Skip to content

Releases: jpowersdev/neuralint

neuralint v0.1.0-alpha.4

Pre-release

Choose a tag to compare

@jpowersdev jpowersdev released this 22 Sep 05:01

neuralint v0.1.0-alpha.4

This alpha introduces rule-selected assessment planners, zero-inference planning, trusted repository planner modules, and configurable blocking thresholds.

Highlights

  • Add assessment.planner to repository rules, with semantic-chunks as the default.
  • Build independent semantic-chunks cases from deterministic changed spans and bounded Tree-sitter scopes and comments.
  • Add a global, unsplittable filenames planner for co-change, placement, migration, manifest, and documentation policies.
  • Add neuralint check --plan to inspect cases and Jev request estimates without model calls.
  • Add trusted JavaScript module planners configured through assessmentPlanners and explicitly enabled with --allow-custom-planners.
  • Validate custom planner schemas, case identifiers, source references, line ranges, changed subject overlap, JSON facts, and complete coverage before inference.
  • Add configurable preflight limits for collection files and bytes, assessment cases, requests, and estimated input tokens.
  • Keep each rule's assessment cases in one Jev request when provider limits permit, improving cross-case policy assessment.
  • Add project-level failOn and per-run --fail-on; warnings remain visible but do not block by default.
  • Include assessment case IDs in findings and reports.

Usage

npm install --global neuralint@alpha
cd /path/to/repository
neuralint init --base origin/main
neuralint check --plan
neuralint check

Select the compact filename planner for a repository rule:

assessment:
  planner: filenames

Register a trusted repository planner module:

assessmentPlanners:
  effect-service-tests:
    module: tools/neuralint/effect-service-tests.mjs
    export: plan
    partitioning: independent-cases

Then select it from a rule and explicitly permit execution:

neuralint check --plan --allow-custom-planners
neuralint check --allow-custom-planners

Custom planner modules execute as trusted repository code. Pull-request workflows should load executable planner configuration only from a trusted source.

Benchmark evidence

The retained 30-rule × 30-file production matrix made 900 decisions in six Jev requests, completed in 1.829 seconds, and retained all 30 expected primary findings as definitive. The estimated cost was $0.01156. The run also produced 19 unanticipated findings; those remain unadjudicated and are not a precision claim.

The benchmark demonstrates retained primary recall after replacing evidence presets with assessment cases. It does not establish production precision, custom-planner quality, or general performance across repositories.

Compatibility

  • The earlier semantic.evidence field remains accepted temporarily but is deprecated and ignored.
  • Rules without assessment.planner use semantic-chunks.
  • Existing configuration without failOn, assessmentPlanners, or limits receives conservative defaults.
  • The runtime requirement remains Node.js 26 or newer.

Known limitations

  • Normal Git checks compare committed base...HEAD; staged and unstaged working-tree changes are not included yet.
  • Complete editor-buffer changed-range support is still planned.
  • Precomputed planner-result manifests are not implemented.
  • Repository module planners require explicit trust and are not an operating-system sandbox.
  • A production Effect service-to-test planner and trusted-base configuration loading for pull-request workflows remain planned.
  • Semantic-concentration limits beyond bounded changed spans, Tree-sitter context, and run budgets require further calibration.
  • Exact Jev wrapper and tokenizer accounting remains conservative rather than provider-authoritative.
  • The alpha does not redact source evidence or provide local inference. Confirm that configured endpoints are approved before sending proprietary code.
  • Rule, planner, report, and library APIs may change before 1.0.

neuralint v0.1.0-alpha.2

Pre-release

Choose a tag to compare

@jpowersdev jpowersdev released this 20 Sep 19:25

neuralint v0.1.0-alpha.2

This alpha reframes neuralint as fast semantic linting for coding-agent loops and adds the first repository onboarding and rule-management workflow.

Highlights

  • Add neuralint init to create .neuralint/config.yaml and one complete example rule without overwriting existing files.
  • Add neuralint rules list and neuralint rules validate.
  • Load the default Git base from repository configuration with a per-run --base override.
  • Replace candidate-dependent screening/localization requests with bounded concurrent Jev decision-matrix packs.
  • Show only definitive findings by default; add --advisories for inconclusive matches.
  • Add --rule RULE_ID for focused checks.
  • Add stdin/editor evaluation with --stdin, --path, and --start-line.
  • Add deterministic JSON finding locations with old/new side and line ranges.
  • Add optional semantic rule context, report boundaries, exceptions, remediation guidance, evidence scope, and contrastive examples.
  • Document the intended fast-lint and focused-remediation product architecture.

Initial usage

npm install --global neuralint@alpha
cd /path/to/repository
neuralint init --base origin/main
neuralint rules validate
neuralint check

Evaluate one rule against an unsaved editor selection:

printf '%s\n' 'logger.info({ token })' | neuralint check \
  --stdin --path src/client.ts --start-line 42 \
  --rule EXAMPLE_NO_SECRET_LOGGING --format json

Benchmark evidence

A 30-rule × 30-file production matrix run completed in 0.98 seconds using three Jev requests, retained all 30 predeclared primary findings as definitive, and cost an estimated $0.00635. This positive-heavy result establishes feasibility, not precision.

A five-case Home Assistant pilot found that gold finding packets handed to Terra produced the same measured remediation quality as full-catalog Terra while completing 3.31× faster and costing 24.1% less. This tests remediation given correct findings; it is not an end-to-end detection claim.

Known limitations

  • Git findings currently use hunk-level ranges; stdin selections preserve their explicit range.
  • Enclosing-symbol and related-definition retrieval are not yet implemented.
  • Focused human remediation is benchmarked but not yet exposed as a CLI command.
  • rules generate, rules test, and rules doctor remain planned.
  • The alpha does not redact diff content or provide local inference. Confirm that the configured endpoint is approved before sending proprietary code.
  • Rule and JSON report schemas may change before 1.0.

neuralint v0.1.0-alpha.1

Pre-release

Choose a tag to compare

@jpowersdev jpowersdev released this 19 Sep 20:28

Experimental first alpha of neuralint.

Highlights:

  • Repository-owned semantic policies under .neuralint/rules/
  • Merge-base-aware Git diff screening
  • Two-stage Jev screening and hunk localization
  • Text and JSON candidate reports
  • Reproducible classifier and repository-backed benchmarks

This is a research alpha, not a sound linter or final review authority. Applicable policy text and diff hunks are sent to the configured TypeSafe API endpoint. See the README for setup, limitations, and data-handling guidance.