You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
Full cora scan on develop @ e9706b7 (pre-tag v0.9.0): 213 files, 292 findings (26 MAJOR, rest MINOR/INFO). Per release policy, MAJORs that are not v0.9.0 regressions and not broken-by-default regressions are triaged to this tracking issue instead of blocking the release.
Verified false positive (removed from blocker list)
Dockerfile:38 "ENTRYPOINT references index.js but adapter-node emits server/index.js" — bun run index.js resolves /app/index.js, which exists at the root of the copied build/ dir and is the adapter-node entry shim that imports ./server/index.js. This exact Dockerfile produced the working v0.7.x/v0.8.0 GHCR images.
docs/deployment.md: shell substitution in .env example; Caddyfile header_up outside reverse_proxy; backup scripts target named volume vs bind mount mismatch
OAuth callback does not validate state parameter (web/src/routes/auth/callback); auth-flow docs omit state/PKCE
TITEN_COOKIE_SECURE defaults to false + token encryption off by default in docker-compose (documented dev default; consider deriving from APP_URL scheme, rungu pattern)
API key accepted via ?api_key= query string (docs + README)
install.sh: binaries installed without checksum verification; PATH fallback writes .bashrc unread by zsh
Correctness
web/src/routes/admin/mentions: reply posted from currently selected account, not the mention's account
web/src/routes/admin/settings: form shows defaults while loading; save can overwrite server config
web/src/routes/admin/schedules: loadMore lacks stale-response guard; triple initial fetch from loaded flag
web/src/routes/admin/accounts: empty Expires At crashes with Invalid Date; avatar placeholder crashes without username
docker-compose: web port always published to host (bypasses Traefik TLS when fronted)
titen-cli: URL query/path interpolation without percent-encoding; response parsed before HTTP status check; pre-restore backup misses WAL
Why
Full scan output kept at release time; items are real but none is a v0.9.0 regression. Each PR merged into v0.9.0 passed the per-PR Cora Review check cleanly.
Testing
Triage per-item when picked up; verify against current develop before fixing (some may already be fixed)
What
Full
cora scanon develop @ e9706b7 (pre-tag v0.9.0): 213 files, 292 findings (26 MAJOR, rest MINOR/INFO). Per release policy, MAJORs that are not v0.9.0 regressions and not broken-by-default regressions are triaged to this tracking issue instead of blocking the release.Verified false positive (removed from blocker list)
Dockerfile:38"ENTRYPOINT references index.js but adapter-node emits server/index.js" —bun run index.jsresolves/app/index.js, which exists at the root of the copiedbuild/dir and is the adapter-node entry shim that imports./server/index.js. This exact Dockerfile produced the working v0.7.x/v0.8.0 GHCR images.MAJOR backlog
Docs accuracy
?confirm=trueon account delete; schema section outdated (8 tables / 4 migrations); missing newer endpoints (/ready,/metrics,/api/health, trends)header_upoutsidereverse_proxy; backup scripts target named volume vs bind mount mismatchSecurity hardening
stateparameter (web/src/routes/auth/callback); auth-flow docs omit state/PKCETITEN_COOKIE_SECUREdefaults to false + token encryption off by default in docker-compose (documented dev default; consider deriving from APP_URL scheme, rungu pattern)/metricsregistered outside auth middleware (always public)?api_key=query string (docs + README)Correctness
loadMorelacks stale-response guard; triple initial fetch fromloadedflagWhy
Full scan output kept at release time; items are real but none is a v0.9.0 regression. Each PR merged into v0.9.0 passed the per-PR Cora Review check cleanly.
Testing