From d4a4fabe454173addf6cf183c52c6ce0b78df0d1 Mon Sep 17 00:00:00 2001 From: Bart Waardenburg Date: Tue, 6 Oct 2026 06:48:48 +0200 Subject: [PATCH] docs: state which script regions gdp-proof-producer checks The rule checks script and module code, including JSX expressions, but not template expressions or Astro inline client scripts. --- explanations/dead-code.mdx | 4 +++- public-content-manifest.json | 6 +++--- 2 files changed, 6 insertions(+), 4 deletions(-) diff --git a/explanations/dead-code.mdx b/explanations/dead-code.mdx index 3cbed43..1475f91 100644 --- a/explanations/dead-code.mdx +++ b/explanations/dead-code.mdx @@ -485,7 +485,9 @@ The `rules."policy-violation"` master setting defaults to `warn`. A per-rule `se The opt-in `gdp-proof-producer` rule follows calls to `@gdp-ts/core.defineProof` through the module graph. It reports factory creation outside the rule's `allowedFiles`. With `proofKinds`, you can require a specific literal proof label to be created only in its owner file. Configure both rules in a [rule pack](/configuration/overview#config-fields). -Fallow recognizes direct, renamed, and namespace imports, including unambiguous re-exports through project modules and workspace packages. A locally shadowed import name does not match. Each call site gets its own finding, with the resolved factory and a static proof label when available. This rule also checks analyzed files unreachable from entry points. +Fallow recognizes direct, renamed, and namespace imports, including unambiguous re-exports through project modules and workspace packages. A locally shadowed import name does not match. Each recognized call site gets its own finding, with the resolved factory and a static proof label when available. This rule also checks analyzed files unreachable from entry points. + +The rule checks JavaScript and TypeScript source, including JSX expressions, Vue and Svelte script blocks, Astro frontmatter, and MDX module statements. It does not check calls in Vue, Svelte, Astro, or MDX template expressions, or in Astro inline client scripts. Move the factory to an allowed authorization module and expose an operation that performs the permission check. Retain the gdp-ts ESLint or Oxlint rules, including `no-exported-prover`, and your TypeScript checks. Restricting factory locations does not prevent an allowed module from exporting a prover that callers can invoke without authorization. diff --git a/public-content-manifest.json b/public-content-manifest.json index c9c846c..4ea3353 100644 --- a/public-content-manifest.json +++ b/public-content-manifest.json @@ -7,7 +7,7 @@ "visibility": "public-only" }, "content": { - "sha256": "8e95c54d440d2281ae6fd8ecabd36a66e163818f824b7385b859448d20fdcd09", + "sha256": "438916731ae5721947f6a9bfc2c7a0d72b431830d4cf3a59c6dd6d977815568a", "files": [ { "path": "adoption.mdx", @@ -291,8 +291,8 @@ }, { "path": "explanations/dead-code.mdx", - "bytes": 92939, - "sha256": "59a88315d81e3195613a30e2944b65e4823e783583ef8846efdfe5daab60c91c" + "bytes": 93215, + "sha256": "8e557f7ac7f2bdcf232a59821c19e991b80f15dfa739a28804b5297a2f54534f" }, { "path": "explanations/duplication.mdx",