Conversation
|
@KodeSage Great news! 🎉 Based on an automated assessment of this PR, the linked Wave issue(s) no longer count against your application limits. You can now already apply to more issues while waiting for a review of this PR. Keep up the great work! 🚀 |
|
👋 Hi @KodeSage, thanks for your contribution! Pull requests from contributors must target the This PR is being closed automatically. Please open a new PR (or retarget this one by reopening it after editing the base branch) against |
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Description
Adds four operator and contributor reference docs under
docs/. All four are built from the code as it is today rather than from intent. Where the code and existing docs disagree, the doc says so and names the file.Docs only: no source, config or CI files change. Each doc passes the repo's pinned Prettier (
3.9.1).1.
docs/environment-variables.md(#542)One table of every environment variable across
apps/backend,apps/web,apps/ai_agentandapps/tests. For each variable it gives the app that reads it, required or optional, the default, when it is loaded, and what breaks if it is wrong..env.example, plus about 30 read throughprocess.envthat.env.exampleleaves out, including all 15RATE_LIMIT_<BUCKET>overrides.config.tsvalidates at boot (crash on start) and which are read later, where a bad value fails silently.NEXT_PUBLIC_*value 🌐 as compiled into the client bundle and therefore public.2.
docs/release-process.md(#547)dev→mainpromotion flow. Only the maintainer merges tomain, matching the check inguard-main-branch.yml.contracts/docs/api-deployment-invocation.md.docs/runbook.md.3.
docs/code-style.md(#551)tsc, ruff + mypy, rustfmt + clippy): the tool, config file, command, and whether CI blocks on it..prettierignoreand its rule: generated output (drizzlemeta/,*.d.ts, Sorobantest_snapshots/) is never formatted.#N —/(#N)). 56 of the 83 non-test backend source files follow it.no-explicit-any), web ESLint 4 (no-unused-vars). These are non-blocking, but no PR may add to them.4.
docs/data-retention.md(#554)docs/threat-model.md.Problems found while writing these docs
These are recorded in the docs and left unfixed so this PR stays docs-only. Each is worth a follow-up issue.
Security
.envfile after all its imports have run. Values set only in.envare therefore missed by any module that reads its settings at import time.JWT_SECRETthen falls back to'test-secret', and the boot check still passes.deploy_group_treasury.shdoes not pass the requiredthresholdargument, so theinitializestep fails. The contract is left deployed but uninitialised, and anyone can initialise it and become admin.audit_logs_no_mutationappend-only trigger is described in the docs and the schema, but no migration creates it.0001_audit_logs.sqldoes not exist.Data retention
/index/messagestores plaintext message content in Weaviate, with no retention window and no delete endpoint.filesrows along with the conversation. The cleanup job never finds them, so their encrypted blobs stay in the object store forever.Config drift
.env.examplelistsRPC_URL, but the code readsSTELLAR_RPC_URL.IDEMPOTENCY_TTL_SECONDSis validated at boot but never used.XMTP_ENV,PROPOSALS_CONTRACT_IDand allS3_*variables are never read.Process and CI
devbranch onoriginyet.main. The guard workflow only checks who opened the PR, so a branch-protection rule is needed.apps/backend/src, acargo fmtcheck, or a backendtsctype check.Issue numbers
Closes #542
Closes #547
Closes #551
Closes #554
Type of change
Checklist
prettier --check, internal links and anchors were checked against the target headings, and the lint and format counts incode-style.mdwere measured by running the tools3.9.1and the shared.prettierrc.json