Tracking issue for a full maintenance audit of this repo (Python data-pipeline at root + Next.js explorer/ app). Grouped by theme. Child issues auto-tick as their PRs merge. Ordering follows the safety-net principle: tests/CI before risky dependency work (encoded as Depends on links in the children).
Context: PRs #15/#16/#33 already cleared the JS-side security backlog and added the first explorer/ tests. The Python side is now the largest gap — 51 of 62 Dependabot alerts are on poetry.lock, and CI does not touch Python at all.
Discoverability
Cleanup
Testing + CI
Dependencies
Security
Docs
UX / correctness
Tracking issue for a full maintenance audit of this repo (Python data-pipeline at root + Next.js
explorer/app). Grouped by theme. Child issues auto-tick as their PRs merge. Ordering follows the safety-net principle: tests/CI before risky dependency work (encoded asDepends onlinks in the children).Context: PRs #15/#16/#33 already cleared the JS-side security backlog and added the first
explorer/tests. The Python side is now the largest gap — 51 of 62 Dependabot alerts are onpoetry.lock, and CI does not touch Python at all.Discoverability
pinecone,neo4j,vector-search,rag,nextjs,scotus), and homepageLICENSE(Apache-2.0 — confirm org standard).githubdefaults vs. repo-localSECURITY.md/CONTRIBUTING.md)Cleanup
route.ts,test.md) + fixpyproject.tomlmetadataTesting + CI
aimigrationDependencies
poetry.lockDependabot alerts + regenerate lockfile (depends on Add a Python CI lane (ruff lint + compile/import check) #37)pinecone-clientv4 → currentpinecone(depends on Add a Python CI lane (ruff lint + compile/import check) #37)ai3→7 / Batch B (depends on Expand explorer test coverage (Graph, API routes, streaming) #38)Security
Docs
UX / correctness
process.pyhardcodedindex_name = "enron"(wrong dataset — investigate whetherprocess.pyis still used)