# Repo hygiene scan (P0.8) Tracked build artifacts, secrets posture, dependency audit, lint/CI gaps. Feeds P5 (repo health / audit-readiness pack). Measured against the repo at commit `b5f61a7` (2026-08-18). This is measurement only. No code, config, or history was changed to produce this document. ## 1. Tracked build artifacts **Confirmed: two build artifacts are tracked and churn on every commit.** `git ls-files | grep tsbuildinfo` → - `webapp/tsconfig.app.tsbuildinfo` (4,853 bytes) - `webapp/tsconfig.node.tsbuildinfo` (47 bytes) Both are TypeScript incremental-build caches, regenerated by every `tsc -b` run. Neither is in `.gitignore` (checked: no `tsbuildinfo` entry exists). Confirmed churning: both files were touched by the two most recent commits (`design(S2)`/`design(S1)`, unrelated feature work) — meaning every commit that runs a typecheck picks up a noise diff on these two files whether or not the change is otherwise related to the webapp build config. Only `webapp/tsconfig.app.tsbuildinfo` was named in the original gauntlet item; `webapp/tsconfig.node.tsbuildinfo` is the same class of file and was found by the same grep, not previously flagged. **No other tracked build artifacts found** — no `dist/`, `build/`, `coverage/`, `*.log`, or `node_modules` entries in `git ls-files` (all four are gitignored and the gitignore is effective, confirmed by absence). ## 2. Secrets posture **Clean — no secret was ever committed, at any point in history.** - `seed.txt`, `*.seed`, `.env`, `.env.*` (with `.env.example` excepted) are all gitignored (`.gitignore:1-6`). - `git log --all --diff-filter=A --name-only` for `seed.txt`, any `.env` file, mnemonic files, and `*.pem`/private-key filenames returns **zero matches** — none of these filenames were ever added to the repo, at any commit, on any branch. - `git log --all -p -- '*.env' 'seed.txt'` grepped for the literal string `mnemonic` (case-insensitive) across every historical diff of any `.env`-named file — **zero matches**. - The one file matching a naive `\.env$` grep, `ops/deploy/vps.env`, is **not a secret** — read in full: it's network-bind port overrides (`READ_PROXY_BIND= 127.0.0.1`, `READ_INDEX_BIND=127.0.0.1`, etc.) for one specific deploy host, with a header comment explicitly stating "Not secrets — safe to commit." Confirmed accurate by content inspection. - `ops/deploy/gcp-logging-key.json` (the GCP service-account key for the log shipper) is explicitly gitignored (`.gitignore:9`) with a comment noting `deploy.ps1` scps it to the host separately — never tracked. ## 3. Dependency audit `pnpm audit --prod` → **"No known vulnerabilities found."** Clean at the time of this scan; this is a point-in-time result, not a standing guarantee — worth re-running periodically rather than treating as permanently closed. ## 4. Lint / CI gaps **Two real gaps found, not previously documented anywhere in the gauntlet backlog.** **(a) CI (`​.github/workflows/ci.yml`) runs only 2 of the repo's 8 test-bearing packages.** The workflow has exactly two jobs: `contracts` (`pnpm --filter ton-primes-contracts test`) and `sim` (`pytest -q` in `sim/`). Per the P0.0d baseline (iteration 5, 2026-08-17), the repo has **47 test files across 8 packages, 972 tests** — `webapp` (38 files/379 tests), `read-proxy` (12/201), `event-poller` (6/51), `keeper` (2/17), `attribution` (3/41), and `bot` (2/35) are never run in CI. A regression in any of those six packages would merge to `main` without CI ever noticing. This is the single most consequential finding in this scan — CI is not exercising 78% of the repo's test files (36 of 46 non-contracts/sim files) or roughly 71% of its tests (725 of 1,022 total across everything, contracts+sim included). **(b) No repo-wide lint script or CI lint step.** Only `webapp/package.json` declares a `"lint"` script; the root `package.json` has no `lint` script at all (its `scripts` block has only `test:contracts` and `test:sim`), and none of the backend packages (`read-proxy`, `event-poller`, `keeper`, `attribution`), `bot/`, or `contracts/` declare one. CI runs no lint step at all, for any package. **Correction, 2026-08-18 (P5.1):** this entry originally speculated that several packages "have ESLint or equivalent tooling available via their `devDependencies`," flagged as not exhaustively verified. Verified while doing P5.1: that speculation was wrong. **ESLint is not installed anywhere in the repo** — zero `devDependencies` entry and zero config file in `webapp/`, every `backend/*` package, `bot/`, or root. `webapp/package.json`'s `"lint"` script has never actually been able to run. This is a bigger gap than "wire the existing lint into CI" — it needs ESLint stood up from scratch, filed as `GAUNTLET.md` P5.3. **No other CI/lint gaps found** — the two existing CI jobs correctly use `--frozen-lockfile`, pin Node 20 and Python 3.12, and cache dependencies. The CI coverage gap (§1's 6 missing packages) and the tracked `.tsbuildinfo` files (§1) are both closed as of P5.1, 2026-08-18 — see the summary table below. ## Summary | Area | Finding | Severity | |---|---|---| | Tracked build artifacts | ~~2 `.tsbuildinfo` files tracked, churn every typecheck~~ **Fixed (P5.1, 2026-08-18)**: untracked, `*.tsbuildinfo` gitignored | Low — cosmetic noise, no correctness risk | | Secrets posture | Clean — nothing ever committed, across full history | None | | Dependency audit | Clean at time of scan | None (re-check periodically) | | CI coverage | ~~6 of 8 test-bearing packages never run in CI~~ **Fixed (P5.1, 2026-08-18)**: all 8 packages now run in CI | **High — a real gap in the safety net, not cosmetic** (now closed) | | Lint | No repo-wide lint script; CI runs no lint step | Medium | This feeds P5 directly. The CI coverage gap (4a) is the standout finding of this scan — everything else here is routine hygiene, but a merge to `main` today can silently break any of six packages with 725 tests between them and CI will report green.