Releases: Refactron-ai/refactron
Releases · Refactron-ai/refactron
Release list
v0.4.6
What's Changed
- chore(deps): bump fast-uri and qs to patched versions
- fix(verify): 0.4.6 security — withhold SAFE for untrusted diffs + forgery/leak hardening (#161)
- docs: match the behavior-preservation claim to what SAFE proves
- docs(changelog): record constant mutation under Unreleased (#149)
- test(verify): pin the False->True constant swap (#149)
- docs(verify): expand ADR-15 with rules, budget, and warts (#149)
- test(verify): pin operators-first budget ordering (#149)
- test(verify): cover bare literals, sub-rules, inline docstrings (#149)
- test(verify): prove the killed constant mutant died (#149)
- fix(verify): fill the mutation budget operators-first (#149)
- fix(verify): exclude docstrings by AST span; tag mutant kind (#149)
- docs(verify): document constant mutation and update ADR-15 (#149)
- test(verify): keep mutation runner fixtures operator-only (#149)
- test(verify): cover constant mutation, sidecar and end-to-end (#149)
- feat(verify): mutate constants in the mutate.py sidecar (#149)
- test(verify): use a busy loop not sleep for the timeout case (#146)
- docs(changelog): stage Unreleased, drop the hook reflow (#146)
- docs(verify): match the flaky reason example to the engine string (#146)
- docs(verify): add real-repo cost and both-flags note to ADR-16 (#146)
- test(verify): pin inconclusive disclosure and C1/C3 precedence (#146)
- test(verify): stop ambient PYTHONHASHSEED flaking the tests (#146)
- fix(verify): reword the flaky reason to not overcount tests (#146)
- fix(verify): harden the stability runner and clarify varied (#146)
- docs(verify): document --flaky-check and add ADR-16 (#146)
- feat(cli): add the --flaky-check flag (#146)
- feat(verify): run the stability check in verify-diff (#146)
- feat(verify): floor SAFE on flaky-test variance (#146)
- feat(verify): add the stability-check runner (#146)
Install
npm install -g refactron@
What's Changed
- feat(verify): add --flaky-check, an opt-in stability check by @omsherikar in #148
- feat(verify): mutate constants in --mutate to catch unasserted values by @omsherikar in #151
- docs(changelog): record constant mutation under Unreleased by @omsherikar in #152
- docs: match the behavior-preservation claim to what SAFE proves by @omsherikar in #153
- fix(verify): withhold SAFE for untrusted diffs — 0.4.6 security by @omsherikar in #161
Full Changelog: v0.4.5...v0.4.6
v0.4.5
What's Changed
- chore(release): fix 0.4.5 changelog placement and sync the lockfile
- docs(verify): align mutation examples with the actual reason format
- fix(verify): keep CI env var unoverridable by a runner's envAdd
- test(verify): gate the unit hang test on win32, not just integration
- test(verify): skip the hung-mutant cases on Windows
- docs(dev-docs): amend ADR-15 with the reviewed mutation shape
- fix(verify): rework mutation per review, run mutants on fresh .pyc
- docs(release): note --mutate in the 0.4.5 changelog
- docs(verify): document --mutate in the verdicts and command guides
- feat(verify): --mutate downgrades SAFE on a surviving mutant
- feat(verify): add the mutate.py operator-mutant sidecar
- docs(dev-docs): add ADR-15, opt-in downgrade-only mutation
- chore: ignore internal strategy and launch-content docs
- docs(dev-docs): correct ADR-14 on branch-conjunct enforcement
- docs(verify): note branch gating excludes comprehensions/ternaries
- test(verify): cover multi-line and negative-arc branch attribution
- fix(verify): assert no partial branch at the SAFE gate itself
- docs(style): sharpen the comment-discipline rule against slop
- chore(release): 0.4.5
- docs(verify): document branch coverage in the verdicts guide
- fix(verify): a changed conditional's untested branch cannot earn SAFE
- docs(dev-docs): add ADR-14, branch coverage gates SAFE
Install
npm install -g refactron@
What's Changed
- fix(verify): a changed conditional's untested branch cannot earn SAFE by @omsherikar in #141
- chore: ignore internal strategy and launch-content docs by @omsherikar in #142
- feat(verify): --mutate, opt-in downgrade-only mutation testing by @omsherikar in #143
- chore(release): fix 0.4.5 changelog placement and sync the lockfile by @omsherikar in #145
Full Changelog: v0.4.4...v0.4.5
v0.4.4
What's Changed
- chore(release): sync package-lock version to 0.4.4
- chore(release): 0.4.4
- test(release): pin the changelog files to the released version
- docs(verify): correct four claims that config narrowing is not seen
- fix(verify): read pytest config when classifying test scope
- docs(release): add the missing 0.4.3 entry to the docs changelog
- test(ci): fail loudly on a permissions shape the parser cannot model
- chore(ci): scope release permissions to the jobs that need them
- test(ci): anchor the guard on run steps, not on matching text
- test(ci): build the CRLF fixture from LF, not from the checkout
- test(ci): read the workflow from a CRLF checkout too
- chore(ci): install without dependency scripts in the publish job
Install
npm install -g refactron@
What's Changed
- chore(ci): install without dependency scripts in the publish job by @omsherikar in #134
- chore(ci): scope release permissions to the jobs that need them by @omsherikar in #136
- docs(release): add the missing 0.4.3 entry to the docs changelog by @omsherikar in #138
- fix(verify): read pytest config when classifying test scope by @omsherikar in #139
Full Changelog: v0.4.3...v0.4.4
v0.4.3
What's Changed
- test(verify): stop the probe-leak test passing without an interpreter
- docs(dev-docs): stop the offensive agent calling every SAFE shift a bug
- docs(release): record the two bypasses found in review of 0.4.3
- fix(verify): resolve symlinks before trusting a diff path
- fix(verify): redact the coverage probe, not only the coverage run
- chore(release): 0.4.3
- docs(dev-docs): list the offensive agent in the roster table
- chore(dev-docs): add an offensive-security-engineer subagent
- docs(dev-docs): rewrite the security policy for the shipped product
- fix(verify): refuse diff paths that point outside the repository
- fix(verify): stop handing our credentials to the verified test suite
Install
npm install -g refactron@
What's Changed
- fix(verify): shadow tree could write to the caller's repo, plus four false SAFEs by @omsherikar in #131
- chore(release): 0.4.3 - credential redaction and diff-intake containment by @omsherikar in #132
Full Changelog: v0.4.2...v0.4.3
v0.4.2
What's Changed
- chore(release): 0.4.2
- docs(release): write the 0.4.2 changelog
- docs(docs): hedge the narrowing claim in verdicts.mdx too
- docs(docs): stop stating the narrowing check as an absolute
- fix(verify): four false SAFEs in the 0.4.1 narrowing classifier
- test(verify): assert working-tree immunity and shadow-tree containment
- fix(verify): resolve shadow-tree containment instead of spelling it
- fix(verify): clean up the shadow tree when containment rejects a change
- fix(verify): copy into the shadow tree instead of hardlinking
Install
npm install -g refactron@
Full Changelog: v0.4.1...v0.4.2
v0.4.1
What's Changed
- chore(release): 0.4.1
- docs(release): write the 0.4.1 changelog
- docs(docs): say which narrowing sources are seen and which are not
- docs(verify): state the narrowing rule in the MCP schema itself
- fix(verify): see filters arriving from the ambient environment
- docs(docs): stop documenting the unittest gap as open
- docs(dev-docs): record that ADR-12 Alternative C shipped, reshaped
- test(verify): pin the unittest false SAFE end to end
- fix(verify): recognise unittest so a single module cannot earn SAFE
- docs(docs): distinguish reportVersion from engineVersion
- docs(dev-docs): record the engineVersion naming decision as ADR-13
- refactor(verify): read the version from one place, not three
- feat(verify): stamp the producing engine version on VerdictReport
- chore(deps): clear two high advisories lockfile-only
- test(cli): assert testScope survives to --json output
- test(verify): assert testScope on the MCP surface
- test(cli): cover the test-scope note wiring in runVerifyDiffCommand
- docs(dev-docs): amend ADR-11's false doc-rollout claim
- docs(docs): state the per-statement SAFE rule the engine implements
- docs(dev-docs): require one logical change per commit
- docs(release): reserve the minor for a delivered milestone
- fix(verify): SAFE requires every coverable changed statement to run
- fix(verify): close two more false SAFEs found reviewing the scope rule
- fix(verify): floor a narrowed test command at UNPROVEN
- chore: point every reference at the renamed repo
- fix(docs): serve the MCP landing page at a URL that exists
Install
npm install -g refactron@
What's Changed
- fix(verify): a narrowed test command cannot earn SAFE by @omsherikar in #112
- fix(verify): SAFE requires every coverable changed statement by @omsherikar in #113
- docs(release): reserve the minor for a delivered milestone by @omsherikar in #114
- docs(dev-docs): require one logical change per commit by @omsherikar in #122
- docs: state the per-statement SAFE rule the engine implements by @omsherikar in #124
- test: assert testScope on the CLI, MCP and --json surfaces by @omsherikar in #125
- chore(deps): clear two high advisories lockfile-only by @omsherikar in #126
- feat(verify): stamp the producing engine version on VerdictReport by @omsherikar in #127
- fix(verify): an unparsed runner with arguments cannot earn SAFE by @omsherikar in #128
- fix(verify): catch narrowing from the ambient environment, and say so in the MCP schema by @omsherikar in #129
- chore(release): 0.4.1 by @omsherikar in #130
- chore: point every reference at the renamed repo by @omsherikar in #106
Full Changelog: v0.4.0...v0.4.1
v0.4.0
What's Changed
- docs: bring the ops docs in line with the split
- docs(py): strip the version pin from the PyPI landing page
- fix(build): make the build cross-platform
- fix(cli): apply three-lens review findings
- fix(deps): restore the cross-platform entries in the lockfile
- ci(release): drop libcst from the pre-release gate
- chore: ignore python and npm build artifacts at the repo root
- chore(release): 0.4.0, the verification-only package
- docs: rewrite for the verification product
- ci: gate the shipped product instead of self-analysis
- chore(deps): regenerate the lockfile after the dependency prune
- fix(cli): rebuild the dispatcher around verify-diff and login
- chore(split): remove the refactoring product from this repo
Install
npm install -g refactron@
What's Changed
- chore(split): ship only the verification layer by @omsherikar in #105
Full Changelog: v0.3.1...v0.4.0
v0.3.1
What's Changed
- docs(changelog): record the MCP tab and the PYTHONPATH reconciliation
- ci(release): install coverage in the pre-release test gate
- chore(release): 0.3.1
- feat(cli): align the palette with the brand, retiring the blue
- refactor(brand): settle on one cream, #E9E6DF
- feat(cli): replace the mascot with Tabslot
- feat(brand): add Tabslot, the mascot, with a validating generator
- fix(coverage): keep resolution tests off the platform that declines
- fix(coverage): decline on windows deliberately, pin the untested paths
- fix(coverage): decline shebangs we cannot reproduce exactly
- docs(verification): reconcile PYTHONPATH guidance on one form
- fix(coverage): name module form when an entry point cannot resolve
- fix(coverage): run a console script under its own interpreter
- test(coverage): skip visibly instead of returning PASSED
- fix(coverage): default testCmd to module form
- test(coverage): make the suite honest about platform differences
- fix(coverage): decline entry points we cannot spawn as the gate does
- fix(coverage): run console entry points as the gate spawns them
- fix(coverage): refuse env prefixes the gate would run differently
- fix(coverage): hoist a leading NAME=VALUE prefix off testCmd
- docs: drop plan files unrelated to the mcp tab
- docs(mcp): per-client setup prompts, copy-only, theme-correct marks
- docs(mcp): use the official mark wherever mcp is referenced
- docs(mcp): theme-aware marks, grouped client, official icon
- docs(mcp): use real client logos in the sidebar
- docs(mcp): make client marks theme-adaptive
- docs(mcp): brand logos, leading clients, copyable agent setup
- docs(vale): accept MCP client and protocol vocabulary
- docs(mcp): make verification/mcp-server a signpost to the MCP tab
- docs(nav): convert navigation to tabs and add the MCP tab
- docs(mcp): add agent instructions and verify_change reference
- docs(mcp): add MCP server pages for every major client
Install
npm install -g refactron@
What's Changed
- docs(mcp): dedicated MCP tab with per-client copy-only setup prompts by @omsherikar in #94
- fix(coverage): hoist env prefixes off testCmd, refuse the unsafe ones by @omsherikar in #97
- fix(coverage): spawn console entry points as the gate does, or decline by @omsherikar in #102
- fix(coverage): console-script interpreter parity, and decline what we cannot reproduce by @omsherikar in #103
Full Changelog: v0.3.0...v0.3.1
v0.3.0
What's Changed
- fix(ci): pin npm major and grant pypi job repo read
- fix(ci): read the wrapper version from its real source
- feat(ops): issue-first workflow and a three-lens review
- docs(agents): retarget subagents at the verification layer
- docs(preflight): code-format the classification values
- docs(dev-docs): v0.3.0 release readiness checklist
- chore(release): v0.3.0
- docs(release): add pypi release steps and the publish ordering
- docs: install from the published 0.3.0 release, not from source
- docs(release): reposition the pip wrapper readme on verification
- fix(release): resolve the node cli in the pip wrapper, never install it
- fix(release): apache-2.0 and release metadata for the pip wrapper
- style(verify): f-string in the sidecar error path
- test(verify): pin fixture line endings and normalize on read
- fix(verify): byte-exact sidecar io and a reason for unknown
- test(verify): drop version-dependent excluded-line assertion
- docs(verify): drop em dashes from the attribution rework prose
- fix(verify): attribute coverage by AST statement containment
- fix(verify): attribute coverage per statement, not physical line
- docs: accept src and sys in vale vocabulary
- docs(verify): oracle-limit example and shadow sys.path guidance
- fix(analyze): quote-aware tokenizing, report-step failure honesty
- fix(analyze): measure script-form test cmds, no fake zero coverage
- docs: accept subprocess terms in vale, use verdict casing
- revert(verify): blanket-skip pycache in shadow tree
- fix(verify): key new-file and submodule guards off disk, not diff claims
- fix(verify): match spec/mts FAIL lines in vitest summarizer (M1)
- fix(verify): retry new failures on a fresh shadow tree (I1)
- fix(verify): floor verdict at UNPROVEN when tests flaky (C1)
- docs(verify): note subprocess coverage gap and SAFE suite limits
- fix(verify): drop changed file sibling pycache in shadow tree
- fix(verify): reject anchorless, submodule, and non-UTF-8 diff inputs
- fix(verify): make tests gate flaky-aware with retry-once delta
- fix(verify): honest reason for removal-only diffs
- fix(analyze): probe coverage by module execution, not import
- fix(verify): close quoted-path empty-deletion gap from review
- fix(verify): reject deleted/renamed/binary diffs instead of dropping
- docs: accept repo and builtins in vale vocabulary
- docs: point vale at the vocabulary via explicit config
- docs: add vale vocabulary so spellcheck accepts product terms
- fix(analyze): ignore phantom coverage files, satisfy self-gate
- fix(verify): tolerate CRLF in sidecar output on Windows
- test(verify): lock fail-closed invariant for sidecar failure
- fix(verify): make imports gate delta-aware and TYPE_CHECKING-safe
- docs: quote frontmatter descriptions containing colons
- docs: normalize remaining transforms-index links
- docs: apply first-run and navigation review fixes
- docs: correct verify-path behavior claims from review
- docs: remove em-dashes across user-facing pages
- docs(concepts): add determinism illustration to why-no-llm
- docs(readme): lead with the verification layer positioning
- docs(changelog): add unreleased verify-diff, mcp, preflight entry
- docs: reframe faq, transforms intro, and reference for verify
- docs(concepts): reframe safety model and determinism for verify
- docs: reposition overview and quickstart to verification layer
- docs(verification): add verify-diff, mcp, verdicts, preflight pages
- docs(assets): add verification-layer brand marks and illustrations
- fix(verify): normalize CRLF before changed-line diff, no false SAFE
- fix(ci): install coverage.py into the python3 the tests spawn
- fix(docs): dedent Update closers so changelog.mdx parses (#76)
- fix(verify): preserve baseline-fail marker past tail truncation
- fix(verify): no false-SAFE mixed-lang, UNPROVEN no-runner, =-form flags
- test: run subprocess-heavy files serially to fix parallel flake
- feat(mcp): verify_change MCP server
- fix(cli): clean error and exit 2 on bad or empty verify-diff input
- feat(cli): verify-diff command
- feat(verify): verifyDiff — verify an arbitrary diff end-to-end
- feat(verify): three-way verdict fusion (SAFE/UNSAFE/UNPROVEN)
- fix(verify): ignore no-newline marker in changed-line derivation
- feat(verify): diff ingestion for arbitrary changes
- docs(phase2): strategy, roadmap, verifyDiff+MCP spec and plan
- docs(g0): phase-0b app-corpus results + reusable harness
- fix(preflight): guard empty-report banner + probe pytest in integration
- test(preflight): integration over a covered/uncovered sqlalchemy fixture
- feat(cli): wire preflight command into dispatcher + help
- feat(cli): add preflight command for migration safety report
- feat(cli): render migration safety report
- test(analyze): cover fail-safe verdict + safe/site assertions
- feat(analyze): safety-verdict classifier for migration sites
- chore(dev-docs): mark Model.query class-attr re-trial condition done
- chore(dev-docs): phase 0 redo — accuracy + table parity fixes
- chore(dev-docs): phase 0 redo — class-attr fix + new G0 verdict
- test(analyze): coverage tagging works for class-attr findings
- test(analyze): drop tautological line>0 assert in class-attr dedup test
- test(analyze): assert single finding per class-attr chain (no dupes)
- test(analyze): cover class-attr form across every flag reason
- feat(analyze): handle Model.query class-attr form in sqlalchemy detector
- chore(dev-docs): phase 0 G0 results — stop at threshold
- fix(analyze): normalize covered-line keys so detector lookups hit
- feat(analyze): tag sqlalchemy findings with test coverage
- feat(analyze): python line-coverage reporter via coverage.py
- feat(analyze): sqlalchemy-query detector with safe/flag classification
Install
npm install -g refactron@
What's Changed
- fix(docs): dedent Update closers so changelog.mdx parses by @omsherikar in #76
- feat(preflight): coverage-aware SQLAlchemy migration safety report by @omsherikar in #74
- feat(v0.3): SQLAlchemy migration phase 0 — detector + coverage reporter by @omsherikar in #72
- feat(verify): verifyDiff + MCP verify_change — verify any diff before it lands by @omsherikar in #75
- docs: reposition to the verification layer for AI code change by @omsherikar in #77
- fix(verify): delta-aware imports gate, no false UNSAFE on real code by @omsherikar in #78
- fix(verify): reject deletion/rename/copy/binary diffs, no false SAFE by @omsherikar in #79
- fix(analyze): probe coverage by module execution, not import by @omsherikar in #80
- fix(verify): honest reason for removal-only diffs by @omsherikar in #81
- feat(verify): flaky-aware tests gate with fresh-tree retry, UNPROVEN floor by @omsherikar in #83
- fix(verify): reject anchorless, submodule, non-UTF-8 diffs; lock shadow immunity by @omsherikar in #82
- fix(analyze): script-form coverage, honest unknowns, shadow-bypass guard by @omsherikar in #84
- docs(verify): oracle-limit example and shadow sys.path guidance by @omsherikar in #85
- fix(verify): attribute coverage by AST statement containment by @omsherikar in #86
- feat(ops): issue-first workflow and verification-aware subagents by @omsherikar in #88
- chore(release): v0.3.0 by @omsherikar in #87
- fix(ci): read the wrapper version from its real source by @omsherikar in #90
- fix(ci): pin npm major and grant pypi job repo read by @omsherikar in #93
Full Changelog: v0.2.4...v0.3.0
v0.2.4
What's Changed
- chore(release): bump refactron-py to 0.2.4 (PR #70 fixup) (#71)
- chore(release): v0.2.4
- feat(brand): filter-cascade banner in Space Grotesk
- docs: drop AI suffix; add Performance + Citations mdx pages
- docs(readme): rewrite in splice style — tighter, prose-led, fewer badges
- chore(license): relicense MIT to Apache-2.0 + rewrite README
- chore(ops): close the well-organized-team gaps
- chore(ops): scaffold senior-team operations layout
- fix(transform-sidecar): stop nested-def isinstance from inflating outer to a candidate
- test(manual-typecheck): cover the remaining two refusal paths (#57 AC)
- chore(format): prettier on manual-typecheck test
- fix(transform-sidecar): emit preconditions on every manual_typecheck refusal
- fix(cli,document): scope --files on apply; survive multi-line signatures
- fix(cli): sync run --transforms list with engine TRANSFORM_ORDER
- chore(ci): apply prettier formatting and refresh class_to_dataclass golden
- test(atomic-writer): skip POSIX mode round-trip cases on Windows
- feat(analyze): tier transforms as debt / modernization / style
- fix(transform-sidecars): emit precondition records on silent refusals
- fix(atomic-writer): preserve file mode across apply and rollback round-trips
- fix(class-to-dataclass): insert injected imports after
from __future__
Install
npm install -g refactron@
What's Changed
- feat(analyze): tier transforms as debt / modernization / style by @omsherikar in #46
- fix(cli): sync run --transforms list with engine TRANSFORM_ORDER by @omsherikar in #49
- fix(cli,document): scope --files on apply; survive multi-line signatures (#50, #51) by @omsherikar in #52
- fix(transform-sidecar): emit preconditions on every manual_typecheck refusal by @omsherikar in #58
- chore(ops): scaffold senior-team operations layout by @omsherikar in #60
- chore(license): relicense MIT to Apache-2.0 + rewrite README by @omsherikar in #61
- chore(release): v0.2.4 by @omsherikar in #70
- chore(release): bump refactron-py to 0.2.4 (PR #70 fixup) by @omsherikar in #71
Full Changelog: v0.2.3...v0.2.4