Skip to program ledger

Living Program Ledger

Frauthy/Project Management

v37 · 2026-07-28

Immutable ingestion receipt

Version 33

This receipt records what the digest claimed at ingestion time. Current health appears only on the current overview.
v33 · · archived

Authenticated workspace installs and gated Site delivery

Source
Ledger event v33
01

Recorded changes

root

status → amber

ci → green (exact-head Root CI run 29693816352: 23 tests, 86 assertions, CLI bundle, lifecycle dry-runs, and port-registry gate)

Root master 7818e29 makes `frauthy deps` inspect selected repo npm credentials, preserve explicit `NODE_AUTH_TOKEN`/`GITHUB_TOKEN`, derive one ephemeral fallback from the authenticated GitHub CLI, and fail before the first repo mutates when credentials are unavailable.

Sequential and parallel repo runners now own detached process groups. SIGINT/SIGTERM reaps the runner and descendant installers/watchers with a bounded forced fallback; regression evidence includes token non-disclosure, fail-before-runner, and a synthetic descendant-reaping test.

This hardening does not close a numbered Root gap; ROOT-1, ROOT-8, ROOT-12, and ROOT-13 remain open.

site

status → green

ci → green (exact-head Site CI run 29694028372: frozen install, UI SDK build, 11 unit tests, LCOV ratchet, Astro/ESLint, static build, browser smoke, accessibility, and Lighthouse budgets)

deploy → Manual Cloudflare Pages production/preview workflow is ready for an existing `frauthy-site` project; no deployment was performed

Closed: SITE-9

Site master 620c6a7 adds a `workflow_dispatch`-only, GitHub-environment-scoped delivery path that fails closed on missing Cloudflare credentials, retains an immutable `site-dist-<commit-sha>` artifact, publishes only `dist/`, and verifies the returned URL plus the canonical `https://frauthy.dev` sitemap.

The workflow cannot create Cloudflare projects, accounts, DNS, domains, or secrets. Resource provisioning remains owned by Infrastructure; the Site workflow only uploads an application artifact to a pre-provisioned Pages project.

Rollback promotes a prior known-good Pages deployment matched to its retained commit artifact. No Site Actions secrets or Cloudflare deployment environments were present during this burst, so the manual workflow was not dispatched.

Program-wide

Active Root, Site, and Project Management UI checkouts were preserved. The untracked `research/packages/ui/ui` tree and all product UI SDK surfaces were untouched.