Skip to content

chore(deps): refresh upstream pins — superpowers v6.3.0 and CC compat 2.1.220 - #92

Merged
tigers1997 merged 2 commits into
mainfrom
chore/upstream-currency
Aug 25, 2026
Merged

tigers1997 merged 2 commits into
mainfrom
chore/upstream-currency

Conversation

@tigers1997

Copy link
Copy Markdown
Owner

What & why

Refreshes both upstream pins this project tracks, in one pass:

  • templates/discipline-skills/ v6.0.2 → v6.3.0 (obra/superpowers). Four upstream releases: plan-scoped SDD workspace + new scripts/sdd-workspace, the resume-the-implementer fix loop with re-review-prompt.md and a five-round circuit breaker, brainstorming's spike/bounded/architectural classification, and controller "rulings" instead of stalls.
  • CLAUDE_CODE_COMPAT tested_up_to 2.1.150 → 2.1.220, surveying every Claude Code release 2.1.183 → 2.1.241.

Supersedes #86, whose window (2.1.183–191) is a strict subset of this survey and which is already CONFLICTING. It also resolves what #86 was waiting on: SchemaStore #5723 was closed unmerged, but #5867 (→2.1.195) and #6131 (→2.1.220) merged, which is what unblocks the bump under the no-lone-bumps rule.

Four shipped defaults turned out to be dead or wrong, not merely stale — the reason this is a fix-flavoured chore:

  1. Project-scope autoMode has been ignored since CC 2.1.207. The classifier reads autoMode only from ~/.claude/settings.json or managed settings, because .claude/settings.json and .claude/settings.local.json both live in the repo. The hard_deny block promoted to an active default in v2.6.0 was doing nothing. Removed; documented as a user-scope block in docs/05; a retrofit strips the exact shipped block (a user-edited variant survives) and the preflight now flags any project-scope autoMode.
  2. Write(.env) / Write(.env.*) deny rules were never consulted. Claude Code checks file permissions against Edit(path) and Read(path) only, and 2.1.210 added a startup warning for exactly these spellings. Dropped; Edit(.env*) already covered the Write tool.
  3. Every shipped command hook now declares "shell": "bash" (13 entries). Without it, a Windows session with no Git Bash sends .sh hooks to PowerShell, where they die on a parser error. Adopted after upstream superpowers v6.2.0 fixed its own SessionStart hook the same way.
  4. CC 2.1.223 made /review the alias of the bundled /code-review. Verified headlessly on 2.1.241 that a project skill wins that name. Documented here; the rename lands in a later PR in this stack.

Also: subagent-driven-development's final whole-branch review now points at this project's own code-reviewer subagent instead of upstream's ../requesting-code-review/code-reviewer.md, retiring the broken-link papercut carried since v5.1.0.

Type of change

  • feat — new module / skill / feature (minor bump)
  • fix — bug fix (patch bump)
  • docs — documentation only
  • chore — tooling, CI, release plumbing
  • refactor — no behavioral change
  • BREAKING

Scope

  • One logical change. (Two atomic commits under one theme: refresh the upstream pins and act on what the survey found. Split further on request.)
  • Modules affected: discipline-skills, safety, git-workflow, token-efficiency, commands, core, mcp
  • Personas affected: solo-newer, solo-experienced, small-team (snapshots regenerated — re-review-prompt.md and scripts/sdd-workspace are new files)

Tests

  • python3 configure.py --check passes locally.
  • Added/updated fixtures under test/ for new behavior — test/retrofit-hooks/test-retired-defaults-migration.sh plus two new cases in test/schema-hygiene/test-preflight-detects-violations.sh; test/discipline-skills/ updated for the two new files.
  • Persona snapshots (examples/persona-*/expected-tree.txt) updated.

CHANGELOG

  • Added an entry under ## Unreleased.
  • I will SHA-anchor the entry after merge.

License & NOTICE (load-bearing — read carefully)

  • My contribution is my own work, or I have the right to submit it under the applicable license.
  • No code under AGPL-3.0-incompatible licenses.
  • Third-party code: templates/discipline-skills/ is the MIT-licensed obra/superpowers fork; NOTICE updated v5.1.0 → v6.3.0 (it had never been bumped).
  • templates/discipline-skills/ stays MIT-clean — content is upstream MIT plus the documented local edits in SYNC.md.
  • NOTICE touched: version pin only.

Signing

  • All commits are signed (GPG or SSH). — Not signed. No signing key exists on the machine these were authored on. A GitHub squash-merge signs the resulting commit, so main's required_signatures is still satisfied; a local merge + push would be rejected. Say the word and I'll re-sign the branch.
  • Conventional Commits prefix in PR title and commit messages.

I understand

  • An automated AI review will run on this PR.
  • No merge is possible while any required check is red.
  • My contribution rights are described in CONTRIBUTING.md.

First of four stacked PRs. Merge in order; GitHub retargets each next PR as the one below it lands.

@claude

claude Bot commented Aug 25, 2026

Copy link
Copy Markdown

VERDICT: PASS

Clean compat survey + discipline-skills sync. No blocking issues found.

Checked against all CONTRIBUTING.md gate criteria:

  • CHANGELOG Unreleased — both chore(compat) and chore(skills) entries are present and detailed.
  • AGPL contamination — no new third-party code in the Python/template layer; discipline-skills additions (re-review-prompt.md, scripts/sdd-workspace) flow from MIT-licensed obra/superpowers v6.3.0, consistent with the carve-out.
  • MIT subtree integrity — NOTICE updated v5.1.0 to v6.3.0 (catches the missed update from the v6.0.2 sync in chore(skills): sync discipline-skills v5.1.0 → v6.0.2 (obra/superpowers) #85); upstream source remains MIT; no AGPL-only code introduced.
  • Schema-claim hygiene — shell:bash was schema-validated at CC 2.1.81, well inside tested_up_to 2.1.220; new settings.local.json.example opt-in stubs are gated on SchemaStore PRs #5867 (2026-07-03) and #6131 (2026-07-27) with explicit 2026-07-27 validation stamp. crossSessionInbound (project-honored but not yet in SchemaStore) correctly held for the next sync.
  • Persona snapshots — all three affected expected-tree.txt files regenerated to include re-review-prompt.md and scripts/sdd-workspace; config_schema.py paths list updated consistently.
  • Correctness — retire logic (RETIRED_PROJECT_AUTOMODE / RETIRED_DENY_RULES) uses exact-match removal and preserves user-edited variants; shell backfill in _merge_hook_groups correctly scopes to configurator-owned commands via the new_shell command-keyed dict; _find_unconsulted_path_rules anchors on the path-form pattern leaving bare tool names unaffected; BOM check placed before frontmatter parsing so the file is read once.
  • Scope — the two changes (chore(compat) and chore(skills)) are interrelated: the upstream v6.2.0 shell:bash fix triggered the configurator-wide adoption documented in the compat survey, and co-shipping a companion compat entry with a skills sync is consistent with prior practice in this repo.

…ers)

Four upstream releases since PR #85, all landing in the seven forked skills.

v6.0.3 moved SDD's scratch files out of .git/ (Claude Code treats it as a
protected path and denies agent writes, which blocked an implementer subagent
mid-run) into a self-ignoring .superpowers/sdd/ working-tree directory, resolved
by a new shared script scripts/sdd-workspace.

v6.2.0 made that workspace plan-scoped (.superpowers/sdd/<plan-basename>/, so a
follow-up plan can't read the previous plan's ledger as its own); review-package
gained the plan file as its first argument. The review-fix loop now resumes the
implementer instead of dispatching fresh, with a scoped re-review prompt
(re-review-prompt.md, NEW) and a five-round circuit breaker. A library-wide
compression campaign removed the Bottom Line / Key Principles / Advantages /
Integration / "Why This Matters" sections, folding the load-bearing arguments
into Excuse/Reality rationalization tables. finishing-a-development-branch no
longer offers "Discard this work" in its menu (discard is explicit-request
only), creates PRs with whichever forge tooling is present, and fixes a real bug
where the worktree path was recomputed after cleanup had already changed
directory.

v6.3.0 teaches brainstorming to classify a request as spike / bounded /
architectural and scale the ceremony to it (only the architectural path writes a
spec; the approval gate never scales). SDD controllers now issue recorded
rulings instead of stalling on plan conflicts, ledger the pre-flight conflict
scan as a table, batch small same-shape tasks into one dispatch, and forbid
implementers and reviewers from spawning their own subagents (duplicate review
seats). Plans carry a Spec: pointer. finishing-a-development-branch stops and
asks when `git worktree remove` refuses because of untracked files.

Local edits re-applied per SYNC.md: `superpowers:` prefixes stripped (14 sites
across three SKILL.md files), brainstorming's ## Visual Companion section and
the visual-companion step of its *architectural* checklist removed (renumbered
to 8; the spike/bounded lists never had one), executing-plans' subagents note
reframed project-neutral.

One NEW local edit: subagent-driven-development's final whole-branch review now
points at the configurator's own code-reviewer subagent
(.claude/agents/code-reviewer.md, with a task-reviewer-prompt.md fallback when
the commands module isn't installed) instead of upstream's
../requesting-code-review/code-reviewer.md -- three digraph labels plus the
## Final Review paragraph. This retires the broken-link papercut carried since
v5.1.0 and documented in SYNC.md. The former "remove the requesting-code-review
/ test-driven-development lines from ## Integration" edits are obsolete;
upstream dropped that section in v6.2.0.

Module paths 15 -> 17 (re-review-prompt.md, scripts/sdd-workspace);
test-module-files-exist.sh and test-scaffold-installs-skills.sh updated (the
scaffold test now asserts all three scripts ship executable); the three persona
snapshots that include the module regenerated. SYNC.md pinned to v6.3.0
(2026-08-12) with a fresh delta paragraph, a CRLF note for Windows checkouts,
and a renumbered canonical-edit list. NOTICE and docs/10-plugin-ecosystem.md
still said v5.1.0; both bumped, along with the module description and README's
carve-out paragraphs.

The new script's index mode was set with `git add --chmod=+x` (this checkout has
core.filemode=false).

Claude Code compat: 2.1.116-2.1.150 (unchanged by this commit).

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01JVndNviHZSnbKJnWP7jFbV
@tigers1997
tigers1997 force-pushed the chore/upstream-currency branch from 2d9394b to 902d640 Compare August 25, 2026 16:05
@claude

claude Bot commented Aug 25, 2026

Copy link
Copy Markdown

VERDICT: COMMENT-ONLY

Advisory

1. Scope: two commits, two CHANGELOG entries in one PR

CONTRIBUTING.md requires "One logical change per PR." This PR has two separate conventional-commit commits and two separate ## Unreleased CHANGELOG entries:

  • a4bac73 chore(skills): sync discipline-skills v6.0.2 → v6.3.0
  • 902d640 chore(compat): CC 2.1.183-2.1.241 survey; retire dead autoMode + Write() defaults; shell:bash on every hook

The changes are causally linked (the configurator-wide "shell": "bash" adoption was explicitly motivated by seeing the upstream superpowers v6.2.0 fix in the skills sync), and the CHANGELOG documents that link. For that reason this is advisory rather than blocking. But for future paired compat+skills cycles: if the coupling is tight enough to merge, prefer a single commit with a single CHANGELOG entry; if they're independently deployable, split the PR.

2. Compat comment claims review.yml was repinned — but it wasn't

config_schema.py's new compat comment block says:

own-CI review.yml repinned claude-sonnet-4-6 -> claude-sonnet-5 (same tier and list price)

.github/workflows/review.yml is not in the PR diff, and line 46 still reads --model claude-sonnet-4-6. The claim is either aspirational or an oversight. Either remove the sentence from the compat comment, or include the review.yml change in this (or a follow-up) PR so the comment matches reality.

…e() defaults; shell:bash on every hook

tested_up_to 2.1.150 -> 2.1.220. The no-lone-bumps gate finally cleared:
SchemaStore #5723 (-> 2.1.150) was closed unmerged, but #5867 (-> 2.1.195,
merged 2026-07-03) and #6131 (-> 2.1.220, merged 2026-07-27) landed. The keys
held since v2.6.0 (fallbackModel, disableBundledSkills) are schema-validated, as
are agent, claudeMdExcludes, skillListingBudgetFraction/MaxDescChars,
sandbox.credentials (deny form) and worktree.symlinkDirectories/sparsePaths --
all promoted to doc-only opt-in stubs in settings.local.json.example. Every
release 2.1.183 -> 2.1.241 was read verbatim; the full survey is recorded in the
CLAUDE_CODE_COMPAT comment block.

Four shipped defaults were dead or wrong, not merely stale:

1. autoMode.hard_deny in project settings has been ignored since CC 2.1.207 --
   the classifier reads autoMode only from ~/.claude/settings.json or managed
   settings, because .claude/settings.json and .claude/settings.local.json both
   live in the repo and could inject allow rules. The block v2.6.0 promoted to
   an active default did nothing. Removed from the safety patch; documented as a
   user-scope block (with "$defaults") in docs/05-safety-permissions.md. A
   retrofit strips the exact shipped block -- a user-edited variant survives --
   and check_settings_validates now flags any project-scope autoMode.

2. Write(.env) / Write(.env.*) deny rules were never consulted. Claude Code
   checks file permissions against Edit(path) and Read(path) only, and 2.1.210
   added a startup warning for exactly these spellings. Dropped from the core
   deny list (the Edit(.env*) rules already covered the Write tool); a retrofit
   strips those two shipped strings; the preflight flags any others via the new
   _find_unconsulted_path_rules.

3. Every shipped command hook now declares "shell": "bash" (13 entries: 9 in the
   settings patches, 4 embedded in config_schema). Without it a Windows session
   with no Git Bash sends .sh hooks to PowerShell, where they die on a parser
   error; with it Claude Code resolves Git for Windows directly and prompts to
   install it when missing. Older CC ignores the key. Adopted after upstream
   superpowers v6.2.0 fixed its own SessionStart hook the same way.
   _merge_hook_groups backfills the key onto configurator-owned entries on
   retrofit, never onto a user's own command or an explicit shell choice.

4. CC 2.1.223 made /review the bundled alias of /code-review -- the collision
   the 2.1.146 survey note was watching for. Rather than assume, this was tested
   headlessly on 2.1.241: a project skill named `review` wins over the bundled
   alias, and `plan` wins over the built-in /plan shortcut. No rename; the
   shadowing is documented in README, docs/03 and the skill's own description.

Wording brought in line with the runtime: subagent nesting (5 -> off -> 3 by
default at 2.1.219, CLAUDE_CODE_MAX_SUBAGENT_SPAWN_DEPTH), the 20-concurrent cap
(2.1.217), background-by-default subagents (2.1.198), the fork subagent type
(2.1.232), Explore inheriting the session model instead of Haiku (2.1.198), the
new SessionStart `fork` source (2.1.214), hook-matcher semantics (hyphen exact-
match 2.1.195, comma separators 2.1.191, cwd-anchored single-segment if: 2.1.214),
DirectoryAdded (2.1.219), Todo-tool withdrawal on Fable 5 / Opus 4.8+ / Sonnet 5
(2.1.233), and the Sonnet 5 / Opus 5 model landscape. The shipped matchers are
pipe-joined tool names, so none of the matcher changes affect behavior.

--check now rejects a UTF-8 BOM at the top of any shipped SKILL.md or agent file
(CC before 2.1.239 silently ignored BOM-prefixed files). A retrofit also re-runs
check_settings_validates against the merged result and surfaces findings under
[ MERGED ] -- the one place a user's own settings.json enters the pipeline.

Held / out of territory: sandbox.network.strictAllowlist, sandbox.filesystem.
disabled and dialogExpiry are user/managed-only per the settings reference;
crossSessionInbound is project-honored but not yet in SchemaStore (the sync stops
at 2.1.220) and is held for the next survey; UI prefs, marketplace/plugin-source/
self-hosted-runner/gateway keys and the removed /agents wizard need no action.

New test/retrofit-hooks/test-retired-defaults-migration.sh and two new cases in
test-preflight-detects-violations.sh. The python-uv-fastapi example is
regenerated, which also catches it up to the docker-compose check field from
c29786d (it was last written by cc-configure 2.6.0).

Claude Code compat: 2.1.116-2.1.220.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01JVndNviHZSnbKJnWP7jFbV
@tigers1997
tigers1997 force-pushed the chore/upstream-currency branch from 902d640 to 63b98b5 Compare August 25, 2026 16:21
@tigers1997

Copy link
Copy Markdown
Owner Author

Advisory 2 was a real error, and mine — fixed in the amended tip.

The compat comment claimed review.yml was repinned to claude-sonnet-5. That change was originally in this PR; I lifted it out earlier because carrying a review.yml edit inside a feature branch makes claude-code-action self-skip ("Workflow validation failed"), which had silently disabled the AI review on this PR and every PR stacked on it. I removed the change from review.yml and from the CHANGELOG entry, but missed this comment — so the PR was left asserting something its own diff contradicted. Exactly the overclaiming the stack elsewhere exists to fix, which makes it worse than a stray comment.

The clause is gone; the sentence now reads scaffold default stays \fable`.and stops there. The repin itself lives in #96 with its own CHANGELOG entry, which is the honest record — and #96 has to merge **last**, since the moment it lands, main'sreview.yml` changes and anything still open starts self-skipping again.

I deliberately did not add the repin note to config_schema.py on #96: that branch is cut from the current main, which doesn't have this compat block yet, so editing that region there would only manufacture a merge conflict with this PR for no gain.

Verified the amend touched nothing else — git diff between the pre- and post-fix tips across the whole stack is exactly this one hunk, 1 insertion and 3 deletions in config_schema.py, on every branch. All commits remain signed and --check passes on all seven branches independently.

On advisory 1 (two commits, two CHANGELOG entries): leaving as-is, since you noted the two are causally linked — the repo-wide "shell": "bash" adoption came directly out of reading the upstream v6.2.0 fix in the skills sync. Happy to split it like #94 and #95 if you'd rather the rule be applied without exception.

@claude

claude Bot commented Aug 25, 2026

Copy link
Copy Markdown

VERDICT: COMMENT-ONLY

Advisory

Scope creep — two distinct logical changes in one PR.

The PR ships two independent sets of template changes, each with its own CHANGELOG entry and its own commit message:

  1. chore(compat): CC 2.1.183–2.1.241 survey — retiring autoMode, Write(.env*), adding shell:bash, bumping tested_up_to, documenting /review shadowing.
  2. chore(skills): sync discipline-skills v6.0.2 → v6.3.0 — upstream SDD workspace, brainstorming classification, circuit breaker, etc.

CONTRIBUTING.md is explicit: "One logical change per PR. Reviewers (human and AI) struggle with mixed-purpose PRs; merge friction goes up; rollback gets messy." Two CHANGELOG entries for two conceptually distinct upstream syncs is the canonical signal of scope creep under that rule.

The PR body acknowledges this ("Two atomic commits under one theme; split further on request") and the shell: "bash" bridge is a genuine causal link between the two. Nothing here is blocking in the strict sense — the changes are thematically related and the shared mechanism exists — but future bundles of this kind should be split at the PR boundary (two commits in the branch already made that split; opening two PRs is the last step).


Everything else checks out:

  • Correctness / regression risk: autoMode retirement uses exact-dict equality (user-edited variants survive); Write(.env*) retirement uses exact-string membership; shell backfill is command-keyed and guards "shell" not in h so it never overwrites a user's explicit choice. BOM check, _find_unconsulted_path_rules, and the retrofit re-validate path are all correct.
  • AGPL contamination: None. New files (re-review-prompt.md, scripts/sdd-workspace) come from the MIT-licensed upstream.
  • discipline-skills/ MIT integrity: Subtree stays MIT-clean; both new files originate from obra/superpowers v6.3.0 (MIT). NOTICE updated from v5.1.0 → v6.3.0.
  • CHANGELOG ## Unreleased: Both entries present. ✅
  • Schema-claim hygiene: tested_up_to 2.1.220 grounded in SchemaStore PRs #5867 (merged 2026-07-03, → 2.1.195) and #6131 (merged 2026-07-27, → 2.1.220), cited in the CHANGELOG and compat comment. New opt-in stubs are doc-only in settings.local.json.example, not active defaults — consistent with the configurator's no-lone-bumps discipline.

@tigers1997
tigers1997 merged commit da326bf into main Aug 25, 2026
4 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant