Skip to content

fix: dependency bumps, shell hardening, gap closures, README cleanup - #28

Merged
amar-python merged 3 commits into
mainfrom
claude/csv-loading-postgres-migration-qvkl4l
Jul 28, 2026
Merged

fix: dependency bumps, shell hardening, gap closures, README cleanup#28
amar-python merged 3 commits into
mainfrom
claude/csv-loading-postgres-migration-qvkl4l

Conversation

@amar-python

Copy link
Copy Markdown
Owner

No description provided.

claude and others added 3 commits July 28, 2026 13:55
Dependencies (supersedes dependabot PRs #16-#20, #25, #26):
- actions/checkout v4 → v7, actions/upload-artifact v4 → v7
- flake8 >=7.3.0, bandit >=1.9.4, pytest-cov >=7.1.0
- fastapi >=0.140.0, uvicorn >=0.51.0

Documentation:
- VCRM.md: mark BR-15 as verified (S09/S10 assertions exist),
  update coverage from 77% to 82% (18/22)
- GAP_ANALYSIS.md: close G5 (142 assertion count confirmed correct)

Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
Shell hardening:
- Replace unsafe `eval echo "$VAR"` with bash indirect expansion
  `${!var}` in csv_utilise.sh, loader_postgresql.sh, adapter_postgresql.sh,
  setup.sh (eliminates command injection via crafted env names)
- Add --env validation (dev|test|staging|prod) to csv_loader.sh,
  csv_utilise.sh, and loader_postgresql.sh

README:
- Remove 125 lines of stale session prompts referencing a different
  repo (amar-python/TestUploadtoGIT)

Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
@amar-python
amar-python merged commit 90d1707 into main Jul 28, 2026
3 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants