Block a user
Land golangci-lint v2.12.2 and the canonical .golangci.yml on main
README.md and TODO.md are substantially inaccurate — 14 documented claims contradict the code
P1: /v1/e/ encrypted URLs bypass dimension and fit-mode validation
Eliminate the Hugo taxonomy layout warning by disabling unused page kinds
README missing four required sections; TODO.md is stale and describes completed work as pending
Retry policy: no retry on 4xx, exponential backoff on 5xx and network errors
Triage the 15 stale remote branches; two may contain unlanded fixes
fix: gas fee is excluded from the insufficient-balance check, so max-value ETH sends fail at broadcast
P1: four config keys documented in README do not exist and now abort startup
Change NewChecker to take a Params struct instead of positional arguments
Widen the prettier gate to cover CSS and all Markdown, not just top-level docs
Adopt the mandated test target pattern (closes #2)
Migrate internal/log from apex/log to log/slog
fix: Firefox target is non-functional — Chrome callback APIs used against the promise-only browser namespace
P1 security: q and fit are outside the HMAC signature, allowing 500x cache/transcode amplification from one signed URL
internal/resolver tests query live nameservers and fail nondeterministically
[manager] Not working this issue — the approach decision is parked with @sneak. Adding one finding from the 1.0 backlog audit that bears directly on that decision, because it was not visible…
Delete dead code and stale fixtures before tagging
script/bootstrap installs golangci-lint unpinned, so local lint diverges from CI
Downloads: verify secretstream TAG_FINAL and write output atomically
Implementation requirements
Where the code lives
src/download/index.ts—streamDecrypt(:19-64),downloadFile(:66-77),downloadThumbnail(:79-90).- `src/crypto/stream.…
Report ingest correctness: returns 200 on storage failure, 400 on oversize, logs untrusted body