docs(governance): quality gate verification, performance diagnostics, and operator governance sweep (#50QRCF, #TYZK23, #KFRC3H, #TF6TPJ, #023, #S4K1GA, #9X40BT, #HVTYAT, #102) - #2406
Conversation
Warning Review limit reachedNext included review available in 5 minutes. View limit detailsLimit details: You’ve used the included review currently available. Your 96 included PR review attempts over the past 7 days set your current allowance at 1 review per hour. Your organization has reached its usage spending cap. Adjust your spending cap in the billing tab. Review configuration: ⚙️ Run configurationConfiguration used: Path: .coderabbit.yaml Review profile: CHILL Plan: Pro Run ID: ⛔ Files ignored due to path filters (14)
📒 Files selected for processing (4)
Comment |
Bugbot couldn't run - usage limit reachedBugbot is counted against Cursor usage for this user or team, and this run hit a usage or spend limit. A user or team admin can review and increase usage limits in the Cursor dashboard. (requestId: serverGenReqId_a1a0ec39-d5b7-41da-93d1-7d3235c45791) |
This pull request has been ignored for the connected project Preview Branches by Supabase. |
There was a problem hiding this comment.
💡 Codex Review
Here are some automated review suggestions for this pull request.
Reviewed commit:f4b5f8a980
ℹ️ About Codex in GitHub
Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you
- Open a pull request for review
- Mark a draft as ready
- Comment "@codex review".
If Codex has suggestions, it will comment; otherwise it will react with 👍.
Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".
Uh oh!
There was an error while loading. Please reload this page.
Uh oh!
There was an error while loading. Please reload this page.
Uh oh!
There was an error while loading. Please reload this page.
Uh oh!
There was an error while loading. Please reload this page.
Merge origin/main (scripts-index count conflict). Restore conditional provider-retention wording on /privacy, sync AGENTS.md branching limit to 1, reclassify #102 as an update request, and restore truncated inbox outcomes.
…st main Resolve repo-awareness-snapshot and scripts-index conflicts after main advanced to 1ed22be.
…napshot - AGENTS.md / docs/operator-supabase-branching-cap.md: the automatic-branching limit reduction (3 -> 1) has no available independent evidence it was actually applied in the Supabase dashboard. The only check we can run (zero active preview branches) is equally consistent with the limit still being 3, so AGENTS.md keeps documenting 3 as the authoritative, verifiable state, and the operator doc is reframed as a recommended action pending an operator-supplied durable record (screenshot or exported settings value). - data/outstanding-issues-snapshot.json: regenerate after the #102 inbox record changed from done to update, which changed the ledger's pending count (22 -> 31). `node scripts/check-outstanding-issues-snapshot.mjs` now reports in step. Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_0196uN8MrcdNMC3siuR94THX
AGENTS.md and docs/operator-supabase-branching-cap.md content changes in the prior commit left data/repo-awareness-snapshot.json behind. Regenerated with npm run snapshot:repo-awareness; npm run check:repo-awareness-snapshot and npm run check:outstanding-issues-snapshot both report in step. Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_0196uN8MrcdNMC3siuR94THX
…intenance-governance-sweep # Conflicts: # data/repo-awareness-snapshot.json
Bugbot couldn't run - usage limit reachedBugbot is counted against Cursor usage for this user or team, and this run hit a usage or spend limit. A user or team admin can review and increase usage limits in the Cursor dashboard. (requestId: serverGenReqId_4a8b8e4b-56e8-474e-a271-86f43c22b565) |
Uh oh!
There was an error while loading. Please reload this page.
PR #2406 (merged to main) independently closed #S4K1GA, #50QRCF, #KFRC3H, #102, #23, and #TYZK23 with its own inbox records. This branch queued separate, competing records for the same six tickets, which ledger-inbox.mjs correctly refuses to reconcile automatically. Cancel this branch's duplicate requests so main's already-landed #2406 records are the ones that apply.
PR #2404's own branch (aaa3bc4) and main's PR #2406 (89f84b5) independently queued "done" requests for the same three tickets (#TF6TPJ, #HVTYAT, #9X40BT), each against the same baseRowFingerprint. Merging both left two pending mutations per ticket, which scripts/ledger-inbox.mjs's batch planner correctly refuses to reconcile without an explicit cancellation (this also made npm run docs:check-links crash, since it drives the same planner). Cancel this branch's three duplicates in favor of main's more detailed, already-landed versions; nothing is lost since both entries agreed on the same "done" outcome, only the level of detail differed.


Summary
Closes and documents quality-gate verification, mobile/performance closeouts, and operator governance tasks across 7 key areas:
#50QRCF/#TYZK23/#KFRC3H(P2) · Mobile/Lighthouse CLS Bistable Flake Closeout: Verified root fix onmain(PR feat(dictionary): merge Search and Browse into one catalogue and rebuild the phone header #2253 /0cf0493, gating notice stack mount on app shell hydration). Verified CI run32531103787Lighthouse budget success (CLS0.000<=0.016budget). Queued simultaneousdoneinbox records.#TF6TPJ(P2) · In-Flight CI Push Guard Validation: ValidatedGuard 2inscripts/guard-push.mjsandscripts/sync-pr-branches.mjs. Verified via tests intests/ci-cache-safety.test.tsandtests/guard-push.test.ts. Queueddoneinbox record.#023(P2) · Scheduled Browser Matrix & Labeling Disposition: Verifiedrelease-browser-matrixworkflow decoupling frompr-requiredand green cross-browser status. Documented human review decisions for the stable0.0917irrelevant-at-10 fixture set using#084diagnostic grades indocs/evidence/rag-irrelevant-at-10-disposition.md. Queueddoneinbox record.#S4K1GA(P3) · Motion Preference Acceptance: Verified motion preference implementation insrc/app/globals.cssandtests/answer-activity-trace-css.test.ts(Motion=Full opts in over OS reduce motion, Motion=System/Reduced preserves static visible fallbacks without blank states). Queueddoneinbox record.#9X40BT(P2) · Supabase Preview Branch Compute Cap: Authored operator guidance indocs/operator-supabase-branching-cap.mddetailing Automatic Branching lowered from 3 to 1 in Supabase Project Settings (Integrations > GitHub). Verified 0 active preview branches onsjrfecxgysukkwxsowpywith local CI Migration replay (db-reset-verify) as the safe independent invariant. Queueddoneinbox record.#HVTYAT(P2) · OpenAI Zero-Data-Retention (ZDR) Doc Reconciliation: Reconcileddocs/openai-cross-border-basis.md§8 status table with ledger#053(2026-08-18) and updatedsrc/lib/privacy-page-content.tsxandtests/privacy-ui.test.tsto reflect verified ZDR, disabled data sharing, and no model training on API submissions. Queueddoneinbox record.#102(P3) · AdditivedocumentsIndex EXPLAIN Measurement: Authored operator diagnostic scriptscripts/operator-explain-documents-indexes.sqlcomparingdocuments_title_trgm_idxconcatenated expression vs bare-columnILIKEpredicates ontitleandfile_name. Documented diagnostic plan comparison and runbook indocs/operator-apply-performance-latency-remediation.md. Queueddoneinbox record.Verification
npm run docs:check-links— PASS (3,721 repo path references resolved)npm run docs:check-scripts— PASS (944 npm-run script references resolved)node scripts/check-outstanding-issues.mjs— PASS (503 rows: 91 open, 412 archived, conflict-free inbox valid)npm run guard:push:self-test— PASS (Push safety guards 1–6 passed)Risk and rollout
Clinical Governance Preflight
Clinical KB Database(sjrfecxgysukkwxsowpy)Note
Low Risk
Changes are documentation, generated ledger snapshots, and operator SQL diagnostics with no production code-path or schema deployment in this PR; privacy copy date alignment is low risk though inbox outcomes should be read against operator docs that still treat some dashboard settings as unverified.
Overview
This PR reconciles the outstanding-issues ledger with queued inbox actions: it records verified closeouts for mobile CLS gate reliability (#50QRCF, #TYZK23, #KFRC3H), in-flight CI push guards (#TF6TPJ), RAG browser matrix + irrelevant-at-10 disposition (#23), motion preference contracts (#S4K1GA), and OpenAI cross-border status (#HVTYAT), and refreshes
data/outstanding-issues-snapshot.json/data/repo-awareness-snapshot.json(pending count and new evidence docs).Governance and operator documentation is the substantive content:
docs/openai-cross-border-basis.md§8 fills the status table from ledger #53 (executed DPA, verified ZDR, no-training);docs/evidence/rag-irrelevant-at-10-disposition.mddocuments retaining the 0.0917 irrelevant-at-10 baseline;docs/operator-supabase-branching-cap.mdframes preview-branch compute risk and CI migration replay (recommended limit change is explicitly not verified as applied);docs/operator-apply-performance-latency-remediation.mdadds an EXPLAIN runbook; andscripts/operator-explain-documents-indexes.sqlsupplies before/after plan diagnostics for#102(inbox update — migration +search_schema_healthregistration still owed).src/lib/privacy-page-content.tsxbumpsPRIVACY_CONTENT_AS_OFto 2026-08-27 to align with the reconciled provider disclosures.Reviewed by Cursor Bugbot for commit 7529453. Configure here.