This week focused on hardening authentication across integrations, with several services now properly throwing errors when API keys or credentials are missing—covering Mailtrap, Toggl, Wakatime, Harvest, Twilio, and Google. The team also added the Reducto plugin, migrated Supabase's project logs…
Get this in your inbox every Monday →A deterministic 0–100 hygiene score — README, license, CI, tests, docs, and freshness.
Who ships this repo — author concentration and the bus factor across the last 300 mainline commits.
How welcoming this repo is to contributors — issue throughput, close time, responsiveness, and good-first-issue count.
What this project is built on — dependency count by ecosystem, the license mix, and anything worth a legal look before you adopt it.
Whether this project's CI can be trusted — pass rate, run times, flaky runs, and which workflow is the weak link.
Grounded in corsair's README, structure, and recent commits — answers won't invent code they haven't seen.
A Monday email with what shipped, in plain English — no account needed.
Remove duplicate accessibility labels
Cleaned up redundant aria-label attributes on the Script page by removing duplicate labels from the tenant selector and code editor, keeping only the more descriptive ones.
Handle missing Mailtrap API keys
The Mailtrap integration now throws a proper authentication error when an API key is missing instead of silently returning an empty string. This helps developers catch configuration issues earlier and understand what went wrong.
Remove Spotify webhook support
Removed the example webhook handler and all webhook-related code from the Spotify plugin, as Spotify does not offer a public webhook API. The plugin now correctly indicates it has no webhooks available.
Handle missing Toggl API keys
The Toggl integration now properly throws an AuthMissingError when the API key is missing or empty, instead of silently returning a blank string. This ensures authentication failures are caught explicitly rather than allowing requests to be sent with invalid credentials.
WakaTime authentication error handling
The WakaTime plugin now properly throws an authentication error when an API key is missing or empty, instead of silently returning a blank value. This helps users identify and fix authentication issues more clearly.
Harvest auth token validation added
The Harvest integration now throws an error when an OAuth access token is missing instead of silently using an empty token. This prevents requests from being sent with invalid authentication headers and includes comprehensive test coverage for the token validation logic.
Validate port flag in UI command
Fixed a bug where invalid port values (like "3000abc" or "abc") passed to the `corsair ui --port` command would cause crashes or unexpected behavior. The CLI now properly validates that the port is a number between 1 and 65535, and exits with a clear error message if invalid.
Remove unused Zendesk example webhook
Removed a non-functional example webhook handler from the Zendesk plugin that only matched test payloads Zendesk never sends. The plugin now has no registered webhooks, matching other integrations like Bitwarden and AlphaVantage.
Updated project logs API endpoint
Fixed the Supabase project logs endpoint to use the correct analytics endpoint path. The endpoint was migrated from `/logs.all` to `/logs` to match the current API specification.
Fix testing permissions database schema
Updated the testing environment's database schema to properly sync the permissions table structure, including adding retry-safe migrations and indexing for the events table.
A floor, not a guess: counts only commits whose author, co-author trailer, or message explicitly credits an AI tool (Claude, Copilot, Cursor, aider, Codex…). Based on 30 mainline commits. Unattributed AI code isn't counted here — the full audit estimates that separately.