pablof7z / pablof7z/nampplets

[M10] Publish GA support, compatibility, upgrade, rollback, incident, and deprecation policy

Open
#175 0 comments 0 reactions 0 assignees View on GitHub

Nobody has claimed this yet.

area: compatibility area: product area: security bdd: required documentation enhancement milestone: M10 priority: blocker type: contract
Dominant language
Rust
Stars
1
Forks
1
PR merge metrics
No merged PRs in 30d

Description

Outcome

Publish the operational contract that makes the ratified runtime supportable after GA: exact support scope, compatibility guarantees, upgrades, rollback, security response, evidence retention, deprecation, and upstream-pin movement.

BDD contract

Scenario: Existing accepted napplet encounters a compatible runtime update
  Given the napplet is covered by the accepted compatibility lock
  When the runtime updates within its published support contract
  Then it runs without source or build changes
  Or the update is blocked and rollback restores the prior accepted runtime and exact build

Scenario: Upstream or protocol movement is proposed
  Given NIP-5D, NAP, Kehto, package, NMP, toolchain, or platform authority changes
  When maintainers propose movement
  Then a dedicated compatibility change regenerates fixtures, inventories, scenarios, measurements, and reports
  And explicit owner, security, and NMP signoff is required

Scenario: Security or compatibility incident occurs
  Given a released build violates a boundary or accepted behavior
  When incident policy is invoked
  Then affected builds and evidence are identifiable
  And containment, revocation, rollback, communication, remediation, and requalification have owners and finite targets

Not done until

Policies are versioned beside the executable contracts, support claims match the generated matrix, release/rollback procedures are rehearsed, and no unresolved blocker or undisclosed exception remains.

Contributor guide

No contributing guide indexed for this repository

First steps

  1. Read the whole issue, then the project's contributing guide.
  2. Comment on the issue to say you are picking it up — it saves two people doing the same work.
  3. Fork the repository and make your change on a branch.
  4. Open a pull request that references the issue number.

Research direction

Start by locating the executable contracts, generated compatibility matrix, fixtures, inventories, scenarios, measurements, and reports referenced in the issue. Map those artifacts to the support, upgrade and rollback, security incident, deprecation, and upstream-pin policies. Done means the policies are versioned beside the contracts, claims match the generated matrix, procedures are rehearsed, and blockers or undisclosed exceptions are resolved.

Written by the indexing model from the issue text.

Assessment

Tech stack
rust
Domain
documentation, release, security
Issue type
Documentation
Difficulty
5/5
Estimated time
Over a week
Activity status
Quiet
Clarity
Needs clarification
Newbie friendliness
25/100

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.