Skip to content

v1.3.12

Choose a tag to compare

@github-actions github-actions released this 13 May 05:20
· 37 commits to main since this release

What's Changed in v1.3.12

docs: sync upstream baseline to 393d397 (#76) by @Jamkris

Summary

Final PR of the 2026-05-13 upstream sync round. Advances the recorded baseline from e9c88458 (2026-05-11) to 393d397 (2026-05-12) — the upstream HEAD at triage time and the last commit evaluated this round.

Round 3 PRs

  • #74 — triage / audit log (upstream/sync-rounds/2026-05-13.md)
  • #75 — port: code-reviewer guardrails + prompt defense baselines

Of 67 commits in the focused range: 2 ported, 8 deferred (net-new feature additions: PRD command, network architect agents, motion skills, Quarkus, Django Celery, cost tracking, frontend design, homelab configs), 57 skipped with rationale.

Files updated (4)

  • upstream/.upstream-sync.json — lastSyncedSha + lastSyncedAt + round notes pointing at the new audit log.
  • upstream/README.md — baseline badge, Last-synced commit, date, round-notes pointer (now references both 2026-05-13 and 2026-05-12).
  • upstream/ko-KR/README.md + upstream/zh-CN/README.md — mirrored.

Expected post-merge behaviour

  • The validator passes — the prose SHA and JSON SHA agree on 393d397.
  • Next scheduled or manually-dispatched upstream-drift workflow run will compute the delta against ECC's current HEAD. If ECC has moved past 393d397 (likely — they merge daily), issue #71 updates with the new (small) count. If no new ECC commits since 393d397, #71 auto-closes.

Test plan

  • node scripts/ci/validate-upstream-sync.js — "OK — both files reference 393d397"
  • npm run lint clean
  • npm test 279/279
  • Manual link check — README baseline → ECC commit, audit log links → 2026-05-13.md + 2026-05-12.md

Round end

This PR closes round 3.

Related to #71.


port: code-reviewer guardrails + prompt defense baselines from ECC (#75) by @Jamkris

Summary

Two ports from the 2026-05-13 sync round:

  • df60af9 — code-reviewer false-positive guardrails
  • 393d397 — prompt defense baselines

agents/code-reviewer.md (df60af9)

Adds false-positive guardrails directly to the agent prompt:

  • Pre-Report Gate — 4-question filter before writing any finding (cite line, name failure mode, read context, defensible severity).
  • HIGH / CRITICAL require proof — exact snippet + scenario + why existing guards don't catch it. Demote or drop otherwise.
  • "Zero findings is valid" — explicit license to APPROVE clean diffs instead of manufacturing nits.
  • Common False Positives catalog — 12 patterns LLM reviewers consistently mis-flag (error handling already at framework level, magic numbers for well-known constants, missing JSDoc on self-describing helpers, security theater on Math.random(), etc.).
  • Approval criteria updated — clean review is valid; don't withhold APPROVE to appear rigorous.

The intent is to reduce the kind of noise this very repo has been seeing in PR reviews — pattern-match nits with no concrete failure scenario.

GEMINI.md + 48 agent files (393d397)

Prepends a uniform Prompt Defense Baseline 6-bullet block:

  • role / persona / identity protection
  • confidential-data / secret protection
  • executable-code output restraint
  • unicode / homoglyph / encoded-trick suspicion
  • external / untrusted data validation
  • harmful-content prohibition

Block content is harness-agnostic; same text as upstream ECC. Inserted right after the closing frontmatter --- on every agent, and after the H1 + intro paragraph on GEMINI.md.

Applied via a one-shot script (idempotent — skips files already containing the block).

ECC commit in scope that did not port

  • cb2a70c (motion skill fix) — EGC has remotion-video-creation but not motion-advanced / motion-foundations. The upstream motion skills are deferred net-new candidates for a future "ECC net-new" round.

Files changed (49)

Group Count Source
agents/code-reviewer.md 1 (both ports) df60af9 + 393d397
agents/*.md (other 47) 47 393d397
GEMINI.md 1 393d397

Total: +520 lines / -1 line.

Test plan

  • npm run lint clean
  • npm test 279/279
  • node scripts/ci/validate-agents.js — 48 agent files validated
  • Spot-checked 3 agents (architect, tdd-guide, code-reviewer) — block correctly inserted after frontmatter
  • Spot-checked GEMINI.md — block inserted between intro paragraph and Guidelines section

Summary by cubic

Adds strict false-positive guardrails to the code-reviewer and applies a 6-point Prompt Defense Baseline to all agents and GEMINI.md to reduce review noise and strengthen prompt safety. This cuts low-signal findings and hardens prompts against injection and unsafe outputs.

  • New Features

    • Code reviewer guardrails: 4-question pre-report gate; proof required for HIGH/CRITICAL; zero-findings APPROVE; skip common false positives; updated approval criteria.
    • Prompt Defense Baseline: 6 rules (role/identity protection, secret protection, executable-output restraint, Unicode/encoding trick suspicion, untrusted-data validation, harmful-content ban) inserted across 48 agents and GEMINI.md.
  • Migration

    • No action needed. The baseline is auto-inserted after frontmatter; the script is idempotent and avoids duplicates.

Written for commit 92a84ba. Summary will update on new commits.

Summary by CodeRabbit

  • Documentation
    • Added comprehensive safety baselines to agent instructions, enforcing explicit constraints for identity preservation, data confidentiality, restricted output formats, and validation of untrusted inputs to ensure consistent secure behavior across all agents.

Review Change Stack


docs: triage ECC upstream commits e9c8845..393d397 (#74) by @Jamkris

Summary

Round 3 audit log. ECC moved 67 commits forward of the baseline recorded at the end of round 2 (#71 reported 65 when the drift tracker opened; ECC merged 2 more before triage).

Round 3 totals

Category Port now Defer (net-new) Skip
skills 0 — 1
docs 0 — 30
agents 2 — 0
commands 0 — 0
shared logic 0 — 6
CI / packaging 0 — 2
other-harness (net-new features) 0 8 0
meta 0 — 1
needs-review (edge cases) 0 — 17
Total 2 8 57

Notable findings

  • df60af9 (code-reviewer guardrails) — adds Pre-Report Gate, HIGH/CRITICAL proof rules, "zero findings is valid" guidance, and a Common False Positives catalog to ECC's code-reviewer agent. All harness-agnostic. Port target.
  • 393d397 (prompt defense baselines) — adds a uniform 6-bullet prompt-defense block to ECC's CLAUDE.md and every agent file (71 files total upstream). Port target — apply to EGC's GEMINI.md and all agents.

Deferred (8 net-new features)

ECC added meaningful new surfaces this round that exceed a sync-round port scope: PRD planning command, network architect agents, motion system skills, Quarkus handling, Django Celery workflow, cost tracking + skill scout, frontend design guidance, homelab config skills. These join the deferred net-new candidates from round 2 (tinystruct-patterns, ios-icon-gen, flox-environments) — should be opened as a dedicated "ECC net-new" PR set in a future round.

Follow-up PRs

  1. `port: code-reviewer guardrails + prompt defense baselines from ECC`
  2. `docs: sync upstream baseline to 393d397` — closes #71

Test plan

  • `npm run lint` clean
  • `npm test` 279/279
  • Doc-only change

Summary by cubic

Adds the 2026-05-13 upstream sync inventory documenting ECC drift (67 commits from e9c8845 to 393d397). It calls out two port targets (code-reviewer guardrails and prompt-defense baselines), defers eight net-new features, and marks 57 skips to guide follow-ups.

Written for commit 925b1c8. Summary will update on new commits.

Summary by CodeRabbit

  • Documentation
    • Added comprehensive documentation for the 2026-05-13 upstream sync round, including triage inventory results across multiple categories, summary statistics, and suggested follow-up actions.

Review Change Stack


docs: record ECC backport in 2026-05-12 sync round log (#73) by @Jamkris

Summary

Adds a "Backports to upstream ECC" section to upstream/sync-rounds/2026-05-12.md recording the two block-no-verify bypass holes that flowed back upstream as affaan-m/everything-claude-code#1843.

Why

Per the dual-PR pattern in CONTRIBUTING.md: when a contribution to EGC is harness-agnostic and would also benefit ECC users, cross-link the two PRs so reviewers on either side can see the upstream/downstream pair. This is the first sync round where work flowed from EGC back to ECC, so the audit log should record it.

Test plan

  • `npm run lint` clean
  • `npm test` 279/279
  • Doc-only change; no source/script modifications

What ships in the upstream PR (cross-link)

  • core.hooksPath case-sensitivity bypass — was case-sensitive; `git -c core.hookspath=…` slipped past the guard.
  • -tn false positive — `COMMIT_SHORT_OPTIONS_WITH_VALUE` missing `'t'` falsely blocked legitimate `git commit -tn template`.

Both originally discovered in EGC PR #68 (commit fbf7908) by CodeRabbit's round-3 review.


Summary by cubic

Adds a “Backports to upstream ECC” section to upstream/sync-rounds/2026-05-12.md documenting two block-no-verify bypass fixes and cross-linking the upstream/downstream pair per the dual-PR pattern.

  • Bug Fixes
    • core.hooksPath case-insensitivity bypass: git -c core.hookspath=… was not caught.
    • -tn false positive: missing 't' in short options caused valid git commit -tn template to be blocked.

Written for commit e67c5e1. Summary will update on new commits.

Summary by CodeRabbit

  • Documentation
    • Updated audit log to document security fixes addressing two bypass vulnerabilities.
    • Added backport information detailing fixes shipped to upstream systems.

Review Change Stack


chore: release v1.3.11 (#72) by @Jamkris

Bump version to 1.3.11


Summary by cubic

Prepare v1.3.11 release by updating version fields in .gemini-plugin/plugin.json, gemini-extension.json, and package.json. No functional changes.

Written for commit 5b96bf7. Summary will update on new commits.