The root manifest carries the dsh family version. bump writes it with the members, because the workspace constraint requires them to match, and that constraint now accepts a prerelease segment: without both, release:dsh 0.0.2 left the root behind and 0.0.1-rc.1 could satisfy neither check. The Landlock workflow no longer passes --access public, which overrode the restricted publishConfig this repository just adopted for those packages. Vendored change detection reads build inputs when a package publishes build output, and vendor/cordis publishes the src its export map already pointed at: its lib/ is untracked, so a real source edit read as 'nothing changed' and the next publish would fail on a version whose bytes moved. The next version also takes the last published version as its baseline, so a re-sync that restores a lower upstream version cannot recompute a version already on the registry, and bump confirms the registry carries what the newest tag names. Tag prefixes are constructed rather than recovered from a full tag, which a hyphenated version defeated. Pack runs group per ref so concurrent pull requests stop displacing each other, the publish job carries the global group, and the unused id-token permission is gone. Every release script sits behind an entry guard, which is what lets the pure judgements carry tests: tag naming, publish order and cycle reporting, version arithmetic, payload policy, and the change judgement. The Agent Note moves to implemented and states what shipped: one probe command, the registry confirmation that now exists, and byte reproducibility recorded as assumed rather than measured.
Cordis
Cordis is a TypeScript plugin framework for applications that need explicit
dependency injection, scoped services, lifecycle-managed cleanup, and optional
configuration-driven loading. The core package is published as cordis; the
official packages in this repository add a loader, config-file includes, HMR,
console logging, timers, and project scaffolding.
Install
yarn add cordis
Cordis is ESM-first. The repository is tested on current Node releases, and the scaffolder requires Node 22 or newer.
Quick Start
import { Context, Service } from 'cordis'
declare module 'cordis' {
interface Context {
counter: Counter
}
interface Events {
'app/ready'(message: string): void
}
}
class Counter extends Service {
value = 0
constructor(ctx: Context) {
super(ctx, 'counter')
}
next() {
return ++this.value
}
}
const greeter = Object.assign((ctx: Context) => {
ctx.on('app/ready', (message) => {
ctx.logger.info('%s #%d', message, ctx.counter.next())
})
}, {
inject: ['counter'],
})
const root = new Context()
await root.plugin(Counter)
await root.plugin(greeter)
root.emit('app/ready', 'started')
await root.fiber.dispose()
The important pieces are:
new Context()creates the root dependency container.ctx.plugin()starts a plugin and returns aFiber.injecttells Cordis which services must exist before the plugin runs.- Effects, event listeners, and services are removed when their owning fiber is disposed.
Documentation
Packages
| Package | Purpose |
|---|---|
cordis |
Core context, plugin registry, fiber lifecycle, events, services, and logger. |
create-cordis |
Interactive project scaffolder. |
@cordisjs/plugin-loader |
Runtime plugin tree and loader service. |
@cordisjs/plugin-include |
YAML/JSON config-file include support for the loader. |
@cordisjs/plugin-group |
Nested plugin groups for loader configs. |
@cordisjs/plugin-hmr |
Hot module replacement for loader-managed plugins. |
@cordisjs/plugin-logger-console |
Console exporter for the built-in logger. |
@cordisjs/plugin-timer |
Disposal-aware timeout, interval, throttle, and debounce helpers. |
@cordisjs/utils |
Shared utilities used by Cordis packages. |
Development
yarn install
yarn build
yarn test
yarn lint
The monorepo uses Yakumo to build and test all packages. Most examples in the
docs use public APIs from cordis; loader examples additionally use
@cordisjs/plugin-loader and @cordisjs/plugin-include.