Skip to content

[Product Readiness] Complete BandScope 1.0 with measurable rehearsal outcomes #958

Description

@seonghobae

Buyer-visible problem

BandScope has a strong local-first analysis foundation, a substantial security/coverage program, and many narrowly scoped feature PRs. It is not yet a complete commercial desktop product because the protected snapshot does not demonstrate the full buyer journey:

install a trusted build
→ import a real song
→ obtain measurably accurate analysis
→ actively rehearse with the analysis
→ save/recover the session
→ share a bounded handoff
→ diagnose a failure without leaking the song
→ update or roll back safely

Snapshot reviewed on 2026-08-20:

  • protected base: develop@acdbea6344fe1231c39535b575f4de35e4c607c9;
  • open pull requests inventoried before the documentation PR: 83;
  • package/runtime version: 0.1.0;
  • saved Figma file: BP30foevuRtufwRpTknZUw;
  • source-backed baseline PR: #968.

The baseline PR adds:

  • docs/product-technical-gap-baseline.md;
  • a machine-readable 83-PR queue seed;
  • ADR-0001 with the Figma file ID and product/merge-train decision;
  • APA 7th product-readiness references.

Passing unit tests or merging the current queue is necessary but not sufficient evidence of a complete rehearsal product.

Product boundary

BandScope remains a local-first rehearsal decision tool, not a notation editor or DAW. Completion work must close the rehearsal loop rather than expand into unrelated composition, multitrack production, plugin hosting, or mandatory cloud-account scope.

Completion workstreams

  • #960 — trusted signed/notarized desktop distribution, update, rollback, and release evidence;
  • #961 — active rehearsal player with transport, precise loops, count-in, role controls, and accessible interaction;
  • #962 — versioned crash-safe project format, autosave, migration, backup, and recovery;
  • #963 — redacted typed diagnostics, crash evidence, and offline support bundle;
  • #964 — licensed first-run demo and measurable time-to-first-rehearsal journey;
  • #965 — Figma, Storybook, shipped-UI, localization, and WCAG 2.2 AA parity;
  • #966 — dependency-aware merge trains and explicit PR succession.

Do not duplicate or weaken existing canonical lanes such as #770 (real-audio MIR acceptance), #781 (local-audio resource policy), #739 (handoff round trip), #610 (naruon vertical), #526 (OpenSSF evidence), #542 (quick-xml lifecycle), #779 (Node/jsdom compatibility), #847 (workflow identity), #852 (source-map evidence), and #864 (bounded native PDF reads).

Definition of BandScope 1.0 GA

Rehearsal outcome

  • A new user can install a trusted build and complete a licensed demo rehearsal without command-line setup.
  • A real local audio file traverses the production intake and analysis boundary and receives a versioned accuracy manifest under [Product Gap] Add real-audio MIR accuracy acceptance benchmarks #770.
  • The user can rehearse a selected passage repeatedly with transport and role controls, not merely inspect static output.
  • Uncertainty, unsupported capabilities, and human-correction boundaries are explicit.

Reliability and safety

  • No accepted user work is lost after crash, power interruption, schema upgrade, or partial write.
  • Every project artifact has a versioned migration and supported rollback/portable-export path.
  • Local files, paths, secrets, private audio, and project content never leak into ordinary logs or support artifacts.
  • Resource admission, cancellation, CPU/GPU parity, and bounded decoding satisfy [Security] Enforce one canonical local-audio resource budget before analysis #781.

Distribution and operability

  • Windows and macOS artifacts are signed; macOS artifacts are notarized; provenance and SBOM are attached.
  • The updater verifies signatures, supports staged rollout, and exposes a tested repair/rollback path.
  • A support bundle is deterministic, redacted, bounded, user-previewable, and useful without uploading the song.
  • Release notes, package/runtime version, updater metadata, and Figma/brand identity agree.

Accessibility and product quality

  • The first-run/import/analyze/rehearse/share/recover journey passes WCAG 2.2 AA and representative assistive-technology acceptance.
  • Graphs and timelines have exact-value tables and print/export equivalents.
  • Figma components, Storybook stories, and shipped components have a reviewed parity matrix.
  • Korean and English preserve equivalent meaning, limitations, and available actions.

Engineering evidence

  • Every open PR belongs to one dependency-aware train with one explicit disposition.
  • Stale, superseded, and duplicate PRs are closed only after unique requirements/tests are transferred.
  • Every merged implementation head has terminal-success current-head checks, qualifying independent approval, zero unresolved actionable threads, 100% repository-owned production statement/branch coverage, and complete public API documentation.
  • The final release comes only from a protected commit with reproducible build, SBOM, provenance, accuracy, accessibility, migration, recovery, and supportability evidence.

Non-goals

  • Do not call an unsigned validation artifact a release.
  • Do not convert BandScope into a DAW or notation editor.
  • Do not add cloud upload as a prerequisite for ordinary analysis or support.
  • Do not merge all inventoried PRs indiscriminately; supersede or close work that no longer forms a coherent product vertical.
  • Do not treat design labels, mocked browser paths, synthetic feature arrays, skipped GPU tests, or predecessor-head checks as production evidence.

Metadata

Metadata

Assignees

No one assigned

    Labels

    area: authAuthentication, authorization, identity, or tenant isolationarea: ci-cdCI, GitHub Actions, checks, release, or supply chainarea: dependenciesDependency or lockfile maintenancearea: securitySecurity boundary, hardening, or vulnerability preventionpriority: mediumNormal-priority or P2 workstatus: triagedOpen issue has an organization taxonomy assignmenttype: featureNew or expanded product capability

    Type

    No type

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions