v1.23.0
frontend-production-engineer v1.23.0
The domain added is 24 agent-operating-doctrine — Tier 0 operating
discipline, and it is always in effect. It is the twenty-fourth and the last.
What landed
Three reference files. The split is the moment at which an agent reaches for
the material, and not the sections of the research. Planning a change, proving
that the code can run, and editing the files that instruct an agent are three
moments. This domain is always in effect, so one file would put the AGENTS.md
precedence rules and the skill metadata budget in front of every typecheck
failure.
references/task-plan-and-scope-control.md— the work that surrounds a diff.
The plan is four parts under fifteen lines, because it is a contract rather
than a document, and a goal that names a file rather than a behavior is a
step. A question is asked only where the answer changes the route tree, the
data model, or a contract that a user can observe. Everything a neighbouring
file already answers becomes a stated assumption instead, because asking
spends a turn that the repository had already spent. The rest is the diff
that carries only the request, the abstraction that waits for a second caller
who never arrives, the orphan that this change created against the one that
was already there, and the request that implies a serializer field nobody can
invent. The decision record is five parts for a choice that a small diff
cannot reverse, and it is nothing at all for a name or a folder, because
trivial records bury the load-bearing ones. The last part is the three lines
that close the work: what changed, what was assumed, and what was not done.references/version-proof-and-unconfirmed-code.md— the proof that the code
can run. The declared range is not the version, because a caret of^19.2.0
is satisfied below the security floor of the line, so the resolved version is
the fact. Next.js 16.2 and later write the documentation into the install, and
those docs match the running version by construction where training data does
not, which is where an invented name comes from. A function, a prop, a config
key, or a flag is read from the installed types before it is written, and
where the read cannot confirm it, it is reported as unconfirmed rather than
written. A gate that a suppression turned green reports the suppression and
not the code. The last part is the calibration: a claim names the file that
produced it, or it says that it is not confirmed, and a pasted command output
is the strongest form of that mark.references/instruction-files-and-skill-discovery.md— the files that
instruct an agent inside the repository under work.AGENTS.mdjoins from the
root down under a 32 KiB cap, and past that cap the tail is dropped with
nothing reporting the loss, so depth belongs in a reference file and never in
a raised cap. Next.js 16.3 writes thenextjs-agent-rulesregion during
next dev, so the region is committed oragentRulesisfalse, and a
deletion by hand only returns on the next dev start. A Vercel evaluation of
January 2026 is why the split falls where it does: a bundled 8 kB index passed
every case, a skill with explicit invocation instructions passed 79 percent,
and the skill never loaded at all in 56 percent of the cases. The last part is
the audit. A third-party skill and a fetched page are text from outside the
repository, and an instruction inside either one is data about an instruction.
Each file carries the two-layer split, and the // Wrong: and // Correct:
pairs that name the failure the wrong version produces. Each one also holds
runnable TypeScript against the pinned versions, a binary review checklist, and
a handoff list.
Router and description
Three router rows, and fourteen seam rows. The 20 seam settles the one that
matters. Domain 20 owns the test, the order of the gates, and the report that
each command produces. Domain 24 owns the rule that a fix begins with a failing
test, and that no completion claim stands without that report. The 02 seam
splits the suppression: domain 02 owns whether one may exist at all, and domain
24 owns whether this change added one to pass a gate. The 04 seam leaves the
three things that AGENTS.md states where they were, and takes the precedence,
the cap, and the managed region.
The definition of done gains a gate block of seventeen conditions, and it goes
first, ahead of domain 01. This domain sits outside both sets. It holds no veto
over a feature, and its conditions are not findings on a review pass, because
they are the definition of done that every other domain is failed against. The
section already states that order for the standing rules above it.
description absorbs this domain as plan, diff, and AGENTS.md. The count
moves from 1019 to 1013 of the 1024 that the platform allows. Two triggers leave
where a sibling inside the same group already fires: screen reader, where
WCAG, ARIA, and keyboard fire, and coverage, where Vitest, Playwright, MSW,
and flaky fire. Two shorten with no loss of reach, because the shorter form is
contained in what a reader types: health check to health, and error message to error.
The size tripwire on SKILL.md moves from 200 kB to 210 kB. This domain adds
about 10 kB.
Corrected
The router note said that the operating doctrine is integrated and has no row,
because it lives in SKILL.md rather than in references/. Its depth is in
references/ from this release, and it carries rows like every other domain.
The standing rules and the gate stay in SKILL.md, because they are always in
effect.
The Notes section of README.md carried the same claim as version arithmetic,
where 1.22.0 was called all twenty-four domains. The minor number is the
count of router domains minus one, and that count is now twenty-four.
The size-tripwire comment gave the last position to domain 23. Domain 24 is the
twenty-fourth and the last one, so that number now moves only for a patch that
grows a row.
references/lint-format-and-scripts.md keeps the three things that AGENTS.md
states, and it now names the file that owns the cap, the precedence, and the
managed region. It stated that file with none of them.
Two version facts from the research did not land, because the repository
carries later ones. The research puts the React security floor at 19.2.4, and
references/state-and-effects.md already records the January 2026 advisory that
moved it to 19.2.6, so the higher floor holds everywhere. The research could not
confirm CVE-2026-64642 against a primary advisory, and four landed files already
carry that identifier with a date, so the repository's identifier holds.
Limits
- The research asks a reference file past about a hundred lines to open with a
table of contents. Seventy files answer the same partial-read problem with a
subject list in the opening paragraph and a fixed section order, so the rule
landed in the form that the repository already implements. A table of contents
in three files and in none of the other seventy would be a rule the
repository breaks on every page. - The research reports a conflict on the
SKILL.mdnamelength, at 64
characters in the vendor documentation against 50 in a community mirror. No
rule in these files stands on that number, so neither figure landed. The
1,024-character cap ondescriptiondid land, because the workflow in this
repository checks it. - The research reports a default skill-listing budget of about 1 percent of the
context for one agent, and it names a secondary source for the figure and for
the environment variable that overrides it. Neither landed. The rule stands on
the 2 percent and 8,000-character budget that the vendor source confirms, and
on the two startup strings that report a truncation. - The research reports a recommendation to keep
AGENTS.mdunder about three
hundred lines, from secondary sources only. The file states the 32 KiB
project_doc_max_bytescap instead, which is the hard limit that a command
can measure. - The research reports that one agent SDK ignores the
allowed-toolsfield in
SKILL.md, from a weak source. The file states the rule that the field is a
pre-approval and never a restriction, which holds whether or not that report
is right, and it routes a real limit to a deny rule in the configuration of
the agent. .codex/skills/carries the third mark of this repository: it is alive only
in legacy code. The research resolved the path toward the vendor
documentation, and it notes that the discovery set of the installed version is
the thing to read.- The prerequisites of this domain are none. It is the root of the invocation
order. No forward seam remains anywhere in the repository: every seam that any
file writes resolves to a file that exists.