chore(deps): bump actions/checkout from 4 to 7#2
Merged
Conversation
There was a problem hiding this comment.
Claude Code Review
This repository is configured for manual code reviews. Comment @claude review to trigger a review and subscribe this PR to future pushes, or @claude review once for a one-time review.
Tip: disable this comment in your organization's Code Review settings.
fbfeef7 to
cab916c
Compare
cortexuvula
added a commit
that referenced
this pull request
Jun 20, 2026
…y, lock scoping) Addresses 9 findings from the codebase bug audit: Critical: - #1 Onboarding bypass: gate on a separate onboarding_started sentinel (written by the wizard on first save) instead of inferring from app_config row existence. An interrupted wizard now reappears on next launch instead of being silently auto-marked complete. Adds set_onboarding_started command + API wrapper. - #2 Ollama/LM Studio deadlock: current_base_url cloned the endpoint out of the read guard and dropped it before locking the url_cache, fixing the AB-BA lock-ordering inversion with set_endpoint. PHI leaks (AGENTS.md line 6): - #3 vocabulary.rs: drop find_text from the 'entry added' log. - #4 whisper_supervisor: allowlist stderr to known-safe diagnostic prefixes; drop arbitrary lines (whisper.cpp can emit recognized text). - #6 peer_discussion.rs: drop physician_name/specialty from the log. Security: - #5 Endpoint-policy: validate_local_endpoint at the top of every test/probe command (probe_endpoint_reachable, test_lmstudio_connection, test_stt_remote_connection, test_ollama_connection) so a crafted payload can't reach a public host. Robustness: - #7 start_with_gate: separate 'starting' guard so status()/watcher don't freeze during the multi-second gate; clean up the whisper child on any error path after it started; stop() clears starting too. - #8 start_sharing_inner: bind ports + start whisper BEFORE taking the sharing write lock; only hold the lock for the assignment; stop the service on any error after start. - #9 SSE malformed-event: propagate as a stream error instead of silent drop, so a truncated SOAP note surfaces visibly.
Owner
|
@dependabot rebase |
Bumps [actions/checkout](https://github.com/actions/checkout) from 4 to 7. - [Release notes](https://github.com/actions/checkout/releases) - [Changelog](https://github.com/actions/checkout/blob/main/CHANGELOG.md) - [Commits](actions/checkout@v4...v7) --- updated-dependencies: - dependency-name: actions/checkout dependency-version: '6' dependency-type: direct:production update-type: version-update:semver-major ... Signed-off-by: dependabot[bot] <support@github.com>
cab916c to
9d6f202
Compare
cortexuvula
added a commit
that referenced
this pull request
Jun 27, 2026
… removal Fixes all 7 privacy/security findings from the application review, plus 10 review bugs found in the initial implementation. Privacy fixes: - P1: Audio recordings now encrypted at rest (AES-256-GCM, key derived from the keychain DB key via SHA-256). New medical-security::file_crypto module. WAVs encrypt on capture-finalize; decrypt transparently on transcription load and audio-levels check. Atomic temp+rename prevents data loss on crash. - P2: Silent plaintext-DB fallback eliminated. The 4 keychain/encryption- failure arms now return InitError::EncryptionUnavailable (surfaced as a recovery screen) instead of silently opening unencrypted. Fresh-install with no data still proceeds plaintext (nothing to protect yet). - P3: Orphaned transcripts now encrypted (.enc) via the same file_crypto helper. Falls back to .txt only if keychain unavailable. - P4: Removed dead ElevenLabs cloud TTS provider (AGENTS.md hosted-AI violation). Default TTS is now "local"; settings migration rewrites stale "elevenlabs" configs via a positive SUPPORTED_TTS_PROVIDERS list. - P5: Webview CSP enabled (was null). default-src 'self', inline styles allowed (Svelte), IPC + asset protocols permitted, no external origins. - P6: PHI-adjacent names redacted from logs. RAG ingestion logs entity_type + name_len; template/audience logs use name_len instead of raw names. - P7: save_recording_field now enforces per-field 500K char cap. Guard test ensures every EDITABLE_FIELDS entry has an explicit cap. Review-bug fixes (found in self-review): - Bug #1: unwrap_or_default() could destroy recordings on I/O failure -> new encrypt_file_in_place propagates read errors + is atomic. - Bug #2: compute_audio_levels didn't decrypt -> shared open_recording_wav helper now used by both load + audio-levels paths. - Bug #3: import_audio_file never encrypted -> now uses encrypt_file_in_place. - Bug #4: encrypt_file non-atomic -> temp+fsync+rename. - Bug #10: CSP missing asset: in connect-src -> added. - Bug #5: Doc said HKDF but impl is plain SHA-256 -> corrected. - Bug #8: TTS migration != "none" was dead -> positive allowlist. - Bug #9: max_chars_for_field _ fallback -> guard test added. - Bug #11: decrypt_bytes untested on truncated/malformed input -> tests added. Verified: cargo test --workspace --lib (14 crates), clippy --all-targets -D warnings (0), fmt clean, vitest (355), svelte-check (0 errors).
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Bumps actions/checkout from 4 to 7.
Release notes
Sourced from actions/checkout's releases.
... (truncated)
Changelog
Sourced from actions/checkout's changelog.
... (truncated)
Commits
9c091bbupdate error wording (#2467)1044a6dgetting ready for checkout v7 release (#2464)f028218Bump the minor-npm-dependencies group across 1 directory with 3 updates (#2462)d914b26upgrade module to esm and update dependencies (#2463)537c7efBump@actions/coreand@actions/tool-cacheand Remove uuid (#2459)130a169Bump js-yaml from 4.1.0 to 4.2.0 (#2461)7d09575Bump flatted from 3.3.1 to 3.4.2 (#2460)0f9f3aaBump actions/publish-immutable-action (#2458)f9e715ablock checking out fork pr for pull_request_target and workflow_run (#2454)df4cb1cUpdate changelog for v6.0.3 (#2446)