Skip to content
Closed
3 changes: 3 additions & 0 deletions docs/branch-review-ledger.md
Original file line number Diff line number Diff line change
Expand Up @@ -953,6 +953,7 @@ This file is append-only. Never rewrite or delete an existing review record; app
| 2026-07-25 | open-pr-babysit-continuation-20260725 | multipass | Babysit continuation after 14 merges: #1177 landed; #1174/#1178/#1153 in progress; drafts #1187/#1192 skipped; large cluster #1162/#1185/#1186/#1188/#1190 content-conflicted (skip). | merge-tree inventory; no provider-backed checks. |
| 2026-07-25 | audit-remediation (PR #1153) | 5a731df5c25fed9b07fd2321a0ad4b6519471f4b | PR babysit: CodeRabbit thread fixes + merge | Before: MERGEABLE/BLOCKED on required_review_thread_resolution + pending CI; 6 CodeRabbit threads. After: fixed sync-skills pad/YAML escape, PDF temp cleanup, squash-aware rollback wording; dispositioned ledger mid-table + retained false-positive; approved CI; merged to main `191b17d2f` (merge commit); branch deleted; tip is ancestor of main. | Hosted CI green on tip; no provider-backed checks. |
| 2026-07-25 | cursor/local-presence-054-7cf3 (PR #1178) | 9135891bfd194394549cb480a7ec86de12b23ee7 | PR babysit: local-presence + /tools + CI/UI fixes + squash merge | Before: flaky Safety audit on package.json scripts, Production UI Sources autofocus flake, CodeRabbit short-env duplicate thread. After: ci-change-scope lockfile-only; strip stale short env keys; sheet open-focus retries + skip focus=1 reclaim under modal; squash-merged `d08ec2e8e`; branch deleted; key-file content-diff empty. | Hosted PR required SUCCESS (Production UI green on tip); focused local-presence vitest; no provider-backed checks. |
| 2026-07-25 | cursor/formulation-contrast-reconcile-14d4 | 5696d11416f5752b2cbb7ef0331fa29427b12d5c | #064 clean-room formulation disabled-state reconciliation and local review | No P0/P1 findings. Native `disabled` semantics remain intact; opacity-only styling was replaced by explicit disabled surfaces, and focused coverage proves disabled/focus/enabled-transition/axe behavior. Historical `agent/formulation-disabled-contrast` source remains untouched but unavailable, so the issue is deferred rather than claimed landed. Residual verification blocker is environment-only: system Chrome reports PWA `in-incognito`, and managed WebKit is absent. | Focused Chromium 2/2; full formulation Chromium 7/7; `verify:cheap` 3,377/3,377; `verify:ui` 271/272 with unrelated PWA installability environment failure; manual desktop/390px flow passed. No provider-backed checks. |
| 2026-07-25 | cursor/search-correctness-030-075-6273 (PR #1177) | 96ba61520aeea59647dcaec6671ccb82618553ef | CORRECTION: real SHA for the 2026-07-24 post-sync #1177 row | That row recorded `96ba6152c1f8e5e0000000000000000000000000`, a zero-padded placeholder that resolves to no Git object. The real commit is `96ba61520aeea59647dcaec6671ccb82618553ef` ("ci: remove PR_POLICY_BODY.md after sync"); the reviewed outcome itself is unchanged. | `git rev-parse` verification; `npm run check:branch-review-ledger` pass; no provider-backed checks run. |
| 2026-07-25 | cursor/eval-matching-distinct-identity-6273 | f5620e3a4a2d60fd8a67fd43d8046726f1761e5f | Self-review of the merged #030/#075 fixes against current main | Before: merged coverage matched expectations to distinct source *positions*, so one document repeated across `answer.citations` still filled both comparison slots, and first-come assignment made `allHit` depend on `expectedFiles` order; `PR_POLICY_BODY.md` was back on main (via #1153) ready to overwrite the next PR body; the #030/#075 queue row survived their archival. After: coverage dedupes by document text and assigns by maximum bipartite matching, label accumulation is linear, the stale template is removed, and #080 records the removed admission widening for approved eval re-test. Both new contracts were verified failing against main's matcher before the fix. RAG impact: no retrieval behaviour change — eval matching and label bookkeeping only. | Focused Vitest 39/39 (eval-document-matching, eval-utils, eval-search, search-scope, rag-imputation-contract); fail-closed proof 2 failed on the `origin/main` matcher; `npm run verify:cheap` pass (3379 passed, 5 skipped); `check:branch-review-ledger` and `check:pr-policy` pass; no OpenAI/Supabase/provider-backed checks run. |
| 2026-07-25 | execute-audit-code-remediation (PR #1162) | d5455837231f5cb6a927e8c4752ef5aa9c72767c | Merge conflict + CI + Bugbot review | Merged origin/main (164 behind). Fixed conflicts in ClinicalDashboard/global-search-shell/mode-home/search-scope/tests/pdf extractor. Renamed duplicate migration 20260724120000→20260724130200. CI: skills openai.yaml, owner-scope setup-status exemption, sitemap, drift hash, answer-render duplicate key, setup-status mock `.eq`. Bugbot: fixed Codex P1 view-only indexing + P2 differential back; also fixed P2 viewer visibility for retained images and duplicate-upload cleanup ledger fail-closed. | Focused Vitest (back-href/worker/skills/setup-status/owner-scope/drift/sitemap/search-scope/favourites/forms/therapy/document-detail/upload-ledger) + typecheck + check:skills/migration-role/sitemap; no provider-backed checks. |
Expand All @@ -961,5 +962,7 @@ This file is append-only. Never rewrite or delete an existing review record; app
| 2026-07-25 | execute-audit-code-remediation (PR #1162) | b9b56c140eb14cbba5a2c2230e3fa28d3a791add | CI unblock after bot sync | Tip 96188eca had PR required SUCCESS (Static/Safety/Unit/Build/Migration/Production UI). Hosted pr-branch-sync then merged main (a420b86b/b9b56c14), leaving CI action_required for bot-authored runs. Pushing agent commit to re-trigger non-bot CI. | Prior tip 96188eca hosted CI green; local services referral Playwright PASS; no provider-backed checks. |
| 2026-07-25 | PR supersede #1186 / `cursor/pr1186-audit-remediation-c94c` | `a38e83860510a4229d5658960657cd7448aff278` | Clean main-based port of intentional #1186 audit fixes | SUPERSEDE #1186 (do not merge old PR). Ported intentional 16-file delta onto current main; dropped conflicted checkpoint tree and placeholder skills. Fixed eval single results binding; async run-heavy so lock heartbeat fires; branch:cleanup dry-run default + argv-safe deletes; skill-create interface YAML. Close #1186. | Focused Vitest tooling+lock 6/6; check:skills 33; prettier on touched files; no provider/live eval runs. |
| 2026-07-25 | `cursor/ledger-066-067-519b` | f04392a408eceee14215c15169cbd6b70ac2041c | Close stale ledger #066/#067 (+ drop resolved #030/#075 from queue) | READY. #066 proven on main via #1174; #067 already fixed in #1191 in-process preflight. Docs-only ledger sync; no code change. | Local proof: `git show`/`log` for #1174/#1191; preflight test already in-process on main; ledger integrity asserts. No providers. |
| 2026-07-25 | cursor/formulation-contrast-reconcile-14d4 | c22c028e4b60900b8c2e5d114f5ed6ba501dcf6a | #064 post-main-sync PR-readiness review | No P0-P2 findings from independent frontend/accessibility and regression reviews. Unique diff remains four files; native disabled semantics, design tokens, forced-colors behavior, and enabled transitions are preserved. Historical `agent/formulation-disabled-contrast` remains untouched and unavailable. Branch is locally PR-ready subject to clean managed-browser CI. | Post-merge focused Chromium 2/2; formulation Chromium 7/7; `verify:cheap` 3,401/3,401; `verify:ui` 272/273 with only system-Chrome PWA `in-incognito`; two independent reviews; no provider-backed checks. |
| 2026-07-25 | execute-audit-remediation-plan (PR #1188) | 8b8639113925601e1687bfe4f1f29c44a4308b61 | Bugbot/diff-review: maintainability remediation tip | BLOCK: tip tree carries unresolved conflict markers (answer/upload APIs, clinical-dashboard, services, tests); invalid `async export function sha256Hex` in indexing-v3 utils; ClinicalDashboard still calls removed `renderSystemNotice`; merge-tree vs main conflicts in check-github-action-pins.mjs + ui-primitives.tsx. Intended notices extraction/dynamic imports look mostly sound; search-scope/migration not in three-dot product delta. | `git grep` conflict markers on tip (none on origin/main); `git show` for ClinicalDashboard:3824 + utils.ts:191; `git merge-tree --write-tree origin/main 8b8639113`; no provider-backed checks. |
| 2026-07-25 | PR #1209 / `cursor/pr1186-audit-remediation-c94c` | `4cb22e45dfe46b1975fa15ddd028c7e14ceb5fab` | Close #1186 + babysit #1209 CI | DONE. Closed #1186 as superseded. Synced origin/main (MERGEABLE/CLEAN). Fixed PR-policy RAG impact line. Hosted PR required SUCCESS (Static/Safety/Unit/Build/Production UI/Advisory UI/containers) on pre-ledger tip; docs-only follow-up pushed. Ready to merge; auto-merge not enabled. | gh pr checks; local policy ok; no provider/eval runs. |
| 2026-07-25 | cursor/formulation-contrast-reconcile-14d4 | 50bed6ebe8e23cfceb802c3181658208d904d168 | #064 final fetched-main readiness confirmation | Fresh `origin/main` merged without changing the four-file unique diff. Prior independent reviews remain applicable with no P0-P2 findings; branch is ready to open and must not merge until hosted required checks are green. | Focused Chromium 2/2; `verify:cheap` 3,419/3,419; `verify:pr-local` passed with build, client-secret scan, and offline RAG fixtures; no provider-backed checks. |
2 changes: 1 addition & 1 deletion docs/outstanding-issues.md
Original file line number Diff line number Diff line change
Expand Up @@ -94,7 +94,7 @@ removed after current-main verification; it is not missing recommended work.
| ID | Pri | Type | Summary | Detail / next action | Source | Added |
| ---- | --- | ----- | --------------------------------------------------------------- | --------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | --------------------------------------------------------------------------------------------------------------------------------------- | ---------- |
| #059 | P1 | task | Verify containment of every credential reported exposed in chat | **Outcome:** every reported exposed credential is rejected or retired. **Next:** in approved security windows, verify and revoke or rotate the GitHub token, OpenAI key, Supabase service-role JWT, database password, and E2E credential; create replacements only when required and update only intended secret stores. **Success:** provider evidence confirms the old credentials cannot authenticate, replacements are distinct and minimally scoped, presence/readiness checks pass, and secret scans remain clean. **Stop:** no provider or secret-store action without approval; never print or paste values into Git, logs, issues, or chat. | session 2026-07-24 security reconciliation; AI Agent Target Manifest | 2026-07-24 |
| #064 | P2 | task | Reconcile the preserved browser and contrast patch | **Outcome:** the isolated dirty formulation/contrast patch is safely landed or explicitly dispositioned. **Next:** rebase its intent against current `main` without overwriting the worktree, then run focused Playwright coverage and `verify:ui`. **Success:** intended disabled/contrast behavior is accessible, browser assertions remain meaningful, and unrelated work is preserved. **Stop:** do not discard or auto-merge the dirty worktree; pause on ambiguous ownership or scope. | `agent/formulation-disabled-contrast`; session 2026-07-24 | 2026-07-24 |
| #064 | P2 | task | Reconcile the preserved browser and contrast patch | **Prepared for PR 2026-07-25:** current `origin/main` is merged at `c22c028e`; two independent reviews found no P0-P2 issue. Clean-room commit `5696d114` replaces opacity-dependent disabled styling and adds native-disabled/focus/axe coverage; the unavailable historical worktree remains untouched. Post-merge focused Chromium passes 2/2, all formulation journeys pass 7/7, and `verify:cheap` passes 3,401 tests. `verify:ui` is 272/273 because system Chrome reports the unrelated PWA `in-incognito`; managed WebKit remains unavailable locally. **Next:** open the PR and require clean managed-browser CI before merge. **Stop:** do not merge with required UI checks red, weaken PWA/access-control assertions, or alter the historical worktree without authorization. | `agent/formulation-disabled-contrast`; `cursor/formulation-contrast-reconcile-14d4`; commits `5696d114`, `c22c028e`; session 2026-07-25 | 2026-07-24 |
| #065 | P2 | task | Complete the paused compact document source-text accordion | **Outcome:** the document viewer uses compact nested disclosures while retaining complete text, citation/search navigation, print behavior, and composer clearance. **Next:** only when the user explicitly resumes, reconcile `codex/chat-document-text-accordion-7cb4` with current `main` and complete the focused 320/390/1280 px tests. **Success:** default disclosures are closed; deep links and search open only the active passage; printing expands/restores state; no overflow. **Verify:** focused document-viewer Playwright, `verify:cheap`, `verify:ui`, and static production-readiness. **Stop:** remain paused until explicit user return; no provider calls. | paused document-viewer task; `codex/chat-document-text-accordion-7cb4` | 2026-07-24 |
| #051 | P2 | task | Stabilise the live answer-quality canary before more RAG tuning | Diagnostics landed in PR #1095: structured JSON/Markdown artifacts now record the actual checked-out SHA, run identity and latency context, and the offline trend tool separates content, provider-route and latency outcomes. First validating run `30018289898` recorded the expected tree and cost, with 36/36 retrieval green, but one report cannot establish variability; PR #1097 prevents a single failure being mislabeled as repeated. Next: compare the scheduled 2026-07-26 structured report with this run. Do not spend on an immediate retry or reapply the archived lithium guard before that comparison. | PR #1095; run `30018289898`; PR #1097; archive ref `refs/archive/rejected-rag/20260723/monitoring-subject-gate` | 2026-07-23 |
| #001 | P2 | task | Semantic reranking still gated off | `RAG_SEMANTIC_RERANK_ENABLED=false` from PR #901. Do not enable until the provider-backed 36/36 retrieval-quality gate **and** an ambiguity-focused canary are explicitly approved and recorded. | `docs/process-hardening.md` (Semantic reranking rollout debt); PR #901 | 2026-07-21 |
Expand Down
4 changes: 2 additions & 2 deletions src/components/formulation/formulation-builder-page.tsx
Original file line number Diff line number Diff line change
Expand Up @@ -678,7 +678,7 @@ export function FormulationBuilderPage({
type="button"
onClick={() => move(-1)}
disabled={activeIndex === 0}
className="inline-flex min-h-tap items-center gap-2 rounded-lg border border-[color:var(--border-strong)] bg-[color:var(--surface)] px-4 text-sm font-bold text-[color:var(--text-muted)] disabled:opacity-40"
className="inline-flex min-h-tap items-center gap-2 rounded-lg border border-[color:var(--border-strong)] bg-[color:var(--surface)] px-4 text-sm font-bold text-[color:var(--text-muted)] disabled:cursor-not-allowed disabled:border-[color:var(--border)] disabled:bg-[color:var(--surface-inset)]"
>
<ArrowLeft className="h-4 w-4" aria-hidden />
Previous
Expand All @@ -688,7 +688,7 @@ export function FormulationBuilderPage({
type="button"
onClick={() => move(1)}
disabled={activeStep === "select" && selectedMechanisms.length === 0}
className="inline-flex min-h-tap items-center gap-2 rounded-lg bg-[color:var(--command)] px-4 text-sm font-bold text-[color:var(--command-contrast)] shadow-[var(--shadow-tight)] disabled:cursor-not-allowed disabled:opacity-45"
className="inline-flex min-h-tap items-center gap-2 rounded-lg border border-transparent bg-[color:var(--command)] px-4 text-sm font-bold text-[color:var(--command-contrast)] shadow-[var(--shadow-tight)] disabled:cursor-not-allowed disabled:border-[color:var(--border)] disabled:bg-[color:var(--surface-inset)] disabled:text-[color:var(--text-muted)] disabled:shadow-none"
>
{activeStep === "select"
? "Continue to framework"
Expand Down
Loading
Loading