Format follows Keep a Changelog.
4.1.0 — 2026-10-02
Better diagnostics and safer migration for older projects. A project whose policy is ambiguous is asked to decide — it is never decided for it.
This release does not promise that every old project migrates automatically, and does not promise that behaviour is unchanged. What it promises: evidence inside the supported range, an explicit message outside it, and no silent change to a project's policy.
Upgrade (read this)
All four packages share a major.minor and are released in lockstep. Each
adapter pins pactkit>=4.1.0,<4.2.0, and doctor.check_adapter_compat requires
the adapter's major.minor to equal Core's. Core 4.1.0 with a 4.0.0 adapter is an
explicitly disallowed combination — deployment is refused by the skew guard.
Upgrading the CLI changes your existing hooks immediately, but does not
migrate the project. The old Git wrapper runs whatever pactkit is on PATH,
so a pip/pipx upgrade takes effect on the next git push — while the project's
config layout, hook chain and .gitignore are left untouched. Run
pactkit commit-gate --install --migrate inside the project to move the chain.
Check three things before upgrading, not just the version number: the
version (pactkit version), the install source (pip show / direct_url.json),
and the artifact's full sha256. Several different builds have reported the same
version number.
Added
- Project shape inventory.
init/update/upgradeandcommit-gate --installfirst print a per-entry table — what each host signal reads on this project — and say plainly that they will not change your config. Read-only; it reports, it does not block. - Three-layer config facts (discovery / selection / parse).
doctor --jsonreports the candidates, the selected layer, the parse status and whether the comparison was complete. "Several copies and no shared layer" and "no config at all" are now two different states.
Fixed
- Copilot adapter ignored
-C.pactkit -C <other-project> update --format copilotwrote 44 generated files into the caller's cwd: the dispatcher silently droppedproject_rootfor any deployer whose signature did not name it, and copilot's deploy root is the project-relative.github/, so it fell back toPath.cwd(). It now refuses rather than dropping the argument, and all three adapters accept and use the project root. doctorprinted the same divergence twice. Per-key detail now appears once as a summary in the text and in full underdoctor --json(config_source.divergence), which previously carried none of it.
Notes
The supported range — what is read compatibly, how copies are chosen, what
update protects, and what is not covered — is documented in
migration-support-scope-4.1.md. The short version: a hostless process reads a
single host copy compatibly (until 5.0.0); two or more copies and no shared
layer selects none of them and every value comes from the defaults.
4.0.0 — 2026-09-26
Kernelization + Repository Coherence. Host ownership leaves Core entirely, and where a generated config is written stops being a guess.
Every change since 3.1.0 is a contract-boundary change, which is why this is a major release rather than a minor one. Even without splitting any package, 4.0 changes the spec lifecycle, the story state machine, the evidence contract, the prompt generation model, the truth hierarchy, migration behaviour, artifact metadata and garden semantics.
Upgrade (read this)
All four packages share a major.minor and are released in lockstep. Two
independent locks say the same thing: each adapter pins pactkit>=4.0.0,<4.1.0,
and doctor.check_adapter_compat requires the adapter's major.minor to equal
Core's.
Core 4.0.0 with a 3.x adapter is an explicitly disallowed combination — the deploy is refused by the skew guard:
✗ Adapter pactkit-codex 3.1.0 incompatible with core 4.0.0 (major/minor mismatch)That is a deliberately lighter failure mode: imports work, registration works,
and only deployment is stopped, with --allow-adapter-skew as the explicit
override. Install all four together:
pip install -U "pactkit==4.0.0" "pactkit-opencode==4.0.0" \
"pactkit-codex==4.0.0" "pactkit-copilot==4.0.0"Removed
- Core declares nothing about any external host (SPEC-4.0-22 Step 7).
Profile, capabilities, pre-tool surface, deployment claim, security facts and
the wire format are all carried by each adapter and registered through
entry-point discovery. Core keeps only the
classichost it ships itself. - The directory-existence fallback in
resolve_pactkit_yaml_dir(Step 8). The write target is no longer decided by which directory happens to exist — measured:mkdir .opencode && pactkit init --format classicwrote classic's config into.opencode/pactkit.yaml. The rule is now: reading may discover existing layers; writing must know which format it is writing for. - Adapters' inline
pactkit.yamltemplates (Step 8 R-②-1). They emittedstack: unknown— a value Core's ownVALID_STACKSrejects — and noschema_version. An adapter was writing config Core's validator would refuse, and nothing read it back to notice.
Changed
- Every host's
pactkit.yamlcomes from the same canonical, format-aware generator. An adapter declares only where the file lives (profile.pactkit_yaml_path) and whether it is needed — never the format. - OpenCode now actually generates
.opencode/pactkit.yaml. It used to be declared and searched but never produced — while another host could still create it. "Declared + searched + never produced" lets a later judgement treat a state that does not exist as a normal candidate. register_adapterkeepsinput_translationon re-registration. It is the fifth declaration member and was the one missing carry-forward: re-registering silently withdrew the wire-format declaration, sotranslate_host_payloadstopped recognising the host and the whole channel failed open.
Notes
- The four hosts generate byte-identical configs on a fresh init. A project
that already has any
pactkit.yamldoes not grow extra host copies — it keeps reusing the existing layers (known behaviour, not a defect). - This entry was written after the
v4.0.0tag, so it is not part of the tree that tag points at.
3.1.0 — 2026-09-25
Host ownership moves out of Core. A contract-boundary change, not an internal refactor — which is why it is a minor release and not a patch.
Removed
- Core no longer declares anything for opencode / codex / copilot. The transitional APIs and state of that period are gone entirely.
Changed
- Hosts go from "pre-seeded by Core" to "present only once the adapter is
installed". A host that is not installed cannot register, so
format: allnever installs a channel for a host that never deployed.
Notes
- Upgrade order matters. Core and adapters must share a major.minor. This release required the adapters first; installing a new adapter against an older Core makes pip silently downgrade Core to satisfy the pin.
3.0.4 — 2026-09-24
The core release that unblocks the adapters. Host-description data moves out of a hard-coded table in core and into a registerable
AdapterRegistration, together with the types and API the three adapters need to declare themselves.This is not the final PactKit 4.0 release — 4.0's lifecycle closure is still ahead. This version exists to let the adapters stand up, not to declare kernelisation finished.
Upgrade
New adapter + old core is an incompatible combination, not a runtime
regression. The three adapters pin pactkit>=3.0.1,<3.1.0, so upgrading to a
new adapter pulls core up to this version too; upgrading core alone is safe.
Conversely, hand-installing a new adapter onto core 3.0.3 gives
ModuleNotFoundError: No module named 'pactkit.capability' and the registry
degrades to classic only — that is an installation-combination problem, not a
defect; reinstalling core restores it.
Added
pactkit.capability— four-level capability resolution and a multi-dimensional guarantee model (SPEC-4.0-04).AdapterRegistrationand declaration types —InputTranslation,DeploymentClaim,SecurityDeclaration,SecurityFacts. Host descriptions (capabilities, pre-tool surface, deployment claims, security facts) are now carried by the adapter itself, collected bycomplete_registration(SPEC-4.0-22 Phase B / Step 6).- Adapter SPI public surface frozen, plus a host-dispatch ratchet (SPEC-4.0-03).
Changed
- Unregistered hosts no longer fabricate a full set of Degraded
capabilities. An unknown host honestly reports
unknown_hostinstead of a capability table that looks like a measurement. - Writes that need tamper_guard authorisation are no longer allowed through
when the security-facts declaration is incomplete. A three-state model
separates
missing(the host said nothing → we do not know) fromempty(the host said it has none → that is a measurement).missingis treated as undecided authorisation, fails closed and names the incomplete category; once the declaration is complete, the normal fine-grained verdicts return (ordinary edits allowed, bypasses still blocked). doctor's host enumeration comes from the registry only, and paths are derived from the profile.- Path values are now derived — forbidden-path patterns grow from 7 to 12, covering every registered host's config directory.
Fixed
--overlayaccepts only the complexity schema; unsupported input fails explicitly.blast_radius's resolver recognises exact paths only; shorthand must be enabled explicitly and ambiguity is never resolved by picking one. The four empty results are separated:resolved/not_found/out_of_scope/truncated.- The analyzer can express "cannot read it" — four copied contracts collapse into one.
query's empty result is no longer treated as proof of absence.done-verifyno longer treats paths inside blockquotes as on-disk paths.report/visualizescanners exclude PactKit deployment artifacts by ownership metadata.- The story lifecycle becomes a contract — the state machine is defined by data, and archiving no longer masquerades as completion.
3.0.3 — 2026-09-21
Three boundary fixes in the evidence chain. One of them destroyed existing records. Upgrade is the only action needed — no migration.
Fixed
-
Committed out-of-scope changes vanished from the scope check. Range integrity only compared
git diff HEAD(the dirty state); the committed half was never implemented. So one commit made an out-of-scope file disappear from the measured range, flippingcompletion_readyfromfalsetotrue. Multi-commit stories, post-commit checks and resumed sessions all reached a wrong conclusion.The starting point is now bound to the Act preflight receipt (a code touchpoint, not a habit), and the check covers everything from there to the working tree. The start is sticky — re-running preflight does not move it. When no trustworthy start exists it reports
not-measuredrather than "no drift". -
"Not measured" could produce a green record.
pactkit evidence-measure --recordcalledrecord_verification()without anoutcome, which defaulted to"green"— a run with zero tests recorded as a passing regression. Deeper: the decision function only compared content fingerprints and never checked whether regression evidence existed at all, so such a record licensedreuseand downstream really skipped regression.outcomeis now required, measurements go through their own entry point, reuse requiresoutcome == "green", and a failing record routes to full re-verification rather than the lightest classification path. -
Different evidence types overwrote each other. Writes replaced the whole file: a negative-control write followed by a regression write lost the former, and vice versa. Records are now typed (
regression/measurement), each binding the code state it was actually measured on. -
Records written before this release are no longer destroyed on upgrade. The older flat shape (regression fields at the top level, measurements under
evidence) was not recognised by the merge — a single write silently dropped half of it. The merge now understands both shapes.
3.0.2 — 2026-09-21
Two CRITICAL gate fixes. Worth upgrading if you have ever released with PactKit, or ever followed a block message to try a human bypass.
Fixed
-
The release gate could report PASS with zero tests run. The Pre-Tag Gate's "Run tests" line pointed at
pactkit regression— a classifier that exits 0 on every path (SKIP and IMPACT alike). The "if either fails" that followed could therefore never fire on a test failure. The line now names a real test runner, andpactkit regressionis explicitly labelled a classifier. -
Human-bypass instructions described a form that cannot work. Block messages suggested an inline prefix such as
PACTKIT_ALLOW_SECRET=1 <command>. Measured: the bypass reads the hook process's own environment, and the PreToolUse hook runs before your command with the session's environment — an inline variable reaches the child process only, so it structurally cannot arrive. Following the instruction left you blocked with the command never having run.All exits now render through a single
bypass_message.human_channel()and state which face they are on: PreToolUse (inline cannot work — run it in a terminal outside the session, or export before starting) versus the git hook (inlineVAR=1 git <cmd>does work — git passes it to its own hook). -
pactkit doctor's two surfaces disagreed about the same tree. Text mode exited 1 while JSON exited 0. Both now share one verdict source. -
done-verifytreated a glob as a declared file._real_pathonly rejected braces — an incomplete implementation of its own rule. -
The audit's "has tests?" heuristic guessed from filenames, producing 40 false negatives and a batch of junk tasks. It now uses graph evidence (call edges ∪ import edges ∪ naming convention).
Added
pactkit evidence-measure— turns "scope integrity" and "negative control" from prose into executable measurement. The negative control pins three things at once: the baseline must be green before mutating, each file must be restored after its run, and only exit code 1 counts as caught — missing any one produces a false pass.- R8/R9 requirements are wired into
delivery_evidence, from prose to a code touchpoint.
3.0.1 — 2026-09-19
Distribution consolidation plus gate fixes. The plugin/marketplace channel is retired — every install is a pip install now — and OpenCode gains a pre-tool gate channel.
Migration (3.0.0 → 3.0.1)
-
The plugin/marketplace distribution channel is gone.
pactkit init --format pluginand--format marketplaceno longer exist. If you installed through Claude Code's/plugin marketplace add pactkit/claude-code-plugin, that repository is archived and will not update again — uninstall it and move to pip:claude plugin uninstall pactkit # inside Claude Code pip install pactkit && pactkit init -
Each host now has exactly one channel: Claude Code ships in the core package; OpenCode, Codex and Copilot each install their own adapter (
pactkit[opencode],pactkit[codex],pactkit-copilot). -
Existing pip installs need no action —
pactkit updateworks as before.
Added
- OpenCode pre-tool gate channel. The gate plugin deploys globally and activates per project via an activation marker, fail-closed. Payload translation moved into Python, so the core bypass regression suite now covers every host channel.
- Organisation baseline GPG detached signatures — provenance is verified, and a missing signature fails closed.
Fixed
- Gate matrix states facts per layer × gate, and partial coverage is now always reported — reading "covered half" as "checked" is exactly the failure this prevents.
- Unknown writable tools are refused, not half-judged. Returning a confident verdict without the full payload reads as "checked" when nothing was checked.
- OpenCode
edit'sreplaceAllwas unmapped — the gate simulated a single replacement, so an edit that weakened enforcement across all matches passed on OpenCode while native Claude blocked it. - Project-level agent instructions no longer
@importa file nothing generates — this affected all three adapter templates. secrets_baselineentries on the same line no longer overwrite each other, and the tool no longer masks its own corruption.
3.0.0 — 2026-09-18
Architecture-slimming release. The Git-hook layer is now pre-commit (the only scheduler), the credential engine is detect-secrets (upstream), code relationships come from Codegraph (MMD files became rendered views), and
pactkit.yamlis read per terminal. This is a major version: old Git hooks need an explicit migration — read the migration notes first.
Migration (2.27.0 → 3.0.0)
- New standard dependencies.
pre-commitanddetect-secretsship with the base install —pip install --upgrade pactkitbrings them.detect-secrets-hookis reached through PactKit and does not need to be on your PATH. - Old PactKit Git hooks are migrated explicitly, never automatically. Per
project:
pactkit commit-gate --install --check(read-only preflight), then--install --migrate. Pristine old wrappers are backed up to.pre-pactkit-migrationand replaced by pre-commit shims; hooks you edited yourself are never touched — the migration stops and lists them. .pre-commit-config.yamlno longer records machine-local absolute paths. Entries namepactkiton PATH, so the same committed config works for every developer and on Linux CI. The migration rewrites absolute entries written by an older PactKit;pactkit doctornames any that remain.- Config is read per terminal. A shared
pactkit.yamlat the repository root applies to every host and to everything with no host signal (plain terminal, CI, and the Git hooks — pre-commit/pre-push are host-agnostic, there is no terminal to ask)..claude/,.codex/and friends override it key by key. Putenforcement.*in the shared file.pactkit schema configprints the host, the layers, and each key's source. - Rolling back:
pip install pactkit==2.27.0(pin the adapters in the same command), thenpactkit update. To remove the Git hooks too,pactkit commit-gate --uninstall-chaindeletes only PactKit's entries and shims — your own checks and your baseline are left alone.
Added
- Codegraph is the single source of code facts; MMD files are rendered views.
pactkit syncbuilds the index,pactkit visualizerendersdocs/architecture/graphs/*.mmdfrom it, and audit insights read the same index. The self-built scanner is gone for good — with no index,visualizefails with a clear message instead of falling back to a guess. - First-run project check. The first pactkit command in a project after an install or upgrade runs a read-only, once-per-version check (config drift, graph views, gate chain) and names the exact next command for each finding. It reports to stderr and modifies nothing.
- pre-push capability limits are documented in
pactkit doctorand the support matrix: a push with several refspecs surfaces only its first ref to the policy, and deleting a remote ref does not run the pre-push stage at all. These are pre-commit's own limits — no second scheduler was built to paper over them, and protected-branch deletion protection belongs on the server.
Changed
- Config copies are no longer flattened automatically. With per-terminal
resolution, propagating one host's config over the others would erase exactly
the per-terminal settings that resolution exists to honour. Unifying is now an
explicit choice:
pactkit update --sync-config-copies. spec_editauthorization token removed — the human channel is now the only way to edit a Spec mid-Act (!prefix withPACTKIT_ALLOW_SPEC_EDIT=1).
Fixed
- Uninstall no longer deletes user configuration. The old line-based removal
tracked "inside our hook" with a flag that only a
repos:line cleared, so a top-level key after our last hook (fail_fast:) was swallowed with it — and an unparseable config was treated as an empty one and then deleted. Unreadable is not the same as empty: parsing failure now stops the operation untouched. - Partial first-time installs roll back completely. The old rollback restored only the wrappers it had removed; a project that had no hooks could be left with a freshly created shim and no config — a hook that fails every commit. Anything created during the run is now removed too.
- The merge path honours an existing baseline.
generate_configwroteargs: [--baseline, .secrets.baseline], but merging into an existing config hand-wrote its own secrets block and dropped that line — the reviewed baseline stayed on disk unused and previously accepted test data blocked commits again. Both paths now render from one hook definition. - The publish gate can no longer accept a daily acceptance run. The same commit has both a daily single-version and a release four-version acceptance run; selecting by SHA alone meant "whichever the API listed first". It now matches this tag's push event and SHA.
2.27.0 — 2026-09-17
Security-hardening release: 34 gate defects fixed across six adversarial review rounds, plus the project-contract lifecycle (
adopt/reconcile/project-preflight). Read the Migration notes before upgrading.
Migration (2.26.1 → 2.27.0)
- spec_guard: content drift now LOCKS instead of unlocking. A live receipt whose hash no longer matches the spec means the spec was modified — exactly what this gate exists to stop. Authorized edits still work.
- secrets_gate / auth_gate audits no longer echo the command text. Redaction only covers known credential shapes; an unmatched secret in the same command used to ride along into the audit record.
- tamper_guard protection widened: the whole
.pactkit/state directory,settings.local.json(the host injects a settings file'senvinto hook processes and hot-reloads it in-session — one Write could disable every gate), and all fourpactkit.yamlcandidates. Use thePACTKIT_ALLOW_CONFIG_EDIT=1human channel when an agent legitimately needs to edit these. - Core and adapters upgrade together:
pip install -U pactkit pactkit-codex pactkit-opencode(mutual version pins, 2.27.x).
Added
- Project contract lifecycle (#13):
pactkit adopt(minimal local contract),pactkit reconcile(safe migration — line-level insert preserving comments, parse-back validation),pactkit project-preflight(UNADOPTED / RECONCILE / CURRENT / BLOCKED). Adoption stays strictly local: no registry, no scanning. - Support matrix (
docs/guides/support-matrix.md): hosts × gates × Python × OS, derived from the installer's own facts with a guard test. OpenCode and Copilot get the git-hook layer only — the four pre-tool gates do not exist there.
Fixed — six adversarial review rounds (34 defects)
- push_gate: quoted refspecs (
git push origin 'main') and the force marker (+main) passed protected branches with a false "not protected" audit record;$VARrefspecs are now unresolvable (WARN + DEGRADED) instead of certified; the pre-push hook uses the refspecs git hands it on stdin (a feature-branch push ofmainused to go through);git -Cnow decides which repo is checked. - commit_gate:
git -c core.hooksPath=/dev/null commithanded the gate to a hook that never ran (including case variants andGIT_CONFIG_*injection); dispatch is anchored to command position (aprintfwriting the Codex hook registration, whose argument merely mentioned a git commit, used to skip the tamper check entirely); an audit-write failure no longer turns a BLOCK into a crash. - tamper_guard: the compound-command regression (
cd .git/hooks && rm -f pre-commit); config weakening across all four candidates; the settings env bypass channel; thetouch .pactkitstate-directory swap; symlinked specs and case-altered spellings on both the Edit and Bash faces;replace_allsimulation. - secrets_gate: added
curl -u,Authorization: Bearer,sk-proj-/sk-ant-, AWS secret keys, URL credentials, and the sshpass/docker/redis/openssl inline password shapes; the private-key body is now redacted whole (previously only the BEGIN line was matched — the leak-prevention gate was persisting key bodies into its own audit records). - auth_gate: global flags before the subcommand (cross-repo
ghinvocation with-R); audits no longer echo the command. - Infrastructure: one shared atomic-write temp-naming seam (a concurrent-write
crash in config.py); gate-name path-escape validation; YAML TypeError /
RecursionError contained;
pactkit cleanno longer crashes on symlinks.
2.26.1 — 2026-09-15
Fixed
- deploy 不再因扫描根下的不可读目录崩溃——
Path.exists()只吞 ENOENT/ENOTDIR/ELOOP,EACCES 会直接抛出;GitHub Ubuntu runner 的/tmp含 root 属主 0750 的systemd-private-*目录,中性 cwd 下deploy → cleaners.detect_stacks的子目录 marker 检查抛PermissionError(pactkit-opencode 2.26.0 Release Acceptance 8 项失败、publish 被拒)。cleaners.detect_stacks与utils.stack_test_plans/_issues的全部 marker 检查改为 OSError 安全版(一律视为无 marker)。
2.26.0 — 2026-09-15
产品重定位版本:PactKit 收敛为轻量开发赋能脚手架——无管理员、无集中控制、 无自建服务。包含大量语义变更,升级前请阅读下方 Migration。
Migration (2.25.2 → 2.26.0)
- 自建 MCP server 已退役:
pactkit mcp变为兼容说明入口(解释退役 + 迁移方向, 非零退出);Codex 的 gate 通道从 MCP 工具迁移到原生 hooks(已有配置自动迁移, 用户/未知条目按证据保留);新部署默认零 MCP 注入(不再写任何 server 注册或 安装推荐)。 - 配置入口统一:
load_effective_config是唯一配置解析入口(候选优先级 + 基线 合并 + tighten-only 方向约束,ADR-0007);直接读单份 pactkit.yaml 的路径已收口。 - 验证决策是结构化数据(ADR-0004):Done 的回归路由消费
pactkit regression --check-record --json的decision.verdict(reuse/supplement/re-verify/no-baseline),不再解析文本前缀。 - 规则语料为 CI 不变量(ADR-0005):改规则必带
tests/fixtures/rules_corpus/语料案例(14 fixture);RULES_VERSION 升至 2026-09.2。
Added
- 轻量脚手架重定位落地(STORY-slim-20260911b2bbd79889e0,三轮复审 18 findings 修复):候选清理限定受管范围(排除备份存储);统一有效配置与门禁语义;能力展示/ 上手/卸载输出与实际行为一致;三宿主 prompt 正文摘要 golden(85/83/71 artefacts, 删改必被检出);真 wheel 组合验收(组合验收按零凭据拆分移交 adapter 仓)。
- 提交路径收敛(STORY-slim-20260915eaf18678ce23):worktree/
core.hooksPath下 经git rev-parse --git-path hooks解析真实 hooks 路径——一次提交一个测试执行者 (此前 worktree 恒双跑全套);被改测试文件直接映射自身(test_X.py不再去找test_test_X.py);映射为空走快速层并显式建议全量(非 Python 栈无按文件选择 能力,保持全量并说明);main/develop 全量安全网保留但原因可见、可配置 (enforcement.main_branch_full_suite);coverage-gate 接受--tests选择集 (Done 剧本已接线,不再二次全量);gate 计划先行(strategy/原因/命令/范围在测试 前可见)+ 流式输出 + 每步耗时入 enforcement 记录details;暂存区为准 (未暂存改动显式报告为排除项)。 - 验证事实与治理开销收敛(STORY-slim-20260915ac3e5c24fdd3):验证记录以内容
指纹为主键(跨 Story/无 Story 可复用);无新鲜无歧义 preflight receipt 时盖章为
无归属(
_unattributed.json+ 指纹仍登记)——"最近 receipt 猜 Story"的错归属 结构上不再可能;PreCompact 只写轻量标记(一次压缩一次 context 生成,内容相同不 重写);spec guard 的 receipt 锁定改为哈希匹配 + 7 天新鲜双条件(无哈希/过期/内容 漂移即解锁并输出依据);telemetry.enabled开关(默认开,关闭不影响门禁契约)。 - PDCA 工程指导按缺口加载(STORY-slim-202609144d0b3cb593aa):复用四判断
(可用性/适用性/决策/证据)与恢复语义集中于共享 capsule;Act 1.5 缺口驱动——
删除"Spec 无关注点则静默跳过"、
pactkit risk --json消费完整 decisions、1–3 篇 为初始建议而非上限(无缺口 0 篇有效,确认的风险超三篇仍读);Plan 关键词降为 候选信号(提及≠义务);Check 增独立复用审查;Done 路由不被指南筛选覆盖。附 63 份 逐会话真实宿主试验记录(docs/acceptance/r8-trial/)。 - 结构化验证决策接口(STORY-slim-2026090699752886f924,ADR-0004/0006):验证 证据由 code touchpoint 盖章;Done Step 0 按结构化 verdict 路由。
- 固定语料规则评估(ADR-0005):
pactkit rules-eval对 14-fixture 语料给 precision/recall,改规则必带语料案例;安全设计 W013/W014 落地。 - codegraph 集成(ADR-0008):语义代码查询统一走
pactkit queryCLI 路由 (--explore/--chain/--callers/--impact --json --explain),freshness 与 fail-closed 由路由器强制。 - 生成式 reference 目录 + 漂移门(STORY-slim-2026082727cc4ab535e7); Codex 并列插件清单让 Codex 真正拿到 skills(STORY-slim-20260827fb6291b717eb)。
Fixed
- worktree 提交不再双跑全套测试(PreToolUse 与共享 git pre-commit 的去重判定 此前恒失效,注释自认 "at worst double-runs")。
- gate -qq 误报(STORY-202609025bc9246b6a54):repo
addopts=-q叠加导致 flaky 真红被误报 no tests collected——junitxml 权威计数通道修复。 - 流式 pytest 输出保住超时上限:Popen 化后读循环补 threading.Timer 看门狗, 无输出挂起在期限内触发 GateUnavailable(复现测试当场卡死实证)。
- done-verify 不再把 Spec 散文里的模板占位符当声明测试文件;
spec-guard解锁原因行不再被吞;pactkit risk输出对齐软预算语义 ((initial read, max 3),空结果提示复核 uncovered risk)。 - 审计记录不落凭据(2026-08-30 发现的续修):命令派生文本入库前 redacted。
Changed
- 行为变更(有意):Spec 编辑锁定从"有 receipt 即锁"改为指纹失效制;验证记录 无归属时不再猜 Story;PreCompact 不再全量刷新 context(SessionStart 单次生成)。
pactkit doctor决策可追溯性降为 WARN(否决才阻断);Codex 默认不再注入 config.toml。- Constitution/prompt 预算基线 107317→109200(逐项理由见
tests/unit/test_story063_prompt_slimming.py注释链)。
2.25.2 — 2026-09-02
Fixed
- commit-gate counts survive repo
addoptsinterference — the gate parsed pass/fail counts from pytest's terminal summary line, but a repo'saddopts = "-q"stacks with the gate's own-qinto-qq, where pytest 9 prints no final summary at all: every run parsed as all-zero, and a genuinely red run was misreported as "no tests collected". Counts now come from a--junitxmlside channel that verbosity cannot suppress, with the terminal parse as fallback; repoaddoptsare otherwise fully honored (required flags such as--asyncio-mode=autokeep applying), and a repo that disables the junitxml plugin degrades to terminal parsing instead of locking commits. Failure messages now report the exit code's actual meaning (no tests ranfor exit 5, usage error for exit 4,counts unparseablewith an addopts hint otherwise), andFAILED/ERRORshort-summary lines reach the block message.
2.25.1 — 2026-09-01
Fixed
pactkit gate authorize <scope>— the form every gate block message documents — now works (the parser previously accepted only the bare positionalpactkit gate <scope>; both forms are valid now).- Gate hooks evaluate
cd <other-repo> && git pushagainst the target repository's enforcement config instead of the session directory's. - commit-gate no longer misfires on docs/meta-only commits —
.gitignore/.claude/**/.codex/**count as doc-only (repo/agent metadata carries no runtime code and no longer disqualifies the change set from the skip path); the full-suite target falls back fromtests/unit/totests/when only a flat layout exists; a zero-collected run reports "no tests collected" instead of implying failures (still RED — the TDD contract is unchanged);No module named pytestfrom a venv-less fallback interpreter degrades to WARN + allow, matching the missing-binary path (R3 self-lock protection).
2.25.0 — 2026-08-30
Added
- Protected-branch push gate —
git pushto a protected branch (defaultmain/master) is intercepted across all three channels (PreToolUse, codex hooks.json, git pre-push) and blocked with the sanctioned path, the human bypass (PACTKIT_ALLOW_DIRECT_PUSH=1), and the repo-owner config. Direct commits on protected branches block by default;--no-verifyis no longer a free bypass. Audited underpush_gate. - Tamper guard — agent modification of enforcement artifacts (
.git/hooks/**,.pactkit/enforcement/**,.codex/hooks.json, gate registrations in settings.json) is blocked. - L1 Hard-Rule Override Protocol — core rules now state that L1 rules are never waivable in conversation; a conflicting user instruction is refused, and editing rules/hooks/config to comply is itself L1 tampering.
- Stack-aware commit-gate — the gate runs the detected stack's real suite (
npm test/go test ./.../mvn|gradle test) instead of forcing pytest onto non-Python repos; doctor probes are stack-aware. - Session context hooks —
pactkit gate --hook session-startinjects regenerated.pactkit/context.mdat session start and after compaction;--hook pre-compactrefreshes state as a side effect and never blocks compaction. - Spec tampering guard — editing a spec with an active preflight receipt is blocked during Act ("Spec is Law", L1); Plan-phase spec writing is unaffected.
- Authorization gate — external-effect commands (PR/release/publish/repo operations) block until the user confirms;
pactkit gate <scope>opens a short-TTL audited window. - Secrets gate — literal credential material in commands blocks by default; env-var indirection (
password=$DB_PASS) is exempt. - Gate telemetry — gate blocks, authorizations, and Skill invocations feed the run-event stream;
pactkit statsreports per-gate block counts, per-command invocation counts, and authorization pairs at project scope. enforcementconfig section — protected_branches / allow_direct_push / tamper_guard / spec_guard / auth_gate / secrets_gate / auth_ttl_minutes, with safe defaults.
Fixed
- Git hooks no longer lock out machines without pactkit (PATH probe + WARN instead of exit 127).
- Audit records no longer persist credentials — command-derived text is redacted before any persistence;
pactkit cleanscrubs legacy records once.
Changed
- Direct commits on
main/masternow block by default (previously: full suite only) — opt out viaenforcement.allow_direct_push.
2.24.2 — 2026-08-27
Fixed
--format allinstalls the codex hooks channel (was: only explicit--format codex).
2.24.1 — 2026-08-27
Fixed
- Enforcement probes resolve the project venv's pytest (pipx-installed CLIs no longer report gates unavailable).
2.24.0 — 2026-08-27
Added
- Run event streams (append-only, crash-tolerant);
pactkit statsfriction metrics; gate enforcement completeness reporting (full/degraded/unavailable+pactkit doctor --jsonenforcement section); Codex native hooks thin registration; authorization audit trail (asked/granted/deniedevents +pactkit continuation deny); outcome_unknown crash recovery (attempt fences with pid); command manifest v2 reference digests.
2.23.0 — 2026-08-27
Replaces the withdrawn 2.21.0/2.22.0 — both were pulled from PyPI shortly after publication due to serious defects.
Added
- Spec preflight + native sessions —
/project-actPhase 0.7 deterministically inlines the Spec's referenced implementation inputs and constraints (with receipts) before any source edit. - Progressive PDCA rule loading — the 16 on-demand rules load on trigger instead of always; every rule states its specific trigger and evidence.
- Unified deployment ownership safety — the manifest-hash ownership proof now covers skills, command prompts, agents, CLAUDE.md and rollback: user-modified files are preserved as
.pactkit-newcandidates, deletions require manifest proof. - Machine-checked prompt-to-CLI consistency — prompts referencing unregistered CLI subcommands now fail CI instead of failing an AI mid-session.
- Legacy-engine usage counter —
pactkit doctorsurfaces the invocation count that gates the frozen legacy package's deletion.
Fixed
- Gates fail closed — pip-audit verdicts, coverage blocks, and commit-gate collection failures no longer masquerade as pass.
- No bricked runs — vanished artifacts fail recoverably (
artifact_vanished), corrupt unrelated run files are skipped safely, Windows engine mutations fixed. - pactkit.yaml multi-copy sync — syncs from the copy readers actually load; writes are atomic.
- Prompts off the legacy surface — Act/Plan prompts no longer invoke the deprecated
continuation/checkpoint commands.
Removed / Deprecated
- Preflight guard hook removed (near-zero enforcement value, session noise); the preflight loader stays in full.
- Legacy workflow engine frozen in
pactkit.legacy— deletion candidate, gated on one release cycle of zero explicit invocations.
2.22.0 — 2026-08-24
Added
- Unified WorkUnit scope derivation for non-standard directory layouts — WorkUnit read/write scope is no longer a hardcoded
src/**/tests/**whitelist. Aresolve_scopeSSoT unions each unit's frozen template floor with project-declaredwrite_scoperoots (source_roots/test_roots/docs_roots) and the Spec'sTouches, so projects withfrontend/src/,backend/,directus-extensions/layouts no longer blockproject-act/project-hotfix. Union (not intersection): the Spec (Tier-1) is never clipped by mutable config.
Fixed
- Completed runs survive legitimate cross-workflow projection evolution — after Plan → Act,
project-check/project-donestart andpactkit work-unit status <plan-run>no longer crash withinvalid_workflow_state. Predecessor lookups scan sibling journals leniently, andfinalize-workflowregeneratescontext.mdto the post-completion canonical. Execution reads stay strict, so tampering is still detected.
2.21.0 — 2026-08-24
Added
- Complete Core-owned lifecycle — all 12
project-*commands now execute as bounded, versioned WorkUnits. Core validates evidence, owns scheduling and journaled completion, and never treats an agent's final response as workflow completion. - Resumable Codex integration — the official App Server bridge persists one thread per run, resumes it across processes, constrains model output with schemas, and converts malformed output or lease failures into durable retries.
Changed
- Act closes the real Story — RED → GREEN, regression, lint, and coverage gates are followed by a crash-recoverable Core transaction that completes canonical Story tasks and regenerates the Sprint Board.
- Side effects require explicit authorization — commits, pushes, pull requests, tags, publishing, releases, and Sprint orchestration pause before execution until approved.
- Distributed IDs —
pactkit generate-idreplaces the removed sequentialnext-idcommand.
Fixed
- Premature workflow stops — finish guards, persisted attempts, idempotent finalizers, and cross-process thread resume keep interrupted Codex workflows recoverable.
- Honest host capability reporting — Doctor reports verified Codex
resumablecapability without hiding weaker hosts; per-host guarantees remain visible.
2.20.0 — 2026-08-22
Added
- Verified resumable Act checkpoints — Story-scoped continuation records validate Spec, Board, focused tests, regression, and lint evidence across process restarts.
Fixed
- Adapter-safe rendering and deployment gates — command rendering preserves CLI semantics across hosts and blocks incompatible Core/adapter combinations.
2.19.0 — 2026-08-17
Added
- Spec Dependency Surface (STORY-slim-143) — every scaffolded Spec now carries a machine-readable
## Dependency Surfacetable (Depends on / Provides / Touches / Conflict risk). Story ordering and file-level conflict surface become data, not tribal knowledge. pactkit spec-graph(STORY-slim-143) — deterministic story dependency DAG: topological execution waves (same-wave stories are parallelizable), a file-overlap conflict matrix, cycle detection, and Mermaid output. Stdlib only, zero new dependencies.- Sprint Wave Mode (STORY-slim-144) —
/project-sprintwith no arguments scans the backlog, consumesspec-graph --json, and runs conflict-free same-wave stories as parallel worktree subagents (capsprint.max_parallel, default 3). Conflicted or under-declared stories serialize safe-by-default; wave N+1 waits for wave N fully merged green. Single-story mode unchanged. - Linter rules E010/W011 (STORY-slim-143) — dangling
Depends onreferences block Act; missing Dependency Surface warns.
2.18.0 — 2026-08-17
Added
- Deployment manifest content hashes (STORY-slim-141) — deploys now record per-file sha256 in
.pactkit-deployed.json;pactkit doctorparity check drops to content level, so "version stamp says new, files are old" drift becomes an explicit report. User-editable files (CLAUDE.md, configs) are structurally excluded — zero false positives on your own additions. - Adapter version skew warning (STORY-slim-142) — doctor warns when an installed adapter package (e.g. pactkit-opencode) lags behind core, with a
pipx injectupgrade hint.
Fixed
- Preview/test deploys no longer clobber live adapters (STORY-slim-142) —
deploy(format="all", target=...)used to invoke adapter deployers with their real home targets, silently overwriting~/.config/opencode& co. Adapters are now skipped with a notice when-tis given. - CI template actions bumped to checkout@v7 / setup-python@v7 — regenerating workflows no longer reverts dependabot updates.
2.17.0 — 2026-08-13
Added
pactkit done-verify(STORY-slim-136) — Mechanical archive-honesty gate for/project-done: requirement→test evidence chains, checkbox↔case consistency, zero-caller detection, and Spec/Board/archive status consistency. FAIL blocks archiving.pactkit commit-gate(STORY-slim-138/140) — Pre-commit test gate with skip≠pass transparency. Claude Code PreToolUse hook auto-installs via init/update; non-Claude formats get a git pre-commit fallback automatically. Self-lock protection built in.pactkit deps(STORY-slim-137) — External dependency registry (node/codegraph/gh) withdeps checkand guideddeps install./project-initPhase 1.5 asks before installing; CLI init only reports.pactkit schema config(STORY-slim-135) — Every pactkit.yaml key with default, effective value, and source.- Deployment parity in
pactkit doctor(STORY-slim-139) — Deploys write.pactkit-deployed.json; doctor reports cross-format drift explicitly.
Changed
- Schema-driven pactkit.yaml (STORY-slim-135) — CONFIG_SCHEMA single source; fresh init writes minimal yaml (stack + developer); multi-copy sync with drift detection.
- Skill deployment manifest (STORY-slim-139) — codex/copilot adapters consume the core manifest; silently dropped skills (garden/audit/report) restored.
Fixed
- Codex adapter config.toml policy — never modifies an existing file (create-if-absent only) after two wipe incidents.
- OpenCode global instructions — merged constitution no longer stripped from the always-load layer.
2.16.1 — 2026-07-23
Fixed
- Bedrock VS Code plugin model compatibility (STORY-slim-134) — Removed
model:field from all/project-*command frontmatter. Claude Code was resolvingmodel: sonnet/opusto Anthropic's latest model ID, bypassingANTHROPIC_DEFAULT_SONNET_MODELin VS Code plugin environments. Commands now inherit the session default model set by the user's provider env vars.
2.16.0 — 2026-07-13
Added
/project-debugcommand (STORY-slim-133) — Hypothesis-driven troubleshooting skill. Structured loop: Symptom → Hypothesize (≤3) → Verify (executable commands) → Narrow → Root Cause. Enforces evidence-gated file access (no aimless reading) and convergence guarantees (escalates to/project-planif stuck after 3 iterations). Uses sonnet model with structured protocol.
2.15.2 — 2026-07-02
Changed
- Codegraph commands decoupled from prompts (STORY-slim-132) — Replaced hardcoded codegraph CLI command lists with runtime
codegraph --helpdiscovery. PactKit no longer needs updates when codegraph changes its command signatures.
Fixed
- Act Phase 0.6 board move command (HOTFIX-slim-132) — Added explicit
board.py move_storycommand template to prevent AI from guessing wrong syntax. - Prompt deployer (HOTFIX-slim-131) — Insert @ references after YAML frontmatter so model: field is parsed.
- Skill frontmatter (HOTFIX-slim-130) — Move @ references below YAML frontmatter in project-* skills.
Refactored
- Moved large rules from @inject to on-demand Read to reduce initial context size.
2.15.1 — 2026-06-10
Added
- Engineering Concerns guide system (STORY-slim-128) — On-demand NFR guide loading via trigger index. Plan Phase scans requirement keywords and includes NFR decisions in Spec; Act Phase loads matched guides (1-3 max). 13 initial concerns covering concurrency, async, database, caching, API integration, events, resilience, memory, observability, configuration, module design, code-review-first, and component-reuse.
- 6 additional engineering guides (STORY-slim-129) — error-recovery, data-consistency, backwards-compatibility, performance-antipatterns, graceful-shutdown, testing-strategy. Total: 19 guides.
lintoptional dependency group —pip install pactkit[lint]includes ruff.
Fixed
- Spec linter accepts heading format for Security Scope entries.
- CI tree-sitter tests skip gracefully when not installed.
2.14.2 — 2026-06-01
Added
- Managed-block update for project CLAUDE.md (STORY-slim-127) —
pactkit updatenow uses<!-- pactkit:start -->/<!-- pactkit:end -->markers. User content outside the managed block is preserved across updates. - Codegraph sync enforcement via code (STORY-slim-126) —
pactkit visualize --lazyandpactkit syncnow runcodegraph syncautomatically when.codegraph/exists. - Codegraph priority in generated CLAUDE.md — Projects with
.codegraph/get a "Code Intelligence" section instructing AI to prefer codegraph over grep/find.
Changed
- MCP strategy trimmed to Context7 + Memory — Removed Playwright, Chrome DevTools, Draw.io, and shadcn from MCP recommendations. Less noise, same value.
- Config backfill removed —
pactkit updateno longer writes default sections back intopactkit.yaml. Absent keys = accept default.
Fixed
- Stale rule warnings — Removed obsolete rule names from
.opencode/pactkit.yaml.
2.14.0 — 2026-05-26
Added
- Codegraph integration (STORY-slim-124) —
pactkit querynow reads from.codegraph/codegraph.db(generated by@colbymchenry/codegraph) whenvisualize.graph_provider: codegraphis configured. Provides 2.6x more edges than pactkit's own suffix-match resolution, with qualified names, line numbers, and type-aware resolution. - Auto-init codegraph — When
graph_provider: codegraphis set and.codegraph/codegraph.dbis missing,pactkit queryauto-runscodegraph init -iif the CLI is on PATH. - Graph Query Protocol dual-mode — PDCA commands now support Codegraph Mode (
pactkit query+ codegraph CLI) and Grep Mode (fallback on.mmdfiles). - Model frontmatter on all PDCA skills (STORY-slim-125) — All 11 command/skill prompts had explicit
model:frontmatter added. (Reverted in 2.16.1 — see STORY-slim-134)
Removed
_write_sqlite_db()— Pactkit no longer generates its owncall_graph.db. The upstream codegraph tool produces a superior graph with tree-sitter + import-aware resolution.visualize.sqlite_outputconfig — Replaced byvisualize.graph_provider: codegraph.
Changed
pactkit query— Now reads.codegraph/codegraph.db(codegraph schema with hash IDs, JOIN edges+nodes) instead of pactkit's owncall_graph.db.- PDCA prompts updated — All references to
call_graph.db/ "SQLite Mode" removed from Plan, Act, Check, Done, Hotfix, and Trace skills.
2.13.0 — 2026-05-07
Added
pactkit interface-summaryCLI — AST-based interface extraction that physically outputs only signatures, types, and docstrings. Enforces "Code Enforces, Prompt Instructs" for Act Phase 1 layered loading — AI receives truncated content by design.- Journey Sync in Act Phase 4 — Conditional step that updates
docs/e2e/journey.mdwhen a Story modifies journey-relevant steps. Closes the create→consume→update lifecycle gap. - Journey Segment in Plan Phase 3.2a — Conditional Spec annotation that links Stories to journey steps, enabling Act Phase 4 auto-detection.
2.12.0 — 2026-05-06
Changed
- Rules architecture refactor — Merged 6 global core rules into single
pactkit.md; on-demand rules renumbered 01-06 and moved to~/.claude/skills/_rules/. Reduces context window usage by ~60% per conversation. - Auto-deploy on version mismatch — After
pipx upgrade pactkit, the next CLI command auto-syncs deployed files without requiring explicitpactkit init.
Fixed
- Hardcoded paths in deployer —
_build_command_rules_header()now usesFormatProfile.rules_dir/skills_dirinstead of hardcoded~/.claude/paths. - Stale filename references — Updated cross-references in visualize.py, commands.py, lazy_visualize.py, and test files to match new rule filenames.
2.11.0 — 2026-04-25
Added
- Lateral Scan — Plan Phase 1 now scans for duplicate patterns before writing Specs. If overlap > 30% with existing implementations, Spec must include
R0: Extract shared abstractionor declare tech debt accepted. - DEFERRED comment mechanism — When skipping a SHOULD requirement, code must include
# DEFERRED(SHOULD): R{N} — reasoncomment. Coverage table output added to Check phase for tracking deferred items.
Fixed
- Residual pactkit.yaml version operations — Removed
update_version()function and CLI subcommand from board.py, plus all stale references in prompts, agents, and skills docs. Version is now exclusively managed inpyproject.toml+__init__.pywith deploy marker at~/.claude/.pactkit-version. - CI tree-sitter deps — Install tree-sitter optional dependencies separately in CI workflow.
2.10.6 — 2026-04-22
Fixed
- L3 SHOULD semantics — Signal Strength Convention L3 Recommended changed from "Violation = warning, non-blocking" to "Default required — skip only with stated reason" (RFC 2119). Prevents AI from systematically deferring SHOULD tasks.
2.10.5 — 2026-04-21
Added
- Solution Design Protocol — New rule
12-solution-design.mdrequires capability delta assessment (framework native + project existing) before implementation. Prevents framework blindness, project blindness, and hardcoded coupling. Includes Implementation Constraints (no magic values, OCP, SRP, dependency direction). Integrated into Plan Phase 1 and Act Phase 1.
Changed
- Global version tracking — Version tracking moved from project-level
pactkit.yamlto global~/.claude/.pactkit-versionmarker. Eliminates cross-project desync when PactKit is upgraded viapipx.pactkit update --if-needednow checks the global marker instead of project yaml.
2.10.4 — 2026-04-20
Added
- Hotfix Impact Check —
/project-hotfixnow includes Phase 0.5 that reads existing.mmdcall graph files before fixing. Warns when target function has 3+ callers. Advisory (L3), non-blocking, gracefully skips when no graphs exist.
2.10.3 — 2026-04-20
Fixed
- Protected parent dirs in
pactkit clean—rglob("dist")was matchingnode_modules/*/dist, destroying npm dependency internals. Added_inside_protected()guard fornode_modules/and.git/; explicit path patterns now use direct matching instead of rglob. - CI tree-sitter tests — CI workflow now installs
[visualize]extras so Java/TS analyzer tests pass in GitHub Actions.
2.10.2 — 2026-04-20
Added
- PDCA Nudge Protocol — AI proactively recommends PDCA commands when free conversation yields actionable conclusions. Trigger matrix maps signals to commands; suppression rules prevent noise.
- Dual-dimension Harness Audit — Audit now scores two dimensions: Config (project + global config, 50pts) and Code (tests, lint, complexity, git hygiene, 50pts). JSON output includes
dimensionsbreakdown field. - Unified HTML Report Dashboard — Single
report.htmlwith tab switching, D3 force-directed graph, harness score ring, layer bars, and hotspot panel.
Fixed
- Shared Protocols Context.md reference — Added missing
Act Phase 4to the Context.md Canonical Format "Referenced by" line. Ensures context.md reflects Act progress for session continuity. - Semantic version comparison — Version mismatch warning now uses tuple comparison instead of string equality, giving correct upgrade/downgrade direction.
- Focus call graph empty output — Fixed focus resolution to use
LANG_PROFILES[stack].source_dirsinstead of hardcodedsrc/prefix.
2.9.13 — 2026-04-15
Fixed
- Slim core dependencies — Moved adapter packages (
pactkit-opencode,pactkit-codex) and tree-sitter bindings to[project.optional-dependencies]. Corepip install pactkitnow only requirespyyaml. Install extras withpactkit[all],pactkit[visualize],pactkit[opencode], orpactkit[codex]. - Spec-lint CLI fallback — Playbooks now include
python3 -m pactkit spec-lintfallback for environments wherepactkitis not on$PATH. - Board add_story signature — Plan playbook Phase 3.3 now shows complete
add_storyinvocation with all required arguments.
2.9.12 — 2026-04-02
Added
- Copilot deployer adapter —
pactkit-copilotadapter package registered via entry_points.pactkit update --format copilotdeploys skills, commands, agents, andcopilot-instructions.mdto.github/. - OCP-compliant rules header dispatch —
_build_command_rules_header()dispatches onprofile.rules_import_styleinstead of hardcoded profile name checks. - Multi-stack auto-detection —
pactkit initauto-detects multiple stacks and writesstack: [python, typescript]list syntax topactkit.yaml. - Two-tier module graph —
visualize --mode modulegenerates dimension-based subgraphs. - Prompt template sync — Canonical prompt templates rendered consistently across all deployer formats.
Fixed
- OpenCode
rules_import_style— Corrected from"instructions"to"inline"to match actual behavior.
2.9.11 — 2026-04-01
Fixed
- Rules template variables —
_deploy_rules()now renders{PROJECT_CONFIG_DIR}and other template variables via_render_prompt(). Previously rules were deployed with raw template strings in Codex/OpenCode. - Copilot agent YAML corruption — Agent
tools:field was iterated char-by-char ([R, e, a, d, ...]→[Read, Write, ...]). - Copilot double annotation —
(terminal only) (terminal only)reduced to single annotation. - Skill CLI refs — All SKILL.md files now pass through
_replace_slash_commands().
2.9.10 — 2026-04-01
Fixed
- Skill script
__future__import —load_script()now hoistsfrom __future__ import annotationsabove_SHARED_HEADER, fixing SyntaxError in deployedspec_linter.py. - Lessons table auto-repair —
append_lesson()now calls_repair_table_structure()before appending, fixing: missing header, wrong header format, data rows before header.
2.9.9 — 2026-04-01
Added
- GitHub Copilot adapter support — New
copilotFormatProfile.pactkit init --format copilotdeploys to project.github/directory. - Dynamic
--formatCLI choices —init,update,upgradecommands derive choices fromVALID_FORMATSinstead of hardcoded list.
Fixed
- Excluded command stripping —
strip_excluded_command_references()strips/project-sprintreferences from all rendered prompts for formats that exclude it.
2.9.4 — 2026-03-31
Fixed
- Init playbook DIP violation — Eliminated
DETECTED_ENVruntime IDE detection; all hardcoded paths replaced with template variables. - Full DIP audit — Fixed hardcoded IDE paths in doctor skill, core-protocol rule, and done command.
- tree-sitter promoted to core dependency — No longer optional; CI install updated.
--focusscan optimization —_scan_filesnow scans only the focused subdirectory, not the full project root.- SCAN_EXCLUDES expanded — From 13 to 30+ entries covering Go, Java, Node, IDE, and VCS directories.
2.9.3 — 2026-03-31
Added
- Multi-language call chain fix (STORY-slim-069) — Dispatch hint comment parsing (
pactkit-trace: dispatches_to) and inheritance edge linking extended from Python-only to Go (struct embedding), Java (extends/implements), and TypeScript (class extends) tree-sitter analyzers. - CLI visualize args exposed (HOTFIX-slim-070) —
--entry,--focus,--reverse,--depth,--max-nodesnow reachable frompactkit visualizeCLI.
Fixed
- 4 call chain断链 (STORY-slim-068) — dict.update scan collision, dynamic dispatch hints, abstract method orphan nodes, cross-package stub edges.
- Nested subgraph call graph (STORY-slim-067) — Fan-in/fan-out analysis with subgraph grouping.
- Edge dedup + cycle fix (HOTFIX-slim-069) — ×N labels for duplicate edges, false positive cycle detection eliminated.
2.9.2 — 2026-03-30
Fixed
- FormatProfile.excluded_commands —
project-sprintexcluded for OpenCode/Codex (requires subagent team, Claude Code only). Doctorcheck_config_driftnow respects format-level exclusions. - Redundant pactkit.yaml component lists — Removed explicit agents/commands/skills/rules lists from
.opencode/pactkit.yaml(absence = deploy all). - Orphaned spec cleanup — Removed 7 pre-developer-prefix spec files that were already archived.
2.9.1 — 2026-03-30
Added
- Topology-aware trace — ApiCallParser (tree-sitter-typescript) and AgentParser (LangGraph/YAML/MCP) for multi-topology code tracing. Plan/Act phases now include topology gate.
Fixed
- Monorepo subdirectory detection — TopologyParser.detect() now scans immediate subdirectories, fixing false negatives for monorepo layouts.
- Doctor false drift warnings —
check_config_drift()now searches global deploy directories instead of only project-local paths. - Canonical lessons.md header — Init enforces
| Date | Lesson | Context |table header, preventing AI-invented column names.
2.9.0 — 2026-03-28
Added
pactkit initdeploys all IDEs by default —--format allis now the CLI default, deploying Claude Code + OpenCode + Codex configs in one shot. No need to specify--formatper IDE.
Fixed
- Entry_point deployer circular import — Lazy-load entry_point deployers to fix
ValueErrorwhen runningpactkit initvia pipx.
2.8.0 — 2026-03-27
Added
- 3-IDE Default Install —
pip install pactkitnow installs all three IDE adapters (Claude Code + OpenCode + Codex) out of the box.
Fixed
- OpenCode Command Architecture — Reverted OpenCode from skills-only back to
commands/+skills/dual architecture. OpenCode auto-discovers commands fromcommands/*.md, while embedded skills inskills/are loaded by AI agent on demand. - Spec Version Confusion —
/project-planno longer reads version frompactkit.yaml(toolkit version). Now explicitly reads from project manifest (pyproject.toml,package.json).
Changed
- Cross-IDE Command Architecture:
- Claude Code: skills-only (
skills/project-*/SKILL.md), prefix/ - OpenCode: commands + skills (
commands/project-*.md+skills/pactkit-*/SKILL.md), prefix/ - Codex: skills-only (
skills/project-*/SKILL.md), prefix$
- Claude Code: skills-only (
2.7.0 — 2026-03-27
Added
- Commands → Skills Migration (STORY-slim-063) — 11 PDCA commands now deploy as
skills/{name}/SKILL.mdsubdirectories for Claude Code format.VALID_SKILLSexpanded from 10 to 21 entries. - Legacy Command Cleanup — Auto-removes old
project-*.mdfromcommands/on upgrade. - Codex FormatProfile (STORY-slim-060) — Re-added
codexprofile to core for thin adapter pattern.pactkit-codexpublished to PyPI. - 3-Package Coordinated Release — First simultaneous release across
pactkit,pactkit-opencode, andpactkit-codex.
Fixed
- board.py update_task (HOTFIX-slim-061) — Recognizes bullet-format Done entries.
- visualize --lazy focus (HOTFIX-slim-062) — Removed hardcoded focus refresh; added stem matching.
Changed
- Unified deploy summary shows
Skills (embedded + commands)count. - Cross-format isolation: OpenCode and Codex unaffected by skills migration.
2.6.0 — 2026-03-26
Added
- DeployerProtocol & DeployerBase (STORY-slim-057) — Extracted deployer interface and shared base class with registry pattern for adapter-based plugin architecture.
- pactkit-opencode Adapter Package (STORY-slim-058) — Extracted all 8 OpenCode-specific functions into standalone package with entry_points-based auto-registration.
- Entry Point Auto-Discovery — Scans
pactkit.deployersentry_point group at import time for zero-config adapter registration.
Removed
- Codex Profile (STORY-slim-059) — Removed dead codex FormatProfile and all references. VALID_FORMATS auto-shrinks via FORMAT_PROFILES.keys().
- OpenCode Functions from Core — 8 functions (~300 lines) moved to pactkit-opencode adapter. deployer.py reduced -17%.
Changed
- deploy() dispatches via registry instead of if/elif chain. New formats only need register_deployer().
2.5.0 — 2026-03-26
Added
- E2E CLI Coverage 100% — 60 subprocess-based E2E tests covering all 25 CLI subcommands
python -m pactkit— Package now supports module invocation as alternative entry point
Fixed
- Mermaid Quote Injection — File/function names containing
"no longer break.mmdgraph rendering - O(N×E) Callee Resolution —
_resolve_callee()uses pre-built suffix index for O(1) lookup - Module Index Collision — Same-name files in different directories no longer cause silent node loss
- Focus Substring False Positives —
--focus auth.pyno longer matchesoauth.py - BFS O(N²) Pop — All BFS sites now use
deque.popleft()instead oflist.pop(0) - Non-Atomic Writes —
pactkit.yaml,.mmdfiles, andatomic_write()all use tmp+rename pattern - Deployer Encoding — 3 bare
read_text()calls now specifyencoding='utf-8' - Large File OOM —
MAX_FILE_BYTES=1MBguard prevents OOM on auto-generated mega-files - Sprint Redundant Operations — Eliminated duplicate visualize/clean/context runs
2.4.1 — 2026-03-26
Fixed
- CI Template Override —
pactkit updateno longer reverts customci.install_cmdinpactkit.yaml - Board ID Validation — Now supports developer-prefixed IDs (
HOTFIX-slim-052,STORY-alice-001)
Added
- Board
move_storyCommand — Move stories between board sections via CLI - Automated PyPI Publish — Tag-triggered CI publishes to PyPI via trusted publisher (OIDC)
Changed
- Closed-Source Migration — Source repo now private; public entry point at pactkit-public
2.4.0 — 2026-03-25
Added
- Multi-Architecture Topology Analysis —
pactkit visualizenow understands 3 project topologies beyond code structure:- PDCA topology — Plan→Act→Check→Done sequence edges in workflow graphs
- Service topology — Parses
docker-compose.yml,openapi.yaml,*.protofor service dependency graphs - Frontend topology — Parses Next.js (App/Pages Router), Vue Router for page→component→hook→store chains
- Cross-topology impact — Regression analysis works across all topology types
- Unified layered graph — Merges code + topology dimensions into a single visualization
Fixed
- Topology auto-detection reliability improvements
- CI dependency configuration for multilang test coverage
- Spec/PRD cross-reference consistency (4 issues)
2.3.0 — 2026-03-22
Added
- 25 Deterministic CLI Subcommands — Core operations now run as Python code, not prompts:
clean,regression,context,lint,test-map,coverage-gate,doctor,spec-lint,spec-status, and more - Coverage Gate —
pactkit coverage-gateenforces 3-tier thresholds (≥80% PASS, 50-79% WARN, <50% BLOCK) - Auto Version Sync —
pactkit update --if-neededskips redeploy when already current - E2E Testing Framework — Config-driven E2E strategy in
pactkit.yaml - Spec Linter Enhancements — W007 Req-AC coverage, W008 placeholder detection, E007 per-subsection validation
Fixed
- Plan phase stall on large Spec generation (split into sub-steps)
- Explore subagent unbounded search (bounded delegation pattern)
- 25+ cross-flow integrity gaps across CLI and prompt references
2.2.0 — 2026-03-20
Added
- Context-Aware Rule Loading — Each command loads only the rules it needs, reducing token usage by 20-83%
- Stack-Aware CI Pipeline — Supports Python, Node.js, Go, and Java with correct setup and test runners
- GitHub Enterprise (GHE) Support —
ci.github_hostandci.actions_refconfiguration
2.1.0 — 2026-03-17
Added
- Multi-Format Deployment — Adding a new AI tool format requires only one registry entry; all downstream code auto-adapts
- Template Variables — 48 hardcoded paths replaced with named placeholders resolved at deploy time
- Document Schema Registry —
pactkit schema [type]CLI for document structure rule discovery - Lazy Rule Loading — Per-turn system prompt overhead reduced by 62%
Fixed
/project-initenvironment detection improvements- Config merge preserves user entries (no more overwrites)
Earlier Releases
- 1.5.0 — PDCA Quality Gates, Impact-Based Regression, Done/Release/PR command split, Community Standards
- 1.4.0 — Spec Linter (14 rules), Active Clarify Gate, Pre-Act Consistency Check, Auto-PR
- 1.3.0 — CI/CD Pipeline Generation, Issue Tracker Integration, Hook Templates, Doctor Diagnostics
- 1.0.0 — Initial public release. 9 agents, 13 commands, 3 skills, 6 constitution rules