chore(release): 3.42.5 + @claude-flow/memory 3.0.0-alpha.25

Ships #3390 (#3327 Finding A). The fix spans two packages and only one of
them rides the release train, so memory is bumped and published alongside:

  - cli/src/memory/memory-bridge.ts      -> @claude-flow/cli 3.42.5 (train)
  - memory/src/controller-registry.ts    -> @claude-flow/memory 3.0.0-alpha.25

Without the memory publish the embedder half of the fix never reaches users
and reasoningBank stays inert, since @claude-flow/memory is NOT in
INTERNAL_RUNTIME_PACKAGES and resolves from the registry via ^3.0.0-alpha.23.

CLAUDE.md: correct the Publishing Rules claim that internal @claude-flow/*
components are all bundled. Only four are (security, codex, mcp,
plugin-agent-federation); cli-core, neural, shared and memory resolve from
the registry and need a standalone publish when their source changes. Adds a
semver-aware pre-tag drift check that fails loudly if it inspects zero leaves.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
This commit is contained in:
ruvnet
2026-09-21 14:52:57 -04:00
co-authored by Claude Opus 5
parent 11ce88327b
commit cf9aebf21e
5 changed files with 42 additions and 6 deletions
+38 -2
View File
@@ -967,8 +967,44 @@ memory_search_unified({ query: "authentication security", limit: 5 })
- The normal public release train is exactly THREE packages:
`@claude-flow/cli`, `claude-flow`, and `ruflo`.
- Internal `@claude-flow/*` components are bundled into the public artifacts;
do not publish them standalone as part of the normal release.
- **Exactly FOUR `@claude-flow/*` components are bundled** into the public
artifacts: `security`, `codex`, `mcp`, `plugin-agent-federation` — the list
is `INTERNAL_RUNTIME_PACKAGES` in `scripts/stage-internal-runtime-bundles.mjs`.
These are built from the tagged source and staged into the tarball's
`package/node_modules/`, so a source change in them ships with the train.
Do not publish those four standalone.
- **Every OTHER `@claude-flow/*` dependency resolves from the registry**, at the
version `v3/@claude-flow/cli/package.json` pins. A source change in one of
those does NOT ship with the train — the release silently carries the last
*published* copy of that package, not the code you just merged. It must be
bumped and published standalone in the same release or the fix reaches nobody:
| dep of `@claude-flow/cli` | bundled? | how a source change reaches users |
|---|---|---|
| `security`, `codex`, `mcp`, `plugin-agent-federation` | yes | with the train |
| `cli-core`, `neural`, `shared`, `memory` | **no** | **standalone publish required** |
`memory` is the easiest of these to miss, for three compounding reasons: it is
the only one on a caret range (`^3.0.0-alpha.23`) rather than an exact pin, so
nothing drifts visibly; `v3/pnpm-lock.yaml` resolves it from the registry
rather than `link:../memory`, so workspace CI never exercises the CLI against
workspace `memory` source; and its own package tests DO run against source, so
CI goes green on a change that cannot ship. #3390 (#3327 Finding A) is the
worked example — it fixed `memory/src/controller-registry.ts` and
`cli/src/memory/memory-bridge.ts` together, and without a standalone `memory`
publish only the `cli` half would have shipped, leaving the fix inert.
- Before tagging, check every non-bundled leaf for drift between what the CLI
pins and what the workspace source says — a mismatch means an unpublished
change is about to be skipped by the release:
```bash
# needs root deps for `semver` — run after `npm ci` at repo root
node -e 'const semver=require("semver"),c=require("./v3/@claude-flow/cli/package.json"),d={...c.dependencies,...c.optionalDependencies},b=["security","codex","mcp","plugin-agent-federation"];let n_=0;for(const[n,v]of Object.entries(d)){if(!n.startsWith("@claude-flow/"))continue;if(b.includes(n.slice(13)))continue;let w;try{w=require(`./v3/${n}/package.json`).version}catch{continue}n_++;if(!semver.satisfies(w,v,{includePrerelease:true}))console.log(`DRIFT ${n}: cli pins ${v}, workspace source ${w} — publish it or the release skips the change`)}if(!n_){console.error("checked 0 leaves — check is broken, do not trust a clean result");process.exit(1)}console.log(`checked ${n_} non-bundled leaves`)'
```
It must use `semver.satisfies`, not a string compare: `memory` is on a range,
so a literal match reports a false DRIFT on every release. It also fails loudly
at zero leaves checked — a guard that inspects nothing must not report clean.
- MUST update ALL dist-tags for ALL THREE packages after publishing (latest + alpha + v3alpha all point to the same version)
- Publish order: `@claude-flow/cli` first, then `claude-flow` (umbrella), then `ruflo` (alias umbrella)
- MUST run verification for ALL THREE before telling user publishing is complete
+1 -1
View File
@@ -1,6 +1,6 @@
{
"name": "claude-flow",
"version": "3.42.4",
"version": "3.42.5",
"workspaces": [
"v3/@claude-flow/codex",
"v3/@claude-flow/mcp",
+1 -1
View File
@@ -1,6 +1,6 @@
{
"name": "ruflo",
"version": "3.42.4",
"version": "3.42.5",
"description": "Ruflo - Enterprise AI agent orchestration platform. Deploy 60+ specialized agents in coordinated swarms with self-learning, fault-tolerant consensus, vector memory, and MCP integration",
"main": "bin/ruflo.js",
"type": "module",
+1 -1
View File
@@ -1,6 +1,6 @@
{
"name": "@claude-flow/cli",
"version": "3.42.4",
"version": "3.42.5",
"type": "module",
"description": "Ruflo CLI - Enterprise AI agent orchestration with 60+ specialized agents, swarm coordination, MCP server, self-learning hooks, and vector memory for Claude Code",
"main": "dist/src/index.js",
+1 -1
View File
@@ -1,6 +1,6 @@
{
"name": "@claude-flow/memory",
"version": "3.0.0-alpha.23",
"version": "3.0.0-alpha.25",
"type": "module",
"description": "Memory module - AgentDB unification, HNSW indexing, vector search, hybrid SQLite+AgentDB backend (ADR-009)",
"main": "dist/index.js",