Releases: collincusce/Clauderizer
Release list
fix: skip node preflight gates whose npm script is missing; parse node:test counts
Missing npm script → skip, not fail.
Applies to tests and build gates that fall back to the profile, when the command is npm run <script>, npm run-script <script> or npm test and package.json has no such script.
The gate is listed in gates_unrun, so it can't read as a pass it didn't earn.
Unchanged:
commands wired under [gates];
a script that exists still runs and can fail;
an unreadable package.json runs the command as before.
Node baseline test count.
The regex only matched mocha's N passing. It now also matches ℹ tests N and # tests N (node:test, spec reporter and TAP) and Tests: N passed (jest, vitest).
Preflight takes whichever alternation group matched.
This applies to new inits. An existing profile.lock.toml keeps its old regex.
2.0.3 — findings register at zero, mcp pin lifted
See CHANGELOG.md — cz_onboard content-based ownership (H-34), mcp>=1.2 both majors (H-31), absolute-path wrapper drift (H-32), cz_add_lesson project scope (H-35). Suite 1635 on both mcp majors.
2.0.2 — a drifted procedure doc can heal, and doctor stops promising
Two defects found by upgrading a real repo on published 2.0.1 — the kind
only a live walk surfaces.
- A drifted procedure doc can now heal.
refresh_procedure_doctriggered on
the config stamp rather than on the doc's own version. A repo whose
docs/gameplans/GAMEPLAN-PROCEDURE.mddrifted while its stamp stayed current
could never recover: the stamp matched the engine, so nothing refreshed, and
doctorfailed its MAJOR check forever on a file the engine owns. The trigger
is now the doc's version — which_procedure_doc_version()had been computing
all along with no caller consulting it. Bites any repo touched by the
withdrawn 3.0.0, whose procedure doc was left at 2.0.0. doctorno longer advertises an actionupgradedoes not perform. With
the docs-layout separation dormant in 2.0.1, doctor still told you to run
clauderize upgradeto separate your docs — and upgrade reported0 mechanical update(s). A shipped instruction that no-ops is the dangling-claim
class this project keeps building detectors for. The split-layout branch
stays, since it reports real state and forked stubs.
Suite 1622 → 1623. Procedure stays 1.13.0; the separation remains dormant.
2.0.1 — doctor certifies what it launched on the local leg too
doctor certifies what it launched on the local leg too. 1.14.0 retired
"MCP server launchable" — a shutil.which presence check standing in for
identity — but the replacement handshake only ever ran for portable wiring.
A repo wired to a machine-local absolute path (any venv, pipx or uv tool
install) still certified presence and called it green: H-20's false green,
surviving in the branch nobody looked at.
- Identity now runs on local wiring whenever the host of record is native and
the server can therefore be spawned, falling back to the launchability probe
only when identity is genuinely unmeasurable — a cross-host target we cannot
execute (D-010/L-59). A skewed local install now warns by name. - Found by a fresh-process test driving the real CLI (L-60: the test
process' import graph is not the CLI's execution leg). That test also
exposed why it hid for three releases:conftestsets
CLAUDERIZER_NO_SPAWN_PROBEsuite-wide, so no in-process test could have
exercised the probe end-to-end, and a naive subprocess test inherits the guard
and passes while measuring nothing. Armed red against the pre-fix branch. - Fixed:
_procedure_driftrenderedm.group(0)— the whole regex match — so a
MAJOR mismatch printedhost procedure vProcedure version**: 2.0.0. - D-083 — no version floor in the emitted
.mcp.json(resolves an open item
from 2026-07-24). A floor couples a committed, twelve-host config to release
cadence, and bounds only downward, so an older repo meeting a newer engine
sails through. The handshake catches skew both directions.
One visible change for NEW repos
clauderize init no longer scaffolds generic doc names — ARCHITECTURE,
VISION, TESTING, SECURITY, SCHEMA, DEPLOYMENT, REQUIREMENTS,
INCIDENTS, DATASOURCES, ENGINEERING-PRINCIPLES — into your docs/. Those
are the project's, and every measured naming collision lived there. They remain
available via clauderize init --seed-project-docs. Existing repos are
unaffected: a repo's recorded module list is preserved, so nothing appears or
disappears on upgrade.
Also present but dormant
The engine/project doc separation (docs/clauderizer/) is implemented and
tested but inert: docs_layout defaults to legacy, the identity default
resolves every path exactly where it always did, and nothing migrates. It ships
as capability, not as behaviour, and will be activated in a release of its own.
Suite 1599 → 1622. Procedure stays 1.13.0 — nothing procedural changed.
2.0.0 — the upgrade path itself was the last defect
2.0 finals, and the last thing it shipped was the upgrade path itself. The
mechanism set is exactly what 2.0.0b1 froze — the two alphas and the beta are
the evidence, and nothing in that set changed here. What changed is the thing
none of them had been tested on: a real 1.13.0 → 2.0 upgrade, walked with
the actual published 1.13.0 wheel instead of a fresh init.
- An upgrade delivers new doc modules, not just new stamps. 2.0 added
docs/GLOSSARY.mdanddocs/ENFORCEMENT.mdto every size manifest, and
77b5135fixed the dangling-pointer class for fresh inits only. On an
existing repo the two docs never arrived:config.merge_missingkeeps the
repo's non-emptymoduleslist,initscaffolds fromconfig.modules
alone, and the mechanical tier had no add-a-module action — so the refreshed
stanza (CLAUDE.md/AGENTS.md) pointed atdocs/ENFORCEMENT.mdand the new
clauderizer-fleetskill pointed atdocs/GLOSSARY.mdwith neither file on
disk, whiledoctorprinted✓ corpus modernized to procedure v1.12.0
over it. Measured, not theorized: the live walk is what found it. The
mechanical tier now carriesensure_modules_current— additive, writing
each doc only when absent (INVARIANT-03), idempotent (a second pass reports
0 mechanical), and recorded in the config so the delivery happens once. The
stated trade-off: the manifest is the size's contract, so a module a user
deliberately deleted comes back — as one visible line that
upgrade --reportshows before anything is written. This is
ensure_gitignore_current's own D-042 tier-1 reasoning, one level up —
"without this the whole policy fix reaches zero existing installs, and every
install in the world already raninit" — applied to the case that comment
did not cover. - The class got the detector it never had (D-069).
doctorgained
engine-referenced docs present: everydocs/<NAME>.mdthe engine's own
wiring names (the shipped stanza, the shipped skills — never the user's prose)
is checked against what the repo's manifest promises to scaffold. Docs created
on demand by a blessed write (docs/LESSONS.md,docs/SKILLS.md) are
declaredON_DEMAND_DOCSand never flagged, so a repo with no lessons yet is
correct rather than broken. - Plus the CI-time ratchet that would have caught 2.0's own defect before
release: engine wiring may only reference a doc some size manifest
scaffolds or that is declared on-demand. Armed against the real historical
tree — grafted onto77b5135^it fails naming
docs/ENFORCEMENT.md (from the shipped stanza), the exact pre-fix state. docs/UPGRADING.mdgets a 1.x → 2.0 section, and its mechanical-tier list
is now complete (it had been silently missing the gitignore and kinds-overlay
actions too). Procedure 1.13.0.- The 1.14.5 CHANGELOG entry is restored to
main. 1.14.5 was cut from a
hotfix branch that was never merged back, so this file jumped 1.14.4 →
2.0.0a1 while 1.14.5 was whatpip install clauderizeractually resolved.
The version-single-sourcing audit could not see it: that check compares the
top entry against__version__, and a hole further down is invisible to it.
Upgrading from 1.x
init + upgrade + doctor — and do not skip upgrade, which is what
delivers the two new docs. Otherwise 2.0 is additive: no cz_* tool was
removed or renamed (67 → 68), no config key changed, requires-python stays
>=3.11, the core engine keeps zero runtime dependencies, and the mechanisms
priced too expensive to default on (per-call cz_state stamps, wind-down
budgets) stay dormant by measured verdict. The one semantic break for
downstream consumers is unchanged from 2.0.0a1: pass_rate reads as goal-met
rate, with deferrals visible beside it rather than laundered into it.
Verification
- Suite 1571 → 1582 passing (7 skips). The delivery tests were armed
behaviorally red on the pre-fix tree — 3 red viamodernize.report/apply
alone, APIs present on both trees (pinning the import path, since an editable
install otherwise serves the fixed source into a pre-fix worktree: H-27's
own class, met while arming a guard against it). The CI ratchet was armed
against the real historical tree at77b5135^. Two guards are green on both
trees by design: manifest/template consistency, and silence on a
already-current corpus (INVARIANT-08 drop-nothing). - Dogfooded on this repo, whose own config was missing both modules while the
docs existed:upgradeadded the modules and leftdocs/GLOSSARY.mdand
docs/ENFORCEMENT.mdbyte-unmodified — the never-clobber property shown
rather than asserted. - Three of this repo's own ratchets fired on this change and were paid, not
widened: the subsystem-doc seam (both new public callables documented), the
separator class (both literals triagedmessagewith the reason), and the
procedure-changelog pin — which turned out to freezePROCEDURE_VERSIONat
exactly1.12.0, failing any later procedure bump for a mechanism it does not
touch; it now asserts>= 1.12.
Shipped with a named gap
- H-31 remains open, deliberately.
mcpstays constrained>=1.2,<2; the
hotfix half shipped as 1.14.5, but adapting to the mcp 2.x SDK — then lifting
the pin with tests against both majors — is unowned follow-up work. 2.0.0
ships the pin as the honest contract, not the adaptation.
2.0.0b1 — beta: the mechanism set freezes
Zero code changes over 2.0.0a2 — the promotion is the release. Two alphas survived first-party dogfood and a real foreign-repo deployment inside 48 hours: fourteen externally-vetted mechanisms graduated-or-dormant by measured verdicts (D-077/D-078/D-079 in docs/DECISIONS.md), both field-reported defects fixed and republished within a day, the a1 wiring caveat closed by the pre-release pin, and the worldwide mcp-2.0 break hotfixed on the stable line (1.14.5) along the way.
Beta means the 2.0 mechanism set and its defaults are frozen for the 2.0.0 line. What remains before final: telemetry accrual on the armed signals (gap-conversion rate, reinforce re-derivation rate, recording coverage → the budgets re-vote) and bug fixes only.
Still a PEP 440 pre-release: install with --pre or ==2.0.0b1; plain resolves keep getting stable 1.14.5.
2.0.0a2 — the field-report alpha
PEP 440 pre-release (--pre or ==2.0.0a2 to install; stable stays 1.14.5). Everything here was earned by the first real 2.0.0a1 deployments.
- Proposals explain themselves before offering "dismiss": every generated modernize proposal carries a
whatline (what a QA gate / deliverable / standing condition IS), and the modernize report +cz_dream's blocked-on-triage state state the triage semantics verbatim — dismiss is a personal, gitignored seen-it that returns on material change; nothing edits the repo. Born from a field session where the human rightly refused to dismiss an unexplained gate proposal. - A zero baseline is anomaly-shaped, not a fact: the digest's baseline line and preflight's tests gate (warn, never fail) now say with one voice that a runner exiting 0 while collecting nothing is usually a broken runner. Born from a field repo where "Baseline: 0 tests" had normalized a Node-24-broken suite into invisibility.
- Init warns when the target is $HOME (hooks wired there run in every session on the machine).
- Pre-release engines pin their portable wiring (
clauderizer[mcp]==<version>) — closes the a1 caveat where alpha-inited repos were silently served by stable; plus the audit's changelog parser now speaks PEP 440, and the fleet skill's guidance carries the measured D-079 figures and the worker branch-point verification.
Suite 1571 passing (+7 skips); new guards armed red-first; full matrix green on the tagged sha.
2.0.0a1 — the measured alpha: fourteen vetted mechanisms, graduated by evidence
PEP 440 pre-release: pip/uvx resolve this only with --pre (or an exact ==2.0.0a1 pin). Stable installs keep getting 1.14.5.
Fourteen externally-vetted mechanisms (ten Fractal-lineage, four jcode-lineage), built advisory-first under binding conditions, then graduated or deliberately kept dormant by a measured evidence matrix — never by taste. Per-mechanism verdicts with figures: D-077, D-078, D-079 in docs/DECISIONS.md; instruments committed beside the gameplan (matrix-p5-harness.py, matrix-p5-results.json).
Highlights (full detail in CHANGELOG):
- Honest endings:
deferred-with-reason as a first-class close; laundering advisory; negative-space ("What I did not check") close-outs. - Lifecycle detectors: stranded-state heal-on-proof (0 false positives across all matrix controls) and the interrupted-session backstop.
- Attention accounting: seen-vs-open receipts (drop-nothing, sidecar-gated), memory-gap detection at the moment of the gap, and the new
cz_reinforce_lessonverb (strengthen instead of duplicate). - Integrity: merge audit for canonical docs (3/3 seeded-fault detection, 0/4 false positives — advisory-silence lifted on evidence), enforcement ladder, transport-parity matrix.
- Fleet pattern productized:
clauderizer-fleetships as a wheel skill with measured guidance (D-079: quality tie solo-vs-fleet under independent adversarial verification; 1.57× wall-clock at ~1.7× compute; 0 collisions under the hub-and-spoke law). - Dormant with figures: the per-call
cz_statestamp (env-armed; DrvFs +86%/op priced default-on out) and budget wind-down (recording coverage measured first: 0.0 — dormant until post-publish telemetry). - Hardening: mcp pinned
>=1.2,<2(H-31), stamps never ratchet backward (H-30), sanitizer removals echo to the writer (H-29), fresh repos scaffold GLOSSARY + ENFORCEMENT at every size.
Suite: 1330 → 1561 passing across the alpha; every new guard armed once (violation injected, red observed, reverted).
Known alpha caveat (by design, doctor tells you): clauderize init writes the portable MCP command (uvx --from clauderizer[mcp]), which resolves the latest stable — so a repo inited by the alpha will be served by 1.14.5 over MCP until you pin the server command to clauderizer[mcp]==2.0.0a1 (or use a local install). clauderize doctor detects and explains the skew explicitly. Alpha-only surfaces (e.g. cz_reinforce_lesson) need the pinned server; everything else works either way.
1.14.5 — hotfix: pin mcp>=1.2,<2
Hotfix: the mcp dependency is now constrained >=1.2,<2. mcp 2.0.0 (released 2026-07-28) removes mcp.server.fastmcp, which broke every fresh clauderizer[mcp] install the same day — the MCP server died at import and doctor's identity handshake reported no serverInfo (H-31).
This release also ships the staged 1.14.4 feature set (job-granularity CI verification in release-check, see CHANGELOG): 1.14.4 was staged in-tree but never tagged or published, so its first appearance on any registry is inside this version.
Adapting to the mcp 2.x SDK is deliberate follow-up work; the pin is the honest immediate contract.
Full matrix evidence on this exact commit: 10/10 jobs green (ubuntu/macos/windows × py3.11–3.13 + fresh-clone).
1.14.3 — the frozen debt paid, both ratchets tighter
The frozen debt gets paid, and the lesson gets an enforcer. 1.14.2 froze two debts visibly rather than laundering them into a passing check — 32 modules with no subsystem doc, and a separator-shaped assertion class L-51 had described for three releases. Freezing was the right call then; it is not a resting place. Both are paid here, and the ratchets close behind them.
The separator class is machine-rejectable, at the point of the mistake
1.14.2 shipped three Windows cells red on assert "uv/archive-v0" in m["serving_path"] — with L-51 already recorded, and already surfaced to the session that wrote the line. Surfacing was not enough.
tests/test_separator_claims.py flags the two shapes the source itself gives evidence for: the compared-against value announcing itself a path (serving_path, a bare str(); .as_posix() exempt as the sanctioned fix), and a literal that is a fragment of an absolute-path literal in the same module. The second rule exists because the fix commit had to change two lines, and ... in digest announces nothing — catching only the obvious one would have missed half the regression. Verified against the real pre-fix blob at f9f8343^: 2 of 2 flagged.
The triage found 40, not 24
The count that scoped the work came from grepping assert "…/…" in …. An AST scan sees single-quoted literals, a second literal on one line, the arms of an or chain, and not in forms. All 40 are classified in writing — why each slash holds on Windows, not a count — and ratcheted both directions. Zero are platform claims: f9f8343 had already fixed the only real instance, and that is said plainly rather than dressed up as repair work. The false-positive floor is a test (11 shapes plus the whole real corpus), not a claim.
The exemption list goes from 32 to zero
nesting.py and engine_identity.py were both written after the doc ratchet existed and neither was ever seen by it — which is what an exemption list does. All 32 modules now carry a subsystem doc, each a tracked entity with real dependency edges, every one at 0 undocumented public callables including ops with 73.
The tightness is discontinuous, not incremental: at zero exemptions the same test flips from "the debt cannot grow" to "a new module with no doc fails immediately". Both ratchets were arm-tested against a real violation.
Suite 1232 → 1311. Every new guard demonstrated behaviorally red first — the separator detector against the pre-fix blob, the doc ratchet against the pre-1.14.3 doc set, both using only APIs present on both trees. CI green on all 9 matrix cells plus fresh-clone and the published-install-path job, at job granularity, on the exact released commit before the tag existed.