Repository navigation
0.8.0 — 2026-09-28
A minor release because three published crates changed public types that a
dependent can match on or construct:
whipplescript-store:NormCommand,NormCommandResult,
NormReferenceRoleandResourceGapKindgained variants;
NormCommandResult::ActivationPlannedgainedeffects;NormVocabulary
gainedconstraintanddeployment;NormChartergainedcanonicalizers.whipplescript-kernel:AdmissionDoorgainedDeploy,RequirementImpact
gainedceiling,ProjectionGap::ExecutionUnavailablegainedrequirement,
norm_buck2_tests::test_reportandnorm_buck2_tests::judgetake a fourth
parameter,norm_projection::EvidenceProjection::capturetakes a type
parameter, andnorm_admission::AdmissionHostis nowCopy.whipplescript:host_runtime::ModelScanWitnessgaineddirectories.
Code that matches those enums without a wildcard arm, builds those structs with
a literal, calls those functions, or casts those enums to integers must follow
the change. The command line, stored data and configuration stay compatible:
nothing a whip user does needs to change.
Added
- The misuse log. Each invocation whip refuses with exit status 2 — an
unknown command, an unknown option, a missing argument — adds one JSON line
to~/.local/state/whipplescript/misuse.jsonl, so the commands people and
agents expect can be counted and the command surface improved from them.
Arguments that can hold a secret are written as<redacted>, and the log
never leaves the machine.WHIPPLESCRIPT_MISUSE_LOGnames another path, or
offkeeps no log.
Changed
- A malformed
whip issueorwhip assertsays what was wrong. Every
mistake used to print the command's whole usage line — forty alternatives
forwhip issue— and nothing else. The refusal now names the problem
(missing <id>,unknown option `--queue`, a tracker passed toready
as--tracker), shows the usage of that one subcommand, and for an unknown
subcommand suggests the nearest, including the verbs other trackers use
(closeforfinishorcancel). The exit status is still 2.
Fixed
- Closing a tracker item no longer leaves empty workspace stores behind.
whip issue finishopened the versioned-workspace stores to attest the
work's cut trail, and opening creates them, so every checkout an item was
closed from gained an untracked.whipplescript/branches.sqliteand
vcs-content.sqlite.issue finish,issue show --json,assertand a
keyedattestnow open them only where they already exist.
Verifying this release
Built on GaugeWright's own fleet. Every file's SHA-256 is in
whipplescript-0.8.0.intoto.json, signed with the key in
docs/release-provenance.pub:
minisign -V -p release-provenance.pub -m whipplescript-0.8.0.intoto.json