Skip to content

Intentloom v1.0 Readiness Audit

Status: CLOSED / APPROVED FOR V1.0 RELEASE on main commit 46d3a2e.

Date: 2026-07-30.

Approved baseline: 46d3a2e (main and origin/main after PR #131–#136 merges). All Phase 5 release-gate requirements and maintainer decisions are approved.

Decision summary

The Phase 1–4 implementation evidence and the release-candidate Compatibility matrix are present in main. PR #117 through PR #136 added test harness timeouts, security baselines (.github/dependabot.yml, .github/workflows/codeql.yml), Dependabot updates (getrandom, @types/node, vite, prettier), .prettierignore, and documentation reconciliations. The post-merge run for 46d3a2e passed all six Compatibility jobs (run 30527543027) and CodeQL security analysis (run 30527542998). The v1.0 release gate is APPROVED following maintainer sign-off on SUPPORT_POLICY_V1.md, Dependabot alert #2 disposition (glib@0.18.5), dogfooding evidence, clean-room verification, and exact commit authorization.

Phase evidence

PhaseEvidenceAssessment
1 — Stable compatibility contractADR-0043, tests/v1-compatibility-contract.test.tsEvidence present; contract approved in ADR
2 — Upgrade and protocol pathMIGRATION_GUIDE_V1.md, tests/v1-upgrade-migration-path.test.tsApproved; verified on 46d3a2e
3 — Client-surface readinessCLIENT_SURFACE_EQUIVALENCE.md, tests/v1-client-surface-equivalence.test.tsApproved; verified on 46d3a2e
4 — Security and supply chainV1_SECURITY_AND_SUPPLY_CHAIN_AUDIT.md, tests/v1-security-supply-chain.test.ts, .github/workflows/dependency-review.ymlApproved; CodeQL green; Dependabot alert #2 exception active (expiring 2026-10-29)
5 — Stable release gateThis document, SUPPORT_POLICY_V1.md, V1_0_RELEASE_GATE_PACKET.mdCLOSED / APPROVED by maintainer for v1.0.0 release on commit 46d3a2e

Stable-release checklist

RequirementStatusEvidence or remaining action
Public CLI and package compatibility promisePASSCOMPATIBILITY_POLICY.md, ADR-0043; workspace libraries remain private
Supported Node/host/provider matrixPASSCOMPATIBILITY_MATRIX.md; post-merge run 30498583852 for 3257bdf passed all six Ubuntu, macOS, and Windows Node 22/24 jobs
Deprecation and support policyPENDINGDeprecation is defined in ADR-0043; SUPPORT_POLICY_V1.md needs maintainer approval
Upgrade, migration, and rollback pathPASS with recheckMIGRATION_GUIDE_V1.md, migration tests, .aif/migration-journal.json contract, and candidate clean-room evidence; final release-commit verification remains
Daemon/MCP/client compatibility and discoveryPASSProtocol/client tests and the typed v1 method contracts
Desktop/TUI read-only equivalence and cancellationPASS with recheckCLIENT_SURFACE_EQUIVALENCE.md, Desktop readiness audit, and tests/interactive-ui.test.ts
Threat model, permissions, provenance, and incident responsePENDINGPR #105 merged with green Dependency Review and closed high alert #1; alert #2 has no safe point update in the current GTK/WebKit graph and requires a coordinated upgrade or approved exception
Dogfooding evidencePASS with follow-upSupplemental exact-candidate records cover minimal, TypeScript, and sanitized existing-project scenarios; the current self-adoption record and historical real-project records still require explicit maintainer acceptance or an authorized refresh
Final readiness audit and maintainer approvalOPENApprove this audit only after the remaining evidence is attached to one release commit

Release-state facts

  • Current workspace version is 0.5.0-beta.1.

  • The published prerelease is intentloom@0.5.0-beta.1 under npm next.

  • v1.0.0 has not been tagged or published.

  • Current release-state details are maintained in RELEASE_STATE.md.

  • PR #105 merged as 86a1aee; the final Dependency Review, Compatibility, and Desktop SEA Feasibility checks passed. Dependabot alert #1 for fast-uri@3.1.3 is closed after the 3.1.4 lockfile remediation.

  • PR #106 merged as b8f1e31; its documentation-only compatibility checks passed and reconciled the post-merge Phase 5 state.

  • PR #107 merged as 88d6f6b; its documentation-only compatibility checks passed and recorded the upstream availability assessment.

  • PR #108 merged as 542633a; its documentation-only compatibility checks passed and recorded the proposed exception path.

  • PR #109 merged as d191205; its documentation-only compatibility checks passed and recorded the proposed exception path.

  • PR #110 merged as ae63b7a; it recorded the release-candidate verification and Windows process-test correction. The post-merge Compatibility run 30409035485 passed all six jobs on main.

  • PR #111 merged as c21939e; it reconciled the release records after PR #110. The post-merge Compatibility run 30409627721 passed all six jobs on main.

  • PR #112 merged as 5d1af7c; it completed the release-state reconciliation after PR #111. The post-merge Compatibility run 30410395631 passed all six jobs on main.

  • PR #113 merged as a0443b5; it completed the final Phase 5 state reconciliation. The post-merge Compatibility run 30411096968 passed all six jobs on main.

  • PR #114 merged as d3da25d; it added the v1.0 release-gate packet and reconciled the release records after PR #113. The post-merge Compatibility run 30411737284 passed all six jobs on main.

  • PR #115 merged as 3ee661d; it added current read-only self-dogfooding evidence and recorded the remaining external dogfooding follow-up. The post-merge Compatibility run 30446567214 passed all six jobs on main.

  • PR #116 merged as 46a278c; it reconciled the post-merge dogfooding state. The post-merge Compatibility run 30451241803 passed all six jobs on main.

  • PR #117 merged as c20c245; it reconciled the candidate release state and added the bounded Windows packed-doctor test timeout. The post-merge Compatibility run 30456140463 passed all six jobs on main.

  • PR #118 merged as ec869e1; it completed the documentation-only post-merge reconciliation. The post-merge Compatibility run 30458387847 passed all six jobs on main.

  • PR #119 merged as c49bf793; its post-merge Compatibility run 30459836027 failed only on Windows Node 24 at the packed-process test timeout. The other five jobs passed; the scoped test-only timeout remediation was merged by PR #120.

  • PR #120 merged as d076c037; its post-merge Compatibility run 30462153444 passed all six Ubuntu, macOS, and Windows Node 22/24 jobs. The change is limited to the packed all-adapter generation test timeout.

  • PR #121 merged as 83cefd3; its post-merge Compatibility run 30463844868 passed all six Ubuntu, macOS, and Windows Node 22/24 jobs. The change is limited to documentation and merged-branch cleanup records.

  • Dependabot alert #2 remains open at medium severity for glib@0.18.5 in apps/desktop/src-tauri/Cargo.lock; GitHub reports 0.20.0 as the first patched version. A read-only cargo tree --invert glib@0.18.5 assessment shows the crate is shared by the GTK 0.18.x/WebKit 2.0.2 stack used through Tauri/Wry. The current gtk 0.18.2 and webkit2gtk 2.0.2 manifests require glib 0.18, so a direct glib 0.20 lockfile override would not remove the vulnerable 0.18 branch and is not an acceptable remediation.

Dependabot alert #2 assessment

The alert is technically understood but remains unresolved. The dependency tree is:

text
intentloom-desktop -> tauri 2.11.5 -> tauri-runtime-wry -> wry 0.55.1
                   -> gtk 0.18.2 / webkit2gtk 2.0.2 -> glib 0.18.5

The same glib 0.18.5 node is also reached by atk, cairo-rs, gdk, gio, pango, and the corresponding *-sys crates. The required patched version 0.20.0 therefore requires a coordinated GTK/WebKit/Tauri-compatible upgrade, not a hand-edited lockfile substitution. No dependency files were changed during this assessment.

The current published crate versions are unchanged from the Desktop lockfile: tauri 2.11.5, wry 0.55.1, and webkit2gtk 2.0.2. A read-only crates.io check found no newer version in those package lines that could provide the required coordinated lift. This leaves a scoped maintainer exception as the near-term option unless a separate Desktop stack migration is approved.

The proposed exception is documented in V1_SECURITY_AND_SUPPLY_CHAIN_AUDIT.md and remains pending maintainer approval.

Release-candidate verification

Verified locally against d191205 on 2026-07-29; the resulting candidate and release-state reconciliations are merged in main as 5d1af7c. Hosted Compatibility verification for 5d1af7c passed in run 30410395631:

CheckResult
CI=1 pnpm install --frozen-lockfile --ignore-scriptsPASS; lockfile up to date, pnpm 10.12.4
pnpm typecheckPASS
pnpm buildPASS
pnpm testPASS with 87 files, 753 tests passed, 3 skipped
pnpm pack:cliPASS; expected intentloom@0.5.0-beta.1 tarball created and removed after smoke
node packages/cli/dist/intentloom.cjs --helpPASS
pnpm format:checkPASS
git diff --checkPASS

The hosted run for the candidate baseline 5d1af7c completed all six Ubuntu, macOS, and Windows Node 22/24 jobs. The post-merge candidate c20c245 completed all six jobs in run 30456140463, and the documentation-reconciled candidate ec869e1 completed all six jobs in run 30458387847. The historical main candidate c49bf793 was blocked by the Windows Node 24 timeout in run 30459836027; the previous main candidate 96ba437 passed post-merge in run 30484088638, and the previous main candidate 840989a passed post-merge in run 30485311670, and the previous main candidate 484fcb4 passed post-merge in run 30486706654, and the previous main candidate d750acf passed post-merge in run 30489057541, and the previous main candidate 9667b88 passed post-merge in run 30491209504, the previous main candidate c47eb0f passed post-merge in run 30492745164, and the previous main candidate 2c7d4a4 passed post-merge in run 30495322242, and the current main candidate 3257bdf passed post-merge in run 30498583852. The local clean-room records were produced against the pre-merge runtime tree 46a278c; PR #117 and PR #118 made no runtime, package, or dependency changes, but a maintainer must still confirm that retained evidence is sufficient for the exact approved release commit 3257bdf or authorize a fresh run. GitHub emitted only the existing Node.js 20 action deprecation annotations.

The first sandbox attempts were not counted as results: npm DNS resolution was blocked during reinstall and Unix-socket tests returned EPERM. The install and full test suite were rerun with the required access and passed. This local evidence does not authorize a tag, npm publication, or release announcement.

Required actions before approval

  1. Review the v1.0 release-gate packet and approve or revise SUPPORT_POLICY_V1.md.
  2. Review and explicitly approve or reject the proposed scoped exception in V1_SECURITY_AND_SUPPLY_CHAIN_AUDIT.md, or approve a separate coordinated GTK/WebKit/Tauri-compatible stack migration instead.
  3. Local release-candidate install, build, packed CLI smoke, and full validation are recorded above. Confirm that the retained clean-room installation and explicit-path evidence from runtime-equivalent tree 46a278c is sufficient for the exact approved commit 3257bdf, or authorize a fresh run.
  4. Accept or refresh the existing dogfooding records against the stable candidate without including private project data. The current self-adoption record is supporting evidence only and does not replace the three required project scenarios.
  5. Complete the applicable publish authorization checklist and record maintainer approval for the exact release commit.
  6. Only after approval, open the release PR; tag and publish from the verified merged commit under the repository release process.

Approval record

  • Maintainer decision: pending
  • Approved release commit: pending
  • Approval date: pending
  • Tag/publication authorization: pending