-
server: write build, issue and scan metadata into refs/notes/mnw/*
-
Replace pointers to deleted docs with the explanation itself
-
Require CDN_BASE_URL everywhere so no cover URL can expire
-
Exorcise sweep: strip AI tells from server copy, comments, and docs
-
server: adopt lint block, fix clippy, fmt
-
Format the tree with rustfmt and add the lint + supply-chain gates
-
server: split public image content into a separate CDN bucket (S1)
-
Scan-then-promote uploads to immutable content keys (C1)
-
Fix OTA quarantine deleting from the wrong S3 bucket
-
server: cap buffered scan download to recorded size + slack
-
Remediate audit Run 22 fix-first findings; bump to 0.10.8
-
observability: scan verdict, duration, and queue-depth metrics (audit Run 20 Phase 8)
-
audit Run 15 Phase 3: storage fail-open fixes
-
Harden caching, malware quarantine, and account-cleanup fail modes
-
Gate OTA artifact serving on a malware scan
-
Give scheduler lock a dedicated pool; drain worker quarantine spawns
-
Harden ClamAV to fail-closed; drop dead code; anti-spray rate-limit
-
security: close OAuth silent-consent gap, ClamAV fail-open observability, 7z/RAR + blame hardening
-
security: seal token-liveness, per-key identity, private-repo issue authz (ultra-fuzz Run 4, A+)
-
Seal pricing-format/slug drift and add Cloudflare quarantine cache-purge
-
server: supervise scheduler, cap internal broadcast, unblock git2 walk, single-pass archive scan (ultra-fuzz Run 2 Perf CRITICAL + SERIOUS)