Skip to content

0.51.0 — Claude Code's own prompt approves commits

Choose a tag to compare

@mikebronner mikebronner released this 29 Sep 17:56
· 6 commits to main since this release

💥 Breaking changes

  • The approve command is gone. Claude Code's own permission prompt now asks before every foreground commit, push, and pull request merge. Re-run /workbench-dev-team:setup after upgrading. Until you do, those commands run with no prompt.
  • Every brief needs an Acceptance: slot. Watson, Holmes, and Lestrade refuse a five-slot brief and name the missing slot. Item ID and Repo sweep runs are unaffected, so the scheduled pipeline keeps working.

🔐 Commits and pushes: ask rules instead of a parser

The old gate parsed shell to decide what to prompt for. Every review found a spelling it missed, and its approval record could be written by any process.

  • Setup installs ten permissions.ask rules for git commit, git push, and gh pr merge, bare forms included.
  • The approval is still your "commit it" in chat after review. The prompt is the mechanical backstop, not a security boundary.
  • commit-guard.sh refuses what the rules cannot see: a sub-agent's commit or push, any merge by a sub-agent or the pipeline, a force or delete push, and a commit or push behind bash -c, env, eval, a NAME=value prefix, or a program path.

🤖 The pipeline stays in its own folders

  • pipeline-scope.sh answers the scheduled pipeline's prompts. It allows one plain git -C, rm, or rmdir line whose paths and repository stay inside $TMPDIR and the scratch roots.
  • A push must send one local branch that is not the clone's default. Pull request merges are never allowed.
  • Each run starts in a fresh mktemp -d folder, so this plugin's own repo is never a run's project folder.
  • The 24 tools pipeline runs used to lose to this repo's local settings are denied with --disallowedTools.

🕵️ Reviews

  • Holmes's helper reviewers run on a new read-only agent type, holmes-lens.
  • The review guard is now a static rule: Holmes and holmes-lens may not write outside the scratch roots. The per-review hold, its records, and its two-hour expiry are gone.
  • Holmes's Local mode reviews against the brief's Acceptance list. /develop grades its three options against the same list and points at /workbench-core:intake.

🧰 Setup

  • Every setup block now passes workbench-core's destructive-scope guard, so setup runs from a session.
  • Setup prints ! rm lines for the old approval script, the old approval records, and the old review-guard records. Nothing is deleted for you.

⬆️ Upgrade

  1. Update the plugin.
  2. Run /workbench-dev-team:setup.
  3. Run the ! rm lines setup prints.
  4. After each Claude Code upgrade, re-run the manual pipeline check in the README ("Re-check after a Claude Code upgrade").

Release workbench-core's Acceptance-slot change only after this one.

Full Changelog: 0.50.1...0.51.0