Whack-a-Mole Fix

detected 2026-03-02

trigger

"6 CSP commits over 11 days, each adding one domain."

what it is

Fixing a class of problem one instance at a time instead of auditing the class. 6 commits adding CSP domains one by one rather than auditing all third-party integrations up front.

what it signals

instead

On the second instance, stop and audit the complete set.

refs

  • wake: CSP commit chain 11cc574 through 6b25ae0 (11 days, 6 commits)

← all patterns