Skip to content

ship/draft continuity recovery - #7939

Merged
matthewevans merged 9 commits into
mainfrom
ship/draft-continuity-recovery
Aug 26, 2026
Merged

ship/draft continuity recovery#7939
matthewevans merged 9 commits into
mainfrom
ship/draft-continuity-recovery

fix(draft): close recovery review gaps

2381b87
Select commit
Loading
Failed to load commit list.
Superagent Security / Contributor trust completed Aug 26, 2026 in 3s

Contributor trust inconclusive

Investigator 1/3: Investigated 34 assigned PRs (10 with hydrated patches, 24 metadata-only). Full/preview patches reviewed for #7833, #7812, #7914, #7832, #7807, #7804, #7784, #7775, #7708, and #7720 show benign, project-typical work: MTG engine rule fixes, UI/i18n improvements, P2P session-hardening, changelog updates, and data-feed refreshes. No suspicious signals in any reviewed hunk (no credential exfiltration, obfuscation, hidden network calls, CI tampering, or permission broadening). The contributor is a MEMBER of phase-rs with sustained, coherent activity in a single repository. Verdict is caution rather than safe because 24 PRs in this shard were metadata-only (unknown) and 70 candidate PRs were omitted globally, leaving material coverage gaps that prevent a high-confidence positive assessment. Investigator 2/3: Investigator 2 reviewed 30 hydrated PRs from contributor matthewevans (shard of 33 from 100 candidate PRs). Ten PRs carried full or preview patches; twenty were metadata-only. All reviewed patches show legitimate, well-documented contributions to the phase-rs/phase project, consistent with the contributor's MEMBER status. Changes span MTG game-engine rules (CR citations, target resolution, payment flows), client UI fixes (drag gestures, stack display, i18n), AI policy hardening, documentation corrections, and automated data refreshes. No patch introduced credential exfiltration, hidden network calls, obfuscation, permission broadening, CI tampering, dependency manipulation, or behavior inconsistent with the PR description. The contributor's activity is confined almost entirely to a single repository with no cross-repo burst pattern. Confidence is medium rather than high because 70 of 100 candidate PRs were omitted from the evidence packet, leaving residual uncertainty; however, the available patch-level evidence is uniformly benign and shows deep domain expertise rather than supply-chain attack behavior. Investigator 3/3: All fully hydrated patches in this shard show legitimate, well-tested bug fixes and maintenance on the phase-rs/phase Magic: The Gathering engine. The contributor is an organization member with coherent, domain-appropriate activity across 58 PRs over ~1 month. The six PRs with full patch mode (7811, 7919, 7909, 7813, 7805, 7407) contain no suspicious signals—only AI logic fixes, P2P reconnection hardening, automated card-data refreshes, UI layout improvements, rules-correct engine changes, and metagame feed updates. The remaining PRs in the shard are either preview-truncated or metadata-only; while this limits complete review coverage, their titles, file paths, and descriptions follow the identical benign patterns observed in the fully hydrated set. No cross-repository burst, no credential handling, no hidden network calls, no dependency tampering, and no obfuscation were found in any patch that could be reviewed. Patch-level safety guard downgraded the result to caution: 70 PRs were metadata-only after compact hydration.