docs(release): close the 3.8.54 cycle — changelog, evolution status, roadmap and final audit - #40
Merged
Merged
Conversation
…admap Dates the [3.8.54] section (2026-09-18) and completes it with the phases and audit fixes that landed after the cycle was opened: route explanation (#34), onboarding (#36), the role layer and admin audit (#31), the accessibility pass (#32), and the three audit-fix pull requests (#37, #38, #39). The two bullets that already existed are kept verbatim — the additions are separate bullets, so the changelog-integrity gate sees a purely additive diff. The 41 i18n mirrors are resynced from the root section. docs/EVOLUTION_STATUS.md is rewritten for the whole plan: the 13 phases with their pull request, merge commit and measured evidence, the known limits of the release, and the Windows host notes. ROADMAP.md gains a fork section recording what 3.8.54 delivered per area and what each area needs next. Verification (isolated DATA_DIR/HOME/USERPROFILE/APPDATA): check-changelog-integrity exit 0 no base bullets lost check-docs-sync exit 0 41 locales, version sections + size check-docs-frontmatter exit 0 132 docs check-doc-links exit 0 172 docs, 1043 internal links check-fabricated-docs exit 0 no fabricated references check-env-doc-sync exit 0 check-deprecated-versions exit 0 check-docs-counts-sync exit 0 Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
|
Important Review skippedAuto reviews are disabled on base/target branches other than the default branch. Please check the settings in the CodeRabbit UI or the ⚙️ Run configurationConfiguration used: defaults Review profile: CHILL Plan: Advanced Run ID: You can disable this status message by setting the Use the checkbox below for a quick retry:
Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out. Comment |
…ion commands The mission brief asks EVOLUTION_STATUS to carry the architectural decisions, the risk register and the commands that reproduce every claim, not only the phase results. Adds the eight decisions the phases were built on and why each one avoids an irreversible or contract-breaking change, a risk table with its mitigation, and the verification commands — each preceded by the isolated DATA_DIR/HOME/USERPROFILE/APPDATA export, because running them without it opens the developer's real database. Verification (isolated env): check-docs-frontmatter exit 0 check-doc-links exit 0 check-fabricated-docs exit 0 check-docs-sync exit 0 Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
…ale claim The verification round found the supply-chain claim had gone stale: a second, higher advisory on adm-zip (GHSA-7q85-xj36-vmfc, high, fixed in 0.6.1) had appeared in the root production tree through the optional @huggingface/transformers -> onnxruntime-node chain, while the register — and the sentence this file carried — still said there was no high advisory there. PR #42 fixed it rather than re-documenting it: a lockfile-only bump to 0.6.1 inside the existing ^0.6.0 override. This commit replaces the assertion with the numbers actually measured on the merged tree, per tree, so the claim can be re-run instead of trusted. Measured with `npm audit --omit=dev --package-lock-only` (isolated env): root production {"info":0,"low":0,"moderate":0,"high":0,"critical":0} electron production {"info":0,"low":0,"moderate":0,"high":1,"critical":0} The remaining high is R-10 (js-yaml 4.3.1), reachable only from the Electron shell's update-check chain — not in the container image, the npm package or the server runtime. Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
The verification round — the three auditors re-checking their own fixes on the final tree — produced two more pull requests, so the release documents have to carry them. CHANGELOG [3.8.54] is dated 2026-09-19, the day the tag is cut, and gains the work from #41 and #42: the cross-origin redirect body leak in the TypeScript SDK, the eight health read paths that were transitioning an OPEN breaker to HALF_OPEN just by being read, the decision lookup now requiring auth when requireLogin is off, the routing-decision build going from 17.0ms/591KiB to 4.6ms/26.5KiB per request at 300 candidates, the adm-zip bump that took the root production audit to zero, and the check:lockfile fix. The two bullets the base tree already carried are still untouched, so the diff stays additive; the 41 i18n mirrors are resynced. EVOLUTION_STATUS now names all five audit pull requests and separates the first audit round from the verification round. Verification (isolated env): check-changelog-integrity exit 0 no base bullets lost check-docs-frontmatter exit 0 check-doc-links exit 0 check-fabricated-docs exit 0 check-docs-sync exit 0 41 locales Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
Records both rounds of the independent audit in FINAL_THREE_AGENT_REVIEW, and restructures the file by release line so the v3.8.51 record stays intact underneath its own heading instead of being overwritten. Round 1, on 20d5b2c: three auditors in parallel, no access to each other's conclusions. Two HIGH (the decision store bounded only by count, and the webhook wizard leaving an enabled all-events webhook behind on cancel), plus the medium, low and improvement findings, each with where it was fixed. Round 2, the verification round on the final tree 68a00d0: the same three auditors re-checking their own fixes. None was found missing, partial or wrong. All three returned PASS with CRITICAL 0 and HIGH 0. The behaviour evidence that mattered most for this release is recorded: provider selection identical to v3.8.53 over 700 of 700 seeded cases, and previewRoutingDecision calling Math.random zero times over 200 previews with the rotator provably untouched. The findings round 2 raised were fixed, not deferred (#41, #42, #43). The only item accepted without a fix is B-03 / R-10, js-yaml 4.3.1 in the Electron update-check chain — not in the container image, the npm package or the server runtime. AUTONOMOUS_MISSION_STATE moves to CANDIDATE_COMPLETED -> RELEASING, with the phase table, the verification round, the Windows-only gate failures, and a note that the publication evidence has to live in the Release notes because publishing the Release locks this branch. Verification (isolated env): check-doc-links exit 0 172 docs, 1043 internal links check-fabricated-docs exit 0 check-docs-frontmatter exit 0 check-changelog-integrity exit 0 Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
The toolchain line quoted `>=24.0.0 <27`, which is only one arm of the declared engines range `>=22.22.2 <23 || >=24.0.0 <27` — it silently dropped the supported 22.x line. Replaced with the full range plus a pointer to the compatibility matrix, which is where the distinction that actually matters lives (tested per PR vs tested nightly vs declared only), and a note that `check:node-runtime` enforces it. check-doc-links exit 0. Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
…idual PR #43 closed the six product findings the QA auditor raised while driving the running product. The two that mattered most are first-screen defects: on a cold start the login page abandoned its login-requirement probe after 5s and left a brand-new user on a password prompt that did nothing (the first call was measured at 44.7s — 27.2s of it Next compiling the route's module graph, which is dev-only), and the webhook wizard rendered raw translation keys because the Slack, Discord and Telegram tutorial strings were missing from all three locales. The accessibility pass now covers /dashboard/logs, the onboarding wizard and the first-run login page. Light theme is 0 violations from 375 to 1440 px on every gated page. One residual is recorded as a decision rather than left silent: white on the dark brand primary (#ffffff on #e54d5e) measures 3.78:1. It is identical on the base tree, and clearing it means changing the brand colour — not a patch-release change. It is the only violation left anywhere in the matrix. The audit review's C-V rows now carry what was actually done instead of pointing at the pull request. Verification (isolated env): check-changelog-integrity exit 0 no base bullets lost check-docs-sync exit 0 41 locales check-doc-links exit 0 check-fabricated-docs exit 0 check-docs-frontmatter exit 0 Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Closes the v3.8.54 evolution cycle: the release documents, and the consolidated record of the three independent audits and their verification round.
What changes
[3.8.54]is dated2026-09-18and completed with the work that landed after the cycle was opened: route explanation (Phase 4: request-id correlated routing decisions, decision lookup, diagnostics and dashboard #34), onboarding (Phase 6: end-to-end first-use onboarding, actionable errors and INITIAL_PASSWORD fix #36), the role layer and admin audit (Phase 8: role layer, admin audit, budget alerts, credential reveal hardening and RBAC design #31), the accessibility pass (Phase 9: zero axe violations on login, dashboard and providers at 375-1440px, keyboard flows #32), and the three audit-fix pull requests (Audit fixes: SDK redirect credentials, POST retries, credential reveal hardening #37, Audit fixes: bounded decision store, strategy budget order, SLO recovery, read-only metrics #38, Audit fixes: webhook wizard, SLO settings UI, backup docs, accessibility #39). The two bullets that already existed are kept verbatim; every addition is a separate bullet, socheck:changelog-integritysees a purely additive diff. The 41 i18n mirrors are resynced from the root section.Verification
Run with isolated
DATA_DIR/HOME/USERPROFILE/APPDATA:check-changelog-integrityorigin/release/v3.8.54check-docs-synccheck-docs-frontmattercheck-doc-linkscheck-fabricated-docscheck-env-doc-synccheck-deprecated-versionscheck-docs-counts-syncDocumentation only — no runtime code changes.
🤖 Generated with Claude Code