Skip to content

docs: OpenStream benchmark report for nixamp 0.24.2 - #184

Merged
ralyodio merged 1 commit into
masterfrom
openstream-report-2026-09-13-nixamp-0.24.2-synthetic
Sep 13, 2026
Merged

ralyodio merged 1 commit into
masterfrom
openstream-report-2026-09-13-nixamp-0.24.2-synthetic

Conversation

@ralyodio

Copy link
Copy Markdown
Contributor

Manual publish of the OpenStream benchmark report attached to the nixamp v0.24.2 release (https://github.com/profullstack/nixamp/releases/tag/v0.24.2). The release run's "Publish the benchmark report to LogicSRC" job (https://github.com/profullstack/nixamp/actions/runs/34750297069) skipped every step because LOGICSRC_PUBLISH_TOKEN is not configured on profullstack/nixamp.

The run used the built-in synthetic corpus on the release runner, so the id carries the -synthetic label per docs/openstream/reports/README.md. Round-trip exactness gated the release.

🤖 Generated with Claude Code

https://claude.ai/code/session_015uheT4Gn9BBKAnSZGcabyN

Manual publish of the report attached to the nixamp v0.24.2 release
(openstream-report-0.24.2.json/.md). The release workflow's
publish-report job skipped because LOGICSRC_PUBLISH_TOKEN is not set
on profullstack/nixamp. Built-in synthetic corpus, so the id carries
the -synthetic label per docs/openstream/reports/README.md.

Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_015uheT4Gn9BBKAnSZGcabyN
@github-actions

Copy link
Copy Markdown

ThreatCrush Security Scan

22 finding(s)

HIGH/CRITICAL: 3 | MEDIUM: 10 | LOW: 9

Severity Rule Location
HIGH secret-private-key plugins/credential-sharing/src/providers/ssh.ts:129
HIGH js-host-header-trust apps/commandboard-web/server.js:27
HIGH js-ssrf-outbound-request apps/pwa/public/sw.js:45
MEDIUM js-unescaped-html-sink apps/commandboard-web/src/main.ts:19
MEDIUM js-unescaped-html-sink apps/logicsrc-web/src/app/[[...slug]]/page.tsx:71
MEDIUM js-unescaped-html-sink apps/logicsrc-web/src/app/layout.tsx:88
MEDIUM js-unescaped-html-sink apps/logicsrc-web/src/app/pricing/page.tsx:46
MEDIUM js-unescaped-html-sink apps/logicsrc-web/src/components/breadcrumbs.tsx:43
MEDIUM js-unescaped-html-sink apps/logicsrc-web/src/components/site-shell.tsx:34
MEDIUM redos-nested-quantifier packages/opencontext/src/ids.ts:10
MEDIUM redos-nested-quantifier packages/opencontext/src/ids.ts:11
MEDIUM js-timing-unsafe-mac-compare packages/opencontext/src/validate.ts:208
MEDIUM redos-nested-quantifier packages/openontology/src/ids.ts:20
LOW secret-generic-credential apps/pwa/test/appbar.test.mjs:10
LOW secret-aws-access-key packages/opencontext/src/permissions.test.ts:260
LOW secret-private-key packages/opencontext/src/permissions.test.ts:261
LOW secret-stripe-key packages/opencontext/src/permissions.test.ts:262
LOW secret-aws-access-key packages/opencontext/src/security.test.ts:228
LOW secret-private-key plugins/credential-sharing/src/providers/ssh.test.ts:7
LOW secret-database-url plugins/credential-sharing/src/rekey.test.ts:33
LOW secret-openai-key plugins/credential-sharing/src/vault-encryption.test.ts:21
LOW secret-generic-credential plugins/credential-sharing/src/vault-encryption.test.ts:21

Snippets are redacted; ThreatCrush never prints matched credential material.

@ralyodio
ralyodio merged commit fd25e8e into master Sep 13, 2026
6 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant