docs(devlog): close the dev hardening unit with a promotion-readiness statement - #2752
Conversation
… statement Records what is proven about dev at 2a72cc0, what is deliberately not on it, and what a promoter still has to do. It is a state record, not an approval to promote: MAINTAINERS.md and scripts/release.ts remain the release authority. The head is 283 commits ahead of main (ec51e42, v2.33.0) and package.json reads 2.34.0, so the version line now sits ahead of the published channel instead of behind it, which was the wp2 defect. Two things the statement is explicit about rather than quiet on. PR #2745 (wp3) is open and must stay open: it touches credential identity on OAuth 429 rotation, which MAINTAINERS.md puts behind security review, so the identity drift is still present on dev. The reviewer refuted the exploit's reachability, which is why it is a review-queue item and not a release blocker. And the audit scope was the core/Lab boundary, the activation window, hygiene, the version line, locale docs, and the local gates -- not provider adapters, not the GUI beyond lint config, and not the release workflow itself.
|
✅ Deterministic PR hygiene checks passed. |
|
Caution Review failedThe pull request is closed. ℹ️ Recent review info⚙️ Run configurationConfiguration used: Path: .coderabbit.yaml Review profile: ASSERTIVE Plan: Pro Plus Run ID: 📒 Files selected for processing (1)
📝 WalkthroughWalkthroughThe pull request adds a promotion-readiness record for the dev hardening unit. It documents the target state, completed and incomplete work, validation results, the open OAuth 429 identity defect, promotion requirements, and audit exclusions. ChangesPromotion readiness
Estimated code review effort: 1 (Trivial) | ~5 minutes Suggested reviewers: ✨ Finishing Touches🧪 Generate unit tests (beta)
Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out. Comment |
There was a problem hiding this comment.
💡 Codex Review
Here are some automated review suggestions for this pull request.
Reviewed commit: a195ba6882
ℹ️ About Codex in GitHub
Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you
- Open a pull request for review
- Mark a draft as ready
- Comment "@codex review".
If Codex has suggestions, it will comment; otherwise it will react with 👍.
Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".
| The review lane that examined it refuted the exploit's reachability — the missing | ||
| `continue recovery` acts as an accidental guard — so this is a correctness defect rather | ||
| than a live vulnerability. That is the reason it is a normal review queue item and not a | ||
| release blocker. |
There was a problem hiding this comment.
Remove the unfixed security assessment from the devlog
Because PR #2745 remains open and the credential defect is still present, these lines publish a severity assessment and the accidental guard that currently prevents exploitation in a tracked public directory. Repository policy requires findings, bypass reasoning, and assessments for unfixed security defects to remain in scratch space; remove these details from the promotion record until the fix has shipped.
AGENTS.md reference: AGENTS.md:L103-L108
Useful? React with 👍 / 👎.
| This is the closing record for the 260827 dev hardening unit. It states what is proven | ||
| about the current `dev` head, what is deliberately not on it, and what a promoter still | ||
| has to do. It is not an approval to promote. |
There was a problem hiding this comment.
Keep the unit open until the launcher failure is resolved
Calling this the unit's closing record omits the already-tracked wp8 result: 060_wp8_launcher_flake.md records two macOS failures of tests/update-stop-first.test.ts and explicitly classifies the recovery slowness as a known open defect. Consequently this closeout can tell a promoter the branch is ready while an unresolved readiness failure remains in the same unit; retain an open status and include wp8's disposition, or resolve it and then move the completed unit to _fin.
AGENTS.md reference: AGENTS.md:L83-L86
Useful? React with 👍 / 👎.
…readiness docs(devlog): close the dev hardening unit with a promotion-readiness statement
…readiness docs(devlog): close the dev hardening unit with a promotion-readiness statement
Summary
Closes the 260827 dev hardening unit with a record of what is proven about
devat2a72cc017, what is deliberately not on it, and what a promoter still has to do. Docs only — no runtime change.It is a state record, not an approval to promote.
MAINTAINERS.mdandscripts/release.tsremain the release authority.What the unit changed
5dfee1a05ca3b379e1a57b9620afetch-tags802f04adc5000321e6doctor:guifailed on dev, so prepush was routinely bypassed2a72cc017Two things the statement is explicit about
PR #2745 stays open. It touches credential identity on OAuth 429 rotation, which
MAINTAINERS.mdputs behind explicit security review, so the identity drift is still present ondev. The review lane refuted the exploit's reachability — the missingcontinue recoveryacts as an accidental guard — which is why this is a review-queue item rather than a release blocker. Anyone promotingdevshould know it is there.The audit scope was bounded. It covered the core/Lab boundary, the startup activation window, repository hygiene, the version line, locale docs, and the local gates. It did not cover provider adapters, the GUI beyond its lint configuration, or the release workflow itself. A green suite is evidence about code that has tests, and the statement says so rather than implying more.
Verification
dev=2a72cc0173af36d4b8172b70ba0a3384db9e6047, 283 commits ahead ofmain(ec51e42d7, v2.33.0);package.jsonreads2.34.0bun run teston the Linux host at the exact dev head: rc=0Checklist
devcommitSummary by CodeRabbit