Bug Receipt v1.4.0 — robust, evidence-safe closeouts
Highlights
- Strengthens automatic bug and incident closeout with a mandatory complete
BUG RECEIPT. - Adds explicit
executed now,supplied, ormixedevidence provenance. - Covers security redaction, rollback recovery, diagnosis-only authority, and rolling version skew.
- Ships receipt schema v2 while retaining version 1 compatibility.
- Hardens installation with safe replacement, backup, rollback, and unsafe-destination refusal.
Measured result
In the pre-registered four-case v1.4 robustness cohort:
- Skills ON: 18/20 assertions (90%)
- Skills OFF: 5/20 assertions (25%)
- Lift: +65 percentage points
- Exact McNemar p = 0.000244
- Natural routing: 4/4
- Complete receipt and correct status: 4/4
- Secret leaks: 0
- Candidate actions: 0
This is a bounded comparison against the no-skill arm, not a claim against every alternative. Methodology and SHA-verified evidence are in benchmarks/RESULTS.md.
Verification
- 33/33 repository tests passed
- lint, TypeScript build, distribution validation, and packed-artifact smoke passed
- CI passed on Windows and Ubuntu with Node 20 and 22
npm audit: 0 vulnerabilities
Install
npx --yes github:lMysticl/bug-receipt#v1.4.0 install