Skip to content

v1.17.0

Latest

Choose a tag to compare

@rubenvdlinde rubenvdlinde released this 10 Sep 04:02
· 168 commits to main since this release
80c58c0

Five new gates and two behaviour changes. The reason this tag matters is that it closes a gap nobody could see: gates 111 to 113 merged after v1.16.1 was cut on 2026-09-07, so since then every app's vendored copy has declared 90 gates while CI ran 93, and the three missing ones included both report-only gates. Nothing in a consuming repo could close that. composer update would have reported success and changed nothing, because the constraints were already satisfied and the versions were simply not released.

v1.16.1 declared 90 gates. v1.17.0 declares 95.

What is new

gate name posture
111 flow-node-taxonomy blocking
112 newman-reach report-only, HYDRA_GATE_NEWMAN_REACH_BLOCKING=1
113 exclusion-evidence report-only, HYDRA_GATE_EXCLUSION_EVIDENCE_BLOCKING=1
114 header-action-budget report-only, HYDRA_GATE_HEADER_ACTION_BUDGET_BLOCKING=1
115 stale-fleet-app-id report-only, HYDRA_GATE_STALE_FLEET_APP_ID_BLOCKING=1

Two behaviour changes to gates you already have:

  • gate-46 now resolves @e2e anchors (report-only) and opens appinfo/ and scripts/ (blocking).
  • A report-only gate no longer prints a FAIL verdict line. gate-112 and gate-113 used to print FAIL from their helper while the runner printed WARNING for the same gate 45 lines later. Two readers counted a failure that had not happened. There is now one verdict line per gate, enforced by the acceptance matrix.

What your repo will start seeing

Measured 2026-09-10 against a clean development clone of each of the 21 core apps. Repos not listed are clean for that gate.

gate-115 stale-fleet-app-id — 20 findings in 6 repos

repo stale names migrated slugs total
pipelinq 2 5 7
learniq 4 0 4
openregister 1 2 3
buildiq 1 2 3
launchpad 2 0 2
hermiq 0 1 1

gate-112 newman-reach — 28 findings in 9 repos: openregister 17, pipelinq 3, opencatalogi 2, and one each in decidiq, dossiq, hermiq, learniq, portaliq, stackiq.

gate-113 exclusion-evidence — 0 unresolved anywhere. It still prints its worklist on every run, so you will see a line like 468 exclusion(s) — 156 name a test that is here, 254 claim a tier without naming a member of it. That is a census, not a finding.

gate-114 header-action-budget — 0 findings without a delta base. It is a ratchet, so a full-scope run with no --base prints its census and says the ratchet half did not run. It reports growth only against a base.

gate-46 — per the change authors, 194 dangling @e2e anchors across four repos (report-only) and 10 findings in three repos from the new directories (blocking). Those figures are theirs, not measured here.

Read this before "fixing" gate-115's slug findings

Ten of the twenty are register slugs the owning app has migrated away from, and they cannot be fixed by swapping the literal.

Both slugs are live across the fleet depending on whether a given instance has run that app's repair step. Swapping 'openconnector' to 'integriq' breaks every instance that has not migrated yet, which is the same bug pointing the other way. The fix is a probe against OpenRegister for the slug the register actually answers to.

Two things to know before deciding whether a slug reference is one of these:

  • The old slug is not always the old app id. stackiq migrated voorzieningen to stackiq, never softwarecatalog.
  • The repair step is not always called the same thing. learniq's is RenameRegisterSlug; everyone else's is MigrateRegisterSlug. Searching one filename reports learniq as never having migrated.

Read this before acting on gate-115's stale-name findings either

The gate reads names. It cannot see whether the method or route you point at exists on the other side. A repoint that lands on a missing method fails exactly as silently as the stale name did, and the diff reads as a fix.

Every one of the 10 stale names remaining in the fleet is a documented gap where the target does not exist, left deliberately by the sweep that repaired the other 47. The gate prints its own blind spot on every run, pass or fail. hydra-gates/PROPOSAL-cross-app-surface-parity.md is what that line points at.

Why the counts are advisory

Every one of these ships report-only because blocking on day one reddens repos on debt no PR introduced. Each carries a per-repo opt-in variable so a repo is worked down first and turned on second. A green verdict means nothing blocking failed, not that nothing was found.