# Public snapshot boundary Private development happens in `gamertan/tend-dev`. The canonical public repository is not a mirror of that Git history. `scripts/export-public.sh` creates an exact-file, exact-commit, allowlisted filesystem snapshot and records its source commit and tree in `PUBLIC-SNAPSHOT.json`. The exporter refuses dirty or unpushed source, destinations inside the source or Git metadata, workflow directories, non-allowlisted paths, and known private material markers. The resulting directory receives a new public root commit. Public Gitea is canonical for issues, contributions, and releases. GitHub is a read-only discovery copy of the same public tree. Tags belong only to canonical Gitea. The snapshot includes the program, security and architecture documentation, copyable examples, release configuration, and local verification scripts. Private workflows, runner configuration, repository credentials, and raw operational evidence remain outside the public root.