All releases
v2026-08-10
August 10, 2026
Patch
In this release
New1
Improved1
Fixed588
Total590

Fix: Netcup live-capacity gate net memory delta (deadlock on shrink+grow deploys)

Fix: Netcup live-capacity gate net memory delta (deadlock on shrink+grow deploys) Fix: phantom in-flight poisons repeat sync scrapes (85s hang + 504) Fix: validate ACTUAL_* replica counts through netcup_is_uint in live-capacity gate Fix: structure-queue :processing LIST periodic reaper + finally-wrapped acks Fix: _is_system_proxy misclassifies trailing-dot FQDN gateway hostname as BYOP

New Features

1

dedicated split-screen signin and signup pages

dedicated split-screen signin and signup pages

Improvements

1

cache mail provider Mail API OAuth token and folder ID across poll cycles

cache mail provider Mail API OAuth token and folder ID across poll cycles

Bug Fixes

588

Fix: Netcup live-capacity gate net memory delta (deadlock on shrink+grow deploys)

Fix: Netcup live-capacity gate net memory delta (deadlock on shrink+grow deploys)

Fix: phantom in-flight poisons repeat sync scrapes (85s hang + 504)

Fix: phantom in-flight poisons repeat sync scrapes (85s hang + 504)

Fix: validate ACTUAL_* replica counts through netcup_is_uint in live-capacity gate

Fix: validate ACTUAL_* replica counts through netcup_is_uint in live-capacity gate

Fix: structure-queue :processing LIST periodic reaper + finally-wrapped acks

Fix: structure-queue :processing LIST periodic reaper + finally-wrapped acks

Fix: _is_system_proxy misclassifies trailing-dot FQDN gateway hostname as BYOP

Fix: _is_system_proxy misclassifies trailing-dot FQDN gateway hostname as BYOP

Fix: document LIST reaper claimed-at hash invariant (review finding — )

Fix: document LIST reaper claimed-at hash invariant (review finding — )

Fix: sitemap advertises ~84 dead /docs-md/* URLs (404s)

Fix: sitemap advertises ~84 dead /docs-md/* URLs (404s)

Fix: exclude thin blog categories from sitemap to match noindex gate

Fix: exclude thin blog categories from sitemap to match noindex gate

Fix: clamp PROCESSING_REAPER_INTERVAL_S to a minimum

Fix: clamp PROCESSING_REAPER_INTERVAL_S to a minimum

Fix: release slot when resolve_extraction_route raises 400

Fix: release slot when resolve_extraction_route raises 400

Fix: remove dead cloud provider worker monitoring scrape jobs

Fix: remove dead cloud provider worker monitoring scrape jobs

Fix: auto-recharge invoices inaccessible in billing Receipts card

Fix: auto-recharge invoices inaccessible in billing Receipts card

Fix: add tier-policy escalation gate observability metric

Fix: add tier-policy escalation gate observability metric

Fix: AI engine Experiment stable created_at anchors retention window

Fix: AI engine Experiment stable created_at anchors retention window

Fix: escalation heuristics fire on byte-count/generic-exceptions without proven detection

Fix: escalation heuristics fire on byte-count/generic-exceptions without proven detection

Fix: enforce IP blacklist in rotating proxy mode

Fix: enforce IP blacklist in rotating proxy mode

Fix: let well-sampled tier evidence override authoritative min_tier floor

Fix: let well-sampled tier evidence override authoritative min_tier floor

Fix: route content-quality T3->T4 escalations through is_escalation_permitted

Fix: route content-quality T3->T4 escalations through is_escalation_permitted

Fix: remove customer-facing domain_not_supported dead-end in worker

Fix: remove customer-facing domain_not_supported dead-end in worker

Fix: route 3 worker fallback/race header merges through merge_headers_in_order

Fix: route 3 worker fallback/race header merges through merge_headers_in_order

capture CB-trip baseline in JobQueue.__init__ not lazily

capture CB-trip baseline in JobQueue.__init__ not lazily

Fix: reload monitoring config on normal full deploy

Fix: reload monitoring config on normal full deploy

Fix: rate-limit gate honors precise wait_ms instead of flat 5s requeue ceiling

Fix: rate-limit gate honors precise wait_ms instead of flat 5s requeue ceiling

Fix: proxy_provided debug log reports mode=rotating after an IP-blacklist reroll

Fix: proxy_provided debug log reports mode=rotating after an IP-blacklist reroll

avoid redundant is_domain_well_sampled cache round-trip

avoid redundant is_domain_well_sampled cache round-trip

Fix: fail closed on TLS parser breakage in chrome-upgrade-safety-gate

Fix: fail closed on TLS parser breakage in chrome-upgrade-safety-gate

Fix: auto-recharge falls back to amount+date when PaymentIntent ID is null

Fix: auto-recharge falls back to amount+date when PaymentIntent ID is null

Fix: headed semaphore slot stays reserved during bundled fallback in CF solver

Fix: headed semaphore slot stays reserved during bundled fallback in CF solver

Fix: normalize chrome136 JA3 field order before TLS drift comparison

Fix: normalize chrome136 JA3 field order before TLS drift comparison

Fix: bounded re-verification loop for IP-blacklist reroll (both sticky and rotating branches)

Fix: bounded re-verification loop for IP-blacklist reroll (both sticky and rotating branches)

Fix: wrap CIRCUIT_BREAKER_TRIPS_TOTAL._value.get behind a stable helper + pin with a test

Fix: wrap CIRCUIT_BREAKER_TRIPS_TOTAL._value.get behind a stable helper + pin with a test

Fix: DomainRateLimiter uses cache TIME instead of client-supplied now_ms (clock-drift hardening)

Fix: DomainRateLimiter uses cache TIME instead of client-supplied now_ms (clock-drift hardening)

Fix: agent ticket-list status filter uses non-existent 'waiting_on_customer'

Fix: agent ticket-list status filter uses non-existent 'waiting_on_customer'

Fix: restore RATE_LIMITED_RETRY_DELAY_SECONDS=0 kill switch (fallthrough into escalation delay)

Fix: restore RATE_LIMITED_RETRY_DELAY_SECONDS=0 kill switch (fallthrough into escalation delay)

Fix: agent_list_tickets status filter omits 'merged'

Fix: agent_list_tickets status filter omits 'merged'

Fix: proxy_provided log still reports mode=rotating for sticky-session domain-blacklist rotations

Fix: proxy_provided log still reports mode=rotating for sticky-session domain-blacklist rotations

Fix: TLS JA3 normalization sorts cipher field too, widening drift blind spot

Fix: TLS JA3 normalization sorts cipher field too, widening drift blind spot

correct stale fail-open docstring on verify_admin_api_key_rate_limited

correct stale fail-open docstring on verify_admin_api_key_rate_limited

Fix: cancellation of unregister_headed_solve can inflate soft in-flight counter

Fix: cancellation of unregister_headed_solve can inflate soft in-flight counter

Fix: escalate doctype-bearing empty-body shells in content_validator

Fix: escalate doctype-bearing empty-body shells in content_validator

Fix: whitespace-only agent note creates blank TicketReply

Fix: whitespace-only agent note creates blank TicketReply

Fix: headed-fallback metrics .inc exception swallow

Fix: headed-fallback metrics .inc exception swallow

Fix: record tier-3 success on content-quality escalation-denied path at T3

Fix: record tier-3 success on content-quality escalation-denied path at T3

Fix: second independent cancellation inside release's manager-unregister await still leaks the counter

Fix: second independent cancellation inside release's manager-unregister await still leaks the counter

Fix: agent triage/ticket-update tags field has no max-items bound

Fix: agent triage/ticket-update tags field has no max-items bound

Fix: ALT-XXXX ref int parse can overflow Postgres int4 (500 instead of 400)

Fix: ALT-XXXX ref int parse can overflow Postgres int4 (500 instead of 400)

Fix: agent-merge audit note commits in same transaction as merge

Fix: agent-merge audit note commits in same transaction as merge

Fix: _perform_ticket_merge mandatory_note guard uses truthy check instead of is-not-None

Fix: _perform_ticket_merge mandatory_note guard uses truthy check instead of is-not-None

Fix: browser_pool_exhausted retries force-pinned to T4 instead of de-escalating to T3

Fix: browser_pool_exhausted retries force-pinned to T4 instead of de-escalating to T3

Fix: pending unregister task not cleaned up on test assertion failure (review finding — )

Fix: pending unregister task not cleaned up on test assertion failure (review finding — )

Fix: narrow blanket except in leaked-task drain loop (review finding — )

Fix: narrow blanket except in leaked-task drain loop (review finding — )

Fix: set MALLOC_ARENA_MAX to cap glibc arena bloat on Netcup workers

Fix: set MALLOC_ARENA_MAX to cap glibc arena bloat on Netcup workers

Fix: internal service alert pipeline KeyError 'message' crashes alert_checks (83-92% failure)

Fix: internal service alert pipeline KeyError 'message' crashes alert_checks (83-92% failure)

Fix: orphan reaper SIGKILLs live Chrome child processes of pooled browsers

Fix: orphan reaper SIGKILLs live Chrome child processes of pooled browsers

Fix: authoritative configuration pins bypass browser-saturation downgrade guard

Fix: authoritative configuration pins bypass browser-saturation downgrade guard

Fix: jobs.tier_used mislabels browser_pool_exhausted as scraping tier

Fix: jobs.tier_used mislabels browser_pool_exhausted as scraping tier

Fix: orphan reaper dual-snapshot TOCTOU window (review finding — )

Fix: orphan reaper dual-snapshot TOCTOU window (review finding — )

Fix: batch of P3 reaper findings — orphan reaper

Fix: batch of P3 reaper findings — orphan reaper

Fix: Groq spend-cap reliability system doesn't trip on 402 (review finding — )

Fix: Groq spend-cap reliability system doesn't trip on 402 (review finding — )

Fix: type _pending_headed_unregister_tasks as set[asyncio.Task]

Fix: type _pending_headed_unregister_tasks as set[asyncio.Task]

recompute stale chrome136 TLS JA3 baseline

recompute stale chrome136 TLS JA3 baseline

Fix: truncate role_arn in ARN-shape error message

Fix: truncate role_arn in ARN-shape error message

Fix: Receipts amount+date Any fallback can hide a real charge

Fix: Receipts amount+date Any fallback can hide a real charge

Fix: truncate role_arn in STS-failure warning log

Fix: truncate role_arn in STS-failure warning log

Fix: demographic profiles never acquire a real NID, false-green verification, wasted video bandwidth

Fix: demographic profiles never acquire a real NID, false-green verification, wasted video bandwidth

Fix: advertiser details always return name=None — call ATC's own RPC instead of scraping SPA shell

Fix: advertiser details always return name=None — call ATC's own RPC instead of scraping SPA shell

Fix: unescaped $1 in ghost-project awk filter breaks Netcup skip guard

Fix: unescaped $1 in ghost-project awk filter breaks Netcup skip guard

Fix: batch P3 findings — initialization cookie allowlist

Fix: batch P3 findings — initialization cookie allowlist

Fix: unbounded exception logging in storage provider clients

Fix: unbounded exception logging in storage provider clients

Fix: unbounded scroll-simulation loop causes 300s TIMEOUT on tall/iframe-hosted pages

Fix: unbounded scroll-simulation loop causes 300s TIMEOUT on tall/iframe-hosted pages

Fix: decouple cloud provider smoke-tests/Cloudflare sync from Netcup-only staleness

Fix: decouple cloud provider smoke-tests/Cloudflare sync from Netcup-only staleness

Fix: scroll_simulation_complete log fires even on deadline-truncated scroll

Fix: scroll_simulation_complete log fires even on deadline-truncated scroll

Fix: batch P3 review findings on deploy-/hotfix-

Fix: batch P3 review findings on deploy-/hotfix-

Fix: deterministic tiebreak for majority-vote image selector

Fix: deterministic tiebreak for majority-vote image selector

Fix: test import + event-loop breakages blocking staging→main CI

Fix: test import + event-loop breakages blocking staging→main CI

Fix: worker b2b test poisons session event loop (224 failures)

Fix: worker b2b test poisons session event loop (224 failures)

Fix: shared/ — hardcode HTTP client profile literal instead of deriving from CHROME_VERSION

Fix: shared/ — hardcode HTTP client profile literal instead of deriving from CHROME_VERSION

Fix: empty-text refund fires on every default-format scrape

Fix: empty-text refund fires on every default-format scrape

Fix: PI-less receipt suppresses by array order — wrong recharge can vanish

Fix: PI-less receipt suppresses by array order — wrong recharge can vanish

Fix: /blog newsletter "Stay in the Loop" section clipped by sticky reveal footer

Fix: /blog newsletter "Stay in the Loop" section clipped by sticky reveal footer

Fix: correct formatter placement of shared.aws.arn imports (CI red on )

Fix: correct formatter placement of shared.aws.arn imports (CI red on )

Fix: stop suppressed invoices from hiding their paired recharge

Fix: stop suppressed invoices from hiding their paired recharge

Fix: mirror openapi-artifact negation into deploy-

Fix: mirror openapi-artifact negation into deploy-

Fix: RecursionError in structurer pool from bs4 object crossing ProcessPoolExecutor boundary

Fix: RecursionError in structurer pool from bs4 object crossing ProcessPoolExecutor boundary

Fix: redact secrets from container-ro inspect output

Fix: redact secrets from container-ro inspect output

Fix: structure-stage failures never refund the scrape debit

Fix: structure-stage failures never refund the scrape debit

Fix: extraction pool bs4 strip recurses into nested list/dict values

Fix: extraction pool bs4 strip recurses into nested list/dict values

Fix: monitor-shell exec N<>/dev/tcp read-write redirect guard bypass

Fix: monitor-shell exec N<>/dev/tcp read-write redirect guard bypass

Fix: structure_insufficient_credits early-return never refunds scrape debit

Fix: structure_insufficient_credits early-return never refunds scrape debit

Fix: container-ro inspect exit code reflects jq's status, not container's

Fix: container-ro inspect exit code reflects jq's status, not container's

Fix: container-ro redaction pattern misses bare CREDENTIALS-style var names

Fix: container-ro redaction pattern misses bare CREDENTIALS-style var names

Fix: migration 0288 number collision + CI guard for staging PRs

Fix: migration 0288 number collision + CI guard for staging PRs

Fix: black-format import block (review finding — )

Fix: black-format import block (review finding — )

Fix: check_t4_circuit_breaker docstring overstates recency of cache-backed data

Fix: check_t4_circuit_breaker docstring overstates recency of cache-backed data

Fix: resolve_t4_decision mislabels authority_source for byos_min_tier/deferred-resume/bot protection system-fallback/stats-override paths

Fix: resolve_t4_decision mislabels authority_source for byos_min_tier/deferred-resume/bot protection system-fallback/stats-override paths

Fix: classify connection-level proxy rejects as ip_reputation subtype (egress IP reputation, ALT-40)

Fix: classify connection-level proxy rejects as ip_reputation subtype (egress IP reputation, ALT-40)

Fix: _record_tier_success decay expiry parity with _record_tier_failure

Fix: _record_tier_success decay expiry parity with _record_tier_failure

Fix: precedence-table docstring order mismatch

Fix: precedence-table docstring order mismatch

Fix: stale precedence count and authority_source order

Fix: stale precedence count and authority_source order

Fix: rebalance billing page layout into actions row + full-width history stack

Fix: rebalance billing page layout into actions row + full-width history stack

Fix: has_billing_account optionality mismatch between Pydantic and TS (review finding — )

Fix: has_billing_account optionality mismatch between Pydantic and TS (review finding — )

make sync-ssh-guard.sh coverage check recursive

make sync-ssh-guard.sh coverage check recursive

Fix: dead hasReceipt conditionals in Receipts.tsx after (review finding)

Fix: dead hasReceipt conditionals in Receipts.tsx after (review finding)

Fix: sync-ssh-guard.sh coverage check silently excludes symlinks

Fix: sync-ssh-guard.sh coverage check silently excludes symlinks

Fix: validate Location header host in billing receipts redirect proxy

Fix: validate Location header host in billing receipts redirect proxy

Fix: appleboy/ssh-action Go-template --format leftover in hotfix- Verify deployment health step

Fix: appleboy/ssh-action Go-template --format leftover in hotfix- Verify deployment health step

observe find's exit status in sync-ssh-guard.sh coverage check

observe find's exit status in sync-ssh-guard.sh coverage check

Fix: billing identity fields can't be cleared once set (review finding — )

Fix: billing identity fields can't be cleared once set (review finding — )

Fix: sync-ssh-guard.sh mktemp failure now fails loudly

Fix: sync-ssh-guard.sh mktemp failure now fails loudly

Fix: add idempotency key to close Stripe customer creation race

Fix: add idempotency key to close Stripe customer creation race

Fix: loadBillingIdentity has no org-switch staleness guard

Fix: loadBillingIdentity has no org-switch staleness guard

Fix: tax-ID diff not atomic against mid-loop Stripe errors

Fix: tax-ID diff not atomic against mid-loop Stripe errors

Fix: account-reclaim never deletes attacker's Stripe Customer object

Fix: account-reclaim never deletes attacker's Stripe Customer object

Fix: billing identity form fields missing labels

Fix: billing identity form fields missing labels

Fix: Stripe error detail returned verbatim in billing identity 502 response

Fix: Stripe error detail returned verbatim in billing identity 502 response

Fix: billing identity fields flash stale org data pre-paint

Fix: billing identity fields flash stale org data pre-paint

Fix: billing identity docstring + narrow InvalidRequestError safe-branch

Fix: billing identity docstring + narrow InvalidRequestError safe-branch

Fix: staleness guard is check-then-act, not atomic

Fix: staleness guard is check-then-act, not atomic

Fix: _strip_bs4_recursive skips __slots__ when object also has __dict__

Fix: _strip_bs4_recursive skips __slots__ when object also has __dict__

Fix: install amcheck + arm btree-corruption detection for domain_analytics_pkey

Fix: install amcheck + arm btree-corruption detection for domain_analytics_pkey

Fix: reconcile bt_index_check probe timeouts in error-trigger.sh

Fix: reconcile bt_index_check probe timeouts in error-trigger.sh

Fix: sticky cookie jar race — non-atomic GET/merge/SETEX drops concurrent captures

Fix: sticky cookie jar race — non-atomic GET/merge/SETEX drops concurrent captures

Fix: billing pre-estimate ignores force_tier="4"

Fix: billing pre-estimate ignores force_tier="4"

Sync: Update SDKs — sticky_session, sticky_session_ttl (from )

Sync: Update SDKs — sticky_session, sticky_session_ttl (from )

Fix: _iter_slot_names re-walks already-scrubbed __dict__ slot in _strip_bs4_recursive

Fix: _iter_slot_names re-walks already-scrubbed __dict__ slot in _strip_bs4_recursive

Fix: fragile_indexes probe list diverges from CRITICAL_INDEXES, omits users_email_key

Fix: fragile_indexes probe list diverges from CRITICAL_INDEXES, omits users_email_key

Fix: Node SDK omits client-side sticky_session validation present in Python SDK

Fix: Node SDK omits client-side sticky_session validation present in Python SDK

Fix: pcall-guard incoming cjson.decode in _STICKY_MERGE_LUA (review finding — )

Fix: pcall-guard incoming cjson.decode in _STICKY_MERGE_LUA (review finding — )

Fix: amcheck bt_index_check probe has no cross-tick caching/backoff

Fix: amcheck bt_index_check probe has no cross-tick caching/backoff

Fix: sticky proxy only threaded into T2 — sub-T2 tiers never share an exit IP

Fix: sticky proxy only threaded into T2 — sub-T2 tiers never share an exit IP

Fix: SERP affinity routing could bypass browser-tier gate if force_tier is ever added to SERP (review finding — )

Fix: SERP affinity routing could bypass browser-tier gate if force_tier is ever added to SERP (review finding — )

Fix: statement_timeout cancellation misclassified as index corruption in error-trigger.sh

Fix: statement_timeout cancellation misclassified as index corruption in error-trigger.sh

Fix: primary API pre-estimate ignores force_tier="4" (review finding — )

Fix: primary API pre-estimate ignores force_tier="4" (review finding — )

Fix: _STICKY_MERGE_LUA guard accepts array-shaped payloads; test fake stricter than Lua

Fix: _STICKY_MERGE_LUA guard accepts array-shaped payloads; test fake stricter than Lua

Fix: server-side sticky merge re-validates shape/length of existing jar entries

Fix: server-side sticky merge re-validates shape/length of existing jar entries

Fix: guard fragile HeaderWriteError import against Python 3.11.x patch skew

Fix: guard fragile HeaderWriteError import against Python 3.11.x patch skew

Fix: stdlib-logger kwarg calls in create_job would TypeError if emitted

Fix: stdlib-logger kwarg calls in create_job would TypeError if emitted

Fix: T2.6 AMP-discovery quick-fetch egresses proxyless while sticky pinned

Fix: T2.6 AMP-discovery quick-fetch egresses proxyless while sticky pinned

Fix: log coverage-gap signal on bt_index_check statement_timeout abort

Fix: log coverage-gap signal on bt_index_check statement_timeout abort

Fix: strip control chars from captured sticky-session cookies before persist/replay

Fix: strip control chars from captured sticky-session cookies before persist/replay

Fix: capture T3 browser-tier cookies into captured_cookies

Fix: capture T3 browser-tier cookies into captured_cookies

bound bt_index_check probe loop with overall latency budget

bound bt_index_check probe loop with overall latency budget

gate amcheck cooldown reset/memo-clear on real scan pass

gate amcheck cooldown reset/memo-clear on real scan pass

Fix: stdlib-logger kwarg calls in cancel_job would TypeError if emitted

Fix: stdlib-logger kwarg calls in cancel_job would TypeError if emitted

Fix: amcheck transient-probe-failure path lacks a WARN log for on-call visibility

Fix: amcheck transient-probe-failure path lacks a WARN log for on-call visibility

Fix: narrow HeaderWriteError fallback alias catch scope in

Fix: narrow HeaderWriteError fallback alias catch scope in

Fix: sanitize cookie jar in before persist/replay

Fix: sanitize cookie jar in before persist/replay

Fix: setup-mail-dns.sh interpolates shell vars into inline python3 -c source

Fix: setup-mail-dns.sh interpolates shell vars into inline python3 -c source

Fix: herald SMTP send path lacks CRLF header-injection validation on to/subject

Fix: herald SMTP send path lacks CRLF header-injection validation on to/subject

Fix: store_cookies overwrites valid jar with empty jar on fully-invalid harvest

Fix: store_cookies overwrites valid jar with empty jar on fully-invalid harvest

Fix: ememo runbook container exec psql to obs-psql

Fix: ememo runbook container exec psql to obs-psql

Fix: residual shell-to-python3 interpolation in SPF log line

Fix: residual shell-to-python3 interpolation in SPF log line

Fix: herald email failover to Resend bypasses SMTP CRLF header-injection guard

Fix: herald email failover to Resend bypasses SMTP CRLF header-injection guard

Fix: add missing rollback file for migration 0296 (amcheck extension)

Fix: add missing rollback file for migration 0296 (amcheck extension)

Fix: guard index-name interpolation in amcheck auto-repair (defense-in-depth)

Fix: guard index-name interpolation in amcheck auto-repair (defense-in-depth)

Fix: get_cookies lacks read-side re-sanitization for rolling-deploy window

Fix: get_cookies lacks read-side re-sanitization for rolling-deploy window

Fix: retry-with-differentiation requeue has same force_tier=4 rolling-deploy gap

Fix: retry-with-differentiation requeue has same force_tier=4 rolling-deploy gap

Fix: add test coverage for retry-differentiation force_tier routing (review finding — )

Fix: add test coverage for retry-differentiation force_tier routing (review finding — )

Fix: scope cross-origin cookies to target domain before sticky jar

Fix: scope cross-origin cookies to target domain before sticky jar

Fix: unused Optional import in

Fix: unused Optional import in

Fix: cookie bracket-access KeyError risk in _filter_cookies_to_target

Fix: cookie bracket-access KeyError risk in _filter_cookies_to_target

Fix: byos_applied mislabeled true for sticky-session-only requests

Fix: byos_applied mislabeled true for sticky-session-only requests

Fix: weekly_business_metrics(weeks=0) silently returns all weeks

Fix: weekly_business_metrics(weeks=0) silently returns all weeks

Fix: herald CRLF guard doesn't cover Unicode line separators / NUL bytes

Fix: herald CRLF guard doesn't cover Unicode line separators / NUL bytes

Fix: _send_via_resend lacks defense-in-depth CRLF guard its docstring implies

Fix: _send_via_resend lacks defense-in-depth CRLF guard its docstring implies

Fix: fallback _registrable_domain lacks short-SLD handling

Fix: fallback _registrable_domain lacks short-SLD handling

Fix: fail closed on unparseable target URL in cookie scoping

Fix: fail closed on unparseable target URL in cookie scoping

Fix: sanitize response cookies in update_cookies

Fix: sanitize response cookies in update_cookies

Fix: strip_control_chars misses C1 range and Cf/Zl/Zp categories

Fix: strip_control_chars misses C1 range and Cf/Zl/Zp categories

Fix: gate sticky-cookie capture directly on STICKY_SESSIONS_ENABLED kill switch

Fix: gate sticky-cookie capture directly on STICKY_SESSIONS_ENABLED kill switch

Fix: rework billing top row to kill card whitespace

Fix: rework billing top row to kill card whitespace

Fix: harden sanitize_cookie_jar against lone UTF-16 surrogates

Fix: harden sanitize_cookie_jar against lone UTF-16 surrogates

Fix: anti-bot system cookie pool write-starved — replenish from every successful session

Fix: anti-bot system cookie pool write-starved — replenish from every successful session

Fix: persist failure_reason in usage-tracking metadata for search 504 timeouts

Fix: persist failure_reason in usage-tracking metadata for search 504 timeouts

Fix: anti-bot system/Distil-Imperva engine-selection routing

Fix: anti-bot system/Distil-Imperva engine-selection routing

Fix: burned-IP blacklist check skipped on force_sticky / RESERVED_HARD proxy paths

Fix: burned-IP blacklist check skipped on force_sticky / RESERVED_HARD proxy paths

Fix: SSR 500 on /dashboard/support/[id] — isomorphic-dompurify jsdom asset ENOENT

Fix: SSR 500 on /dashboard/support/[id] — isomorphic-dompurify jsdom asset ENOENT

Fix: single-source cookie_manager sanitize bounds

Fix: single-source cookie_manager sanitize bounds

Fix: close portal Configuration create race with idempotency key

Fix: close portal Configuration create race with idempotency key

Fix: parallel-IP race fires identical requests at zero stagger

Fix: parallel-IP race fires identical requests at zero stagger

Fix: remove stale hardcoded Chrome/120 UA from

Fix: remove stale hardcoded Chrome/120 UA from

Fix: ASN reroll closure replicates unlocked session-id read TOCTOU

Fix: ASN reroll closure replicates unlocked session-id read TOCTOU

Fix: configuration-hint cold-start fallback missing anti-bot system/Distil-Imperva arms

Fix: configuration-hint cold-start fallback missing anti-bot system/Distil-Imperva arms

Fix: SCAN MATCH cost scales with total keyspace, not per-domain match count (review finding — )

Fix: SCAN MATCH cost scales with total keyspace, not per-domain match count (review finding — )

Fix: 4 sibling admin pages may share the SSR-unconditional-dompurify-sanitize crash class

Fix: 4 sibling admin pages may share the SSR-unconditional-dompurify-sanitize crash class

Fix: task1 orphaned if _streaming_ip_race cancelled mid-stagger

Fix: task1 orphaned if _streaming_ip_race cancelled mid-stagger

Fix: guarantee browser close on exception paths in cookie harvester

Fix: guarantee browser close on exception paths in cookie harvester

Fix: cache pool-key format migration gap misses pre-deploy old-format keys

Fix: cache pool-key format migration gap misses pre-deploy old-format keys

Fix: stale sanitized HTML can flash in broadcast preview dialog

Fix: stale sanitized HTML can flash in broadcast preview dialog

Fix: sync sec-ch-ua client hints to CHROME_VERSION on live worker Playwright contexts

Fix: sync sec-ch-ua client hints to CHROME_VERSION on live worker Playwright contexts

Fix: correct misleading docstring on unused harvested user_agent

Fix: correct misleading docstring on unused harvested user_agent

Fix: has_control_chars does not catch lone surrogates (Cs category)

Fix: has_control_chars does not catch lone surrogates (Cs category)

Fix: stale sanitized email body can briefly pair with wrong message header

Fix: stale sanitized email body can briefly pair with wrong message header

re-check domain/session match before RESERVED_HARD reroll mutation

re-check domain/session match before RESERVED_HARD reroll mutation

Fix: preserve reroll state in _reroll_ip_if_blacklisted exception handler

Fix: preserve reroll state in _reroll_ip_if_blacklisted exception handler

Fix: AI engine experimental hardcodes stale Chrome UA, no client-hint sync

Fix: AI engine experimental hardcodes stale Chrome UA, no client-hint sync

Fix: strengthen assertions in

Fix: strengthen assertions in

Fix: close residual TOCTOU window in ASN-reroll two-lock structure

Fix: close residual TOCTOU window in ASN-reroll two-lock structure

Fix: close sibling unlocked-read TOCTOU in reroll paths

Fix: close sibling unlocked-read TOCTOU in reroll paths

SHARED-segment ASN reroll lacks idempotency guard present in RESERVED_HARD reroll

SHARED-segment ASN reroll lacks idempotency guard present in RESERVED_HARD reroll

Fix: disambiguate unverified-reroll mode_suffix in

Fix: disambiguate unverified-reroll mode_suffix in

Fix: useLayoutEffect triggers SSR console warning on admin email page

Fix: useLayoutEffect triggers SSR console warning on admin email page

Fix: unlocked session-id reads in log statements

Fix: unlocked session-id reads in log statements

unblock staging→main deploy

unblock staging→main deploy

Fix: T2 race sequential composition — T2 starts at t=0

Fix: T2 race sequential composition — T2 starts at t=0

Fix: sibling IP/domain-blacklist reroll missing idempotency guard

Fix: sibling IP/domain-blacklist reroll missing idempotency guard

Fix: route Kasada/Shape through vendor_engine (write-only detection gap)

Fix: route Kasada/Shape through vendor_engine (write-only detection gap)

fall back to legacy pool key in identity selection path

fall back to legacy pool key in identity selection path

Fix: broadcasts stale-preview guard uses isomorphic layout effect

Fix: broadcasts stale-preview guard uses isomorphic layout effect

Fix: extend authoritative min_tier floor override to vendor-class evidence

Fix: extend authoritative min_tier floor override to vendor-class evidence

Fix: decay cold-start antibot_skip_t2 counter instead of blanket 14-day expiry lock

Fix: decay cold-start antibot_skip_t2 counter instead of blanket 14-day expiry lock

Fix: event-driven Turnstile wait (replaces fixed poll loops)

Fix: event-driven Turnstile wait (replaces fixed poll loops)

Fix: make T2 race timeout budget-aware, matching T3/T4 pattern

Fix: make T2 race timeout budget-aware, matching T3/T4 pattern

Fix: _compute_timezone_offset except clause missing TypeError guard

Fix: _compute_timezone_offset except clause missing TypeError guard

Fix: legacy-pool migration path skips size-cap prune

Fix: legacy-pool migration path skips size-cap prune

Fix: vendor-class floor override doesn't verify evidence source matches floor origin

Fix: vendor-class floor override doesn't verify evidence source matches floor origin

Fix: cffi_task can leak on exception/cancellation during T2 race head-start window

Fix: cffi_task can leak on exception/cancellation during T2 race head-start window

Fix: remove duplicate assertion in anti-bot system proxy_url test

Fix: remove duplicate assertion in anti-bot system proxy_url test

Fix: get_domain_stats double-counts identity during old/new pool-key migration window

Fix: get_domain_stats double-counts identity during old/new pool-key migration window

Fix: curl_task can leak on external cancellation in T2 race

Fix: curl_task can leak on external cancellation in T2 race

Fix: AsyncMock pipe fixture mismatches sync sadd/expire calls

Fix: AsyncMock pipe fixture mismatches sync sadd/expire calls

Fix: legacy-pool migration prune converges to cap in one pass

Fix: legacy-pool migration prune converges to cap in one pass

Fix: stub redis.scard in legacy-pool fallback test

Fix: stub redis.scard in legacy-pool fallback test

Fix: identity_id_set uses set[str] annotation in get_domain_stats

Fix: identity_id_set uses set[str] annotation in get_domain_stats

Fix: scope T4 stealth retry to the solve step, not full pipeline re-invocation

Fix: scope T4 stealth retry to the solve step, not full pipeline re-invocation

Fix: remove TOCTOU EXISTS+SMEMBERS gap on legacy pool key in

Fix: remove TOCTOU EXISTS+SMEMBERS gap on legacy pool key in

Fix: distinguish predicate errors from expected teardown in Turnstile wait

Fix: distinguish predicate errors from expected teardown in Turnstile wait

Fix: gate stealth-retry wait-skip on actual challenge re-check

Fix: gate stealth-retry wait-skip on actual challenge re-check

Fix: cap Turnstile wait_for_function polling to 250ms

Fix: cap Turnstile wait_for_function polling to 250ms

Fix: Turnstile solve_mode signal never populated on failure branch

Fix: Turnstile solve_mode signal never populated on failure branch

Fix: guard prune size-check with per-domain lock

Fix: guard prune size-check with per-domain lock

Fix: narrow movement-task except to CancelledError only

Fix: narrow movement-task except to CancelledError only

Fix: add Phase 3 movement-task cancellation tests (review finding )

Fix: add Phase 3 movement-task cancellation tests (review finding )

Fix: per-agent CSAT (by_admin) always empty — attribute via reply author fallback

Fix: per-agent CSAT (by_admin) always empty — attribute via reply author fallback

Fix: auto-drop orphaned _ccnew/_ccold indexes from interrupted REINDEX CONCURRENTLY

Fix: auto-drop orphaned _ccnew/_ccold indexes from interrupted REINDEX CONCURRENTLY

Fix: adidas.fr /ar-api/ bot protection system initialization uses XHR headers on homepage navigation

Fix: adidas.fr /ar-api/ bot protection system initialization uses XHR headers on homepage navigation

Fix: herald_api_conn ememo alert false-fires on Bing indexing events

Fix: herald_api_conn ememo alert false-fires on Bing indexing events

Fix: exercise Turnstile wait JS predicates against a real page

Fix: exercise Turnstile wait JS predicates against a real page

Fix: finally-block release masking original exception in _check_and_prune_pool

Fix: finally-block release masking original exception in _check_and_prune_pool

Fix: CSAT LATERAL subquery doesn't exclude internal notes — attribution theft

Fix: CSAT LATERAL subquery doesn't exclude internal notes — attribution theft

Fix: adidas empty-query listing rewrite returns Bad Request as billable HTTP 200

Fix: adidas empty-query listing rewrite returns Bad Request as billable HTTP 200

Fix: require valid same-table sibling before _ccnew/_ccold auto-drop

Fix: require valid same-table sibling before _ccnew/_ccold auto-drop

Fix: clarify _launch_real_chromium docstring re: live_benchmark marker

Fix: clarify _launch_real_chromium docstring re: live_benchmark marker

Fix: CSAT LATERAL subquery non-deterministic tiebreak

Fix: CSAT LATERAL subquery non-deterministic tiebreak

Fix: tier_intelligence gather short-circuit + log swallowed cache errors

Fix: tier_intelligence gather short-circuit + log swallowed cache errors

Fix: AI engine hypothesis generation now self-heals around a dead OpenRouter free model

Fix: AI engine hypothesis generation now self-heals around a dead OpenRouter free model

Fix: telemetry outcome misclassified as failed when upstream status is non-2xx

Fix: telemetry outcome misclassified as failed when upstream status is non-2xx

Fix: add debug log to silent CF T2 IP-reputation recorder except block

Fix: add debug log to silent CF T2 IP-reputation recorder except block

Fix: surface tier_status_codes in UnifiedScrapeResponse construction sites

Fix: surface tier_status_codes in UnifiedScrapeResponse construction sites

Fix: block replies with failed attachments

Fix: block replies with failed attachments

Fix: release spend reservations on validation exits

Fix: release spend reservations on validation exits

Fix: retry webhook lock heartbeat after cache errors

Fix: retry webhook lock heartbeat after cache errors

Fix: compensate debit when webhook validation fails

Fix: compensate debit when webhook validation fails

Fix: first_indexed query failure now surfaces as a distinct signal

Fix: first_indexed query failure now surfaces as a distinct signal

Fix: assert absence of stall log in disabled-organic-cache test

Fix: assert absence of stall log in disabled-organic-cache test

Fix: fail migration runner when transactional SQL aborts

Fix: fail migration runner when transactional SQL aborts

Fix: shutdown refund idempotency key mismatch with API reaper (double-refund)

Fix: shutdown refund idempotency key mismatch with API reaper (double-refund)

Fix: structure-job refund idempotency key matches API reaper

Fix: structure-job refund idempotency key matches API reaper

Fix: restore_from_backup atomic via --single-transaction

Fix: restore_from_backup atomic via --single-transaction

Fix: deploy.sh stateful-recreate advisory omits healthcheck changes

Fix: deploy.sh stateful-recreate advisory omits healthcheck changes

Fix: failed refunds now durably retried via record_failed_refund

Fix: failed refunds now durably retried via record_failed_refund

Fix: shutdown refund exception emits billing_discrepancy for ops alerting

Fix: shutdown refund exception emits billing_discrepancy for ops alerting

Fix: deploy.sh Check 4 healthcheck awk extraction uses unanchored test: match

Fix: deploy.sh Check 4 healthcheck awk extraction uses unanchored test: match

Fix: replay entry can be stranded by CancelledError mid-replay

Fix: replay entry can be stranded by CancelledError mid-replay

Fix: scope deploy.sh Check 4 envsubst call to explicit allowlist

Fix: scope deploy.sh Check 4 envsubst call to explicit allowlist

Fix: worker tests assert stale refund idempotency key, red on staging

Fix: worker tests assert stale refund idempotency key, red on staging

Fix: refund_retry early dead-letter branches unprotected against CancelledError

Fix: refund_retry early dead-letter branches unprotected against CancelledError

Fix: shield refund compensation from CancelledError in shutdown finalize

Fix: shield refund compensation from CancelledError in shutdown finalize

Fix: refund_retry logs raw payload at ERROR level

Fix: refund_retry logs raw payload at ERROR level

Fix: shutdown early return skips scrape-stage success metrics

Fix: shutdown early return skips scrape-stage success metrics

Fix: refund_retry duplicate dead-letter write under cancellation timing

Fix: refund_retry duplicate dead-letter write under cancellation timing

Fix: align refund principal test with helper

Fix: align refund principal test with helper

document Netcup cache recreation safety

document Netcup cache recreation safety

enforce decrement ledger foreign keys

enforce decrement ledger foreign keys

clarify storage startup behavior

clarify storage startup behavior

record cancelled refund retries

record cancelled refund retries

refund_retry dead-letter dedupe field not asserted in 3 test call sites (review finding — )

refund_retry dead-letter dedupe field not asserted in 3 test call sites (review finding — )

cover shielded shutdown cancellation

cover shielded shutdown cancellation

mark local structurer dequeue healthy

mark local structurer dequeue healthy

prevent destructive historical replays

prevent destructive historical replays

distinguish equal fallback retry entries

distinguish equal fallback retry entries

eagerly acquire system proxy

eagerly acquire system proxy

compensate ambiguous refund retry requeues

compensate ambiguous refund retry requeues

separate local and shared cache health

separate local and shared cache health

validate historical preflight during dry-run

validate historical preflight during dry-run

complete spend adjustment after shielded refund cancellation

complete spend adjustment after shielded refund cancellation

route _compensate_api_debit failures into durable refund-retry queue

route _compensate_api_debit failures into durable refund-retry queue

Fix: close duplicate-backup-cron detection gap in setup-cron.sh

Fix: close duplicate-backup-cron detection gap in setup-cron.sh

Fix: guard post-commit cache invalidation to prevent 500s and skipped audit logs

Fix: guard post-commit cache invalidation to prevent 500s and skipped audit logs

Fix: preserve first-run dry-run preview (review finding — )

Fix: preserve first-run dry-run preview (review finding — )

Fix: migration 0300 notifications_type_check ACCESS EXCLUSIVE lock (NOT VALID split)

Fix: migration 0300 notifications_type_check ACCESS EXCLUSIVE lock (NOT VALID split)

guard credit_balance_cache writes against incomplete-ledger recompute

guard credit_balance_cache writes against incomplete-ledger recompute

Fix: health checks must detect a schema/table-empty database

Fix: health checks must detect a schema/table-empty database

restore repeat-scrape hint dropped by fire-and-forget refactor

restore repeat-scrape hint dropped by fire-and-forget refactor

Fix: anchor MANAGED_SCRIPT_PATTERN to path/word boundary in setup-cron.sh

Fix: anchor MANAGED_SCRIPT_PATTERN to path/word boundary in setup-cron.sh

assert data-plane health in blue/green gate, not just container status

assert data-plane health in blue/green gate, not just container status

validate backup integrity before upload or success report

validate backup integrity before upload or success report

wrap container exec in verify_data_plane_health with an outer timeout

wrap container exec in verify_data_plane_health with an outer timeout

size offsite-backup disk preflight to round-trip verification footprint

size offsite-backup disk preflight to round-trip verification footprint

hotfix- stale-backup purge lacks newest-backup floor

hotfix- stale-backup purge lacks newest-backup floor

add incident lockout to production deploy

add incident lockout to production deploy

freeze deploys after a hotfix-cancelled mid-migration run

freeze deploys after a hotfix-cancelled mid-migration run

restore rename-swap fails when live database does not exist

restore rename-swap fails when live database does not exist

catch material partial data loss in restore plausibility gate

catch material partial data loss in restore plausibility gate

Fix: restore recharge_attempts_credited_ledger_id_fkey

Fix: restore recharge_attempts_credited_ledger_id_fkey

fail loudly on cancelled-path DEPLOY_FREEZE write failure

fail loudly on cancelled-path DEPLOY_FREEZE write failure

Fix: backup coverage is a hardcoded exclusion list — new tables are silently unprotected

Fix: backup coverage is a hardcoded exclusion list — new tables are silently unprotected

P3 batch — offsite-backup trap order, scratch dir, fail-closed disk checks

P3 batch — offsite-backup trap order, scratch dir, fail-closed disk checks

Fix: refund retry dead-letter write can silently fail after lrem compensation

Fix: refund retry dead-letter write can silently fail after lrem compensation

batch P3 fixes — deploy-freeze clear/set asymmetry + verification docs

batch P3 fixes — deploy-freeze clear/set asymmetry + verification docs

bound and batch validate-backup.sh manifest, fail-closed role detection

bound and batch validate-backup.sh manifest, fail-closed role detection

validate RESTORE_MIN_RETENTION_RATIO before use

validate RESTORE_MIN_RETENTION_RATIO before use

set executable bit and use merge-base diff in hotfix-marker coverage check

set executable bit and use merge-base diff in hotfix-marker coverage check

compensate ambiguous refund retry requeue on CancelledError

compensate ambiguous refund retry requeue on CancelledError

P3 batch — restore-safety fail-closed guards, reaper, test coverage

P3 batch — restore-safety fail-closed guards, reaper, test coverage

add rename/copy diff-parsing regression coverage to hotfix-unsafe marker check

add rename/copy diff-parsing regression coverage to hotfix-unsafe marker check

fail closed on 5 registry/coverage edge cases in backup-database.sh

fail closed on 5 registry/coverage edge cases in backup-database.sh

fail closed on FK exposure into data-excluded backup tables

fail closed on FK exposure into data-excluded backup tables

P3 review-finding batch on run-migrations.sh reap/coverage checks

P3 review-finding batch on run-migrations.sh reap/coverage checks

document and guard migration /CONCURRENTLY-index patterns (batch )

document and guard migration /CONCURRENTLY-index patterns (batch )

batch P3 fixes to backup-database.sh registry parser and FK preflight

batch P3 fixes to backup-database.sh registry parser and FK preflight

verify pre-migration dump integrity (gzip -t + completion trailer) in run-migrations.sh

verify pre-migration dump integrity (gzip -t + completion trailer) in run-migrations.sh

fail closed on offsite-backup scratch-dir and -size failures

fail closed on offsite-backup scratch-dir and -size failures

fail closed on unparseable WAL archiver failed_count

fail closed on unparseable WAL archiver failed_count

replace validate-backup.sh eMemo denylist sanitizer with printf-based construction

replace validate-backup.sh eMemo denylist sanitizer with printf-based construction

re-read ledger sum before guard call in reconcile_all_inconsistent_balances

re-read ledger sum before guard call in reconcile_all_inconsistent_balances

add mutual exclusion to validate-backup.sh scratch-DB restore

add mutual exclusion to validate-backup.sh scratch-DB restore

revoke PUBLIC EXECUTE on credit_balance_cache_upsert

revoke PUBLIC EXECUTE on credit_balance_cache_upsert

paren-depth-aware call slicing in test_repeat_tracking_is_awaited_for_same_request_hint

paren-depth-aware call slicing in test_repeat_tracking_is_awaited_for_same_request_hint

rate-limit the DB-backed /api/health/ready endpoint

rate-limit the DB-backed /api/health/ready endpoint

clear stale structure claim during crash recovery

clear stale structure claim during crash recovery

add disk-space preflight for validate-backup.sh scratch restore

add disk-space preflight for validate-backup.sh scratch restore

Fix: isolate per-item claim-clear failures in crash recovery

Fix: isolate per-item claim-clear failures in crash recovery

warn on null row-count regardless of registered exclusion

warn on null row-count regardless of registered exclusion

Fix: narrow postgres scripts/ read-only mount to wal-archive.sh only

Fix: narrow postgres scripts/ read-only mount to wal-archive.sh only

guard WAL archiver lockfile write and init Discord alerting first

guard WAL archiver lockfile write and init Discord alerting first

Fix: claim-recovery tests write keys outside fixture teardown namespace

Fix: claim-recovery tests write keys outside fixture teardown namespace

close validate-backup.sh lock fd for forked subprocesses

close validate-backup.sh lock fd for forked subprocesses

remove stranded lockfile on partial write in WAL archiver monitor

remove stranded lockfile on partial write in WAL archiver monitor

pre-acquire advisory lock in ensure_balance_cache

pre-acquire advisory lock in ensure_balance_cache

batch P2/P3 review findings — scripts/validate-backup.sh

batch P2/P3 review findings — scripts/validate-backup.sh

Fix: claim-recovery fixture teardown SCAN patterns guarded against non-isolated cache db

Fix: claim-recovery fixture teardown SCAN patterns guarded against non-isolated cache db

ShutdownManager orphan-cancellation follow-ups (batch #6)

ShutdownManager orphan-cancellation follow-ups (batch #6)

surface legacy negative-account ledger/cache divergence

surface legacy negative-account ledger/cache divergence

add covering index for credit_balance_mutations retention DELETE

add covering index for credit_balance_mutations retention DELETE

reconstruct credit_balance_cache_upsert last-known-good from credit_ledger, not cache

reconstruct credit_balance_cache_upsert last-known-good from credit_ledger, not cache

harden pre-deploy-migration-rehearsal job (batch )

harden pre-deploy-migration-rehearsal job (batch )

reconcile_all batch-limit priority, tunability, and boundary warning (batch )

reconcile_all batch-limit priority, tunability, and boundary warning (batch )

reconcile_all query_canceled lock leak + GUC bounds (batch )

reconcile_all query_canceled lock leak + GUC bounds (batch )

distinguish git resolution failure from legitimate absence in schedule-check script

distinguish git resolution failure from legitimate absence in schedule-check script

redact Postgres DETAIL/CONTEXT lines from restore-failure CI logs

redact Postgres DETAIL/CONTEXT lines from restore-failure CI logs

pre-flight check for backup-role table access before create_backup

pre-flight check for backup-role table access before create_backup

pin migration-shadow- privileged scripts to trusted base ref

pin migration-shadow- privileged scripts to trusted base ref

compute credit_ledger.balance_after from fresh ledger SUM, not guard-substituted value

compute credit_ledger.balance_after from fresh ledger SUM, not guard-substituted value

wire backup/restore/migration-safety test suites into CI

wire backup/restore/migration-safety test suites into CI

add refuse-stub rollback for 0344; close 0339-gap finding as resolved

add refuse-stub rollback for 0344; close 0339-gap finding as resolved

route backup-database.sh prune through purge-stale-backups.sh (, batch )

route backup-database.sh prune through purge-stale-backups.sh (, batch )

pin pytest and add Postgres service to backup-safety CI job (batch: , )

pin pytest and add Postgres service to backup-safety CI job (batch: , )

close two redaction bypasses in restore-database.sh log filter

close two redaction bypasses in restore-database.sh log filter

discover backup/restore/migration-safety suites by glob, guard against drift

discover backup/restore/migration-safety suites by glob, guard against drift

backup/restore failure signal routing (final sweep, batch H)

backup/restore failure signal routing (final sweep, batch H)

build a genuinely flock-free PATH for the missing-flock lock test

build a genuinely flock-free PATH for the missing-flock lock test

Fix: scope SET LOCAL statement_timeout to the SELECT 1 it guards in /api/health/ready

Fix: scope SET LOCAL statement_timeout to the SELECT 1 it guards in /api/health/ready

Fix: chmod 600 decrypted secrets output file

Fix: chmod 600 decrypted secrets output file

widen structure-job execution-claim try/finally to cover billing calls

widen structure-job execution-claim try/finally to cover billing calls

black-format after the execution-claim try/finally widening

black-format after the execution-claim try/finally widening

drop redundant _track_job_end on the insufficient-credits return

drop redundant _track_job_end on the insufficient-credits return

stop the insufficient-credits path double-refunding the scrape debit

stop the insufficient-credits path double-refunding the scrape debit

Fix: check exit status of schema_migrations bookkeeping write in apply_migration

Fix: check exit status of schema_migrations bookkeeping write in apply_migration

add deploy-time WAL archiving config-drift assertion

add deploy-time WAL archiving config-drift assertion

batch — P3 migration file hygiene (rollback gaps, 0339, domain_profiles DROP)

batch — P3 migration file hygiene (rollback gaps, 0339, domain_profiles DROP)

Fix: error-trigger.sh anti-bot/scrape-fleet checks targeted cloud provider instead of Netcup

Fix: error-trigger.sh anti-bot/scrape-fleet checks targeted cloud provider instead of Netcup

restore false-success gate for tier-capped T4 jobs (ALT-51)

restore false-success gate for tier-capped T4 jobs (ALT-51)

make pre-migration restore tolerant of FK into excluded jobs table

make pre-migration restore tolerant of FK into excluded jobs table

migration shadow dry run never runs on staging->main PRs and is broken where it does run

migration shadow dry run never runs on staging->main PRs and is broken where it does run

sync domain_playbooks.json with 's approved min_tier removal

sync domain_playbooks.json with 's approved min_tier removal

retire evidence-backed min_tier:4 bot protection system pins for idealo.at/levi.com/byfood.com

retire evidence-backed min_tier:4 bot protection system pins for idealo.at/levi.com/byfood.com

assert_single_schedule cron guard now covers every installed job

assert_single_schedule cron guard now covers every installed job

normalize ToS §8.1 spacing wrapper + confirm /maintenance link resolves

normalize ToS §8.1 spacing wrapper + confirm /maintenance link resolves

run-migrations.sh flock fd leak, FK-rewrite provenance, NOT VALID alert

run-migrations.sh flock fd leak, FK-rewrite provenance, NOT VALID alert

provision alterlab_admin and monitor_ro roles in backup-restore-drill scratch Postgres

provision alterlab_admin and monitor_ro roles in backup-restore-drill scratch Postgres

correct opentable.com vendor to Shape Security and probe hardcoded min_tier=4 floor

correct opentable.com vendor to Shape Security and probe hardcoded min_tier=4 floor

deploy- hardening — concurrency-group conflict, run: interpolation, sequential host deploys

deploy- hardening — concurrency-group conflict, run: interpolation, sequential host deploys

retire anti-bot system min_tier:4 pins for rh.com, reuters.com

retire anti-bot system min_tier:4 pins for rh.com, reuters.com

port NOT-VALID FK rewrite to restore-database.sh

port NOT-VALID FK rewrite to restore-database.sh

retire imperva-soft/unclassified min_tier:4 pins

retire imperva-soft/unclassified min_tier:4 pins

harden backup-exclusions sidecar — atomicity, collision-safe keying, prove-it coverage

harden backup-exclusions sidecar — atomicity, collision-safe keying, prove-it coverage

test coverage for JSON configuration min_tier fast-fail — registry fallback exception path + cache expiry expiry

test coverage for JSON configuration min_tier fast-fail — registry fallback exception path + cache expiry expiry

Fix: find_unresolved_ledger_cache_divergence misses recompute-path guard blocks

Fix: find_unresolved_ledger_cache_divergence misses recompute-path guard blocks

/status maintenance surface polish — 5 review findings from

/status maintenance surface polish — 5 review findings from

— 3 further review findings from

— 3 further review findings from

add BEFORE UPDATE trigger for maintenance_windows.updated_at

add BEFORE UPDATE trigger for maintenance_windows.updated_at

remove unused non-rate-limited MaintenanceAuth alias

remove unused non-rate-limited MaintenanceAuth alias

allowlist announcement CTA href scheme at render site

allowlist announcement CTA href scheme at render site

eliminate nested bash -c double-substitution in check_mail_cert

eliminate nested bash -c double-substitution in check_mail_cert

narrow backup-restore- container build context + document cron scheduling

narrow backup-restore- container build context + document cron scheduling

sanitize log samples before Discord/eMemo markdown embedding

sanitize log samples before Discord/eMemo markdown embedding

BACKUP_CORRUPT_RETENTION_DAYS unvalidated before find -mtime, can abort script under set -e

BACKUP_CORRUPT_RETENTION_DAYS unvalidated before find -mtime, can abort script under set -e

replace unquoted heredoc + sed-denylist in base-backup.sh alert path

replace unquoted heredoc + sed-denylist in base-backup.sh alert path

validate $VERSION format before sed interpolation

validate $VERSION format before sed interpolation

pre-restrict decrypted secrets file to 0600 before write

pre-restrict decrypted secrets file to 0600 before write

fail-closed unresolvable-IP rate-limit bucket, drop spoofable XFF fallback

fail-closed unresolvable-IP rate-limit bucket, drop spoofable XFF fallback

pass Cloudflare API token via curl stdin config, not argv

pass Cloudflare API token via curl stdin config, not argv

PGPASSWORD interpolated unescaped into single-quoted SQL literal inside heredoc

PGPASSWORD interpolated unescaped into single-quoted SQL literal inside heredoc

backup-restore-drill auto-files a P1 per failed run — no , mislabels manual probes as scheduled

backup-restore-drill auto-files a P1 per failed run — no , mislabels manual probes as scheduled

close protocol-relative/backslash bypass in announcement CTA href validator

close protocol-relative/backslash bypass in announcement CTA href validator

reclaim runner disk space and log df -h in backup-restore-drill

reclaim runner disk space and log df -h in backup-restore-drill

remove credential material from unintended disclosure channels

remove credential material from unintended disclosure channels

reject auto-recharge threshold a single recharge cannot clear

reject auto-recharge threshold a single recharge cannot clear

harden decrypt-secrets.sh sibling config writes against symlink planting

harden decrypt-secrets.sh sibling config writes against symlink planting

remove unused non-rate-limited AdminAuth alias

remove unused non-rate-limited AdminAuth alias

don't blind-escalate tier on unclassified 429/5xx job retry

don't blind-escalate tier on unclassified 429/5xx job retry

correct AutoRechargeSettingsRequest.threshold_microcents default

correct AutoRechargeSettingsRequest.threshold_microcents default

real end-to-end antibot_hint fallback tests, fix kasada/shape telemetry monitoring system loss

real end-to-end antibot_hint fallback tests, fix kasada/shape telemetry monitoring system loss

close restore-database.sh host-TCP guard bypass

close restore-database.sh host-TCP guard bypass

correct stale pricing pointer + narrow gitignore test blackhole

correct stale pricing pointer + narrow gitignore test blackhole

trust staging deployment scripts in shadow dry run

trust staging deployment scripts in shadow dry run

Fix: skip unused proxy identity resolution on trivial scrapes

Fix: skip unused proxy identity resolution on trivial scrapes

Fix: retain a bounded cookie-cohort routing session

Fix: retain a bounded cookie-cohort routing session

reclaim runner disk in Migration Shadow Dry Run before restore

reclaim runner disk in Migration Shadow Dry Run before restore

prune oldest objects to fit the storage cap before failing closed

prune oldest objects to fit the storage cap before failing closed

meter sync downgrade persistence failures (batch )

meter sync downgrade persistence failures (batch )

optional prune-credential split for offsite-backup.sh

optional prune-credential split for offsite-backup.sh

reduce R2_RETENTION_DAYS default from 3 to 2 to fit 10GB cap

reduce R2_RETENTION_DAYS default from 3 to 2 to fit 10GB cap

Fix: merge concurrent passive stack cache evidence atomically (batch )

Fix: merge concurrent passive stack cache evidence atomically (batch )

Fix: post-result T4 deferral provenance flag is cleared by mixed-origin requeue

Fix: post-result T4 deferral provenance flag is cleared by mixed-origin requeue

capture fingerprinted query attribution for Check 8 idle-in-tx

capture fingerprinted query attribution for Check 8 idle-in-tx

migration 0349 rollback + natural-key UUID resolution

migration 0349 rollback + natural-key UUID resolution

coerce or skip malformed learning elements in transform_claude_learnings

coerce or skip malformed learning elements in transform_claude_learnings

wire mail.cf_dns_token primary/fallback sourcing

wire mail.cf_dns_token primary/fallback sourcing

stop fabricating tier-4 recommendations for domains that have never succeeded

stop fabricating tier-4 recommendations for domains that have never succeeded

fail ci-pass gate closed on cancelled job results

fail ci-pass gate closed on cancelled job results

gate jobs.result content.html on html_ref

gate jobs.result content.html on html_ref

Fix: DomainPlaybooks.get arity crash — deploy blocker

Fix: DomainPlaybooks.get arity crash — deploy blocker

link merged confidence to primary vendor, add CAS read-error tolerance

link merged confidence to primary vendor, add CAS read-error tolerance

batch fix for error-trigger idle-tx findings

batch fix for error-trigger idle-tx findings

resolve vendor-signal review findings (batch)

resolve vendor-signal review findings (batch)

bound outcome label enum and tighten tier-guard test

bound outcome label enum and tighten tier-guard test

reject unsafe object names in prune-to-fit fallback

reject unsafe object names in prune-to-fit fallback

Fix: batch — tier-intelligence fabrication findings ( cohort, )

Fix: batch — tier-intelligence fabrication findings ( cohort, )

name log format explicitly on conditional access_log

name log format explicitly on conditional access_log

reformat at the configured line length

reformat at the configured line length

provision production-parity roles in shadow migration dry run

provision production-parity roles in shadow migration dry run

move CREATE ROLE out of DO block in shadow dry-run privilege step

move CREATE ROLE out of DO block in shadow dry-run privilege step

document multi-format html-trim blind spot in false-success audit

document multi-format html-trim blind spot in false-success audit

run server config validation unconditionally on every PR

run server config validation unconditionally on every PR

guard decrypt_credentials to stop killing profile_consumer_loop

guard decrypt_credentials to stop killing profile_consumer_loop

offsite-backup.sh prune-to-fit dot-name filter and remote-collision guard

offsite-backup.sh prune-to-fit dot-name filter and remote-collision guard

guard non-numeric total_credits cast in billing audit query

guard non-numeric total_credits cast in billing audit query

preserve CAS guard on cache_antibot_stack watch failure

preserve CAS guard on cache_antibot_stack watch failure

log-monitor.sh scan-window scaling and job_id revalidation ( cohort)

log-monitor.sh scan-window scaling and job_id revalidation ( cohort)

refund screenshot/PDF add-on when persistence fails after charge

refund screenshot/PDF add-on when persistence fails after charge

restate full 4-condition html-trim guard in audit script

restate full 4-condition html-trim guard in audit script

close read transaction before provider network call in proxy_integrations

close read transaction before provider network call in proxy_integrations

stop Downloads check paging on scanner 404 noise

stop Downloads check paging on scanner 404 noise

alert on retention/cap drift before it silently blocks a nightly upload

alert on retention/cap drift before it silently blocks a nightly upload

scope setup-phase RedisError to the verify retry budget

scope setup-phase RedisError to the verify retry budget

set executable bit on check-migration-immutability.sh

set executable bit on check-migration-immutability.sh

widen billing audit regex guard to match native ::int tolerance

widen billing audit regex guard to match native ::int tolerance

migration 0349 natural-key author lookup ignores soft-delete

migration 0349 natural-key author lookup ignores soft-delete

surface excluded-row count in billing audit sum guards

surface excluded-row count in billing audit sum guards

profile_consumer setup-guard refinements ( cohort)

profile_consumer setup-guard refinements ( cohort)

tag Postgres connections with application_name for idle-in-tx correlation

tag Postgres connections with application_name for idle-in-tx correlation

stop DOWNLOADS_NOISE_FILTER prefix list from drifting silently

stop DOWNLOADS_NOISE_FILTER prefix list from drifting silently

classify evidenced IP-reputation-only vendor blocks in proxy failure subtype

classify evidenced IP-reputation-only vendor blocks in proxy failure subtype

profile_consumer error-boundary and -key findings (, )

profile_consumer error-boundary and -key findings (, )

Fix: _record_stage_duration_call_sites uses AST parsing instead of raw paren counting

Fix: _record_stage_duration_call_sites uses AST parsing instead of raw paren counting

add missing pdf_url field to Node SDK ScrapeResponse

add missing pdf_url field to Node SDK ScrapeResponse

route log-monitor 5xx scan truncation to eMemo/STATUS, ASCII-anchor jid state-file guard

route log-monitor 5xx scan truncation to eMemo/STATUS, ASCII-anchor jid state-file guard

emit outcome metric for cf_clearance cache-hit-without-cookie

emit outcome metric for cf_clearance cache-hit-without-cookie

reconcile addon refund against a later successful retry

reconcile addon refund against a later successful retry

set executable bit on pg-repack-restore-headroom-check.sh

set executable bit on pg-repack-restore-headroom-check.sh

raise log-monitor.sh truncation floor, add locale-immunity test

raise log-monitor.sh truncation floor, add locale-immunity test

match attribute-style calls in record_stage_duration test helper

match attribute-style calls in record_stage_duration test helper

remove redundant shallow re-fetch from migration-immutability guard

remove redundant shallow re-fetch from migration-immutability guard

Fix: log-monitor.sh diagnostic findings ( cohort, batch )

Fix: log-monitor.sh diagnostic findings ( cohort, batch )

Fix: get_cached_challenge_cookies emits hit without checking required cookie present

Fix: get_cached_challenge_cookies emits hit without checking required cookie present

remove leftover deliberate-break blocking Misc Regression Suites on staging

remove leftover deliberate-break blocking Misc Regression Suites on staging

executable-bit-check runs on push to staging/main with observable failure alert

executable-bit-check runs on push to staging/main with observable failure alert

sync CHALLENGE_TITLES with canonical list, add drift gate

sync CHALLENGE_TITLES with canonical list, add drift gate

stop cancel-in-progress from swallowing executable-bit-check push failure alerts

stop cancel-in-progress from swallowing executable-bit-check push failure alerts

Fix: stop asserting domains 'cannot be scraped' in customer-facing text

Fix: stop asserting domains 'cannot be scraped' in customer-facing text

document REDIS_AOF_WARN_MB/REDIS_AOF_CRIT_MB in .env.example

document REDIS_AOF_WARN_MB/REDIS_AOF_CRIT_MB in .env.example

wire infra/ssh-guard/tests/ into the orphan-suite guard

wire infra/ssh-guard/tests/ into the orphan-suite guard

recognize actual review-verdict format in shadow-dryrun trust escalation

recognize actual review-verdict format in shadow-dryrun trust escalation

align trusted-source test fixtures with identity scoping

align trusted-source test fixtures with identity scoping

Fix: route empty-DB shadow-migration replay through alterlab_admin

Fix: route empty-DB shadow-migration replay through alterlab_admin

clean npm cache so the Trivy scan of the api image stops timing out

clean npm cache so the Trivy scan of the api image stops timing out

Fix: refund template Option B 1000x over-refund guidance

Fix: refund template Option B 1000x over-refund guidance

revert intent-differentiation retarget on alterlab-vs-* blog posts

revert intent-differentiation retarget on alterlab-vs-* blog posts

Fix: errexit aborts entire log-monitor run when 5xx SLO psql probe fails

Fix: errexit aborts entire log-monitor run when 5xx SLO psql probe fails

quarantine malformed B2B drain members instead of livelocking the batch

quarantine malformed B2B drain members instead of livelocking the batch

default proxy sticky_session_id to cohort routing identity

default proxy sticky_session_id to cohort routing identity

run local-backup purge on every exit, not just success

run local-backup purge on every exit, not just success

Fix: per-stage duration metric cannot record a failure outcome

Fix: per-stage duration metric cannot record a failure outcome

run-migrations.sh no longer de-transactionalizes migrations whose data contains commit/concurrently

run-migrations.sh no longer de-transactionalizes migrations whose data contains commit/concurrently

Fix: services/herald fails black --check on staging

Fix: services/herald fails black --check on staging

run-migrations.sh dollar-quote detection + batch review-finding cohort

run-migrations.sh dollar-quote detection + batch review-finding cohort

cooldown CLI fail-closed + atomic stdout (, )

cooldown CLI fail-closed + atomic stdout (, )

Fix: worker stage_timer records outcome=timeout for CancelledError instead of success

Fix: worker stage_timer records outcome=timeout for CancelledError instead of success

DomainRateLimiter expiry coverage and mutex release

DomainRateLimiter expiry coverage and mutex release

close dispatch-entitlement review-finding batch (, )

close dispatch-entitlement review-finding batch (, )

distinguish caller-owned vs platform-derived sticky proxy sessions

distinguish caller-owned vs platform-derived sticky proxy sessions

guard fallback-branch find -delete calls in purge_stale_local_backups

guard fallback-branch find -delete calls in purge_stale_local_backups

wire IP-reputation egress re-roll into unwired T3 vendor gates

wire IP-reputation egress re-roll into unwired T3 vendor gates

production_actions_admin TOCTOU, idempotency, and validation gaps

production_actions_admin TOCTOU, idempotency, and validation gaps

capture field names not type annotations in ecosystem-sync SDK titles

capture field names not type annotations in ecosystem-sync SDK titles

grandfather duplicate migration prefix 0356

grandfather duplicate migration prefix 0356

Fix: datetime shadowed by nested imports in process_scrape_job — soft-block job.failed webhook never delivered

Fix: datetime shadowed by nested imports in process_scrape_job — soft-block job.failed webhook never delivered

copy error/result from cache truth in stuck-job reconcile

copy error/result from cache truth in stuck-job reconcile

account for pre-poll elapsed time in sync scrape poll deadline

account for pre-poll elapsed time in sync scrape poll deadline

raise shadow-dryrun timeout budgets with measured headroom

raise shadow-dryrun timeout budgets with measured headroom

profile_consumer setup-guard follow-ups — redaction + bounded cache retry

profile_consumer setup-guard follow-ups — redaction + bounded cache retry

production_actions_admin gen-2 review-finding cohort

production_actions_admin gen-2 review-finding cohort

concurrent default-proxy race 500 + reconcile-without-error counter inflation

concurrent default-proxy race 500 + reconcile-without-error counter inflation

match PostgreSQL's real dollar-quote-tag grammar in run-migrations.sh

match PostgreSQL's real dollar-quote-tag grammar in run-migrations.sh

stop importlib.reload cross-file class-identity leak in env_validation tests

stop importlib.reload cross-file class-identity leak in env_validation tests

Netcup downloads force-recreate + artifact-delivery wiring (batch )

Netcup downloads force-recreate + artifact-delivery wiring (batch )

production-action executor follow-ups — gen-2 review-finding cohort

production-action executor follow-ups — gen-2 review-finding cohort

detect cross-branch migration prefix collisions via push trigger

detect cross-branch migration prefix collisions via push trigger

cooldown CLI except ValueError also catches unrelated urlparse errors from --check-urls args

cooldown CLI except ValueError also catches unrelated urlparse errors from --check-urls args

rehearsal disk floor REQUIRED_GB=30 is stale — derive it from the actual dump size

rehearsal disk floor REQUIRED_GB=30 is stale — derive it from the actual dump size

services/api/app/routers findings — reconcile, production-actions, proxy defaults

services/api/app/routers findings — reconcile, production-actions, proxy defaults

tolerate concurrent recheck resolution in dispatch re-lock, document id.desc tiebreak

tolerate concurrent recheck resolution in dispatch re-lock, document id.desc tiebreak

make RADWARE T3 gate reachable, restore reroll gate context

make RADWARE T3 gate reachable, restore reroll gate context

Fix: jitter low-sample T1 probe cadence to avoid periodicity signal

Fix: jitter low-sample T1 probe cadence to avoid periodicity signal

deliver container exec credentials via --env-file, not -e argv

deliver container exec credentials via --env-file, not -e argv

add regression coverage for handler-registry execution-call scanner

add regression coverage for handler-registry execution-call scanner

Fix: gate idle-in-tx alert on hold duration, not just count

Fix: gate idle-in-tx alert on hold duration, not just count

widen IP-reputation egress re-roll trigger to vendor-classified gates

widen IP-reputation egress re-roll trigger to vendor-classified gates

rehearsal disk-floor follow-ups — coarse pre-download check, alert-list gap

rehearsal disk-floor follow-ups — coarse pre-download check, alert-list gap

recognize verifying -> superseded as a benign concurrent resolution

recognize verifying -> superseded as a benign concurrent resolution

deliver container exec credentials via --env-file in log-monitor.sh and redis-health.sh

deliver container exec credentials via --env-file in log-monitor.sh and redis-health.sh

tier-stats invalidation follow-ups ( cohort, )

tier-stats invalidation follow-ups ( cohort, )

make custom configuration tier-stats writers atomic with stats_version stamp

make custom configuration tier-stats writers atomic with stats_version stamp

deferral-budget cap logging + edge-case test coverage

deferral-budget cap logging + edge-case test coverage

add coarse pre-download disk-floor check to backup-restore-

add coarse pre-download disk-floor check to backup-restore-

check-branch-protection-drift.sh now covers classic protection on main

check-branch-protection-drift.sh now covers classic protection on main

infra/monitoring batch follow-ups (error-trigger sanitization, atomic idle-tx query, log-monitor mv guard)

infra/monitoring batch follow-ups (error-trigger sanitization, atomic idle-tx query, log-monitor mv guard)

detect and fail closed on composite FKs in restore-database.sh orphan sweep

detect and fail closed on composite FKs in restore-database.sh orphan sweep

custom configuration stats_version follow-ups ( cohort)

custom configuration stats_version follow-ups ( cohort)

guard db.rollback in proxy_integrations IntegrityError handlers

guard db.rollback in proxy_integrations IntegrityError handlers

concurrent probes, dedupe, and statement timeout

concurrent probes, dedupe, and statement timeout

scripts/ recovery-tooling follow-ups

scripts/ recovery-tooling follow-ups

close window-coupling concurrency defects (batch )

close window-coupling concurrency defects (batch )

remove spent 0349 migration-immutability allowlist entry

remove spent 0349 migration-immutability allowlist entry

add operator scrub script for usage data credential rows

add operator scrub script for usage data credential rows

defer health-loop session rotation while lease is held

defer health-loop session rotation while lease is held

Fix: stop asserting a false homepage-origin narrative on Google SERP requests

Fix: stop asserting a false homepage-origin narrative on Google SERP requests

guard identity lease-refresh-failure close against active lease

guard identity lease-refresh-failure close against active lease

Fix: allow empty subscriptions restore

Fix: allow empty subscriptions restore

Fix: remediate image vulnerabilities

Fix: remediate image vulnerabilities

Fix: fail closed on stale backup paths

Fix: fail closed on stale backup paths

Merge: repair backup redaction CI fixtures

Merge: repair backup redaction CI fixtures

extend Trivy worker scan timeout

extend Trivy worker scan timeout

Fix: gate SERP search on successful homepage initialization

Fix: gate SERP search on successful homepage initialization

Fix: stale detail can mutate the wrong production action

Fix: stale detail can mutate the wrong production action

Fix: Reserved rate-limit slots are discarded and reacquired indefinitely

Fix: Reserved rate-limit slots are discarded and reacquired indefinitely

Fix: Mutation responses omit prior audit events

Fix: Mutation responses omit prior audit events

Fix: Netcup artifact startup and probe fail open

Fix: Netcup artifact startup and probe fail open

Fix: SERP response reports the requested engine, not the engine that answered — Bing results labelled and billed as Google

Fix: SERP response reports the requested engine, not the engine that answered — Bing results labelled and billed as Google

Fix: redact demographic profile DB error text

Fix: redact demographic profile DB error text

Fix: scraper tier-guard findings from

Fix: scraper tier-guard findings from

Fix: SERP thin-result findings from

Fix: SERP thin-result findings from

Fix: align thin-result grace timing contract

Fix: align thin-result grace timing contract

move attachment probes outside claim gate

move attachment probes outside claim gate

harden batch admission and schedule state

harden batch admission and schedule state

close SERP correctness gaps in batch

close SERP correctness gaps in batch

close regression-watch state-machine follow-ups

close regression-watch state-machine follow-ups

route default cohorts through DataImpulse session-ID gateway

route default cohorts through DataImpulse session-ID gateway

sanitize post-login callback URLs

sanitize post-login callback URLs

preserve rate-slot clock and live frontiers

preserve rate-slot clock and live frontiers

complete FIRST_SCRAPE lifecycle coverage

complete FIRST_SCRAPE lifecycle coverage

normalize cache byte keys before recovery ledger writes

normalize cache byte keys before recovery ledger writes

keep feature PR gates off staging

keep feature PR gates off staging

harden rollback finalization and eMemo delivery

harden rollback finalization and eMemo delivery

close replay integrity batch

close replay integrity batch

retain replay claims on dead-letter failure

retain replay claims on dead-letter failure

Fix: denied scheduled runs retain debit

Fix: denied scheduled runs retain debit

lock sql drop target relation

lock sql drop target relation

Fix: reject future-dated backup manifests

Fix: reject future-dated backup manifests

protect refund outbox drain acknowledgement

protect refund outbox drain acknowledgement

align batch response contract and drift check

align batch response contract and drift check

quarantine non-object B2B payloads

quarantine non-object B2B payloads

Fix: restore valid supersede controls

Fix: restore valid supersede controls

reconcile rejected mutations

reconcile rejected mutations

atomically claim low-sample probes

atomically claim low-sample probes

skip AI engine root install in deploy gate

skip AI engine root install in deploy gate