-
code-index v0.24.1
StableAll checks were successfulCI / cargo fmt (push) Successful in 46sCI / OSS corpus tier-3 scale (weekly) (push) Has been skippedCI / Grammar rebuild from source (weekly) (push) Has been skippedCI / cargo test (abi, 32-bit + wasm32) (push) Successful in 4m13sCI / cargo doc (intra-doc links) (push) Successful in 5m7sCI / cargo check (MSRV 1.98) (push) Successful in 5m15sCI / cargo clippy (push) Successful in 5m16sCI / cargo check (windows-gnu) (push) Successful in 5m51sCI / cargo deny (push) Successful in 6m45sCI / OSS corpus (tier 1) (push) Successful in 15m35sCI / cargo test (push) Successful in 16m48sCI / cargo test (daemon transport) (push) Successful in 5m18sCI / Plugin path cost + pool throughput (weekly) (push) Has been skippedCI (Windows) / fmt + clippy + build + test (windows) (push) Successful in 32m36sRelease Build / Generate Version (push) Successful in 17sRelease Build / Required CI green (push) Successful in 1m0sRelease Build / Build linux-aarch64 (push) Successful in 12m59sRelease Build / Build windows-x86_64 (push) Successful in 13m6sRelease Build / Build linux-x86_64 (push) Successful in 15m56sRelease Build / Build linux-x86_64-musl (push) Successful in 16m21sRelease Build / Pack the XAML reference package (push) Successful in 46sRelease Build / Create Forgejo Release (push) Successful in 3m1sreleased this
2026-09-02 18:04:41 +02:00 | 492 commits to master since this releasecode-index v0.24.1
Build: v0.24.1+546
Four-binary release:
code-index-mcp(MCP stdio bridge — the usual entry),code-index-daemon(long-lived watcher + RPC server, auto-spawned),code-index-plugin-host(sandboxed worker for plugin packages, spawned by the daemon), andcode-index(CLI: init, index, watch, doctor, link, plugin).Signed packages, and the one command that installs one.
v0.24.0 published a
.cipfor the first time. This release makes it
verifiable — and, unavoidably, makes v0.24.0's copy permanently
uninstallable: it was published unsigned, and no later release can
retroactively sign bytes that are already out. Take the package from
this release instead.Signing
Ed25519 over the package digest, in a detached
.cips. Signing the
digest rather than the container means the signature check and the
digest check are the same check, so no path exists where a signature
verifies over bytes the digest did not cover.The store verifies at BOTH doors.
Store::getmatters as much as
install, because trust is not a constant:plugin trust removemeans
stop running what that key signed, and that can only take effect where
the signature is re-examined against the current trust set.Unsigned is refused, with no
--allow-unsigned— a named downgrade is
the state everyone ends up in. The escape hatch is three local
commands and the refusal names them.ed25519-compact's verify does not cover the small-order key family;
measured, an order-8 key with a zero scalar verifies roughly three
messages in four. The parser screens keys itself, and the test asserts
both that we refuse and that the library alone would not — so the
workaround can be retired on evidence rather than on faith.One command
plugin addreplaces four commands and a hand-assembled bridge
string. Nothing is written before the answer: it verifies, measures
the reindex domain, and shows one block naming the publisher from your
own trust label and all three effects — installs bytes, RUNS the
package sandboxed against its own fixtures, grants for this project
only. Bare Enter is no.--yesrequires an explicit--grant, and that clause is the whole
difference between a pre-filled answer and a delegation.Honesty
A zero now says which of three things it is: measured, structurally
unmeasurable, or filtered away by an argument the reply now names. And
an agent asking why a plugin stopped working can tell "lost its
signature" from "never installed" — two states with different repairs,
which is why they do not share a code.Getting the package
code-index plugin trust add code-index-publisher.pub \ --fingerprint sha256:1cb03259a8c870b6db02360abd9351e17e67724d1f8c3509d85c4bf6b06fa72c \ --name '<your label for us>' code-index plugin add de.h-dv.xaml-0.1.0.cipAnchoring is a decision about a PUBLISHER, not a package, and it is
the one step that should happen at a keyboard. The fingerprint above
is published here and committed in the repository precisely so it
reaches you by a channel other than the key file: a fingerprint you
compute from the file in front of you agrees with itself and proves
nothing.A signature says these bytes are the ones we signed. It does not say
they are safe.Co-Authored-By: Claude Opus 5 (1M context) noreply@anthropic.com
Claude-Session: https://claude.ai/code/session_01K1zj5VcFJvJt3pQxe9259KDownloads
Four platforms are built for every release. The table below says which ones THIS release published.
Platform Archive Linux x86_64 (glibc) code-index-v0.24.1-linux-x86_64.tar.gz Linux x86_64 (static/musl) code-index-v0.24.1-linux-x86_64-musl.tar.gz Linux ARM64 code-index-v0.24.1-linux-aarch64.tar.gz Windows x64 code-index-v0.24.1-windows-x86_64.zip XAML plugin package
de.h-dv.xaml-0.1.0.cipmakes.xamlfiles carry symbols and references instead of being text-only:x:ClassandClick=handlers bind into the paired C# code-behind,x:Namebecomes a searchable declaration, and{Binding …}stays unresolved because no bridge can reach it.It is NOT installed by installing code-index. Packages are installed into a user-controlled store and approved per project, and installing grants nothing —
enableis the grant.Download
de.h-dv.xaml-0.1.0.cipsandcode-index-publisher.pubtoo, and keep the.cipsbeside the.cip. Packages are signed and an unsigned one is refused (signature_missing) with no flag that accepts it, so anchoring the publisher is the FIRST command and not an optional one — an install run before it refuses withsignature_untrusted:code-index plugin trust add code-index-publisher.pub --fingerprint sha256:1cb03259a8c870b6db02360abd9351e17e67724d1f8c3509d85c4bf6b06fa72c --name 'h-dv (first party)' code-index plugin install de.h-dv.xaml-0.1.0.cip --sha256 sha256:584fe7183b234e7133fa7d257cc8a8d687f38bfb43d235cfda657ba13b1186dd code-index plugin check sha256:584fe7183b234e7133fa7d257cc8a8d687f38bfb43d235cfda657ba13b1186dd code-index plugin enable sha256:584fe7183b234e7133fa7d257cc8a8d687f38bfb43d235cfda657ba13b1186dd \n --capabilities bridge_source \n --bridges 'de.h-dv.xaml/xaml:type->csharp:class,de.h-dv.xaml/xaml:call->csharp:method'The digest above is the one this release packed and it is what
--sha256pins;de.h-dv.xaml-0.1.0.cip.digest.txtcarries it and the extraction identity. A digest that changes between releases means the package changed — re-pin, and read the notes.Only
.xamlis claimed..datasetand other markup remain text-only (searchable, no symbols).About that key
sha256:1cb03259a8c870b6db02360abd9351e17e67724d1f8c3509d85c4bf6b06fa72cis a long-lived Ed25519 key held as a secret in this project's CI, used to sign released packages automatically. Anchoring it means trusting this project's release pipeline, not only its maintainers: anyone who can run a release workflow here can produce a package that verifies under it. There is no expiry — deliberately, because offline installations must not break on a timer — so withdrawal is manual and on your side:code-index plugin trust remove sha256:1cb03259a8c870b6db02360abd9351e17e67724d1f8c3509d85c4bf6b06fa72c. If this key is ever rotated or withdrawn, the new fingerprint is published in the release notes and intests/packages/first-party.fingerprint, and every machine has to runplugin trust addagain.An anchor is machine-wide and it is yours: the
--nameabove is a label YOU choose, and nothing in the package, the key file or the signature can name its own publisher.macOS is not currently built. No
x86_64-apple-darwinoraarch64-apple-darwinarchive is published — macOS users should build from source (cargo build --release). This is a deliberate deferral, tracked in #59; no date is promised.Wire into Claude Code
{ "mcpServers": { "code-index": { "command": "/usr/local/bin/code-index-mcp", "args": ["--root", "/path/to/your/project"] } } }SHA256 checksums (.sha256 files) available for every archive.
Downloads
-
Source code (ZIP)
0 downloads
-
Source code (TAR.GZ)
0 downloads
-
Source code (ZIP)