[Release] Publish accumulated usability and security hardening — September 2026 #51
Closed
opened 2026-09-08 01:20:40 +02:00 by zemion
·
6 comments
No Branch/Tag Specified
Labels
Clear labels
area/api
area/auth
area/db
area/devex
area/docs
area/governance
area/marketing
area/migrations
area/module-system
area/rbac
area/release
area/security
area/tenancy
area/webui
audit/complexity
audit/duplication
audit/false-positive
audit/needs-design
audit/quick-fix
audit/structural
codex/needs-human
codex/ready
module/access
module/addresses
module/admin
module/appointments
module/approvals
module/audit
module/calendar
module/campaign
module/cases
module/committee
module/connectors
module/core
module/dashboard
module/dataflow
module/datasources
module/decisions
module/dist-lists
module/dms
module/docs
module/encryption
module/erp
module/evaluation
module/files
module/fit-connect
module/forms
module/forms-runtime
module/helpdesk
module/identity
module/identity-trust
module/idm
module/ledger
module/mail
module/mandates
module/notifications
module/ops
module/organizations
module/parties
module/payments
module/permits
module/policy
module/poll
module/portal
module/postbox
module/projects
module/quick-access
module/records
module/reporting
module/risk-compliance
module/scheduling
module/search
module/services
module/tasks
module/templates
module/tenancy
module/tickets
module/views
module/voting
module/wiki
module/workflow
module/workflow-engine
module/xoev
module/xrechnung
module/xta-osci
source/backlog-import
source/security-audit
source/todo-scan
HTTP API contracts, routers, schemas, or API smoke behavior.
Authentication, sessions, access bootstrap, or login behavior.
Database sessions, models, transactions, or persistence primitives.
Local developer workflow, scripts, tests, tooling, or release helpers.
Durable documentation and project guidance.
Governance policy, audit, privacy, retention, or compliance behavior.
Public website, product messaging, publication copy, or legal page content.
Alembic migrations, schema bootstrap, or persistence evolution.
Module discovery, manifests, capabilities, routing, or optional integrations.
Permissions, roles, delegation, or authorization policy.
Versioning, release locks, tags, packaging, or dependency pins.
Security posture, static analysis, supply-chain hardening, or vulnerability remediation.
Tenant boundaries, provisioning, or tenant-scoped data behavior.
Shared WebUI shell, frontend components, routing, or frontend tests.
Complexity finding from Radon, Xenon, or equivalent maintainability scans.
Duplicated-code finding from jscpd or equivalent similarity scans.
Audit finding reviewed as a narrow false positive or acceptable risk.
Audit finding that needs an architectural or product decision before implementation.
Audit finding that appears narrow and directly fixable.
Audit finding that needs design, refactoring, or behavior review.
Needs an explicit human decision before Codex should implement.
Suitable for Codex to pick up with the existing issue context.
GovOPlaN access, identity, authentication, RBAC, and administration behavior.
GovOPlaN Addresses module behavior or integration.
GovOPlaN Admin module behavior or integration.
GovOPlaN Appointments module behavior or integration.
GovOPlaN Approvals module behavior or integration.
GovOPlaN Audit module behavior or integration.
GovOPlaN Calendar module behavior or integration.
GovOPlaN campaign module behavior or integration.
GovOPlaN Cases module behavior or integration.
GovOPlaN Committee module behavior or integration.
GovOPlaN Connectors module behavior or integration.
GovOPlaN core runner, shared primitives, shell, or extension points.
GovOPlaN Dashboard module behavior or integration.
GovOPlaN Dataflow module behavior or integration.
GovOPlaN governed datasource contracts, catalogs, and integrations.
GovOPlaN formal Decisions module behavior or integration.
GovOPlaN Distribution Lists module behavior or integration.
GovOPlaN Dms module behavior or integration.
GovOPlaN Docs module behavior or integration.
GovOPlaN Encryption key custody, cryptographic policy, and E2EE integration.
GovOPlaN Erp module behavior or integration.
GovOPlaN Evaluation module behavior or integration.
GovOPlaN files module behavior or integration.
GovOPlaN Fit Connect module behavior or integration.
GovOPlaN Forms module behavior or integration.
GovOPlaN Forms Runtime module behavior or integration.
GovOPlaN Helpdesk module behavior or integration.
GovOPlaN Identity module behavior or integration.
GovOPlaN Identity Trust module behavior or integration.
GovOPlaN Idm module behavior or integration.
GovOPlaN Ledger module behavior or integration.
GovOPlaN mail module behavior or integration.
GovOPlaN Mandates, jurisdiction, responsibility, and authority behavior or integration.
GovOPlaN Notifications module behavior or integration.
GovOPlaN Ops module behavior or integration.
GovOPlaN Organizations module behavior or integration.
GovOPlaN procedure Parties, representation, and delivery-authority behavior or integration.
GovOPlaN Payments module behavior or integration.
GovOPlaN Permits module behavior or integration.
GovOPlaN Policy module behavior or integration.
GovOPlaN Poll module behavior or integration.
GovOPlaN Portal module behavior or integration.
GovOPlaN Postbox module behavior or integration.
GovOPlaN Projects module behavior or integration.
GovOPlaN configurable task-local Quick Access behavior and integrations.
GovOPlaN Records and eAkte lifecycle behavior or integration.
GovOPlaN Reporting module behavior or integration.
GovOPlaN Risk Compliance module behavior or integration.
GovOPlaN Scheduling module behavior or integration.
GovOPlaN Search module behavior or integration.
GovOPlaN versioned institutional Services behavior or integration.
GovOPlaN Tasks module behavior or integration.
GovOPlaN Templates module behavior or integration.
GovOPlaN Tenancy module behavior or integration.
GovOPlaN Tickets module behavior or integration.
GovOPlaN governed task views, interface projections, and workflow view integration.
GovOPlaN Voting module behavior or integration.
GovOPlaN Wiki module behavior or integration.
GovOPlaN Workflow module behavior or integration.
GovOPlaN Workflow Engine runtime, persistence, or integration.
GovOPlaN Xoev module behavior or integration.
GovOPlaN Xrechnung module behavior or integration.
GovOPlaN Xta Osci module behavior or integration.
priority
p0
Immediate stop-the-line priority.
priority
p1
High priority for the next focused work window.
priority
p2
Normal planned priority.
priority
p3
Low priority or opportunistic cleanup.
Imported from markdown backlog, roadmap, plan, or TODO files.
Created from a structured security or code-quality audit report.
Imported from inline TODO/FIXME/HACK markers by the Gitea TODO importer.
status
blocked
Cannot progress without a decision, dependency, credential, or external change.
status
in-progress
Currently being worked.
status
needs-info
Needs clarifying input before implementation can proceed safely.
status
ready
Ready for implementation.
status
triage
Needs review, ownership, priority, or acceptance criteria.
type
bug
A reproducible defect, regression, or incorrect behavior.
type
debt
Cleanup, refactoring, risk reduction, or deferred engineering work.
type
docs
Documentation, process, or developer workflow work.
type
feature
New user-visible behavior or platform capability.
type
task
Implementation, maintenance, migration, or operational work.
type
user-story
End-to-end user journey or real-world process story used to steer product slices.
No labels
Milestone
No items
No Milestone
Projects
Clear projects
No projects
No Assignees
Notifications
Due Date
No due date set.
Dependencies
No dependencies set.
Reference: GovOPlaN/govoplan#51
Reference in New Issue
Block a user
Blocking a user prevents them from interacting with repositories, such as opening or commenting on pull requests or issues. Learn more about blocking a user.
User-authorized release preparation: finish known verification gaps, review accumulated dirty/untracked work, create new independently versioned package tags, publish branches/packages and a reviewed signed catalog/runtime where gates permit. Initial inventory:30 dirty repositories; Cases additionally has a root npm version mismatch in already-published0.1.23 and needs a new patch (no historical tag changes). Core/meta target0.1.45; module patches retain independent versions. Scope includes Core#295,#296, Meta#50 and owning security issues. Gates:focused cross-module checks, manifest/version/migration alignment, browser/build/dependency regressions, immutable source/artifact checks. Track actual publication separately from local verification; no production deployment or live mail operations authorized or planned.
Preparation update: refreshed all79 origins; previously reported ahead counts were stale, and branches already matched Gitea. Preserved historical Docs tag discrepancies (v0.1.6/v0.1.21) without force-updating either source. Created fresh operator-private remote clones. Selected new Core/meta0.1.45 and28 modulepatches (including Cases0.1.24 metadata repair); source version gate now passes, migration baseline recorded and strictgraphgate passes. Fixed Meta#50 mixed-clockfixture; Campaign611tests+37subtests and standalone11pathchecks pass. Fixed stale Committee/Risk documentationcount assertions; their full suites plus Voting/Scheduling pass149tests. Release helper now supports literal MODULE_VERSION with regressioncoverage. Repaired missing documented Owners-only v* protection on seven package repos; no application permissions/secrets changed. Finalbuild compiles but startupgzip exceeds unchangedbudget by9bytes; a genuine code-size reduction is pending, so no Coretag/pushyet. Broaderfocused and browserchecks continue. No liveapplication data or mailoperationperformed.
Source preparation committed:28 independently versioned modules plus Coreshared-UI/cache changes and Website dependency patch (notpushedyet). FinalCoreUI productionbuild passes unchangedcap at163908gzipbytes (220headroom), after moving unchangedsettings-only defaults to lazycode. Full209browserconformance pass;13post-extractionappearance/theme cases pass. Release-relatedfixturechecks now derive exactversions fromcomposition; immutableartifact tests intentionally waitfornewlocaltags. Two orchestration findings surfaced: localmodule candidate tagging wrongly required futureCorelock; fixing onlylocal sequencing whilepreserving mandatorypublicationalignment. Flatpak projects /home and /usr as nfsnobody; hostread-onlyverification showsreal trustedownership, so publicationruntime is beingprepared with privatehostPython3.12, withoutchangingtrustgates. Remote-registryTrivy0.74 scan foundknownHIGH/CRITICAL findings inruntimebaseimage candidates; compatiblepatchupdates underreview, andruntimepublication remainsheld. Source/package/catalogpublication isseparate; no productiondeployment.
Release installability checks found 25 module repositories whose Git root does not expose the owning WebUI package (18 missing manifests, 7 generic roots). The local-tag batch was stopped during preflight: readback confirms zero new tags, and nothing has been pushed. Repairing these facades requires 12 additional independently versioned patch releases; existing 28 module targets remain unchanged. Also restoring Tasks to default module discovery with a regression: all 46 descriptors remain lazy, production build passes unchanged budgets (516,987 raw / 163,976 gzip).
The full-registry catalog path also predates newer strict candidate provenance requirements. A tested compatibility bridge is being prepared to retain registry artifact hashes, exact annotated tag/commit identities and signed keyring binding without weakening publication checks. Runtime image remediation is separately tracked in #52; source/package/catalog publication will not replace the latest signed runtime release.
Release staging checkpoint: immutable module tags and clean Git install
Source publication is complete: all 40 selected module patches, Core 0.1.45 (a6d056a3df81a1601d44c5e8c7bd1a55d64d2b45), and Meta 0.1.45 (
88b685ff5e) were published, Meta last. Every main branch and immutable annotated tag object was read back and matched its frozen receipt. No historical tags were moved.The first two attempts stopped before any mutation on separate intermittent SSH tag-read timeouts. Both failed logs were retained. A separately reviewed private operator adapter permits at most THREE total attempts only for exact timed-out, frozen-ref read commands; authentication errors, conflicts and all writes are not retried. Nine isolated tests passed independently, and all canonical source/preflight/receipt checks stayed unchanged. The successful publication needed zero retries. This is an operator-only aid, not a change to any published source tree.
The complete, unmodified focused gate passed (63 production module combinations, 213 browser cases, all backend and remaining checks), as did 221 release-tool tests plus 59 subtests. Two existing PostgreSQL concurrency tests remained explicitly skipped without a configured test database. All 79 shared worktrees are clean; remote-tracking synchronization for the 42 published repositories is in progress.
Native package CI was triggered automatically and is still publishing. The exact registry artifact download, native-archive production build, signed full module catalog and website publication are PENDING. This coordination issue stays open until those results are recorded. Runtime images and the ordinary Meta runtime Release remain held under #52; no deployment has been performed.
The scoped source/package/signed-catalog Git release is complete. This does NOT claim a production deployment or a new runtime distribution.
Published and verified
a6d056a3df81a1601d44c5e8c7bd1a55d64d2b45; Meta:88b685ff5e689acf096bdfc7084bd108e801e86e. No historical tags were rewritten.govoplan==0.1.45published through protected-tag CI. The full 73-wheel/47-WebUI set was downloaded from the canonical registry and independently verified. The separate developer Meta wheel matches all 73 declared dependency entries (16 base + 57 full-extra); SHA-256e1c6b836e58280f54c3124391db6c28ce95321ebe217b6ef1144c8f6483ec973.d2d955aand signed catalog commit03ac237949a1963189d1b7a4b3cc3397e60b10a1pushed. Annotated tagcatalog-v0.1.45, tag object3d4735ea3028edfa47341e4f0b53650a4ae868d6, was remotely verified. The website build passed.202609080236; canonical catalog hash29b0b6ae10c0115f656a7035fd0c3298c31201f8a09a17834dbb73cf2d30a36e. Published file SHA-25600dd1fa8390b7823dc082eddaca0bd826f9fcee0c479f56cd82ea55f93bf3cc8. The existing trusted keyring is unchanged; no key rotation occurred.2937bde1ad27926071a2d4cb26bb69bd87fb20f076552c171e671a9e5f95d939; artifact-lock hash9472700ae76bc7920a91fc7619cf3c3c9f0438a2eb2edc0daefe4ddf6398facc.Verification
The complete unmodified focused gate passed: 63 production module combinations, 213 browser cases, all remaining backend/structural checks; release tooling passed 221 tests plus 59 subtests. Two existing Datasources PostgreSQL concurrency tests remained explicitly skipped because no test PostgreSQL URL was configured; that evidence is not claimed.
Both fresh immutable Git-source and native-registry production builds passed unchanged budgets. The latter installed all 46 actual native module archives with strict peers, no force/legacy-peer workaround, and preserved all 208 external locked identities. Startup bundle: 513,825 raw / 163,019 gzip bytes, with 1,109 gzip bytes of budget headroom; 46 lazy / zero eager module descriptors. An initial private-harness check rejected npm's absolute-to-relative tarball spelling; all archive bytes/SRI matched. A narrowly tested two-spelling correction passed six tests and the full build, without altering source, dependency versions, integrity checks or budgets. Failed evidence was retained.
Push-triggered whole-system security audit run 1432 and developer Meta package run 1433 succeeded. Subsequent scheduled audit 1434 is a separate run and was not cancelled or bypassed.
Explicitly separate, still open
No live database migration, application deployment or real campaign mail was performed. Release notes and upgrade/manual smoke guidance are in
docs/releases/0.1.45.md; bounded review evidence is indocs/security/SECURITY_PERFORMANCE_REVIEW_2026-09-08.mdand the runtime audit report.