← rule catalog
stale.version-pin
heuristicunmeasuredseverity: low
A behavioral claim we believe and have not measured. Labeled unmeasured in every reporter line, excluded from the chaff score, and never fails a build by default.
Claim
A pinned build/version string sits in resident prose. Version pins go stale silently and then mislead.
Rationale
A version in prose ("2.1.220") is a fact with an expiry date and no expiry marking. Believed harmful; not yet measured.
Fix
State the behavior, not the build number, or move the pin into a lockfile/config the tooling owns.
chaff explain stale.version-pin: same registry, offline, from the CLI.