Skip to content

Meet complete-product assurance and v1 release criteria #29

Description

@hyperpolymath

Outcome

Define and meet the assurance, performance, documentation, and release criteria for Bag as a complete product rather than a proof of concept.

Scope

  • Publish a threat model covering workers, webhook input, manifests, ledgers, keys, GitHub status substitution, supply chain, downgrade, and operator error.
  • Expand Idris2 invariants and add drift detection for generated/neutral interface artefacts actually consumed by Zig/Elixir.
  • Add property, mutation, fuzz, fault-injection, compatibility, upgrade, and long-running soak tests.
  • Benchmark scheduling, signing, thaw/verification, queue throughput, and reporting without weakening security.
  • Correct template residue in machine-readable state/governance files and publish an accurate support/maturity matrix.
  • Define versioning, migration, deprecation, security-response, release-signing, SBOM, and reproducible-release policies.

Acceptance criteria

  • A versioned v1 release checklist has objective pass/fail gates and named evidence.
  • Formal claims map to checked artefacts and executable conformance tests.
  • Supported and unsupported deployment modes are explicit.
  • A clean installation can be built, operated, upgraded, backed up, restored, and independently verified from the documentation.

Metadata

Metadata

Assignees

No one assigned

    Labels

    area:operationsPackaging, deployment, observability, and recoveryarea:securityTrust boundaries, attestation, and hardeningpriority:p1Important product completion workroadmapPlanned product-roadmap work

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions