diff --git a/docs/verification.md b/docs/verification.md index 3391d1a..a2e9883 100644 --- a/docs/verification.md +++ b/docs/verification.md @@ -37,8 +37,18 @@ edit, branch, or tag was made during this audit. production commit `921e04b3608007675e22e7e26e0beb3975dbba58`, compact topology, external PostgreSQL 18.4, healthy application containers, and passing public readiness. The plan correctly refused release because the - production checkout still lacks five Android/push capability groups. It - reported 38 pending local commits and made no remote change. + production checkout still lacks browser VAPID, the Firebase Android client, + server FCM delivery, and Android App Links. It reported 46 pending local + commits and made no remote change. +- A separate read-only isolation check observed the public Git `main` reference + still at production commit `921e04b3608007675e22e7e26e0beb3975dbba58`. + The test checkout remained clean at + `cf7bacdf61ffb171ebac85e32dfcf12bc6972d59`, with + `DEPLOYMENT_ENV=test`, Compose project `who_need_help_test`, its own + container database, and healthy application/database containers. Both + `https://test.whoneedhelp.com/healthz/ready` and + `https://whoneedhelp.com/healthz/ready` returned `ready`; no test, + production, public-Git, or Devpost mutation was performed. - A separate manual application rollback command now consumes only a successful release's mode-`0600` manifest. Its plan verifies current/previous commits, old application/edge images, backup checksum/catalog, runtime identity, and