Skip to content

Add section-marker-rev to vault - #55

Merged
afonsojramos merged 2 commits into
spicetify:mainfrom
Golevka2001:add-section-marker-rev
Oct 9, 2026
Merged

afonsojramos merged 2 commits into
spicetify:mainfrom
Golevka2001:add-section-marker-rev

Conversation

@Golevka2001

Copy link
Copy Markdown
Contributor

Adds a vault entry for section-marker-rev, the Spicetify v3 port of Aimarekin's section-marker,
revised by Golevka2001.

Copilot AI balanced review requested due to automatic review settings October 7, 2026 07:26

Copilot AI left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Copilot was unable to review this pull request because the user who requested the review has reached their quota limit.

@coderabbitai

coderabbitai Bot commented Oct 7, 2026 •

Copy link
Copy Markdown

Important

  • 🔍 Trigger review

This repository does not receive automatic reviews because it has fewer than 10 stars.

⚙️ Run configuration
  • Configuration used: Organization UI
  • Review profile: CHILL
  • Plan: Advanced
  • Run ID: b62e6b02-b8a4-4316-b69f-9d1e44ecd222
  • Autofix · Keep fixing CodeRabbit findings and required CI, and resolving merge conflicts

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

@pullfrog pullfrog Bot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Verdict: concerns

Provenance

  • section-marker-rev@2.0.0 — unverified: Golevka2001/section-marker-rev has no attestation for this artifact. This review therefore covers the built output only — the zip downloaded from the release URL in vault/section-marker-rev.json (its sha256 matches the vault checksum 742fd9b8…126c4d). I did not clone a source repository or build anything.

Reviewed changes

  • vault/section-marker-rev.json — new vault entry (kind extension, one artifact, no providers, checksum, metadata).

What the built module does

The zip contains index.js, index.css, mod.js, their source maps (which embed the original TypeScript), metadata.json, and spicetify-module.json. The module renders a song's audio-analysis sections as markers on the playbar. Reviewed behavior:

  • No network primitives found — no fetch, XMLHttpRequest, WebSocket, EventSource, or sendBeacon, and no remote script/image URLs. The only data call is Spicetify.getAudioData(uri), which is a client API documented as a stdlibBoundary exception in the bundled metadata.json. No arbitrary host is contacted by the module.
  • No remote or dynamic code — no eval, new Function, string setTimeout, remote import(), or injected <script>. DOM is built with createElement + classList + textContent; no innerHTML/insertAdjacentHTML.
  • No credentials or session access — no Platform.AuthorizationAPI, getState().token, accessToken, cookies, or token exfiltration.
  • No Spicetify internals abuse — no __SPICETIFY_DAEMON_TOKEN__, no 127.0.0.1:7967, no CORSProxy, no spicetify.modules.local.* writes (no localStorage use at all).
  • No concealment — the embedded TypeScript in mod.js.map/index.js.map faithfully matches the compiled JS; no non-ASCII/zero-width padding and no reviewer-addressing text.

Finding

  • ℹ️ Unbounded readiness wait could hang the loader. mod.js:393 (source app.ts:12 in the bundled source map) loops while (!client.player.data || !client.uri || !client.locale || !client.cosmos || !client.react) await new Promise(r => setTimeout(r, 100)), and the default export (mod.js:412–414) awaits main(). There is no attempt cap or timeout, so if any of those five stdlib client properties never becomes available (e.g. after a stdlib/client change), the module's load promise never settles and can stall the module loader. These are core stdlib properties, so real-world risk is low, but bounding the retry would remove the hang.

Not reviewed

  • The source repository and its build pipeline (Golevka2001/section-marker-rev) — no verified commit to check out.
  • Any package.json/lockfile/supply chain — no such files are bundled in the zip.
  • Prior versions — the vault record contains only 2.0.0; nothing to diff against.
  • Remote preview assets (README.assets/default.png, showcase.gif) — referenced only in metadata.json, not fetched or inspected.

Pullfrog  | Fix it ➔ | View workflow run | Using deepseek-v4.1-flash (free via Pullfrog for OSS) | 𝕏

@afonsojramos
afonsojramos merged commit 467ec17 into spicetify:main Oct 9, 2026
1 check passed
@Golevka2001
Golevka2001 deleted the add-section-marker-rev branch October 10, 2026 08:19
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants