Record transactional email launch proof

This commit is contained in:
SimpleTest 2026-08-12 16:40:36 +03:00
parent 009ed6dafa
commit 7c812526d0
2 changed files with 48 additions and 1 deletions

View File

@ -43,6 +43,14 @@ final image scans after updating Phoenix LiveView from advisory-affected
`1.2.8` to patched `1.2.9`. Exact unit, timing, memory, cleanup, and dependency
evidence are recorded in `docs/verification.md`.
The current 2026-08-12 launch-boundary rerun passed 462 ExUnit tests, fourteen
browser map-asset tests, the migration-registry completeness check, all
configured quality/security and production-release drills, and the final image
scans with zero detected vulnerabilities. The isolated unit completed in
4 minutes 47.572 seconds with a measured 222.3 MiB memory peak and left no
run-scoped container or temporary image. Exact email-flow and migration evidence
is recorded in `docs/verification.md`.
## 2. Verify production configuration without exposing secrets
Run both checks against the single ignored production `.env`. The first reports

View File

@ -1,8 +1,47 @@
# Who Need Help — implementation verification
Observed through 2026-08-10 in the local workspace. This report separates observed
Observed through 2026-08-12 in the local workspace. This report separates observed
results from product limits and unknown production properties.
## Current launch-boundary and transactional-email proof on 2026-08-12
- The complete isolated `scripts/quality.sh` pipeline passed in user-systemd
unit
`codex-heavy-wnh-quality-launch-boundary-20260812-163255-3402967.service`.
It completed successfully in 4 minutes 47.572 seconds with a measured
222.3 MiB memory peak. ExUnit reported 462 passing tests with seed `616444`,
and the browser map-asset suite reported fourteen passes.
- The run passed the repository policy, ShellCheck, Hadolint at the configured
threshold, actionlint, Compose, Helm, observability, format, compiler, xref,
Credo, Sobelow, Dialyzer, dependency audits, migration and rollback drills,
and the production-release orchestration drills. The final Debian 13.6
application image and all pinned infrastructure images reported zero detected
vulnerabilities.
- The migration compatibility registry is now checked against every migration
at or after the first reviewed version. The pending
`20260812120611_allow_inbox_only_nearby_subscriptions.exs` migration is
explicitly classified `application_safe`; the isolated policy drill proved
that missing registry entries are rejected while reviewed safe and
forward-only entries are accepted by their respective release paths.
- Immediate per-request nearby email is retired. Nearby matches use the private
in-app inbox and optional push; the settings UI states that an email digest is
not enabled. Support contact verification enqueues one operator alert only
after the address is verified. Requester email is limited to the first staff
response or a later public-status change, while authenticated requesters also
receive an in-app support update. Ordinary requester and staff conversation
messages do not each generate email.
- Optional support email runs through the dedicated Oban `mail` queue, whose
default concurrency is one per worker. Fixed-purpose delivery telemetry
records only the allow-listed purpose and outcome, without email addresses or
message content. Authentication and content-removal confirmations remain
transactional email paths by design.
- Exact-name inspection after completion found no container or temporary image
belonging to quality scope `20260812133255-3403320` /
`wnh_quality_202608121332553403320`.
- This was local verification only. It did not deploy production, modify the
frozen hackathon-test checkout, change shared Caddy, save Google Play Console
fields, or push the public Git remote.
## Current local quality and dependency-security proof on 2026-08-10
- The complete isolated `scripts/quality.sh` pipeline passed in user-systemd