Compare commits

..
1 Commits
Author SHA1 Message Date
sneak 8076a183e0 List only after-1.0 work in the README roadmap (closes #208)
check / check (pull_request) Successful in 5m0s
The README roadmap and the TODO.md Next Step still described finished
1.0 work as remaining. The roadmap now lists only work planned after
1.0. The security item says the encryption and blob-generation code was
reviewed before 1.0, that every bug the review found was fixed, and
that the risks it accepted are listed in Accepted Risks; an outside
audit stays as after-1.0 work rather than a blocker. The error-condition
item is gone because every failure case it listed now has a
fault-injection test. Daemon mode, which the owner put after 1.0, is
added to the roadmap. TODO.md says the 1.0 work is complete on next and
that merging to main and tagging are the owner's; Future Steps points
to the roadmap.

Judgement call: dropped the human-readable size flags item; no command
flag takes a raw-integer size.

Model: opus-5-5
2026-10-01 18:59:24 +00:00
+4 -2
View File
@@ -582,8 +582,10 @@ Work planned after 1.0. Loosely ordered by priority.
### correctness and operability
* **Outside security audit.** Before 1.0 the encryption and
blob-generation code was reviewed and every finding fixed; no
outside audit has been done. age + zstd + content-defined chunking
blob-generation code was reviewed: every bug the review found was
fixed, and the risks it accepted are listed in
[Accepted Risks](docs/REPOSTRUCTURE.md#accepted-risks). No outside
audit has been done. age + zstd + content-defined chunking
is mostly off-the-shelf pieces, but the seams (key handling,
recipient parsing, manifest trust boundary, restore-time identity
validation) need an outside read.