Little Imp
July 20, 2026 · View on GitHub
Directory Structure
tasks/
backlog/ — tasks not yet started
todo/ — prioritized for current cycle
in-progress/ — actively being worked on
in-review/ — implementation complete, under review
done/ — completed tasks
Task Index
| ID | Title | Phase | Priority | Status |
|---|---|---|---|---|
| TASK-001 | littleimpd Daemon Setup | v0-alpha | high | done |
| TASK-002 | SQLite Database Schema | v0-alpha | high | done |
| TASK-003 | Bookmark Ingestion API | v0-alpha | high | done |
| TASK-004 | Content Extraction Pipeline | v0-alpha | high | done |
| TASK-005 | Keyword Search (FTS5) | v0-alpha | high | done |
| TASK-006 | HTML Bookmark Import | v0-alpha | high | done |
| TASK-007 | LLM Enrichment | v0-beta | medium | done |
| TASK-008 | Embeddings & Semantic Search | v0-beta | medium | done |
| TASK-009 | Categories & Tags API | v0-alpha | medium | done |
| TASK-010 | Export API (JSON & CSV) | v0-alpha | low | done |
| TASK-011 | Autonomous Organization Agent | v0.2 | low | done |
| TASK-012 | Library Evolution Timeline | v0.2 | low | done |
| TASK-013 | Preferences / Settings API | v0-beta | medium | done |
| TASK-014 | Frontend API Integration | v0-alpha | high | done |
| TASK-015 | Domains Page — Real Data | v0-alpha | low | done |
| TASK-016 | Review Queue UI | v0.2 | low | done |
| TASK-017 | AI Palette Integration | v0-beta | medium | done |
| TASK-018 | Shell Installer Script | v0-alpha | medium | done |
| TASK-019 | PDF Extractor | future | low | done |
| TASK-020 | YouTube Transcript Extractor | future | low | done |
| TASK-021 | Bookmark Status Actions (Pin, Archive, Read) | M1 | high | done |
| TASK-022 | Trash System (Soft Delete + 30-day Purge) | M1 | high | done |
| TASK-023 | Personal Notes on Bookmarks | M1 | high | done |
| TASK-024 | Category Management UI (Rename, Delete, Move) | M1 | high | done |
| TASK-025 | Settings Page (/settings) | M2 | high | done |
| TASK-026 | Embeddings Pipeline Integration | M3 | medium | done |
| TASK-027 | Semantic & Hybrid Search | M3 | medium | done |
| TASK-028 | Organization Agent — Full Wiring | M3 | medium | done |
| TASK-030 | Daemon Integration Tests | M4 | medium | done |
| TASK-031 | Frontend Tests | M4 | medium | done |
| TASK-032 | Distribution Readiness | M5 | low | done |
| TASK-033 | Backup & Restore | M5 | medium | done |
| TASK-034 | Category Drag-and-Drop Reparenting | M1 | medium | done |
| TASK-035 | Pipeline Stage Unit Tests | M4 | medium | done |
| TASK-036 | First-Run Experience | M5 | medium | done |
| TASK-037 | Remote Backup S3 | M5 | medium | done |
| TASK-038 | Scheduled Backup Snapshots | M5 | medium | done |
| TASK-039 | Custom Backup Destination | M5 | medium | done |
| TASK-040 | MCP Server Integration | v1.0 | medium | done |
| TASK-041 | Unify Runtime Settings with AI and Embedding Execution | v0-beta hardening | high | done |
| TASK-042 | Fix Docker Distribution and Network Safety | v0-beta hardening | high | done |
| TASK-043 | Restore Quality Gates and Add CI | v0-beta hardening | high | done |
| TASK-044 | Make Backup and Restore Safe and Match the Design | v0-beta hardening | high | done |
| TASK-045 | Create a Source-of-Truth API Contract and Regenerated Docs | v0-beta hardening | medium | done |
| TASK-046 | Adopt the Shared API Contract in the Frontend | v0-beta hardening | medium | done |
| TASK-047 | Align Roadmap, Release, and Product Documentation | v0-beta hardening | medium | done |
| TASK-048 | Release Validation and Docker Restore Hardening | v0-beta release validation | high | done |
| TASK-049 | Packaged Backup CLI Commands | next release operations | medium | done |
| TASK-050 | In-App Backup Verification UX | next release operations | medium | done |
| TASK-051 | Encrypted Backup Packages | next release operations | medium | done |
| TASK-052 | Multi-Provider AI Support | next release AI integrations | medium | done |
| TASK-053 | Native Installer Frontend Bundle Install | next release distribution polish | medium | done |
| TASK-054 | CLI Update Check Foundation | next release distribution polish | medium | done |
| TASK-055 | Daemon Update Check Service | next release distribution polish | medium | done |
| TASK-056 | In-App Update Check | next release distribution polish | medium | done |
| TASK-057 | In-App Encrypted Backup Packages | next release operations | medium | done |
| TASK-058 | MVP Evidence and Acceptance Criteria Audit | MVP readiness | high | done |
| TASK-059 | Signed Release Archive Packaging | MVP readiness | high | done |
| TASK-060 | One-Command Installer Entry Point | MVP readiness | high | done |
| TASK-061 | Packaged Upgrade Flow | MVP readiness | high | done |
| TASK-062 | Installer Matrix Validation | MVP readiness | high | done |
| TASK-063 | Homebrew Formula or Tap | MVP readiness | medium | done |
| TASK-064 | Library Reprocess and Re-Embed Jobs | MVP readiness | high | done |
| TASK-065 | Pipeline Failure Recovery UX | MVP readiness | high | done |
| TASK-066 | In-App Encrypted Backup Verify and Restore | MVP readiness | medium | done |
| TASK-067 | Post-Restore Restart and Recovery UX | MVP readiness | medium | done |
| TASK-068 | Diagnostics and Support Bundle | MVP readiness | medium | done |
| TASK-069 | Production Security Headers and Local Hardening | MVP readiness | medium | done |
| TASK-070 | Installed-App E2E Smoke Suite | MVP readiness | high | done |
| TASK-071 | MVP Release Documentation Pass | MVP readiness | high | done |
| TASK-072 | Audit Follow-Up Gaps | post-MVP polish | low | done |
| TASK-073 | Project Status Review Package | MVP readiness | medium | done |
| TASK-074 | Two-Week Engineering Presentation | post-MVP polish | low | done |
| TASK-075 | Release Candidate Freeze and Version Audit | MVP release closeout | high | done |
| TASK-076 | Signed Release Artifact Publication | MVP release closeout | high | done |
| TASK-077 | Fresh-Host Installer Matrix Evidence | MVP release closeout | high | done |
| TASK-078 | Published One-Command and CLI Upgrade Validation | MVP release closeout | high | in-progress |
| TASK-079 | Homebrew Tap Publication and Live Install Validation | MVP release closeout | medium | in-progress |
| TASK-080 | MVP First-User UX Smoke Pass | MVP release closeout | medium | done |
| TASK-081 | Public Artifact Installed-App E2E | MVP release closeout | high | done |
| TASK-082 | Final Localhost Security Regression Pass | MVP release closeout | high | done |
| TASK-083 | Release Notes and Support Readiness | MVP release closeout | medium | done |
| TASK-084 | MVP Release Decision Package | MVP release closeout | medium | done |
| TASK-085 | Grimoire Parity Scope And Non-Goals | Grimoire parity | critical | done |
| TASK-086 | Parity Task Conversion Criteria And Labels | Grimoire parity | high | done |
| TASK-087 | Daemon Network Exposure Security Boundaries | Grimoire parity | critical | done |
| TASK-088 | Recurring Parity Release Checklist | Grimoire parity | medium | done |
| TASK-089 | Read Later Bookmark Flag | Grimoire parity | high | done |
| TASK-090 | Bookmark Importance Rating (Rejected) | Grimoire parity | medium | done |
| TASK-091 | Bookmark Open Metrics | Grimoire parity | medium | done |
| TASK-092 | Bookmark Detail Metadata And Content Sections | Grimoire parity | high | done |
| TASK-093 | Bookmark Media Handling And Preview | Grimoire parity | medium | done |
| TASK-094 | Bookmark Mutation And Detail Regression Tests | Grimoire parity | high | done |
| TASK-095 | Sidebar Categories From Full Tree | Grimoire parity | high | done |
| TASK-096 | Category Detail Page | Grimoire parity | medium | done |
| TASK-097 | Category Metadata Fields | Grimoire parity | medium | done |
| TASK-098 | Tag Management Surface | Grimoire parity | high | done |
| TASK-099 | Tag Detail Pages | Grimoire parity | medium | done |
| TASK-100 | Tag Rename API And UI | Grimoire parity | medium | done |
| TASK-101 | Category And Tag Regression Tests | Grimoire parity | high | done |
| TASK-102 | Integration Token Authentication | Grimoire parity | critical | done |
| TASK-103 | Human Readable API Examples | Grimoire parity | high | done |
| TASK-104 | OpenAPI Contract Output | Grimoire parity | high | done |
| TASK-105 | One Click Capture Endpoint | Grimoire parity | high | done |
| TASK-106 | Integration CORS And Origin Controls | Grimoire parity | high | done |
| TASK-107 | Preserve Import Folder Hierarchy | Grimoire parity | high | done |
| TASK-108 | Pre Import Review | Grimoire parity | high | done |
| TASK-109 | Import Category And Tag Remapping | Grimoire parity | medium | done |
| TASK-110 | Import Result Report | Grimoire parity | medium | done |
| TASK-111 | Export Parity Fields | Grimoire parity | medium | done |
| TASK-112 | Future Grimoire Backup Import | Grimoire parity | low | done |
| TASK-113 | Import Export Regression Tests | Grimoire parity | high | done |
| TASK-114 | Library Pagination | Grimoire parity | high | done |
| TASK-115 | Server Driven Sorting | Grimoire parity | medium | done |
| TASK-116 | Library Parity Filters | Grimoire parity | high | done |
| TASK-117 | Persist Library View Preferences | Grimoire parity | medium | done |
| TASK-118 | Aggregate Count Endpoints | Grimoire parity | medium | done |
| TASK-119 | Large Library Performance Tests | Grimoire parity | medium | done |
| TASK-120 | Import Duplicate Handling Policy | Grimoire parity | high | done |
| TASK-121 | Contract Route Behavior Checks | Grimoire parity | high | done |
| TASK-125 | macOS x64 Validation or Documented Acceptance | Release unblocking | high | done |
| TASK-126 | Browser Bookmarklet Client | First-user experience | high | done |
| TASK-127 | In-App Update Notification | First-user experience | high | done |
| TASK-128 | In-App Backup Verify from Arbitrary Paths | First-user experience | medium | done |
| TASK-129 | First-Run Guided Tour and Demo Content | First-user experience | medium | done |
| TASK-130 | sqlite-vec Vector Index Integration | Performance and polish | medium | done |
| TASK-131 | GitHub Issues Extractor | Performance and polish | low | done |
| TASK-132 | Large-Library Search Performance | Performance and polish | low | done |
| TASK-133 | Parity Task Reports and Visual Verification | Verification and release readiness | medium | done |
| TASK-134 | Parity Acceptance Checklist | Verification and release readiness | medium | done |
| TASK-135 | Public Documentation Polish | Verification and release readiness | high | done |
| TASK-136 | Restore CI and Acceptance Integrity | Product reset and public beta | critical | todo |
| TASK-137 | Production Security and Dependency Hardening | Product reset and public beta | critical | todo |
| TASK-138 | Trustworthy Browser Capture Flow | Product reset and public beta | critical | todo |
| TASK-139 | Product Positioning and Beta Evidence Plan | Product reset and public beta | high | todo |
| TASK-140 | Real Browser-Daemon Core Journey E2E | Product reset and public beta | critical | backlog |
| TASK-141 | Canonical Product and Release Documentation Reset | Product reset and public beta | high | backlog |
| TASK-142 | Public Beta Distribution and Live Validation | Product reset and public beta | critical | backlog |
| TASK-143 | Private Beta Cohort and Outcome Review | Product reset and public beta | critical | backlog |
| TASK-144 | Targeted Frontend Decomposition and Loading | Post-beta maintainability | medium | backlog |
| TASK-145 | Evidence-Based Roadmap Reset | Post-beta planning | high | backlog |
| TASK-146 | Hallmark UI System Remediation | Product reset and public beta | medium | done |
Current Status
Core product tasks, v0-beta hardening tasks, release validation work, the first three next-release operations tasks, TASK-052 multi-provider AI support, TASK-053 native installer frontend bundle install, TASK-054 CLI update check foundation, TASK-055 daemon update check service, TASK-056 in-app update check, TASK-057 in-app encrypted backup package work, TASK-058 MVP evidence and acceptance criteria audit, TASK-059 signed release archive packaging work, and TASK-060 one-command installer entry point work available from this macOS workspace are complete.
TASK-061 packaged upgrade support, TASK-062 installer matrix validation,
TASK-063 Homebrew alternate install path, TASK-064 library reprocess/re-embed
support, TASK-065 pipeline failure recovery UX, TASK-066 in-app encrypted backup
verify/restore, TASK-067 post-restore restart/recovery UX, TASK-068
diagnostics/support bundles, TASK-069 local production hardening, and TASK-070
installed-artifact smoke testing are complete. TASK-063 includes the
in-repository Homebrew formula, checksum/docs coverage, Homebrew style/audit
validation, and dry-run install planning; full post-publish brew install
validation is gated on public access to the v0.1.0-beta release artifacts.
TASK-071 is complete with final MVP release documentation alignment across
user-facing, contributor, release-operator, roadmap, PRD, security, changelog,
and update-system docs. TASK-072 is complete with hybrid command-palette search
and user timeline events for manual category mutations. TASK-073 is complete
with post-MVP multi-user direction research and a focused development-server
Playwright smoke suite for documented business requirements. TASK-074 is
complete with a self-contained contributor engineering presentation, tracked
implementation plan, and local static/browser/type/test verification.
The MVP release-closeout queue is TASK-075 through TASK-084. These tasks do not add new product scope; they close the gap between the implemented app and an MVP-ready public build by freezing release metadata, publishing signed artifacts, validating fresh-host installers, validating public install/update paths, completing publication-gated Homebrew checks, smoke-testing first-user UX, extending installed-app E2E to public artifacts, rerunning localhost security regressions, preparing release/support notes, and producing the final go/no-go release decision package. TASK-075 through TASK-077 and TASK-081 through TASK-084 are complete. TASK-078 is in progress but blocked on public artifact visibility. TASK-079 is in progress with local formula checksum, test, audit, and dry-run evidence, but live Homebrew install validation remains blocked on public artifact visibility. TASK-080 is complete after a real fresh-data smoke pass with an isolated loopback daemon. TASK-084 is complete with a final no-go recommendation for public MVP promotion until unauthenticated artifact access and the dependent public validation paths are fixed or an authenticated distribution path is deliberately adopted.
The Grimoire parity workstream is now represented by TASK-085 through TASK-120,
converted from approved and refined rows in
docs/parity/grimoire-parity-task-proposals.md. The current parity batch is
local-first, single-user, loopback-first, and local-integrations-only. It covers
explicit non-goals, security boundaries, pragmatic local integration token auth,
bookmark read-later/open-metric parity, category/tag parity, import/export
workflow hardening, explicit pagination/filtering, aggregate counts, and
large-library verification. TASK-086 is complete as the conversion record.
TASK-085 is complete after locking the parity scope and non-goals across the
parity report, roadmap, release docs, and task-report index. TASK-087 is
complete after adding the canonical loopback/local-integration threat model,
public-network release gates, and release-checklist blockers for network
exposure changes. TASK-088 is complete after adding recurring Grimoire parity
release checklist coverage for API contracts, bookmark fields, category/tag
management, import/export, search/filter/pagination/aggregate behavior, local
integrations, and their required verification signals. TASK-089 is complete
after adding first-class read-later persistence, API/list/search/export
filters, frontend badges and controls, filtered exports, generated docs, visual
reporting, e2e coverage, and review hardening for validation and cache
invalidation. TASK-091 is complete with open-metric persistence, API/export
fields, shared frontend open tracking, generated docs, visual reporting, review
hardening for native external-link behavior and visible metric refresh, and
full local verification. TASK-092 is complete with bookmark detail metadata and
extracted content sections. TASK-093 is complete with local bounded media
caching, daemon-served favicon/page-preview/extracted-image paths, local-only UI
fallbacks, private-redirect and SVG cache hardening, duplicate final URL
deduping, permanent-delete cache purging, generated API docs, visual reporting,
and focused/full daemon/frontend verification. TASK-094 is complete with bookmark mutation/detail
regression coverage, and TASK-095 is complete with full-tree sidebar category
navigation for empty and nested categories. TASK-096 is complete with a
stable category detail route, metadata and child-category rendering,
category-scoped daemon pagination, sidebar route navigation, focused frontend
tests, e2e coverage, and visual reporting. TASK-097 is complete with local
category metadata persistence, validation, generated API docs, category detail
rendering/editing, focused tests, closeout verification, and visual reporting.
TASK-098 is complete with a dedicated tag management page, API-backed active
tag counts, create and delete flows, sidebar navigation, tag detail browsing
links, filtered-library hydration, focused frontend tests, daemon tag route
coverage, closeout verification, and visual reporting.
TASK-099 is complete with stable tag detail routes, tag metadata, bookmark
chip navigation, focused tag management links, daemon-paginated scoped bookmark
lists, focused tests, e2e coverage, and visual reporting.
TASK-100 is complete with atomic tag rename behavior, duplicate-name conflict
handling, generated API docs, tag management and detail rename controls, cache
consistency hardening, FTS search verification, focused daemon/frontend tests,
e2e coverage, and visual reporting.
TASK-101 is complete with focused category/tag regression coverage for empty
rows, active counts, selected filter refresh, tag delete filter/search cleanup,
category move/delete behavior, and whole-branch category depth validation.
TASK-102 is complete with managed local integration bearer tokens, hashed token
storage, redacted list output, MCP protection, optional REST bearer validation,
rotation, revocation, generated API docs, security documentation, and focused
daemon auth coverage.
TASK-103 is complete with generated request/response examples for local
integration clients across integration tokens, MCP auth failures, bookmark
create/list/detail/update, search filtering and pagination, import/export,
categories, tags, backup, and common error flows. The examples are stored in
the source API contract and regenerated into both API.md and
docs/api-contract.json, with docs drift covered by npm run docs:api:check.
TASK-104 is complete with OpenAPI 3.0 output generated from the same source
contract into docs/openapi.json, OpenAPI-only generation/check commands, and
focused generator coverage for parameters, responses, pagination schemas, and
MCP bearer-token security.
TASK-106 is complete with explicit unsafe CORS preflight rejection, missing
Origin local-client coverage, generated local CORS setup documentation,
loopback-only configured origin handling, and refreshed security-boundary
documentation.
TASK-107 is done with Netscape import folder paths preserved as local
categories, empty folder creation, duplicate folder names scoped by parent,
bookmark category assignment, generated import summary/progress fields, and
focused daemon import coverage for nested folders, empty folders, duplicates,
re-import behavior, and category route limit parity.
TASK-108 is complete with a cancelable preview-first import dialog, TASK-120
duplicate policy controls, detected folders/tags/duplicate/invalid/private row
summaries, confirm-before-commit behavior, focused frontend tests, e2e smoke
coverage, and visual reporting.
TASK-109 is complete with daemon-owned category/tag remapping for import
preview and commit, normalized remapping result data, row-level target category
and tag fields, import-dialog mapping controls, regenerated API/OpenAPI docs,
focused daemon/frontend tests, e2e coverage, visual reporting, and review
hardening for nested folder inheritance, explicit tag target validation, and
category aggregate refresh after import.
TASK-110 is complete with daemon import result payloads, generated API/OpenAPI
docs, frontend completion report UI, row-level warning/failure rendering,
focused daemon/frontend tests, e2e coverage, visual reporting, and review
hardening for post-create row failure IDs and final SSE progress parsing.
TASK-111 is complete with JSON and CSV export parity fields for notes, read
state, archive state, pinned/starred mapping, read-later state, and open
metrics, plus regenerated API/OpenAPI docs, focused daemon export coverage, and
visual task reporting.
TASK-120 is complete with non-mutating import preview classification, shared
duplicate policy semantics for active merge and archived/trashed restore-merge,
invalid/private skip reporting, generated API docs/OpenAPI updates, frontend API
helpers, SSE merged/restored progress fields, full daemon and frontend test
coverage, and visual task reporting.
TASK-113 is complete with import/export regression coverage for large but
local-friendly import fixtures, nested folders, duplicates, invalid/private
URLs, duplicate policy preview/commit states, result reports, frontend preview
row caps, JSON/CSV parity field serialization, and broader review validation.
TASK-114 is complete with daemon-backed library pagination, visible result
ranges, page-size choices, cross-page selection clearing, empty-page recovery
for library/category/tag pagination paths, focused frontend tests, e2e coverage,
and visual task reporting.
TASK-117 is complete with local-only library filter/sort/search-mode/page-size
preference persistence, page-offset exclusion, route-tag precedence for shared
links, a toolbar reset command that also resets bookmark view mode, focused hook
and page tests, and desktop/mobile visual reporting.
TASK-118 is done with page-independent active-library aggregate counts for
categories, tags, domains, read state, pinned/starred state, and read-later
state; sidebar category, tag, and domain badges now use daemon-owned aggregate
data without collapsing under selected facets, generated API/OpenAPI docs are
refreshed, and focused daemon/frontend tests cover filtered and larger-count
scenarios.
TASK-119 is done with a separate large-library performance command,
2,000-bookmark deterministic fixtures, 240-row import preview/commit coverage,
explicit budgets for list/search/filter/import/pagination paths, and documented
heavy-check usage in docs/performance.md.
Bookmark importance is rejected for this batch, TASK-105 protected local
capture is complete, TASK-112 is complete as the documented future Grimoire
backup import source-shape and field-mapping handoff,
multi-user/server account parity remains deferred, and Grimoire endpoint
aliases plus packaged browser-extension clients and extension smoke tests remain
rejected or out of scope for the current parity batch.
The TASK-125 through TASK-135 follow-up batch added release, first-user, performance, parity, and documentation work. TASK-125 through TASK-129 are recorded as complete, covering macOS x64 acceptance, browser bookmarklet capture, in-app update notification, arbitrary path encrypted-backup verification, and first-run guided tour/demo content. TASK-130 is complete with optional sqlite-vec vector indexing, durable BLOB fallback, search and organization-agent integration, fallback hardening, and a 100/1K/5K/10K nearest-neighbor benchmark matrix. TASK-131 is complete with GitHub issue API extraction, label-to-tag persistence, focused daemon tests, documentation updates, and task-report coverage. TASK-132 is complete with a 10K regression fixture, 1K/10K/50K scaling evidence, query-plan assertions, hybrid-search profiling, bulk FTS fixture setup, and safe exhaustive sqlite-vec fallback behavior, with the 10K budget enforced by a dedicated CI job. TASK-133 is complete with a synthetic parity task-report and desktop/narrow visual verification sweep linked from the task-report indexes. TASK-134 is complete with the final parity acceptance checklist and release evidence links verified. TASK-135 is complete with public-facing README, FAQ, security, contributing, task-report, and link-audit work.
The active product-reset tranche is TASK-136 through TASK-145. TASK-136 through
TASK-139 are dependency-free todo work: restore green CI and acceptance
integrity, remediate production security/dependency risk, make browser capture
trustworthy, and define the product/beta evidence plan. TASK-140 through
TASK-145 remain dependency-gated in backlog: add a real browser-daemon E2E,
reset canonical documentation, validate one usable beta distribution path, run
a 5-10 person private beta, perform targeted frontend decomposition only after
evidence, and rebuild the roadmap from observed outcomes. The former TASK-122,
TASK-123, and TASK-124 backlog split is consolidated into TASK-140 and TASK-142.
TASK-146 is complete with semantic visual-system remediation, keyboard and
touch-safe bookmark actions, responsive-header verification, focused regression
coverage, and visual task-report evidence.
Completed release validation evidence:
npm run checkpassed locally.npm run test:e2epassed historically; the current local run is blocked by a missing Playwright browser installation and the current GitHub E2E job is failing.- Docker Compose build/start/health validation passed with the host port bound to
127.0.0.1:3210:3210. docker compose downpreserved the named data volume.- Native macOS install/health/upgrade/uninstall/purge smoke passed in an isolated temporary home.
- Release-target and local markdown link audits passed.
- GitHub Actions
Quality Gatespassed for historical release-validation commits. The currentdevelophead passes lint/types/unit/docs/build, Docker, and performance jobs but fails Playwright E2E; TASK-136 owns restoration. - Linux systemd user installer smoke passed in an Ubuntu 24.04 Docker environment with systemd running as PID 1 and a non-root
systemctl --usermanager. - Installer matrix validation names the exact MVP OS targets and passed the packaged Linux archive smoke on Ubuntu 24.04 LTS and Debian 12 systemd-user containers.
- Final MVP release documentation alignment passed generated API docs drift checking and local Markdown link auditing.
- TASK-075 release-candidate freeze verified the root and daemon package
versions, release-tagged installer URLs, release-facing documentation, task
board status, API docs drift check, and local Markdown links for the
0.1.0-betarelease target. - TASK-076 generated signed macOS and Linux release archives, verified
checksums and detached GPG signatures, passed
npm run release:validate -- --require-signatures, and publishedv0.1.0-betaas a GitHub prerelease with archives, checksum files, signatures, andrelease-manifest.jsonattached. - TASK-077 reran signed-artifact Linux installer matrix validation on Ubuntu
24.04 LTS and Debian 12 systemd-user containers, confirmed install,
/healthversion0.1.0-beta, autostart, upgrade data preservation, uninstall data preservation, and explicit purge behavior, and recorded macOS arm64/x64 availability gaps in the installer matrix evidence. - TASK-081 added a published-artifact installed-app smoke mode and release
checklist command. The local installed-app smoke passed against freshly
packaged artifacts; the published-artifact command stopped before
install/runtime work because the public macOS archive URL returned
HTTP 404, preserving TASK-078 as the release-blocking visibility issue. - TASK-082 reran final localhost security regressions. The current source
daemon bound to
127.0.0.1, Docker Compose rendered a loopback-only host publish, unsafe browser origins were rejected, CSP and browser hardening headers were present, private-host/update-source blocking and guarded body/path handling stayed covered by daemon tests, diagnostics redaction now includes explicit content/notes/embedding model/vector regression coverage, and refreshed GitHub release artifacts passed checksum and GPG signature validation. - TASK-079 local Homebrew validation updated the in-repository formula to the
final signed release artifact checksums from
release/release-manifest.json, added checksum drift coverage toscripts/homebrew-formula.test.ts, passed the focused formula test, passedbrew style Formula/little-imp.rb, passedbrew audit --strict goniszewski/little-imp/little-impfor the registered tap formula shape, and passed the registered-tap Homebrew dry-run install plan. - TASK-083 added
docs/release-notes-v0.1.0-beta.mdwith final user-facing release notes covering install paths, supported OS matrix, checksum/signature guidance, validation summary, known limitations, diagnostics posture, troubleshooting links, and security reporting guidance. - TASK-084 added
docs/release-decision-v0.1.0-beta.mdwith the release identity, artifact inventory, checksum/signature status, validation matrix, explicit skipped checks, accepted MVP limitations, and a no-go decision for public promotion while public artifact URLs still returnHTTP 404.
Notes:
- TASK-029 is not present as a task file; daemon test coverage is represented by TASK-030 and TASK-035.
- TASK-047 was the final consistency pass after the implementation-facing hardening tasks landed.
- TASK-048 completed the release checklist paths available in this workspace, including a containerized Ubuntu systemd-user smoke for the Linux installer path.
- TASK-062 documents macOS 12+ x64 as a manual pre-publish target because this workspace does not have Intel macOS hardware or an x64 macOS VM.
- TASK-078 is in progress and currently blocked by repository visibility:
authenticated GitHub release inspection sees the
v0.1.0-betaprerelease and expected assets, but unauthenticated public checks for the documented tag-qualified installer and release archive URLs return404while the repository is private. TASK-079 shares the same public artifact access dependency. Several checks also depend on Homebrew tap availability. - TASK-079 is in progress. Formula checksum validation is now covered locally,
but
brew fetch --formula goniszewski/little-imp/little-impstill returnsHTTP 404for the public macOS archive URL, so livebrew install, service, health, uninstall, and data-preservation checks remain blocked. - TASK-080 is complete after adding a loopback-only
VITE_DAEMON_URLoverride for isolated smoke runs. The real fresh-data pass covered add/search/detail, degraded AI and embedding states, import, backup create/verify, encrypted package create/verify, restore recovery, diagnostics, and publication-gated update-check messaging without stopping the installed daemon on127.0.0.1:3210. - TASK-081 is complete with a documented
npm run test:e2e:installed:publishedcommand that downloads public release artifacts, verifies the archive checksum and detached signature, and runs the existing installed-app smoke against the verified archive. On May 29, 2026 the live command failed before install/runtime work because the public macOS archive URL returnedHTTP 404, so TASK-078 remains the release-blocking public visibility item. - TASK-084 is complete. The final release decision is no-go for public MVP promotion until the public installer/archive URLs are reachable and TASK-078, TASK-079, and the public-artifact smoke path are rerun successfully, or until an authenticated distribution path is explicitly chosen and validated.
- TASK-142 now consolidates the remaining public distribution, Homebrew decision, and published-artifact validation into one dependency-gated beta release task.
See docs/roadmap.md for full milestone details.