v0.1.1
Security hardening. Everything that must be fixed before Circa is exposed on the network again. The app has been offline for some months, so nothing here is an active incident - but the audit of 2026-07-28 found an unauthenticated-to-RCE chain (any account the IdP accepts is auto-provisioned as reviewer; reviewer can reach POST /api/ingest; ingest writes attacker-controlled bytes to an attacker-controlled path). Exit criteria: every CRITICAL and HIGH security finding is closed, lockfiles are committed, and pip-audit/npm audit run clean in CI. Do not put the app back online until this milestone closes.
No due date
100% Completed