diff --git a/.planning/phases/01-framework-kernel-foundation/01-RESEARCH.md b/.planning/phases/01-framework-kernel-foundation/01-RESEARCH.md index 2d14fa4..2a4e791 100644 --- a/.planning/phases/01-framework-kernel-foundation/01-RESEARCH.md +++ b/.planning/phases/01-framework-kernel-foundation/01-RESEARCH.md @@ -40,7 +40,22 @@ Build the first executable path through `examples/hello`: explicit `summer.yaml` | Watch | `github.com/fsnotify/fsnotify` | Observe app workspace directories and rebuild. | | Tests | `go test`, `go test -race`, `go vet`; `testify` only if helpful | Unit and example integration coverage. | -The context authorizes these dependencies. Resolve exact module tags during implementation and commit `go.sum`; do not use `@latest` in repeatable plan commands. The [koanf docs](https://pkg.go.dev/github.com/knadh/koanf/v2) confirm successive `Load` calls merge into the existing tree. The current [env/v2 provider](https://pkg.go.dev/github.com/knadh/koanf/providers/env/v2) has `Opt{Prefix, TransformFunc, EnvironFunc}` and can inject an environment source in tests. The earlier project STACK.md's unversioned env-provider example is a sketch, not a required import path. +The context authorizes these dependencies. Use checked module tags and commit `go.sum`; do not use `@latest` in repeatable plan commands. The [koanf docs](https://pkg.go.dev/github.com/knadh/koanf/v2) confirm successive `Load` calls merge into the existing tree. The current [env/v2 provider](https://pkg.go.dev/github.com/knadh/koanf/providers/env/v2) has `Opt{Prefix, TransformFunc, EnvironFunc}` and can inject an environment source in tests. The earlier project STACK.md's unversioned env-provider example is a sketch, not a required import path. + +### Package Legitimacy Audit + +All Phase 1 external packages below have live package pages and tagged module versions as of 2026-09-16; none is assumed. These are verified available tags, not a claim that no newer tag exists. + +| Module | Checked tag | Primary source | +|---|---|---| +| `github.com/knadh/koanf/v2` | `v2.3.6` | [pkg.go.dev](https://pkg.go.dev/github.com/knadh/koanf/v2) | +| `github.com/knadh/koanf/providers/file` | `v1.2.1` | [pkg.go.dev](https://pkg.go.dev/github.com/knadh/koanf/providers/file) | +| `github.com/knadh/koanf/providers/confmap` | `v1.0.1` | [pkg.go.dev](https://pkg.go.dev/github.com/knadh/koanf/providers/confmap) | +| `github.com/knadh/koanf/providers/env/v2` | `v2.0.1` | [pkg.go.dev](https://pkg.go.dev/github.com/knadh/koanf/providers/env/v2) | +| `github.com/knadh/koanf/parsers/yaml` | `v1.1.1` | [pkg.go.dev](https://pkg.go.dev/github.com/knadh/koanf/parsers/yaml) | +| `github.com/spf13/cobra` | `v1.10.2` | [pkg.go.dev](https://pkg.go.dev/github.com/spf13/cobra) | +| `github.com/fsnotify/fsnotify` | `v1.10.1` | [pkg.go.dev](https://pkg.go.dev/github.com/fsnotify/fsnotify) | +| `golang.org/x/term` | `v0.46.0` | [pkg.go.dev](https://pkg.go.dev/golang.org/x/term) |