Difference between revisions of "FHIR NPM Package Spec"
Line 4: | Line 4: | ||
One use of packages is for FHIR Implementation Guides - they are all published as NPM packages, one package for each IG. See below for further discussion. | One use of packages is for FHIR Implementation Guides - they are all published as NPM packages, one package for each IG. See below for further discussion. | ||
− | = Package name = | + | =Package name= |
Each package has a canonical name (a globally unique identifier). A package name consists of one or more namespaces separated by a dot. Each namespace starts with an lowercase alphabet character followed by zero-or-more lowercase alphanumeric characters or a dashes. | Each package has a canonical name (a globally unique identifier). A package name consists of one or more namespaces separated by a dot. Each namespace starts with an lowercase alphabet character followed by zero-or-more lowercase alphanumeric characters or a dashes. | ||
Line 19: | Line 19: | ||
ihe.mhd | ihe.mhd | ||
− | == Scoping == | + | ==Scoping== |
A fhir package should not contain an npm scope. Packages published by HL7 or the FHIR foundation SHALL not contain a scope. | A fhir package should not contain an npm scope. Packages published by HL7 or the FHIR foundation SHALL not contain a scope. | ||
Line 25: | Line 25: | ||
Note: Npm packages can [contain a scope](https://docs.npmjs.com/misc/scope). Scopes are a way of grouping related packages together. A scope is usually the owner, and was introduced relatively late in the npm standard. Only the user can add packages to his/her scope. It's a way to identify the official packages from organizations. In Nuget that same logic is enabled with the package prefix, which is cleaner and more readable. A npm scope, starts with at (@) and ends with a slash '/'. It makes both the client and the server more complex to implement. And we want easy and broad adoption. | Note: Npm packages can [contain a scope](https://docs.npmjs.com/misc/scope). Scopes are a way of grouping related packages together. A scope is usually the owner, and was introduced relatively late in the npm standard. Only the user can add packages to his/her scope. It's a way to identify the official packages from organizations. In Nuget that same logic is enabled with the package prefix, which is cleaner and more readable. A npm scope, starts with at (@) and ends with a slash '/'. It makes both the client and the server more complex to implement. And we want easy and broad adoption. | ||
− | == Name Management == | + | ==Name Management== |
Names under hl7.fhir. or fhir. are assigned by the FHIR Product Director - contact fhir-director@hl7.org for assistance. | Names under hl7.fhir. or fhir. are assigned by the FHIR Product Director - contact fhir-director@hl7.org for assistance. | ||
Line 38: | Line 38: | ||
e.g. hl7.fhir.us.core.structuredefinition - creating packages with names like this does not require approval. Other combinations - use a name in a different namespace, or ask for approval. | e.g. hl7.fhir.us.core.structuredefinition - creating packages with names like this does not require approval. Other combinations - use a name in a different namespace, or ask for approval. | ||
− | = Versions = | + | =Versions= |
All packages have a mandatory version. [SemVer](https://semver.org/) SHOULD be used (and SHALL be used for packages published by HL7 or the FHIR Foundation) | All packages have a mandatory version. [SemVer](https://semver.org/) SHOULD be used (and SHALL be used for packages published by HL7 or the FHIR Foundation) | ||
Line 46: | Line 46: | ||
Version strings SHALL contain only letters, numbers, and the characters ".", "_", and "-" | Version strings SHALL contain only letters, numbers, and the characters ".", "_", and "-" | ||
− | == Version references == | + | ==Version references== |
When packages point to dependencies they should refer to the whole package version number and not use wildcards, except for the patch version in a semver version reference: | When packages point to dependencies they should refer to the whole package version number and not use wildcards, except for the patch version in a semver version reference: | ||
Line 56: | Line 56: | ||
Note: Npm has elaborate logic package version references. It allows version forwarding, ranges, wildcards, etc. The FHIR package standard does not allow this. The only ranges that are allowed are wildcards (x) for the patch version as described here. Most of the matured package managing tools, have acknowledged that having advanced version references would create instability and more confusion than help. Fhir packages also need to be consumed by non technical users. Installing package dependencies should not need a manual. | Note: Npm has elaborate logic package version references. It allows version forwarding, ranges, wildcards, etc. The FHIR package standard does not allow this. The only ranges that are allowed are wildcards (x) for the patch version as described here. Most of the matured package managing tools, have acknowledged that having advanced version references would create instability and more confusion than help. Fhir packages also need to be consumed by non technical users. Installing package dependencies should not need a manual. | ||
− | == Version selection strategy == | + | ==Version selection strategy== |
Dependencies with mismatching versions | Dependencies with mismatching versions | ||
Line 70: | Line 70: | ||
For FHIR we still need to define more precisely how a project that consumes different versions of the same package should resolve these issues. This is part of a bigger versioning discussion in FHIR. | For FHIR we still need to define more precisely how a project that consumes different versions of the same package should resolve these issues. This is part of a bigger versioning discussion in FHIR. | ||
− | = Format = | + | =Format= |
A FHIR package is a tarball (tar in gzip). The package contains | A FHIR package is a tarball (tar in gzip). The package contains | ||
− | * a subfolder named 'package' | + | |
− | * a package manifest (package/package.json) | + | *a subfolder named 'package' |
− | * A set of conformance resource files, also in the package subfolder | + | *a package manifest (package/package.json) |
− | * It MAY contain additional content, like example resources or documentation: | + | *A set of conformance resource files, also in the package subfolder |
− | ** such files SHALL not be in the package subfolder | + | *It MAY contain additional content, like example resources or documentation: |
− | ** this may include XML schemas in an "xml" subfolder | + | **such files SHALL not be in the package subfolder |
− | ** this may include openAPI files in an "openapi" subfolder | + | **this may include XML schemas in an "xml" subfolder |
− | ** this may include turtle RDF representations in an rdf folder | + | **this may include openAPI files in an "openapi" subfolder |
− | ** Package consumers SHALL ignore content in other subfolders that they do not use (and most consumers will only use the resources in /package) | + | **this may include turtle RDF representations in an rdf folder |
+ | **Package consumers SHALL ignore content in other subfolders that they do not use (and most consumers will only use the resources in /package) | ||
Tarballs SHALL be in the original tarball format (e.g. a 99 character file name length limit). | Tarballs SHALL be in the original tarball format (e.g. a 99 character file name length limit). | ||
Line 87: | Line 88: | ||
Note: discussion on this - see [[https://chat.fhir.org/#narrow/stream/99-IG-creation/subject/NPM.20Package.20File]] | Note: discussion on this - see [[https://chat.fhir.org/#narrow/stream/99-IG-creation/subject/NPM.20Package.20File]] | ||
− | = Package manifest = | + | =Package manifest= |
A package manifest is a json file called 'package.json'. It conforms to the npm package.json format, but contains only a subset of properties. Other properties are allowed, but should be ignored by a FHIR package consumer. | A package manifest is a json file called 'package.json'. It conforms to the npm package.json format, but contains only a subset of properties. Other properties are allowed, but should be ignored by a FHIR package consumer. | ||
Line 119: | Line 120: | ||
Package Manifest Properties | Package Manifest Properties | ||
− | * name - mandatory - the globally unique identifier of the package as described above | + | *name - mandatory - the globally unique identifier of the package as described above |
− | * version - mandatory - SHOULD use [SemVer](https://semver.org/) | + | *version - mandatory - SHOULD use [SemVer](https://semver.org/) |
− | * canonical - optional (but required for IGs - see below) | + | *canonical - optional (but required for IGs - see below) |
− | * url - optional = where information about the package can be found on the web | + | *url - optional = where information about the package can be found on the web |
− | * title - optional short description for the package | + | *title - optional short description for the package |
− | * description - mandatory | + | *description - mandatory |
− | * dependencies - at least one to fhir core | + | *dependencies - at least one to fhir core |
− | * keywords - optional | + | *keywords - optional |
− | * author - mandatory | + | *author - mandatory |
− | * maintainers - optional | + | *maintainers - optional |
− | * license - optional. Follow the [spdx naming convention](https://spdx.org/licenses/) | + | *license - optional. Follow the [spdx naming convention](https://spdx.org/licenses/) |
Other properties (e.g. from base NPM spec) are ignored if present | Other properties (e.g. from base NPM spec) are ignored if present | ||
− | == Dependencies == | + | ==Dependencies== |
A fhir package may have dependencies. It SHALL always have at least one dependency to hl7.fhir.core which specifies the FHIR version. Package consumers should be aware of these dependencies and resolve them by downloading and installing each dependency recursively. | A fhir package may have dependencies. It SHALL always have at least one dependency to hl7.fhir.core which specifies the FHIR version. Package consumers should be aware of these dependencies and resolve them by downloading and installing each dependency recursively. | ||
− | = Package Content = | + | =Package Content= |
A package contains a set of FHIR conformance resources in the JSON format for the specified FHIR version. Each conformance resource is saved in a separate .JSON file. | A package contains a set of FHIR conformance resources in the JSON format for the specified FHIR version. Each conformance resource is saved in a separate .JSON file. | ||
All conformance resource files are saved in the 'package' directly under the root. | All conformance resource files are saved in the 'package' directly under the root. | ||
− | = Meta packages = | + | =Meta packages= |
Packages MAY instead of having content only reference other packages. This is called a meta package. | Packages MAY instead of having content only reference other packages. This is called a meta package. | ||
Line 155: | Line 156: | ||
acme.api.profiles | acme.api.profiles | ||
− | = Implementation Guides and packages = | + | =Implementation Guides and packages= |
All FHIR Implementation Guides are published as NPM packages, one package for each IG. This is the primary way to distribute IGs for computational use (validation, code generation, etc). | All FHIR Implementation Guides are published as NPM packages, one package for each IG. This is the primary way to distribute IGs for computational use (validation, code generation, etc). | ||
− | == Package Manifest properties for IGs == | + | ==Package Manifest properties for IGs== |
− | * name = ImplementationGuide.packageId | + | *name = ImplementationGuide.packageId |
− | * version = ImplementationGuide.version - note: Semver SHALL be used for packages published by HL7 or the FHIR Foundation | + | *version = ImplementationGuide.version - note: Semver SHALL be used for packages published by HL7 or the FHIR Foundation |
− | * canonical = ImplementationGuide.url - required for IGs | + | *canonical = ImplementationGuide.url - required for IGs |
− | * url = ImplementationGuide.manifest.rendering - required for IGs | + | *url = ImplementationGuide.manifest.rendering - required for IGs |
− | * title = ImplementationGuide.title | + | *title = ImplementationGuide.title |
− | * description = ImplementationGuide.description | + | *description = ImplementationGuide.description |
− | * dependencies = from ImplementationGuide.dependsOn | + | *dependencies = from ImplementationGuide.dependsOn |
− | * author = ImplementationGuide.publisher | + | *author = ImplementationGuide.publisher |
− | * maintainers = ImplementationGuide.contacts | + | *maintainers = ImplementationGuide.contacts |
− | * license = ImplementationGuide.license - mandatory for packages published by HL7 or the FHIR Foundation | + | *license = ImplementationGuide.license - mandatory for packages published by HL7 or the FHIR Foundation |
− | == IG Subsets == | + | ==IG Subsets== |
Additional packages containing subsets of a package information can be created. E.g. if a package is hl7.fhir.us.core, then the package hl7.fhir.us.core.tx would contain only terminologies resources. Except as described for multi-version IGs, sub-packages SHALL not additional information not in scope for the main package, though they may contain additional kinds of computable information not in the main package e.g. hl7.fhir.us.core.xml might contain schematron not found in the main package (but only for profiles that are found in the main package). | Additional packages containing subsets of a package information can be created. E.g. if a package is hl7.fhir.us.core, then the package hl7.fhir.us.core.tx would contain only terminologies resources. Except as described for multi-version IGs, sub-packages SHALL not additional information not in scope for the main package, though they may contain additional kinds of computable information not in the main package e.g. hl7.fhir.us.core.xml might contain schematron not found in the main package (but only for profiles that are found in the main package). | ||
Line 179: | Line 180: | ||
Known subsets (others can be used, but if these sub names are used, they must be for the described purpose): | Known subsets (others can be used, but if these sub names are used, they must be for the described purpose): | ||
− | * .profiles - all structure definitions | + | *.profiles - all structure definitions |
− | * .tx - all code systems, value sets, concept maps | + | *.tx - all code systems, value sets, concept maps |
− | * .api - CapabilityStatements, Search Parameters, Operation Definitions | + | *.api - CapabilityStatements, Search Parameters, Operation Definitions |
− | == Multi-version support == | + | ==Multi-version support== |
When an implementation guide covers multiple FHIR version, the package structure that represents it follows this pattern: | When an implementation guide covers multiple FHIR version, the package structure that represents it follows this pattern: | ||
Line 189: | Line 190: | ||
hl7.fhir.example | hl7.fhir.example | ||
− | * in \package - only package.json and an IG resource in the latest version | + | *in \package - only package.json and an IG resource in the latest version |
− | * in package.json: dependencies on hl7.fhir.example.r2 and hl7.fhir.example.r3 | + | *in package.json: dependencies on hl7.fhir.example.r2 and hl7.fhir.example.r3 |
− | * in IG: latest resource | + | *in IG: latest resource |
hl7.fhir.example.r2 | hl7.fhir.example.r2 | ||
− | * in \package - package.json + resources applicable to R2 | + | *in \package - package.json + resources applicable to R2 |
− | * in package.json: dependencies on hl7.fhir.core | + | *in package.json: dependencies on hl7.fhir.r2.core |
hl7.fhir.example.r3 | hl7.fhir.example.r3 | ||
− | * in \package - package.json + resources applicable to R3 | + | *in \package - package.json + resources applicable to R3 |
− | * in package.json: dependencies on hl7.fhir.core | + | *in package.json: dependencies on hl7.fhir.r3.core |
Revision as of 02:26, 20 September 2019
A FHIR package groups a coherent collection of conformance resources, like StructureDefinitions and ValueSets into an easily distributed NPM package. FHIR packages use a subset of the features used by npm packages.
One use of packages is for FHIR Implementation Guides - they are all published as NPM packages, one package for each IG. See below for further discussion.
Contents
Package name
Each package has a canonical name (a globally unique identifier). A package name consists of one or more namespaces separated by a dot. Each namespace starts with an lowercase alphabet character followed by zero-or-more lowercase alphanumeric characters or a dashes.
The first part of the namespace should identify the author, the authoring organization, or region. The second part of the namespace should identify the functional scope or purpose of the package.
Examples:
hl7.fhir.core (main build) hl7.fhir.us.core hl7.au.base hl7.nl.medmij ihe.pix ihe.mhd
Scoping
A fhir package should not contain an npm scope. Packages published by HL7 or the FHIR foundation SHALL not contain a scope.
Note: Npm packages can [contain a scope](https://docs.npmjs.com/misc/scope). Scopes are a way of grouping related packages together. A scope is usually the owner, and was introduced relatively late in the npm standard. Only the user can add packages to his/her scope. It's a way to identify the official packages from organizations. In Nuget that same logic is enabled with the package prefix, which is cleaner and more readable. A npm scope, starts with at (@) and ends with a slash '/'. It makes both the client and the server more complex to implement. And we want easy and broad adoption.
Name Management
Names under hl7.fhir. or fhir. are assigned by the FHIR Product Director - contact fhir-director@hl7.org for assistance. Implementers may (of course) use any names they wish in other namespaces, but should be careful to preserve global uniqueness.
For Packages published by HL7, when implementers create a subset of the package, implementers are pre-approved to use the following suffixes:
.terminology .conformance .[type]
e.g. hl7.fhir.us.core.structuredefinition - creating packages with names like this does not require approval. Other combinations - use a name in a different namespace, or ask for approval.
Versions
All packages have a mandatory version. [SemVer](https://semver.org/) SHOULD be used (and SHALL be used for packages published by HL7 or the FHIR Foundation)
When comparing two versions that start with a digit (0..9), they SHALL not be interpreted as a string, but as a structured numerical version reference. Package generators SHALL ensure that versions starting with a digit have more recent versions with higher numbers.
Version strings SHALL contain only letters, numbers, and the characters ".", "_", and "-"
Version references
When packages point to dependencies they should refer to the whole package version number and not use wildcards, except for the patch version in a semver version reference:
"hl7.fhir.core" : "3.0.x"
This x here means that it should a package resolver should accept the package with the highest found patch number.
Note: Npm has elaborate logic package version references. It allows version forwarding, ranges, wildcards, etc. The FHIR package standard does not allow this. The only ranges that are allowed are wildcards (x) for the patch version as described here. Most of the matured package managing tools, have acknowledged that having advanced version references would create instability and more confusion than help. Fhir packages also need to be consumed by non technical users. Installing package dependencies should not need a manual.
Version selection strategy
Dependencies with mismatching versions One of the main problems that a package managing standard has to solve is how to resolve deep dependency collision. Dependencies that each have their own dependency on a different version of the same package.
There are several strategies in play with most packaging standards.
1. The owner of the deep dependency should strictly follow the semver rules, and not introduce breaking changes 2. The owner of the consuming dependencies can play loose and fast with their dependency range 3. The client package tool can apply a set of algorithms to upgrade one deep dependency, downgrade the other, or keep multiple dependencies. This can cause type mismatches if the consuming tool lets the shallow dependencies interact. See also [this analysis](https://research.swtch.com/vgo-import) of go packaging.
For FHIR we still need to define more precisely how a project that consumes different versions of the same package should resolve these issues. This is part of a bigger versioning discussion in FHIR.
Format
A FHIR package is a tarball (tar in gzip). The package contains
- a subfolder named 'package'
- a package manifest (package/package.json)
- A set of conformance resource files, also in the package subfolder
- It MAY contain additional content, like example resources or documentation:
- such files SHALL not be in the package subfolder
- this may include XML schemas in an "xml" subfolder
- this may include openAPI files in an "openapi" subfolder
- this may include turtle RDF representations in an rdf folder
- Package consumers SHALL ignore content in other subfolders that they do not use (and most consumers will only use the resources in /package)
Tarballs SHALL be in the original tarball format (e.g. a 99 character file name length limit).
Note: discussion on this - see [[1]]
Package manifest
A package manifest is a json file called 'package.json'. It conforms to the npm package.json format, but contains only a subset of properties. Other properties are allowed, but should be ignored by a FHIR package consumer.
{ "name": "hl7.fhir.us.acme", "version" : "0.1.0", "canonical" : "http://hl7.org/fhir/us/acme", "web" : "http://hl7.org/fhir/us/acme/Draft1", "title" : "ACME project IG", "description": "Describes how the ACME project uses FHIR for it's primary API", "dependencies": { "hl7.fhir.core": "3.0.0", "hl7.fhir.us.core": "1.1.0" }, "keywords": [ "us", "United States", "ACME" ], "author": "hl7", "maintainers": [ { "name": "US Steering Committee", "email": "ussc@lists.hl7.com" } ], "license": "CC0-1.0" }
Package Manifest Properties
- name - mandatory - the globally unique identifier of the package as described above
- version - mandatory - SHOULD use [SemVer](https://semver.org/)
- canonical - optional (but required for IGs - see below)
- url - optional = where information about the package can be found on the web
- title - optional short description for the package
- description - mandatory
- dependencies - at least one to fhir core
- keywords - optional
- author - mandatory
- maintainers - optional
- license - optional. Follow the [spdx naming convention](https://spdx.org/licenses/)
Other properties (e.g. from base NPM spec) are ignored if present
Dependencies
A fhir package may have dependencies. It SHALL always have at least one dependency to hl7.fhir.core which specifies the FHIR version. Package consumers should be aware of these dependencies and resolve them by downloading and installing each dependency recursively.
Package Content
A package contains a set of FHIR conformance resources in the JSON format for the specified FHIR version. Each conformance resource is saved in a separate .JSON file. All conformance resource files are saved in the 'package' directly under the root.
Meta packages
Packages MAY instead of having content only reference other packages. This is called a meta package. Its purpose is to group certain packages and their use case together.
Example: acme.api
Containing only references to acme.api.terminology acme.api.extensions acme.api.profiles
Implementation Guides and packages
All FHIR Implementation Guides are published as NPM packages, one package for each IG. This is the primary way to distribute IGs for computational use (validation, code generation, etc).
Package Manifest properties for IGs
- name = ImplementationGuide.packageId
- version = ImplementationGuide.version - note: Semver SHALL be used for packages published by HL7 or the FHIR Foundation
- canonical = ImplementationGuide.url - required for IGs
- url = ImplementationGuide.manifest.rendering - required for IGs
- title = ImplementationGuide.title
- description = ImplementationGuide.description
- dependencies = from ImplementationGuide.dependsOn
- author = ImplementationGuide.publisher
- maintainers = ImplementationGuide.contacts
- license = ImplementationGuide.license - mandatory for packages published by HL7 or the FHIR Foundation
IG Subsets
Additional packages containing subsets of a package information can be created. E.g. if a package is hl7.fhir.us.core, then the package hl7.fhir.us.core.tx would contain only terminologies resources. Except as described for multi-version IGs, sub-packages SHALL not additional information not in scope for the main package, though they may contain additional kinds of computable information not in the main package e.g. hl7.fhir.us.core.xml might contain schematron not found in the main package (but only for profiles that are found in the main package).
Known subsets (others can be used, but if these sub names are used, they must be for the described purpose):
- .profiles - all structure definitions
- .tx - all code systems, value sets, concept maps
- .api - CapabilityStatements, Search Parameters, Operation Definitions
Multi-version support
When an implementation guide covers multiple FHIR version, the package structure that represents it follows this pattern:
hl7.fhir.example
- in \package - only package.json and an IG resource in the latest version
- in package.json: dependencies on hl7.fhir.example.r2 and hl7.fhir.example.r3
- in IG: latest resource
hl7.fhir.example.r2
- in \package - package.json + resources applicable to R2
- in package.json: dependencies on hl7.fhir.r2.core
hl7.fhir.example.r3
- in \package - package.json + resources applicable to R3
- in package.json: dependencies on hl7.fhir.r3.core