Conversation
|
GhostDeps independent review - CHANGES REQUESTED at head The The other limits are stated accurately: synthetic adapter evidence is not real JS adapter coverage; local |
|
GhostDeps independent review - APPROVE the evidence inventory at head The Disposable merged worktree: core tests 487/487, build, ESLint, Prettier and diff check pass. Hosted Node 22/24 tests were still running at review time; this approves the scoped evidence only. Keep the draft gated and unmerged until its separate prerequisites are resolved. No activation or merge by me. |
Scope
Gated evidence inventory, not apply activation. Three granular commits add canonical npm v3 fixture directories, five executable core cases, and a pass/fail table in
docs/slice2-evidence-gate.md.The tests cover a read-only eligible leaf preview; stale source changing the finding key; a source mutation during static overlay causing refusal;
.npmrcrefusal preserving ordinary scans; and newly observed usage refusing a former preview on the same bytes. The synthetic adapter isolates core semantics rather than claiming real JS adapter or GitHub integration proof.Validation
pnpm --filter @ghostdeps/core test: 487 pass, 0 fail after rebasing onto mainpnpm exec eslint packages/core/src/engine/fix-evidence.test.tspnpm exec prettier --check packages/core/src/engine/fix-evidence.test.ts fixtures/fix-evidence/README.md docs/slice2-evidence-gate.mdGate result
Partial, not passed for user-facing comment/apply. Real adapter coverage, permission-decline scan-only integration, PR-head CAS, independent App/runner revalidation, M3 stability and ADR-0004 boundary review remain. Do not merge this draft as an activation claim; review the evidence and gaps first. Related: #389 and gated scaffold #405.
Fixture manifests (auto-triage rule 13007)
This PR adds new fixture manifests not yet covered by dependabot auto-triage rule 13007 (exact paths, no globs). Qa: please extend the rule with:
fixtures/fix-evidence/declined/package.jsonfixtures/fix-evidence/declined/package-lock.jsonfixtures/fix-evidence/eligible/package.jsonfixtures/fix-evidence/eligible/package-lock.jsonfixtures/fix-evidence/stale-source/package.jsonfixtures/fix-evidence/stale-source/package-lock.jsonfixtures/fix-evidence/usage-revalidated/package.jsonfixtures/fix-evidence/usage-revalidated/package-lock.json