Skip to content

Releases: popixoxipop-collab/backend-skeleton

v1.9.0

Choose a tag to compare

@popixoxipop-collab popixoxipop-collab released this 22 Sep 02:31

Full Changelog: v1.8.0...v1.9.0

v1.8.0 — Ruby on Rails scanning

Choose a tag to compare

@popixoxipop-collab popixoxipop-collab released this 21 Sep 17:19

Highlights

  • Adds the ruby-rails scanner adapter for Rails 8 applications, including conventional verbs, resources/resource expansion, namespaces/scopes, member/collection routes, and ActiveRecord table/primary-key metadata.
  • Adds explicit bskel scan --runtime-routes support using bin/rails routes --expanded; the default scan remains static and never boots the target application.
  • Adds deterministic synthesized Rails operation IDs and route-based OpenAPI reconciliation that adopts source operation IDs when available.
  • Pins and passes production-repository verification against Discourse, Forem, and Mastodon.
  • Adds real Rails 8.0.5.1 and 8.1.3.1 CI boot/integration coverage.
  • Fixes production-size ripgrep file lists being truncated into empty scans and makes Docker-backed CI recover stale smoke-test containers.

Verification

  • Local suite: 1,858 passed, 10 skipped, 0 failed.
  • GitHub CI: 16 jobs passed, 1 scheduled-only canary skipped, 0 failed.
  • Published to npm as backend-skeleton@1.8.0 with GitHub Actions OIDC provenance.

v1.7.1

Choose a tag to compare

@popixoxipop-collab popixoxipop-collab released this 21 Sep 15:25

Patch release adding CommonJS support to the JavaScript/Express scanner.

Highlights:

  • Detects both ESM and CommonJS Express applications.
  • Resolves direct require()-based router mounts through the existing mount graph.
  • Verified against pinned real-world JavaScript/Express repositories, including the CommonJS Conduit implementation with all 19 routes recovered.
  • Published to npm as backend-skeleton@1.7.1 with GitHub Actions OIDC provenance.

Install:
npm install -g backend-skeleton@1.7.1

Validation: 1,845 tests passed locally with zero failures, package-install verification passed, and the full GitHub Actions matrix completed successfully.

v1.0.0

Choose a tag to compare

@popixoxipop-collab popixoxipop-collab released this 02 Sep 00:09

First stable release of backend-skeleton — a deterministic gate layer for AI-assisted (and human) backend work: before a change counts as done, bskel checks it against disk, not against what an agent or a person claims.

Published to npm as backend-skeleton:

npm install -g backend-skeleton

What 1.0.0 means

1.0.0 is an API-stability commitment, not a maturity claim: bskel's CLI surface — command/flag names and meaning, every --json output shape (all schemas under schemas/), gate names and pass/fail semantics, and exit codes — is now stable. Breaking that surface requires a major version bump. It does not mean every subsystem has been proven in production — handles codegen is functionally complete and tested but has never been deployed to a real production repo; that caveat is unchanged by this release. See D-stable-api-contract in DECISIONS.md for the full policy.

Highlights since 1.0.0-beta.3

81 commits, curated to the major feature areas (full design rationale for every decision — WHY, mechanism, real-oracle measurement, and what's explicitly deferred — lives in DECISIONS.md; the complete catalog is in CATALOG.md):

  • Cross-feature safety — detects when two different features collide on the same resourceType/DB table/operationId (bskel scan cross-feature-check), plus a 4th signal correlating a real live Postgres foreign-key edge across features, with a staleness/freshness token on every correlation.
  • Live database write path — bskel patch propose --kind ddl-apply extends the existing propose/approve/apply/rollback lifecycle to hand-authored DDL against a real Postgres database, transaction-wrapped with automatic rollback on any postcondition mismatch, and a GitHub-style "type the table name to confirm" gate on DROP TABLE.
  • Cryptographically signed gate attestations — bskel gate export --sign + offline bskel attest verify (Ed25519, zero new dependencies): CI-independent, verifiable-without-network proof of what a repo's gates looked like at capture time.
  • Runtime contract-conformance receipts — opt-in middleware (Java/Spring, Python/FastAPI, TypeScript/Express) validates real HTTP traffic against a feature's emitted contract, verdict-only, feeding a new conformance gate — the first "static contract → observed reality" loop in this project.
  • Content-addressed patch transactions — generalizes config-file patching into a real propose/approve/apply/rollback lifecycle with a content-addressed preimage check, refusing to apply if the target changed since approval.
  • Handle trust model (O3/O5) — opt-in --enforce-registry (revocation-aware, checked on fetch/patch/recover), plus fetch and patch now derive independently correct authorization roles instead of silently sharing one.
  • Field-to-field dependencies — bskel dependency declare records when one feature's data depends on another's, warns the source feature at codegen time, and ships a small local HTTP server with a read/write browser UI over the dependency graph.
  • npm publishing automated — OIDC trusted publishing (no long-lived token), with real provenance attestation.

npm test: 1325/1325 passing.

Status

Split by actual maturity, not by feature list — scan/contract/new have real, measured verification against a production Spring Boot repo; handles is functionally complete but not yet deployed to production. See README.md's Status section for the full breakdown.

v1.0.0-beta.3

v1.0.0-beta.3 Pre-release
Pre-release

Choose a tag to compare

@popixoxipop-collab popixoxipop-collab released this 27 Aug 16:28

First GitHub release for backend-skeleton — a spec-driven backend scaffolding CLI (bskel) that closes 5 real gaps found trialing Spec Kit-style workflows against brownfield repos: forced brownfield collision scanning, feature_id-keyed machine-readable contracts, UUID-addressable field handles, immediate stack-choice wiring, and worktree base-ref verification.

Published to npm as backend-skeleton:

npm install backend-skeleton@beta

What's in this release

Since npm's last publish (1.0.0-beta.2), three real slices landed:

  • A9 — source-backed path-parameter schemas, replacing the /id$/i → UUID name heuristic with a real --openapi-file source schema when one resolves. Fixes a genuine false-negative (batchRequestId, a plain string previously pinned to a UUID pattern) that made contract validate reject a real, valid request.
  • A10 — opt-in operation-level description passthrough (contract emit --descriptions), copying a source document's real operation description verbatim.
  • A11 — the same --descriptions flag extended one level deeper: schema field-level description/example (a property's own annotation, distinct from the operation-level field) is now copied too.

Full design rationale for every decision (WHY / mechanism / real-oracle measurement / EXIT) lives in DECISIONS.md; the complete feature catalog (36+ items, what's built vs. explicitly deferred and why) is in CATALOG.md.

npm test: 973/973 passing.

Status

Pre-1.0, beta tag. Two catalog items (O3/O5 — the handle trust model and full authorization-contract enforcement) are deliberately deferred until handles are actually deployed to a production target; see CATALOG.md for the reasoning.