Harness Intelligence Wiki
SpecsCLIIssue 43 Bundled Baseline Update Guard

Implementation Notes: Issue 43 Bundled Baseline Update Guard

Implementation Notes: Issue 43 Bundled Baseline Update Guard

Summary

Added a guard that prevents dp update --write and dp update --yes from applying an implicit bundled baseline when the scaffold manifest records a different baseline version.

Changes

  • apps/cli/src/update/run.ts computes an unsafe bundled-baseline drift condition after the apply decision and before tool bootstrapping or file writes.
  • apps/cli/src/cli/update-command.ts marks bundled drift application as allowed only when the operator explicitly selected bundled through --baseline bundled or DP_BASELINE=bundled.
  • apps/cli/src/update/run.test.ts covers refusal of implicit bundled writes and preservation of explicit bundled writes.
  • Docs now state the update guard in the root README, root runbook, routed wiki runbook, and install page.

Validation Evidence

  • bun --cwd apps/cli test src/update/run.test.ts src/baseline/resolve.test.ts
  • bun --cwd apps/cli test src/content/content.test.ts src/update/run.test.ts
  • bun run check
  • git diff --check

Manual Review Checklist

CheckResultEvidence
Implicit bundled downgrade blockedPassFocused update test expects a CliValidationError and unchanged local file.
Explicit bundled override preservedPassFocused update test passes allowBundledBaselineDriftApply and applies the managed script update.
Check mode unchangedPassGuard runs only after apply is requested.
Operator guidance updatedPassRoot and routed docs describe the refusal and override.

On this page