0035
September 1, 2026 · View on GitHub
- Status: superseded by 0036
- Date: 2026-08-23
Context
0014 let every caller resolve public
@kody/* (and other platform-account) packages live, including saved packages
that statically imported or packages.invoked them. That made official package
exports a public API the operator had to keep stable: no semver
(0001), no pins
(0031), and packages.invoke of a
platform target is live on every job run.
Ad hoc execute is ephemeral. Agents rewrite. Saved packages, jobs, and apps are durable products.
Decision
Official platform packages are execute-only.
- Ad hoc
executemay statically import orpackages.invokea public platform scope. The modules still run in the caller's runtime against the caller's secrets. - Saved person-account packages must not statically import, declare, or
packages.invokea platform scope. Publish checks fail. Package, job, and app runtimes fail closed. Already-published person-package artifacts that recordedplatformOwneddependencies fail at run time. No compatibility lane. - To use official helpers in a durable package,
communityForkinto the caller's scope and depend on that copy. Fork rewrite maps same-package@kody/nameself-imports onto the new owner; remaining@kody/otherreferences stay foreign and must be forked too. - Platform-account packages may still compose with each other when the operator publishes them.
Consequences
The operator can change official package exports without a fleet of user-package republishes. Agents still get live helpers in execute. Users who want insulation or durability own a fork.
This record does not change the 0014 packageStorage() grant exclusion for
platform-owned static dependencies.
0036 vacated person-account official
live-resolve; current grant mechanics:
packageStorage grants and caller-owned packages.
Revisit only if official packages grow a real versioning contract that 0001 and 0031 still refuse.