Repository navigation
Releases: hupe1980/devplane
Release list
v0.11.0
Devplane signs in to GitHub itself, and this release closes the ways an agent could steer its own
verdict.
Breaking
ghis no longer used. Sign in withdevplane login github(OAuth device flow, token in the OS credential
store);DEVPLANE_GHis gone. Without[github] pull_request,change offerprintsgit pushand the compare URL.- A task is never called verified: the count is seen by a passing check (
seen_by_passon the wire). - A change is verified only while its project declares a
checkanddevplane.tomlloads. change offeris refused (exit3, HTTP409) while a weakened-check row is unseen.- Commands:
gate run→gate,speckit install→speckit,issues/prs→forge issues/forge prs,
asks→inbox --all;focusandrulesremoved. --jsononly on commands that print JSON; a refused command prints{"error": …}and exits non-zero.connect,disconnectandchange stoprefuse without--yeswhen stdin is not a terminal.answer:--optionexcludes--allow/--deny;--fieldis for questions only.- Store schema 11. The old store is moved aside, not migrated.
- Telemetry settings carry a new token: run
devplane connectagain.
Security
- The tree digest hashes every file as it is on disk. A clean filter planted in
.git/configcould make edited code
digest as verified code, and ran in the host. - Vendor settings carry a telemetry-only token (
~/.devplane/telemetry-token). Claude Code hands its settings'
environment to every tool call, so the old header gave agents the token that answers permissions. - On Codex, an ask is a deny: Codex runs a call its hook asks about. A crash while deciding refuses on every vendor.
- A prohibition cannot be walked past through a wrapper the reader does not know (
pkexec,unbuffer,taskset, …),
flock -c, or an abbreviated long flag (rm --rec --for). - Host-run git never starts
core.fsmonitor, never prompts, and times out; the offer pushes with--no-verify. - Built-in prohibition: an agent may not edit Devplane's files, read its token, or edit its repository's
devplane.toml.change offer|finish|archiveandreview --seenare refused from an agent's session. - A line whose effect cannot be read statically (a variable naming the program,
GIT_SSH_COMMAND,LD_PRELOAD,
more than eight wrappers) is put to a person. - The workbench is served with a
'self'-only Content-Security-Policy,no-referrerandnosniff. - The GitHub token lives only in the OS credential store; a token GitHub rejects is deleted.
- The host refuses a taken port instead of moving; the token is accepted only in the
Authorizationheader;
~/.devplaneis0700and its files0600. - An unreadable diff holds the offer. Trusting a repository is recorded in the ledger.
Added
- GitHub:
devplane login github [--host] [--with-token],logout github, Setup → GitHub in the workbench,
Enterprise hosts ([github] host,[github.hosts."<host>"] client_id), and a GitHub section indoctor. - The Forge view and
devplane forgename each failure — not signed in, expired, rate limited, unreachable, not a
GitHub repository — with its fix, and say how many items lie past the page. - Verified is always shown with its qualifier (verified · 1 check weakened) on every surface.
change review <id> --seen <path>marks a weakened row read; the certificate says when.- The review also flags: a test added with no assertion, an assertion removed or made trivial, a removed test, a
changed tolerance, lint and type suppressions, a test file renamed out of the suite, a new.gitignorepattern,
edits to build, lint, coverage and CI configuration or to a script a gate runs, and masked failures (|| true, …). doctorreports a hook whose binary is gone as gate off.- Driven agents get Devplane's read-only MCP server, start in their worktree, and are closed with
session/close. cargo install devplane --features appbuilds the desktop app from crates.io.- Docs: Troubleshooting, a platform table, an upgrade section, and a quickstart from nothing to a verified change.
Changed
- A forge poll is one GraphQL request per repository plus one search per host, not two
ghprocesses per project. - The inbox never offers a change; ready to decide leads with Review.
snoozeis capped at 30 days.- The workbench keeps its state through the poll, pauses while hidden, never shows a count before its list loads,
says when a read failed or is stale, and shows progress on long writes. - Keys:
Alt+shortcuts work on macOS,a/dallow and deny in the inbox, and Enter opens an item. - The pure core no longer reads the clock or the disk.
Removed
- The
offerinbox action, the review's accept mark, and the OTLP metrics receiver.
Fixed
- Spec Kit, OpenSpec and Kiro repositories without a
devplane.tomllisted no specifications. - The certificate's re-run steps checked out a commit without the verified work.
- An answer to something the agent did not ask closed the question and stranded the agent.
- Concurrent opens of an old-schema store could leave the retired copy empty.
- Retention deleted the runs of open changes.
- A report's issue could be filed twice.
- A late telemetry event could clear a waiting permission or revive an ended run.
- An agent that could not start ended silently.
- Offering a branch that already had a pull request failed on every retry.
- Needs you missed assigned issues past the first page and repositories whose name differs in case.
- The inbox could read Clear. while items waited; marking one hunk marked a whole file's weakened checks.
- The window's host used a random port, so telemetry reached nothing.
trustneeded a running host;disconnectdamaged a status line ending in a quote..worktreeincludefailed on file systems without hard links.
Install: curl -LsSf https://github.com/hupe1980/devplane/releases/download/v0.11.0/devplane-installer.sh | sh
v0.10.0
Breaking
- No prebuilt binary for Intel Macs: macOS is Apple Silicon only.
cargo install devplanestill
builds on Intel. devplane dispatch,batch,say,tailandlibraryare removed. Usedevplane change start "…" [--project X]…
(one prompt to several projects, every refusal reported before anything is created),devplane change prompt
anddevplane watch [RUN].- Work is now Change everywhere, with no alias:
devplane change …,/api/changes…, idsc-…, tablechanges.
A change's state (drafted,isolated,in flight,verified,offered,archived) is computed on every read. - Removed: pipelines (
[pipelines], roles, human steps, findings,.devplane/prompts/), change kinds, per-kind
budgets, reproduction gates ([gates.named.*] expect), batches, the prompt/skill library and its sidecars, and
change approve. A config still carrying an old key is refused by name, with a sentence saying what to do. - The budget is one
usdplusmax_turnsandmax_runtime. [workspace] includeis replaced by the repository's own.worktreeinclude(.gitignoresyntax, ignored files only).- The authority
daemonis renameddevplane; the event source ishost.~/.devplane/daemon.jsonishost.json. - Branches are named
change/<slug>. - Store schema version 9. The old store is moved aside, not migrated.
- Hooks write straight to the store; nothing auto-starts a host.
/devplane/hook,/decided,/holdand
/statuslineare gone. Re-rundevplane connect claude. Read commands fall back to the store when no host answers. devplane stopisdevplane quit(POST /api/quit), and says what it ends first.- A second
devplane serveis refused by asking the recorded port's/healthz, not by trusting a pid. A port given
with--portorDEVPLANE_PORTis bound or the start fails. - Nothing opens a pull request by itself:
change finishrecords the basis and removes nothing
(--remove-worktreeis gone). Usechange offer. change archivekeeps the branch unless--delete-branch;--discard-uncommittedis separate from--force.- API:
/api/dispatch*,/api/batch*,/api/library,/api/changes/{id}/approve,/api/changes/{id}/diffand
/api/runs/{id}/eventsare removed.POST /api/changes/preflightis added. - Exact command rules with no wildcard require the same flag set:
Bash(git status)no longer covers
git status --short. PowerShell alias canonicalisation is gone. devplane connectanddisconnectshow the diff and ask;--yeswrites without asking.GET /api/setupreportsdeclares_gatesinstead ofverified;GET /api/attentiondropsoversight.
Added
- The workbench UI: a title bar with the ⌘K command palette and New change, an activity bar with counts, sidebar
lists, preview tabs, a bottom panel (Activity, Sight; ⌘J) and a status bar. Light and dark themes. - A change opens as a document with Overview, Tasks, Review, Gates, Ledger and Agent tabs.
- Review: file tree plus unified or side-by-side diff, keys
j/k/n/p/s/a/f/v. "Checks weakened or
changed" (skip markers, deleted tests, gate or CI config edits) leads the review and is named in the certificate. devplane change review <id> [--by intent]reads a change in[review] rolesorder, each file with its role,
covering test, decisions and task.- Sessions, ledger, reports, forge and search are sortable, groupable grids.
- The New change dialog runs a live preflight, including install-cost notes (
[workspace] setup, lockfiles). - The certificate names a digest of the gate commands and says when the change altered a check.
- Every dispatched prompt tells the agent it may stop and say the specification cannot be satisfied.
devplane change start --spec <folder> --task <selector>: send chosen task lines (a requirement token, or
file:linewhatever the notation); a selector matching nothing refuses before anything is created.- A change naming a specification reports ticked and verified counts separately.
devplane change drift <id> --run <run> --tell|--acceptwhen the specification moved under a run.[spec] tokensdeclares requirement-id shapes;GET /api/specscarriestrace,layoutsandno_layout.- Spec Kit
[USn]and Kiro nested_Requirements:citations are read; OpenSpec's legacyproject.mdmarker is
detected; timestamped Spec Kit folders are accepted. devplane change adopt <branch>,change archive,change offer(pushes and opens a PR only with
[github] pull_request = true, otherwise prints the commands),change promptandchange stop.devplane report file|ls|show|start|reject|defer|fixed|open: file a finding about another project; it reaches that
project's person, and a GitHub draft is sent only byreport open.[reports] deliver_fromopts a live run in.devplane app(cargo featureapp): the same host in a window, with notifications, a tray badge, a global
shortcut ([app] shortcut),devplane://deep links and open-in-editor/terminal.devplane connect codex, through~/.codex/hooks.json; Codex runs the hooks only after you approve them in it.- Copilot's hooks are all
commandhooks and decide without a host. [workspace] share = ["cargo"]shares oneCARGO_TARGET_DIRbetween a project's isolated changes.- The inbox is six bands, and
devplane inboxprints how many items are snoozed. devplane doctoropens with ahostsection and dates each vendor row.- One host per home, held by
~/.devplane/host.lock. connect --statuslineand--yesare accepted after the vendor name.- The event stream sends a
resyncevent.
Changed
- Verified means the latest
checkgate passed against the working tree as it is now, digested (untracked files
included) before and after the run, so uncommitted work can be verified. Named gates never verify. - A stale pass reads gates passed, stale with both tree digests wherever a change is shown.
- Gates, pull-request settings and budgets are read from your own checkout, never from the agent's branch.
events.sourcenames which vendor's shim wrote a hook row (hook,copilot_hook,codex_hook).- A host killed mid-run is recovered by the next one; its runs read as ended by the host.
Fixed
- Verified was unreachable without a commit, and a passing named gate after a failing
checkread as verified. - Gate output byte counts and digests were wrong over 32 KB; the gate stamp was taken after the commands ran.
- Hook events became invisible after a retention pass (
events.seqis never reused); projection replay double-counted. host.jsonand the token are written atomically, the token created0600.- Upserting a project on the hook path no longer resets its trust.
- Review listed files twice and dropped lines starting
---or+++. - "Formatter-only" no longer hides Python or YAML re-indentation.
- Decisions were matched to files by substring path.
change offerrefuses a dirty or empty branch and no longer passes an invalid--repotogh pr create.- Merge checks use the configured base branch, and a merged PR counts as merged.
- A spec folder missing from the base branch is refused at start.
change drift --tellcarries the changed text.- In-place changes are gated.
- The UI's POSTs were sent without a JSON content type (HTTP 415).
- A directory reached through a symlink (macOS
/tmp) became a second project. - The host registered its own working directory as a project named
.. - Decision rows now carry their project.
- A refused call no longer reads as the session's current work.
Security
- A
devplane.tomlorpolicy.tomlthat fails to load now makes every gated call ask; before, it disabled every rule. - Holding hooks are installed with a timeout above the longest hold.
devplane answer --allowis refused inside an agent session. Limit: the host's bearer token is still readable by
the agent.- The command reader sees through functions,
coproc, brace expansion and globs in the program word, here-strings and
<into a shell,builtin, and wrapper flags. - The matcher is a quote-aware reader: flags compare as a set (
-rf=-fr=-r -f),sh -c/eval/su -care
read inside, and a line it cannot read is unresolved (a question), never silently undecided. - Exception rules apply per simple command; exact rules compare short flags as a set.
- Ask answers are compare-and-set.
- The governing project is the longest canonical registered root; a worktree's
.gitfile is honoured only when
git's back-reference verifies it. base_branchis validated as a git ref, and every user-supplied ref follows--end-of-options.- A text tool's
-e/-c(sed,grep, …) is read as a pattern, not a command line.
Install: curl -LsSf https://github.com/hupe1980/devplane/releases/download/v0.10.0/devplane-installer.sh | sh
v0.9.0
Install: curl -LsSf https://github.com/hupe1980/devplane/releases/latest/download/devplane-installer.sh | sh
v0.8.0
Install: curl -LsSf https://github.com/hupe1980/devplane/releases/latest/download/devplane-installer.sh | sh
v0.7.0
Install: curl -LsSf https://github.com/hupe1980/devplane/releases/latest/download/devplane-installer.sh | sh
v0.6.0
Install: curl -LsSf https://github.com/hupe1980/devplane/releases/latest/download/devplane-installer.sh | sh
v0.5.0
Install: curl -LsSf https://github.com/hupe1980/vibeplane/releases/latest/download/vibeplane-installer.sh | sh
v0.4.0
Install: curl -LsSf https://github.com/hupe1980/vibeplane/releases/latest/download/vibeplane-installer.sh | sh
v0.3.0
Install: curl -LsSf https://github.com/hupe1980/vibeplane/releases/latest/download/vibeplane-installer.sh | sh
v0.2.0
Install: curl -LsSf https://github.com/hupe1980/vibeplane/releases/latest/download/vibeplane-installer.sh | sh