Releases: trugurpala/divan
Releases · trugurpala/divan
Release list
Divan v0.16.0
Immutable
release. Only release title and notes can be modified.
Divan v0.16.0
Added
- Schema 2 installed-project ownership with immutable Divan source identity,
project identity, and hashes for every managed whole file or marked block. - Read-only
project status, dry-run-first transactionalproject update, and
intentionally narrowproject repaircommands with fail-closed drift,
marker, symlink/reparse, stale-plan, and unowned-path handling. - Verified goal archival with receipt/artifact hash binding, collision checks,
controlled source removal, and rollback on interrupted application. - Privacy-bounded JSON and Markdown adoption receipts with explicit
maintainer/independent declarations and offline verification.
Changed
divan-project.pyznow carries source metadata schema 2 and the complete
ownership, lifecycle, archive, and adoption engine while retaining
deterministic byte-identical builds.- DCS-007 and the impact graph now cover host lifecycle and installed-project
lifecycle together. English/Turkish README, Project OS, install, Wiki, and
publication surfaces distinguish host update, project update, audit, and
lifecycle status. - Ruff, mypy, coverage, and the Clean Code debt ratchet now include the
first-party Company OS runtime instead of measuring onlyscripts/and
evals/. Existing exact-symbol debt is pinned and cannot grow silently.
Security
- Project updates run only from the immutable code already executing; they do
not fetch remote refs or execute target-project code. Install state is written
last inside the proven locked, journaled, authority-bound transaction. - Repair never force-overwrites user changes. Adoption exports reject secrets,
email addresses, usernames, absolute paths, remotes, unrelated plugin
inventory, and command-output bodies.
Verified
- The release candidate passed the full local unit suite with 10
platform-specific skips plus focused lifecycle, archive, adoption,
reproducible-runner, Unicode, and fail-closed impact tests. - Five packages and 41 discoverable skills remain unchanged. Owner-operated
canary evidence is classified separately and cannot close the independent
adoption gate; v1 readiness remains 7/8. - This entry records local release preparation only. PR checks, immutable
main, tag, GitHub Release, assets/attestations, Pages, Wiki, canary readback,
and dual-host global update require separate evidence.
Sabitlenmiş kurulum
- Claude Code/Desktop Code + Codex:
python scripts/divan.py install --host both --ref v0.16.0 --execute. - Önce dry-run için aynı komutu
--executeolmadan çalıştırın. - Eski-host fallback varlıkları:
divan-v0.16.0.zipvedivan-v0.16.0.sha256.
Yükseltmeden önce kurulum ve kaldırma/geri alma rehberlerini okuyun.
Divan v0.15.0
Immutable
release. Only release title and notes can be modified.
Divan v0.15.0
Added
- A portable Project OS contract with deterministic
init,inspect,audit,
plan,impact,goal,verify,release, and receipt-verification
routes. Installed projects receive bounded.divan/rules, specs, plans,
tasks, waivers, and append-only evidence without losing existing host text. - Twelve
DPS-*installed-project standards, scoped by project type, alongside
Divan's existingDCS-*repository-maintenance standards. - Unicode-aware English/Turkish intent routing, recursive bounded workspace
discovery, native package-manager command detection, multi-workflow
composition, and fail-closed impact classification. - Provider capability contracts for local, GitHub, Context7, and Vercel
delivery; a read-only composite action; and a reproducible standalone
divan-project.pyzrunner. - Static public-web SEO contracts covering canonical metadata, robots,
sitemap, hreflang, social cards, structured data, internal links, and pinned
Lighthouse CI/Lychee evidence.
Changed
- Sadrazam can carry a supervised goal from intent through specification,
planning, verified evidence, preview, release, and live observation while
keeping provider mutations behind explicit authority. - English machine interfaces and public technical documentation are canonical;
Turkish localization remains synchronized and first-class. Existing Turkish
script names remain bounded compatibility wrappers throughout0.x. - README, Project OS and Company OS guides, Community Standards, Wiki sources,
Pages/site metadata, install references, and release manifests now share one
change-impact and publication contract.
Security
- Project discovery never executes target code, rejects symlink/path escape,
bounds traversal and input sizes, and reports every unknown changed path as
unclassified. - Project initialization is dry-run-first, idempotent, transactionally locked,
atomic, and fail-closed on malformed managed blocks or untrusted recovery
state. - Release completion requires provider-native, source-bound evidence and live
readback. Missing capabilities remainBLOCKED; ambient executables,
environment variables, local JSON, secrets, and hidden reasoning cannot
establish release authority.
Verified
- The approved release candidate passed 452 repository tests with 10
platform-specific skips, Ruff, mypy, the Clean Code debt ratchet, and 71%
branch coverage against the 64% floor. - Five packages and 41 discoverable skills remain unchanged. The independent
adoption gate remains open, so v1 readiness honestly stays 7/8. - This section records local release preparation only. PR checks, immutable
main, tag, GitHub Release, Pages, Wiki, attestations, and dual-host global
installation require separate post-merge evidence.
Sabitlenmiş kurulum
- Claude Code/Desktop Code + Codex:
python scripts/divan.py install --host both --ref v0.15.0 --execute. - Önce dry-run için aynı komutu
--executeolmadan çalıştırın. - Eski-host fallback varlıkları:
divan-v0.15.0.zipvedivan-v0.15.0.sha256.
Yükseltmeden önce kurulum ve kaldırma/geri alma rehberlerini okuyun.
Divan v0.14.1
Immutable
release. Only release title and notes can be modified.
Divan v0.14.1
Fixed
- Codex marketplace snapshots now accept Codex's validated, isolated
.codex-marketplace-install.jsonmetadata file even when the CLI reports an
explicit marketplace ref. Other untracked files, malformed metadata, source
drift, and ref drift remain fail-closed.
Sabitlenmiş kurulum
- Claude Code/Desktop Code + Codex:
python scripts/divan.py install --host both --ref v0.14.1 --execute. - Önce dry-run için aynı komutu
--executeolmadan çalıştırın. - Eski-host fallback varlıkları:
divan-v0.14.1.zipvedivan-v0.14.1.sha256.
Yükseltmeden önce kurulum ve kaldırma/geri alma rehberlerini okuyun.
Divan v0.14.0
Immutable
release. Only release title and notes can be modified.
Divan v0.14.0
Added
- Company OS contracts for 12 functional roles, 8 delivery workflows,
evidence-based framework detection, and transitive change-impact analysis. - A portable
scripts/divan.pyCLI for project inspection, planning, impact
analysis, contract validation, install, update, doctor, and recovery. - DCS-011 and a machine-readable naming policy enforcing English canonical
technical entrypoints with Turkish localization and bounded legacy aliases. - English and Turkish Company OS guides plus synchronized Pages and Wiki entry.
Changed
- Sadrazam now routes natural-language intent through Company OS and selects the
smallest justified combination of Core, UI, React, and Zanaat packs. - English is the canonical README and contributor surface; Turkish remains
first-class throughREADME.tr.mdandCONTRIBUTING.tr.md. - Workflows and maintainer scripts use English canonical names. Pre-v1 Turkish
script names remain narrow deprecated wrappers to avoid breaking users.
Security
- Project inspection is bounded, read-only, path-safe, and never executes
project code. - Framework packs are selected from manifest evidence; integrations and
creative tooling are not activated for unrelated tasks.
Sabitlenmiş kurulum
- Claude Code/Desktop Code + Codex:
python scripts/divan.py install --host both --ref v0.14.0 --execute. - Önce dry-run için aynı komutu
--executeolmadan çalıştırın. - Eski-host fallback varlıkları:
divan-v0.14.0.zipvedivan-v0.14.0.sha256.
Yükseltmeden önce kurulum ve kaldırma/geri alma rehberlerini okuyun.
Divan v0.13.0
Immutable
release. Only release title and notes can be modified.
Divan v0.13.0
Added
- A machine-readable registry for DCS-001..DCS-010, narrow expiring
exceptions, deterministic documentation, and a CI enforcement gate. - Read-only
--doctor, dry-run-first--upgrade, and ownership-checked
interrupted-transaction recovery for Claude Code/Desktop Code and Codex. - Deterministic SPDX 2.3 SBOM generation, OpenSSF Scorecard, pull-request
dependency review, and release provenance for both ZIP and SBOM assets. - Bilingual contribution guidance, request-specific support routes, and a
version-controlled 1280x640 Mühürdar social preview under 1 MB.
Changed
- New code is ratcheted at McCabe 10, 50 lines per function, and 400 lines per
module. The enforced branch-coverage floor is the recorded 64% baseline. - The legacy-debt registry must exactly match current violations; growth is
rejected and shrinkage/removal requires the same reviewed baseline refresh. - Host adapters, transaction journals, lock/transition validation, eval
provenance, and result contracts moved into smaller stdlib modules. - README, Wiki sources, Pages, install, upgrade, rollback, uninstall, and
contribution surfaces now share one five-minute first-success path.
Security
- Upgrade refuses host mutation until it proves a clean pinned source commit,
catalog digest, full package fingerprints, and a single active transaction. - Durable intent is written before every external mutation. Verification and
rollback touch only transaction-owned Divan rows and reject foreign state. - GitHub Actions remain full-SHA pinned, narrowly permissioned, and release
assets are never overwritten. - Social-preview validation traverses every PNG chunk and requires valid CRCs,
one exact IHDR, at least one IDAT, and a terminal empty IEND.
Verified
- Local pre-release integration passed 223 tests (2 platform-specific Windows
skips), Ruff, mypy, Clean Code, actionlint 1.7.10, skills-ref 0.1.1 for all
41 skills, and Claude Code 2.1.212 for the marketplace and five packages. - This is local release-candidate evidence. PR/main, repository rules, Pages,
Wiki, tag, GitHub Release, attestations, and global v0.13.0 host upgrade are
separate delivery states that remain pending. - v1 remains 7/8 because no independent non-owner acceptance evidence exists.
Sabitlenmiş kurulum
- Claude Code/Desktop Code + Codex:
python scripts/kur-hostlar.py --host both --ref v0.13.0 --execute. - Önce dry-run için aynı komutu
--executeolmadan çalıştırın. - Eski-host fallback varlıkları:
divan-v0.13.0.zipvedivan-v0.13.0.sha256.
Yükseltmeden önce kurulum ve kaldırma/geri alma rehberlerini okuyun.
Divan v0.12.2
Immutable
release. Only release title and notes can be modified.
Divan v0.12.2
Fixed
scripts/hijyen.py --cleanartık Windows'ta salt-okunur özniteliği taşıyan
allowlist cache ağaçlarını, silme sınırını genişletmeden yazılabilir yapıp
kalıcı kaldırır.- Windows salt-okunur
__pycache__regresyonu birim testine bağlandı.
Sabitlenmiş kurulum
- Claude Code/Desktop Code + Codex:
python scripts/kur-hostlar.py --host both --ref v0.12.2 --execute. - Önce dry-run için aynı komutu
--executeolmadan çalıştırın. - Eski-host fallback varlıkları:
divan-v0.12.2.zipvedivan-v0.12.2.sha256.
Yükseltmeden önce kurulum ve kaldırma/geri alma rehberlerini okuyun.
Divan v0.12.1
Immutable
release. Only release title and notes can be modified.
Divan v0.12.1
Added
scripts/hijyen.py --check/--clean: UTF-8/BOM/mojibake denetimi, açık
subprocess kodlaması kuralı ve yalnız yeniden üretilebilir cache'leri silen
fail-closed repo temizliği.- UTF-8/LF editor ve Git sözleşmesi ile Ruff C90 McCabe 25 karmaşıklık bütçesi.
Changed
- Pazar, skill, belge, ajan ve vitrin denetimleri isimli tek-sorumluluk
fonksiyonlarına ayrıldı; kurulum rollback'i ile v1 kanıt doğrulaması aynı
public davranışı koruyan aşamalara bölündü. - Windows sistem locale'ine bırakılan host CLI ve Git metin çıktıları açık
encoding="utf-8"sözleşmesine geçirildi.
Security
- Temizlik allowlist dışındaki yedek, manifest, kanıt ve kullanıcı dosyalarını
silmez. Aktif rollback yedekleri korunur; yalnız üretilebilir cache içeriği
kalıcı kaldırılabilir.
Sabitlenmiş kurulum
- Claude Code/Desktop Code + Codex:
python scripts/kur-hostlar.py --host both --ref v0.12.1 --execute. - Önce dry-run için aynı komutu
--executeolmadan çalıştırın. - Eski-host fallback varlıkları:
divan-v0.12.1.zipvedivan-v0.12.1.sha256.
Yükseltmeden önce kurulum ve kaldırma/geri alma rehberlerini okuyun.
Divan v0.12.0
Immutable
release. Only release title and notes can be modified.
Divan v0.12.0
Added
- Native Codex marketplace manifests for the same five packages and 41 skills
already published through Claude Code, with a cross-host drift validator. - Dry-run-first transactional installer for Claude Code/Desktop Code and Codex;
it records pre-state, preserves unrelated plugins, verifies all packages, and
rolls back only entries created by the failed transaction. - First-party real-provider evaluation adapters: Claude Code as the bounded
agent and an ephemeral read-only Codex process as the blinded JSON judge. - CodeQL, Ruff, mypy, Coverage, actionlint, and immutable GitHub Action pins.
Changed
- The legacy loose-skill installer is now a compatibility fallback. Release
archives are SHA-256 verified before extraction and manifests record version,
ref, source commit, archive hash, per-skill installed hash, install time,
target, and backup. Migration preflights every row, quarantines owned content,
preserves changed targets, and reverses every move on failure. - Site navigation now has a keyboard-visible skip link, one main landmark,
WCAG AA coral contrast, reduced-motion verification, and mobile/landscape
overflow checks in real Chromium. - Root licensing is canonical MIT with separate notices; 15 current upstream
differences were reviewed and pinned without automatically copying content.
Security
- Release workflows publish a versioned fallback archive and checksum with its
source commit; mutablemaindownloads, mutable Action tags, moved release
tags, and release-asset overwrite attempts are rejected. - Host mutations are atomically journaled before execution and interrupted
transactions have an ownership-checked, resumable recovery command. Legacy
migration and fallback copying use their own durable, reversible journals;
parent rollback restores even a completed legacy migration before removing
native packages and fails closed if the recorded legacy journal is missing. - Eval subprocesses are bounded, do not use dangerous bypass flags, redact
secrets/PII/home paths, keep per-case A/B outcomes private, and bind publishable
provenance to a clean Git HEAD plus provider-derived versions. Windows
provider.cmdwrappers are resolved without invoking a shell for other
commands, adapter JSON I/O is explicitly UTF-8 across platforms, and the
Codex judge disables plugins while using a strict static score-array schema.
Verified
- Fixture and repository tests prove host preservation/rollback, checksum
fail-closed behavior, transactional legacy quarantine, marketplace parity,
blind judging, and accessibility. - A publishable first-party comparison ran three
baglam-muhafizicases with
Claude Code 2.1.209 /claude-sonnet-5as the bounded agent and Codex CLI
0.144.4 /gpt-5.6-terraas the blinded judge. The skill condition won zero
cases, baseline won one, and two tied; no release threshold was predeclared,
so this is auditable run evidence rather than a quality-improvement claim. Independent
adoption remains pending for v1. - Public eval evidence uses a commit-reveal boundary with a runner-generated
256-bit OS-random seed: the raw blinding seed, condition mapping, per-case
winner, and judge reasons remain in the private
key while the public provenance records only the seed's SHA-256 commitment.
Sabitlenmiş kurulum
- Claude Code/Desktop Code + Codex:
python scripts/kur-hostlar.py --host both --ref v0.12.0 --execute. - Önce dry-run için aynı komutu
--executeolmadan çalıştırın. - Eski-host fallback varlıkları:
divan-v0.12.0.zipvedivan-v0.12.0.sha256.
Yükseltmeden önce kurulum ve kaldırma/geri alma rehberlerini okuyun.
Divan v0.11.1
Divan v0.11.1
Added
- Repository-root
CLAUDE.md, giving Claude Code a native durable handoff
contract instead of relying on prior chat context. scripts/devral.py --checkand regression tests that reject a missing
handoff chain or a progress journal without an exact next action.- GitHub Actions Dependabot configuration and CODEOWNERS coverage for policy,
automation, release, registry, and project-memory surfaces.
Changed
- Sadrazam advanced to 0.9.1; SessionStart now surfaces the Claude handoff
contract before the current progress journal. - Publication and local audit gates now cover Claude handoff and dependency
maintenance as release-controlled surfaces.
Security
- Guidance distinguishes controls stored in Git from GitHub settings requiring
platform verification: rulesets, required reviews, secret scanning, push
protection, Dependabot alerts, and CodeQL.
Sabitlenmiş kurulum
- Claude Code: marketplace'i ekledikten sonra paketleri
divankaynağından kurun. - Codex/macOS/Linux:
DIVAN_REF=v0.11.1ilescripts/kur-codex.shkullanın. - Codex/Windows:
$env:DIVAN_REF = "v0.11.1"ilescripts/kur-codex.ps1kullanın.
Yükseltmeden önce kurulum ve kaldırma/geri alma rehberlerini okuyun.
Divan v0.11.0
Divan v0.11.0
Added
- Publication control plane with a machine-readable surface manifest,
deterministic version preparation, drift checks, and changelog-derived
GitHub Release notes. - Idempotent
mainworkflow that waits for matching Pages and Wiki versions,
then creates the immutable tag/Release or updates notes without moving a tag. - Clean-host compatibility matrix: official Claude Code marketplace validation
plus Codex install/discovery/removal on Ubuntu, macOS, and Windows. - Manifest-driven Codex removal/rollback scripts, independent adoption evidence
issue form, and a generated machine-readable v1 readiness scorecard. /yayincommand and Sadrazam publication-surface law so future agents do not
rely on the user to remind them about README, Wiki, site, or Release pages.
Changed
- Sadrazam advanced to 0.9.0 and the public publication contract now treats
README, marketplace, Pages, Wiki, changelog, tag, and GitHub Release as one
ordered but separately verified delivery chain. - v1 claims are gated by eight explicit evidence records; real-agent comparison
and independent adoption remain pending instead of being inferred.
Verified
- Unit coverage rejects stale public surfaces, validates release-note sourcing,
checks the generated v1 scorecard, and rehearses installer rollback. - GitHub's official documentation was used for least-privilege
contents: write, non-recursiveGITHUB_TOKENbehavior, and workflow
concurrency design. - PR #12 and all seven post-merge workflows passed. The release workflow
verified Linux/macOS/Windows rollback, live Pages and Wiki markers, and the
interactive site in Chromium before publishing tag/Release v0.11.0 at
commit5680337a.
Sabitlenmiş kurulum
- Claude Code: marketplace'i ekledikten sonra paketleri
divankaynağından kurun. - Codex/macOS/Linux:
DIVAN_REF=v0.11.0ilescripts/kur-codex.shkullanın. - Codex/Windows:
$env:DIVAN_REF = "v0.11.0"ilescripts/kur-codex.ps1kullanın.
Yükseltmeden önce kurulum ve kaldırma/geri alma rehberlerini okuyun.