Skip to content

v16.13.0

Choose a tag to compare

@dyoshikawa dyoshikawa released this 18 Aug 02:22
· 1616 commits to main since this release
Immutable release. Only release title and notes can be modified.
b329a60

What's Changed

New capabilities

  • rules (devin): global non-root rules are now emitted per rule into ~/.devin/rules/*.md with their trigger/globs frontmatter, instead of the global slice being a single always-on ~/.config/devin/AGENTS.md blob. Note the upstream directory split — the per-rule global directory is the home ~/.devin/, not the ~/.config/devin/ tree the global root uses.
  • rules (kiro): directory-scoped rules are emitted as nested AGENTS.md files.
  • permissions (pi): pi is now a permissions target, emitting defaultTools.
  • permissions (antigravity-cli): agentMode can be authored in the global settings.json.
  • mcp (copilotcli): the canonical enabledTools is mapped onto Copilot CLI's tools allowlist.
  • skills (cursor): the user-invocable frontmatter field is supported.
  • hooks (grokcli): the StopCancelled event is tracked as the canonical stopCancelled.
  • hooks (hermesagent): the full 37-entry VALID_HOOKS set from v0.20.2 is tracked.

Fixes

  • permissions (claudecode), security-relevant: sandbox.* keys Claude Code honors only from user/managed/--settings scope are no longer written into a project .claude/settings.json, and sandbox.credentials.envVars/files entries with "mode": "mask" are dropped per entry at project scope. A committed mask entry is ignored by Claude Code, so it read as though a credential were masked while nothing protected it; the deny entries in the same lists, which project settings do honor, are kept.
  • rules (devin, zoocode): personal localRoot rules are emitted to AGENTS.local.md instead of being concatenated into the committed AGENTS.md. For zoocode this required making local-root dispatch subclass-aware.
  • subagents (vibe): system prompts are written to .vibe/prompts and referenced by id.
  • permissions (antigravity-cli): toolPermission and artifactReviewPolicy are filtered against their documented values on import, so a preset rulesync does not know about can no longer fail validation of the whole .rulesync/permissions.jsonc. Dropped values are now warned about rather than discarded silently.

Documentation

  • The user-invocable and disable-model-invocation notes now record that devin consumes the root-level values.
  • The canonical-vs-native MCP collision rule is documented on enabledTools and cross-referenced from the copilotcli, kiro and codexcli adapters.
  • musecode: .agents/memory/ is recorded as a deliberately excluded surface.

Dependencies

  • Bumped the all-dependencies group with 85 updates, and the all-actions group with 3 updates.

Contributors

Full Changelog

v16.12.0...v16.13.0