Repository navigation
fix(msdmd): never read own outputs; close consumer-review findings - #118
Conversation
Base: main 9867ab3. - collector excludes the configured output, sibling temp/candidate outputs, collector temp files, and a redirected stdout file, so differently-named runs produce identical collections (stack #78 blocker) - git-ignored local files are never read - aggregate retained-bytes budget (--max-total-bytes, default 256 MiB); bytes only retained for files a reader or marker applies to - missing native reader runtimes are errors (runtime-unavailable, exit 3) unless --allow-missing-reader-runtimes - schema-1 relative helper detected before writing (exit 4) - generator_identity()/--print-generator-identity covers Python, TS worker, package/lock, schema and requirements files - redaction: camel/PascalCase secret keys, systemd URL credentials and credential directives, SVG metadata, DSSE envelope payload - unnamed URL/VCS/path requirements stay hmmm instead of fabricated package names; backslash continuations joined - ratios semantic graph resolves schema-2 declaration addresses - regression tests: tests/test_msdmd_consumer_review.py - regenerated skill-lib_msdmd.ts
Codex Review SummaryThis comment shows the latest Codex review activity on this pull request.
ℹ️ About Codex in GitHubYour team has set up Codex to review pull requests in this repo. Reviews are triggered when you
Codex reacts with 👀 while any review is running, comments if it has suggestions, and reacts with 👍 once all reviews finish with no findings. |
py/clear-text-storage-sensitive-data flagged the dummy fixture dict named 'secrets' written into a temp repo. Rename only; behaviour unchanged. Regenerate skill-lib_msdmd.ts.
There was a problem hiding this comment.
💡 Codex Review
Here are some automated review suggestions for this pull request.
Reviewed commit: 034f0262db
ℹ️ About Codex in GitHub
Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you
- Open a pull request for review
- Mark a draft as ready
- Comment "@codex review".
If Codex has suggestions, it will comment; otherwise it will react with 👍.
Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".
| files = sorted( | ||
| path for path in base.rglob("*") | ||
| if path.is_file() | ||
| and not {"node_modules", "__pycache__", "references"} & set(path.relative_to(base).parts) | ||
| and (path.suffix in {".py", ".cjs", ".json"} or path.name == "requirements.txt") |
There was a problem hiding this comment.
Include the Python runtime in generator identity
When collection jobs run under different Python minor versions, read_python emits a different Python X.Y convention version and the AST grammar/output can also differ, but generator_identity() returns the same digest because it hashes only files below msdmd. A freshness controller can therefore reuse a receipt and skip regeneration even though the current generator would produce different bytes; include the effective Python/runtime identity in this digest or bind it separately in the freshness key.
AGENTS.md reference: AGENTS.md:L176-L179
Useful? React with 👍 / 👎.
| envelope = dict(value, payload={'$withheld': True, 'reason': 'decoded-statement-projected', 'pointer': '/payload'}) | ||
| envelope_fact = emit('dsse.envelope', 'v1', 'signed-envelope', '', envelope, scope='attestation', standing='reported-evidence') | ||
| envelope_fact['projection'] = {'mapping_version': 'dsse-envelope@1', 'supersedes': 'structured-document', | ||
| 'loss': 'raw base64 payload withheld; decoded statement published at /payload'} |
There was a problem hiding this comment.
Supersede the DSSE root only after projecting its payload
For a DSSE envelope whose payload decodes successfully but is not an in-toto Statement object—for example {"foo":"bar"}—this unconditional supersedes marker removes the generic structured-document fact, while the _type check below emits no decoded-payload fact. The result contains only a $withheld placeholder claiming the payload was projected, with neither the data nor an unsupported/invalid diagnostic; only supersede after a replacement fact is emitted, or preserve the redacted decoded payload as hmmm.
AGENTS.md reference: AGENTS.md:L124-L124
Useful? React with 👍 / 👎.
| def _is_sensitive_key(name: Any) -> bool: | ||
| """Match secret-bearing names in snake, kebab, camel and Pascal case.""" | ||
| text = str(name) | ||
| return bool(_SENSITIVE_KEY_RE.search(text) or _SENSITIVE_KEY_RE.search(_CAMEL_BOUNDARY_RE.sub("_", text))) |
There was a problem hiding this comment.
Preserve descriptive camel-case metadata fields
When a non-secret field contains a sensitive-looking component, such as passwordPolicyUrl, tokenEndpoint, privateKeyAlgorithm, or secretRotationPeriod, splitting camel case and applying the existing unanchored matcher classifies the entire value as secret. This newly erases legitimate schema and configuration metadata—the added test even places passwordPolicyUrl in the keep fixture without asserting it—so camel/Pascal matching should distinguish terminal secret-value names from descriptive fields.
Useful? React with 👍 / 👎.
| # Direct URL, VCS and local-path forms carry no leading distribution name. | ||
| _REQUIREMENT_DIRECT_RE = re.compile( | ||
| r"^(?:[A-Za-z][A-Za-z0-9+.-]*://|(?:git|hg|svn|bzr)\+|file:|\.{1,2}(?:/|\\|$)|/|~)", re.IGNORECASE) | ||
| _REQUIREMENT_ARCHIVE_RE = re.compile(r"\.(?:whl|zip|tar\.gz|tar\.bz2|tar\.xz|tgz|tar)(?:[#?]|$)", re.IGNORECASE) |
There was a problem hiding this comment.
Recognize Windows drive paths as unnamed requirements
When a requirements file contains an absolute Windows local path such as C:\src\pkg, this matcher does not recognize the drive-letter form, so the fallback name regex records package C and emits a false python-package:C dependency edge. Treat drive-letter paths as unnamed direct requirements, as is already done for ./, /, and ~ paths, so the distribution name remains hmmm rather than guessed.
AGENTS.md reference: AGENTS.md:L118-L124
Useful? React with 👍 / 👎.
| except (OSError, subprocess.CalledProcessError): | ||
| return None |
There was a problem hiding this comment.
Fail closed when Git visibility cannot be determined
In a Git checkout where the git executable is unavailable or git ls-files fails, this exception path returns None, which _discover() interprets as permission to scan every filesystem entry. Ignored local files such as private.json are then read and can be emitted even though the new contract says Git-ignored files are never read; distinguish a non-Git directory from a failed Git visibility check and abort or emit an error for the latter.
Useful? React with 👍 / 👎.
| def owners(key: str) -> set[str]: | ||
| # Exact address first; the short id is the legacy/unresolved fallback. | ||
| return address_files.get(key) or id_files.get(key, set()) |
There was a problem hiding this comment.
Keep ambiguous semantic edges unresolved
When a schema-2 edge targets an ID declared by multiple eligible files, the collector leaves the short target and marks it target_resolution: "ambiguous", but this fallback maps that ID to every owning file. Because the source address now resolves, semantic_file_graph() reports concrete edges to all candidates and increments resolved_edges instead of retaining the ambiguity; inspect target_resolution before applying the short-ID fallback.
AGENTS.md reference: AGENTS.md:L118-L124
Useful? React with 👍 / 👎.
| if candidate.is_file(): | ||
| text = candidate.read_text(encoding="utf-8", errors="replace") | ||
| missing = [name for name in names if not re.search(r"\bexport\b[^;]*\b" + re.escape(name) + r"\b", text)] | ||
| if missing: |
There was a problem hiding this comment.
Verify exports without spanning unrelated declarations
When the helper contains a semicolonless exported declaration followed by a non-exported function named defineMsdmdCollectionV2, this regex starts at the earlier export and scans across lines until a later semicolon, falsely treating the local function as exported. The CLI then writes a collection that imports a value the helper does not provide; use syntax-aware export detection or constrain the match to the actual declaration/export statement.
Useful? React with 👍 / 👎.
| if pending is not None: | ||
| records.append((start, line_number, pending)) |
There was a problem hiding this comment.
Reject unterminated requirement continuations
When a requirements file ends with a continuation backslash, this branch removes the backslash and emits the pending text as a normal dependency—for example, foo==1.0 \ becomes a supported foo==1.0 fact with no diagnostic. This can let malformed or truncated input satisfy required-source coverage; retain it as unresolved/invalid and report the unterminated continuation instead of silently completing it.
AGENTS.md reference: AGENTS.md:L124-L124
Useful? React with 👍 / 👎.
- requirements: comment lines never continue; trailing continuation at EOF is diagnosed; Windows paths (C:\x, D:/x) stay unnamed - git visibility fails closed: ls-files failure or broken .git marker reads nothing and errors; a root ignored by an enclosing repo is diagnosed and the snapshot marked incomplete - schema helper check compares exported MSDMD_COLLECTION_HELPER_VERSION (new in collection.ts) instead of a regex; 9867ab3-era helpers exit 4 - generator identity adds Python minor, reader package, Node and TypeScript versions; --print-generator-identity --json shows the components - DSSE: non-Statement payload diagnosed and kept as a decoded signed-payload fact; supersedes set only after a replacement fact exists - camelCase redaction only when the final word is sensitive; add authorization - ratios: ambiguous/unresolved short-id targets are not resolved edges - submodules: excluded ledger entry with pinned commit, in snapshot identity - CLI: exit-3 message names the real skill dir and the opt-out; exit 3 and 4 reported together; only a missing typescript package is a missing TS runtime (other worker exits are typescript_reader_failed); --out resolved for the helper check; budget overflow always warns; --max-*-bytes > 0 - rename detection reads both porcelain columns and both paths - docs: CHANGELOG, ORG_DISTRIBUTION, propagation checklist, runner guidance - tests: tests/test_msdmd_review_followup.py; regenerate skill-lib_msdmd.ts
There was a problem hiding this comment.
💡 Codex Review
Here are some automated review suggestions for this pull request.
Reviewed commit: a97d7fdbf8
ℹ️ About Codex in GitHub
Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you
- Open a pull request for review
- Mark a draft as ready
- Comment "@codex review".
If Codex has suggestions, it will comment; otherwise it will react with 👍.
Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".
| match = re.match(r"\s*([A-Za-z0-9][A-Za-z0-9._-]*)", line.split("#", 1)[0]) | ||
| if match: | ||
| try: | ||
| packages[match.group(1)] = metadata.version(match.group(1)) |
There was a problem hiding this comment.
Bind the actually imported reader code in generator identity
When PYTHONPATH, the working directory, or an editable installation supplies a different docstring_parser implementation under the same distribution version, metadata.version() does not identify the code that read_python() actually imports. Fresh evidence beyond the prior runtime-identity finding: two distinct docstring_parser.py modules selected through PYTHONPATH produced different documentation facts while generator_identity() returned the same digest, allowing a freshness controller to reuse an invalid receipt; isolate dependency resolution or hash the resolved module bytes.
AGENTS.md reference: AGENTS.md:L176-L179
Useful? React with 👍 / 👎.
| excluded_inodes = [] | ||
| if not args.out: |
There was a problem hiding this comment.
Exclude outputs in legacy collection mode
When --legacy-blocks-only writes to a noncanonical filename or stdout is redirected into the scanned tree, this output/inode exclusion setup is skipped because it exists only in the non-legacy branch. For example, rerunning legacy collection with --expected-block DOCS --out custom.ts --check reads the first generated custom.ts, adds it as a missing-block gap, and reports drift; pass the actual output and redirected inode exclusions through collect_legacy() as well.
AGENTS.md reference: AGENTS.md:L176-L179
Useful? React with 👍 / 👎.
… resolved reader module identity - git_visibility_unavailable / root_git_ignored now print an ERROR and exit 5 without writing (also in --legacy-blocks-only). --check reports 5, not drift 1; --strict cannot mask it as 2. Precedence 5, then 3, then 4; all reported together. - With --out outside the root (e.g. /tmp in CI), the schema helper is located from the root so the MSDMD_COLLECTION_HELPER_VERSION check (exit 4) runs. - Generator identity adds python_modules: digests of the files each reader package's import names resolve to via find_spec, so a shadowing module on PYTHONPATH changes the identity. - Tests: no git on PATH, ignored root (plain/--strict/--check), out-of-tree helper, shadowed docstring_parser. - Docs: exit 5 in SKILL.md, CHANGELOG, ORG_DISTRIBUTION.md, propagation-checklist, runner-config-guidance; regenerate skill-lib_msdmd.ts.
There was a problem hiding this comment.
💡 Codex Review
Here are some automated review suggestions for this pull request.
Reviewed commit: faf85c7584
ℹ️ About Codex in GitHub
Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you
- Open a pull request for review
- Mark a draft as ready
- Comment "@codex review".
If Codex has suggestions, it will comment; otherwise it will react with 👍.
Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".
| if args.out and not args.json: | ||
| problem, found = helper_incompatibility(args.out, args.import_path, rendered, args.root) |
There was a problem hiding this comment.
