Skip to content
Merged
Show file tree
Hide file tree
Changes from 1 commit
Commits
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
57 changes: 15 additions & 42 deletions CHANGELOG.md
Original file line number Diff line number Diff line change
Expand Up @@ -7,52 +7,33 @@ and this project adheres to [Semantic Versioning](https://semver.org/spec/v2.0.0

## [Unreleased]

### Fixed

- `apm install` now fails on incompatible immutable dependency requirements instead of silently keeping one version, including inconsistent frozen replay and short SHA pins; equivalent tag/SHA pins remain valid. Align root/parent refs, then run `apm install` without `--frozen` to regenerate the lockfile. (#3061)
- Partial dependency updates preserve concrete deployment targets for refreshed and untouched packages, including skills under `.agents/skills/`, instead of demoting them to `legacy`. (#2924)
- Transient resolution-staging paths are shorter, so `apm install` no longer fails with `[WinError 206] The filename or extension is too long.` from a deep Windows checkout. The staging root drops from a full `uuid4().hex` to 12 hex characters and each per-destination slot from a full SHA-256 digest to 16, freeing 68 characters on every staged path. This is not a guarantee of arbitrary long-path support. Orphaned staging roots left by earlier versions are still cleaned up. (#2896)
## [0.32.0] - 2026-09-25

### Added

- Autopilot maintainer canvas (`packages/autopilot/autopilot-maintainer-canvas`) gives CODEOWNERS a Copilot App control surface over live GitHub: accept/defer/panel-review labels and isolated spawn of the canonical autopilot schedulers/workers. `autopilot-comment` is the sole GitHub comment writer (public or debug body plus `Generated by <source_skill>. This comment is AI-generated and may contain errors.`). The canvas does not assign, request reviewers, merge, or run skill logic in the canvas session. (#3024)
- Issue triage, issue implementation, and PR review now share an ORIGIN x INTENT contract: unattended automations (Agentic Workflows, gh-aw, future scheduled runs) never assign. Actor-session ownership writes are: issue triage none (no assignment needed); issue delivery assign the implementing user as a hard gate; standalone PR review request that user as reviewer (`gh pr edit --add-reviewer @me`), never as assignee. Both advisory panels read the full conversation, no-op unchanged receipts, and refuse advice that contradicts CODEOWNERS.
- The Autopilot maintainer canvas lets CODEOWNERS label issues and PRs and launch isolated triage, delivery, and review sessions from Copilot App. PR reviews support `panel-mode: full | lean | delta`, and all Autopilot comments use a shared writer with an AI disclaimer. (by @sergio-sisternes-epam, #3024)

### Changed

- `apm --help`, `apm doctor --help`, and `apm config get` no longer import heavyweight command modules (`install`, `audit`, `pack`, `marketplace`, `uninstall`, `update`); those load only when the matching verb is invoked. (#3001)
- Autopilot PR review takes `panel-mode: full | lean | delta` (omitted or unknown is `lean`); merge-worker plans before fold/push (`kickoff_mode: plan`); triage workers post only via `autopilot-comment`; canvas spawn uses a compact activation card. (#3024)
- Issue and PR triage GitHub comments are human prose only. Activation cards default `json: off` (omitted is off, not a missing-field stop). `json: on` emits an internal `triage-recommendation` receipt only; never post JSON on GitHub. The Triage Panel agentic workflow passes `json: off` and does not require a JSON tail. The PR Review Panel agentic workflow loads `autopilot-pr-review-scheduler` then runs `autopilot-pr-review-worker` in-thread; it does not compose the merge worker. PR triage auto-applies `status/deferred` when there is no linked `status/accepted` issue, thanks the author, and asks them to open an issue first per CONTRIBUTING.md.
- Autopilot worker sessions are named `{Domain} {stage} #{n}` (`Issue triage #2993`). No GitHub title.
- Issue and PR triage sweeps exclude `triage/recommended` and `status/triaged` at GitHub so already-advised open items are not re-listed. Do not write `status/triaged`.
- Autopilot scheduler `invocation` is the harness: Copilot App is `actor-session`. `agentic-workflow` is only gh-aw / Actions. Do not copy `origin` into `invocation`.
- Autopilot schedulers must emit a keep-set and drop-set table (number, kind, labels, rationale, slot) before any spawn. Missing column or blank rationale stops the run.
- Autopilot skill packages live under `packages/autopilot/`. The maintainer map is `packages/autopilot/README.md`.
- Autopilot skills declare `activation_card: on`. Canonical skills emit Enter before work and Exit after. Schedulers are `write: off`. Workers default `write: on`; `write: off` returns the template without GitHub writes.
- Autopilot PR-review worker is the advisory panel (formerly `autopilot-pr-review-panel` / `apm-review-panel`). Drive-to-merge is `autopilot-pr-merge-worker` (activation card `path: merge`, `write` default `on`). The PR-review scheduler never comments, labels, assigns, requests reviewers, or composes the merge worker.
- Autopilot issue and PR triage workers own the advisory comment and processing labels, including when summoned without a scheduler. Schedulers only select work and fan out slots.
- Autopilot `FANOUT_LIMIT` is concurrent slots, not queue length. Schedulers persist the full helper-selected list and refill a slot when it returns.
- Issue delivery no longer drops bot-authored issues that already carry `status/accepted`. Human accept is the gate; author type is not.
- PRINCIPLES.md and remaining autopilot skill assets name the canonical `autopilot-{domain}-{stage}-{role}` skills only.
- Autopilot queues are `autopilot-issue-triage-scheduler`, `autopilot-issue-delivery-scheduler`, `autopilot-pr-triage-scheduler`, and `autopilot-pr-review-scheduler` (isolated pool default 2). Workers are `autopilot-issue-triage-worker`, `autopilot-issue-delivery-worker`, `autopilot-pr-triage-worker`, `autopilot-pr-review-worker` (advisory), and `autopilot-pr-merge-worker` (drive-to-merge, summoned by name). Issue triage advice is `autopilot-issue-triage-worker`. Schedulers own queue selection (`fetch_queue.py` then `triage_state.py`) and fan-out; if spawn is unavailable they run the worker in-thread, one item at a time. PR triage classifies community PRs (with or without a linked issue) and never merges, assigns, or requests reviewers. PR review is advisory only. Issue delivery queues on `status/accepted` or a named bounded accept, then re-checks `scripts/governance/eligibility.cjs` and requires fresh responsible-human confirmation; unattended ORIGIN never implements. Actor-session assignment is a hard gate for implementation only. Triage request trigger is only `triage/requested`; `status/needs-triage` stays human state.

### Removed

- Compatibility alias skill packages are gone (`apm-triage-panel`, `apm-review-panel`, `autopilot-pr-review-panel`, `apm-issue-autopilot`, `batch-bug-shepherd`, `shepherd-driver`, and the leftover `autopilot-*-scheduler` / `autopilot-*-worker` stubs). Invoke the canonical `autopilot-{domain}-{stage}-{role}` names only.
- **BREAKING:** Autopilot packages now use canonical `autopilot-{domain}-{stage}-{role}` scheduler/worker names, with CODEOWNER-aware review gates and no unattended implementation or assignment. Replace removed aliases such as `apm-review-panel`, `apm-issue-autopilot`, and `batch-bug-shepherd` using the map in `packages/autopilot/README.md`. (by @sergio-sisternes-epam, #3003)
- `apm --help`, `apm doctor --help`, and `apm config get` no longer import heavyweight command modules; those load only when the matching command runs. (by @sergio-sisternes-epam, #3001)

### Fixed

- `apm prune` removes unneeded manifestless skill installs after their lock entries disappear, while retaining bundles and whole roots containing needed nested packages. Personal files inside removable package roots are also removed; keep personal source outside `apm_modules/` and preview with `--dry-run`. -- by @fangkangmi (#3057)
- Autopilot maintainer canvas removes a Decide row as soon as GitHub confirms `status/accepted`, without waiting for a full issue/PR refetch.
- Issue and PR triage no longer skip bot-authored items (Copilot, Dependabot, github-actions). They stay in the queue like any other contribution. (#3024)
- PR-review scheduler no longer queues every open pull request. A fresh review requires the `panel-review` label (same trigger as the Agentic Workflow), `status/accepted` on the PR, or an explicit named PR list. The reviewing session also requires `status/accepted` on the PR or a linked issue; otherwise scheduler and review-worker stop with no comment. The worker may clear `panel-review`; the scheduler does not comment or change labels. Both also apply a CODEOWNERS last-comment gate: read the last CODEOWNER comment as conditions and evaluate them against later comments AND labels on the PR and linked issues. Drop or `noop` only when those conditions are unmet or unclear. Named list does not bypass that gate.
- Issue-triage sweep no longer classifies real GitHub bug forms as spam: heading/list line matches no longer swallow the rest of the body after markup strip.
- Preserve marketplace discovery provenance across dependency updates so `plugin@marketplace` uninstall aliases keep working in project and global scope. -- by @mfroembgen (#2949)
- Copilot hooks: `UserPromptSubmit` and `userPromptSubmit` now deploy as `userPromptSubmitted`, the event Copilot CLI runs; they were written as `userPromptSubmit`, which never fired. -- by @sheilagithub (#3030)
- `apm prune` removes orphaned manifestless skills while retaining bundles and roots containing needed nested packages. Keep personal files outside `apm_modules/` and preview with `--dry-run`, since personal files inside removable package roots are also deleted. (by @fangkangmi, #3057)
- `apm install` now rejects incompatible immutable dependency requirements, including inconsistent frozen replay and short SHA pins, instead of silently keeping one version; equivalent tag/SHA pins remain valid. Align root/parent refs, then run `apm install` without `--frozen` to regenerate the lockfile. (#3061)
- `apm marketplace check` now authenticates bare `owner/repo` sources through the configured default host and standard token chain, so private GitHub and GHES checks honor `GITHUB_APM_PAT`. (by @yfoel, #2917)
- Copilot hooks declared as `UserPromptSubmit` or `userPromptSubmit` now deploy as `userPromptSubmitted`, so Copilot CLI actually runs them. (by @sheilagithub, #3030)
- Partial dependency updates preserve deployment targets for refreshed and untouched packages, including `.agents/skills/`, instead of demoting them to `legacy`. (by @Wanming08, #2924)
- The Unix installer now checks the prebuilt Linux glibc 2.38 minimum and routes older systems to the existing eligible Python/pip fallback before downloading an incompatible binary. (#2931)
- `apm install` shortens dependency-staging paths by 68 characters to avoid Windows `MAX_PATH` failures in deep checkouts. This does not guarantee arbitrary long-path support. (by @MohammedAlkindi, closes #2896, #2941)
- Dependency updates preserve marketplace provenance so `plugin@marketplace` uninstall aliases keep working in project and global scope. (by @mfroembgen, #2949)
- `apm audit` drift replay now discovers root-local primitives with the same source scope as a normal install, rather than treating the scratch deployment directory as the project root. (#3021)

### Security

- **BREAKING (invalid inputs):** Reject bare `.`/`..` aliases and unsafe symlink destinations; safe dotted aliases and CLI commands/flags are unchanged. Preserve replay placement via optional lock `alias`, without a `lockfile_version` bump. Clients lacking 0.1.41 manifest `$schema` support fail closed on that explicit opt-in; see `specs/openapm-v0.1.md` (`req-mf-025`) and [migration](https://microsoft.github.io/apm/troubleshooting/migration/#rejected-dependency-aliases). - by @Danvs60 (#2901)
- **BREAKING:** `apm install` rejects bare `.`/`..` aliases and unsafe symlink destinations, and records optional lockfile aliases for replay without changing `lockfile_version`. Replace rejected aliases with a safe name and reinstall; opting into the 0.1.41 manifest schema requires a supporting client (see [migration](https://microsoft.github.io/apm/troubleshooting/migration/#rejected-dependency-aliases)). (by @Danvs60, #2901)
- The locked build toolchain now uses setuptools 83.0.0 to address Unicode filename mismatches that could bypass `MANIFEST.in` exclusions during source-distribution creation on macOS. (#2893)

## [0.31.0] - 2026-09-15

Expand All @@ -76,14 +57,6 @@ and this project adheres to [Semantic Versioning](https://semver.org/spec/v2.0.0
- `apm install` again accepts `skills:` subsets from Git collections with nested `skills/<name>/SKILL.md` files but no root manifest or skill, without a `path:` workaround. (#2891)
- Registry `apm outdated` now separates installed `Current`, constraint-bound `Wanted`, and published `Latest`, so exact pins no longer hide newer releases. It leaves legacy lockfiles unchanged, while `apm update` continues respecting manifest constraints. (#2874)

### Fixed

- The Unix installer now declares the prebuilt Linux glibc 2.38 minimum and routes older systems to the existing eligible Python/pip fallback before downloading an incompatible binary, with matching recovery guidance. (#2931)

### Fixed

- `apm marketplace check` now resolves bare `owner/repo` sources through the configured default host and standard authentication chain, so `GITHUB_APM_PAT` works consistently for private GitHub and GHES repositories. (#2917)

### Security

- The shared gh-aw APM pack job now declares `contents: read` (previously `permissions: {}`), the minimum the explicit built-in-token path needs. No write scope is added, and the token is not forwarded to restore or agent jobs. (#2706)
Expand Down
2 changes: 1 addition & 1 deletion pyproject.toml
Original file line number Diff line number Diff line change
Expand Up @@ -4,7 +4,7 @@ build-backend = "setuptools.build_meta"

[project]
name = "apm-cli"
version = "0.31.0"
version = "0.32.0"
description = "MCP configuration tool"
readme = "README.md"
requires-python = ">=3.10"
Expand Down
2 changes: 1 addition & 1 deletion uv.lock

Some generated files are not rendered by default. Learn more about how customized files appear on GitHub.

Loading