Skip to content

v1.10.1 — second live-run remediation

Choose a tag to compare

@UberMorgott UberMorgott released this 30 May 21:36
· 49 commits to main since this release

Doc-only patch. A second live audit run (Level 2 + verified, against a real Go marketplace monorepo with Docker/compose/GitHub-workflows) validated the v1.10.0 features working and surfaced 10 instruction defects, now fixed.

Validated on the live run

Reproduction wave (Wave 2.5), verified mode, infra.md (skip_if paths + manual infra checks), osv-scanner item-0, audit-bugs.json step 6.6 (schema + integrity all PASS), monorepo handling.

Fixed (10 defects)

  • D1 piping 2>&1 to | head/grep clobbers $? — added capture-exit caution (go.md/README).
  • D2 osv-scanner-missing fallback to per-stack vuln tools + cross-ecosystem gap → Audit Limitations.
  • D3 golangci-lint config precedence (.golangci.yml wins; --enable list is config-less only).
  • D4 fuzz/race Windows guard reworded (bash default → PS twin, not "skip"); PS fuzz twin guards zero-_test.go.
  • D5 gitleaks tie-break: tracked⇒REAL / ignored⇒INFO / untracked-not-ignored⇒INFO-pending.
  • D6 deadcode test-helper false positives (testutil/Setup*/Seed*) — cross-check _test.go callers.
  • D7 gosec doesn't honor //nolint:gosec — post-filter before scoring.
  • D8 Phase-0 tool check extends with infra.md tools + osv-scanner when infra detected.
  • D9 monorepo manifest enumeration excludes node_modules/vendor/.git/build.
  • D10 SCA/CVE reproduction = re-run scanner + lockfile version (no fabricated test).

Verified: lint_docs.py PASS; independent review confirmed all 10 APPLIED-CORRECT, no regressions.