Updated: 2026-02-27
src/papyrus/core/renderer.py(network_boundary)src/papyrus/core/html_cleaner.py(input_boundary)src/papyrus/core/parser.py(input_boundary)
- Bus factor is
1for untrusted-input processing and renderer execution paths.
- Added explicit hotspot ownership in
.github/CODEOWNERS. - Existing parser/renderer tests retained as required baseline:
tests/test_renderer.pytests/test_parser.py
- Add at least one additional human maintainer for each sensitive path.
- Enforce code-owner review requirement in branch protection.
- Add recurring pair-review for parser and renderer changes.