Skip to content

docs(release): close the 3.8.54 cycle — changelog, evolution status, roadmap and final audit - #40

Merged
LMPrado-DZ23 merged 10 commits into
release/v3.8.54from
chore/release-3854-final
Sep 19, 2026
Merged

LMPrado-DZ23 merged 10 commits into
release/v3.8.54from
chore/release-3854-final

Conversation

@LMPrado-DZ23

Copy link
Copy Markdown
Owner

Closes the v3.8.54 evolution cycle: the release documents, and the consolidated record of the three independent audits and their verification round.

What changes

Verification

Run with isolated DATA_DIR / HOME / USERPROFILE / APPDATA:

Gate Exit Result
check-changelog-integrity 0 no base bullets lost vs origin/release/v3.8.54
check-docs-sync 0 41 locales, version sections + size check
check-docs-frontmatter 0 132 docs
check-doc-links 0 172 docs, 1043 internal links
check-fabricated-docs 0 no fabricated API/env/CLI references
check-env-doc-sync 0 —
check-deprecated-versions 0 —
check-docs-counts-sync 0 —

Documentation only — no runtime code changes.

🤖 Generated with Claude Code

…admap

Dates the [3.8.54] section (2026-09-18) and completes it with the phases and
audit fixes that landed after the cycle was opened: route explanation (#34),
onboarding (#36), the role layer and admin audit (#31), the accessibility pass
(#32), and the three audit-fix pull requests (#37, #38, #39). The two bullets
that already existed are kept verbatim — the additions are separate bullets, so
the changelog-integrity gate sees a purely additive diff. The 41 i18n mirrors
are resynced from the root section.

docs/EVOLUTION_STATUS.md is rewritten for the whole plan: the 13 phases with
their pull request, merge commit and measured evidence, the known limits of the
release, and the Windows host notes. ROADMAP.md gains a fork section recording
what 3.8.54 delivered per area and what each area needs next.

Verification (isolated DATA_DIR/HOME/USERPROFILE/APPDATA):
  check-changelog-integrity   exit 0  no base bullets lost
  check-docs-sync             exit 0  41 locales, version sections + size
  check-docs-frontmatter      exit 0  132 docs
  check-doc-links             exit 0  172 docs, 1043 internal links
  check-fabricated-docs       exit 0  no fabricated references
  check-env-doc-sync          exit 0
  check-deprecated-versions   exit 0
  check-docs-counts-sync      exit 0

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
@coderabbitai

coderabbitai Bot commented Sep 19, 2026 •

Copy link
Copy Markdown

Important

Review skipped

Auto reviews are disabled on base/target branches other than the default branch.

Please check the settings in the CodeRabbit UI or the .coderabbit.yaml file in this repository. To trigger a single review, invoke the @coderabbitai review command.

⚙️ Run configuration

Configuration used: defaults

Review profile: CHILL

Plan: Advanced

Run ID: a30f31a6-738a-40ae-9445-457af908454d

You can disable this status message by setting the reviews.review_status to false in the CodeRabbit configuration file.

Use the checkbox below for a quick retry:

  • 🔍 Trigger review

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

zodyprado-web and others added 9 commits September 18, 2026 23:29
…ion commands

The mission brief asks EVOLUTION_STATUS to carry the architectural decisions,
the risk register and the commands that reproduce every claim, not only the
phase results. Adds the eight decisions the phases were built on and why each
one avoids an irreversible or contract-breaking change, a risk table with its
mitigation, and the verification commands — each preceded by the isolated
DATA_DIR/HOME/USERPROFILE/APPDATA export, because running them without it opens
the developer's real database.

Verification (isolated env):
  check-docs-frontmatter  exit 0
  check-doc-links         exit 0
  check-fabricated-docs   exit 0
  check-docs-sync         exit 0

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
…ale claim

The verification round found the supply-chain claim had gone stale: a second,
higher advisory on adm-zip (GHSA-7q85-xj36-vmfc, high, fixed in 0.6.1) had
appeared in the root production tree through the optional
@huggingface/transformers -> onnxruntime-node chain, while the register — and
the sentence this file carried — still said there was no high advisory there.

PR #42 fixed it rather than re-documenting it: a lockfile-only bump to 0.6.1
inside the existing ^0.6.0 override. This commit replaces the assertion with the
numbers actually measured on the merged tree, per tree, so the claim can be
re-run instead of trusted.

Measured with `npm audit --omit=dev --package-lock-only` (isolated env):
  root production      {"info":0,"low":0,"moderate":0,"high":0,"critical":0}
  electron production  {"info":0,"low":0,"moderate":0,"high":1,"critical":0}

The remaining high is R-10 (js-yaml 4.3.1), reachable only from the Electron
shell's update-check chain — not in the container image, the npm package or the
server runtime.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
The verification round — the three auditors re-checking their own fixes on the
final tree — produced two more pull requests, so the release documents have to
carry them.

CHANGELOG [3.8.54] is dated 2026-09-19, the day the tag is cut, and gains the
work from #41 and #42: the cross-origin redirect body leak in the TypeScript
SDK, the eight health read paths that were transitioning an OPEN breaker to
HALF_OPEN just by being read, the decision lookup now requiring auth when
requireLogin is off, the routing-decision build going from 17.0ms/591KiB to
4.6ms/26.5KiB per request at 300 candidates, the adm-zip bump that took the root
production audit to zero, and the check:lockfile fix. The two bullets the base
tree already carried are still untouched, so the diff stays additive; the 41
i18n mirrors are resynced.

EVOLUTION_STATUS now names all five audit pull requests and separates the first
audit round from the verification round.

Verification (isolated env):
  check-changelog-integrity  exit 0  no base bullets lost
  check-docs-frontmatter     exit 0
  check-doc-links            exit 0
  check-fabricated-docs      exit 0
  check-docs-sync            exit 0  41 locales

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
Records both rounds of the independent audit in FINAL_THREE_AGENT_REVIEW, and
restructures the file by release line so the v3.8.51 record stays intact
underneath its own heading instead of being overwritten.

Round 1, on 20d5b2c: three auditors in parallel, no access to each other's
conclusions. Two HIGH (the decision store bounded only by count, and the webhook
wizard leaving an enabled all-events webhook behind on cancel), plus the medium,
low and improvement findings, each with where it was fixed.

Round 2, the verification round on the final tree 68a00d0: the same three
auditors re-checking their own fixes. None was found missing, partial or wrong.
All three returned PASS with CRITICAL 0 and HIGH 0. The behaviour evidence that
mattered most for this release is recorded: provider selection identical to
v3.8.53 over 700 of 700 seeded cases, and previewRoutingDecision calling
Math.random zero times over 200 previews with the rotator provably untouched.

The findings round 2 raised were fixed, not deferred (#41, #42, #43). The only
item accepted without a fix is B-03 / R-10, js-yaml 4.3.1 in the Electron
update-check chain — not in the container image, the npm package or the server
runtime.

AUTONOMOUS_MISSION_STATE moves to CANDIDATE_COMPLETED -> RELEASING, with the
phase table, the verification round, the Windows-only gate failures, and a note
that the publication evidence has to live in the Release notes because
publishing the Release locks this branch.

Verification (isolated env):
  check-doc-links            exit 0  172 docs, 1043 internal links
  check-fabricated-docs      exit 0
  check-docs-frontmatter     exit 0
  check-changelog-integrity  exit 0

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
The toolchain line quoted `>=24.0.0 <27`, which is only one arm of the declared
engines range `>=22.22.2 <23 || >=24.0.0 <27` — it silently dropped the
supported 22.x line. Replaced with the full range plus a pointer to the
compatibility matrix, which is where the distinction that actually matters lives
(tested per PR vs tested nightly vs declared only), and a note that
`check:node-runtime` enforces it.

check-doc-links exit 0.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
…idual

PR #43 closed the six product findings the QA auditor raised while driving the
running product. The two that mattered most are first-screen defects: on a cold
start the login page abandoned its login-requirement probe after 5s and left a
brand-new user on a password prompt that did nothing (the first call was
measured at 44.7s — 27.2s of it Next compiling the route's module graph, which
is dev-only), and the webhook wizard rendered raw translation keys because the
Slack, Discord and Telegram tutorial strings were missing from all three
locales.

The accessibility pass now covers /dashboard/logs, the onboarding wizard and the
first-run login page. Light theme is 0 violations from 375 to 1440 px on every
gated page.

One residual is recorded as a decision rather than left silent: white on the
dark brand primary (#ffffff on #e54d5e) measures 3.78:1. It is identical on the
base tree, and clearing it means changing the brand colour — not a patch-release
change. It is the only violation left anywhere in the matrix.

The audit review's C-V rows now carry what was actually done instead of
pointing at the pull request.

Verification (isolated env):
  check-changelog-integrity  exit 0  no base bullets lost
  check-docs-sync            exit 0  41 locales
  check-doc-links            exit 0
  check-fabricated-docs      exit 0
  check-docs-frontmatter     exit 0

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
@LMPrado-DZ23
LMPrado-DZ23 merged commit c4ede43 into release/v3.8.54 Sep 19, 2026
11 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants