-
server: collapse slug allocation into insert_with_unique_slug (ultra-fuzz Run #1 --deep Phase 5)
-
server: convert remaining money-path DB modules to compile-checked SQL (ultra-fuzz Run #1 --deep Phase 4)
-
synckit: bump to 0.5.0; document deep A+ wire formats and the clean-change gate
-
synckit: chunked AEAD blob format (sk3) with streaming, bounded-RAM download
-
synckit: forced clean-change HLC gate via CleanChanges
-
server: convert pending_uploads/pending_s3_deletions/pending_refunds to compile-checked SQL (ultra-fuzz Run #1 --deep Phase 4)
-
server: adopt sqlx-offline; convert db::idempotency to compile-checked SQL (ultra-fuzz Run #1 --deep Phase 4)
-
synckit: typed WireVersion envelope dispatch, reject unknown versions loudly
-
synckit: seal AEAD associated data behind AeadContext
-
server: dedupe pagination range into a shared helper (ultra-fuzz Run #1 --deep Phase 4)
-
synckit: Cents money newtype + typed BillingInterval + retry-idempotency proof
-
server: seal S3 keys behind a typed builder; close storage A+ gaps (ultra-fuzz Run #1 --deep Phase 3)
-
synckit: strongly-typed DeviceId/UserId/AppId newtypes + non_exhaustive responses
-
server: hash OAuth authorization codes at rest (ultra-fuzz Run #1 --deep Phase 2)
-
server: drive Payments axis to A+ (ultra-fuzz Run #1 --deep Phase 1)
-
mt-db: compile-time checked SQL via sqlx macros (ultra-fuzz M3, A+)
-
mt: land ultra-fuzz Run #4 remediation (S1, H2, P1/P2, M2, NOTE-1, UX1, security LOWs, P3)
-
synckit: add constant-time OAuth state check, tighten loopback TLS exemption (ultra-fuzz Run #1 Auth)
-
synckit: honor retry contract + overflow-guard pricing, non_exhaustive API (ultra-fuzz Run #1 API)
-
synckit: verify + AAD-bind blob content hash, jitter backoff (ultra-fuzz Run #1 Transport)
-
synckit: bind entry ciphertext to (table,row_id), explicit wire version, HLC overflow guard (ultra-fuzz Run #1 Sync)
-
synckit: bind AEAD associated data + version tag, fix rotation resume (ultra-fuzz Run #1 Crypto)
-
server: report authoritative license activation_count (ultra-fuzz Run #1 Payments MINOR)
-
server: compute onboarding progress percent in Rust (ultra-fuzz Run #1 UX LOW)
-
server: size-bound the idempotency negative cache (ultra-fuzz Run #1 Perf LOW)
-
server: enqueue old S3 key inside the replace tx (ultra-fuzz Run #1 Storage LOW)
-
server: harden OAuth code redemption + challenge length (ultra-fuzz Run #1 Security LOWs)
-
server: route idempotency cache write through bounded pool (ultra-fuzz Run #1 Perf MODERATE)
-
server: dedup section slugs and hash-fallback non-Latin slugs (ultra-fuzz Run #1 UX)
-
server: weave version id into download S3 key (ultra-fuzz Run #1 Storage HIGH)