ci / bun-nix (pull_request) Successful in 35s
ci / docs-drift (pull_request) Successful in 35s
ci / docs-site (pull_request) Successful in 1m18s
ci / web (pull_request) Successful in 1m42s
apple / swift (pull_request) Successful in 2m16s
apple / distribute (pull_request) Skipped
apple / screenshots (pull_request) Skipped
ci / rust-arm64 (pull_request) Successful in 6m46s
ci / rust (pull_request) Failing after 4m25s
android / android (pull_request) Canceled after 9m18s
nix / flake (pull_request) Canceled after 6m51s
windows-client / client (arm64, --no-default-features, aarch64-pc-windows-msvc, C:\t-a64) (pull_request) Successful in 2m56s
windows-client / client (x64, , x86_64-pc-windows-msvc, C:\t) (pull_request) Canceled after 1s
Security review 2026-08-25, 58 confirmed findings across host, console, clients and supply chain. Nearly every serious one is a documented boundary whose code stopped enforcing what its comment promised — so where the two disagreed, the comment won and the code was made to match, and where it could not be, the comment was corrected instead. Critical — a console session cookie alone reached code execution: every pairing route rode the generic catch-all with the operator's admin bearer attached. Arming, approving and PIN submission now sit behind the console password like the other trust-root routes, and the armed PIN is returned once in that gated response instead of riding a 1 s status poll. High — the plugin lane no longer reads the unredacted log ring (which carried the webhook credentials the /hooks carve-out exists to withhold); hook lines log an origin and a short id, never a URL or a command line; a plugin-reported pid is held to procscan's start-time floor before the SYSTEM host will signal it; ClipOffer is gated on the live grant mask, so a revoked guest loses the host clipboard in both directions; ENet refuses connects with no live launch instead of letting LAN peers squat all four slots; Windows secrets are born with their DACL applied rather than world-readable; the sysext feed binds FEED and a monotonic SERIAL inside the signed bytes; privileged_field allowlists the host-resolved launch kinds so a new kind is privileged by default; five parser panics reachable from one malformed NALU are range-checked; release-signing jobs pin bun, sccache and actions by checksum/SHA; h2 -> 0.4.19 (RUSTSEC-2026-0258). Deep links only auto-dial by stable record id now — a display name or an address gets a confirmation on every client. The Apple identity key moves to ThisDeviceOnly so it stops riding encrypted backups. pf-vdisplay stops routing session identity through the process environment: the injector backend threads through a typed slot, so per-batch getenv no longer races a per-session setenv. The four remaining writes have no in-repo readers and are documented as such; the SAFETY proof that claimed ENV_LOCK made them sound is gone. Verified: cargo clippy --workspace --all-targets --locked -D warnings and cargo fmt --all --check clean in the CI image; web builds, tsc --noEmit clean, 22/22 server tests; Swift debug+release + 26/26, Kotlin :kit 7/7. Not fixed, deliberately: the plugin token can still mint command execution (the plugin launch kind exists so a plugin names a command the host runs — per-plugin identity does not change that, and the runner is one process hosting fibers, so there is nowhere to hang a credential); the shared plugin-UI origin; the rollback Authenticode publisher pin (Azure mints a fresh leaf per request, and the signer subject is not in the tree). Each is now described accurately where it lives instead of being claimed closed.