0.51.0 — Claude Code's own prompt approves commits
💥 Breaking changes
- The
approvecommand is gone. Claude Code's own permission prompt now asks before every foreground commit, push, and pull request merge. Re-run/workbench-dev-team:setupafter upgrading. Until you do, those commands run with no prompt. - Every brief needs an
Acceptance:slot. Watson, Holmes, and Lestrade refuse a five-slot brief and name the missing slot.Item IDandRepo sweepruns are unaffected, so the scheduled pipeline keeps working.
🔐 Commits and pushes: ask rules instead of a parser
The old gate parsed shell to decide what to prompt for. Every review found a spelling it missed, and its approval record could be written by any process.
- Setup installs ten
permissions.askrules forgit commit,git push, andgh pr merge, bare forms included. - The approval is still your "commit it" in chat after review. The prompt is the mechanical backstop, not a security boundary.
commit-guard.shrefuses what the rules cannot see: a sub-agent's commit or push, any merge by a sub-agent or the pipeline, a force or delete push, and a commit or push behindbash -c,env,eval, aNAME=valueprefix, or a program path.
🤖 The pipeline stays in its own folders
pipeline-scope.shanswers the scheduled pipeline's prompts. It allows one plaingit -C,rm, orrmdirline whose paths and repository stay inside$TMPDIRand the scratch roots.- A push must send one local branch that is not the clone's default. Pull request merges are never allowed.
- Each run starts in a fresh
mktemp -dfolder, so this plugin's own repo is never a run's project folder. - The 24 tools pipeline runs used to lose to this repo's local settings are denied with
--disallowedTools.
🕵️ Reviews
- Holmes's helper reviewers run on a new read-only agent type,
holmes-lens. - The review guard is now a static rule: Holmes and
holmes-lensmay not write outside the scratch roots. The per-review hold, its records, and its two-hour expiry are gone. - Holmes's Local mode reviews against the brief's Acceptance list.
/developgrades its three options against the same list and points at/workbench-core:intake.
🧰 Setup
- Every setup block now passes workbench-core's destructive-scope guard, so setup runs from a session.
- Setup prints
! rmlines for the old approval script, the old approval records, and the old review-guard records. Nothing is deleted for you.
⬆️ Upgrade
- Update the plugin.
- Run
/workbench-dev-team:setup. - Run the
! rmlines setup prints. - After each Claude Code upgrade, re-run the manual pipeline check in the README ("Re-check after a Claude Code upgrade").
Release workbench-core's Acceptance-slot change only after this one.
Full Changelog: 0.50.1...0.51.0