Releases: CryptVenture/TestAtlas
Release list
v2.0.10
Changelog
All notable changes to this project will be documented in this file. Format is based on Keep a Changelog, and this project adheres to Semantic Versioning. Releases are managed via @changesets/cli.
[Unreleased]
Added
Changed
Removed
[2.0.10] - 2026-05-14
Added
.testatlas/schemas/report.schema.jsonV2 composite sections. 15 new optional top-level properties (kind,priorReport,generationMode,coverage,severityBreakdown,confidenceBreakdown,regressions,qualityRisks,testPyramidHealth,evidenceCatalogSummary,capabilityDegradation,scorecardSnapshot,trendVsPrior,runLogTail,readinessRationale) accept the structured-section shape thatgenerate-report.jsemits.runSummarywidened tooneOf: string | objectso V1 prose-summary reports and V2 structured-summary reports both validate. The V1environmentsCovered/domainsCovered/flowsCovered/testsExecuted/evidenceCountproperties moved fromrequired[]to optional and now carry descriptions pointing at their V2 successors undercoverage/runSummary/evidenceCatalogSummary..testatlas/schemas/test-run.schema.jsonexecution-mode + sub-run shape. New optionalexecutionMode(enum:sequential,sequential-fallback,parallel-subagents,all-flows,all-domains,inline) for the audit-honesty contract/atlas:test-flow,/atlas:test-all, and/atlas:test-domainrequire; new optionalchildrenasoneOf: array | objectso the V1/atlas:test-allsub-run-kind-keyed object and the V2 array shape both validate; new optionalskipped/summary/notesrun-level fields..testatlas/schemas/workspace-manifest.schema.jsoncounts surface widened.counts.scenarios(count oftests/scenarios/TEST-*.jsonwritten by/atlas:test-generate-scenarios) andcounts.charters(count of exploratory charters undertests/charters/) added as optional integers. Both are additive — older manifests continue to validate unchanged.
Changed
scripts/lib/validate/check-schemas.jsskip-before-$schema ordering. Path-based SKIP rules now fire BEFORE the inferer honors a file's own$schemafield. This unblocks V2 sub-artefacts whose authors stamped$schemapointers at schemas that don't exist yet in.testatlas/schemas/(e.g. council persona outputs referencepersona_output.schema.json); previously the inferer accepted the (non-existent)$schemapointer and surfacedTESTATLAS_UNKNOWN_SCHEMAfor every persona output in every council session.scripts/lib/validate/check-schemas.jsfour new SKIP rules.tests/generated_automation/<framework>/<flow-slug>.meta.json(status-tracker sidecars per/atlas:test-generate-automationskill spec),sessions/<persona>.json(Chrome DevTools storageState snapshots — heterogeneous per session),runs/RUN-*.jsonat workspace root (framework-specific per-tool run records distinct fromtests/runs/), andagents/councils/sessions/<id>/outputs/*.json(persona-specific council outputs). Each rule's comment cites the producing command and the reason no canonical schema exists yet.docs/SCHEMAS.mdregenerated. Reflects the new optional properties onissue.schema.json(Phase 47/48 sealing metadata:closedOn,closedAt,closedBy,closedNote,closingPhase,closingPlan,closingCommit,closingNote,closingNotes,closingReq,closedByCommits,closedInPhase,consolidatedInto,statusHistory,by_phase,fix_commit),report.schema.json(the 15 V2 composite sections listed above), andtest-run.schema.json(executionMode,children,skipped,summary,notes).- Example workspaces resynced. The mirrored
brain/schema/trees underexamples/cli-tool/,examples/mobile-web-hybrid/,examples/monorepo/,examples/monorepo/apps/api/,examples/monorepo/apps/web/,examples/nextjs-saas/,examples/node-api/were regenerated so everyissue/report/test-run/workspace-manifestschema in every example is byte-identical to the canonical.testatlas/schemas/.
Removed
[2.0.9] - 2026-05-13
Added
better-sqlite3added todevDependencies— required by recently-added dogfood tooling; absence broke localpnpm installfor contributors using the explore/brain scripts.
Changed
- Release workflow hardened with retry-with-backoff at two known-flaky points. (1)
npm publishis now wrapped in a 3-attempt loop with 10s/30s backoff between attempts. The observed failure (v2.0.7 + v2.0.8, 2026-05-13) wasPOST 201 oidc/token/exchange→ sigstore-provenance-signed →PUT 400 OIDC publish authorize: Invalid token: the OIDC trade succeeded but the actual publish PUT was rejected. npm CLI mints a fresh ID token on each attempt, so retrying clears the failure when it's transient on npm's side; when it's structural (trusted-publisher config drift), all 3 attempts fail and the step exits non-zero with the full verbose log preserved per attempt. (2) The post-publishcurlof the registry tarball URL (used to compute the SHA-256 forinstall.sh+ sigstore sidecar) is now wrapped in a 10-attempt loop with 6s backoff. The race was observed at v2.0.6:PUT 200at T+0s, thencurl 404at T+0.3s — the npm CDN had not yet propagated the new tarball. The pure-publish step now succeeds end-to-end through the install.sh sync, sha256 sidecar emission, sigstore-bundle fetch, and GitHub Release creation in a single workflow run.
Removed
- Phantom 2.0.7 and 2.0.8 git tags + GitHub Releases withdrawn. Both were cut locally by
bump-version.jsbut the release workflow'snpm publishstep was rejected on both attempts (see Changed above), so neither version ever reached the npm registry. Leaving the tags + Releases in place would have confused users runningnpx @webventures/testatlas@2.0.7 …against annpm viewthat doesn't list them. The functional change that v2.0.7 was meant to ship (tarball-URL scope fix below) is rolled forward into this release.
Fixed
scripts/lib/tarball.jsregistry URL now includes the@webventuresscope. Pre-fix,npmTarballUrl(version)returnedhttps://registry.npmjs.org/testatlas/-/testatlas-${version}.tgz(unscoped path), which 404s for a scoped package; the correct form ishttps://registry.npmjs.org/@webventures/testatlas/-/testatlas-${version}.tgz. Symptom:npx @webventures/testatlas updatefailed with 404 when the workflow fell through to direct registry download. (Originally landed as commitf501a56d, was meant to ship in v2.0.7.)
[2.0.6] - 2026-05-13
Fixed
scripts/triage.js#verifyEvidenceOnDiskresolves bare evidence IDs under the canonicalevidence/directory. Pre-fix, when an issue'sevidence[]array contained a bare ID (no/separator) that wasn't yet present in the evidence index, the fallbackstat()looked at<wsDir>/<ID>instead of<wsDir>/evidence/<ID>, causing false-positive missing-evidence flags ontriageruns against workspaces where evidence existed in the canonical spot but the index was stale. Resolver now tries<wsDir>/evidence/<ID>first for bare IDs, falls back to<wsDir>/<ID>for back-compat, and treats paths containing/or\as relative to<wsDir>unchanged. Newtest/scripts/triage-script.test.jscases pin both paths.
[2.0.5] - 2026-05-12
No notable changes since 2.0.4.
[2.0.4] - 2026-05-12
No notable changes since 2.0.3.
[2.0.3] - 2026-05-12
Added
.testatlas/package.jsonESM marker — adds a 4-linepackage.json({"type":"module","private":true}) at the suite root so Node parses the entire.testatlas/scripts/subtree as ES modules without walking up to the consumer's ownpackage.json. Pre-fix, every script invocation in installed targets without"type":"module"in their rootpackage.json(or with nopackage.jsonat all) emitted(node:NNN) [MODULE_TYPELESS_PACKAGE_JSON] Warning: Module type of file:///...validate-brain.js is not specified and it doesn't parse as CommonJS.because Node defaulted to CommonJS, failed onimport/exportsyntax, then fell back to ESM. Scripts ran correctly but every invocation was prefixed with the noisy warning, obscuring real warnings/errors. The new marker is self-contained — doesn't shadow the consumer's ownpackage.json(lives only inside.testatlas/), doesn't ship as a standalone npm package ("private":true), and the suite source's existing rootpackage.json("type":"module") means the marker is harmless when scripts run from the source tree. Ships via the npm tarball atpackage/.testatlas/package.json→extractTarballlands it at<dstDir>/package.json→ atomic swap puts it at<target>/.testatlas/package.jsonfor both init and update paths automatically. The fixture intest/scripts/extract-tarball-strips-package-wrapper.test.jswas updated to includepackage/.testatlas/package.json; the existing assertion that "tarball-rootpackage.jsonmust NOT extract" was flipped to assert the ESM marker DOES extract withtype:"module"content (the strip filterpackage/.testatlasstill correctly excludes the outerpackage/package.json). Top-level shape assertion updated to['adapters','bootstrap.md','migrations','package.json','scripts']..testatlas/adapters/claude-code/.claude/commands/atlas-create-persona.md— adds the long-missing adapter output for thecreate-personasource command. The file was generated locally during phase-17-05 butgit addsilently dropped it because.gitignore's bare.claude/pattern matched the nested adapter path (see Fixed entry below). The file content is byte-identical to whatassemble-adapter --checkwas expecting and matches the 12 sibling adapters that already shipatlas-create-persona.<ext>for the same source.
Changed
- CI workflow
install.sh smoketarball glob —...
v2.0.9
Added
better-sqlite3added todevDependencies— required by recently-added dogfood tooling; absence broke localpnpm installfor contributors using the explore/brain scripts.
Changed
- Release workflow hardened with retry-with-backoff at two known-flaky points. (1)
npm publishis now wrapped in a 3-attempt loop with 10s/30s backoff between attempts. The observed failure (v2.0.7 + v2.0.8, 2026-05-13) wasPOST 201 oidc/token/exchange→ sigstore-provenance-signed →PUT 400 OIDC publish authorize: Invalid token: the OIDC trade succeeded but the actual publish PUT was rejected. npm CLI mints a fresh ID token on each attempt, so retrying clears the failure when it's transient on npm's side; when it's structural (trusted-publisher config drift), all 3 attempts fail and the step exits non-zero with the full verbose log preserved per attempt. (2) The post-publishcurlof the registry tarball URL (used to compute the SHA-256 forinstall.sh+ sigstore sidecar) is now wrapped in a 10-attempt loop with 6s backoff. The race was observed at v2.0.6:PUT 200at T+0s, thencurl 404at T+0.3s — the npm CDN had not yet propagated the new tarball. The pure-publish step now succeeds end-to-end through the install.sh sync, sha256 sidecar emission, sigstore-bundle fetch, and GitHub Release creation in a single workflow run.
Removed
- Phantom 2.0.7 and 2.0.8 git tags + GitHub Releases withdrawn. Both were cut locally by
bump-version.jsbut the release workflow'snpm publishstep was rejected on both attempts (see Changed above), so neither version ever reached the npm registry. Leaving the tags + Releases in place would have confused users runningnpx @webventures/testatlas@2.0.7 …against annpm viewthat doesn't list them. The functional change that v2.0.7 was meant to ship (tarball-URL scope fix below) is rolled forward into this release.
Fixed
scripts/lib/tarball.jsregistry URL now includes the@webventuresscope. Pre-fix,npmTarballUrl(version)returnedhttps://registry.npmjs.org/testatlas/-/testatlas-${version}.tgz(unscoped path), which 404s for a scoped package; the correct form ishttps://registry.npmjs.org/@webventures/testatlas/-/testatlas-${version}.tgz. Symptom:npx @webventures/testatlas updatefailed with 404 when the workflow fell through to direct registry download. (Originally landed as commitf501a56d, was meant to ship in v2.0.7.)
v2.0.6
v2.0.5
Changelog
All notable changes to this project will be documented in this file. Format is based on Keep a Changelog, and this project adheres to Semantic Versioning. Releases are managed via @changesets/cli.
[Unreleased]
Added
Changed
Removed
[2.0.5] - 2026-05-12
No notable changes since 2.0.4.
[2.0.4] - 2026-05-12
No notable changes since 2.0.3.
[2.0.3] - 2026-05-12
Added
.testatlas/package.jsonESM marker — adds a 4-linepackage.json({"type":"module","private":true}) at the suite root so Node parses the entire.testatlas/scripts/subtree as ES modules without walking up to the consumer's ownpackage.json. Pre-fix, every script invocation in installed targets without"type":"module"in their rootpackage.json(or with nopackage.jsonat all) emitted(node:NNN) [MODULE_TYPELESS_PACKAGE_JSON] Warning: Module type of file:///...validate-brain.js is not specified and it doesn't parse as CommonJS.because Node defaulted to CommonJS, failed onimport/exportsyntax, then fell back to ESM. Scripts ran correctly but every invocation was prefixed with the noisy warning, obscuring real warnings/errors. The new marker is self-contained — doesn't shadow the consumer's ownpackage.json(lives only inside.testatlas/), doesn't ship as a standalone npm package ("private":true), and the suite source's existing rootpackage.json("type":"module") means the marker is harmless when scripts run from the source tree. Ships via the npm tarball atpackage/.testatlas/package.json→extractTarballlands it at<dstDir>/package.json→ atomic swap puts it at<target>/.testatlas/package.jsonfor both init and update paths automatically. The fixture intest/scripts/extract-tarball-strips-package-wrapper.test.jswas updated to includepackage/.testatlas/package.json; the existing assertion that "tarball-rootpackage.jsonmust NOT extract" was flipped to assert the ESM marker DOES extract withtype:"module"content (the strip filterpackage/.testatlasstill correctly excludes the outerpackage/package.json). Top-level shape assertion updated to['adapters','bootstrap.md','migrations','package.json','scripts']..testatlas/adapters/claude-code/.claude/commands/atlas-create-persona.md— adds the long-missing adapter output for thecreate-personasource command. The file was generated locally during phase-17-05 butgit addsilently dropped it because.gitignore's bare.claude/pattern matched the nested adapter path (see Fixed entry below). The file content is byte-identical to whatassemble-adapter --checkwas expecting and matches the 12 sibling adapters that already shipatlas-create-persona.<ext>for the same source.
Changed
- CI workflow
install.sh smoketarball glob —.github/workflows/ci.yml:255,264switched fromtestatlas-*.tgzto*testatlas-*.tgzto match both the legacy unscoped name and the currentwebventures-testatlas-<version>.tgzproduced bypnpm packsince the package was renamed to@webventures/testatlasin commit490d44ef(2026-05-04). Pre-fix, the glob expanded to no files →$TARBALL=""→_TESTATLAS_TARBALL_OVERRIDE=$PWD/→install.shtried tocpthe working directory →cp: -r not specified→ exit 1. Both the install and uninstall round-trip steps now also asserttest -n "$TARBALL"as a defensive backstop so a future rename fails loudly instead of silently breaking the same way. - Biome lint debt cleared.
pnpm lintpreviously emitted 33 errors / 19 warnings / 3 infos (auto-detected by Biome 2.x);pnpm biome check --writeapplied safe fixes across 26 files: import-sort organization (alphabetical, grouped by source) and single-line collapse of multi-line single-statement expressions. Zero semantic changes — all 1888 tests remain green / 2 intentional skip post-autofix; full sample-diff review confirmed pure formatting changes (no logic edits, no removed branches, no signature changes). Touched files: 6 underscripts/(mcp-server, reconcile-counts, record-execution-mode, update-brain-after-command, script-flag-metadata, lib/safety) and 20 undertest/(mostly lint-commands invariant suites).pnpm lintnow exits 0 with 16 remaining warnings (down from 19) and 3 infos that are non-blocking.
Removed
Fixed
.gitignoreno longer silently swallows new adapter outputs under.testatlas/adapters/<name>/<dotdir>/. The bare patterns.claude/,.cursor/,.opencode/,.kilocode/,.aider/,.windsurf/,.continue/,.cline/,.codex/,.gemini/,.roo/,.kiro/(intended to ignore consumer-side installed adapter directories that may appear in adapter authors' working trees) also matched the nested adapter-source paths like.testatlas/adapters/claude-code/.claude/commands/. When a new source command was added and the adapter regen produced a corresponding output file in any of those nested paths,git addsilently dropped it (no error, no stderr — gitignore-match is invisible). The 72 sibling adapter files already in those paths kept being tracked under the grandfather rule (gitignore doesn't untrack previously-tracked files), sogit statusshowed nothing wrong; only CI's fresh-checkout adapter-parity tests caught the gap, withexpected 73 flat derived files; got 72and downstream cascades inadapter-parity-final,adapter-parity-stub,adapter-flat-discovery, REQUIREMENTS.md / CLAUDE.md drift checks, andgraph-relationshipintegrity tests (~29 subtest failures total across the Test ×9 matrix). The fix adds explicit negation patterns (!.testatlas/adapters/**/.claude/, etc.) for all 12 historically-gitignored adapter output dirs, restoringgit addvisibility for the full.testatlas/adapters/subtree without affecting the original intent of ignoring consumer-side installed dirs at repo roots.- Tests reading suite-author-local dogfood state now skip cleanly on fresh CI checkouts. Several test files unconditionally read files under
.planning/REQUIREMENTS.md,CLAUDE.md,_testatlas/brain/*,_testatlas/bootstrap/*,_testatlas/agents/registry.json, and_testatlas/tests/— all of which are intentionally gitignored (suite-author working-tree state). Locally these tests verify real content; on CI fresh checkout they failed withENOENTbecause the files don't exist. Added a sharedskipIfMissing(t, path)helper (test/_helpers/repo-local-state.js) and applied it to the entry points intest/dist/dist03-changelog.test.js(4 tests, REQUIREMENTS.md),test/governance/doc-drift.test.js(2 tests, CLAUDE.md),test/graph-relationship.test.js(1 test, brain/graph.json),test/requirements-val05-closure.test.js(3 tests, REQUIREMENTS.md),test/schemas/drift-record-additivity.test.js(3 tests, brain/drift.json),test/schemas/matrix-id-pattern.test.js(1 test, tests/), andtest/v2-structure.test.js(8 tests, brain + bootstrap + agents/registry). Each skip is annotated with the reason in the test-reporter output so anyone reading CI logs understands the test was skipped because the file is suite-author state, not because the test was disabled. In the source repo (suite author with files present) the tests still RUN and verify content; the skip path only fires on fresh checkouts. Eliminates 20+ CI failures across all 3 OS × 3 Node versions. - install.sh
_TESTATLAS_TARBALL_OVERRIDEno longer hard-fails on the published-tarball SHA mismatch. The test hook copies a local tarball in place of the network fetch. Pre-fix,_verify_checksumthen ran against the hardcodedTARBALL_SHA256(synced at release time to the published npm tarball's SHA), and a locally-packed tarball can never match becausetarmetadata + compression bits differ.cp: -r not specified — omitting directorywas the user-facing symptom when the CI glob also failed; with the glob fix, the next layer surfaced asWARNING: 1 computed checksum did NOT match. Fix: when the override env var is set,install.shnow internally setsTESTATLAS_SKIP_CHECKSUM=1before calling_verify_checksum, so the existing skip-with-log path fires ("TESTATLAS_SKIP_CHECKSUM=1 set; skipping checksum verification.") rather than rejecting the local file. The placeholder-mode contract (TARBALL_SHA256="REPLACE_AT_RELEASE") is unchanged. Signature verification (TESTATLAS_VERIFY_SIGNATURE) still runs when the user explicitly pins that env var alongside the override — they're then explicitly opting into a sigstore check that fails by design against a non-published tarball, which is the right behavior (loud failure = explicit consent). - macOS test jobs no longer fail at the prerequisite-install step with
shellcheck: command not found. GitHub-hosted macOS runner images previously preinstalledshellcheckvia Homebrew; sometime mid-2026 that preinstall was dropped. The CI workflow's prerequisite step (Install dogfood-test prerequisites) assumed it was present and just ranshellcheck --versionto validate. Now the step runsbrew install shellcheckfirst (no-op if already present) before invoking--version, restoring all 3 macOS Test matrix jobs (Node 20, 22, 24). - Banner detection tests accept both Unicode (
█) and ASCII (#) art. On Windows runners withoutWT_SESSION/TERM_PROGRAMenv vars,isUnicode()(scripts/lib/colors.js) returnsfalseand the banner renders ASCII; the originalBANNER_LINES(Unicode-only) lookup intest/cli/install-js-banner.test.js,test/cli/update-js-banner.test.js,test/cli/uninstall-js-banner.test.js, andtest/cli/install-sh-banner.test.jsmatched 0 hits and failed withexpected ≥4 banner art lines; got 0even though the ASCII banner was rendered correctly in stdout. Tests now count hits against bothBANNER_LINESandBANNER_ASCII_LINESand accept ≥4 in EITHER set, so the "did we render a banner?" assertion ...
v2.0.2
Changelog
All notable changes to this project will be documented in this file. Format is based on Keep a Changelog, and this project adheres to Semantic Versioning. Releases are managed via @changesets/cli.
[Unreleased]
Added
Changed
Removed
[2.0.2] - 2026-05-10
Added
Changed
Removed
Fixed
- Hotfix —
updateno longer wipes<target>/.testatlas/scripts/.extractTarball()(scripts/lib/tarball.js) extracted onlypackage/.testatlas/from the npm tarball, dropping the siblingpackage/scripts/tree on the floor. The atomic-swap step inrunUpdate()then renamed the staged tree (with noscripts/) into place, deleting the script subtree the priorinithad populated viacopyValidatorScripts(). Net effect on every released v2.0.x consumer: the firstnpx @webventures/testatlas update [--force-reinstall]removed every accelerator script (create-domain.js,sync-system-map.js,create-issue.js,create-flow.js,create-evidence-record.js,update-indexes.js,validate-workspace.js, etc.) plus theirlib/closure, forcing every/atlas:*command into its slow manual-fallback path and breaking the/atlas:map-domainspreferred path the user reported. v2.0.2 makesextractTarballperform two staged extractions:package/.testatlas/(--strip-components=2, unchanged) andpackage/scripts/(--strip-components=1, excludingscripts/e2e/to mirrorcopyValidatorScripts's init-time exclusion). The staged tree now mirrors a fully-installed.testatlas/so the post-swap<target>/.testatlas/includes itsscripts/subtree. Three new regression tests intest/scripts/extract-tarball-strips-package-wrapper.test.jspin the new contract:package/scripts/x.js → dstDir/scripts/x.js,package/scripts/lib/y.js → dstDir/scripts/lib/y.js, andpackage/scripts/e2e/z.jsexcluded; the existing top-level-shape assertion was updated to['adapters','bootstrap.md','migrations','scripts']. End-to-end verified by packing the suite locally and asserting all six user-facing accelerator scripts arrive in the staged tree. No init-path change required —copyValidatorScripts()(scripts/lib/install-core.js:472-494) already handled this for fresh installs; v2.0.2 brings the update path to parity.
[2.0.1] - 2026-05-10
Fixed
- Hotfix —
update --force-reinstallno longer denied by defaultsafeMode:true. v2.0.0 added arequireCapability(config, 'destructive-fs')gate atrunUpdate()entry (Phase 18-01 / ISSUE-011 defense-in-depth) but left no bypass for top-level CLI invocations, sonpx @webventures/testatlas update --force-reinstallagainst a fresh install hitCapability denied (destructive-fs): safeMode is enabledeven though the user explicitly invoked the canonical update command. v2.0.1 addsopts.bypassSafetyGatetorunUpdate()andrunUninstall();bin/testatlas.jspassesbypassSafetyGate: truefor both subcommands (CLI = explicit user consent). Programmatic / sub-agent callers do NOT pass the flag and remain config-gated, preserving the original ISSUE-011 / ISSUE-014 defense-in-depth value. Two new regression tests intest/update/update-safety.test.jspin both paths: bypass honored undersafeMode:true; absence of bypass still denies undersafeMode:true.
Changed
Added
[2.0.0] - 2026-05-10
TestAtlas v2.0.0 is a major release introducing the Multi-Agent Quality Intelligence Brain — a persistent, machine-readable quality layer that turns any capable AI agent into a product-understanding, exploration, and evidence-collection system. V2 adds 41 new commands, 18 new schemas, 14 system personas, 11 council commands, and full support across all 18 host adapters. Phase 22 + Phase 23 follow-on work (closing 8 COUNCIL-2026-05-09-003 brain-audit findings) plus the COUNCIL-2026-05-10-001 release-readiness fixpack are folded into the v2.0.0 release per Option A of the council's release-cut decision.
Phase 23 — Close 8 COUNCIL-2026-05-09-003 brain-audit findings (DEC-001..DEC-008 + OPEN-001)
Phase 23 closes the structural-not-functional residue from Phase 22 surfaced by COUNCIL-2026-05-09-003. All 8 motions carried; 5 net-new high-leverage gaps the Phase-22 verifier missed. Backward-compat absolute — every fix is additive.
Fixed (Phase 23)
- DEC-001 / ISSUE-042 + ISSUE-045 — Audit-honesty: 22-04-SUMMARY.md + Phase-22 Verification narrative now cite live test counts (1842 / 1836 pass / 6 distinct fail / 2 skip) with all 6 distinct failure names enumerated.
- DEC-002 / ISSUE-038 —
_testatlas/brain/drift.jsonrepopulated with 11 schema-conforming records (DRIFT-001..DRIFT-011) reflecting COUNCIL-2026-05-09-002 audit findings;drift-record-additivity.test.jsTest 4 (length===11) GREEN. - DEC-003 / ISSUE-039 —
scripts/update-indexes.js#listCouncilSessionsreads each session.json and emits per-session bullets withtopic + mode= + participants=N + status=; 09_artifact_index.md council-sessions block now enumerates real metadata. Missing session.json falls back to path-only (back-compat). - DEC-004 / ISSUE-040 —
.testatlas/commands/explore.mdtrimmed to ≤1800 words AND ≤6 What's Next entries; long-form per-child brief contract extracted to NEW.testatlas/reference/explore-orchestration.md. - DEC-005 / ISSUE-043 —
_testatlas/00_overview.md"Core Domains" section replaced with TESTATLAS:GENERATEDdomain-countblock driven bystate.json#counts.domains; doc never drifts from brain truth. - DEC-006 / ISSUE-041 —
--reconcile-counts --populate-from-app-map --detect-driftflags wired into the existingupdate-brain-after-command.jsinvocations in.testatlas/commands/explore-codebase.mdand.testatlas/commands/core/brain-sync.md; Phase-22 producer scripts now fire at runtime;lifecycle-flag-wiring.test.jspins the wiring. - DEC-007 / ISSUE-044 —
scripts/consolidate-council.jsdocstring lines 215-221 trimmed to drop the orphan'strong-suspect'mention; comment now matches code at line 227. - DEC-008 —
CHANGELOG.md [0.1.0]gains### Schema migrationsection;package.json#versionbumped 1.2.6 → 2.0.0. DIST-03 + package-version-vs-CHANGELOG tests GREEN.
Added (Phase 23)
- OPEN-001 ADR captured —
.testatlas/reference/council-protocol.mdgains "Deferred design — vote-status producer (OPEN-001)" section documenting the futureupdate-claim-status-from-votes.jsproducer that would let DEC-004's OR-gate tighten to AND without re-introducing the 5-phase silent zero-promotion regression. Implementation deferred; design + scaffolding captured here. - NEW
.testatlas/reference/explore-orchestration.md— long-form per-child brief contract reference extracted fromexplore.mdper CMD-03 budget compliance.
Verification (Phase 23)
pnpm test: 1877 total / 1875 pass / 0 fail / 2 intentional skip (the previously-failing 6 distinct ✖ all flipped GREEN; Wave-2 cascade RED bars closed by Wave-3 adapter + example regen).check-adapter-parity --strict: 1314/1314 obligations (100.0%) — restored from Wave-2 source-body divergence (910/1314 RED → 1314/1314 GREEN).lint-commands0 violations;check-command-budgets/validate-workspace/validate-brainall exit 0.- 18 adapter trees + 7 example workspaces regenerated; 5 Wave-0 RED-bar tests authored (
update-indexes-council-sessions-rich,00-overview-domain-count,lifecycle-flag-wiring,consolidate-council-comment-code-parity,council-protocol-deferred-design) — all GREEN post-Wave-1/2 implementation. - Concurrent-agent boundary preserved through Phase-23 closure:
scripts/lib/install-core.js+scripts/lib/update-core.jsbyte-identical pre-/post (commits70e73331..838bae58).
Fixed (Phase 23 / Plan 23-03 — DEC-001 audit-honesty correction to Phase-22 verification)
- Phase-22 Verification narrative corrected. Original CHANGELOG +
22-04-SUMMARY.mdcited "1837/3/2 of 1842"; live counts at Phase-22 closure were 1842 / 1836 pass / 6 distinct ✖ / 2 skip. Phase 23 closes all 6. Full post-mortem: see.testatlas/reference/audit-honesty-history.md.
Added (Phase 23 / Plan 23-01 — Wave 0 TDD red-bar)
- 5 RED-bar regression tests pinning Phase-23 contracts (DEC-003, DEC-005, DEC-006, DEC-007, OPEN-001) BEFORE production-code edits, per Nyquist contract:
test/update-indexes-council-sessions-rich.test.js— DEC-003 pinslistCouncilSessionsenrichment.test/00-overview-domain-count.test.js— DEC-005 pinsdomain-countGENERATED block live-sync.test/commands/lifecycle-flag-wiring.test.js— DEC-006 pins--reconcile-counts --populate-from-app-map --detect-driftinvocation.test/scripts/consolidate-council-comment-code-parity.test.js— DEC-007 pins zerostrong-suspectin docstring.test/reference/council-protocol-deferred-design.test.js— OPEN-001 pins the deferred-design ADR.
- Test suite delta: 1842 → 1877 (+35); 1834 → 1849 pass (+15 baselines GREEN); 6 → 26 fail (+20 RED contract pins). All baseline RED tests preserved unchanged.
Fixed (Release-readiness post-Phase-23, COUNCIL-2026-05-10-001)
- DEC-002..DEC-005 fixpack — Pre-tag closure of 9 residual workspace-hygiene findings surfaced by the Release Readiness council (2026-05-10): cleared
validate-workspaceschema-discipline (dropped unregistered$schemaURL from_testatlas/brain/drift.json; auto-healed manifest counts; refreshed cross-cut index hashes for 7to_fix/by_*indexes —validate-workspace0 errors / 0 warnings); transitioned 8 brain rows ISSUE-038..045 fromstatus:new→status:closedwith append-only history entries (closing the lifecycle gap where Phase-23 closed code but did not flip status); trimmedCHANGELOG.mdfrom 3080 → 3000 words by extracting the Phase-22 audit-honesty post-mortem to.testatlas/reference/audit-honesty-history.md(with 1-li...
v2.0.1
Changelog
All notable changes to this project will be documented in this file. Format is based on Keep a Changelog, and this project adheres to Semantic Versioning. Releases are managed via @changesets/cli.
[Unreleased]
Added
Changed
Removed
[2.0.1] - 2026-05-10
Fixed
- Hotfix —
update --force-reinstallno longer denied by defaultsafeMode:true. v2.0.0 added arequireCapability(config, 'destructive-fs')gate atrunUpdate()entry (Phase 18-01 / ISSUE-011 defense-in-depth) but left no bypass for top-level CLI invocations, sonpx @webventures/testatlas update --force-reinstallagainst a fresh install hitCapability denied (destructive-fs): safeMode is enabledeven though the user explicitly invoked the canonical update command. v2.0.1 addsopts.bypassSafetyGatetorunUpdate()andrunUninstall();bin/testatlas.jspassesbypassSafetyGate: truefor both subcommands (CLI = explicit user consent). Programmatic / sub-agent callers do NOT pass the flag and remain config-gated, preserving the original ISSUE-011 / ISSUE-014 defense-in-depth value. Two new regression tests intest/update/update-safety.test.jspin both paths: bypass honored undersafeMode:true; absence of bypass still denies undersafeMode:true.
Changed
Added
[2.0.0] - 2026-05-10
TestAtlas v2.0.0 is a major release introducing the Multi-Agent Quality Intelligence Brain — a persistent, machine-readable quality layer that turns any capable AI agent into a product-understanding, exploration, and evidence-collection system. V2 adds 41 new commands, 18 new schemas, 14 system personas, 11 council commands, and full support across all 18 host adapters. Phase 22 + Phase 23 follow-on work (closing 8 COUNCIL-2026-05-09-003 brain-audit findings) plus the COUNCIL-2026-05-10-001 release-readiness fixpack are folded into the v2.0.0 release per Option A of the council's release-cut decision.
Phase 23 — Close 8 COUNCIL-2026-05-09-003 brain-audit findings (DEC-001..DEC-008 + OPEN-001)
Phase 23 closes the structural-not-functional residue from Phase 22 surfaced by COUNCIL-2026-05-09-003. All 8 motions carried; 5 net-new high-leverage gaps the Phase-22 verifier missed. Backward-compat absolute — every fix is additive.
Fixed (Phase 23)
- DEC-001 / ISSUE-042 + ISSUE-045 — Audit-honesty: 22-04-SUMMARY.md + Phase-22 Verification narrative now cite live test counts (1842 / 1836 pass / 6 distinct fail / 2 skip) with all 6 distinct failure names enumerated.
- DEC-002 / ISSUE-038 —
_testatlas/brain/drift.jsonrepopulated with 11 schema-conforming records (DRIFT-001..DRIFT-011) reflecting COUNCIL-2026-05-09-002 audit findings;drift-record-additivity.test.jsTest 4 (length===11) GREEN. - DEC-003 / ISSUE-039 —
scripts/update-indexes.js#listCouncilSessionsreads each session.json and emits per-session bullets withtopic + mode= + participants=N + status=; 09_artifact_index.md council-sessions block now enumerates real metadata. Missing session.json falls back to path-only (back-compat). - DEC-004 / ISSUE-040 —
.testatlas/commands/explore.mdtrimmed to ≤1800 words AND ≤6 What's Next entries; long-form per-child brief contract extracted to NEW.testatlas/reference/explore-orchestration.md. - DEC-005 / ISSUE-043 —
_testatlas/00_overview.md"Core Domains" section replaced with TESTATLAS:GENERATEDdomain-countblock driven bystate.json#counts.domains; doc never drifts from brain truth. - DEC-006 / ISSUE-041 —
--reconcile-counts --populate-from-app-map --detect-driftflags wired into the existingupdate-brain-after-command.jsinvocations in.testatlas/commands/explore-codebase.mdand.testatlas/commands/core/brain-sync.md; Phase-22 producer scripts now fire at runtime;lifecycle-flag-wiring.test.jspins the wiring. - DEC-007 / ISSUE-044 —
scripts/consolidate-council.jsdocstring lines 215-221 trimmed to drop the orphan'strong-suspect'mention; comment now matches code at line 227. - DEC-008 —
CHANGELOG.md [0.1.0]gains### Schema migrationsection;package.json#versionbumped 1.2.6 → 2.0.0. DIST-03 + package-version-vs-CHANGELOG tests GREEN.
Added (Phase 23)
- OPEN-001 ADR captured —
.testatlas/reference/council-protocol.mdgains "Deferred design — vote-status producer (OPEN-001)" section documenting the futureupdate-claim-status-from-votes.jsproducer that would let DEC-004's OR-gate tighten to AND without re-introducing the 5-phase silent zero-promotion regression. Implementation deferred; design + scaffolding captured here. - NEW
.testatlas/reference/explore-orchestration.md— long-form per-child brief contract reference extracted fromexplore.mdper CMD-03 budget compliance.
Verification (Phase 23)
pnpm test: 1877 total / 1875 pass / 0 fail / 2 intentional skip (the previously-failing 6 distinct ✖ all flipped GREEN; Wave-2 cascade RED bars closed by Wave-3 adapter + example regen).check-adapter-parity --strict: 1314/1314 obligations (100.0%) — restored from Wave-2 source-body divergence (910/1314 RED → 1314/1314 GREEN).lint-commands0 violations;check-command-budgets/validate-workspace/validate-brainall exit 0.- 18 adapter trees + 7 example workspaces regenerated; 5 Wave-0 RED-bar tests authored (
update-indexes-council-sessions-rich,00-overview-domain-count,lifecycle-flag-wiring,consolidate-council-comment-code-parity,council-protocol-deferred-design) — all GREEN post-Wave-1/2 implementation. - Concurrent-agent boundary preserved through Phase-23 closure:
scripts/lib/install-core.js+scripts/lib/update-core.jsbyte-identical pre-/post (commits70e73331..838bae58).
Fixed (Phase 23 / Plan 23-03 — DEC-001 audit-honesty correction to Phase-22 verification)
- Phase-22 Verification narrative corrected. Original CHANGELOG +
22-04-SUMMARY.mdcited "1837/3/2 of 1842"; live counts at Phase-22 closure were 1842 / 1836 pass / 6 distinct ✖ / 2 skip. Phase 23 closes all 6. Full post-mortem: see.testatlas/reference/audit-honesty-history.md.
Added (Phase 23 / Plan 23-01 — Wave 0 TDD red-bar)
- 5 RED-bar regression tests pinning Phase-23 contracts (DEC-003, DEC-005, DEC-006, DEC-007, OPEN-001) BEFORE production-code edits, per Nyquist contract:
test/update-indexes-council-sessions-rich.test.js— DEC-003 pinslistCouncilSessionsenrichment.test/00-overview-domain-count.test.js— DEC-005 pinsdomain-countGENERATED block live-sync.test/commands/lifecycle-flag-wiring.test.js— DEC-006 pins--reconcile-counts --populate-from-app-map --detect-driftinvocation.test/scripts/consolidate-council-comment-code-parity.test.js— DEC-007 pins zerostrong-suspectin docstring.test/reference/council-protocol-deferred-design.test.js— OPEN-001 pins the deferred-design ADR.
- Test suite delta: 1842 → 1877 (+35); 1834 → 1849 pass (+15 baselines GREEN); 6 → 26 fail (+20 RED contract pins). All baseline RED tests preserved unchanged.
Fixed (Release-readiness post-Phase-23, COUNCIL-2026-05-10-001)
- DEC-002..DEC-005 fixpack — Pre-tag closure of 9 residual workspace-hygiene findings surfaced by the Release Readiness council (2026-05-10): cleared
validate-workspaceschema-discipline (dropped unregistered$schemaURL from_testatlas/brain/drift.json; auto-healed manifest counts; refreshed cross-cut index hashes for 7to_fix/by_*indexes —validate-workspace0 errors / 0 warnings); transitioned 8 brain rows ISSUE-038..045 fromstatus:new→status:closedwith append-only history entries (closing the lifecycle gap where Phase-23 closed code but did not flip status); trimmedCHANGELOG.mdfrom 3080 → 3000 words by extracting the Phase-22 audit-honesty post-mortem to.testatlas/reference/audit-honesty-history.md(with 1-line cross-reference); folded the[Unreleased]Phase-22+23 entries into this[2.0.0]block per release-cut Option A. Surfaced 4 issue candidates (validate-workspace.js + check-token-budget.js exit-code masking — turned out NOT to be regressions; the masking was a piped-tailmeasurement artifact in the council prompt; AJV singleton drift schema registration; brain-status lifecycle gap → OPEN-007 obd-verifier checklist extension). Final state:pnpm test1877/1875/0/2;validate-workspace0/0;validate-brainOK;check-adapter-parity --strict1314/1314;check-token-budget CHANGELOG.md 3000PASS. Full audit at_testatlas/agents/councils/sessions/COUNCIL-2026-05-10-001/.
Added
-
V2 Multi-Agent Quality Intelligence Brain. A persistent
_testatlas/brain/tree with 16 JSON files (manifest.json,state.json,coverage.json,domains.json,flows.json,issues.json,evidence.json,decisions.json,risks.json,assumptions.json,graph.json,quality_scores.json,drift.json,agent_sessions.json,personas.json,events.jsonl) that captures everything an agent learns about the product under test. Every brain file is AJV-validated before write.scripts/validate-brain.js— full brain validation against V2 schemasscripts/score-quality.js— 11 deterministic quality metrics (0-100, no LLM judgment)scripts/detect-drift.js— git-diff-based drift detection with 7 input categoriesscripts/update-graph.js— 16-relationship knowledge graph populatorscripts/update-brain-after-command.js— automated post-operation brain update hookscripts/sync-markdown-json.js— idempotent markdown/JSON reconciliationscripts/index-artifacts.js— brain index rebuild from workspace scanscripts/generate-dashboard-data.js— machine-readable dashboard exportscripts/build-sqlite.js— optional SQLite projector (graceful degrade whenbetter-sqlite3absent)
-
V2 Command Surface — 41 new commands (73 total). Commands are now organ...
v2.0.0
Changelog
All notable changes to this project will be documented in this file. Format is based on Keep a Changelog, and this project adheres to Semantic Versioning. Releases are managed via @changesets/cli.
[Unreleased]
Added
Changed
Fixed
[2.0.0] - 2026-05-10
TestAtlas v2.0.0 is a major release introducing the Multi-Agent Quality Intelligence Brain — a persistent, machine-readable quality layer that turns any capable AI agent into a product-understanding, exploration, and evidence-collection system. V2 adds 41 new commands, 18 new schemas, 14 system personas, 11 council commands, and full support across all 18 host adapters. Phase 22 + Phase 23 follow-on work (closing 8 COUNCIL-2026-05-09-003 brain-audit findings) plus the COUNCIL-2026-05-10-001 release-readiness fixpack are folded into the v2.0.0 release per Option A of the council's release-cut decision.
Phase 23 — Close 8 COUNCIL-2026-05-09-003 brain-audit findings (DEC-001..DEC-008 + OPEN-001)
Phase 23 closes the structural-not-functional residue from Phase 22 surfaced by COUNCIL-2026-05-09-003. All 8 motions carried; 5 net-new high-leverage gaps the Phase-22 verifier missed. Backward-compat absolute — every fix is additive.
Fixed (Phase 23)
- DEC-001 / ISSUE-042 + ISSUE-045 — Audit-honesty: 22-04-SUMMARY.md + Phase-22 Verification narrative now cite live test counts (1842 / 1836 pass / 6 distinct fail / 2 skip) with all 6 distinct failure names enumerated.
- DEC-002 / ISSUE-038 —
_testatlas/brain/drift.jsonrepopulated with 11 schema-conforming records (DRIFT-001..DRIFT-011) reflecting COUNCIL-2026-05-09-002 audit findings;drift-record-additivity.test.jsTest 4 (length===11) GREEN. - DEC-003 / ISSUE-039 —
scripts/update-indexes.js#listCouncilSessionsreads each session.json and emits per-session bullets withtopic + mode= + participants=N + status=; 09_artifact_index.md council-sessions block now enumerates real metadata. Missing session.json falls back to path-only (back-compat). - DEC-004 / ISSUE-040 —
.testatlas/commands/explore.mdtrimmed to ≤1800 words AND ≤6 What's Next entries; long-form per-child brief contract extracted to NEW.testatlas/reference/explore-orchestration.md. - DEC-005 / ISSUE-043 —
_testatlas/00_overview.md"Core Domains" section replaced with TESTATLAS:GENERATEDdomain-countblock driven bystate.json#counts.domains; doc never drifts from brain truth. - DEC-006 / ISSUE-041 —
--reconcile-counts --populate-from-app-map --detect-driftflags wired into the existingupdate-brain-after-command.jsinvocations in.testatlas/commands/explore-codebase.mdand.testatlas/commands/core/brain-sync.md; Phase-22 producer scripts now fire at runtime;lifecycle-flag-wiring.test.jspins the wiring. - DEC-007 / ISSUE-044 —
scripts/consolidate-council.jsdocstring lines 215-221 trimmed to drop the orphan'strong-suspect'mention; comment now matches code at line 227. - DEC-008 —
CHANGELOG.md [0.1.0]gains### Schema migrationsection;package.json#versionbumped 1.2.6 → 2.0.0. DIST-03 + package-version-vs-CHANGELOG tests GREEN.
Added (Phase 23)
- OPEN-001 ADR captured —
.testatlas/reference/council-protocol.mdgains "Deferred design — vote-status producer (OPEN-001)" section documenting the futureupdate-claim-status-from-votes.jsproducer that would let DEC-004's OR-gate tighten to AND without re-introducing the 5-phase silent zero-promotion regression. Implementation deferred; design + scaffolding captured here. - NEW
.testatlas/reference/explore-orchestration.md— long-form per-child brief contract reference extracted fromexplore.mdper CMD-03 budget compliance.
Verification (Phase 23)
pnpm test: 1877 total / 1875 pass / 0 fail / 2 intentional skip (the previously-failing 6 distinct ✖ all flipped GREEN; Wave-2 cascade RED bars closed by Wave-3 adapter + example regen).check-adapter-parity --strict: 1314/1314 obligations (100.0%) — restored from Wave-2 source-body divergence (910/1314 RED → 1314/1314 GREEN).lint-commands0 violations;check-command-budgets/validate-workspace/validate-brainall exit 0.- 18 adapter trees + 7 example workspaces regenerated; 5 Wave-0 RED-bar tests authored (
update-indexes-council-sessions-rich,00-overview-domain-count,lifecycle-flag-wiring,consolidate-council-comment-code-parity,council-protocol-deferred-design) — all GREEN post-Wave-1/2 implementation. - Concurrent-agent boundary preserved through Phase-23 closure:
scripts/lib/install-core.js+scripts/lib/update-core.jsbyte-identical pre-/post (commits70e73331..838bae58).
Fixed (Phase 23 / Plan 23-03 — DEC-001 audit-honesty correction to Phase-22 verification)
- Phase-22 Verification narrative corrected. Original CHANGELOG +
22-04-SUMMARY.mdcited "1837/3/2 of 1842"; live counts at Phase-22 closure were 1842 / 1836 pass / 6 distinct ✖ / 2 skip. Phase 23 closes all 6. Full post-mortem: see.testatlas/reference/audit-honesty-history.md.
Added (Phase 23 / Plan 23-01 — Wave 0 TDD red-bar)
- 5 RED-bar regression tests pinning Phase-23 contracts (DEC-003, DEC-005, DEC-006, DEC-007, OPEN-001) BEFORE production-code edits, per Nyquist contract:
test/update-indexes-council-sessions-rich.test.js— DEC-003 pinslistCouncilSessionsenrichment.test/00-overview-domain-count.test.js— DEC-005 pinsdomain-countGENERATED block live-sync.test/commands/lifecycle-flag-wiring.test.js— DEC-006 pins--reconcile-counts --populate-from-app-map --detect-driftinvocation.test/scripts/consolidate-council-comment-code-parity.test.js— DEC-007 pins zerostrong-suspectin docstring.test/reference/council-protocol-deferred-design.test.js— OPEN-001 pins the deferred-design ADR.
- Test suite delta: 1842 → 1877 (+35); 1834 → 1849 pass (+15 baselines GREEN); 6 → 26 fail (+20 RED contract pins). All baseline RED tests preserved unchanged.
Fixed (Release-readiness post-Phase-23, COUNCIL-2026-05-10-001)
- DEC-002..DEC-005 fixpack — Pre-tag closure of 9 residual workspace-hygiene findings surfaced by the Release Readiness council (2026-05-10): cleared
validate-workspaceschema-discipline (dropped unregistered$schemaURL from_testatlas/brain/drift.json; auto-healed manifest counts; refreshed cross-cut index hashes for 7to_fix/by_*indexes —validate-workspace0 errors / 0 warnings); transitioned 8 brain rows ISSUE-038..045 fromstatus:new→status:closedwith append-only history entries (closing the lifecycle gap where Phase-23 closed code but did not flip status); trimmedCHANGELOG.mdfrom 3080 → 3000 words by extracting the Phase-22 audit-honesty post-mortem to.testatlas/reference/audit-honesty-history.md(with 1-line cross-reference); folded the[Unreleased]Phase-22+23 entries into this[2.0.0]block per release-cut Option A. Surfaced 4 issue candidates (validate-workspace.js + check-token-budget.js exit-code masking — turned out NOT to be regressions; the masking was a piped-tailmeasurement artifact in the council prompt; AJV singleton drift schema registration; brain-status lifecycle gap → OPEN-007 obd-verifier checklist extension). Final state:pnpm test1877/1875/0/2;validate-workspace0/0;validate-brainOK;check-adapter-parity --strict1314/1314;check-token-budget CHANGELOG.md 3000PASS. Full audit at_testatlas/agents/councils/sessions/COUNCIL-2026-05-10-001/.
Added
-
V2 Multi-Agent Quality Intelligence Brain. A persistent
_testatlas/brain/tree with 16 JSON files (manifest.json,state.json,coverage.json,domains.json,flows.json,issues.json,evidence.json,decisions.json,risks.json,assumptions.json,graph.json,quality_scores.json,drift.json,agent_sessions.json,personas.json,events.jsonl) that captures everything an agent learns about the product under test. Every brain file is AJV-validated before write.scripts/validate-brain.js— full brain validation against V2 schemasscripts/score-quality.js— 11 deterministic quality metrics (0-100, no LLM judgment)scripts/detect-drift.js— git-diff-based drift detection with 7 input categoriesscripts/update-graph.js— 16-relationship knowledge graph populatorscripts/update-brain-after-command.js— automated post-operation brain update hookscripts/sync-markdown-json.js— idempotent markdown/JSON reconciliationscripts/index-artifacts.js— brain index rebuild from workspace scanscripts/generate-dashboard-data.js— machine-readable dashboard exportscripts/build-sqlite.js— optional SQLite projector (graceful degrade whenbetter-sqlite3absent)
-
V2 Command Surface — 41 new commands (73 total). Commands are now organized into 7 categories:
core/—init,status,bootstrap-refresh,brain-sync,brain-validate,brain-query,brain-compact,brain-export(8 commands)explore/—explore-state,explore-errors,explore-components,explore-routes,explore-jobs,explore-security-privacy,explore-observability,explore-tests,explore-brain,explore-release-readiness,explore-all(11 commands)test/—generate-scenarios,generate-automation,generate-retest-pack,test-critical-flows(4 commands)council/—council,council-domain-review,council-flow-review,council-product-review,council-bug-triage,council-release-readiness,council-red-team,council-brain-audit,council-retest,council-design-critique,council-test-plan(11 commands)brain/—brain-score,brain-drift(2 commands)report/—report-domain,report-release,report-dashboard-data(3 commands)maintain/—maintain-migrate,maintain-validate-artifacts(2 commands)
-
*...
v1.2.6
Changelog
All notable changes to this project will be documented in this file. Format is based on Keep a Changelog, and this project adheres to Semantic Versioning. Releases are managed via @changesets/cli.
[Unreleased]
Added
Changed
Removed
[1.2.6] - 2026-05-06
No notable changes since 1.2.5.
[1.2.5] - 2026-05-06
No notable changes since 1.2.4.
[1.2.4] - 2026-05-06
No notable changes since 1.2.3.
[1.2.3] - 2026-05-06
No notable changes since 1.2.2.
[1.2.2] - 2026-05-06
No notable changes since 1.2.1.
[1.2.1] - 2026-05-06
No notable changes since 1.2.0.
[1.2.0] - 2026-05-06
Changed
- BREAKING —
validate-workspace --auto-healnow applies by default (Quick 260506-nj2). The CLI flag previously required pairing with--applyto actually persist heals; users who ran--auto-healalone saw "Would apply (N)" and (correctly) concluded nothing changed. The dual-flag UX caused real-world reports to be filed as "autoheal not working." With v1.2.0, bare--auto-healwrites to disk; pass--dry-runfor preview. The--applyflag is now a documented no-op (kept parseable for back-compat) and emits a one-time stderr note when paired with--auto-heal. Migration: if you have CI / scripts that ranvalidate-workspace --auto-healexpecting preview-only behavior, add--dry-runto keep the old semantics. The programmaticvalidateWorkspace({autoHeal, apply, dryRun})API is unchanged — only the CLI default flipped. scripts/lib/adapters/render-mcp.jsrequires explicitversionparameter (Quick 260506-nj2). The renderer previously hardcodedversion: '1.0.0'regardless of project version, so every release shipped an mcp manifest claiming v1.0.0 (the parity-check refresh masked it locally per release). The renderer nowthrow new TypeErrors ifversionis omitted;scripts/assemble-adapter.jsreads<workspace>/package.json#versionand injects it, so the published mcp manifest correctly tracks the suite version (v1.2.0 ships"version": "1.2.0").
Fixed
- High-severity —
runUpdatenow executes full adapter upgrade lifecycle for all 7 adapters (ISSUE-030; Quick 260506-mgr). Atomic-swap previously only renamed.testatlas/. Adapter outputs that live OUTSIDE the suite tree (.claude/commands/atlas-*.mdfor claude-code,.cursor/rules/*.mdcfor cursor,AGENTS.mdfor opencode/generic,.aider/CONVENTIONS.mdfor aider, mcp-server config, kilo equivalents) were never re-emitted on update — every consumer-side update from v1.0.0 onward left those files at install-time bodies forever.regenerateInstallManifestwalked only.testatlas/, dropping adapter files from the regenerated manifest and silently disabling drift detection + clean uninstall for them. v1.2.0 adds arestageAdaptershelper invoked between tarball cleanup and manifest regen: re-emits all adapter command files from the new tarball viacopyAdapterCommandFiles, prunes orphaned entries (files removed in vNext), honorsmanifest.mode === 'global', and includes the re-emitted entries in the regenerated manifest with correcttype. Per-adapter try/catch — one bad adapter does not abort the rest. Action required for users on v1.0.0–v1.1.5: runnpx @webventures/testatlas update --force-reinstallonce after updating to v1.2.0 to refresh the adapter command files in your repo. Subsequent updates will refresh them automatically. - Reporter preview subtitle now appears under the section header (Quick 260506-nj2). When
--auto-heal --dry-runis used (preview mode), the report previously only showed a per-row footer "Preview only" note. Users skimming the section header could miss the indicator. v1.2.0 adds a section-header subtitle directly under### Would apply (N)so the preview-only state is unmissable. Footer wording updated from "re-run with--apply" to "re-run without--dry-run" to match the new flag semantics. No change whenapplied.length === 0(nothing to preview).
Added
[1.1.5] - 2026-05-06
No notable changes since 1.1.4.
[1.1.4] - 2026-05-06
No notable changes since 1.1.3.
[1.1.3] - 2026-05-06
No notable changes since 1.1.2.
[1.1.2] - 2026-05-06
No notable changes since 1.1.1.
[1.1.1] - 2026-05-06
No notable changes since 1.1.0.
[1.1.0] - 2026-05-06
Added
- Cosign + dogfood-test infrastructure (Quick 260506-07b).
sigstore/cosign-installer@v3(SHA-pinned) wired into.github/workflows/ci.ymlso dogfood scenarios run against a real cosign install. Newscripts/setup-dogfood-env.shPOSIX pre-flight probes for cosign + shellcheck + gh + sha256sum + tar + git + curl + jq + node ≥ 20; copy-paste install hints per missing binary; optional--installflag attempts non-interactive install on Linux. CONTRIBUTING.mdDogfood Test Prerequisites section (Quick 260506-07b). Documents required binaries with version floors; tells contributors to runsh scripts/setup-dogfood-env.shbefore/atlas:test-flow --all; notes CI installs these automatically.- NEW scenario
TEST-install-cosign-absent-degrade(Quick 260506-07b). Verifies install.sh's fail-open default path: whenTESTATLAS_VERIFY_SIGNATUREis unset and cosign is not on PATH, installer proceeds with sha256-only verification (exit 0). Sibling toTEST-install-cosign-verification-smoke(tamper-fail focus). Scenario count 25→26. - Per-area report views (Quick 260506-dyb G5).
scripts/generate-report.jsnow emits_testatlas/reports/regressions.md,readiness.md,coverage.md,quality_risks.mdfrom the same aggregation pass. Previously these were declared in the spec but never written. counts.reportsfield inworkspace-manifest.schema.json(Quick 260506-dyb G4). Optional integer ≥0 added additively (no migration required); HEAL-01 + check-status-counts updated to validate it;sync-status.jswrites it from disk truth (_testatlas/reports/REPORT-*.mdcount).scripts/triage.jsaccelerator (Quick 260506-esm). Production-grade idempotent triage driver mirroringscripts/create-issue.jsshape. Loads all_testatlas/to_fix/ISSUE-*.json; verifies evidence-on-disk per issue (downgrades confidence toneeds-validationif missing); applies 3 duplicate heuristics (exact-title, shared-evidence path, same-domain+flow+repro Levenshtein ≥0.8); transitionsstatus:new→status:triagedwith append-only history; AJV-validates every mutated record before atomicWrite; regeneratestriage-report-<ts>.md+blockers.md+groups.md. CLI flags:--workspace,--cwd,--dry-run,--severity-override <ID>=<sev>(repeatable),--help. Idempotent: live runs against a stable corpus produce zero file mutations.- POSIX banner in
install.sh(Quick 260506-h9q). New_print_banner()emits the same 9-line ASCII art asscripts/lib/banner.js BANNER_UNICODE_LINES; honorsNO_COLOR(no ANSI when set),NO_UNICODE(#-art fallback), and non-TTY (no escape codes). Banner now renders on the curl-pipe path, matching the npx + git-clone + direct-script paths. renderBannerwired intoinstall.js,scripts/update.js,scripts/uninstall.js(Quick 260506-h9q). Previously onlybin/testatlas.js(npx path) rendered the banner. All entry-points now consistent.- Production-grade release driver (Quick 260506-hqu). Refactored
scripts/bump-version.js(770 LOC) is now a true one-liner: pre-flight gates (pnpm test+check-adapter-parity --strict+validate-workspace), CHANGELOG[Unreleased]→[X.Y.Z]body migration, atomic commit + annotated tag,git push origin <branch>+git push origin <tag>,gh release create vX.Y.Z --notes-file <CHANGELOG-extract>(NOT--generate-notes), optional--waitpollsrelease.ymluntil OIDC publish + asset attachment completes (10-min timeout). Fires the existingrelease.ymlworkflow which handles npm publish via OIDC, sha256 + sigstore fetch, install.shTARBALL_SHA256sync, and asset attachment automatically. docs/RELEASE.md"Local release driver" section (Quick 260506-hqu). Documents the canonicalnode scripts/bump-version.js --minor --release --waitflow + every flag with examples + OIDC vs bootstrap path tradeoff.
Changed
scripts/generate-report.jsreadiness verdict (Quick 260506-esm) now filterssortedIssuestostatus ∉ {closed, wont_fix}BEFORE the severity check. Previously counted closed issues toward CONDITIONAL verdict; now correctly reads READY when 0 critical+open AND 0 high+open. Closes ISSUE-029.scripts/generate-report.jsrun dedup (Quick 260506-dyb G1).readTestRunsgroups by RUN-<ts>stem; prefers.jsonsidecar; merges.mdfrontmatter as supplementary. Previously read each run twice (once via .md glob, once via .json glob), reporting2 run(s)for 1 actual run.scripts/generate-report.jsper-domain coverage detection (Quick 260506-dyb G2). Walksr.parsed.scenariosRun[].domaininstead of the (non-existent) top-levelr.parsed.domainfield. Previously claimed all domains uncovered; now correctly credits scenario coverage.scripts/generate-report.jsTest Pyramid type-classification (Quick 260506-dyb G3). Resolves scenariotypevia matching_testatlas/tests/scenarios/TEST-<id>.jsonsidecar. Previously emittedunknown: Nbucket only; now reflects actual smoke/regression/state/negative/setup/integration/user-flow distribution.scripts/generate-report.jsautoheal parity (Quick 260506-esm). HEAL-01 now recomputescounts.reportsalongside the other counts when re-deriving manifest from disk; previously only check-status-counts validated it but heal didn't fix mismatches..testatlas/commands/triage.mdPreferred-path entry (Quick 260506-esm). Source command now declaresnode .testatlas/scripts/triage.jsas the preferred-when-shell-available path, mirroring `create-...
v1.2.5
Changelog
All notable changes to this project will be documented in this file. Format is based on Keep a Changelog, and this project adheres to Semantic Versioning. Releases are managed via @changesets/cli.
