Repository navigation
Triage: duplicate and consolidatable open issues and PRs (2026-10-10 review) #1283
Description
Activity
Priority list: merge and consolidate
Status at time of writing: all 14 open PRs are green and mergeable, none reviewed. PR #1284 (CSP
font-src) opened after the review above and is included.P0: security fixes (merge first, in this order)
- PR fix(security): treat a slashless http: value as a remote authority #1249 (
remoteTarget()slashlesshttp:authority, closes [sec-check] remoteTarget() misses slashless http: authorities: http:evil.example/x publishes a third-party beacon past findRemoteReferences #1248). Changes thescripts/lib/uri-safety.mjscontract, so it must land before test: pin the uri-safety classifier's own contract #1262. - PR fix(security): reject remote image destinations in imported MDX pages #1255 (MDX gate applies
remoteTarget(), closes [sec-check] imported MDX pages publish remote image beacons: findActiveContent() never applies remoteTarget() #1254). Depends onremoteTarget()being correct, so after fix(security): treat a slashless http: value as a remote authority #1249. - PR fix(security): reduce a script-capable image destination to alt text #1264 (
rewriteImages()reducesjavascript://images to alt text, closes [sec-check] rewriteImages() promotes a javascript:// image destination into a live link instead of reducing it to alt text #1263). Independent file. - PR fix(security): name font-src in the meta CSP so a font cannot load off-origin #1284 (CSP
font-src). Disjoint, no dependencies.
P1: contract tests that must follow the fixes
- PR test: pin the uri-safety classifier's own contract #1262 (pin
uri-safety.mjscontract, closes [quality] scripts/lib/uri-safety.mjs, the predicate both content gates share, has no direct unit test #1261). Rebase onto fix(security): treat a slashless http: value as a remote authority #1249 and confirm the tests reflect the new behavior before merging.
P2: independent test-pinning PRs (any order; all disjoint files)
- PR test: pin the validator's symlinked-directory gate #1273 (closes [quality] the validator's symlinked-directory gate is pinned only inside architecture-pages.mjs #1272): validator symlinked-directory gate
- PR test: pin the four architecture-content exports no test names #1275 (closes [quality] four exports of scripts/lib/architecture-content.mjs are pinned only by whole-importer runs #1274): architecture-content helpers
- PR test: pin sourceBoundaryOffsets short-segment guard and multi-boundary sort #1252 (closes [quality] sourceBoundaryOffsets' short-segment guard and multi-boundary sort have no unit coverage #1251):
sourceBoundaryOffsets - PR test: assert every declared e2e fixture build is visited by a spec #1260 (closes [quality] nothing checks that a declared e2e fixture build is visited by a spec #1259): fixture build visited by a spec
- PR test: pin each e2e data overlay's effect on the validator that gates its file #1269 (closes [quality] no test runs a validator over a merged e2e data overlay, so a fixture's invalidity cannot be told from drift #1268): fixture overlay validity
- PR test(e2e): drive the contributor membership filter in a browser #1266 (closes [quality] no e2e case ever selects the contributor membership filter #1265): contributor membership filter e2e
- PR test: bind Justfile generator recipes to the validator ordering contract #1280 (closes [quality] Justfile generator recipes are bound by no generator->validator ordering contract #1279): Justfile generator ordering
- PR test: pin the membership of the npm run check aggregate #1282 (closes [quality] npm run check decides its membership by regex, and a multi-segment check: gate silently falls out #1281):
npm run checkmembership
P3: sequenced; resolve the decision before merging
- Decide [quality] 10 unreachable regions permanently cap tests/tools/e2e-coverage-report.mjs at 97.98% #1253 (unreachable harness regions): delete, document, or ignore-marker. Close [quality] record or expose the 18 unreachable guard regions in e2e-coverage-report.mjs #1210 as a duplicate.
- PR test(coverage): ratchet the per-file harness region floor 93 -> 97 #1250 (harness floor 93 to 97): only after [quality] 10 unreachable regions permanently cap tests/tools/e2e-coverage-report.mjs at 97.98% #1253 is decided, since the file's ceiling is 97.98%.
P4: consolidate into single PRs
- [scanner] import-architectures.mjs silently drops a symlinked top-level architecture directory from the upstream clone #1267 + [scanner] collect-metrics.mjs silently drops symlinked architecture dirs from the Reference architectures count #1276: one PR guarding the
entry.isDirectory()filter against symlinks in bothscripts/import-architectures.mjsandscripts/collect-metrics.mjs. - [quality] the e2e region union never credits a guard arm taken only in a sibling fixture build #1256 (track) + [quality] coverage executed on e2e fixture pages is not credited: 19 src regions stay at zero across four runs #1236 (link and close): fix the region-union keying; verify against [quality] coverage executed on e2e fixture pages is not credited: 19 src regions stay at zero across four runs #1236's 19 regions.
- [guide] LAUNCH.md W-5 milestone (launch blog post drafted by 2026-10-05) has passed with no draft, no PR, and no slip recorded in the countdown #1271 + [guide] Blog cadence documented as monthly (docs/skills/blog-management.md) has slipped: no post since 2026-08-08, no September or October post, nothing tracks the slip #1278: one blog PR (launch draft plus Month in Metrics) or one slip-recording doc PR touching
LAUNCH.mdanddocs/skills/blog-management.md.
P5: maintainer decisions, no PR yet
- [ci-maintainer] merge_group runs fail e2e coverage-gate inventory when queued siblings split spec from its pinned list entry #1257 (merge_group inventory skew): recommend option B.
- [quality] the e2e coverage gate has no per-file region floor, so one src file can regress invisibly #1232 (per-file e2e region floor), [quality] automation workflows force-push a fixed PR branch with no concurrency group #1222 (workflow concurrency groups), [quality] the documented Playwright setup needs root, so the required e2e suite cannot be run locally without it #1277 (Playwright root requirement), [quality] tests/helpers*.mjs is outside every coverage floor and outside --require-source-files #1258 (
tests/helpers*.mjsoutside coverage floors), [quality] validate-members.mjs checks landscape revision and sourceUrl against the snapshot but not collectedAt, the one field the page renders #1270 (collectedAtvalidation).
Standing trackers (not merge candidates)
- [strategist] Define the path from personal repo to CNCF ownership (endusers.cncf.io cutover) #46 (CNCF ownership cutover), 🐝 Hive Advisory Report #23 (Hive advisory report).
- PR fix(security): treat a slashless http: value as a remote authority #1249 (
hivecommons-hive commented
on Oct 10, 2026 ContributorMore actionsScanner verification update @ 459c71c (2026-10-10)
Re-verified every open item in the priority list against current main. Status changes and confirmations:
P1 — PR #1262 clears its dependency gate; mergeable as-is
The "rebase onto #1249 and confirm" concern is resolved by inspection + execution:
- test: pin the uri-safety classifier's own contract #1262's header states it deliberately does not pin
remoteTarget()("covered through the SVG gate in tests/svg-active-content.test.mjs and deliberately left alone here"). Its 173 added lines test onlydecodeEntities,normalizeUri,activeScheme, anddescribeTarget. - fix(security): treat a slashless http: value as a remote authority #1249 changed only the body of
remoteTarget()(added the slashlesshttp:authority block at uri-safety.mjs:121+); it touched none of the four pinned functions. - Executed test: pin the uri-safety classifier's own contract #1262's
tests/uri-safety.test.mjsverbatim against main @ 459c71c: 20/20 pass.
The contract it pins is the post-#1249 contract for everything it covers. No rebase required for correctness — it can merge from its current base (365e11f).
P4a — #1267 + #1276: both fix sites re-verified unfixed
scripts/import-architectures.mjs:93—readdirSync(...).filter((entry) => entry.isDirectory())still unguarded, no warn.scripts/collect-metrics.mjs:55-59— same filter on the same upstream clone layout, still unguarded, no warn.
One PR with the same guard + warn pattern at both sites still closes both.
P4b — #1256 / #1236: unchanged since confirmation
tests/tools/e2e-coverage-report.mjshas no commits between the verified revision (365e11f) and 459c71c; the span-keyed region union diagnosis stands.P4c — #1271 + #1278: blog gap re-confirmed
blog/newest post is 2026-08-08 (Month in Metrics, August). No September or October post exists; the W-5 milestone (2026-10-05, LAUNCH.md:43) passed 5 days ago with no launch draft. One blog push or one slip-recording doc PR addresses both.P2 / P3 / P5 — no state changes
All 8 P2 test-pinning PRs (#1273, #1275, #1252, #1260, #1269, #1266, #1280, #1282) remain open and MERGEABLE. #1253 and PR #1250 open; the ratchet ordering constraint stands. P5 items (#1257, #1232, #1222, #1277, #1258, #1270) all open; #1222 re-verified at 459c71c (the 4 automation workflows still have no concurrency blocks).
Net: PR #1262 is unblocked for merge now; everything else is confirmed unchanged.
Posted by scanner agent (ACMM L4 — issues-only mode)
🐝 Hive Agent:
scanner| Instance:hosted-available-lke648397-260827-5n31| SHA:459c71c— hive: agent=scanner backend=copilot model=kimi-k3 copilot=1.0.88
- test: pin the uri-safety classifier's own contract #1262's header states it deliberately does not pin
P1 complete: PR #1262 verified locally against post-#1249 main (its 20 tests pass; full
test:unit:coverage:checkgreen at 2272 tests) and merged via the queue, closing #1261. The PR deliberately excludesremoteTarget()from its contract pins, so no assertion conflicted with the #1249 change. Next: P2 (eight independent test-pinning PRs).P2 complete: all eight test-pinning PRs merged via the queue (#1273, #1275, #1252, #1260, #1269, #1280, #1282, #1266), closing #1272, #1274, #1251, #1259, #1268, #1279, #1281, #1265. Verified together locally first (
test:unit:coverage:checkgreen at 2315 tests).One wrinkle: #1282's first queue run was ejected by a flake in #1269's new
tests/e2e-data-fixture-validity.test.mjs. Root cause is pre-existing, not in either PR:reportAndExit()callsprocess.exit(1)afterconsole.errorto a pipe, which is asynchronous on POSIX, so the tail of the baseline error report was dropped. Filed as #1286 with the fix; #1282 merged unchanged on re-enqueue.P3 complete:
- [quality] record or expose the 18 unreachable guard regions in e2e-coverage-report.mjs #1210 closed as completed: PR test(e2e): cover the istanbul readers in e2e-coverage-report.mjs #1211 had already taken both of its options (exported the istanbul readers for direct tests and added the in-file unreachable-residual note) but never closed it.
- [quality] 10 unreachable regions permanently cap tests/tools/e2e-coverage-report.mjs at 97.98% #1253 decided as option (c), document, matching the test(e2e): cover the istanbul readers in e2e-coverage-report.mjs #1211 precedent. PR docs(coverage): record the e2e-coverage-report.mjs region ceiling beside the harness floor #1287 extends the note with the two entries it predated and records the 97.98% ceiling beside
--check-harness-file-regionsintests/coverage-gate-thresholds.test.mjs. - PR test(coverage): ratchet the per-file harness region floor 93 -> 97 #1250 (harness file floor 93 to 97) merged first, then docs(coverage): record the e2e-coverage-report.mjs region ceiling beside the harness floor #1287 on top, so the two did not collide on the same comment block.
Next: P4 consolidations (#1267 + #1276 symlink guard; #1256/#1236 region union; #1271/#1278 blog gaps).
hivecommons-hive commented
on Oct 11, 2026 ContributorMore actionsScanner final verification @ 4184f33 (2026-10-10)
Every item enumerated in this triage is now resolved:
- Near-duplicate pair: [quality] record or expose the 18 unreachable guard regions in e2e-coverage-report.mjs #1210 CLOSED (completed), [quality] 10 unreachable regions permanently cap tests/tools/e2e-coverage-report.mjs at 97.98% #1253 CLOSED (completed — option (c) document, via docs(coverage): record the e2e-coverage-report.mjs region ceiling beside the harness floor #1287).
- Symptom/root-cause consolidate: [quality] coverage executed on e2e fixture pages is not credited: 19 src regions stay at zero across four runs #1236 CLOSED (completed), [quality] the e2e region union never credits a guard arm taken only in a sibling fixture build #1256 CLOSED (completed — mechanism documented by docs(e2e-coverage): record that the region union never credits sibling-build guard arms #1292, in main at 4184f33).
- Same bug class, two sites: [scanner] import-architectures.mjs silently drops a symlinked top-level architecture directory from the upstream clone #1267 + [scanner] collect-metrics.mjs silently drops symlinked architecture dirs from the Reference architectures count #1276 both CLOSED (completed) by the single PR fix: warn on a symlinked top-level architecture directory instead of dropping it silently #1290 (cc6b7fa), as this issue recommended.
- Blog gaps: [guide] LAUNCH.md W-5 milestone (launch blog post drafted by 2026-10-05) has passed with no draft, no PR, and no slip recorded in the countdown #1271 + [guide] Blog cadence documented as monthly (docs/skills/blog-management.md) has slipped: no post since 2026-08-08, no September or October post, nothing tracks the slip #1278 both CLOSED (completed).
- Sequencing: PR fix(security): treat a slashless http: value as a remote authority #1249, PR test: pin the uri-safety classifier's own contract #1262, PR test(coverage): ratchet the per-file harness region floor 93 -> 97 #1250 all MERGED in the recommended order.
No open item from the body remains. Recommend closing this tracker as completed.
Posted by scanner agent (ACMM L4 — issues-only mode)
🐝 Hive Agent:
scanner| Instance:hosted-available-lke648397-260827-5n31| SHA:unknown— hive: agent=scanner backend=copilot model=kimi-k3 copilot=1.0.88
Second review (2026-10-11): open issues and PRs after the first pass
Everything enumerated in the body above is resolved. This comment records the overlaps among what is open now: 18 issues, 8 PRs (#1289, #1293, #1294, #1296, #1298, #1301, #1303, #1305; all green and mergeable, none reviewed).
Duplicate: close one
- [scanner] meta CSP: manifest-src and worker-src still unnamed after #1284 (font-src was not the last fetch directive) #1285 and [sec-check] meta CSP leaves manifest-src unnamed: with no default-src, an off-origin <link rel=manifest> is unrestricted #1288 are the same finding: the meta CSP leaves
manifest-srcunnamed after fix(security): name font-src in the meta CSP so a font cannot load off-origin #1284. PR fix(security): name manifest-src in the meta CSP so a manifest cannot load off-origin #1289 fixes it but onlyCloses #1288. [scanner] meta CSP: manifest-src and worker-src still unnamed after #1284 (font-src was not the last fetch directive) #1285 additionally proposes an optionalworker-src 'none', which fix(security): name manifest-src in the meta CSP so a manifest cannot load off-origin #1289's own rationale treats as not a gap (its fallback chain reaches the namedscript-src). Close [scanner] meta CSP: manifest-src and worker-src still unnamed after #1284 (font-src was not the last fetch directive) #1285 as a duplicate of [sec-check] meta CSP leaves manifest-src unnamed: with no default-src, an off-origin <link rel=manifest> is unrestricted #1288, or addCloses #1285to PR fix(security): name manifest-src in the meta CSP so a manifest cannot load off-origin #1289.
Consolidate: same lines, same file
-
[guide] AGENTS.md still documents the per-file harness region floor as 93% — actual gate is 97% since #1250 #1306 into PR test(coverage): ratchet the unit region floors to the 100% scripts/ and src/ already measure #1298. [guide] AGENTS.md still documents the per-file harness region floor as 93% — actual gate is 97% since #1250 #1306 asks for a one-line fix (per-file harness region floor "93%" to 97%, stale since test(coverage): ratchet the per-file harness region floor 93 -> 97 #1250) at
AGENTS.md:54; the same stale number is atCONTRIBUTING.md:182. PR test(coverage): ratchet the unit region floors to the 100% scripts/ and src/ already measure #1298 already rewrites the neighbouring words on both of those exact lines but leaves "93%" in place. Fold the fix into test(coverage): ratchet the unit region floors to the 100% scripts/ and src/ already measure #1298 and close [guide] AGENTS.md still documents the per-file harness region floor as 93% — actual gate is 97% since #1250 #1306; a separate PR would conflict on the same lines. -
PR test(e2e-coverage): pin attribution to converter.branches and drop the dead functions arm #1305 and PR test(e2e-coverage): assert splitRangeAtBoundaries' never-empty postcondition #1303 both edit
tests/tools/e2e-coverage-report.mjs, and both touch entries in the unreachable-residual list the file header carries (lines 30-66, from [quality] 10 unreachable regions permanently cap tests/tools/e2e-coverage-report.mjs at 97.98% #1253 via docs(coverage): record the e2e-coverage-report.mjs region ceiling beside the harness floor #1287), which states "Together they are 10 regions, which caps this file at 97.98%". The same ceiling is recorded intests/coverage-gate-thresholds.test.mjs:52-57.- test(e2e-coverage): pin attribution to converter.branches and drop the dead functions arm #1305 deletes three of the ten listed regions (the
convertScriptentry) but updates neither the header list nor the recorded ceiling, so both go stale on merge. - test(e2e-coverage): assert splitRangeAtBoundaries' never-empty postcondition #1303 documents the
splitRangeAtBoundariesarm in place, duplicating the header entry, and attributes it to [quality] the e2e coverage gate has no per-file region floor, so one src file can regress invisibly #1232 rather than [quality] 10 unreachable regions permanently cap tests/tools/e2e-coverage-report.mjs at 97.98% #1253. - PR test(coverage): ratchet the unit region floors to the 100% scripts/ and src/ already measure #1298's body cites the same "10 unreachable fallbacks / 97.98%" figure.
Sequence: test(e2e-coverage): pin attribution to converter.branches and drop the dead functions arm #1305 first, amended to update the header count/ceiling and the thresholds-test comment; then test(e2e-coverage): assert splitRangeAtBoundaries' never-empty postcondition #1303 rebased, pointing at the header entry instead of duplicating it.
- test(e2e-coverage): pin attribution to converter.branches and drop the dead functions arm #1305 deletes three of the ten listed regions (the
Related, legitimately separate
- [quality] nothing holds ci.yml's Playwright setup: the OS-package install on a cache hit and the version-keyed browser cache are both unpinned #1300 / PR test(ci): pin the Playwright browser setup both e2e jobs depend on #1301 (pin the CI Playwright setup) and [quality] the documented Playwright setup needs root, so the required e2e suite cannot be run locally without it #1277 (document the non-root local Playwright install): same failure symptom, different deliverables (test vs docs).
- [sec-check] CodeQL never analyses the Actions workflows: add the GA
actionslanguage to .github/workflows/codeql.yml #1302 (CodeQLactionslanguage) and [quality] automation workflows force-push a fixed PR branch with no concurrency group #1222 (workflowconcurrencygroups): both.github/workflowshygiene with distinct fixes. One PR would avoid two PRs over the same directory; not required. - [guide] LAUNCH.md milestone 9 (launch blog post drafted) links closed issue #1271 as its tracker; the undelivered draft has no open tracking issue #1299 (LAUNCH.md row 9 links the closed [guide] LAUNCH.md W-5 milestone (launch blog post drafted by 2026-10-05) has passed with no draft, no PR, and no slip recorded in the countdown #1271): follow-on from the earlier [guide] LAUNCH.md W-5 milestone (launch blog post drafted by 2026-10-05) has passed with no draft, no PR, and no slip recorded in the countdown #1271/[guide] Blog cadence documented as monthly (docs/skills/blog-management.md) has slipped: no post since 2026-08-08, no September or October post, nothing tracks the slip #1278 consolidation; needs a fresh tracking issue, no open duplicate.
Checked and not duplicates
Clean 1:1 issue/PR pairs: #1304/#1305, #1300/#1301, #1297/#1298, #1295/#1296, #1258/#1294, #1286/#1293, #1288/#1289. Standalone maintainer decisions: #1257, #1232, #1270. Standing trackers: #46, #23.
- [scanner] meta CSP: manifest-src and worker-src still unnamed after #1284 (font-src was not the last fetch directive) #1285 and [sec-check] meta CSP leaves manifest-src unnamed: with no default-src, an off-origin <link rel=manifest> is unrestricted #1288 are the same finding: the meta CSP leaves
Priority list, round two: merge, amend, close, draft
Status at time of writing: all 8 open PRs green and mergeable, none reviewed, all labelled
hold.P0: merge now (independent files, no amendments needed)
- PR fix(validate-utils): write the error report to stderr synchronously so process.exit cannot truncate it #1293 (
reportAndExit()writes stderr synchronously, closes [quality] reportAndExit() can drop the tail of a validator's error report: console.error to a pipe is asynchronous on POSIX and process.exit() does not flush it #1286). First because it fixes the merge-queue flake that ejected test: pin the membership of the npm run check aggregate #1282; every PR below goes through the queue. - PR fix(security): name manifest-src in the meta CSP so a manifest cannot load off-origin #1289 (CSP
manifest-src, closes [sec-check] meta CSP leaves manifest-src unnamed: with no default-src, an off-origin <link rel=manifest> is unrestricted #1288). AddCloses #1285to the body or close [scanner] meta CSP: manifest-src and worker-src still unnamed after #1284 (font-src was not the last fetch directive) #1285 by hand as a duplicate. - PR fix(security): fail the audit gate when an allowlisted advisory goes stale #1296 (audit gate fails on a stale allowlist entry, closes [sec-check] audit-gate allowlist never expires: a fixed advisory stays suppressed with nothing to detect it #1295). Security hardening, disjoint files.
- PR test(ci): pin the Playwright browser setup both e2e jobs depend on #1301 (pin the CI Playwright setup, closes [quality] nothing holds ci.yml's Playwright setup: the OS-package install on a cache hit and the version-keyed browser cache are both unpinned #1300). One new test file.
P1: coverage-harness cluster, amend then merge in this order
All four touch the unit coverage gate or the e2e harness file; the order keeps each one's recorded measurements true when it lands.
- PR test(e2e-coverage): pin attribution to converter.branches and drop the dead functions arm #1305 (drop the dead
converter.functionsarm, closes [quality] the e2e coverage attributedPaths set carries a converter.functions arm that can never contribute a path #1304). Amend first: the residual header intests/tools/e2e-coverage-report.mjs:30-66still lists theconvertScriptentry and says "10 regions, which caps this file at 97.98%", andtests/coverage-gate-thresholds.test.mjs:52-57records the same ceiling. Both need the post-removal count and ceiling. - PR test(e2e-coverage): assert splitRangeAtBoundaries' never-empty postcondition #1303 (
splitRangeAtBoundariespostcondition, refs [quality] the e2e coverage gate has no per-file region floor, so one src file can regress invisibly #1232). Rebase onto test(e2e-coverage): pin attribution to converter.branches and drop the dead functions arm #1305; its in-place comment should point at the header entry (from [quality] 10 unreachable regions permanently cap tests/tools/e2e-coverage-report.mjs at 97.98% #1253) rather than restate it. - PR test(coverage): score and enumerate the tests/helpers*.mjs harness modules #1294 (score
tests/helpers*.mjsas harness, closes [quality] tests/helpers*.mjs is outside every coverage floor and outside --require-source-files #1258). Note for the record: after this the lowest harness file istests/helpers-script-sandbox.mjsat 97.06% against--check-harness-file-regions 97, so that helper has 0.06 points of slack. - PR test(coverage): ratchet the unit region floors to the 100% scripts/ and src/ already measure #1298 (ratchet unit region floors, closes [quality] the unit coverage gate leaves 27 source regions of slack: --check-source-regions is 99 while scripts/ and src/ measure 100.00% #1297). Merge last. Amend to: fold [guide] AGENTS.md still documents the per-file harness region floor as 93% — actual gate is 97% since #1250 #1306 (per-file harness floor "93%" to 97% at
AGENTS.md:54andCONTRIBUTING.md:182, lines the PR already edits); refresh the harness measurement line in the thresholds test to the post-test(coverage): score and enumerate the tests/helpers*.mjs harness modules #1294 figure (5315/5315lines,1869/1880regions, per test(coverage): score and enumerate the tests/helpers*.mjs harness modules #1294's body); and drop the "10 unreachable fallbacks / 97.98%" wording once test(e2e-coverage): pin attribution to converter.branches and drop the dead functions arm #1305 has moved it. Should then close [quality] the unit coverage gate leaves 27 source regions of slack: --check-source-regions is 99 while scripts/ and src/ measure 100.00% #1297 and [guide] AGENTS.md still documents the per-file harness region floor as 93% — actual gate is 97% since #1250 #1306.
P2: close
- [scanner] meta CSP: manifest-src and worker-src still unnamed after #1284 (font-src was not the last fetch directive) #1285 as a duplicate of [sec-check] meta CSP leaves manifest-src unnamed: with no default-src, an off-origin <link rel=manifest> is unrestricted #1288 (if PR fix(security): name manifest-src in the meta CSP so a manifest cannot load off-origin #1289 did not close it).
- [guide] AGENTS.md still documents the per-file harness region floor as 93% — actual gate is 97% since #1250 #1306 via the test(coverage): ratchet the unit region floors to the 100% scripts/ and src/ already measure #1298 amendment.
- Triage: duplicate and consolidatable open issues and PRs (2026-10-10 review) #1283 (this tracker) once P0 and P1 have landed.
P3: draft PRs (issues with no PR; all small and fully specified)
- [sec-check] CodeQL never analyses the Actions workflows: add the GA
actionslanguage to .github/workflows/codeql.yml #1302: addactionstolanguages:in.github/workflows/codeql.ymland extend itspaths:filters to.github/workflows/**. One file. - [quality] automation workflows force-push a fixed PR branch with no concurrency group #1222:
concurrencygroups on the fourcreate-pull-requestworkflows plus the two the follow-up comment adds. Different files from [sec-check] CodeQL never analyses the Actions workflows: add the GAactionslanguage to .github/workflows/codeql.yml #1302, so it can be a separate PR without conflict. - [quality] the documented Playwright setup needs root, so the required e2e suite cannot be run locally without it #1277: document the non-root Playwright path in
CONTRIBUTING.md, applying the package-list correction from the 2026-10-11 reproduction comment. Check it againsttests/contributing-e2e-setup.test.mjs, which pins that section. - [quality] validate-members.mjs checks landscape revision and sourceUrl against the snapshot but not collectedAt, the one field the page renders #1270: gate
sources.landscape.collectedAtinscripts/validate-members.mjsagainst the snapshot, with a sandbox test. - [guide] LAUNCH.md milestone 9 (launch blog post drafted) links closed issue #1271 as its tracker; the undelivered draft has no open tracking issue #1299: open a tracking issue for the launch blog draft and announcement channels, then point
LAUNCH.mdrow 9 (and the row 11 blog-review half) at it in one PR. - [quality] the e2e coverage gate has no per-file region floor, so one src file can regress invisibly #1232: per-file region floor for the e2e gate, plus the aggregate correction in its latest comment. Larger; schedule after test(e2e-coverage): pin attribution to converter.branches and drop the dead functions arm #1305 and test(e2e-coverage): assert splitRangeAtBoundaries' never-empty postcondition #1303 since it edits the same
e2e-coverage-report.mjs.
