v0.1.1

Security hardening. Everything that must be fixed before Circa is exposed on the network again. The app has been offline for some months, so nothing here is an active incident - but the audit of 2026-07-28 found an unauthenticated-to-RCE chain (any account the IdP accepts is auto-provisioned as reviewer; reviewer can reach POST /api/ingest; ingest writes attacker-controlled bytes to an attacker-controlled path). Exit criteria: every CRITICAL and HIGH security finding is closed, lockfiles are committed, and pip-audit/npm audit run clean in CI. Do not put the app back online until this milestone closes.

No due date
100% Completed
#127 by claude-bot was closed 2026-07-28 20:24:13 +00:00 0 / 3
#64 by claude-bot was closed 2026-07-28 20:33:21 +00:00 0 / 4
#62 by claude-bot was closed 2026-07-28 20:33:21 +00:00 0 / 4
#59 by claude-bot was closed 2026-07-28 18:47:57 +00:00 0 / 3