Skip to content

v1.5.2 — Auto-Sync Integrity

Latest

Choose a tag to compare

@RaNDoM6913 RaNDoM6913 released this 10 Jul 01:13
· 6 commits to main since this release

The auto-sync integrity release. Five defects were found by using the kit in a real production consumer project — and every one flowed back here and got fixed with tests. The headline for anyone running superkit in their own repos: your local customizations now survive kit updates. Headline component counts unchanged; no breaking changes.

🛡️ Your customizations survive updates now

superkit-update.sh used to blind-copy kit files over yours on every version bump — silently reverting local repairs two releases in a row in our own production testbed. Now:

  • A consumer file is overwritten only when its content matches a released tag's blob (your install baseline + the last 5 tags). Edited files are preserved — and any uncertainty (missing tag, git error) also preserves. Fail-safe by default.
  • Every sync prints a SessionStart report: superkit-update: N synced · M preserved (locally customized) · K skipped (internal) + the preserved paths. Silence is what let the old behavior run unnoticed — it's gone.
  • Self-bootstrap: the updater replaces itself from source and re-execs before syncing anything, so this fix protects even the update that delivers it.
  • Coverage extended: stack-rules/, the Go references/ knowledge docs, and hooks/lib/ now sync too (they previously drifted forever).
  • Proven on a 31-case fixture suite plus a dry-run against a real consumer copy: 102 stale files synced, all 7 known customizations preserved byte-identical.

🔒 Repo-only files can't leak anymore

Three superkit-internal files (superkit-counts-verify.sh, verify-hooks.sh, superkit-integrity.md) kept re-appearing in consumer projects. The skip-list was hand-duplicated in two places and missing from the updater entirely. Now: one packages/core/INTERNAL-FILES manifest feeds the installer, the counts gate and the updater — with a per-category fallback (fixed in this release, proven failing-first) so even a manifest that loses a single line can't ship internals, and a stderr warning when a category goes empty.

✂️ The commit gates stop blocking their own advice

  • dev-required-on-commit.sh: the exempt-files check now runs before the override branch — a memory/- or .claude/-only commit can never be penalty-blocked again. Override tags ([no-dev:…], [wip], …) count only when they open a line of the commit message; prose that merely mentions a tag is not an override.
  • block-dangerous-git.sh: commit-message payloads (-m, --message, -F - heredocs) are stripped before the guards run — a message describing --no-verify or a force-push no longer trips the hook, while git commit -m "x" && git push --force still blocks (38-case matrix, non-weakening proven adversarially).

📄 The ADR template actually installs

dev.md and superkit-init referenced docs-templates/adr-template.md — but the installer never shipped it. Now installed unconditionally and idempotently (never overwrites your copy); the updater creates it when missing; /dev's nudge degrades silently if absent.

📊 Statusline — a real dashboard now

  • ctx as a colour heat bar (ctx ██████░░░░ 62%, percent-only to stay narrow).
  • Real 5-hour / weekly rate-limit bars with time-to-reset, read from Claude Code's own rate_limits payload — the same numbers /usage shows. No estimated denominators, no calibration guesswork; absent on API-key billing → the segments simply don't render.
  • Current model (cyan) + effort heat-graded bold (⚙high green / ⚙xhigh yellow / ⚙max red) + a ⟁ULTRA badge while ultracode is active.
  • Your active task (.claude/.task-state.json) and git branch in readable bright white — CLAUDE_STATUSLINE_THEME=light flips them to black for light terminals.
  • Everything fail-open; older CLIs just show fewer segments. Note: statusline.cjs is installer-only by design (consumers legitimately fork it) — existing projects keep their fork; fresh installs get the new one.

🧪 Verification

31-case updater fixture suite (throwaway git repo, never the real clone) · 15/15 hook suites · 79/79 mirror-invariants · 30/30 npm incl. fresh-install smoke · counts reconciled · the per-category fallback proven failing-first (the leak reproduced before the fix, gone after).


Full changelog: CHANGELOG.md · Previous: v1.5.1