feat: mock-publish channel order with social-sdk mockBackend - #201
Conversation
The channel cut is LinkedIn, then TikTok, then YouTube Shorts. The publisher calls mockBackend only, so nothing is posted live. Jev fails when stake or VETO is spoken as a product claim.
|
The latest updates on your projects. Learn more about Vercel for GitHub.
|
Strix Security ReviewNo security issues found. Review summaryReviewed the five changed files: the Updated for Reviewed by Strix |
There was a problem hiding this comment.
Your trial has ended. Reactivate Greptile to resume code reviews.
There was a problem hiding this comment.
Reviewed the five changed files: the cmo-mock-publish.mjs script, its CHANNEL.md documentation, the cmo-jev.test.ts test, and the package.json/package-lock.json additions. The publish script uses @opencoredev/social-sdk's mockBackend with purely hardcoded, non-sensitive inputs and ships only mock publish state to stdout; it is not included in the published package's files[]. The test spawns the script via a static executable and path with no attacker-controllable input. The new @opencoredev/social-sdk package is a devDependency consumed only by the mock script and test and is not part of the runtime bundle. No injection sinks, hardcoded credentials, unsafe deserialization, or other security-relevant defects were found in the changed code.
Reviewed by Strix
Configure security review settings
Mock publish for the channel order. Nothing is posted live.
scripts/cmo-mock-publish.mjscalls@opencoredev/social-sdkmockBackend(immediate-text-success) for LinkedIn, then TikTok, then YouTube.docs/CHANNEL.mdrecords that order and the inbox clips01-lie,02-caught,03-receipt.tests/cmo-jev.test.tsfails when stake or VETO is spoken as a product claim.@opencoredev/social-sdkis a devDependency. The script is not infiles[]. No HeyGen. REAL_STAKING was not flipped.Related to #199.