mirror of
https://github.com/obra/superpowers.git
synced 2026-07-26 12:14:01 +08:00
Compare commits
1 Commits
docs/codex
...
fix/worktr
| Author | SHA1 | Date | |
|---|---|---|---|
|
|
1f0e2ab912 |
@@ -9,7 +9,7 @@
|
||||
{
|
||||
"name": "superpowers",
|
||||
"description": "Core skills library for Claude Code: TDD, debugging, collaboration patterns, and proven techniques",
|
||||
"version": "6.2.0",
|
||||
"version": "6.1.1",
|
||||
"source": "./",
|
||||
"author": {
|
||||
"name": "Jesse Vincent",
|
||||
|
||||
@@ -1,7 +1,7 @@
|
||||
{
|
||||
"name": "superpowers",
|
||||
"description": "Core skills library for Claude Code: TDD, debugging, collaboration patterns, and proven techniques",
|
||||
"version": "6.2.0",
|
||||
"version": "6.1.1",
|
||||
"author": {
|
||||
"name": "Jesse Vincent",
|
||||
"email": "jesse@fsck.com"
|
||||
|
||||
@@ -1,6 +1,6 @@
|
||||
{
|
||||
"name": "superpowers",
|
||||
"version": "6.2.0",
|
||||
"version": "6.1.1",
|
||||
"description": "An agentic skills framework & software development methodology that works: planning, TDD, debugging, and collaboration workflows.",
|
||||
"author": {
|
||||
"name": "Jesse Vincent",
|
||||
|
||||
@@ -2,7 +2,7 @@
|
||||
"name": "superpowers",
|
||||
"displayName": "Superpowers",
|
||||
"description": "Core skills library: TDD, debugging, collaboration patterns, and proven techniques",
|
||||
"version": "6.2.0",
|
||||
"version": "6.1.1",
|
||||
"author": {
|
||||
"name": "Jesse Vincent",
|
||||
"email": "jesse@fsck.com"
|
||||
|
||||
@@ -1,6 +1,6 @@
|
||||
{
|
||||
"name": "superpowers",
|
||||
"version": "6.2.0",
|
||||
"version": "6.1.1",
|
||||
"description": "An agentic skills framework and software development methodology.",
|
||||
"author": {
|
||||
"name": "Jesse Vincent",
|
||||
|
||||
@@ -1,38 +1,5 @@
|
||||
# Superpowers Release Notes
|
||||
|
||||
## v6.2.0 (2026-07-23)
|
||||
|
||||
### Subagent-Driven Development
|
||||
|
||||
Two structural changes to how SDD tracks progress and closes out review findings, both developed against live eval campaigns.
|
||||
|
||||
- **The workspace is now plan-scoped.** `.superpowers/sdd/` had no plan identity and no end-of-life: a follow-up plan in the same working tree could read the previous plan's ledger as its own progress (observed in the wild, with multiple contamination rounds and ad-hoc workarounds). `sdd-workspace` now requires the plan file and resolves a per-plan directory, `.superpowers/sdd/<plan-basename>/`; `task-brief` and `review-package` write into their plan's directory (`review-package` gains the plan file as its first argument); the ledger names its plan on its first line; and the workspace is deleted once the final review is clean — git history is the durable record. Baseline evals showed controllers already refused foreign ledgers, but at a cost of 6–13 tool calls of cross-plan git forensics per resume; plan-scoping makes the answer structural instead. (25/25 baseline and GREEN eval runs documented in `docs/specs/` and `docs/plans/`.)
|
||||
- **The review-fix loop resumes the implementer.** The lifecycle restructure gives fix rounds resume-the-implementer semantics instead of fresh dispatches, adds a scoped re-review prompt (`re-review-prompt.md`) so the re-reviewer checks the fixes rather than re-reading the whole task, and installs a five-round circuit breaker with controller adjudication when it trips. SKILL.md reorganizes by lifecycle, and its Red Flags convert to the house rationalization-table form.
|
||||
|
||||
### Skills
|
||||
|
||||
A branch-wide compression campaign: recap sections, social proof, and benefits-selling prose aimed at a reader who has already invoked the skill are gone, with every load-bearing argument folded into a rationalization-table row or moved to its point of use. Each cut was micro-tested with subagent probes, and the one cut that measurably degraded behavior was reworked rather than shipped.
|
||||
|
||||
- **`testing-anti-patterns.md` is now `writing-good-tests.md`.** The TDD reference doc is rebuilt as a positive catalog — six rules that lead with the GOOD example — and absorbs a falsifiability discipline: name the production change that would fail the test, derive expectations independently of the code under test, and a closing mutation check. It closes two holes by name: the string-presence trap (grep-style tests on scripts, skills, and prompts counterfeit falsifiability — the observable is behavior, never text) and the change-detector trap (a constant assertion can fail and still protect nothing), each with a hard stop in the gate function. Trivial code and human prose earn no test; the trigger broadens from "adding mocks" to any test writing.
|
||||
- **TDD's "Why Order Matters" rebuttals survive as rationalization rows.** Deleting the section outright measurably degraded test-first behavior under "just write it, tests after" pressure (control 8/10 → treatment 5/10, corroborated on Claude and Codex), so each prose rebuttal now lives in its Common Rationalizations row — the section is gone but the arguments fire where an agent hits them mid-rationalization.
|
||||
- **`finishing-a-development-branch` no longer offers to discard your work.** The completion menu dates from when throwing away branches was routine; "Discard this work" next to "Merge" advertised destroying finished, passing work. Discard survives as an explicit-request-only path with the same typed-confirmation ritual. The same pass made PR creation forge-agnostic (your forge's CLI or the URL printed on push, not a blessed list of tools) and fixed a real bug: the worktree path was recomputed after cleanup had already changed directory, so provenance checks never matched and cleanup silently no-oped.
|
||||
- **Recap and persuasion prose removed across the library.** `brainstorming`, `systematic-debugging`, `dispatching-parallel-agents`, `verification-before-completion`, `executing-plans`, `subagent-driven-development`, `requesting-code-review`, `receiving-code-review`, `using-git-worktrees`, `writing-plans`, and `writing-skills` all drop their Bottom Line / Key Principles / Real-World Impact / Advantages sections; `using-git-worktrees` and `finishing-a-development-branch` convert their guard sections to the house Excuse/Reality rationalization table.
|
||||
|
||||
### Windows
|
||||
|
||||
- **The SessionStart hook now dispatches via Git Bash.** The hook's command string starts with a quoted path, which broke both shells Claude Code might hand it to: PowerShell parsed the quoted string as an expression and died with a parser error (#1751), and cmd.exe's quote-stripping rule truncated the command when the profile path contained a metacharacter like `(` (#1918) — either way the bootstrap silently never loaded. The hook now declares `shell: "bash"`, which Claude Code ≥ 2.1.81 resolves to Git for Windows directly, and which surfaces an actionable install prompt when Git Bash is missing. Older Claude Code versions ignore the unknown key and behave as before. Verified end-to-end on Linux, Windows 11 with Git Bash under a hostile path, and Windows 11 without Git Bash.
|
||||
|
||||
### Harness Support
|
||||
|
||||
- **Gemini CLI support is restored.** The v6.1.0 removal (on the news that Google had EOLed the Gemini CLI) was premature; the install docs and the `gemini-tools.md` tool-mapping reference are back while permanent removal gets a proper evaluation. (#1959)
|
||||
|
||||
### Fixes
|
||||
|
||||
- **`find-polluter.sh` actually finds test files now.** `find .` emits `./`-prefixed paths, so the documented `-path "src/**/*.test.ts"` pattern matched nothing — and `wc -l` on empty input then reported "Found 1". Fixed the prefix mismatch (#2008, #2011), plus two follow-ups: a caller-supplied `./`-prefixed pattern no longer double-prefixes into a never-matching form, and `**/` is also matched collapsed so tests directly under the base directory (`src/top.test.ts` vs `src/**/*.test.ts`) aren't silently skipped. The script gains a deterministic test suite.
|
||||
- **The Codex package script works beyond macOS.** Deterministic-metadata tar flags were bsdtar-only spellings, staged file modes depended on two umasks canceling out, and the test's timestamp assertion parsed bsdtar's column layout in a US timezone. GNU tar now gets equivalent flags producing byte-identical headers, modes are pinned canonical, and the test asserts mtime via `tarfile`.
|
||||
- **SDD's skill test no longer flakes.** The file's worst case exceeded the runner's per-file ceiling (raised to 900s), and the assert helpers matched free-form model prose case-sensitively; matching is now case-insensitive and `assert_order` dumps output on failure so the next flake is diagnosable.
|
||||
- **Docs and test cleanup after the v6.1.0 reference pruning.** Dead links to the deleted `claude-code-tools.md`/`copilot-tools.md` are replaced with the current architecture (#1969), a dangling `#subagent-support` anchor in the Antigravity reference is dropped (#2010), and the Antigravity/Pi mapping tests assert only the surviving harness-specific mappings — scoped to the table so they fail again if it's deleted.
|
||||
|
||||
## v6.1.1 (2026-07-02)
|
||||
|
||||
### Codex
|
||||
|
||||
@@ -1,85 +0,0 @@
|
||||
# Releasing to the Codex portal
|
||||
|
||||
How to package a Superpowers release as the zip artifact OpenAI's Codex
|
||||
plugin portal expects, and what to check before handing it over.
|
||||
|
||||
This is distinct from the older flow of syncing files into a fork of
|
||||
`openai/plugins` and opening a PR, which
|
||||
`scripts/sync-to-codex-plugin.sh` still implements — see the distribution
|
||||
table in [porting-to-a-new-harness.md](porting-to-a-new-harness.md). The portal
|
||||
artifact is a standalone, rootless archive: `.codex-plugin/`, `assets/`,
|
||||
`skills/`, `README.md`, `LICENSE`, and `CODE_OF_CONDUCT.md` sit at the
|
||||
archive root. Hooks, tests, docs, scripts, and other harnesses' manifests
|
||||
are deliberately not shipped.
|
||||
|
||||
## Prerequisite: the OpenAI metadata source
|
||||
|
||||
Each packaged skill must carry `skills/<name>/agents/openai.yaml`. That
|
||||
metadata is OpenAI-owned — it does not live in this repo — so the packaging
|
||||
script seeds it from a prior official package. By default it looks for, in
|
||||
order:
|
||||
|
||||
1. `../_tmp/sup-codex-packaging/superpowers/` (an unpacked package)
|
||||
2. `../_tmp/sup-codex-packaging/superpowers.zip`
|
||||
3. `../_tmp/sup-codex-packaging/superpowers.tar.gz`
|
||||
|
||||
or pass `--metadata-source <dir|.zip|.tar.gz>` explicitly.
|
||||
|
||||
If you have no prior package on disk, extract one from `openai/plugins`
|
||||
(the upstream repo still carries the plugin, including the metadata):
|
||||
|
||||
```bash
|
||||
# from a clone with an `upstream` remote pointing at github.com/openai/plugins
|
||||
git fetch upstream
|
||||
mkdir -p ../_tmp/sup-codex-packaging/superpowers
|
||||
git archive upstream/main -- plugins/superpowers |
|
||||
tar -x --strip-components 2 -C ../_tmp/sup-codex-packaging/superpowers
|
||||
```
|
||||
|
||||
**New skills fail the build.** The script requires one `openai.yaml` per
|
||||
skill directory; otherwise it prints `Missing OpenAI agent metadata for
|
||||
skill: <name>` for each gap and dies with `metadata source is incomplete`.
|
||||
If a release adds a skill, there is no metadata for it yet;
|
||||
you need an updated official package (or metadata added upstream in
|
||||
`openai/plugins`) before you can package. Don't hand-invent the yaml.
|
||||
|
||||
## Build the archive
|
||||
|
||||
From a clean working tree, package the release tag:
|
||||
|
||||
```bash
|
||||
scripts/package-codex-plugin.sh --ref vX.X.X
|
||||
```
|
||||
|
||||
The script reads the version from `.codex-plugin/plugin.json` (bumped by
|
||||
`scripts/bump-version.sh`, so it matches the release tag), stages the tree
|
||||
from the git ref — never from the working copy — and writes
|
||||
`../_tmp/sup-codex-packaging/superpowers-VERSION.zip`, printing entry
|
||||
count, skill count, and a SHA-256. Timestamps and file order are pinned so
|
||||
rebuilding the same ref reproduces the same archive.
|
||||
|
||||
Useful flags: `--output PATH`, `--format zip|tar.gz`, `--allow-dirty`
|
||||
(archive still comes from `--ref`), `--keep-stage` (inspect the staging
|
||||
dir). `--help` has the full list.
|
||||
|
||||
## Verify
|
||||
|
||||
The script already refuses archives containing source-only paths and
|
||||
mismatched metadata counts. Sanity-check the result anyway:
|
||||
|
||||
```bash
|
||||
unzip -Z1 ../_tmp/sup-codex-packaging/superpowers-X.X.X.zip | head
|
||||
unzip -Z1 ../_tmp/sup-codex-packaging/superpowers-X.X.X.zip | grep -c 'agents/openai.yaml'
|
||||
unzip -p ../_tmp/sup-codex-packaging/superpowers-X.X.X.zip .codex-plugin/plugin.json | jq -r .version
|
||||
```
|
||||
|
||||
Expect: rootless top-level entries (`.codex-plugin/`, `assets/`,
|
||||
`skills/`), one `openai.yaml` per skill, and the release version.
|
||||
|
||||
The script itself is covered by `tests/codex/test-package-codex-plugin.sh`.
|
||||
|
||||
## Upload
|
||||
|
||||
Upload the zip through OpenAI's Codex plugin portal. This is a manual step
|
||||
outside this repo; record the SHA-256 the script printed so the uploaded
|
||||
artifact can be matched to the build.
|
||||
@@ -1,6 +1,6 @@
|
||||
{
|
||||
"name": "superpowers",
|
||||
"description": "Core skills library: TDD, debugging, collaboration patterns, and proven techniques",
|
||||
"version": "6.2.0",
|
||||
"version": "6.1.1",
|
||||
"contextFileName": "GEMINI.md"
|
||||
}
|
||||
|
||||
@@ -1,6 +1,6 @@
|
||||
{
|
||||
"name": "superpowers",
|
||||
"version": "6.2.0",
|
||||
"version": "6.1.1",
|
||||
"description": "Superpowers skills and runtime bootstrap for coding agents",
|
||||
"type": "module",
|
||||
"main": ".opencode/plugins/superpowers.js",
|
||||
|
||||
@@ -174,6 +174,29 @@ git worktree remove "$WORKTREE_PATH"
|
||||
git worktree prune # Self-healing: clean up any stale registrations
|
||||
```
|
||||
|
||||
**If removal is refused** (`contains modified or untracked files`): the
|
||||
worktree holds files that exist nowhere else — uncommitted plans, notes,
|
||||
or scratch work. Never `--force` on your own initiative. Show your human
|
||||
partner what is at stake and ask:
|
||||
|
||||
```bash
|
||||
git -C "$WORKTREE_PATH" status --porcelain
|
||||
```
|
||||
|
||||
```
|
||||
Worktree removal refused — these files were never committed:
|
||||
|
||||
<file list>
|
||||
|
||||
1. Commit them to <branch> before cleanup
|
||||
2. Move them into <main repo root>
|
||||
3. Delete them (unrecoverable)
|
||||
|
||||
Which?
|
||||
```
|
||||
|
||||
Carry out the choice, then remove the worktree.
|
||||
|
||||
**Otherwise:** The host environment owns this workspace — leave it in
|
||||
place. If your platform provides a workspace-exit tool, use it.
|
||||
|
||||
@@ -196,6 +219,7 @@ place. If your platform provides a workspace-exit tool, use it.
|
||||
| "'Yeah, get rid of it' counts as confirmation" | Only the typed word `discard` authorizes deletion. |
|
||||
| "The PR is up, so the worktree is clutter now" | PR feedback gets fixed in that worktree. It stays until the work lands. |
|
||||
| "This other worktree looks stale — I'll clean it too" | Clean up only worktrees under `.worktrees/` or `worktrees/`. Everything else belongs to the host. |
|
||||
| "Removal refused — `--force` is just finishing the cleanup" | The refusal means files exist only in that worktree. `--force` destroys them permanently. Show your human partner and ask. |
|
||||
| "The merged-result failure is probably flaky" | A failing merged result stops everything. Branch and worktree stay put while you investigate. |
|
||||
| "The base branch is obviously main" | Confirm the fork point or ask. Merging into the wrong base is expensive to undo. |
|
||||
| "The push was rejected — force-push will fix it" | A rejected push means the remote moved. Investigate; force-push only on your human partner's explicit request. |
|
||||
|
||||
Reference in New Issue
Block a user