Skip to content

Phase 0: stop the unsupported claims (Sep 8 audit) - #9

Merged
fosterstack-admin merged 1 commit into
mainfrom
phase0/claims
Sep 11, 2026
Merged

Phase 0: stop the unsupported claims (Sep 8 audit)#9
fosterstack-admin merged 1 commit into
mainfrom
phase0/claims

Conversation

@fosterstack-admin

Copy link
Copy Markdown
Contributor

This PR stays open for your cold read, same as cache#42 — the two halves of Phase 0 should be approved together.

The Sep 8 audit's §28 corrections, applied to the site. Everything here is a present-tense claim the product now backs, or an explicitly labeled intention.

What was false, and what it says now

  • The feature cards claimed things that do not exist. TTLs (there are none — LRU only), read/write credential split (one shared credential; the split is a roadmap issue), "entry sizes and top misses" (not exposed), "a CI matrix tests every new Gradle and JDK release the day it ships" (no such matrix exists), "config translator" (a guide exists; a translator does not). Each card now describes what ships: size-capped LRU, Basic Auth as it actually works, Prometheus + status page + Grafana dashboard, the 48h target labeled as a stated intention, the real Gradle acceptance gate, and the migration guide as a guide.
  • "A license key unlocks enterprise features" — present tense for tiers that are not built. Now future-tense and explicitly labeled, matching the pricing section's own framing.
  • "public compatibility matrix" in the trust list — none exists. Replaced with what does: signed commits/releases, public release notes, and a pointer to SECURITY.md's exact statement of what the release evidence proves.
  • Maven "drop-in" qualified in the lede and llms.txt: the extension's remote mode is implemented; acceptance coverage is in progress. Gradle keeps its claim — it has a real acceptance test.
  • "release pipeline work and are tested" in the maturity label — the release pipeline's evidence chain is being rebuilt; the label now points at SECURITY.md for exactly what is and is not proven.

No timelines added, no email capture, no 800-204D anywhere (checked).

Sep 8 audit §28 applied to the site. The feature cards claimed TTLs, a
read/write credential split, entry-size/top-miss visibility, a day-one
Gradle/JDK compatibility matrix, and a config translator — none of which
exist. Each card now describes what ships. The trust list's "license key
unlocks" goes future-tense and labeled; "public compatibility matrix" is
replaced by what is real. Maven "drop-in" is qualified in the lede and
llms.txt; Gradle keeps the claim because a real acceptance test backs it.
The maturity label points at SECURITY.md for exactly what the release
evidence proves today.
@cloudflare-workers-and-pages

cloudflare-workers-and-pages Bot commented Sep 9, 2026

Copy link
Copy Markdown

Deploying www with  Cloudflare Pages  Cloudflare Pages

Latest commit: 13a66ed
Status: ✅  Deploy successful!
Preview URL: https://39b624d7.www-4rw.pages.dev
Branch Preview URL: https://phase0-claims.www-4rw.pages.dev

View logs

@fosterstack-admin fosterstack-admin left a comment

Copy link
Copy Markdown
Contributor Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

LGTM

@fosterstack-admin
fosterstack-admin merged commit 169a959 into main Sep 11, 2026
2 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant