Release Notes
Public Deployment History
WarpIntel release notes are public-safe by design. They show what changed, how it was verified, and which safety boundaries stayed intact without exposing credentials, private EVE data, raw logs, or account data.
EVE SSO Owner Proof Targets
Public-safe release entries in this page.
Only public routes, short commits, deployment ids, and verification classes are listed.
EVE SSO Owner Proof Targets
Added no-secret owner-run proof targets to the public EVE SSO launch/readiness surfaces, public health snapshot, and production smoke gates so the eventual controlled EVE sign-in smoke has route-based proof without starting OAuth, exchanging tokens, calling protected provider state, exposing credentials, EVE tokens, private EVE data, account data, raw submissions, protected setup packet contents, private logs, or separate-project details.
- Date: 2026-06-23
- Commit: fbbd7d1
- Deployment: dpl_BGiBU6h1fMGDAYbUyntVi2BQyqpg
Verification
- Type check
- Full test suite
- Production build
- Production live smoke
Safety
- The EVE SSO proof-target release note exposes only public readiness links, safe route labels, the short commit, deployment id, verification classes, and sanitized safety summaries
- The EVE SSO launch page and JSON readiness feed now expose ten owner-run proof targets with expected outcomes only
- Each proof target is marked no-OAuth and no-private-data so the first controlled owner-run login smoke can be rehearsed without starting provider authorization
- Public health and production smoke now verify the owner proof-target count while keeping EVE client IDs, client secrets, access tokens, refresh tokens, cookies, authorization headers, provider console state, and private EVE data out of public output
- Production live smoke verifies /eve-sso-launch, /api/auth/eve/readiness, /permissions/preview, public health/status counters, release-readiness links, no-secret text boundaries, and the expected production commit
Public Release Safety Gate
Added a runtime release-readiness gate for internal project labels, private account labels, and separate-project labels, sanitized historical public release wording, and added regression tests so the public release feed moves to review if unsafe public release text returns without exposing credentials, EVE tokens, private EVE data, account data, raw submissions, protected setup packet contents, private logs, or separate-project details.
- Date: 2026-06-23
- Commit: eb718a4
- Deployment: dpl_5Sm26Qt8JN9hbEt8zGGGp6AXDS31
Verification
- Type check
- Full test suite
- Production build
- Production live smoke
Safety
- The release safety-gate note exposes only public readiness links, the short commit, deployment id, verification classes, and sanitized safety summaries
- Release-readiness checks now treat internal project labels, private account labels, and separate-project labels as unsafe public release text
- The regression coverage proves the public release-readiness feed moves to review when unsafe labels appear in release summaries
- Historical public release wording now uses public-safe project-owner and build-team labels instead of private internal names
- Production live smoke verifies /releases, /api/releases, release-readiness feeds, public health/status counters, no-secret text boundaries, and the expected production commit
Public External Setup Readiness
Added a public external setup readiness page, machine-readable external setup feed, navigation and sitemap discovery, public health counters, monitoring counters, SEO readiness coverage, and production live-smoke gates so project-owner account work, provider review blockers, protected setup packet coverage, proof targets, activation criteria, and build-while-blocked lanes can be reviewed from public no-secret surfaces without exposing protected setup packet bodies, provider credentials, API keys, passwords, EVE tokens, private EVE data, account data, raw submissions, provider cookies, private logs, or separate-project account details.
- Date: 2026-06-23
- Commit: 71d2d0a
- Deployment: dpl_GFKSHPi8Q5Zb7JLotuwC3Ckq9ibf
Verification
- Type check
- Full test suite
- Production build
- Production live smoke
Safety
- The external setup release note exposes only public readiness links, aggregate setup lane counts, the short commit, deployment id, verification classes, and sanitized safety summaries
- The external setup page and JSON feed expose sanitized blocker labels, public owner categories, public proof links, activation criteria, and protected setup packet counts only
- Protected setup packet bodies, provider account details, raw owner notes, private logs, private EVE data, EVE tokens, credentials, cookies, authorization headers, raw submissions, and separate-project account details remain excluded from the public external setup surfaces
- Public health, monitoring readiness, SEO readiness, and production smoke verify external setup aggregate counts, route-smoke coverage, public-feed coverage, sitemap coverage, ready proof-target parity, and no-secret text boundaries without calling providers, mutating external services, starting OAuth, or enabling gated integrations
- Production live smoke verifies /external-setup, the external setup JSON feed, public health/status counters, monitoring and SEO readiness feeds, release-readiness links, no-secret text boundaries, and the expected production commit
Protected Owner Handoff Export
Added protected admin owner-handoff JSON and Markdown exports, /ops download links, protected route-smoke coverage, public ops-readiness counters, public health counters, and production live-smoke markers so owner-review lanes, approval checklist states, protected review links, proof targets, and build-while-blocked work can be handed off from an admin-only packet without exposing provider credentials, API keys, EVE tokens, private EVE data, account data, raw submissions, protected setup packet bodies, provider cookies, private logs, or separate-project account details.
- Date: 2026-06-22
- Commit: da1b99d
- Deployment: dpl_4qELP6DSKeMuepTdFsPyTyV6CM95
Verification
- Type check
- Full test suite
- Production build
- Production live smoke
Safety
- The protected owner-handoff release note exposes only public readiness links, protected route labels, the short commit, deployment id, verification classes, and sanitized safety summaries
- The admin owner-handoff JSON and Markdown exports remain admin-only, private no-store, noindex responses and return unauthorized private JSON when unauthenticated
- The protected packet reports aggregate owner lane counts, owner-action counts, buildable-work counts, proof-target counts, approval checklist states, and route labels only; it does not expand protected setup packet bodies or raw queue submissions
- Public ops-readiness, public health, and production smoke expose aggregate coverage counts only while verifying the new protected route pair returns private unauthorized responses without provider calls or external mutations
- Production live smoke verifies /ops-readiness, public health/status counters, release-readiness links, no-secret text boundaries, the expected production commit, and the protected owner-handoff JSON/Markdown route pair
Public Owner Handoff Readiness
Added a public owner-handoff page, owner-handoff JSON feed, public health counters, SEO/discovery coverage, and production live-smoke markers so project-owner actions, provider-account review, buildable work, activation criteria, and proof targets have one public no-secret review surface without exposing provider credentials, API keys, passwords, EVE tokens, private EVE data, account data, raw submissions, protected setup packet contents, provider cookies, private logs, or separate-project account details.
- Date: 2026-06-22
- Commit: e7754d3
- Deployment: dpl_HxzSmQrMX4wdL4SB8YTJZSM6XM4U
Verification
- Type check
- Full test suite
- Production build
- Production live smoke
Safety
- The owner-handoff release note exposes only public readiness links, aggregate lane counts, proof-target counts, the short commit, deployment id, verification classes, and sanitized safety summaries
- The owner-handoff page and JSON feed expose owner-review lanes, waiting/staged action counts, buildable work counts, activation criteria, proof targets, and public route labels only
- Protected setup packet contents, provider account details, raw owner notes, private logs, private EVE data, EVE tokens, credentials, cookies, authorization headers, and raw submissions remain excluded from the public owner-handoff surfaces
- Public health and production smoke verify owner-handoff aggregate counts, ready proof-target parity, no-secret text boundaries, route-smoke coverage, public-feed coverage, and SEO/discovery coverage without calling providers, mutating external services, starting OAuth, or enabling gated integrations
- Production live smoke verifies /owner-handoff, the owner-handoff JSON feed, public health/status counters, release-readiness links, no-secret text boundaries, and expected production commit
Public Next Actions Proof Targets
Added public proof targets to the Next Actions page, Next Actions JSON feed, public health counters, and production live smoke so project-owner review, provider-account readiness, build-team handoff, feature-gate review, and build-while-blocked lanes have reviewable public proof surfaces without exposing protected setup packet contents, credentials, private EVE data, raw submissions, provider cookies, private logs, or separate-project account details.
- Date: 2026-06-22
- Commit: fd1d1ec
- Deployment: dpl_EkMJLkuTfQuiqVdCcF9sDNUEyFYY
Verification
- Type check
- Full test suite
- Production build
- Production live smoke
Safety
- The Next Actions proof-target release note exposes only public readiness links, aggregate proof-target counts, the short commit, deployment id, verification classes, and sanitized safety summaries
- The Next Actions page and JSON feed expose eleven public proof targets, ready-count totals, blocked-count totals, route labels, and public-safe review notes only
- Protected setup packet contents, provider account details, raw owner notes, private logs, private EVE data, EVE tokens, credentials, cookies, authorization headers, and raw submissions remain excluded from the public proof-target surfaces
- Public health and production smoke verify the proof-target count floor and ready-count parity without calling providers, mutating external services, starting OAuth, or enabling gated integrations
- Production live smoke verifies /next-actions, the Next Actions JSON feed, public health/status counters, release-readiness links, no-secret text boundaries, and expected production commit
Protected AdSense Owner Acceptance Checklist
Added a protected owner-acceptance checklist to the AdSense setup packet and public AdSense readiness counts so the ads launch can be reviewed through Google account boundary, site-policy, verification, public client configuration, ads.txt, feature-flag, proof-target, rollback, and tracker-evidence checks without calling Google, loading ad scripts, serving ads, mutating provider settings, enabling ad monetization, exposing publisher IDs, exposing slot IDs, exposing Google credentials, exposing verification prompts, exposing payment profile details, exposing tax records, exposing private EVE data, or touching separate-project accounts.
- Date: 2026-06-22
- Commit: 59cf394
- Deployment: dpl_3S2di5ceAw6vamnH7pHzmKXe4NS4
Verification
- Type check
- Full test suite
- Production build
- Production live smoke
Safety
- The AdSense owner-acceptance release note exposes only public readiness links, protected route names, the short commit, deployment id, verification classes, and sanitized safety summaries
- The protected AdSense setup, dry-run, and activation-rehearsal packets remain admin-only, private no-store, and return unauthorized private JSON when unauthenticated
- The owner-acceptance checklist reports eight checks, ten proof targets, review-state counts, and no-provider-action safety booleans only; it does not call Google, load ad scripts, serve ads, mutate provider settings, or enable ad monetization
- Public AdSense readiness exposes aggregate public-route counts, owner-handoff counts, owner-acceptance counts, ads.txt readiness, review gates, rollback counts, and dry-run safety only; it does not expose publisher IDs, slot IDs, Google credentials, verification prompts, payment profile details, tax records, private EVE data, or protected setup packet details
- Production live smoke verifies public AdSense readiness, ads.txt, ad choices, privacy, terms, support, revenue, protected AdSense admin routes, public health/status/ops counters, no-secret text boundaries, and expected production commit
Protected Stripe Owner Acceptance Checklist
Added a protected owner-acceptance checklist to the Stripe voluntary-support setup packet and public Stripe readiness counts so the support-link launch can be reviewed through account-boundary, voluntary-copy, reviewed-link, feature-flag, proof-target, rollback, and tracker-evidence checks without calling Stripe, creating checkout or payment links, mutating provider settings, enabling paid feature gates, exposing payment links, exposing Stripe secrets, exposing webhook secrets, exposing checkout IDs, exposing customer records, exposing payment profile details, exposing shared legal-entity fields, exposing private EVE data, or touching separate-project accounts.
- Date: 2026-06-22
- Commit: 3969ed4
- Deployment: dpl_GTywTDKYQnFcQGQDzCXVZDKAqbuH
Verification
- Type check
- Full test suite
- Production build
- Production live smoke
Safety
- The Stripe owner-acceptance release note exposes only public readiness links, protected route names, the short commit, deployment id, verification classes, and sanitized safety summaries
- The protected Stripe setup, dry-run, and activation-rehearsal packets remain admin-only, private no-store, and return unauthorized private JSON when unauthenticated
- The owner-acceptance checklist reports seven checks, eight proof targets, review-state counts, and no-provider-action safety booleans only; it does not call Stripe, create checkout sessions, create payment links, mutate provider settings, or enable paid feature gates
- Public Stripe readiness exposes aggregate support-link booleans, public route counts, owner-handoff counts, owner-acceptance counts, rollback counts, and dry-run safety only; it does not expose payment links, environment variable names, Stripe secret keys, webhook secrets, checkout IDs, customer records, payment profile details, bank details, shared legal-entity fields, EVE tokens, private EVE data, or protected setup packet details
- Production live smoke verifies public Stripe readiness, support, support-project, revenue, support readiness, protected Stripe admin routes, public health/status/ops counters, no-secret text boundaries, and expected production commit
Protected EVE Owner Acceptance Checklist
Added a protected owner-acceptance checklist to the EVE SSO activation packet and surfaced the owner-review counts on the admin ops dashboard so the controlled first-login smoke can be reviewed through project-boundary, callback and credential, feature-flag, publicData consent-preview, proof-target, rollback, live-smoke, and tracker-evidence checks without starting OAuth, exchanging tokens, calling CCP/EVE, mutating sessions, enabling live login, exposing EVE client credentials, exposing cookies or authorization headers, exposing token data, exposing private EVE data, or touching separate-project accounts.
- Date: 2026-06-22
- Commit: 57f1d7a
- Deployment: dpl_Ek3C76YzLmY1pCZXQXYgUA7hDK5f
Verification
- Type check
- Full test suite
- Production build
- Production live smoke
Safety
- The EVE owner-acceptance release note exposes only public readiness links, protected route names, the short commit, deployment id, verification classes, and sanitized safety summaries
- The protected EVE SSO activation packet remains admin-only, private no-store, and returns unauthorized private JSON when unauthenticated
- The owner-acceptance checklist reports eight checks, eight proof targets, review-state counts, and no-action safety booleans only; it does not start OAuth, exchange tokens, call CCP/EVE, mutate sessions, or enable live login
- The controlled first-login smoke remains owner-gated until the feature-flag switch, tracker evidence, rollback plan, and production live smoke are reviewed
- Production live smoke verifies the protected activation packet, EVE session, login, consent-preview, callback state-failure, logout, disconnect, account controls, public EVE readiness, public health/status/ops counters, no-secret text boundaries, and expected production commit
Protected EVE First-Login Smoke Rehearsal
Added a protected admin EVE auth-flow first-login smoke rehearsal packet and ops metrics so session baseline, publicData consent preview, login gate, callback state-failure handling, logout, disconnect, account export, account deletion, proof targets, tracker evidence, and safety booleans can be reviewed before owner-run EVE SSO activation without starting OAuth, exchanging tokens, calling CCP/EVE, mutating sessions, enabling live login, exposing EVE client credentials, exposing cookies or authorization headers, exposing token data, exposing private EVE data, or touching separate-project accounts.
- Date: 2026-06-22
- Commit: 727c0e7
- Deployment: dpl_FcVxkzunBbGLVZGBEL7p5WVTXcbf
Verification
- Type check
- Full test suite
- Production build
- Production live smoke
Safety
- The EVE first-login smoke rehearsal release note exposes only public readiness links, protected route names, the short commit, deployment id, verification classes, and sanitized safety summaries
- The protected auth-flow review packet remains admin-only, private no-store, and returns unauthorized private JSON when unauthenticated
- The rehearsal packet reports eight first-login smoke steps and eight proof targets only; it does not start OAuth, exchange tokens, call CCP/EVE, mutate sessions, or enable live login
- EVE SSO first-login owner smoke remains blocked until the WarpIntel-only browser session, publicData consent preview, login gate, callback state-failure handling, logout/disconnect controls, account controls, production smoke, and tracker evidence are reviewed
- Production live smoke verifies the EVE session, login, consent-preview, callback state-failure, logout, disconnect, account export, account delete, protected auth-flow, public EVE readiness, public health/status/ops counters, no-secret text boundaries, and expected production commit
Protected EVE SSO Activation Rehearsal
Added a protected admin-only /api/admin/eve/activation-rehearsal POST route and no-OAuth/no-token-exchange/no-provider-mutation rehearsal preview for future WarpIntel EVE SSO activation so production callback readiness, runtime credential presence, publicData first login, feature-consent previews, runtime login guards, first-login smoke approval, tracker evidence, proof targets, rollback decisions, protected setup-action coverage, and safety booleans can be reviewed without starting OAuth, calling CCP/EVE, exchanging tokens, mutating provider settings, enabling public login, exposing EVE client credentials, exposing cookies or authorization headers, exposing token data, exposing private EVE data, or touching separate-project accounts.
- Date: 2026-06-22
- Commit: f49e9d0
- Deployment: dpl_FDSU3S9JVLiSVsmt9HuKbJ7kWWqE
Verification
- Type check
- Full test suite
- Production build
- Production live smoke
Safety
- The EVE SSO activation rehearsal release note exposes only public readiness links, protected route names, the short commit, deployment id, verification classes, and sanitized safety summaries
- The protected rehearsal route is admin-only, POST-only, private no-store, and returns unauthorized private JSON when unauthenticated
- The rehearsal preview reports callback, credential-presence, publicData, consent-preview, runtime guard, first-login smoke, tracker, proof-target, rollback, and safety booleans only; it does not start OAuth, call CCP/EVE, exchange tokens, mutate provider settings, or enable public login
- EVE SSO live login remains blocked until the production callback, WarpIntel-only credential presence, publicData scope, feature-specific consent previews, runtime guard, owner-approved first-login smoke, rollback plan, and tracker evidence are reviewed
- Production live smoke verifies the new protected setup-action route, public EVE SSO-readiness counters, public health/status/ops counters, no-secret text boundaries, and expected production commit
Protected OpenAI Activation Rehearsal
Added a protected admin-only /api/admin/openai/activation-rehearsal POST route and no-OpenAI-call/no-token-spend rehearsal preview for future WarpIntel AI enhancement activation so WarpIntel/Olympus provider boundary gates, approved-key and feature-flag gates, spend approval, first-tool scope review, deterministic fallback review, input/output safety review, first-tool smoke prerequisites, production proof targets, rollback decisions, tracker evidence, protected setup-action coverage, and safety booleans can be reviewed without instantiating OpenAI, calling a provider, submitting prompts, spending tokens, mutating provider settings, enabling live AI, exposing API keys, exposing raw model environment values, exposing billing details, exposing raw prompt text, exposing private EVE data, or touching separate-project accounts.
- Date: 2026-06-22
- Commit: 1a70682
- Deployment: dpl_FrartrdPg1YaLHuTeVupFhtLqXZ5
Verification
- Type check
- Full test suite
- Production build
- Production live smoke
Safety
- The OpenAI activation rehearsal release note exposes only public readiness links, protected route names, the short commit, deployment id, verification classes, and sanitized safety summaries
- The protected rehearsal route is admin-only, POST-only, private no-store, and returns unauthorized private JSON when unauthenticated
- The rehearsal preview reports provider boundary gates, approved-key and feature-flag gates, spend approval, first-tool scope, deterministic fallback, safety review, proof targets, rollback decisions, tracker evidence, and booleans only; it does not instantiate OpenAI, call a provider, submit prompts, spend tokens, mutate provider settings, or enable live AI
- OpenAI enhancement remains blocked until the WarpIntel/Olympus provider boundary, approved key, feature flag, spend approval, first-tool scope, deterministic fallback, safety review, production smoke, rollback plan, and tracker evidence are owner-reviewed
- Production live smoke verifies the new protected setup-action route, public AI-readiness counters, public health/status/ops counters, no-secret text boundaries, and expected production commit
Protected Sentry Activation Rehearsal
Added a protected admin-only /api/admin/sentry/activation-rehearsal POST route and no-Sentry-call/no-provider-mutation rehearsal preview for future WarpIntel Sentry activation so provider boundary gates, DSN and feature-flag gates, instrumentation review, scrub readiness, sample-capture prerequisites, production proof targets, rollback decisions, tracker evidence, protected setup-action coverage, and safety booleans can be reviewed without calling Sentry, sending events, uploading source maps, mutating provider settings, enabling capture, exposing DSN values, exposing provider identifiers, exposing event URLs, exposing stack traces, exposing cookies, exposing authorization headers, exposing public environment values, exposing private EVE data, or touching separate-project accounts.
- Date: 2026-06-22
- Commit: fec0c53
- Deployment: dpl_HUsn8dVXss4DNSMtSiLSip76kbKu
Verification
- Type check
- Full test suite
- Production build
- Production live smoke
Safety
- The Sentry activation rehearsal release note exposes only public readiness links, protected route names, the short commit, deployment id, verification classes, and sanitized safety summaries
- The protected rehearsal route is admin-only, POST-only, private no-store, and returns unauthorized private JSON when unauthenticated
- The rehearsal preview reports provider boundary gates, DSN and feature-flag gates, instrumentation review, scrub readiness, sample-capture prerequisites, proof targets, rollback decisions, tracker evidence, and booleans only; it does not call Sentry, send events, upload source maps, mutate provider settings, or enable capture
- Sentry capture remains blocked until the WarpIntel-only provider boundary, feature flag, DSN review, instrumentation check, scrub review, protected sample-capture path, production smoke, rollback plan, and tracker evidence are owner-reviewed
- Production live smoke verifies the new protected setup-action route, public Sentry-readiness counters, public health/status/ops counters, no-secret text boundaries, and expected production commit
Protected Discord Activation Rehearsal
Added a protected admin-only /api/admin/discord/activation-rehearsal POST route and no-Discord-call/no-provider-mutation rehearsal preview for future WarpIntel Discord activation so signed interaction endpoint readiness, app identity gates, bot and first-guild gates, guild command rollout readiness, role-sync boundaries, command payload review, production proof targets, rollback decisions, tracker evidence, protected setup-action coverage, and safety booleans can be reviewed without calling Discord, registering commands, syncing roles, validating endpoints, creating install URLs, exposing bot tokens, exposing client IDs, exposing guild IDs, exposing public keys, exposing Discord API URLs, exposing provider identifiers, exposing public environment values, exposing private EVE data, or touching separate-project accounts.
- Date: 2026-06-22
- Commit: 4a79d18
- Deployment: dpl_BaYzXGxu9JaKp8HAg3xwaagHztEp
Verification
- Type check
- Full test suite
- Production build
- Production live smoke
Safety
- The Discord activation rehearsal release note exposes only public readiness links, protected route names, the short commit, deployment id, verification classes, and sanitized safety summaries
- The protected rehearsal route is admin-only, POST-only, private no-store, and returns unauthorized private JSON when unauthenticated
- The rehearsal preview reports signed endpoint gates, app identity gates, bot and guild gates, guild command rollout readiness, role-sync boundaries, command payload review, proof targets, rollback decisions, tracker evidence, and booleans only; it does not call Discord, register commands, sync roles, validate endpoints, or create install URLs
- Discord activation remains blocked until the WarpIntel-only Discord app identity, public key, bot token, first guild, command rollout, role-sync boundary, feature flag, production smoke, rollback plan, and tracker evidence are reviewed
- Production live smoke verifies the new protected setup-action route, public Discord-readiness counters, public health/status/ops counters, no-secret text boundaries, and expected production commit
Protected Email Activation Rehearsal
Added a protected admin-only /api/admin/email/activation-rehearsal POST route and no-send/no-provider-mutation rehearsal preview for future WarpIntel transactional email activation so sender identity, provider boundary, provider approval, reply and webhook review, feature-flag readiness, support receipt template review, non-sensitive smoke planning, production proof targets, rollback decisions, tracker evidence, protected setup-action coverage, and safety booleans can be reviewed without calling Resend, opening SMTP connections, sending email, mutating webhooks, mutating DNS, changing provider state, exposing provider credentials, exposing sender or reply-to mailbox values, exposing recipient addresses, exposing message identifiers, exposing raw support messages, exposing public environment values, exposing private EVE data, or touching separate-project accounts.
- Date: 2026-06-22
- Commit: aa41e9b
- Deployment: dpl_9G1ye1KCbGqnLfHGAWeg29Cocmwa
Verification
- Type check
- Full test suite
- Production build
- Production live smoke
Safety
- The email activation rehearsal release note exposes only public readiness links, protected route names, the short commit, deployment id, verification classes, and sanitized safety summaries
- The protected rehearsal route is admin-only, POST-only, private no-store, and returns unauthorized private JSON when unauthenticated
- The rehearsal preview reports sender identity gates, provider boundary gates, reply and webhook review, support receipt template review, proof targets, rollback decisions, tracker evidence, and booleans only; it does not call Resend, open SMTP connections, send email, mutate webhooks, mutate DNS, or change provider state
- Transactional email remains blocked until the WarpIntel-only sender identity, provider approval, reply routing, webhook review, feature flag, non-sensitive smoke, rollback plan, and tracker evidence are reviewed
- Production live smoke verifies the new protected setup-action route, public email-readiness counters, public health/status/ops counters, no-secret text boundaries, and expected production commit
Protected AdSense Activation Rehearsal
Added a protected admin-only /api/admin/adsense/activation-rehearsal POST route and no-provider-mutation rehearsal preview for future Google AdSense activation so Google account review, site policy checks, public client and slot gates, ads.txt authorization, public placement review, feature flag readiness, production proof targets, rollback decisions, tracker evidence, protected setup-action coverage, and safety booleans can be reviewed without calling Google, loading ad scripts, serving ads, changing payment profiles, changing tax records, exposing verification prompts, exposing account credentials, exposing public IDs, exposing public environment values, exposing private EVE data, or placing ads on protected/private views.
- Date: 2026-06-22
- Commit: ff47d7b
- Deployment: dpl_3T5TrcnFyNVPzynhwHk5inQyx2cW
Verification
- Type check
- Full test suite
- Production build
- Production live smoke
Safety
- The AdSense activation rehearsal release note exposes only public readiness links, protected route names, the short commit, deployment id, verification classes, and sanitized safety summaries
- The protected rehearsal route is admin-only, POST-only, private no-store, and returns unauthorized private JSON when unauthenticated
- The rehearsal preview reports Google review gates, public ID gates, ads.txt readiness, placement review, proof targets, rollback decisions, tracker evidence, and booleans only; it does not call Google, load ad scripts, serve ads, change payment profiles, change tax records, or expose verification prompts
- Public ad loading remains blocked until Google review, valid public IDs, numeric slot IDs, ads.txt authorization, public placement review, feature flag review, production smoke, rollback plan, and tracker evidence are reviewed
- Production live smoke verifies the new protected setup-action route, public AdSense-readiness counters, public health/status/ops counters, no-secret text boundaries, and expected production commit
Protected Stripe Support Activation Rehearsal
Added a protected admin-only /api/admin/stripe/activation-rehearsal POST route and no-payment-mutation rehearsal preview for future voluntary support-link activation so publish gates, production proof targets, owner handoff checks, rollback decision points, tracker evidence, protected setup-action coverage, and safety booleans can be reviewed without calling Stripe, creating Checkout Sessions, creating Payment Links, changing products or prices, touching customers, creating subscriptions, configuring webhooks, changing legal-entity fields, exposing payment links, exposing public environment values, exposing provider secrets, exposing customer records, exposing payment profile details, exposing private EVE data, or unlocking app features.
- Date: 2026-06-22
- Commit: 0e13759
- Deployment: dpl_A86EETgbdgXPJQ69VXmp2XBXiwiS
Verification
- Type check
- Full test suite
- Production build
- Production live smoke
Safety
- The Stripe support activation rehearsal release note exposes only public readiness links, protected route names, the short commit, deployment id, verification classes, and sanitized safety summaries
- The protected rehearsal route is admin-only, POST-only, private no-store, and returns unauthorized private JSON when unauthenticated
- The rehearsal preview reports support-link publish gates, proof targets, owner handoff checks, rollback decision points, tracker evidence, and booleans only; it does not call Stripe, create Checkout Sessions, create Payment Links, or mutate payment objects
- Voluntary support remains blocked until the WarpIntel-only Stripe profile, reviewed Stripe-hosted HTTPS link, no-unlock copy, feature flag, production smoke, rollback plan, and tracker evidence are reviewed
- Production live smoke verifies the new protected setup-action route, public Stripe-readiness counters, public health/status/ops counters, no-secret text boundaries, and expected production commit
Protected Backup Restore Drill Rehearsal
Added a protected admin-only /api/admin/backup-readiness/restore-drill-rehearsal POST route and no-provider-mutation rehearsal preview for future backup restore drills so baseline proof targets, owner approval gates, acceptance criteria, rollback decision points, tracker-ready evidence, protected setup-action coverage, and safety booleans can be reviewed without restoring Neon, rolling back Vercel, reading environment values, writing database rows, mutating provider state, returning database credentials, exposing migration tags, exposing provider artifacts, returning token ciphertext, exposing raw IP or user-agent data, exposing private account data, exposing private EVE data, or marking a real restore drill verified.
- Date: 2026-06-22
- Commit: ce8f476
- Deployment: dpl_Aat5GoH3n9JaQrzqjcHeJpmgjQXw
Verification
- Type check
- Full test suite
- Production build
- Production live smoke
Safety
- The backup restore-drill rehearsal release note exposes only public readiness links, protected route names, the short commit, deployment id, verification classes, and sanitized safety summaries
- The protected rehearsal route is admin-only, POST-only, private no-store, and returns unauthorized private JSON when unauthenticated
- The rehearsal preview reports baseline proof targets, owner approval gates, acceptance criteria, rollback decision points, tracker-ready evidence, protected setup-action coverage, and booleans only; it does not restore Neon, roll back Vercel, read environment values, write database rows, or mutate provider state
- A real restore drill remains blocked until owner approval, isolated restore target confirmation, migration reconciliation, post-restore proof capture, and rollback decisions are reviewed
- Production live smoke verifies the new protected setup-action route, public backup-readiness counters, public health/status/ops counters, no-secret text boundaries, and expected production commit
Protected Growth Search Submission Dry Run
Added a protected admin-only /api/admin/growth/search-submission-dry-run POST route and no-provider-call dry-run preview for future Google Search Console and Bing Webmaster Tools sitemap submission review so provider labels, public console URLs, sitemap and robots URLs, verification-configured booleans, activation criteria, next steps, owner-approval requirements, search-submission status, and safety booleans can be reviewed without calling Google or Bing, submitting sitemaps, enabling analytics or Speed Insights, returning verification token values, writing database rows, writing cookies, exposing provider credentials, exposing raw pageview data, exposing workflow-click payloads, exposing private account data, exposing private EVE data, or touching separate-project accounts.
- Date: 2026-06-22
- Commit: 444e3bf
- Deployment: dpl_F2GbpVoNhF91AtREAv6H3hPkEZGj
Verification
- Type check
- Full test suite
- Production build
- Production live smoke
Safety
- The growth search-submission dry-run release note exposes only public readiness links, protected route names, the short commit, deployment id, verification classes, and sanitized safety summaries
- The protected dry-run route is admin-only, POST-only, private no-store, and returns unauthorized private JSON when unauthenticated
- The dry-run preview reports provider labels, public console URLs, sitemap and robots URLs, verification-configured booleans, activation criteria, next steps, owner-approval requirements, and booleans only; it does not call Google or Bing, submit sitemaps, enable telemetry, or expose verification token values
- Search-provider submission remains blocked until WarpIntel provider accounts are confirmed, public meta verification is configured, owner approval is recorded, and provider-console submission steps are reviewed
- Production live smoke verifies the new protected setup-action route, public growth-readiness counters, public health/status/ops counters, no-secret text boundaries, and expected production commit
Protected External Activation Dry Run
Added a protected admin-only /api/admin/external-readiness/activation-dry-run POST route and no-provider-call dry-run preview for external feature activation gates so setup packet links, provider dry-run routes, feature-gate names, readiness counts, owner-approval requirements, activation criteria, next steps, and safety booleans can be reviewed without calling EVE or CCP, Stripe, AdSense, Discord, Resend or email providers, OpenAI, Sentry, Vercel, GitHub, or Neon; changing feature flags or runtime environment values; starting EVE OAuth; creating Stripe checkout links; loading Google ad scripts; registering Discord commands; sending email; calling OpenAI; capturing Sentry events; changing Vercel or GitHub links; restoring Neon; writing database rows; writing cookies; exposing provider credentials; exposing EVE tokens; exposing private EVE data; exposing account payloads; exposing raw submissions; or touching separate-project accounts.
- Date: 2026-06-22
- Commit: 321f23a
- Deployment: dpl_9RfFPF33kqVP2udyizXWoMCqAe3v
Verification
- Type check
- Full test suite
- Production build
- Production live smoke
Safety
- The external activation dry-run release note exposes only public readiness links, protected route names, the short commit, deployment id, verification classes, and sanitized safety summaries
- The protected dry-run route is admin-only, POST-only, private no-store, and returns unauthorized private JSON when unauthenticated
- The dry-run preview reports setup packet links, provider dry-run routes, feature-gate names, readiness counts, owner-approval requirements, activation criteria, next steps, and booleans only; it does not call external providers, change feature flags, or write runtime state
- External provider activation remains blocked until owner approval, live credentials, production callback checks, domain verification, provider dry-run packets, and rollback steps are reviewed
- Production live smoke verifies the new protected setup-action route, public health/status/ops counters, no-secret text boundaries, and expected production commit
Protected EVE Token Revocation Drill
Added a protected admin-only /api/admin/eve/token-revocation-drill POST route and metadata-only dry-run preview for future EVE token revocation and disconnect review so aggregate token-health counts, drill steps, dry-run criteria, blocked live-activation criteria, route names, account-control links, owner-approval gates, and safety booleans can be reviewed without calling EVE or CCP, starting OAuth, revoking tokens, returning token values, returning token ciphertext, returning refresh or access tokens, returning raw scopes, returning account payloads, reading private EVE data, writing database records, writing cookies, deleting sessions, exposing provider credentials, or touching separate-project accounts.
- Date: 2026-06-22
- Commit: ad7ef9f
- Deployment: dpl_E45gTVBUouPG3XqjmfDTdensmLBG
Verification
- Type check
- Full test suite
- Production build
- Production live smoke
Safety
- The token revocation drill release note exposes only public readiness links, protected route names, the short commit, deployment id, verification classes, and sanitized safety summaries
- The protected drill route is admin-only, POST-only, private no-store, and returns unauthorized private JSON when unauthenticated
- The dry-run preview reports aggregate token-health counts, route names, checklist steps, and booleans only; it does not call EVE or CCP, start OAuth, revoke tokens, or expose token material
- Live revocation remains blocked until a specific token target, owner approval, and an audited provider revocation worker exist
- Production live smoke verifies the new protected setup-action route, public health/status/ops counters, no-secret text boundaries, and expected production commit
Protected Reports Webhook Dry Run
Added a protected admin-only /api/admin/reports/webhook-dry-run POST route and metadata-only dry-run preview for future signed report webhook delivery so the envelope shape, header names, signing requirement, replay-protection requirement, rate-limit requirement, owner-approval gate, activation criteria, no-delivery status, and safety booleans can be reviewed without sending outbound webhooks, generating real signatures, exposing webhook signing secrets, including report bodies, including raw pasted inputs, including account reports, including account exports, reading private EVE data, using provider credentials, or touching separate-project accounts.
- Date: 2026-06-22
- Commit: d631fcc
- Deployment: dpl_ByJ1Hx1tGmjDL94FsJknpSpfvVC7
Verification
- Type check
- Full test suite
- Production build
- Production live smoke
Safety
- The reports webhook dry-run release note exposes only public readiness links, protected route names, the short commit, deployment id, verification classes, and sanitized safety summaries
- The dry-run preview is protected by the admin session boundary and returns private no-store unauthorized responses when unauthenticated
- The preview reports metadata-only envelope and header names; it does not send outbound webhooks, generate real signatures, expose signing secrets, or include report bodies
- Activation criteria require signing, replay protection, rate limiting, owner approval, metadata-only payloads, and no live delivery before any future webhook can be enabled
- Production live smoke verifies the new protected setup-action route, public health/status/ops counters, no-secret text boundaries, and expected production commit
Public EVE SSO Launch Checklist
Added the public /eve-sso-launch page so the EVE SSO launch state, production callback gate, publicData first-login boundary, feature-specific consent plans, activation criteria, owner review, rollback decision paths, blocking checks, and public readiness links can be reviewed without starting OAuth, redirecting to CCP, exchanging tokens, exposing client IDs or secrets, exposing access or refresh tokens, reading account data, reading private EVE data, or enabling unfinished provider integrations.
- Date: 2026-06-22
- Commit: d74f89e
- Deployment: dpl_8MKsLX6Yd8j39q8tDizBq4GCrkpU
Verification
- Type check
- Full test suite
- Production build
- Production live smoke
Safety
- The EVE SSO launch checklist release note exposes only public readiness links, the short commit, deployment id, verification classes, and sanitized launch safety summaries
- The /eve-sso-launch page reads the existing public no-secret readiness manifest; it does not start OAuth, redirect to CCP, exchange tokens, reveal client identifiers, reveal client secrets, or expose EVE access or refresh tokens
- The checklist keeps production callback approval, public sign-in activation, advanced permission grants, token health review, and rollback decisions as owner-reviewed launch steps rather than automatic public actions
- Sitemap, SEO, public discovery, health, status, and live-smoke coverage now include the EVE SSO launch checklist without exposing provider secrets, private EVE data, or separate-project account data
- Production live smoke verifies the EVE SSO launch page, public readiness links, no-secret text boundaries, health counters, sitemap/SEO metadata, and expected production commit
Public PI Ops Analyzer
Added the public PI Ops analyzer and /tools/pi-ops route so user-pasted planet, colony, extractor, P0-P4 chain, factory, launchpad, storage, POCO tax, import/export, hauling, market, timing, risk, review, and approval notes can be reviewed with local rule-based planetary-industry readiness without reading colonies, planets, assets, wallets, market orders, corporation hangars, POCO ACLs, tax settings, private character data, corporation data, or EVE tokens and without setting up colonies, restarting extractors, editing routes, launching goods, importing or exporting materials, changing POCO taxes, creating market orders, moving assets, or creating contracts.
- Date: 2026-06-22
- Commit: 3d51277
- Deployment: dpl_AwXm3JR7stNah9pCtJagmse9CB7z
Verification
- Type check
- Full test suite
- Production build
- Production live smoke
Safety
- The PI Ops release note exposes only public analyzer links, the short commit, deployment id, verification classes, and sanitized safety summaries
- PI Ops uses user-pasted planet, colony, extractor, P0-P4 chain, factory, launchpad, storage, POCO tax, import/export, hauling, market, timing, risk, review, and approval notes plus local keyword rules; it does not read colonies, planets, assets, wallets, market orders, corporation hangars, POCO ACLs, tax settings, private character data, corporation data, or EVE tokens
- The analyzer keeps colony setup, extractor restarts, route edits, launches, imports, exports, POCO tax changes, market orders, asset movement, contracts, and account-specific PI operations as human-approved external decisions rather than automation
- Public directory, SEO, sitemap, health, monitoring, capability, tool-readiness, live-smoke, report-export, account-report, workflow-click, and Drizzle enum coverage now include PI Ops without exposing provider secrets or separate-project data
- Production live smoke verifies the PI Ops page, tool-directory counters, reports-readiness counters, monitoring counters, sitemap/SEO metadata, health counters, no-secret text boundaries, and expected production commit
Public Wormhole Ops Analyzer
Added the public Wormhole Ops analyzer and /tools/wormhole-ops route so user-pasted wormhole chain, signature, static, mass, lifetime, scout, D-scan, mapper, site, logistics, hauler, route, risk, review, and approval notes can be reviewed with local rule-based chain readiness without reading private mapper membership, private bookmarks, live locations, fleet membership, structures, Discord data, private character data, corporation data, or EVE tokens and without updating mappers, rolling holes, setting destinations, pinging fleets, moving assets, anchoring structures, changing bookmarks, or changing access.
- Date: 2026-06-22
- Commit: 2825e16
- Deployment: dpl_2DHDQWnaKyykx1MJ9xt94JkxG6mo
Verification
- Type check
- Full test suite
- Production build
- Production live smoke
Safety
- The Wormhole Ops release note exposes only public analyzer links, the short commit, deployment id, verification classes, and sanitized safety summaries
- Wormhole Ops uses user-pasted chain, signature, static, mass, lifetime, scout, D-scan, mapper, site, logistics, hauler, route, risk, review, and approval notes plus local keyword rules; it does not read private mapper membership, private bookmarks, live locations, fleet membership, structures, Discord data, private character data, corporation data, or EVE tokens
- The analyzer keeps mapper updates, hole rolling, destination writes, fleet pings, asset movement, structure anchoring, bookmark changes, access changes, and account-specific wormhole operations as human-approved external decisions rather than automation
- Public directory, SEO, sitemap, health, monitoring, capability, tool-readiness, live-smoke, report-export, account-report, workflow-click, and Drizzle enum coverage now include Wormhole Ops without exposing provider secrets or separate-project data
- Production live smoke verifies the Wormhole Ops page, tool-directory counters, reports-readiness counters, monitoring counters, sitemap/SEO metadata, health counters, no-secret text boundaries, and expected production commit
Public Diplomacy Ops Analyzer
Added the public Diplomacy Ops analyzer and /tools/diplomacy-ops route so user-pasted diplomacy, standings, access, agreement, comms, proof, review, and risk notes can be reviewed with local rule-based director-readiness without reading private standings, contacts, EVE mails, roles, ACLs, wallets, assets, fleet membership, locations, private character data, corporation data, or EVE tokens and without changing standings, granting access, sending messages or pings, approving treaties, creating diplomacy notices, moving ISK or assets, inviting pilots, or altering roles.
- Date: 2026-06-22
- Commit: d850e03
- Deployment: dpl_J8EjaFzTumfybV5R31WzuCSdtxPQ
Verification
- Type check
- Full test suite
- Production build
- Production live smoke
Safety
- The Diplomacy Ops release note exposes only public analyzer links, the short commit, deployment id, verification classes, and sanitized safety summaries
- Diplomacy Ops uses user-pasted diplomacy, standings, access, agreement, comms, proof, review, and risk notes plus local keyword rules; it does not read private standings, contacts, EVE mails, roles, ACLs, wallets, assets, fleet membership, locations, private character data, corporation data, or EVE tokens
- The analyzer keeps standings changes, ACL or role grants, messages, pings, treaty approvals, diplomacy notices, ISK movement, asset movement, pilot invites, and role changes as human-approved external decisions rather than automation
- Public directory, SEO, sitemap, health, monitoring, capability, tool-readiness, live-smoke, report-export, account-report, workflow-click, and Drizzle enum coverage now include Diplomacy Ops without exposing provider secrets or separate-project data
- Production live smoke verifies the Diplomacy Ops page, tool-directory counters, reports-readiness counters, monitoring counters, sitemap/SEO metadata, health counters, no-secret text boundaries, and expected production commit
Public Sovereignty Ops Analyzer
Added the public Sovereignty Ops analyzer and /tools/sovereignty-ops route so user-pasted sovereignty campaign, iHub, TCU, entosis, command-node, ADM/index, fleet, logistics, diplomacy, route, jump-bridge, cyno, and risk notes can be reviewed with local rule-based campaign readiness without reading private structures, ACLs, fleet membership, assets, wallets, roles, locations, standings, timers, character data, or EVE tokens and without starting entosis activity, creating fleets, moving pilots, setting destinations, using jump bridges, lighting cynos, changing structures, sending pings, changing standings, or moving assets.
- Date: 2026-06-22
- Commit: cc27612
- Deployment: dpl_9Afwhd6MVniFAijdBWQCpvYMabqQ
Verification
- Type check
- Full test suite
- Production build
- Production live smoke
Safety
- The Sovereignty Ops release note exposes only public analyzer links, the short commit, deployment id, verification classes, and sanitized safety summaries
- Sovereignty Ops uses user-pasted campaign, iHub, TCU, entosis, command-node, timer, ADM, fleet, logistics, diplomacy, route, and risk notes plus local keyword rules; it does not read private structures, ACLs, fleet membership, assets, wallets, roles, locations, standings, timers, character data, or EVE tokens
- The analyzer keeps entosis activity, fleet creation, pilot movement, destination setting, jump-bridge use, cyno lighting, structure changes, pings, standings changes, asset movement, diplomacy notices, and command decisions as human-approved external decisions rather than automation
- Public directory, SEO, sitemap, health, monitoring, capability, tool-readiness, live-smoke, report-export, account-report, workflow-click, and Drizzle enum coverage now include Sovereignty Ops without exposing provider secrets or separate-project data
- Production live smoke verifies the Sovereignty Ops page, tool-directory counters, reports-readiness counters, monitoring counters, sitemap/SEO metadata, health counters, no-secret text boundaries, and expected production commit
Public Structure Ops Analyzer
Added the public Structure Ops analyzer and /tools/structure-ops route so user-pasted structure, timer, fuel, service, defense, ACL, logistics, access, and risk notes can be reviewed with local rule-based timer and logistics readiness without reading private structures, ACLs, assets, fuel bays, corporation wallets, roles, timers, character data, or EVE tokens and without putting services online or offline, changing ACLs, fueling structures, fitting modules, deploying, unanchoring, creating defense pings, or moving assets.
- Date: 2026-06-22
- Commit: 58f5290
- Deployment: dpl_3RfA4cV6Lrzf52fGjA4H5J6mjWsA
Verification
- Type check
- Full test suite
- Production build
- Production live smoke
Safety
- The Structure Ops release note exposes only public analyzer links, the short commit, deployment id, verification classes, and sanitized safety summaries
- Structure Ops uses user-pasted structure, timer, fuel, service, defense, ACL, logistics, access, and risk notes plus local keyword rules; it does not read private structures, ACLs, assets, fuel bays, corporation wallets, roles, timers, character data, or EVE tokens
- The analyzer keeps service state changes, ACL changes, structure fueling, module fitting, deployment, unanchoring, defense ping creation, asset movement, and account-specific structure actions as human-approved external decisions rather than automation
- Public directory, SEO, sitemap, health, monitoring, capability, tool-readiness, live-smoke, report-export, account-report, workflow-click, and Drizzle enum coverage now include Structure Ops without exposing provider secrets or separate-project data
- Production live smoke verifies the Structure Ops page, tool-directory counters, reports-readiness counters, monitoring counters, sitemap/SEO metadata, health counters, no-secret text boundaries, and expected production commit
Public Industry Ops Analyzer
Added the public Industry Ops analyzer and /tools/industry-ops route so user-pasted blueprint, job-run, material, PI, reaction, cost, market, logistics, facility, structure, timing, and margin notes can be reviewed with local rule-based build-plan readiness without reading private jobs, blueprints, assets, wallets, contracts, corporation hangars, character data, or EVE tokens and without submitting jobs, starting reactions, creating market orders, moving assets, creating contracts, or selecting facilities automatically.
- Date: 2026-06-22
- Commit: a6ff04f
- Deployment: dpl_69zypKDd4bXeGtV2iJcfgXiYto49
Verification
- Type check
- Full test suite
- Production build
- Production live smoke
Safety
- The Industry Ops release note exposes only public analyzer links, the short commit, deployment id, verification classes, and sanitized safety summaries
- Industry Ops uses user-pasted blueprint, run, material, PI, reaction, cost, market, logistics, facility, structure, timing, and margin notes plus local keyword rules; it does not read private jobs, blueprints, assets, wallets, contracts, corporation hangars, character data, or EVE tokens
- The analyzer keeps job submission, reaction starts, market order creation, asset movement, contract creation, facility selection, structure decisions, and account-specific build execution as human-approved external decisions rather than automation
- Public directory, SEO, sitemap, health, monitoring, capability, tool-readiness, live-smoke, report-export, account-report, workflow-click, and Drizzle enum coverage now include Industry Ops without exposing provider secrets or separate-project data
- Production live smoke verifies the Industry Ops page, tool-directory counters, reports-readiness counters, monitoring counters, sitemap/SEO metadata, health counters, no-secret text boundaries, and expected production commit
Public Recruiting Ops Analyzer
Added the public Recruiting Ops analyzer and /tools/recruiting-ops route so user-pasted recruiting packets, application notes, experience summaries, role-fit context, availability windows, interview status, communication readiness, sponsor or vouch notes, training signals, and risk context can be reviewed with local rule-based recruiting readiness without reading private character data, corporation data, contacts, standings, mail, assets, wallets, roles, Discord accounts, or EVE tokens and without accepting or rejecting applications, granting roles, syncing Discord roles, contacting pilots, or changing access.
- Date: 2026-06-22
- Commit: 7e3336a
- Deployment: dpl_7gSoKvskDanQNJS2qtqnAhaw1zRe
Verification
- Type check
- Full test suite
- Production build
- Production live smoke
Safety
- The Recruiting Ops release note exposes only public analyzer links, the short commit, deployment id, verification classes, and sanitized safety summaries
- Recruiting Ops uses user-pasted application, interview, experience, role-fit, availability, communication, sponsor, training, and risk notes plus local keyword rules; it does not read private character data, corporation data, contacts, standings, mail, assets, wallets, roles, Discord accounts, or EVE tokens
- The analyzer keeps application decisions, access grants, corporation roles, Discord role sync, pilot contact, background checks, and account-specific review as human-approved external decisions rather than automation
- Public directory, SEO, sitemap, health, monitoring, capability, tool-readiness, live-smoke, report-export, account-report, workflow-click, and Drizzle enum coverage now include Recruiting Ops without exposing provider secrets or separate-project data
- Production live smoke verifies the Recruiting Ops page, tool-directory counters, reports-readiness counters, monitoring counters, sitemap/SEO metadata, health counters, no-secret text boundaries, and expected production commit
Public SRP Ops Analyzer
Added the public SRP Ops analyzer and /tools/srp-ops route so user-pasted killmail, loss, fleet, doctrine, FC, policy, value, insurance, payout, reviewer, duplicate, denial-risk, and proof context can be reviewed with local rule-based SRP packet readiness without reading wallets, contracts, private killmails, private fleet membership, private character data, or corporation records and without approving SRP, moving ISK, creating contracts, posting to Discord, or changing payout status.
- Date: 2026-06-22
- Commit: e0ee5ea
- Deployment: dpl_FrDqzyJBK17UTdcA5ibhUEZxZEyq
Verification
- Type check
- Full test suite
- Production build
- Production live smoke
Safety
- The SRP Ops release note exposes only public analyzer links, the short commit, deployment id, verification classes, and sanitized safety summaries
- SRP Ops uses user-pasted killmail, loss, fleet, doctrine, FC, policy, value, insurance, payout, reviewer, duplicate, and denial-risk notes plus local keyword rules; it does not read wallets, contracts, private killmails, private fleet membership, private character data, or corporation records
- The analyzer keeps SRP approval, ISK movement, contract reimbursement, Discord notices, payout status changes, duplicate adjudication, denial decisions, and account-specific checks as human-approved external decisions rather than automation
- Public directory, SEO, sitemap, health, monitoring, capability, tool-readiness, live-smoke, report-export, account-report, workflow-click, and Drizzle enum coverage now include SRP Ops without exposing provider secrets or separate-project data
- Production live smoke verifies the SRP Ops page, tool-directory counters, reports-readiness counters, monitoring counters, sitemap/SEO metadata, health counters, no-secret text boundaries, and expected production commit
Public Fleet Ops Analyzer
Added the public Fleet Ops analyzer and /tools/fleet-ops route so user-pasted fleet pings, timer notes, objective details, form-up timing, FC ownership, doctrine, comms, scout, support, SRP, and route-risk context can be reviewed with local rule-based fleet-brief readiness without reading fleet membership, locations, contacts, calendar data, private character data, or corporation records and without creating fleets, sending invites, moving pilots, setting destinations, posting to Discord, automating scouts, or approving SRP.
- Date: 2026-06-22
- Commit: 77879a5
- Deployment: dpl_4VKgaXWxp37v5nqrnpUURJXpuf2D
Verification
- Type check
- Full test suite
- Production build
- Production live smoke
Safety
- The Fleet Ops release note exposes only public analyzer links, the short commit, deployment id, verification classes, and sanitized safety summaries
- Fleet Ops uses user-pasted pings, timer notes, doctrine, comms, scout, support, route, and SRP notes plus local keyword rules; it does not read fleet membership, locations, contacts, calendar data, private character data, or corporation records
- The analyzer keeps fleet creation, invites, pilot movement, destination setting, Discord posting, scout automation, and SRP approval as human-approved external decisions rather than automation
- Public directory, SEO, sitemap, health, monitoring, capability, tool-readiness, live-smoke, report-export, account-report, workflow-click, and Drizzle enum coverage now include Fleet Ops without exposing provider secrets or separate-project data
- Production live smoke verifies the Fleet Ops page, tool-directory counters, reports-readiness counters, monitoring counters, sitemap/SEO metadata, health counters, no-secret text boundaries, and expected production commit
Public Hauling Ops Analyzer
Added the public Hauling Ops analyzer and /tools/hauling-ops route so user-pasted hauling, courier, cargo, collateral, volume, hull, route-risk, choke-point, scout, web, escort, dock-bookmark, split-load, market, and buyback context can be reviewed with local rule-based logistics readiness without reading private assets, contracts, wallets, EVE routes, locations, or character data and without automating courier contracts, route setting, docking, webbing, scouting, fleet invites, or EVE client behavior.
- Date: 2026-06-22
- Commit: 6e473af
- Deployment: dpl_42nFNtfQxC7GcpGw2hYHHC8SdLd4
Verification
- Type check
- Full test suite
- Production build
- Production live smoke
Safety
- The Hauling Ops release note exposes only public analyzer links, the short commit, deployment id, verification classes, and sanitized safety summaries
- Hauling Ops uses user-pasted hauling, courier, cargo, route, scout, collateral, and mitigation notes plus local keyword rules; it does not read assets, contracts, wallets, locations, EVE routes, private character data, or corporation records
- The analyzer keeps courier contracts, route setting, docking, webbing, scouting, fleet invites, EVE client behavior, and ISK movement as human-approved external decisions rather than automation
- Public directory, SEO, sitemap, health, monitoring, capability, tool-readiness, live-smoke, account-report, workflow-click, and Drizzle enum coverage now include Hauling Ops without exposing provider secrets or separate-project data
- Production live smoke verifies the Hauling Ops page, tool-directory counters, sitemap/SEO metadata, health counters, no-secret text boundaries, and expected production commit
Public Access Readiness Coverage
Added the public Access Readiness page and /api/access/readiness manifest so access request intake, protected review routes, feature-specific EVE consent previews, publicData first-login posture, manual grant boundaries, disabled role sync, private-data exclusions, and no-secret readiness checks are represented in public health, status, SEO, sitemap, monitoring, and live-smoke coverage without exposing raw access request rows, character names, contacts, Discord handles, evidence URLs, reviewer notes, grant state, EVE session ids, EVE tokens, private EVE data, role-sync payloads, provider secrets, or automated approvals publicly.
- Date: 2026-06-22
- Commit: 4d4105b
- Deployment: dpl_Dm8jSZe2xZR7FyJcGqzS9RR7Z16j
Verification
- Type check
- Full test suite
- Production build
- Production live smoke
Safety
- The access readiness release note exposes only public readiness links, the short commit, deployment id, verification classes, and sanitized safety summaries
- The public Access Readiness page and JSON feed expose access surface counts, public route counts, protected review route counts, consent-route counts, workflow-stage counts, feature-consent counts, publicData first-login posture, and no-secret safety booleans only
- Raw access request rows, character names, corporation or alliance labels from submitted rows, raw access reasons, contact details, Discord handles, evidence URLs, sponsor references, admin reviewer notes, access grant state, rate-limit hashes, browser identifiers, EVE session ids, EVE tokens, private EVE data, role-sync payloads, provider secrets, automated approvals, and access grants remain excluded from public pages
- Status, health, SEO, monitoring, sitemap, and live-smoke coverage now include the Access Readiness page and API while keeping protected review actions behind admin routes
- Production live smoke verifies the new Access Readiness public page, JSON feed, status links, health counters, no-secret text boundaries, and expected production commit
Protected Access Handoff Coverage
Extended the protected access review packet with owner handoff coverage, rollback decision coverage, access handoff readiness, protected Markdown sections, and /ops access review cards so identity context, policy trust, feature-specific consent, elevated expiry gates, future role-sync gates, and tracker evidence can be reviewed without exposing character names, raw access reasons, contact values, Discord handles, evidence URLs, reviewer notes, private EVE data, tokens, or access grants publicly.
- Date: 2026-06-22
- Commit: cc35549
- Deployment: dpl_9ER2DMjzB5KCX2qyj3Tm5NzAMfDY
Verification
- Type check
- Full test suite
- Production build
- Production live smoke
Safety
- The access handoff release note exposes only public readiness links, the short commit, deployment id, verification classes, and sanitized safety summaries
- Protected access packet exports now include reviewer checklist counts, owner handoff counts, rollback decision counts, and access handoff readiness while character names, raw access reasons, raw contacts, Discord handles, evidence URLs, reviewer notes, private EVE data, EVE tokens, provider secrets, automated approvals, and access grants remain excluded from public pages
- The /ops access review panel now surfaces owner handoff and rollback decision counts without exposing protected access request bodies, raw contact paths, Discord handles, evidence URLs, reviewer notes, private account data, or access grants
- Rollback decision coverage keeps raw access exposure, automated approval or access grant drift, and unsafe scope, secret, or private-data drift blocked before broader access workflow expansion
- Production live smoke verifies protected access packet lockouts, access readiness, release feeds, no-secret text boundaries, and expected production commit
Protected Mining Handoff Coverage
Extended the protected mining review packet with owner handoff coverage, rollback decision coverage, mining handoff readiness, protected Markdown sections, and /ops mining review cards so ledger context, proof-safe references, manual pricing, corp-cut review, payout and contract gates, future private-scope consent, and tracker evidence can be reviewed without exposing raw ore or loot lines, proof URLs, contacts, queue notes, payout notes, wallet journals, contract records, asset locations, corporation mining ledgers, member mining history, ISK movement, or contract automation publicly.
- Date: 2026-06-22
- Commit: 3cdb64e
- Deployment: dpl_HFkcQxt8RghVLfbYQ4y2dVzCu9V3
Verification
- Type check
- Full test suite
- Production build
- Production live smoke
Safety
- The mining handoff release note exposes only public readiness links, the short commit, deployment id, verification classes, and sanitized safety summaries
- Protected mining packet exports now include reviewer checklist counts, owner handoff counts, rollback decision counts, and mining handoff readiness while raw ore or loot lines, proof URLs, contacts, raw queue notes, payout notes, wallet journals, contract records, asset locations, corporation mining ledgers, member mining history, EVE tokens, ISK movement, contract automation, and provider secrets remain excluded from public pages
- The /ops mining review panel now surfaces owner handoff and rollback decision counts without exposing protected mining ledger rows, raw ore text, proof URLs, contact values, payout notes, or private scope data
- Rollback decision coverage keeps raw mining exposure, wallet, contract, or payout automation drift, and unsafe ledger, secret, or separate-project data drift blocked before broader mining workflow expansion
- Production live smoke verifies protected mining packet lockouts, mining readiness, release feeds, no-secret text boundaries, and expected production commit
Protected Fleet Handoff Coverage
Extended the protected fleet/timer review packet with owner handoff coverage, rollback decision coverage, fleet handoff readiness, protected Markdown sections, and /ops fleet review cards so fleet context, private timer visibility, participation-data boundaries, manual invite and action gates, SRP reserve coordination, and tracker evidence can be reviewed without exposing private fleet rows, sensitive timers, membership, attendance, FAT context, location reads, online-state reads, ship-type reads, invite artifacts, or fleet write actions publicly.
- Date: 2026-06-22
- Commit: e292865
- Deployment: dpl_CjsiAaaJE6ksLJfDUy9U8tS8jDHs
Verification
- Type check
- Full test suite
- Production build
- Production live smoke
Safety
- The fleet handoff release note exposes only public readiness links, the short commit, deployment id, verification classes, and sanitized safety summaries
- Protected fleet packet exports now include reviewer checklist counts, owner handoff counts, rollback decision counts, and fleet handoff readiness while private fleet rows, sensitive timers, membership, attendance, FAT context, live location reads, online-state reads, ship-type reads, EVE tokens, invite artifacts, provider secrets, and fleet write actions remain excluded from public pages
- The /ops fleet review panel now surfaces owner handoff and rollback decision counts without exposing protected fleet queue details, private timers, membership data, attendance data, or invite/action artifacts
- Rollback decision coverage keeps private fleet exposure, fleet write or invite automation drift, and unsafe location, secret, or separate-project data drift blocked before broader fleet workflow expansion
- Production live smoke verifies protected fleet packet lockouts, fleet readiness, release feeds, no-secret text boundaries, and expected production commit
Protected Recruitment Handoff Coverage
Extended the protected recruitment review packet with owner handoff coverage, rollback decision coverage, recruitment handoff readiness, protected Markdown sections, and /ops recruitment review cards so application context, manual contact/vouch review, safety screening, manual approval gates, future identity and role gates, and tracker evidence can be reviewed without exposing raw contact values, goals, availability, application notes, reviewer notes, Discord identifiers, or private applicant details publicly.
- Date: 2026-06-22
- Commit: 0891fc2
- Deployment: dpl_BDHynF2AvoPxn8UrBi2nHAx3xrgU
Verification
- Type check
- Full test suite
- Production build
- Production live smoke
Safety
- The recruitment handoff release note exposes only public readiness links, the short commit, deployment id, verification classes, and sanitized safety summaries
- Protected recruitment packet exports now include reviewer checklist counts, owner handoff counts, rollback decision counts, and recruitment handoff readiness while raw contact values, goals, availability, application notes, reviewer notes, Discord identifiers, private EVE data, and provider secrets remain excluded from public pages
- The /ops recruitment review panel now surfaces owner handoff and rollback decision counts without exposing protected application bodies, contacts, goals, availability, reviewer notes, or Discord identifiers
- Rollback decision coverage keeps raw recruitment exposure, automated approval or access grants, and unsafe policy, secret, or private-data drift blocked before broader recruitment workflow expansion
- Production live smoke verifies protected recruitment packet lockouts, recruitment readiness, release feeds, no-secret text boundaries, and expected production commit
Protected Support Handoff Coverage
Extended the protected support review packet with owner handoff coverage, rollback decision coverage, support handoff readiness, protected Markdown sections, and /ops support review cards so request triage, reply-draft assistance, safe page references, manual reply gates, payment/account/security escalation, and future provider-send boundaries can be reviewed without exposing raw support messages, contacts, subjects, page URLs, reviewer notes, payment records, or private account details publicly.
- Date: 2026-06-22
- Commit: 40f7d96
- Deployment: dpl_J9k2QPFWzmcG8YQ6jB7hgFQ3t7t6
Verification
- Type check
- Full test suite
- Production build
- Production live smoke
Safety
- The support handoff release note exposes only public readiness links, the short commit, deployment id, verification classes, and sanitized safety summaries
- Protected support packet exports now include reviewer checklist counts, owner handoff counts, rollback decision counts, and support handoff readiness while raw support messages, contact values, page URLs, raw subjects, raw reviewer notes, email ids, payment records, customer records, account decisions, private EVE data, and provider secrets remain excluded from public pages
- The /ops support review panel now surfaces owner handoff and rollback decision counts without exposing protected support request bodies, contacts, subjects, page URLs, reviewer notes, payment details, or account decisions
- Rollback decision coverage keeps raw support exposure, unapproved provider sends or account actions, and unsafe secret, payment, or private-data drift blocked before broader support workflow expansion
- Production live smoke verifies protected support packet lockouts, support readiness, release feeds, no-secret text boundaries, and expected production commit
Protected Buyback Handoff Coverage
Extended the protected buyback review packet with owner handoff coverage, rollback decision coverage, buyback handoff readiness, protected Markdown sections, and /ops buyback review cards so item policy checks, proof readiness, quote state, manual contract gates, payout exposure, and future private-scope boundaries can be reviewed without exposing raw item rows, proof URLs, contacts, payout notes, or private request details publicly.
- Date: 2026-06-22
- Commit: 09f8cf2
- Deployment: dpl_991oubp2smGi53hUG9A1ErA4NPTK
Verification
- Type check
- Full test suite
- Production build
- Production live smoke
Safety
- The buyback handoff release note exposes only public readiness links, the short commit, deployment id, verification classes, and sanitized safety summaries
- Protected buyback packet exports now include reviewer checklist counts, owner handoff counts, rollback decision counts, and buyback handoff readiness while raw item rows, proof URLs, contacts, queue notes, payout notes, private request details, wallet reads, contract reads, and ISK movement remain excluded from public pages
- The /ops buyback review panel now surfaces owner handoff and rollback decision counts without exposing protected buyback queue rows, proof details, contacts, payout notes, or private request records
- Rollback decision coverage keeps raw buyback exposure, wallet or contract automation drift, and unsafe proof or secret drift blocked before broader buyback workflow expansion
- Production live smoke verifies protected buyback packet lockouts, buyback readiness, release feeds, no-secret text boundaries, and expected production commit
Protected SRP Handoff Coverage
Extended the protected SRP review packet with owner handoff coverage, rollback decision coverage, SRP handoff readiness, protected Markdown sections, and /ops SRP reserve metrics so killmail evidence, doctrine exceptions, reserve exposure, protected exports, and manual payout gates can be reviewed without exposing pilot names, killmail links, payout context, or private account data publicly.
- Date: 2026-06-22
- Commit: 09f613a
- Deployment: dpl_2bhkp4yJfz21LCUKtyE5tHNoZmtb
Verification
- Type check
- Full test suite
- Production build
- Production live smoke
Safety
- The SRP handoff release note exposes only public readiness links, the short commit, deployment id, verification classes, and sanitized safety summaries
- Protected SRP packet exports now include reviewer checklist counts, owner handoff counts, rollback decision counts, and SRP handoff readiness while public pages exclude pilot names, killmail links, decision notes, payout context, EVE tokens, provider secrets, wallet reads, contract reads, and payout actions
- The /ops SRP reserve panel now surfaces owner handoff and rollback decision counts without exposing protected SRP queue rows or payout decisions
- Rollback decision coverage keeps public pilot or killmail exposure, wallet or payout automation drift, and unsafe evidence or secret drift blocked before broader SRP workflow expansion
- Production live smoke verifies protected SRP packet lockouts, SRP readiness, release feeds, no-secret text boundaries, and expected production commit
Protected Ops Queue Handoff Coverage
Extended the protected ops queue export with owner handoff coverage, rollback decision coverage, queue handoff readiness, aggregate-only protected Markdown sections, CSV spreadsheet-opening protection, safe link filtering, and /ops queue readiness signals so SRP, buyback, access, support, recruitment, mining, and fleet operation queues can be reviewed without exposing row-level private queue data.
- Date: 2026-06-22
- Commit: 4411f15
- Deployment: dpl_8HyorYfgbZBVe6mevTmceWmgs6JA
Verification
- Type check
- Full test suite
- Production build
- Production live smoke
Safety
- The ops queue handoff release note exposes only public readiness links, the short commit, deployment id, verification classes, and sanitized safety summaries
- Protected ops queue exports now include aggregate queue lane counts, CSV column counts, owner handoff counts, rollback decision counts, and queue handoff readiness while private queue rows, contacts, support messages, payout instructions, access reasons, proof details, private EVE data, provider credentials, and separate-project account data remain excluded from public pages
- The /ops dashboard now surfaces queue handoff and rollback decision counts without exposing protected queue rows or private manual review records
- Rollback decision coverage keeps row-level queue exposure, unsafe CSV or link export behavior, and unapproved operator actions blocked before broader queue workflow expansion
- Production live smoke verifies protected queue export lockouts, ops readiness, release feeds, no-secret text boundaries, and expected production commit
Protected Reports Review Handoff Coverage
Extended the protected reports review packet with owner handoff coverage, rollback decision coverage, report handoff readiness, protected Markdown sections, and /ops reports-review count cards so browser-local report controls, account-save gates, export manifest boundaries, webhook delivery gates, protected downloads, and tracker evidence can be reviewed without exposing report bodies or private account data.
- Date: 2026-06-22
- Commit: ad78774
- Deployment: dpl_CFiQcrkFFFZ5kReBuJc5wWMo1Mad
Verification
- Type check
- Full test suite
- Production build
- Production live smoke
Safety
- The reports handoff release note exposes only public readiness links, the short commit, deployment id, verification classes, and sanitized safety summaries
- Protected reports packet exports now include owner handoff counts, rollback decision counts, and report handoff readiness while report bodies, raw pasted inputs, account report payloads, account export payloads, private EVE data, token values, token ciphertext, provider credentials, webhook secrets, raw visitor identifiers, and separate-project account data remain excluded
- The /ops reports review panel now surfaces owner handoff and rollback decision counts without exposing protected report contents or account report records
- Rollback decision coverage keeps report body exposure, account-save auth drift, and unexpected webhook delivery blocked before broader report workflow expansion
- Production live smoke verifies protected reports packet lockouts, reports readiness, release feeds, no-secret text boundaries, and expected production commit
Protected EVE Permissions Handoff Coverage
Extended the protected EVE permissions review packet with first-login owner handoff coverage, rollback decision coverage, permission handoff readiness, protected Markdown sections, and /ops permission-review count cards so publicData first login, feature-specific private-scope consent, high-trust scopes, write/action scopes, and account-boundary checks can be reviewed with the same no-secret governance.
- Date: 2026-06-22
- Commit: b2c4736
- Deployment: dpl_5HUpLPbQ7BXT3Kc9VF4rrncq1hQC
Verification
- Type check
- Full test suite
- Production build
- Production live smoke
Safety
- The permissions handoff release note exposes only public readiness links, the short commit, deployment id, verification classes, and sanitized safety summaries
- Protected permissions packet exports now include owner handoff counts, rollback decision counts, and permission handoff readiness while EVE client ID values, client secrets, token values, refresh tokens, access tokens, private EVE data, account payloads, provider credentials, raw logs, and separate-project account data remain excluded
- The /ops permission review panel now surfaces owner handoff and rollback decision counts without exposing protected scope payloads, provider credentials, or user account records
- Rollback decision coverage keeps wrong account or application state, callback or scope drift, and unexpected OAuth or private-data exposure blocked before first-login activation or private-scope expansion
- Production live smoke verifies protected permissions packet lockouts, EVE SSO readiness, release feeds, no-secret text boundaries, and expected production commit
Protected EVE Token Health Handoff Coverage
Extended the protected EVE token-health review packet with first-login owner handoff coverage, rollback decision coverage, token handoff readiness, protected Markdown sections, and /ops token-health count metrics so aggregate token risk, unknown scopes, expiry, stale sessions, high-trust scopes, and write/action scope signals can be reviewed with the same no-secret first-login governance.
- Date: 2026-06-22
- Commit: 9bb9d8a
- Deployment: dpl_6Upu13vyYkE6bJhjyC9LLimWq9we
Verification
- Type check
- Full test suite
- Production build
- Production live smoke
Safety
- The token-health handoff release note exposes only public readiness links, the short commit, deployment id, verification classes, and sanitized safety summaries
- Protected token-health packet exports now include owner handoff counts, rollback decision counts, and token handoff readiness while token values, token ciphertext, refresh tokens, access tokens, raw scopes, character names, account payloads, private EVE data, and raw logs remain excluded
- The /ops account monitor now surfaces token handoff and token rollback counts without exposing protected provider data or token records
- Rollback decision coverage keeps wrong account or application state, callback or scope drift, and unexpected OAuth or private-data exposure blocked before private ESI sync or action-scope expansion
- Production live smoke verifies protected token-health lockouts, EVE SSO readiness, release feeds, no-secret text boundaries, and expected production commit
Protected EVE Auth Flow Handoff Coverage
Extended the protected EVE auth-flow review packet with first-login owner handoff coverage, rollback decision coverage, auth handoff readiness, protected Markdown sections, and /ops auth-flow count metrics so session, login, callback, consent preview, logout, disconnect, account export, and account delete controls can be reviewed with the same no-secret first-login governance.
- Date: 2026-06-22
- Commit: 9c40e6a
- Deployment: dpl_sfokwNxLMxiFG3Ug3C22WZvFyJSF
Verification
- Type check
- Full test suite
- Production build
- Production live smoke
Safety
- The auth-flow handoff release note exposes only public readiness links, the short commit, deployment id, verification classes, and sanitized safety summaries
- Protected auth-flow packet exports now include owner handoff counts, rollback decision counts, and auth handoff readiness while client credential values, token values, cookie values, session payloads, raw scopes, account payloads, private EVE data, and raw logs remain excluded
- The /ops account monitor now surfaces auth route, auth handoff, and auth rollback counts without exposing protected provider data or route bodies
- Rollback decision coverage keeps wrong account or application state, callback or scope drift, and unexpected OAuth or private-data exposure blocked before broader auth activation
- Production live smoke verifies protected auth-flow lockouts, EVE SSO readiness, release feeds, no-secret text boundaries, and expected production commit
Protected EVE SSO Activation Handoff
Added protected EVE SSO activation packet owner handoff and rollback decision coverage so the admin activation rehearsal can show six owner-reviewed first-login steps, three rollback decision points, copy-safe handoff readiness, protected Markdown evidence, and /ops summary cards while public release evidence stays no-secret and public-route only.
- Date: 2026-06-22
- Commit: a6ff48d
- Deployment: dpl_pfnjUbsBFcxyaEfAniaGV5qAX45E
Verification
- Type check
- Full test suite
- Production build
- Production live smoke
Safety
- The protected activation handoff release note exposes only public readiness links, the short commit, deployment id, verification classes, and sanitized safety summaries
- Protected activation packet exports now include owner handoff counts, rollback decision counts, and copy-safe handoff readiness while EVE client ID values, client secrets, access tokens, refresh tokens, cookie values, account payloads, raw logs, and private EVE data remain excluded
- The /ops activation rehearsal cards now surface owner handoff readiness and rollback decision counts without exposing protected provider data or starting OAuth
- Rollback decision coverage is copied from the reviewed EVE SSO readiness lane so wrong account or application state, callback or scope drift, and unexpected OAuth or private-data exposure remain blocked before activation
- Production live smoke verifies the release feeds, EVE SSO readiness, protected admin route lockouts, no-secret text boundaries, and expected production commit
EVE SSO First-Login Handoff Coverage
Added public-safe owner handoff and rollback decision coverage for the EVE SSO first-login lane so WarpIntel account boundaries, callback review, protected credential storage, publicData first-login scope review, controlled sign-in smoke, and tracker evidence can be reviewed while OAuth start, token exchange, private EVE data, cookies, account payloads, and provider console state remain gated.
- Date: 2026-06-22
- Commit: a2f0c39
- Deployment: dpl_HeZTVYv8HaAL5ovzvt8L7jQMxGXi
Verification
- Type check
- Full test suite
- Production build
- Production live smoke
Safety
- The EVE SSO handoff release note exposes only public readiness links, the short commit, deployment id, verification classes, and sanitized safety summaries
- Public EVE SSO readiness now reports six owner-reviewed first-login handoff steps and three rollback decision paths while EVE client ID values, client secrets, access tokens, refresh tokens, cookie values, session payloads, raw scopes, and private EVE data remain excluded
- The handoff covers WarpIntel account boundary review, callback and domain review, credential storage review, first-login publicData scope review, controlled-login smoke review, and tracker record without enabling live OAuth
- Rollback decision paths cover wrong EVE app or account, callback or scope drift, and unexpected OAuth or private-data exposure while runtime login remains blocked until owner review is complete
- Production live smoke verifies EVE SSO handoff markers, rollback decision counts, public health counters, public readiness JSON, release feeds, no-secret text boundaries, and expected production commit
AdSense Readiness Handoff Coverage
Added public-safe owner handoff and rollback decision coverage for the AdSense readiness lane so Google account boundary review, site policy review, public ID and slot review, ads.txt review, public placement review, and tracker evidence can be reviewed while ad scripts, ad serving, provider calls, public IDs, slot values, and protected placements remain gated.
- Date: 2026-06-22
- Commit: fe87947
- Deployment: dpl_9P8Tk3iN75jfKRajZ8d3Ydgsz9e7
Verification
- Type check
- Full test suite
- Production build
- Production live smoke
Safety
- The AdSense handoff release note exposes only public readiness links, the short commit, deployment id, verification classes, and sanitized safety summaries
- Public AdSense readiness now reports six owner-reviewed handoff steps and three rollback decision paths while Google account credentials, verification prompts, ca-pub values, ad slot IDs, payment profile details, tax records, provider cookies, and separate-project account data remain excluded
- The handoff covers Google account boundary review, site policy review, public ID and slot review, ads.txt review, public placement review, and tracker record without enabling ad script loading or public ad serving
- Rollback decision paths cover wrong Google account or site, unsafe public ID or slot output, and unexpected ad load or protected placement while dry runs keep Google provider calls disabled
- Production live smoke verifies AdSense handoff markers, rollback decision counts, public health counters, public readiness JSON, release feeds, no-secret text boundaries, and expected production commit
Stripe Readiness Handoff Coverage
Added public-safe owner handoff and rollback decision coverage for the Stripe voluntary-support readiness lane so account boundary review, support copy, payment-link URL review, feature flags, support-page smoke, and tracker evidence can be reviewed while payment links, checkout creation, provider mutations, and feature unlocks remain gated.
- Date: 2026-06-22
- Commit: aa1af3e
- Deployment: dpl_ADueGX7JtZorP28r7AjeLRicneHu
Verification
- Type check
- Full test suite
- Production build
- Production live smoke
Safety
- The Stripe handoff release note exposes only public readiness links, the short commit, deployment id, verification classes, and sanitized safety summaries
- Public Stripe readiness now reports six owner-reviewed handoff steps and three rollback decision paths while Stripe secret keys, webhook signing secrets, payment links, checkout IDs, customer records, bank details, provider account names, and shared legal-entity fields remain excluded
- The handoff covers Stripe account boundary review, voluntary support copy review, payment-link URL review, feature flag and env review, support page smoke review, and tracker record without enabling checkout creation or public payment links
- Rollback decision paths cover wrong Stripe profile or cross-project branding, unsafe link or paid-unlock copy, and unexpected live payment mutation while dry runs keep Stripe provider writes disabled
- Production live smoke verifies Stripe handoff markers, rollback decision counts, public health counters, public readiness JSON, release feeds, no-secret text boundaries, and expected production commit
Discord Readiness Handoff Coverage
Added public-safe owner handoff and rollback decision coverage for the Discord bot readiness lane so app boundary review, interaction endpoint validation, command rollout, bot-token environment checks, role-sync consent, and tracker evidence can be reviewed while command registration and role sync remain gated.
- Date: 2026-06-22
- Commit: 906bafc
- Deployment: dpl_EisGwPpdhZUxgJKLRxVMjw6FXNhe
Verification
- Type check
- Full test suite
- Production build
- Production live smoke
Safety
- The Discord handoff release note exposes only public readiness links, the short commit, deployment id, verification classes, and sanitized safety summaries
- Public Discord readiness now reports six owner-reviewed handoff steps and three rollback decision paths while bot tokens, app client identifiers, guild identifiers, public keys, install URLs, provider API URLs, and role assignment data remain excluded
- The handoff covers Discord app boundary review, interaction endpoint validation, guild command rollout review, bot-token environment review, role-sync consent review, and tracker record without enabling command registration or role mutation
- Rollback decision paths cover wrong Discord app or guild, endpoint signature validation failure, and unexpected command registration or role mutation while dry runs keep Discord provider writes disabled
- Production live smoke verifies Discord handoff markers, rollback decision counts, public health counters, public readiness JSON, release feeds, no-secret text boundaries, and expected production commit
Email Readiness Handoff Coverage
Added public-safe owner handoff and rollback decision coverage for the transactional email and Resend readiness lane so sender identity, provider boundary, feature flags, template safety, delivery smoke, and tracker evidence can be reviewed while live sending remains disabled.
- Date: 2026-06-22
- Commit: c999e70
- Deployment: dpl_73bFahGF4SuY9L3c2gPWfmnso4Bd
Verification
- Type check
- Full test suite
- Production build
- Production live smoke
Safety
- The email handoff release note exposes only public readiness links, the short commit, deployment id, verification classes, and sanitized safety summaries
- Public email readiness now reports six owner-reviewed handoff steps and three rollback decision paths while Resend API keys, SMTP credentials, webhook secrets, sender addresses, reply-to addresses, recipient addresses, message IDs, and raw support messages remain excluded
- The handoff covers WarpIntel sender identity review, provider account boundary review, feature flag and env review, template no-secret review, non-sensitive delivery smoke, and tracker record without enabling live sends
- Rollback decision paths cover provider boundary mismatch, sender or webhook verification failure, and unexpected live send or secret risk while dry runs keep provider sends disabled
- Production live smoke verifies email handoff markers, rollback decision counts, public health counters, public readiness JSON, release feeds, no-secret text boundaries, and expected production commit
Vercel GitHub Handoff Coverage
Added public-safe owner handoff and rollback decision coverage for the Vercel/GitHub provider-link readiness lane so production deploys, repository boundaries, preview smoke, tracker confirmation, and rollback gates can be reviewed without provider mutations or credential exposure.
- Date: 2026-06-22
- Commit: 154f9df
- Deployment: dpl_9AoynuGu3jTQ5bwXXsMWvFxMbKDd
Verification
- Type check
- Full test suite
- Production build
- Production live smoke
Safety
- The Vercel/GitHub handoff release note exposes only public readiness links, the short commit, deployment id, verification classes, and sanitized safety summaries
- Public Vercel/GitHub readiness now reports six owner-reviewed handoff steps and three rollback decision paths while provider tokens, OIDC values, account cookies, installation IDs, private repository data, environment values, database URLs, and cron secrets remain excluded
- The handoff covers production deploy baseline, repository boundary review, Vercel project scope, preview smoke planning, environment secret boundaries, and tracker confirmation without changing provider settings
- Rollback decision paths cover wrong provider account, repository link mismatch, and preview or production smoke regression while dry runs keep provider mutations, GitHub auth flow, token return, env-var changes, and repo-link changes disabled
- Production live smoke verifies Vercel/GitHub handoff markers, rollback decision counts, public health counters, public readiness JSON, release feeds, no-secret text boundaries, and expected production commit
Growth Readiness Handoff
Added public-safe growth owner handoff and rollback decision coverage across growth readiness, public health, status, and production live smoke so analytics, search verification, and sitemap submission can be reviewed without enabling provider calls, publishing verification tokens, or exposing traffic data.
- Date: 2026-06-22
- Commit: bd10dab
- Deployment: dpl_9svK8KzD1hAc9sBHekvChkPLeFP1
Verification
- Type check
- Full test suite
- Production build
- Production live smoke
Safety
- The growth readiness handoff release note exposes only public readiness links, the short commit, deployment id, verification classes, and sanitized safety summaries
- Public growth readiness now reports six owner-reviewed setup handoff steps and three rollback decision paths while analytics IDs, verification token values, Google/Bing account details, provider cookies, Search Console screenshots, raw pageview data, and workflow-click payloads remain excluded
- The handoff covers telemetry provider boundaries, privacy copy review, search token entry, sitemap submission proof, traffic signal review, and tracker records without enabling provider calls or publishing protected setup details
- Rollback decision paths cover provider boundary mismatch, token leak risk, and unexpected telemetry capture while dry runs keep sitemap submissions, telemetry enablement, and verification-token output disabled
- Production live smoke verifies growth readiness handoff markers, rollback decision counts, public health counters, public status coverage, release feeds, no-secret text boundaries, and expected production commit
EVE SSO Launch Readiness Alignment
Aligned the public launch readiness lane with the no-secret EVE SSO readiness model so staged production credentials, publicData first-login scope, and the exact WarpIntel callback are reflected correctly while public sign-in remains hidden behind the explicit feature flag and live sign-in smoke gate.
- Date: 2026-06-22
- Commit: e643a29
- Deployment: dpl_45iye4b55i4bV33T8qSrt4QrPsJc
Verification
- Type check
- Full test suite
- Production build
- Production live smoke
Safety
- The EVE SSO launch readiness release note exposes only public readiness links, the short commit, deployment id, verification classes, and sanitized safety summaries
- Public launch readiness now distinguishes staged callback readiness from public sign-in activation while EVE client IDs, client secrets, access tokens, refresh tokens, private EVE data, and account records remain excluded
- The launch lane continues to keep public sign-in hidden until the feature flag and controlled live sign-in smoke are approved even when credentials, publicData, and the production callback are staged
- Public status/readiness counters now classify the EVE callback action as staged instead of blocked when the callback is configured, without exposing provider credentials, setup packet contents, or separate-project account details
- Production live smoke verifies launch readiness, EVE readiness, integrations, public status and health counters, release feeds, no-secret text boundaries, and expected production commit
Sentry Sample Capture Handoff
Added public-safe Sentry sample-capture owner handoff steps and rollback decision paths across Sentry readiness, public health, and production live smoke so future provider capture can be reviewed while capture remains off and provider calls stay disabled.
- Date: 2026-06-22
- Commit: 0cd28f8
- Deployment: dpl_33eonS5BbT4ktveFfem8syuiNVX2
Verification
- Type check
- Full test suite
- Production build
- Production live smoke
Safety
- The Sentry sample-capture handoff release note exposes only public readiness links, the short commit, deployment id, verification classes, and sanitized safety summaries
- Public Sentry readiness now reports owner-handoff and rollback decision counts while DSN values, provider org identifiers, provider project identifiers, event URLs, stack traces, cookies, authorization headers, EVE tokens, private account data, and raw pasted analyzer inputs remain excluded
- The handoff covers provider boundary confirmation, safe trigger route preparation, scrub preview review, provider event review, trigger disablement, and release tracker record as owner-reviewed steps without publishing protected setup packet contents
- Rollback decision paths cover provider boundary mismatch, scrub preview failure, and unexpected capture activity while keeping capture off, provider calls disabled, and public health aligned with the no-secret boundary
- Production live smoke verifies Sentry readiness handoff markers, rollback decision counts, public health counters, public readiness JSON, release feeds, no-secret text boundaries, and expected production commit
Backup Restore Drill Handoff
Added public-safe restore-drill owner handoff steps and rollback decision paths across backup readiness, public status, public health, and production live smoke so recovery rehearsal can be reviewed without exposing provider artifacts or private database materials.
- Date: 2026-06-22
- Commit: 28d87a2
- Deployment: dpl_GSdCVZ4CoveD4QC5netraPxKqe9z
Verification
- Type check
- Full test suite
- Production build
- Production live smoke
Safety
- The backup restore-drill handoff release note exposes only public readiness links, the short commit, deployment id, verification classes, and sanitized safety summaries
- Public backup readiness now reports owner-handoff and rollback decision counts while database connection values, cron secret values, migration tags, SQL dumps, provider-console backup artifacts, token ciphertext, raw IPs, raw user-agent strings, and raw pasted analyzer inputs remain excluded
- The handoff covers baseline review, provider boundary review, isolated restore path, migration reconcile, app proof review, and tracker release record as owner-reviewed steps without publishing provider-console restore details
- Rollback decision paths cover deployment regression, data restore mismatch, and environment boundary mismatch without exposing database URLs, Neon passwords, Vercel rollback targets, provider artifacts, EVE tokens, private EVE data, or separate-project account data
- Production live smoke verifies backup readiness handoff markers, rollback decision counts, public health counters, status rollup counters, release feeds, no-secret text boundaries, and expected production commit
Revenue Email Provider Readiness
Added transactional email as a third public-safe revenue readiness lane beside Stripe support and AdSense, with provider labels, public routes, protected setup and dry-run availability, and aggregate activation-criteria counts exposed through revenue readiness, public health, public status, support readiness, and production live smoke.
- Date: 2026-06-22
- Commit: 780b83b
- Deployment: dpl_7iEMEhhB9RBqEeYTDtZbLDJh4AvG
Verification
- Type check
- Full test suite
- Production build
- Production live smoke
Safety
- The revenue email provider readiness release note exposes only public readiness links, the short commit, deployment id, verification classes, and sanitized safety summaries
- Public revenue readiness now reports Stripe support, AdSense, and transactional email provider lanes while payment links, provider keys, SMTP credentials, mailbox addresses, customer records, and protected setup packet URLs remain excluded
- The revenue rollup reports 23 combined provider activation criteria as aggregate counts across Stripe support, AdSense, and transactional email without exposing public environment variable names or provider setup values
- Payment links, Stripe secrets, webhook signing secrets, Google account credentials, email provider keys, SMTP credentials, mailbox addresses, customer data, payment profile details, tax records, EVE tokens, private EVE data, and separate-project account data remain excluded
- Production live smoke verifies revenue readiness, support readiness, public health counters, public status rollups, release feeds, no-secret text boundaries, and expected production commit
Next Actions Activation Handoff
Added public-safe activation handoff lanes across the next-actions board, next-actions JSON feed, public health, and production live smoke so project-owner, provider/account, build-team, feature-gate, and production-planning actions stay grouped without exposing protected setup details.
- Date: 2026-06-22
- Commit: 38dc098
- Deployment: dpl_63NqH2tDEk8vUaBrXucNRW9CiPQm
Verification
- Type check
- Full test suite
- Production build
- Production live smoke
Safety
- The next-actions activation handoff release note exposes only public readiness links, the short commit, deployment id, verification classes, and sanitized safety summaries
- Public next actions now report activation-handoff counts while provider credentials, API keys, passwords, EVE tokens, private EVE data, account data, raw submissions, and protected setup packet contents remain excluded
- The handoff groups project-owner, provider/account, build-team, feature-gate, and production-planning actions while requiring top-action coverage, waiting-lane coverage, buildable-lane coverage, and no-secret public text
- Provider credentials, API keys, passwords, EVE tokens, private EVE data, account data, raw submissions, protected setup packet contents, provider cookies, private logs, and separate-project account data remain excluded
- Production live smoke verifies next-actions handoff readiness, public health counters, public feed markers, public page markers, release feeds, no-secret text boundaries, and expected production commit
Next Actions Activation Criteria
Added eight required next-actions activation criteria across the public action board, public next-actions feed, public health, and production live smoke so launch and integration follow-up stays useful while provider/account blockers remain separated from buildable work.
- Date: 2026-06-22
- Commit: 247a025
- Deployment: dpl_NQB25yb8rffjTWT6KwcCSM67eJib
Verification
- Type check
- Full test suite
- Production build
- Production live smoke
Safety
- The next-actions activation release note exposes only public readiness links, the short commit, deployment id, verification classes, and sanitized safety summaries
- Public next actions now report activation-criteria counts while provider credentials, API keys, passwords, EVE tokens, private EVE data, account data, raw submissions, and protected setup packet contents remain excluded
- The criteria require a merged launch/integration queue, blocked versus staged work separation, build-while-blocked lanes, public owner categories, critical external lane priority, public link coverage, protected setup packets linked-not-expanded, and a no-secret public action surface
- Provider credentials, API keys, passwords, EVE tokens, private EVE data, account data, raw submissions, protected setup packet contents, provider cookies, private logs, and separate-project account data remain excluded
- Production live smoke verifies next-actions readiness, public health counters, public feed markers, public page markers, release feeds, no-secret text boundaries, and expected production commit
Vercel GitHub Activation Criteria
Added eight required Vercel/GitHub activation criteria across public deployment readiness, protected setup review, public health, and production live smoke so provider-link readiness remains gated until production deploys, the expected WarpIntel repo identity, Vercel project link confirmation, protected no-mutation dry runs, preview smoke, and tracker confirmation are ready.
- Date: 2026-06-22
- Commit: 8210f5e
- Deployment: dpl_5w2zEXSVQAEvJNp93vYan3czsqWs
Verification
- Type check
- Full test suite
- Production build
- Production live smoke
Safety
- The Vercel/GitHub activation release note exposes only public readiness links, the short commit, deployment id, verification classes, and sanitized safety summaries
- Public Vercel/GitHub readiness now reports activation-criteria counts while Vercel tokens, GitHub tokens, OIDC values, provider account cookies, installation IDs, private repository data, and environment values remain excluded
- The criteria require production deploy readiness, expected WarpIntel repo identity, Vercel project link confirmation, protected setup packet readiness, protected no-provider-mutation dry run, separate-project boundary, preview deploy smoke gate, and tracker confirmation gate
- Vercel tokens, GitHub tokens, OIDC values, provider account cookies, installation IDs, private repository data, env var values, database URLs, cron secrets, EVE tokens, private EVE data, and separate-project account data remain excluded
- Production live smoke verifies Vercel/GitHub readiness, public health counters, protected setup and dry-run boundaries, release feeds, no-secret text boundaries, and expected production commit
Backup Recovery Activation Criteria
Added eight required backup recovery activation criteria across public readiness, protected recovery review, public health, status readiness, and production live smoke so database restore readiness remains gated until the dedicated WarpIntel Neon boundary, runtime gates, safe exports, restore acceptance evidence, protected dry run, and owner-reviewed restore drill are ready.
- Date: 2026-06-22
- Commit: 5fbfbf7
- Deployment: dpl_CoJSXirHdna7q2ztHqjzurzA47Zm
Verification
- Type check
- Full test suite
- Production build
- Production live smoke
Safety
- The backup recovery activation release note exposes only public readiness links, the short commit, deployment id, verification classes, and sanitized safety summaries
- Public backup readiness now reports activation-criteria counts while database connection values, cron secret values, migration tags, SQL dumps, provider-console backup artifacts, token ciphertext, raw IPs, raw user-agent strings, and raw pasted analyzer inputs remain excluded
- The criteria require a dedicated WarpIntel Neon project boundary, migration ledger readiness, runtime database gate, protected heartbeat gate, safe recovery exports, restore acceptance criteria readiness, protected no-provider-mutation dry run, and owner-reviewed restore drill gate
- Database connection values, cron secret values, migration tags, SQL dumps, Neon passwords, Vercel rollback targets, provider-console backup artifacts, EVE tokens, private EVE data, and separate-project account data remain excluded
- Production live smoke verifies backup readiness, public health counters, status rollup counters, protected recovery packets and dry-run boundaries, release feeds, no-secret text boundaries, and expected production commit
Sentry Activation Criteria
Added eight required Sentry activation criteria across public readiness, protected setup review, public health, monitoring readiness, and production live smoke while tightening actual browser, server, and edge Sentry capture so DSNs and the feature flag are not enough until the owner-reviewed sample-capture verification gate is ready.
- Date: 2026-06-22
- Commit: da6361b
- Deployment: dpl_BnnH31JVD1RCACurFnpHdTReiPqd
Verification
- Type check
- Full test suite
- Production build
- Production live smoke
Safety
- The Sentry activation release note exposes only public readiness links, the short commit, deployment id, verification classes, and sanitized safety summaries
- Public Sentry readiness now reports activation-criteria counts while DSN values, provider org or project identifiers, event URLs, stack traces, cookies, authorization headers, and raw pasted analyzer inputs remain excluded
- The criteria require a WarpIntel-only provider boundary, feature flag and DSN gate, provider project review, installed instrumentation gate, private data scrub gate, protected no-provider-call dry run, sample-capture criteria readiness, and owner-reviewed sample-capture gate
- Sentry DSN values, provider org or project identifiers, event URLs, stack traces, cookies, authorization headers, EVE tokens, private EVE data, raw pasted analyzer inputs, and separate-project account data remain excluded
- Production live smoke verifies Sentry readiness, public health counters, protected setup and dry-run boundaries, monitoring readiness, release feeds, no-secret text boundaries, and expected production commit
AI Activation Criteria
Added eight required AI activation criteria across public readiness, protected setup review, public health, and production live smoke while tightening actual OpenAI provider calls so feature flag, approved key, spend approval, and first-tool smoke verification are all required before live AI enhancement can run.
- Date: 2026-06-22
- Commit: 6330c60
- Deployment: dpl_GFggkWFS4CBpR2bQTHLXuUbFo75b
Verification
- Type check
- Full test suite
- Production build
- Production live smoke
Safety
- The AI activation release note exposes only public readiness links, the short commit, deployment id, verification classes, and sanitized safety summaries
- Public AI readiness now reports activation-criteria counts while OpenAI keys, model environment values, billing details, raw prompts, token-spend records, and raw pasted analyzer inputs remain excluded
- The criteria require a WarpIntel/Olympus account boundary, feature flag and key gate, spend and budget review gate, first-tool scope boundary, deterministic fallback, protected no-provider-call dry run, input and output safety boundary, and first-tool smoke review
- OpenAI keys, model environment values, billing details, raw prompts, token-spend records, raw pasted analyzer inputs, EVE tokens, private EVE data, and separate-project account data remain excluded
- Production live smoke verifies AI readiness, public health counters, protected setup and dry-run boundaries, release feeds, no-secret text boundaries, and expected production commit
Transactional Email Activation Criteria
Added eight required transactional email activation criteria across public readiness, protected setup and dry-run packets, public health, and production live smoke so Resend or SMTP sending remains gated until provider approval, sender review, live-send feature flag review, reply and webhook review, no-provider-send dry runs, and no-secret smoke coverage are ready.
- Date: 2026-06-21
- Commit: cae6e12
- Deployment: dpl_JAM93GEq7xrwGsPL88eXqnmHzX3L
Verification
- Type check
- Full test suite
- Production build
- Production live smoke
Safety
- The transactional email activation release note exposes only public readiness links, the short commit, deployment id, verification classes, and sanitized safety summaries
- Public email readiness now reports activation-criteria counts while provider keys, SMTP credentials, webhook secrets, sender addresses, reply-to addresses, recipient addresses, message ids, and raw support messages remain excluded
- The criteria require a WarpIntel domain sender boundary, provider approval and sender gate, feature-flagged live-send gate, no-sensitive-template boundary, support receipt first adapter, reply and webhook review gate, protected no-send dry run, and public no-secret smoke coverage
- Provider credentials, SMTP credentials, webhook secrets, mailbox addresses, message ids, raw support queue bodies, EVE tokens, private EVE data, and separate-project account data remain excluded
- Production live smoke verifies email readiness, public health counters, protected setup and dry-run boundaries, release feeds, no-secret text boundaries, and expected production commit
Discord Bot And Role Sync Activation Criteria
Added eight required Discord activation criteria across public readiness, protected setup and dry-run packets, public health, and production live smoke so Discord commands and future role sync remain gated until signed endpoint validation, app identity review, first-guild rollout, role-sync gating, no-provider-mutation dry runs, and no-secret smoke coverage are ready.
- Date: 2026-06-21
- Commit: a1a393b
- Deployment: dpl_ChzoQnxsne8xy5gE4gA243nzNVhW
Verification
- Type check
- Full test suite
- Production build
- Production live smoke
Safety
- The Discord activation release note exposes only public readiness links, the short commit, deployment id, verification classes, and sanitized safety summaries
- Public Discord readiness now reports activation-criteria counts while bot tokens, client IDs, guild IDs, public keys, install URLs, Discord API URLs, and role assignment data remain excluded
- The criteria require a separate WarpIntel Discord app boundary, signed interaction endpoint, public key and app identity gate, bot token and first-guild gate, role-sync feature gate, guild command registration review, protected no-mutation dry run, and public no-secret smoke coverage
- Discord bot tokens, client IDs, guild IDs, public keys, install URLs, provider API URLs, role assignment data, provider cookies, authorization headers, EVE tokens, private EVE data, and separate-project account data remain excluded
- Production live smoke verifies Discord readiness, public health counters, protected setup and dry-run boundaries, public command and interaction endpoints, release feeds, no-secret text boundaries, and expected production commit
AdSense Review Activation Criteria
Added eight required AdSense activation criteria across public readiness, protected setup and dry-run packets, public health, and production live smoke so public ads remain disabled until Google review, public provider IDs, ads.txt, public-page-only placement, no-provider-call dry run, protected review packets, and no-secret smoke coverage are ready.
- Date: 2026-06-21
- Commit: 61db403
- Deployment: dpl_6Ng9bqVBqfGGqPewbWVL9U7o4FdH
Verification
- Type check
- Full test suite
- Production build
- Production live smoke
Safety
- The AdSense activation release note exposes only public readiness links, the short commit, deployment id, verification classes, and sanitized safety summaries
- Public AdSense readiness now reports activation-criteria counts while public provider identifiers, ad slot IDs, Google account details, verification prompts, payment profile details, and tax records remain excluded
- The criteria require approved account/provider review, reviewable site policies, public ID format gates, ads.txt authorized-seller gating, public-page-only placements, no-Google-call dry runs, protected review packets, and public no-secret smoke coverage
- Google account credentials, verification prompts, phone numbers, payment profile details, tax records, provider cookies, public env values, EVE tokens, private EVE data, and separate-project account data remain excluded
- Production live smoke verifies AdSense readiness, public health counters, protected setup and dry-run boundaries, ads.txt, release feeds, no-secret text boundaries, and expected production commit
Stripe Support Activation Criteria
Added seven required Stripe support-link activation criteria across public readiness, protected setup and dry-run packets, public health, and production live smoke so voluntary support remains gated until the WarpIntel-only account boundary, reviewed HTTPS support link, no-feature-unlock rule, no-live-provider dry run, no-secret surface, and smoke evidence are ready.
- Date: 2026-06-21
- Commit: edb742f
- Deployment: dpl_4zsGeg2E8SpPpVwu9VXZfd4uZUze
Verification
- Type check
- Full test suite
- Production build
- Production live smoke
Safety
- The Stripe activation release note exposes only public readiness links, the short commit, deployment id, verification classes, and sanitized safety summaries
- Public Stripe readiness now reports activation-criteria counts while payment links, checkout IDs, customer records, provider account records, and shared legal-entity details remain excluded
- The criteria require a separate WarpIntel-only Stripe account boundary, reviewed Stripe-hosted HTTPS support-link gate, feature-flagged public display, voluntary support with no app unlocks, protected no-live-provider dry runs, public no-secret readiness surfaces, and production smoke coverage
- Stripe secret keys, webhook secrets, payment links, checkout IDs, customer records, bank details, public env values, shared legal-entity fields, EVE tokens, private EVE data, and separate-project account data remain excluded
- Production live smoke verifies Stripe readiness, public health counters, protected setup and dry-run boundaries, release feeds, no-secret text boundaries, hidden-link guarantees, and expected production commit
EVE SSO Activation Acceptance Criteria
Added seven required EVE SSO activation criteria across public readiness, protected activation packets, public health, and production live smoke so real login stays gated until callback, credential-presence, publicData, consent-preview, runtime-guard, protected-review, and smoke-route evidence is ready.
- Date: 2026-06-21
- Commit: d650fe2
- Deployment: dpl_2XKvMLMpHG6ariTjuNbXxj8T2Ysf
Verification
- Type check
- Full test suite
- Production build
- Production live smoke
Safety
- The EVE SSO activation-criteria release note exposes only public readiness links, the short commit, deployment id, verification classes, and sanitized safety summaries
- Public EVE SSO readiness now reports activation-criteria counts while credential values, callback secrets, OAuth state values, and provider-console state remain excluded
- The criteria require production callback exact match, runtime credential presence by boolean only, publicData first login, feature consent previews, runtime guard before OAuth state/provider redirect, protected review packets, and live-smoke EVE auth boundary routes
- EVE client IDs, client secrets, access tokens, refresh tokens, token ciphertext, private EVE data, account payloads, cookies, raw logs, provider-console state, and separate-project account data remain excluded
- Production live smoke verifies EVE SSO readiness, public health counters, protected activation packet boundaries, release feeds, no-secret text boundaries, and expected production commit
Growth Activation Readiness Criteria
Added required activation criteria to growth readiness so analytics, Speed Insights, search verification, sitemap submission, privacy review, and tracker evidence stay gated until owner/provider review is complete.
- Date: 2026-06-21
- Commit: 0b3626d
- Deployment: dpl_6w9TTdaG7z8ntSMXakujWNYb5hun
Verification
- Type check
- Full test suite
- Production build
- Production live smoke
Safety
- The growth activation release note exposes only public readiness links, the short commit, deployment id, verification classes, and sanitized safety summaries
- Public growth readiness now reports activation-criteria counts while provider calls, telemetry enablement, search submission, and token values remain protected
- The criteria require owner telemetry approval, Vercel Analytics flag review, Speed Insights flag review, Google verification, Bing verification, sitemap submission review, and secret-free privacy/tracker evidence
- Analytics IDs, verification token values, Google or Bing account details, provider cookies, Search Console screenshots, raw pageview data, workflow-click payloads, EVE tokens, private EVE data, raw pasted analyzer inputs, and separate-project account data remain excluded
- Production live smoke verifies growth readiness, public health counters, status readiness, release feeds, no-secret text boundaries, and expected production commit
Sentry Sample Capture Readiness Criteria
Added explicit no-secret scrub-rule counts and sample-capture acceptance criteria to Sentry readiness so provider capture remains off until a protected admin-only sample event passes owner review.
- Date: 2026-06-21
- Commit: 927a0de
- Deployment: dpl_FFrZuZGX1fuHGraQrjTkfmdopupF
Verification
- Type check
- Full test suite
- Production build
- Production live smoke
Safety
- The Sentry sample-capture release note exposes only public readiness links, the short commit, deployment id, verification classes, and sanitized safety summaries
- Public Sentry readiness now reports scrub-rule counts and required sample-capture criteria counts while provider capture remains gated and inactive
- The criteria require a protected admin-only trigger, a static non-sensitive message, local scrubbed-event preview, provider event review, trigger removal, and secret-free tracker evidence before capture can be considered verified
- Sentry DSNs, provider org or project identifiers, event URLs, stack traces, cookies, authorization headers, EVE tokens, token ciphertext, private EVE data, raw pasted analyzer inputs, browser agent strings, and separate-project account data remain excluded
- Production live smoke verifies Sentry readiness, public health counters, release feeds, no-secret text boundaries, and expected production commit
Backup Restore Drill Acceptance Criteria
Added explicit restore-drill acceptance criteria to backup readiness so public health and readiness feeds can prove the checklist exists before any real Neon or Vercel recovery drill is marked verified.
- Date: 2026-06-21
- Commit: 71db612
- Deployment: dpl_6qCS8gFJRvL9AzcokSQkuqDv3AHj
Verification
- Type check
- Full test suite
- Production build
- Production live smoke
Safety
- The backup restore-drill release note exposes only public readiness links, the short commit, deployment id, verification classes, and sanitized safety summaries
- Public backup readiness now reports restore-drill acceptance-criteria counts while protected backup packet and dry-run routes keep detailed review evidence behind admin authorization
- The criteria require release fingerprint, route smoke, migration ledger, protected ops snapshot, and secret-free tracker evidence before a real restore drill can be marked verified
- Database URLs, cron secrets, migration SQL, migration tags, Neon passwords, provider-console restore artifacts, SQL dumps, EVE tokens, token ciphertext, private EVE data, raw IPs, raw user agents, and separate-project account data remain excluded
- Production live smoke verifies backup readiness, public health counters, status readiness, release feeds, no-secret text boundaries, and expected production commit
EVE Login Runtime Guard Readiness
Exposed the EVE login runtime callback guard in public readiness, public health, and live smoke so production checks prove OAuth cannot start on a callback mismatch before state cookies or provider redirects are created.
- Date: 2026-06-21
- Commit: 9e10234
- Deployment: dpl_AVhGaTm6uPyDD3x8tzxUHf8Ktev5
Verification
- Type check
- Full test suite
- Production build
- Production live smoke
Safety
- The EVE login runtime-guard release note exposes only public readiness links, the short commit, deployment id, verification classes, and sanitized safety summaries
- Runtime guard readiness reports enforced booleans, the approved expected callback, and the safe mismatch status without exposing the configured callback value
- Public health and live smoke now require the runtime guard count and pre-OAuth state/provider redirect block guarantees before production can pass
- EVE client IDs, client secrets, access tokens, refresh tokens, token ciphertext, configured callback values, private EVE data, provider console state, and separate-project account data remain excluded
- Production live smoke verifies EVE SSO readiness, public health, release feeds, no-secret text boundaries, and expected production commit
EVE Login Production Callback Gate
Added a runtime guard to the EVE login route so CCP OAuth cannot start unless the configured callback exactly matches the approved WarpIntel production callback origin.
- Date: 2026-06-21
- Commit: 55066b9
- Deployment: dpl_6TNuiUA3Wsa8fp3ur2emnCok8vAw
Verification
- Type check
- Full test suite
- Production build
- Production live smoke
Safety
- The EVE login callback-gate release note exposes only public readiness links, the short commit, deployment id, verification classes, and sanitized safety summaries
- Callback mismatches redirect safely inside WarpIntel before OAuth state cookies are set or a CCP authorize URL is created
- Dashboard sign-in messaging now explains the paused callback state without exposing configured client credential values
- EVE client IDs, client secrets, access tokens, refresh tokens, token ciphertext, private EVE data, provider console state, and separate-project account data remain excluded
- Production live smoke verifies EVE SSO readiness, consent-preview routes, auth boundary routes, release feeds, no-secret text boundaries, and expected production commit
EVE SSO Callback Origin Guard
Hardened EVE SSO readiness so setup packets, dry runs, and expected callback checks fall back to the approved WarpIntel production origin when the runtime site URL is local, non-HTTPS, malformed, or not the WarpIntel app domain.
- Date: 2026-06-21
- Commit: 69d5a79
- Deployment: dpl_73h3BBykh1tAMGe8nx2UxPgVzhtz
Verification
- Type check
- Full test suite
- Production build
- Production live smoke
Safety
- The EVE SSO callback guard release note exposes only public readiness links, the short commit, deployment id, verification classes, and sanitized safety summaries
- Unsafe, local, preview, malformed, or non-WarpIntel site URLs cannot make a local callback appear production-ready
- EVE setup packets and dry runs continue to publish the approved callback target without exposing configured client credential values
- EVE client IDs, client secrets, access tokens, refresh tokens, token ciphertext, private EVE data, provider console state, and separate-project account data remain excluded
- Production live smoke verifies EVE SSO readiness, consent-preview routes, auth boundary routes, release feeds, no-secret text boundaries, and expected production commit
Stripe Support Link Host Gate
Restricted public Stripe support-link readiness to trusted Stripe-hosted HTTPS checkout and payment-link hosts so arbitrary HTTPS links cannot be treated as valid support destinations before the Stripe feature flag is enabled.
- Date: 2026-06-21
- Commit: 43c829b
- Deployment: dpl_7LngpZ2wQKUPnLcrgb2LURHVEVpz
Verification
- Type check
- Full test suite
- Production build
- Production live smoke
Safety
- The Stripe host-gate release note exposes only public readiness links, the short commit, deployment id, verification classes, and sanitized safety summaries
- Support-link readiness now accepts only Stripe-hosted HTTPS checkout or payment-link URLs and keeps arbitrary HTTPS URLs configured-but-not-valid
- Protected setup packets do not echo rejected support URLs and require a WarpIntel-only, Stripe-hosted, HTTPS, reviewed support link before the public Stripe flag can be enabled
- Stripe secret keys, webhook signing secrets, payment links, checkout IDs, customer records, shared legal-entity fields, bank details, provider account data, and separate-project account data remain excluded
- Production live smoke verifies Stripe readiness, revenue readiness, support readiness, release feeds, no-secret text boundaries, and expected production commit
Gated Sentry Instrumentation
Added gated Sentry instrumentation for client, server, and edge runtime paths; a global error boundary; scrubbed event handling; report-only ingest CSP allowance; and public readiness signals that keep capture inactive until WarpIntel-only provider values and feature flags are configured.
- Date: 2026-06-21
- Commit: f33be5f
- Deployment: dpl_3CDPmoNKqVMVRKZxHMM8ymfrAnX7
Verification
- Type check
- Full test suite
- Production build
- Production live smoke
Safety
- The Sentry instrumentation release note exposes only public readiness links, the short commit, deployment id, verification classes, and sanitized safety summaries
- Error capture stays gated behind WarpIntel-specific provider configuration and feature flags, with sample capture marked unverified until a safe production event is reviewed
- Event scrubbing removes authorization, cookie, token, secret, database, raw input, visitor identifier, browser agent, private EVE data, account payload, and provider credential fields before capture
- Source-map upload stays disabled until a WarpIntel-only provider token is configured, and provider telemetry remains disabled in the build wrapper
- Production live smoke verifies the Sentry readiness routes, release feeds, health counts, no-secret text boundaries, and expected production commit
Protected EVE Auth Flow Review Packet
Added an admin-only EVE auth-flow review packet with JSON and Markdown exports, Ops dashboard download links, protected-export smoke coverage, and public readiness counts for session status, login gate, callback state failure, consent preview, logout, disconnect, account export, and account delete routes without exposing protected route bodies.
- Date: 2026-06-21
- Commit: 65dbadb
- Deployment: dpl_5VDwtFDX7V5b4CfoYm6Fed6KzdPb
Verification
- Type check
- Full test suite
- Production build
- Production live smoke
Safety
- The EVE auth-flow release note exposes only public readiness links, the short commit, deployment id, verification classes, and sanitized safety summaries
- The actual EVE auth-flow JSON and Markdown downloads stay behind protected admin routes with private no-store headers and unauthenticated 401 responses
- The auth-flow packet excludes EVE client credential values, token values, token ciphertext, cookie values, session payloads, raw scopes, account payloads, private EVE data, raw logs, provider credentials, raw visitor identifiers, browser agent strings, separate-project account details, and secrets
- The auth-flow review starts no OAuth flow, makes no EVE/CCP calls, and reads no protected session body from public surfaces
- Production live smoke verifies the protected auth-flow routes, updated protected-export counts, release feeds, no-secret text boundaries, and expected production commit
Protected EVE Token Health Review Packet
Added an admin-only EVE token health review packet with JSON and Markdown exports, Ops dashboard review links, token-health action counts, protected-export smoke coverage, and public readiness counts that show the new export coverage without exposing token values or protected route bodies.
- Date: 2026-06-21
- Commit: 97549c0
- Deployment: dpl_6XM5EWhTR49WF7YfQ1qaYKcwUU2J
Verification
- Type check
- Full test suite
- Production build
- Production live smoke
Safety
- The EVE token health release note exposes only public readiness links, the short commit, deployment id, verification classes, and sanitized safety summaries
- The actual EVE token health JSON and Markdown downloads stay behind protected admin routes with private no-store headers and unauthenticated 401 responses
- The token health packet excludes token values, token ciphertext, access tokens, refresh tokens, raw scopes, account payloads, character names, private EVE data, raw logs, provider credentials, raw visitor identifiers, browser agent strings, separate-project account details, and secrets
- The token health review starts no OAuth flow and makes no EVE/CCP calls; it summarizes existing aggregate token-health status only
- Production live smoke verifies the protected token-health routes, updated protected-export counts, release feeds, no-secret text boundaries, and expected production commit
Protected EVE SSO Activation Packet
Added an admin-only EVE SSO activation rehearsal packet with JSON and Markdown exports, an Ops dashboard activation panel, protected-export smoke coverage for the packet routes, and public readiness counts that show the new export coverage without exposing private route bodies.
- Date: 2026-06-21
- Commit: 17038f5
- Deployment: dpl_2GhQcyKLV3JoxA9kGDHLigDgviqL
Verification
- Type check
- Full test suite
- Production build
- Production live smoke
Safety
- The EVE SSO activation packet release note exposes only public readiness links, the short commit, deployment id, verification classes, and sanitized safety summaries
- The actual EVE SSO activation packet JSON and Markdown downloads stay behind protected admin routes with private no-store headers and unauthenticated 401 responses
- The activation packet summarizes callback, credential, publicData, rehearsal, rollback, and smoke-check state without starting OAuth or contacting EVE/CCP
- EVE client credential values, access tokens, refresh tokens, token ciphertext, private EVE data, account payloads, raw logs, provider credentials, raw visitor identifiers, browser agent strings, separate-project account details, and secrets remain excluded from public release surfaces
- Production live smoke verifies the protected activation routes, updated protected-export counts, release feeds, no-secret text boundaries, and expected production commit
Protected EVE Permission Review Packet
Added admin-only EVE permission review packet JSON and Markdown exports so reviewers can download permission-group counts, planned scope counts, allowed scope coverage, feature consent plan counts, preview-safe consent routes, high-trust/write-action counts, callback readiness booleans, and safety boundaries without exposing private EVE data publicly.
- Date: 2026-06-21
- Commit: 8231be3
- Deployment: dpl_CRBwg19pVen9NakU3DrAWRjDSmkE
Verification
- Type check
- Full test suite
- Production build
- Production live smoke
Safety
- The EVE permission review packet release note exposes only public readiness links, the short commit, deployment id, verification classes, and sanitized safety summaries
- EVE client credential values, access tokens, refresh tokens, token ciphertext, private EVE data, account payloads, raw logs, provider credentials, raw visitor identifiers, browser agent strings, separate-project account details, and secrets remain excluded from public release surfaces
- The actual EVE permission review packet JSON and Markdown downloads stay behind protected admin routes with private no-store headers and unauthenticated 401 responses
- Public Ops, Permissions, EVE SSO, Data Rights, Monitoring, Status, Health, and Release readiness surfaces show aggregate counts and safe route references only
- Production live smoke verifies the protected packet routes, updated protected-export counts, release feeds, no-secret text boundaries, and expected production commit
Protected Reports Review Packet
Added admin-only reports review packet JSON and Markdown exports so reviewers can download report format counts, local-save tool counts, account-save gates, endpoint references, workflow stages, webhook flags, and exclusion categories without exposing report bodies publicly.
- Date: 2026-06-21
- Commit: 20632be
- Deployment: dpl_6Cr29GJKSSwh3N2UrsG1YQ4a9bTD
Verification
- Type check
- Full test suite
- Production build
- Production live smoke
Safety
- The reports review packet release note exposes only public readiness links, the short commit, deployment id, verification classes, and sanitized safety summaries
- Report bodies, raw pasted inputs, account report payloads, account export payloads, private EVE data, token values, token ciphertext, provider credentials, webhook secrets, raw visitor identifiers, browser agent strings, separate-project account details, and secrets remain excluded from public release surfaces
- The actual reports review packet JSON and Markdown downloads stay behind protected admin routes with private no-store headers and unauthenticated 401 responses
- Public Ops, Reports, Monitoring, Status, Health, and Release readiness surfaces show aggregate counts and safe route references only
- Production live smoke verifies the protected packet routes, updated protected-export counts, release feeds, no-secret text boundaries, and expected production commit
Protected Data Rights Review Packet
Added admin-only data-rights review packet JSON and Markdown exports so reviewers can download account-control counts, browser-local surface counts, protected smoke coverage, workflow stages, and exclusion categories without exposing account export payloads publicly.
- Date: 2026-06-21
- Commit: ea65ad8
- Deployment: dpl_8DWAQoao8PGFLrPzMhZs1VU2Pg8F
Verification
- Type check
- Full test suite
- Production build
- Production live smoke
Safety
- The data-rights review packet release note exposes only public readiness links, the short commit, deployment id, verification classes, and sanitized safety summaries
- Account export payloads, token values, token ciphertext, private EVE data, raw pasted inputs, raw visitor identifiers, browser agent strings, payment profile details, raw support messages, manual queue notes, provider secrets, OAuth tokens, authorization headers, database URLs, separate-project account details, and secrets remain excluded from public release surfaces
- The actual data-rights review packet JSON and Markdown downloads stay behind protected admin routes with private no-store headers and unauthenticated 401 responses
- Public Ops, Data Rights, Privacy, Monitoring, Status, Health, and Release readiness surfaces show aggregate counts and safe route references only
- Production live smoke verifies the protected packet routes, updated protected-export counts, release feeds, no-secret text boundaries, and expected production commit
Protected Support Review Packet
Added admin-only support review packet JSON and Markdown exports so reviewers can download queue labels, missing-context triage, reply-draft status, safe-reference availability, and manual response boundaries without exposing protected support request bodies publicly.
- Date: 2026-06-21
- Commit: 658a288
- Deployment: dpl_2FVeGHSkMFeoAnqtr1fUVfmBHuj7
Verification
- Type check
- Full test suite
- Production build
- Production live smoke
Safety
- The support review packet release note exposes only public readiness links, the short commit, deployment id, verification classes, and sanitized safety summaries
- Raw support messages, contact values, email addresses, Discord handles, raw subjects, page URLs, reviewer notes, private EVE data, payment profiles, customer records, provider secrets, email ids, OAuth tokens, authorization headers, database URLs, separate-project account details, and secrets remain excluded from public release surfaces
- The actual support review packet JSON and Markdown downloads stay behind protected admin routes with private no-store headers and unauthenticated 401 responses
- Public Ops, Support, Email, Stripe, Monitoring, Status, Health, and Release readiness surfaces show aggregate counts and safe route references only
- Production live smoke verifies the protected packet routes, updated readiness counts, release feeds, no-secret text boundaries, and expected production commit
Protected Access Review Packet
Added admin-only access request review packet JSON and Markdown exports so reviewers can download request labels, missing-context triage, consent-plan counts, permission audit counts, and manual decision boundaries without exposing protected applicant context publicly.
- Date: 2026-06-21
- Commit: b0435ab
- Deployment: dpl_H7mAnagbf5wpqf5R8eo85wBoarzV
Verification
- Type check
- Full test suite
- Production build
- Production live smoke
Safety
- The access review packet release note exposes only public readiness links, the short commit, deployment id, verification classes, and sanitized safety summaries
- Raw contact values, Discord handles, raw request reasons, evidence URLs, raw reviewer notes, private EVE data, EVE tokens, OAuth client secrets, provider credentials, cookies, authorization headers, database URLs, separate-project account details, automated approvals, access grants, and secrets remain excluded from public release surfaces
- The actual access review packet JSON and Markdown downloads stay behind protected admin routes with private no-store headers and unauthenticated 401 responses
- Public Ops, Intake, Permissions, Monitoring, Status, Health, and Release readiness surfaces show aggregate counts and safe route references only
- Production live smoke verifies the protected packet routes, updated readiness counts, release feeds, no-secret text boundaries, and expected production commit
Protected Recruitment Review Packet
Added admin-only recruitment review packet JSON and Markdown exports so reviewers can download application labels, missing-context triage, recruiter questions, suggested status notes, and manual approval boundaries without exposing protected applicant context publicly.
- Date: 2026-06-21
- Commit: a7cd67d
- Deployment: dpl_EfJzbKwTNW3NquSAHzMpyB8D9psV
Verification
- Type check
- Full test suite
- Production build
- Production live smoke
Safety
- The recruitment review packet release note exposes only public readiness links, the short commit, deployment id, verification classes, and sanitized safety summaries
- Raw contact values, raw goal text, raw availability, raw application notes, raw reviewer notes, Discord identifiers, private EVE data, EVE tokens, OAuth client secrets, provider credentials, cookies, authorization headers, database URLs, separate-project account details, automated approvals, access grants, and secrets remain excluded from public release surfaces
- The actual recruitment review packet JSON and Markdown downloads stay behind protected admin routes with private no-store headers and unauthenticated 401 responses
- Public Ops, Intake, Monitoring, Status, Health, and Release readiness surfaces show aggregate counts and safe route references only
- Production live smoke verifies the protected packet routes, updated readiness counts, release feeds, no-secret text boundaries, and expected production commit
Protected Mining Review Packet
Added admin-only mining ledger review packet JSON and Markdown exports so reviewers can download operation labels, missing-context triage, split policy checks, estimated value labels, and manual pricing/payout boundaries without exposing protected mining ledger rows publicly.
- Date: 2026-06-21
- Commit: 3e75ce0
- Deployment: dpl_4QKF1ToLepQcZzfp2HqJrd1Ae5KN
Verification
- Type check
- Full test suite
- Production build
- Production live smoke
Safety
- The mining review packet release note exposes only public readiness links, the short commit, deployment id, verification classes, and sanitized safety summaries
- Raw ore or loot lines, proof URLs, contact details, raw queue notes, wallet reads, contract reads, asset locations, corporation mining ledgers, member mining history, ISK movement, contract automation, EVE tokens, OAuth client secrets, provider credentials, cookies, authorization headers, database URLs, separate-project account details, and secrets remain excluded from public release surfaces
- The actual mining review packet JSON and Markdown downloads stay behind protected admin routes with private no-store headers and unauthenticated 401 responses
- Public Ops, Mining, Monitoring, Status, Health, and Release readiness surfaces show aggregate counts and safe route references only
- Production live smoke verifies the protected packet routes, updated readiness counts, release feeds, no-secret text boundaries, and expected production commit
Protected Buyback Review Packet
Added admin-only buyback review packet JSON and Markdown exports so reviewers can download missing-context triage, payout estimate labels, reviewer checklist guidance, and manual contract/hauling/pricing boundaries without exposing protected buyback queue rows publicly.
- Date: 2026-06-21
- Commit: 6561074
- Deployment: dpl_3KKCfWP8yD5jdHJ2Zck1paW4pi4e
Verification
- Type check
- Full test suite
- Production build
- Production live smoke
Safety
- The buyback review packet release note exposes only public readiness links, the short commit, deployment id, verification classes, and sanitized safety summaries
- Raw item rows, proof URLs, contact details, raw queue notes, wallet reads, contract reads, asset locations, corporation buyback ledgers, ISK movement, contract automation, EVE tokens, OAuth client secrets, provider credentials, cookies, authorization headers, database URLs, separate-project account details, and secrets remain excluded from public release surfaces
- The actual buyback review packet JSON and Markdown downloads stay behind protected admin routes with private no-store headers and unauthenticated 401 responses
- Public Ops, Buyback, Monitoring, Status, Health, and Release readiness surfaces show aggregate counts and safe route references only
- Production live smoke verifies the protected packet routes, updated readiness counts, release feeds, no-secret text boundaries, and expected production commit
Protected Fleet Review Packet
Added admin-only fleet/timer review packet JSON and Markdown exports so reviewers can download timing labels, missing-context triage, reviewer checklist guidance, and public/private fleet row boundaries without exposing protected fleet context publicly.
- Date: 2026-06-21
- Commit: 77cbf98
- Deployment: dpl_BkXBeVe8PAJowyHkV8mFQzRGSaJT
Verification
- Type check
- Full test suite
- Production build
- Production live smoke
Safety
- The fleet review packet release note exposes only public readiness links, the short commit, deployment id, verification classes, and sanitized safety summaries
- Fleet membership, participation ledgers, invite tokens, pilot location reads, online state reads, ship type reads, fleet write actions, EVE tokens, OAuth client secrets, provider credentials, cookies, authorization headers, database URLs, separate-project account details, and secrets remain excluded from public release surfaces
- The actual fleet review packet JSON and Markdown downloads stay behind protected admin routes with private no-store headers and unauthenticated 401 responses
- Public Ops, Fleet, Monitoring, Status, Health, and Release readiness surfaces show aggregate counts and safe route references only
- Production live smoke verifies the protected packet routes, updated readiness counts, release feeds, no-secret text boundaries, and expected production commit
Protected SRP Review Packet
Added admin-only SRP review packet JSON and Markdown exports so reviewers can download doctrine checks, evidence checklists, decision drafts, reserve labels, and manual payout boundaries without exposing protected queue bodies publicly.
- Date: 2026-06-21
- Commit: 7d7afc2
- Deployment: dpl_HmMnFN1sxENknEh4bRhRgZsiHHh9
Verification
- Type check
- Full test suite
- Production build
- Production live smoke
Safety
- The SRP review packet release note exposes only public readiness links, the short commit, deployment id, verification classes, and sanitized safety summaries
- Pilot names, killmail URLs, raw SRP notes, protected review bodies, wallet reads, contract reads, payout actions, EVE tokens, OAuth client secrets, provider credentials, cookies, authorization headers, database URLs, separate-project account details, and secrets remain excluded from public release surfaces
- The actual SRP review packet JSON and Markdown downloads stay behind protected admin routes with private no-store headers and unauthenticated 401 responses
- Public Ops, SRP, Monitoring, Status, Health, and Release readiness surfaces show aggregate counts and safe route references only
- Production live smoke verifies the protected packet routes, updated readiness counts, release feeds, no-secret text boundaries, and expected production commit
Loss Reviewer SRP Readiness Lane
Enhanced the public Loss Reviewer with SRP readiness triage for proof, fleet context, doctrine, value estimate, review risks, and protected SRP queue handoff while keeping reimbursements human-approved.
- Date: 2026-06-21
- Commit: 314874b
- Deployment: dpl_3fRcsVPESG3MR5SzyT48M7EeKMh7
Verification
- Type check
- Full test suite
- Production build
- Production live smoke
Safety
- The Loss Reviewer SRP lane exposes only advisory readiness labels, evidence-group names, gap summaries, public tool output, and no-secret workflow handoffs
- Private EVE data, wallets, contracts, corporation assets, private fleet membership, EVE tokens, OAuth client secrets, refresh tokens, access tokens, account data, provider credentials, separate-project account details, cookies, authorization headers, database URLs, and secrets remain excluded
- SRP readiness is inferred from pasted proof, fleet context, doctrine, value, and review-risk keywords only; raw loss text is not published by release notes, health feeds, or readiness manifests
- The analyzer does not approve payouts, move ISK, create contracts, read private EVE endpoints, mutate provider state, start EVE OAuth, or request private scopes
- Production live smoke verifies /tools/loss-reviewer, the protected SRP intake route boundaries, updated release feeds, no-secret text boundaries, and expected production commit
Public Mining Ops Analyzer
Added a public Mining Ops analyzer that reviews pasted mining operation notes for material lines, payout readiness, split policy, proof gaps, role coverage, and manual review actions without requiring EVE SSO or private character data.
- Date: 2026-06-21
- Commit: 056209d
- Deployment: dpl_2GT8S8iNtZTSwUJ1rMxBSQAidXuY
Verification
- Type check
- Full test suite
- Production build
- Production live smoke
Safety
- The Mining Ops analyzer exposes only public no-login tool labels, aggregate readiness counts, sample presets, manual review next steps, public workflow links, and no-secret readiness flags
- Raw pasted mining notes, private EVE data, EVE tokens, OAuth client secrets, refresh tokens, access tokens, account exports, wallet data, contract data, mining ledger rows, provider credentials, separate-project account details, cookies, authorization headers, database URLs, and secrets remain excluded
- Reports, account export schemas, local export manifests, tool readiness, roadmap, public sitemap, SEO readiness, route-smoke, monitoring readiness, status, health, and live-smoke floors now include /tools/mining-ops
- The analyzer does not automate payouts, move ISK, create contracts, send fleet invites, read private character or corporation mining data, mutate provider state, start EVE OAuth, or request private scopes
- Production live smoke verifies /tools/mining-ops, updated readiness feeds, the corrected production smoke floors, no-secret text boundaries, and expected production commit
Public Legal Readiness Page
Added a public Legal Readiness page and no-secret legal-readiness JSON feed that translate policy pages, trust evidence, attribution, security reporting, revenue disclosures, no-unlock statements, private-data exclusions, and safety boundaries into a human-reviewable public surface.
- Date: 2026-06-21
- Commit: 591a26d
- Deployment: dpl_8RU4TPcw4tMkZKk6jAFTv1vJTyRr
Verification
- Type check
- Full test suite
- Production build
- Production live smoke
Safety
- The Legal Readiness page exposes only aggregate legal-page counts, manifest counts, trust-section counts, attribution counts, security-reporting counts, revenue-disclosure counts, private-data exclusion counts, public links, and no-secret readiness flags
- OAuth tokens, provider credentials, API keys, database URLs, raw pasted inputs, raw support messages, raw vulnerability reports, account exports, raw logs, raw IP addresses, private EVE data, payment profile details, separate-project account details, cookies, authorization headers, and secrets remain excluded
- Status, Health, route-smoke, public monitoring readiness, public sitemap, public SEO readiness, public discovery, and live-smoke floors now include /legal-readiness and /api/legal/readiness
- The page does not read protected setup packets, reveal provider-account evidence, mutate provider state, start EVE OAuth, request private scopes, call private EVE endpoints, expose vulnerability reports, or publish account identifiers
- Production live smoke verifies /legal-readiness, the public Legal Readiness JSON feed, updated SEO route counts, updated monitoring route counts, no-secret text boundaries, and expected production commit
Public Release Readiness Page
Added a public Release Readiness page and no-secret release-readiness JSON feed that translate release counts, page-card counts, verification coverage, deployment-id formatting, public links, and safety summaries into a human-reviewable public surface.
- Date: 2026-06-21
- Commit: 8823634
- Deployment: dpl_C1b2kGMunMN5r5WshnrgvD6zcPcj
Verification
- Type check
- Full test suite
- Production build
- Production live smoke
Safety
- The Release Readiness page exposes only aggregate release counts, public link counts, verification counts, short-commit counts, deployment-id counts, manifest link counts, safety summary counts, and no-secret readiness flags
- Credentials, tokens, private EVE data, raw logs, raw IP addresses, raw pasted analyzer inputs, manual queue submissions, account exports, account data, provider credentials, separate-project account names, authorization headers, database URLs, and secrets remain excluded
- Status, Health, monitoring readiness, route-smoke, public sitemap, public discovery, and live-smoke floors now include /release-readiness and /api/releases/readiness while protected release-readiness exports stay admin-only
- The page does not read protected exports, reveal private release evidence, mutate provider state, start EVE OAuth, request private scopes, call private EVE endpoints, expose admin queue bodies, or reveal private account identifiers
- Production live smoke verifies /release-readiness, the public Release Readiness JSON feed, updated SEO route counts, updated monitoring route counts, no-secret text boundaries, and expected production commit
Public SEO Readiness Page
Added a public SEO Readiness page that translates sitemap coverage, robots exclusions, web-app manifest state, guide and tool metadata, search-verification gates, discovery links, and no-secret crawler boundaries into a human-reviewable public surface.
- Date: 2026-06-21
- Commit: 830b148
- Deployment: dpl_AUSzkBN8rukm8gL62qgEQuBrSDMH
Verification
- Type check
- Full test suite
- Production build
- Production live smoke
Safety
- The SEO Readiness page exposes only aggregate sitemap counts, robots counts, manifest counts, metadata counts, search-verification gate counts, public discovery link counts, and no-secret readiness flags
- Verification token values, analytics IDs, provider account details, cookies, admin exports, private EVE data, raw logs, raw pasted analyzer inputs, EVE tokens, OAuth client secrets, refresh tokens, access tokens, account data, provider credentials, separate-project account names, authorization headers, database URLs, and secrets remain excluded
- Status, Health, monitoring readiness, route-smoke, public sitemap, public discovery, and live-smoke floors now include /seo-readiness while verification-token values and provider-side search evidence stay protected
- The page does not submit sitemaps, enable analytics, mutate provider state, start EVE OAuth, request private scopes, call private EVE endpoints, read protected queues, expose admin exports, or reveal private account identifiers
- Production live smoke verifies /seo-readiness, the SEO JSON feed, sitemap, robots, manifest, updated route-smoke counts, no-secret text boundaries, and expected production commit
Public Capability Readiness Page
Added a public Capability Readiness page that translates live public tools, browser-local workflows, protected review queues, EVE SSO consent gates, provider gates, route coverage, and no-secret capability boundaries into a human-reviewable public surface.
- Date: 2026-06-21
- Commit: 6b74801
- Deployment: dpl_GTVPhFRtYdm8MpMCqfzwKbxNDYfP
Verification
- Type check
- Full test suite
- Production build
- Production live smoke
Safety
- The Capability Readiness page exposes only aggregate capability counts, public-route counts, consent-preview counts, provider-gate counts, section counts, public links, and no-secret readiness flags
- Private EVE data, EVE tokens, OAuth client secrets, refresh tokens, access tokens, account data, raw submissions, protected review bodies, hidden setup packets, provider credentials, separate-project account names, cookies, authorization headers, database URLs, and secrets remain excluded
- Status, Health, SEO readiness, monitoring readiness, route-smoke, public sitemap, public discovery, and live-smoke floors now include /capability-readiness while protected review state and setup packets stay behind guarded flows
- The page does not submit intake, read protected queues, start EVE OAuth, request private scopes, call private EVE endpoints, mutate provider state, expose protected review bodies, or reveal private account identifiers
- Production live smoke verifies /capability-readiness, the Capability JSON feed, updated SEO route counts, updated monitoring route counts, no-secret text boundaries, and expected production commit
Public Tool Readiness Page
Added a public Tool Readiness page that translates analyzer coverage, public EVE data tools, browser-local workflows, manual review queues, no-secret boundaries, and linked tool-readiness JSON feeds into a human-reviewable public surface.
- Date: 2026-06-21
- Commit: 085fef0
- Deployment: dpl_HyEoDW3cWuAyeYEZ6PAvB7omzvJ2
Verification
- Type check
- Full test suite
- Production build
- Production live smoke
Safety
- The Tool Readiness page exposes only aggregate analyzer counts, directory group counts, public-data tool counts, browser-local tool counts, manual-review workflow counts, public links, and no-secret readiness flags
- Private EVE data, raw pasted analyzer inputs, manual queue bodies, EVE tokens, OAuth client secrets, refresh tokens, access tokens, account data, provider credentials, separate-project account names, cookies, authorization headers, database URLs, and secrets remain excluded
- Status, Health, SEO readiness, monitoring readiness, route-smoke, public sitemap, public discovery, and live-smoke floors now include /tool-readiness while protected analyzer inputs and admin review state stay behind guarded flows
- The page does not submit analyzer jobs, store pasted payloads, call private EVE endpoints, read protected queues, start OAuth, mutate provider state, expose protected review bodies, or reveal private account identifiers
- Production live smoke verifies /tool-readiness, the Tool Directory JSON feed, the Local Tool Readiness JSON feed, updated SEO route counts, updated monitoring route counts, no-secret text boundaries, and expected production commit
Public Permissions Readiness Page
Added a public Permissions Readiness page that translates EVE SSO scope groups, feature consent previews, high-trust and write/action boundaries, no-OAuth safety, and no-secret permission catalog coverage into a human-reviewable public surface.
- Date: 2026-06-21
- Commit: f468685
- Deployment: dpl_FZvdSRQF8ABgBTn2mw5SLkJKvDMK
Verification
- Type check
- Full test suite
- Production build
- Production live smoke
Safety
- The Permissions Readiness page exposes only aggregate scope-group counts, known-scope counts, preview counts, feature consent plan counts, high-trust scope counts, write/action scope counts, public links, and no-secret readiness flags
- Private EVE data, EVE tokens, OAuth client secrets, refresh tokens, access tokens, account data, raw submissions, raw logs, provider credentials, separate-project account names, cookies, authorization headers, database URLs, and secrets remain excluded
- Status, Health, SEO readiness, monitoring readiness, route-smoke, public sitemap, permission catalog, and live-smoke floors now include /permissions-readiness while OAuth starts and private account state stay behind feature-specific consent and protected flows
- The page does not start EVE OAuth, exchange authorization codes, read private EVE endpoints, expose token state, request new permissions, mutate provider state, or reveal private account identifiers
- Production live smoke verifies /permissions-readiness, the Permission Readiness JSON feed, the Scope Catalog JSON feed, updated SEO route counts, updated monitoring route counts, no-secret text boundaries, and expected production commit
Public Revenue Readiness Page
Added a public Revenue Readiness page that translates voluntary support, Stripe, AdSense, email, provider gates, protected dry runs, and no paid gameplay unlock boundaries into a human-reviewable public surface.
- Date: 2026-06-21
- Commit: dc7ad7a
- Deployment: dpl_2J2enQ6JR5Rz79Ea2uhuuEyifCtH
Verification
- Type check
- Full test suite
- Production build
- Production live smoke
Safety
- The Revenue Readiness page exposes only aggregate provider counts, review counts, setup-packet counts, dry-run counts, missing public config counts, public links, and no-secret readiness flags
- Public env names, Stripe secrets, webhook signing secrets, Google account credentials, payment profile details, tax records, customer data, raw support messages, private EVE data, protected setup packet URLs, cookies, authorization headers, database URLs, and secrets remain excluded
- Status, Health, SEO readiness, monitoring readiness, route-smoke, public sitemap, and live-smoke floors now include /revenue-readiness while payment, customer, tax, setup, and provider account details stay behind protected or feature-gated surfaces
- The page does not create payments, enable ads, send email, mutate provider state, unlock gameplay features, grant account access, call private EVE endpoints, or reveal private account identifiers
- Production live smoke verifies /revenue-readiness, the Revenue JSON feed, updated SEO route counts, updated monitoring route counts, protected-route privacy, no-secret text boundaries, and expected production commit
Public Intake Readiness Page
Added a public Intake Readiness page that translates access, recruiting, and support intake posture, guarded submission routes, protected review boundaries, workflow stages, and no-secret queue handling into a human-reviewable public surface.
- Date: 2026-06-21
- Commit: 4a1302f
- Deployment: dpl_nDp9WVDwfhDmzAD2UJyKPPhsu8cV
Verification
- Type check
- Full test suite
- Production build
- Production live smoke
Safety
- The Intake Readiness page exposes only aggregate public route counts, submission route counts, protected review counts, workflow-stage counts, private-data exclusion counts, readiness flags, public links, and no-secret boundaries
- Raw access request rows, raw recruitment applications, raw support messages, applicant names, contact details, vouch notes, admin review notes, audit event metadata, rate-limit hashes, EVE session ids, EVE tokens, provider secrets, private EVE data, notification sends, account decisions, cookies, authorization headers, database URLs, and secrets remain excluded
- Status, Health, SEO readiness, monitoring readiness, route-smoke, public sitemap, and live-smoke floors now include /intake-readiness while protected queue details and admin review actions stay behind protected routes
- The page does not call private EVE endpoints, read queue rows, expose protected review bodies, send email, grant access, approve accounts, mutate provider state, or reveal private account identifiers
- Production live smoke verifies /intake-readiness, the Intake Readiness JSON feed, updated SEO route counts, updated monitoring route counts, protected-route privacy, no-secret text boundaries, and expected production commit
Public Ops Readiness Page
Added a public Ops Readiness page and JSON feed that translate protected operations export coverage, admin-only route boundaries, private-header coverage, queue and snapshot labels, and no-secret monitoring posture into a human-reviewable public surface.
- Date: 2026-06-21
- Commit: 89c4031
- Deployment: dpl_2n5SqBrQQ3G6PioCpkdkejDJ9XgL
Verification
- Type check
- Full test suite
- Production build
- Production live smoke
Safety
- The Ops Readiness page exposes only aggregate protected export counts, expected export target counts, private-header target counts, export kind counts, export group counts, boundary counts, public links, and no-secret readiness flags
- Protected export bodies, protected route URLs, queue rows, setup packet details, provider credentials, auth cookies, EVE tokens, private EVE data, account data, raw submissions, raw logs, provider account details, separate-project account names, cookies, authorization headers, database URLs, and secrets remain excluded
- Status, Health, SEO readiness, monitoring readiness, route-smoke, public sitemap, and live-smoke floors now include /ops-readiness and /api/ops/readiness while /ops and /api/admin/* remain protected and excluded from the sitemap
- The page does not call private EVE endpoints, read protected operations queues, expand admin setup packets, expose private dashboards, expose protected export bodies, mutate provider state, or reveal private account identifiers
- Production live smoke verifies /ops-readiness, the Ops Readiness JSON feed, updated SEO route counts, updated monitoring route counts, protected-route privacy, no-secret text boundaries, and expected production commit
Public Provider Readiness Pages
Added public Sentry and Vercel/GitHub readiness pages that translate provider setup gates, protected checks, production deployment posture, no-provider-call dry runs, and no-secret account boundaries into human-reviewable public surfaces.
- Date: 2026-06-21
- Commit: 4c7ae2e
- Deployment: dpl_BTMLphAgkeXifP6Viws4tg9WvbrM
Verification
- Type check
- Full test suite
- Production build
- Production live smoke
Safety
- The provider readiness pages expose only aggregate protected-check counts, required-gate counts, verified-boundary counts, production-deploy readiness, dry-run status, public links, and no-secret boundaries
- DSN values, provider org or project identifiers, event URLs, stack traces, provider tokens, GitHub or Vercel tokens, OIDC values, installation IDs, private repository data, env var values, database URLs, cron secrets, cookies, authorization headers, EVE tokens, private EVE data, raw pasted analyzer inputs, protected setup details, provider cookies, private logs, provider account details, and separate-project account names remain excluded
- Status, Health, SEO readiness, monitoring readiness, route-smoke, public sitemap, and live-smoke floors now include /sentry-readiness, /vercel-github-readiness, /api/sentry/readiness, and /api/vercel-github/readiness
- The pages do not call provider APIs, create Sentry events, mutate GitHub or Vercel state, start provider auth flows, return provider tokens, expose protected setup packets, expose private dashboards, or reveal private account identifiers
- Production live smoke verifies both provider readiness pages, both provider readiness JSON feeds, updated SEO route counts, updated monitoring link counts, protected-route privacy, forbidden separate-project text exclusion, and expected production commit
Public Next Actions Page
Added a public Next Actions page and JSON feed that combine launch and integration action queues into a no-secret view of blockers, build-while-blocked lanes, provider/account review, and public readiness links.
- Date: 2026-06-21
- Commit: 9670814
- Deployment: dpl_9HMeKBrisf3LA3bRtdkjzmXwcyUf
Verification
- Type check
- Full test suite
- Production build
- Production live smoke
Safety
- The Next Actions page exposes only sanitized launch and integration action labels, statuses, owner categories, public links, next-step summaries, build-while-blocked counts, and no-secret boundaries
- Provider credentials, API keys, passwords, EVE tokens, private EVE data, account data, raw submissions, protected setup packet contents, provider cookies, private logs, authorization headers, analytics IDs, verification token values, and separate-project account details remain excluded
- Sitemap, SEO readiness, route-smoke targets, public health, monitoring readiness, and live-smoke floors now include /next-actions and /api/next-actions/readiness
- The page does not read protected queues, expand admin setup packets, call provider accounts, mutate external services, start OAuth, expose cookies, or reveal private account identifiers
- Production live smoke verifies /next-actions, the Next Actions readiness JSON feed, updated SEO route counts, updated route-smoke counts, protected-route privacy, and expected production commit
Public Growth Readiness Page
Added a public Growth Readiness page that translates analytics gates, search verification, provider-safe dry runs, protected setup review, and no-secret growth boundaries into a human-reviewable public surface.
- Date: 2026-06-21
- Commit: 1697fe2
- Deployment: dpl_J9G7YK5kQtKwWxjonw8HWEduxkGG
Verification
- Type check
- Full test suite
- Production build
- Production live smoke
Safety
- The Growth Readiness page exposes only aggregate readiness item counts, telemetry-gate counts, search-verification counts, component counts, protected-check counts, no-provider-call dry-run status, public links, and no-secret boundaries
- Analytics IDs, verification token values, Google account details, Bing account details, provider cookies, Search Console screenshots, raw pageview data, workflow-click payloads, EVE tokens, private account data, raw pasted analyzer inputs, and separate-project account details remain excluded
- Status, Health, SEO readiness, route-smoke, public sitemap, and live-smoke floors now include /growth-readiness and its no-secret public readiness markers
- The page does not enable analytics, enable Speed Insights, submit search verification, return verification tokens, expose protected setup packets, expose private dashboards, call private EVE endpoints, or mutate provider state
- Production live smoke verifies /growth-readiness, the Growth readiness JSON feed, updated SEO route counts, updated route-smoke counts, protected-route privacy, and expected production commit
Public AI Readiness Page
Added a public AI Readiness page that translates deterministic fallback, protected OpenAI setup review, no-provider-call dry runs, feature gates, and no-secret AI boundaries into a human-reviewable public surface.
- Date: 2026-06-21
- Commit: 258edd4
- Deployment: dpl_9ivGPMxLc6k9Fr8dNtSzQq8k6DLG
Verification
- Type check
- Full test suite
- Production build
- Production live smoke
Safety
- The AI Readiness page exposes only aggregate eligible-tool counts, ready-tool counts, missing-gate counts, protected-check counts, deterministic fallback status, no-provider-call dry-run status, public links, and no-secret boundaries
- OpenAI keys, model environment values, AI billing details, raw prompts, token-spend records, raw pasted analyzer inputs, EVE tokens, private account data, provider secrets, and separate-project account details remain excluded
- Status, Health, SEO readiness, route-smoke, public sitemap, and live-smoke floors now include /ai-readiness and its no-secret public readiness markers
- The page does not call OpenAI, submit prompts, spend tokens, expose protected setup packets, expose private dashboards, read private EVE data, or enable AI provider usage without explicit feature gates and approved provider setup
- Production live smoke verifies /ai-readiness, the AI readiness JSON feed, updated SEO route counts, updated route-smoke counts, protected-route privacy, and expected production commit
Public Backup Readiness Page
Added a public Backup Readiness page that translates production recovery posture, protected setup review, safe exports, proof targets, restore-drill gates, and no-provider-mutation boundaries into a human-reviewable public surface.
- Date: 2026-06-21
- Commit: d24004c
- Deployment: dpl_FJ4BbCfLMJwUFP6DQDnW4JE1o9xe
Verification
- Type check
- Full test suite
- Production build
- Production live smoke
Safety
- The Backup Readiness page exposes only aggregate recovery counts, migration count, protected-check counts, proof-target counts, safe-export counts, restore-drill status, no-provider-mutation dry-run status, public links, and no-secret boundaries
- Database connection values, cron secret values, migration tags, Neon passwords, SQL dumps, Vercel rollback targets, provider-console backup artifacts, token ciphertext, raw IP addresses, raw user-agent strings, EVE tokens, private account data, raw pasted analyzer inputs, and separate-project account details remain excluded
- Status, Health, SEO readiness, route-smoke, public sitemap, and live-smoke floors now include /backup-readiness and its no-secret public readiness markers
- The page does not call private EVE endpoints, read database backups, expose restore artifacts, expose protected setup packets, expose private dashboards, mutate provider state, or claim a verified restore drill before owner review
- Production live smoke verifies /backup-readiness, the Backup readiness JSON feed, updated SEO route counts, updated route-smoke counts, protected-route privacy, and expected production commit
Public Support Readiness Page
Added a public Support Readiness page that translates support intake, voluntary support, protected review, provider gates, and no-live provider boundaries into a human-reviewable public surface.
- Date: 2026-06-21
- Commit: eb36118
- Deployment: dpl_HjuqYmhzv7oeQirLLvm4fdNsFy2A
Verification
- Type check
- Full test suite
- Production build
- Production live smoke
Safety
- The Support Readiness page exposes only aggregate support surface counts, public route counts, support request route counts, protected review route counts, workflow-stage counts, provider-gate counts, readiness booleans, public links, and no-secret boundaries
- Raw support messages, contact details, email addresses, Discord handles, in-game names, private page URLs, admin review notes, support queue statuses, rate-limit hashes, browser identifiers, EVE session ids, EVE tokens, Stripe customer records, payment profile details, provider secrets, email message ids, paid unlocks, account decisions, and separate-project account details remain excluded
- Status, Health, SEO readiness, route-smoke, public sitemap, and live-smoke floors now include /support-readiness and its no-secret public readiness markers
- The page does not call private EVE endpoints, read support queue rows, expose payment profile details, create Stripe payment links, send provider email, expose protected setup packets, expose private dashboards, or unlock gameplay or account access
- Production live smoke verifies /support-readiness, the Support readiness JSON feed, updated SEO route counts, updated route-smoke counts, protected-route privacy, and expected production commit
Public Reports Readiness Page
Added a public Reports Readiness page that translates browser-local report saves, public export manifests, private account report gates, and disabled webhook delivery into a human-reviewable public surface.
- Date: 2026-06-21
- Commit: 3feee5a
- Deployment: dpl_BDx3Tbk25Vv2b83MQP9mQsGA7hQk
Verification
- Type check
- Full test suite
- Production build
- Production live smoke
Safety
- The Reports Readiness page exposes only aggregate format counts, tool counts, local-save counts, account-save counts, public-export counts, endpoint counts, workflow-stage counts, webhook safety flags, readiness booleans, public links, and no-secret boundaries
- Report bodies, raw pasted analyzer inputs, account reports, account exports, EVE OAuth token values, token ciphertext, provider credentials, private EVE data, raw visitor identifiers, raw browser agent strings, webhook signing secrets, and separate-project account details remain excluded
- Status, Health, SEO readiness, route-smoke, public sitemap, and live-smoke floors now include /reports-readiness and its no-secret public readiness markers
- The page does not call private EVE endpoints, read account report bodies, expose local report payloads, export account data, deliver webhooks, expose protected setup packets, or expose private dashboards
- Production live smoke verifies /reports-readiness, the Reports readiness JSON feed, updated SEO route counts, updated route-smoke counts, protected-route privacy, and expected production commit
Public PI Readiness Page
Added a public PI Readiness page that translates template planning, public market estimates, future colony consent, manual colony setup, and no-secret colony automation boundaries into a human-reviewable public surface.
- Date: 2026-06-21
- Commit: 64f2bc7
- Deployment: dpl_8mQWTzJadTSjjgRnowk858oaEaEY
Verification
- Type check
- Full test suite
- Production build
- Production live smoke
Safety
- The PI Readiness page exposes only aggregate template counts, public route counts, public API route counts, protected setup route counts, workflow-stage counts, consent-preview links, readiness booleans, public links, and no-secret boundaries
- Private colony layouts, planet pin positions, extractor routes, storage levels, customs office ownership notes, private assets, wallet journals, industry job history, EVE tokens, provider secrets, private EVE data, colony read automation, colony write automation, and separate-project account details remain excluded
- Status, Health, SEO readiness, route-smoke, public sitemap, and live-smoke floors now include /pi-readiness and its no-secret public readiness markers
- The page does not call private EVE endpoints, read private colonies, read assets, read wallets, read industry jobs, expose protected setup packets, expose private dashboards, automate colony reads, automate colony writes, or click or modify the EVE client
- Production live smoke verifies /pi-readiness, the PI readiness JSON feed, updated SEO route counts, updated route-smoke counts, protected-route privacy, and expected production commit
Public Mining Readiness Page
Added a public Mining Readiness page that translates manual mining ledger intake, protected review, manual pricing and payout decisions, future mining/corporation consent, and no-secret payout/contract boundary coverage into a human-reviewable public surface.
- Date: 2026-06-21
- Commit: 3801f49
- Deployment: dpl_EVcVsB77zQiekWgW9jNRBrSTYFyR
Verification
- Type check
- Full test suite
- Production build
- Production live smoke
Safety
- The Mining Readiness page exposes only aggregate public route counts, intake route counts, protected review route counts, workflow-stage counts, consent-preview links, readiness booleans, public links, and no-secret boundaries
- Raw ore or loot lines, proof URLs, payout character notes, wallet journals, contract records, asset locations, corporation mining ledgers, member mining history, EVE tokens, provider secrets, private EVE data, ISK movement, contract automation, and separate-project account details remain excluded
- Status, Health, SEO readiness, route-smoke, public sitemap, and live-smoke floors now include /mining-readiness and its no-secret public readiness markers
- The page does not call private EVE endpoints, read mining history, read wallets, read assets, read contracts, expose protected setup packets, expose private dashboards, move ISK, or automate contracts
- Production live smoke verifies /mining-readiness, the Mining readiness JSON feed, updated SEO route counts, updated route-smoke counts, protected-route privacy, and expected production commit
Public SRP Readiness Page
Added a public SRP Readiness page that translates manual loss intake, protected review, reserve planning, future proof consent, manual payout decisions, and no-secret payout-boundary coverage into a human-reviewable public surface.
- Date: 2026-06-21
- Commit: 048e3dd
- Deployment: dpl_2WVF4Qd38RPkjs82J5yWdj6qnffz
Verification
- Type check
- Full test suite
- Production build
- Production live smoke
Safety
- The SRP Readiness page exposes only aggregate public route counts, protected review route counts, workflow-stage counts, consent-preview links, readiness booleans, public links, and no-secret boundaries
- Pilot names, killmail URLs, raw SRP queue notes, wallet balances, contract data, EVE tokens, provider secrets, private EVE data, payout actions, and separate-project account details remain excluded
- Status, Health, SEO readiness, route-smoke, public sitemap, and live-smoke floors now include /srp-readiness and its no-secret public readiness markers
- The page does not call private EVE endpoints, read wallets, read contracts, expose queue rows, automate payouts, expose protected setup packets, or expose private dashboards
- Production live smoke verifies /srp-readiness, the SRP readiness JSON feed, updated SEO route counts, updated route-smoke counts, protected-route privacy, and expected production commit
Public Fleet Readiness Page
Added a public Fleet Readiness page that translates fleet board, protected publishing, SRP context, future fleet context/write consent, human-led decisions, and no-secret fleet-action boundary coverage into a human-reviewable public surface.
- Date: 2026-06-21
- Commit: 06be5a8
- Deployment: dpl_DwJnBK6vHRGuoXcr3BLCWcUAUPyi
Verification
- Type check
- Full test suite
- Production build
- Production live smoke
Safety
- The Fleet Readiness page exposes only aggregate public route counts, protected publish route counts, workflow-stage counts, consent-preview links, readiness booleans, public links, and no-secret boundaries
- Private fleet membership, fleet participation ledgers, FAT links, pilot location, online state, ship type, private killmails, fleet invitation tokens, EVE tokens, provider secrets, private EVE data, fleet write actions, and separate-project account details remain excluded
- Status, Health, SEO readiness, route-smoke, public sitemap, and live-smoke floors now include /fleet-readiness and its no-secret public readiness markers
- The page does not call private EVE endpoints, read fleet membership, read online state, read location, issue fleet invitations, kick fleet members, modify fleet ads, expose protected setup packets, or expose private dashboards
- Production live smoke verifies /fleet-readiness, the Fleet readiness JSON feed, updated SEO route counts, updated route-smoke counts, protected-route privacy, and expected production commit
Public Buyback Readiness Page
Added a public Buyback Readiness page that translates buyback calculator, manual request intake, quote API, protected review, future market/corporation consent, and no-secret payout-boundary coverage into a human-reviewable public surface.
- Date: 2026-06-21
- Commit: b52a1d4
- Deployment: dpl_798bwJhyoSu7oCbu8QLEFJR64aTG
Verification
- Type check
- Full test suite
- Production build
- Production live smoke
Safety
- The Buyback Readiness page exposes only aggregate public route counts, public intake route counts, public quote route counts, protected review route counts, workflow-stage counts, consent-preview links, readiness booleans, public links, and no-secret boundaries
- Raw item rows, proof URLs, character contacts, requested locations, contract notes, raw queue notes, wallet journals, contract records, asset locations, corporation buyback ledgers, EVE tokens, provider secrets, private EVE data, and separate-project account details remain excluded
- Status, Health, SEO readiness, route-smoke, public sitemap, and live-smoke floors now include /buyback-readiness and its no-secret public readiness markers
- The page does not move ISK, automate contracts, call private EVE endpoints, read wallets, read assets, read contracts, expose protected setup packets, or expose private dashboards
- Production live smoke verifies /buyback-readiness, the Buyback readiness JSON feed, updated SEO route counts, updated route-smoke counts, protected-route privacy, and expected production commit
Public Market Readiness Page
Added a public Market Readiness page that translates market command, appraisal, buyback quote, browser-local watchlist, future market-data consent, manual trade, and no-secret financial boundary coverage into a human-reviewable public surface.
- Date: 2026-06-21
- Commit: f524a83
- Deployment: dpl_4V2tCgoGqLBAjyUwnkq4VHHxTLfa
Verification
- Type check
- Full test suite
- Production build
- Production live smoke
Safety
- The Market Readiness page exposes only aggregate public route counts, public API route counts, workflow-stage counts, consent-preview links, readiness booleans, public links, and no-secret boundaries
- Private market orders, wallet journals, asset locations, contract records, market order ownership, industry jobs, character contact details, raw saved watchlist entries, EVE tokens, provider secrets, automated trade actions, and separate-project account details remain excluded
- Status, Health, SEO readiness, route-smoke, public sitemap, and live-smoke floors now include /market-readiness and its no-secret public readiness markers
- The page does not call private EVE endpoints, read wallets, read assets, read contracts, read industry jobs, update orders, create contracts, move ISK, expose protected setup packets, or expose private dashboards
- Production live smoke verifies /market-readiness, the Market readiness JSON feed, updated SEO route counts, updated route-smoke counts, protected-route privacy, and expected production commit
Public Discord Readiness Page
Added a public Discord Readiness page that translates command, interaction, protected setup, endpoint validation, no-provider-call dry-run, and no-secret Discord-boundary coverage into a human-reviewable public surface.
- Date: 2026-06-21
- Commit: 5181a28
- Deployment: dpl_3Bu7s42Dybx7qkwMiWzaEKD2TXeD
Verification
- Type check
- Full test suite
- Production build
- Production live smoke
Safety
- The Discord Readiness page exposes only aggregate command counts, public endpoint counts, protected-check counts, command category labels, readiness booleans, public links, and no-secret boundaries
- Bot tokens, app client identifiers, guild identifiers, public keys, install URLs, Discord API URLs, provider cookies, authorization headers, EVE tokens, private account data, raw pasted analyzer inputs, and separate-project account details remain excluded
- Status, Health, SEO readiness, route-smoke, public sitemap, and live-smoke floors now include /discord-readiness and its no-secret public readiness markers
- The page does not call Discord, register commands, mutate provider settings, expose protected setup packets, expose private dashboards, or enable bot actions
- Production live smoke verifies /discord-readiness, the Discord readiness JSON feed, Discord command and interaction public APIs, updated SEO route counts, updated route-smoke counts, protected-route privacy, and expected production commit
Public AdSense Readiness Page
Added a public AdSense Readiness page that translates Google advertising gates into human-reviewable no-Google-call dry-run, protected-check, review-checklist, feature-flag, ads.txt, ad-slot, and no-secret advertising-boundary coverage.
- Date: 2026-06-21
- Commit: 409ec39
- Deployment: dpl_Fa8isSS96Ueei9rS7MSuBffYfFuM
Verification
- Type check
- Full test suite
- Production build
- Production live smoke
Safety
- The AdSense Readiness page exposes only aggregate advertising status, route counts, protected-check counts, review-checklist counts, feature-gate booleans, public links, and no-secret boundaries
- ca-pub values, ad slot IDs, Google account credentials, verification prompts, phone numbers, payment profile details, tax records, provider cookies, public environment variable names, and separate-project account details remain excluded
- Status, Health, SEO readiness, route-smoke, public sitemap, and live-smoke floors now include /adsense-readiness and its no-secret public readiness markers
- The page does not call Google, load ad scripts, serve ads, mutate provider settings, expose protected setup packets, expose private dashboards, or share private EVE data with advertising surfaces
- Production live smoke verifies /adsense-readiness, the AdSense readiness JSON feed, updated SEO route counts, updated route-smoke counts, protected-route privacy, and expected production commit
Public Stripe Readiness Page
Added a public Stripe Readiness page that translates voluntary support-link and payment-provider gates into human-reviewable no-live-Stripe dry-run, protected-check, checklist-count, feature-flag, and no-secret payment-boundary coverage.
- Date: 2026-06-21
- Commit: c40fd8d
- Deployment: dpl_5cpGtjJQWXAVKNbJKD6tx8GAj4Hg
Verification
- Type check
- Full test suite
- Production build
- Production live smoke
Safety
- The Stripe Readiness page exposes only aggregate support-link status, route counts, protected-check counts, dashboard checklist counts, app checklist counts, public links, and no-secret boundaries
- Payment links, public environment variable names, Stripe secret keys, webhook secrets, checkout IDs, customer records, payment profile details, bank details, shared legal-entity fields, cookies, authorization headers, and separate-project account details remain excluded
- Status, Health, SEO readiness, support readiness, route-smoke, public sitemap, and live-smoke floors now include /stripe-readiness and its no-secret public readiness markers
- The page does not create payment links, start checkout, call Stripe, mutate provider settings, expose protected setup packets, expose support queue bodies, or enable paid feature unlocks
- Production live smoke verifies /stripe-readiness, the Stripe readiness JSON feed, updated SEO route counts, updated route-smoke counts, protected-route privacy, and expected production commit
Public Email Readiness Page
Added a public Email Readiness page that translates transactional email provider gates into human-reviewable no-send dry-run, email-type, protected-check, provider-label, and no-secret sender-boundary coverage.
- Date: 2026-06-21
- Commit: 33ebee3
- Deployment: dpl_AFdJym8fujUJ9fGgmPcTUbYp55g1
Verification
- Type check
- Full test suite
- Production build
- Production live smoke
Safety
- The Email Readiness page exposes only aggregate transactional email status, safe counts, email type labels, provider labels, public links, and no-secret boundaries
- Provider keys, SMTP credentials, webhook secrets, sender addresses, reply-to addresses, recipient addresses, message identifiers, raw support messages, account records, cookies, authorization headers, and separate-project account details remain excluded
- Status, Health, SEO readiness, route-smoke, public sitemap, and live-smoke floors now include /email-readiness and its no-secret public readiness markers
- The page does not send email, call Resend or SMTP, mutate provider settings, expose protected setup packets, expose support queue bodies, or enable transactional sending
- Production live smoke verifies /email-readiness, the email readiness JSON feed, updated SEO route counts, updated route-smoke counts, protected-route privacy, and expected production commit
Public EVE SSO Readiness Page
Added a public EVE SSO Readiness page that translates the no-secret EVE sign-in gate into human-reviewable callback, publicData first-login, consent-preview, permission-group, and feature-consent coverage.
