Skip to content

docs: correct five stale claims found in the weekly source audit (iou-architectuur#105) - #236

Merged
sgort merged 1 commit into
accfrom
fix/audit-105-doc-and-comment-staleness
Sep 29, 2026
Merged

sgort merged 1 commit into
accfrom
fix/audit-105-doc-and-comment-staleness

Conversation

@sgort

@sgort sgort commented Sep 29, 2026

Copy link
Copy Markdown
Owner

Items 4, 8, 10, 12 and the linked-data-explorer half of 17 in sgort/iou-architectuur#105. Comments and prose only; no behaviour changes. Each was re-checked against acc at 05b3168 rather than taken from the issue.

#
4 scripts/check-deps.sh:16 named the snapshot script write-deps-marker.sh the root postinstall runs write-deps-marker.mjs, which is the file that exists
8 .npmrc said Node 22.23.2 bundles npm 10.9.8 and so ignores min-release-age .nvmrc is 24.21.0, which bundles npm 11.19.0 and honours it — the comment described the gap #80 had already closed
10 docs/ci-posture-across-repos.md:213 said all four App Services run NODE|22-lts line 128 of the same file said "Node 24 on both tiers". Azure says this repo's two are NODE|24-lts, RBA's two NODE|22-lts
12 azure-backend-acc.yml:113 and azure-backend-production.yml:79 said the major matches NODE|22-lts lines 416 and 369 of the same files said it was switched to NODE|24-lts
17 SECURITY-PIPELINE.md said "all eight workflows" and "all nine workflows" there are eleven, since promote-to-production.yml, dependency-audit.yml and sbom.yml were added

On 10 and 12 the runtime was read from Azure with az webapp config show --query linuxFxVersion on 27 September 2026, not inferred.

On 17, before changing the zizmor sentence I checked the measurement it carries is still current: zizmor.yml pins version: '1.29.0', which matches the prose, and the Supply-chain audit job is green on acc.

Checks

check-supply-chain green (31 pinned references, register agrees) · all eleven workflow files parse · check-deps.sh passes bash -n.

The five prettier warnings on root markdown are pre-existing on clean acc — same count with these changes stashed — and outside check-format's --workspaces scope.

Not in this PR

Items 5 and 6 are source fixes and follow in a second PR. Item 18's LDE half is a repository-settings decision.

Items 4, 8, 10, 12 and the linked-data-explorer half of 17 in
sgort/iou-architectuur#105. Comments and prose only; no behaviour changes.
Each was re-checked against acc at 05b3168 rather than taken from the issue.

**4. scripts/check-deps.sh named the wrong marker script.** The comment said the
snapshot is taken by scripts/write-deps-marker.sh; the root postinstall runs
scripts/write-deps-marker.mjs, which is the file that exists.

**8. .npmrc described the caveat the Node 24 move had already closed.** It said
Node 22.23.2 bundles npm 10.9.8 and so ignores min-release-age. .nvmrc is
24.21.0, which bundles npm 11.19.0 and honours the setting. The comment now
says that, and that check-deps.sh's warning matters only on a workstation
running something older than .nvmrc.

**10. docs/ci-posture-across-repos.md contradicted itself.** Line 128 said
"Node 24 on both tiers"; line 213 said all four App Services across both
repositories run NODE|22-lts. Azure says this repository's two run NODE|24-lts
and ronl-business-api's two run NODE|22-lts, read with
`az webapp config show --query linuxFxVersion` on 27 September 2026.

**12. Both backend workflows carried the same contradiction.**
azure-backend-acc.yml:113 and azure-backend-production.yml:79 said the Node
major "matches the App Service runtime, NODE|22-lts", while lines 416 and 369
of the same files said the App Service was switched to NODE|24-lts.

**17. SECURITY-PIPELINE.md undercounted the workflows.** Line 25 said "all
eight workflows" and line 39 "all nine workflows". There are eleven, since
promote-to-production.yml, dependency-audit.yml and sbom.yml were added.
Verified before changing the zizmor line: the pinned version there, 1.29.0,
still matches zizmor.yml, and the Supply-chain audit job is green on acc.

check-supply-chain green (31 pinned references, register agrees), all eleven
workflow files still parse, check-deps.sh still passes bash -n. The five
prettier warnings on root markdown are pre-existing on clean acc and outside
check-format's --workspaces scope.
@sgort
sgort merged commit f394d40 into acc Sep 29, 2026
10 checks passed
@sgort
sgort deleted the fix/audit-105-doc-and-comment-staleness branch September 29, 2026 21:05

This branch was successfully deployed

1 active deployment
acceptance — b30f89c2 Deployed Sep 29, 2026 by sgort via deploy #312
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant