The repository is public now: tidy what it shows, fix a vulnerable dependency, and add a licence #146
Loading…
Add table
Add a link
Reference in a new issue
No description provided.
Delete branch "%!s()"
Deleting a branch is permanent. Although the deleted branch may continue to exist for a short time before it actually gets removed, it CANNOT be undone in most cases. Continue?
The repository was made public on 2026-10-05 and renamed from
openspec-flowtobraid. A review of the tree, the history, the issues and the deploy setup found no credentials, but it left a list of smaller things to put right.What is wrong
urllib3is locked at 2.7.0, whichpip-auditreports under PYSEC-2026-4175, -4176 and -4177. All three are fixed in 2.8.0.outA.json,outB.jsonand an emptypa.jsondate from the first design commit and are used by nothing.deploy/README.md,deploy/.env.example,deploy/forgejo/README.mdanddocs/environment.mdgive LAN addresses, the Portainer address and an ssh login. None of it is reachable from outside, but a public runbook should read as an example to adapt, not as a map of one network.README.md,CLAUDE.md,openspec/config.yaml,deploy/README.mdand the image's source label point atcmoriarty/openspec-flow. The web redirect works; git over ssh does not follow it.LICENSEgrants a reader nothing. The owner has chosen MIT.SECURITY.mdsaying how to report a problem and what the trust model is (an internal tool, with no login in front on a private network).What should not change
forgejo.underthere.xyz/cmoriarty/openspec-flow. A package's name is its own, not the repository's, and production pulls it by that name.<!-- openspec-flow:begin -->markers and the Python package name stay: runs and their AGENTS.md blocks depend on them.Out of scope
Rewriting history to drop the run state committed in
184fb8e(decided against: it holds no credential, and a force-push costs every clone). Rotating tokens. The Forgejo instance's own settings, which were fixed by hand on 2026-10-05 (OpenID sign-up off, 2FA on the admin account).Shipped in
67060dcand live on production since 2026-10-05 20:44Z; the change is archived as2026-10-05-public-repo-tidy(f78da2b).What shipped
urllib32.7.0 → 2.8.0 inuv.lock.pip-auditon the runtime requirements reports no known vulnerability, and the running container has 2.8.0.outA.json,outB.jsonandpa.jsonare deleted.deploy/README.md,deploy/forgejo/README.md,docs/environment.mdand the README no longer give LAN addresses, the Portainer address or an ssh login.cmoriarty/braid.LICENSE, the field inpyproject.toml, and a line in the README.What did not
SECURITY.md: decided against.deploy/docker-compose.yml,deploy/.env.example,src/osf/config.py,src/osf/notify.py,tools/demo.shandtools/context_curve.py, so production and a laptop start with no new variable.openspec/specs/deployment/spec.mdstill names the VM's address in a requirement.cmoriarty/openspec-flow.Checks
The fast lane passed (2,603 backend tests, UI types, unit tests, build and browser specs). The image's self-check passed in the deploy.
One thing found on the way
The deploy's Portainer webhook was accepted and did nothing for three runs in a row (deploy runs 110, 111 and 112); production took the commit only after a manual Pull and redeploy. Runs 108 and 109 earlier the same day worked. The cause is not known yet and needs Portainer's own log.