DevNav is distributed through GitHub Releases, the public npm bootstrap package, and the public Scoop bucket. Release payloads are checksum-verified with SHA-256; checksums verify integrity and are not digital signatures.
This roadmap covers the next 12 months from its current revision. During that horizon DevNav intends to keep Windows x64 and ARM64 as the supported platforms, maintain the native Rust + PowerShell architecture, preserve the GitHub Release, npm-bootstrap and Scoop distribution paths, pursue public WinGet catalog availability, and continue improving quality and security controls without rewriting published release history.
During the same horizon DevNav does not plan to claim Linux or macOS support, replace the native core with a JavaScript runtime, or make package runners own updates after installation. Linux/WSL remains an evaluation item rather than a committed deliverable.
- Rust, PowerShell and npm bootstrap test suites green in CI on pushes to
mainand on pull requests (pinned toolchains: Rust 1.97.1, Pester 6.1.0, PSScriptAnalyzer 1.25.0, Node 22/24/26 with 24 as the release baseline). - Coverage floors enforced in CI at >= 80% for all three languages: Rust production-only lines and regions, PowerShell commands and lines, and npm bootstrap lines (Node native coverage).
- CodeQL static analysis for Rust, GitHub Actions and
JavaScript/TypeScript; ClusterFuzzLite fuzzing of the
config.tsvparser;cargo denyadvisory/license/ban checks. - Version consistency across all channels enforced mechanically.
- Keep reducing CodeQL Rust extraction errors if upstream extractor support improves (current residual is macro-expansion-related and documented in SECURITY.md).
- Revisit OpenSSF Scorecard findings that require organizational decisions (branch protection coverage, review and maintenance signals) rather than code changes.
- Validate a real cross-version Scoop upgrade on a future release and automate WinGet submissions once a catalog installation is verified.
- GitHub releases with x64 and ARM64 application binaries.
- Per-user Windows installers and PowerShell integration.
- Publish the v0.10.0 multichannel release payload.
- Publish
@jacoboptimiza/devnavas a public npm bootstrap package. - Verify Bun, npm, pnpm and Yarn bootstrap commands from the public registry.
- Configure npm Trusted Publishing for future releases.
- Publish portable x64 and ARM64 Scoop artifacts in the GitHub Release.
- Create and validate the public
JacobOptimiza/scoop-bucketbootstrap. - Generate WinGet manifests with immutable versioned URLs and SHA-256.
- Submit the initial
JacobOptimiza.DevNavmanifests tomicrosoft/winget-pkgs. - Microsoft acceptance and public WinGet catalog propagation.
- Validate fresh Scoop install, package-manager ownership, update behavior, and uninstall on a clean GitHub-hosted Windows runner.
- Validate a real cross-version Scoop upgrade from 0.13.0 to 0.14.0.
- Complete local Chocolatey machine-owned packaging readiness for x64 and ARM64; Community publication remains pending a future release and verifier exemption.
- Automate future WinGet submissions after a real catalog installation has been verified.
The roadmap describes status only. Operational instructions live in the packaging documentation and workflows.