From fe962e3c5a800c4871c15c8bfd1bd27d49eb450a Mon Sep 17 00:00:00 2001 From: Mark Beacom Date: Wed, 30 Sep 2026 22:53:33 -0400 Subject: [PATCH 1/3] chore(release): prepare v0.16.0 Moves the lockstep surface to 0.16.0: the four public packages, CLI_VERSION, SERVER_INFO and server.json, bun.lock's workspace entries, and every documented pin (README, ci.mdx, badges.mdx, quickstart, the site hero, RELEASING.md, the bug-report template). The CHANGELOG's Unreleased section becomes 0.16.0, with what it was missing: - Security: the Action bundles' undici 6.29.0 (GHSA-rfgv-xxqx-mfg5, #251). It is the main reason to release now, since published v0 consumers still run 6.27.0. - Added: acceptAdrSource, a new @adrkit/core runtime export, which the release policy requires calling out. - Changed: adr queue --format defaults to auto (only a terminal sees a difference), and the Bun 1.4.2 toolchain move, which shrinks the Action bundles by dropping unused zod locales and helpers. The docs also catch up with adr accept, which adrkit.dev has described since #250 merged but npm doesn't ship yet: the AGENTS.md status line and the CLI README command lists name it, the CLI README and root README gain a short queue-and-accept section with the terminal view, and the container section lists accept among the commands that write. The Action bundles rebuild byte-identical under linux/amd64 Bun 1.4.2, and release:pack prepares all five packages for v0.16.0. Signed-off-by: Mark Beacom --- .github/ISSUE_TEMPLATE/bug_report.yml | 2 +- AGENTS.md | 4 ++-- CHANGELOG.md | 32 ++++++++++++++++++++++++++- README.md | 31 +++++++++++++++++++++----- bun.lock | 8 +++---- docs/RELEASING.md | 6 ++--- package.json | 2 +- packages/cli/README.md | 22 ++++++++++++++++++ packages/cli/package.json | 2 +- packages/cli/src/index.ts | 2 +- packages/cli/test/color.test.ts | 2 +- packages/core/package.json | 2 +- packages/evaluator/package.json | 2 +- packages/mcp/package.json | 2 +- packages/mcp/server.json | 4 ++-- packages/mcp/src/server.ts | 2 +- site/src/components/Hero.astro | 2 +- site/src/content/docs/badges.mdx | 4 ++-- site/src/content/docs/ci.mdx | 10 ++++----- site/src/content/docs/index.mdx | 2 +- site/src/content/docs/quickstart.mdx | 2 +- 21 files changed, 109 insertions(+), 36 deletions(-) diff --git a/.github/ISSUE_TEMPLATE/bug_report.yml b/.github/ISSUE_TEMPLATE/bug_report.yml index 2af99b3..950904a 100644 --- a/.github/ISSUE_TEMPLATE/bug_report.yml +++ b/.github/ISSUE_TEMPLATE/bug_report.yml @@ -31,7 +31,7 @@ body: attributes: label: adrkit version description: Output of `adr --version` (or the package version you installed). - placeholder: '0.15.0' + placeholder: '0.16.0' validations: required: true - type: dropdown diff --git a/AGENTS.md b/AGENTS.md index b7265b9..cc07bbc 100644 --- a/AGENTS.md +++ b/AGENTS.md @@ -2,9 +2,9 @@ Decision memory for human- and agent-authored plans — machine-readable ADRs that are enforceable in CI and legible to agents, without leaving git. -Status: early — phases 0–6 landed and v0.15.0 is public. `@adrkit/core`, +Status: early — phases 0–6 landed and v0.16.0 is public. `@adrkit/core`, `@adrkit/evaluator`, `@adrkit/cli` (`lint`, `new`, `graph`, `explain`, -`check`, `queue`, `migrate --from madr`, `evaluate`) are published on npm, as is +`check`, `queue`, `accept`, `migrate --from madr`, `evaluate`) are published on npm, as is the independently versioned `@adrkit/spec-kit` Spec Kit extension (0.1.4); the repository-backed CI Action is available at `mbeacom/adrkit/packages/ci@v0`. The governing-decisions Action also has a root `action.yml` alias for GitHub diff --git a/CHANGELOG.md b/CHANGELOG.md index 1bca149..cdf69a1 100644 --- a/CHANGELOG.md +++ b/CHANGELOG.md @@ -9,6 +9,19 @@ Until `1.0.0`, minor releases may include breaking changes ## [Unreleased] +## [0.16.0] - 2026-10-01 + +### Security + +- **The Action bundles carry `undici` 6.29.0**, up from 6.27.0, closing + [GHSA-rfgv-xxqx-mfg5](https://github.com/advisories/GHSA-rfgv-xxqx-mfg5) + (high): a denial of service through an unrequested WebSocket subprotocol. + `undici` reaches both Actions through `@actions/github` and + `@actions/http-client`. Consumers of `packages/ci@v0` and + `packages/ci/queue@v0` pick it up when `v0` moves to this release; anyone + pinned to `v0.15.0` or earlier should move to `v0.16.0` + ([#251](https://github.com/mbeacom/adrkit/pull/251)). + ### Added - **`adr accept --by `** ratifies a `proposed` record. It sets @@ -25,6 +38,22 @@ Until `1.0.0`, minor releases may include breaking changes blocked. Piped, redirected, and captured output is still the Markdown report, byte for byte. `--format terminal` and `--format markdown` choose explicitly. +- **`acceptAdrSource` in `@adrkit/core`**, the pure transition behind + `adr accept`: given a record's source text, a ratifier, and a timestamp, it + returns the new text or a typed refusal. This adds a runtime export. + +### Changed + +- **`adr queue --format` defaults to `auto` instead of `markdown`.** Only stdout + attached to a terminal sees a difference. Pipes, redirects, CI, the + managed-issue Action, and agents still receive the Markdown report byte for + byte, and `--format markdown` restores it in a terminal. +- **The toolchain moved from Bun 1.3.14 to 1.4.2** + ([#249](https://github.com/mbeacom/adrkit/pull/249)). The published packages + are still Node-targeted and are now built with 1.4.2. The Action bundles are + about 25% smaller because 1.4.2 drops the parts of `zod` nothing calls: + every error-message locale except English, and unused helpers. Every other bundled + dependency is unchanged. ## [0.15.0] - 2026-09-28 @@ -1696,7 +1725,8 @@ against live Spec Kit, rather than reasoning about it: - Node-targeted published distribution of all packages, smoke-tested under Node 22 and 24. -[Unreleased]: https://github.com/mbeacom/adrkit/compare/v0.15.0...HEAD +[Unreleased]: https://github.com/mbeacom/adrkit/compare/v0.16.0...HEAD +[0.16.0]: https://github.com/mbeacom/adrkit/compare/v0.15.0...v0.16.0 [0.15.0]: https://github.com/mbeacom/adrkit/compare/v0.14.0...v0.15.0 [0.14.0]: https://github.com/mbeacom/adrkit/compare/v0.13.0...v0.14.0 [0.13.0]: https://github.com/mbeacom/adrkit/compare/v0.12.0...v0.13.0 diff --git a/README.md b/README.md index a40144f..0874659 100644 --- a/README.md +++ b/README.md @@ -93,8 +93,8 @@ docker run --rm --read-only --network none -i \ The MCP command keeps stdin open because MCP uses stdio. Its repository mount is read-only, matching the server contract; use an absolute host path in MCP client -configuration. For CLI commands that intentionally write (`new`, or -`migrate` without `--dry-run`), omit `--read-only` and the mount's `:ro` +configuration. For CLI commands that intentionally write (`new`, `accept`, +or `migrate` without `--dry-run`), omit `--read-only` and the mount's `:ro` suffix. The image runs as the non-root `node` user; on a host with a different UID/GID, add `--user "$(id -u):$(id -g)"`. On SELinux hosts, add the appropriate bind-mount label (for example, `:Z`). @@ -152,6 +152,22 @@ Corpus fingerprint: `96e7f3185c5bb89bd1c87e10a28dcbef66703f381d3f14ea486ceaf2990 | 2 | `0015` | Validate descriptors against Backstage field formats … | arb | within-sla | 2027-01-25 | 0/- | 0 | ``` +That is what a pipe, a CI job, or an agent receives. In a terminal the same +report prints as a list sized to the window, and each item ends with its next +step — the command to accept it, or the reason it cannot be accepted yet: + +```text +1. 0044 within-sla · due 2027-03-31 (in 182 days) + Ratify a proposed record with adr accept and present the queue for terminals + async · asynchronous human review + approvals 0 · objections 0 · route @mbeacom + docs/adr/0044-ratify-a-proposed-record-with-adr-accept-and-present-the-queue-for-terminals.md + next: adr accept 0044 --by +``` + +`adr accept 0044 --by @you` then sets `status`, `provenance.ratifiedBy`, and +`review.decidedAt`, and changes no other line, for review in a pull request. + In CI, the `@adrkit/ci` Action comments the governing decisions on the PRs that touch them — read-only, comment-only, no database, no approval. See [Use in CI](https://adrkit.dev/ci/). @@ -336,7 +352,12 @@ answer where the next decision is actually being made. approves, persists, or writes**. - **`adr queue`** — emit the ARB operations queue: a read-only, deterministic projection of the corpus's `review` metadata (tiers, SLA state, approvals, - objections) as Markdown or `QueueReport` v1 JSON; also a managed-issue Action. + objections) as Markdown or `QueueReport` v1 JSON, or as a list sized to the + window in a terminal; also a managed-issue Action. +- **`adr accept --by `** — ratify a `proposed` record from the + queue. It changes only `status`, `provenance.ratifiedBy`, and + `review.decidedAt`, refuses a record with an unresolved objection, an unmet + quorum, or a result that would not validate, and never infers who ratified. - **CI comment** — the `@adrkit/ci` GitHub Action surfaces the governing decisions on the PRs that touch or explicitly declare them; pattern matches render as `via` and PR-authored marker claims as `declared by`. The comment also distinguishes @@ -351,7 +372,7 @@ answer where the next decision is actually being made. It never approves anything. It routes, and humans decide. The root Marketplace entry point has shipped with every release since -`v0.13.0`. Pin its immutable root reference — currently `v0.15.0` — for the +`v0.13.0`. Pin its immutable root reference — currently `v0.16.0` — for the complete governing-decisions workflow (see [Use in CI](https://adrkit.dev/ci/)): @@ -370,7 +391,7 @@ jobs: runs-on: ubuntu-latest steps: - uses: actions/checkout@v4 - - uses: mbeacom/adrkit@v0.15.0 + - uses: mbeacom/adrkit@v0.16.0 ``` Existing consumers of the nested form can stay on diff --git a/bun.lock b/bun.lock index a33f347..33d5f35 100644 --- a/bun.lock +++ b/bun.lock @@ -55,7 +55,7 @@ }, "packages/cli": { "name": "@adrkit/cli", - "version": "0.15.0", + "version": "0.16.0", "bin": { "adr": "./dist/index.js", "adrkit": "./dist/index.js", @@ -70,7 +70,7 @@ }, "packages/core": { "name": "@adrkit/core", - "version": "0.15.0", + "version": "0.16.0", "dependencies": { "picomatch": "^4", "semver": "^7", @@ -85,7 +85,7 @@ }, "packages/evaluator": { "name": "@adrkit/evaluator", - "version": "0.15.0", + "version": "0.16.0", "dependencies": { "@adrkit/core": "workspace:*", "jsonpath-rfc9535": "1.3.0", @@ -96,7 +96,7 @@ }, "packages/mcp": { "name": "@adrkit/mcp", - "version": "0.15.0", + "version": "0.16.0", "bin": { "adrkit-mcp": "./dist/bin.js", }, diff --git a/docs/RELEASING.md b/docs/RELEASING.md index 4f0e354..99c7b1c 100644 --- a/docs/RELEASING.md +++ b/docs/RELEASING.md @@ -10,8 +10,8 @@ Actions, one Marketplace entry point, and one lockstep OCI image: | `@adrkit/cli` (`adr`, `adrkit`) | npm | | `@adrkit/mcp` (`adrkit-mcp`) | npm | | `action.yml` | GitHub Actions Marketplace and Git tag (governing-decisions alias; available beginning with `v0.13.0`) | -| `packages/ci/action.yml` | Git tag (existing governing-decisions subpath, latest immutable release `v0.15.0`, moving `v0`) | -| `packages/ci/queue/action.yml` | Git tag (nested queue Action, latest immutable release `v0.15.0`, moving `v0`) | +| `packages/ci/action.yml` | Git tag (existing governing-decisions subpath, latest immutable release `v0.16.0`, moving `v0`) | +| `packages/ci/queue/action.yml` | Git tag (nested queue Action, latest immutable release `v0.16.0`, moving `v0`) | | `ghcr.io/mbeacom/adrkit` | GitHub Container Registry (`vX.Y.Z`, moving `vX`, `latest`; begins with the first release containing ADR-0032) | `@adrkit/ci` stays private because GitHub executes the committed Action bundle @@ -23,7 +23,7 @@ Action intentionally remains nested. `scripts/marketplace-action-contract.test.t keeps the two governing-decisions metadata contracts identical except for their different bundle paths. -The coordinated lockstep surface is published; the current release is `v0.15.0`. `@adrkit/core`, +The coordinated lockstep surface is published; the current release is `v0.16.0`. `@adrkit/core`, `@adrkit/evaluator`, and `@adrkit/cli` use GitHub Actions Trusted Publishing. `@adrkit/mcp` was created with the isolated one-time bootstrap path below; its Trusted Publisher and token-restriction cleanup must be completed before the diff --git a/package.json b/package.json index a0b465c..b0c93a8 100644 --- a/package.json +++ b/package.json @@ -1,6 +1,6 @@ { "name": "adrkit", - "version": "0.15.0", + "version": "0.16.0", "description": "Decision memory for human and agent-authored plans \u2014 machine-readable, CI-enforceable architecture decision records.", "type": "module", "private": true, diff --git a/packages/cli/README.md b/packages/cli/README.md index 612c007..fe2ec20 100644 --- a/packages/cli/README.md +++ b/packages/cli/README.md @@ -54,6 +54,7 @@ The binary includes: - `explain` - `check` - `queue` +- `accept` - `migrate --from madr` - `completion` - `evaluate` @@ -61,6 +62,27 @@ The binary includes: Run `adr --help` for the command list, `adr help ` for one command's flags, and `adr --version` to print the installed version. +## Review queue and acceptance + +`adr queue` lists every `proposed` record with its SLA state, deadline, +approvals, and objections. In a terminal it prints a list sized to the window, +and each item ends with the next step: the command to accept it, or the reason +it cannot be accepted yet. Piped, redirected, or captured output is the +deterministic Markdown report, unchanged; `--format json` emits `QueueReport` +v1, and `--format terminal|markdown` choose explicitly. + +```bash +adr queue +adr accept 0044 --by @octocat +``` + +`adr accept` sets `status: accepted`, `provenance.ratifiedBy`, and +`review.decidedAt` (now, UTC, with seconds), and changes no other line. It +commits nothing. It refuses, and leaves the file untouched, when the record is +not `proposed`, has an unresolved objection, has fewer approvals than its +`review.quorum`, or would not be a valid accepted record. `--by` is required and +is never inferred. Exit codes: `0` accepted, `1` refused, `2` usage error. + ## Decision graph `adr graph` chooses its default at the stdout boundary: an interactive terminal diff --git a/packages/cli/package.json b/packages/cli/package.json index 3e71bc1..d0fdae5 100644 --- a/packages/cli/package.json +++ b/packages/cli/package.json @@ -1,6 +1,6 @@ { "name": "@adrkit/cli", - "version": "0.15.0", + "version": "0.16.0", "description": "Git-native architecture decision record tooling from adrkit.", "type": "module", "license": "Apache-2.0", diff --git a/packages/cli/src/index.ts b/packages/cli/src/index.ts index bb90f8c..7ef557b 100644 --- a/packages/cli/src/index.ts +++ b/packages/cli/src/index.ts @@ -69,7 +69,7 @@ import { getPresentation, setPresentation, styleUsageBlock, type ColorMode, type * (mirroring `@adrkit/mcp`'s `SERVER_INFO`) so the bundled `dist/index.js` never has * to locate `package.json` at runtime. `version.test.ts` asserts the two agree. */ -export const CLI_VERSION = '0.15.0'; +export const CLI_VERSION = '0.16.0'; function topLevelUsage(style?: StreamStyle): string { return renderTopLevelUsage(CLI_VERSION, style); diff --git a/packages/cli/test/color.test.ts b/packages/cli/test/color.test.ts index d9b10e0..8231d40 100644 --- a/packages/cli/test/color.test.ts +++ b/packages/cli/test/color.test.ts @@ -33,7 +33,7 @@ describe('CLI color presentation', () => { expect(result.exitCode).toBe(0); expect(result.stderr).toBe(''); expect(result.stdout).toContain('\u001b['); - expect(result.stdout).toContain('adrkit 0.15.0'); + expect(result.stdout).toContain('adrkit 0.16.0'); }); test('forced color keeps lint stdout and stderr separated', async () => { diff --git a/packages/core/package.json b/packages/core/package.json index 5a8ba3f..f34721e 100644 --- a/packages/core/package.json +++ b/packages/core/package.json @@ -1,6 +1,6 @@ { "name": "@adrkit/core", - "version": "0.15.0", + "version": "0.16.0", "description": "Pure ADR parsing, validation, migration, and affects resolution for adrkit.", "type": "module", "license": "Apache-2.0", diff --git a/packages/evaluator/package.json b/packages/evaluator/package.json index c82d73c..22daa46 100644 --- a/packages/evaluator/package.json +++ b/packages/evaluator/package.json @@ -1,6 +1,6 @@ { "name": "@adrkit/evaluator", - "version": "0.15.0", + "version": "0.16.0", "description": "Deterministic, model-free ADR proposal evaluation and routing for adrkit.", "type": "module", "license": "Apache-2.0", diff --git a/packages/mcp/package.json b/packages/mcp/package.json index a11a259..3476c9d 100644 --- a/packages/mcp/package.json +++ b/packages/mcp/package.json @@ -1,7 +1,7 @@ { "name": "@adrkit/mcp", "mcpName": "dev.adrkit/mcp", - "version": "0.15.0", + "version": "0.16.0", "description": "Local, read-only Model Context Protocol server exposing adrkit decision retrieval over stdio.", "type": "module", "license": "Apache-2.0", diff --git a/packages/mcp/server.json b/packages/mcp/server.json index a71aa54..4b103e2 100644 --- a/packages/mcp/server.json +++ b/packages/mcp/server.json @@ -3,7 +3,7 @@ "name": "dev.adrkit/mcp", "title": "adrkit decision memory", "description": "Deterministic, offline, read-only ADR decision memory for coding agents. No model or network calls.", - "version": "0.15.0", + "version": "0.16.0", "websiteUrl": "https://adrkit.dev", "repository": { "url": "https://github.com/mbeacom/adrkit", @@ -15,7 +15,7 @@ "registryType": "npm", "registryBaseUrl": "https://registry.npmjs.org", "identifier": "@adrkit/mcp", - "version": "0.15.0", + "version": "0.16.0", "runtimeHint": "npx", "transport": { "type": "stdio" diff --git a/packages/mcp/src/server.ts b/packages/mcp/src/server.ts index ee61eef..78e8713 100644 --- a/packages/mcp/src/server.ts +++ b/packages/mcp/src/server.ts @@ -14,7 +14,7 @@ import { registerGetDecisionContext } from './tools/get-decision-context.ts'; import { registerListSuperseded } from './tools/list-superseded.ts'; import type { ToolConfig } from './tools/shared.ts'; -export const SERVER_INFO = { name: '@adrkit/mcp', version: '0.15.0' } as const; +export const SERVER_INFO = { name: '@adrkit/mcp', version: '0.16.0' } as const; /** * The MCP protocol revision this server serves through `serveStdio`'s modern era. diff --git a/site/src/components/Hero.astro b/site/src/components/Hero.astro index b22e028..08a71d7 100644 --- a/site/src/components/Hero.astro +++ b/site/src/components/Hero.astro @@ -14,7 +14,7 @@ const { title = data.title, tagline, actions = [] } = data.hero || {}; CLI works today - v0.15.0 on npm · decision memory in git + v0.16.0 on npm · decision memory in git

diff --git a/site/src/content/docs/badges.mdx b/site/src/content/docs/badges.mdx index 5993c3f..23c8379 100644 --- a/site/src/content/docs/badges.mdx +++ b/site/src/content/docs/badges.mdx @@ -100,8 +100,8 @@ jobs: # current release. - run: | mkdir -p .adrkit - npx @adrkit/cli@0.15.0 queue --format json > .adrkit/queue.json.tmp - npx @adrkit/cli@0.15.0 lint --json > .adrkit/lint.json.tmp + npx @adrkit/cli@0.16.0 queue --format json > .adrkit/queue.json.tmp + npx @adrkit/cli@0.16.0 lint --json > .adrkit/lint.json.tmp # A truncated or malformed write renders as `no result` on the badge, which # reads as a bug in your tooling. Fail here instead of committing it. diff --git a/site/src/content/docs/ci.mdx b/site/src/content/docs/ci.mdx index ffc27fb..fe62d00 100644 --- a/site/src/content/docs/ci.mdx +++ b/site/src/content/docs/ci.mdx @@ -42,7 +42,7 @@ jobs: runs-on: ubuntu-latest steps: - uses: actions/checkout@v4 - - uses: mbeacom/adrkit@v0.15.0 + - uses: mbeacom/adrkit@v0.16.0 # with: # dir: docs/adr # ADR corpus directory (default: docs/adr) # token: ${{ github.token }} @@ -67,7 +67,7 @@ the comment reaches GitHub's size limit. Keep the default checkout rooted at `GITHUB_WORKSPACE`; if a workflow checks out elsewhere, marker health will identify files the Action could not inspect. -The Marketplace form is pinned to the immutable `v0.15.0` release. For +The Marketplace form is pinned to the immutable `v0.16.0` release. For the nested compatibility form, `v0` is a moving major tag; pin an immutable release tag or commit SHA when maximum reproducibility matters. @@ -78,14 +78,14 @@ release tag or commit SHA when maximum reproducibility matters.