Forgevena v1.4.0 Implementation Status¶
Decision¶
The software-controlled implementation of the v1.4.0 Production Provider Platform is complete at the merge checkpoint. PR #42 merged as commit 0dc68066c7c3cf9fbab8d7669e21ba96ea5b01a2 after all pull-request checks passed, and the release-candidate preparation merged as PR #44 at commit 41fe1f47fbc744425a4fe15773ca0aa12522c386. Signed v1.4.0-rc.1 is published as a prerelease. It is not a stable release; promotion remains on HOLD until credential-gated live-provider evidence and the remaining clean-install/rehearsal matrix complete.
PR #53 subsequently merged the credential-slot and dashboard readiness changes at commit bbb56f7de055e8d60537c7117cbce9516a3b8592. RC1 predates that merge and remains immutable. RC2 preparation is in progress; no RC2 tag or publication exists until the version-bump change is reviewed, merged, and release validation succeeds.
Implemented¶
| Area | Result | Evidence |
|---|---|---|
| Provider domain | Shared ProviderService, ProviderRegistry, ProviderAdapter v1, and invocation coordination | src/provider-service.js, src/provider-registry.js, src/provider-adapter.js, src/invocation-coordinator.js |
| Stable provider scope | OpenAI, Anthropic through the public claude ID, Gemini, OpenRouter, and Ollama | src/provider-runtime.js, providers/compatibility-evidence.json |
| Compatibility hosts | Codex, Cursor, and Windsurf remain compatibility-only agent hosts | src/providers.js, provider documentation |
| Invocation safety | One deadline, cancellation, bounded retries, Retry-After, full jitter, idempotency, budgets, and explicit fallback | src/invocation-coordinator.js, provider resilience tests |
| Streaming | Ordered normalized events and malformed-stream rejection | Provider stream fixtures and contract tests |
| Registry migration | Preview, backup, transform, validation, atomic commit, and rollback | src/provider-registry.js, migration tests |
| Privacy | Restricted content and credentials are recursively excluded from logs, errors, diagnostics, registries, and evidence | Privacy review and adversarial redaction tests |
| Interfaces | Existing provider CLI and dashboard use shared domain services with structured envelopes | CLI and dashboard tests |
| Governance | RFC, ADR, threat model, privacy review, traceability, Tier-3 scorecard, and retained merge evidence | docs/evidence/changes/v1.4.0-provider-platform/ |
Latest Verification¶
| Gate | Result |
|---|---|
| Node tests | 362 passed locally and in hosted CI |
| Overall line coverage | 95.88% |
| Overall branch coverage | 85.52% |
| Overall function coverage | 92.03% |
| Mutation gate | 100% |
| Tier-3 merge readiness | 100/100, no blockers |
| Package clean install | Published RC installed in an isolated Windows npm prefix |
| Standalone binaries | Hosted Windows, Ubuntu, and macOS builds passed; published Windows and Ubuntu artifacts smoke-tested |
| Docker non-root CLI | Local Node 22 container version, read-only doctor, and mounted-workspace dry run passed |
| RC distribution | GitHub prerelease assets, npm next, GitHub Packages, and GHCR 1.4.0-rc.1 published |
| Documentation and governance | Documentation CI, Mermaid, links, and strict build passed |
The exact local release-candidate commands, observed safety behavior, and remaining boundaries are retained in v1.4.0-rc.1 local smoke validation.
Exact Remaining Boundaries¶
- Credential-gated, consent-gated live smoke tests for supported hosted providers; Ollama requires an explicitly available local endpoint.
- Clean artifact-install, upgrade, rollback, offline, cancellation, and uninstall rehearsals on macOS and Linux. Windows and Ubuntu standalone smoke evidence, deterministic migration/rollback, Docker, and hosted platform coverage are already retained.
- Dated compatibility evidence with provider and model/server versions, expiry, limitations, and sanitized results.
- Stable
v1.4.0tag, final documentation deployment verification, and post-release installation, health, rollback, and channel verification.
No private credential, billing action, live request, tag, package publication, or deployment is performed by local deterministic validation.