Harness Intelligence Wiki
SpecsCLIRegistry Baseline

Registry Baseline: code review 1

Registry Baseline code review 1

  • Target: git diff origin/main...d43e0f302 on team/stefan/registry-baseline.
  • Governing sources: SPEC.md (a89796e7), ARCHITECTURE.md (3e63ec3c), PLAN.md D1 to D16.
  • Reviewers: primary comprehensive (Standards, Spec, architecture, simplify) and an independent security and data-loss challenger. Lint and format debt were out of scope by user instruction.
  • Primary verdict: do not merge before repair. Challenger verdict: conditionally safe (no critical or high).

Findings and routes

IdSeverityAreaFindingRoute
P-F1highlintInterrupted first adoption seeds an empty oxlint.local.ts (Built config written first)repair (R2)
P-F2highCommit GateDeletion-only commit fails files-mode coveragerepair (R2)
P-F3mediumpipelineMigration mutates before STEP-004; refusal says "Nothing was written" (AC-018)repair (R1a)
P-F4mediumshapeInstaller-written .ts files flip JS workspaces to TypeScriptrepair (R1b)
P-F5mediumlintUnevaluable existing config seeds empty local filerepair (R2)
P-F6mediumdepsProject's own devDependency recorded as installer-added, later removedrepair (R1b)
P-F7mediummigrationLocally edited Copied files overwritten on first update without --yesrepair (R1a)
P-F8mediumreleaseRe-run after partial publish never convergesrepair (R3)
P-F9lowdriftInstalled render uses current settingsdebt
P-F10lowpipelineTwo text normalizers disagreerepair (R1a)
P-F11lowversion rangePrerelease of the upper bound satisfies <X.Y.Zdebt
P-F12lowreleaseRoot catalog written before version catalogrepair (R3)
P-F13lowmigrationArchived skill with a managed id is droppeddebt (needs user decision)
P-F14lowhooksExisting .codex/config.toml never gets Codex hooks (Authored, per spec)none
S-F1mediumsecuritypostInstall from the network runs with full env; settings registry accepts any schemerepair (R1a allowlist + minimal env, R1b https-only settings URL); signing is debt
S-F2mediumsecurityCatalog item name can escape the cache directoryrepair (R1b)
S-F3mediumdata lossSymlinked merge target replaced by a filerepair (R1a)
S-F4mediumdata lossStale removal deletes locally edited Copied filesrepair (R1a)
S-F5lowdata lossMigration deletes archives it never readdebt
S-F6lowsecurityhi diff/hi update import repository manifest.mjs (runs repo code)debt (documented)
S-F7lowsecurityRewrites drop file modesrepair (R1a)
P-A1lowarchitectureDuplicated helpers (canonical JSON, byte compare, item fetch), init double catalog fetch, runners inside pipeline.tsdebt

Spec coverage from the primary pass: 25 of 37 AC fully tested, 11 partially tested, AC-018 partially met (P-F3), none missing. Gaps are listed in the primary report; live evidence for AC-004, AC-005, AC-009, AC-014, AC-018, AC-024, AC-026, AC-027, AC-029, AC-031 and AC-034 is recorded in IMPLEMENTATION-NOTES.

Repair validation

  • Repairs landed for P-F1, P-F2, P-F3, P-F4, P-F5, P-F6, P-F7, P-F8, P-F10, P-F12, S-F1 (CLI allowlist, minimal environment, https-only settings Registry URL, non-default Registry notice), S-F2, S-F3, S-F4, S-F7, each with a regression test that failed before its fix.
  • Focused Repair Validation: apps/cli test:source 512 passed, test:release 74 passed, check-types clean.
  • The repairs changed a public-contract edge (settings registry accepts https only) and security behavior (post-install allowlist); both are covered by the challenger findings they close. A second full review pass was not opened; debt items stay recorded above.
  • Behavior notes: the release readback now also accepts a newer latest that publishing deliberately kept (never moves latest back); a rename out of a Software Scope still needs Commit Gate coverage.

On this page