Skip to content

fix(licence): rb56-work — clear scaffold-placeholder leak (superproject)#64

Merged
hyperpolymath merged 1 commit into
mainfrom
licence-debt/agg-placeholder
May 19, 2026
Merged

fix(licence): rb56-work — clear scaffold-placeholder leak (superproject)#64
hyperpolymath merged 1 commit into
mainfrom
licence-debt/agg-placeholder

Conversation

@hyperpolymath
Copy link
Copy Markdown
Owner

Owner-ruled in scope (aggregates not excluded). Superproject's OWN tracked files only — submodule contents (gitlinks) untouched. 9 files: PLMP/PMLP + doubled → PMPL-1.0-or-later (repo dominant). Built clean from origin/main via worktree (sidesteps dirty/ahead). SPDX-only, diff-shape asserted. 🤖 Generated with Claude Code

@hyperpolymath hyperpolymath force-pushed the licence-debt/agg-placeholder branch 2 times, most recently from a0ee865 to 96f1bd4 Compare May 19, 2026 07:57
Re-done cleanly after a shared-remote collision (rb56-work/.rb56-fix/
reposystem are 3 local checkouts of ONE repo). 9 superproject-own
files PLMP/PMLP+doubled -> PMPL-1.0-or-later. Licence-text excluded. Worktree-clean
from origin/main. SPDX-only, diff-shape asserted.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
@hyperpolymath hyperpolymath force-pushed the licence-debt/agg-placeholder branch from 96f1bd4 to 98f883d Compare May 19, 2026 08:01
@hyperpolymath hyperpolymath merged commit 6a9bf91 into main May 19, 2026
10 of 11 checks passed
@hyperpolymath hyperpolymath deleted the licence-debt/agg-placeholder branch May 19, 2026 08:02
@github-actions
Copy link
Copy Markdown

🔍 Hypatia Security Scan

Findings: 195 issues detected

Severity Count
🔴 Critical 14
🟠 High 112
🟡 Medium 69

⚠️ Action Required: Critical security issues found!

View findings
[
  {
    "reason": "Issue in quality.yml",
    "type": "missing_workflow",
    "file": "quality.yml",
    "action": "create",
    "rule_module": "workflow_audit",
    "severity": "high"
  },
  {
    "reason": "Issue in security-policy.yml",
    "type": "missing_workflow",
    "file": "security-policy.yml",
    "action": "create",
    "rule_module": "workflow_audit",
    "severity": "medium"
  },
  {
    "reason": "Action hyperpolymath/standards/.github/workflows/governance-reusable.yml@main needs attention",
    "type": "unpinned_action",
    "file": "governance.yml",
    "action": "pin_sha",
    "rule_module": "workflow_audit",
    "severity": "high"
  },
  {
    "reason": "TypeScript file detected -- banned language",
    "type": "banned_language_file",
    "file": "/home/runner/work/reposystem/reposystem/tools/rsr-certified/extensions/vscode/src/extension.ts",
    "action": "flag",
    "rule_module": "cicd_rules",
    "severity": "critical"
  },
  {
    "reason": "innerHTML assignment -- XSS risk, use textContent or SafeDOM (5 occurrences, CWE-79)",
    "type": "js_innerhtml",
    "file": "/home/runner/work/reposystem/reposystem/stateful-artefacts/browser-extension/scripts/popup.js",
    "action": "flag",
    "rule_module": "code_safety",
    "severity": "high"
  },
  {
    "reason": "innerHTML assignment -- XSS risk, use textContent or SafeDOM (1 occurrences, CWE-79)",
    "type": "js_innerhtml",
    "file": "/home/runner/work/reposystem/reposystem/stateful-artefacts/browser-extension/scripts/content.js",
    "action": "flag",
    "rule_module": "code_safety",
    "severity": "high"
  },
  {
    "reason": "innerHTML assignment -- XSS risk, use textContent or SafeDOM (4 occurrences, CWE-79)",
    "type": "js_innerhtml",
    "file": "/home/runner/work/reposystem/reposystem/stateful-artefacts/dashboard/js/dashboard.js",
    "action": "flag",
    "rule_module": "code_safety",
    "severity": "high"
  },
  {
    "reason": "innerHTML assignment -- XSS risk, use textContent or SafeDOM (5 occurrences, CWE-79)",
    "type": "js_innerhtml",
    "file": "/home/runner/work/reposystem/reposystem/stateful-artefacts/annotation-layer/annotations.js",
    "action": "flag",
    "rule_module": "code_safety",
    "severity": "high"
  },
  {
    "reason": "innerHTML assignment -- XSS risk, use textContent or SafeDOM (7 occurrences, CWE-79)",
    "type": "js_innerhtml",
    "file": "/home/runner/work/reposystem/reposystem/web/app.js",
    "action": "flag",
    "rule_module": "code_safety",
    "severity": "high"
  },
  {
    "reason": "HTTP URL in code -- use HTTPS for non-localhost (16 occurrences, CWE-319)",
    "type": "js_http_url_in_code",
    "file": "/home/runner/work/reposystem/reposystem/web/app.js",
    "action": "flag",
    "rule_module": "code_safety",
    "severity": "medium"
  }
]

Powered by Hypatia Neurosymbolic CI/CD Intelligence

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant