You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
{{ message }}
Repository navigation
Commit 98932b8
Browse filesBrowse the repository at this point in the historyBrowse files
fix(observability-map): name the suppression directive honestly, and tighten the tests
obs-map-disable-next-line applied to the whole entry point, so a directive on
the last line of a file switched a check off for everything above it. Scoping
it to a line is not available, since a finding is attached to an entry point and
carries no line number to match against, and inventing a proximity rule would
silently drop legitimate suppressions. So the name is now obs-map-disable, which
is what it does. The old spelling is not honoured and a test says so.
The CONTEXT line now says how many of the collapsed entries are sensitive, 18 of
333, so a reader knows to open the JSON rather than trusting the list.
Three tests were passing by luck. The FIX FIRST ordering test sliced on a string
the report no longer prints, so its assertions ran against the whole tail. The
--no-write test never checked that no file was written, so it would have written
into the repo root if the flag broke. A suppression test asserted toContain('1')
against a report full of digits, and another never asserted the measured flag it
was named for.
README corrected: the score is 18, auth-boundary applies to 23 entry points
rather than 26 and gates on sensitivity before the one-hop limit, and the
invariant section now states both directions.
0 commit comments