Repository navigation
v20.0.0 — streaming attachments and lifecycle correctness
V20 restores supported node and edge byte attachments: stream content into storage, attach/replace/clear through admitted intents, and stream current or captured historical content through observers. Ordered intent arrays publish atomically as one patch and receipt. Allocation/admission bounds and test, storage, and release tooling are hardened.
Upgrade from v19.1.0
This is a major interpretation change. Node removals clear earlier properties even when concurrent membership keeps a node alive; edge properties also respect their retained removal boundary. Affected node-state hashes and observer diffs can change. Authoritative patch history is retained.
Stop and upgrade readers and writers together, keep an independent verified backup and interpreter-qualified historical receipts, rebuild derived checkpoints from retained patches, and verify the workload before resuming traffic. Old clients are not automatically fenced. The separate retained-v18 migrator is not required merely to upgrade an already-v19.1.0 repository.
Capability boundaries
Staging writes bytes to storage but does not create a graph causal event; the attachment write publishes the association. Each node or edge has one current attachment association. Staging alone does not guarantee retention. Git synchronization requires the relevant WARP refs; unconfigured push/pull is not a blanket synchronization guarantee.
This release does not implement production recursive graph ownership, typed graph attachment references, cross-graph traversal/retention, safe general tombstone retirement, or a constant bound on total graph metadata. Those remaining capabilities retain their explicit roadmap issues. The Entity surface remains an unofficial, unstable preview. Node >=22 remains the supported Node floor.
Release evidence and retrospective
Public registry closure verified in release workflow37148457531. npm accepted publication before public processing completed; only the failed visibility/consumer verification job was rerun. Both registries and the exact installed npm consumer are verified.
Registry publish summary
- npm:
published - JSR:
published
Dist-tag: latest
Version: 20.0.0
If one registry failed, re-run only that job from Actions.
What's Changed
- Restore atomic intent-array writes by @flyingrobots in #872
- Enforce the npm package payload boundary by @flyingrobots in #874
- Expose basis-bound entity admission inventories by @flyingrobots in #875
- Report stalled concurrent occurrence lifecycle stages by @flyingrobots in #879
- Cover the op strategy dispatch table by @flyingrobots in #881
- Stream exact-tree path scans with bounded memory by @flyingrobots in #846
- fix(storage): complete idle Git session shutdown by @flyingrobots in #880
- Verify published releases against public registries by @flyingrobots in #877
- Shrink npm payload and report bundle health in release preflight by @flyingrobots in #898
- docs(security): correct the dependency table and flag expired risk acceptances by @flyingrobots in #892
- Fix: stop a stable tag claiming latest just for being stable by @flyingrobots in #890
- Fix: integrate safe property reclamation and malformed-key handling by @flyingrobots in #889
- Fix: safely reclaim permanently stale property registers in GC by @flyingrobots in #883
- Make removed and re-added nodes and edges converge on every replica by recording their adds and removes by @flyingrobots in #893
- Fix: reclaim node properties with a monotone LWW clear by @flyingrobots in #910
- docs: define capability plans for seven release milestones by @flyingrobots in #920
- Enforce Docker isolation for tests and benchmarks by @flyingrobots in #915
- Fix: keep developer hooks relative to each worktree by @flyingrobots in #914
- Fix: adopt published CAS recovery for attachment GC by @flyingrobots in #925
- Fix: stream-only attachments and bounded byte collection by @flyingrobots in #926
- Restore public node and edge content attachments by @flyingrobots in #927
- test: require installed-package public attachment consumers by @flyingrobots in #929
- fix(api): reject oversized atomic descriptors before encoding (#916) by @flyingrobots in #931
- fix(crdt): retain removal evidence during low-level compaction (#911) by @flyingrobots in #930
- Integrate v20 attachment safety and consumer acceptance stack by @flyingrobots in #928
- Document the supported byte attachment lifecycle and migration (#904) by @flyingrobots in #938
- Define structural ownership and document supported attachments (#903, #904) by @flyingrobots in #932
- Honor checkpoint tombstones in bounded node liveness (#894) by @flyingrobots in #935
- Fix VersionVector constructor validation and ownership (#205) by @flyingrobots in #942
- test(cli): prove session-event retention across authority paths by @flyingrobots in #944
- Bound Mermaid render, browser shutdown, and owned process reclamation (#870) by @flyingrobots in #937
- fix(crdt): validate constructors and preserve checkpoint identities (#189) by @flyingrobots in #949
- fix(bun): enforce the reviewed npm dependency graph by @flyingrobots in #941
- Align neighbor-provider contract with backend label semantics (#913) by @flyingrobots in #933
- docs: make installation and contributor setup explicit (#125) by @flyingrobots in #940
- fix: batch bounded precommit guard readings (#706) by @flyingrobots in #947
- Fix: retire unsupported Node20 test matrix route (#951) by @flyingrobots in #952
- test: smoke-test the packed public package under Deno (#118) by @flyingrobots in #946
- Register unavailable checkpoint basis failure cause (#895) by @flyingrobots in #934
- Fix public-registry consumer Docker isolation (#922) by @flyingrobots in #945
- Execute legacy upgrade through symlink entry paths (#900) by @flyingrobots in #936
- fix: isolate in-memory adapter hashing capabilities (#221) by @flyingrobots in #943
- fix: replace vulnerable declaration patch tooling by @flyingrobots in #950
- fix: bound coverage workers and refuse incomplete ratchet writes by @flyingrobots in #939
- Release v20.0.0: memory safety and public attachments by @flyingrobots in #953
Full Changelog: v19.1.0...v20.0.0