Document the dependency-locking migration and the alert outcome Quality-and-Testing gains a section on why the Python supply chain was invisible: GitHub builds its dependency graph from manifest files, so a hand-written list of 16 direct pins left 183 of 201 installed packages untracked. The lockfiles fix that, at the cost of two traps that only appear in a clean container. Also records the sequence 0 -> 6 -> 14 -> 0 as each layer became visible, the evidence that the vite 5->8 upgrade changed nothing observable (byte-identical stylesheet), and the chromadb risk acceptance with the reasoning for it.
Document the security review Quality-and-Testing records the full CodeQL outcome: 22 findings, all resolved, grouped by rule with the fix for each, and an explicit note that the 14 dismissals are false positives caused by an unmodelled sanitiser rather than suppressed risk - with the model pack that will clear them once published. Test counts updated to 382, with the regression module now 15 classes / 58 tests. The scheduled-snapshot emission fix and the execution-precondition guard are covered on the same page.
Document the defects found by this review The wiki review found nine defects the test suite could not see. Each page that described the old behaviour is corrected, and the pages that documented the defects as open gaps now document the fixes: - Real-Time-Layer: the four event-path gaps (snapshot payload, unreachable offline state, dropped greeting, missing autonomy broadcast) are now a "defects and fixes" table rather than a known-gaps list. - Data-Model: documents link_code_issued_at and why the link code expiry needed a new column to be enforceable at all. - API-Reference: run-agent is caller-scoped with a truthful 429; snapshots no longer 500 on a malformed limit; the webhook fails closed. - Operations: scoped debounce keys, dispatch_market_sweep, last-use token purge. - Telegram-Bot, Configuration: corrected three claims that the fixes made false. - Quality-and-Testing: 359 tests, with the new regression module documented. - Incident-Log: a closing note that a documentation pass found eight more.
Rewrite the wiki as full engineering documentation Replaces the default stub with 16 pages covering architecture, the agent debate, the execution guard, the data model, the real-time layer, the API, the MCP tool server, the Telegram bot, configuration, operations, quality and testing, engineering decisions, an incident log and the roadmap. Adds a custom _Sidebar for navigation between all of them. INC-003 documents the WebSocket flap with a reproduced root cause: redis-py 8.1.0's implicit DEFAULT_SOCKET_TIMEOUT of 5s is identical to channels_redis's brpop_timeout of 5s, so the read deadline races the blocking window. Measured 4/4 failures at the old value and 4/4 clean at the shipped value.