Skip to content

Fixes from running JevGate on widely used projects - #41

Merged
tauanbinato merged 12 commits into
mainfrom
hot-projects
Sep 28, 2026
Merged

tauanbinato merged 12 commits into
mainfrom
hot-projects

Conversation

@tauanbinato

@tauanbinato tauanbinato commented Sep 28, 2026 •

Copy link
Copy Markdown
Contributor

Ran JevGate on popular projects under daily development (rtk, headroom, paperclip, hermes-agent, cc-switch, freellmapi, herdr, multica, OmniRoute, dify, immich, openclaw), checked every review and consider it raised against the code, and fixed what it got wrong. Each fix is measured on the labeled corpus; numbers are in the commits, doc comments and CHANGELOG.

Crashes and documentation

  • Two panics on non-ASCII text stopped whole runs on herdr, hermes-agent and OmniRoute (0871ba2).
  • Staleness: a path with an anchor (guide.md#setup), and a module path without its extension (web/test/i18n-mock), name their files (6e42bdb, 2cb24d8). A make/just target is checked only where a Makefile/justfile is tracked (54e2f88).
  • Per-release doc copies (docs/versions/0.7.5) and one language's copy of the docs under i18n/<lang>/ are left out (9af3f53, 5f22584): herdr 137 of 147 doc considers, OmniRoute 543 of 547 staleness considers.
  • A translation is not reported as repeating its original (f2ab926): 12 pairs on freellmapi, cc-switch, rtk.
  • No corpus documentation finding changes.

Security follow-ups (7bb31b6, 96fcd5a): each wrong kind of finding is asked the one thing that decided it, only after the finding:

  • SQL/command/code: what the values can hold (fixed clauses a key selects, parsed ids…).
  • Markup considers on parameters: what the values hold where they enter the markup.
  • Unescaped HTML (dangerouslySetInnerHTML): what the HTML holds (a highlighter's escaped output, bundled icons).
  • Logging: whether the value is the output its user asked for.
  • Error details: who reads the text, with the README's opening (sent only then, within the upload patterns); only at 0.80.
  • URL findings: where the URLs come from, now also when the check is decided.

Corpus, 55 projects with labeled security findings: 15 wrong and 1 debatable become notes for 1 right; held-out projects unchanged; about $0.04 of new questions in total. Hot projects: freellmapi −5, cc-switch −2, headroom −26, rtk −1, multica −17, paperclip −8 reviews and −89 considers.

Tried and dropped after measuring: a placeholder-key settle (real fallback secrets read as placeholders), asking cookie flags of decided findings (no effect), lowering dev_only to 0.65.

cargo test ((501 tests)), cargo clippy --all-targets -D warnings and cargo +1.90.0 check --locked pass.

…ranges

A colon after non-ASCII text ("已移除:`x`") panicked in the docs role parser,
and a Python test ending in a multi-byte character panicked when counting its
last line. Both stopped JevGate on herdr, hermes-agent and OmniRoute.
`docs/en/env/01-variables.md#idempotency` in freellmapi's docs was reported
as a missing path although the file and its heading exist.
herdr keeps a copy of its website docs per release under docs/versions/;
137 of its 147 documentation considers named a section of such a copy.
Two documents whose paths name different locales (docs/en and docs/zh-cn,
README.md and README_zh.md) or whose prose is in different scripts are
translations: their sections are asked only whether they disagree, as when
the translation question itself says so. freellmapi, cc-switch and rtk had
12 translated pairs reported as repetition; no corpus finding pairs two
languages.
The hot projects' security findings were mostly wrong in a few ways, each
missing one fact. Each is now asked, only after the finding:

- SQL, command or code findings: what their values can hold where they
  enter the text (fixed clauses a key selects, parsed ids, the program's
  own names, or a query the sender may run anyway make a note).
- Markup considers on parameters: what their values hold where they enter
  the markup, as markup reviews already were.
- Weak-settings findings of the escaping check: what the unescaped HTML
  holds (a library's escaped output or markup the program ships).
- Logging findings: whether the value is the output its user asked for.
- Error-detail findings: who reads the error text, with the README's
  opening; only the operator, the project's own services or the person
  running it locally, at 0.80, make a note.

Corpus (55 projects with labeled security findings): 15 wrong and 1
debatable become notes for 1 right; held-out projects unchanged; about
$0.02 of new questions. Hot projects: freellmapi -5, cc-switch -2,
headroom -26, rtk -1, multica -17 reviews and considers.

The post-finding follow-ups of a security unit move into one boxed
Confirms struct.
…t clear

The settle Choice on a URL's parts was asked only while the check stayed
undecided. paperclip's cloud route, a fixed path on its configured origin
with the user's id in a header, was a review at 0.81 and puts 0.88 on its
own host. On the corpus no review or consider changed (every labeled right
finding asked it put at most 0.56 there) and 47 notes on URLs of fixed or
configured hosts cleared, for about $0.02.
OmniRoute keeps its docs in 30 languages under docs/i18n/<lang>/; 543 of
its 547 staleness considers repeated an original's finding in a
translation. Documents under i18n, l10n, locales or translations followed
by a language code are left out like per-release copies. No corpus finding
changes.
dify's web/docs/test.md tells readers to import from web/test/i18n-mock,
which is web/test/i18n-mock.ts; it was reported as missing. No corpus
finding changes.
openclaw documents `make routing-isolation` from a separate models
repository and has no Makefile; the target was reported as undeclared. No
corpus finding changes.
n8n's i18n docs run `pnpm n8n-generate-translations`, a bin of its core
package; it was reported as a script no manifest declares. No corpus
finding changes.
The candidate paths are built with the platform's separator, so on
Windows `src\services\quota` never matched the tracked
`src/services/quota.ts`.
@tauanbinato
tauanbinato merged commit 7b26b31 into main Sep 28, 2026
9 checks passed
@tauanbinato
tauanbinato deleted the hot-projects branch September 28, 2026 02:10
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant