v0.14.2
Upgrading to v0.14.2
Behaviour changes
version-lockstep(looser (a change is not blamed for drift it did not cause)): Drift the base already had is a note, notversion-mismatch, when the change touches none of the group's sources; the next change that touches one must resolve it. Migration: None.dependency-delta(looser (false positive removed)): Apyproject.tomlrequirement on the project's own extras (all = ["<project>[a,b]"]) is not reported as a new or wildcard dependency. Migration: None.time-estimates(looser (false positives removed)): A lookback (the last 24 hours, also across a soft wrap),this <period>'s, andQ<n>followed by a reporting noun (the Q3 invoice) are not reported. Migration: None.ci-integrity(looser (false positives removed); one error becomes a warning): Fewer false positives, found by consumer adoption runs: a rollup job withif: always()that reads itsneedsresults is notverification-job-masked-by-condition; aset +ewhose$?is saved and tested is notexit-code-masked;verification-step-masked-by-conditionis reported only when an existing verification step now runs only after a failure (a newif: failure()diagnostic, or a barealways(), is not); a verification job or workflow whose steps pair by body with a job this change added (a rename, split, or move to another file) is a note, notverification-job-removed/verification-workflow-deleted.always() && <condition>on a verification step is nowverification-step-narrowed(warning), not masked-by-condition (error). Migration: None.--format agent-prompt,hook run, MCPcheck_diff(output (agent text)): Warnings are listed after the blocking findings under## Warnings (not blocking), with the instruction to fix one only if the change caused it; a report with only warnings says they do not block. Observe mode's note and log name only the blocking codes.--fail-on-warningskeeps every finding an issue. Migration: None.hook install(additive): A release binary writes the Copilot setup step pinned to its own commit (uses: orieg/discipline@<sha> # v<version>) instead of the tag;hook installwarns when git ignores a file it wrote; the Claude Code bootstrap puts~/.local/binonPATHthroughCLAUDE_ENV_FILEwhen it is not there. Migration: A setup-steps workflow written by an earlier release keeps its tag ref; pin it by hand or rewrite it.doctor(looser (a satisfied advisory no longer reported)): Thepush-triggerfinding is Pass, not Info, whenmerged-pr-bodyis enabled and every discipline job that runs on push is grantedpull-requests: readorwrite(orread-all/write-all) by its job'spermissions:or, when the job declares none, the workflow's: that grant is the fix the Info finding asked for. A job-levelpermissions:without it still reports Info, since it replaces the workflow's. Migration: None.replay --json(additive): Each entry ofcases_detailgainsfindings: thecode,severity,fileandlineof every error and warning of that change's report, so what blocked a change is read from the replay instead of acheckper commit. The message is never included, since a finding can echo secret material.discipline.replay.schema.jsongains the field; itsschema_versionstays 1. Migration: None. A consumer that validates replay output against a copy of the old schema withadditionalProperties: falseupdates its copy.check(additive): New environment variableDISCIPLINE_PR_BODY_FILEnames the file--pr-body-filewould: the flag wins over it, and it wins overPR_BODY. Before, it was silently ignored. The agent hooks (hook run) andreplayclear it for the checks they run, as they clearPR_BODY. Migration: None, unless a pipeline setDISCIPLINE_PR_BODY_FILEfor another purpose: its file is now read as the pull-request body.baseline --migrate(looser): With no baseline file,baseline --migrateprints a note that there is nothing to migrate and exits 0, so an adoption script can run it unconditionally; before, it was an error (exit 2). A baseline file that cannot be read still exits 2. Migration: None.doctor(looser (a false warning removed)): A workflow step that uses the action withinstall_only: true(ashook install --agent copilot --cloud-agentwrites) is no longer counted as a discipline job: its triggers, token and push runs are not reported, sodoctor --strictno longer fails on the Copilot setup steps. A step whoseinstall_onlyis an expression still counts. Migration: None.
The full ledger is in docs/ROADMAP.md.
What's Changed
- fix(doctor): an install_only action step is not a discipline job by @orieg in #236
- chore(hooks): dogfood discipline's agent hooks in observe mode by @orieg in #235
- fix(gates): false positives from v0.14.1 adoption runs by @orieg in #237
- fix(hook): warnings apart from blocking issues, a pinned cloud-agent step, and CLI adoption fixes by @orieg in #238
- chore(release): bump version to 0.14.2 with its ledger rows by @orieg in #239
Full Changelog: v0.14.1...v0.14.2