Skip to content

Tidyup - #21

Merged
acuciureanu merged 2 commits into
mainfrom
tidyup
Aug 10, 2026
Merged

acuciureanu merged 2 commits into
mainfrom
tidyup

Conversation

@acuciureanu

@acuciureanu acuciureanu commented Aug 10, 2026 •

Copy link
Copy Markdown
Owner

What does this PR do?

Checklist

  • npm run lint passes
  • npm run test:ci passes
  • Behaviour changes to detection/reproduction come with a fixture or test
  • Findings are still only reported when reproduced in fresh child processes
    (no heuristic-only reports — see CONTRIBUTING.md)
  • Docs updated if user-facing behaviour changed (README, docs/usage.md,
    docs/configuration.md)

Notes for reviewers

Wanted something that shows the tool finds gadgets by watching the target,
not by matching a name against a list. Added a fixture whose property
(zqxkvBlorple) isn't in any of them - not the seed dictionary, the
known-gadget DB, or the gate list - and a test that runs it through
discovery, the differential oracle, and the reproduction gate and checks
it still gets found and reproduced. Wrote up the seeds-vs-mechanism split
in the architecture doc and linked it from the README.
import-source, require-main and require-node-options were sitting in the
corpus as 'not verified' repro entries, which felt like a cop-out. Swapped
them for behavioral probes that import/require the real module clean vs
polluted and compare a fingerprint, so the mitigated/fixed verdicts get
checked every run - if one ever comes back the fingerprint changes and the
run catches it. Dropped probeImport/probeRequireDir, nothing uses them now.
@acuciureanu
acuciureanu merged commit 7479368 into main Aug 10, 2026
6 checks passed
@acuciureanu
acuciureanu deleted the tidyup branch August 10, 2026 20:57
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant