Foundation and UX
Landing, wallet gate, static IDE, documentation, and monorepo boundaries.
One stable Web runtime and no false security boundary.
Kode ships only when each security and compatibility gate passes. Dates follow evidence; they never override protocol correctness.
Every milestone produces an independently verifiable capability. Downstream work cannot redefine upstream object formats, authorization rules, or trust boundaries.
Landing, wallet gate, static IDE, documentation, and monorepo boundaries.
One stable Web runtime and no false security boundary.
Canonical objects, authorization rules, protocol limits, and security invariants are executable.
Go and TypeScript pass one normative vector suite.
Offline repository engine with objects, commits, refs, branches, diff, and verification.
Deterministic CIDs and corruption-safe local repositories.
Move wallet authentication and repository authorization behind the Go security boundary.
Browser-created sessions cannot access protected repository data.
Replace mocked files with Monaco models and real repository operations.
A real repository can be created and committed from the browser.
Verified, resumable repository transfer across authorized go-libp2p nodes.
Two nodes synchronize safely under interruption and hostile input.
Versioned non-upgradeable contracts for repository policy, branches, PRs, and approvals.
Authorization and state-machine invariants pass audit-grade tests.
Reconcile local repository intent with finalized protected state on EVM.
Local views recover correctly from failed and reorganized transactions.
Wails client with embedded Go node, native filesystem, terminal, and secure keys.
Desktop and Web share one object and protocol implementation.
Commit-bound reviews, protected merges, PR coordination, and auditable activity.
Every protected merge is policy-valid and attributable.
Audit, recovery, performance, observability, packaging, and incident readiness.
Critical findings are closed and recovery drills pass.
Freeze the supported protocol, contract deployment, migration rules, and release policy.
Audited, versioned, monitored, and migration-ready.
Contracts begin only after canonical repository objects pass conformance tests.
Protected repository access moves behind the Go gateway before Web Alpha.
CLI, Gateway, and Desktop call the same Go application services.
Protocol utility must exist independently of speculative economics.
Build the offline Go repository engine on the proven object format: strict decoding, atomic storage, safe refs, working-tree operations, and delegated commit signatures.