diff --git a/.github/workflows/version-drift.yml b/.github/workflows/version-drift.yml new file mode 100644 index 0000000..6c014c3 --- /dev/null +++ b/.github/workflows/version-drift.yml @@ -0,0 +1,78 @@ +name: Version Drift Check + +on: + schedule: + # Every Monday 04:00 UTC (11:00 WIB) + - cron: "0 4 * * 1" + workflow_dispatch: + pull_request: + paths: + - "README.md" + - "src/uteke/SKILL.md" + - "src/cora-code/SKILL.md" + +permissions: + contents: read + +env: + # All products listed in the README quick-install table. + PRODUCTS: "uteke cora-code covecto" + # Only these skills document the product binary 1:1, so only these + # must keep their `version:` aligned with the product release tag. + # (covecto skill teaches the vtracer library and versions independently.) + SKILL_PRODUCTS: "uteke cora-code" + +jobs: + drift-check: + runs-on: ubuntu-latest + steps: + - name: Checkout + uses: actions/checkout@v4 + + - name: Compare live releases vs declared versions + run: | + set -euo pipefail + drift=0 + + get_readme_version() { + # Row looks like: | [Uteke](https://github.com/codecoradev/uteke) | v0.15.0 | ... + grep -oP "codecoradev/$1\)\s*\|\s*\Kv[0-9.]+" README.md | head -1 + } + + get_skill_version() { + local f="src/$1/SKILL.md" + [ -f "$f" ] && grep -m1 '^version:' "$f" | awk '{print "v" $2}' + } + + for repo in $PRODUCTS; do + live=$(curl -sfL "https://api.github.com/repos/codecoradev/$repo/releases/latest" | grep -oP '"tag_name":\s*"\K[^"]+') + readme_v=$(get_readme_version "$repo" || echo "MISSING") + + echo "$repo: live=$live readme=$readme_v" + + if [ "$readme_v" != "$live" ]; then + echo "::error file=README.md::$repo README says ${readme_v:-MISSING} but latest release is $live" + drift=1 + fi + done + + for repo in $SKILL_PRODUCTS; do + live=$(curl -sfL "https://api.github.com/repos/codecoradev/$repo/releases/latest" | grep -oP '"tag_name":\s*"\K[^"]+') + skill_v=$(get_skill_version "$repo" || echo "vMISSING") + + echo "$repo: live=$live skill=$skill_v" + + if [ "$skill_v" != "$live" ]; then + echo "::error::$repo SKILL.md says $skill_v but latest release is $live" + drift=1 + fi + done + + if [ "$drift" -ne 0 ]; then + echo "" + echo "Version drift detected. Update the README table and SKILL.md frontmatter," + echo "then add a 'What's New' entry covering the missed releases." + exit 1 + fi + + echo "All product versions in sync." diff --git a/README.md b/README.md index bf91b4c..8d81328 100644 --- a/README.md +++ b/README.md @@ -36,8 +36,8 @@ Product skills require their respective binary installed. Download from GitHub R | Product | Latest | Download | |---------|--------|----------| -| [Uteke](https://github.com/codecoradev/uteke) | v0.15.0 | [Releases](https://github.com/codecoradev/uteke/releases/latest) (Linux, macOS, Windows) | -| [Cora Code](https://github.com/codecoradev/cora-code) | v0.13.0 | [Releases](https://github.com/codecoradev/cora-code/releases/latest) (Linux, macOS, Windows) | +| [Uteke](https://github.com/codecoradev/uteke) | v0.17.0 | [Releases](https://github.com/codecoradev/uteke/releases/latest) (Linux, macOS, Windows) | +| [Cora Code](https://github.com/codecoradev/cora-code) | v0.15.0 | [Releases](https://github.com/codecoradev/cora-code/releases/latest) (Linux, macOS, Windows) | | [Covecto](https://github.com/codecoradev/covecto) | v0.1.1 | [Releases](https://github.com/codecoradev/covecto/releases/latest) (Linux, macOS, Windows) | Each release ships binaries for x86_64 and aarch64 on Linux/macOS, plus x86_64 on Windows. diff --git a/extensions/uteke-extract/__pycache__/handler.cpython-313.pyc b/extensions/uteke-extract/__pycache__/handler.cpython-313.pyc deleted file mode 100644 index d7db645..0000000 Binary files a/extensions/uteke-extract/__pycache__/handler.cpython-313.pyc and /dev/null differ diff --git a/extensions/uteke-recall/__pycache__/handler.cpython-313.pyc b/extensions/uteke-recall/__pycache__/handler.cpython-313.pyc deleted file mode 100644 index ae6db5a..0000000 Binary files a/extensions/uteke-recall/__pycache__/handler.cpython-313.pyc and /dev/null differ diff --git a/plugins/uteke-tool/__pycache__/tool.cpython-313.pyc b/plugins/uteke-tool/__pycache__/tool.cpython-313.pyc deleted file mode 100644 index b7164d1..0000000 Binary files a/plugins/uteke-tool/__pycache__/tool.cpython-313.pyc and /dev/null differ diff --git a/src/cora-code/SKILL.md b/src/cora-code/SKILL.md index d845060..0fc5fd3 100644 --- a/src/cora-code/SKILL.md +++ b/src/cora-code/SKILL.md @@ -4,7 +4,7 @@ description: | Cora Code — complete guide covering usage (review, scan, brain search, code intelligence) AND development (architecture, Brain Mode roadmap, embedding strategy, CI pitfalls, tree-sitter). CLI binary cora. BYOK AI code review + code intelligence platform. -version: 0.12.0 +version: 0.15.0 metadata: author: CodeCoraDev hermes: @@ -73,29 +73,28 @@ After restart, tools become `mcp_cora_brain_search`, `mcp_cora_find_callers`, `m - Debugging cora issues (auth, config, CI failures) - Adding CI review to a repo -## What's New (v0.11.0 — v0.12.0) - -### v0.12.0 -- **FTS5 camelCase search fixed** — `split_camel_case()` decomposes identifiers (`findUser` → `find OR user`). Added `file` column to FTS5 virtual table (schema v6) (#451). -- **Dead-code false positives on framework entry points** — `FRAMEWORK_ENTRY_PREFIXES` (`handle_*`, `on_*`, `route_*`) excluded from dead-code detection (#452). -- **Symbol-level suppression markers** — `// cora: keep` in symbol body excludes it from dead-code detection (#452). -- **Sticky skip files on config change** — `index_config_hash` column re-evaluates skipped files when `.cora.yaml` changes (#453). -- **`entry_point_patterns` config field** — Custom glob patterns for framework-specific entry points in `.cora.yaml`. -- **Schema migration v6** — Auto-migration: adds `index_config_hash`, rebuilds FTS5 with `file` column. - -### v0.11.0 -- **Unused import detection** — Index-powered scanner flags imports never referenced in file. Works across Rust, TypeScript, Go, Python. -- **Dead code in review** — Changed files with dead functions/methods (zero callers) auto-flagged during review. -- **Breaking change detection** — Removed/modified public symbols flagged with affected callers list. -- **HTTP route detection** — Route handlers (Axum, Actix, Express, Go net/http) tracked as `ROUTE` edges. -- **Brain enrichment (Tier 1)** — Review pipeline leverages symbol index for caller resolution, impact analysis, affected tests, semantic search. - -### v0.10.0 -- **Dead code detection** — `cora dead-code` CLI + MCP tool. Call graph analysis, zero-caller detection. -- **Graph query DSL** — `cora query "main -> *"` for code graph traversal. -- **Auto-config agent installer** — `cora install` detects 40+ AI coding agents, configures MCP server. -- **Background reindex on serve** — `cora serve` auto-reindexes before starting MCP server. -- **Tree-sitter default feature** — AST-based extraction in all builds including release binaries. +## What's New (v0.13.0 — v0.15.0) + +### v0.15.0 — quantized vector store (vecq) +- **Opt-in `vecq` vector store for Brain Mode** — `brain.vector_store: vecq` in `.cora.yaml` replaces the usearch HNSW index with a vecq quantized scan (pure Rust, deterministic, ~5x smaller). Keyed persistence: symbol IDs survive reload, so `cora index` no longer re-embeds unchanged projects (#542, #547). +- **`brain.vector_bits` knob** — `residual` (default) | `4` | `5` | `6`. Default residual = best recall@10 at 4-bit scan speed. Changing width rebuilds the index once on next `cora index` (#542). +- **Fixed: vector signal never fired in a fresh process** — `cora brain` / MCP `brain_search` silently degraded to FTS-only unless the same process had run the embed. Index now lazy-loads once per process with a dimension guard (#545). +- **Fixed: stale embed fingerprints after a global index rebuild** — rebuilds now clear fingerprints for all projects (#545). + +### v0.14.0 — reasoning-model robustness + honest dead-code +- **Empty LLM responses from reasoning models fixed** — GLM-style models that burn `max_tokens` on chain-of-thought no longer surface as `EOF while parsing`; cora retries with doubled budget (up to 32768), salvages JSON from reasoning text, reports explicit "EMPTY response" (#536). +- **Dead-code skips public API surface by default** — `pub`/`export` items excluded; `--include-pub` / MCP `include_pub_api` opt back in (#520). +- **Fixed: dead-code false positives from cross-crate method calls** — was 557 false positives on a 5-crate workspace (#519). +- **Fixed: index root mismatch between CLI and MCP** — root resolution prefers `[workspace]` Cargo.toml, never climbs past `.git` (#522). +- **Fixed: `ignore.files` honored by the index** — matched files are excluded from indexing entirely (#521). +- **Default `max_tokens` raised 4096 → 8192** (#536). +- **Relicensed MIT → Apache-2.0** + CLA added (individual + corporate). + +### v0.13.0 — runtime embedding backend +- **Runtime embedding backend selection** — `brain.embedding` in `.cora.yaml`: `auto` (default) | `hashing` (256d, zero-dependency) | `pretrained` (768d nomic). No recompilation to switch. +- **Incremental per-symbol embedding** — `embed_fingerprint` (name + signature hash) skips unchanged symbols; re-index after touching one file embeds only changes. Schema v7, auto-migrates. + +See the [CHANGELOG](https://github.com/codecoradev/cora-code/blob/main/CHANGELOG.md) for the full history. ## Data Directory diff --git a/src/uteke/SKILL.md b/src/uteke/SKILL.md index 16aa6e9..f31637b 100644 --- a/src/uteke/SKILL.md +++ b/src/uteke/SKILL.md @@ -1,7 +1,7 @@ --- name: uteke description: "Uteke offline semantic memory engine — open source product." -version: 0.11.0 +version: 0.17.0 metadata: hermes: tags: [uteke, memory, semantic-search, offline, rust, local-first] @@ -18,7 +18,7 @@ Persistent, searchable AI memory — offline, single Rust binary, ~30ms recall. | Topic | Details | |-------|---------| -| **Binary** | `uteke` (v0.11.0, installed from GitHub release). Set env: `UTEKE_BASE_URL` (default `http://localhost:8767`), `UTEKE_TOKEN`, `UTEKE_NAMESPACE`. Use `curl` to the server API when running uteke-serve in Docker. | +| **Binary** | `uteke` (v0.17.0, installed from GitHub release). Set env: `UTEKE_BASE_URL` (default `http://localhost:8767`), `UTEKE_TOKEN`, `UTEKE_NAMESPACE`. Use `curl` to the server API when running uteke-serve in Docker. | | **License** | Apache 2.0 | | **Install** | `curl -sSL codecora.dev/install | sh` (one-liner, all platforms) | | **Source** | [codecoradev/uteke](https://github.com/codecoradev/uteke) (Rust, develop=mainline, main=release mirror) | @@ -77,20 +77,29 @@ curl -X DELETE ${UTEKE_BASE_URL}/room/document/remove \ ⚠️ Always use `--namespace `, `--type `, `--detect-contradiction` when re-storing. -## What's New (v0.10.2 — v0.11.0) - -### v0.11.0 -- **`POST /doc/move` fixed** — `deny_unknown_fields` + UUID fallback for parent resolution. Wrong field names now return 400 instead of silent data loss (#833). -- **Recall score reports cosine similarity** — not RRF rank, when results appear in only one store (#831). -- **MCP/CLI store mismatch fixed** — hardcoded `~/.uteke` paths resolved through `uteke_home()`. MCP and CLI now share the same store (#830). -- **`POST /consolidate` accepts string threshold** — flex deserializer for MCP layers that stringify params (#826). -- **API route drift guard** — source-backed test ensures all handler routes are registered (#829). - -### v0.10.2 -- **SIGILL fix for non-AVX2 CPUs** — Runtime CPU feature detection selects between AVX2 and SSE4.2 ONNX libraries. Use `*-legacy*` release bundles on older CPUs (#709). -- **Room operations filter deprecated** — `room_stats`, `recall_room`, `get_room_memory_ids` now filter `deprecated = 0` (was 76% stat inflation). -- **Short ID prefix for forget** — `DELETE /forget` accepts 8-char prefix, not just full UUID. -- **Auto-generated API reference** — `crates/docgen` generates `docs/api-reference.md` from route registry. +## What's New (v0.15.0 — v0.17.0) + +### v0.17.0 — inspectable, trustworthy memory +- **Explain recall** — `uteke recall "…" --explain` shows WHY each memory ranked: vector/FTS ranks, RRF score with per-channel fusion contributions, boost deltas. Also `POST /recall` with `"explain": true` and MCP `uteke_recall` explain flag (#1160). +- **Contradiction ledger + undo** — supersessions are an auditable ledger: `uteke contradictions list|undo`, `GET /contradictions`, `POST /contradictions/undo`, MCP `uteke_contradictions`/`uteke_contradictions_undo`. `undo_supersession(id)` restores a retired memory (#1172). +- **`uteke supersede [--reason]`** — CLI surface parity for supersession (previously MCP/HTTP only) (#1172). +- **`uteke provenance `** — SHA-256 content hash at write time (tamper evidence), actor/evidence timeline, trust tier. Schema v18, additive (#1172). +- **Namespace ops** — `uteke namespace move|rename|delete` (delete needs `--confirm`; strategies: `refuse`/`merge`/`deprecate`). `PUT /memory` accepts `namespace` to move a memory (#1181). +- **`/list` pagination metadata** — `"include_meta": true` returns `{memories, total, has_more, next_offset}` envelope; default response unchanged (#1188). +- **Fixed** — `/graph` no longer returns stale nodes from forgotten/deprecated memories; memory graph nodes get readable content-preview labels instead of raw UUIDs; `POST /graph/edge` accepts memory IDs (was 500). + +### v0.16.0 — fusion is the default everywhere +- **`fusion` recall strategy** — weighted RRF of vector + hybrid rankings (k=60). **Default recall strategy is now `fusion`** (CLI, HTTP, MCP) when no strategy is specified; explicit `default_strategy` configs are untouched. LongMemEval fast50: R@5 0.98 vs 0.9267 hybrid (#1123). +- **Public benchmark page** — `docs/benchmarks.md`: recall_any@5 98.2%, recall_all@10 95.4%. + +### v0.15.0 — trust + portability +- **UUIDv7 for new IDs** — time-ordered; existing v4 IDs keep working (#1060). +- **Supersession workflow** — mark stale decisions superseded; recall flags superseded entries (#1069). +- **Structural export/import** — full-store round-trip: rooms, graph, edges, documents, timeline (#1068). +- **MCP `uteke_get` + `uteke_update`** — read/edit a single memory by ID, short-ID resolution (#1067). +- **Fixed** — `uteke_dream` is dry-run-first (destructive passes need explicit confirmation); `/export` keeps namespace attribution; recall cache score parity; soft-forgotten memories no longer leak into list/search/doctor counts. + +See the [CHANGELOG](https://github.com/codecoradev/uteke/blob/main/CHANGELOG.md) for the full history (v0.12.0—v0.14.3: merge_from_file config fix, FTS5 content indexing, room-document junction tools, hybrid default strategy, HTTP/MCP strategy parity, crates.io publish fix). ## ⚠️ Breaking Changes (v0.8.0)