Harness Intelligence Wiki
Changelog

CLI Changelog

@punks/cli npm executable release notes

Unreleased

6.1.0 - 2026-09-28

Added

  • Give Codex native TypeScript 7 semantic reads with the TypeScript Pack. hi update installs the pinned Typegraph MCP runtime once per machine under ${XDG_DATA_HOME:-~/.local/share}/hi-tools/typegraph-mcp/<version> (exact lock, npm ci --ignore-scripts, reused through a receipt, never pruned), finds each git-listed tsconfig.json Compiler Project (wiki and solution-only configs excluded, nested ones reported as ambiguous, settings typescript.compilerProjects overrides), load-probes it, and keeps one read-only Codex server per passing project in a fenced # BEGIN hi typegraph block of .codex/config.toml. Each server exposes five reads. The block is restored on every update and removed when the Pack is deselected; every byte outside it is kept, and a user-defined table with the same name wins. Needs Node 22.18 or newer and npm.
  • hi check reports semanticReads when the TypeScript Pack is installed: whether the runtime is installed, how many Codex entries are registered, and each Compiler Project's load probe, as three separate lines. Probes share a 30 s budget and never change status.

Fixed

  • hi tools ensure runs install and validation commands with the caller's PATH, so tools already installed are found (#239).
  • hi operator accepts the running CLI major again: the operator skill compatibility range follows the CLI version instead of stopping at 6.0.0 (#240).
  • Workspace prompt specs list only the default Packs meant for workspaces (docs, misc, and verification stay in the shared, root, and docs specs), and list the frontend and backend Packs only for workspaces that show their signals (#241).
  • Repository detection skips git-ignored paths, so ignored build output or stray files no longer propose Packs or workspaces; the docs prompt spec is written only when a docs/ directory exists (#242).

6.0.1 - 2026-09-28

Fixed

  • Never follow a symlinked parent outside the repository during migration or merge-target validation; such paths are skipped (migrated-skipped) or refused before any write.
  • Replace an installer-owned Copied or Built file when a later Baseline turns the path into a symlink (a locally edited file still waits for --yes).
  • Keep the Drift Check working offline right after hi init/hi update by caching the applied Baseline catalog.
  • Run allowed post-install commands without a Unix shell, so they work on Windows.
  • Deduplicate a harness skill whose id .agents/skills already holds, keeping a differing copy as [DEPRECATED] <id> (<harness>), so the shared skills link can be created.
  • Record installer-added devDependencies when a first install is interrupted and retried; never claim a dependency the last commit already declared.
  • hi diff resolves the latest Baseline from the current settings.packs.
  • An empty backlog project URL answer in hi init clears a stored URL.
  • Never move the Registry latest pointer back when an older same-day Baseline is republished.
  • Wrap seeded oxlint.local.ts arrays at the formatter's print width.
  • Honor settings commitGateChecks.repository again: the Commit Gate runs the repository lint or format command for staged repository-level paths outside every Software Scope (the wiki stays excluded), as CLI 5.x did.

6.0.0 - 2026-09-28

Changed

  • Install and update the harness from the public Registry (https://api.harness-intelligence.devpunks.com/r). The CLI sends no credential, carries no bundled Baseline, and refuses a Baseline whose CLI range excludes it.
  • Replace the lifecycle commands with hi init, hi update [--yes], hi diff, and hi check. hi scaffold and hi ensure are removed; hi init detects the repository once, proposes Packs and Software Scopes, and writes .devpunks/settings.json.
  • Keep two local state files: .devpunks/settings.json (intent, including packs) and .devpunks/installed.json (the Installed Record: Baseline version, Recorded Shape, item-to-path map, failed links). No content hashes are stored.
  • Apply Copied Artifacts by overwrite, re-render Built Artifacts, and write Authored Artifacts only when absent. hi update --yes overwrites a Copied Artifact with a local edit and an upstream change and reports its path.
  • Build subagent files for Claude, Codex, Cursor, and OpenCode inside the CLI (Harness Adapters); sync-subagents.mjs and the harness-projection scripts are no longer installed.
  • Keep pre-existing skills as Project Skills; when a Baseline skill takes the same id, rename the Project Skill to [DEPRECATED] <name>.
  • hi check compares the installed Baseline with the latest one only and returns status (current, update-available, unavailable, not-installed); hi diff runs the three-way Drift Check.
  • Migrate manifest-based repositories in the first hi update.

Fixed

  • Classify lint findings correctly for any oxlint output size and pass Commit Gate file lists without exceeding operating-system argument limits (#232).
  • Never block edits in a worktree without an Installed Record (#231).

5.2.2 - 2026-09-24

Changed

  • Leave wiki package setup, routes, content, and metadata to the owning project; hi init, hi scaffold, and hi update no longer create or align a wiki.
  • Check an existing wiki against the project structure during the shared hi-cli post-command handoff.

Fixed

  • Recognize the repository's Turbo check route and read-only format commands when adopting managed lint, and preserve disjoint inherited Oxlint policy.
  • Accept the scoped root static gate while retaining the full managed lint dispatcher for operator runs and linting changed files in CI.
  • Find Node when the managed lint runner validates tools from a scoped runtime.
  • Keep edited-file lint available when an unrelated repository symlink points outside the root, while rejecting external required lint inputs.
  • Preserve update preparation evidence when publication readiness fails after a lint preview.
  • Plan the edited-file hook when managed quality setup will add Oxfmt during the same update.

5.2.1 - 2026-09-23

Fixed

  • Make managed lint scope selection explicit and route every eligible file to its most-specific selected owner across package scripts, CI, Commit Gate, and edited-file checks (#224).
  • Preserve inherited Oxlint policy, supported custom commands, warning thresholds, and referenced lint catalogs through adoption and repeated updates (#224).
  • Skip managed checks for excluded-only changes while preserving independent Python/Ruff behavior; keep wiki paths and unselected package boundaries outside managed software lint (#224).
  • Validate dependent policy, config, routes, and tool inputs before activation, and report selection, drift, findings, and unresolved migration failures with actionable context (#224).

5.2.0 - 2026-09-22

Added

  • Add explicit file, owner, and repository execution scopes for Commit Gate checks, including repository lint and format authority in project settings (#222).

Fixed

  • Validate the complete update candidate, including live guidance targets, staged replacements, and removals, before publishing managed changes (#222).
  • Limit update installation and lint work to affected consumers, including optional dependency consumers; support generated backoffice Vitest overrides and preserve actionable installation and configuration errors (#222).
  • Keep unrelated archives and migration payloads out of generation freshness while retaining validation of explicitly referenced inputs (#222).
  • Cover root changes, deletions, and cross-owner renames in Commit Gate checks; preserve command output, deduplicate identical checks, and enforce zero warnings for generated Oxlint commands (#222).

Changed

  • Retire the standalone handback skill and its generated prompt pointers in favor of handback guidance owned by lifecycle phases (#222).
  • Use Bun 1.4.0 for repository tooling and two-vCPU Linux CI workers, removing automated macOS jobs and provisioning browsers only for selected consumers (#223).
  • Reuse verification results across unrelated documentation changes while tracking consumed inputs and runtime capabilities; remove duplicate task execution (#223).
  • Reduce routine test setup and repeated assertions, use minimal real release recovery histories, and retain full historical recovery replay and updater benchmarking as on-demand diagnostics (#223).

5.1.1 - 2026-09-17

Added

  • Make hi update derive managed artifacts from a shared manifest-driven plan, validate in an isolated candidate, and reuse validation and prepared-install results only for matching relevant inputs (#215).
  • Report update lifecycle progress while preserving a single final JSON stdout document, with local cache clearing and optional signed remote-cache transport outcomes surfaced explicitly (#215).

Fixed

  • Fail closed before dependent update work when validation inputs are incomplete, uncontained through canonical path aliases, or use uncontrolled executable configuration; retain precise subprocess failure facts (#215).
  • Keep update planned and completed operations truthful across no-change, recovery, cache-reuse, and managed-drift outcomes (#215).

5.1.0 - 2026-09-15

Added

  • Distribute verify-behavior, create-verification-skill, and update-verification-skill together in the default verification pack while preserving project-owned verifier reference bytes (#207).

Fixed

  • Preserve repository-owned wiki starters during scaffold/check/update and honor populated directories and flat routes without false missing-seed findings (#203).
  • Resolve nested Oxlint transition rules through registered workspace plugin aliases and retain JSON lint policy in both planning and materialization (#203).
  • Regenerate managed handoffs from current authoring proofs so completed post-command work does not leave stale pending actions (#203).
  • Resolve Commit Gate contract roots from the current checkout or linked worktree, and report actionable working-directory and process-launch errors instead of an empty exit-1 failure (#204).
  • Restore Effect internal-module topology and repository-boundary guidance while keeping service qualification and application policy in effect-service-design (#205).
  • Limit automatic React Doctor and TDD activation to their intended task boundaries, and resolve React Doctor changed scans from the checked-out branch's configured origin upstream with an explicit base. Keep verify-behavior available to explicit orchestration without top-level automatic activation (#206).

5.0.1 - 2026-09-10

Fixed

  • Resolve the latest canonical wearedevpunks/skills main once per operator command, freeze its immutable commit across scopes and readbacks, and install or update only exact verified hi-cli content without falling back to the compiled skill.

Changed

  • Clarify that scaffold and update install the shared verify-behavior skill while preserving project-owned verification references; implement-spec remains responsible for Uncovered Surface and Uncovered Behavior work.

5.0.0 - 2026-09-10

Added

  • Add explicit scaffold artifact obligations, baseline-delivered shared-agent guidance, planned Commit Gate setup, and recovery for interrupted adoption and coupled publication.
  • Add dependency-ready delivery task gates, active write-scope ownership, project-owned executable verification, a frozen review epoch, and bounded repair validation.

Changed

  • Preserve planned workspace topology during isolated scaffold validation, refresh only affected guidance scopes, and retain project-owned verifier references across scaffold and update flows.
  • Use compact pointer-based worker context and durable handoff evidence while keeping V4.3 acceptance at 170 satisfied criteria and four excepted_not_passed benchmark criteria (AC-044–AC-047).

Fixed

  • Inherit the process environment when generated JavaScript files run without an explicit environment, while preserving explicitly supplied environments.
  • Materialize Commit Gate setup from the selected nested package root in repositories without a root package.json.
  • Persist independently completed reconciliation receipt entries when Commit Gate setup is deferred.
  • Leave user-owned Lefthook configuration unpinned when Commit Gate is disabled and no managed gate command exists.
  • Reject wrapped formatter commands that enable write mode, including short -w flags, from read-only Commit Gate format checks.

4.0.4 - 2026-09-03

Fixed

  • Canonicalize generated sync-subagents entrypoint paths so the intended guard runs, and stage completed prior projection-receipt evidence before candidate synchronization validates it.

4.0.3 - 2026-09-03

Added

  • Deliver normalized Oxlint diagnostics through managed post-edit hooks for Codex, Claude, Cursor, and OpenCode.
  • Preview candidate lint impact before scaffold updates and document bounded Ultracite operator commands.

Fixed

  • Apply safe file-scoped formatting and Oxlint fixes with bounded retry protection while preserving nearest lint configuration and workspace-owned typed lint settings.
  • Remove the managed post-edit hook's unused unlinkSync import so the distributed lint-feedback path passes repository-wide verification.

4.0.2 - 2026-08-27

Added

  • Distribute the verb-first architect-pipeline skill for repository-aware, provider-neutral CI/CD design and implementation, including infrastructure deployment, release, artifact promotion, and retry theory.
  • Keep Pulumi-specific APIs, resources, state, registry, and authentication details in the Pulumi skills while routing explicit CI/CD security audits to audit-cicd-security.

4.0.1 - 2026-08-27

Added

  • Distribute make-tsuite for automated software test-portfolio audits and authorized test-only changes across languages, frameworks, and toolchains.

4.0.0 - 2026-08-26

Changed

  • Replace the implicit Finder flow with human-invoked business, functional, and technical entrypoints backed by one Fog lifecycle engine.
  • Make write-backlog the provider-writing boundary for the Area → Initiative → Epic → Story → Task topology, lateral Fog provenance, contextual V* milestones, and native Task blockers.
  • Require hi ensure to migrate legacy Linear project URLs to the configured root Initiative destination before backlog writes continue.

Fixed

  • Reject Technical Finder Task graphs when a Task milestone differs from its parent Story milestone.
  • Reject incomplete Business hierarchy, Functional Story membership/provenance, and full reachable Technical blocker-graph readback before Finder returns, including milestone order and cross-Epic blockers.
  • Keep Effect prepare-hook ownership and its scaffold receipt at the root package instead of duplicating workspace entries.

3.3.6 - 2026-08-25

Fixed

  • Align the Context Plan, subagent manifest specification, and rendered subagent manifest in one scaffold pass while preserving project-authored roles and role guidance.
  • Restore the exact compatible Effect lint tuple: @effect/tsgo@0.36.5, oxlint@1.78.0, and oxlint-tsgolint@7.0.2001.
  • Keep historical provider-readback recovery declarations valid after the destination CLI version advances.

3.3.5 - 2026-08-25

Changed

  • Let Effect lint scaffolds install the latest @effect/tsgo and oxlint-tsgolint when missing, while preserving project-owned Oxlint and Effect tooling versions instead of enforcing the former exact compatibility tuple.

3.3.4 - 2026-08-24

Added

  • Scaffold $handback and graph-based skill authoring in default skill packs.

Fixed

  • Preserve non-secret executable, operation, exit code, working directory, and artifact/input/output path context when protected release publication fails with an opaque ENOENT.

Changed

  • Generate one centralized autonomy pointer across shared, root, and scoped agent guidance and preserve it through scaffold handoffs.

  • Bound direct autoreview and delivery/review/debugging expansion behind durable human steering.

  • Prepare baseline/stable/2026.08.18-requirements-grill-technical-grounding for CLI >=3.2.2 <4 from canonical wearedevpunks/skills@eb1026c0355759c8addfb91856beb6bd5eae94f9, requiring code grounding before the first technical frontier, evidence/constraint/code-consequence questions, and closure only after applicable technical dimensions are resolved.

  • Prepare baseline/stable/2026.08.18-write-backlog-milestone-membership for CLI >=3.2.2 <4 from canonical wearedevpunks/skills@713367ca0846785fa347adcd3e3224b7455e36df, allowing stories to share their containing overview milestone without using milestones to order story relations.

  • Prepare baseline/stable/2026.08.17-requirements-grill-live-show-me for CLI >=3.2.2 <4 from canonical wearedevpunks/skills@6a633da2b18537a53e51172e37c2c7fc2a3b8c5b, using $show-me throughout active requirements grilling and interleaving code-grounded technical questions wherever a branch benefits.

  • Prepare baseline/stable/2026.08.17-high-signal-tests for CLI >=3.2.1 <4 from canonical wearedevpunks/skills@ebc83ccfc317c9dbae1f6348a7827cba2783a02d, strengthening high-signal TDD culling and the scoped source-first skill-release flow.

  • Sync canonical wearedevpunks/skills@354d08e26897ddbf28eb667498fdf3363ca2081c from main and rename the domain-document convention from CONTEXT.md/CONTEXT-MAP.md to GLOSSARY.md/GLOSSARY-MAP.md, including GLOSSARY-FORMAT.md.

Added

  • Add the concise rule-authoring skill for scaffold and update handoffs that create or reconcile project-owned .agents/rules.

Changed

  • Delegate hi operator to Skills CLI's interactive or automatic harness selection, removing the Harness agent prompt, HI_OPERATOR_AGENT, and explicit --agent; migration now requires verified replacement identity and full reported legacy-agent coverage before unscoped removal.
  • Close applicable technical architecture during requirements grilling so specs own accepted topology, boundaries, dependencies, and seams while planning derives execution work.
  • Use $show-me throughout active requirements grilling for difficult questions and key turning points, with code-grounded technical depth placed wherever the branch benefits and the final persisted-state presentation retained.
  • Make Full Delivery continue through its authorized phases and review cycles without confirmation; HITL pauses now require an explicit user request.

3.3.3 - 2026-08-24

Fixed

  • Provision Bun in the production release job before publication so release scripts can invoke the CLI toolchain.

Changed

  • Select baseline releases only from non-empty BASELINE_CHANGELOG.md notes and CLI releases only from matching non-empty CHANGELOG.md version notes; when both changelogs qualify, publish both, while retaining strict candidate proof and artifact readback.

3.3.2 - 2026-08-20

Added

  • Add the Effect pack's type-aware @effect/tsgo recommended Oxlint preset and version-coupled patch setup.

Fixed

  • Keep exact Effect lint package.json catalog references stable through hi check and hi update; fail closed without mutation for incompatible project-owned catalog values or when pnpm-workspace.yaml owns the catalog; preserve simple existing prepare && chains, including quoted &&, while deduplicating and receipt-managing the patch command, and reject ambiguous complex shell syntax.

Changed

  • Require semantic release classification and reviewed, non-empty product changelogs before release-bearing work completes; publish the pending improve-mobile-frontend baseline matching baseline authority.
  • Delegate hi operator target selection to Skills CLI while preserving verified legacy-agent migration coverage.

3.3.1 - 2026-08-20

Changed

  • Require semantic release classification and reviewed, non-empty product changelogs before release-bearing work completes; publish the pending improve-mobile-frontend baseline with matching baseline authority.
  • Delegate hi operator target selection to Skills CLI while preserving verified legacy-agent migration coverage.

3.3.0 - 2026-08-19

Added

  • Add animate-expo to the Expo pack and add animate plus review-animations to the frontend pack, retaining Emil Kowalski's upstream MIT license and attribution with the distributed skills.

Changed

  • Scaffold React workspaces with Oxlint's React Compiler-powered correctness rules so compiler validation failures surface during normal lint runs.

baseline/stable/2026.08.19-animation-react-compiler-lint - 2026-08-19

Added

  • Distribute animate-expo with the Expo pack and animate plus review-animations with the frontend pack, including their upstream MIT license and attribution.

Changed

  • Enable Oxlint's React Compiler-powered correctness rules for the React pack.

3.2.2 - 2026-08-17

Fixed

  • Detect SQLAlchemy and Alembic from Python dependency files so scaffold pack selection includes the sqlalchemy pack without manual selection.
  • Preserve project-authored wiki AGENTS.md content during semantic scaffold reconciliation while continuing to enforce its CLAUDE.md mirror and managed wiki files.

3.2.1 - 2026-08-13

Changed

  • Sync canonical wearedevpunks/skills@1739a7a75ab975ca867da8603766c39d4befc25b from main.
  • Enforce plan-wide architecture convergence in create-plan and implement-spec: $show-me-authored ownership, dependency, responsibility, architecture-wave, public-seam, and migration-ledger contracts; task-level ownership fields; cumulative per-wave conformance; and final zero-drift closure with an empty migration ledger.

Fixed

  • Reuse the cache-backed, partitioned pull-request verification as release evidence instead of replaying the CLI test suite during publication.
  • Stage TypeScript Anti-Slop adoption for existing Harness workspaces while keeping strict defaults for new consumers and excluding vendored plugin sources.
  • Keep baseline archive tests event-loop responsive and avoid duplicate full Turbo graph probes in repository contract tests.
  • Centralize the requirements grilling completion transition before the derived $show-me presentation.

3.2.0 - 2026-08-13

Added

  • Add domain-modeling to requirements workflows so downstream skills consume the canonical routed glossary and route terminology changes back through requirements-grill.
  • Add show-me visual explanations across planning and delivery workflows while preserving their authoritative text and evidence.
  • Add verify-behavior to implementation and debugging workflows with retained user-visible behavior evidence.

Changed

  • Package the selected TypeScript Anti-Slop lint assets in the scaffold baseline and remove the retired Stack skill.

baseline/stable/2026.08.13-cli-3.2.0-quality-workflows - 2026-08-13

Added

  • Distribute the show-me, verify-behavior, and domain-modeling quality workflows, including durable glossary state and behavior evidence.

Changed

  • Package and verify TypeScript Anti-Slop lint assets across scaffold workspaces and remove the retired Stack skill.

3.1.13 - 2026-08-12

Added

  • Classify reusable verification as portable, capability-keyed, or fresh; add staged and exact-tree local gates plus complete release-candidate evidence.
  • Classify exact candidates as none, baseline, npm, or mixed and reconcile reviewed first-parent releases in retry-safe order through protected production authority.

Changed

  • Require complete bundled-baseline and npm inventories, semantic product intent, matching reviewed changelog authority, and exact pull-request evidence before release eligibility.
  • Activate exact-tree main convergence with 45-minute release and test ceilings, GitHub Production anchor/control-plane/baseline configuration, npm Trusted Publishing OIDC, and no Vercel release credentials. Mixed impact publishes the commit-derived baseline before reviewed npm 3.1.13.
  • Compact generated docs/workspace prompt specs around repository invariants and exact-trigger installed-skill pointers while preserving Source Guide, mirror, and validation seams.
  • Recognize CODEX_CI and CODEX_SANDBOX as Codex operator hosts while preserving explicit HI_OPERATOR_AGENT precedence, unknown-host handling, and one exact Skills CLI target.
  • Package the review handoff contract from wearedevpunks/skills@684f98dff76ac94ad3db2eb1f74230cb9910e1ad, retained by sync/review-contract-handoff-consistency-684f98dff76a: non-empty review scopes, exact commit-tree report retention, finding-owned derived routes, and capture-first mixed debt routing with durable post-capture repair continuation. Primary debt capture persists docs_ingest or closeout, and the router resumes that state before artifact inference. Dynamic and bundled subagent manifests and planning/setup consumers now enforce final docs/workspace ## Skills tables headed Skill | Exact trigger through installed SKILL.md authority; root guidance stays table-free.

3.1.12 - 2026-08-11

Added

  • Add the detected sqlalchemy pack and bundled sqlalchemy-schema-design skill to the CLI catalog and scaffold baseline.

baseline/stable/2026.08.11-sqlalchemy-schema-design - 2026-08-11

Added

  • Add the detected SQLAlchemy framework pack with stateless schema and Alembic migration guidance.

baseline/stable/2026.08.11-review-phase-durable-workflow-graph - 2026-08-11

Changed

  • Sync the exact canonical wearedevpunks/skills@423c6d59b285a423262ee8983475de4e13864746.
  • Refactor review-phase into a bootstrap, deterministic router, and four flat gates for preparation, one all-lens review, report retention, and routing return.
  • Add one mode-specific runtime handoff contract so delivery and standalone reviews cold-resume from current evidence without transcript continuity.
  • Preserve explicit operator invocation, immutable retained reports, delivery-owned repair, and the three-review/three-repair budget with no review 4.

baseline/stable/2026.08.11-frontend-domain-structure - 2026-08-11

Changed

  • Strengthen frontend-domain-structure with domain-worthiness and sibling-scan checks, recursive public acyclic boundaries, a narrow discouraged peer-feature exception, and cohesive React responsibility/test-seam splitting guidance from wearedevpunks/skills@211ce3b6bf93319732f261da2f66b419c0262a52.

3.1.11 - 2026-08-11

Changed

  • Make generated docs and workspace AGENTS.md authoring structure-first, progressively disclose conditional repository conventions through exact relative references, and describe every selected scoped skill in a complete Skill | What / when table.
  • Make create-plan select the exact matching What / when rows across every touched scope and load each selected skill's complete SKILL.md before planning.
  • Always generate the opensrc/README.md Source Guide index and direct third-party library investigations through it.

baseline/stable/2026.08.11-scoped-agent-guidance - 2026-08-11

Changed

  • Distribute the structure-first scoped-prompt contract, progressive-disclosure rules, complete scoped skill tables, exact cross-scope create-plan skill loading, unconditional Source Guide index, and source-first hi-cli continuation guidance for CLI 3.1.11.

baseline/stable/2026.08.11-review-phase-graph-rework - 2026-08-11

Changed

  • Sync the exact canonical wearedevpunks/skills@baf97d7a3f55c838f9007af8387aeafddda09d91.
  • Make review-phase explicit-only and run standards and skill adherence, architecture, simplification, and specification lenses against one frozen review snapshot.
  • Require an immutable retained wiki review report before a pass is valid.
  • Bound delivery review to three review and three repair passes, with no fourth review after repair three.
  • Carry implementation skill guidance from plans into worker briefs and record skill application evidence in implementation notes for adversarial review.

baseline/stable/2026.08.11-python-backend-structure - 2026-08-11

Changed

  • Make canonical python-backend-structure compound backend-domain-structure with a strict acyclic, no-sibling import topology while retaining python-project-structure as a deprecated compatibility alias.

3.1.10 - 2026-08-10

Fixed

  • Normalize baseline-declared skill aliases in preserved manifest skill arrays before project-local validation while retaining compatibility assets for older CLIs and keeping aliases out of the canonical runtime skill catalog.

baseline/stable/2026.08.10-cli-3.1.9-effect-service-design - 2026-08-10

Fixed

  • Restore the cataloged effect-service-design skill asset to the packaged baseline for CLI 3.1.9 and compatible CLI 3.1.8 consumers.

baseline/stable/2026.08.10-cli-3.1.9 - 2026-08-10

Fixed

  • Publish the stable scaffold baseline for CLI 3.1.9 while retaining compatibility with CLI 3.1.8.

3.1.9 - 2026-08-10

Fixed

  • Use the production API custom domain for bundled control-plane requests.

baseline/stable/2026.08.10-oxfmt-baseline-assets - 2026-08-10

Changed

  • Sync the exact canonical wearedevpunks/skills@0b2b0358c3db260171815b2cc51f021963249771, including the prior docs-onboarding correction to run hi init from the repository root and repo-wide Oxfmt normalization of distributed baseline assets.
  • Format the complete staged baseline archive inventory with the repository-pinned Oxfmt before hashing or archiving, and fail the build or publication when formatting fails.

baseline/stable/2026.08.10-projection-receipt-output-integrity-r2 - 2026-08-10

Fixed

  • Pair the projection-receipt integrity baseline with CLI 3.1.8 after incomplete manual package staging in 3.1.6 and 3.1.7.

3.1.8 - 2026-08-10

Fixed

  • Publish the complete isolated package containing both the nested managed .gitignore and bundled baseline manifest/archive.

baseline/stable/2026.08.10-projection-receipt-output-integrity-r1 - 2026-08-10

Fixed

  • Publish the same projection-receipt integrity baseline for CLI 3.1.7 after the 3.1.6 direct-package release omitted a required nested managed .gitignore.

3.1.7 - 2026-08-10

Fixed

  • Restore the nested NestJS managed .gitignore by publishing through the isolated npm pack-control path.

baseline/stable/2026.08.10-projection-receipt-output-integrity - 2026-08-10

Changed

  • Bind generated projection receipts to the canonical semantic fingerprint of the effective available-hook set and rendered Claude, Codex, Cursor, and OpenCode output maps.
  • Retain exact receipt-entry compare-and-swap publication while making effective project-authored subagent output changes observable to downstream integrity checks.
  • Keep expected provider capability limitations and preserved project-owned prompts as neutral receipt provenance with healthy receipt/manifest status and empty scaffold degradations; reserve partial for genuine actionable nonfatal anomalies and fail actual projection/application faults.

baseline/stable/2026.08.07-wait-what-edit-hooks - 2026-08-07

Changed

  • Sync shared skills from wearedevpunks/skills@2379a59c84431357321b75ea9dfab12ae8ada0b0.
  • Preserve Finder-derived fog evidence parents and validate the complete configured intake taxonomy before provider mutation (#102).
  • Apply $wait-what language to bounded parallel-research synthesis, SPEC.md, PLAN.md, and IMPLEMENTATION-NOTES.md production (#103).
  • Restore automatic scoped format and lint hooks after file edits across Claude, Codex, Cursor, and OpenCode projections.

3.1.6 - 2026-08-07

Changed

  • Make hi update apply verified baseline changes by default while retaining --write and --yes as compatibility aliases; keep --check read-only.
  • Preserve project-owned, intentionally customizable, and current ProjectGenerated files silently, and let the generated projection producer refresh only its exact scaffold-receipt entry with individually atomic, compare-and-swap publication that is safe to retry.
  • Record renderedOutputSha256 in projection receipts so effective project-authored renderer changes advance semantic evidence without treating context-plan formatting as drift.
  • Expand installed-consumer validation to six evidence rows covering semantic JSON, managed archive/replacement, silent project-owned exceptions, exact receipt-entry refresh, provider-output restoration, and corruption failure.

Fixed

  • Report actual edits to fixed ScaffoldManaged files during check, then archive them under .devpunks/replaced-scaffold/<fingerprint>/<path> and replace them from the verified baseline during a normal update. Baseline-identical files with stale receipt evidence now refresh without an archive.
  • Reject contradictory update flags before baseline, operation, or filesystem effects, and keep unavailable baseline authority distinct from scaffold drift.

baseline/stable/2026.08.07-scaffold-integrity-convergence - 2026-08-07

Changed

  • Align the stable scaffold with default-applying update semantics, read-only --check, recoverable replacement for fixed scaffold-managed edits, and silent preservation for project-owned exceptions.
  • Make the generated projection producer advance only its exact receipt evidence through individually atomic, compare-and-swap publication; cross-file crash atomicity remains outside the contract.

Fixed

  • Converge baseline-identical stale receipt evidence without an archive and keep unavailable authority separate from managed-content drift.

3.1.5 - 2026-08-06

Changed

  • Make scaffold ownership decisions consistent across check, update, stale detection, and receipt persistence, including project-generated managed output.
  • Use the actual worktree filesystem case semantics when excluding managed and bootstrap paths from automatic formatting and linting.

Fixed

  • Preserve valid project-generated output while reporting missing, stale, mismatched, receipt-only, and semantically overlapping ownership cases accurately.
  • Fail closed when the filesystem case probe is indeterminate and reject drive-qualified Windows receipt paths, including drive-relative forms such as C:foo.

baseline/stable/2026.08.06-managed-format-hook-case-semantics - 2026-08-06

Fixed

  • Protect alternate-cased managed and bootstrap paths according to the actual worktree filesystem case semantics, including default case-insensitive macOS and Windows filesystems while preserving genuinely case-sensitive roots.
  • Fail closed without invoking a formatter or linter when the worktree case-semantics probe is indeterminate.
  • Reject drive-qualified Windows receipt paths, including drive-relative forms such as C:foo.

baseline/stable/2026.08.06-managed-format-hook - 2026-08-06

Fixed

  • Make the distributed automatic format hook skip every path in a valid scaffold managed-files receipt, preserving authoritative scaffold bytes beyond the former partial path list.
  • Fail closed without invoking a formatter or linter when the receipt is missing, unreadable, malformed, or invalid.

Changed

  • Keep .devpunks/scaffold-manifest.json as the sole bootstrap exclusion, preserve existing unmanaged-file behavior, and leave manually invoked repository-wide formatting outside Harness.

baseline/stable/2026.08.06-parallel-research-wiki - 2026-08-06

Changed

  • Sync parallel-research from wearedevpunks/skills@b7f939c626d7fd929261726f21949198c5df2aef and make every run retain one consolidated report at <wiki-root>/content/docs/project/research/<slug>-research-report.md with immutable commit proof.

baseline/stable/2026.08.06-requirements-grill-wait-what - 2026-08-06

Changed

  • Sync requirements-grill from wearedevpunks/skills@7d8a73cd74fbbf32f3134cf132afa4f958a30382 and require $wait-what for every grilling question and recommendation before durable round completion.

baseline/stable/2026.08.05-wayfinder-lifecycle - 2026-08-05

Changed

  • Update prototype to the upstream v1.2.0 logic and UI artifact formats, including one-file HTML logic demos with guided walkthroughs and route-level UI variants selected by ?variant=.
  • Replace writing-great-skills with writing-for-agents in the default docs pack.
  • Add the default misc pack with wait-what, scoped to shared .agents guidance rather than application workspaces.
  • Activate writing-for-agents in scaffold/init/update handoffs and generated subagent authoring instructions whenever the continuation edits agent-facing documents.

baseline/stable/2026.08.05-effect-service-design - 2026-08-05

Added

  • Add effect-service-design, imported from dmmulroy/skills@8603380821fee6a77c82639f364ce8fe4f5a92be, with its exact MIT LICENSE (Copyright (c) 2026 Matt Pocock).

Changed

  • Sync shared skills from wearedevpunks/skills@5d8f709b8a0ca8ef05c9b0e0cb45ed07ca25d59e and publish the baseline for CLI >=3.0.0 <4.
  • Route Effect service qualification, dependency-preserving layerWithoutDependencies, ready production layer, test substitutes, and service audits through effect-service-design; preserve action-owned orchestration and integration-owned contracts in effect-backend-structure.
  • Include the previously published parallel-delivery managed skill state, making delivery and implement-spec worker-wave-only and removing the superseded sequential branch.

3.1.3 - 2026-08-05

Fixed

  • Keep generated baseline JSON formatter-stable and hash context/projection evidence canonically so hi scaffold followed by hi check does not report formatter-only drift (issue #97).

3.1.4 - 2026-08-06

Added

  • Add explicit, fingerprint-bound project-generated managed-file ownership so hi check can recognize current repository mirrors without broad path or file-kind exemptions.

Changed

  • Make check, apply, stale detection, and receipt persistence consume one ownership decision; preserve current project-generated output while keeping missing, stale, mismatched, receipt-only, and semantic-overlap cases strict.
  • Replace writing-great-skills with writing-for-agents in the default docs pack and activate it in CLI continuations that author prompt specs, handoffs, root/scoped AGENTS.md, or subagent templates/instructions.
  • Add the default misc pack with wait-what, scoped to shared .agents guidance rather than application workspaces.
  • Adopt the upstream prototype v1.2.0 formats: one-file interactive HTML for logic/state questions and URL-switchable route variants for UI questions.

Fixed

  • Keep missing project-generated output as truthful planned drift without running its producer, inventing output, or reporting a write when repository state remains unchanged.
  • Resolve the Effect v4 source guide against Effect-TS/effect main by default while retaining project-pinned package resolution for exact installed-version behavior.
  • Load baseline publisher settings from apps/cli/.env without overriding exported values and accept Vercel's public control-plane URL as the fallback publisher origin.

3.1.2 - 2026-08-03

Fixed

  • Treat recursive wiki content/docs/**/meta.json route metadata as project-authored when checking and writing updates, while continuing to validate and repair source projections.
  • Restore regression coverage for stale wiki source projections so update checks report and write projected pages without overwriting project-owned route metadata.
  • Generate workspace Oxlint configs with Effect's authoritative OxlintConfig type so the generated configs remain typecheckable alongside their pack-owned rules and plugins.

3.1.1 - 2026-08-03

Added

  • Add durable stable-baseline promotion after verified GitHub asset publication, with idempotent retry reconciliation and post-commit control-plane confirmation.
  • Add bun run baseline:rollback for audited rollback to an explicit stable release with optimistic revision checks.

Changed

  • Make baseline archives reproducible from the release commit timestamp, normalized permissions, deterministic ordering, and timestamp-free gzip metadata.
  • Reuse matching baseline release assets and upload only missing assets while rejecting malformed, duplicate, or mismatched existing assets.
  • Increase the default remote baseline resolution timeout from 1.5 seconds to 5 seconds to tolerate control-plane latency.
  • Prompt for the Skills CLI agent name when hi operator cannot detect one in an interactive terminal, while JSON, plain, redirected, and other noninteractive runs remain fail-closed and require HI_OPERATOR_AGENT.
  • Treat operator-skill identity mismatches from older Skills CLI inventory as repairable outdated copies, guiding operators from hi operator status to hi operator update while preserving the selected agent within one application operation.

Fixed

  • Make hi operator install and hi operator update safely replace outdated copies and verify the exact authoritative identity after installation.
  • Make hi operator migrate verify the replacement before removing the legacy skill, retaining the legacy copy when replacement verification fails.

3.1.1-beta.1 - 2026-08-03

Changed

  • Treat operator-skill identity mismatches from older Skills CLI inventory as repairable outdated copies instead of terminal verification failures.
  • Guide operators from hi operator status to hi operator update when the effective copy is outdated, while preserving the selected agent within one application operation.
  • Make hi operator install and hi operator update safely replace outdated copies and verify the authoritative identity after installation.
  • Make hi operator migrate verify the replacement before removing the legacy skill, retaining the legacy copy when replacement verification fails.

3.1.1-beta.0 - 2026-08-03

Published as @punks/cli@3.1.1-beta.0; the v3.1.1-beta.0 tag and GitHub release remain pending.

Added

  • Add durable stable-baseline promotion after GitHub asset verification, with idempotent retry reconciliation and post-commit control-plane confirmation.
  • Add bun run baseline:rollback for audited rollback to an explicit stable release with optimistic revision checks.

Changed

  • Make baseline archives reproducible from the release commit timestamp, normalized permissions, deterministic ordering, and timestamp-free gzip metadata.
  • Increase the default remote baseline resolution timeout from 1.5 seconds to 5 seconds to tolerate control-plane latency.
  • Reuse matching baseline release assets and upload only missing assets while rejecting malformed, duplicate, or mismatched existing assets.

Fixed

  • Prompt for the Skills CLI agent name when hi operator cannot detect one in an interactive terminal, while JSON, plain, redirected, and other noninteractive runs remain fail-closed and require HI_OPERATOR_AGENT.

3.1.0 - 2026-07-30

Published as @punks/cli@3.1.0 with tag v3.1.0.

Added

  • Add a default security pack (audit-cicd-security, security-best-practices) with source-pinned security guidance.

Changed

  • Sync security skills from wearedevpunks/skills@844890de0f89f4e66cc078147143e61456ff0bec.
  • Add provider-agnostic CI security auditing with progressive references for GitHub Actions, GitLab CI/CD, Jenkins, Azure Pipelines, CircleCI, Bitbucket Pipelines, Buildkite, Tekton, and Argo Workflows in audit-cicd-security.
  • Confirm Critical/High local remediation in audit-cicd-security only with explicit user approval; keep the audit read-only by default.
  • Attribute security-best-practices as vendored from openai/skills (Apache-2.0), synced through wearedevpunks/skills@844890de0f89f4e66cc078147143e61456ff0bec.

Fixed

  • Align security pack defaults and source pin references with baseline-scoped security documentation and required skill manifests.

baseline/stable/2026.07.30-security-pack - 2026-07-30

Added

  • Make security a mandatory default pack (audit-cicd-security, security-best-practices) in scaffold and discovery outputs.

Changed

  • Sync audit-cicd-security and security-best-practices from wearedevpunks/skills@844890de0f89f4e66cc078147143e61456ff0bec.
  • Keep audit-cicd-security read-only by default and gate Critical/High local remediation behind explicit user approval.
  • Vendor security-best-practices from openai/skills (Apache-2.0), then sync via the shared-source commit 844890de0f89f4e66cc078147143e61456ff0bec.

3.0.1 - 2026-07-30

Added

  • Add installed-tarball regression coverage that proves repeated plain hi check runs fetch fresh remote baseline metadata and archives.

Changed

  • Resolve every non-bundled hi check against fresh remote baseline authority, defaulting an omitted selector to the configured baseline or stable.

Fixed

  • Report unavailable remote baseline authority without claiming scaffold drift, while preserving fatal integrity failures for bundled baselines.

3.0.0 - 2026-07-28

Published as @punks/cli@3.0.0 with tag v3.0.0 after the stable M7-M9 cutover.

Stable M7-M9 release completed in #88.

Added

  • Add repeatable packaged-consumer validation for fresh initialization, drift detection, conflict-preserving updates, and installed hi/hint command behavior.
  • Add verified operator-skill lifecycle and baseline-authority flows with explicit provenance, compatibility, and fallback contracts.

Changed

  • Rebuild CLI orchestration around feature-owned Effect v4 domains, typed failures, explicit configuration boundaries, and a unified command metadata authority.
  • Converge settings, scaffold state, context projection, and non-destructive reconciliation behind deterministic plans shared by hi init, hi check, and hi update.
  • Make hi tools ensure refresh every auto-managed required tool through a baseline-owned explicit latest target while keeping manual platform tools validation-only and preserving scaffold/update minimum-version repair behavior.
  • Sync and pin the hi-cli operator skill 1.1.0 to wearedevpunks/skills@09a6f3c, aligned with v3 root init, scaffold, and check, settings-only ensure, and latest-refresh tools ensure.

Fixed

  • Keep JSON and redirected command output machine-safe and noninteractive while preserving cancellation, rollback ownership, and fail-closed baseline behavior.
  • Harden Linux validation, generated wiki/scaffold determinism, cleanup ownership, and provider interruption handling across the M7-M9 release gates.
  • Materialize the frozen hi-cli revision in an exact detached temporary Git checkout before invoking Skills CLI 1.5.20 with a copied local source, while retaining post-write manifest verification before legacy removal and cleaning temporary state on every exit.

baseline/stable/2026.07.23-effect-v4-source-authority - 2026-07-23

Fixed

  • Sync Effect skills from wearedevpunks/skills@45d731db6f5f3e715ecbd2db195b7f68d13dcff9.
  • Declare effect-backend-structure compatible with Effect v4 and replace its Effect v3 service guidance with the canonical $effect and Context.Service contract (#75).
  • Make opensrc path Effect-TS/effect and the Effect repository main branch the primary Effect v4 source authority; retain project-pinned package lookup for exact installed-version behavior.

baseline/stable/2026.07.21-create-spec-vocabulary-removal - 2026-07-21

Changed

  • Sync create-spec from wearedevpunks/skills@52866e7 and end the skill at completed-spec review.

baseline/stable/2026.07.17-grilling-primitive-contract - 2026-07-17

Changed

  • Sync shared skills from wearedevpunks/skills@e2039dd.
  • Make grilling the sole generic question and closure contract while wrappers retain domain pressure tests, durable artifact state, stricter local formats, output mappings, and downstream transitions.

baseline/stable/2026.07.17-batched-grilling-frontier - 2026-07-17

Changed

  • Sync shared skills from wearedevpunks/skills@9fb9184.
  • Replace sequential grilling with Matt Pocock's MIT-licensed batch-grill-me frontier primitive pinned at 9603c1cc8118d08bc1b3bf34cf714f62178dea3b, preserving the stable local grilling id and wrapper composition.
  • Persist stable question ids, prerequisites, current-frontier membership, answered and unanswered state, canonical routed grill paths, and explicit empty-frontier shared-understanding confirmation before backlog, plan, spec, or prototype work.

Fixed

  • Advertise explicit-only design-phase as a global workflow entrypoint while excluding it from scoped primary-skill generation.

baseline/stable/2026.07.16-effect-v4-consolidation - 2026-07-16

Changed

  • Make effect the sole canonical Effect v4 patterns and authoring skill, with Effect-Atom and observability guidance disclosed as focused references.
  • Remove the redundant effect-authoring skill after syncing wearedevpunks/skills@65b8833; retain the distinct backend-structure and recoverable-action workflows.

baseline/stable/2026.07.16-effect-v4-patterns - 2026-07-16

Changed

  • Replace the overlapping effect-best-practices skill with the pinned, MIT-licensed Effect v4 effect skill from wearedevpunks/skills@d18cfc7.
  • Route the detected Effect pack and bundled subagent guidance through the canonical effect skill while retaining distinct authoring, backend-structure, and recoverable-action workflows.

baseline/stable/2026.07.13-create-spec-title-frontmatter - 2026-07-13

Fixed

  • Sync the stable baseline's create-spec skill from wearedevpunks/skills@40b83fb so routed Fumadocs specs include non-empty title frontmatter and enforce it in the quality bar (#72).

2.6.2 - 2026-07-13

Pending npm publish: @punks/cli@2.6.2.

Fixed

  • Sync the create-spec template so scaffolded specs emit the required non-empty title frontmatter when written directly into routed Fumadocs trees (#72).

2.6.1 - 2026-07-13

Pending npm publish: @punks/cli@2.6.1.

Added

  • Add hi operator status, hi operator install, hi operator update, and hi operator migrate for explicit operator-skill management.

Changed

  • Deprecate hi skills rename while retaining it as an alias for hi operator migrate.

Fixed

  • Route change-sensitive hi update post-command handling correctly and refresh only targeted hi-cli installations without invoking Skills CLI update-all behavior.

baseline/stable/2026.07.13-runtime-product-validation - 2026-07-13

Changed

  • Release a baseline-only shared-skill update that makes real supported-runtime evidence an explicit planning and implementation completion contract (#70).

2.6.0 - 2026-07-13

Pending npm publish: @punks/cli@2.6.0.

Added

  • Add hi ensure to reconfigure backlog, asset, repository, and backlog project URL settings without rerunning scaffold initialization; scaffolded write-backlog now requires that configured destination before provider work.

Fixed

  • Stop generated .codex/config.toml files from setting legacy agents.max_threads, which conflicts with Codex multi_agent_v2; retain agents.max_depth and generated hooks (#71).

baseline/stable/2026.07.13-codex-multi-agent-config - 2026-07-13

Fixed

  • Release the stable scaffold baseline for Codex multi_agent_v2 compatibility by omitting legacy agents.max_threads from generated .codex/config.toml while retaining agents.max_depth and Harness hooks.

2.5.4 - 2026-07-10

Pending npm publish: @punks/cli@2.5.4.

Fixed

  • Preserve an existing project-owned apps/wiki/scripts/sync-content.mjs during hi update and hi check, while still reporting and recreating the script when missing (#69).

baseline/stable/2026.07.10-manual-delivery-phase - 2026-07-10

Fixed

  • Make delivery-phase explicit-only alongside the six external/manual lifecycle phases, leaving only review-phase, debugging-phase, and docs-ingest-phase model-invocable as delivery's internal delegates.
  • Sync shared skills from wearedevpunks/skills@7fde033; design and debt resolution now present a bounded delivery brief and stop for explicit user $delivery-phase invocation.

baseline/stable/2026.07.10-external-phase-invocation - 2026-07-10

Fixed

  • Limit explicit-only invocation to the six external/manual lifecycle entrypoints: bug-discovery-phase, bug-resolution-phase, design-phase, finder-phase, requirements-phase, and resolve-debt-phase.
  • Sync the correction from wearedevpunks/skills@a2648cc, restoring model invocation for delivery-phase, review-phase, debugging-phase, and docs-ingest-phase so routed workflows can delegate to them.

baseline/stable/2026.07.10-explicit-phase-invocation - 2026-07-10

Changed

  • Release the stable scaffold baseline with lifecycle *-phase skills as explicit user entrypoints.
  • Sync shared skills from wearedevpunks/skills@5779f6e, setting Claude disable-model-invocation: true and Codex policy.allow_implicit_invocation: false on all lifecycle phase skills.

2.5.3 - 2026-07-09

Pending npm publish: @punks/cli@2.5.3.

Fixed

  • Fix generated Effect Oxlint config typing so scaffolded oxlint.config.ts files typecheck with narrowed custom rule tuples.
  • Keep local lint config dependencies owned by the CLI package so isolated installs can resolve Oxlint and Ultracite config imports.

baseline/stable/2026.07.09-backend-domain-guardrails - 2026-07-09

Changed

  • Release the stable scaffold baseline for expanded backend domain structure guardrails.
  • Sync shared skills from wearedevpunks/skills@062f811, adding layer classification, dependency direction, dependency-injection boundaries, public module/package API rules, and validation prompts to backend-domain-structure.

baseline/stable/2026.07.09-goalify-activation-contract - 2026-07-09

Changed

  • Release the stable scaffold baseline for the lean goalify activation contract.
  • Sync shared skills from wearedevpunks/skills@cc4556d, keeping goalify focused on generating and activating one goal immediately.
  • Remove fallback and gotcha guidance from the bundled goalify skill.

2.5.2 - 2026-07-08

Pending npm publish: @punks/cli@2.5.2.

Added

  • Add hi skills rename to install/update the hi-cli operator skill from the public skills repo and remove legacy global/project dp-cli installs once hi-cli is present.

Fixed

  • Allow Linear to be selected as assetProviderSlug independently from a GitHub repositoryManager, so Linear backlog image assets can be uploaded and embedded while required repository tools still come from GitHub.
  • Skip scaffold-owned hooks, scripts, skills, and hook mirrors in the neutral format hook so hi update --check --json and hi check --json stay clean after managed scaffold updates.

Changed

  • Rename bundled operator skill guidance from $dp-cli to $hi-cli across the CLI command guide, scaffold prompts, install docs, runbooks, and wiki command docs.

baseline/stable/2026.07.09-pulumi-skills-pack - 2026-07-09

Added

  • Release the stable scaffold baseline for the Pulumi detected pack, including the shared-skills sync from wearedevpunks/skills@9653bf9.
  • Select the pulumi pack when @pulumi/pulumi or @pulumi/* packages are present, distributing Pulumi overview, best practices, ComponentResource, Automation API, ESC, provider-upgrade, and package-usage skills.

baseline/stable/2026.07.09-linear-assets-managed-format - 2026-07-09

Fixed

  • Release the stable scaffold baseline for Linear asset-provider settings and managed format-hook drift prevention.
  • Keep required tools sourced from the repository manager while allowing Linear backlog assets through assetProviderSlug.
  • Skip scaffold-owned hooks, scripts, skills, and hook mirrors in the neutral format hook so managed scaffold assets stay hash-clean after update/check.

baseline/stable/2026.07.08-hi-cli-skill-rename - 2026-07-08

Changed

  • Release the scaffold baseline for the hi-cli operator skill rename, including the shared-skills sync from wearedevpunks/skills@45072f4, updated install guidance, and bundled hi-cli skill path.
  • Add the hi skills rename migration command to the stable CLI baseline so old dp-cli installs can be removed after hi-cli is installed.

2.5.1 - 2026-07-08

Pending npm publish: @punks/cli@2.5.1.

Fixed

  • Restore the gradient ASCII HARNESS INTELLIGENCE title block for root and scaffold command output.

2.5.0 - 2026-07-08

Pending npm publish: @punks/cli@2.5.0.

Changed

  • Rebrand the installed executable and user-facing command tree from dp/punks/devpunks to hi, with hint as an alias, while keeping the npm package identity at @punks/cli.
  • Update root/scaffold command guides, startup checks, scaffold handoffs, hooks, and bundled dp-cli guidance to use hi command names and the HARNESS INTELLIGENCE title.

baseline/stable/2026.07.08-hi-command-rebrand - 2026-07-08

Changed

  • Release the scaffold baseline for the hi/hint command rename, updated $dp-cli guidance, hooks, handoffs, generated prompts, and HARNESS INTELLIGENCE title.

2.4.3 - 2026-07-07

Pending npm publish: @punks/cli@2.4.3.

Fixed

  • Clarify the dp scaffold init operator prompt so it describes the generated default-pack managed scaffold surface and separates the four onboarding entrypoint skills from the full scaffolded skill set.

2.4.2 - 2026-07-07

Pending npm publish: @punks/cli@2.4.2.

Fixed

  • Make dp scaffold init distribute the accepted default-pack scaffold surface, including the scaffold manifest, handoff prompt, default-pack skills, hooks, scripts, and subagent manifest, while preserving init's backlog, repository manager, and wiki selections.

2.4.1 - 2026-07-06

Pending npm publish: @punks/cli@2.4.1.

Fixed

  • Let dp update --yes and dp update --write accept newly resolved default or detected packs, persist them in the scaffold manifest, and refresh their managed assets without a separate scaffold setup run.
  • Keep generated wiki sync scripts formatter-idempotent so dp update does not leave persistent managed drift on apps/wiki/scripts/sync-content.mjs.

2.4.0 - 2026-07-06

Pending npm publish: @punks/cli@2.4.0.

Added

  • Bundle finder-phase and wayfinder as scaffolded planning skills.
  • Add finder-phase to global phase routing so loose oversized work reaches the decision frontier before ordinary requirements, research, prototype, design, or delivery phases.

Changed

  • Include the finder-phase and wayfinder planning-pack catalog wiring in the npm CLI.
  • Expand bundled write-backlog guidance around first-class backlog kinds: fog, grilling, research, prototype, epic, and story.
  • Ship Finder Phase wiki docs, scaffold routing docs, and the latest shared-skills sync from wearedevpunks/skills@583be0c.

baseline/stable/2026.07.06-finder-phase-wayfinder - 2026-07-06

Changed

  • Release scaffold baseline finder-phase and wayfinder routing for oversized foggy work before bounded requirements, research, prototype, design, or delivery phases.
  • Add finder-phase and wayfinder to the planning pack, root workflow routing, catalog tests, and generated prompt guidance.
  • Expand write-backlog around first-class backlog kinds: fog, grilling, research, prototype, epic, and story.
  • Include the Finder Phase public entrypoint docs and the latest goalify activation clarification.

baseline/stable/2026.06.30-review-skill-phase - 2026-06-30

Changed

  • Release scaffold baseline upstream review skill and route review-phase startup through Standards versus Spec review axes.
  • Include review in the default research/review skill pack.

This changelog tracks @punks/cli npm executable release notes from the 2.x line onward. Published entries include the npm version and matching git tag or version commit when available. Baseline-only releases use baseline/stable/* GitHub releases and should still get an entry here; BASELINE_CHANGELOG.md can carry extra baseline-specific detail.

2.3.3 - 2026-07-03

Pending npm publish: @punks/cli@2.3.3.

Added

  • Bundle the Expo scaffold pack and shared Expo skills in the npm CLI.

Changed

  • Include runtime changelog metadata for baseline/stable/2026.07.03-expo-skills-pack.

2.3.2 - 2026-06-30

Pending npm publish: @punks/cli@2.3.2.

Added

  • Add dp check read-only session-start drift gate for CLI version, scaffold baseline, managed files, pack selection, changelog summaries, and subagent-owned remediation guidance.

Changed

  • Bundle runtime changelog metadata into packaged CLI commands so update and baseline drift can be explained without local repository files.
  • Clarify dp scaffold init, dp scaffold setup, dp update, and $dp-cli pre-existing skill reconciliation: commands do not detect skill overlaps, preserve blind evidence snapshots, and hand exact-name overlap handling to the follow-up agent.

baseline/stable/2026.06.30-scaffold-skill-reconciliation - 2026-06-30

Changed

  • Release scaffold baseline dp check session-start drift guidance and agent-owned pre-existing skill reconciliation guidance.
  • Sync updated shared dp-cli guidance from wearedevpunks/skills@a889421.

2.3.1 - 2026-06-30

Pending npm publish: @punks/cli@2.3.1.

Fixed

  • Preserve existing Claude settings, including permissions.allow, when scaffold setup injects managed hooks.
  • Keep Windows scaffold setup completing when symlink creation is blocked by using directory links or managed mirror copies.
  • Cover issue #58 Windows scaffold mirror and Claude settings preservation regressions.

2.3.0 - 2026-06-29

Pending npm publish: @punks/cli@2.3.0.

Fixed

  • Remove dp update patch previews and JSON patch bodies, keeping drift output compact path/kind/status summaries.

  • Avoid non-docs scaffold manifests staging wiki alignment drift, and skip generated wiki output directories during docs-owned update alignment.

  • Add regression coverage for CLI scaffold/update drift behavior, database-backed backoffice access, API mutation routes, project activity monotonicity, and OpenAPI route contracts.

  • Default stable baseline resolution no longer reports false drift from stale control-plane metadata or corrupt cached baselines; it validates cached and materialized baseline assets, then falls back to canonical GitHub stable.

  • Scaffold prompt target detection discovers authored scoped AGENTS.md files outside package manifests, so repo-specific surfaces like infra/opentelemetry get prompt specs, subagents, and native agent mirrors without Harness-specific placeholder boundaries.

2.2.8 - 2026-06-29

Pending npm publish: @punks/cli@2.2.8.

Fixed

  • Publish the npm CLI bin as a portable Node script with bundled scaffold assets instead of a host-native Bun executable, so dp, punks, and devpunks run on Windows package-manager shims.
  • Strengthen release validation to run the built bin through Node and through temp npm-installed dp, punks, and devpunks commands before publishing.
  • Stop treating intentionally selected optional scaffold packs as actionable dp update --check pack drift.
  • Report and rewrite stale generated handoff/system-prompt references from .devpunks/required-tools.json to .devpunks/settings.json while preserving local handoff text.
  • Preserve scaffold-time tailored .agents/scripts/sync-subagents.mjs files during update checks and writes.
  • Keep bundled fallback subagent manifest defaults repo-shape neutral instead of shipping Harness-specific app/package paths.

baseline/stable/2026.06.29-frontend-imagegen-skills - 2026-06-29

Changed

  • Release a scaffold baseline with the frontend image-generation skills split into dedicated web and mobile surfaces and included in the frontend skill pack.

baseline/stable/2026.06.29-lean-goalify-activation - 2026-06-29

Changed

  • Release a scaffold baseline with goalify rewritten as a very lean goal compiler that activates the goal immediately and uses disclosed examples only when structure is needed.

baseline/stable/2026.06.29-clawpatch-provider-defaults - 2026-06-29

Changed

  • Release a scaffold baseline where ClawPatch bug-discovery and bug-resolution phases inherit the current agent/launcher provider by default.
  • Update operator docs to remove the obsolete provider-cost warning and treat provider/model flags as explicit overrides only.

2.2.7 - 2026-06-27

Pending npm publish: @punks/cli@2.2.7.

Fixed

  • Accept legacy .devpunks/required-tools.json managed-file entries while keeping .devpunks/settings.json as the required-tool source of truth for new scaffold output.
  • Stop reporting project-authored prompt specs, handoff text, scaffold manifest hashes, subagent guidance, and generated agent prompt mirrors as dp update --check drift.

baseline/stable/2026.06.27-high-signal-tdd-tests - 2026-06-27

Changed

  • Release a scaffold baseline with high-signal TDD guidance for durable behavior through public seams, contract-safe assertions, and invariant-based regression tests.

baseline/stable/2026.06.27-design-phase-prototype-routing - 2026-06-27

Changed

  • Release a scaffold baseline with the research-pack $prototype skill, design-phase prototype routing, and docs-ingested operator guidance for prototype/image artifact handoff.

baseline/stable/2026.06.25-required-tools-settings - 2026-06-25

Changed

  • Release a scaffold baseline that consolidates all required tools in .devpunks/settings.json and removes the separate required-tools manifest.

baseline/stable/2026.06.25-design-phase-asset-evidence - 2026-06-25

Changed

  • Release a scaffold baseline with route-gated design-phase, durable repo asset management, provider settings authority, and backlog/PR visual evidence handoff guidance.

2.2.6 - 2026-06-23

Pending npm publish: @punks/cli@2.2.6.

Changed

  • Sync the simplified goalify skill contract from wearedevpunks/skills@dd95edd.

Fixed

  • Verify refreshed stable baseline metadata against the latest published stable release so stale control-plane metadata cannot hide a newer stable scaffold baseline.

baseline/stable/2026.06.23-stable-refresh-goalify - 2026-06-23

Changed

  • Release a scaffold baseline with the simplified goalify skill contract and issue 49 stable-refresh documentation.

2.2.5 - 2026-06-23

Pending npm publish: @punks/cli@2.2.5.

Changed

  • Generate root prompt surfaces from scaffold specs so root prompts stay aligned with the managed scaffold copy pipeline.

Fixed

  • Preserve repo-specific subagent guidance when syncing generated subagent scripts.
  • Ignore wiki-only roots during pack detection so documentation surfaces do not cause false app/package pack matches.

baseline/stable/2026.06.23-scaffold-detection-guidance - 2026-06-23

Changed

  • Release a scaffold baseline with repo-specific subagent guidance preservation, scaffold-spec-backed root prompt generation, and wiki-root pack detection fixes.

2.2.4 - 2026-06-23

Pending npm publish: @punks/cli@2.2.4.

Fixed

  • Detect Bun global installs through the resolved dp / punks bin symlink, including packaged executable argv shapes, so dp upgrade can reinstall a fresh CLI instead of asking for manual reinstall.
  • Run generated scaffold maintenance scripts with node by default, with DP_SCRIPT_RUNTIME as an override, so packaged CLI installs do not recurse through process.execPath or Bun.execPath while syncing subagents.
  • Restore public stable baseline downloads through the Harness control plane, with token or gh GitHub access retained only as maintainer fallback.

baseline/stable/2026.06.23-scoped-review-phases - 2026-06-23

Changed

  • Release a scaffold baseline with lean scoped review and ClawPatch phase skills.

2.2.2 - 2026-06-23

Pending npm publish: @punks/cli@2.2.2.

Fixed

  • Run generated scaffold maintenance scripts through the host runtime in packaged CLI installs so dp update and dp update --check --json do not re-enter the CLI entrypoint while syncing subagents.

2.2.1 - 2026-06-23

Pending npm publish: @punks/cli@2.2.1.

Changed

  • Bump the CLI executable package after app-surfaced wiki root handling and release-validation fixes.
  • Document that all releases, including baseline-only releases, must update CHANGELOG.md.

Fixed

  • Preserve app/wiki for app-surfaced single repos during scaffold init and update without reintroducing competing wiki/ or apps/wiki/ roots.
  • Preserve monorepo apps/wiki, standalone wiki, marker-backed wiki roots, route-only app/wiki, stale root cleanup cases, and recorded repoShapeMode overrides during update alignment.
  • Add missing routed wiki frontmatter to the CLI tool-validation implementation notes so the wiki production build succeeds.

2.2.0 - 2026-06-23

Pending npm publish: @punks/cli@2.2.0.

Changed

  • Add dp tools ensure / punks tools ensure to check and repair required external Harness tools from .devpunks/required-tools.json tool IDs or the default toolchain, using trusted stable/bundled baseline install contracts.
  • Add dp -v / punks -v as a short alias for --version.
  • Build the npm CLI as a Bun standalone executable so installed dp, punks, and devpunks commands no longer require Bun at runtime.
  • Embed bundled scaffold data and skills into the executable while preserving the existing runtime asset copy paths through a temp extraction cache.
  • Document that Bun is required for repository builds and publishing, not for npm-installed CLI usage.

Fixed

  • Avoid forcing agent-browser install to download Chrome when a supported Chrome, Chromium, or Brave executable is already present.
  • Let already-present required tools validate without Bun, pnpm, or npm on PATH; a package manager is required only when repair is needed.
  • Make the built-dist assertion execute the compiled CLI directly and fail if the package regresses to a Bun shebang.
  • Ad-hoc sign macOS standalone builds so local release validation can execute the compiled binary.

2.1.11 - 2026-06-16

Pending npm publish: @punks/cli@2.1.11.

Changed

  • Sync the generic handoff skill into the CLI catalog.
  • Refine docs-ingest routing and bundled context-engineering docs.

Fixed

  • Resolve dp update report issues.
  • Fix scaffold report output and update drift handling.

2.1.10 - 2026-06-12

Pending npm publish: @punks/cli@2.1.10.

Changed

  • Bump the CLI executable after adding scaffolded session-start update checks.
  • Scaffold a Harness update-check hook that runs dp update --check for Codex, Claude Code, Cursor, and OpenCode session starts.

Fixed

  • Align the built CLI publish assertion with the current dp report --help description.

2.1.9 - 2026-05-28

Pending npm publish: @punks/cli@2.1.9. Version commit: 79d8b25.

Changed

  • Add TanStack Start wiki scaffold support with runtime dependencies, package scripts, check wiring, and OG image scaffolding.
  • Tighten scaffolded spec and implementation workflow guidance around lifecycle docs, backlog sync, and subagent usage.
  • Expand report and wiki debt closeout documentation for GitHub-backed reports and TanStack wiki scaffolds.

Fixed

  • Gate report GitHub writes and AI metadata behind authenticated/token-backed flows.
  • Deduplicate GitHub-backed backoffice reports and tolerate invalid AI verdict output.
  • Fix wiki scaffold update drift for frontmatter, .gitignore, package merges, generated scripts, and TanStack-only route replacements.

2.1.8 - 2026-05-27

Matched npm publish: @punks/cli@2.1.8. Matched git tag: v2.1.8.

Changed

  • Generate scaffolded Oxlint configs from Ultracite core/framework presets with explicit pack-owned overlays.
  • Update scaffolded review/autoreview skill content and release bookkeeping for categorized GitHub notes.

Fixed

  • Fix issue 16 by activating generated OpenCode formatter hooks and routing Python edits through Ruff.
  • Route ESLint-only lint overlay packages through Oxlint jsPlugins instead of native Oxlint plugins.

2.1.7 - 2026-05-27

Matched npm publish: @punks/cli@2.1.7. Version commit: 98b61a0. No matching local v2.1.7 tag was found during changelog update.

Changed

  • Improve the scaffold init backlog provider picker flow.

Fixed

  • Fix project usage detail rendering in the internal backoffice surface shipped with the release branch.

2.1.6 - 2026-05-27

Matched npm publish: @punks/cli@2.1.6. Matched git tag: v2.1.6.

Changed

  • Add Mermaid rendering support to scaffolded wiki apps.
  • Align project domain source indexes under content/docs/project/domains.
  • Harden scaffold/update handling for existing wiki routes, metadata drift, and CLI release scaffolding.

Fixed

  • Close the issue 15 update drift where dp update expected the old apps/wiki/domains sync contract.

2.1.5 - 2026-05-26

Matched npm publish: @punks/cli@2.1.5. Version commit: 71460ce. No matching local v2.1.5 tag was found during changelog backfill.

Changed

  • Bump the CLI executable after requirements wiki scaffold-path updates.

2.1.4 - 2026-05-26

Matched npm publish: @punks/cli@2.1.4. Version commit: 1c5fc88. No matching local v2.1.4 tag was found during changelog backfill.

Changed

  • Update CLI version and installation docs for the dp-cli operator skill flow.

2.1.3 - 2026-05-26

Matched npm publish: @punks/cli@2.1.3. Version commit: 2de8b01. No matching local v2.1.3 tag was found during changelog backfill.

Changed

  • Sync bundled skills and bump the CLI executable package.

2.1.2 - 2026-05-26

Matched npm publish: @punks/cli@2.1.2. Version commit: 40e2aa8. No matching local v2.1.2 tag was found during changelog backfill.

Changed

  • Bump the CLI package after release-test stabilization work.

2.1.1 - 2026-05-25

Matched npm publish: @punks/cli@2.1.1. Matched git tag: v2.1.1.

Changed

  • Bump the CLI executable after the 2.1.0 baseline release line.

2.1.0 - 2026-05-25

Matched npm publish: @punks/cli@2.1.0. Version commit: e6a0941. No matching local v2.1.0 tag was found during changelog backfill.

Changed

  • Release the 2.1.0 CLI baseline with updated backoffice auth, report, and stage-skill guidance.

2.0.1 - 2026-05-22

Matched npm publish: @punks/cli@2.0.1. Version commit: 35be311. No matching local v2.0.1 tag was found during changelog backfill.

Changed

  • Bump the CLI executable after device-auth and backoffice follow-up work.

2.0.0 - 2026-05-21

Matched npm publish: @punks/cli@2.0.0. Matched git tag: v2.0.0.

Changed

  • Promote the Harness Intelligence monorepo-era CLI to the stable 2.0.0 line.
  • Include the private wiki, routed docs, control-plane baseline path, and updated scaffold content from the 2.0.0 delivery branch.

2.0.0-beta.4 - 2026-05-14

Matched npm publish: @punks/cli@2.0.0-beta.4. Matched git tag: v2.0.0-beta.4.

Changed

  • Bump the beta CLI after private wiki and Harness Intelligence rename work.

2.0.0-beta.3 - 2026-05-13

Matched npm publish: @punks/cli@2.0.0-beta.3. Matched git tag: v2.0.0-beta.3.

Fixed

  • Publish the sanitized CLI npm package so workspace and catalog specifiers do not leak into the install artifact.

2.0.0-beta.2 - 2026-05-13

Matched npm publish: @punks/cli@2.0.0-beta.2. Version commit: 2dc13cd. No matching local v2.0.0-beta.2 tag was found during changelog backfill.

Changed

  • Bump the beta package version during the 2.0.0 beta release sequence.

2.0.0-beta.1 - 2026-05-13

Matched npm publish: @punks/cli@2.0.0-beta.1. Version commit: 2d0d1f1. No matching local v2.0.0-beta.1 tag was found during changelog backfill.

Changed

  • Bump the beta package version after adding the beta release task.

2.0.0-beta.0 - 2026-05-13

Matched npm publish: @punks/cli@2.0.0-beta.0. Matched git tag: v2.0.0-beta.0.

Added

  • Introduce the 2.0.0 beta line for Harness phase-skill distribution and monorepo-era scaffold output.