Skip to content

J1-PIPELINE: arah audit, security hardening, and documentation fixes - #3

Open
OneByJorah wants to merge 10 commits into
masterfrom
publish/20260705
Open

J1-PIPELINE: arah audit, security hardening, and documentation fixes#3
OneByJorah wants to merge 10 commits into
masterfrom
publish/20260705

Conversation

@OneByJorah

Copy link
Copy Markdown
Owner

J1-PIPELINE Phase 14 (PUBLISHER) — arah

This PR bundles all pending local changes for arah after the ORACLE audit, security hardening, and documentation fixes.

Changes included

  • docs(oracle): Add INTENT.md — J1-PIPELINE ORACLE phase intent reconstruction
  • Previous commits (already pushed): security hardening (hardcoded IP/secret key/email redaction, CodeQL config fix), docs alignment (README, MAINTENANCE.md), CI fixes, ruff auto-fixes, and more

Branch

publish/20260705

Merge settings

  • AUTO_MERGE: false (manual review required)

J1-PIPELINE added 10 commits July 5, 2026 20:54
…ig generation

Replace hardcoded 100.66.142.21 with SERVER_IP env var (defaults to
same value for backward compatibility) in setup-wizard.sh and
apply-setup.sh. This allows users to configure their own Tailscale IP
and avoids leaking private network topology in source code.
Replace hardcoded /workspace, /cloudflared, and /home/j1admin/.cloudflared/
paths with env-var-based defaults (REPO_ROOT, CF_DIR, CLOUDFLARED_HOME,
SERVER_IP). This makes the web setup API functional outside of devcontainer
environments and avoids leaking private network topology.
…ndabot pip directory, fix smoke test paths, fix MAINTENANCE.md

- README: Replace reference to non-existent ci-cd.yml with actual codeql.yml
- README: Comment out non-existent screenshot references
- Dependabot: Fix pip directory from '/' to '/noc-dashboard/backend'
- Smoke test: Replace hardcoded /home/j1admin/StackDeploy with script-relative paths
- MAINTENANCE.md: Replace llama-server reference with docker compose pull
Remove healthcheck.sh.patched and docker-compose.headroom.yml.patched
which are artifacts of a previous patching process and no longer needed.
Replace hardcoded 'stackdeploy-searxng' secret key in searxng/settings.yml
with a placeholder and add SEARXNG_SECRET_KEY env var to docker-compose.yml.
Document the new variable in README environment variables table.
No .ts or .tsx files exist in the repo. TypeScript was a template
vestige that would cause an unnecessary CodeQL analysis pass.
Prevent pipeline-generated reports from appearing as untracked files.
…ternal references

- Updated git remote from OneByJorah/arah to OneByJorah/AutoStack
- Updated INTENT.md: all 'arah' references → 'AutoStack', resolved naming discrepancy note
- Updated live-manifest.json: repo name, URL, tunnel hostname
- Updated noc-dashboard/templates/setup.html: title, heading, placeholders
- Updated docs/SETUP_WIZARD.md: description and Cloudflare URL
- Updated scripts/setup-wizard.sh and scripts/apply-setup.sh: echo text
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant