Summary
One low-severity correctness defect confirmed against the audited commit: --output silently truncates an existing CSV.
Findings
Found by the 2026-09-02 codebase audit, finding A10-010, reported by one reviewer and independently confirmed by a second. Full report: docs/audits/codebase-audit-2026-09-02.md.
Scope after the split
Monorepo split: this repo is now CLI-only (cmd/*.go). A05-015, A06-009, A06-019 lived in internal/purchase, internal/server, internal/analytics, which are not in this repo, so they were split out. A06-022 lived in internal/reporter, which moved to pkg/reporter in the go repo, so it was split out too. This issue is now scoped to A10-010 only, which remains this repo's own code.
Sibling issues:
Summary
One low-severity correctness defect confirmed against the audited commit:
--outputsilently truncates an existing CSV.Findings
--outputsilently truncates an existing CSV (A10-010)cmd/multi_service_csv.go:198(os.Create);validateFilePathsatcmd/validators.go:213-222stats only the parent directory;generateCSVFilenamereturnscfg.CSVOutputverbatim atcmd/multi_service_helpers.go:162-165at 3c0f8accudly --purchase --output run.csv, then re-runs with the same--outputwhile iterating on filters.os.Createtruncates the first run's purchase report. The auto-generated filename is timestamped and safe, so the hazard is confined to the explicit-path case. Scope note from the verifier: on the main purchase path the durable record of what was bought is the append-only audit log (cmd/multi_service.go:401-404,pkg/common/audit.go:28, LeanerCloud/cloud-commitments-go), so the CSV is not the only record; the harm holds fully only on the--input-csvpath, which writes no audit records.validateFilePaths,os.Statthe--outputpath and refuse when it exists, or open withos.O_CREATE|os.O_EXCLand surface the collision.Found by the 2026-09-02 codebase audit, finding
A10-010, reported by one reviewer and independently confirmed by a second. Full report:docs/audits/codebase-audit-2026-09-02.md.Scope after the split
Monorepo split: this repo is now CLI-only (
cmd/*.go). A05-015, A06-009, A06-019 lived ininternal/purchase,internal/server,internal/analytics, which are not in this repo, so they were split out. A06-022 lived ininternal/reporter, which moved topkg/reporterin the go repo, so it was split out too. This issue is now scoped to A10-010 only, which remains this repo's own code.Sibling issues:
pkg/reporter).