docs: fix-verification pass over the review-remediation batch (#50–#65) - #66
Merged
Merged
Conversation
Read-only verification of PRs #50-#65 against the current merged state of dev. Confirms 10/11 HIGH, 26/26 MEDIUM (as addressed), and 24/25 LOW findings resolved with covering tests, and that the five mid-batch decisions (M2, M11, M23, H11, CON-11) landed as decided. Flags the one genuine miss (H5/CON-4, scanner JSON parse still on the event loop, with no deviation entry), triages the two Dependabot default-branch alerts as already-fixed-on-dev-pending-promotion, and notes the L24/SC-11 and M19-untested residuals.
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Summary
Read-only verification of the review-remediation batch (PRs #50–#65) against the current merged state of
dev(e545d77), not against what any report claims. Addsdocs/reviews/fix-verification.md. Docs only — no application code touched.Headline results
scanners/trivy.py:285,grype.py:186,base.py:362), and it has nodocs/ARCHIVE.md§14 entry at all (fell through the gap between the "Top 5 Phase 1 — Auth & secrets foundation #2" and "CON-5–CON-20" change-sets). Not fixed, not logged as deferred.persist-credentials: falsemissing onci.yml(partial, low risk).Decision-specific checks (all landed as decided)
le=32, AND the connection-release-after-atomic-claim refactor).v0.4.2; wollomatic migration NOT done in-batch, tracked in issue Evaluate migrating the Docker socket proxy from tecnativa to wollomatic/socket-proxy #63.--require-hashesinstall; CI drift check present.Regressions / conflicts checked — all clean
CON-10 session threading in
_run/_dispatch/_persist/_fail/_notify; CSP vs. the SPA; the two "Run now" fixes (L8/CON-17 ↔ L12/APIR-7, no double-apply); restore/backup pair (M10/CON-9 ↔ CON-3/SEC-2, no conflict). CLAUDE.md ↔ §14 drift (R1–R8, D1, D2) confirmed closed.Dependabot triage (2 alerts: 1 high, 1 moderate on default branch)
Default branch is
main@ v0.1.0; the entire remediation batch (H11 lockfile, SC dependency bumps, #51 dogfood CVE fixes) lives ondevand is unpromoted. The alerts are category (a) — already fixed ondev, pending a release promotion — not genuinely new CVEs. Recommended: promotedev→main. (The exact advisory IDs couldn't be enumerated from this read-only session — the Dependabot alerts endpoint isn't exposed by the available tooling; the triage is structural.)See
docs/reviews/fix-verification.mdfor the full regressions/needs-attention section, HIGH/MEDIUM tables, LOW backlog, and decision-verification detail.Not merging — for your review.