Skip to content

v1.23.0

Choose a tag to compare

@n-shadloo n-shadloo released this 19 Aug 07:43
· 10 commits to main since this release
v1.23.0
f9b6710

frontend-production-engineer v1.23.0

The domain added is 24 agent-operating-doctrine — Tier 0 operating
discipline, and it is always in effect. It is the twenty-fourth and the last.

What landed

Three reference files. The split is the moment at which an agent reaches for
the material, and not the sections of the research. Planning a change, proving
that the code can run, and editing the files that instruct an agent are three
moments. This domain is always in effect, so one file would put the AGENTS.md
precedence rules and the skill metadata budget in front of every typecheck
failure.

  • references/task-plan-and-scope-control.md — the work that surrounds a diff.
    The plan is four parts under fifteen lines, because it is a contract rather
    than a document, and a goal that names a file rather than a behavior is a
    step. A question is asked only where the answer changes the route tree, the
    data model, or a contract that a user can observe. Everything a neighbouring
    file already answers becomes a stated assumption instead, because asking
    spends a turn that the repository had already spent. The rest is the diff
    that carries only the request, the abstraction that waits for a second caller
    who never arrives, the orphan that this change created against the one that
    was already there, and the request that implies a serializer field nobody can
    invent. The decision record is five parts for a choice that a small diff
    cannot reverse, and it is nothing at all for a name or a folder, because
    trivial records bury the load-bearing ones. The last part is the three lines
    that close the work: what changed, what was assumed, and what was not done.
  • references/version-proof-and-unconfirmed-code.md — the proof that the code
    can run. The declared range is not the version, because a caret of ^19.2.0
    is satisfied below the security floor of the line, so the resolved version is
    the fact. Next.js 16.2 and later write the documentation into the install, and
    those docs match the running version by construction where training data does
    not, which is where an invented name comes from. A function, a prop, a config
    key, or a flag is read from the installed types before it is written, and
    where the read cannot confirm it, it is reported as unconfirmed rather than
    written. A gate that a suppression turned green reports the suppression and
    not the code. The last part is the calibration: a claim names the file that
    produced it, or it says that it is not confirmed, and a pasted command output
    is the strongest form of that mark.
  • references/instruction-files-and-skill-discovery.md — the files that
    instruct an agent inside the repository under work. AGENTS.md joins from the
    root down under a 32 KiB cap, and past that cap the tail is dropped with
    nothing reporting the loss, so depth belongs in a reference file and never in
    a raised cap. Next.js 16.3 writes the nextjs-agent-rules region during
    next dev, so the region is committed or agentRules is false, and a
    deletion by hand only returns on the next dev start. A Vercel evaluation of
    January 2026 is why the split falls where it does: a bundled 8 kB index passed
    every case, a skill with explicit invocation instructions passed 79 percent,
    and the skill never loaded at all in 56 percent of the cases. The last part is
    the audit. A third-party skill and a fetched page are text from outside the
    repository, and an instruction inside either one is data about an instruction.

Each file carries the two-layer split, and the // Wrong: and // Correct:
pairs that name the failure the wrong version produces. Each one also holds
runnable TypeScript against the pinned versions, a binary review checklist, and
a handoff list.

Router and description

Three router rows, and fourteen seam rows. The 20 seam settles the one that
matters. Domain 20 owns the test, the order of the gates, and the report that
each command produces. Domain 24 owns the rule that a fix begins with a failing
test, and that no completion claim stands without that report. The 02 seam
splits the suppression: domain 02 owns whether one may exist at all, and domain
24 owns whether this change added one to pass a gate. The 04 seam leaves the
three things that AGENTS.md states where they were, and takes the precedence,
the cap, and the managed region.

The definition of done gains a gate block of seventeen conditions, and it goes
first, ahead of domain 01. This domain sits outside both sets. It holds no veto
over a feature, and its conditions are not findings on a review pass, because
they are the definition of done that every other domain is failed against. The
section already states that order for the standing rules above it.

description absorbs this domain as plan, diff, and AGENTS.md. The count
moves from 1019 to 1013 of the 1024 that the platform allows. Two triggers leave
where a sibling inside the same group already fires: screen reader, where
WCAG, ARIA, and keyboard fire, and coverage, where Vitest, Playwright, MSW,
and flaky fire. Two shorten with no loss of reach, because the shorter form is
contained in what a reader types: health check to health, and error message to error.

The size tripwire on SKILL.md moves from 200 kB to 210 kB. This domain adds
about 10 kB.

Corrected

The router note said that the operating doctrine is integrated and has no row,
because it lives in SKILL.md rather than in references/. Its depth is in
references/ from this release, and it carries rows like every other domain.
The standing rules and the gate stay in SKILL.md, because they are always in
effect.

The Notes section of README.md carried the same claim as version arithmetic,
where 1.22.0 was called all twenty-four domains. The minor number is the
count of router domains minus one, and that count is now twenty-four.

The size-tripwire comment gave the last position to domain 23. Domain 24 is the
twenty-fourth and the last one, so that number now moves only for a patch that
grows a row.

references/lint-format-and-scripts.md keeps the three things that AGENTS.md
states, and it now names the file that owns the cap, the precedence, and the
managed region. It stated that file with none of them.

Two version facts from the research did not land, because the repository
carries later ones. The research puts the React security floor at 19.2.4, and
references/state-and-effects.md already records the January 2026 advisory that
moved it to 19.2.6, so the higher floor holds everywhere. The research could not
confirm CVE-2026-64642 against a primary advisory, and four landed files already
carry that identifier with a date, so the repository's identifier holds.

Limits

  • The research asks a reference file past about a hundred lines to open with a
    table of contents. Seventy files answer the same partial-read problem with a
    subject list in the opening paragraph and a fixed section order, so the rule
    landed in the form that the repository already implements. A table of contents
    in three files and in none of the other seventy would be a rule the
    repository breaks on every page.
  • The research reports a conflict on the SKILL.md name length, at 64
    characters in the vendor documentation against 50 in a community mirror. No
    rule in these files stands on that number, so neither figure landed. The
    1,024-character cap on description did land, because the workflow in this
    repository checks it.
  • The research reports a default skill-listing budget of about 1 percent of the
    context for one agent, and it names a secondary source for the figure and for
    the environment variable that overrides it. Neither landed. The rule stands on
    the 2 percent and 8,000-character budget that the vendor source confirms, and
    on the two startup strings that report a truncation.
  • The research reports a recommendation to keep AGENTS.md under about three
    hundred lines, from secondary sources only. The file states the 32 KiB
    project_doc_max_bytes cap instead, which is the hard limit that a command
    can measure.
  • The research reports that one agent SDK ignores the allowed-tools field in
    SKILL.md, from a weak source. The file states the rule that the field is a
    pre-approval and never a restriction, which holds whether or not that report
    is right, and it routes a real limit to a deny rule in the configuration of
    the agent.
  • .codex/skills/ carries the third mark of this repository: it is alive only
    in legacy code. The research resolved the path toward the vendor
    documentation, and it notes that the discovery set of the installed version is
    the thing to read.
  • The prerequisites of this domain are none. It is the root of the invocation
    order. No forward seam remains anywhere in the repository: every seam that any
    file writes resolves to a file that exists.