Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
4 changes: 4 additions & 0 deletions CHANGELOG.md
Original file line number Diff line number Diff line change
Expand Up @@ -4,6 +4,10 @@ All notable changes follow [Semantic Versioning](docs/versioning/README.md).

## [Unreleased]

## [0.2.20] - 2026-10-09

- Keep disposable Git fixture commits independent of workstation signing preferences.

### Fixed

- Static repository scanners now skip default ignored directories such as
Expand Down
2 changes: 1 addition & 1 deletion docs/release/npm-package.md
Original file line number Diff line number Diff line change
Expand Up @@ -7,7 +7,7 @@ safety model.
## Current Package Shape

- Package name: `coding-agent-skills`.
- Package version: `0.2.19`.
- Package version: `0.2.20`.
- CLI bin: `coding-agent-skills` mapped to `bin/coding-agent-skills`.
- Module type: `module`.
- Dependencies: none.
Expand Down
2 changes: 1 addition & 1 deletion package.json
Original file line number Diff line number Diff line change
@@ -1,6 +1,6 @@
{
"name": "coding-agent-skills",
"version": "0.2.19",
"version": "0.2.20",
"description": "Evidence-first, read-only coding-agent skills and project adapter tooling.",
"type": "module",
"private": false,
Expand Down
7 changes: 7 additions & 0 deletions runs/skill-runs.md
Original file line number Diff line number Diff line change
Expand Up @@ -373,3 +373,10 @@ This file records bounded maintainer-loop runs. Entries must not contain secrets
complete Node test suite. The earlier transient stderr assertion could not be
reproduced and is no longer a completion blocker.
- Commit/tag/push status: not requested.


## Distribution reconciliation — 2026-10-09

Candidate `0.2.20` reconciles npm with the current GitHub implementation under the owner-authorised package update objective. Local validation, tarball inspection, clean installation, and authenticated publication are required. Registry publication is pending; existing product authority and execution boundaries remain unchanged.

Validation evidence: Passed pack validation, complete npm test, maintainer-loop validation, evidence-bundle replay and archive report. A fresh-cache tarball install passed installed validate-pack. Synthetic .env.example fixtures are intentional; no credential-pattern matches were found. Registry publication and post-publication installation remain pending.
34 changes: 17 additions & 17 deletions scripts/test-pack.mjs
Original file line number Diff line number Diff line change
Expand Up @@ -175,7 +175,7 @@ function createGitFixture(sourceRelativePath) {
runGitFixtureCommand(temporary, ["config", "user.name", "Fixture User"]);
runGitFixtureCommand(temporary, ["config", "user.email", "fixture@example.invalid"]);
runGitFixtureCommand(temporary, ["add", "."]);
runGitFixtureCommand(temporary, ["commit", "-m", "initial fixture commit"]);
runGitFixtureCommand(temporary, ["-c", "commit.gpgsign=false", "commit", "-m", "initial fixture commit"]);
return temporary;
}

Expand Down Expand Up @@ -236,7 +236,7 @@ function snapshotAbsoluteDirectory(directory) {
return digest.digest("hex");
}

function assertOpenClawJsonContract(value, command, packageVersion = "0.2.19") {
function assertOpenClawJsonContract(value, command, packageVersion = "0.2.20") {
assert.equal(value.tool, "coding-agent-skills");
assert.equal(value.command, command);
assert.equal(value.packageVersion, packageVersion);
Expand Down Expand Up @@ -490,7 +490,7 @@ test("local CLI emits OpenClaw-compatible JSON for public commands", () => {
assert.equal(result.stderr, "");
const parsed = JSON.parse(result.stdout);
assertOpenClawJsonContract(parsed, args[0]);
assert.deepEqual(validateCliResult(cliResultSchema, parsed, "0.2.19"), []);
assert.deepEqual(validateCliResult(cliResultSchema, parsed, "0.2.20"), []);
}

const emptyAdapters = spawnSync(
Expand Down Expand Up @@ -552,7 +552,7 @@ test("public CLI result schema and semantic rules cover success and controlled f
const result = spawnSync(cliPath, item.args, { cwd: root, encoding: "utf8", stdio: "pipe" });
assert.equal(result.status, item.exitCode, `${item.args.join(" ")}\n${result.stderr}`);
const parsed = JSON.parse(result.stdout);
assert.deepEqual(validateCliResult(cliResultSchema, parsed, "0.2.19"), []);
assert.deepEqual(validateCliResult(cliResultSchema, parsed, "0.2.20"), []);
assert.equal(parsed.exitCode, item.exitCode);
assert.equal(parsed.changedState, false);
assert.equal(parsed.safety.secretsRead, false);
Expand All @@ -571,8 +571,8 @@ test("public CLI result schema and semantic rules cover success and controlled f
test("aggregate audit is deterministic, adapter-optional, and mutation-free", () => {
const fixture = createGitFixture(path.join("tests", "fixtures", "audit-bundle", "static-project"));
const before = snapshotAbsoluteDirectory(fixture);
const first = buildAuditBundleReport(fixture, { coreRoot: root, packageVersion: "0.2.19" });
const second = buildAuditBundleReport(fixture, { coreRoot: root, packageVersion: "0.2.19" });
const first = buildAuditBundleReport(fixture, { coreRoot: root, packageVersion: "0.2.20" });
const second = buildAuditBundleReport(fixture, { coreRoot: root, packageVersion: "0.2.20" });
const after = snapshotAbsoluteDirectory(fixture);

assert.equal(before, after);
Expand All @@ -586,12 +586,12 @@ test("aggregate audit is deterministic, adapter-optional, and mutation-free", ()
assert.equal(fs.existsSync(path.join(fixture, "migration-command-ran")), false);
assert.equal(fs.existsSync(path.join(fixture, "deployment-command-ran")), false);

const outcome = auditBundleCliResult(fixture, { coreRoot: root, packageVersion: "0.2.19" });
const outcome = auditBundleCliResult(fixture, { coreRoot: root, packageVersion: "0.2.20" });
const json = buildCliResult("audit", [fixture], outcome, {
packageVersion: "0.2.19",
packageVersion: "0.2.20",
commandMetadata: PUBLIC_COMMAND_METADATA,
});
assert.deepEqual(validateCliResult(cliResultSchema, json, "0.2.19"), []);
assert.deepEqual(validateCliResult(cliResultSchema, json, "0.2.20"), []);
assert.equal(json.results.length, 8);
assert.equal(json.metrics.boundedOutput, true);
assert.ok(json.results.every((result) => result.metrics.boundedOutput === true));
Expand All @@ -603,7 +603,7 @@ test("aggregate audit accepts valid adapters, marks partial applicability, and r
const fixtureRoot = path.join(root, "tests", "fixtures", "project-adapter-installation");
const valid = auditBundleCliResult(path.join(fixtureRoot, "valid-exact-pin"), {
coreRoot: root,
packageVersion: "0.2.19",
packageVersion: "0.2.20",
});
assert.equal(valid.exitCode, 0);
assert.equal(valid.report.adapter.present, true);
Expand All @@ -612,32 +612,32 @@ test("aggregate audit accepts valid adapters, marks partial applicability, and r

const unsafe = auditBundleCliResult(path.join(fixtureRoot, "invalid-weakens-restrictions"), {
coreRoot: root,
packageVersion: "0.2.19",
packageVersion: "0.2.20",
});
assert.equal(unsafe.exitCode, 3);
assert.equal(unsafe.report.status, "blocked");
});

test("CLI semantic validation rejects unsafe or contradictory evidence", () => {
const valid = {
packageVersion: "0.2.19",
packageVersion: "0.2.20",
changedState: false,
status: "complete",
exitCode: 0,
exitCodeMeaning: "handled",
recommendedNextAction: { label: "Review", reason: "Evidence only", requiresApproval: false },
safety: { readOnly: true, secretsRead: false, targetCommandsRun: false, mutationsPerformed: false },
};
assert.deepEqual(cliResultSemanticIssues(valid, "0.2.19"), []);
assert.ok(cliResultSemanticIssues({ ...valid, changedState: true }, "0.2.19").length > 0);
assert.ok(cliResultSemanticIssues({ ...valid, exitCode: 4 }, "0.2.19").length > 0);
assert.ok(cliResultSemanticIssues({ ...valid, packageVersion: "9.9.9" }, "0.2.19").length > 0);
assert.deepEqual(cliResultSemanticIssues(valid, "0.2.20"), []);
assert.ok(cliResultSemanticIssues({ ...valid, changedState: true }, "0.2.20").length > 0);
assert.ok(cliResultSemanticIssues({ ...valid, exitCode: 4 }, "0.2.20").length > 0);
assert.ok(cliResultSemanticIssues({ ...valid, packageVersion: "9.9.9" }, "0.2.20").length > 0);
});

test("npm package metadata is public-ready and dependency-free", () => {
const packageJson = readJson("package.json");
assert.equal(packageJson.name, "coding-agent-skills");
assert.equal(packageJson.version, "0.2.19");
assert.equal(packageJson.version, "0.2.20");
assert.equal(
packageJson.description,
"Evidence-first, read-only coding-agent skills and project adapter tooling.",
Expand Down
4 changes: 2 additions & 2 deletions scripts/validate-pack.mjs
Original file line number Diff line number Diff line change
Expand Up @@ -698,8 +698,8 @@ if (packageJson) {
if (packageJson.name !== "coding-agent-skills") {
failures.push("package.json has unexpected package name");
}
if (packageJson.version !== "0.2.19") {
failures.push("package.json version must be 0.2.19 for public package validation");
if (packageJson.version !== "0.2.20") {
failures.push("package.json version must be 0.2.20 for public package validation");
}
if (packageJson.type !== "module") failures.push("package.json must preserve ESM mode");
if (packageJson.private !== false) {
Expand Down
7 changes: 7 additions & 0 deletions work-ledger.md
Original file line number Diff line number Diff line change
Expand Up @@ -279,3 +279,10 @@ No autonomous maintainer-loop run has been recorded yet.
- Required permission: `evidence-harness`
- Validation result: pass
- Next recommended milestone: human direction required before selecting the next bounded milestone.


## Distribution reconciliation — 2026-10-09

Candidate `0.2.20` reconciles npm with the current GitHub implementation under the owner-authorised package update objective. Local validation, tarball inspection, clean installation, and authenticated publication are required. Registry publication is pending; existing product authority and execution boundaries remain unchanged.

Validation evidence: Passed pack validation, complete npm test, maintainer-loop validation, evidence-bundle replay and archive report. A fresh-cache tarball install passed installed validate-pack. Synthetic .env.example fixtures are intentional; no credential-pattern matches were found. Registry publication and post-publication installation remain pending.
Loading