Closes out the remaining CRA Phase 1 items (S4, P2, V3, docs-site advisories) from punktfunk-planning design/cra-readiness.md:
S4 — compliance/vendored-components.md: per-component pin location, update procedure, and watch feed for everything no package-manager advisory scan can see (pyrowave tree, libvpl, the windows-rs rev pin, FFmpeg DLLs, SDL3, gamescope + patch series, the bundled Bun runtime). This is the Art. 13(5) due-diligence record the technical file will cite.
P2 — retention verified, not assumed: Gitea serves the full release history (v0.17.x → current), stable sysext feeds publish KEEP=0, flatpak rsyncs without --delete. Recorded with a no-pruning-of-security-releases policy.
SBOM fragment — gains Bun 1.3.14 (the portable runtime bundled in the Windows installer was in no lockfile and no SBOM) and stops hardcoding the gamescope patch count.
V3 — SECURITY.md now states security fixes are free, ship without undue delay, and ride patch releases separated from features (the stable channel already worked this way, unwritten). Also drops the stale "current line is 0.22.x".
docs-site — bun update + @unom/ui 0.9.2 / @unom/app-ui 0.2.1; build, tsc --noEmit, and a served smoke test pass. Audit stays non-blocking: all 67 remaining advisories are pinned inside @unom/ui's payload chain (@payloadcms/* → fast-uri/image-size/sharp, next 16.x, sass → immutable) and can only be fixed by a ui-package release — the audit.yml comment now names that blocker precisely.
Notably: VB-CABLE is no longer bundled (audio-substrate program) — the E4 wishlist item closed itself; the watch doc records it as intentionally absent.
Closes out the remaining CRA Phase 1 items (S4, P2, V3, docs-site advisories) from `punktfunk-planning design/cra-readiness.md`:
- **S4** — `compliance/vendored-components.md`: per-component pin location, update procedure, and watch feed for everything no package-manager advisory scan can see (pyrowave tree, libvpl, the windows-rs rev pin, FFmpeg DLLs, SDL3, gamescope + patch series, the bundled Bun runtime). This is the Art. 13(5) due-diligence record the technical file will cite.
- **P2** — retention verified, not assumed: Gitea serves the full release history (v0.17.x → current), stable sysext feeds publish `KEEP=0`, flatpak rsyncs without `--delete`. Recorded with a no-pruning-of-security-releases policy.
- **SBOM fragment** — gains Bun 1.3.14 (the portable runtime bundled in the Windows installer was in no lockfile and no SBOM) and stops hardcoding the gamescope patch count.
- **V3** — SECURITY.md now states security fixes are free, ship without undue delay, and ride patch releases separated from features (the stable channel already worked this way, unwritten). Also drops the stale "current line is 0.22.x".
- **docs-site** — `bun update` + @unom/ui 0.9.2 / @unom/app-ui 0.2.1; build, `tsc --noEmit`, and a served smoke test pass. Audit stays non-blocking: all 67 remaining advisories are pinned inside @unom/ui's payload chain (@payloadcms/* → fast-uri/image-size/sharp, next 16.x, sass → immutable) and can only be fixed by a ui-package release — the audit.yml comment now names that blocker precisely.
Notably: VB-CABLE is no longer bundled (audio-substrate program) — the E4 wishlist item closed itself; the watch doc records it as intentionally absent.
bun update (fumadocs 16.14, tanstack ~1.170, react 19.2) plus @unom/ui 0.8.16
-> 0.9.2 and @unom/app-ui 0.1 -> 0.2.1. Build, tsc --noEmit and a served
smoke test all pass. The audit stays non-blocking: every remaining advisory
is pinned inside @unom/ui's own dependency tree (@payloadcms/* -> fast-uri/
image-size/sharp, next 16.x, sass -> immutable) — nothing bumpable from this
lockfile, and overrides would fork what the CMS actually ships. The comment
in audit.yml now names that blocker instead of the stale dompurify/node-tar
list.
compliance/vendored-components.md records, per vendored/bundled component,
where the pin lives, how it updates, and which feed to watch — the CRA
Art. 13(5) due-diligence evidence (S4 in the roadmap). Retention verified
while writing it: Gitea serves the full release history v0.17.x -> current,
stable sysext feeds publish KEEP=0, flatpak rsyncs without --delete.
The manual SBOM fragment gains the bundled Bun 1.3.14 runtime (portable
bun.exe in the Windows installer for the console + plugin runner — it was
in no lockfile and no SBOM) and stops hardcoding the gamescope patch count
at 3 when the series is at 9. SECURITY.md gets the one sentence Annex I
Part II asks for: security fixes are free, prompt, and ride patch releases
— which the stable channel already did, unwritten.
Blocking a user prevents them from interacting with repositories, such as opening or commenting on pull requests or issues. Learn more about blocking a user.
Closes out the remaining CRA Phase 1 items (S4, P2, V3, docs-site advisories) from
punktfunk-planning design/cra-readiness.md:compliance/vendored-components.md: per-component pin location, update procedure, and watch feed for everything no package-manager advisory scan can see (pyrowave tree, libvpl, the windows-rs rev pin, FFmpeg DLLs, SDL3, gamescope + patch series, the bundled Bun runtime). This is the Art. 13(5) due-diligence record the technical file will cite.KEEP=0, flatpak rsyncs without--delete. Recorded with a no-pruning-of-security-releases policy.bun update+ @unom/ui 0.9.2 / @unom/app-ui 0.2.1; build,tsc --noEmit, and a served smoke test pass. Audit stays non-blocking: all 67 remaining advisories are pinned inside @unom/ui's payload chain (@payloadcms/* → fast-uri/image-size/sharp, next 16.x, sass → immutable) and can only be fixed by a ui-package release — the audit.yml comment now names that blocker precisely.Notably: VB-CABLE is no longer bundled (audio-substrate program) — the E4 wishlist item closed itself; the watch doc records it as intentionally absent.