{"slug":"mfr-review-viewer","total":5,"limit":100,"offset":0,"since":null,"commits":[{"hash":"eb911f0","date":"2026-07-16 09:59:12 -0700","author":"Steve Abrams","subject":"Strip hardcoded Shopify API tokens from source (env-first); no rotation/deploy — response to Shopify exposed-credentials notice","body":""},{"hash":"942d742","date":"2026-05-19 17:34:34 -0700","author":"Steve Abrams","subject":"SECURITY HOLD — live Shopify shpat_ token committed at server.js:197","body":"Token targets designer-laboratory-sandbox (= live prod DW store per MEMORY).\nRotate at Shopify admin BEFORE source fix. This repo is SUSPENDED from the\nfleet-refactor-sweep until SECURITY-HOLD.md is removed by Steve.\n\nCo-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>"},{"hash":"77e2f8b","date":"2026-05-19 17:33:23 -0700","author":"Steve Abrams","subject":"add 404-guard middleware for .bak / .pre- snapshot paths","body":"Defense-in-depth — even though no static root is served today, this\nprevents accidental exposure of editor backup files if a static dir\ngets added later.\n\nCo-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>"},{"hash":"c72578f","date":"2026-05-19 17:33:05 -0700","author":"Steve Abrams","subject":"broaden .gitignore to cover .bak.* and .pre-* snapshot files","body":"Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>"},{"hash":"aacc009","date":"2026-05-06 10:25:42 -0700","author":"Steve Abrams","subject":"initial scaffold (gitify-all 2026-05-06)","body":""}]}