Skip to content

Releases: hannsxpeter/godpowers

Godpowers 6.3.0

Choose a tag to compare

@hannsxpeter hannsxpeter released this 19 Aug 15:50
c45d047

Godpowers 6.3.0 Release

Status: Published and verified
Date: 2026-08-19

  • [DECISION] Godpowers 6.3.0 adds explicit evidence and authority contracts to runtime verification, debugging, program design, archaeology, durable decision history, and command routing.
  • [DECISION] The release retains 124 slash commands, 41 specialist agents, 13 workflows, and 45 recipes.
  • [DECISION] The core package contains 117 runtime library modules and keeps zero root production, optional, or peer dependencies.
  • [DECISION] The repository contains 117 focused test scripts and 54 core reference documents.
  • [DECISION] The root package-content check reports 659 files, including the new dependency-free validators and the optional operations pack publication surface.
  • [DECISION] The root godpowers package supports Node.js 18 or newer, while the read-only @godpowers/mcp companion requires Node.js 20 or newer; both manifests declare version 6.3.0.

Engineering Evidence Contracts

  • [DECISION] /god-test-runtime now selects one material verification profile for CLI, SDK, API, UI, service, or library products and rejects incomplete or generic completion evidence.
  • [DECISION] Existing test-only, audit-only, and a11y-only runtime modes remain available and keep their previous identifiers.
  • [DECISION] /god-debug requires an executed deterministic reproduction before hypothesis formation, requires a changed prediction after each failed hypothesis, and stops repeated tests that produce no new information.
  • [DECISION] Medium and large program designs now name callers and dependents, design pressures, at least two distinct alternative shapes, one selected shape, and a rule that returns the work to planning after the same design deviation occurs twice.
  • [DECISION] /god-archaeology --why <target> validates bounded cited evidence from independent source categories, calibrates confidence, rejects contradictions and unknowns, and leaves default archaeology unchanged when --why is absent.

Durable Decisions And Invocation Authority

  • [DECISION] decision.recorded extends the existing event vocabulary with a bounded allowlisted record for the decision, reason, cited evidence, result, and constrained metadata.
  • [DECISION] The writer, generic emitter, and reader share one validator, reject secret-bearing fields and provider tokens, and reject HTTPS authority credentials, every query string, and unsafe fragments without echoing rejected values.
  • [DECISION] /god-trace --decisions verifies and parses one immutable snapshot per selected run, returns { items, integrityFailures }, retains the newest bounded decision and run windows, and does not claim authentication, full recomputation detection, or tail-truncation detection from the local hash chain.
  • [DECISION] Every one of the 124 canonical route files declares one policy from explicit-only, suggestible, auto-local, auto-bounded, or approval-required.
  • [DECISION] Router loading and route-quality checks derive command identity from canonical filenames and reject route metadata spoofing, duplicate commands, and noncanonical route YAML.
  • [DECISION] External, destructive, dependency, recovery, and release actions remain approval-required.

Optional Operations Pack

  • [DECISION] @godpowers/operations-pack version 0.1.0 adds issue-triage and human-only setup skills without adding a core command or root runtime dependency.
  • [DECISION] Issue triage verifies the complete item, recommends exactly one category and one state, and waits for explicit maintainer approval before any tracker mutation or separately approved story creation.
  • [DECISION] The setup wizard inspects the repository first, verifies exact URLs and repository authority, statically checks generated Bash, keeps secrets off command arguments, rejects tracked environment destinations, and requires exact YES for irreversible steps.
  • [DECISION] The shell helpers validate keys and values, quote environment values, preserve existing files, publish through temporary replacement, clean up on failure, and propagate filtering, write, permission, and rename errors.

Independent Authorship And License Boundary

  • [DECISION] Product-form verification, bounded why evidence, and architecture-pressure ideas were informed by the MIT-licensed pstack skills linked from INSPIRATION.md.
  • [DECISION] Feedback-loop debugging, deeper program design, alternative shapes, issue triage, and setup guidance were informed by the MIT-licensed Matt Pocock engineering skills linked from INSPIRATION.md.
  • [DECISION] Godpowers independently authored every validator, contract, template, fixture, test, and result; no upstream prose, code, template, fixture, or result is copied or vendored, and neither source is a runtime dependency.

Release Hardening

  • [DECISION] The OWASP Web Top 10:2025 walkthrough found one Critical workflow-input boundary, two High filesystem and remote-target boundaries, and three Medium fail-closed, recovery-integrity, and resource-bound groups; every finding was repaired before publication.
  • [DECISION] Manual extension-pack inputs now cross into Bash only through environment variables, then pass an explicit pack allowlist and strict SemVer validation before identity checks or npm credentials are available.
  • [DECISION] Event history stays under the selected project root, rejects linked run paths, and caps snapshots at 8 MiB and 50,000 lines.
  • [DECISION] SkillUI validates remote targets but never passes a URL or remote repository location to the external CLI; remote forms fail closed and require an already reviewed local directory because subprocess redirects and DNS answers cannot be pinned.
  • [DECISION] Unknown route prerequisite predicates fail closed, and the four named non-prefixed predicates used by core routes now have explicit behavior.
  • [DECISION] Verification profiles, debug feedback records, recursive scans, and event snapshots enforce bounded collection, depth, node, byte, and line limits.
  • [DECISION] Root and MCP recovery publication compares registry dist.integrity and dist.shasum to the exact packed candidates before either package can be promoted to latest.
  • [DECISION] The repaired release has zero unresolved Critical, High, Medium, or Low findings; the fresh hardening artifact hash, executed evidence, and full release suite all passed before publication.

Observed Validation

  • [DECISION] Product-form verification passed 10 of 10 focused tests.
  • [DECISION] Debug feedback-loop validation passed 18 of 18 focused tests.
  • [DECISION] Program-design validation passed 14 of 14 focused tests, with the integrated gate suite also passing 28 of 28.
  • [DECISION] Why-evidence validation passed 11 of 11 focused tests.
  • [DECISION] Event writing and decision projection passed 25 of 25 tests each.
  • [DECISION] Invocation-policy, router, and automation-surface suites passed 7 of 7, 47 of 47, and 17 of 17 tests.
  • [DECISION] SkillUI remote-target validation passed 27 of 27 focused tests, including HTTP, internal, metadata, mixed-address, public-URL, and public-repository rejection before dispatch.
  • [DECISION] Operations-pack tests passed 7 of 7, extension publication readiness passed 81 of 81, static checks passed 35 of 35, and package contents passed at 659 files.
  • [DECISION] Every implementation slice passed an independent Stage 1 specification review and Stage 2 quality review after adversarial repairs.
  • [DECISION] npm run release:check passed 121 commands and 3,290 tests with 94.70 percent line coverage, 80.75 percent branch coverage, and 97.32 percent function coverage.
  • [DECISION] The release gate also passed official skill validation, Pillars conformance, per-file coverage, zero-vulnerability production audit, live advisory checks, the 140-check self-project truth gate, evidence drift, the 659-file root package check, and the 8-file MCP package check.
  • [DECISION] The final harden gate passed with one executed-backed release command, all ten OWASP rows cited to ledger evidence, and no warning or error finding.
  • [DECISION] The fresh pre-publication gate passed against hardening revision sha256:69bd088dc44e405b144536bd51701088bb0da7d5e2200685e9b3e13be7403f5f with zero unresolved or accepted Critical findings.
  • [DECISION] Pull request 97, pull-request CI run 32271677551, and merged-main CI run 32272127234 passed against release commit c45d0473ad946fcd7c02a5706b02f51a40ed0d25.
  • [DECISION] Annotated tags v6.3.0 and operations-pack-v0.1.0 both resolve to the exact merged release commit.
  • [DECISION] Provenance workflow 32272150358 published and promoted the exact godpowers@6.3.0 and @godpowers/mcp@6.3.0 pair after release, prepublication, integrity, and shasum checks passed.
  • [DECISION] Provenance workflow 32272475321 published @godpowers/operations-pack@0.1.0 after merged-tag identity, pack-readiness, and fresh prepublication checks passed.
  • [DECISION] GitHub Release v6.3.0 was published at 2026-08-19T15:50:34Z from the annotated release tag.

Upgrade

  • [DECISION] Root CLI and MCP users need no state migration, artifact migration, command rename, or production dependency change for 6.3.0.
  • [DECISION] Install the release with npm install -g godpowers@6.3.0 or run it with npx godpowers@6.3.0.
  • [DECISION] Root CLI users continue to need Node.js 18 or newer, and MCP users continue to need Node.js 20 or newer.
  • [DECISION] Existing extension packs remain compatible with the Godpowers 6.x peer range; the optional operations pack requires explicit installation.

Publication Evidence

  • [DECISION] Pull request: https://github.com/hannsxpeter/godpowers/pull/97.
  • [DECISION] Release commit: c45d0473ad946fcd7c02a5706b02f51a40ed0d25, merged at 2026-08-19T15:47:11Z.
  • [DECISION] Pull-request CI: https://github.com/hannsxpeter/godpowers/actions/runs/32271677551.
  • [DECISION] Merged-main CI: `https://github.com/hannsxpeter/godpowers/ac...
Read more

Godpowers 6.2.0

Choose a tag to compare

@hannsxpeter hannsxpeter released this 19 Aug 10:25
010f02d

Blast-radius review hardening release. Godpowers now requires Stage 2 to prove
one load-bearing safety fact across repository and delivery boundaries instead
of treating direct callers, static search, or reviewer agreement as behavioral
proof.

Added

  • Shared references/building/BLAST-RADIUS.md protocol with one load-bearing
    safety fact, evidence levels 1 through 5, Confirmed Risks, Cleared Risks,
    Unproven Claims, runtime applicability, and a 10-class boundary inventory.
  • Read-only lib/evidence.resolveReviewEvidence projection. It matches one
    executed record by claim, exact command, canonical substep, verdict, and
    freshness, then verifies its SHA-256 digest-bound gate event and event chain
    without returning raw claims, commands, or output tails.
  • Six adversarial temporary-repository fixtures for pinned dependency behavior,
    lifecycle ordering, serialized consumers, installed-copy drift, package
    omission, and cross-language invocation. Fixture subprocesses fail closed at
    a 10-second timeout or 1 MiB output cap.

Changed

  • Evidence levels 1 through 3 remain UNPROVEN; level 4 requires a focused
    godpowers verify probe, and level 5 requires an applicable reproduction
    through the running or installed delivery boundary.
  • High-impact UNPROVEN claims now fail Stage 2. Lower-impact uncertainty
    remains a warning with one exact next proof.
  • Changes crossing at least 3 boundary classes or at least 2 high-impact
    classes now receive at least 2 independent fresh-context safety cases, even
    after a provisional first-pass failure. Bounded changes keep 1 Stage 2 pass.
  • lib/impact.js now labels its results as unproven static candidates with
    maximum evidence level 2. The existing /god-review, /god-build,
    verification ledger, state rollup, and public command surface remain in
    place.
  • The package now ships the shared protocol through the existing references/
    tree. This release adds no slash command, CLI operation, route, workflow,
    specialist, production dependency, evidence store, state writer, or
    execution authority.
  • The protocol and fixtures were authored independently after reviewing
    pstack's MIT-licensed blast-radius skill. No upstream prose, code, fixture,
    result, or runtime dependency is copied or shipped.

Security

  • Executed verification records retain their existing shape. Gate events add
    record ID and record digest bindings so altered, missing, duplicate, stale,
    mismatched, failed, timed-out, or attested-only evidence cannot clear a risk.
  • Reviewer context receives only the sanitized resolver projection. The local
    hash-chain check detects inconsistency inside a trusted workspace but does
    not authenticate against an actor able to rewrite every trusted file and
    recompute the chain.
  • High-impact review classes cover authentication or authorization, secret
    disclosure, state loss or corruption, destructive actions, installer or
    published-package failure, public or serialized contract violations, and
    verification-ledger integrity.

Upgrade

  • No state or artifact migration is required. The root package continues to
    support Node.js 18 or newer; @godpowers/mcp continues to require Node.js 20
    or newer.
  • Verification records created before 6.2.0 lack digest-bound gate events and
    cannot support new level 4 or level 5 review conclusions. Generate a fresh
    godpowers verify record for each load-bearing safety claim.

Release evidence

Godpowers 6.1.0

Choose a tag to compare

@hannsxpeter hannsxpeter released this 19 Aug 07:22
b52c919

Godpowers 6.1.0 Release

Status: Published and verified
Date: 2026-08-19

  • [DECISION] Godpowers 6.1.0 adds a shared post-draft prose audit, a pure
    advisory scanner, and universal non-blocking U-12 findings without changing
    the existing three-label, substitution, or blocking artifact checks.
  • [DECISION] The public surface contains 124 slash commands, 41 specialist agents,
    13 workflows, and 45 recipes; this release adds, removes, or renames
    none of those surfaces.
  • [DECISION] The core package contains 113 runtime library modules, supports
    Node.js 18 or newer, and keeps zero production dependencies.
  • [DECISION] The read-only @godpowers/mcp companion shares version 6.1.0 and
    requires Node.js 20 or newer.
  • [DECISION] The repository contains 111 focused test scripts, and the current
    root package-content check reports 646 files.

Shared Prose Contract

  • [DECISION] references/shared/VOICE.md now runs one post-draft audit after
    the draft's meaning, requirements, and evidence are settled.
  • [DECISION] The audit checks each claim for a named actor, action or decision,
    mechanism or source, observable effect, and reader action when one is needed.
  • [DECISION] The audit preserves requirements, verified facts, code terms,
    quotations, and user-approved tone; it does not replace the three-label rule
    or substitution test.
  • [DECISION] Godpowers-specific before-and-after pairs cover artifact decisions,
    technical explanations, and public launch copy.

Advisory Scanner And Validation

  • [DECISION] lib/prose-lint.js is a dependency-free CommonJS scanner that
    treats input as inert text and returns ordered findings without file-system
    writes, network access, subprocesses, or dynamic evaluation.
  • [DECISION] Seven context-sensitive rules cover filler, vague attribution,
    stacked hedging, stock framing, inflated phrasing, empty conclusions, and
    dense sentences.
  • [DECISION] Each finding contains a rule id, line, column, sanitized excerpt,
    explanation, and review suggestion; excerpts stop at 160 characters.
  • [DECISION] lib/have-nots-validator.js maps scanner findings to universal
    U-12 warnings, and U-12 warnings never increase an artifact's error count.
  • [DECISION] Existing artifact errors retain their blocking severities, and
    the npm package guard explicitly requires lib/prose-lint.js.

Output-Specific Review

  • [DECISION] The documentation specialist favors direct factual explanations,
    exact repository names, verified commands, concrete behavior, runbook steps,
    and preserved evidence language.
  • [DECISION] The launch specialist may retain approved founder or product voice,
    positioning, and channel constraints while operational status and
    engineering evidence remain direct and neutral.
  • [DECISION] Both specialists treat U-12 findings as human review prompts and
    preserve the shared audit's meaning, evidence, and tone boundaries.
  • [DECISION] INSPIRATION.md acknowledges the pstack unslop skill as an
    influence on the scan, targeted rewrite, meaning and tone preservation, and
    final self-audit sequence.
  • [DECISION] No upstream prose, rule catalog, code, fixture, or result is
    vendored, and no runtime dependency on the pstack plugin exists.

Safety And Parser Hardening

  • [DECISION] The scanner masks opening YAML frontmatter, matching backtick or
    tilde fences, inline code, Markdown link destinations, and marked bad, avoid,
    or wrong examples before applying prose rules.
  • [DECISION] Fence closing requires the same delimiter character, at least the
    opener's length, and whitespace-only trailing content; indentation and CRLF
    behavior have focused regressions.
  • [DECISION] Double-backtick spans may contain a single backtick, and adversarial
    unique delimiter runs stay inside the focused 250-millisecond p95 limit.
  • [DECISION] Finding excerpts replace terminal control bytes before formatting,
    which keeps artifact reports safe for terminal display.

Advisory Boundaries

  • [DECISION] U-12 is advisory and non-blocking; a finding does not authorize an
    automatic rewrite or prove that the original sentence is wrong.
  • [DECISION] The scanner matches sentence patterns rather than standalone word
    bans, so concrete technical uses of surface, harness, primitive,
    robust, and leverage remain valid.
  • [DECISION] Pattern matching can produce false positives or miss prose that
    needs revision; a clean scan does not prove that text is human-authored,
    correct, or objectively good.
  • [DECISION] Masking handles the documented Markdown structures but is not a
    complete Markdown parser, so human judgment remains the final authority for
    prose changes.

Validation

  • [DECISION] Independent Stage 1 specification review, Stage 2 quality review,
    and scoped hardening review passed for the prose-quality feature.
  • [DECISION] node scripts/test-prose-lint.js passes 31 of 31 focused tests.
  • [DECISION] node scripts/test-artifact-linter.js passes 73 of 73 tests.
  • [DECISION] node scripts/static-check.js passes 35 of 35 checks and reports
    zero prose warnings across 233 shipped Markdown and MDX files.
  • [DECISION] node scripts/test-voice-lint.js passes 11 of 11 tests.
  • [DECISION] The current package-content check reports 646 root package files
    and includes lib/prose-lint.js in the required payload.
  • [DECISION] The final post-publication release gate passes 115 test commands
    in 81.3 seconds with 94.68 percent line coverage and zero production
    dependency vulnerabilities.
  • [DECISION] Pull-request CI, merged-main CI, the tag workflow, registry
    verification, GitHub Release creation, and isolated published-install checks
    are complete.

Upgrade

  • [DECISION] Install the root CLI with
    npm install -g godpowers@6.1.0 or run it with npx godpowers@6.1.0.
  • [DECISION] Root CLI users need no state migration, artifact migration,
    command rename, or production dependency change for this upgrade.
  • [DECISION] MCP users must run Node.js 20 or newer before upgrading
    @godpowers/mcp to 6.1.0; the root CLI retains Node.js 18 support.
  • [DECISION] Existing automation may continue treating artifact errors as its
    blocking signal because the new U-12 findings remain warnings.

Publication Evidence

  • [DECISION] Pull request 93 passed Node.js 18, 20, and 22 plus the package gate
    in CI run 32226287260 and merged as main commit
    b52c919bc3e02ff3dfae50e35c4a1fe070f0e619.
  • [DECISION] Merged-main CI run 32226644093 passed the same Node.js matrix and
    package gate against the exact merge commit.
  • [DECISION] Annotated tag v6.1.0 resolves to merge commit
    b52c919bc3e02ff3dfae50e35c4a1fe070f0e619.
  • [DECISION] Provenance workflow 32227120049 passed release identity, the full
    release gate, and the fresh pre-publication gate; it published and verified
    the exact root and MCP pair under release-6-1-0, then promoted both packages
    to latest.
  • [DECISION] Root registry integrity is
    sha512-6Xw4aqYktmn/bZLU3JB2fYa4kY9PIgdKzKLnPgL8xOq9lTArMXz+0RC5TEw7Rv2+DZVaIBoERG5GLZ6/yyfVSQ==
    with shasum 2300fff21af7554f29966bc577f276bcc61714dd.
  • [DECISION] MCP registry integrity is
    sha512-MnDTK2bZjQmQuRZ0ITd2xdgeQ5aYtJ+UKCLlezOzo/w0yOQy4JVOXbJtmwh1PNVwk7HDjo6LCcjJD8bERp3SkA==
    with shasum ed351975f6fa662860376664455836b61aef7fa0.
  • [DECISION] A fresh isolated install resolved both exact 6.1.0 packages,
    reported zero dependency vulnerabilities, and ran the root and MCP help
    commands successfully.
  • [DECISION] npm audit signatures verified registry signatures and
    attestations for all five packages in the isolated dependency tree.
  • [DECISION] GitHub Release v6.1.0 is published at
    https://github.com/hannsxpeter/godpowers/releases/tag/v6.1.0; npm remains
    the authoritative package artifact source.

Godpowers 6.0.0: harden the coding agent harness

Choose a tag to compare

@hannsxpeter hannsxpeter released this 18 Aug 04:01
9eb6a5c

Godpowers 6.0.0 Release

Status: Published and verified
Date: 2026-08-17

  • [DECISION] Godpowers 6.0.0 hardens the complete coding-agent harness: verification output, specialist context, larger-change design, slice resume, maintainability interpretation, and sequential changeability evidence now have executable contracts.
  • [DECISION] The public surface contains 124 slash commands, 41 specialist agents, 13 workflows, and 45 recipes; no command, specialist, workflow, or recipe was added, removed, or renamed.
  • [DECISION] The core package contains 112 runtime library modules, supports Node.js 18 or newer, and keeps zero production dependencies.
  • [DECISION] The read-only @godpowers/mcp companion shares version 6.0.0, uses the MCP v2 server package, and requires Node.js 20 or newer.
  • [DECISION] The package contains 110 focused test scripts, including the new harness-quality and authorized provenance suites.

Harness Quality

  • [DECISION] npm test -- --agent-output retains complete child bytes in a private log while presenting bounded aggregate success or focused first-failure evidence; normal output remains unchanged without the flag.
  • [DECISION] All 41 specialists declare required context, optional context, inline inputs, and a positive token cap or an explicit no-project-context contract; file sources reject symlinks and retain pinned bytes, and every loadout event path preserves complete counts but no source contents.
  • [DECISION] Medium and large Build plans require a program design approved by a hash-bound user.resolve event, while small plans require a recorded size and skip rationale; plan text cannot authorize itself.
  • [DECISION] Slice handoffs stay at or below 8 KiB, preserve the recovery-critical fields, and remain projections under .godpowers/state.json authority.
  • [DECISION] Maintainability trajectories report separate measures, signed deltas, and sample counts without turning one score into a build gate during the first three release candidates.
  • [DECISION] The packaged evolution benchmark reveals exactly six requirements in order, runs behavior plus maintainability checks offline, isolates Git configuration and hooks, bounds inputs, baselines, traversal, and evidence, retains partial interruption evidence, and removes temporary state.

Authorized Provenance Extension

  • [DECISION] @godpowers/provenance-pack provides an optional skill, specialist, responsible-use contract, and dependency-free client for content the user owns or is authorized to process.
  • [DECISION] Loopback is the default. Remote HTTPS and internal-network transfers require separate grants matching the exact normalized origin, credentials remain in environment variables, service responses are bounded and sanitized, and source bytes are preserved by default.
  • [DECISION] The root package does not install or start the external inspection service, and the extension remains inactive until the user installs it.

MCP v2 And Compatibility

  • [DECISION] @godpowers/mcp moved from the legacy MCP SDK production server to @modelcontextprotocol/server v2 and zod 4.2.
  • [DECISION] Protocol tests exercise the current v2 client and the legacy v1 client against the same nine read-only tools.
  • [DECISION] Every MCP tool is pinned to the server-configured project root, and artifact lint paths reject symbolic links before canonical containment is verified.
  • [DECISION] The MCP companion now requires Node.js 20 or newer, which is the breaking change that requires the 6.0.0 major version; the root CLI retains Node.js 18 support.
  • [DECISION] First-party extension manifests and peer dependencies accept the Godpowers 6.x line.
  • [DECISION] Root and MCP packages publish first under one staging tag, verify as an exact pair, and only then promote latest; reruns recover a missing half without republishing the existing version.
  • [DECISION] First-party extension packs publish only from a matching version tag whose commit is already merged into main.

Validation

  • [DECISION] Independent specification and quality reviews passed for compact verification, context loadouts, program design, slice handoffs, and maintainability trajectory behavior.
  • [DECISION] The evolution benchmark quality review exposed and drove repairs for symlink containment, network guard bypasses, interruption cleanup, evidence bounds, Git metadata and hooks, baseline resource limits, invalid numeric evidence, canonical handoff validation, falsy handoff substitution, and test-temporary cleanup; the repaired focused suite passes 18 checks.
  • [DECISION] The release hardening review exposed and drove repairs for MCP root containment, authoritative plan approval, context identity pinning, exact-origin consent, universal event bounds, resource-bounded scans, recoverable pair publication, and merged-tag pack publication.
  • [DECISION] Provenance client and pack suites pass 20 and 14 checks, the extension publication suite passes 65 checks, and the MCP protocol suite passes with modern and legacy clients.
  • [DECISION] The final local release gate passes 114 test commands and 3,113 checks, 94.64 percent line coverage, 79.8 percent branch coverage, the 70 percent per-file floor across 110 included runtime modules, zero dependency vulnerabilities, 140 self-project truth checks, synchronized Mythify 5.6.0 evidence provenance, and root plus MCP package-content verification.
  • [DECISION] The pre-publication gate passes against hardening revision sha256:5f65a4de4bb0ab7dcce5e7fb11c182a77345f23b2e6f75077c549ccef4ce9268 with zero unresolved or accepted Critical findings.
  • [DECISION] Pull-request CI, merged-main CI, exact package publication, registry integrity, latest promotion, GitHub Release creation, and isolated published installation are complete.
  • [DECISION] The tag workflow published both immutable packages with npm provenance under release-6-0-0; its immediate exact-version read encountered registry propagation delay, so the documented recovery path verified both versions and promoted MCP first and root second without republishing either artifact.
  • [DECISION] The publication workflow now retries exact-version reads for up to 120 seconds before treating registry propagation as a failed pair verification.

Upgrade

  • [DECISION] Install the root CLI with npm install -g godpowers@6.0.0 or run it with npx godpowers@6.0.0.
  • [DECISION] Root CLI users have no state migration, artifact migration, command rename, or production dependency change.
  • [DECISION] MCP users must run Node.js 20 or newer before upgrading @godpowers/mcp to 6.0.0.
  • [DECISION] Third-party extension maintainers should validate against 6.0.0 and widen any <6.0.0 peer range deliberately.

Publication Evidence

  • [DECISION] Pull request 91 passed Node.js 18, 20, and 22 plus the package gate in CI run 32096760451 and merged as main commit 9eb6a5cbdff3399e6d65a5cc660bf135814de7b7.
  • [DECISION] Merged-main CI run 32097014555 passed the same Node.js matrix and package gate against the exact merge commit.
  • [DECISION] Annotated tag v6.0.0 resolves to merge commit 9eb6a5cbdff3399e6d65a5cc660bf135814de7b7.
  • [DECISION] Provenance workflow 32097275283 passed release identity, the full release gate, and the fresh pre-publication gate, then published godpowers@6.0.0 and @godpowers/mcp@6.0.0 under release-6-0-0 with npm provenance.
  • [DECISION] The workflow encountered an npm registry propagation delay during its immediate exact-version read and stopped before promotion; recovery verified both staged artifacts, promoted @godpowers/mcp@6.0.0 first and godpowers@6.0.0 second, and confirmed both latest tags resolve to 6.0.0.
  • [DECISION] Root registry integrity is sha512-R7tLOkMP9JhXZzYLIGOhXwgB6YIXKi5RjiiY1t7uNRvCpd2RlhexyoCImtu3zSOA2BgqrpF8R6cBKbkNOT6cnQ== with shasum e6f63897d83b06b21da20659202fe0614b24809e.
  • [DECISION] MCP registry integrity is sha512-hfwyLGgjuPsh6yJeNq/SYgNZ3s8h5xxoil/R+288VmgFrXHqTzBLWfgAc361gKPG2VTLoVFMbC3mNk56FQJomA== with shasum 6c70dc38f938a7852da0cc7ea570d1d7cc0b1395.
  • [DECISION] Isolated exact-version verification with node scripts/verify-published-install.js godpowers@6.0.0 passes Quick Proof, read-only project inspection, dashboard, next route, Claude install, and Codex install checks.
  • [DECISION] The published MCP executable resolves through npx -y -p @godpowers/mcp@6.0.0 godpowers-mcp --help on Node.js 20 or newer.
  • [DECISION] GitHub Release v6.0.0 is published at https://github.com/hannsxpeter/godpowers/releases/tag/v6.0.0 as the notes and tag record; npm remains the authoritative package artifact source.

Godpowers 5.17.1: close the two recorded publish-run traps

Choose a tag to compare

@hannsxpeter hannsxpeter released this 06 Aug 14:08

Godpowers 5.17.1 Release

Status: Publishing via tag-triggered provenance workflow
Date: 2026-08-06

  • [DECISION] Godpowers 5.17.1 hardens the release gate itself. The two publish-run traps recorded after 5.14.x, the npm advisory-cache gap and late version-surface drift, are now closed mechanically inside the gate instead of documented for humans to remember.
  • [DECISION] The public surface contains 124 slash commands, 41 specialist agents, 13 workflows, and 45 recipes; no command, agent, workflow, or recipe was added, removed, or renamed.
  • [DECISION] The core package contains 108 runtime library modules and keeps zero production dependencies. No runtime module was added; both changes live in scripts/ and package.json scripts wiring.
  • [DECISION] The @godpowers/mcp companion remains read-only and shares version 5.17.1.

Changes

  • [DECISION] The audit gate reads the live advisory feed. npm audit reads advisories through npm's HTTP cache, so a local npm audit --omit=dev could pass minutes before CI failed the same gate on an advisory published in between; that is how the hono advisory surfaced during 5.14.x as a failed publish run. test:audit now also runs scripts/check-live-advisories.js, which collects the resolved production dependency set from package-lock.json (the same --omit=dev scope, including workspace production dependencies) and POSTs it directly to the registry's bulk advisory endpoint with plain fetch, no npm cache in the path. Any returned advisory fails the gate at every severity, matching npm audit's default. A network or registry failure exits as blocked, never as clean, per the release checklist's do-not-claim-verified rule. npm run audit:live runs the check alone for the pre-tag re-check.
  • [DECISION] Version-surface drift fails first and names its own fix. release:check now runs version:check before anything else, so a package.json edit made after release:prepare fails in seconds with the exact remediation (npm run version:sync) instead of surfacing minutes later as a self-truth failure mid-gate. The publish workflow runs the same release:check, so CI gets the identical early check.
  • [DECISION] The remediation posture is unchanged and now enforced in the failure text: a live advisory finding points at merging the Dependabot pull request, not at hand-rolling an npm override (CONTRIBUTING.md, "Dependencies and security advisories").

Validation

  • [DECISION] One new test suite rides npm test: scripts/test-live-advisories.js (103 test script files total). It is offline by design: fetch is injected everywhere, the collector is exercised against both a fixture lockfile and the real package-lock.json, and the blocked, findings, clean, and empty-set paths are all pinned.
  • [DECISION] The full suite passes, and the complete release gate is green end to end with both new guards visibly firing in its log: version surfaces checked first, live advisory feed clean for the resolved production set.
  • [DECISION] Every changed file was checked for em dashes, en dashes, and decorative emoji, per the repository style policy.

Upgrade

  • [DECISION] Install with npm install -g godpowers@5.17.1 or npx godpowers@5.17.1.
  • [DECISION] Nothing to migrate. No state format, artifact schema, command name, or gate behavior of the installed product changed; both fixes harden the repository's own release tooling. The published package differs from 5.17.0 only in version metadata and the package.json scripts block.
  • [DECISION] Contributors get both guards automatically: npm run release:check now fails fast on version drift, and npm run test:audit now reads the same live advisory feed CI reads.

Publication Evidence

  • [DECISION] Tag v5.17.1 resolves to main commit f2215bade61fb2dec44ec5438c121c81d96bb70d.
  • [DECISION] Provenance workflow 31109012123 verified the release identity, ran the release and pre-publication gates, and published godpowers@5.17.1 and @godpowers/mcp@5.17.1 under the latest tag with npm provenance.
  • [DECISION] The root registry integrity is sha512-sTsoYdBKOeDETEDcro80iATGzpl2n8RmBvAMp8ZGv8opD3hASvMBE2yYsZuNLLZ0v1HuEcocTqjh4iEtHVkEOA== (shasum 81e302262026de43318277ae11ed0514ec03d2fc).
  • [DECISION] The MCP registry integrity is sha512-IKZ9OCn2E0t3nPS8rm14IlcqFWtrsRCtOVfbWY0rd5Ydzvo7lAMwwRgSuloYp587AIFDaj7oPFswmWRw12P09g== (shasum 5bb5861a8e2329b574b776e4108c5821d292a51b).
  • [DECISION] Isolated exact-version verification (scripts/verify-published-install.js godpowers@5.17.1) passes against the registry artifact: Quick Proof, read-only project inspection, dashboard, next route, Claude install surface, and Codex install surface.
  • [DECISION] GitHub Release v5.17.1 was created by hand from this file after the workflow went green, notes only, no tarball assets.

Godpowers 5.17.0: judge the design blind against a shipped bar

Choose a tag to compare

@hannsxpeter hannsxpeter released this 06 Aug 07:51

Godpowers 5.17.0 Release

Status: Publishing via tag-triggered provenance workflow
Date: 2026-08-06

  • [DECISION] Godpowers 5.17.0 gives the design loop an external bar. DESIGN.md can name a shipped product as its reference anchor, the runtime audit judges the app against it through sealed blind A/B pairs, design reviews and divergence passes gained the same blind protocol, and the new /god-polish command climbs toward the bar inside hard bounds.
  • [DECISION] The public surface contains 124 slash commands, 41 specialist agents, 13 workflows, and 45 recipes. One command was added: /god-polish (build family, tier 3). No command, agent, workflow, or recipe was removed or renamed.
  • [DECISION] The core package contains 108 runtime library modules and keeps zero production dependencies. One runtime module was added: lib/blind-compare.js.
  • [DECISION] The @godpowers/mcp companion remains read-only and shares version 5.17.0.

Changes

  • [DECISION] DESIGN.md gained an optional reference anchor. A reference: frontmatter block (name, url, focus) names a shipped external product as the audit-time quality bar. lib/design-spec.js validates the block (D-REFERENCE-SHAPE, D-REFERENCE-NAME, D-REFERENCE-URL), lib/runtime-audit.js captures the reference beside the app during design audits, and god-browser-tester judges the pair blind. The anchor is a verification anchor only: it never supplies tokens, god-designer records one only when the user names it, and anchor changes gate through god-design-reviewer like any other DESIGN.md change.
  • [DECISION] Blind judgment is mechanical, not procedural trust. lib/blind-compare.js copies two role-named artifacts into neutral a/b slots, seals the role assignment in a sidecar, and enforces ordering in code: unseal refuses until a verdict exists, a recorded verdict is immutable, an unsealed pair refuses new verdicts, and a judged pair cannot be rebuilt. The protocol (references/design/BLIND-COMPARISON.md) states the honest limit plainly: the sidecar sits on disk during judging, so the blindness is a seatbelt against accidental peeking and after-the-fact edits, not cryptography.
  • [DECISION] The reference verdict is advisory by design. A lost comparison files a warning-severity reference-comparison finding into REVIEW-REQUIRED.md; an unreachable reference degrades to a reference-unreachable warning. Neither trips the critical-finding gate, and god-browser-tester's have-nots now make escalating one a named failure. Losing to Linear is information, not a broken build.
  • [DECISION] Reviews and divergence judge pixels, not labels. god-design-reviewer stage 1 judges rendered current-vs-proposed pairs blind when a design change renders, and the divergence pass judges rendered candidate pairs blind before convergence. Both skip honestly when nothing renders or the artifacts are identifiable at a glance, and both record the skip.
  • [DECISION] /god-polish is a bounded climb, not a gauntlet. Each round runs the design audit (including the blind reference comparison when anchored), turns findings into one design-scoped fix slice, applies it under unchanged TDD and two-stage review rules, and re-audits as proof. The loop stops on the first of: the polish-rounds-limit loop parameter (new, default 3, hard max 10, tuned via /god-budget --loop), a human stop, a dry round with no measurable improvement, or a critical finding. State lives in .godpowers/polish/POLISH.mdx ledger entries with polish.round and polish.closed events; the loop refuses to run on a red build.
  • [DECISION] The influence is acknowledged once, in the canonical place. INSPIRATION.md credits the gauntlet-loop skill (Matt Shumer's aim prompt, packaged by duolahypercho, MIT) for the reference-bar, blind-judgment, and climb-loop framings, and names what godpowers inverted: sealed mechanical ordering over trusted procedure, advisory severity over an unreachable "utterly wowed" bar, and a rounds cap plus dry-round detector over "the human is the only brake". No code or prose is vendored and there is no runtime dependency.

Validation

  • [DECISION] One new test suite rides npm test: scripts/test-blind-compare.js (102 test script files total). scripts/test-runtime-audit.js and scripts/test-design-foundation.js grew reference-anchor and capture coverage; lib/blind-compare.js lands at 100% line coverage and the lib aggregate stays above the 90/75 floors.
  • [DECISION] The full suite passes, and the complete release gate is green end to end: standards, coverage, per-file coverage, audit, self-project truth, evidence drift, and both package-content checks.
  • [DECISION] Every changed file was checked for em dashes, en dashes, and decorative emoji, per the repository style policy.

Upgrade

  • [DECISION] Install with npm install -g godpowers@5.17.0 or npx godpowers@5.17.0.
  • [DECISION] Nothing to migrate. No state format, artifact schema, command name, or gate behavior changed. Both new surfaces are opt-in: a DESIGN.md without a reference: block audits exactly as before, and /god-polish runs only when invoked and refuses pre-green projects.
  • [DECISION] Existing projects gain the blind reference comparison on their next design audit after declaring an anchor; polish-rounds-limit uses its built-in default until a project overrides it.

Publication Evidence

  • [DECISION] Tag v5.17.0 resolves to main commit c94844f6e0c460f4a33d749240ab29780185f537.
  • [DECISION] Provenance workflow 31082286088 verified the release identity, ran the release and pre-publication gates, and published godpowers@5.17.0 and @godpowers/mcp@5.17.0 under the latest tag with npm provenance.
  • [DECISION] The root registry integrity is sha512-BvpACgoQumsrWn1Oi2U0FS7vFV/pGc0S/DWPDOaf9lFy7emgD7yjR4Ppd5rf7j2iodBdTslE/P14tPWA5Pkt1g== (shasum 60ed785b1b5f71aebcf87d623fe4f5dc91a072cd).
  • [DECISION] The MCP registry integrity is sha512-SmQ1/thyJKeX0ZvCzqF2oLrjzqMqLQekEQhhzgbI5ZCAk5gJOfiOKzz1bBOfbdklDSuMOEhXPURb+s4WnThCHA== (shasum 9f307a3cf47efa57e925f554d2da3026c3ba987c).
  • [DECISION] Isolated exact-version verification (scripts/verify-published-install.js godpowers@5.17.0) passes against the registry artifact: Quick Proof, read-only project inspection, dashboard, next route, Claude install surface, and Codex install surface.
  • [DECISION] GitHub Release v5.17.0 was created by hand from this file after the workflow went green, notes only, no tarball assets.

v5.15.1

Choose a tag to compare

@hannsxpeter hannsxpeter released this 04 Aug 08:44

Godpowers 5.15.1 Release

Status: Publishing via tag-triggered provenance workflow
Date: 2026-08-04

  • [DECISION] Godpowers 5.15.1 is a documentation release. It rewrites the public documentation surface for a broader, less technical audience and changes no runtime behavior.
  • [DECISION] The public surface contains 123 slash commands, 41 specialist agents, 13 workflows, and 45 recipes; no command, agent, workflow, or recipe was added, removed, or renamed.
  • [DECISION] The core package contains 105 runtime library modules and keeps zero production dependencies. No runtime module changed in this release.
  • [DECISION] The @godpowers/mcp companion remains read-only and shares version 5.15.1.

Changes

  • [DECISION] The public documentation now leads with the reader's problem rather than the system's mechanism. README, docs/getting-started.md, docs/concepts.md, docs/quick-proof.md, docs/tutorials/first-project.md, SUPPORT.md, USERS.md, CONTRIBUTING.md, SECURITY.md, CODE_OF_CONDUCT.md, and docs/README.md were rewritten. docs/loop-engineering.md, docs/mcp.md, docs/host-capabilities.md, docs/extension-authoring.md, docs/brownfield-bluefield.md, docs/automation-providers.md, docs/validation.md, docs/recipes.md, docs/reference.md, and docs/command-flows.md were revised.
  • [DECISION] Jargon moved after the on-ramp, each term glossed on first use. Vocabulary that appears in real tool output (arc, tier, gate, have-nots) is retained deliberately, because a user cannot read the dashboard without it.
  • [DECISION] Reference-grade material keeps its precision. Per-command flows, validation internals, and recipe tables gained entry points and audience signposts rather than prose simplification, which would degrade them for the reader who actually needs them at incident time.
  • [DECISION] Marketing tone for this product means concrete and specific, not superlative. A documentation surface full of unquantified decoration words would fail the substitution test that Godpowers enforces on every artifact it produces, on its own front page.
  • [DECISION] README gained a "Who this is for" audience table and an "Honest limits" section stating what Godpowers does not claim: it does not evaluate whether a product idea is good, it is not a penetration test, it does not behave identically on every host, and it does not remove the need to read its output.
  • [DECISION] USERS.md keeps "Godpowers has zero recorded production users" as its opening line and now frames why that sentence stays in place until it is false.
  • [DECISION] Mermaid diagrams were added for the gate loop (README) and the tier model (docs/concepts.md), and the brownfield decision tree moved from box-drawing ASCII to Mermaid. All three render natively on GitHub and require no image assets or external requests.

Fixed

  • [DECISION] docs/concepts.md claimed both 25 and 30 mechanical have-nots within the same section. The count derived from lib/have-nots-validator.js is 25.
  • [DECISION] docs/reference.md listed /god-build and /god-fix twice in the verb dispatcher sentence.
  • [DECISION] docs/mcp.md documented 5 of the 9 tools exported by packages/mcp/lib/tools.js, pinned 4.0.2 in its setup and serve commands, and described the mutation boundary as scoped to the 4.0.0 release.
  • [DECISION] USERS.md described the 3.0 line as current in a stale run-on paragraph.

Validation

  • [DECISION] The full suite passes, and the complete release gate is green end to end: standards, coverage, per-file coverage, audit, self-project truth, evidence drift, and both package-content checks.
  • [DECISION] The self-project truth gate returns pass at 140 checks on the release tree.
  • [DECISION] The documentation drift guards did their job during this work: lib/repo-doc-sync.js failed the suite when a rewrite dropped the repo documentation sync phrase from CONTRIBUTING.md, and the change was corrected before commit rather than shipped.
  • [DECISION] Every changed file was checked for em dashes, en dashes, and decorative emoji, per the repository style policy. None are present.
  • [DECISION] No runtime module, route, skill, agent, workflow, or recipe changed, so behavioral risk for existing projects is limited to what users read.

Upgrade

  • [DECISION] Install with npm install -g godpowers@5.15.1 or npx godpowers@5.15.1.
  • [DECISION] Nothing to migrate. No state format, artifact schema, command name, or gate behavior changed.
  • [DECISION] Existing installs gain nothing functional by upgrading. Upgrade for the documentation, or skip this release safely.

Publication Evidence

  • [DECISION] Pushing tag v5.15.1 triggers the identity-bound provenance publication workflow, which verifies the tag against both package versions and against origin/main, runs the release and pre-publication gates, and publishes godpowers@5.15.1 and @godpowers/mcp@5.15.1 with npm provenance.
  • [DECISION] The GitHub Release is created by hand from this file after the workflow goes green; the workflow does not create it.
  • [DECISION] Post-publication registry integrity, tarball digests, and isolated exact-version install verification are recorded in a follow-up publication-evidence commit, consistent with the 5.10.x release flow.

Godpowers 5.15.0

Choose a tag to compare

@hannsxpeter hannsxpeter released this 04 Aug 06:38

Godpowers 5.15.0 Release

Status: Publishing via tag-triggered provenance workflow
Date: 2026-08-04

  • [DECISION] Godpowers 5.15.0 rewires the improvement-loop network from mutual confirmation to anchored verification: metrics never travel alone, gates corroborate claims against executed evidence, no auditor grades its own gate, and fast loops can no longer close slow loops' freshness checks.
  • [DECISION] The public surface contains 123 slash commands, 41 specialist agents, 13 workflows, and 45 recipes; no command or agent was added or removed. references/HAVE-NOTS.md gains a Severity Overrides table without changing its 183-entry catalog.
  • [DECISION] The core package contains 105 runtime library modules and keeps zero production dependencies. Four modules are new: findings-verdict.js, repair-integrity.js, cadence-guard.js, and loop-config.js.
  • [DECISION] The @godpowers/mcp companion remains read-only and shares version 5.15.0.

Changes

  • [DECISION] The tier gate pairs every claimed-pass verification command in state.json with its executed-backed count from the evidence ledger (lib/evidence.js verifications.jsonl). A claimed pass with no fresh verified executed record raises <tier>-attestation-gap ("attested, not executed") at warning severity behind a single promotion constant, so in-flight projects do not retroactively fail while the fabrication channel becomes visible on every gate run and dashboard.
  • [DECISION] lib/findings-verdict.js is now the only parser of .godpowers/harden/FINDINGS.mdx. The launch and publication policies are pinned as one tested contract: accepted risk resumes the arc, it never authorizes publication. The Launch gate: PASSED short-circuit in lib/router.js is deleted; the harden auditor writes that file, so trusting its own summary line let the audited party grade its own gate. A static check forbids any other lib module from parsing the findings artifact.
  • [DECISION] fixtures/tripwires/ plus scripts/test-gate-tripwires.js negative-test the release sensors: a self-passed Critical, an attested-not-executed state file, and an uncited OWASP table must each FAIL their sensor. The suite pins both the current warning-stage behavior and the future error-stage behavior of the attestation gap, so severity promotion is a deliberate tested transition.
  • [DECISION] The autonomous repair loop gains a test-integrity counter-metric (lib/repair-integrity.js): a green re-run whose repair deleted test files, added skip markers, or lowered coverage thresholds is SUSPECT and escalates via lib/executor-repair.js regardless of remaining budget. The signals are deliberately cross-language and high-precision; renames stay quiet.
  • [DECISION] scripts/version-sync.js may re-bless the roadmap artifact hash only when the delta is exactly its own managed version stamp (lib/cadence-guard.js classifies the delta; lib/artifact-map.js records each artifact's cadence tier). Content drift is queued to .godpowers/REVIEW-REQUIRED.mdx and reported red instead of re-stamped; a human blesses deliberately with --bless-roadmap="<reason>", logged to SYNC-LOG.mdx. This generalizes the 5.14.3 fix: the blind re-stamp of commit 1e99b1b is now structurally impossible, not just patched once.
  • [DECISION] Error-severity review-queue items mechanically block Tier 3 routes through the safe-sync-clear prerequisite until /god-review-changes clears them, and judgment-grade failures under --yolo are deferred into that queue instead of vanishing, so autonomy can keep building but cannot reach deploy, harden, or launch past an unreviewed judgment failure.
  • [DECISION] lib/loop-config.js is the single home for fast-loop knobs, with per-project overrides in intent.yaml > loop-params edited via /god-budget --loop with a logged reason. It closes a live defect: the runbook allowed 3 repair attempts while lib/executor-repair.js defaulted to 2. A static check keeps the runbook prose equal to the exported default.
  • [DECISION] Headline percentages carry their counter-metric: workflow percent travels with built percent when steps were skipped, a roadmap-declared done increment is annotated declared-only when linkage evidence does not back it, and linkage coverage of an empty requirement set reads 0 with a no-known-ids reason instead of a vacuously perfect 1.
  • [DECISION] The Severity Overrides table in references/HAVE-NOTS.md registers the A-14/A-15/A-16 compatibility downgrades with owner, rationale, and sunset; scripts/test-have-nots-tally.js asserts the validator's behavior matches the table and god-standards-check grades at the enforced severity, so the mechanical and LLM graders can no longer fork on one catalog.
  • [DECISION] npm run evidence:drift joins release:check: the vendored verification engine is compared against its pinned upstream on every release (soft-skip when the upstream checkout is absent so CI stays green). The check fired on its first run, catching a real upstream refactor and an additive record key, reviewed and recorded in lib/evidence/.provenance.json.
  • [DECISION] The full-suite guard in scripts/static-check.js is derived from disk: every scripts/test-*.js must be registered in the runner, with an explicit tombstone list, replacing a hand allowlist that covered 9 of ~90 suites.

Validation

  • [DECISION] The full suite (98 test scripts plus integration and MCP protocol tests) passes, and the complete release gate is green end to end: standards, coverage, per-file coverage, audit, self-project truth, evidence drift, and both package-content checks.
  • [DECISION] Coverage holds at 94.95 percent lines and 79.74 percent branches, above the 90 and 75 release floors, with the per-file 70 percent gate green across 103 lib modules.
  • [DECISION] The self-project truth gate returns pass at 140 checks on the release tree.
  • [DECISION] The tripwire suite proves each hardened sensor fails its known-bad fixture; the fixtures are frozen and the suite is protected from silent removal by the derived runner guard.
  • [DECISION] An independent Codex review at maximum reasoning effort was run over the complete change set before release; findings were triaged and addressed.
  • [DECISION] The complete release gate and the official Agent Skills validator run in the GitHub publication workflow before the artifact is published.

Upgrade

  • [DECISION] Install with npm install -g godpowers@5.15.0 or npx godpowers@5.15.0.
  • [DECISION] Nothing to migrate for existing .godpowers projects. The attestation gap ships as a warning, the OWASP citation check is advisory, and the roadmap re-bless guard only changes behavior in this repository's own version-sync flow. Projects that want claimed passes to become executed-backed run their verification commands through npx godpowers verify "<command>" --substep=<id>.
  • [DECISION] The Launch gate: PASSED short-circuit removal is the one behavioral tightening user projects can observe: a findings file whose summary line disagrees with its per-finding statuses no longer passes the launch prerequisite. A compliant findings file (statuses resolved or human-accepted) is unaffected.

Publication Evidence

  • [DECISION] Pushing tag v5.15.0 triggers the identity-bound provenance publication workflow, which verifies the tag against both package versions and against origin/main, runs the release and pre-publication gates, and publishes godpowers@5.15.0 and @godpowers/mcp@5.15.0 with npm provenance.
  • [DECISION] The GitHub Release is created by hand from this file after the workflow goes green; the workflow does not create it.
  • [DECISION] Post-publication registry integrity, tarball digests, and isolated exact-version install verification are recorded in a follow-up publication-evidence commit, consistent with the 5.10.x release flow.

v5.14.3

Choose a tag to compare

@hannsxpeter hannsxpeter released this 04 Aug 05:14

Godpowers 5.14.3 Release

Status: Publishing via tag-triggered provenance workflow
Date: 2026-08-04

  • [DECISION] Godpowers 5.14.3 clears the last two open Dependabot pull requests and deletes the reason one of them could never have gone green on its own.
  • [DECISION] The public surface contains 123 slash commands, 41 specialist agents, 13 workflows, and 45 recipes; no command, agent, reference, or have-not changed since 5.14.0.
  • [DECISION] The core package contains 101 runtime library modules and keeps zero production dependencies.
  • [DECISION] The @godpowers/mcp companion remains read-only and shares version 5.14.3.

Changes

  • [DECISION] The roadmap's Evidence Provenance block no longer records a package.json source hash. The check asserted a derivation that does not exist: god-roadmapper is spawned with the PRD and ARCH paths and never reads the manifest, ROADMAP.mdx derives no content from it, and the only value it does take, the version, is separately asserted by roadmap:source-version.
  • [DECISION] What the hash did in practice was fail every pull request touching a root dependency, because Dependabot cannot run npm run version:sync. PR #78 failed on exactly that with all three Node jobs green and the coverage gate complete; the c8 upgrade itself was never the problem.
  • [DECISION] The three genuine roadmap sources, PRD, ARCH, and the stack decision, keep whole-file hashes at full strength, and nothing about them is narrowed. A regression test proves a devDependency bump alone now leaves the roadmap evidence valid, and the existing staleness test is repointed at PRD.mdx rather than deleted.
  • [DECISION] scripts/version-sync.js loses the step that re-stamped the deleted hash. The documented remedy for a red roadmap:hash:package.json was to run version:sync, which rewrote the value blind; across 151 commits touching package.json it never once made anybody read a diff. That is have-not U-07 inside a guard, where the mechanism exists and the review it implies is auto-dismissed by the standard fix.
  • [DECISION] A new "root manifest keeps its declared shape" check in scripts/static-check.js pays for the deletion with strictly more coverage than it removes. It asserts the exact top-level key set of package.json and that dependencies, optionalDependencies, and peerDependencies are each empty.
  • [DECISION] That closes a real hole rather than a hypothetical one: the previous check read only dependencies, so ARCH ADR-002's no-production-dependency claim could have been violated through optionalDependencies with nothing noticing, because the override guard reads the lockfile and npm audit fires only on a known advisory. A clean production dependency passed every gate in the repository.
  • [DECISION] c8 moves to 12.0.0 through Dependabot PR #78. It declares engines.node: ^20.19 || ^22.12 || >=23, but it is a devDependency that only the coverage job runs, on Node 20, so engines.node stays at >=18 and the Node 18 test job is untouched.
  • [DECISION] The pinned GitHub Actions move through Dependabot PR #89: actions/checkout to v7.0.1, actions/setup-node to v7.0.0, and actions/setup-python to v7.0.0 across all four workflows. The regenerated pull request included security-audit.yml, so no workflow is left behind on an older pin.

Validation

  • [DECISION] The fix is proven by construction, not by assertion: a simulated Dependabot root-manifest bump was applied to a clean tree and the self-project truth gate returned pass at 140 checks with no version:sync and no hand-edited hash.
  • [DECISION] Coverage under c8 12.0.0 holds at 94.78 percent lines and 79.56 percent branches, above the 90 and 75 release floors, with the per-file 70 percent gate green across 99 lib modules.
  • [DECISION] The self-project truth ledger moves from 141 checks to 140 and .godpowers/AUDIT-REPORT.mdx is corrected to match; nothing else in the repository quoted the old number.
  • [DECISION] The full suite, the complete release gate, the pre-publication gate, and the static check are green on the tagged commit.
  • [DECISION] The complete release gate and the official Agent Skills validator run in the GitHub publication workflow before the artifact is published.

Upgrade

  • [DECISION] Install with npm install -g godpowers@5.14.3 or npx godpowers@5.14.3.
  • [DECISION] Nothing to migrate. Every change is to this repository's own gates, evidence, and development dependencies; no shipped runtime file changed.
  • [DECISION] A .godpowers project in the wild is unaffected. lib/self-project-truth.js returns early unless the package name is godpowers, and templates/ROADMAP.mdx has no provenance block at all, so the hash that was removed only ever existed in this repository's self-hosted copy.

Publication Evidence

  • [DECISION] Pushing tag v5.14.3 triggers the identity-bound provenance publication workflow, which verifies the tag against both package versions and against origin/main, runs the release and pre-publication gates, and publishes godpowers@5.14.3 and @godpowers/mcp@5.14.3 with npm provenance.
  • [DECISION] The GitHub Release is created by hand from this file after the workflow goes green; the workflow does not create it.
  • [DECISION] Post-publication registry integrity, tarball digests, and isolated exact-version install verification are recorded in a follow-up publication-evidence commit, consistent with the 5.10.x release flow.

v5.14.2

Choose a tag to compare

@hannsxpeter hannsxpeter released this 04 Aug 04:44

Godpowers 5.14.2 Release

Status: Publishing via tag-triggered provenance workflow
Date: 2026-08-04

  • [DECISION] Godpowers 5.14.2 hands the advisory response back to Dependabot, which had been doing the job correctly all along, and closes the two gaps that let an advisory go unnoticed between pushes.
  • [DECISION] The public surface contains 123 slash commands, 41 specialist agents, 13 workflows, and 45 recipes; no command, agent, reference, or have-not changed since 5.14.0.
  • [DECISION] The core package contains 101 runtime library modules and keeps zero production dependencies.
  • [DECISION] The @godpowers/mcp companion remains read-only and shares version 5.14.2.

Changes

  • [DECISION] The npm overrides block is removed. Dependabot alerts and automated security fixes were already enabled and already working: it opened a pull request within about a minute of each 5.14.x advisory, and both were closed unmerged only because a hand-written pin landed first.
  • [DECISION] Four of the five overrides were never load-bearing. The patched hono, ip-address, fast-uri, and brace-expansion releases were already inside the ranges their parents declare, so npm selects them unaided and a lockfile refresh was the entire fix.
  • [DECISION] The fifth was real: @modelcontextprotocol/sdk 1.29.0 declared @hono/node-server at ^1.19.9 and no 1.x release was ever patched for GHSA-frvp-7c67-39w9, so no resolution could reach a fix. Version 1.30.0 widens that to ^1.19.9 || ^2.0.5 and retires the override. With the block deleted the tree resolves to @hono/node-server 2.0.11, hono 4.13.0, ip-address 10.4.0, fast-uri 3.1.5, and brace-expansion 5.0.9.
  • [DECISION] Removing them is not housekeeping. Dependabot reads npm overrides, and one that caps resolution below a fix produces no pull request at all, only an error recorded against the alert, so a stale pin is a way for a repository to look patched while pinned to a vulnerable version. fast-uri: "^3.1.5" capped at 3.x while upstream shipped 4.x.
  • [DECISION] scripts/test-dependency-overrides.js fails the suite when an override is absent from the lockfile, carries no advisory id in overrides-rationale, or is no longer load-bearing because every declaring parent has caught up. It is offline and semver-only, so advisory freshness stays the scheduled workflow's job.
  • [DECISION] .github/workflows/security-audit.yml runs npm audit daily in both scopes. npm run test:audit runs on every push and pull request, but nothing evaluated the tree between pushes, and it audits with --omit=dev, so a development-scope advisory could never fail any gate: all three brace-expansion alerts were development scope and Dependabot was the only thing that saw them.
  • [DECISION] .github/dependabot.yml gains applies-to: security-updates groups for both ecosystems. Security updates ignore schedule and open-pull-requests-limit entirely, so grouping is the only lever the file has over them; the effect was immediate, with three separate GitHub Actions pull requests replaced by one grouped request.
  • [DECISION] codeaudit.md, secaudit.md, and uxaudit.md are no longer tracked. They are regenerated auditor output, and the committed copies described branch codex/product-trust-hardening at 5.3.0 while presenting as current at the repository root.

Validation

  • [DECISION] Zero advisories across all 141 packages in the tree including development dependencies, verified by posting the resolved dependency set to the registry bulk advisory API rather than reading a locally cached npm audit.
  • [DECISION] The override guard was proven to fire, not merely to pass, by reintroducing a redundant fast-uri pin and a pin on a package absent from the lockfile and confirming both are reported.
  • [DECISION] .github/workflows/security-audit.yml was run on demand before release and passed both scopes, so the daily schedule starts from a known-green state.
  • [DECISION] The full suite, the complete release gate, the pre-publication gate, and the static check are green on the tagged commit.
  • [DECISION] The complete release gate and the official Agent Skills validator run in the GitHub publication workflow before the artifact is published.

Upgrade

  • [DECISION] Install with npm install -g godpowers@5.14.2 or npx godpowers@5.14.2.
  • [DECISION] Nothing to migrate. The only shipped change is the removal of the overrides block from package.json, and npm ignores that field inside an installed dependency, so no consuming project resolved differently because of it.
  • [DECISION] Contributors working from a clone should run npm install so the lockfile refresh takes effect locally.

Publication Evidence

  • [DECISION] Pushing tag v5.14.2 triggers the identity-bound provenance publication workflow, which verifies the tag against both package versions and against origin/main, runs the release and pre-publication gates, and publishes godpowers@5.14.2 and @godpowers/mcp@5.14.2 with npm provenance.
  • [DECISION] The GitHub Release is created by hand from this file after the workflow goes green; the workflow does not create it.
  • [DECISION] Post-publication registry integrity, tarball digests, and isolated exact-version install verification are recorded in a follow-up publication-evidence commit, consistent with the 5.10.x release flow.