Skip to content

Pre-public-release inherited-core readiness audit #6

Description

@yaacovcorcos

Purpose

Complete a focused inherited-core readiness audit before the first confident public Scient desktop release.

The initial Synara disposition review intentionally did not merge the broad upstream audit or claim that its internals were independently re-audited. This issue keeps the release boundary visible without turning every deferred upstream item into a duplicate backlog.

Required lanes

  • authentication, credentials, permissions, and session isolation
  • storage, migrations, recovery, and rollback
  • attachments, local files, and path handling
  • provider, WebSocket, and runtime lifecycle reliability
  • release/update provenance, signing, notarization, manifests, and rollback

Acceptance criteria

  • Inventory the current Scient-owned implementation in every lane above.
  • Inspect the relevant upstream changes and record an explicit Adopt, Adapt, Reimplement, Defer, or Reject disposition for each bounded candidate.
  • Preserve Scient identity, project-init, credential, session, storage, permission, and updater boundaries.
  • Add focused regression tests for every behavior changed or retained because of the audit.
  • Run the full hosted desktop CI and release-smoke checks at the exact candidate head.
  • Produce and inspect the release candidate artifacts, including signing/notarization status and updater manifests.
  • Verify installation, launch, project opening, agent connection, update behavior, and rollback on an isolated machine/profile.
  • Record exact evidence in the parent Scient source review/intake record before release approval.

Non-goals

  • No broad upstream merge merely to become current.
  • No unrelated product features in the audit PRs.
  • No claim that a disposition review alone proves security or release readiness.

This issue blocks public release approval. It does not block ordinary Scient product development.

Metadata

Metadata

Assignees

No one assigned

    Labels

    release-blockerMust be resolved before a public release

    Type

    No type

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions