Skip to content

chore(deps): update Superpowers to v6.2.0 - #142

Merged
rochecompaan merged 1 commit into
mainfrom
automation/superpowers-v6.2.0
Aug 6, 2026
Merged

chore(deps): update Superpowers to v6.2.0#142
rochecompaan merged 1 commit into
mainfrom
automation/superpowers-v6.2.0

Conversation

@patchmill-release-please-bot

Copy link
Copy Markdown
Contributor

Superpowers dependency upgrade

Updates Superpowers from 6.0.3 to 6.2.0.
This pull request is review-gated and does not auto-merge or publish.

Changed files

  • .patchmill/skills/brainstorming/SKILL.md
  • .patchmill/skills/dispatching-parallel-agents/SKILL.md
  • .patchmill/skills/executing-plans/SKILL.md
  • .patchmill/skills/finishing-a-development-branch/SKILL.md
  • .patchmill/skills/patchmill-skill-pack.json
  • .patchmill/skills/receiving-code-review/SKILL.md
  • .patchmill/skills/requesting-code-review/SKILL.md
  • .patchmill/skills/subagent-driven-development/SKILL.md
  • .patchmill/skills/subagent-driven-development/implementer-prompt.md
  • .patchmill/skills/subagent-driven-development/re-review-prompt.md
  • .patchmill/skills/subagent-driven-development/scripts/review-package
  • .patchmill/skills/subagent-driven-development/scripts/sdd-workspace
  • .patchmill/skills/subagent-driven-development/scripts/task-brief
  • .patchmill/skills/subagent-driven-development/task-reviewer-prompt.md
  • .patchmill/skills/systematic-debugging/SKILL.md
  • .patchmill/skills/systematic-debugging/find-polluter.sh
  • .patchmill/skills/test-driven-development/SKILL.md
  • .patchmill/skills/test-driven-development/testing-anti-patterns.md
  • .patchmill/skills/test-driven-development/writing-good-tests.md
  • .patchmill/skills/using-git-worktrees/SKILL.md
  • .patchmill/skills/using-superpowers/SKILL.md
  • .patchmill/skills/using-superpowers/references/antigravity-tools.md
  • .patchmill/skills/using-superpowers/references/claude-code-tools.md
  • .patchmill/skills/using-superpowers/references/codex-tools.md
  • .patchmill/skills/using-superpowers/references/copilot-tools.md
  • .patchmill/skills/using-superpowers/references/pi-tools.md
  • .patchmill/skills/verification-before-completion/SKILL.md
  • .patchmill/skills/writing-plans/SKILL.md
  • .patchmill/skills/writing-skills/SKILL.md
  • THIRD_PARTY_NOTICES.md
  • nix/package.nix
  • npm-shrinkwrap.json
  • package-lock.json
  • package.json
  • src/workflow/skill-pack.ts

Validation

  • npm ci
  • node bin/patchmill.ts skills update
  • node --test src/cli/commands/init/pi-dependency-contract.test.ts
  • npm test
  • node scripts/smoke-packed-artifact.mjs
  • npm run lint
  • scripts/update-npm-deps-hash.sh
  • nix build .#patchmill --print-build-logs

Upstream release notes

v6.1.0

Published: 2026-06-30T18:42:18Z

Release: https://github.com/obra/superpowers/releases/tag/v6.1.0


### Lower Per-Session Token Cost

The `using-superpowers` bootstrap is injected into every session, so its size is paid for constantly. This release trims it and the per-harness references it points to, without dropping behavior-shaping content.

- **Compressed the `using-superpowers` bootstrap.** Replaced the graphviz skill-flow diagram with the prose it encoded, folded the standalone Instruction-Priority section into User Instructions, dropped the per-platform "How to Access Skills" walkthrough, and trimmed the Platform Adaptation pointer to the harnesses that still ship a reference file. The full Red Flags rationalization table and the user-instruction precedence rules are unchanged.
- **Pruned the per-harness tool-mapping references.** The verbose action-to-tool tables restated guidance modern agents already follow. Each reference file is trimmed to the harness-specific notes that still carry weight — subagent dispatch, task tracking, instructions-file paths — and `claude-code-tools.md` and `copilot-tools.md`, which had nothing harness-specific left, are deleted.

### Codex

- **Codex can install from the marketplace.** Codex marketplace sources expect a `.agents/plugins/marketplace.json` at the marketplace root; the repo only shipped the Claude marketplace file, so Codex could name the marketplace but found no installable plugin entries. A repo-local Codex marketplace manifest now points at the same repository root, so the plugin is installable from Codex.
- **Codex no longer ships a SessionStart hook.** Codex reliably triggers skills on its own, and the bootstrap hook made the UX worse rather than better. The Codex hook config (`hooks-codex.json`) and its manifest registration are removed.

### Harness Support

- **Gemini CLI support removed.** Google EOLed the Gemini CLI on 2026-06-18; the extension can no longer be installed or updated. Gemini is gone from the install docs, the subagent-capable platform lists, and the eval-harness description, and its tool-mapping reference is deleted.


v6.1.1

Published: 2026-07-02T21:58:30Z

Release: https://github.com/obra/superpowers/releases/tag/v6.1.1

## v6.1.1 (2026-07-02)

### Codex

- **Codex no longer re-registers the Claude SessionStart hook.** v6.1.0 removed the Codex hook config and its manifest `hooks` pointer, meaning to stop Codex from installing a SessionStart hook — but with no `hooks` field, Codex fell back to auto-discovering `hooks/hooks.json`, the Claude Code SessionStart hook that the marketplace ships from the repo root, and re-registered it along with its install-time trust prompt. The Codex manifest now declares an explicit empty hooks object (`hooks: {}`), which Codex reads as "no hooks" instead of reaching the auto-discovery fallback. An absent field, `[]`, and an empty inline list all collapse back to the fallback, so the value has to be exactly `{}`.
- **Removed orphaned Codex session-start dead code.** `hooks/session-start-codex` had no caller once the Codex hook config was deleted, so it and its redundant test cases are gone. The worked shell-hook example in `docs/porting-to-a-new-harness.md` moves from Codex — now native skill discovery with no session-start hook — to Cursor, a live shell-hook harness, and the stale `hooks-codex.json` pointer in `docs/windows/polyglot-hooks.md` is corrected. The Codex plugin category is also fixed to "Developer Tools".

### Packaging

- **New `package-codex-plugin.sh` for building the Codex portal package.** A maintainer script produces a deterministic Codex "portal" archive — `.zip` by default, `tar.gz` on request — that normalizes entry timestamps, preserves executable modes, verifies every packaged skill ships its OpenAI metadata, includes the app and composer icons, and refuses to run against a dirty worktree. The packaged manifest keeps the source `hooks: {}` object so a portal-installed plugin avoids the same SessionStart auto-discovery, and the script can rebuild a byte-identical archive from a saved metadata source. Covered by a new test suite.


v6.2.0

Published: 2026-07-24T00:28:17Z

Release: https://github.com/obra/superpowers/releases/tag/v6.2.0

## v6.2.0 (2026-07-23)

### Subagent-Driven Development

Two structural changes to how SDD tracks progress and closes out review findings, both developed against live eval campaigns.

- **The workspace is now plan-scoped.** `.superpowers/sdd/` had no plan identity and no end-of-life: a follow-up plan in the same working tree could read the previous plan's ledger as its own progress (observed in the wild, with multiple contamination rounds and ad-hoc workarounds). `sdd-workspace` now requires the plan file and resolves a per-plan directory, `.superpowers/sdd/<plan-basename>/`; `task-brief` and `review-package` write into their plan's directory (`review-package` gains the plan file as its first argument); the ledger names its plan on its first line; and the workspace is deleted once the final review is clean — git history is the durable record. Baseline evals showed controllers already refused foreign ledgers, but at a cost of 6–13 tool calls of cross-plan git forensics per resume; plan-scoping makes the answer structural instead. (25/25 baseline and GREEN eval runs documented in `docs/specs/` and `docs/plans/`.)
- **The review-fix loop resumes the implementer.** The lifecycle restructure gives fix rounds resume-the-implementer semantics instead of fresh dispatches, adds a scoped re-review prompt (`re-review-prompt.md`) so the re-reviewer checks the fixes rather than re-reading the whole task, and installs a five-round circuit breaker with controller adjudication when it trips. SKILL.md reorganizes by lifecycle, and its Red Flags convert to the house rationalization-table form.

### Skills

A branch-wide compression campaign: recap sections, social proof, and benefits-selling prose aimed at a reader who has already invoked the skill are gone, with every load-bearing argument folded into a rationalization-table row or moved to its point of use. Each cut was micro-tested with subagent probes, and the one cut that measurably degraded behavior was reworked rather than shipped.

- **`testing-anti-patterns.md` is now `writing-good-tests.md`.** The TDD reference doc is rebuilt as a positive catalog — six rules that lead with the GOOD example — and absorbs a falsifiability discipline: name the production change that would fail the test, derive expectations independently of the code under test, and a closing mutation check. It closes two holes by name: the string-presence trap (grep-style tests on scripts, skills, and prompts counterfeit falsifiability — the observable is behavior, never text) and the change-detector trap (a constant assertion can fail and still protect nothing), each with a hard stop in the gate function. Trivial code and human prose earn no test; the trigger broadens from "adding mocks" to any test writing.
- **TDD's "Why Order Matters" rebuttals survive as rationalization rows.** Deleting the section outright measurably degraded test-first behavior under "just write it, tests after" pressure (control 8/10 → treatment 5/10, corroborated on Claude and Codex), so each prose rebuttal now lives in its Common Rationalizations row — the section is gone but the arguments fire where an agent hits them mid-rationalization.
- **`finishing-a-development-branch` no longer offers to discard your work.** The completion menu dates from when throwing away branches was routine; "Discard this work" next to "Merge" advertised destroying finished, passing work. Discard survives as an explicit-request-only path with the same typed-confirmation ritual. The same pass made PR creation forge-agnostic (your forge's CLI or the URL printed on push, not a blessed list of tools) and fixed a real bug: the worktree path was recomputed after cleanup had already changed directory, so provenance checks never matched and cleanup silently no-oped.
- **Recap and persuasion prose removed across the library.** `brainstorming`, `systematic-debugging`, `dispatching-parallel-agents`, `verification-before-completion`, `executing-plans`, `subagent-driven-development`, `requesting-code-review`, `receiving-code-review`, `using-git-worktrees`, `writing-plans`, and `writing-skills` all drop their Bottom Line / Key Principles / Real-World Impact / Advantages sections; `using-git-worktrees` and `finishing-a-development-branch` convert their guard sections to the house Excuse/Reality rationalization table.

### Windows

- **The SessionStart hook now dispatches via Git Bash.** The hook's command string starts with a quoted path, which broke both shells Claude Code might hand it to: PowerShell parsed the quoted string as an expression and died with a parser error (#1751), and cmd.exe's quote-stripping rule truncated the command when the profile path contained a metacharacter like `(` (#1918) — either way the bootstrap silently never loaded. The hook now declares `shell: "bash"`, which Claude Code ≥ 2.1.81 resolves to Git for Windows directly, and which surfaces an actionable install prompt when Git Bash is missing. Older Claude Code versions ignore the unknown key and behave as before. Verified end-to-end on Linux, Windows 11 with Git Bash under a hostile path, and Windows 11 without Git Bash.

### Harness Support

- **Gemini CLI support is restored.** The v6.1.0 removal (on the news that Google had EOLed the Gemini CLI) was premature; the install docs and the `gemini-tools.md` tool-mapping reference are back while permanent removal gets a proper evaluation. (#1959)

### Fixes

- **`find-polluter.sh` actually finds test files now.** `find .` emits `./`-prefixed paths, so the documented `-path "src/**/*.test.ts"` pattern matched nothing — and `wc -l` on empty input then reported "Found 1". Fixed the prefix mismatch (#2008, #2011), plus two follow-ups: a caller-supplied `./`-prefixed pattern no longer double-prefixes into a never-matching form, and `**/` is also matched collapsed so tests directly under the base directory (`src/top.test.ts` vs `src/**/*.test.ts`) aren't silently skipped. The script gains a deterministic test suite.
- **The Codex package script works beyond macOS.** Deterministic-metadata tar flags were bsdtar-only spellings, staged file modes depended on two umasks canceling out, and the test's timestamp assertion parsed bsdtar's column layout in a US timezone. GNU tar now gets equivalent flags producing byte-identical headers, modes are pinned canonical, and the test asserts mtime via `tarfile`.
- **SDD's skill test no longer flakes.** The file's worst case exceeded the runner's per-file ceiling (raised to 900s), and the assert helpers matched free-form model prose case-sensitively; matching is now case-insensitive and `assert_order` dumps output on failure so the next flake is diagnosable.
- **Docs and test cleanup after the v6.1.0 reference pruning.** Dead links to the deleted `claude-code-tools.md`/`copilot-tools.md` are replaced with the current architecture (#1969), a dangling `#subagent-support` anchor in the Antigravity reference is dropped (#2010), and the Antigravity/Pi mapping tests assert only the surviving harness-specific mappings — scoped to the table so they fail again if it's deleted.


@rochecompaan
rochecompaan merged commit 4089687 into main Aug 6, 2026
2 checks passed
@rochecompaan
rochecompaan deleted the automation/superpowers-v6.2.0 branch August 6, 2026 10:40
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant