You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
{{ message }}
Repository navigation
docs(adr): require one version across GraphForge core and adapters #292
The v0.5.0 publication incident exposed a missing architectural rule. After npm accepted an incomplete immutable @curatelabs/graphforge@0.5.0, a proposed recovery was to publish npm adapters at 0.5.1 while leaving the Rust core and PyPI surface at 0.5.0.
That recovery is rejected. GraphForge is one product with Rust-owned behavior and thin language adapters. A public adapter version must identify the exact same GraphForge release as the Rust core it exposes; registry-specific version divergence would make compatibility, support, provenance, and user expectations ambiguous.
Related recovery issue: #291. Related publication trackers: #192, #196, and #198.
Decision to record
Add ADR 0017 establishing a single-version invariant for a GraphForge release:
the public Rust core/crate surface, Python package, Node main package, and Node native platform packages use one identical release version;
first-party CLI and agent-skills packages participating in that release train use that same version;
adapters remain thin distributions of the same Rust-owned product, not independently versioned products;
registry immutability or a partial publication failure does not authorize advancing only one ecosystem;
recovery must preserve version unity, even when that requires a coordinated new release version across every public surface or another explicitly documented whole-release disposition.
This issue records policy and enforceable guidance. It does not choose the recovery version or authorize additional publication for #291.
Acceptance criteria
Add accepted ADR 0017 under docs/adr/ with context, decision, alternatives, consequences, and partial-publication recovery rules.
Define which first-party artifacts are in the shared version set, including all 15 graphforge-* crates, graphforge on PyPI, @curatelabs/graphforge, its five native npm packages, the CLI, and agent skills.
State unambiguously that adapter/core version divergence is forbidden, including temporary or registry-specific patch divergence.
Document the rule in contributor release guidance, publication order/rollback guidance, and the release operator runbook.
Update both ADR indexes required by repository convention.
Add a deterministic repository/publication contract that fails before registry writes when any shared-version artifact or recovery plan diverges.
Add regression coverage for the rejected scenario: npm 0.5.1 with Rust/Python 0.5.0 must fail closed.
Update [Unreleased] and its published documentation mirror.
Context
The v0.5.0 publication incident exposed a missing architectural rule. After npm accepted an incomplete immutable
@curatelabs/graphforge@0.5.0, a proposed recovery was to publish npm adapters at0.5.1while leaving the Rust core and PyPI surface at0.5.0.That recovery is rejected. GraphForge is one product with Rust-owned behavior and thin language adapters. A public adapter version must identify the exact same GraphForge release as the Rust core it exposes; registry-specific version divergence would make compatibility, support, provenance, and user expectations ambiguous.
Related recovery issue: #291. Related publication trackers: #192, #196, and #198.
Decision to record
Add ADR 0017 establishing a single-version invariant for a GraphForge release:
This issue records policy and enforceable guidance. It does not choose the recovery version or authorize additional publication for #291.
Acceptance criteria
docs/adr/with context, decision, alternatives, consequences, and partial-publication recovery rules.graphforge-*crates,graphforgeon PyPI,@curatelabs/graphforge, its five native npm packages, the CLI, and agent skills.0.5.1with Rust/Python0.5.0must fail closed.[Unreleased]and its published documentation mirror.Non-goals
v0.5.0.