Tracks the open-source delivery boundary: the public product is the Python core, Rust session engine and Solid PWA delivered as the supported stack.
Delivered
The repository-side implementation and public delivery surface are complete on dev:
- MIT governance and contributor/security documentation.
- Core, engine and PWA boundary with the supported Compose overlays.
- Clean-checkout build path, public delivery checks and current release references.
- Sanitized Firebase handling, out-of-tree CI configuration and tracked-secret guards.
- Renamed Android identities and the mobile/voice implementation.
The GitHub repository is PUBLIC.
Remaining publication and security gates
The repository-side work is not waiting on another code PR. The package is currently PRIVATE, and the historical Firebase key remains reachable from old Git refs, so publication/security acceptance is not claimed.
Close condition
Close this tracker after #265, #266 and #191 record their owner-controlled security, publication and device evidence, then run the anonymous delivery smoke against the public repository and package.
Tracks the open-source delivery boundary: the public product is the Python core, Rust session engine and Solid PWA delivered as the supported stack.
Delivered
The repository-side implementation and public delivery surface are complete on
dev:The GitHub repository is PUBLIC.
Remaining publication and security gates
vogtGHCR package public and verify anonymous manifests, pull and Compose startup.The repository-side work is not waiting on another code PR. The package is currently PRIVATE, and the historical Firebase key remains reachable from old Git refs, so publication/security acceptance is not claimed.
Close condition
Close this tracker after #265, #266 and #191 record their owner-controlled security, publication and device evidence, then run the anonymous delivery smoke against the public repository and package.