## Dicklesworthstone/ultimate_bug_scanner — v5.4.18…v5.4.19

_36 commits._

### Features
- **feat: connect verified scan service and scoped JVM dataflow** (53e8a1c)
- **feat(python): track shell argv and executable provenance across command APIs** (f70052f)
- **feat(python): activate control-flow-aware command-injection analysis** (68586a9)

### Fixes
- **fix(taint): retain loop states while heap-call summaries are pending** (e6b1cd3)
- **fix(taint): release recursive argument-expansion closures after each call** (3058733)
- **perf(js-taint): preserve sink-domain pruning and its regression coverage** (2302ab9)
- **perf(js): retain escaping heap-call effects without carrying helper-local allocations** (f7bb72e)
- **perf(js): retain closure cells while removing unused whole-block capture states** (f8d1796)
- **perf(report): recount JavaScript bridge findings without retaining the sink** (3aaba1f)
- **perf(js): avoid sink-free scope graphs and preserve v5.4.19 evidence** (072e948)
- **perf(js): stream selection reconciliation and complete JSON finding reports** (852e771)
- **perf(js): solve active sink rules and release completed taint flow state** (08a1fb4)

### Backend
- **Merge upstream analysis fixes and harden Ruby rule allocation (q150.6)** (f11f08f)
- **merge: retain remote taint improvements and all local scan-cost regressions** (809e161)
- **harmonize(rust): scope-aware archive-entry-path detector precision (from stranded scratch_and_probes/ubs-qual-greenfinch-57.dALzOR, orig bead 0xjg.7 detector, tree on 881097b)** (2a44006)
- **merge: retain published Python compatibility validation and both parent histories** (b1c505a)
- **merge: preserve closure-state optimization and published macOS control-flow validation** (43c483d)

### Tests
- **test(rust): retry bounded isolated publication on the responding ARM pool** (ebab133)
- **test(rust): bound decoding memory for the verified legacy checkpoint** (84108c2)
- **test(rust): retry isolated validation on standard Linux and preserve file modes** (0f9e9d3)
- **test(rust): isolate read-only dataflow validation from data-only blob publication** (a663000)
- **test(csharp): validate project linking and indexed resolution as separate atomic batches** (b35ef53)
- **test(csharp): validate selected-project dataflow and atomic installation integrity** (0d2cf99)
- **test(python): rebase validated command batches onto concurrent Rust security changes** (a8bf55b)
- **test(python): retry immutable publication across independent hosted runner pools** (4ae3a11)
- **test(python): retry frozen command-analysis publication on lightweight runners** (5399310)
- **test(python): validate final command batches while preserving concurrent runtime pins** (888cfde)
- **test(python): validate both command-analysis batches with atomic integrity snapshots** (f247072)
- **test(python): preserve Python 3.9 compatibility in control-flow validation** (c31e50a)
- **test(python): validate command control-flow candidate on macOS** (f9c9ef1)
- **test(python): validate command control-flow candidate and installation integrity** (59a60b2)

### Docs
- **docs(beads): retain C6 replay losses, recovered evidence and the lifetime checkpoint** (01f876b)
- **docs(beads): preserve C6's failed real-corpus memory gate and bounded replay evidence** (9b2625b)
- **docs(beads): preserve the JavaScript memory-check acceptance checkpoint** (9a9f5b4)

### Chore
- **chore(beads): retain the C6 pending-summary investigation and open gates** (492ff8b)
- **refactor(js): bound parser spans and function-body retention (q150.6)** (3181bdc)

_Recap by [Repo Wrapped](https://repowrapped.com/gh/Dicklesworthstone/ultimate_bug_scanner?utm_source=github-action)._