Production-readiness pass before the demo: stable Python, real lint/CI, plain failures, honest docs - #2
Merged
Conversation
.python-version pointed at 3.14 (a release candidate). With the locked pydantic, FastAPI fails to import there, so `patchowner serve` crashes and one test fails on a fresh checkout. Pin 3.12, which CLAUDE.md and requires-python already assume; 3.13 passes too. CLAUDE.md and the repo hook both call `uv run ruff`, but ruff was not a dependency, so the hook failed on every edit. Add ruff to the dev group with an explicit config in pyproject.toml, run check --fix and format once across the codebase, and replace the hook command (which relied on an empty CLAUDE_FILE_PATHS variable) with a small script that reads the edited path from the hook's stdin JSON. Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_012ZCSLekTvZQ7X3PsAUJuXk
…ape report data - kev.load_feed raises FeedError with a sentence for the person running the tool instead of a raw URLError or JSONDecodeError. A failed or non-JSON download never overwrites an existing cache. The CLI prints it and exits 3; the web form shows it in place of a 500. - /replay refuses uploads over 5 MB before parsing, checks the look-back range, and shows every error as escaped text. /act bounds field sizes. - Policy.parse reports short rows and non-numeric row numbers as PolicyError rather than IndexError/ValueError. - The client-data JSON embedded in the report's <script> tag now escapes <, > and &, so an asset name or advisory text containing "</script>" cannot end the tag. Tests cover each of these. Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_012ZCSLekTvZQ7X3PsAUJuXk
…ibe the real stack db/models.py and db/sesion.py are SQLAlchemy models for a hosted multi-tenant version that does not exist yet. Nothing imports them and their dependencies are not installed, while the README says multi-tenant views are deliberately not here. Keep the sketch, but under docs/design/db with a README that says exactly what it is and is not. CLAUDE.md described PostgreSQL, Alembic, Row-Level Security and a continuous KEV sync, and pointed at rules files that do not exist. Rewrite it around what the code actually does, keep the transparency and disclaimer rules explicit, and list planned work as planned. The security-auditor subagent now reviews the surfaces that exist. Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_012ZCSLekTvZQ7X3PsAUJuXk
GitHub Actions runs ruff and pytest on Python 3.12 and 3.13 for every push and pull request; the four tests that need the live KEV feed skip there so results do not depend on CISA's servers. README gets the badge, the real test count (101, four skipped without the cached feed), the supported Python versions, and layout entries for site/ and the design sketch. SECURITY.md says what the tool does and does not do and how to report a problem in it. Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_012ZCSLekTvZQ7X3PsAUJuXk
|
The latest updates on your projects. Learn more about Vercel for GitHub.
|
e-allora
marked this pull request as ready for review
October 2, 2026 14:28
This branch was successfully deployed
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
What this fixes
An audit of the repo and the deployed site (
site/index.htmlis what Vercel serves) ahead of the demo video. The site copy, disclaimers, and About tab were already accurate; the gaps were in the repo's own plumbing and in a few places where the repo said more than the code does.Breaks on a fresh checkout
.python-versionpinned3.14(a release candidate). FastAPI fails to import there with the locked pydantic, sopatchowner servecrashes andtests/test_state.py::test_web_act_endpoint_records_and_rejectsfails. Pinned to 3.12 (what CLAUDE.md andrequires-pythonalready assumed). CI runs 3.12 and 3.13.uv run ruff, but ruff was not a dependency, and the hook read an emptyCLAUDE_FILE_PATHSvariable. Ruff is now a dev dependency with explicit config, the codebase is formatted once, and the hook is a small script that reads the edited path from stdin.Failures that were tracebacks
URLError(HTTP 500 in serve mode). It is now aFeedErrorwith one sentence for the person running the tool. The CLI exits 3; the web form shows the sentence. A bad download never overwrites an existing cache./replayrefuses uploads over 5 MB before parsing, validates the look-back range, and escapes every error message./actbounds field lengths.Policy.parsereports short rows and non-numeric row numbers asPolicyError.One real escaping gap
<script>tag with|safe. An asset name or advisory text containing</script>could end the tag. The JSON now escapes<,>and&; a test renders a hostile inventory and asserts the page still has exactly its own three script tags.Repo said more than the code does
db/models.pyanddb/sesion.pywere SQLAlchemy models for a hosted multi-tenant version: unused, undeclared dependencies, and contradicting the README's "deliberately not here yet". Moved todocs/design/db/with a README that says exactly what they are.site/and the design sketch added to the layout, CI badge.New
.github/workflows/ci.yml: ruff + pytest on 3.12 and 3.13, plus a CLI smoke test. The four tests that replay the live catalog skip in CI so results never depend on CISA's servers.SECURITY.md.Not changed, and why
site/index.htmlis untouched. It is a build artifact and the template logic did not change in a way that alters the rendered page. This sandbox cannot reach cisa.gov, so I could not refresh the demo report to today's catalog version. If you want the Health tab to show a current date on camera, runuv run patchowner replay examples/inventory.csv --refresh && cp out/report.html site/index.htmllocally and push; everything else on the page already states its snapshot date.Verification
🤖 Generated with Claude Code
https://claude.ai/code/session_012ZCSLekTvZQ7X3PsAUJuXk
Generated by Claude Code