You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
None. Only one open PR (#1449, changeset-release/main, authored by mrbro-bot[bot]) exists and all its checks (Lint, Type Check, Test, Package smoke, CodeQL, Renovate) are passing.
Security
None. gh api repos/marcusrbrown/infra/dependabot/alerts returned HTTP 200 with zero open alerts. No security-labeled or vulnerable-dependency PRs are open.
Code Quality & Repo Hygiene
Check
Result
Action
Stale TODOs
0 found
None — full-repo scan (excluding node_modules/.git/dist/.cache) found no code-level TODO/FIXME/HACK annotations; only matches were this workflow's own prompt text and doc references about an unrelated cross-repo TODO marker
Convention drift
✅ Clean
Mechanical structural checks are gated by ESLint + packages/cli/src/conventions.test.ts, both passing
AGENTS.md accuracy
✅ Current
All apps/* and packages/* directories match root AGENTS.md STRUCTURE; per-package AGENTS.md command trees match actual source layout
Code-aware drift
✅ Clean
Spot-checked gateway (WORKSPACE_PERMISSION_POLICY, REQUIRED_ENV_VARS, egress host allowlist), dashboard (compose hardening block), cliproxy (config.yaml skip-if-exists), and CLI (x-management-key header, multiselect import) — all match documented behavior
Workflow Integrity
Check
Result
Action
SHA pinning
✅ Clean
All 77 third-party uses: refs across 20 workflow files pinned to full commit SHAs with trailing # vX.Y.Z/# name@X.Y.Z comments
Least privilege
✅ Clean
Workflow-level permissions: mostly contents: read; elevated scopes (packages: write, id-token: write, issues: write) scoped to the specific jobs that need them. scorecard.yaml's workflow-level read-all is overridden by a minimal job-level block per this repo's own permissions-replacement convention
Fork/secret boundary
✅ Clean
renovate-changesets.yaml (pull_request_target) gates on head.repo.fork == false + actor allowlist before checkout; fro-bot.yaml's comment-triggered job always checks out default branch first and only resolves a trusted head SHA for same-repo PRs
Cross-org secrets: inherit
✅ Clean
No secrets: inherit usage anywhere; the two bfra-me/.github reusable-workflow calls and one reusable action call pass secrets explicitly
Deploy router/approval gates
✅ Intact
deploy.yaml fans out to 7 per-app reusable workflows, each with its own environment: block (keeweb/cliproxy/gateway/umami/vpn/dashboard/broker) gating required-reviewer approval
Quality Gates
Check
Result
Action
Lint
✅ Clean
0 errors, 73 pre-existing warnings (no-console in server/CLI logging code, no-non-null-assertion in test files) — no failures to fix
Type check
✅ Clean
bunx tsc --noEmit — no errors
Tests
✅ Clean
bun test --recursive: 3248 pass, 1 skip, 0 fail across 103 files, 8579 expect() calls
KeeWeb build
✅ Pass
DROPBOX_APP_SECRET=placeholder bun run --cwd apps/keeweb build succeeded; dist/ contains index.html and config.json
Developer Experience
No fixes needed this run — lint/type-check/tests are all clean; no PR opened.
Deploy Pipeline Health
App
Check
Status
Details
keeweb
Last deploy-keeweb run
✅ Pass
run 26855044047 (2026-06-02, last time apps/keeweb/** changed on main)
keeweb
kw.igg.ms reachable
✅ 200
curl HTTP 200
keeweb
Env secrets
✅ Set
DEPLOY_SSH_KEY, DROPBOX_APP_SECRET present in keeweb environment
Stranded-deploy note: gateway, vpn, cliproxy, and dashboard are all parked behind their required_reviewers approval gates with growing unactioned queues (dashboard now 5 versions behind). This is intentional gate behavior, not a bug — existing trackers #1412, #1436, #1437, #1440 were updated in place this run with the latest queue state. No approvals or deploys were performed.
Live Site Review
Check
Status
Details
Page load
✅ OK
HTTP 200; console confirms App started in 1047ms
App init
✅ Rendered
Launcher UI (Open/New/Demo/More) rendered immediately, no stuck spinner
Dropbox option visible
✅ Yes
Collapsed under More by default (expected); visible alongside WebDAV/Google Drive/OneDrive after expanding
Console errors
✅ None
Only benign log/info entries; zero error/warning entries; no requests to Dropbox API endpoints on page load
Service worker
✅ Registered
navigator.serviceWorker.getRegistrations() confirms active registration scoped to https://kw.igg.ms/
Security headers
✅ Present
content-security-policy, x-content-type-options, x-frame-options, strict-transport-security, referrer-policy all present
Mobile layout (375px)
✅ OK
No horizontal overflow (scrollWidth === clientWidth === 375); all controls remained visible/clickable
No issues filed — every check passed on the first pass.
Cross-Project Intelligence (Inbound)
Baseline: @bfra.me/eslint-config@0.54.0, @bfra.me/prettier-config@0.16.13, @bfra.me/tsconfig@0.13.2, fro-bot/agent@v0.117.0. All six focus repos were reachable; none is ahead of infra on @bfra.me config versions or fro-bot/agent (sparkle/gpt/renovate-config match infra's fro-bot/agent@v0.117.0; containers/copiloting are behind).
Repo
Finding
Actionable for infra?
Priority
sparkle
regenerate-docs.yaml auto-detects source changes via path filters, rebuilds generated docs, diffs, and opens a bot PR only when output changed — a tighter, push-triggered mechanism than relying on the daily autoheal's category-3 sweep to catch AGENTS.md drift once a day.
Model a push-triggered, path-filtered workflow around the existing generating-project-docs skill that opens a PR on detected drift.
Low
Checked with nothing actionable: containers (only behind on prettier-config/fro-bot-agent, no transferable tooling), gpt (Vitest/Playwright/Lighthouse don't map — infra has no in-repo frontend UI source), copiloting (all configs well behind infra), .github (no package.json; main.yaml uses an older prettier-action pattern than infra's own flat-config lint setup). Note: infra already runs its own CodeQL (codeql.yaml, javascript-typescript, passing) and Scorecard (scorecard.yaml) workflows, so no gap exists there relative to renovate-config's setup.
Adopt a docs-drift-on-push workflow modeled on sparkle's regenerate-docs.yaml. Evidence: today's category-3 sweep found AGENTS.md accurate, but that's only checked once daily; a path-filtered, diff-gated PR workflow (see Cross-Project Intelligence above) would catch drift the moment a relevant path changes rather than up to 24h later. Effort/risk: Low — additive workflow, PR-only, no impact on existing gates. Adoption path: wire the existing generating-project-docs skill into a new push-triggered workflow scoped to apps/**/AGENTS.md-adjacent paths.
Outcome: Give AGENTS.md drift detection push-triggered coverage instead of waiting for the next daily autoheal cycle. Evidence:marcusrbrown/sparkle's regenerate-docs.yaml (path-filtered rebuild + diff + bot PR); this repo's existing .agents/skills/generating-project-docs skill already contains the regeneration logic. Paths/surfaces: new .github/workflows/*.yaml, .agents/skills/generating-project-docs/. Safety constraints: PR-only output, never a direct push to main. Verification target: touching a documented path with no actual structural change produces a no-op run (no PR opened); touching it with a real structural change produces exactly one draft PR with the corrected doc.
Daily Autohealing Report — 2026-09-29 (UTC)
Errored PRs
None. Only one open PR (#1449,
changeset-release/main, authored bymrbro-bot[bot]) exists and all its checks (Lint, Type Check, Test, Package smoke, CodeQL, Renovate) are passing.Security
None.
gh api repos/marcusrbrown/infra/dependabot/alertsreturned HTTP 200 with zero open alerts. No security-labeled or vulnerable-dependency PRs are open.Code Quality & Repo Hygiene
packages/cli/src/conventions.test.ts, both passingapps/*andpackages/*directories match root AGENTS.md STRUCTURE; per-package AGENTS.md command trees match actual source layoutWORKSPACE_PERMISSION_POLICY,REQUIRED_ENV_VARS, egress host allowlist), dashboard (compose hardening block), cliproxy (config.yaml skip-if-exists), and CLI (x-management-keyheader,multiselectimport) — all match documented behaviorWorkflow Integrity
uses:refs across 20 workflow files pinned to full commit SHAs with trailing# vX.Y.Z/# name@X.Y.Zcommentspermissions:mostlycontents: read; elevated scopes (packages: write,id-token: write,issues: write) scoped to the specific jobs that need them.scorecard.yaml's workflow-levelread-allis overridden by a minimal job-level block per this repo's own permissions-replacement conventionrenovate-changesets.yaml(pull_request_target) gates onhead.repo.fork == false+ actor allowlist before checkout;fro-bot.yaml's comment-triggered job always checks out default branch first and only resolves a trusted head SHA for same-repo PRssecrets: inheritsecrets: inheritusage anywhere; the twobfra-me/.githubreusable-workflow calls and one reusable action call pass secrets explicitlydeploy.yamlfans out to 7 per-app reusable workflows, each with its ownenvironment:block (keeweb/cliproxy/gateway/umami/vpn/dashboard/broker) gating required-reviewer approvalQuality Gates
no-consolein server/CLI logging code,no-non-null-assertionin test files) — no failures to fixbunx tsc --noEmit— no errorsbun test --recursive: 3248 pass, 1 skip, 0 fail across 103 files, 8579 expect() callsDROPBOX_APP_SECRET=placeholder bun run --cwd apps/keeweb buildsucceeded;dist/containsindex.htmlandconfig.jsonDeveloper Experience
Deploy Pipeline Health
apps/keeweb/**changed on main)curlHTTP 200DEPLOY_SSH_KEY,DROPBOX_APP_SECRETpresent inkeewebenvironmentbox.heatvision.coed25519/ecdsa/rsa entries presentwaiting~5d; 3 intermediate bumps auto-cancelled; newest 36306810708 (v7.3.20)pending. Prod still on v7.3.15CLIPROXY_SSH_KEY,CLIPROXY_MANAGEMENT_KEY,CLIPROXY_DOMAINpresentcliproxy.fro.botdomain + droplet-IP entries presentprobe=healthy reason=ok. No stalecliproxy-auth-monitorissue open (both prior instances closed)waiting~4d7h; newest 36480447585pendingbehind it. Prod still on run 35648619590GATEWAY_SSH_KEY,GATEWAY_HOST,DISCORD_*,AWS_*,S3_*) plus operator-auth/push secretsgateway.fro.botdomain + droplet-IP entries presentdeploy-umamisuccess)curlHTTP 200 on/api/heartbeatUMAMI_SSH_KEY,UMAMI_DOMAIN,UMAMI_APP_SECRET,UMAMI_DB_PASSWORD,UMAMI_ADMIN_PASSWORDpresentmetrics.fro.botdomain + droplet-IP entries presentwaiting) through 2026.09.24 (pending, newest) never reachedsuccess(3 intermediate cancelled)curlHTTP 200dashboard.fro.botdomain + droplet-IP entries presentVPN_SSH_KEY,VPN_HOST,VPN_PEERSpresent52.208.116.13presentdeploy-brokersuccess)curlHTTP 200BROKER_SSH_KEY,BROKER_HOST,CLIPROXY_MANAGEMENT_KEYsecrets +BROKER_AUDvariable presentbroker.fro.botdomain + droplet-IP entries presentStranded-deploy note: gateway, vpn, cliproxy, and dashboard are all parked behind their
required_reviewersapproval gates with growing unactioned queues (dashboard now 5 versions behind). This is intentional gate behavior, not a bug — existing trackers #1412, #1436, #1437, #1440 were updated in place this run with the latest queue state. No approvals or deploys were performed.Live Site Review
App started in 1047msMoreby default (expected); visible alongside WebDAV/Google Drive/OneDrive after expandingnavigator.serviceWorker.getRegistrations()confirms active registration scoped tohttps://kw.igg.ms/content-security-policy,x-content-type-options,x-frame-options,strict-transport-security,referrer-policyall presentscrollWidth === clientWidth === 375); all controls remained visible/clickableNo issues filed — every check passed on the first pass.
Cross-Project Intelligence (Inbound)
Baseline:
@bfra.me/eslint-config@0.54.0,@bfra.me/prettier-config@0.16.13,@bfra.me/tsconfig@0.13.2,fro-bot/agent@v0.117.0. All six focus repos were reachable; none is ahead of infra on@bfra.meconfig versions orfro-bot/agent(sparkle/gpt/renovate-config match infra'sfro-bot/agent@v0.117.0; containers/copiloting are behind).regenerate-docs.yamlauto-detects source changes via path filters, rebuilds generated docs, diffs, and opens a bot PR only when output changed — a tighter, push-triggered mechanism than relying on the daily autoheal's category-3 sweep to catch AGENTS.md drift once a day.generating-project-docsskill that opens a PR on detected drift.Checked with nothing actionable:
containers(only behind on prettier-config/fro-bot-agent, no transferable tooling),gpt(Vitest/Playwright/Lighthouse don't map — infra has no in-repo frontend UI source),copiloting(all configs well behind infra),.github(no package.json;main.yamluses an older prettier-action pattern than infra's own flat-config lint setup). Note: infra already runs its own CodeQL (codeql.yaml,javascript-typescript, passing) and Scorecard (scorecard.yaml) workflows, so no gap exists there relative torenovate-config's setup.Progressive Improvement
.github/workflows/deploy-*.yaml, which is outside this run's write scope (workflow files are report-only for autoheal). Adoption path: a human-directed follow-up PR adding a scheduled check that pings Discord/opens-once when awaitingdeploy run exceeds e.g. 48h, without touching the approval gate itself.sparkle'sregenerate-docs.yaml. Evidence: today's category-3 sweep found AGENTS.md accurate, but that's only checked once daily; a path-filtered, diff-gated PR workflow (see Cross-Project Intelligence above) would catch drift the moment a relevant path changes rather than up to 24h later. Effort/risk: Low — additive workflow, PR-only, no impact on existing gates. Adoption path: wire the existinggenerating-project-docsskill into a new push-triggered workflow scoped toapps/**/AGENTS.md-adjacent paths.Agent-Ready Notes
.github/workflows/deploy-*.yaml,.github/workflows/deploy.yaml(environment approval blocks). Safety constraints: must never auto-approve or bypassrequired_reviewers; notification-only. Verification target: a synthetic queued run older than the chosen threshold produces exactly one deduped notification and zero approval/deploy side effects.marcusrbrown/sparkle'sregenerate-docs.yaml(path-filtered rebuild + diff + bot PR); this repo's existing.agents/skills/generating-project-docsskill already contains the regeneration logic. Paths/surfaces: new.github/workflows/*.yaml,.agents/skills/generating-project-docs/. Safety constraints: PR-only output, never a direct push to main. Verification target: touching a documented path with no actual structural change produces a no-op run (no PR opened); touching it with a real structural change produces exactly one draft PR with the corrected doc.Needs Human Attention