The auto-sync integrity release. Five defects were found by using the kit in a real production consumer project — and every one flowed back here and got fixed with tests. The headline for anyone running superkit in their own repos: your local customizations now survive kit updates. Headline component counts unchanged; no breaking changes.
🛡️ Your customizations survive updates now
superkit-update.sh used to blind-copy kit files over yours on every version bump — silently reverting local repairs two releases in a row in our own production testbed. Now:
- A consumer file is overwritten only when its content matches a released tag's blob (your install baseline + the last 5 tags). Edited files are preserved — and any uncertainty (missing tag, git error) also preserves. Fail-safe by default.
- Every sync prints a SessionStart report:
superkit-update: N synced · M preserved (locally customized) · K skipped (internal)+ the preserved paths. Silence is what let the old behavior run unnoticed — it's gone. - Self-bootstrap: the updater replaces itself from source and re-execs before syncing anything, so this fix protects even the update that delivers it.
- Coverage extended:
stack-rules/, the Goreferences/knowledge docs, andhooks/lib/now sync too (they previously drifted forever). - Proven on a 31-case fixture suite plus a dry-run against a real consumer copy: 102 stale files synced, all 7 known customizations preserved byte-identical.
🔒 Repo-only files can't leak anymore
Three superkit-internal files (superkit-counts-verify.sh, verify-hooks.sh, superkit-integrity.md) kept re-appearing in consumer projects. The skip-list was hand-duplicated in two places and missing from the updater entirely. Now: one packages/core/INTERNAL-FILES manifest feeds the installer, the counts gate and the updater — with a per-category fallback (fixed in this release, proven failing-first) so even a manifest that loses a single line can't ship internals, and a stderr warning when a category goes empty.
✂️ The commit gates stop blocking their own advice
dev-required-on-commit.sh: the exempt-files check now runs before the override branch — amemory/- or.claude/-only commit can never be penalty-blocked again. Override tags ([no-dev:…],[wip], …) count only when they open a line of the commit message; prose that merely mentions a tag is not an override.block-dangerous-git.sh: commit-message payloads (-m,--message,-F -heredocs) are stripped before the guards run — a message describing--no-verifyor a force-push no longer trips the hook, whilegit commit -m "x" && git push --forcestill blocks (38-case matrix, non-weakening proven adversarially).
📄 The ADR template actually installs
dev.md and superkit-init referenced docs-templates/adr-template.md — but the installer never shipped it. Now installed unconditionally and idempotently (never overwrites your copy); the updater creates it when missing; /dev's nudge degrades silently if absent.
📊 Statusline — a real dashboard now
- ctx as a colour heat bar (
ctx ██████░░░░ 62%, percent-only to stay narrow). - Real 5-hour / weekly rate-limit bars with time-to-reset, read from Claude Code's own
rate_limitspayload — the same numbers/usageshows. No estimated denominators, no calibration guesswork; absent on API-key billing → the segments simply don't render. - Current model (cyan) + effort heat-graded bold (
⚙highgreen /⚙xhighyellow /⚙maxred) + a⟁ULTRAbadge while ultracode is active. - Your active task (
.claude/.task-state.json) and git branch in readable bright white —CLAUDE_STATUSLINE_THEME=lightflips them to black for light terminals. - Everything fail-open; older CLIs just show fewer segments. Note:
statusline.cjsis installer-only by design (consumers legitimately fork it) — existing projects keep their fork; fresh installs get the new one.
🧪 Verification
31-case updater fixture suite (throwaway git repo, never the real clone) · 15/15 hook suites · 79/79 mirror-invariants · 30/30 npm incl. fresh-install smoke · counts reconciled · the per-category fallback proven failing-first (the leak reproduced before the fix, gone after).
Full changelog: CHANGELOG.md · Previous: v1.5.1