Jordan-Hall / Jordan-Hall/browser

[P1][EVAL-04] Signed distribution, updates and operations

Open
#104 1 comment 0 reactions 0 assignees View on GitHub
Dominant language
No language data
Stars
0
Forks
0
PR merge metrics
No merged PRs in 30d

Description

Programme: #1
Epic: #33

## Objective
Make the browser/runtime safely installable, patchable, recoverable and supportable as everyday software, with an independent fast lane for browser/security updates.

## Scope
- Signed installers/packages for declared desktop platforms.
- Signed update manifests, staged rollout channels, rollback and emergency revocation.
- Separate browser-engine security patch pipeline from feature releases.
- Dependency inventory/SBOM, binary/model/package provenance and reproducible-build goals where feasible.
- Database/schema/artifact backup, restore and migration recovery.
- Crash diagnostics and privacy-preserving telemetry with explicit consent/settings.
- Safe mode with inference/extensions/connectors disabled for recovery.
- Incident-response integration, support bundles and operational runbooks.
- Release support matrix for OS/browser/model/connectors and known limitations.

## Release rules
- Failed update must preserve or recover user-owned state without replaying consequential operations.
- Rollback cannot silently downgrade to a known-vulnerable or schema-incompatible build.
- Security patching cannot wait for unrelated feature readiness.

## Acceptance criteria
- [ ] Signed install/update/rollback paths are tested on every declared supported platform.
- [ ] Interrupted/corrupt update returns to a bootable safe prior/current build without workspace loss.
- [ ] Browser-engine emergency update can ship independently of the main feature train.
- [ ] Backup/restore exercise recovers declared workspace/artifact state and preserves transaction/audit correctness.
- [ ] Safe mode can start with local inference, extensions and third-party connectors disabled.
- [ ] Support bundle redacts credentials/private content according to policy and records versions needed for reproduction.

## Dependencies
- SEC-01
- SEC-05
- CORE-02

**First phase:** P1
**Maturity target:** P7
**Owner:** security-evaluation-release

Contributor guide

No contributing guide indexed for this repository

Research direction

No files, tests, or entry points are named. Start by reading the dependency issues SEC-01, SEC-05, and CORE-02, then decompose the scope into independently testable release, recovery, security-update, backup, and safe-mode work; done is defined by the listed acceptance criteria across supported platforms.

Written by the indexing model from the issue text.

Assessment

Domain
devops, infrastructure, release, security
Issue type
Feature
Difficulty
5/5
Estimated time
Over a week
Activity status
Active
Clarity
Needs clarification
Newbie friendliness
25/100

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.