docs: generate the Mintlify changelog, sync the site with the review fixes, clear CodeQL - #165
Merged
Merged
Conversation
CodeQL flagged one new high-severity alert in #164 and two older ones. A local run of the same CodeQL version (2.27.0, javascript-code-scanning suite) goes from 3 results to 0 with this change. - scripts/claims-status.mjs (js/incomplete-sanitization, new in #164): table cells escaped `|` but not `\`, so a trailing backslash could undo the escape. Backslashes are escaped first. - src/model_catalog.js (js/polynomial-redos, pre-existing): the tokenizer's `/(?:\.0)+$/` and trimUrl's `/\/+$/` backtracked quadratically on library input. Trailing ".0" parts are popped instead, and URLs use a new linear stripTrailingSlashes (src/util.js). - The same patterns in code added by #164 are hardened too: the workspace-glob trim (src/stack.js) and the semantic guard's edge punctuation trim, now a code-point scan (trimEdges). Each replacement is checked against the regex it replaced (tokenize on known ids; trimEdges on 2,000 seeded random tokens) and gets a linear-time test on a hostile input. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01GVVG2VDETWsDxMu6MBWPz2
The docs site's changelog page was hand-written and stopped at one July entry while thirty releases shipped. It is now generated: - src/changelog_page.js parses CHANGELOG.md and renders every release, plus [Unreleased], as a Mintlify <Update> entry: each change's headline (the bold lead, else the first sentence), filter tags per section, and a link to the release's full notes on GitHub. Text is made MDX-safe outside code spans, and relative links point at GitHub. - forge docs render splices it between JSX-comment markers (MDX rejects HTML comments). It is a strict target, so forge docs check fails when the page is stale. - scripts/bump.mjs regenerates the page in the release commit, so a release never leaves it behind (the bump workflow commits with git add -A). All 19 Mintlify pages compile under MDX 3. CHANGELOG corrections that the page surfaced: 1.1.2 called the project's own second-machine re-run an independent replication (now a dated correction), and 1.0.0 had lost the \r\n / \n escapes inside two code spans. GUIDE, ARCHITECTURE, the Mintlify README/CLI page and CLAUDE.md describe the new surface. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01GVVG2VDETWsDxMu6MBWPz2
After the 2026-09-26 review fixes merged (#164), several surfaces still described the old behavior: - Mintlify reference: forge verify (per-package coverage, pre/post binding, verifier events, .forge/forge.config.json), forge stack (available runners), forge context (what COMPLETE means, --budget, --block), forge reuse and forge ledger (lossless keys, serve-time revalidation, one vote per event, archive reasons, conflicts, --fix --dry-run), forge dash (Host check on every route, session token), and the universal router, which the site did not cover at all (objectives, INFEASIBLE, advice-only models, outcome provenance, and the limits of its evidence). - Landing page: all ten native targets (OpenClaw was missing, "Nine native targets"). The grid is now two rows of five on wide screens and two columns below 1180px, checked in headless Chromium at eight widths with no overflow or horizontal scroll. - Claim registry: the claims the review found refuted at d2abfa6 are re-assessed on 7eef611 (the merge), after re-running the review's probes as regression tests (46 pass; 1 skip needs a non-root user): verify binding, context completeness and exact reuse are implemented (with their scope in the notes); evidence independence and outcome provenance are partial; the imagine sandbox and router target claims stay refuted. The impact fixture's F1 is 0.28 after the CLI move. - biome.json migrated to the installed Biome 2.5.13 (schema URL; `recommended` → `preset`); lint results unchanged. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01GVVG2VDETWsDxMu6MBWPz2
CodeWithJuber
marked this pull request as ready for review
September 26, 2026 21:32
The v1.5.0 release commit (fd71bf8) moved the [Unreleased] notes of #164 under [1.5.0] and bumped the version strings; this branch had added its own notes to the same [Unreleased] section, so the PR could not merge and CI never ran. Resolution: - CHANGELOG.md: this PR's four new entries (the CodeQL fixes, the generated changelog page, the Mintlify reference sync and the two historical corrections) move back to [Unreleased]; [1.5.0] keeps exactly what shipped, apart from this PR's bold headline leads. Fixes a doubled "separately" in the Qur'anic-lens entry. - landing/index.html: this branch's page with the release's version strings (softwareVersion and both "forgekit v1.5.0" labels), as scripts/bump.mjs writes them. - mintlify/changelog/overview.mdx: re-rendered with `forge docs render`. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01GVVG2VDETWsDxMu6MBWPz2
…t stale The Windows CI job (Git Bash, core.autocrlf) failed "the repository's changelog page is current": the page checks out with CRLF while `forge docs render` emits LF, so the byte comparison could never match. `forge docs check` had the same fault for every strict block on a Windows checkout, and `forge docs render` wrote LF block lines into CRLF files. src/docs_render.js now reads each managed doc in LF (renderDocs and renderFile), compares in LF, and writes a changed file back in its own line endings. The page test normalizes the file it reads. New tests reproduce a CRLF checkout for both render paths; both fail against the old renderer. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01GVVG2VDETWsDxMu6MBWPz2
12 tasks
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
What & why
This is a follow-up to #164, which merged with one red check: CodeQL flagged one new high-severity alert. The Mintlify changelog page had also fallen behind: it had one hand-written entry from July while about thirty releases shipped. Several doc surfaces still described behavior from before the review fixes.
1. Security: CodeQL goes from 3 results to 0. I verified this with a local run of the same CodeQL version (2.27.0,
javascript-code-scanningsuite).scripts/claims-status.mjs, js/incomplete-sanitization (high, new in fix: repair the trust guarantees and research claims from the 2026-09-26 deep review #164). Table cells escaped|but not\, so a trailing backslash could undo the escape. Backslashes are now escaped first.src/model_catalog.js, js/polynomial-redos ×2 (high, older than fix: repair the trust guarantees and research claims from the 2026-09-26 deep review #164). The tokenizer's/(?:\.0)+$/andtrimUrl's/\/+$/backtracked quadratically. They are replaced by linear scans, including a newstripTrailingSlashesinsrc/util.js.trimEdges).trimEdgesis checked on 2,000 seeded random tokens. Each also has a linear-time test on a hostile input.2. The Mintlify changelog page is generated from
CHANGELOG.md.src/changelog_page.jsrenders every release, plus[Unreleased], as a Mintlify<Update>entry: 62 entries and 428 headlines. Each entry has filter tags and a link to that release's full notes on GitHub.forge docs renderwrites the page between JSX-comment markers, because MDX rejects HTML comments. It is a strict target, soforge docs checkfails when the page is stale.scripts/bump.mjsregenerates the page in the release commit, so a release can't leave it behind.\r\nescapes inside two code spans.3. Docs synced with the merged fixes.
Mintlify reference pages:
forge verify: per-package coverage, pre/post binding, verifier events,.forge/forge.config.json.forge stack:availablerunners.forge context: whatCOMPLETEmeans,--block.forge reuseandforge ledger: lossless keys, serve-time revalidation, one vote per event, archive reasons, conflicts,--fix --dry-run.forge dash: Host check on every route, session token.Landing page: now lists all ten native targets; OpenClaw was missing. The grid was checked in headless Chromium at 8 widths: rows are always full and nothing overflows.
Claim registry: I re-ran the review's probes on the merged commit
7eef611, as regression tests: 46 pass, and 1 skip needs a non-root user. The claims found refuted atd2abfa6are re-assessed:The impact fixture's F1 is updated to 0.28.
Config and contributor docs:
biome.jsonis migrated to the installed Biome 2.5.13, with lint results unchanged.CLAUDE.mdnow states the right Biome version and says to rundocs renderafter editing the CHANGELOG.Checklist
npm testpasses: 1,692 tests, 1,688 pass, 0 fail, 4 platform-gated skips (Node 22 locally)npm run checkpasses (Biome lint + format)feat:/fix:/docs:…)CHANGELOG.mdupdated under## [Unreleased]forge substrate,forge impact, router/gate, or MCP substrate toolsRisk & rollback
CHANGELOG.md, runnode src/cli.js docs render. The docs check names this fix when it fails, andCLAUDE.mdstates it.Extra checks (tick if applicable)
npm run typecheckpasses🤖 Generated with Claude Code
https://claude.ai/code/session_01GVVG2VDETWsDxMu6MBWPz2
Generated by Claude Code