Roadmap
What is shipped and what comes next — the VS Code extension on the Marketplace, quick fixes, then cross-repository resolution.
Shipped
- Data-flow engine: workflows and local composite actions, nested reusable workflows, same-repository references.
- Exact matrix expansion and per-combination evaluation; declared shapes for runtime-computed matrices
(
matrixShapes). - 50 rules (
FP1xx–FP9xx) with stable codes, docs pages andflowpact explain. - Contracts:
flowpact generatewrites a deterministic lockfile per workflow and local action;flowpact checkreports missing, outdated, orphaned and invalid contracts and breaking interface changes (FP801–FP805), with agit apply-able patch for anyone who cannot run the CLI. - Overrides with a mandatory reason, an optional expiry date and owner; expired,
unused and soon-expiring overrides are reported (
FP901–FP903). - GitHub Action: job summary, pull request annotations, SARIF and the regenerated contracts as an artifact.
- CLI:
lint,check,generate,graph(tree, Mermaid, DOT, JSON),trace,explain,rules; pretty, JSON, Markdown and SARIF output; debug logging. - Plugins: organization-specific rules loaded from the config.
- Impact mode: for publishers of reusable workflows and actions — the release impact a pull
request declares (Conventional Commits title, labels or release version) is checked against what its changes
require, including the check names consumers' branch protection depends on (
FP810–FP814). - Language server (
flowpact lsp): diagnostics as you type across files, hover traces, go to definition across workflow calls, and references. - Config file, contracts and reports with published JSON Schemas.
In progress: editors
The language server brings the analysis into the editor. Still to come:
- The VS Code extension on the Marketplace and Open VSX. It works today when built from the repository.
- Quick fixes — add a missing input, remove an unused one, add the missing matrix key, regenerate contracts, or add an override with a reason prompt.
Later: cross-repository resolution
Reusable workflows called from other repositories (owner/repo/.github/workflows/x.yml@ref) are reported today as
unverified (FP603). Next, flowpact will resolve them — from published contracts or by fetching the referenced
workflow — so interfaces and breaking changes can be checked across repository boundaries.