Whack-a-Mole Fix
detected 2026-03-02
trigger
"6 CSP commits over 11 days, each adding one domain."
what it is
Fixing a class of problem one instance at a time instead of auditing the class. 6 commits adding CSP domains one by one rather than auditing all third-party integrations up front.
what it signals
instead
On the second instance, stop and audit the complete set.
refs
- wake: CSP commit chain 11cc574 through 6b25ae0 (11 days, 6 commits)
← all patterns