Changelog¶
All notable changes to this project will be documented in this file.
The format is based on Keep a Changelog, this project adheres to Semantic Versioning, commits follow Conventional Commits, and this changelog is generated by Structured Changelog.
Unreleased¶
v0.2.0 - 2026-09-13¶
Highlights¶
- Semantic diff engine: a typed ChangeSet between two architectures with change-impact classification
- Baseline / Assessment / ChangeReview model for reviewing an architecture change against a baseline
- FedRAMP change-assessment profile: three-outcome classification with control-mapping hooks
- Container & sandbox node/boundary kinds for K8s-native and sandboxed-execution topology
- Module renamed to github.com/plexusone/systemspec-architecture
Added¶
- Semantic diff engine with a typed ChangeSet (
51c281a) - Change-impact classification for diffs (
80f3d42) - Baseline, Assessment, and ChangeReview model (
40bc2c0) - compute.container/compute.sandbox node kinds and container/sandbox boundary kinds; bridge/threatmodel.boundaryType() emits sandbox/container/breached instead of collapsing to network (
4e146ce) - FedRAMP change-assessment profile (diff/fedramp) (
92affaf)
Changed¶
- Rename Go module to github.com/plexusone/systemspec-architecture (repo rename; mechanical import-path rewrite) (
2c19dc0)
Documentation¶
- Document container/sandbox kinds in SPEC.md (kind taxonomies); update README/index status to v0.2 and add the diff and diff/fedramp packages; add v0.2.0 release notes
v0.1.0 - 2026-09-07 (728c446)¶
Highlights¶
- Initial release: a statically-typed-friendly, Go-first semantic graph model for systems architecture (Node, Relationship, Boundary, Identity, Entitlement, Extensions), with generated JSON Schema and Zod/TypeScript conforming to the same fixture corpus as the Go model
- Views as queries plus Mermaid/D2/Graphviz DOT renderers, each verified against the real d2/dot CLIs, closing the diagrams payoff (M2): SAS replaces hand-drawn diagrams for a real horizontal and vertical portfolio app
- Profile-conditional validation (development, deployment, security, threat-model, sre) including launch-readiness rules that gate internet-facing traffic before go-live
- PIDL ProtocolBinding and the Threat Model Spec bridge, both verified against the real external schemas they integrate with rather than internal assumptions about their shape, closing the launch-readiness payoff (M3) and v0.1
Added¶
- Core semantic graph types Architecture, Node, and Boundary, with a small closed NodeKind vocabulary, many-to-many boundary membership, and assurance evidence references (
a5ffa0e) - Relationship as the richest core type: transport, generic operation verbs, identity, entitlements, data classification, and boundary-crossing — the security-significant facts most diagram formats collapse into an unlabeled arrow (
625f496) - First-class Identity (type, mechanism, ref) and Entitlement (subject-action-resource) types shaped to map cleanly onto ReBAC systems without making SAS a ReBAC engine (
6b79b90) - Extensions as explicit, statically typed namespace fields (security, sre, compliance, agent) instead of a generic map, and ExternalRef for pointing at detail owned by OpenAPI, PIDL, Threat Model Spec, Multi-Agent Spec, Terraform, and OTel (
bfdac78) - JSON Schema generation from the Go model via invopop/jsonschema (lint-clean under schemakit's camelCase profile) and Zod/TypeScript types generated from that schema, proven by a shared fixture round-tripping through both Go and TypeScript. Closes Phase 1 (Core IR & Schema Pipeline) (
474052a) - View as a query over an Architecture (IncludeKinds/IncludeRelations/IncludeBoundaries) and CrossedBoundaries, which derives which boundaries a relationship crosses from its endpoints' declared membership (
1b0c448) - Profile model (development, deployment, security, threat-model, sre): optional-in-core semantics that become mandatory only for the profile that needs them (
5522a1a) - Validation rules engine: always-on referential-integrity checks plus profile-conditional rules for deployment, security, threat-model, and sre (
b4908cc) - sas CLI foundation (cli business-logic package plus a thin Cobra cmd/sas adapter) with
sas validate(4ebd340) - Invalid-fixture schema-conformance coverage and end-to-end dogfooding of two real portfolio architectures, fixing two genuine gaps validate surfaced (missing OAuth identity and data classification) (
a39ec0e) - Shared render package (boundary-based node grouping, shape-by-kind, edge labeling) and the Mermaid renderer (
44e8f25) - D2 renderer, verified against the real d2 CLI compiling generated output to SVG (
5c90796) - Graphviz DOT renderer, verified against the real dot CLI compiling generated output to SVG (
ef7330e) - AWS/GCP/Kubernetes technology display-name and icon-hint catalogs, plus HTTP/SQL/MCP operation-to-generic-verb mappings (
a747498) sas view, rendering a declared or ad-hoc view as Mermaid, D2, or DOT. Closes Phase 3 (Rendering & Catalogs) and the M2 milestone: SAS replaces hand-drawn diagrams for a real horizontal and vertical portfolio app (b895dd9)- ProtocolBinding, instantiating a PIDL protocol's abstract entities as concrete SAS nodes, and
sas bind, verified against the real github.com/grokify/pidl OAuth 2.0 Authorization Code example (0e0e104) sas assure, reporting per-category assurance-evidence coverage (tests, metrics, detections, deployment) with a concrete per-element gap list, not just a summary percentage (9f099c9)- Threat Model Spec bridge (
sas export threat-model), translating an Architecture into DiagramIR's system-under-analysis, verified against the real published threat-model-spec JSON Schema (6d9b637) - Launch-readiness rules under the security profile: every internet-facing relationship must declare transport encryption, identity, and data classification, and its target node must declare an owner — the single command a launch checklist runs before going live. Closes Phase 4 and v0.1 (M3) (
63f6105)
Dependencies¶
- 1 dependency update
Documentation¶
- INIT-SYSTEMSARCHITECTURESPEC-001 PRD, TRD, PLAN, and ROADMAP defining SAS v0.1 scope (
0dd4914) - SPEC.md, the normative specification of the SAS data model. Closes v0.1 (M3) alongside the launch-readiness rules (
10220f4) - Update README to reflect the shipped v0.1 implementation: real package layout, CLI surface, and a verified working example (
cb77d5f) - Add GitHub Actions/status badges to README (
a8ce9c8) - Update README status badges to match the shared-workflow filenames (
cf60ca2)
Build¶
- GitHub Actions workflow running go build/vet/test/golangci-lint, schemakit lint against the embedded JSON Schema, and the TypeScript/Zod typecheck+test suite on every push and pull request (
1cf6aed) - Adopt the plexusone org's shared reusable GitHub Actions workflows (go-ci, go-lint, go-sast-codeql) and Dependabot configuration (
0b0b21e) - Rename the ad-hoc CI workflow file to the shared workflow filename convention, superseding it with the org's reusable go-ci workflow (
45bab82)
Internal¶
- Scaffold the repo shell (Go module, MIT LICENSE, README, gitignore) before core type implementation began (
750276d) - Replace the two real dogfood architecture files with a fictional example of equivalent field coverage and scrub the removed ideation transcript and architecture files from git history, since this repo is public and real company architecture belongs in a private internal repo (
fa9224f) - Suppress gosec false positives on the AWS/Kubernetes display-name lookup maps, which its variable-name heuristic misflags as potential hardcoded credentials (
3ae2b6f)