diff --git a/CHANGELOG.md b/CHANGELOG.md index cd24307..aa1dcda 100644 --- a/CHANGELOG.md +++ b/CHANGELOG.md @@ -4,6 +4,10 @@ All notable changes follow [Semantic Versioning](docs/versioning/README.md). ## [Unreleased] +## [0.2.20] - 2026-10-09 + +- Keep disposable Git fixture commits independent of workstation signing preferences. + ### Fixed - Static repository scanners now skip default ignored directories such as diff --git a/docs/release/npm-package.md b/docs/release/npm-package.md index 6e0fd90..8bcd8f0 100644 --- a/docs/release/npm-package.md +++ b/docs/release/npm-package.md @@ -7,7 +7,7 @@ safety model. ## Current Package Shape - Package name: `coding-agent-skills`. -- Package version: `0.2.19`. +- Package version: `0.2.20`. - CLI bin: `coding-agent-skills` mapped to `bin/coding-agent-skills`. - Module type: `module`. - Dependencies: none. diff --git a/package.json b/package.json index 31e5991..31dddaf 100644 --- a/package.json +++ b/package.json @@ -1,6 +1,6 @@ { "name": "coding-agent-skills", - "version": "0.2.19", + "version": "0.2.20", "description": "Evidence-first, read-only coding-agent skills and project adapter tooling.", "type": "module", "private": false, diff --git a/runs/skill-runs.md b/runs/skill-runs.md index 6d9c7e3..a9101af 100644 --- a/runs/skill-runs.md +++ b/runs/skill-runs.md @@ -373,3 +373,10 @@ This file records bounded maintainer-loop runs. Entries must not contain secrets complete Node test suite. The earlier transient stderr assertion could not be reproduced and is no longer a completion blocker. - Commit/tag/push status: not requested. + + +## Distribution reconciliation — 2026-10-09 + +Candidate `0.2.20` reconciles npm with the current GitHub implementation under the owner-authorised package update objective. Local validation, tarball inspection, clean installation, and authenticated publication are required. Registry publication is pending; existing product authority and execution boundaries remain unchanged. + +Validation evidence: Passed pack validation, complete npm test, maintainer-loop validation, evidence-bundle replay and archive report. A fresh-cache tarball install passed installed validate-pack. Synthetic .env.example fixtures are intentional; no credential-pattern matches were found. Registry publication and post-publication installation remain pending. diff --git a/scripts/test-pack.mjs b/scripts/test-pack.mjs index cc691d2..6b13339 100644 --- a/scripts/test-pack.mjs +++ b/scripts/test-pack.mjs @@ -175,7 +175,7 @@ function createGitFixture(sourceRelativePath) { runGitFixtureCommand(temporary, ["config", "user.name", "Fixture User"]); runGitFixtureCommand(temporary, ["config", "user.email", "fixture@example.invalid"]); runGitFixtureCommand(temporary, ["add", "."]); - runGitFixtureCommand(temporary, ["commit", "-m", "initial fixture commit"]); + runGitFixtureCommand(temporary, ["-c", "commit.gpgsign=false", "commit", "-m", "initial fixture commit"]); return temporary; } @@ -236,7 +236,7 @@ function snapshotAbsoluteDirectory(directory) { return digest.digest("hex"); } -function assertOpenClawJsonContract(value, command, packageVersion = "0.2.19") { +function assertOpenClawJsonContract(value, command, packageVersion = "0.2.20") { assert.equal(value.tool, "coding-agent-skills"); assert.equal(value.command, command); assert.equal(value.packageVersion, packageVersion); @@ -490,7 +490,7 @@ test("local CLI emits OpenClaw-compatible JSON for public commands", () => { assert.equal(result.stderr, ""); const parsed = JSON.parse(result.stdout); assertOpenClawJsonContract(parsed, args[0]); - assert.deepEqual(validateCliResult(cliResultSchema, parsed, "0.2.19"), []); + assert.deepEqual(validateCliResult(cliResultSchema, parsed, "0.2.20"), []); } const emptyAdapters = spawnSync( @@ -552,7 +552,7 @@ test("public CLI result schema and semantic rules cover success and controlled f const result = spawnSync(cliPath, item.args, { cwd: root, encoding: "utf8", stdio: "pipe" }); assert.equal(result.status, item.exitCode, `${item.args.join(" ")}\n${result.stderr}`); const parsed = JSON.parse(result.stdout); - assert.deepEqual(validateCliResult(cliResultSchema, parsed, "0.2.19"), []); + assert.deepEqual(validateCliResult(cliResultSchema, parsed, "0.2.20"), []); assert.equal(parsed.exitCode, item.exitCode); assert.equal(parsed.changedState, false); assert.equal(parsed.safety.secretsRead, false); @@ -571,8 +571,8 @@ test("public CLI result schema and semantic rules cover success and controlled f test("aggregate audit is deterministic, adapter-optional, and mutation-free", () => { const fixture = createGitFixture(path.join("tests", "fixtures", "audit-bundle", "static-project")); const before = snapshotAbsoluteDirectory(fixture); - const first = buildAuditBundleReport(fixture, { coreRoot: root, packageVersion: "0.2.19" }); - const second = buildAuditBundleReport(fixture, { coreRoot: root, packageVersion: "0.2.19" }); + const first = buildAuditBundleReport(fixture, { coreRoot: root, packageVersion: "0.2.20" }); + const second = buildAuditBundleReport(fixture, { coreRoot: root, packageVersion: "0.2.20" }); const after = snapshotAbsoluteDirectory(fixture); assert.equal(before, after); @@ -586,12 +586,12 @@ test("aggregate audit is deterministic, adapter-optional, and mutation-free", () assert.equal(fs.existsSync(path.join(fixture, "migration-command-ran")), false); assert.equal(fs.existsSync(path.join(fixture, "deployment-command-ran")), false); - const outcome = auditBundleCliResult(fixture, { coreRoot: root, packageVersion: "0.2.19" }); + const outcome = auditBundleCliResult(fixture, { coreRoot: root, packageVersion: "0.2.20" }); const json = buildCliResult("audit", [fixture], outcome, { - packageVersion: "0.2.19", + packageVersion: "0.2.20", commandMetadata: PUBLIC_COMMAND_METADATA, }); - assert.deepEqual(validateCliResult(cliResultSchema, json, "0.2.19"), []); + assert.deepEqual(validateCliResult(cliResultSchema, json, "0.2.20"), []); assert.equal(json.results.length, 8); assert.equal(json.metrics.boundedOutput, true); assert.ok(json.results.every((result) => result.metrics.boundedOutput === true)); @@ -603,7 +603,7 @@ test("aggregate audit accepts valid adapters, marks partial applicability, and r const fixtureRoot = path.join(root, "tests", "fixtures", "project-adapter-installation"); const valid = auditBundleCliResult(path.join(fixtureRoot, "valid-exact-pin"), { coreRoot: root, - packageVersion: "0.2.19", + packageVersion: "0.2.20", }); assert.equal(valid.exitCode, 0); assert.equal(valid.report.adapter.present, true); @@ -612,7 +612,7 @@ test("aggregate audit accepts valid adapters, marks partial applicability, and r const unsafe = auditBundleCliResult(path.join(fixtureRoot, "invalid-weakens-restrictions"), { coreRoot: root, - packageVersion: "0.2.19", + packageVersion: "0.2.20", }); assert.equal(unsafe.exitCode, 3); assert.equal(unsafe.report.status, "blocked"); @@ -620,7 +620,7 @@ test("aggregate audit accepts valid adapters, marks partial applicability, and r test("CLI semantic validation rejects unsafe or contradictory evidence", () => { const valid = { - packageVersion: "0.2.19", + packageVersion: "0.2.20", changedState: false, status: "complete", exitCode: 0, @@ -628,16 +628,16 @@ test("CLI semantic validation rejects unsafe or contradictory evidence", () => { recommendedNextAction: { label: "Review", reason: "Evidence only", requiresApproval: false }, safety: { readOnly: true, secretsRead: false, targetCommandsRun: false, mutationsPerformed: false }, }; - assert.deepEqual(cliResultSemanticIssues(valid, "0.2.19"), []); - assert.ok(cliResultSemanticIssues({ ...valid, changedState: true }, "0.2.19").length > 0); - assert.ok(cliResultSemanticIssues({ ...valid, exitCode: 4 }, "0.2.19").length > 0); - assert.ok(cliResultSemanticIssues({ ...valid, packageVersion: "9.9.9" }, "0.2.19").length > 0); + assert.deepEqual(cliResultSemanticIssues(valid, "0.2.20"), []); + assert.ok(cliResultSemanticIssues({ ...valid, changedState: true }, "0.2.20").length > 0); + assert.ok(cliResultSemanticIssues({ ...valid, exitCode: 4 }, "0.2.20").length > 0); + assert.ok(cliResultSemanticIssues({ ...valid, packageVersion: "9.9.9" }, "0.2.20").length > 0); }); test("npm package metadata is public-ready and dependency-free", () => { const packageJson = readJson("package.json"); assert.equal(packageJson.name, "coding-agent-skills"); - assert.equal(packageJson.version, "0.2.19"); + assert.equal(packageJson.version, "0.2.20"); assert.equal( packageJson.description, "Evidence-first, read-only coding-agent skills and project adapter tooling.", diff --git a/scripts/validate-pack.mjs b/scripts/validate-pack.mjs index 82b9fb7..8b0cd17 100644 --- a/scripts/validate-pack.mjs +++ b/scripts/validate-pack.mjs @@ -698,8 +698,8 @@ if (packageJson) { if (packageJson.name !== "coding-agent-skills") { failures.push("package.json has unexpected package name"); } - if (packageJson.version !== "0.2.19") { - failures.push("package.json version must be 0.2.19 for public package validation"); + if (packageJson.version !== "0.2.20") { + failures.push("package.json version must be 0.2.20 for public package validation"); } if (packageJson.type !== "module") failures.push("package.json must preserve ESM mode"); if (packageJson.private !== false) { diff --git a/work-ledger.md b/work-ledger.md index 057576d..5e7659e 100644 --- a/work-ledger.md +++ b/work-ledger.md @@ -279,3 +279,10 @@ No autonomous maintainer-loop run has been recorded yet. - Required permission: `evidence-harness` - Validation result: pass - Next recommended milestone: human direction required before selecting the next bounded milestone. + + +## Distribution reconciliation — 2026-10-09 + +Candidate `0.2.20` reconciles npm with the current GitHub implementation under the owner-authorised package update objective. Local validation, tarball inspection, clean installation, and authenticated publication are required. Registry publication is pending; existing product authority and execution boundaries remain unchanged. + +Validation evidence: Passed pack validation, complete npm test, maintainer-loop validation, evidence-bundle replay and archive report. A fresh-cache tarball install passed installed validate-pack. Synthetic .env.example fixtures are intentional; no credential-pattern matches were found. Registry publication and post-publication installation remain pending.