Skip to content

Prepare secure v0.1.0 release - #18

Merged
jiangsir-tech merged 2 commits into
mainfrom
agent/share-ready-v0.1.0
Aug 1, 2026
Merged

jiangsir-tech merged 2 commits into
mainfrom
agent/share-ready-v0.1.0

Conversation

@jiangsir-tech

@jiangsir-tech jiangsir-tech commented Aug 1, 2026 •

Copy link
Copy Markdown
Owner

Summary

  • close the three validated low-severity notification privacy findings
  • enforce HTTPS Bark endpoints and exact Device Key redaction at the final payload boundary
  • harden install, update, uninstall, rollback, and stale lifecycle-lock recovery
  • replace the Device Key screenshot with a fully synthetic example
  • align README, installation, security, changelog, and release documentation

Verification

  • npm run test:all: 129 passed, 0 failed
  • aggregate coverage: 86.04% lines, 78.35% branches, 85.47% functions
  • sh scripts/install.sh --verify: passed on Node.js 24.18.0
  • current local installation updated without changing config, Hooks, or the saved Device Key
  • current text and asset scans found no complete Bark endpoint key or local username
  • independent code review found no remaining P0-P2 issues

Release decision

The owner explicitly waived independent-user validation for v0.1.0 and accepted the risk of fixing real-world issues in follow-up releases. Release notes must disclose that no independent macOS plus Bark user completed the install and uninstall flow before publication. The immutable release archive will still be downloaded and retested before the GitHub Release is published.

@jiangsir-tech

Copy link
Copy Markdown
Owner Author

独立用户验收入口

正式 v0.1.0 Tag 尚未创建。请只测试这个不可变候选 commit:

https://github.com/jiangsir-tech/codex-bark-notifier/tree/fca0eefa52becaabd8a702956916bdf8ddb92ea6

把下面内容复制给 Mac 上的 Codex 本地任务,并把最后一行换成测试者自己的 Bark Device Key:


请直接在这台 Mac 上安装、验证并随后安全卸载 Codex Bark Notifier 候选版本,不要只给操作说明。只使用上面的固定 commit,不要改用 main,也不要使用尚不存在的 v0.1.0 Tag。

先阅读该 commit 中的 README、SECURITY、安装指南和安装器帮助。运行完整 verify 和 dry-run,确认不覆盖原有 notify 或其他 Hooks;再通过交互式隐藏输入把 Device Key 交给安装器,不要在命令、日志或回复里显示。安装后只发送一条测试通知,由我确认 iPhone 是否收到;再引导我在 Codex CLI 的 /hooks 中人工核对 PermissionRequest Hook,不得自动信任或批准。

确认安装工作后,运行默认的可恢复卸载,不得使用 purge。核对原有 notify、其他 Hooks 和后来配置都保留或恢复,私有 Key、公开配置、日志和备份按设计保留。最后报告 macOS、Codex/ChatGPT、Node.js 来源与版本、测试数量、安装与卸载结果、手机实收结果、Hook 状态和任何异常。不要提交或推送仓库。

我的 Bark Device Key:
<粘贴测试者自己的 Device Key>


验收通过后,再将 PR 转为 Ready、合并并创建不可移动的 v0.1.0 Tag/Release。

@jiangsir-tech
jiangsir-tech marked this pull request as ready for review August 1, 2026 11:52
@jiangsir-tech
jiangsir-tech merged commit a514ef8 into main Aug 1, 2026
8 checks passed
@jiangsir-tech
jiangsir-tech deleted the agent/share-ready-v0.1.0 branch August 1, 2026 11:53
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant