Skip to content

Release 0.14.0: protected files, declared imports, instruction checks, decision log - #46

Merged
renezander030 merged 1 commit into
masterfrom
release/v0.14.0
Oct 9, 2026
Merged

renezander030 merged 1 commit into
masterfrom
release/v0.14.0

Conversation

@renezander030

Copy link
Copy Markdown
Owner

Release 0.14.0: four new gates, instruction coverage, changed files for commands, a decision log and corpus replay. Prepares @reneza/skillgate 0.14.0.

Added

  • unchanged gate: files matching a glob that existed at the base ref must stay byte-identical. It protects snapshots, golden outputs, applied migrations and CI workflows from being edited to make a check pass. Content is compared the way Git stores it: line-ending normalization does not count as a change, and symlinks are compared by their target. Diff-aware, and fails closed without a base.
  • deps-declared gate: every package a JS/TS file imports must be declared in the nearest package.json. This catches imports that resolve only through hoisting or a global install. Builtins, relative paths, #subpath imports, protocol specifiers and self-references are skipped. A type-only import is also satisfied by @types/<name>, and allow covers path aliases. Workspace packages are checked against their own manifest.
  • instruction-refs gate: every @import, relative Markdown link and directory-qualified code-span path in the agent instruction files must exist. Failures point at file:line. Fenced code, URLs, bare file names and branch-like spans (origin/main) are not judged.
  • instruction-sync.require: each listed tool (claude-code, gemini-cli, …) must have its own instruction file, in sync with or linked to the canonical one. When AGENTS.md is the only file, a tool that reads it only through a fallback no longer passes. The failure reason names a CLAUDE.local.md that turns that fallback off. skillgate sync --create <tools> writes the missing @AGENTS.md pointers.
  • signed-commits gate: every commit between the base ref and HEAD must be signed (trust: signed), or carry a good, checkable signature (trust: verified).
  • Changed files for command gates: SKILLGATE_CHANGED_FILES (a file listing the changed files that still exist, filtered by when.changed) and SKILLGATE_CHANGED_COUNT. Both are unset when no base resolves, so a command can fall back to a full run.
  • Decision log: --log <file> or SKILLGATE_LOG appends each gate and check verdict as one JSON line. skillgate log summarizes blocks per gate and the blocked commands. A log path inside the worktree (outside .git/) is refused, and logging never changes a verdict.
  • skillgate explain --commands <file|->: replays a command list, or a decision log, against the current finishLine and names the gates each command would run. explain --command now lists those gates too.

Changed

  • A passing trivy gate now reports the vulnerabilities below the blocking severities (not blocking: 12 HIGH). This adds one informational JSON scan after a passing vulnerability scan; summary: false turns it off.
  • --cache also reuses passing unchanged results.
  • Version 0.14.0, a CHANGELOG section, an updated JSON schema, and docs for every addition: the spec reference, README and the bundled skill.

Verification

  • npm test: 218 tests pass on Node 20 and on Node 22 (194 before this change, plus 24 new). Node 18 runs in the CI matrix.
  • npm run test:coverage (Node 22) passes the configured thresholds: 94.06% lines, 83.44% branches, 97.53% functions.
  • The repository's own gates pass (node dist/src/cli.js check), and git diff --check is clean.
  • changelog-section.mjs 0.14.0 extracts the new section.
  • Packed-artifact smoke test: npm pack, then installed the tarball in an empty project. --version prints 0.14.0. gate blocked a git push that changed a protected file (exit 2), log summarized the decision, and explain --commands replayed the log.
  • The instruction-refs and deps-declared gates were also run read-only against several existing repositories. Two heuristics were tightened as a result: a string literal that reads "import" is no longer taken for an import, and bare file names and extension-only code spans are no longer judged.

Review notes

  • Based on 99eb46f (master). There were no other open PRs when this was prepared.
  • Touched: the gate evaluator (src/core.ts), spec validation and types (src/spec.ts), Git plumbing (src/git.ts), src/process.ts (optional environment for command gates), src/link.ts (sync --create) and the CLI (log, explain --commands, --log). New modules: src/imports.ts, src/refs.ts, src/log.ts. Also touched: the schema, docs, CHANGELOG, package version, and the existing trivy test, which now also asserts the summary scan.
  • Untouched: agent hook installers and their output protocols, pinning, receipts (apart from the cache allow-list), the dependency-lock checks, the zk/fhe features, and the CI/release workflows. Existing gates behave as before, except for the trivy pass message and its one extra scan.
  • The new gates are opt-in: none is added to skillgate init or audit defaults.
  • No tag, release or package publication is part of this PR.

…, decision log

Add the unchanged, deps-declared, instruction-refs and signed-commits gates,
instruction-sync `require` with `sync --create`, changed files for command
gates, a severity summary for passing Trivy scans, an opt-in decision log with
`skillgate log`, and `explain --commands` for replaying a command list.
@renezander030
renezander030 merged commit deb0852 into master Oct 9, 2026
7 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant