50 identified risks across security, technical, legal, operational, privacy, strategic, and business categories. Likelihood x Impact 1--25. Click any row to expand.
✎ You have unsaved status changes.These are stored in your browser. Copy the export to update the source file.
Filter:
Session close — 12 Jul 2026 (split night)
NEW RISKS: (R-059) 8 pre-existing dead-code ReferenceErrors in unreachable paths — throw if paths become reachable; fix post-upgrade (cards s0-29..34). (R-060) SupportBot remains in page.jsx shell, un-extracted — no locked-plan session covered it (card s8-5). (R-061) Process: runtime gate was skipped during split deploy; Vercel build failure was the catch. Mitigation: no-undef lint added to verification suite (s0-35); gate wording hardened. CLOSED: page.jsx monolith risk — split complete and in production.
Session close 2 — 12 Jul 2026 (upgrade day)
NEW: (R-062) middleware.ts -> proxy.ts rename touches the auth layer — mitigated by staged staging verification before production; monitor sign-in/sign-out error rates. (R-063) @stripe/react-stripe-js 2->6 + stripe-js 4->9 (multi-major) — checkout path needs monitoring through first real transactions. (R-064) PROCESS: the /api/stripe/* build failure was misdiagnosed as a benign local-env error across multiple gates before being identified as a latent lazy-init bug — lesson: no error is "known benign" without root-cause. UPDATED: R-061 mitigation held (lint sweep now standard). CLOSED: Next.js 14 EOL exposure — now on 16.2.10 LTS. s0-27/s0-28 re-scored: React 19 did NOT fix; real fixes scheduled Batch 1.