Skip to content

Harden production monitoring and refresh dependencies - #38

Merged
sppidy merged 1 commit into
mainfrom
codex/maintenance-hardening
Aug 23, 2026
Merged

sppidy merged 1 commit into
mainfrom
codex/maintenance-hardening

Conversation

@sppidy

@sppidy sppidy commented Aug 23, 2026

Copy link
Copy Markdown
Owner

Summary

  • add an authenticated public-edge production synthetic for REST, SSE, WebSocket, and passkey RP validation
  • deploy it as a sandboxed systemd timer using protected credentials and bounded stream/memory handling
  • remediate Dependabot alert chore(deps): bump aws-sdk-s3 from 1.132.0 to 1.133.0 #8 (cmov 0.5.4), consolidate safe Rust/web updates, and advance checkout actions
  • align the production web image with Node 22 and make the journey runner accept a system Chromium

Validation

  • full Rust clippy/test/fmt and web lint/typecheck/unit/build suite
  • Docker server/web/agent builds
  • Playwright fleet read-plane journey: 1 passed
  • production synthetic unit tests: 6 passed
  • live public-edge dry run: 5/5 agents online and fresh; REST, SSE, WebSocket, and passkey RP checks passed
  • security diff review: complete, 0 reportable findings

Enterprise Edition remains separate and private.

Copilot AI lite review requested due to automatic review settings August 23, 2026 15:37

Copilot AI left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Copilot was unable to review this pull request because the user who requested the review has reached their quota limit.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants