1.2.8 — Technical Debt
VelinStyle 1.2.8 — Technical Debt
Audit follow-up after docs/internal/CODE_AUDIT_2026-08-06.md. Focus: honest metrics, check integration, tests — not new product surface.
Highlights
velinstyle checkruns a security step (doctor-mode engine)publish.pack-dry-run—npm pack --dry-runwith timeout / missing-npm warnings- Lockfile findings use
no-lockfile(not mislabeled “outdated”) - Malware category for lifecycle/typosquat; empty malware score is n/a
- Motion V2 triggers:
planned+runtime: false, visible fallback documented - Experience
--helpincludesdesign(Motion) npm run test:securityincludestests/security.test.js
npx velinstyle check .
npx velinstyle security publish
npx velinstyle --helpGuide: docs/guides/velin-security.md
Not in 1.2.8
- Live
npm outdated - Motion Studio / true V2 trigger runtime
- npm publish / GitHub Release (local pin only until you ship)