-
Test db money/race cold spots; fix inert cancel_stale_rotation
-
audit Run 16 Phase 6: Observability
-
audit Run 16 Phase 5: Performance
-
audit Run 16 Phase 4: Resilience
-
audit Run 16 Phase 3: Concurrency
-
audit Run 16 Phase 2: Data integrity / Types
-
audit Run 16 Phase 1: Security axis A- -> A
-
audit Run 15 Phase 5: update promo-code XSS test for delegated handlers
-
audit Run 15 Phase 5: CSP script-src drops 'unsafe-inline'
-
audit Run 15 Phase 4: resilience polish
-
audit Run 15 Phase 3: storage fail-open fixes
-
audit Run 15 Phase 2: security fixes
-
audit Run 15 Phase 1: payments & data-integrity fixes
-
audit Run 14 Phase 4: git push-gate unit tests + concurrent license-activation races
-
audit Run 14 Phase 3: adversarial CSV import tests
-
audit Run 14 Phase 2: split helpers.rs grab-bag into focused submodules
-
audit Run 14 Phase 1: close ammonia mXSS, refresh dep tree, codify advisory triage
-
audit Run 14 Phase 0: reject line breaks in single-line titles, dedup instrument, align archive verdict
-
Pin the storage-cap CAS contract at the DB layer
-
Payments resilience: fan-out dead-letter, billing guards, inbound idempotency
-
Observability + API consistency cold spots
-
Frontend: kill media-picker XSS; render_string surfaces errors
-
DB concurrency: project-split lock, issue retry/search, webhook claim
-
Harden caching, malware quarantine, and account-cleanup fail modes
-
Cap platform credit as spend-once balance; authenticate inbound sender
-
Drain scheduler on shutdown; escape filename in upload-queue row
-
Gate OTA artifact serving on a malware scan
-
Storage: atomic quarantine purge, scan-job retry budget, honest signing chips
-
Scope internal-API identity to a signed SSH-authenticated assertion
-
Harden invites and TOTP replay; add enum-drift guard