• v0.25.0 5d5eba67cf

    code-index v0.25.0
    All checks were successful
    CI / cargo fmt (push) Successful in 45s
    CI / Grammar rebuild from source (weekly) (push) Has been skipped
    CI / OSS corpus tier-3 scale (weekly) (push) Has been skipped
    CI / cargo doc (intra-doc links) (push) Successful in 4m22s
    CI / cargo test (abi, 32-bit + wasm32) (push) Successful in 4m28s
    CI / cargo clippy (push) Successful in 5m24s
    CI / cargo check (MSRV 1.98) (push) Successful in 5m28s
    CI / cargo check (windows-gnu) (push) Successful in 5m35s
    CI / cargo deny (push) Successful in 6m15s
    CI / OSS corpus (tier 1) (push) Successful in 15m10s
    CI / cargo test (push) Successful in 16m52s
    CI / cargo test (daemon transport) (push) Successful in 6m11s
    CI / Plugin path cost + pool throughput (weekly) (push) Has been skipped
    CI (Windows) / fmt + clippy + build + test (windows) (push) Successful in 32m42s
    Release Build / Generate Version (push) Successful in 18s
    Release Build / Required CI green (push) Successful in 56s
    Release Build / Build linux-aarch64 (push) Successful in 12m55s
    Release Build / Build windows-x86_64 (push) Successful in 13m5s
    Release Build / Build linux-x86_64 (push) Successful in 15m41s
    Release Build / Build linux-x86_64-musl (push) Successful in 15m44s
    Release Build / Pack the XAML reference package (push) Successful in 52s
    Release Build / Create Forgejo Release (push) Successful in 2m49s
    Stable

    buildagent released this 2026-09-03 08:43:46 +02:00 | 487 commits to master since this release

    code-index v0.25.0

    Build: v0.25.0+556

    Four-binary release: code-index-mcp (MCP stdio bridge — the usual entry), code-index-daemon (long-lived watcher + RPC server, auto-spawned), code-index-plugin-host (sandboxed worker for plugin packages, spawned by the daemon), and code-index (CLI: init, index, watch, doctor, link, plugin).

    Our key ships in the binary, and an agent can ask to install a plugin.

    Installing a package we publish takes one command

    v0.24.1 made packages verifiable and, in doing so, made anchoring a
    publisher the FIRST thing a new operator had to do — a trust add
    with a fingerprint fetched through a second channel, before an install
    that would otherwise refuse. Correct, and the wrong first impression:
    the ceremony that protects you from a stranger was charged to you for
    a package that arrived inside the same archive as the program.

    The first-party key is now compiled into the binaries.
    plugin trust list shows it as [BUILTIN]. plugin add de.h-dv.xaml-0.1.0.cip works on a machine with an empty trust store.

    It extends no trust you had not already extended — forging that anchor
    means forging the binary you are running — and anchoring a THIRD-PARTY
    publisher is still the deliberate act it was.

    It is revocable, offline, like any other key. plugin trust remove <fingerprint> on a built-in WRITES a denial into your trust directory
    rather than deleting a file that is not there, and the key stops
    verifying at the next load. Which mechanic runs is decided from the
    compiled-in bytes and never from a file's own builtin flag, so a
    hand-edited anchor can neither turn the withdrawal into a no-op nor
    let a delete quietly restore trust.

    The fingerprint stays
    sha256:1cb03259a8c870b6db02360abd9351e17e67724d1f8c3509d85c4bf6b06fa72c.
    It is compiled in, committed in tests/packages/first-party.fingerprint,
    printed in these notes, and a gate compares all three — plus one that
    asserts the SHIPPED BINARY lists it, so drift is caught in the artifact
    and not only in the tree.

    plugin_add over MCP

    The CLI half shipped in v0.24.1; this is the other half, and its
    security property is different. On a terminal the human is the caller.
    Over MCP the caller is an agent that reads the repository — the
    untrusted party.

    So there is no approving argument. Inventing one is refused by the
    unknown-argument gate rather than dropped silently. A grant is a
    REQUEST; only the elicitation is an answer. A client declaring no
    elicitation capability gets confirmation_unavailable — no fallback
    and no auto-approve, because a tool that proceeds when there is nobody
    to ask is worse than one that does not exist. Decline, cancel and
    timeout all leave the user root and the project byte-identical.

    The daemon says when it has not looked yet

    project_overview could answer from the database while the live
    package set was still being discovered, and the reply was
    indistinguishable from a healthy project's: an active generation, a
    covered file, and the two package fields simply MISSING because both
    are omitted when absent. Measured at 9 failures in 10 runs under load.

    The daemon binding its listener before discovery finishes is the
    design. Not saying so was the defect. package_set_consulted is now
    on the block: false means nobody has looked yet — ask again — and
    carries the prose explaining it; true means an absent package field
    is a MEASUREMENT; absent still means a daemon that does not report it.

    index_host had the same shape one level down: a worker binary that
    disappeared between two stats produced a silent builtins-only pass
    wearing a line that read as a measurement, in the one state the pass
    policy exists to refuse. It re-measures and re-applies that policy now
    rather than deciding a second time.

    Three binaries stopped shipping a wasm compiler

    nm -C on the release's own build found 441 cranelift symbols in
    code-index, code-index-daemon and code-index-mcp. Cargo unifies
    features across the packages selected in ONE invocation, and
    code-index-plugin-host needs tree-sitter's wasm feature. The
    release builds in two invocations now; shared dependencies compile
    twice, which is the price of three binaries not carrying a JIT.

    Getting the package

    code-index plugin add de.h-dv.xaml-0.1.0.cip
    

    No trust add first. Keep the .cips beside the .cip.

    A signature says these bytes are the ones we signed. It does not say
    they are safe.

    Downloads

    Four platforms are built for every release. The table below says which ones THIS release published.

    Platform Archive
    Linux x86_64 (glibc) code-index-v0.25.0-linux-x86_64.tar.gz
    Linux x86_64 (static/musl) code-index-v0.25.0-linux-x86_64-musl.tar.gz
    Linux ARM64 code-index-v0.25.0-linux-aarch64.tar.gz
    Windows x64 code-index-v0.25.0-windows-x86_64.zip

    XAML plugin package

    de.h-dv.xaml-0.1.0.cip makes .xaml files carry symbols and references instead of being text-only: x:Class and Click= handlers bind into the paired C# code-behind, x:Name becomes a searchable declaration, and {Binding …} stays unresolved because no bridge can reach it.

    It is NOT installed by installing code-index. Packages are installed into a user-controlled store and approved per project, and installing grants nothing — enable is the grant.

    Download de.h-dv.xaml-0.1.0.cips too and keep the .cips beside the .cip. Packages are signed and an unsigned one is refused (signature_missing) with no flag that accepts it. You do NOT need to anchor us first: this release's publisher key is compiled into the binary, so the install below works on a machine that has anchored nobody. code-index plugin trust list shows it, marked [BUILTIN], and code-index plugin trust remove sha256:1cb03259a8c870b6db02360abd9351e17e67724d1f8c3509d85c4bf6b06fa72c withdraws it — see About that key.

    code-index plugin install de.h-dv.xaml-0.1.0.cip --sha256 sha256:584fe7183b234e7133fa7d257cc8a8d687f38bfb43d235cfda657ba13b1186dd
    code-index plugin check   sha256:584fe7183b234e7133fa7d257cc8a8d687f38bfb43d235cfda657ba13b1186dd
    code-index plugin enable  sha256:584fe7183b234e7133fa7d257cc8a8d687f38bfb43d235cfda657ba13b1186dd \
        --capabilities bridge_source \
        --bridges 'de.h-dv.xaml/xaml:type->csharp:class,de.h-dv.xaml/xaml:call->csharp:method'
    

    The digest above is the one this release packed and it is what --sha256 pins; de.h-dv.xaml-0.1.0.cip.digest.txt carries it and the extraction identity. A digest that changes between releases means the package changed — re-pin, and read the notes.

    Only .xaml is claimed. .dataset and other markup remain text-only (searchable, no symbols).

    About that key

    sha256:1cb03259a8c870b6db02360abd9351e17e67724d1f8c3509d85c4bf6b06fa72c is a long-lived Ed25519 key held as a secret in this project's CI, used to sign released packages automatically, and it is compiled into the binaries in this release. That trusts this project's release pipeline, not only its maintainers: anyone who can run a release workflow here can produce a package that verifies under it. It adds nothing you had not already granted — the bytes are inside the program you are running, so forging that anchor means forging the binary — but you are entitled to know it is there before a package installs rather than after.

    There is no expiry — deliberately, because offline installations must not break on a timer — and withdrawal is on your side and works: code-index plugin trust remove sha256:1cb03259a8c870b6db02360abd9351e17e67724d1f8c3509d85c4bf6b06fa72c. A compiled-in key has no file to delete, so that writes one instead, carrying denied = true; the key stops verifying at the next load, plugin trust list shows it marked [DENIED], and deleting that file (the command prints its path) is the only undo. If the key is ever rotated, the new fingerprint is published here and in tests/packages/first-party.fingerprint, and a build that predates the rotation will not trust it.

    You may anchor it yourself instead — code-index plugin trust add code-index-publisher.pub --fingerprint sha256:1cb03259a8c870b6db02360abd9351e17e67724d1f8c3509d85c4bf6b06fa72c --name 'a label you choose', with code-index-publisher.pub from this release's assets. Your file replaces the compiled-in entry, and the --name is a label YOU choose: nothing in the package, the key file or the signature can name its own publisher.

    macOS is not currently built. No x86_64-apple-darwin or aarch64-apple-darwin archive is published — macOS users should build from source (cargo build --release). This is a deliberate deferral, tracked in #59; no date is promised.

    Wire into Claude Code

    { "mcpServers": { "code-index": { "command": "/usr/local/bin/code-index-mcp", "args": ["--root", "/path/to/your/project"] } } }
    

    SHA256 checksums (.sha256 files) available for every archive.

    Downloads