v1.10.1 — second live-run remediation
Doc-only patch. A second live audit run (Level 2 + verified, against a real Go marketplace monorepo with Docker/compose/GitHub-workflows) validated the v1.10.0 features working and surfaced 10 instruction defects, now fixed.
Validated on the live run
Reproduction wave (Wave 2.5), verified mode, infra.md (skip_if paths + manual infra checks), osv-scanner item-0, audit-bugs.json step 6.6 (schema + integrity all PASS), monorepo handling.
Fixed (10 defects)
- D1 piping
2>&1to| head/grepclobbers$?— added capture-exit caution (go.md/README). - D2 osv-scanner-missing fallback to per-stack vuln tools + cross-ecosystem gap → Audit Limitations.
- D3 golangci-lint config precedence (
.golangci.ymlwins;--enablelist is config-less only). - D4 fuzz/race Windows guard reworded (bash default → PS twin, not "skip"); PS fuzz twin guards zero-
_test.go. - D5 gitleaks tie-break: tracked⇒REAL / ignored⇒INFO / untracked-not-ignored⇒INFO-pending.
- D6 deadcode test-helper false positives (testutil/Setup*/Seed*) — cross-check
_test.gocallers. - D7 gosec doesn't honor
//nolint:gosec— post-filter before scoring. - D8 Phase-0 tool check extends with infra.md tools + osv-scanner when infra detected.
- D9 monorepo manifest enumeration excludes node_modules/vendor/.git/build.
- D10 SCA/CVE reproduction = re-run scanner + lockfile version (no fabricated test).
Verified: lint_docs.py PASS; independent review confirmed all 10 APPLIED-CORRECT, no regressions.