fix: close kimi security acceptance gaps #12
Loading…
Add table
Add a link
Reference in a new issue
No description provided.
Delete branch "fix/security-kimi-completion"
Deleting a branch is permanent. Although the deleted branch may continue to exist for a short time before it actually gets removed, it CANNOT be undone in most cases. Continue?
Closes the remaining finish2-kimi3.md acceptance gaps.\n\nChanges:\n- Fix JMAP session accountCapabilities to include core/mail/vendor capabilities.\n- Add standard Email/query total and limit fields with unit, dispatcher, and golden fixture coverage.\n- Harden HTTP Content-Length parsing to strict decimal and fix streaming file-slice TLS writes.\n- Expand TLS renewal/SPKI pin rotation FreeBSD deployment docs.\n- Make make verify match Kimi acceptance by including e2e, audit, SBOM, and fuzz evidence.\n- Vendor the fuzz dependency closure and pin jsqlite fetch metadata.\n- Bump VERSION and synchronized package/app/native versions to 0.2.3.\n\nVerification:\n- jerboa_check_balance on all changed .ss files: OK.\n- jerboa_verify on changed production .ss files: OK.\n- jerboa_security_scan on lib/jjmap/session.ss, lib/jjmap/email.ss, lib/jjmap/http.ss, lib/jjmap/main.ss: no findings after documented CLI-only suppressions.\n- make test: PASS.\n- make verify: PASS, including security-gates, unit tests, Rust native tests, Android native tests, binary build, e2e, cargo audit, SBOM, and fuzz evidence.\n- env -i PATH=... ./jjmapd version: jjmapd 0.2.3.