Skip to content

Kuan v1.0 — final stabilization, database CI and release validation - #37

Merged
NomosLudens merged 5 commits into
mainfrom
codex/finalize-kuan-v1.0-stabilization-and-ci
Jul 12, 2026
Merged

NomosLudens merged 5 commits into
mainfrom
codex/finalize-kuan-v1.0-stabilization-and-ci

Conversation

@NomosLudens

Copy link
Copy Markdown
Owner

Motivation

  • Repair the GitHub Actions startup failure and add a safe, minimal CI flow to validate the app and database for Kuan v1.0.
  • Ensure migrations, RLS, RPC grants and supersede concurrency/normalization are validated in a disposable Supabase local run in CI (without touching remote projects or secrets).
  • Provide a small set of QA scripts and an honest release report so remote runners can produce verifiable evidence for technical approval.

Description

  • Hardened the CI workflow (.github/workflows/ci.yml) by adding top-level permissions: contents: read, job timeout-minutes, pinned action versions (actions/checkout@v4, oven-sh/setup-bun@v2 with bun-version: 1.2.14, supabase/setup-cli@v3 with version: 2.84.2), and a safe explicit supabase status -o env export that only injects SUPABASE_ variables into the environment.
  • Added a PostgreSQL audit script scripts/qa/kuan-v1-database-audit.sh that checks function security_type and RPC EXECUTE grants using information_schema to enforce DEFINER/INVOKER and grantee constraints (PUBLIC/anon blocked, authenticated allowed).
  • Expanded and hardened QA fixtures and scripts: scripts/qa/setup-pr36-fixtures.ts now creates dedicated decisions for isolation, supersede, concurrency, normalization and invalid-state cases; scripts/qa/pr36-supersede-concurrency.ts was extended to validate anon denial, authenticated A/B isolation, RPC grants, normalization (trim and size checks), invalid-state rejection, concurrency atomicity (exactly one winner/one failure), orphan-row checks and counts.
  • Minor editorial/formatting updates to QA docs (docs/qa/KUAN_CALENDAR_PRIVACY_RUNTIME_CHECKLIST.md, docs/qa/KUAN_COMMERCIAL_CONTEXT_INTERPRETER_CHECKLIST.md) and a new canonical release report docs/qa/KUAN_V1_RELEASE_REPORT.md documenting what was executed and known limitations.

Testing

  • Local automated checks executed: bun run format:check (Prettier passed), bun run lint (ESLint completed with warnings but zero errors), bun run typecheck (TypeScript passed), bun run test (Vitest: all tests passed: 23 files / 248 tests), and bun run build (Vite build succeeded).
  • Runtime smoke: after build bun run start launched the server and curl -I against /, /kuan, and /kuan/plano returned HTTP 200 (smoke OK).
  • Database CI and Supabase-backed QA were prepared in the workflow and QA scripts, but could not be executed in this environment because the local runner lacked Docker/Supabase CLI and the repository remote (origin) is not configured here; therefore remote GitHub Actions runs (the intended verify and database checks) are pending and must be observed on the GitHub runner for final verification.
  • Cloudflare dry-run attempted resolution of wrangler but failed due to registry access (npm returned 403), so Cloudflare dry-run/deploy was not executed.

Codex Task

@cloudflare-workers-and-pages

cloudflare-workers-and-pages Bot commented Jul 12, 2026 •

Copy link
Copy Markdown
Contributor

Deploying with  Cloudflare Workers  Cloudflare Workers

The latest updates on your project. Learn more about integrating Git with Workers.

Status Name Latest Commit Updated (UTC)
✅ Deployment successful!
View logs
kuan 3e2d87e Jul 12 2026, 06:59 PM

@NomosLudens
NomosLudens merged commit 1888bb1 into main Jul 12, 2026
3 checks passed
@NomosLudens
NomosLudens deleted the codex/finalize-kuan-v1.0-stabilization-and-ci branch September 4, 2026 00:22
NomosLudens pushed a commit that referenced this pull request Sep 4, 2026
…lization-and-ci

Kuan v1.0 — final stabilization, database CI and release validation
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant