Repository navigation
Releases: openqodex/openqodex
Release list
openqodex@0.9.0
Minor Changes
-
#62
45267e0Thanks @siddhant-mohan! - -initfollowsCLAUDE_CONFIG_DIRandCODEX_HOME: it finds Claude Code and Codex by those folders and writes the skill, the instructions and the push hook where each agent reads them, never half in the default folder.- Inside Cursor's agent,
reviewtries Cursor first among the reviewers, as it does for Claude Code and Codex, andinitknows it runs inside an agent. initreplaces a skill file that holds the skill exactly as some version shipped it, such as the copynpx skills addwrites, with the skill it keeps up to date. Before, it kept that copy as yours and it never updated. A copy you edited is still left alone.initasks one question, "Write these files?", after a plan that lists every file under "For you, on this machine" or "For the team, in this repo". The git pre-push hook and the team review section are lines of that plan, on by default;--hook noneand--no-repoleave them out. Before, it asked up to three questions.- Inside Claude Code, Codex or Cursor with no terminal,
initwrites its plan without--yes. With no terminal and no agent it still exits 2, now after printing the plan and the flags that change it. - Answering no to "Write these files?" stops
init: it writes nothing, removes nothing from~/.openqodexand starts no review. Before, the review afterinitstill ran and created the.openqodexfolder, and old runtimes, receipts and locks were cleaned up anyway. - When
initfinds no coding agent and has a terminal, it asks which of Claude Code, Cursor, Codex CLI and Cline to install into. Without a terminal it still exits 2 with the--agentlist. - The line
initadds to each agent's global instruction file (such as~/.claude/CLAUDE.md) is now one sentence: "Before any push, review the change with the openqodex skill." The nextinitputs it in place of the longer section of earlier versions. Project scope and the Cursor and Cline rules keep the longer section. - After writing,
initlists what it wrote for you, with the command that undoes it, and what it wrote for the team, to commit, and namesinit --project, which puts the agent files inside the repository instead (the scanners andinit's record stay in~/.openqodex). - Every command
initprints (the next review, the undo,init --project) starts with the launcher's full path, so it runs when pasted: an npx install puts noopenqodexon yourPATH, andinitnever edits a shell profile. Its last line is the command to run next. initchecks every reviewer at once after writing and prints "Reviewer ready" with the one it found, or "No reviewer can start yet" with each one's reason and fix and thereview --agentcommand. It no longer runs a first review that cannot start, and it ends with one line:First review: finished,incomplete,skippedorunavailable.- The review
initends with waits up to two minutes for a scanner its change needs thatinithas just started downloading, then names any still downloading. Before, it ran with downloads off, so the first review had the fewest scanners of any. - The README, the quickstart and the skill give agents one install line,
npx -y openqodex@<version> init --yes --agent <host>: the same install asinitin a terminal, push check included.npx skills add openqodex/openqodex -gstays as the skill-only option, labelled so, in user scope so it writes nothing into the repository. init --yeskeeps what a repository chose before (--no-repo,--hook none) and takes the defaults only for what it never answered. Before,--yesput the team review section back where the repository had left it out.- With no terminal, no agent and no
--yes,initwrites nothing at all, its record of choices included, and runs no review, even when there is no file to write. initsays every push from the repository is checked only when its git pre-push hook is in place. Where husky or lefthook runs the hooks, or a pre-push hook it did not write is there, it says the hook is not set up and what to add.initdecides each write from where the path really lands, never from its spelling: it never writes through a symbolic link that lies in the repository, in either scope (an agent folder set inside the repository withCLAUDE_CONFIG_DIRorCODEX_HOMEincluded), nor to a place outside the repository, your home folder, the agents' folders and~/.openqodex. It checks each path when it plans the file and again right before the write lands. A link outside the repository, such as a dotfiles link into your home, is still followed; one that lands outside those folders is now refused.- Every file
initwrites, renames or removes, OpenQodex's own record, launcher and runtime copies in~/.openqodexincluded, goes through one checked path that knows each folder by its identity on disk, not its spelling: a repository named in another case or Unicode form, or a work tree inside its bare repository, no longer slips past the link check, andinstall.jsonorruntime/as a link to somewhere else is refused, never written or cleaned up through. - In a terminal,
initalso asks "Write these files?" when it would only record a choice or clean up old runtimes, receipts or lock files. - A skill file that spells out the placeholder the ownership check uses is kept as yours.
- Inside Cursor's agent,
-
#62
568d264Thanks @siddhant-mohan! -reviewnow ends with a short receipt instead of the whole report: the verdict, the reviewer's summary, one line per finding (number, severity, category, title, file and line) and the absolute paths ofreport.htmlandreport.md, which--quietkeeps.--format markdown,jsonandsarifstill print the whole report. Each review writesreport.html, one local page with each changed file as a diff and each finding under its line, then the coverage, the scanners and the blast radius; it runs no script, loads nothing and redacts the secrets the scanners found. The skill (whichguide skillprints), the project Cursor and Cline rules, the team section and the push gate tell the agent to show the receipt, ask "Fix all, or tell me which?" and fix only the findings you name; the newopenqodex findings 1,3prints the named findings in full. The report prints the reviewer's summary, and its coverage says "Files the reviewer opened" and "Files not opened (their changed lines were in the brief)". Each line of a multi-line secret, such as a private key, is now redacted wherever it appears alone.--report-dirreached through a symbolic link stopsreviewandscanwith exit 2 before anything is written, and a link the repository holds is refused at every write after that. When the first review afterinitcould not writereport.html,initsaysFirst review: incompletewith that reason. -
#62
584ee32Thanks @siddhant-mohan! - Scanners now download only where a repository's files call for them.doctor --installinside a repository installs the scanners its files need, lessscanners.disableandreview.paths.exclude, and prints why for each one;doctor --install --all-scannersinstalls every scanner, asdoctor --installdid before.initpicks its downloads the same way, from tracked and untracked files alike, prints one line per scanner it downloads, such asbrakeman: Rails app in backend/, andinit --dry-runprints those lines without downloading. The GitHub Action installs what the repository needs and keys its cache on the pinned scanner versions and those scanners, so a release that pins nothing new reuses the cache.Each changed file now belongs to its nearest project, read from that project's manifests as text. brakeman runs only for a file in a Rails app (rails in the
GemfileorGemfile.lock, andconfig/application.rborbin/rails), from that app's folder, so a Rails app inbackend/is scanned and a React Native app's CocoaPodsGemfileno longer pulls in brakeman. rubocop no longer runs for aGemfilealone and loads its Rails cops only in a Rails app. oxlint runs its React, accessibility and Next.js rules in projects that depend on them, and then the reviewer is no longer handed theuseEffectdependency pattern oxlint already checks. ruff adds its Django, FastAPI and Airflow rules in those projects. shellcheck checks an extensionless script whose first line names sh or bash.scan.jsonrecords the projects of the change.osv-scanner moves to 2.6.0 and reads
bun.lock,uv.lock,pdm.lock,pylock.toml, the NuGet lockfiles and more; it no longer getsgo.sum, which it cannot read and which stopped the whole lockfile check. It sends dependency names and versions to osv.dev only: its deps.dev and file-hash lookups are off. Aliased advisories are one finding, and a lockfile with no package is no longer a failure.oxlint moves to 1.86.0 and installs from its GitHub release, checked against its sha256, with no npm. semgrep, bandit, brakeman and rubocop install from lock files shipped in the package that name every dependency at one version with its sha256, and each download is checked against it, so their dependencies no longer float between machines. brakeman now asks for Ruby 3.0 or newer, which its pinned gem needs.
The README and docs now say which scanners download when, and every trivy example passes `--disable-telemetry --skip-version-check --skip-c...
openqodex@0.10.0
Minor Changes
- #65
d42e17eThanks @siddhant-mohan! - - The code graph finds callers across the packages of a workspace (pnpm, npm or yarn workspaces), through the nearest tsconfig.json of each file, and across Pythonsrcroots. Before, a change to a function of one package listed no caller in another.- Every caller in the brief says how sure the graph is: certain (an import, a definition in the same scope or a known receiver type proves it) or likely, with a note naming the convention it rests on, such as a workspace package reached through its built
distentry with no tsconfigpaths, project reference or source condition mapping it to source, or possible, when a name twoexport *statements bring from different modules could be either. A method inherited from a base class is no surer than the binding of the base. A path a package'sexportsmap does not expose, a Python module found in two places and a call on a value typedany,unknownorobjectare never bound, and each is said with its cause. - The brief's block is now "What this change reaches". It lists the public names the change stopped exporting or bound to another definition, with every place that used them and what each binds now; a function moved to another file under another name with the same body as moved and renamed; and what the graph could not see near the change, with the cause. A caller list that may be short is marked as a floor, with the reasons.
- Every cut the graph makes says what it left out: a hub's callers past the 20 nearest, the second hop past 20 callers of each caller, files past the parse cap, the time budget or the memory bound.
- The graph keeps its work between reviews in the repository's
.openqodex/graph/, ignored by the folder's own.gitignore: a file that did not change is never parsed again. Builds are kept whole and never changed after they are written; a review holds the build it read until it ends; the folder is held undergraph.max_cache_mb(512 MB by default). With--report-dirnothing is kept. The folder is used only while it and each file read from it are yours alone: a folder other users can write is refused with the reason and the graph is built in memory, and a build or a facts file is used only when~/.openqodex/graph/records it, for this repository, as one your own runs saved; anything else is parsed again. - Each kept build's files stay readable with
git show <tree>:<path>through a local ref,refs/openqodex/graph/<tree>, deleted with the build. A plaingit pushdoes not send it. - The review writes the graph's files into its snapshot under
.openqodex-review/graph/(every caller, the second hop, what the change calls, importers, the changed public names, what the graph could not see, the base version of removed code), so its reviewer can open everything the brief leaves out without leaving the snapshot. Before, the brief pointed atimpact.jsonbeside it, outside the folder the reviewer may read, and following it ended the review (#58). - When the build the next review needs is predicted, from this machine's own measurements, to take under five seconds, the graph is built fresh from what is cached. Over five seconds, a graph command uses the kept index of the same files when there is one, and a review builds under its time budget and keeps an index.
graph.max_filesnow counts new parses, never files whose facts are cached. New keys:graph.max_cache_mbandgraph.max_heap_mb.- The graph also runs when a change edits only a manifest (
package.json,tsconfig.json,pyproject.toml,go.mod, ...), and lists the imports whose target it changed. - A manifest, lockfile or tsconfig the graph cannot read is named with what failed. One whose loss can hide a call (a
package.json, a tsconfig, a workspace file, ago.mod) also marks the build partial and floors the callers in its folder;docs/graph.mdhas the table. A name re-exported through more than 8 modules is said as such. Afile:orlink:dependency binds to a workspace package only when its path leads to that package's folder. - A kept index is reused only when every file the project model read or looked for (tsconfig chains, whatever they are named, manifests, workspace files, lockfiles) and every file left out are the same as when it was built.
- Hidden commands, which may change before 1.0:
openqodex graph build | status | search | symbol | callers | callees | importers | changes | unknowns | explain | capabilities, with--json.docs/graph.mddescribes the graph.
- Every caller in the brief says how sure the graph is: certain (an import, a definition in the same scope or a known receiver type proves it) or likely, with a note naming the convention it rests on, such as a workspace package reached through its built
openqodex@0.8.1
Patch Changes
-
#54
8c9041aThanks @siddhant-mohan! - A new docs page,claude-code-review, on code review in Claude Code. -
#55
0d9bcbeThanks @siddhant-mohan! - The README, the docs, the Claude Code plugin's README,openqodex --helpand the CLI's messages now name.openqodex/config.yamlas the config file. A root.openqodex.yamlis still read when.openqodex/config.yamldoes not exist.
openqodex --help, the docs index and the Claude Code marketplace entry now describe OpenQodex as it works today: AI code review before you push, from your coding agent or your terminal, with the scanners and a separate reviewer.
openqodex@0.7.1
Patch Changes
-
#49
d27a66bThanks @siddhant-mohan! - A review no longer ends incomplete when the reviewer searches with a brace list of paths, such as{src/**,scripts/*.mjs}, that stays inside the change; a list with any path outside still ends it.A review no longer ends incomplete when the reviewer reads or searches a name with two dots in it, such as Next.js's
app/[...slug]/page.tsx; a..step that climbs out still ends it.A review no longer ends incomplete when the reviewer reads a file named with
$or%, such as Remix'sapp/routes/posts.$slug.tsx, that exists in the change; a path like$HOME/.ssh/id_rsathat names no such file still ends it.The check of what the reviewer read now reads each call as Claude Code does: a Grep file filter split at a space or comma, a filter that starts with
!, or a path with spaces around it ends the review when any reading points outside the change, and on a disk that keeps case, a folder whose name differs from the change's copy only in case counts as outside.
openqodex@0.7.0
Minor Changes
- #46
ee608c8Thanks @siddhant-mohan! - - The GitHub Action runs the full review on a pull request when the workflow setsANTHROPIC_API_KEYon its step from a secret: the scanners, the code graph and a Claude Code reviewer, with the report in the job summary and the findings in code scanning. Without a key it runs the scanners only, as before, and says in one line how to turn the review on. Each review spends the repository's own API credit.- The new Action input
reviewtakesauto(the review with a key, the default),offorrequired, which fails the job without a complete review. The new inputclaude-code-versionpins the Claude Code the Action installs. The new outputsreviewed,review-statusandreviewersay what ran. - In a pull request the Action's review reads the custom instructions from the base branch, like the config, so a pull request cannot write its own. The reviewer's web tools are off in the Action, the key reaches the review command alone, and the review never runs on
pull_request_target. - When the Action's review does not complete, the job also runs the scanners, so an incomplete review never hides a scanner finding: the summary shows the partial review and then the scan, code scanning gets the scan's findings, and a blocking finding from either fails the job.
- The Action's
versionandclaude-code-versioninputs take an exact SemVer release version only, such as0.6.1; a tag such aslatest, a range, a path or afile:package now fails the step. The Action runs its helpers from the system folders only, runsgit,node,npx,npmandclaudeonly from outside the checkout and gives its programs a PATH of those alone plus the system folders, keeps every program's output from writing workflow commands into the job log, escapes the text it puts in the job summary, and sets the key empty on its other steps. A pull request that commits.openqodex/reviewsor.openqodexas a link no longer turns a blocking finding into a tool failure. openqodex reviewtakes--block-on-severity, asscandoes,--instructions <file>to read the owners' instructions from another file,--reviewer-web on|offto set the reviewer's web tools for one run over the user config, and--report-dir <folder>to write every file of the run, and areviewer.jsonthat says whether a reviewer started and which, to a folder of your choice instead of.openqodex/, touching nothing under.openqodex/in the repository.openqodex scantakes--report-dirtoo.- A
.openqodex/latest.jsonthat is a link no longer fails a finished review:reviewwarns and keeps its exit code. - The markdown scan report escapes every markdown and HTML character in scanner messages and reasons, as the review report does.
- The new Action input
openqodex@0.6.1
Patch Changes
-
#41
9c0a2e5Thanks @siddhant-mohan! - The package and the three plugins now name https://qodex.ai/openqodex as their homepage. -
#20
da8878fThanks @siddhant-mohan! - OpenQodex is packaged for three plugin directories: the Claude Code plugin gains a README and an icon, a new Codex plugin inplugins/codex/carries the skill for the OpenAI plugin directory, and.cursor-plugin/plugin.jsonmakes the repository a Cursor plugin.
A new privacy page,docs/privacy.md, says what OpenQodex collects (nothing) and lists every network call it makes.openqodex guide privacyprints it.
The skill's description now names the requests it answers: a code review, a security scan, a diff or a pull request.
The npm package, the GitHub Action and the plugins have new descriptions and keywords, and the README opens with a banner.
openqodex@0.6.0
Minor Changes
-
#35
dfef509Thanks @siddhant-mohan! - Codex can now be the reviewer.openqodex review --reviewer codexruns the full review withcodex execon your Codex login, andautopicks Codex when you run the command from Codex or when Codex is the only reviewer installed.
The Codex reviewer reads the copy of the change in a read-only sandbox with no network for its commands. It still loads your global~/.codex/AGENTS.md.
Before each Codex review, OpenQodex checks that the sandbox refuses a read outside the copy and a write inside it. If it does not, the review does not start and you get "Full review unavailable" with the fallback.
With Codex, the report says file reads were not recorded, because Codex does not show every command it runs. Changed lines count only when the brief or a correction round put them in front of the reviewer.
Inside Codex's own sandbox, where a second Codex cannot start,review --reviewer codexprints "Full review unavailable" and thereview --agentfallback.
The reviewer brief no longer tells the reviewer which tools it has; it says to inspect the copy with its own tools, edit nothing and run none of the repository's code. -
#35
8e614e4Thanks @siddhant-mohan! - The reviewer can now search the web and open web pages by default; setreviewer_web: offin~/.openqodex/config.yamlto remove the web tools.
Patch Changes
-
#37
0b0b923Thanks @siddhant-mohan! - A scanner download that is stopped for being too large or too slow no longer leaves its partial file behind. -
#35
59bb4b6Thanks @siddhant-mohan! - - The terminal report no longer prints a line reading only "agent" under a finding the reviewing agent raised from its own reading; a scanner finding the agent verified still names its scanner.- The line
hook installprints for husky or a pre-push hook of your own now passes git's hook arguments ("$@"), so a push to a remote other than origin is checked against that remote. The lefthook line passes none, because lefthook would put a remote URL into the command as raw shell text; with lefthook a push is still checked against origin. docs/security.mdnow lists the problem report among the network uses: what the issue holds, and that it is sent only when you choose it.- The skill now says that two scanners go online: semgrep downloads its rule packs, and osv-scanner sends dependency names and versions to osv.dev.
--offlineskips both. - A brief written by a local build of OpenQodex (run with
node <path>/dist/bin.js) now names that same node and file in its finalize command, and in the fallback line when no reviewer can start, instead ofnpx -y openqodex@<version>. A run through npx or the launcher is unchanged. initand the first scan or review no longer tell you to commit a file that git ignores in your repository; they say it is ignored and not shared with your team.
- The line
-
#35
379c2caThanks @siddhant-mohan! - In a work tree nested inside its bare repository (such asrepo.git/main), the review afterinitno longer includes the filesinititself wrote. -
#35
1ce2facThanks @siddhant-mohan! - The pre-push hook now finds a complete review of the pushed branch even after a later review of other work.
openqodex@0.5.0
Minor Changes
-
#31
4e5b25dThanks @siddhant-mohan! - - The GitHub Action reads a pull request's OpenQodex config from its base branch, so the pull request cannot hide findings through its own config; when the base cannot be read it uses the built-in defaults, never the pull request's file. The new inputconfig-from: headreads the pull request's config instead. A wrongconfig-fromorblock-on-severityvalue now fails the step.- The GitHub Action handles a failed scanner install like a failed scan: a warning and
status: tool-failed, and a failed job only withfail-on-tool-error: true. An incomplete review in SARIF is now a failed run that names what is missing. - The push hooks check each range a push sends against the commit the remote holds, so a force push over work the review never saw is not covered by it. The agent hook checks your current work for a plain
git pushand says it cannot tell for any other push command (a deny whenblock_on_severityis set); the git pre-push hook stays the check that sees the exact commits. A pre-push that sends nothing passes. - A review stops before the reviewer starts when a file name holds a secret the scanners found, and the reviewer's trace is redacted like the report.
- A review counts a changed file that was too large to map or brief as unread until the reviewer reads it.
- A finding must start on a changed line and end within the file and 200 lines.
- Ctrl-C during a review stops the reviewer and its children and removes the snapshot.
- The review
initends with now reviews your own earlier edits to files init writes, such as CLAUDE.md, without init's own section. - A review from the older two-step protocol counts for the push hooks only when this machine ran its scan.
- The review
initends with now runs wheninitalso installs the git pre-push hook or adds a.git/info/excludeline; before, it stopped with "the review after init did not run". - The git pre-push hook accepts a review of a branch made with no upstream set when it is pushed over its remote tip, as long as the review covered exactly the pushed commit; before, such a push counted as unreviewed and, under
block_on_severity, was stopped every time. When a branch the remote has is still unreviewed and has no upstream, the hook's line says to set the upstream, review, then push. - When no reviewer can start (only Codex or only Cursor installed, or Claude Code logged out),
reviewnow names a fallback after "Full review unavailable": the agent you are in runsreview --agentand follows the brief it prints. The skill tells the agent to follow it. - A review finished through
review --agentandreview --finalizesays "Reviewed by the coding agent you are using." on the first line after the verdict, in the terminal,report.md,report.json(reviewed_by) andreport.sarif(a run property). Its brief ends by telling the agent to show you the report as printed.
- The GitHub Action handles a failed scanner install like a failed scan: a warning and
-
#31
a3eb515Thanks @siddhant-mohan! - ---reviewernow takesauto,claude,codexorcursor, andreviewer:in~/.openqodex/config.yamlsets it for every review. Only Claude Code is enabled as a reviewer: Codex and Cursor say why they are not and the review exits 2.reviewer_web: onin~/.openqodex/config.yamlgives the reviewer Claude Code's web tools. It is off by default.initnow ends with a review of your change, or asks what to review when there is none (the whole repository, a pull request, a branch, or not now). Without a terminal it prints the three commands.--no-reviewskips it, and a review that cannot run never failsinit.- The push hooks now look up the review of exactly what is pushed. A complete passing review is silent, a missing one asks for
openqodex review, an incomplete one never blocks, and a review from the older two-step protocol counts, with a line naming who reviewed. - The push hooks trust only the review record in your own
~/.openqodex/receipts/, never report files a branch carries under.openqodex/.initandupdateremove records older than 30 days. - The git pre-push hook no longer scans or prints scanner findings.
- The GitHub Action says first that it runs the scanners only. A tool failure (exit 2) no longer fails the job: it shows a warning annotation and a job summary line, and sets the new
statusoutput totool-failed. The new inputfail-on-tool-error: truefails the job instead, and the new inputblock-on-severitysets a gate that the pull request's own config cannot weaken. scan --block-on-severity <severity>wins over the config'sreview.block_on_severity.- The skill, the agent rules and the team section now give the agent one command,
review, and tell it to show the report exactly as printed. Claude Code is allowed to runreviewandreview --allwithout asking; the olderreview --agentandreview --finalizerules are removed. - Progress shows one line for the scanner stage, such as "Scanners: 6 ran, 5 had nothing to check, 14 candidates to check", instead of a line per scanner.
-
#31
93a4a4aThanks @siddhant-mohan! - -openqodex reviewnow does the whole review in one run: it copies your change into a temporary snapshot, runs the scanners and the code graph on it, starts Claude Code as a separate reviewer that can only read the snapshot, checks the answer with a script and prints one report. Each finding says where, the problem, why it matters and the fix, and the report ends with which reviewer ran, how long it took and what it used.- A review is complete only when every scanner candidate was raised or dropped with a reason and every changed range was given to the reviewer. Otherwise the report says what is missing and the command exits 2.
- With no reviewer installed and logged in,
reviewprints "Full review unavailable", says what is missing, saves the unchecked scanner candidates to a file and exits 2. It never shows scanner output as a review. - New flags:
--reviewer auto|claudeand--timeout <seconds>(600 by default). review --agentandreview --finalizestill work for older skills; a review finished that way is recorded as a legacy review.
openqodex@0.4.0
Minor Changes
- #25
000d3dfThanks @siddhant-mohan! - -openqodex review <branch>andopenqodex review '[#42](https://github.com/openqodex/openqodex/issues/42)'(or a pull request link) review a branch or a pull request that is not your current work. OpenQodex fetches it, checks it out in a temporary folder without running anything from it, and reviews what it added since it left its base. Your own settings and approvals apply, never the target's.- The base of a branch or pull request review comes from
--base, the pull request's base whenghis installed,review.default_base, or the remote's default branch, and the output says which. review --finalize --run <id>finalizes one run by name; the brief of a branch or pull request review prints it.- A change to a scanner's own settings or ignore file, such as
.gitleaksignoreorruff.toml, is raised as a candidate the reviewer must clear, since it can hide that scanner's findings. A scan shows it as a note that never counts toward the verdict. - A change that only deletes code can now carry a finding that counts: the lines next to a deletion count as changed, and the brief lists each deletion point (issue #22).
- The base of a branch or pull request review comes from
openqodex@0.3.0
Minor Changes
-
#21
db539cdThanks @siddhant-mohan! -initinside a repository adds a short review section to the repository'sCLAUDE.mdandAGENTS.md, so a teammate's agent reviews before pushing with nothing installed; the files show ingit statusto be committed.--no-reposkips it, and--uninstallremoves exactly that section.
Every user-scope install gets the launcher in~/.openqodex/bin/, even for Cursor or Cline alone. The user-scope skill is now a short stub that runs<launcher> guide skillfor the full procedure of the active version, and the user-scope Cursor and Cline rules call the launcher instead ofnpx -y openqodex@<version>. The nextinitreplaces a skill or rule an earlierinitwrote, while it is unchanged.
Newguide skill: prints the review procedure of the running version, with its commands written for the launcher when the launcher started it.
The launcher runs the version named on the first line of~/.openqodex/runtime/current, and the versioninitinstalled when that line is missing, malformed or names a copy that is gone. A runtime copy is never replaced once written.
The skill installed withnpx skills adduses~/.openqodex/bin/openqodexwhen it exists. -
#21
3f53203Thanks @siddhant-mohan! - In user scope,initadds rules so Claude Code runs the exact review command lines the skill names (review --agent,review --finalize, their--alland--offlineforms) andguidewithout asking. When the launcher's path holds*, no rule is written andinitsays so, so a review can run unattended; any other flag or command still asks.init --uninstallremoves exactly the rules it added.
The skillinitwrites in project scope keeps the committednpx -y openqodex@<version>commands and no longer tells an agent to prefer the launcher.
initskips the team review section for aCLAUDE.mdorAGENTS.mdthe repository's git ignore rules hide, and says why.
init --uninstallremoves the update state, and~/.openqodex/config.yamlwhenopenqodex updatecreated it and it is unchanged.
openqodex update --rollbackturns updates off before anything else and changes nothing when it cannot.
openqodex --helpnow shows four commands;scanis part ofreview; the other commands still work.
init, uninstall,hook installand the update's switch take one lock that the operating system releases when a process ends: a listener on 127.0.0.1 that accepts no data. Lock files from earlier versions are removed byinit. -
#21
23f6714Thanks @siddhant-mohan! - An install made withinitupdates itself: at most once a day, after a review, scan or push check run through the launcher, a background check installs a newer release that is at least 24 hours old and whose npm provenance was signed by this repository's release workflow. The command never waits for it, and the next command says once which version it moved to.
Newopenqodex updatecommand:--now,--rollback,--off,--onand--status.doctorshows the update state. Updates are off withupdate: offin~/.openqodex/config.yaml,OPENQODEX_AUTO_UPDATE=0,--offlineand in CI.
review --finalizeruns on the openqodex version that wrote the brief, and the brief's finalize command names that version's own runtime when the launcher started it.
A run through npx or a project-scope file never checks for updates;doctor,reviewandscansay when that pinned version is behind the newest one a check on this machine saw.
Patch Changes
- #21
58b8578Thanks @siddhant-mohan! - A review no longer misses a file edited at the same size within the same second that git last wrote its index.