Skip to content

chore: client release assets, deploy var guard, import fixes - #11

Merged
danieltruong merged 2 commits into
mainfrom
chore/client-provenance
Sep 7, 2026
Merged

danieltruong merged 2 commits into
mainfrom
chore/client-provenance

Conversation

@danieltruong

Copy link
Copy Markdown
Collaborator
  • publish-client.yaml attaches the packed tarball and SHA256SUMS to the
    GitHub release for each client-v* tag so vendored copies can be traced
    to a build; client/README.md documents how consumers vendor and verify.
  • deploy-infra.sh refuses required values containing whitespace or a
    literal backslash-n; one such value put a 66-char header into the test
    Function while APIM held the 64-char value, and every gateway route
    answered 401.
  • import-penguin-history.js: push rows in a loop (spread overflowed the
    stack at 330k rows), map penguin event names to the client's names,
    and import only names the products emit; penguin stored free-text
    event names and 148 of 178 distinct prod values were injection
    payloads.
  • Direct unit tests for src/auth/origin.js and src/auth/safe-equal.js.

- publish-client.yaml attaches the packed tarball and SHA256SUMS to the
  GitHub release for each client-v* tag so vendored copies can be traced
  to a build; client/README.md documents how consumers vendor and verify.
- deploy-infra.sh refuses required values containing whitespace or a
  literal backslash-n; one such value put a 66-char header into the test
  Function while APIM held the 64-char value, and every gateway route
  answered 401.
- import-penguin-history.js: push rows in a loop (spread overflowed the
  stack at 330k rows), map penguin event names to the client's names,
  and import only names the products emit; penguin stored free-text
  event names and 148 of 178 distinct prod values were injection
  payloads.
- Direct unit tests for src/auth/origin.js and src/auth/safe-equal.js.
@danieltruong
danieltruong merged commit e8bbe75 into main Sep 7, 2026
3 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant