feat(parity): source reads of Bitwarden, Passbolt, Vault and Nextcloud Passwords, sources and 38 demand rows - #761
Merged
Conversation
…gnal rows, sources per system (work in progress)
…ined rows (work in progress)
…s settled (work in progress)
…he killed readers (work in progress)
… with changelog origins (work in progress)
…e read (work in progress)
… from its proposals (work in progress)
Contributor
Quality Report — ConductionNL/keepiq @
|
| Check | PHP | Vue | Security | License | Tests |
|---|---|---|---|---|---|
| lint | ✅ | ||||
| phpcs | ✅ | ||||
| phpmd | ✅ | ||||
| psalm | ✅ | ||||
| phpstan | ✅ | ||||
| phpmetrics | ✅ | ||||
| eslint | ✅ | ||||
| stylelint | ✅ | ||||
| build | ✅ | ||||
| check-manifest | ✅ | ||||
| test-l10n | ✅ | ||||
| format | ✅ | ||||
| check-l10n-js | ✅ | ||||
| check-schema-l10n | ✅ | ||||
| composer | ✅ | ✅ 114/114 | |||
| npm | ✅ | ✅ 660/660 | |||
| app:check-code | ⏭️ | ||||
| info.xml | ✅ | ||||
| REUSE | ✅ | ||||
| lockfile sync | ✅ | ||||
| PHPUnit | ⏭️ not run for this diff — no file in this diff matches the code globs, and none carries a source extension — the heavy tier has nothing to decide about it. | ||||
| Newman | ✅ | ||||
| Playwright | ⏭️ deferred: E2E runs locally and on the promotion path only. This pull request targets development, so the suite is asked once per promotion into beta and main rather than once per push per open pull request. Run it on any branch from the Actions tab, or locally with npx playwright test. |
||||
| Hydra gates | ✅ |
Quality workflow — 2026-09-26 14:26 UTC
Download the full PDF report from the workflow artifacts.
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
What this does
Deepens the competitor columns of keepiq's capability matrix (wave 5). Four systems whose source is public are now rated from their code at a release tag, with
path:lineevidence. Every system gains asourcesobject, and 38 rows are added (23 mined from demand signals, 15 from the source reads). Data file only:openspec/parity/capabilities.json. No page is wired, and a JSON file underopenspec/cannot affect the app's suites, so they were not run.Read on
developmentat c88ff04. Branch head is the last commit of this PR.Grades, before and after
The grade enum has no value for a source read, so the grade stays
docs-only,readOnis 2026-09-26, and each system carriessourceReadplus agradeNote. No labs were booted in this lane, so no system reacheddriven. No images were pulled.Ratings per column (yes / partial / no / unknown)
Unknowns settled on the existing 191 rows: HashiCorp Vault 87 (88 unknown before, 1 left), Bitwarden 43 (all), Nextcloud Passwords 33, Passbolt 31, 1Password 2, Keeper 0. Most settle as
nofrom a stated search of the source (terms and directories are in each cell).Every rating change (evidence cut to 110 characters; the full string is in the file) on the existing 191 rows
bitwarden: 47 changes (unknown→no 33, unknown→partial 7, unknown→yes 3, partial→yes 2, yes→partial 1, no→partial 1)
onepassword: 2 changes (unknown→partial 2)
passbolt: 37 changes (unknown→no 25, unknown→partial 5, partial→yes 5, yes→partial 1, unknown→yes 1)
hashicorp-vault: 89 changes (unknown→no 72, unknown→partial 13, unknown→yes 2, partial→yes 1, yes→partial 1)
nextcloud-passwords: 37 changes (unknown→no 32, no→partial 2, yes→partial 1, partial→yes 1, unknown→yes 1)
New rows (38)
By origin: {'featureRequest': 19, 'changelog': 13, 'tender': 2, 'roadmap': 1, 'source read': 3}. The first pass added 23 rows: 20 mined, of which featureRequest 13 (Bitwarden and Passbolt community boards), roadmap 1 (Passbolt), changelog 4 (Bitwarden clients PRs, Passbolt v5.0.0), tender 2 (TenderNed 295007 Gemeente Eindhoven, CanadaBuys); the other 3 came from the Vault source read. Fifteen more came from the reader proposals: 8 from Bitwarden, 3 kept of 6 from Passbolt, and 4 kept of 6 from Nextcloud Passwords. Each has a changelog or feature-request URL.
Sources per system
Every system has a
sourcesobject. An absent field isnull, with its reason undersources.nullReasons(hydra#706).bitwarden
onepassword
passbolt
keeper
hashicorp-vault
vault server -devis the vendor's own local route)nextcloud-passwords
Verifier
hydra development
parity_verify.py --strict, fetched fresh today; the schema is the one after hydra#707. Before, on development c88ff04:After:
The after run shows only the unknown census. Most of the 150 unknown cells are 1Password and Keeper on the new rows: closed source, rated from vendor docs where the docs speak. JSON Schema validation against
capabilities.schema.json(hydra development): 0 errors.Where the method was harder
Bitwarden: several features sit behind feature flags (for example FeatureFlag.Pam on the PAM access rules); the source shows the flag, not its default per tenant, so a
yesbehind a flag means "shipped in the code", not "on for every customer".The eight rows from the Bitwarden source read carry origin
changelogwith the release that mentions the feature in the last twelve months; for three (critical applications web-v2026.6.2, member access report web-v2025.11.1, device approval server v2026.4.0) the release entry is a fix to an existing feature, so it proves the feature is live rather than new. Vault cells for these eight were rated by the lane from the Vault source.Tenders: SURF (TenderNed 260154, 269319, 270057, 307164, 311305, 314176, 316729, 334533; 334533 awarded to Bitwarden, EUR 9.5M) and Gemeente Eindhoven (295007, 306724, 345771) are in the intelligence database with eisen_count 0 and no tender_documents, tagged not-relevant or iam rather than to this category. Only the Eindhoven 295007 description yielded a row (admin-22, business use enforced). The method's "tender requirements tagged to the category" found nothing under the category and no requirement lists anywhere.
Passbolt proposals: six, deduped against the rows; three kept with a feature-request URL (admin-26 from Bitwarden community 93955, clients-23 from 157, sharing-27 from 82556), three dropped because no feature request or changelog entry could be found for them: the personal security colour and code on every dialog, admin choice of email notification content, and a dry run of directory synchronisation. All three are real Passbolt capabilities read from v5.16.0.
Passbolt: nine cells keep their docs rating because the CLI, Ansible, Terraform, SDK and mobile and desktop apps live in repositories not cloned; each cell says so.
Source reads leave products in other repos unread. Passbolt's Go CLI, Ansible, Terraform, SDK and mobile and desktop apps, and the Nextcloud Passwords browser extension and mobile apps, sit in repos that were not cloned. Those cells keep their docs rating, and each one starts with "not in the cloned repos, docs rating kept:". A few stay
unknownwith the reason.Vault's commercial features (control groups, secrets sync, automated snapshots) show in the public UI tree and changelog, but their server code is not public. They are rated from the UI routes and changelog, and each cell says so.
Nextcloud Passwords: sharing an end-to-end encrypted item downgrades it to server-side encryption (CreateShareAction.js:45,90; CreatePasswordShareHelper.php:187). This is noted on crypto-01 and crypto-22.
One keepiq cell was fixed for the schema: admin-18
built.statewaspartial, which is outside the enum. It is nowbuilding, because the API and store exist and no page reaches them.A killed lane was resumed from its partial packs. The fold is idempotent, so the packs were folded as they grew.
Pre-existing: one em-dash in the file is a verbatim quote of keepiq UI copy ('There is no trash ... cannot be undone').
🤖 Generated with Claude Code