Releases: IvoryCanvas/QAMap
Release list
v0.4.16
QAMap 0.4.16 tightens deterministic QA evidence boundaries, release validation, and public packaging.
Added
- Added a complete public brand asset inventory with editable masters, app and web icons, social cards, and dedicated light and dark plugin artwork.
- Added exact diff evidence and measurable QA contracts for changed rendering work, image request priority, deferred modules, initial HTML and hydration, font loading, and delivery cache policy.
- Added bounded OpenAPI and Swagger response-example parsing as the authoritative source for generated local JSON response scaffolds.
Changed
- Release-focused changes prefer a repository-declared non-publishing validation gate and avoid repeating commands already covered by that gate.
- Network evidence can route affected behavior and QA, but repository types, schemas, UI copy, and fixture keys no longer authorize invented response values.
- Refreshed the README, skill, plugin, GitHub preview, and reusable brand assets around one production-ready visual identity.
Fixed
- Performance-focused changes no longer stop at a generic screen flow when the changed hunk supports a measurable runtime or delivery contract.
- Changed endpoint implementations are observed instead of intercepted, while schemas or status codes without concrete response examples remain explicit evidence gaps.
- Publishing, tagging, pushing, and deployment scripts are never promoted as automatic release validation.
- Working-tree-only release changes no longer inherit test contracts from an earlier target-branch commit outside the active comparison.
Validation
- 429/429 tests passed
- 37/37 static recommendation contracts passed
- 10/10 context checks passed
- 3/3 execution contracts passed and caught all three seeded regressions
- Agent benchmark dry-run contract passed without an external provider call
- Scan completed with zero findings
- Coverage thresholds passed; two consecutive runs measured 90.69-90.73% lines, 87.13-87.21% branches, and 95.97% functions
- Plugin isolated-install smoke and 207-file package preview passed
The GitHub Action can be pinned to IvoryCanvas/QAMap@v0.4.16. Generated scenarios and drafts remain not-run until an explicit execution action produces a receipt.
v0.4.15
QAMap 0.4.15 adds a bounded path from evidence-backed QA scenarios to explicit local execution while improving static risk and repository-validation selection.
Added
- Added
qamap e2e run <scenario-id>with repository-declared executors, fixtures, assertion receipts, timing, failure-only artifacts, and rerun comparison. - Added account-scoped storage evidence and account-switch QA for writes without an owner discriminator.
- Added divergent-copy evidence for related user-facing surfaces.
- Added an opt-in provider-neutral agent token benchmark with a deterministic offline release contract.
Changed
- Repository-validation routes preserve every applicable changed test and benchmark command while
qamap qa runretains its single-command boundary. - Shared benchmark fixture setup now uses one materialization helper.
Fixed
- Independent feature commits no longer merge merely because they edit the same analyzer file.
- Identifier matching respects symbol boundaries, preventing names such as
requireDirectoryfrom becoming redirect scenarios.
Validation
- 412/412 tests passed
- 35/35 static recommendation contracts passed
- 10/10 context checks passed
- 3/3 execution contracts passed and caught all three seeded regressions
- Agent benchmark dry-run contract passed without an external provider call
- Coverage: 90.70% lines, 87.15% branches, 95.99% functions
- Plugin isolated-install smoke and 198-file package preview passed
The GitHub Action can be pinned to IvoryCanvas/QAMap@v0.4.15. Generated scenarios and drafts remain not-run until an explicit execution action produces a receipt.
v0.4.14
QAMap 0.4.14 strengthens the path from a pull request diff to the evidence a reviewer or coding agent should trust before optional E2E work.
Added
- Detects delivery-integrity risks such as referenced assets that are missing from the committed change and validation commands that can rewrite shared history.
- Traces supported runtime activation changes across guards, configuration sources, side effects, and restart, reload, or deployment boundaries.
- Separates stable repository QA facts from the current pull request delta through the versioned
qamap.contextcontract. - Adds a deterministic, provider-neutral benchmark for context identity, reuse, invalidation reasons, and compact payload size.
Changed
- Keeps independent behavior-bearing commits separate when broad package vocabulary is their only connection.
- Treats removed UI as an absence contract rather than an executable entry point.
- Keeps formatting-only UI changes contextual while preserving real React and Vue state transitions.
- Aligns the npm package, CLI, native plugin manifests, portable skill, changelog, and submission metadata on
0.4.14.
Validation
- 382/382 tests passing
- 0 scanner findings
- 33/33 static recommendation contracts passing
- 10/10 context identity and reuse checks passing
- 3/3 execution contracts passing with all seeded regressions caught
- Coverage: 90.30% lines, 87.06% branches, 95.80% functions
- Published package smoke verified from
@ivorycanvas/qamap@0.4.14 - 195 files in the npm package
GitHub Actions users can pin this release with uses: IvoryCanvas/QAMap@v0.4.14.
QAMap still treats static scenarios and generated drafts as not-run until an explicit validation action is executed. The OpenAI Plugin Directory update remains a separate review and publication step.
v0.4.13
QAMap 0.4.13 improves the path from repository evidence to the validation a reviewer should actually trust.
Added
- Traces supported React and Next.js runtime prerequisites through bounded local imports, fail-fast context contracts, and provider wrappers.
- Detects newly divergent Django migration graph leaves and routes them to repository-owned graph validation.
- Adds separate English and Korean documentation entry points and a Korean product cover.
- Adds public positive and negative benchmark controls for runtime prerequisites and benchmark-path routing.
Changed
- Keeps target-branch merge history out of feature intent while preserving the branch's own work.
- Preserves package working directories and routes repository documentation, workflow metadata, and analyzer changes to their exact validation contracts.
- Keeps mocked consumers from becoming sufficient proof of a runtime prerequisite.
- Aligns the npm package, CLI, native plugin manifests, portable skill, changelog, and submission metadata on
0.4.13.
Validation
- 356/356 tests passing
- 0 scanner findings
- 30/30 static recommendation contracts passing
- 3/3 execution contracts passing; all seeded regressions caught
- Coverage: 89.68% lines, 86.75% branches, 95.73% functions
- Published package smoke verified from
@ivorycanvas/qamap@0.4.13 - 192 files in the npm package
GitHub Actions users can pin this release with uses: IvoryCanvas/QAMap@v0.4.13.
The OpenAI Plugin Directory remains on its separately reviewed 0.4.12 version until the 0.4.13 plugin package is uploaded, reviewed, and published.
v0.4.12
QAMap 0.4.12 improves the first-run QA reasoning path and makes the published OpenAI plugin easier to install.
Changed
- Makes the OpenAI Plugin Directory installation path explicit on the README first screen.
- Uses commit scope and subject to isolate change intent instead of allowing repeated body prose to merge unrelated work.
- Keeps cleanup-only commits as provenance without creating standalone QA scenarios.
- Documents provenance-only intent and observable-proof gaps for human and agent consumers.
Fixed
- Prevents cleanup-only changes from re-entering QA through generic fallbacks.
- Prevents raw helper names, side-effect names, and scenario-title echoes from becoming observable proof.
- Prevents unrelated lifecycle stages from joining through broad transitive vocabulary.
Validation
- 330/330 tests passing
- 0 scanner findings
- All static recommendation contracts passing
- 3/3 execution contracts passing
- Coverage: 89.73% lines, 86.46% branches, 95.70% functions
- Published package smoke verified from
@ivorycanvas/qamap@0.4.12 - 172 files in the npm package
GitHub Actions users can pin this release with uses: IvoryCanvas/QAMap@v0.4.12.
The OpenAI Plugin Directory remains on its separately reviewed version until the replacement plugin package is submitted and approved.
v0.4.11
Summary
QAMap 0.4.11 improves cross-repository QA precision and ships the reproducible package needed for a skills-only official plugin review. It fixes false scheduling scenarios from calendar UI vocabulary, adds event timing/payload/duplication checks for instrumentation changes, and keeps repository configuration on its existing validation route.
Highlights
- Added a skills-only submission package with three starter prompts, five positive evaluations, three negative controls, legal/support documents, and canonical brand assets.
- Added isolated pack-and-install smoke validation for the published CLI and agent handoff.
- Added domain-neutral calendar and instrumentation benchmarks, bringing the recommendation corpus to 27 targets.
- Secured compact agent recovery reports with owner-only, exclusive temporary files and stale-report cleanup.
- Stopped
.githubissue templates containingrequestfrom becoming fabricated API flows. - Kept repository-validation changes from advertising unrelated product automation as the next action.
Validation
- 315/315 tests passing
- 27/27 static recommendation contracts passing
- 3/3 seeded-regression execution contracts passing
- 0 QAMap scan findings
- Coverage: 89.65% lines, 86.30% branches, 95.66% functions
- Published-package execution confirmed for
@ivorycanvas/qamap@0.4.11 - Official skill and plugin structural validators passing
Install
npx --yes @ivorycanvas/qamap@0.4.11 qaGitHub Actions and repository integrations can pin this release as v0.4.11.
The included skills-only plugin metadata is a submission candidate. This release does not imply approval or availability in the official Plugins Directory.
v0.4.10
QAMap 0.4.10 makes the first QA decision easier to read without hiding the reasoning path.
Highlights
qamap qanow opens with a concise terminal summary of changed behavior, required proof, exact diff evidence, routing status, and the next action. Use--format markdownfor the complete trace.- Parser, serializer, mapper, converter, normalizer, codec, and transformer changes now receive input-to-output verification contracts instead of invented API, authentication, visual, or product E2E requirements.
- The README now starts with a 60-second workflow and one compact GIF recorded from actual CLI output. Obsolete recordings were removed.
- Contributor guidance and issue templates now turn missed risks, false positives, wrong evidence, and unusable drafts into safe, minimized regression cases.
Validation
- 308 tests passed
- 25 static recommendation contracts passed
- 3 seeded-regression execution contracts passed
- 0 scanner findings
- Coverage: 89.64% lines, 86.32% branches, 95.66% functions
Install or run directly:
npx --yes @ivorycanvas/qamap@0.4.10 qaSee the changelog and release validation for the complete evidence.
v0.4.9
Added
- Added explicit QA knowledge authority (
team-policy,repository-contract, orqamap-inference) and harness test classes (golden,regression, oredge) to human reports, agent handoffs, and the additive v1 schema. - Added a working-tree-only current delta that isolates uncommitted files and changed test contracts from older branch history.
- Added an evidence-gated validation-recovery compiler. When a diff-backed form timing change connects to a route, validated input, visible error, submit action, and visible success result, QAMap now compiles both a valid submission path and an invalid-input, correction, and stale-error recovery scenario.
- Added a third seeded-regression execution contract that requires the byte-identical generated browser artifact to fail when corrected input leaves stale validation feedback and pass when first-touch revalidation is restored.
- Added native Codex and Claude Code plugin manifests that expose the existing vendor-neutral
qamap-pr-qaskill without duplicating the local analysis engine. - Added Codex skill presentation metadata and a plugin contract test that keeps both host manifests, the npm package, and the shared skill version aligned.
- Added multi-commit benchmark fixtures: a target can declare ordered
commitsoverlays instead of a singlehead/snapshot, and amustNamePrimaryIntentexpectation pins which intent must rank first. A new cleanup-tip fixture materializes a feature commit followed byfix: minor refactorand requires the feature to stay in the headline, flow title, and draft filename. - Added
restoredto the visible success-outcome vocabulary so standard "restored to defaults" confirmations qualify as diff-anchored success signals, matching the existing completed-state words such asupdatedandarchived.
Changed
- Newer independent change intents and current local test commands now rank ahead of stale branch history, while the complete branch remains available for wider impact analysis.
- Latest-commit diff evidence is reserved before the bounded branch-wide scan, preventing a large accumulated PR from hiding the current behavior and its test contracts.
- Agent payload compaction preserves current-delta evidence and authority metadata on retained flows while remaining below the 4KB contract.
- Form validation timing detection now reads the changed hunk and uses word-bounded form context, preserving framework-neutral React and Vue cases without treating unrelated format-mode vocabulary as product validation QA.
- The agent skill now converts
route.nextActioninto exactly one immediate action and reports later command execution separately from QAMap's staticnot-runreceipt. qamap init --agentnow installs the complete skill bundle, including optional host metadata, while continuing to preserve locally modified skill files unless--forceis explicit.- QA handoffs now prefer test contracts changed by the current PR over broader historical filename or keyword matches, while keeping unrelated changed tests out of individual flow evidence.
- Safely recognized npm, pnpm, and Yarn workspaces now place one behavior-linked changed-test command per affected package before the unchanged package suites. Ambiguous custom pipelines remain suite-wide.
- Automatically selected package commands now include the package directory, so copied commands execute from the workspace root instead of depending on an unstated working directory.
- Unrelated feature tests no longer attach to a flow merely because both paths contain generic structural words, and standalone nested packages with their own lockfile can route changed contracts to their package suite.
- Changed-test contract extraction now ignores test-like source strings embedded inside fixture builders instead of reporting them as executable repository tests.
- Compact agent handoffs now retain one repository test-evidence path for secondary affected flows instead of dropping that trace during the 4KB payload reduction.
Fixed
- Symbol-derived lifecycle labels now read behaviorally instead of exposing raw identifiers. Setter-derived state changes phrase the target ("Update the form error state." instead of "Update state through form.setError."), and side effects, outcomes, and other calls that cannot be phrased naturally mark the identifier as code with backticks ("Invoke
fetch."). Exact symbols remain on each stage and its evidence, and implementation-stage classification now keys on the structural symbol instead of parsing the label text. - Issue-tracker tags such as
[ABC-123]in commit subjects now survive exactly once, in the intent title, instead of repeating through every derived lifecycle label, assertion, and success signal. Subjects that lead with a tag ([ABC-123] fix: …) now also parse as conventional commits instead of falling back to raw-subject heuristics. - Two-letter all-lowercase directory segments (
ee,ui,db) keep their acronym form in derived flow, domain, and test-plan names instead of producing labels like "Ee". Longer segments are untouched because three-letter directories are often plain words. - Success signals no longer restate the flow title as their own proof. When no diff-anchored observable outcome exists, the flow says so explicitly ("no diff-anchored observable outcome was extracted from this change — define the expected user-visible result manually"), the review question asks what the outcome should be, fallback draft steps ask to define the signal instead of asserting the gap statement, and the machine-readable brief carries
successSignalUnresolved: true. Concrete diff-anchored signals are unchanged. - Compacted agent payloads no longer emit partial identifier values. Draft paths, changed files, existing evidence, selectors, entry hints, and commands stay whole at every compaction stage; an oversized payload drops whole optional values — disclosed through the existing omitted counts — instead of truncating a path the consuming agent could not open.
base,head, andmanifeststay whole up to 256 characters. The previously undocumentedfloorandhardLimitcompaction flags are now part of the documented schema. qamap qa --format agentnow writes the pre-compaction summary to a temp file and discloses it ascompaction.fullReport(additive v1 field), so an agent can recover omitted traces, scenarios, and flows without re-running the analysis. The analyzed repository stays untouched; the library exportformatAgentQaFullReportproduces the same document.- Fixed change-intent review ranking so a cleanup-shaped tip commit (for example
fix: minor refactororfix: tidy up and add tests) no longer displaces the branch's substantive intent from the headline, scenario names, and generated draft filenames. Cleanup-only intents are demoted below substantive intents but never dropped, and pure-cleanup branches keep their newest intent first. Observed on real public PR branches, where review-feedback commits routinely close a branch.
v0.4.8
QAMap v0.4.8 strengthens the path from a PR diff to traceable QA evidence and optional executable checks. The release adds opt-in symbol context, portable agent-skill installation, and CI-enforced execution contracts that prove generated artifacts can catch known regressions.
Added
- Added optional JS/TS symbol QA annotations through
@qamapFlow,@qamapStage,@qamapOutcome, and@qamapRisk. QAMap applies them only when the attached named export overlaps the diff, preserves the changed line as routing evidence, and reports malformed or stale annotations instead of silently trusting them. - Added an evidence-gated repeated-action compiler. QAMap emits a runnable duplicate-request check only when the selected scenario, user action, request boundary, route, and visible outcome are connected by repository evidence.
- Added committed execution benchmarks that generate browser specs once, require them to fail against seeded repeated-action and persisted-state regressions for the intended assertions, and require the same byte-identical artifacts to pass against their fixes.
- Added portable project-skill installation through
qamap init --agentfor.agents/skillsand explicit compatibility paths, while preserving local edits unless--forceis requested. - Added a domain-neutral two-surface React benchmark and per-flow compilation contracts. A benchmark can now require every affected flow to retain a primary scenario receipt, mapped action, mapped assertion, and fully compiled draft independently.
- Added deterministic trace evidence dispositions for confirmed causal chains, missing source locations, and failed behavior joins. Human and machine output now count unique sources instead of treating repeated citations as stronger evidence.
- Added human-approved manifest correction proposals to QA traces. A wrong judgment points to an existing flow anchor or a concrete repo-local flow target even when no automation artifact exists yet.
Changed
- The README demo now uses a committed runnable application and real generated tests, and the release gate verifies both its green result and its ability to catch the seeded defect.
- Agent setup uses the packaged vendor-neutral
qamap-pr-qaskill as its single workflow source. Future editor or plugin wrappers are documented as thin consumers of the same local CLI and versioned agent contract. - Repository test planning and changed-file inspection code now stays on the analyzer-verification path when direct product behavior evidence is absent. Supporting utility conditions no longer turn an analyzer-focused change into product automation work.
- Primary intent scenarios now retain located diff evidence alongside commit and lifecycle context. When a commit phrase and a code signal describe the same behavior, their provenance is merged instead of discarding the source hunk.
- Multi-flow reasoning traces and compact agent output now aggregate every artifact for the same logical scenario and disclose
flowCoverage. A compiled draft on one surface can no longer hide a partial or unmapped draft on another. - Compact agent output preserves evidence-gap counts and the highest-priority manifest correction target through emergency 4KB compaction.
Fixed
- Static matcher vocabulary, CI environment variable names, and background-service labels no longer fabricate scheduling, navigation, or conditional UI QA. Actual product scheduling and destination changes remain covered by the existing positive benchmark contracts.
- Package root or public API exports no longer imply network timeout and retry QA without network behavior evidence.
- Analyzer-focused changes no longer borrow unrelated mock handlers or fixture endpoints from benchmark and test directories as product E2E guidance.
- Repository and Git context analyzers no longer surface implementation guards such as numeric finiteness checks as affected product lifecycle stages.
- Repository-validation routes no longer report missing product E2E compilation as a required scenario gap when automation is explicitly not applicable.
- Analyzer reasoning traces, including emergency 4KB agent output, now retain the concrete false-negative and false-positive risk instead of falling back to a generic product outcome regression.
- Surface-scoped primary scenarios no longer fall back to review-only when their flow has direct diff evidence, and abstract commit phrases such as refreshing an affected state no longer become fake user actions in generated E2E code.
Validation
250/250tests passed.22/22static recommendation contracts passed.2/2execution contracts passed and caught two seeded regressions with byte-identical generated artifacts.- Repository scan reported
0findings. - Coverage: lines
89.29%, branches85.91%, functions95.76%. - npm package preview and public publish completed for
@ivorycanvas/qamap@0.4.8.
The GitHub Action can now be pinned to IvoryCanvas/QAMap@v0.4.8.
v0.4.7
Summary
QAMap 0.4.7 strengthens the path from a PR diff to traceable QA decisions and optional executable evidence.
- Resolves the effective PR base from explicit input, CI metadata, repository configuration, and Git history, then discloses the chosen evidence.
- Separates the complete QA risk map from evidence that can be executed now and scenarios that still require a human or agent contract.
- Adds one canonical machine route for choosing an optional automation draft or an existing repository validation command.
- Connects nested user actions to repository-backed prerequisites and ranks exact JavaScript or Python regression evidence.
- Preserves independent QA flows, changed files, review questions, and success signals across multiple product surfaces.
- Keeps a compact second affected flow when agent output must remain below 4KB.
- Exports the documented programmatic API and TypeScript declarations from the package root.
- Includes a provenance-pinned public PR reduction and a repository-local manifest feedback lifecycle benchmark.
Validation
- 207/207 tests passed
- 19/19 benchmark contracts passed
- QAMap scan: 0 findings
- Coverage: lines 88.89%, branches 85.48%, functions 95.87%
- Package preview and publish checks passed: 146 files, 903.5 kB packed
- Generated Playwright release smoke: 1/1 passed in the isolated fixture
- Large multi-surface handoff canary retained two distinct flows in 3,670 bytes and disclosed the two omitted flows
QAMap still reports target product execution as not-run unless a separate explicit execution boundary provides evidence.
Install
pnpm add -D @ivorycanvas/qamap@0.4.7Or run it once:
pnpm dlx @ivorycanvas/qamap@0.4.7 qaGitHub Actions can pin this release as IvoryCanvas/QAMap@v0.4.7.