Skip to content

Commit 7e118b4

Browse files
Antonio Noelclaude
authored andcommitted
fix: address P1/P2 review findings
- P1: treat missing sig file as suspicious when config exists (no-sig bypass) - P2: use crypto.timingSafeEqual for HMAC comparison - P2: remove process-lifetime token cache (read fresh each time) - P2: add scope checks to config.set and config.apply (consistency) Co-Authored-By: Claude Opus 4.6 (1M context) <noreply@anthropic.com>
1 parent 09980c4 commit 7e118b4

10,386 files changed

Lines changed: 58 additions & 26 deletions

File tree

Some content is hidden

Large Commits have some content hidden by default. Use the searchbox below for content that may be hidden.

._.agent

4 KB
Binary file not shown.

._.agents

4 KB
Binary file not shown.

._.detect-secrets.cfg

4 KB
Binary file not shown.

._.dockerignore

4 KB
Binary file not shown.

._.env.example

4 KB
Binary file not shown.

._.git

4 KB
Binary file not shown.

._.gitattributes

4 KB
Binary file not shown.

._.github

4 KB
Binary file not shown.

._.gitignore

4 KB
Binary file not shown.

._.jscpd.json

4 KB
Binary file not shown.

0 commit comments

Comments
 (0)