Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
2 changes: 1 addition & 1 deletion .deckent/workspace/IDENTITY.md
Original file line number Diff line number Diff line change
Expand Up @@ -17,7 +17,7 @@ Direction (2026-06-29 pivot): Tool-driven, progressive-disclosure, full-control
Moat: Deterministik eval-backed orchestration · governance-by-construction · outcome→evidence→routing→promotion→training-trace kapalı öğrenme döngüsü
SSOT: `docs/MASTER-PLAN.md` · core-memory: `.deckent/docs/core-memory/MEMORY.md` · yön gerekçesi: `.analysis/hermes-vs-deckent-direction-decisions.md`
<!-- AUTOGEN:START id="identity-tests" -->
Tests: 34,295 descriptors (parsed from tests/**/*.test.ts(x))
Tests: 34,307 descriptors (parsed from tests/**/*.test.ts(x))
Dashboard Tests: 96 descriptors (parsed from src/dashboard/src/**/*.test.tsx)
Coverage: N/A
<!-- AUTOGEN:END id="identity-tests" -->
Expand Down
2 changes: 1 addition & 1 deletion README.md
Original file line number Diff line number Diff line change
Expand Up @@ -94,7 +94,7 @@ Deckent's three immutable laws are Dual Lens + Scale, Every Environment, and Nev
License: MIT. [Evidence: `package.json:90-91`; `LICENSE`]

<!-- AUTOGEN:START id="badges" -->
[![npm version](https://img.shields.io/npm/v/deckent.svg)](https://www.npmjs.com/package/deckent) [![tests](https://img.shields.io/badge/tests-34295%2B-brightgreen)](https://github.com/VerhexIO/deckent) [![license](https://img.shields.io/badge/license-MIT-blue.svg)](LICENSE) [![sprints](https://img.shields.io/badge/sprints-492%2B-teal)](https://github.com/VerhexIO/deckent) [![version](https://img.shields.io/badge/version-v1.0.0--beta.1-orange)](https://github.com/VerhexIO/deckent) [![CI](https://img.shields.io/github/actions/workflow/status/VerhexIO/deckent/ci.yml?label=ci)](https://github.com/VerhexIO/deckent/actions)
[![npm version](https://img.shields.io/npm/v/deckent.svg)](https://www.npmjs.com/package/deckent) [![tests](https://img.shields.io/badge/tests-34307%2B-brightgreen)](https://github.com/VerhexIO/deckent) [![license](https://img.shields.io/badge/license-MIT-blue.svg)](LICENSE) [![sprints](https://img.shields.io/badge/sprints-492%2B-teal)](https://github.com/VerhexIO/deckent) [![version](https://img.shields.io/badge/version-v1.0.0--beta.1-orange)](https://github.com/VerhexIO/deckent) [![CI](https://img.shields.io/github/actions/workflow/status/VerhexIO/deckent/ci.yml?label=ci)](https://github.com/VerhexIO/deckent/actions)
<!-- AUTOGEN:END id="badges" -->

<!-- AUTOGEN:START id="stat-counts" -->
Expand Down
2 changes: 1 addition & 1 deletion README.tr.md
Original file line number Diff line number Diff line change
Expand Up @@ -94,7 +94,7 @@ Deckent'in üç Immutable Law'u Dual Lens + Scale, Every Environment ve Never MV
License: MIT. [Kanıt: `package.json:90-91`; `LICENSE`]

<!-- AUTOGEN:START id="badges" -->
[![npm version](https://img.shields.io/npm/v/deckent.svg)](https://www.npmjs.com/package/deckent) [![tests](https://img.shields.io/badge/tests-34295%2B-brightgreen)](https://github.com/VerhexIO/deckent) [![license](https://img.shields.io/badge/license-MIT-blue.svg)](LICENSE) [![sprints](https://img.shields.io/badge/sprints-492%2B-teal)](https://github.com/VerhexIO/deckent) [![version](https://img.shields.io/badge/version-v1.0.0--beta.1-orange)](https://github.com/VerhexIO/deckent) [![CI](https://img.shields.io/github/actions/workflow/status/VerhexIO/deckent/ci.yml?label=ci)](https://github.com/VerhexIO/deckent/actions)
[![npm version](https://img.shields.io/npm/v/deckent.svg)](https://www.npmjs.com/package/deckent) [![tests](https://img.shields.io/badge/tests-34307%2B-brightgreen)](https://github.com/VerhexIO/deckent) [![license](https://img.shields.io/badge/license-MIT-blue.svg)](LICENSE) [![sprints](https://img.shields.io/badge/sprints-492%2B-teal)](https://github.com/VerhexIO/deckent) [![version](https://img.shields.io/badge/version-v1.0.0--beta.1-orange)](https://github.com/VerhexIO/deckent) [![CI](https://img.shields.io/github/actions/workflow/status/VerhexIO/deckent/ci.yml?label=ci)](https://github.com/VerhexIO/deckent/actions)
<!-- AUTOGEN:END id="badges" -->

<!-- AUTOGEN:START id="stat-counts" -->
Expand Down
3 changes: 3 additions & 0 deletions docs/MASTER-PLAN.md
Original file line number Diff line number Diff line change
Expand Up @@ -406,6 +406,8 @@ Current receipt register:
| `GR-2026-08-09-DRIFT-VISIBILITY-SUPP-01` | RECOVERY-DO-DOGFOOD-001 | G1 | `scripts/lint-test-hermeticity.mjs@530d522c516d68cb84c73c77977e88ab2dca639ac8d4e8319b4dee4c669ce909`; drift-gorunurluk mekanik baseline supp — dilim sprint-spawner ve sprint-utils uretim modullerini ve zaten-izlenen test dosyasini duzenledi, unresolved ve production-inventory digest drift etti, baseline digest-only tazelendi (ayni count), sanctioned mekanik refresh | owner=Alperen; decision=APPROVED; scope=exact one-path mechanical hermeticity baseline refresh for the drift-visibility slice; exclusions=production-code,sprint,provider-call,build,destructive-action,other-files | 2026-08-09T10:46:08Z | `ONE_SHOT`: consumed@2026-08-09T10:46:08Z |
| `GR-2026-08-09-STALE-SPRINT-LOCK-01` | RECOVERY-DO-DOGFOOD-001 | G1 | `scripts/clean.mjs@60a9583a9aadb78989f25a8710dd4798a1f05541c96cd4eb3fc0971432f80268`; `tests/scripts/clean-active-execution-guard.test.ts@e97f2f9e599e8cc25860fe95ec26a3de9a74cd03b5ed19f418c45f15eb9649c8`; RECOVERY-DO-DOGFOOD stale-sprint kilidi (owner canli onay 2026-08-09, A-B-C zincirinin kalici C adimi) — olculen kapali dongu: basarisiz spawn sprint-state'i PLANNING SPAWN pid null olarak birakti, clean-authority bunu AKTIF sayip build'i E_CLEAN_ACTIVE_EXECUTION_HOLD ile reddetti, kurtarma araci ise binary-identity guard'a takildi cunku dist bayatti ve dist'i tazelemek icin gereken build zaten bloke idi; yani bir basarisiz kosu arti bir kaynak duzenlemesi her iki kurtarma yolunu da kapatiyor. Owner onayiyla manuel seam kullanildi (clean-siz tsc build, finalize force, cleanup) ve kilit kirildi. Kod-truth clean.mjs sprint yuzeyinde karari YALNIZ state.status'tan veriyor canlilik kanitina hic bakmiyor, oysa ayni rapor run-flow yuzeyinde processProbe ile ucslu siniflandirma yapiyor: alive bloklar, dead bloklamayan STALE_DEAD projeksiyonu uretir, unknown typed bloklar. Bu dilim o yerlesik deseni sprint yuzeyine tasir; gercekten canli sprint bloklamaya devam eder, belirsiz durum typed unknown olarak bloklar, yalnizca kaniti olmayan olu sprint projeksiyona duser. ACIK typed-residual binary-identity guard'in kurtarma komutlarini da kilitlemesi ayri dilimdir | owner=Alperen; decision=APPROVED; scope=exact two-path liveness-aware stale-sprint classification in the clean active-execution authority with regression tests; exclusions=sprint,provider-call,destructive-action,other-files | 2026-08-09T12:22:16Z | `ONE_SHOT`: consumed@2026-08-09T12:47:18Z |
| `GR-2026-08-09-STALE-SPRINT-LOCK-SUPP-01` | RECOVERY-DO-DOGFOOD-001 | G1 | `scripts/lint-test-hermeticity.mjs@63daea1a593c5d5263eb419fdd03dd86b2787ee1a6205e9212fb95f7154e6a21`; stale-sprint kilidi mekanik baseline supp — alti yeni liveness fixture'i tmpdir'a sprint-state yazdigi icin unresolved sayaci 12499'dan 12509'a cikti (durustce not edildi) ve clean.mjs degistigi icin production-inventory digest'i kaydi, baseline tazelendi, sanctioned mekanik refresh | owner=Alperen; decision=APPROVED; scope=exact one-path mechanical hermeticity baseline refresh for the stale-sprint liveness slice; exclusions=production-code,sprint,provider-call,build,destructive-action,other-files | 2026-08-09T12:47:18Z | `ONE_SHOT`: consumed@2026-08-09T12:47:18Z |
| `GR-2026-08-09-MODEL-ACTIVATION-01` | MODEL-ACTIVATION-001 | G1 | `src/core/model-activation-store.ts@ABSENT`; `src/core/model-auto-detect.ts@c97d89f22c6e7e87540cc6cb9c62fa43d5ed898a1ff0dbbd0a5d20d65db27df3`; `src/cli/commands/models.ts@30ea562cb60fc9ef9f6c3c05f08aed76e75381c931d762b56756b35d765e6595`; `tests/core/model-activation-store.test.ts@ABSENT`; MODEL-ACTIVATION-001 ilk dilimi (owner Q&A 2026-08-09; store yeri owner secimi proje-kapsamli models db) — tespit-havuzunun ustune aktiflik katmani: yeni model-activation-store SQLite tablosu provider arti model kimligi basina aktif bayragi tutar, kayit yoksa bugunku davranis korunur boylece sessiz davranis degisikligi olmaz, auto-detect kayit yolu pasif modelleri registry'ye almaz, ve deckent models yuzeyi activate ile deactivate alt komutlarini kazanir boylece son-kullanici dosya duzenlemeden yonetir. Brain modeli worker havuzuna girmez. ACIK typed-residual planner atamasinin aktif kumeye karsi dogrulanmasi ve min_tier alaninin olu olmasi ayri dilimlerdir | owner=Alperen; decision=APPROVED; scope=project-scoped model activation store plus auto-detect registration enforcement and CLI activate-deactivate management with tests; exclusions=sprint,provider-call,build,destructive-action,other-files | 2026-08-09T14:56:00Z | `ONE_SHOT`: consumed@2026-08-09T15:41:31Z |
| `GR-2026-08-09-MODEL-ACTIVATION-SUPP-01` | MODEL-ACTIVATION-001 | G1 | `scripts/lint-test-hermeticity.mjs@defab35626b6b0138d5ffbb1fdbb42dc0023fb0b47e799d6ebfd25719f1f31c3`; model-aktiflik mekanik baseline supp — yeni uretim modulu model-activation-store eklendigi icin production-inventory sayaci 1203'ten 1204'e cikti ve digest kaydi, baseline tazelendi, sanctioned mekanik refresh | owner=Alperen; decision=APPROVED; scope=exact one-path mechanical hermeticity baseline refresh for the model activation slice; exclusions=production-code,sprint,provider-call,build,destructive-action,other-files | 2026-08-09T15:41:31Z | `ONE_SHOT`: consumed@2026-08-09T15:41:31Z |

### 3.5 Typed blocker register

Expand Down Expand Up @@ -1034,6 +1036,7 @@ specification'ını execute eder. Legacy provider adapter'ının varlığı PAEP
| 7050 | HUB-001 | ECOSYSTEM-001 | ECOSYSTEM | Production-ready Deckent Hub and signed distribution | P1 | SUPPLY-CHAIN-001, PLUGIN-SANDBOX-001 | G2,G5 | BLOCKED | ~/~/0/?/0/?/? | Real key custody, package signing, verification, tenancy, moderation and rollback | Legacy 503; owner key decision required | 2026-07-26 |
| 7060 | TOOL-COMPUTER-001 | ECOSYSTEM-001 | TOOL | Optional computer-use/browser automation pack | P2 | TOOL-AUTHORITY-001, PLUGIN-SANDBOX-001 | G2,G1 | OPEN | 1/~/0/?/0/0/? | Explicit install/approval, isolated permissions, replay-resistant audit and platform truth | Legacy 83 | 2026-07-26 |
| 7070 | PROVIDER-EXTENSION-001 | ECOSYSTEM-001 | PROVIDER | OpenRouter and future provider extensions through PAEP | P1 | P02-637, P02-646, P02-647 | G2,G1 | OPEN | 1/~/0/?/0/?/? | No bespoke bypass; exact model/reachability/usage/policy conformance | Legacy 477 | 2026-07-26 |
| 7075 | MODEL-ACTIVATION-001 | ECOSYSTEM-001 | PROVIDER | Owner-managed model activation over the auto-detected pool | P1 | — | G1 | VERIFY | 1/1/1/1/1/0/0 | Owner can activate or deactivate any detected model per provider from a first-class surface without editing files; only active models reach the routing pool; an absent record preserves current behaviour; brain-only models never enter the worker pool | Açılış 2026-08-09: Alperen Q&A kararı (çift-mercek — ürün kullanıcısı model/provider yönetimini kolayca yapabilmeli, dogfood aynı store'u kullanır; store yeri owner seçimi `.deckent/models.db` proje-kapsamlı). Kod-truth: `model-auto-detect.ts` provider artı authMode başına gerçekten sunulan modelleri tespit edip registry'ye kaydeder ve cache'ler, fakat AKTİFLİK kavramı yoktur — tespit edilen her model havuza girer. Ölçüm 2026-08-09: codex oturumunda `o3` `gpt-5.5` `gpt-4.1` `o4-mini` `gpt-5-mini` `gpt-4.1-mini` eski nesilleri `gpt-5.6` ailesiyle yan yana duruyor ve AI-planner ilk dogfood koşusunda economy görevine `gpt-5-mini` atadı. İlişkili iki kusur da ölçüldü ve ayrı residual'dır: `min_tier` config alanı `model-selector.ts` içinde HİÇ okunmuyor (yalnız `haiku_allowed` türetiliyor, oysa şema tersini vaat ediyor) ve tier tabanı planner'ın atamasına uygulanmıyor; `currentGeneration` bayrağı doğru nesilleri işaret etse de planner onu bypass ediyor ; `receipt=GR-2026-08-09-MODEL-ACTIVATION-01`; `receipt=GR-2026-08-09-MODEL-ACTIVATION-SUPP-01`; SETTLEMENT 2026-08-09: aktiflik katmani tespit-havuzunun ustune kuruldu — ModelActivationStore (.deckent/models.db, owner secimi) provider arti model basina owner karari tutar, kaydi olmayan model AKTIF kalir yani kurulum hicbir projede sessiz daralma yapmaz. Enforcement tek kayit otoritesinde: deaktif model executable registry'den UNREGISTER edilir, yalnizca kesif listesini filtrelemek yetmezdi cunku cloud modeller bundled katalogdan zaten kayitliydi ve planner yine secebilirdi. Kullanici yuzeyi deckent models activate/deactivate/activation — dosya duzenlemeden yonetim (KANUN 1 cift-mercek, ayni store dogfood'u da yonetir). Brain modeli ayri kalir worker havuzuna girmez. Gercek-binary kosumu ile owner listesi uygulandi: codex o3 gpt-5.5 gpt-4.1 o4-mini gpt-5-mini gpt-4.1-mini ve claude opus-4-8 kapatildi, aktif havuz gpt-5.6 ailesi arti claude opus-5 sonnet-5 haiku-4-5 olarak kaldi. `proof=model-activation-12-pins-plus-42-green-plus-real-binary-7-decisions`; 4 pin arti 1 mekanik supp. ACIK typed-residual: planner atamasinin aktif kumeye karsi dogrulanmasi, min_tier alaninin model-selector'da olu olmasi, ve cross-platform arti olcek kanitlari ayri dilimlerdir | 2026-08-09 |
| 7080 | IDE-ADAPTER-001 | ECOSYSTEM-001 | SURFACE | VS Code, JetBrains and future IDE adapters as non-canonical clients | P2 | APP-SERVICE-001, SURFACE-CONTRACT-001 | G2,G1 | OPEN | 1/~/0/?/0/0/? | Thin adapters, no second engine; capability matrix and honest support lifecycle | Legacy 64; native Deckent remains primary | 2026-07-26 |
| 7090 | ORPHAN-WIRE-001 | ECOSYSTEM-001 | TRUTH | Production import graph orphan disposition and wiring | P0 | REPO-CLEANUP-001, SURFACE-CUTOVER-001 | G2,G1 | BLOCKED | 1/~/0/?/0/?/? | Each deliverable wired, intentionally public or owner-disposed; fresh-clone reachability proof | Waits cleanup manifest and surface cutover | 2026-07-26 |
| 7100 | DEP-SUPPLY-DEFENSE-001 | ECOSYSTEM-001 | SECURITY | npm dependency supply-chain savunmasını ürün özelliği olarak değerlendir: worker/CI install yollarında install-script guard, lockfile-integrity gate, bilinen-IOC taraması ve editör-hook (workspace-trust) koruması | P1 | — | G2,G1 | OPEN | 0/0/0/?/0/?/? | Owner değerlendirmesi: kapsam ve tasarım kararı verilir; kabul kriterleri, platform matrisi ve enforcement modu (advisory/enforce) değerlendirme sonucunda tiplenir; karar redde de çıkabilir | Açılış: Alperen 2026-08-04 talebi ("değerlendirilecek madde"). Tetikleyici: 2026-08-04 "Shai-Hulud: Here We Go Again" npm worm'u — keyv@6.0.0 başlangıç, ~1.684 zehirli versiyon/420 paket adı, preinstall `setup.mjs` + Bun-derlenmiş payload, repo'lara `.claude/settings.json` SessionStart ve `.vscode/tasks.json` folderOpen hook'ları, `gh-token-monitor` persistence ve dead-man's-switch token izleyicisi. Bu repo aynı gün denetlendi ve TEMİZ: hiçbir lockfile'da etkilenen versiyon yok (desktop `keyv@4.5.4` integrity-pinli, saldırı öncesi sürüm), IOC dosyası/persistence/editör-hook izi yok, o gün install koşmadı. Değerlendirme sorusu (Dual-Lens): deckent worker'ları kullanıcı projelerinde bağımlılık kurabildiği için bu savunma katmanı hem dogfood hem son-kullanıcı ürünü olarak hangi kapsamda inşa edilmeli. Kaynaklar: safedep.io/keyv-npm-supply-chain-compromise, thehackernews.com/2026/08/keyv-linked-npm-worm-poisons-hundreds.html | 2026-08-04 |
Expand Down
Loading
Loading