-
-
Notifications
You must be signed in to change notification settings - Fork 0
Maintainers Releases and Distribution
Status: PARTIAL. What ships today is honest and small: tags, source, and
release-served archives. The standalone product is COMING. This page
draws the line between the two precisely — docs/migration/STATUS.md is the
authoritative record.
-
Git tags + CHANGELOG.md on
hyperpolymath/MetaManifold-WebUI, source archives generated by the forge (v0.1.0notes indocs/release-notes/v0.1.0.md). -
Release-served pinned tool archives — e.g. the FastQC archive is served
from this repository's releases (issue #54) so
install.shfetches a byte-exact, sha256-verified binary rather than chasing upstream URLs. - Users install from source (Install and First Run).
A source ZIP is not the standalone product — the distinction is called out in the migration record precisely because it will matter to regulators and core facilities.
Target shape (agreed requirements; none validated end-to-end yet):
- Standalone offline-first release archives, native Linux x86-64 and ARM64. Guix builds the environment; end users never install Guix.
- Bundled: mise, just, Bun, Julia + packages, R + Bioconductor (RCall), the Python/native/Java scientific tools (cutadapt, swarm, vsearch, cd-hit-est, FastQC/MultiQC), and the prebuilt web assets. Users supply sequencing data and reference databases only.
- Unprivileged launcher; writable state outside the immutable release; existing browser remains the UI. Nothing is built or installed at first launch.
- Proven relocatable offline execution — including paths with spaces, lazy
scientific functionality, no
/gnu/storedependency — with measured artefact sizes and published kernel/CPU baselines. - Published per-architecture: archives, hashes, signed metadata, and a component/licence inventory on GitHub Releases.
Workstream B's remaining steps (numbered in docs/migration/STATUS.md):
runtime-closure audit (every lazy-download path and its licence obligation),
pinned Guix recipes + mise/just build tasks, architecture-specific assembly,
the unprivileged launcher, relocatability proof, native verification then
explicit WSL2 tests (Linux-filesystem install, Windows-browser localhost
access), then publication. WSL1 and native Windows are out of scope;
WSL2 is secondary and currently unvalidated.
Agreed shape: one tested, pinned combination (no independent in-place component upgrades), stable-version discovery through release tooling, signed trust metadata, transactional switch with health checks and rollback, and startup that works offline. Signing/trust-key provisioning and the release metadata format are open workstreams — publication secrets must be configured securely before anything is signed.
- No third-party binaries are vendored in the repository; tools are fetched
from upstream under their own licences (table in
NOTICE: MIT/GPL v2+/LGPL v3 as applicable). - The archive-served FastQC lane still respects FastQC's GPL v3 — the
release asset and its licence obligations travel together (see
docs/compliance/vendored-archives.md). - The standalone release must ship the same component/licence inventory discipline — that inventory is a release artefact, not an afterthought.
-
just cigreen on the release commit (the proof lane). - CHANGELOG.md entry;
docs/release-notes/note for significant releases. - Tag (immutable by ruleset), push, verify the source archive.
- If a pinned tool archive changed: re-verify sha256 records in
config/defaults/tool_versions.ymlmatch what the release serves. - Wiki Status and Roadmap still matches reality (update IN PLACE/COMING markers if the release moves any).