docs: record the pre-1.0 security review in TODO.md #497

Merged
clawbot merged 1 commits from issue-383-security-review-record into next 2026-10-07 09:43:07 +02:00
Collaborator

Records the result of #383 in TODO.md, the one item of its definition of done still open. Only TODO.md changes.

  • Completed Steps: a new entry says what the review read (the tree at 99292b9), that its ten findings are filed and fixed on next, the three owner decisions it raised that are still open (#401, #408, #409), and what it did not cover, including that the planned independent second check of each finding never ran.
  • Next Step: takes the one Future Steps item, cutting 1.0.0 once the milestone is empty, now with a link to the milestone. Future Steps is left with only its opening sentence.
  • Status: the dated make check result is gone, the milestone PR link is now #388, and the make check sentence says what it runs.

README.md is unchanged. It makes no claim about the review, and its unchecked "Security audit of key management" box is still accurate.

Judgement call: besides the three areas in the issue title, the entry names the site permission model and storage, because the review summary says it read them.

Model: opus-5-5

Records the result of https://git.eeqj.de/sneak/AutistMask/issues/383 in `TODO.md`, the one item of its definition of done still open. Only `TODO.md` changes. - Completed Steps: a new entry says what the review read (the tree at `99292b9`), that its ten findings are filed and fixed on `next`, the three owner decisions it raised that are still open (https://git.eeqj.de/sneak/AutistMask/issues/401, https://git.eeqj.de/sneak/AutistMask/issues/408, https://git.eeqj.de/sneak/AutistMask/issues/409), and what it did not cover, including that the planned independent second check of each finding never ran. - Next Step: takes the one Future Steps item, cutting 1.0.0 once the milestone is empty, now with a link to the milestone. Future Steps is left with only its opening sentence. - Status: the dated `make check` result is gone, the milestone PR link is now https://git.eeqj.de/sneak/AutistMask/pulls/388, and the `make check` sentence says what it runs. `README.md` is unchanged. It makes no claim about the review, and its unchecked "Security audit of key management" box is still accurate. Judgement call: besides the three areas in the issue title, the entry names the site permission model and storage, because the review summary says it read them. Model: opus-5-5
clawbot added the needs-review label 2026-10-07 09:13:46 +02:00
clawbot self-assigned this 2026-10-07 09:13:46 +02:00
clawbot added 1 commit 2026-10-07 09:13:46 +02:00
docs: record the pre-1.0 security review in TODO.md (closes #383)
check / check (push) Waiting to run
e2e / e2e-chrome (push) Waiting to run
e2e / e2e-firefox (push) Waiting to run
260563af6c
The security review moves from Next Step to Completed Steps, saying what it
read (the tree at 99292b9), that its ten findings are filed and fixed on next,
which owner decisions it raised are still open, and what it did not cover.
Next Step takes the one Future Steps item, cutting 1.0.0 once the milestone is
empty. Status drops a dated gate result and links the current milestone PR.

Model: opus-5-5
Author
Collaborator

PASS

Model: opus-5-5

PASS Model: opus-5-5
clawbot merged commit 29ba54d5b6 into next 2026-10-07 09:43:07 +02:00
clawbot deleted branch issue-383-security-review-record 2026-10-07 09:43:07 +02:00
Sign in to join this conversation.
No Reviewers
1 Participants
Notifications
Due Date
No due date set.
Dependencies

No dependencies set.

Reference: sneak/AutistMask#497