- Extended the pool fetch path to prune missing git object alternates, delete bad refs reported by git, and retry fetch operations after each repair.
- Added a Database helper to persist issue branch updates and verified fetch repair behavior with a new test that ensures stale alternates and bad refs are removed.
- Added proxy-mode settings loading via load_proxy_settings in src/robomp/config.py to validate required serve-time env.
- Implemented query-aware HMAC signing and verification for request targets in src/robomp/proxy_client.py and src/robomp/proxy/server.py.
- Added hard body size limits in src/robomp/proxy/server.py returning 413 before full read or auth.
- Added origin URL validation in src/robomp/proxy/server.py before git push to block non-github or mismatched repos.
- Added configurable git timeouts in src/robomp/git_ops.py and enforced wall-clock limits in src/robomp/proxy/server.py git handlers.
- Updated src/robomp/git_ops.py push to pin --force-with-lease to refs/remotes/origin/<branch> for safer concurrent push protection.
- Added proxy HMAC contract tests for valid signatures and 401 responses on missing, bad, and stale headers.
- Added end-to-end tests for proxy request/response mapping across repo, issue, comment, review, and pull-request endpoints.
- Added GitHubProxyClient and ProxyGitTransport git flow tests for clone/push success and head-drift/repo mismatch failures.