Skip to content

[finding] Two test comments still claim validateSecurityPosture is CLI_ONLY — false since PR #8390, and drifting further as #7891 slices land #8547

Description

@qq9340100

Observation-class (comments only, no behavior). Found while implementing #8310 (session session_012MNV7ZSCjNfA38eDCjsXQL, PR #8546); filed rather than fixed because both files are outside that card's surface and the prose will need re-judging again when the escalated object decision on #8310 lands.

The two sites

Why it is false

The entry has declared surfaces: ['cli', 'runtime-publish'] since PR #8390 (#8307, runtimeTypes: ['seed']), and PR #8546 (#8310) widens runtimeTypes to ['seed', 'permission', 'book']. object specifically is still NOT runtime-declared (escalated on #8310), so the carve-out reasoning these comments support happens to still hold for object writes — the cited registry fact is what rotted, not (yet) the conclusion. Whoever picks this up after the #8310object decision should restate the reason in terms of the decision taken, not patch the word CLI_ONLY.

Blocked-by: #8310 (the object decision reshapes what the corrected sentence should say).

Metadata

Metadata

Assignees

No one assigned

    Type

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions