Skip to content

feat: mock-publish channel order with social-sdk mockBackend - #201

Merged
DealAppSeo merged 1 commit into
mainfrom
feat/cmo-mock-publish
Sep 26, 2026
Merged

DealAppSeo merged 1 commit into
mainfrom
feat/cmo-mock-publish

Conversation

@DealAppSeo

Copy link
Copy Markdown
Owner

Mock publish for the channel order. Nothing is posted live.

  • scripts/cmo-mock-publish.mjs calls @opencoredev/social-sdk mockBackend (immediate-text-success) for LinkedIn, then TikTok, then YouTube.
  • docs/CHANNEL.md records that order and the inbox clips 01-lie, 02-caught, 03-receipt.
  • tests/cmo-jev.test.ts fails when stake or VETO is spoken as a product claim.

@opencoredev/social-sdk is a devDependency. The script is not in files[]. No HeyGen. REAL_STAKING was not flipped.

Related to #199.

The channel cut is LinkedIn, then TikTok, then YouTube Shorts. The publisher calls mockBackend only, so nothing is posted live. Jev fails when stake or VETO is spoken as a product claim.
@vercel

vercel Bot commented Sep 26, 2026 •

Copy link
Copy Markdown

The latest updates on your projects. Learn more about Vercel for GitHub.

Project Deployment Actions Updated
trustshell-landing Ready Ready Preview Sep 26, 2026 9:29pm UTC

Request Review

@strix-security

strix-security Bot commented Sep 26, 2026 •

Copy link
Copy Markdown

Strix Security Review

No security issues found.

Review summary

Reviewed the five changed files: the cmo-mock-publish.mjs script, its CHANNEL.md documentation, the cmo-jev.test.ts test, and the package.json/package-lock.json additions. The publish script uses @opencoredev/social-sdk's mockBackend with purely hardcoded, non-sensitive inputs and ships only mock publish state to stdout; it is not included in the published package's files[]. The test spawns the script via a static executable and path with no attacker-controllable input. The new @opencoredev/social-sdk package is a devDependency consumed only by the mock script and test and is not part of the runtime bundle. No injection sinks, hardcoded credentials, unsafe deserialization, or other security-relevant defects were found in the changed code.

Updated for 282539e.


Reviewed by Strix
Re-run review · Configure security review settings

@greptile-apps greptile-apps Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Your trial has ended. Reactivate Greptile to resume code reviews.

@strix-security strix-security Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Reviewed the five changed files: the cmo-mock-publish.mjs script, its CHANNEL.md documentation, the cmo-jev.test.ts test, and the package.json/package-lock.json additions. The publish script uses @opencoredev/social-sdk's mockBackend with purely hardcoded, non-sensitive inputs and ships only mock publish state to stdout; it is not included in the published package's files[]. The test spawns the script via a static executable and path with no attacker-controllable input. The new @opencoredev/social-sdk package is a devDependency consumed only by the mock script and test and is not part of the runtime bundle. No injection sinks, hardcoded credentials, unsafe deserialization, or other security-relevant defects were found in the changed code.


Reviewed by Strix
Configure security review settings

@DealAppSeo
DealAppSeo merged commit 131aba5 into main Sep 26, 2026
5 checks passed

This branch was successfully deployed

1 active deployment
Preview — 282539e3 Deployed Sep 26, 2026 by vercel[bot]
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant