Repository navigation
v1.0.11
[1.0.11] — 2026-10-02
Code audit — data safety, installer ownership, native loading, CI and site
- DB migrations are atomic and self-healing — each schema step now commits its DDL and its
schema_versionbump in one transaction (SQLite DDL is transactional), and ALTER steps checkPRAGMA table_infofirst. Before, a crash between an ALTER and its version stamp left a database whose next open re-ran the ALTER, failed withduplicate column name, and bricked every later command against that repo; the idempotent guard also repairs databases the old code had already stranded. Regression-tested (interrupted_migration_is_repaired_not_fatal). - The installer no longer wipes unparseable configs —
readJsonused to swallow any JSON parse error and return{}, which the subsequent rewrite made permanent. A non-empty unparseable file now aborts the install with a refusal naming the path; a UTF-8 BOM is tolerated; and.vscode/mcp.json(officially JSONC — comments and trailing commas are legal) is parsed with a conservative comment/trailing-comma stripper so commented team configs install without losing their servers. All installer config rewrites (JSON, the Codex TOML, markdown sections, git hooks) now write via temp-file + rename, so a crash mid-write can never leave a truncated file — which is what previously turned into a wipe on the next install. - Uninstall removes only what install wrote — three ownership gaps closed:
removeAgentMcpdeleted anyastria/graphifyMCP entry regardless of authorship (a user-written entry with those names survived install's own preserve check only to be deleted on uninstall);removeSectiondeleted unmanaged## astriamarkdown sections that install correctly treats as user-owned, and its heading match was prefix-based, so## astria-guidewas caught too; and hook entries were claimed by bare substring — a user's ownastria hook-guard read --strictPreToolUse hook (the command our own docs suggest) was deleted byastria uninstall claude. MCP ownership now uses oneisInstallerServerpredicate across install/uninstall/legacy cleanup; markdown removal requires the managed marker; hook matching keys on the structural fingerprints every installer template carries (a quoted.astria/.graphifypath segment, or the pre-1.0 package name). - The updater hook is no longer appended to shell hooks — appending the JavaScript updater to a
#!/bin/shhook (a user hook, or a husky-style hook undercore.hooksPath) broke that hook with syntax errors on every commit while the graph refresh silently never ran; the old test asserted the appended file content but never executed the hook. Install now appends only to Node-script hooks and skips others with an explicit notice (a foreign Node hook still merges cleanly — both paths tested). - A missing native binary no longer kills the whole CLI — the platform-package
requirehad no try/catch (the crafted diagnostic was unreachable in exactly its target scenario), the musl switch arms require packages that were never published (Alpine was a guaranteed rawMODULE_NOT_FOUND), and the binding loaded at module scope, so evenastria install,astria uninstall, and--versioncrashed before Commander ran. Every require is guarded, the binding loads lazily on first native call, and the diagnostic names the resolved platform target and the musl limitation. - Bolt decoding bounds server-controlled sizes — PackStream list/struct lengths from a Neo4j server fed
Vec::with_capacityunbounded (a hostile LIST_32 length was an allocator abort, uncatchable across the napi boundary), and message deframing had no total-size cap; both are now bounded (element count clamped to remaining bytes, messages capped at 256 MiB with anInvalidDataerror). Hostile-input tests added for all three decoders and the frame cap. - Copilot's skill file installs where Copilot reads it — repo-scoped
.github/skills/in the project (docs.github.com), not~/.github/skills/; the test's own comment already said project-scoped while asserting the home path. Installs clean up the 1.0.9/1.0.10-era home-dir copy, and file-stem layouts (cline/roo) keep their identity guard so a second install still never deletes its own skill. - Smaller correctness fixes — unknown
--platformnow exits 1 (it printedUnknown platformand exited 0, so scripts could not detect the failure); uninstall readsCLAUDE_CONFIG_DIRthrough the same sanitizer install uses and removes both candidate skill roots (the raw env var previously reached anunlinkSyncunvalidated);npm run napi:dev -- --debugbuilds no longer lose to a stale release artifact (candidate order follows the profile just built); bench-snapshot's two pushing jobs are serialized (needs:— the concurrency group serializes runs, not jobs within a run, so one push used to lose the race) with permissions narrowed per job;promptfoois pinned (@0.123.1) instead ofnpx promptfoo@latestwith the judge API key in env. - Website truthiness — homepage language count corrected to 25 (the registry has 25; README already said 25); the 1.0.10 docs version cut and
lastVersionrefresh (default/docswas five releases stale at 1.0.5); release-notes blog posts for 1.0.9 and 1.0.10, which the sidebar's "Release notes" feed stopped at 1.0.8.
Distribution audit — four fixes
- Homebrew formula installed no executable —
std_npm_argsinstalls global-style intolibexec(package atlibexec/lib/node_modules, executables linked atlibexec/bin), but the 1.0.10 formula symlinkedlibexec/node_modules/.bin/astria— a local-install path that never exists underlibexec— and Homebrew'sinstall_symlinkover an empty glob is a silent no-op, sobrew install nodesify/tap/astria"succeeded" with noastriacommand. The formula now symlinkslibexec/bin/*(homebrew-core's idiom for npm packages) atrevision 1; the live tap carries the same fix. - The Claude Code plugin shipped without its MCP server — the plugin root is the repo root (marketplace
source: "./"), and its only MCP registration was the root.mcp.json, which is machine-local and gitignored — so marketplace installs delivered the skill, commands, and subagent but zero MCP servers, despite 1.0.9's "the tracked.mcp.json" changelog claim and the plugin's own description..claude-plugin/plugin.jsonnow declares theastriastdio server inline viamcpServers(the sameastria mcpentryastria installwrites), which ships with the tracked tree. Plugin and marketplace metadata move to1.0.11ahead of the npm package so version-caching plugin managers register the changed plugin — the npm package,server.json, and the registry listing stay at 1.0.10 until the next tagged release. - The release verify step checked versions only — the field that actually broke v1.0.9 (
mcpNamevsserver.jsonname, the 403 namespace case mismatch) was never compared, so a future drift would again surface only at the post-npm registry step where immutability makes it unfixable without burning a version. The step now verifies name vs mcpName, the npm entry's identifier vs the package name, and the per-package version, alongside the top-level version. - mcp-publisher is pinned and checksum-verified — the registry publish step downloaded
releases/latestand executed it with the job's OIDC and GitHub tokens, the only unpinned external code in a workflow where every action is SHA-pinned. Now pinned tov1.8.1with a sha256 check; moving to a newer publisher is a deliberate tag+checksum bump.
What's Changed
- docs: update documentation for astria 1.0.5 by @nodesify-technology in #86
- chore(bench): publish 1.0.5 benchmark snapshots by @erictong0602 in #87
- Release 1.0.6 — chunked document retrieval, cross-conversation ranking, introspection commands by @erictong0602 in #88
- ci: Node 24 action upgrades + runner label pinning by @nodesify-technology in #89
- Release 1.0.7 — judged semantics, drill-down viewer, scoped retrieval by @erictong0602 in #90
- Release 1.0.8 — RESOLVED provenance, code-aware embeddings, sixteen platforms by @erictong0602 in #91
- Release 1.0.9 — official MCP Registry publishing, Claude Code plugin marketplace, Homebrew tap by @nodesify-technology in #92
- Sync main with 1.0.10 — registry namespace fix, hardened release workflow by @erictong0602 in #93
- Sync main — distribution audit fixes: plugin MCP server, brew binary, release gates, pinned publisher by @erictong0602 in #94
- Sync main — full-repo audit: atomic migrations, installer data safety, lazy native loading, bolt bounds by @erictong0602 in #95
- Release 1.0.11 — hardening release (audit fixes + distribution follow-ups) by @erictong0602 in #96
Full Changelog: v1.0.5...v1.0.11