Skip to content

docs: name the FreeAgent evidence artifacts without machine paths - #430

Merged
TheAmericanMaker merged 1 commit into
mainfrom
docs/scrub-absolute-paths
Sep 21, 2026
Merged

TheAmericanMaker merged 1 commit into
mainfrom
docs/scrub-absolute-paths

Conversation

@TheAmericanMaker

Copy link
Copy Markdown
Member

Found while verifying that #429 left no machine paths behind.

What was there

docs/plans/post-0.11-evidence-roadmap.md listed six absolute paths under a home directory on my machine, dating from f3f7438 (#44):

/home/<user>/Documents/Github/FreeAgent/.codecarto/workflow/status.yaml
...

They served no reader. The FreeAgent run was local and its outputs were never published, so nobody cloning this repo could open any of them. All they carried was the OS, the username, and the local directory layout of the machine that cut the release.

Replaced with the same six artifacts named relative to that workspace's .codecarto/ — which is what the surrounding prose actually needs, since it cites which artifacts the conclusions rest on rather than offering a link.

R11 sweep

Class: machine-specific absolute path in tracked content. Surface: the whole tracked tree, not just this file.

pattern result
/home/<user>/ 6 instances, all here, all closed
/Users/<user>/ none
C:\Users\<user>\ none
bare username / hostname / private IPs none
credential-shaped strings 1, a deliberate fixture

Five other /home/ hits are synthetic test inputs (/home/someone, /home/me). One is /home/james in tests/dashboard.test.mjs — that is the input to a test asserting an absolute session path is not rendered as a link. It is not this machine's home, and changing it would weaken the test. The credential hit is sk-abc...1234 in tests/broadside-verify.test.mjs, a fixture proving a secret never reaches the provider.

Exposure scope

docs/ is not in package.json files[], so this never shipped in an npm tarball — verified with a real npm pack, zero docs/ entries.

It has been in public git history since f3f7438 and stays there. This commit removes it from the current tree; rewriting history is a separate call and yours to make. Given it is a username and a directory layout rather than a credential, I would not force-push a public repo over it — but say the word if you want that done.

The evidence baseline listed six absolute paths under a home directory on the
author's machine. They dated from f3f7438 (#44) and served no reader: the
FreeAgent run was local and its outputs were never published, so nobody
cloning this repo could open any of them. All they carried was the operating
system, the username, and the local directory layout of the machine that made
the release.

Replaced with the same six artifacts named relative to that workspace's
.codecarto/, which is what the surrounding text actually needs - it is citing
WHICH artifacts the conclusions rest on, not offering a link.

R11 sweep - the class is "machine-specific absolute path in tracked content",
swept across the whole tracked tree rather than this file:

- /home/<user>/ - six instances, all here, all closed. Five other hits are
  synthetic test inputs (/home/someone, /home/me) and one is /home/james in
  tests/dashboard.test.mjs, which is the INPUT to a test asserting that an
  absolute session path is not rendered as a link. It is not this machine's
  home and changing it would weaken the test.
- /Users/<user>/ and C:\Users\<user>\ - none.
- bare username, hostname, private IPs - none.
- credential-shaped strings - one hit, "sk-abc...1234", a deliberate fixture
  in a test proving a secret never reaches the provider.

Scope of the original exposure: docs/ is not in package.json files[], so this
never shipped in an npm tarball (verified with a real npm pack: zero docs/
entries). It has been in public git history since f3f7438 and remains there -
this commit stops it being in the current tree, and rewriting history is a
separate decision for the maintainer.
@TheAmericanMaker
TheAmericanMaker merged commit ae492f6 into main Sep 21, 2026
6 checks passed
@TheAmericanMaker
TheAmericanMaker deleted the docs/scrub-absolute-paths branch September 21, 2026 07:06
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant