flowpactworkflow contracts

Roadmap

What is shipped and what comes next — the VS Code extension on the Marketplace, quick fixes, then cross-repository resolution.

Shipped

  • Data-flow engine: workflows and local composite actions, nested reusable workflows, same-repository references.
  • Exact matrix expansion and per-combination evaluation; declared shapes for runtime-computed matrices (matrixShapes).
  • 50 rules (FP1xx–FP9xx) with stable codes, docs pages and flowpact explain.
  • Contracts: flowpact generate writes a deterministic lockfile per workflow and local action; flowpact check reports missing, outdated, orphaned and invalid contracts and breaking interface changes (FP801–FP805), with a git apply-able patch for anyone who cannot run the CLI.
  • Overrides with a mandatory reason, an optional expiry date and owner; expired, unused and soon-expiring overrides are reported (FP901–FP903).
  • GitHub Action: job summary, pull request annotations, SARIF and the regenerated contracts as an artifact.
  • CLI: lint, check, generate, graph (tree, Mermaid, DOT, JSON), trace, explain, rules; pretty, JSON, Markdown and SARIF output; debug logging.
  • Plugins: organization-specific rules loaded from the config.
  • Impact mode: for publishers of reusable workflows and actions — the release impact a pull request declares (Conventional Commits title, labels or release version) is checked against what its changes require, including the check names consumers' branch protection depends on (FP810–FP814).
  • Language server (flowpact lsp): diagnostics as you type across files, hover traces, go to definition across workflow calls, and references.
  • Config file, contracts and reports with published JSON Schemas.

In progress: editors

The language server brings the analysis into the editor. Still to come:

  • The VS Code extension on the Marketplace and Open VSX. It works today when built from the repository.
  • Quick fixes — add a missing input, remove an unused one, add the missing matrix key, regenerate contracts, or add an override with a reason prompt.

Later: cross-repository resolution

Reusable workflows called from other repositories (owner/repo/.github/workflows/x.yml@ref) are reported today as unverified (FP603). Next, flowpact will resolve them — from published contracts or by fetching the referenced workflow — so interfaces and breaking changes can be checked across repository boundaries.

On this page