Skip to content

audit fixes (P12): record the seven follow-ups the remediation programme surfaced - #2635

Merged
BigSimmo merged 2 commits into
mainfrom
claude/audit-fix-p12
Sep 5, 2026
Merged

audit fixes (P12): record the seven follow-ups the remediation programme surfaced#2635
BigSimmo merged 2 commits into
mainfrom
claude/audit-fix-p12

Conversation

@BigSimmo

@BigSimmo BigSimmo commented Sep 4, 2026

Copy link
Copy Markdown
Owner

Summary

Audit remediation package P12 — Ledger housekeeping, the package designed to land last. It carries no audit findings of its own; it records what the other twenty packages found and could not close.

Seven requests, queued through npm run issues:add only. docs/outstanding-issues.md is not touched — these apply on the next npm run issues:reconcile.

The one that is P1

Caring Contacts message-content controls are unreachable. grep -rn "validateGovernedMessage" src worker scripts returns only message-copy.ts and the module itself. Every message-content policy control documented in docs/caring-contacts/message-review-pack.md (added by PR #2626, now merged) is therefore proof about a function, not about a delivered message. Nothing is being sent today, so there is no present risk — but it should be read as blocking for a real-patient pilot, alongside the three unmitigated hazards #1S81R8 already names.

The six at P2

RAG impact: none

Verification

  • npm run check:ledger-write-disciplineledger write discipline self-test passed. / Ledger write discipline passed for 02a82b2f6951..HEAD.
  • npm run check:outstanding-issues[snapshot] in step with data/outstanding-issues-snapshot.json (73 open, 0 pending)
  • Every request was created by npm run issues:add. No table row was hand-edited, no existing request changed, no request deleted.

Verification not run: npm run verify:pr-local — this package adds only append-only inbox request files and touches no source, test, workflow or generated file. The two gates above are the ones that govern this change; the heavy gate is left to CI.
Verification not run: npm run verify:ui, npm run verify:release, and every provider-backed gate.

Risk and rollout

  • Risk: low. Seven new append-only JSON files under docs/outstanding-issues-inbox/. No code, no schema, no generated artefact.
  • Rollback: revert this PR's single commit; the requests vanish and the canonical ledger is unchanged either way, because nothing has been reconciled yet.
  • Provider or production effects: None.
  • RAG impact: none
  • Follow-up required after merge: npm run issues:reconcile from a fresh-base branch, which is the only sanctioned way these reach docs/outstanding-issues.md.

Clinical Governance Preflight

  • Source-backed claims still require linked source verification before clinical use
    unchanged; this package records findings and alters no clinical behaviour.
  • No patient-identifiable document workflow was introduced or expanded without explicit governance approval
    none introduced or expanded.
  • Supabase target remains Clinical KB Database (sjrfecxgysukkwxsowpy)
    unchanged; nothing under supabase/ is touched.
  • Service-role keys and private document access remain server-only
    unchanged.
  • Demo/synthetic content remains clearly separated from real clinical sources
    reinforced — one of the recorded findings is precisely that a mockup's invented phone numbers may fall outside the range reserved for fiction.
  • Source metadata, review status, and outdated/unknown-source behavior remain conservative
    unchanged.
  • Deployment classification/TGA SaMD impact was checked when clinical decision-support behavior changed
    reviewed; ledger records only, no decision-support behaviour added.

🤖 Generated with Claude Code

https://claude.ai/code/session_01DHSyfuC6mS98ystWFiitAR


Generated by Claude Code


Note

Low Risk
Append-only documentation queue JSON with no runtime, schema, or dependency changes; canonical ledger updates happen only after reconcile.

Overview
Audit remediation P12 (ledger housekeeping) appends seven version-2 add requests under docs/outstanding-issues-inbox/. It does not change docs/outstanding-issues.md or application code; those entries apply only after a later npm run issues:reconcile.

The queued items capture open work from the 2026-09-02 audit programme: one P1 issue that validateGovernedMessage has no production caller (Caring Contacts policy is not enforced on real sends), plus six P2 items covering patient-plan mockup phone numbers outside the fiction range, crisis-line verification cadence and missing number provenance, blocking npm audit advisories on main, deferred audit findings (ownership/tooling), CSRF Origin check browser coverage, and Supabase types regenerated from schema.sql with drift-escape removals.

Reviewed by Cursor Bugbot for commit b336b85. Configure here.

Queued through npm run issues:add only; docs/outstanding-issues.md itself is
untouched, and these apply on the next npm run issues:reconcile.

P1: Caring Contacts validateGovernedMessage has no production caller, so every
message-content control the new review pack documents is proof about a function
rather than about a delivered message - blocking for a real-patient pilot.

P2: patient-plan mockup prints invented mobiles above the fiction-reserved block
and the range test cannot see them; the crisis-line re-verification cadence is
six months in the new record and twelve in the audit, and the Lifeline and 13YARN
numbers carry no source or verification date at all; two high production
advisories on main make the dependency audit blocking for any PR touching
package.json; the deferred audit findings and what unblocks each; P15's CSRF
Origin check has unit coverage only while its browser suite is red; and P20's
regenerated Supabase types came from schema.sql rather than the live database
with the escapes that hid drift now removed.

Verified: check:outstanding-issues in step (73 open, 0 pending).

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01DHSyfuC6mS98ystWFiitAR
@coderabbitai

coderabbitai Bot commented Sep 4, 2026

Copy link
Copy Markdown
Contributor

Important

  • 🔍 Trigger review

This repository does not receive automatic reviews because it has fewer than 10 stars.

⚙️ Run configuration

Configuration used: Path: .coderabbit.yaml

Review profile: CHILL

Plan: Team

Run ID: 95a0d23d-f8e0-457e-85f3-d0d53b801a99


Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

@supabase

supabase Bot commented Sep 4, 2026

Copy link
Copy Markdown

This pull request has been ignored for the connected project sjrfecxgysukkwxsowpy because there are no changes detected in supabase directory. You can change this behaviour in Project Integrations Settings ↗︎.


Preview Branches by Supabase.
Learn more about Supabase Branching ↗︎.

@BigSimmo
BigSimmo marked this pull request as ready for review September 5, 2026 12:19
@chatgpt-codex-connector

Copy link
Copy Markdown

You have reached your Codex usage limits for code reviews. You can see your limits in the Codex usage dashboard.
To continue using code reviews, add credits to your account and enable them for code reviews in your settings.

@BigSimmo
BigSimmo enabled auto-merge (squash) September 5, 2026 12:19
@cursor

cursor Bot commented Sep 5, 2026

Copy link
Copy Markdown
Contributor

Bugbot couldn't run - usage limit reached

Bugbot is counted against Cursor usage for this user or team, and this run hit a usage or spend limit.

A user or team admin can review and increase usage limits in the Cursor dashboard.

(requestId: serverGenReqId_912108af-aa67-4d4b-b917-21d6ea141328)

@BigSimmo
BigSimmo merged commit 0a01ceb into main Sep 5, 2026
31 of 35 checks passed
@BigSimmo
BigSimmo deleted the claude/audit-fix-p12 branch September 5, 2026 12:21
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants