From a9d78831379a77cd91d1017a5519c571e0da383c Mon Sep 17 00:00:00 2001 From: haroldboom Date: Wed, 29 Apr 2026 07:47:09 +1000 Subject: [PATCH 01/20] Add langchain-dkg integration --- integrations/langchain-dkg.json | 41 +++++++++++++++++++++++++++++++++ 1 file changed, 41 insertions(+) create mode 100644 integrations/langchain-dkg.json diff --git a/integrations/langchain-dkg.json b/integrations/langchain-dkg.json new file mode 100644 index 0000000..2e45dc5 --- /dev/null +++ b/integrations/langchain-dkg.json @@ -0,0 +1,41 @@ +{ + "$schema": "../schema/integration.schema.json", + "schemaVersion": "0.1.0", + "slug": "langchain-dkg", + "name": "LangChain DKG Adapter", + "description": "LangChain memory and retriever components backed by OriginTrail DKG v10. Gives LangChain agents durable, verifiable, queryable memory — conversation history is stored as Knowledge Assets in Working Memory and retrieved via tri-modal search (vector + SPARQL + text).", + "category": ["working-memory", "retrieval", "python", "langchain", "rag"], + "maintainer": { + "github": "@haroldboom", + "contact": "spangers11@gmail.com" + }, + "repo": "https://github.com/haroldboom/dkg-langchain", + "commit": "80392345732114b2e2d4395bcece3b1a5df5bcb5", + "license": "MIT", + "requiresDkgNodeVersion": ">=10.0.0", + "memoryLayers": ["WM", "SWM"], + "v10PrimitivesUsed": ["UAL", "KnowledgeAsset", "ContextGraph", "Assertion"], + "publicInterfacesUsed": ["http-api"], + + "install": { + "kind": "manual", + "docsUrl": "https://github.com/haroldboom/dkg-langchain#readme", + "oneLiner": "pip install langchain-dkg — then set DKG_API_URL and DKG_TOKEN and import DKGChatMessageHistory, DKGMemory, or DKGRetriever." + }, + + "security": { + "networkEgress": [], + "writeAuthority": [ + "POST /api/memory/turn", + "POST /api/assertion/{name}/promote" + ], + "credentialsHandled": [], + "notes": "Communicates only with the local DKG node (default localhost:9200) — no external network egress. Credentials are read from the DKG_TOKEN environment variable or passed explicitly to DKGClient; never hardcoded. POST /api/memory/turn stores conversation turns as Knowledge Assets in Working Memory. POST /api/assertion/{name}/promote is a Curator-authority SHARE operation that moves a turn to Shared Working Memory; this is always explicit and agent-initiated, never automatic. No Verified Memory (PUBLISH) operations are performed. The package has no postinstall, install, or preinstall scripts." + }, + + "trustTier": "community", + + "designBrief": "https://github.com/haroldboom/dkg-langchain/blob/master/DESIGN_BRIEF.md", + "promotionPath": "Every conversation turn stored via DKGChatMessageHistory returns a turnUri (UAL). The agent can call promote_to_shared(turn_uri) to SHARE the Knowledge Asset from Working Memory to Shared Working Memory via POST /api/assertion/{name}/promote — promotion is always explicit. From Shared Working Memory, a future PUBLISH call (Round 2 scope) moves the Context Graph to Verified Memory on-chain, preserving the full UAL provenance chain from original turn through to the paranet record. DKGRetriever queries the same WM/SWM graph via SPARQL SELECT, so promoted artifacts are immediately available as RAG context for downstream agents.", + "fitNotes": "Directly targets the LLM-Wiki / autoresearch direction: LangChain agents are the dominant production consumer of external memory systems, and this adapter maps Karpathy's memory taxonomy (in-context, external, team, long-term) onto the DKG v10 layer model (WM, SWM, VM). DKGRetriever is a drop-in BaseRetriever for any LangChain RAG pipeline, giving any autoresearch-style agent a verifiable, attributable upstream knowledge source." +} From 04c3d87fcb66afbd0239809900fc25c16de51384 Mon Sep 17 00:00:00 2001 From: haroldboom Date: Sun, 24 May 2026 01:31:06 +1000 Subject: [PATCH 02/20] Update langchain-dkg entry for review - Bump pinned commit to ad6295e (CI + README badges, current HEAD on master) - Drop email from maintainer; GitHub is the canonical contact channel - Add targetAgents (AutoResearch / generic-HTTP / generic-CLI) - Add demo field pointing at the YouTube walkthrough - Cite 25/25 unit tests + CI matrix in security.notes --- integrations/langchain-dkg.json | 9 +++++---- 1 file changed, 5 insertions(+), 4 deletions(-) diff --git a/integrations/langchain-dkg.json b/integrations/langchain-dkg.json index 2e45dc5..dabffa8 100644 --- a/integrations/langchain-dkg.json +++ b/integrations/langchain-dkg.json @@ -6,16 +6,16 @@ "description": "LangChain memory and retriever components backed by OriginTrail DKG v10. Gives LangChain agents durable, verifiable, queryable memory — conversation history is stored as Knowledge Assets in Working Memory and retrieved via tri-modal search (vector + SPARQL + text).", "category": ["working-memory", "retrieval", "python", "langchain", "rag"], "maintainer": { - "github": "@haroldboom", - "contact": "spangers11@gmail.com" + "github": "@haroldboom" }, "repo": "https://github.com/haroldboom/dkg-langchain", - "commit": "80392345732114b2e2d4395bcece3b1a5df5bcb5", + "commit": "ad6295e6a9c9d94e75dd63bb215aa892b9630dac", "license": "MIT", "requiresDkgNodeVersion": ">=10.0.0", "memoryLayers": ["WM", "SWM"], "v10PrimitivesUsed": ["UAL", "KnowledgeAsset", "ContextGraph", "Assertion"], "publicInterfacesUsed": ["http-api"], + "targetAgents": ["AutoResearch", "generic-HTTP", "generic-CLI"], "install": { "kind": "manual", @@ -30,12 +30,13 @@ "POST /api/assertion/{name}/promote" ], "credentialsHandled": [], - "notes": "Communicates only with the local DKG node (default localhost:9200) — no external network egress. Credentials are read from the DKG_TOKEN environment variable or passed explicitly to DKGClient; never hardcoded. POST /api/memory/turn stores conversation turns as Knowledge Assets in Working Memory. POST /api/assertion/{name}/promote is a Curator-authority SHARE operation that moves a turn to Shared Working Memory; this is always explicit and agent-initiated, never automatic. No Verified Memory (PUBLISH) operations are performed. The package has no postinstall, install, or preinstall scripts." + "notes": "Communicates only with the local DKG node (default localhost:9200) — no external network egress. Credentials are read from the DKG_TOKEN environment variable or passed explicitly to DKGClient; never hardcoded. POST /api/memory/turn stores conversation turns as Knowledge Assets in Working Memory. POST /api/assertion/{name}/promote is a Curator-authority SHARE operation that moves a turn to Shared Working Memory; this is always explicit and agent-initiated, never automatic. No Verified Memory (PUBLISH) operations are performed. 25/25 unit tests pass against the published wheel (verified in a fresh venv outside the source tree); GitHub Actions CI runs the suite on Python 3.10/3.11/3.12 for every push and PR. The package has no postinstall, install, or preinstall scripts." }, "trustTier": "community", "designBrief": "https://github.com/haroldboom/dkg-langchain/blob/master/DESIGN_BRIEF.md", + "demo": "https://youtu.be/0XVYrikAZFQ", "promotionPath": "Every conversation turn stored via DKGChatMessageHistory returns a turnUri (UAL). The agent can call promote_to_shared(turn_uri) to SHARE the Knowledge Asset from Working Memory to Shared Working Memory via POST /api/assertion/{name}/promote — promotion is always explicit. From Shared Working Memory, a future PUBLISH call (Round 2 scope) moves the Context Graph to Verified Memory on-chain, preserving the full UAL provenance chain from original turn through to the paranet record. DKGRetriever queries the same WM/SWM graph via SPARQL SELECT, so promoted artifacts are immediately available as RAG context for downstream agents.", "fitNotes": "Directly targets the LLM-Wiki / autoresearch direction: LangChain agents are the dominant production consumer of external memory systems, and this adapter maps Karpathy's memory taxonomy (in-context, external, team, long-term) onto the DKG v10 layer model (WM, SWM, VM). DKGRetriever is a drop-in BaseRetriever for any LangChain RAG pipeline, giving any autoresearch-style agent a verifiable, attributable upstream knowledge source." } From a830da5e36158825930623058bef7969cc893c2b Mon Sep 17 00:00:00 2001 From: haroldboom Date: Sun, 24 May 2026 01:34:40 +1000 Subject: [PATCH 03/20] Add email contact to maintainer --- integrations/langchain-dkg.json | 3 ++- 1 file changed, 2 insertions(+), 1 deletion(-) diff --git a/integrations/langchain-dkg.json b/integrations/langchain-dkg.json index dabffa8..0d01cc2 100644 --- a/integrations/langchain-dkg.json +++ b/integrations/langchain-dkg.json @@ -6,7 +6,8 @@ "description": "LangChain memory and retriever components backed by OriginTrail DKG v10. Gives LangChain agents durable, verifiable, queryable memory — conversation history is stored as Knowledge Assets in Working Memory and retrieved via tri-modal search (vector + SPARQL + text).", "category": ["working-memory", "retrieval", "python", "langchain", "rag"], "maintainer": { - "github": "@haroldboom" + "github": "@haroldboom", + "contact": "spangers11@gmail.com" }, "repo": "https://github.com/haroldboom/dkg-langchain", "commit": "ad6295e6a9c9d94e75dd63bb215aa892b9630dac", From 0052604eda0472d0d7bea73a51b6cc05b6762602 Mon Sep 17 00:00:00 2001 From: haroldboom Date: Sun, 24 May 2026 01:50:53 +1000 Subject: [PATCH 04/20] Bump pin to bd7bc94 (positioning section + Trusted Publishing workflow) --- integrations/langchain-dkg.json | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/integrations/langchain-dkg.json b/integrations/langchain-dkg.json index 0d01cc2..17392d4 100644 --- a/integrations/langchain-dkg.json +++ b/integrations/langchain-dkg.json @@ -10,7 +10,7 @@ "contact": "spangers11@gmail.com" }, "repo": "https://github.com/haroldboom/dkg-langchain", - "commit": "ad6295e6a9c9d94e75dd63bb215aa892b9630dac", + "commit": "bd7bc9469df95faccad675ad31377a8efee90c8b", "license": "MIT", "requiresDkgNodeVersion": ">=10.0.0", "memoryLayers": ["WM", "SWM"], From 3902941b602f268dffb27fb865ae8e4b0b675983 Mon Sep 17 00:00:00 2001 From: haroldboom Date: Sun, 24 May 2026 02:21:33 +1000 Subject: [PATCH 05/20] Bump langchain-dkg to v0.1.2 with PyPI Trusted Publishing attestations MIME-Version: 1.0 Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 8bit - commit pin: bd7bc94 → 97ecf2a (the v0.1.2 release commit) - install.oneLiner: pins to ==0.1.2 so installers grab the attested wheel - security.notes: declares PEP-740 attestation published via pypa/gh-action-pypi-publish@release/v1; signed by GitHub Actions runner for haroldboom/dkg-langchain / publish.yml / env=pypi --- integrations/langchain-dkg.json | 6 +++--- 1 file changed, 3 insertions(+), 3 deletions(-) diff --git a/integrations/langchain-dkg.json b/integrations/langchain-dkg.json index 17392d4..08d61e3 100644 --- a/integrations/langchain-dkg.json +++ b/integrations/langchain-dkg.json @@ -10,7 +10,7 @@ "contact": "spangers11@gmail.com" }, "repo": "https://github.com/haroldboom/dkg-langchain", - "commit": "bd7bc9469df95faccad675ad31377a8efee90c8b", + "commit": "97ecf2a3013f8c28f6711fb86dc636cf76a56edd", "license": "MIT", "requiresDkgNodeVersion": ">=10.0.0", "memoryLayers": ["WM", "SWM"], @@ -21,7 +21,7 @@ "install": { "kind": "manual", "docsUrl": "https://github.com/haroldboom/dkg-langchain#readme", - "oneLiner": "pip install langchain-dkg — then set DKG_API_URL and DKG_TOKEN and import DKGChatMessageHistory, DKGMemory, or DKGRetriever." + "oneLiner": "pip install langchain-dkg==0.1.2 — then set DKG_API_URL and DKG_TOKEN and import DKGChatMessageHistory, DKGMemory, or DKGRetriever." }, "security": { @@ -31,7 +31,7 @@ "POST /api/assertion/{name}/promote" ], "credentialsHandled": [], - "notes": "Communicates only with the local DKG node (default localhost:9200) — no external network egress. Credentials are read from the DKG_TOKEN environment variable or passed explicitly to DKGClient; never hardcoded. POST /api/memory/turn stores conversation turns as Knowledge Assets in Working Memory. POST /api/assertion/{name}/promote is a Curator-authority SHARE operation that moves a turn to Shared Working Memory; this is always explicit and agent-initiated, never automatic. No Verified Memory (PUBLISH) operations are performed. 25/25 unit tests pass against the published wheel (verified in a fresh venv outside the source tree); GitHub Actions CI runs the suite on Python 3.10/3.11/3.12 for every push and PR. The package has no postinstall, install, or preinstall scripts." + "notes": "Communicates only with the local DKG node (default localhost:9200) — no external network egress. Credentials are read from the DKG_TOKEN environment variable or passed explicitly to DKGClient; never hardcoded. POST /api/memory/turn stores conversation turns as Knowledge Assets in Working Memory. POST /api/assertion/{name}/promote is a Curator-authority SHARE operation that moves a turn to Shared Working Memory; this is always explicit and agent-initiated, never automatic. No Verified Memory (PUBLISH) operations are performed. 25/25 unit tests pass against the published wheel (verified in a fresh venv outside the source tree); GitHub Actions CI runs the suite on Python 3.10/3.11/3.12 for every push and PR. The package has no postinstall, install, or preinstall scripts. Published to PyPI via `pypa/gh-action-pypi-publish@release/v1` with `attestations: true` under PyPI Trusted Publishing (workflow `publish.yml`, environment `pypi`) — wheel ships with a PEP-740 attestation signed by the GitHub Actions runner, fetchable at `https://pypi.org/integrity/langchain-dkg/0.1.2//provenance`." }, "trustTier": "community", From b847f7bac1a43cbbb4708949824126e83004339d Mon Sep 17 00:00:00 2001 From: haroldboom Date: Tue, 9 Jun 2026 20:15:52 +1000 Subject: [PATCH 06/20] =?UTF-8?q?Pin=20langchain-dkg=20to=20v0.1.3=20?= =?UTF-8?q?=E2=80=94=20verified=20with=20dkg=20SDK=208.1.1rc2?= MIME-Version: 1.0 Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 8bit Co-Authored-By: Claude Opus 4.6 --- integrations/github-dkg.json | 42 +++++++++++++++++++++++++++++++++ integrations/langchain-dkg.json | 6 ++--- 2 files changed, 45 insertions(+), 3 deletions(-) create mode 100644 integrations/github-dkg.json diff --git a/integrations/github-dkg.json b/integrations/github-dkg.json new file mode 100644 index 0000000..6b98594 --- /dev/null +++ b/integrations/github-dkg.json @@ -0,0 +1,42 @@ +{ + "$schema": "../schema/integration.schema.json", + "schemaVersion": "0.1.0", + "slug": "github-dkg", + "name": "GitHub Knowledge Ingest for DKG v10", + "description": "Ingests GitHub issues, pull requests, and review comments into DKG v10 Working Memory as Knowledge Assets. Each item becomes one tri-modal asset (markdown + structural triples + embedding); architecture-decision PRs can be promoted to Shared Working Memory for team-wide visibility. Ships as a CLI and a Docker-based GitHub Action that fires on issue / pull_request / pull_request_review events.", + "category": ["ingestion", "github", "working-memory", "shared-memory", "engineering", "provenance"], + "maintainer": { + "github": "@haroldboom", + "contact": "spangers11@gmail.com" + }, + "repo": "https://github.com/haroldboom/github-dkg", + "commit": "b9c1edee9be4076f8e9d8e2a05c75aaa3fc8d0c1", + "license": "MIT", + "requiresDkgNodeVersion": ">=10.0.0-rc.1", + "memoryLayers": ["WM", "SWM"], + "v10PrimitivesUsed": ["ContextGraph", "Assertion", "KnowledgeAsset"], + "publicInterfacesUsed": ["http-api"], + "targetAgents": ["generic-CLI", "generic-HTTP"], + "install": { + "kind": "cli", + "package": "github-dkg", + "version": "0.1.1", + "binary": "github-dkg", + "envRequired": ["DKG_TOKEN", "DKG_BASE_URL", "DKG_CONTEXT_GRAPH", "GITHUB_TOKEN"], + "usageHint": "Bulk-ingest:\n github-dkg ingest owner/repo\nSingle item:\n github-dkg ingest-one owner/repo 42 --type issue\nSearch:\n github-dkg search \"query\"\nPromote WM→SWM:\n github-dkg promote \nAll commands accept --context-graph (or read $DKG_CONTEXT_GRAPH). Also ships as a Docker-based GitHub Action: haroldboom/github-dkg@v0.1.0." + }, + "security": { + "networkEgress": ["api.github.com"], + "writeAuthority": [ + "POST /api/memory/turn", + "POST /api/assertion/{name}/promote" + ], + "credentialsHandled": ["GITHUB_TOKEN"], + "notes": "Communicates with the local DKG node (HTTP, port 9200 by default) and the GitHub REST API at api.github.com. Writes Knowledge Assets to Working Memory by default; promotion to Shared Working Memory (POST /api/assertion/{name}/promote) is always explicit and never automatic — the bundled GitHub Action example workflow gates promotion on a PR label (`architecture-decision`) so the choice is the team's, not the integration's. PUBLISH (Verified Memory) is never called. GitHub rate-limit responses (403/429 with X-RateLimit-Remaining: 0) surface as a typed GitHubRateLimitError carrying the reset timestamp, so callers can back off rather than retry into a ban. 23/23 unit tests pass against the published wheel (verified in a fresh venv outside the source tree); GitHub Actions CI runs the suite on Python 3.10/3.11/3.12 for every push and PR. Verified compatible with DKG v10 rc.8 (latest at submission). No postinstall/preinstall scripts. Published to PyPI via `pypa/gh-action-pypi-publish@release/v1` with `attestations: true` under PyPI Trusted Publishing (workflow `publish.yml`, environment `pypi`) — wheel ships with a PEP-740 attestation signed by the GitHub Actions runner, fetchable at `https://pypi.org/integrity/github-dkg/0.1.1//provenance`." + }, + "trustTier": "community", + "designBrief": "https://github.com/haroldboom/github-dkg/blob/master/DESIGN_BRIEF.md", + "demo": "https://youtu.be/9Tgb4-OXGuk", + "promotionPath": "Issues, PRs, and review comments land in Working Memory as Knowledge Assets at ingest time. The integration exposes an explicit `promote` operation (CLI: `github-dkg promote `; programmatic: `GitHubDKGIngestor.promote(turn_uri)`) that calls POST /api/assertion/{name}/promote to graduate selected assets to Shared Working Memory — `examples/workflow.yml` shows the canonical gate (closed+merged PR + label `architecture-decision`). Verified Memory promotion is intentionally not automated by the package; a downstream Curator step (POST /api/shared-memory/publish) anchors team-validated decisions on-chain when warranted, at which point those assets become consumable by context oracles for downstream agents reasoning about the project's history.", + "fitNotes": "Targets the auto-research direction by closing the loop on engineering tacit knowledge: issue threads, PR descriptions, and review comments — the highest-signal substrate inside any software organisation — become first-class, attributable, queryable assets on the DKG. Pairs naturally with langchain-dkg (sister Round 1 submission, also under the haroldboom account): github-dkg writes the substrate, langchain-dkg gives any LangChain agent persistent memory backed by it." +} diff --git a/integrations/langchain-dkg.json b/integrations/langchain-dkg.json index 08d61e3..8318e0b 100644 --- a/integrations/langchain-dkg.json +++ b/integrations/langchain-dkg.json @@ -10,7 +10,7 @@ "contact": "spangers11@gmail.com" }, "repo": "https://github.com/haroldboom/dkg-langchain", - "commit": "97ecf2a3013f8c28f6711fb86dc636cf76a56edd", + "commit": "b4afb7a4edd07c927e9dc92297a43a62d26901cb", "license": "MIT", "requiresDkgNodeVersion": ">=10.0.0", "memoryLayers": ["WM", "SWM"], @@ -21,7 +21,7 @@ "install": { "kind": "manual", "docsUrl": "https://github.com/haroldboom/dkg-langchain#readme", - "oneLiner": "pip install langchain-dkg==0.1.2 — then set DKG_API_URL and DKG_TOKEN and import DKGChatMessageHistory, DKGMemory, or DKGRetriever." + "oneLiner": "pip install langchain-dkg==0.1.3 — then set DKG_API_URL and DKG_TOKEN and import DKGChatMessageHistory, DKGMemory, or DKGRetriever." }, "security": { @@ -31,7 +31,7 @@ "POST /api/assertion/{name}/promote" ], "credentialsHandled": [], - "notes": "Communicates only with the local DKG node (default localhost:9200) — no external network egress. Credentials are read from the DKG_TOKEN environment variable or passed explicitly to DKGClient; never hardcoded. POST /api/memory/turn stores conversation turns as Knowledge Assets in Working Memory. POST /api/assertion/{name}/promote is a Curator-authority SHARE operation that moves a turn to Shared Working Memory; this is always explicit and agent-initiated, never automatic. No Verified Memory (PUBLISH) operations are performed. 25/25 unit tests pass against the published wheel (verified in a fresh venv outside the source tree); GitHub Actions CI runs the suite on Python 3.10/3.11/3.12 for every push and PR. The package has no postinstall, install, or preinstall scripts. Published to PyPI via `pypa/gh-action-pypi-publish@release/v1` with `attestations: true` under PyPI Trusted Publishing (workflow `publish.yml`, environment `pypi`) — wheel ships with a PEP-740 attestation signed by the GitHub Actions runner, fetchable at `https://pypi.org/integrity/langchain-dkg/0.1.2//provenance`." + "notes": "Communicates only with the local DKG node (default localhost:9200) — no external network egress. Credentials are read from the DKG_TOKEN environment variable or passed explicitly to DKGClient; never hardcoded. POST /api/memory/turn stores conversation turns as Knowledge Assets in Working Memory. POST /api/assertion/{name}/promote is a Curator-authority SHARE operation that moves a turn to Shared Working Memory; this is always explicit and agent-initiated, never automatic. No Verified Memory (PUBLISH) operations are performed. 25/25 unit tests pass against the published wheel (verified in a fresh venv outside the source tree); GitHub Actions CI runs the suite on Python 3.10/3.11/3.12 for every push and PR. The package has no postinstall, install, or preinstall scripts. Published to PyPI via `pypa/gh-action-pypi-publish@release/v1` with `attestations: true` under PyPI Trusted Publishing (workflow `publish.yml`, environment `pypi`) — wheel ships with a PEP-740 attestation signed by the GitHub Actions runner, fetchable at `https://pypi.org/integrity/langchain-dkg/0.1.3//provenance`. Verified compatible with dkg SDK 8.1.1rc2 (2026-06-09)." }, "trustTier": "community", From c0c17a010be3dc3c77c0e2cc1dd7b33c3e262b0e Mon Sep 17 00:00:00 2001 From: haroldboom Date: Tue, 9 Jun 2026 20:16:09 +1000 Subject: [PATCH 07/20] Remove github-dkg.json from langchain-dkg branch (belongs on add/github-dkg) Co-Authored-By: Claude Opus 4.6 --- integrations/github-dkg.json | 42 ------------------------------------ 1 file changed, 42 deletions(-) delete mode 100644 integrations/github-dkg.json diff --git a/integrations/github-dkg.json b/integrations/github-dkg.json deleted file mode 100644 index 6b98594..0000000 --- a/integrations/github-dkg.json +++ /dev/null @@ -1,42 +0,0 @@ -{ - "$schema": "../schema/integration.schema.json", - "schemaVersion": "0.1.0", - "slug": "github-dkg", - "name": "GitHub Knowledge Ingest for DKG v10", - "description": "Ingests GitHub issues, pull requests, and review comments into DKG v10 Working Memory as Knowledge Assets. Each item becomes one tri-modal asset (markdown + structural triples + embedding); architecture-decision PRs can be promoted to Shared Working Memory for team-wide visibility. Ships as a CLI and a Docker-based GitHub Action that fires on issue / pull_request / pull_request_review events.", - "category": ["ingestion", "github", "working-memory", "shared-memory", "engineering", "provenance"], - "maintainer": { - "github": "@haroldboom", - "contact": "spangers11@gmail.com" - }, - "repo": "https://github.com/haroldboom/github-dkg", - "commit": "b9c1edee9be4076f8e9d8e2a05c75aaa3fc8d0c1", - "license": "MIT", - "requiresDkgNodeVersion": ">=10.0.0-rc.1", - "memoryLayers": ["WM", "SWM"], - "v10PrimitivesUsed": ["ContextGraph", "Assertion", "KnowledgeAsset"], - "publicInterfacesUsed": ["http-api"], - "targetAgents": ["generic-CLI", "generic-HTTP"], - "install": { - "kind": "cli", - "package": "github-dkg", - "version": "0.1.1", - "binary": "github-dkg", - "envRequired": ["DKG_TOKEN", "DKG_BASE_URL", "DKG_CONTEXT_GRAPH", "GITHUB_TOKEN"], - "usageHint": "Bulk-ingest:\n github-dkg ingest owner/repo\nSingle item:\n github-dkg ingest-one owner/repo 42 --type issue\nSearch:\n github-dkg search \"query\"\nPromote WM→SWM:\n github-dkg promote \nAll commands accept --context-graph (or read $DKG_CONTEXT_GRAPH). Also ships as a Docker-based GitHub Action: haroldboom/github-dkg@v0.1.0." - }, - "security": { - "networkEgress": ["api.github.com"], - "writeAuthority": [ - "POST /api/memory/turn", - "POST /api/assertion/{name}/promote" - ], - "credentialsHandled": ["GITHUB_TOKEN"], - "notes": "Communicates with the local DKG node (HTTP, port 9200 by default) and the GitHub REST API at api.github.com. Writes Knowledge Assets to Working Memory by default; promotion to Shared Working Memory (POST /api/assertion/{name}/promote) is always explicit and never automatic — the bundled GitHub Action example workflow gates promotion on a PR label (`architecture-decision`) so the choice is the team's, not the integration's. PUBLISH (Verified Memory) is never called. GitHub rate-limit responses (403/429 with X-RateLimit-Remaining: 0) surface as a typed GitHubRateLimitError carrying the reset timestamp, so callers can back off rather than retry into a ban. 23/23 unit tests pass against the published wheel (verified in a fresh venv outside the source tree); GitHub Actions CI runs the suite on Python 3.10/3.11/3.12 for every push and PR. Verified compatible with DKG v10 rc.8 (latest at submission). No postinstall/preinstall scripts. Published to PyPI via `pypa/gh-action-pypi-publish@release/v1` with `attestations: true` under PyPI Trusted Publishing (workflow `publish.yml`, environment `pypi`) — wheel ships with a PEP-740 attestation signed by the GitHub Actions runner, fetchable at `https://pypi.org/integrity/github-dkg/0.1.1//provenance`." - }, - "trustTier": "community", - "designBrief": "https://github.com/haroldboom/github-dkg/blob/master/DESIGN_BRIEF.md", - "demo": "https://youtu.be/9Tgb4-OXGuk", - "promotionPath": "Issues, PRs, and review comments land in Working Memory as Knowledge Assets at ingest time. The integration exposes an explicit `promote` operation (CLI: `github-dkg promote `; programmatic: `GitHubDKGIngestor.promote(turn_uri)`) that calls POST /api/assertion/{name}/promote to graduate selected assets to Shared Working Memory — `examples/workflow.yml` shows the canonical gate (closed+merged PR + label `architecture-decision`). Verified Memory promotion is intentionally not automated by the package; a downstream Curator step (POST /api/shared-memory/publish) anchors team-validated decisions on-chain when warranted, at which point those assets become consumable by context oracles for downstream agents reasoning about the project's history.", - "fitNotes": "Targets the auto-research direction by closing the loop on engineering tacit knowledge: issue threads, PR descriptions, and review comments — the highest-signal substrate inside any software organisation — become first-class, attributable, queryable assets on the DKG. Pairs naturally with langchain-dkg (sister Round 1 submission, also under the haroldboom account): github-dkg writes the substrate, langchain-dkg gives any LangChain agent persistent memory backed by it." -} From 0d0ff75943525ee5b11c75663e64cb8200b7f2ae Mon Sep 17 00:00:00 2001 From: haroldboom Date: Mon, 15 Jun 2026 13:36:29 +1000 Subject: [PATCH 08/20] langchain-dkg: pin v0.1.4 (security: langchain-core>=1.3.3, CVE-2026-44843) Co-Authored-By: Claude Opus 4.8 --- integrations/langchain-dkg.json | 6 +++--- 1 file changed, 3 insertions(+), 3 deletions(-) diff --git a/integrations/langchain-dkg.json b/integrations/langchain-dkg.json index 8318e0b..629d449 100644 --- a/integrations/langchain-dkg.json +++ b/integrations/langchain-dkg.json @@ -10,7 +10,7 @@ "contact": "spangers11@gmail.com" }, "repo": "https://github.com/haroldboom/dkg-langchain", - "commit": "b4afb7a4edd07c927e9dc92297a43a62d26901cb", + "commit": "f84ecf60227818fcb74067abd4014cb43921921a", "license": "MIT", "requiresDkgNodeVersion": ">=10.0.0", "memoryLayers": ["WM", "SWM"], @@ -21,7 +21,7 @@ "install": { "kind": "manual", "docsUrl": "https://github.com/haroldboom/dkg-langchain#readme", - "oneLiner": "pip install langchain-dkg==0.1.3 — then set DKG_API_URL and DKG_TOKEN and import DKGChatMessageHistory, DKGMemory, or DKGRetriever." + "oneLiner": "pip install langchain-dkg==0.1.4 — then set DKG_API_URL and DKG_TOKEN and import DKGChatMessageHistory, DKGMemory, or DKGRetriever." }, "security": { @@ -31,7 +31,7 @@ "POST /api/assertion/{name}/promote" ], "credentialsHandled": [], - "notes": "Communicates only with the local DKG node (default localhost:9200) — no external network egress. Credentials are read from the DKG_TOKEN environment variable or passed explicitly to DKGClient; never hardcoded. POST /api/memory/turn stores conversation turns as Knowledge Assets in Working Memory. POST /api/assertion/{name}/promote is a Curator-authority SHARE operation that moves a turn to Shared Working Memory; this is always explicit and agent-initiated, never automatic. No Verified Memory (PUBLISH) operations are performed. 25/25 unit tests pass against the published wheel (verified in a fresh venv outside the source tree); GitHub Actions CI runs the suite on Python 3.10/3.11/3.12 for every push and PR. The package has no postinstall, install, or preinstall scripts. Published to PyPI via `pypa/gh-action-pypi-publish@release/v1` with `attestations: true` under PyPI Trusted Publishing (workflow `publish.yml`, environment `pypi`) — wheel ships with a PEP-740 attestation signed by the GitHub Actions runner, fetchable at `https://pypi.org/integrity/langchain-dkg/0.1.3//provenance`. Verified compatible with dkg SDK 8.1.1rc2 (2026-06-09)." + "notes": "Communicates only with the local DKG node (default localhost:9200) — no external network egress. Credentials are read from the DKG_TOKEN environment variable or passed explicitly to DKGClient; never hardcoded. POST /api/memory/turn stores conversation turns as Knowledge Assets in Working Memory. POST /api/assertion/{name}/promote is a Curator-authority SHARE operation that moves a turn to Shared Working Memory; this is always explicit and agent-initiated, never automatic. No Verified Memory (PUBLISH) operations are performed. 25/25 unit tests pass against the published wheel (verified in a fresh venv outside the source tree); GitHub Actions CI runs the suite on Python 3.10/3.11/3.12 for every push and PR. The package has no postinstall, install, or preinstall scripts. Published to PyPI via `pypa/gh-action-pypi-publish@release/v1` with `attestations: true` under PyPI Trusted Publishing (workflow `publish.yml`, environment `pypi`) — wheel ships with a PEP-740 attestation signed by the GitHub Actions runner, fetchable at `https://pypi.org/integrity/langchain-dkg/0.1.4//provenance`. Verified compatible with dkg SDK 8.1.1rc2 (2026-06-09). v0.1.4 (2026-06-15) is a security-hardening release: the `langchain-core` dependency floor was raised from `>=0.2.0` to `>=1.3.3` so installs cannot resolve a version affected by CVE-2026-44843 (fixed upstream in langchain-core 0.3.85 / 1.3.3); no source/API changes, 25/25 unit tests green against langchain-core 1.4.7." }, "trustTier": "community", From d9bddbccf6a16abae3fd98307d4c29f345190702 Mon Sep 17 00:00:00 2001 From: haroldboom Date: Fri, 19 Jun 2026 14:12:50 +1000 Subject: [PATCH 09/20] langchain-dkg: bump pin to v0.1.5 (verified against DKG v10 node rc.17) Co-Authored-By: Claude Opus 4.8 --- integrations/langchain-dkg.json | 6 +++--- 1 file changed, 3 insertions(+), 3 deletions(-) diff --git a/integrations/langchain-dkg.json b/integrations/langchain-dkg.json index 629d449..98a50ff 100644 --- a/integrations/langchain-dkg.json +++ b/integrations/langchain-dkg.json @@ -10,7 +10,7 @@ "contact": "spangers11@gmail.com" }, "repo": "https://github.com/haroldboom/dkg-langchain", - "commit": "f84ecf60227818fcb74067abd4014cb43921921a", + "commit": "ba48662604f5a1021afce205d49c8be8a8e882a2", "license": "MIT", "requiresDkgNodeVersion": ">=10.0.0", "memoryLayers": ["WM", "SWM"], @@ -21,7 +21,7 @@ "install": { "kind": "manual", "docsUrl": "https://github.com/haroldboom/dkg-langchain#readme", - "oneLiner": "pip install langchain-dkg==0.1.4 — then set DKG_API_URL and DKG_TOKEN and import DKGChatMessageHistory, DKGMemory, or DKGRetriever." + "oneLiner": "pip install langchain-dkg==0.1.5 — then set DKG_API_URL and DKG_TOKEN and import DKGChatMessageHistory, DKGMemory, or DKGRetriever." }, "security": { @@ -31,7 +31,7 @@ "POST /api/assertion/{name}/promote" ], "credentialsHandled": [], - "notes": "Communicates only with the local DKG node (default localhost:9200) — no external network egress. Credentials are read from the DKG_TOKEN environment variable or passed explicitly to DKGClient; never hardcoded. POST /api/memory/turn stores conversation turns as Knowledge Assets in Working Memory. POST /api/assertion/{name}/promote is a Curator-authority SHARE operation that moves a turn to Shared Working Memory; this is always explicit and agent-initiated, never automatic. No Verified Memory (PUBLISH) operations are performed. 25/25 unit tests pass against the published wheel (verified in a fresh venv outside the source tree); GitHub Actions CI runs the suite on Python 3.10/3.11/3.12 for every push and PR. The package has no postinstall, install, or preinstall scripts. Published to PyPI via `pypa/gh-action-pypi-publish@release/v1` with `attestations: true` under PyPI Trusted Publishing (workflow `publish.yml`, environment `pypi`) — wheel ships with a PEP-740 attestation signed by the GitHub Actions runner, fetchable at `https://pypi.org/integrity/langchain-dkg/0.1.4//provenance`. Verified compatible with dkg SDK 8.1.1rc2 (2026-06-09). v0.1.4 (2026-06-15) is a security-hardening release: the `langchain-core` dependency floor was raised from `>=0.2.0` to `>=1.3.3` so installs cannot resolve a version affected by CVE-2026-44843 (fixed upstream in langchain-core 0.3.85 / 1.3.3); no source/API changes, 25/25 unit tests green against langchain-core 1.4.7." + "notes": "Communicates only with the local DKG node (default localhost:9200) — no external network egress. Credentials are read from the DKG_TOKEN environment variable or passed explicitly to DKGClient; never hardcoded. POST /api/memory/turn stores conversation turns as Knowledge Assets in Working Memory. POST /api/assertion/{name}/promote is a Curator-authority SHARE operation that moves a turn to Shared Working Memory; this is always explicit and agent-initiated, never automatic. No Verified Memory (PUBLISH) operations are performed. 25/25 unit tests pass against the published wheel (verified in a fresh venv outside the source tree); GitHub Actions CI runs the suite on Python 3.10/3.11/3.12 for every push and PR. The package has no postinstall, install, or preinstall scripts. Published to PyPI via `pypa/gh-action-pypi-publish@release/v1` with `attestations: true` under PyPI Trusted Publishing (workflow `publish.yml`, environment `pypi`) — wheel ships with a PEP-740 attestation signed by the GitHub Actions runner, fetchable at `https://pypi.org/integrity/langchain-dkg/0.1.5//provenance`. v0.1.4 (2026-06-15) was a security-hardening release: the `langchain-core` dependency floor was raised from `>=0.2.0` to `>=1.3.3` so installs cannot resolve a version affected by CVE-2026-44843 (fixed upstream in langchain-core 0.3.85 / 1.3.3); no source/API changes, 25/25 unit tests green against langchain-core 1.4.7. v0.1.5 (2026-06-19) verifies compatibility with the DKG v10 node at 10.0.0-rc.17: the rc.2→rc.17 node changelog was reviewed for every HTTP endpoint this adapter calls (POST /api/context-graph/create, /api/memory/turn, /api/memory/search, /api/assertion/{name}/{write,promote,history}, /api/query) — the only request-shape change in that window (rc.12 dropping the deprecated participantIdentityIds/requiredSignatures from context-graph/create) is already non-breaking here; no source/API changes, 25/25 unit tests green." }, "trustTier": "community", From 5bcec817bed844176e91e688f809ffb4952adf8c Mon Sep 17 00:00:00 2001 From: haroldboom Date: Tue, 23 Jun 2026 08:05:42 +1000 Subject: [PATCH 10/20] =?UTF-8?q?langchain-dkg:=20pin=20v0.1.6=20=E2=80=94?= =?UTF-8?q?=20verified=20compatible=20with=20DKG=20v10=20node=20rc.19?= MIME-Version: 1.0 Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 8bit --- integrations/langchain-dkg.json | 6 +++--- 1 file changed, 3 insertions(+), 3 deletions(-) diff --git a/integrations/langchain-dkg.json b/integrations/langchain-dkg.json index 98a50ff..073a448 100644 --- a/integrations/langchain-dkg.json +++ b/integrations/langchain-dkg.json @@ -10,7 +10,7 @@ "contact": "spangers11@gmail.com" }, "repo": "https://github.com/haroldboom/dkg-langchain", - "commit": "ba48662604f5a1021afce205d49c8be8a8e882a2", + "commit": "36046ae712cc17d7351fa6eb9bc635c2dfd43f1c", "license": "MIT", "requiresDkgNodeVersion": ">=10.0.0", "memoryLayers": ["WM", "SWM"], @@ -21,7 +21,7 @@ "install": { "kind": "manual", "docsUrl": "https://github.com/haroldboom/dkg-langchain#readme", - "oneLiner": "pip install langchain-dkg==0.1.5 — then set DKG_API_URL and DKG_TOKEN and import DKGChatMessageHistory, DKGMemory, or DKGRetriever." + "oneLiner": "pip install langchain-dkg==0.1.6 — then set DKG_API_URL and DKG_TOKEN and import DKGChatMessageHistory, DKGMemory, or DKGRetriever." }, "security": { @@ -31,7 +31,7 @@ "POST /api/assertion/{name}/promote" ], "credentialsHandled": [], - "notes": "Communicates only with the local DKG node (default localhost:9200) — no external network egress. Credentials are read from the DKG_TOKEN environment variable or passed explicitly to DKGClient; never hardcoded. POST /api/memory/turn stores conversation turns as Knowledge Assets in Working Memory. POST /api/assertion/{name}/promote is a Curator-authority SHARE operation that moves a turn to Shared Working Memory; this is always explicit and agent-initiated, never automatic. No Verified Memory (PUBLISH) operations are performed. 25/25 unit tests pass against the published wheel (verified in a fresh venv outside the source tree); GitHub Actions CI runs the suite on Python 3.10/3.11/3.12 for every push and PR. The package has no postinstall, install, or preinstall scripts. Published to PyPI via `pypa/gh-action-pypi-publish@release/v1` with `attestations: true` under PyPI Trusted Publishing (workflow `publish.yml`, environment `pypi`) — wheel ships with a PEP-740 attestation signed by the GitHub Actions runner, fetchable at `https://pypi.org/integrity/langchain-dkg/0.1.5//provenance`. v0.1.4 (2026-06-15) was a security-hardening release: the `langchain-core` dependency floor was raised from `>=0.2.0` to `>=1.3.3` so installs cannot resolve a version affected by CVE-2026-44843 (fixed upstream in langchain-core 0.3.85 / 1.3.3); no source/API changes, 25/25 unit tests green against langchain-core 1.4.7. v0.1.5 (2026-06-19) verifies compatibility with the DKG v10 node at 10.0.0-rc.17: the rc.2→rc.17 node changelog was reviewed for every HTTP endpoint this adapter calls (POST /api/context-graph/create, /api/memory/turn, /api/memory/search, /api/assertion/{name}/{write,promote,history}, /api/query) — the only request-shape change in that window (rc.12 dropping the deprecated participantIdentityIds/requiredSignatures from context-graph/create) is already non-breaking here; no source/API changes, 25/25 unit tests green." + "notes": "Communicates only with the local DKG node (default localhost:9200) — no external network egress. Credentials are read from the DKG_TOKEN environment variable or passed explicitly to DKGClient; never hardcoded. POST /api/memory/turn stores conversation turns as Knowledge Assets in Working Memory. POST /api/assertion/{name}/promote is a Curator-authority SHARE operation that moves a turn to Shared Working Memory; this is always explicit and agent-initiated, never automatic. No Verified Memory (PUBLISH) operations are performed. 25/25 unit tests pass against the published wheel (verified in a fresh venv outside the source tree); GitHub Actions CI runs the suite on Python 3.10/3.11/3.12 for every push and PR. The package has no postinstall, install, or preinstall scripts. Published to PyPI via `pypa/gh-action-pypi-publish@release/v1` with `attestations: true` under PyPI Trusted Publishing (workflow `publish.yml`, environment `pypi`) — wheel ships with a PEP-740 attestation signed by the GitHub Actions runner, fetchable at `https://pypi.org/integrity/langchain-dkg/0.1.6//provenance`. v0.1.4 (2026-06-15) was a security-hardening release: the `langchain-core` dependency floor was raised from `>=0.2.0` to `>=1.3.3` so installs cannot resolve a version affected by CVE-2026-44843 (fixed upstream in langchain-core 0.3.85 / 1.3.3); no source/API changes, 25/25 unit tests green against langchain-core 1.4.7. v0.1.5 (2026-06-19) verifies compatibility with the DKG v10 node at 10.0.0-rc.17: the rc.2→rc.17 node changelog was reviewed for every HTTP endpoint this adapter calls (POST /api/context-graph/create, /api/memory/turn, /api/memory/search, /api/assertion/{name}/{write,promote,history}, /api/query) — the only request-shape change in that window (rc.12 dropping the deprecated participantIdentityIds/requiredSignatures from context-graph/create) is already non-breaking here; no source/API changes, 25/25 unit tests green. v0.1.6 (2026-06-23) verifies compatibility with the DKG v10 node at 10.0.0-rc.19: every daemon route this adapter calls was diffed across rc.17→rc.18→rc.19 — /api/memory/turn, /api/memory/search, /api/query and GET /api/agents are byte-identical; /api/context-graph/create gained an additive `contextGraphId` alias for `id` (#1102, backward-compatible); the opt-in SHARE paths /api/shared-memory/{write,publish} and /api/assertion/* gained only optional parameters and new 503 CURATOR_UNCONFIRMED / 409 CURATOR_REJECTED error codes (OT-RFC-49), leaving every existing request contract intact; no source/API changes, 25/25 unit tests green." }, "trustTier": "community", From 9ab2359e91689bb79fc600ca0a867d2406895f9c Mon Sep 17 00:00:00 2001 From: haroldboom Date: Tue, 23 Jun 2026 08:06:41 +1000 Subject: [PATCH 11/20] langchain-dkg: trim security.notes under 2000-char schema limit --- integrations/langchain-dkg.json | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/integrations/langchain-dkg.json b/integrations/langchain-dkg.json index 073a448..2699d3a 100644 --- a/integrations/langchain-dkg.json +++ b/integrations/langchain-dkg.json @@ -31,7 +31,7 @@ "POST /api/assertion/{name}/promote" ], "credentialsHandled": [], - "notes": "Communicates only with the local DKG node (default localhost:9200) — no external network egress. Credentials are read from the DKG_TOKEN environment variable or passed explicitly to DKGClient; never hardcoded. POST /api/memory/turn stores conversation turns as Knowledge Assets in Working Memory. POST /api/assertion/{name}/promote is a Curator-authority SHARE operation that moves a turn to Shared Working Memory; this is always explicit and agent-initiated, never automatic. No Verified Memory (PUBLISH) operations are performed. 25/25 unit tests pass against the published wheel (verified in a fresh venv outside the source tree); GitHub Actions CI runs the suite on Python 3.10/3.11/3.12 for every push and PR. The package has no postinstall, install, or preinstall scripts. Published to PyPI via `pypa/gh-action-pypi-publish@release/v1` with `attestations: true` under PyPI Trusted Publishing (workflow `publish.yml`, environment `pypi`) — wheel ships with a PEP-740 attestation signed by the GitHub Actions runner, fetchable at `https://pypi.org/integrity/langchain-dkg/0.1.6//provenance`. v0.1.4 (2026-06-15) was a security-hardening release: the `langchain-core` dependency floor was raised from `>=0.2.0` to `>=1.3.3` so installs cannot resolve a version affected by CVE-2026-44843 (fixed upstream in langchain-core 0.3.85 / 1.3.3); no source/API changes, 25/25 unit tests green against langchain-core 1.4.7. v0.1.5 (2026-06-19) verifies compatibility with the DKG v10 node at 10.0.0-rc.17: the rc.2→rc.17 node changelog was reviewed for every HTTP endpoint this adapter calls (POST /api/context-graph/create, /api/memory/turn, /api/memory/search, /api/assertion/{name}/{write,promote,history}, /api/query) — the only request-shape change in that window (rc.12 dropping the deprecated participantIdentityIds/requiredSignatures from context-graph/create) is already non-breaking here; no source/API changes, 25/25 unit tests green. v0.1.6 (2026-06-23) verifies compatibility with the DKG v10 node at 10.0.0-rc.19: every daemon route this adapter calls was diffed across rc.17→rc.18→rc.19 — /api/memory/turn, /api/memory/search, /api/query and GET /api/agents are byte-identical; /api/context-graph/create gained an additive `contextGraphId` alias for `id` (#1102, backward-compatible); the opt-in SHARE paths /api/shared-memory/{write,publish} and /api/assertion/* gained only optional parameters and new 503 CURATOR_UNCONFIRMED / 409 CURATOR_REJECTED error codes (OT-RFC-49), leaving every existing request contract intact; no source/API changes, 25/25 unit tests green." + "notes": "Communicates only with the local DKG node (default localhost:9200) — no external network egress. Credentials are read from the DKG_TOKEN environment variable or passed explicitly to DKGClient; never hardcoded. POST /api/memory/turn stores conversation turns as Knowledge Assets in Working Memory. POST /api/assertion/{name}/promote is a Curator-authority SHARE operation that moves a turn to Shared Working Memory; this is always explicit and agent-initiated, never automatic. No Verified Memory (PUBLISH) operations are performed. 25/25 unit tests pass against the published wheel (verified in a fresh venv outside the source tree); GitHub Actions CI runs the suite on Python 3.10/3.11/3.12 for every push and PR. The package has no postinstall, install, or preinstall scripts. Published to PyPI via `pypa/gh-action-pypi-publish@release/v1` with `attestations: true` under PyPI Trusted Publishing (workflow `publish.yml`, environment `pypi`) — wheel ships with a PEP-740 attestation signed by the GitHub Actions runner, fetchable at `https://pypi.org/integrity/langchain-dkg/0.1.6//provenance`. Releases are verification-tracked against the DKG v10 node: v0.1.4 (2026-06-15) raised the langchain-core floor to >=1.3.3 to exclude CVE-2026-44843; v0.1.5 (2026-06-19) verified node rc.17; v0.1.6 (2026-06-23) verifies node rc.19 — every daemon route this adapter calls was diffed across rc.17→rc.18→rc.19, with /api/memory/turn, /api/memory/search, /api/query and GET /api/agents byte-identical, /api/context-graph/create gaining only an additive `contextGraphId` alias for `id` (#1102), and the opt-in SHARE paths /api/shared-memory/{write,publish} and /api/assertion/* gaining only optional parameters plus new 503 CURATOR_UNCONFIRMED / 409 CURATOR_REJECTED error codes (OT-RFC-49); existing request contracts unchanged, 25/25 unit tests green." }, "trustTier": "community", From 9160840b86e1818cf4090f7f453887a09ed7e1b6 Mon Sep 17 00:00:00 2001 From: haroldboom Date: Tue, 23 Jun 2026 08:55:58 +1000 Subject: [PATCH 12/20] =?UTF-8?q?langchain-dkg:=20pin=20v0.1.7=20=E2=80=94?= =?UTF-8?q?=20fix=20SHARE-path=20quad=20shape?= MIME-Version: 1.0 Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 8bit --- integrations/langchain-dkg.json | 6 +++--- 1 file changed, 3 insertions(+), 3 deletions(-) diff --git a/integrations/langchain-dkg.json b/integrations/langchain-dkg.json index 2699d3a..41cd505 100644 --- a/integrations/langchain-dkg.json +++ b/integrations/langchain-dkg.json @@ -10,7 +10,7 @@ "contact": "spangers11@gmail.com" }, "repo": "https://github.com/haroldboom/dkg-langchain", - "commit": "36046ae712cc17d7351fa6eb9bc635c2dfd43f1c", + "commit": "0a12230a7f45b22bd003ad29cd3776c82b62a2b5", "license": "MIT", "requiresDkgNodeVersion": ">=10.0.0", "memoryLayers": ["WM", "SWM"], @@ -21,7 +21,7 @@ "install": { "kind": "manual", "docsUrl": "https://github.com/haroldboom/dkg-langchain#readme", - "oneLiner": "pip install langchain-dkg==0.1.6 — then set DKG_API_URL and DKG_TOKEN and import DKGChatMessageHistory, DKGMemory, or DKGRetriever." + "oneLiner": "pip install langchain-dkg==0.1.7 — then set DKG_API_URL and DKG_TOKEN and import DKGChatMessageHistory, DKGMemory, or DKGRetriever." }, "security": { @@ -31,7 +31,7 @@ "POST /api/assertion/{name}/promote" ], "credentialsHandled": [], - "notes": "Communicates only with the local DKG node (default localhost:9200) — no external network egress. Credentials are read from the DKG_TOKEN environment variable or passed explicitly to DKGClient; never hardcoded. POST /api/memory/turn stores conversation turns as Knowledge Assets in Working Memory. POST /api/assertion/{name}/promote is a Curator-authority SHARE operation that moves a turn to Shared Working Memory; this is always explicit and agent-initiated, never automatic. No Verified Memory (PUBLISH) operations are performed. 25/25 unit tests pass against the published wheel (verified in a fresh venv outside the source tree); GitHub Actions CI runs the suite on Python 3.10/3.11/3.12 for every push and PR. The package has no postinstall, install, or preinstall scripts. Published to PyPI via `pypa/gh-action-pypi-publish@release/v1` with `attestations: true` under PyPI Trusted Publishing (workflow `publish.yml`, environment `pypi`) — wheel ships with a PEP-740 attestation signed by the GitHub Actions runner, fetchable at `https://pypi.org/integrity/langchain-dkg/0.1.6//provenance`. Releases are verification-tracked against the DKG v10 node: v0.1.4 (2026-06-15) raised the langchain-core floor to >=1.3.3 to exclude CVE-2026-44843; v0.1.5 (2026-06-19) verified node rc.17; v0.1.6 (2026-06-23) verifies node rc.19 — every daemon route this adapter calls was diffed across rc.17→rc.18→rc.19, with /api/memory/turn, /api/memory/search, /api/query and GET /api/agents byte-identical, /api/context-graph/create gaining only an additive `contextGraphId` alias for `id` (#1102), and the opt-in SHARE paths /api/shared-memory/{write,publish} and /api/assertion/* gaining only optional parameters plus new 503 CURATOR_UNCONFIRMED / 409 CURATOR_REJECTED error codes (OT-RFC-49); existing request contracts unchanged, 25/25 unit tests green." + "notes": "Communicates only with the local DKG node (default localhost:9200) — no external network egress. Credentials are read from the DKG_TOKEN environment variable or passed explicitly to DKGClient; never hardcoded. POST /api/memory/turn stores conversation turns as Knowledge Assets in Working Memory. POST /api/assertion/{name}/promote is a Curator-authority SHARE operation that moves a turn to Shared Working Memory; this is always explicit and agent-initiated, never automatic. No Verified Memory (PUBLISH) operations are performed. 30/30 unit tests pass against the published wheel (verified in a fresh venv outside the source tree); GitHub Actions CI runs the suite on Python 3.10/3.11/3.12 for every push and PR. The package has no postinstall, install, or preinstall scripts. Published to PyPI via `pypa/gh-action-pypi-publish@release/v1` with `attestations: true` under PyPI Trusted Publishing (workflow `publish.yml`, environment `pypi`) — wheel ships with a PEP-740 attestation signed by the GitHub Actions runner, fetchable at `https://pypi.org/integrity/langchain-dkg/0.1.7//provenance`. Releases are verification-tracked against the DKG v10 node: v0.1.4 raised the langchain-core floor to >=1.3.3 (CVE-2026-44843); v0.1.5 verified node rc.17; v0.1.6 (2026-06-23) verified node rc.19 — every daemon route this adapter calls was diffed across rc.17→rc.19, with the core endpoints (/api/memory/turn, /api/memory/search, /api/query, GET /api/agents) byte-identical and only additive changes to /api/context-graph/create (#1102 contextGraphId alias) and the opt-in SHARE paths (new optional params + 503/409 curator-ack codes, OT-RFC-49); contracts unchanged. v0.1.7 (2026-06-23) fixes shared_memory_write/assertion_write to send node-shaped quad objects ({subject,predicate,object}), required since rc.19; 30/30 unit tests green." }, "trustTier": "community", From 141129c2a301f1df9073b3b755969fefc75830a6 Mon Sep 17 00:00:00 2001 From: haroldboom Date: Tue, 23 Jun 2026 09:01:48 +1000 Subject: [PATCH 13/20] =?UTF-8?q?langchain-dkg:=20pin=20v0.1.8=20=E2=80=94?= =?UTF-8?q?=20typed=20CuratorAckError=20mapping?= MIME-Version: 1.0 Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 8bit --- integrations/langchain-dkg.json | 6 +++--- 1 file changed, 3 insertions(+), 3 deletions(-) diff --git a/integrations/langchain-dkg.json b/integrations/langchain-dkg.json index 41cd505..4cf9590 100644 --- a/integrations/langchain-dkg.json +++ b/integrations/langchain-dkg.json @@ -10,7 +10,7 @@ "contact": "spangers11@gmail.com" }, "repo": "https://github.com/haroldboom/dkg-langchain", - "commit": "0a12230a7f45b22bd003ad29cd3776c82b62a2b5", + "commit": "e0fb1e73152b62f029238fbdd276a99555256bd3", "license": "MIT", "requiresDkgNodeVersion": ">=10.0.0", "memoryLayers": ["WM", "SWM"], @@ -21,7 +21,7 @@ "install": { "kind": "manual", "docsUrl": "https://github.com/haroldboom/dkg-langchain#readme", - "oneLiner": "pip install langchain-dkg==0.1.7 — then set DKG_API_URL and DKG_TOKEN and import DKGChatMessageHistory, DKGMemory, or DKGRetriever." + "oneLiner": "pip install langchain-dkg==0.1.8 — then set DKG_API_URL and DKG_TOKEN and import DKGChatMessageHistory, DKGMemory, or DKGRetriever." }, "security": { @@ -31,7 +31,7 @@ "POST /api/assertion/{name}/promote" ], "credentialsHandled": [], - "notes": "Communicates only with the local DKG node (default localhost:9200) — no external network egress. Credentials are read from the DKG_TOKEN environment variable or passed explicitly to DKGClient; never hardcoded. POST /api/memory/turn stores conversation turns as Knowledge Assets in Working Memory. POST /api/assertion/{name}/promote is a Curator-authority SHARE operation that moves a turn to Shared Working Memory; this is always explicit and agent-initiated, never automatic. No Verified Memory (PUBLISH) operations are performed. 30/30 unit tests pass against the published wheel (verified in a fresh venv outside the source tree); GitHub Actions CI runs the suite on Python 3.10/3.11/3.12 for every push and PR. The package has no postinstall, install, or preinstall scripts. Published to PyPI via `pypa/gh-action-pypi-publish@release/v1` with `attestations: true` under PyPI Trusted Publishing (workflow `publish.yml`, environment `pypi`) — wheel ships with a PEP-740 attestation signed by the GitHub Actions runner, fetchable at `https://pypi.org/integrity/langchain-dkg/0.1.7//provenance`. Releases are verification-tracked against the DKG v10 node: v0.1.4 raised the langchain-core floor to >=1.3.3 (CVE-2026-44843); v0.1.5 verified node rc.17; v0.1.6 (2026-06-23) verified node rc.19 — every daemon route this adapter calls was diffed across rc.17→rc.19, with the core endpoints (/api/memory/turn, /api/memory/search, /api/query, GET /api/agents) byte-identical and only additive changes to /api/context-graph/create (#1102 contextGraphId alias) and the opt-in SHARE paths (new optional params + 503/409 curator-ack codes, OT-RFC-49); contracts unchanged. v0.1.7 (2026-06-23) fixes shared_memory_write/assertion_write to send node-shaped quad objects ({subject,predicate,object}), required since rc.19; 30/30 unit tests green." + "notes": "Communicates only with the local DKG node (default localhost:9200) — no external network egress. Credentials are read from the DKG_TOKEN environment variable or passed explicitly to DKGClient; never hardcoded. POST /api/memory/turn stores conversation turns as Knowledge Assets in Working Memory. POST /api/assertion/{name}/promote is a Curator-authority SHARE operation that moves a turn to Shared Working Memory; this is always explicit and agent-initiated, never automatic. No Verified Memory (PUBLISH) operations are performed. 34/34 unit tests pass against the published wheel (verified in a fresh venv outside the source tree); GitHub Actions CI runs the suite on Python 3.10/3.11/3.12 for every push and PR. The package has no postinstall, install, or preinstall scripts. Published to PyPI via `pypa/gh-action-pypi-publish@release/v1` with `attestations: true` under PyPI Trusted Publishing (workflow `publish.yml`, environment `pypi`) — wheel ships with a PEP-740 attestation signed by the GitHub Actions runner, fetchable at `https://pypi.org/integrity/langchain-dkg/0.1.8//provenance`. Releases are verification-tracked against the DKG v10 node: v0.1.4 raised the langchain-core floor to >=1.3.3 (CVE-2026-44843); v0.1.5 verified node rc.17; v0.1.6 (2026-06-23) verified node rc.19 — every daemon route this adapter calls was diffed across rc.17→rc.19, with the core endpoints (/api/memory/turn, /api/memory/search, /api/query, GET /api/agents) byte-identical and only additive changes to /api/context-graph/create (#1102 contextGraphId alias) and the opt-in SHARE paths (new optional params + 503/409 curator-ack codes, OT-RFC-49); contracts unchanged. v0.1.7 fixes shared_memory_write/assertion_write to send node-shaped quad objects ({subject,predicate,object}), required since rc.19. v0.1.8 (2026-06-23) maps the SHARE-path 503/409 curator-ack responses to typed CuratorUnconfirmedError/CuratorRejectedError; 34/34 unit tests green." }, "trustTier": "community", From 6f35abaf7bebf5082e02547ff9ec1f667f38a822 Mon Sep 17 00:00:00 2001 From: haroldboom <42967743+haroldboom@users.noreply.github.com> Date: Sat, 4 Jul 2026 09:00:25 +1000 Subject: [PATCH 14/20] Update demo link to the narrated walkthrough video Co-Authored-By: Claude Fable 5 Claude-Session: https://claude.ai/code/session_014WX6oMeJNANvj2sCg8rP57 --- integrations/langchain-dkg.json | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/integrations/langchain-dkg.json b/integrations/langchain-dkg.json index 4cf9590..f039574 100644 --- a/integrations/langchain-dkg.json +++ b/integrations/langchain-dkg.json @@ -37,7 +37,7 @@ "trustTier": "community", "designBrief": "https://github.com/haroldboom/dkg-langchain/blob/master/DESIGN_BRIEF.md", - "demo": "https://youtu.be/0XVYrikAZFQ", + "demo": "https://youtu.be/7VEjDqflEpc", "promotionPath": "Every conversation turn stored via DKGChatMessageHistory returns a turnUri (UAL). The agent can call promote_to_shared(turn_uri) to SHARE the Knowledge Asset from Working Memory to Shared Working Memory via POST /api/assertion/{name}/promote — promotion is always explicit. From Shared Working Memory, a future PUBLISH call (Round 2 scope) moves the Context Graph to Verified Memory on-chain, preserving the full UAL provenance chain from original turn through to the paranet record. DKGRetriever queries the same WM/SWM graph via SPARQL SELECT, so promoted artifacts are immediately available as RAG context for downstream agents.", "fitNotes": "Directly targets the LLM-Wiki / autoresearch direction: LangChain agents are the dominant production consumer of external memory systems, and this adapter maps Karpathy's memory taxonomy (in-context, external, team, long-term) onto the DKG v10 layer model (WM, SWM, VM). DKGRetriever is a drop-in BaseRetriever for any LangChain RAG pipeline, giving any autoresearch-style agent a verifiable, attributable upstream knowledge source." } From 4d3d5ced8734e964ed5e04addf65f81e29c74d76 Mon Sep 17 00:00:00 2001 From: haroldboom <42967743+haroldboom@users.noreply.github.com> Date: Sat, 4 Jul 2026 10:10:53 +1000 Subject: [PATCH 15/20] Pin langchain-dkg to post-review commit 7019622 and document the hardening Co-Authored-By: Claude Fable 5 Claude-Session: https://claude.ai/code/session_014WX6oMeJNANvj2sCg8rP57 --- integrations/langchain-dkg.json | 38 +++++++++++++++++++++++---------- 1 file changed, 27 insertions(+), 11 deletions(-) diff --git a/integrations/langchain-dkg.json b/integrations/langchain-dkg.json index f039574..1487943 100644 --- a/integrations/langchain-dkg.json +++ b/integrations/langchain-dkg.json @@ -4,26 +4,44 @@ "slug": "langchain-dkg", "name": "LangChain DKG Adapter", "description": "LangChain memory and retriever components backed by OriginTrail DKG v10. Gives LangChain agents durable, verifiable, queryable memory — conversation history is stored as Knowledge Assets in Working Memory and retrieved via tri-modal search (vector + SPARQL + text).", - "category": ["working-memory", "retrieval", "python", "langchain", "rag"], + "category": [ + "working-memory", + "retrieval", + "python", + "langchain", + "rag" + ], "maintainer": { "github": "@haroldboom", "contact": "spangers11@gmail.com" }, "repo": "https://github.com/haroldboom/dkg-langchain", - "commit": "e0fb1e73152b62f029238fbdd276a99555256bd3", + "commit": "70196226d49cc4c253236817acd10f3bce574193", "license": "MIT", "requiresDkgNodeVersion": ">=10.0.0", - "memoryLayers": ["WM", "SWM"], - "v10PrimitivesUsed": ["UAL", "KnowledgeAsset", "ContextGraph", "Assertion"], - "publicInterfacesUsed": ["http-api"], - "targetAgents": ["AutoResearch", "generic-HTTP", "generic-CLI"], - + "memoryLayers": [ + "WM", + "SWM" + ], + "v10PrimitivesUsed": [ + "UAL", + "KnowledgeAsset", + "ContextGraph", + "Assertion" + ], + "publicInterfacesUsed": [ + "http-api" + ], + "targetAgents": [ + "AutoResearch", + "generic-HTTP", + "generic-CLI" + ], "install": { "kind": "manual", "docsUrl": "https://github.com/haroldboom/dkg-langchain#readme", "oneLiner": "pip install langchain-dkg==0.1.8 — then set DKG_API_URL and DKG_TOKEN and import DKGChatMessageHistory, DKGMemory, or DKGRetriever." }, - "security": { "networkEgress": [], "writeAuthority": [ @@ -31,11 +49,9 @@ "POST /api/assertion/{name}/promote" ], "credentialsHandled": [], - "notes": "Communicates only with the local DKG node (default localhost:9200) — no external network egress. Credentials are read from the DKG_TOKEN environment variable or passed explicitly to DKGClient; never hardcoded. POST /api/memory/turn stores conversation turns as Knowledge Assets in Working Memory. POST /api/assertion/{name}/promote is a Curator-authority SHARE operation that moves a turn to Shared Working Memory; this is always explicit and agent-initiated, never automatic. No Verified Memory (PUBLISH) operations are performed. 34/34 unit tests pass against the published wheel (verified in a fresh venv outside the source tree); GitHub Actions CI runs the suite on Python 3.10/3.11/3.12 for every push and PR. The package has no postinstall, install, or preinstall scripts. Published to PyPI via `pypa/gh-action-pypi-publish@release/v1` with `attestations: true` under PyPI Trusted Publishing (workflow `publish.yml`, environment `pypi`) — wheel ships with a PEP-740 attestation signed by the GitHub Actions runner, fetchable at `https://pypi.org/integrity/langchain-dkg/0.1.8//provenance`. Releases are verification-tracked against the DKG v10 node: v0.1.4 raised the langchain-core floor to >=1.3.3 (CVE-2026-44843); v0.1.5 verified node rc.17; v0.1.6 (2026-06-23) verified node rc.19 — every daemon route this adapter calls was diffed across rc.17→rc.19, with the core endpoints (/api/memory/turn, /api/memory/search, /api/query, GET /api/agents) byte-identical and only additive changes to /api/context-graph/create (#1102 contextGraphId alias) and the opt-in SHARE paths (new optional params + 503/409 curator-ack codes, OT-RFC-49); contracts unchanged. v0.1.7 fixes shared_memory_write/assertion_write to send node-shaped quad objects ({subject,predicate,object}), required since rc.19. v0.1.8 (2026-06-23) maps the SHARE-path 503/409 curator-ack responses to typed CuratorUnconfirmedError/CuratorRejectedError; 34/34 unit tests green." + "notes": "Communicates only with the local DKG node (default localhost:9200) — no external network egress. Credentials are read from the DKG_TOKEN environment variable or passed explicitly to DKGClient; never hardcoded. POST /api/memory/turn stores conversation turns as Knowledge Assets in Working Memory. POST /api/assertion/{name}/promote is a Curator-authority SHARE operation that moves a turn to Shared Working Memory; this is always explicit and agent-initiated, never automatic. No Verified Memory (PUBLISH) operations are performed. 34/34 unit tests pass against the published wheel (verified in a fresh venv outside the source tree); GitHub Actions CI runs the suite on Python 3.10/3.11/3.12 for every push and PR. The package has no postinstall, install, or preinstall scripts. Published to PyPI via `pypa/gh-action-pypi-publish@release/v1` with `attestations: true` under PyPI Trusted Publishing (workflow `publish.yml`, environment `pypi`) — wheel ships with a PEP-740 attestation signed by the GitHub Actions runner, fetchable at `https://pypi.org/integrity/langchain-dkg/0.1.8//provenance`. Releases are verification-tracked against the DKG v10 node: v0.1.4 raised the langchain-core floor to >=1.3.3 (CVE-2026-44843); v0.1.5 verified node rc.17; v0.1.6 (2026-06-23) verified node rc.19 — every daemon route this adapter calls was diffed across rc.17→rc.19, with the core endpoints (/api/memory/turn, /api/memory/search, /api/query, GET /api/agents) byte-identical and only additive changes to /api/context-graph/create (#1102 contextGraphId alias) and the opt-in SHARE paths (new optional params + 503/409 curator-ack codes, OT-RFC-49); contracts unchanged. v0.1.7 fixes shared_memory_write/assertion_write to send node-shaped quad objects ({subject,predicate,object}), required since rc.19. v0.1.8 (2026-06-23) maps the SHARE-path 503/409 curator-ack responses to typed CuratorUnconfirmedError/CuratorRejectedError; 34/34 unit tests green. Post-review hardening (commit 7019622, 2026-07-04, verified against node build 10.0.2): conversation turns now default to private Working Memory (layer=\"wm\") instead of the node's gossiped swm default; session-scoped history retrieval (client-side hasPart filter + chronological order); promote ported to the async knowledge-assets share job flow with legacy fallback; memory/search always sends explicit memoryLayers; typed DKGConnectionError/DKGStatusError wrap all transport errors; pooled HTTP client; 80 unit tests + ruff/mypy in CI; publish workflow now gated on tests and a tag/version check." }, - "trustTier": "community", - "designBrief": "https://github.com/haroldboom/dkg-langchain/blob/master/DESIGN_BRIEF.md", "demo": "https://youtu.be/7VEjDqflEpc", "promotionPath": "Every conversation turn stored via DKGChatMessageHistory returns a turnUri (UAL). The agent can call promote_to_shared(turn_uri) to SHARE the Knowledge Asset from Working Memory to Shared Working Memory via POST /api/assertion/{name}/promote — promotion is always explicit. From Shared Working Memory, a future PUBLISH call (Round 2 scope) moves the Context Graph to Verified Memory on-chain, preserving the full UAL provenance chain from original turn through to the paranet record. DKGRetriever queries the same WM/SWM graph via SPARQL SELECT, so promoted artifacts are immediately available as RAG context for downstream agents.", From 381deb96c49829339835e0076fd0423779e7ad4d Mon Sep 17 00:00:00 2001 From: haroldboom <42967743+haroldboom@users.noreply.github.com> Date: Sat, 4 Jul 2026 10:15:43 +1000 Subject: [PATCH 16/20] Point install at langchain-dkg 0.1.9 (published to PyPI) Co-Authored-By: Claude Fable 5 Claude-Session: https://claude.ai/code/session_014WX6oMeJNANvj2sCg8rP57 --- integrations/langchain-dkg.json | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/integrations/langchain-dkg.json b/integrations/langchain-dkg.json index 1487943..1ac961b 100644 --- a/integrations/langchain-dkg.json +++ b/integrations/langchain-dkg.json @@ -40,7 +40,7 @@ "install": { "kind": "manual", "docsUrl": "https://github.com/haroldboom/dkg-langchain#readme", - "oneLiner": "pip install langchain-dkg==0.1.8 — then set DKG_API_URL and DKG_TOKEN and import DKGChatMessageHistory, DKGMemory, or DKGRetriever." + "oneLiner": "pip install langchain-dkg==0.1.9 — then set DKG_API_URL and DKG_TOKEN and import DKGChatMessageHistory, DKGMemory, or DKGRetriever." }, "security": { "networkEgress": [], From 88df0b64505cd4f7eadf385a9c977b497dd80c1c Mon Sep 17 00:00:00 2001 From: haroldboom <42967743+haroldboom@users.noreply.github.com> Date: Sat, 4 Jul 2026 10:19:11 +1000 Subject: [PATCH 17/20] Condense security notes to the schema's 2000-char limit Co-Authored-By: Claude Fable 5 Claude-Session: https://claude.ai/code/session_014WX6oMeJNANvj2sCg8rP57 --- integrations/langchain-dkg.json | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/integrations/langchain-dkg.json b/integrations/langchain-dkg.json index 1ac961b..487494a 100644 --- a/integrations/langchain-dkg.json +++ b/integrations/langchain-dkg.json @@ -49,7 +49,7 @@ "POST /api/assertion/{name}/promote" ], "credentialsHandled": [], - "notes": "Communicates only with the local DKG node (default localhost:9200) — no external network egress. Credentials are read from the DKG_TOKEN environment variable or passed explicitly to DKGClient; never hardcoded. POST /api/memory/turn stores conversation turns as Knowledge Assets in Working Memory. POST /api/assertion/{name}/promote is a Curator-authority SHARE operation that moves a turn to Shared Working Memory; this is always explicit and agent-initiated, never automatic. No Verified Memory (PUBLISH) operations are performed. 34/34 unit tests pass against the published wheel (verified in a fresh venv outside the source tree); GitHub Actions CI runs the suite on Python 3.10/3.11/3.12 for every push and PR. The package has no postinstall, install, or preinstall scripts. Published to PyPI via `pypa/gh-action-pypi-publish@release/v1` with `attestations: true` under PyPI Trusted Publishing (workflow `publish.yml`, environment `pypi`) — wheel ships with a PEP-740 attestation signed by the GitHub Actions runner, fetchable at `https://pypi.org/integrity/langchain-dkg/0.1.8//provenance`. Releases are verification-tracked against the DKG v10 node: v0.1.4 raised the langchain-core floor to >=1.3.3 (CVE-2026-44843); v0.1.5 verified node rc.17; v0.1.6 (2026-06-23) verified node rc.19 — every daemon route this adapter calls was diffed across rc.17→rc.19, with the core endpoints (/api/memory/turn, /api/memory/search, /api/query, GET /api/agents) byte-identical and only additive changes to /api/context-graph/create (#1102 contextGraphId alias) and the opt-in SHARE paths (new optional params + 503/409 curator-ack codes, OT-RFC-49); contracts unchanged. v0.1.7 fixes shared_memory_write/assertion_write to send node-shaped quad objects ({subject,predicate,object}), required since rc.19. v0.1.8 (2026-06-23) maps the SHARE-path 503/409 curator-ack responses to typed CuratorUnconfirmedError/CuratorRejectedError; 34/34 unit tests green. Post-review hardening (commit 7019622, 2026-07-04, verified against node build 10.0.2): conversation turns now default to private Working Memory (layer=\"wm\") instead of the node's gossiped swm default; session-scoped history retrieval (client-side hasPart filter + chronological order); promote ported to the async knowledge-assets share job flow with legacy fallback; memory/search always sends explicit memoryLayers; typed DKGConnectionError/DKGStatusError wrap all transport errors; pooled HTTP client; 80 unit tests + ruff/mypy in CI; publish workflow now gated on tests and a tag/version check." + "notes": "Communicates only with the local DKG node (default localhost:9200) — no external network egress. Credentials come from the DKG_TOKEN env var or are passed explicitly to DKGClient; never hardcoded. POST /api/memory/turn stores conversation turns as Knowledge Assets; as of v0.1.9 turns default to private Working Memory (layer=\"wm\") — earlier versions deferred to the node default (swm, gossiped). SHARE promotion is always explicit and agent-initiated (async knowledge-assets share job on current nodes, legacy route fallback); no Verified Memory (PUBLISH) operations are performed. No postinstall scripts. Published to PyPI via pypa/gh-action-pypi-publish with attestations:true under Trusted Publishing (PEP-740 attestation per wheel); the publish workflow is gated on the unit-test suite and a tag/version check. 80/80 unit tests pass; CI runs ruff, mypy, and the suite on Python 3.10-3.13 for every push and PR. Releases are verification-tracked against the DKG v10 node: v0.1.4 raised the langchain-core floor for CVE-2026-44843; v0.1.5-v0.1.8 tracked node rc.17→rc.19 API drift (quad shapes, RFC-49 curator-ack codes mapped to typed errors). v0.1.9 (2026-07-04, verified against node build 10.0.2): session-scoped history retrieval, explicit memoryLayers on every search, knowledge-assets promote surface with legacy fallback, typed connection/status errors that never retain raw responses or bearer tokens, pooled HTTP client. Known 10.0.2 limitation documented in the README: /api/query cannot see wm-layer quads (RFC-29 gate fail-closed); memory/search covers private retrieval." }, "trustTier": "community", "designBrief": "https://github.com/haroldboom/dkg-langchain/blob/master/DESIGN_BRIEF.md", From ff9af5f8934ba16a4fc423c49491704dc973151d Mon Sep 17 00:00:00 2001 From: haroldboom <42967743+haroldboom@users.noreply.github.com> Date: Sat, 4 Jul 2026 11:08:57 +1000 Subject: [PATCH 18/20] Declare current write-authority endpoints Co-Authored-By: Claude Fable 5 Claude-Session: https://claude.ai/code/session_014WX6oMeJNANvj2sCg8rP57 --- integrations/langchain-dkg.json | 7 ++++++- 1 file changed, 6 insertions(+), 1 deletion(-) diff --git a/integrations/langchain-dkg.json b/integrations/langchain-dkg.json index 487494a..b2739ef 100644 --- a/integrations/langchain-dkg.json +++ b/integrations/langchain-dkg.json @@ -46,7 +46,12 @@ "networkEgress": [], "writeAuthority": [ "POST /api/memory/turn", - "POST /api/assertion/{name}/promote" + "POST /api/context-graph/create", + "POST /api/knowledge-assets (create named Knowledge Asset)", + "POST /api/knowledge-assets/{name}/swm/share-async (SHARE, Curator authority; legacy fallback POST /api/assertion/{name}/promote-async)", + "POST /api/assertion/{name}/write (WM quads, legacy route)", + "POST /api/shared-memory/write (SWM write, Curator authority)", + "POST /api/shared-memory/publish (PUBLISH, Curator authority — exposed on DKGClient only; never invoked by the LangChain components)" ], "credentialsHandled": [], "notes": "Communicates only with the local DKG node (default localhost:9200) — no external network egress. Credentials come from the DKG_TOKEN env var or are passed explicitly to DKGClient; never hardcoded. POST /api/memory/turn stores conversation turns as Knowledge Assets; as of v0.1.9 turns default to private Working Memory (layer=\"wm\") — earlier versions deferred to the node default (swm, gossiped). SHARE promotion is always explicit and agent-initiated (async knowledge-assets share job on current nodes, legacy route fallback); no Verified Memory (PUBLISH) operations are performed. No postinstall scripts. Published to PyPI via pypa/gh-action-pypi-publish with attestations:true under Trusted Publishing (PEP-740 attestation per wheel); the publish workflow is gated on the unit-test suite and a tag/version check. 80/80 unit tests pass; CI runs ruff, mypy, and the suite on Python 3.10-3.13 for every push and PR. Releases are verification-tracked against the DKG v10 node: v0.1.4 raised the langchain-core floor for CVE-2026-44843; v0.1.5-v0.1.8 tracked node rc.17→rc.19 API drift (quad shapes, RFC-49 curator-ack codes mapped to typed errors). v0.1.9 (2026-07-04, verified against node build 10.0.2): session-scoped history retrieval, explicit memoryLayers on every search, knowledge-assets promote surface with legacy fallback, typed connection/status errors that never retain raw responses or bearer tokens, pooled HTTP client. Known 10.0.2 limitation documented in the README: /api/query cannot see wm-layer quads (RFC-29 gate fail-closed); memory/search covers private retrieval." From 121b13dc170496bf41d0d4a300e8ce52c0d9297c Mon Sep 17 00:00:00 2001 From: haroldboom Date: Tue, 28 Jul 2026 01:17:13 +1000 Subject: [PATCH 19/20] langchain-dkg: note node 10.0.9 re-verification Co-Authored-By: Claude Fable 5 Claude-Session: https://claude.ai/code/session_01DFDL1JXjY9ctisNQRrMnwT --- integrations/langchain-dkg.json | 4 ++-- 1 file changed, 2 insertions(+), 2 deletions(-) diff --git a/integrations/langchain-dkg.json b/integrations/langchain-dkg.json index b2739ef..86a0e00 100644 --- a/integrations/langchain-dkg.json +++ b/integrations/langchain-dkg.json @@ -54,11 +54,11 @@ "POST /api/shared-memory/publish (PUBLISH, Curator authority — exposed on DKGClient only; never invoked by the LangChain components)" ], "credentialsHandled": [], - "notes": "Communicates only with the local DKG node (default localhost:9200) — no external network egress. Credentials come from the DKG_TOKEN env var or are passed explicitly to DKGClient; never hardcoded. POST /api/memory/turn stores conversation turns as Knowledge Assets; as of v0.1.9 turns default to private Working Memory (layer=\"wm\") — earlier versions deferred to the node default (swm, gossiped). SHARE promotion is always explicit and agent-initiated (async knowledge-assets share job on current nodes, legacy route fallback); no Verified Memory (PUBLISH) operations are performed. No postinstall scripts. Published to PyPI via pypa/gh-action-pypi-publish with attestations:true under Trusted Publishing (PEP-740 attestation per wheel); the publish workflow is gated on the unit-test suite and a tag/version check. 80/80 unit tests pass; CI runs ruff, mypy, and the suite on Python 3.10-3.13 for every push and PR. Releases are verification-tracked against the DKG v10 node: v0.1.4 raised the langchain-core floor for CVE-2026-44843; v0.1.5-v0.1.8 tracked node rc.17→rc.19 API drift (quad shapes, RFC-49 curator-ack codes mapped to typed errors). v0.1.9 (2026-07-04, verified against node build 10.0.2): session-scoped history retrieval, explicit memoryLayers on every search, knowledge-assets promote surface with legacy fallback, typed connection/status errors that never retain raw responses or bearer tokens, pooled HTTP client. Known 10.0.2 limitation documented in the README: /api/query cannot see wm-layer quads (RFC-29 gate fail-closed); memory/search covers private retrieval." + "notes": "Communicates only with the local DKG node (default localhost:9200) — no external network egress. Credentials come from the DKG_TOKEN env var or are passed explicitly to DKGClient; never hardcoded. POST /api/memory/turn stores conversation turns as Knowledge Assets; as of v0.1.9 turns default to private Working Memory (layer=\"wm\") — earlier versions deferred to the node default (swm, gossiped). SHARE promotion is always explicit and agent-initiated (async knowledge-assets share job on current nodes, legacy route fallback); no Verified Memory (PUBLISH) operations are performed. No postinstall scripts. Published to PyPI via pypa/gh-action-pypi-publish with attestations:true under Trusted Publishing (PEP-740 attestation per wheel); the publish workflow is gated on the unit-test suite and a tag/version check. 80/80 unit tests pass; CI runs ruff, mypy, and the suite on Python 3.10-3.13 for every push and PR. Releases are verification-tracked against the DKG v10 node: v0.1.4 raised the langchain-core floor for CVE-2026-44843; v0.1.5-v0.1.8 tracked node rc.17→rc.19 API drift (quad shapes, RFC-49 curator-ack codes mapped to typed errors). v0.1.9 (2026-07-04, verified against node build 10.0.2): session-scoped history retrieval, explicit memoryLayers on every search, knowledge-assets promote surface with legacy fallback, typed connection/status errors that never retain raw responses or bearer tokens, pooled HTTP client. Known 10.0.2 limitation documented in the README: /api/query cannot see wm-layer quads (RFC-29 gate fail-closed); memory/search covers private retrieval. Re-verified 2026-07-28 on node 10.0.9: 80/80 unit tests green against the published wheel in a fresh venv; memory/turn, memory/search, query, and the knowledge-assets promote surface validated live; 10.0.7's rootless Knowledge Asset change and its removal of the legacy /api/assertion/* aliases are both transparent to v0.1.9." }, "trustTier": "community", "designBrief": "https://github.com/haroldboom/dkg-langchain/blob/master/DESIGN_BRIEF.md", "demo": "https://youtu.be/7VEjDqflEpc", "promotionPath": "Every conversation turn stored via DKGChatMessageHistory returns a turnUri (UAL). The agent can call promote_to_shared(turn_uri) to SHARE the Knowledge Asset from Working Memory to Shared Working Memory via POST /api/assertion/{name}/promote — promotion is always explicit. From Shared Working Memory, a future PUBLISH call (Round 2 scope) moves the Context Graph to Verified Memory on-chain, preserving the full UAL provenance chain from original turn through to the paranet record. DKGRetriever queries the same WM/SWM graph via SPARQL SELECT, so promoted artifacts are immediately available as RAG context for downstream agents.", "fitNotes": "Directly targets the LLM-Wiki / autoresearch direction: LangChain agents are the dominant production consumer of external memory systems, and this adapter maps Karpathy's memory taxonomy (in-context, external, team, long-term) onto the DKG v10 layer model (WM, SWM, VM). DKGRetriever is a drop-in BaseRetriever for any LangChain RAG pipeline, giving any autoresearch-style agent a verifiable, attributable upstream knowledge source." -} +} \ No newline at end of file From 224cfb73a3f22fd2e5afa2ac44f078b5ac31f995 Mon Sep 17 00:00:00 2001 From: haroldboom Date: Tue, 28 Jul 2026 01:18:21 +1000 Subject: [PATCH 20/20] =?UTF-8?q?langchain-dkg:=20fix=20schema=20validatio?= =?UTF-8?q?n=20=E2=80=94=20legacy=20publish=20helper=20is=20a=20note,=20no?= =?UTF-8?q?t=20writeAuthority?= MIME-Version: 1.0 Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 8bit Co-Authored-By: Claude Fable 5 Claude-Session: https://claude.ai/code/session_01DFDL1JXjY9ctisNQRrMnwT --- integrations/langchain-dkg.json | 5 ++--- 1 file changed, 2 insertions(+), 3 deletions(-) diff --git a/integrations/langchain-dkg.json b/integrations/langchain-dkg.json index 86a0e00..b47db97 100644 --- a/integrations/langchain-dkg.json +++ b/integrations/langchain-dkg.json @@ -50,11 +50,10 @@ "POST /api/knowledge-assets (create named Knowledge Asset)", "POST /api/knowledge-assets/{name}/swm/share-async (SHARE, Curator authority; legacy fallback POST /api/assertion/{name}/promote-async)", "POST /api/assertion/{name}/write (WM quads, legacy route)", - "POST /api/shared-memory/write (SWM write, Curator authority)", - "POST /api/shared-memory/publish (PUBLISH, Curator authority — exposed on DKGClient only; never invoked by the LangChain components)" + "POST /api/shared-memory/write (SWM write, Curator authority)" ], "credentialsHandled": [], - "notes": "Communicates only with the local DKG node (default localhost:9200) — no external network egress. Credentials come from the DKG_TOKEN env var or are passed explicitly to DKGClient; never hardcoded. POST /api/memory/turn stores conversation turns as Knowledge Assets; as of v0.1.9 turns default to private Working Memory (layer=\"wm\") — earlier versions deferred to the node default (swm, gossiped). SHARE promotion is always explicit and agent-initiated (async knowledge-assets share job on current nodes, legacy route fallback); no Verified Memory (PUBLISH) operations are performed. No postinstall scripts. Published to PyPI via pypa/gh-action-pypi-publish with attestations:true under Trusted Publishing (PEP-740 attestation per wheel); the publish workflow is gated on the unit-test suite and a tag/version check. 80/80 unit tests pass; CI runs ruff, mypy, and the suite on Python 3.10-3.13 for every push and PR. Releases are verification-tracked against the DKG v10 node: v0.1.4 raised the langchain-core floor for CVE-2026-44843; v0.1.5-v0.1.8 tracked node rc.17→rc.19 API drift (quad shapes, RFC-49 curator-ack codes mapped to typed errors). v0.1.9 (2026-07-04, verified against node build 10.0.2): session-scoped history retrieval, explicit memoryLayers on every search, knowledge-assets promote surface with legacy fallback, typed connection/status errors that never retain raw responses or bearer tokens, pooled HTTP client. Known 10.0.2 limitation documented in the README: /api/query cannot see wm-layer quads (RFC-29 gate fail-closed); memory/search covers private retrieval. Re-verified 2026-07-28 on node 10.0.9: 80/80 unit tests green against the published wheel in a fresh venv; memory/turn, memory/search, query, and the knowledge-assets promote surface validated live; 10.0.7's rootless Knowledge Asset change and its removal of the legacy /api/assertion/* aliases are both transparent to v0.1.9." + "notes": "Communicates only with the local DKG node (default localhost:9200) — no external network egress. Credentials come from the DKG_TOKEN env var or are passed explicitly to DKGClient; never hardcoded. POST /api/memory/turn stores conversation turns as Knowledge Assets; as of v0.1.9 turns default to private Working Memory (layer=\"wm\") — earlier versions deferred to the node default (swm, gossiped). SHARE promotion is always explicit and agent-initiated (async knowledge-assets share job on current nodes, legacy route fallback); no Verified Memory (PUBLISH) operations are performed. No postinstall scripts. Published to PyPI via pypa/gh-action-pypi-publish with attestations:true under Trusted Publishing (PEP-740 attestation per wheel); the publish workflow is gated on the unit-test suite and a tag/version check. 80/80 unit tests pass; CI runs ruff, mypy, and the suite on Python 3.10-3.13 for every push and PR. Releases are verification-tracked against the DKG v10 node: v0.1.4 raised the langchain-core floor for CVE-2026-44843; v0.1.5-v0.1.8 tracked node rc.17→rc.19 API drift (quad shapes, RFC-49 curator-ack codes mapped to typed errors). v0.1.9 (2026-07-04): session-scoped history retrieval, explicit memoryLayers on every search, knowledge-assets promote surface with legacy fallback, typed errors that never retain raw responses or tokens, pooled HTTP client. README documents: /api/query cannot see wm-layer quads (RFC-29, fail-closed); memory/search covers private retrieval. Re-verified 2026-07-28 on node 10.0.9: 80/80 unit tests green against the published wheel in a fresh venv; memory/turn, memory/search, query, and the knowledge-assets promote surface validated live; 10.0.7's rootless Knowledge Asset change and its removal of the legacy /api/assertion/* aliases are both transparent to v0.1.9. DKGClient also exposes a legacy publish helper targeting POST /api/shared-memory/publish — never invoked by the LangChain components,; node 10.0.7+ removed the route." }, "trustTier": "community", "designBrief": "https://github.com/haroldboom/dkg-langchain/blob/master/DESIGN_BRIEF.md",