Skip to content

fix: prioritize selectable library search cards - #6972

Merged
matthewevans merged 1 commit into
mainfrom
ship/fix-prioritize-selectable-library-search-cards
Aug 3, 2026
Merged

fix: prioritize selectable library search cards#6972
matthewevans merged 1 commit into
mainfrom
ship/fix-prioritize-selectable-library-search-cards

fix: prioritize selectable library search cards

4fd3c74
Select commit
Loading
Failed to load commit list.
Superagent Security / Contributor trust completed Aug 3, 2026 in 1s

Contributor trust inconclusive

Investigator 1/3: Investigator 1 reviewed 34 PRs from member contributor matthewevans (10 with hydrated patches, 24 metadata-only). All hydrated patches show legitimate, sophisticated Magic: The Gathering engine development: parser bugfixes (PR #6853, #6882), engine refactors with extensive tests (PR #6819, #6933), agent workflow hardening (PR #6931), metagame data refreshes (PR #6835, #6810), WASM proposal fixes (PR #6830), BO3 concession controls (PR #6817), and parser IR modernization (PR #6806). No evidence of credential exfiltration, hidden network calls, dependency tampering, obfuscated code, CI tampering, or backdoors. The 24 metadata-only PRs follow consistent engine/parser refactor patterns. Contributor has focused activity in a single repository as a MEMBER with no broad cross-repo activity. Investigator 2/3: All hydrated patches in this shard are benign. The contributor (matthewevans) is a MEMBER of phase-rs/phase, and every PR targets that single repository. Fully reviewed patches consist of: (1) automated MTGJSON card-data refreshes (token catalogs and vintage date stamps), (2) metagame feed JSON updates from MTGGoldfish, (3) a changelog publication with gameplay/UI/AI release notes, (4) a Rust regression test for resolution-stack frame transitions, and (5) previewed parser/engine refactorings and AI security-hardening changes that bind AI actions to engine-validated proposals. None of the patches introduce network calls, credential handling, obfuscated code, dependency/script changes, or permission broadening. There is no cross-repository burst and no unsolicited PR activity. The metadata-only PRs are consistent with the same patterns (data feeds, parser refactors, client/UI fixes, engine journaling). No credible malicious or backdoor evidence was found. Investigator 3/3: Investigator 3 reviewed 33 assigned PRs from contributor 'matthewevans' across the phase-rs/phase repository. Ten PRs had full or preview patches hydrated; the remainder were metadata-only. All hydrated patches show legitimate, high-quality contributions to a Magic: The Gathering game engine (parser, engine core, AI, client UI). Code is extensively commented with Comprehensive Rules citations, includes thorough test coverage and integration tests, and contains no evidence of credential exfiltration, hidden network calls, obfuscated code, CI tampering, suspicious dependency changes, or backdoors. PR #6847 is an automated data feed refresh with no executable code. The contributor is a MEMBER of the organization with activity concentrated in a single legitimate project (plus its fork). No cross-repo pattern of concern. The metadata-only PRs follow consistent naming and description patterns matching the hydrated ones (parser refactors, engine fixes, AI improvements, documentation updates). Based on direct patch-level review of the highest-risk hydrated PRs and the absence of any suspicious signals, the contributor's history is assessed as safe. Patch-level safety guard downgraded the result to caution: 70 PRs were metadata-only after compact hydration.