Merge pull request #85 from PhysShell/claude/fp-static-class-escape #491
ci.yml
on: push
lint (ruff + mypy --strict)
11s
extended codegen fuzz
37s
golden C# compiles & runs (.NET)
24s
C# leak extractor (Roslyn) -> OwnIR -> core
33s
own-check repo scan (github + msbuild) + composite action
41s
own-check SARIF -> GitHub code scanning (dog-food)
28s
corpus benchmark (real C# recall + specificity)
2m 16s
Matrix: tests
Annotations
20 errors and 41 warnings
own-check repo scan (github + msbuild) + composite action:
frontend/roslyn/samples/FlowLocalsSample.cs#L68
IDisposable local 'whileLeak' is never disposed (leak) |
own-check repo scan (github + msbuild) + composite action:
frontend/roslyn/samples/FlowLocalsSample.cs#L38
IDisposable local 'dbl' is disposed more than once |
own-check repo scan (github + msbuild) + composite action:
frontend/roslyn/samples/FlowLocalsSample.cs#L28
IDisposable local 'leak' may not be disposed on every path (leak) |
own-check repo scan (github + msbuild) + composite action:
frontend/roslyn/samples/FlowLocalsSample.cs#L19
IDisposable local 'uad' is used after it is disposed |
own-check repo scan (github + msbuild) + composite action:
frontend/roslyn/samples/FieldReleaseSample.cs#L45
pooled buffer 'leakedBuf' is rented but never returned to the pool (leak) |
own-check repo scan (github + msbuild) + composite action:
frontend/roslyn/samples/FieldReleaseSample.cs#L23
IDisposable field 'stream' (type 'MemoryStream') is never disposed — its owner 'NeverDisposesField' leaks it (leak) |
own-check repo scan (github + msbuild) + composite action:
frontend/roslyn/samples/DisposableFieldViewModel.cs#L10
IDisposable field '_cts' (type 'CancellationTokenSource') is never disposed — its owner 'ReportViewModel' leaks it (leak) |
own-check repo scan (github + msbuild) + composite action singleton 'PrimaryCtorService' captures scoped service 'AppDbContext' (captive dependency: PrimaryCtorService -> AppDbContext) |
own-check repo scan (github + msbuild) + composite action singleton 'CacheService' captures scoped service 'IRepo' (captive dependency: CacheService -> IRepo) |
own-check repo scan (github + msbuild) + composite action singleton 'EmailSender' captures scoped service 'AppDbContext' (captive dependency: EmailSender -> AppDbContext) |
OWN001:
frontend/roslyn/samples/FlowLocalsSample.cs#L68
[OWN001] IDisposable local 'whileLeak' is never disposed (leak) [resource: disposable] |
OWN003:
frontend/roslyn/samples/FlowLocalsSample.cs#L38
[OWN003] IDisposable local 'dbl' is disposed more than once [resource: disposable] |
OWN001:
frontend/roslyn/samples/FlowLocalsSample.cs#L28
[OWN001] IDisposable local 'leak' may not be disposed on every path (leak) [resource: disposable] |
OWN002:
frontend/roslyn/samples/FlowLocalsSample.cs#L19
[OWN002] IDisposable local 'uad' is used after it is disposed [resource: disposable] |
OWN001:
frontend/roslyn/samples/FieldReleaseSample.cs#L45
[OWN001] pooled buffer 'leakedBuf' is rented but never returned to the pool (leak) [resource: pooled buffer] |
OWN001:
frontend/roslyn/samples/FieldReleaseSample.cs#L23
[OWN001] IDisposable field 'stream' (type 'MemoryStream') is never disposed — its owner 'NeverDisposesField' leaks it (leak) [resource: disposable field] |
OWN001:
frontend/roslyn/samples/DisposableFieldViewModel.cs#L10
[OWN001] IDisposable field '_cts' (type 'CancellationTokenSource') is never disposed — its owner 'ReportViewModel' leaks it (leak) [resource: disposable field] |
DI001:
frontend/roslyn/samples/DiCaptiveSample.cs#L160
[DI001] singleton 'PrimaryCtorService' captures scoped service 'AppDbContext' (captive dependency: PrimaryCtorService -> AppDbContext) [consumed by the 'PrimaryCtorService' constructor at frontend/roslyn/samples/DiCaptiveSample.cs:33] [resource: DI lifetime] |
DI001:
frontend/roslyn/samples/DiCaptiveSample.cs#L157
[DI001] singleton 'CacheService' captures scoped service 'IRepo' (captive dependency: CacheService -> IRepo) [consumed by the 'CacheService' constructor at frontend/roslyn/samples/DiCaptiveSample.cs:28] [resource: DI lifetime] |
DI001:
frontend/roslyn/samples/DiCaptiveSample.cs#L149
[DI001] singleton 'EmailSender' captures scoped service 'AppDbContext' (captive dependency: EmailSender -> AppDbContext) [consumed by the 'EmailSender' constructor at frontend/roslyn/samples/DiCaptiveSample.cs:25] [resource: DI lifetime] |
tests (py3.13) Node.js 20 is deprecated. The following actions target Node.js 20 but are being forced to run on Node.js 24: actions/checkout@v4, actions/setup-python@v5. For more information see: https://github.blog/changelog/2025-09-19-deprecation-of-node-20-on-github-actions-runners/ |
tests (py3.12) Node.js 20 is deprecated. The following actions target Node.js 20 but are being forced to run on Node.js 24: actions/checkout@v4, actions/setup-python@v5. For more information see: https://github.blog/changelog/2025-09-19-deprecation-of-node-20-on-github-actions-runners/ |
tests (py3.11) Node.js 20 is deprecated. The following actions target Node.js 20 but are being forced to run on Node.js 24: actions/checkout@v4, actions/setup-python@v5. For more information see: https://github.blog/changelog/2025-09-19-deprecation-of-node-20-on-github-actions-runners/ |
lint (ruff + mypy --strict) Node.js 20 is deprecated. The following actions target Node.js 20 but are being forced to run on Node.js 24: actions/checkout@v4, actions/setup-python@v5. For more information see: https://github.blog/changelog/2025-09-19-deprecation-of-node-20-on-github-actions-runners/ |
golden C# compiles & runs (.NET) Node.js 20 is deprecated. The following actions target Node.js 20 but are being forced to run on Node.js 24: actions/checkout@v4, actions/setup-dotnet@v4, actions/setup-python@v5. For more information see: https://github.blog/changelog/2025-09-19-deprecation-of-node-20-on-github-actions-runners/ |
own-check SARIF -> GitHub code scanning (dog-food) Node.js 20 is deprecated. The following actions target Node.js 20 but are being forced to run on Node.js 24: actions/checkout@v4, actions/setup-dotnet@v4, actions/setup-python@v5. For more information see: https://github.blog/changelog/2025-09-19-deprecation-of-node-20-on-github-actions-runners/ |
own-check SARIF -> GitHub code scanning (dog-food):
frontend/roslyn/OwnSharp.Extractor/Program.cs#L1947
Argument of type 'IEnumerable<string?>' cannot be used for parameter 'collection' of type 'IEnumerable<string>' in 'HashSet<string>.HashSet(IEnumerable<string> collection, IEqualityComparer<string>? comparer)' due to differences in the nullability of reference types. |
C# leak extractor (Roslyn) -> OwnIR -> core Node.js 20 is deprecated. The following actions target Node.js 20 but are being forced to run on Node.js 24: actions/checkout@v4, actions/setup-dotnet@v4, actions/setup-python@v5. For more information see: https://github.blog/changelog/2025-09-19-deprecation-of-node-20-on-github-actions-runners/ |
C# leak extractor (Roslyn) -> OwnIR -> core:
frontend/roslyn/OwnSharp.Extractor/Program.cs#L1947
Argument of type 'IEnumerable<string?>' cannot be used for parameter 'collection' of type 'IEnumerable<string>' in 'HashSet<string>.HashSet(IEnumerable<string> collection, IEqualityComparer<string>? comparer)' due to differences in the nullability of reference types. |
extended codegen fuzz Node.js 20 is deprecated. The following actions target Node.js 20 but are being forced to run on Node.js 24: actions/checkout@v4, actions/setup-python@v5. For more information see: https://github.blog/changelog/2025-09-19-deprecation-of-node-20-on-github-actions-runners/ |
own-check repo scan (github + msbuild) + composite action singleton 'WeakCache' weakly captures scoped service 'AppDbContext' (WeakReference): 'AppDbContext' is still resolved from the root provider and promoted to application lifetime — the weak reference avoids pinning it for the GC but does not fix the captive-dependency lifetime violation (WeakCache -> AppDbContext) |
own-check repo scan (github + msbuild) + composite action singleton 'ConnectionWarmer' captures transient IDisposable 'PooledConnection': it is promoted to application lifetime and disposed only when the root provider is disposed (ConnectionWarmer -> PooledConnection) |
own-check repo scan (github + msbuild) + composite action singleton 'PrimaryCtorService' captures scoped service 'AppDbContext' (captive dependency: PrimaryCtorService -> AppDbContext) |
own-check repo scan (github + msbuild) + composite action singleton 'CacheService' captures scoped service 'IRepo' (captive dependency: CacheService -> IRepo) |
own-check repo scan (github + msbuild) + composite action singleton 'EmailSender' captures scoped service 'AppDbContext' (captive dependency: EmailSender -> AppDbContext) |
own-check repo scan (github + msbuild) + composite action singleton 'WrapperResolver' resolves transient IDisposable 'PooledConnection' by hand from its injected root IServiceProvider (GetService/GetRequiredService — the service-locator anti-pattern): the root provider tracks every IDisposable it resolves and frees them only at application shutdown, so each call leaks a transient that should be scope-lived — resolve it from an IServiceScope instead (WrapperResolver -> MidConnection -> PooledConnection) |
own-check repo scan (github + msbuild) + composite action singleton 'ExprBodiedResolver' resolves transient IDisposable 'PooledConnection' by hand from its injected root IServiceProvider (GetService/GetRequiredService — the service-locator anti-pattern): the root provider tracks every IDisposable it resolves and frees them only at application shutdown, so each call leaks a transient that should be scope-lived — resolve it from an IServiceScope instead (ExprBodiedResolver -> PooledConnection) |
own-check repo scan (github + msbuild) + composite action singleton 'ConnectionResolver' resolves transient IDisposable 'PooledConnection' by hand from its injected root IServiceProvider (GetService/GetRequiredService — the service-locator anti-pattern): the root provider tracks every IDisposable it resolves and frees them only at application shutdown, so each call leaks a transient that should be scope-lived — resolve it from an IServiceScope instead (ConnectionResolver -> PooledConnection) |
own-check repo scan (github + msbuild) + composite action:
frontend/roslyn/samples/CustomerViewModel.cs#L15
event 'bus.CustomerChanged' is subscribed (handler 'OnCustomerChanged') but never unsubscribed; its source is an injected dependency whose lifetime is unknown, so it may outlive and keep 'CustomerViewModel' alive (possible leak) |
own-check repo scan (github + msbuild) + composite action:
frontend/roslyn/samples/AliasedSourceViewModel.cs#L23
event 'src.CustomerChanged' is subscribed (handler 'OnAliased') but never unsubscribed; its source is an injected dependency whose lifetime is unknown, so it may outlive and keep 'AliasedSourceViewModel' alive (possible leak) |
own-check repo scan (github + msbuild) + composite action:
frontend/roslyn/samples/InjectedDcViewSample.xaml.cs#L22
event '_vm.Changed' is subscribed (handler 'OnChanged') but never unsubscribed; its source is an injected dependency whose lifetime is unknown, so it may outlive and keep 'InjectedDcView' alive (possible leak) |
own-check repo scan (github + msbuild) + composite action:
frontend/roslyn/samples/ExternalRefSubscription.cs#L20
event '_bus.Changed' is subscribed (handler 'OnChanged') but never unsubscribed; its source is an injected dependency whose lifetime is unknown, so it may outlive and keep 'ExternalRefSubscription' alive (possible leak) |
own-check repo scan (github + msbuild) + composite action singleton 'WeakCacheOpt' weakly captures scoped service 'AppDbContext' (WeakReference): 'AppDbContext' is still resolved from the root provider and promoted to application lifetime — the weak reference avoids pinning it for the GC but does not fix the captive-dependency lifetime violation (WeakCacheOpt -> AppDbContext) |
own-check repo scan (github + msbuild) + composite action singleton 'WeakCache' weakly captures scoped service 'AppDbContext' (WeakReference): 'AppDbContext' is still resolved from the root provider and promoted to application lifetime — the weak reference avoids pinning it for the GC but does not fix the captive-dependency lifetime violation (WeakCache -> AppDbContext) |
own-check repo scan (github + msbuild) + composite action singleton 'ConnectionWarmer' captures transient IDisposable 'PooledConnection': it is promoted to application lifetime and disposed only when the root provider is disposed (ConnectionWarmer -> PooledConnection) |
own-check repo scan (github + msbuild) + composite action singleton 'WrapperResolver' resolves transient IDisposable 'PooledConnection' by hand from its injected root IServiceProvider (GetService/GetRequiredService — the service-locator anti-pattern): the root provider tracks every IDisposable it resolves and frees them only at application shutdown, so each call leaks a transient that should be scope-lived — resolve it from an IServiceScope instead (WrapperResolver -> MidConnection -> PooledConnection) |
own-check repo scan (github + msbuild) + composite action singleton 'ExprBodiedResolver' resolves transient IDisposable 'PooledConnection' by hand from its injected root IServiceProvider (GetService/GetRequiredService — the service-locator anti-pattern): the root provider tracks every IDisposable it resolves and frees them only at application shutdown, so each call leaks a transient that should be scope-lived — resolve it from an IServiceScope instead (ExprBodiedResolver -> PooledConnection) |
own-check repo scan (github + msbuild) + composite action singleton 'ConnectionResolver' resolves transient IDisposable 'PooledConnection' by hand from its injected root IServiceProvider (GetService/GetRequiredService — the service-locator anti-pattern): the root provider tracks every IDisposable it resolves and frees them only at application shutdown, so each call leaks a transient that should be scope-lived — resolve it from an IServiceScope instead (ConnectionResolver -> PooledConnection) |
own-check repo scan (github + msbuild) + composite action:
frontend/roslyn/samples/CustomerViewModel.cs#L15
event 'bus.CustomerChanged' is subscribed (handler 'OnCustomerChanged') but never unsubscribed; its source is an injected dependency whose lifetime is unknown, so it may outlive and keep 'CustomerViewModel' alive (possible leak) |
own-check repo scan (github + msbuild) + composite action:
frontend/roslyn/samples/AliasedSourceViewModel.cs#L23
event 'src.CustomerChanged' is subscribed (handler 'OnAliased') but never unsubscribed; its source is an injected dependency whose lifetime is unknown, so it may outlive and keep 'AliasedSourceViewModel' alive (possible leak) |
OWN001:
frontend/roslyn/samples/ExternalRefSubscription.cs#L20
[OWN001] event '_bus.Changed' is subscribed (handler 'OnChanged') but never unsubscribed; its source is an injected dependency whose lifetime is unknown, so it may outlive and keep 'ExternalRefSubscription' alive (possible leak) [resource: subscription token] |
DI002:
frontend/roslyn/samples/DiCaptiveSample.cs#L182
[DI002] singleton 'WeakCacheOpt' weakly captures scoped service 'AppDbContext' (WeakReference): 'AppDbContext' is still resolved from the root provider and promoted to application lifetime — the weak reference avoids pinning it for the GC but does not fix the captive-dependency lifetime violation (WeakCacheOpt -> AppDbContext) [consumed by the 'WeakCacheOpt' constructor at frontend/roslyn/samples/DiCaptiveSample.cs:60] [resource: DI lifetime] |
DI002:
frontend/roslyn/samples/DiCaptiveSample.cs#L179
[DI002] singleton 'WeakCache' weakly captures scoped service 'AppDbContext' (WeakReference): 'AppDbContext' is still resolved from the root provider and promoted to application lifetime — the weak reference avoids pinning it for the GC but does not fix the captive-dependency lifetime violation (WeakCache -> AppDbContext) [consumed by the 'WeakCache' constructor at frontend/roslyn/samples/DiCaptiveSample.cs:57] [resource: DI lifetime] |
DI003:
frontend/roslyn/samples/DiCaptiveSample.cs#L173
[DI003] singleton 'ConnectionWarmer' captures transient IDisposable 'PooledConnection': it is promoted to application lifetime and disposed only when the root provider is disposed (ConnectionWarmer -> PooledConnection) [consumed by the 'ConnectionWarmer' constructor at frontend/roslyn/samples/DiCaptiveSample.cs:50] [resource: DI lifetime] |
DI004:
frontend/roslyn/samples/DiCaptiveSample.cs#L137
[DI004] singleton 'WrapperResolver' resolves transient IDisposable 'PooledConnection' by hand from its injected root IServiceProvider (GetService/GetRequiredService — the service-locator anti-pattern): the root provider tracks every IDisposable it resolves and frees them only at application shutdown, so each call leaks a transient that should be scope-lived — resolve it from an IServiceScope instead (WrapperResolver -> MidConnection -> PooledConnection) [singleton registered at frontend/roslyn/samples/DiCaptiveSample.cs:205] [resource: DI lifetime] |
DI004:
frontend/roslyn/samples/DiCaptiveSample.cs#L123
[DI004] singleton 'ExprBodiedResolver' resolves transient IDisposable 'PooledConnection' by hand from its injected root IServiceProvider (GetService/GetRequiredService — the service-locator anti-pattern): the root provider tracks every IDisposable it resolves and frees them only at application shutdown, so each call leaks a transient that should be scope-lived — resolve it from an IServiceScope instead (ExprBodiedResolver -> PooledConnection) [singleton registered at frontend/roslyn/samples/DiCaptiveSample.cs:201] [resource: DI lifetime] |
DI004:
frontend/roslyn/samples/DiCaptiveSample.cs#L79
[DI004] singleton 'ConnectionResolver' resolves transient IDisposable 'PooledConnection' by hand from its injected root IServiceProvider (GetService/GetRequiredService — the service-locator anti-pattern): the root provider tracks every IDisposable it resolves and frees them only at application shutdown, so each call leaks a transient that should be scope-lived — resolve it from an IServiceScope instead (ConnectionResolver -> PooledConnection) [singleton registered at frontend/roslyn/samples/DiCaptiveSample.cs:192] [resource: DI lifetime] |
OWN001:
frontend/roslyn/samples/CustomerViewModel.cs#L15
[OWN001] event 'bus.CustomerChanged' is subscribed (handler 'OnCustomerChanged') but never unsubscribed; its source is an injected dependency whose lifetime is unknown, so it may outlive and keep 'CustomerViewModel' alive (possible leak) [resource: subscription token] |
OWN001:
frontend/roslyn/samples/AliasedSourceViewModel.cs#L23
[OWN001] event 'src.CustomerChanged' is subscribed (handler 'OnAliased') but never unsubscribed; its source is an injected dependency whose lifetime is unknown, so it may outlive and keep 'AliasedSourceViewModel' alive (possible leak) [resource: subscription token] |
own-check repo scan (github + msbuild) + composite action:
frontend/roslyn/OwnSharp.Extractor/Program.cs#L1947
Argument of type 'IEnumerable<string?>' cannot be used for parameter 'collection' of type 'IEnumerable<string>' in 'HashSet<string>.HashSet(IEnumerable<string> collection, IEqualityComparer<string>? comparer)' due to differences in the nullability of reference types. |
corpus benchmark (real C# recall + specificity) Node.js 20 is deprecated. The following actions target Node.js 20 but are being forced to run on Node.js 24: actions/checkout@v4, actions/setup-dotnet@v4, actions/setup-python@v5. For more information see: https://github.blog/changelog/2025-09-19-deprecation-of-node-20-on-github-actions-runners/ |