From b59adb6226fdc7b09b47895bd469a99b51700259 Mon Sep 17 00:00:00 2001 From: operator Date: Sat, 3 Oct 2026 17:28:41 +0900 Subject: [PATCH 1/3] chore(deps): keep @types/node on the supported runtime floor `engines.node` is `>=22.23.2` and `@types/node` is pinned `^22.10.0` for that reason: the types describe the oldest runtime this package supports, not the newest one that exists. Dependabot opened the 22 -> 26 bump as #1151. It typechecks cleanly, which is exactly the problem -- types from a later major admit APIs node 22 does not have, and the type checker is the only thing that would refuse them, so a release would compile here and fail on a runtime the package claims to support. A major bump here is a decision about the support floor, made by hand next to `engines`. The ignore rule says so instead of leaving a pull request to be closed unread every month. Minor and patch updates inside the pinned major still arrive, and a security advisory ignores the block entirely. Limit: `engines.node` is `>=22.23.2` and `@types/node` is pinned `^22.10.0`, so the types track the oldest supported runtime rather than the newest that exists Ruled-out: taking the 22 -> 26 major bump of @types/node (#1151) | types from a later major describe APIs node 22 does not have, and the type checker is the only thing that would refuse them, so a release would compile here and fail on a supported runtime Warn: a green typecheck on a `@types/node` major bump is not evidence the bump is safe; the floor is `engines.node`, and nothing in the suite asks whether an API exists on the oldest runtime Blast: module Undo: easy Certainty: firm Record-Id: r-typesnodefloor Provenance: drafted --- .github/dependabot.yml | 15 +++++++++++++++ 1 file changed, 15 insertions(+) diff --git a/.github/dependabot.yml b/.github/dependabot.yml index 7a22fe3e..2f36ba66 100644 --- a/.github/dependabot.yml +++ b/.github/dependabot.yml @@ -16,6 +16,21 @@ updates: dev-dependencies: dependency-type: development update-types: [minor, patch] + ignore: + # `@types/node` tracks the oldest runtime this package supports, not the + # newest one that exists. `engines.node` is `>=22.23.2` and the dependency + # is pinned `^22.10.0` for that reason: types from a later major describe + # APIs node 22 does not have, and the type checker is the only thing that + # would refuse them -- a release would compile here and fail on a + # supported runtime. Dependabot opened the 22 -> 26 bump as #1151, which + # typechecked cleanly and was still wrong for that reason. + # + # A major bump here is therefore a decision about the support floor, made + # by hand together with `engines`, not a monthly pull request. Minor and + # patch updates inside the pinned major still arrive as usual, and a + # security advisory ignores this block entirely. + - dependency-name: '@types/node' + update-types: ['version-update:semver-major'] commit-message: # Dependabot commits on GitHub's side, so the local commit-msg hook never # sees them. What does see them is the dogfooding gate, which validates From 9c88c0ced5850ef0c63bb222b5360517abe97992 Mon Sep 17 00:00:00 2001 From: operator Date: Sat, 3 Oct 2026 18:13:55 +0900 Subject: [PATCH 2/3] release: prepare 1.7.3 squash inheritance fix --- .claude-plugin/plugin.json | 2 +- .codex-plugin/plugin.json | 2 +- CHANGELOG.md | 23 +++++++++++++++++++++++ README.ja.md | 16 ++++++++-------- README.ko.md | 16 ++++++++-------- README.md | 16 ++++++++-------- README.zh-CN.md | 16 ++++++++-------- install.ps1 | 4 ++-- install.sh | 4 ++-- package-lock.json | 4 ++-- package.json | 2 +- server.json | 6 +++--- 12 files changed, 67 insertions(+), 44 deletions(-) diff --git a/.claude-plugin/plugin.json b/.claude-plugin/plugin.json index edb7d9c4..3d4bf4a0 100644 --- a/.claude-plugin/plugin.json +++ b/.claude-plugin/plugin.json @@ -1,7 +1,7 @@ { "name": "commitlore", "displayName": "CommitLore", - "version": "1.7.2", + "version": "1.7.3", "description": "Recorded decisions from git history, delivered to the agent before it edits. Constraints, alternatives already ruled out, and warnings left by whoever was here last.", "author": { "name": "MongLong0214", diff --git a/.codex-plugin/plugin.json b/.codex-plugin/plugin.json index 42545df4..153ad9db 100644 --- a/.codex-plugin/plugin.json +++ b/.codex-plugin/plugin.json @@ -1,6 +1,6 @@ { "name": "commitlore", - "version": "1.7.2", + "version": "1.7.3", "description": "Decision memory from Git history, with verified capture for coding sessions.", "author": { "name": "MongLong0214", diff --git a/CHANGELOG.md b/CHANGELOG.md index 4503b240..4ec3625e 100644 --- a/CHANGELOG.md +++ b/CHANGELOG.md @@ -4,6 +4,29 @@ Release notes for 1.0.0, 1.0.1 and 1.0.2 are on the [GitHub releases page](https://github.com/MongLong0214/commitlore/releases); they were not written here. +## 1.7.3 + +- **A trailer paragraph that carries no record is no longer inherited as one + (#1153).** Git reads a message's last paragraph as a trailer block whatever + its keys mean, so `squash-preserve` collected a merge commit whose only + trailer was `Claude-Session:` as an inherited record, stamped it + `Provenance: inherited `, and composed a message `commitlore validate` + then refused as `unknown-key` — blocking the squash merge it had been run to + protect. An inherited block now carries only the keys SPEC §3 defines, per + trailer rather than per block, so a paragraph that mixes `Limit:` with a + foreign key keeps its record and loses only the foreign key, and a block left + with nothing contributes nothing. The identity-collision check compares an + inherited copy by its record content, so a faithful copy of such a record is + no longer reported as `duplicate-id`. + +- **Dependencies.** `@modelcontextprotocol/sdk` 1.30.1, `js-yaml` 5.4.2 (dev), + and `docker/setup-qemu-action` v4.4.0 in CI. `@types/node` stays on 22.x: + `engines.node` is `>=22.23.2`, and types from a later major would admit APIs + that runtime does not have. + +This is a patch release: it repairs existing squash and validation behavior and +adds no command, flag, trailer key, or host setting. + ## 1.7.2 - **Squash-preserved drafts validate against their reachable originals (#1147).** diff --git a/README.ja.md b/README.ja.md index 70106f3e..5e1e0286 100644 --- a/README.ja.md +++ b/README.ja.md @@ -47,18 +47,18 @@

```bash -curl -fsSL https://raw.githubusercontent.com/MongLong0214/commitlore/v1.7.2/install.sh | sh -s v1.7.2 +curl -fsSL https://raw.githubusercontent.com/MongLong0214/commitlore/v1.7.3/install.sh | sh -s v1.7.3 ```
先にインストーラーを読みたいですか? ```bash -curl -fsSLO https://raw.githubusercontent.com/MongLong0214/commitlore/v1.7.2/install.sh -sh install.sh v1.7.2 +curl -fsSLO https://raw.githubusercontent.com/MongLong0214/commitlore/v1.7.3/install.sh +sh install.sh v1.7.3 # あるいはスクリプトを使わずに。スクリプトが作るチェックアウトは自分でも作れます。 -git clone --depth 1 --branch v1.7.2 https://github.com/MongLong0214/commitlore +git clone --depth 1 --branch v1.7.3 https://github.com/MongLong0214/commitlore node commitlore/dist/commitlore.mjs --version ``` @@ -107,13 +107,13 @@ CommitLore はその判断をコードのそばに残します。 macOS と Linux: ```bash -curl -fsSL https://raw.githubusercontent.com/MongLong0214/commitlore/v1.7.2/install.sh | sh -s v1.7.2 +curl -fsSL https://raw.githubusercontent.com/MongLong0214/commitlore/v1.7.3/install.sh | sh -s v1.7.3 ``` Windows: ```powershell -& ([scriptblock]::Create((irm https://raw.githubusercontent.com/MongLong0214/commitlore/v1.7.2/install.ps1))) v1.7.2 +& ([scriptblock]::Create((irm https://raw.githubusercontent.com/MongLong0214/commitlore/v1.7.3/install.ps1))) v1.7.3 ``` Node.js 22.23.2+ と Git が必要です。スクリプトは何かを書き込む前に両方を確認します。 @@ -294,11 +294,11 @@ jobs: - uses: actions/checkout@v4 with: repository: MongLong0214/commitlore - ref: v1.7.2 + ref: v1.7.3 path: .commitlore-cli persist-credentials: false - - uses: MongLong0214/commitlore/action/preserve@v1.7.2 + - uses: MongLong0214/commitlore/action/preserve@v1.7.3 with: cli-path: .commitlore-cli/dist/cli.js ``` diff --git a/README.ko.md b/README.ko.md index ea35d7dc..2fa7f626 100644 --- a/README.ko.md +++ b/README.ko.md @@ -47,18 +47,18 @@

```bash -curl -fsSL https://raw.githubusercontent.com/MongLong0214/commitlore/v1.7.2/install.sh | sh -s v1.7.2 +curl -fsSL https://raw.githubusercontent.com/MongLong0214/commitlore/v1.7.3/install.sh | sh -s v1.7.3 ```
먼저 설치기를 읽어 보고 싶나요? ```bash -curl -fsSLO https://raw.githubusercontent.com/MongLong0214/commitlore/v1.7.2/install.sh -sh install.sh v1.7.2 +curl -fsSLO https://raw.githubusercontent.com/MongLong0214/commitlore/v1.7.3/install.sh +sh install.sh v1.7.3 # 또는 스크립트를 건너뜁니다. 스크립트가 만드는 체크아웃은 직접 만들 수 있습니다. -git clone --depth 1 --branch v1.7.2 https://github.com/MongLong0214/commitlore +git clone --depth 1 --branch v1.7.3 https://github.com/MongLong0214/commitlore node commitlore/dist/commitlore.mjs --version ``` @@ -107,13 +107,13 @@ CommitLore는 그 판단을 코드 곁에 보관합니다. macOS와 Linux: ```bash -curl -fsSL https://raw.githubusercontent.com/MongLong0214/commitlore/v1.7.2/install.sh | sh -s v1.7.2 +curl -fsSL https://raw.githubusercontent.com/MongLong0214/commitlore/v1.7.3/install.sh | sh -s v1.7.3 ``` Windows: ```powershell -& ([scriptblock]::Create((irm https://raw.githubusercontent.com/MongLong0214/commitlore/v1.7.2/install.ps1))) v1.7.2 +& ([scriptblock]::Create((irm https://raw.githubusercontent.com/MongLong0214/commitlore/v1.7.3/install.ps1))) v1.7.3 ``` Node.js 22.23.2+와 Git이 필요합니다. 스크립트는 무엇이든 쓰기 전에 둘을 확인합니다. @@ -292,11 +292,11 @@ jobs: - uses: actions/checkout@v4 with: repository: MongLong0214/commitlore - ref: v1.7.2 + ref: v1.7.3 path: .commitlore-cli persist-credentials: false - - uses: MongLong0214/commitlore/action/preserve@v1.7.2 + - uses: MongLong0214/commitlore/action/preserve@v1.7.3 with: cli-path: .commitlore-cli/dist/cli.js ``` diff --git a/README.md b/README.md index 0978d2ef..ab407608 100644 --- a/README.md +++ b/README.md @@ -48,18 +48,18 @@

```bash -curl -fsSL https://raw.githubusercontent.com/MongLong0214/commitlore/v1.7.2/install.sh | sh -s v1.7.2 +curl -fsSL https://raw.githubusercontent.com/MongLong0214/commitlore/v1.7.3/install.sh | sh -s v1.7.3 ```
Prefer to read the installer first? ```bash -curl -fsSLO https://raw.githubusercontent.com/MongLong0214/commitlore/v1.7.2/install.sh -sh install.sh v1.7.2 +curl -fsSLO https://raw.githubusercontent.com/MongLong0214/commitlore/v1.7.3/install.sh +sh install.sh v1.7.3 # Or skip the script: the checkout it makes is one you can make yourself. -git clone --depth 1 --branch v1.7.2 https://github.com/MongLong0214/commitlore +git clone --depth 1 --branch v1.7.3 https://github.com/MongLong0214/commitlore node commitlore/dist/commitlore.mjs --version ``` @@ -109,13 +109,13 @@ preserve, not for narrating every change. macOS and Linux: ```bash -curl -fsSL https://raw.githubusercontent.com/MongLong0214/commitlore/v1.7.2/install.sh | sh -s v1.7.2 +curl -fsSL https://raw.githubusercontent.com/MongLong0214/commitlore/v1.7.3/install.sh | sh -s v1.7.3 ``` Windows: ```powershell -& ([scriptblock]::Create((irm https://raw.githubusercontent.com/MongLong0214/commitlore/v1.7.2/install.ps1))) v1.7.2 +& ([scriptblock]::Create((irm https://raw.githubusercontent.com/MongLong0214/commitlore/v1.7.3/install.ps1))) v1.7.3 ``` Requires Node.js 22.23.2+ and Git. The script checks both before it writes anything. @@ -304,11 +304,11 @@ jobs: - uses: actions/checkout@v4 with: repository: MongLong0214/commitlore - ref: v1.7.2 + ref: v1.7.3 path: .commitlore-cli persist-credentials: false - - uses: MongLong0214/commitlore/action/preserve@v1.7.2 + - uses: MongLong0214/commitlore/action/preserve@v1.7.3 with: cli-path: .commitlore-cli/dist/cli.js ``` diff --git a/README.zh-CN.md b/README.zh-CN.md index c3a8f879..67c782de 100644 --- a/README.zh-CN.md +++ b/README.zh-CN.md @@ -47,18 +47,18 @@

```bash -curl -fsSL https://raw.githubusercontent.com/MongLong0214/commitlore/v1.7.2/install.sh | sh -s v1.7.2 +curl -fsSL https://raw.githubusercontent.com/MongLong0214/commitlore/v1.7.3/install.sh | sh -s v1.7.3 ```
想先阅读安装器吗? ```bash -curl -fsSLO https://raw.githubusercontent.com/MongLong0214/commitlore/v1.7.2/install.sh -sh install.sh v1.7.2 +curl -fsSLO https://raw.githubusercontent.com/MongLong0214/commitlore/v1.7.3/install.sh +sh install.sh v1.7.3 # 或者跳过脚本:它创建的检出,你自己也能创建。 -git clone --depth 1 --branch v1.7.2 https://github.com/MongLong0214/commitlore +git clone --depth 1 --branch v1.7.3 https://github.com/MongLong0214/commitlore node commitlore/dist/commitlore.mjs --version ``` @@ -105,13 +105,13 @@ CommitLore 把那份判断留在代码旁边。 macOS 和 Linux: ```bash -curl -fsSL https://raw.githubusercontent.com/MongLong0214/commitlore/v1.7.2/install.sh | sh -s v1.7.2 +curl -fsSL https://raw.githubusercontent.com/MongLong0214/commitlore/v1.7.3/install.sh | sh -s v1.7.3 ``` Windows: ```powershell -& ([scriptblock]::Create((irm https://raw.githubusercontent.com/MongLong0214/commitlore/v1.7.2/install.ps1))) v1.7.2 +& ([scriptblock]::Create((irm https://raw.githubusercontent.com/MongLong0214/commitlore/v1.7.3/install.ps1))) v1.7.3 ``` 需要 Node.js 22.23.2+ 和 Git。脚本会在写入任何内容前检查两者。 @@ -286,11 +286,11 @@ jobs: - uses: actions/checkout@v4 with: repository: MongLong0214/commitlore - ref: v1.7.2 + ref: v1.7.3 path: .commitlore-cli persist-credentials: false - - uses: MongLong0214/commitlore/action/preserve@v1.7.2 + - uses: MongLong0214/commitlore/action/preserve@v1.7.3 with: cli-path: .commitlore-cli/dist/cli.js ``` diff --git a/install.ps1 b/install.ps1 index a1379a21..853c5489 100644 --- a/install.ps1 +++ b/install.ps1 @@ -1,8 +1,8 @@ <# Installs commitlore from source on Windows, for any agent that is not Claude Code. - irm https://raw.githubusercontent.com/MongLong0214/commitlore/v1.7.2/install.ps1 | iex - & ([scriptblock]::Create((irm https://raw.githubusercontent.com/MongLong0214/commitlore/v1.7.2/install.ps1))) v1.7.2 + irm https://raw.githubusercontent.com/MongLong0214/commitlore/v1.7.3/install.ps1 | iex + & ([scriptblock]::Create((irm https://raw.githubusercontent.com/MongLong0214/commitlore/v1.7.3/install.ps1))) v1.7.3 Claude Code users do not need this script. The repository is itself a plugin marketplace (ADR-0011), so two /plugin commands register the MCP server, the diff --git a/install.sh b/install.sh index 744e197c..2dd07937 100755 --- a/install.sh +++ b/install.sh @@ -1,8 +1,8 @@ #!/bin/sh # Installs commitlore from source, for any agent that is not Claude Code. # -# curl -fsSL https://raw.githubusercontent.com/MongLong0214/commitlore/v1.7.2/install.sh | sh -# curl -fsSL https://raw.githubusercontent.com/MongLong0214/commitlore/v1.7.2/install.sh | sh -s v1.7.2 +# curl -fsSL https://raw.githubusercontent.com/MongLong0214/commitlore/v1.7.3/install.sh | sh +# curl -fsSL https://raw.githubusercontent.com/MongLong0214/commitlore/v1.7.3/install.sh | sh -s v1.7.3 # # **Claude Code users do not need this script.** The repository is itself a # plugin marketplace (ADR-0011), so two `/plugin` commands register the MCP diff --git a/package-lock.json b/package-lock.json index 8408af54..c2f139a0 100644 --- a/package-lock.json +++ b/package-lock.json @@ -1,12 +1,12 @@ { "name": "commitlore", - "version": "1.7.2", + "version": "1.7.3", "lockfileVersion": 3, "requires": true, "packages": { "": { "name": "commitlore", - "version": "1.7.2", + "version": "1.7.3", "license": "MIT", "dependencies": { "@modelcontextprotocol/sdk": "^1.30.1", diff --git a/package.json b/package.json index 21f1df20..f0f4aec3 100644 --- a/package.json +++ b/package.json @@ -1,6 +1,6 @@ { "name": "commitlore", - "version": "1.7.2", + "version": "1.7.3", "description": "Git-native, lifecycle-aware decision memory for coding agents", "license": "MIT", "private": true, diff --git a/server.json b/server.json index 4ae68313..6aee7817 100644 --- a/server.json +++ b/server.json @@ -8,7 +8,7 @@ "source": "github" }, "websiteUrl": "https://github.com/MongLong0214/commitlore#readme", - "version": "1.7.2", + "version": "1.7.3", "_meta": { "io.modelcontextprotocol.registry/publisher-provided": { "registryFit": "Distribution is a tagged git checkout plus a Claude Code plugin marketplace (ADR-0011 registry-free git distribution, ADR-0026 no compiled executables and no uploaded release asset), so no official package type applies and this record relies on websiteUrl plus publisher metadata.", @@ -18,8 +18,8 @@ "/plugin marketplace add MongLong0214/commitlore", "/plugin install commitlore@commitlore" ], - "installer": "curl -fsSL https://raw.githubusercontent.com/MongLong0214/commitlore/v1.7.2/install.sh | sh -s v1.7.2", - "release": "https://github.com/MongLong0214/commitlore/releases/tag/v1.7.2" + "installer": "curl -fsSL https://raw.githubusercontent.com/MongLong0214/commitlore/v1.7.3/install.sh | sh -s v1.7.3", + "release": "https://github.com/MongLong0214/commitlore/releases/tag/v1.7.3" }, "runtime": { "transport": "stdio", From c04d20aea9b4d262925fec43e0706c7c2e8d80d8 Mon Sep 17 00:00:00 2001 From: "commitlore-canonical-build[bot]" <317873099+commitlore-canonical-build[bot]@users.noreply.github.com> Date: Sat, 3 Oct 2026 09:15:29 +0000 Subject: [PATCH 3/3] Rebuild the canonical bundle for #1158 `build:canonical` on the merged tree, so the commit that lands matches the source it lands with. The pull request carried source only, which is what a contributor on a host that cannot run a linux/amd64 Docker build can produce (#720). Limit: this proves the bundle matches this tree; whether this tree is what a reviewer wants is what the pull request is for Blast: system Undo: easy Certainty: firm Record-Id: r-canonmerge1158 Provenance: authored Verified: artifact:verify passed against the regenerated manifest in the same job, before any credential was available to it CommitLore-Version: 2.0.0 --- installer/canonical-artifact.json | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/installer/canonical-artifact.json b/installer/canonical-artifact.json index 2535efb9..ed098cc4 100644 --- a/installer/canonical-artifact.json +++ b/installer/canonical-artifact.json @@ -15,7 +15,7 @@ "tsconfig.json", "src" ], - "sha256": "77fa87b6c582e68281004d4d098563652b138e81ff64e290c7c1b7288a222368" + "sha256": "a8efc178582f8cf52e75466177c304b136795a93c7e50b5738c9f16adbf7179c" }, "artifact": { "sha256": "148696fcc3cda54db7e539c2cb63ab40eebc325e7ff5c2ab7c82a8599ed75e8b",