Skip to content

v0.1.0

Choose a tag to compare

@github-actions github-actions released this 18 Aug 08:06
· 9 commits to main since this release

What changed

  • docs: story 15 walks — Memnoc opens a stranger's code lit at its own lines, and nothing gates the tag
  • docs: R-3 and R-4 close on Memnoc's word — six dispositions recorded, none left as silence
  • docs: R-2 signs and lands — the transparency position stated once, in the notes and the README
  • docs: R-1, R-3 and R-5 close where the evidence lets them — the shipping entry lands, Colorado is a court order, Illinois stays honest
  • docs: the Compliance Round enters the record — verdict ready, five remediation rows gate the tag
  • docs: the V3 harden walk — nineteen stories watched, the twentieth waits for the fresh machine
  • chore: ticket 09 closes green — the dry run proved the release, the arm question answered itself on real hardware
  • fix: walkthrough-steps stops case-colliding with Walkthrough — the first macOS build ever run caught it
  • feat: a tag becomes evidence — the release workflow builds four targets, sealed beside default, and the dry run publishes nothing
  • docs: the provenance sentence tells the store-level truth — one record, the last run that wrote it
  • docs: the release documents — the README leads with download-and-run, the notes template says what needs no key and how this was built
  • feat: the store survives strangers — a rewrite carries the sections it does not understand, version 2 stands
  • feat: ask input closes its last open dimension — citations clamp at count and length, the malformed turn's 400 is pinned
  • feat: the wire keeps HTTP's promises — every 405 names its Allow, three tokens or nothing, FROB draws an honest 501
  • feat: the share artifact stays innocent — the wire chunk never rides it, and the byte-scan holds every route out
  • feat: opened source arrives highlighted — the seven vendored grammars drive their own queries, plain text stated for the rest
  • feat: the dashboard opens code — the offer rides the selection, a symbol lands lit at its own lines
  • feat: the source route exists exactly behind --open-code — the map is the allowlist, truncation is disclosed
  • chore: the V3 ticket set — nine slices, frontier of five
  • docs: /to-spec crystallises V3 — 20 stories, six seams, the contract untouched
  • docs: the V3 interview closes — ADR-0013 open code, ADR-0014 distribution
  • docs: the conversation pair re-exported — Memnoc's own touch-up, same names, drop-in
  • docs: /next harvests the V3 agenda — distribution and open code are the headliners
  • chore: the recording shot script parks in scratch — disposable once the take is in the README
  • docs: the banner set closes — three V2 cards join, the head slot waits for the recording
  • docs: the README runs on the final banner set — three concept cards in, seven stale captures out
  • docs: Memnoc walks the four visual spots and accepts — V2 is shipped
  • docs: the first harden walk — all 26 stories pass, open code parked for /next
  • docs: ticket 13 records its residuals — the batch closes with nothing unstated
  • feat: the serve surface keeps HTTP's word — HEAD mirrors GET, garbage draws 400, accept errors pause
  • fix: bare callees walk the caller's namespace outward — twice finds nsq again
  • feat: c++ namespaced symbols wear their qualified name — geo::nsq resolves
  • fix: the files tab remembers — its state moves to the component that owns the tabs
  • docs: the twoviews banner joins the re-export debt, dated — not silent
  • fix: the tally never says structural twice — the grouping segment reads Layer
  • feat: a bounded request read — one deadline, two caps, three refusals
  • docs: ticket 07 records the old-binary drop — the no-bump edge, stated
  • feat: region prose is bought once — the description rides the name's hash
  • docs: the Provenance entry stops overclaiming what the dashboard badges
  • feat: a layer says what it is — description published, badged per part
  • feat: the conversation docks beside the map — a column, not a band
  • test: the security document may name no route the registry dropped — stale is the other drift
  • feat: the handler walks a registry — SECURITY.md must name every route
  • docs: story 26 — the conversation moves beside the map it describes
  • feat: the answer panel is a thread, and every exchange says what it spent
  • docs: ticket 08 records its two accepted residuals — stated, not silent
  • feat: the ask route carries a conversation — clamped, citations-first, stateless
  • docs: ticket 10 inherits magnify's imports-only caveat from the 16 review
  • feat: magnify draws the neighbourhood — a lens, and the way back is free
  • docs: the curve knob existed after all — measured, rejected, proofs on record
  • feat: a fan rather than a knot — every edge lands at its own point
  • fix: the grouping switch lets go — no selection outlives its reveal
  • feat: nothing points at a hidden file — the pointer reveals its region first
  • fix: the tie-break becomes the producer's — one comparator, one order
  • docs: magnify joins the lap — stories 24 and 25, and the ticket that draws them
  • feat: the drill view opens readable — forty cards, the rest one gesture away
  • docs: ticket 03 absorbs the third consumer — the rankings
  • docs: the repository states its terms — MIT, and a Status that is true again
  • feat: the map says which files matter — significance, published once
  • test: the share artifact gets a ceiling — two megabytes, or a decision
  • docs: V2 cut into fifteen tickets — blockers first, the frontier wide
  • docs: the V2 spec lands — 23 stories, six groups, no new seams
  • docs: the V2 interview closes — three ADRs signed, the glossary is born
  • docs: quick start gains the optional aliases, provider flag welded in
  • docs: the nameplate leads, the plumbing sinks, and thanks are given
  • docs: the README shows the product — twelve banner pairs, two held
  • fix: region edges count nouns — 1 import, 2 imports, never importss
  • docs: the /next harvest — V2 agenda at docs/intake/2026-08-12-codeatlas-v1-next.md
  • docs: every story passes — V1 is shipped
  • fix: the walkthrough card paints above the canvas it explains
  • docs: the sixth harden walk — 23 stories, zero failures, two unverifiable
  • docs: the FILES tab joins the browser walk, and its magic number goes
  • fix: the filter/search division was defended by a test that could not fail
  • feat: the files tab folds its regions and filters what is left
  • docs: the browser walk, and ticket 44 for the unfiled serve hint
  • docs: stories 22 and 23, so /harden can walk what already shipped
  • chore: close tickets 40 and 42, and record how 40 was nearly closed falsely
  • feat: --dry-run, and tests that assert what the binary prints (ticket 40)
  • fix: the range assertion accepted a collapsed prompt figure
  • feat: enrichment says what it will cost, and how far it has got (ticket 40)
  • feat: a failed enrichment says how much of it survived
  • feat: enrichment keeps what it paid for, and buys it four at a time (ticket 42)
  • feat: commit the enriched annotations for this repository
  • chore: fold the cost estimate into ticket 40
  • chore: file tickets 42 and 43 on what enrichment costs
  • chore: file tickets 40 and 41, both open
  • feat: plain serve says how to turn questions on
  • feat: the frame folds away and gives its space to the map (ticket 39)
  • fix: the walkthrough card measures itself instead of guessing
  • fix: the walkthrough card stays on screen at the right edge
  • fix: crosscheck amendment for ticket 37
  • fix: crosscheck amendment for ticket 35
  • chore: file ticket 38, deferred — a header block that never ends
  • feat: a Go package qualifier reaches the package, not one file (ticket 37)
  • fix: every response reaches the client that asked for it (ticket 35)
  • chore: defer ticket 36 past V1
  • fix: crosscheck amendment for ticket 26
  • fix: crosscheck amendment for ticket 33
  • feat: a walkthrough of the interface, not of the codebase (ticket 26)
  • test: story 2's convention checklist becomes a fixture table (ticket 33)
  • fix: crosscheck amendment for ticket 30
  • feat: enrichment arrives with the repository (ticket 30)
  • chore: file ticket 36 — the serve surface and the document that describes it
  • fix: one model call per question, and a serve surface the docs describe (ticket 27)
  • feat: ask the codebase a question from the search bar (ticket 27)
  • chore: file ticket 35 — a refusal the client sometimes never receives
  • fix: correct the claims that describe the three configurations (ticket 32)
  • feat: three build configurations, and the claims that describe them (ticket 32)
  • chore: unblock tickets 27 and 32 now that 34 has landed
  • feat: the serving binary answers questions about the map (ticket 34)
  • feat: enrich through an authenticated Claude CLI (ticket 31)
  • feat: provider selection gets a flag, not just an env var (ticket 29)
  • chore: file tickets 29-34 and split ticket 27
  • docs: amend the V1 spec for LLM access — stories 18-21, story 2 rewritten
  • docs: record ADRs 0007-0009 for LLM access and credentials
  • feat: say what export is for, and name the share route (ticket 28)
  • fix: close the Escape dead zone and drop two invented colours (crosscheck)
  • feat: dismiss the search overlay, a way back, gold connections, "classes"
  • docs: file tickets 22-27 from a round of dashboard use
  • fix: resolve qualified calls through the module that holds them (ticket 21)
  • feat: caption the cards, name the focused edges, narrate the panel
  • docs: harden fifth walk — 16/17, story 2 fails on calls, file ticket 21
  • feat: rework the dashboard around regions, insights and a readable canvas
  • fix: build the embedded dashboard with NODE_ENV=production
  • fix: resolve from pkg import module to the module (ticket 20)
  • docs: harden fourth walk — 16/17, story 2 fails on Python, file ticket 20
  • test: stop the egress suite sharing dist, and make it unable to pass vacuously (ticket 19)
  • fix: resolve Rust crate-name import paths (ticket 18)
  • docs: capture the dashboard UI reference
  • docs: file ticket 19 — the egress suite shares dist with the build
  • feat: Rosé Pine Dawn and Moon themes with a header toggle
  • docs: harden third walk — 16/17, story 2 fails, V1 not shipped
  • docs: file ticket 18 — Rust crate-name path resolution
  • fix: resolve TypeScript NodeNext import specifiers (ticket 17)
  • docs: file ticket 17 — TypeScript NodeNext import specifiers
  • docs: harden re-walk — all 17 stories pass after ticket 16
  • feat: surface flows and the guided tour, bounded and curated (ticket 16)
  • docs: harden verification — 16/17 stories pass, file ticket 16
  • docs: add README
  • docs: note the dev-dependency trap in the sealed tree probe
  • feat: sealed build, egress suite, dual-config CI (ticket 15)
  • feat: share artifact with allowlist redaction (ticket 14)
  • feat: enrich layers, flows, and tour narration (ticket 13)
  • fix: enrichment egress cannot follow redirects or env proxies (ticket 12)
  • feat: Claude API provider behind the network feature (ticket 12)
  • fix: renames report full blast radius in diff overlay (ticket 10)
  • feat: diff impact overlay (ticket 10)
  • feat: codeatlas serve — embedded dashboard over loopback (ticket 09)
  • feat: enrichment core — provider trait, carry-over annotations (ticket 11)
  • feat: C and C++ extraction (ticket 05)
  • feat: remaining scripted languages — Rust, Python, Go, Markdown (ticket 04)
  • feat: dashboard renders a map (ticket 08)
  • feat: mechanical semantics — layers, flows, tour order (ticket 06)
  • feat: published map contract + drift CI (ticket 07)
  • feat: import and call edges (ticket 03)
  • feat: parser interface + TS/JS extraction (ticket 02)
  • feat: walking skeleton — codeatlas scan emits a schema-valid map (ticket 01)
  • tickets: break the V1 spec into 15 tracer-bullet slices
  • docs: record the V1 decision trail — intake, research, ADRs 0001-0006, spec
  • Add Northstar conventions map

What needs no key, and what needs Claude

scan, serve, diff and share need no key and no account: they never
open a non-loopback socket, and the dashboard is compiled in, so the one
downloaded file is the whole install. serve --open-code, which lets the
dashboard show a mapped file's source, is the same kind of thing — it
changes what your own browser can be told, never what leaves the host.

Two flags reach a model, and only these two: scan --enrich, which buys
prose for the map, and serve --ask, which answers questions about it.
Both need Claude, in one of two ways: your own API key
(--provider claudeANTHROPIC_API_KEY or an ant auth login
profile, billed per token to that account), or the Claude CLI you are
already logged into (--provider cli:claude — drawing on that
subscription's allowance; CodeAtlas never handles the credential). What a
model receives on each path is bounded and documented in
docs/SECURITY.md, and it never includes your file contents. Without a
provider you still get the complete structural map — enrichment relabels
what the scan found, it never creates it.

The -sealed binary beside each default one is the build where this
section is enforced by the compiler: built --no-default-features, it
contains neither path to a model, every no-key command above works, and
--enrich and --ask refuse with a message saying the build has no
backend. It is the binary to hand a security review.

Artifacts

  • codeatlas-v0.1.0-aarch64-apple-darwin — 17090992 bytes
  • codeatlas-v0.1.0-aarch64-apple-darwin-sealed — 14715744 bytes
  • codeatlas-v0.1.0-aarch64-unknown-linux-musl — 18011736 bytes
  • codeatlas-v0.1.0-aarch64-unknown-linux-musl-sealed — 15313200 bytes
  • codeatlas-v0.1.0-checksums.txt — 880 bytes
  • codeatlas-v0.1.0-x86_64-apple-darwin — 17470408 bytes
  • codeatlas-v0.1.0-x86_64-apple-darwin-sealed — 14921300 bytes
  • codeatlas-v0.1.0-x86_64-unknown-linux-musl — 18677088 bytes
  • codeatlas-v0.1.0-x86_64-unknown-linux-musl-sealed — 15814392 bytes

Verify what you downloaded

Every artifact is listed in codeatlas-v0.1.0-checksums.txt; check the one you took:

sha256sum --check --ignore-missing codeatlas-v0.1.0-checksums.txt       # Linux
shasum -a 256 --check --ignore-missing codeatlas-v0.1.0-checksums.txt   # macOS

Every artifact carries a GitHub build-provenance attestation tying it to
the exact workflow run and commit that built it:

gh attestation verify codeatlas-v0.1.0-<target> --repo Memnoc/CodeAtlas

On macOS: these binaries are not Apple-signed or notarized, so a
browser-downloaded copy arrives quarantined and Gatekeeper refuses its
first run. Verify it with the two commands above, then clear the mark —
xattr -d com.apple.quarantine <the file> — or allow it under System
Settings → Privacy & Security. A curl download never receives the
quarantine mark.

How this software was built

CodeAtlas is built AI-assisted, under the Northstar engineering pipeline:
every change arrives as a spec'd, ticketed slice, is built test-first, and
is cross-checked against the spec and the house standards before it lands.
The decisions are a human's, recorded as ADRs in docs/adr/. The same
disclosure runs through the artifact: prose a model wrote inside a map
always says so — the annotation store carries one record naming the
provider, the model and the UTC date of the last run that wrote it, and
prose bought by earlier runs rides beneath that latest record; the
dashboard badges enriched prose where it renders it, and share redacts
it from the exported file. The security posture — what can reach a model,
what it receives, and the committed test behind each claim — is
docs/SECURITY.md.

Transparency

CodeAtlas's AI is strictly bring-your-own: --ask and enrichment call
Anthropic's Claude with credentials you supply, and nothing else in the
tool talks to a model — the sealed build cannot even be compiled to.
Wherever AI-written prose appears it says so: the dashboard badges
enriched text where it renders it, the annotation store carries a
machine-readable record naming the provider, the model and the UTC date
of the last run that wrote it, and share removes AI prose from the
exported file entirely. Interaction with the model is always labelled as
interaction with the model. This is stated as practice, verified by the
tests docs/SECURITY.md names — not as a reading of where any law's
lines fall — so a reader never has to guess which words a model wrote.