Add typed long-term context graph - #3
Conversation
|
Exact candidate verification: Verified from a detached clean worktree:
Notes:
|
|
Final candidate: Prior independent-review blockers addressed:
Evidence at this exact SHA:
Final independent exact-SHA re-review is in progress. Merge/tag/release remains blocked until APPROVE. |
|
Final release candidate: Additional clean-clone release gate addressed:
Exact-head GitHub Actions run: https://github.com/hungrytech/knowledge-wiki/actions/runs/30618766319
The GitHub commit archive was downloaded independently; required files were present and its clean-source Quickstart preprocessing plus Compose config passed. Release remains fail-closed pending independent approval of this exact SHA. |
|
Final candidate superseded again after security review: Fail-closed fixes since
Regression coverage includes DNS-to-loopback, multicast literals, IP pinning/Host/encoding, private redirect rejection before a second request, and response-size rejection. Real pinned HTTPS smoke passed. Exact-head CI run 30621057464: server, web test/build/audit, Compose, and fail-closed aggregate all passed; annotations: 0. Prior-SHA reviews remain stale and are not release approvals. |
|
Current final candidate: Additional fail-closed hardening after stale review findings:
Exact evidence:
Publishing remains blocked pending an independent SHA-bound approval of |
|
Current exact candidate: Follow-up release-boundary fixes since
Exact evidence:
The prior SHA review results are stale. Publishing remains fail-closed pending an independent approval of exact |
|
GitHub-authenticated clean archive gate completed for exact
Release remains blocked only on an independent exact-SHA APPROVE. |
|
Current exact candidate: The Exact evidence:
Publishing remains fail-closed pending an independent approval bound to exact |
|
Final exact candidate is now A clean Docker rebuild exposed dependency drift in the previous Dockerfile (
Final exact evidence:
Publication remains fail-closed pending independent approval bound to exact |
|
Final exact candidate after resolving the slow-response-header lifecycle BLOCK: The URL fetch path now preserves the synchronous API while executing HTTP I/O through New regression evidence includes both a cancellable in-memory slow-header transport and a real TCP server that drip-feeds an incomplete response header, verifies return within the total budget, and observes peer socket closure. The real-socket probe was reproduced on Linux and is part of CI. Exact evidence:
|
|
Published after fresh independent APPROVE bound only to exact SHA Promotion and publication evidence:
CI retained no build artifacts; this is explicitly a source release. The public GitHub-generated source archive was independently downloaded and tree-verified after publication. |
Summary
Safety and compatibility
links-toedgesweb/vite.config.tsare excludedVerification
uv run --project server pytest server/tests -q— 32 passednpm --prefix web test -- --run— 9 passednpm --prefix web run build— passedgit diff --check— passedCurrent release caveat
This repository currently has no GitHub Actions workflow, so there is no remote CI evidence yet. The PR remains a release candidate until independent review and exact-SHA runtime verification complete.