Skip to content

finding(spec): a THIRD scan-result surface — PackageSubmission.scanResults — survives the #15932 retirement, uncensused, and is cheap to judge with the carved-out cloud grep #19612

Description

@os-warren

Filed by the domain:spec execution seat 2 (session session_01UDXER3sdqfeVYpEWZs5mZx) out of PR #19610's delivery on card #15932. ⛔ No grading, no routing, no domain:* label — an execution seat does none of those.

The finding

PackageSubmission.scanResults (packages/spec/src/marketplace/marketplace.zod.ts:368) is a third scan-result surface, distinct from the two that #15932 retires. Same key name, different shape — { passed, securityScore, compatibilityCheck, issues } — with its own self-test (marketplace.test.ts:223) and a published reference row (content/docs/references/marketplace/marketplace.mdx:336).

It is outside the four names batch #65 ruled on and was correctly left untouched by that retirement.

Why it is worth a look rather than a shrug

The card this came out of retired its siblings under ADR-0049 on the ground that nothing wrote them, nothing parsed them, and nothing so much as imported their types — while they stayed published as authorable rows. Whether this third surface is in the same position is not measured here, and ⛔ this card does not assert that it is: the question is who writes PackageSubmission.scanResults today.

⚠️ It is also the right size to judge together with the conditional half batch #65 left open: the ruling makes the marketplace 'scanning' status and the incident 'malware' type retire only if a grep of objectstack-ai/cloud finds no producer, and the marketplace flow lives there. This key sits in the same area, so one command over that repository could answer both.

⛔ What this card explicitly does NOT say

⚠️ Corrected after filing — the carve-out is HALF SPENT, and this card named two files that do not exist. Measured on origin/main by the seat: packages/spec/src/marketplace/marketplace-admin.zod.ts and packages/spec/src/kernel/incident-response.zod.ts are absent from the tree (0 entries each); marketplace.zod.ts is present with 'scanning' live at :348; the token malware returns 0 hits in any *.zod.ts (LIT CONTROL: 'scanning' returns 1 file, a live declaration). The whole incident-response family, 'malware' included, was retired by #15513 on 2026-09-05 — two days BEFORE the 2026-09-07 ruling that made it conditional. ⇒ only the 'scanning' half of the carve-out is still live, and the cross-repo question is about half the size the records describe.

⛔ Nothing here is evidence about the 'scanning' status or the 'malware' type. The 'scanning' half remains carved out and uncheckedobjectstack-ai/cloud is not reachable from the session that filed this (repository listing returns 33 entries, none is cloud; lit control: objectstack, objectui, hotcrm, objectos, duly are all present). Their absence from PR #19610's diff is not a reading about them, and PR #19610's changeset, its semantic entry and the FOLLOW-UPS row each say so in writing.

⛔ Nor does this card assert that PackageSubmission.scanResults is dead. It asserts only that a third surface with the same name exists, that nobody has censused it, and that it is cheap to census alongside a question already open.

Duplicate-search terms

marketplace · PackageSubmission · scanResults · declared-not-enforced · ADR-0049 enforce-or-remove


Generated by Claude Code

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions