This page states what support the Architecture as Code (CALM) project provides, which releases are supported, and when a release stops receiving security updates.
Support is provided by the community on a best-effort basis. There is no service-level agreement.
- Questions and usage help: open a Support Question issue, or join the monthly community meeting and weekly Office Hours listed in the README.
- Bugs: open a Bug Report.
- CALM specification: ask questions, report bugs and propose schema changes in finos/calm-schema. Report a vulnerability in the schema privately through its Security tab.
- Security vulnerabilities: do not open a public issue. Follow SECURITY.md.
- Documentation: https://calm.finos.org
The project ships several independently released components. For every component, only the latest published release is supported. Bug fixes and security fixes are delivered by publishing a new release, not by patching older ones.
| Component | Distribution | Supported |
|---|---|---|
| CALM specification (finos/calm-schema) | https://calm.finos.org/release and npm @finos/calm-schema, tagged v<major>.<minor> |
Latest release. Earlier published releases stay available at their URLs so existing documents keep validating, but they receive no further changes. |
@finos/calm-cli, @finos/calm-server |
npm | Latest published version of each package. @finos/calm-shared, @finos/calm-models and @finos/calm-widgets are bundled into the CLI and are not published separately. |
calm-models (Java) |
Maven Central | Latest published version. |
| CALM Hub | Docker Hub finos/calm-hub (and the read-only and native variants) |
Latest tag. |
| CALM VS Code extension | Visual Studio Marketplace | Latest published version. |
| CALM Lab | Web app at https://lab.calm.finos.org | The deployed version. There are no versioned releases: a change to the lab, or to a package it is built from, is deployed when it merges to main. |
CALM Studio, CALMGuard, experimental/ |
Various | Experimental. No support commitment and no security-update commitment until they are promoted out of experimental status. |
A release stops receiving security updates at the moment a newer release of the same component is published. Security fixes are always released as a new version. If you are on an older version, upgrade to the latest release to receive the fix.
Pre-releases (for example -rc or -next versions) are not supported and receive no security updates.
All components follow Semantic Versioning. Breaking changes only ship in a new major version and are called out in the release notes.