Deep analysis of marketplaces-main.zip (hub.numus.cc/numus/marketplaces).
Findings:
- Not a fork of us. Separate platform monorepo (NestJS + Postgres +
2 Angular apps + infra) sharing an older dexarmarket ancestor.
- Our repo is vendored inside it as reference/parallel-frontend/,
SHA-256 pinned, dated 11 Aug 2026, classified "reference, not production".
- Zero VK/Yandex/OAuth code anywhere in their source. Their only
customer login is Telegram, proxied to an external service.
- They lead on backend truth and ops; we lead on frontend depth,
tests, e2e, and framework currency.
Three of their audit findings are still live in our code and are
defects, not just posture: plaintext ip-api.com call from an HTTPS
origin (mixed content, region detect silently dead), unvalidated
bypassSecurityTrustResourceUrl on a bank URL rendered in an iframe,
and provider credentials plus a partner ID literal in the bundle.
Adds:
- docs/FORK-ANALYSIS-2026-08-21.md - full comparison, their audit of
us assessed line by line, and a VK ID + Yandex ID design.
- docs/superpowers/specs/2026-08-21-fork-harvest-design.md - working
brief, five lanes, four waves, scope and rejection rules.
- docs/FORK-HARVEST-TODO.md - 42 items with effort, dependencies and
acceptance criteria. Improvements only; nothing regresses our
Angular version, test count, or architecture governance.
No implementation changes.
Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>