withcoral/coral
56.0
Adequate · 30 September 2026
223.1k
lines of production code
Rust
with TypeScript
2
measurements over time
What this system is
Coral is a local-first, federated SQL query engine that allows users to connect to and query diverse data sources—including databases, HTTP APIs, files, and Model Context Protocol (MCP) services—using standard SQL. It provides a comprehensive application layer with a CLI, a React-based web UI, and a desktop client, all secured by robust OAuth 2.0/OIDC authentication and strict workspace-based access control. The system manages the full lifecycle of source definitions, credentials, and user state, exposing these capabilities via a stable gRPC API and an MCP server for AI agent integration.
Features
Add BarChart, LineChart, and Sparkline components to WAX
The WAX charting library now includes three new SVG-based visualization components: BarChart, LineChart, and Sparkline. BarChart renders vertical bars with rounded corners, gridlines, and axis labels. LineChart supports multiple data series with area fills, gridlines, and axis labels. Sparkline provides a compact, inline line chart with area fill. All components use the WAX theme system for styling and are exported from the charts module.
apps/coral-ui/app/wax/components/charts/bar-chart, apps/coral-ui/app/wax/components/charts/line-chart, apps/coral-ui/app/wax/components/charts/sparkline · high confidence
Add Firefox local source for querying browser data via SQL
Users can now query local Mozilla Firefox data (bookmarks, history, extensions, and top sites) using SQL through a new community source. This feature introduces a zero-dependency Python server that reads Firefox SQLite databases and serves them over localhost, requiring a shared bearer token for access. The source exposes tables for bookmarks, history (capped at 5,000 rows), extensions, and top sites, along with a \history\_slice\ function for filtered history queries. Setup involves running the local server, exporting a generated API key, and registering the source manifest with Coral.
sources/community/firefox · high confidence
Add shell script for installing the Coral CLI
A new install.sh script is introduced to automate the installation of the Coral CLI tool. The script detects the user's operating system and architecture, fetches the latest release from GitHub, downloads the appropriate archive, verifies its integrity using SHA-256 checksums, and installs the binary to a local directory. It also provides instructions for adding the binary to the system PATH and running the initial onboarding command.
scripts · high confidence
Added AWS SigV4 request authenticator
Users can now authenticate requests to AWS services using the SigV4 protocol by setting \auth.authenticator = "aws\_sigv4"\. This new authenticator, implemented in \crates/auth/aws\, allows configuration of the AWS service name, region, access key ID, secret access key, and optional session token via input templates, automatically signing outgoing HTTP requests with the appropriate authorization headers.
crates/auth · high confidence
Added gRPC health check service definition
The API now exposes a standard gRPC health check endpoint, allowing clients to verify service availability and status via the \grpc.health.v1.Health\ service. This addition enables external monitoring tools and load balancers to perform health probes against the Coral API.
crates/coral-api/proto/grpc · high confidence
CLI now embeds the build git SHA in version output
The \coral-cli\ crate now includes a build script that captures the current git commit SHA at compile time and embeds it into the binary. This allows users to identify the exact source version of their CLI installation by checking the version output, which is particularly useful for debugging and verifying deployment integrity.
crates/coral-cli · high confidence
Catalog metadata is now indexed and searchable via SQLite
The application now includes a dedicated SQLite-backed search provider for catalog metadata. This change introduces a new indexing layer that ingests tables, table functions, columns, and filters from the engine's catalog into a local SQLite database with full-text search capabilities. Users will see catalog items (such as tables and their columns) appear in Universal Search results, with ranking based on BM25 scores weighted toward names and descriptions. The system maintains index freshness using content fingerprints, automatically refreshing the local index when the underlying catalog structure changes, and supports maintenance operations to clear or rebuild the catalog search data.
crates/coral-app/src/search/catalog · high confidence
Desktop app renderer, auto-update, and MCP configuration
The desktop application now serves its UI via a custom 'coral-app' protocol instead of a local TCP server, applying strict Content Security Policies with nonces to enhance security. It introduces a robust auto-update system for macOS, Windows (NSIS), and Linux (AppImage) that supports background downloads, manual installation prompts, and coordinated shutdowns to ensure updates are applied safely. Additionally, the desktop now manages isolated Coral state and configures MCP clients to use the desktop's specific config directory, ensuring proper workspace access and environment isolation for agent integrations.
apps/desktop/src · high confidence
Establish protobuf transport contract and build infrastructure for coral-api
The coral-api crate now owns the protobuf transport contract and generated Rust bindings for app and client communication. This change introduces the initial set of protobuf message and service definitions (including catalog, resources, workspaces, task, feedback, features, sources, query, search, functions, traces, GUI onboarding, and users) under the proto directory, along with the build script and Buf configuration required to generate the corresponding tonic and prost bindings. This establishes the wire-contract stability foundation for the API layer.
crates/coral-api · high confidence
Establishes the local gRPC transport contract and configuration constants
The \coral-api\ crate is introduced as the shared transport layer for the local Coral application, exposing generated \protobuf\ and \tonic\ bindings for the \coral.v1\ service. This change defines the canonical wire contract by setting increased gRPC message size limits (64 MB) for \QueryService\, \CatalogService\, \SourceService\, and \SearchService\ responses to accommodate large manifests and metadata, while also configuring HTTP/2 header limits and establishing shared constants for error domains, task attribution metadata, and default workspace identifiers.
crates/coral-api/src · high confidence
Initial release of the Coral v1 gRPC API surface
This change introduces the complete set of Protocol Buffer definitions for the Coral v1 API, establishing the contract for all client-server interactions. The new schema defines core services for managing workspaces and users, discovering and querying catalog tables and functions, executing and explaining SQL statements, and inspecting local traces. It also covers source configuration with detailed OAuth credential flows, universal search maintenance, function lifecycle management, and GUI onboarding state, providing the foundational interface for the Coral application.
crates/coral-api/proto/coral · high confidence
Introduce Coral Desktop application with platform-specific packaging and auto-update support
Adds the Coral Desktop app, an Electron shell that bundles the Coral CLI as a supervised local sidecar and serves the Coral UI interface via a custom \coral-app://\ scheme. The entry includes the initial project scaffolding (configuration files, build scripts, and documentation) and configures \electron-builder\ to package the application for macOS (DMG/ZIP with signing and notarization), Linux (AppImage and deb), and Windows (NSIS installer). Release builds enable automatic updates from GitHub Releases for macOS, Linux AppImage, and Windows, while QA builds remain unsigned with the updater disabled.
apps/desktop · high confidence
Introduce Coral MCP server with stdio and Streamable HTTP transports
The \coral-mcp\ crate now provides the core implementation for the Model Context Protocol (MCP) server, exposing Coral as a SQL database to AI agents. It supports two transport modes: a standard \stdio\ adapter for CLI integration and a new \Streamable HTTP\ server for network access. The HTTP server enforces OAuth bearer authentication by default, while offering an opt-in, loopback-only mode for unauthenticated local development. The server exposes a standardized set of tools—including \sql\, \search\, \list\_catalog\, and task lifecycle management—along with resources like the database guide and table metadata. It also features a host-extension system that allows external providers to register custom tools and customize the initialization instructions served to clients.
crates/coral-mcp/src · high confidence
Introduce Coral query engine with extension points and type mapping
The new \coral-engine\ crate provides the federated DataFusion query engine, exposing high-level APIs like \CoralQuery\ and \PreparedQuery\ for executing SQL against managed sources. It introduces a composition layer (\EngineExtensions\) that allows registering custom authenticators, source decorators, and observation hooks for source scans and query results. Additionally, it establishes canonical type conversions between the Coral manifest data types and Arrow/DataFusion types, ensuring consistent handling of scalars like timestamps and JSON.
crates/coral-engine/src · high confidence
Introduce DSL v4 source materialization and validation artifacts
The v4 specification module now includes a complete artifact model for materialized sources, enabling the system to persist, validate, and reload processed source definitions. This change adds fingerprinting logic to verify schema versions, importer versions, and source identity, ensuring that cached or persisted artifacts remain compatible with the current generator. It also introduces a diagnostic system for capturing import errors and a lookup-key inference mechanism for REST surfaces that automatically identifies which query parameters can safely anchor dependent joins while excluding pagination, presentation, and search parameters. Additionally, the module defines the v4 manifest structure supporting OpenAPI, MCP, and Database surface types, along with comprehensive tests for manifest parsing and identifier normalization.
crates/coral-spec/src/v4 · high confidence
Introduce MCP surface type support in DSL v4 IR
The v4 intermediate representation now supports Model Context Protocol (MCP) as a distinct surface type alongside REST. This is implemented by adding a new \mcp.rs\ module defining \McpExecutionAttachment\ and updating the \IrExecutionAttachment\ enum in \model.rs\ to include an MCP variant. The \mod.rs\ file exposes these new types, enabling the DSL to model and import MCP-based operations in addition to existing REST capabilities.
crates/coral-spec/src/v4/ir · high confidence
Introduce Universal Search with SQLite-backed catalog and observed values
The search module now implements a Universal Search engine that aggregates results from multiple providers (catalog metadata and observed values) into a single, fused ranking using Reciprocal Rank Fusion. This capability is backed by a new SQLite store, including database migrations for catalog documents, observed values, and queue jobs, along with maintenance controls for rebuilding indexes and draining queues. The search service exposes these capabilities via gRPC, enforcing workspace authorization and providing detailed provider status and truncation notes in the response.
crates/coral-app/src/search · high confidence
Introduce backend-specific manifest models for database, file, HTTP, and MCP sources
The \crates/coral-spec/src/backends\ module now defines the normalized, validated manifest structures consumed by the query engine for four distinct source backends. The \database\ backend introduces \DatabaseSourceManifest\ with provider-specific connection specs for PostgreSQL, MySQL, and SQLite. The \file\ backend adds \FileSourceManifest\ to handle native file-backed sources (Parquet, JSONL, JSON, CSV) with format-specific options and schema inference logic. The \http\ backend provides \HttpSourceManifest\ for declarative HTTP sources, supporting Basic, Header, and Custom authentication, rate-limit handling, and request templating. Finally, the \mcp\ backend adds \McpSourceManifest\ to support Model Context Protocol sources, including both stdio and Streamable HTTP transports with Bearer token authentication. These types centralize validation and provide a unified interface for the engine to process source definitions.
crates/coral-spec/src/backends · high confidence
Introduce catalog discovery service for table and function search
A new catalog discovery service has been added to the application, exposing gRPC endpoints (ListCatalog, SearchCatalog, DescribeCatalogSurface) that allow users to search for and inspect database tables and table functions within their workspace. The implementation includes pagination support, case-insensitive pattern matching, and authorization checks to ensure users can only access resources in workspaces they are permitted to read.
crates/coral-app/src/catalog · high confidence
Introduce dependent join execution for predicate pushdown
The runtime now supports dependent joins, allowing queries to push filters from a resolver side into lookups against an HTTP-backed dependent table. This change adds the full execution pipeline—including a DataFusion optimizer rule, logical/physical nodes, a concurrency-controlled fetcher, and output assembly—so that joins against external APIs are executed as targeted, keyed lookups rather than broad scans.
_crates/coral-engine/src/runtime/dependent\join · high confidence
Introduce local management plane with bundled source support and architectural guidelines
The \coral-app\ crate is established as the local management plane and internal gRPC server composition root, providing the wiring for local server bootstrap, persisted state under \CORAL\_CONFIG\_DIR\, workspace identity, source lifecycle, and credential persistence. A new build script (\build.rs\) automatically discovers bundled source packages from \sources/core\, validates their manifest names, and generates a Rust constant array of source name-to-manifest mappings for runtime inclusion. The crate also introduces architectural documentation (\AGENTS.md\) defining layering rules, invariants for database-backed state and DSL v4 materialization, and boundaries for catalog discovery and runtime package assembly.
crates/coral-app · high confidence
Introduce local runtime feature flags for database sources, feedback, and search
The Coral app now supports runtime feature flags that allow operators to enable or disable specific capabilities via the local configuration file or command-line launch flags. Three features are introduced: \database\_sources\ (disabled by default) to enable relational database source installation and runtime loading, \feedback\ (disabled by default) to expose the MCP feedback tool, and \observed\_values\_search\ (disabled by default) to enable observed-value collection and retrieval for Universal Search. These features are managed through a new \FeatureService\ exposed over gRPC, which allows listing current status and changing enabled/disabled states, subject to host-global authorization checks.
crates/coral-app/src/bootstrap · high confidence
Introduce local-first CLI with interactive onboarding and structured error reporting
The \coral-cli\ crate now provides the primary user interface for Coral, replacing the previous embedded browser UI with a local-first, terminal-based experience. Users can now run an interactive onboarding wizard (\coral onboard\) to discover and connect data sources, manage workspaces, and execute SQL queries directly from the command line. The CLI features structured error rendering for SQL failures, displaying clear Error, Detail, and Hint blocks to aid debugging. It also supports shell completions, runtime feature flags, and a long-running server mode that composes gRPC and MCP HTTP surfaces, allowing the CLI to act as a local bootstrap for the Coral engine.
crates/coral-cli/src · high confidence
Introduce manifest-driven HTTP source backend
This change adds a new HTTP source backend to the engine, enabling users to query external APIs as tables and table functions via declarative manifests. It includes a dedicated HTTP client with configurable timeouts, user agents, and credential-safe redirect policies, alongside a comprehensive authentication system supporting Basic, custom headers, and extensible custom authenticators that enforce HTTPS or loopback-only transports for sensitive credentials. The backend features a robust pagination engine handling offset, cursor, link-header, and next-URL modes, along with structured error mapping for API failures, rate limits, and decode errors. Additionally, it provides filter-usage analysis to push SQL filters into HTTP request templates and supports source-scoped table functions for flexible data retrieval.
crates/coral-engine/src/backends/http · high confidence
Introduce observed-values search provider with collection, governance, and privacy controls
This change adds a new observed-values search provider in the search module, enabling the system to collect, store, and search against values observed from installed sources. The collector gathers candidate values from data batches while enforcing strict budgets on the number of candidates, inspected cells, and byte sizes. To protect privacy, the system automatically suppresses values from columns with sensitive names (such as 'password' or 'token') and sanitizes structured content like JSON, URLs, and form data to remove recognized secret shapes. Collected values are persisted in a local SQLite store, which includes a governance layer to manage storage limits, evict stale or excess rows, and maintain the full-text search index. The provider integrates with the application's source lifecycle, dynamically loading live scopes based on installed source manifests and credential revisions, and exposes these observed values as a distinct, diversified surface in search results.
crates/coral-app/src/search/observed · high confidence
Introduce opt-in feedback reporting with local persistence and remote upload
Users can now submit feedback reports (capturing what they were trying to do, what they tried, and where they got stuck) which are persisted locally as JSONL records per workspace and asynchronously uploaded to the hosted Coral feedback endpoint. The service enforces workspace read authorization before filing a report and optionally attributes the feedback to a specific task ID.
crates/coral-app/src/feedback · high confidence
Introduce persistent app configuration and filesystem layout management
The application now persists its configuration, including engine settings (dependent joins, memory limits), workspace records, installed sources, and installed functions, into a top-level \config.toml\ file. A new \AppStateLayout\ component manages the local filesystem structure, defining paths for the config directory, database (\coral.db\), workspace data, installed functions, secrets, and search indexes. This change establishes the foundation for durable state management, ensuring that user settings and installed artifacts survive application restarts.
crates/coral-app/src/state · high confidence
Introduce shared Coral client transport and result-decoding library
The new \coral-client\ crate provides a unified bootstrap and transport layer for local Coral gRPC clients. It centralizes connection handling with support for HTTPS bearer authentication, loopback-plaintext connections for local embedding, and automatic OpenTelemetry span instrumentation for every gRPC call. The library exposes typed clients for all core services (source, workspace, user, catalog, query, search, function, feedback, task, and health) and includes shared helpers to decode Arrow IPC query results into structured formats (ASCII tables, JSON arrays, and JSON row objects), ensuring that large numeric types like Int64, UInt64, and Decimals are safely serialized as JSON strings to prevent precision loss. It also standardizes the decoding of AIP-193 structured query errors from server status details and provides utilities for rendering Universal Search responses.
crates/coral-client · high confidence
Introduce shared backend execution and filtering infrastructure
This change adds a new shared module for the Coral engine that standardizes how HTTP and MCP backends process JSON responses. It introduces a unified filter expression system to classify and extract pushed-down DataFusion filters into manifest-defined source filters, ensuring consistent pushdown decisions. A new \JsonExec\ execution plan node handles the conversion of fetched JSON rows into Arrow record batches, while shared helpers manage row extraction strategies (Direct, DictEntries, SeriesPointList) and column mapping. Additionally, the module provides backend-agnostic tracing helpers for W3C trace context propagation and URL sanitization, along with source-scan observation hooks to publish scan metrics.
crates/coral-engine/src/backends/shared · high confidence
Introduce unified file backend for local and object-store data sources
Users can now query files stored locally or in object stores (such as S3) directly through a new file backend. This feature adds support for reading JSON, JSONL, CSV, and Parquet formats, with capabilities for Hive-style partition pruning, file metadata columns (like file name and line number), and custom JSON array parsing. The backend integrates with DataFusion to handle file listing, schema inference (including complex Parquet dictionary expansion), and efficient scan execution.
crates/coral-engine/src/backends/file · high confidence
Introduce user-installed SQL function management
The application now supports installing, listing, and deleting user-defined SQL functions within a workspace. This change adds a new \FunctionManager\ and \FunctionService\ (exposed via gRPC) that handle the full lifecycle: persisting function artifacts to the file system, validating SQL against the runtime, and enforcing workspace-level authorization for both read (listing) and manage (add/delete) operations. Functions are tracked by name and write surface (CLI, MCP, or Unknown), and the system ensures that publish targets are unique and that runtime validation errors are surfaced to the user.
crates/coral-app/src/functions · high confidence
Introduces Coral UI with hosted OAuth authentication and Storybook component library
This change adds the Coral UI application, a React-based frontend shell that supports optional hosted authentication via OAuth 2.0 with PKCE. When enabled, it derives OAuth identifiers (client ID, redirect URI, resource) from a public URL and enforces strict security rules, such as requiring HTTPS or explicit loopback HTTP for both the public URL and the authorization issuer. The app includes a Storybook setup for the Wax component library, featuring a theme-comparison addon to preview components in both light and dark modes, and enforces architectural rules to keep data fetching out of presentation components.
apps/coral-ui · high confidence
Introduces durable SQL-backed state persistence for the application
The application now persists core state—including login identities, workspace catalogs, task activity, and GUI onboarding progress—into a relational database instead of relying solely on local file-based storage. This change introduces a new database layer supporting both SQLite (default, local) and PostgreSQL (remote), with configuration managed via \config.toml\. It includes a one-time migration to import legacy workspace data into the new schema and automatically assigns local ownership to previously ownerless workspaces. Users benefit from more robust state recovery and the ability to run the application against a shared remote database.
crates/coral-app/src/state/db · high confidence
Introduces encrypted credential storage with configurable backends and OAuth support
The application now supports storing credentials in encrypted files or the system keychain, with the storage method configurable via \config.toml\ (defaulting to automatic selection). Credential data is protected using envelope encryption (AES-256-GCM) with versioned binding contexts to ensure integrity and prevent tampering. Additionally, the credentials module now includes a comprehensive OAuth service that handles authorization code and device code flows, dynamic client registration, and automatic access token refresh, allowing sources to authenticate securely without exposing raw tokens.
crates/coral-app/src/credentials · high confidence
Introduces explicit user confirmation for OAuth authorization requests
The authorization server now presents a dedicated approval page to users before granting access, requiring an explicit 'Continue' or 'Cancel' decision. This change adds a confirmation flow that validates the request origin, manages secure and loopback-specific cookies for browser binding, and displays client details along with a warning for local redirect URIs. The implementation includes a new confirmation handler, a styled HTML page with strict Content Security Policy headers, and logic to parse and validate the user's submission ticket.
_crates/coral-app/src/auth/authorization\server/authorize · high confidence
Introduces identity principal model and encrypted spec document storage
The application now defines a structured identity model with \PrincipalId\ and \Principal\ types to represent authenticated users and agents, including support for a reserved local principal. Additionally, it implements encryption for identity-spec setup documents, ensuring that sensitive configuration values are sealed with authenticated encryption bound to specific keys, preventing replay or cross-scope misuse.
crates/coral-app/src/identity · high confidence
Introduces identity spec input resolution and management
The application now includes a dedicated module for managing installed identity specifications, specifically handling the preparation, validation, and resolution of setup inputs. This change adds logic to merge caller-supplied input values with previously stored material, ensuring that required inputs are present and that sensitive data is handled securely. It also provides a manager that retrieves identity specs from the database, decrypts their associated input material, and resolves them for use, supporting both exact lookups and workspace-scoped resolution with global fallback.
_crates/coral-app/src/identity\specs · high confidence
Introduces private, atomic filesystem storage helpers
The application now includes a new local storage module (\crates/coral-app/src/storage\) that provides utilities for managing private directories and files. This includes functions to ensure directories and files have restricted permissions, perform atomic writes via temporary files to prevent data corruption, and handle safe directory deletion with rollback capabilities. These changes lay the groundwork for durable, secure local persistence of application state.
crates/coral-app/src/storage · high confidence
Introduces stable, structured contracts for catalog metadata, query execution, and error handling
The \coral-engine\ now exposes a formalized set of type-safe contracts that define how the engine communicates with the application layer. Users benefit from richer, structured error messages that include specific hints for missing columns or tables, and a unified catalog interface that exposes detailed metadata for tables, columns, and table functions (including arguments and result schemas). The query execution model is also standardized, providing clear definitions for source configurations, memory usage tracking, and provenance, ensuring consistent behavior across different source types like databases, HTTP, and MCP.
crates/coral-engine/src/contracts · high confidence
Introduces structured MCP surface helpers and catalog tools
The \crates/coral-mcp/src/surface\ module now provides a dedicated layer for argument validation, catalog discovery, and error handling. It adds a \reject\_unknown\_arguments\ helper to enforce strict tool schemas, preventing agents from passing unrecognized parameters. New catalog tools (\list\_catalog\, \describe\, \list\_columns\) allow agents to discover tables, table functions, and column metadata, with pagination support and regex-based column filtering. The module also introduces a \ToolError\ structure for structured error reporting and a \ToolDescriptionContext\ to dynamically inject connected source names and visible table counts into tool descriptions and initial instructions.
crates/coral-mcp/src/surface · high confidence
Introduction of durable local database schema for app state and identity
The application now persists core state to a local SQL database, replacing ephemeral storage. This change introduces tables for workspaces, tasks (including SQL query history and relations), and GUI onboarding completion status. It also adds support for identity specs with encrypted document storage, trace search response logging, and user workspace membership with role-based access control (owner/member).
crates/coral-app/migrations · high confidence
Local trace inspection with bounded query stream listing
The application now captures and stores local OpenTelemetry spans in a JSONL-backed local store, enabling users to inspect trace history directly within the app. This includes a new configuration system (loaded from \config.toml\) to control OpenTelemetry export settings and trace history retention (defaulting to 7 days), as well as a bounded listing mechanism for the query stream that efficiently paginates through stored traces while respecting workspace scoping and pruning expired files.
crates/coral-app/src/telemetry · high confidence
New Ansible facts source for querying infrastructure state via SQL
Users can now query sanitized, normalized Ansible fact exports as SQL tables within the \ansible\ schema. This file-backed, read-only source exposes seven tables—\hosts\, \services\, \packages\, \mounts\, \interfaces\, \security\, and \roles\—allowing for infrastructure inventory, service-state checks, package inspection, disk and mount analysis, network interface discovery, coarse security posture review, and role-drift detection. The source requires users to gather facts with Ansible, normalize them into JSONL files, and register the source via a manifest, ensuring Coral never executes playbooks, connects via SSH, or accesses raw secrets.
sources/community/ansible · high confidence
New OAuth 2.0 / OIDC authorization server implementation
The application now includes a complete OAuth 2.0 and OpenID Connect authorization server implementation within the \coral-app\ crate. This adds the ability to handle OAuth authorization requests, validate client metadata, manage user login provisioning, and issue access tokens. The implementation supports PKCE (S256), allows trusted clients to skip the approval page, and enforces strict security headers and query parameter limits to prevent abuse.
_crates/coral-app/src/auth/authorization\server · high confidence
New OpenAPI v4 importer with 3.1 support and schema normalization
The v4 specification surface now includes a dedicated OpenAPI importer that accepts both OpenAPI 3.0 and 3.1 documents. To handle 3.1's JSON Schema-aligned nullability (e.g., \type: \[string, null\]\ or \anyOf\ unions), the importer normalizes schemas on-the-fly into the 3.0 \nullable\ form, ensuring consistent type inference without altering the original document structure. The importer validates supported versions, resolves local \$ref\ pointers, and extracts document metadata like server URLs and descriptions. It processes operations by importing parameters, request bodies, and responses, while handling 2XX status code ranges and reporting diagnostics for unsupported external references or cyclic compositions.
crates/coral-spec/src/v4/surfaces/openapi · high confidence
New authorization server and OIDC integration for user login and OAuth flows
Coral now includes a built-in authorization server and OpenID Connect (OIDC) client, enabling users to authenticate via external identity providers and allowing external applications to obtain access tokens through standard OAuth 2.0 flows. The new \auth\ module handles OIDC discovery, ID token validation (supporting algorithms like ES256, RS256, and EdDSA), and the issuance of internal session tokens. It also manages the full OAuth authorization code flow, including state storage, code exchange, and client metadata validation, while supporting additional server audiences and loopback client configurations.
crates/coral-app/src/auth · high confidence
New declarative source-spec parsing and validation crate
The \coral-spec\ crate now owns the full lifecycle of source-spec manifests, providing a unified, engine-neutral layer for parsing, validating, and normalizing source definitions. It introduces support for multi-document YAML bundles that can include both source manifests and authored identity specs, enabling declarative identity management alongside source configuration. The crate defines a standardized DSL v4 model with a normalized scalar type vocabulary (\ManifestDataType\), supports multiple backends (HTTP, File, MCP, Database), and handles interactive install-time inputs (variables and secrets) with OAuth credential retrieval flows. It also centralizes error handling via \ManifestError\ and exposes validated models to sibling crates like \coral-engine\ and \coral-cli\ for import, linting, and runtime compilation.
crates/coral-spec/src · high confidence
New desktop build and development scripts
The desktop application now includes a suite of new Node.js scripts to manage the build lifecycle and local development environment. These scripts handle cleaning distribution artifacts, staging the Coral UI server and CLI binary, and configuring Electron Builder for platform-specific packaging (AppImage/deb for Linux, NSIS for Windows, DMG/ZIP for macOS) with strict signing and notarization for release builds. A new development script (\dev.mjs\) ensures the Electron binary is present and orchestrates the Coral UI dev server and Electron main process, while verification scripts validate release outputs and ensure the updater is correctly compiled into release bundles.
apps/desktop/scripts · high confidence
New isolated benchmarking tool for token efficiency and search relevance
Developers now have access to a new \coral-benchmarks\ CLI tool that provides isolated performance and relevance measurements. The tool includes a \list\_columns\ benchmark to measure the token cost of catalog metadata responses using the o200k\_base tokenizer, and a comprehensive \universal\_search\ workflow that allows preparing catalog samples, generating AI-driven questions, collecting search results, and replaying them to evaluate ranking quality.
xtask/benchmarks · high confidence
New source management module with bundled catalog and DSL v4 materialization
The application introduces a dedicated source management module (\crates/coral-app/src/sources\) that centralizes the source lifecycle. This includes a bundled source catalog that resolves and lists pre-packaged sources, a manager handling installation, import, and credential workflows (including OAuth), and a materialization layer that compiles DSL v4 source manifests into runtime packages. The module also defines the core domain models for source identity and origin, ensuring consistent handling of bundled versus imported sources and their associated credentials.
crates/coral-app/src/sources · high confidence
New source metadata catalog and structured error handling in the query runtime
The query runtime now exposes a \coral\ system schema containing discoverable metadata tables (\tables\, \columns\, \filters\, \inputs\, \table\_functions\) that let users inspect active sources and their configurations. It also introduces structured error handling for missing tables and unknown columns, replacing generic internal errors with specific, actionable messages. Additionally, the runtime adds JSON query functions, validates \SIMILAR TO\ patterns to prevent silent failures from SQL-standard wildcard misuse, and implements memory accounting for retained query results.
crates/coral-engine/src/runtime · high confidence
New telemetry crate for shared tracing utilities and privacy-safe error handling
A new \coral-telemetry\ crate has been introduced to centralize cross-crate telemetry helpers, preventing dependency cycles between the app, client, engine, and MCP adapter. This library provides W3C trace-context propagation helpers (extracting and injecting \traceparent\/\tracestate\ headers) and defines specific span attributes for Query Stream operations (such as \coral.stream.kind\ and \coral.local.search.query\). Crucially, it introduces a \record\_failure\ function that logs errors using stable, non-user-controlled messages, ensuring that caller-provided error details are not exposed in exported traces, thereby enhancing privacy and security in telemetry data.
crates/coral-telemetry · high confidence
New v4 projection catalog generation and validation
The v4 spec module now includes a new \projections\ subsystem that generates a \ProjectionCatalog\ from the semantic IR and validates its compatibility with the source manifest. This introduces editor-friendly YAML serialization (avoiding local tags), explicit indexing policies (\do\_not\_index\), and strict validation for input exposure (ensuring required inputs are not hidden) and column paths (ensuring they match the actual row schema). It also handles projection name collision resolution and enforces that pagination-owned inputs remain internal.
crates/coral-spec/src/v4/projections · high confidence
New xtask subcommands for documentation generation, truncation detection, and workspace recovery
The xtask developer tooling now includes several new capabilities: \generate-docs\ automatically regenerates the bundled and community source catalog pages and the changelog in the Mintlify documentation site, updating the navigation index accordingly; \detect-truncations\ scans source manifests for descriptions that appear to be cut off mid-sentence, helping maintain documentation quality; and \workspace-admin\ (available only when the \admin\ feature is enabled) provides repository-side recovery tools to repair workspace ownership and access control in a deployment's state database when a user is locked out. Additionally, \benchmark\ and \perf-check\ subcommands have been added to run performance benchmarks and regression checks.
xtask · high confidence
Official Coral and Coral UI Docker images with secure, reproducible builds
The project now publishes official Docker images for both the Coral server and the Coral UI frontend. The Coral server image is built from verified release tarballs to ensure reproducibility and includes a health check via grpc\_health\_probe, while the Coral UI image is compiled from source using Node 24.15.0 and exposes port 3000. Both images enforce non-root execution, use read-only root filesystems where applicable, and include robust entrypoint scripts that handle configuration seeding, validation, and secure defaults (e.g., requiring explicit opt-in for insecure endpoints in Coral UI). Comprehensive smoke tests and publication workflows ensure image integrity and correct runtime behavior.
docker · high confidence
Persistent local storage for onboarding, identity specs, tasks, and user sessions
The application now persists key user and system state to a local database (SQLite or Postgres) instead of relying solely on in-memory or ephemeral storage. This includes tracking GUI onboarding completion per user, storing identity specifications (including encrypted setup documents) with global and workspace scopes, recording task execution history and SQL activity, and maintaining user login and workspace membership records. A state migration system ensures legacy workspaces are correctly owned after upgrade. Users will see their onboarding progress, identity configurations, and task history survive application restarts, and login sessions are securely maintained locally.
crates/coral-app/src/state/db/repositories · high confidence
Support for MCP-backed sources via stdio and Streamable HTTP transports
Users can now connect to external services using the Model Context Protocol (MCP). The engine introduces a new backend in \crates/coral-engine/src/backends/mcp\ that supports both local stdio servers and remote Streamable HTTP servers. This implementation allows MCP tools to be exposed as queryable tables and table functions, handling tool discovery, argument binding, pagination (cursor and offset), and structured error reporting. It also includes observability features like request/response body capture for tracing.
crates/coral-engine/src/backends/mcp · high confidence
Support for importing MCP tool surfaces in DSL v4
The DSL v4 specification now supports importing surfaces defined via the Model Context Protocol (MCP). This change introduces a new importer in the \crates/coral-spec\ crate that processes an MCP tool catalog, converting tool definitions into internal operations with typed inputs and outputs. The importer automatically infers pagination strategies (cursor and offset-based) by analyzing input arguments and response schemas, and handles wrapped-list detection to ensure correct list-like behavior for paginated results. Users can now configure a surface with \type: mcp\ to automatically generate operations from their MCP server's tool definitions.
crates/coral-spec/src/v4/surfaces/mcp · high confidence
Support for relational database sources via DataFusion catalog backend
The engine now supports connecting to relational databases (PostgreSQL, MySQL, SQLite) as data sources. This change introduces a new backend in \crates/coral-engine/src/backends/database\ that registers a DataFusion catalog adapter, allowing the engine to query remote database tables and views. It includes a workspace-scoped connection pool registry to cache and reuse database connections across queries, and implements lazy column metadata fetching to efficiently retrieve schema information from the database's system catalogs (e.g., \information\_schema\) rather than probing each table individually.
crates/coral-engine/src/backends/database · high confidence
Task lifecycle persistence and SQL activity tracking
The application now persists task lifecycle events (start and completion) to SQL, enforcing a maximum of 10,000 active tasks per workspace and validating task intent strings. Additionally, SQL query activity for validated tasks is recorded to the database, capturing details such as the SQL statement, execution status, and affected relations, with a 64 KB limit on recorded SQL bytes.
crates/coral-app/src/task · high confidence
macOS signing and notarization configuration added
The desktop application now includes the necessary configuration files to support macOS code signing and notarization. This change adds an SVG application icon for the desktop build, along with two entitlements property list files: a main configuration enabling Just-In-Time (JIT) compilation required by the Electron runtime, and an inherited configuration for nested executables like Electron helpers and the bundled Coral sidecar.
apps/desktop/resources · high confidence
Architecture
Restructure v4 surface parsing into modular components
The v4 surface parsing logic has been refactored to improve modularity and maintainability. The \json\_schema.rs\ module has been extracted to handle JSON Schema resolution, walking, and comparison, including support for normalized schemas and sibling metadata preservation. The \mod.rs\ file now explicitly exports the MCP and OpenAPI surface importers and normalizers, separating concerns for better code organization.
crates/coral-spec/src/v4/surfaces · high confidence
Behavioural changes
Enforce authorization matrix across every service
The application now enforces a centralized authorization matrix that explicitly defines access rules for every gRPC RPC. This module declares the required principal type for each service method—such as Read, Manage, OwnerDirectory, or LocalOnly—and includes tests that verify the matrix remains synchronized with the protobuf definitions, ensuring no RPC is left unclassified or misclassified.
crates/coral-app/src · high confidence
Enforce workspace authorization matrix and explicit lifecycle management
The workspace module now centralizes access control through a new \WorkspaceAuthorizer\ that enforces a strict authorization matrix, distinguishing between \Read\ and \Manage\ actions and applying specific rules such as rejecting agent credentials from managing workspaces and handling local principal policies. This change introduces explicit workspace provisioning where creation is tied to user ownership, and implements a robust lifecycle management system with \WorkspaceManager\ that handles creation, deletion, and membership changes (add/remove/list) via a gRPC service. The system now persists workspace state and membership roles (Owner/Member) in the database, ensuring that access decisions are grounded in verified membership rather than implicit trust.
crates/coral-app/src/workspaces · high confidence
Introduce unified backend registration and composite source compilation
The engine now compiles query sources into a unified runtime representation via the new \backends\ module. This change introduces a common registry of tables, table functions, and inputs, and supports composite sources that aggregate multiple backend components (HTTP, file, database, MCP) into a single logical source. Users benefit from consistent source metadata exposure and the ability to combine different data origins under one source name, with duplicate table or function names within a schema now detected and rejected during registration.
crates/coral-engine/src/backends · high confidence
Introduces query attribution and credential-refreshing input resolution
The query subsystem now tracks the originating task and tool intent for every SQL execution, stamping \task.id\ on \coral.query\ spans for better observability and durable activity recording. Additionally, source credential inputs are resolved through a new \CredentialRefreshingInputResolver\ that automatically refreshes OAuth tokens and persists materialized secrets before the engine runtime executes queries, ensuring credentials are always current without manual intervention.
crates/coral-app/src/query · high confidence
Test coverage
Add tests for MCP HTTP session authentication and workspace scoping; Added gRPC integration test suite for app services; Added integration test harness for CLI commands; Added integration tests for CLI commands and features; Added integration tests for gRPC access control and telemetry behavior; Integration test suite for the coral-engine query API.
Dependencies
Initial dependency manifests and lockfiles for Coral workspace
This change introduces the foundational dependency configuration for the Coral project, establishing the Rust workspace (Cargo.toml/Cargo.lock) and the frontend application manifests (package.json/package-lock.json). It defines the core library versions, including DataFusion 54, Arrow 58, React 19, and React Router 8, and sets the Rust toolchain requirement to version 1.97.
(dependencies) · high confidence
Written by watchdog.canine.dev from the codebase's own history, inside the signed delivery this page is composed from.
How this codebase got here
Score
- CAI 64 → 56 (-8.5)
- Rubric changed (rubric-2026.09.11 → rubric-2026.09.18) — scores are not directly comparable.
Lenses
- Code Health 89 → 89 (-0.0)
- Architecture 63 → 44 (-18.9)
- Maturity 75 → 74 (-0.3)
- Readiness 65 → 60 (-5.0)
- Security 63 → 67 (+4.4)
- Domain Modelling 100 → 100 (+0.0)
- Event Sourcing 100 → 100 (+0.0)
- Accessibility 62 → 62 (+0.0)
- Performance 100 (new)
Resolved (30)
- Dependency hygiene PARTLY measured — npm pinning read, dependency currency not (no pnpm-resolved versions to grade)
- High CVE: [CVE redacted] (apps/desktop/package-lock.json)
- High CVE: [CVE redacted] (apps/coral-ui/package-lock.json)
- High CVE: [CVE redacted] (apps/desktop/package-lock.json)
- High CVE: [CVE redacted] (apps/coral-ui/package-lock.json)
- High CVE: [CVE redacted] (apps/desktop/package-lock.json)
- High CVE: [GHSA redacted] (apps/desktop/package-lock.json)
- Hotspot: apps/coral-ui/app/lib/coral-endpoint.server.ts (apps/coral-ui/app/lib/coral-endpoint.server.ts)
- Hotspot: apps/coral-ui/app/views/sources/source-add.tsx (apps/coral-ui/app/views/sources/source-add.tsx)
- Hotspot: apps/coral-ui/app/views/traces/http-span-detail.tsx (apps/coral-ui/app/views/traces/http-span-detail.tsx)
- Hotspot: crates/coral-api/src/lib.rs (crates/coral-api/src/lib.rs)
- Hotspot: crates/coral-app/src/search/observed/governance.rs (crates/coral-app/src/search/observed/governance.rs)
- Hotspot: crates/coral-app/src/search/observed/sqlite_projection.rs (crates/coral-app/src/search/observed/sqlite_projection.rs)
- Hotspot: crates/coral-app/src/sources/manager.rs (crates/coral-app/src/sources/manager.rs)
- Hotspot: crates/coral-engine/src/backends/shared/filter_expr.rs (crates/coral-engine/src/backends/shared/filter_expr.rs)
- Hotspot: crates/coral-engine/src/backends/shared/mapping.rs (crates/coral-engine/src/backends/shared/mapping.rs)
- Hotspot: crates/coral-engine/src/runtime/dependent_join/optimizer.rs (crates/coral-engine/src/runtime/dependent_join/optimizer.rs)
- Hotspot: crates/coral-spec/src/backends/mcp.rs (crates/coral-spec/src/backends/mcp.rs)
- Hotspot: crates/coral-spec/src/v4/operation_metadata/structural.rs (crates/coral-spec/src/v4/operation_metadata/structural.rs)
- Hotspot: crates/coral-spec/src/v4/projections/validation.rs (crates/coral-spec/src/v4/projections/validation.rs)
- …and 10 more
New (27)
- Dependency hygiene PARTLY measured — Cargo dependencies read, dependency currency not (crates.io unreachable)
- End-of-life runtime: Rust 1.97
- High CVE: [GHSA redacted] (Cargo.lock)
- High CVE: [GHSA redacted] (apps/coral-ui/package-lock.json)
- High CVE: [GHSA redacted] (apps/desktop/package-lock.json)
- High CVE: [GHSA redacted] (apps/desktop/package-lock.json)
- High CVE: [GHSA redacted] (apps/desktop/package-lock.json)
- High CVE: [GHSA redacted] (apps/desktop/package-lock.json)
- Hotspot: apps/coral-ui/app/views/traces/trace-detail.tsx (apps/coral-ui/app/views/traces/trace-detail.tsx)
- Hotspot: apps/coral-ui/app/views/traces/traces-index.tsx (apps/coral-ui/app/views/traces/traces-index.tsx)
- Hotspot: apps/desktop/src/main/auto-update-core.ts (apps/desktop/src/main/auto-update-core.ts)
- Leaked secret: signing-key (apps/coral-ui/app/routes/_protected.server.test.tsx)
- Low cohesion: ServerConfig (LCOM4 5) (crates/coral-app/src/bootstrap/server.rs)
- Low cohesion: TraceStore (LCOM4 6) (crates/coral-app/src/telemetry/local_store.rs)
- Medium CVE: [GHSA redacted] (apps/coral-ui/package-lock.json)
- Medium CVE: [GHSA redacted] (apps/desktop/package-lock.json)
- Medium vulnerability: RUSTSEC-2026-0285 (Cargo.lock)
- Off the main sequence: coral-telemetry
- Off-boarding risk: anonymized user #5
- Off-boarding risk: anonymized user #6
- …and 7 more
Written by watchdog.canine.dev from the codebase's own history, inside the signed delivery this page is composed from.
Survey your own repository
withcoral/coral was measured the same way every project in this corpus was: the same rubric, at a pinned commit, with the result published in full. Point a surveyor at a repository you know and see whether you agree with it.
About this page
- The score is its most recent published measurement, taken on 30 September 2026 at a pinned commit. It is not a live figure and does not change until the project is measured again.
- Measured at commit 2c58881841bf62fc52a44bb5c2571760e65a58dd — the exact code this score is about.
- Scored under rubric-2026.09.18 — the same rubric and the same method as every other entry in this index.
- Measured by watchdog.canine.dev using codehealth-analyzer preprod-cb25ca4feafa.