Skip to content

Upgrade to Sub2API v0.2.13 and harden verified build dependencies - #62

Merged
XiaoSiKe merged 14 commits into
mainfrom
codex/upgrade-v0.2.13
Oct 3, 2026
Merged

XiaoSiKe merged 14 commits into
mainfrom
codex/upgrade-v0.2.13

Conversation

@XiaoSiKe

@XiaoSiKe XiaoSiKe commented Oct 3, 2026 •

Copy link
Copy Markdown
Owner

This upgrades the fixed Sub2API baseline from v0.2.12 to v0.2.13 while preserving Zero One contracts and the approved production UI.

A request whose API Key is deleted before settlement now still bills the user transactionally; only the missing key counters are skipped, and genuine database errors still fail. TypeSafe API Key account creation accepts the default upstream billing probe setting, with official endpoints retaining the unsupported/no-request policy. Existing account-cost snapshots, financial records, authorization and monitor ownership remain intact. There are no new migrations.

The build toolchain also mitigates newly reviewed GHSA-vfj7-8cjw-p6xm with a locked pnpm braces depth patch, adversarial/normal caller regressions and a security-CI prerequisite. The exact advisory exception expires on 2026-10-17 because no upstream fix is published; the raw audit still reports the package version. Landing Vitest moves to 4.1.11 to remove its mocker advisory. Both Docker builders install the patch before frozen dependencies; the deployment builder heap cap becomes 3 GiB after reproducing typecheck OOM at 1.5 GiB.

Baseline/provenance, current operations docs and the deterministic seven-path change map are updated. Nineteen reviewed screenshots differ only inside the version badge; historical production assets stay byte-identical. The approved UI tag fixes the final source/snapshot set.

Validation:

  • Complete make test: ordinary/unit/integration Go suites, zero lint issues, 308 Console files / 2,255 tests, and 18 Landing files / 134 tests.
  • Optional critical diagnostics: all 20 paths exist and 266 tests pass after removing seven stale references.
  • 135 release-policy tests, 33 adapter/tool tests, upgrade readiness and UI/upstream boundaries pass.
  • Source builds, all frozen Console generators, locked patch installation, Docker frontend build, release/storage/cleanup/Compose/context/routing/edge checks pass.
  • Full Chromium on the final hosted commit: 290 passed / 78 conditional skips, with no failures. The 19 reviewed snapshot changes contain zero changed pixels outside the version badge.
  • Go audit: no reachable vulnerabilities; Landing audit: zero advisories; Console audit: the exact tested mitigation above.

Production deployment requires successful exact-main product/security evidence, paired same-SHA multi-architecture images, a fresh encrypted off-host restore/rehearsal, unchanged migration ledger and business-column fingerprints, Backend-first cutover with watchdog, dedicated model probes and at least 30 minutes of observation. Recovery data and credentials remain outside Git.

github-actions Bot and others added 14 commits October 2, 2026 06:45
The create form shows the upstream billing auto-probe toggle for every
API-key platform and enables it by default. TypeSafe was added as an
API-key platform but not to IsUpstreamBillingProbeIdentity, so creating a
TypeSafe account with the default form state fails with
400 UPSTREAM_BILLING_PROBE_ACCOUNT_INVALID ("account is not an API key
account").

TypeSafe accounts store credentials.api_key/base_url like every other
API-key platform, which is all the probe reads. Add TypeSafe to the probe
identity set, and add typesafe.ai to the official API domains so accounts
on the default https://api.typesafe.ai base URL record "unsupported"
without sending the key to a path that cannot exist, matching the other
official providers.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
docs: add security policy with private vulnerability reporting
… completes

When an API key with quota or rate limits was deleted while a request was
still in flight, the key counter update matched no rows and returned
ErrAPIKeyNotFound, rolling back the whole billing transaction including the
balance/subscription charge. Skip the key-scoped counters in that case and
keep settling the user and account side as usual.
fix(billing): settle usage when the API key is deleted before billing completes
…ng-probe

fix(billing): allow upstream billing probe for TypeSafe API-key accounts
@XiaoSiKe
XiaoSiKe merged commit 973bd8a into main Oct 3, 2026
12 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants