You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
{{ message }}
Repository navigation
[Bug]: synchronize superseded release status documentation #114
docs/security-audit-report.md retains its exact-subject historical NO-GO without an upfront resolution/supersession notice, so readers can mistake it for current release status.
Expected behavior
Current-status documentation must match merged main and distinguish historical exact-SHA audit results from the later remediation and Gate C PASS. It must preserve all Live/Fixture, MANUAL_REVIEW, STOP, Moss integration-fork, Clear402, wallet/signing, and no-hosted-Live limitations.
Reproduction
Check out 4ec4e2d8c5e8fbbc08572f544461cbd5e1c24d7d.
Writable scope is exactly the six documentation files listed in the Issue. The correction will reconcile current status with Gate C, #102, visual QA, current main CI, and public health while preserving all accepted evidence and trust boundaries.
No runtime, test, dependency, lockfile, Gate verdict, tag, media, or submission change is authorized. Historical audit results remain intact with an explicit later-resolution notice.
Verification: six-file path audit, local-link audit, claim-risk classification, Node 22 pnpm check, production audit, public 9-test smoke, exact-head CI, and detached clean SINGLE_OPERATOR_QA.
POST_MERGE_AUDIT: squash merge 34f64df is on protected main; Issue is Closed; Project status is Done; merged-main quality-gate run 31304149377 succeeded; remote feature branch was deleted; no trust-boundary or runtime behavior changed.
Observed behavior
Current
main@4ec4e2d8c5e8fbbc08572f544461cbd5e1c24d7dcontains mutually contradictory release statements:README.mdsays implementation stops at M5-06 although Gate C, visual QA, deployment, and the merged frontend are complete.SECURITY.mdcalls the application a non-integrated Web/API baseline.docs/real-vs-mock.mdsays there is no integrated runnable demo and lists already implemented Moss, orchestration, report, and UI behavior as absent.docs/judge-map.mdlists completed workbench and visual acceptance as remaining proof.docs/known-issues.mdreports production advisories as currently open although P0: remediate production dependency advisories blocking Gate C #102/PR P0: remediate production dependency advisories #104 remediated them and Gate C's production audit passed.docs/security-audit-report.mdretains its exact-subject historical NO-GO without an upfront resolution/supersession notice, so readers can mistake it for current release status.Expected behavior
Current-status documentation must match merged main and distinguish historical exact-SHA audit results from the later remediation and Gate C PASS. It must preserve all Live/Fixture, MANUAL_REVIEW, STOP, Moss integration-fork, Clear402, wallet/signing, and no-hosted-Live limitations.
Reproduction
4ec4e2d8c5e8fbbc08572f544461cbd5e1c24d7d.docs/gate-c-report.md,docs/visual-qa-report.md, closed P0: remediate production dependency advisories blocking Gate C #102, and main quality-gate run 31300536251.Evidence
b28116979084719f6f4fa0fd829f3671b4ab28f2, including clean production audit.4ec4e2d8c5e8fbbc08572f544461cbd5e1c24d7d, quality-gate run 31300536251 SUCCESS, public smoke 9/9.network.configured=false,clear402.enabled=false, MossofficialRelease=false.Scope
Writable only:
README.mdSECURITY.mddocs/real-vs-mock.mddocs/judge-map.mddocs/known-issues.mddocs/security-audit-report.mdNon-goals
Acceptance
pnpm check, production audit, public smoke, andgit diff --checkpass.Security impact
Documentation-only correction. It reduces misleading release and evidence claims without changing runtime behavior or assurance.