vestige/.github/workflows
Sam Valladares 6bbafc0241 fix(release): close the 3 pre-ship blockers from the final audit
README: add the '## Vestige Pro' section so the #vestige-pro anchor that six
shipped surfaces link to actually resolves. States the price and the
zero-knowledge guarantee honestly, with no checkout link, because checkout is
not open yet.

SECURITY: 'Vulnerabilities: 0' was false at 5. Updated rustls-webpki,
quinn-proto and crossbeam-epoch; cargo audit now genuinely exits 0. Supported
versions now list 2.3.x.

Migration V20: clears connector sync cursors so the V19 idempotency repair
happens automatically on the next source_sync, instead of a changelog note
telling users to run something that could not have worked.

cloud-sync hardening: redact the sync key and passphrase from Debug, require
https (loopback carve-out), enforce a 12 character passphrase minimum.
Trace retention days are clamped so a hostile value cannot abort the process.

release.yml: add 'connectors' to the Windows and Intel Mac rows so source_sync
is a real tool on those platforms rather than a compiled-out stub.

CHANGELOG: correct three claims the audit fact-checked as false, document the
breaking plaintext-sync change, and add the two new env levers.

Gates: cargo test 1588/0, cloud-sync suite 18/0, clippy clean, svelte-check
937/0/0, dashboard build green, cargo audit 0 vulnerabilities.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
2026-07-26 00:20:35 +08:00
..
ci.yml feat(pro): mandatory zero-knowledge cloud sync + Pro upgrade surfaces 2026-07-25 21:40:28 +08:00
guard-no-private-cloud.yml ci: guard against private cloud service code in public repo 2026-06-21 18:19:01 -05:00
pages.yml fix(pages): serve dashboard at site root, drop double /vestige nesting 2026-06-21 17:50:10 -05:00
release.yml fix(release): close the 3 pre-ship blockers from the final audit 2026-07-26 00:20:35 +08:00
test.yml Prepare agent-neutral hardening release 2026-05-24 16:09:44 -05:00