Repository navigation
Reconcile PointUp overhaul and prepare semantic AWS releases - #55
Merged
Merged
Conversation
jckail
marked this pull request as ready for review
October 6, 2026 20:24
There was a problem hiding this comment.
Cursor Bugbot has reviewed your changes using default effort and found 1 potential issue.
❌ Bugbot Autofix is OFF. To automatically fix reported issues with cloud agents, have a team admin enable autofix in the Cursor dashboard.
Reviewed by Cursor Bugbot for commit 7d5da63. Configure here.
| const changelog = readFileSync(resolve(cwd, 'CHANGELOG.md'), 'utf8'); | ||
| const sections = changelog.split(/(?=^## )/m); | ||
| const section = sections.find(value => value.startsWith(`## [${version}]`)); | ||
| assert(section && section.trim().split('\n').length > 2, `CHANGELOG.md needs a substantive [${version}] entry`); |
There was a problem hiding this comment.
Release notes match version prefixes
Medium Severity
notes() selects a changelog section with startsWith('## [${version}]'), so a later heading such as ## [1.0.10] matches a lookup for 1.0.1. Newest-first changelogs make that the first hit, and the GitHub release can publish the wrong notes.
Reviewed by Cursor Bugbot for commit 7d5da63. Configure here.
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.


PointUp's recent work is spread across legacy scaffolds, a preserved alternate migration history and nine integration commits beyond master. This change adopts the current TypeScript/Drizzle integration lineage and adds secure release preparation, while preserving the alternate history for recovery.
The dashboard separates its summary from program categories, fits mobile viewports, uses jordan@quarg.io for contact and displays the configured runtime MCP endpoint. Bot callbacks use literal HTTPS authorities and path-only input without redirects. AWS configuration uses scoped Clerk Secrets Manager imports, a public-only build loader and a tested POSIX stdin bridge. Optional Supabase wiring separates application and session migration connections; migration 0023 permits the restricted server role while keeping unrelated API roles denied. Kubernetes remains inactive preparation. Stable version checks and tag-driven source releases reuse full CI and publish exact-commit receipts.
Validation: head 7d5da63 passed all hosted CI jobs in run 37525556115, CodeQL workflow 37525556118 and the separate CodeQL PR security check. Earlier aggregate local verification passed 2,020 workspace tests, lint/types, production bundles, 46 deployment/release contracts, 33 infrastructure contracts and Docker/PgBouncer API/MCP smoke. Additional focused callback tests passed 55; the service-role regression passed. All 24 Drizzle migrations applied under a restricted migrator on PostgreSQL 17.6, with 24 journal rows and 19 scoped policies verified. Chrome verified local demo sync, consent/token revocation and desktop/mobile rendering. The application production lock audit reports zero vulnerabilities; the AWS CDK bundled brace-expansion high finding remains upstream and is explicitly recorded.
AWS activation, genuine production Clerk authentication, database credentials, legacy data migration and tested recovery, semantic tag publication and provider/model acceptance remain open. Supabase project creation and a completed legacy disk snapshot do not prove cutover acceptance. This source integration supersedes #54 and tracks JCK-333, retaining the separate JCK-128/JCK-234 acceptance scopes. The user-requested deep product/documentation overhaul continues separately.
Note
High Risk
Changes span deploy configuration (Clerk/database secret wiring), bot outbound callback security, and broad CI/release gates; mistakes could block deployments or affect authentication and deferred bot replies.
Overview
This PR wires semantic versioning and tag-driven source releases (
release.yml,CHANGELOG.md,scripts/release/version.mjs) into CI, broadens deployment script tests, and shifts production Clerk identity from a GitHub secret publishable key to an approved Secrets Manager ARN loaded at deploy time.The bot is refactored into
createBotServerwith bounded request bodies and safer error handling; Slack/Discord deferred replies use fixed HTTPS authorities viasendCallback(no redirects, no credential-bearing logs), with large transport and HTTP-boundary test suites.Web/dashboard changes return structured sync success/failure messages through
SyncBalanceForm, validate consent duration 1–90 days on grant, improve agents panel capture timestamps, accessibility, and post-revoke feedback, split dashboard stat layout for mobile, add footer contact, and preferPUBLIC_MCP_URLfor MCP display. The assistant path re-enforces private OpenAI SDK logging on every run.Supporting updates include inactive Kubernetes manifests and docs, reconciliation/release verification notes, and minor Next env typing.
Reviewed by Cursor Bugbot for commit 7d5da63. Bugbot is set up for automated code reviews on this repo. Configure here.