Skip to content

Security

April 14: Hardening Spree

Thirteen-PR security and correctness blitz — auth rate limiting, account lockout, user enumeration prevention, data enumeration prevention across analysis and composite endpoints, NaN and empty-input guards across the processing pipeline, and a handful of race-condition and validation bugs.

April 4: Security Foundations

Heavy security-infrastructure day — added the .NET exception hierarchy with centralized error middleware, security headers middleware on the gateway, gitleaks secret scanning in pre-commit and CI, plus the Claude Code GitHub workflow, a narrowed exception swallow in FITS save, and a full dependabot drop.