-
audit Run 15 Phase 4: resilience polish
-
audit Run 15 Phase 3: storage fail-open fixes
-
audit Run 15 Phase 2: security fixes
-
audit Run 15 Phase 1: payments & data-integrity fixes
-
audit Run 14 Phase 4: git push-gate unit tests + concurrent license-activation races
-
audit Run 14 Phase 3: adversarial CSV import tests
-
audit Run 14 Phase 2: split helpers.rs grab-bag into focused submodules
-
audit Run 14 Phase 1: close ammonia mXSS, refresh dep tree, codify advisory triage
-
audit Run 14 Phase 0: reject line breaks in single-line titles, dedup instrument, align archive verdict
-
Pin the storage-cap CAS contract at the DB layer
-
Payments resilience: fan-out dead-letter, billing guards, inbound idempotency
-
Observability + API consistency cold spots
-
Frontend: kill media-picker XSS; render_string surfaces errors
-
DB concurrency: project-split lock, issue retry/search, webhook claim
-
Harden caching, malware quarantine, and account-cleanup fail modes
-
Cap platform credit as spend-once balance; authenticate inbound sender
-
Drain scheduler on shutdown; escape filename in upload-queue row
-
Gate OTA artifact serving on a malware scan
-
Storage: atomic quarantine purge, scan-job retry budget, honest signing chips
-
Scope internal-API identity to a signed SSH-authenticated assertion
-
Harden invites and TOTP replay; add enum-drift guard
-
Fix all-free cart promo reservation and CSV negative-subdollar parse
-
Support video clips in dynamic insertions
-
Make the CLI upload confirm idempotent on replay (ultra-fuzz Run 12 Storage)
-
Surface fragment render errors and de-fragilize two UX sinks (ultra-fuzz Run 12 UX)
-
Memoize discover facets and CDN-cache /economics (ultra-fuzz Run 12 Performance)
-
Harden the OTA path and stop orphaning S3 on failed cleanup enqueue (ultra-fuzz Run 12 Storage)
-
Sync Cargo.lock to v0.10.7
-
Stop CDN-caching the private feed and couple cache invalidation to deletion (ultra-fuzz Run 12 Security)
-
Redeliver inbound Postmark email on transient failure (ultra-fuzz Run 12 doubledown)