Found while prepping the C5 live test: the embeddings backend
(bge-multilingual-gemma2 via LiteLLM) caps input arrays at 25 per request
("given batch size overflow maximal one", max: 25), but embed() sent the whole
input in a single request. ControlIndex::build embeds the entire master-controls
corpus (~1.8k texts) in one embed() call, and the RAG pipeline batches docs too —
both 500 at scale. Unit tests passed only because they embed <=3 texts.
Fix: embed() now chunks into EMBED_BATCH_SIZE (16) requests and concatenates in
order; empty input short-circuits. Validated live — 1,784 texts over 112 chunked
requests succeed (~70s, one-time + cached by the index).
Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
Adds code inspector, file tree components, graph visualization JS,
graph API handlers, sidebar navigation updates, and misc improvements.
Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
Add DAST scanning and code knowledge graph features across the stack:
- compliance-dast and compliance-graph workspace crates
- Agent API handlers and routes for DAST targets/scans and graph builds
- Core models and traits for DAST and graph domains
- Dashboard pages for DAST targets/findings/overview and graph explorer/impact
- Toast notification system with auto-dismiss for async action feedback
- Button click animations and disabled states for better UX
Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
- Run cargo fmt on all crates
- Fix regex patterns using unsupported lookahead in patterns.rs
- Replace unwrap() calls with compile_regex() helper
- Fix never type fallback in GitHub tracker
- Fix redundant field name in findings page
- Allow enum_variant_names for Dioxus Route enum
- Fix &mut Vec -> &mut [T] clippy lint in sbom.rs
- Mark unused-but-intended APIs with #[allow(dead_code)]
Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>