refactor(release): remove unreachable DER parser guards - #399
Conversation
|
@codex review |
|
Codex Review: Didn't find any major issues. Keep them coming! Reviewed commit: ℹ️ About Codex in GitHubYour team has set up Codex to review pull requests in this repo. Reviews are triggered when you
If Codex has suggestions, it will comment; otherwise it will react with 👍. Codex can also answer questions or update the PR. Try commenting "@codex address that feedback". |
|
Security review completed. No security issues were found in this pull request. Reviewed commit: Only the user who started this review can view the report in Codex. ℹ️ About Codex security reviews in GitHubThis is an experimental Codex feature. Security reviews are triggered when:
Once complete, Codex will leave suggestions, or a comment if no findings are found. |
zcrab-oai
left a comment
There was a problem hiding this comment.
Looks good. Removes unreachable DER parser guards while preserving malformed certificate and release-signing verification.
Summary
Remove unreachable DER parser checks and a test that snapshots their source text.
Changes
Testing
bun test tests-ts/release-automation.test.ts tests-ts/package-provenance.test.ts --timeout 30000— passed.pnpm run types— passed.prettier --check scripts/release-automation.mjs tests-ts/release-automation.test.ts— passed.git diff --check— passed.Risk and rollout
Every accepted DER element consumes its tag and length bytes, and the parser rejects elements extending beyond their parent. Existing malformed-certificate, signing, and package-provenance tests continue to exercise the actual verification behavior.
Public disclosure review