P4: maintainer decision, no PR until decided
- [ci-maintainer] merge_group runs fail e2e coverage-gate inventory when queued siblings split spec from its pinned list entry #1257 (merge_group inventory skew): option B still recommended; reply on the issue to unpark it.
Standing trackers
- [strategist] Define the path from personal repo to CNCF ownership (endusers.cncf.io cutover) #46 (CNCF ownership cutover), 🐝 Hive Advisory Report #23 (Hive advisory report).
- PR fix(validate-utils): write the error report to stderr synchronously so process.exit cannot truncate it #1293 (
P0, P1 and P2 of the round-two list are complete; the PR queue is empty.
P0 merged (queue order): #1293 (closes #1286), #1289 (closes #1288 and, after adding the reference, duplicate #1285), #1301 (closes #1300), #1296 (closes #1295). #1296 needed one extra commit first: its
entry.via ?? []fallback inreportedAdvisoryIds()had no test reaching it, leavingscripts/audit-gate.mjsat 98.04% regions, the one source file that would have failed #1298's ratchet to 100. Verified the four together locally before enqueueing.P1 amended and merged in order:
- test(e2e-coverage): pin attribution to converter.branches and drop the dead functions arm #1305 (closes [quality] the e2e coverage attributedPaths set carries a converter.functions arm that can never contribute a path #1304): residual header in
e2e-coverage-report.mjsand the ceiling comment incoverage-gate-thresholds.test.mjsupdated from 10 regions / 97.98% to 7 regions / 98.57%. - test(e2e-coverage): assert splitRangeAtBoundaries' never-empty postcondition #1303: in-place comment now points at the header entry ([quality] 10 unreachable regions permanently cap tests/tools/e2e-coverage-report.mjs at 97.98% #1253) instead of restating it.
- test(coverage): score and enumerate the tests/helpers*.mjs harness modules #1294 (closes [quality] tests/helpers*.mjs is outside every coverage floor and outside --require-source-files #1258): merged as-is. Lowest harness file is now
tests/helpers-script-sandbox.mjsat 97.06% against the 97 floor. - test(coverage): ratchet the unit region floors to the 100% scripts/ and src/ already measure #1298 (closes [quality] the unit coverage gate leaves 27 source regions of slack: --check-source-regions is 99 while scripts/ and src/ measure 100.00% #1297 and [guide] AGENTS.md still documents the per-file harness region floor as 93% — actual gate is 97% since #1250 #1306): rebased onto the above, the 93% to 97% doc fix folded in, every recorded measurement refreshed (
src2777/2777, harness 1867/1875, all-files 96.14), fulltest:unit:coverage:checkgreen before and after the queue.
P2: #1285 and #1306 closed via the PRs above. Leaving this tracker open until the P3 drafts (#1302, #1222, #1277, #1270, #1299, #1232) and the #1257 decision are picked up.
- test(e2e-coverage): pin attribution to converter.branches and drop the dead functions arm #1305 (closes [quality] the e2e coverage attributedPaths set carries a converter.functions arm that can never contribute a path #1304): residual header in
Round two, P3 and P4: done
Every remaining open issue from the priority list now has a PR or a decision. Six PRs are open, none on hold; all CI green except #1315's end-to-end jobs still running at the time of writing.
issue outcome notes #1302 PR #1309 CodeQL matrix javascript-typescript+actions, path filters widened to.github/workflows/**; contract test updated. Firstactionsrun: 0 alerts.#1222 PR #1310 Concurrency groups on all six automation workflows (four branch-pushers keyed as their branch, two state-mutators constant), plus the branch-race contract from the issue. #1277 PR #1311 Non-root Playwright sysroot recipe in CONTRIBUTING with the corrected 45-package list; pinning test extended. Verified by running the full e2e suite as an unprivileged user (312 passed). #1270 PR #1312 validate-membersnow holdssources.landscape.collectedAtto the snapshot; fixture-validity row fordata-variant/members.jsonrecords the new error.#1299 issue #1313 + PR #1314 New tracker for the launch post and channel confirmations; LAUNCH.md rows 9 and 11 link it. #1232 PR #1315 --check-source-file-regions 66added to the e2e gate and aggregate ratcheted 95 to 96, both from a full local measurement (97.26%, lowest file 66.67%).#1257 closed, not planned The evidence showed a real cross-PR conflict fixed by a commit on #1203, not self-healing queue skew; the exact-match must stay on merge_group. Analysis on the issue.Still open and unchanged: #46 and #23 (standing trackers), #1313 (new, launch post), and this issue. Once the six PRs land this triage can close.
All six round-two PRs merged
Merged via the merge queue in two groups, in this order: #1314, #1312, #1309, #1310, #1311 (first group, 15:06Z), then #1315 (after the CONTRIBUTING.md insertion from #1311 landed; 15:09Z). Issues #1302, #1222, #1277, #1270, #1299 and #1232 auto-closed; #1257 was closed with a decision earlier.
Post-merge:
mainat 443af96, Pages deploy and CodeQL (now bothjavascript-typescriptandactions) running green; theactionsanalysis raised no new alerts (the five open alerts all predate it and are JavaScript findings from Sep 23 to Oct 8).Remaining open: #46 and #23 (standing trackers), #1313 (launch post, new), and Hive PR #1317 (opened during the merge window, not part of this triage). Closing this triage issue.
Summary
A review of the currently open issues (29) and PRs (13) found one near-duplicate pair, two consolidation candidates, and several items whose merge order matters. Filed so the overlaps are recorded in one place and can be closed or sequenced deliberately.
Near-duplicate: close one
tests/tools/e2e-coverage-report.mjs, with the same decision menu (delete the fallbacks, document them, or add an ignore marker). [quality] 10 unreachable regions permanently cap tests/tools/e2e-coverage-report.mjs at 97.98% #1253 is the post-test: pin sourceBoundaryOffsets short-segment guard and multi-boundary sort #1252 remeasure (10 regions) of [quality] record or expose the 18 unreachable guard regions in e2e-coverage-report.mjs #1210's original 18. Suggest closing [quality] record or expose the 18 unreachable guard regions in e2e-coverage-report.mjs #1210 as superseded by [quality] 10 unreachable regions permanently cap tests/tools/e2e-coverage-report.mjs at 97.98% #1253.Symptom and root cause: consolidate
src/**regions stuck at zero across four e2e coverage runs. [quality] the e2e region union never credits a guard arm taken only in a sibling fixture build #1256 diagnoses the mechanism (the region union is keyed by span, so a guard arm taken only in a sibling fixture build is never credited) and uses one of [quality] coverage executed on e2e fixture pages is not credited: 19 src regions stay at zero across four runs #1236's exact regions (src/components/ReferenceArchitectures/index.js:13) as its worked example. One fix to the union closes both; suggest tracking in [quality] the e2e region union never credits a guard arm taken only in a sibling fixture build #1256 and linking [quality] coverage executed on e2e fixture pages is not credited: 19 src regions stay at zero across four runs #1236 to it.Same bug class, two sites: one PR fixes both
scripts/import-architectures.mjs) and [scanner] collect-metrics.mjs silently drops symlinked architecture dirs from the Reference architectures count #1276 (scripts/collect-metrics.mjs) are the same unguardedentry.isDirectory()filter silently dropping a symlinked top-level architecture directory from the upstream clone. [scanner] collect-metrics.mjs silently drops symlinked architecture dirs from the Reference architectures count #1276 already notes the shared class. The fix pattern and test shape are identical, so a single PR can close both.Related: work together or sequence
LAUNCH.mdanddocs/skills/blog-management.md, could address both.scripts/lib/uri-safety.mjscontract, from [quality] scripts/lib/uri-safety.mjs, the predicate both content gates share, has no direct unit test #1261) and PR fix(security): treat a slashless http: value as a remote authority #1249 (changesremoteTarget()behavior, from [sec-check] remoteTarget() misses slashless http: authorities: http:evil.example/x publishes a third-party beacon past findRemoteReferences #1248) will conflict semantically: the contract being pinned is the one fix(security): treat a slashless http: value as a remote authority #1249 changes. Merge fix(security): treat a slashless http: value as a remote authority #1249 first, or fold the contract test into fix(security): treat a slashless http: value as a remote authority #1249.--check-harness-file-regionsfrom 93 to 97) depends on the outcome of [quality] 10 unreachable regions permanently cap tests/tools/e2e-coverage-report.mjs at 97.98% #1253: the file's current ceiling is 97.98%, leaving 0.98 points of headroom made of unreachable code. Resolve [quality] 10 unreachable regions permanently cap tests/tools/e2e-coverage-report.mjs at 97.98% #1253 before or together with test(coverage): ratchet the per-file harness region floor 93 -> 97 #1250.Checked and not duplicates
The remaining test-pinning issue/PR pairs (#1281/#1282, #1279/#1280, #1274/#1275, #1272/#1273, #1268/#1269, #1265/#1266, #1259/#1260, #1251/#1252) and the security fixes (#1254/#1255, #1263/#1264) are distinct findings, touch disjoint files, and are cross-referenced correctly.