docs(reviews): add STATUS.md as current source of truth for the review-remediation batch - #74
Merged
Merged
Conversation
…w-remediation batch Re-verifies every finding across all six original code-review reports (including findings never carried into 00-summary.md) against the current state of dev, after the H5/CON-4 follow-up (#67) and the dev->main promotion (#70). Records the current STILL-OPEN backlog (frontend Priority-3 batch, SC-12/SC-14, D5b, test debt), deferred-by-decision items with their tracking refs, a resolved index, and the ARCHIVE.md section-14 entry gaps (#53 H1/SEC-1, #57 H9+H10, #65 D1/D2/R1-R6, #59).
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Summary
Adds
docs/reviews/STATUS.md— a single, current status document for the 2026-07 code-reviewremediation batch — produced by a fresh, read-only re-verification of every finding
across all six original
/code-reviewreports (security, supply-chain, api, frontend,concurrency, claude-md-compliance) against the current state of
devatfile:line. Thisincludes findings that were never carried into
00-summary.md's severity tables. Noapplication code was changed; the only file added is the status doc.
STATUS.md is intended to replace the need to read the older per-report files for current
status going forward.
What it records
file:line) — all LOW/INFO: thefrontend-review Priority 3 batch (P3-1…P3-8, never summarized), SC-12 (floating build
backend), SC-14 (tests/scripts in runtime image), D5b (latent ruff
I001), plus test debt onM19/M20/M21. No HIGH or MEDIUM findings remain open.
standardization (
ROADMAP.md:84-86), SC-13 Mantine v7 (locked §2), and the acceptedaudit-only limitations L1/L2/L3.
(H1/SEC-1), ci: SHA-pin workflow actions, expand Dependabot coverage, harden checkouts #57 (H9/SC-2 + H10/SC-3), docs: close CLAUDE.md compliance drift (D1, D2, R1–R8) #65 (D1/D2/R1–R6), and backend: bump pytest 9.0.3, pytest-asyncio 1.4.0, black 26.3.1 #59 (dev-dep bumps).
Notes
dev→mainpromotion (Promote dev to main: security & code-review remediation batch #70), so itsupersedes
fix-verification.mdwhere its status has since changed (H5 and L24 now resolved;promotion done).
docs/reviews/folder (keep-as-historical vs. archive)is provided out-of-band for the maintainer to decide — no files were moved or deleted.
See
docs/reviews/STATUS.mdfor the full detail.