chore(deps): refresh upstream pins — superpowers v6.3.0 and CC compat 2.1.220 - #92
Conversation
9380084 to
2d9394b
Compare
|
VERDICT: PASS Clean compat survey + discipline-skills sync. No blocking issues found. Checked against all CONTRIBUTING.md gate criteria:
|
…ers) Four upstream releases since PR #85, all landing in the seven forked skills. v6.0.3 moved SDD's scratch files out of .git/ (Claude Code treats it as a protected path and denies agent writes, which blocked an implementer subagent mid-run) into a self-ignoring .superpowers/sdd/ working-tree directory, resolved by a new shared script scripts/sdd-workspace. v6.2.0 made that workspace plan-scoped (.superpowers/sdd/<plan-basename>/, so a follow-up plan can't read the previous plan's ledger as its own); review-package gained the plan file as its first argument. The review-fix loop now resumes the implementer instead of dispatching fresh, with a scoped re-review prompt (re-review-prompt.md, NEW) and a five-round circuit breaker. A library-wide compression campaign removed the Bottom Line / Key Principles / Advantages / Integration / "Why This Matters" sections, folding the load-bearing arguments into Excuse/Reality rationalization tables. finishing-a-development-branch no longer offers "Discard this work" in its menu (discard is explicit-request only), creates PRs with whichever forge tooling is present, and fixes a real bug where the worktree path was recomputed after cleanup had already changed directory. v6.3.0 teaches brainstorming to classify a request as spike / bounded / architectural and scale the ceremony to it (only the architectural path writes a spec; the approval gate never scales). SDD controllers now issue recorded rulings instead of stalling on plan conflicts, ledger the pre-flight conflict scan as a table, batch small same-shape tasks into one dispatch, and forbid implementers and reviewers from spawning their own subagents (duplicate review seats). Plans carry a Spec: pointer. finishing-a-development-branch stops and asks when `git worktree remove` refuses because of untracked files. Local edits re-applied per SYNC.md: `superpowers:` prefixes stripped (14 sites across three SKILL.md files), brainstorming's ## Visual Companion section and the visual-companion step of its *architectural* checklist removed (renumbered to 8; the spike/bounded lists never had one), executing-plans' subagents note reframed project-neutral. One NEW local edit: subagent-driven-development's final whole-branch review now points at the configurator's own code-reviewer subagent (.claude/agents/code-reviewer.md, with a task-reviewer-prompt.md fallback when the commands module isn't installed) instead of upstream's ../requesting-code-review/code-reviewer.md -- three digraph labels plus the ## Final Review paragraph. This retires the broken-link papercut carried since v5.1.0 and documented in SYNC.md. The former "remove the requesting-code-review / test-driven-development lines from ## Integration" edits are obsolete; upstream dropped that section in v6.2.0. Module paths 15 -> 17 (re-review-prompt.md, scripts/sdd-workspace); test-module-files-exist.sh and test-scaffold-installs-skills.sh updated (the scaffold test now asserts all three scripts ship executable); the three persona snapshots that include the module regenerated. SYNC.md pinned to v6.3.0 (2026-08-12) with a fresh delta paragraph, a CRLF note for Windows checkouts, and a renumbered canonical-edit list. NOTICE and docs/10-plugin-ecosystem.md still said v5.1.0; both bumped, along with the module description and README's carve-out paragraphs. The new script's index mode was set with `git add --chmod=+x` (this checkout has core.filemode=false). Claude Code compat: 2.1.116-2.1.150 (unchanged by this commit). Co-Authored-By: Claude Opus 5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01JVndNviHZSnbKJnWP7jFbV
2d9394b to
902d640
Compare
|
VERDICT: COMMENT-ONLY Advisory1. Scope: two commits, two CHANGELOG entries in one PRCONTRIBUTING.md requires "One logical change per PR." This PR has two separate conventional-commit commits and two separate
The changes are causally linked (the configurator-wide 2. Compat comment claims
|
…e() defaults; shell:bash on every hook tested_up_to 2.1.150 -> 2.1.220. The no-lone-bumps gate finally cleared: SchemaStore #5723 (-> 2.1.150) was closed unmerged, but #5867 (-> 2.1.195, merged 2026-07-03) and #6131 (-> 2.1.220, merged 2026-07-27) landed. The keys held since v2.6.0 (fallbackModel, disableBundledSkills) are schema-validated, as are agent, claudeMdExcludes, skillListingBudgetFraction/MaxDescChars, sandbox.credentials (deny form) and worktree.symlinkDirectories/sparsePaths -- all promoted to doc-only opt-in stubs in settings.local.json.example. Every release 2.1.183 -> 2.1.241 was read verbatim; the full survey is recorded in the CLAUDE_CODE_COMPAT comment block. Four shipped defaults were dead or wrong, not merely stale: 1. autoMode.hard_deny in project settings has been ignored since CC 2.1.207 -- the classifier reads autoMode only from ~/.claude/settings.json or managed settings, because .claude/settings.json and .claude/settings.local.json both live in the repo and could inject allow rules. The block v2.6.0 promoted to an active default did nothing. Removed from the safety patch; documented as a user-scope block (with "$defaults") in docs/05-safety-permissions.md. A retrofit strips the exact shipped block -- a user-edited variant survives -- and check_settings_validates now flags any project-scope autoMode. 2. Write(.env) / Write(.env.*) deny rules were never consulted. Claude Code checks file permissions against Edit(path) and Read(path) only, and 2.1.210 added a startup warning for exactly these spellings. Dropped from the core deny list (the Edit(.env*) rules already covered the Write tool); a retrofit strips those two shipped strings; the preflight flags any others via the new _find_unconsulted_path_rules. 3. Every shipped command hook now declares "shell": "bash" (13 entries: 9 in the settings patches, 4 embedded in config_schema). Without it a Windows session with no Git Bash sends .sh hooks to PowerShell, where they die on a parser error; with it Claude Code resolves Git for Windows directly and prompts to install it when missing. Older CC ignores the key. Adopted after upstream superpowers v6.2.0 fixed its own SessionStart hook the same way. _merge_hook_groups backfills the key onto configurator-owned entries on retrofit, never onto a user's own command or an explicit shell choice. 4. CC 2.1.223 made /review the bundled alias of /code-review -- the collision the 2.1.146 survey note was watching for. Rather than assume, this was tested headlessly on 2.1.241: a project skill named `review` wins over the bundled alias, and `plan` wins over the built-in /plan shortcut. No rename; the shadowing is documented in README, docs/03 and the skill's own description. Wording brought in line with the runtime: subagent nesting (5 -> off -> 3 by default at 2.1.219, CLAUDE_CODE_MAX_SUBAGENT_SPAWN_DEPTH), the 20-concurrent cap (2.1.217), background-by-default subagents (2.1.198), the fork subagent type (2.1.232), Explore inheriting the session model instead of Haiku (2.1.198), the new SessionStart `fork` source (2.1.214), hook-matcher semantics (hyphen exact- match 2.1.195, comma separators 2.1.191, cwd-anchored single-segment if: 2.1.214), DirectoryAdded (2.1.219), Todo-tool withdrawal on Fable 5 / Opus 4.8+ / Sonnet 5 (2.1.233), and the Sonnet 5 / Opus 5 model landscape. The shipped matchers are pipe-joined tool names, so none of the matcher changes affect behavior. --check now rejects a UTF-8 BOM at the top of any shipped SKILL.md or agent file (CC before 2.1.239 silently ignored BOM-prefixed files). A retrofit also re-runs check_settings_validates against the merged result and surfaces findings under [ MERGED ] -- the one place a user's own settings.json enters the pipeline. Held / out of territory: sandbox.network.strictAllowlist, sandbox.filesystem. disabled and dialogExpiry are user/managed-only per the settings reference; crossSessionInbound is project-honored but not yet in SchemaStore (the sync stops at 2.1.220) and is held for the next survey; UI prefs, marketplace/plugin-source/ self-hosted-runner/gateway keys and the removed /agents wizard need no action. New test/retrofit-hooks/test-retired-defaults-migration.sh and two new cases in test-preflight-detects-violations.sh. The python-uv-fastapi example is regenerated, which also catches it up to the docker-compose check field from c29786d (it was last written by cc-configure 2.6.0). Claude Code compat: 2.1.116-2.1.220. Co-Authored-By: Claude Opus 5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01JVndNviHZSnbKJnWP7jFbV
902d640 to
63b98b5
Compare
|
Advisory 2 was a real error, and mine — fixed in the amended tip. The compat comment claimed The clause is gone; the sentence now reads I deliberately did not add the repin note to Verified the amend touched nothing else — On advisory 1 (two commits, two CHANGELOG entries): leaving as-is, since you noted the two are causally linked — the repo-wide |
|
VERDICT: COMMENT-ONLY AdvisoryScope creep — two distinct logical changes in one PR. The PR ships two independent sets of template changes, each with its own CHANGELOG entry and its own commit message:
The PR body acknowledges this ("Two atomic commits under one theme; split further on request") and the Everything else checks out:
|
What & why
Refreshes both upstream pins this project tracks, in one pass:
templates/discipline-skills/v6.0.2 → v6.3.0 (obra/superpowers). Four upstream releases: plan-scoped SDD workspace + newscripts/sdd-workspace, the resume-the-implementer fix loop withre-review-prompt.mdand a five-round circuit breaker, brainstorming's spike/bounded/architectural classification, and controller "rulings" instead of stalls.CLAUDE_CODE_COMPATtested_up_to2.1.150 → 2.1.220, surveying every Claude Code release 2.1.183 → 2.1.241.Supersedes #86, whose window (2.1.183–191) is a strict subset of this survey and which is already
CONFLICTING. It also resolves what #86 was waiting on: SchemaStore #5723 was closed unmerged, but #5867 (→2.1.195) and #6131 (→2.1.220) merged, which is what unblocks the bump under the no-lone-bumps rule.Four shipped defaults turned out to be dead or wrong, not merely stale — the reason this is a
fix-flavoured chore:autoModehas been ignored since CC 2.1.207. The classifier readsautoModeonly from~/.claude/settings.jsonor managed settings, because.claude/settings.jsonand.claude/settings.local.jsonboth live in the repo. Thehard_denyblock promoted to an active default in v2.6.0 was doing nothing. Removed; documented as a user-scope block indocs/05; a retrofit strips the exact shipped block (a user-edited variant survives) and the preflight now flags any project-scopeautoMode.Write(.env)/Write(.env.*)deny rules were never consulted. Claude Code checks file permissions againstEdit(path)andRead(path)only, and 2.1.210 added a startup warning for exactly these spellings. Dropped;Edit(.env*)already covered the Write tool."shell": "bash"(13 entries). Without it, a Windows session with no Git Bash sends.shhooks to PowerShell, where they die on a parser error. Adopted after upstream superpowers v6.2.0 fixed its own SessionStart hook the same way./reviewthe alias of the bundled/code-review. Verified headlessly on 2.1.241 that a project skill wins that name. Documented here; the rename lands in a later PR in this stack.Also:
subagent-driven-development's final whole-branch review now points at this project's owncode-reviewersubagent instead of upstream's../requesting-code-review/code-reviewer.md, retiring the broken-link papercut carried since v5.1.0.Type of change
Scope
discipline-skills,safety,git-workflow,token-efficiency,commands,core,mcpsolo-newer,solo-experienced,small-team(snapshots regenerated —re-review-prompt.mdandscripts/sdd-workspaceare new files)Tests
python3 configure.py --checkpasses locally.test/for new behavior —test/retrofit-hooks/test-retired-defaults-migration.shplus two new cases intest/schema-hygiene/test-preflight-detects-violations.sh;test/discipline-skills/updated for the two new files.examples/persona-*/expected-tree.txt) updated.CHANGELOG
## Unreleased.License & NOTICE (load-bearing — read carefully)
templates/discipline-skills/is the MIT-licensed obra/superpowers fork;NOTICEupdated v5.1.0 → v6.3.0 (it had never been bumped).templates/discipline-skills/stays MIT-clean — content is upstream MIT plus the documented local edits inSYNC.md.NOTICEtouched: version pin only.Signing
main'srequired_signaturesis still satisfied; a local merge + push would be rejected. Say the word and I'll re-sign the branch.I understand
CONTRIBUTING.md.First of four stacked PRs. Merge in order; GitHub retargets each next PR as the one below it lands.