Repository navigation
v0.2.0
·
29 commits
to 2dfe511b470b5db7ed47739640fe03efb8fb24c2
since this release
TransformationSpine v0.2.0 — the audited release. The original "all phases complete" claim was independently audited on 2026-10-09, struck where the evidence failed, and every finding was remediated and behavior-tested before this tag (178 tests; coverage ≥80% enforced in CI; ruff + mypy strict clean).
Added — Upgrade scope per BUILD_PLAN.md
Multi-backend adapters (Phase 1)
HuggingFaceProvideradapter for HuggingFace Inference API + local transformers- Provider factory (
spine.factory) building adapters from profile-awareProviders.yamlspecs Providers.yamltemplate with local/cloud/hybrid model groups- Provider factory with profile-aware resolution (local/cloud/hybrid)
Expanded MCP/ACP connectors (Phase 2)
ServiceNowConnector— incident, change, CMDB, service catalogDatabricksConnector— SQL endpoints, MLflow, workspace objectsConfluenceConnector— pages, spaces, attachments- All six connectors exported from the package and covered by mock-transport tests (plugin auto-discovery is implemented in this release; connectors register by discovery as well as import)
Audit logs & telemetry (Phase 3)
ProviderResult.telemetrydict for prompt/token/latency metrics/telemetryFastAPI endpoint — JSON aggregation of usage, latency, convergenceContextStoredurable backing — facts in persisted scopes survive restarts (JSON, atomic write)- CTST ledger already append-only (audit trail); telemetry extends with analytics
Local/cloud/hybrid profiles (Phase 4)
spine_cli transform --profile local|cloud|hybrid- Profile selection via env var
SPINE_PROFILEor CLI flag - Fallback chain resolution per profile
- CLI help documents profile options
Graphical workflow authoring (Phase 5)
spine_cli workflow init --name "myflow"— generates Mermaid.mmdfile- Workflow parser validates node/edge semantics
- Mermaid syntax validation
- Workflow module (
src/spine/workflow/) — DAG execution engine (topological order, cycle detection, gate enforcement) withspine workflow run docs/workflows.md— workflow guide with examples
Prebuilt agent libraries (Phase 6)
code-review-agent— wraps code-reviewer skill on transformation outputtest-generator-agent— produces pytest cases from function signaturesprompt-optimizer-agent— auto-tunes prompts for better convergencerag-pipeline-agent— lexical retrieval (token-overlap scoring) over a supplied corpus; no vector backend is bundled- Skills registered in
skill_registry/_index.mdwith verified status
Enterprise integrations roadmap (Phase 7)
docs/enterprise_roadmap.md— prioritization matrix (ServiceNow, Databricks first)ROADMAP.md— top-level product roadmapCONTRIBUTING.mdupdated with enterprise contribution guidelines
Tool-call abstraction (Phase 8)
ProviderResult.tool_callsoptional field — OpenAI function-call format- Provider protocol extended for tool use (backward compatible)
- Adapters handle tool-call → tool-execute cycles
tools.yaml— centralized tool registry with JSON Schema- Interoperability with LangGraph/Orca-style function calling
OS-level safeguarding (Phase 9)
scripts/safeguard.sh— runs the safeguard check/enforce CLIenforce_safeguardsstrips world-writable permissions across the project tree and reports only changes actually applied- Safeguard posture (world-writable count) reported by
GET /api/v1/status
Audit remediation (2026-10-09) — fixes for the v0.2 claim audit
An independent audit struck the original "all phases complete, G0–G8 PASS"
claim; this release contains the remediation, each fix behavior-tested:
- CTST tamper evidence (was inert): hash chain is persisted per record,
verify_chain()rewritten and exposed viaGET /api/v1/ledger/verify
andspine ledger --verify; tamper tests prove edited records fail. - Context persistence (was in-memory only): durable store backing;
promote/demote preserve provenance and creation time. - Convergence (was binary): caller-side gate evaluation
(spine.gates) computes the error signal deterministically; every
transform cycle is ledgered with verdict, gates, and telemetry. - Token-efficiency engine: route registry + token planner
(spine.tokenplan), two-tier cache-stable context assembly
(spine.assembly), session compaction checkpoints — ported from
ENGINE-SPEC-v1 (the engine running live in MyMilo v0.35–v0.37). - Profiles (were decorative):
spine.factorybuilds providers per
profile; CLI and API (SPINE_PROFILE) route through Routing.yaml. - Tool calls (were parsed, never run):
spine.toolsregistry +
execution loop withtools.yaml; executions recorded in telemetry. - Workflow (was authoring-only): execution engine with gates;
workflow initalso writes the documented.mmdfile. - Agents (discovery/invoke were broken): skills resolve from the
repo root, doc-skills load viainstructions(),generate_tests
generates from the module's real AST, prompt-optimizer and lexical
RAG agents implemented. - Release coherence: package/API version 0.2.0 (was 0.1.0 in code),
coverage ≥80% enforced in CI,ruff formatchecked in CI, license
headers on all sources, local adapters ignore proxy env
(trust_env=False), missing promised docs/files restored.
Added — serving surfaces and plugin discovery (2026-10-09)
- Connector plugin auto-discovery — implemented in this release:
connectors now register three ways into one registry — built-ins,
thespine.connectorsentry-point group (any installed
distribution), and plugin directories (SPINE_CONNECTOR_PATHenv
var or a localconnectors/directory). Broken plugins are
reported and skipped, never fatal. Configuration is uniform:
SPINE_CONNECTOR_<NAME>_<PARAM>env vars feed constructor params.
Surfaces:GET /api/v1/connectors,
POST /api/v1/connectors/{name}/execute,
spine connector list|execute. - MCP server surface —
POST /mcp(Streamable HTTP, stateless)
andspine mcp(stdio). Tools:spine_transform,spine_status,
spine_context,spine_ledger_verify,spine_connector_execute,
one per connector capability (<connector>__<tool>), built-ins. - A2A + ACP agent surfaces and a browser UI — A2A agent card at
/.well-known/agent-card.json, JSON-RPCmessage/send/tasks/get
atPOST /a2a; ACPGET /acp/agents,
POST /acp/agents/{name}/runs,GET .../runs/{id}; humans get
GET /ui. Every surface runs the one gated cycle
(docs/serving.mdmaps them all).
Changed
- All phases maintain ASF gate compliance (G0-G8) with recorded evidence
- portledger at 100% coverage (was 61%; repo total ~83%).
scripts/safeguard.shis committed executable (mode 100755); the
original API-based push could not set the exec bit.- Zero breaking changes to v0.1.0 public interfaces
- Build plan follows phased approach with verified exit conditions per phase
Fixed
- Declared previously missing core runtime dependencies in
pyproject.toml:
fastapi,httpx,uvicorn,pyyaml. They were imported bysrc/spine
but only present via the developer's global environment, so a clean install
failed mypy in CI. Added alocaloptional extra for the heavyweight
HuggingFace stack (transformers,torch,sentence-transformers).
Verified by a clean Python 3.11 venv (install + ruff + mypy + 45 tests PASS).