Skip to content

Promote Blueprints 0.8.0 interactive board - #83

Closed
ATAC-Helicopter wants to merge 26 commits into
mainfrom
develop
Closed

ATAC-Helicopter wants to merge 26 commits into
mainfrom
develop

Conversation

@ATAC-Helicopter

Copy link
Copy Markdown
Member

What changed

  • replaces the changelog-like canvas with version frames and lifecycle columns
  • adds Plan, Dependencies, and Release Notes projections with direct typed-relationship authoring
  • adds compact navigation, filters, focus, minimap interaction, a tabbed inspector, and light/dark canvas resources
  • adds backward-compatible signed item lifecycle state, validation, audit history, tests, and documentation

Why

The primary workspace needed to communicate release structure, progress, dependencies, readiness, and direct manipulation clearly without creating a second source of truth.

Compatibility and security

  • signed workspace schema remains version 1
  • legacy incomplete/completed items map to Planned/Complete without rewrite
  • lifecycle and relationship edits retain trust, conflict, immutability, signing, transactional audit, and collaboration checks
  • view mode, viewport, search, filters, minimap, and collapse preferences remain machine-local

Verification

  • ./scripts/verify.sh
  • dotnet format Blueprints.sln --verify-no-changes --no-restore
  • 190 tests passing, Release build with zero warnings

ATAC-Helicopter and others added 26 commits May 17, 2026 22:35
Bumps Avalonia from 11.3.12 to 12.0.3
Bumps Avalonia.Desktop from 11.3.12 to 12.0.3
Bumps Avalonia.Diagnostics from 11.3.12 to 11.3.15
Bumps Avalonia.Fonts.Inter from 11.3.12 to 12.0.3
Bumps Avalonia.Themes.Fluent from 11.3.12 to 12.0.3

---
updated-dependencies:
- dependency-name: Avalonia
  dependency-version: 12.0.3
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: nuget-all
- dependency-name: Avalonia.Desktop
  dependency-version: 12.0.3
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: nuget-all
- dependency-name: Avalonia.Diagnostics
  dependency-version: 11.3.15
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: nuget-all
- dependency-name: Avalonia.Fonts.Inter
  dependency-version: 12.0.3
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: nuget-all
- dependency-name: Avalonia.Themes.Fluent
  dependency-version: 12.0.3
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: nuget-all
...

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
Establish the public project baseline with reproducible builds, canonical documentation and roadmap, branding, security controls, contribution templates, cross-platform CI, CodeQL, dependency review, and release packaging.
Validated across Windows, Linux, and macOS with CodeQL and the full test suite.
Rework the desktop shell into a usable blueprint-themed project map, add milestone-only release records, folder pickers, navigation tests, and updated documentation.
Make the blueprint canvas the primary workspace with draggable nodes, real relationship connectors, direct inspection and editing, and a compact secondary tool rail.
Add signed shared canvas layouts, machine-local viewport state, interactive pan/zoom and layout controls, validation, tests, and full canvas documentation.
Add bounded read-only source discovery, editable approval proposals, signed batch import, adaptive guidance, clear navigation, tests, and complete Source Lens documentation.
Record the alpha.2 milestone, support prerelease tags, pin the .NET Sonar scanner, and add safe disabled-by-default SonarQube Cloud analysis with activation documentation.
## Outcome

Makes the blueprint map safer and more hands-on by allowing users to
undo and redo node drags and auto-arrangement without bypassing signed
workspace history.

## Changes

- add a bounded, session-scoped canvas layout history service
- expose toolbar controls plus Ctrl+Z, Ctrl+Shift+Z, and Ctrl+Y
- persist every applied undo/redo as a new signed and audited layout
revision
- block node dragging whenever workspace trust or conflict state forbids
mutation
- identify post-release builds as 0.2.0-alpha.3-dev
- update the changelog, roadmap, canvas engine, and user guide

## Verification

- [x] `./scripts/verify.sh`
- [x] Added or updated automated tests (77 passing)
- [x] Performed relevant manual verification (macOS launch and toolbar
rendering)
- [x] Updated documentation
- [x] `dotnet format Blueprints.sln --no-restore --verify-no-changes`
- [x] no known vulnerable direct or transitive NuGet packages

## Risk review

- Security/trust impact: layout interaction now respects
`CanMutateWorkspace`; undo/redo uses the existing signed, validated,
audited save path.
- Workspace-format or migration impact: none.
- Recovery/rollback: revert this commit; persisted layouts remain valid
schema-1 documents.

## Checklist

- [x] This PR targets `develop` unless it is a release promotion.
- [x] The diff contains no secrets, private keys, tokens, or real
confidential workspace data.
- [x] New dependencies are justified (none added).
Complete the v0.3 collaboration milestone with signed invitations, hardened shared-workspace synchronization and recovery, release workflow polish, documentation, and verification.
Begin alpha 4 with advanced canvas interactions, multi-repository release readiness, provider-neutral source references, and bounded read-only issue, pull-request, release, and Project discovery.
## Summary
- add an optional signed, revisioned relationship graph with
user-defined directional and undirected types
- validate entity endpoints, logical duplicates, bounded input, archive
cleanup, audit operations, sync behavior, and whole-document conflict
summaries
- add inspector authoring, colored canvas projection, schema
documentation, roadmap tracking, and workspace compatibility guidance

## Verification
- `dotnet test Blueprints.sln --no-restore` (112 passed)
- `dotnet format Blueprints.sln --no-restore --verify-no-changes`
- `dotnet list Blueprints.sln package --vulnerable --include-transitive`
(no vulnerable packages)
- application startup smoke test
## Summary
- replace GitHub CLI-backed discovery with bounded parallel REST and
GraphQL reads
- allow anonymous public discovery and use an environment-only token for
private repositories and Projects
- preserve project-linked issue classification, filter issue/pull
duplicates, and bound response sizes and counts
- define an exact-target, expiring, single-use approval policy for any
future provider write operation
- update integration status, security guidance, Source Lens docs,
changelog, and roadmap

## Verification
- `dotnet test Blueprints.sln --no-restore` (123 passed)
- `dotnet format Blueprints.sln --no-restore --verify-no-changes`
- `dotnet list Blueprints.sln package --vulnerable --include-transitive`
(no vulnerable packages)
- live GitHub GraphQL query contract validation
- application startup smoke test
## Summary
- detect GitLab.com origins, including nested group paths, and route
hosted reads by provider
- add bounded parallel issue, merge-request, release, and milestone
discovery with anonymous public access and environment-only private
credentials
- generalize hosted source kinds and counts from GitHub-specific names
to provider-neutral issue, planning, and change-request concepts
- update integration status, security guidance, Source Lens docs,
changelog, and roadmap

## Verification
- `dotnet test Blueprints.sln --no-restore` (128 passed)
- `dotnet format Blueprints.sln --no-restore --verify-no-changes`
- `dotnet list Blueprints.sln package --vulnerable --include-transitive`
(no vulnerable packages)
- live GitLab.com route and endpoint contract checks
- application startup smoke test
## Summary
- finalize the v0.4 source-control awareness roadmap milestone
- freeze the changelog with security, compatibility, and
known-limitations notes
- remove the alpha development suffix so release builds report 0.4.0
- add the completed milestone to release history

## Verification
- `./scripts/verify.sh` (Release build, 128 tests passed)
- `dotnet format Blueprints.sln --no-restore --verify-no-changes`
- resolved package version: `0.4.0`
## Summary
- begin the v0.5 milestone with a read-only VaultSync metadata and
backup-health adapter
- add a machine-local VaultSync link and health state to the
Integrations workspace
- define the bounded schema-1 health sidecar and future opt-in
exchange-root ownership contract
- harden integration settings with bounded reads, malformed-input
recovery, and atomic writes
- advance development versioning to `0.5.0-alpha.5-dev` and update
roadmap, changelog, architecture, security, and user documentation

## Safety boundary
- Blueprints confirms `vaultsync.meta.db` exists but never parses SQLite
- health JSON is capped at 1 MiB, depth 16, and 32 warnings
- VaultSync evidence remains machine-local and cannot establish signed
workspace trust
- passive detection performs no VaultSync or exchange-root writes

## Verification
- `./scripts/verify.sh` (Release build, 142 tests)
- `dotnet format Blueprints.sln --no-restore --verify-no-changes`
- `dotnet list Blueprints.sln package --vulnerable --include-transitive`
(none found)
- resolved package version: `0.5.0-alpha.5-dev`
## Summary
- add an explicit two-step adapter for project-specific VaultSync
exchange-root registration
- derive the canonical destination-owned path from detected VaultSync
metadata
- persist the prepared exchange link locally and surface unavailable
registered roots as health warnings
- keep the active collaboration root unchanged until the project is
deliberately reopened
- complete the v0.5 exchange-registration roadmap item and document
ownership, format, and recovery boundaries

## Safety boundary
- fresh exact-project/exact-destination approvals expire within ten
minutes and are consumed once
- registration rejects non-canonical layouts, linked internal
directories, oversized or mismatched markers, and unregistered existing
content
- the registration marker is bounded and written atomically
- no signed project data, VaultSync project metadata, backup payload, or
current session path is mutated

## Verification
- `./scripts/verify.sh` (Release build, 150 tests)
- `dotnet format Blueprints.sln --no-restore --verify-no-changes`
- `dotnet list Blueprints.sln package --vulnerable --include-transitive`
(none found)
## Summary
- carry structured VaultSync health evidence into release readiness
- classify missing, risky, incomplete, stale, future-dated, and recent
healthy recovery evidence
- use a documented seven-day freshness window and five-minute future
clock-skew allowance
- keep VaultSync readiness advisory so core release planning remains
independent
- complete the v0.5 release-safety roadmap item and update user,
architecture, and security guidance

## Safety boundary
- diagnostics consume the bounded structured health result, never
display text or SQLite
- producer claims do not elevate Blueprints trust or prove backup
payload integrity
- VaultSync absence or risk never silently disables the explicit release
action

## Verification
- `./scripts/verify.sh` (Release build, 154 tests)
- `dotnet format Blueprints.sln --no-restore --verify-no-changes`
- `dotnet list Blueprints.sln package --vulnerable --include-transitive`
(none found)
## Summary
- add an end-to-end recovery drill for independently backed-up local and
registered VaultSync exchange workspaces
- relocate both copies, revalidate project trust and manifest
continuity, and publish another signed change after restore
- complete the final v0.5 roadmap item and document the exact recovery
procedure and responsibility boundary

## Safety boundary
- the drill validates Blueprints signatures, marker identity, manifest
continuity, and continuation behavior
- it does not claim or simulate VaultSync payload verification
- restored copies use new paths and never overwrite the backed-up
evidence

## Verification
- `./scripts/verify.sh` (Release build, 155 tests)
- `dotnet format Blueprints.sln --no-restore --verify-no-changes`
- `dotnet list Blueprints.sln package --vulnerable --include-transitive`
(none found)
## Summary
- freeze the completed VaultSync recovery-integration milestone as
Blueprints 0.5.0
- move the complete v0.5 record into the dated changelog
- record v0.5.0 in release history and close every v0.5 roadmap item
- document workspace compatibility, security boundaries, and remaining
limitations

## Verification
- `./scripts/verify.sh` (Release build, 155 tests)
- `dotnet format Blueprints.sln --no-restore --verify-no-changes`
- `dotnet list Blueprints.sln package --vulnerable --include-transitive`
(none found)
- resolved version: `0.5.0`
Rebuild the beginner-first desktop experience and add atomic local mutation, migrations, encrypted identity recovery, stable provider contracts, accessibility foundations, threat modeling, and support targets.
## Outcome

Completes the 0.7.0 repository-workflow and blueprint-clarity milestone.

- organizes related work into category, work-type, or version lanes
- exposes visible 25%–250% zoom with pointer-centered scaling and
fit-to-view
- adds native local repository browsing plus clone, fast-forward pull,
commit-all, and push
- removes the former 100-item Markdown/import ceiling while retaining
explicit safety bounds
- suppresses hooks and submodules and rejects executable
repository-local Git configuration
- updates security, architecture, user, canvas, Source Lens, roadmap,
changelog, and release history documentation

## Verification

- ./scripts/verify.sh
- dotnet format Blueprints.sln --verify-no-changes --no-restore
- 181 tests passing
- Release build: 0 warnings
- macOS runtime review of setup, repository workbench, and a 37-item
grouped canvas
@github-actions github-actions Bot added documentation Improvements or additions to documentation app Avalonia app and UI shell work security Security-sensitive change or report core Core domain model and business rules labels Jul 31, 2026
@github-actions github-actions Bot added storage Storage, schemas, and filesystem concerns collaboration Sync, merge, and collaboration logic tests Automated or manual test coverage ci Continuous integration and repository automation labels Jul 31, 2026
@ATAC-Helicopter

Copy link
Copy Markdown
Member Author

Superseded by a clean promotion branch from main because the long-lived develop/main histories cannot produce a merge commit despite the verified source diff.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

app Avalonia app and UI shell work ci Continuous integration and repository automation collaboration Sync, merge, and collaboration logic core Core domain model and business rules documentation Improvements or additions to documentation security Security-sensitive change or report storage Storage, schemas, and filesystem concerns tests Automated or manual test coverage

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant