Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
4 changes: 4 additions & 0 deletions CHANGELOG.md
Original file line number Diff line number Diff line change
Expand Up @@ -4,6 +4,10 @@ All notable changes to this project. Format: [Keep a Changelog](https://keepacha

## Unreleased

- **chore(compat): CC 2.1.183–2.1.241 survey — `tested_up_to` 2.1.150 → 2.1.220; retire the dead project-scope `autoMode` default and the `Write(.env*)` deny rules; `shell: "bash"` on every shipped hook; `/review` shadowing documented.** The no-lone-bumps gate finally cleared: SchemaStore's #5723 (→ 2.1.150) was closed unmerged, but #5867 (→ 2.1.195, merged 2026-07-03) and #6131 (→ 2.1.220, merged 2026-07-27) landed, so `tested_up_to` moves to **2.1.220** and the keys held since v2.6.0 (`fallbackModel`, `disableBundledSkills`) plus `agent`, `claudeMdExcludes`, `skillListingBudgetFraction` / `skillListingMaxDescChars`, `sandbox.credentials` (deny form) and `worktree.symlinkDirectories` / `sparsePaths` are schema-validated and promoted to doc-only opt-in stubs in `settings.local.json.example` (validation stamp 2026-07-27; the file also gains an `ANTHROPIC_DEFAULT_MODEL` note and an explicit "autoMode is NOT read from this file" warning). Every release 2.1.183 → 2.1.241 was read verbatim (2.1.182/184/188/189/192/194/213/230 are absent upstream); the installed CC is 2.1.241. **Template-affecting findings, all acted on:** **(1)** Since CC 2.1.207 the auto-mode classifier reads `autoMode` only from `~/.claude/settings.json` or managed settings — the live `auto-mode-config` doc states neither `.claude/settings.json` nor `.claude/settings.local.json` is read (both live in the repo) — so the `autoMode.hard_deny` block the safety module has shipped as an active default since v2.6.0 was dead config. It is removed from `templates/safety/settings-patch.json`; the old two rules are documented as a user-scope copy-paste block in `docs/05-safety-permissions.md` (with `"$defaults"`), a retrofit strips the *exact* shipped block from project settings (a user-edited variant is preserved), and `check_settings_validates` now flags any project-scope `autoMode` under `[ SETTINGS WARNINGS ]`. **(2)** CC 2.1.210 warns at startup about `Write(path)` / `NotebookEdit(path)` / `Glob(path)` rules, which it never consulted (`Edit(path)` covers Write and NotebookEdit; `Read(path)` covers Glob/Grep) — `Write(.env)` / `Write(.env.*)` are dropped from the core deny list (`Edit(.env)` / `Edit(.env.*)` stay), a retrofit strips those two shipped strings, and the preflight flags any remaining never-consulted path rule. New `RETIRED_PROJECT_AUTOMODE` / `RETIRED_DENY_RULES` constants in `configure.py`; the `[ MERGED ]` summary reports "removed N retired configurator default(s)". **(3)** Every shipped command hook (9 entries across the safety / slop-scan / git-workflow / token-efficiency-pro / microbit patches + 4 schema-embedded entries: PreCompact snapshot, the two mcp drift-check groups, the discipline bootstrap) now declares `"shell": "bash"` — a schema-validated key (CC 2.1.81+) that makes Windows sessions resolve Git for Windows directly instead of falling back to PowerShell and dying on the `.sh` entrypoint, and prompts to install Git Bash when it's missing; older CC ignores the key. Adopted after upstream superpowers v6.2.0 fixed its own SessionStart hook the same way. `_merge_hook_groups` backfills the key onto configurator-owned entries on retrofit (never onto a user's own commands or an explicit `shell` choice); README's Windows row rewritten. **(4)** CC 2.1.223 made `/review` the bundled alias of `/code-review` — the collision the 2.1.146 survey note watched for. The skills doc says a same-named project skill overrides a bundled one, and a headless check on 2.1.241 (a project skill named `review`, then `claude -p /review`) ran the project skill — likewise a project `plan` skill over the built-in `/plan` plan-mode shortcut — so no rename: the shadowing is documented in README's `commands` row, `docs/03`'s starter kit, and `review/SKILL.md`'s description ("Distinct from Claude Code's built-in /code-review"). **(5)** Subagent runtime changed under the docs: nesting default 5 → off (2.1.217) → 3 (2.1.219, `CLAUDE_CODE_MAX_SUBAGENT_SPAWN_DEPTH`), 20-concurrent cap (`CLAUDE_CODE_MAX_CONCURRENT_SUBAGENTS`, 2.1.217), background-by-default subagents with a narrower tool set (2.1.198), `fork` subagent type on by default (2.1.232), `Explore` inheriting the session model capped at Opus instead of Haiku (2.1.198), the Task tool's `mode` parameter deprecated (2.1.212) — `docs/04`, `docs/06`, `templates/commands/infinite/SKILL.md` and `multi-agent-guardrails.md` (new "Runtime caps to design around" section) reworded; the leaf-design guidance stands. **(6)** SessionStart gained the `fork` source (2.1.214; forks used to report `resume`): the microbit marker-clear stays `startup|clear` (markers now also persist across `/fork`, which is right) and the mcp drift-check stays `startup|resume`; comments and `docs/03` list the new source. Hook-matcher semantics (hyphenated names exact-match since 2.1.195, comma separators since 2.1.191, cwd-anchored single-segment `if:` patterns since 2.1.214) leave the pipe-joined shipped matchers unaffected and are documented in `docs/03`, whose event table also gains `DirectoryAdded` (2.1.219) and the settings example the `shell` key. **(7)** TodoWrite/Task* tools are withdrawn on Fable 5 / Opus 4.8+ / Sonnet 5 (2.1.233; `CLAUDE_CODE_ENABLE_TODO_TOOLS=1` restores) — no shipped template named them; noted in `docs/06`, which also refreshes the model lever for Sonnet 5 (2.1.197, Claude Code's default) and Opus 5 (2.1.219) and the `xhigh` effort default. **(8)** `--check` now rejects a UTF-8 BOM at the top of any shipped SKILL.md / agent file (CC before 2.1.239 silently ignored BOM-prefixed files). **Held / out of territory:** `sandbox.network.strictAllowlist` (2.1.219), `sandbox.filesystem.disabled` (2.1.216) and `dialogExpiry` (2.1.224) are user/managed-only per the settings reference; `crossSessionInbound` (2.1.224) is project-honored but not yet in SchemaStore (sync stops at 2.1.220) — held for the next sync; UI prefs (`keybindingFlavor`, `spellcheck`, `emojiCompletionEnabled`, `axScreenReader`, `vimInsertModeRemaps`, `respondToBashCommands`, `awaySummaryEnabled`), marketplace/plugin-source/self-hosted-runner/gateway keys and the removed `/agents` wizard need no configurator action. Full survey recorded in `CLAUDE_CODE_COMPAT`'s comment block. New tests: `test/retrofit-hooks/test-retired-defaults-migration.sh` (shipped autoMode + Write rules migrate out, `shell` backfilled on every hook, a user-edited autoMode block survives) and two new cases in `test/schema-hygiene/test-preflight-detects-violations.sh`; the `python-uv-fastapi` example regenerated. Claude Code compat: **2.1.116–2.1.220**.

- **chore(skills): sync discipline-skills v6.0.2 → v6.3.0 (obra/superpowers).** Four upstream releases since #85, all landing in the seven forked skills. **v6.0.3** moved SDD's scratch files out of `.git/` (Claude Code denies agent writes there) into a self-ignoring `.superpowers/sdd/` working-tree directory resolved by a new shared script, `scripts/sdd-workspace`. **v6.2.0** made that workspace plan-scoped (`.superpowers/sdd/<plan-basename>/`; `scripts/review-package` now takes the plan file first: `review-package PLAN_FILE BASE HEAD`), restructured the review-fix loop to resume the implementer with a scoped re-review (`re-review-prompt.md`, NEW) and a five-round circuit breaker, ran a library-wide compression campaign (the Bottom Line / Key Principles / Advantages / Integration / "Why This Matters" sections are gone; `using-git-worktrees` and `finishing-a-development-branch` gained Excuse/Reality rationalization tables), dropped "Discard this work" from the finishing menu (discard is explicit-request-only), made PR creation forge-agnostic and fixed the worktree path being recomputed after the cleanup `cd`. **v6.3.0** teaches `brainstorming` to classify requests as spike / bounded / architectural and scale the ceremony (only the architectural path writes a spec; the approval gate never scales), has SDD controllers issue recorded rulings instead of stalling on plan conflicts (ledgered pre-flight scan table, batched same-shape tasks, a hard "implementers and reviewers never spawn subagents" contract in both prompt templates, a `**Spec:**` pointer in the `writing-plans` header, reviewers re-reading illegible evidence instead of re-running suites), and stops `finishing-a-development-branch` from `--force`-removing a worktree that holds untracked files. Local edits re-applied per SYNC.md: `superpowers:` prefixes stripped (14 sites across three SKILL.md files), the brainstorming `## Visual Companion` section and the visual-companion step of the *architectural* checklist removed (8 items; the spike/bounded lists have none), the executing-plans subagents note reframed project-neutral. **One new local edit:** SDD's final whole-branch review now points at the configurator's own `code-reviewer` subagent (`.claude/agents/code-reviewer.md`, with a `task-reviewer-prompt.md` fallback when the `commands` module isn't installed) instead of upstream's `../requesting-code-review/code-reviewer.md` — three digraph labels plus the `## Final Review` paragraph — which retires the broken-link papercut carried since v5.1.0. The former "remove the requesting-code-review / test-driven-development lines from `## Integration`" edits are obsolete (upstream dropped the section in v6.2.0). Module `paths:` 15 → 17 (`re-review-prompt.md`, `scripts/sdd-workspace`); `test-module-files-exist.sh` and `test-scaffold-installs-skills.sh` updated (the scaffold test now asserts all three scripts ship executable); the three persona snapshots that include the module regenerated; SYNC.md pinned to v6.3.0 (2026-08-12) with a fresh delta paragraph, a CRLF note for Windows checkouts, and a renumbered canonical-edit list; the module description, README carve-out paragraphs, `NOTICE` and `docs/10` (the last two still said v5.1.0) bumped. On a `core.filemode=false` checkout the new script's index mode was set with `git add --chmod=+x`. Upstream's v6.2.0 Windows fix (`"shell": "bash"` on its SessionStart hook) is adopted configurator-wide in the companion compat entry.

- **feat(hooks): `stop-run-checks` can run a check inside its docker-compose service (dogfood F3).** A containerized project's check loop no-op'd because the toolchain lives in the image, not on the host PATH (F2 warned about this). A `CHECKS` entry now takes an optional 3rd field — `label|command|service` — and when a service is named the Stop hook runs the check inside it: `docker compose exec -T <svc> <cmd>` if the service is up, else `docker compose run --rm <svc> <cmd>` (a throwaway instance of the *existing* service — no new container, no host rebuild, no path translation). The host-PATH/manifest guards are bypassed for container checks; infra-not-ready (no docker/compose, or service undefined) skips silently (fail-open), and a non-zero container exit is reported as a normal check FAIL. Two-field `label|command` entries — including host commands containing a literal `|` — are unchanged; an entry is container-bound only when it has ≥2 pipes and a bare-token final field. The F2 `[ STACK WARNINGS ]` note now points at this field. New `test/stop-run-checks/test-container-checks.sh` (run-vs-exec by service state, skip when compose/service absent, FAIL on non-zero, 2-field stays host-side) via a `docker` stub. **Deferred follow-up:** a conditional intake field that detects `docker-compose.yml` and pre-populates the service per check (this format is the substrate). No `tested_up_to` / `CC_VERSION` bump.

- **fix(preflight): host-PATH gate handles path-like binaries (`./gradlew`); drop redundant `import shutil`; tighten the retrofit-migration test (review follow-ups to #88/#89).** Three non-blocking advisories from the split dogfood PRs: **(1)** `check_stack_reality`'s container-note gate used `shutil.which(b)`, which always returns `None` for a path-like binary like `./gradlew` (a project-local wrapper, never on PATH) — so a Gradle-wrapper project with a `Dockerfile`/compose and no root `build.gradle` got a spurious "toolchain lives in the container" note. The gate now file-checks path-like binaries (`(target_dir / b).exists()`) and only consults `shutil.which` for bare names. **(2)** the inline `import shutil` inside `check_stack_reality` was redundant (shutil is imported at module top) and is removed. **(3)** `test/retrofit-hooks/test-sessionstart-matcher-migration.sh` case 2 now asserts the marker-clear migrates *out* of a user's mixed matcherless group (appearing exactly once, under `startup|clear`), not merely that the user hook survives. New `./gradlew` case in `test/cc-manifest/test-stack-reality-preflight.sh`. No behavior change for non-path stacks.
Expand Down
2 changes: 1 addition & 1 deletion NOTICE
Original file line number Diff line number Diff line change
Expand Up @@ -9,7 +9,7 @@ version 3 (AGPL-3.0). See LICENSE for the full text.
Bundled third-party code under different (compatible) licenses:

* templates/discipline-skills/
Forked from obra/superpowers v5.1.0
Forked from obra/superpowers v6.3.0
(https://github.com/obra/superpowers)
Copyright (c) 2025 Jesse Vincent
Licensed under the MIT License
Expand Down
Loading