Block a user
Upstream fork is 6 minor releases behind with no cherry-picks; hotspot files have heavy upstream churn
Resolved by the upstream v0.25.0 merge (c6f97278, shipped as 0.25.0-lotus.1). Toolchain consequences (Node 24 / pnpm 11 direct install, oxlint+oxfmt, git-pinned matrix-js-sdk) are documented in…
CI: no dependency update automation (Renovate/Dependabot)
CI: no secret scanning, and
config.json (incl. any gifApiKey) ships inside the build image
CI: add a Playwright smoke test that boots the built client and exercises the composer in an E2EE room
CI: the Docker image is never built — add a
docker build job so the documented deploy path can't rot
CI: the
lotus-build.sh upstream-merge path deploys without running CI
Fixed in LotusGuild/matrix@67a08c7: lotus-build.sh now merges, runs the local gates (npm ci, typecheck, eslint, prettier, tests) and pushes; CI + lotus_deploy.sh deploy the result like any other…
Dead code: unused useForceUpdate.js
syncDecorations.mjs fragile regex parsing
Fragile postinstall patch script for folds Icon
OIDC callback does not invalidate a cached client id the provider rejects
Dedupe the screenshare confirmation and route CallControls through useRoomCallPolicy
Favouriting/low-priority a room doesn't move it in the sidebar until an unrelated re-render
Lotus-added UI bypasses the app's i18next mechanism entirely — always renders in English regardless of user locale
Repo hygiene: eight dead GitHub Actions workflows under
.github/workflows never run on Gitea
CI: the
lotus-build.sh upstream-merge path deploys without running CI