Block a user
Config hygiene: env-only tokens + lint to block secrets in manifests/systemd
Post-install health probe + auto-revert to staged previous bundle
Clipboard fallback: permissions-first + download link
Diagnostics UX: show /dev/shm/pikit-diag.log in updater modal
Automated tests for updater flows (pytest + Playwright smoke)
Move updater apply to dedicated systemd runner