Promote Blueprints 0.8.0 interactive board - #83
Closed
ATAC-Helicopter wants to merge 26 commits into
Closed
ATAC-Helicopter wants to merge 26 commits into
ATAC-Helicopter wants to merge 26 commits into
Conversation
Bumps Avalonia from 11.3.12 to 12.0.3 Bumps Avalonia.Desktop from 11.3.12 to 12.0.3 Bumps Avalonia.Diagnostics from 11.3.12 to 11.3.15 Bumps Avalonia.Fonts.Inter from 11.3.12 to 12.0.3 Bumps Avalonia.Themes.Fluent from 11.3.12 to 12.0.3 --- updated-dependencies: - dependency-name: Avalonia dependency-version: 12.0.3 dependency-type: direct:production update-type: version-update:semver-patch dependency-group: nuget-all - dependency-name: Avalonia.Desktop dependency-version: 12.0.3 dependency-type: direct:production update-type: version-update:semver-patch dependency-group: nuget-all - dependency-name: Avalonia.Diagnostics dependency-version: 11.3.15 dependency-type: direct:production update-type: version-update:semver-patch dependency-group: nuget-all - dependency-name: Avalonia.Fonts.Inter dependency-version: 12.0.3 dependency-type: direct:production update-type: version-update:semver-patch dependency-group: nuget-all - dependency-name: Avalonia.Themes.Fluent dependency-version: 12.0.3 dependency-type: direct:production update-type: version-update:semver-patch dependency-group: nuget-all ... Signed-off-by: dependabot[bot] <support@github.com> Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
Establish the public project baseline with reproducible builds, canonical documentation and roadmap, branding, security controls, contribution templates, cross-platform CI, CodeQL, dependency review, and release packaging.
Validated across Windows, Linux, and macOS with CodeQL and the full test suite.
Rework the desktop shell into a usable blueprint-themed project map, add milestone-only release records, folder pickers, navigation tests, and updated documentation.
Make the blueprint canvas the primary workspace with draggable nodes, real relationship connectors, direct inspection and editing, and a compact secondary tool rail.
Add signed shared canvas layouts, machine-local viewport state, interactive pan/zoom and layout controls, validation, tests, and full canvas documentation.
Add bounded read-only source discovery, editable approval proposals, signed batch import, adaptive guidance, clear navigation, tests, and complete Source Lens documentation.
Record the alpha.2 milestone, support prerelease tags, pin the .NET Sonar scanner, and add safe disabled-by-default SonarQube Cloud analysis with activation documentation.
## Outcome Makes the blueprint map safer and more hands-on by allowing users to undo and redo node drags and auto-arrangement without bypassing signed workspace history. ## Changes - add a bounded, session-scoped canvas layout history service - expose toolbar controls plus Ctrl+Z, Ctrl+Shift+Z, and Ctrl+Y - persist every applied undo/redo as a new signed and audited layout revision - block node dragging whenever workspace trust or conflict state forbids mutation - identify post-release builds as 0.2.0-alpha.3-dev - update the changelog, roadmap, canvas engine, and user guide ## Verification - [x] `./scripts/verify.sh` - [x] Added or updated automated tests (77 passing) - [x] Performed relevant manual verification (macOS launch and toolbar rendering) - [x] Updated documentation - [x] `dotnet format Blueprints.sln --no-restore --verify-no-changes` - [x] no known vulnerable direct or transitive NuGet packages ## Risk review - Security/trust impact: layout interaction now respects `CanMutateWorkspace`; undo/redo uses the existing signed, validated, audited save path. - Workspace-format or migration impact: none. - Recovery/rollback: revert this commit; persisted layouts remain valid schema-1 documents. ## Checklist - [x] This PR targets `develop` unless it is a release promotion. - [x] The diff contains no secrets, private keys, tokens, or real confidential workspace data. - [x] New dependencies are justified (none added).
Complete the v0.3 collaboration milestone with signed invitations, hardened shared-workspace synchronization and recovery, release workflow polish, documentation, and verification.
Begin alpha 4 with advanced canvas interactions, multi-repository release readiness, provider-neutral source references, and bounded read-only issue, pull-request, release, and Project discovery.
## Summary - add an optional signed, revisioned relationship graph with user-defined directional and undirected types - validate entity endpoints, logical duplicates, bounded input, archive cleanup, audit operations, sync behavior, and whole-document conflict summaries - add inspector authoring, colored canvas projection, schema documentation, roadmap tracking, and workspace compatibility guidance ## Verification - `dotnet test Blueprints.sln --no-restore` (112 passed) - `dotnet format Blueprints.sln --no-restore --verify-no-changes` - `dotnet list Blueprints.sln package --vulnerable --include-transitive` (no vulnerable packages) - application startup smoke test
## Summary - replace GitHub CLI-backed discovery with bounded parallel REST and GraphQL reads - allow anonymous public discovery and use an environment-only token for private repositories and Projects - preserve project-linked issue classification, filter issue/pull duplicates, and bound response sizes and counts - define an exact-target, expiring, single-use approval policy for any future provider write operation - update integration status, security guidance, Source Lens docs, changelog, and roadmap ## Verification - `dotnet test Blueprints.sln --no-restore` (123 passed) - `dotnet format Blueprints.sln --no-restore --verify-no-changes` - `dotnet list Blueprints.sln package --vulnerable --include-transitive` (no vulnerable packages) - live GitHub GraphQL query contract validation - application startup smoke test
## Summary - detect GitLab.com origins, including nested group paths, and route hosted reads by provider - add bounded parallel issue, merge-request, release, and milestone discovery with anonymous public access and environment-only private credentials - generalize hosted source kinds and counts from GitHub-specific names to provider-neutral issue, planning, and change-request concepts - update integration status, security guidance, Source Lens docs, changelog, and roadmap ## Verification - `dotnet test Blueprints.sln --no-restore` (128 passed) - `dotnet format Blueprints.sln --no-restore --verify-no-changes` - `dotnet list Blueprints.sln package --vulnerable --include-transitive` (no vulnerable packages) - live GitLab.com route and endpoint contract checks - application startup smoke test
## Summary - finalize the v0.4 source-control awareness roadmap milestone - freeze the changelog with security, compatibility, and known-limitations notes - remove the alpha development suffix so release builds report 0.4.0 - add the completed milestone to release history ## Verification - `./scripts/verify.sh` (Release build, 128 tests passed) - `dotnet format Blueprints.sln --no-restore --verify-no-changes` - resolved package version: `0.4.0`
## Summary - begin the v0.5 milestone with a read-only VaultSync metadata and backup-health adapter - add a machine-local VaultSync link and health state to the Integrations workspace - define the bounded schema-1 health sidecar and future opt-in exchange-root ownership contract - harden integration settings with bounded reads, malformed-input recovery, and atomic writes - advance development versioning to `0.5.0-alpha.5-dev` and update roadmap, changelog, architecture, security, and user documentation ## Safety boundary - Blueprints confirms `vaultsync.meta.db` exists but never parses SQLite - health JSON is capped at 1 MiB, depth 16, and 32 warnings - VaultSync evidence remains machine-local and cannot establish signed workspace trust - passive detection performs no VaultSync or exchange-root writes ## Verification - `./scripts/verify.sh` (Release build, 142 tests) - `dotnet format Blueprints.sln --no-restore --verify-no-changes` - `dotnet list Blueprints.sln package --vulnerable --include-transitive` (none found) - resolved package version: `0.5.0-alpha.5-dev`
## Summary - add an explicit two-step adapter for project-specific VaultSync exchange-root registration - derive the canonical destination-owned path from detected VaultSync metadata - persist the prepared exchange link locally and surface unavailable registered roots as health warnings - keep the active collaboration root unchanged until the project is deliberately reopened - complete the v0.5 exchange-registration roadmap item and document ownership, format, and recovery boundaries ## Safety boundary - fresh exact-project/exact-destination approvals expire within ten minutes and are consumed once - registration rejects non-canonical layouts, linked internal directories, oversized or mismatched markers, and unregistered existing content - the registration marker is bounded and written atomically - no signed project data, VaultSync project metadata, backup payload, or current session path is mutated ## Verification - `./scripts/verify.sh` (Release build, 150 tests) - `dotnet format Blueprints.sln --no-restore --verify-no-changes` - `dotnet list Blueprints.sln package --vulnerable --include-transitive` (none found)
## Summary - carry structured VaultSync health evidence into release readiness - classify missing, risky, incomplete, stale, future-dated, and recent healthy recovery evidence - use a documented seven-day freshness window and five-minute future clock-skew allowance - keep VaultSync readiness advisory so core release planning remains independent - complete the v0.5 release-safety roadmap item and update user, architecture, and security guidance ## Safety boundary - diagnostics consume the bounded structured health result, never display text or SQLite - producer claims do not elevate Blueprints trust or prove backup payload integrity - VaultSync absence or risk never silently disables the explicit release action ## Verification - `./scripts/verify.sh` (Release build, 154 tests) - `dotnet format Blueprints.sln --no-restore --verify-no-changes` - `dotnet list Blueprints.sln package --vulnerable --include-transitive` (none found)
## Summary - add an end-to-end recovery drill for independently backed-up local and registered VaultSync exchange workspaces - relocate both copies, revalidate project trust and manifest continuity, and publish another signed change after restore - complete the final v0.5 roadmap item and document the exact recovery procedure and responsibility boundary ## Safety boundary - the drill validates Blueprints signatures, marker identity, manifest continuity, and continuation behavior - it does not claim or simulate VaultSync payload verification - restored copies use new paths and never overwrite the backed-up evidence ## Verification - `./scripts/verify.sh` (Release build, 155 tests) - `dotnet format Blueprints.sln --no-restore --verify-no-changes` - `dotnet list Blueprints.sln package --vulnerable --include-transitive` (none found)
## Summary - freeze the completed VaultSync recovery-integration milestone as Blueprints 0.5.0 - move the complete v0.5 record into the dated changelog - record v0.5.0 in release history and close every v0.5 roadmap item - document workspace compatibility, security boundaries, and remaining limitations ## Verification - `./scripts/verify.sh` (Release build, 155 tests) - `dotnet format Blueprints.sln --no-restore --verify-no-changes` - `dotnet list Blueprints.sln package --vulnerable --include-transitive` (none found) - resolved version: `0.5.0`
Rebuild the beginner-first desktop experience and add atomic local mutation, migrations, encrypted identity recovery, stable provider contracts, accessibility foundations, threat modeling, and support targets.
## Outcome Completes the 0.7.0 repository-workflow and blueprint-clarity milestone. - organizes related work into category, work-type, or version lanes - exposes visible 25%–250% zoom with pointer-centered scaling and fit-to-view - adds native local repository browsing plus clone, fast-forward pull, commit-all, and push - removes the former 100-item Markdown/import ceiling while retaining explicit safety bounds - suppresses hooks and submodules and rejects executable repository-local Git configuration - updates security, architecture, user, canvas, Source Lens, roadmap, changelog, and release history documentation ## Verification - ./scripts/verify.sh - dotnet format Blueprints.sln --verify-no-changes --no-restore - 181 tests passing - Release build: 0 warnings - macOS runtime review of setup, repository workbench, and a 37-item grouped canvas
Member
Author
|
Superseded by a clean promotion branch from main because the long-lived develop/main histories cannot produce a merge commit despite the verified source diff. |
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
What changed
Why
The primary workspace needed to communicate release structure, progress, dependencies, readiness, and direct manipulation clearly without creating a second source of truth.
Compatibility and security
Verification
./scripts/verify.shdotnet format Blueprints.sln --verify-no-changes --no-restore