feat: ship Installory 1.4 audit campaign - #2
Merged
Conversation
Build the registered migrator through an internal factory so tests can stop at the shipped v1 boundary. Seed every v1 table, upgrade through v2, and verify row, foreign-key, and schema preservation.\n\nVerified: cd Installory && swift test (482 Swift Testing tests plus 21 XCTest cases).
Relinquish the implicit security-scoped access granted by NSOpenPanel and NSSavePanel after bookmark creation or file writes. Existing persisted-bookmark start/stop accounting is unchanged.\n\nVerified: signing-disabled Debug xcodebuild succeeds.\n\nManual QA: grant a custom folder, export CSV/Markdown and an environment report, and save a generated script; confirm each panel completes and repeated operations continue to work.
Add a dependency-free invariant gate for subprocess, runtime-network, entitlement, and XcodeGen-source-of-truth regressions. Extend macos-15 CI with pinned, checksum-verified XcodeGen and signing-disabled Debug/Release app builds (TEST25-001, TEST25-002).\n\nVerified locally: invariant script, bash syntax, YAML parse, executable mode, and diff checks.
Prevent limited or skipped-registry runs from replacing the bundled corpus by default. Add structural/count floors, last-good retention checks, atomic writes, scratch/check modes, and 12 dependency-free regression tests (TEST25-008, INF-09).\n\nVerified: stdlib unittest (12 passed), Python compile, existing corpus validation, and a real --limit guard that exits before network access.
Implement bounded symlink-safe size measurement, cancellation checkpoints, environment-root discovery, and partition-aware reconciliation. Fix pip REQUESTED semantics, pipx suffixed identities, and RubyGems platform/dependency/version parsing (CORE-05, CORE-07, CORE-08, CORE25-001, CORE25-002, CORE25-004–007, TEST25-005/007/009).
Sanitize every metadata-derived comment and terminal preview, target pipx environments and gem versions exactly, preserve Cargo restore sources, and replace quadratic bulk ordering with a deterministic heap (CORE25-003/004/007/009, SEC25-003, PERF25-010).
Match dependencies within manager qualifiers with PEP 503 normalization, derive scoped npm executable roots correctly, and make duplicate/orphan output identities deterministic (CORE25-008/010, APP25-018/022).
Keep coexisting gem versions distinct, sort change sets deterministically, list metadata without decoding payloads, lazy-load targeted snapshots through async GRDB APIs, and inject capture time for deterministic tests (CORE25-007/015, PERF25-008).
Fix CORE-09/11/12, CORE25-008/011/013/017, SEC25-005, and PERF25-004/005/006. Add bounded seek-based history reads, cooperative cancellation, scoped command matching, atomic persistence, bounded co-install samples, and central credential/path redaction. Tests: cd Installory && swift test (638 Swift Testing, 21 XCTest; pass)
Fix PERF25-011 by giving pipx a METADATA-only path and bounding pip RECORD/INSTALLER reads before loading. Preserve cancellation instead of converting it into a skipped distribution. Tests: cd Installory && swift test (638 Swift Testing, 21 XCTest; pass)
Preserve last-known inventory across failed partitions, hydrate all persisted surfaces off the main actor, join concurrent hydration, lazily load snapshot payloads, reconcile stale selections, and balance scoped file access. Covers APP25-001/003/004/006/007/011/012/014/015/016/017, SEC25-002/009, and PERF25-007/008/009/012. Tests: cd Installory && swift test (638 tests in 57 suites plus 21 XCTest); xcodebuild -quiet -project Installory.xcodeproj -scheme Installory -destination platform=macOS,arch=arm64 test CODE_SIGNING_ALLOWED=NO. Manual QA: relaunch with scan-on-launch disabled and inspect saved inventory/snapshots; select two snapshots and confirm lazy loading; cancel and fail script exports; revoke one grant while retaining unrelated grants; cancel an onboarding folder panel.
Show coverage-aware empty states, preserve demo provenance visibility, route external-path actions through scoped bookmarks, surface cleanup-mode zero matches, cancel the snapshot prompt with Escape, and improve onboarding and badge accessibility. Covers APP-08/09, APP25-005/008/010/013/018/019/020/021/022, and PERF25-009. Tests: cd Installory && swift test (638 tests in 57 suites plus 21 XCTest); xcodebuild -quiet -project Installory.xcodeproj -scheme Installory -destination platform=macOS,arch=arm64 test CODE_SIGNING_ALLOWED=NO. Manual QA: inspect analysis empty states after complete and partial scans; run demo mode with tracing disabled; navigate every sidebar section in Cleanup Mode; verify VoiceOver page position and restore selection; inspect manager badges in light and dark appearances.
Replace the read-only user-selected entitlement with Apple’s read-write entitlement so save-panel exports and generated scripts can be written to paths the user explicitly chooses. Persistent scanning bookmarks remain read-only through securityScopeAllowOnlyReadAccess, now enforced by the invariant check. Verification: ./scripts/check-invariants.sh; cd Installory && swift test (638 tests in 57 suites plus 21 XCTest); xcodebuild Release build with signing disabled.
Refresh the bundled offline corpus after repairing deterministic npm discovery. Coverage is now brew 8,494, casks 5,057, PyPI 14,714, and npm 5,249 for 33,514 total descriptions. Verification: corpus count/key validation; unique npm seed check; python3 -m unittest discover -s scripts/generate-descriptions/tests -p test_*.py (18 tests); cd Installory && swift test; xcodebuild Release build with signing disabled.
Match package names, qualifiers, and install paths through one Core predicate; add native toolbar search to Duplicates, Review Candidates, and AI Installed; retain whole duplicate groups for comparison context and clear stale detail selection when a result is hidden. Regression coverage: qualifier/path/whitespace matching and search-selection reconciliation. Verified 648 Swift Testing tests + 21 XCTest tests and the generated macOS app test scheme. Manual QA: search each analysis by name and scoped path, confirm search-empty copy, keyboard focus, group context, and detail clearing.
Share one cleanup eligibility contract between the app and script generator, scope selections to the current sidebar, and add bulk selection controls to Duplicates and Review Candidates. Tests: cd Installory && swift test --quiet (649 Swift Testing + 21 XCTest); xcodebuild -project Installory.xcodeproj -scheme Installory test -quiet CODE_SIGNING_ALLOWED=NO. Manual QA: enter Cleanup Mode in All, a manager, Duplicates, and Review Candidates; select rows, filter search, switch sections, confirm the displayed count and generated script contain only eligible packages; confirm read-only/MAS rows are locked and unsupported sections disable Shift-Command-K.
Encode the complete Package model as deterministic, diff-friendly JSON and expose the format through the Inventory menu and Settings save flow. Tests: InventoryExporterTests (10/10); full core suite (649 Swift Testing + 21 XCTest); xcodebuild Installory test with code signing disabled. Manual QA: load an inventory, export JSON from both Inventory > Export Inventory as JSON and Settings > Scanning, confirm the save panel suggests installory-inventory.json, then decode the file and compare package identity, dates, paths, flags, dependencies, and sizes with the UI.
Reject non-regular or oversized METADATA before loading it, then read one byte beyond the ceiling to catch a file that grows after metadata inspection. Regression: PERF25-011 oversized METADATA is rejected before its contents are loaded. Tests: cd Installory && swift test --quiet (650 Swift Testing + 21 XCTest).
Add a filesystem-only uv tool scanner with bounded receipt and metadata parsing, environment relocation support, exact cleanup targeting, provenance detection, descriptions, persistence, reconciliation, and app grant/display wiring. Keep uv reinstall output manual-review-only because receipts do not preserve a trustworthy original install request.\n\nTests: cd Installory && swift test --quiet (684 Swift Testing + 21 XCTest)\nTests: xcodebuild -project Installory.xcodeproj -scheme Installory test\nManual QA: grant ~/.local/share/uv, scan a persistent tool, verify its uv badge/version/size/path/entry points, and inspect the generated UV_TOOL_DIR-scoped uninstall command. Also verify uvx-only use is not inventoried.
Add a native macOS Table with stable multi-column sorting, nil-last size and install-date semantics, ID-based selection, cleanup controls, shared safe context actions, and persisted List/Table presentation preferences. Add View-menu shortcuts for ordinary inventory sections while preserving each mode's independent sort state.\n\nTests: xcodebuild -project Installory.xcodeproj -scheme Installory test (38 app tests)\nBuild: xcodebuild -project Installory.xcodeproj -scheme Installory build -quiet\nManual QA: switch with the segmented picker and Command-1/Command-2; sort and Shift-sort all columns; verify search, selection, cleanup checks, context menus, relaunch persistence, VoiceOver wording, and Light/Dark Mode.
Add a pure, overflow-safe disk-usage summary that distinguishes measured zero from unavailable sizes, reports per-manager coverage, and ranks a bounded deterministic largest-package list. Add the dedicated persisted sidebar selection without routing it through row filtering.\n\nTests: cd Installory && swift test --quiet (691 Swift Testing + 21 XCTest)
Add a cached Disk Usage analysis with explicit measurement coverage, overflow and unknown-size wording, a manager-level Apple Charts view, and a keyboard-selectable top-ten list that drives existing package details. Keep cleanup unavailable and reconcile selections that fall outside the ranked list.\n\nTests: xcodebuild -project Installory.xcodeproj -scheme Installory test -quiet (41 app tests)\nManual QA: inspect demo and real inventories; verify partial, all-unknown, zero, and positive states; select a top package by keyboard; refresh; then check chart labels and notices with VoiceOver, Light/Dark Mode, Increased Contrast, and a narrow window.
Track the fresh audit and final resolution ledger, record verification growth and manual QA, document explicit deferrals and the proposed 1.4.0 (10) release, and refresh README features, test counts, entitlement boundaries, and corpus cadence.\n\nVerification: 691 Swift Testing + 21 XCTest; 41 app tests; 18 description-tool tests; signing-disabled Release build; invariant gate.
Make README.md and RELEASE.md the canonical current guides, remove historical handoffs and duplicate screenshot assets, and refresh stale source comments.\n\nVerified: 712 Core tests, 46 app tests, 18 description-tool tests, invariant and plist checks, and unsigned Release build.
willytop8
force-pushed
the
campaign/2026-07-audit
branch
from
July 16, 2026 06:10
ab2aa13 to
7d0d74a
Compare
willytop8
force-pushed
the
campaign/2026-07-audit
branch
from
July 16, 2026 06:15
7d0d74a to
804940d
Compare
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Summary
Product invariants
Verification
Release
The submitted archive is version 1.4.0 (build 10) and was created after the selected-row Table crash fix. Documentation-only cleanup after that archive does not alter the submitted app binary.