Skip to content

fix(meta): replace the discredited 65-90% claim, drop the Windows zone artifact - #14

Merged
ruslanlap merged 1 commit into
masterfrom
fix/plugin-metadata-honesty
Sep 30, 2026
Merged

ruslanlap merged 1 commit into
masterfrom
fix/plugin-metadata-honesty

Conversation

@ruslanlap

@ruslanlap ruslanlap commented Sep 30, 2026 •

Copy link
Copy Markdown
Owner

Security audit result: clean, two metadata fixes applied

An audit of the full history (all 158 git objects, every blob across all reachable refs) found no credential material: no AWS keys, no ghp_/github_pat_, no sk-/sk-ant-, no Slack tokens, no PEM private keys, no JWTs. The maintainer's own PAT has zero occurrences in the repo. git fsck --full --unreachable is clean — no dangling blobs, stashes or scrubbed history. Every host referenced is public (registry.npmjs.org, github.com, img.shields.io, opencollective.com, www.anthropic.com, tidelift.com, nodejs.org, docs.claude.com); no internal host, no local path, no VPS address.

Two things it did turn up, both fixed here:

1. The metadata still advertised the discredited number

plugin.json and marketplace.json said −65-90% tokens, 0% accuracy loss — the exact claim the v2.2.0 three-arm benchmark disproved. A visitor reading the plugin listing, not the README, would still have seen it. Now -49% ... on top of a terse control, measured.

This was the same class of error as v2.1.0's fabricated stats: a number nobody had measured, sitting in a file nobody diffs against the benchmark.

2. A Windows NTFS artifact was committed

hooks/cavemenko-statusline.ps1:Zone.Identifier is an alternate-data-stream marker Windows creates when a file is downloaded. It is never source. Removed, and *:Zone.Identifier added to .gitignore so it cannot reappear.

Not changed

lapin@ucu.edu.ua appears in five commit authors and the tagger fields. That is the maintainer's public contact address, already visible on their GitHub profile — changing it now would rewrite history for no privacy gain.

147 tests pass.


Devin Review

…e artifact

A security audit of the full history (all 158 git objects) came back clean
on credentials, but it flagged two things worth fixing:

- plugin.json and marketplace.json still advertised '-65-90% tokens, 0%
  accuracy loss'. Those are the numbers the v2.2.0 3-arm benchmark
  disproved; the measured figure is -49% on top of a terse control, and
  that is what the metadata now says.
- 'hooks/cavemenko-statusline.ps1:Zone.Identifier' was a Windows NTFS
  alternate-data-stream marker committed by accident. Removed, and
  gitignored so it cannot come back.

No secrets were found and none were exposed.

@devin-ai-integration devin-ai-integration Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

🔍 Devin Review: 1 flag

Not posted on this PR by your GitHub settings — view it in Devin Review. (Configure)

Devin Review

@ruslanlap
ruslanlap merged commit 6e8a027 into master Sep 30, 2026
4 checks passed
@ruslanlap
ruslanlap deleted the fix/plugin-metadata-honesty branch September 30, 2026 08:32
ruslanlap added a commit that referenced this pull request Sep 30, 2026
…ions

PR #14 fixed the discredited number but left it as free text in three
strings (plugin.json, marketplace.json metadata, marketplace.json plugin)
with nothing checking them. That is how v2.1.0's invented -65-90% claim
reached two files in the first place. Assert the number and the word
'measured' in all three, and fail on the discredited phrasings.

Verified failing: replacing plugin.json's description with a vague one
trips 2 of the 3 new tests.
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant