Skip to content

Merge pull request #85 from PhysShell/claude/fp-static-class-escape #491

Merge pull request #85 from PhysShell/claude/fp-static-class-escape

Merge pull request #85 from PhysShell/claude/fp-static-class-escape #491

Triggered via push June 22, 2026 11:33
StatusSuccess
Total duration 2m 20s
Artifacts

ci.yml

on: push
lint (ruff + mypy --strict)
11s
lint (ruff + mypy --strict)
extended codegen fuzz
37s
extended codegen fuzz
golden C# compiles & runs (.NET)
24s
golden C# compiles & runs (.NET)
C# leak extractor (Roslyn) -> OwnIR -> core
33s
C# leak extractor (Roslyn) -> OwnIR -> core
own-check repo scan (github + msbuild) + composite action
41s
own-check repo scan (github + msbuild) + composite action
own-check SARIF -> GitHub code scanning (dog-food)
28s
own-check SARIF -> GitHub code scanning (dog-food)
corpus benchmark (real C# recall + specificity)
2m 16s
corpus benchmark (real C# recall + specificity)
Matrix: tests
Fit to window
Zoom out
Zoom in

Annotations

20 errors and 41 warnings
own-check repo scan (github + msbuild) + composite action: frontend/roslyn/samples/FlowLocalsSample.cs#L68
IDisposable local 'whileLeak' is never disposed (leak)
own-check repo scan (github + msbuild) + composite action: frontend/roslyn/samples/FlowLocalsSample.cs#L28
IDisposable local 'leak' may not be disposed on every path (leak)
own-check repo scan (github + msbuild) + composite action: frontend/roslyn/samples/FieldReleaseSample.cs#L45
pooled buffer 'leakedBuf' is rented but never returned to the pool (leak)
own-check repo scan (github + msbuild) + composite action: frontend/roslyn/samples/FieldReleaseSample.cs#L23
IDisposable field 'stream' (type 'MemoryStream') is never disposed — its owner 'NeverDisposesField' leaks it (leak)
own-check repo scan (github + msbuild) + composite action: frontend/roslyn/samples/DisposableFieldViewModel.cs#L10
IDisposable field '_cts' (type 'CancellationTokenSource') is never disposed — its owner 'ReportViewModel' leaks it (leak)
own-check repo scan (github + msbuild) + composite action
singleton 'PrimaryCtorService' captures scoped service 'AppDbContext' (captive dependency: PrimaryCtorService -> AppDbContext)
own-check repo scan (github + msbuild) + composite action
singleton 'CacheService' captures scoped service 'IRepo' (captive dependency: CacheService -> IRepo)
own-check repo scan (github + msbuild) + composite action
singleton 'EmailSender' captures scoped service 'AppDbContext' (captive dependency: EmailSender -> AppDbContext)
OWN001: frontend/roslyn/samples/FlowLocalsSample.cs#L68
[OWN001] IDisposable local 'whileLeak' is never disposed (leak) [resource: disposable]
OWN003: frontend/roslyn/samples/FlowLocalsSample.cs#L38
[OWN003] IDisposable local 'dbl' is disposed more than once [resource: disposable]
OWN001: frontend/roslyn/samples/FlowLocalsSample.cs#L28
[OWN001] IDisposable local 'leak' may not be disposed on every path (leak) [resource: disposable]
OWN002: frontend/roslyn/samples/FlowLocalsSample.cs#L19
[OWN002] IDisposable local 'uad' is used after it is disposed [resource: disposable]
OWN001: frontend/roslyn/samples/FieldReleaseSample.cs#L45
[OWN001] pooled buffer 'leakedBuf' is rented but never returned to the pool (leak) [resource: pooled buffer]
OWN001: frontend/roslyn/samples/FieldReleaseSample.cs#L23
[OWN001] IDisposable field 'stream' (type 'MemoryStream') is never disposed — its owner 'NeverDisposesField' leaks it (leak) [resource: disposable field]
OWN001: frontend/roslyn/samples/DisposableFieldViewModel.cs#L10
[OWN001] IDisposable field '_cts' (type 'CancellationTokenSource') is never disposed — its owner 'ReportViewModel' leaks it (leak) [resource: disposable field]
DI001: frontend/roslyn/samples/DiCaptiveSample.cs#L160
[DI001] singleton 'PrimaryCtorService' captures scoped service 'AppDbContext' (captive dependency: PrimaryCtorService -> AppDbContext) [consumed by the 'PrimaryCtorService' constructor at frontend/roslyn/samples/DiCaptiveSample.cs:33] [resource: DI lifetime]
DI001: frontend/roslyn/samples/DiCaptiveSample.cs#L157
[DI001] singleton 'CacheService' captures scoped service 'IRepo' (captive dependency: CacheService -> IRepo) [consumed by the 'CacheService' constructor at frontend/roslyn/samples/DiCaptiveSample.cs:28] [resource: DI lifetime]
DI001: frontend/roslyn/samples/DiCaptiveSample.cs#L149
[DI001] singleton 'EmailSender' captures scoped service 'AppDbContext' (captive dependency: EmailSender -> AppDbContext) [consumed by the 'EmailSender' constructor at frontend/roslyn/samples/DiCaptiveSample.cs:25] [resource: DI lifetime]
tests (py3.13)
Node.js 20 is deprecated. The following actions target Node.js 20 but are being forced to run on Node.js 24: actions/checkout@v4, actions/setup-python@v5. For more information see: https://github.blog/changelog/2025-09-19-deprecation-of-node-20-on-github-actions-runners/
tests (py3.12)
Node.js 20 is deprecated. The following actions target Node.js 20 but are being forced to run on Node.js 24: actions/checkout@v4, actions/setup-python@v5. For more information see: https://github.blog/changelog/2025-09-19-deprecation-of-node-20-on-github-actions-runners/
tests (py3.11)
Node.js 20 is deprecated. The following actions target Node.js 20 but are being forced to run on Node.js 24: actions/checkout@v4, actions/setup-python@v5. For more information see: https://github.blog/changelog/2025-09-19-deprecation-of-node-20-on-github-actions-runners/
lint (ruff + mypy --strict)
Node.js 20 is deprecated. The following actions target Node.js 20 but are being forced to run on Node.js 24: actions/checkout@v4, actions/setup-python@v5. For more information see: https://github.blog/changelog/2025-09-19-deprecation-of-node-20-on-github-actions-runners/
golden C# compiles & runs (.NET)
Node.js 20 is deprecated. The following actions target Node.js 20 but are being forced to run on Node.js 24: actions/checkout@v4, actions/setup-dotnet@v4, actions/setup-python@v5. For more information see: https://github.blog/changelog/2025-09-19-deprecation-of-node-20-on-github-actions-runners/
own-check SARIF -> GitHub code scanning (dog-food)
Node.js 20 is deprecated. The following actions target Node.js 20 but are being forced to run on Node.js 24: actions/checkout@v4, actions/setup-dotnet@v4, actions/setup-python@v5. For more information see: https://github.blog/changelog/2025-09-19-deprecation-of-node-20-on-github-actions-runners/
own-check SARIF -> GitHub code scanning (dog-food): frontend/roslyn/OwnSharp.Extractor/Program.cs#L1947
Argument of type 'IEnumerable<string?>' cannot be used for parameter 'collection' of type 'IEnumerable<string>' in 'HashSet<string>.HashSet(IEnumerable<string> collection, IEqualityComparer<string>? comparer)' due to differences in the nullability of reference types.
C# leak extractor (Roslyn) -> OwnIR -> core
Node.js 20 is deprecated. The following actions target Node.js 20 but are being forced to run on Node.js 24: actions/checkout@v4, actions/setup-dotnet@v4, actions/setup-python@v5. For more information see: https://github.blog/changelog/2025-09-19-deprecation-of-node-20-on-github-actions-runners/
C# leak extractor (Roslyn) -> OwnIR -> core: frontend/roslyn/OwnSharp.Extractor/Program.cs#L1947
Argument of type 'IEnumerable<string?>' cannot be used for parameter 'collection' of type 'IEnumerable<string>' in 'HashSet<string>.HashSet(IEnumerable<string> collection, IEqualityComparer<string>? comparer)' due to differences in the nullability of reference types.
extended codegen fuzz
Node.js 20 is deprecated. The following actions target Node.js 20 but are being forced to run on Node.js 24: actions/checkout@v4, actions/setup-python@v5. For more information see: https://github.blog/changelog/2025-09-19-deprecation-of-node-20-on-github-actions-runners/
own-check repo scan (github + msbuild) + composite action
singleton 'WeakCache' weakly captures scoped service 'AppDbContext' (WeakReference): 'AppDbContext' is still resolved from the root provider and promoted to application lifetime — the weak reference avoids pinning it for the GC but does not fix the captive-dependency lifetime violation (WeakCache -> AppDbContext)
own-check repo scan (github + msbuild) + composite action
singleton 'ConnectionWarmer' captures transient IDisposable 'PooledConnection': it is promoted to application lifetime and disposed only when the root provider is disposed (ConnectionWarmer -> PooledConnection)
own-check repo scan (github + msbuild) + composite action
singleton 'PrimaryCtorService' captures scoped service 'AppDbContext' (captive dependency: PrimaryCtorService -> AppDbContext)
own-check repo scan (github + msbuild) + composite action
singleton 'CacheService' captures scoped service 'IRepo' (captive dependency: CacheService -> IRepo)
own-check repo scan (github + msbuild) + composite action
singleton 'EmailSender' captures scoped service 'AppDbContext' (captive dependency: EmailSender -> AppDbContext)
own-check repo scan (github + msbuild) + composite action
singleton 'WrapperResolver' resolves transient IDisposable 'PooledConnection' by hand from its injected root IServiceProvider (GetService/GetRequiredService — the service-locator anti-pattern): the root provider tracks every IDisposable it resolves and frees them only at application shutdown, so each call leaks a transient that should be scope-lived — resolve it from an IServiceScope instead (WrapperResolver -> MidConnection -> PooledConnection)
own-check repo scan (github + msbuild) + composite action
singleton 'ExprBodiedResolver' resolves transient IDisposable 'PooledConnection' by hand from its injected root IServiceProvider (GetService/GetRequiredService — the service-locator anti-pattern): the root provider tracks every IDisposable it resolves and frees them only at application shutdown, so each call leaks a transient that should be scope-lived — resolve it from an IServiceScope instead (ExprBodiedResolver -> PooledConnection)
own-check repo scan (github + msbuild) + composite action
singleton 'ConnectionResolver' resolves transient IDisposable 'PooledConnection' by hand from its injected root IServiceProvider (GetService/GetRequiredService — the service-locator anti-pattern): the root provider tracks every IDisposable it resolves and frees them only at application shutdown, so each call leaks a transient that should be scope-lived — resolve it from an IServiceScope instead (ConnectionResolver -> PooledConnection)
own-check repo scan (github + msbuild) + composite action: frontend/roslyn/samples/CustomerViewModel.cs#L15
event 'bus.CustomerChanged' is subscribed (handler 'OnCustomerChanged') but never unsubscribed; its source is an injected dependency whose lifetime is unknown, so it may outlive and keep 'CustomerViewModel' alive (possible leak)
own-check repo scan (github + msbuild) + composite action: frontend/roslyn/samples/AliasedSourceViewModel.cs#L23
event 'src.CustomerChanged' is subscribed (handler 'OnAliased') but never unsubscribed; its source is an injected dependency whose lifetime is unknown, so it may outlive and keep 'AliasedSourceViewModel' alive (possible leak)
own-check repo scan (github + msbuild) + composite action: frontend/roslyn/samples/InjectedDcViewSample.xaml.cs#L22
event '_vm.Changed' is subscribed (handler 'OnChanged') but never unsubscribed; its source is an injected dependency whose lifetime is unknown, so it may outlive and keep 'InjectedDcView' alive (possible leak)
own-check repo scan (github + msbuild) + composite action: frontend/roslyn/samples/ExternalRefSubscription.cs#L20
event '_bus.Changed' is subscribed (handler 'OnChanged') but never unsubscribed; its source is an injected dependency whose lifetime is unknown, so it may outlive and keep 'ExternalRefSubscription' alive (possible leak)
own-check repo scan (github + msbuild) + composite action
singleton 'WeakCacheOpt' weakly captures scoped service 'AppDbContext' (WeakReference): 'AppDbContext' is still resolved from the root provider and promoted to application lifetime — the weak reference avoids pinning it for the GC but does not fix the captive-dependency lifetime violation (WeakCacheOpt -> AppDbContext)
own-check repo scan (github + msbuild) + composite action
singleton 'WeakCache' weakly captures scoped service 'AppDbContext' (WeakReference): 'AppDbContext' is still resolved from the root provider and promoted to application lifetime — the weak reference avoids pinning it for the GC but does not fix the captive-dependency lifetime violation (WeakCache -> AppDbContext)
own-check repo scan (github + msbuild) + composite action
singleton 'ConnectionWarmer' captures transient IDisposable 'PooledConnection': it is promoted to application lifetime and disposed only when the root provider is disposed (ConnectionWarmer -> PooledConnection)
own-check repo scan (github + msbuild) + composite action
singleton 'WrapperResolver' resolves transient IDisposable 'PooledConnection' by hand from its injected root IServiceProvider (GetService/GetRequiredService — the service-locator anti-pattern): the root provider tracks every IDisposable it resolves and frees them only at application shutdown, so each call leaks a transient that should be scope-lived — resolve it from an IServiceScope instead (WrapperResolver -> MidConnection -> PooledConnection)
own-check repo scan (github + msbuild) + composite action
singleton 'ExprBodiedResolver' resolves transient IDisposable 'PooledConnection' by hand from its injected root IServiceProvider (GetService/GetRequiredService — the service-locator anti-pattern): the root provider tracks every IDisposable it resolves and frees them only at application shutdown, so each call leaks a transient that should be scope-lived — resolve it from an IServiceScope instead (ExprBodiedResolver -> PooledConnection)
own-check repo scan (github + msbuild) + composite action
singleton 'ConnectionResolver' resolves transient IDisposable 'PooledConnection' by hand from its injected root IServiceProvider (GetService/GetRequiredService — the service-locator anti-pattern): the root provider tracks every IDisposable it resolves and frees them only at application shutdown, so each call leaks a transient that should be scope-lived — resolve it from an IServiceScope instead (ConnectionResolver -> PooledConnection)
own-check repo scan (github + msbuild) + composite action: frontend/roslyn/samples/CustomerViewModel.cs#L15
event 'bus.CustomerChanged' is subscribed (handler 'OnCustomerChanged') but never unsubscribed; its source is an injected dependency whose lifetime is unknown, so it may outlive and keep 'CustomerViewModel' alive (possible leak)
own-check repo scan (github + msbuild) + composite action: frontend/roslyn/samples/AliasedSourceViewModel.cs#L23
event 'src.CustomerChanged' is subscribed (handler 'OnAliased') but never unsubscribed; its source is an injected dependency whose lifetime is unknown, so it may outlive and keep 'AliasedSourceViewModel' alive (possible leak)
OWN001: frontend/roslyn/samples/ExternalRefSubscription.cs#L20
[OWN001] event '_bus.Changed' is subscribed (handler 'OnChanged') but never unsubscribed; its source is an injected dependency whose lifetime is unknown, so it may outlive and keep 'ExternalRefSubscription' alive (possible leak) [resource: subscription token]
DI002: frontend/roslyn/samples/DiCaptiveSample.cs#L182
[DI002] singleton 'WeakCacheOpt' weakly captures scoped service 'AppDbContext' (WeakReference): 'AppDbContext' is still resolved from the root provider and promoted to application lifetime — the weak reference avoids pinning it for the GC but does not fix the captive-dependency lifetime violation (WeakCacheOpt -> AppDbContext) [consumed by the 'WeakCacheOpt' constructor at frontend/roslyn/samples/DiCaptiveSample.cs:60] [resource: DI lifetime]
DI002: frontend/roslyn/samples/DiCaptiveSample.cs#L179
[DI002] singleton 'WeakCache' weakly captures scoped service 'AppDbContext' (WeakReference): 'AppDbContext' is still resolved from the root provider and promoted to application lifetime — the weak reference avoids pinning it for the GC but does not fix the captive-dependency lifetime violation (WeakCache -> AppDbContext) [consumed by the 'WeakCache' constructor at frontend/roslyn/samples/DiCaptiveSample.cs:57] [resource: DI lifetime]
DI003: frontend/roslyn/samples/DiCaptiveSample.cs#L173
[DI003] singleton 'ConnectionWarmer' captures transient IDisposable 'PooledConnection': it is promoted to application lifetime and disposed only when the root provider is disposed (ConnectionWarmer -> PooledConnection) [consumed by the 'ConnectionWarmer' constructor at frontend/roslyn/samples/DiCaptiveSample.cs:50] [resource: DI lifetime]
DI004: frontend/roslyn/samples/DiCaptiveSample.cs#L137
[DI004] singleton 'WrapperResolver' resolves transient IDisposable 'PooledConnection' by hand from its injected root IServiceProvider (GetService/GetRequiredService — the service-locator anti-pattern): the root provider tracks every IDisposable it resolves and frees them only at application shutdown, so each call leaks a transient that should be scope-lived — resolve it from an IServiceScope instead (WrapperResolver -> MidConnection -> PooledConnection) [singleton registered at frontend/roslyn/samples/DiCaptiveSample.cs:205] [resource: DI lifetime]
DI004: frontend/roslyn/samples/DiCaptiveSample.cs#L123
[DI004] singleton 'ExprBodiedResolver' resolves transient IDisposable 'PooledConnection' by hand from its injected root IServiceProvider (GetService/GetRequiredService — the service-locator anti-pattern): the root provider tracks every IDisposable it resolves and frees them only at application shutdown, so each call leaks a transient that should be scope-lived — resolve it from an IServiceScope instead (ExprBodiedResolver -> PooledConnection) [singleton registered at frontend/roslyn/samples/DiCaptiveSample.cs:201] [resource: DI lifetime]
DI004: frontend/roslyn/samples/DiCaptiveSample.cs#L79
[DI004] singleton 'ConnectionResolver' resolves transient IDisposable 'PooledConnection' by hand from its injected root IServiceProvider (GetService/GetRequiredService — the service-locator anti-pattern): the root provider tracks every IDisposable it resolves and frees them only at application shutdown, so each call leaks a transient that should be scope-lived — resolve it from an IServiceScope instead (ConnectionResolver -> PooledConnection) [singleton registered at frontend/roslyn/samples/DiCaptiveSample.cs:192] [resource: DI lifetime]
OWN001: frontend/roslyn/samples/CustomerViewModel.cs#L15
[OWN001] event 'bus.CustomerChanged' is subscribed (handler 'OnCustomerChanged') but never unsubscribed; its source is an injected dependency whose lifetime is unknown, so it may outlive and keep 'CustomerViewModel' alive (possible leak) [resource: subscription token]
OWN001: frontend/roslyn/samples/AliasedSourceViewModel.cs#L23
[OWN001] event 'src.CustomerChanged' is subscribed (handler 'OnAliased') but never unsubscribed; its source is an injected dependency whose lifetime is unknown, so it may outlive and keep 'AliasedSourceViewModel' alive (possible leak) [resource: subscription token]
own-check repo scan (github + msbuild) + composite action: frontend/roslyn/OwnSharp.Extractor/Program.cs#L1947
Argument of type 'IEnumerable<string?>' cannot be used for parameter 'collection' of type 'IEnumerable<string>' in 'HashSet<string>.HashSet(IEnumerable<string> collection, IEqualityComparer<string>? comparer)' due to differences in the nullability of reference types.
corpus benchmark (real C# recall + specificity)
Node.js 20 is deprecated. The following actions target Node.js 20 but are being forced to run on Node.js 24: actions/checkout@v4, actions/setup-dotnet@v4, actions/setup-python@v5. For more information see: https://github.blog/changelog/2025-09-19-deprecation-of-node-20-on-github-actions-runners/