Repository navigation
Release 0.14.0: protected files, declared imports, instruction checks, decision log - #46
Merged
Merged
Conversation
…, decision log Add the unchanged, deps-declared, instruction-refs and signed-commits gates, instruction-sync `require` with `sync --create`, changed files for command gates, a severity summary for passing Trivy scans, an opt-in decision log with `skillgate log`, and `explain --commands` for replaying a command list.
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Release 0.14.0: four new gates, instruction coverage, changed files for commands, a decision log and corpus replay. Prepares
@reneza/skillgate0.14.0.Added
unchangedgate: files matching a glob that existed at the base ref must stay byte-identical. It protects snapshots, golden outputs, applied migrations and CI workflows from being edited to make a check pass. Content is compared the way Git stores it: line-ending normalization does not count as a change, and symlinks are compared by their target. Diff-aware, and fails closed without a base.deps-declaredgate: every package a JS/TS file imports must be declared in the nearestpackage.json. This catches imports that resolve only through hoisting or a global install. Builtins, relative paths,#subpathimports, protocol specifiers and self-references are skipped. A type-only import is also satisfied by@types/<name>, andallowcovers path aliases. Workspace packages are checked against their own manifest.instruction-refsgate: every@import, relative Markdown link and directory-qualified code-span path in the agent instruction files must exist. Failures point atfile:line. Fenced code, URLs, bare file names and branch-like spans (origin/main) are not judged.instruction-sync.require: each listed tool (claude-code,gemini-cli, …) must have its own instruction file, in sync with or linked to the canonical one. When AGENTS.md is the only file, a tool that reads it only through a fallback no longer passes. The failure reason names aCLAUDE.local.mdthat turns that fallback off.skillgate sync --create <tools>writes the missing@AGENTS.mdpointers.signed-commitsgate: every commit between the base ref and HEAD must be signed (trust: signed), or carry a good, checkable signature (trust: verified).SKILLGATE_CHANGED_FILES(a file listing the changed files that still exist, filtered bywhen.changed) andSKILLGATE_CHANGED_COUNT. Both are unset when no base resolves, so a command can fall back to a full run.--log <file>orSKILLGATE_LOGappends eachgateandcheckverdict as one JSON line.skillgate logsummarizes blocks per gate and the blocked commands. A log path inside the worktree (outside.git/) is refused, and logging never changes a verdict.skillgate explain --commands <file|->: replays a command list, or a decision log, against the currentfinishLineand names the gates each command would run.explain --commandnow lists those gates too.Changed
trivygate now reports the vulnerabilities below the blocking severities (not blocking: 12 HIGH). This adds one informational JSON scan after a passing vulnerability scan;summary: falseturns it off.--cachealso reuses passingunchangedresults.Verification
npm test: 218 tests pass on Node 20 and on Node 22 (194 before this change, plus 24 new). Node 18 runs in the CI matrix.npm run test:coverage(Node 22) passes the configured thresholds: 94.06% lines, 83.44% branches, 97.53% functions.node dist/src/cli.js check), andgit diff --checkis clean.changelog-section.mjs 0.14.0extracts the new section.npm pack, then installed the tarball in an empty project.--versionprints 0.14.0.gateblocked agit pushthat changed a protected file (exit 2),logsummarized the decision, andexplain --commandsreplayed the log.instruction-refsanddeps-declaredgates were also run read-only against several existing repositories. Two heuristics were tightened as a result: a string literal that reads"import"is no longer taken for an import, and bare file names and extension-only code spans are no longer judged.Review notes
99eb46f(master). There were no other open PRs when this was prepared.src/core.ts), spec validation and types (src/spec.ts), Git plumbing (src/git.ts),src/process.ts(optional environment for command gates),src/link.ts(sync --create) and the CLI (log,explain --commands,--log). New modules:src/imports.ts,src/refs.ts,src/log.ts. Also touched: the schema, docs, CHANGELOG, package version, and the existing trivy test, which now also asserts the summary scan.skillgate initorauditdefaults.