Skip to content

Patch dependencies and verify hosted MCP, recovery and container workflows - #1

Merged
agammann merged 3 commits into
mainfrom
verify-hosted-onboarding
Oct 2, 2026
Merged

agammann merged 3 commits into
mainfrom
verify-hosted-onboarding

Conversation

@agammann

@agammann agammann commented Oct 2, 2026 •

Copy link
Copy Markdown
Owner

Cove’s locked dependencies reported 24 advisories, and CI did not exercise the compiled hosted MCP endpoint or the separate recovery/container scripts. Patch Fastify, Nodemailer, Wrangler and compatible transitive packages; add actual HTTP OAuth checks for all seven tools, independent grants and live revocation; and run a disposable Compose backup/restore and production-container job. Recovery now compares complete project/history contents and only drops a restore database it successfully created.

Validation: frozen installation, lint, types and audit pass; the audit reports zero advisories. Final CI run 36963265214 passed 21 PostgreSQL/domain/Sites tests, the local email-auth browser journey, the compiled D1 browser/HTTP MCP checks, saved-history restoration and database restart, and non-root/read-only container migration, health, frontend, Host guard, restart and insecure-configuration checks.

The README and development guide link dated evidence and repeatable commands. Real production ChatGPT sign-in and native assistant-host connections still require the owner’s account connection; SDK checks do not establish those integrations.

@agammann agammann changed the title Verify compiled browser and MCP onboarding and patch dependencies Patch dependencies and verify hosted MCP, recovery and container workflows Oct 2, 2026
@agammann
agammann marked this pull request as ready for review October 2, 2026 04:14
@agammann
agammann merged commit 21c069f into main Oct 2, 2026
4 checks passed
@chatgpt-codex-connector

chatgpt-codex-connector Bot commented Oct 2, 2026 •

Copy link
Copy Markdown

Codex Review Summary

This comment shows the latest Codex review activity on this pull request.

Review Status Commit Review trigger
📝 Code Review ✅ Completed 2026-10-02T04:15:17.377819Z c1cc9e9 Draft marked ready
ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review" or "@codex security review".

Codex reacts with 👀 while any review is running, comments if it has suggestions, and reacts with 👍 once all reviews finish with no findings.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant