Releases: popixoxipop-collab/backend-skeleton
Release list
v1.9.0
Full Changelog: v1.8.0...v1.9.0
v1.8.0 — Ruby on Rails scanning
Highlights
- Adds the
ruby-railsscanner adapter for Rails 8 applications, including conventional verbs, resources/resource expansion, namespaces/scopes, member/collection routes, and ActiveRecord table/primary-key metadata. - Adds explicit
bskel scan --runtime-routessupport usingbin/rails routes --expanded; the default scan remains static and never boots the target application. - Adds deterministic synthesized Rails operation IDs and route-based OpenAPI reconciliation that adopts source operation IDs when available.
- Pins and passes production-repository verification against Discourse, Forem, and Mastodon.
- Adds real Rails 8.0.5.1 and 8.1.3.1 CI boot/integration coverage.
- Fixes production-size ripgrep file lists being truncated into empty scans and makes Docker-backed CI recover stale smoke-test containers.
Verification
- Local suite: 1,858 passed, 10 skipped, 0 failed.
- GitHub CI: 16 jobs passed, 1 scheduled-only canary skipped, 0 failed.
- Published to npm as
backend-skeleton@1.8.0with GitHub Actions OIDC provenance.
v1.7.1
Patch release adding CommonJS support to the JavaScript/Express scanner.
Highlights:
- Detects both ESM and CommonJS Express applications.
- Resolves direct require()-based router mounts through the existing mount graph.
- Verified against pinned real-world JavaScript/Express repositories, including the CommonJS Conduit implementation with all 19 routes recovered.
- Published to npm as backend-skeleton@1.7.1 with GitHub Actions OIDC provenance.
Install:
npm install -g backend-skeleton@1.7.1
Validation: 1,845 tests passed locally with zero failures, package-install verification passed, and the full GitHub Actions matrix completed successfully.
v1.0.0
First stable release of backend-skeleton — a deterministic gate layer for AI-assisted (and human) backend work: before a change counts as done, bskel checks it against disk, not against what an agent or a person claims.
Published to npm as backend-skeleton:
npm install -g backend-skeleton
What 1.0.0 means
1.0.0 is an API-stability commitment, not a maturity claim: bskel's CLI surface — command/flag names and meaning, every --json output shape (all schemas under schemas/), gate names and pass/fail semantics, and exit codes — is now stable. Breaking that surface requires a major version bump. It does not mean every subsystem has been proven in production — handles codegen is functionally complete and tested but has never been deployed to a real production repo; that caveat is unchanged by this release. See D-stable-api-contract in DECISIONS.md for the full policy.
Highlights since 1.0.0-beta.3
81 commits, curated to the major feature areas (full design rationale for every decision — WHY, mechanism, real-oracle measurement, and what's explicitly deferred — lives in DECISIONS.md; the complete catalog is in CATALOG.md):
- Cross-feature safety — detects when two different features collide on the same resourceType/DB table/operationId (
bskel scan cross-feature-check), plus a 4th signal correlating a real live Postgres foreign-key edge across features, with a staleness/freshness token on every correlation. - Live database write path —
bskel patch propose --kind ddl-applyextends the existing propose/approve/apply/rollback lifecycle to hand-authored DDL against a real Postgres database, transaction-wrapped with automatic rollback on any postcondition mismatch, and a GitHub-style "type the table name to confirm" gate onDROP TABLE. - Cryptographically signed gate attestations —
bskel gate export --sign+ offlinebskel attest verify(Ed25519, zero new dependencies): CI-independent, verifiable-without-network proof of what a repo's gates looked like at capture time. - Runtime contract-conformance receipts — opt-in middleware (Java/Spring, Python/FastAPI, TypeScript/Express) validates real HTTP traffic against a feature's emitted contract, verdict-only, feeding a new
conformancegate — the first "static contract → observed reality" loop in this project. - Content-addressed patch transactions — generalizes config-file patching into a real propose/approve/apply/rollback lifecycle with a content-addressed preimage check, refusing to apply if the target changed since approval.
- Handle trust model (O3/O5) — opt-in
--enforce-registry(revocation-aware, checked on fetch/patch/recover), plus fetch and patch now derive independently correct authorization roles instead of silently sharing one. - Field-to-field dependencies —
bskel dependency declarerecords when one feature's data depends on another's, warns the source feature at codegen time, and ships a small local HTTP server with a read/write browser UI over the dependency graph. - npm publishing automated — OIDC trusted publishing (no long-lived token), with real provenance attestation.
npm test: 1325/1325 passing.
Status
Split by actual maturity, not by feature list — scan/contract/new have real, measured verification against a production Spring Boot repo; handles is functionally complete but not yet deployed to production. See README.md's Status section for the full breakdown.
v1.0.0-beta.3
First GitHub release for backend-skeleton — a spec-driven backend scaffolding CLI (bskel) that closes 5 real gaps found trialing Spec Kit-style workflows against brownfield repos: forced brownfield collision scanning, feature_id-keyed machine-readable contracts, UUID-addressable field handles, immediate stack-choice wiring, and worktree base-ref verification.
Published to npm as backend-skeleton:
npm install backend-skeleton@beta
What's in this release
Since npm's last publish (1.0.0-beta.2), three real slices landed:
- A9 — source-backed path-parameter schemas, replacing the
/id$/i→ UUID name heuristic with a real--openapi-filesource schema when one resolves. Fixes a genuine false-negative (batchRequestId, a plain string previously pinned to a UUID pattern) that madecontract validatereject a real, valid request. - A10 — opt-in operation-level
descriptionpassthrough (contract emit --descriptions), copying a source document's real operation description verbatim. - A11 — the same
--descriptionsflag extended one level deeper: schema field-leveldescription/example(a property's own annotation, distinct from the operation-level field) is now copied too.
Full design rationale for every decision (WHY / mechanism / real-oracle measurement / EXIT) lives in DECISIONS.md; the complete feature catalog (36+ items, what's built vs. explicitly deferred and why) is in CATALOG.md.
npm test: 973/973 passing.
Status
Pre-1.0, beta tag. Two catalog items (O3/O5 — the handle trust model and full authorization-contract enforcement) are deliberately deferred until handles are actually deployed to a production target; see CATALOG.md for the reasoning.