Skip to content

Docs/thesis corrections - #10

Merged
mkmuniz merged 3 commits into
mainfrom
docs/thesis-corrections
Oct 3, 2026
Merged

mkmuniz merged 3 commits into
mainfrom
docs/thesis-corrections

Conversation

@mkmuniz

@mkmuniz mkmuniz commented Oct 3, 2026

Copy link
Copy Markdown
Owner

What this changes

Corrects three factual errors in the docs found while checking the project against its problem thesis: a false claim about other tools, the wrong date for the alphanumeric CNPJ, and a name section that still explained the old name. Adds the first alphanumeric CNPJ the Receita Federal ever issued to the corpus.

Why

Every one of these was a checkable claim, and each was wrong:

"No maintained open-source tool detects CPF, CNPJ, CNH, Pix keys, card PANs and E2EIDs. Not underserved — empty." At least one maintained project detects and validates Brazilian identifiers in free text. A README that states something a reader can disprove in a minute costs more credibility than the claim was ever worth.

"In force since 2026-07-06." The Receita Federal generated the first alphanumeric CNPJ on 2026-07-31 (gov.br). The earlier date came from a preliminary timeline, not from the authority, and it had spread to seven places: both READMEs, the package doc in cnpj.go, three test comments and the corpus header.

"Надзор (vedei) is Russian for oversight." The rename pasted the new name into the old etymology. Vedei is Portuguese — the first person past tense of vedar, to seal or keep from passing.

Closes #

Checklist

  • make test passes
  • make lint reports zero issues
  • New code does not lower coverage — no code changed; one Go file changed only in a comment

If this adds or changes a detector

No detector changes. One corpus case is added, and it is worth more than its size suggests:

  • The validator is untouched; detect/br/cnpj.go changed only in its doc comment
  • Property-based tests — not applicable, no logic changed. The existing FuzzCNPJCheckDigits still covers the arithmetic
  • Edge case covered, and the PR says why below
  • Entry added to corpus/: 00.000.000/E08G-12 as a true positive. No new reject — none of the corrections introduced a value that must stay quiet
  • Confidence unchanged

Why this case matters: every other CNPJ vector in the suite is generated, which only proves the algorithm agrees with itself. 00.000.000/E08G-12 is a Banco do Brasil branch, published by the Receita as the first alphanumeric CNPJ issued. It proves the algorithm agrees with the issuer. The check digits computed from 00000000E08G are 1 and 2, matching.

It also settles a question raised elsewhere: some secondary sources claimed certain letters (I, O, U, Q, F) would be excluded from the alphanumeric format. The Receita's own announcement says positions take "letras maiúsculas de A a Z", so the validator accepting all 26 is correct and stays.

If this touches anything a detected value passes through

Nothing on that path changed.

  • No path sends Finding.Raw out of the process
  • Redaction still hides the identifying part of the value
  • Findings with ValidityInvalid still never leave the engine

Trade-offs and limitations

The positioning paragraph no longer names any other tool, by deliberate choice. It says what vedei does — validation by check digit, enforcement where data leaves, one binary — rather than comparing. A future comparison, if one is published, should come with an open methodology and a shared corpus, not a sentence in a README.

The new corpus case is a real, public CNPJ. It belongs to a bank branch and was published by the Receita as a news item, so it is a public record rather than personal data. Its fingerprint is in .vedeiignore with that reason written next to it, so the self-scan stays clean.

"July 2026" mentions were left alone. Several comments say the format arrived in July 2026, which remains true; only the exact wrong date was changed.

The repository name's casing is not changed here. The GitHub repo is Vedei while the module path, badge and uses: are vedei. It works through GitHub's case-insensitive routing, but aligning it is a repository setting, not a commit.

How to verify

$ grep -rn "2026-07-06\|06/07/2026" .
(no output)

$ grep -rni "надзор\|nadzor" .
(no output)

$ make corpus
    corpus_test.go:60: 41 cases: precision 1.000 (22 reported, 0 wrong), recall 1.000 (22/22 found)

$ make build && ./bin/vedei scan .
.: nothing found in 142 file(s) (538.6 KB)
113 finding(s) silenced by .vedeiignore

The official CNPJ, checked directly:

$ echo 'cnpj 00.000.000/E08G-12' | ./bin/vedei stream
cnpj **.***.***/****-12 [vedei: cnpj redacted]

By opening this PR you agree it is licensed under the MIT License and that you follow the Code of Conduct.

"No maintained open-source tool detects CPF, CNPJ, CNH, Pix keys, card PANs
and E2EIDs. Not underserved — empty." is not true: at least one maintained
project detects and validates Brazilian identifiers in free text. A README
that makes a checkable claim and gets it wrong costs more credibility than the
claim was ever worth.

The paragraph now says what vedei does rather than what others do not: it
validates Brazilian data by check digit instead of matching by shape, and it
enforces at the boundary where data leaves — agent context, CI, logs — in one
Go binary with no runtime and no network.
…07-06

The Receita Federal generated the first alphanumeric CNPJ on 2026-07-31; the
2026-07-06 date in seven places came from an early timeline, not from the
authority. Corrected everywhere it appeared — README, the package doc in
cnpj.go, test comments, the corpus header — with the gov.br announcement
linked from both READMEs.

The corpus gains that first CNPJ itself: 00.000.000/E08G-12, a Banco do Brasil
branch, published by the Receita. Every other CNPJ vector in the suite is
generated, which only proves the algorithm agrees with itself; this one proves
it agrees with the issuer. It validates — the check digits computed from
00000000E08G are 1 and 2.

Its fingerprint joins .vedeiignore, so the self-scan stays clean. Corpus:
41 cases, precision and recall 1.000.
The "The name" section still explained Надзор, Russian for oversight, with
"(vedei)" pasted into it by the rename — an etymology for a word the project no
longer uses.

Vedei is Portuguese: the first person past tense of vedar, to seal or keep from
passing. "Eu vedei" — I sealed it. It is what the person running the tool says
once it has done its job: the CPF did not reach the model, the key did not reach
the log. Written in both READMEs, and no reference to the old name remains
anywhere in the repository.
@mkmuniz mkmuniz self-assigned this Oct 3, 2026
@mkmuniz mkmuniz added the documentation Improvements or additions to documentation label Oct 3, 2026
@mkmuniz
mkmuniz merged commit 678b982 into main Oct 3, 2026
16 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

documentation Improvements or additions to documentation

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant