Skip to content

Changelog

All notable changes to this project will be documented in this file.

The format is based on Keep a Changelog, this project adheres to Semantic Versioning, commits follow Conventional Commits, and this changelog is generated by Structured Changelog.

Unreleased

v0.2.0 - 2026-09-13

Highlights

  • Semantic diff engine: a typed ChangeSet between two architectures with change-impact classification
  • Baseline / Assessment / ChangeReview model for reviewing an architecture change against a baseline
  • FedRAMP change-assessment profile: three-outcome classification with control-mapping hooks
  • Container & sandbox node/boundary kinds for K8s-native and sandboxed-execution topology
  • Module renamed to github.com/plexusone/systemspec-architecture

Added

  • Semantic diff engine with a typed ChangeSet (51c281a)
  • Change-impact classification for diffs (80f3d42)
  • Baseline, Assessment, and ChangeReview model (40bc2c0)
  • compute.container/compute.sandbox node kinds and container/sandbox boundary kinds; bridge/threatmodel.boundaryType() emits sandbox/container/breached instead of collapsing to network (4e146ce)
  • FedRAMP change-assessment profile (diff/fedramp) (92affaf)

Changed

  • Rename Go module to github.com/plexusone/systemspec-architecture (repo rename; mechanical import-path rewrite) (2c19dc0)

Documentation

  • Document container/sandbox kinds in SPEC.md (kind taxonomies); update README/index status to v0.2 and add the diff and diff/fedramp packages; add v0.2.0 release notes

v0.1.0 - 2026-09-07 (728c446)

Highlights

  • Initial release: a statically-typed-friendly, Go-first semantic graph model for systems architecture (Node, Relationship, Boundary, Identity, Entitlement, Extensions), with generated JSON Schema and Zod/TypeScript conforming to the same fixture corpus as the Go model
  • Views as queries plus Mermaid/D2/Graphviz DOT renderers, each verified against the real d2/dot CLIs, closing the diagrams payoff (M2): SAS replaces hand-drawn diagrams for a real horizontal and vertical portfolio app
  • Profile-conditional validation (development, deployment, security, threat-model, sre) including launch-readiness rules that gate internet-facing traffic before go-live
  • PIDL ProtocolBinding and the Threat Model Spec bridge, both verified against the real external schemas they integrate with rather than internal assumptions about their shape, closing the launch-readiness payoff (M3) and v0.1

Added

  • Core semantic graph types Architecture, Node, and Boundary, with a small closed NodeKind vocabulary, many-to-many boundary membership, and assurance evidence references (a5ffa0e)
  • Relationship as the richest core type: transport, generic operation verbs, identity, entitlements, data classification, and boundary-crossing — the security-significant facts most diagram formats collapse into an unlabeled arrow (625f496)
  • First-class Identity (type, mechanism, ref) and Entitlement (subject-action-resource) types shaped to map cleanly onto ReBAC systems without making SAS a ReBAC engine (6b79b90)
  • Extensions as explicit, statically typed namespace fields (security, sre, compliance, agent) instead of a generic map, and ExternalRef for pointing at detail owned by OpenAPI, PIDL, Threat Model Spec, Multi-Agent Spec, Terraform, and OTel (bfdac78)
  • JSON Schema generation from the Go model via invopop/jsonschema (lint-clean under schemakit's camelCase profile) and Zod/TypeScript types generated from that schema, proven by a shared fixture round-tripping through both Go and TypeScript. Closes Phase 1 (Core IR & Schema Pipeline) (474052a)
  • View as a query over an Architecture (IncludeKinds/IncludeRelations/IncludeBoundaries) and CrossedBoundaries, which derives which boundaries a relationship crosses from its endpoints' declared membership (1b0c448)
  • Profile model (development, deployment, security, threat-model, sre): optional-in-core semantics that become mandatory only for the profile that needs them (5522a1a)
  • Validation rules engine: always-on referential-integrity checks plus profile-conditional rules for deployment, security, threat-model, and sre (b4908cc)
  • sas CLI foundation (cli business-logic package plus a thin Cobra cmd/sas adapter) with sas validate (4ebd340)
  • Invalid-fixture schema-conformance coverage and end-to-end dogfooding of two real portfolio architectures, fixing two genuine gaps validate surfaced (missing OAuth identity and data classification) (a39ec0e)
  • Shared render package (boundary-based node grouping, shape-by-kind, edge labeling) and the Mermaid renderer (44e8f25)
  • D2 renderer, verified against the real d2 CLI compiling generated output to SVG (5c90796)
  • Graphviz DOT renderer, verified against the real dot CLI compiling generated output to SVG (ef7330e)
  • AWS/GCP/Kubernetes technology display-name and icon-hint catalogs, plus HTTP/SQL/MCP operation-to-generic-verb mappings (a747498)
  • sas view, rendering a declared or ad-hoc view as Mermaid, D2, or DOT. Closes Phase 3 (Rendering & Catalogs) and the M2 milestone: SAS replaces hand-drawn diagrams for a real horizontal and vertical portfolio app (b895dd9)
  • ProtocolBinding, instantiating a PIDL protocol's abstract entities as concrete SAS nodes, and sas bind, verified against the real github.com/grokify/pidl OAuth 2.0 Authorization Code example (0e0e104)
  • sas assure, reporting per-category assurance-evidence coverage (tests, metrics, detections, deployment) with a concrete per-element gap list, not just a summary percentage (9f099c9)
  • Threat Model Spec bridge (sas export threat-model), translating an Architecture into DiagramIR's system-under-analysis, verified against the real published threat-model-spec JSON Schema (6d9b637)
  • Launch-readiness rules under the security profile: every internet-facing relationship must declare transport encryption, identity, and data classification, and its target node must declare an owner — the single command a launch checklist runs before going live. Closes Phase 4 and v0.1 (M3) (63f6105)

Dependencies

  • 1 dependency update

Documentation

  • INIT-SYSTEMSARCHITECTURESPEC-001 PRD, TRD, PLAN, and ROADMAP defining SAS v0.1 scope (0dd4914)
  • SPEC.md, the normative specification of the SAS data model. Closes v0.1 (M3) alongside the launch-readiness rules (10220f4)
  • Update README to reflect the shipped v0.1 implementation: real package layout, CLI surface, and a verified working example (cb77d5f)
  • Add GitHub Actions/status badges to README (a8ce9c8)
  • Update README status badges to match the shared-workflow filenames (cf60ca2)

Build

  • GitHub Actions workflow running go build/vet/test/golangci-lint, schemakit lint against the embedded JSON Schema, and the TypeScript/Zod typecheck+test suite on every push and pull request (1cf6aed)
  • Adopt the plexusone org's shared reusable GitHub Actions workflows (go-ci, go-lint, go-sast-codeql) and Dependabot configuration (0b0b21e)
  • Rename the ad-hoc CI workflow file to the shared workflow filename convention, superseding it with the org's reusable go-ci workflow (45bab82)

Internal

  • Scaffold the repo shell (Go module, MIT LICENSE, README, gitignore) before core type implementation began (750276d)
  • Replace the two real dogfood architecture files with a fictional example of equivalent field coverage and scrub the removed ideation transcript and architecture files from git history, since this repo is public and real company architecture belongs in a private internal repo (fa9224f)
  • Suppress gosec false positives on the AWS/Kubernetes display-name lookup maps, which its variable-name heuristic misflags as potential hardcoded credentials (3ae2b6f)