Repository navigation
Releases: hadron-memory/hadron-cli
Release list
v0.20.0
Improvements
team chat readnow attributes message and head-probe reads to the bound worker session when the App and deployment match. With a supporting server,advanceReadState:falseretains attribution and heartbeat while cursor acknowledgement remains after successful delivery under the existing guards.- The binding's session, App and deployment are rechecked before each attributed request. Metadata diagnostics remain headerless.
- Older servers retry reads headerless only for the specific unsupported-argument validation refusal, with a note that session attribution is unavailable. Other failures are not retried as compatibility errors.
This release preserves the v0.19.1 stale-page checks and explicit acknowledgement behavior. Session attribution requires the server read-state opt-out introduced in hadron-server#1633.
v0.19.1
Bug fixes
team chat readnow detects empty or short forward pages and newest pages that omit a message observed by an independent pre-read head probe. A suspected discrepancy exits 5, keeps returned messages visible, and advances neither local nor server read state. Retry from the original cursor.- Text and JSON expose the pre-read worker cursor, latest surviving-message head and allocator head. Unknown values are explicit. Optional App metadata cannot deny readable chat, and older servers without the backward head probe report that comparison is unavailable.
Matching samples can both be stale; this detects discrepancies rather than guaranteeing freshness or diagnosing the stale layer. Filtered and bounded reads have their documented paging semantics.
v0.19.0
New commands & capabilities
- Approve and verify node revisions with
node approveandnode verify; approve a memory's eligible nodes withmemory approve-all. - Mint individual approved nodes with
node mint.spec mintnow uses per-node minting on current servers. - Apply memory config templates with
memory config template apply, including a dry-run preview and revision checks; unlock locked rules withmemory config rule unlock.
Improvements
node getandnode revisionreads now show server-authored authorship and content-validation stamps. Node and spec reads show approval and mint status.spec listcan filter by approval and mint state with--approved,--unapproved,--minted, and--unminted.
Bug fixes
spec edit --abstract-still-accuratereports whether the server actually refreshed abstract verification, including a stale outcome.- Spec edit conflict text now explains that the server may record out-of-band drift while refusing the proposed edit.
v0.18.1
Bug fixes
secret createandsecret listnow accept only the server-supporteduserandorgowner scopes. Unsupportedappandmemoryscopes are rejected locally, and help examples reflect the supported values.
v0.18.0
Highlights
- Agent commands work with the deployed server again.
agent get,list,create, andupdateno longer query the removedAgent.personaPromptfield. This fixes the v0.17.0 failure reported in #795. - Draft spec corpora for Micromentor:
memory set --draft-corpusandspec reserve,renumber,backlinks,unresolved, andmintsupport changing citations before a one-way mint.spec lint,list,get,describe, andreplaceunderstand draft placeholders and draft-only writes. - Handoff at bind:
team session startshows the previous worker handoff after binding. - Plain rebind after lapse: an ended or lapsed local binding can be replaced without
--force. The old lapsed session stays open for its driver to end with a handoff; live bindings still get the separate-worktree guard. - Invitation compatibility:
org invite showuses the server's public invitation projection, so an invitation can be inspected before it is accepted.
New commands & capabilities
- Memory configuration:
memory config getandmemory config rule add|update|rmmanage node-role rules.memory config template list|get|create|update|rmmanages reusable rule templates. - Ownership transfers:
memory transferpreviews a free-standing memory's new owner, URN, dependencies, and blockers before an explicit apply. - Team attention:
team attentionpolls unread counts,team attention switchoverpreviews and applies a cursor handoff, andteam chat mark-readadvances your own read cursor. - Revision and export tools:
node revisionlists, reads, labels, restores, and clears revisions; skill export records revision provenance and can select individual tasks with--node. - AI configuration:
ai-config endpoints <provider>shows server-owned endpoint choices, with endpoint overrides on create and update.team session log --modelattributes individual worklog milestones to the model that produced them.
Improvements
- Safer spec editing:
spec edit --dry-runshows the actual text diff from the stored body. Saves use the revision read with the proposal;--expected-revisionguards a later approved save against intervening edits. - Typed specs:
spec new <loc> --roleaccepts an explicit spec subrole and plain title. Read and replace commands find specs marked by their governed role even when they lack the legacy spec tag; lint accepts role-only specs and human-readable names. - Skill diagnostics:
skill statusandskill exportshow the server's reason when a declaration cannot be exported.skill pluginuses the server's scope selection.
Breaking changes
- Agent prompt flags and JSON:
agentcommands use the sharedsystemPromptfield and--system-prompt/--system-prompt-file. The retired--persona-promptflags fail locally with a migration hint, and Agent JSON no longer includespersonaPrompt. - Spec lint results: the old universal content rubric (
abstract,invalidates,data-version,scaffold-body) is retired. A spec missing only those sections may now lint clean; structural checks remain.
Bug fixes
- Team chat reads: the default read takes one page, a cursorless tail stays out of read state, and bounded attention pages are drained before returning the next token.
- Server compatibility and errors: ordinary memory creates and team session reads remain usable against older servers that lack newer optional fields. Raw GraphQL errors with null entries are sanitized and mapped to the substantive server refusal.
- Stored spec text:
spec supersedeandspec extract --strip-sourcepreserve raw template placeholders when writing back; draft lint retains unreadable-placeholder errors and handles CRLF fences.
Full changelog: v0.17.0...v0.18.0
v0.17.0
New commands & capabilities
hadron skill plugin --out <dir>: builds an installable plugin per host from your enabled skill declarations. You get a Claude Code plugin (hadron/) that is also a one-plugin marketplace, and a Codex skills folder (hadron-codex/).--zipalso writes an upload-ready archive, which Cowork accepts.--nameand--scopenarrow the bundle, and--dry-runpreviews it.- The plugin version is a hash of its content, so hosts update when a skill changes.
- The command never replaces anything it didn't write.
- Specs at any loc.
spec new <loc>creates a spec at exactly that loc, with no derived parent, contract or allocation (add--inheritto link one), andspec supersede <old> --to <loc>replaces a spec with one at any loc.get,list,edit,link,find,grep,replaceandcheck-toolsno longer check the old numbering, and no command drops a spec from its output for its shape.registerlists specs outside the numbering underoutsideNumbering.
Improvements
- Node files carry the node's kind and collection.
memory exportandnode importnow carryrole,runnableandobjectType(JSON:role,isRunnable,objectType), in the same format the server's git mirror uses.- A file without these keys changes nothing on import, and neither does an empty or blank
objectType. - Import writes through the door the node's kind requires (task, spec, review), as
node addandnode updatedo. A file that would make a node two governed kinds at once is refused before anything is written,--dry-runincluded.
- A file without these keys changes nothing on import, and neither does an empty or blank
skill lintflagssyncedas a reserved name for Claude skills, in any capitalization. Claude Code keeps its own synced skills in a folder of that name, so an exported skill there would never load. The server already refuses it.skill pluginreports a host with no skills by naming the empty artifact and saying why, and offers no install line for it.spec lintno longer enforces the legacy tier obligations:parent-exists,toc-edge,inheritance-edge,index-incomplete,loc-shapeandmixed-arity.
Breaking changes
spec describeis now a neutral inventory:specs,roots,maxDepth,legacyNumberedandoutsideNumbering.- The flat/product scheme is retired, so
--jsonno longer includesscheme,source,declared,derived,products,modules, the per-tiercounts,contractsorwarnings. - A scheme stored on a memory is shown as
retiredDeclarationand never applied.
- The flat/product scheme is retired, so
spec describe --declareis retired. It is refused before any request (exit 2), and nothing is written.- Exit code: the server's
ROLE_GOVERNEDrefusal now exits 2, not 1. That's a write sent through the wrong door for a task, spec or review, or a governed revision restore that no door can make yet. It now matches the CLI's own refusal of the same case, andhadron apiexits 2 on it too.
Bug fixes
node importonto an existing task, spec or review no longer fails withROLE_GOVERNEDwhen the file says nothing about the kind.node update <task> --runnable=false, and a role change away fromspecorreview, now go through that kind's door instead of being refused.skill pluginartifacts get ordinary permissions (0755/0644under your umask) instead of the temp files' private0700/0600.
Full changelog: v0.16.0...v0.17.0
v0.16.0
New commands & capabilities
hadron skill exportwrites aSKILL.mdfor every enabled task declaration you can read. It writes to Claude Code (~/.claude/skills) and Codex (~/.agents/skills), and the server renders each file.--dry-runshows exactly what the real run would do.--forceregenerates files that export would otherwise skip.--pruneremoves orphaned skills that export wrote.- Renaming a declaration moves its skill, and disabling one removes it.
- It never replaces a
SKILL.mdit didn't write, and it refuses symlinked skills roots. - Every item is reported. If anything is refused or fails, the run exits 5 after the full report.
Improvements
- OAuth scope refusals are recognised. An MCP-only key or an unsupported scope now exits 3 with a remedy that works, and
hadron auth status/hadron token validateexplain the refusal. An ordinary permission denial is never mistaken for one. hadron spec newandhadron spec extractwrite the spec node and its edges in one request, so a failure no longer leaves an orphaned node.hadron spec supersedewires its replacement inline. It retires the old node only once it has seen thesuperseded-bylink. If it can't tell whether a step succeeded, it names the check to run instead of suggesting a blind rerun.hadron spec lintremedies now name ahadron spec linkcommand that actually runs.
Bug fixes
- The schema snapshot is refreshed, and
skillplanning omitsforceunless you pass it. - README: Homebrew 7 needs
brew trustbefore it will load thehadroncask.
Full changelog: v0.15.0...v0.16.0
v0.15.0
⚠️ Upgrade note: sign in again if your CLI says "limited to the MCP surface"
hadron auth login now requests the account OAuth scope. v0.14.0 requested mcp, and since the server began enforcing scopes, a v0.14.0 browser login stores a key that every CLI command refuses (This OAuth credential is limited to the MCP surface).
If you are affected: upgrade, then run hadron auth logout && hadron auth login.
Homebrew 7 asks you to trust our tap first. If brew upgrade stops with Refusing to load cask hadron-memory/hadron-cli/hadron from untrusted tap, run this once, then upgrade again:
brew trust --cask hadron-memory/hadron-cli/hadron
brew upgrade --cask hadronThis is a Homebrew 7.0 change: non-official taps must be trusted before Homebrew loads them. Nothing changed in the cask. If you tapped it as hadron-memory/tap, trust hadron-memory/tap/hadron instead.
Can't upgrade yet? Mint a personal key on the portal's API keys page (/app/account/api-keys) and run echo $KEY | hadron auth login --with-token.
Breaking changes
auth loginrequests theaccountscope, and never falls back tomcp. If the server doesn't offeraccount, or grants a key without it, login refuses rather than storing a key the CLI can't use, and it names the portal-token route instead. (#658)- Skill declarations live in
properties.exports.<host>(claudeSkill,codexSkill), each{name, description, enable}.enablemust betrueto publish. The old top-levelskill/claudeSkillkeys are still read, as aliases. (D12) - Skill collisions count only enabled declarations, per host. (#676)
- The skill file header carries the node id, and the id is always hashed. A generated file with no or empty
id=is skipped. (#650, #654, #663) - Skill targets no longer filter by visibility, plugin included. (D9)
- A permission refusal exits
8, not the generic1. Scripts that match on exit codes should handle it. (#619)
New commands & capabilities
hadron skill status: walks your installed skill files, pairs each with its node by id, and reports the server's drift class.--strictexits non-zero on drift, parse failures, orphans, warnings, or an empty scope. (#620)hadron skill lintjudges every host. Codex declarations are checked against Codex's own limits. An unknownexportskey is a host-free warning (skill-unknown-host-key) and never blocks a known host. (#665, #676)hadron channel register: manage Channel participation. (#636)hadron team session whoamianswers from the server when there's no local binding.--checkasks whether the bound session is still open. (#623, #484)--owned-by-meonmemory list,agent listandapp list. (#617, #635)--roleonnode addandnode update, routed through the node kind's governed door. (#1201)
Improvements
- Team chat posts go through the Channel, so the CLI no longer maintains a second chat model. (#367)
spec lintprints each URN example's decomposition and refuses to guess an ambiguous one. (#527)spec replacereports the governed specs the server skipped, instead of silently counting fewer. (#659)- Reading a document from
-refuses an interactive terminal, so a forgotten pipe no longer hangs waiting on stdin. This covers--content -,--abstract -,--data-merge -,node import -,hadron api -, chat bodies,team session end --handoff -, coding check bodies,review run --diff -, agent prompts and ai-config files. Secrets read from-(--data-key -,ai-config --api-key -) still accept a terminal. (#643, #648) - The schema snapshot and tool manifest are refreshed against current hadron-server.
Bug fixes
- Chat shows the author the server recorded, not the one implied by the address. (#630)
Full changelog: v0.14.0...v0.15.0
v0.14.0
⚠️ Upgrade required
This release is mandatory for anyone authoring specs, review checks, or runnable nodes.
hadron-server #1201/#1203 replaced the generic protected-write path with one door per node kind and deleted the old one. Against a current server, v0.13.0 and earlier now fail on:
hadron node add --runnableandhadron node updateon any runnable node — refused outright todayhadron spec new/spec edit/spec supersede/spec extractandhadron coding review create— these still work while the specs corpus is ungoverned, and stop the moment it is governed
v0.14.0 routes every one of those writes through the door its kind requires.
New commands & capabilities
hadron channel— the Channel noun and its messaging: list, create, read and post, with the register that tells you which channels an App installs.hadron scope— named search scopes.hadron search --scope <name>runs inside one, a default scope can be set, and every search now prints the scope it ran under rather than leaving you to guess at its reach.hadron org use— set the active org, and--scope globalnow means something concrete.hadron skill lint— the first verb of the skill command group: validates a skill's front matter and structure.hadron spec edit --abstract-still-accurate— assert you re-read a spec's abstract and it still describes the node. It re-sends the abstract unchanged so the server re-fingerprints it against the new body, which is the only way to settle theabstract-stalemarker a body-only edit arms. Works alongside a body edit or on its own.hadron team workercan amend a casting's prompt override, so a worker's individuality can be edited without recasting it.
Improvements
spec lintgainedindex-incomplete: a module or feature whose body omits a child's citation is reported, with the uncited locs named. The corpus convention is two-layer — the abstract routes by describing subjects, the body indexes by citing children — and this checks the second. Full citations, the last two atoms, and the colon-leaf form all count, as does a struck entry for a superseded child.spec lintchecks an abstract against its body —abstract-stalewhen the stored fingerprint disagrees with the content, andabstract-unverifiedwhen an abstract has a body but never had a fingerprint. Both matter because the abstract is the retrieval surface, so a drifted one answers a semantic query authoritatively and wrongly.abstract-length's remedy is tier-aware. At the rule tier a long abstract is a granularity signal and the fix is a supersede-level split. At the module/feature tier the abstract is an index, a split cannot move children, and the real defect is that it restates its children instead of routing to them.- A server refusal renders as the server's own sentence, not as a genqlient wrapper around it.
- Under
--json, the error envelope goes to stdout, so a parsing caller reads it from the stream it is already reading. node get --jsonemitsabstractOriginHash, so a caller can check abstract freshness without dropping tohadron api.hadron team whoamishows the user's URN, and an empty provenance result says so rather than printing nothing.hadron wherenames the column a predicate reads and shows the column it actually filtered on.- Access docs pin both server generations and state plainly that the
resourceUrnshim is compatibility-only.
Bug fixes
- A duplicate loc exits 5 (CONFLICT), not 1. The CLI's own agent contract already promised 5 for a taken loc elsewhere;
createreturning a generic failure for the same fact was a gap. Any caller branching on exit 1 for a taken loc must move to 5. hadron memory extractrefuses to scatter a memory across the repository you are standing in.hadron codingkeeps dotted tokens in a written trigger, and reports an unresolved endpoint as its own finding instead of folding it into another.
Full changelog: v0.13.0...v0.14.0
v0.13.0
Team & worker workflows land in force this release, alongside a batch of
CLI ergonomics and error-classification fixes.
New commands & capabilities
--version/-vnow print the version, alongside the existinghadron version(#393).node mv—mvalias fornode move, matchingls/rmon its siblings (#450).memory create/new/add— aliases for thememory setupsert, so the create verb is discoverable like every other noun (#308).agent create --install-into <app>installs a new agent into an App's cast pool in one run, so it is castable immediately (#543).agent create/agent update --persona-prompt-file/--system-prompt-file(and-for stdin) — supply the CLI's longest text fields from a file rather than an inline argument that a shell would mangle (#541).team worker release <name>clears the hold on a name and reports what the server actually did — the released holder, whether the team-chat announcement went out (#554, #522, #524).team worker listnow shows who holds each name and whether anyone is actively driving it (#487, #523).team chat readwalks backward:--before <seq>,--limit, and aprevBeforecursor for stable paging under a chat being posted to (#548, #556).team role list/team worker castwarn when a role definition and an agent's persona role diverge — the silent direction that used to pass unremarked (#542).team session lognames the bound worker in its receipt (✓ logged … as Vera) and in--json(workerName/workerId), so a misattributed append-only record is caught on sight (#559).coding review runbuckets the review checklist against a diff and returns the checks a change could fire, with their bodies, in one response;codingnow resolves its memory from the repository and says which source answered (#551, #561, #562).specreports abstract-length headroom and escalates at the 2000-char wall, and gains two lint rules that catch a corrupted spec (#539, #547).
Improvements
- App references are validated client-side (
--app,--install-into, theappgroup's positionals,app set-active): a bad ref is refused with a message naming the flag and the canonicalhrn:app:<root>:<slug>forms, before any request — instead of leaking the server's GraphQL internals and teaching the retired::grammar (#540). - Error classification honors the GraphQL envelope code over the HTTP status, on both the curated commands and the raw
hadron apipath — so a 4xx/5xx that carries a typed code (e.g.WORKER_TAKEN,NOT_FOUND) exits with the right code rather than a generic failure; a gateway 5xx with a real body is classified from it (#563, #544). - Required flags now say so in their usage, and a command reports the whole missing set at once rather than one flag at a time (#536, #534, #538).
- Session lifecycle is sturdier: a refused
session endno longer takes the handoff with it,session start's takeover gate reads derived liveness rather than a merely-open row, and a demoted read no longer fails a bind except where it decides one (#528, #550, #552, #553).
Bug fixes
chat post/team chat post: a missing or unreadable--body-file(or a failed--body -stdin read) now exits Usage (2), the documented contract, instead of the generic 1 (#390).
Full changelog: v0.12.0...v0.13.0