J1-PIPELINE: arah audit, security hardening, and documentation fixes - #3
Open
OneByJorah wants to merge 10 commits into
Open
J1-PIPELINE: arah audit, security hardening, and documentation fixes#3OneByJorah wants to merge 10 commits into
OneByJorah wants to merge 10 commits into
Conversation
added 10 commits
July 5, 2026 20:54
…ig generation Replace hardcoded 100.66.142.21 with SERVER_IP env var (defaults to same value for backward compatibility) in setup-wizard.sh and apply-setup.sh. This allows users to configure their own Tailscale IP and avoids leaking private network topology in source code.
Replace hardcoded /workspace, /cloudflared, and /home/j1admin/.cloudflared/ paths with env-var-based defaults (REPO_ROOT, CF_DIR, CLOUDFLARED_HOME, SERVER_IP). This makes the web setup API functional outside of devcontainer environments and avoids leaking private network topology.
…ndabot pip directory, fix smoke test paths, fix MAINTENANCE.md - README: Replace reference to non-existent ci-cd.yml with actual codeql.yml - README: Comment out non-existent screenshot references - Dependabot: Fix pip directory from '/' to '/noc-dashboard/backend' - Smoke test: Replace hardcoded /home/j1admin/StackDeploy with script-relative paths - MAINTENANCE.md: Replace llama-server reference with docker compose pull
Remove healthcheck.sh.patched and docker-compose.headroom.yml.patched which are artifacts of a previous patching process and no longer needed.
Replace hardcoded 'stackdeploy-searxng' secret key in searxng/settings.yml with a placeholder and add SEARXNG_SECRET_KEY env var to docker-compose.yml. Document the new variable in README environment variables table.
No .ts or .tsx files exist in the repo. TypeScript was a template vestige that would cause an unnecessary CodeQL analysis pass.
Prevent pipeline-generated reports from appearing as untracked files.
…ternal references - Updated git remote from OneByJorah/arah to OneByJorah/AutoStack - Updated INTENT.md: all 'arah' references → 'AutoStack', resolved naming discrepancy note - Updated live-manifest.json: repo name, URL, tunnel hostname - Updated noc-dashboard/templates/setup.html: title, heading, placeholders - Updated docs/SETUP_WIZARD.md: description and Cloudflare URL - Updated scripts/setup-wizard.sh and scripts/apply-setup.sh: echo text
…s, scripts, and dashboard
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
J1-PIPELINE Phase 14 (PUBLISHER) — arah
This PR bundles all pending local changes for arah after the ORACLE audit, security hardening, and documentation fixes.
Changes included
Branch
publish/20260705Merge settings
false(manual review required)