Repository navigation
fix(meta): replace the discredited 65-90% claim, drop the Windows zone artifact - #14
Merged
Merged
Conversation
…e artifact A security audit of the full history (all 158 git objects) came back clean on credentials, but it flagged two things worth fixing: - plugin.json and marketplace.json still advertised '-65-90% tokens, 0% accuracy loss'. Those are the numbers the v2.2.0 3-arm benchmark disproved; the measured figure is -49% on top of a terse control, and that is what the metadata now says. - 'hooks/cavemenko-statusline.ps1:Zone.Identifier' was a Windows NTFS alternate-data-stream marker committed by accident. Removed, and gitignored so it cannot come back. No secrets were found and none were exposed.
There was a problem hiding this comment.
🔍 Devin Review: 1 flag
Not posted on this PR by your GitHub settings — view it in Devin Review. (Configure)
ruslanlap
added a commit
that referenced
this pull request
Sep 30, 2026
…ions PR #14 fixed the discredited number but left it as free text in three strings (plugin.json, marketplace.json metadata, marketplace.json plugin) with nothing checking them. That is how v2.1.0's invented -65-90% claim reached two files in the first place. Assert the number and the word 'measured' in all three, and fail on the discredited phrasings. Verified failing: replacing plugin.json's description with a vague one trips 2 of the 3 new tests.
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Security audit result: clean, two metadata fixes applied
An audit of the full history (all 158 git objects, every blob across all reachable refs) found no credential material: no AWS keys, no
ghp_/github_pat_, nosk-/sk-ant-, no Slack tokens, no PEM private keys, no JWTs. The maintainer's own PAT has zero occurrences in the repo.git fsck --full --unreachableis clean — no dangling blobs, stashes or scrubbed history. Every host referenced is public (registry.npmjs.org,github.com,img.shields.io,opencollective.com,www.anthropic.com,tidelift.com,nodejs.org,docs.claude.com); no internal host, no local path, no VPS address.Two things it did turn up, both fixed here:
1. The metadata still advertised the discredited number
plugin.jsonandmarketplace.jsonsaid−65-90% tokens, 0% accuracy loss— the exact claim the v2.2.0 three-arm benchmark disproved. A visitor reading the plugin listing, not the README, would still have seen it. Now-49% ... on top of a terse control, measured.This was the same class of error as v2.1.0's fabricated stats: a number nobody had measured, sitting in a file nobody diffs against the benchmark.
2. A Windows NTFS artifact was committed
hooks/cavemenko-statusline.ps1:Zone.Identifieris an alternate-data-stream marker Windows creates when a file is downloaded. It is never source. Removed, and*:Zone.Identifieradded to.gitignoreso it cannot reappear.Not changed
lapin@ucu.edu.uaappears in five commit authors and the tagger fields. That is the maintainer's public contact address, already visible on their GitHub profile — changing it now would rewrite history for no privacy gain.147 tests pass.