Chatbot 26Q3 Engineering Initiatives
Bucket for Chatbot's systemic engineering work in 26Q3. As of 2026-07-13 it follows CDP's classed, unranked engineering-bucket model for independent EOL tech-stack, runtime, framework, dependency, security, reliability, performance, and architectural-modernization stories.
Repository workflows, test infrastructure, MCP, hooks, agent skills, and internal operational tooling are explicitly excluded and route to Chatbot Q3 2026 Code Readiness, Epic BOT-4500. Customer- facing outcomes route to their product initiative. See the approved routing ADR.
The first two stories (A1, A2) landed 2026-07-13 with their RFCs. On 2026-07-13 the Jira mirror was minted (Epic BOT-4620, Stories BOT-4621/BOT-4622) and staffing was confirmed: BE/DRI = Agus, QA = Tito, Izzul. Effort estimates remain intentionally unsized (bucket stories enter as pull-in fill). FE staffing is split across stories — Linggar (A2), Baghiz (A3) — confirmed 2026-07-16.
Scope Changes
- Backend
- Frontend
- Infra
Stories — per-story tracker (canonical)
| Story | Class | DRI | Status | Added | Scope | BE | FE | QA | Jira Story | Summary (→ RFC) |
|---|---|---|---|---|---|---|---|---|---|---|
| A1 | 🔴 Expedite | Agus | backlog | 2026-07-13 | Backend, Infra | Agus | — | Tito, Izzul | BOT-4621 | Phase 1: Ruby 3.2.2→3.4.10 + Rails 7.1.3.2→7.2.3.1 (both EOL/security-expired) → rfc |
| A2 | 🟡 Standard | Agus | backlog | 2026-07-13 | Backend, Frontend, Infra | Agus | Linggar | Tito, Izzul | BOT-4622 | Phase 2: Rails 7.2→8.1.3 (then optional Ruby 4.0.5 — deferred) → rfc |
| A3 | 🔴 Expedite | Baghiz | done | 2026-07-14 | Frontend | — | Baghiz | Tito, Izzul | BOT-4661 | SCA remediation: upgrade pdfjs-dist 3.11.174→4.2.67 (CVE-2024-4367, HIGH, actively exploited) → rfc |
| A4 | 🟡 Standard | Linggar | in-review | 2026-07-20 | Frontend | — | Linggar | Tito, Izzul | BOT-4696 | Subscription feature-flag gating reliability (cold-reload): eager subscriptionStore() init + hasFeature/featureMap API, ~30 call-sites migrated off $hasSubscription → placeholder story (no RFC; reconstructed from BOT-4650 code changes) |
| A5 | 🟡 Standard | Eko Aprianto | backlog | 2026-07-27 | Backend, Infra | Eko Aprianto | — | Tito, Izzul | BOT-4795 | Aegis alert on AI Service no-response (5-min threshold) triggering the AI Agent's configured fallback automatically; event recorded in the Impact report → context note (no RFC yet) |
| A6 | 🟡 Standard | Eko Aprianto | backlog | 2026-07-27 | Backend, Infra | Eko Aprianto | — | Tito, Izzul | BOT-4796 | Alert detecting a knowledge upload stuck in Processing for more than 5 hours (Fast Track cluster C; BOT-4746, BOT-3635) → context note (no RFC yet) |
Progress rollup: 1 of 6 done (17%) as of 2026-07-27.
When an item is ready, add the next canonical tracker row as A3, and so on. Each row must record
its Class, DRI, Status, Added date, Scope, BE/FE/QA staffing, Jira Story, and RFC link; do not
renumber existing stories.
Pull rule
The bucket takes no ## Priority rank. A future story is classed and pulled independently:
🟡 Standard and ⚪ Intangible work fill available capacity without delaying ranked work; 🔴 Expedite
may preempt only when authorized and recorded in the log below. At most one Expedite story may be
in flight.
Expedite log
| Story | Date | Authorized by | Preempts | Reason |
|---|---|---|---|---|
| A1 | 2026-07-13 | TBD | — (backlog) | Security-facing: Ruby 3.2 is out of all support since 2026-03-31, and Rails 7.1 has been unpatched since its 2025-10-01 security-EOL, including a missed 2026-03 CVE batch. Classification only — currently backlog, so no preemption has occurred yet (WIP limit 1). |
| A3 | 2026-07-14 | TBD | — (A1 still backlog, so no live preemption) | Security-facing: CVE-2024-4367 in pdfjs-dist 3.11.174, HIGH severity and actively exploited. Retroactive log entry added 2026-07-16 (sprint-resync pass 6) — the story reached in-review (BOT-4661, Baghiz) on the board before this row existed; Authorized by needs DRI/TPM confirmation, and the story's own RFC (sca-pdfjs-dist-upgrade.md) is still draft with DRI/reviewers/approvers all TBD despite the build being nearly done. |
How the bucket grows
- Add a focused RFC under
rfcs/with repository evidence, proposed change, validation, and rollback. - Add the first real tracker row (
A1), then append subsequent items asA2,A3, and so on. - Create the bucket Epic and one Jira Story per real item; replace the relevant
TBDvalues. - Record DRI, staffing, effort, QA ownership, and roadmap/capacity mirrors before pull-in.
- Refresh the roadmap's Adhoc / Interrupt lane and progress rollup.
QA Lane
Lane B is the conservative scaffold default. Confirm the appropriate lane, QA owner, and coverage for each real story before it enters delivery. A1 and A2 both await per-story QA-lane confirmation; QA ownership is staffed (Tito, Izzul — confirmed 2026-07-13).