-
#296: remove the unsubscribe-token dual-verify window early
All checks were successfulCD / Smoke tests against Test (push) Successful in 1m25sCD / Promote to Int (push) Successful in 12sRelease / Build release images and notes (push) Successful in 3m31sRelease / Release-candidate operations QA (push) Successful in 46sCI / Build container images (push) Has been skippedProd deploy / Deploy the released images to Prod (push) Successful in 58sCI / Import/export fidelity gate (push) Successful in 59sCI / Lint, typecheck, test (push) Successful in 6m40sCI / Auth e2e pack (push) Successful in 8m21sRestore drill / Restore the latest backup into a scratch stack (push) Successful in 1m18sCI / Build container images (pull_request) Successful in 2m53sCI / Auth e2e pack (pull_request) Successful in 8m34sCI / Lint, typecheck, test (pull_request) Successful in 6m22sCI / Import/export fidelity gate (pull_request) Successful in 59sCD / Build and push images (push) Successful in 19sCD / Deploy to Test (push) Successful in 14sreleased this
2026-07-31 23:03:03 +02:00 | 37 commits to main since this releaseOperator decision at the ADR 0020 acceptance: verification is
subkey-only now instead of waiting for the stated 2026-11-01 expiry.
Links in digest mails sent before the #188 key separation stop working;
recipients use the in-app notification settings. A regression test pins
that the legacy derivation (root key + purpose prefix) can never verify
again; security.md records the removal.Co-Authored-By: Claude Fable 5 noreply@anthropic.com
Claude-Session: https://claude.ai/code/session_01AUtYMxwTCMHG9mVHnwbFg8Downloads