Files
git.stella-ops.org/src/Scanner/__Libraries/StellaOps.Scanner.Analyzers.Lang.Bun/TASKS.md
StellaOps Bot 6e45066e37
Some checks failed
Concelier Attestation Tests / attestation-tests (push) Has been cancelled
Policy Simulation / policy-simulate (push) Has been cancelled
AOC Guard CI / aoc-guard (push) Has been cancelled
AOC Guard CI / aoc-verify (push) Has been cancelled
Signals CI & Image / signals-ci (push) Has been cancelled
Signals Reachability Scoring & Events / reachability-smoke (push) Has been cancelled
Signals Reachability Scoring & Events / sign-and-upload (push) Has been cancelled
Docs CI / lint-and-preview (push) Has been cancelled
Policy Lint & Smoke / policy-lint (push) Has been cancelled
Scanner Analyzers / Discover Analyzers (push) Has been cancelled
Scanner Analyzers / Build Analyzers (push) Has been cancelled
Scanner Analyzers / Test Language Analyzers (push) Has been cancelled
Scanner Analyzers / Validate Test Fixtures (push) Has been cancelled
Scanner Analyzers / Verify Deterministic Output (push) Has been cancelled
up
2025-12-13 09:37:15 +02:00

1.2 KiB

Bun Analyzer Tasks (Sprint 0407)

Task ID Status Notes Updated (UTC)
SCAN-BUN-407-001 DONE Container-layer aware project discovery (layers/, .layers/, layer*), bounded + deterministic. 2025-12-13
SCAN-BUN-407-002 DONE Declared-only fallback from package.json with safe identities (no range-as-version PURLs). 2025-12-13
SCAN-BUN-407-003 DONE bun.lock v1 graph enrichment (dependency specifiers + deterministic dev/optional/peer classification). 2025-12-13
SCAN-BUN-407-004 DONE Make includeDev meaningful for lockfile-only and installed scans; use scopeUnknown when unsure. 2025-12-13
SCAN-BUN-407-005 DONE Version-specific patch mapping + relative patch paths (no absolute path leakage). 2025-12-13
SCAN-BUN-407-006 DONE Evidence strengthening + locator precision (bun.lock locators, bounded sha256). 2025-12-13
SCAN-BUN-407-007 DONE Identity safety for non-npm sources (git/file/link/workspace/tarball/custom registry). 2025-12-13
SCAN-BUN-407-008 DONE Document analyzer contract under docs/modules/scanner/ and link sprint. 2025-12-13
SCAN-BUN-407-009 DONE Optional: deterministic benchmark if perf risk materializes. 2025-12-13