Skip to content

ci: Bump actions/setup-node from 4 to 6 - #3

Open
dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/github_actions/actions/setup-node-6
Open

ci: Bump actions/setup-node from 4 to 6#3
dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/github_actions/actions/setup-node-6

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github May 12, 2026

Copy link
Copy Markdown

Bumps actions/setup-node from 4 to 6.

Release notes

Sourced from actions/setup-node's releases.

v6.0.0

What's Changed

Breaking Changes

Dependency Upgrades

Full Changelog: actions/setup-node@v5...v6.0.0

v5.0.0

What's Changed

Breaking Changes

This update, introduces automatic caching when a valid packageManager field is present in your package.json. This aims to improve workflow performance and make dependency management more seamless. To disable this automatic caching, set package-manager-cache: false

steps:
- uses: actions/checkout@v5
- uses: actions/setup-node@v5
  with:
    package-manager-cache: false

Make sure your runner is on version v2.327.1 or later to ensure compatibility with this release. See Release Notes

Dependency Upgrades

New Contributors

Full Changelog: actions/setup-node@v4...v5.0.0

v4.4.0

... (truncated)

Commits

Dependabot compatibility score

You can trigger a rebase of this PR by commenting @dependabot rebase.


Dependabot commands and options

You can trigger Dependabot actions by commenting on this PR:

  • @dependabot rebase will rebase this PR
  • @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
  • @dependabot show <dependency name> ignore conditions will show all of the ignore conditions of the specified dependency
  • @dependabot ignore this major version will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this minor version will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this dependency will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)

Note
Automatic rebases have been disabled on this pull request as it has been open for over 30 days.

Bumps [actions/setup-node](https://github.com/actions/setup-node) from 4 to 6.
- [Release notes](https://github.com/actions/setup-node/releases)
- [Commits](actions/setup-node@v4...v6)

---
updated-dependencies:
- dependency-name: actions/setup-node
  dependency-version: '6'
  dependency-type: direct:production
  update-type: version-update:semver-major
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot @github

dependabot Bot commented on behalf of github May 12, 2026

Copy link
Copy Markdown
Author

Labels

The following labels could not be found: ci/cd. Please create it before Dependabot can add it to a pull request.

Please fix the above issues or remove invalid values from dependabot.yml.

AlbSar added a commit that referenced this pull request May 14, 2026
…on — 17 madde fix

Sprint 168 v1→v4 zinciri:
- v1 (commit fc91fcd): brainstorming output
- v2 systematic-debugging eval (Agent A): 79/100, Phase 4.5 trigger, 5 critical/high
- v3 devil's advocate eval (Agent B): 22/100 — hedef <30 KARŞILANDI ✅
- v4 (bu commit): 17 madde fix integration
- v5 Alperen final approval bekliyor

17 madde fix entegre:
1. (Agent A #1 CRITICAL) C0e cross-sprint orphan handling — Option C selective filter + startup invocation
2. (Agent A #2 CRITICAL) C0a bundle split → C0a-1/C0a-2/C0a-3/C0a-4 (4 sub-anchor)
3. (Agent A #3 CRITICAL) C0c subscriber owner: decision-engine.ts designate + function signature + BRAIN→SPAWN:BLOCKED event mandatory test
4. (Agent A #4 + B V7 HIGH) ADR-047 Manuel Subagent Dispatch Protocol Sprint 168'de (önceki 168.5 ertelenmiş)
5. (Agent A #5 + B Saldırı #2 HIGH) Smoke test complex scenario: 3+ task (collision + crash + parallel)
6. (B V5 HIGH) Sprint 168 NO_GO → Sprint 168.5 fallback explicit (recursion paradox kabul)
7. (B V7 HIGH) TDD skip enforcement gate (skip artış 0 + Alperen review)
8. (Agent A #8 MED) checkSpawnLock singular helper eklendi
9. (Agent A #9 MED) auto_archive_directives Alperen decision NOW (spec yazımı sırasında)
10. (Agent B #5 MED) Subagent git branch isolation (worktree per cluster)
11. (Agent B #7 MED) ADR-046 invariant test C0a-2 + C0a-3 integration test
12. (Agent B #6 MED) ADR-048 multi-provider parity (Docker + Subprocess + Tmux)
13. (Agent B #4 MED) ADR-048 Wave 1.5 serial gate + Alperen CHECKPOINT
14. (P4.5 MED) Cross-cluster dependency graph spec içinde explicit (Section 2)
15. (Agent B #3 MED) Baseline tolerance "0 yeni skip" GO/NO_GO row
16. (Agent B V6 LOW) Effort yeniden tahmin 22-30h → 35h gerçekçi
17. (Agent B #1 LOW) Brain "kırık" iddiası modül-fonksiyon-satır kanıtı (Section 1)

v1 → v4 büyük yapı değişiklikleri:
- Scope 5 task → 8 task (C0a split + ADR-047 yeni)
- Effort tahmin 22-30h → 35h
- ADR sayısı 1 (ADR-048) → 2 (ADR-047 + ADR-048)
- Smoke test 2-task echo → 3+ task complex (collision + crash + parallel)
- Subagent dispatch "manuel" → "hardened (worktree + file authority + lock + TDD gate)"
- Sprint 168.5 dependency açıklama (NO_GO → manuel dispatch replay)
- Section 2 cross-cluster dependency graph yeni
- Section 3.2 (dispatch mechanism + lock pattern + TDD gate + fallback) yeni
- Section 5.3 complex smoke test suite yeni
- Pre-Flight checklist 11 → 14 madde (git worktree, dispatch locks, smoke test, Alperen auto_archive decision)

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
AlbSar added a commit that referenced this pull request May 14, 2026
… (çift hedef başarılı)

v4 üzerine 2nd round eval patch — Sprint 167 paterni gibi (v1→v5):
- v4 (72b4880): 17 madde 1st round integration
- v5 2nd round Agent A: 96/100 APPROVED ✅ (hedef ≥95)
- v5 2nd round Agent B: 26/100 SHIP_AS_IS ✅ (hedef <30 korundu)
- v5 patch (bu): 6 madde minor — 4 Agent A cosmetic + 2 Agent B clarification

6 madde patch:
1. (Agent A 2nd round #2) Section 1 — 10 bug attribution explicit per cluster:
   Cluster A 4 bug + B 1 + C 3 + D 1 + E 1 = 10 ✓
2. (Agent A 2nd round #1 CRITICAL miss) C0e scope — getActiveWorkerIds() public
   helper extract instruction (auditor.ts:2162-2168 → src/core/active-workers.ts)
3. (Agent A 2nd round MINOR-3) Section 5.1 prompt template reword —
   "Skip artış YASAK" → "Yeni test'lerde skip kullanma" daha net
4. (Agent A 2nd round Section 3.4 önerisi) GO_WTD ≤1 candidate netleştir —
   en muhtemel C0d cosmetic metrics fix
5. (Agent B 2nd round Saldırı #2) Section 5.3 — Sprint 168.5 pre-flight smoke test
   eklendi (multi-file + DB write + repo scan pattern coverage)
6. (Agent B 2nd round Saldırı #3) Section 8 — Sprint 168.5 wave split opsiyonu
   (168.5a + 168.5b auto-split threshold ≥10 task)
+ (Agent A 2nd round MINOR-4) Pre-Flight checkbox count netleştir: 16 madde

Sprint 168 eval final:
- Agent A 1st 79 → 2nd 96 (+17 puan, APPROVED ≥95 ✓)
- Agent B 1st 22 → 2nd 26 (+4 puan, SHIP_AS_IS <30 korundu ✓)
- v5 patch sonrası spec çift hedef başarılı + minor refinement

v6 Alperen final approval bekliyor — sonra writing-plans skill Sprint 168 TDD plan.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
AlbSar added a commit that referenced this pull request May 20, 2026
…ical docs

Sub-project #1/4 (Embedded Web Terminal) shipped 2026-05-19→2026-05-20,
operationally smoke-confirmed by Alperen. Update reader-facing docs to
reflect the delivery honestly + the four-part path ahead.

- README + README-TR: new Highlights bullet (top), link to terminal guide
- VISION + VISION-TR: extend 'Where we are now' / 'Where we are going'
  with the embedded terminal as the first concrete step toward agentic-
  OS workflows + the 3 deferred sub-projects (#2 self-security,
  #3 multi-tenant/k8s, #4 enterprise integrations) with the seams
  (AuthProvider / SessionBackend / tenantId) called out
- docs/release/roadmap.md: new 'Phase 3.6: Embedded Web Terminal' before
  Phase 3.5, with delivered checklist + sub-project #2-4 backlog
- docs/release/beta-tracker.md + -tr.md: Last-updated header refreshed
  (2026-05-14→2026-05-20); new 'Sprint 175 — Embedded Web Terminal'
  section with metrics (46/46 tests, build/pack clean), honest debt
  (node-pty linux-x64 prebuild, DECKENT_API_AUTH_DISABLED=1 dashboard
  precondition), process learnings (two durable feedback memories)
- docs/ROADMAP-GOD-LEVEL.md: new ⚡ 2026-05-20 section at the top, full
  Sprint 175 record + sub-project backlog table + Sprint 176+ priorities
- docs/adr/README.md: regenerated index (already had ADR-062/063 after
  collision rename earlier)

No exaggeration: smoke confirmed, but DECKENT_API_AUTH_DISABLED=1 is
still required for dashboard data calls (frontend general API auth
plumbing is sub-project #2/#3 scope) and node-pty linux-x64 prebuild
needs the optionalDep fix in Sprint 176. Recorded as honest debt.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
AlbSar added a commit that referenced this pull request May 20, 2026
Six independent build-blockers surfaced when PR #16 triggered the docs
workflow for the first time (main never had a passing docs build).
Pre-existing root causes, none introduced by Sprint 175:

1. docs/launch/blog-devto-launch.md — YAML frontmatter `description:`
   contained an unquoted second colon ("...one hard-won insight: multi-
   agent..."), parsed as an incomplete explicit mapping pair. Quoted.

2. docs/.vitepress/config.ts — srcExclude expanded to skip developer-
   only directories (superpowers/, audits/, launch/, governance/) that
   contain TS generics (`trace<T>`), placeholder syntax (`<PID>`,
   `<noreply@anthropic.com>`), and other patterns VitePress's Vue
   compiler interprets as unclosed HTML elements. reference/ was
   re-included now that placeholders inside it are escaped (see #3).

3. scripts/gen-reference-docs.mjs — tableCell() now HTML-entity-escapes
   bare-word placeholders like `<sprint-id>`, `<command>`, `<id>` in
   auto-generated reference tables. Regen propagated to cli.md and
   mcp-tools.md. Real HTML tags in source (`<br/>`, `<sub>`) won't
   match this anchored single-token pattern.

4. src/mcp/tools/audit.ts — `.deckent/<sprint-id>-gate.json` in the
   description rewritten as `.deckent/{sprintId}-gate.json` so the
   auto-gen output doesn't ship the breaking placeholder.

5. docs/adr/030 + docs/reference/managed-docs.md — `{{path.to.value}}`
   template placeholders in prose escaped as `&#123;&#123;…&#125;&#125;`
   so Vue's interpolation parser leaves them alone. (Code blocks like
   JSON examples are safe — VitePress treats fenced code as raw.)

6. docs/reference/security.md + docs/guide/docker-backend.md — two
   dead-link callouts fixed: `[ADR Index](../adr/)` → `(../adr/README)`
   (vitepress directory links don't fall back to README), and the
   architecture-overview cross-link replaced with a GitHub URL (the
   architecture/ dir stays in srcExclude due to its TS generics).

Verification: `cd docs && npx vitepress build` completes clean.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
AlbSar added a commit that referenced this pull request May 20, 2026
…isions

Phase 1 root cause: dashboard works only via DECKENT_API_AUTH_DISABLED=1
(no browser auth path for header-less transports; B-022 flagged).
Decisions: terminal WS auth independent+stricter than global bypass;
token via localhost page-inject → WS subprotocol; serve.ts CLI surface.
+ VSCode dock-panel UX; enterprise AuthProvider/SessionBackend/tenantId
seams (design now, implement #3). Decomposition preserved.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
AlbSar added a commit that referenced this pull request May 20, 2026
Wave 1 of the Embedded Web Terminal (Sprint 175, sub-project #1/4):

- LocalTokenAuthProvider: SHA-256 + timingSafeEqual constant-time compare;
  DELIBERATELY ignores DECKENT_API_AUTH_DISABLED — terminal auth is
  independent of and stricter than the global API bypass (spec §1c.2,
  aligns with Sprint-171 B-022 hardening). RCE endpoint must NEVER inherit
  a dev convenience.
- SessionBackend interface + LocalPtyBackend impl (node-pty spawn). The
  interface is the enterprise seam: future remote / k8s pod-exec impls
  ship in sub-project #3 without call-site changes.
- TerminalAudit: low-volume structured events to memory.db (audit type,
  tenant_id column, decay_exempt). Raw PTY output is NEVER passed in.
  memory-store.ts schema: additive ALTER TABLE for tenant_id (idempotent
  PRAGMA-guarded migration); memory-types.ts adds 'audit' EntryType.
- PtySessionManager: Map<sessionId,PtySession>, bounded ring buffer
  (scrollbackBytes), attach/detach ≠ kill (tmux-like), explicit kill,
  idle reaper via idleTimeoutMs (deckent kind exempt for long sprints).

Tests: 4/4 auth-provider (incl. bypass-independence), 1/1 session-backend
(real bash spawn), 4/4 session-manager (ring bound, detach≠kill,
maxSessions, reaper deckent-exempt). All TDD RED→GREEN.

Plan: docs/superpowers/plans/2026-05-19-embedded-web-terminal.md W1

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
AlbSar added a commit that referenced this pull request May 20, 2026
…ical docs

Sub-project #1/4 (Embedded Web Terminal) shipped 2026-05-19→2026-05-20,
operationally smoke-confirmed by Alperen. Update reader-facing docs to
reflect the delivery honestly + the four-part path ahead.

- README + README-TR: new Highlights bullet (top), link to terminal guide
- VISION + VISION-TR: extend 'Where we are now' / 'Where we are going'
  with the embedded terminal as the first concrete step toward agentic-
  OS workflows + the 3 deferred sub-projects (#2 self-security,
  #3 multi-tenant/k8s, #4 enterprise integrations) with the seams
  (AuthProvider / SessionBackend / tenantId) called out
- docs/release/roadmap.md: new 'Phase 3.6: Embedded Web Terminal' before
  Phase 3.5, with delivered checklist + sub-project #2-4 backlog
- docs/release/beta-tracker.md + -tr.md: Last-updated header refreshed
  (2026-05-14→2026-05-20); new 'Sprint 175 — Embedded Web Terminal'
  section with metrics (46/46 tests, build/pack clean), honest debt
  (node-pty linux-x64 prebuild, DECKENT_API_AUTH_DISABLED=1 dashboard
  precondition), process learnings (two durable feedback memories)
- docs/ROADMAP-GOD-LEVEL.md: new ⚡ 2026-05-20 section at the top, full
  Sprint 175 record + sub-project backlog table + Sprint 176+ priorities
- docs/adr/README.md: regenerated index (already had ADR-062/063 after
  collision rename earlier)

No exaggeration: smoke confirmed, but DECKENT_API_AUTH_DISABLED=1 is
still required for dashboard data calls (frontend general API auth
plumbing is sub-project #2/#3 scope) and node-pty linux-x64 prebuild
needs the optionalDep fix in Sprint 176. Recorded as honest debt.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
AlbSar added a commit that referenced this pull request May 20, 2026
Six independent build-blockers surfaced when PR #16 triggered the docs
workflow for the first time (main never had a passing docs build).
Pre-existing root causes, none introduced by Sprint 175:

1. docs/launch/blog-devto-launch.md — YAML frontmatter `description:`
   contained an unquoted second colon ("...one hard-won insight: multi-
   agent..."), parsed as an incomplete explicit mapping pair. Quoted.

2. docs/.vitepress/config.ts — srcExclude expanded to skip developer-
   only directories (superpowers/, audits/, launch/, governance/) that
   contain TS generics (`trace<T>`), placeholder syntax (`<PID>`,
   `<noreply@anthropic.com>`), and other patterns VitePress's Vue
   compiler interprets as unclosed HTML elements. reference/ was
   re-included now that placeholders inside it are escaped (see #3).

3. scripts/gen-reference-docs.mjs — tableCell() now HTML-entity-escapes
   bare-word placeholders like `<sprint-id>`, `<command>`, `<id>` in
   auto-generated reference tables. Regen propagated to cli.md and
   mcp-tools.md. Real HTML tags in source (`<br/>`, `<sub>`) won't
   match this anchored single-token pattern.

4. src/mcp/tools/audit.ts — `.deckent/<sprint-id>-gate.json` in the
   description rewritten as `.deckent/{sprintId}-gate.json` so the
   auto-gen output doesn't ship the breaking placeholder.

5. docs/adr/030 + docs/reference/managed-docs.md — `{{path.to.value}}`
   template placeholders in prose escaped as `&#123;&#123;…&#125;&#125;`
   so Vue's interpolation parser leaves them alone. (Code blocks like
   JSON examples are safe — VitePress treats fenced code as raw.)

6. docs/reference/security.md + docs/guide/docker-backend.md — two
   dead-link callouts fixed: `[ADR Index](../adr/)` → `(../adr/README)`
   (vitepress directory links don't fall back to README), and the
   architecture-overview cross-link replaced with a GitHub URL (the
   architecture/ dir stays in srcExclude due to its TS generics).

Verification: `cd docs && npx vitepress build` completes clean.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
AlbSar added a commit that referenced this pull request May 20, 2026
…rity

Sprint 176 spec — 12 task, 5 wave, June 1 2026 beta-blocker:

A. Planner state-hygiene (W1-W3, 7 task):
   1. Auto-debt empty-scope (sprint-planner.ts:197-216)
   2. Re-plan orphan task file cleanup
   3. DEP0190 shell:true (3 call-site)
   4. Coverage hard-floor / aspirational split
   5. Dashboard TS errors + root lint wire
   6. doctor DECISIONS.md obsolete + 5-file cascade
   7. CI-only test flakes (lokal-CI divergence)

B. Self-security guards (W4-W5, 5 task — interceptor pattern, 5 new files):
   8. Prompt guard (input pattern matcher)
   9. Command guard (shell-kind deny-list, remote-only)
   10. Outbound rate-limit (daily tenant-scoped quota)
   11. mTLS hook (AuthProvider interface extension)
   12. Self-audit-of-audit (HMAC append-only chain + verify CLI)

Five non-negotiable security invariants (I1-I5):
- I1 no silent drop, I2 no raw payload in audit, I3 default-deny
  on host≠127.0.0.1, I4 append-only audit + HMAC tamper detect,
  I5 tenant-scope isolation (audit + quota + guard state).

Locked decisions: single sprint #176, structured planning, sequential
self-modifying dispatch (Sprint 175 pattern), Brain manuel wave gates
(ADR-047), non-destructive memory.db ALTER, GO_WITH_TECH_DEBT acceptable
verdict (≤2 GWT, W1-W3≥5 DONE, W4≥2 DONE).

Predecessor: PR #16 (sub-project #1, terminal, merged 2026-05-20).
Successor: sub-project #3 (multi-tenant + k8s + mTLS impl, post-beta).

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
AlbSar added a commit that referenced this pull request May 21, 2026
… NO_GO recovery + beta launch (10 task)

Sprint 183 = son beta-blocker sprint. Sub-project #3 + #4 Sprint 184+'ya iter.

Layer 1 — 3 P0 fix (Sprint 182 dogfood'dan keşfedildi):
- W1-1: Nervous PLAN-phase pasif (FSWatcher debounce + phase guard)
  Root: nervous=true PLAN'da 14+dk donuyor, 17 task JSON yazımı sırasında FS event amplification
- W1-2: DEPENDENCY_BLOCKED event spam debounce (state-change only emit)
  Root: 550+ event Sprint 182, 95% spam (her 5sn'de aynı state)
- W1-3: Worker timeout RC investigation + fix
  Root: 5 task "exit 0 without result" — prompt size? Docker overhead? heartbeat write?

Layer 2 — Sprint 182 5 NO_GO recovery:
- W2-1: mock hygiene orphan-cleaner-ipc + archive-debt (Sprint 181'den beri pre-existing)
- W2-2: vitest CI=true parity verify (W2-1 sonrası smoke)
- W2-3: title-prefix Dependencies resolver tamamla (Sprint 182 dosya yazıldı, impl eksik)
- W2-4: integration smoke regression tamamla (Sprint 182 dosya yazıldı, timeout)

Layer 3 — Beta Launch v1.0.0-beta.1:
- W3-1: validate:publish 6/6 GREEN recheck + Brain re-eval RC investigation
  (Sprint 182 W4-1 worker raporu GREEN ama Brain NO_GO; ironik durum)
- W3-2: npm pack + lint:adr + lint:link final hijyen
- W3-3: v1.0.0-beta.1 final smoke (build:all + vitest + dashboard + serve)

DIRECTIVES'te retro/stub task YOK (feedback_no_retro_task_in_directives memory rule).

Sub-project Roadmap (post-Sprint 183, post-beta):
- Sprint 184: Repo housekeeping + docs cleanup (Alperen analiz)
- Sprint 185: Sub-project #3 başlangıç (multi-tenant audit + mTLS scaffold)
- Sprint 186-188: Sub-project #3 tamamlama (k8s + cross-tenant + HW key)
- Sprint 189-192: Sub-project #4 (Enterprise SSO + SIEM + compliance)
- Sprint 193+: Nervous Faz 2/3 + AEGIS + daily-assistant + local LLM CUDA

Config Sprint 183:
- nervous_system.enabled: false (P0-1 fix LAND etmeden risk)
- dependency_pipeline_enabled: true (Sprint 182 dogfood'da kanıtlandı, korunur)
- directives_protection.auto_restore: true (Sprint 177-005 hook canlı)

June 1 OSS beta launch yolu net — Sprint 183 GO sonrası npm publish Alperen manuel.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
AlbSar added a commit that referenced this pull request May 21, 2026
- ROADMAP-GOD-LEVEL.md: ⚡ 2026-05-21 Crisis Stab Initiative (Sprint 177-183) 7-sprint summary, F1-F8 + ADR-064 + I1-I5 wins, Sub-project #3/#4 4-sprint detail each, Nervous Faz 2/3 + AEGIS Phase 1-3, Sprint 200 God-Level GA, Local LLM CUDA sub-project #5
- vision/roadmap.md: Trinity maturity update (Developer 95% beta READY, System Worker 55%, Assistant 30%), Crisis Stab closure section, Sprint 134-145 table replaced by Sprint 184-200 post-beta roadmap, MIT licensing callout for enterprise features

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
AlbSar added a commit that referenced this pull request Jun 1, 2026
…21 eksik madde + 5 düzeltme

Workflow (master-plan-gap-analysis, 24 ajan, 595 ileri-madde tarandı, 101 aday,
101 kod-tabanında doğrulandı — sayı/grep değil semantik okuma).

EKLEMELER (21): F1-008 naive chat, F2-006d --resume, F5-005 dormant evrim modülleri
(E-2/4/5/6 0-caller), F6-005 live model catalog, F7-009 Nervous UI, F7-010 evolution
page, #3-ext brain-evolution retro, W-INTEGRITY/W-H/W-J/W-B/W-A detayları, DeckentHub
20 seed skill + governance, OSS publish pipeline kararları, AEGIS standard track,
M1-M4 monitoring gate, synthetic-NO_GO KAYNAK 6+7 closure, memory.db sprint-log fix,
Voice+Mobile (10K/50K star gate), AEGIS methodology (ADR-061).

DÜZELTMELER (5): core 90→111 + orchestra 76→88 module drift, README badge/96% claim
stale, sub-#5 Ollama "infra-ready"→"partial (adapter live)", sub-#3 mTLS/audit-shard
abartılı→gerçek (sadece LocalTokenAuthProvider), F6-001 provider-fallback landed detayı.

§13 Out-of-Scope: stale/obsolete düşürülen maddeler gerekçeleriyle (cloud SaaS ADR-033
red, ekstra provider/RAG/SWE-bench P3+, daemon/Electron redundant, doğrulanmış non-bug'lar).
Sıfır-kayıp: hiçbir doğrulanmış madde sessizce atılmadı.

Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
AlbSar added a commit that referenced this pull request Jun 1, 2026
…eni feature-area'lar

Kapsamlı değerlendirme (kod-doğrulanmış): Copilot dokümanının ~%50'si deckent'te
ZATEN VAR (Brain=Planner+Supervisor, Auditor=Validator, security-auditor, approval
workflow, Memory V2, sandbox), ~%25 yeni+DNA-uyumlu, ~%25 DNA-gerilimli (MS/enterprise).

EKLENEN (Alperen seçimi, DNA-uyumlu):
- F8 Capability Broker — capability soyutlama (mail.search→IMAP/Graph/Exchange) + scoped-perms
- F9 MCP Client / Dynamic Discovery — deckent dış MCP server TÜKETSİN (server+client), ekosistem açıcı
- F10 Policy Engine — RBAC+activation+condition birleşik (OPA-style, self-hosted)
- F3-008 Workflow Composer (flows üstüne deklaratif)
- #3-mesh Distributed Agent Mesh (k8s sub-#3 üstüne multi-host)
- §10 post-beta ecosystem satırı + §13 out-of-scope (MS-track opsiyonel/ertelendi, LangSmith red, "Enterprise Operating Layer" konumu red)

Source etiketli (Copilot analizi, Sprint 212). MS-ecosystem core + LangSmith DNA-gerilimi
nedeniyle §13'te considered-deferred (sıfır-kayıp).

Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
AlbSar added a commit that referenced this pull request Jun 3, 2026
…status anchor + queue preview

Closes the orientation findings (Alperen live test):
- #1 visible cursor: InputBar renders an inverse-video caret → you always SEE
  where you are. Reuses the tested editInput reducer + InputHistory.
- #4 arrow keys: ←/→/Home/End move the cursor, ↑/↓ walk history, Backspace/
  Delete/Ctrl-A/E/U edit — full line editing (was append-only).
- #2 'working vs done': a PERSISTENT status anchor above the input shows the
  phase every frame — ⠋ düşünüyor… / üretiliyor… (animated, so a mid-reply
  network pause still reads as 'working') / ✓ hazır · sıra sende when idle.
- #3 queue visibility: queued continuation prompts render as '⋯ kuyrukta N: …'
  previews while busy (was invisible).

InputBar owns input only while active (isActive=false during the confirm modal);
batched/pasted Enter is split so completed lines submit. PTY-harness verified
(scripts/ink-pty-test.mjs now supports <LEFT>/<CR>/<BS> tokens): edit + reply +
clean exit code 0. i18n: tui.generating/ready keys. Opt-in DECKENT_INK=1.
tsc+build+tests/cli green.

Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
AlbSar added a commit that referenced this pull request Jun 3, 2026
Verified the continuation analysis findings against code (file:line), folded
into W-K (detail-2) with F-homes:
- (5) Docker live-monitoring unwired: OutputCollector/output-stream(unmounted)/
  DockerMonitorAdapter all 0-caller; PTY no worker-attach. → F7-004+sub-#1
- (6) Team-collab dormant: shared-memory/handoff/multi-agent "no integration"
- (7) Scale-async: auditor.ts:108 per-worker spawnSync('docker') O(n) in 30s
  scan; serial docker spawn. → W-J+sub-#3
- (8) Provider docs drift: Gemini needs CLI (gemini.ts:294) but docs imply
  API-only; ollama/deepseek unmentioned; suspect auth-login cmds. → W-H
- (9) Per-provider rule drift: karpathy only in .claude; worker-default 139
  vs 112 lines for codex/gemini. → W-B

Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
AlbSar added a commit that referenced this pull request Jun 9, 2026
…r goes live (gap #3)

Closes the largest dormant cluster from capability-maturity §5 #3 (857 LoC,
4 seams: capability-broker + capability-handlers + capability-handlers-data
+ capability-audit-bridge — zero external callers until now):

- backlog: third kind 'capability' with spec.capabilityTarget (verb/args/
  connector, work-model CapabilityTarget); intake validation requires a
  non-empty verb.
- execute-dispatcher: capability branch — resolves the target through an
  injected CapabilityRegistry (never-throw CapabilityResult), status
  writeback done/failed, projectRoot + tenant-derived actor in the
  invocation context. No registry wired → clear failure reason.
- NEW core/capability-runtime.ts composition root:
  createAuditedCapabilityRegistry = reference + extended + data handlers,
  each wrapped with the audit bridge; emit is contained fail-safe.
  Allowlist-gated handlers (env.read, shell.exec) DENY by default.
- runtime-loop: buildEngineRuntime composes the audited registry by
  default; every capability invocation lands on the ENT-3 audit
  hash-chain via writeAuditEvent (capability.success/error events).
- policy-gate: capability EffectClass — read-only verbs (echo, fs.read,
  http.get, env.read, db.query, mail.search, erp.read) → pure;
  side-effecting/unknown → critical-irreversible (risk-tagged parks).
- CLI/MCP surface: backlog add --kind capability --capability <verb>
  --args <json> --connector <id> (+ MCP params; i18n en/tr errors for
  missing verb / invalid args JSON). Real-binary smoke verified.

TDD: 19 new tests (dispatcher 5, engine full-cycle 2, runtime 6,
backlog 3, CLI 4, policy-gate 3 within 2 blocks); tsc clean; 333
targeted tests green. MASTER-PLAN F8 section refreshed (was stale
"not built"); AUT-11 recorded.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
AlbSar added a commit that referenced this pull request Jun 13, 2026
…d assertion (M3 review)

Final-review findings: #2 dist-missing must SKIP→exit 0 (header/sibling consistency, no pre-build false-red); #3 tighten confirm-card assertion to the strict 'y = allow'/'y = izin' form.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
AlbSar added a commit that referenced this pull request Jun 15, 2026
…ransparency

Trust-fix: non-safety-floor 'approve' eylemlerin 10s auto-proceed'i artık configurable.
- config nervous_system.approve_timeout_ms (default 10000); 0/negatif → auto-proceed
  KAPALI (eylem siz accept/reject edene dek pending kalır — temkinli-kullanıcı ayarı).
- executor.ts: shouldArmAutoProceed(locked, ms) pure-predicate (safety-floor asla
  auto-proceed etmez; ms<=0 herkese kapatır); Executor approveTimeoutMs ctor-param;
  bootstrap config'ten thread eder.
- Şeffaflık: describeApproveTimeout(ms, lang) + nervous enable banner'ında auto-proceed
  sözleşmesi basılır (10s auto-apply veya "DISABLED" — sessiz sürpriz yok).
TDD: predicate 3 + transparency 2 test, executor mock güncellendi, 334 nervous + 8 yeşil,
tsc temiz. make-usable batch #3 TAMAM.

Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
AlbSar added a commit that referenced this pull request Jun 15, 2026
…oval codes, bot chat grounding

From Alperen's live dogfood feedback (nervous-on sprint-289):

#1 Stale-worker false-positive noise (was: WORKER_RESPAWN spam on DONE workers)
  - sprint-state-tracker: a worker that has written its .result is FINISHED, not
    active — its .hb is never deleted so it ages out and read as 'stale'. Exclude
    such .hb from activeWorkers at the source (every consumer benefits).
  - stale-worker detector: default threshold 3min → 10min (finished workers are
    already excluded; this is only for a genuinely-hung ACTIVE worker, so don't
    flag a long tool-call early). Configurable via stale_worker.threshold_ms.

#2 Bot chat quality (3/100): the conversational path grounds the persistent claude
   session in NOTHING but tool directives. buildBotSystemPrompt() now injects the
   live project context (.brain/exports/summary.md, bounded) + a 'be an accurate
   deckent-expert, do not make things up' instruction. Volatile state stays
   tool-driven (deckent_status), never baked into the prompt.

#3 Short approval codes: nervous notifications showed a full UUID — typing
   'approve <uuid>' on a phone is torture. Proposer now mints a deterministic
   5-char shortCode per notification; every operator surface (Telegram message,
   deckent status/watch, CLI/REPL nervous accept) shows + resolves it. Also fixed
   a real gap: connector-notify-adapter never rendered notification actions, so
   the Telegram message now carries the copy-pasteable approve/reject command.

Follow-up to f326a68: narrow isObserverNoiseFile to ONLY self-cascade files
(ERRORS.md/nervous-*/metrics/events.jsonl). .hb + sprint-state.json are written by
the worker/controller, never self-cascade, and are useful debounced triggers — so
they're no longer filtered (restores the observer-phase-guard contract).

tsc clean; nervous+connectors 575/575 green (incl. new tests for each fix).

Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
AlbSar added a commit that referenced this pull request Jun 15, 2026
…t autonomous cleanup` (AUT-6, MASTER-PLAN §4A devam #3)

cleanupAutonomousArtifacts existed since AUT-6 but had ZERO callers (dormant) — so
`.tasks/` accumulated stray per-run files (task-run-*.{hb,result,json,prompt,
worker,log}, _*.pid) across autonomous sessions (observed 2026-06-08). This is the
ROOT of the stale-.hb hygiene issue the stale-worker fix only worked around.

- cleanupAutonomousArtifacts now returns the count removed.
- handleStart finally: sweep on engine stop (loop ended → no task in-flight → safe).
- New `deckent autonomous cleanup` subcommand for an on-demand/post-crash sweep,
  with i18n (en/tr) count report.

Run-proven (real binary): planted 2 task-run-* + a real task → `autonomous cleanup`
→ 'Swept 2 ...', real task kept. tsc clean; backlog + autonomous-command + i18n
53/53 green.

Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
AlbSar added a commit that referenced this pull request Jun 16, 2026
…ent tasks

Structural floor: an economy-tier model (haiku family — haiku, gpt-5-mini,
gpt-4.1-mini, gemini-2.0-flash) may ONLY run a document-write / audit task.
A code-development task (anything touching source, incl. in-code i18n string
work) can never auto-default to economy — the router upgrades economy→standard
(provider-appropriate) unless the user explicitly pinned the model (forceModel).

