Repository navigation
Add section-marker-rev to vault - #55
Merged
Merged
Conversation
|
Important
This repository does not receive automatic reviews because it has fewer than 10 stars. ⚙️ Run configuration
Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out. Comment |
Contributor
There was a problem hiding this comment.
Verdict: concerns
Provenance
section-marker-rev@2.0.0— unverified:Golevka2001/section-marker-rev has no attestation for this artifact. This review therefore covers the built output only — the zip downloaded from the release URL invault/section-marker-rev.json(itssha256matches the vault checksum742fd9b8…126c4d). I did not clone a source repository or build anything.
Reviewed changes
vault/section-marker-rev.json— new vault entry (kindextension, one artifact, no providers, checksum, metadata).
What the built module does
The zip contains index.js, index.css, mod.js, their source maps (which embed the original TypeScript), metadata.json, and spicetify-module.json. The module renders a song's audio-analysis sections as markers on the playbar. Reviewed behavior:
- No network primitives found — no
fetch,XMLHttpRequest,WebSocket,EventSource, orsendBeacon, and no remote script/image URLs. The only data call isSpicetify.getAudioData(uri), which is a client API documented as astdlibBoundaryexception in the bundledmetadata.json. No arbitrary host is contacted by the module. - No remote or dynamic code — no
eval,new Function, stringsetTimeout, remoteimport(), or injected<script>. DOM is built withcreateElement+classList+textContent; noinnerHTML/insertAdjacentHTML. - No credentials or session access — no
Platform.AuthorizationAPI,getState().token,accessToken, cookies, or token exfiltration. - No Spicetify internals abuse — no
__SPICETIFY_DAEMON_TOKEN__, no127.0.0.1:7967, noCORSProxy, nospicetify.modules.local.*writes (nolocalStorageuse at all). - No concealment — the embedded TypeScript in
mod.js.map/index.js.mapfaithfully matches the compiled JS; no non-ASCII/zero-width padding and no reviewer-addressing text.
Finding
- ℹ️ Unbounded readiness wait could hang the loader.
mod.js:393(sourceapp.ts:12in the bundled source map) loopswhile (!client.player.data || !client.uri || !client.locale || !client.cosmos || !client.react) await new Promise(r => setTimeout(r, 100)), and the default export (mod.js:412–414) awaitsmain(). There is no attempt cap or timeout, so if any of those five stdlib client properties never becomes available (e.g. after a stdlib/client change), the module'sloadpromise never settles and can stall the module loader. These are core stdlib properties, so real-world risk is low, but bounding the retry would remove the hang.
Not reviewed
- The source repository and its build pipeline (
Golevka2001/section-marker-rev) — no verified commit to check out. - Any
package.json/lockfile/supply chain — no such files are bundled in the zip. - Prior versions — the vault record contains only
2.0.0; nothing to diff against. - Remote preview assets (
README.assets/default.png,showcase.gif) — referenced only inmetadata.json, not fetched or inspected.
deepseek-v4.1-flash (free via Pullfrog for OSS) | 𝕏
afonsojramos
approved these changes
Oct 9, 2026
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.

Adds a vault entry for
section-marker-rev, the Spicetify v3 port of Aimarekin's section-marker,revised by Golevka2001.