• v0.32.2 1f6430f1c7

    code-index v0.32.2
    Some checks failed
    CI / cargo fmt (pull_request) Successful in 48s
    CI / OSS corpus tier-3 scale (nightly) (pull_request) Has been skipped
    CI / Grammar rebuild from source (nightly) (pull_request) Has been skipped
    CI / CI lane wall-clock headroom (pull_request) Successful in 50s
    CI / guest crates (fmt, clippy, doc) (pull_request) Successful in 1m16s
    CI / cargo doc (intra-doc links) (pull_request) Successful in 5m10s
    CI / cargo check (MSRV 1.98) (pull_request) Successful in 6m4s
    CI / cargo test (abi, 32-bit + wasm32) (pull_request) Successful in 6m15s
    CI / cargo deny (pull_request) Successful in 6m28s
    CI / cargo clippy (pull_request) Successful in 6m31s
    CI / cargo check (windows-gnu) (pull_request) Successful in 6m38s
    CI / OSS corpus (tier 1) (pull_request) Successful in 27m30s
    CI / cargo test (pull_request) Successful in 31m20s
    CI / cargo test (daemon transport) (pull_request) Successful in 9m51s
    CI / Plugin path cost + pool throughput (nightly) (pull_request) Has been skipped
    CI (Windows) / fmt + clippy + build + test (windows) (pull_request) Successful in 1h14m55s
    Release Build / Generate Version (push) Successful in 29s
    CI / OSS corpus tier-3 scale (nightly) (push) Has been skipped
    CI / Grammar rebuild from source (nightly) (push) Has been skipped
    CI / cargo fmt (push) Successful in 49s
    CI / guest crates (fmt, clippy, doc) (push) Successful in 54s
    CI / CI lane wall-clock headroom (push) Successful in 1m8s
    CI / cargo doc (intra-doc links) (push) Successful in 5m24s
    CI / cargo clippy (push) Successful in 6m10s
    CI / cargo test (abi, 32-bit + wasm32) (push) Successful in 6m17s
    CI / cargo check (MSRV 1.98) (push) Successful in 6m28s
    CI / cargo deny (push) Successful in 6m35s
    CI / cargo check (windows-gnu) (push) Successful in 6m45s
    CI / OSS corpus (tier 1) (push) Successful in 31m9s
    Release Build / Required CI green (push) Failing after 51m25s
    Release Build / Build linux-aarch64 (push) Has been skipped
    Release Build / Build linux-x86_64 (push) Has been skipped
    Release Build / Build linux-x86_64-musl (push) Has been skipped
    Release Build / Build windows-x86_64 (push) Has been skipped
    Release Build / Pack the XAML reference package (push) Has been skipped
    Release Build / Pack the TimeLine package (push) Has been skipped
    Release Build / Pack the Ruby language package (push) Has been skipped
    Release Build / Pack the Svelte language package (push) Has been skipped
    CI / cargo test (push) Successful in 50m27s
    CI (Windows) / fmt + clippy + build + test (windows) (push) Successful in 1h10m17s
    Release Build / Windows archive smoke (msvc) (push) Has been skipped
    Release Build / Create Forgejo Release (push) Failing after 3m33s
    CI / cargo test (daemon transport) (push) Successful in 23m21s
    CI / Plugin path cost + pool throughput (nightly) (push) Has been skipped
    Stable

    buildagent released this 2026-09-26 17:02:05 +02:00 | 60 commits to master since this release

    code-index v0.32.2

    Build: v0.32.2+916

    Installer: install.sh and checksum. Both come from this release commit. To pin the installed binaries too, run it with --tag v0.32.2.

    Windows installer: install.ps1 and checksum, from the same release commit. It installs AND updates — the same code does both — verifies the archive against its published .sha256 before unpacking, refuses hostile archive members (absolute paths, .. escapes, symlinks and reparse points, which Expand-Archive does not protect you from), and grants nothing when it installs a package: the bytes go into the machine's store and the approving line is PRINTED for you to run from inside a project. -Help lists the flags; -Tag v0.32.2 pins the binaries.

    Four-binary release: code-index-mcp (MCP stdio bridge — the usual entry), code-index-daemon (long-lived watcher + RPC server, auto-spawned), code-index-plugin-host (bounded worker for plugin packages, spawned by the daemon), and code-index (CLI: init, index, watch, doctor, link, plugin).

    Changes

    This release fixes the mid-session disconnects two Windows users reported, and adds the tool improvements they asked for.

    Daemon robustness

    • Locked writes wait instead of crashing the daemon. The writer now waits out a write lock held by another process (BEGIN IMMEDIATE, backing off from 25 ms to 1 s). Before, it gave up after five retries within about 7 ms and the whole daemon exited. A writer blocked by another process now says so, and SQLITE_LOCKED is no longer retried.
    • Every daemon and MCP exit leaves a reason in .code-index/daemon.exit and daemon.log. Panics are logged with a backtrace. A panic on the MCP main thread now exits instead of leaving the server alive but unresponsive.
    • No more silent long hangs. Each tool call gets one shared daemon budget (default 180 s, CODE_INDEX_TOOL_CALL_BUDGET_SECS), never lower than a raised per-call timeout, and at most one daemon respawn. The reply says when the daemon was replaced and why (daemon_restarted).
    • Plugin workers:
      • They exit when their daemon dies.
      • They retire after 60 s idle.
      • On Linux they are the OOM killer's first choice.
    • On Windows the daemon runs in its own hidden console and process group.
    • code-index index next to a running daemon now defers to it and exits 0 instead of refusing. It never becomes a second writer.
    • Maintenance and logging: files_fts compaction defers while the write lock is held. Undecodable text files warn once per content version instead of on every pass.

    Tool improvements

    • find_callers on a type reports target_is_type with a count of the type's members, or says when it cannot count them. This covers Rust impl blocks and C# partial classes.
    • index_freshness names the lagging paths and says whether results for all other files are current.
    • search_text takes max_lines_per_file (up to 1000) to list every matching line.
    • read_code takes a list of up to 8 targets in one call.
    • envelope: "minimal" is available on every tool. It drops explanatory prose and provenance but keeps every verdict as a field, and saved about 17% on a representative call mix. The default reply is unchanged.
    • Diagnostics:
      • A reason for a missing per-row field now compares the daemon's build with the server's instead of always blaming the daemon.
      • A failing batch entry names its own query.

    Upgrade

    No schema change and no reparse. Replace the binaries. Running daemons are replaced on the next call, and the reply reports the replacement.

    Known limits

    These are tracked as follow-ups:

    • The writer-blocked state is logged but not yet shown in index_freshness or project_overview.
    • Panic-hook cost for plugin panics.
    • The Windows parent-death check treats every error as the parent being gone.
    • Exit codes on signals.

    Validation

    • CI: the release commit passed CI on Linux and on native Windows.
      • Linux ran fmt, clippy, MSRV, the windows-gnu check, the 32-bit and wasm32 ABI tests, cargo deny, the guest crates, strict rustdoc, the workspace suite, the daemon-transport suite and the tier-1 OSS corpus job.
    • Reviews: both halves of the change were independently reviewed. Each finding was fixed together with a test that fails when the fix is removed.
    • Not covered: Linux ARM64 is cross-built and has no native runtime test. This release does not provide macOS or Windows ARM64 archives.

    Downloads

    Four platforms are built for every release. The table below says which ones THIS release published.

    Platform Archive
    Linux x86_64 (glibc) code-index-v0.32.2-linux-x86_64.tar.gz
    Linux x86_64 (static/musl) code-index-v0.32.2-linux-x86_64-musl.tar.gz
    Linux ARM64 code-index-v0.32.2-linux-aarch64.tar.gz
    Windows x64 code-index-v0.32.2-windows-x86_64.zip

    XAML plugin package

    de.h-dv.xaml-0.2.0.cip makes .xaml files carry symbols and references instead of being text-only: x:Class and Click= handlers bind into the paired C# code-behind, x:Name becomes a searchable declaration, and {Binding …} stays unresolved because no bridge can reach it.

    It is NOT installed by installing code-index. Packages are installed into a user-controlled store and approved per project, and installing grants nothing — enable is the grant.

    Download de.h-dv.xaml-0.2.0.cips too and keep the .cips beside the .cip. Packages are signed and an unsigned one is refused (signature_missing) with no flag that accepts it. You do NOT need to anchor us first: this release's publisher key is compiled into the binary, so the install below works on a machine that has anchored nobody. code-index plugin trust list shows it, marked [BUILTIN], and code-index plugin trust remove sha256:1cb03259a8c870b6db02360abd9351e17e67724d1f8c3509d85c4bf6b06fa72c withdraws it — see About that key.

    code-index plugin install de.h-dv.xaml-0.2.0.cip --sha256 sha256:7b572f5cc32ffcd5af550900a451bbef37e255804776d7e3e3e71d2dd7d0aa79
    code-index plugin check   sha256:7b572f5cc32ffcd5af550900a451bbef37e255804776d7e3e3e71d2dd7d0aa79
    code-index plugin enable  sha256:7b572f5cc32ffcd5af550900a451bbef37e255804776d7e3e3e71d2dd7d0aa79 \
        --capabilities bridge_source \
        --bridges 'de.h-dv.xaml/xaml:type->csharp:class,de.h-dv.xaml/xaml:call->csharp:method'
    

    The digest above is the one this release packed and it is what --sha256 pins; de.h-dv.xaml-0.2.0.cip.digest.txt carries it and the extraction identity. A digest that changes between releases means the package changed — re-pin, and read the notes.

    Only .xaml is claimed by this package. The TimeLine package below claims .dataset, .xsql, .shd and .lgd, and the Svelte package below claims .svelte; all other markup remains text-only (searchable, no symbols).

    TimeLine plugin package

    de.h-dv.timeline-0.1.0.cip makes the four TimeLine definition formats carry symbols and references instead of being text-only: .dataset and .xsql through one language, .shd and .lgd through another, both out of a single sandboxed extractor. References resolve INSIDE a definition file; nothing in v1 crosses into the C# that loads it.

    It is NOT installed by installing code-index. Packages are installed into a user-controlled store and approved per project, and installing grants nothing — enable is the grant.

    Download de.h-dv.timeline-0.1.0.cips too and keep the .cips beside the .cip. The same signature rules apply as for the XAML package above, and the same key signs both.

    code-index plugin install de.h-dv.timeline-0.1.0.cip --sha256 sha256:150ceb22ed9757a660d5a2bf58b80c81b60043cc419e5da5dde559d5d6fc9c9f
    code-index plugin check   sha256:150ceb22ed9757a660d5a2bf58b80c81b60043cc419e5da5dde559d5d6fc9c9f
    code-index plugin enable  sha256:150ceb22ed9757a660d5a2bf58b80c81b60043cc419e5da5dde559d5d6fc9c9f \
        --capabilities same_file_candidate,exported_candidate
    

    No --bridges, and that is the package saying so: it declares none, so there is nothing to grant. The digest above is the one this release packed and it is what --sha256 pins; de.h-dv.timeline-0.1.0.cip.digest.txt carries it and the extraction identity.

    The 5 fixtures shipped inside it are synthetic and modelled on the worked examples in the two format specifications. They carry no customer definition.

    Ruby plugin package

    de.h-dv.ruby-0.7.0.cip is the compiled-in Ruby extractor as an EXTERNAL, sandboxed package: tree-sitter-ruby loaded at runtime, the extractor compiled to wasm32-unknown-unknown and byte-reproducible from crates/guest/ruby/, and the same symbols, references, visibility and Rails association names the built-in produces.

    It claims .rbx, not .rb. The compiled-in Ruby plugin owns .rb, .rake, .gemspec, Rakefile and Gemfile, and a package may not claim a file a built-in claims. So installing this changes NOTHING about how your .rb files are indexed — it is the migration proof for running a full language out of a package, published so it can be read and run rather than described. Do not install it expecting to replace built-in Ruby support.

    It is NOT installed by installing code-index. Packages are installed into a user-controlled store and approved per project, and installing grants nothing — enable is the grant.

    Download de.h-dv.ruby-0.7.0.cips too and keep the .cips beside the .cip. The same signature rules apply as for the packages above, and one key signs every package in this release.

    code-index plugin install de.h-dv.ruby-0.7.0.cip --sha256 sha256:5779e34c30d88e213d71091b725b2f3363dfdac53c9f58b85604577db08ad9e3
    code-index plugin check   sha256:5779e34c30d88e213d71091b725b2f3363dfdac53c9f58b85604577db08ad9e3 --derived-names
    code-index plugin enable  sha256:5779e34c30d88e213d71091b725b2f3363dfdac53c9f58b85604577db08ad9e3 --derived-names \
        --capabilities same_file_candidate,exported_candidate,reachability_anchor,qualified_candidate,type_position_candidate,member_candidate
    

    --derived-names is required on check as well as on enable, and without it check REPORTS FAILED. Rails' has_many :posts emits a type reference named Post at the span of the literal :posts, so the name was not copied out of the source it points at; validation is all-or-nothing per file, so the authority is what admits the whole file rather than the one row. Withhold it and you keep the package with every Rails file refused — that is a supported answer, not a broken install.

    No --bridges: Ruby resolves inside its own language, so the package declares none. The six capabilities above are exactly what its manifest requests and enable refuses a grant wider than the request; grant fewer and the index stays searchable but resolves less, because every candidate pool a reference could be admitted to is one of them.

    The digest above is the one this release packed and it is what --sha256 pins; de.h-dv.ruby-0.7.0.cip.digest.txt carries it and the extraction identity.

    The 5 fixtures shipped inside it were generated from the COMPILED-IN Ruby extractor, by a different author from the port they grade, and plugin check compares the package's facts against them exhaustively.

    Svelte plugin package

    de.h-dv.svelte-0.1.0.cip makes .svelte files carry symbols and references instead of being text-only: the TEMPLATE half of a single-file component — markup, mustaches, {#snippet} declarations and {@render} uses — out of one sandboxed extractor over the tree-sitter-svelte-ng grammar.

    It claims .svelte and NOTHING ELSE. .svelte.ts and .svelte.js are deliberately not claimed and this package declares no [[displaces]]: those files are Svelte 5 runes modules, valid TypeScript and valid JavaScript, which the built-in plugins already index correctly. Claiming them would take files away from a producer that reads them in order to read them worse.

    It is NOT installed by installing code-index. Packages are installed into a user-controlled store and approved per project, and installing grants nothing — enable is the grant.

    Download de.h-dv.svelte-0.1.0.cips too and keep the .cips beside the .cip. The same signature rules apply as for the packages above, and one key signs every package in this release.

    code-index plugin install de.h-dv.svelte-0.1.0.cip --sha256 sha256:4b10a478532d67f3694995373e1a64d397611af5c4f2615c085b006628b3322f
    code-index plugin check   sha256:4b10a478532d67f3694995373e1a64d397611af5c4f2615c085b006628b3322f
    code-index plugin enable  sha256:4b10a478532d67f3694995373e1a64d397611af5c4f2615c085b006628b3322f \
        --capabilities same_file_candidate
    

    One capability, and that is the package asking for exactly what it can use. Every symbol this version emits is a {#snippet}, whose visibility is file: reachable by name anywhere in its own component and nowhere else. exported_candidate would admit an empty set, so it is not requested — and enable refuses a grant wider than the manifest asks for, so the line above cannot be padded. No --bridges: this package declares none.

    The digest above is the one this release packed and it is what --sha256 pins; de.h-dv.svelte-0.1.0.cip.digest.txt carries it and the extraction identity.

    The 4 fixtures shipped inside it are synthetic: one positive control in which every rule fires, two that are bait for all of them with an empty expectation, and one malformed source. None carries anybody's component.

    About that key

    sha256:1cb03259a8c870b6db02360abd9351e17e67724d1f8c3509d85c4bf6b06fa72c is a long-lived Ed25519 key held as a secret in this project's CI, used to sign released packages automatically, and it is compiled into the binaries in this release. It signs every package above. That trusts this project's release pipeline, not only its maintainers: anyone who can run a release workflow here can produce a package that verifies under it. It adds nothing you had not already granted — the bytes are inside the program you are running, so forging that anchor means forging the binary — but you are entitled to know it is there before a package installs rather than after.

    There is no expiry — deliberately, because offline installations must not break on a timer — and withdrawal is on your side and works: code-index plugin trust remove sha256:1cb03259a8c870b6db02360abd9351e17e67724d1f8c3509d85c4bf6b06fa72c. A compiled-in key has no file to delete, so that writes one instead, carrying denied = true; the key stops verifying at the next load, plugin trust list shows it marked [DENIED], and deleting that file (the command prints its path) is the only undo. If the key is ever rotated, the new fingerprint is published here and in tests/packages/first-party.fingerprint, and a build that predates the rotation will not trust it.

    You may anchor it yourself instead — code-index plugin trust add code-index-publisher.pub --fingerprint sha256:1cb03259a8c870b6db02360abd9351e17e67724d1f8c3509d85c4bf6b06fa72c --name 'a label you choose', with code-index-publisher.pub from this release's assets. Your file replaces the compiled-in entry, and the --name is a label YOU choose: nothing in the package, the key file or the signature can name its own publisher.

    macOS is not currently built. No x86_64-apple-darwin or aarch64-apple-darwin archive is published — macOS users should build from source (cargo build --release). This is a deliberate deferral, tracked in #59; no date is promised.

    Wire into Claude Code

    { "mcpServers": { "code-index": { "command": "/usr/local/bin/code-index-mcp", "args": ["--root", "/path/to/your/project"] } } }
    

    SHA256 checksums (.sha256 files) available for every archive.

    Downloads
  • v0.32.1 1e7cf2c751

    code-index v0.32.1
    All checks were successful
    CI / cargo fmt (push) Successful in 51s
    CI / OSS corpus tier-3 scale (nightly) (push) Has been skipped
    CI / Grammar rebuild from source (nightly) (push) Has been skipped
    CI / guest crates (fmt, clippy, doc) (push) Successful in 1m24s
    CI / CI lane wall-clock headroom (push) Successful in 1m29s
    CI / cargo doc (intra-doc links) (push) Successful in 6m4s
    CI / cargo deny (push) Successful in 7m14s
    CI / cargo test (abi, 32-bit + wasm32) (push) Successful in 7m47s
    CI / cargo clippy (push) Successful in 7m48s
    CI / cargo check (MSRV 1.98) (push) Successful in 8m11s
    CI / cargo check (windows-gnu) (push) Successful in 8m22s
    CI / OSS corpus (tier 1) (push) Successful in 36m32s
    CI / cargo test (push) Successful in 49m47s
    CI (Windows) / fmt + clippy + build + test (windows) (push) Successful in 1h1m16s
    CI / cargo test (daemon transport) (push) Successful in 22m6s
    CI / Plugin path cost + pool throughput (nightly) (push) Has been skipped
    Release Build / Generate Version (push) Successful in 29s
    Release Build / Required CI green (push) Successful in 1m5s
    Release Build / Build linux-aarch64 (push) Successful in 12m51s
    Release Build / Build linux-x86_64 (push) Successful in 15m40s
    Release Build / Build linux-x86_64-musl (push) Successful in 15m59s
    Release Build / Pack the Ruby language package (push) Successful in 50s
    Release Build / Pack the XAML reference package (push) Successful in 1m2s
    Release Build / Pack the TimeLine package (push) Successful in 1m11s
    Release Build / Pack the Svelte language package (push) Successful in 1m20s
    Release Build / Build windows-x86_64 (push) Successful in 23m57s
    Release Build / Windows archive smoke (msvc) (push) Successful in 26s
    Release Build / Create Forgejo Release (push) Successful in 5m50s
    Stable

    buildagent released this 2026-09-26 08:08:16 +02:00 | 94 commits to master since this release

    code-index v0.32.1

    Build: v0.32.1+908

    Installer: install.sh and checksum. Both come from this release commit. To pin the installed binaries too, run it with --tag v0.32.1.

    Windows installer: install.ps1 and checksum, from the same release commit. It installs AND updates — the same code does both — verifies the archive against its published .sha256 before unpacking, refuses hostile archive members (absolute paths, .. escapes, symlinks and reparse points, which Expand-Archive does not protect you from), and grants nothing when it installs a package: the bytes go into the machine's store and the approving line is PRINTED for you to run from inside a project. -Help lists the flags; -Tag v0.32.1 pins the binaries.

    Four-binary release: code-index-mcp (MCP stdio bridge — the usual entry), code-index-daemon (long-lived watcher + RPC server, auto-spawned), code-index-plugin-host (bounded worker for plugin packages, spawned by the daemon), and code-index (CLI: init, index, watch, doctor, link, plugin).

    Changes

    v0.32.1 fixes the precision and recall defects that two independent reviews found
    in v0.32.0. Binds were measured one by one against v0.32.0 on nine pinned repositories.

    • pytest fixtures bind again. v0.32.0 correctly stopped fixture parameters
      from binding as ordinary names, but that also removed every fixture edge. For
      example, Flask's conftest.py::client fell from 305 refs to 0. A parameter
      of a test or fixture now binds the @pytest.fixture / @fixture it names,
      including name= aliases. The lookup order is the consumer's class, its module,
      then the nearest conftest.py in the same or an ancestor directory, as pytest
      does. A fixture never resolves to itself. Two definitions at the deciding
      level refuse to bind. Calling the parameter binds nothing. Names supplied by
      @pytest.mark.parametrize are not treated as fixtures, unless they are routed
      back to a fixture with indirect=. Flask gains 786 fixture edges, and 237
      parameter uses that had bound unrelated class members now bind their fixture.
      Not modelled: pytestmark parametrization, pytest_plugins, and built-in
      fixtures.
    • Fewer wrong binds.
      • A name's own import decides a use only when that import's target was
        proven, is a free symbol rather than a member, and is visible at the use.
        Rust inline modules do not inherit the parent's use, and a Python nested
        import shadows the outer one.

      • Aliased-import and local-scope refusals follow the scope they occur in.

      • JavaScript/TypeScript body bindings are function-scoped. Arrow and one-line
        parameters belong to their function, and a generic constraint's parameters
        are no longer read as the function's own.

      • Every Rust parameter is local.

      • Measured against v0.32.0:

        Repository Wrong binds removed Correct binds lost Correct binds restored
        rust-analyzer 92 7 (glob re-exports) 0
        Zod 25 1 0
        Django 9 0 0
        Express 4 0 0

        Django's one correct loss during development, a ProxyModel bind, is
        restored by the innermost-import rule. Flask and Django also lose 8 and
        1 wrong binds from calls of a fixture's value and a mock-injected
        parameter. Guzzle,
        Sinatra and Dapper are unchanged. No wrong bind was added in any
        repository. Every change was read at source.

    • Python scope is decided at extraction. The resolver no longer re-parses
      every Python file on every pass; Django's local-scope step went from 4.4 s to
      0.4 s. Comprehensions, walrus inside comprehensions, match captures and
      PEP 695 type parameters now have their own scopes. A column mismatch that
      broke lines containing non-ASCII text is fixed.
    • Cost. The resolver statements added in v0.32.0 were rewritten. Every
      pinned repository is within +2.0% SQLite VM steps of the previous baseline
      (Flask −2.4%).
    • Clearer failures.
      • An index created by a newer build is refused by name (project_not_available
        with schema_skew, and the repair).
      • A daemon's fatal error now also reaches daemon.log.
      • code-index query exits 1 only when every batch entry refused. It warns
        when the answering server or daemon is a different build or came from
        PATH, and its --log level now reaches the server it spawns.
    • review_diff grades deleting a crate- or package-internal item as
      low internal_symbol_deleted, not an API break, and untested_change now says
      which shapes it cannot see.

    Upgrade

    Schema 71 marks every code file for one reparse. That takes about a minute on a
    3,000-file repository and a few seconds on a small one. Upgrading from 0.31.x
    or older runs schemas 70 and 71 in the same single reparse. Text files keep
    their cache.

    After upgrading, run code-index index once in each project, or let an MCP
    session's daemon finish its reconcile. Answers are incomplete until it does.
    Without a daemon, a one-shot code-index query answers warming_up with a
    reconcile_pending block (converges_on_retry: false). Retrying alone does not
    finish the reconcile, because resolution is one transaction. Making it
    resumable is tracked in #301.

    Known limits

    • #300: six wrong-bind shapes that predate this release, found by the final review.
    • 21 Django refs whose value comes from apps.get_model(...) or import_module
      stay unresolved. The one narrow rule we tried added 12 wrong binds, so it
      was not shipped.

    Validation

    The release tree passed CI on Linux (fmt, clippy, MSRV, windows-gnu check,
    32-bit and wasm32 ABI tests, cargo deny, guest crates, strict rustdoc, the
    workspace suite, the daemon-transport suite and the tier-1 OSS corpus job) and
    on native Windows. Locally the same tree passed 4,172 workspace tests, 876
    daemon-transport tests, all 14 CI corpus suites (including corpus_mutation,
    which deletes and renames definitions and requires 0 rebinds across 7,850
    sites), the tier-3 ratchet, and seven precision fixtures with 0 phantoms.

    Every fix was reviewed independently before release, and every new test's
    mutation was run: each fails when its fix is removed. The corpus change against
    v0.32.0 was measured bind for bind on all nine pinned repositories.

    Linux ARM64 is cross-built, and no native ARM64 runtime test is available.
    This release does not provide macOS or Windows ARM64 archives.

    Downloads

    Four platforms are built for every release. The table below says which ones THIS release published.

    Platform Archive
    Linux x86_64 (glibc) code-index-v0.32.1-linux-x86_64.tar.gz
    Linux x86_64 (static/musl) code-index-v0.32.1-linux-x86_64-musl.tar.gz
    Linux ARM64 code-index-v0.32.1-linux-aarch64.tar.gz
    Windows x64 code-index-v0.32.1-windows-x86_64.zip

    XAML plugin package

    de.h-dv.xaml-0.2.0.cip makes .xaml files carry symbols and references instead of being text-only: x:Class and Click= handlers bind into the paired C# code-behind, x:Name becomes a searchable declaration, and {Binding …} stays unresolved because no bridge can reach it.

    It is NOT installed by installing code-index. Packages are installed into a user-controlled store and approved per project, and installing grants nothing — enable is the grant.

    Download de.h-dv.xaml-0.2.0.cips too and keep the .cips beside the .cip. Packages are signed and an unsigned one is refused (signature_missing) with no flag that accepts it. You do NOT need to anchor us first: this release's publisher key is compiled into the binary, so the install below works on a machine that has anchored nobody. code-index plugin trust list shows it, marked [BUILTIN], and code-index plugin trust remove sha256:1cb03259a8c870b6db02360abd9351e17e67724d1f8c3509d85c4bf6b06fa72c withdraws it — see About that key.

    code-index plugin install de.h-dv.xaml-0.2.0.cip --sha256 sha256:7b572f5cc32ffcd5af550900a451bbef37e255804776d7e3e3e71d2dd7d0aa79
    code-index plugin check   sha256:7b572f5cc32ffcd5af550900a451bbef37e255804776d7e3e3e71d2dd7d0aa79
    code-index plugin enable  sha256:7b572f5cc32ffcd5af550900a451bbef37e255804776d7e3e3e71d2dd7d0aa79 \
        --capabilities bridge_source \
        --bridges 'de.h-dv.xaml/xaml:type->csharp:class,de.h-dv.xaml/xaml:call->csharp:method'
    

    The digest above is the one this release packed and it is what --sha256 pins; de.h-dv.xaml-0.2.0.cip.digest.txt carries it and the extraction identity. A digest that changes between releases means the package changed — re-pin, and read the notes.

    Only .xaml is claimed by this package. The TimeLine package below claims .dataset, .xsql, .shd and .lgd, and the Svelte package below claims .svelte; all other markup remains text-only (searchable, no symbols).

    TimeLine plugin package

    de.h-dv.timeline-0.1.0.cip makes the four TimeLine definition formats carry symbols and references instead of being text-only: .dataset and .xsql through one language, .shd and .lgd through another, both out of a single sandboxed extractor. References resolve INSIDE a definition file; nothing in v1 crosses into the C# that loads it.

    It is NOT installed by installing code-index. Packages are installed into a user-controlled store and approved per project, and installing grants nothing — enable is the grant.

    Download de.h-dv.timeline-0.1.0.cips too and keep the .cips beside the .cip. The same signature rules apply as for the XAML package above, and the same key signs both.

    code-index plugin install de.h-dv.timeline-0.1.0.cip --sha256 sha256:150ceb22ed9757a660d5a2bf58b80c81b60043cc419e5da5dde559d5d6fc9c9f
    code-index plugin check   sha256:150ceb22ed9757a660d5a2bf58b80c81b60043cc419e5da5dde559d5d6fc9c9f
    code-index plugin enable  sha256:150ceb22ed9757a660d5a2bf58b80c81b60043cc419e5da5dde559d5d6fc9c9f \
        --capabilities same_file_candidate,exported_candidate
    

    No --bridges, and that is the package saying so: it declares none, so there is nothing to grant. The digest above is the one this release packed and it is what --sha256 pins; de.h-dv.timeline-0.1.0.cip.digest.txt carries it and the extraction identity.

    The 5 fixtures shipped inside it are synthetic and modelled on the worked examples in the two format specifications. They carry no customer definition.

    Ruby plugin package

    de.h-dv.ruby-0.7.0.cip is the compiled-in Ruby extractor as an EXTERNAL, sandboxed package: tree-sitter-ruby loaded at runtime, the extractor compiled to wasm32-unknown-unknown and byte-reproducible from crates/guest/ruby/, and the same symbols, references, visibility and Rails association names the built-in produces.

    It claims .rbx, not .rb. The compiled-in Ruby plugin owns .rb, .rake, .gemspec, Rakefile and Gemfile, and a package may not claim a file a built-in claims. So installing this changes NOTHING about how your .rb files are indexed — it is the migration proof for running a full language out of a package, published so it can be read and run rather than described. Do not install it expecting to replace built-in Ruby support.

    It is NOT installed by installing code-index. Packages are installed into a user-controlled store and approved per project, and installing grants nothing — enable is the grant.

    Download de.h-dv.ruby-0.7.0.cips too and keep the .cips beside the .cip. The same signature rules apply as for the packages above, and one key signs every package in this release.

    code-index plugin install de.h-dv.ruby-0.7.0.cip --sha256 sha256:5779e34c30d88e213d71091b725b2f3363dfdac53c9f58b85604577db08ad9e3
    code-index plugin check   sha256:5779e34c30d88e213d71091b725b2f3363dfdac53c9f58b85604577db08ad9e3 --derived-names
    code-index plugin enable  sha256:5779e34c30d88e213d71091b725b2f3363dfdac53c9f58b85604577db08ad9e3 --derived-names \
        --capabilities same_file_candidate,exported_candidate,reachability_anchor,qualified_candidate,type_position_candidate,member_candidate
    

    --derived-names is required on check as well as on enable, and without it check REPORTS FAILED. Rails' has_many :posts emits a type reference named Post at the span of the literal :posts, so the name was not copied out of the source it points at; validation is all-or-nothing per file, so the authority is what admits the whole file rather than the one row. Withhold it and you keep the package with every Rails file refused — that is a supported answer, not a broken install.

    No --bridges: Ruby resolves inside its own language, so the package declares none. The six capabilities above are exactly what its manifest requests and enable refuses a grant wider than the request; grant fewer and the index stays searchable but resolves less, because every candidate pool a reference could be admitted to is one of them.

    The digest above is the one this release packed and it is what --sha256 pins; de.h-dv.ruby-0.7.0.cip.digest.txt carries it and the extraction identity.

    The 5 fixtures shipped inside it were generated from the COMPILED-IN Ruby extractor, by a different author from the port they grade, and plugin check compares the package's facts against them exhaustively.

    Svelte plugin package

    de.h-dv.svelte-0.1.0.cip makes .svelte files carry symbols and references instead of being text-only: the TEMPLATE half of a single-file component — markup, mustaches, {#snippet} declarations and {@render} uses — out of one sandboxed extractor over the tree-sitter-svelte-ng grammar.

    It claims .svelte and NOTHING ELSE. .svelte.ts and .svelte.js are deliberately not claimed and this package declares no [[displaces]]: those files are Svelte 5 runes modules, valid TypeScript and valid JavaScript, which the built-in plugins already index correctly. Claiming them would take files away from a producer that reads them in order to read them worse.

    It is NOT installed by installing code-index. Packages are installed into a user-controlled store and approved per project, and installing grants nothing — enable is the grant.

    Download de.h-dv.svelte-0.1.0.cips too and keep the .cips beside the .cip. The same signature rules apply as for the packages above, and one key signs every package in this release.

    code-index plugin install de.h-dv.svelte-0.1.0.cip --sha256 sha256:4b10a478532d67f3694995373e1a64d397611af5c4f2615c085b006628b3322f
    code-index plugin check   sha256:4b10a478532d67f3694995373e1a64d397611af5c4f2615c085b006628b3322f
    code-index plugin enable  sha256:4b10a478532d67f3694995373e1a64d397611af5c4f2615c085b006628b3322f \
        --capabilities same_file_candidate
    

    One capability, and that is the package asking for exactly what it can use. Every symbol this version emits is a {#snippet}, whose visibility is file: reachable by name anywhere in its own component and nowhere else. exported_candidate would admit an empty set, so it is not requested — and enable refuses a grant wider than the manifest asks for, so the line above cannot be padded. No --bridges: this package declares none.

    The digest above is the one this release packed and it is what --sha256 pins; de.h-dv.svelte-0.1.0.cip.digest.txt carries it and the extraction identity.

    The 4 fixtures shipped inside it are synthetic: one positive control in which every rule fires, two that are bait for all of them with an empty expectation, and one malformed source. None carries anybody's component.

    About that key

    sha256:1cb03259a8c870b6db02360abd9351e17e67724d1f8c3509d85c4bf6b06fa72c is a long-lived Ed25519 key held as a secret in this project's CI, used to sign released packages automatically, and it is compiled into the binaries in this release. It signs every package above. That trusts this project's release pipeline, not only its maintainers: anyone who can run a release workflow here can produce a package that verifies under it. It adds nothing you had not already granted — the bytes are inside the program you are running, so forging that anchor means forging the binary — but you are entitled to know it is there before a package installs rather than after.

    There is no expiry — deliberately, because offline installations must not break on a timer — and withdrawal is on your side and works: code-index plugin trust remove sha256:1cb03259a8c870b6db02360abd9351e17e67724d1f8c3509d85c4bf6b06fa72c. A compiled-in key has no file to delete, so that writes one instead, carrying denied = true; the key stops verifying at the next load, plugin trust list shows it marked [DENIED], and deleting that file (the command prints its path) is the only undo. If the key is ever rotated, the new fingerprint is published here and in tests/packages/first-party.fingerprint, and a build that predates the rotation will not trust it.

    You may anchor it yourself instead — code-index plugin trust add code-index-publisher.pub --fingerprint sha256:1cb03259a8c870b6db02360abd9351e17e67724d1f8c3509d85c4bf6b06fa72c --name 'a label you choose', with code-index-publisher.pub from this release's assets. Your file replaces the compiled-in entry, and the --name is a label YOU choose: nothing in the package, the key file or the signature can name its own publisher.

    macOS is not currently built. No x86_64-apple-darwin or aarch64-apple-darwin archive is published — macOS users should build from source (cargo build --release). This is a deliberate deferral, tracked in #59; no date is promised.

    Wire into Claude Code

    { "mcpServers": { "code-index": { "command": "/usr/local/bin/code-index-mcp", "args": ["--root", "/path/to/your/project"] } } }
    

    SHA256 checksums (.sha256 files) available for every archive.

    Downloads
  • v0.32.0 4e3034a258

    code-index v0.32.0
    All checks were successful
    CI / cargo fmt (push) Successful in 49s
    CI / OSS corpus tier-3 scale (nightly) (push) Has been skipped
    CI / Grammar rebuild from source (nightly) (push) Has been skipped
    CI / CI lane wall-clock headroom (push) Successful in 1m12s
    CI / guest crates (fmt, clippy, doc) (push) Successful in 1m19s
    CI / cargo doc (intra-doc links) (push) Successful in 7m14s
    CI / cargo deny (push) Successful in 7m42s
    CI / cargo test (abi, 32-bit + wasm32) (push) Successful in 8m34s
    CI / cargo clippy (push) Successful in 8m48s
    CI / cargo check (MSRV 1.98) (push) Successful in 8m57s
    CI / cargo check (windows-gnu) (push) Successful in 9m17s
    CI / OSS corpus (tier 1) (push) Successful in 38m26s
    CI / cargo test (push) Successful in 49m34s
    CI / cargo test (daemon transport) (push) Successful in 21m18s
    CI / Plugin path cost + pool throughput (nightly) (push) Has been skipped
    CI (Windows) / fmt + clippy + build + test (windows) (push) Successful in 58m23s
    Release Build / Generate Version (push) Successful in 28s
    Release Build / Required CI green (push) Successful in 57s
    Release Build / Build linux-aarch64 (push) Successful in 12m44s
    Release Build / Build linux-x86_64 (push) Successful in 15m31s
    Release Build / Build linux-x86_64-musl (push) Successful in 16m7s
    Release Build / Pack the TimeLine package (push) Successful in 52s
    Release Build / Pack the Ruby language package (push) Successful in 58s
    Release Build / Pack the XAML reference package (push) Successful in 1m18s
    Release Build / Windows archive smoke (msvc) (push) Successful in 25s
    Release Build / Create Forgejo Release (push) Successful in 5m41s
    Release Build / Pack the Svelte language package (push) Successful in 1m9s
    Release Build / Build windows-x86_64 (push) Successful in 25m0s
    Stable

    buildagent released this 2026-09-24 21:40:12 +02:00 | 149 commits to master since this release

    code-index v0.32.0

    Build: v0.32.0+899

    Installer: install.sh and checksum. Both come from this release commit. To pin the installed binaries too, run it with --tag v0.32.0.

    Windows installer: install.ps1 and checksum, from the same release commit. It installs AND updates — the same code does both — verifies the archive against its published .sha256 before unpacking, refuses hostile archive members (absolute paths, .. escapes, symlinks and reparse points, which Expand-Archive does not protect you from), and grants nothing when it installs a package: the bytes go into the machine's store and the approving line is PRINTED for you to run from inside a project. -Help lists the flags; -Tag v0.32.0 pins the binaries.

    Four-binary release: code-index-mcp (MCP stdio bridge — the usual entry), code-index-daemon (long-lived watcher + RPC server, auto-spawned), code-index-plugin-host (bounded worker for plugin packages, spawned by the daemon), and code-index (CLI: init, index, watch, doctor, link, plugin).

    Changes

    Python module constants and type aliases are now indexed. Name resolution handles
    local values, nested scopes, imports, and qualified receivers more accurately,
    including a fix for nested imports shadowed by parameters in an outer function.

    Symbol search adds identifier-token matching and reports its match tiers. Linked
    projects use the same ranking when merging pages, preventing repeated or omitted
    token matches. Symbol-name arguments and read_code text responses complete the
    resolver and search integration.

    Upgrade

    Index schema 70 reparses code files once on upgrade so existing indexes receive
    the new extraction and resolution behavior. Text metadata is preserved.

    Validation

    The release commit passed 4,107 workspace tests, 871 daemon-transport tests,
    42 corpus/package checks, seven precision fixtures, and the agent benchmark.
    Mutation checks confirmed both new regression tests fail when their fixes are
    removed. Linux and native Windows CI passed, including the repeat runs on master.
    The first release build also passed all four archive builds, plugin packaging,
    and the native Windows archive smoke test; publication stopped only because
    these tag notes lacked the required Markdown headings.

    Linux ARM64 is cross-built; no native ARM64 runtime test is available. macOS and
    Windows ARM64 archives are not provided by this release.

    Downloads

    Four platforms are built for every release. The table below says which ones THIS release published.

    Platform Archive
    Linux x86_64 (glibc) code-index-v0.32.0-linux-x86_64.tar.gz
    Linux x86_64 (static/musl) code-index-v0.32.0-linux-x86_64-musl.tar.gz
    Linux ARM64 code-index-v0.32.0-linux-aarch64.tar.gz
    Windows x64 code-index-v0.32.0-windows-x86_64.zip

    XAML plugin package

    de.h-dv.xaml-0.2.0.cip makes .xaml files carry symbols and references instead of being text-only: x:Class and Click= handlers bind into the paired C# code-behind, x:Name becomes a searchable declaration, and {Binding …} stays unresolved because no bridge can reach it.

    It is NOT installed by installing code-index. Packages are installed into a user-controlled store and approved per project, and installing grants nothing — enable is the grant.

    Download de.h-dv.xaml-0.2.0.cips too and keep the .cips beside the .cip. Packages are signed and an unsigned one is refused (signature_missing) with no flag that accepts it. You do NOT need to anchor us first: this release's publisher key is compiled into the binary, so the install below works on a machine that has anchored nobody. code-index plugin trust list shows it, marked [BUILTIN], and code-index plugin trust remove sha256:1cb03259a8c870b6db02360abd9351e17e67724d1f8c3509d85c4bf6b06fa72c withdraws it — see About that key.

    code-index plugin install de.h-dv.xaml-0.2.0.cip --sha256 sha256:7b572f5cc32ffcd5af550900a451bbef37e255804776d7e3e3e71d2dd7d0aa79
    code-index plugin check   sha256:7b572f5cc32ffcd5af550900a451bbef37e255804776d7e3e3e71d2dd7d0aa79
    code-index plugin enable  sha256:7b572f5cc32ffcd5af550900a451bbef37e255804776d7e3e3e71d2dd7d0aa79 \
        --capabilities bridge_source \
        --bridges 'de.h-dv.xaml/xaml:type->csharp:class,de.h-dv.xaml/xaml:call->csharp:method'
    

    The digest above is the one this release packed and it is what --sha256 pins; de.h-dv.xaml-0.2.0.cip.digest.txt carries it and the extraction identity. A digest that changes between releases means the package changed — re-pin, and read the notes.

    Only .xaml is claimed by this package. The TimeLine package below claims .dataset, .xsql, .shd and .lgd, and the Svelte package below claims .svelte; all other markup remains text-only (searchable, no symbols).

    TimeLine plugin package

    de.h-dv.timeline-0.1.0.cip makes the four TimeLine definition formats carry symbols and references instead of being text-only: .dataset and .xsql through one language, .shd and .lgd through another, both out of a single sandboxed extractor. References resolve INSIDE a definition file; nothing in v1 crosses into the C# that loads it.

    It is NOT installed by installing code-index. Packages are installed into a user-controlled store and approved per project, and installing grants nothing — enable is the grant.

    Download de.h-dv.timeline-0.1.0.cips too and keep the .cips beside the .cip. The same signature rules apply as for the XAML package above, and the same key signs both.

    code-index plugin install de.h-dv.timeline-0.1.0.cip --sha256 sha256:150ceb22ed9757a660d5a2bf58b80c81b60043cc419e5da5dde559d5d6fc9c9f
    code-index plugin check   sha256:150ceb22ed9757a660d5a2bf58b80c81b60043cc419e5da5dde559d5d6fc9c9f
    code-index plugin enable  sha256:150ceb22ed9757a660d5a2bf58b80c81b60043cc419e5da5dde559d5d6fc9c9f \
        --capabilities same_file_candidate,exported_candidate
    

    No --bridges, and that is the package saying so: it declares none, so there is nothing to grant. The digest above is the one this release packed and it is what --sha256 pins; de.h-dv.timeline-0.1.0.cip.digest.txt carries it and the extraction identity.

    The 5 fixtures shipped inside it are synthetic and modelled on the worked examples in the two format specifications. They carry no customer definition.

    Ruby plugin package

    de.h-dv.ruby-0.7.0.cip is the compiled-in Ruby extractor as an EXTERNAL, sandboxed package: tree-sitter-ruby loaded at runtime, the extractor compiled to wasm32-unknown-unknown and byte-reproducible from crates/guest/ruby/, and the same symbols, references, visibility and Rails association names the built-in produces.

    It claims .rbx, not .rb. The compiled-in Ruby plugin owns .rb, .rake, .gemspec, Rakefile and Gemfile, and a package may not claim a file a built-in claims. So installing this changes NOTHING about how your .rb files are indexed — it is the migration proof for running a full language out of a package, published so it can be read and run rather than described. Do not install it expecting to replace built-in Ruby support.

    It is NOT installed by installing code-index. Packages are installed into a user-controlled store and approved per project, and installing grants nothing — enable is the grant.

    Download de.h-dv.ruby-0.7.0.cips too and keep the .cips beside the .cip. The same signature rules apply as for the packages above, and one key signs every package in this release.

    code-index plugin install de.h-dv.ruby-0.7.0.cip --sha256 sha256:5779e34c30d88e213d71091b725b2f3363dfdac53c9f58b85604577db08ad9e3
    code-index plugin check   sha256:5779e34c30d88e213d71091b725b2f3363dfdac53c9f58b85604577db08ad9e3 --derived-names
    code-index plugin enable  sha256:5779e34c30d88e213d71091b725b2f3363dfdac53c9f58b85604577db08ad9e3 --derived-names \
        --capabilities same_file_candidate,exported_candidate,reachability_anchor,qualified_candidate,type_position_candidate,member_candidate
    

    --derived-names is required on check as well as on enable, and without it check REPORTS FAILED. Rails' has_many :posts emits a type reference named Post at the span of the literal :posts, so the name was not copied out of the source it points at; validation is all-or-nothing per file, so the authority is what admits the whole file rather than the one row. Withhold it and you keep the package with every Rails file refused — that is a supported answer, not a broken install.

    No --bridges: Ruby resolves inside its own language, so the package declares none. The six capabilities above are exactly what its manifest requests and enable refuses a grant wider than the request; grant fewer and the index stays searchable but resolves less, because every candidate pool a reference could be admitted to is one of them.

    The digest above is the one this release packed and it is what --sha256 pins; de.h-dv.ruby-0.7.0.cip.digest.txt carries it and the extraction identity.

    The 5 fixtures shipped inside it were generated from the COMPILED-IN Ruby extractor, by a different author from the port they grade, and plugin check compares the package's facts against them exhaustively.

    Svelte plugin package

    de.h-dv.svelte-0.1.0.cip makes .svelte files carry symbols and references instead of being text-only: the TEMPLATE half of a single-file component — markup, mustaches, {#snippet} declarations and {@render} uses — out of one sandboxed extractor over the tree-sitter-svelte-ng grammar.

    It claims .svelte and NOTHING ELSE. .svelte.ts and .svelte.js are deliberately not claimed and this package declares no [[displaces]]: those files are Svelte 5 runes modules, valid TypeScript and valid JavaScript, which the built-in plugins already index correctly. Claiming them would take files away from a producer that reads them in order to read them worse.

    It is NOT installed by installing code-index. Packages are installed into a user-controlled store and approved per project, and installing grants nothing — enable is the grant.

    Download de.h-dv.svelte-0.1.0.cips too and keep the .cips beside the .cip. The same signature rules apply as for the packages above, and one key signs every package in this release.

    code-index plugin install de.h-dv.svelte-0.1.0.cip --sha256 sha256:4b10a478532d67f3694995373e1a64d397611af5c4f2615c085b006628b3322f
    code-index plugin check   sha256:4b10a478532d67f3694995373e1a64d397611af5c4f2615c085b006628b3322f
    code-index plugin enable  sha256:4b10a478532d67f3694995373e1a64d397611af5c4f2615c085b006628b3322f \
        --capabilities same_file_candidate
    

    One capability, and that is the package asking for exactly what it can use. Every symbol this version emits is a {#snippet}, whose visibility is file: reachable by name anywhere in its own component and nowhere else. exported_candidate would admit an empty set, so it is not requested — and enable refuses a grant wider than the manifest asks for, so the line above cannot be padded. No --bridges: this package declares none.

    The digest above is the one this release packed and it is what --sha256 pins; de.h-dv.svelte-0.1.0.cip.digest.txt carries it and the extraction identity.

    The 4 fixtures shipped inside it are synthetic: one positive control in which every rule fires, two that are bait for all of them with an empty expectation, and one malformed source. None carries anybody's component.

    About that key

    sha256:1cb03259a8c870b6db02360abd9351e17e67724d1f8c3509d85c4bf6b06fa72c is a long-lived Ed25519 key held as a secret in this project's CI, used to sign released packages automatically, and it is compiled into the binaries in this release. It signs every package above. That trusts this project's release pipeline, not only its maintainers: anyone who can run a release workflow here can produce a package that verifies under it. It adds nothing you had not already granted — the bytes are inside the program you are running, so forging that anchor means forging the binary — but you are entitled to know it is there before a package installs rather than after.

    There is no expiry — deliberately, because offline installations must not break on a timer — and withdrawal is on your side and works: code-index plugin trust remove sha256:1cb03259a8c870b6db02360abd9351e17e67724d1f8c3509d85c4bf6b06fa72c. A compiled-in key has no file to delete, so that writes one instead, carrying denied = true; the key stops verifying at the next load, plugin trust list shows it marked [DENIED], and deleting that file (the command prints its path) is the only undo. If the key is ever rotated, the new fingerprint is published here and in tests/packages/first-party.fingerprint, and a build that predates the rotation will not trust it.

    You may anchor it yourself instead — code-index plugin trust add code-index-publisher.pub --fingerprint sha256:1cb03259a8c870b6db02360abd9351e17e67724d1f8c3509d85c4bf6b06fa72c --name 'a label you choose', with code-index-publisher.pub from this release's assets. Your file replaces the compiled-in entry, and the --name is a label YOU choose: nothing in the package, the key file or the signature can name its own publisher.

    macOS is not currently built. No x86_64-apple-darwin or aarch64-apple-darwin archive is published — macOS users should build from source (cargo build --release). This is a deliberate deferral, tracked in #59; no date is promised.

    Wire into Claude Code

    { "mcpServers": { "code-index": { "command": "/usr/local/bin/code-index-mcp", "args": ["--root", "/path/to/your/project"] } } }
    

    SHA256 checksums (.sha256 files) available for every archive.

    Downloads
  • v0.31.2 e255008cf3

    code-index v0.31.2
    All checks were successful
    CI / cargo fmt (push) Successful in 49s
    CI / OSS corpus tier-3 scale (nightly) (push) Has been skipped
    CI / Grammar rebuild from source (nightly) (push) Has been skipped
    CI / CI lane wall-clock headroom (push) Successful in 1m0s
    CI / guest crates (fmt, clippy, doc) (push) Successful in 1m30s
    CI / cargo doc (intra-doc links) (push) Successful in 5m11s
    CI / cargo clippy (push) Successful in 5m53s
    CI / cargo deny (push) Successful in 6m13s
    CI / cargo test (abi, 32-bit + wasm32) (push) Successful in 6m19s
    CI / cargo check (MSRV 1.98) (push) Successful in 6m24s
    CI / cargo check (windows-gnu) (push) Successful in 6m30s
    CI / OSS corpus (tier 1) (push) Successful in 29m26s
    CI / cargo test (push) Successful in 41m7s
    CI (Windows) / fmt + clippy + build + test (windows) (push) Successful in 1h1m14s
    CI / cargo test (daemon transport) (push) Successful in 20m19s
    CI / Plugin path cost + pool throughput (nightly) (push) Has been skipped
    Release Build / Generate Version (push) Successful in 22s
    Release Build / Required CI green (push) Successful in 1m10s
    Release Build / Build linux-aarch64 (push) Successful in 13m9s
    Release Build / Build linux-x86_64 (push) Successful in 15m29s
    Release Build / Build linux-x86_64-musl (push) Successful in 16m12s
    Release Build / Pack the XAML reference package (push) Successful in 53s
    Release Build / Pack the Ruby language package (push) Successful in 59s
    Release Build / Pack the TimeLine package (push) Successful in 1m12s
    Release Build / Pack the Svelte language package (push) Successful in 1m21s
    Release Build / Build windows-x86_64 (push) Successful in 23m18s
    Release Build / Windows archive smoke (msvc) (push) Successful in 24s
    Release Build / Create Forgejo Release (push) Successful in 5m49s
    Stable

    buildagent released this 2026-09-23 22:32:31 +02:00 | 182 commits to master since this release

    code-index v0.31.2

    Build: v0.31.2+890

    Installer: install.sh and checksum. Both come from this release commit. To pin the installed binaries too, run it with --tag v0.31.2.

    Windows installer: install.ps1 and checksum, from the same release commit. It installs AND updates — the same code does both — verifies the archive against its published .sha256 before unpacking, refuses hostile archive members (absolute paths, .. escapes, symlinks and reparse points, which Expand-Archive does not protect you from), and grants nothing when it installs a package: the bytes go into the machine's store and the approving line is PRINTED for you to run from inside a project. -Help lists the flags; -Tag v0.31.2 pins the binaries.

    Four-binary release: code-index-mcp (MCP stdio bridge — the usual entry), code-index-daemon (long-lived watcher + RPC server, auto-spawned), code-index-plugin-host (bounded worker for plugin packages, spawned by the daemon), and code-index (CLI: init, index, watch, doctor, link, plugin).

    #294: calls with no parentheses produced no reference

    forbidden_response — no parentheses, no arguments, no receiver — is how
    Ruby normally calls an attribute reader, predicate or memoized helper. It
    parses exactly like a local-variable read, and the extractor recorded
    nothing for it. A method called only that way showed ref_count: 0 and
    name_fallback_count: 0 with no qualification: an earned-looking zero over
    real call sites.

    Both extractors — the builtin and the de.h-dv.ruby package — now apply
    Ruby's own lexical rule (a name is a local once an assignment, parameter,
    block parameter, pattern or regex capture binds it; otherwise it is a call)
    and emit a row per call site. A row binds only when the calling class
    defines the method in the same file; inside a block, where instance_eval
    may have changed self, it stays unresolved and disclosed. Five encodings
    were measured bind-for-bind on the Ruby corpus before this one held.

    de.h-dv.ruby is 0.7.0: both digests moved, so projects with the
    package enabled re-extract their .rbx files.

    #295: check_rename and Ruby method names

    Renaming to valid?, save! or name= is now accepted for Ruby symbols,
    and the text scan runs on those names instead of switching off.

    Search ranking

    A symbol declared past column 200 — minified or generated code, measured
    against every human-written declaration in the corpus — now ranks below the
    project's own symbols of the same name. It is demoted, never hidden.

    Wording

    The "1.00 precision" figure now says what it is: precision, not recall.

    Known and filed

    Constant-receiver calls (#296), autoload as a dependency (#297) and
    extensionless shebang scripts (#298) are unresolved and disclosed; each
    issue carries the measurement showing why the obvious fix was not shipped.

    Downloads

    Four platforms are built for every release. The table below says which ones THIS release published.

    Platform Archive
    Linux x86_64 (glibc) code-index-v0.31.2-linux-x86_64.tar.gz
    Linux x86_64 (static/musl) code-index-v0.31.2-linux-x86_64-musl.tar.gz
    Linux ARM64 code-index-v0.31.2-linux-aarch64.tar.gz
    Windows x64 code-index-v0.31.2-windows-x86_64.zip

    XAML plugin package

    de.h-dv.xaml-0.2.0.cip makes .xaml files carry symbols and references instead of being text-only: x:Class and Click= handlers bind into the paired C# code-behind, x:Name becomes a searchable declaration, and {Binding …} stays unresolved because no bridge can reach it.

    It is NOT installed by installing code-index. Packages are installed into a user-controlled store and approved per project, and installing grants nothing — enable is the grant.

    Download de.h-dv.xaml-0.2.0.cips too and keep the .cips beside the .cip. Packages are signed and an unsigned one is refused (signature_missing) with no flag that accepts it. You do NOT need to anchor us first: this release's publisher key is compiled into the binary, so the install below works on a machine that has anchored nobody. code-index plugin trust list shows it, marked [BUILTIN], and code-index plugin trust remove sha256:1cb03259a8c870b6db02360abd9351e17e67724d1f8c3509d85c4bf6b06fa72c withdraws it — see About that key.

    code-index plugin install de.h-dv.xaml-0.2.0.cip --sha256 sha256:7b572f5cc32ffcd5af550900a451bbef37e255804776d7e3e3e71d2dd7d0aa79
    code-index plugin check   sha256:7b572f5cc32ffcd5af550900a451bbef37e255804776d7e3e3e71d2dd7d0aa79
    code-index plugin enable  sha256:7b572f5cc32ffcd5af550900a451bbef37e255804776d7e3e3e71d2dd7d0aa79 \
        --capabilities bridge_source \
        --bridges 'de.h-dv.xaml/xaml:type->csharp:class,de.h-dv.xaml/xaml:call->csharp:method'
    

    The digest above is the one this release packed and it is what --sha256 pins; de.h-dv.xaml-0.2.0.cip.digest.txt carries it and the extraction identity. A digest that changes between releases means the package changed — re-pin, and read the notes.

    Only .xaml is claimed by this package. The TimeLine package below claims .dataset, .xsql, .shd and .lgd, and the Svelte package below claims .svelte; all other markup remains text-only (searchable, no symbols).

    TimeLine plugin package

    de.h-dv.timeline-0.1.0.cip makes the four TimeLine definition formats carry symbols and references instead of being text-only: .dataset and .xsql through one language, .shd and .lgd through another, both out of a single sandboxed extractor. References resolve INSIDE a definition file; nothing in v1 crosses into the C# that loads it.

    It is NOT installed by installing code-index. Packages are installed into a user-controlled store and approved per project, and installing grants nothing — enable is the grant.

    Download de.h-dv.timeline-0.1.0.cips too and keep the .cips beside the .cip. The same signature rules apply as for the XAML package above, and the same key signs both.

    code-index plugin install de.h-dv.timeline-0.1.0.cip --sha256 sha256:150ceb22ed9757a660d5a2bf58b80c81b60043cc419e5da5dde559d5d6fc9c9f
    code-index plugin check   sha256:150ceb22ed9757a660d5a2bf58b80c81b60043cc419e5da5dde559d5d6fc9c9f
    code-index plugin enable  sha256:150ceb22ed9757a660d5a2bf58b80c81b60043cc419e5da5dde559d5d6fc9c9f \
        --capabilities same_file_candidate,exported_candidate
    

    No --bridges, and that is the package saying so: it declares none, so there is nothing to grant. The digest above is the one this release packed and it is what --sha256 pins; de.h-dv.timeline-0.1.0.cip.digest.txt carries it and the extraction identity.

    The 5 fixtures shipped inside it are synthetic and modelled on the worked examples in the two format specifications. They carry no customer definition.

    Ruby plugin package

    de.h-dv.ruby-0.7.0.cip is the compiled-in Ruby extractor as an EXTERNAL, sandboxed package: tree-sitter-ruby loaded at runtime, the extractor compiled to wasm32-unknown-unknown and byte-reproducible from crates/guest/ruby/, and the same symbols, references, visibility and Rails association names the built-in produces.

    It claims .rbx, not .rb. The compiled-in Ruby plugin owns .rb, .rake, .gemspec, Rakefile and Gemfile, and a package may not claim a file a built-in claims. So installing this changes NOTHING about how your .rb files are indexed — it is the migration proof for running a full language out of a package, published so it can be read and run rather than described. Do not install it expecting to replace built-in Ruby support.

    It is NOT installed by installing code-index. Packages are installed into a user-controlled store and approved per project, and installing grants nothing — enable is the grant.

    Download de.h-dv.ruby-0.7.0.cips too and keep the .cips beside the .cip. The same signature rules apply as for the packages above, and one key signs every package in this release.

    code-index plugin install de.h-dv.ruby-0.7.0.cip --sha256 sha256:5779e34c30d88e213d71091b725b2f3363dfdac53c9f58b85604577db08ad9e3
    code-index plugin check   sha256:5779e34c30d88e213d71091b725b2f3363dfdac53c9f58b85604577db08ad9e3 --derived-names
    code-index plugin enable  sha256:5779e34c30d88e213d71091b725b2f3363dfdac53c9f58b85604577db08ad9e3 --derived-names \
        --capabilities same_file_candidate,exported_candidate,reachability_anchor,qualified_candidate,type_position_candidate,member_candidate
    

    --derived-names is required on check as well as on enable, and without it check REPORTS FAILED. Rails' has_many :posts emits a type reference named Post at the span of the literal :posts, so the name was not copied out of the source it points at; validation is all-or-nothing per file, so the authority is what admits the whole file rather than the one row. Withhold it and you keep the package with every Rails file refused — that is a supported answer, not a broken install.

    No --bridges: Ruby resolves inside its own language, so the package declares none. The six capabilities above are exactly what its manifest requests and enable refuses a grant wider than the request; grant fewer and the index stays searchable but resolves less, because every candidate pool a reference could be admitted to is one of them.

    The digest above is the one this release packed and it is what --sha256 pins; de.h-dv.ruby-0.7.0.cip.digest.txt carries it and the extraction identity.

    The 5 fixtures shipped inside it were generated from the COMPILED-IN Ruby extractor, by a different author from the port they grade, and plugin check compares the package's facts against them exhaustively.

    Svelte plugin package

    de.h-dv.svelte-0.1.0.cip makes .svelte files carry symbols and references instead of being text-only: the TEMPLATE half of a single-file component — markup, mustaches, {#snippet} declarations and {@render} uses — out of one sandboxed extractor over the tree-sitter-svelte-ng grammar.

    It claims .svelte and NOTHING ELSE. .svelte.ts and .svelte.js are deliberately not claimed and this package declares no [[displaces]]: those files are Svelte 5 runes modules, valid TypeScript and valid JavaScript, which the built-in plugins already index correctly. Claiming them would take files away from a producer that reads them in order to read them worse.

    It is NOT installed by installing code-index. Packages are installed into a user-controlled store and approved per project, and installing grants nothing — enable is the grant.

    Download de.h-dv.svelte-0.1.0.cips too and keep the .cips beside the .cip. The same signature rules apply as for the packages above, and one key signs every package in this release.

    code-index plugin install de.h-dv.svelte-0.1.0.cip --sha256 sha256:4b10a478532d67f3694995373e1a64d397611af5c4f2615c085b006628b3322f
    code-index plugin check   sha256:4b10a478532d67f3694995373e1a64d397611af5c4f2615c085b006628b3322f
    code-index plugin enable  sha256:4b10a478532d67f3694995373e1a64d397611af5c4f2615c085b006628b3322f \
        --capabilities same_file_candidate
    

    One capability, and that is the package asking for exactly what it can use. Every symbol this version emits is a {#snippet}, whose visibility is file: reachable by name anywhere in its own component and nowhere else. exported_candidate would admit an empty set, so it is not requested — and enable refuses a grant wider than the manifest asks for, so the line above cannot be padded. No --bridges: this package declares none.

    The digest above is the one this release packed and it is what --sha256 pins; de.h-dv.svelte-0.1.0.cip.digest.txt carries it and the extraction identity.

    The 4 fixtures shipped inside it are synthetic: one positive control in which every rule fires, two that are bait for all of them with an empty expectation, and one malformed source. None carries anybody's component.

    About that key

    sha256:1cb03259a8c870b6db02360abd9351e17e67724d1f8c3509d85c4bf6b06fa72c is a long-lived Ed25519 key held as a secret in this project's CI, used to sign released packages automatically, and it is compiled into the binaries in this release. It signs every package above. That trusts this project's release pipeline, not only its maintainers: anyone who can run a release workflow here can produce a package that verifies under it. It adds nothing you had not already granted — the bytes are inside the program you are running, so forging that anchor means forging the binary — but you are entitled to know it is there before a package installs rather than after.

    There is no expiry — deliberately, because offline installations must not break on a timer — and withdrawal is on your side and works: code-index plugin trust remove sha256:1cb03259a8c870b6db02360abd9351e17e67724d1f8c3509d85c4bf6b06fa72c. A compiled-in key has no file to delete, so that writes one instead, carrying denied = true; the key stops verifying at the next load, plugin trust list shows it marked [DENIED], and deleting that file (the command prints its path) is the only undo. If the key is ever rotated, the new fingerprint is published here and in tests/packages/first-party.fingerprint, and a build that predates the rotation will not trust it.

    You may anchor it yourself instead — code-index plugin trust add code-index-publisher.pub --fingerprint sha256:1cb03259a8c870b6db02360abd9351e17e67724d1f8c3509d85c4bf6b06fa72c --name 'a label you choose', with code-index-publisher.pub from this release's assets. Your file replaces the compiled-in entry, and the --name is a label YOU choose: nothing in the package, the key file or the signature can name its own publisher.

    macOS is not currently built. No x86_64-apple-darwin or aarch64-apple-darwin archive is published — macOS users should build from source (cargo build --release). This is a deliberate deferral, tracked in #59; no date is promised.

    Wire into Claude Code

    { "mcpServers": { "code-index": { "command": "/usr/local/bin/code-index-mcp", "args": ["--root", "/path/to/your/project"] } } }
    

    SHA256 checksums (.sha256 files) available for every archive.

    Downloads
  • v0.31.1 023ee7a53d

    code-index v0.31.1
    All checks were successful
    CI / cargo fmt (push) Successful in 51s
    CI / OSS corpus tier-3 scale (nightly) (push) Has been skipped
    CI / Grammar rebuild from source (nightly) (push) Has been skipped
    CI / CI lane wall-clock headroom (push) Successful in 50s
    CI / guest crates (fmt, clippy, doc) (push) Successful in 1m25s
    CI / cargo doc (intra-doc links) (push) Successful in 5m25s
    CI / cargo deny (push) Successful in 5m37s
    CI / cargo clippy (push) Successful in 6m35s
    CI / cargo test (abi, 32-bit + wasm32) (push) Successful in 6m47s
    CI / cargo check (MSRV 1.98) (push) Successful in 6m49s
    CI / cargo check (windows-gnu) (push) Successful in 6m58s
    CI / OSS corpus (tier 1) (push) Successful in 30m27s
    CI / cargo test (push) Successful in 40m59s
    CI / cargo test (daemon transport) (push) Successful in 20m25s
    CI / Plugin path cost + pool throughput (nightly) (push) Has been skipped
    CI (Windows) / fmt + clippy + build + test (windows) (push) Successful in 1h32m32s
    Release Build / Generate Version (push) Successful in 28s
    Release Build / Required CI green (push) Successful in 1m4s
    Release Build / Build linux-aarch64 (push) Successful in 12m48s
    Release Build / Build linux-x86_64 (push) Successful in 15m50s
    Release Build / Build linux-x86_64-musl (push) Successful in 16m5s
    Release Build / Pack the Svelte language package (push) Successful in 51s
    Release Build / Pack the Ruby language package (push) Successful in 57s
    Release Build / Pack the XAML reference package (push) Successful in 1m8s
    Release Build / Pack the TimeLine package (push) Successful in 1m18s
    Release Build / Build windows-x86_64 (push) Successful in 21m56s
    Release Build / Windows archive smoke (msvc) (push) Successful in 23s
    Release Build / Create Forgejo Release (push) Successful in 5m47s
    Stable

    buildagent released this 2026-09-22 20:55:32 +02:00 | 188 commits to master since this release

    code-index v0.31.1

    Build: v0.31.1+884

    Installer: install.sh and checksum. Both come from this release commit. To pin the installed binaries too, run it with --tag v0.31.1.

    Windows installer: install.ps1 and checksum, from the same release commit. It installs AND updates — the same code does both — verifies the archive against its published .sha256 before unpacking, refuses hostile archive members (absolute paths, .. escapes, symlinks and reparse points, which Expand-Archive does not protect you from), and grants nothing when it installs a package: the bytes go into the machine's store and the approving line is PRINTED for you to run from inside a project. -Help lists the flags; -Tag v0.31.1 pins the binaries.

    Four-binary release: code-index-mcp (MCP stdio bridge — the usual entry), code-index-daemon (long-lived watcher + RPC server, auto-spawned), code-index-plugin-host (bounded worker for plugin packages, spawned by the daemon), and code-index (CLI: init, index, watch, doctor, link, plugin).

    The defect

    Every member of the windows-x86_64 archive used a backslash path
    separator, in this release's three predecessors as well as v0.31.0.
    APPNOTE 4.4.17.1 says the separator is /, and install.ps1 refuses a
    non-conforming archive — so the supported Windows install path had been
    broken since v0.30.0, the release that added that refusal, and three
    releases went out over it with every gate green.

    A user hit it on a clean Windows machine within hours of v0.31.0.

    Why the writer produced them

    The archive was packed with ZipFile::CreateFromDirectory, adopted in
    #231 specifically to avoid backslashes, on the recorded basis that it
    "writes '/' unconditionally". That holds on .NET Core and .NET 5+. Every
    PowerShell step in the release workflow declares shell: powershell —
    Windows PowerShell 5.1, on .NET Framework — where the same call
    emits Path.DirectorySeparatorChar. The fix was real and the hazard was
    named correctly; the premise was wrong about the runtime it ran on.

    Why nothing caught it

    Three instruments, each reasonable, all blind in the same direction:

    • windows-archive-smoke unpacked with Expand-Archive, the one
      unpacker that tolerates a backslash — named as such in the
      workflow's own comment, one screen earlier. Every path assertion after
      the unpack then passed.
    • installer_ps1_e2e.rs grades the installer's refusals against
      fixture archives it builds itself, so the check and the malformed
      artefact were never in the same room.
    • The writer asserted nothing about what it had written.

    No gate was missing an assertion. They were pointed at synthetic inputs,
    or made after a normalising step had destroyed the evidence.

    The repairs

    • Entry names are built by hand as <name>/<file> — a literal / — and
      the step then reopens the finished zip and refuses a backslash or
      an unexpected root.
    • The smoke job reads the shipped entry names before it unpacks.
    • windows-archive-smoke now runs the repository's own install.ps1
      against the archive the run just built, then executes each installed
      binary and matches --version against the tag. This is the step whose
      absence let the defect ship three times.
    • windows_archive_shape.rs moves all of it to cargo test.

    For users on v0.31.0 or earlier

    Expand-Archive tolerates the malformed archive, so a manual unpack
    works and the published .sha256 still verifies the bytes. v0.31.1
    installs normally.

    No schema migration, no plugin activation change, and no change to any
    published catalog field. All four language packages are republished
    under this tag.

    Downloads

    Four platforms are built for every release. The table below says which ones THIS release published.

    Platform Archive
    Linux x86_64 (glibc) code-index-v0.31.1-linux-x86_64.tar.gz
    Linux x86_64 (static/musl) code-index-v0.31.1-linux-x86_64-musl.tar.gz
    Linux ARM64 code-index-v0.31.1-linux-aarch64.tar.gz
    Windows x64 code-index-v0.31.1-windows-x86_64.zip

    XAML plugin package

    de.h-dv.xaml-0.2.0.cip makes .xaml files carry symbols and references instead of being text-only: x:Class and Click= handlers bind into the paired C# code-behind, x:Name becomes a searchable declaration, and {Binding …} stays unresolved because no bridge can reach it.

    It is NOT installed by installing code-index. Packages are installed into a user-controlled store and approved per project, and installing grants nothing — enable is the grant.

    Download de.h-dv.xaml-0.2.0.cips too and keep the .cips beside the .cip. Packages are signed and an unsigned one is refused (signature_missing) with no flag that accepts it. You do NOT need to anchor us first: this release's publisher key is compiled into the binary, so the install below works on a machine that has anchored nobody. code-index plugin trust list shows it, marked [BUILTIN], and code-index plugin trust remove sha256:1cb03259a8c870b6db02360abd9351e17e67724d1f8c3509d85c4bf6b06fa72c withdraws it — see About that key.

    code-index plugin install de.h-dv.xaml-0.2.0.cip --sha256 sha256:7b572f5cc32ffcd5af550900a451bbef37e255804776d7e3e3e71d2dd7d0aa79
    code-index plugin check   sha256:7b572f5cc32ffcd5af550900a451bbef37e255804776d7e3e3e71d2dd7d0aa79
    code-index plugin enable  sha256:7b572f5cc32ffcd5af550900a451bbef37e255804776d7e3e3e71d2dd7d0aa79 \
        --capabilities bridge_source \
        --bridges 'de.h-dv.xaml/xaml:type->csharp:class,de.h-dv.xaml/xaml:call->csharp:method'
    

    The digest above is the one this release packed and it is what --sha256 pins; de.h-dv.xaml-0.2.0.cip.digest.txt carries it and the extraction identity. A digest that changes between releases means the package changed — re-pin, and read the notes.

    Only .xaml is claimed by this package. The TimeLine package below claims .dataset, .xsql, .shd and .lgd, and the Svelte package below claims .svelte; all other markup remains text-only (searchable, no symbols).

    TimeLine plugin package

    de.h-dv.timeline-0.1.0.cip makes the four TimeLine definition formats carry symbols and references instead of being text-only: .dataset and .xsql through one language, .shd and .lgd through another, both out of a single sandboxed extractor. References resolve INSIDE a definition file; nothing in v1 crosses into the C# that loads it.

    It is NOT installed by installing code-index. Packages are installed into a user-controlled store and approved per project, and installing grants nothing — enable is the grant.

    Download de.h-dv.timeline-0.1.0.cips too and keep the .cips beside the .cip. The same signature rules apply as for the XAML package above, and the same key signs both.

    code-index plugin install de.h-dv.timeline-0.1.0.cip --sha256 sha256:150ceb22ed9757a660d5a2bf58b80c81b60043cc419e5da5dde559d5d6fc9c9f
    code-index plugin check   sha256:150ceb22ed9757a660d5a2bf58b80c81b60043cc419e5da5dde559d5d6fc9c9f
    code-index plugin enable  sha256:150ceb22ed9757a660d5a2bf58b80c81b60043cc419e5da5dde559d5d6fc9c9f \
        --capabilities same_file_candidate,exported_candidate
    

    No --bridges, and that is the package saying so: it declares none, so there is nothing to grant. The digest above is the one this release packed and it is what --sha256 pins; de.h-dv.timeline-0.1.0.cip.digest.txt carries it and the extraction identity.

    The 5 fixtures shipped inside it are synthetic and modelled on the worked examples in the two format specifications. They carry no customer definition.

    Ruby plugin package

    de.h-dv.ruby-0.6.0.cip is the compiled-in Ruby extractor as an EXTERNAL, sandboxed package: tree-sitter-ruby loaded at runtime, the extractor compiled to wasm32-unknown-unknown and byte-reproducible from crates/guest/ruby/, and the same symbols, references, visibility and Rails association names the built-in produces.

    It claims .rbx, not .rb. The compiled-in Ruby plugin owns .rb, .rake, .gemspec, Rakefile and Gemfile, and a package may not claim a file a built-in claims. So installing this changes NOTHING about how your .rb files are indexed — it is the migration proof for running a full language out of a package, published so it can be read and run rather than described. Do not install it expecting to replace built-in Ruby support.

    It is NOT installed by installing code-index. Packages are installed into a user-controlled store and approved per project, and installing grants nothing — enable is the grant.

    Download de.h-dv.ruby-0.6.0.cips too and keep the .cips beside the .cip. The same signature rules apply as for the packages above, and one key signs every package in this release.

    code-index plugin install de.h-dv.ruby-0.6.0.cip --sha256 sha256:a6b8d7787cecb49c225ff3dda9016c96babc00c4cf59242a2d774c8b06672048
    code-index plugin check   sha256:a6b8d7787cecb49c225ff3dda9016c96babc00c4cf59242a2d774c8b06672048 --derived-names
    code-index plugin enable  sha256:a6b8d7787cecb49c225ff3dda9016c96babc00c4cf59242a2d774c8b06672048 --derived-names \
        --capabilities same_file_candidate,exported_candidate,reachability_anchor,qualified_candidate,type_position_candidate,member_candidate
    

    --derived-names is required on check as well as on enable, and without it check REPORTS FAILED. Rails' has_many :posts emits a type reference named Post at the span of the literal :posts, so the name was not copied out of the source it points at; validation is all-or-nothing per file, so the authority is what admits the whole file rather than the one row. Withhold it and you keep the package with every Rails file refused — that is a supported answer, not a broken install.

    No --bridges: Ruby resolves inside its own language, so the package declares none. The six capabilities above are exactly what its manifest requests and enable refuses a grant wider than the request; grant fewer and the index stays searchable but resolves less, because every candidate pool a reference could be admitted to is one of them.

    The digest above is the one this release packed and it is what --sha256 pins; de.h-dv.ruby-0.6.0.cip.digest.txt carries it and the extraction identity.

    The 5 fixtures shipped inside it were generated from the COMPILED-IN Ruby extractor, by a different author from the port they grade, and plugin check compares the package's facts against them exhaustively.

    Svelte plugin package

    de.h-dv.svelte-0.1.0.cip makes .svelte files carry symbols and references instead of being text-only: the TEMPLATE half of a single-file component — markup, mustaches, {#snippet} declarations and {@render} uses — out of one sandboxed extractor over the tree-sitter-svelte-ng grammar.

    It claims .svelte and NOTHING ELSE. .svelte.ts and .svelte.js are deliberately not claimed and this package declares no [[displaces]]: those files are Svelte 5 runes modules, valid TypeScript and valid JavaScript, which the built-in plugins already index correctly. Claiming them would take files away from a producer that reads them in order to read them worse.

    It is NOT installed by installing code-index. Packages are installed into a user-controlled store and approved per project, and installing grants nothing — enable is the grant.

    Download de.h-dv.svelte-0.1.0.cips too and keep the .cips beside the .cip. The same signature rules apply as for the packages above, and one key signs every package in this release.

    code-index plugin install de.h-dv.svelte-0.1.0.cip --sha256 sha256:4b10a478532d67f3694995373e1a64d397611af5c4f2615c085b006628b3322f
    code-index plugin check   sha256:4b10a478532d67f3694995373e1a64d397611af5c4f2615c085b006628b3322f
    code-index plugin enable  sha256:4b10a478532d67f3694995373e1a64d397611af5c4f2615c085b006628b3322f \
        --capabilities same_file_candidate
    

    One capability, and that is the package asking for exactly what it can use. Every symbol this version emits is a {#snippet}, whose visibility is file: reachable by name anywhere in its own component and nowhere else. exported_candidate would admit an empty set, so it is not requested — and enable refuses a grant wider than the manifest asks for, so the line above cannot be padded. No --bridges: this package declares none.

    The digest above is the one this release packed and it is what --sha256 pins; de.h-dv.svelte-0.1.0.cip.digest.txt carries it and the extraction identity.

    The 4 fixtures shipped inside it are synthetic: one positive control in which every rule fires, two that are bait for all of them with an empty expectation, and one malformed source. None carries anybody's component.

    About that key

    sha256:1cb03259a8c870b6db02360abd9351e17e67724d1f8c3509d85c4bf6b06fa72c is a long-lived Ed25519 key held as a secret in this project's CI, used to sign released packages automatically, and it is compiled into the binaries in this release. It signs every package above. That trusts this project's release pipeline, not only its maintainers: anyone who can run a release workflow here can produce a package that verifies under it. It adds nothing you had not already granted — the bytes are inside the program you are running, so forging that anchor means forging the binary — but you are entitled to know it is there before a package installs rather than after.

    There is no expiry — deliberately, because offline installations must not break on a timer — and withdrawal is on your side and works: code-index plugin trust remove sha256:1cb03259a8c870b6db02360abd9351e17e67724d1f8c3509d85c4bf6b06fa72c. A compiled-in key has no file to delete, so that writes one instead, carrying denied = true; the key stops verifying at the next load, plugin trust list shows it marked [DENIED], and deleting that file (the command prints its path) is the only undo. If the key is ever rotated, the new fingerprint is published here and in tests/packages/first-party.fingerprint, and a build that predates the rotation will not trust it.

    You may anchor it yourself instead — code-index plugin trust add code-index-publisher.pub --fingerprint sha256:1cb03259a8c870b6db02360abd9351e17e67724d1f8c3509d85c4bf6b06fa72c --name 'a label you choose', with code-index-publisher.pub from this release's assets. Your file replaces the compiled-in entry, and the --name is a label YOU choose: nothing in the package, the key file or the signature can name its own publisher.

    macOS is not currently built. No x86_64-apple-darwin or aarch64-apple-darwin archive is published — macOS users should build from source (cargo build --release). This is a deliberate deferral, tracked in #59; no date is promised.

    Wire into Claude Code

    { "mcpServers": { "code-index": { "command": "/usr/local/bin/code-index-mcp", "args": ["--root", "/path/to/your/project"] } } }
    

    SHA256 checksums (.sha256 files) available for every archive.

    Downloads
  • v0.31.0 2453904534

    code-index v0.31.0
    All checks were successful
    CI / cargo fmt (push) Successful in 53s
    CI / OSS corpus tier-3 scale (nightly) (push) Has been skipped
    CI / Grammar rebuild from source (nightly) (push) Has been skipped
    CI / CI lane wall-clock headroom (push) Successful in 1m29s
    CI / guest crates (fmt, clippy, doc) (push) Successful in 1m33s
    CI / cargo doc (intra-doc links) (push) Successful in 8m30s
    CI / cargo deny (push) Successful in 9m41s
    CI / cargo test (abi, 32-bit + wasm32) (push) Successful in 10m9s
    CI / cargo check (MSRV 1.98) (push) Successful in 10m40s
    CI / cargo clippy (push) Successful in 10m53s
    CI / cargo check (windows-gnu) (push) Successful in 11m50s
    CI / OSS corpus (tier 1) (push) Successful in 55m56s
    CI (Windows) / fmt + clippy + build + test (windows) (push) Successful in 1h2m25s
    CI / cargo test (push) Successful in 1h12m51s
    CI / cargo test (daemon transport) (push) Successful in 26m5s
    CI / Plugin path cost + pool throughput (nightly) (push) Has been skipped
    Release Build / Generate Version (push) Successful in 35s
    Release Build / Required CI green (push) Successful in 1m10s
    Release Build / Build linux-aarch64 (push) Successful in 23m19s
    Release Build / Build windows-x86_64 (push) Successful in 23m17s
    Release Build / Windows archive smoke (msvc) (push) Successful in 9s
    Release Build / Build linux-x86_64 (push) Successful in 26m53s
    Release Build / Build linux-x86_64-musl (push) Successful in 27m47s
    Release Build / Pack the XAML reference package (push) Successful in 56s
    Release Build / Pack the Svelte language package (push) Successful in 59s
    Release Build / Pack the TimeLine package (push) Successful in 1m4s
    Release Build / Pack the Ruby language package (push) Successful in 1m6s
    Release Build / Create Forgejo Release (push) Successful in 5m47s
    Stable

    buildagent released this 2026-09-22 15:54:30 +02:00 | 190 commits to master since this release

    code-index v0.31.0

    Build: v0.31.0+879

    Installer: install.sh and checksum. Both come from this release commit. To pin the installed binaries too, run it with --tag v0.31.0.

    Windows installer: install.ps1 and checksum, from the same release commit. It installs AND updates — the same code does both — verifies the archive against its published .sha256 before unpacking, refuses hostile archive members (absolute paths, .. escapes, symlinks and reparse points, which Expand-Archive does not protect you from), and grants nothing when it installs a package: the bytes go into the machine's store and the approving line is PRINTED for you to run from inside a project. -Help lists the flags; -Tag v0.31.0 pins the binaries.

    Four-binary release: code-index-mcp (MCP stdio bridge — the usual entry), code-index-daemon (long-lived watcher + RPC server, auto-spawned), code-index-plugin-host (bounded worker for plugin packages, spawned by the daemon), and code-index (CLI: init, index, watch, doctor, link, plugin).

    The agent skill

    An agent reads a code-index payload the way it reads any search result: a zero
    means none, a count means the count. Both readings are wrong here, and the
    payload's own disclosure fields are what make them wrong. Until now the only
    place that was written down was CLAUDE.md, which an MCP client never receives.

    The server now serves that doctrine as a skill, under the official Skills
    extension io.modelcontextprotocol/skills:

    • skills/list and skills/get, and the resource skill://code-index/SKILL.md
    • code-index rules writes the same bytes to .claude/skills/code-index/SKILL.md

    Both doors read one include_str!. A host that verifies the published sha256
    and byte size against what it received will find them equal, and that is graded
    by digest rather than by a contains() check — a trimmed newline or a
    normalised dash is a document the host discards as corrupt, and only a digest
    fails for the same reason the host does.

    Found while building it: the ordinary resource path truncates, so a skill body
    served through it would have been cut mid-document and still passed any
    non-digest test.

    Protocol

    rmcp 1.8 → 3.4, protocol pinned to 2026-07-28. server/discover is a modelled
    method in 3.4, so a pre-initialize call now answers -32600 rather than
    -32601.

    A version bump that cannot half-land (#284)

    A bump touches eight files. Six were found by a gate going red rather than by
    anyone looking, and the four guest lockfiles are invisible to every
    workspace-wide command because those crates sit outside the workspace (#276).

    The site set is now derived from the tree and compared against a declared
    registry, so a new file that starts naming the release goes red in the commit
    that adds it. Three claims no gate held before: README.md, the guest
    lockfiles, and occurrence-level agreement — the per-file claims all pass over a
    README where three of five occurrences moved.

    install.ps1 left the bump set entirely. Its two example tags said "a specific
    release, including an older one" while naming the current release; the
    install.sh lines they mirror have sat at v0.28.0 untouched. Freezing them
    removes a site instead of automating it.

    Documentation

    code-index rules and code-index query shipped in v0.30.0 and appeared
    nowhere in README.md for its whole life. Both are documented now, and a gate
    reads the verb list out of code-index --help and fails on any subcommand the
    README does not mention.

    Packages

    All four language packages — de.h-dv.ruby, de.h-dv.svelte,
    de.h-dv.timeline, de.h-dv.xaml — are built and published under this tag, and
    the catalog's asset URLs point at it. No package digest moved.

    Downloads

    Four platforms are built for every release. The table below says which ones THIS release published.

    Platform Archive
    Linux x86_64 (glibc) code-index-v0.31.0-linux-x86_64.tar.gz
    Linux x86_64 (static/musl) code-index-v0.31.0-linux-x86_64-musl.tar.gz
    Linux ARM64 code-index-v0.31.0-linux-aarch64.tar.gz
    Windows x64 code-index-v0.31.0-windows-x86_64.zip

    XAML plugin package

    de.h-dv.xaml-0.2.0.cip makes .xaml files carry symbols and references instead of being text-only: x:Class and Click= handlers bind into the paired C# code-behind, x:Name becomes a searchable declaration, and {Binding …} stays unresolved because no bridge can reach it.

    It is NOT installed by installing code-index. Packages are installed into a user-controlled store and approved per project, and installing grants nothing — enable is the grant.

    Download de.h-dv.xaml-0.2.0.cips too and keep the .cips beside the .cip. Packages are signed and an unsigned one is refused (signature_missing) with no flag that accepts it. You do NOT need to anchor us first: this release's publisher key is compiled into the binary, so the install below works on a machine that has anchored nobody. code-index plugin trust list shows it, marked [BUILTIN], and code-index plugin trust remove sha256:1cb03259a8c870b6db02360abd9351e17e67724d1f8c3509d85c4bf6b06fa72c withdraws it — see About that key.

    code-index plugin install de.h-dv.xaml-0.2.0.cip --sha256 sha256:7b572f5cc32ffcd5af550900a451bbef37e255804776d7e3e3e71d2dd7d0aa79
    code-index plugin check   sha256:7b572f5cc32ffcd5af550900a451bbef37e255804776d7e3e3e71d2dd7d0aa79
    code-index plugin enable  sha256:7b572f5cc32ffcd5af550900a451bbef37e255804776d7e3e3e71d2dd7d0aa79 \
        --capabilities bridge_source \
        --bridges 'de.h-dv.xaml/xaml:type->csharp:class,de.h-dv.xaml/xaml:call->csharp:method'
    

    The digest above is the one this release packed and it is what --sha256 pins; de.h-dv.xaml-0.2.0.cip.digest.txt carries it and the extraction identity. A digest that changes between releases means the package changed — re-pin, and read the notes.

    Only .xaml is claimed by this package. The TimeLine package below claims .dataset, .xsql, .shd and .lgd, and the Svelte package below claims .svelte; all other markup remains text-only (searchable, no symbols).

    TimeLine plugin package

    de.h-dv.timeline-0.1.0.cip makes the four TimeLine definition formats carry symbols and references instead of being text-only: .dataset and .xsql through one language, .shd and .lgd through another, both out of a single sandboxed extractor. References resolve INSIDE a definition file; nothing in v1 crosses into the C# that loads it.

    It is NOT installed by installing code-index. Packages are installed into a user-controlled store and approved per project, and installing grants nothing — enable is the grant.

    Download de.h-dv.timeline-0.1.0.cips too and keep the .cips beside the .cip. The same signature rules apply as for the XAML package above, and the same key signs both.

    code-index plugin install de.h-dv.timeline-0.1.0.cip --sha256 sha256:150ceb22ed9757a660d5a2bf58b80c81b60043cc419e5da5dde559d5d6fc9c9f
    code-index plugin check   sha256:150ceb22ed9757a660d5a2bf58b80c81b60043cc419e5da5dde559d5d6fc9c9f
    code-index plugin enable  sha256:150ceb22ed9757a660d5a2bf58b80c81b60043cc419e5da5dde559d5d6fc9c9f \
        --capabilities same_file_candidate,exported_candidate
    

    No --bridges, and that is the package saying so: it declares none, so there is nothing to grant. The digest above is the one this release packed and it is what --sha256 pins; de.h-dv.timeline-0.1.0.cip.digest.txt carries it and the extraction identity.

    The 5 fixtures shipped inside it are synthetic and modelled on the worked examples in the two format specifications. They carry no customer definition.

    Ruby plugin package

    de.h-dv.ruby-0.6.0.cip is the compiled-in Ruby extractor as an EXTERNAL, sandboxed package: tree-sitter-ruby loaded at runtime, the extractor compiled to wasm32-unknown-unknown and byte-reproducible from crates/guest/ruby/, and the same symbols, references, visibility and Rails association names the built-in produces.

    It claims .rbx, not .rb. The compiled-in Ruby plugin owns .rb, .rake, .gemspec, Rakefile and Gemfile, and a package may not claim a file a built-in claims. So installing this changes NOTHING about how your .rb files are indexed — it is the migration proof for running a full language out of a package, published so it can be read and run rather than described. Do not install it expecting to replace built-in Ruby support.

    It is NOT installed by installing code-index. Packages are installed into a user-controlled store and approved per project, and installing grants nothing — enable is the grant.

    Download de.h-dv.ruby-0.6.0.cips too and keep the .cips beside the .cip. The same signature rules apply as for the packages above, and one key signs every package in this release.

    code-index plugin install de.h-dv.ruby-0.6.0.cip --sha256 sha256:a6b8d7787cecb49c225ff3dda9016c96babc00c4cf59242a2d774c8b06672048
    code-index plugin check   sha256:a6b8d7787cecb49c225ff3dda9016c96babc00c4cf59242a2d774c8b06672048 --derived-names
    code-index plugin enable  sha256:a6b8d7787cecb49c225ff3dda9016c96babc00c4cf59242a2d774c8b06672048 --derived-names \
        --capabilities same_file_candidate,exported_candidate,reachability_anchor,qualified_candidate,type_position_candidate,member_candidate
    

    --derived-names is required on check as well as on enable, and without it check REPORTS FAILED. Rails' has_many :posts emits a type reference named Post at the span of the literal :posts, so the name was not copied out of the source it points at; validation is all-or-nothing per file, so the authority is what admits the whole file rather than the one row. Withhold it and you keep the package with every Rails file refused — that is a supported answer, not a broken install.

    No --bridges: Ruby resolves inside its own language, so the package declares none. The six capabilities above are exactly what its manifest requests and enable refuses a grant wider than the request; grant fewer and the index stays searchable but resolves less, because every candidate pool a reference could be admitted to is one of them.

    The digest above is the one this release packed and it is what --sha256 pins; de.h-dv.ruby-0.6.0.cip.digest.txt carries it and the extraction identity.

    The 5 fixtures shipped inside it were generated from the COMPILED-IN Ruby extractor, by a different author from the port they grade, and plugin check compares the package's facts against them exhaustively.

    Svelte plugin package

    de.h-dv.svelte-0.1.0.cip makes .svelte files carry symbols and references instead of being text-only: the TEMPLATE half of a single-file component — markup, mustaches, {#snippet} declarations and {@render} uses — out of one sandboxed extractor over the tree-sitter-svelte-ng grammar.

    It claims .svelte and NOTHING ELSE. .svelte.ts and .svelte.js are deliberately not claimed and this package declares no [[displaces]]: those files are Svelte 5 runes modules, valid TypeScript and valid JavaScript, which the built-in plugins already index correctly. Claiming them would take files away from a producer that reads them in order to read them worse.

    It is NOT installed by installing code-index. Packages are installed into a user-controlled store and approved per project, and installing grants nothing — enable is the grant.

    Download de.h-dv.svelte-0.1.0.cips too and keep the .cips beside the .cip. The same signature rules apply as for the packages above, and one key signs every package in this release.

    code-index plugin install de.h-dv.svelte-0.1.0.cip --sha256 sha256:4b10a478532d67f3694995373e1a64d397611af5c4f2615c085b006628b3322f
    code-index plugin check   sha256:4b10a478532d67f3694995373e1a64d397611af5c4f2615c085b006628b3322f
    code-index plugin enable  sha256:4b10a478532d67f3694995373e1a64d397611af5c4f2615c085b006628b3322f \
        --capabilities same_file_candidate
    

    One capability, and that is the package asking for exactly what it can use. Every symbol this version emits is a {#snippet}, whose visibility is file: reachable by name anywhere in its own component and nowhere else. exported_candidate would admit an empty set, so it is not requested — and enable refuses a grant wider than the manifest asks for, so the line above cannot be padded. No --bridges: this package declares none.

    The digest above is the one this release packed and it is what --sha256 pins; de.h-dv.svelte-0.1.0.cip.digest.txt carries it and the extraction identity.

    The 4 fixtures shipped inside it are synthetic: one positive control in which every rule fires, two that are bait for all of them with an empty expectation, and one malformed source. None carries anybody's component.

    About that key

    sha256:1cb03259a8c870b6db02360abd9351e17e67724d1f8c3509d85c4bf6b06fa72c is a long-lived Ed25519 key held as a secret in this project's CI, used to sign released packages automatically, and it is compiled into the binaries in this release. It signs every package above. That trusts this project's release pipeline, not only its maintainers: anyone who can run a release workflow here can produce a package that verifies under it. It adds nothing you had not already granted — the bytes are inside the program you are running, so forging that anchor means forging the binary — but you are entitled to know it is there before a package installs rather than after.

    There is no expiry — deliberately, because offline installations must not break on a timer — and withdrawal is on your side and works: code-index plugin trust remove sha256:1cb03259a8c870b6db02360abd9351e17e67724d1f8c3509d85c4bf6b06fa72c. A compiled-in key has no file to delete, so that writes one instead, carrying denied = true; the key stops verifying at the next load, plugin trust list shows it marked [DENIED], and deleting that file (the command prints its path) is the only undo. If the key is ever rotated, the new fingerprint is published here and in tests/packages/first-party.fingerprint, and a build that predates the rotation will not trust it.

    You may anchor it yourself instead — code-index plugin trust add code-index-publisher.pub --fingerprint sha256:1cb03259a8c870b6db02360abd9351e17e67724d1f8c3509d85c4bf6b06fa72c --name 'a label you choose', with code-index-publisher.pub from this release's assets. Your file replaces the compiled-in entry, and the --name is a label YOU choose: nothing in the package, the key file or the signature can name its own publisher.

    macOS is not currently built. No x86_64-apple-darwin or aarch64-apple-darwin archive is published — macOS users should build from source (cargo build --release). This is a deliberate deferral, tracked in #59; no date is promised.

    Wire into Claude Code

    { "mcpServers": { "code-index": { "command": "/usr/local/bin/code-index-mcp", "args": ["--root", "/path/to/your/project"] } } }
    

    SHA256 checksums (.sha256 files) available for every archive.

    Downloads
  • v0.30.1 a4fe1fad9c

    code-index v0.30.1
    All checks were successful
    CI / cargo fmt (push) Successful in 49s
    CI / OSS corpus tier-3 scale (nightly) (push) Has been skipped
    CI / Grammar rebuild from source (nightly) (push) Has been skipped
    CI / cargo doc (intra-doc links) (push) Successful in 4m49s
    CI / cargo check (MSRV 1.98) (push) Successful in 5m59s
    CI / cargo deny (push) Successful in 6m8s
    CI / cargo clippy (push) Successful in 6m11s
    CI / cargo check (windows-gnu) (push) Successful in 6m16s
    CI / cargo test (abi, 32-bit + wasm32) (push) Successful in 6m11s
    CI / OSS corpus (tier 1) (push) Successful in 29m7s
    CI / cargo test (push) Successful in 39m51s
    CI (Windows) / fmt + clippy + build + test (windows) (push) Successful in 1h0m48s
    CI / cargo test (daemon transport) (push) Successful in 19m41s
    CI / Plugin path cost + pool throughput (nightly) (push) Has been skipped
    Release Build / Generate Version (push) Successful in 21s
    Release Build / Required CI green (push) Successful in 1m7s
    Release Build / Build linux-aarch64 (push) Successful in 21m7s
    Release Build / Build linux-x86_64 (push) Successful in 24m11s
    Release Build / Build linux-x86_64-musl (push) Successful in 24m32s
    Release Build / Pack the XAML reference package (push) Successful in 54s
    Release Build / Pack the Svelte language package (push) Successful in 1m5s
    Release Build / Pack the TimeLine package (push) Successful in 1m14s
    Release Build / Pack the Ruby language package (push) Successful in 1m20s
    Release Build / Build windows-x86_64 (push) Successful in 22m1s
    Release Build / Windows archive smoke (msvc) (push) Successful in 9s
    Release Build / Create Forgejo Release (push) Successful in 5m42s
    Stable

    buildagent released this 2026-09-18 18:17:23 +02:00 | 204 commits to master since this release

    code-index v0.30.1

    Build: v0.30.1+848

    Installer: install.sh and checksum. Both come from this release commit. To pin the installed binaries too, run it with --tag v0.30.1.

    Windows installer: install.ps1 and checksum, from the same release commit. It installs AND updates — the same code does both — verifies the archive against its published .sha256 before unpacking, refuses hostile archive members (absolute paths, .. escapes, symlinks and reparse points, which Expand-Archive does not protect you from), and grants nothing when it installs a package: the bytes go into the machine's store and the approving line is PRINTED for you to run from inside a project. -Help lists the flags; -Tag v0.30.1 pins the binaries.

    Four-binary release: code-index-mcp (MCP stdio bridge — the usual entry), code-index-daemon (long-lived watcher + RPC server, auto-spawned), code-index-plugin-host (bounded worker for plugin packages, spawned by the daemon), and code-index (CLI: init, index, watch, doctor, link, plugin).

    Bug fixes

    Bugfix release addressing three defects uncovered during live dogfooding:

    • Outline pagination: Budget trimming now preserves the complete requested symbol population, including child symbols (methods, fields, nested items), and paginates at the actual emitted row boundary through next_cursor.
    • Trigram tokenizer agreement: The trigram floor classifier shares SQLite's query parser via an in-memory virtual table to decode escaped quotes, column constraints, prefix anchors, and NEAR distances without tokenizer divergence.
    • Truthful search evidence: Filter-miss diagnostics are withheld when trigram index limitations prevent a measured absence. Zero-result wording covers mixed expressions.

    Downloads

    Four platforms are built for every release. The table below says which ones THIS release published.

    Platform Archive
    Linux x86_64 (glibc) code-index-v0.30.1-linux-x86_64.tar.gz
    Linux x86_64 (static/musl) code-index-v0.30.1-linux-x86_64-musl.tar.gz
    Linux ARM64 code-index-v0.30.1-linux-aarch64.tar.gz
    Windows x64 code-index-v0.30.1-windows-x86_64.zip

    XAML plugin package

    de.h-dv.xaml-0.2.0.cip makes .xaml files carry symbols and references instead of being text-only: x:Class and Click= handlers bind into the paired C# code-behind, x:Name becomes a searchable declaration, and {Binding …} stays unresolved because no bridge can reach it.

    It is NOT installed by installing code-index. Packages are installed into a user-controlled store and approved per project, and installing grants nothing — enable is the grant.

    Download de.h-dv.xaml-0.2.0.cips too and keep the .cips beside the .cip. Packages are signed and an unsigned one is refused (signature_missing) with no flag that accepts it. You do NOT need to anchor us first: this release's publisher key is compiled into the binary, so the install below works on a machine that has anchored nobody. code-index plugin trust list shows it, marked [BUILTIN], and code-index plugin trust remove sha256:1cb03259a8c870b6db02360abd9351e17e67724d1f8c3509d85c4bf6b06fa72c withdraws it — see About that key.

    code-index plugin install de.h-dv.xaml-0.2.0.cip --sha256 sha256:7b572f5cc32ffcd5af550900a451bbef37e255804776d7e3e3e71d2dd7d0aa79
    code-index plugin check   sha256:7b572f5cc32ffcd5af550900a451bbef37e255804776d7e3e3e71d2dd7d0aa79
    code-index plugin enable  sha256:7b572f5cc32ffcd5af550900a451bbef37e255804776d7e3e3e71d2dd7d0aa79 \
        --capabilities bridge_source \
        --bridges 'de.h-dv.xaml/xaml:type->csharp:class,de.h-dv.xaml/xaml:call->csharp:method'
    

    The digest above is the one this release packed and it is what --sha256 pins; de.h-dv.xaml-0.2.0.cip.digest.txt carries it and the extraction identity. A digest that changes between releases means the package changed — re-pin, and read the notes.

    Only .xaml is claimed by this package. The TimeLine package below claims .dataset, .xsql, .shd and .lgd, and the Svelte package below claims .svelte; all other markup remains text-only (searchable, no symbols).

    TimeLine plugin package

    de.h-dv.timeline-0.1.0.cip makes the four TimeLine definition formats carry symbols and references instead of being text-only: .dataset and .xsql through one language, .shd and .lgd through another, both out of a single sandboxed extractor. References resolve INSIDE a definition file; nothing in v1 crosses into the C# that loads it.

    It is NOT installed by installing code-index. Packages are installed into a user-controlled store and approved per project, and installing grants nothing — enable is the grant.

    Download de.h-dv.timeline-0.1.0.cips too and keep the .cips beside the .cip. The same signature rules apply as for the XAML package above, and the same key signs both.

    code-index plugin install de.h-dv.timeline-0.1.0.cip --sha256 sha256:150ceb22ed9757a660d5a2bf58b80c81b60043cc419e5da5dde559d5d6fc9c9f
    code-index plugin check   sha256:150ceb22ed9757a660d5a2bf58b80c81b60043cc419e5da5dde559d5d6fc9c9f
    code-index plugin enable  sha256:150ceb22ed9757a660d5a2bf58b80c81b60043cc419e5da5dde559d5d6fc9c9f \
        --capabilities same_file_candidate,exported_candidate
    

    No --bridges, and that is the package saying so: it declares none, so there is nothing to grant. The digest above is the one this release packed and it is what --sha256 pins; de.h-dv.timeline-0.1.0.cip.digest.txt carries it and the extraction identity.

    The 5 fixtures shipped inside it are synthetic and modelled on the worked examples in the two format specifications. They carry no customer definition.

    Ruby plugin package

    de.h-dv.ruby-0.6.0.cip is the compiled-in Ruby extractor as an EXTERNAL, sandboxed package: tree-sitter-ruby loaded at runtime, the extractor compiled to wasm32-unknown-unknown and byte-reproducible from crates/guest/ruby/, and the same symbols, references, visibility and Rails association names the built-in produces.

    It claims .rbx, not .rb. The compiled-in Ruby plugin owns .rb, .rake, .gemspec, Rakefile and Gemfile, and a package may not claim a file a built-in claims. So installing this changes NOTHING about how your .rb files are indexed — it is the migration proof for running a full language out of a package, published so it can be read and run rather than described. Do not install it expecting to replace built-in Ruby support.

    It is NOT installed by installing code-index. Packages are installed into a user-controlled store and approved per project, and installing grants nothing — enable is the grant.

    Download de.h-dv.ruby-0.6.0.cips too and keep the .cips beside the .cip. The same signature rules apply as for the packages above, and one key signs every package in this release.

    code-index plugin install de.h-dv.ruby-0.6.0.cip --sha256 sha256:a6b8d7787cecb49c225ff3dda9016c96babc00c4cf59242a2d774c8b06672048
    code-index plugin check   sha256:a6b8d7787cecb49c225ff3dda9016c96babc00c4cf59242a2d774c8b06672048 --derived-names
    code-index plugin enable  sha256:a6b8d7787cecb49c225ff3dda9016c96babc00c4cf59242a2d774c8b06672048 --derived-names \
        --capabilities same_file_candidate,exported_candidate,reachability_anchor,qualified_candidate,type_position_candidate,member_candidate
    

    --derived-names is required on check as well as on enable, and without it check REPORTS FAILED. Rails' has_many :posts emits a type reference named Post at the span of the literal :posts, so the name was not copied out of the source it points at; validation is all-or-nothing per file, so the authority is what admits the whole file rather than the one row. Withhold it and you keep the package with every Rails file refused — that is a supported answer, not a broken install.

    No --bridges: Ruby resolves inside its own language, so the package declares none. The six capabilities above are exactly what its manifest requests and enable refuses a grant wider than the request; grant fewer and the index stays searchable but resolves less, because every candidate pool a reference could be admitted to is one of them.

    The digest above is the one this release packed and it is what --sha256 pins; de.h-dv.ruby-0.6.0.cip.digest.txt carries it and the extraction identity.

    The 5 fixtures shipped inside it were generated from the COMPILED-IN Ruby extractor, by a different author from the port they grade, and plugin check compares the package's facts against them exhaustively.

    Svelte plugin package

    de.h-dv.svelte-0.1.0.cip makes .svelte files carry symbols and references instead of being text-only: the TEMPLATE half of a single-file component — markup, mustaches, {#snippet} declarations and {@render} uses — out of one sandboxed extractor over the tree-sitter-svelte-ng grammar.

    It claims .svelte and NOTHING ELSE. .svelte.ts and .svelte.js are deliberately not claimed and this package declares no [[displaces]]: those files are Svelte 5 runes modules, valid TypeScript and valid JavaScript, which the built-in plugins already index correctly. Claiming them would take files away from a producer that reads them in order to read them worse.

    It is NOT installed by installing code-index. Packages are installed into a user-controlled store and approved per project, and installing grants nothing — enable is the grant.

    Download de.h-dv.svelte-0.1.0.cips too and keep the .cips beside the .cip. The same signature rules apply as for the packages above, and one key signs every package in this release.

    code-index plugin install de.h-dv.svelte-0.1.0.cip --sha256 sha256:4b10a478532d67f3694995373e1a64d397611af5c4f2615c085b006628b3322f
    code-index plugin check   sha256:4b10a478532d67f3694995373e1a64d397611af5c4f2615c085b006628b3322f
    code-index plugin enable  sha256:4b10a478532d67f3694995373e1a64d397611af5c4f2615c085b006628b3322f \
        --capabilities same_file_candidate
    

    One capability, and that is the package asking for exactly what it can use. Every symbol this version emits is a {#snippet}, whose visibility is file: reachable by name anywhere in its own component and nowhere else. exported_candidate would admit an empty set, so it is not requested — and enable refuses a grant wider than the manifest asks for, so the line above cannot be padded. No --bridges: this package declares none.

    The digest above is the one this release packed and it is what --sha256 pins; de.h-dv.svelte-0.1.0.cip.digest.txt carries it and the extraction identity.

    The 4 fixtures shipped inside it are synthetic: one positive control in which every rule fires, two that are bait for all of them with an empty expectation, and one malformed source. None carries anybody's component.

    About that key

    sha256:1cb03259a8c870b6db02360abd9351e17e67724d1f8c3509d85c4bf6b06fa72c is a long-lived Ed25519 key held as a secret in this project's CI, used to sign released packages automatically, and it is compiled into the binaries in this release. It signs every package above. That trusts this project's release pipeline, not only its maintainers: anyone who can run a release workflow here can produce a package that verifies under it. It adds nothing you had not already granted — the bytes are inside the program you are running, so forging that anchor means forging the binary — but you are entitled to know it is there before a package installs rather than after.

    There is no expiry — deliberately, because offline installations must not break on a timer — and withdrawal is on your side and works: code-index plugin trust remove sha256:1cb03259a8c870b6db02360abd9351e17e67724d1f8c3509d85c4bf6b06fa72c. A compiled-in key has no file to delete, so that writes one instead, carrying denied = true; the key stops verifying at the next load, plugin trust list shows it marked [DENIED], and deleting that file (the command prints its path) is the only undo. If the key is ever rotated, the new fingerprint is published here and in tests/packages/first-party.fingerprint, and a build that predates the rotation will not trust it.

    You may anchor it yourself instead — code-index plugin trust add code-index-publisher.pub --fingerprint sha256:1cb03259a8c870b6db02360abd9351e17e67724d1f8c3509d85c4bf6b06fa72c --name 'a label you choose', with code-index-publisher.pub from this release's assets. Your file replaces the compiled-in entry, and the --name is a label YOU choose: nothing in the package, the key file or the signature can name its own publisher.

    macOS is not currently built. No x86_64-apple-darwin or aarch64-apple-darwin archive is published — macOS users should build from source (cargo build --release). This is a deliberate deferral, tracked in #59; no date is promised.

    Wire into Claude Code

    { "mcpServers": { "code-index": { "command": "/usr/local/bin/code-index-mcp", "args": ["--root", "/path/to/your/project"] } } }
    

    SHA256 checksums (.sha256 files) available for every archive.

    Downloads
  • v0.30.0 878fec1497

    code-index v0.30.0
    All checks were successful
    CI / cargo fmt (push) Successful in 49s
    CI / OSS corpus tier-3 scale (nightly) (push) Has been skipped
    CI / Grammar rebuild from source (nightly) (push) Has been skipped
    CI / cargo doc (intra-doc links) (push) Successful in 4m53s
    CI / cargo check (MSRV 1.98) (push) Successful in 6m12s
    CI / cargo deny (push) Successful in 6m16s
    CI / cargo test (abi, 32-bit + wasm32) (push) Successful in 6m29s
    CI / cargo clippy (push) Successful in 6m40s
    CI / cargo check (windows-gnu) (push) Successful in 6m47s
    CI / OSS corpus (tier 1) (push) Successful in 30m28s
    CI / cargo test (push) Successful in 41m8s
    CI (Windows) / fmt + clippy + build + test (windows) (push) Successful in 57m32s
    CI / cargo test (daemon transport) (push) Successful in 20m23s
    CI / Plugin path cost + pool throughput (nightly) (push) Has been skipped
    Release Build / Generate Version (push) Successful in 22s
    Release Build / Required CI green (push) Successful in 1m6s
    Release Build / Build linux-aarch64 (push) Successful in 12m58s
    Release Build / Build linux-x86_64 (push) Successful in 15m30s
    Release Build / Build linux-x86_64-musl (push) Successful in 16m18s
    Release Build / Pack the XAML reference package (push) Successful in 2m7s
    Release Build / Pack the Ruby language package (push) Successful in 2m14s
    Release Build / Pack the Svelte language package (push) Successful in 2m26s
    Release Build / Pack the TimeLine package (push) Successful in 2m38s
    Release Build / Build windows-x86_64 (push) Successful in 21m57s
    Release Build / Windows archive smoke (msvc) (push) Successful in 8s
    Release Build / Create Forgejo Release (push) Successful in 5m47s
    Stable

    buildagent released this 2026-09-17 12:49:42 +02:00 | 210 commits to master since this release

    code-index v0.30.0

    Build: v0.30.0+835

    Installer: install.sh and checksum. Both come from this release commit. To pin the installed binaries too, run it with --tag v0.30.0.

    Windows installer: install.ps1 and checksum, from the same release commit. It installs AND updates — the same code does both — verifies the archive against its published .sha256 before unpacking, refuses hostile archive members (absolute paths, .. escapes, symlinks and reparse points, which Expand-Archive does not protect you from), and grants nothing when it installs a package: the bytes go into the machine's store and the approving line is PRINTED for you to run from inside a project. -Help lists the flags; -Tag v0.30.0 pins the binaries.

    Four-binary release: code-index-mcp (MCP stdio bridge — the usual entry), code-index-daemon (long-lived watcher + RPC server, auto-spawned), code-index-plugin-host (bounded worker for plugin packages, spawned by the daemon), and code-index (CLI: init, index, watch, doctor, link, plugin).

    ACTION REQUIRED: run code-index rules in every project

    Your agent instruction files are stale, and this release is what makes
    that fixable.

    I040 measured that "prefer code-index over shell search OR FILE READS"
    is a rule wrong in part — read_code("path:10-50") is one call exactly
    like sed -n — and that an agent given a rule wrong in part discards it
    WHOLE, taking the search half down with it. The mission rewrote the MCP
    server's own instructions and never touched the generator that writes
    AGENTS.md, .cursorrules, .windsurfrules, .clinerules,
    .github/copilot-instructions.md, .gemini/rules/ and
    .cursor/rules/. Those kept the harmful copy for four releases.

    It stayed invisible because rules could only ever be WRITTEN by
    code-index init, a first-run command. Nothing refreshed them, so every
    existing project is frozen on whatever shipped the day it was
    initialised.

    code-index rules            # refresh them
    code-index rules --check    # exit 1 if stale; for CI
    

    CLAUDE.md and any shared file carrying your own guidance is left
    alone.

    New: ask the index from a shell

    code-index query --list
    code-index query change_impact '{"symbol_ids":[900392]}'
    code-index query search_text '{"query":"TODO"}' | jq .
    

    All 23 tools, JSON in and JSON out, with the disclosure envelope intact.
    Arguments come from the command line or from stdin with -.

    Every query tool used to exist only over MCP, so no hook, pre-commit, CI
    step or human could ask the index anything. Instructions are portable —
    one rule set, eight agent conventions — and enforcement was not, because
    a check has to run inside the runtime and no runtime speaks MCP.

    Exit codes are the contract: 0 answered, 1 the tool refused, 2 nothing
    was asked (no such tool, or arguments that are not a JSON object). The
    last two are separate on purpose: a hook that blocked a commit because a
    binary was missing, the same way it blocks one because the index found a
    problem, would be worse than no hook.

    New: a hook that tells you what depends on what you just changed

    code-index rules --hooks
    

    Installs a Claude Code PostToolUse hook. After an edit to a code file it
    asks which PUBLIC symbols in that file now differ and what depends on
    them:

    You changed `merge_rules` — public, and 12 symbol(s) depend on it.
      crates/cli/src/rules.rs :: write_agent_rules
      crates/cli/src/main.rs  :: cmd_rules
      …
    

    It is mostly a decision about when to stay quiet: a non-code file,
    nothing public changed, nothing depends on it, or the same finding
    already reported this session — all silent. A hook that speaks on every
    edit is one an agent learns to skip.

    Registered without disturbing anything else in .claude/settings.json,
    and a settings file that will not parse is refused rather than replaced.

    Fewer, larger calls

    query on search_text and search_symbols now takes a STRING OR A
    LIST — up to 8 searches in one call, each with its own batches entry.

    Measured over 702 real tool responses: the reply envelope is a FIXED
    ~1,130 characters per call and does not move with result count, so its
    share runs from 74% of a one-row answer down to 14% of a sixteen-row
    one. The lever was never shrinking disclosures — every mechanism for
    that was already built and deliberate — it was making fewer calls.

    Refusals rather than truncation: over the cap, an empty list, an empty
    entry and a cursor beside a batch are all refused, because a truncated
    batch answers nine questions with eight answers and the missing one
    reads as "found nothing".

    search_text names the symbol each hit sits inside

    search_text({query: "…", enclosing_symbol: true})
    

    "Nine call sites" is not something a reviewer can act on; "seven in
    render_activation, two in a test helper" is. Off by default.

    Windows

    A native Windows installer and updater (install.ps1), with the gates
    that make it real, plus three defects only a real Windows host could
    show.

    Svelte

    de.h-dv.svelte 0.1.0 — single-file components: markup, mustaches,
    {#snippet} and {@render}, on a new TAG_SYMBOL_BASENAME ABI input.

    Faster

    • a one-shot code-index query attaches to a running daemon or answers
      in-process, and never STARTS one. It was paying
      DAEMON_STARTUP_CEILING — fifteen minutes' worth of budget — for a
      question it answers in milliseconds. Measured on a Windows runner:
      ~10 minutes per invocation, now ~0.3s. The CI lane it was quietly
      consuming went from 2h53m to 56m.
    • read_file_claim's diagnostics subquery is pinned to the file_id
      index: 0.098s to 0.002s on 888 files, on a path that runs once per
      changed file.

    Disclosure

    code-index plugin now names the derived_names answer on the screen
    the operator approves, instead of leaving a granted capability
    unmentioned.

    Upgrading

    curl -fsSL https://git.h-dv.de/h-dv/code-index/raw/branch/master/install.sh | sh
    # or, Windows:
    iwr -useb https://git.h-dv.de/h-dv/code-index/raw/branch/master/install.ps1 | iex
    

    Then, in each project:

    code-index rules
    

    Downloads

    Four platforms are built for every release. The table below says which ones THIS release published.

    Platform Archive
    Linux x86_64 (glibc) code-index-v0.30.0-linux-x86_64.tar.gz
    Linux x86_64 (static/musl) code-index-v0.30.0-linux-x86_64-musl.tar.gz
    Linux ARM64 code-index-v0.30.0-linux-aarch64.tar.gz
    Windows x64 code-index-v0.30.0-windows-x86_64.zip

    XAML plugin package

    de.h-dv.xaml-0.2.0.cip makes .xaml files carry symbols and references instead of being text-only: x:Class and Click= handlers bind into the paired C# code-behind, x:Name becomes a searchable declaration, and {Binding …} stays unresolved because no bridge can reach it.

    It is NOT installed by installing code-index. Packages are installed into a user-controlled store and approved per project, and installing grants nothing — enable is the grant.

    Download de.h-dv.xaml-0.2.0.cips too and keep the .cips beside the .cip. Packages are signed and an unsigned one is refused (signature_missing) with no flag that accepts it. You do NOT need to anchor us first: this release's publisher key is compiled into the binary, so the install below works on a machine that has anchored nobody. code-index plugin trust list shows it, marked [BUILTIN], and code-index plugin trust remove sha256:1cb03259a8c870b6db02360abd9351e17e67724d1f8c3509d85c4bf6b06fa72c withdraws it — see About that key.

    code-index plugin install de.h-dv.xaml-0.2.0.cip --sha256 sha256:7b572f5cc32ffcd5af550900a451bbef37e255804776d7e3e3e71d2dd7d0aa79
    code-index plugin check   sha256:7b572f5cc32ffcd5af550900a451bbef37e255804776d7e3e3e71d2dd7d0aa79
    code-index plugin enable  sha256:7b572f5cc32ffcd5af550900a451bbef37e255804776d7e3e3e71d2dd7d0aa79 \
        --capabilities bridge_source \
        --bridges 'de.h-dv.xaml/xaml:type->csharp:class,de.h-dv.xaml/xaml:call->csharp:method'
    

    The digest above is the one this release packed and it is what --sha256 pins; de.h-dv.xaml-0.2.0.cip.digest.txt carries it and the extraction identity. A digest that changes between releases means the package changed — re-pin, and read the notes.

    Only .xaml is claimed by this package. The TimeLine package below claims .dataset, .xsql, .shd and .lgd, and the Svelte package below claims .svelte; all other markup remains text-only (searchable, no symbols).

    TimeLine plugin package

    de.h-dv.timeline-0.1.0.cip makes the four TimeLine definition formats carry symbols and references instead of being text-only: .dataset and .xsql through one language, .shd and .lgd through another, both out of a single sandboxed extractor. References resolve INSIDE a definition file; nothing in v1 crosses into the C# that loads it.

    It is NOT installed by installing code-index. Packages are installed into a user-controlled store and approved per project, and installing grants nothing — enable is the grant.

    Download de.h-dv.timeline-0.1.0.cips too and keep the .cips beside the .cip. The same signature rules apply as for the XAML package above, and the same key signs both.

    code-index plugin install de.h-dv.timeline-0.1.0.cip --sha256 sha256:150ceb22ed9757a660d5a2bf58b80c81b60043cc419e5da5dde559d5d6fc9c9f
    code-index plugin check   sha256:150ceb22ed9757a660d5a2bf58b80c81b60043cc419e5da5dde559d5d6fc9c9f
    code-index plugin enable  sha256:150ceb22ed9757a660d5a2bf58b80c81b60043cc419e5da5dde559d5d6fc9c9f \
        --capabilities same_file_candidate,exported_candidate
    

    No --bridges, and that is the package saying so: it declares none, so there is nothing to grant. The digest above is the one this release packed and it is what --sha256 pins; de.h-dv.timeline-0.1.0.cip.digest.txt carries it and the extraction identity.

    The 5 fixtures shipped inside it are synthetic and modelled on the worked examples in the two format specifications. They carry no customer definition.

    Ruby plugin package

    de.h-dv.ruby-0.6.0.cip is the compiled-in Ruby extractor as an EXTERNAL, sandboxed package: tree-sitter-ruby loaded at runtime, the extractor compiled to wasm32-unknown-unknown and byte-reproducible from crates/guest/ruby/, and the same symbols, references, visibility and Rails association names the built-in produces.

    It claims .rbx, not .rb. The compiled-in Ruby plugin owns .rb, .rake, .gemspec, Rakefile and Gemfile, and a package may not claim a file a built-in claims. So installing this changes NOTHING about how your .rb files are indexed — it is the migration proof for running a full language out of a package, published so it can be read and run rather than described. Do not install it expecting to replace built-in Ruby support.

    It is NOT installed by installing code-index. Packages are installed into a user-controlled store and approved per project, and installing grants nothing — enable is the grant.

    Download de.h-dv.ruby-0.6.0.cips too and keep the .cips beside the .cip. The same signature rules apply as for the packages above, and one key signs every package in this release.

    code-index plugin install de.h-dv.ruby-0.6.0.cip --sha256 sha256:a6b8d7787cecb49c225ff3dda9016c96babc00c4cf59242a2d774c8b06672048
    code-index plugin check   sha256:a6b8d7787cecb49c225ff3dda9016c96babc00c4cf59242a2d774c8b06672048 --derived-names
    code-index plugin enable  sha256:a6b8d7787cecb49c225ff3dda9016c96babc00c4cf59242a2d774c8b06672048 --derived-names \
        --capabilities same_file_candidate,exported_candidate,reachability_anchor,qualified_candidate,type_position_candidate,member_candidate
    

    --derived-names is required on check as well as on enable, and without it check REPORTS FAILED. Rails' has_many :posts emits a type reference named Post at the span of the literal :posts, so the name was not copied out of the source it points at; validation is all-or-nothing per file, so the authority is what admits the whole file rather than the one row. Withhold it and you keep the package with every Rails file refused — that is a supported answer, not a broken install.

    No --bridges: Ruby resolves inside its own language, so the package declares none. The six capabilities above are exactly what its manifest requests and enable refuses a grant wider than the request; grant fewer and the index stays searchable but resolves less, because every candidate pool a reference could be admitted to is one of them.

    The digest above is the one this release packed and it is what --sha256 pins; de.h-dv.ruby-0.6.0.cip.digest.txt carries it and the extraction identity.

    The 5 fixtures shipped inside it were generated from the COMPILED-IN Ruby extractor, by a different author from the port they grade, and plugin check compares the package's facts against them exhaustively.

    Svelte plugin package

    de.h-dv.svelte-0.1.0.cip makes .svelte files carry symbols and references instead of being text-only: the TEMPLATE half of a single-file component — markup, mustaches, {#snippet} declarations and {@render} uses — out of one sandboxed extractor over the tree-sitter-svelte-ng grammar.

    It claims .svelte and NOTHING ELSE. .svelte.ts and .svelte.js are deliberately not claimed and this package declares no [[displaces]]: those files are Svelte 5 runes modules, valid TypeScript and valid JavaScript, which the built-in plugins already index correctly. Claiming them would take files away from a producer that reads them in order to read them worse.

    It is NOT installed by installing code-index. Packages are installed into a user-controlled store and approved per project, and installing grants nothing — enable is the grant.

    Download de.h-dv.svelte-0.1.0.cips too and keep the .cips beside the .cip. The same signature rules apply as for the packages above, and one key signs every package in this release.

    code-index plugin install de.h-dv.svelte-0.1.0.cip --sha256 sha256:4b10a478532d67f3694995373e1a64d397611af5c4f2615c085b006628b3322f
    code-index plugin check   sha256:4b10a478532d67f3694995373e1a64d397611af5c4f2615c085b006628b3322f
    code-index plugin enable  sha256:4b10a478532d67f3694995373e1a64d397611af5c4f2615c085b006628b3322f \
        --capabilities same_file_candidate
    

    One capability, and that is the package asking for exactly what it can use. Every symbol this version emits is a {#snippet}, whose visibility is file: reachable by name anywhere in its own component and nowhere else. exported_candidate would admit an empty set, so it is not requested — and enable refuses a grant wider than the manifest asks for, so the line above cannot be padded. No --bridges: this package declares none.

    The digest above is the one this release packed and it is what --sha256 pins; de.h-dv.svelte-0.1.0.cip.digest.txt carries it and the extraction identity.

    The 4 fixtures shipped inside it are synthetic: one positive control in which every rule fires, two that are bait for all of them with an empty expectation, and one malformed source. None carries anybody's component.

    About that key

    sha256:1cb03259a8c870b6db02360abd9351e17e67724d1f8c3509d85c4bf6b06fa72c is a long-lived Ed25519 key held as a secret in this project's CI, used to sign released packages automatically, and it is compiled into the binaries in this release. It signs every package above. That trusts this project's release pipeline, not only its maintainers: anyone who can run a release workflow here can produce a package that verifies under it. It adds nothing you had not already granted — the bytes are inside the program you are running, so forging that anchor means forging the binary — but you are entitled to know it is there before a package installs rather than after.

    There is no expiry — deliberately, because offline installations must not break on a timer — and withdrawal is on your side and works: code-index plugin trust remove sha256:1cb03259a8c870b6db02360abd9351e17e67724d1f8c3509d85c4bf6b06fa72c. A compiled-in key has no file to delete, so that writes one instead, carrying denied = true; the key stops verifying at the next load, plugin trust list shows it marked [DENIED], and deleting that file (the command prints its path) is the only undo. If the key is ever rotated, the new fingerprint is published here and in tests/packages/first-party.fingerprint, and a build that predates the rotation will not trust it.

    You may anchor it yourself instead — code-index plugin trust add code-index-publisher.pub --fingerprint sha256:1cb03259a8c870b6db02360abd9351e17e67724d1f8c3509d85c4bf6b06fa72c --name 'a label you choose', with code-index-publisher.pub from this release's assets. Your file replaces the compiled-in entry, and the --name is a label YOU choose: nothing in the package, the key file or the signature can name its own publisher.

    macOS is not currently built. No x86_64-apple-darwin or aarch64-apple-darwin archive is published — macOS users should build from source (cargo build --release). This is a deliberate deferral, tracked in #59; no date is promised.

    Wire into Claude Code

    { "mcpServers": { "code-index": { "command": "/usr/local/bin/code-index-mcp", "args": ["--root", "/path/to/your/project"] } } }
    

    SHA256 checksums (.sha256 files) available for every archive.

    Downloads
  • v0.29.0 a509b96470

    code-index v0.29.0
    All checks were successful
    CI / cargo fmt (push) Successful in 49s
    CI / OSS corpus tier-3 scale (nightly) (push) Has been skipped
    CI / Grammar rebuild from source (nightly) (push) Has been skipped
    CI / cargo doc (intra-doc links) (push) Successful in 4m20s
    CI / cargo test (abi, 32-bit + wasm32) (push) Successful in 5m28s
    CI / cargo check (MSRV 1.98) (push) Successful in 5m56s
    CI / cargo clippy (push) Successful in 6m18s
    CI / cargo check (windows-gnu) (push) Successful in 6m21s
    CI / cargo deny (push) Successful in 6m27s
    CI / OSS corpus (tier 1) (push) Successful in 28m56s
    CI / cargo test (push) Successful in 38m52s
    CI (Windows) / fmt + clippy + build + test (windows) (push) Successful in 50m49s
    CI / cargo test (daemon transport) (push) Successful in 18m10s
    CI / Plugin path cost + pool throughput (nightly) (push) Has been skipped
    Release Build / Generate Version (push) Successful in 30s
    Release Build / Required CI green (push) Successful in 1m3s
    Release Build / Build linux-aarch64 (push) Successful in 12m57s
    Release Build / Build linux-x86_64 (push) Successful in 15m28s
    Release Build / Build linux-x86_64-musl (push) Successful in 16m19s
    Release Build / Pack the Ruby language package (push) Successful in 50s
    Release Build / Pack the XAML reference package (push) Successful in 52s
    Release Build / Pack the TimeLine package (push) Successful in 1m1s
    Release Build / Build windows-x86_64 (push) Successful in 20m22s
    Release Build / Windows archive smoke (msvc) (push) Successful in 6s
    Release Build / Create Forgejo Release (push) Successful in 5m0s
    Stable

    buildagent released this 2026-09-14 07:12:03 +02:00 | 235 commits to master since this release

    code-index v0.29.0

    Build: v0.29.0+786

    Installer: install.sh and checksum. Both come from this release commit. To pin the installed binaries too, run it with --tag v0.29.0.

    Four-binary release: code-index-mcp (MCP stdio bridge — the usual entry), code-index-daemon (long-lived watcher + RPC server, auto-spawned), code-index-plugin-host (bounded worker for plugin packages, spawned by the daemon), and code-index (CLI: init, index, watch, doctor, link, plugin).

    v0.28.3 published a distribution catalog whose four platform checksums were fabricated, signed with the publisher key, and wrong. The real linux-x86_64 archive hashed 0dce077f…; the catalog said d95f0cb7…. All four disagreed with CI's own .sha256 sidecars. Nothing broke only because nothing consumed them yet — install.sh still used the per-archive sidecars — so the first consumer to trust that catalog would have rejected genuine artifacts.

    The cause was structural rather than careless: a gate pinned the catalog's version to the crate version, so every release forced someone to edit that file and invent four hashes that cannot exist until CI has built the archives. The gate demanded the edit and could not grade it.

    One rule

    No value in distribution/registry.v1.json is authored. Each is derived from the artifact it describes, by the step holding that artifact.

    Plugin facts are derivable in-tree, from tests/packages/*/plugin.toml and the packed .cip; platform facts only at release time, from the archives' own checksum sidecars. A document that cannot derive a fact now declares it unmeasured instead of inventing one — platforms is a tagged measured/unmeasured state, so an empty map can never stand in for "not measured here", and a source form carrying a generated_at timestamp is refused outright.

    min_code_index_version was dropped rather than authored: no artifact states a minimum host version and no code read it. The package's own [abi] bracket is the real statement, and plugin install already enforces it.

    The catalog now covers all three published packages

    v0.28.3 listed one of three, so plugin add de.h-dv.ruby could not resolve at all. Every plugin fact is re-derived from the package that ships it and compared, and the package set is enumerated from disk — so the tree GROWING is caught, not only the catalog shrinking.

    The signature is verified, by the keys you anchor

    verify_catalog_signature existed with zero callers while the client fetched catalogs over HTTP and used them. It is now required at every door but the compiled-in one, and checked against your trust set rather than the built-in anchors directly — so plugin trust remove reaches the catalog door exactly as it reaches an installed package. There is no flag that accepts an unsigned catalog: a catalog decides which bytes get fetched and which digest they are pinned to.

    Probed end to end through the shipped binary: a valid catalog reports the signer's fingerprint; a single changed byte is signature_invalid; a missing .sig is signature_missing naming the exact path it looked for; an unanchored signer is signature_untrusted; and after plugin trust remove, the same previously-valid catalog refuses, with the trusted-key count dropping 2 to 1.

    Installing grants nothing

    install.sh --with-plugin <id> fetches, verifies and installs into the machine-wide store, then prints the code-index plugin add <id> line for you to run inside a project. It previously ran plugin add --grant requested --yes, which made the first capability grant on a fresh machine non-interactively, inside a curl | sh, for whichever project the working directory happened to detect. The first grant on a machine stays a human decision.

    Updating from the catalog

    [update."<id>"] gains from = "registry" as its own key, mutually exclusive with source. A sentinel inside source was indistinguishable from a hostname — registry.example.com/pkg.cip is a real thing an operator may write, and the old prefix test swallowed it and served the embedded catalog instead, silently. The registry path is held to the same clause as a URL, so a stale or hostile catalog offering an older signed version is refused rather than applied.

    New

    • code-index plugin catalog [SOURCE] — read-only. Reports the source, byte count, the fingerprint that verified it, the platform state and the plugin list; exits non-zero on any refusal. The release uses it to check its own signature through the same door a customer takes.
    • plugin_add over MCP accepts package: "<id>", fetches it when the store does not already hold it, and enforces the catalog's pinned digest before the operator is asked anything.
    • code-index://registry/plugins answers which package claims a symbol-blind extension in this workspace, with an explicit availability state rather than an absent key.

    Honesty notes

    project_overview's registry_available block is gone. It collapsed four different absences into one rendering and read an unconsultable package store as "nothing installed". The workspace join moved to the registry resource, which is not token-ratcheted and can afford to say what it measured.

    Two failures were found in this release's own CI and fixed here: the CI image ships no jq (the release would have died at catalog staging), and cargo fmt --all exceeds the Windows 32767-character command-line limit once the workspace passes ~350 targets. Both now have gates that measure the real thing and print their numbers on every run.

    Downloads

    Four platforms are built for every release. The table below says which ones THIS release published.

    Platform Archive
    Linux x86_64 (glibc) code-index-v0.29.0-linux-x86_64.tar.gz
    Linux x86_64 (static/musl) code-index-v0.29.0-linux-x86_64-musl.tar.gz
    Linux ARM64 code-index-v0.29.0-linux-aarch64.tar.gz
    Windows x64 code-index-v0.29.0-windows-x86_64.zip

    XAML plugin package

    de.h-dv.xaml-0.2.0.cip makes .xaml files carry symbols and references instead of being text-only: x:Class and Click= handlers bind into the paired C# code-behind, x:Name becomes a searchable declaration, and {Binding …} stays unresolved because no bridge can reach it.

    It is NOT installed by installing code-index. Packages are installed into a user-controlled store and approved per project, and installing grants nothing — enable is the grant.

    Download de.h-dv.xaml-0.2.0.cips too and keep the .cips beside the .cip. Packages are signed and an unsigned one is refused (signature_missing) with no flag that accepts it. You do NOT need to anchor us first: this release's publisher key is compiled into the binary, so the install below works on a machine that has anchored nobody. code-index plugin trust list shows it, marked [BUILTIN], and code-index plugin trust remove sha256:1cb03259a8c870b6db02360abd9351e17e67724d1f8c3509d85c4bf6b06fa72c withdraws it — see About that key.

    code-index plugin install de.h-dv.xaml-0.2.0.cip --sha256 sha256:7b572f5cc32ffcd5af550900a451bbef37e255804776d7e3e3e71d2dd7d0aa79
    code-index plugin check   sha256:7b572f5cc32ffcd5af550900a451bbef37e255804776d7e3e3e71d2dd7d0aa79
    code-index plugin enable  sha256:7b572f5cc32ffcd5af550900a451bbef37e255804776d7e3e3e71d2dd7d0aa79 \
        --capabilities bridge_source \
        --bridges 'de.h-dv.xaml/xaml:type->csharp:class,de.h-dv.xaml/xaml:call->csharp:method'
    

    The digest above is the one this release packed and it is what --sha256 pins; de.h-dv.xaml-0.2.0.cip.digest.txt carries it and the extraction identity. A digest that changes between releases means the package changed — re-pin, and read the notes.

    Only .xaml is claimed by this package. The TimeLine package below claims .dataset, .xsql, .shd and .lgd; all other markup remains text-only (searchable, no symbols).

    TimeLine plugin package

    de.h-dv.timeline-0.1.0.cip makes the four TimeLine definition formats carry symbols and references instead of being text-only: .dataset and .xsql through one language, .shd and .lgd through another, both out of a single sandboxed extractor. References resolve INSIDE a definition file; nothing in v1 crosses into the C# that loads it.

    It is NOT installed by installing code-index. Packages are installed into a user-controlled store and approved per project, and installing grants nothing — enable is the grant.

    Download de.h-dv.timeline-0.1.0.cips too and keep the .cips beside the .cip. The same signature rules apply as for the XAML package above, and the same key signs both.

    code-index plugin install de.h-dv.timeline-0.1.0.cip --sha256 sha256:150ceb22ed9757a660d5a2bf58b80c81b60043cc419e5da5dde559d5d6fc9c9f
    code-index plugin check   sha256:150ceb22ed9757a660d5a2bf58b80c81b60043cc419e5da5dde559d5d6fc9c9f
    code-index plugin enable  sha256:150ceb22ed9757a660d5a2bf58b80c81b60043cc419e5da5dde559d5d6fc9c9f \
        --capabilities same_file_candidate,exported_candidate
    

    No --bridges, and that is the package saying so: it declares none, so there is nothing to grant. The digest above is the one this release packed and it is what --sha256 pins; de.h-dv.timeline-0.1.0.cip.digest.txt carries it and the extraction identity.

    The 5 fixtures shipped inside it are synthetic and modelled on the worked examples in the two format specifications. They carry no customer definition.

    Ruby plugin package

    de.h-dv.ruby-0.6.0.cip is the compiled-in Ruby extractor as an EXTERNAL, sandboxed package: tree-sitter-ruby loaded at runtime, the extractor compiled to wasm32-unknown-unknown and byte-reproducible from crates/guest/ruby/, and the same symbols, references, visibility and Rails association names the built-in produces.

    It claims .rbx, not .rb. The compiled-in Ruby plugin owns .rb, .rake, .gemspec, Rakefile and Gemfile, and a package may not claim a file a built-in claims. So installing this changes NOTHING about how your .rb files are indexed — it is the migration proof for running a full language out of a package, published so it can be read and run rather than described. Do not install it expecting to replace built-in Ruby support.

    It is NOT installed by installing code-index. Packages are installed into a user-controlled store and approved per project, and installing grants nothing — enable is the grant.

    Download de.h-dv.ruby-0.6.0.cips too and keep the .cips beside the .cip. The same signature rules apply as for the packages above, and the same key signs all three.

    code-index plugin install de.h-dv.ruby-0.6.0.cip --sha256 sha256:a6b8d7787cecb49c225ff3dda9016c96babc00c4cf59242a2d774c8b06672048
    code-index plugin check   sha256:a6b8d7787cecb49c225ff3dda9016c96babc00c4cf59242a2d774c8b06672048 --derived-names
    code-index plugin enable  sha256:a6b8d7787cecb49c225ff3dda9016c96babc00c4cf59242a2d774c8b06672048 --derived-names \
        --capabilities same_file_candidate,exported_candidate,reachability_anchor,qualified_candidate,type_position_candidate,member_candidate
    

    --derived-names is required on check as well as on enable, and without it check REPORTS FAILED. Rails' has_many :posts emits a type reference named Post at the span of the literal :posts, so the name was not copied out of the source it points at; validation is all-or-nothing per file, so the authority is what admits the whole file rather than the one row. Withhold it and you keep the package with every Rails file refused — that is a supported answer, not a broken install.

    No --bridges: Ruby resolves inside its own language, so the package declares none. The six capabilities above are exactly what its manifest requests and enable refuses a grant wider than the request; grant fewer and the index stays searchable but resolves less, because every candidate pool a reference could be admitted to is one of them.

    The digest above is the one this release packed and it is what --sha256 pins; de.h-dv.ruby-0.6.0.cip.digest.txt carries it and the extraction identity.

    The 5 fixtures shipped inside it were generated from the COMPILED-IN Ruby extractor, by a different author from the port they grade, and plugin check compares the package's facts against them exhaustively.

    About that key

    sha256:1cb03259a8c870b6db02360abd9351e17e67724d1f8c3509d85c4bf6b06fa72c is a long-lived Ed25519 key held as a secret in this project's CI, used to sign released packages automatically, and it is compiled into the binaries in this release. It signs every package above. That trusts this project's release pipeline, not only its maintainers: anyone who can run a release workflow here can produce a package that verifies under it. It adds nothing you had not already granted — the bytes are inside the program you are running, so forging that anchor means forging the binary — but you are entitled to know it is there before a package installs rather than after.

    There is no expiry — deliberately, because offline installations must not break on a timer — and withdrawal is on your side and works: code-index plugin trust remove sha256:1cb03259a8c870b6db02360abd9351e17e67724d1f8c3509d85c4bf6b06fa72c. A compiled-in key has no file to delete, so that writes one instead, carrying denied = true; the key stops verifying at the next load, plugin trust list shows it marked [DENIED], and deleting that file (the command prints its path) is the only undo. If the key is ever rotated, the new fingerprint is published here and in tests/packages/first-party.fingerprint, and a build that predates the rotation will not trust it.

    You may anchor it yourself instead — code-index plugin trust add code-index-publisher.pub --fingerprint sha256:1cb03259a8c870b6db02360abd9351e17e67724d1f8c3509d85c4bf6b06fa72c --name 'a label you choose', with code-index-publisher.pub from this release's assets. Your file replaces the compiled-in entry, and the --name is a label YOU choose: nothing in the package, the key file or the signature can name its own publisher.

    macOS is not currently built. No x86_64-apple-darwin or aarch64-apple-darwin archive is published — macOS users should build from source (cargo build --release). This is a deliberate deferral, tracked in #59; no date is promised.

    Wire into Claude Code

    { "mcpServers": { "code-index": { "command": "/usr/local/bin/code-index-mcp", "args": ["--root", "/path/to/your/project"] } } }
    

    SHA256 checksums (.sha256 files) available for every archive.

    Downloads
  • v0.28.3 e48d538d1b

    code-index v0.28.3
    Some checks failed
    Release Build / Generate Version (push) Successful in 28s
    CI / cargo fmt (push) Successful in 50s
    CI / OSS corpus tier-3 scale (nightly) (push) Has been skipped
    CI / Grammar rebuild from source (nightly) (push) Has been skipped
    CI / cargo doc (intra-doc links) (push) Successful in 5m42s
    CI / cargo test (abi, 32-bit + wasm32) (push) Successful in 5m51s
    CI / cargo clippy (push) Successful in 6m19s
    CI / cargo deny (push) Successful in 6m35s
    CI / cargo check (MSRV 1.98) (push) Successful in 6m37s
    CI / cargo check (windows-gnu) (push) Successful in 6m55s
    CI / OSS corpus (tier 1) (push) Successful in 31m40s
    CI / cargo test (push) Successful in 42m8s
    CI (Windows) / fmt + clippy + build + test (windows) (push) Successful in 49m27s
    Release Build / Required CI green (push) Failing after 51m54s
    Release Build / Build linux-aarch64 (push) Has been skipped
    Release Build / Build linux-x86_64 (push) Has been skipped
    Release Build / Build linux-x86_64-musl (push) Has been skipped
    Release Build / Build windows-x86_64 (push) Has been skipped
    Release Build / Pack the XAML reference package (push) Has been skipped
    Release Build / Pack the TimeLine package (push) Has been skipped
    Release Build / Pack the Ruby language package (push) Has been skipped
    Release Build / Windows archive smoke (msvc) (push) Has been skipped
    Release Build / Create Forgejo Release (push) Failing after 3m27s
    CI / cargo test (daemon transport) (push) Successful in 18m40s
    CI / Plugin path cost + pool throughput (nightly) (push) Has been skipped
    Stable

    buildagent released this 2026-09-13 11:56:44 +02:00 | 240 commits to master since this release

    code-index v0.28.3

    Build: v0.28.3+771

    Installer: install.sh and checksum. Both come from this release commit. To pin the installed binaries too, run it with --tag v0.28.3.

    Four-binary release: code-index-mcp (MCP stdio bridge — the usual entry), code-index-daemon (long-lived watcher + RPC server, auto-spawned), code-index-plugin-host (bounded worker for plugin packages, spawned by the daemon), and code-index (CLI: init, index, watch, doctor, link, plugin).

    Distribution Registry and Package Management (#269)

    • Introduced unified in-tree distribution catalog distribution/registry.v1.json and JSON schema distribution/schema.v1.json.
    • code-index-core provides RegistryCatalog, PlatformBinary, PluginCatalogEntry, and validation for platform binaries and plugin packages.
    • CLI enhancements:
      • code-index plugin add <id> resolves package IDs and semver constraints directly against the distribution registry.
      • Added --registry and --registry-file options with CODE_INDEX_REGISTRY_URL / CODE_INDEX_REGISTRY_PATH environment variable overrides.
      • Added support for --raw signature generation and verification in code-index plugin sign.
      • Added install.sh --with-plugin <id> flag for streamlined bootstrapping.
    • MCP Server enhancements:
      • Added read-only code-index://registry resource exposing the active distribution catalog.
      • plugin_add MCP tool resolves registered plugins by ID with optional version constraints and capabilities negotiation.
    • Release CI pipeline stages, audits, and publishes registry.v1.json alongside .sha256 checksum and cryptographic signature in both Forgejo generic packages and release downloads.

    Validation and limits

    All 34 release gate invariants pass, including guest lockfile parity and release script isolation.
    Distribution registry schemas and signatures are validated in CLI and MCP integration tests.
    Plugin installation enforces publisher fingerprint verification and package digest authentication.

    Downloads

    Four platforms are built for every release. The table below says which ones THIS release published.

    Platform Archive
    Linux x86_64 (glibc) code-index-v0.28.3-linux-x86_64.tar.gz
    Linux x86_64 (static/musl) code-index-v0.28.3-linux-x86_64-musl.tar.gz
    Linux ARM64 code-index-v0.28.3-linux-aarch64.tar.gz
    Windows x64 code-index-v0.28.3-windows-x86_64.zip

    XAML plugin package

    de.h-dv.xaml-0.2.0.cip makes .xaml files carry symbols and references instead of being text-only: x:Class and Click= handlers bind into the paired C# code-behind, x:Name becomes a searchable declaration, and {Binding …} stays unresolved because no bridge can reach it.

    It is NOT installed by installing code-index. Packages are installed into a user-controlled store and approved per project, and installing grants nothing — enable is the grant.

    Download de.h-dv.xaml-0.2.0.cips too and keep the .cips beside the .cip. Packages are signed and an unsigned one is refused (signature_missing) with no flag that accepts it. You do NOT need to anchor us first: this release's publisher key is compiled into the binary, so the install below works on a machine that has anchored nobody. code-index plugin trust list shows it, marked [BUILTIN], and code-index plugin trust remove sha256:1cb03259a8c870b6db02360abd9351e17e67724d1f8c3509d85c4bf6b06fa72c withdraws it — see About that key.

    code-index plugin install de.h-dv.xaml-0.2.0.cip --sha256 sha256:7b572f5cc32ffcd5af550900a451bbef37e255804776d7e3e3e71d2dd7d0aa79
    code-index plugin check   sha256:7b572f5cc32ffcd5af550900a451bbef37e255804776d7e3e3e71d2dd7d0aa79
    code-index plugin enable  sha256:7b572f5cc32ffcd5af550900a451bbef37e255804776d7e3e3e71d2dd7d0aa79 \
        --capabilities bridge_source \
        --bridges 'de.h-dv.xaml/xaml:type->csharp:class,de.h-dv.xaml/xaml:call->csharp:method'
    

    The digest above is the one this release packed and it is what --sha256 pins; de.h-dv.xaml-0.2.0.cip.digest.txt carries it and the extraction identity. A digest that changes between releases means the package changed — re-pin, and read the notes.

    Only .xaml is claimed by this package. The TimeLine package below claims .dataset, .xsql, .shd and .lgd; all other markup remains text-only (searchable, no symbols).

    TimeLine plugin package

    de.h-dv.timeline-0.1.0.cip makes the four TimeLine definition formats carry symbols and references instead of being text-only: .dataset and .xsql through one language, .shd and .lgd through another, both out of a single sandboxed extractor. References resolve INSIDE a definition file; nothing in v1 crosses into the C# that loads it.

    It is NOT installed by installing code-index. Packages are installed into a user-controlled store and approved per project, and installing grants nothing — enable is the grant.

    Download de.h-dv.timeline-0.1.0.cips too and keep the .cips beside the .cip. The same signature rules apply as for the XAML package above, and the same key signs both.

    code-index plugin install de.h-dv.timeline-0.1.0.cip --sha256 sha256:150ceb22ed9757a660d5a2bf58b80c81b60043cc419e5da5dde559d5d6fc9c9f
    code-index plugin check   sha256:150ceb22ed9757a660d5a2bf58b80c81b60043cc419e5da5dde559d5d6fc9c9f
    code-index plugin enable  sha256:150ceb22ed9757a660d5a2bf58b80c81b60043cc419e5da5dde559d5d6fc9c9f \
        --capabilities same_file_candidate,exported_candidate
    

    No --bridges, and that is the package saying so: it declares none, so there is nothing to grant. The digest above is the one this release packed and it is what --sha256 pins; de.h-dv.timeline-0.1.0.cip.digest.txt carries it and the extraction identity.

    The 5 fixtures shipped inside it are synthetic and modelled on the worked examples in the two format specifications. They carry no customer definition.

    Ruby plugin package

    de.h-dv.ruby-0.6.0.cip is the compiled-in Ruby extractor as an EXTERNAL, sandboxed package: tree-sitter-ruby loaded at runtime, the extractor compiled to wasm32-unknown-unknown and byte-reproducible from crates/guest/ruby/, and the same symbols, references, visibility and Rails association names the built-in produces.

    It claims .rbx, not .rb. The compiled-in Ruby plugin owns .rb, .rake, .gemspec, Rakefile and Gemfile, and a package may not claim a file a built-in claims. So installing this changes NOTHING about how your .rb files are indexed — it is the migration proof for running a full language out of a package, published so it can be read and run rather than described. Do not install it expecting to replace built-in Ruby support.

    It is NOT installed by installing code-index. Packages are installed into a user-controlled store and approved per project, and installing grants nothing — enable is the grant.

    Download de.h-dv.ruby-0.6.0.cips too and keep the .cips beside the .cip. The same signature rules apply as for the packages above, and the same key signs all three.

    code-index plugin install de.h-dv.ruby-0.6.0.cip --sha256 sha256:a6b8d7787cecb49c225ff3dda9016c96babc00c4cf59242a2d774c8b06672048
    code-index plugin check   sha256:a6b8d7787cecb49c225ff3dda9016c96babc00c4cf59242a2d774c8b06672048 --derived-names
    code-index plugin enable  sha256:a6b8d7787cecb49c225ff3dda9016c96babc00c4cf59242a2d774c8b06672048 --derived-names \
        --capabilities same_file_candidate,exported_candidate,reachability_anchor,qualified_candidate,type_position_candidate,member_candidate
    

    --derived-names is required on check as well as on enable, and without it check REPORTS FAILED. Rails' has_many :posts emits a type reference named Post at the span of the literal :posts, so the name was not copied out of the source it points at; validation is all-or-nothing per file, so the authority is what admits the whole file rather than the one row. Withhold it and you keep the package with every Rails file refused — that is a supported answer, not a broken install.

    No --bridges: Ruby resolves inside its own language, so the package declares none. The six capabilities above are exactly what its manifest requests and enable refuses a grant wider than the request; grant fewer and the index stays searchable but resolves less, because every candidate pool a reference could be admitted to is one of them.

    The digest above is the one this release packed and it is what --sha256 pins; de.h-dv.ruby-0.6.0.cip.digest.txt carries it and the extraction identity.

    The 5 fixtures shipped inside it were generated from the COMPILED-IN Ruby extractor, by a different author from the port they grade, and plugin check compares the package's facts against them exhaustively.

    About that key

    sha256:1cb03259a8c870b6db02360abd9351e17e67724d1f8c3509d85c4bf6b06fa72c is a long-lived Ed25519 key held as a secret in this project's CI, used to sign released packages automatically, and it is compiled into the binaries in this release. It signs every package above. That trusts this project's release pipeline, not only its maintainers: anyone who can run a release workflow here can produce a package that verifies under it. It adds nothing you had not already granted — the bytes are inside the program you are running, so forging that anchor means forging the binary — but you are entitled to know it is there before a package installs rather than after.

    There is no expiry — deliberately, because offline installations must not break on a timer — and withdrawal is on your side and works: code-index plugin trust remove sha256:1cb03259a8c870b6db02360abd9351e17e67724d1f8c3509d85c4bf6b06fa72c. A compiled-in key has no file to delete, so that writes one instead, carrying denied = true; the key stops verifying at the next load, plugin trust list shows it marked [DENIED], and deleting that file (the command prints its path) is the only undo. If the key is ever rotated, the new fingerprint is published here and in tests/packages/first-party.fingerprint, and a build that predates the rotation will not trust it.

    You may anchor it yourself instead — code-index plugin trust add code-index-publisher.pub --fingerprint sha256:1cb03259a8c870b6db02360abd9351e17e67724d1f8c3509d85c4bf6b06fa72c --name 'a label you choose', with code-index-publisher.pub from this release's assets. Your file replaces the compiled-in entry, and the --name is a label YOU choose: nothing in the package, the key file or the signature can name its own publisher.

    macOS is not currently built. No x86_64-apple-darwin or aarch64-apple-darwin archive is published — macOS users should build from source (cargo build --release). This is a deliberate deferral, tracked in #59; no date is promised.

    Wire into Claude Code

    { "mcpServers": { "code-index": { "command": "/usr/local/bin/code-index-mcp", "args": ["--root", "/path/to/your/project"] } } }
    

    SHA256 checksums (.sha256 files) available for every archive.

    Downloads