Point the §2 scan at the published surface, and re-vendor the script that could not aim there - #9
Merged
Merged
Conversation
…that
could not aim there
DS §2 (v2.71.0, tgwab-standards#180) makes the eval scan's target the
PUBLISHED SURFACE rather than the literal dist/. This repo is the case that
produced the ruling.
Its `files` list ships BOTH src and dist, and its default export is
`"." : "./src/index.js"` — so `import … from 'markdownwizard-tools'` resolves
to the SOURCE, and `no-eval.sh dist` covered only the `./iife` subpath. The
gate was aimed at the path most consumers do not use.
THE SCRIPT IS RE-VENDORED IN THE SAME CHANGE BECAUSE IT HAD TO BE. The copy
this repo carried read only "$1", so `./scripts/no-eval.sh dist src` would
have scanned dist and dropped src silently — the widened gate would have
looked widened and covered exactly what it did before. Demonstrated here, in
this repo, with one hazard planted in src/:
new script, `dist src` exit 1 src/__negctl__.js:1 ... new Function(
OLD script, `dist src` exit 0 "eval-free: OK (dist)" <-- silent miss
new script, `dist` exit 0 the hazard really is only in src
Removing the control returns the run to green: `eval-free: OK (dist src)`.
The output naming both targets is itself the evidence the second is read.
NO HAZARD WAS FOUND OR FIXED. src/ scanned clean before this change and
scans clean after — all 8 files, exit 0. This is a scope defect, a control
aimed at the wrong path, not an incident. Lint and the test suite are
unchanged and green.
MERGE ORDER: the vendored scripts/no-eval.sh here matches
templates/no-eval.sh on tgwab-standards#180, which is open. If that PR
changes in review, re-sync this copy before merging — the two are meant to be
identical, and #180 adds the suite that proves it.
Refs MichalAFerber/tgwab-standards#179
Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_016beCydw4C9VrgL9eHzGUG2
MichalAFerber
marked this pull request as ready for review
September 7, 2026 09:52
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
DS §2 (v2.71.0 — MichalAFerber/tgwab-standards#180) makes the eval scan's target the published surface rather than the literal
dist/. This repo is the case that produced that ruling.Its
fileslist ships bothsrcanddist, and its default export is"." : "./src/index.js"— soimport … from 'markdownwizard-tools'resolves to the source, andno-eval.sh distcovered only the./iifesubpath. The gate was aimed at the path most consumers do not use.The script is re-vendored in the same change because it had to be
The copy this repo carried read only
$1../scripts/no-eval.sh dist srcwould have scanneddistand droppedsrcsilently — the widened gate would have looked widened and covered exactly what it did before.Demonstrated here, in this repo, with one hazard planted in
src/:dist srcsrc/__negctl__.js:1 … new Function(dist srceval-free: OK (dist)— the silent missdistalonesrcRemoving the control returns the run to green:
eval-free: OK (dist src). The output naming both targets is itself the evidence the second one is read.No hazard was found or fixed
src/scanned clean before this change and scans clean after — all 8 files, exit 0. This is a scope defect, not an incident: a control aimed at the wrong path. Writing it up as a hazard would invite someone to look, find nothing, and discount the rule.Lint and the test suite are unchanged and green.
Merge order
The vendored
scripts/no-eval.shhere is identical totemplates/no-eval.shon tgwab-standards#180, which is open. If that PR changes in review, re-sync this copy before merging — the two are meant to be byte-identical, and #180 adds the suite (scripts/no-eval.test.sh, 10 cases) that proves the fixed behavior.Refs MichalAFerber/tgwab-standards#179
🤖 Generated with Claude Code
https://claude.ai/code/session_016beCydw4C9VrgL9eHzGUG2