Harness Intelligence Wiki
SpecsCLIIssue 43 Bundled Baseline Update Guard

Spec: Bundled Baseline Update Guard

Spec: Bundled Baseline Update Guard

Initial Situation

Harness distributes scaffold content through stable baseline releases, while the npm CLI package also includes a bundled baseline for offline use. Issue 43 showed a hazardous interaction: after a newer stable baseline was published, global dp update --yes could resolve to the older bundled baseline and produce managed-file changes that downgraded repo guidance.

Issue

Bundled fallback is useful for offline diagnosis and intentional recovery, but dp update --write and dp update --yes are write paths. When the repo's .devpunks/scaffold-manifest.json records a different baseline version, applying implicit bundled fallback is unsafe because the command cannot know whether it is refreshing or downgrading.

Solution

Keep fallback resolution intact, but add a write guard inside runUpdate:

  • allow check/json mode to report baseline drift
  • block apply mode when active baseline source is bundled and manifest baseline drift exists
  • allow explicit bundled application when the operator passes --baseline bundled or sets DP_BASELINE=bundled

This keeps offline visibility while requiring an explicit decision before old bundled assets can replace newer managed scaffold files.

Non-Goals

  • Removing bundled fallback.
  • Changing baseline publish mechanics.
  • Changing pack drift behavior.
  • Rewriting control-plane or GitHub release resolution.

Acceptance Criteria

  • dp update --yes refuses to write from implicit bundled fallback when manifest baseline drift exists.
  • dp update --check can still report baseline drift without writing.
  • Explicit bundled mode can still apply managed-file changes.
  • Operator docs explain the guard and the explicit override.
  • Focused update tests cover blocked and explicit bundled write paths.

On this page