Repository navigation
Expand file tree
/
Copy pathpubspec.yaml
More file actions
301 lines (274 loc) · 14.5 KB
/
Copy pathpubspec.yaml
File metadata and controls
301 lines (274 loc) · 14.5 KB
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
82
83
84
85
86
87
88
89
90
91
92
93
94
95
96
97
98
99
100
101
102
103
104
105
106
107
108
109
110
111
112
113
114
115
116
117
118
119
120
121
122
123
124
125
126
127
128
129
130
131
132
133
134
135
136
137
138
139
140
141
142
143
144
145
146
147
148
149
150
151
152
153
154
155
156
157
158
159
160
161
162
163
164
165
166
167
168
169
170
171
172
173
174
175
176
177
178
179
180
181
182
183
184
185
186
187
188
189
190
191
192
193
194
195
196
197
198
199
200
201
202
203
204
205
206
207
208
209
210
211
212
213
214
215
216
217
218
219
220
221
222
223
224
225
226
227
228
229
230
231
232
233
234
235
236
237
238
239
240
241
242
243
244
245
246
247
248
249
250
251
252
253
254
255
256
257
258
259
260
261
262
263
264
265
266
267
268
269
270
271
272
273
274
275
276
277
278
279
280
281
282
283
284
285
286
287
288
289
290
291
292
293
294
295
296
297
298
299
300
301
name: openstrap_edge
description: "Open-source, local-first fitness tracking companion for WHOOP 4.0 hardware. Not affiliated with WHOOP, Inc."
publish_to: 'none'
# NOTE: bumping this also requires manually bumping MARKETING_VERSION/
# CURRENT_PROJECT_VERSION for the OpenStrapWidget(Extension) and "OpenStrapWatch
# Watch App" targets in ios/Runner.xcodeproj/project.pbxproj — they aren't wired
# to FLUTTER_BUILD_NAME/FLUTTER_BUILD_NUMBER. See guides/IOS_INSTALLATION.md
# "Version Numbers".
version: 0.9.26+57
environment:
sdk: ^3.11.4
dependencies:
flutter:
sdk: flutter
cupertino_icons: ^1.0.8
# Local pure-Dart packages — the protocol byte codecs and the metric/analytics
# engine. Replace the old cloud backend: decode happens on-device, and the
# local re-layer computes metrics here (see lib/data/local_repository.dart +
# lib/compute/derivation_engine.dart). The analytics package now points at the
# 1 Hz-native family (import via `package:openstrap_analytics/onehz.dart`).
# SIBLING PACKAGES ARE PINNED TO COMMIT SHAs, NOT FLOATING `main`/BRANCH REFS.
# A floating ref means an upstream commit silently changes the behaviour of an
# already-tagged edge release (this bit us: analytics v42 rode `ref: main` into
# 0.9.13/0.9.14 with no edge change and shipped the main-thread staging ANRs).
# Bump these SHAs deliberately, as part of a reviewed edge change. Local dev
# still builds against ../analytics and ../protocol via pubspec_overrides.yaml.
# NOTE: this branch is intentionally WHOOP-4-only — protocol stays on `main`,
# NOT the gen5/multiband branch.
# Both are now MERGE COMMITS ON `main`, not PR-branch heads — the PR-branch
# SHAs these briefly pointed at are no longer the canonical location of the
# change, and a branch deletion could orphan them.
openstrap_protocol:
git:
url: https://github.com/OpenStrap/protocol.git
# Tip of protocol main — OpenStrap/protocol#20 merged: the reassembler now
# checks the length-field crc8 before trusting it (a corrupted length byte
# used to consume up to 4092 bytes of good stream before this), and
# hexToBytes rejects odd-length hex instead of silently flooring it. This
# PR sat unpinned for a full day after merging — see fix/issues #22 for
# why (edge's own release pipeline shipped the pre-fix decoder).
# protocol main @ #21 merge. Picks up the realtimeRr RR-bound (live.dart
# accepted ANY positive int16 as an interval, unlike parseRealtimeHr and
# parseR24 which both gate 200-2500ms, so a misaligned 0x28 frame could
# hand a 5ms "beat" to live HRV/coherence) plus the historical-family
# activity/steps_inc null-instead-of-0 fix. Edge does not read the latter
# two fields, so only the RR bound is behaviour-visible here.
# Verified present: `git show <sha>:lib/src/live.dart | grep -c kMinRrMs`.
ref: 7edcb3e377329968118c62cb03a81d95e2f6db8e
openstrap_analytics:
git:
url: https://github.com/OpenStrap/analytics.git
# analytics main @ #34 merge. Two hops in one: #32 (the HR-onset bypass
# for low-limb-swing cardio) had already merged and this pin was still
# sitting on its PR-branch head, and #34 lands the sleep-stager rewrite.
#
# #34 replaces the deep/REM boolean conjunctions with weighted robust-z
# scores. Measured against 99 PSG-labelled wrist nights (DREAMT), the old
# rules scored kappa 0.036 — deep PPV 5.7% against a 4.5% base rate, REM
# 12.1% against 14.0%, i.e. at or below chance — because the deep rule
# AND-ed one good axis, one null axis (rmssd, d -0.13) and one INVERTED
# axis (mean HR, d +0.31), so they could only co-fire by luck. That is
# what produced 30-second deep specks the 3-min bout rule then deleted.
# Now kappa 0.128 (0.132 held out), deep 53.0/12.9 sens/PPV, REM
# 52.6/20.7. Cutoffs are calibrated on OUR captures, not DREAMT — the
# DREAMT-optimal values under-called REM badly on real WHOOP data.
# Verified present: `git show <sha>:lib/src/onehz/sleep/cardio_stager.dart
# | grep -E 'classifyCardioEpochs|_remScoreCut = 0.5'`.
#
# analytics main @ #35 merge (1fb34dc). Neither side of this conflict was
# right: HEAD had #35's PR-BRANCH head (38a8636, never on main) and main
# had the older #38 merge (c3a30be). This SHA is analytics main and carries
# all three hops this release needs -- #38 (nap detector), #39 (the awake-HR
# baseline P0 that shipped inside #38), and #35 (the 1 Hz step estimate
# deleted + movement minutes on measured evidence), the sibling half of
# THIS branch.
#
# Verified against the SHA: `dailyStepEstimate` absent,
# `dailyActiveMinutes` present in lib/src/onehz/motion/steps.dart.
#
# analytics main @ #41 merge (ebe45da). Adds `journalNumericCorrelations`
# — Spearman rho + Theil-Sen slope over journal fields that carry a dose,
# which the typed journal entries shipped in edge #218 had no way to
# correlate. Nothing else changed; #41 only appends to coaching.dart.
#
# Verified against the SHA:
# `git show ebe45da:lib/src/onehz/human/coaching.dart |
# grep -E 'journalNumericCorrelations|class JournalNumericDay'`
#
# analytics main @ #42 merge (e047c59). Names the sample gap cap that
# `estimateBoutCalories` applies when the next HR sample is late, so the
# live workout scorer in app_state can read the same 150 s rather than
# restating it. A default-argument literal is unreachable from another
# package, so the second copy was going to drift the day the cap moved.
#
# Verified against the SHA:
# `git show e047c59:lib/src/onehz/workout/calories.dart |
# grep defaultMergeGapCapS`
ref: e047c5920ea2e0def28f028d0fc990c1fe64cd6b
# BLE — flutter_blue_plus is the maintained cross-platform GATT client.
flutter_blue_plus: ^1.36.8
# Local raw-first storage.
sqflite: ^2.4.1
path: ^1.9.0
path_provider: ^2.1.5
# Unwrapping the archives users actually pick on the import screen: a WHOOP
# "My Data" export is a ZIP of CSVs, and a NOOP `.noopbak` is a ZIP holding a
# SQLite database (issues #199, #160). Already present transitively; declared
# directly because `lib/import/import_container.dart` imports it.
archive: ^4.0.9
# Background scheduled derivation (the heavy nightly pass: sleep staging +
# 24-h spectra). Android: a real OS-scheduled WorkManager job. iOS: see the
# honest caveat in lib/compute/background_derivation.dart — app-killed heavy
# compute is opportunistic via BGTaskScheduler, never guaranteed.
workmanager: ^0.9.0
# HTTP — retained ONLY for the OTA self-update pointer (see lib/sync/update_service.dart)
# and the AI Coach's direct LLM (BYOK) calls. No backend / auth traffic anymore.
http: ^1.2.2
# State + small settings persistence.
provider: ^6.1.2
shared_preferences: ^2.3.3
# Charts (for the future server-analytics view).
fl_chart: ^0.69.2
# Interactive maps for GPS workout routes (run/ride/walk). Raster tiles are
# fetched on demand from CARTO (basemaps.cartocdn.com) — OSM data, but served
# by CARTO rather than tile.openstreetmap.org, whose tile-usage policy does
# not permit app traffic. No cloud API keys, no Google/Mapbox. The
# "© OpenStreetMap contributors" attribution is rendered on every map.
# Recorded GPS points are stored on-device only (workout_route table) and are
# never uploaded — but the tile requests do tell CARTO which area is on
# screen, which PRIVACY.md states.
# flutter_map_tile_caching (offline tile cache) is a documented follow-up — it
# pulls heavier native storage deps, so v1 uses live CARTO tiles only.
flutter_map: ^7.0.2
latlong2: ^0.9.1
geolocator: ^13.0.2
# Type: Manrope + Barlow Condensed are BUNDLED under assets/fonts/ (declared
# in flutter.fonts below), not pulled at runtime — see the note there.
# Icon packs backing lib/ui/kit/os_icons.dart (see that file's header for the
# full per-concept rationale). Mixed deliberately — each pack is used only
# for the concepts it's genuinely best at, normalized to one consistent
# size/weight by OsAppIcon:
# - phosphor_flutter — Duotone weight; the primary "hero" biometric/
# domain glyphs (closest replacement for the old illustrations).
# - solar_icons — Bold weight; literal sport + sleep-stage glyphs.
# - iconsax_flutter — battery/bluetooth variants + the heartbeat-zigzag
# "activity" glyph (cardio/resting-HR family).
# - fluentui_system_icons — Regular weight; plain monochrome UI chrome
# (arrows, check, settings, calendar…) — reads crisper flat than duotone
# at small utility sizes.
# - hugeicons — used for exactly the 2 concepts it wins outright
# (a literal ECG waveform + a literal blood-drop); nothing else uses it.
hugeicons: ^0.0.11
solar_icons: ^0.1.0
iconsax_flutter: ^1.0.1
fluentui_system_icons: ^1.1.273
phosphor_flutter: ^2.1.0
# Declarative motion language for the design system (entrance stagger, press
# pops, count-ups, shimmer) — one consistent vocabulary instead of hand-rolled
# AnimationControllers in every component. See lib/ui/design/motion.dart.
flutter_animate: ^4.5.2
# Injectable clock (RouteTracker's stall watchdog) — was a transitive dep via
# fake_async/flutter_test; declared directly since lib/ code now imports it.
# `clock.now()` instead of raw DateTime.now() lets fakeAsync tests control
# time deterministically instead of needing a real multi-second sleep.
clock: ^1.1.2
# Cold-start splash video (assets/splash/splashscreen.mp4) shown while AppState
# initializes; dismissed the instant the route gate resolves. See
# lib/ui/splash/boot_splash.dart.
video_player: ^2.9.2
# Share recap cards (rendered card → image → share sheet).
share_plus: ^10.1.4
# File picker for data imports (NOOP raw CSV, Edge .db backup, WHOOP export CSV).
file_picker: ^8.1.6
# Apple Health (HealthKit, iOS) + Google Health Connect (Android) — export each
# day's derived metrics to the platform health store.
health: ^11.1.1
# Open the Health Connect app/settings so the user can grant per-app access
# manually (the reliable path when its in-app request dialog is locked out).
android_intent_plus: ^5.1.0
# Opt-in, consent-gated companion telemetry + health-data contribution:
# • device_info_plus — OEM / model / OS for crash-report context
# • battery_plus — phone battery + charging state (upload gate)
# • connectivity_plus — Wi-Fi check (only upload the heavy .db on unmetered)
# • uuid — stable anonymous install id (the device_id anchor)
device_info_plus: ^10.1.2 # capped <11 by `health`
battery_plus: ^6.1.0
connectivity_plus: ^6.1.0
uuid: ^4.5.1
# Home/lock-screen widget bridge (writes a snapshot to the App Group → WidgetKit).
home_widget: ^0.6.0
# OS-level notifications (band battery low / charging, health alerts, recovery,
# scheduled reminders). The single display layer; see lib/notify/. Local +
# scheduled only (no FCM — the app is cloud-free).
flutter_local_notifications: ^18.0.1
# zonedSchedule needs an initialized tz database + the device's IANA zone, so
# wind-down / weekly-recap nudges fire at the right wall-clock time.
timezone: ^0.9.4
flutter_timezone: ^3.0.1
# OTA self-update (Android sideload): read our own version, download + install the
# signed APK from the backend's update pointer, with a browser fallback.
package_info_plus: ^8.1.0
ota_update: ^7.1.0
url_launcher: ^6.3.0
notification_listener_service: ^1.0.0
installed_apps: ^2.1.1
flutter_secure_storage: ^10.3.1
gpt_markdown: ^1.1.7
firebase_core: ^4.11.0
firebase_crashlytics: ^5.2.4
firebase_performance: ^0.11.4+3
firebase_analytics: ^12.4.3
# NOTE: to build against the in-tree sibling packages during local development,
# create a (gitignored) pubspec_overrides.yaml — pub auto-detects it. Keeping the
# overrides OUT of this file means CI/release resolves the pinned git refs above
# (the siblings aren't checked out in CI, so a committed path override fails
# `flutter pub get` with exit 66).
dev_dependencies:
flutter_test:
sdk: flutter
flutter_lints: ^6.0.0
test: ^1.25.8
# no_runtime_font_fetch_test parses pubspec.yaml to assert every family the
# type scale uses is bundled rather than fetched at runtime.
yaml: ^3.1.2
flutter_launcher_icons: ^0.13.1
sqflite_common_ffi: ^2.4.0+3
# RouteTracker's stall-watchdog tests drive virtual time (was a transitive
# dep via flutter_test; declared directly since test/ now imports it).
fake_async: ^1.3.1
# day_window_dst_test moves the PROCESS timezone via libc setenv/tzset so the
# DST day-length regressions are real on a non-DST host (transitive via
# sqflite_common_ffi; declared directly since test/ now imports it).
ffi: ^2.1.0
# db_p0_fixes_test swaps PathProviderPlatform.instance for a temp-dir fake so
# exportDaysDb can run without a platform plugin (transitive via
# path_provider; declared directly since test/ now imports it).
path_provider_platform_interface: ^2.1.0
flutter_launcher_icons:
android: "launcher_icon"
ios: true
image_path: "assets/images/icon.png"
remove_alpha_ios: true
adaptive_icon_background: "#F4F1EC"
adaptive_icon_foreground: "assets/images/icon.png"
flutter:
uses-material-design: true
assets:
- assets/images/
- assets/splash/
# Both families are bundled, not fetched. google_fonts resolves a missing
# family over HTTP to fonts.gstatic.com on first launch — before the user
# has seen the consent screen, and contrary to PRIVACY.md. It also lets the
# hero readiness numerals flicker or fall back on a cold offline launch.
# SIL Open Font License (OFL.txt alongside the .ttf files, from
# https://github.com/google/fonts).
fonts:
- family: Barlow Condensed
fonts:
- asset: assets/fonts/BarlowCondensed/BarlowCondensed-Bold.ttf
weight: 700
- asset: assets/fonts/BarlowCondensed/BarlowCondensed-ExtraBold.ttf
weight: 800
- family: Manrope
fonts:
- asset: assets/fonts/Manrope/Manrope-400.ttf
weight: 400
- asset: assets/fonts/Manrope/Manrope-500.ttf
weight: 500
- asset: assets/fonts/Manrope/Manrope-600.ttf
weight: 600
- asset: assets/fonts/Manrope/Manrope-700.ttf
weight: 700
- asset: assets/fonts/Manrope/Manrope-800.ttf
weight: 800