* ops: deploy app.logicsrc.com to dev2 on merge
Railway deployed this on push; dev2 does not by itself. The workflow ssh's
to the box and runs /home/anthony/www/app.logicsrc.com/deploy-app.sh, which builds
the image from this checkout and restarts the compose stack. Generated by
cli-tools dev2/dev2-site scaffold.
Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
* ops: stop committing the nixpacks build plan
`railway up` writes .nixpacks/ into the working tree: a Dockerfile, a
nixpkgs pin, and a build.sh that hard-codes the absolute path of the
worktree it ran in plus a one-off image tag. None of it is reusable and
no workflow reads it, so every branch that deploys regenerates it and
conflicts with the last one -- which is exactly how this branch ended up
CONFLICTING against master.
Drop it and ignore it.
* ops: drop the nixpacks build plan master picked up in #215
Same detritus, same stale absolute path (a worktree that no longer
exists). Now ignored, so it will not come back.
---------
Co-authored-by: Claude Fable 5.1 <noreply@anthropic.com>
Railway deployed this on push; dev2 does not by itself. The workflow ssh's
to the box and runs /home/anthony/www/logicsrc.com/deploy-app.sh, which builds
the image from this checkout and restarts the compose stack. Generated by
cli-tools dev2/dev2-site scaffold.
Co-authored-by: Claude Fable 5.1 <noreply@anthropic.com>
vu1nz reviews a diff by calling Claude, which needs ANTHROPIC_API_KEY
supplied through the ENV_FILE secret. That key is not present on this
repository, so the scanner has never reviewed a pull request. On pack
1.0.0 and 1.0.1 that failure was silent: the job reported "0 finding(s),
no high/critical issues" on a diff nothing had read, which is worse than
no scanner at all.
threatcrush-scan covers the same ground deterministically - credentials,
injection, SSRF, unsafe deserialisation, XXE, dependency tampering - with
no API key and no per-pull-request cost.
Reinstallable from the sh1pt Actions Store if the key is ever provisioned.
Co-authored-by: Claude Opus 5 <noreply@anthropic.com>
Installs threatcrush-scan@1.1.0 from the sh1pt Actions Store.
Scans pull requests for hardcoded credentials, injection, SSRF, unsafe
deserialisation and dependency tampering; uploads SARIF to the Security
tab.
Report-only — it will not fail a pull request. Set the pack's failOn
input to critical,high once the existing findings are triaged.
Co-authored-by: Claude Opus 5 (1M context) <noreply@anthropic.com>
The 'test' workflow ran 'npm test' without building, so dependents could not
resolve @logicsrc/plugin-core / @logicsrc/validators (they publish from dist/).
Build first. Also document PUBLIC_URL (canonical site URL) in .env.example.
Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>