v1.2.4
Changelog
All notable changes to this project will be documented in this file. Format is based on Keep a Changelog, and this project adheres to Semantic Versioning. Releases are managed via @changesets/cli.
[Unreleased]
Added
Changed
Removed
[1.2.4] - 2026-05-06
No notable changes since 1.2.3.
[1.2.3] - 2026-05-06
No notable changes since 1.2.2.
[1.2.2] - 2026-05-06
No notable changes since 1.2.1.
[1.2.1] - 2026-05-06
No notable changes since 1.2.0.
[1.2.0] - 2026-05-06
Changed
- BREAKING —
validate-workspace --auto-healnow applies by default (Quick 260506-nj2). The CLI flag previously required pairing with--applyto actually persist heals; users who ran--auto-healalone saw "Would apply (N)" and (correctly) concluded nothing changed. The dual-flag UX caused real-world reports to be filed as "autoheal not working." With v1.2.0, bare--auto-healwrites to disk; pass--dry-runfor preview. The--applyflag is now a documented no-op (kept parseable for back-compat) and emits a one-time stderr note when paired with--auto-heal. Migration: if you have CI / scripts that ranvalidate-workspace --auto-healexpecting preview-only behavior, add--dry-runto keep the old semantics. The programmaticvalidateWorkspace({autoHeal, apply, dryRun})API is unchanged — only the CLI default flipped. scripts/lib/adapters/render-mcp.jsrequires explicitversionparameter (Quick 260506-nj2). The renderer previously hardcodedversion: '1.0.0'regardless of project version, so every release shipped an mcp manifest claiming v1.0.0 (the parity-check refresh masked it locally per release). The renderer nowthrow new TypeErrors ifversionis omitted;scripts/assemble-adapter.jsreads<workspace>/package.json#versionand injects it, so the published mcp manifest correctly tracks the suite version (v1.2.0 ships"version": "1.2.0").
Fixed
- High-severity —
runUpdatenow executes full adapter upgrade lifecycle for all 7 adapters (ISSUE-030; Quick 260506-mgr). Atomic-swap previously only renamed.testatlas/. Adapter outputs that live OUTSIDE the suite tree (.claude/commands/atlas-*.mdfor claude-code,.cursor/rules/*.mdcfor cursor,AGENTS.mdfor opencode/generic,.aider/CONVENTIONS.mdfor aider, mcp-server config, kilo equivalents) were never re-emitted on update — every consumer-side update from v1.0.0 onward left those files at install-time bodies forever.regenerateInstallManifestwalked only.testatlas/, dropping adapter files from the regenerated manifest and silently disabling drift detection + clean uninstall for them. v1.2.0 adds arestageAdaptershelper invoked between tarball cleanup and manifest regen: re-emits all adapter command files from the new tarball viacopyAdapterCommandFiles, prunes orphaned entries (files removed in vNext), honorsmanifest.mode === 'global', and includes the re-emitted entries in the regenerated manifest with correcttype. Per-adapter try/catch — one bad adapter does not abort the rest. Action required for users on v1.0.0–v1.1.5: runnpx @webventures/testatlas update --force-reinstallonce after updating to v1.2.0 to refresh the adapter command files in your repo. Subsequent updates will refresh them automatically. - Reporter preview subtitle now appears under the section header (Quick 260506-nj2). When
--auto-heal --dry-runis used (preview mode), the report previously only showed a per-row footer "Preview only" note. Users skimming the section header could miss the indicator. v1.2.0 adds a section-header subtitle directly under### Would apply (N)so the preview-only state is unmissable. Footer wording updated from "re-run with--apply" to "re-run without--dry-run" to match the new flag semantics. No change whenapplied.length === 0(nothing to preview).
Added
[1.1.5] - 2026-05-06
No notable changes since 1.1.4.
[1.1.4] - 2026-05-06
No notable changes since 1.1.3.
[1.1.3] - 2026-05-06
No notable changes since 1.1.2.
[1.1.2] - 2026-05-06
No notable changes since 1.1.1.
[1.1.1] - 2026-05-06
No notable changes since 1.1.0.
[1.1.0] - 2026-05-06
Added
- Cosign + dogfood-test infrastructure (Quick 260506-07b).
sigstore/cosign-installer@v3(SHA-pinned) wired into.github/workflows/ci.ymlso dogfood scenarios run against a real cosign install. Newscripts/setup-dogfood-env.shPOSIX pre-flight probes for cosign + shellcheck + gh + sha256sum + tar + git + curl + jq + node ≥ 20; copy-paste install hints per missing binary; optional--installflag attempts non-interactive install on Linux. CONTRIBUTING.mdDogfood Test Prerequisites section (Quick 260506-07b). Documents required binaries with version floors; tells contributors to runsh scripts/setup-dogfood-env.shbefore/atlas:test-flow --all; notes CI installs these automatically.- NEW scenario
TEST-install-cosign-absent-degrade(Quick 260506-07b). Verifies install.sh's fail-open default path: whenTESTATLAS_VERIFY_SIGNATUREis unset and cosign is not on PATH, installer proceeds with sha256-only verification (exit 0). Sibling toTEST-install-cosign-verification-smoke(tamper-fail focus). Scenario count 25→26. - Per-area report views (Quick 260506-dyb G5).
scripts/generate-report.jsnow emits_testatlas/reports/regressions.md,readiness.md,coverage.md,quality_risks.mdfrom the same aggregation pass. Previously these were declared in the spec but never written. counts.reportsfield inworkspace-manifest.schema.json(Quick 260506-dyb G4). Optional integer ≥0 added additively (no migration required); HEAL-01 + check-status-counts updated to validate it;sync-status.jswrites it from disk truth (_testatlas/reports/REPORT-*.mdcount).scripts/triage.jsaccelerator (Quick 260506-esm). Production-grade idempotent triage driver mirroringscripts/create-issue.jsshape. Loads all_testatlas/to_fix/ISSUE-*.json; verifies evidence-on-disk per issue (downgrades confidence toneeds-validationif missing); applies 3 duplicate heuristics (exact-title, shared-evidence path, same-domain+flow+repro Levenshtein ≥0.8); transitionsstatus:new→status:triagedwith append-only history; AJV-validates every mutated record before atomicWrite; regeneratestriage-report-<ts>.md+blockers.md+groups.md. CLI flags:--workspace,--cwd,--dry-run,--severity-override <ID>=<sev>(repeatable),--help. Idempotent: live runs against a stable corpus produce zero file mutations.- POSIX banner in
install.sh(Quick 260506-h9q). New_print_banner()emits the same 9-line ASCII art asscripts/lib/banner.js BANNER_UNICODE_LINES; honorsNO_COLOR(no ANSI when set),NO_UNICODE(#-art fallback), and non-TTY (no escape codes). Banner now renders on the curl-pipe path, matching the npx + git-clone + direct-script paths. renderBannerwired intoinstall.js,scripts/update.js,scripts/uninstall.js(Quick 260506-h9q). Previously onlybin/testatlas.js(npx path) rendered the banner. All entry-points now consistent.- Production-grade release driver (Quick 260506-hqu). Refactored
scripts/bump-version.js(770 LOC) is now a true one-liner: pre-flight gates (pnpm test+check-adapter-parity --strict+validate-workspace), CHANGELOG[Unreleased]→[X.Y.Z]body migration, atomic commit + annotated tag,git push origin <branch>+git push origin <tag>,gh release create vX.Y.Z --notes-file <CHANGELOG-extract>(NOT--generate-notes), optional--waitpollsrelease.ymluntil OIDC publish + asset attachment completes (10-min timeout). Fires the existingrelease.ymlworkflow which handles npm publish via OIDC, sha256 + sigstore fetch, install.shTARBALL_SHA256sync, and asset attachment automatically. docs/RELEASE.md"Local release driver" section (Quick 260506-hqu). Documents the canonicalnode scripts/bump-version.js --minor --release --waitflow + every flag with examples + OIDC vs bootstrap path tradeoff.
Changed
scripts/generate-report.jsreadiness verdict (Quick 260506-esm) now filterssortedIssuestostatus ∉ {closed, wont_fix}BEFORE the severity check. Previously counted closed issues toward CONDITIONAL verdict; now correctly reads READY when 0 critical+open AND 0 high+open. Closes ISSUE-029.scripts/generate-report.jsrun dedup (Quick 260506-dyb G1).readTestRunsgroups by RUN-<ts>stem; prefers.jsonsidecar; merges.mdfrontmatter as supplementary. Previously read each run twice (once via .md glob, once via .json glob), reporting2 run(s)for 1 actual run.scripts/generate-report.jsper-domain coverage detection (Quick 260506-dyb G2). Walksr.parsed.scenariosRun[].domaininstead of the (non-existent) top-levelr.parsed.domainfield. Previously claimed all domains uncovered; now correctly credits scenario coverage.scripts/generate-report.jsTest Pyramid type-classification (Quick 260506-dyb G3). Resolves scenariotypevia matching_testatlas/tests/scenarios/TEST-<id>.jsonsidecar. Previously emittedunknown: Nbucket only; now reflects actual smoke/regression/state/negative/setup/integration/user-flow distribution.scripts/generate-report.jsautoheal parity (Quick 260506-esm). HEAL-01 now recomputescounts.reportsalongside the other counts when re-deriving manifest from disk; previously only check-status-counts validated it but heal didn't fix mismatches..testatlas/commands/triage.mdPreferred-path entry (Quick 260506-esm). Source command now declaresnode .testatlas/scripts/triage.jsas the preferred-when-shell-available path, mirroringcreate-issue.md/generate-report.mdpatterns. 18 adapter trees regenerated.install.shline budget raised 250→290 (Quick 260506-h9q) to accommodate the_print_bannershell function. Banner code itself was tightened to ~30 lines via inline color/unicode tests + printf loop.test/release/pack-contents.test.jsceiling raised 5MB→8MB (Quick 260506-dyb side-effect). Per-area views library + adapter regens nudged the pack size past the prior 5MB ceiling.scripts/sync-status.jstightened (Quick 260506-dyb side-effect) — reports counter now matchesREPORT-*.mdfiles only (excludes per-area views).- Bootstrap-token publish path deprecated in active workflow.
release.yml's OIDC path is now the canonical publish route since Trusted Publishing is configured at https://www.npmjs.com/package/@webventures/testatlas/access. The legacy NPM_TOKEN repo secret is no longer used; documented as "remove from repo secrets after first OIDC publish" indocs/RELEASE.md.
Notes
- Phase 9 + dogfood-loop work shipped at v1.0.0 (per Option A release decision on 2026-05-06). The original
[Unreleased]Phase 9 content (subagent-spawn capability, sub-agent orchestration on 4 umbrella commands + 11 sub-explorers, cross-reference integrity test, E2E pipeline harness, 18-adapter capability matrix, post-GA framing cleanup) effectively shipped in the v1.0.0 tag at commit8962859and is recorded under[1.0.0]. This[Unreleased]section tracks only post-v1.0.0 dogfood-loop work. - Dogfood loop closure (post-v1.0.0). The framework was tested end-to-end against itself:
/atlas:test-flow --allagainst the 26-scenario matrix (RUN-20260505T233506Z) produced 25 passes / 1 environmental block (publishing-release-provenance — unblocks at v1.1.0 via OIDC + sigstore). Six self-bugs surfaced + fixed + filed (ISSUE-024..029); zero observed-but-unrecorded bugs remain in the framework's own surface; readiness verdict naturally READY (0 blockers · 0 open critical/high · 5 open issues all medium/low/triaged). - Test count delta v1.0.0 → v1.1.0: 1071 → 1141 (+70 net new across 6 Quicks).
[1.0.0] - 2026-05-04
First production GA release. Closes Phase 8 (examples + auto-doc generators + GA polish) and consolidates everything from the 0.1.0-pre baseline through the v1 requirement set (98/98 Complete).
Added
- Bootstrap & Constitution (Phase 1):
.testatlas/bootstrap.mdconstitution under the 3000-word budget; capability-aware degradation rule; full config layer (default.config.json+config.schema.json+ project override). - Schemas & Templates (Phase 2): 18 JSON Schemas (Draft 2020-12) +
vocabulary.json; markdown templates for every workspace artifact; generated-section markers with defensive parser; atomic-write kernel. - Workspace skeleton (Phase 2):
_testatlas/with 14 canonical documents and 23 top-level subdirectories; manifest counts; lifecycle file conventions. - Commands (Phase 3+4): 30
/atlas:*commands covering init, validate, explore (×11 sub-explorers: ui, cli, api, codebase, runtime, data, docs, integrations, accessibility, performance, security), test (×10 types), issue lifecycle (log/triage/retest), reporting, lifecycle/handoff/cleanup. - Explorers, tests, issues, reports (Phase 4): 11 explorers + 10 test types + issue lifecycle + reporting. Domain-aware mapping;
confidence: needs-validationdiscipline. - Utility scripts (Phase 5): 12 utility scripts with shared
scripts/lib/(atomic-write, content-hash, slug, frontmatter parser, schema-loader, all-workspaces);validate-workspacecovers the full PRD §33 condition set;--auto-healrepair mode. - Adapters (Phase 6): 7 agent adapters (Claude Code canonical, Generic, OpenCode, KiloCode, Cursor, Aider, MCP) generated via
assemble-adapter.js; per-adapter capability matrix; adapter-parity CI gate. - Distribution (Phase 7): 3 install paths (
npx,install.sh,git clone); atomic update with backup + rollback; migration framework (forward-only, idempotent, N→N+1 with long-jump composition); workspace lockfile (PID + age dual stale detection);--verify-signatureopt-in cosign verification; cross-platform CI matrix (Linux/macOS/Windows × Node 20/22/24). - Examples (Phase 8): 5 example workspaces —
nextjs-saas(EX-01),node-api(EX-02),cli-toolAider-only (EX-03 + EX-07),monorepo(EX-04),mobile-web-hybrid(EX-05).scripts/regenerate-example.jsdeterministic-replay engine.example-script.schema.json(19th schema). CI matrix runsregenerate-example --check+validate-workspaceper example on every PR (closes EX-06 + VAL-02).--all-workspacesflag for monorepo orchestration. - Auto-generated docs (Phase 8):
docs/COMMANDS.md(auto-generated from.testatlas/commands/*.md, 30 sections, drift-detected in CI);docs/SCHEMAS.md(auto-generated from.testatlas/schemas/*.schema.json, 19 sections);examples/README.mdgallery;docs/MONOREPO.mddocumenting the hybrid pattern; final GA README structure. - Pre-flight checks (Phase 8):
scripts/check-org-placeholder.jsgreps for the literal angle-bracketedorgplaceholder string and exits non-zero if any are found in active code (excludesnode_modules,.git,.planning,dist,build,coverage,.next,.expo,.testatlas.bak.*). - Phase 9 — Agentic Workflow Completeness Audit + Sub-Agent Orchestration. Closes the post-v1.0 agentic completeness work surfaced after GA across 5 plans (09-01 through 09-05).
subagent-spawncapability vocabulary entry (6th entry; locked) — declared invocabulary.json$defs/capabilityand consumed bycommand-instruction.schema.jsonandadapter-capabilities.schema.jsonvia$ref.bootstrap.mdCapability Degradation block + per-host invocation table covering all 18 adapters with their canonical 2026 sub-agent invocation pattern.## Sub-Agent Orchestrationblocks on the 4 umbrella commands (/atlas:explore,/atlas:plan,/atlas:test-flow,/atlas:consolidate) — parallel sub-agent spawning when host capability is available, sequential-fallback otherwise.## Sub-Agent Task Brief Contractsections on the 11 sub-explorer commands so they work both as parallel children of an umbrella and as standalone slash invocations.## What's Nexttail navigation on all 30 command files +README.md+docs/GETTING_STARTED.md+docs/INSTALL.md+docs/UPDATE.md.- Cross-reference integrity test (
test/agentic/cross-reference-integrity.test.js) gating the test suite — every/atlas:NAMEmention, every relative.mdlink, every schema$idURL must resolve to a real file on disk. - E2E pipeline harness
scripts/e2e/run-node-api-graph.jsexercising the full command graph (init → explore → map-domains → plan → test-flow → report) in bothparallel-subagentsandsequential-fallbackmodes againstexamples/node-api/. Companion env-gated tests (TESTATLAS_E2E=1) attest/agentic/e2e-pipeline.test.js.
Changed
- First production release. The previous
0.1.0baseline (Phase 7 closure) is collapsed into this1.0.0entry — every artifact landed by Phases 1–7 is part of the v1.0.0 surface. package.json#version:0.1.0→1.0.0. The repo also collapsed the prior0.1.0-preand0.1.0markers;1.0.0is the first version that ships to npm.- The angle-bracketed GitHub-org placeholder (the pre-GA stand-in) finalized to
testatlas-devacrosspackage.json,install.sh,install.js,scripts/lib/constants.js,scripts/lib/update-check.js, README, and the docs gallery. - 9 adapters now declare
subagent-spawnin.testatlas/adapters/adapter-capabilities.json(claude-code, opencode, kilocode, codex, gemini-cli, github-copilot, cline, kiro, sourcegraph-amp). The other 9 (cursor, continue-dev, aider, generic, mcp, windsurf, roo-code, zed, amazon-q) remain documented as no-spawn (sequential-fallback only). .testatlas/templates/canonical/03_execution_status.md"Next Highest-Value Steps" rewritten to use the canonical command graph (/atlas:explore→/atlas:map-domains→/atlas:plan) instead of legacy never-implemented command names that previously appeared there.- Eight explorer/map-domains commands updated to reference the canonical
01_system_map.mdinstead of the never-bootstrapped01_app_inventory.md.
Removed
- All "Phase X ships this", "(deferred to v2)", "(coming in Phase X)", and "Phase X not yet installed" framings from tracked
.mdcontent. Post-v1.0 framing is now consistent acrossREADME.md, the 12docs/*.md, the 30 command files, and the 18 adapter trees.
Notes
- npm publish via Trusted Publisher (OIDC). First publish (v1.0.0) uses a one-shot
NPM_TOKEN(granular access token, package-scoped, 7-day expiry) because Trusted Publishing requires the npm package to exist before a trust relationship can be declared. After v1.0.0 lands, the maintainer configures Trusted Publishing at https://www.npmjs.com/package/testatlas/access and revokes the bootstrap token. v1.0.1+ uses OIDC only. Seedocs/RELEASE.md§ "Trusted Publisher (one-time setup)" for the full chicken-and-egg path. - GitHub Releases tarball includes cosign sigstore sidecar (
.tgz.sigstore.json) per UPDATE-07.--verify-signatureopt-in flag triggers cosign attestation verification at install/update time. - Examples are NOT shipped in the npm tarball.
package.json#filesis a positive whitelist (bin/,install.js,install.sh,scripts/,.testatlas/,package.json,README.md,LICENSE,CHANGELOG.md);examples/lives in the GitHub repo only.
Schema migration
- None. v1.0.0 is the baseline
schemaVersion: 1. The first migration (schemaVersion: 1 → 2) arrives with a future minor or major release.
Security
- npm publish via Trusted Publishing (OIDC); SLSA Build L3 provenance via
--provenance. - GitHub Releases ship signed sigstore bundle as sidecar (
testatlas-1.0.0.tgz.sigstore.json). - Two-tree invariant enforced:
update.jswrites only to.testatlas/(suite swap); never touches_testatlas/content except via explicit migrationup()functions. - POSIX
install.shpartial-pipe protection via_main "$@"sentinel pattern. - Default verification path is
npm audit signatures(zero-install);--verify-signatureopts intocosign verify-blob-attestationwithcertificate-identity-regexppinned to the canonical release workflow on a tagged release.
[0.1.0] - 2026-05-04
First public-ready cut of TestAtlas. Phase 0–7 complete; Phase 8 (examples + GA publish) follows.
Added
npx testatlas initone-liner (Plan 07-01) with adapter auto-detection (.claude/,.cursor/,.aider.conf.yml,kilocode/,.opencode/,mcpsignals);--all-adaptersflag installs all 7.- POSIX
install.shcurl-pipe installer (Plan 07-02), <200 lines, shellcheck-clean, partial-pipe sentinel (_main "$@"last-line idiom). git clone && node install.js <target>offline-capable install path.node uninstall.js(--purge,--force-untracked,--dry-run); preserves_testatlas/by default; manifest-driven precision.- 18th JSON Schema:
install-manifest.schema.json(Draft 2020-12) tracks every installed file with content hash. node update.jsatomic self-update (Plan 07-03): stage → migrate → swap → backup → prune; rollback on failure; SIGINT-safe.- Migration framework: forward-only, idempotent, N→N+1 with long-jump composition. v0.1.0 ships with no migrations; framework ready for v0.2.0+.
- Workspace lockfile (
_testatlas/.lock): PID + age dual stale detection. - GitHub Releases auto-check (Plan 07-04): configurable TTL (default 24h), offline-tolerant, rate-limit-aware.
- Version pinning + stale-pin warnings:
pinnedVersion,pinnedSince,pinAlertThresholdDaysconfig fields. --verify-signatureopt-in cosign attestation verification.- Cross-platform CI matrix: Linux/macOS/Windows × Node 20.x/22.x/24.x.
- Phase 7 release pipeline (
.github/workflows/release.yml): npm Trusted Publishing (OIDC) + provenance + post-publish install.sh sed-and-commit + GitHub Release sigstore sidecar attach + workflow_dispatch dry-run trigger. - DIST-01 docs gallery: README install section, docs/INSTALL.md, docs/UPDATE.md, docs/UNINSTALL.md, docs/SIGNING.md, docs/LTS.md, docs/RELEASE.md.
- Phase 0–6 deliverables (already complete in earlier phases): governance + bootstrap + workspace skeleton + 30 commands + 7 adapters + utility scripts + validation gates.
Changed
package.json: flippedprivate: true→ removed; bumpedversion0.1.0-pre→0.1.0; addedpublishConfig: { access: "public", provenance: true }.- Existing config schema: added
pinnedSince(date-time) andpinAlertThresholdDays(default 90). .github/workflows/release.yml: replaced skeleton with full pipeline (workflow_dispatch dry-run + release:published trigger + post-publish install.sh sync + sigstore sidecar attach).
Schema migration
- None. v0.1.0 is the baseline
schemaVersion: 1. First migration arrives at v0.2.0.
Security
- npm publish via Trusted Publishing (OIDC); SLSA Build L3 provenance via
--provenance. - GitHub Releases ship signed sigstore bundle as sidecar (
testatlas-<VERSION>.tgz.sigstore.json). - Two-tree invariant enforced:
update.jswrites only to.testatlas/(suite swap); never touches_testatlas/content except via explicit migrationup()functions. - POSIX
install.shpartial-pipe protection via_main "$@"sentinel pattern. - Default verification path is
npm audit signatures(zero-install);--verify-signatureopts into cosign verify-blob-attestation with certificate-identity-regexp pinned to the canonical release workflow.