chore: close out low-severity audit findings - #10
Merged
Merged
Conversation
- Helper daemon: drain stdout/stderr concurrently before waitUntilExit so output larger than the pipe buffer can't deadlock the root helper. - Propagate the helper's real error message to the UI via a new WdutilError.failed(String) case (LocalizedError) instead of flattening every failure to 'not authorized'. - Bound TelemetryStore markers at 500 (samples were already ring-buffered; markers grew without limit under a flapping AP). - Pin actions/checkout to a commit SHA (v5, also clears the Node 20 deprecation) and verify the Sparkle tools tarball against a pinned SHA-256 in the release workflow. - Docs: drop stale hard-coded test counts (34/44) in favor of 'runs in CI' wording; refresh HANDOFF.md repo/CI status. Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
jdmills-edu
enabled auto-merge
July 8, 2026 17:45
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Batches the remaining low-severity items from the security/quality audit:
Code (TDD where testable — 3 new tests, suite now 50/50):
wdutiloutput only afterwaitUntilExit(); output beyond the ~64 KB pipe buffer would deadlock. Both pipes now drain concurrently before waiting.WdutilError.failed(String)(withLocalizedError) carries the real reason to the degraded-mode UI.TelemetryStore.markersnow capped at 500 (oldest dropped), matching the bounded-memory guarantee the samples already had.Supply chain:
actions/checkoutpinned to the v5.0.0 commit SHA in both workflows (also clears the Node 20 deprecation annotation).Docs: removed twice-stale hard-coded test counts from README/HANDOFF; HANDOFF.md status section updated to reflect the published repo + CI/release governance.
Verified:
swift test50/50 locally; full app (incl. helper target) builds clean.🤖 Generated with Claude Code