• v0.28.1 340a75af85

    code-index v0.28.1
    All checks were successful
    CI / cargo fmt (pull_request) Successful in 47s
    CI / OSS corpus tier-3 scale (nightly) (pull_request) Has been skipped
    CI / Grammar rebuild from source (nightly) (pull_request) Has been skipped
    CI / cargo doc (intra-doc links) (pull_request) Successful in 3m57s
    CI / cargo test (abi, 32-bit + wasm32) (pull_request) Successful in 5m3s
    CI / cargo deny (pull_request) Successful in 5m49s
    CI / cargo check (MSRV 1.98) (pull_request) Successful in 5m54s
    CI / cargo check (windows-gnu) (pull_request) Successful in 6m2s
    CI / cargo clippy (pull_request) Successful in 5m59s
    CI / OSS corpus (tier 1) (pull_request) Successful in 25m46s
    CI / cargo test (pull_request) Successful in 26m39s
    CI / cargo test (daemon transport) (pull_request) Successful in 9m31s
    CI / Plugin path cost + pool throughput (nightly) (pull_request) Has been skipped
    CI (Windows) / fmt + clippy + build + test (windows) (pull_request) Successful in 53m15s
    Release Build / Generate Version (push) Successful in 37s
    Release Build / Required CI green (push) Successful in 1m23s
    Release Build / Build linux-aarch64 (push) Successful in 31m5s
    Release Build / Build linux-x86_64 (push) Successful in 34m50s
    Release Build / Build linux-x86_64-musl (push) Successful in 34m58s
    Release Build / Pack the Ruby language package (push) Successful in 51s
    Release Build / Pack the TimeLine package (push) Successful in 57s
    Release Build / Pack the XAML reference package (push) Successful in 1m7s
    Release Build / Build windows-x86_64 (push) Successful in 26m13s
    Release Build / Windows archive smoke (msvc) (push) Successful in 9s
    Release Build / Create Forgejo Release (push) Successful in 4m40s
    Stable

    buildagent released this 2026-09-11 18:57:54 +02:00 | 252 commits to master since this release

    code-index v0.28.1

    Build: v0.28.1+752

    Installer: install.sh and checksum. Both come from this release commit. To pin the installed binaries too, run it with --tag v0.28.1.

    Four-binary release: code-index-mcp (MCP stdio bridge — the usual entry), code-index-daemon (long-lived watcher + RPC server, auto-spawned), code-index-plugin-host (bounded worker for plugin packages, spawned by the daemon), and code-index (CLI: init, index, watch, doctor, link, plugin).

    Maintenance fixes

    This EBF ships the fixes merged in PR #264, plus the release version update in PR #265.

    • Query provenance identifies the SQLite content actually read, including its database incarnation and committed revision. Cursors are bound to that content, and compound queries disclose inconsistent snapshots. An older daemon that cannot report this evidence leaves it unavailable (#245).
    • Bounded working-tree observations distinguish detected changes and incomplete scans from a measured current index. The checks cover new, deleted, ignored and text-only files; they do not promise a complete filesystem snapshot (#260).
    • Python module, import, alias and conservative re-export resolution follows the proven module origin. Project modules shadowing standard-library names no longer receive the reported false bindings (#251). The imported views.serve case in #250 is repaired. Import-aware receiver narrowing is included, but the two real Django User.email sites in #246 remain wrong because an unrelated local rebinding suppresses their import evidence; the smaller regression fixture did not cover that shape.
    • Routing regression checks measure deterministic work instead of using a wall-clock floor that fails under contention (#253).
    • install.sh and its SHA-256 sidecar are release assets, audited against the tagged source before publication. Pin both the installer URL and its --tag argument (#261).
    • All four shipped executables, including code-index-plugin-host, report their version and common build identity. Archive checks derive the executable population from the archive and reject mixed versions (#262).

    Upgrade and coverage

    The database advances to schema 67. Existing Python bindings are cleared and resolved again; actual Flask and Django schema-65 database upgrades matched fresh indexes in validation. Allow reconciliation to finish after upgrading.

    The source-adjudicated comparison against v0.28.0 kept all nine reference populations unchanged, and all seven non-Python corpora were bind-for-bind unchanged. Django gained 1715 correct bindings, removed 1126 false bindings, lost 74 correct and 76 conditionally correct bindings, and corrected two targets. Flask gained 13 correct bindings, removed 10 false bindings, and lost two correct bindings.

    The accepted coverage losses involve composed exports, additional import roots, object/ancestry flows, runtime proxies, GIS configuration and task decorators. Query response costs and corpus measurements were recorded with explicit attribution; tolerance multipliers and the response drift allowance were not widened. Plugin package versions and package identities are unchanged.

    Remaining work

    The two User.email sites in #246 remain falsely bound, and the untyped storage.request.COOKIES chain in #250 is still unresolved. The historical before/after acceptance evidence and membership-isolation regression in #263 are separate follow-ups. This release does not claim these issues are complete.

    macOS remains unsupported (#59). Linux ARM64 is cross-built; the release workflow does not execute that archive on an ARM64 host. The release's download table reports which archives were actually published.

    Validation

    Publication requires green native Windows CI, Linux workspace and daemon-transport tests, and the OSS corpus gates on the release commit. The release pipeline runs plugin loading, timeout and trap-recovery checks against the supported executable artifacts, including the Windows archive after its artifact-store round trip. Post-publication checks verify the installer and downloaded archive checksums, executable versions and installation into an isolated prefix.

    Downloads

    Four platforms are built for every release. The table below says which ones THIS release published.

    Platform Archive
    Linux x86_64 (glibc) code-index-v0.28.1-linux-x86_64.tar.gz
    Linux x86_64 (static/musl) code-index-v0.28.1-linux-x86_64-musl.tar.gz
    Linux ARM64 code-index-v0.28.1-linux-aarch64.tar.gz
    Windows x64 code-index-v0.28.1-windows-x86_64.zip

    XAML plugin package

    de.h-dv.xaml-0.2.0.cip makes .xaml files carry symbols and references instead of being text-only: x:Class and Click= handlers bind into the paired C# code-behind, x:Name becomes a searchable declaration, and {Binding …} stays unresolved because no bridge can reach it.

    It is NOT installed by installing code-index. Packages are installed into a user-controlled store and approved per project, and installing grants nothing — enable is the grant.

    Download de.h-dv.xaml-0.2.0.cips too and keep the .cips beside the .cip. Packages are signed and an unsigned one is refused (signature_missing) with no flag that accepts it. You do NOT need to anchor us first: this release's publisher key is compiled into the binary, so the install below works on a machine that has anchored nobody. code-index plugin trust list shows it, marked [BUILTIN], and code-index plugin trust remove sha256:1cb03259a8c870b6db02360abd9351e17e67724d1f8c3509d85c4bf6b06fa72c withdraws it — see About that key.

    code-index plugin install de.h-dv.xaml-0.2.0.cip --sha256 sha256:7b572f5cc32ffcd5af550900a451bbef37e255804776d7e3e3e71d2dd7d0aa79
    code-index plugin check   sha256:7b572f5cc32ffcd5af550900a451bbef37e255804776d7e3e3e71d2dd7d0aa79
    code-index plugin enable  sha256:7b572f5cc32ffcd5af550900a451bbef37e255804776d7e3e3e71d2dd7d0aa79 \
        --capabilities bridge_source \
        --bridges 'de.h-dv.xaml/xaml:type->csharp:class,de.h-dv.xaml/xaml:call->csharp:method'
    

    The digest above is the one this release packed and it is what --sha256 pins; de.h-dv.xaml-0.2.0.cip.digest.txt carries it and the extraction identity. A digest that changes between releases means the package changed — re-pin, and read the notes.

    Only .xaml is claimed by this package. The TimeLine package below claims .dataset, .xsql, .shd and .lgd; all other markup remains text-only (searchable, no symbols).

    TimeLine plugin package

    de.h-dv.timeline-0.1.0.cip makes the four TimeLine definition formats carry symbols and references instead of being text-only: .dataset and .xsql through one language, .shd and .lgd through another, both out of a single sandboxed extractor. References resolve INSIDE a definition file; nothing in v1 crosses into the C# that loads it.

    It is NOT installed by installing code-index. Packages are installed into a user-controlled store and approved per project, and installing grants nothing — enable is the grant.

    Download de.h-dv.timeline-0.1.0.cips too and keep the .cips beside the .cip. The same signature rules apply as for the XAML package above, and the same key signs both.

    code-index plugin install de.h-dv.timeline-0.1.0.cip --sha256 sha256:150ceb22ed9757a660d5a2bf58b80c81b60043cc419e5da5dde559d5d6fc9c9f
    code-index plugin check   sha256:150ceb22ed9757a660d5a2bf58b80c81b60043cc419e5da5dde559d5d6fc9c9f
    code-index plugin enable  sha256:150ceb22ed9757a660d5a2bf58b80c81b60043cc419e5da5dde559d5d6fc9c9f \
        --capabilities same_file_candidate,exported_candidate
    

    No --bridges, and that is the package saying so: it declares none, so there is nothing to grant. The digest above is the one this release packed and it is what --sha256 pins; de.h-dv.timeline-0.1.0.cip.digest.txt carries it and the extraction identity.

    The 5 fixtures shipped inside it are synthetic and modelled on the worked examples in the two format specifications. They carry no customer definition.

    Ruby plugin package

    de.h-dv.ruby-0.6.0.cip is the compiled-in Ruby extractor as an EXTERNAL, sandboxed package: tree-sitter-ruby loaded at runtime, the extractor compiled to wasm32-unknown-unknown and byte-reproducible from crates/guest/ruby/, and the same symbols, references, visibility and Rails association names the built-in produces.

    It claims .rbx, not .rb. The compiled-in Ruby plugin owns .rb, .rake, .gemspec, Rakefile and Gemfile, and a package may not claim a file a built-in claims. So installing this changes NOTHING about how your .rb files are indexed — it is the migration proof for running a full language out of a package, published so it can be read and run rather than described. Do not install it expecting to replace built-in Ruby support.

    It is NOT installed by installing code-index. Packages are installed into a user-controlled store and approved per project, and installing grants nothing — enable is the grant.

    Download de.h-dv.ruby-0.6.0.cips too and keep the .cips beside the .cip. The same signature rules apply as for the packages above, and the same key signs all three.

    code-index plugin install de.h-dv.ruby-0.6.0.cip --sha256 sha256:a6b8d7787cecb49c225ff3dda9016c96babc00c4cf59242a2d774c8b06672048
    code-index plugin check   sha256:a6b8d7787cecb49c225ff3dda9016c96babc00c4cf59242a2d774c8b06672048 --derived-names
    code-index plugin enable  sha256:a6b8d7787cecb49c225ff3dda9016c96babc00c4cf59242a2d774c8b06672048 --derived-names \
        --capabilities same_file_candidate,exported_candidate,reachability_anchor,qualified_candidate,type_position_candidate,member_candidate
    

    --derived-names is required on check as well as on enable, and without it check REPORTS FAILED. Rails' has_many :posts emits a type reference named Post at the span of the literal :posts, so the name was not copied out of the source it points at; validation is all-or-nothing per file, so the authority is what admits the whole file rather than the one row. Withhold it and you keep the package with every Rails file refused — that is a supported answer, not a broken install.

    No --bridges: Ruby resolves inside its own language, so the package declares none. The six capabilities above are exactly what its manifest requests and enable refuses a grant wider than the request; grant fewer and the index stays searchable but resolves less, because every candidate pool a reference could be admitted to is one of them.

    The digest above is the one this release packed and it is what --sha256 pins; de.h-dv.ruby-0.6.0.cip.digest.txt carries it and the extraction identity.

    The 5 fixtures shipped inside it were generated from the COMPILED-IN Ruby extractor, by a different author from the port they grade, and plugin check compares the package's facts against them exhaustively.

    About that key

    sha256:1cb03259a8c870b6db02360abd9351e17e67724d1f8c3509d85c4bf6b06fa72c is a long-lived Ed25519 key held as a secret in this project's CI, used to sign released packages automatically, and it is compiled into the binaries in this release. It signs every package above. That trusts this project's release pipeline, not only its maintainers: anyone who can run a release workflow here can produce a package that verifies under it. It adds nothing you had not already granted — the bytes are inside the program you are running, so forging that anchor means forging the binary — but you are entitled to know it is there before a package installs rather than after.

    There is no expiry — deliberately, because offline installations must not break on a timer — and withdrawal is on your side and works: code-index plugin trust remove sha256:1cb03259a8c870b6db02360abd9351e17e67724d1f8c3509d85c4bf6b06fa72c. A compiled-in key has no file to delete, so that writes one instead, carrying denied = true; the key stops verifying at the next load, plugin trust list shows it marked [DENIED], and deleting that file (the command prints its path) is the only undo. If the key is ever rotated, the new fingerprint is published here and in tests/packages/first-party.fingerprint, and a build that predates the rotation will not trust it.

    You may anchor it yourself instead — code-index plugin trust add code-index-publisher.pub --fingerprint sha256:1cb03259a8c870b6db02360abd9351e17e67724d1f8c3509d85c4bf6b06fa72c --name 'a label you choose', with code-index-publisher.pub from this release's assets. Your file replaces the compiled-in entry, and the --name is a label YOU choose: nothing in the package, the key file or the signature can name its own publisher.

    macOS is not currently built. No x86_64-apple-darwin or aarch64-apple-darwin archive is published — macOS users should build from source (cargo build --release). This is a deliberate deferral, tracked in #59; no date is promised.

    Wire into Claude Code

    { "mcpServers": { "code-index": { "command": "/usr/local/bin/code-index-mcp", "args": ["--root", "/path/to/your/project"] } } }
    

    SHA256 checksums (.sha256 files) available for every archive.

    Downloads