From c0a051210d60296ab9445077e51db5c5f663b00b Mon Sep 17 00:00:00 2001 From: Maximilian Scholz Date: Wed, 16 Sep 2026 23:15:18 +0200 Subject: [PATCH 1/2] docs(corpus): refresh stale ledger metadata Hygiene for #475. The tidyverse source_sha256 flagged in the issue (d9d1fca1 vs actual 27c0c289) was already superseded on main by the RY106 regeneration (bb164033) and the superassignment recompute (c636b6b7); the recorded 21661fef verified to reproduce from the committed 32 non-posit root reports concatenated in filename order, so no digest change was needed. ecosystem/posit-packages.txt carried audit-era (ry 0.8.0) per-package counts that never tracked the regenerated reports: all 36 stale comments are refreshed to the current committed posit.*.root.txt / ledger counts, including the issue's lintr 12 -> 9 and testthat 9 -> 2. Tier membership is deliberately untouched (roxygen2/recipes/corrr/ bigrquery now read clean inside the fast tier; rmarkdown/tidyr/learnr/ dtplyr/bslib carry counts inside the full tier) because re-tiering changes what --tier fast clones and reconciles. docs/corpus/README.md's digest-recipe paragraph said six ungated reports hold 46 unowned findings with only fs and withr empty; the current reports hold 44 across three (cli, rlang, testthat) and five are empty (scales since #460, curl and jsonlite since #374). The tidyverse ledger pins the two duplicated dbplyr RY091 identities (test-backend-.R:110:36, test-translate-sql-string.R:13:36) with a note: the hermetic report emits each twice at the same span and reconcile.R compares multisets, so both copies are load-bearing. docs/rules.md's RY093 row drops abs() from the parenthetical: the pinned test (comparison_inside_selected_scalar_calls_is_diagnosed) asserts abs fires RY100, not RY093. One-time commit audit: all 86 package pins across both ledgers plus the upstream-fix note references (dbe32a6 dtplyr, 6fec3ad hms) resolve in their upstream repos via the GitHub API, and both ledgers' ry_commit 1dc59989 and the fd48562 baseline note resolve in this repository. No rewritten-away references remain. --- docs/corpus/README.md | 6 ++- docs/corpus/tidyverse-0.7.1.json | 3 +- docs/rules.md | 2 +- ecosystem/posit-packages.txt | 72 ++++++++++++++++---------------- 4 files changed, 43 insertions(+), 40 deletions(-) diff --git a/docs/corpus/README.md b/docs/corpus/README.md index 01355fde..581ac24c 100644 --- a/docs/corpus/README.md +++ b/docs/corpus/README.md @@ -103,8 +103,10 @@ The tidyverse ledger’s `source_sha256` uses the same recipe over every non-`posit` `*.root.txt` report — all 32 `ecosystem/packages.txt` manifest entries — while the index’s “24 Packages” counts ledger packages-block entries: eight manifest packages (cli, curl, fs, jsonlite, rlang, scales, -testthat, withr) have no block entry. Six of their reports contain 46 unowned -findings in total; only fs and withr have empty reports. +testthat, withr) have no block entry. Three of their reports (cli, rlang, +testthat) contain 44 unowned findings in total; the remaining five (curl, fs, +jsonlite, scales, withr) are empty — scales since #460, curl and jsonlite +since the #374 superassignment modeling. The Posit ledger’s `source_sha256` hashes the concatenated bytes of all `ecosystem/reports/posit.