Skip to content

FUSI-006: PR Runfusion/Fusion #3562 — fix(engine): validate integrationBranch exists before worktree acquisition - #9

Closed
timoteo7 wants to merge 1 commit into
mainfrom
fusion/fusi-006
Closed

timoteo7 wants to merge 1 commit into
mainfrom
fusion/fusi-006

Conversation

@timoteo7

Copy link
Copy Markdown
Owner

Automated PR for FUSI-006.

PR Runfusion/Fusion Runfusion#3562 — fix(engine): validate integrationBranch exists before worktree acquisition (branch fix/integration-branch-validate-exists). Estado 14/09: Greptile 5/5, ZERO threads não resolvidas de bots; CI com Lint FAILURE (único check vermelho). Meta (missão FUSI Greptile 5/5): Lint verde mantendo 5/5 e zero threads; PR permanece aberto (fora do escopo). Loop via skill greploop, máx 5 iterações por ciclo.

@github-actions

github-actions Bot commented Sep 19, 2026 •

Copy link
Copy Markdown

ThreatCrush Security Scan

4586 finding(s)

HIGH/CRITICAL: 43 | MEDIUM: 4032 | LOW: 511

Severity Rule Location
HIGH secret-database-url .github/workflows/full-suite.yml:55
HIGH secret-generic-credential .github/workflows/full-suite.yml:56
HIGH secret-database-url .github/workflows/full-suite.yml:284
HIGH secret-generic-credential .github/workflows/full-suite.yml:285
HIGH secret-database-url .github/workflows/full-suite.yml:324
HIGH secret-generic-credential .github/workflows/full-suite.yml:325
HIGH secret-database-url .github/workflows/pr-checks.yml:221
HIGH secret-generic-credential .github/workflows/pr-checks.yml:222
HIGH secret-generic-credential .github/workflows/release.yml:522
HIGH secret-generic-credential .github/workflows/release.yml:524
HIGH secret-generic-credential .github/workflows/test-release.yml:445
HIGH secret-generic-credential .github/workflows/test-release.yml:447
HIGH secret-generic-credential docs/cli-reference.md:80
HIGH secret-generic-credential docs/signals-connectors.md:34
HIGH secret-generic-credential docs/signals-connectors.md:77
HIGH secret-generic-credential docs/signals-connectors.md:94
HIGH secret-generic-credential docs/signals-connectors.md:117
HIGH secret-generic-credential docs/signals-connectors.md:159
HIGH secret-generic-credential packages/cli/STANDALONE.md:71
HIGH secret-database-url packages/core/src/postgres/credential-redact.ts:12
HIGH secret-database-url packages/core/src/postgres/credential-redact.ts:30
HIGH secret-database-url packages/core/src/postgres/credential-redact.ts:31
HIGH secret-database-url packages/core/src/postgres/credential-redact.ts:102
HIGH secret-database-url packages/core/src/postgres/credential-redact.ts:103
HIGH secret-generic-credential packages/core/src/postgres/embedded-lifecycle.ts:843
HIGH secret-database-url packages/core/src/postgres/embedded-lifecycle.ts:1574
HIGH secret-database-url packages/core/src/postgres/pg-backup.ts:756
HIGH js-ssrf-outbound-request packages/dashboard/app/public/sw.js:651
HIGH js-ssrf-outbound-request packages/dashboard/app/public/sw.js:727
HIGH js-host-header-trust packages/dashboard/src/cli-session-ws.ts:81
HIGH js-host-header-trust packages/dashboard/src/cli-session-ws.ts:115
HIGH js-ssrf-outbound-request packages/dashboard/src/routes.ts:1858
HIGH js-host-header-trust packages/dashboard/src/server.ts:2689
HIGH js-host-header-trust packages/dashboard/src/server.ts:2714
HIGH js-host-header-trust packages/dashboard/src/server.ts:3025
HIGH js-host-header-trust packages/dashboard/src/server.ts:3193
HIGH secret-slack-webhook plugins/examples/fusion-plugin-notification/README.md:46
HIGH secret-database-url scripts/pg-test-server.mjs:200
HIGH secret-database-url scripts/pg-test-server.mjs:231
HIGH secret-database-url scripts/pg-test-server.mjs:241
HIGH secret-generic-credential scripts/sync-fusion-skill-tools.mjs:550
HIGH secret-generic-credential scripts/verify-windows-elevated-restricted.mjs:81
HIGH secret-generic-credential scripts/verify-windows-encoding-recovery.mjs:41
MEDIUM redos-nested-quantifier docs/agents.md:1710
MEDIUM insecure-temp-file packages/cli/src/__tests__/bin.test.ts:136
MEDIUM insecure-temp-file packages/cli/src/__tests__/dev-with-memory-lib.test.ts:33
MEDIUM insecure-temp-file packages/cli/src/__tests__/dev-with-memory-lib.test.ts:34
MEDIUM insecure-temp-file packages/cli/src/__tests__/dev-with-memory-lib.test.ts:35
MEDIUM insecure-temp-file packages/cli/src/__tests__/dev-with-memory-lib.test.ts:43
MEDIUM insecure-temp-file packages/cli/src/__tests__/dev-with-memory-lib.test.ts:48

…and 4536 more. Full results in the Security tab.

Snippets are redacted; ThreatCrush never prints matched credential material.

Comment thread docs/solutions/performance-issues/event-driven-task-dispatch.md Fixed
Comment thread docs/testing.md Fixed
Comment thread docs/testing.md Fixed
Comment thread packages/engine/src/__tests__/event-driven-dispatch.test.ts Fixed
Comment thread packages/engine/src/__tests__/event-driven-dispatch.test.ts Fixed
Comment thread packages/engine/src/__tests__/event-driven-dispatch.test.ts Fixed
Comment thread packages/engine/src/__tests__/event-driven-dispatch.test.ts Fixed
Comment thread packages/engine/src/__tests__/event-driven-dispatch.test.ts Fixed
Comment thread packages/engine/src/__tests__/event-driven-dispatch.test.ts Fixed
Comment thread packages/engine/src/__tests__/event-driven-dispatch.test.ts Fixed
…ition

Resolve the integration branch through a verified ladder — integrationBranch -> baseBranch -> origin/HEAD -> inference -> main — probing refs/heads via argv-based `git show-ref --verify` (no shell interpolation). A set-but-missing integrationBranch no longer hides a valid baseBranch. Configured, origin/HEAD and inferred branches that exist only under refs/remotes/origin are materialized locally (plain `git branch <name> refs/remotes/origin/<name>`, never --track) before being returned, so worktree acquisition and merge consumers always find refs/heads/<branch>. Candidates are validated with full git-check-ref-format(1) semantics (pure JS, parity pinned by a real-git test) at every rung and inference return path: names git rejects (leading dash, reserved HEAD, spaces, .lock/@{/dot rules) fall through the ladder instead of being passed as a bare name or aborting fallback resolution. Only show-ref's missing-ref exit (1) means absent; operational git failures propagate.
@timoteo7

Copy link
Copy Markdown
Owner Author

Consolidated into #5 (sub-theme).

@timoteo7 timoteo7 closed this Sep 23, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants