Release Notes
Version 1.0.0
📅 Release Date
August 7, 2026
📖 Overview
The first release of @bayudwiyansatria/core. The kernel that lived inside an application as src/core/system/ is now
a package, so every service that wants this architecture shares one copy rather than forking it.
The extraction was anticipated. That directory's own module documentation said it was "meant to be liftable into a package the other services can share", and an ESLint boundary rule had been enforcing the constraint. It held: across all 45 files, the only import pointing outward was the one documented exception.
This repository previously held the Node.js library template. Its scaffolding was replaced with the newer generation —
flat ESLint config, four Rollup outputs with an exports map, the TypeDoc gate — and its placeholder source removed.
🚀 Features
- Capabilities:
Capabilityand the ten interfaces over it (CacheStore,CoordinationStore,DataStore,InferenceEngine,MessageQueue,ObjectStore,RateLimiter,SqlConnectionProvider,TelemetrySink,VectorIndex), plusRequestMetadataand the shapes their calls exchange. - Configuration:
configure,resolve,systemDefaults, and the settings shapes. The merge semantics are per field rather than per module, and an override set explicitly toundefinedis ignored. - Contracts:
Serviceand theAPIResponseenvelope itsok()/fail()builders produce. - No-op implementations:
NoopCacheStore,NoopMessageQueue,NoopRateLimiter,NoopTelemetrySink, each degrading exactly as its interface documents. - Observability:
Logger,LogContext, and theLOG_LEVELenvironment override. - Security and utilities:
timingSafeEqual,Signature,Text,Time. - Errors:
MissingCapabilityErrorandConfigurationError.
42 names in all, from a single entry point:
| Category | Exports |
|---|---|
| Contracts | Service, APIResponse |
| Capabilities | Capability, the ten interfaces over it, RequestMetadata, their shapes, the Noop* four |
| Configuration | configure, resolve, systemDefaults, the settings shapes |
| Observability | Logger, LogContext |
| Security | timingSafeEqual |
| Errors | MissingCapabilityError, ConfigurationError |
| Utilities | Signature, Text, Time |
🔧 Enhancements
configure()replaces the import ofsrc/config/:resolve()used to import the application's configuration directly, which is fine inside one repository and impossible across a package boundary — a package cannot reach into its consumer's source tree. The application now assembles the surface and hands it over:configure({ ...systemDefaults, ...platformDefaults }, overrides).ConfigurationErroris new:resolve()throws it for a module registered nowhere, and the message names both ways that happens —configure()has not run yet, or two copies of this package are loaded. The second is the nastier one, because the registry is module state: a duplicate copy means one registry gets seeded and another gets read, and nothing about the stack trace would otherwise suggest a packaging problem. Returningundefinedinstead would push the fault downstream to whichever binding first dereferenced the settings, where the message would name the cache rather than the actual cause.Logger.fromEnvno longer names a platform: it tookEnv, an ambient global from the runtime it was written for, and now takes{ LOG_LEVEL?: string } | null | undefined— which an environment object, aprocess.env, or a bare object literal all satisfy. This was the only real reference to a platform type in the whole kernel; every other match was prose in a doc comment.resolve()is generic over the settings shape:resolve<CacheSettings>('cache'), since the kernel cannot know the assembled surface.Signaturederives its key type from the runtime:CryptoKeyis only an ambient global when a runtime-specific lib (DOM,WebWorker) is in scope, and this package deliberately compiles with neither so anything runtime-specific fails the build. WebCrypto itself is part of the minimum API every target runtime provides, so the value is always there — only the type name is not. The alias is derived fromcrypto.subtleand never reaches the public surface.systemDefaults.logging.serviceis'app', rather than the name of the application this came from. An application-specific value had no business being a library default; the placeholder is deliberately generic so an un-overridden deployment reads as unconfigured rather than as some other project.
🔐 Security
- A kernel-purity ESLint rule: no
@cloudflare/*,hono, orcloudflare:*anywhere insrc/, plus a leaf-layer rule keepingtypes/,constants/,exceptions/,security/, andutils/free ofcore/. The boundary that made this extraction possible is worth keeping enforced now that the code has somewhere to be extracted to. timingSafeEqualis covered by specs over exactly the cases an early return would get wrong.
🧪 Tests
85 specs across nine suites; statement coverage 99.45%. They cover the configure/resolve merge contract including
both ConfigurationError paths, timingSafeEqual, Signature sign/verify with a case per forgeable input, Logger
threshold and context handling, Service envelopes, the four Noop* capabilities, and MissingCapabilityError
including the cross-package instanceof a subclass depends on.
📚 Documentation
docs/reference/configuration.mdcoversconfigure,resolve, the merge semantics, and the ordering constraint.- TypeDoc runs under
treatWarningsAsErrors, so an undocumented export fails the build.
🚨 Known Issues
- None
📦 Dependencies
- Runtime: none
- Toolchain: TypeScript, Rollup, Jest, ts-jest, ESLint, Prettier, TypeDoc, HonKit
The exports map exposes . and ./package.json only. There are no deep import paths, so the src/ layout is not
part of the public contract and may be rearranged in a patch release.
⬆️ Upgrading
Nothing to upgrade — this is the first release. A service moving off a vendored src/core/ should follow the migration
guide published by its adapter package.
👥 Contributors
- Bayu Dwiyan Satria
🙏 Acknowledgments
Special thanks to all contributors and the open-source community for their support.
For more information, visit the project's GitHub repository.