deepseek-harness/scripts
Yichen Jiang 590b76a7f0 fix(config): close the review findings on configuration source ownership
Two had real security consequences:

The bootstrap rejection ran on npm dotenv's parser while process.loadEnvFile
applied the file with Node's own. Two independently maintained dialects meant
the check and the thing it guards could disagree: a name Node accepts but the
checker misses would reach process.env unchecked, and BASH_ENV there runs a
file of the project's choosing on every `bash -c` the bash tool issues. Parse
once with node:util's parseEnv — the same engine loadEnvFile uses — and assign
the entries already checked, which also drops the dotenv dependency.

llm-pi-ai still returned a literal profile.apiKey ahead of everything, and it
registers a settings namespace, so the defect removed from llm-deepseek
survived intact in its design twin. The field is gone from the profile schema,
the resolution path, and the tests.

The rest are consistency and documentation defects the review named:

- verify-config-source-ownership did not scan the Python runtime's bundled
  cordis.yml, which still inlined apiKey and baseURL. Both are covered now, and
  the line-anchored INLINE_DENY documents that it is a tripwire, not a parser.
- The deny list missed NODE_TLS_REJECT_UNAUTHORIZED, the askpass hooks, the
  GIT_CONFIG_* redirections, and PYTHONHOME — all implied by its own stated
  rule about what a variable does.
- Snapshot lookups folded case on Windows, where environment names are
  case-insensitive and an exact-match Map could miss a higher-ranked layer.
- The credentials note claimed a read-time permission check was "not taken"
  while this PR implemented it; the credentials-local README still described
  two layers, live process.env reads, dotenv-era limitations, and a renamed
  anchor; the llm-deepseek README still advertised the removed literal apiKey;
  and web.ts and base.cordis.yml kept personal-overlay wording.
- The ownership note's literal-apiKey claim now names its scope: the
  web-search providers keep a literal field but register no settings
  namespace, so nothing can shadow a stored credential through them.
2026-08-05 11:18:06 +08:00
..
fixtures/translation-prompt fix(i18n): harden prompt response handling 2026-07-23 23:12:56 +08:00
snapshots cleanup: remove TUI package and legacy dsh entrypoints 2026-08-04 13:20:28 +08:00
agent-note-tree.ts fix(notes): keep archive helpers internal 2026-07-26 23:29:46 +08:00
AGENTS.md docs(windows): clarify portability rules 2026-07-18 13:03:44 +08:00
archived-agent-notes.spec.ts Merge remote-tracking branch 'origin/master' into worktree/archive-agent-notes-20260726 2026-07-27 00:53:07 +08:00
archived-agent-notes.ts fix(notes): anchor archive seals to prior Git state 2026-07-27 00:01:39 +08:00
build-exe-for-python-sdk.ts cleanup: remove TUI package and legacy dsh entrypoints 2026-08-04 13:20:28 +08:00
build-python-release.py cleanup(build): minimize native payload handling 2026-07-30 01:29:18 +08:00
change-scope.spec.ts refactor(dev-infra): narrow change scope report 2026-07-28 01:02:43 +08:00
change-scope.ts refactor(dev-infra): narrow change scope report 2026-07-28 01:02:43 +08:00
check-expected-filenames.sh ci: reject golden filenames on matching PRs 2026-07-19 21:24:42 +08:00
check-vendor-manifest.sh Add lefthook git hooks with a vendor-manifest guard 2026-06-11 15:07:55 +08:00
check-workspace-constraints.ts cleanup: remove TUI package and legacy dsh entrypoints 2026-08-04 13:20:28 +08:00
ci-workflow.spec.ts fix(ci): isolate pnpm setup per runner 2026-07-29 00:45:52 +08:00
clean.spec.ts fix(build): contain clean targets within repository 2026-07-26 02:51:58 +08:00
clean.ts fix(build): contain clean targets within repository 2026-07-26 02:51:58 +08:00
client-bundle-css.spec.ts feat(ui): complete trajectory request inspection 2026-07-28 09:53:32 +08:00
client-bundle-purity.spec.ts fix(client): load plugin bundles as external scripts 2026-08-04 14:18:47 +08:00
client-tsconfig.spec.ts fix(ci): make local Wine gate portable on macOS 2026-07-27 18:43:00 +08:00
cordis-config-files.spec.ts Stabilize master CI across platforms 2026-07-25 00:10:37 +08:00
cordis-config-files.ts fix(ci): ignore translation records in Cordis config scan 2026-07-23 00:39:55 +08:00
cordis-core-api.spec.ts docs: restore generated Cordis core API 2026-07-20 16:33:44 +08:00
cordis-core-api.ts docs: restore generated Cordis core API 2026-07-20 16:33:44 +08:00
cordis-walk.ts refactor(cordis): generate catalogs from Typert models 2026-07-29 23:55:12 +08:00
coverage-exempt.spec.ts fix(ci): review follow-ups for the coverage lane split 2026-07-31 02:55:37 +08:00
coverage-exempt.ts ci: run coverage-exempt heavy suites uninstrumented in parallel 2026-07-31 02:55:37 +08:00
demo-code-mode.mjs fix(cli): close shared config review gaps 2026-07-30 14:56:39 +08:00
demo-cordis.mjs refactor(cli)!: one shared base config with per-surface overlays 2026-07-29 21:15:42 +08:00
dev-web.spec.ts fix(web): verify current GUI updates end to end 2026-07-29 11:22:48 +08:00
dev-web.ts fix(web): verify current GUI updates end to end 2026-07-29 11:22:48 +08:00
doc-budgets.manifest.json fix(subagent): confirm steering request admission 2026-08-02 04:34:16 +08:00
doc-typecheck-paths.spec.ts fix(docs): map exact source aliases in built checks 2026-07-19 19:26:38 +08:00
doc-typecheck-paths.ts feat(gui): step1 skeleton — dsc web serves built web UI over booted harness host 2026-07-22 16:24:44 +08:00
doc-typecheck.ts Merge remote-tracking branch 'origin/master' into nih-imp-gates 2026-07-27 06:21:53 +08:00
gen-config-catalog.ts Rename RFCs to Agent Notes 2026-07-19 22:52:03 +08:00
gen-cordis-api.ts refactor(cordis): generate catalogs from Typert models 2026-07-29 23:55:12 +08:00
gen-cordis-catalog.ts cleanup: remove TUI package and legacy dsh entrypoints 2026-08-04 13:20:28 +08:00
gen-doc-graphs.spec.ts fix(scripts): share package-source selection to clear the jscpd clone 2026-07-30 19:57:17 +08:00
gen-doc-graphs.ts cleanup: remove TUI package and legacy dsh entrypoints 2026-08-04 13:20:28 +08:00
gen-module-graph.ts refactor(acp): reduce bridge to automation protocol 2026-07-24 01:40:25 +08:00
gen-persistence-catalog.ts docs(notes): aggressive archive sweep of low-value decision records 2026-07-28 00:00:51 +08:00
gen-scoped-events.ts refactor(tsconfig): single root solution graph over host/client aggregates 2026-07-23 03:59:05 +08:00
gen-third-party-notices.spec.ts fix(fs-search): address the second-round #1119 review 2026-08-02 01:11:08 +08:00
gen-third-party-notices.ts fix(fs-search): address the second-round #1119 review 2026-08-02 01:11:08 +08:00
gen-tool-catalog.ts Merge remote-tracking branch 'origin/master' into feat/ripgrep-packaged-binary 2026-08-02 16:18:46 +08:00
gen-translation-brief.ts feat(i18n): unit-mapped briefings with mechanical --apply, adopting the #684 planner mechanics 2026-07-27 02:31:07 +08:00
hero-composer-dom-continuity.mjs docs(web): the composer bar is one session-maybe slot, not a swapped pair 2026-07-30 15:18:06 +08:00
install-lefthook.mjs fix(ci): tolerate initializing Lefthook lock 2026-07-30 20:17:04 -07:00
install-lefthook.spec.ts fix(ci): stabilize merged coverage gates 2026-07-30 20:52:35 -07:00
install.sh cleanup: remove TUI package and legacy dsh entrypoints 2026-08-04 13:20:28 +08:00
jsdoc.ts feat: slash system / input service / agent scope 2026-07-27 03:28:39 +08:00
lint-rule-fingerprint.spec.ts test: make lint profile fingerprint honest 2026-07-29 23:26:16 +08:00
markdown.ts fix(scripts): address review findings on the gate consolidation 2026-07-27 12:02:39 +08:00
migrate-packed-session-fixtures.ts feat(session): default JSONL writes to packed rows 2026-07-26 23:44:52 +08:00
oxlint-contract.spec.ts fix: allow ignored-only staged lint 2026-07-29 23:36:08 +08:00
package-graph.ts fix: normalize glob paths with split(sep).join('/') on Windows 2026-07-15 19:11:20 +08:00
package-invariants.spec.ts fix(invariants): harden runtime contracts and gates 2026-07-21 00:25:38 +08:00
package-invariants.ts fix(invariants): harden runtime contracts and gates 2026-07-21 00:25:38 +08:00
paired-markdown-derivatives.spec.ts docs: deduplicate paired code-block checks 2026-07-26 02:52:48 +08:00
paired-markdown-derivatives.ts docs: deduplicate paired code-block checks 2026-07-26 02:52:48 +08:00
prepare-ci-bubblewrap.sh docs: record final larger-runner evidence 2026-07-22 16:55:39 +08:00
project-doc-site.spec.ts fix(docs): index the full persistence outline 2026-07-31 13:47:51 +08:00
project-doc-site.ts fix(docs): index persistence events in page outline 2026-07-31 13:43:03 +08:00
publint-all.spec.ts feat(dev-infra): make gate plans inspectable and replayable 2026-07-27 21:27:42 +08:00
publint-all.ts fix(scripts): address review findings on the gate consolidation 2026-07-27 12:02:39 +08:00
repo-files.ts Merge remote-tracking branch 'origin/master' into worktree/archive-agent-notes-20260726 2026-07-27 00:53:07 +08:00
run-gates.spec.ts Merge remote-tracking branch 'origin/master' into fix/node26-vitest-webstorage 2026-07-31 10:26:05 +08:00
run-gates.ts Merge branch 'master' into claude/unified-environment-credentials-c8841a 2026-08-04 17:51:44 +08:00
run-oxlint.spec.ts refactor: centralize Oxlint worker bounds 2026-07-29 23:39:49 +08:00
run-oxlint.ts refactor: centralize Oxlint worker bounds 2026-07-29 23:39:49 +08:00
session-fixture-layout.snapshot.ts feat(session): default JSONL writes to packed rows 2026-07-26 23:44:52 +08:00
session-fixture-layout.spec.ts fix(scripts): complete fixture migration diagnostics 2026-07-27 03:54:33 +08:00
session-fixture-layout.ts fix(scripts): complete fixture migration diagnostics 2026-07-27 03:54:33 +08:00
smoke-python-runtime.py Merge branch 'worktree-llm-dynamic-config' into worktree-llm-web-config 2026-07-30 20:15:40 +08:00
test-invariants.spec.ts fix(test): preserve invariant config failures 2026-07-31 10:41:44 +08:00
test-invariants.ts fix(test): preserve invariant config failures 2026-07-31 10:41:44 +08:00
translation-brief.spec.ts feat(i18n): unit-mapped briefings with mechanical --apply, adopting the #684 planner mechanics 2026-07-27 02:31:07 +08:00
translation-brief.ts feat(i18n): unit-mapped briefings with mechanical --apply, adopting the #684 planner mechanics 2026-07-27 02:31:07 +08:00
translation-pairing-git.ts fix(i18n): pin translation snapshots against gc 2026-07-28 10:28:49 -07:00
translation-pairing.manifest.json docs(subprocess): bilingual pair for the consumer-migration Agent Note 2026-07-26 15:51:24 +08:00
translation-pairing.spec.ts fix(i18n): pin translation snapshots against gc 2026-07-28 10:28:49 -07:00
translation-pairing.ts Merge remote-tracking branch 'origin/master' into worktree-i18n-update-workflow 2026-07-27 09:39:54 +08:00
translation-prompt.snapshot.ts fix(i18n): complete prompt v4 pipeline path 2026-07-23 22:41:53 +08:00
translation-prompt.spec.ts fix(i18n): harden prompt response handling 2026-07-23 23:12:56 +08:00
translation-prompt.ts fix(i18n): harden prompt response handling 2026-07-23 23:12:56 +08:00
ts-project.ts fix(build): reuse TypeScript config host 2026-07-26 00:30:20 +08:00
type-equiv.manifest.json feat(subagent): add explicit child reports 2026-08-02 12:51:10 +08:00
verify-agent-note-classification.ts Remove generated Agent Note index 2026-07-19 23:15:23 +08:00
verify-agent-note-format.ts Remove generated Agent Note index 2026-07-19 23:15:23 +08:00
verify-archived-agent-notes.ts fix(notes): anchor archive seals to prior Git state 2026-07-27 00:01:39 +08:00
verify-built-package-invariants.mjs refactor(scripts): consolidate gate scripts on mdast fences, parseArgs, and globSync 2026-07-26 23:14:28 +08:00
verify-built-package-invariants.spec.ts ci: enforce bounded build lanes 2026-07-21 20:15:09 +08:00
verify-client-domain-graph.ts refactor(scripts): consolidate gate scripts on mdast fences, parseArgs, and globSync 2026-07-26 23:14:28 +08:00
verify-config-source-ownership.ts fix(config): close the review findings on configuration source ownership 2026-08-05 11:18:06 +08:00
verify-cordis-config.ts feat(examples): add generic memory MCP overlays 2026-07-31 02:00:14 -07:00
verify-doc-budgets.ts docs: rebalance prose cleanup and add trimming skill 2026-07-13 23:27:00 +08:00
verify-doc-refs.ts Rename RFCs to Agent Notes 2026-07-19 22:52:03 +08:00
verify-export-jsdoc.ts refactor: migrate linting to Oxlint 2026-07-29 14:32:11 +08:00
verify-md-links.ts feat(skills): bundle and harden personal maintenance workflows 2026-07-27 18:53:30 +08:00
verify-md-wrap.ts docs(notes): archive low-value decision records 2026-07-26 23:06:00 +08:00
verify-mermaid.ts feat(skills): bundle and harden personal maintenance workflows 2026-07-27 18:53:30 +08:00
verify-node-next-types.ts fix(scripts): run publint/tsc via node JS entry, not a shell .cmd shim 2026-07-15 16:38:22 +08:00
verify-package-invariants.ts feat(invariants): implement package runtime checks 2026-07-20 00:38:37 +08:00
verify-package-paths.ts Merge remote-tracking branch 'origin/master' into nih-imp-gates 2026-07-27 06:21:53 +08:00
verify-package-readme-limitations.ts Rename RFCs to Agent Notes 2026-07-19 22:52:03 +08:00
verify-package-readme-model-experience.ts feat(config)!: one ordering for configuration sources, and a bootstrap deny rule 2026-08-04 16:17:32 +08:00
verify-runtime-closure.ts refactor(scripts): consolidate gate scripts on mdast fences, parseArgs, and globSync 2026-07-26 23:14:28 +08:00
verify-translation-pairing.ts fix(i18n): persist uncommitted translation snapshots 2026-07-28 04:34:05 -07:00
verify-translation-prompt.ts fix(i18n): harden prompt response handling 2026-07-23 23:12:56 +08:00
verify-type-equiv.ts fix(scripts): address review findings on the gate consolidation 2026-07-27 12:02:39 +08:00
verify-vendored-links.ts fix(review): label host-preparation failures and gate vendored lockfile links 2026-08-02 01:25:01 +08:00
vitest-environment.compat.spec.ts fix(test): isolate jsdom storage on Node 26 2026-07-30 21:49:33 +08:00
wine-windows-gates.sh fix(ci): retry the Wine lane's pnpm install on the hoisted-linker rename race 2026-07-28 16:16:10 +08:00