Skip to content

Forgevena v1.4.0 Implementation Status

Decision

The software-controlled implementation of the v1.4.0 Production Provider Platform is complete at the merge checkpoint. PR #42 merged as commit 0dc68066c7c3cf9fbab8d7669e21ba96ea5b01a2 after all pull-request checks passed, and the release-candidate preparation merged as PR #44 at commit 41fe1f47fbc744425a4fe15773ca0aa12522c386. Signed v1.4.0-rc.1 is published as a prerelease. It is not a stable release; promotion remains on HOLD until credential-gated live-provider evidence and the remaining clean-install/rehearsal matrix complete.

PR #53 subsequently merged the credential-slot and dashboard readiness changes at commit bbb56f7de055e8d60537c7117cbce9516a3b8592. RC1 predates that merge and remains immutable. RC2 preparation is in progress; no RC2 tag or publication exists until the version-bump change is reviewed, merged, and release validation succeeds.

Implemented

Area Result Evidence
Provider domain Shared ProviderService, ProviderRegistry, ProviderAdapter v1, and invocation coordination src/provider-service.js, src/provider-registry.js, src/provider-adapter.js, src/invocation-coordinator.js
Stable provider scope OpenAI, Anthropic through the public claude ID, Gemini, OpenRouter, and Ollama src/provider-runtime.js, providers/compatibility-evidence.json
Compatibility hosts Codex, Cursor, and Windsurf remain compatibility-only agent hosts src/providers.js, provider documentation
Invocation safety One deadline, cancellation, bounded retries, Retry-After, full jitter, idempotency, budgets, and explicit fallback src/invocation-coordinator.js, provider resilience tests
Streaming Ordered normalized events and malformed-stream rejection Provider stream fixtures and contract tests
Registry migration Preview, backup, transform, validation, atomic commit, and rollback src/provider-registry.js, migration tests
Privacy Restricted content and credentials are recursively excluded from logs, errors, diagnostics, registries, and evidence Privacy review and adversarial redaction tests
Interfaces Existing provider CLI and dashboard use shared domain services with structured envelopes CLI and dashboard tests
Governance RFC, ADR, threat model, privacy review, traceability, Tier-3 scorecard, and retained merge evidence docs/evidence/changes/v1.4.0-provider-platform/

Latest Verification

Gate Result
Node tests 362 passed locally and in hosted CI
Overall line coverage 95.88%
Overall branch coverage 85.52%
Overall function coverage 92.03%
Mutation gate 100%
Tier-3 merge readiness 100/100, no blockers
Package clean install Published RC installed in an isolated Windows npm prefix
Standalone binaries Hosted Windows, Ubuntu, and macOS builds passed; published Windows and Ubuntu artifacts smoke-tested
Docker non-root CLI Local Node 22 container version, read-only doctor, and mounted-workspace dry run passed
RC distribution GitHub prerelease assets, npm next, GitHub Packages, and GHCR 1.4.0-rc.1 published
Documentation and governance Documentation CI, Mermaid, links, and strict build passed

The exact local release-candidate commands, observed safety behavior, and remaining boundaries are retained in v1.4.0-rc.1 local smoke validation.

Exact Remaining Boundaries

  1. Credential-gated, consent-gated live smoke tests for supported hosted providers; Ollama requires an explicitly available local endpoint.
  2. Clean artifact-install, upgrade, rollback, offline, cancellation, and uninstall rehearsals on macOS and Linux. Windows and Ubuntu standalone smoke evidence, deterministic migration/rollback, Docker, and hosted platform coverage are already retained.
  3. Dated compatibility evidence with provider and model/server versions, expiry, limitations, and sanitized results.
  4. Stable v1.4.0 tag, final documentation deployment verification, and post-release installation, health, rollback, and channel verification.

No private credential, billing action, live request, tag, package publication, or deployment is performed by local deterministic validation.