Goal
define an explicit application payload for standalone packaging.
Background and verified evidence
Review date: 2026-09-17. Reviewed commit: 38042cbf23b9380c626aae6c9fe168f97096c1cc. Parent: #214.
scripts/vendor builds the application portion through copy_tree, which enumerates every regular file beneath the supplied application directory. The documented workflow packages a project checkout directly. Define a reviewable distribution boundary for that application payload so development-only material cannot enter a distributable package by default. A local synthetic fixture confirmed the current traversal is broader than the runnable application. Detailed security reproduction material is retained locally rather than included in this public issue.
Scope and acceptance criteria
Validation
Use synthetic marker fixtures only, verify both included and excluded inventory, exercise the documented dist/app path, and run vendor/artifact tests plus full validation.
Non-goals
No unrelated API expansion or automatic release publication. Preserve immutable published assets and unrelated consumer files.
Project fields
- Status: Ready
- Priority: P1
- Area: Security
- Initiative: Adoption Polish
- Size: M
- Milestone: v2.2.0
- Target date: unset; no delivery date has been committed.
- Type: Task
Agent assignment
Assignee: codeforester. This is review/backlog intake; implementation has not started.
Goal
define an explicit application payload for standalone packaging.
Background and verified evidence
Review date: 2026-09-17. Reviewed commit:
38042cbf23b9380c626aae6c9fe168f97096c1cc. Parent: #214.scripts/vendorbuilds the application portion throughcopy_tree, which enumerates every regular file beneath the supplied application directory. The documented workflow packages a project checkout directly. Define a reviewable distribution boundary for that application payload so development-only material cannot enter a distributable package by default. A local synthetic fixture confirmed the current traversal is broader than the runnable application. Detailed security reproduction material is retained locally rather than included in this public issue.Scope and acceptance criteria
Validation
Use synthetic marker fixtures only, verify both included and excluded inventory, exercise the documented dist/app path, and run vendor/artifact tests plus full validation.
Non-goals
No unrelated API expansion or automatic release publication. Preserve immutable published assets and unrelated consumer files.
Project fields
Agent assignment
Assignee: codeforester. This is review/backlog intake; implementation has not started.