You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
Audit follow-up. The Codeac analyze results check (Codeac GitHub App) fails on every PR (e.g. PR #81). It is not a required context — PRs merge anyway — but it is permanent red noise.
Findings (from the Codeac analysis page for the last commit + Codeac's own docs at codeac.io/documentation/thresholds.html):
The fail state is an analysis crash, not findings. Codeac docs: "If the threshold is not specified, Codeac will signal a success to all commits with finished analysis. The failed state is used only when the whole analysis fails, for example with configuration issues or other errors." — this repo has no .codeac.yml thresholds, so its ~31k findings alone would still report success.
So: fixing #82 removes the ESLint crash and is the in-repo fix for this check. The residual risk is the processing timeout on this monorepo's volume.
It IS configurable: per-tool native configs (ESLint, PHPMD, SCSS Lint, jscpd via .jscpd.json, ignore files like .codesizeignore), and optional .codeac.yml thresholds. But the analysis set (phpmd clean-code rules like CamelCase* on WordPress-style PHP, scsslint style rules on journal-theme) will keep producing thousands of style findings this codebase will never "fix", and taming that means maintaining several suppression configs.
Recommendation: fix #82 and re-check on the follow-up PR. If analysis still times out or keeps failing for tool crashes, disable it (uninstall the Codeac GitHub App or at least keep it out of required contexts) — it duplicates CodeFactor + Semgrep + GitGuardian + Hypatia Security Scan + gitleaks, which all pass here.
Verification plan: watch this check on the fixing PR; close this issue if it goes green after #82 lands.
Audit follow-up. The Codeac analyze results check (Codeac GitHub App) fails on every PR (e.g. PR #81). It is not a required context — PRs merge anyway — but it is permanent red noise.
Findings (from the Codeac analysis page for the last commit + Codeac's own docs at codeac.io/documentation/thresholds.html):
.codeac.ymlthresholds, so its ~31k findings alone would still report success.praxis/SymbolicEngine/graphql/package.json—Error: Expected double-quoted property name in JSON at position 1399— i.e. exactly issue A1: praxis/SymbolicEngine/graphql/package.json is invalid JSON (trailing comma after "bun-types") #82's invalid JSON. Plus "Processing of this commit timed out."So: fixing #82 removes the ESLint crash and is the in-repo fix for this check. The residual risk is the processing timeout on this monorepo's volume.
It IS configurable: per-tool native configs (ESLint, PHPMD, SCSS Lint, jscpd via
.jscpd.json, ignore files like.codesizeignore), and optional.codeac.ymlthresholds. But the analysis set (phpmd clean-code rules like CamelCase* on WordPress-style PHP, scsslint style rules on journal-theme) will keep producing thousands of style findings this codebase will never "fix", and taming that means maintaining several suppression configs.Recommendation: fix #82 and re-check on the follow-up PR. If analysis still times out or keeps failing for tool crashes, disable it (uninstall the Codeac GitHub App or at least keep it out of required contexts) — it duplicates CodeFactor + Semgrep + GitGuardian + Hypatia Security Scan + gitleaks, which all pass here.
Verification plan: watch this check on the fixing PR; close this issue if it goes green after #82 lands.