38 slides · use ← → · built from the report
existing-system audit
A well-engineered open-source commerce framework that has quietly lost its steward for the second time in ten years — and a competitor that came back from the dead with a business model behind it.
Solidus is not a hosted store: it is a set of Rails libraries you install into your own application — you run the servers, you own the database, you keep every customization.
observed
Solidus is technically healthy and strategically adrift. Both are true, and the gap between them is the whole story.
observed
PL1 · direction · proposed
The project engineers migrations well and never schedules them — RC1 (Migrations are engineered but never scheduled) is the mechanism behind the largest recurring cost in the ledger, D1 (Three unfinished rewrites — the largest recurring cost in the project). Promotions has shipped a complete engine and a 190-line migration guide for two years, and no release anywhere says when the legacy engine goes. This rule closes the gap at the source: a successor ships as parallel opt-in only alongside a named removal release for the incumbent. Rails and Ruby both publish deprecation timelines this way; the statement costs nothing and assigns nobody labour. Its first invocation is B5 (Name the release that removes legacy promotions), which has been free to do for two years.
PL2 · allocation · proposed
Every serious spending year funded a single engagement, and the one that failed — $45,760 for six "Agile Design Sprints" in 2023 — is the one that bought activity instead of an outcome (F1 (A definition of finished existed, and the money was not wired to it)). The rule: a funded engagement names its deliverable, its completion criterion, and who carries the work after the money stops. The funding model itself is already settled and deliberate — independent developers paid from the collective while the maintaining firms stay on client work — so this row ratifies a norm the project already holds and writes down the arm's-length standard that currently exists only in Slack and in one maintainer's head. Backtested against the record: the 2020, 2024 and 2025 engagements pass on shape and fail on succession; the 2023 purchase fails outright, and this rule is the difference.
PL3 · guidance · proposed
The Core Team holds explicit technical authority and the community meets weekly, yet no decision reaches a public artifact: the roadmap board is a changelog wearing a roadmap's name, and the clearest statement of project strategy lives on a consultancy's marketing blog (S1 (Reject the JavaScript-framework direction on purpose)). A prospective adopter finds a well-kept record that the project had a past and no evidence it has a future. The rule: each Core Team decision lands within a month as a status post or a forward-looking roadmap item. This is publication, not governance — the decisions may already be getting made; nothing about them is visible. The blog has already half-resumed on its own, with one release announcement in May 2026 ; this rule turns that from an occasional act into a habit.
PL4 · approval · proposed
The admin has been neither shipped nor cancelled for three years inside a governance structure that plainly permits either — authority exists, a venue does not (S5 (Merge authority belongs to a self-appointing Core Team), D2 (Governance describes a project that no longer exists)). The rule gives the recurring decision an address: once a quarter, each parallel initiative is declared progressing, funded, paused until a named date, or cancelled, and the answer is written where outsiders can read it. The mechanism cannot fail silently, which is the property that matters — a quarter with no disposition list is itself visible. This is the row that would have caught the admin's stall in 2024 instead of letting an architecture that hides abandonment (R3 (The half-built admin becomes a permanent third state)) hide it for two more years.
PL5 · guidance · proposed
When the 2025 funded developer stopped, seven admin pull requests went stale where they sat, and the project's only rescue so far was one contributor volunteering by hand a year later (F3 (The last developer's work was abandoned mid-flight)). That rescue worked — it moved to a fresh pull request on 30 July 2026, with the reviewer's preferred approach adopted — which proves the mechanism and indicts its coverage: one orphan in six found an adopter, by accident. The rule makes the accident routine. When a contributor departs, each of their open drafts gets an explicit adopt-or-close decision within one release cycle. Closing is a legitimate outcome; the only illegitimate one is the current default, indefinite limbo preserved by a compatibility rule that never expires anything.
inferred
The policy layer in one line: schedule what you replace, buy outcomes not time, publish decisions, give each initiative a quarterly disposition, adopt or close departed work — five rules, all proposed, none asking a volunteer to work.
observed
The arc in one line: forked from Spree in 2015, its creator gone by 2018, its steward's engineering gone by 2024 — and the machine still running on discipline the departed built.
observed
| Year | Paid out | Expenses | Where it went |
|---|---|---|---|
| 2019 | $11,768 | 10 | Conference costs — Sean Denny 43%, Cindy Backman 42% |
| 2020 | $35,736 | 24 | Peter Berkenbosch 80% — monthly "Development & Maintenance" |
| 2021 | $0 | 0 | nothing at all |
| 2022 | $500 | 1 | One conference video-editing invoice |
| 2023 | $45,760 | 7 | The admin — Nebulab 79%, Andrea Iurisci 21%. 100% of the year. |
| 2024 | $32,506 | 16 | Logicielle B.V. 100% — 16 development invoices, Aug–Dec |
| 2025 | $16,888 | 6 | "e.c441" 100% — 6 development invoices, Feb–Jul |
| 2026 | $0 | 0 | nothing at all |
observed
The money in one line: funded development stopped in July 2025, thirteen months of income have arrived since, and $133,750 sits unspent.
observed
observed
The product in one line: three parallel rewrites read as systemic failure to finish, but promotions is a managed migration, the storefront a success — only the admin has stalled.
observed
| Person (organization) | 2022 | 2023 | 2024 | 2025 | 2026 |
|---|---|---|---|---|---|
| Elia Schito (Nebulab) | 133 | 696 | 46 | 4 | 0 |
| Alberto Vena (Nebulab) | 70 | 232 | 52 | 12 | 3 |
| Rainer Dema (Nebulab) | — | 168 | 2 | 0 | 0 |
| Super Good Software (all) | 34 | 3 | 140 | 62 | 136 |
observed
The people in one line: Nebulab supplied roughly 60% of all commits in 2023 and 0.8% over the last twelve months, and no announcement was ever made.
observed
The machine in one line: every change tested against four Ruby–Rails combinations with the newest of each adopted within weeks of release, deprecations failing the build, fixes back-ported automatically — top-decile delivery machinery for a project this size.
observed
The most expensive initiative in the project's history stopped without a sound: three years and $45,760 in, the new admin is at version 0.4 — and the architecture makes abandonment produce no symptom.
observed
| Metric | Solidus | Spree |
|---|---|---|
| Commits in the last 52 weeks (GitHub's own series — the git log in §06 counts 493 over the same window; the 5.5× ratio uses one instrument on both sides) | 400 | 2,190 — 5.5× |
| GitHub stars | 5,317 | 15,572 |
| Forks | 1,400 | 5,287 |
| Latest release | v4.7.0 · 15 Apr 2026 | v5.6.1 · 28 Jul 2026 |
| Platform releases in July 2026 | 0 | 6 |
| Cumulative package downloads | 3.22M | 2.85M |
observed
Spree's open source is a marketing cost carried on a real business; Solidus's is carried on a $25k-a-year donation pot.
observed
The competitor in one line: Spree ships five and a half times Solidus's commit volume, six platform releases in July 2026 alone, and its free edition is the sales funnel for a paid enterprise product.
observed
| Rule | Written where? | Health | |
|---|---|---|---|
| S1 | Reject the JavaScript-framework direction on purpose. Simplicity, one stack, no fees, distributed governance. | on the lead maintainer's company blog | The project's actual strategy — stated, just not here |
| S2 | Never break an existing store. Deprecate before removing; back-port fixes to old versions. | ratified | Holding — at a cost nobody has priced |
| S3 | Ship replacements alongside the old version as opt-in, with a written migration guide; the old one stays until stores have moved. | in the gems, not the governance | Working — see the promotions migration guide |
| S4 | Core stays lean; capabilities live in separate extensions. | nowhere | Weakening — four official extensions dormant |
observed
| Rule | Written where? | Health | |
|---|---|---|---|
| S5 | Merge authority belongs to a self-appointing Core Team. Money buys votes on spending, never on code. | ratified | Yes — the separation is deliberate and healthy |
| S6 | Quality is enforced by machines; style is not argued about. | only in CI config | The best-functioning rule in the project |
| S7 | All delivery is done by humans. | by omission | Untested — no agent harness exists |
inferred
Losing the steward is not a shock this project suffered once; it is its normal condition, and in ten years the governance never grew a mechanism for handling it.
observed
The two causes compound into a single condition: an unfunded initiative sitting next to an unspent budget.
inferred
| Risk | Flag | Likelihood | Would you notice? | |
|---|---|---|---|---|
| R1 | Routine dependency drift between security releases | downgraded | Low for disclosed vulnerabilities — that path is covered. Medium for drift | For a disclosed CVE, yes. For gradual drift, no |
| R2 | Two firms are 78% of the money and most of the code | hard to detect | Medium — this has already happened twice | Not for months. A departure looks exactly like a quiet quarter |
| R3 | The half-built admin becomes a permanent third state | hard to detect | Lowered at rev 24 — deliberately paced by the Core Team's account; the confirming observable has not fired yet | No. Every signal a maintainer looks at is green |
| R4 | Spree takes the new-project market | easy to see coming | ||
| R5 | The new storefront breaks existing extensions by design |
inferred
inferred
| Debt | Kind | |
|---|---|---|
| D1 | Three unfinished rewrites | strategic |
| D2 | Governance describes a project that no longer exists | organizational |
| D3 | Architectural decisions are never recorded | knowledge |
| D4 | The agent harness, and two small automation gaps | technical |
observed
| Credit | Status | |
|---|---|---|
| C1 | Test matrix current to the newest Rails and Ruby | confirmed |
| C2 | Deprecation build gate | confirmed |
| C3 | Automated back-porting | confirmed |
| C4 | Automated code style | confirmed |
| C5 | Release and changelog automation | confirmed |
| C6 | Reproducible development environment | confirmed |
| C7 | The storefront | confirmed |
| C8 | solidus_promotions | overdue |
| C9 | solidus_admin | past the point of write-off |
inferred
The conclusion this evidence supports is a role, not a comeback: the commerce framework you can still own in ten years, serving the merchants who already chose it.
inferred
| Role | The move | The catch |
|---|---|---|
| A — Steward the installed base | No new initiatives; guarantee upgrades and security; finish promotions; cancel the admin and storefront | An explicit acceptance of managed decline — some contributors will leave |
| B — Contest the agent channel | Ship the missing agent harness; sell "one runtime, one test command" to agent-driven builders | Spree shipped theirs first — a modifier on Role A, not an alternative |
| C — Converge with Spree | Fold back into the project Solidus forked from | Nobody inside will propose it, which is exactly why it must be written down |
inferred
| Bet | Verdict | Addresses | Cost | |
|---|---|---|---|---|
| B2 | Restart funded development — buying an outcome, not sprints | Do | R3, D1 | one meeting agenda item |
| B5 | Name the release that removes legacy promotions — a policy statement, not labour; the first invocation of PL1 | Do | D1, RC1 | free |
| B6 | Decide the admin — by manufacturing the evidence, not deliberating without it | Decide | R3, D1 | one hard screen |
| B7 | Match Spree's React storefront | Kill | R4 | — |
| B8 | GraphQL / headless surface | Wait | R4 | — |
inferred
| Bet | Verdict | Addresses | Cost | |
|---|---|---|---|---|
| B9 | Dual asset-pipeline support, with an agent-executed migration | Do | R1, D3, D4 | see template |
| B10 | Publish technical decisions — restart the status posts, file forward-looking roadmap items; the one-time act behind PL3 | Do | D2, D3, S1, R4 | an hour a month |
inferred
inferred
The moves in one line: none of the first steps is expensive — publish the decisions being made, name the release that removes legacy promotions, and fund outcomes rather than sprints.
Nothing here asks to be believed: every factual claim in this report carries a tag saying how it was arrived at, and the tags are counted by the build, never authored.
Before the conclusions
How much of what you just heard was actually observed.