{"data":[{"appId":"app_espocrm","name":"EspoCRM","channel":"candidate","license":{"spdxId":"AGPL-3.0-or-later","gateOk":false,"gateSweptAt":"2026-09-22T14:30:17.147Z","gateFilesScanned":0},"digest":null,"capabilities":["crm"],"architectureOs":["linux"],"resourceProfile":{"cpuCores":2,"ramGb":4,"diskGb":40},"uiIntegrationTier":null,"supportBoundary":null,"knownLimitations":["No wired ApplicationAdapter exists for this app anywhere in the estate (sax3l/vibe src/adapters/registry.ts has no app_espocrm entry) — it cannot be installed by VIBE's pipeline today, only planned/costed/H0ST-staged.","No lifecycle drill has ever been run against a real EspoCRM instance (contrast with listmonk's executed drill, scripts/listmonk-lifecycle-drill.mjs) — health/backup/restore/upgrade/rollback are all unproven, not merely undocumented.","No database engine, version, or upstream repository URL was ever recorded for this entry in its source (sax3l/vibe RAW_CATALOG) — see catalog.json's own null fields above and provenance.json.","qualification.json accordingly records status \"candidate\", not \"installable\" — see D-03/ADR-021 and qualification-gate.ts for why that distinction is schema-enforced, not just a convention."],"cappedFrom":{"channel":"candidate","reason":"license-gate violation: cannot-verify:no-license-file-at-root:/home/simon/Documents/siax-app-catalog/apps/espocrm"},"attestation":null,"sourceDigestPin":"ff7719df3a4d3959b0b0aba54ef7bdf2de952649","updatedAt":"2026-09-23T15:30:08.521Z"},{"appId":"app_listmonk","name":"listmonk","channel":"candidate","license":{"spdxId":"AGPL-3.0","gateOk":false,"gateSweptAt":"2026-09-22T14:30:17.148Z","gateFilesScanned":0},"digest":"sha256:179d00d9553c371b6fe88c9b145095d651e275bdd66db46b2e0b79daff316b6f","capabilities":["email-marketing"],"architectureOs":["linux"],"resourceProfile":{"cpuCores":1,"ramGb":1,"diskGb":10},"uiIntegrationTier":null,"supportBoundary":null,"knownLimitations":["OIDC-to-Zitadel wiring not tested against a live Zitadel org (isolated-sandbox constraint) — local session-cookie auth WAS proven for real.","listmonk publishes no official minimum resource footprint; the resourceModel above is VIBE's own conservative estimate, not an upstream number.","Rollback correctness for THIS migration (v6.2.0 -> v6.1.0) happened to be forgiving even without a full restore (see lifecycle.rollback note) — this adapter does not rely on that being true for every future listmonk release, and neither should a caller.","Import was only tested subscriber-CSV + list JSON; campaigns/templates/media are exported by exportData() only as row counts in the manifest, not round-tripped through import (listmonk's own import API is subscriber-only; campaigns/templates have no equivalent bulk-import endpoint).","Multi-replica / horizontal scaling not tested — this pass ran exactly one app container per instance, matching listmonk's own official docker-compose.yml.","H0ST's real Docker adapter (h0st/src/integrations/docker-client.ts) cannot run this app as-is — it has no env/port/volume/network support. This catalog entry's lifecycle was proven against a NEW, more capable orchestrator built for this pass (vibe/src/adapters/docker/docker-orchestrator.ts), not H0ST's adapter. See that module's header for the full reasoning; lifting it into H0ST once a second app needs it is a documented next step, not done here."],"cappedFrom":{"channel":"tested","reason":"license-gate violation: cannot-verify:no-license-file-at-root:/home/simon/Documents/siax-app-catalog/apps/listmonk"},"attestation":null,"sourceDigestPin":"ff7719df3a4d3959b0b0aba54ef7bdf2de952649","updatedAt":"2026-09-23T15:30:08.521Z"}]}