Final pre-release read-through of the whole codebase for correctness, security, and
consistency before a production release.
Scope (checklist)
Security: credential/token storage (data/security/*), TLS/STARTTLS enforcement,
WebView hardening (reader), Outlook OAuth flow, the opt-in SQLCipher path.
Correctness: sync/IDLE concurrency, outbox retry, Room migrations (schemas), error
handling.
Privacy: no PII/tokens in release logs; debug-pipeline data flow (#10/#11).
Consistency: SPDX headers on every file, ktlint/detekt clean, dependency licenses
GPL-compatible.
Run /security-review and /code-review (or ultra) over the release branch; triage
findings.
Acceptance criteria
A documented audit pass with findings triaged (fixed or ticketed); lint + tests clean.
Dependencies
Run after feature work lands; gates store compliance (#16/#17/#18) and release (#19).
## Context
Final pre-release read-through of the whole codebase for correctness, security, and
consistency before a production release.
## Scope (checklist)
- [ ] **Security:** credential/token storage (`data/security/*`), TLS/STARTTLS enforcement,
WebView hardening (reader), Outlook OAuth flow, the opt-in SQLCipher path.
- [ ] **Correctness:** sync/IDLE concurrency, outbox retry, Room migrations (schemas), error
handling.
- [ ] **Privacy:** no PII/tokens in release logs; debug-pipeline data flow (#10/#11).
- [ ] **Consistency:** SPDX headers on every file, ktlint/detekt clean, dependency licenses
GPL-compatible.
- [ ] Run `/security-review` and `/code-review` (or ultra) over the release branch; triage
findings.
## Acceptance criteria
- A documented audit pass with findings triaged (fixed or ticketed); lint + tests clean.
## Dependencies
Run after feature work lands; gates store compliance (#16/#17/#18) and release (#19).
Blocking a user prevents them from interacting with repositories, such as opening or commenting on pull requests or issues. Learn more about blocking a user.
Context
Final pre-release read-through of the whole codebase for correctness, security, and
consistency before a production release.
Scope (checklist)
data/security/*), TLS/STARTTLS enforcement,WebView hardening (reader), Outlook OAuth flow, the opt-in SQLCipher path.
handling.
GPL-compatible.
/security-reviewand/code-review(or ultra) over the release branch; triagefindings.
Acceptance criteria
Dependencies
Run after feature work lands; gates store compliance (#16/#17/#18) and release (#19).