TopicForge 0.5.3
Fixes from an independent review of the whole repository, including a supply-chain issue. Upgrade recommended.
Security
- Extras depended on package names that do not exist on PyPI.
fastdds(in[dds],[dds-fast],[all],[dds-all-oss]) anddust-dds-python(in[dds-dust]) are not registered, so the documentedpip install topicforge[dds]failed, and anyone could have published those names to run code on install. Only extras whose packages exist remain:[dds-cyclone],[dds](Cyclone only),[bags],[all]. Versions 0.3.0 to 0.5.2 are affected and have been yanked from PyPI. - Removed the automatic
topicforge_proplugin hook, which imported any package by that (unclaimed) name at startup and gave it the full MCP server, enough to register write tools.
Fixed
health_checknow reports the adapter actually running. It used to saylivewhile serving mock fixtures whenros2was missing.- An explicit
TOPICFORGE_DDS_BACKENDis honoured without theros2CLI instead of silently serving fixtures. autono longer picks the OpenDDS/Dust stubs, which made it lose the real Cyclone backend.- A broken DDS environment no longer crashes startup.
- Every Cyclone read is bounded (an unbounded read could hang the server on an active topic).
topic_metricsno longer counts samples that were never received.
Changed
- Payload decoding of user DDS topics is disabled. It never worked on either backend, and cannot be validated without a live bus.
peek_dds_samplesreports that a topic is present without decoding it; the three builtin discovery topics are unaffected. - Python 3.10 is supported, so ROS 2 Humble (Ubuntu 22.04) users can install it.
- Tool descriptions read by the LLM corrected;
topic_metricsstates its real limits.
Breaking
TOPICFORGE_DDS_BACKENDno longer acceptsrti,opensplice,coredx,intercom. RTI and other vendors are still observed on the bus through standard discovery.- Extras
[dds-fast],[dds-opendds],[dds-dust],[dds-all-oss]removed. Fast DDS still works once its Python binding is built from eProsima's sources.
Correction
- The 0.5.1 notes said sequence gaps are counted per writer. No adapter provides the writer identity, so that statement was wrong.
pip install --upgrade topicforge==0.5.3Full details: https://github.com/yaniswav/TopicForge/blob/main/CHANGELOG.md#053---2026-10-01