Live proof (Sprint-283): the FIX-router misrouted a tsx-i18n task to haiku +
doc-writer; CC caught it pre-spawn. This guard re-asserts the floor in both
model-finalization paths.

- New shared guard: src/core/model-tier-guard.ts (enforceModelTierGuard,
  isEconomyAllowedForKind, isCodeKindString). Pure, deterministic,
  provider-agnostic via model registry; English diagnostic reasons (mechanism
  module, no i18n binding). Self-contained scope→kind classifier (no orchestra
  import — ADR-008).
- Wire #1+#3 (routing/planner default + brain model): resolveTaskModel
  (model-selector.ts) guards the auto-selected model before return. forceModel
  paths return early (Layer 0) = explicit override honored. sprint-planner.ts:414
  / decision-engine.ts:169 inherit the guard transitively (no planner-smoke edit).
- Wire #2 (FIX/reroute): mid-sprint-adapter.applyReroute re-asserts the floor
  using task.type + task.scope, honoring task.forceModel.

TDD: 16 guard-unit tests + 5 reroute tests; updated 6 stale tests that pinned
the old (buggy) economy-on-code behavior to assert the new floor (+ added
doc-scope economy-allowed and explicit-override-honored cases).

Verify: tsc --noEmit clean; tests/core + tests/orchestra green (655 files,
11242 tests, 0 fail).

Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
AlbSar added a commit that referenced this pull request Jun 24, 2026
…(no race)

Lifecycle-robustness #3 (sprint-323). `finalize --force` finalized the sprint STATE
but left the original `deckent start` process running its EXECUTE wait-loop — it
then raced the finalize: re-clobbering results and able to re-finalize on its own
multi-hour timeout. The hung process is exactly why --force is needed, so finalize
must also stop it.

Fix: new terminateOwnedSprintProcess(root, sprintId, deps?) in sprint-pid-manager —
reads the recorded PID, verifies ownership (start-token), and SIGTERMs it when
'owned'/'unknown' + alive; NEVER signals a 'reused' (recycled) PID; no-op when
dead. finalize --force calls it (after the force warning) + clearPid. Injectable
kill/isAlive deps for tests.

Faithful: sprint-pid-manager.test — owned+alive → killed (SIGTERM, matching pid);
no-pid → not-alive (no signal); recorded-but-dead → not-alive (no signal). tsc=0;
pid-manager + tests/cli (finalize) 4612 pass / 0 fail.

Part of LIFECYCLE-ROBUSTNESS-FIX-PLAN.md (P0-C of 3). All 3 P0 done → build + restart.

Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
AlbSar added a commit that referenced this pull request Jul 15, 2026
…s -f + gerçek-subprocess)

Advisor #3 kapatma: S3 gerçek-alpine-container → gerçek `docker logs -f` follow → 🔧-activity;
S2 gerçek-subprocess (sahte-claude-script) → gerçek spawn+tee → 🔧-activity + raw-log korunumu.
Spawn-shim'ler artık gerçek-binary-doğrulandı (yalnız gerçek-claude-worker docker-içi-stream'i
maliyetli-sprint gerektirdiğinden kalan-gap; SDK-envelope-şekli hermetik test-edildi).

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
AlbSar added a commit that referenced this pull request Aug 3, 2026
…(karar #3)

Type Check kapısı açılınca görünür olan test borcu ölçüldü. Düzeltme YAPILMADI;
Alperen'in kararı "önce envanter" idi.

Orchestra 349 · MCP-bundle 176 · CLI 116 · Core+Agents 9 · Dashboard 0 (2 dosya canlı
sunucu istiyor) · Docs+Scripts 0 (bugün düzeltildi). Toplam ~650 test / ~120 dosya.

Sınıflandırma (iyi haber: yığının çoğu tek desende):
- A (~230): eksik modül/fs mock'ları — renameSync 127, ProviderError 48, chmodSync 24,
  statSync().isFile 14, bindSprintLockToExecution 10, mkdirSync 6. Üretim kodu atomik
  yazıma/yeni export'lara geçti, vi.mock sahteleri güncellenmedi. Kaynak izlendi:
  cd51e18 (run-status atomik yazım, 1 Ağu) ve 10bb6c9 (sprint-log) — ikisi de bugün
  push edilen yerel birikimin içindeydi ve CI onları hiç test edemedi. Düzeltme mekanik.
- B (4): provider-observation v2 runId'yi zorunlu yaptı, tüketiciler güncellenmedi
  (ZodError). Scoped testleri geçiyor, tüketicileri kırık — production wiring closure vakası.
- C (3/46): error-registry ratchet — kayıtsız 46 raw throw birikmiş.
- D (116): CLI spy/beklenti drift'i — tek kök neden yok, vaka-vaka.
- E (~6): ortam-bağımlı (Windows taskkill Linux'ta, .deckent/skills/docs, 60sn timeout,
  dashboard canlı-sunucu).

Çıkarım: borç iki günde birikti ve görünmezdi; 1-2 Ağustos'taki yoğun iş hiç CI görmedi.
Önerilen sıra A → B → C → D; A tek hamlede ~230 kırığı kapatır.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants