Block a user
Denoise graph keeps running (full ML inference) while the mic is muted
Racing
LocalTrackPublished events start two denoise processors (two AudioContexts, two wasm inits)
Model load failure silently publishes raw audio while the host UI says denoise is on
Nothing in CI or the test suite exercises
src/lotus/* at all
Denoise init blocks LiveKit's track-change lock, freezing mute/unmute for seconds
In-call avatar decoration is sized 1:1 with the avatar (no inset like the host) and has no onError fallback
Fork CI never runs the test/lint/typecheck suite before publish
Denoise restart fallback hands LiveKit the raw mic as
processedTrack, which later gets stopped
focus_participant is a silent no-op in EC's default grid layout
Deafen via per-participant setVolume is undone by EC volume controls and clobbers tile volumes on undeafen
Repo hygiene: eight dead GitHub Actions workflows under
.github/workflows never run on Gitea
Process: no CODEOWNERS or required review — a single push to
lotus deploys to production in ~11 minutes
CI: the
lotus-build.sh upstream-merge path deploys without running CI
CI: bundle size is reported but has no budget — regressions pass green
CI: ESLint runs without
--max-warnings, so new react-hooks/exhaustive-deps warnings never surface
CI: no dependency update automation (Renovate/Dependabot)
CI: no secret scanning, and
config.json (incl. any gifApiKey) ships inside the build image
CI: built output is never loaded — add a
vite preview boot check after npm run build
CI: the Docker image is never built — add a
docker build job so the documented deploy path can't rot
CI:
npm audit is informational — high-severity advisories should fail pull requests