Releases: Kpoiut/ruleblast
Release list
v2.5.11
RuleBlast 2.5.11
Tree 2.5.11 on commit d826c90a911749651ecb299fe67a896cf4b7eb74. Four actions only. Four bundled realities. No fifth action. No fifth bundled reality. No --pack loader.
npx --yes ruleblast@2.5.11 .
npx --yes ruleblast@2.5.11 diff HEAD~1
npx --yes ruleblast@2.5.11 --mcpCanonical JSON remains schemaVersion: 1 / resolverRevision: 1. Overlay wall is still four analysis pairs. The 5 s test clock is unchanged. Do not overwrite Marketplace 2.2.0 or 2.2.1.
This GitHub Release serves the packed CLI tarball and companion VSIX. npm ruleblast@2.5.11 is not independently verified in this receipt until the registry accepts the same tarball.
What 2.5.11 carries
- Nested Copilot/Claude fixtures, interned seals, interpreter-only pack load, MCP
-32602/-32700, SHA-pinned Verify, and a separaterelease:checkworkflow from2.5.10. - Advertised install pin
ruleblast@2.5.11. Packed GO preflight: localrelease:checkand GitHub Verify 3 OS × 4 Node on73f7267.
Artifacts
ruleblast-2.5.11.tgz219,830 bytes · SHA-256705ba446b77a78d835fb8414fcdd012b4613f9304b18808da91f6d6cc2d0c4d2ruleblast-companion-2.5.11.vsix193,771 bytes · SHA-256e5c6e67ca5aa617b0408e6b03371bc761779c187ef3f6a060a575c88556c0b8e
Install the companion from the GitHub Release asset. Same four actions in VS Code-family hosts.
v2.5.9 — Honest calibration, identity seal, pair topology
RuleBlast 2.5.9
Tree 2.5.9 on commit 8cc3a9f737c344c6f360ba9df5eceeceb170dfa8. Four actions only. Four bundled realities. No fifth action. No fifth bundled reality. No --pack loader.
npx --yes ruleblast@2.5.9 .
npx --yes ruleblast@2.5.9 diff HEAD~1
npx --yes ruleblast@2.5.9 --mcpCanonical JSON remains schemaVersion: 1 / resolverRevision: 1. Overlay wall is still four analysis pairs. The 5 s test clock is unchanged. Do not overwrite Marketplace 2.2.0 or 2.2.1.
This GitHub Release serves the packed CLI tarball and companion VSIX. npm ruleblast@2.5.9 is not independently verified in this receipt until the registry accepts the same tarball.
What 2.5.9 changes
CALIBRATEDre-runs the sealed vendor-source observer. Interpreter payload equality isORACLE, not the calibration gate.ORACLEstores the semantic stack identity seal (projectionDigest), not a hash of an object that already contains that digest.- Payload relation uses units as the law. Pair topology is one path-event walk. Overlay
DIVERGENTrequires a proven DIFFERENT pair. - Replay metrics fold from path rows. macOS
/varrealpath packing. MCPpathsOnly/witness.
Artifacts
ruleblast-2.5.9.tgz204,749 bytes · SHA-25696debe28b646e914cbb60ed53b8f2c72202b3f241e3cf3958e25cd8f8c22493fruleblast-companion-2.5.9.vsix185,323 bytes · SHA-2566aadb190b06442ece123811cc950010cfa4616906553da6bd8f904122aa7ff7f
Install the companion from the GitHub Release asset. Same four actions in VS Code-family hosts.
v2.5.7 — Four interpreted realities, host process, runtime allowlist
RuleBlast 2.5.7
This is the public npm and GitHub Release of tree 2.5.7. It is the first independently published CLI after 2.5.1. Versions 2.5.2 through 2.5.6 were merged to main and are included in this package. They were not separate npm versions.
npx --yes ruleblast@2.5.7 .
npx --yes ruleblast@2.5.7 diff HEAD~1
npx --yes ruleblast@2.5.7 --mcpFour actions only: current stacks, diff, explain, case. Four bundled realities: Codex CLI, Claude Code CLI, Copilot CLI, Gemini CLI. No fifth action. No fifth bundled reality. No --pack loader. A model name is never a reality.
Canonical JSON remains schemaVersion: 1 / resolverRevision: 1. Overlay wall is still four baseline analyses and four analysis-plus-overlay samples. Overlay median/p95 add less than 500 ms. The 5 s test clock is unchanged.
Do not overwrite Marketplace 2.2.0 or 2.2.1.
Official lineage
| Tree | In-repo record | Commit | Public npm |
|---|---|---|---|
2.5.1 |
RELEASED — Copilot interpreted from resolver.json |
e60fd18ec4a83ce8aff7488b0bb9203ab4a8cedc |
ruleblast@2.5.1 |
2.5.2 |
merged to main — Claude interpreted from resolver.json |
cda8834b3bc79f52123eb4f05019b35d775c9655 |
included in 2.5.7 |
2.5.3 |
merged to main — Gemini interpreted by composed operations |
796c5d9abdde755f5827351358b747ce30260cb1 |
included in 2.5.7 |
2.5.4 |
merged to main — host quoting and macOS verify |
f4154fd063e99f0f6e43e78b2e62ce2516cbdf0e |
included in 2.5.7 |
2.5.5 |
merged to main — host Git spawn and shared snapshot entry |
7b99d529355383977ad4589d746fe83c87a59185 |
included in 2.5.7 |
2.5.6 |
merged to main — runtime IDs, not model names |
742e27d07cec76e72a18c40598315e0b11b2b146 |
included in 2.5.7; gate later replaced |
2.5.7 |
RELEASED — exact runtime allowlist | cf6badd2ab376f1aa7f6f9b1d3be9559c1457503 |
ruleblast@2.5.7 |
The in-repo changelog keeps 2.5.2–2.5.6 as development headings. This GitHub Release is the official public history of that work as one published package.
Verified publication receipt
Independently verified external records, not facts inferred from a checkout.
npm ruleblast@2.5.7
- npm
ruleblast@2.5.7 - integrity
sha512-SzTP41slyb4hvPPYZ0KHj97SLf8sesfHz2morW/O55tQ9FTG4QoIhYgprxgNNT1YhXdTq5kQBJKDLD+Wm/eQVQ== - shasum
ea5280804857851b599539b7fa9b8f9a5b758875 - tarball 185,439 bytes · SHA-256
8873e179d261ecb7715b88c9268abcd7233720b40fcb7657bbd024f419c5d426 - unpacked size 1,454,645 bytes
- exact-tarball publication: registry
gitHeadis absent rather than invented - a registry download of
ruleblast@2.5.7is byte-identical to the packedruleblast-2.5.7.tgzfromcf6badd
GitHub
- Annotated tag object
dd46f4a9c08d10a9de1f113092b6036091e0f2daforv2.5.7targets commitcf6badd2ab376f1aa7f6f9b1d3be9559c1457503 - GitHub Release tarball is the same 185,439-byte
ruleblast-2.5.7.tgzwith SHA-2568873e179d261ecb7715b88c9268abcd7233720b40fcb7657bbd024f419c5d426 - Companion
ruleblast-companion-2.5.7.vsix167,204 bytes · SHA-256afac7b99c17afd07fee7255e6abca78fa04c518416f2cb8a2309b9728b93155e - Do not overwrite Marketplace
2.2.0or2.2.1
2.5.2 — Claude Code interpreted from resolver.json
Commit cda8834b3bc79f52123eb4f05019b35d775c9655. Merged to main. Not a separate npm version.
Claude Code is no longer a fingerprint-only engine on the catalog path.
The interpreter executes the Claude pack as data:
strip-html-comments@pathimport with lexerclaude-markdown-v1(four import edges)json-exclude-globson.claude/settings.json- frontmatter-glob
pathswith brace-budget matching - same-basename partial for dual root memory (
CLAUDE.md/.claude/CLAUDE.md)
Live interpreter projections are byte-identical to createClaudeProfile on every packed Claude fixture. Lab INTERPRET / ORACLE. The adapter remains the test oracle and is not imported by the interpreter.
Frontmatter apply is narrow YAML shared with Copilot applyTo: one mapping field to a string scalar (comma-split) or a string sequence. Maps, aliases, and merge keys fail closed.
Transform admission is the operations the engine executes (byte-budget, strip-html-comments, at-path-import with a named lexer, json-exclude-globs). Markdown tokenize/import and glob-budget matchers live under src/packs/ops-* and are reused by adapters as the same primitive, not a third vendor interpreter.
Interpreter admission is the two executable families:
- first-per-directory / ordered / byte-budget
- select-all / unspecified assemble
At 2.5.2 Gemini still fingerprinted on onSymlink (partial-unfollowed) and ordered assemble. Flipping the symlink policy does not admit a third family. Select-all prepares frontmatter, rule parse, and document tokens once, then caches projections.
Lab --detail / --receipt recorded Codex, Copilot, and Claude as INTERPRET / ORACLE and Gemini as FINGERPRINT / ADAPTER with sealed probe counts. Overlay wall and the 5 s clock stayed unchanged. Not a fifth action. Not a fifth bundled reality.
2.5.3 — Gemini interpreted by composed operations
Commit 796c5d9abdde755f5827351358b747ce30260cb1. Merged to main. Not a separate npm version.
Gemini CLI is interpreted by composing operations the engine already had:
select.modeallassemble.modeorderedonSymlinkpartial-unfollowedat-path-importwith lexermarkdown-v1json-union-namesfor trackedcontext.fileName
Live interpreter projections are byte-identical to createGeminiProfile on every packed Gemini fixture and on union-name snapshots. Lab INTERPRET / ORACLE for all four bundled realities. No third interpreter family. The adapter remains the test oracle and is not imported by the interpreter.
Lexer markdown-v1 is the shared markdown mechanism. Pack id is the lookup key on --detail. Compact --receipt keeps badges only. HTML-comment strip is a separate transform. json-union-names has no vendor field branch.
onSymlink selects UNKNOWN vs PARTIAL on one markdown import expander. Ordered-assemble evidence is pack claims plus union parse plus expansion, not interpreter-hardcoded Gemini strings.
Admission checks executable select/assemble/symlink/transform capabilities. Select-all prepares import expansions once and caches ancestor-directory chains for ordered assemble.
Lab --detail prints pack id beside engine, proof, ops, and sealed probe counts so an agent can look up the executing reality. Benchmark 10k/GIF uses catalog interpreters (the CLI path), records all four engines on the same snapshot, and requires four ORACLE rows. Overlay wall and the 5 s clock stayed unchanged. Not a fifth action. Not a fifth bundled reality.
2.5.4 — Host platform quoting and macOS verify
Commit f4154fd063e99f0f6e43e78b2e62ce2516cbdf0e. Merged to main. Not a separate npm version.
Host shell quoting follows the process platform: PowerShell on Windows, POSIX on Linux and macOS. CLI, MCP stdio, companion presentExplain, and GIF explain share hostShellDialect(). MCP no longer hardcodes POSIX CTAs on Windows.
Verify runs ubuntu-latest, windows-latest, and macos-latest on Node 20/22/24/26. Same 20-minute cell clock.
Select-all prepare records the matching discover origin once per captured path instead of scanning origins again.
Overlay wall still four analysis pairs. Not a fifth action. Not a fifth bundled reality. Not a kernel.
2.5.5 — Host Git spawn and shared snapshot entry
Commit 7b99d529355383977ad4589d746fe83c87a59185. Merged to main. Not a separate npm version.
Git analysis and companion Diff From git log share one runGit() with the same lock/fsmonitor flags and windowsHide on Windows. That is not a second Git engine.
Omitted text presentation context uses hostShellDialect(), so companion Show Detail CTAs match the host. CLI and MCP still pass the dialect explicitly.
Interpreter and Codex/Claude adapter prepare capture snapshot entries through ownSnapshotEntry(). Same closed-record check. Four copies of entry validation are one primitive.
Overlay wall still four analysis pairs. Not a fifth action. Not a fifth bundled reality.
2.5.6 — Runtime IDs, not model names (then corrected)
Commit 742e27d07cec76e72a18c40598315e0b11b2b146. Merged to main. Not a separate npm version. The 2.5.6 heading stays in the changelog as the historical record.
2.5.6 introduced a candidate roster keyed by runtime IDs and refused --reality grok-4 as a model name. That direction was right:
- IDs name CLIs and harnesses, not model products.
xai/grok-build-cliis a not-admitted candidate runtime.grok-4,glm-5.3, andgpt-4are model names.--realityand MCP refuse those with distinct text.- Projection of a candidate remains
UNEXECUTED.RECORDEDis not a passing oracle. - No public fifth
--reality. No public--pack.
The first implementation was not that gate:
- a denylist of product names
- invented empty watch stubs (
deepseek/dsh-harness,moonshot/kimi-code-cli) - treating
xai/grok-build-cli@1as the unversioned forming candidate
2.5.7 replaces that gate. Empty watch stubs are not inventory. A revision suffix is not implied.
2.5.7 — Exact runtime allowlist and shared host process
Commit cf6badd2ab376f1aa7f6f9b1d3be9559c1457503. This is the tagged package.
Runtime classification is an allowlist of catalog ids and committed candidate ids, exact match only.
- Modeled public realities remain
openai/codex-cli@1,anthropic/claude-code-cli@1,github/copilot-cli@1,google/gemini-cli@1. - Forming candidates in this package: `xai/grok-build-cl...
v2.5.1: Copilot interpreted from resolver.json
RuleBlast 2.5.1
Copilot CLI interpreted from resolver.json: multi-origin discover, select-all, unspecified assemble, frontmatter-glob applyTo, unexpanded @ mention. Lab INTERPRET / ORACLE. Claude and Gemini still fingerprint. No fifth action. No fifth bundled reality. No --pack. A model name is never a reality.
npx --yes ruleblast@2.5.1 .
npx --yes ruleblast@2.5.1 diff HEAD~1Verified npm
- npm
ruleblast@2.5.1 - integrity
sha512-cAchQ4It9MM4E+CmOMvnviX/zGic+28DvxbHIK908NN+qJ9aLAsi7iPiIEelKBJiY/N4Ie0RxiVeOqhB1TbfhQ== - tarball 177,160 bytes · SHA-256
32e3cc817f0dd915764f2f9d67c8b3f3f8aa4bc9215c11c8439842ed52ee6c4a - exact-tarball publication: registry
gitHeadis absent
GitHub
- Signed tag object
761f547ca00d911cf5c5b826461b82c01ccac900forv2.5.1targetse60fd18ec4a83ce8aff7488b0bb9203ab4a8cedc - Companion
ruleblast-companion-2.5.1.vsix160,281 bytes · SHA-25626ed18e60cf4f4bad0dfef78514f2924d2f14878355547c5644a6220e1b09869 - Do not overwrite Marketplace
2.2.0or2.2.1
v2.5.0: Candidate Reality Conformance Lab
RuleBlast 2.5.0
Candidate Reality Conformance Lab on --detail and --receipt. Bundled INTERPRET versus FINGERPRINT coverage from a sealed oracle.json per pack. No fifth action. No fifth bundled reality. No --pack. A model name is never a reality.
npx --yes ruleblast@2.5.0 .
npx --yes ruleblast@2.5.0 diff HEAD~1Verified npm
- npm
ruleblast@2.5.0 - integrity
sha512-+L5dINRsAs5/vW2nSYbBpzwL4NTCAF7/P9corxZtjd/Ats/0VvKTlU61vYVL1xqW5S4MIo9e2LpqHeKS2f1Eag== - tarball 174,972 bytes · SHA-256
4fede04c92030ed7e98fdf44868f1c334f24b4d66b233ad2bf68cc6967272e4f - exact-tarball publication: registry
gitHeadis absent
GitHub
- Signed tag object
a6ab195c517815cddfcbea326452e67782477fc9forv2.5.0targets0afa7e251f70454078b50391cf93e5d7dc19cac5 - Companion
ruleblast-companion-2.5.0.vsix157,848 bytes · SHA-256a1933630a594ae617defe530ea2e3bcaa44bba054a797f88e123710f90db1606 - Do not overwrite Marketplace
2.2.0or2.2.1
v2.4.6: Spec-driven pack interpreter
RuleBlast 2.4.6
Catalog Codex is interpreted from pack resolver.json. createCodexProfile stays the adapter oracle. The interpreter does not import that adapter. No fifth bundled reality. No --pack. A model name is never a reality.
npx --yes ruleblast@2.4.6 .
npx --yes ruleblast@2.4.6 diff HEAD~1Verified npm
- npm
ruleblast@2.4.6 - integrity
sha512-MpYQzjNive82VKCJWqhUCx32/NXHgy8Hm878oCSt4u33y9bZgqLlTpYXPxNWHODZn+CL838IyzKZ1j/ip3SL8g== - tarball 153,122 bytes · SHA-256
c8438947be110f783b66e2f9746b5bbc6f9941a2bc5776a2a22af23fc063cdd9 - exact-tarball publication: registry
gitHeadis absent
GitHub
- Signed tag object
137dec9cb431d6b6f20869e14252d3f5b8c838b8forv2.4.6targets44124475babc60bbb73186debe311ab6753d2f6b - Companion
ruleblast-companion-2.4.6.vsix148,086 bytes · SHA-256877c565790c2e4b7366ef4ba467c9dd02efc7b0638ddca4fc95fb1faa67d0404 - Do not overwrite Marketplace
2.2.0or2.2.1
v2.4.5: Packed hosts of one result
RuleBlast 2.4.5
Packed CLI --help and --version stay off the analysis graph. The packaged case verifies once. Gemini prepare reads instruction files and followed imports. MCP diff uses the same overlay pair as the CLI and accepts detail. Companion Show Detail renders the last result without a fifth action.
npx --yes ruleblast@2.4.5 .
npx --yes ruleblast@2.4.5 diff HEAD~1Verified npm
- npm
ruleblast@2.4.5 - integrity
sha512-nnrLHacDTodnWAypkJZIiolXIMVIOo0TgHy711FK2bT3K3eimc3v6p61AdaH40Y1gSJQ8Z6SBOjYOYAQ55tt4Q== - tarball 147,397 bytes · SHA-256
9a8b228b0bcf42fc862704fa43f0a27c0b35a2b988a0f67bfd8e276998f950da - exact-tarball publication: registry
gitHeadis absent
GitHub
- Signed tag object
1bbdb7b276bede8e862e1b8c5ccc3d3f32497a13forv2.4.5targetsc599195b1c64cdff215e7380b7fee9d737e0a10e - Companion
ruleblast-companion-2.4.5.vsix142,254 bytes · SHA-2565b45c7fb9daf0e4674de1ab1007a0612e57d8cf11516551aba49739c0a865ea5 - Do not overwrite Marketplace
2.2.0or2.2.1
v2.4.1 Republished progressive disclosure
RuleBlast 2.4.1
Replacement for unpublished ruleblast@2.4.0. npm does not allow that version number to be reused.
Same progressive disclosure: --paths-only, explain --compare, PROOF, companion glance. --json stays canonical.
npx --yes ruleblast@2.4.1 .
npx --yes ruleblast@2.4.1 diff HEAD~1Verified npm
- npm
ruleblast@2.4.1 - integrity
sha512-MTTZpr2qhuMaR4BN9z5LsMe1pORPkbDeNV5Gr8f2GXb0jLI3MoPYaM5rX1CQqtyMePcNEfU4JdHXFYQWiGglOA== - tarball 144,495 bytes · SHA-256
6c89d285e938fae0e9f5aa717fc0a6403fc48f57d825c1b7310ea01c52231483
GitHub
- Tag
v2.4.1targetsf80b0d0fb2af6ab0c37d703b1d36a094c9a0cc58 - Companion
ruleblast-companion-2.4.1.vsix137,302 bytes · SHA-25629efd185756292c136312f900eb89115b7a7707b8d30a3d58adc8534f654ebf6 - Do not overwrite Marketplace
2.2.0or2.2.1 - Do not install unpublished
ruleblast@2.4.0
v2.4.0 Progressive disclosure
RuleBlast 2.4.0 — Progressive disclosure
Git shows the instruction edit. This release names the files that inherit it — then lets you go one layer deeper only when you need to.
--paths-only— one attention path per lineexplain --compare— two selected-reality stacks- Explain
PROOF— source chain from the same result - Companion Status Bar follows the active file
--json stays canonical. No fifth action. No dashboard. No model call.
Verified npm
- npm
ruleblast@2.4.0 - integrity
sha512-s1K6hIOMOR/q+/+z+JN/6SAmYWq1CResaKSs3Y+J/ztzjRw6tUEbeR62yqcaAcIwDIGXLiL+gtKbmX5T9210oA== - tarball 144,516 bytes · SHA-256
bbc35dfb12e0c5557dba288f2208c4763e8aab52f2c04ece126fab24f17d8755 - registry
gitHeadat publish:a0848463a493516eba64d5d73aecf0ea3b097e07
GitHub
- Tag
v2.4.0targets82514d7dc03614094001ec737a7d2bb13402d45a(public pin flip after npm publish) - Companion
ruleblast-companion-2.4.0.vsix137,302 bytes · SHA-256e4032b708cd98a92ac0dd17bcf7b35f1dec73ff7ca129ee7a8731eacb1988c50 - Do not overwrite Marketplace
2.2.0or2.2.1
npx --yes ruleblast@2.4.0 .
npx --yes ruleblast@2.4.0 diff HEAD~1v2.3.0 Overlay, work map, and companion control
npm
ruleblast@2.3.0 is latest.
- integrity
sha512-1G1yAOUMnMQUfVX64YoLbBVKPNrFsX7ivIZ8OhJwL5YQUFyC6EyWYk4mNokyDIh+q7KqeLt9djgQSXxlQ2fn2Q== - tarball 138,135 bytes SHA-256
1672bdd9133f960d8658e003b8d7cb77a13b3fbd79c9238a2b009abf2839ba2e - registry
gitHeadat publish was67280fd8b43a53cd262d68058e3b4680410c8d2dand is not the 2.3.0 source commit
Source
Signed tag object 73e0fdf25f68c18380c9db5b459406419f72fc06 targets 7ca69ba262f3250e6e33630ca05c205d9f01e14c.
What people get
- Human Git↔Git and Git→WORKTREE
diffappends OTHER TRACKED CHANGES from Git storage blob-object identity, then WORK MAP and CHANGE ALIGNMENT (ALIGNED/MIXED/DIVERGENT/UNRESOLVED) - Companion
ruleblast-companion-2.3.0.vsix: themed SVG, welcome scan/diff/explain/case,Ctrl+Alt+RthenS/D/E/C - CLI and MCP:
npx --yes ruleblast@2.3.0 --mcp - Action default pin is
2.3.0
Not a fifth action. --json stays canonical. A host is not a modeled reality. Do not overwrite Marketplace 2.2.0 or 2.2.1.
Companion
125,885-byte ruleblast-companion-2.3.0.vsix SHA-256 40aca6dbb59bf2b5d19938788f0454baa80abb806802290429aff8c3f255ab60