Skip to content

v0.15.0

Choose a tag to compare

@github-actions github-actions released this 23 Sep 23:00
· 96 commits to main since this release
36dac1b

⚠️ Upgrade note: sign in again if your CLI says "limited to the MCP surface"

hadron auth login now requests the account OAuth scope. v0.14.0 requested mcp, and since the server began enforcing scopes, a v0.14.0 browser login stores a key that every CLI command refuses (This OAuth credential is limited to the MCP surface).

If you are affected: upgrade, then run hadron auth logout && hadron auth login.

Homebrew 7 asks you to trust our tap first. If brew upgrade stops with Refusing to load cask hadron-memory/hadron-cli/hadron from untrusted tap, run this once, then upgrade again:

brew trust --cask hadron-memory/hadron-cli/hadron
brew upgrade --cask hadron

This is a Homebrew 7.0 change: non-official taps must be trusted before Homebrew loads them. Nothing changed in the cask. If you tapped it as hadron-memory/tap, trust hadron-memory/tap/hadron instead.

Can't upgrade yet? Mint a personal key on the portal's API keys page (/app/account/api-keys) and run echo $KEY | hadron auth login --with-token.

Breaking changes

  • auth login requests the account scope, and never falls back to mcp. If the server doesn't offer account, or grants a key without it, login refuses rather than storing a key the CLI can't use, and it names the portal-token route instead. (#658)
  • Skill declarations live in properties.exports.<host> (claudeSkill, codexSkill), each {name, description, enable}. enable must be true to publish. The old top-level skill/claudeSkill keys are still read, as aliases. (D12)
  • Skill collisions count only enabled declarations, per host. (#676)
  • The skill file header carries the node id, and the id is always hashed. A generated file with no or empty id= is skipped. (#650, #654, #663)
  • Skill targets no longer filter by visibility, plugin included. (D9)
  • A permission refusal exits 8, not the generic 1. Scripts that match on exit codes should handle it. (#619)

New commands & capabilities

  • hadron skill status: walks your installed skill files, pairs each with its node by id, and reports the server's drift class. --strict exits non-zero on drift, parse failures, orphans, warnings, or an empty scope. (#620)
  • hadron skill lint judges every host. Codex declarations are checked against Codex's own limits. An unknown exports key is a host-free warning (skill-unknown-host-key) and never blocks a known host. (#665, #676)
  • hadron channel register: manage Channel participation. (#636)
  • hadron team session whoami answers from the server when there's no local binding. --check asks whether the bound session is still open. (#623, #484)
  • --owned-by-me on memory list, agent list and app list. (#617, #635)
  • --role on node add and node update, routed through the node kind's governed door. (#1201)

Improvements

  • Team chat posts go through the Channel, so the CLI no longer maintains a second chat model. (#367)
  • spec lint prints each URN example's decomposition and refuses to guess an ambiguous one. (#527)
  • spec replace reports the governed specs the server skipped, instead of silently counting fewer. (#659)
  • Reading a document from - refuses an interactive terminal, so a forgotten pipe no longer hangs waiting on stdin. This covers --content -, --abstract -, --data-merge -, node import -, hadron api -, chat bodies, team session end --handoff -, coding check bodies, review run --diff -, agent prompts and ai-config files. Secrets read from - (--data-key -, ai-config --api-key -) still accept a terminal. (#643, #648)
  • The schema snapshot and tool manifest are refreshed against current hadron-server.

Bug fixes

  • Chat shows the author the server recorded, not the one implied by the address. (#630)

Full changelog: v0.14.0...v0.15.0