- Date: 2026-06-21
- Commit: e7c4ede
- Deployment: dpl_3RLAvVo7bAxQ97hEXKVT8W5sSrHZ
Verification
- Type check
- Full test suite
- Production build
- Production live smoke
Safety
- The EVE SSO Readiness page exposes only public gate status, safe counts, expected callback URL, preview links, permission-group coverage counts, and no-secret boundaries
- EVE client IDs, client secrets, access tokens, refresh tokens, account records, private EVE data, cookies, authorization headers, provider console state, raw logs, and separate-project account details remain excluded
- Status, Health, SEO readiness, route-smoke, public sitemap, and live-smoke floors now include /eve-sso-readiness and its no-secret public readiness markers
- The page does not start OAuth, exchange tokens, mutate EVE provider settings, enable public sign-in, request private scopes, or expose protected EVE setup packets
- Production live smoke verifies /eve-sso-readiness, the EVE readiness JSON feed, updated SEO route counts, updated route-smoke counts, protected-route privacy, and expected production commit
Public Domain Contact Readiness Page
Added a public Domain Contact Readiness page for warpintel.app HTTPS, support mailbox, security policy, contact routes, policy routes, provider-boundary disclosures, and no-secret launch checks.
- Date: 2026-06-21
- Commit: c02d073
- Deployment: dpl_8agTywcdgTNGeJTwKB3Kjpqdy8Lz
Verification
- Type check
- Full test suite
- Production build
- Production live smoke
Safety
- The Domain Readiness page exposes only the production domain, public support contact, route counts, policy/contact route lists, provider-boundary counts, and safety booleans
- Registrar account details, DNS zone records, TLS private keys, mailbox credentials, provider account ids, provider tokens, EVE tokens, private EVE data, raw logs, and separate-project account details remain excluded
- Status, Health, SEO readiness, route-smoke, public sitemap, and live-smoke floors now include /domain-readiness and its no-secret public readiness markers
- External account mutation stays disabled; the page does not change registrar, DNS, TLS, mailbox, payment, ad, Discord, email, database, Vercel, GitHub, or EVE provider settings
- Production live smoke verifies /domain-readiness, the domain readiness JSON feed, updated SEO route counts, updated route-smoke counts, protected-route privacy, and expected production commit
Public Navigation Safety Readiness Page
Added a public Navigation Safety Readiness page that translates the navigation readiness manifest into human-reviewable coverage for systems, route planning, map, sovereignty, structures, wormholes, private-intel consent boundaries, and disabled action automation.
- Date: 2026-06-21
- Commit: 37d0cb0
- Deployment: dpl_D5eYbV3n4sUghQgK4avZj1kY9KfM
Verification
- Type check
- Full test suite
- Production build
- Production live smoke
Safety
- The Navigation page is generated from the existing public navigation readiness manifest and exposes only route labels, aggregate counts, workflow stages, future consent needs, public links, and no-secret boundaries
- Private pilot location, online state, ship type, bookmarks, private fleet membership, private killmails, EVE OAuth tokens, provider secrets, raw logs, and account data remain excluded from public pages, JSON feeds, screenshots, and smoke output
- Future private navigation intel remains behind feature-specific consent previews while fleet actions, client actions, and provider writes stay disabled
- Status, Health, SEO readiness, route-smoke, and live-smoke floors now include /navigation and its no-secret public readiness markers
- The page keeps WarpIntel account and service boundaries separate from unrelated project accounts and does not expose external-service setup details
Public Monitoring Readiness Surface
Added a public Monitoring page and no-secret monitoring-readiness JSON feed that composes health, route smoke, protected Ops export coverage, release readiness, growth telemetry, Sentry, and Vercel/GitHub deploy-link signals into one production-safe monitoring surface.
- Date: 2026-06-21
- Commit: 0279b2a
- Deployment: dpl_AfksPCXupxCJQwkycMnkbNsWk247
Verification
- Type check
- Full test suite
- Production build
- Production live smoke
Safety
- Public monitoring readiness exposes only aggregate route-smoke counts, protected Ops export counts, release counts, readiness booleans, provider gate states, and public links
- The Monitoring page and JSON feed do not expose provider tokens, provider account names, provider cookies, private repository data, raw logs, raw visitor identifiers, EVE tokens, private EVE data, private account data, protected export bodies, protected setup details, or raw pasted analyzer inputs
- Sentry capture, growth telemetry, provider actions, Discord, email, payments, ads, AI, fleet actions, and other external services remain feature-gated until their matching readiness lane is approved
- Sitemap, SEO readiness, route-smoke targets, public health, status-readiness, and live-smoke floors were updated so production checks cover both /monitoring and /api/monitoring/readiness
- Production live smoke verifies the Monitoring page, monitoring readiness JSON feed, health monitoring counters, route/feed target counts, protected-route privacy, and expected production commit
Vercel GitHub Launch Readiness Alignment
Aligned the public launch-readiness and status-readiness lanes with the already-confirmed Vercel/GitHub production link so the deploy boundary no longer stays in the gated action queue when non-secret production metadata confirms the expected repo-linked deployment path.
- Date: 2026-06-21
- Commit: 9d8ca34
- Deployment: dpl_EWyern5dmeZc9QFegdVtckGdnvRr
Verification
- Type check
- Full test suite
- Production build
- Production live smoke
Safety
- The launch-readiness lane derives readiness only from the count-level Vercel/GitHub readiness coverage and non-secret link confirmation metadata
- Public health and status readiness expose only aggregate launch action counts, deploy/link booleans, and public readiness states
- Local and unconfirmed runtimes still report the Vercel/GitHub lane as blocked or staged instead of pretending the production link is ready
- Vercel tokens, GitHub tokens, provider cookies, installation IDs, environment values, private repository data, database URLs, EVE tokens, private EVE data, raw submissions, and separate-project account details remain excluded
- Production live smoke verifies the reduced launch action queue, status-readiness queue floor, Vercel/GitHub link confirmation, protected-route privacy, and expected production commit
Protected Capability Readiness Export
Added an admin-gated Capability Readiness JSON and Markdown export, linked it from Ops, and expanded protected export smoke coverage so operators can review capability counts, section summaries, consent previews, provider gates, and no-secret boundaries without exposing protected packet bodies.
- Date: 2026-06-21
- Commit: 7c20484
- Deployment: dpl_UzQosxF3WaqNUy9ZURdvhpqyzxXR
Verification
- Type check
- Full test suite
- Production build
- Production live smoke
Safety
- Capability readiness exports are served only from protected admin routes and unauthenticated JSON and Markdown requests return private no-store/noindex responses
- Public health exposes only aggregate protected export counts, private-header counts, and readiness booleans for the capability handoff
- The Ops dashboard shows capability readiness counts and download links only after admin authentication
- Provider credentials, EVE tokens, private EVE data, raw submissions, private logs, protected packet bodies, provider account details, and separate-project account data remain excluded
- Production live smoke verifies the new protected capability-readiness routes, protected-route privacy headers, health protected export counters, and expected production commit
Capability Readiness Health Panel
Added a public Capability Readiness panel to Status and mirrored public capability coverage into Health JSON, status-readiness coverage, and live-smoke floors for public tools, browser-local workflows, protected review queues, EVE SSO gates, provider gates, and no-secret safety boundaries.
- Date: 2026-06-21
- Commit: 7f79fb3
- Deployment: dpl_5qjGPrHMgDjsrqYuHDKD2cofVc4K
Verification
- Type check
- Full test suite
- Production build
- Production live smoke
Safety
- Public capability readiness exposes only aggregate capability counts, route-link counts, consent-preview counts, provider-gate counts, link counts, and boundary counts
- Private EVE data, EVE OAuth tokens, provider credentials, account details, raw submissions, private logs, hidden setup packets, raw pasted analyzer inputs, and separate-project account details remain excluded
- The Status page now shows capability readiness without starting EVE OAuth, enabling provider actions, sending email, creating payment links, registering Discord commands, or making client/fleet actions
- Health JSON mirrors only count-level publicCapabilitiesReadiness and publicStatusReadiness fields for uptime checks and does not expose setup details or private review payloads
- Production live smoke verifies the Status page capability markers, capability JSON link, health readiness counters, protected-route privacy, and expected production commit
Public Capability Matrix
Added a public no-secret capability matrix page and JSON feed for live public tools, browser-local workflows, protected review queues, EVE SSO-gated modules, external provider gates, sitemap discovery, route-smoke coverage, and health-readiness counts.
- Date: 2026-06-20
- Commit: 74cafd3
- Deployment: dpl_6PHtxd3X1uaTwG1Ehmb9kraGc9uq
Verification
- Type check
- Full test suite
- Production build
- Production live smoke
Safety
- Public capability data exposes only public route labels, browser-local workflow labels, protected review labels, EVE SSO consent timing, provider gate labels, aggregate counts, and public links
- Private EVE data, EVE OAuth tokens, provider credentials, account details, raw submissions, hidden setup packets, protected response bodies, payment profile details, Discord secrets, email provider keys, and raw pasted analyzer inputs remain excluded
- First login remains limited to publicData while private EVE modules stay feature-specific and consent-previewed
- Provider-gated services remain behind feature flags, verification, or provider approval and the matrix does not enable payments, ads, email sending, Discord actions, AI calls, fleet controls, client actions, or payouts
- Production live smoke verifies the capability page, capability JSON, sitemap count, public route-smoke counts, public feed counts, trust/policy counts, private cache/robots headers, and no-secret capability text
Protected Owner Action Focus
Added a protected owner-focus summary to the Ops dashboard and owner-action JSON/Markdown exports so project-owner actions, build-team build-while-blocked lanes, and provider waits are separated while setup blockers remain gated.
- Date: 2026-06-20
- Commit: 5da6f47
- Deployment: dpl_H3zqQnKsaxb9Prw3AkAn1JFgyPde
Verification
- Type check
- Full test suite
- Production build
- Production live smoke
Safety
- Owner-focus details are served only through protected admin owner-action and Ops routes
- Public release notes expose only safe summary text, short commit, deployment id, verification classes, and public/protected route references
- Unauthenticated owner-action JSON and Markdown requests still return private no-store/noindex responses
- Provider secrets, account passwords, API keys, EVE client secrets, EVE tokens, private EVE data, raw queue data, raw IP addresses, raw user-agent strings, and account records remain excluded
- The owner-focus summary is an admin handoff aid only and does not enable OAuth, provider writes, payment actions, Discord actions, fleet controls, client actions, or payouts
Public Domain Contact Readiness
Added a public domain/contact readiness feed, Status page panel, and health/live-smoke coverage for warpintel.app, support@warpintel.app, HTTPS/contact routes, provider-boundary exclusions, and no external account mutation.
- Date: 2026-06-20
- Commit: fd82afc
- Deployment: dpl_4Y2jZedhaKPMTq7exHMz3JDUD1j3
Verification
- Type check
- Full test suite
- Production build
- Production live smoke
Safety
- Public domain readiness exposes only aggregate public page counts, machine-readable route counts, contact route counts, policy route counts, provider-boundary counts, support-surface counts, and safety booleans
- Registrar account details, DNS zone records, TLS private keys, mailbox credentials, provider console IDs, payment/ad account details, email provider API keys, database URLs, OAuth client secrets, EVE tokens, private EVE data, admin notes, raw support messages, and separate-project account details remain excluded
- The support@warpintel.app address is public contact text only and does not expose mailbox credentials, provider message IDs, or support queue contents
- The readiness feed confirms HTTPS/contact coverage and externalAccountMutationEnabled=false without making registrar, DNS, TLS, mailbox, Stripe, AdSense, Resend, Vercel, or GitHub account changes
- Production live smoke verifies the domain readiness JSON, Status page marker, health domain/status-readiness counters, no-secret text checks, and private cache/robots headers
Public Local Tool Readiness Feed
Added a public local-tool readiness feed, Status page link, and health/live-smoke coverage for browser-local tools, public-data tools, future sync lanes, high-trust upgrade boundaries, and no-server-storage safety.
- Date: 2026-06-20
- Commit: 72d81a6
- Deployment: dpl_AeMtk3KqSXb3HSazkxrfvN8F7Vzc
Verification
- Type check
- Full test suite
- Production build
- Production live smoke
Safety
- Public local-tool readiness exposes only aggregate browser-local tool counts, public-data tool counts, safe route links, future-sync counts, high-trust upgrade counts, and private-data exclusion counts
- Browser-local notes, browser-local reports, raw pasted analyzer inputs, manual queue submissions, support messages, account reports, admin review notes, EVE OAuth token values, provider credentials, private EVE data, wallet data, asset data, contract data, mail data, location data, and separate-project account details remain excluded
- Browser-local tools continue to store working state in the visitor browser unless the user exports it or later chooses account sync after EVE SSO is live
- Server-storage usage stays at zero for browser-local tool readiness and private EVE scope upgrades remain feature-specific consent lanes
- Production live smoke verifies the local-tool readiness JSON, Status page link, health local-tool/status-readiness counters, no-secret text checks, and private cache/robots headers
Vercel/GitHub Link Confirmation
Confirmed the production Vercel/GitHub project link after production metadata matched WarpIntelHQ/warpintel-app, redeployed the existing production app, and moved public Vercel/GitHub readiness from review to ready without exposing provider tokens or private repository data.
- Date: 2026-06-20
- Commit: 5bd37d7
- Deployment: dpl_4Lo8nioW4FMU67kNDUE8UdsR2GYb
Verification
- Type check
- Full test suite
- Production build
- Production live smoke
Safety
- The production confirmation uses only the non-secret Vercel/GitHub link readiness flag after the production Git metadata identified WarpIntelHQ/warpintel-app
- Public readiness exposes only aggregate deploy/link booleans, protected setup counts, dry-run availability, no-provider-mutation status, and separate-project separation status
- Vercel tokens, GitHub tokens, OIDC values, provider account cookies, installation IDs, private repository data, environment values, database URLs, cron secrets, EVE tokens, private account data, and raw pasted analyzer inputs remain excluded
- Separate-project accounts, repos, credentials, and deployments remain excluded from WarpIntel production readiness
- Production live smoke verifies the app still serves the expected commit, public Vercel/GitHub readiness is ready, and protected setup routes remain private
Public Support Readiness Feed
Added a public support readiness feed, Status page support readiness panels, and health/live-smoke coverage for support intake, voluntary support, Stripe support-link gates, email no-send gates, revenue provider boundaries, protected support review, and no-secret support readiness.
- Date: 2026-06-20
- Commit: ed78b4d
- Deployment: dpl_DcEuZqs6HBiNUtAbeRJsX4DedmiC
Verification
- Type check
- Full test suite
- Production build
- Production live smoke
Safety
- Public support readiness exposes only aggregate support surface counts, support request route counts, protected review route counts, provider-gate counts, workflow-stage counts, private-data exclusion counts, and no-live-provider safety booleans
- Raw support messages, contact details, email addresses, Discord handles, in-game names, page URLs, admin review notes, support queue statuses, rate-limit hashes, browser identifiers, EVE session ids, EVE tokens, Stripe customer records, payment profile details, provider secrets, email message ids, paid unlocks, and account decisions remain excluded
- Stripe support-link exposure remains disabled, Stripe live calls remain disabled, and payment-link creation remains blocked until the provider gate is intentionally enabled
- Email live sending remains disabled and the readiness feed confirms the no-provider-send dry-run boundary while support requests stay human-reviewed
- Production live smoke verifies the support readiness JSON, Status page marker, health support/status-readiness counters, no-secret text checks, and private cache/robots headers
Public Reports Readiness Feed
Added a public reports readiness feed, Status page reports readiness panels, and health/live-smoke coverage for browser-local report tools, export manifest formats, signed-in account report boundaries, disabled webhook delivery, and no-secret report readiness.
- Date: 2026-06-20
- Commit: 33a276a
- Deployment: dpl_dm7L22dim3LDUZZvAFgovxnfqCcJ
Verification
- Type check
- Full test suite
- Production build
- Production live smoke
Safety
- Public reports readiness exposes only aggregate report-format counts, tool counts, endpoint counts, public link counts, workflow-stage counts, webhook safety flags, and private-data exclusion counts
- Report bodies, raw pasted analyzer inputs, account reports, account exports, EVE OAuth token values, token ciphertext, provider credentials, private EVE data, raw visitor identifiers, raw browser agent strings, and webhook signing secrets remain excluded
- Account report storage remains signed-in and private; public report export coverage stays limited to browser-local save/export affordances and the public export manifest
- Webhook public delivery remains disabled and webhook signing remains required before any future delivery path can send report payloads outside the app
- Production live smoke verifies the reports readiness JSON, Status page marker, health reports/status-readiness counters, no-secret text checks, and private cache/robots headers
Public Permission Readiness Feed
Added a public permission readiness feed, Status page permission readiness link, and health/live-smoke coverage for EVE scope groups, feature consent previews, high-trust/write-scope boundaries, no-OAuth behavior, and no-secret permission catalog readiness.
- Date: 2026-06-20
- Commit: f4b5a34
- Deployment: dpl_HHNAKesB8JLR8jiPusR2q2VCbXYd
Verification
- Type check
- Full test suite
- Production build
- Production live smoke
Safety
- Public permission readiness exposes only aggregate EVE scope-group counts, scope counts, consent-preview counts, high-trust counts, write-action counts, public link counts, and safety-boundary counts
- EVE tokens, OAuth secrets, private character data, private corporation data, wallet journals, mail, contacts, assets, locations, fleet membership, and raw approval notes remain excluded
- The readiness feed confirms permission preview coverage without starting OAuth, changing user permissions, or requesting feature-specific consent outside user-driven preview/login flows
- Production live smoke verifies the permission readiness JSON, Status page marker, health permission/status-readiness counters, no-secret text checks, and private cache/robots headers
- Tracker evidence stays scoped to public schema checks, deployment ids, commit ids, aggregate readiness counts, and no-secret verification results
Public SEO Readiness Feed
Added a public SEO readiness feed, Status page SEO readiness panels, and health/live-smoke coverage for sitemap, robots, web app manifest, guide metadata, tool metadata, search-verification gates, and no-secret discovery boundaries.
- Date: 2026-06-20
- Commit: 58266c8
- Deployment: dpl_7uqQEaehbcWtKBwzR4d5Zb7kvME8
Verification
- Type check
- Full test suite
- Production build
- Production live smoke
Safety
- Public SEO readiness exposes only aggregate sitemap, robots, web-app-manifest, guide metadata, tool metadata, search-verification gate, public discovery link, and safety counts
- Search verification token values, analytics IDs, Search Console accounts, provider cookies, EVE tokens, private EVE data, admin exports, raw logs, and raw pasted analyzer inputs remain excluded
- Search provider setup remains a public gate only; the feed does not expose provider account state, verification values, or private approval details
- Production live smoke verifies the public SEO readiness JSON, Status page markers, and health SEO/status-readiness counters
- Tracker evidence stays scoped to public schema checks, deployment ids, commit ids, and no-secret verification results
Public Navigation Readiness Feed
Added a public navigation readiness manifest, Status page readiness panels, and health/live-smoke coverage for systems, routes, map, sovereignty, structures, wormholes, future private-intel consent, and manual route-action boundaries.
- Date: 2026-06-20
- Commit: 3ce53d3
- Deployment: dpl_HA1NZGDCAQAr5SP4ryxeKptq2HJz
Verification
- Type check
- Full test suite
- Production build
- Production live smoke
Safety
- Public navigation readiness exposes only public page counts, public route counts, public API route counts, workflow-stage counts, consent-preview links, and safety booleans
- Pilot location, online state, ship type, private route history, private bookmarks, private fleet membership, fleet participation ledgers, private killmails, structure access lists, EVE tokens, provider secrets, and private EVE data remain excluded
- Location read automation, fleet action automation, route decisions, destination selection, fleet movement, scouting, and in-game actions remain disabled for launch and require human-approved decisions before any future enablement
- Production live smoke verifies the public navigation readiness JSON, navigation page markers, Status page markers, and health navigation readiness counters
- Tracker evidence stays scoped to public schema checks, deployment ids, commit ids, and no-secret verification results
Public PI Readiness Feed
Added a public PI readiness manifest, Status page readiness panels, and health/live-smoke coverage for PI planner templates, future colony consent, protected setup route checks, and manual colony action boundaries.
- Date: 2026-06-20
- Commit: af57eed
- Deployment: dpl_DMjRd9hhtfYkDPfaT8n3UGX34yC9
Verification
- Type check
- Full test suite
- Production build
- Production live smoke
Safety
- Public PI readiness exposes only PI template counts, public route counts, public API route counts, protected setup route counts, workflow-stage counts, consent-preview links, and safety booleans
- Private colony layouts, planet pin positions, extractor routes, storage levels, customs office ownership notes, private assets, wallet journals, industry job history, EVE tokens, provider secrets, and private EVE data remain excluded
- Colony read automation, colony write automation, client actions, hauling, tax decisions, and route changes remain disabled for launch and require human-approved decisions before any future enablement
- Production live smoke verifies the public PI readiness JSON, PI Planner markers, Status page markers, and health PI readiness counters
- Tracker evidence stays scoped to public schema checks, deployment ids, commit ids, and no-secret verification results
Public Intake Readiness Feed
Added a public operations intake readiness manifest, Status page readiness panels, and health/live-smoke coverage for access, recruiting, and support intake, protected ops review, hashed quota guard coverage, and human decision boundaries.
- Date: 2026-06-20
- Commit: 7bde1f8
- Deployment: dpl_4XEVU8c4Z4byafxJzSD7cFJgLGYa
Verification
- Type check
- Full test suite
- Production build
- Production live smoke
Safety
- Public intake readiness exposes only public route counts, submission route counts, protected review route counts, workflow-stage counts, and safety booleans
- Raw access request rows, recruitment applications, support messages, applicant names, contact details, vouch notes, admin notes, audit metadata, rate-limit hashes, EVE tokens, provider secrets, and private EVE data remain excluded
- Notification sends, approvals, denials, access grants, recruitment decisions, support decisions, and account decisions remain disabled for automation and human-reviewed for launch
- Production live smoke verifies the public intake readiness JSON, Status page markers, and health intake readiness counters
- Tracker evidence stays scoped to public schema checks, deployment ids, commit ids, and no-secret verification results
Public Market Readiness Feed
Added a public market readiness manifest, Market Command/status page readiness panels, and health/live-smoke coverage for public appraisal and buyback surfaces, browser-local watchlists, future market/industry consent, and manual trade-decision boundaries.
- Date: 2026-06-20
- Commit: fd18849
- Deployment: dpl_DRszLukGyArXwakW7DLtsYUkF9aK
Verification
- Type check
- Full test suite
- Production build
- Production live smoke
Safety
- Public market readiness exposes only public route counts, public API route counts, workflow-stage counts, consent-preview links, and safety booleans
- Private wallet orders, market transactions, personal industry jobs, asset locations, corporation market ledgers, browser-local watchlist values, EVE tokens, provider secrets, and private EVE data remain excluded
- Order, contract, and wallet automation remain disabled for launch and require human-approved pricing, contract, and trade decisions before any future enablement
- Production live smoke verifies the public market readiness JSON, Market Command markers, Status page markers, and health market readiness counters
- Tracker evidence stays scoped to public schema checks, deployment ids, commit ids, and no-secret verification results
Public Buyback Readiness Feed
Added a public buyback readiness manifest, Buyback Calculator/status page readiness panels, and health/live-smoke coverage for public buyback calculator/intake, protected admin review, future market/corporation reconciliation consent, and manual pricing/contract/ISK boundaries.
- Date: 2026-06-20
- Commit: e4e3868
- Deployment: dpl_CMY2dGYyoh4X8NrKf9FR1Lb3uzk5
Verification
- Type check
- Full test suite
- Production build
- Production live smoke
Safety
- Public buyback readiness exposes only public route counts, public intake route counts, public quote route counts, protected review route counts, workflow-stage counts, consent-preview links, and safety booleans
- Raw item list rows, proof URLs, character contact details, requested locations, contract character notes, buyback queue notes, wallet journals, contract records, asset locations, corporation buyback ledgers, EVE tokens, provider secrets, and private EVE data remain excluded
- ISK movement and contract automation remain disabled for launch and require human-approved pricing, hauling, contract, and payout decisions before any future enablement
- Production live smoke verifies the public buyback readiness JSON, Buyback Calculator markers, Status page markers, and health buyback readiness counters
- Tracker evidence stays scoped to public schema checks, deployment ids, commit ids, and no-secret verification results
Public Mining Readiness Feed
Added a public mining readiness manifest, Mining Ledger/status page readiness panels, and health/live-smoke coverage for public manual mining intake, protected admin review, future mining data consent, corporation reconciliation consent, and manual payout/contract boundaries.
- Date: 2026-06-20
- Commit: eb3d9e5
- Deployment: dpl_CJDpZpprhjopW9orEuxa6xXPyhzh
Verification
- Type check
- Full test suite
- Production build
- Production live smoke
Safety
- Public mining readiness exposes only public route counts, public intake route counts, protected review route counts, workflow-stage counts, consent-preview links, and safety booleans
- Raw ore and loot lines, proof URLs, payout character notes, wallet journals, contract records, asset locations, corporation mining ledgers, member mining history, EVE tokens, provider secrets, and private EVE data remain excluded
- ISK movement and contract automation remain disabled for launch and require human-approved payout decisions before any future enablement
- Production live smoke verifies the public mining readiness JSON, Mining Ledger markers, Status page markers, and health mining readiness counters
- Tracker evidence stays scoped to public schema checks, deployment ids, commit ids, and no-secret verification results
Public Fleet Readiness Feed
Added a public fleet readiness manifest, Fleet Board/status page readiness panels, and health/live-smoke coverage for public fleet scheduling, protected publishing, future fleet context consent, high-trust write-action boundaries, and human-led fleet decisions.
- Date: 2026-06-20
- Commit: 5aa2cd0
- Deployment: dpl_A7ysPevsvGHqx7akypFiS9KGHVJq
Verification
- Type check
- Full test suite
- Production build
- Production live smoke
Safety
- Public fleet readiness exposes only public route counts, protected publishing route counts, workflow-stage counts, consent-preview links, and safety booleans
- Private fleet membership, fleet participation ledgers, FAT links, pilot location, online state, ship type, private killmails, fleet invitation tokens, EVE tokens, provider secrets, and private EVE data remain excluded
- Fleet write/client actions remain disabled for launch and require high-trust consent, role checks, audit history, and explicit human confirmation before any future enablement
- Production live smoke verifies the public fleet readiness JSON, Fleet Board markers, Status page markers, and health fleet readiness counters
- Tracker evidence stays scoped to public schema checks, deployment ids, commit ids, and no-secret verification results
Public Data Rights Readiness Feed
Added a public data-rights readiness manifest, Data Rights/status page readiness panels, and health/live-smoke coverage for export, delete, disconnect, browser-local storage, and private no-store account-control boundaries.
- Date: 2026-06-20
- Commit: 534f6ec
- Deployment: dpl_PfsNrZ9rCLkXgr1YL7M48cCYuEFG
Verification
- Type check
- Full test suite
- Production build
- Production live smoke
Safety
- Public data-rights readiness exposes only public route counts, protected account-control route counts, browser-local surface counts, protected smoke counts, readiness links, and safety booleans
- Account export payloads, EVE token values, token ciphertext, provider secrets, private EVE data, raw pasted inputs, raw visitor identifiers, raw support messages, and manual review queue notes remain excluded
- Account export, account deletion, EVE disconnect, EVE logout, and session status remain private no-store account-control responses
- Production live smoke verifies the public data-rights readiness JSON and health data-rights readiness counters
- Tracker evidence stays scoped to public schema checks, deployment ids, commit ids, and no-secret verification results
Public SRP Readiness Surface
Added a public SRP readiness manifest, SRP/status page readiness panels, and health/live-smoke coverage for SRP public intake, protected review, future EVE consent, and manual payout boundaries.
- Date: 2026-06-20
- Commit: b59bb59
- Deployment: dpl_4Kf9dWXyA86jMBqhMfdn8ciXYr8E
Verification
- Type check
- Full test suite
- Production build
- Production live smoke
Safety
- Public SRP readiness exposes only public route counts, protected route counts, workflow-stage counts, consent-preview links, and safety booleans
- Pilot names, killmail URLs, raw SRP queue notes, wallet data, contract data, EVE tokens, provider secrets, private EVE data, and payout actions remain excluded
- SRP review, approval, denial, and payout decisions remain human-approved with payout automation disabled
- Production live smoke verifies the public SRP readiness JSON and health SRP readiness counters
- Tracker evidence stays scoped to public schema checks, deployment ids, commit ids, and no-secret verification results
Public Separate-Project Smoke Guard
Added production live-smoke forbidden-marker guards for public release JSON and public Vercel/GitHub readiness JSON so separate-project names and old project-name-specific readiness fields fail future production smoke runs.
- Date: 2026-06-20
- Commit: 88a6357
- Deployment: dpl_9StCXUZJjubu9Jit7YGsjt4KXMEr
Verification
- Type check
- Full test suite
- Production build
- Production live smoke
Safety
- Production live smoke now rejects separate-project names in public release and public Vercel/GitHub readiness JSON
- Production live smoke now rejects the old project-name-specific readiness field if it reappears in public JSON
- Provider credentials, account data, repository internals, EVE tokens, private EVE data, raw logs, and secret-like values remain excluded
- The guard is automated in the same production smoke path used before tracker evidence is recorded
- Tracker evidence stays scoped to public schema checks, deployment ids, commit ids, and no-secret verification results
Public Separate-Project Wording Cleanup
Neutralized public release-note and Vercel/GitHub readiness wording so public JSON uses generic separate-project language and the public readiness flag is separateProjectExcluded.
- Date: 2026-06-20
- Commit: e54f90d
- Deployment: dpl_H1SbUTSgjwZ3kA6DDHShzadumxRN
Verification
- Type check
- Full test suite
- Production build
- Production live smoke
Safety
- Public release notes use generic separate-project wording instead of naming separate accounts or projects
- Public Vercel/GitHub readiness exposes the generic separateProjectExcluded aggregate flag instead of project-name-specific public fields
- Provider credentials, account details, repository internals, tokens, environment values, private EVE data, and raw logs remain excluded
- Production live smoke verifies the public Vercel/GitHub readiness aggregate boundary and release-readiness health counters
- Tracker evidence remains secret-safe and scoped to WarpIntel production deployment details only
Public Status Integration Action Queue Summary
Added a public-safe Integration Action Queue summary to /status, mirrored the status-page integration queue counts into public health, and neutralized public email-provider wording so internal account names stay out of public status text.
- Date: 2026-06-20
- Commit: 7e9767b
- Deployment: dpl_8B1NvtTTHgtxd1ey8cxWtoKPzBaf
Verification
- Type check
- Full test suite
- Production build
- Production live smoke
Safety
- Public status integration queue coverage exposes only sanitized priorities, public state, public owner category, setup-impact summaries, public links, and aggregate counts
- Provider credentials, payment profile details, API keys, EVE tokens, private EVE data, account data, raw submissions, private logs, hidden setup packets, internal account names, and separate-project account details remain excluded
- Production live smoke verifies Integration Action Queue and Open Integration Queue markers on /status
- Public health mirrors the status-page integration queue counts as aggregate fields only and keeps status readiness secret-like text checks enabled
- WarpIntel status evidence and tracker entries remain separated from separate-project accounts and services
Public Integrations Action Queue
Added a public-safe Integration Action Queue to /integrations and mirrored sanitized provider, account, feature-flag, and production-planning queue counts into public health.
- Date: 2026-06-20
- Commit: a15fc4c
- Deployment: dpl_61JmwuiqVDTUPpS2ATWF41rptmr3
Verification
- Type check
- Full test suite
- Production build
- Production live smoke
Safety
- Public integration queue coverage exposes only sanitized priorities, public state, public owner category, launch-impact summaries, public links, and aggregate counts
- Provider credentials, payment profile details, API keys, EVE tokens, private EVE data, account data, raw submissions, private logs, hidden setup packets, internal account names, and separate-project account details remain excluded
- Production live smoke now verifies Integration Action Queue markers on /integrations and actionQueueCount markers in /api/integrations
- Public health mirrors integration queue counts as aggregate fields only and allows provider progress to reduce gated counts without false production failures
- WarpIntel integration evidence and tracker entries remain separated from separate-project accounts and services
Public Status Launch Action Queue Summary
Added a public-safe Launch Action Queue summary to /status and mirrored the status-page queue counts into public health so monitors can verify the main public status surface without scraping private setup data.
- Date: 2026-06-20
- Commit: 65de828
- Deployment: dpl_HUGbqerrHSCu5DNdPnunNhc6o5ry
Verification
- Type check
- Full test suite
- Production build
- Production live smoke
Safety
- Public status launch queue coverage exposes only sanitized priority, public state, public owner category, area, next-step summaries, launch-impact text, and aggregate counts
- Provider credentials, API keys, passwords, payment profile details, EVE tokens, private EVE data, raw submissions, setup packets, internal account names, and separate-project account details remain excluded
- Production live smoke now verifies the public status page contains Launch Action Queue and Open Launch Queue markers
- Public health mirrors the status-page launch queue counts as aggregate count fields only
- WarpIntel status evidence and tracker entries remain separated from separate-project accounts and services
Public Launch Action Queue
Added a public-safe launch action queue so provider, account, and owner follow-ups are prioritized on /launch-readiness and monitored through aggregate health counts without exposing setup secrets.
- Date: 2026-06-20
- Commit: 9d8e052
- Deployment: dpl_9h64jSt8txcJjtU1e9cTuQ9D5zFf
Verification
- Type check
- Full test suite
- Production build
- Production live smoke
Safety
- The launch action queue exposes only sanitized labels, areas, public state, owner category, next-step summaries, launch impact text, and aggregate counts
- Provider credentials, API keys, passwords, payment profile details, EVE tokens, private EVE data, account data, raw submissions, hidden setup packets, internal account names, and separate-project account details remain excluded
- Production live smoke now verifies the public launch action queue marker and the aggregate action queue/blocker counts in public health
- The smoke floor allows provider progress to reduce blocker counts without creating false production failures
- WarpIntel launch readiness evidence and tracker entries remain separated from separate-project accounts and services
Public Status Permission Catalog Summary
Added a no-secret Permission Catalog section to the public status page so operators and visitors can review aggregate EVE scope groups, consent-preview coverage, high-trust/write-action counts, and OAuth boundary status without private account data.
- Date: 2026-06-20
- Commit: 6a2472b
- Deployment: dpl_44GJgRdJUCztowywUSQodECcKF2D
Verification
- Type check
- Full test suite
- Production build
- Production live smoke
Safety
- Public status permission catalog coverage exposes only aggregate scope counts, group counts, consent-preview counts, link counts, and safety-boundary text
- EVE tokens, client secrets, refresh tokens, private EVE data, account exports, raw queue notes, raw logs, raw IP addresses, provider setup details, internal account names, and separate-project account details remain excluded
- Production live smoke now verifies the public status page contains Permission Catalog, Known Scopes, and OAuth Boundary markers
- The status summary links to dry public permission previews and catalog JSON only; it does not start OAuth, contact CCP, request credentials, exchange tokens, perform gameplay actions, or store private account data
- WarpIntel status evidence and tracker entries remain separated from separate-project accounts and services
Public Permission Catalog Health Coverage
Added no-secret public permission catalog readiness coverage to health and live smoke so scope groups, consent-preview samples, high-trust/write-action scope counts, unknown-scope status, and OAuth-start boundaries can be monitored through aggregate counts.
- Date: 2026-06-20
- Commit: 9b59665
- Deployment: dpl_CPEAxvYTkfbmHfX289vf9S9VyDU4
Verification
- Type check
- Full test suite
- Production build
- Production live smoke
Safety
- Permission catalog health coverage exposes only aggregate group counts, scope counts, consent-preview counts, feature consent route counts, public link counts, and safety-boundary counts
- EVE tokens, client secrets, refresh tokens, private EVE data, account exports, raw queue notes, raw logs, raw IP addresses, provider setup details, internal account names, and separate-project account details remain excluded
- Production live smoke now verifies public permission catalog counts and fails if unknown scopes appear or the no-secret coverage flag disappears
- Consent preview routes remain public dry previews and do not start OAuth, contact CCP, request credentials, exchange tokens, perform gameplay actions, or store private account data
- WarpIntel permission readiness evidence and tracker entries remain separated from separate-project accounts and services
Public Roadmap Health Coverage
Added no-secret public roadmap readiness coverage to health and live smoke so roadmap phases, lanes, public links, protected labels, and gated EVE/provider milestones can be monitored through aggregate counts.
- Date: 2026-06-20
- Commit: 4daca25
- Deployment: dpl_ExniHAPyz7xZXxYxbEsKPUVJgnLR
Verification
- Type check
- Full test suite
- Production build
- Production live smoke
Safety
- Roadmap health coverage exposes only aggregate phase counts, lane counts, route-link counts, public tool counts, first-login scope status, and safety-boundary counts
- Credentials, token values, private EVE data, account exports, raw queue notes, raw logs, raw IP addresses, provider setup details, internal account names, and separate-project account details remain excluded
- Production live smoke now verifies public roadmap coverage counts and fails if the no-secret coverage flag disappears
- Protected ops and gated EVE/private-provider work stay labeled as protected or gated rather than exposing private payloads
- WarpIntel roadmap evidence and tracker entries remain separated from separate-project accounts and services
Public Integrations Health Coverage
Added no-secret public integrations readiness coverage to health and live smoke so external service setup can be monitored through aggregate counts, category coverage, public links, and safety boundaries.
- Date: 2026-06-20
- Commit: bbdb544
- Deployment: dpl_2NBSBVUFLQatLn84huS1ZfzZ3uHE
Verification
- Type check
- Full test suite
- Production build
- Production live smoke
Safety
- Integrations health coverage exposes only aggregate service counts, category counts, public link counts, and boundary booleans
- Provider credentials, payment profile details, API keys, EVE tokens, private EVE data, account data, raw submissions, private logs, setup packets, and internal account names remain excluded
- Production live smoke now verifies the public integrations coverage object and fails if no-secret boundary flags disappear
- Gated and blocked integration counts are treated as consistency signals so production can improve without failing because fewer services are pending
- WarpIntel integration readiness evidence and tracker entries remain separated from separate-project accounts and services
Support Link Gate Readiness Coverage
Exposed no-secret support-link gate status in public Stripe readiness and health so monitors can verify blocked, review, or ready state without payment-link exposure.
- Date: 2026-06-20
- Commit: 04e2877
- Deployment: dpl_KwiHURJApSsmBGGULvpXTJSZDTWo
Verification
- Type check
- Full test suite
- Production build
- Production live smoke
Safety
- Support-link gate readiness exposes only status, ready booleans, public route, and no-feature-unlock flags
- Payment links, support-link hrefs, Stripe account identifiers, checkout IDs, webhook details, customer records, and public env values remain excluded
- Production live smoke now fails if public Stripe readiness exposes a support-link href or loses the no-feature-unlock boundary
- Voluntary support remains feature-gated and does not unlock EVE data, app functionality, private dashboards, SRP priority, recruitment approval, fleet roles, or automation
- WarpIntel revenue readiness evidence and tracker entries remain separated from separate-project accounts and services
Public Support Link Gate
Centralized the public Stripe support-link gate so support panels share one safe ready, review, or pending state and only show reviewed HTTPS support links behind feature flags.
- Date: 2026-06-20
- Commit: dd08d5f
- Deployment: dpl_HFLAAoxrEVPUcjexS8eTxFpWX9Cd
Verification
- Type check
- Full test suite
- Production build
- Production live smoke
Safety
- Public support-link state exposes only safe ready, review, pending, and no-feature-unlock labels
- Unsafe or malformed Stripe URLs are rejected before public UI state can link to them
- No Stripe secret keys, webhook secrets, checkout IDs, customer records, payment profile details, support messages, EVE tokens, or private EVE data are exposed
- Voluntary support remains separated from special access, paid EVE data, private dashboards, SRP priority, recruitment approval, fleet roles, and automation
- WarpIntel revenue gate evidence and tracker entries remain separated from separate-project accounts and services
Tool SEO HTML Smoke Coverage
Upgraded production live smoke so all six public analyzer tool detail pages verify rendered description, canonical, OpenGraph URL, and website-type metadata.
- Date: 2026-06-20
- Commit: 8133682
- Deployment: dpl_6HXgVuU1qpN14K36BaBhhkcjLLzh
Verification
- Type check
- Full test suite
- Production build
- Production live smoke
Safety
- Tool SEO HTML smoke checks only public rendered analyzer tool pages and public metadata tags
- No EVE tokens, private EVE data, pasted analyzer inputs, provider credentials, raw logs, raw IP addresses, account records, payment details, or admin exports are exposed
- Tool pages remain public advisory content and do not request EVE SSO, call providers, perform gameplay actions, or store private account data
- Production live smoke now fails when rendered tool HTML loses description, canonical, OpenGraph URL, or website-type metadata
- WarpIntel tool smoke evidence and tracker entries remain separated from separate-project accounts and services
Guide SEO HTML Smoke Coverage
Upgraded production live smoke so all eight public guide detail pages verify rendered description, canonical, OpenGraph URL, and article-type metadata.
- Date: 2026-06-20
- Commit: bf082cb
- Deployment: dpl_9CW2wFzpUgeMqb2kccZqVrmF2JJC
Verification
- Type check
- Full test suite
- Production build
- Production live smoke
Safety
- Guide SEO HTML smoke checks only public rendered guide pages and public metadata tags
- No EVE tokens, private EVE data, pasted analyzer inputs, provider credentials, raw logs, raw IP addresses, account records, payment details, or admin exports are exposed
- Guide pages remain public advisory content and do not request EVE SSO, call providers, perform gameplay actions, or store private account data
- Production live smoke now fails when rendered guide HTML loses description, canonical, OpenGraph URL, or article-type metadata
- WarpIntel smoke evidence and tracker entries remain separated from separate-project accounts and services
Guide Metadata SEO Health Coverage
Added reusable guide metadata helpers and public health/live-smoke coverage for guide detail static paths, titles, canonical URLs, and OpenGraph metadata.
- Date: 2026-06-20
- Commit: 37d8b1a
- Deployment: dpl_HJDbpJvRZwEHTCHepVfPbzGf58wU
Verification
- Type check
- Full test suite
- Production build
- Production live smoke
Safety
- Guide metadata SEO health exposes aggregate guide metadata, canonical, OpenGraph, and static path counts only
- No EVE tokens, private EVE data, pasted analyzer inputs, provider credentials, raw logs, raw IP addresses, account records, payment details, or admin exports are exposed
- Public guide detail metadata remains static advisory content and does not start EVE SSO, call providers, perform gameplay actions, or store private account data
- Production live smoke now fails when guide metadata coverage drifts from the eight indexed public guide detail pages
- WarpIntel guide SEO health and tracker evidence remain separated from separate-project accounts and services
Tool Metadata SEO Health Coverage
Added public health and live-smoke coverage for analyzer tool detail metadata, canonical URLs, OpenGraph metadata, and static path coverage.
- Date: 2026-06-20
- Commit: df813d0
- Deployment: dpl_2W3UcnkBDhnzcgZFQ37jTxU8yTBd
Verification
- Type check
- Full test suite
- Production build
- Production live smoke
Safety
- Tool metadata SEO health exposes aggregate metadata, canonical, OpenGraph, and static path counts only
- No EVE tokens, private EVE data, pasted analyzer inputs, provider credentials, raw logs, raw IP addresses, account records, payment details, or admin exports are exposed
- Public tool detail metadata remains static advisory content and does not start EVE SSO, call providers, perform gameplay actions, or store private account data
- Production live smoke now fails when analyzer tool metadata coverage drifts from the six indexed public tool detail pages
- WarpIntel SEO health and tracker evidence remain separated from separate-project accounts and services
Static Tool Detail SEO Pages
Prebuilt all six public analyzer tool detail pages and added per-tool SEO metadata plus public no-login data-boundary content.
- Date: 2026-06-20
- Commit: dbceace
- Deployment: dpl_8tGuqzwYbv4jVP7Qvx97g7fSDxSJ
Verification
- Type check
- Full test suite
- Production build
- Production live smoke
Safety
- Static tool detail metadata lists only public analyzer titles, summaries, canonical routes, and public no-login boundaries
- No EVE tokens, private EVE data, pasted analyzer inputs, provider credentials, raw logs, raw IP addresses, account records, payment details, or admin exports are exposed
- Tool detail pages remain public advisory content and do not start EVE SSO, call providers, perform gameplay actions, or store private account data
- Production build now prebuilds the six indexed analyzer routes while live smoke continues to verify each public tool detail page
- WarpIntel SEO and tracker evidence remain separated from separate-project accounts and services
Tool Detail Smoke Coverage
Added production live-smoke and health coverage for six indexed public analyzer tool detail pages so sitemap-listed tool pages are checked individually.
- Date: 2026-06-20
- Commit: 9856b31
- Deployment: dpl_Dc7qcMMAmfZTxQKhuCBcwh2bqKyo
Verification
- Type check
- Full test suite
- Production build
- Production live smoke
Safety
- Public tool-detail smoke coverage checks only public static analyzer pages and aggregate route-smoke counts
- No EVE tokens, pasted analyzer inputs, private EVE data, provider credentials, raw logs, raw IP addresses, admin exports, payment details, or account records are exposed
- Tool detail pages remain public advisory content and do not request EVE SSO, perform gameplay actions, call providers, or store private account data
- Live smoke now fails when any indexed public analyzer tool detail route stops rendering or when tool-detail route-smoke health drops below the expected floor
- WarpIntel tool and tracker evidence remain separated from separate-project accounts and services
Guide Detail Smoke Coverage
Added production live-smoke and health coverage for all eight indexed public EVE guide detail pages so sitemap-listed guides are checked individually.
- Date: 2026-06-20
- Commit: a000475
- Deployment: dpl_9Xqyavd5y9PAH1PsebLWksH2kgie
Verification
- Type check
- Full test suite
- Production build
- Production live smoke
Safety
- Public guide smoke coverage checks only public static guide pages and aggregate route-smoke counts
- No EVE tokens, user-entered guide notes, private EVE data, provider credentials, raw logs, raw IP addresses, admin exports, or account records are exposed
- Guide detail pages remain public advisory content and do not request EVE SSO, perform gameplay actions, call providers, or store private account data
- Live smoke now fails when any indexed guide detail route stops rendering or when guide-detail route-smoke health drops below the expected floor
- WarpIntel guide and tracker evidence remain separated from separate-project accounts and services
Public SEO Discovery Readiness Coverage
Added aggregate public SEO and discovery readiness coverage to health checks so sitemap, robots, manifest, guide, and search-verification gate coverage is production-smoke checked.
- Date: 2026-06-20
- Commit: 31af7a1
- Deployment: dpl_3twYLtSR1mKjAUCst4B4bfCUcVcR
Verification
- Type check
- Full test suite
- Production build
- Production live smoke
Safety
- Public SEO readiness exposes aggregate sitemap, robots, manifest, guide, search-verification, link, and boundary counts only
- No verification token values, analytics IDs, Search Console accounts, provider cookies, EVE tokens, private EVE data, admin exports, raw logs, or raw pasted analyzer inputs are returned
- Sitemap, robots, and manifest definitions share a single public discovery source so health checks can fail on drift without exposing protected surfaces
- Live smoke now fails when public SEO/discovery coverage drops below MVP floors or top-level SEO-readiness health drifts from publicApp counters
- WarpIntel discovery and tracker evidence remain separated from separate-project accounts and services
Public Legal Readiness Health Coverage
Added aggregate public legal and compliance readiness coverage to health checks so privacy, terms, legal, data-rights, ad-choice, security, attribution, trust, referral, and revenue-boundary surfaces are production-smoke checked.
- Date: 2026-06-20
- Commit: 3d630e4
- Deployment: dpl_83iD4LDpdD2AerBxrC1qvGxF9D9j
Verification
- Type check
- Full test suite
- Production build
- Production live smoke
Safety
- Public legal readiness exposes aggregate legal-page, trust, security, attribution, revenue-disclosure, manifest, link, and boundary counts only
- No OAuth tokens, provider credentials, API keys, database URLs, raw pasted inputs, raw support messages, raw vulnerability reports, account exports, raw logs, raw IP addresses, payment profile details, private EVE data, or separate-project account details are returned
- Legal and revenue disclosures remain public no-secret pages and do not enable paid gates, provider calls, ad scripts, Stripe checkout, EVE SSO, or private account reads
- Live smoke now fails when public legal/compliance coverage drops below MVP floors or top-level legal-readiness health drifts from publicApp counters
- WarpIntel legal, revenue, and tracker evidence remain separated from separate-project accounts and services
Public Source Readiness Health Coverage
Added aggregate public source and freshness readiness coverage to health checks so source lanes, public-first boundaries, freshness rules, links, and no-secret source safety are production-smoke checked.
- Date: 2026-06-20
- Commit: d5a0dd9
- Deployment: dpl_6baMwpuXj5DoxU3ctUxCcu9hezBR
Verification
- Type check
- Full test suite
- Production build
- Production live smoke
Safety
- Public source readiness exposes aggregate source-lane, source-type, freshness, link, and boundary counts only
- No OAuth tokens, provider credentials, API keys, database URLs, raw pasted inputs, raw queue notes, account records, raw logs, cookies, or private EVE data are returned
- Future authorized EVE SSO data remains marked as future/private and excluded from public pages, ads, screenshots, analytics, and logs
- Live smoke now fails when public source/freshness coverage drops below MVP floors or top-level source-readiness health drifts from publicApp counters
- WarpIntel source and tracker entries remain separated from separate-project accounts and services
Protected Setup Packet Index Handoff Metadata
Added explicit Markdown handoff URLs and filename patterns to the protected setup-packet index, external readiness export, and Ops setup board so service handoffs are discoverable without guessing route formats.
- Date: 2026-06-20
- Commit: c0d487c
- Deployment: dpl_8d9PBSPXeikHxocuVA51ECj5pxWJ
Verification
- Type check
- Full test suite
- Production build
- Production live smoke
Safety
- Setup-packet handoff metadata is served only through protected admin setup and readiness routes
- Public release notes expose only safe summary text, short commit, deployment id, and public/protected route references
- Unauthenticated setup-packet index requests still return private no-store/noindex responses
- No provider credentials, account passwords, API keys, webhook secrets, database connection values, EVE tokens, private EVE data, payment profile details, or account records
- The metadata documents protected review links only and does not enable providers, read env vars, send email, register Discord commands, call OpenAI, change Stripe or AdSense, trigger deploys, or perform payouts
Protected External Setup Packet Markdown Handoffs
Added protected Markdown handoff downloads for the remaining external setup packets, linked them from Ops, and expanded protected setup-packet smoke coverage from 14 to 22 while keeping service setup evidence admin-only and no-secret.
- Date: 2026-06-20
- Commit: b742026
- Deployment: dpl_7z48em79MP4cpFQUQJ3y7h1VbB6w
Verification
- Type check
- Full test suite
- Production build
- Production live smoke
Safety
- Service setup Markdown handoffs are served only from protected admin setup-packet routes
- Public release notes expose only safe summary text, short commit, deployment id, and public/protected route references
- Unauthenticated service setup JSON and Markdown requests still return private no-store/noindex responses
- No provider credentials, account passwords, API keys, webhook secrets, database connection values, EVE tokens, private EVE data, payment profile details, or account records
- The Markdown handoffs are setup-review downloads only and do not enable providers, read env vars, send email, register Discord commands, call OpenAI, change Stripe or AdSense, trigger deploys, or perform payouts
Protected Backup Readiness Markdown Export
Added a protected Markdown recovery handoff for backup readiness, linked it from Ops, and included the Markdown URL in protected setup-packet smoke coverage while keeping recovery evidence admin-only and no-secret.
- Date: 2026-06-20
- Commit: 5bffee2
- Deployment: dpl_GfQGsyfkDrk3qwWLYdraf378ZFv4
Verification
- Type check
- Full test suite
- Production build
- Production live smoke
Safety
- Backup readiness Markdown is served only from the protected admin backup-readiness route
- Public release notes expose only safe summary text, short commit, deployment id, and public/protected route references
- Unauthenticated backup readiness JSON and Markdown requests still return private no-store/noindex responses
- No provider credentials, account passwords, database connection values, cron secret values, EVE token ciphertext, private EVE data, raw SQL dumps, or account records
- The Markdown export is a recovery-review handoff only and does not restore Neon, roll back Vercel, read env vars, enable provider setup, expose private reads, trigger write actions, or perform payouts
Protected Route-Smoke Markdown Summary
Added a protected Markdown summary for public route-smoke evidence, linked it from Ops, and included the Markdown URL in private live-smoke coverage while keeping route evidence status/header-only.
- Date: 2026-06-20
- Commit: 16144e1
- Deployment: dpl_5LqpwzQGKqznB3n9QrrHESVnV4gY
Verification
- Type check
- Full test suite
- Production build
- Production live smoke
Safety
- Route-smoke Markdown is served only from the protected admin route-smoke route
- Public release notes expose only safe summary text, short commit, deployment id, and public/protected route references
- Unauthenticated route-smoke JSON and Markdown requests still return private no-store/noindex responses
- No provider credentials, account passwords, EVE client secrets, EVE tokens, private EVE data, raw route bodies, or account records
- The Markdown export is a status/header-only human-review handoff and does not enable OAuth, provider setup, private reads, write actions, fleet controls, client actions, role changes, or payouts
Protected Ops Queue Markdown Summary
Added a protected aggregate Markdown summary for ops queues, linked it from Ops, and included the route in protected ops export smoke and health coverage while keeping row-level queue details in the protected CSV path.
- Date: 2026-06-20
- Commit: 52cfff9
- Deployment: dpl_73MqwdZqQPLnwABoVxGDw81qwYAz
Verification
- Type check
- Full test suite
- Production build
- Production live smoke
Safety
- Ops queue Markdown is served only from the protected admin ops-queues route
- Public release notes expose only safe summary text, short commit, deployment id, and public/protected route references
- Unauthenticated queue CSV and Markdown requests still return private no-store/noindex responses
- No provider credentials, account passwords, EVE client secrets, EVE tokens, private EVE data, raw queue data, or account records
- The Markdown export is an aggregate human-review handoff only and does not enable OAuth, provider setup, private reads, write actions, fleet controls, client actions, role changes, or payouts
Protected Release Readiness Markdown Export
Added a protected Markdown download for release readiness, linked it from Ops, and included the route in protected ops export smoke and health coverage while keeping the release-readiness body admin-only.
- Date: 2026-06-20
- Commit: 7b485e8
- Deployment: dpl_9ZKt2jaq5nFQdqdmbeFmQZ7yPNhS
Verification
- Type check
- Full test suite
- Production build
- Production live smoke
Safety
- Release readiness Markdown is served only from the protected admin release-readiness route
- Public release notes expose only safe summary text, short commit, deployment id, and public/protected route references
- Unauthenticated release-readiness JSON and Markdown requests still return private no-store/noindex responses
- No provider credentials, account passwords, EVE client secrets, EVE tokens, private EVE data, raw queue data, or account records
- The Markdown export is a human-review handoff only and does not enable OAuth, provider setup, private reads, write actions, fleet controls, client actions, or payouts
Protected Owner Action Markdown Export
Added a protected Markdown download for the owner action plan, linked it from Ops, and included the new route in protected ops export smoke and health coverage while keeping the owner-action body admin-only.
- Date: 2026-06-20
- Commit: 2882a11
- Deployment: dpl_AJEwBSYv5kuVXdug4XAXwNmhki7A
Verification
- Type check
- Full test suite
- Production build
- Production live smoke
Safety
- Owner action Markdown is served only from the protected admin owner-actions route
- Public release notes expose only safe summary text, short commit, deployment id, and public/protected route references
- Unauthenticated owner-action JSON and Markdown requests still return private no-store/noindex responses
- No provider credentials, account passwords, EVE client secrets, EVE tokens, private EVE data, raw queue data, or account records
- The Markdown export is a human-review handoff only and does not enable OAuth, provider setup, private reads, write actions, fleet controls, client actions, or payouts
Owner Action Plan EVE Scope Gap Action
Added the EVE scope-gap review to the protected owner action plan as a build-team-owned action so external setup work and remaining EVE mega-app permission review stay grouped in one admin export.
- Date: 2026-06-20
- Commit: 9dc3bd3
- Deployment: dpl_825tsEz7fL3wopoJ3gy729vkX6aZ
Verification
- Type check
- Full test suite
- Production build
- Production live smoke
Safety
- Owner action details are shown only through protected admin owner-action routes
- Public release notes list only safe summary text, short commit, deployment id, and public/protected route references
- Unauthenticated owner-action requests still return private no-store/noindex responses
- No EVE client IDs, client secrets, tokens, cookies, authorization headers, private EVE data, or account records
- Scope-gap owner actions are review signals only and do not enable OAuth, private reads, write actions, fleet controls, client actions, or payouts
Ops EVE Scope Gap Visibility
Surfaced EVE permission-group gaps on the protected Ops scope-risk panel and Ops review Markdown so admins can see partial groups, missing groups, missing scope totals, and write-action gap counts from the command view.
- Date: 2026-06-20
- Commit: 0c8c53a
- Deployment: dpl_FPzxee4taEvUmmPji3pYk6cr7Vrd
Verification
- Type check
- Full test suite
- Production build
- Production live smoke
Safety
- Scope gap counters are shown on protected Ops/admin surfaces only
- Public readiness and release notes continue to expose only safe summaries and aggregate release counts
- Unauthenticated admin overview and Ops review requests still return private no-store/noindex responses
- No EVE client IDs, client secrets, tokens, cookies, authorization headers, private EVE data, or account records
- Missing scope counts are review signals only and do not enable OAuth, private reads, write actions, fleet controls, client actions, or payouts
Protected EVE Setup Scope Gap Review
Added a protected-only EVE SSO scope gap review to the admin setup packet JSON and Markdown handoff so admins can see partial or missing permission groups, missing planned scope names, related feature plans, and next actions while public readiness stays count-only.
- Date: 2026-06-20
- Commit: 832d135
- Deployment: dpl_G6hhX8DMDtFMvhutoNYpk86tbRBp
Verification
- Type check
- Full test suite
- Production build
- Production live smoke
Safety
- Scope gap details are available only through protected admin setup packet routes
- Public readiness stays limited to safe booleans, counts, group names, and route links
- Unauthenticated setup packet requests still return private no-store/noindex responses
- No EVE client IDs, client secrets, access tokens, refresh tokens, cookies, authorization headers, or account data
- Missing write/action scopes remain review-only and do not enable OAuth, fleet controls, client actions, mail, contacts, or payouts
EVE SSO Scope Coverage Visibility
Added no-secret EVE permission-group coverage to the public readiness manifest and updated the Status Scope Map card so partial or missing permission groups show Review instead of Mapped while the write-actions group remains only partially allowed.
- Date: 2026-06-20
- Commit: d13dad3
- Deployment: dpl_EqXpTum1jzoW5JDTGNyKRhHzhzg3
Verification
- Type check
- Full test suite
- Production build
- Production live smoke
Safety
- Public readiness exposes permission group names, counts, and state only
- Raw allowed scope arrays, missing scope names, client IDs, client secrets, access tokens, and refresh tokens remain excluded
- Status page shows aggregate group coverage instead of protected EVE data or account data
- No private character, corporation, wallet, asset, location, mail, provider console, or callback secret data
- Write/action scope gaps remain review-only and do not enable OAuth, client actions, fleet actions, or payouts
Ops Review SRP Reserve Export Handoff
Added direct protected SRP reserve JSON and Markdown export links to the Ops review Markdown packet so admins can find reserve downloads from the SRP Reserve Planner section while keeping protected review content admin-only.
- Date: 2026-06-19
- Commit: 37b13d7
- Deployment: dpl_Cfyer6WGvNZDaPyzCzrHkoYFGiE5
Verification
- Type check
- Full test suite
- Production build
- Production live smoke
Safety
- Public release note lists only public routes, short commit, deployment id, and no-secret summary text
- Ops review body, SRP reserve export bodies, queue rows, pilot names, killmail URLs, and raw notes remain protected
- Unauthenticated Ops review requests still return private no-store/noindex responses
- No EVE tokens, provider secrets, private EVE data, account records, wallet reads, contract data, or payout actions
- Download links are admin handoff helpers only; human payout review and manual approval boundaries remain unchanged
Ops SRP Reserve Export Links
Added protected Ops dashboard links for the SRP reserve JSON and Markdown exports so admins can download reserve packets directly from the SRP Reserve Planner while preserving admin-only private-route behavior and no-public-private-data boundaries.
- Date: 2026-06-19
- Commit: 2f6b250
- Deployment: dpl_2yUJ1ivuqs4tzJevvkXshTV9Csi8
Verification
- Type check
- Full test suite
- Production build
- Production live smoke
Safety
- UI links point to protected admin export routes only
- Unauthenticated export requests still return private no-store/noindex responses
- No pilot names, killmail URLs, raw queue rows, EVE tokens, provider secrets, wallet reads, contract data, or payout actions
- No public exposure of protected SRP queue data, private fleet details, private EVE data, raw pasted analyzer inputs, or account data
- Download links are discoverability helpers only; human payout review and manual approval boundaries remain unchanged
Protected SRP Reserve Export
Added protected admin-only SRP reserve JSON and Markdown exports for fleet/SRP reserve monitoring, wired the routes into protected ops export smoke coverage and public health counts, and kept raw queue rows, pilot names, killmail URLs, EVE tokens, provider secrets, wallet reads, and payout actions out of public surfaces.
- Date: 2026-06-19
- Commit: 06478a7
- Deployment: dpl_8e46oZ5Nz78i6YP2EH7b3qm12an1
Verification
- Type check
- Full test suite
- Production build
- Production live smoke
Safety
- Aggregate reserve math, doctrine-lane exposure counts, route counts, and private-header checks only
- SRP reserve exports remain admin-only and return private no-store/noindex headers when unauthorized
- No pilot names, killmail URLs, raw queue rows, raw notes, EVE tokens, provider secrets, wallet reads, contract data, or payout actions
- No public exposure of protected SRP queue data, private fleet details, private EVE data, raw pasted analyzer inputs, or account data
- Human payout review remains required; the export provides reserve guidance only and does not automate reimbursements
Public Stripe Readiness Manifest
Added a public no-secret /api/stripe/readiness manifest for voluntary support-link readiness, public route coverage, protected setup coverage, and no-live-Stripe dry-run boundaries while keeping payment links, public environment variable names, Stripe account details, customer records, webhook details, shared legal-entity fields, EVE tokens, and private EVE data protected.
- Date: 2026-06-19
- Commit: 38903c0
- Deployment: dpl_HeXS4qWFGbbnhhC7Xbn2r4S7FvHt
Verification
- Type check
- Full test suite
- Production build
- Production live smoke
Safety
- Aggregate Stripe support-link booleans, route counts, checklist counts, and protected-check counts only
- Live Stripe calls, payment-link creation, customer mutations, and feature unlocks remain disabled from dry-run readiness surfaces
- No payment links, checkout IDs, Stripe account identifiers, customer records, webhook secrets, bank details, or shared legal-entity fields
- No public environment variable names, EVE tokens, private EVE data, protected setup packet details, raw pasted analyzer inputs, or private account data
- Support remains voluntary-only and does not unlock EVE app features, private-data access, approvals, or operational privileges
Public AdSense Readiness Manifest
Added a public no-secret /api/adsense/readiness manifest for Google AdSense review readiness, public route coverage, protected setup coverage, and no-Google-call dry-run boundaries while keeping ca-pub values, ad slot IDs, Google account details, verification prompts, payment profile details, tax records, provider cookies, public environment variable names, EVE tokens, and private EVE data protected.
- Date: 2026-06-19
- Commit: 1c5772e
- Deployment: dpl_Cmmr91SDGHkx1QLCZf2yHfYb6ovr
Verification
- Type check
- Full test suite
- Production build
- Production live smoke
Safety
- Aggregate AdSense route counts, readiness booleans, checklist counts, and protected-check counts only
- Google calls, ad script loading, and ad serving remain disabled from dry-run readiness surfaces
- No ca-pub values, ad slot IDs, Google account credentials, verification prompts, phone numbers, provider cookies, payment profile details, or tax records
- No public environment variable names, EVE tokens, private EVE data, protected setup packet details, raw pasted analyzer inputs, or private account data
- Ads remain public-page only and excluded from protected ops, private dashboards, account exports, and user-submitted private data views
Public Growth Readiness Manifest
Added a public no-secret /api/growth/readiness manifest for aggregate telemetry gates, search-verification gates, installed-component counts, protected setup coverage, and no-provider-call dry-run boundaries while keeping analytics IDs, verification token values, Google/Bing account details, provider cookies, Search Console screenshots, raw pageview data, workflow-click payloads, and private account data protected.
- Date: 2026-06-19
- Commit: 9c4e051
- Deployment: dpl_6UxRMJgenpEqBxzUWLXVtCyFhRwA
Verification
- Type check
- Full test suite
- Production build
- Production live smoke
Safety
- Aggregate growth telemetry and search-verification readiness counts only
- Provider calls, analytics enablement, Speed Insights enablement, Search Console submission, and verification-token return remain disabled from dry-run surfaces
- No analytics IDs, verification token values, Google account details, Bing account details, provider cookies, or Search Console screenshots
- No raw pageview data, workflow-click payloads, EVE tokens, private account data, or raw pasted analyzer inputs
- No separate-project account data
Public Vercel/GitHub Readiness Manifest
Added a public no-secret /api/vercel-github/readiness manifest for aggregate deployment-link readiness, production deploy status, protected setup coverage, no-mutation dry-run boundaries, and project-separation status while keeping provider tokens, OIDC values, provider account cookies, installation IDs, private repository data, environment variable values, and protected setup details private.
- Date: 2026-06-19
- Commit: 501b4a3
- Deployment: dpl_3DnUu4SNJP6mFBauifQMtjg7jK8a
Verification
- Type check
- Full test suite
- Production build
- Production live smoke
Safety
- Aggregate deployment-link readiness booleans and counts only
- Vercel/GitHub provider mutations and auth flows remain disabled from public and dry-run surfaces
- No Vercel tokens, GitHub tokens, OIDC values, provider account cookies, or installation IDs
- No private repository data, environment variable values, database URLs, cron secrets, EVE tokens, private account data, or raw pasted analyzer inputs
- separate-project accounts, repos, credentials, and deployments remain excluded
Public Sentry Readiness Manifest
Added a public no-secret /api/sentry/readiness manifest for aggregate error-monitoring readiness, protected setup coverage, capture-off status, instrumentation status, sample-capture status, and no-provider-call dry-run boundaries while keeping DSNs, Sentry org/project identifiers, event links, stack traces, cookies, authorization headers, and private payloads protected.
- Date: 2026-06-19
- Commit: bdb1769
- Deployment: dpl_FR4xteo2SGmsvxyvPLrqNZnvxrEK
Verification
- Type check
- Full test suite
- Production build
- Production live smoke
Safety
- Aggregate Sentry readiness counts only
- Sentry capture remains disabled until a WarpIntel-only DSN, instrumentation, scrub rules, and a safe protected sample capture are approved
- No DSN values, provider org identifiers, provider project identifiers, ingest URLs, or event links
- No stack traces, cookies, authorization headers, EVE tokens, private account data, or raw pasted analyzer inputs
- No separate-project account data
Public Backup Readiness Manifest
Added a public no-secret /api/backup/readiness manifest for recovery counts, migration count, protected setup coverage, safe export counts, proof target counts, restore-drill status, and no-provider-mutation dry-run boundaries while keeping Neon, Vercel, database, cron, migration tag, restore artifact, and protected setup details private.
- Date: 2026-06-19
- Commit: beda65c
- Deployment: dpl_2uv7T6b5K9H6Fm5kMTSXJLjtYqA4
Verification
- Type check
- Full test suite
- Production build
- Production live smoke
Safety
- Aggregate backup and recovery readiness counts only
- Restore drill status remains informational until a real provider-console drill is completed and recorded without secrets
- No database connection values, cron secret values, migration tags, Neon passwords, SQL dumps, or Vercel rollback targets
- No provider-console backup artifacts, token ciphertext, raw IP addresses, raw user-agent strings, EVE tokens, private account data, or raw pasted analyzer inputs
- No separate-project account data
Public AI Readiness Manifest
Added a public no-secret /api/ai/readiness manifest for first-tool AI enhancement coverage, deterministic fallback status, protected setup coverage, and no-provider-call dry-run boundaries while keeping OpenAI usage feature-gated until approved WarpIntel/Olympus key ownership, budget, and first-tool smoke checks are complete.
- Date: 2026-06-19
- Commit: 9bc7efb
- Deployment: dpl_EDMG1c3tVbCTcCcXRoxRuW4W7tyq
Verification
- Type check
- Full test suite
- Production build
- Production live smoke
Safety
- Aggregate first-tool AI readiness counts only
- OpenAI usage remains feature-gated until approved key ownership, budget, and first-tool smoke checks are complete
- No provider API keys, model environment values, authorization headers, billing details, or token-spend records
- No raw prompts, raw pasted analyzer inputs, EVE tokens, private account data, or protected setup details
- No separate-project account data
Public Discord Readiness Manifest
Added a public no-secret /api/discord/readiness manifest for command counts, public endpoint coverage, protected setup coverage, and no-provider-call dry-run status while keeping Discord app identifiers, bot tokens, guild IDs, public keys, install URLs, and command registration details protected.
- Date: 2026-06-19
- Commit: 95de409
- Deployment: dpl_4oxkHYgq9eSRALgbiQ1QxgYwU6J1
Verification
- Type check
- Full test suite
- Production build
- Production live smoke
Safety
- Aggregate Discord command and readiness counts only
- Discord setup remains feature-gated until app verification and endpoint validation are complete
- No app client identifiers, guild identifiers, public keys, install URLs, Discord API URLs, or command registration endpoints
- No bot tokens, provider credentials, authorization headers, EVE tokens, private account data, or raw pasted analyzer inputs
- No separate-project account data
Public Email Readiness Manifest
Added a public no-secret /api/email readiness manifest for Resend and approved SMTP fallback status, linked the feed from integrations and Support The Project, and expanded public feed smoke coverage while keeping transactional sending disabled until provider setup and no-sensitive smoke checks are approved.
- Date: 2026-06-19
- Commit: c2641ad
- Deployment: dpl_CZkasrp838GoGL5xbQdWfMhGrdSp
Verification
- Type check
- Full test suite
- Production build
- Production live smoke
Safety
- Aggregate email readiness counts and provider labels only
- Transactional sending remains disabled until the reviewed feature gate and provider setup are ready
- No sender, reply-to, recipient, mailbox, message identifier, or raw support message data
- No provider credentials, webhook signing values, EVE tokens, private account data, or raw pasted analyzer inputs
- No separate-project account data
Public Revenue Readiness Manifest
Added a public no-secret /api/revenue readiness manifest for Stripe support-link and Google AdSense status, linked it from Support The Project, expanded public feed smoke coverage, and kept unfinished revenue services behind feature flags until reviewed setup is complete.
- Date: 2026-06-19
- Commit: 055bb2c
- Deployment: dpl_4DQ7dqgxb2ZQTMrCxaCXmiktMwq3
Verification
- Type check
- Full test suite
- Production build
- Production live smoke
Safety
- Public provider readiness counts and routes only
- Stripe and AdSense remain feature-gated until reviewed setup is complete
- No paid gameplay advantage, app unlock, SRP priority, recruitment approval, or fleet role
- No private EVE data, provider credentials, account records, tax details, customer data, or protected setup packets
- No separate-project account data
Public Project Support Page
Added a dedicated public Support The Project page at /support-project with voluntary-support copy, Stripe feature-gate status, revenue-readiness cards, sitemap coverage, and route-smoke revenue-boundary health checks while keeping support optional and separate from gameplay access or private EVE data.
- Date: 2026-06-19
- Commit: 688d033
- Deployment: dpl_5taURwZB8FTFrSRiFRrkZfefrS8y
Verification
- Type check
- Full test suite
- Production build
- Production live smoke
Safety
- Voluntary support only
- Stripe link stays hidden until a reviewed WarpIntel HTTPS support link and feature flag are ready
- No paid gameplay advantage, SRP priority, recruitment approval, fleet role, or private dashboard unlock
- No private EVE data, provider secrets, customer records, or payment profile details
- No separate-project account data
Public Sovereignty Fallback Guard
Changed the public sovereignty API failure path from a 502 to a no-secret degraded fallback response so the sovereignty page, public route smoke, and production monitors stay reachable during transient public ESI outages while still showing live public sovereignty data whenever ESI is available.
- Date: 2026-06-19
- Commit: 6e4c1f2
- Deployment: dpl_2UiXYtUTYpAXUPkYUKsqvnbBckeq
Verification
- Type check
- Full test suite
- Production build
- Production live smoke
Safety
- Public ESI sovereignty map and campaign data only
- Degraded fallback includes no holder rows when public ESI is unavailable
- No private EVE scopes, wallets, assets, orders, contracts, tokens, or fleet data
- No strategic automation, client modification, or in-game action
- No separate-project account data
Public Appraisal Desk
Added a first-class public Appraisal Desk at /appraisal so pilots can price item lists with public Jita/The Forge market snapshots, review warning lines, and copy, download, or save local Markdown appraisal reports before moving into buyback, SRP, mining, or market planning.
- Date: 2026-06-19
- Commit: 728989a
- Deployment: dpl_CFbJ9iNhEdQ7Ze74r8ZM65Mi5Gga
Verification
- Type check
- Full test suite
- Production build
- Production live smoke
Safety
- Public ESI market and item-resolution data only
- User-entered item text stays out of public analytics and logs
- No private EVE scopes, wallets, assets, orders, contracts, or tokens
- No contract creation, ISK movement, EVE client modification, or trading automation
- No separate-project account data
Protected Owner Action Plan
Added a protected owner action plan export and Ops dashboard action summary that groups project-owner, build-team, and provider setup tasks from current launch blockers so external service work stays organized while preserving WarpIntel-only account boundaries and no-secret exports.
- Date: 2026-06-19
- Commit: 7b13f3e
- Deployment: dpl_8zXuwkRq8kbj9aYL1wFkKgmLzkNs
Verification
- Type check
- Full test suite
- Production build
- Production live smoke
Safety
- Protected admin-only export
- Public release note links only to public pages
- No provider secrets, passwords, API keys, or tokens
- No private EVE data, raw logs, raw IP addresses, or account data
- No separate-project account data
Protected Release Readiness Export
Added an admin-gated release readiness packet and Ops dashboard release-readiness panel so operators can review release-count, release-page-card, public href, verification, safety, and no-secret release text coverage from /ops without exposing credentials, tokens, private EVE data, raw logs, raw IP addresses, raw pasted analyzer inputs, raw manual queue submissions, or account data.
- Date: 2026-06-19
- Commit: 6ac1bd8
- Deployment: dpl_HZMSS9FsXDdJTKsE6EaRzgqjK5mo
Verification
- Type check
- Full test suite
- Production build
- Production live smoke
Safety
- Protected admin-only export
- Public release note links only to public pages
- No credentials, tokens, or private EVE data
- No raw logs or raw IP addresses
- No raw pasted analyzer inputs, raw manual queue submissions, or account data
Public Release Readiness Health Counts
Added count-only public health coverage for the public release manifest so monitors can verify release count, release page card count, total link count, unique public href count, health/release link coverage, verification check count, commit/deployment formatting, safety item count, manifest link count, safety-boundary count, and no-secret release text without credentials, tokens, private EVE data, raw logs, raw IP addresses, raw pasted analyzer inputs, raw manual queue submissions, or account data.
- Date: 2026-06-19
- Commit: a3ffd48
- Deployment: dpl_8SUHAtrYWMT33nPGWUiaTJspxwJ4
Verification
- Type check
- Full test suite
- Production build
- Production live smoke
Safety
- Public aggregate counts only
- No credentials, tokens, or private EVE data
- No raw logs or raw IP addresses
- No raw pasted analyzer inputs or manual queue submissions
- No account data
Public Status Readiness Health Counts
Added count-only public health coverage for the public status surface so monitors can verify service counts, status summary card count, production-check card count, route-smoke count, intake guard count, security header count, EVE consent-plan count, tool-boundary card count, setup-breakdown count, safe-default count, protected surface count, public link count, and no-secret status text without EVE tokens, provider credentials, account data, raw pasted analyzer inputs, raw manual queue submissions, raw logs, cookies, raw visitor identifiers, or separate-project account details.
- Date: 2026-06-19
- Commit: 57b0a6a
- Deployment: dpl_3ZHy7jUroDrnn5htEJPXQbj989UJ
Verification
- Type check
- Full test suite
- Production build
- Production live smoke
Safety
- Public aggregate counts only
- No EVE tokens, provider credentials, or account data
- No raw pasted analyzer inputs or manual queue submissions
- No raw logs, cookies, or visitor identifiers
- No separate-project account details
Public Tool Readiness Health Counts
Added count-only public health coverage for the public tool directory so monitors can verify total link count, analyzer tool count, directory group count, public data tool count, browser-local tool count, manual-review workflow count, unique href count, manifest link count, safety-boundary count, and no-secret tool text without private EVE data, account data, provider credentials, tokens, cookies, raw pasted analyzer inputs, raw manual queue submissions, admin routes, protected ops routes, or separate-project account details.
- Date: 2026-06-19
- Commit: d51849f
- Deployment: dpl_BThbt3bTYtEhgtUn32F6jSekuXot
Verification
- Type check
- Full test suite
- Production build
- Production live smoke
Safety
- Public aggregate counts only
- No private EVE data or account data
- No provider credentials, tokens, or cookies
- No raw pasted analyzer inputs or manual queue submissions
- No admin routes, protected ops routes, or separate-project account details
Public Trust Readiness Health Counts
Added count-only public health coverage for trust, source, attribution, and legal readiness so monitors can verify public page count, manifest count, trust section count, source matrix item count, attribution section count, legal hub link count, safety-boundary count, and no-secret trust text without OAuth tokens, provider credentials, API keys, database URLs, raw pasted inputs, raw queue notes, account exports, raw logs, raw IP addresses, private EVE data, or separate-project account details.
- Date: 2026-06-19
- Commit: 8707e6f
- Deployment: dpl_JDfcjUxAWFozh6yqAy9QX4UrRZ1M
Verification
- Type check
- Full test suite
- Production build
- Production live smoke
Safety
- Public aggregate counts only
- No OAuth tokens, provider credentials, API keys, or database URLs
- No raw pasted inputs, raw queue notes, raw logs, or raw IP addresses
- No account exports or private EVE data
- No separate-project account details
Public Launch Readiness Health Counts
Added count-only public health coverage for launch readiness so monitors can verify lane count, area count, gated-lane count, public link count, safety-boundary count, sanitized-lane count, and no-secret launch text without provider credentials, API keys, passwords, payment profile details, EVE tokens, private EVE data, account data, raw submissions, hidden setup packets, internal account names, or separate-project account details.
- Date: 2026-06-19
- Commit: 0b0f7e1
- Deployment: dpl_D6ShjdAwcfHF19G5CU216huNZUGd
Verification
- Type check
- Full test suite
- Production build
- Production live smoke
Safety
- Public aggregate counts only
- No provider credentials, API keys, or passwords
- No payment profile details
- No EVE tokens or private EVE data
- No raw submissions, setup packets, or separate-project account details
Public EVE SSO Readiness Health Counts
Added count-only public health coverage for EVE SSO readiness so monitors can verify checklist count, feature-consent plan count, consent-preview count, protected setup and dry-run coverage, verified boundary count, and dry-run OAuth/token safety without EVE client IDs, client secrets, access tokens, refresh tokens, cookies, authorization headers, user account data, or private EVE data.
- Date: 2026-06-19
- Commit: fa46396
- Deployment: dpl_8hhDKp2msPcHoUymNCwj3RL1KQqe
Verification
- Type check
- Full test suite
- Production build
- Production live smoke
Safety
- Public aggregate counts only
- No EVE client IDs or client secrets
- No access or refresh tokens
- No cookies or authorization headers
- No user account data or private EVE data
Public Growth Readiness Health Counts
Added count-only public health coverage for growth telemetry readiness so monitors can verify readiness item count, telemetry gates, search-verification gates, protected setup and dry-run coverage, verified boundary count, and no-provider-call dry-run safety without analytics IDs, verification token values, Google or Bing account details, provider cookies, raw pageview data, workflow-click payloads, or private EVE data.
- Date: 2026-06-19
- Commit: 4e613e8
- Deployment: dpl_2JsVxSDoz7P6PURQjDJMB2oTUyX7
Verification
- Type check
- Full test suite
- Production build
- Production live smoke
Safety
- Public aggregate counts only
- No analytics IDs or verification token values
- No Google or Bing account details
- No provider account cookies
- No raw pageview or workflow-click payloads
Public Vercel GitHub Readiness Health Counts
Added count-only public health coverage for the Vercel/GitHub deployment boundary so monitors can verify protected setup coverage, dry-run coverage, production deploy status, repo/link confirmation posture, no-mutation safety, and separate-project separation without provider tokens, OIDC values, installation IDs, private repo data, or environment values.
- Date: 2026-06-19
- Commit: 63d0578
- Deployment: dpl_3F1WjauLUs7MbBfUuZoDPpF6xPnN
Verification
- Type check
- Full test suite
- Production build
- Production live smoke
Safety
- Public aggregate counts only
- No Vercel or GitHub tokens
- No OIDC values or installation IDs
- No provider account cookies
- No separate-project crossover
Public Email Readiness Health Counts
Added count-only public health coverage for transactional email readiness so monitors can verify first-launch email type count, protected setup packet coverage, protected dry-run coverage, provider-readiness booleans, and no-send dry-run safety without provider keys, SMTP credentials, webhook secrets, mailbox addresses, recipient addresses, or raw support messages.
- Date: 2026-06-19
- Commit: 9bf3ae3
- Deployment: dpl_86MwVfyzbf1Uskhmn8CBMbMJuL6x
Verification
- Type check
- Full test suite
- Production build
- Production live smoke
Safety
- Public aggregate counts only
- No provider keys or SMTP credentials
- No webhook secret values
- No sender, reply-to, or recipient addresses
- No raw support messages
Public Backup Readiness Health Counts
Added count-only public health coverage for backup and recovery readiness so monitors can verify migration-ledger count, recovery checklist coverage, proof-target coverage, safe-export coverage, and no-provider-mutation dry-run safety without database credentials or provider-console artifacts.
- Date: 2026-06-19
- Commit: 60dd465
- Deployment: dpl_2LQpbZ8j72Fzmuffaviy5p1WxymW
Verification
- Type check
- Full test suite
- Production build
- Production live smoke
Safety
- Public aggregate counts only
- No database connection values
- No cron secret values
- No migration tags or SQL dumps
- No provider-console backup artifacts
Public Discord Readiness Health Counts
Added count-only public health coverage for Discord readiness so monitors can verify command manifest size, public endpoint coverage, protected setup packet coverage, protected dry-run coverage, and dry-run safety without bot tokens or Discord identifiers.
- Date: 2026-06-19
- Commit: 9bac818
- Deployment: dpl_HzqaEucDfvTrmySru7oyx6ueqKaW
Verification
- Type check
- Full test suite
- Production build
- Production live smoke
Safety
- Public aggregate counts only
- No Discord bot tokens
- No client, guild, or public key identifiers
- No install URLs or Discord API URLs
Public Sentry Readiness Health Counts
Added count-only public health coverage for Sentry readiness so monitors can verify protected setup packet coverage, protected dry-run coverage, capture-off status, and safe-to-enable status without DSNs or provider identifiers.
- Date: 2026-06-19
- Commit: acd2f9a
- Deployment: dpl_Du7FeS8UJPb5f1zs6ekQD7LD6kKu
Verification
- Type check
- Full test suite
- Production build
- Production live smoke
Safety
- Public aggregate counts only
- No DSN values
- No provider org or project identifiers
- No stack traces or event URLs
Public AI Readiness Health Counts
Added count-only public health coverage for first-tool AI readiness so monitors can verify eligible tool count, setup-packet coverage, dry-run coverage, and deterministic fallback status without provider secrets or prompt data.
- Date: 2026-06-19
- Commit: ac8d7ac
- Deployment: dpl_HBz9J18SPUPGokqrzrHx2AmRoUEV
Verification
- Type check
- Full test suite
- Production build
- Production live smoke
Safety
- Public aggregate counts only
- No provider key state
- No raw prompts
- No AI billing or model env values
Public Revenue Readiness Health Counts
Added count-only public health coverage for Stripe and AdSense readiness so monitors can confirm provider count, setup-packet coverage, and dry-run coverage without exposing env names or provider details.
- Date: 2026-06-19
- Commit: 53ae5a2
- Deployment: dpl_65unBWGMTRAcaghHeumx8iTR2sAb
Verification
- Type check
- Full test suite
- Production build
- Production live smoke
Safety
- Public aggregate counts only
- No env var names
- No provider account details
- No payment or ad customer data
Protected Revenue Readiness Coverage
Added protected Stripe and AdSense readiness coverage to /ops, the ops review Markdown, and the ops snapshot export so admins can review public env gaps, setup packets, and dry runs without provider secrets.
- Date: 2026-06-19
- Commit: a153709
- Deployment: dpl_H9ao4kELrGAeCRS6BPsAwa5pQ2Wd
Verification
- Type check
- Full test suite
- Production build
- Production live smoke
Safety
- Protected admin-only coverage
- No payment-link creation
- No ad script loading
- No provider secrets
Gated Support Receipt Email Adapter
Added a feature-gated Resend support receipt adapter for support intake so receipt sending can be enabled only after WarpIntel sender settings, feature flag, and no-sensitive smoke testing are ready.
- Date: 2026-06-19
- Commit: 2964903
- Deployment: dpl_8jXRMDiG35CTNZUcjqXD955VeYcT
Verification
- Type check
- Full test suite
- Production build
- Production live smoke
Safety
- Feature-gated email send
- No raw support message in receipt
- No EVE tokens
- No provider secrets
Protected Feature Consent Coverage
Added protected feature-consent coverage to the /ops permission audit, ops review Markdown, and ops snapshot export so admins can verify planned EVE consent paths without exposing private data.
- Date: 2026-06-19
- Commit: d71aaef
- Deployment: dpl_BzFxJf1bC3B6zp2sRKhKF6B2k2sx
Verification
- Type check
- Full test suite
- Production build
- Production live smoke
Safety
- Protected admin-only coverage
- No OAuth exchange
- No EVE tokens
- No private EVE data
EVE Feature Consent Health Coverage
Mirrored EVE feature-consent coverage counts into /api/health and the public /status EVE login gate so monitors can confirm planned consent paths before OAuth starts.
- Date: 2026-06-19
- Commit: 5bdb79a
- Deployment: dpl_CA7FvPQ5jLXnuMEC2XFeK2T2J1ii
Verification
- Type check
- Full test suite
- Production build
- Production live smoke
Safety
- Public no-secret health counts
- No OAuth start
- No EVE secrets
- No private EVE data
EVE Feature Consent Readiness
Exposed preview-only feature consent plans through the EVE SSO readiness gate and setup packet so monitors can see planned consent coverage before OAuth starts.
- Date: 2026-06-19
- Commit: d45694a
- Deployment: dpl_EijYkaB3ZAVG7emHiGUvTcPLp4jS
Verification
- Type check
- Full test suite
- Production build
- Production live smoke
Safety
- Preview-only consent metadata
- No OAuth start
- No EVE secrets
- No private EVE data
EVE Feature Consent Map
Added a public-safe feature consent map to /permissions and the EVE scope catalog so MVP features show consent timing, scope groups, preview links, and high-trust boundaries before OAuth starts.
- Date: 2026-06-19
- Commit: b629015
- Deployment: dpl_FJhh3ascd5ajyQZpo1ia7g2G6Pqc
Verification
- Type check
- Full test suite
- Production build
- Production live smoke
Safety
- Preview-only consent links
- No OAuth start
- No EVE tokens
- No private EVE data
Ops Setup Dry-Run Actions
Added protected dry-run actions directly to the /ops external setup cards and mirrored the packet plus dry-run route pair in admin review handoffs.
- Date: 2026-06-19
- Commit: 36a2cc2
- Deployment: dpl_2MeMk2BpuLxbFDhrHiDYNMB2RoZA
Verification
- Type check
- Full test suite
- Production build
- Production live smoke
Safety
- Protected admin actions
- No provider writes
- No provider credentials
- No private EVE data
Protected Setup Packet Dry-Run Links
Added protected dry-run action links to the admin setup-packet index and external readiness export so provider setup lanes show both packet and safe preview-action routes.
- Date: 2026-06-19
- Commit: 18a1c06
- Deployment: dpl_DmaUGyms9FgzLLxtAJX8KZY1g5j8
Verification
- Type check
- Full test suite
- Production build
- Production live smoke
Safety
- Protected admin index
- No provider writes
- No provider credentials
- No private EVE data
Protected EVE SSO Dry Run
Added the protected /ops EVE SSO dry-run action, admin-only JSON preview route, and production smoke coverage for validating the EVE login gate without starting OAuth.
- Date: 2026-06-19
- Commit: 6263df1
- Deployment: dpl_GGaQA7WATqwGWh5LLdiLvG3qqjBh
Verification
- Type check
- Full test suite
- Production build
- Production live smoke
Safety
- No OAuth start
- No token exchange
- No EVE client secrets
- No private EVE data
Public EVE SSO Readiness Manifest
Added the no-secret /api/auth/eve/readiness manifest, health/status/permissions links, and production smoke coverage for the public EVE login gate.
- Date: 2026-06-19
- Commit: 089289c
- Deployment: dpl_H7TTfRkZRNtjTUw8ry71eT1tc8RF
Verification
- Type check
- Full test suite
- Production build
- Production live smoke
Safety
- No EVE client secrets
- No EVE tokens
- No private EVE data
- No account data
Public Launch Readiness Manifest
Added the public /launch-readiness page and no-secret /api/launch-readiness manifest for MVP readiness, provider gates, feature flags, and launch safety boundaries.
- Date: 2026-06-18
- Commit: 148c32a
- Deployment: dpl_AmQtRQj4kD4Y4PyuJ7tfBGv8RNP8
Verification
- Type check
- Full test suite
- Production build
- Production live smoke
Safety
- No private EVE data
- No provider credentials
- No account data
- No hidden setup packets
Public Security Baseline Manifest
Added the no-secret /api/security security baseline manifest, security page JSON link, status and health metadata, and production smoke coverage for security-boundary monitors.
- Date: 2026-06-18
- Commit: 61927a9
- Deployment: dpl_95Ek9Jgbbhi8mHF1HCnrBrVrpRSN
Verification
- Type check
- Full test suite
- Production build
- Production live smoke
Safety
- No private EVE data
- No provider credentials
- No account data
- No raw vulnerability reports
Public Integrations Readiness Manifest
Added the public /integrations page and no-secret /api/integrations readiness manifest for EVE SSO, Discord, Stripe, AdSense, Resend, AI, telemetry, and monitoring gates.
- Date: 2026-06-18
- Commit: 755899f
- Deployment: dpl_3EZ2CC9r4J4EMxhiNzwq1ujYAbxz
Verification
- Type check
- Full test suite
- Production build
- Production live smoke
Safety
- No private EVE data
- No provider credentials
- No account data
- No hidden setup packets
Public Trust Center Manifest
Added the no-secret /api/trust trust center manifest, public /trust feed link, status and health metadata, and production smoke coverage for trust-boundary monitors.
- Date: 2026-06-18
- Commit: 0c36c29
- Deployment: dpl_F1hrM1PiL7CcVyh1xXFTiMWhgF2W
Verification
- Type check
- Full test suite
- Production build
- Production live smoke
Safety
- No private EVE data
- No provider credentials
- No account data
- No raw queue notes
Public Source Matrix Manifest
Added the no-secret /api/sources source and freshness manifest, public /sources link, public status link, health metadata, and production smoke coverage for source-boundary monitors.
- Date: 2026-06-18
- Commit: 03a1ee7
- Deployment: dpl_EQucyr9chAtAx1hCb1UVw9jZdJ5G
Verification
- Type check
- Full test suite
- Production build
- Production live smoke
Safety
- No private EVE data
- No provider credentials
- No account data
- No raw pasted inputs
Public Roadmap Manifest
Added the public /roadmap page and no-secret /api/roadmap manifest for live MVP lanes, protected ops lanes, EVE SSO gates, and external-provider readiness boundaries.
- Date: 2026-06-18
- Commit: 67d7d07
- Deployment: dpl_6micBzmn2wJadVaLUQ6rmpwKXDqz
Verification
- Type check
- Full test suite
- Production build
- Production live smoke
Safety
- No private EVE data
- No provider credentials
- No account data
- No separate-project account use
Protected External Readiness Export
Added a protected /api/admin/external-readiness export and Markdown variant that combine service status, setup packet links, and no-secret safety boundaries for external-provider setup review.
- Date: 2026-06-18
- Commit: 2376e01
- Deployment: dpl_3fJYTSfprKqgMKTo6Ra4sWrk6Vbr
Verification
- Type check
- Full test suite
- Production build
- Production live smoke
Safety
- Protected admin route
- No provider credentials
- No payment profile details
- No private EVE data
Public EVE Permission Catalog
Added a no-secret /api/permissions/scopes manifest for the EVE SSO scope catalog, consent preview samples, status/health links, and production smoke coverage.
- Date: 2026-06-18
- Commit: 1b2b0be
- Deployment: dpl_HkCvXLtcKvRHtizcQBRjYv9GMcuU
Verification
- Type check
- Full test suite
- Production build
- Production live smoke
Safety
- Does not start OAuth
- No EVE tokens
- No private EVE data
- No account data
Public Release Manifest
Added a no-secret /api/releases JSON manifest, public health/status links, and production smoke coverage for release history consumers.
- Date: 2026-06-18
- Commit: b847a39
- Deployment: dpl_FdWxMp2yXPfHuLyyesss4EwrT1ks
Verification
- Type check
- Full test suite
- Production build
- Production live smoke
Safety
- No provider credentials
- No private EVE data
- No account data
- No raw logs
Public Tool Directory Manifest
Added a no-secret /api/tools/directory JSON manifest for agents, monitors, and future UI surfaces to consume the tested public tool catalog without scraping /tools.
- Date: 2026-06-18
- Commit: 2248ff8
- Deployment: dpl_6YPCbMrHku4Jy1nWXt7bw1Ayhfa8
Verification
- Type check
- Full test suite
- Production build
- Production live smoke
Safety
- No private EVE data
- No provider credentials
- No account data
- No raw submissions
Public Tool Directory Coverage
Expanded /tools into a tested 33-link public app directory covering analyzer tools, public data and reference routes, browser-local planning tools, and manual review workflows.
- Date: 2026-06-18
- Commit: 73f9860
- Deployment: dpl_74nqtGEafmhQPugwS2EJBiH3mBg5
Verification
- Type check
- Full test suite
- Production build
- Production live smoke
Safety
- No private EVE data
- No provider credentials
- No account data
- No separate-project account use
Protected Launch Blockers Export
Added an admin-only launch blockers export with JSON and Markdown downloads, ops dashboard access, protected ops export smoke coverage, and public health/status count updates.
- Date: 2026-06-18
- Commit: cfa4101
- Deployment: dpl_BUg55FZD2zEkGsWpPe8aatVtzu5E
Verification
- Type check
- Full test suite
- Production build
- Production live smoke
Safety
- Protected admin route
- No provider credentials
- No private EVE data
- No raw submissions
EVE SSO Setup Handoff
Added a protected EVE SSO setup Markdown handoff for the production callback blocker, admin download route variant, ops dashboard link, and protected setup-packet smoke coverage.
- Date: 2026-06-18
- Commit: ee2504c
- Deployment: dpl_ACruV6R3YNESAjh3yZEF4onJey1w
Verification
- Type check
- Full test suite
- Production build
- Production live smoke
Safety
- Protected admin route
- No EVE client secret
- No EVE token values
- No private EVE data
Public Release Notes
Added the public /releases page, release summary module, public navigation link, sitemap entry, status link, and live smoke coverage for public deployment history.
- Date: 2026-06-18
- Commit: 76e94de
- Deployment: dpl_FxCzCmapk96HuuZXRqHE1kdsVuZi
Verification
- Type check
- Full test suite
- Production build
- Production live smoke
Safety
- No raw logs
- No provider credentials
- No private account data
- No private EVE data
Public Legal Hub
Added the public /legal hub, sitemap and navigation links, and route-smoke coverage for the legal/trust disclosure surface.
- Date: 2026-06-18
- Commit: 15c5900
- Deployment: dpl_LzVeWybSaJ5VfWxZC7VBee9aFgsK
Verification
- Type check
- Full test suite
- Production build
- Production live smoke
Safety
- No private EVE data
- No provider credentials
- No account data
- No separate-project account use
Backup Recovery Dry Run
Added an admin-only backup recovery dry run for release/recovery checklist review without Neon restores, Vercel rollbacks, environment changes, or database writes.
- Date: 2026-06-18
- Commit: 22ec804
- Deployment: dpl_BiW7vG68gjzQju9n4cyewMdCx1aT
Verification
- Type check
- Full test suite
- Production build
- Production live smoke
Safety
- No Neon restore
- No Vercel rollback
- No env-var change
- No secret export
Vercel/GitHub Dry Run
Added an admin-only Vercel/GitHub dry run for the WarpIntelHQ repo and Olympus deployment boundary without provider auth flows or mutations.
- Date: 2026-06-18
- Commit: 345f95f
- Deployment: dpl_6veMq4csmQgkexecygtcc8y28s4K
Verification
- Type check
- Full test suite
- Production build
- Production live smoke
Safety
- No GitHub mutation
- No Vercel mutation
- No provider auth flow
- No token exposure
Growth, OpenAI, Discord, Sentry, Ads, And Stripe Dry Runs
Staged provider readiness dry runs behind protected admin actions so external services can be reviewed without live calls, provider writes, or secret exposure.
- Date: 2026-06-18
- Commit: 037de94
- Deployment: dpl_4PEwCd45Yeo5VCP1fwU3ZgqKBFWf
Verification
- Type check
- Full test suite
- Production build
- Production live smoke
Safety
- No live provider calls
- No AI token spend
- No ad script enablement
- No payment-link creation
Public release notes list only public routes, short commits, deployment ids, verification classes, and no-secret safety summaries. They never include credentials, token values, private account data, private EVE data, raw logs, raw IPs, or raw pasted tool inputs.
