Skip to content

Releases: CryptVenture/TestAtlas

v2.0.10

Choose a tag to compare

@CryptVenture CryptVenture released this 14 May 19:44

Changelog

All notable changes to this project will be documented in this file. Format is based on Keep a Changelog, and this project adheres to Semantic Versioning. Releases are managed via @changesets/cli.

[Unreleased]

Added

Changed

Removed

[2.0.10] - 2026-05-14

Added

  • .testatlas/schemas/report.schema.json V2 composite sections. 15 new optional top-level properties (kind, priorReport, generationMode, coverage, severityBreakdown, confidenceBreakdown, regressions, qualityRisks, testPyramidHealth, evidenceCatalogSummary, capabilityDegradation, scorecardSnapshot, trendVsPrior, runLogTail, readinessRationale) accept the structured-section shape that generate-report.js emits. runSummary widened to oneOf: string | object so V1 prose-summary reports and V2 structured-summary reports both validate. The V1 environmentsCovered / domainsCovered / flowsCovered / testsExecuted / evidenceCount properties moved from required[] to optional and now carry descriptions pointing at their V2 successors under coverage / runSummary / evidenceCatalogSummary.
  • .testatlas/schemas/test-run.schema.json execution-mode + sub-run shape. New optional executionMode (enum: sequential, sequential-fallback, parallel-subagents, all-flows, all-domains, inline) for the audit-honesty contract /atlas:test-flow, /atlas:test-all, and /atlas:test-domain require; new optional children as oneOf: array | object so the V1 /atlas:test-all sub-run-kind-keyed object and the V2 array shape both validate; new optional skipped / summary / notes run-level fields.
  • .testatlas/schemas/workspace-manifest.schema.json counts surface widened. counts.scenarios (count of tests/scenarios/TEST-*.json written by /atlas:test-generate-scenarios) and counts.charters (count of exploratory charters under tests/charters/) added as optional integers. Both are additive — older manifests continue to validate unchanged.

Changed

  • scripts/lib/validate/check-schemas.js skip-before-$schema ordering. Path-based SKIP rules now fire BEFORE the inferer honors a file's own $schema field. This unblocks V2 sub-artefacts whose authors stamped $schema pointers at schemas that don't exist yet in .testatlas/schemas/ (e.g. council persona outputs reference persona_output.schema.json); previously the inferer accepted the (non-existent) $schema pointer and surfaced TESTATLAS_UNKNOWN_SCHEMA for every persona output in every council session.
  • scripts/lib/validate/check-schemas.js four new SKIP rules. tests/generated_automation/<framework>/<flow-slug>.meta.json (status-tracker sidecars per /atlas:test-generate-automation skill spec), sessions/<persona>.json (Chrome DevTools storageState snapshots — heterogeneous per session), runs/RUN-*.json at workspace root (framework-specific per-tool run records distinct from tests/runs/), and agents/councils/sessions/<id>/outputs/*.json (persona-specific council outputs). Each rule's comment cites the producing command and the reason no canonical schema exists yet.
  • docs/SCHEMAS.md regenerated. Reflects the new optional properties on issue.schema.json (Phase 47/48 sealing metadata: closedOn, closedAt, closedBy, closedNote, closingPhase, closingPlan, closingCommit, closingNote, closingNotes, closingReq, closedByCommits, closedInPhase, consolidatedInto, statusHistory, by_phase, fix_commit), report.schema.json (the 15 V2 composite sections listed above), and test-run.schema.json (executionMode, children, skipped, summary, notes).
  • Example workspaces resynced. The mirrored brain/schema/ trees under examples/cli-tool/, examples/mobile-web-hybrid/, examples/monorepo/, examples/monorepo/apps/api/, examples/monorepo/apps/web/, examples/nextjs-saas/, examples/node-api/ were regenerated so every issue/report/test-run/workspace-manifest schema in every example is byte-identical to the canonical .testatlas/schemas/.

Removed

[2.0.9] - 2026-05-13

Added

  • better-sqlite3 added to devDependencies — required by recently-added dogfood tooling; absence broke local pnpm install for contributors using the explore/brain scripts.

Changed

  • Release workflow hardened with retry-with-backoff at two known-flaky points. (1) npm publish is now wrapped in a 3-attempt loop with 10s/30s backoff between attempts. The observed failure (v2.0.7 + v2.0.8, 2026-05-13) was POST 201 oidc/token/exchange → sigstore-provenance-signed → PUT 400 OIDC publish authorize: Invalid token: the OIDC trade succeeded but the actual publish PUT was rejected. npm CLI mints a fresh ID token on each attempt, so retrying clears the failure when it's transient on npm's side; when it's structural (trusted-publisher config drift), all 3 attempts fail and the step exits non-zero with the full verbose log preserved per attempt. (2) The post-publish curl of the registry tarball URL (used to compute the SHA-256 for install.sh + sigstore sidecar) is now wrapped in a 10-attempt loop with 6s backoff. The race was observed at v2.0.6: PUT 200 at T+0s, then curl 404 at T+0.3s — the npm CDN had not yet propagated the new tarball. The pure-publish step now succeeds end-to-end through the install.sh sync, sha256 sidecar emission, sigstore-bundle fetch, and GitHub Release creation in a single workflow run.

Removed

  • Phantom 2.0.7 and 2.0.8 git tags + GitHub Releases withdrawn. Both were cut locally by bump-version.js but the release workflow's npm publish step was rejected on both attempts (see Changed above), so neither version ever reached the npm registry. Leaving the tags + Releases in place would have confused users running npx @webventures/testatlas@2.0.7 … against an npm view that doesn't list them. The functional change that v2.0.7 was meant to ship (tarball-URL scope fix below) is rolled forward into this release.

Fixed

  • scripts/lib/tarball.js registry URL now includes the @webventures scope. Pre-fix, npmTarballUrl(version) returned https://registry.npmjs.org/testatlas/-/testatlas-${version}.tgz (unscoped path), which 404s for a scoped package; the correct form is https://registry.npmjs.org/@webventures/testatlas/-/testatlas-${version}.tgz. Symptom: npx @webventures/testatlas update failed with 404 when the workflow fell through to direct registry download. (Originally landed as commit f501a56d, was meant to ship in v2.0.7.)

[2.0.6] - 2026-05-13

Fixed

  • scripts/triage.js#verifyEvidenceOnDisk resolves bare evidence IDs under the canonical evidence/ directory. Pre-fix, when an issue's evidence[] array contained a bare ID (no / separator) that wasn't yet present in the evidence index, the fallback stat() looked at <wsDir>/<ID> instead of <wsDir>/evidence/<ID>, causing false-positive missing-evidence flags on triage runs against workspaces where evidence existed in the canonical spot but the index was stale. Resolver now tries <wsDir>/evidence/<ID> first for bare IDs, falls back to <wsDir>/<ID> for back-compat, and treats paths containing / or \ as relative to <wsDir> unchanged. New test/scripts/triage-script.test.js cases pin both paths.

[2.0.5] - 2026-05-12

No notable changes since 2.0.4.

[2.0.4] - 2026-05-12

No notable changes since 2.0.3.

[2.0.3] - 2026-05-12

Added

  • .testatlas/package.json ESM marker — adds a 4-line package.json ({"type":"module","private":true}) at the suite root so Node parses the entire .testatlas/scripts/ subtree as ES modules without walking up to the consumer's own package.json. Pre-fix, every script invocation in installed targets without "type":"module" in their root package.json (or with no package.json at all) emitted (node:NNN) [MODULE_TYPELESS_PACKAGE_JSON] Warning: Module type of file:///...validate-brain.js is not specified and it doesn't parse as CommonJS. because Node defaulted to CommonJS, failed on import/export syntax, then fell back to ESM. Scripts ran correctly but every invocation was prefixed with the noisy warning, obscuring real warnings/errors. The new marker is self-contained — doesn't shadow the consumer's own package.json (lives only inside .testatlas/), doesn't ship as a standalone npm package ("private":true), and the suite source's existing root package.json ("type":"module") means the marker is harmless when scripts run from the source tree. Ships via the npm tarball at package/.testatlas/package.json → extractTarball lands it at <dstDir>/package.json → atomic swap puts it at <target>/.testatlas/package.json for both init and update paths automatically. The fixture in test/scripts/extract-tarball-strips-package-wrapper.test.js was updated to include package/.testatlas/package.json; the existing assertion that "tarball-root package.json must NOT extract" was flipped to assert the ESM marker DOES extract with type:"module" content (the strip filter package/.testatlas still correctly excludes the outer package/package.json). Top-level shape assertion updated to ['adapters','bootstrap.md','migrations','package.json','scripts'].
  • .testatlas/adapters/claude-code/.claude/commands/atlas-create-persona.md — adds the long-missing adapter output for the create-persona source command. The file was generated locally during phase-17-05 but git add silently dropped it because .gitignore's bare .claude/ pattern matched the nested adapter path (see Fixed entry below). The file content is byte-identical to what assemble-adapter --check was expecting and matches the 12 sibling adapters that already ship atlas-create-persona.<ext> for the same source.

Changed

  • CI workflow install.sh smoke tarball glob —...
Read more

v2.0.9

Choose a tag to compare

@CryptVenture CryptVenture released this 13 May 20:23

Added

  • better-sqlite3 added to devDependencies — required by recently-added dogfood tooling; absence broke local pnpm install for contributors using the explore/brain scripts.

Changed

  • Release workflow hardened with retry-with-backoff at two known-flaky points. (1) npm publish is now wrapped in a 3-attempt loop with 10s/30s backoff between attempts. The observed failure (v2.0.7 + v2.0.8, 2026-05-13) was POST 201 oidc/token/exchange → sigstore-provenance-signed → PUT 400 OIDC publish authorize: Invalid token: the OIDC trade succeeded but the actual publish PUT was rejected. npm CLI mints a fresh ID token on each attempt, so retrying clears the failure when it's transient on npm's side; when it's structural (trusted-publisher config drift), all 3 attempts fail and the step exits non-zero with the full verbose log preserved per attempt. (2) The post-publish curl of the registry tarball URL (used to compute the SHA-256 for install.sh + sigstore sidecar) is now wrapped in a 10-attempt loop with 6s backoff. The race was observed at v2.0.6: PUT 200 at T+0s, then curl 404 at T+0.3s — the npm CDN had not yet propagated the new tarball. The pure-publish step now succeeds end-to-end through the install.sh sync, sha256 sidecar emission, sigstore-bundle fetch, and GitHub Release creation in a single workflow run.

Removed

  • Phantom 2.0.7 and 2.0.8 git tags + GitHub Releases withdrawn. Both were cut locally by bump-version.js but the release workflow's npm publish step was rejected on both attempts (see Changed above), so neither version ever reached the npm registry. Leaving the tags + Releases in place would have confused users running npx @webventures/testatlas@2.0.7 … against an npm view that doesn't list them. The functional change that v2.0.7 was meant to ship (tarball-URL scope fix below) is rolled forward into this release.

Fixed

  • scripts/lib/tarball.js registry URL now includes the @webventures scope. Pre-fix, npmTarballUrl(version) returned https://registry.npmjs.org/testatlas/-/testatlas-${version}.tgz (unscoped path), which 404s for a scoped package; the correct form is https://registry.npmjs.org/@webventures/testatlas/-/testatlas-${version}.tgz. Symptom: npx @webventures/testatlas update failed with 404 when the workflow fell through to direct registry download. (Originally landed as commit f501a56d, was meant to ship in v2.0.7.)

v2.0.6

Choose a tag to compare

@CryptVenture CryptVenture released this 13 May 18:33

No notable changes since 2.0.5.

v2.0.5

Choose a tag to compare

@CryptVenture CryptVenture released this 12 May 15:08

Changelog

All notable changes to this project will be documented in this file. Format is based on Keep a Changelog, and this project adheres to Semantic Versioning. Releases are managed via @changesets/cli.

[Unreleased]

Added

Changed

Removed

[2.0.5] - 2026-05-12

No notable changes since 2.0.4.

[2.0.4] - 2026-05-12

No notable changes since 2.0.3.

[2.0.3] - 2026-05-12

Added

  • .testatlas/package.json ESM marker — adds a 4-line package.json ({"type":"module","private":true}) at the suite root so Node parses the entire .testatlas/scripts/ subtree as ES modules without walking up to the consumer's own package.json. Pre-fix, every script invocation in installed targets without "type":"module" in their root package.json (or with no package.json at all) emitted (node:NNN) [MODULE_TYPELESS_PACKAGE_JSON] Warning: Module type of file:///...validate-brain.js is not specified and it doesn't parse as CommonJS. because Node defaulted to CommonJS, failed on import/export syntax, then fell back to ESM. Scripts ran correctly but every invocation was prefixed with the noisy warning, obscuring real warnings/errors. The new marker is self-contained — doesn't shadow the consumer's own package.json (lives only inside .testatlas/), doesn't ship as a standalone npm package ("private":true), and the suite source's existing root package.json ("type":"module") means the marker is harmless when scripts run from the source tree. Ships via the npm tarball at package/.testatlas/package.json → extractTarball lands it at <dstDir>/package.json → atomic swap puts it at <target>/.testatlas/package.json for both init and update paths automatically. The fixture in test/scripts/extract-tarball-strips-package-wrapper.test.js was updated to include package/.testatlas/package.json; the existing assertion that "tarball-root package.json must NOT extract" was flipped to assert the ESM marker DOES extract with type:"module" content (the strip filter package/.testatlas still correctly excludes the outer package/package.json). Top-level shape assertion updated to ['adapters','bootstrap.md','migrations','package.json','scripts'].
  • .testatlas/adapters/claude-code/.claude/commands/atlas-create-persona.md — adds the long-missing adapter output for the create-persona source command. The file was generated locally during phase-17-05 but git add silently dropped it because .gitignore's bare .claude/ pattern matched the nested adapter path (see Fixed entry below). The file content is byte-identical to what assemble-adapter --check was expecting and matches the 12 sibling adapters that already ship atlas-create-persona.<ext> for the same source.

Changed

  • CI workflow install.sh smoke tarball glob — .github/workflows/ci.yml:255,264 switched from testatlas-*.tgz to *testatlas-*.tgz to match both the legacy unscoped name and the current webventures-testatlas-<version>.tgz produced by pnpm pack since the package was renamed to @webventures/testatlas in commit 490d44ef (2026-05-04). Pre-fix, the glob expanded to no files → $TARBALL="" → _TESTATLAS_TARBALL_OVERRIDE=$PWD/ → install.sh tried to cp the working directory → cp: -r not specified → exit 1. Both the install and uninstall round-trip steps now also assert test -n "$TARBALL" as a defensive backstop so a future rename fails loudly instead of silently breaking the same way.
  • Biome lint debt cleared. pnpm lint previously emitted 33 errors / 19 warnings / 3 infos (auto-detected by Biome 2.x); pnpm biome check --write applied safe fixes across 26 files: import-sort organization (alphabetical, grouped by source) and single-line collapse of multi-line single-statement expressions. Zero semantic changes — all 1888 tests remain green / 2 intentional skip post-autofix; full sample-diff review confirmed pure formatting changes (no logic edits, no removed branches, no signature changes). Touched files: 6 under scripts/ (mcp-server, reconcile-counts, record-execution-mode, update-brain-after-command, script-flag-metadata, lib/safety) and 20 under test/ (mostly lint-commands invariant suites). pnpm lint now exits 0 with 16 remaining warnings (down from 19) and 3 infos that are non-blocking.

Removed

Fixed

  • .gitignore no longer silently swallows new adapter outputs under .testatlas/adapters/<name>/<dotdir>/. The bare patterns .claude/, .cursor/, .opencode/, .kilocode/, .aider/, .windsurf/, .continue/, .cline/, .codex/, .gemini/, .roo/, .kiro/ (intended to ignore consumer-side installed adapter directories that may appear in adapter authors' working trees) also matched the nested adapter-source paths like .testatlas/adapters/claude-code/.claude/commands/. When a new source command was added and the adapter regen produced a corresponding output file in any of those nested paths, git add silently dropped it (no error, no stderr — gitignore-match is invisible). The 72 sibling adapter files already in those paths kept being tracked under the grandfather rule (gitignore doesn't untrack previously-tracked files), so git status showed nothing wrong; only CI's fresh-checkout adapter-parity tests caught the gap, with expected 73 flat derived files; got 72 and downstream cascades in adapter-parity-final, adapter-parity-stub, adapter-flat-discovery, REQUIREMENTS.md / CLAUDE.md drift checks, and graph-relationship integrity tests (~29 subtest failures total across the Test ×9 matrix). The fix adds explicit negation patterns (!.testatlas/adapters/**/.claude/, etc.) for all 12 historically-gitignored adapter output dirs, restoring git add visibility for the full .testatlas/adapters/ subtree without affecting the original intent of ignoring consumer-side installed dirs at repo roots.
  • Tests reading suite-author-local dogfood state now skip cleanly on fresh CI checkouts. Several test files unconditionally read files under .planning/REQUIREMENTS.md, CLAUDE.md, _testatlas/brain/*, _testatlas/bootstrap/*, _testatlas/agents/registry.json, and _testatlas/tests/ — all of which are intentionally gitignored (suite-author working-tree state). Locally these tests verify real content; on CI fresh checkout they failed with ENOENT because the files don't exist. Added a shared skipIfMissing(t, path) helper (test/_helpers/repo-local-state.js) and applied it to the entry points in test/dist/dist03-changelog.test.js (4 tests, REQUIREMENTS.md), test/governance/doc-drift.test.js (2 tests, CLAUDE.md), test/graph-relationship.test.js (1 test, brain/graph.json), test/requirements-val05-closure.test.js (3 tests, REQUIREMENTS.md), test/schemas/drift-record-additivity.test.js (3 tests, brain/drift.json), test/schemas/matrix-id-pattern.test.js (1 test, tests/), and test/v2-structure.test.js (8 tests, brain + bootstrap + agents/registry). Each skip is annotated with the reason in the test-reporter output so anyone reading CI logs understands the test was skipped because the file is suite-author state, not because the test was disabled. In the source repo (suite author with files present) the tests still RUN and verify content; the skip path only fires on fresh checkouts. Eliminates 20+ CI failures across all 3 OS × 3 Node versions.
  • install.sh _TESTATLAS_TARBALL_OVERRIDE no longer hard-fails on the published-tarball SHA mismatch. The test hook copies a local tarball in place of the network fetch. Pre-fix, _verify_checksum then ran against the hardcoded TARBALL_SHA256 (synced at release time to the published npm tarball's SHA), and a locally-packed tarball can never match because tar metadata + compression bits differ. cp: -r not specified — omitting directory was the user-facing symptom when the CI glob also failed; with the glob fix, the next layer surfaced as WARNING: 1 computed checksum did NOT match. Fix: when the override env var is set, install.sh now internally sets TESTATLAS_SKIP_CHECKSUM=1 before calling _verify_checksum, so the existing skip-with-log path fires ("TESTATLAS_SKIP_CHECKSUM=1 set; skipping checksum verification.") rather than rejecting the local file. The placeholder-mode contract (TARBALL_SHA256="REPLACE_AT_RELEASE") is unchanged. Signature verification (TESTATLAS_VERIFY_SIGNATURE) still runs when the user explicitly pins that env var alongside the override — they're then explicitly opting into a sigstore check that fails by design against a non-published tarball, which is the right behavior (loud failure = explicit consent).
  • macOS test jobs no longer fail at the prerequisite-install step with shellcheck: command not found. GitHub-hosted macOS runner images previously preinstalled shellcheck via Homebrew; sometime mid-2026 that preinstall was dropped. The CI workflow's prerequisite step (Install dogfood-test prerequisites) assumed it was present and just ran shellcheck --version to validate. Now the step runs brew install shellcheck first (no-op if already present) before invoking --version, restoring all 3 macOS Test matrix jobs (Node 20, 22, 24).
  • Banner detection tests accept both Unicode (█) and ASCII (#) art. On Windows runners without WT_SESSION/TERM_PROGRAM env vars, isUnicode() (scripts/lib/colors.js) returns false and the banner renders ASCII; the original BANNER_LINES (Unicode-only) lookup in test/cli/install-js-banner.test.js, test/cli/update-js-banner.test.js, test/cli/uninstall-js-banner.test.js, and test/cli/install-sh-banner.test.js matched 0 hits and failed with expected ≥4 banner art lines; got 0 even though the ASCII banner was rendered correctly in stdout. Tests now count hits against both BANNER_LINES and BANNER_ASCII_LINES and accept ≥4 in EITHER set, so the "did we render a banner?" assertion ...
Read more

v2.0.2

Choose a tag to compare

@CryptVenture CryptVenture released this 10 May 16:14

Changelog

All notable changes to this project will be documented in this file. Format is based on Keep a Changelog, and this project adheres to Semantic Versioning. Releases are managed via @changesets/cli.

[Unreleased]

Added

Changed

Removed

[2.0.2] - 2026-05-10

Added

Changed

Removed

Fixed

  • Hotfix — update no longer wipes <target>/.testatlas/scripts/. extractTarball() (scripts/lib/tarball.js) extracted only package/.testatlas/ from the npm tarball, dropping the sibling package/scripts/ tree on the floor. The atomic-swap step in runUpdate() then renamed the staged tree (with no scripts/) into place, deleting the script subtree the prior init had populated via copyValidatorScripts(). Net effect on every released v2.0.x consumer: the first npx @webventures/testatlas update [--force-reinstall] removed every accelerator script (create-domain.js, sync-system-map.js, create-issue.js, create-flow.js, create-evidence-record.js, update-indexes.js, validate-workspace.js, etc.) plus their lib/ closure, forcing every /atlas:* command into its slow manual-fallback path and breaking the /atlas:map-domains preferred path the user reported. v2.0.2 makes extractTarball perform two staged extractions: package/.testatlas/ (--strip-components=2, unchanged) and package/scripts/ (--strip-components=1, excluding scripts/e2e/ to mirror copyValidatorScripts's init-time exclusion). The staged tree now mirrors a fully-installed .testatlas/ so the post-swap <target>/.testatlas/ includes its scripts/ subtree. Three new regression tests in test/scripts/extract-tarball-strips-package-wrapper.test.js pin the new contract: package/scripts/x.js → dstDir/scripts/x.js, package/scripts/lib/y.js → dstDir/scripts/lib/y.js, and package/scripts/e2e/z.js excluded; the existing top-level-shape assertion was updated to ['adapters','bootstrap.md','migrations','scripts']. End-to-end verified by packing the suite locally and asserting all six user-facing accelerator scripts arrive in the staged tree. No init-path change required — copyValidatorScripts() (scripts/lib/install-core.js:472-494) already handled this for fresh installs; v2.0.2 brings the update path to parity.

[2.0.1] - 2026-05-10

Fixed

  • Hotfix — update --force-reinstall no longer denied by default safeMode:true. v2.0.0 added a requireCapability(config, 'destructive-fs') gate at runUpdate() entry (Phase 18-01 / ISSUE-011 defense-in-depth) but left no bypass for top-level CLI invocations, so npx @webventures/testatlas update --force-reinstall against a fresh install hit Capability denied (destructive-fs): safeMode is enabled even though the user explicitly invoked the canonical update command. v2.0.1 adds opts.bypassSafetyGate to runUpdate() and runUninstall(); bin/testatlas.js passes bypassSafetyGate: true for both subcommands (CLI = explicit user consent). Programmatic / sub-agent callers do NOT pass the flag and remain config-gated, preserving the original ISSUE-011 / ISSUE-014 defense-in-depth value. Two new regression tests in test/update/update-safety.test.js pin both paths: bypass honored under safeMode:true; absence of bypass still denies under safeMode:true.

Changed

Added

[2.0.0] - 2026-05-10

TestAtlas v2.0.0 is a major release introducing the Multi-Agent Quality Intelligence Brain — a persistent, machine-readable quality layer that turns any capable AI agent into a product-understanding, exploration, and evidence-collection system. V2 adds 41 new commands, 18 new schemas, 14 system personas, 11 council commands, and full support across all 18 host adapters. Phase 22 + Phase 23 follow-on work (closing 8 COUNCIL-2026-05-09-003 brain-audit findings) plus the COUNCIL-2026-05-10-001 release-readiness fixpack are folded into the v2.0.0 release per Option A of the council's release-cut decision.

Phase 23 — Close 8 COUNCIL-2026-05-09-003 brain-audit findings (DEC-001..DEC-008 + OPEN-001)

Phase 23 closes the structural-not-functional residue from Phase 22 surfaced by COUNCIL-2026-05-09-003. All 8 motions carried; 5 net-new high-leverage gaps the Phase-22 verifier missed. Backward-compat absolute — every fix is additive.

Fixed (Phase 23)

  • DEC-001 / ISSUE-042 + ISSUE-045 — Audit-honesty: 22-04-SUMMARY.md + Phase-22 Verification narrative now cite live test counts (1842 / 1836 pass / 6 distinct fail / 2 skip) with all 6 distinct failure names enumerated.
  • DEC-002 / ISSUE-038 — _testatlas/brain/drift.json repopulated with 11 schema-conforming records (DRIFT-001..DRIFT-011) reflecting COUNCIL-2026-05-09-002 audit findings; drift-record-additivity.test.js Test 4 (length===11) GREEN.
  • DEC-003 / ISSUE-039 — scripts/update-indexes.js#listCouncilSessions reads each session.json and emits per-session bullets with topic + mode= + participants=N + status=; 09_artifact_index.md council-sessions block now enumerates real metadata. Missing session.json falls back to path-only (back-compat).
  • DEC-004 / ISSUE-040 — .testatlas/commands/explore.md trimmed to ≤1800 words AND ≤6 What's Next entries; long-form per-child brief contract extracted to NEW .testatlas/reference/explore-orchestration.md.
  • DEC-005 / ISSUE-043 — _testatlas/00_overview.md "Core Domains" section replaced with TESTATLAS:GENERATED domain-count block driven by state.json#counts.domains; doc never drifts from brain truth.
  • DEC-006 / ISSUE-041 — --reconcile-counts --populate-from-app-map --detect-drift flags wired into the existing update-brain-after-command.js invocations in .testatlas/commands/explore-codebase.md and .testatlas/commands/core/brain-sync.md; Phase-22 producer scripts now fire at runtime; lifecycle-flag-wiring.test.js pins the wiring.
  • DEC-007 / ISSUE-044 — scripts/consolidate-council.js docstring lines 215-221 trimmed to drop the orphan 'strong-suspect' mention; comment now matches code at line 227.
  • DEC-008 — CHANGELOG.md [0.1.0] gains ### Schema migration section; package.json#version bumped 1.2.6 → 2.0.0. DIST-03 + package-version-vs-CHANGELOG tests GREEN.

Added (Phase 23)

  • OPEN-001 ADR captured — .testatlas/reference/council-protocol.md gains "Deferred design — vote-status producer (OPEN-001)" section documenting the future update-claim-status-from-votes.js producer that would let DEC-004's OR-gate tighten to AND without re-introducing the 5-phase silent zero-promotion regression. Implementation deferred; design + scaffolding captured here.
  • NEW .testatlas/reference/explore-orchestration.md — long-form per-child brief contract reference extracted from explore.md per CMD-03 budget compliance.

Verification (Phase 23)

  • pnpm test: 1877 total / 1875 pass / 0 fail / 2 intentional skip (the previously-failing 6 distinct ✖ all flipped GREEN; Wave-2 cascade RED bars closed by Wave-3 adapter + example regen).
  • check-adapter-parity --strict: 1314/1314 obligations (100.0%) — restored from Wave-2 source-body divergence (910/1314 RED → 1314/1314 GREEN).
  • lint-commands 0 violations; check-command-budgets / validate-workspace / validate-brain all exit 0.
  • 18 adapter trees + 7 example workspaces regenerated; 5 Wave-0 RED-bar tests authored (update-indexes-council-sessions-rich, 00-overview-domain-count, lifecycle-flag-wiring, consolidate-council-comment-code-parity, council-protocol-deferred-design) — all GREEN post-Wave-1/2 implementation.
  • Concurrent-agent boundary preserved through Phase-23 closure: scripts/lib/install-core.js + scripts/lib/update-core.js byte-identical pre-/post (commits 70e73331..838bae58).

Fixed (Phase 23 / Plan 23-03 — DEC-001 audit-honesty correction to Phase-22 verification)

  • Phase-22 Verification narrative corrected. Original CHANGELOG + 22-04-SUMMARY.md cited "1837/3/2 of 1842"; live counts at Phase-22 closure were 1842 / 1836 pass / 6 distinct ✖ / 2 skip. Phase 23 closes all 6. Full post-mortem: see .testatlas/reference/audit-honesty-history.md.

Added (Phase 23 / Plan 23-01 — Wave 0 TDD red-bar)

  • 5 RED-bar regression tests pinning Phase-23 contracts (DEC-003, DEC-005, DEC-006, DEC-007, OPEN-001) BEFORE production-code edits, per Nyquist contract:
    • test/update-indexes-council-sessions-rich.test.js — DEC-003 pins listCouncilSessions enrichment.
    • test/00-overview-domain-count.test.js — DEC-005 pins domain-count GENERATED block live-sync.
    • test/commands/lifecycle-flag-wiring.test.js — DEC-006 pins --reconcile-counts --populate-from-app-map --detect-drift invocation.
    • test/scripts/consolidate-council-comment-code-parity.test.js — DEC-007 pins zero strong-suspect in docstring.
    • test/reference/council-protocol-deferred-design.test.js — OPEN-001 pins the deferred-design ADR.
  • Test suite delta: 1842 → 1877 (+35); 1834 → 1849 pass (+15 baselines GREEN); 6 → 26 fail (+20 RED contract pins). All baseline RED tests preserved unchanged.

Fixed (Release-readiness post-Phase-23, COUNCIL-2026-05-10-001)

  • DEC-002..DEC-005 fixpack — Pre-tag closure of 9 residual workspace-hygiene findings surfaced by the Release Readiness council (2026-05-10): cleared validate-workspace schema-discipline (dropped unregistered $schema URL from _testatlas/brain/drift.json; auto-healed manifest counts; refreshed cross-cut index hashes for 7 to_fix/by_* indexes — validate-workspace 0 errors / 0 warnings); transitioned 8 brain rows ISSUE-038..045 from status:new → status:closed with append-only history entries (closing the lifecycle gap where Phase-23 closed code but did not flip status); trimmed CHANGELOG.md from 3080 → 3000 words by extracting the Phase-22 audit-honesty post-mortem to .testatlas/reference/audit-honesty-history.md (with 1-li...
Read more

v2.0.1

Choose a tag to compare

@CryptVenture CryptVenture released this 10 May 15:54

Changelog

All notable changes to this project will be documented in this file. Format is based on Keep a Changelog, and this project adheres to Semantic Versioning. Releases are managed via @changesets/cli.

[Unreleased]

Added

Changed

Removed

[2.0.1] - 2026-05-10

Fixed

  • Hotfix — update --force-reinstall no longer denied by default safeMode:true. v2.0.0 added a requireCapability(config, 'destructive-fs') gate at runUpdate() entry (Phase 18-01 / ISSUE-011 defense-in-depth) but left no bypass for top-level CLI invocations, so npx @webventures/testatlas update --force-reinstall against a fresh install hit Capability denied (destructive-fs): safeMode is enabled even though the user explicitly invoked the canonical update command. v2.0.1 adds opts.bypassSafetyGate to runUpdate() and runUninstall(); bin/testatlas.js passes bypassSafetyGate: true for both subcommands (CLI = explicit user consent). Programmatic / sub-agent callers do NOT pass the flag and remain config-gated, preserving the original ISSUE-011 / ISSUE-014 defense-in-depth value. Two new regression tests in test/update/update-safety.test.js pin both paths: bypass honored under safeMode:true; absence of bypass still denies under safeMode:true.

Changed

Added

[2.0.0] - 2026-05-10

TestAtlas v2.0.0 is a major release introducing the Multi-Agent Quality Intelligence Brain — a persistent, machine-readable quality layer that turns any capable AI agent into a product-understanding, exploration, and evidence-collection system. V2 adds 41 new commands, 18 new schemas, 14 system personas, 11 council commands, and full support across all 18 host adapters. Phase 22 + Phase 23 follow-on work (closing 8 COUNCIL-2026-05-09-003 brain-audit findings) plus the COUNCIL-2026-05-10-001 release-readiness fixpack are folded into the v2.0.0 release per Option A of the council's release-cut decision.

Phase 23 — Close 8 COUNCIL-2026-05-09-003 brain-audit findings (DEC-001..DEC-008 + OPEN-001)

Phase 23 closes the structural-not-functional residue from Phase 22 surfaced by COUNCIL-2026-05-09-003. All 8 motions carried; 5 net-new high-leverage gaps the Phase-22 verifier missed. Backward-compat absolute — every fix is additive.

Fixed (Phase 23)

  • DEC-001 / ISSUE-042 + ISSUE-045 — Audit-honesty: 22-04-SUMMARY.md + Phase-22 Verification narrative now cite live test counts (1842 / 1836 pass / 6 distinct fail / 2 skip) with all 6 distinct failure names enumerated.
  • DEC-002 / ISSUE-038 — _testatlas/brain/drift.json repopulated with 11 schema-conforming records (DRIFT-001..DRIFT-011) reflecting COUNCIL-2026-05-09-002 audit findings; drift-record-additivity.test.js Test 4 (length===11) GREEN.
  • DEC-003 / ISSUE-039 — scripts/update-indexes.js#listCouncilSessions reads each session.json and emits per-session bullets with topic + mode= + participants=N + status=; 09_artifact_index.md council-sessions block now enumerates real metadata. Missing session.json falls back to path-only (back-compat).
  • DEC-004 / ISSUE-040 — .testatlas/commands/explore.md trimmed to ≤1800 words AND ≤6 What's Next entries; long-form per-child brief contract extracted to NEW .testatlas/reference/explore-orchestration.md.
  • DEC-005 / ISSUE-043 — _testatlas/00_overview.md "Core Domains" section replaced with TESTATLAS:GENERATED domain-count block driven by state.json#counts.domains; doc never drifts from brain truth.
  • DEC-006 / ISSUE-041 — --reconcile-counts --populate-from-app-map --detect-drift flags wired into the existing update-brain-after-command.js invocations in .testatlas/commands/explore-codebase.md and .testatlas/commands/core/brain-sync.md; Phase-22 producer scripts now fire at runtime; lifecycle-flag-wiring.test.js pins the wiring.
  • DEC-007 / ISSUE-044 — scripts/consolidate-council.js docstring lines 215-221 trimmed to drop the orphan 'strong-suspect' mention; comment now matches code at line 227.
  • DEC-008 — CHANGELOG.md [0.1.0] gains ### Schema migration section; package.json#version bumped 1.2.6 → 2.0.0. DIST-03 + package-version-vs-CHANGELOG tests GREEN.

Added (Phase 23)

  • OPEN-001 ADR captured — .testatlas/reference/council-protocol.md gains "Deferred design — vote-status producer (OPEN-001)" section documenting the future update-claim-status-from-votes.js producer that would let DEC-004's OR-gate tighten to AND without re-introducing the 5-phase silent zero-promotion regression. Implementation deferred; design + scaffolding captured here.
  • NEW .testatlas/reference/explore-orchestration.md — long-form per-child brief contract reference extracted from explore.md per CMD-03 budget compliance.

Verification (Phase 23)

  • pnpm test: 1877 total / 1875 pass / 0 fail / 2 intentional skip (the previously-failing 6 distinct ✖ all flipped GREEN; Wave-2 cascade RED bars closed by Wave-3 adapter + example regen).
  • check-adapter-parity --strict: 1314/1314 obligations (100.0%) — restored from Wave-2 source-body divergence (910/1314 RED → 1314/1314 GREEN).
  • lint-commands 0 violations; check-command-budgets / validate-workspace / validate-brain all exit 0.
  • 18 adapter trees + 7 example workspaces regenerated; 5 Wave-0 RED-bar tests authored (update-indexes-council-sessions-rich, 00-overview-domain-count, lifecycle-flag-wiring, consolidate-council-comment-code-parity, council-protocol-deferred-design) — all GREEN post-Wave-1/2 implementation.
  • Concurrent-agent boundary preserved through Phase-23 closure: scripts/lib/install-core.js + scripts/lib/update-core.js byte-identical pre-/post (commits 70e73331..838bae58).

Fixed (Phase 23 / Plan 23-03 — DEC-001 audit-honesty correction to Phase-22 verification)

  • Phase-22 Verification narrative corrected. Original CHANGELOG + 22-04-SUMMARY.md cited "1837/3/2 of 1842"; live counts at Phase-22 closure were 1842 / 1836 pass / 6 distinct ✖ / 2 skip. Phase 23 closes all 6. Full post-mortem: see .testatlas/reference/audit-honesty-history.md.

Added (Phase 23 / Plan 23-01 — Wave 0 TDD red-bar)

  • 5 RED-bar regression tests pinning Phase-23 contracts (DEC-003, DEC-005, DEC-006, DEC-007, OPEN-001) BEFORE production-code edits, per Nyquist contract:
    • test/update-indexes-council-sessions-rich.test.js — DEC-003 pins listCouncilSessions enrichment.
    • test/00-overview-domain-count.test.js — DEC-005 pins domain-count GENERATED block live-sync.
    • test/commands/lifecycle-flag-wiring.test.js — DEC-006 pins --reconcile-counts --populate-from-app-map --detect-drift invocation.
    • test/scripts/consolidate-council-comment-code-parity.test.js — DEC-007 pins zero strong-suspect in docstring.
    • test/reference/council-protocol-deferred-design.test.js — OPEN-001 pins the deferred-design ADR.
  • Test suite delta: 1842 → 1877 (+35); 1834 → 1849 pass (+15 baselines GREEN); 6 → 26 fail (+20 RED contract pins). All baseline RED tests preserved unchanged.

Fixed (Release-readiness post-Phase-23, COUNCIL-2026-05-10-001)

  • DEC-002..DEC-005 fixpack — Pre-tag closure of 9 residual workspace-hygiene findings surfaced by the Release Readiness council (2026-05-10): cleared validate-workspace schema-discipline (dropped unregistered $schema URL from _testatlas/brain/drift.json; auto-healed manifest counts; refreshed cross-cut index hashes for 7 to_fix/by_* indexes — validate-workspace 0 errors / 0 warnings); transitioned 8 brain rows ISSUE-038..045 from status:new → status:closed with append-only history entries (closing the lifecycle gap where Phase-23 closed code but did not flip status); trimmed CHANGELOG.md from 3080 → 3000 words by extracting the Phase-22 audit-honesty post-mortem to .testatlas/reference/audit-honesty-history.md (with 1-line cross-reference); folded the [Unreleased] Phase-22+23 entries into this [2.0.0] block per release-cut Option A. Surfaced 4 issue candidates (validate-workspace.js + check-token-budget.js exit-code masking — turned out NOT to be regressions; the masking was a piped-tail measurement artifact in the council prompt; AJV singleton drift schema registration; brain-status lifecycle gap → OPEN-007 obd-verifier checklist extension). Final state: pnpm test 1877/1875/0/2; validate-workspace 0/0; validate-brain OK; check-adapter-parity --strict 1314/1314; check-token-budget CHANGELOG.md 3000 PASS. Full audit at _testatlas/agents/councils/sessions/COUNCIL-2026-05-10-001/.

