v2026.7.4
fortemi-react v2026.7.4 release notes.
fortemi-react v2026.7.4
fortemi-react v2026.7.4 ships the interactive graph tier (2D Sigma explorer and 3D force-directed view as lazy-loaded subpaths, opt-in node dragging, and snapshot-first loading), makes PGlite optional for non-database consumers, completes the Knowledge Shard attachment story with a BLAKE3 blob sidecar, and lands a broad correctness/security hardening batch across the AIWG index and shard surfaces. It is also the first release published to npmjs.org through npm trusted publishing (OIDC) with provenance attestations — there is no long-lived npm token anywhere in the pipeline.
Highlights
- Interactive graph views (#262, #263, #245, #264): `SigmaGraphView` on
`@fortemi/react/graph-2d` (live ForceAtlas2 settling, hover-neighborhood dimming, click-to-focus, ⌘-click re-anchor) and `ForceGraph3DView` on `@fortemi/react/graph-3d` (Three.js orbit/zoom, re-anchor, reader-safe memoised scene). Both load their heavy renderers as optional peer dependencies via dynamic `import()` — nothing ships until a view mounts. The static `GraphView` gains opt-in node dragging with pin-and-resettle, and all tiers share the same `mapCommunityGraph` / `loadRenderSnapshot` warm-start helpers from `@fortemi/graph`.
- PGlite is optional (#261): the WASM database engine now lazy-loads on
first archive open, `@electric-sql/pglite` moved to `optionalDependencies`, and the new PGlite-free `@fortemi/react/graph` subpath lets presentational consumers render graphs without dragging the database in. All three package barrels are `"sideEffects": false`.
- Knowledge Shard blob sidecar (#271): `exportShard({ includeBlobs: true })`
writes attachment binaries as content-addressed `blobs/<hash>` tar entries keyed by BLAKE3 — the same hash the Fortémi server records — and `importShard` restores them into the local blob store. Attachment blob storage design accepted as ADR-012 (#282).
- Hardening batch (#265–#294): completed the SEC1 prototype-pollution fix
at the three remaining untrusted-key sites; validators return structured results on hostile input; `importShard` reports malformed input as `{ success: false, errors }`; bounded URL reader and checksum verification on `openShard`; chunked v2 indexes with `source.graph` load correctly; privacy filtering fails closed; soft-deleted notes excluded from embedding-set builders; the vendored AIWG index schema is pinned with a provenance receipt.
- Tokenless npm publishing (#310): the GitHub-mirror publish workflow
authenticates to npmjs.org via OIDC trusted publishing and publishes with `--provenance`; the workflow independently verifies the attestation landed for every package before the run may succeed. The legacy `NPMJS_TOKEN` is retired. Verification remains on Gitea CI; GitHub is the delivery leg only.
- Docs (#274, #309): repositioned as the browser edition of the Fortémi
intelligent-database stack; full code-to-docs sync plus four new API-reference sections (Knowledge Shards, AIWG index, graph render pipeline, React graph views).
Published Packages
- `@fortemi/[email protected]`
- `@fortemi/[email protected]`
- `@fortemi/[email protected]`
Compatibility
Additive. Existing consumers are unaffected: `draggableNodes` defaults off, the 2D/3D views live on new subpaths with optional peers, and the root-import surface of all three packages is unchanged. One packaging change to note: `@electric-sql/pglite` is now an `optionalDependency` of `@fortemi/core` and loads lazily — hosts that open archives see identical behavior, while hosts that never touch the database no longer bundle the WASM engine. Knowledge Shards, embedding sets, and static indexes from v2026.7.3 remain valid; shards exported with `includeBlobs` are readable by older importers (sidecar entries are ignored where unsupported).
Verification
Release preparation uses the configured release flow:
- `pnpm typecheck`
- `pnpm lint`
- `pnpm test:core`
- `pnpm test:e2e`
- `pnpm build`
- CI green before tag publication
First OIDC-published release: post-publish, each package's npmjs.org provenance attestation was verified as a hard gate of the publish workflow.