Check the helper for redirected TypeScript output
When schema-2 output is redirected from stdout rather than written with --out, this condition skips helper_incompatibility() even though the collector detects that stdout is a regular file. A consumer can therefore run python -m msdmd.collect ... > repo_msdmd.ts against a schema-1 or unversioned helper, receive exit 0, and persist an artifact whose import cannot type-check; apply the helper gate to redirected TypeScript output as well.
Useful? React with 👍 / 👎.
| for path, commit in sorted(submodules.items()): | ||
| # Submodule contents belong to another repository; record the pin, never read it. | ||
| ledger.append({"file": path, "entry_kind": "submodule", "status": "excluded", "reason": "git-submodule", | ||
| "reader_ids": [], "content_sha256": "hmmm", "commit": commit}) |
There was a problem hiding this comment.
Bind submodule pins into snapshot_sha256
When a gitlink is updated to a different submodule commit without changing other files, the discovery entry changes only in commit while retaining content_sha256: "hmmm"; the later snapshot_sha256 calculation hashes only file, content digest, and status, so it remains identical across the two source snapshots. Consumers using this advertised snapshot digest as an input identity can consequently reuse stale derived data; include the pinned commit in the snapshot digest, for example by using it as the submodule content identity.
AGENTS.md reference: AGENTS.md:L176-L179
Useful? React with 👍 / 👎.
| try: | ||
| probe = subprocess.run(["node", "-e", _NODE_PROBE], cwd=base, env=env, capture_output=True, text=True, check=False) | ||
| if probe.returncode == 0: | ||
| node = {key: str(value) for key, value in json.loads(probe.stdout).items()} |
There was a problem hiding this comment.
Hash the TypeScript implementation in generator identity
When the installed node_modules/typescript code is modified or replaced by different bytes carrying the same package version, this probe records the same Node and TypeScript version while source_sha256 explicitly excludes node_modules; the worker nevertheless loads those changed files and may emit different facts under the same generator digest. Fresh evidence beyond the earlier Python-module finding is that the effective TypeScript implementation remains unbound, so hash the resolved package bytes or bind a verified package-integrity digest.
AGENTS.md reference: AGENTS.md:L176-L179
Useful? React with 👍 / 👎.
| listed = run("ls-files", "-z", "--cached", "--others", "--exclude-standard") | ||
| staged = run("ls-files", "-z", "--stage") |
There was a problem hiding this comment.
Account for sparse index entries before declaring completeness
In a sparse checkout, git ls-files --cached returns skip-worktree entries that are absent from the filesystem, but _discover() only visits paths that exist and never reconciles the remaining visible_files; the omitted tracked files therefore receive no ledger entry or diagnostic, dirty_worktree remains false, and snapshot_complete is incorrectly true for an incomplete fact set at the recorded HEAD. The local git ls-files -h describes --cached as “show cached files in the output”; reconcile those index entries against discovery and mark absent sparse paths unresolved rather than silently dropping them.
AGENTS.md reference: AGENTS.md:L176-L179
Useful? React with 👍 / 👎.
Base:
mainat9867ab33877f2b1f50f8a501cf379aa99360bd52. One PR; Erin merges.This fixes the collector bug that blocks stack #78 and the Codex P1/P2 findings on the 9867ab3 msdmd/ratios code that Erin chose to fix. The findings come from the review comments on the stack #78 and batch-1 consumer sync PRs. Every fix has a regression test in
tests/test_msdmd_consumer_review.py(16 tests). All 16 fail on 9867ab3 and pass here.Stack #78 will be re-synced to the new main with a normal commit after this merges. That re-sync also needs to switch
backend/msdmd.pyto--print-generator-identityand install the native-reader runtimes (see finding 6 and 8).Findings, sources, fixes, tests
1. Collector reads its own output or temp files (stack #78 blocker)
.<outname>.*sibling temp and candidate outputs.msdmd-*temp files.*_msdmd.ts.*siblings<repo>_msdmd.tsis recorded as an output entry.git status --porcelain -z -- ., scoped to the collection root.OwnOutputTests):test_stack_candidate_then_verifier_flow_is_byte_identicalreproduces the candidate-then-verifier flow in stackbackend/msdmd.py. It writes two differently named outputs into the repo and checks they are byte-identical, then checks a fresh-status verify.test_configured_output_does_not_dirty_the_worktree_or_drifttest_stdout_redirect_into_the_scanned_tree_is_not_an_input2. Gaps in secret redaction
Environmentvalues and other directives.SetCredentialandSetCredentialEncryptedbecomeID:<redacted>._redact_sensitiveand emits a diagnostic.payload, which is projected from the decoded statement (dsse-envelope@1, supersedes the structured-document fact).RedactionTests):test_camel_and_pascal_case_secret_keys_are_redacted(JSON, YAML, TOML)test_systemd_url_credentials_and_credential_data_are_withheldtest_svg_metadata_is_redacted_with_a_diagnostictest_dsse_envelope_does_not_republish_the_raw_payload3. URL requirements turned into package names
hmmm, no dependency edge, and anunresolved_direct_requirement_namediagnostic. Namedpkg @ urlrequirements keep their name.RequirementTests):test_direct_url_vcs_and_path_requirements_stay_unresolvedtest_backslash_continuations_form_one_requirement4. Schema-2 addresses in the ratios semantic graph
semantic_file_graphindexes declarations by schema-2addressas well as id. Owner lookup tries the address first.RatiosSemanticGraphTests.test_schema_two_block_edges_resolve_to_owning_files5. Memory limit
--max-total-bytes, default 256 MiB.aggregate-size-limit, and anaggregate_size_limiterror diagnostic is emitted.DiscoveryMemoryTests.test_aggregate_byte_budget_is_enforced_and_diagnosed6. Generator fingerprint covered only
.pyfilesmsdmd.collect.generator_identity()and--print-generator-identity. The fingerprint hashes every.py,.cjsand.jsonfile undermsdmd/(TS reader,package.json,package-lock.json, schema) plusrequirements.txt. It excludesnode_modules,__pycache__andreferences/.backend/msdmd.pyhas to call this during the stack re-sync.GeneratorIdentityTests.test_identity_covers_typescript_worker_lock_and_assets_only7. Unusable output for repos that still carry the schema-1 helper
--import-pathhelper exports the names the rendered collection imports (e.g.defineMsdmdCollectionV2). Superseded by the follow-up below: the check now compares an exportedMSDMD_COLLECTION_HELPER_VERSION.--legacy-blocks-only.SchemaHelperTests.test_schema_one_helper_target_is_refused_without_writing(schema-1 helper is refused, legacy flag works, schema-2 helper works)8. Missing native-reader dependencies gave matching but incomplete output
missing_docstring_parser,typescript_reader_unavailableandreader_dependency_unavailableare nowerrorseverity, and the reader run status isruntime-unavailable(added tocollection.ts).--allow-missing-reader-runtimesis passed. With that flag it writes and still prints a loud WARNING.ReaderRuntimeTests):test_missing_runtime_is_an_error_and_marks_the_readertest_cli_fails_closed_unless_explicitly_allowed9. Git-ignored local files read into collections
git ls-files --cached --others --exclude-standard. This applies in both commit-bound and snapshot modes.GitIgnoredInputTests.test_ignored_local_files_are_never_readhmmm (not changed here)
token): fixing it needs schema-aware redaction, which is a design choice. The camelCase widening in finding 2 adds a few false positives (e.g.passwordHashis now redacted).--max-total-bytes.git ls-files.__all__, llms.txt root restriction, SPDX/JSON Schema/$refitems, TS re-exports and destructuring, visualize indirect helper, ratios named seals, and stack-onlyvm-mcpandtools/ai.sh.Gates (local, Node 24.15.0, Python 3.13)
--checkandtsc --strict: pass. A clean-clone--checkalso passes.--strict: pass--check: passskill-lib_msdmd.tsis regenerated. Consumer<repo>_msdmd.tsfiles stay as they are until each consumer is re-synced.The second commit (7498f42) renames a fixture dict in the redaction test. This clears a CodeQL
py/clear-text-storage-sensitive-datafalse positive on dummy test values, which I confirmed with a local CodeQL 2.27.1 run. It changes no behaviour, andskill-lib_msdmd.tsis regenerated.Follow-up commit a97d7fd: Review findings
Tests are in
tests/test_msdmd_review_followup.py(18 tests). 16 of them fail on 7498f42; the other 2 are controls. The redaction test intests/test_msdmd_consumer_review.pynow asserts the keep list.\at end of file is diagnosed asdangling_requirement_continuation.C:\xandD:/xstay unnamed.RequirementLineTests..gitmarker exists but git cannot list files (corrupt index, broken gitdir), nothing is read. The collector emits agit_visibility_unavailableerror and marks the snapshot incomplete. Tests:GitVisibilityTests.test_ls_files_failure_*andtest_broken_git_marker_*.git check-ignore -q .detects a root that an enclosing repo ignores. It emits aroot_git_ignorederror and marks the snapshot incomplete. Tracked files are still read. Test:test_root_inside_an_ignored_directory_*.collection.tsnow exportsMSDMD_COLLECTION_HELPER_VERSION = 1, and the collector requires it to be at leastREQUIRED_HELPER_VERSION.tscwith TS2322 onruntime-unavailable.defineMsdmdCollection.SchemaHelperVersionTests.generator_identity()now also covers the Python minor version, the installed version of each pinned reader package, and the Node and TypeScript versions the worker resolves. A missing one is recorded asabsent.--print-generator-identity --jsonshows the components.GeneratorIdentityRuntimeTests.dsse_payload_not_in_toto_statementdiagnostic and is kept as a decoded, redactedsigned-payloadfact.supersedesis set only after the replacement fact is emitted.DsseSupersessionTests.CHANGELOG.md.ORG_DISTRIBUTION.md,docs/propagation-checklist.mdanddocs/runner-config-guidance.mdnow cover runtime installation, exit codes 3 and 4, and their opt-outs.--legacy-blocks-only.tokenUrl,passwordPolicyUrl,passwordHash,apiKeyPrefix,accessKeyId,tokenCount,tokenType,secretNameandprivateKeyPathare kept.authorizationwas added.CamelRedactionFinalTokenTestsand the updatedRedactionTests.target_resolutionofambiguousorexternal-or-unresolvedare listed as unresolved and never added to adjacency. Test:AmbiguousSemanticEdgeTests.excludedledger entry (entry_kind: submodule,reason: git-submodule,commit). Its contents are never read.SubmoduleLedgerTests.Cannot find module 'typescript'counts astypescript_reader_unavailable. Other worker exits aretypescript_reader_failederrors, and stderr is not published.--outis resolved before the helper check.test_runtime_and_helper_problems_are_reported_together,TypeScriptWorkerFailureTests, and the relative--outcase.--max-total-bytesand--max-file-bytesmust be positive (argparse). Test:BudgetVisibilityTests.RenameDetectionTests.Follow-up 2 (faf85c7): exit 5, out-of-tree helper, resolved reader modules
git_visibility_unavailableandroot_git_ignorednow printmsdmd: ERROR: <code>: …and exit 5 without writing.--legacy-blocks-only.--checkreturns 5, not drift 1, and--strictcannot mask it as 2.VisibilityExitTests(no git on PATH; ignored root under plain,--strictand--check).--out(11d): when--outis outside--root(for example/tmpin edcm/ptcna CI), the--import-pathhelper is located from the root. TheMSDMD_COLLECTION_HELPER_VERSIONcheck (exit 4) now runs there. Test:OutOfTreeHelperTests.python_modulescomponent holds a sha256 of the files each reader package's import names resolve to throughimportlib.util.find_spec(nothing is imported). A shadowingdocstring_parseron PYTHONPATH now changes the identity even though the metadata versions do not. Test:ShadowedReaderModuleTests.skill-lib_msdmd.tswas regenerated.Known follow-ups (not in this PR)
--legacy-blocks-onlywith a custom--outcan read its own previous output. This is pre-existing.password_hash(snake_case, redacted) andpasswordHash(camelCase, kept) is not yet reconciled.Gates for faf85c7 (Node 24.15.0, Python 3.13): 418 tests OK; collect
--check, tsc, gonol, drift, compliance, Codex adapters, ratios strict, llms, LOTO and bytecode all pass.Earlier gates (a97d7fd, Node 24.15.0, Python 3.13): 414 tests OK, collect
--check, tsc, gonol, drift, compliance, Codex adapters, ratios strict, llms, LOTO and bytecode all pass. A local CodeQL 2.27.1 python-code-scanning suite reports 0 alerts.On Node 20.20.2, collect
--checkand tsc pass. The pre-existingtest_universal_parser.test_typescript_numeric_field_contractfails because it imports a.tsfile directly, which Node 20 cannot do.