Every ticket as the root of its provenance graph — goal, patch, approval, runs and (as the ticket-class build lands) mandate, manifestations, guarantees, journey, artifacts and children. Rendered through the <<<TicketGraphList>>> tag.
PREDICTION: $itemKey in SQL + isset($itemKey) closes the SQLi
goal
PREDICTION: validateNumericKey("5 OR 1=1")=NULL and validateNumericKey("5")="5"; after fix no raw $key remains in CatalogDAO SQL, a malicious key builds no injectable query; gates green. [RESULT] CONFIRMED — no raw $key in SQL; malicious keys sanitize to NULL -> guard skips -> no injectable query; valid numeric passes; gates green.
patch
none
approval
unapproved
runs
no runs recorded
mandate (clauses)
not yet recorded — lands with the ticket-class build
manifestations
not yet recorded — lands with the ticket-class build
guarantees
not yet recorded — lands with the ticket-class build
journey (blunders & successes)
not yet recorded — lands with the ticket-class build
artifacts (forge)
not yet recorded — lands with the ticket-class build