v2026.8.2
·
792 commits
to main
since this release
@unbrained/pm-cli 2026.8.2
Source range: v2026.8.1...v2026.8.2
Changelog
Added
- Episode identity: a stable, labelled, nestable episode key that survives process, surface and harness boundaries so trajectory grouping and fleet aggregation have a join key (pm-oqo9l2)
Fixed
- Both published bin names are refused as subcommands, so npx PKG pm init and bunx PKG pm init fail while the version probe that guards them passes (pm-rnl3sa)
- The intent budget binds downward and is inert upward: a sevenfold budget increase buys zero rows and the field that would reveal the clamp is omitted exactly when it applies (pm-prsvjh)
- The MCP action vocabulary is not derived from the CLI contract table: 26 MCP-only spellings, and seven contracted capability families including merge, workspace snapshot and eval have no MCP route at all (pm-0834kq)
- The SDK boundary gate proves the CLI stopped importing private core and never proves the CLI only imports the published SDK, so ten private SDK modules carry our own commands (pm-xpumg4)
- GH-855: core mutation locators must honor extension-registered item types (pm-scga6k)
- GH-853: extension command test harness must inject the real host-bound SDK (pm-wx2lr5)
- Session-topic provenance has no descriptor keys on any harness, and effort/role are wired for only claude-code and codex, so most fleet history records harness and model but nothing about the work's shape (pm-rbg1qo)
- Explicit-unavailable provenance is recorded for the model dimension only, so effort and role absence is permanently indistinguishable from a legacy entry (pm-9wbiye)
- GH-851: compare init discovery roots by filesystem identity (pm-noq46i)
- GH-847: tighten managed built-in static SDK contracts and author guidance (pm-ka6m65)
- The MCP server never receives the harness provenance environment, so one agent session writes permanently divergent identity records depending on which surface it used (pm-1zhfls)
- The bounded read costs 13.8 times the unbounded read to deliver the same set, because eight metadata blocks are re-emitted per page and the page carries two rows (pm-sf31yl)
- Declared intent token budgets are smaller than the smallest projection their own command can emit, so three of five intents return no result at all on this tracker (pm-yekkvt)
- Declared read-intent token budgets are written to a flag three of five intent commands do not accept, so the shipped intent layer overruns its own declaration by up to 43.8x (pm-7hbfch)
- The public SDK's item-lifecycle surface re-exports CLI command modules, so lifecycle policy cannot be expressed, inspected, or overridden through the SDK (pm-z5pmf8)
Security
- GH-854: transactional extension mutation guards for enforceable domain invariants (pm-hx23u5)
- CodeQL alert 33: eliminate polynomial trailing-whitespace matching in SDK append (pm-8wskoj)
Other
- Self-reported token accounting: any command can report the token cost of its own output so budget spend is attributable at runtime and in CI (pm-t5dt4z)
PM Tracker Evidence
Closed pm items in release window: 20
By type: Issue=17, Story=1, Feature=1, Task=1
By status: closed=20
Selected release-related tracker items:
- pm-rnl3sa [Issue/closed] Both published bin names are refused as subcommands, so npx PKG pm init and bunx PKG pm init fail while the version probe that guards them passes