-
code-index v0.29.0
StableAll checks were successfulCI / cargo fmt (push) Successful in 49sCI / OSS corpus tier-3 scale (nightly) (push) Has been skippedCI / Grammar rebuild from source (nightly) (push) Has been skippedCI / cargo doc (intra-doc links) (push) Successful in 4m20sCI / cargo test (abi, 32-bit + wasm32) (push) Successful in 5m28sCI / cargo check (MSRV 1.98) (push) Successful in 5m56sCI / cargo clippy (push) Successful in 6m18sCI / cargo check (windows-gnu) (push) Successful in 6m21sCI / cargo deny (push) Successful in 6m27sCI / OSS corpus (tier 1) (push) Successful in 28m56sCI / cargo test (push) Successful in 38m52sCI (Windows) / fmt + clippy + build + test (windows) (push) Successful in 50m49sCI / cargo test (daemon transport) (push) Successful in 18m10sCI / Plugin path cost + pool throughput (nightly) (push) Has been skippedRelease Build / Generate Version (push) Successful in 30sRelease Build / Required CI green (push) Successful in 1m3sRelease Build / Build linux-aarch64 (push) Successful in 12m57sRelease Build / Build linux-x86_64 (push) Successful in 15m28sRelease Build / Build linux-x86_64-musl (push) Successful in 16m19sRelease Build / Pack the Ruby language package (push) Successful in 50sRelease Build / Pack the XAML reference package (push) Successful in 52sRelease Build / Pack the TimeLine package (push) Successful in 1m1sRelease Build / Build windows-x86_64 (push) Successful in 20m22sRelease Build / Windows archive smoke (msvc) (push) Successful in 6sRelease Build / Create Forgejo Release (push) Successful in 5m0sreleased this
2026-09-14 07:12:03 +02:00 | 235 commits to master since this releasecode-index v0.29.0
Build: v0.29.0+786
Installer: install.sh and checksum. Both come from this release commit. To pin the installed binaries too, run it with
--tag v0.29.0.Four-binary release:
code-index-mcp(MCP stdio bridge — the usual entry),code-index-daemon(long-lived watcher + RPC server, auto-spawned),code-index-plugin-host(bounded worker for plugin packages, spawned by the daemon), andcode-index(CLI: init, index, watch, doctor, link, plugin).v0.28.3 published a distribution catalog whose four platform checksums were fabricated, signed with the publisher key, and wrong. The real
linux-x86_64archive hashed0dce077f…; the catalog saidd95f0cb7…. All four disagreed with CI's own.sha256sidecars. Nothing broke only because nothing consumed them yet —install.shstill used the per-archive sidecars — so the first consumer to trust that catalog would have rejected genuine artifacts.The cause was structural rather than careless: a gate pinned the catalog's version to the crate version, so every release forced someone to edit that file and invent four hashes that cannot exist until CI has built the archives. The gate demanded the edit and could not grade it.
One rule
No value in
distribution/registry.v1.jsonis authored. Each is derived from the artifact it describes, by the step holding that artifact.Plugin facts are derivable in-tree, from
tests/packages/*/plugin.tomland the packed.cip; platform facts only at release time, from the archives' own checksum sidecars. A document that cannot derive a fact now declares it unmeasured instead of inventing one —platformsis a taggedmeasured/unmeasuredstate, so an empty map can never stand in for "not measured here", and a source form carrying agenerated_attimestamp is refused outright.min_code_index_versionwas dropped rather than authored: no artifact states a minimum host version and no code read it. The package's own[abi]bracket is the real statement, andplugin installalready enforces it.The catalog now covers all three published packages
v0.28.3 listed one of three, so
plugin add de.h-dv.rubycould not resolve at all. Every plugin fact is re-derived from the package that ships it and compared, and the package set is enumerated from disk — so the tree GROWING is caught, not only the catalog shrinking.The signature is verified, by the keys you anchor
verify_catalog_signatureexisted with zero callers while the client fetched catalogs over HTTP and used them. It is now required at every door but the compiled-in one, and checked against your trust set rather than the built-in anchors directly — soplugin trust removereaches the catalog door exactly as it reaches an installed package. There is no flag that accepts an unsigned catalog: a catalog decides which bytes get fetched and which digest they are pinned to.Probed end to end through the shipped binary: a valid catalog reports the signer's fingerprint; a single changed byte is
signature_invalid; a missing.sigissignature_missingnaming the exact path it looked for; an unanchored signer issignature_untrusted; and afterplugin trust remove, the same previously-valid catalog refuses, with the trusted-key count dropping 2 to 1.Installing grants nothing
install.sh --with-plugin <id>fetches, verifies and installs into the machine-wide store, then prints thecode-index plugin add <id>line for you to run inside a project. It previously ranplugin add --grant requested --yes, which made the first capability grant on a fresh machine non-interactively, inside acurl | sh, for whichever project the working directory happened to detect. The first grant on a machine stays a human decision.Updating from the catalog
[update."<id>"]gainsfrom = "registry"as its own key, mutually exclusive withsource. A sentinel insidesourcewas indistinguishable from a hostname —registry.example.com/pkg.cipis a real thing an operator may write, and the old prefix test swallowed it and served the embedded catalog instead, silently. The registry path is held to the same clause as a URL, so a stale or hostile catalog offering an older signed version is refused rather than applied.New
code-index plugin catalog [SOURCE]— read-only. Reports the source, byte count, the fingerprint that verified it, the platform state and the plugin list; exits non-zero on any refusal. The release uses it to check its own signature through the same door a customer takes.plugin_addover MCP acceptspackage: "<id>", fetches it when the store does not already hold it, and enforces the catalog's pinned digest before the operator is asked anything.code-index://registry/pluginsanswers which package claims a symbol-blind extension in this workspace, with an explicit availability state rather than an absent key.
Honesty notes
project_overview'sregistry_availableblock is gone. It collapsed four different absences into one rendering and read an unconsultable package store as "nothing installed". The workspace join moved to the registry resource, which is not token-ratcheted and can afford to say what it measured.Two failures were found in this release's own CI and fixed here: the CI image ships no
jq(the release would have died at catalog staging), andcargo fmt --allexceeds the Windows 32767-character command-line limit once the workspace passes ~350 targets. Both now have gates that measure the real thing and print their numbers on every run.Downloads
Four platforms are built for every release. The table below says which ones THIS release published.
Platform Archive Linux x86_64 (glibc) code-index-v0.29.0-linux-x86_64.tar.gz Linux x86_64 (static/musl) code-index-v0.29.0-linux-x86_64-musl.tar.gz Linux ARM64 code-index-v0.29.0-linux-aarch64.tar.gz Windows x64 code-index-v0.29.0-windows-x86_64.zip XAML plugin package
de.h-dv.xaml-0.2.0.cipmakes.xamlfiles carry symbols and references instead of being text-only:x:ClassandClick=handlers bind into the paired C# code-behind,x:Namebecomes a searchable declaration, and{Binding …}stays unresolved because no bridge can reach it.It is NOT installed by installing code-index. Packages are installed into a user-controlled store and approved per project, and installing grants nothing —
enableis the grant.Download
de.h-dv.xaml-0.2.0.cipstoo and keep the.cipsbeside the.cip. Packages are signed and an unsigned one is refused (signature_missing) with no flag that accepts it. You do NOT need to anchor us first: this release's publisher key is compiled into the binary, so the install below works on a machine that has anchored nobody.code-index plugin trust listshows it, marked[BUILTIN], andcode-index plugin trust remove sha256:1cb03259a8c870b6db02360abd9351e17e67724d1f8c3509d85c4bf6b06fa72cwithdraws it — see About that key.code-index plugin install de.h-dv.xaml-0.2.0.cip --sha256 sha256:7b572f5cc32ffcd5af550900a451bbef37e255804776d7e3e3e71d2dd7d0aa79 code-index plugin check sha256:7b572f5cc32ffcd5af550900a451bbef37e255804776d7e3e3e71d2dd7d0aa79 code-index plugin enable sha256:7b572f5cc32ffcd5af550900a451bbef37e255804776d7e3e3e71d2dd7d0aa79 \ --capabilities bridge_source \ --bridges 'de.h-dv.xaml/xaml:type->csharp:class,de.h-dv.xaml/xaml:call->csharp:method'The digest above is the one this release packed and it is what
--sha256pins;de.h-dv.xaml-0.2.0.cip.digest.txtcarries it and the extraction identity. A digest that changes between releases means the package changed — re-pin, and read the notes.Only
.xamlis claimed by this package. The TimeLine package below claims.dataset,.xsql,.shdand.lgd; all other markup remains text-only (searchable, no symbols).TimeLine plugin package
de.h-dv.timeline-0.1.0.cipmakes the four TimeLine definition formats carry symbols and references instead of being text-only:.datasetand.xsqlthrough one language,.shdand.lgdthrough another, both out of a single sandboxed extractor. References resolve INSIDE a definition file; nothing in v1 crosses into the C# that loads it.It is NOT installed by installing code-index. Packages are installed into a user-controlled store and approved per project, and installing grants nothing —
enableis the grant.Download
de.h-dv.timeline-0.1.0.cipstoo and keep the.cipsbeside the.cip. The same signature rules apply as for the XAML package above, and the same key signs both.code-index plugin install de.h-dv.timeline-0.1.0.cip --sha256 sha256:150ceb22ed9757a660d5a2bf58b80c81b60043cc419e5da5dde559d5d6fc9c9f code-index plugin check sha256:150ceb22ed9757a660d5a2bf58b80c81b60043cc419e5da5dde559d5d6fc9c9f code-index plugin enable sha256:150ceb22ed9757a660d5a2bf58b80c81b60043cc419e5da5dde559d5d6fc9c9f \ --capabilities same_file_candidate,exported_candidateNo
--bridges, and that is the package saying so: it declares none, so there is nothing to grant. The digest above is the one this release packed and it is what--sha256pins;de.h-dv.timeline-0.1.0.cip.digest.txtcarries it and the extraction identity.The 5 fixtures shipped inside it are synthetic and modelled on the worked examples in the two format specifications. They carry no customer definition.
Ruby plugin package
de.h-dv.ruby-0.6.0.cipis the compiled-in Ruby extractor as an EXTERNAL, sandboxed package:tree-sitter-rubyloaded at runtime, the extractor compiled towasm32-unknown-unknownand byte-reproducible fromcrates/guest/ruby/, and the same symbols, references, visibility and Rails association names the built-in produces.It claims
.rbx, not.rb. The compiled-in Ruby plugin owns.rb,.rake,.gemspec,RakefileandGemfile, and a package may not claim a file a built-in claims. So installing this changes NOTHING about how your.rbfiles are indexed — it is the migration proof for running a full language out of a package, published so it can be read and run rather than described. Do not install it expecting to replace built-in Ruby support.It is NOT installed by installing code-index. Packages are installed into a user-controlled store and approved per project, and installing grants nothing —
enableis the grant.Download
de.h-dv.ruby-0.6.0.cipstoo and keep the.cipsbeside the.cip. The same signature rules apply as for the packages above, and the same key signs all three.code-index plugin install de.h-dv.ruby-0.6.0.cip --sha256 sha256:a6b8d7787cecb49c225ff3dda9016c96babc00c4cf59242a2d774c8b06672048 code-index plugin check sha256:a6b8d7787cecb49c225ff3dda9016c96babc00c4cf59242a2d774c8b06672048 --derived-names code-index plugin enable sha256:a6b8d7787cecb49c225ff3dda9016c96babc00c4cf59242a2d774c8b06672048 --derived-names \ --capabilities same_file_candidate,exported_candidate,reachability_anchor,qualified_candidate,type_position_candidate,member_candidate--derived-namesis required oncheckas well as onenable, and without itcheckREPORTS FAILED. Rails'has_many :postsemits a type reference namedPostat the span of the literal:posts, so the name was not copied out of the source it points at; validation is all-or-nothing per file, so the authority is what admits the whole file rather than the one row. Withhold it and you keep the package with every Rails file refused — that is a supported answer, not a broken install.No
--bridges: Ruby resolves inside its own language, so the package declares none. The six capabilities above are exactly what its manifest requests andenablerefuses a grant wider than the request; grant fewer and the index stays searchable but resolves less, because every candidate pool a reference could be admitted to is one of them.The digest above is the one this release packed and it is what
--sha256pins;de.h-dv.ruby-0.6.0.cip.digest.txtcarries it and the extraction identity.The 5 fixtures shipped inside it were generated from the COMPILED-IN Ruby extractor, by a different author from the port they grade, and
plugin checkcompares the package's facts against them exhaustively.About that key
sha256:1cb03259a8c870b6db02360abd9351e17e67724d1f8c3509d85c4bf6b06fa72cis a long-lived Ed25519 key held as a secret in this project's CI, used to sign released packages automatically, and it is compiled into the binaries in this release. It signs every package above. That trusts this project's release pipeline, not only its maintainers: anyone who can run a release workflow here can produce a package that verifies under it. It adds nothing you had not already granted — the bytes are inside the program you are running, so forging that anchor means forging the binary — but you are entitled to know it is there before a package installs rather than after.There is no expiry — deliberately, because offline installations must not break on a timer — and withdrawal is on your side and works:
code-index plugin trust remove sha256:1cb03259a8c870b6db02360abd9351e17e67724d1f8c3509d85c4bf6b06fa72c. A compiled-in key has no file to delete, so that writes one instead, carryingdenied = true; the key stops verifying at the next load,plugin trust listshows it marked[DENIED], and deleting that file (the command prints its path) is the only undo. If the key is ever rotated, the new fingerprint is published here and intests/packages/first-party.fingerprint, and a build that predates the rotation will not trust it.You may anchor it yourself instead —
code-index plugin trust add code-index-publisher.pub --fingerprint sha256:1cb03259a8c870b6db02360abd9351e17e67724d1f8c3509d85c4bf6b06fa72c --name 'a label you choose', withcode-index-publisher.pubfrom this release's assets. Your file replaces the compiled-in entry, and the--nameis a label YOU choose: nothing in the package, the key file or the signature can name its own publisher.macOS is not currently built. No
x86_64-apple-darwinoraarch64-apple-darwinarchive is published — macOS users should build from source (cargo build --release). This is a deliberate deferral, tracked in #59; no date is promised.Wire into Claude Code
{ "mcpServers": { "code-index": { "command": "/usr/local/bin/code-index-mcp", "args": ["--root", "/path/to/your/project"] } } }SHA256 checksums (.sha256 files) available for every archive.
Downloads
-
Source code (ZIP)
0 downloads
-
Source code (TAR.GZ)
0 downloads