Example only. Names, the company, and the repository are made up. This is the form of note we send if a job is still open at four hours.

Four-hour update

CodeVolt · Job CV-25-0041

21 August 2026, 13:10 Europe/London · four hours after lock

To: Alex Reid, North Harbour Books
From: Emma, CodeVolt, rook@codevolt.co.uk

Locked task

This file: in src/webhooks/stripe.ts, reject empty Stripe webhook bodies with HTTP 400 before signature checks run. Return the change as a patch. Not a live deploy.

Status

In progress. Emma has written and checked the patch. The delivery pack has not been sent yet.

Done in this window

  • Locked the task after payment, 09:10.
  • Read only src/webhooks/stripe.ts and the tests beside it.
  • Drafted the one-file patch: an empty or missing raw body returns 400. Signature verification is unchanged.
  • Ran the unit tests that do not need live Stripe keys. Fourteen passed. The two tests that call the live webhook secret were marked could-not-run.

Next

Write the delivery note, then send the patch, the test evidence, and what we refused to change. Expected later today.

Waiting on you

Nothing. Do not send more files.

What we refused to touch

  • src/billing/invoice.ts — a separate total-rounding issue. Not this job.
  • Deploy scripts and production environment variables.
  • A second webhook handler in the same folder.

About this note

The starting job includes a progress note only when the job is still open at four hours. If we finish sooner, you get the delivery pack instead. Quoted work gets the same form every four hours until we deliver or stop.

Back to how we keep you posted · From £5