Skip to content

Simplify README, fix security dependencies, and verify source installation - #21

Merged
dKosarevsky merged 3 commits into
mainfrom
fix/docs-install-security
Oct 8, 2026
Merged

dKosarevsky merged 3 commits into
mainfrom
fix/docs-install-security

Conversation

@dKosarevsky

@dKosarevsky dKosarevsky commented Oct 7, 2026 •

Copy link
Copy Markdown
Contributor

Summary

  • Reduce the README to a 65-line quick start; retain detailed API, configuration, operations, architecture, development, and model guidance in linked Markdown pages.
  • Fix actual Security failures without exemptions: raise anyhow to 1.0.103 (RUSTSEC-2026-0190) and replace yanked der 0.8.0 with 0.8.2.
  • Add repeatable source-install CI using the installed binary and real default Parakeet model, plus an API smoke script using generated silence.
  • Validate model files before reporting setup success; preserve an installed model when a forced replacement download is incomplete or contains directories instead of files. Add seven offline setup tests.
  • Bind Docker Compose to host loopback, matching the local/private quick start.
  • Document current terminal usage and an explicitly proposed Claude Code mod integration, with official sources checked 2026-10-07. No microphone/extension implementation is claimed.
  • Update existing documentation-contract tests to follow the moved content while asserting README navigation links.

Verification on 20705f7

CI passed:

  • All 163 Rust tests, formatting, Clippy, and the 88% line-coverage floor.
  • All seven offline setup-script tests, relative Markdown file links, and shell syntax.
  • cargo install --locked --path crates/aximo on a clean GitHub Linux runner.
  • Default Parakeet model download and startup of the installed release binary.
  • Live/readiness/capabilities/OpenAPI/docs/metrics checks; real-model transcription of one-second synthetic silence; expected 415/400 API error contracts.

Silence verifies service wiring, not speech accuracy. A representative speech benchmark and native macOS/Windows validation remain outside this verification. The local assistant environment could not finish bootstrapping Rust; the successful source-install evidence above comes from GitHub Actions.

Security passed: Cargo audit, Cargo deny, and CycloneDX SBOM generation. Image Security passed: image build, Trivy, Grype, and SARIF/report uploads. Both restored workflows triggered automatically for this PR update and completed successfully on the exact head commit.

Root causes and badge behavior

  • The last main Security run failed on anyhow 1.0.102 and yanked der 0.8.0. RustSec advisory.
  • Both scheduled security workflows were disabled by GitHub for repository inactivity. They have now been re-enabled; no token permissions, secrets, audit exemptions, or scan thresholds were changed.
  • Main badges remain truthful: dependency fixes affect main only after this PR is merged and those main workflows succeed. The coverage badge is the last measured main result, not this PR's coverage.

@dKosarevsky
dKosarevsky marked this pull request as ready for review October 8, 2026 05:52
@dKosarevsky
dKosarevsky merged commit eca35cc into main Oct 8, 2026
13 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant