Skip to content

Leogriel v1.0.0-beta.3

Pre-release
Pre-release

Choose a tag to compare

@xFurti xFurti released this 18 Jul 20:26
· 6 commits to main since this release

Leogriel 1.0.0-beta.3

This prerelease consolidates the 1.0 candidate with stricter target diagnostics, complete structured import output, local opt-in runner validation, updated architecture and security documentation, and coordinated package hardening.

Full comparison: v1.0.0-beta.2...v1.0.0-beta.3

npm packages

All coordinated packages are published with the next dist-tag and verified against the attached tarballs:

  • @leogriel/core@1.0.0-beta.3
  • @leogriel/manifest@1.0.0-beta.3
  • @leogriel/lockfile@1.0.0-beta.3
  • @leogriel/link-manager@1.0.0-beta.3
  • @leogriel/plugin-system@1.0.0-beta.3
  • @leogriel/project-state@1.0.0-beta.3
  • @leogriel/adapters@1.0.0-beta.3
  • @leogriel/security@1.0.0-beta.3
  • @leogriel/registry@1.0.0-beta.3
  • @leogriel/import@1.0.0-beta.3
  • @leogriel/testing@1.0.0-beta.3
  • @leogriel/cli@1.0.0-beta.3

Install the prerelease CLI with npm install --global @leogriel/cli@next.

Added

  • Added leogriel test <skill> --compare <git-ref> to run paired regressions between the skill at an immutable Git commit and the current working-tree candidate, recording both integrity hashes.
  • Added an official composite GitHub Action with frozen restore, Job Summary, redacted JSON/Markdown/HTML reports, downloadable artifacts, Shields badge data, optional pull-request comments, and fail-after-report regression enforcement.
  • Added an experimental Claude Code AgentRunner alongside Codex, with version/capability detection, isolated configuration, fail-closed native sandboxing, subprocess credential filtering, default-deny networking, explicit staged-skill injection, and an opt-in live smoke.
  • Added bilingual public-contract and 1.0 migration candidates plus an evidence-based external validation matrix for local, redacted runner validation.

Changed

  • Made live runner validation local and opt-in, removing the hosted credential workflow while retaining the composite Action as an optional consumer feature.
  • Replaced the mixed current/historical design document with a concise Leogriel architecture and archived the original skillctl proposal under docs/history/.
  • Removed the unused registries and experimental.plugins config type fields; legacy values are ignored without changing config schema version 1.
  • Added repository security guidance, structured issue and pull-request templates, and automated documentation/version/meta-skill contract checks.
  • Restricted every published package to an explicit public root export in preparation for stable API contracts.
  • Extended plugin audit findings with categories, remediation, confidence, and evidence fields matching the first-party audit model.
  • Updated tar to 7.5.20 and removed the deprecated external @types/tar package.

Fixed

  • Made doctor report missing and managed-stale targets as warnings with exit code 1, expose state counts, and re-inspect targets after --fix.
  • Added structured schema-1 JSON output to plain leogriel import, including deterministic dry-run and empty-project results.
  • Completed help descriptions for backup and plugin lifecycle subcommands and rejected interactive import flags in JSON mode.
  • Ignored the built-in Pi adapter target directory in the repository dogfood state.
  • Aligned the README, package documentation, bilingual site, migration guide, validation matrix, roadmap, contributor guide, and first-party skill with the beta.3 candidate.
  • Made non-interactive Codex runs set an explicit no-prompt approval policy and require the elevated native Windows sandbox, preserving fail-closed workspace writes and network denial.
  • Made the release gate execute the root test command so release-script contract tests cannot be skipped.
  • Updated the architecture document to reflect the completed Leogriel rebrand and current beta baseline.
  • Removed active 0.5.0 fallbacks from HTTP and import runtime metadata; both now derive their version from the owning package and use unknown only when package metadata is unavailable.
  • Included ANTHROPIC_API_KEY in centralized CLI output redaction and kept authentication variables out of runner installation steps.