Skip to content

docs(forensics): §3.7 production window — five 20260818 migrations found already applied by the Supabase GitHub integration; db push not run - #2123

Merged
BigSimmo merged 4 commits into
mainfrom
claude/clinical-kb-prod-migration-db4aab
Aug 18, 2026
Merged

docs(forensics): §3.7 production window — five 20260818 migrations found already applied by the Supabase GitHub integration; db push not run#2123
BigSimmo merged 4 commits into
mainfrom
claude/clinical-kb-prod-migration-db4aab

Conversation

@BigSimmo

Copy link
Copy Markdown
Owner

Summary

  • Appends §3.7 Production window to docs/audit/live-drift-forensics-2026-08.md. The owner authorised one production supabase db push window for exactly 20260818090000, 110000, 111000, 112000, 113000 against Clinical KB Database (sjrfecxgysukkwxsowpy), conditional on supabase migration list showing exactly those five pending. The pending set was empty — all five were already applied with executed statements (3/11/12/5/4, the CLI's per-statement shape, not the mark-applied shape) — so db push was not run, no migration repair/mark-applied path was used, no vault secret was read, staging was not touched, and production received zero writes.
  • Records the read-only verification: schema_drift_snapshot() v2 live (snapshot_version 2, probe ok, the expected 20 migration_history rows — nothing allowlisted); ten work_mem rows at the D1 values; live-drift run 32131517648 with zero function def_hash mismatches, 20 missing_live, 2 unexpected_live, 15 migration_history findings.
  • Records the finding for the coordinator (not absorbed): supabase branches list shows the production project bound to git branch main, and the push-triggered live-drift runs bracket the application to within 34 s of feat(db): codify live SET work_mem on the ten match_* RPCs, the eight schema-only objects, and three chain-stale columns (#316) #2106's squash-merge — the Supabase GitHub integration applies merged migrations to production automatically. Owner decision needed on keeping/disabling it; Phase 4 must not rely on create index concurrently inside an auto-db push.
  • Adds the immutable branch-review record for this branch (docs/branch-review-records/9f07fe8e….record.md).

Verification

  • npm run verify:pr-local — docs route: completed: check:runtime, check:installed-lock-parity, format:changed, sitemap:check, docs:check-index, docs:check-inventory, docs:check-scripts, docs:check-links, check:branch-review-ledger, check:outstanding-issues, check:ledger-write-discipline · failed: (none) · not reached: (none).
  • UI verification not run: docs-only change, no UI, routing, or styling touched.
  • Provider reads made under the owner's explicit window authorisation: supabase migration list --linked, four read-only supabase db query --linked SELECTs, supabase branches list, and GitHub reads of three live-drift run logs. No provider writes.

Risk and rollout

  • Risk: none to production — documentation and one review-record file only.
  • Rollback: revert the squash commit.
  • Provider or production effects: None from this PR. The window's authorised db push was deliberately not executed because the pending set differed from the authorisation.

Clinical Governance Preflight

  • Source-backed claims still require linked source verification before clinical use
  • No patient-identifiable document workflow was introduced or expanded without explicit governance approval
  • Supabase target remains Clinical KB Database (sjrfecxgysukkwxsowpy)
  • Service-role keys and private document access remain server-only
  • Demo/synthetic content remains clearly separated from real clinical sources
  • Source metadata, review status, and outdated/unknown-source behavior remain conservative
  • Deployment classification/TGA SaMD impact was checked when clinical decision-support behavior changed

Notes

🤖 Generated with Claude Code

BigSimmoand others added 2 commits August 18, 2026 21:47
…und already applied by the Supabase GitHub integration; db push not run
Owner-authorised production window for 20260818090000/110000/111000/112000/113000
against sjrfecxgysukkwxsowpy. Pre-flight `supabase migration list` showed the pending
set was empty, so per the authorisation condition `supabase db push` was not run and no
mark-applied path was used. Read-only verification: all five history rows carry executed
statements (3/11/12/5/4), schema_drift_snapshot() v2 probe ok with the expected 20
history rows (nothing allowlisted), ten work_mem rows at the D1 values, and live-drift run
32131517648 shows zero function mismatches / 20 missing_live / 2 unexpected_live / 15
migration_history findings. Timing across the push-triggered live-drift runs (applied 34 s
after #2106 merged) plus `supabase branches list` (production bound to git branch main)
shows the Supabase GitHub integration applies merged migrations to production on merge —
recorded as an owner decision for the coordinator, not absorbed.
Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
@chatgpt-codex-connector

Copy link
Copy Markdown

You have reached your Codex usage limits for code reviews. You can see your limits in the Codex usage dashboard.
To continue using code reviews, add credits to your account and enable them for code reviews in your settings.

@supabase

supabaseBot commented Aug 18, 2026

Copy link
Copy Markdown

This pull request has been ignored for the connected project sjrfecxgysukkwxsowpy because there are no changes detected in supabase directory. You can change this behaviour in Project Integrations Settings ↗︎.


Preview Branches by Supabase.
Learn more about Supabase Branching ↗︎.

@coderabbitai

coderabbitaiBot commented Aug 18, 2026

Copy link
Copy Markdown
Contributor

Warning

Review limit reached

You’ve reached a temporary PR review limit under our Fair Usage Limits Policy.

Your recent review volume is higher than typical usage, so adaptive limits are currently applied.

Next review available in:7 minutes

Limit details: You’ve used all 1 included review currently available under your plan. You completed 101 included PR reviews in the past 7 days; at that activity level, included reviews refill at 1 review per hour.

Your organization has reached its usage spending cap. Adjust your spending cap in the billing tab.

How can I continue?

After more reviews become available, a review can be triggered using the @coderabbitai review command as a PR comment. Alternatively, push new commits to this PR.

To avoid repeated limits, reduce automatic review volume by pausing incremental auto-reviews earlier, using label-based review opt-in, excluding WIP or generated PR titles, or requesting reviews manually when the PR is ready. If your team needs uninterrupted high-volume reviews, an organization admin can enable usage-based reviews.

How do review limits work?

CodeRabbit enforces per-developer PR review limits for each organization. Most developers receive the normal plan review availability.

For paid Pro and Pro+ PR reviews, CodeRabbit uses adaptive limits for sustained high-volume activity. When a developer's recent PR review activity reaches the 95th percentile or higher among CodeRabbit users, additional reviews become available more gradually as earlier reviews age out of the rolling window.

Please refer docs for additional details.

Review details
⚙️ Run configuration

Configuration used: Path: .coderabbit.yaml

Review profile: CHILL

Plan: Pro

Run ID: ac89f5c4-bd6b-4d52-8022-808e31a125d1

📥 Commits

Reviewing files that changed from the base of the PR and between 5d5ff89 and 37b0ac7.

📒 Files selected for processing (2)
  • docs/audit/live-drift-forensics-2026-08.md
  • docs/branch-review-records/9f07fe8e5559d62b5ddb863fad587daa01b7dd770ef8b4101d3cedabdbb7fb69.record.md

Comment @coderabbitai help to get the list of available commands.

@BigSimmo
BigSimmo merged commit 17cdd46 into mainAug 18, 2026
23 checks passed
@BigSimmo
BigSimmo deleted the claude/clinical-kb-prod-migration-db4aab branch August 18, 2026 14:59
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant

@BigSimmo