Repository navigation
docs: name the FreeAgent evidence artifacts without machine paths - #430
Merged
Merged
Conversation
The evidence baseline listed six absolute paths under a home directory on the author's machine. They dated from f3f7438 (#44) and served no reader: the FreeAgent run was local and its outputs were never published, so nobody cloning this repo could open any of them. All they carried was the operating system, the username, and the local directory layout of the machine that made the release. Replaced with the same six artifacts named relative to that workspace's .codecarto/, which is what the surrounding text actually needs - it is citing WHICH artifacts the conclusions rest on, not offering a link. R11 sweep - the class is "machine-specific absolute path in tracked content", swept across the whole tracked tree rather than this file: - /home/<user>/ - six instances, all here, all closed. Five other hits are synthetic test inputs (/home/someone, /home/me) and one is /home/james in tests/dashboard.test.mjs, which is the INPUT to a test asserting that an absolute session path is not rendered as a link. It is not this machine's home and changing it would weaken the test. - /Users/<user>/ and C:\Users\<user>\ - none. - bare username, hostname, private IPs - none. - credential-shaped strings - one hit, "sk-abc...1234", a deliberate fixture in a test proving a secret never reaches the provider. Scope of the original exposure: docs/ is not in package.json files[], so this never shipped in an npm tarball (verified with a real npm pack: zero docs/ entries). It has been in public git history since f3f7438 and remains there - this commit stops it being in the current tree, and rewriting history is a separate decision for the maintainer.
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Found while verifying that #429 left no machine paths behind.
What was there
docs/plans/post-0.11-evidence-roadmap.mdlisted six absolute paths under a home directory on my machine, dating fromf3f7438(#44):They served no reader. The FreeAgent run was local and its outputs were never published, so nobody cloning this repo could open any of them. All they carried was the OS, the username, and the local directory layout of the machine that cut the release.
Replaced with the same six artifacts named relative to that workspace's
.codecarto/— which is what the surrounding prose actually needs, since it cites which artifacts the conclusions rest on rather than offering a link.R11 sweep
Class: machine-specific absolute path in tracked content. Surface: the whole tracked tree, not just this file.
/home/<user>//Users/<user>/C:\Users\<user>\Five other
/home/hits are synthetic test inputs (/home/someone,/home/me). One is/home/jamesintests/dashboard.test.mjs— that is the input to a test asserting an absolute session path is not rendered as a link. It is not this machine's home, and changing it would weaken the test. The credential hit issk-abc...1234intests/broadside-verify.test.mjs, a fixture proving a secret never reaches the provider.Exposure scope
docs/is not inpackage.jsonfiles[], so this never shipped in an npm tarball — verified with a realnpm pack, zerodocs/entries.It has been in public git history since
f3f7438and stays there. This commit removes it from the current tree; rewriting history is a separate call and yours to make. Given it is a username and a directory layout rather than a credential, I would not force-push a public repo over it — but say the word if you want that done.