-for-humans-and-ai-agents/11.1-REVIEW-DISPOSITION.md
2026-10-01 09:25:15 +02:00

124 lines
4.7 KiB
Markdown

---
phase: 11.1
review: 11.1-REVIEW.md
titles: json
findings:
- id: CR-01
severity: critical
disposition: open
title: "`src=` and Go fences inside blockquotes or callouts bypass snippet verification but are still published as \"verified source\""
- id: WR-01
severity: warning
disposition: open
title: "An Example without `// Output:` is a reachability root, so code go test never runs is accepted as \"run\""
- id: WR-02
severity: warning
disposition: open
title: "Go sources excluded by build constraints pass the \"compiled by go test\" check"
- id: WR-03
severity: warning
disposition: open
title: "The `go doc` fallback accepts identifiers with the wrong case"
- id: WR-04
severity: warning
disposition: open
title: "`golang` fences (and other Go aliases) bypass the \"go fence needs src=\" policy"
- id: WR-05
severity: warning
disposition: open
title: "The command checker skips common shell forms, so unknown commands are published unchecked"
- id: WR-06
severity: warning
disposition: open
title: "Heading IDs can collide with theme element IDs, which breaks search on that page and produces invalid HTML"
- id: WR-07
severity: warning
disposition: open
title: "The walkthrough's hand-written files carry \"Code generated … DO NOT EDIT\" headers"
- id: IN-01
severity: info
disposition: open
title: "A failed write leaves an unmarked output directory that the next build refuses to clean"
- id: IN-02
severity: info
disposition: open
title: "`scanFences` treats 4-space-indented backticks as fenced code, which gives false positives and differs from goldmark"
- id: IN-03
severity: info
disposition: open
title: "`data-href` from `source_url` is HTML-escaped but its URL scheme is not checked"
- id: IN-04
severity: info
disposition: open
title: "Dead error branch and a nil request in serve.go"
- id: IN-05
severity: info
disposition: open
title: "Search highlighting uses offsets from `toLowerCase()` on the original string"
- id: IN-06
severity: info
disposition: open
title: "The gate's forbidden sweep treats grep errors as \"no hits\""
- id: IN-07
severity: info
disposition: open
title: "The gate depends on GNU-only tools"
- id: IN-08
severity: info
disposition: open
title: "The identifier checker cannot see several span forms"
- id: WR-08
severity: warning
disposition: open
title: "Shell fences in any language other than the exact words sh, shell, bash and console are not command-checked"
- id: WR-09
severity: warning
disposition: open
title: "checkBuiltGo still accepts Go files go test ./... does not build"
- id: WR-10
severity: warning
disposition: open
title: "A trailing shell continuation is reported as the command name, and the real command on the next line is never checked"
- id: WR-11
severity: warning
disposition: open
title: "The acceptance scanner misses a list-item fence on the marker line, and it marks a normal indented fence as nested"
- id: IN-09
severity: info
disposition: open
title: "The identifier index still counts files the default build ignores"
open: 21
total: 21
recorded: 2026-10-01T07:25:00.000Z
---
# Phase 11.1: Code Review Disposition
| Finding | Severity | Disposition | Source |
|---------|----------|-------------|--------|
| CR-01 | critical | open | - |
| WR-01 | warning | open | - |
| WR-02 | warning | open | - |
| WR-03 | warning | open | - |
| WR-04 | warning | open | - |
| WR-05 | warning | open | - |
| WR-06 | warning | open | - |
| WR-07 | warning | open | - |
| IN-01 | info | open | - |
| IN-02 | info | open | - |
| IN-03 | info | open | - |
| IN-04 | info | open | - |
| IN-05 | info | open | - |
| IN-06 | info | open | - |
| IN-07 | info | open | - |
| IN-08 | info | open | - |
| WR-08 | warning | open | - |
| WR-09 | warning | open | - |
| WR-10 | warning | open | - |
| WR-11 | warning | open | - |
| IN-09 | info | open | - |
Dispositions: `open` (recorded, not yet triaged), `fixed`, `skipped`, `deferred`.
Set `deferred` by hand and put the reason in the Source cell; both are preserved. A `|` in the reason is kept as prose and escaped on the next run.
Re-running the gate keeps every row it can. A row the current review no longer reports is kept and its Source cell flagged, so a finding does not leave this record silently. ONE exception: when a finding id is REUSED by a different finding, the earlier decision cannot keep a row — the id is taken — and it is dropped. A RECORDED decision (anything but `open`) is named on the console when that happens; a row still at `open` is replaced silently, because `open` records no decision to lose.