From f45c4119986f35cd5b44736d86c31ba077c56907 Mon Sep 17 00:00:00 2001 From: "dependabot[bot]" <49699333+dependabot[bot]@users.noreply.github.com> Date: Sat, 3 Oct 2026 04:39:27 +0000 Subject: [PATCH 1/8] Bump brace-expansion Bumps the npm_and_yarn group with 1 update in the / directory: [brace-expansion](https://github.com/juliangruber/brace-expansion). Updates `brace-expansion` from 5.0.9 to 5.0.12 - [Release notes](https://github.com/juliangruber/brace-expansion/releases) - [Commits](https://github.com/juliangruber/brace-expansion/compare/v5.0.9...v5.0.12) --- updated-dependencies: - dependency-name: brace-expansion dependency-version: 5.0.12 dependency-type: indirect dependency-group: npm_and_yarn ... Signed-off-by: dependabot[bot] (cherry picked from commit 8d5ddb37dbd6da48fb456e631a75fdae5dfde7df) --- package-lock.json | 6 +++--- 1 file changed, 3 insertions(+), 3 deletions(-) diff --git a/package-lock.json b/package-lock.json index 6544151..e50b6f7 100644 --- a/package-lock.json +++ b/package-lock.json @@ -1249,9 +1249,9 @@ } }, "node_modules/brace-expansion": { - "version": "5.0.9", - "resolved": "https://registry.npmjs.org/brace-expansion/-/brace-expansion-5.0.9.tgz", - "integrity": "sha512-ScQ4IuvIEF1TMlP7Zt+vjJ//9zlPb2SDcxWxM3bk8s6t6GGdJ7KO1dCcTidOPJKePW30LE/2cT7wCyPho9/Wxg==", + "version": "5.0.12", + "resolved": "https://registry.npmjs.org/brace-expansion/-/brace-expansion-5.0.12.tgz", + "integrity": "sha512-YovQ3rzhaLMIrDjNDMkNS01tea93qhEhG5xy8f6+R0l+dw3Ki+5sCoIoI942iuLZTHWogWktgwVDhU09iNEimQ==", "dev": true, "license": "MIT", "dependencies": { From 77aadd219b4cd9179eaa9707cddf89dc33c200ca Mon Sep 17 00:00:00 2001 From: Shinrai Date: Sat, 3 Oct 2026 20:09:45 -0700 Subject: [PATCH 2/8] deps: bump @cldmv/fix-headers to 2.1.4 and restamp file headers Bumps @cldmv/fix-headers to 2.1.4 and re-runs npm run fix:headers. 0 files' headers were restamped. --- package-lock.json | 8 ++++---- package.json | 2 +- 2 files changed, 5 insertions(+), 5 deletions(-) diff --git a/package-lock.json b/package-lock.json index f9ac3c0..96acb30 100644 --- a/package-lock.json +++ b/package-lock.json @@ -22,7 +22,7 @@ "devDependencies": { "@cldmv/configs": "^1.2.0", "@cldmv/eslint-plugin-jsonv": "^1.0.3", - "@cldmv/fix-headers": "^2.1.1", + "@cldmv/fix-headers": "^2.1.4", "@cldmv/jsonv": "^1.0.2", "@cldmv/prettier-plugin-jsonv": "^1.0.1", "@cldmv/vitest-runner": "^1.2.0", @@ -162,9 +162,9 @@ } }, "node_modules/@cldmv/fix-headers": { - "version": "2.1.1", - "resolved": "https://registry.npmjs.org/@cldmv/fix-headers/-/fix-headers-2.1.1.tgz", - "integrity": "sha512-08xW44RvtrKUCTOjUFKHyrDvx6rT70zGqgRR+tdW0R9ElZrHwSg25xCRrZD+U7Dmj5fK9KmtuOWPjZtJYSfzYA==", + "version": "2.1.4", + "resolved": "https://registry.npmjs.org/@cldmv/fix-headers/-/fix-headers-2.1.4.tgz", + "integrity": "sha512-PvCKMztN9k+jOjEpMCANMaDIkNW7cs2qp5P73JVzResk1+DfqhoZVqT9jpTT8cUu+6OGszsNqj8/X0Q9IhfNtg==", "dev": true, "license": "Apache-2.0", "dependencies": { diff --git a/package.json b/package.json index d7f37ec..dd644da 100644 --- a/package.json +++ b/package.json @@ -90,7 +90,7 @@ "devDependencies": { "@cldmv/configs": "^1.2.0", "@cldmv/eslint-plugin-jsonv": "^1.0.3", - "@cldmv/fix-headers": "^2.1.1", + "@cldmv/fix-headers": "^2.1.4", "@cldmv/jsonv": "^1.0.2", "@cldmv/prettier-plugin-jsonv": "^1.0.1", "@cldmv/vitest-runner": "^1.2.0", From 6b28ea736af2e042878e48ec9fd202af02737407 Mon Sep 17 00:00:00 2001 From: "cldmv-bot[bot]" <230771808+cldmv-bot[bot]@users.noreply.github.com> Date: Sun, 4 Oct 2026 03:25:15 +0000 Subject: [PATCH 3/8] chore: bump version to 1.1.12 --- package-lock.json | 4 ++-- package.json | 2 +- 2 files changed, 3 insertions(+), 3 deletions(-) diff --git a/package-lock.json b/package-lock.json index 96acb30..40f0a8b 100644 --- a/package-lock.json +++ b/package-lock.json @@ -1,12 +1,12 @@ { "name": "@cldmv/git-embedded", - "version": "1.1.11", + "version": "1.1.12", "lockfileVersion": 3, "requires": true, "packages": { "": { "name": "@cldmv/git-embedded", - "version": "1.1.11", + "version": "1.1.12", "license": "Apache-2.0", "dependencies": { "@cldmv/slothlet": "^3.7.0", diff --git a/package.json b/package.json index dd644da..2cb42dc 100644 --- a/package.json +++ b/package.json @@ -1,6 +1,6 @@ { "name": "@cldmv/git-embedded", - "version": "1.1.11", + "version": "1.1.12", "description": "Manage embedded git repositories (anonymous gitlinks) without .gitmodules. Provides hooks that restore standard git-command ergonomics for embedded children while keeping the child's origin URL out of the public parent repo.", "type": "module", "license": "Apache-2.0", From 58f8c677c742e481903bf94837262fbfde015087 Mon Sep 17 00:00:00 2001 From: Shinrai Date: Sat, 3 Oct 2026 20:51:44 -0700 Subject: [PATCH 4/8] docs: backfill changelogs for v1.0.0 through v1.1.11 --- docs/changelog/v1/v1.0.0.md | 60 +++++++++++++++++++ docs/changelog/v1/v1.1.0.md | 112 +++++++++++++++++++++++++++++++++++ docs/changelog/v1/v1.1.1.md | 35 +++++++++++ docs/changelog/v1/v1.1.10.md | 44 ++++++++++++++ docs/changelog/v1/v1.1.11.md | 28 +++++++++ docs/changelog/v1/v1.1.2.md | 23 +++++++ docs/changelog/v1/v1.1.3.md | 40 +++++++++++++ docs/changelog/v1/v1.1.4.md | 23 +++++++ docs/changelog/v1/v1.1.5.md | 23 +++++++ docs/changelog/v1/v1.1.6.md | 23 +++++++ docs/changelog/v1/v1.1.7.md | 32 ++++++++++ docs/changelog/v1/v1.1.8.md | 22 +++++++ docs/changelog/v1/v1.1.9.md | 30 ++++++++++ 13 files changed, 495 insertions(+) create mode 100644 docs/changelog/v1/v1.0.0.md create mode 100644 docs/changelog/v1/v1.1.0.md create mode 100644 docs/changelog/v1/v1.1.1.md create mode 100644 docs/changelog/v1/v1.1.10.md create mode 100644 docs/changelog/v1/v1.1.11.md create mode 100644 docs/changelog/v1/v1.1.2.md create mode 100644 docs/changelog/v1/v1.1.3.md create mode 100644 docs/changelog/v1/v1.1.4.md create mode 100644 docs/changelog/v1/v1.1.5.md create mode 100644 docs/changelog/v1/v1.1.6.md create mode 100644 docs/changelog/v1/v1.1.7.md create mode 100644 docs/changelog/v1/v1.1.8.md create mode 100644 docs/changelog/v1/v1.1.9.md diff --git a/docs/changelog/v1/v1.0.0.md b/docs/changelog/v1/v1.0.0.md new file mode 100644 index 0000000..e3d8834 --- /dev/null +++ b/docs/changelog/v1/v1.0.0.md @@ -0,0 +1,60 @@ +# @cldmv/git-embedded v1.0.0 Changelog + +**Release Date**: May 2026 +**Release Type**: Major (initial release) +**Availability**: Published to npm ([@cldmv/git-embedded@1.0.0](https://www.npmjs.com/package/@cldmv/git-embedded/v/1.0.0)); the repository has no `v1.0.0` tag + +--- + +## Overview + +Initial release of `@cldmv/git-embedded`, a CLI and hook set for managing embedded git repositories (anonymous gitlinks, tree entries of mode `160000`) without a `.gitmodules` registry. The package restores the working-tree ergonomics that submodule registration normally provides, while keeping the child repository's origin URL out of the public parent repository. + +The motivating use case is an open-source repository that runs a comprehensive test suite in CI but keeps that suite in a private child repo. The mechanism is general: the hooks work for any gitlink, such as private vendor directories or license-restricted dependencies. + +--- + +## ✨ Features + +### Hooks + +- **`reference-transaction`** blocks HEAD-moving operations (`git checkout`, `git switch`, `git reset`, `git pull`, `git merge`, `git rebase`, `git bisect`, `git cherry-pick`) when any embedded child repo has uncommitted changes, so the parent never moves to a new commit while a child stays behind, dirty. It requires git 2.28 or newer. +- **`update-embedded-repos`** is installed as `post-checkout`, `post-merge` and `post-rewrite`. After a HEAD-moving operation it walks every gitlink in the new HEAD and updates the embedded child to its pinned SHA, fetching missing commits from the child's own `origin` remote. + +### CLI (`git embedded …`) + +- `doctor` inspects the environment and reports what an install would do; it takes no action. +- `install-hooks` installs the per-repo hooks into `.git/hooks`, adapting to the existing setup. With nothing configured it offers to create a dispatcher at `~/.config/git/hooks/_dispatch`, link every standard hook name to it and set the global `core.hooksPath`; with a canonical dispatcher already present it installs only the per-repo scripts; with a dispatcher missing entries it offers to add the missing symlinks. It refuses to install over Husky, lefthook, simple-git-hooks or pre-commit, and over a non-conforming dispatcher or bare `.githooks/`, and prints hand-integration instructions instead. +- `uninstall-hooks` removes only hooks recognizably installed by this CLI. +- `init` runs `install-hooks` and then sets `advice.addEmbeddedRepo=false` to silence git's "embedded git repository" warning. +- `link ` clones a repo and stages it as an anonymous gitlink, without committing and without writing `.gitmodules`. +- `install-template` installs the hooks into `init.templateDir/hooks` so new repositories start with them wired. +- `print-hook-script ` writes a packaged hook script to stdout. +- `version` (aliases `-V`, `--version`) prints the package, Node and platform versions. +- `install-hooks` accepts `--no-symlinks` (hard links instead of symbolic links, which avoids the Windows UAC prompt on a single volume), `--yes` and `--dispatcher-dir `. + +### Platform and requirements + +- Node 20.19 or newer for the CLI; the hooks themselves are shell scripts with no Node dependency at hook time. +- Linux, macOS and Windows. On Windows, symlink creation requests a one-shot elevation unless `--no-symlinks` is used. + +--- + +## 📚 Documentation + +- README covering the gitlink model, installation, usage, manual install and compatibility. +- `docs/design.md` describing how the hooks work, the coverage matrix, limitations and the comparison with standard submodules. +- `docs/use-case-private-tests.md` describing the private-tests motivation, threat model and licensing strategy. + +--- + +## 🔧 Dependencies + +Runtime dependencies: `@cldmv/slothlet` `^3.7.0`, `@cldmv/wisp` `^1.0.1`, `chalk` `^5.4.1`, `commander` `^14.0.0`, `marked` `^15.0.12` and `marked-terminal` `^7.3.0`. Development tooling: `vitest` `^2.1.9` with `@vitest/coverage-v8`, `eslint` `^9.18.0` and `prettier` `^3.4.2`. + +--- + +## Upgrade notes + +- First release; nothing to migrate. +- Next release: [v1.1.0](./v1.1.0.md). diff --git a/docs/changelog/v1/v1.1.0.md b/docs/changelog/v1/v1.1.0.md new file mode 100644 index 0000000..332cd1e --- /dev/null +++ b/docs/changelog/v1/v1.1.0.md @@ -0,0 +1,112 @@ +# @cldmv/git-embedded v1.1.0 Changelog + +**Release Date**: July 2026 +**Release Type**: Minor +**Availability**: Release commit on `master` only; not tagged and not published to npm + +--- + +## Overview + +Version 1.1.0 turns git-embedded from a hook installer into a full workflow for embedded children. It adds commands to restore children on a fresh clone (`restore`), share their URLs between machines (`record`, `export`), and move them to new pins after a pull (`sync`). The `reference-transaction` guard gains configurable modes, and a new `pre-push` hook refuses to publish a parent whose pins point at child commits that were never pushed. + +Runtime code changed substantially. Two defaults change for existing installs, so read [Breaking Changes](#-breaking-changes) before upgrading, even though this is a minor release. This version was never published to npm; users on npm move from [v1.0.0](./v1.0.0.md) directly to [v1.1.1](./v1.1.1.md), which includes everything here. + +--- + +## 💥 Breaking Changes + +### A new `pre-push` hook rejects pushes with unpublished pins + +`install-hooks` and `install-template` now install a `pre-push` hook alongside the existing four (`PACKAGE_HOOK_MAP` gains `pre-push`; `print-hook-script` accepts it). With the default `embedded.pushRecurse=check`, a push is rejected when a gitlink pin that is new to the remote is not reachable from any `origin` branch of the child, or when the child repo is not present locally to verify against. A push that worked on v1.0.0 can therefore fail on v1.1.0 once the hook is installed. + +Upgrade steps: + +- Hooks are copied into a repo's `.git/hooks`, so existing repos only pick this up when `git embedded install-hooks` is run again. +- Push the child first when the rejection says to, or set `git config embedded.pushRecurse on-demand` to have the hook try pushing the child's current branch before verifying. +- Set `embedded.pushRecurse=off` to disable the check, or bypass once with `git -c embedded.pushRecurse=off push`. + +### The `reference-transaction` guard defaults to `precise`, not "block on any dirty child" + +On v1.0.0 any uncommitted change in any child blocked every HEAD move in the parent. The guard now reads `embedded.guard` (`precise`, `strict` or `off`, default `precise`). In `precise` mode only a dirty child whose HEAD differs from the pin in the new commit blocks; clean children, and dirty children whose pin already equals their HEAD, no longer block. That is more permissive than v1.0.0 by default. + +Upgrade steps: + +- To keep the v1.0.0 "dirty child blocks everything" behavior, and additionally refuse a parent commit while any child's pin is stale, set `git config embedded.guard strict`. +- `strict` blocks any dirty child on any move, and on commit, merge and cherry-pick requires each child's HEAD to equal its recorded pin. Checkout and reset only require all children clean. +- `embedded.guard=off` disables guarding; `git -c embedded.guard= ` overrides once. +- Because the hook script is copied into `.git/hooks`, re-run `git embedded install-hooks` to receive the new guard. + +### `link` accepts empty directories and now refuses targets outside the worktree + +`git embedded link ` previously refused any existing path. It now clones into a missing or empty real directory (a fresh clone of a parent leaves each gitlink as an empty directory), and still refuses a non-empty directory, a file, an unreadable path or a symlink (even to an empty directory). It also exits with status 2 when the target resolves outside the repository worktree, and records the child under the normalized repo-relative path (`./tests` and `tests/` both record as `tests`). + +--- + +## ✨ Features + +### Restoring children on a fresh clone: `git embedded restore` + +A fresh clone of the parent materializes each embedded child as an empty directory, because the parent commits a path and a pinned SHA but never a URL. `restore` clones each child and checks out its pinned SHA. It accepts `[paths...]`, `--from `, `--base `, `--skip ` and `--dry-run`. + +Each child's clone URL is resolved from up to four optional sources, strictest first: + +1. The local config registry, `embedded..url` in the clone's `.git/config` (never committed). +2. A manifest JSON file passed with `--from`. +3. `--base `, which derives `/.git`. +4. Convention: the parent's origin with its last path segment replaced by `.git`, handling both URL-style and scp-style origins. + +Every clone is SHA-verified. If the pinned commit is absent after a fetch (for example a convention guess named the wrong repo), the clone that `restore` created is removed and the child is reported `pinned-mismatch`, so a wrong guess never leaves the wrong code in place. Per-child outcomes are `restored`, `already-present`, `unresolved`, `pinned-mismatch` and `skipped`; the command exits non-zero if any child is `unresolved` or `pinned-mismatch`. + +Branches are resolved with the same layering (`embedded..branch`, then the manifest); when neither provides one and exactly one `origin` branch contains the pin, that branch is used. The child then ends on the branch at the pin with upstream tracking set to `origin/`. An ambiguous or unmatched pin keeps a detached checkout. A successful restore registers the URL and branch locally. + +### Sharing URLs between machines: `record` and `export` + +- `git embedded record [paths...]` writes the origin URL and current branch of every child present on disk into the local registry. +- `git embedded export [-o ] [--scan]` serializes the registry to a manifest JSON on stdout or a file; `--scan` records present children first. When `-o` writes inside the worktree the filename is appended to `.git/info/exclude`. The manifest contains the child URLs the design keeps out of the tree and is meant to be carried out-of-band, never committed. + +### Day-2 syncing: `git embedded sync` + +After the parent pulls commits that move gitlink pins, `sync [paths...] [--skip ] [--dry-run]` moves the children already on disk to the new pins; it never touches the parent. A clean child follows the pin: a child on its registered branch fast-forwards, and a detached child snaps to the pin. Work in progress is reported and left alone: `dirty` (uncommitted changes), `ahead` (commits beyond the pin) and `unregistered-branch`. A pin missing locally triggers one `git fetch origin` in the child; if it is still absent the child is `pin-unavailable` and the command exits non-zero, as does an unexpected checkout failure (`sync-failed`). + +### Guard configuration + +- `embedded.guard` (`precise`, `strict`, `off`) controls when the `reference-transaction` hook blocks a HEAD move; see Breaking Changes for the semantics. +- `embedded.pushRecurse` (`check`, `on-demand`, `off`) controls the `pre-push` verification. The hook is git-embedded's analog of `git push --recurse-submodules=check`, which stock git cannot provide for children not registered in `.gitmodules`. +- `link` now records the child's URL and branch into the local registry after staging. + +--- + +## 🐛 Bug Fixes + +- The `reference-transaction` guard now watches the current branch ref (`refs/heads/`) as well as `HEAD`. Git 2.54 reports a plain commit only on the branch ref, so on that version commits slipped past a guard that matched `HEAD` alone. +- The guard no longer misreads a child it cannot read: an unborn child (fresh `git init`) is skipped, and in `strict` mode a broken or corrupt child fails closed. Git commands run inside a child are anchored with `GIT_CEILING_DIRECTORIES` so a broken child cannot silently resolve the parent's HEAD, and child paths containing spaces are handled. +- `link` passes `--` before the URL and path to `git clone` and `git add`, so a value starting with `-` cannot be interpreted as a git option (such as `--upload-pack`). + +--- + +## 📚 Documentation + +- README documents the guard configuration table, `restore`, branch-aware checkout, obscured children, `record` / `export`, and `sync`. +- `docs/design.md` is expanded to cover the guard modes, the push check, the registry and the restore/sync model. + +--- + +## 🔧 CI & tooling + +- The v4 workflow set from `CLDMV/.github` is added: CI, CodeQL, dependency review, Dependabot configuration and auto-merge, feature-PR and release automation, hotfix redirection, branch retention, labeler, stale, welcome, tag health, master-commit audit, publish and bootstrap. +- New test suites cover the provisioning commands (`tests/embedded-provisioning.test.mjs`) and the hook guards (`tests/hook-guards.test.mjs`). +- `tmp/` is added to `.gitignore`. + +## 🔧 Dependencies + +- Dev dependencies `vitest` and `@vitest/coverage-v8` move from `^2.1.9` to `^4.1.10`. Runtime dependencies are unchanged. + +--- + +## Upgrade notes + +- This version was not published to npm; install [v1.1.1](./v1.1.1.md) or later from the registry. +- Re-run `git embedded install-hooks` in each parent repo to install the new `pre-push` hook and the updated `reference-transaction` guard. +- Set `embedded.guard=strict` if you rely on the v1.0.0 behavior of blocking on any dirty child. +- No runtime dependency or `engines` changes. diff --git a/docs/changelog/v1/v1.1.1.md b/docs/changelog/v1/v1.1.1.md new file mode 100644 index 0000000..24ddcbc --- /dev/null +++ b/docs/changelog/v1/v1.1.1.md @@ -0,0 +1,35 @@ +# @cldmv/git-embedded v1.1.1 Changelog + +**Release Date**: July 2026 +**Release Type**: Patch + +--- + +## Overview + +A tooling release that adds the missing `build:ci` script and moves the test suite onto `@cldmv/vitest-runner`. No runtime behavior changed: the only edits under `src/` are coverage-ignore comments, plus a one-line `/* v8 ignore else */` restructuring in the help renderer that does not change its output. + +This is the first version of the [v1.1.0](./v1.1.0.md) feature set published to npm, so it carries everything described there. Users upgrading from the published v1.0.0 should read that changelog's Breaking Changes first. + +--- + +## 🔧 CI & tooling + +- `package.json` gains `build:ci` (a no-op echo, since the package ships source) and `ci:coverage`, which runs `npm run coverage`. The shared CI workflows expect both scripts to exist ([#15](https://github.com/CLDMV/git-embedded/pull/15)). +- `test` and `coverage` now run `node tests/run-vitest.mjs`, a thin wrapper around `@cldmv/vitest-runner` that runs each test file in its own process and, under coverage, merges per-file blobs so one process never holds the whole suite's coverage data. `coverage` passes `--coverage-quiet`; `test:watch` still calls vitest directly. +- `.configs/vitest.config.mjs` inlines `@cldmv/slothlet` via `server.deps.inline` so the coverage collector attributes execution of the slothlet-loaded API modules, and excludes the Windows-only elevation helpers (`src/api/link/elevate-windows.mjs`, `src/lib/elevate-windows-child.mjs`) from coverage. +- About 5,000 lines of new tests (CLI, hooks, detectors, link, restore/sync, help rendering) raise coverage of `src/`; the `v8 ignore` comments added under `src/` mark defensive branches the suite cannot reproduce. +- CI skips the type-check step with a recorded reason: the API is composed dynamically by slothlet and cannot be statically typed. +- Added the `cla.yml`, `release-notify.yml` and `scorecard.yml` workflows, and refreshed the headers of the existing workflow files. + +## 🔧 Dependencies + +- **NEW** dev dependency: `@cldmv/vitest-runner` `^1.2.0`. +- Runtime dependencies are unchanged. + +--- + +## Upgrade notes + +- No runtime changes; no action required beyond the notes in [v1.1.0](./v1.1.0.md) if upgrading from v1.0.0. +- Previous: [v1.1.0](./v1.1.0.md). Next: [v1.1.2](./v1.1.2.md). diff --git a/docs/changelog/v1/v1.1.10.md b/docs/changelog/v1/v1.1.10.md new file mode 100644 index 0000000..6154868 --- /dev/null +++ b/docs/changelog/v1/v1.1.10.md @@ -0,0 +1,44 @@ +# @cldmv/git-embedded v1.1.10 Changelog + +**Release Date**: October 2026 +**Release Type**: Patch + +--- + +## Overview + +A maintenance release with no change to the CLI's behavior. Every source, hook-adjacent module, test, config and workflow file now carries the uniform CLDMV file header from the shared `@cldmv/configs` fix-headers config, the `LICENSE` file is restored to the verbatim Apache-2.0 text, the workflows are synced with the `CLDMV/.github` v4.29.2 templates, a skipped PR run can no longer satisfy `✅ Required PR Check`, and a batch of dependency updates lands. The only edits under `src/` and `bin/` are the new header comments; `bin/git-embedded.mjs` keeps its `#!/usr/bin/env node` line first. + +--- + +## 🔧 CI & tooling + +### Uniform file headers from the shared CLDMV config ([#83](https://github.com/CLDMV/git-embedded/pull/83)) + +A new `fix:headers` script runs `@cldmv/fix-headers` against `.configs/fix-headers.json`, which extends `@cldmv/configs/fix-headers.json`. The first run stamped every file under `src/`, `bin/`, `tests/` and `.configs/` with a header, and rewrote the workflow headers to the same layout, with ISO 8601 dates. + +### v4 workflow sync with CLDMV/.github v4.29.2 ([#80](https://github.com/CLDMV/git-embedded/pull/80)) + +The workflows are synced with the current templates, adding `bundle-size.yml`, `dependabot-recreate.yml`, `member-auto-merge.yml`, `pr-notify.yml`, `provenance.yml` and `release-merge.yml`, keeping the template's full `release-merge` workflow list, and correcting the template header metadata. + +### A skipped PR run no longer satisfies Required PR Check ([#84](https://github.com/CLDMV/git-embedded/pull/84)) + +On an in-repo feature PR, the `pull_request` run skips the `required-check` mirror job because the push run on the head branch owns the status. GitHub still posts a check run for a skipped job and treats a skipped required check as passing, so the skipped job, named `✅ Required PR Check`, could green-light the ruleset (and auto-merge) before the push run's real mirror existed. The job name is now an expression that evaluates to `✅ Required PR Check` only on the paths that own the status. + +## 📚 Documentation + +- `LICENSE` is restored to the verbatim Apache-2.0 text ([#79](https://github.com/CLDMV/git-embedded/pull/79)): the Trademarks clause regains its "reasonable and customary use" wording, and the appendix's example notice is back to its `Copyright [yyyy] [name of copyright owner]` placeholder instead of `Copyright 2026 CLDMV`. The license terms are unchanged. + +## 🔧 Dependencies + +- `@cldmv/slothlet` 3.15.3 → 3.17.0 within the minor group ([#76](https://github.com/CLDMV/git-embedded/pull/76)); the runtime range stays `^3.7.0`. +- `chalk` 6.0.0 → 6.0.1 and other updates within the patch group ([#82](https://github.com/CLDMV/git-embedded/pull/82)); the runtime range stays `^6.0.0`. +- `eslint` 10.10.0 → 10.11.0 ([#73](https://github.com/CLDMV/git-embedded/pull/73)), `prettier` 3.9.6 → 3.9.9 ([#74](https://github.com/CLDMV/git-embedded/pull/74), [#82](https://github.com/CLDMV/git-embedded/pull/82)), and `vitest` and `@vitest/coverage-v8` 5.0.0 → 5.0.2 ([#72](https://github.com/CLDMV/git-embedded/pull/72), [#82](https://github.com/CLDMV/git-embedded/pull/82)) — dev-only. +- `@cldmv/eslint-plugin-jsonv` 1.0.3 → 1.0.10, `@cldmv/jsonv` 1.0.7 → 1.0.9 and `@cldmv/prettier-plugin-jsonv` 1.0.1 → 1.0.6 in the lockfile (dev-only). +- **NEW** dev dependencies: `@cldmv/configs` `^1.2.0` and `@cldmv/fix-headers` `^2.1.1`, for the header tooling ([#83](https://github.com/CLDMV/git-embedded/pull/83)). + +--- + +## Upgrade notes + +- No runtime changes — drop-in for v1.1.9. diff --git a/docs/changelog/v1/v1.1.11.md b/docs/changelog/v1/v1.1.11.md new file mode 100644 index 0000000..ff88157 --- /dev/null +++ b/docs/changelog/v1/v1.1.11.md @@ -0,0 +1,28 @@ +# @cldmv/git-embedded v1.1.11 Changelog + +**Release Date**: October 2026 +**Release Type**: Patch + +--- + +## Overview + +A CI and lockfile release: the `✅ Required PR Check` mirror job now runs on every path instead of being skipped on in-repo feature PRs, and the lockfile picks up newer versions of several dependencies. No source file or dependency range changed. The release PR's auto-generated notes also listed the v1.1.10 changes again; only the items below are new in this version. + +--- + +## 🔧 CI & tooling + +### Run the in-repo PR mirror job instead of skipping it ([#88](https://github.com/CLDMV/git-embedded/pull/88)) + +The fix in [v1.1.10](./v1.1.10.md) gave the mirror job a conditional name so a skipped run would not report under the required name, but GitHub does not evaluate the `name:` of a skipped job, so the skipped run showed up under the raw expression text. The job now always runs (`if: always()`), so its name is always evaluated: on the paths that own the status it reports as `✅ Required PR Check` and mirrors the test matrix's result, and on an in-repo feature PR's `pull_request` run it reports as `⏭️ Required PR Check (reported by the push run)` and exits as a no-op. + +## 🔧 Dependencies + +- Lockfile updates within existing ranges ([#85](https://github.com/CLDMV/git-embedded/pull/85), [#86](https://github.com/CLDMV/git-embedded/pull/86)): the runtime dependency `@cldmv/slothlet` 3.17.0 → 3.21.0 (range still `^3.7.0`), and dev-only `@cldmv/vitest-runner` 1.2.0 → 1.5.1, `@cldmv/eslint-plugin-jsonv` 1.0.10 → 1.0.13, `@cldmv/jsonv` 1.0.9 → 1.1.1 and `@cldmv/prettier-plugin-jsonv` 1.0.6 → 1.1.0. + +--- + +## Upgrade notes + +- No runtime changes — drop-in for v1.1.10. diff --git a/docs/changelog/v1/v1.1.2.md b/docs/changelog/v1/v1.1.2.md new file mode 100644 index 0000000..e2e9d98 --- /dev/null +++ b/docs/changelog/v1/v1.1.2.md @@ -0,0 +1,23 @@ +# @cldmv/git-embedded v1.1.2 Changelog + +**Release Date**: July 2026 +**Release Type**: Patch + +--- + +## Overview + +A test-logging release: vitest now uses the `dot` reporter. No runtime code and no dependencies changed; the published CLI and hooks are identical to [v1.1.1](./v1.1.1.md). + +--- + +## 🔧 CI & tooling + +- `.configs/vitest.config.mjs` sets `reporters: ["dot"]`, which prints one character per test file instead of reprinting a full per-file pass/fail block for every file in the non-interactive CI fallback. The final "Test Files" and "Tests" summary is unaffected ([#19](https://github.com/CLDMV/git-embedded/pull/19), released in [#20](https://github.com/CLDMV/git-embedded/pull/20)). + +--- + +## Upgrade notes + +- No runtime changes. +- Previous: [v1.1.1](./v1.1.1.md). diff --git a/docs/changelog/v1/v1.1.3.md b/docs/changelog/v1/v1.1.3.md new file mode 100644 index 0000000..6d745e3 --- /dev/null +++ b/docs/changelog/v1/v1.1.3.md @@ -0,0 +1,40 @@ +# @cldmv/git-embedded v1.1.3 Changelog + +**Release Date**: July 2026 +**Release Type**: Patch + +--- + +## Overview + +Version 1.1.3 raises the minimum supported Node.js version from 20.19 to 22.12 and upgrades the runtime dependencies `chalk` and `commander` to new major versions, despite being a patch release. The CLI source under `src/` and `bin/` is unchanged. The rest of the release replaces the repository's inlined v4 release-flow workflows with thin callers of the `CLDMV/.github` reusable workflows ([#23](https://github.com/CLDMV/git-embedded/pull/23)). + +--- + +## 💥 Breaking Changes + +### `engines.node` raised to `>=22.12.0` (despite being a patch release) + +`package.json` `engines.node` changed from `>=20.19.0` to `>=22.12.0`, the floor the upgraded `commander` 15 runtime dependency requires. Installing on Node 20 now produces an `EBADENGINE` warning (or an error with `engine-strict`), and the package is no longer tested on Node 20. The CI matrix default `min_node_version` in `ci.yml` and `publish.yml` moved from `20` to `22` in the same release. + +**Upgrade steps**: move to Node 22.12 or newer (an even-numbered LTS line) before installing 1.1.3, or stay on 1.1.2 if you must remain on Node 20. + +--- + +## 🔧 Dependencies + +- Runtime `chalk` `^5.4.1` → `^6.0.0` and `commander` `^14.0.0` → `^15.0.0`. These are major-version bumps of libraries the CLI uses for colored output and argument parsing, and they set the new Node floor: `commander` 15 declares `engines.node` `>=22.12.0` and `chalk` 6 declares `>=22`. No CLI flags or options changed in this release. +- Dev-only: `@eslint/json` `^0.10.0` → `^2.0.1`, `@eslint/markdown` `^6.2.2` → `^8.0.3`, `eslint` `^9.18.0` → `^10.8.0`, `globals` `^15.14.0` → `^17.7.0`. + +## 🔧 CI & tooling + +- `feature-pr.yml`, `hotfix-redirector.yml`, `hotfixes-release.yml`, `next-release.yml`, `next-reset.yml` and `pr-title-normalizer.yml` are now thin callers pinned to the `@v4` reusable workflows in `CLDMV/.github`; the step-by-step job logic they used to carry inline moved into the reusables. `next-release.yml` and `hotfixes-release.yml` also gain a `workflow_dispatch` trigger so a release PR can be opened or refreshed manually. +- `master-commit-audit.yml` no longer hardcodes `allowed_patterns`; it inherits the canonical default from the `audit-commit-subject` action, which accepts the `release: vX.Y.Z - ` subject form. +- A stopgap `build` script (`echo 'no build step ...'`) is added so the coverage-badge job's default `npm run build` succeeds. + +--- + +## Upgrade notes + +- Requires Node.js 22.12 or newer. If you are on Node 20, stay on 1.1.2 or upgrade Node first. +- No `git-embedded` command, flag, hook or config key changed. diff --git a/docs/changelog/v1/v1.1.4.md b/docs/changelog/v1/v1.1.4.md new file mode 100644 index 0000000..deb33bc --- /dev/null +++ b/docs/changelog/v1/v1.1.4.md @@ -0,0 +1,23 @@ +# @cldmv/git-embedded v1.1.4 Changelog + +**Release Date**: August 2026 +**Release Type**: Patch + +--- + +## Overview + +A test-tooling release: every vitest test file is renamed from `*.test.mjs` to the CLDMV-standard `*.test.vitest.mjs`, and the configs that discover them are updated to match. No runtime code changed ([#39](https://github.com/CLDMV/git-embedded/pull/39)). + +--- + +## 🔧 CI & tooling + +- All 17 test files under `tests/` are renamed (for example `tests/helpers.test.mjs` → `tests/helpers.test.vitest.mjs`), keeping history via rename. +- `.configs/vitest.config.mjs` `include` and `tests/run-vitest.mjs` `testFilePattern` now match `*.test.vitest.mjs`, and the test-globals block in `.configs/eslint.config.mjs` uses the same glob. A handful of the renamed tests also had one to six lines edited to follow the new file names. + +--- + +## Upgrade notes + +- No runtime changes. The `tests/` folder is not part of the published package. diff --git a/docs/changelog/v1/v1.1.5.md b/docs/changelog/v1/v1.1.5.md new file mode 100644 index 0000000..af2fe59 --- /dev/null +++ b/docs/changelog/v1/v1.1.5.md @@ -0,0 +1,23 @@ +# @cldmv/git-embedded v1.1.5 Changelog + +**Release Date**: August 2026 +**Release Type**: Patch +**Availability**: Release commit on `master` only; not tagged and not published to npm + +--- + +## Overview + +A CI-only release: the `ci.yml` concurrency policy is reworked so release-relevant runs are never cancelled. No runtime code changed. Version 1.1.5 was never tagged or published; its change reached npm as part of [v1.1.6](./v1.1.6.md) ([#41](https://github.com/CLDMV/git-embedded/pull/41)). + +--- + +## 🔧 CI & tooling + +- `ci.yml` concurrency: runs on feature branches and feature PRs are still cancelled when superseded, but runs for pushes to the release base branch (`CLDMV_RELEASE_BASE`, falling back to the repository's default branch), to `next` and `hotfixes`, and for the `next`/`hotfixes` release PRs now each get a unique group (the run id is appended). Every run in the burst of pushes a release produces therefore completes and reports a green check, instead of an earlier run being cancelled into a red X on the release PR. + +--- + +## Upgrade notes + +- No runtime changes, and no package was published for this version. diff --git a/docs/changelog/v1/v1.1.6.md b/docs/changelog/v1/v1.1.6.md new file mode 100644 index 0000000..aab4304 --- /dev/null +++ b/docs/changelog/v1/v1.1.6.md @@ -0,0 +1,23 @@ +# @cldmv/git-embedded v1.1.6 Changelog + +**Release Date**: August 2026 +**Release Type**: Patch + +--- + +## Overview + +A CI-only release: the local `✅ Required PR Check` mirror job in `ci.yml` now picks its runner the same way the reusable CI workflow does. No runtime code changed ([#45](https://github.com/CLDMV/git-embedded/pull/45)). + +--- + +## 🔧 CI & tooling + +- The mirror job's `runs-on` was hardcoded to `ubuntu-latest`. It now resolves to the `RUNS_ON_DEFAULT` variable when set, `cldmv-runners` for private CLDMV repositories, and `ubuntu-latest` otherwise, so the required check can still provision a runner on private repositories. +- Includes the `ci.yml` concurrency rework that was committed as the untagged v1.1.5 (see [v1.1.5](./v1.1.5.md)). + +--- + +## Upgrade notes + +- No runtime changes. diff --git a/docs/changelog/v1/v1.1.7.md b/docs/changelog/v1/v1.1.7.md new file mode 100644 index 0000000..2b6cf00 --- /dev/null +++ b/docs/changelog/v1/v1.1.7.md @@ -0,0 +1,32 @@ +# @cldmv/git-embedded v1.1.7 Changelog + +**Release Date**: September 2026 +**Release Type**: Patch + +--- + +## Overview + +A formatting release. The `postcss` bump the release title names is a lockfile-only update of a transitive development dependency; alongside it, the repository-wide Prettier pass was applied to sources, shipped message templates, docs and workflows. Runtime behavior is unchanged: the edits under `src/` only re-wrap lines, with no change to logic, option names or output text ([#62](https://github.com/CLDMV/git-embedded/pull/62)). + +--- + +## 🔧 CI & tooling + +- Formatting only in `src/api/cli/install-hooks.mjs`, `src/api/cli/restore.mjs`, `src/api/commander/custom-help.mjs` and `src/api/detect/dispatcher.mjs` (long lines wrapped or joined, single-line array literals collapsed). `tests/embedded-coverage.test.vitest.mjs` is reformatted the same way. +- The `.github/workflows/*.yml` files and `.github/dependabot.yml` are re-indented from 4 spaces to 2 and quotes normalized. The only content difference is in `feature-pr.yml`, where branch-prefix globs switch from single to double quotes. + +## 📚 Documentation + +- Shipped message templates are reformatted: `messages/setup-dispatcher-missing-symlinks.md` gains blank lines before its fenced code blocks, `messages/setup-simple-git-hooks.md` re-indents its JSON example with tabs and aligns the keys, and `messages/setup-pre-commit.md` reflows the `stages: [reference-transaction]` entry in its YAML example onto separate lines (same value). The commands and hook names shown are unchanged. +- `docs/use-case-private-tests.md` switches two emphasis spans from `*...*` to `_..._`. + +## 🔧 Dependencies + +- Transitive `postcss` 8.5.19 → 8.5.28 in `package-lock.json` (dev-only; `package.json` is unchanged). + +--- + +## Upgrade notes + +- No runtime changes; the published `messages/` and `docs/` carry the reformatted text. diff --git a/docs/changelog/v1/v1.1.8.md b/docs/changelog/v1/v1.1.8.md new file mode 100644 index 0000000..73fd0b3 --- /dev/null +++ b/docs/changelog/v1/v1.1.8.md @@ -0,0 +1,22 @@ +# @cldmv/git-embedded v1.1.8 Changelog + +**Release Date**: September 2026 +**Release Type**: Patch + +--- + +## Overview + +A dev-dependency release: `vitest` and `@vitest/coverage-v8` move to the 5.x line together so installs resolve cleanly. No runtime code changed ([#70](https://github.com/CLDMV/git-embedded/pull/70)). + +--- + +## 🔧 Dependencies + +- Dev-only: `vitest` `^4.1.10` → `^5.0.0` and `@vitest/coverage-v8` `^4.1.10` → `^5.0.0`. The coverage package's peer range must match the vitest major, and bumping only one of them fails with an `ERESOLVE` error. + +--- + +## Upgrade notes + +- No runtime changes; these are test toolchain packages and are not installed by consumers. diff --git a/docs/changelog/v1/v1.1.9.md b/docs/changelog/v1/v1.1.9.md new file mode 100644 index 0000000..51943ed --- /dev/null +++ b/docs/changelog/v1/v1.1.9.md @@ -0,0 +1,30 @@ +# @cldmv/git-embedded v1.1.9 Changelog + +**Release Date**: September 2026 +**Release Type**: Patch + +--- + +## Overview + +A tooling release. No runtime code changed: `src/`, `bin/`, `hooks/` and `messages/` are identical to [v1.1.8](./v1.1.8.md). The repository adopts the canonical CLDMV ESLint and Prettier configuration (including `.jsonv` support), the CI matrix moves to the Node range vitest 5 runs on, redirected security PRs are signed, and Dependabot groups updates. The release is titled after the eslint bump in the patch group ([#48](https://github.com/CLDMV/git-embedded/pull/48)). + +--- + +## 🔧 CI & tooling + +- **Lint and format config.** `.configs/eslint.config.mjs` gains `@cldmv/eslint-plugin-jsonv` for `*.jsonv`, `@eslint/css` for `*.css`, `json5` handling, browser globals alongside Node's, and ignores for `tmp/`, `trash/`, `*.min.*` and copy-file patterns. `.configs/.prettierrc` registers `@cldmv/prettier-plugin-jsonv` with a `*.jsonv` override, and a new `.prettierignore` excludes generated output, `package-lock.json`, `*.min.*` and all YAML (the workflows are deliberately 4-space indented, which Prettier would rewrite). +- **CI Node range.** `ci.yml` and `publish.yml` default `min_node_version` to `22.12.0` (the floor vitest 5 runs on) and `max_node_major` to `26`. +- **Bot identity and signing.** `hotfix-redirector.yml` maps the four `CLDMV_BOT_*` secrets (name, email, GPG private key and passphrase) so a security PR redirected to `hotfixes` is cherry-picked as a signed commit, and `feature-pr.yml`, `next-release.yml` and `hotfixes-release.yml` pass the bot name and email to the reusable workflows. +- **Dependabot groups.** `.github/dependabot.yml` bundles updates into security, patch and minor groups, with dedicated groups for packages that must move together (vitest, eslint, prettier). + +## 🔧 Dependencies + +- **NEW** dev dependencies for the lint/format config: `@cldmv/eslint-plugin-jsonv` `^1.0.3`, `@cldmv/jsonv` `^1.0.2`, `@cldmv/prettier-plugin-jsonv` `^1.0.1` and `@eslint/css` `^2.0.0`. +- Lockfile updates within existing ranges: `eslint` 10.8.0 → 10.10.0, `@eslint/js` 9.39.4 → 9.39.5, `@eslint/json` 2.0.1 → 2.1.0 and `globals` 17.9.0 → 17.12.0 (dev-only), and the runtime dependency `@cldmv/slothlet` 3.12.2 → 3.15.3. The `@cldmv/slothlet` range stays `^3.7.0`, so an install from npm resolves its own copy either way. + +--- + +## Upgrade notes + +- No runtime changes — drop-in for v1.1.8. From 70909dcf4c21b009c700f10d7746a6427d9e9a19 Mon Sep 17 00:00:00 2001 From: Shinrai Date: Sat, 3 Oct 2026 20:51:45 -0700 Subject: [PATCH 5/8] docs: add the v1.1.12 changelog and update What's New --- README.md | 17 +++++++++++++++++ docs/changelog/v1/v1.1.12.md | 28 ++++++++++++++++++++++++++++ 2 files changed, 45 insertions(+) create mode 100644 docs/changelog/v1/v1.1.12.md diff --git a/README.md b/README.md index 3cc7cdf..32664cc 100644 --- a/README.md +++ b/README.md @@ -6,6 +6,23 @@ Manage embedded git repositories (anonymous gitlinks) without `.gitmodules`. Provides hooks that restore standard git-command ergonomics for embedded child repos while keeping the child's origin URL out of the public parent repo. +## ✨ What's New + +### Latest: v1.1.12 (October 2026) + +- **Header tooling on fix-headers 2.1.4** — the `@cldmv/fix-headers` dev dependency moves to 2.1.4 and the header pass was re-run; every file already matched, so nothing was restamped. No CLI code, hook, published file or runtime dependency changed (#91). +- **Complete version history** — every release from v1.0.0 onward now has a changelog under [docs/changelog/](https://github.com/CLDMV/git-embedded/tree/master/docs/changelog/). Note that v1.1.3 raised `engines.node` to `>=22.12.0` despite being a patch release, and that v1.1.0 (first published as part of v1.1.1) added the `pre-push` check and changed the default `reference-transaction` guard. +- [View full v1.1.12 Changelog](https://github.com/CLDMV/git-embedded/blob/master/docs/changelog/v1/v1.1.12.md) + +### Recent Releases + +- **v1.1.11** (October 2026) — the CI `✅ Required PR Check` mirror job runs on every path instead of being skipped on in-repo PRs, plus lockfile updates (#85, #86, #88) ([Changelog](https://github.com/CLDMV/git-embedded/blob/master/docs/changelog/v1/v1.1.11.md)) +- **v1.1.10** (October 2026) — uniform file headers from the shared CLDMV config, the verbatim Apache-2.0 license text, a v4.29.2 workflow sync and a batch of dependency updates (#76, #79, #80, #82, #83, #84) ([Changelog](https://github.com/CLDMV/git-embedded/blob/master/docs/changelog/v1/v1.1.10.md)) +- **v1.1.9** (September 2026) — the canonical CLDMV ESLint/Prettier config with `.jsonv` support, the vitest 5 Node range in CI, and signed redirected security PRs (#48) ([Changelog](https://github.com/CLDMV/git-embedded/blob/master/docs/changelog/v1/v1.1.9.md)) +- **v1.1.8** (September 2026) — `vitest` and `@vitest/coverage-v8` move to 5.x together (#70) ([Changelog](https://github.com/CLDMV/git-embedded/blob/master/docs/changelog/v1/v1.1.8.md)) + +📚 **For complete version history, see [docs/changelog/](https://github.com/CLDMV/git-embedded/tree/master/docs/changelog/) and the [GitHub Releases](https://github.com/CLDMV/git-embedded/releases).** + ## What this is Git uses **gitlinks** internally to track sub-repositories: a tree entry of mode `160000` pointing at a specific commit SHA in another repository. Submodules are built on top of gitlinks, with a registry file (`.gitmodules`) that records the child's URL alongside the gitlink. The URL is what makes `git clone --recurse-submodules`, `git submodule update`, and `submodule.recurse=true` checkout-flavored automation work — but it's also what publicly advertises the child repo's existence and location. diff --git a/docs/changelog/v1/v1.1.12.md b/docs/changelog/v1/v1.1.12.md new file mode 100644 index 0000000..027a2ed --- /dev/null +++ b/docs/changelog/v1/v1.1.12.md @@ -0,0 +1,28 @@ +# @cldmv/git-embedded v1.1.12 Changelog + +**Release Date**: October 2026 +**Release Type**: Patch +**Branch**: `release/1.1.12` + +--- + +## Overview + +A dev-dependency release: `@cldmv/fix-headers` moves to 2.1.4 and the header pass was re-run. Every header already matched what 2.1.4 writes, so no file was restamped. No CLI code, hook, published file or runtime dependency changed. + +--- + +## 📚 Documentation + +- **NEW:** [docs/changelog/v1/v1.1.12.md](./v1.1.12.md) — this changelog, plus backfilled changelog files for every earlier release, [v1.0.0](./v1.0.0.md) through [v1.1.11](./v1.1.11.md). +- **NEW:** README **✨ What's New** section. + +## 🔧 Dependencies + +- `@cldmv/fix-headers` 2.1.1 → 2.1.4 ([#91](https://github.com/CLDMV/git-embedded/pull/91), dev-only). + +--- + +## Upgrade notes + +- No runtime changes — drop-in for v1.1.11. From 987ffe9548ddb5ff2d256ff9ee90480346152924 Mon Sep 17 00:00:00 2001 From: Shinrai Date: Sun, 4 Oct 2026 16:39:48 -0700 Subject: [PATCH 6/8] deps: bump @cldmv/fix-headers to 2.2.0 Bumps @cldmv/fix-headers from 2.1.4 to 2.2.0. No file headers changed. --- package-lock.json | 8 ++++---- package.json | 2 +- 2 files changed, 5 insertions(+), 5 deletions(-) diff --git a/package-lock.json b/package-lock.json index 46ba8f9..85c2730 100644 --- a/package-lock.json +++ b/package-lock.json @@ -22,7 +22,7 @@ "devDependencies": { "@cldmv/configs": "^1.2.0", "@cldmv/eslint-plugin-jsonv": "^1.0.3", - "@cldmv/fix-headers": "^2.1.4", + "@cldmv/fix-headers": "^2.2.0", "@cldmv/jsonv": "^1.0.2", "@cldmv/prettier-plugin-jsonv": "^1.0.1", "@cldmv/vitest-runner": "^1.2.0", @@ -162,9 +162,9 @@ } }, "node_modules/@cldmv/fix-headers": { - "version": "2.1.4", - "resolved": "https://registry.npmjs.org/@cldmv/fix-headers/-/fix-headers-2.1.4.tgz", - "integrity": "sha512-PvCKMztN9k+jOjEpMCANMaDIkNW7cs2qp5P73JVzResk1+DfqhoZVqT9jpTT8cUu+6OGszsNqj8/X0Q9IhfNtg==", + "version": "2.2.0", + "resolved": "https://registry.npmjs.org/@cldmv/fix-headers/-/fix-headers-2.2.0.tgz", + "integrity": "sha512-EQTAKCo0B639q2bde+vO5ciYbtvNgAJFm0DBthIJQnmTFJmQDUlObp5EsTRgg5CUlFoUnGMX+q35LC02QvYU4w==", "dev": true, "license": "Apache-2.0", "dependencies": { diff --git a/package.json b/package.json index 2cb42dc..c371b35 100644 --- a/package.json +++ b/package.json @@ -90,7 +90,7 @@ "devDependencies": { "@cldmv/configs": "^1.2.0", "@cldmv/eslint-plugin-jsonv": "^1.0.3", - "@cldmv/fix-headers": "^2.1.4", + "@cldmv/fix-headers": "^2.2.0", "@cldmv/jsonv": "^1.0.2", "@cldmv/prettier-plugin-jsonv": "^1.0.1", "@cldmv/vitest-runner": "^1.2.0", From e33ff95a15e936d6ea33786a96a1df010f3df528 Mon Sep 17 00:00:00 2001 From: Shinrai Date: Sun, 4 Oct 2026 19:04:53 -0700 Subject: [PATCH 7/8] deps: bump @cldmv/configs to 1.2.4 Range ^1.2.0 -> ^1.2.4 (lockfile previously pinned 1.2.x below 1.2.4). The shared fix-headers.json in 1.2.4 sets forceAuthorUpdate and forceLastModifiedAuthorUpdate to false, so with @cldmv/fix-headers 2.2.0 @Author is never rewritten and @Last modified by changes only on real content edits. Restamped 0 files; fix:headers made no changes. --- package-lock.json | 8 ++++---- package.json | 2 +- 2 files changed, 5 insertions(+), 5 deletions(-) diff --git a/package-lock.json b/package-lock.json index 85c2730..a5572e0 100644 --- a/package-lock.json +++ b/package-lock.json @@ -20,7 +20,7 @@ "git-embedded": "bin/git-embedded.mjs" }, "devDependencies": { - "@cldmv/configs": "^1.2.0", + "@cldmv/configs": "^1.2.4", "@cldmv/eslint-plugin-jsonv": "^1.0.3", "@cldmv/fix-headers": "^2.2.0", "@cldmv/jsonv": "^1.0.2", @@ -129,9 +129,9 @@ } }, "node_modules/@cldmv/configs": { - "version": "1.2.0", - "resolved": "https://registry.npmjs.org/@cldmv/configs/-/configs-1.2.0.tgz", - "integrity": "sha512-FDmlxOx6ceKuD5zTamUy9XOfAC4opeOaLxWqZz9okKxj8TsTZP6dN7W0VccRYRdw4606NvXjhdZqOPibcNpXmQ==", + "version": "1.2.4", + "resolved": "https://registry.npmjs.org/@cldmv/configs/-/configs-1.2.4.tgz", + "integrity": "sha512-7HPqAgCKqol3fHpawEsXJ5ZqHxlDPZk1puoFu43f/gaNfhWwufDTzjkvLk90yVEumyz4N3pUwIxfbHUkUTpDEg==", "dev": true, "license": "Apache-2.0", "funding": { diff --git a/package.json b/package.json index c371b35..5d50f7b 100644 --- a/package.json +++ b/package.json @@ -88,7 +88,7 @@ "marked-terminal": "^7.3.0" }, "devDependencies": { - "@cldmv/configs": "^1.2.0", + "@cldmv/configs": "^1.2.4", "@cldmv/eslint-plugin-jsonv": "^1.0.3", "@cldmv/fix-headers": "^2.2.0", "@cldmv/jsonv": "^1.0.2", From 99e4b340b1ed1608e0d6e5cd6fb1f3fc45ddb418 Mon Sep 17 00:00:00 2001 From: Shinrai Date: Sun, 4 Oct 2026 20:07:39 -0700 Subject: [PATCH 8/8] docs: update the v1.1.12 release notes --- README.md | 2 +- docs/changelog/v1/v1.1.12.md | 9 +++++++-- 2 files changed, 8 insertions(+), 3 deletions(-) diff --git a/README.md b/README.md index 32664cc..80d12f8 100644 --- a/README.md +++ b/README.md @@ -10,7 +10,7 @@ Manage embedded git repositories (anonymous gitlinks) without `.gitmodules`. Pro ### Latest: v1.1.12 (October 2026) -- **Header tooling on fix-headers 2.1.4** — the `@cldmv/fix-headers` dev dependency moves to 2.1.4 and the header pass was re-run; every file already matched, so nothing was restamped. No CLI code, hook, published file or runtime dependency changed (#91). +- **Header tooling on fix-headers 2.2.0** — the `@cldmv/fix-headers` dev dependency moves to 2.2.0 (`@Last modified by` now follows content edits only) with `@cldmv/configs` 1.2.4, and a dev-only `brace-expansion` patch update lands in the lockfile; nothing needed restamping. No CLI code, hook, published file or runtime dependency changed (#90, #91, #94). - **Complete version history** — every release from v1.0.0 onward now has a changelog under [docs/changelog/](https://github.com/CLDMV/git-embedded/tree/master/docs/changelog/). Note that v1.1.3 raised `engines.node` to `>=22.12.0` despite being a patch release, and that v1.1.0 (first published as part of v1.1.1) added the `pre-push` check and changed the default `reference-transaction` guard. - [View full v1.1.12 Changelog](https://github.com/CLDMV/git-embedded/blob/master/docs/changelog/v1/v1.1.12.md) diff --git a/docs/changelog/v1/v1.1.12.md b/docs/changelog/v1/v1.1.12.md index 027a2ed..af1447c 100644 --- a/docs/changelog/v1/v1.1.12.md +++ b/docs/changelog/v1/v1.1.12.md @@ -8,7 +8,7 @@ ## Overview -A dev-dependency release: `@cldmv/fix-headers` moves to 2.1.4 and the header pass was re-run. Every header already matched what 2.1.4 writes, so no file was restamped. No CLI code, hook, published file or runtime dependency changed. +A dev-dependency release: `@cldmv/fix-headers` moves to 2.2.0 (through 2.1.4 on the way) and `@cldmv/configs` to 1.2.4, no file needed restamping, and a patch update of the dev-only transitive `brace-expansion` lands in the lockfile. No CLI code, hook, published file or runtime dependency changed. --- @@ -19,7 +19,12 @@ A dev-dependency release: `@cldmv/fix-headers` moves to 2.1.4 and the header pas ## 🔧 Dependencies -- `@cldmv/fix-headers` 2.1.1 → 2.1.4 ([#91](https://github.com/CLDMV/git-embedded/pull/91), dev-only). +All changes are dev-only and none touches the published package. + +- `@cldmv/fix-headers` ^2.1.1 → ^2.2.0 (dev), resolved to 2.2.0. The version was first bumped to 2.1.4 ([#91](https://github.com/CLDMV/git-embedded/pull/91)) and then to 2.2.0 ([#94](https://github.com/CLDMV/git-embedded/pull/94)). 2.2.0 changes `@Last modified by` only when a file's content was edited; header-only rewrites keep the recorded editor. +- `@cldmv/configs` ^1.2.0 → ^1.2.4 (dev), resolved to 1.2.4. The shared fix-headers config now sets `forceAuthorUpdate` and `forceLastModifiedAuthorUpdate` to false ([#94](https://github.com/CLDMV/git-embedded/pull/94)). +- `brace-expansion` 5.0.9 → 5.0.12, a dev-only transitive dependency, updated in the lockfile only ([#90](https://github.com/CLDMV/git-embedded/pull/90), the Dependabot group update re-applied onto `next`). +- No file was restamped: neither bump PR touches a source file, so every header already matched what 2.1.4 and 2.2.0 write. ---