SpecsCLIIssue 43 Bundled Baseline Update Guard
Implementation Notes: Issue 43 Bundled Baseline Update Guard
Implementation Notes: Issue 43 Bundled Baseline Update Guard
Summary
Added a guard that prevents dp update --write and dp update --yes from applying an implicit bundled baseline when the scaffold manifest records a different baseline version.
Changes
apps/cli/src/update/run.tscomputes an unsafe bundled-baseline drift condition after the apply decision and before tool bootstrapping or file writes.apps/cli/src/cli/update-command.tsmarks bundled drift application as allowed only when the operator explicitly selected bundled through--baseline bundledorDP_BASELINE=bundled.apps/cli/src/update/run.test.tscovers refusal of implicit bundled writes and preservation of explicit bundled writes.- Docs now state the update guard in the root README, root runbook, routed wiki runbook, and install page.
Validation Evidence
bun --cwd apps/cli test src/update/run.test.ts src/baseline/resolve.test.tsbun --cwd apps/cli test src/content/content.test.ts src/update/run.test.tsbun run checkgit diff --check
Manual Review Checklist
| Check | Result | Evidence |
|---|---|---|
| Implicit bundled downgrade blocked | Pass | Focused update test expects a CliValidationError and unchanged local file. |
| Explicit bundled override preserved | Pass | Focused update test passes allowBundledBaselineDriftApply and applies the managed script update. |
| Check mode unchanged | Pass | Guard runs only after apply is requested. |
| Operator guidance updated | Pass | Root and routed docs describe the refusal and override. |