Sitelet https://github.com/msgwing/ZeroSMTP/pull/273
Skip to content

feat(ci): sprawdzaj czy strony producentow istnieja, i mow gdy nie da sie stwierdzic - #273

Merged
msgwing merged 1 commit into
mainfrom
verify-advisory-links
Aug 24, 2026
Merged

msgwing merged 1 commit into
mainfrom
verify-advisory-links

Conversation

@msgwing

@msgwing msgwing commented Aug 24, 2026

Copy link
Copy Markdown
Owner

Każdy wiersz w data/devices.json jest wart cytowania dlatego, że stoi za nim strona producenta. Gdy taka strona się przenosi, wiersz dalej coś twierdzi, nie mając za sobą niczego — i nikt się nie dowiaduje, dopóki czytelnik nie kliknie.

Dwadzieścia wierszy, siedemnaście zewnętrznych linków, zero sprawdzania. Miesięczny przegląd wypisywał je człowiekowi do klikania.

Fakt zautomatyzowany, ocena zostawiona

Czy strona istnieje — fakt, więc jest sprawdzana. Czy oświadczenie zmieniło się w sposób istotny — ocena, więc zostaje przy człowieku. Ten workflow już rysował tę granicę i zostaję po tej samej stronie.

Trzy wyniki, nie dwa — i trzeci jest tym, który czyni to użytecznym

Wynik Znaczenie
ok strona odpowiada
gone (404/410) producent mówi, że strony nie ma — wiersz stracił dowód
unverified nie dało się dosięgnąć z serwerowni — co jest zupełnie innym stwierdzeniem

To rozróżnienie nie jest teoretyczne. support.hp.com odpowiedziało 200 z ręki dziś rano i odmówiło połączenia godzinę później z tej samej maszyny. Kilku z tych producentów ogranicza ruch albo blokuje adresy nieresydencjalne.

Pierwsza wersja tego sprawdzenia oznaczyła wszystkie szesnaście linków jako zepsute — a to była sieć, nie producenci.

Wysłanie tamtej wersji dałoby miesięczną listę pełną nieprawdziwych alarmów. Lista, która krzyczy „wilk", przestaje być czytana — a to kosztuje więcej, niż całe sprawdzenie było kiedykolwiek warte.

… cannot tell

Every row in data/devices.json is worth citing because a vendor page stands
behind it. When one of those pages moves, the row goes on asserting something
with nothing holding it up, and nobody finds out until a reader clicks. Twenty
rows, seventeen external links, and nothing was testing them - the monthly
review listed them for a human to click.

Whether a page still exists is a fact, so it gets checked. Whether an advisory
changed in a way that matters is a judgement, so it stays with a person. The
existing note in this workflow already drew that line and this stays on the
same side of it.

The implementation has three outcomes rather than two, and the third is the
one that makes it usable. 404 and 410 are the vendor saying the page is gone:
definite, flagged loudly, and the row has lost its evidence. Everything else -
a timeout, a 403, a refused connection - means we could not reach the page from
a data centre, which is a different statement entirely.

That distinction is not theoretical. support.hp.com answered 200 by hand this
morning and refused a connection an hour later from the same machine; several
of these vendors rate-limit or block non-residential addresses. A first draft
of this check flagged all sixteen links as broken, which was the network and
not the vendors.

Shipping that version would have produced a monthly checklist full of alarms
that are not real, and a checklist that cries wolf stops being read - which
costs more than the check was ever worth. The unverified case is therefore
worded as a note that the check could not be taken, which is the same rule this
project applies to every other measurement it cannot make.
@msgwing
msgwing enabled auto-merge August 24, 2026 21:45
@github-actions github-actions Bot added the ci label Aug 24, 2026
@msgwing
msgwing merged commit 8881ce2 into main Aug 24, 2026
36 checks passed
@msgwing
msgwing deleted the verify-advisory-links branch August 24, 2026 21:46
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant