Skip to content

refactor: rename Rho to Decoder and centralize version at 0.0.1 - #346

Open
Patel230 wants to merge 4 commits into
mainfrom
refactor/rename-mux-decoder
Open

Patel230 wants to merge 4 commits into
mainfrom
refactor/rename-mux-decoder

Conversation

@Patel230

@Patel230 Patel230 commented Oct 11, 2026 •

Copy link
Copy Markdown
Contributor

Summary

Rename Rho to Decoder end to end and integrate the renamed Mux provider runtime. Set the project version to the root VERSION value, embedded into standalone builds and reused for package/API metadata. Depends on GrayCodeAI/mux#127; merge Mux first. The dependency pins its signed commit e418cdb5eb919c9975c6a1ca8d59fb6b2f00d1e9 with matching module checksums.

Changes

  • Rename the module, CLI, Go identifiers, npm packaging, GitHub Actions, daemon/integrations, documentation and terminal wordmark to Decoder.
  • Move configuration, environment variables, state paths and keychain namespaces to Decoder; users must migrate state and reconfigure credentials for the new namespace.
  • Require Go 1.27.2 and use the new github.com/GrayCodeAI/mux module, with the checksum authenticated by the public Go proxy and checksum database.
  • Update Go analysis tools, replace the ineffective vulnerability JSON filter with the scanner's native exit status, and patch reachable HTTP/2, gRPC and telemetry advisories. Migrate telemetry value conversion to the patched SDK's attribute API.
  • Embed VERSION for CLI, MCP, daemon and telemetry defaults, including binaries run outside the checkout. Generate npm/package pins and OpenAPI metadata using make version-sync; CI rejects drift.
  • Reset the project version series to 0.0.1. Retain and reject known incompatible hawk-era install tags; use explicit Decoder tags or @main rather than relying on @latest while historical higher versions remain.

Testing

Three local verification rounds passed across both repositories: full builds and test compilation, targeted runtime tests, rename audits, version metadata checks, standalone CLI/version checks, SDK syntax/compilation, YAML/JSON parsing and boundary guards. Both the pinned CI formatter and the current local formatter pass. make lint, go vet and module checksum verification pass.

Both telemetry packages pass their complete race-test suites. The vulnerability scan against a local snapshot of the official Go vulnerability database reports zero reachable vulnerabilities (previously eight). Installer tests cover the reset version and legacy-tag rejection; standalone binaries report VERSION outside the checkout.

Final GitHub CI passed all 22 jobs on signed commit cc1d05578572445b16526fec34e899b3d2ddd033, including the full race/coverage suite, all nine fuzz targets, security scans, public module resolution, parity, API reference, smoke tests and six platform builds. Clean committed-tree verification also passed all 72 cross-repository checks. All eight commits across the two PRs have verified SSH signatures on GitHub.

Checklist

  • Commits follow Conventional Commits
  • make build passes
  • make lint passes
  • Full race test suite passes in GitHub CI (local full runtime tests require sockets/filesystem access denied by the sandbox)
  • New or changed code has relevant tests/validation
  • Public APIs have godoc comments
  • CHANGELOG updated under Unreleased
  • No secrets, tokens, or PII added
  • No Co-authored-by trailers

@Patel230
Patel230 marked this pull request as ready for review October 11, 2026 04:27
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant