Skip to content

v16.16.0

Choose a tag to compare

@dyoshikawa dyoshikawa released this 25 Aug 05:07
· 1495 commits to main since this release
Immutable release. Only release title and notes can be modified.
5fe3c73

What's Changed

New Features

  • Multiple input roots: generate now accepts --input-roots <paths...>, an ordered list of rulesync source trees (e.g. .rulesync .rulesync.local). Each entry is the source tree itself — the directory that directly contains rules/, skills/, mcp.jsonc — and later roots override earlier ones for the same relative path. Later roots are optional overlays and may be absent. The library API gains the matching GenerateOptions.inputRoots. The previous --input-root flag (and GenerateOptions.inputRoot) still works as a deprecated alias that expands to --input-roots <path>/.rulesync, so existing setups are unaffected. (#2714)
  • Junie: rules are now imported from .junie/rules/ and .junie/playbook.md, the shared .agents/skills root is scanned for skills, and generated subagents declare permissionMode. (#2730, #2742)
  • Factory Droid: skill packaging frontmatter is preserved through generation instead of being dropped. (#2748)
  • Muse Code: .muse/worktrees/ is added to the derived gitignore entries, and the .muse harness-state surface is recorded. (#2734)
  • Skills: the research-tool-updates skill now scouts for coding agents rulesync does not support yet and files a tracking issue for promising candidates. (#2756)

Bug Fixes

  • Rovo Dev: mcpConfigPath is only pointed at the generated project mcp.json when rulesync actually manages a startable server. Writing it unconditionally traded the user's global MCP servers for an empty project config. Authoring the pointer is now logged, unmanaged toolPermissions.bash sub-keys are preserved, and the runInSandbox: false notice is raised on every code path. (#2735)
  • Rules: an import-only rule root is read only while the tool's own root file is absent, so .junie/rules/** is no longer re-imported beside .junie/AGENTS.md and can no longer shadow the rulesync root rule. Skipped files are named in a warning, and directories ending in .md no longer fail the whole import. (#2742)
  • Skills / Subagents: cross-root de-duplication now folds case, and a folded-case collision reports which root it came from. (#2738)
  • Claude Code: managed-only sandbox paths are refused rather than emitted, and the trust warnings are aggregated into a single walk, including a warning for crossSessionInbound. (#2754)
  • Vibe: hook imports accept the pre-2.21.0 event spellings (pre_tool, post_tool, post_agent_turn), and event names that would resolve to a prototype member (e.g. __proto__, constructor) are dropped instead of keying the imported config by that member. (#2755)
  • Input roots: warning and diagnostic segments derived from input root paths are sanitized, the shadowing warning is re-armed per run, and missing overlay roots, empty roots, and local-root gitignore deferral are handled correctly. (#2752)

Security & Maintenance

  • Scoped the OIDC id-token permission to the docs deploy job, dropped it where unused, bumped the gray-matter > js-yaml override, and documented the residual supply-chain risk of the action pin scope. (#2719)

Contributors

Full Changelog

v16.15.0...v16.16.0