Unicity project — daily brief

Friday, 17 July 2026

Coverage: Thursday, 16 July 2026 · GitHub API (author + involves sweep) Updated: 17 July 2026, 05:21 UTC
Daily StandupFriday, 17 July 2026
41 in progress3 in test
Astrid board ↗
🔧 In Progress (17)
astrid #772
Bearer revocation on principal delete
unassigned
astrid #187
Discord frontend as WASM capsule with host-side Gateway …
@MastaP
astrid #249
feat(openclaw): wire up transpiler pipeline end-to-end f…
unassigned
astrid #250
feat(capsule): impl Hook Bridge translate kernel events …
unassigned
astrid #252
feat(capsule): impl Context Engine pluggable compaction …
unassigned
astrid #514
bug: VFS security traps instead of returning Err on deni…
unassigned
astrid #653
tracking: production multi-tenancy — complete user isola…
@joshuajbouw
astrid #927
agent create: add --clone <principal> to replicate an ag…
unassigned
astrid #943
Install-hook Skills not mirrored to non-install principa…
unassigned
astrid #982
Runtime capsule install never invalidates non-default pr…
@joshuajbouw
astrid #1065
Install-time capability-approval gate: manual capsules i…
unassigned
astrid #1071
test(core): establish runtime e2e harness foundation
unassigned
astrid #1078
fetch_url agent tool hangs indefinitely despite working …
unassigned
astrid #1084
test(core): design structured fuzzing coverage for CLI, …
@joshuajbouw
astrid #1087
test(core): add parser and wire-format fuzz targets
unassigned
astrid #1107
0.9.0 host cannot instantiate capsules importing astrid:…
unassigned
astrid #1259
Add signed stable, dev, and nightly release channels
unassigned
🧪 In Test (0)
✓ Nothing in test
Sphere board ↗
🔧 In Progress (15)
sphere-api #23
Auth victim recovery flow + admin actions (Ban / Unban /…
@KruGoL
sphere-sdk #148
NostrTransportProvider rewrites wallet.json on every inb…
@MastaP
sphere-sdk #97
[TGE] Universal Unicity token exchange container format …
@vrogojin
sphere-quest #1
Sphere Quests
@igmahl @KruGoL
sphere #110
AgentSphere: L3 Wallet sync and recovery using IPFS
@vrogojin
sphere-api #17
Security: pre-bind hijack via unverified directAddress c…
unassigned
sphere-sdk-connect-example #7
Add backend demo for full wallet-auth flow + remove stal…
unassigned
sphere-api #18
feat(quests): period-bound verification for repeatable q…
@KruGoL
foundation-website #1
Migrate Foundation prototype to Next.js matching unicity…
@igmahl
sphere-sdk #274
perf: SDK API call latency on payment path measured in m…
@vrogojin
sphere-sdk #273
fix(profile,transport)(#272): decouple per-flush HEAD-ve…
@vrogojin
sphere-api #24
feat: S3 image upload across the platform
@KruGoL
sphere-sdk #308
refreshKnownBundles corrupt-OpLog auto-bypass not engagi…
@vrogojin
sphere-sdk #307
Profile-TokenStorage infinite boot-loop on unfetchable b…
@vrogojin
sphere-sdk #306
createBrowserProfileProviders doesn't inject cidRefStore…
@vrogojin
🧪 In Test (0)
✓ Nothing in test
Protocol board ↗
🔧 In Progress (8)
foundation-website #1
Migrate Foundation prototype to Next.js matching unicity…
@igmahl
sphere #128
Agent Sphere: Improve address management UX in wallet
@KruGoL
state-transition-sdk-java #48
Rewrite Java SDK based on academic paper
@martti007
state-transition-sdk-java #73
Hardening based on JS SDK issue #127
@martti007
state-transition-sdk-java #75
Switch SMT inclusion verification from version 3o to 6a
@martti007
aggregator-subscription #56
Admission semaphore (GATEWAY_MAX_IN_FLIGHT=256) caps wri…
@MastaP
state-transition-sdk-java #78
Remove current version of nametags
@martti007
state-transition-sdk-java #79
Sync Java SDK SMT/RSMT bit ordering with the spec
@martti007
🧪 In Test (0)
✓ Nothing in test
SIF board ↗
🔧 In Progress (1)
semanticd #21
P1: Identify Candidate ML models for MvP
@machmode
🧪 In Test (2)
semanticd #9
P2: Review threading model for MvP
@lploom
semanticd #48
Roll out staging environment
@b3y0urs3lf
Concierge board ↗
🔧 In Progress (0)
✓ Nothing in progress
🧪 In Test (1)
concierge #237
In-flow spend-approval prompt — agent-triggered card cha…
unassigned
PRs merged
12
Releases
0
Open PRs >7 days
36
Contributors
4
Astrid / Sphere / Network
2 / 9 / 1
Astrid2 PRs merged
AOS CE product complete with signed channels and migration
PR #29 delivers the full AOS CE product implementation, encompassing migration tooling and signed channel support, marking a major milestone for the AOS community edition. PR #4 rebuilds the AOS product site and developer guide from the ground up, ensuring documentation keeps pace with the completed feature set. Together these two PRs from @joshuajbouw bring the AOS CE surface — both the runtime and its public-facing documentation — to a shippable state. Signed channels in particular establish a verified communication layer that downstream integrators can rely on for authenticated message delivery.
aos-ce, unicity-aos.github.io
Sphere9 PRs merged
Author-controlled banner framing rendered identically everywhere
PR #18 in sphere-ui introduced the core author-chosen banner framing feature, allowing content creators to define how their banner is cropped and positioned rather than accepting a default. PR #444 in sphere carried that work into the marketplace, ensuring the selected framing is applied consistently across every screen size and device class, eliminating the visual inconsistency that existed before. PRs #24 and #26 wired the new sphere-ui 0.1.32 capability into sphere-backoffice and sphere-dev-portal respectively, giving editors in both portals access to the banner frame editor UI. This chain of PRs from @KruGoL closes the loop from component library through to every consumer surface.
sphere-ui, sphere-backoffice, sphere-dev-portal, sphere
Media size cap enforced on baked file, picker copy corrected
PR #19 corrected where the maxSize constraint is applied in sphere-ui: the limit is now enforced on the baked (processed) output file rather than the raw picked source, which is the semantically correct boundary for storage and delivery quotas. PR #20 followed up by removing the stored-size cap from the picker's advertised constraints so the UI no longer misleads authors into thinking the limit applies at selection time. PRs #25 and #27 bumped sphere-backoffice and sphere-dev-portal to sphere-ui 0.1.34 to pull in both fixes, keeping downstream portals honest about what the picker does and does not restrict. The net effect is accurate user-facing copy and a correctly enforced file-size policy across all upload flows.
sphere-ui, sphere-backoffice, sphere-dev-portal
Double-pay prevention: keep-open send codes always shown as pending
PR #442 addresses a double-payment vulnerability tracked in issues #440 and #441, where keep-open send codes could be presented as re-sendable despite a payment already being in flight. The fix forces all keep-open send codes into a persistent pending state, preventing users from triggering a second payment submission on the same code. This is a targeted safety fix by @MastaP with direct user-facing impact, protecting wallet balances from erroneous duplicate charges until a code is explicitly resolved or cancelled.
sphere

Timeline — Thursday, 16 July 2026

Thu 17:13sphere-ui #18 — feat(media): author-chosen banner framing, identical on every screen
Thu 17:49–17:50sphere-dev-portal #26 (feat(media): banner frame editor via sphere-ui 0.1.32) · sphere-backoffice #24 (feat(media): banner frame editor via sphere-ui 0.1.32)
Thu 18:29sphere-ui #19 — fix(media): enforce maxSize on the baked file, not the picked source
Thu 18:54sphere-ui #20 — fix(media): stop advertising the stored-size cap as a picking constraint
Thu 18:59–19:00sphere-dev-portal #27 (chore(deps): sphere-ui 0.1.34 — size limit on the baked file + honest picker copy) · sphere-backoffice #25 (chore(deps): sphere-ui 0.1.34 — size limit on the baked file + honest picker copy)
Thu 19:19sphere #444 — fix(marketplace): frame project banners identically on every screen
Fri 00:07sphere #442 — fix(payments): present all keep-open send codes as pending, never re-sendable (double-pay #440/#441)
Unicity Network1 PRs merged
Automatic API key downgrade on GET requests
PR #72 by @lploom introduces automatic API key privilege downgrading for GET requests hitting the aggregator-subscription service. This means that read-only requests are transparently handled with a reduced-privilege key, limiting the blast radius of any credential exposure on non-mutating endpoints. The change improves the security posture of the aggregator subscription layer without requiring callers to manage multiple keys themselves. It is a defensive, infrastructure-level hardening measure that aligns key privilege with actual request intent.
aggregator-subscription
Project board comparison Stale statuses · No Status · open PRs not tracked

Astrid board ↗Backlog 236 · In progress 17 · No Status 5 · Done 508

✗ NOT ON BOARD
MISSING
capsule-memory #3 · Open PR not tracked on any board
MISSING
capsule-react #16 · Open PR not tracked on any board
MISSING
capsule-cli #16 · Open PR not tracked on any board
MISSING
capsule-shell #16 · Open PR not tracked on any board

Sphere board ↗Backlog 31 · In progress 15 · Ready 2 · Done 99

⚠ STALE STATUS
STALE
sphere-sdk #90 · PR merged, still “Backlog” on board
✗ NOT ON BOARD
MISSING
sphere-cli #3 · Open PR not tracked on any board
MISSING
sphere-cli #9 · Open PR not tracked on any board
MISSING
sphere-cli #12 · Open PR not tracked on any board
MISSING
sphere-cli #30 · Open PR not tracked on any board
MISSING
sphere-apps #4 · Open PR not tracked on any board
MISSING
astrid-site #1 · Open PR not tracked on any board
MISSING
sphere-api #42 · Open PR not tracked on any board

Unicity Network board ↗Blocked 5 · In Dev 8 · Todo 87 · Done 362

⚠ STALE STATUS
STALE
aggregator-go #51 · PR merged, still “Todo” on board
✗ NOT ON BOARD
MISSING
bft-core #11 · Open PR not tracked on any board
MISSING
nostr-js-sdk #4 · Open PR not tracked on any board
MISSING
nostr-sdk #4 · Open PR not tracked on any board
MISSING
state-transition-sdk-js #106 · Open PR not tracked on any board
MISSING
unicity-node #9 · Open PR not tracked on any board
MISSING
js-faucet #2 · Open PR not tracked on any board
MISSING
state-transition-sdk-java #66 · Open PR not tracked on any board
MISSING
finality-gadget #18 · Open PR not tracked on any board
MISSING
MISSING
unicity-node #15 · Open PR not tracked on any board
MISSING
MISSING
ipfs-storage #14 · Open PR not tracked on any board
MISSING
ipfs-storage #15 · Open PR not tracked on any board
MISSING
astrid-capsule-sif #5 · Open PR not tracked on any board
MISSING
Boxy-Run #2 · Open PR not tracked on any board
MISSING
astrid-capsule-sif #6 · Open PR not tracked on any board
MISSING
state-transition-sdk-java #74 · Open PR not tracked on any board
MISSING
aggregator-go #166 · Open PR not tracked on any board
MISSING
state-transition-sdk-rust #14 · Open PR not tracked on any board
MISSING
state-transition-sdk-java #76 · Open PR not tracked on any board
⛔ Blocked itemsAll items in Blocked column across all project boards

Unicity Network board ↗

Team activityAll members — author + involves sweep
Joshua J. Bouw @joshuajbouw
2 PRs merged, 4 open PRs, involved in 4 items
aos-cehomebrew-taporaclesunicity-aos.github.io
Pavel Grigorenko @MastaP
1 PR merged, involved in 5 items
aggregator-subscriptionsphere
Igor Mahlinovski @igmahl
involved in 1 item
sphere
Alexander Khrushkov @KruGoL
8 PRs merged, 1 open PR
spheresphere-backofficesphere-dev-portalsphere-ui
Risto Laanoja @ristik
1 open PR
aggr-layer-paper
@b3y0urs3lf
4 open PRs, involved in 2 items
aggregator-subscription
@lploom
1 PR merged, involved in 5 items
aggregator-subscription

No activity this window

@martti007, @jvsteiner, @ahtotruu, @jait91, @vrogojin, @0xt1mo

Sweep method (permanent): Each report runs involves:USERNAME for every team member in addition to org-level PR/issue sweeps. Catches closes, reviews, comments, and assignments — not just authored items.
Long-standing open PRsAll open PRs older than 7 days — sorted oldest first
AgePRAuthor
178d EVMDraft
bft-core #11
@MastaP
161d test: add comprehensive unit tests for uncovered modules
nostr-js-sdk #4
@b3y0urs3lf
161d Add comprehensive unit tests (366 new tests)
nostr-sdk #4
@b3y0urs3lf
121d feat: KV-backed memory with add_memory tool and /memory-export command
capsule-memory #3
@joshuajbouw
100d Feature/test infrastructure
state-transition-sdk-js #106
@b3y0urs3lf
92d feat: CI/CD fixes, documentation, security policy, and release automation
unicity-node #9
@0xgetz
83d ci: harden nightly integration workflow — drop artifact upload
sphere-cli #3
@vrogojin
73d feat(trader): add 'sphere trader withdraw' subcommand
sphere-cli #9
@vrogojin
72d fix: drop the imagined { data: ... } wrapper from session/compact response reads
capsule-react #16
@joshuajbouw
68d feat(trader): add sphere trader withdraw subcommand
sphere-cli #12
@vrogojin
67d fix(faucet): use conservative transferMode for FAUCET_REQUEST sends
js-faucet #2
@vrogojin
64d Add BDD test suite covering V2 SDK functionality
state-transition-sdk-java #66
@b3y0urs3lf
57d test: FGP audit coverage (#1-#12) + hardening gap-documentation (#17)
finality-gadget #18
@b3y0urs3lf
57d fix(aggregator): classify submit_commitment/get_inclusion_proof failures as unreachable
infra-probe #1
@vrogojin
53d Forward direct tool calls + attribute by principal
capsule-cli #16
@jvsteiner
49d test: unicity-node audit coverage (#1 / #5 / #6) + hardening repros (…
unicity-node #15
@b3y0urs3lf
49d feat(acp-adapter): expose SPHERE_AGGREGATOR_URL + SPHERE_TRUSTBASE_URL env overrides
js-faucet #3
@vrogojin
48d config(sidecar): bump SIDECAR_CACHE_MAX_ENTRIES 10k -> 100k (#13)Draft
ipfs-storage #14
@vrogojin
47d Reject partial integer option parsing
sphere-cli #30
@samsamtrum
46d feat(nginx)(sphere-sdk-#370): expose /api/v0/dag/import + /api/v0/dag/export
ipfs-storage #15
@vrogojin
43d Update apps.json
sphere-apps #4
@Vadya05
40d feat: port background-process tools to the persistent process tier
capsule-shell #16
@joshuajbouw
36d fix(cli)(#48): wrapper field-trial fixes — 3-shot bootstrap, UNICITY_ env strip, identical-path bind, post-spawn SET_STRATEGY
sphere-cli #50
@vrogojin
25d chore(ci): bump actions/checkout from 6 to 7
astrid-capsule-sif #5
@dependabot[bot]
24d Migrate to @unicitylabs/sphere-sdk 0.10.3
Boxy-Run #2
@MastaP
June release8/8 done · 0 days to deadlineon trackboard ↗

✔ What's moving

All 8 release items completed on schedule
Every tracked work item for the June 2026 release has been marked done with zero open items remaining. The release is fully closed out against the original scope baseline.
Release scope fully verified and closed
Final item closure achieved at the June 30 deadline, indicating no last-minute slippage or scope creep was recorded in the Unicity project tracker.
Zero outstanding blockers at ship date
No blocked tasks, pending reviews, or unresolved dependencies are reported, suggesting integration and QA gates were cleared prior to the deadline.
Delivery cadence maintained across full cycle
Completion of 8 of 8 items reflects sustained execution velocity throughout the release cycle with no items deferred to a future milestone.

⚠ What worries

No owner or repo data provided for audit
The assessment lacks specific owner handles, repository names, and task-level metadata, making it impossible to verify accountability or trace which teams drove completion. Post-release retrospective should capture this.
Late closure leaves no buffer for defects
All items closed exactly at the June 30 deadline with zero days of margin. Any post-merge defects or smoke-test failures discovered on ship day would have no remediation window before release.
Binary completion status may mask partial quality
Items marked done do not confirm passing acceptance criteria, sign-off by QA leads, or stakeholder approval. Without attestation records, 'done' may reflect task closure rather than shippable quality.
No deferred items tracked; scope risk unverified
A clean 8-of-8 count with no deferrals could indicate that items were descoped rather than completed. Without a change log or scope delta record, regression of originally planned features cannot be ruled out.
Concentration risk if key owners are unavailable post-release
Without owner handle data, it is unknown whether completion was distributed across the team or concentrated in one or two contributors who may not be available for hotfix support after June 30.