The repository is public and MIT-licensed.
Anyone can inspect its current 37-entry tree, history, tags, SDK, documentation, workflows and declared license terms.
Repository API + LICENSE · checked 2026-08-06Transparency ledger · Checked August 6, 2026
Luczystrap publishes a GitHub repository, MIT license, Plugin SDK, release history and a hash for 1.4.9. It does not publish the current application source or a reproducible source-to-EXE chain.
Exact wording: Luczystrap is partially open source. Public historical code and SDK files can be reviewed; the current 1.4.9 application binary cannot be independently rebuilt from the public main tree.
A public repo answers “what files are published?” Reproducibility answers “can these exact inputs recreate this exact release?”
01 / One-sentence answer
“Open source” becomes misleading when repository visibility, license permissions and current binary provenance are collapsed into one badge.
Anyone can inspect its current 37-entry tree, history, tags, SDK, documentation, workflows and declared license terms.
Repository API + LICENSE · checked 2026-08-06Historical tags expose earlier application snapshots and main contains the Plugin SDK. The current app directory contains no application source.
No published chain connects complete current source, a unique version revision, exact build inputs and an independently matching EXE.
File hash is published; provenance chain is incomplete02 / Interactive evidence ledger
Select a record to see what the public evidence proves, what it cannot prove and the wording this site will use until the record changes.
Choose an evidence record
GitHub reports public visibility, main as the default branch, MIT as the detected license and archived: false. Public access permits inspection; it does not make every product version source-complete.
github.com/Luc6i/Luczystrap · visibility public · branch main · archived false · license MIT
Files, refs, issues, releases and declared repository metadata are publicly accessible.
A public repository can omit the source or build inputs used for a distributed executable.
Site wording: “public repository,” not “fully open-source current application.”
03 / Public inventory
A file can be useful evidence without answering every question. This table prevents documentation, license text or an automation file from being treated as current application source.
| Record | Current public state | What it proves | What it cannot prove | Status |
|---|---|---|---|---|
| Default branch |
main at 778690b
|
Current public revision and 37-entry tree | That this tree produced release 1.4.9 | Public |
| Application directory | One zero-byte marker named Open sourcing is closed For now
|
The current tree intentionally does not expose app files there | Implementation or behavior of the distributed app | Missing |
| Plugin SDK | Interfaces, managers, README and example plugin | Published developer contract and intended plugin surfaces | Current closed loader implementation or enforcement | Public |
| Historical tags | Earlier refs retain historical source states | Versioned evidence for older snapshots | Current 1.4.9 implementation when tags collapse | Historical |
| MIT LICENSE | Copyright 2025 Luc6i and contributors | Declared permissions, conditions and warranty disclaimer | Safety, audit result or source-to-binary identity | Published |
| Release 1.4.9 | EXE, date, size, notes and GitHub SHA-256 | Canonical asset record and exact byte identity | Complete build inputs or matching public source | Artifact |
| CI (Release) | Active workflow file targeting missing app project and .NET 6 | An intended historical automation recipe | A runnable current-main build or link to the 1.4.9 asset | Stale path |
| SECURITY.md | Private Discord DM route and claimed 48-hour acknowledgement | Project-authored reporting instructions | Dedicated email, private GitHub form or measured response performance | Partial |
License boundary: this page describes evidence, not legal advice. The MIT file states permissions and an “as is” warranty disclaimer; it does not substitute for the missing current source or a security assessment.
04 / Reproducibility chain
A trustworthy release chain needs each link. Publishing the final digest is valuable, but it cannot repair missing source, collapsed version refs or an unconnected build process.
The application project used for 1.4.9 must be available with dependencies and generated inputs.
A version tag should resolve to the exact source state represented by that release.
Toolchain versions, dependency locks and build commands must run against the published revision.
The published asset should be connected to the revision and workflow that created it.
A local file can be compared byte-for-byte with the canonical GitHub release asset.
Result: a matching hash proves that the local file equals the canonical 1.4.9 asset. It does not show which source produced those bytes or whether the code is safe.
05 / Tag collapse
These lightweight tag refs are public and useful as records. Because they resolve to one commit, they cannot distinguish the code changes claimed across the seven labels.
778690b35adc…
commit
778690b35adc…
commit
778690b35adc…
commit
778690b35adc…
commit
778690b35adc…
commit
778690b35adc…
commit
778690b35adc…
commit
06 / Maintenance snapshot
Maintenance is a time-sensitive status, not a permanent feature. These public signals are reported with dates and without converting silence into a discontinuation claim.
GitHub reports archived: false and disabled: false for the official repository.
The latest public main revision is 778690b, authored as “Modding Tools.”
Release 1.4.9 remains the latest public release and contains one Windows executable asset.
Artifact release signal · no current roadmapGitHub’s open_issues_count combines open issues and pull requests; it is workload evidence, not a bug count.
Current label: unconfirmed. The evidence does not support a current active-maintenance guarantee, but an unarchived repository and absent official closure statement also do not prove discontinuation.
07 / Vulnerability reporting
The project-authored policy is evidence of reporting intent. Response performance and confidentiality still depend on the actual private channel and maintainer behavior.
The policy directs reporters to privately message a maintainer through the project Discord and include enough information to reproduce and assess the issue.
State affected feature, version and observed behavior without publishing exploit details.
Include minimum conditions and redacted evidence; never share live credentials.
For example data exposure, account risk, unwanted execution or application failure.
The policy names Discord and states a target acknowledgement within 48 hours.
08 / Closing the gaps
These are concrete evidence improvements—not requests for marketing badges or absolute safety claims.
Include the exact 1.4.9 project, dependencies, generated inputs and source history.
Closes the largest audit boundaryGive every release one commit or annotated tag that represents its exact source state.
Restores version-level traceabilityPin toolchain and dependencies, document commands and compare independent output hashes.
Connects source to bytesPublish workflow provenance, revision identity, checksums and signing information with each asset.
Creates an auditable release chainName supported versions, current maintainers, roadmap or end-of-life state and update cadence.
Replaces inference with a project statementAdd a dedicated security address or private-reporting form, supported versions and response stages.
Improves reporter access and accountability09 / Direct answers
Each answer distinguishes a public claim, a verifiable record and the stronger conclusion that the record cannot support.
Partially. The repository, historical refs and Plugin SDK are public and MIT-licensed. The current application source is absent from the public main tree.
No complete reproducible path is published. Current app source is missing, seven 1.4-family tags share one commit, and the visible release workflow references a missing project.
It establishes declared permissions, conditions and warranty terms for material distributed under it. It does not prove safety or that an EXE matches public source.
Yes: d71c31057677bc392f680c6303dcfda9fa8f366240284dac6d5a14f7cc352424. A match proves exact asset identity, not source provenance or safety.
The public record does not explain why. It proves only that the seven named refs resolve to 778690b, so they cannot identify seven different public source states.
Current maintenance is unconfirmed. The repository is unarchived, but the latest main commit and release are from 2025. Neither “actively maintained” nor “discontinued” is proven.
Yes. It requests private maintainer contact through Discord, description, reproduction steps and impact, and states a 48-hour acknowledgement target.
No. Workflow files show intended automation. The current release workflow cannot establish a current-main source build or connection to the 1.4.9 asset.
No affiliation or endorsement is claimed. Luczystrap is a third-party project, and official Roblox policies and account actions belong on Roblox-owned sources.
10 / Primary evidence
Repository, ref and release sources are linked directly. GitHub documentation explains what release integrity and security-policy features can establish.
Checked August 6, 2026. Repository state, counts, branches, workflows and maintenance signals can change after publication. This ledger treats the official repository and GitHub API as primary records, distinguishes direct evidence from inference and does not interpret a public license, workflow badge, release digest or unarchived repository as a security certification. Luczystrap is a third-party project and is not affiliated with or endorsed by Roblox Corporation.