Fixes from running JevGate on widely used projects - #41
Merged
Merged
Conversation
…ranges
A colon after non-ASCII text ("已移除:`x`") panicked in the docs role parser,
and a Python test ending in a multi-byte character panicked when counting its
last line. Both stopped JevGate on herdr, hermes-agent and OmniRoute.
`docs/en/env/01-variables.md#idempotency` in freellmapi's docs was reported as a missing path although the file and its heading exist.
herdr keeps a copy of its website docs per release under docs/versions/; 137 of its 147 documentation considers named a section of such a copy.
Two documents whose paths name different locales (docs/en and docs/zh-cn, README.md and README_zh.md) or whose prose is in different scripts are translations: their sections are asked only whether they disagree, as when the translation question itself says so. freellmapi, cc-switch and rtk had 12 translated pairs reported as repetition; no corpus finding pairs two languages.
The hot projects' security findings were mostly wrong in a few ways, each missing one fact. Each is now asked, only after the finding: - SQL, command or code findings: what their values can hold where they enter the text (fixed clauses a key selects, parsed ids, the program's own names, or a query the sender may run anyway make a note). - Markup considers on parameters: what their values hold where they enter the markup, as markup reviews already were. - Weak-settings findings of the escaping check: what the unescaped HTML holds (a library's escaped output or markup the program ships). - Logging findings: whether the value is the output its user asked for. - Error-detail findings: who reads the error text, with the README's opening; only the operator, the project's own services or the person running it locally, at 0.80, make a note. Corpus (55 projects with labeled security findings): 15 wrong and 1 debatable become notes for 1 right; held-out projects unchanged; about $0.02 of new questions. Hot projects: freellmapi -5, cc-switch -2, headroom -26, rtk -1, multica -17 reviews and considers. The post-finding follow-ups of a security unit move into one boxed Confirms struct.
…t clear The settle Choice on a URL's parts was asked only while the check stayed undecided. paperclip's cloud route, a fixed path on its configured origin with the user's id in a header, was a review at 0.81 and puts 0.88 on its own host. On the corpus no review or consider changed (every labeled right finding asked it put at most 0.56 there) and 47 notes on URLs of fixed or configured hosts cleared, for about $0.02.
OmniRoute keeps its docs in 30 languages under docs/i18n/<lang>/; 543 of its 547 staleness considers repeated an original's finding in a translation. Documents under i18n, l10n, locales or translations followed by a language code are left out like per-release copies. No corpus finding changes.
dify's web/docs/test.md tells readers to import from web/test/i18n-mock, which is web/test/i18n-mock.ts; it was reported as missing. No corpus finding changes.
openclaw documents `make routing-isolation` from a separate models repository and has no Makefile; the target was reported as undeclared. No corpus finding changes.
n8n's i18n docs run `pnpm n8n-generate-translations`, a bin of its core package; it was reported as a script no manifest declares. No corpus finding changes.
The candidate paths are built with the platform's separator, so on Windows `src\services\quota` never matched the tracked `src/services/quota.ts`.
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Ran JevGate on popular projects under daily development (rtk, headroom, paperclip, hermes-agent, cc-switch, freellmapi, herdr, multica, OmniRoute, dify, immich, openclaw), checked every review and consider it raised against the code, and fixed what it got wrong. Each fix is measured on the labeled corpus; numbers are in the commits, doc comments and CHANGELOG.
Crashes and documentation
0871ba2).guide.md#setup), and a module path without its extension (web/test/i18n-mock), name their files (6e42bdb,2cb24d8). Amake/justtarget is checked only where a Makefile/justfile is tracked (54e2f88).docs/versions/0.7.5) and one language's copy of the docs underi18n/<lang>/are left out (9af3f53,5f22584): herdr 137 of 147 doc considers, OmniRoute 543 of 547 staleness considers.f2ab926): 12 pairs on freellmapi, cc-switch, rtk.Security follow-ups (
7bb31b6,96fcd5a): each wrong kind of finding is asked the one thing that decided it, only after the finding:dangerouslySetInnerHTML): what the HTML holds (a highlighter's escaped output, bundled icons).Corpus, 55 projects with labeled security findings: 15 wrong and 1 debatable become notes for 1 right; held-out projects unchanged; about $0.04 of new questions in total. Hot projects: freellmapi −5, cc-switch −2, headroom −26, rtk −1, multica −17, paperclip −8 reviews and −89 considers.
Tried and dropped after measuring: a placeholder-key settle (real fallback secrets read as placeholders), asking cookie flags of decided findings (no effect), lowering
dev_onlyto 0.65.cargo test((501 tests)),cargo clippy --all-targets -D warningsandcargo +1.90.0 check --lockedpass.