Skip to content

chore: close out low-severity audit findings - #10

Merged
jdmills-edu merged 1 commit into
mainfrom
chore/audit-low-findings
Jul 8, 2026
Merged

jdmills-edu merged 1 commit into
mainfrom
chore/audit-low-findings

Conversation

@jdmills-edu

Copy link
Copy Markdown
Member

Batches the remaining low-severity items from the security/quality audit:

Code (TDD where testable — 3 new tests, suite now 50/50):

  • Helper pipe deadlock (latent): the root helper read wdutil output only after waitUntilExit(); output beyond the ~64 KB pipe buffer would deadlock. Both pipes now drain concurrently before waiting.
  • Helper error flattening: the app discarded the helper's error string and reported everything as "not authorized". New WdutilError.failed(String) (with LocalizedError) carries the real reason to the degraded-mode UI.
  • Unbounded markers: TelemetryStore.markers now capped at 500 (oldest dropped), matching the bounded-memory guarantee the samples already had.

Supply chain:

  • actions/checkout pinned to the v5.0.0 commit SHA in both workflows (also clears the Node 20 deprecation annotation).
  • Release workflow verifies the Sparkle tools tarball against a pinned SHA-256 before use.

Docs: removed twice-stale hard-coded test counts from README/HANDOFF; HANDOFF.md status section updated to reflect the published repo + CI/release governance.

Verified: swift test 50/50 locally; full app (incl. helper target) builds clean.

🤖 Generated with Claude Code

- Helper daemon: drain stdout/stderr concurrently before waitUntilExit
  so output larger than the pipe buffer can't deadlock the root helper.
- Propagate the helper's real error message to the UI via a new
  WdutilError.failed(String) case (LocalizedError) instead of
  flattening every failure to 'not authorized'.
- Bound TelemetryStore markers at 500 (samples were already
  ring-buffered; markers grew without limit under a flapping AP).
- Pin actions/checkout to a commit SHA (v5, also clears the Node 20
  deprecation) and verify the Sparkle tools tarball against a pinned
  SHA-256 in the release workflow.
- Docs: drop stale hard-coded test counts (34/44) in favor of
  'runs in CI' wording; refresh HANDOFF.md repo/CI status.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
@jdmills-edu
jdmills-edu enabled auto-merge July 8, 2026 17:45
@jdmills-edu
jdmills-edu merged commit c5ccaa0 into main Jul 8, 2026
1 check passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant