vestige/.github
Sam Valladares 6bbafc0241 fix(release): close the 3 pre-ship blockers from the final audit
README: add the '## Vestige Pro' section so the #vestige-pro anchor that six
shipped surfaces link to actually resolves. States the price and the
zero-knowledge guarantee honestly, with no checkout link, because checkout is
not open yet.

SECURITY: 'Vulnerabilities: 0' was false at 5. Updated rustls-webpki,
quinn-proto and crossbeam-epoch; cargo audit now genuinely exits 0. Supported
versions now list 2.3.x.

Migration V20: clears connector sync cursors so the V19 idempotency repair
happens automatically on the next source_sync, instead of a changelog note
telling users to run something that could not have worked.

cloud-sync hardening: redact the sync key and passphrase from Debug, require
https (loopback carve-out), enforce a 12 character passphrase minimum.
Trace retention days are clamped so a hostile value cannot abort the process.

release.yml: add 'connectors' to the Windows and Intel Mac rows so source_sync
is a real tool on those platforms rather than a compiled-out stub.

CHANGELOG: correct three claims the audit fact-checked as false, document the
breaking plaintext-sync change, and add the two new env levers.

Gates: cargo test 1588/0, cloud-sync suite 18/0, clippy clean, svelte-check
937/0/0, dashboard build green, cargo audit 0 vulnerabilities.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
2026-07-26 00:20:35 +08:00
..
ISSUE_TEMPLATE Add Codex integration docs 2026-04-05 18:50:57 +03:00
workflows fix(release): close the 3 pre-ship blockers from the final audit 2026-07-26 00:20:35 +08:00