Skip to content

v0.14.2

Choose a tag to compare

@github-actions github-actions released this 27 Sep 17:16
· 74 commits to main since this release
v0.14.2
f251807

Upgrading to v0.14.2

Behaviour changes

  • version-lockstep (looser (a change is not blamed for drift it did not cause)): Drift the base already had is a note, not version-mismatch, when the change touches none of the group's sources; the next change that touches one must resolve it. Migration: None.
  • dependency-delta (looser (false positive removed)): A pyproject.toml requirement on the project's own extras (all = ["<project>[a,b]"]) is not reported as a new or wildcard dependency. Migration: None.
  • time-estimates (looser (false positives removed)): A lookback (the last 24 hours, also across a soft wrap), this <period>'s, and Q<n> followed by a reporting noun (the Q3 invoice) are not reported. Migration: None.
  • ci-integrity (looser (false positives removed); one error becomes a warning): Fewer false positives, found by consumer adoption runs: a rollup job with if: always() that reads its needs results is not verification-job-masked-by-condition; a set +e whose $? is saved and tested is not exit-code-masked; verification-step-masked-by-condition is reported only when an existing verification step now runs only after a failure (a new if: failure() diagnostic, or a bare always(), is not); a verification job or workflow whose steps pair by body with a job this change added (a rename, split, or move to another file) is a note, not verification-job-removed / verification-workflow-deleted. always() && <condition> on a verification step is now verification-step-narrowed (warning), not masked-by-condition (error). Migration: None.
  • --format agent-prompt, hook run, MCP check_diff (output (agent text)): Warnings are listed after the blocking findings under ## Warnings (not blocking), with the instruction to fix one only if the change caused it; a report with only warnings says they do not block. Observe mode's note and log name only the blocking codes. --fail-on-warnings keeps every finding an issue. Migration: None.
  • hook install (additive): A release binary writes the Copilot setup step pinned to its own commit (uses: orieg/discipline@<sha> # v<version>) instead of the tag; hook install warns when git ignores a file it wrote; the Claude Code bootstrap puts ~/.local/bin on PATH through CLAUDE_ENV_FILE when it is not there. Migration: A setup-steps workflow written by an earlier release keeps its tag ref; pin it by hand or rewrite it.
  • doctor (looser (a satisfied advisory no longer reported)): The push-trigger finding is Pass, not Info, when merged-pr-body is enabled and every discipline job that runs on push is granted pull-requests: read or write (or read-all / write-all) by its job's permissions: or, when the job declares none, the workflow's: that grant is the fix the Info finding asked for. A job-level permissions: without it still reports Info, since it replaces the workflow's. Migration: None.
  • replay --json (additive): Each entry of cases_detail gains findings: the code, severity, file and line of every error and warning of that change's report, so what blocked a change is read from the replay instead of a check per commit. The message is never included, since a finding can echo secret material. discipline.replay.schema.json gains the field; its schema_version stays 1. Migration: None. A consumer that validates replay output against a copy of the old schema with additionalProperties: false updates its copy.
  • check (additive): New environment variable DISCIPLINE_PR_BODY_FILE names the file --pr-body-file would: the flag wins over it, and it wins over PR_BODY. Before, it was silently ignored. The agent hooks (hook run) and replay clear it for the checks they run, as they clear PR_BODY. Migration: None, unless a pipeline set DISCIPLINE_PR_BODY_FILE for another purpose: its file is now read as the pull-request body.
  • baseline --migrate (looser): With no baseline file, baseline --migrate prints a note that there is nothing to migrate and exits 0, so an adoption script can run it unconditionally; before, it was an error (exit 2). A baseline file that cannot be read still exits 2. Migration: None.
  • doctor (looser (a false warning removed)): A workflow step that uses the action with install_only: true (as hook install --agent copilot --cloud-agent writes) is no longer counted as a discipline job: its triggers, token and push runs are not reported, so doctor --strict no longer fails on the Copilot setup steps. A step whose install_only is an expression still counts. Migration: None.

The full ledger is in docs/ROADMAP.md.

What's Changed

  • fix(doctor): an install_only action step is not a discipline job by @orieg in #236
  • chore(hooks): dogfood discipline's agent hooks in observe mode by @orieg in #235
  • fix(gates): false positives from v0.14.1 adoption runs by @orieg in #237
  • fix(hook): warnings apart from blocking issues, a pinned cloud-agent step, and CLI adoption fixes by @orieg in #238
  • chore(release): bump version to 0.14.2 with its ledger rows by @orieg in #239

Full Changelog: v0.14.1...v0.14.2