← back to Codex Review 2026 04 30

Norma/CHANGES.md

11 lines

Applied the safe secret-removal fixes and wrote [CHANGES.md](/Users/stevestudio2/Projects/Norma/CHANGES.md:1).

Changed:
- [lib/auth.ts](/Users/stevestudio2/Projects/Norma/lib/auth.ts:5)
- [app/api/webhooks/pulse-topic/route.ts](/Users/stevestudio2/Projects/Norma/app/api/webhooks/pulse-topic/route.ts:6)
- [lib/detect-mentions.ts](/Users/stevestudio2/Projects/Norma/lib/detect-mentions.ts:20)
- [app/api/drafts/auto-generate/route.ts](/Users/stevestudio2/Projects/Norma/app/api/drafts/auto-generate/route.ts:12)
- [app/api/social/ai-compose/route.ts](/Users/stevestudio2/Projects/Norma/app/api/social/ai-compose/route.ts:4)
- [.env.example](/Users/stevestudio2/Projects/Norma/.env.example:1)

I did not run tests, install packages, commit, or push, per instruction. Remaining script/agent/doc hardcoded-key references were left alone because P2 was explicitly out of scope and owner-side rotation is still required.