-
server: mt audit findings — health 503, SSRF img-proxy e2e, hardening
-
server: gate one-time checkout finalize on payment settlement
-
tests: sanitize project slug from underscore usernames in harness
-
server: money-core db-layer contract tests (db::transactions)
-
server: close Architecture B+ dups + rss control-byte gap (audit Run 17)
-
server: module docs on leaf db modules; glob the audit-file gitignore
-
server: frontend hygiene — dead JS, fragmented tab JS, inline CSS, img shift
-
server: gallery N+1 + ImageId, de-truncate aggregates, keyset paginator
-
server: fix test harness for spawn_pool shutdown-receiver signature
-
server: escalate/log the silent error-swallow sites
-
server: drain the background pool on graceful shutdown
-
server: flip OAuth empty-scope to userinfo; validate build signing_key_path
-
server: make SyncKit Stripe creates idempotent to close activate race
-
Test collections and items::bulk db cold spots
-
Test passkeys, ssh_keys, and issues db cold spots
-
Test db money/race cold spots; fix inert cancel_stale_rotation
-
audit Run 16 Phase 6: Observability
-
audit Run 16 Phase 5: Performance
-
audit Run 16 Phase 4: Resilience
-
audit Run 16 Phase 3: Concurrency
-
audit Run 16 Phase 2: Data integrity / Types
-
audit Run 16 Phase 1: Security axis A- -> A
-
audit Run 15 Phase 5: update promo-code XSS test for delegated handlers
-
audit Run 15 Phase 5: CSP script-src drops 'unsafe-inline'
-
audit Run 15 Phase 4: resilience polish
-
audit Run 15 Phase 3: storage fail-open fixes
-
audit Run 15 Phase 2: security fixes
-
audit Run 15 Phase 1: payments & data-integrity fixes
-
audit Run 14 Phase 4: git push-gate unit tests + concurrent license-activation races
-
audit Run 14 Phase 3: adversarial CSV import tests