Skip to content

Conversation

@tukuaiai
Copy link
Owner

变更摘要

  • docs(security): 添加信号引擎安全审计报告

    • signal_audit_full.md: 完整代码与安全审计
    • signal_audit_pg.md: PG 引擎专项审计
    • spec_security_dual_audit_template.md: 双重审计模板
  • refactor(vis): 移除废弃的 VPVR 可视化模板

    • 删除 vpvr-zone-dotvpvr-zone-grid(已被 vpvr-zone-strip 替代)
    • 减少 232 行冗余代码
  • chore(i18n): 同步编译翻译文件

测试方式

  • 审计文档为纯文档,无需测试
  • vis-service 模板删除后,剩余模板功能不受影响(vpvr-zone-strip 仍可用)
  • i18n 文件为编译产物,源 .po 文件已验证

风险评估

低风险

  • 审计文档仅记录发现,不改变运行时行为
  • 删除的模板未被生产使用
  • i18n 编译文件与源文件同步

- Add full code and security audit report (signal_audit_full.md)
- Add PG engine specific audit report (signal_audit_pg.md)
- Add dual audit template for future security reviews

Key findings documented:
- SQL injection risk in PG symbol queries (High)
- Event loop threading issues in signal push (Medium)
- History DB permission and cleanup concerns (Medium)
…plates

Remove 232 lines of unused VPVR visualization templates:
- vpvr-zone-dot: value area dot matrix chart
- vpvr-zone-grid: multi-card grid layout

These templates were superseded by vpvr-zone-strip which provides
better visualization with less complexity.
Regenerate .mo files to sync with latest .po translations.
@tukuaiai tukuaiai merged commit 0536a43 into main Jan 10, 2026
1 of 2 checks passed
@tukuaiai tukuaiai deleted the chore/cleanup-and-audit-docs-20260110 branch January 10, 2026 13:24
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants