diff --git a/CHANGELOG.md b/CHANGELOG.md index b96f0d4b9d..1666036b80 100644 --- a/CHANGELOG.md +++ b/CHANGELOG.md @@ -7,52 +7,28 @@ and this project adheres to [Semantic Versioning](https://semver.org/spec/v2.0.0 ## [Unreleased] -### Fixed - -- `apm install` now fails on incompatible immutable dependency requirements instead of silently keeping one version, including inconsistent frozen replay and short SHA pins; equivalent tag/SHA pins remain valid. Align root/parent refs, then run `apm install` without `--frozen` to regenerate the lockfile. (#3061) -- Partial dependency updates preserve concrete deployment targets for refreshed and untouched packages, including skills under `.agents/skills/`, instead of demoting them to `legacy`. (#2924) -- Transient resolution-staging paths are shorter, so `apm install` no longer fails with `[WinError 206] The filename or extension is too long.` from a deep Windows checkout. The staging root drops from a full `uuid4().hex` to 12 hex characters and each per-destination slot from a full SHA-256 digest to 16, freeing 68 characters on every staged path. This is not a guarantee of arbitrary long-path support. Orphaned staging roots left by earlier versions are still cleaned up. (#2896) - -### Added - -- Autopilot maintainer canvas (`packages/autopilot/autopilot-maintainer-canvas`) gives CODEOWNERS a Copilot App control surface over live GitHub: accept/defer/panel-review labels and isolated spawn of the canonical autopilot schedulers/workers. `autopilot-comment` is the sole GitHub comment writer (public or debug body plus `Generated by . This comment is AI-generated and may contain errors.`). The canvas does not assign, request reviewers, merge, or run skill logic in the canvas session. (#3024) -- Issue triage, issue implementation, and PR review now share an ORIGIN x INTENT contract: unattended automations (Agentic Workflows, gh-aw, future scheduled runs) never assign. Actor-session ownership writes are: issue triage none (no assignment needed); issue delivery assign the implementing user as a hard gate; standalone PR review request that user as reviewer (`gh pr edit --add-reviewer @me`), never as assignee. Both advisory panels read the full conversation, no-op unchanged receipts, and refuse advice that contradicts CODEOWNERS. +## [0.32.0] - 2026-09-25 ### Changed -- `apm --help`, `apm doctor --help`, and `apm config get` no longer import heavyweight command modules (`install`, `audit`, `pack`, `marketplace`, `uninstall`, `update`); those load only when the matching verb is invoked. (#3001) -- Autopilot PR review takes `panel-mode: full | lean | delta` (omitted or unknown is `lean`); merge-worker plans before fold/push (`kickoff_mode: plan`); triage workers post only via `autopilot-comment`; canvas spawn uses a compact activation card. (#3024) -- Issue and PR triage GitHub comments are human prose only. Activation cards default `json: off` (omitted is off, not a missing-field stop). `json: on` emits an internal `triage-recommendation` receipt only; never post JSON on GitHub. The Triage Panel agentic workflow passes `json: off` and does not require a JSON tail. The PR Review Panel agentic workflow loads `autopilot-pr-review-scheduler` then runs `autopilot-pr-review-worker` in-thread; it does not compose the merge worker. PR triage auto-applies `status/deferred` when there is no linked `status/accepted` issue, thanks the author, and asks them to open an issue first per CONTRIBUTING.md. -- Autopilot worker sessions are named `{Domain} {stage} #{n}` (`Issue triage #2993`). No GitHub title. -- Issue and PR triage sweeps exclude `triage/recommended` and `status/triaged` at GitHub so already-advised open items are not re-listed. Do not write `status/triaged`. -- Autopilot scheduler `invocation` is the harness: Copilot App is `actor-session`. `agentic-workflow` is only gh-aw / Actions. Do not copy `origin` into `invocation`. -- Autopilot schedulers must emit a keep-set and drop-set table (number, kind, labels, rationale, slot) before any spawn. Missing column or blank rationale stops the run. -- Autopilot skill packages live under `packages/autopilot/`. The maintainer map is `packages/autopilot/README.md`. -- Autopilot skills declare `activation_card: on`. Canonical skills emit Enter before work and Exit after. Schedulers are `write: off`. Workers default `write: on`; `write: off` returns the template without GitHub writes. -- Autopilot PR-review worker is the advisory panel (formerly `autopilot-pr-review-panel` / `apm-review-panel`). Drive-to-merge is `autopilot-pr-merge-worker` (activation card `path: merge`, `write` default `on`). The PR-review scheduler never comments, labels, assigns, requests reviewers, or composes the merge worker. -- Autopilot issue and PR triage workers own the advisory comment and processing labels, including when summoned without a scheduler. Schedulers only select work and fan out slots. -- Autopilot `FANOUT_LIMIT` is concurrent slots, not queue length. Schedulers persist the full helper-selected list and refill a slot when it returns. -- Issue delivery no longer drops bot-authored issues that already carry `status/accepted`. Human accept is the gate; author type is not. -- PRINCIPLES.md and remaining autopilot skill assets name the canonical `autopilot-{domain}-{stage}-{role}` skills only. -- Autopilot queues are `autopilot-issue-triage-scheduler`, `autopilot-issue-delivery-scheduler`, `autopilot-pr-triage-scheduler`, and `autopilot-pr-review-scheduler` (isolated pool default 2). Workers are `autopilot-issue-triage-worker`, `autopilot-issue-delivery-worker`, `autopilot-pr-triage-worker`, `autopilot-pr-review-worker` (advisory), and `autopilot-pr-merge-worker` (drive-to-merge, summoned by name). Issue triage advice is `autopilot-issue-triage-worker`. Schedulers own queue selection (`fetch_queue.py` then `triage_state.py`) and fan-out; if spawn is unavailable they run the worker in-thread, one item at a time. PR triage classifies community PRs (with or without a linked issue) and never merges, assigns, or requests reviewers. PR review is advisory only. Issue delivery queues on `status/accepted` or a named bounded accept, then re-checks `scripts/governance/eligibility.cjs` and requires fresh responsible-human confirmation; unattended ORIGIN never implements. Actor-session assignment is a hard gate for implementation only. Triage request trigger is only `triage/requested`; `status/needs-triage` stays human state. - -### Removed - -- Compatibility alias skill packages are gone (`apm-triage-panel`, `apm-review-panel`, `autopilot-pr-review-panel`, `apm-issue-autopilot`, `batch-bug-shepherd`, `shepherd-driver`, and the leftover `autopilot-*-scheduler` / `autopilot-*-worker` stubs). Invoke the canonical `autopilot-{domain}-{stage}-{role}` names only. +- `apm --help`, `apm doctor --help`, and `apm config get` no longer import heavyweight command modules; those load only when the matching command runs. (by @sergio-sisternes-epam, #3001) ### Fixed -- `apm prune` removes unneeded manifestless skill installs after their lock entries disappear, while retaining bundles and whole roots containing needed nested packages. Personal files inside removable package roots are also removed; keep personal source outside `apm_modules/` and preview with `--dry-run`. -- by @fangkangmi (#3057) -- Autopilot maintainer canvas removes a Decide row as soon as GitHub confirms `status/accepted`, without waiting for a full issue/PR refetch. -- Issue and PR triage no longer skip bot-authored items (Copilot, Dependabot, github-actions). They stay in the queue like any other contribution. (#3024) -- PR-review scheduler no longer queues every open pull request. A fresh review requires the `panel-review` label (same trigger as the Agentic Workflow), `status/accepted` on the PR, or an explicit named PR list. The reviewing session also requires `status/accepted` on the PR or a linked issue; otherwise scheduler and review-worker stop with no comment. The worker may clear `panel-review`; the scheduler does not comment or change labels. Both also apply a CODEOWNERS last-comment gate: read the last CODEOWNER comment as conditions and evaluate them against later comments AND labels on the PR and linked issues. Drop or `noop` only when those conditions are unmet or unclear. Named list does not bypass that gate. -- Issue-triage sweep no longer classifies real GitHub bug forms as spam: heading/list line matches no longer swallow the rest of the body after markup strip. -- Preserve marketplace discovery provenance across dependency updates so `plugin@marketplace` uninstall aliases keep working in project and global scope. -- by @mfroembgen (#2949) -- Copilot hooks: `UserPromptSubmit` and `userPromptSubmit` now deploy as `userPromptSubmitted`, the event Copilot CLI runs; they were written as `userPromptSubmit`, which never fired. -- by @sheilagithub (#3030) +- `apm prune` removes orphaned manifestless skills while retaining bundles and roots containing needed nested packages. Keep personal files outside `apm_modules/` and preview with `--dry-run`, since personal files inside removable package roots are also deleted. (by @fangkangmi, #3057) +- `apm install` now rejects incompatible immutable dependency requirements, including inconsistent frozen replay and short SHA pins, instead of silently keeping one version; equivalent tag/SHA pins remain valid. Align root/parent refs, then run `apm install` without `--frozen` to regenerate the lockfile. (#3061) +- `apm marketplace check` now authenticates bare `owner/repo` sources through the configured default host and standard token chain, so private GitHub and GHES checks honor `GITHUB_APM_PAT`. (by @yfoel, #2917) +- Copilot hooks declared as `UserPromptSubmit` or `userPromptSubmit` now deploy as `userPromptSubmitted`, so Copilot CLI actually runs them. (by @sheilagithub, #3030) +- Partial dependency updates preserve deployment targets for refreshed and untouched packages, including `.agents/skills/`, instead of demoting them to `legacy`. (by @Wanming08, #2924) +- The Unix installer now checks the prebuilt Linux glibc 2.38 minimum and routes older systems to the existing eligible Python/pip fallback before downloading an incompatible binary. (#2931) +- `apm install` shortens dependency-staging paths by 68 characters to avoid Windows `MAX_PATH` failures in deep checkouts. This does not guarantee arbitrary long-path support. (by @MohammedAlkindi, closes #2896, #2941) +- Dependency updates preserve marketplace provenance so `plugin@marketplace` uninstall aliases keep working in project and global scope. (by @mfroembgen, #2949) +- `apm audit` drift replay now discovers root-local primitives with the same source scope as a normal install, rather than treating the scratch deployment directory as the project root. (#3021) ### Security -- **BREAKING (invalid inputs):** Reject bare `.`/`..` aliases and unsafe symlink destinations; safe dotted aliases and CLI commands/flags are unchanged. Preserve replay placement via optional lock `alias`, without a `lockfile_version` bump. Clients lacking 0.1.41 manifest `$schema` support fail closed on that explicit opt-in; see `specs/openapm-v0.1.md` (`req-mf-025`) and [migration](https://microsoft.github.io/apm/troubleshooting/migration/#rejected-dependency-aliases). - by @Danvs60 (#2901) +- **BREAKING:** `apm install` rejects bare `.`/`..` aliases and unsafe symlink destinations, and records optional lockfile aliases for replay without changing `lockfile_version`. Replace rejected aliases with a safe name and reinstall; opting into the 0.1.41 manifest schema requires a supporting client (see [migration](https://microsoft.github.io/apm/troubleshooting/migration/#rejected-dependency-aliases)). (by @Danvs60, #2901) +- The locked build toolchain now uses setuptools 83.0.0 to address Unicode filename mismatches that could bypass `MANIFEST.in` exclusions during source-distribution creation on macOS. (#2893) ## [0.31.0] - 2026-09-15 @@ -76,14 +52,6 @@ and this project adheres to [Semantic Versioning](https://semver.org/spec/v2.0.0 - `apm install` again accepts `skills:` subsets from Git collections with nested `skills//SKILL.md` files but no root manifest or skill, without a `path:` workaround. (#2891) - Registry `apm outdated` now separates installed `Current`, constraint-bound `Wanted`, and published `Latest`, so exact pins no longer hide newer releases. It leaves legacy lockfiles unchanged, while `apm update` continues respecting manifest constraints. (#2874) -### Fixed - -- The Unix installer now declares the prebuilt Linux glibc 2.38 minimum and routes older systems to the existing eligible Python/pip fallback before downloading an incompatible binary, with matching recovery guidance. (#2931) - -### Fixed - -- `apm marketplace check` now resolves bare `owner/repo` sources through the configured default host and standard authentication chain, so `GITHUB_APM_PAT` works consistently for private GitHub and GHES repositories. (#2917) - ### Security - The shared gh-aw APM pack job now declares `contents: read` (previously `permissions: {}`), the minimum the explicit built-in-token path needs. No write scope is added, and the token is not forwarded to restore or agent jobs. (#2706) diff --git a/pyproject.toml b/pyproject.toml index 5824d58928..34ff529d51 100644 --- a/pyproject.toml +++ b/pyproject.toml @@ -4,7 +4,7 @@ build-backend = "setuptools.build_meta" [project] name = "apm-cli" -version = "0.31.0" +version = "0.32.0" description = "MCP configuration tool" readme = "README.md" requires-python = ">=3.10" diff --git a/uv.lock b/uv.lock index 6b9be4501f..047b3d9b4c 100644 --- a/uv.lock +++ b/uv.lock @@ -202,7 +202,7 @@ wheels = [ [[package]] name = "apm-cli" -version = "0.31.0" +version = "0.32.0" source = { editable = "." } dependencies = [ { name = "click" },