Skip to content

docs: road-to-1.0.0 roadmap - #7

Merged
asharahmed merged 1 commit into
mainfrom
docs/roadmap-1.0
Jul 17, 2026
Merged

docs: road-to-1.0.0 roadmap#7
asharahmed merged 1 commit into
mainfrom
docs/roadmap-1.0

Conversation

@asharahmed

Copy link
Copy Markdown
Owner

Adds docs/ROADMAP.md — the authoritative plan for reaching 1.0.0.

Defines the 1.0 contract (per-user authorization, a stable /api/v1, a one-command self-host, and immutable/correct compliance numbers) and organizes the gap into three milestones:

  • 0.8 — Trustworthy numbers & security model: per-project authorization (the top blocker: any Viewer currently sees all data), token revocation, immutable posture snapshots, TimeProvider.
  • 0.9 — Runnable & integrable: Docker Compose quickstart, /api/v1 + typed OpenAPI, SARIF ingestion, accepted-risk-with-expiry.
  • 1.0 — Production-operable & documented: deploy health gate + fail-closed migrations, email/digest alerts, operator docs (CHANGELOG, config reference), infra hardening from the code review.

Each item is grounded in the current code and the open review findings; ends with a Definition-of-done checklist. Docs only.

Defines what 1.0.0 means for Ravelin (real authz, versioned API, one-command
self-host, immutable/correct numbers) and the milestones that close the gap,
each with rationale grounded in the codebase + open code-review findings, and a
Definition-of-done checklist. Planning doc only; no code changes.
@asharahmed
asharahmed merged commit 1f5202b into main Jul 17, 2026
10 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant