Brad Groux
9369ca8bcf
docs: update all documentation for v1.2.0 + v1.3.0
...
- Bump all package versions to 1.3.0
- README: version badge, blocked column, new feature highlights
- CHANGELOG: full v1.2.0 and v1.3.0 entries
- FEATURES.md: GitHub sync, activity feed, standup summary sections
- FEATURES.md: storage architecture, API envelope docs, new CLI commands
- FEATURES.md: updated API endpoints table and response format docs
2026-01-31 23:33:37 -06:00
Brad Groux
d8dab5a612
chore: bump version to v1.1.0 + changelog
2026-01-31 07:09:18 -06:00
Brad Groux
a2aa5053c6
feat: add seed data and first-run auto-seeding for clean public repo
...
- Remove tracked personal attachment screenshots from git
- Add tasks/attachments/ and tasks/archive-attachments/ to .gitignore
- Create 4 example tasks showcasing features (auth, bug, research, automation)
- Add seedIfEmpty() to TaskService for automatic first-run seeding
- Add pnpm seed script for manual seeding
- Update README quickstart with seed docs
- Fix version badge mismatch (1.1.0 → 1.0.0)
2026-01-29 15:45:38 -06:00
Brad Groux
0c0f5b344d
security+quality: final codebase review fixes
...
Security (critical):
- Remove shell:true from preview-service spawn (command injection fix)
- Replace exec() with execFile() in github-service (no shell interpolation)
- Add SIGKILL fallback after SIGTERM timeout in worktree-service
Stability:
- Add process cleanup handlers (SIGTERM/SIGINT) for preview servers
- Add MAX_PREVIEW_SERVERS=5 limit to prevent resource exhaustion
- Memoize WebSocket context value to prevent unnecessary re-renders
Code quality:
- Remove hardcoded 'Brad' author → 'User' (3 files)
- Replace hardcoded localhost:3001 URLs with API_BASE (AttachmentsSection)
- Fix SECURITY-AUDIT.md date (2025 → 2026)
- Add license/repository/author to all 6 package.json files
Data hygiene:
- Untrack all runtime data files (.veritas-kanban/*.json, telemetry, activity)
- Simplify .gitignore: .veritas-kanban/* except .gitkeep
- Removed ~15,700 lines of runtime data from git history
2026-01-29 06:13:10 -06:00
Brad Groux
e59c5072cf
fix: resolve infinite render loop in useKeyboard test + memoize context value
...
Two bugs fixed:
1. TestConsumer's default param (tasks=[]) created a new array ref every render,
causing an infinite useEffect loop with setTasks. Fixed with stable EMPTY_TASKS constant.
2. KeyboardProvider's context value was a new object literal every render.
Wrapped in useMemo to prevent unnecessary consumer re-renders.
3. Destructured useKeyboard() return in test to use stable callback refs
instead of the whole context object as useEffect deps.
Also: added root vitest.config.ts with workspace projects for mono-repo test runs.
2026-01-29 05:54:22 -06:00
Brad Groux
aa0c79e9ea
test: add k6 load testing suite with 5 scenarios
2026-01-29 05:09:14 -06:00
Brad Groux
5cfd9d88c2
fix(security): audit dependencies and add automated vulnerability scanning
2026-01-29 04:32:23 -06:00
Brad Groux
3edffec98c
chore: bump version to 1.0.0, add CHANGELOG
...
- Bump all 6 package.json files from 0.1.0 to 1.0.0
- Add CHANGELOG.md with full feature summary
- Git history scrubbed of security.json (JWT secret)
2026-01-29 01:42:04 -06:00
Brad Groux
3ebfa2c8b7
chore: add pre-commit hooks with husky + lint-staged
2026-01-28 17:17:40 -06:00
Brad Groux
b6fadfaa4c
docs: add security, performance, and quality audit reports
2026-01-28 16:59:09 -06:00
Brad Groux
615b9b03b4
feat(security): replace custom rate limiter with express-rate-limit
...
- Swap hand-rolled Map-based rate limiter for battle-tested express-rate-limit
- Built-in MemoryStore handles TTL cleanup automatically (no memory leaks)
- Uses sliding window counter algorithm instead of fixed window
- Emits both IETF draft-7 (RateLimit-*) and legacy (X-RateLimit-*) headers
- Remove duplicate inline rate limiter from settings.ts, use shared strictRateLimit middleware
- Redis not warranted for single-instance local dev tool
2026-01-28 12:22:34 -06:00
Brad Groux
58bfae2c25
RF-22: Add ESLint with TypeScript and React plugins
...
- Added ESLint flat config (eslint.config.js)
- Added @typescript-eslint/parser and plugin
- Added eslint-plugin-react and react-hooks
- Fixed ActivityItem naming collision in ActivitySidebar.tsx
- 0 errors, 141 warnings (existing code issues to fix over time)
- Rules: no-explicit-any (warn), no-non-null-assertion (warn), react-hooks/rules-of-hooks (error)
2026-01-28 06:31:53 -06:00
Brad Groux
39eccf3556
feat: Sprint US-1200 Refactoring batch — 13 tasks complete
...
Completed refactors:
- RF-02: Fix dependency vulnerabilities (xlsx → exceljs, Hono updates)
- RF-05: Add React error boundaries (FeatureErrorBoundary wrapper)
- RF-06: Server error handling middleware (AppError classes, asyncHandler)
- RF-10: Split shared types.ts into domain modules (6 files)
- RF-11: Consolidate frontend API layer (hooks now use api.ts)
- RF-13: TaskConfigContext — eliminate prop drilling
- RF-14: Split god components (GitSection, TaskDetailPanel, CreateTaskDialog, DiffViewer)
- RF-16: Frontend accessibility (ARIA labels, sr-only text)
- RF-17: Modularize CLI (899 → commands/ structure)
- RF-18: Modularize MCP (843 → tools/ structure)
- RF-19: Create shared API client library
- RF-21: Server performance (batch loading, memory limits, timeouts, graceful shutdown)
- RF-23: Extract shared utilities (path, format, constants)
Stats: ~59 files changed, significant code reduction through modularization
2026-01-28 06:08:59 -06:00
Brad Groux
45a5c37612
feat: complete US-102 (task parser) and US-103 (REST API)
...
- Task schema with full types in shared package
- TaskService with injectable paths for testing
- gray-matter for markdown frontmatter parsing
- 15 unit tests for parser/service
- Full CRUD API with zod validation
- Fixed undefined value handling in frontmatter
- Updated sprint tracking
2026-01-26 02:49:09 -06:00
Brad Groux
a489c5358f
feat: initial project scaffolding
...
- Dev container with Node.js 22
- pnpm workspace monorepo structure
- Express + WebSocket server
- React + Vite + shadcn/ui frontend
- Shared TypeScript types package
- Kanban board with drag-and-drop
- Task CRUD with file-based persistence
- Dark mode styling
Sprint 1 - US-101: Project scaffolding with dev container
2026-01-26 02:34:54 -06:00