Release v0.5.0: OKF Registry, Dependency Locking & Multi-Scope Vendor Layering
Release v0.5.0 introduces native package management and multi-scope knowledge layering to the OKF ecosystem. With the launch of the official OKF Registry (https://registry.okf-memory.dev), agents and developers can now distribute, pull, lock, and compose external knowledge bundles alongside local project memory with deterministic precedence, cryptographic verification, and hermetic cross-scope linking.
1. OKF Registry Integration & Package Resolution
- Decentralized Registry Client (
pkg/registry):- Connects to the canonical registry at
https://registry.okf-memory.devwith support for private mirrors via--registry <url>andOKF_REGISTRY_URL. - Supports both scoped (
@org/bundle) and top-level (bundle) package slugs. - Resolves explicit semantic versions (
@1.2.0,@v1.2.0), tags (@latest), and direct Git repository archives (github.com/org/repo@vX.Y.Z). - Warns when pulling floating branch targets, encouraging immutable version tags.
- Connects to the canonical registry at
- On-the-Fly Archive Extraction & Knowledge Promotion:
- Automatically flattens root container directories in GitHub release archives.
- Stream-filters and promotes standard
knowledge/directories from DMAA repositories directly into.okf/vendor/<bundle-id>/without disk churn or repository root pollution.
- Cryptographic Integrity & Rollback Failsafe:
- Verifies downloaded archives against SHA-256 integrity checksums.
- Executes immediate post-install validation (
okf validate); any validation failure or broken graph triggers an automatic, clean rollback.
2. Zero-Dependency Lockfile (okf.lock)
- Standardized
okf.lockSpecification (pkg/lock):- Deterministically tracks installed vendor packages, source URLs, pinned versions, SHA-256 checksums, and installation timestamps.
- Pure Go implementation with zero external dependencies, adhering strictly to the repository's zero-dependency invariant.
- Deterministic Restoration:
okf restore: Re-installs and validates all declared dependencies fromokf.lockin fresh environments and CI/CD pipelines.
3. Package Management Subcommands (internal/cli)
okf pull [<bundle-id|git-url>]:- Installs a dependency, verifies it, writes
.okf/vendor/<bundle-id>/, and records it inokf.lock. - When called without arguments, seamlessly falls back to restoring all locked bundles.
- Installs a dependency, verifies it, writes
okf restore:- Restores all dependencies declared in
okf.lockwith optional--forcereinstallation.
- Restores all dependencies declared in
okf vendor:okf vendor list: Displays installed vendor bundles, versions, and paths.okf vendor remove <bundle-id>: Cleans the bundle directory from.okf/vendor/, safely handles namespace parent directories, and prunesokf.lock.
4. Multi-Scope Composite BM25 Indexing & Cross-Scope Linking (Closes #11)
- Multi-Scope Priority Layering (
pkg/okf/scope.go):- Establishes a 4-tier scope hierarchy:
project(priority 100),vendor(priority 70),user(priority 50), andsystem(priority 10). - Enforces local shadowing: local project concepts in
knowledge/override vendor concepts with identical IDs, which in turn shadow user and system concepts.
- Establishes a 4-tier scope hierarchy:
- Scope Specification Matrix:
| Scope | Link / Reference Syntax | Canonical URN | Storage Location | Priority | Precedence & Behavior |
|---|---|---|---|---|---|
project |
decisions/routing.md |
(bundle relative) | ./knowledge/ |
100 | Authoritative local project memory. Strictly shadows identical IDs across vendor, user, and system layers. |
vendor |
@nextjs-15/routing.md@peter/django-rules/auth.md |
okf://@nextjs-15/routingokf://@peter/django-rules/auth |
.okf/vendor/<bundle>/ |
70 | External packages pulled via okf pull. Strictly shadows user and system layers. |
user |
user:guidelines/style.md |
okf://user/guidelines/style |
~/.okf/ |
50 | Personal developer preferences and cross-project notes. Strictly shadows system layer. |
system |
system:corp/policies.md |
okf://system/corp/policies |
/etc/okf/ |
10 | Machine-level and enterprise compliance standards. |
- Layer-Filtered Search (
--scope):okf searchsupports--scope <all|project|bundle|vendor|user|system>(default:all).- Cross-scope searches normalize BM25 scores while ranking strictly by layer priority.
- Hermetic Cross-Scope Linking:
- Vendor references use clean package identifiers:
@<bundle-id>/<concept-id>.md(e.g.@peter/django-5-rules/decisions/auth.mdor@nextjs-15/decisions/routing.md). - User and System references use collision-free URN shorthands:
user:<concept-id>.mdandsystem:<concept-id>.md. - Strict boundary disambiguation: identifiers with leading
@resolve into.okf/vendor/, while references without@strictly search the local project bundle (knowledge/). - Bundle validation (
okf validate --strict) recognizes all external references (@,user:,system:,okf://,https://) without emitting broken links or orphan false-positives, guaranteeing 0 broken links in standalone CI.
- Vendor references use clean package identifiers:
Community & Special Thanks
- Ritsu Kuroda (@kurodaritsu): For initiating the multi-scope bundle memory proposal (#11) and detailed analysis of multi-bundle IDF ranking dynamics.
- MemContinuum & OKF Community: Invaluable architectural discussions regarding multi-scope memory layering, dependency composition, and epistemic boundaries.
Pre-Built Binaries
Pre-compiled standalone binaries for macOS, Linux, and Windows are available in the release assets on GitHub:
- macOS (
darwin/arm64,darwin/amd64) - Linux (
linux/amd64,linux/arm64) - Windows (
windows/amd64,windows/arm64)
Full Changelog
See commits between v0.4.4...v0.5.0 on GitHub.