feat(scanner): reject plugin deno publish and pod trunk push - #1189
Draft
seonghobae wants to merge 16 commits into
Draft
feat(scanner): reject plugin deno publish and pod trunk push#1189seonghobae wants to merge 16 commits into
seonghobae wants to merge 16 commits into
Conversation
Hook and manifest deno publish and pod trunk push must fail closed. deno info, pod install, pod lib lint, comments, echo lookalikes, assignment values, and README wording stay inventory. Relates to #1099.
Fail closed on executable deno publish and pod trunk push. deno info, pod install, and pod lib lint stay inventory. sbt publish stays the sbt class. Relates to #1099.
…9' into feat/claude-plugin-deno-pod-1099
|
Important Draft PR not reviewedDraft PRs are not automatically reviewed by default.
To automatically review draft PRs, update your CodeRabbit configuration: reviews:
auto_review:
drafts: trueThanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out. Comment |
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Successor of #1188 / issue #1099. Does not Close those. sbt/conan stay #1188. gradle/luarocks stay #1187. cabal/mvn stay #1186. Pass is not Noema admission.
Unique delta
Fail closed when a plugin hook or manifest runs remaining JSR and CocoaPods writes that #1188 left as inventory:
deno publishasclaude-plugin-deno-publish-command(CWE-269)pod trunk pushasclaude-plugin-pod-trunk-push-command(CWE-250)deno info,pod install, andpod lib lintstay inventorysbt publishstaysclaude-plugin-sbt-publish-command#comments,echo/printflookalikes, assignment values, and marketplace description prose are not this classcomposer publishandgo uploadare not invented; they are not real package-manager CLIs#1188 remains owner of sbt/conan publish.
Evidence
1b02a97then GREENc86ac8cthen non-force restack merge0ce7e13onto live feat(scanner): reject plugin sbt publish and conan upload #118863c42a7tests/test_claude_plugin_deno_pod.pyplus sibling sbt/gradle/cabal lockRelates to #1099. Relates to #1188.
Current quoted task repair — 2026-09-08
RED
e41648b4bd8e0dd82c7e69b0c8eb7ccc56efb9e4proves that executabledeno "publish"andpod trunk 'push'were missed by both admission and capability inventory. Production GREEN471a89fcd3c3e956f206e3bc4238ec8a4df5b2fdadds exact quoted-token admission without crossing line boundaries. Exact verification exposed that the inventory's shared terminal word boundary still rejected closing quotes; follow-up GREEN0616f328803d91122d93d1bb1792df04d5953223fixes that separate boundary without widening near-task names.Traceability head
c13142c6447877a65ad282a0ee482372b6efb7d9is the current exact candidate. Full source and test AST parse withSyntaxWarningdenied. Exact production-pattern probes pass Deno 5/5 positive and 4/4 negative, CocoaPods 4/4 positive and 5/5 negative, and capability inventory 4/4 positive and 4/4 negative.publishLocal-style near names,pod lib lint, cross-line token assembly, mismatched quotes, reporting/assignment prose, and closed here-document payloads remain outside these findings. This custom-base PR stays Draft until hosted integration, coverage, and independent current-head review exist; predecessor evidence does not transfer.Current quoted CLI and suffix repair — 2026-09-08
Quoted CLI-name RED
18be77f1271b2c4d3f9dc0e59608715eb410c5afand strengthened receipt/inventory REDc0124b7ce4be48b007d0e6700863d577cbc70158prove that"deno" publishand'pod' trunk pushbypassed admission and inventory. GREEN31ff8f492843f8d6d34dc1a6e8445d9904c35172→425a1d87ac365118958ff24e847a75e4e7509d29repairs paired CLI tokens. Suffix REDd8cacddaa798a37d1bf79c030f40452590e0fa25→ exact GREEN headf7964beb79be28ca7acc46971a2137830d1781carejects quoted near-task suffixes without losing exact quoted tasks. Source/test AST passes; exact helpers pass 10/10 and inventory passes 4/4 positive plus 4/4 negative. This PR stays Draft: no hosted workflow exists on the custom base, and canonical #1173 no-op repair plus the remaining argv/sh -cparser gaps are not yet integrated.