[Unreleased]
Added
Changed
Removed
[1.2.5] - 2026-05-06
No notable changes since 1.2.4.
[1.2.4] - 2026-05-06
No notable changes since 1.2.3.
[1.2.3] - 2026-05-06
No notable changes since 1.2.2.
[1.2.2] - 2026-05-06
No notable changes since 1.2.1.
[1.2.1] - 2026-05-06
No notable changes since 1.2.0.
[1.2.0] - 2026-05-06
Changed
- BREAKING —
validate-workspace --auto-healnow applies by default (Quick 260506-nj2). The CLI flag previously required pairing with--applyto actually persist heals; users who ran--auto-healalone saw "Would apply (N)" and (correctly) concluded nothing changed. The dual-flag UX caused real-world reports to be filed as "autoheal not working." With v1.2.0, bare--auto-healwrites to disk; pass--dry-runfor preview. The--applyflag is now a documented no-op (kept parseable for back-compat) and emits a one-time stderr note when paired with--auto-heal. Migration: if you have CI / scripts that ranvalidate-workspace --auto-healexpecting preview-only behavior, add--dry-runto keep the old semantics. The programmaticvalidateWorkspace({autoHeal, apply, dryRun})API is unchanged — only the CLI default flipped. scripts/lib/adapters/render-mcp.jsrequires explicitversionparameter (Quick 260506-nj2). The renderer previously hardcodedversion: '1.0.0'regardless of project version, so every release shipped an mcp manifest claiming v1.0.0 (the parity-check refresh masked it locally per release). The renderer nowthrow new TypeErrors ifversionis omitted;scripts/assemble-adapter.jsreads<workspace>/package.json#versionand injects it, so the published mcp manifest correctly tracks the suite version (v1.2.0 ships"version": "1.2.0").
Fixed
- High-severity —
runUpdatenow executes full adapter upgrade lifecycle for all 7 adapters (ISSUE-030; Quick 260506-mgr). Atomic-swap previously only renamed.testatlas/. Adapter outputs that live OUTSIDE the suite tree (.claude/commands/atlas-*.mdfor claude-code,.cursor/rules/*.mdcfor cursor,AGENTS.mdfor opencode/generic,.aider/CONVENTIONS.mdfor aider, mcp-server config, kilo equivalents) were never re-emitted on update — every consumer-side update from v1.0.0 onward left those files at install-time bodies forever.regenerateInstallManifestwalked only.testatlas/, dropping adapter files from the regenerated manifest and silently disabling drift detection + clean uninstall for them. v1.2.0 adds arestageAdaptershelper invoked between tarball cleanup and manifest regen: re-emits all adapter command files from the new tarball viacopyAdapterCommandFiles, prunes orphaned entries (files removed in vNext), honorsmanifest.mode === 'global', and includes the re-emitted entries in the regenerated manifest with correcttype. Per-adapter try/catch — one bad adapter does not abort the rest. Action required for users on v1.0.0–v1.1.5: runnpx @webventures/testatlas update --force-reinstallonce after updating to v1.2.0 to refresh the adapter command files in your repo. Subsequent updates will refresh them automatically. - Reporter preview subtitle now appears under the section header (Quick 260506-nj2). When
--auto-heal --dry-runis used (preview mode), the report previously only showed a per-row footer "Preview only" note. Users skimming the section header could miss the indicator. v1.2.0 adds a section-header subtitle directly under### Would apply (N)so the preview-only state is unmissable. Footer wording updated from "re-run with--apply" to "re-run without--dry-run" to match the new flag semantics. No change whenapplied.length === 0(nothing to preview).
Added
[1.1.5] - 2026-05-06
No notable changes since 1.1.4.
[1.1.4] - 2026-05-06
No notable changes since 1.1.3.
[1.1.3] - 2026-05-06
No notable changes since 1.1.2.
[1.1.2] - 2026-05-06
No notable changes since 1.1.1.
[1.1.1] - 2026-05-06
No notable changes since 1.1.0.
[1.1.0] - 2026-05-06
Added
- Cosign + dogfood-test infrastructure (Quick 260506-07b).
sigstore/cosign-installer@v3(SHA-pinned) wired into.github/workflows/ci.ymlso dogfood scenarios run against a real cosign install. Newscripts/setup-dogfood-env.shPOSIX pre-flight probes for cosign + shellcheck + gh + sha256sum + tar + git + curl + jq + node ≥ 20; copy-paste install hints per missing binary; optional--installflag attempts non-interactive install on Linux. CONTRIBUTING.mdDogfood Test Prerequisites section (Quick 260506-07b). Documents required binaries with version floors; tells contributors to runsh scripts/setup-dogfood-env.shbefore/atlas:test-flow --all; notes CI installs these automatically.- NEW scenario
TEST-install-cosign-absent-degrade(Quick 260506-07b). Verifies install.sh's fail-open default path: whenTESTATLAS_VERIFY_SIGNATUREis unset and cosign is not on PATH, installer proceeds with sha256-only verification (exit 0). Sibling toTEST-install-cosign-verification-smoke(tamper-fail focus). Scenario count 25→26. - Per-area report views (Quick 260506-dyb G5).
scripts/generate-report.jsnow emits_testatlas/reports/regressions.md,readiness.md,coverage.md,quality_risks.mdfrom the same aggregation pass. Previously these were declared in the spec but never written. counts.reportsfield inworkspace-manifest.schema.json(Quick 260506-dyb G4). Optional integer ≥0 added additively (no migration required); HEAL-01 + check-status-counts updated to validate it;sync-status.jswrites it from disk truth (_testatlas/reports/REPORT-*.mdcount).scripts/triage.jsaccelerator (Quick 260506-esm). Production-grade idempotent triage driver mirroringscripts/create-issue.jsshape. Loads all_testatlas/to_fix/ISSUE-*.json; verifies evidence-on-disk per issue (downgrades confidence toneeds-validationif missing); applies 3 duplicate heuristics (exact-title, shared-evidence path, same-domain+flow+repro Levenshtein ≥0.8); transitionsstatus:new→status:triagedwith append-only history; AJV-validates every mutated record before atomicWrite; regeneratestriage-report-<ts>.md+blockers.md+groups.md. CLI flags:--workspace,--cwd,--dry-run,--severity-override <ID>=<sev>(repeatable),--help. Idempotent: live runs against a stable corpus produce zero file mutations.- POSIX banner in
install.sh(Quick 260506-h9q). New_print_banner()emits the same 9-line ASCII art asscripts/lib/banner.js BANNER_UNICODE_LINES; honorsNO_COLOR(no ANSI when set),NO_UNICODE(#-art fallback), and non-TTY (no escape codes). Banner now renders on the curl-pipe path, matching the npx + git-clone + direct-script paths. renderBannerwired intoinstall.js,scripts/update.js,scripts/uninstall.js(Quick 260506-h9q). Previously onlybin/testatlas.js(npx path) rendered the banner. All entry-points now consistent.- Production-grade release driver (Quick 260506-hqu). Refactored
scripts/bump-version.js(770 LOC) is now a true one-liner: pre-flight gates (pnpm test+check-adapter-parity --strict+validate-workspace), CHANGELOG[Unreleased]→[X.Y.Z]body migration, atomic commit + annotated tag,git push origin <branch>+git push origin <tag>,gh release create vX.Y.Z --notes-file <CHANGELOG-extract>(NOT--generate-notes), optional--waitpollsrelease.ymluntil OIDC publish + asset attachment completes (10-min timeout). Fires the existingrelease.ymlworkflow which handles npm publish via OIDC, sha256 + sigstore fetch, install.shTARBALL_SHA256sync, and asset attachment automatically. docs/RELEASE.md"Local release driver" section (Quick 260506-hqu). Documents the canonicalnode scripts/bump-version.js --minor --release --waitflow + every flag with examples + OIDC vs bootstrap path tradeoff.
Changed
scripts/generate-report.jsreadiness verdict (Quick 260506-esm) now filterssortedIssuestostatus ∉ {closed, wont_fix}BEFORE the severity check. Previously counted closed issues toward CONDITIONAL verdict; now correctly reads READY when 0 critical+open AND 0 high+open. Closes ISSUE-029.scripts/generate-report.jsrun dedup (Quick 260506-dyb G1).readTestRunsgroups by RUN-<ts>stem; prefers.jsonsidecar; merges.mdfrontmatter as supplementary. Previously read each run twice (once via .md glob, once via .json glob), reporting2 run(s)for 1 actual run.scripts/generate-report.jsper-domain coverage detection (Quick 260506-dyb G2). Walksr.parsed.scenariosRun[].domaininstead of the (non-existent) top-levelr.parsed.domainfield. Previously claimed all domains uncovered; now correctly credits scenario coverage.scripts/generate-report.jsTest Pyramid type-classification (Quick 260506-dyb G3). Resolves scenariotypevia matching_testatlas/tests/scenarios/TEST-<id>.jsonsidecar. Previously emittedunknown: Nbucket only; now reflects actual smoke/regression/state/negative/setup/integration/user-flow distribution.scripts/generate-report.jsautoheal parity (Quick 260506-esm). HEAL-01 now recomputescounts.reportsalongside the other counts when re-deriving manifest from disk; previously only check-status-counts validated it but heal didn't fix mismatches..testatlas/commands/triage.mdPreferred-path entry (Quick 260506-esm). Source command now declaresnode .testatlas/scripts/triage.jsas the preferred-when-shell-available path, mirroringcreate-issue.md/generate-report.mdpatterns. 18 adapter trees ...
v1.2.4
Changelog
All notable changes to this project will be documented in this file. Format is based on Keep a Changelog, and this project adheres to Semantic Versioning. Releases are managed via @changesets/cli.
[Unreleased]
Added
Changed
Removed
[1.2.4] - 2026-05-06
No notable changes since 1.2.3.
[1.2.3] - 2026-05-06
No notable changes since 1.2.2.
[1.2.2] - 2026-05-06
No notable changes since 1.2.1.
[1.2.1] - 2026-05-06
No notable changes since 1.2.0.
[1.2.0] - 2026-05-06
Changed
- BREAKING —
validate-workspace --auto-healnow applies by default (Quick 260506-nj2). The CLI flag previously required pairing with--applyto actually persist heals; users who ran--auto-healalone saw "Would apply (N)" and (correctly) concluded nothing changed. The dual-flag UX caused real-world reports to be filed as "autoheal not working." With v1.2.0, bare--auto-healwrites to disk; pass--dry-runfor preview. The--applyflag is now a documented no-op (kept parseable for back-compat) and emits a one-time stderr note when paired with--auto-heal. Migration: if you have CI / scripts that ranvalidate-workspace --auto-healexpecting preview-only behavior, add--dry-runto keep the old semantics. The programmaticvalidateWorkspace({autoHeal, apply, dryRun})API is unchanged — only the CLI default flipped. scripts/lib/adapters/render-mcp.jsrequires explicitversionparameter (Quick 260506-nj2). The renderer previously hardcodedversion: '1.0.0'regardless of project version, so every release shipped an mcp manifest claiming v1.0.0 (the parity-check refresh masked it locally per release). The renderer nowthrow new TypeErrors ifversionis omitted;scripts/assemble-adapter.jsreads<workspace>/package.json#versionand injects it, so the published mcp manifest correctly tracks the suite version (v1.2.0 ships"version": "1.2.0").
Fixed
- High-severity —
runUpdatenow executes full adapter upgrade lifecycle for all 7 adapters (ISSUE-030; Quick 260506-mgr). Atomic-swap previously only renamed.testatlas/. Adapter outputs that live OUTSIDE the suite tree (.claude/commands/atlas-*.mdfor claude-code,.cursor/rules/*.mdcfor cursor,AGENTS.mdfor opencode/generic,.aider/CONVENTIONS.mdfor aider, mcp-server config, kilo equivalents) were never re-emitted on update — every consumer-side update from v1.0.0 onward left those files at install-time bodies forever.regenerateInstallManifestwalked only.testatlas/, dropping adapter files from the regenerated manifest and silently disabling drift detection + clean uninstall for them. v1.2.0 adds arestageAdaptershelper invoked between tarball cleanup and manifest regen: re-emits all adapter command files from the new tarball viacopyAdapterCommandFiles, prunes orphaned entries (files removed in vNext), honorsmanifest.mode === 'global', and includes the re-emitted entries in the regenerated manifest with correcttype. Per-adapter try/catch — one bad adapter does not abort the rest. Action required for users on v1.0.0–v1.1.5: runnpx @webventures/testatlas update --force-reinstallonce after updating to v1.2.0 to refresh the adapter command files in your repo. Subsequent updates will refresh them automatically. - Reporter preview subtitle now appears under the section header (Quick 260506-nj2). When
--auto-heal --dry-runis used (preview mode), the report previously only showed a per-row footer "Preview only" note. Users skimming the section header could miss the indicator. v1.2.0 adds a section-header subtitle directly under### Would apply (N)so the preview-only state is unmissable. Footer wording updated from "re-run with--apply" to "re-run without--dry-run" to match the new flag semantics. No change whenapplied.length === 0(nothing to preview).
Added
[1.1.5] - 2026-05-06
No notable changes since 1.1.4.
[1.1.4] - 2026-05-06
No notable changes since 1.1.3.
[1.1.3] - 2026-05-06
No notable changes since 1.1.2.
[1.1.2] - 2026-05-06
No notable changes since 1.1.1.
[1.1.1] - 2026-05-06
No notable changes since 1.1.0.
[1.1.0] - 2026-05-06
Added
- Cosign + dogfood-test infrastructure (Quick 260506-07b).
sigstore/cosign-installer@v3(SHA-pinned) wired into.github/workflows/ci.ymlso dogfood scenarios run against a real cosign install. Newscripts/setup-dogfood-env.shPOSIX pre-flight probes for cosign + shellcheck + gh + sha256sum + tar + git + curl + jq + node ≥ 20; copy-paste install hints per missing binary; optional--installflag attempts non-interactive install on Linux. CONTRIBUTING.mdDogfood Test Prerequisites section (Quick 260506-07b). Documents required binaries with version floors; tells contributors to runsh scripts/setup-dogfood-env.shbefore/atlas:test-flow --all; notes CI installs these automatically.- NEW scenario
TEST-install-cosign-absent-degrade(Quick 260506-07b). Verifies install.sh's fail-open default path: whenTESTATLAS_VERIFY_SIGNATUREis unset and cosign is not on PATH, installer proceeds with sha256-only verification (exit 0). Sibling toTEST-install-cosign-verification-smoke(tamper-fail focus). Scenario count 25→26. - Per-area report views (Quick 260506-dyb G5).
scripts/generate-report.jsnow emits_testatlas/reports/regressions.md,readiness.md,coverage.md,quality_risks.mdfrom the same aggregation pass. Previously these were declared in the spec but never written. counts.reportsfield inworkspace-manifest.schema.json(Quick 260506-dyb G4). Optional integer ≥0 added additively (no migration required); HEAL-01 + check-status-counts updated to validate it;sync-status.jswrites it from disk truth (_testatlas/reports/REPORT-*.mdcount).scripts/triage.jsaccelerator (Quick 260506-esm). Production-grade idempotent triage driver mirroringscripts/create-issue.jsshape. Loads all_testatlas/to_fix/ISSUE-*.json; verifies evidence-on-disk per issue (downgrades confidence toneeds-validationif missing); applies 3 duplicate heuristics (exact-title, shared-evidence path, same-domain+flow+repro Levenshtein ≥0.8); transitionsstatus:new→status:triagedwith append-only history; AJV-validates every mutated record before atomicWrite; regeneratestriage-report-<ts>.md+blockers.md+groups.md. CLI flags:--workspace,--cwd,--dry-run,--severity-override <ID>=<sev>(repeatable),--help. Idempotent: live runs against a stable corpus produce zero file mutations.- POSIX banner in
install.sh(Quick 260506-h9q). New_print_banner()emits the same 9-line ASCII art asscripts/lib/banner.js BANNER_UNICODE_LINES; honorsNO_COLOR(no ANSI when set),NO_UNICODE(#-art fallback), and non-TTY (no escape codes). Banner now renders on the curl-pipe path, matching the npx + git-clone + direct-script paths. renderBannerwired intoinstall.js,scripts/update.js,scripts/uninstall.js(Quick 260506-h9q). Previously onlybin/testatlas.js(npx path) rendered the banner. All entry-points now consistent.- Production-grade release driver (Quick 260506-hqu). Refactored
scripts/bump-version.js(770 LOC) is now a true one-liner: pre-flight gates (pnpm test+check-adapter-parity --strict+validate-workspace), CHANGELOG[Unreleased]→[X.Y.Z]body migration, atomic commit + annotated tag,git push origin <branch>+git push origin <tag>,gh release create vX.Y.Z --notes-file <CHANGELOG-extract>(NOT--generate-notes), optional--waitpollsrelease.ymluntil OIDC publish + asset attachment completes (10-min timeout). Fires the existingrelease.ymlworkflow which handles npm publish via OIDC, sha256 + sigstore fetch, install.shTARBALL_SHA256sync, and asset attachment automatically. docs/RELEASE.md"Local release driver" section (Quick 260506-hqu). Documents the canonicalnode scripts/bump-version.js --minor --release --waitflow + every flag with examples + OIDC vs bootstrap path tradeoff.
Changed
scripts/generate-report.jsreadiness verdict (Quick 260506-esm) now filterssortedIssuestostatus ∉ {closed, wont_fix}BEFORE the severity check. Previously counted closed issues toward CONDITIONAL verdict; now correctly reads READY when 0 critical+open AND 0 high+open. Closes ISSUE-029.scripts/generate-report.jsrun dedup (Quick 260506-dyb G1).readTestRunsgroups by RUN-<ts>stem; prefers.jsonsidecar; merges.mdfrontmatter as supplementary. Previously read each run twice (once via .md glob, once via .json glob), reporting2 run(s)for 1 actual run.scripts/generate-report.jsper-domain coverage detection (Quick 260506-dyb G2). Walksr.parsed.scenariosRun[].domaininstead of the (non-existent) top-levelr.parsed.domainfield. Previously claimed all domains uncovered; now correctly credits scenario coverage.scripts/generate-report.jsTest Pyramid type-classification (Quick 260506-dyb G3). Resolves scenariotypevia matching_testatlas/tests/scenarios/TEST-<id>.jsonsidecar. Previously emittedunknown: Nbucket only; now reflects actual smoke/regression/state/negative/setup/integration/user-flow distribution.scripts/generate-report.jsautoheal parity (Quick 260506-esm). HEAL-01 now recomputescounts.reportsalongside the other counts when re-deriving manifest from disk; previously only check-status-counts validated it but heal didn't fix mismatches..testatlas/commands/triage.mdPreferred-path entry (Quick 260506-esm). Source command now declaresnode .testatlas/scripts/triage.jsas the preferred-when-shell-available path, mirroringcreate-issue.md/generate-report.mdpatterns. 18 adapter trees regenerated.install.shline budget raised 250→290 (...