Skip to content

staging → main: the dpp-web audit remediation - #18

Merged
LKSNDRTMLKV merged 186 commits into
mainfrom
staging
Oct 1, 2026
Merged

LKSNDRTMLKV merged 186 commits into
mainfrom
staging

Conversation

@LKSNDRTMLKV

Copy link
Copy Markdown
Member

Integration branch for the 2026-08 audit remediation. This is the promotion gate — main is what Cloudflare Pages publishes, so nothing reaches production without passing through here first.

Contains every branch from PRs #10, #13, #14, #15, #16 and #17, plus two CI fixes that could not be made on the individual branches. Each of those PRs remains open as the per-topic review record; this one is the thing that ships.

What changes for a reader of the site

  • An ESPR electronics delegated act that does not exist — with an adoption date, an effective date, four named product classes and two compliance windows — is off the site. One of its sentences told a named class of manufacturer they were already in breach of it.
  • Roughly twenty regulatory citations now match the Official Journal: the recycled-content annex, an invented A–E carbon-footprint class, the battery category set, the back-up-copy article, the retention figure ESPR does not state, and the construction, detergent and toy dates.
  • Four security-property claims now match the engine: the sandbox grants a pinned clock and OS randomness rather than denying both, the engine does hash on its own account, the database role holds one sanctioned DELETE grant, and nothing switches a determination on by date.
  • The registry is described as live, which it has been since 20 July 2026 — together with the two blockers that still stand between that and a registration succeeding.
  • The conformance claim against standards nobody here has read is retracted, and says why.
  • Licensing is published, without a restated dependency-licence table that had been wrong since 2024.

What changes for CI

Four gates, each tested against a known-bad input before being trusted: a link crawler over the built output, a leakage scan covering public/, an API-spec drift check, and a dependency audit. The workflow token is scoped to read-only.

The two CI fixes made here

The spec check was tied to another repo's moving main. That deadlocks any coordinated change — the web side cannot go green until the engine side merges, so neither can be reviewed on a green build — and lets an unrelated engine merge redden pull requests here. The vendored spec is now pinned to an explicit engine commit recorded in openapi-source.json, so the check is deterministic and self-contained, and bumping the pin is a reviewable line in a diff. A separate non-blocking step reports how far the pin is behind, because "the published spec is old" was the original finding and must stay visible.

A resync of an unmerged upstream change was reverted. The credential-standard correction belongs entirely to dpp-engine #140. It comes back here when that merges, via a pin bump.

Verification on this branch

pnpm -r build green · pnpm -r check 0 errors / 0 warnings / 5 hints · 824 internal links across 44 pages resolve · leakage clean · spec matches the pin · pnpm audit --audit-level critical passes.

Searched the built output for every retracted claim — 18 March 2026, 1 April 2026, foldable, Annex X minimum, no system clock, cannot delete rows, maintained conformance matrix, remains unpublished — zero files each.

Still open, deliberately

  • The privacy policy names no data controller. GDPR Art. 13(1)(a) requires one. Blocked on a registered entity existing; not something a copy edit reaches.
  • proxyUrl was verified statically, not at runtime. It stops the API reference relaying requests through a third party, and the claim is a privacy one — worth confirming in a browser before launch.
  • i18n (feat(landing,docs): i18n foundation, content de-dup, and de/it/fr/es #11) merges after this, so regulatory prose is corrected before it is translated into five locales.

dependabot Bot and others added 27 commits July 17, 2026 08:06
Bumps [vite-plugin-static-copy](https://github.com/sapphi-red/vite-plugin-static-copy) from 4.1.0 to 4.1.1.
- [Release notes](https://github.com/sapphi-red/vite-plugin-static-copy/releases)
- [Changelog](https://github.com/sapphi-red/vite-plugin-static-copy/blob/main/CHANGELOG.md)
- [Commits](https://github.com/sapphi-red/vite-plugin-static-copy/compare/vite-plugin-static-copy@4.1.0...vite-plugin-static-copy@4.1.1)

---
updated-dependencies:
- dependency-name: vite-plugin-static-copy
  dependency-version: 4.1.1
  dependency-type: direct:development
  update-type: version-update:semver-patch
...

Signed-off-by: dependabot[bot] <support@github.com>
Bumps [@tailwindcss/vite](https://github.com/tailwindlabs/tailwindcss/tree/HEAD/packages/@tailwindcss-vite) from 4.3.0 to 4.3.3.
- [Release notes](https://github.com/tailwindlabs/tailwindcss/releases)
- [Changelog](https://github.com/tailwindlabs/tailwindcss/blob/main/CHANGELOG.md)
- [Commits](https://github.com/tailwindlabs/tailwindcss/commits/v4.3.3/packages/@tailwindcss-vite)

---
updated-dependencies:
- dependency-name: "@tailwindcss/vite"
  dependency-version: 4.3.2
  dependency-type: direct:production
  update-type: version-update:semver-patch
...

Signed-off-by: dependabot[bot] <support@github.com>
Bumps [tailwindcss](https://github.com/tailwindlabs/tailwindcss/tree/HEAD/packages/tailwindcss) from 4.3.0 to 4.3.3.
- [Release notes](https://github.com/tailwindlabs/tailwindcss/releases)
- [Changelog](https://github.com/tailwindlabs/tailwindcss/blob/main/CHANGELOG.md)
- [Commits](https://github.com/tailwindlabs/tailwindcss/commits/v4.3.3/packages/tailwindcss)

---
updated-dependencies:
- dependency-name: tailwindcss
  dependency-version: 4.3.2
  dependency-type: direct:production
  update-type: version-update:semver-patch
...

Signed-off-by: dependabot[bot] <support@github.com>
ESPR Article 10 is Requirements for the digital product passport and defines no tiers; access is Art. 11(b), free of charge, with the actor-to-data mapping delegated per product group under Art. 9(2)(f) and no such act adopted yet, so the public Public/Restricted/Private tier page was wrong at its premise and is replaced by the Battery Art. 77(2) lattice plus the constraints common to every regime.
…ate per-passport-per-day count with no scanner-identifying field
…ng a removed product-category schema and an internal decision-record reference from published content
…d act that does not exist, and correct the ESPR sector table's electronics basis and unsold-goods article
…ne, and give the docs site the headers and robots file the landing site already had
# Conflicts:
#	site/dpp-docs/src/content/docs/regulatory/electronics.mdx
…istry status and access vocabulary against primary text and engine source
…retract the unverified standards-conformance claim, and correct the remaining landing and roadmap claims
…ocial config and the deprecated zod re-export
…ft check is deterministic and cross-repo changes are not deadlocked
…ected credential-standard version"

This reverts commit ec48fe3.
# Conflicts:
#	site/dpp-docs/src/content/docs/regulatory/electronics.mdx
# Conflicts:
#	.github/workflows/ci.yml
@cloudflare-workers-and-pages

cloudflare-workers-and-pages Bot commented Aug 20, 2026 •

Copy link
Copy Markdown

Deploying odal-node-docs with  Cloudflare Pages  Cloudflare Pages

Latest commit: ae70907
Status: ✅  Deploy successful!
Preview URL: https://5ed7a712.odal-node-docs.pages.dev
Branch Preview URL: https://staging.odal-node-docs.pages.dev

View logs

@cloudflare-workers-and-pages

cloudflare-workers-and-pages Bot commented Aug 20, 2026 •

Copy link
Copy Markdown

Deploying odal-node-landing with  Cloudflare Pages  Cloudflare Pages

Latest commit: ae70907
Status: ✅  Deploy successful!
Preview URL: https://970e1a1c.odal-node-landing.pages.dev
Branch Preview URL: https://staging.odal-node-landing.pages.dev

View logs

…stop restating the licence split on the introduction
…ytes the engine signed, and say why the dossier file lists the keys the other way round
… order they were signed, and fail the tests if a re-copy from the engine brings code-point order back
…corpus in signed key order, byte for byte, now that the engine writes it that way
…om the engine's regenerated corpus, and keep the canonicalisation keys in a dossier of their own
… that everything it stores stays on the operator's infrastructure
…nto shared pieces so the home page can reuse them, with no change to /passport-check
…ith the waitlist's three questions and a visible tag naming the page it came from
…able checklist of what to have ready, ungated, ending in an email to us
… main action for buyers beside the docs and three licence facts under them
…passport check, keeping the new copy, both actions and the licence facts, and drop the pieces only the hero check used
…he public GitHub discussions and says where bugs, security reports and confidential questions go instead
…e the project instead of a note on reply times
…module so the home page can show part of it, with no change to /example-passport
…e and from every passport-check answer that needs a passport
…s, a flow of where each step happens, standards with their status, the two licences and where the roadmap stands
…ider status label, and fold the data-and-key line into the hero's subtitle
…f the code, the planning documents and the standards landscape, and group what is being considered by theme
…aining, and say that credentials follow the W3C standard and that six of eight passport standards are cited
…-group checklists and the roadmap and glossary additions.
… and the stale lines a full scan of staging found
… injecting its bot-detection script and cookie
@LKSNDRTMLKV
LKSNDRTMLKV marked this pull request as ready for review October 1, 2026 11:42
@LKSNDRTMLKV
LKSNDRTMLKV merged commit d1de55b into main Oct 1, 2026
3 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant