From b59adb6226fdc7b09b47895bd469a99b51700259 Mon Sep 17 00:00:00 2001
From: operator
Date: Sat, 3 Oct 2026 17:28:41 +0900
Subject: [PATCH 1/2] chore(deps): keep @types/node on the supported runtime
floor
`engines.node` is `>=22.23.2` and `@types/node` is pinned `^22.10.0` for that
reason: the types describe the oldest runtime this package supports, not the
newest one that exists. Dependabot opened the 22 -> 26 bump as #1151. It
typechecks cleanly, which is exactly the problem -- types from a later major
admit APIs node 22 does not have, and the type checker is the only thing that
would refuse them, so a release would compile here and fail on a runtime the
package claims to support.
A major bump here is a decision about the support floor, made by hand next to
`engines`. The ignore rule says so instead of leaving a pull request to be
closed unread every month. Minor and patch updates inside the pinned major
still arrive, and a security advisory ignores the block entirely.
Limit: `engines.node` is `>=22.23.2` and `@types/node` is pinned `^22.10.0`, so the types track the oldest supported runtime rather than the newest that exists
Ruled-out: taking the 22 -> 26 major bump of @types/node (#1151) | types from a later major describe APIs node 22 does not have, and the type checker is the only thing that would refuse them, so a release would compile here and fail on a supported runtime
Warn: a green typecheck on a `@types/node` major bump is not evidence the bump is safe; the floor is `engines.node`, and nothing in the suite asks whether an API exists on the oldest runtime
Blast: module
Undo: easy
Certainty: firm
Record-Id: r-typesnodefloor
Provenance: drafted
---
.github/dependabot.yml | 15 +++++++++++++++
1 file changed, 15 insertions(+)
diff --git a/.github/dependabot.yml b/.github/dependabot.yml
index 7a22fe3e..2f36ba66 100644
--- a/.github/dependabot.yml
+++ b/.github/dependabot.yml
@@ -16,6 +16,21 @@ updates:
dev-dependencies:
dependency-type: development
update-types: [minor, patch]
+ ignore:
+ # `@types/node` tracks the oldest runtime this package supports, not the
+ # newest one that exists. `engines.node` is `>=22.23.2` and the dependency
+ # is pinned `^22.10.0` for that reason: types from a later major describe
+ # APIs node 22 does not have, and the type checker is the only thing that
+ # would refuse them -- a release would compile here and fail on a
+ # supported runtime. Dependabot opened the 22 -> 26 bump as #1151, which
+ # typechecked cleanly and was still wrong for that reason.
+ #
+ # A major bump here is therefore a decision about the support floor, made
+ # by hand together with `engines`, not a monthly pull request. Minor and
+ # patch updates inside the pinned major still arrive as usual, and a
+ # security advisory ignores this block entirely.
+ - dependency-name: '@types/node'
+ update-types: ['version-update:semver-major']
commit-message:
# Dependabot commits on GitHub's side, so the local commit-msg hook never
# sees them. What does see them is the dogfooding gate, which validates
From 9c88c0ced5850ef0c63bb222b5360517abe97992 Mon Sep 17 00:00:00 2001
From: operator
Date: Sat, 3 Oct 2026 18:13:55 +0900
Subject: [PATCH 2/2] release: prepare 1.7.3 squash inheritance fix
---
.claude-plugin/plugin.json | 2 +-
.codex-plugin/plugin.json | 2 +-
CHANGELOG.md | 23 +++++++++++++++++++++++
README.ja.md | 16 ++++++++--------
README.ko.md | 16 ++++++++--------
README.md | 16 ++++++++--------
README.zh-CN.md | 16 ++++++++--------
install.ps1 | 4 ++--
install.sh | 4 ++--
package-lock.json | 4 ++--
package.json | 2 +-
server.json | 6 +++---
12 files changed, 67 insertions(+), 44 deletions(-)
diff --git a/.claude-plugin/plugin.json b/.claude-plugin/plugin.json
index edb7d9c4..3d4bf4a0 100644
--- a/.claude-plugin/plugin.json
+++ b/.claude-plugin/plugin.json
@@ -1,7 +1,7 @@
{
"name": "commitlore",
"displayName": "CommitLore",
- "version": "1.7.2",
+ "version": "1.7.3",
"description": "Recorded decisions from git history, delivered to the agent before it edits. Constraints, alternatives already ruled out, and warnings left by whoever was here last.",
"author": {
"name": "MongLong0214",
diff --git a/.codex-plugin/plugin.json b/.codex-plugin/plugin.json
index 42545df4..153ad9db 100644
--- a/.codex-plugin/plugin.json
+++ b/.codex-plugin/plugin.json
@@ -1,6 +1,6 @@
{
"name": "commitlore",
- "version": "1.7.2",
+ "version": "1.7.3",
"description": "Decision memory from Git history, with verified capture for coding sessions.",
"author": {
"name": "MongLong0214",
diff --git a/CHANGELOG.md b/CHANGELOG.md
index 4503b240..4ec3625e 100644
--- a/CHANGELOG.md
+++ b/CHANGELOG.md
@@ -4,6 +4,29 @@ Release notes for 1.0.0, 1.0.1 and 1.0.2 are on the
[GitHub releases page](https://github.com/MongLong0214/commitlore/releases); they
were not written here.
+## 1.7.3
+
+- **A trailer paragraph that carries no record is no longer inherited as one
+ (#1153).** Git reads a message's last paragraph as a trailer block whatever
+ its keys mean, so `squash-preserve` collected a merge commit whose only
+ trailer was `Claude-Session:` as an inherited record, stamped it
+ `Provenance: inherited `, and composed a message `commitlore validate`
+ then refused as `unknown-key` — blocking the squash merge it had been run to
+ protect. An inherited block now carries only the keys SPEC §3 defines, per
+ trailer rather than per block, so a paragraph that mixes `Limit:` with a
+ foreign key keeps its record and loses only the foreign key, and a block left
+ with nothing contributes nothing. The identity-collision check compares an
+ inherited copy by its record content, so a faithful copy of such a record is
+ no longer reported as `duplicate-id`.
+
+- **Dependencies.** `@modelcontextprotocol/sdk` 1.30.1, `js-yaml` 5.4.2 (dev),
+ and `docker/setup-qemu-action` v4.4.0 in CI. `@types/node` stays on 22.x:
+ `engines.node` is `>=22.23.2`, and types from a later major would admit APIs
+ that runtime does not have.
+
+This is a patch release: it repairs existing squash and validation behavior and
+adds no command, flag, trailer key, or host setting.
+
## 1.7.2
- **Squash-preserved drafts validate against their reachable originals (#1147).**
diff --git a/README.ja.md b/README.ja.md
index 70106f3e..5e1e0286 100644
--- a/README.ja.md
+++ b/README.ja.md
@@ -47,18 +47,18 @@
```bash
-curl -fsSL https://raw.githubusercontent.com/MongLong0214/commitlore/v1.7.2/install.sh | sh -s v1.7.2
+curl -fsSL https://raw.githubusercontent.com/MongLong0214/commitlore/v1.7.3/install.sh | sh -s v1.7.3
```
先にインストーラーを読みたいですか?
```bash
-curl -fsSLO https://raw.githubusercontent.com/MongLong0214/commitlore/v1.7.2/install.sh
-sh install.sh v1.7.2
+curl -fsSLO https://raw.githubusercontent.com/MongLong0214/commitlore/v1.7.3/install.sh
+sh install.sh v1.7.3
# あるいはスクリプトを使わずに。スクリプトが作るチェックアウトは自分でも作れます。
-git clone --depth 1 --branch v1.7.2 https://github.com/MongLong0214/commitlore
+git clone --depth 1 --branch v1.7.3 https://github.com/MongLong0214/commitlore
node commitlore/dist/commitlore.mjs --version
```
@@ -107,13 +107,13 @@ CommitLore はその判断をコードのそばに残します。
macOS と Linux:
```bash
-curl -fsSL https://raw.githubusercontent.com/MongLong0214/commitlore/v1.7.2/install.sh | sh -s v1.7.2
+curl -fsSL https://raw.githubusercontent.com/MongLong0214/commitlore/v1.7.3/install.sh | sh -s v1.7.3
```
Windows:
```powershell
-& ([scriptblock]::Create((irm https://raw.githubusercontent.com/MongLong0214/commitlore/v1.7.2/install.ps1))) v1.7.2
+& ([scriptblock]::Create((irm https://raw.githubusercontent.com/MongLong0214/commitlore/v1.7.3/install.ps1))) v1.7.3
```
Node.js 22.23.2+ と Git が必要です。スクリプトは何かを書き込む前に両方を確認します。
@@ -294,11 +294,11 @@ jobs:
- uses: actions/checkout@v4
with:
repository: MongLong0214/commitlore
- ref: v1.7.2
+ ref: v1.7.3
path: .commitlore-cli
persist-credentials: false
- - uses: MongLong0214/commitlore/action/preserve@v1.7.2
+ - uses: MongLong0214/commitlore/action/preserve@v1.7.3
with:
cli-path: .commitlore-cli/dist/cli.js
```
diff --git a/README.ko.md b/README.ko.md
index ea35d7dc..2fa7f626 100644
--- a/README.ko.md
+++ b/README.ko.md
@@ -47,18 +47,18 @@
```bash
-curl -fsSL https://raw.githubusercontent.com/MongLong0214/commitlore/v1.7.2/install.sh | sh -s v1.7.2
+curl -fsSL https://raw.githubusercontent.com/MongLong0214/commitlore/v1.7.3/install.sh | sh -s v1.7.3
```
먼저 설치기를 읽어 보고 싶나요?
```bash
-curl -fsSLO https://raw.githubusercontent.com/MongLong0214/commitlore/v1.7.2/install.sh
-sh install.sh v1.7.2
+curl -fsSLO https://raw.githubusercontent.com/MongLong0214/commitlore/v1.7.3/install.sh
+sh install.sh v1.7.3
# 또는 스크립트를 건너뜁니다. 스크립트가 만드는 체크아웃은 직접 만들 수 있습니다.
-git clone --depth 1 --branch v1.7.2 https://github.com/MongLong0214/commitlore
+git clone --depth 1 --branch v1.7.3 https://github.com/MongLong0214/commitlore
node commitlore/dist/commitlore.mjs --version
```
@@ -107,13 +107,13 @@ CommitLore는 그 판단을 코드 곁에 보관합니다.
macOS와 Linux:
```bash
-curl -fsSL https://raw.githubusercontent.com/MongLong0214/commitlore/v1.7.2/install.sh | sh -s v1.7.2
+curl -fsSL https://raw.githubusercontent.com/MongLong0214/commitlore/v1.7.3/install.sh | sh -s v1.7.3
```
Windows:
```powershell
-& ([scriptblock]::Create((irm https://raw.githubusercontent.com/MongLong0214/commitlore/v1.7.2/install.ps1))) v1.7.2
+& ([scriptblock]::Create((irm https://raw.githubusercontent.com/MongLong0214/commitlore/v1.7.3/install.ps1))) v1.7.3
```
Node.js 22.23.2+와 Git이 필요합니다. 스크립트는 무엇이든 쓰기 전에 둘을 확인합니다.
@@ -292,11 +292,11 @@ jobs:
- uses: actions/checkout@v4
with:
repository: MongLong0214/commitlore
- ref: v1.7.2
+ ref: v1.7.3
path: .commitlore-cli
persist-credentials: false
- - uses: MongLong0214/commitlore/action/preserve@v1.7.2
+ - uses: MongLong0214/commitlore/action/preserve@v1.7.3
with:
cli-path: .commitlore-cli/dist/cli.js
```
diff --git a/README.md b/README.md
index 0978d2ef..ab407608 100644
--- a/README.md
+++ b/README.md
@@ -48,18 +48,18 @@
```bash
-curl -fsSL https://raw.githubusercontent.com/MongLong0214/commitlore/v1.7.2/install.sh | sh -s v1.7.2
+curl -fsSL https://raw.githubusercontent.com/MongLong0214/commitlore/v1.7.3/install.sh | sh -s v1.7.3
```
Prefer to read the installer first?
```bash
-curl -fsSLO https://raw.githubusercontent.com/MongLong0214/commitlore/v1.7.2/install.sh
-sh install.sh v1.7.2
+curl -fsSLO https://raw.githubusercontent.com/MongLong0214/commitlore/v1.7.3/install.sh
+sh install.sh v1.7.3
# Or skip the script: the checkout it makes is one you can make yourself.
-git clone --depth 1 --branch v1.7.2 https://github.com/MongLong0214/commitlore
+git clone --depth 1 --branch v1.7.3 https://github.com/MongLong0214/commitlore
node commitlore/dist/commitlore.mjs --version
```
@@ -109,13 +109,13 @@ preserve, not for narrating every change.
macOS and Linux:
```bash
-curl -fsSL https://raw.githubusercontent.com/MongLong0214/commitlore/v1.7.2/install.sh | sh -s v1.7.2
+curl -fsSL https://raw.githubusercontent.com/MongLong0214/commitlore/v1.7.3/install.sh | sh -s v1.7.3
```
Windows:
```powershell
-& ([scriptblock]::Create((irm https://raw.githubusercontent.com/MongLong0214/commitlore/v1.7.2/install.ps1))) v1.7.2
+& ([scriptblock]::Create((irm https://raw.githubusercontent.com/MongLong0214/commitlore/v1.7.3/install.ps1))) v1.7.3
```
Requires Node.js 22.23.2+ and Git. The script checks both before it writes anything.
@@ -304,11 +304,11 @@ jobs:
- uses: actions/checkout@v4
with:
repository: MongLong0214/commitlore
- ref: v1.7.2
+ ref: v1.7.3
path: .commitlore-cli
persist-credentials: false
- - uses: MongLong0214/commitlore/action/preserve@v1.7.2
+ - uses: MongLong0214/commitlore/action/preserve@v1.7.3
with:
cli-path: .commitlore-cli/dist/cli.js
```
diff --git a/README.zh-CN.md b/README.zh-CN.md
index c3a8f879..67c782de 100644
--- a/README.zh-CN.md
+++ b/README.zh-CN.md
@@ -47,18 +47,18 @@
```bash
-curl -fsSL https://raw.githubusercontent.com/MongLong0214/commitlore/v1.7.2/install.sh | sh -s v1.7.2
+curl -fsSL https://raw.githubusercontent.com/MongLong0214/commitlore/v1.7.3/install.sh | sh -s v1.7.3
```
想先阅读安装器吗?
```bash
-curl -fsSLO https://raw.githubusercontent.com/MongLong0214/commitlore/v1.7.2/install.sh
-sh install.sh v1.7.2
+curl -fsSLO https://raw.githubusercontent.com/MongLong0214/commitlore/v1.7.3/install.sh
+sh install.sh v1.7.3
# 或者跳过脚本:它创建的检出,你自己也能创建。
-git clone --depth 1 --branch v1.7.2 https://github.com/MongLong0214/commitlore
+git clone --depth 1 --branch v1.7.3 https://github.com/MongLong0214/commitlore
node commitlore/dist/commitlore.mjs --version
```
@@ -105,13 +105,13 @@ CommitLore 把那份判断留在代码旁边。
macOS 和 Linux:
```bash
-curl -fsSL https://raw.githubusercontent.com/MongLong0214/commitlore/v1.7.2/install.sh | sh -s v1.7.2
+curl -fsSL https://raw.githubusercontent.com/MongLong0214/commitlore/v1.7.3/install.sh | sh -s v1.7.3
```
Windows:
```powershell
-& ([scriptblock]::Create((irm https://raw.githubusercontent.com/MongLong0214/commitlore/v1.7.2/install.ps1))) v1.7.2
+& ([scriptblock]::Create((irm https://raw.githubusercontent.com/MongLong0214/commitlore/v1.7.3/install.ps1))) v1.7.3
```
需要 Node.js 22.23.2+ 和 Git。脚本会在写入任何内容前检查两者。
@@ -286,11 +286,11 @@ jobs:
- uses: actions/checkout@v4
with:
repository: MongLong0214/commitlore
- ref: v1.7.2
+ ref: v1.7.3
path: .commitlore-cli
persist-credentials: false
- - uses: MongLong0214/commitlore/action/preserve@v1.7.2
+ - uses: MongLong0214/commitlore/action/preserve@v1.7.3
with:
cli-path: .commitlore-cli/dist/cli.js
```
diff --git a/install.ps1 b/install.ps1
index a1379a21..853c5489 100644
--- a/install.ps1
+++ b/install.ps1
@@ -1,8 +1,8 @@
<#
Installs commitlore from source on Windows, for any agent that is not Claude Code.
- irm https://raw.githubusercontent.com/MongLong0214/commitlore/v1.7.2/install.ps1 | iex
- & ([scriptblock]::Create((irm https://raw.githubusercontent.com/MongLong0214/commitlore/v1.7.2/install.ps1))) v1.7.2
+ irm https://raw.githubusercontent.com/MongLong0214/commitlore/v1.7.3/install.ps1 | iex
+ & ([scriptblock]::Create((irm https://raw.githubusercontent.com/MongLong0214/commitlore/v1.7.3/install.ps1))) v1.7.3
Claude Code users do not need this script. The repository is itself a plugin
marketplace (ADR-0011), so two /plugin commands register the MCP server, the
diff --git a/install.sh b/install.sh
index 744e197c..2dd07937 100755
--- a/install.sh
+++ b/install.sh
@@ -1,8 +1,8 @@
#!/bin/sh
# Installs commitlore from source, for any agent that is not Claude Code.
#
-# curl -fsSL https://raw.githubusercontent.com/MongLong0214/commitlore/v1.7.2/install.sh | sh
-# curl -fsSL https://raw.githubusercontent.com/MongLong0214/commitlore/v1.7.2/install.sh | sh -s v1.7.2
+# curl -fsSL https://raw.githubusercontent.com/MongLong0214/commitlore/v1.7.3/install.sh | sh
+# curl -fsSL https://raw.githubusercontent.com/MongLong0214/commitlore/v1.7.3/install.sh | sh -s v1.7.3
#
# **Claude Code users do not need this script.** The repository is itself a
# plugin marketplace (ADR-0011), so two `/plugin` commands register the MCP
diff --git a/package-lock.json b/package-lock.json
index 8408af54..c2f139a0 100644
--- a/package-lock.json
+++ b/package-lock.json
@@ -1,12 +1,12 @@
{
"name": "commitlore",
- "version": "1.7.2",
+ "version": "1.7.3",
"lockfileVersion": 3,
"requires": true,
"packages": {
"": {
"name": "commitlore",
- "version": "1.7.2",
+ "version": "1.7.3",
"license": "MIT",
"dependencies": {
"@modelcontextprotocol/sdk": "^1.30.1",
diff --git a/package.json b/package.json
index 21f1df20..f0f4aec3 100644
--- a/package.json
+++ b/package.json
@@ -1,6 +1,6 @@
{
"name": "commitlore",
- "version": "1.7.2",
+ "version": "1.7.3",
"description": "Git-native, lifecycle-aware decision memory for coding agents",
"license": "MIT",
"private": true,
diff --git a/server.json b/server.json
index 4ae68313..6aee7817 100644
--- a/server.json
+++ b/server.json
@@ -8,7 +8,7 @@
"source": "github"
},
"websiteUrl": "https://github.com/MongLong0214/commitlore#readme",
- "version": "1.7.2",
+ "version": "1.7.3",
"_meta": {
"io.modelcontextprotocol.registry/publisher-provided": {
"registryFit": "Distribution is a tagged git checkout plus a Claude Code plugin marketplace (ADR-0011 registry-free git distribution, ADR-0026 no compiled executables and no uploaded release asset), so no official package type applies and this record relies on websiteUrl plus publisher metadata.",
@@ -18,8 +18,8 @@
"/plugin marketplace add MongLong0214/commitlore",
"/plugin install commitlore@commitlore"
],
- "installer": "curl -fsSL https://raw.githubusercontent.com/MongLong0214/commitlore/v1.7.2/install.sh | sh -s v1.7.2",
- "release": "https://github.com/MongLong0214/commitlore/releases/tag/v1.7.2"
+ "installer": "curl -fsSL https://raw.githubusercontent.com/MongLong0214/commitlore/v1.7.3/install.sh | sh -s v1.7.3",
+ "release": "https://github.com/MongLong0214/commitlore/releases/tag/v1.7.3"
},
"runtime": {
"transport": "stdio",