chore: strip advisory IDs from code comments and changelog (#4720)

Per the project's policy of treating security advisory IDs as
secret-like, remove the identifiers embedded in source/test comments
and CHANGELOG entries. Each keeps its human-readable description (and
PR number where present), so traceability is preserved. No logic changes.
This commit is contained in:
jekkos authored and GitHub committed 2026-09-30 15:49:18 +02:00
1 parent 5d56c2cecd
commit 9eaa2f34f3
15 files changed
+25 -25

No files matched your search

+1 -1
View File
@@ -14,7 +14,7 @@ use Tests\Support\EmployeeFixtureTrait;
use Tests\Support\SaleFixtureTrait;
/**
* Regression tests for GHSA-3xf6-8fmq-44wg.
* Regression tests for the Sales per-endpoint access-control bypass.
*
* A cashier holding only the base "sales" grant (no "reports_sales") must
* not be able to reach the per-sale endpoints that getManage() gates