The roadmap contradicts the issue tracker, and the security policy asks for an email it never gives #78

Closed
opened 2026-09-07 10:46:22 +00:00 by tiagoagueda · 0 comments
Owner

Observation

Found while auditing main. Several documents describe a project that stopped existing
some time ago, and one of them promises a contact that is not given.

What is wrong

wiki/Roadmap.md contradicts the repository

Still to come. Nothing is planned before somebody has run this for a while.

There are seven open issues across four milestones.

After version 1. A browser extension… Email ingestion and calendar synchronisation.
French and Portuguese translations.

All of those exist. postulo-chromium and postulo-firefox are the extension;
postulo-imap reads a mailbox and suggests what it says happened; postulo-dav syncs
contacts to CardDAV and interviews to CalDAV; French and Portuguese are two of the
twenty-four European Union languages that are complete.

The page opens by saying it exists "so nothing on this wiki reads as a promise", which is
the opposite of what it now does.

SECURITY.md asks for an email it does not give

…or email the maintainer if you have no account there.

No address anywhere in the file. Somebody without a Forgejo account and a vulnerability to
report has nowhere to send it — on the page whose whole purpose is to be reachable.

docs/PLAN.md stops at v0.1.0

Section 8's milestone table ends at M6, and section 9's fourth open assumption still says
the application "ships fully usable in British English; French and Portuguese arrive when
someone writes them". Twenty-three catalogues are complete and twenty-nine more exist. The
"deliberately after v1" list names four things, three of which shipped.

The status lines are ambiguous rather than wrong

README.md, wiki/Home.md and wiki/Roadmap.md all say 0.1.0, which is the truth
about the last release and nothing like the truth about the code. Milestone 0.2.0 is
complete — forty-four issues — and has never been tagged, which is deliberate: releasing is
a separate act. But a reader cannot tell the difference between "0.1.0 is current" and
"0.1.0 is the last thing anybody tagged", and the second is what is meant.

Not included

Bumping the version or tagging 0.2.0. That is a decision, not a documentation fix.

Classification

Documentation. The kind that costs trust rather than time: a roadmap that contradicts the
issue tracker teaches people not to read the roadmap.

## Observation Found while auditing `main`. Several documents describe a project that stopped existing some time ago, and one of them promises a contact that is not given. ## What is wrong ### `wiki/Roadmap.md` contradicts the repository > **Still to come.** Nothing is planned before somebody has run this for a while. There are seven open issues across four milestones. > **After version 1.** A browser extension… Email ingestion and calendar synchronisation. > French and Portuguese translations. All of those exist. `postulo-chromium` and `postulo-firefox` are the extension; `postulo-imap` reads a mailbox and suggests what it says happened; `postulo-dav` syncs contacts to CardDAV and interviews to CalDAV; French and Portuguese are two of the twenty-four European Union languages that are complete. The page opens by saying it exists "so nothing on this wiki reads as a promise", which is the opposite of what it now does. ### `SECURITY.md` asks for an email it does not give > …or email the maintainer if you have no account there. No address anywhere in the file. Somebody without a Forgejo account and a vulnerability to report has nowhere to send it — on the page whose whole purpose is to be reachable. ### `docs/PLAN.md` stops at v0.1.0 Section 8's milestone table ends at M6, and section 9's fourth open assumption still says the application "ships fully usable in British English; French and Portuguese arrive when someone writes them". Twenty-three catalogues are complete and twenty-nine more exist. The "deliberately after v1" list names four things, three of which shipped. ### The status lines are ambiguous rather than wrong `README.md`, `wiki/Home.md` and `wiki/Roadmap.md` all say **0.1.0**, which is the truth about the last *release* and nothing like the truth about the code. Milestone 0.2.0 is complete — forty-four issues — and has never been tagged, which is deliberate: releasing is a separate act. But a reader cannot tell the difference between "0.1.0 is current" and "0.1.0 is the last thing anybody tagged", and the second is what is meant. ## Not included Bumping the version or tagging 0.2.0. That is a decision, not a documentation fix. ## Classification Documentation. The kind that costs trust rather than time: a roadmap that contradicts the issue tracker teaches people not to read the roadmap.
tiagoagueda added this to the 0.3.0 milestone 2026-09-07 10:46:22 +00:00
tiagoagueda modified the milestone from 0.3.0 to 0.2.0 2026-09-07 11:44:18 +00:00
Sign in to join this conversation.
No milestone
No project
No assignees
1 participant
Notifications
Due date
The due date is invalid or out of range. Please use the format "yyyy-mm-dd".

No due date set.

Dependencies

No dependencies set.

Reference
Postulo/postulo#78
No description provided.