Skip to content

Canonical merge of #1156 - #1157

Merged
MongLong0214 merged 6 commits into
mainfrom
canonical/pr-1156
Oct 3, 2026
Merged

MongLong0214 merged 6 commits into
mainfrom
canonical/pr-1156

Conversation

@commitlore-canonical-build

Copy link
Copy Markdown
Contributor

The commit that will land for #1156: main plus that source plus a canonical rebuild, built together so all eleven required contexts run on the tree that merges rather than on one that resembles it.

#1156 carries source only, which is what a contributor on a host that cannot run a linux/amd64 Docker build can produce (#720). Nothing was rebuilt by hand.

Merge this with a merge commit, not a squash. This branch merged #1156 with --no-ff, so its head commit is an ancestor here: a merge commit lands that commit on main, and GitHub then records #1156 as merged because its head is reachable -- which is what T-1502 asks for. A squash lands new bytes instead, and #1156 stays open with nothing to point at.

This body deliberately carries no closing keyword. GitHub binds one only to the number straight after it, and a pull request closed by keyword is recorded closed rather than merged -- the opposite of the line above. Reachability does the closing here.

Opened by canonical-merge.yml for #719.

dependabot Bot and others added 6 commits October 1, 2026 07:21
Bumps the dev-dependencies group with 1 update: [js-yaml](https://github.com/nodeca/js-yaml).


Updates `js-yaml` from 5.4.1 to 5.4.2
- [Changelog](https://github.com/nodeca/js-yaml/blob/master/CHANGELOG.md)
- [Commits](nodeca/js-yaml@5.4.1...5.4.2)

---
updated-dependencies:
- dependency-name: js-yaml
  dependency-version: 5.4.2
  dependency-type: direct:development
  update-type: version-update:semver-patch
  dependency-group: dev-dependencies
...

Signed-off-by: dependabot[bot] <support@github.com>
Bumps [@modelcontextprotocol/sdk](https://github.com/modelcontextprotocol/typescript-sdk) from 1.30.0 to 1.30.1.
- [Release notes](https://github.com/modelcontextprotocol/typescript-sdk/releases)
- [Commits](modelcontextprotocol/typescript-sdk@1.30.0...1.30.1)

---
updated-dependencies:
- dependency-name: "@modelcontextprotocol/sdk"
  dependency-version: 1.30.1
  dependency-type: direct:production
  update-type: version-update:semver-patch
...

Signed-off-by: dependabot[bot] <support@github.com>
`build:canonical` on the merged tree, so the commit that lands matches the source it lands with. The pull request carried source only, which is what a contributor on a host that cannot run a linux/amd64 Docker build can produce (#720).

Limit: this proves the bundle matches this tree; whether this tree is what a reviewer wants is what the pull request is for
Blast: system
Undo: easy
Certainty: firm
Record-Id: r-canonmerge1156
Provenance: authored
Verified: artifact:verify passed against the regenerated manifest in the same job, before any credential was available to it
CommitLore-Version: 2.0.0
@github-actions

github-actions Bot commented Oct 3, 2026

Copy link
Copy Markdown

CommitLore — record lint

Trailers: clean — 6 commits in origin/main..d703e48ea0f605c00b086b71efbaf6f531e9443c
Active constraints: 240 limits · 249 ruled-out · 61 warnings — from 264 records over 3 changed paths

Active constraints for the paths this PR touches

Limits (240)

  • r-canonmerge1156 d703e48 — this proves the bundle matches this tree; whether this tree is what a reviewer wants is what the pull request is for
  • r-canonmerge1154 7423261 — this proves the bundle matches this tree; whether this tree is what a reviewer wants is what the pull request is for
  • r-2fb1c649b3ad 922f95f — 새 ip-address advisory가 기존 production audit gate를 실패시켜 이번 릴리즈에 compatible transitive patch가 필요하다.
  • r-3081e462f9b8 3b2fd09 — canonical-merge publication의 force push가 승인 조건과 충돌하여 공식 pinned builder로 artifacts를 만들고 일반 PR로 제출한다.
  • r-canonmerge1141 11e5a77 — this proves the bundle matches this tree; whether this tree is what a reviewer wants is what the pull request is for
  • r-ef0defcd69a8 11ef133 — the previous version occurs 62 times across twelve files on main; 59 are install pins and manifest versions and moved, and the three that stay are CHANGELOG.md's 1.6.0 heading and the lockfile's sourcemap-codec version and tarball URL
  • r-canonmerge1139 c5c9a3f — this proves the bundle matches this tree; whether this tree is what a reviewer wants is what the pull request is for
  • r-canonmerge1132 21febb3 — this proves the bundle matches this tree; whether this tree is what a reviewer wants is what the pull request is for
  • r-276fed4dac2b d71a55c — after the bump the only occurrence of the previous version is CHANGELOG.md's own 1.5.1 heading, which is that release's section and must not move; the other 59 across eleven files are install pins and manifest versions
  • r-canonmerge1130 031ff70 — this proves the bundle matches this tree; whether this tree is what a reviewer wants is what the pull request is for
  • r-canonmerge1123 c9f1a0b — this proves the bundle matches this tree; whether this tree is what a reviewer wants is what the pull request is for
  • r-release151 94e85f9 — two occurrences must not move and were read rather than filtered -- CHANGELOG.md carries 1.5.0 as its previous heading, and docs/adr/ADR-0009 carries gitlore@1.5.0, which is a different package's version and a coincidence of numbers
  • r-canonmerge1119 47e5337 — this proves the bundle matches this tree; whether this tree is what a reviewer wants is what the pull request is for
  • r-canonmerge1117 579649a — this proves the bundle matches this tree; whether this tree is what a reviewer wants is what the pull request is for
  • r-canonmerge1080 e0bf513 — this proves the bundle matches this tree; whether this tree is what a reviewer wants is what the pull request is for
  • r-canonmerge1067 e8baba1 — this proves the bundle matches this tree; whether this tree is what a reviewer wants is what the pull request is for
  • r-canonmerge1064 cce948b — this proves the bundle matches this tree; whether this tree is what a reviewer wants is what the pull request is for
  • r-release150 df9fe0d — enforcement exists only where a Bash PreToolUse hook does; a person at a terminal, CI, a script and every host without that hook get a simpler command and no gate
  • r-release150 df9fe0d — the trivial thresholds are chosen rather than measured, and are not configurable in this release -- a trivial block in the policy would move policy_identity_hash and invalidate every binding and pending transaction in flight
  • r-canonmerge1062 6415e5a — this proves the bundle matches this tree; whether this tree is what a reviewer wants is what the pull request is for
  • r-canonmerge1057 f5c3071 — this proves the bundle matches this tree; whether this tree is what a reviewer wants is what the pull request is for
  • r-release142 208b821 — the version pins moved across 11 files; installer/canonical-artifact.json is regenerated by the canonical build and is deliberately not among them
  • r-canonmerge1052 3dea4df — this proves the bundle matches this tree; whether this tree is what a reviewer wants is what the pull request is for
  • r-treebind1030 ad4c4ef — the argument is optional, so a caller that does not pass it binds to the server's checkout exactly as before -- this closes the silent case only for callers that say what they meant
  • r-treebind1030 ad4c4ef — the assertion compares working trees, so a server and caller in the same tree at different times are indistinguishable; HEAD moving under a prepared transaction is still the receipt's job (r-requirereceipt1005)
  • r-treebind1030 ad4c4ef — commitlore capture on the CLI is unchanged and needs no assertion, because it binds to its own working directory -- only the MCP surface can disagree with its caller
  • r-canonmerge1026 434ca28 — this proves the bundle matches this tree; whether this tree is what a reviewer wants is what the pull request is for
  • r-canonmerge1018 9e5317c — this proves the bundle matches this tree; whether this tree is what a reviewer wants is what the pull request is for
  • r-canonmerge1016 0d2b737 — this proves the bundle matches this tree; whether this tree is what a reviewer wants is what the pull request is for
  • r-canonmerge1013 4159c6b — this proves the bundle matches this tree; whether this tree is what a reviewer wants is what the pull request is for
  • r-canonmerge1010 cf5fdee — this proves the bundle matches this tree; whether this tree is what a reviewer wants is what the pull request is for
  • r-canonmerge1008 e3ff79f — this proves the bundle matches this tree; whether this tree is what a reviewer wants is what the pull request is for
  • r-canonmerge1006 d36e450 — this proves the bundle matches this tree; whether this tree is what a reviewer wants is what the pull request is for
  • r-canonmerge1003 b6c6b5c — this proves the bundle matches this tree; whether this tree is what a reviewer wants is what the pull request is for
  • r-canonmerge1000 74f684b — this proves the bundle matches this tree; whether this tree is what a reviewer wants is what the pull request is for
  • r-measurewrites988 4edfd9f — dbstat is a SQLite compile option, and the harness prints an empty table rather than failing where it is absent -- an empty table there means the measurement did not run, not that the cost is zero
  • r-measurewrites988 4edfd9f — a bare npx vitest run still reads whatever dist/ is on disk; only the two documented commands build first, and nothing but a paragraph in CONTRIBUTING guards the third
  • r-canonmerge998 9419931 — this proves the bundle matches this tree; whether this tree is what a reviewer wants is what the pull request is for
  • r-canonmerge996 fef169a — this proves the bundle matches this tree; whether this tree is what a reviewer wants is what the pull request is for
  • r-canonmerge994 d9a01c0 — this proves the bundle matches this tree; whether this tree is what a reviewer wants is what the pull request is for
  • r-canonmerge992 9154912 — this proves the bundle matches this tree; whether this tree is what a reviewer wants is what the pull request is for
  • r-canonmerge983 78c4d9a — this proves the bundle matches this tree; whether this tree is what a reviewer wants is what the pull request is for
  • r-buildbeforetest960 346006a — npm test and a bare vitest run are untouched, so the same trap is still open for anyone who reaches past the documented command -- CI builds explicitly, which is why that is tolerable rather than fixed
  • r-believablesuite960 3ee700c — the harness reverses one hunk at a time, so a fix spread over two hunks that only fails together reads as two unguarded changes
  • r-believablesuite960 3ee700c — 120s is a measurement from one machine; a slower one needs its own number rather than this one inherited
  • r-canonmerge980 9fba099 — this proves the bundle matches this tree; whether this tree is what a reviewer wants is what the pull request is for
  • r-pinnedmirror957 a06b984 — a note's own block still costs a process each, because %(trailers) parses the annotated commit's message and there is no atom for a note body
  • r-pinnedmirror957 a06b984 — the reachability filter still reads HEAD at listing time, so a HEAD that moves mid-pass can still change which notes are in scope; only the mirror is pinned here
  • r-canonmerge978 445c515 — this proves the bundle matches this tree; whether this tree is what a reviewer wants is what the pull request is for
  • r-probeconsumers975 adcbd50 — the block cache lives on CollectCache and therefore for one invocation only -- hoisting it to module scope would serve a rewritten message from memory, which is the staleness r-staleonepass names
  • r-probeconsumers975 adcbd50 — doctor still spends 71 parses against a complete index, through its own short per-branch ranges; batching within a range trades N parses for one batch and a short range has few, so the batch has to span ranges to help there
  • r-canonmerge973 6ef03bb — this proves the bundle matches this tree; whether this tree is what a reviewer wants is what the pull request is for
  • r-monotonic968 8f5ee12 — two unbudgeted rebuilds racing still overwrite each other, and repeated replacement can still keep a drain from converging -- neither is closed by this
  • r-monotonic968 8f5ee12 — the comparison is inside the write transaction and the scan is not, so a rebuild can still do the whole scan and then discard it; what it cannot do is publish it over something better
  • r-canonmerge969 8f6b287 — this proves the bundle matches this tree; whether this tree is what a reviewer wants is what the pull request is for
  • r-probebatch951 8d78b62 — the equivalence is proven over this repository's 114 candidate paragraphs and sixteen constructed shapes, not over every paragraph git can parse -- the two shapes that broke the first design were both outside the first corpus
  • r-probebatch951 8d78b62 — one temp directory per call, removed in a guarded finally; a process killed with SIGKILL leaves it for the operating system
  • r-probebatch951 8d78b62 — the batch shares an answer between identical paragraph texts within one call, which holds only while git's configuration is fixed for that call
  • r-canonmerge954 7672c37 — this proves the bundle matches this tree; whether this tree is what a reviewer wants is what the pull request is for
  • r-atomreuse951 eb2869d — the saving is one process per message that reaches the recovery pass, so a history with no multi-block messages sees no change at all -- 20,000 generated commits spent zero interpret-trailers before this and spend zero after
  • r-atomreuse951 eb2869d — atomIsAmbiguous still sends a message to the process, so the count is bounded by the framing of real messages rather than by a rule
  • r-canonmerge952 7a57d4c — this proves the bundle matches this tree; whether this tree is what a reviewer wants is what the pull request is for
  • r-resume951 83f5629 — the drain reads one batch before its deadline may cancel anything, so a call can overshoot its slice by one batch -- without that floor a batch costing more than the slice is cancelled every time and the queue never drains at all
  • r-resume951 83f5629 — a note's body is still read through the live ref after the mirror was listed from it, so a single invocation can cross a notes update; the queue now carries its originating ref, which closes the resumed case and not that one
  • r-resume951 83f5629 — the equivalence is proven on this repository and on synthetic histories of 400 commits, not over every repository shape
  • r-canonmerge947 b9819f6 — this proves the bundle matches this tree; whether this tree is what a reviewer wants is what the pull request is for
  • r-release1219 6fd1ed5 — the pin count is a property of this tree and grows with each README section, so the next release measures it rather than reusing 59
  • r-canonmerge945 f0e7122 — this proves the bundle matches this tree; whether this tree is what a reviewer wants is what the pull request is for
  • r-release1218 3ba5d09 — the pin count is a property of this tree and grows with each README section, so the next release measures it rather than reusing 59
  • r-canonmerge940 31c971e — this proves the bundle matches this tree; whether this tree is what a reviewer wants is what the pull request is for
  • r-canonmerge936 05e6419 — this proves the bundle matches this tree; whether this tree is what a reviewer wants is what the pull request is for
  • r-release1217 4836a95 — the pin count is a property of this tree and grows with each README section, so the next release measures it rather than reusing 59
  • r-canonmerge932 73a9995 — this proves the bundle matches this tree; whether this tree is what a reviewer wants is what the pull request is for
  • r-release1216 573d14c — the pin count is a property of this tree and grows with each README section, so the next release measures it again rather than reusing 59
  • r-canonmerge927 a1543bd — this proves the bundle matches this tree; whether this tree is what a reviewer wants is what the pull request is for
  • r-release1215 b6d2cfe — the pin count is a property of this tree; the surface grows with each README section, so the next release must measure it again rather than reuse 44
  • r-canonmerge918 e998491 — this proves the bundle matches this tree; whether this tree is what a reviewer wants is what the pull request is for
  • r-release1214 6e91b8e — dist/ is not rebuilt here -- the canonical bundle is rebuilt on linux/amd64 by canonical-merge.yml, and a macOS esbuild output would not match CI
  • r-canonmerge916 7be23ec — this proves the bundle matches this tree; whether this tree is what a reviewer wants is what the pull request is for
  • r-release1213 86f6dab — dist/ is not rebuilt here -- the canonical bundle is rebuilt on linux/amd64 by canonical-merge.yml, and a macOS esbuild output would not match CI
  • r-canonmerge912 29aa38c — this proves the bundle matches this tree; whether this tree is what a reviewer wants is what the pull request is for
  • r-release1212 0e93f7c — dist/ is not rebuilt here -- the canonical bundle is rebuilt on linux/amd64 by canonical-merge.yml, and a macOS esbuild output would not match CI
  • r-canonmerge908 d9ab06a — this proves the bundle matches this tree; whether this tree is what a reviewer wants is what the pull request is for
  • r-release1211 24dbdcf — dist/ is not rebuilt here -- the canonical bundle is rebuilt on linux/amd64 by canonical-merge.yml, and a macOS esbuild output would not match CI
  • r-canonmerge904 bb6b2e6 — this proves the bundle matches this tree; whether this tree is what a reviewer wants is what the pull request is for
  • r-release1210 da1cc9f — dist/ is not rebuilt here -- the canonical bundle is rebuilt on linux/amd64 by canonical-merge.yml, and a macOS esbuild output would not match CI
  • r-canonmerge899 3cae2fb — this proves the bundle matches this tree; whether this tree is what a reviewer wants is what the pull request is for
  • r-release129 276feed — dist/ and installer/canonical-artifact.json are absent by design, so artifact:verify fails on this tree -- canonical-merge.yml rebuilds them on linux/amd64
  • r-canonmerge894 f48642f — this proves the bundle matches this tree; whether this tree is what a reviewer wants is what the pull request is for
  • r-release128 795791c — dist/ and installer/canonical-artifact.json are absent by design, so artifact:verify fails on this tree -- canonical-merge.yml rebuilds them on linux/amd64
  • r-canonmerge891 f771749 — this proves the bundle matches this tree; whether this tree is what a reviewer wants is what the pull request is for
  • r-release127 ba88444 — dist/ and installer/canonical-artifact.json are absent by design, so artifact:verify fails on this tree -- canonical-merge.yml rebuilds them on linux/amd64
  • r-honoadvisory d339291 — this repairs one resolution rather than the class -- the next advisory in a transitive production dependency will block a release the same way, and nothing here notices earlier
  • r-canonmerge886 369e2e6 — this proves the bundle matches this tree; whether this tree is what a reviewer wants is what the pull request is for
  • r-release126 55e8d79 — dist/ and installer/canonical-artifact.json are absent by design, so artifact:verify fails on this tree -- canonical-merge.yml rebuilds them on linux/amd64, where a macOS esbuild output would not match
  • r-canonmerge882 2020ef1 — this proves the bundle matches this tree; whether this tree is what a reviewer wants is what the pull request is for
  • r-release125 9d03977 — dist/ and installer/canonical-artifact.json are not in this commit, so artifact:verify fails on this tree by design -- canonical-merge.yml rebuilds them on linux/amd64, where a macOS esbuild output would not match
  • r-canonmerge879 87f6dac — this proves the bundle matches this tree; whether this tree is what a reviewer wants is what the pull request is for
  • r-canonmerge874 09fa8b8 — this proves the bundle matches this tree; whether this tree is what a reviewer wants is what the pull request is for
  • r-canonmerge871 dcc1f6b — this proves the bundle matches this tree; whether this tree is what a reviewer wants is what the pull request is for
  • r-reviewcaughtserverjson c7debaf — the gate now reads server.json's .version; the installer command and release URL inside it are strings nothing compares, exactly as the four READMEs and two installers are
  • r-release121 9845d44 — npm audit is a claim about advisories published now, not about the code; and the canonical build was reproduced on one machine against the pinned image digest, which CI repeats twice but no one has repeated on another date
  • r-depsbatchbump 42013a6 — says nothing about behaviour changes inside SDK 1.30.0 itself; the suite covers this repository's use of the SDK, not the SDK
  • r-fasturiqsaudit 1752273 — an audit is a claim about advisories published at this moment, not about the code; a clean run says nothing about tomorrow's disclosures
  • r-cdebmanifest d64b006 — reproducibility is established for one run on one machine against the pinned image digest. The contract's own comment notes node:24-bookworm is mutable, and this says nothing about a rebuild on a different date
  • r-cdebremoval 36ae3ab — four documents still mention CDEB and are deliberately kept -- ADR-0033, the archived readiness SSOT, an archived handoff, and two CHANGELOG lines. They are the record of decisions that were made, and rewriting them would be deleting evidence rather than code
  • r-cdebremoval 36ae3ab — one full-suite run in the middle of this work reported a single failure that the next two runs did not reproduce, with no relevant change between them. Its name was not captured before the output was discarded, so it is recorded as an unidentified flake rather than as something this commit fixed
  • r-v5stage1r1reviewfixes 87cacec — the pilot-gate custody gap is open and needs role separation -- execution, custody of arm-coded outcomes, and continuation held by different parties. That is an owner decision and it has to be settled before the pilot, not after
  • r-v5stage1r1reviewfixes 87cacec — the firewall now names who produced the maintenance need and refuses a producer not declared record-blind, but a declaration is not evidence. Making it evidence needs an attestable isolated authoring environment this layer does not have
  • r-v5stage1r1reviewfixes 87cacec — tau_squared_bound = 0.06 is a frozen assumption, not a measurement. It is conservative in the direction that matters -- lower true heterogeneity means the study detects more than promised -- but nothing here establishes the true value
  • r-v5stage1r1designlayer 28699d8 — the task-author firewall has still never run. Whoever built this corpus has read all 241 records, so the record-blind half cannot be satisfied from here -- it needs an author whose only inputs are the base tree and the maintenance need, with the manifest proving it
  • r-v5stage1r1designlayer 28699d8 — no oracle exists for any of the 62. Stage 0 recorded that reviewers thought one could be written; between that and a validated discriminating oracle sits the whole of G2, and nothing has crossed it
  • r-v5stage1r1designlayer 28699d8 — the between-candidate variance in the power table is a range I chose to bracket, not a measurement. The pilot supplies the real value, and only then does the detectable effect stop being a family of curves
  • r-833multiblocknotice fe84c6b — this makes the cost audible, it does not remove it. A merge commit written from a multi-block draft still carries records that git-native tooling will not report as trailers, and --target remains the only way to have every record visible on both channels
  • r-v4qualification b8ff1b9 — G3 and G4 were judged from the commit message, the changed paths and the ruling. Neither reviewer read the current code or ran a test, so both are informed judgements about a maintenance task rather than measurements of one. G5 classifies whether an oracle could be written; none was built
  • r-v4qualification b8ff1b9 — this says nothing about whether recording decisions helps an agent. It says the four surveyed repositories cannot supply gold that is independent of the records being tested, which is a fact about these repositories and this gate
  • r-v3manifestsync c195b48 — this proves the manifest matches this checkout. It does not prove the pinned image produced the committed dist on any other machine, which is what the pinned digest is for
  • r-v3terminalseal 7754f1a — the placeholder row remains in the ledger and always will. This makes it legible, not absent, and a reader who takes digests on faith rather than reading the deviation is still misled
  • r-v3terminalseal 7754f1a — the canonical digest binds the artifact list it is given. A transition that names too few artifacts is bound to a partial set, and nothing here decides what the right set is for a future study
  • r-v3terminalseal 7754f1a — guard coverage is unchanged -- thirteen exclusion kinds remain uncovered and one scan inert, recorded in the mutation baseline
  • r-coauthoredcasing 06354f9 — the exemption stays a fixed pair. A standardised trailer this repository has not met -- Reviewed-by:, say -- is still refused as unknown-key, which is deliberate but will read as the same bug to whoever hits it next
  • r-democopycanonicalbuild 8ce56bc — the bundle changed only because one output string did; nothing about the build is different
  • r-release120 b073960 — the passive notice only speaks once a check has landed, so the first invocation after this install says nothing however out of date the next release finds it. That is the trade the zero-latency design buys, and the answer arrives on the following command
  • r-lazysignaturemode f7dc7ef — a scan that reads even one commit still asks, so the cost returns on any invocation that has catching up to do. That is the invocation that can afford it
  • r-rebuildworknobodyreads 1a66b26 — the deadline is still only checked between batches and before the expensive half of one, so a late batch of 1024 commits can overshoot by whatever that batch costs -- bounded by one batch rather than by the whole scan. And an unsigned-mode index now carries '' where it carried git's verdict, so a reader wanting the cached status without turning signature mode on no longer gets it; none exists
  • - 1ca0ac9 — the other tracked dist files auto-merged rather than conflicting, and a line-wise merge of generated JavaScript is not something to trust on its own -- the canonical rebuild is what makes them correct, not git's resolution
  • r-rebuildopensdamaged 70dc155 — this covers a full-text table that will not rebuild. Damage that makes createSchema or the first meta read fail still surfaces through the open's own catch, which is where it belonged already; nothing here widens that
  • r-initsayswhatitpinned c7de40d — the report names the pinned version and the newer one, but not whether the pinned checkout is intact -- doctor compares the running build against the pinned one and is where that question belongs
  • r-upgradeperforms b1e75c9 — nothing here can tell a current that resolves to the right tag over a checkout whose contents are wrong. install.sh verifies a reused checkout's manifest and tag, and doctor compares the running build against the pinned one; step 4's failure text names doctor for exactly that reason
  • r-doctorreleasefreshness 174e120 — latestReleaseSync cannot signal a process group, so a git that spawns an SSH client which then hangs is bounded by spawnSync's timeout on the child alone. The async path exists because the notice cannot afford that and this report can
  • r-passiveupdatenotice a783a95 — the notice speaks only when a check has already landed, so on a cold cache the first invocation says nothing however out of date it is. That is the trade the zero-latency property buys, and the answer arrives on the next command rather than the first
  • r-upgradereadonly ccc634c — upgrade accepts --check but performs no upgrade in this build, and --check is therefore the only behaviour. T-1606 makes the bare form act; until then the command names the install line rather than running it
  • r-integrityoffread 2584678 — commitlore index --rebuild still cannot open a structurally damaged index -- openIndex rebuilds the FTS table on open and throws first (commitlore index --rebuild cannot open the index it is meant to rebuild #785). That predates this change and the documented remedy has never run in that state; test/index-corruption.test.ts opens the database directly to work around it and says so
  • r-pluginawaredelivery 46c4169 — this does not clean up dual installs already on disk -- somebody in that state keeps paying twice until they remove one by hand. It also reads Claude Code's private state, which has already changed shape once (the registry is on version: 2); when that breaks, it breaks toward writing the hook, which is the direction chosen on purpose
  • r-hookmatcherunify fa4373d — neither installer knows the other exists -- init writes the settings.json hook unconditionally, so a user who follows the README to the plugin and then runs commitlore init carries two PreToolUse hooks running the same command. Unifying does not create that double fire, but it widens the overlap from Edit and Write to all five; the partial overlap it replaces was worse to diagnose, because the same user saw records twice on an edit and once on a read
  • r-rebuildschema a6d577e — this recreates the file whenever the recorded version differs, so a downgrade discards an index a newer build wrote rather than reading what it can from it
  • r-partialsilence 9553e2c — this says the scan was cut short, not which records were missed -- the payload cannot name what it never read
  • r-rel114 9692b6d — the README restructure and the mobile hero redesign are not in this release, so the four READMEs remain long and the hero's labels remain small at 375px
  • r-builderpin cb1515f — nothing checks that the pinned digest still exists upstream, so a digest deleted from the registry surfaces as a build failure rather than as a clear message
  • r-canonmerge761 6a88f2f — this proves the bundle matches this tree; whether this tree is what a reviewer wants is what the pull request is for
  • r-rel113 17a1301 — #749 question 1 stays open -- a fix that lives in the hook reaches a repository only on its next visit, and nothing on this machine knows which repositories exist
  • r-machinescope e46af2a — this is one check's classification, not a scope field -- another machine-scoped check added later will default to claiming attention again, and nothing here would notice
  • r-upgraderebind 49765af — this reaches a repository only when its stub already carries the arm, so one installed before this still needs hooks install once -- the same boundary After an upgrade the hook says "cannot find the CLI" when the CLI is fine and containment refused it #746 recorded, and the reason that command stays the named remedy
  • r-746message 5dda01b — the stub is written into .git/hooks at install time, so a repository wired before this keeps the old text and gets the old sentence until hooks install runs there; installing a corrected release is not enough
  • r-746narrow 5dda01b — commitlore.node is only tested for -x, so a recorded interpreter that exists but cannot run this bundle still reaches neither arm and falls through to the absence message
  • r-rel112 ad6fee3 — the readback confirms the link, not that the interpreter behind it runs -- doctor remains the check for that
  • r-rel112 ad6fee3 — this repairs the installer; a machine already upgraded to 1.1.0 or 1.1.1 keeps its stale current until the installer is re-run, which is why the note names the command to check
  • r-detectrule728 f1784ce — this records the rule, it does not enforce it -- a new host added with the wrong test still compiles, and Plant a host fixture in Windows CI so this class can't hide behind an empty runner #722's planted fixture is where that could be caught
  • r-detectwhy728 f1784ce — still recorded, not enforced -- a new host added with the wrong test compiles
  • r-rel111 8c29f5d — Hermes still fails on that machine for a cause that is not this one and is not yet named (Windows: every detected host fails to wire — the temp filename carries the whole path, and hasCommand cannot see a .cmd #716)
  • r-rel111 8c29f5d — a zero-byte .cursor/mcp.json on the tester's machine is a user file; the installer read the file it says it reads and reported the true reason
  • r-rel111why 8c29f5d — this changes the note, not the behaviour -- the behaviour shipped in the merged branch and is already covered by artifact:verify
  • r-canon720 7bf5b82 — this adds no judgement about the Windows behaviour -- it makes the branch buildable, and the live evidence on the pull request is still the only evidence for that path
  • r-canon720b 7bf5b82 — this rebuilds, it does not judge -- the Windows behaviour still rests on the live evidence recorded on the pull request, and Hermes and the first-run probe timeout are still open on Windows: every detected host fails to wire — the temp filename carries the whole path, and hasCommand cannot see a .cmd #716
  • r-winargv716 7bf5b82 — Does not change executable-only Claude detection or the pre-existing MCP probe shell path; a new canonical dist rebuild is not included from Windows
  • r-winexec716 7bf5b82 — Does not change MCP probing or rebuild generated artifacts.
  • r-rel110 d9a041f — this release does not make host wiring work on Windows -- detection still cannot see a .cmd and spawn still cannot run one (Windows: every detected host fails to wire — the temp filename carries the whole path, and hasCommand cannot see a .cmd #716)
  • r-rel110 d9a041f — 1.0.0 through 1.0.2 have no CHANGELOG entries; a pointer to the releases page stands in rather than reconstructing them
  • r-rellock110 d9a041f — nineteen version surfaces was already wrong before this -- the lockfile makes it twenty-one, and the count is only ever known after the gate says so
  • r-relmanifest110 d9a041f — this is the release commit's own repair, not a fix -- the next release will need the same regeneration for the same reason
  • r-namefile716 f728e69 — only failures name their file; a successful wire still reports no path
  • r-namefile716 f728e69 — this makes the cursor question answerable on the next Windows run -- it does not answer it, and the outcome (failed) was never in doubt
  • r-overlay709 7e08cbf — unattended is an input to the effective digest but not to the defaults digest -- M-UX: capture leaves the user's workflow #511's exclusion rests on a file's identity being its own bytes, which an overlay breaks
  • r-overlay709 7e08cbf — a broken overlay falls back to the built-in defaults, not to the committed file -- layering onto a policy nobody could read states an effective policy no file states
  • r-wintmp716 f0ed513 — this fixes the write, not the detection -- codex, hermes and claude-code failed for the second cause and still will
  • r-wintmp716 f0ed513 — no Windows machine has run this fix; the guard proves the name, not the install
  • r-pend710 b452535 — the wording is checked, not the severity — an abandoned draft still warns
  • r-rel102 25c11ed — an installer-boundary fix reaches nobody until it is released
  • r-codexok 9021dd9 — a requested integration that failed is not a healthy host
  • r-697codx ae6245f — one owner per host step, in the place both installers call
  • r-693curr 14909c3 — a hook records a path that does not name a release
  • r-693mut2 14909c3 — a rejection test names what does the rejecting
  • r-rel101 b65e34f — a distribution-boundary fix reaches nobody until it is released
  • r-689host c0e909b — a host is wired or reported undetected, never absent
  • r-686skil adbe186 — a permanent config never records a path that belongs to one invocation
  • r-682herm 2e64424 — recognition is by field, never by formatting
  • r-680ver 47359a1 — an assertion that reads the source it checks proves nothing
  • r-rel100 47359a1 — a published install URL must resolve the moment it is published
  • r-status550 de514ea — a setting and a behaviour never share one word
  • r-590gate 63e48fa — the preregistered verdict is the authority for published M5 figures
  • r-g1build 63e48fa — identity travels as version and digest, never as a path
  • r-g1e2e1 63e48fa — parity is only measured across process boundaries
  • r-gateplan 63e48fa — a plan that lives only in a session is lost at the next compaction
  • r-631cov 92c1b37 — coverage describes the index, history describes the sources
  • r-638bnd 2607bae — git reports the message's origin, not the commit's
  • r-cleanrebuild664 da8948d — the manifest binds dist to committed source, so any uncommitted edit anywhere in src makes a local verification meaningless — this is a property of the check, not of this branch
  • r-formatnotmachine661 2cc274d — verified locally only; whether the warning list's numbering also shifts when the check flips is a question only CI answers, because the runners are where the two runs actually diverged
  • r-selfscan661 ccab7f4 — ancestry is only knowable while the ancestor lives; a server orphaned by a doctor that has already exited is indistinguishable from any other session's, and is correctly counted as one
  • r-liveruntime660 6a221db — ps is the seam, so this reports nothing on win32 and says so rather than claiming a clean machine
  • r-committedat650 f077870 — this pins the spelling, not the clock; nothing here makes two gits agree about anything else in %cI
  • r-prosetrailer647 30e40c7 — this changes the advice, not the outcome; the commit is still refused, which is correct while git reads the line as a trailer
  • r-repointsays629 c7ab87e — this reports the move, it does not verify the new target runs — hooks status owns that check and is unchanged here
  • r-childtreediag640 69c98a0 — the diagnosis is printed, not asserted — the next failure explains itself but the step still cannot say which outcome is acceptable
  • r-childtreepre640 69c98a0 — windows-latest is the only evidence for this path; nothing here was verified locally
  • r-coldstart640 69c98a0 — this measures the launcher's own child; it does not measure when cmd.exe started, so a stall before node is attributed to the same interval
  • r-launchernode640 69c98a0 — the earlier commit raising the probe budget to 15s stands on its own measurement — a healthy probe used 4478ms of 5000ms — but its message claimed that budget explained this flakiness, and it did not
  • r-launcherwhy640 69c98a0 — the deadline explanation is two independent diagnoses and a margin measurement, not a reproduction — the confirming evidence is the next run's own output
  • r-mcpidentity572 69c98a0 — Windows behaviour here rests on windows-latest runs and nothing else; a slower machine than three times the measured passing case will still be told it could not be verified, which is at least true
  • r-nodedrive640 69c98a0 — this reproduces the spawn, not the whole probe; a silent result narrows the cause without naming the fix
  • r-probefacts572 69c98a0 — the close-stdin outcome is measured, not guaranteed by the shell -- a platform whose shell defers the redirect past the parent's first write would produce the timeout code instead, and this case would then need its own seam rather than a looser assertion
  • r-proberace572 69c98a0 — this leaves one outcome unpinned, so a regression that swapped closed-input for timed-out on that fixture would not be caught here -- the four other cases still pin their codes exactly
  • r-reclaimnogate640 69c98a0 — windows-latest is the only evidence for this path, and one green run does not settle a race — this needs to hold across runs before The MCP probe's Windows behaviour is unverified: PATHEXT resolution and child-tree cleanup #640 can be called closed
  • r-sawinput640 69c98a0 — this records the arrival, not the response; if bytes arrive and nothing comes back, the next question is the probe's reader
  • r-slownotbroken640 69c98a0 — fifteen seconds is calibrated against one Windows runner's measurement; a machine slower than three times that will still be told it could not be verified, which is at least now true
  • r-mirrorsays632 aafd5ab — this states the retry, it does not verify it — nothing here checks that the following push actually published the note
  • r-keyringgen653 8b066c7 — the generation identifies the keys the verifier can list, not every reason git might reach a different verdict; expiry and revocation are outside what this binds
  • r-preflight002 0dca998 — MCP capture advertisement requires package manifest, SPEC, and schema to be available in the active runtime
  • r-recheck002 0dca998 — a readiness answer is only as fresh as the request that asked for it; nothing here prevents an asset vanishing between the check and the work
  • r-canon605 f474cf4 — esbuild resolves a platform-specific binary
  • r-rel0820 59c6730 — release versions must agree across manifests, lockfile roots, installer pins, and the runtime CLI
  • r-pretag01 86e0153 — registers_commitlore reads the key, so a config that registers under a different key -- a host with its own naming -- still reads as unregistered and is wired again
  • r-engfloor01 fe83524 — the parser covers the range shapes npm packages actually publish -- comparators like >=22 <23, and pre-release identifiers, are read by their first version and not by their bounds
  • r-nodefloor1 f4c924f — this bounds the version, not the feature -- a Node that ships node:sqlite behind a flag, or removes it, is not detected here
  • r-release081 ffe702a — the capture half reaches a host that surfaces MCP instructions; one that ignores that field still needs --agents-md, and nothing detects which kind a host is
  • r-cdeb10reg 48bd5a8 — wrong-path viability, deterministic oracle feasibility, code disclosure, bounded implementation, and unproven ordinary or benchmark authorship cannot be decided from history and remain undecided for human review
  • r-cdeb08an 60db89f — the paired bootstrap describes resampling stability within these five frozen repositories and thirty frozen tasks, and says nothing about any other repository, task or agent population
  • r-rel071 af8e0ab — 0.7.0 stays published with its notes amended to name the defect at the top; retracting a tag people may already have installed trades a known-bad version for an unknown one
  • r-rel070 d4a4d8b — the README's behaviour claim now rests on M5 while the generated numbers block beneath it still publishes M4, which is The README's generated numbers block still publishes M4; M5 measured the thing the README leads with #480 rather than a release-time edit
  • r-cdebver01 ce7b278 — the schemas freeze protocol 1.2.0 constants -- thresholds, matrix size, category names -- so a protocol change is a schema change and CI notices
  • r-m5analysis 3450656 — the script enforces the row count, not the identity of the rows; a run that produced 1,160 rows under a changed harness would satisfy it, which is what harness_commit and dist_digest on each row are for
  • r-benchscope 67f4375 — nothing checks the shape of the eight metric-row files. This gate names them and steps over them, and bench/deterministic/types.ts is the only definition that family has -- there is no JSON schema for it, so drift on that side is still invisible
  • r-benchscope 67f4375 — the pre-provenance exemption reads started_at, which is data on the row rather than a fact about the file. A row that misreported it would be held to the shorter list of requirements; that is a deliberate falsification rather than the omission this fixes, and nothing here detects it
  • r-3c9d52 dc9e769 — the sweep is two git log calls per path and the delivery phase runs git log --follow on every tracked path, so a full run over the four externals is hours rather than minutes on one machine
  • r-rel060 e999b9d — the install one-liner in all four READMEs now points at a tag that does not exist until this is tagged, so the window between merging to main and pushing v0.6.0 is one where the documented install is broken
  • r-release051 19810d2 — the hook is written at install time, so no release repairs a repository that already has one; every release touching hook behaviour has to restate what does
  • r-convertreadme e12c816 — a README claim about the default workflow is only true if the shipped skill performs it, and the skill currently requires the user to name CommitLore first
  • r-release050 ad402c7 — the hook is written at install time, so a corrected release never reaches a repository that already has one; every release fixing hook behaviour has to say what repairs an existing install
  • r-rel041notes 71efe1f — 0.4.1 makes the installer honest about a verification it cannot complete rather than fixing the kill, so an upgrading user may still see the unverified message instead of a version
  • r-rel040notes 5d57a72 — the 26.3-point density gap quoted in the notes is measured at this head and will drift with merge volume; it is illustrative of the denominator problem rather than a stable figure
  • r-rel021a a79e350 — v0.2.0 remains on the remote with no release attached
  • r-fix93pkg 9c4a396 — package.json remains a development artifact (build, typecheck, dependency floor) -- it is not read as a distribution manifest by anything in this repository
  • r-relinstall c6e1d04 — never tested against the real GitHub release infrastructure (no release exists yet — that is the owner's action) — verified against a locally built SEA binary, a hand-made SHA256SUMS, and a local HTTP server standing in for GitHub's release-asset redirects, which is everything this repository lets a change verify before a tag exists.
  • r-adr0012 e263059 — node:sqlite is experimental and version-gated -- it does not exist before Node 22.5, which satisfies but predates the >=22 floor in package.json; loadDatabaseCtor stays lazy so that gap degrades to --no-index instead of breaking validate/guard/parse
  • r-det058 695cdf6 — the suite must need no model, agent, network or uncommitted benchmark input
  • r-7a3e91 cf859e4 — better-sqlite3 stays external because it is native — the bundle degrades to --no-index without it, which only works because r-6f2a08 made that load lazy first
  • r-4a8e15 49e12c7 — git's grammar requires a subject before a trailer block, so a serialized block is not by itself a parseable message
  • r-7e5f02 e5f5e00 — npm installs through an engine mismatch, so the ecosystem's own signal cannot be relied on to stop anything
  • r-5a8c04 c46a577 — git owns the definition of a trailer block, so any behavior we cannot get from interpret-trailers is behavior we must not invent
  • r-c0f4e2 3d249cd — npm gitlore is held by an active same-domain CLI, so the owner's first-choice name was not available
  • r-b2e7f1 00d348d — Parsing must delegate to git interpret-trailers -- reimplementing the block rules would drift from the rest of the git ecosystem

Ruled out (249)

  • r-ef0defcd69a8 11ef133 — publishing this release as 1.6.1 rather than 1.7.0 | COMMITLORE_DOCTOR_REMOTE_TIMEOUT_MS is a new setting and hooks install has a new way to exit 2, and 1.6.0 set the rule that a new configuration key makes a minor
  • r-276fed4dac2b d71a55c — publishing this release as a patch rather than a minor | commitlore.syncRemote is a new configuration key and a dry run's --json outcomes changed names
  • r-release151 94e85f9 — keeping the regenerated manifest in the release commit | canonical-merge refuses that path outright, and the canonical build is what writes it
  • r-release151 94e85f9 — publishing this version bump as a minor release rather than a patch | the only user-facing change is the folded-block withholding defect, and a defect fix that adds no command, flag or trailer key is a patch
  • r-release151 94e85f9 — bumping the CHANGELOG's 1.5.0 heading or the ADR's gitlore@1.5.0 | the first is the previous release's own heading and the second is another package
  • r-release151 94e85f9 — text-replacing the version in the lockfile | it also matches dependencies genuinely at that version, and no test reads those fields, so the corruption is silent
  • r-treebind1030 ad4c4ef — resolving the repository from the caller's argument | r-emptystageddiff911 refused it and the refusal stands -- a caller that names the tree would turn a wrong-tree answer into a wrong-tree write, where an assertion can only produce a refusal
  • r-treebind1030 ad4c4ef — inferring the caller's working directory from the process tree | MCP carries no such field and the inference is wrong in exactly the multi-worktree case this exists for, which would make the check fail where it is needed
  • r-treebind1030 ad4c4ef — refusing every prepare whose staged diff is empty | it is the report's preferred shape and r-emptystageddiff911 already measured it out: it removes recording a decision with no code change and contradicts harvest --prompt-only emits nothing without a staged diff, though the contract it prints is static #310
  • r-treebind1030 ad4c4ef — naming the repository in the harvest prompt's no-diff branch | text present only in that branch inflates the pricing scaffold above a real prompt, which test/token-ledger.test.ts refuses -- the same rejection r-emptystageddiff911 recorded
  • r-treebind1030 ad4c4ef — git rev-parse --path-format=absolute for the common dir | it is git 2.31 and later, and this package states no git floor beyond "and Git", so it would turn a correct assertion into a refusal on the oldest runtime
  • r-measurewrites988 4edfd9f — PRAGMA page_count deltas for write amplification | it measures growth, and freelist reuse is invisible to it -- which is how the zero was produced
  • r-measurewrites988 4edfd9f — whole-database bytes divided by a row count | it prices a proposed table with the average of every existing structure
  • r-buildbeforetest960 346006a — a vitest globalSetup that builds | it would build for every invocation including a single-file run during a debugging loop, where the developer is already rebuilding deliberately
  • r-buildbeforetest960 346006a — a test asserting dist matches src | a local esbuild bundle is not byte-identical to the canonical Docker build that is committed, so the comparison is red in a clean checkout
  • r-believablesuite960 3ee700c — making the mutation check a CI gate | a gate would be answered by tests that fail for any mutation, which is not the same as tests that check the property
  • r-believablesuite960 3ee700c — splitting the suite into a fast tier and a history tier | the split runs along a line nobody can maintain -- most files build a temporary repository and a handful read the real one, and the boundary moves every time a test is added; bounding the parallelism needs no boundary
  • r-believablesuite960 3ee700c — lowering the global testTimeout and giving every slow test its own | it moves the same contention limit rather than removing it, which the vitest 4 upgrade already measured
  • r-pinnedmirror957 a06b984 — a rev-parse after the pass to detect that the ref moved | it is detection rather than closure, costs a process, and still leaves the caller holding rows it has to throw away
  • r-pinnedmirror957 a06b984 — accepting the window because it self-corrects | it corrects on the next call only while the ref keeps moving; a ref that returns to the stamped value leaves the mixture in place indefinitely
  • r-pinnedmirror957 a06b984 — cat-file --batch-command to fetch bodies and commit fields together | its format atoms carry no committer date and no %G?, and an embedded signature is not git's verification verdict
  • r-pinnedmirror957 a06b984 — re-scoping a resumed queue against the current mirror | the rows already written came from the earlier scope, so re-scoping would mix two of them under one stamp -- the defect this closes, arriving by another route
  • r-probeconsumers975 adcbd50 — batching inside collectRange | it is squash-preserve's reader and doctor's, not validate's, and batching there changed neither command -- the stack attribution is what found the reader that mattered
  • r-probeconsumers975 adcbd50 — memoising the note blocks by sha alone | the reference pass sees sources with no sha yet, which is the case the commit-msg hook takes, so the cache is keyed on the message text
  • r-probeconsumers975 adcbd50 — pairing noteMessages with readRecordBlocks | both call showNote, so the batch would have read every note twice and spent more processes than it saved
  • r-probeconsumers975 adcbd50 — writing the measurement rule down without a harness | I had noticed this failure three times before making it a fourth, so noticing is demonstrably not the mechanism
  • r-monotonic968 8f5ee12 — holding the writer lock across the scan | it closes the unbudgeted case too, and serialises cold rebuilds on exactly the path the budget exists to keep bounded
  • r-monotonic968 8f5ee12 — recording an indexed-commit count to compare against | scan_pending already carries it, and a second number for the same fact is a second thing that can disagree with the rows
  • r-monotonic968 8f5ee12 — comparing without pinning HEAD | two rebuilds against different heads owe different things, so the comparison would refuse a rebuild that is not worse, only different
  • r-monotonic968 8f5ee12 — accepting the regression because it is recoverable | it is recoverable over later calls, and the answers given in between come from an index that was complete a moment earlier
  • r-probebatch951 8d78b62 — appending the marker to the paragraph | git accepts a group holding a recognised trailer once a quarter of its lines are trailers, so one appended line can carry a paragraph over the threshold and manufacture a block; and a scissors line swallows an appended marker while still emitting the trailers above it, which moves those records into the next paragraph's answer
  • r-probebatch951 8d78b62 — counting markers against the answers written | that detects a duplicate index and not a missing one, so the scissors case passed it -- the count has to be against the inputs, in order, or it is checking its own output
  • r-probebatch951 8d78b62 — a trailer atom for a note's body | %N is the note text and %(trailers) parses the annotated commit's message; adding both to one format does not compose them, so a note's own block stays a process
  • r-probebatch951 8d78b62 — deciding a paragraph's shape without git | SPEC 2.1 B3 is unreproducible by line matching, and the 25% rule found here is a second reason the rule is not the one a regex would encode
  • r-atomreuse951 eb2869d — tightening the candidate prefilter in the same change | the necessary condition a tighter filter would test is "a line beginning with the exact key", and trailer.<token>.key lets a repository configure an alias git would emit that key from, so a pure regex cannot be a sound filter without first reading that configuration
  • r-atomreuse951 eb2869d — batching the candidate parses into one process here | git processes several files in one invocation but emits nothing between them, so attribution needs a sentinel trailer appended to each paragraph; that is a real design with a real proof obligation and does not belong in a change whose whole claim is that it altered no row
  • r-atomreuse951 eb2869d — passing the stripped trailers as the last block | stripConventional can empty a block that git parsed as non-empty, which changes blocks.length <= 1 and so which messages are treated as multi-block; the raw atom field is what the existing entry point takes
  • r-resume951 83f5629 — a positional watermark into rev-list <head> | grafts, git replace and a deepened shallow clone all change that list without changing the commit it starts from, so the saved offset silently addresses different work
  • r-resume951 83f5629 — deriving the unread set from rows already stored | a commit with no trailers leaves no row, so a processed recordless commit and an unread one are indistinguishable in trailers and commit_paths
  • r-resume951 83f5629 — making the budgeted incremental resumable with its own watermark | its range overlaps scan_pending, and two watermarks over overlapping ranges can disagree about which commits are owed
  • r-resume951 83f5629 — leaving the drain the whole remaining budget | it converged in four calls and made every budgeted call cost the full ceiling, which is the edit hook's latency on every fire until the backlog cleared
  • r-release1219 6fd1ed5 — holding the mode-only fix for its own release | it is a wrong verdict that prescribes writing records onto a commit, and it has shipped in every version measured
  • r-release1219 6fd1ed5 — a minor version | nothing gained a command or changed a contract; one verdict got narrower and three paths stopped repeating themselves
  • r-release1218 3ba5d09 — folding this into 1.2.17 | that release is tagged and published, and the guard's whole claim is that it would have failed on it
  • r-release1218 3ba5d09 — a minor version | nothing gained a command or changed a contract; a test artifact moved and a test was added
  • r-release1218 3ba5d09 — shipping the baseline in spec | package.json ships that directory, and 80 KB of one implementation's regression record is not the protocol
  • r-release1217 4836a95 — holding the two fixes for separate releases | they are one report from two directions, the second was found while fixing the first, and their fixtures share a directory and a test
  • r-release1217 4836a95 — a minor version for the new capture refusal | it refuses a draft that would have been withheld anyway, so no record that reaches a reader today stops reaching one
  • r-release1217 4836a95 — text-replacing the version in the JSON files | the lockfile holds dependency versions that resemble ours
  • r-release1216 573d14c — calling this a minor release | nothing gained a command or changed a contract; vantage is a field added to an envelope, and the rest are fixes to what existing surfaces report
  • r-release1216 573d14c — holding the parser change for its own release | it shares a file and a test harness with the notes fix, and separating them would leave a commit whose source and tests disagree
  • r-release1216 573d14c — text-replacing the version in the JSON files | package-lock.json holds dependency versions that resemble ours closely enough for a careless pattern to reach one
  • r-release1215 b6d2cfe — text-replacing the version in the JSON files too | package-lock.json holds dependency versions that resemble ours, and one of them is close enough that a careless pattern reaches it
  • r-release1215 b6d2cfe — releasing as 1.3.0 rather than a patch version | every change here is a fix to how a diagnostic reports, and no command's contract or output schema moved
  • r-release1215 b6d2cfe — holding README's squash-inheritance workflow omits the required cli-path input, so the recipe as published cannot run #926 for its own release | the broken recipe is published and reachable now, and the row that hid it shipped in the same version
  • r-release1214 6e91b8e — replace 1.2.13 globally across tracked files | it would rewrite the changelog heading and the rolldown dependency, which are not pins on this project
  • r-release1213 86f6dab — replace 1.2.12 globally across tracked files | it would rewrite the changelog heading and the rolldown dependency, which are not pins on this project
  • r-release1213 86f6dab — leave the README action pin unbumped | a reader copying the workflow would wire an older action than the CLI they just installed, and nothing else in the suite reads that line
  • r-release1212 0e93f7c — fold the version bump into the fix commit | the pins move as one surface and two tests assert them together, so a partial bump fails CI in a way that reads as a test problem
  • r-release1212 0e93f7c — replace 1.2.11 globally across tracked files | it would rewrite the changelog heading and the rolldown dependency, which are not pins on this project
  • r-release1211 24dbdcf — fold the version bump into the fix commits | the pins move as one surface and two tests assert them together, so a partial bump fails CI in a way that reads as a test problem
  • r-release1211 24dbdcf — replace 1.2.10 globally across tracked files | it would rewrite the changelog heading and the rolldown dependency, which are not pins on this project
  • r-release1210 da1cc9f — fold the version bump into the fix commits | the pins move as one surface and two tests assert them together, so a partial bump fails CI in a way that reads as a test problem
  • r-release1210 da1cc9f — replace 1.2.9 globally across tracked files | it would rewrite the changelog heading and the rolldown dependency, which are not pins on this project
  • r-release129 276feed — text-replacing the version across the manifests | it has matched a real dependency in two of the last four releases, at a different name each time
  • r-release128 795791c — text-replacing the version across the manifests | it has matched a real dependency in two of the last three releases, at a different name each time
  • r-release127 ba88444 — text-replacing the version across the manifests | rolldown and its fifteen bindings are at 1.2.6, so this release would have corrupted over fifty lockfile lines that no test reads
  • r-release127 ba88444 — bumping every v1.2.6 in the READMEs | only the three install shapes are pins, and README.md's release-boundary prose is a historical statement
  • r-honoadvisory d339291 — npm audit fix as written | it also strips all ten libc hints from the optional platform packages, which is how npm chooses glibc against musl binaries, and this project installs on musl in CI
  • r-honoadvisory d339291 — an npm overrides entry pinning hono | the SDK's own ^4.11.4 already admits the fixed version, so an override would add a permanent constraint to work around nothing
  • r-honoadvisory d339291 — waiting for a new @modelcontextprotocol/sdk | it is already the newest published version, and the advisory blocks the release now
  • r-release126 55e8d79 — text-replacing the version across the manifests | it also matches dependencies genuinely at that version, and which dependency that is changes from release to release
  • r-release126 55e8d79 — bumping every v1.2.5 in the READMEs | the install shapes are the only pins; README.md's release-boundary prose is a historical statement no test guards
  • r-release125 9d03977 — text-replacing the version across all manifests | it also matches four dependencies genuinely at that version, and no test reads them
  • r-release125 9d03977 — bumping every v1.2.4 found in the READMEs | README.md's release-boundary prose is a historical statement, and moving it makes the document say something false that no test checks
  • r-reviewcaughtserverjson c7debaf — bumping server.json without adding it to the gate | the bump fixes this release and nothing else; the gate not reading it is the defect, and the Codex manifest note in that same script is the record of what happens when only the bump is done
  • r-reviewcaughtserverjson c7debaf — anchoring REMOTE_NOT_FOUND but leaving the timeout to fall through it | a tightened expression still cannot see that ETIMEDOUT is present and load-bearing; the precedence has to be explicit or the next phrasing that slips through erases it again
  • r-reviewcaughtserverjson c7debaf — amending the earlier commits so the branch reads as if this was right the first time | the review finding is the evidence that the gate has a hole, and rewriting it away would leave the hole documented nowhere
  • r-release121 9845d44 — releasing the security fix alone and holding the rest | it was already merged and the remaining advisories are only reachable through the vitest upgrade, so a fix-only release would have left five of the seven, one critical, in a tree that says it is production ready
  • r-release121 9845d44 — one branch per remaining pull request | main requires its checks against the current base, so each merge invalidates the others and costs a full 45-minute cycle; five sequential merges buy no evidence that one branch carrying five recorded commits does not
  • r-depsbatchbump 42013a6 — repairing chore(deps-dev): bump js-yaml from 5.2.3 to 5.4.1 in the dev-dependencies group #862 and chore(deps): bump @modelcontextprotocol/sdk from 1.29.0 to 1.30.0 #863 on their own branches | each regenerates the same manifest file, so the first to merge invalidates the second; the cost is a rebuild and a full CI cycle per bump for no additional evidence
  • r-depsbatchbump 42013a6 — npm audit fix --force alongside these | the remaining advisories are dev-only and its breaking upgrades are the vitest major question, which is a separate decision with a measured cost
  • r-fasturiqsaudit 1752273 — fixing this on each dependency pull request instead | the advisories are on main, so each branch would carry an identical lockfile and dist change and the three would conflict with each other on merge
  • r-fasturiqsaudit 1752273 — npm audit fix --force | it also rewrites the dev tree through breaking upgrades, which is the vitest major question and not a security fix; the five remaining advisories are dev-only and outside what CI's --omit=dev gate asserts
  • r-cdebmanifest d64b006 — running npm run artifact:manifest alone without the canonical build | it would have produced this same one-line diff, but from an unverified assumption that dist could not have moved; the build is what turns that into an observation
  • r-cdebmanifest d64b006 — putting the manifest update into the previous commit by amending it | that commit is pushed and force-pushing is not available here, so the correction is additive
  • r-cdebremoval 36ae3ab — archiving bench/cdeb to a tag or an orphan branch instead of deleting | the instruction was to discard it, and the history already holds every version; a tag would be a second place to keep something nobody is to consult
  • r-cdebremoval 36ae3ab — keeping guard-mutations and pointing its registry at product tests | it had never guarded a product test, so re-aiming it would be new work introduced under a removal, and it belongs in its own change if it is wanted
  • r-cdebremoval 36ae3ab — leaving the two jobs in ci.yml as no-ops so the workflow digest and REQUIRED_CHECKS could stay | a required check that cannot fail is the shape this repository's release gate exists to reject
  • r-v5stage1r1reviewfixes 87cacec — treating the reviewer's findings as claims to weigh | six of them were statements about what the code does, and running the code settled each one in under a minute
  • r-v5stage1r1reviewfixes 87cacec — keeping 8 repeats and reporting the detectable effect as a range | the range was over a parameter the design had no way to obtain, which is how an operator ends up choosing the favourable end of it
  • r-v5stage1r1reviewfixes 87cacec — lowering the minimum important effect to what 8 repeats reaches | that is the move the HOLD rule exists to refuse, and writing it into the rule that refuses it would have been circular
  • r-v5stage1r1reviewfixes 87cacec — claiming the pilot custody finding was closed by the schema | the record now cannot carry an arm contrast and the operator can still have watched the runs; a control over bytes is not a control over people
  • r-v5stage1r1designlayer 28699d8 — filling the runtime lock with plausible placeholder values | an unpinned runtime that reads as pinned is worse than an empty lock, because the next reader stops asking
  • r-v5stage1r1designlayer 28699d8 — marking the 62 screen-surviving candidates BUILDABLE | the screens can only refute, and calling a candidate buildable without an oracle is the claim the census exists to check

Truncated: 222 lines omitted — the comment hit GitHub's 65000 character limit.

Trailer violations fail this check. Active constraints are informational — they are what the repository already decided, not a verdict on this PR.

@MongLong0214
MongLong0214 merged commit 0da586f into main Oct 3, 2026
13 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant