forked from heavy-duty/ceremony
@codex-reviewer-andresmgsl's three findings (#4712), each a route by which
an unprovable read could still be reported as a whole one — the guard
leaking the failure class it exists to stop.
1. x-total-count was never validated. `X-Total-Count: not-a-number` returned
rc=0 with that string as the bound the walk compared against, reproduced
on
|
||
|---|---|---|
| .. | ||
| changelog.sh | ||
| closes_references.sh | ||
| decide.sh | ||
| facts.sh | ||
| forge-forgejo.sh | ||
| forge-github.sh | ||
| forge.sh | ||
| ruling.sh | ||
| version.sh | ||