Added

  • V2 Multi-Agent Quality Intelligence Brain. A persistent _testatlas/brain/ tree with 16 JSON files (manifest.json, state.json, coverage.json, domains.json, flows.json, issues.json, evidence.json, decisions.json, risks.json, assumptions.json, graph.json, quality_scores.json, drift.json, agent_sessions.json, personas.json, events.jsonl) that captures everything an agent learns about the product under test. Every brain file is AJV-validated before write.

    • scripts/validate-brain.js — full brain validation against V2 schemas
    • scripts/score-quality.js — 11 deterministic quality metrics (0-100, no LLM judgment)
    • scripts/detect-drift.js — git-diff-based drift detection with 7 input categories
    • scripts/update-graph.js — 16-relationship knowledge graph populator
    • scripts/update-brain-after-command.js — automated post-operation brain update hook
    • scripts/sync-markdown-json.js — idempotent markdown/JSON reconciliation
    • scripts/index-artifacts.js — brain index rebuild from workspace scan
    • scripts/generate-dashboard-data.js — machine-readable dashboard export
    • scripts/build-sqlite.js — optional SQLite projector (graceful degrade when better-sqlite3 absent)
  • V2 Command Surface — 41 new commands (73 total). Commands are now organ...

Read more

v2.0.0

Choose a tag to compare

@CryptVenture CryptVenture released this 10 May 15:37

Changelog

All notable changes to this project will be documented in this file. Format is based on Keep a Changelog, and this project adheres to Semantic Versioning. Releases are managed via @changesets/cli.

[Unreleased]

Added

Changed

Fixed

[2.0.0] - 2026-05-10

TestAtlas v2.0.0 is a major release introducing the Multi-Agent Quality Intelligence Brain — a persistent, machine-readable quality layer that turns any capable AI agent into a product-understanding, exploration, and evidence-collection system. V2 adds 41 new commands, 18 new schemas, 14 system personas, 11 council commands, and full support across all 18 host adapters. Phase 22 + Phase 23 follow-on work (closing 8 COUNCIL-2026-05-09-003 brain-audit findings) plus the COUNCIL-2026-05-10-001 release-readiness fixpack are folded into the v2.0.0 release per Option A of the council's release-cut decision.

Phase 23 — Close 8 COUNCIL-2026-05-09-003 brain-audit findings (DEC-001..DEC-008 + OPEN-001)

Phase 23 closes the structural-not-functional residue from Phase 22 surfaced by COUNCIL-2026-05-09-003. All 8 motions carried; 5 net-new high-leverage gaps the Phase-22 verifier missed. Backward-compat absolute — every fix is additive.

Fixed (Phase 23)

  • DEC-001 / ISSUE-042 + ISSUE-045 — Audit-honesty: 22-04-SUMMARY.md + Phase-22 Verification narrative now cite live test counts (1842 / 1836 pass / 6 distinct fail / 2 skip) with all 6 distinct failure names enumerated.
  • DEC-002 / ISSUE-038 — _testatlas/brain/drift.json repopulated with 11 schema-conforming records (DRIFT-001..DRIFT-011) reflecting COUNCIL-2026-05-09-002 audit findings; drift-record-additivity.test.js Test 4 (length===11) GREEN.
  • DEC-003 / ISSUE-039 — scripts/update-indexes.js#listCouncilSessions reads each session.json and emits per-session bullets with topic + mode= + participants=N + status=; 09_artifact_index.md council-sessions block now enumerates real metadata. Missing session.json falls back to path-only (back-compat).
  • DEC-004 / ISSUE-040 — .testatlas/commands/explore.md trimmed to ≤1800 words AND ≤6 What's Next entries; long-form per-child brief contract extracted to NEW .testatlas/reference/explore-orchestration.md.
  • DEC-005 / ISSUE-043 — _testatlas/00_overview.md "Core Domains" section replaced with TESTATLAS:GENERATED domain-count block driven by state.json#counts.domains; doc never drifts from brain truth.
  • DEC-006 / ISSUE-041 — --reconcile-counts --populate-from-app-map --detect-drift flags wired into the existing update-brain-after-command.js invocations in .testatlas/commands/explore-codebase.md and .testatlas/commands/core/brain-sync.md; Phase-22 producer scripts now fire at runtime; lifecycle-flag-wiring.test.js pins the wiring.
  • DEC-007 / ISSUE-044 — scripts/consolidate-council.js docstring lines 215-221 trimmed to drop the orphan 'strong-suspect' mention; comment now matches code at line 227.
  • DEC-008 — CHANGELOG.md [0.1.0] gains ### Schema migration section; package.json#version bumped 1.2.6 → 2.0.0. DIST-03 + package-version-vs-CHANGELOG tests GREEN.

Added (Phase 23)

  • OPEN-001 ADR captured — .testatlas/reference/council-protocol.md gains "Deferred design — vote-status producer (OPEN-001)" section documenting the future update-claim-status-from-votes.js producer that would let DEC-004's OR-gate tighten to AND without re-introducing the 5-phase silent zero-promotion regression. Implementation deferred; design + scaffolding captured here.
  • NEW .testatlas/reference/explore-orchestration.md — long-form per-child brief contract reference extracted from explore.md per CMD-03 budget compliance.

Verification (Phase 23)

  • pnpm test: 1877 total / 1875 pass / 0 fail / 2 intentional skip (the previously-failing 6 distinct ✖ all flipped GREEN; Wave-2 cascade RED bars closed by Wave-3 adapter + example regen).
  • check-adapter-parity --strict: 1314/1314 obligations (100.0%) — restored from Wave-2 source-body divergence (910/1314 RED → 1314/1314 GREEN).
  • lint-commands 0 violations; check-command-budgets / validate-workspace / validate-brain all exit 0.
  • 18 adapter trees + 7 example workspaces regenerated; 5 Wave-0 RED-bar tests authored (update-indexes-council-sessions-rich, 00-overview-domain-count, lifecycle-flag-wiring, consolidate-council-comment-code-parity, council-protocol-deferred-design) — all GREEN post-Wave-1/2 implementation.
  • Concurrent-agent boundary preserved through Phase-23 closure: scripts/lib/install-core.js + scripts/lib/update-core.js byte-identical pre-/post (commits 70e73331..838bae58).

Fixed (Phase 23 / Plan 23-03 — DEC-001 audit-honesty correction to Phase-22 verification)

  • Phase-22 Verification narrative corrected. Original CHANGELOG + 22-04-SUMMARY.md cited "1837/3/2 of 1842"; live counts at Phase-22 closure were 1842 / 1836 pass / 6 distinct ✖ / 2 skip. Phase 23 closes all 6. Full post-mortem: see .testatlas/reference/audit-honesty-history.md.

Added (Phase 23 / Plan 23-01 — Wave 0 TDD red-bar)

  • 5 RED-bar regression tests pinning Phase-23 contracts (DEC-003, DEC-005, DEC-006, DEC-007, OPEN-001) BEFORE production-code edits, per Nyquist contract:
    • test/update-indexes-council-sessions-rich.test.js — DEC-003 pins listCouncilSessions enrichment.
    • test/00-overview-domain-count.test.js — DEC-005 pins domain-count GENERATED block live-sync.
    • test/commands/lifecycle-flag-wiring.test.js — DEC-006 pins --reconcile-counts --populate-from-app-map --detect-drift invocation.
    • test/scripts/consolidate-council-comment-code-parity.test.js — DEC-007 pins zero strong-suspect in docstring.
    • test/reference/council-protocol-deferred-design.test.js — OPEN-001 pins the deferred-design ADR.
  • Test suite delta: 1842 → 1877 (+35); 1834 → 1849 pass (+15 baselines GREEN); 6 → 26 fail (+20 RED contract pins). All baseline RED tests preserved unchanged.

Fixed (Release-readiness post-Phase-23, COUNCIL-2026-05-10-001)

  • DEC-002..DEC-005 fixpack — Pre-tag closure of 9 residual workspace-hygiene findings surfaced by the Release Readiness council (2026-05-10): cleared validate-workspace schema-discipline (dropped unregistered $schema URL from _testatlas/brain/drift.json; auto-healed manifest counts; refreshed cross-cut index hashes for 7 to_fix/by_* indexes — validate-workspace 0 errors / 0 warnings); transitioned 8 brain rows ISSUE-038..045 from status:new → status:closed with append-only history entries (closing the lifecycle gap where Phase-23 closed code but did not flip status); trimmed CHANGELOG.md from 3080 → 3000 words by extracting the Phase-22 audit-honesty post-mortem to .testatlas/reference/audit-honesty-history.md (with 1-line cross-reference); folded the [Unreleased] Phase-22+23 entries into this [2.0.0] block per release-cut Option A. Surfaced 4 issue candidates (validate-workspace.js + check-token-budget.js exit-code masking — turned out NOT to be regressions; the masking was a piped-tail measurement artifact in the council prompt; AJV singleton drift schema registration; brain-status lifecycle gap → OPEN-007 obd-verifier checklist extension). Final state: pnpm test 1877/1875/0/2; validate-workspace 0/0; validate-brain OK; check-adapter-parity --strict 1314/1314; check-token-budget CHANGELOG.md 3000 PASS. Full audit at _testatlas/agents/councils/sessions/COUNCIL-2026-05-10-001/.

Added

  • V2 Multi-Agent Quality Intelligence Brain. A persistent _testatlas/brain/ tree with 16 JSON files (manifest.json, state.json, coverage.json, domains.json, flows.json, issues.json, evidence.json, decisions.json, risks.json, assumptions.json, graph.json, quality_scores.json, drift.json, agent_sessions.json, personas.json, events.jsonl) that captures everything an agent learns about the product under test. Every brain file is AJV-validated before write.

    • scripts/validate-brain.js — full brain validation against V2 schemas
    • scripts/score-quality.js — 11 deterministic quality metrics (0-100, no LLM judgment)
    • scripts/detect-drift.js — git-diff-based drift detection with 7 input categories
    • scripts/update-graph.js — 16-relationship knowledge graph populator
    • scripts/update-brain-after-command.js — automated post-operation brain update hook
    • scripts/sync-markdown-json.js — idempotent markdown/JSON reconciliation
    • scripts/index-artifacts.js — brain index rebuild from workspace scan
    • scripts/generate-dashboard-data.js — machine-readable dashboard export
    • scripts/build-sqlite.js — optional SQLite projector (graceful degrade when better-sqlite3 absent)
  • V2 Command Surface — 41 new commands (73 total). Commands are now organized into 7 categories:

    • core/ — init, status, bootstrap-refresh, brain-sync, brain-validate, brain-query, brain-compact, brain-export (8 commands)
    • explore/ — explore-state, explore-errors, explore-components, explore-routes, explore-jobs, explore-security-privacy, explore-observability, explore-tests, explore-brain, explore-release-readiness, explore-all (11 commands)
    • test/ — generate-scenarios, generate-automation, generate-retest-pack, test-critical-flows (4 commands)
    • council/ — council, council-domain-review, council-flow-review, council-product-review, council-bug-triage, council-release-readiness, council-red-team, council-brain-audit, council-retest, council-design-critique, council-test-plan (11 commands)
    • brain/ — brain-score, brain-drift (2 commands)
    • report/ — report-domain, report-release, report-dashboard-data (3 commands)
    • maintain/ — maintain-migrate, maintain-validate-artifacts (2 commands)
  • *...

Read more

v1.2.6

Choose a tag to compare

@CryptVenture CryptVenture released this 06 May 22:09

Changelog

All notable changes to this project will be documented in this file. Format is based on Keep a Changelog, and this project adheres to Semantic Versioning. Releases are managed via @changesets/cli.

[Unreleased]

Added

Changed

Removed

[1.2.6] - 2026-05-06

No notable changes since 1.2.5.

[1.2.5] - 2026-05-06

No notable changes since 1.2.4.

[1.2.4] - 2026-05-06

No notable changes since 1.2.3.

[1.2.3] - 2026-05-06

No notable changes since 1.2.2.

[1.2.2] - 2026-05-06

No notable changes since 1.2.1.

[1.2.1] - 2026-05-06

No notable changes since 1.2.0.

[1.2.0] - 2026-05-06

Changed

  • BREAKING — validate-workspace --auto-heal now applies by default (Quick 260506-nj2). The CLI flag previously required pairing with --apply to actually persist heals; users who ran --auto-heal alone saw "Would apply (N)" and (correctly) concluded nothing changed. The dual-flag UX caused real-world reports to be filed as "autoheal not working." With v1.2.0, bare --auto-heal writes to disk; pass --dry-run for preview. The --apply flag is now a documented no-op (kept parseable for back-compat) and emits a one-time stderr note when paired with --auto-heal. Migration: if you have CI / scripts that ran validate-workspace --auto-heal expecting preview-only behavior, add --dry-run to keep the old semantics. The programmatic validateWorkspace({autoHeal, apply, dryRun}) API is unchanged — only the CLI default flipped.
  • scripts/lib/adapters/render-mcp.js requires explicit version parameter (Quick 260506-nj2). The renderer previously hardcoded version: '1.0.0' regardless of project version, so every release shipped an mcp manifest claiming v1.0.0 (the parity-check refresh masked it locally per release). The renderer now throw new TypeErrors if version is omitted; scripts/assemble-adapter.js reads <workspace>/package.json#version and injects it, so the published mcp manifest correctly tracks the suite version (v1.2.0 ships "version": "1.2.0").

Fixed

  • High-severity — runUpdate now executes full adapter upgrade lifecycle for all 7 adapters (ISSUE-030; Quick 260506-mgr). Atomic-swap previously only renamed .testatlas/. Adapter outputs that live OUTSIDE the suite tree (.claude/commands/atlas-*.md for claude-code, .cursor/rules/*.mdc for cursor, AGENTS.md for opencode/generic, .aider/CONVENTIONS.md for aider, mcp-server config, kilo equivalents) were never re-emitted on update — every consumer-side update from v1.0.0 onward left those files at install-time bodies forever. regenerateInstallManifest walked only .testatlas/, dropping adapter files from the regenerated manifest and silently disabling drift detection + clean uninstall for them. v1.2.0 adds a restageAdapters helper invoked between tarball cleanup and manifest regen: re-emits all adapter command files from the new tarball via copyAdapterCommandFiles, prunes orphaned entries (files removed in vNext), honors manifest.mode === 'global', and includes the re-emitted entries in the regenerated manifest with correct type. Per-adapter try/catch — one bad adapter does not abort the rest. Action required for users on v1.0.0–v1.1.5: run npx @webventures/testatlas update --force-reinstall once after updating to v1.2.0 to refresh the adapter command files in your repo. Subsequent updates will refresh them automatically.
  • Reporter preview subtitle now appears under the section header (Quick 260506-nj2). When --auto-heal --dry-run is used (preview mode), the report previously only showed a per-row footer "Preview only" note. Users skimming the section header could miss the indicator. v1.2.0 adds a section-header subtitle directly under ### Would apply (N) so the preview-only state is unmissable. Footer wording updated from "re-run with --apply" to "re-run without --dry-run" to match the new flag semantics. No change when applied.length === 0 (nothing to preview).

Added

[1.1.5] - 2026-05-06

No notable changes since 1.1.4.

[1.1.4] - 2026-05-06

No notable changes since 1.1.3.

[1.1.3] - 2026-05-06

No notable changes since 1.1.2.

[1.1.2] - 2026-05-06

No notable changes since 1.1.1.

[1.1.1] - 2026-05-06

No notable changes since 1.1.0.

[1.1.0] - 2026-05-06

Added

  • Cosign + dogfood-test infrastructure (Quick 260506-07b). sigstore/cosign-installer@v3 (SHA-pinned) wired into .github/workflows/ci.yml so dogfood scenarios run against a real cosign install. New scripts/setup-dogfood-env.sh POSIX pre-flight probes for cosign + shellcheck + gh + sha256sum + tar + git + curl + jq + node ≥ 20; copy-paste install hints per missing binary; optional --install flag attempts non-interactive install on Linux.
  • CONTRIBUTING.md Dogfood Test Prerequisites section (Quick 260506-07b). Documents required binaries with version floors; tells contributors to run sh scripts/setup-dogfood-env.sh before /atlas:test-flow --all; notes CI installs these automatically.
  • NEW scenario TEST-install-cosign-absent-degrade (Quick 260506-07b). Verifies install.sh's fail-open default path: when TESTATLAS_VERIFY_SIGNATURE is unset and cosign is not on PATH, installer proceeds with sha256-only verification (exit 0). Sibling to TEST-install-cosign-verification-smoke (tamper-fail focus). Scenario count 25→26.
  • Per-area report views (Quick 260506-dyb G5). scripts/generate-report.js now emits _testatlas/reports/regressions.md, readiness.md, coverage.md, quality_risks.md from the same aggregation pass. Previously these were declared in the spec but never written.
  • counts.reports field in workspace-manifest.schema.json (Quick 260506-dyb G4). Optional integer ≥0 added additively (no migration required); HEAL-01 + check-status-counts updated to validate it; sync-status.js writes it from disk truth (_testatlas/reports/REPORT-*.md count).
  • scripts/triage.js accelerator (Quick 260506-esm). Production-grade idempotent triage driver mirroring scripts/create-issue.js shape. Loads all _testatlas/to_fix/ISSUE-*.json; verifies evidence-on-disk per issue (downgrades confidence to needs-validation if missing); applies 3 duplicate heuristics (exact-title, shared-evidence path, same-domain+flow+repro Levenshtein ≥0.8); transitions status:new → status:triaged with append-only history; AJV-validates every mutated record before atomicWrite; regenerates triage-report-<ts>.md + blockers.md + groups.md. CLI flags: --workspace, --cwd, --dry-run, --severity-override <ID>=<sev> (repeatable), --help. Idempotent: live runs against a stable corpus produce zero file mutations.
  • POSIX banner in install.sh (Quick 260506-h9q). New _print_banner() emits the same 9-line ASCII art as scripts/lib/banner.js BANNER_UNICODE_LINES; honors NO_COLOR (no ANSI when set), NO_UNICODE (#-art fallback), and non-TTY (no escape codes). Banner now renders on the curl-pipe path, matching the npx + git-clone + direct-script paths.
  • renderBanner wired into install.js, scripts/update.js, scripts/uninstall.js (Quick 260506-h9q). Previously only bin/testatlas.js (npx path) rendered the banner. All entry-points now consistent.
  • Production-grade release driver (Quick 260506-hqu). Refactored scripts/bump-version.js (770 LOC) is now a true one-liner: pre-flight gates (pnpm test + check-adapter-parity --strict + validate-workspace), CHANGELOG [Unreleased] → [X.Y.Z] body migration, atomic commit + annotated tag, git push origin <branch> + git push origin <tag>, gh release create vX.Y.Z --notes-file <CHANGELOG-extract> (NOT --generate-notes), optional --wait polls release.yml until OIDC publish + asset attachment completes (10-min timeout). Fires the existing release.yml workflow which handles npm publish via OIDC, sha256 + sigstore fetch, install.sh TARBALL_SHA256 sync, and asset attachment automatically.
  • docs/RELEASE.md "Local release driver" section (Quick 260506-hqu). Documents the canonical node scripts/bump-version.js --minor --release --wait flow + every flag with examples + OIDC vs bootstrap path tradeoff.

Changed

  • scripts/generate-report.js readiness verdict (Quick 260506-esm) now filters sortedIssues to status ∉ {closed, wont_fix} BEFORE the severity check. Previously counted closed issues toward CONDITIONAL verdict; now correctly reads READY when 0 critical+open AND 0 high+open. Closes ISSUE-029.
  • scripts/generate-report.js run dedup (Quick 260506-dyb G1). readTestRuns groups by RUN-<ts> stem; prefers .json sidecar; merges .md frontmatter as supplementary. Previously read each run twice (once via .md glob, once via .json glob), reporting 2 run(s) for 1 actual run.
  • scripts/generate-report.js per-domain coverage detection (Quick 260506-dyb G2). Walks r.parsed.scenariosRun[].domain instead of the (non-existent) top-level r.parsed.domain field. Previously claimed all domains uncovered; now correctly credits scenario coverage.
  • scripts/generate-report.js Test Pyramid type-classification (Quick 260506-dyb G3). Resolves scenario type via matching _testatlas/tests/scenarios/TEST-<id>.json sidecar. Previously emitted unknown: N bucket only; now reflects actual smoke/regression/state/negative/setup/integration/user-flow distribution.
  • scripts/generate-report.js autoheal parity (Quick 260506-esm). HEAL-01 now recomputes counts.reports alongside the other counts when re-deriving manifest from disk; previously only check-status-counts validated it but heal didn't fix mismatches.
  • .testatlas/commands/triage.md Preferred-path entry (Quick 260506-esm). Source command now declares node .testatlas/scripts/triage.js as the preferred-when-shell-available path, mirroring `create-...
Read more

v1.2.5

Choose a tag to compare

@CryptVenture CryptVenture released this 06 May 21:53

Changelog

All notable changes to this project will be documented in this file. Format is based on Keep a Changelog, and this project adheres to Semantic Versioning. Releases are managed via @changesets/cli.

[Unreleased]

Added

Changed

Removed

[1.2.5] - 2026-05-06

No notable changes since 1.2.4.

[1.2.4] - 2026-05-06

No notable changes since 1.2.3.

[1.2.3] - 2026-05-06

No notable changes since 1.2.2.

[1.2.2] - 2026-05-06

No notable changes since 1.2.1.

[1.2.1] - 2026-05-06

No notable changes since 1.2.0.

[1.2.0] - 2026-05-06

Changed

  • BREAKING — validate-workspace --auto-heal now applies by default (Quick 260506-nj2). The CLI flag previously required pairing with --apply to actually persist heals; users who ran --auto-heal alone saw "Would apply (N)" and (correctly) concluded nothing changed. The dual-flag UX caused real-world reports to be filed as "autoheal not working." With v1.2.0, bare --auto-heal writes to disk; pass --dry-run for preview. The --apply flag is now a documented no-op (kept parseable for back-compat) and emits a one-time stderr note when paired with --auto-heal. Migration: if you have CI / scripts that ran validate-workspace --auto-heal expecting preview-only behavior, add --dry-run to keep the old semantics. The programmatic validateWorkspace({autoHeal, apply, dryRun}) API is unchanged — only the CLI default flipped.
  • scripts/lib/adapters/render-mcp.js requires explicit version parameter (Quick 260506-nj2). The renderer previously hardcoded version: '1.0.0' regardless of project version, so every release shipped an mcp manifest claiming v1.0.0 (the parity-check refresh masked it locally per release). The renderer now throw new TypeErrors if version is omitted; scripts/assemble-adapter.js reads <workspace>/package.json#version and injects it, so the published mcp manifest correctly tracks the suite version (v1.2.0 ships "version": "1.2.0").

Fixed

  • High-severity — runUpdate now executes full adapter upgrade lifecycle for all 7 adapters (ISSUE-030; Quick 260506-mgr). Atomic-swap previously only renamed .testatlas/. Adapter outputs that live OUTSIDE the suite tree (.claude/commands/atlas-*.md for claude-code, .cursor/rules/*.mdc for cursor, AGENTS.md for opencode/generic, .aider/CONVENTIONS.md for aider, mcp-server config, kilo equivalents) were never re-emitted on update — every consumer-side update from v1.0.0 onward left those files at install-time bodies forever. regenerateInstallManifest walked only .testatlas/, dropping adapter files from the regenerated manifest and silently disabling drift detection + clean uninstall for them. v1.2.0 adds a restageAdapters helper invoked between tarball cleanup and manifest regen: re-emits all adapter command files from the new tarball via copyAdapterCommandFiles, prunes orphaned entries (files removed in vNext), honors manifest.mode === 'global', and includes the re-emitted entries in the regenerated manifest with correct type. Per-adapter try/catch — one bad adapter does not abort the rest. Action required for users on v1.0.0–v1.1.5: run npx @webventures/testatlas update --force-reinstall once after updating to v1.2.0 to refresh the adapter command files in your repo. Subsequent updates will refresh them automatically.
  • Reporter preview subtitle now appears under the section header (Quick 260506-nj2). When --auto-heal --dry-run is used (preview mode), the report previously only showed a per-row footer "Preview only" note. Users skimming the section header could miss the indicator. v1.2.0 adds a section-header subtitle directly under ### Would apply (N) so the preview-only state is unmissable. Footer wording updated from "re-run with --apply" to "re-run without --dry-run" to match the new flag semantics. No change when applied.length === 0 (nothing to preview).

Added

[1.1.5] - 2026-05-06

No notable changes since 1.1.4.

[1.1.4] - 2026-05-06

No notable changes since 1.1.3.

[1.1.3] - 2026-05-06

No notable changes since 1.1.2.

[1.1.2] - 2026-05-06

No notable changes since 1.1.1.

[1.1.1] - 2026-05-06

No notable changes since 1.1.0.

[1.1.0] - 2026-05-06

Added

  • Cosign + dogfood-test infrastructure (Quick 260506-07b). sigstore/cosign-installer@v3 (SHA-pinned) wired into .github/workflows/ci.yml so dogfood scenarios run against a real cosign install. New scripts/setup-dogfood-env.sh POSIX pre-flight probes for cosign + shellcheck + gh + sha256sum + tar + git + curl + jq + node ≥ 20; copy-paste install hints per missing binary; optional --install flag attempts non-interactive install on Linux.
  • CONTRIBUTING.md Dogfood Test Prerequisites section (Quick 260506-07b). Documents required binaries with version floors; tells contributors to run sh scripts/setup-dogfood-env.sh before /atlas:test-flow --all; notes CI installs these automatically.
  • NEW scenario TEST-install-cosign-absent-degrade (Quick 260506-07b). Verifies install.sh's fail-open default path: when TESTATLAS_VERIFY_SIGNATURE is unset and cosign is not on PATH, installer proceeds with sha256-only verification (exit 0). Sibling to TEST-install-cosign-verification-smoke (tamper-fail focus). Scenario count 25→26.
  • Per-area report views (Quick 260506-dyb G5). scripts/generate-report.js now emits _testatlas/reports/regressions.md, readiness.md, coverage.md, quality_risks.md from the same aggregation pass. Previously these were declared in the spec but never written.
  • counts.reports field in workspace-manifest.schema.json (Quick 260506-dyb G4). Optional integer ≥0 added additively (no migration required); HEAL-01 + check-status-counts updated to validate it; sync-status.js writes it from disk truth (_testatlas/reports/REPORT-*.md count).
  • scripts/triage.js accelerator (Quick 260506-esm). Production-grade idempotent triage driver mirroring scripts/create-issue.js shape. Loads all _testatlas/to_fix/ISSUE-*.json; verifies evidence-on-disk per issue (downgrades confidence to needs-validation if missing); applies 3 duplicate heuristics (exact-title, shared-evidence path, same-domain+flow+repro Levenshtein ≥0.8); transitions status:new → status:triaged with append-only history; AJV-validates every mutated record before atomicWrite; regenerates triage-report-<ts>.md + blockers.md + groups.md. CLI flags: --workspace, --cwd, --dry-run, --severity-override <ID>=<sev> (repeatable), --help. Idempotent: live runs against a stable corpus produce zero file mutations.
  • POSIX banner in install.sh (Quick 260506-h9q). New _print_banner() emits the same 9-line ASCII art as scripts/lib/banner.js BANNER_UNICODE_LINES; honors NO_COLOR (no ANSI when set), NO_UNICODE (#-art fallback), and non-TTY (no escape codes). Banner now renders on the curl-pipe path, matching the npx + git-clone + direct-script paths.
  • renderBanner wired into install.js, scripts/update.js, scripts/uninstall.js (Quick 260506-h9q). Previously only bin/testatlas.js (npx path) rendered the banner. All entry-points now consistent.
  • Production-grade release driver (Quick 260506-hqu). Refactored scripts/bump-version.js (770 LOC) is now a true one-liner: pre-flight gates (pnpm test + check-adapter-parity --strict + validate-workspace), CHANGELOG [Unreleased] → [X.Y.Z] body migration, atomic commit + annotated tag, git push origin <branch> + git push origin <tag>, gh release create vX.Y.Z --notes-file <CHANGELOG-extract> (NOT --generate-notes), optional --wait polls release.yml until OIDC publish + asset attachment completes (10-min timeout). Fires the existing release.yml workflow which handles npm publish via OIDC, sha256 + sigstore fetch, install.sh TARBALL_SHA256 sync, and asset attachment automatically.
  • docs/RELEASE.md "Local release driver" section (Quick 260506-hqu). Documents the canonical node scripts/bump-version.js --minor --release --wait flow + every flag with examples + OIDC vs bootstrap path tradeoff.

Changed

  • scripts/generate-report.js readiness verdict (Quick 260506-esm) now filters sortedIssues to status ∉ {closed, wont_fix} BEFORE the severity check. Previously counted closed issues toward CONDITIONAL verdict; now correctly reads READY when 0 critical+open AND 0 high+open. Closes ISSUE-029.
  • scripts/generate-report.js run dedup (Quick 260506-dyb G1). readTestRuns groups by RUN-<ts> stem; prefers .json sidecar; merges .md frontmatter as supplementary. Previously read each run twice (once via .md glob, once via .json glob), reporting 2 run(s) for 1 actual run.
  • scripts/generate-report.js per-domain coverage detection (Quick 260506-dyb G2). Walks r.parsed.scenariosRun[].domain instead of the (non-existent) top-level r.parsed.domain field. Previously claimed all domains uncovered; now correctly credits scenario coverage.
  • scripts/generate-report.js Test Pyramid type-classification (Quick 260506-dyb G3). Resolves scenario type via matching _testatlas/tests/scenarios/TEST-<id>.json sidecar. Previously emitted unknown: N bucket only; now reflects actual smoke/regression/state/negative/setup/integration/user-flow distribution.
  • scripts/generate-report.js autoheal parity (Quick 260506-esm). HEAL-01 now recomputes counts.reports alongside the other counts when re-deriving manifest from disk; previously only check-status-counts validated it but heal didn't fix mismatches.
  • .testatlas/commands/triage.md Preferred-path entry (Quick 260506-esm). Source command now declares node .testatlas/scripts/triage.js as the preferred-when-shell-available path, mirroring create-issue.md / generate-report.md patterns. 18 adapter trees ...
Read more

v1.2.4

Choose a tag to compare

@CryptVenture CryptVenture released this 06 May 21:27

Changelog

All notable changes to this project will be documented in this file. Format is based on Keep a Changelog, and this project adheres to Semantic Versioning. Releases are managed via @changesets/cli.

[Unreleased]

Added

Changed

Removed

[1.2.4] - 2026-05-06

No notable changes since 1.2.3.

[1.2.3] - 2026-05-06

No notable changes since 1.2.2.

[1.2.2] - 2026-05-06

No notable changes since 1.2.1.

[1.2.1] - 2026-05-06

No notable changes since 1.2.0.

[1.2.0] - 2026-05-06

Changed

  • BREAKING — validate-workspace --auto-heal now applies by default (Quick 260506-nj2). The CLI flag previously required pairing with --apply to actually persist heals; users who ran --auto-heal alone saw "Would apply (N)" and (correctly) concluded nothing changed. The dual-flag UX caused real-world reports to be filed as "autoheal not working." With v1.2.0, bare --auto-heal writes to disk; pass --dry-run for preview. The --apply flag is now a documented no-op (kept parseable for back-compat) and emits a one-time stderr note when paired with --auto-heal. Migration: if you have CI / scripts that ran validate-workspace --auto-heal expecting preview-only behavior, add --dry-run to keep the old semantics. The programmatic validateWorkspace({autoHeal, apply, dryRun}) API is unchanged — only the CLI default flipped.
  • scripts/lib/adapters/render-mcp.js requires explicit version parameter (Quick 260506-nj2). The renderer previously hardcoded version: '1.0.0' regardless of project version, so every release shipped an mcp manifest claiming v1.0.0 (the parity-check refresh masked it locally per release). The renderer now throw new TypeErrors if version is omitted; scripts/assemble-adapter.js reads <workspace>/package.json#version and injects it, so the published mcp manifest correctly tracks the suite version (v1.2.0 ships "version": "1.2.0").

Fixed

  • High-severity — runUpdate now executes full adapter upgrade lifecycle for all 7 adapters (ISSUE-030; Quick 260506-mgr). Atomic-swap previously only renamed .testatlas/. Adapter outputs that live OUTSIDE the suite tree (.claude/commands/atlas-*.md for claude-code, .cursor/rules/*.mdc for cursor, AGENTS.md for opencode/generic, .aider/CONVENTIONS.md for aider, mcp-server config, kilo equivalents) were never re-emitted on update — every consumer-side update from v1.0.0 onward left those files at install-time bodies forever. regenerateInstallManifest walked only .testatlas/, dropping adapter files from the regenerated manifest and silently disabling drift detection + clean uninstall for them. v1.2.0 adds a restageAdapters helper invoked between tarball cleanup and manifest regen: re-emits all adapter command files from the new tarball via copyAdapterCommandFiles, prunes orphaned entries (files removed in vNext), honors manifest.mode === 'global', and includes the re-emitted entries in the regenerated manifest with correct type. Per-adapter try/catch — one bad adapter does not abort the rest. Action required for users on v1.0.0–v1.1.5: run npx @webventures/testatlas update --force-reinstall once after updating to v1.2.0 to refresh the adapter command files in your repo. Subsequent updates will refresh them automatically.
  • Reporter preview subtitle now appears under the section header (Quick 260506-nj2). When --auto-heal --dry-run is used (preview mode), the report previously only showed a per-row footer "Preview only" note. Users skimming the section header could miss the indicator. v1.2.0 adds a section-header subtitle directly under ### Would apply (N) so the preview-only state is unmissable. Footer wording updated from "re-run with --apply" to "re-run without --dry-run" to match the new flag semantics. No change when applied.length === 0 (nothing to preview).

Added

[1.1.5] - 2026-05-06

No notable changes since 1.1.4.

[1.1.4] - 2026-05-06

No notable changes since 1.1.3.

[1.1.3] - 2026-05-06

No notable changes since 1.1.2.

[1.1.2] - 2026-05-06

No notable changes since 1.1.1.

[1.1.1] - 2026-05-06

No notable changes since 1.1.0.

[1.1.0] - 2026-05-06

Added

  • Cosign + dogfood-test infrastructure (Quick 260506-07b). sigstore/cosign-installer@v3 (SHA-pinned) wired into .github/workflows/ci.yml so dogfood scenarios run against a real cosign install. New scripts/setup-dogfood-env.sh POSIX pre-flight probes for cosign + shellcheck + gh + sha256sum + tar + git + curl + jq + node ≥ 20; copy-paste install hints per missing binary; optional --install flag attempts non-interactive install on Linux.
  • CONTRIBUTING.md Dogfood Test Prerequisites section (Quick 260506-07b). Documents required binaries with version floors; tells contributors to run sh scripts/setup-dogfood-env.sh before /atlas:test-flow --all; notes CI installs these automatically.
  • NEW scenario TEST-install-cosign-absent-degrade (Quick 260506-07b). Verifies install.sh's fail-open default path: when TESTATLAS_VERIFY_SIGNATURE is unset and cosign is not on PATH, installer proceeds with sha256-only verification (exit 0). Sibling to TEST-install-cosign-verification-smoke (tamper-fail focus). Scenario count 25→26.
  • Per-area report views (Quick 260506-dyb G5). scripts/generate-report.js now emits _testatlas/reports/regressions.md, readiness.md, coverage.md, quality_risks.md from the same aggregation pass. Previously these were declared in the spec but never written.
  • counts.reports field in workspace-manifest.schema.json (Quick 260506-dyb G4). Optional integer ≥0 added additively (no migration required); HEAL-01 + check-status-counts updated to validate it; sync-status.js writes it from disk truth (_testatlas/reports/REPORT-*.md count).
  • scripts/triage.js accelerator (Quick 260506-esm). Production-grade idempotent triage driver mirroring scripts/create-issue.js shape. Loads all _testatlas/to_fix/ISSUE-*.json; verifies evidence-on-disk per issue (downgrades confidence to needs-validation if missing); applies 3 duplicate heuristics (exact-title, shared-evidence path, same-domain+flow+repro Levenshtein ≥0.8); transitions status:new → status:triaged with append-only history; AJV-validates every mutated record before atomicWrite; regenerates triage-report-<ts>.md + blockers.md + groups.md. CLI flags: --workspace, --cwd, --dry-run, --severity-override <ID>=<sev> (repeatable), --help. Idempotent: live runs against a stable corpus produce zero file mutations.
  • POSIX banner in install.sh (Quick 260506-h9q). New _print_banner() emits the same 9-line ASCII art as scripts/lib/banner.js BANNER_UNICODE_LINES; honors NO_COLOR (no ANSI when set), NO_UNICODE (#-art fallback), and non-TTY (no escape codes). Banner now renders on the curl-pipe path, matching the npx + git-clone + direct-script paths.
  • renderBanner wired into install.js, scripts/update.js, scripts/uninstall.js (Quick 260506-h9q). Previously only bin/testatlas.js (npx path) rendered the banner. All entry-points now consistent.
  • Production-grade release driver (Quick 260506-hqu). Refactored scripts/bump-version.js (770 LOC) is now a true one-liner: pre-flight gates (pnpm test + check-adapter-parity --strict + validate-workspace), CHANGELOG [Unreleased] → [X.Y.Z] body migration, atomic commit + annotated tag, git push origin <branch> + git push origin <tag>, gh release create vX.Y.Z --notes-file <CHANGELOG-extract> (NOT --generate-notes), optional --wait polls release.yml until OIDC publish + asset attachment completes (10-min timeout). Fires the existing release.yml workflow which handles npm publish via OIDC, sha256 + sigstore fetch, install.sh TARBALL_SHA256 sync, and asset attachment automatically.
  • docs/RELEASE.md "Local release driver" section (Quick 260506-hqu). Documents the canonical node scripts/bump-version.js --minor --release --wait flow + every flag with examples + OIDC vs bootstrap path tradeoff.

Changed

  • scripts/generate-report.js readiness verdict (Quick 260506-esm) now filters sortedIssues to status ∉ {closed, wont_fix} BEFORE the severity check. Previously counted closed issues toward CONDITIONAL verdict; now correctly reads READY when 0 critical+open AND 0 high+open. Closes ISSUE-029.
  • scripts/generate-report.js run dedup (Quick 260506-dyb G1). readTestRuns groups by RUN-<ts> stem; prefers .json sidecar; merges .md frontmatter as supplementary. Previously read each run twice (once via .md glob, once via .json glob), reporting 2 run(s) for 1 actual run.
  • scripts/generate-report.js per-domain coverage detection (Quick 260506-dyb G2). Walks r.parsed.scenariosRun[].domain instead of the (non-existent) top-level r.parsed.domain field. Previously claimed all domains uncovered; now correctly credits scenario coverage.
  • scripts/generate-report.js Test Pyramid type-classification (Quick 260506-dyb G3). Resolves scenario type via matching _testatlas/tests/scenarios/TEST-<id>.json sidecar. Previously emitted unknown: N bucket only; now reflects actual smoke/regression/state/negative/setup/integration/user-flow distribution.
  • scripts/generate-report.js autoheal parity (Quick 260506-esm). HEAL-01 now recomputes counts.reports alongside the other counts when re-deriving manifest from disk; previously only check-status-counts validated it but heal didn't fix mismatches.
  • .testatlas/commands/triage.md Preferred-path entry (Quick 260506-esm). Source command now declares node .testatlas/scripts/triage.js as the preferred-when-shell-available path, mirroring create-issue.md / generate-report.md patterns. 18 adapter trees regenerated.
  • install.sh line budget raised 250→290 (...
Read more