Phase/8 operational hardening - #10
Merged
Merged
Conversation
|
| GitGuardian id | GitGuardian status | Secret | Commit | Filename | |
|---|---|---|---|---|---|
| 35177584 | Triggered | Generic Password | 2b49cfd | compose.yaml | View secret |
🛠 Guidelines to remediate hardcoded secrets
- Understand the implications of revoking this secret by investigating where it is used in your code.
- Replace and store your secret safely. Learn here the best practices.
- Revoke and rotate this secret.
- If possible, rewrite git history. Rewriting git history is not a trivial act. You might completely break other contributing developers' workflow and you risk accidentally deleting legitimate data.
To avoid such incidents in the future consider
- following these best practices for managing and storing secrets including API keys and other credentials
- install secret detection on pre-commit to catch secret before it leaves your machine and ease remediation.
🦉 GitGuardian detects secrets in your source code to help developers and security teams secure the modern development process. You are seeing this because you or someone else with access to this repository has authorized GitGuardian to scan your pull request.
Mujhtech
force-pushed
the
phase/8-operational-hardening
branch
from
July 31, 2026 09:35
dbf2113 to
fd549ab
Compare
Mujhtech
force-pushed
the
phase/8-operational-hardening
branch
from
July 31, 2026 09:36
fd549ab to
9c2faca
Compare
Mujhtech
force-pushed
the
phase/8-operational-hardening
branch
from
July 31, 2026 09:36
9c2faca to
96884a1
Compare
Mujhtech
force-pushed
the
phase/8-operational-hardening
branch
from
July 31, 2026 09:37
96884a1 to
4008fe9
Compare
Mujhtech
force-pushed
the
phase/8-operational-hardening
branch
from
July 31, 2026 09:37
4008fe9 to
834bb79
Compare
Mujhtech
force-pushed
the
phase/8-operational-hardening
branch
from
July 31, 2026 09:37
834bb79 to
32406bd
Compare
Mujhtech
force-pushed
the
phase/8-operational-hardening
branch
from
July 31, 2026 09:38
32406bd to
bf5d95a
Compare
Organization switcher rewrite, route guards and sign-out, error classification and degraded states, app-wide field accessibility, error boundaries, pending states, focus management, browser matrix, runtime config injection, diagnostics panel, version stamping, dashboard Dockerfile and operations documentation.
Embedded protocol schemas with drift test, version-stamped images, migration preflight with advisory locking and refuse-on-affected-data downs, experiment schedule lease recovery, analytics ingestion minimization enforcement, trusted-proxy rate limiting, observability metrics and spans, dependency-aware readiness and draining shutdown, production config guards, backup/restore/keyring tooling, upgrade workflow, and stdlib load-generation harness. Migrations 00019-00021.
Explicit tree codecs replace reflective Gson for cached configuration and experiment assignment records (R8-safe persistence), corrected consumer rules, minified example release build as regression guard, file-backed bounded no-backup Google Play delivery store off the main dispatcher, scroll-indicator recomposition fix, analytics registry flag reconciliation, RevenueCat publication parity, version 0.1.0-dev.7 with reconciled wire constant, canonical assignment-vector test binding, R8 and installation documentation, known-limitations register.
Storage failures can no longer escape public APIs (dispose, lifecycle flush, identity persistence with poisoning fix), decidePlacement degrades to sealed unavailable, v2 analytics acknowledgements are now accepted (exposure-loss fix), rollout tuple emitted atomically, per-event v2 correlation/attribution allow-lists in the decoder, version reconciled to 0.2.0-dev.11 with matching wire constant, floor raised to Flutter 3.22/Dart 3.4, canonical v1 invalid and v2 fixture sweeps, honest installation docs, docs/sdk rewrite.
…n android Correlation allow-lists for every schema version, attribution ownership extended to v1, ingestion responses retain and require the echoed contract version so v1 responses cannot acknowledge v2 experiment batches, rollout tuple all-or-none by construction, six canonical invalid fixtures consumed directly in tests.
…at contract level (stage 3) Manifest lifecycle widened (retired status, deprecation metadata) before the one-way approval flip of all 13 contracts, Delivery v3 readerPolicy fallback keys, Local Preview 0.2 manifest wired into validation, generator-enforced per-event correlation/attribution allow-lists and dependent-required tuples in canonical analytics schemas, rejection-layer metadata for invalid fixtures, corrected export-name documentation, compatibility/deprecation/breaking-change/fixture-lifecycle/release policies and per-contract migration guides.
Verified conversion events already emit on v2 with the complete tuple under an active assignment (blocker non-reproduction, evidence-backed); locked the three previously untested mechanisms with emitter and canonical-fixture tests including tuple event-scope boundaries.
iOS 15 floor restored (monotonic clock replaces ContinuousClock) with a deployment-target typecheck guard, privacy manifest with SystemBootTime declaration, version reconciliation to 0.1.0-dev.6 across podspecs and wire constants, trap paths converted to safe errors, configure degrades to in-memory persistence with bundled fallback instead of throwing, packaged bundled fallback made loadable (digest and delivery-version bugs), acknowledgement contract-version pairing enforced, canonical assignment-vector test binding, pinned swift-format config, honest installation and validation docs.
…s tuple-free Journey batch now exercises the exposure-to-conversion join; normative rule that conversions on fallback presentations must omit the experiment tuple (denominator displacement / category 12), with detection signal; three unsatisfiable guardrail metrics identified against the approved contract.
Conversion events carry the immutable all-or-none experiment tuple on schema v2 only for exposed original-variant presentations; fallback and QA-override presentations emit tuple-free; v2 lane batching keeps versions unmixed; attributed canonical fixtures round-trip; version- dependent context validation fixed.
…ndled fallback Conversion tuple attaches only when the presentation was an exposed original variant (excludes fallback and QA-override presentations, matching the exposure-emission condition exactly); packaged bundled fallback pinned with renderability and byte-equality tests through R8.
Conversion attribution attaches only when the presentation was not a fallback (non-vacuity-proven regression test); stale v0.1-era golden removed and redundant test consolidated; baseline re-recorded on Xcode 26.5/iOS 26.5 with documented visual review; simulator suite 12/12 and deterministic across runs.
README rewritten for v1 reality, SECURITY/CONTRIBUTING/CODE_OF_CONDUCT, draft v1.0.0 release notes, support policy, ten grounded user guides, TEST.md credential file removed (rotation remains an owner action), accidentally truncated known-limitations sections restored.
Experiment publishing worked against PostgreSQL for the first time: wrong assets column name and semicolon-joined parameterized statements fixed in experimentpostgres; email validation no longer performs live MX lookups (isolated installs could not create an administrator); placement/alias/attribute keys validated against the schema pattern instead of 500ing; 5xx causes now logged with request correlation; drill evidence for D1, D7, D8, D14 recorded including non-zero experiment conversion verification.
Compose volume isolation and env passthrough (59 vars), script project overrides, truthful readiness during dependency failure, named 406 capability details, worker job log identity, experiment schedule insert schema drift (and three sibling writer/schema drifts), deliberate 5xx statuses no longer collapsed to internal_error, audit history readable after experiment actions, diagnosable 422s, migrate down-to parsing, secret redaction in error-cause logging, loadgen capability headers, embedded schema re-sync; drills D2-D6, D9, D10, D12-D14 evidence, full integration suite green, both triage items resolved, first performance measurements recorded.
QA-override presentations leaked the tuple with no exposure row behind it; tuple attachment and exposure emission now share one predicate (recordsStatisticalExposure) so they cannot drift, verified across six presentation shapes with a non-vacuity-proven biconditional test.
Installation, upgrade, backup/restore, and troubleshooting guides grounded in executed drill commands; 21 operator runbooks with index; README documentation index updated; non-drill-validated steps labelled explicitly.
…tes, asset 404, drift sweep Configurable readiness drain delay before shutdown (D6 pass), experiment publishes carry a usable v1 representation forward so v1-only SDKs keep receiving configuration, explicit experiment_placement_decision_required code, missing asset object is a 404 with operator-log integrity detail while storage failure stays 503, writer/schema drift sweep script clean across 88 tables with two additional defect classes audited.
Backend (format/vet/build/full integration tests against postgres and minio, writer-schema drift sweep, govulncheck, Go SBOM), protocol (tests, contract validation, generation drift gate, audit), dashboard (full check including relay, audit, npm SBOM), Flutter, Android with minified example R8 gate, iOS with the iOS 15 deployment-target typecheck, compose readiness smoke, and secret scanning.
Server/platform and dashboard known-limitation sections, BUGS.md item registered and file removed, experiments guide prerequisites and emergency-stop accuracy, publishing/placements trap propagation, troubleshooting updated to post-fix behavior, release notes dashboard section and deliberate D8 deviation, README matrix alignment, installation guide dashboard configuration and first-screen accuracy.
…otiation guarantees Eleven changelog entries carry the approved-at-GA status line, the release-approval checklist now requires it, the every-release-carries- every-approved-version production guarantee and the 406 details wire shape with its closed reason vocabulary are documented, remaining unconsumed fixture coverage recorded.
Opt-in integration harness proves fetch, cache-served outage survival, bundled fallback with empty cache, and 304 recovery against a live compose stack; evidence and suite/toolchain record appended; fragile fixture path in placement_test routed through repositoryFile.
…ions Code-to-copy-and-recovery mapping ahead of the status fallback with details rendering (blockers, fields, reason, capability), diagnostics moved outside the auth guard, studio back control targets /workspace, raw server messages routed through the mapper, rule-set archive uses a focus-managed sheet without internal phase vocabulary, Access naming reconciled, api version rows in diagnostics, unrepresentable empty-copy states, fast-uri audit fix, node base image bump, relay as an explicit check gate, dashboard docs contradiction fixed.
…te limiters, structured otel errors Binary-mode govulncheck clean on 1.26.5 (8 called stdlib vulns on 1.26.2), X-Forwarded-For walked right-to-left past trusted hops with forged-prefix tests, pinned edge address with a /32 trust default, upload and export limiter families, otel errors through zerolog, drill-evidence corrections with inline validator output, health envelope spec widened, cross-surface verification record closing the relay owner condition.
…, regenerated health types
Toolchain directive so CI builds on 1.26.5, CI MinIO pinned to the compose version via run steps with bucket creation, obsolete rate-limit register entry removed, stale audit row corrected, 406 capability details test case added, and the Phase 8 review document recording Ready with documented limitations.
Mujhtech
force-pushed
the
phase/8-operational-hardening
branch
from
July 31, 2026 09:39
bf5d95a to
ba1fffe
Compare
Mujhtech
marked this pull request as ready for review
July 31, 2026 09:39
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
No description provided.