CLI Changelog
@punks/cli npm executable release notes
Unreleased
6.1.0 - 2026-09-28
Added
- Give Codex native TypeScript 7 semantic reads with the TypeScript Pack.
hi updateinstalls the pinned Typegraph MCP runtime once per machine under${XDG_DATA_HOME:-~/.local/share}/hi-tools/typegraph-mcp/<version>(exact lock,npm ci --ignore-scripts, reused through a receipt, never pruned), finds each git-listedtsconfig.jsonCompiler Project (wiki and solution-only configs excluded, nested ones reported as ambiguous, settingstypescript.compilerProjectsoverrides), load-probes it, and keeps one read-only Codex server per passing project in a fenced# BEGIN hi typegraphblock of.codex/config.toml. Each server exposes five reads. The block is restored on every update and removed when the Pack is deselected; every byte outside it is kept, and a user-defined table with the same name wins. Needs Node 22.18 or newer andnpm. hi checkreportssemanticReadswhen the TypeScript Pack is installed: whether the runtime is installed, how many Codex entries are registered, and each Compiler Project's load probe, as three separate lines. Probes share a 30 s budget and never changestatus.
Fixed
hi tools ensureruns install and validation commands with the caller'sPATH, so tools already installed are found (#239).hi operatoraccepts the running CLI major again: the operator skill compatibility range follows the CLI version instead of stopping at 6.0.0 (#240).- Workspace prompt specs list only the default Packs meant for workspaces
(
docs,misc, andverificationstay in the shared, root, and docs specs), and list thefrontendandbackendPacks only for workspaces that show their signals (#241). - Repository detection skips git-ignored paths, so ignored build output or
stray files no longer propose Packs or workspaces; the docs prompt spec is
written only when a
docs/directory exists (#242).
6.0.1 - 2026-09-28
Fixed
- Never follow a symlinked parent outside the repository during migration or
merge-target validation; such paths are skipped (
migrated-skipped) or refused before any write. - Replace an installer-owned Copied or Built file when a later Baseline turns
the path into a symlink (a locally edited file still waits for
--yes). - Keep the Drift Check working offline right after
hi init/hi updateby caching the applied Baseline catalog. - Run allowed post-install commands without a Unix shell, so they work on Windows.
- Deduplicate a harness skill whose id
.agents/skillsalready holds, keeping a differing copy as[DEPRECATED] <id> (<harness>), so the shared skills link can be created. - Record installer-added devDependencies when a first install is interrupted and retried; never claim a dependency the last commit already declared.
hi diffresolves the latest Baseline from the currentsettings.packs.- An empty backlog project URL answer in
hi initclears a stored URL. - Never move the Registry
latestpointer back when an older same-day Baseline is republished. - Wrap seeded
oxlint.local.tsarrays at the formatter's print width. - Honor settings
commitGateChecks.repositoryagain: the Commit Gate runs the repository lint or format command for staged repository-level paths outside every Software Scope (the wiki stays excluded), as CLI 5.x did.
6.0.0 - 2026-09-28
Changed
- Install and update the harness from the public Registry
(
https://api.harness-intelligence.devpunks.com/r). The CLI sends no credential, carries no bundled Baseline, and refuses a Baseline whose CLI range excludes it. - Replace the lifecycle commands with
hi init,hi update [--yes],hi diff, andhi check.hi scaffoldandhi ensureare removed;hi initdetects the repository once, proposes Packs and Software Scopes, and writes.devpunks/settings.json. - Keep two local state files:
.devpunks/settings.json(intent, includingpacks) and.devpunks/installed.json(the Installed Record: Baseline version, Recorded Shape, item-to-path map, failed links). No content hashes are stored. - Apply Copied Artifacts by overwrite, re-render Built Artifacts, and write
Authored Artifacts only when absent.
hi update --yesoverwrites a Copied Artifact with a local edit and an upstream change and reports its path. - Build subagent files for Claude, Codex, Cursor, and OpenCode inside the CLI
(Harness Adapters);
sync-subagents.mjsand the harness-projection scripts are no longer installed. - Keep pre-existing skills as Project Skills; when a Baseline skill takes the
same id, rename the Project Skill to
[DEPRECATED] <name>. hi checkcompares the installed Baseline with the latest one only and returnsstatus(current,update-available,unavailable,not-installed);hi diffruns the three-way Drift Check.- Migrate manifest-based repositories in the first
hi update.
Fixed
- Classify lint findings correctly for any oxlint output size and pass Commit Gate file lists without exceeding operating-system argument limits (#232).
- Never block edits in a worktree without an Installed Record (#231).
5.2.2 - 2026-09-24
Changed
- Leave wiki package setup, routes, content, and metadata to the owning project;
hi init,hi scaffold, andhi updateno longer create or align a wiki. - Check an existing wiki against the project structure during the shared
hi-clipost-command handoff.
Fixed
- Recognize the repository's Turbo check route and read-only format commands when adopting managed lint, and preserve disjoint inherited Oxlint policy.
- Accept the scoped root static gate while retaining the full managed lint dispatcher for operator runs and linting changed files in CI.
- Find Node when the managed lint runner validates tools from a scoped runtime.
- Keep edited-file lint available when an unrelated repository symlink points outside the root, while rejecting external required lint inputs.
- Preserve update preparation evidence when publication readiness fails after a lint preview.
- Plan the edited-file hook when managed quality setup will add Oxfmt during the same update.
5.2.1 - 2026-09-23
Fixed
- Make managed lint scope selection explicit and route every eligible file to its most-specific selected owner across package scripts, CI, Commit Gate, and edited-file checks (#224).
- Preserve inherited Oxlint policy, supported custom commands, warning thresholds, and referenced lint catalogs through adoption and repeated updates (#224).
- Skip managed checks for excluded-only changes while preserving independent Python/Ruff behavior; keep wiki paths and unselected package boundaries outside managed software lint (#224).
- Validate dependent policy, config, routes, and tool inputs before activation, and report selection, drift, findings, and unresolved migration failures with actionable context (#224).
5.2.0 - 2026-09-22
Added
- Add explicit file, owner, and repository execution scopes for Commit Gate checks, including repository lint and format authority in project settings (#222).
Fixed
- Validate the complete update candidate, including live guidance targets, staged replacements, and removals, before publishing managed changes (#222).
- Limit update installation and lint work to affected consumers, including optional dependency consumers; support generated backoffice Vitest overrides and preserve actionable installation and configuration errors (#222).
- Keep unrelated archives and migration payloads out of generation freshness while retaining validation of explicitly referenced inputs (#222).
- Cover root changes, deletions, and cross-owner renames in Commit Gate checks; preserve command output, deduplicate identical checks, and enforce zero warnings for generated Oxlint commands (#222).
Changed
- Retire the standalone handback skill and its generated prompt pointers in favor of handback guidance owned by lifecycle phases (#222).
- Use Bun 1.4.0 for repository tooling and two-vCPU Linux CI workers, removing automated macOS jobs and provisioning browsers only for selected consumers (#223).
- Reuse verification results across unrelated documentation changes while tracking consumed inputs and runtime capabilities; remove duplicate task execution (#223).
- Reduce routine test setup and repeated assertions, use minimal real release recovery histories, and retain full historical recovery replay and updater benchmarking as on-demand diagnostics (#223).
5.1.1 - 2026-09-17
Added
- Make
hi updatederive managed artifacts from a shared manifest-driven plan, validate in an isolated candidate, and reuse validation and prepared-install results only for matching relevant inputs (#215). - Report update lifecycle progress while preserving a single final JSON stdout document, with local cache clearing and optional signed remote-cache transport outcomes surfaced explicitly (#215).
Fixed
- Fail closed before dependent update work when validation inputs are incomplete, uncontained through canonical path aliases, or use uncontrolled executable configuration; retain precise subprocess failure facts (#215).
- Keep update planned and completed operations truthful across no-change, recovery, cache-reuse, and managed-drift outcomes (#215).
5.1.0 - 2026-09-15
Added
- Distribute
verify-behavior,create-verification-skill, andupdate-verification-skilltogether in the default verification pack while preserving project-owned verifier reference bytes (#207).
Fixed
- Preserve repository-owned wiki starters during scaffold/check/update and honor populated directories and flat routes without false missing-seed findings (#203).
- Resolve nested Oxlint transition rules through registered workspace plugin aliases and retain JSON lint policy in both planning and materialization (#203).
- Regenerate managed handoffs from current authoring proofs so completed post-command work does not leave stale pending actions (#203).
- Resolve Commit Gate contract roots from the current checkout or linked worktree, and report actionable working-directory and process-launch errors instead of an empty exit-1 failure (#204).
- Restore Effect internal-module topology and repository-boundary guidance while
keeping service qualification and application policy in
effect-service-design(#205). - Limit automatic React Doctor and TDD activation to their intended task
boundaries, and resolve React Doctor changed scans from the checked-out branch's
configured origin upstream with an explicit base. Keep
verify-behavioravailable to explicit orchestration without top-level automatic activation (#206).
5.0.1 - 2026-09-10
Fixed
- Resolve the latest canonical
wearedevpunks/skillsmainonce per operator command, freeze its immutable commit across scopes and readbacks, and install or update only exact verifiedhi-clicontent without falling back to the compiled skill.
Changed
- Clarify that scaffold and update install the shared
verify-behaviorskill while preserving project-owned verification references;implement-specremains responsible for Uncovered Surface and Uncovered Behavior work.
5.0.0 - 2026-09-10
Added
- Add explicit scaffold artifact obligations, baseline-delivered shared-agent guidance, planned Commit Gate setup, and recovery for interrupted adoption and coupled publication.
- Add dependency-ready delivery task gates, active write-scope ownership, project-owned executable verification, a frozen review epoch, and bounded repair validation.
Changed
- Preserve planned workspace topology during isolated scaffold validation, refresh only affected guidance scopes, and retain project-owned verifier references across scaffold and update flows.
- Use compact pointer-based worker context and durable handoff evidence while
keeping V4.3 acceptance at 170 satisfied criteria and four
excepted_not_passedbenchmark criteria (AC-044–AC-047).
Fixed
- Inherit the process environment when generated JavaScript files run without an explicit environment, while preserving explicitly supplied environments.
- Materialize Commit Gate setup from the selected nested package root in
repositories without a root
package.json. - Persist independently completed reconciliation receipt entries when Commit Gate setup is deferred.
- Leave user-owned Lefthook configuration unpinned when Commit Gate is disabled and no managed gate command exists.
- Reject wrapped formatter commands that enable write mode, including short
-wflags, from read-only Commit Gate format checks.
4.0.4 - 2026-09-03
Fixed
- Canonicalize generated sync-subagents entrypoint paths so the intended guard runs, and stage completed prior projection-receipt evidence before candidate synchronization validates it.
4.0.3 - 2026-09-03
Added
- Deliver normalized Oxlint diagnostics through managed post-edit hooks for Codex, Claude, Cursor, and OpenCode.
- Preview candidate lint impact before scaffold updates and document bounded Ultracite operator commands.
Fixed
- Apply safe file-scoped formatting and Oxlint fixes with bounded retry protection while preserving nearest lint configuration and workspace-owned typed lint settings.
- Remove the managed post-edit hook's unused
unlinkSyncimport so the distributed lint-feedback path passes repository-wide verification.
4.0.2 - 2026-08-27
Added
- Distribute the verb-first
architect-pipelineskill for repository-aware, provider-neutral CI/CD design and implementation, including infrastructure deployment, release, artifact promotion, and retry theory. - Keep Pulumi-specific APIs, resources, state, registry, and authentication details in the Pulumi skills while routing explicit CI/CD security audits to
audit-cicd-security.
4.0.1 - 2026-08-27
Added
- Distribute
make-tsuitefor automated software test-portfolio audits and authorized test-only changes across languages, frameworks, and toolchains.
4.0.0 - 2026-08-26
Changed
- Replace the implicit Finder flow with human-invoked business, functional, and technical entrypoints backed by one Fog lifecycle engine.
- Make
write-backlogthe provider-writing boundary for the Area → Initiative → Epic → Story → Task topology, lateral Fog provenance, contextualV*milestones, and native Task blockers. - Require
hi ensureto migrate legacy Linear project URLs to the configured root Initiative destination before backlog writes continue.
Fixed
- Reject Technical Finder Task graphs when a Task milestone differs from its parent Story milestone.
- Reject incomplete Business hierarchy, Functional Story membership/provenance, and full reachable Technical blocker-graph readback before Finder returns, including milestone order and cross-Epic blockers.
- Keep Effect prepare-hook ownership and its scaffold receipt at the root package instead of duplicating workspace entries.
3.3.6 - 2026-08-25
Fixed
- Align the Context Plan, subagent manifest specification, and rendered subagent manifest in one scaffold pass while preserving project-authored roles and role guidance.
- Restore the exact compatible Effect lint tuple:
@effect/tsgo@0.36.5,oxlint@1.78.0, andoxlint-tsgolint@7.0.2001. - Keep historical provider-readback recovery declarations valid after the destination CLI version advances.
3.3.5 - 2026-08-25
Changed
- Let Effect lint scaffolds install the latest
@effect/tsgoandoxlint-tsgolintwhen missing, while preserving project-owned Oxlint and Effect tooling versions instead of enforcing the former exact compatibility tuple.
3.3.4 - 2026-08-24
Added
- Scaffold
$handbackand graph-based skill authoring in default skill packs.
Fixed
- Preserve non-secret executable, operation, exit code, working directory, and artifact/input/output path context when protected release publication fails with an opaque
ENOENT.
Changed
Generate one centralized autonomy pointer across shared, root, and scoped agent guidance and preserve it through scaffold handoffs.
Bound direct autoreview and delivery/review/debugging expansion behind durable human steering.
Prepare
baseline/stable/2026.08.18-requirements-grill-technical-groundingfor CLI>=3.2.2 <4from canonicalwearedevpunks/skills@eb1026c0355759c8addfb91856beb6bd5eae94f9, requiring code grounding before the first technical frontier, evidence/constraint/code-consequence questions, and closure only after applicable technical dimensions are resolved.Prepare
baseline/stable/2026.08.18-write-backlog-milestone-membershipfor CLI>=3.2.2 <4from canonicalwearedevpunks/skills@713367ca0846785fa347adcd3e3224b7455e36df, allowing stories to share their containing overview milestone without using milestones to order story relations.Prepare
baseline/stable/2026.08.17-requirements-grill-live-show-mefor CLI>=3.2.2 <4from canonicalwearedevpunks/skills@6a633da2b18537a53e51172e37c2c7fc2a3b8c5b, using$show-methroughout active requirements grilling and interleaving code-grounded technical questions wherever a branch benefits.Prepare
baseline/stable/2026.08.17-high-signal-testsfor CLI>=3.2.1 <4from canonicalwearedevpunks/skills@ebc83ccfc317c9dbae1f6348a7827cba2783a02d, strengthening high-signal TDD culling and the scoped source-first skill-release flow.Sync canonical
wearedevpunks/skills@354d08e26897ddbf28eb667498fdf3363ca2081cfrommainand rename the domain-document convention fromCONTEXT.md/CONTEXT-MAP.mdtoGLOSSARY.md/GLOSSARY-MAP.md, includingGLOSSARY-FORMAT.md.
Added
- Add the concise
rule-authoringskill for scaffold and update handoffs that create or reconcile project-owned.agents/rules.
Changed
- Delegate
hi operatorto Skills CLI's interactive or automatic harness selection, removing the Harness agent prompt,HI_OPERATOR_AGENT, and explicit--agent; migration now requires verified replacement identity and full reported legacy-agent coverage before unscoped removal. - Close applicable technical architecture during requirements grilling so specs own accepted topology, boundaries, dependencies, and seams while planning derives execution work.
- Use
$show-methroughout active requirements grilling for difficult questions and key turning points, with code-grounded technical depth placed wherever the branch benefits and the final persisted-state presentation retained. - Make Full Delivery continue through its authorized phases and review cycles without confirmation; HITL pauses now require an explicit user request.
3.3.3 - 2026-08-24
Fixed
- Provision Bun in the production release job before publication so release scripts can invoke the CLI toolchain.
Changed
- Select baseline releases only from non-empty
BASELINE_CHANGELOG.mdnotes and CLI releases only from matching non-emptyCHANGELOG.mdversion notes; when both changelogs qualify, publish both, while retaining strict candidate proof and artifact readback.
3.3.2 - 2026-08-20
Added
- Add the Effect pack's type-aware
@effect/tsgorecommended Oxlint preset and version-coupled patch setup.
Fixed
- Keep exact Effect lint package.json catalog references stable through
hi checkandhi update; fail closed without mutation for incompatible project-owned catalog values or whenpnpm-workspace.yamlowns the catalog; preserve simple existingprepare&&chains, including quoted&&, while deduplicating and receipt-managing the patch command, and reject ambiguous complex shell syntax.
Changed
- Require semantic release classification and reviewed, non-empty product changelogs before release-bearing work completes; publish the pending
improve-mobile-frontendbaseline matching baseline authority. - Delegate
hi operatortarget selection to Skills CLI while preserving verified legacy-agent migration coverage.
3.3.1 - 2026-08-20
Changed
- Require semantic release classification and reviewed, non-empty product changelogs before release-bearing work completes; publish the pending
improve-mobile-frontendbaseline with matching baseline authority. - Delegate
hi operatortarget selection to Skills CLI while preserving verified legacy-agent migration coverage.
3.3.0 - 2026-08-19
Added
- Add
animate-expoto the Expo pack and addanimateplusreview-animationsto the frontend pack, retaining Emil Kowalski's upstream MIT license and attribution with the distributed skills.
Changed
- Scaffold React workspaces with Oxlint's React Compiler-powered correctness rules so compiler validation failures surface during normal lint runs.
baseline/stable/2026.08.19-animation-react-compiler-lint - 2026-08-19
Added
- Distribute
animate-expowith the Expo pack andanimateplusreview-animationswith the frontend pack, including their upstream MIT license and attribution.
Changed
- Enable Oxlint's React Compiler-powered correctness rules for the React pack.
3.2.2 - 2026-08-17
Fixed
- Detect SQLAlchemy and Alembic from Python dependency files so scaffold pack selection includes the
sqlalchemypack without manual selection. - Preserve project-authored wiki
AGENTS.mdcontent during semantic scaffold reconciliation while continuing to enforce itsCLAUDE.mdmirror and managed wiki files.
3.2.1 - 2026-08-13
Changed
- Sync canonical
wearedevpunks/skills@1739a7a75ab975ca867da8603766c39d4befc25bfrommain. - Enforce plan-wide architecture convergence in
create-planandimplement-spec:$show-me-authored ownership, dependency, responsibility, architecture-wave, public-seam, and migration-ledger contracts; task-level ownership fields; cumulative per-wave conformance; and final zero-drift closure with an empty migration ledger.
Fixed
- Reuse the cache-backed, partitioned pull-request verification as release evidence instead of replaying the CLI test suite during publication.
- Stage TypeScript Anti-Slop adoption for existing Harness workspaces while keeping strict defaults for new consumers and excluding vendored plugin sources.
- Keep baseline archive tests event-loop responsive and avoid duplicate full Turbo graph probes in repository contract tests.
- Centralize the requirements grilling completion transition before the derived
$show-mepresentation.
3.2.0 - 2026-08-13
Added
- Add
domain-modelingto requirements workflows so downstream skills consume the canonical routed glossary and route terminology changes back throughrequirements-grill. - Add
show-mevisual explanations across planning and delivery workflows while preserving their authoritative text and evidence. - Add
verify-behaviorto implementation and debugging workflows with retained user-visible behavior evidence.
Changed
- Package the selected TypeScript Anti-Slop lint assets in the scaffold baseline and remove the retired Stack skill.
baseline/stable/2026.08.13-cli-3.2.0-quality-workflows - 2026-08-13
Added
- Distribute the
show-me,verify-behavior, anddomain-modelingquality workflows, including durable glossary state and behavior evidence.
Changed
- Package and verify TypeScript Anti-Slop lint assets across scaffold workspaces and remove the retired Stack skill.
3.1.13 - 2026-08-12
Added
- Classify reusable verification as portable, capability-keyed, or fresh; add staged and exact-tree local gates plus complete release-candidate evidence.
- Classify exact candidates as
none,baseline,npm, ormixedand reconcile reviewed first-parent releases in retry-safe order through protected production authority.
Changed
- Require complete bundled-baseline and npm inventories, semantic product intent, matching reviewed changelog authority, and exact pull-request evidence before release eligibility.
- Activate exact-tree
mainconvergence with 45-minute release and test ceilings, GitHubProductionanchor/control-plane/baseline configuration, npm Trusted Publishing OIDC, and no Vercel release credentials. Mixed impact publishes the commit-derived baseline before reviewed npm 3.1.13. - Compact generated docs/workspace prompt specs around repository invariants and exact-trigger installed-skill pointers while preserving Source Guide, mirror, and validation seams.
- Recognize
CODEX_CIandCODEX_SANDBOXas Codex operator hosts while preserving explicitHI_OPERATOR_AGENTprecedence, unknown-host handling, and one exact Skills CLI target. - Package the review handoff contract from
wearedevpunks/skills@684f98dff76ac94ad3db2eb1f74230cb9910e1ad, retained bysync/review-contract-handoff-consistency-684f98dff76a: non-empty review scopes, exact commit-tree report retention, finding-owned derived routes, and capture-first mixed debt routing with durable post-capture repair continuation. Primary debt capture persistsdocs_ingestorcloseout, and the router resumes that state before artifact inference. Dynamic and bundled subagent manifests and planning/setup consumers now enforce final docs/workspace## Skillstables headedSkill | Exact triggerthrough installedSKILL.mdauthority; root guidance stays table-free.
3.1.12 - 2026-08-11
Added
- Add the detected
sqlalchemypack and bundledsqlalchemy-schema-designskill to the CLI catalog and scaffold baseline.
baseline/stable/2026.08.11-sqlalchemy-schema-design - 2026-08-11
Added
- Add the detected SQLAlchemy framework pack with stateless schema and Alembic migration guidance.
baseline/stable/2026.08.11-review-phase-durable-workflow-graph - 2026-08-11
Changed
- Sync the exact canonical
wearedevpunks/skills@423c6d59b285a423262ee8983475de4e13864746. - Refactor
review-phaseinto a bootstrap, deterministic router, and four flat gates for preparation, one all-lens review, report retention, and routing return. - Add one mode-specific runtime handoff contract so delivery and standalone reviews cold-resume from current evidence without transcript continuity.
- Preserve explicit operator invocation, immutable retained reports, delivery-owned repair, and the three-review/three-repair budget with no review 4.
baseline/stable/2026.08.11-frontend-domain-structure - 2026-08-11
Changed
- Strengthen
frontend-domain-structurewith domain-worthiness and sibling-scan checks, recursive public acyclic boundaries, a narrow discouraged peer-feature exception, and cohesive React responsibility/test-seam splitting guidance fromwearedevpunks/skills@211ce3b6bf93319732f261da2f66b419c0262a52.
3.1.11 - 2026-08-11
Changed
- Make generated docs and workspace
AGENTS.mdauthoring structure-first, progressively disclose conditional repository conventions through exact relative references, and describe every selected scoped skill in a completeSkill | What / whentable. - Make
create-planselect the exact matchingWhat / whenrows across every touched scope and load each selected skill's completeSKILL.mdbefore planning. - Always generate the
opensrc/README.mdSource Guide index and direct third-party library investigations through it.
baseline/stable/2026.08.11-scoped-agent-guidance - 2026-08-11
Changed
- Distribute the structure-first scoped-prompt contract, progressive-disclosure rules, complete scoped skill tables, exact cross-scope
create-planskill loading, unconditional Source Guide index, and source-firsthi-clicontinuation guidance for CLI 3.1.11.
baseline/stable/2026.08.11-review-phase-graph-rework - 2026-08-11
Changed
- Sync the exact canonical
wearedevpunks/skills@baf97d7a3f55c838f9007af8387aeafddda09d91. - Make
review-phaseexplicit-only and run standards and skill adherence, architecture, simplification, and specification lenses against one frozen review snapshot. - Require an immutable retained wiki review report before a pass is valid.
- Bound delivery review to three review and three repair passes, with no fourth review after repair three.
- Carry implementation skill guidance from plans into worker briefs and record skill application evidence in implementation notes for adversarial review.
baseline/stable/2026.08.11-python-backend-structure - 2026-08-11
Changed
- Make canonical
python-backend-structurecompoundbackend-domain-structurewith a strict acyclic, no-sibling import topology while retainingpython-project-structureas a deprecated compatibility alias.
3.1.10 - 2026-08-10
Fixed
- Normalize baseline-declared skill aliases in preserved manifest skill arrays before project-local validation while retaining compatibility assets for older CLIs and keeping aliases out of the canonical runtime skill catalog.
baseline/stable/2026.08.10-cli-3.1.9-effect-service-design - 2026-08-10
Fixed
- Restore the cataloged
effect-service-designskill asset to the packaged baseline for CLI 3.1.9 and compatible CLI 3.1.8 consumers.
baseline/stable/2026.08.10-cli-3.1.9 - 2026-08-10
Fixed
- Publish the stable scaffold baseline for CLI 3.1.9 while retaining compatibility with CLI 3.1.8.
3.1.9 - 2026-08-10
Fixed
- Use the production API custom domain for bundled control-plane requests.
baseline/stable/2026.08.10-oxfmt-baseline-assets - 2026-08-10
Changed
- Sync the exact canonical
wearedevpunks/skills@0b2b0358c3db260171815b2cc51f021963249771, including the priordocs-onboardingcorrection to runhi initfrom the repository root and repo-wide Oxfmt normalization of distributed baseline assets. - Format the complete staged baseline archive inventory with the repository-pinned Oxfmt before hashing or archiving, and fail the build or publication when formatting fails.
baseline/stable/2026.08.10-projection-receipt-output-integrity-r2 - 2026-08-10
Fixed
- Pair the projection-receipt integrity baseline with CLI 3.1.8 after incomplete manual package staging in 3.1.6 and 3.1.7.
3.1.8 - 2026-08-10
Fixed
- Publish the complete isolated package containing both the nested managed
.gitignoreand bundled baseline manifest/archive.
baseline/stable/2026.08.10-projection-receipt-output-integrity-r1 - 2026-08-10
Fixed
- Publish the same projection-receipt integrity baseline for CLI 3.1.7 after the 3.1.6 direct-package release omitted a required nested managed
.gitignore.
3.1.7 - 2026-08-10
Fixed
- Restore the nested NestJS managed
.gitignoreby publishing through the isolated npm pack-control path.
baseline/stable/2026.08.10-projection-receipt-output-integrity - 2026-08-10
Changed
- Bind generated projection receipts to the canonical semantic fingerprint of the effective available-hook set and rendered Claude, Codex, Cursor, and OpenCode output maps.
- Retain exact receipt-entry compare-and-swap publication while making effective project-authored subagent output changes observable to downstream integrity checks.
- Keep expected provider capability limitations and preserved project-owned prompts as neutral receipt provenance with healthy receipt/manifest status and empty scaffold degradations; reserve
partialfor genuine actionable nonfatal anomalies and fail actual projection/application faults.
baseline/stable/2026.08.07-wait-what-edit-hooks - 2026-08-07
Changed
- Sync shared skills from
wearedevpunks/skills@2379a59c84431357321b75ea9dfab12ae8ada0b0. - Preserve Finder-derived fog evidence parents and validate the complete configured intake taxonomy before provider mutation (#102).
- Apply
$wait-whatlanguage to boundedparallel-researchsynthesis,SPEC.md,PLAN.md, andIMPLEMENTATION-NOTES.mdproduction (#103). - Restore automatic scoped format and lint hooks after file edits across Claude, Codex, Cursor, and OpenCode projections.
3.1.6 - 2026-08-07
Changed
- Make
hi updateapply verified baseline changes by default while retaining--writeand--yesas compatibility aliases; keep--checkread-only. - Preserve project-owned, intentionally customizable, and current
ProjectGeneratedfiles silently, and let the generated projection producer refresh only its exact scaffold-receipt entry with individually atomic, compare-and-swap publication that is safe to retry. - Record
renderedOutputSha256in projection receipts so effective project-authored renderer changes advance semantic evidence without treating context-plan formatting as drift. - Expand installed-consumer validation to six evidence rows covering semantic JSON, managed archive/replacement, silent project-owned exceptions, exact receipt-entry refresh, provider-output restoration, and corruption failure.
Fixed
- Report actual edits to fixed
ScaffoldManagedfiles during check, then archive them under.devpunks/replaced-scaffold/<fingerprint>/<path>and replace them from the verified baseline during a normal update. Baseline-identical files with stale receipt evidence now refresh without an archive. - Reject contradictory update flags before baseline, operation, or filesystem effects, and keep unavailable baseline authority distinct from scaffold drift.
baseline/stable/2026.08.07-scaffold-integrity-convergence - 2026-08-07
Changed
- Align the stable scaffold with default-applying update semantics, read-only
--check, recoverable replacement for fixed scaffold-managed edits, and silent preservation for project-owned exceptions. - Make the generated projection producer advance only its exact receipt evidence through individually atomic, compare-and-swap publication; cross-file crash atomicity remains outside the contract.
Fixed
- Converge baseline-identical stale receipt evidence without an archive and keep unavailable authority separate from managed-content drift.
3.1.5 - 2026-08-06
Changed
- Make scaffold ownership decisions consistent across check, update, stale detection, and receipt persistence, including project-generated managed output.
- Use the actual worktree filesystem case semantics when excluding managed and bootstrap paths from automatic formatting and linting.
Fixed
- Preserve valid project-generated output while reporting missing, stale, mismatched, receipt-only, and semantically overlapping ownership cases accurately.
- Fail closed when the filesystem case probe is indeterminate and reject drive-qualified Windows receipt paths, including drive-relative forms such as
C:foo.
baseline/stable/2026.08.06-managed-format-hook-case-semantics - 2026-08-06
Fixed
- Protect alternate-cased managed and bootstrap paths according to the actual worktree filesystem case semantics, including default case-insensitive macOS and Windows filesystems while preserving genuinely case-sensitive roots.
- Fail closed without invoking a formatter or linter when the worktree case-semantics probe is indeterminate.
- Reject drive-qualified Windows receipt paths, including drive-relative forms such as
C:foo.
baseline/stable/2026.08.06-managed-format-hook - 2026-08-06
Fixed
- Make the distributed automatic format hook skip every path in a valid scaffold managed-files receipt, preserving authoritative scaffold bytes beyond the former partial path list.
- Fail closed without invoking a formatter or linter when the receipt is missing, unreadable, malformed, or invalid.
Changed
- Keep
.devpunks/scaffold-manifest.jsonas the sole bootstrap exclusion, preserve existing unmanaged-file behavior, and leave manually invoked repository-wide formatting outside Harness.
baseline/stable/2026.08.06-parallel-research-wiki - 2026-08-06
Changed
- Sync
parallel-researchfromwearedevpunks/skills@b7f939c626d7fd929261726f21949198c5df2aefand make every run retain one consolidated report at<wiki-root>/content/docs/project/research/<slug>-research-report.mdwith immutable commit proof.
baseline/stable/2026.08.06-requirements-grill-wait-what - 2026-08-06
Changed
- Sync
requirements-grillfromwearedevpunks/skills@7d8a73cd74fbbf32f3134cf132afa4f958a30382and require$wait-whatfor every grilling question and recommendation before durable round completion.
baseline/stable/2026.08.05-wayfinder-lifecycle - 2026-08-05
Changed
- Update
prototypeto the upstream v1.2.0 logic and UI artifact formats, including one-file HTML logic demos with guided walkthroughs and route-level UI variants selected by?variant=. - Replace
writing-great-skillswithwriting-for-agentsin the default docs pack. - Add the default
miscpack withwait-what, scoped to shared.agentsguidance rather than application workspaces. - Activate
writing-for-agentsin scaffold/init/update handoffs and generated subagent authoring instructions whenever the continuation edits agent-facing documents.
baseline/stable/2026.08.05-effect-service-design - 2026-08-05
Added
- Add
effect-service-design, imported fromdmmulroy/skills@8603380821fee6a77c82639f364ce8fe4f5a92be, with its exact MITLICENSE(Copyright (c) 2026 Matt Pocock).
Changed
- Sync shared skills from
wearedevpunks/skills@5d8f709b8a0ca8ef05c9b0e0cb45ed07ca25d59eand publish the baseline for CLI>=3.0.0 <4. - Route Effect service qualification, dependency-preserving
layerWithoutDependencies, ready productionlayer, test substitutes, and service audits througheffect-service-design; preserve action-owned orchestration and integration-owned contracts ineffect-backend-structure. - Include the previously published parallel-delivery managed skill state, making delivery and
implement-specworker-wave-only and removing the superseded sequential branch.
3.1.3 - 2026-08-05
Fixed
- Keep generated baseline JSON formatter-stable and hash context/projection evidence canonically so
hi scaffoldfollowed byhi checkdoes not report formatter-only drift (issue #97).
3.1.4 - 2026-08-06
Added
- Add explicit, fingerprint-bound project-generated managed-file ownership so
hi checkcan recognize current repository mirrors without broad path or file-kind exemptions.
Changed
- Make check, apply, stale detection, and receipt persistence consume one ownership decision; preserve current project-generated output while keeping missing, stale, mismatched, receipt-only, and semantic-overlap cases strict.
- Replace
writing-great-skillswithwriting-for-agentsin the default docs pack and activate it in CLI continuations that author prompt specs, handoffs, root/scopedAGENTS.md, or subagent templates/instructions. - Add the default
miscpack withwait-what, scoped to shared.agentsguidance rather than application workspaces. - Adopt the upstream prototype v1.2.0 formats: one-file interactive HTML for logic/state questions and URL-switchable route variants for UI questions.
Fixed
- Keep missing project-generated output as truthful planned drift without running its producer, inventing output, or reporting a write when repository state remains unchanged.
- Resolve the Effect v4 source guide against
Effect-TS/effectmain by default while retaining project-pinned package resolution for exact installed-version behavior. - Load baseline publisher settings from
apps/cli/.envwithout overriding exported values and accept Vercel's public control-plane URL as the fallback publisher origin.
3.1.2 - 2026-08-03
Fixed
- Treat recursive wiki
content/docs/**/meta.jsonroute metadata as project-authored when checking and writing updates, while continuing to validate and repair source projections. - Restore regression coverage for stale wiki source projections so update checks report and write projected pages without overwriting project-owned route metadata.
- Generate workspace Oxlint configs with Effect's authoritative
OxlintConfigtype so the generated configs remain typecheckable alongside their pack-owned rules and plugins.
3.1.1 - 2026-08-03
Added
- Add durable stable-baseline promotion after verified GitHub asset publication, with idempotent retry reconciliation and post-commit control-plane confirmation.
- Add
bun run baseline:rollbackfor audited rollback to an explicit stable release with optimistic revision checks.
Changed
- Make baseline archives reproducible from the release commit timestamp, normalized permissions, deterministic ordering, and timestamp-free gzip metadata.
- Reuse matching baseline release assets and upload only missing assets while rejecting malformed, duplicate, or mismatched existing assets.
- Increase the default remote baseline resolution timeout from 1.5 seconds to 5 seconds to tolerate control-plane latency.
- Prompt for the Skills CLI agent name when
hi operatorcannot detect one in an interactive terminal, while JSON, plain, redirected, and other noninteractive runs remain fail-closed and requireHI_OPERATOR_AGENT. - Treat operator-skill identity mismatches from older Skills CLI inventory as repairable outdated copies, guiding operators from
hi operator statustohi operator updatewhile preserving the selected agent within one application operation.
Fixed
- Make
hi operator installandhi operator updatesafely replace outdated copies and verify the exact authoritative identity after installation. - Make
hi operator migrateverify the replacement before removing the legacy skill, retaining the legacy copy when replacement verification fails.
3.1.1-beta.1 - 2026-08-03
Changed
- Treat operator-skill identity mismatches from older Skills CLI inventory as repairable outdated copies instead of terminal verification failures.
- Guide operators from
hi operator statustohi operator updatewhen the effective copy is outdated, while preserving the selected agent within one application operation. - Make
hi operator installandhi operator updatesafely replace outdated copies and verify the authoritative identity after installation. - Make
hi operator migrateverify the replacement before removing the legacy skill, retaining the legacy copy when replacement verification fails.
3.1.1-beta.0 - 2026-08-03
Published as @punks/cli@3.1.1-beta.0; the v3.1.1-beta.0 tag and GitHub release remain pending.
Added
- Add durable stable-baseline promotion after GitHub asset verification, with idempotent retry reconciliation and post-commit control-plane confirmation.
- Add
bun run baseline:rollbackfor audited rollback to an explicit stable release with optimistic revision checks.
Changed
- Make baseline archives reproducible from the release commit timestamp, normalized permissions, deterministic ordering, and timestamp-free gzip metadata.
- Increase the default remote baseline resolution timeout from 1.5 seconds to 5 seconds to tolerate control-plane latency.
- Reuse matching baseline release assets and upload only missing assets while rejecting malformed, duplicate, or mismatched existing assets.
Fixed
- Prompt for the Skills CLI agent name when
hi operatorcannot detect one in an interactive terminal, while JSON, plain, redirected, and other noninteractive runs remain fail-closed and requireHI_OPERATOR_AGENT.
3.1.0 - 2026-07-30
Published as @punks/cli@3.1.0 with tag v3.1.0.
Added
- Add a default
securitypack (audit-cicd-security,security-best-practices) with source-pinned security guidance.
Changed
- Sync security skills from
wearedevpunks/skills@844890de0f89f4e66cc078147143e61456ff0bec. - Add provider-agnostic CI security auditing with progressive references for GitHub Actions, GitLab CI/CD, Jenkins, Azure Pipelines, CircleCI, Bitbucket Pipelines, Buildkite, Tekton, and Argo Workflows in
audit-cicd-security. - Confirm Critical/High local remediation in
audit-cicd-securityonly with explicit user approval; keep the audit read-only by default. - Attribute
security-best-practicesas vendored fromopenai/skills(Apache-2.0), synced throughwearedevpunks/skills@844890de0f89f4e66cc078147143e61456ff0bec.
Fixed
- Align security pack defaults and source pin references with baseline-scoped security documentation and required skill manifests.
baseline/stable/2026.07.30-security-pack - 2026-07-30
Added
- Make
securitya mandatory default pack (audit-cicd-security,security-best-practices) in scaffold and discovery outputs.
Changed
- Sync
audit-cicd-securityandsecurity-best-practicesfromwearedevpunks/skills@844890de0f89f4e66cc078147143e61456ff0bec. - Keep
audit-cicd-securityread-only by default and gate Critical/High local remediation behind explicit user approval. - Vendor
security-best-practicesfromopenai/skills(Apache-2.0), then sync via the shared-source commit844890de0f89f4e66cc078147143e61456ff0bec.
3.0.1 - 2026-07-30
Added
- Add installed-tarball regression coverage that proves repeated plain
hi checkruns fetch fresh remote baseline metadata and archives.
Changed
- Resolve every non-bundled
hi checkagainst fresh remote baseline authority, defaulting an omitted selector to the configured baseline orstable.
Fixed
- Report unavailable remote baseline authority without claiming scaffold drift, while preserving fatal integrity failures for bundled baselines.
3.0.0 - 2026-07-28
Published as @punks/cli@3.0.0 with tag v3.0.0 after the stable M7-M9 cutover.
Stable M7-M9 release completed in #88.
Added
- Add repeatable packaged-consumer validation for fresh initialization, drift detection, conflict-preserving updates, and installed
hi/hintcommand behavior. - Add verified operator-skill lifecycle and baseline-authority flows with explicit provenance, compatibility, and fallback contracts.
Changed
- Rebuild CLI orchestration around feature-owned Effect v4 domains, typed failures, explicit configuration boundaries, and a unified command metadata authority.
- Converge settings, scaffold state, context projection, and non-destructive reconciliation behind deterministic plans shared by
hi init,hi check, andhi update. - Make
hi tools ensurerefresh every auto-managed required tool through a baseline-owned explicit latest target while keeping manual platform tools validation-only and preserving scaffold/update minimum-version repair behavior. - Sync and pin the
hi-clioperator skill 1.1.0 towearedevpunks/skills@09a6f3c, aligned with v3 rootinit,scaffold, andcheck, settings-onlyensure, and latest-refreshtools ensure.
Fixed
- Keep JSON and redirected command output machine-safe and noninteractive while preserving cancellation, rollback ownership, and fail-closed baseline behavior.
- Harden Linux validation, generated wiki/scaffold determinism, cleanup ownership, and provider interruption handling across the M7-M9 release gates.
- Materialize the frozen
hi-clirevision in an exact detached temporary Git checkout before invoking Skills CLI 1.5.20 with a copied local source, while retaining post-write manifest verification before legacy removal and cleaning temporary state on every exit.
baseline/stable/2026.07.23-effect-v4-source-authority - 2026-07-23
Fixed
- Sync Effect skills from
wearedevpunks/skills@45d731db6f5f3e715ecbd2db195b7f68d13dcff9. - Declare
effect-backend-structurecompatible with Effect v4 and replace its Effect v3 service guidance with the canonical$effectandContext.Servicecontract (#75). - Make
opensrc path Effect-TS/effectand the Effect repository main branch the primary Effect v4 source authority; retain project-pinned package lookup for exact installed-version behavior.
baseline/stable/2026.07.21-create-spec-vocabulary-removal - 2026-07-21
Changed
- Sync
create-specfromwearedevpunks/skills@52866e7and end the skill at completed-spec review.
baseline/stable/2026.07.17-grilling-primitive-contract - 2026-07-17
Changed
- Sync shared skills from
wearedevpunks/skills@e2039dd. - Make
grillingthe sole generic question and closure contract while wrappers retain domain pressure tests, durable artifact state, stricter local formats, output mappings, and downstream transitions.
baseline/stable/2026.07.17-batched-grilling-frontier - 2026-07-17
Changed
- Sync shared skills from
wearedevpunks/skills@9fb9184. - Replace sequential grilling with Matt Pocock's MIT-licensed
batch-grill-mefrontier primitive pinned at9603c1cc8118d08bc1b3bf34cf714f62178dea3b, preserving the stable localgrillingid and wrapper composition. - Persist stable question ids, prerequisites, current-frontier membership, answered and unanswered state, canonical routed grill paths, and explicit empty-frontier shared-understanding confirmation before backlog, plan, spec, or prototype work.
Fixed
- Advertise explicit-only
design-phaseas a global workflow entrypoint while excluding it from scoped primary-skill generation.
baseline/stable/2026.07.16-effect-v4-consolidation - 2026-07-16
Changed
- Make
effectthe sole canonical Effect v4 patterns and authoring skill, with Effect-Atom and observability guidance disclosed as focused references. - Remove the redundant
effect-authoringskill after syncingwearedevpunks/skills@65b8833; retain the distinct backend-structure and recoverable-action workflows.
baseline/stable/2026.07.16-effect-v4-patterns - 2026-07-16
Changed
- Replace the overlapping
effect-best-practicesskill with the pinned, MIT-licensed Effect v4effectskill fromwearedevpunks/skills@d18cfc7. - Route the detected Effect pack and bundled subagent guidance through the canonical
effectskill while retaining distinct authoring, backend-structure, and recoverable-action workflows.
baseline/stable/2026.07.13-create-spec-title-frontmatter - 2026-07-13
Fixed
- Sync the stable baseline's
create-specskill fromwearedevpunks/skills@40b83fbso routed Fumadocs specs include non-emptytitlefrontmatter and enforce it in the quality bar (#72).
2.6.2 - 2026-07-13
Pending npm publish: @punks/cli@2.6.2.
Fixed
- Sync the
create-spectemplate so scaffolded specs emit the required non-emptytitlefrontmatter when written directly into routed Fumadocs trees (#72).
2.6.1 - 2026-07-13
Pending npm publish: @punks/cli@2.6.1.
Added
- Add
hi operator status,hi operator install,hi operator update, andhi operator migratefor explicit operator-skill management.
Changed
- Deprecate
hi skills renamewhile retaining it as an alias forhi operator migrate.
Fixed
- Route change-sensitive
hi updatepost-command handling correctly and refresh only targetedhi-cliinstallations without invoking Skills CLI update-all behavior.
baseline/stable/2026.07.13-runtime-product-validation - 2026-07-13
Changed
- Release a baseline-only shared-skill update that makes real supported-runtime evidence an explicit planning and implementation completion contract (#70).
2.6.0 - 2026-07-13
Pending npm publish: @punks/cli@2.6.0.
Added
- Add
hi ensureto reconfigure backlog, asset, repository, and backlog project URL settings without rerunning scaffold initialization; scaffoldedwrite-backlognow requires that configured destination before provider work.
Fixed
- Stop generated
.codex/config.tomlfiles from setting legacyagents.max_threads, which conflicts with Codexmulti_agent_v2; retainagents.max_depthand generated hooks (#71).
baseline/stable/2026.07.13-codex-multi-agent-config - 2026-07-13
Fixed
- Release the stable scaffold baseline for Codex
multi_agent_v2compatibility by omitting legacyagents.max_threadsfrom generated.codex/config.tomlwhile retainingagents.max_depthand Harness hooks.
2.5.4 - 2026-07-10
Pending npm publish: @punks/cli@2.5.4.
Fixed
- Preserve an existing project-owned
apps/wiki/scripts/sync-content.mjsduringhi updateandhi check, while still reporting and recreating the script when missing (#69).
baseline/stable/2026.07.10-manual-delivery-phase - 2026-07-10
Fixed
- Make
delivery-phaseexplicit-only alongside the six external/manual lifecycle phases, leaving onlyreview-phase,debugging-phase, anddocs-ingest-phasemodel-invocable as delivery's internal delegates. - Sync shared skills from
wearedevpunks/skills@7fde033; design and debt resolution now present a bounded delivery brief and stop for explicit user$delivery-phaseinvocation.
baseline/stable/2026.07.10-external-phase-invocation - 2026-07-10
Fixed
- Limit explicit-only invocation to the six external/manual lifecycle entrypoints:
bug-discovery-phase,bug-resolution-phase,design-phase,finder-phase,requirements-phase, andresolve-debt-phase. - Sync the correction from
wearedevpunks/skills@a2648cc, restoring model invocation fordelivery-phase,review-phase,debugging-phase, anddocs-ingest-phaseso routed workflows can delegate to them.
baseline/stable/2026.07.10-explicit-phase-invocation - 2026-07-10
Changed
- Release the stable scaffold baseline with lifecycle
*-phaseskills as explicit user entrypoints. - Sync shared skills from
wearedevpunks/skills@5779f6e, setting Claudedisable-model-invocation: trueand Codexpolicy.allow_implicit_invocation: falseon all lifecycle phase skills.
2.5.3 - 2026-07-09
Pending npm publish: @punks/cli@2.5.3.
Fixed
- Fix generated Effect Oxlint config typing so scaffolded
oxlint.config.tsfiles typecheck with narrowed custom rule tuples. - Keep local lint config dependencies owned by the CLI package so isolated installs can resolve Oxlint and Ultracite config imports.
baseline/stable/2026.07.09-backend-domain-guardrails - 2026-07-09
Changed
- Release the stable scaffold baseline for expanded backend domain structure guardrails.
- Sync shared skills from
wearedevpunks/skills@062f811, adding layer classification, dependency direction, dependency-injection boundaries, public module/package API rules, and validation prompts tobackend-domain-structure.
baseline/stable/2026.07.09-goalify-activation-contract - 2026-07-09
Changed
- Release the stable scaffold baseline for the lean
goalifyactivation contract. - Sync shared skills from
wearedevpunks/skills@cc4556d, keepinggoalifyfocused on generating and activating one goal immediately. - Remove fallback and gotcha guidance from the bundled
goalifyskill.
2.5.2 - 2026-07-08
Pending npm publish: @punks/cli@2.5.2.
Added
- Add
hi skills renameto install/update thehi-clioperator skill from the public skills repo and remove legacy global/projectdp-cliinstalls oncehi-cliis present.
Fixed
- Allow Linear to be selected as
assetProviderSlugindependently from a GitHubrepositoryManager, so Linear backlog image assets can be uploaded and embedded while required repository tools still come from GitHub. - Skip scaffold-owned hooks, scripts, skills, and hook mirrors in the neutral format hook so
hi update --check --jsonandhi check --jsonstay clean after managed scaffold updates.
Changed
- Rename bundled operator skill guidance from
$dp-clito$hi-cliacross the CLI command guide, scaffold prompts, install docs, runbooks, and wiki command docs.
baseline/stable/2026.07.09-pulumi-skills-pack - 2026-07-09
Added
- Release the stable scaffold baseline for the Pulumi detected pack, including the shared-skills sync from
wearedevpunks/skills@9653bf9. - Select the
pulumipack when@pulumi/pulumior@pulumi/*packages are present, distributing Pulumi overview, best practices, ComponentResource, Automation API, ESC, provider-upgrade, and package-usage skills.
baseline/stable/2026.07.09-linear-assets-managed-format - 2026-07-09
Fixed
- Release the stable scaffold baseline for Linear asset-provider settings and managed format-hook drift prevention.
- Keep required tools sourced from the repository manager while allowing Linear backlog assets through
assetProviderSlug. - Skip scaffold-owned hooks, scripts, skills, and hook mirrors in the neutral format hook so managed scaffold assets stay hash-clean after update/check.
baseline/stable/2026.07.08-hi-cli-skill-rename - 2026-07-08
Changed
- Release the scaffold baseline for the
hi-clioperator skill rename, including the shared-skills sync fromwearedevpunks/skills@45072f4, updated install guidance, and bundledhi-cliskill path. - Add the
hi skills renamemigration command to the stable CLI baseline so olddp-cliinstalls can be removed afterhi-cliis installed.
2.5.1 - 2026-07-08
Pending npm publish: @punks/cli@2.5.1.
Fixed
- Restore the gradient ASCII
HARNESS INTELLIGENCEtitle block for root and scaffold command output.
2.5.0 - 2026-07-08
Pending npm publish: @punks/cli@2.5.0.
Changed
- Rebrand the installed executable and user-facing command tree from
dp/punks/devpunkstohi, withhintas an alias, while keeping the npm package identity at@punks/cli. - Update root/scaffold command guides, startup checks, scaffold handoffs, hooks, and bundled
dp-cliguidance to usehicommand names and theHARNESS INTELLIGENCEtitle.
baseline/stable/2026.07.08-hi-command-rebrand - 2026-07-08
Changed
- Release the scaffold baseline for the
hi/hintcommand rename, updated$dp-cliguidance, hooks, handoffs, generated prompts, andHARNESS INTELLIGENCEtitle.
2.4.3 - 2026-07-07
Pending npm publish: @punks/cli@2.4.3.
Fixed
- Clarify the
dp scaffold initoperator prompt so it describes the generated default-pack managed scaffold surface and separates the four onboarding entrypoint skills from the full scaffolded skill set.
2.4.2 - 2026-07-07
Pending npm publish: @punks/cli@2.4.2.
Fixed
- Make
dp scaffold initdistribute the accepted default-pack scaffold surface, including the scaffold manifest, handoff prompt, default-pack skills, hooks, scripts, and subagent manifest, while preserving init's backlog, repository manager, and wiki selections.
2.4.1 - 2026-07-06
Pending npm publish: @punks/cli@2.4.1.
Fixed
- Let
dp update --yesanddp update --writeaccept newly resolved default or detected packs, persist them in the scaffold manifest, and refresh their managed assets without a separate scaffold setup run. - Keep generated wiki sync scripts formatter-idempotent so
dp updatedoes not leave persistent managed drift onapps/wiki/scripts/sync-content.mjs.
2.4.0 - 2026-07-06
Pending npm publish: @punks/cli@2.4.0.
Added
- Bundle
finder-phaseandwayfinderas scaffolded planning skills. - Add
finder-phaseto global phase routing so loose oversized work reaches the decision frontier before ordinary requirements, research, prototype, design, or delivery phases.
Changed
- Include the
finder-phaseandwayfinderplanning-pack catalog wiring in the npm CLI. - Expand bundled
write-backlogguidance around first-class backlog kinds:fog,grilling,research,prototype,epic, andstory. - Ship Finder Phase wiki docs, scaffold routing docs, and the latest shared-skills sync from
wearedevpunks/skills@583be0c.
baseline/stable/2026.07.06-finder-phase-wayfinder - 2026-07-06
Changed
- Release scaffold baseline
finder-phaseandwayfinderrouting for oversized foggy work before bounded requirements, research, prototype, design, or delivery phases. - Add
finder-phaseandwayfinderto the planning pack, root workflow routing, catalog tests, and generated prompt guidance. - Expand
write-backlogaround first-class backlog kinds:fog,grilling,research,prototype,epic, andstory. - Include the Finder Phase public entrypoint docs and the latest
goalifyactivation clarification.
baseline/stable/2026.06.30-review-skill-phase - 2026-06-30
Changed
- Release scaffold baseline upstream
reviewskill and routereview-phasestartup through Standards versus Spec review axes. - Include
reviewin the default research/review skill pack.
This changelog tracks @punks/cli npm executable release notes from the 2.x line onward.
Published entries include the npm version and matching git tag or version commit when available.
Baseline-only releases use baseline/stable/* GitHub releases and should still get an entry
here; BASELINE_CHANGELOG.md can carry extra baseline-specific detail.
2.3.3 - 2026-07-03
Pending npm publish: @punks/cli@2.3.3.
Added
- Bundle the Expo scaffold pack and shared Expo skills in the npm CLI.
Changed
- Include runtime changelog metadata for
baseline/stable/2026.07.03-expo-skills-pack.
2.3.2 - 2026-06-30
Pending npm publish: @punks/cli@2.3.2.
Added
- Add
dp checkread-only session-start drift gate for CLI version, scaffold baseline, managed files, pack selection, changelog summaries, and subagent-owned remediation guidance.
Changed
- Bundle runtime changelog metadata into packaged CLI commands so update and baseline drift can be explained without local repository files.
- Clarify
dp scaffold init,dp scaffold setup,dp update, and$dp-clipre-existing skill reconciliation: commands do not detect skill overlaps, preserve blind evidence snapshots, and hand exact-name overlap handling to the follow-up agent.
baseline/stable/2026.06.30-scaffold-skill-reconciliation - 2026-06-30
Changed
- Release scaffold baseline
dp checksession-start drift guidance and agent-owned pre-existing skill reconciliation guidance. - Sync updated shared
dp-cliguidance fromwearedevpunks/skills@a889421.
2.3.1 - 2026-06-30
Pending npm publish: @punks/cli@2.3.1.
Fixed
- Preserve existing Claude settings, including
permissions.allow, when scaffold setup injects managed hooks. - Keep Windows scaffold setup completing when symlink creation is blocked by using directory links or managed mirror copies.
- Cover issue #58 Windows scaffold mirror and Claude settings preservation regressions.
2.3.0 - 2026-06-29
Pending npm publish: @punks/cli@2.3.0.
Fixed
Remove
dp updatepatch previews and JSON patch bodies, keeping drift output compact path/kind/status summaries.Avoid non-docs scaffold manifests staging wiki alignment drift, and skip generated wiki output directories during docs-owned update alignment.
Add regression coverage for CLI scaffold/update drift behavior, database-backed backoffice access, API mutation routes, project activity monotonicity, and OpenAPI route contracts.
Default stable baseline resolution no longer reports false drift from stale control-plane metadata or corrupt cached baselines; it validates cached and materialized baseline assets, then falls back to canonical GitHub stable.
Scaffold prompt target detection discovers authored scoped
AGENTS.mdfiles outside package manifests, so repo-specific surfaces likeinfra/opentelemetryget prompt specs, subagents, and native agent mirrors without Harness-specific placeholder boundaries.
2.2.8 - 2026-06-29
Pending npm publish: @punks/cli@2.2.8.
Fixed
- Publish the npm CLI bin as a portable Node script with bundled scaffold assets instead of a host-native Bun executable, so
dp,punks, anddevpunksrun on Windows package-manager shims. - Strengthen release validation to run the built bin through Node and through temp npm-installed
dp,punks, anddevpunkscommands before publishing. - Stop treating intentionally selected optional scaffold packs as actionable
dp update --checkpack drift. - Report and rewrite stale generated handoff/system-prompt references from
.devpunks/required-tools.jsonto.devpunks/settings.jsonwhile preserving local handoff text. - Preserve scaffold-time tailored
.agents/scripts/sync-subagents.mjsfiles during update checks and writes. - Keep bundled fallback subagent manifest defaults repo-shape neutral instead of shipping Harness-specific app/package paths.
baseline/stable/2026.06.29-frontend-imagegen-skills - 2026-06-29
Changed
- Release a scaffold baseline with the frontend image-generation skills split into dedicated web and mobile surfaces and included in the frontend skill pack.
baseline/stable/2026.06.29-lean-goalify-activation - 2026-06-29
Changed
- Release a scaffold baseline with
goalifyrewritten as a very lean goal compiler that activates the goal immediately and uses disclosed examples only when structure is needed.
baseline/stable/2026.06.29-clawpatch-provider-defaults - 2026-06-29
Changed
- Release a scaffold baseline where ClawPatch bug-discovery and bug-resolution phases inherit the current agent/launcher provider by default.
- Update operator docs to remove the obsolete provider-cost warning and treat provider/model flags as explicit overrides only.
2.2.7 - 2026-06-27
Pending npm publish: @punks/cli@2.2.7.
Fixed
- Accept legacy
.devpunks/required-tools.jsonmanaged-file entries while keeping.devpunks/settings.jsonas the required-tool source of truth for new scaffold output. - Stop reporting project-authored prompt specs, handoff text, scaffold manifest hashes, subagent guidance, and generated agent prompt mirrors as
dp update --checkdrift.
baseline/stable/2026.06.27-high-signal-tdd-tests - 2026-06-27
Changed
- Release a scaffold baseline with high-signal TDD guidance for durable behavior through public seams, contract-safe assertions, and invariant-based regression tests.
baseline/stable/2026.06.27-design-phase-prototype-routing - 2026-06-27
Changed
- Release a scaffold baseline with the research-pack
$prototypeskill, design-phase prototype routing, and docs-ingested operator guidance for prototype/image artifact handoff.
baseline/stable/2026.06.25-required-tools-settings - 2026-06-25
Changed
- Release a scaffold baseline that consolidates all required tools in
.devpunks/settings.jsonand removes the separate required-tools manifest.
baseline/stable/2026.06.25-design-phase-asset-evidence - 2026-06-25
Changed
- Release a scaffold baseline with route-gated
design-phase, durable repo asset management, provider settings authority, and backlog/PR visual evidence handoff guidance.
2.2.6 - 2026-06-23
Pending npm publish: @punks/cli@2.2.6.
Changed
- Sync the simplified
goalifyskill contract fromwearedevpunks/skills@dd95edd.
Fixed
- Verify refreshed stable baseline metadata against the latest published stable release so stale control-plane metadata cannot hide a newer stable scaffold baseline.
baseline/stable/2026.06.23-stable-refresh-goalify - 2026-06-23
Changed
- Release a scaffold baseline with the simplified
goalifyskill contract and issue 49 stable-refresh documentation.
2.2.5 - 2026-06-23
Pending npm publish: @punks/cli@2.2.5.
Changed
- Generate root prompt surfaces from scaffold specs so root prompts stay aligned with the managed scaffold copy pipeline.
Fixed
- Preserve repo-specific subagent guidance when syncing generated subagent scripts.
- Ignore wiki-only roots during pack detection so documentation surfaces do not cause false app/package pack matches.
baseline/stable/2026.06.23-scaffold-detection-guidance - 2026-06-23
Changed
- Release a scaffold baseline with repo-specific subagent guidance preservation, scaffold-spec-backed root prompt generation, and wiki-root pack detection fixes.
2.2.4 - 2026-06-23
Pending npm publish: @punks/cli@2.2.4.
Fixed
- Detect Bun global installs through the resolved
dp/punksbin symlink, including packaged executable argv shapes, sodp upgradecan reinstall a fresh CLI instead of asking for manual reinstall. - Run generated scaffold maintenance scripts with
nodeby default, withDP_SCRIPT_RUNTIMEas an override, so packaged CLI installs do not recurse throughprocess.execPathorBun.execPathwhile syncing subagents. - Restore public stable baseline downloads through the Harness control plane, with token or
ghGitHub access retained only as maintainer fallback.
baseline/stable/2026.06.23-scoped-review-phases - 2026-06-23
Changed
- Release a scaffold baseline with lean scoped review and ClawPatch phase skills.
2.2.2 - 2026-06-23
Pending npm publish: @punks/cli@2.2.2.
Fixed
- Run generated scaffold maintenance scripts through the host runtime in packaged CLI installs so
dp updateanddp update --check --jsondo not re-enter the CLI entrypoint while syncing subagents.
2.2.1 - 2026-06-23
Pending npm publish: @punks/cli@2.2.1.
Changed
- Bump the CLI executable package after app-surfaced wiki root handling and release-validation fixes.
- Document that all releases, including baseline-only releases, must update
CHANGELOG.md.
Fixed
- Preserve
app/wikifor app-surfaced single repos during scaffold init and update without reintroducing competingwiki/orapps/wiki/roots. - Preserve monorepo
apps/wiki, standalonewiki, marker-backed wiki roots, route-onlyapp/wiki, stale root cleanup cases, and recordedrepoShapeModeoverrides during update alignment. - Add missing routed wiki frontmatter to the CLI tool-validation implementation notes so the wiki production build succeeds.
2.2.0 - 2026-06-23
Pending npm publish: @punks/cli@2.2.0.
Changed
- Add
dp tools ensure/punks tools ensureto check and repair required external Harness tools from.devpunks/required-tools.jsontool IDs or the default toolchain, using trusted stable/bundled baseline install contracts. - Add
dp -v/punks -vas a short alias for--version. - Build the npm CLI as a Bun standalone executable so installed
dp,punks, anddevpunkscommands no longer require Bun at runtime. - Embed bundled scaffold data and skills into the executable while preserving the existing runtime asset copy paths through a temp extraction cache.
- Document that Bun is required for repository builds and publishing, not for npm-installed CLI usage.
Fixed
- Avoid forcing
agent-browser installto download Chrome when a supported Chrome, Chromium, or Brave executable is already present. - Let already-present required tools validate without Bun, pnpm, or npm on PATH; a package manager is required only when repair is needed.
- Make the built-dist assertion execute the compiled CLI directly and fail if the package regresses to a Bun shebang.
- Ad-hoc sign macOS standalone builds so local release validation can execute the compiled binary.
2.1.11 - 2026-06-16
Pending npm publish: @punks/cli@2.1.11.
Changed
- Sync the generic handoff skill into the CLI catalog.
- Refine docs-ingest routing and bundled context-engineering docs.
Fixed
- Resolve
dp updatereport issues. - Fix scaffold report output and update drift handling.
2.1.10 - 2026-06-12
Pending npm publish: @punks/cli@2.1.10.
Changed
- Bump the CLI executable after adding scaffolded session-start update checks.
- Scaffold a Harness update-check hook that runs
dp update --checkfor Codex, Claude Code, Cursor, and OpenCode session starts.
Fixed
- Align the built CLI publish assertion with the current
dp report --helpdescription.
2.1.9 - 2026-05-28
Pending npm publish: @punks/cli@2.1.9. Version commit: 79d8b25.
Changed
- Add TanStack Start wiki scaffold support with runtime dependencies, package scripts, check wiring, and OG image scaffolding.
- Tighten scaffolded spec and implementation workflow guidance around lifecycle docs, backlog sync, and subagent usage.
- Expand report and wiki debt closeout documentation for GitHub-backed reports and TanStack wiki scaffolds.
Fixed
- Gate report GitHub writes and AI metadata behind authenticated/token-backed flows.
- Deduplicate GitHub-backed backoffice reports and tolerate invalid AI verdict output.
- Fix wiki scaffold update drift for frontmatter,
.gitignore, package merges, generated scripts, and TanStack-only route replacements.
2.1.8 - 2026-05-27
Matched npm publish: @punks/cli@2.1.8. Matched git tag: v2.1.8.
Changed
- Generate scaffolded Oxlint configs from Ultracite core/framework presets with explicit pack-owned overlays.
- Update scaffolded review/autoreview skill content and release bookkeeping for categorized GitHub notes.
Fixed
- Fix issue 16 by activating generated OpenCode formatter hooks and routing Python edits through Ruff.
- Route ESLint-only lint overlay packages through Oxlint
jsPluginsinstead of native Oxlint plugins.
2.1.7 - 2026-05-27
Matched npm publish: @punks/cli@2.1.7. Version commit: 98b61a0. No matching local v2.1.7
tag was found during changelog update.
Changed
- Improve the scaffold init backlog provider picker flow.
Fixed
- Fix project usage detail rendering in the internal backoffice surface shipped with the release branch.
2.1.6 - 2026-05-27
Matched npm publish: @punks/cli@2.1.6. Matched git tag: v2.1.6.
Changed
- Add Mermaid rendering support to scaffolded wiki apps.
- Align project domain source indexes under
content/docs/project/domains. - Harden scaffold/update handling for existing wiki routes, metadata drift, and CLI release scaffolding.
Fixed
- Close the issue 15 update drift where
dp updateexpected the oldapps/wiki/domainssync contract.
2.1.5 - 2026-05-26
Matched npm publish: @punks/cli@2.1.5. Version commit: 71460ce. No matching local v2.1.5
tag was found during changelog backfill.
Changed
- Bump the CLI executable after requirements wiki scaffold-path updates.
2.1.4 - 2026-05-26
Matched npm publish: @punks/cli@2.1.4. Version commit: 1c5fc88. No matching local v2.1.4
tag was found during changelog backfill.
Changed
- Update CLI version and installation docs for the
dp-clioperator skill flow.
2.1.3 - 2026-05-26
Matched npm publish: @punks/cli@2.1.3. Version commit: 2de8b01. No matching local v2.1.3
tag was found during changelog backfill.
Changed
- Sync bundled skills and bump the CLI executable package.
2.1.2 - 2026-05-26
Matched npm publish: @punks/cli@2.1.2. Version commit: 40e2aa8. No matching local v2.1.2
tag was found during changelog backfill.
Changed
- Bump the CLI package after release-test stabilization work.
2.1.1 - 2026-05-25
Matched npm publish: @punks/cli@2.1.1. Matched git tag: v2.1.1.
Changed
- Bump the CLI executable after the 2.1.0 baseline release line.
2.1.0 - 2026-05-25
Matched npm publish: @punks/cli@2.1.0. Version commit: e6a0941. No matching local v2.1.0
tag was found during changelog backfill.
Changed
- Release the 2.1.0 CLI baseline with updated backoffice auth, report, and stage-skill guidance.
2.0.1 - 2026-05-22
Matched npm publish: @punks/cli@2.0.1. Version commit: 35be311. No matching local v2.0.1
tag was found during changelog backfill.
Changed
- Bump the CLI executable after device-auth and backoffice follow-up work.
2.0.0 - 2026-05-21
Matched npm publish: @punks/cli@2.0.0. Matched git tag: v2.0.0.
Changed
- Promote the Harness Intelligence monorepo-era CLI to the stable 2.0.0 line.
- Include the private wiki, routed docs, control-plane baseline path, and updated scaffold content from the 2.0.0 delivery branch.
2.0.0-beta.4 - 2026-05-14
Matched npm publish: @punks/cli@2.0.0-beta.4. Matched git tag: v2.0.0-beta.4.
Changed
- Bump the beta CLI after private wiki and Harness Intelligence rename work.
2.0.0-beta.3 - 2026-05-13
Matched npm publish: @punks/cli@2.0.0-beta.3. Matched git tag: v2.0.0-beta.3.
Fixed
- Publish the sanitized CLI npm package so workspace and catalog specifiers do not leak into the install artifact.
2.0.0-beta.2 - 2026-05-13
Matched npm publish: @punks/cli@2.0.0-beta.2. Version commit: 2dc13cd. No matching local
v2.0.0-beta.2 tag was found during changelog backfill.
Changed
- Bump the beta package version during the 2.0.0 beta release sequence.
2.0.0-beta.1 - 2026-05-13
Matched npm publish: @punks/cli@2.0.0-beta.1. Version commit: 2d0d1f1. No matching local
v2.0.0-beta.1 tag was found during changelog backfill.
Changed
- Bump the beta package version after adding the beta release task.
2.0.0-beta.0 - 2026-05-13
Matched npm publish: @punks/cli@2.0.0-beta.0. Matched git tag: v2.0.0-beta.0.
Added
- Introduce the 2.0.0 beta line for Harness phase-skill distribution and monorepo-era scaffold output.