v2.23.0
Security rules had never once looked at a
.mjsfile,forEach+awaitonly counted when it wasn't an arrow function, and the CI fix agent ran out of steps before it could finish.
Fixed
-
.mjsand.cjswere invisible to thirteen rules. Every rule that names
.jsin itsextensionslist — which is all four security rules, plus the
performance and best-practice ones — skipped these files entirely.eval(),
innerHTMLand hardcoded credentials went unreported in any ES-module or
CommonJS-suffixed file. Found while reviewingcodeep-action, whose own
scripts are.mjs: its self-review had never applied a single security rule
to itself.The extension is now normalised once, rather than widening thirteen arrays
that would go stale on the next rule added. The directory walk picks these
files up too, so a whole-project review no longer steps over them. -
foreach-awaitnever matched an arrow function. The pattern required the
awaitto follow forEach's closing paren, which only lines up for
function (x) {. Every modern form went unreported, and the rule also only
fired whenawaitwas the very first token in the body — so
{ out.push(await f(id)) }was invisible. Both bounds stay explicit and both
classes negated, so matching is linear. -
A CI fix run gave up after 12 steps.
codeep review --fixcapped the
agent at 12 iterations, under half the product default. Fixing oneinnerHTML
call and running the test suite exhausted it, and an agent stopped mid-edit
leaves a worse diff than one that never started. Now 25, the same as
everywhere else; the plan size and the caller's wall-clock are the real bounds.