Releases: asphyx0r/git-starter-kit
Release list
v2.11.4
v2.11.4
Correct synchronization guidance for configured and legacy repositories.
Highlights
- Explain how
automations.agentRulesSynccontrols automatic synchronization. - Clarify manual updates on the default branch and legacy variable behavior.
Changes
| Reference | Date | Description | Author(s) |
|---|---|---|---|
| 138f757 | 2026-09-26 | docs(ci): clarify agent-rule sync activation | asphyx |
v2.11.3
v2.11.3
This patch strengthens repository validation, updates the locked quality toolchain, and clarifies setup and dependency maintenance.
Highlights
- Update Markdownlint CLI2 to 0.23.3, Commitlint to 21.2.3, Coverage to 7.16.1 and Ruff to 0.16.8.
- Audit every branch and tag content push and block high or critical npm vulnerabilities.
- Handle rewritten push history explicitly and isolate linked-worktree Git hooks.
- Clarify the quick start, complete Dependabot updates and reproducible lock generation.
Changes
| Reference | Date | Description | Author(s) |
|---|---|---|---|
| 4485ff8 | 2026-09-25 | build(tools): update commitlint to 21.2.3 | dependabot[bot] |
| 6903479 | 2026-09-25 | build(tools): update ruff and lock generation | dependabot[bot] |
| ab8224e | 2026-09-25 | fix(audit): update coverage and push history | dependabot[bot] |
| 7a7cfab | 2026-09-24 | fix(audit): secure CI, dependencies and hooks | asphyx |
| a97dad4 | 2026-09-15 | docs(docs): add project quick-start guide | asphyx |
v2.11.2
v2.11.2
This maintenance release corrects consumer documentation and refines the default
ignore policy. Shared project configuration and sanitized fixtures remain
trackable, with the existing cumulative upgrade strategies preserved.
Highlights
- Clarify guarded-merge activation and default-branch protections.
- Correct packaged documentation links and identify maintenance-only tests.
- Ignore approved editor recovery files, root-local credentials, and IDE state.
- Preserve shared editor configuration, contextual files, and sanitized fixtures.
Changes
| Reference | Date | Description | Author(s) |
|---|---|---|---|
| 5f66340 | 2026-09-14 | fix(templates): correct docs and ignore rules | asphyx |
v2.11.1
v2.11.1
Restore agent-rule synchronization for immutable workflow checkouts and unblock
publication of the universal repository starter ZIP.
Highlights
- Attach the default branch to the exact trusted commit before synchronization.
- Preserve support for both main and master without following a moving branch.
- Cover detached checkouts and invalid commit inputs with a regression test.
Changes
| Reference | Date | Description | Author(s) |
|---|---|---|---|
| edcfa6f | 2026-09-13 | fix(ci): attach the trusted agent sync checkout | asphyx |
v2.11.0
v2.11.0
Initialize universal projects from the enriched release ZIP, with a clear
separation between the shared repository foundation and application code.
Highlights
- Initialize on
mainwith an annotated, system-onlyv1.0.0release. - Separate core checks from project validation and explicitly enabled
automations; keep CI compatible withmainandmaster. - Preserve source tracking with conservative language-specific ignores,
document Laravel inlaravel/, and provision local quality tools. - Package verified latest agent rules and preserve cumulative upgrade
compatibility, including Windows path handling.
Changes
| Reference | Date | Description | Author(s) |
|---|---|---|---|
| faecfd2 | 2026-09-13 | fix(ci): authenticate agent-rule verification | asphyx |
| 7b197bd | 2026-09-13 | fix(validation): preserve audit and merge checks | asphyx |
| bdf23f6 | 2026-09-13 | feat(templates): support universal projects | asphyx |
Historical publication, superseded by later releases. This incomplete prerelease is retained with its original notes and tag for traceability. Use the latest stable release for installation.
v2.10.0
v2.10.0
Harden repository upgrades and release publication, enforce branch coverage and secret scanning,
and improve validation on Linux and Windows.
Highlights
- Validate upgrade inputs and provenance, and recover interrupted upgrades.
- Require the exact release-event checks before publishing sealed package assets.
- Enforce coverage and secret scanning with locked, cached toolchains.
- Correct Git Bash path identity and Windows process deadline tests.
Changes
| Reference | Date | Description | Author(s) |
|---|---|---|---|
| ce35f1a | 2026-09-08 | Validate upgrade paths, legacy manifests, payload digests and provenance. | asphyx |
| ce35f1a | 2026-09-08 | Restore interrupted upgrades and report final non-compliance as failure. | asphyx |
| ce35f1a | 2026-09-08 | Bound external commands and stream Git inventory metadata. | asphyx |
| ce35f1a | 2026-09-08 | Require exact release-event checks before publishing package assets. | asphyx |
| ce35f1a | 2026-09-08 | Enforce branch coverage and mandatory secret scanning. | asphyx |
| ce35f1a | 2026-09-08 | Select affected hook checks and validate workflow semantics across platforms. | asphyx |
| ce35f1a | 2026-09-08 | Cache locked dependencies and reduce release validation dependencies. | asphyx |
| 4b381c1 | 2026-09-08 | Accept equivalent Git Bash paths while rejecting redirected hook clones. | asphyx |
| caa282e | 2026-09-09 | Document locked CI caches and focused Windows hook checks. | asphyx |
| 19d84d0 | 2026-09-09 | Measure process deadlines after synchronous startup while preserving timeout and descendant cleanup checks. | asphyx |
v2.9.2
v2.9.2
Maintenance release updating the pinned CI and quality toolchain to
actions/checkout 7.0.1, Commitlint 21.2.2, Ruff 0.16.5, and Codespell 2.4.3,
with matching validation contracts.
Highlights
- Update actions/checkout to 7.0.1 and align workflow contracts.
- Align Commitlint 21.2.2 dependencies and validation contracts.
- Align Ruff 0.16.5 dependencies and validation contracts.
- Align Codespell 2.4.3 dependencies and validation contracts.
Changes
| Reference | Date | Description | Author(s) |
|---|---|---|---|
| 7867c7c | 2026-09-06 | chore(tools): align codespell 2.4.3 pins | dependabot[bot] |
| 51b37da | 2026-09-06 | chore(tools): align ruff 0.16.5 pins | dependabot[bot] |
| 3178e44 | 2026-09-06 | chore(tools): align commitlint 21.2.2 pins | dependabot[bot] |
| 483e802 | 2026-09-06 | chore(ci): align checkout 7.0.1 contracts | dependabot[bot] |
v2.9.1
v2.9.1
This patch corrects release validation for the modular upgrade toolkit.
The published package format and upgrade behavior remain unchanged.
Highlights
- Validate the exact nine-file toolkit inventory, including its Python modules.
- Compare that inventory with a built toolkit in a regression test.
Changes
| Reference | Date | Description | Author(s) |
|---|---|---|---|
| 6dea144 | 2026-09-06 | fix(release): align modular toolkit validation | asphyx |
v2.9.0
v2.9.0
This release adds guarded squash merges and aligns release publication with
protected branches, exact commit-message validation, and sealed package assets.
Highlights
- Validate the exact squash message with Commitlint before privileged merging.
- Read the auto-merge policy with the workflow's read-only token and fail closed
when the policy cannot be verified. - Prepare release changes through separate guarded pull requests and verify the
resulting commit, tree, and message. - Audit a dedicated preflight ref before tagging, then verify the sealed package
assets before stable release promotion.
Changes
| Reference | Date | Description | Author(s) |
|---|---|---|---|
| e2149b0 | 2026-09-06 | fix(release): align protected release workflow | asphyx |
| 1aa74bb | 2026-09-06 | fix(git): read guard policy with read-only tokens | asphyx |
| 021c0b9 | 2026-09-06 | fix(git): guard squash merge messages | asphyx |
v2.8.1
v2.8.1
Git Starter Kit v2.8.1 corrects composed release-package validation by
invoking the locked Codespell console entry point installed by the workflow.
It also keeps the unchanged-VERSION regression fixture valid across future
releases.
Highlights
- Invoke the installed Codespell CLI during composed package validation.
- Reject the unsupported
python -m codespellform in the self-audit contract. - Derive the unchanged-
VERSIONfixture ref from its current version. - Regenerate and verify the canonical v2.8.1 manifests and checksums.
Changes
| Reference | Date | Description | Author(s) |
|---|---|---|---|
| 963b1e4 | 2026-09-05 | Invoke Codespell CLI for composed package validation | asphyx |
| 963b1e4 | 2026-09-05 | Reject unsupported module invocation in the self-audit contract | asphyx |
| 83b4e0b | 2026-09-05 | Keep the unchanged-VERSION fixture valid across releases |
asphyx |
| 83b4e0b | 2026-09-05 | Regenerate and verify v2.8.1 release artifacts | asphyx |