- Breaking (license): relicensed from MIT to Apache-2.0, along with the rest of
the repository in Caveman 3.0.0. Releases before this one keep the MIT license. - Breaking (package): renamed
@caveman/contracts→@caveman-ai/contracts.
package.jsonhad stayed at 1.0.0 after the 1.1.0 entry below; this release
realigns them. - Breaking (schema IDs): every
$idis now
https://raw.githubusercontent.com/JuliusBrussee/caveman/contracts-v2.0.0/packages/shared/contracts/schemas/<file>,
pinned to this release's immutable tag (previouslyhttps://caveman.so/schemas/…
andhttps://caveman.cloud/schemas/…, which did not resolve). Every
cross-schema$refis relative (middleware-common.schema.json#/$defs/token),
so tools that load the schemas or the OpenAPI document from the package
directory resolve them locally, with no network access. Each release moves
the tag in every$id;scripts/validate-schemas.mjsfails when an$id
does not embed thepackage.jsonversion or a$refis absolute. No wire
shape changed because of this. - Middleware protocol 1.1 (additive;
schema_versionstays 1), specified in
docs/technical/middleware-protocol.md:middleware-capabilities: optionalprotocol {min,max},features,
max_retention_seconds; optionallimitskeysretrieve_deadline_ms,
queue_depth,retrieve_queue_depth,max_segments,
max_manifest_items,receipt_bytes,quota_requests_per_minute.
Any otherlimitskey must be a positive safe integer (protocol 1.0
clients reject anything else).- New:
middleware-error,middleware-session-delete,
middleware-session-delete-response,middleware-receipt-response,
middleware-decision-event;middleware-commongainsfeature,
reason,positive_limit. - New
openapi/middleware.openapi.json(OpenAPI 3.1) covering
capabilities,optimize,retrieve,receipts,sessions/delete. - The response schemas are closed (
additionalProperties: false) on
purpose: they describe exactly what a 1.1 server emits and are what the
conformance kit checks servers against. Clients must not validate
responses against them (spec §4, §16); each schema'sdescriptionsays so.
build/lint/testrun bothscripts/validate-schemas.mjsand
scripts/validate.mjs. The former now also checks$idagainst the file
name, the protocol 1.1 fixture examples, and every OpenAPI$ref.
Verify this release
- Registry provenance (trusted publishing from this workflow): https://www.npmjs.com/package/@caveman-ai/contracts/v/2.0.0#provenance
- CycloneDX SBOM of the published dependency graph: attached
.cdx.json - Built from annotated, GitHub-verified tag
contracts-v2.0.0onmain