slopless 0.2.21
slopless 0.2.21
Docs and supply-chain housekeeping on top of 0.2.20. No rule or behavior changes.
- README: new "What it catches" example (structural/rhetorical slop, no duplicated spans),
npx slopless --helpsurfaced in the usage loop, removed the rate-limited minzip and broken snyk-advisor badges, added a credit to Graham Rowe. - CI hardening: scoped workflow token permissions to
contents: readand SHA-pinned every GitHub Action. - Supply chain: forced the patched
qs6.15.2 across the dependency tree (CVE-2026-8723) for local/CI installs; Dependabot now ignores@types/nodesemver-major to track the Node-22 baseline and waits out pnpm's release-age gate.