Libra CodeHub

CedarCopilot/cedar-mail

Branch: staging

[2026-09-09] merging staging to main

merged#2743CedarCopilot

CedarCopilot wants to merge 1 commit into main from staging

Not deployedTimeline and evidence
  1. Opened
    Sep 9, 2026, 12:32 PM
  2. Sep 9, 2026, 12:42 PM
  3. Merged
    Sep 9, 2026, 12:53 PM
  4. Live on staging, live on prod, observed
    Pending
  5. Not deployed

    Not deployed

    Pending

Libra has no production signal for this change yet because it has not deployed. Libra checks hourly for 3 days after each deploy.

Greptile Summary

Summary

  • Remove the committed Warp evidence database because it contains customer-sales conversations, CRM information, and internal identifiers.
  • Replace the compiler-silencing assertion and remove the unused import in the follow-up email export script.
  • The repository requirements identified in the script must be satisfied before merging.

Confidence Score: 3/5

Not safe to merge until the committed customer-sales evidence is removed and the explicit repository requirements are satisfied.

The review includes a verified disclosure of confidential customer and commercial data in a committed artifact.

Files Needing Attention: docs/audits/warp/data/warp-discovery-evidence.db and apps/server/scripts/dump-followup-emails.ts

Security Review

The committed Warp SQLite database contains internal Cedar conversation identifiers, CRM outcomes and loss reasons, and verbatim customer-sales conversation material. Publishing the repository would disclose confidential customer and commercial information.

T-Rex T-Rex Logs

What T-Rex did

  • T-Rex produced a finding-comment-proof for a posted P1 finding.
  • T-Rex produced a second finding-comment-proof for the posted P1 finding.
  • T-Rex executed the warp-audit-exposure-check.py script, observed the output log, and confirmed the run exited with status 0 while querying the committed SQLite artifact.

View all artifacts

T-Rex Ran code and verified through T-Rex

Comments Outside Diff (2)

  1. docs/audits/warp/data/warp-discovery-evidence.db, line 1 (link)

    P1 security Remove customer sales evidence

    This committed database contains 122 internal Cedar conversation identifiers associated with CRM outcomes and loss reasons, plus verbatim buyer and representative conversation text and commercial discussion. Publishing this repository discloses confidential customer and commercial information outside the systems intended to protect it. Remove the database and other source-level audit artifacts, retaining only reviewed and anonymized aggregate results before merging.

    How this was verified: The committed database contains internal conversation identifiers, CRM outcome fields, and verbatim customer-sales conversation records.

    Artifacts

    Evidence from the check

    • The narrowly authored Python check queries the committed Warp SQLite audit artifact for its tracking status, schema, identifiers, CRM fields, and transcript evidence, showing the inspection me
Show production surfaces and changed-file mapping

Production surfaces

Libra has not measured any production surfaces for this change yet.

Changed files → surfaces

  • apps/server/scripts/dump-followup-emails.tsno production surface mapped
  • apps/server/scripts/run-dump-followup-emails.mjsno production surface mapped
  • apps/server/src/pipelines.tsno production surface mapped
  • apps/server/src/services/crm/__tests__/meeting-s3-cross-user-resolution.test.tsno production surface mapped
  • apps/server/src/services/crm/events.tsno production surface mapped
  • docs/audits/warp/EXTRACTION-RUN-2026-08-29.mdno production surface mapped
  • docs/audits/warp/FINDINGS-SUMMARY.mdno production surface mapped
  • docs/audits/warp/FRICTION-SIGNALS.mdno production surface mapped
  • docs/audits/warp/VOCABULARY.mdno production surface mapped
  • docs/audits/warp/artifacts/PRODUCT-FEEDBACK-REPORT.mdno production surface mapped
  • docs/audits/warp/artifacts/warp-data-lineage.htmlno production surface mapped
  • docs/audits/warp/artifacts/warp-discovery-report.mdno production surface mapped
  • docs/audits/warp/artifacts/warp-sales-analysis-v2.htmlno production surface mapped
  • docs/audits/warp/artifacts/warp-sales-analysis-v2.rendered.txtno production surface mapped
  • docs/audits/warp/artifacts/warp-sales-analysis.htmlno production surface mapped
  • docs/audits/warp/artifacts/warp-sales-analysis.rendered.txtno production surface mapped
  • docs/audits/warp/bucket_loss_reasons.pyno production surface mapped
  • docs/audits/warp/build_evidence_db.pyno production surface mapped
  • docs/audits/warp/data/discovery-diff/DETERMINISTIC.mdno production surface mapped
  • docs/audits/warp/data/discovery-diff/RUBRIC_emergent.mdno production surface mapped
  • docs/audits/warp/data/discovery-diff/RUBRIC_framework.mdno production surface mapped
  • docs/audits/warp/data/discovery-diff/det_metrics.jsonno production surface mapped
  • docs/audits/warp/data/warp-discovery-evidence.dbno production surface mapped
  • docs/audits/warp/load_email_findings.pyno production surface mapped
  • docs/audits/warp/load_findings.pyno production surface mapped
  • docs/bug-reports/participant-roster-rep-buyer-misclassification.mdno production surface mapped