Skip to content

Latest commit

 

History

History
343 lines (241 loc) · 16.6 KB

File metadata and controls

343 lines (241 loc) · 16.6 KB

Changelog

All notable changes to the github plugin are documented here. Format follows Keep a Changelog; this plugin uses semantic versioning.

[0.3.30] - 2026-10-04

Changed

  • The browser-automation offer's preference order points at the browser-tool rubric in /testing:run-e2e and applies its logged-in-browser row; Claude in Chrome's WSL status is read from that row, or from the upstream WSL note when the testing plugin is not installed.

[0.3.29] - 2026-10-04

Changed

  • The shipped recommendation-basis contract (context/recommendation-basis.md) follows the convention's 2.0.0 grounding bar: a design pattern is grounded in the canonical source that defines it, not in how popular it is; recency never discounts a canonical pattern definition; and a pattern found in a template, sample, or popular repository is checked against the principle it claims to serve.

[0.3.28] - 2026-10-04

Changed

  • Upstream plugin doc links repointed to the split plugins/ pages (#5962). The README options block now links plugins/cli-reference#plugin-install for the --config flag, since the old plugins-reference page no longer carries that section, and plugins/manifest-reference#user-configuration for the userConfig schema.

[0.3.27] - 2026-10-03

Changed

  • github.test.sh declares the files it reads without naming them in a # test-scope: header, so CI's test selection runs it when one of them changes. Nothing the plugin runs changed.

[0.3.26] - 2026-10-02

Fixed

  • plugin.json no longer sets $schema. claude.ai's marketplace sync stripped it with a warning, and Claude Code ignores it at load time.

[0.3.25] - 2026-10-02

Changed

  • The offer_browser_automation option title is a noun phrase, "Browser automation offer", per the plugin option naming convention (docs/conventions/plugin-option-naming/).

[0.3.24] - 2026-10-02

Fixed

  • The setup argument-hint uses Claude Code's official bracket notation: it leads with its check action and keeps alternatives inside brackets with an unspaced |.

[0.3.23] - 2026-10-01

Changed

  • References to the claude-config, claude-memory and claude-ops plugins now use their new names, harness-config, harness-memory and harness-ops.

[0.3.22] - 2026-09-30

Changed

  • The /install-github-app Boundary bullet in advise no longer asserts that the command ships with Claude Code. It keeps the provenance class, what the command does and how it is invoked, in the native-references template form.

[0.3.21] - 2026-09-29

Added

  • advise carries a Boundary section for the built-in command /install-github-app. The command installs the Claude GitHub App and its Actions workflow on one repository; this skill advises on the surrounding policy. The model offers the person-run command when the ask is that installation.

[0.3.20] - 2026-09-28

Fixed

  • Org-specific repository links removed from plugin prose. advise and context/recommendation-basis.md name the convention by its path in the marketplace repository, so the plugin's agnosticism check passes. The 0.3.19 entry's convention link is corrected in place the same way.

[0.3.19] - 2026-09-28

Changed

  • advise checks cross-repo blast radius. Advice that changes something other repositories consume (an org ruleset, a required or reusable workflow, an org Actions policy, org secrets or variables, custom properties) first lists the repositories it reaches with GET-only reads, and every recommendation carries a Basis:, per the recommendation-basis convention (docs/conventions/recommendation-basis/README.md in the marketplace repository).
  • Ships context/recommendation-basis.md, a byte-identical copy of the discipline recommendation-basis contract, since an installed plugin cannot read the repository's docs/. An unsettled consequential recommendation is withheld as a decision point.

[0.3.18] - 2026-09-25

Changed

  • Prompt audit for Claude Fable 5.1 and Opus 5.5: removed dated prompt patterns (history narration, migration-relative phrasing, stale references, stacked emphasis) from model-read reference text. Behavior and contracts are unchanged.

[0.3.17]

Changed

  • The github plugin test suite spells its agnosticism grep out literally again so the plugin-contract validator can keep its regex aligned with the org-agnosticism token list.

[0.3.16]

Changed

  • The desktop-notification, eol-normalizer, go-format, and github test suites route repeated invocations through shared runner and counter helpers, the eol-normalizer hook derives its status from the taken message directly, and the education workspace lister and firecrawl updater drop a redundant subshell and conjunct, with identical output.

[0.3.15]

Changed

  • Options reference drops its em dashes. The generated How-to-set-these block is rewritten by scripts/sync-plugin-options-docs.py, which is the fix site: its output is regenerated, never hand-edited. The block no longer needs the ignore marker that exempted it from the repository's em-dash gate, so that marker is gone as well.

  • Every markdown surface in the plugin passes /ai-slop:audit. Em dashes in the plugin's own prose (this changelog, the method ladder, change routing, browser automation, areas and conventions-file references, and the four recipes) are rewritten as a comma, a period, a colon where a definition or list follows, or a restructured sentence. Thirteen headings took the colon form; no file links any of the old anchors. No rung, routing value, area key, or checklist question was dropped: where a dash held two clauses apart inside a checklist question, the question became two questions rather than one comma-run.

  • github.test.sh passes at 36/0. That suite pins the six recipe section headings, a floor of ten questions per checklist, the area-key oracle, and the no-endpoints, no-prices, and no-scopes sweeps, so it covers exactly the surfaces this rewrite touched.

  • The plugin's markdown is declared in scripts/em-dash-purged-paths.txt, so the gate defends it from here on.

  • Changelog, in-place wording corrections to released entries: the same rewrite was applied inside [0.3.10], [0.3.4], [0.3.0], [0.2.0], and [0.1.0]. Wording only; every entry's facts are unchanged.

[0.3.14]

Changed

  • advise, audit: the read-only contract's enumeration of gh api write-capable flags carries a dated verification record with a recheck trigger.
  • Applied from the 2026-09 prompt-audit against Claude Fable 5.1 (docs/specs/prompt-audit-skills-2026-09.md).

[0.3.13]

Changed

  • Options reference cites the plugin-reconfiguration convention. The generated How-to-set-these block no longer restates the 2.1.240 verified-version record. This plugin cites the in-repo path rather than the published URL, because the agnosticism sweep forbids the publisher org name in shipped markdown.

[0.3.12]

Changed

  • setup check reports PASS/FAIL/INFO. The per-layer table used exists/absent and "hard finding" instead of the setup-contract verdict vocabulary. Rows are now PASS/FAIL/INFO with a remediation line per FAIL (team: unignore or commit; overlay: git rm --cached plus rotate, or recommend the gitignore line when present but unignored). All-layers-absent is INFO, not FAIL. user-invocable: true was already explicit in 0.3.10.

[0.3.11]

Changed

  • setup: after a team-layer write, re-run the tracked-file pair (git check-ignore -v no match AND git ls-files --error-unmatch exit 0). Non-zero ls-files means written but untracked: commit it to share with the team, never success.

[0.3.10]

Changed

  • Explicit user-invocable: true on advise, audit, and setup. The three skills were the fleet's only holdouts (with two in other plugins) declaring disable-model-invocation but not user-invocable; the value is the documented default, so nothing changes behaviorally. The key is now explicit for the same auditability reason the fleet writes disable-model-invocation on every skill.

[0.3.9]

Changed

  • Authoring-doctrine pass over README.md. Fixed sentences that parsed two ways. Every edit was verified against the file by an agent that did not propose it. Prose only; no behavior, contract, or trigger phrase changed.

[0.3.8]

Changed

  • The generated options block sits under ## Configuration. It was under ## Install. The generated table itself is unchanged; a ## Configuration heading was added above it. Docs-hygiene sweep, L8-write-for-humans.

[0.3.7]

Changed

  • Options-reference regeneration. scripts/sync-plugin-options-docs.py dropped the phrase in order to from its shared options template, per the repo's own write-for-humans style rule that the phrase is just to. The generated options block in README.md regenerated with the shorter wording; no other change.

[0.3.6]

Changed

  • Repo-wide /ai-slop:audit fix pass (#3359). The README's "No endpoint tables, no scope lists, no prices" cadence flattened to a single plain enumeration; all three denied items stay asserted. The read-only contract enumeration also stays: it defines the actual guarantee.

[0.3.5]

Changed

  • Instruction-surface de-slop (#2891, github cluster). Rewrote this plugin's README.md and every SKILL.md to drop em dashes under the repo's zero-tolerance house policy, using /ai-slop:audit fix semantics: periods or commas, or a restructured sentence, never parentheses, en dashes, or a spaced hyphen as a stand-in. Meaning stays; only the mark and the sentence break change. The generated options block is ignore-fenced because scripts/sync-plugin-options-docs.py still emits em dashes from its shared template.

[0.3.4]

Changed

  • Normalized fleet-wide framing this plugin restates (cross-vendor advisor fallback, untrusted-content posture, and attribution/idiom prose, as touched) to the canonical SSOT wording, operable text kept inline with provenance-only citations (#2698).

[0.3.3]

Fixed

  • Docs: the generated options block's headless route no longer implies --config applies only at install time, and now carries the CLI version its claim was verified against (#3111). Two upstream links that pointed at empty backward-compatibility anchors on the settings page were repointed at the headings that hold the content.

[0.3.2]

Changed

  • Explicit disable-model-invocation on advise and audit (#2968). Both skills now state the invocation mode the harness already applied for an absent key (false), so the choice is auditable and gated by skill-quality:check check 24. No behavior change. Rubric: docs/conventions/invocation-mode/README.md.

[0.3.1]

Changed

  • Docs: actionable /plugin configure guidance now uses the marketplace-qualified form (<plugin>@<marketplace>; generated option blocks use @<marketplace>) per docs/extensibility-contract-smoke-tests.md Test E (#1360). Targetless references to the flow stay unqualified.

[0.3.0]

Removed

  • The bare /<skill> alias for this plugin's skills. Their SKILL.md files no longer declare a frontmatter name. The field is optional and defaults to the directory name, so declaring it only restated the path while registering a second, unnamespaced command that the slash-command picker then echoed back as /plugin:skill (skill). Invoke a skill by its namespaced command; the command itself is unchanged.

[0.2.0]

Changed

  • /github:setup apply now states the two state-assessing clauses the setup contract requires of it. The skill said apply "never blindly rewrites" and carried an idempotency check, but neither of the contract's specific guarantees had a line to cite: nothing preserved keys in an existing routing.yaml that the schema does not recognize, and nothing said a recognized value the current version cannot reconcile is reported rather than converged. Both are now explicit and scoped to routing.yaml, which is the only file apply merges. conventions.md is a prose stub already governed by never-overwrite, so a preserve-keys guarantee about it would say nothing. An unrecognized key may be a consumer extension or a newer version's, and an unreconcilable value quietly rewritten is config loss the consumer discovers only when routing misbehaves.

[0.1.0]

Added

  • Published to the marketplace catalog (category: operations) after clearing the per-plugin migration gate and the plugin-acceptance security review (record in the playbook's security-review section: no hooks/MCP/bin; egress limited to the consumer's own gh auth, official-docs runtime fetches, and the opt-in confirm-gated browser-automation offer; ingested GitHub content treated as untrusted data).

  • Walking skeleton: the audit skill end-to-end, covering the area router (reference/areas.md, every coverage-matrix area), the generic method ladder (reference/method-ladder.md: gh native → gh api REST → GraphQL → UI-only detection → guided manual + deep link, with fetch-integrity, 403/404 disambiguation, plan/SKU honest degradation, and org-scale scoping rules), and the read-only contract stated in write-capability terms.

  • Plugin manifest, README (verb contract including the advise verb declaration), and drafted audit eval cases.

  • Consumer config surface: reference/change-routing.md (routing.yaml schema contract_version 1.0.0: scope blocks, per-key override layering, policy-floor inversion on write-posture keys, target-resolution rule) and reference/conventions-file.md (concatenating prose conventions audits compare against).

  • The setup skill (user-invoked only): check verifies gh, auth, credential-modality picture, and per-layer config verdicts; apply writes .claude/github/ config idempotently via interview. Drafted setup eval cases.

  • The advise skill: forward-looking guidance and hand-holding grounded in live gh state and freshly fetched official docs, proactive in-session suggestions (offered, never acted on), and a declared routing boundary against audit in both skill descriptions. Drafted advise eval cases.

  • The --apply resolution flow in reference/change-routing.md (scope+target resolved first, with org/enterprise targets asked and never silently inferred; then propose / guided-apply with per-step confirms, doc provenance, and post-write read-back / handoff; unconfigured → propose), wired into both audit and advise.

  • The browser-automation offer for UI-only surfaces: reference/browser-automation.md (presence gates for claude-in-chrome and the playwright plugin, claude-in-chrome-first preference order, never-auto-fire rule, confirm-gate offer template naming surface + action + doc provenance + authenticated-session fact, post-write read-back verification, guided-manual deep-link fallback), the offer_browser_automation plugin setting (boolean, default true, advisory gate layered under the per-action confirm), and the method ladder's UI-only rung now citing the reference. Gate value surfaced in audit and advise prose via ${user_config.offer_browser_automation}.

  • Evals and QA surface: completed eval suites for all three skills (trigger routing, happy path, refusal branches, and both anti-pattern contracts: injected instructions in fetched GitHub content cause no write/browser/routing action; browser automation is offered and confirm-gated, never auto-fired), schema-validated. Committed contract test github.test.sh (runs under the repo's plugin-test runner) durably enforcing the zero-vendored-knowledge sweeps (no endpoints, no scope names in shipped prose, no prices), the agnosticism sweep, the area-coverage oracle (canonical area-key fixture diffed against reference/areas.md), and the recipe non-hollow contract (six sections plus a ≥10-question checklist per recipe).

  • Primary-tier method recipes under reference/recipes/: billing.md, security-posture.md (authentication, advanced security, GitHub Apps, OAuth app policy, PATs), rulesets-repo-drift.md, actions-policy.md. Each carries a credential-and-gate preflight, a curated audit-question checklist, cost-control levers or posture heuristics, a drift-comparison procedure against declared conventions, dated re-verify-live caveats, and stable official-doc entry pointers, with zero vendored endpoints, scopes, or prices (mechanics resolve at runtime via the method ladder). reference/areas.md primary rows link their recipes.