You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
A discussion dedicated to the Portable Desktop module. Share your thoughts, questions, and feedback here.
Module Scorecard
Presentation & Onboarding
Credential Hygiene
Restricted-Environment Readiness
Engineering Quality
Overall
12 / 17
16 / 20
11 / 20
7 / 10
69 / 100
Drilldown
Presentation & Onboarding — 12 / 17
Criterion
Max
Score
Notes
Configuration-mode examples
12
12
Three examples cover the major modes: default install, custom url + sha256, and install_dir. All three optional inputs are demonstrated with sensible defaults.
Visual preview
5
0
No image, GIF, or video embedded in the README. The frontmatter icon field is a file reference, not an embedded visual.
Credential Hygiene — 16 / 20
Criterion
Max
Score
Notes
Secrets marked sensitive
16
16
No sensitive inputs exist (agent_id, url, sha256, install_dir are all non-secret). README examples contain no inline secrets or placeholder keys.
Non-hardcoded auth path
4
0
The module performs no authentication (public binary download). No auth path is documented. Criterion is not marked "if applicable" in the rubric, so absent support scores zero.
Restricted-Environment Readiness — 11 / 20
Criterion
Max
Score
Notes
Mirrorable artifact source
5
5
The url variable (main.tf) overrides the default GitHub release URL for both amd64 and arm64. Documented in README with a concrete example (url = "https://example.com/portabledesktop-linux-x64").
Bring-your-own binary
10
5
run.sh checks command -v portabledesktop and [ -x "${BINARY_PATH}" ] to skip download if the binary is already present. However, this behavior is not documented in the README—no section or example explains how to pre-bake the binary into an image.
Egress transparency
3
0
No dedicated README section enumerates external endpoints (GitHub releases API, custom URL) or provides notes for restricted/air-gapped environments.
Runs without sudo
2
1
Core install (download to CODER_SCRIPT_DATA_DIR, symlink to CODER_SCRIPT_BIN_DIR) requires no root. sudo is invoked only in the optional install_dir copy path (sudo mkdir, sudo cp). Sudo for an optional feature with a working non-root fallback earns half.
Engineering Quality — 7 / 10
Criterion
Max
Score
Notes
Input quality
6
3
All four variables have clear descriptions and sensible null defaults. However, no validation blocks are present (e.g., url could validate as a URL, sha256 could enforce 64-char hex, install_dir could check path format).
Test coverage
4
4
main.test.ts provides 7 comprehensive end-to-end tests (install, checksum pass/fail, skip, sudo fallback, dir creation, wget fallback) running the actual script in containers. portabledesktop.tftest.hcl adds 3 plan-level assertions. Clear testing story with strong e2e coverage.
Overall — 69 / 100
Raw 46 / 67 → round(46 / 67 × 100) = 69
Track: Utility (desktop binary installer; not an AI coding agent or IDE)
Scored against SCORECARD.md on 2026-10-05 with solstice-1.
reacted with thumbs up emoji reacted with thumbs down emoji reacted with laugh emoji reacted with hooray emoji reacted with confused emoji reacted with heart emoji reacted with rocket emoji reacted with eyes emoji
Uh oh!
There was an error while loading. Please reload this page.
Uh oh!
There was an error while loading. Please reload this page.
A discussion dedicated to the Portable Desktop module. Share your thoughts, questions, and feedback here.
Module Scorecard
Drilldown
Presentation & Onboarding — 12 / 17
url+sha256, andinstall_dir. All three optional inputs are demonstrated with sensible defaults.iconfield is a file reference, not an embedded visual.Credential Hygiene — 16 / 20
agent_id,url,sha256,install_dirare all non-secret). README examples contain no inline secrets or placeholder keys.Restricted-Environment Readiness — 11 / 20
urlvariable (main.tf) overrides the default GitHub release URL for both amd64 and arm64. Documented in README with a concrete example (url = "https://example.com/portabledesktop-linux-x64").run.shcheckscommand -v portabledesktopand[ -x "${BINARY_PATH}" ]to skip download if the binary is already present. However, this behavior is not documented in the README—no section or example explains how to pre-bake the binary into an image.CODER_SCRIPT_DATA_DIR, symlink toCODER_SCRIPT_BIN_DIR) requires no root.sudois invoked only in the optionalinstall_dircopy path (sudo mkdir,sudo cp). Sudo for an optional feature with a working non-root fallback earns half.Engineering Quality — 7 / 10
nulldefaults. However, novalidationblocks are present (e.g.,urlcould validate as a URL,sha256could enforce 64-char hex,install_dircould check path format).main.test.tsprovides 7 comprehensive end-to-end tests (install, checksum pass/fail, skip, sudo fallback, dir creation, wget fallback) running the actual script in containers.portabledesktop.tftest.hcladds 3 plan-level assertions. Clear testing story with strong e2e coverage.Overall — 69 / 100
Raw 46 / 67 → round(46 / 67 × 100) = 69
Track: Utility (desktop binary installer; not an AI coding agent or IDE)
Scored against SCORECARD.md on 2026-10-05 with
solstice-1.All reactions