Roadmap
What ships, and what does not
ForkReason will not move required work into a roadmap to make a release look finished. Everything below that is not shipped is genuinely unbuilt.
SHIPPED
Forensic pipeline
Eight stages from pinned snapshot to consensus-ready digest, with real progress at every step.
Six Repo DNA layers
Code, Architecture, History, Bug, Test and Language, weighted by rarity rather than by count.
Canonical evidence manifest
A deterministic, hashable record that anyone can recompute and check.
GenLayer consensus
Independent validator re-derivation, fail-closed parsing, append-only revisions.
Prompt-injection gate
Adversarial fixtures across READMEs, comments, strings, HTML and commit metadata.
Public registry
Every case permanently addressable, with its counter-evidence and competing explanations.
NEXT
Stronger upstream discovery
Current heuristics miss ancestors when no fork parent is declared.
Improved historical bug inference
Bug DNA is the strongest available signal; widen the detectable defect signatures.
Richer evidence exports
Portable, signed evidence bundles that travel with a bug report without losing the manifest hash.
Improved shareable reports
Print-quality and embeddable case reports, with Open Graph cards for shared URLs.
LATER
GitLab and Bitbucket
Intake is already host-agnostic in design.
npm and PyPI lineage
Which published version corresponds to which commit.
Package provenance
Tying registry publishing events to repository history.
CI integration
Lineage checks on every push or release.
RESEARCH
Private repositories
Needs user-authorized access and a new intake threat model.
Team workspaces
Multi-tenant collections, sharing and permissions.
Provenance graph
Repositories and relationships as a first-class graph.
Calibrated confidence
Report a probability only where a calibration corpus earns one.
WHAT WILL NOT BE BUILT
- Legal conclusions: ForkReason reports development relationships, not infringement.
- Authorship inference: who wrote what, and with what intent.
- Probabilities without a calibration methodology to stand on.
- Any custodial action on a user's behalf.
A tool that claims to measure provenance has to be clear about where it refuses to.