{"slug":"vendor-discount-agent","total":6,"limit":100,"offset":0,"since":null,"commits":[{"hash":"d104f24","date":"2026-07-16 09:59:12 -0700","author":"Steve Abrams","subject":"Strip hardcoded Shopify API tokens from source (env-first); no rotation/deploy — response to Shopify exposed-credentials notice","body":""},{"hash":"59c40d4","date":"2026-05-30 21:22:43 -0700","author":"Steve Abrams","subject":"fix: populate discount_found field in check record when discount is calculated","body":"checkRecord.discount_found was never assigned, always writing NULL to the\nvendor_discount_checks.discount_found column even when a discount was\nsuccessfully parsed. Now mirrors calculated_discount at the point of success.\n\nCo-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>"},{"hash":"73ea192","date":"2026-05-30 09:49:20 -0700","author":"Steve","subject":"security: strip hardcoded dw_admin DSN password -> env-first/passwordless. No rotation/deploy.","body":""},{"hash":"1eaaf46","date":"2026-05-19 17:25:26 -0700","author":"Steve Abrams","subject":"harden static root: 404-guard .bak/.pre- paths + broaden gitignore","body":"Fleet-refactor sweep tick — Express middleware drops any request whose\npath contains .bak or .pre- with a hard 404 before express.static runs,\nso accidentally-dropped snapshot files can never be served. .gitignore\nnow also covers *.bak.* and *.pre-* variants.\n\nCo-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>"},{"hash":"8453ee6","date":"2026-05-13 08:58:03 -0700","author":"Steve","subject":"snapshot: 1 file(s) changed, ~1 modified","body":""},{"hash":"d09d526","date":"2026-05-06 10:25:50 -0700","author":"Steve Abrams","subject":"initial scaffold (gitify-all 2026-05-06)","body":""}]}