Repository navigation
Conversation
…t handling - drop symlinks whose realpath leaves the repository or has none (D-sc-03; the scanner-source-listing pin no longer lists an out-of-tree symlink) - skip unreadable package manifests with a diagnostic instead of failing the whole observation (D-sc-04) - report dangling tsconfig projectReferences as diagnostics and never follow references outside the repository (D-sc-05) - cap the Swift worker output buffer at 256 MB (D-sc-08) - resolve dependency versions only from in-tree installs (D-sc-09)
Source file names flowed unescaped into groma/relationships.md table rows; a name containing pipes, newlines, or brackets mangled the row and permanently broke every architecture load (D-sc-02). Link text, hrefs, and cells are now escaped so every row round-trips through the strict reader.
…ences - reject requests whose Host is not loopback (DNS rebinding, WEB-01) - refuse cross-origin state-changing requests while bare clients still work (WEB-02) - refuse stored code references that escape the repository at the web layer (WEB-03) - render work-island pins and statuses as text nodes, never innerHTML (WEB-04)
- catch errors in the root, export, and instructions actions (D2-3) - catch welcome-loop action failures like groma scan does (D2-4) - correct draft relation help to the required flags (D2-5) - reflect scanner errors in the welcome status bar (D2-7) - exit deterministically when a rejected close() fails during shutdown (D2-8)
GromaFileSystem.write now writes a same-directory temp file and renames it over the target, matching the existing replaceFile pattern, so an interrupted write can no longer leave a truncated, unloadable record (D2-1).
- validate task ids before spawning the CLI and quote shim arguments (D-work-01) - resync the snapshot stream past noise and malformed regions (D-work-02) - coerce degenerate task fields to the work-source contract (D-work-03) - escalate to SIGKILL when a watched CLI ignores SIGTERM (D-work-04) - order dotted task ids segment by segment (D-work-05)
Every third-party action was referenced by a floating tag while the release workflow ran with contents: write and id-token: write and committed to main through an unpinned action (D5-5). All 13 distinct actions are now pinned to their current tag commits with the tag kept as a comment.
…the code - product-model: exports ship the profile, map, flows, and read-only source inspection without task data, matching the implementation (D5-0) - component-markdown: point the package example at the real system path (D5-1) - relationship-inference: re-measured counts 119 elements, 42 authored, 21 derived rows (D5-2) - inspect: --json is a groma scanner discover option only (D5-4) - CONTRIBUTING: remove the deleted typescript-scanner verify step (D-sc-07) and the deleted parcel-bytecode test instruction (D-work-06)
TASK-531 tracks the remediation PR required by CONTRIBUTING: actor, entry points, observable result, and per-finding scope.
Groma architecture comparison
|
…comparisons External fork PRs no longer export architecture automatically. Maintainers can review a PR, then choose **Groma architecture → Run workflow** on `main` and enter its number. Same-repository PRs remain automatic; the manual choice applies to one run. Comparison jobs keep the trusted base checked out and fetch the PR head only as Git data, so checkout v7 protection remains enabled. The workflow selects Groma 0.6.6 explicitly through the tested Action version input. README and contributor instructions explain the workflow and reader upgrades. Validation: `bun run check` passes (773 Bun tests, 51 optional skips, plus Node/lint/type checks). The released 0.6.6 CLI exported #113 from a trusted main checkout. The selection command excludes #113 by default and includes its exact head/base when selected manually. Action integration passes with a base checkout and a different exported head. Action change: MrLesk/groma.md-action#5
Record completed validation only. Source commit 6151fce passed CI on Windows, Linux, and macOS in run 37453651554. No code or workflow changes. [skip ci]
|
I checked this PR while looking at Groma for a Gray Cat video. Two security gaps still remain at
The existing web tests passed, including the foreign-host, foreign-origin and direct I ran the 11 changed test files on Bun 1.3.14: 32 tests passed, and two files failed to load because of parser errors in unchanged scanner files. I did not run the declared Bun 1.4.2 version. The two reviewers completed the source review; the live reproductions above were run by Codex. I would fix these gaps before relying on this PR for safe local use. 😸 Generated with The Gray Cat | Orchestrated by OpenAI Codex; reviewed by Codex + Claude in parallel |
What this is
An external, adversarial security and correctness audit of groma.md v0.5.0 (HEAD
5882073a), run with a three-pass methodology:Result: 37 triple-validated findings — 28 fixed, 9 reported on this branch. Each finding has its own issue with full evidence, failure scenario, remediation, and validation notes:
Triple-validated: independent discovery (R1), adversarial re-derivation by a separate reviewer given only the claim text (R2), and source reproduction on HEAD 5882073.
Fixed on this branch (28)
Reported for maintainer decision (9)
These are real and confirmed, but the right fix is a design/product decision, so this PR deliberately does not change them:
Fixed by area
maxBuffer: Infinity, out-of-tree dependency version attribution.GromaFileSystem.writechoke point, try/catch on root/export/instructions actions, welcome-loop action errors, draft-relation help text, status-bar/notice contradiction, signal-shutdown close() crash.Amended pinned test (needs review)
test-bun/scanner-source-listing.test.tsincidentally pinned the audited D-sc-03 behavior: its fixture symlinksShared.swiftto a file outside the repository root (a sibling temp dir) and asserted the symlink stays listed. Under the fix, out-of-tree symlinks are excluded (that is the point of D-sc-03), so the expected list was amended to dropShared.swift; the test's actual subject — the in-tree symlink deduped to its listed target — is untouched and still passes.Checks run
bun run checkon this branch: 763 pass / 7 fail (+26 new tests, all passing). The 7 fails are the pre-existing environment-dependent set on this arm64 macOS host with no Java/SwiftSyntax toolchain — 6 Swift (worker needs bundled SwiftParser host modules that ship via CI's setup-swift) and 1 Java (JDK-version-sensitive assertion; verified identical pre-fix at 737/7 with JDK 21 and 763/7 with JDK 27, so none are regressions). CI validates these.Checked and cleared (not filed, for completeness)
Linked task: TASK-531 ("Harden audited surfaces and correct documentation drift") in
backlog/tasks/.