Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
8 changes: 4 additions & 4 deletions PLAN.md
Original file line number Diff line number Diff line change
Expand Up @@ -60,7 +60,7 @@
| **v1.0.10** | Dependency-manifest drift guard — CI fails if `pyproject.toml` / `uv.lock` / `requirements.txt` disagree | ✅ shipped |
| **v1.0.11** | Cache Components navigation-state sweep — roast duplication, `/me` staleness, analytics double-count, badge a11y, session snapshot; + fixture time-bomb and backend version-drift guards | ✅ shipped |
| **v1.0.12** | Narrative output sweep — truncated/empty/markdown narratives, alertable fallback signal; + alembic logging bug, 72 DB tests enabled in CI (12 repaired), Next 16.3.2 | ✅ shipped |
| **v1.0.13** | Audit remediation + dependency refresh — two critical Next.js advisories, commit-before-response, singleflight coalescing, fresh force refresh, cron classification, honest share/delete UI, structured logs; `requirements.txt` generated in CI | 🚧 PR open, tag pending |
| **v1.0.13** | Audit remediation + dependency refresh — two critical Next.js advisories, commit-before-response, singleflight coalescing, fresh force refresh, cron classification, honest share/delete UI, structured logs; `requirements.txt` generated in CI | ✅ shipped |
| **v1.0.14** | Toolchain majors — TypeScript 6, Vitest 5, jest-dom 7, Sentry SDK 11, framer-motion 13, openai 3, SQLAlchemy 2.1, each proven alone | 📋 proposed |

---
Expand Down Expand Up @@ -1050,9 +1050,9 @@ The narrative-mode CHECK constraint was a third drift in the same family — the
- [x] Backend: ruff clean; full suite green with a database attached.
- [x] Frontend: lint, tsc, vitest and a production build pass; `npm audit` reports 0.
- [x] All four version constants at `1.0.13`.
- [ ] PR checks green and merged; prod smoke passed.
- [ ] Housekeeping: blocked Dependabot PRs closed; Sentry noise archived.
- [ ] `CHANGELOG.md` `[1.0.13]`; tag `v1.0.13` (operator checkpoint).
- [x] PR **#111** checks green and merged; prod smoke passed: `/health` reports 1.0.13 on GET and HEAD, the narrator streams, and log lines arrive in Vercel as JSON carrying a `request_id` that matches the response's `X-Request-Id`.
- [x] Housekeeping: Dependabot PRs 12 → 1 (blocked majors and superseded updates closed with notes; #75 kept for v1.0.14); Sentry FRONTEND-3/4/5 archived until escalating; 0 open Dependabot alerts (21 marked fixed).
- [x] `CHANGELOG.md` `[1.0.13]`; tag `v1.0.13` on `d1b1e58`; GitHub Release published.

---

Expand Down
29 changes: 29 additions & 0 deletions docs/PROGRESS_LOG.md
Original file line number Diff line number Diff line change
Expand Up @@ -19,6 +19,35 @@ Format:

---

## 2026-10-01 — Claude (Opus 5.5) with Shaan — v1.0.13 released

**Slice:** v1.0.13 closeout.

**Done:**
- **Merged and deployed.** PR #111 merged as `d1b1e58`, with all five checks green on the PR and on `main`.
- **Production verified:**
- `/health` returns `{"status":"ok","version":"1.0.13","db":"up","cache":"up"}`, and `HEAD /health` returns 200 (it was 405).
- Security headers are unchanged.
- A live mentor narrative streamed (292 chunks in 4.3s, ended by the done sentinel, not truncated).
- A cache-hit request's log line reached Vercel as JSON (`event`, `level`, `logger`, `timestamp`) with a `request_id` matching the response's `X-Request-Id`.
- The new deployment logged zero `HTTP Request:` lines, even with a live Groq call.
- **Dependabot alerts: 17 open → 0**; GitHub marked 21 as fixed.
- **Dependabot PRs: 12 → 1.**
- Dependabot closed #20, #73 and #74 itself once the ignore rules landed, with a generic "no longer updated" note, so each now also has a comment naming the real blocker.
- It also closed the superseded group PRs #107–#110.
- #71, #77, #78 and #80 were closed by hand as superseded.
- #75 (jest-dom 7) stays open for v1.0.14.
- **Sentry:** FRONTEND-3/4/5 archived "until escalating" through a headless Sentry MCP session, so they return on their own if they recur.
- **Released:** tagged `v1.0.13` on `d1b1e58`, and `release.yml` published the GitHub Release from `CHANGELOG [1.0.13]`.

**Blocked / open:**
- The deferred minors in the 2026-09-30 entry.
- Operator items: the Sentry alert rule and source-map upload; browser-only checks of sign-in and share revoke on production.

**Next:** v1.0.14, toolchain majors.

---

## 2026-09-30 — Claude (Opus 5.5) with Shaan — v1.0.13: full audit, remediation and dependency refresh

**Slice:** v1.0.13 (spec `docs/superpowers/specs/2026-09-30-v1.0.13-audit-remediation-design.md`, plan `docs/superpowers/plans/2026-09-30-v1.0.13-audit-remediation.md`).
Expand Down
Loading