Repository navigation
Publish section-marker-rev@2.0.1 - #62
Conversation
There was a problem hiding this comment.
✅ No new issues found.
Reviewed changes — reviewed the version-bump submission adding section-marker-rev@2.0.1 to the vault entry.
- Vault entry for
2.0.1— newartifactsURL,sha256:d24fe465…checksum, andupdatedAt: 2026-10-10invault/section-marker-rev.json; prior2.0.0entry untouched. - Artifact tie-out — downloaded the release zip and confirmed its
sha256matches the vault checksum; bundle layout is the standard loaderindex.js→mod.jsplusindex.css,metadata.json, and embedded-TS source maps.
No behavioral concerns in the reviewed diff itself; the change is a mechanical version addition with a matching checksum.
muse-spark-1.3-contributor (free via Pullfrog for OSS) | 𝕏
There was a problem hiding this comment.
Verdict: concerns
Provenance for section-marker-rev@2.0.1: verified at Golevka2001/section-marker-rev@138995e (built by spicetify/actions build-module). Reviewed the source, metadata.json, package.json, and bun.lock at that commit. This review covers source, not the built zip bytes.
Findings:
- Loader-hang hazard (unbounded
awaitin the default-export path):app.tspollsclient.player.data / uri / locale / cosmos / reactwithwhile (...) await new Promise(setTimeout 100ms)and no cap/timeout — https://github.com/Golevka2001/section-marker-rev/blob/138995e873755c120968aa6f5188753568a31b07/app.ts#L22-L24 — awaited through https://github.com/Golevka2001/section-marker-rev/blob/138995e873755c120968aa6f5188753568a31b07/mod.ts#L5-L6 and https://github.com/Golevka2001/section-marker-rev/blob/138995e873755c120968aa6f5188753568a31b07/index.ts#L3-L5. If the surfaces never appear, the module'sloadpromise never settles and can hold up the loader and other modules. Same shape inwaitForElm, which only warns after 5s and never settles — https://github.com/Golevka2001/section-marker-rev/blob/138995e873755c120968aa6f5188753568a31b07/dom-watcher.ts#L8-L42 — awaited at https://github.com/Golevka2001/section-marker-rev/blob/138995e873755c120968aa6f5188753568a31b07/interface.ts#L52. Worth a maintainer's look; bounding startup with a timeout and returning (degraded, no markers) instead of awaiting forever would remove it. - No other concerns found: no
fetch/XHR/WebSocket/EventSource/sendBeaconor remote hosts in runtime code (onlymetadata.jsonpreview/repository URLs); noeval/new Function/remoteimport()/injected<script>/innerHTML; no token/cookie exfiltration (getState()andSpicetify.Queueare only read for current/next track URIs); no daemon token,127.0.0.1:7967,CORSProxy, orspicetify.modules.local.*writes; no obfuscation;stdlibBoundary.exceptionsinmetadata.jsondocument theSpicetify.getAudioData/Spicetify.Queue/playbar-DOM use. Delta vs 2.0.0 per CHANGELOG (per-track cache, timeout-warn fix, width-gate removal, per-section data attributes) matches the reviewed code; no full 2.0.0 source diff performed.
Not reviewed: zip-byte checksum/concealment check against the release artifact (trusted to CI validator + attestation), stylesheet behavior, test files in depth, and runtime execution.
muse-spark-1.3-contributor (free via Pullfrog for OSS) | 𝕏
|
I will add some exception handling measures in the next version. |

Submitted by the publish action from Golevka2001/section-marker-rev. The artifact is downloaded and re-hashed by the validator.