Skip to content

Releases: collincusce/Clauderizer

fix: skip node preflight gates whose npm script is missing; parse node:test counts

Choose a tag to compare

@collincusce collincusce released this 05 Oct 09:52
af66855

Missing npm script → skip, not fail.
Applies to tests and build gates that fall back to the profile, when the command is npm run <script>, npm run-script <script> or npm test and package.json has no such script.
The gate is listed in gates_unrun, so it can't read as a pass it didn't earn.
Unchanged:
commands wired under [gates];
a script that exists still runs and can fail;
an unreadable package.json runs the command as before.
Node baseline test count.
The regex only matched mocha's N passing. It now also matches ℹ tests N and # tests N (node:test, spec reporter and TAP) and Tests: N passed (jest, vitest).
Preflight takes whichever alternation group matched.
This applies to new inits. An existing profile.lock.toml keeps its old regex.

2.0.3 — findings register at zero, mcp pin lifted

Choose a tag to compare

@collincusce collincusce released this 31 Jul 22:49

See CHANGELOG.md — cz_onboard content-based ownership (H-34), mcp>=1.2 both majors (H-31), absolute-path wrapper drift (H-32), cz_add_lesson project scope (H-35). Suite 1635 on both mcp majors.

2.0.2 — a drifted procedure doc can heal, and doctor stops promising

Choose a tag to compare

@collincusce collincusce released this 31 Jul 20:07

Two defects found by upgrading a real repo on published 2.0.1 — the kind
only a live walk surfaces.

  • A drifted procedure doc can now heal. refresh_procedure_doc triggered on
    the config stamp rather than on the doc's own version. A repo whose
    docs/gameplans/GAMEPLAN-PROCEDURE.md drifted while its stamp stayed current
    could never recover: the stamp matched the engine, so nothing refreshed, and
    doctor failed its MAJOR check forever on a file the engine owns. The trigger
    is now the doc's version — which _procedure_doc_version() had been computing
    all along with no caller consulting it. Bites any repo touched by the
    withdrawn 3.0.0, whose procedure doc was left at 2.0.0.
  • doctor no longer advertises an action upgrade does not perform. With
    the docs-layout separation dormant in 2.0.1, doctor still told you to run
    clauderize upgrade to separate your docs — and upgrade reported 0 mechanical update(s). A shipped instruction that no-ops is the dangling-claim
    class this project keeps building detectors for. The split-layout branch
    stays, since it reports real state and forked stubs.

Suite 1622 → 1623. Procedure stays 1.13.0; the separation remains dormant.

2.0.1 — doctor certifies what it launched on the local leg too

Choose a tag to compare

@collincusce collincusce released this 31 Jul 19:30

doctor certifies what it launched on the local leg too. 1.14.0 retired
"MCP server launchable" — a shutil.which presence check standing in for
identity — but the replacement handshake only ever ran for portable wiring.
A repo wired to a machine-local absolute path (any venv, pipx or uv tool
install) still certified presence and called it green: H-20's false green,
surviving in the branch nobody looked at.

  • Identity now runs on local wiring whenever the host of record is native and
    the server can therefore be spawned, falling back to the launchability probe
    only when identity is genuinely unmeasurable — a cross-host target we cannot
    execute (D-010/L-59). A skewed local install now warns by name.
  • Found by a fresh-process test driving the real CLI (L-60: the test
    process' import graph is not the CLI's execution leg
    ). That test also
    exposed why it hid for three releases: conftest sets
    CLAUDERIZER_NO_SPAWN_PROBE suite-wide, so no in-process test could have
    exercised the probe end-to-end, and a naive subprocess test inherits the guard
    and passes while measuring nothing. Armed red against the pre-fix branch.
  • Fixed: _procedure_drift rendered m.group(0) — the whole regex match — so a
    MAJOR mismatch printed host procedure vProcedure version**: 2.0.0.
  • D-083 — no version floor in the emitted .mcp.json (resolves an open item
    from 2026-07-24). A floor couples a committed, twelve-host config to release
    cadence, and bounds only downward, so an older repo meeting a newer engine
    sails through. The handshake catches skew both directions.

One visible change for NEW repos

clauderize init no longer scaffolds generic doc names — ARCHITECTURE,
VISION, TESTING, SECURITY, SCHEMA, DEPLOYMENT, REQUIREMENTS,
INCIDENTS, DATASOURCES, ENGINEERING-PRINCIPLES — into your docs/. Those
are the project's, and every measured naming collision lived there. They remain
available via clauderize init --seed-project-docs. Existing repos are
unaffected
: a repo's recorded module list is preserved, so nothing appears or
disappears on upgrade.

Also present but dormant

The engine/project doc separation (docs/clauderizer/) is implemented and
tested but inert: docs_layout defaults to legacy, the identity default
resolves every path exactly where it always did, and nothing migrates. It ships
as capability, not as behaviour, and will be activated in a release of its own.

Suite 1599 → 1622. Procedure stays 1.13.0 — nothing procedural changed.

2.0.0 — the upgrade path itself was the last defect

Choose a tag to compare

@collincusce collincusce released this 30 Jul 05:49

2.0 finals, and the last thing it shipped was the upgrade path itself. The
mechanism set is exactly what 2.0.0b1 froze — the two alphas and the beta are
the evidence, and nothing in that set changed here. What changed is the thing
none of them had been tested on: a real 1.13.0 → 2.0 upgrade, walked with
the actual published 1.13.0 wheel instead of a fresh init.

  • An upgrade delivers new doc modules, not just new stamps. 2.0 added
    docs/GLOSSARY.md and docs/ENFORCEMENT.md to every size manifest, and
    77b5135 fixed the dangling-pointer class for fresh inits only. On an
    existing repo the two docs never arrived: config.merge_missing keeps the
    repo's non-empty modules list, init scaffolds from config.modules
    alone, and the mechanical tier had no add-a-module action — so the refreshed
    stanza (CLAUDE.md/AGENTS.md) pointed at docs/ENFORCEMENT.md and the new
    clauderizer-fleet skill pointed at docs/GLOSSARY.md with neither file on
    disk
    , while doctor printed ✓ corpus modernized to procedure v1.12.0
    over it. Measured, not theorized: the live walk is what found it. The
    mechanical tier now carries ensure_modules_current — additive, writing
    each doc only when absent (INVARIANT-03), idempotent (a second pass reports
    0 mechanical), and recorded in the config so the delivery happens once. The
    stated trade-off: the manifest is the size's contract, so a module a user
    deliberately deleted comes back — as one visible line that
    upgrade --report shows before anything is written. This is
    ensure_gitignore_current's own D-042 tier-1 reasoning, one level up —
    "without this the whole policy fix reaches zero existing installs, and every
    install in the world already ran init"
    — applied to the case that comment
    did not cover.
  • The class got the detector it never had (D-069). doctor gained
    engine-referenced docs present: every docs/<NAME>.md the engine's own
    wiring names (the shipped stanza, the shipped skills — never the user's prose)
    is checked against what the repo's manifest promises to scaffold. Docs created
    on demand by a blessed write (docs/LESSONS.md, docs/SKILLS.md) are
    declared ON_DEMAND_DOCS and never flagged, so a repo with no lessons yet is
    correct rather than broken.
  • Plus the CI-time ratchet that would have caught 2.0's own defect before
    release
    : engine wiring may only reference a doc some size manifest
    scaffolds or that is declared on-demand. Armed against the real historical
    tree
    — grafted onto 77b5135^ it fails naming
    docs/ENFORCEMENT.md (from the shipped stanza), the exact pre-fix state.
  • docs/UPGRADING.md gets a 1.x → 2.0 section, and its mechanical-tier list
    is now complete (it had been silently missing the gitignore and kinds-overlay
    actions too). Procedure 1.13.0.
  • The 1.14.5 CHANGELOG entry is restored to main. 1.14.5 was cut from a
    hotfix branch that was never merged back, so this file jumped 1.14.4 →
    2.0.0a1 while 1.14.5 was what pip install clauderizer actually resolved.
    The version-single-sourcing audit could not see it: that check compares the
    top entry against __version__, and a hole further down is invisible to it.

Upgrading from 1.x

init + upgrade + doctor — and do not skip upgrade, which is what
delivers the two new docs. Otherwise 2.0 is additive: no cz_* tool was
removed or renamed (67 → 68), no config key changed, requires-python stays
>=3.11, the core engine keeps zero runtime dependencies, and the mechanisms
priced too expensive to default on (per-call cz_state stamps, wind-down
budgets) stay dormant by measured verdict. The one semantic break for
downstream consumers is unchanged from 2.0.0a1: pass_rate reads as goal-met
rate
, with deferrals visible beside it rather than laundered into it.

Verification

  • Suite 1571 → 1582 passing (7 skips). The delivery tests were armed
    behaviorally red on the pre-fix tree — 3 red via modernize.report/apply
    alone, APIs present on both trees (pinning the import path, since an editable
    install otherwise serves the fixed source into a pre-fix worktree: H-27's
    own class, met while arming a guard against it). The CI ratchet was armed
    against the real historical tree at 77b5135^. Two guards are green on both
    trees by design: manifest/template consistency, and silence on a
    already-current corpus (INVARIANT-08 drop-nothing).
  • Dogfooded on this repo, whose own config was missing both modules while the
    docs existed: upgrade added the modules and left docs/GLOSSARY.md and
    docs/ENFORCEMENT.md byte-unmodified — the never-clobber property shown
    rather than asserted.
  • Three of this repo's own ratchets fired on this change and were paid, not
    widened: the subsystem-doc seam (both new public callables documented), the
    separator class (both literals triaged message with the reason), and the
    procedure-changelog pin — which turned out to freeze PROCEDURE_VERSION at
    exactly 1.12.0, failing any later procedure bump for a mechanism it does not
    touch; it now asserts >= 1.12.

Shipped with a named gap

  • H-31 remains open, deliberately. mcp stays constrained >=1.2,<2; the
    hotfix half shipped as 1.14.5, but adapting to the mcp 2.x SDK — then lifting
    the pin with tests against both majors — is unowned follow-up work. 2.0.0
    ships the pin as the honest contract, not the adaptation.

2.0.0b1 — beta: the mechanism set freezes

Choose a tag to compare

@collincusce collincusce released this 30 Jul 04:37

Zero code changes over 2.0.0a2 — the promotion is the release. Two alphas survived first-party dogfood and a real foreign-repo deployment inside 48 hours: fourteen externally-vetted mechanisms graduated-or-dormant by measured verdicts (D-077/D-078/D-079 in docs/DECISIONS.md), both field-reported defects fixed and republished within a day, the a1 wiring caveat closed by the pre-release pin, and the worldwide mcp-2.0 break hotfixed on the stable line (1.14.5) along the way.

Beta means the 2.0 mechanism set and its defaults are frozen for the 2.0.0 line. What remains before final: telemetry accrual on the armed signals (gap-conversion rate, reinforce re-derivation rate, recording coverage → the budgets re-vote) and bug fixes only.

Still a PEP 440 pre-release: install with --pre or ==2.0.0b1; plain resolves keep getting stable 1.14.5.

2.0.0a2 — the field-report alpha

Pre-release

Choose a tag to compare

@collincusce collincusce released this 29 Jul 06:54

PEP 440 pre-release (--pre or ==2.0.0a2 to install; stable stays 1.14.5). Everything here was earned by the first real 2.0.0a1 deployments.

  • Proposals explain themselves before offering "dismiss": every generated modernize proposal carries a what line (what a QA gate / deliverable / standing condition IS), and the modernize report + cz_dream's blocked-on-triage state state the triage semantics verbatim — dismiss is a personal, gitignored seen-it that returns on material change; nothing edits the repo. Born from a field session where the human rightly refused to dismiss an unexplained gate proposal.
  • A zero baseline is anomaly-shaped, not a fact: the digest's baseline line and preflight's tests gate (warn, never fail) now say with one voice that a runner exiting 0 while collecting nothing is usually a broken runner. Born from a field repo where "Baseline: 0 tests" had normalized a Node-24-broken suite into invisibility.
  • Init warns when the target is $HOME (hooks wired there run in every session on the machine).
  • Pre-release engines pin their portable wiring (clauderizer[mcp]==<version>) — closes the a1 caveat where alpha-inited repos were silently served by stable; plus the audit's changelog parser now speaks PEP 440, and the fleet skill's guidance carries the measured D-079 figures and the worker branch-point verification.

Suite 1571 passing (+7 skips); new guards armed red-first; full matrix green on the tagged sha.

2.0.0a1 — the measured alpha: fourteen vetted mechanisms, graduated by evidence

Choose a tag to compare

@collincusce collincusce released this 28 Jul 19:05

PEP 440 pre-release: pip/uvx resolve this only with --pre (or an exact ==2.0.0a1 pin). Stable installs keep getting 1.14.5.

Fourteen externally-vetted mechanisms (ten Fractal-lineage, four jcode-lineage), built advisory-first under binding conditions, then graduated or deliberately kept dormant by a measured evidence matrix — never by taste. Per-mechanism verdicts with figures: D-077, D-078, D-079 in docs/DECISIONS.md; instruments committed beside the gameplan (matrix-p5-harness.py, matrix-p5-results.json).

Highlights (full detail in CHANGELOG):

  • Honest endings: deferred-with-reason as a first-class close; laundering advisory; negative-space ("What I did not check") close-outs.
  • Lifecycle detectors: stranded-state heal-on-proof (0 false positives across all matrix controls) and the interrupted-session backstop.
  • Attention accounting: seen-vs-open receipts (drop-nothing, sidecar-gated), memory-gap detection at the moment of the gap, and the new cz_reinforce_lesson verb (strengthen instead of duplicate).
  • Integrity: merge audit for canonical docs (3/3 seeded-fault detection, 0/4 false positives — advisory-silence lifted on evidence), enforcement ladder, transport-parity matrix.
  • Fleet pattern productized: clauderizer-fleet ships as a wheel skill with measured guidance (D-079: quality tie solo-vs-fleet under independent adversarial verification; 1.57× wall-clock at ~1.7× compute; 0 collisions under the hub-and-spoke law).
  • Dormant with figures: the per-call cz_state stamp (env-armed; DrvFs +86%/op priced default-on out) and budget wind-down (recording coverage measured first: 0.0 — dormant until post-publish telemetry).
  • Hardening: mcp pinned >=1.2,<2 (H-31), stamps never ratchet backward (H-30), sanitizer removals echo to the writer (H-29), fresh repos scaffold GLOSSARY + ENFORCEMENT at every size.

Suite: 1330 → 1561 passing across the alpha; every new guard armed once (violation injected, red observed, reverted).

Known alpha caveat (by design, doctor tells you): clauderize init writes the portable MCP command (uvx --from clauderizer[mcp]), which resolves the latest stable — so a repo inited by the alpha will be served by 1.14.5 over MCP until you pin the server command to clauderizer[mcp]==2.0.0a1 (or use a local install). clauderize doctor detects and explains the skew explicitly. Alpha-only surfaces (e.g. cz_reinforce_lesson) need the pinned server; everything else works either way.

1.14.5 — hotfix: pin mcp>=1.2,<2

Choose a tag to compare

@collincusce collincusce released this 28 Jul 18:57

Hotfix: the mcp dependency is now constrained >=1.2,<2. mcp 2.0.0 (released 2026-07-28) removes mcp.server.fastmcp, which broke every fresh clauderizer[mcp] install the same day — the MCP server died at import and doctor's identity handshake reported no serverInfo (H-31).

This release also ships the staged 1.14.4 feature set (job-granularity CI verification in release-check, see CHANGELOG): 1.14.4 was staged in-tree but never tagged or published, so its first appearance on any registry is inside this version.

Adapting to the mcp 2.x SDK is deliberate follow-up work; the pin is the honest immediate contract.

Full matrix evidence on this exact commit: 10/10 jobs green (ubuntu/macos/windows × py3.11–3.13 + fresh-clone).

1.14.3 — the frozen debt paid, both ratchets tighter

Choose a tag to compare

@collincusce collincusce released this 26 Jul 04:57

The frozen debt gets paid, and the lesson gets an enforcer. 1.14.2 froze two debts visibly rather than laundering them into a passing check — 32 modules with no subsystem doc, and a separator-shaped assertion class L-51 had described for three releases. Freezing was the right call then; it is not a resting place. Both are paid here, and the ratchets close behind them.

The separator class is machine-rejectable, at the point of the mistake

1.14.2 shipped three Windows cells red on assert "uv/archive-v0" in m["serving_path"] — with L-51 already recorded, and already surfaced to the session that wrote the line. Surfacing was not enough.

tests/test_separator_claims.py flags the two shapes the source itself gives evidence for: the compared-against value announcing itself a path (serving_path, a bare str(); .as_posix() exempt as the sanctioned fix), and a literal that is a fragment of an absolute-path literal in the same module. The second rule exists because the fix commit had to change two lines, and ... in digest announces nothing — catching only the obvious one would have missed half the regression. Verified against the real pre-fix blob at f9f8343^: 2 of 2 flagged.

The triage found 40, not 24

The count that scoped the work came from grepping assert "…/…" in …. An AST scan sees single-quoted literals, a second literal on one line, the arms of an or chain, and not in forms. All 40 are classified in writing — why each slash holds on Windows, not a count — and ratcheted both directions. Zero are platform claims: f9f8343 had already fixed the only real instance, and that is said plainly rather than dressed up as repair work. The false-positive floor is a test (11 shapes plus the whole real corpus), not a claim.

The exemption list goes from 32 to zero

nesting.py and engine_identity.py were both written after the doc ratchet existed and neither was ever seen by it — which is what an exemption list does. All 32 modules now carry a subsystem doc, each a tracked entity with real dependency edges, every one at 0 undocumented public callables including ops with 73.

The tightness is discontinuous, not incremental: at zero exemptions the same test flips from "the debt cannot grow" to "a new module with no doc fails immediately". Both ratchets were arm-tested against a real violation.


Suite 1232 → 1311. Every new guard demonstrated behaviorally red first — the separator detector against the pre-fix blob, the doc ratchet against the pre-1.14.3 doc set, both using only APIs present on both trees. CI green on all 9 matrix cells plus fresh-clone and the published-install-path job, at job granularity, on the exact released commit before the tag existed.