-
server: split public image content into a separate CDN bucket (S1)
-
Remediate audit Run 21 findings across server
-
security: seal admin gate, close export quarantine bypass, drop legacy sessions (audit Run 20 Phase 2)
-
audit Run 15 Phase 5: CSP script-src drops 'unsafe-inline'
-
Stop CDN-caching the private feed and couple cache invalidation to deletion (ultra-fuzz Run 12 Security)
-
ux: friendly errors for validated extractors, widen hide/strobe guards, posture+clamp fixes
-
payments: idempotent re-runnable webhook finalize (ultra-fuzz Run 4 M-Pay1, A+)
-
synckit: indexed pull hot path, SSE cursor, deferred egress, sealed warning tick (ultra-fuzz --deep Perf A+)
-
Seal pricing-format/slug drift and add Cloudflare quarantine cache-purge
-
server: bound per-tick scheduler sweeps; anchor request-timeout exemptions
-
Add global request timeout; background the content export
-
Stream git clone packfile and gate clone concurrency
-
OAuth maturation + HMAC method+path+nonce (close MT S13)
-
server: creator custom pages (HTML/CSS) on u.makenot.work
-
server: Tier 0 creator theming + fold in Run 18 storage work