Produced with model assistance. Every page on this site, and every document in the dev packs area, was drafted with a large language model and reviewed by a person before publication. Nothing on this site is a compliance assessment, and no page claims conformity to any standard. What we do not say, and why · how every claim here is evidenced

store.sgit.ai / versions / v0.1.16

v0.1.16 — reviews become a dated register, and the second one is this repository reviewing its own instrument

There are two reviews now and there will be more, so they live in a dated register at /admin/reviews/ rather than at one address: newest first, each carrying the version it was taken against and the screenshots it was taken from. A review is a moment locked — dated, kept, never rewritten — and a month from now it is the only record of what this store looked like today.

ADDING ONE IS ADDING A FILE. A review is a JSON record in data/reviews/ and a line in the register; the page, its markdown twin, its card and its place in the sort are generated. The build refuses a register entry with no file and a file with no register entry, and a check holds the cards to date order, every review to naming the version it reviewed, and every cited screenshot to existing.

THE SECOND REVIEW IS THIS REPOSITORY READING ITS OWN INSTRUMENT, and the case against is longer than the case for. The synthetic-user runs found eighteen things, three costing a sale, two of them regressions this repository had shipped four releases earlier — and two findings a human partner independently made the same week, which is the only external validity evidence the method has. Against that: the agent never chose anything. The protocol says it is shown a screenshot and decides; the runner follows a step list written beforehand, so the divergence the journeys promised was structurally impossible. The persona and their reaction were written by the same model in the same pass, which cannot be fixed and is marked won’t do rather than dressed up.

THE VAULT IS LINKED AND NOT EMBEDDED, and the page says why in those words. An embed is an iframe, an iframe is a connection to another host, and “no page here opens a network connection at all” sits in the footer of every page, in llms.txt, and behind a build check. That is a larger claim than the one that moved to put reason boxes on a review, and it is not the builder’s to spend. The slot is rendered, the read key is printed, the link works.

TWO RULES NARROWED RATHER THAN LOOSENED. A vault WRITE key stays barred from this output absolutely, with no page and no ruling that makes one acceptable. A READ key — which opens a vault and cannot write to it, verified by cloning with one — may appear for a vault in a frozen list of vaults ruled public, on that vault’s review page and nowhere else. And the secret scanner’s generic JSON pattern learned what its own header already said: a value that is publishable by design is not a finding, while a random value in a field called read_key still is.

/review/ stays where it was and says where the register went, because a published address should not start returning nothing. The sitemap and llms-full.txt now exclude what is noindex rather than what sits under one path, which is what made that stub possible.

Versionv0.1.16
Released2026-09-15
Built from commit0d873dc16cebab4660a669e08573f30c049bcba4
Sitestore.sgit.ai

Touched: assets · build.py · content · data · tools

← v0.1.17v0.1.15 →

Every release of this site is listed on the release history, and the same records are served as JSON so a script can read them without parsing a page.