*.root.txt` files, sorted by filename. Recompute it diff --git a/docs/corpus/tidyverse-0.7.1.json b/docs/corpus/tidyverse-0.7.1.json index d2b089df..b7549d32 100644 --- a/docs/corpus/tidyverse-0.7.1.json +++ b/docs/corpus/tidyverse-0.7.1.json @@ -931,7 +931,8 @@ "RY107 (any-all-scalar-comparison, issue #356) adds exactly one identity across the corpus: glue R/utils.R:32:7, the audited `any(lengths) == 0` parenthesization defect in recycle_columns(). Runtime-verified true positive: `FALSE == 0` is TRUE, so the written guard computes `!any(lengths)` and the zero-length branch never runs, while the same commit writes the intended `any(lengths == 0)` at glue.R:139,191. Value-preserving comparisons (`== 1`, `> 0`, ...) stay silent, keeping diffobj's `!all(diff(x)) == 1L` idiom quiet.", "RY106 (ifelse-mode-collapse, #461) adds two owned true positives: hms R/hms.R:218:3 and blob R/format.R:43:10, the exact typed-NA select behind tidyverse/hms#231 (ifelse(is.na(x), NA_character_, ) over an open-world test, runtime-verified as logical(0) for empty x). The googledrive R/drive_mime_type.R:56 len=0 join artifact stays silent: inferred zero lengths are not collapse proofs, so the definite half fires only on literal empty or NA tests. The regeneration also replaces a source_sha256 that had been stale on main since the 0.5.1 vendor reconciliation regenerated ggplot2.root.txt without recomputing the digest; the recorded value now reproduces from the committed 32 non-posit root reports in filename order.", "RY109 (self-referential-default, issue #364) adds 10 true positives across 6 packages, each runtime-verified as a default that can only resolve to its own promise and therefore can never evaluate. The dtplyr trio (step-join.R:162 `copy = copy`, tidyeval-across.R:6,20 `j = j`) is the shipped bug upstream fixed in dbe32a6: triggering the default errors. purrr progress-bars.R:56 `caller_env = caller_env()` errors when the stop_input_type branch is reached. The dplyr R/distinct.R:81 and dbplyr R/verb-distinct.R:61 defaults `caller_env = caller_env(2)` shadow rlang's caller_env() with the formal, but neither body consumes the formal, so the calls run when it is missing: the defaults are dead on arrival and would error the moment anyone consumed them (dplyr's sibling `error_call = caller_env()` at distinct.R:82 is a legal cross-formal reference and correctly stays quiet). ggplot2 stat-bindot.R:133 `method = method` (unused in the body; `densitybin(1:3)` runs) and stat-quantilemethods.R:81 `method.args = method.args` (forced through inject), and lubridate's `tz = tz(x)` (parse.r:975, forced on the character branch) and `.select_formats = .select_formats` (guess.r:265, intent was the namespace function, shadowed by the formal) complete the set. Defusing suppression: dbplyr's sql_runif `n = n()` (body verifies the captured default via enquo) stays silent through typeshed captures_promise provenance; in the posit corpus the same mechanism keeps corrr's enquo/{{ }} idioms quiet, while rlang's own defusing tests (test-nse-defuse.R:329,334) warn because their bare enexpr/enquo are defined in-project -- 2 labeled false positives there, and this manifest's ungated rlang root report (rlang has no packages-block entry) gains exactly those two identities. Bare defuser names defined by the project itself are never credited without provenance.", - "RY108 (seq-defaulted-forward, #463) adds one owned true positive: hms R/hms.R:307:15, the tidyverse/hms#231 defect itself -- the defaulted `to = hms(1)` is validated (`is_hms(to)`), cast, and forwarded without a `missing(to)` check, so `seq(hms(1), length.out = 3)` repeats the default endpoint (three identical values) and a forwarded `by` errors with \"too many arguments\". The upstream fix (6fec3ad) guards every `to` use with `missing(to)`, exactly the shape the rule's supplied-vs-defaulted flow analysis recognizes; seq.Date (no default on `to`, cached mTo tests) and the other seq.* methods in the corpus stay silent." + "RY108 (seq-defaulted-forward, #463) adds one owned true positive: hms R/hms.R:307:15, the tidyverse/hms#231 defect itself -- the defaulted `to = hms(1)` is validated (`is_hms(to)`), cast, and forwarded without a `missing(to)` check, so `seq(hms(1), length.out = 3)` repeats the default endpoint (three identical values) and a forwarded `by` errors with \"too many arguments\". The upstream fix (6fec3ad) guards every `to` use with `missing(to)`, exactly the shape the rule's supplied-vs-defaulted flow analysis recognizes; seq.Date (no default on `to`, cached mTo tests) and the other seq.* methods in the corpus stay silent.", + "Metadata hygiene (#475): the dbplyr RY091 identities tests/testthat/test-backend-.R:110:36 (`ifelse(x, 1L)`, missing `no`) and test-translate-sql-string.R:13:36 (`substr(\"test\", 0)`, missing `stop`) are each recorded twice because the committed hermetic report emits each diagnostic twice at the same span (both calls sit inside the NSE-capturing expect_translation_snapshot helper). ecosystem/reconcile.R compares report and ledger multisets, so both copies are pinned; the 88-finding total and the pr195-nse-stubs count of 6 include the repeats." ], "ry_commit": "1dc5998988aa8ae41d422df19da31f7353d73137", "source_sha256": "21661fef4a99296e616422025eb0773d5c21ffea27d3ddafeb84e97375088354" diff --git a/docs/rules.md b/docs/rules.md index c610eb82..97387def 100644 --- a/docs/rules.md +++ b/docs/rules.md @@ -33,7 +33,7 @@ explanation for one rule. | RY090 | unknown-argument | warning | A named call argument does not match any formal parameter after R's exact and partial argument matching. | | RY091 | missing-required-argument | warning | A required formal parameter has no supplied value, including an explicitly omitted actual. | | RY092 | argument-type-mismatch | error | A call argument has a known mode incompatible with the parameter type declared by the resolved signature. | -| RY093 | comparison-inside-length | warning | A comparison directly inside `length()` (also `nchar()`, `abs()`) is usually a parenthesization mistake. | +| RY093 | comparison-inside-length | warning | A comparison directly inside `length()` (also `nchar()`) is usually a parenthesization mistake. | | RY094 | printf-argument-count | warning | A literal printf-family format string has more conversions than supplied value arguments. | | RY096 | hasarg-non-formal | warning | `hasArg()` names a parameter that is not a formal of an enclosing function without `...`. | | RY097 | not-r-source | info | File does not appear to be R source (e.g. Ratfor); its diagnostics are suppressed. | diff --git a/ecosystem/posit-packages.txt b/ecosystem/posit-packages.txt index 868d5eb0..cb74e5b0 100644 --- a/ecosystem/posit-packages.txt +++ b/ecosystem/posit-packages.txt @@ -16,49 +16,49 @@ # packages so one turning noisy is caught as an unowned finding. # # === fast tier (>=1 ry diagnostic) === -ggplot2 https://github.com/tidyverse/ggplot2.git 6870419aa6e106c3580c45c81d5b688cb31758bd # 8 diagnostics, 6982 stars -shiny-r https://github.com/rstudio/shiny.git ca1800475ac5a1e6037fea1020260a868d8798ee # 310 diagnostics, 5673 stars -dplyr https://github.com/tidyverse/dplyr.git d5e94e7fa8fd4a5f79c1a707d1842216bb4c691f # 30 diagnostics, 5054 stars -gt https://github.com/rstudio/gt.git caa074012b9825ddd71996f40e309c00f7b9e180 # 16 diagnostics, 2161 stars -blogdown https://github.com/rstudio/blogdown.git 07f3de89f672c0155149fd657a0946c29684a7f8 # 4 diagnostics, 1792 stars -reticulate https://github.com/rstudio/reticulate.git afe2221ded74a7f18ab3d5e89bb0a49b1f9d3114 # 4 diagnostics, 1759 stars -broom https://github.com/tidymodels/broom.git 6230a9014b0d839e4e8ed5b1763de65dde8f2205 # 5 diagnostics, 1524 stars -plumber https://github.com/rstudio/plumber.git 393920505f289f914150d57e06d97347556a55dc # 1 diagnostics, 1437 stars -purrr https://github.com/tidyverse/purrr.git 481e829f297fd4315b386518215157f361475ad0 # 5 diagnostics, 1401 stars -tensorflow https://github.com/rstudio/tensorflow.git fed1fe79742d9a979884b07f69c126b91a93050b # 1 diagnostics, 1340 stars -lintr https://github.com/r-lib/lintr.git 990e57870498634ce67d1fa0e53311f385b4b3d4 # 12 diagnostics, 1289 stars -renv https://github.com/rstudio/renv.git a3f8952cf8f4b9cd6e676805431cb81ca5a24b64 # 51 diagnostics, 1160 stars -tinytex https://github.com/rstudio/tinytex.git db1fc10763fa637f758a75ec24e070d82920bbce # 1 diagnostics, 1140 stars -httr https://github.com/r-lib/httr.git 34b956569ebaa20cd955150fad765cd834f38be4 # 1 diagnostics, 980 stars -sparklyr https://github.com/sparklyr/sparklyr.git 7f006a6d5c01a4e7a36d203d1ace56c53261900e # 3 diagnostics, 972 stars -testthat https://github.com/r-lib/testthat.git 9b6f12b9f50c297b4b5f485f728a2a19305770eb # 9 diagnostics, 938 stars -usethis https://github.com/r-lib/usethis.git 5f60819dc5dee7071d6e67cfa1fd934bb665466c # 1 diagnostics, 919 stars +ggplot2 https://github.com/tidyverse/ggplot2.git 6870419aa6e106c3580c45c81d5b688cb31758bd # 15 diagnostics, 6982 stars +shiny-r https://github.com/rstudio/shiny.git ca1800475ac5a1e6037fea1020260a868d8798ee # 52 diagnostics, 5673 stars +dplyr https://github.com/tidyverse/dplyr.git d5e94e7fa8fd4a5f79c1a707d1842216bb4c691f # 21 diagnostics, 5054 stars +gt https://github.com/rstudio/gt.git caa074012b9825ddd71996f40e309c00f7b9e180 # 11 diagnostics, 2161 stars +blogdown https://github.com/rstudio/blogdown.git 07f3de89f672c0155149fd657a0946c29684a7f8 # 3 diagnostics, 1792 stars +reticulate https://github.com/rstudio/reticulate.git afe2221ded74a7f18ab3d5e89bb0a49b1f9d3114 # 6 diagnostics, 1759 stars +broom https://github.com/tidymodels/broom.git 6230a9014b0d839e4e8ed5b1763de65dde8f2205 # 6 diagnostics, 1524 stars +plumber https://github.com/rstudio/plumber.git 393920505f289f914150d57e06d97347556a55dc # 2 diagnostics, 1437 stars +purrr https://github.com/tidyverse/purrr.git 481e829f297fd4315b386518215157f361475ad0 # 4 diagnostics, 1401 stars +tensorflow https://github.com/rstudio/tensorflow.git fed1fe79742d9a979884b07f69c126b91a93050b # 2 diagnostics, 1340 stars +lintr https://github.com/r-lib/lintr.git 990e57870498634ce67d1fa0e53311f385b4b3d4 # 9 diagnostics, 1289 stars +renv https://github.com/rstudio/renv.git a3f8952cf8f4b9cd6e676805431cb81ca5a24b64 # 49 diagnostics, 1160 stars +tinytex https://github.com/rstudio/tinytex.git db1fc10763fa637f758a75ec24e070d82920bbce # 3 diagnostics, 1140 stars +httr https://github.com/r-lib/httr.git 34b956569ebaa20cd955150fad765cd834f38be4 # 3 diagnostics, 980 stars +sparklyr https://github.com/sparklyr/sparklyr.git 7f006a6d5c01a4e7a36d203d1ace56c53261900e # 9 diagnostics, 972 stars +testthat https://github.com/r-lib/testthat.git 9b6f12b9f50c297b4b5f485f728a2a19305770eb # 2 diagnostics, 938 stars +usethis https://github.com/r-lib/usethis.git 5f60819dc5dee7071d6e67cfa1fd934bb665466c # 6 diagnostics, 919 stars keras3 https://github.com/rstudio/keras3.git 753ffeeb4b9a76ae37388cf63be64a45a5a8ef20 # 14 diagnostics, 856 stars flexdashboard https://github.com/rstudio/flexdashboard.git 8ae8623f2d9cdadb2316b953908bed0ba7bc3f87 # 3 diagnostics, 846 stars -pak https://github.com/r-lib/pak.git cdbd4ceb07f5a7eb2b317c57237dad561e5fb4e7 # 35 diagnostics, 817 stars -lubridate https://github.com/tidyverse/lubridate.git 8e9f2b289ee8384d9499e2527fb1e449c97e5370 # 1 diagnostics, 801 stars +pak https://github.com/r-lib/pak.git cdbd4ceb07f5a7eb2b317c57237dad561e5fb4e7 # 22 diagnostics, 817 stars +lubridate https://github.com/tidyverse/lubridate.git 8e9f2b289ee8384d9499e2527fb1e449c97e5370 # 8 diagnostics, 801 stars infer https://github.com/tidymodels/infer.git 0b9c910e658a5d4ed9f6b13e4978b9c23a225cad # 1 diagnostics, 795 stars -pkgdown https://github.com/r-lib/pkgdown.git 179cfaee3d4e17eaa9e7d7c700b1269dc62e4d46 # 7 diagnostics, 772 stars -styler https://github.com/r-lib/styler.git d3d7854df2d73f539b6cb2286dbf5dddaf3e58f6 # 471 diagnostics, 770 stars -glue https://github.com/tidyverse/glue.git da9c73f7a3de6a27f3103cb5bb2355820a4c3a6a # 1 diagnostics, 748 stars -cli https://github.com/r-lib/cli.git 86bdefe1eb23399499b40884f7fab84194283bc1 # 18 diagnostics, 719 stars -parsnip https://github.com/tidymodels/parsnip.git b992bc4f13bdb70d661dd629afee615d3711dd80 # 2 diagnostics, 658 stars -roxygen2 https://github.com/r-lib/roxygen2.git 81691b0f075f707b70b443131a0edcca065d5fbb # 14 diagnostics, 658 stars -recipes https://github.com/tidymodels/recipes.git 92704cb072b1bb4951061034be6bfa4678e0e43a # 28 diagnostics, 618 stars -ellmer https://github.com/tidyverse/ellmer.git f8281bed083ff0228e9064c38fb2164cd594d3f1 # 2 diagnostics, 612 stars -corrr https://github.com/tidymodels/corrr.git aa0488f1a26e0e04dda9e08535719e8f6b6f9154 # 1 diagnostics, 592 stars -rlang https://github.com/r-lib/rlang.git 1d0e00659b628c07c93c362687550727597ef09f # 37 diagnostics, 581 stars +pkgdown https://github.com/r-lib/pkgdown.git 179cfaee3d4e17eaa9e7d7c700b1269dc62e4d46 # 8 diagnostics, 772 stars +styler https://github.com/r-lib/styler.git d3d7854df2d73f539b6cb2286dbf5dddaf3e58f6 # 5 diagnostics, 770 stars +glue https://github.com/tidyverse/glue.git da9c73f7a3de6a27f3103cb5bb2355820a4c3a6a # 2 diagnostics, 748 stars +cli https://github.com/r-lib/cli.git 86bdefe1eb23399499b40884f7fab84194283bc1 # 16 diagnostics, 719 stars +parsnip https://github.com/tidymodels/parsnip.git b992bc4f13bdb70d661dd629afee615d3711dd80 # 1 diagnostics, 658 stars +roxygen2 https://github.com/r-lib/roxygen2.git 81691b0f075f707b70b443131a0edcca065d5fbb # clean, 658 stars +recipes https://github.com/tidymodels/recipes.git 92704cb072b1bb4951061034be6bfa4678e0e43a # clean, 618 stars +ellmer https://github.com/tidyverse/ellmer.git f8281bed083ff0228e9064c38fb2164cd594d3f1 # 65 diagnostics, 612 stars +corrr https://github.com/tidymodels/corrr.git aa0488f1a26e0e04dda9e08535719e8f6b6f9154 # clean, 592 stars +rlang https://github.com/r-lib/rlang.git 1d0e00659b628c07c93c362687550727597ef09f # 15 diagnostics, 581 stars torch https://github.com/mlverse/torch.git c67c2fb2909fc77e8fc127ec2867e1a551ee1bf3 # 18 diagnostics, 567 stars -bigrquery https://github.com/r-dbi/bigrquery.git fdb0f1eaebc6b7bab66d3727b2817f966d55e473 # 23 diagnostics, 528 stars -dbplyr https://github.com/tidyverse/dbplyr.git f478e2070c9a60f4aebcc94132048312209dd097 # 4 diagnostics, 514 stars +bigrquery https://github.com/r-dbi/bigrquery.git fdb0f1eaebc6b7bab66d3727b2817f966d55e473 # clean, 528 stars +dbplyr https://github.com/tidyverse/dbplyr.git f478e2070c9a60f4aebcc94132048312209dd097 # 10 diagnostics, 514 stars # === full tier (0 ry diagnostics; clean) === bookdown https://github.com/rstudio/bookdown.git 92e702a5133adcbce1f7e3f35cd9700bcbb370b6 # clean, 4063 stars -rmarkdown https://github.com/rstudio/rmarkdown.git 194c2a11e3d345e294906152b6f60f0439422022 # clean, 3054 stars +rmarkdown https://github.com/rstudio/rmarkdown.git 194c2a11e3d345e294906152b6f60f0439422022 # 2 diagnostics, 3054 stars devtools https://github.com/r-lib/devtools.git 5a10248bb3b727f84a34e517b92fff118652be1e # clean, 2516 stars tidyverse https://github.com/tidyverse/tidyverse.git 0231aafbc56914ee5371dd6c7b60677f168d7154 # clean, 1797 stars rticles https://github.com/rstudio/rticles.git 2e55e747dacb65c2645cc0273db7f7374a1bb1f2 # clean, 1538 stars rvest https://github.com/tidyverse/rvest.git 6c955c0ecfbb0f0bdb1891f0ef952af388b51851 # clean, 1522 stars -tidyr https://github.com/tidyverse/tidyr.git 26f83e89a690b6cf31a260489b828df0ff43ebb2 # clean, 1437 stars +tidyr https://github.com/tidyverse/tidyr.git 26f83e89a690b6cf31a260489b828df0ff43ebb2 # 8 diagnostics, 1437 stars actions https://github.com/r-lib/actions.git aae88a2d9cd3d63571eb05980b09f44611788515 # clean, 1064 stars readr https://github.com/tidyverse/readr.git 238ea873fdc1a34b3638f01493bd8df9f770ac62 # clean, 1036 stars magrittr https://github.com/tidyverse/magrittr.git 73d66ee89c1079d66d235bfde551b6110c934259 # clean, 972 stars @@ -69,13 +69,13 @@ tidymodels https://github.com/tidymodels/tidymodels.git 35bb4145b32999a651e3b6db tibble https://github.com/tidyverse/tibble.git b5e7406e83d8c3291573dbd1ae06bbb9f87b6aac # clean, 755 stars readxl https://github.com/tidyverse/readxl.git 47f8aeac0a99eee6c6db2d64ead2225e5e3ae4af # clean, 752 stars reprex https://github.com/tidyverse/reprex.git 0dcf301940c050e1cf32f230cab45503d85ac5a4 # clean, 752 stars -learnr https://github.com/rstudio/learnr.git e7164a86172200cdfeb53c5f17382e1f86e3e78a # clean, 735 stars -dtplyr https://github.com/tidyverse/dtplyr.git bffe46e664d62021e47251c158c9f02c4cd30400 # clean, 676 stars +learnr https://github.com/rstudio/learnr.git e7164a86172200cdfeb53c5f17382e1f86e3e78a # 1 diagnostics, 735 stars +dtplyr https://github.com/tidyverse/dtplyr.git bffe46e664d62021e47251c158c9f02c4cd30400 # 3 diagnostics, 676 stars stringr https://github.com/tidyverse/stringr.git ae054b1d28f630fee22ddb3cb7525396e62af4fe # clean, 665 stars multidplyr https://github.com/tidyverse/multidplyr.git e960a1e83f6a0dded147366053b1d057d46ad2f4 # clean, 650 stars vroom https://github.com/tidyverse/vroom.git 56e0ce23bd40de8acc3daacc0e85924b7c18d766 # clean, 642 stars dt https://github.com/rstudio/DT.git 6f957f3126b2999e2f65cdeac942d930fb34b8ea # clean, 621 stars blastula https://github.com/rstudio/blastula.git 8b8a6f97ec3aa4cf605321ed3ee7a65c31dc4b24 # clean, 575 stars -bslib https://github.com/rstudio/bslib.git f74283b4782f0871254d21b3edf59d84a621b1d2 # clean, 565 stars +bslib https://github.com/rstudio/bslib.git f74283b4782f0871254d21b3edf59d84a621b1d2 # 5 diagnostics, 565 stars forcats https://github.com/tidyverse/forcats.git f83e0e682d9f874d066630ff78eb12586b5b2a32 # clean, 558 stars r2d3 https://github.com/rstudio/r2d3.git becfb81989c7fabfe79dee2dde999190025d4ba3 # clean, 525 stars From d278b41be2c70da7511e5a49ad9784b2fe9842f6 Mon Sep 17 00:00:00 2001 From: Maximilian Scholz Date: Wed, 16 Sep 2026 23:25:13 +0200 Subject: [PATCH 2/2] docs(corpus): credit #459 for emptying the scales report Review of #501: 6d4ba4f, the commit that took ecosystem/reports/scales.root.txt from 62 bytes to empty, landed via #459, not #460 (the 0.10.0 release-prep PR merged a few hours later, none of whose commits touch the file). The README attribution now names the PR that actually emptied it; the curl/jsonlite -> #374 attribution on the same line is verified correct and unchanged. --- docs/corpus/README.md | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/docs/corpus/README.md b/docs/corpus/README.md index 581ac24c..77557b79 100644 --- a/docs/corpus/README.md +++ b/docs/corpus/README.md @@ -105,7 +105,7 @@ entries — while the index’s “24 Packages” counts ledger packages-block entries: eight manifest packages (cli, curl, fs, jsonlite, rlang, scales, testthat, withr) have no block entry. Three of their reports (cli, rlang, testthat) contain 44 unowned findings in total; the remaining five (curl, fs, -jsonlite, scales, withr) are empty — scales since #460, curl and jsonlite +jsonlite, scales, withr) are empty — scales since #459, curl and jsonlite since the #374 superassignment modeling. The Posit ledger’s `source_sha256` hashes the concatenated bytes of all