Org (tenant) layer
- New Org model with org_uuid denormalized onto workspaces, assets,
vulnerabilities and runs so cross-workspace queries need no join
- Automatic attribution via BeforeAppendModel hooks; importers stay org-unaware
- Read semantics: empty org means no filter (backward compatible)
Write semantics: empty org coerced to the default org
- Migration backfills every pre-existing row into the default org
- CLI: osmedeus org create/show/assign/use/rename/delete
- API: /osm/api/orgs CRUD plus ?org= on assets, vulns, runs and workspaces
npm distribution
- npm install -g @j3ssie/osmedeus ships the Go binary through npm
- One npm name with version-suffixed platform builds pulled in as aliased
optionalDependencies, so an install downloads exactly one binary
- Binary ships gzipped and is decompressed on first run into a
version-scoped cache, so an upgrade can never exec a stale binary
- make bump-version is the single source of truth for the version constant
Bundled agent skills
- public/skills/ embedded in the binary, installed via osmedeus skills install
- Filesystem-driven discovery: a new bundle needs no code change
- make sync-skills mirrors bundles out to the standalone skills repo
Platform sub-projects
- Vendor dashboard, registry and workflow under platform/ so they version
with the engine they talk to; make sync-platform publishes them out
- Rebuild the embedded UI in public/ui/