Changelog
All notable changes to Renma are documented in this file.
This project follows the spirit of Keep a Changelog and uses semantic version tags.
Unreleased
0.38.1 - 2026-09-05
Changed
Improved the CI report’s diagnostic severity policy section with a comparison table, direction indicators, and concise CI-impact guidance. Policy evaluation and JSON output are unchanged.
Aligned remaining guide help, scaffold handoff, and execution-constraint warning text with evidence-first, conditional clarification. Diagnostic consumer guidance scopes blocked recommendations to their dependent changes and avoids rerunning unchanged evidence solely because a user replied. Diagnostic detection, severity, approval gates, and JSON schemas are unchanged.
Clarified model-neutral Skill authoring: decision tables and progress formats are optional working aids, questions concern unresolved blocking decisions, and independent investigation can continue while preserving the creation gate, source authority, ownership, and separate approval requirements.
Reduced default guide repetition while retaining disposition and platform-handoff reference tables in the complete JSON guide. Guide and handoff schema identities, fields, and governance boundaries are unchanged.
Aligned guide, scaffold, and authoring documentation on relevant validation, conditional report commands, and evidence-based repetition of checks. Required CI and release checks retain their scope. Clarified that a metadata
no-proposalresult does not stop separately requested Skill-body work.
0.38.0 - 2026-09-04
Added
- Added
revokedas a first-class inactive lifecycle status for explicit withdrawal of trust or authorization because of a known problem. Revoked assets require reviewed reason/date evidence, remain unusable for active composition and Discovery, retain lifecycle evidence across catalog, inspect, Readiness, BOM, and Trust Graph projections, and produce dedicated required/optional dependency findings without propagating status to dependents. Required revoked dependencies default to High and optional ones to Low, with repository overrides throughdiagnostics.severity. - Added repository-wide scan-finding severity policy through
diagnostics.severity, keyed by stable diagnostic ID. Effective severity now feeds scan output, suppression evidence, failure thresholds, Readiness, diff, and CI projections while retaining the producer default as traceability.diagnostics.ci_policygoverns severity-policy weakening with the stricter compared endpoint, including attempts to weaken the guard in the same change. Policy diff resolves built-in severity independently of emitted findings, compares effective values for both added and removed overrides, represents equal transitions as neutral, and requires review when the built-in severity cannot be resolved to one static value. Existing catalogerrordiagnostics retain their established High scan-Finding conversion. Configuration now accepts only IDs registered on the configurable scan-Finding surface and rejects stable raw-diagnostic IDs that the policy cannot affect.
0.37.2 - 2026-09-02
Changed
- Replaced the stable
renma.skill-authoring-guide.v1JSON contract withrenma.skill-authoring-guide.v2. V2 preserves Renma's creation-gate, evidence, asset-boundary, handoff, and human-review guarantees while changing interaction semantics from a prescribed clarification protocol to adaptive authoring activities. Clarification is conditional, question batching and blocker presentation are adaptive, prerequisite-aware questioning is required, human-review rules have an explicit field, and recursive external traversal has a compact applicability pointer. The gate may be declared passed only after every requirement, including the smallest justified asset structure, is established and no Blocking decision remains; this dependency does not prescribe an internal reasoning sequence. Consumers must branch onschemaVersionand must not apply v1 phase-order, mandatory-clarification, fixed-batch, or last-phase assumptions to v2.
0.37.1 - 2026-08-30
Changed
- Clarified the default Skill guide prompt and stable JSON guide so generated artifacts retain bounded producer-scoped evidentiary value without becoming governing authority, review consequences are evidence-backed or potential impacts are labeled Proposed or Unresolved, and material handoff evidence is rechecked when current applicability cannot be established.
- Made
npm testemit a single summary on success and failure-only diagnostics on error to reduce LLM context usage. Full per-test output remains available throughnpm run test:verbose.
0.37.0 - 2026-08-24
Changed
- Made the typed Diagnostics v2 repair model the standard
Findingcontract. The typedverificationStepsV2field is nowverificationSteps, and the legacy string-onlyconstraintsandverificationStepsprojections were removed together with their internal compatibility layer. Findings now exposerepairConstraintsandverificationStepsdirectly as typed guidance.
0.36.1 - 2026-08-23
Changed
- Narrowed 27 security-analysis helper types to their owning modules. Their definitions and the function signatures that use them are unchanged, while unsupported internal deep-import surfaces no longer expose local-only names.
- Narrowed body-policy lexical exports to the completed patterns and recognizers used by neighboring analyzers. Regex vocabulary fragments used only to assemble those patterns now remain private to their owner module; diagnostic behavior is unchanged.
- Narrowed internal security-command dependencies to import destination analysis functions and types from their owning modules instead of routing through the security-destination subsystem entrypoint. Public exports and runtime behavior remain unchanged.
- Simplified the security-destination subsystem entrypoint so bindings used only for forwarding are re-exported directly from their owners. The cohesive entrypoint and all destination-analysis consumers remain unchanged.
- Moved the public JSON schema inventory from production commands to test support, its only consumer. Compatibility tests still derive every identifier from its runtime owner, while the unused production module is no longer built or packaged.
- Folded the single-consumer Markdown source-to-visible offset projection into
MarkdownSecurityView. The standalone implementation module and its exported working types were removed without changing Markdown parsing or diagnostic source mapping. - Replaced the single-consumer rule-engine abstraction with a local function registry in
rules.ts. Eleven decorative registry IDs, object wrappers, and the unreachable optional-config guard were removed without changing finding IDs, evaluation order, or diagnostics. - Removed two destination-analysis composition wrappers that were used only by tests. Production consumers continue to use the underlying typed analysis and intent projections directly; test-only convenience stays in test code.
- Enabled TypeScript's unused-local and unused-parameter checks across source and tests, and removed the nine unused imports, locals, parameters, and test helpers they exposed. Runtime behavior and test coverage remain unchanged.
- Removed the remaining cross-owner internal type re-exports from executable inventory, body-policy clause analysis, and security-command working types. Consumers now import those contracts from their defining modules; intentional public facades and cohesive subsystem entrypoints remain unchanged.
- Made 63 command- and CLI-local types module-private after verifying that they have no cross-file consumers. Cross-module command contracts and every public package entrypoint remain unchanged.
- Narrowed the internal runtime surface by making 33 helpers module-private after verifying that they have no cross-file consumers. Public package entrypoints, schema identities, and type contracts remain unchanged.
- Removed five zero-consumer internal declarations: the historical Agent Skill name-validation wrapper, three unused derived types, and one unused body-policy test projection helper.
- Consolidated internal module ownership by removing cross-owner re-exports from metadata parsing, discovery, repository paths, and security diagnostics. Internal consumers now import metadata definitions, Skill path contracts, helper-command evidence, and destination analysis from their cohesive owners; the supported
renma/discoverypublic surface remains unchanged. - Removed the internal
AGENT_SKILLS_TOP_LEVEL_FIELDSre-export fromagent-skills.ts; internal contract tests now import the metadata definition owner directly. - Removed the unused internal
CanonicalSecurityOperationalFieldre-export fromsecurity-policy.ts; its definition remains owned bymetadata-definitions.ts. - Removed the one-line internal
context-language-diagnostics.tsfacade; catalog analysis now imports its implementation owner directly. - Removed the internal
AssetOwnershipre-export frommodel.ts; command consumers now import the cohesive governance type owner directly. - Removed Catalog Finding compatibility re-exports from
scanner.ts; the ordered definition registry and diagnostic conversion remain owned only bycatalog-findings.ts. - Removed internal result-type and renderer compatibility re-exports from the inspect and suggest-metadata command modules. Internal consumers now import the evidence, decision, and renderer owners directly.
- Removed the final internal dependency-layer exception by keeping the single-use classification index projection inside repository snapshot construction instead of a higher-layer evidence module.
- Removed the unused internal
src/types.tscompatibility facade and updated tests to import cohesive type owners directly. The supportedrenma/typespackage export remains owned bysrc/public-types.tsand is unchanged. - Froze the Renma 1.0 release-candidate top-level JSON schema identities while retaining the existing whole-document, published-schema, semantic-contract, and public TypeScript API compatibility checks. The experimental execution contract and internal working models remain outside the freeze.
- Made normalized scan diagnostics the canonical internal
ScanResult.diagnosticscollection behind the v2 serializer. Renamed the producer-level collection to internalrawDiagnosticsand moved scan normalization and review bundling from the version-named module toscan-diagnosticswithout changing public output. - Replaced the three overlapping pre-1.0 scan JSON projections with the
renma.scan.v2contract. Active results now use one normalizeddiagnosticsarray, suppressed results usesuppressedDiagnostics, and the wire-levelfindings,suppressedFindings, anddiagnosticsV2fields were removed. - Made
diffandci-reportcollect each archived repository revision once. CI now applies its fail-closed endpoint boundary while building the shared target snapshot, then derives both semantic diff and CI policy output from that snapshot instead of rediscovering the target revision. - Reduced prose-only safeguard-bypass, risky-failure-suppression, instruction-hierarchy, and untrusted-content inference to explicit local line or clause evidence and advisory severity. Structural POSIX shell, PowerShell, and Windows batch analysis remains in place.
- Documented the Renma 1.0 stabilization boundary, including retention of the existing
ci-reportGitHub Actions workflow and the separation between structural command evidence and incomplete natural-language review aids.
0.36.0 - 2026-08-23
Added
- Added a concise public security policy covering supported versions, private vulnerability reporting, and coordinated disclosure without promising a response SLA.
- Added
SEC-RISKY-OPERATION-ERROR-SUPPRESSIONfor bounded shell and prose instructions that explicitly hide failure from an already-recognized destructive, privileged, upload, or sensitive-data operation. Destructive and privileged shell evidence requires the risky executable in command position instead of a quoted argument mention, while static executable paths, bounded wrappers, and existing upload classification remain supported. - Added
SEC-INSTRUCTION-HIERARCHY-OVERRIDEfor explicit, bounded attempts to supersede system, developer, platform, prior, or higher-level instructions without treating ordinary persona wording, correct authority ordering, bounded questions, explicit attribution, or defensive statements as violations; bare prompt mentions and earlier independent clauses cannot suppress an operational override.
Changed
- Clarified that a Context Asset is a Git-reviewed governance entry point for independently maintained knowledge whose authoritative content may remain in an external governed system without being copied into
contexts/. - Defined the 1.x diagnostic and rule evolution policy, including stable-ID, severity, and behavioral CI compatibility expectations for patch, minor, and major releases.
- Release preparation now verifies both the document-level and root-package versions in lockfile v3 against the target release version.
- Destructive and privileged shell diagnostics now classify bounded shell text as literal-only, operational, or unknown. Quoted risky text is suppressed only along proven literal-only command and data paths; shell
-c/evalcontexts and standard input consumed as shell code remain operational, while unrecognized wrappers, consumers, and shell options use conservative matching. - Shell-wrapper execution evidence now distinguishes proven execution, known non-execution modes, and unknown options, so lookup, help, or version modes stay inert while unrecognized options retain conservative command-risk matching.
- The npm publication workflow now blocks its OIDC-enabled publish job on the existing deterministic release metadata contract as well as exact annotated tag,
origin/main, and package-version identity. - Bounded negative-subject safeguard instructions such as “No Skill … may bypass” no longer overlap with
SEC-SAFEGUARD-BYPASS-INSTRUCTION; a later independently expressed bypass remains reportable. - Made the pre-1.0 compatibility boundary explicit without changing stable CLI behavior or stable JSON output: scan JSON now uses an explicit wire projection, supported TypeScript entrypoints have a checked declaration snapshot, classification wire enums are documented and typed as open while known-value helpers remain closed, typed diagnostic repair guidance is the internal authority for legacy text projections, and asset path normalization rejects every parent-directory segment without an unreachable normalization branch.
0.35.0 - 2026-08-20
Added
- Added focused macOS and Windows CI evidence for path, filesystem, shell-family parsing, package startup, and representative JSON behavior while retaining the complete Linux quality gate.
- Added
SEC-EXECUTABLE-AS-POLICY-AUTHORITYfor the bounded case where a recognized inline Skill helper is explicitly made the allow/deny authority for a security-relevant operation.
Changed
- Completed whole-document golden compatibility assurance for every stable public JSON producer except Trust Graph v2, which retains its published JSON Schema and frozen exact semantic-contract test. Documented the 1.x stability policy and retained the published
renma.trustGraph.v2spelling.
0.34.0 - 2026-08-18
Added
- Added the public
ScanJsonDocumenttype for the serializedrenma.scan.v1wire contract while retainingScanResultas the internal core scan result, plus an internal stable/experimental registry synchronized with the documented public top-level JSON schema inventory. - Added bounded inspection evidence for explicitly referenced noncanonical Agent Skills package files. Exact local targets remain separate from canonical Renma support/governance, while excluded, oversized, depth-limited, symlinked, and unreadable targets now block strict completeness.
Changed
- Changed Readiness from
renma.readiness.v1torenma.readiness.v2and Repository Context BOM from v2 torenma.repository-context-bom.v3. The breaking migration replaces the producerlesslayout.disallowed_skill_assetscheck withskills.support_integrity, which is backed by authoritative static-support inspection coverage plus missing-reference evidence. Excluded, symlinked, unreadable, oversized, depth-limited, and unsupported explicit support now fail the check without allowing finding suppression to manufacture inspection completeness. BOM v3 otherwise carries forward the v2 field contract. - Narrowed
renma/discoveryto canonical Skill entrypoint types, renamed the Skill-specific path helper tonormalizeRepositorySkillRelativePath, and kept lowercase and flat historical entrypoint recognition inside explicit migration tooling. - Renamed the Renma-owned unsupported routing metadata warning to
RN-SKILL-UNSUPPORTED-ROUTING-METADATAwithout changing its warning severity, authoring category, Skill validity, or non-operational semantics. - Kept
SecurityAnalysisCoverageon the cohesiverenma/typesfacade without adding a separate focused package subpath. - Narrowed
ScanJsonDocument.formatto the literal"json"and made the JSON serializer enforce that wire invariant without changingrenma.scan.v1CLI output. - Reduced the pre-1.0 npm type surface to contracts with supported producers: scan JSON, diagnostics, classification/discovery, and composed security coverage. Low-level parser/runtime models remain available to Renma source modules but are no longer package exports.
Fixed
- Made production ordering and selection for scan, catalog, graph, Trust Graph, BOM, Readiness, diff/CI, executable evidence, suppressions, and the experimental execution-contract digest explicitly locale-independent by using one ECMAScript UTF-16 code-unit comparator. Existing schema identifiers remain unchanged for this implementation fix because those contracts already promised deterministic stable ordering; Readiness and BOM change versions only for their separate check-collection migration.
- Rejected conventional and explicit configuration paths that are symlinks, cross a symlinked parent, are outside the repository, or are not regular files. Broken conventional config symlinks now fail as caller-correctable configuration errors instead of silently selecting defaults.
Removed
- Removed the producerless pre-1.0 diagnostic IDs
LAYOUT-SKILL-EXECUTABLE-COMMAND,LAYOUT-SKILL-NOT-THIN,PATH-HELPER-COMMAND-SKILL-SCRIPTS, andLAYOUT-DISALLOWED-SKILL-ASSET, including their compatibility-only documentation and Diagnostics V2 grouping surface. - Removed the compatibility-only
layoutconfiguration surface, includingtool_namespace,workflow_aliases,LayoutPolicyConfig, and normalizedScanConfiglayout state. Authoredlayoutobjects now fail with explicit pre-1.0 deletion guidance and no replacement key. - Removed package subpaths for raw artifacts, parsed metadata, normalized runtime configuration, internal decision/governance projections, and the producerless core
ScanResulttype before 1.0.
0.33.0 - 2026-08-18
Added
- Extended
renma.inspection-coverage.v1to close statically proven Skill-support inspection gaps. A reachable local support target that becomes excluded, oversized, unreadable, depth-limited, symlinked, or otherwise uninspectable now contributes exact blocking evidence with static-reference provenance, so--strictcontinues to fail throughstrict_scan.incomplete_inspectionand inspection-coverage diffs expose parsed-to-blocked regressions. Authority still requires one unambiguous owning Skill and a fully parsed source chain; unreferenced support and unknown transitive children remain outside this boundary, and unparsed targets do not receive synthetic security-analysis coverage rows. - Extended CST-backed YAML frontmatter-comment security analysis from Skills to eligible, known non-Skill Markdown artifacts with a closed Renma frontmatter envelope. Comments retain the raw-agent-visible, no-policy-authority boundary and exact source evidence; successful zero-comment extraction reports
yamlFrontmatterComments: "analyzed", while malformed input remains non-analyzable and arbitraryunknownMarkdown remains out of scope. - Hardened HTML-comment security projection to use the same raw-agent-visible, no-policy-authority trust boundary as YAML frontmatter comments. Inner Markdown presentation and negative-example labels can no longer opt hidden security-sensitive text out of analysis, and policy-looking comment text cannot authorize or allowlist its own projection.
- Added semantic security analysis for discovered UTF-8
.txtSkill support files only when the existing repository-local static-reference graph proves them reachable from exactly one owning Skill. Reachable plain-text support now reportssemanticInstructions: "analyzed"; otherwise identical unreferenced text remainsunsupported, and structured, executable, binary, external, escaping, symlinked, and unresolved targets remain outside this capability. - Added versioned
renma.security-analysis-coverage.v1scan JSON evidence for every discovered and scanned artifact. The target-state rows distinguish executed, unsupported, inapplicable, and non-analyzable hidden-Unicode, Markdown semantic instruction, canonical Skill description, and YAML frontmatter comment layers without changing findings or CI policy.
Changed
- Finalized the pre-1.0 repository contract around one operational spelling: shared Context Assets use
contexts/**; Skills use exactSKILL.mdunder a supported Skill root; configuration usesrenma.config.jsoncorrenma.config.json; Context Lenses useapplies_toandexpected_outputs; and security-profile policy fields use their documented canonical spelling. Historical paths,.renma.json, Lens aliases, profile aliases, andcanonical_contextnow produce explicit migration diagnostics or configuration errors without operational interpretation. - Made portable Agent Skills
descriptionthe sole Skill capability and selection-boundary source.renma.when-to-useandrenma.when-not-to-useare unsupported and ignored operationally with migration-oriented authoring warnings; pre-0.16 top-level routing fields remain one-way migration evidence only and may help recoverdescription. - Restricted non-Skill local security-policy authority to canonical, closed Renma frontmatter envelopes. Policy-looking Markdown body text remains visible instruction evidence and can no longer authorize network, secret, upload, approval, or floating-dependency behavior. Strict scans now also fail with
strict_scan.incomplete_security_analysiswhen applicable parser-owned YAML frontmatter-comment analysis cannot be completed safely. - Raised
SUPPORT-MISSING-PATHfrom Medium to High because a statically referenced local resource that does not exist is a broken declared relationship. Missing targets remain structural findings rather than inspection-coverage issues.
Fixed
- Made non-Skill Renma metadata consume one shared YAML 1.2 parse before catalog, governance, Context Lens, and security interpretation. Quoted, block, and flow values now retain YAML semantics consistently, while malformed or non-mapping frontmatter and duplicate recognized operational keys fail closed with explicit diagnostics instead of selecting raw-line or first/last values.
- Routed Markdown link, image, autolink, and resolved reference destinations through parser-owned evidence for security analysis and Skill-local support reachability. Reference definitions remain non-operational by themselves, visible labels and resolved targets remain additive when distinct, and overlapping destination candidates preserve the governing instruction.
- Closed frontmatter security-boundary gaps by accounting for parser-hidden YAML comments in exact non-Skill envelopes, rejecting reviewed invisible or default-ignorable corruption of registered policy keys and delimiters without recovering their values, and treating exactly one absolute leading
U+FEFFas an encoding BOM while additional or embedded corruption remains fail-closed. - Preserved safe Skill-local support file identity across exact exclusion so a unique basename-only static reference still produces blocking
excludedinspection evidence. Excluded files continue to count during basename disambiguation, while their contents remain unread and unparsed. When an excluded support directory makes a basename candidate set incomplete, Renma now emits blocking subtree evidence without traversing the directory or inventing an exact child path. Symlink targets remain unfollowed and uninspectable even when their path identity supplies blocking evidence.
Removed
- Removed every
renma/dist/...package export and the semantic command, renderer, guidance, and migration exports. The intentional v1 library API is now the focusedrenma/typessurface plusrenma/discovery; removed paths fail withERR_PACKAGE_PATH_NOT_EXPORTED, while therenmaCLI remains available through the package binary. - Removed operational compatibility for the
context/**root, historicalskill.mdand*.skill.mdentrypoints,.renma.json, Context Lenstarget/targets/output/outputs, andcanonical_context. Explicit pre-0.16 and historical-entrypoint migration throughsuggest-metadataremains one-way.
0.32.1 - 2026-08-13
Fixed
- Fixed false-positive-prone Unicode tag handling by allowing the three exact RGI subdivision flag sequences for England, Scotland, and Wales. Standalone, malformed, token-embedded, missing-terminator, non-RGI, and encoded-looking tag usage remains covered by
SEC-SUSPICIOUS-INVISIBLE-CHARACTER, with every tag code point escaped in reported evidence. - Fixed a hidden-Unicode detection gap for suspicious consecutive runs of Mongolian Free Variation Selectors (
U+180B–U+180D,U+180F), Variation Selectors (U+FE00–U+FE0F), and Variation Selectors Supplement (U+E0100–U+E01EF). The existingSEC-SUSPICIOUS-INVISIBLE-CHARACTERdiagnostic now includes escaped code-point and range/run evidence while isolated legitimate selectors remain allowed.U+180EMONGOLIAN VOWEL SEPARATOR is also no longer reported solely for appearing in legitimate Mongolian text.
0.32.0 - 2026-08-10
Added
Added bounded static executable-dependency analysis for PowerShell
.ps1and Windows batch.bat/.cmdsurfaces. Explicit relative execution, PowerShell call and dot-source forms, sole$PSScriptRoot, batchcall, sole%~dp0, and boundedpwsh/powershell -Fileandcmd /cforms now feed the shared inventory, graph, reachability, execution-contract, diff, and CI evidence paths. Comments, here-strings, multiline data, and continuation lines are suppressed conservatively; dynamic expressions, bare/PATH command lookup, PowerShell modules, and general interpreter semantics remain unsupported.Added bounded static shell executable-dependency analysis for text
.shand.bashsurfaces. Direct relative execution through./or../, immediatebash/shinvocation, andsource/ dot-source forms now contribute deterministicstatic-executionorstatic-sourceevidence to executable graphs, execution contracts, and semantic diff propagation. Dynamic paths, wrappers, launcher options, absolute or external targets, and repository escapes remain outside the analyzer's deliberately narrow grammar.Added the Medium advisory
QUAL-SKILL-DESCRIPTION-HIGH-RISK-LITERALfor concrete high-risk literals in structurally bounded, non-operational routing examples. Skill scaffolds,renma guide skill, remediation, and authoring guidance now direct authors toward semantic capability and selection wording, with exact dangerous evidence kept in clearly non-operational body sections when necessary.Added repository-level
metadata.requiredpolicy for the registry-backed Skill/non-Skill metadata vocabulary, with strict configuration validation, declared-value presence semantics, canonical Skill enforcement, and the HighMETA-POLICY-REQUIRED-FIELD-MISSINGfinding. The list defaults to empty, so existing repositories retain current metadata requirements.Added deterministic
renma.metadata-policy-diff.v1evidence andmetadata.ci_policy(off,warn, orfail, defaultfail). Required-field removal and CI-mode weakening are independent stable CI matches governed by the stricter archived endpoint; additions and mode tightening remain visible non-blocking transitions.Added repository-configurable warning and High token-budget policy for Skill, Context, Reference, Profile, and Example Markdown through the corresponding
quality.*_token_warningandquality.*_token_highkeys, with independent defaulting, positive-safe-integer and ordering validation, structured policy provenance, and revision-localdiff/ci-reportevaluation.Added deterministic
renma.quality-policy-diff.v1threshold-transition evidence andquality.ci_policy(off,warn, orfail, defaultfail). CI uses the stricter endpoint mode and gates both numeric threshold increases and CI-mode weakening. Mode and numeric transitions remain independently visible inrenma.quality-policy-ci-policy.v1outcomes; tightening is non-blocking.
Changed
Added a concise product-boundary diagram to the development design, showing current single-repository identity, governance, and review capabilities while keeping organizational federation and owner-authority enforcement separate.
Reframed the development roadmap's Current State as a version-independent description of Renma's stable single-repository governance boundary and clarified that stricter organizational metadata requirements are optional repository policy rather than Renma or portable Agent Skills defaults.
Pull-request Renma reporting now checks out the exact event head SHA with full history and passes the exact event base and head SHAs to
ci-report, avoiding mutable branch-name or synthetic merge-checkout ambiguity while preserving the existing strict current-head scan and report-enforcement policy.Clarified that English is the primary and strongest language for Renma's bounded governance and security wording recognizers while multilingual content remains supported and does not produce a generic warning. Documented language-independent URL, command, path, executable-reference, Markdown structure, and hidden-Unicode evidence remains active across languages. Multilingual description exemption now requires non-ASCII letter or mark evidence, so typographic punctuation and emoji cannot disable normal English-primary authoring diagnostics.
Hardened npm publication so a separate non-OIDC job fetches and verifies the exact remote release tag object and
origin/main, requires an annotated tag peeled to the exact main commit, and checks the package version before the environment-gated trusted-publishing job can run. Minimum-Node and LTS validation remain required.Pinned every external GitHub Action in repository workflows and the maintained consumer workflow example to a verified full commit SHA while retaining the intended release tag in an inline comment. Dependabot's GitHub Actions updater remains enabled.
Release preparation now verifies each maintained consumer installation using its narrow file-specific command form: one exact
npm install --save-dev --save-exact renma@<version>command, the GitHub Actionsnpm cistep, and every maintainednpx --no-install renmainvocation, including every exactnpxword in same-line shell compositions. Separate shell expressions cannot supply pieces of the contract. Current-example tests run in an isolated tagged fixture, so shallow or tagless caller checkouts remain supported. Both pin-bearing files remain in the local release finalization set.Canonical Agent Skill descriptions are now security-governed semantic units with exact frontmatter evidence. Bounded quoted routing-example lists remain non-operational, while later operational clauses stay visible; actual destructive commands and other operational policy violations in descriptions retain their existing High-severity security findings.
Improved bounded safeguard-bypass analysis for action-local prohibition and negation scope, dependent purpose clauses, finite and conditional clauses, punctuation-separated fallback actions, and Markdown-presentational emphasis. Operationally routed blockquotes are scanned while ordinary attributed report quotations remain inert, with original source evidence preserved.
Security-policy metadata eligibility is now evaluated independently from whichever individual findings an operational instruction emits. Fetch, upload, and sensitive-input workflows therefore continue to require declared policy even when no separate destination or disclosure rule fires.
Updated the GitHub Actions example and CI guidance to use an exact installed Renma dependency through
npm ciandnpx --no-install; source-checkout development continues to build and invokedistdirectly.Tuned the Renma default to Skill (6,400/8,000): no finding through 6,400 estimated tokens, Medium above 6,400 through 8,000, and High above 8,000. The separate portable Agent Skills recommendation remains 5,000 tokens. The High result uses the ordinary
--fail-on highseverity gate; token size remains review evidence and never triggers automatic splitting or rewriting.Extended that two-tier severity model to full-file Context (6,400/8,000), Reference (7,200/9,000), Profile (3,200/4,000), and Example (4,800/6,000) budgets. Valid per-file overrides raise the effective warning floor while the effective High threshold remains at least that floor.
Changed semantic asset comparison to use canonical catalog content hashes. Content-only edits now appear as changed assets in
diffandci-report, with a visible bounded content-change count, while remaining neutral unless an independent finding or governance rule changes CI status.
Fixed
- Matched the bounded PowerShell and CMD grammar tokens with their native case-insensitive semantics: PowerShell
-File,$PSScriptRoot,.ps1, CMDcall,/c,%~dp0,.bat, and.cmdnow accept casing variants. Captured repository path spelling remains exact; path lookup is not case-folded. - Closed the raw-Markdown HTML-comment security blind spot with the dedicated, suppressible
SEC-HIDDEN-OPERATIONAL-INSTRUCTIONdiagnostic. Each real comment is analyzed as an isolated raw-agent-visible span with exact source evidence and the underlying matched diagnostic identity; ordinary formatting, metadata, explanatory, prohibited, and clearly negative-example comments remain inert, and raw hidden-Unicode inspection remains independent. Raw comment projections reuse the visible-Markdown structural example boundaries: a same-node marker, a preceding negative-example label, or a negative-example heading can bound the applicable example payload, while a later independent workflow instruction remains eligible. Inline markers are punctuation-clause-local, including within one physical line or a soft-wrapped paragraph, so only the bounded example clause becomes non-operational. - Shell dependency collection now excludes recognized heredoc bodies, multiline quoted literal regions, and backslash-continued physical lines. Unsupported or dynamic heredoc delimiters fail closed for the rest of the source, preventing data-only shell text from becoming dependency, graph, reachability, or execution-contract topology. Obvious
$(( ... ))and(( ... ))arithmetic regions are tracked separately, so arithmetic shift operators cannot start a false heredoc or hide later supported dependencies. Bash<<<here-strings are consumed as complete non-heredoc operators, so an overlapping<<suffix cannot hide dependencies on later lines. - Removed the release-version literal from the CI consumer-workflow contract test. The expected exact
npm install --save-dev --save-exact renma@<package version>command is now derived frompackage.json, so a correctly pinned next-version release fixture passes finalization without a release-specific test edit or an expansion of the release-file allowlist. - Unedited or partially edited Renma Skill and Context scaffolds now emit the High
QUAL-RENMA-SCAFFOLD-PLACEHOLDERfinding for each exact Renma-owned marker with line-level evidence. Strict High scans fail, Readiness applies a blocking scaffold-completeness check and penalty, and workflow projections no longer count the generated routing, input, completion, or verification prose as authored evidence. Detection is limited to canonical generated strings and does not claim general semantic-incompleteness analysis. - Release preparation now fails clearly when a maintained consumer Renma pin is missing, stale, ambiguous, or inconsistent with the requested/package version, including
--check-only --finalizevalidation.
Compatibility
Repository Context BOM v2 additively accepts the
powershellandbatchdependency analyzer values and thepwsh,powershell,cmd, and.exelauncher spellings. Existing fields, meanings, relation values, and ordering remain unchanged. Repositories with recognized Windows chains may now show additive surface, invocation, dependency, reachability, execution-contract, semantic-diff, and CI evidence. Consumers with exhaustive enum switches must accept the new values; BOM v2 and executable-surface inventory v1 identifiers are unchanged.Repository Context BOM v2 dependency rows add the
shellanalyzer andstatic-execution/static-sourcerelation enum values. Existing fields and analyzers remain compatible; repositories containing newly recognized shell edges may now show additive dependency, reachability, execution-contract, and diff evidence. Agent-facing Markdown containing security-sensitive instructions in HTML comments may now produce the new finding at the matched detector's severity, with a High fallback for a policy-relevant instruction surface, and can use the existing narrow ID-and-path suppression contract when independently justified.npm trusted publishing now requires the
npm-publishGitHub Environment in its OIDC identity. Maintainers must separately configure npm's Trusted Publisher for the exactnpm-publish.ymlfilename and environment, protect the Environment with reviewers and deployment ref rules, and protectv*tag creation with a GitHub ruleset. Repository checks cannot verify those external settings or defend against a tagged workflow commit that replaces its own checks. The authoritative release Skill and Context now preserve scan-clean human-approval guards, stop before tag push unless those external prerequisites are independently observed or explicitly confirmed by a maintainer, and record pending Environment reviewer approval.Security diagnostics remain deterministic static checks and bounded, best-effort natural-language heuristics; they do not claim complete semantic or coreference analysis. Runtime gateway policy, sandboxing, filesystem and network restrictions, and approval enforcement remain required execution controls, with Renma serving as one layer of the combined defense.
The repository-required metadata policy leaves portable Agent Skills validity, ownership inheritance, scaffold and migration behavior, and Context Lens compatibility unchanged. Security fields and token-budget decision metadata are not eligible required fields. An inherited effective owner remains available to ownership consumers but does not satisfy an explicit declared-field policy. Binary, non-metadata-capable, configuration, unknown, and runtime-only assets do not receive impossible metadata requirements.
Repositories without
qualityconfiguration continue to load without migration and receive the documented Renma defaults for every governed asset kind. Existing valid support-asset override declarations remain valid and now compose with the repository warning/High pair. Declaration validation uses a stable compatibility baseline, so an accepted override below a tuned warning remains valid but cannot lower repository policy; its rationale is retained. Metadata-size, Script, and Asset policies are unchanged. Quality thresholds do not participate in scan-boundary weakening policy.Semantic diff JSON adds
qualityPolicy, and CI-report JSON adds top-levelqualityPolicy. The CI evaluation additively recordsmodeTransitionand independentnumericThresholdChanges; a mode weakening emitsquality_policy_ci.ci_policy_relaxed. A finding decrease alongside a threshold weakening is not described as verified remediation. Existing fields remain compatible and support-asset finding details add declaration, validation-baseline, and effective-warning-impact evidence.Semantic diff and nested CI-report JSON add optional
contentHashvalues to asset endpoints andcontentChangedto newly built changed-asset rows when both endpoints provide comparable content identity.summary.contentChangedAssetsappears only when every shared asset is comparable.changedFieldsremains the governance-metadata field list; formatters continue to accept legacy and partially comparable rows and snapshots without fabricating a negative content-transition result.
0.31.0 - 2026-08-08
Added
Added the versioned
renma.skill-authoring-handoff.v1exchange contract, published JSON Schema, guide construction template, and optional Skill-onlyscaffold --handoff <path>workflow with pre-write gate, target, identity, relationship, and resource validation. Existing direct scaffold use remains compatible.Added
executable_surface.ci_policywithoff,warn, andfailmodes, defaulting tooff, stricter archived-endpoint selection, stableexecutable_surface_ci.*matches sourced from canonical executable diff evidence, and a top-levelrenma.executable-surface-ci-policy.v1CI-report evaluation.Added canonical
renma.scan-boundary.v1evidence to scan and diff output, including config identity, exact runtime coverage declarations, limits, and active suppressions, plus retained structuredsuppressedFindingsevidence.Added
scan_boundary.ci_policywith fail-closedoff,warn, andfailgovernance, defaulting tofail, stablescan_boundary_ci.*matches, and arenma.scan-boundary-ci-policy.v1CI evaluation.Added deterministic target-path endpoint-coverage union evidence as
renma.ci-evidence-boundary.v1, preventing target-only globs, exclusions, limits, or suppressions from hiding CI enforcement findings.Added canonical per-asset effective scalar/list security-policy transitions to semantic diff output, preserving canonical asset identity, exact boolean/
unspecifiedstates or added/removed values, and provenance without relying on cancelable aggregate inventory counts.Added
security.ci_policywithoff,warn, andfailmodes, defaulting tofailand resolving the stricter mode across both compared revisions. Stablesecurity_policy_ci.*matches now make policy weakening explicitly reviewable and independently auditable per asset.Added the
renma.security-policy-ci-policy.v1CI-report evaluation and prominent Markdown policy-relaxation evidence in bothdiffandci-report.Added the experimental
execution-contractJSON command for one exact Skill, projecting deterministic direct/transitive executable relationships, line-level and unresolved evidence, lifecycle and caller-provided revision provenance, and bounded-analysis facts from one repository snapshot without runtime observation or authorization semantics.Added five-way external-upload governance counts to Security Policy Inventory so denied, approval-required, approval-not-required, approval-unspecified, and upload-permission-unspecified states remain explicit across Readiness, BOM, scan, diff, and CI reporting.
Changed
Changed
ci-reportto compose executable-surface policy outcomes with its existing semantic, Skill Discovery, security, and scan-boundary outcomes. The evaluator consumes the PR #177 enforcement-view executable diff, while directdiff, Readiness, and--fail-on-statussemantics remain unchanged.Made the canonical Skill-root grammar explicit and symmetric across
skills/and.agents/skills/, centralized reserved support discovery rules, broadenedskills/**/references/**/*to include non-Markdown resources like the existing.agents/skills/root, and made scaffold reject targets the shared classifier treats as reserved support.Changed suppression application to keep active findings disjoint from a complete suppression ledger. CI trusts a common exact rule ID and normalized path scope only while active on both revisions and uses the stricter endpoint expiration; reason changes are audit metadata and do not affect equivalence.
Changed scan-boundary identity to preserve runtime-significant glob and exclusion syntax exactly, and made repository-controlled suppression reasons single-line visible values in Markdown and terminal reports.
Changed
ci-reportto fail by default on scan-boundary weakening and to avoid describing a finding reduction as verified remediation when coverage or suppression trust changed.Changed
ci-reportso a default-mode security-policy relaxation fails with exit code1, whilewarnpromotes onlyPASStoWARNandoffleaves status unchanged. A finding decrease that accompanies policy relaxation is no longer described as verified remediation. Single-revisionscan,scan --fail-on, and Readiness semantics are unchanged.Expanded security-policy relaxation governance to approved network/upload destination additions, allowed-data additions, forbidden-input removals, and disallowed-command removals.
Compatibility
CI-report JSON adds top-level
executableSurfacePolicy. The executable inventory and semantic diff remain policy-free, and the defaultoffmode preserves prior status behavior while retaining informational matches.Scan JSON adds
scanBoundaryandsuppressedFindings; semantic diff JSON adds top-levelscanBoundaryandfindings.suppressed; CI-report JSON adds top-levelscanBoundaryPolicywith its effective enforcement boundary. Existing BOM and Trust Graph schemas are unchanged because those artifacts do not embed the scan/diff/CI suppression ledger.Newly generated semantic diff JSON adds
security.policyTransitions, and CI-report JSON adds top-levelsecurityPolicy. Transition rows are now a discriminatedkind: "scalar" | "list"union; scalar rows carryfromState/toState, while list rows carryadded/removed. CI matches use the samekinddiscriminator and add an explicit relaxationdirectionplusaddedValuesorremovedValuesfor list matches. These fields are the authoritative transition and evaluation representations; existing aggregate inventory deltas remain summaries only. The new defaultsecurity.ci_policy: "fail"can change CI-report status for repositories that weaken effective security policy without explicitly configuring another mode.Security Policy Inventory JSON additively emits
externalUploadGovernancewhile retaining the independentexternalUploadAllowedandhumanApprovalRequiredcounts. BOM stays v2; its published schema accepts older v2 inventories without the new field and strictly validates all five nested counts when the field is present.
0.30.0 - 2026-08-04
Added
- Added JSONC repository configuration support with
renma.config.jsoncas the recommended filename, including deterministic precedence, comment-preserving diagnostics, and JSON-compatible parsing. - Updated
renma initto create a documented JSONC configuration while preserving support for existingrenma.config.jsonand.renma.jsonfiles.
0.29.0 - 2026-08-03
Added
- Added reversible
suspendedlifecycle evidence for Skills and cataloged non-Skill assets, including reviewed reason/date metadata, inactive dependency and Discovery gates, Readiness evidence, public projections, schemas, semantic diff, and CI-report visibility without runtime enforcement or automatic restoration.
0.28.5 - 2026-08-03
Added
- Added one authoritative User Manual metadata reference covering portable Agent Skills fields, every operational Renma Skill/non-Skill mapping, exact value formats, applicability, compatibility status, projections, inheritance boundaries, and complete Skill and Context examples.
- Added implementation-owned metadata definition registries and deterministic documentation-drift coverage so catalog, Discovery, security, specialized non-Skill, and token-budget fields cannot silently diverge from the manual.
Changed
- Improved the operational metadata reference with responsive presentation and consistent accessible horizontal scrolling at every width while preserving its authoritative Markdown source and documentation-drift tests.
- Expanded the documentation-wide technical-reference layout with a fixed-width primary sidebar on wide screens and readable wrapping in responsive page outlines.
- Updated the remaining diagnostic and authoring documentation to delegate complete metadata inventory ownership to the User Manual while retaining feature-specific semantics and practical guidance.
0.28.4 - 2026-08-01
Added
- Added automatic, security-constrained Mermaid rendering to the VitePress documentation site, with dedicated theme integration, rendering tests, and maintainer guidance for diagram changes.
- Added Cloudflare Web Analytics to the documentation site.
- Added Dependabot configuration and updated GitHub Actions dependencies for CI, documentation deployment, Renma reporting, and trusted npm publication.
- Extended the isolated SkillSpector evidence-correlation experiment to compare exact scanner file evidence with Renma's public executable graph while preserving the boundaries between invocation, containment, ownership, reachability, reviewed scope, and runtime impact.
Changed
- Updated runtime and development dependencies, TypeScript, formatting, and lint configuration for the current toolchain without changing Renma's public commands or package schemas.
0.28.3 - 2026-08-01
Added
- Added an isolated, non-production SkillSpector evidence-correlation experiment that preserves scanner-native findings and deterministically correlates exact source paths with Renma catalog assets. It includes inert fixture templates, experiment-only tests, one audited captured run, and explicit inconclusive-state handling without adding a Renma command, diagnostic, readiness input, CI policy, runtime dependency, or public schema.
- Added a VitePress documentation site deployed under the
/renma/GitHub Pages base, with structured navigation, local search, build and preview scripts, and a dedicated Pages workflow. - Added the approved deep-indigo Renma visual identity to the documentation header, favicon, landing page, and repository README, with stable PNG asset names, accessible text, responsive sizing, and maintainer-facing provenance.
Changed
- Updated the package homepage to the GitHub Pages documentation site and constrained npm package contents to omit branding images and VitePress-only configuration, cache, temporary, and generated output while retaining the source documentation.
0.28.2 - 2026-08-01
Added
- Added
renma graph --view executablewith optional Skill-or-script--focusfor deterministic Skill-to-script, reverseused by, script-to-script, shared-use, external-target, and independent structural containment inspection across JSON, Markdown, and Mermaid. The topology reuses normalized invocation evidence and canonical deduplicated executable dependency edges while retaining detailed declaration rows for audit. Default graph views, ownership semantics, CI reporting, and repository-wide orphan discovery are unchanged.
0.28.1 - 2026-07-31
Changed
- Compacted
ci-reportMarkdown for pull-request review by keeping status, range, readiness, ownership coverage, non-zero summary deltas, and review notes visible, and by surfacing compact non-zero groups for meaningful underlying changes even when aggregate deltas remain neutral. Verbose and unchanged evidence stays under a collapsed details section. Complete JSON output remains unchanged.
0.28.0 - 2026-07-31
Added
- Extended bounded direct helper-invocation evidence from fenced command lines to single-line inline code spans whose mdast paragraph prefix is exactly
RunorRun:. Top-level and nested list-item paragraphs are supported; cue emphasis and strong formatting remain harmless only when they contain textual cue content. Blockquotes, headings, links, images, non-comment HTML, linked or emphasized command spans, broader prose, chained secondary spans, other verbs, lowercase or multilingual cues, and arbitrary inline code remain outside the grammar. Fenced and inline forms share the existing launcher, target, resolution, governance, reference deduplication, semantic identity, and dependency-reachability projections without a schema, finding, readiness, CI, or package-version change. - Extended
renma.executable-surface-inventory.v1with bounded, non-executing static dependency evidence for JavaScript/TypeScript ESM declarations and Python explicit relative imports. A fixed private analyzer boundary emits language-neutral candidates into one Renma-owned repository resolver; no public plugin API, dynamic loading, subprocess analyzer, configuration, or runtime dependency was added. - Added deterministic executable dependency resolution, incoming/outgoing edge counts, and breadth-first direct/transitive/unreached invocation reachability with minimum depths and cycle termination. Existing direct invocation counts retain their established meaning, and invocation-context policy does not propagate through dependency edges.
- Preserved every recognized dependency declaration as an auditable row while deduplicating graph topology by source path and normalized target. Duplicate declarations no longer multiply edge counts, alter reachability or depth, or create dependency-graph diff reasons.
- Preserved textually identical declarations on the same source line as distinct evidence rows with stable occurrence ordinals, using collection-only source offsets that remain absent from scan and BOM JSON.
- Excluded declaration-level and pure inline TypeScript type-only named imports and re-exports from runtime dependency evidence. Mixed clauses, default and namespace imports, and bindings literally named
typeremain included. - Added complete dependency evidence to scan and BOM output plus line-insensitive semantic diff and bounded neutral CI review. Repository Context BOM remains v2 and the inventory remains v1; new published-schema fields are optional for earlier 0.27.x compatibility and strict when present.
- Added
.ts,.mts, and.ctsexecutable surfaces consistently for Skill-local scripts, repository tools, directnodetargets, and dependency sources/targets..tsx,.jsx, other languages, runtime imports, CommonJS calls, compiler/package/environment resolution, role classification, public plugin loading, findings, Readiness, enforcement, Trust Graph integration, and policy propagation remain deferred. - Extended
renma.executable-surface-inventory.v1with deterministic invocation-context governance evidence from already prepared source-artifact and owning-Skill policy rows, plus per-surface aggregates, summary counts, semantic diff changes, and bounded informational CI rendering. Surface policy remains separate; caller policy is not inherited by shared tools, evidence is not merged or given precedence, and multiple fingerprints are visibility rather than conflict or enforcement. - Kept the extension compatible with Repository Context BOM v2: current output emits the additive governance fields, while the published schema accepts Renma 0.27.0 BOMs that omit them and strictly validates each new object when present. No package version, finding, diagnostic, readiness check, policy inventory semantic, Trust Graph edge, or CI verdict changed.
Changed
- Compacted healthy default scan text to one executable-surface summary and expanded only bounded evidence relevant to resolution, scope, reachability, missing context-policy evidence, or multiple fingerprints. Complete scan JSON and BOM output remain unchanged.
- Added explicit diff and CI visibility for newly introduced invocations that already have multiple effective policy fingerprints, including total deltas and bounded neutral detail without changing path-problem evidence or CI verdicts.
0.27.0 - 2026-07-30
Added
- Added the provider-neutral, non-executing
renma.executable-surface-inventory.v1projection to scan output and Repository Context BOM v2. It reports already-discovered Skill-local scripts, repository-roottools/**helpers, non-canonical discovered scripts, bounded static helper invocations, reachability, interpreter hints, content identity, and effective security-policy correlation. Semantic diff and CI reports expose its changes as informational evidence. - The inventory does not widen repository discovery or execute, import, compile, or sandbox source. It adds no finding, readiness rule, CI blocker, failure threshold, or Trust Graph semantic; presence does not classify a file as safe, unsafe, malicious, or actively executed, and missing effective policy is visibility evidence rather than an automatic violation. Package-manager scripts, workflow files, Dockerfiles, Git hooks, import graphs, dynamic invocations, and runtime telemetry remain out of scope.
0.26.0 - 2026-07-30
Added
- Added deterministic raw-source findings for suspicious bidirectional controls and conservative invisible/deprecated Unicode characters across every already-discovered UTF-8 text artifact, including scripts, configuration, and non-Markdown assets. Findings preserve original source lines, aggregate by diagnostic and line, escape hidden evidence, retain existing suppression and Diagnostics v2 behavior, and exclude binary files and ordinary multilingual or emoji text.
0.25.3 - 2026-07-28
Fixed
- Corrected
SEC-UNPINNED-DEPENDENCY-INSTALLso npm-family dist-tags, ranges, partial versions, and wildcards no longer pass as pinned literals. Added bounded pip, versionedpython -m pip,py -m pip, anduv piprequirement analysis; explicit indirect and unsupported-source evidence; and selector-specific asset-local npm/PyPI floating allowances that preserve the underlying floating classification. Follow-up hardening recognizes bounded pip general options beforeinstall, corrects post-install option arity, normalizes valid PEP 508 requirement whitespace, validates==separately from arbitrary===, and acceptsv/=only on complete exact npm versions. Existing bounded Homebrew formula and Docker image fallback detection remains unchanged, and shared remediation now covers every detected ecosystem. Floating allowances are visible as asset-local Security Policy Inventory evidence while remaining excluded from effective policy, inheritance, provenance, fingerprints, and existing policy counts. Existing diagnostic identity, severity, confidence, risk class, evidence, ordering, suppression, Diagnostics v2, and review-bundle behavior remain compatible, with additive npm/PyPI dependency details.
0.25.2 - 2026-07-28
Changed
- Added a candidate external-review governance design and a SkillSpector experiment harness for evaluating provider-neutral review evidence. These additions are planning and experimental artifacts only; they do not change the current CLI, metadata, schema, configuration, or plugin contracts.
0.25.1 - 2026-07-27
Changed
- Refactored body-policy analysis into private lexical recognition, bounded statement components, centralized subject and policy-context transitions, predicate semantics, and fact projection layers without changing supported grammar or public diagnostic projections. Reorganized the compatibility suites and added deterministic structural properties for ranges, determinism, ordering, deduplication, enclosures, relative components, and Markdown soft wraps. Added an explicit package subpath allowlist that preserves established deep imports while keeping the package root, CLI implementation entrypoint, and separated body-policy modules unavailable as library imports. The installed CLI remains available through
bin.renma.
0.25.0 - 2026-07-26
Fixed
- Preserved the Renma 0.24.4 body-policy boundary for every frozen golden case except explicitly allowlisted precision and evidence changes. Coordinated requirement, local, qualified, safeguard, and workflow prohibition predicates remain independent for each domain, including when an earlier predicate has no body-policy domain, has local or specific scope, or mentions another domain.
- Restored directly supported workflow-prefix prohibitions across bounded short modifiers, modal bridges, colon or dash punctuation, and bounded relative or unqualified parenthetical modifiers. Composed bridges preserve local-step, source/target, exception, and allowance qualifications; phase-local parentheticals no longer become workflow-wide prohibitions.
- Preserved standalone policy scope through bounded directive prefixes and independent subjectless coordination. Paired-comma modifiers remain attached to their prohibition, while prepositions in inline relative clauses qualify only the nearest bounded action or domain phrase.
- Kept outer directive proof separate from an embedded workflow subject's local bridge proof, accepted unknown imperatives only across an independent bare semicolon, and modeled bounded
modal + neverandmodal + notforms as semantically classified prohibition candidates. - Promoted workflow subjects after supported directive and policy-label prefixes into statement-group state, unified bounded modifier and
modal + neverpredicate prefixes across direct and inherited facts, and retained the prefix in projected evidence. - Made bare-semicolon standalone proof quote-enclosure-aware, supported bounded paired-comma object-relative clauses without attributing their inner prohibitions to the main workflow, and added bounded
ensure thatandmake sure thatdirective forms. - Carried private quote-enclosure provenance through technical-clause, sentence, contrastive, ordinary
and, and comma segmentation so quoted examples cannot inherit workflow scope or receive standalone policy scope. Enclosed separators are opaque but no longer clear an outer subject or policy context needed by an unquoted continuation after the closing quote. - Classified bounded paired subject-relative predicates independently while retaining object-relative changed subjects for the later main predicate. Multi-predicate subject-relative components reuse the same statement-group state machine within their comma bounds.
- Added policy context as private statement-group state independent of workflow subject state, allowing supported labels and directives to scope and promote later subjectless predicates without manufacturing a grammatical subject.
- Separated deontic and commitment modal negation from recommendation, epistemic, capability, hypothetical, and availability language for both
modal + neverand active or passivemodal + not. Plainmust,shall, andwillremain emitting; bounded policy or directive context additionally supportsshouldandmay, while availability states andmight,can,could, andwouldremain non-emitting. - Composed at most one supported policy label with one bounded directive or safety component for standalone proof, embedded subjects, paired modifiers, and evidence origins.
- Required explicit statement-level scope proof for direct facts, preventing a supported subjectless prohibition under descriptive, changed-subject, conditional, or unsupported syntax from receiving default workflow scope.
- Restored subject continuation through base and third-person policy verbs while recognizing strong noun phrases followed by copular, auxiliary, finite, or negative modal heads before their first word can be treated as a subjectless verb.
- Recognized noun/verb homographs followed by compatible finite security actions as changed subjects while preserving genuine subjectless forms such as
audits logs,reviews results, andchecks use cases. - Kept affirmative requirement language distinct from genuinely negative
not-requiredfacts so it cannot suppress a later workflow prohibition. - Added 241 immutable, self-contained test-only 0.24.4 golden cases generated from the full tagged commit. The exact legacy bodies and public projections cover subjects, predicate kinds, connectors, domains, scopes, layouts, evidence, ordering, and deduplication; a 32-case matrix proves the requested pairwise interactions, deterministic current-only matrices cover scope proof, bridge precision and the directive/bridge, separator/previous-predicate, modal/domain, modifier/qualification, and homograph/predicate-head cross-products. Composed matrices additionally cover outer prefixes, continuation connectors, inherited modifiers, all separator quote enclosures and outer continuations, independent subject and policy state, multi-predicate subject-relative shapes, active/passive/state modal-negation semantics, composed prefixes, layouts, evidence, ordering, and deduplication; every observed difference is explicitly allowlisted.
Changed
- Replaced growing sentence-level body-policy contradiction patterns with a private statement-group and clause-facts model that establishes grammatical workflow-subject inheritance before separating security domain, modality, scope, and supported-clause completeness.
- Reused the same statement-group analyzer for prepared prose and eligible fallback lines such as headings. Subject inheritance supports multiple consecutive copular, auxiliary or modal, and curated ordinary-verb predicates, as well as the bounded
also,still, andthereforemodifier grammar. It stops at sentence endings, Markdown hard breaks, structural boundaries, changed subjects, conditional or subordinate prefixes, and unsupported syntax. - Preserved precision-first handling: only complete, high-confidence workflow-wide prohibitions contradict permissive policy metadata; local safeguards, requirement language, specific sources or targets, unknown states, and unsupported clauses remain unreported.
- Reused prepared Markdown clauses and retained physical source offsets so ordinary soft wraps preserve meaning, explicit hard breaks remain boundaries, and mixed-clause evidence stays bounded.
- Kept exact shared lexical vocabulary separate from classifier-specific semantic fact composition.
Compatibility
- Preserved diagnostic IDs, titles, severities, confidence, risk classes, remediation, LLM hints, bounded physical evidence, ordering, deduplication, policy resolution, CLI behavior, Diagnostics v2, review bundles, public types, schemas, package entrypoints, and supported deep imports. Compatibility means exact frozen 0.24.4 output plus the named allowlist: inherited evidence may include the supported later predicate, independent facts may restore a previously suppressed finding, and descriptive, changed-subject, destination-specific, conditional, or unsupported syntax may intentionally suppress a legacy false positive.
- Added no dependencies, public diagnostics, public configuration, or public clause-fact output.
0.24.4 - 2026-07-26
Fixed
- Distinguished workflow-wide network, upload, and secret prohibitions from local command, destination, source, and data-handling safeguards when reporting
SEC-BODY-POLICY-CONTRADICTION. - Preserved one-line and Markdown soft-wrap parity for local safeguards such as preventing
npxfrom downloading a missing package, while retaining genuine workflow-wide policy contradictions. - Distinguished requirement language such as “not required,” “not needed,” and “optional” from an actual workflow-wide prohibition, including bounded
should,will,would, andmayrequirement forms. - Kept explicit local setup, installation, validation, command, and phase restrictions non-contradictory while retaining qualifiers that clearly name the whole workflow, task, process, run, or operation.
- Preserved bounded global prohibition grammar for network access, external uploads, and secret use without attempting general natural-language intent classification.
- Required a recognized prohibition to consume the supported semantic content of its containing clause, leaving exception-bearing or otherwise unclassified clause remainders intentionally unreported.
Changed
- Consolidated only exact shared security-prose action, destination, workflow scope, and body-secret lexical sources into one private internal vocabulary module. Intentional classifier-specific supersets and subsets remain local.
- Prepared normalized paragraph, clause-range, structural-eligibility, and line-intersection facts once per paragraph and reused the ordered paragraph list across security checks.
- Cached paragraph-clause destination analysis by exact prepared paragraph identity and clause offsets while keeping line-specific guard and Finding evidence unchanged.
- Documented ownership boundaries for security diagnostics, command guards, sensitive-data classification, destination association, and shared prose vocabulary.
Compatibility
- Preserved diagnostic IDs, severity, evidence, deduplication, ordering, CLI schemas, and exit behavior outside the intentional body-policy false-positive correction.
- Added no dependencies and made no public API or package export changes.
0.24.3 - 2026-07-25
Fixed
- Fixed a false-positive
SEC-SECRET-MATERIAL-INSTRUCTIONresult when an explicit no-disclosure sentence was soft-wrapped across physical lines within one Markdown paragraph. - Preserved paragraph-local negation for the secret-specific
SEC-INSTRUCTION-VIOLATES-POLICYinterpretation under restrictive policy. - Retained each physical line's normalized range in the paragraph projection so action polarity remains available when the disclosure action and secret term occur on different soft-wrapped lines, while an earlier unrelated action does not invalidate a later explicit no-disclosure clause.
- Preserved explicit Markdown hard breaks as clause boundaries while joining genuine soft wraps with a space.
- Paragraph-local negation remains clause-aware and does not cross paragraph, list-item, blockquote, heading, thematic-break, hidden-comment, or code boundaries. Genuine positive disclosure instructions remain detected.
- Extended Markdown soft-wrap parity to adjacent security checks where actions, sensitive targets, configured forbidden inputs, or policy-prohibition phrases span physical lines within one clause. Explicit Markdown hard breaks remain clause boundaries, and genuine positive instructions remain detected.
- Distinguished structural command context from ordinary prose that mentions command names such as Git, AWS, or echo, preserving paragraph-level approval, forbidden-input, and body-policy interpretation across soft wraps while keeping code and prepared logical commands command-scoped.
Changed
- Made security-diagnostics document preparation explicit while retaining one parsed local policy, one effective policy, one Markdown structural view, and the existing visible-line and scan-start projections.
- Prepared one document-scoped logical-command analysis set, with one destination analysis and one security-command analysis per logical command plus the established physical-member-line index.
- Isolated the intentionally mutable human-approval and command-risk guard histories from immutable document facts, preserving current-line evaluation before history updates.
- Separated the document policy prelude, physical-line pass, semantic-unit pass, policy-contradiction pass, and final deduplication and Finding projection.
- Preserved the single lazy line analysis accessor and the deliberate distinction between line-local checks on physical members and command-scoped checks at logical-command starts.
Compatibility
- Except for the documented soft-wrap parity corrections, Renma 0.24.3 preserves public diagnostics, ordering, deduplication, policy semantics, CLI behavior, schemas, package entrypoints, and runtime boundaries.
- Paragraph context remains a private, clause-bounded interpretation input. It supplements selected prose-only polarity, action-target association, destination, approval, forbidden-input, body-policy, and Context-scope checks without replacing physical source evidence or command-scoped analysis.
- Existing unaffected Finding evidence remains unchanged. Newly recognized wrapped cases use the smallest source-based physical-line range required to represent the matched action, target, literal phrase, or prohibition.
0.24.2 - 2026-07-25
Changed
- Reused prepared per-asset security policy evidence when constructing policy inventory summaries, so snapshot-based scan and BOM paths do not parse or resolve the same policy solely for the summary.
- Moved Catalog diagnostic-to-Finding definitions into their cohesive deterministic analysis module while preserving the established scanner deep-import re-exports.
- Indexed BOM dependency, dependent, and exact-path diagnostic associations once before projecting assets, preserving their stable order and duplicate behavior.
- Centralized the exact two-space
JSON.stringifydocument format with one trailing newline while leaving deterministic key order with report construction. - Reviewed directly touched private and local names; none were materially misleading, so no naming-only changes were included.
Compatibility
- This internal maintainability release intentionally preserves public CLI behavior, schemas, diagnostics, findings, ordering, deduplication, evidence, deep imports, package entrypoints, and runtime boundaries. Package-version-derived values, including the BOM generator version and quality-profile identifiers, advance to 0.24.2.
0.24.1 - 2026-07-25
Changed
- Aligned the README, user and authoring guides, diagnostics and security references, architecture, product design, and roadmap with the shipped CLI, repository model, and public output contracts.
- Clarified which document owns each current contract, replaced duplicated release narration with canonical cross-links, and kept historical behavior in this changelog or focused compatibility documentation.
- Documented internal module responsibilities, dependency direction, compatibility facades, immutable projections, deterministic ordering, evidence ranges, and fail-closed boundaries in terms of their rationale and invariants.
- Removed redundant or obsolete release-specific code comments and corrected comments that understated the assets or relationships represented by the catalog.
- Added lightweight consistency checks for canonical documentation links and package/changelog version agreement.
Compatibility
- This is a documentation and maintainability release. It intentionally preserves every public command, option, schema identifier, Finding field, diagnostic ID, severity and risk classification, exit behavior, evidence range, ordering, deduplication rule, discovery boundary, compatibility re-export, deep import, and package-content contract.
0.24.0 - 2026-07-24
Added
- Added an internal
security-commandanalysis layer that classifies npm-style dependency pinning, sensitive sources, local and disclosure sinks, exact guard evidence, destination evidence, and supported/fallback state once per relevant command. The analysis is deterministic, non-executing, and is not a new public CLI JSON contract. - Added exact structural guard evidence with source ranges for the same instruction, same list item, preceding paragraph, and active safety section. Added focused unit, integration, scan, compatibility, and fixed-seed property coverage for source ranges, determinism, immutability, guard scope, variable identity, and fail-closed disclosure behavior.
Changed
- Changed npm, pnpm, and yarn version-variable handling so an unguarded variable emits
SEC-UNPINNED-DEPENDENCY-INSTALL. The exact${NAME:?message}fail-closed form is accepted at the use site or from a structurally associated executable guard for the same case-sensitive variable. Comments, prose, single-quoted literals, later guards, and unsupported control flow are not guard evidence. Renma does not infer verification from a variable name, assignment, default, or ambient environment and does not invent a remediation version. - Corrected npm-style attached option values so they do not consume the next package candidate, retained separated option-value handling, and recognized bounded pnpm filter and Yarn working-directory options before their subcommands. Incomplete or ambiguous candidate and manager-option projections select conservative fallback without discarding reliable package evidence.
- Changed sensitive-file decisions to distinguish actual environment files, keys, certificates/signing material, credential stores, cloud credentials, and other sensitive files from environment-variable API access.
process.env.NAMEandprocess.env["NAME"]remain non-file evidence. - Changed guarded local-only sensitive handling to avoid
SEC-SENSITIVE-FILE-REFERENCEand related secret-material findings only when bounded analysis proves every sink is a local file and an exact structural no-disclosure guard applies. Stdout, logs, prompts/Context, network, uploads, contradictory instructions, and unknown syntax remain findings. - Classified standard output/error descriptor devices as disclosure,
/dev/tcp/**and/dev/udp/**as network, and other unproven special devices as unknown. Disclosure negation now applies to its bounded action clause, so defensive wording cannot hide a later positive disclosure or upload. - Kept unsupported shell and JavaScript syntax on an explicit conservative fallback. Existing pip, Brew, container-image, destination, policy, severity, remediation, ordering, and deduplication behavior remains in place.
- Broadened the repository-owned
release-prepSkill to trigger for general release, publish, ship, and GitHub Release page requests, and to resume safely from already verified release stages without repeating completed external writes.
Compatibility
- Preserved every public diagnostic ID, Finding field, CLI schema, deep import, command option, exit behavior, destination normalization rule, logical shell continuation, policy inheritance rule, and deterministic ordering contract. The internal source, sink, guard, support, and trace evidence is not exposed through scan, readiness, BOM, diff, or CI JSON in 0.24.0.
- Preserved one destination and command analysis per logical command and one cached analysis per relevant line-local instruction. Full shell parsing, general JavaScript/TypeScript data flow, cross-command or cross-file taint, public source-to-sink JSON, configurable security suppressions, and runtime enforcement remain deferred.
0.23.5 - 2026-07-24
Added
- Added readiness-derived ownership endpoint counts to semantic diff and CI JSON while retaining
summary.ownershipCoverageDelta. CI Markdown now shows owned and eligible asset counts, percentages, and percentage-point changes. - Added bounded CI Markdown details for added, removed, and changed assets; canonical declared/effective owner changes; added and removed graph edges with resolution state; and readiness check status, severity, and summary changes. Complete unbounded collections remain available in JSON.
- Added concrete security policy inventory changes for denied network access, denied external upload, denied secrets, required human approval, and forbidden inputs, using the same security-change projection as direct diff Markdown.
Changed
- Changed semantic diff asset ownership to expose only canonical declared and effective ownership, including inherited and unowned states.
- Changed graph edge identity to use the stable source asset ID and declared target independently from source-path evidence and resolution-derived target fields. Resolved presentation still prefers the resolved target asset ID.
Compatibility
- Preserved existing JSON keys, ownership coverage delta, readiness scoring, unresolved-required-edge handling, Discovery CI policy, and established
PASS/WARN/FAILbehavior. Added resolved edges, owner-covered assets, and fail-closed policy inventory changes remain review evidence rather than regressions.
0.23.4 - 2026-07-24
Changed
- Reduced the published npm package from 3,078,627 to 2,062,004 unpacked bytes (33.0% smaller) and from 315 to 205 files (34.9% fewer) compared with 0.23.3. The release omits generated JavaScript source maps, repository examples, and internal planning documents from the package while retaining them in the source repository.
- Changed links to repository-only examples and planning documents in packaged documentation to use stable GitHub URLs, so those resources remain accessible without being duplicated in the npm artifact.
- Added package verification guards that reject generated source maps, repository examples, and internal planning documents if they re-enter the published artifact.
Compatibility
- Preserved the CLI, runtime JavaScript, TypeScript declarations, published schemas, user documentation, README targets, and deep-import checks. The reduction changes only debug source-map availability and which repository-only support files are copied into the npm package.
0.23.3 - 2026-07-24
Added
- Added strict
skill_discovery.ci_policyconfiguration with supported valuesoffandwarn. It defaults tooff;warnrequiresskill_discovery.adopted: true, and unknown keys, non-string modes, and unsupported modes are configuration errors.renma initremains unchanged and does not enable the policy. - Added the top-level
CiReport.skillDiscoveryPolicycontract with schemarenma.skill-discovery-ci-policy.v1. It records the base, target, and stricter effective modes plus deterministicpass/warnoutcome, count, and compact matches. Stable match IDs cover adoption weakened, adoption incomplete, newly not-reached eligible Skills under authoritative coverage, existing routes becoming unusable under authoritative coverage, and newly added unusable routes under authoritative coverage. - Added bounded CI Markdown policy configuration, outcome, and match details plus one plural-aware review note when matches request review. Added focused configuration, evaluator, archived-ref, status-composition, exit, cycle neutrality, formatter compatibility, instrumentation, and public-contract tests. Fixed-seed properties cover disabled-policy neutrality, cycle neutrality, permutation invariance, immutability, and deterministic repeated evaluation.
Changed
- Changed CI execution to retain only the two archived
skillDiscovery.ciPolicymodes beside the unchangedDiffReport. The stricteroff < warnmode wins, so bothoff -> warnandwarn -> offevaluate immediately and target-only policy removal cannot bypass review. - Added a pure warn-only evaluator and pure status composition. Existing
FAILremains dominant, existingWARNremainsWARN, and an existingPASSbecomesWARNonly when the enabled Discovery policy matches. Policy warnings still exit0; no Discovery policy condition can produceFAIL. - Preserved the one-pass archived-ref pipeline: one repository collection, one parse per artifact, one catalog preparation, one Agent Skills validation, one Skill Discovery preparation per ref, and one Discovery diff construction. CI performs no second config load, repository discovery, or semantic diff.
Compatibility
- Preserved
renma.skill-discovery-diff.v1, direct diff JSON and Markdown, direct diff exits, route and cycle identities, Readiness scoring and levels, diagnostics,buildDiffReport(), anddiffWithoutSkillDiscovery(). The nested CI-compatiblediffremains free of Discovery and policy fields. - Preserved pre-0.23.2 CI formatting without invented Discovery fields and 0.23.2 observation-only formatting without an invented policy evaluation. Newly generated reports always contain both
skillDiscoveryandskillDiscoveryPolicy. - Cycles, removed entrypoints, newly unrouted Skills, removed routes, declaration-count-only changes, newly reachable or resolved not-reached Skills, routes becoming usable, adoption becoming authoritative, and count deltas without matching identities remain non-policy evidence. Hard-fail gating, a fail mode, per-rule configuration, suppressions, and allowlists remain deferred for independent review without an assigned release.
0.23.2 - 2026-07-23
Added
- Added the required top-level
CiReport.skillDiscoveryfield using the existing observation-onlyrenma.skill-discovery-diff.v1contract. Newly generated CI JSON includes the complete deterministic Discovery diff once; the nesteddiffremains the established Discovery-freeCiCompatibleDiffReport. - Added a bounded
## Skill Discovery ChangesCI Markdown section after the semantic-diff summary. It reports schema, neutral policy effect, adoption, coverage, entrypoint, reachability, unrouted-Skill, route, and cycle changes, caps detail lists with the shared presentation limit, and directs readers to JSON for omitted entries. - Added focused archived-ref, pure-projection, formatter-compatibility, instrumentation, exit-behavior, and public CI JSON golden tests. Fixed-seed properties prove that Discovery-only changes cannot affect status or notes, mutate the direct diff, enter the nested compatible diff, or make repeated projection nondeterministic.
Changed
- Changed
ci-reportto call the complete public semantic diff exactly once and project it throughbuildCiReportFromDiff(). Each ref still has one immutableRepositorySnapshot, one discovery pass, one parse per artifact, one catalog preparation, and one Agent Skills validation; CI now intentionally prepares one Skill Discovery index per ref and constructs the existing diff once. - Preserved CI policy by continuing to pass only
CiCompatibleDiffReportinto status and review-note evaluation. Adoption, coverage, publication, reachability, unrouted Skills, route usability, and cycles remain neutral review facts and do not change Readiness scores,PASS/WARN/FAIL, notes, or exit codes.
Compatibility
- Preserved direct
renma diffJSON, Markdown, route and cycle identities, and exit behavior.diffWithoutSkillDiscovery()remains available as the older projection for compatibility consumers. - Added a defensive CI formatter input for pre-0.23.2 serialized reports. Legacy reports without
skillDiscoverykeep their previous JSON and Markdown shape without an invented neutral section or mutation. - Updated only the intentional CI report golden. The existing
skill-discovery-diff.goldenand unrelated public JSON goldens are unchanged. Optional Discovery CI policy and gating remain deferred without an assigned release.
0.23.1 - 2026-07-23
Added
- Added the observation-only top-level
DiffReport.discoverycontract with schema versionrenma.skill-discovery-diff.v1. Direct diff now reports exact adoption and coverage transitions, compactto - fromsummary deltas, effective published entrypoint additions/removals, newly reachable and not-reached Skills, newly and resolved unrouted Skills, route additions/removals/state changes, and added/resolved maximal cyclic components. - Added deterministic route grouping by normalized repository-relative source Skill path plus normalized declared target. Duplicate declarations are represented by one route group's
declarationCount; declaration reordering, YAML array position, source lines, discovery order, and resolved target are not route identity. - Added compact bounded
## Skill Discovery ChangesMarkdown details and a complete deterministic JSON section without copying Skill Index arrays, Discovery diagnostics, raw evidence, declaration indices, temporary roots, timestamps, or mutable internals. - Added focused route-state, publication, reachability, unrouted, normalization, duplicate, cycle, invalid/duplicate-ID, snapshot-instrumentation, direct diff/CI compatibility, and fixed public JSON golden coverage. Property tests cover insertion and declaration permutation, reversal, determinism, summary negation, and input immutability.
Changed
- Changed semantic diff snapshot preparation to collect exactly one immutable
RepositorySnapshotper Git ref. Graph, the Discovery-excluded Readiness subset, andsnapshot.skillDiscoverynow share one discovery pass, one parse per artifact, one catalog preparation, one Agent Skills validation, and one Skill Discovery preparation per ref. Diff does not callskill-index, reconstruct Discovery, or recollect for graph or Readiness. - Changed CI report to request its pre-0.23.1 semantic-diff projection before snapshot derivation. Each ref still uses one repository collection and one parse per artifact, while CI does not prepare
skill-discoveryor construct a Discovery diff. A defensiveCiCompatibleDiffReportomission remains at the output boundary. CI JSON and Markdown, status calculation, notes, and exit behavior retain their existing contract and receive no Discovery integration or policy in 0.23.1. - Updated the roadmap sequence to 0.23.0 Readiness, 0.23.1 direct semantic diff, independently reviewed 0.23.2 CI report integration, and only later optional CI policy or gating.
Compatibility
- Preserved Discovery route resolution, usability, publication, adoption, reachability, unrouted, and cycle semantics and every Discovery diagnostic ID, severity, message, evidence, repair constraint, and verification step. Generic
readiness.checkChangesstill excludesdiscovery.*; Readiness scoring and levels, Skill Index, Discovery graph, BOM, Trust Graph, ownership, runtime boundaries, and direct diff exit behavior are unchanged. - Preserved the exported pre-0.23.1
buildDiffReport()snapshot shape and legacyformatDiff()inputs. Missing prepared indexes produce a stable neutral Discovery compatibility projection without inferred topology; legacy reports withoutdiscoveryrender the previous non-Discovery Markdown. - Added only the intentional Discovery semantic diff golden. No unrelated public JSON golden was regenerated. CI report integration remains deferred to 0.23.2 review; optional CI policy or gating remains a later independent decision.
0.23.0 - 2026-07-23
Added
- Added additive
summary.skillDiscoveryReadiness JSON with the existing adoption state and compact counts for effective published entrypoints, route-eligible, reachable, not-reached, and unrouted Skills, usable, unusable, and unresolved routes, and maximal cyclic components. - Added
discovery.publication,discovery.route_validity,discovery.coverage,discovery.unrouted_skills, anddiscovery.cycle_reviewReadiness checks with deterministic compact evidence derived from the prepared Skill Discovery index and its existing structured diagnostics. - Added a compact Skill Discovery section to Readiness Markdown with direct guidance to
renma skill-indexandrenma graph --view discoveryfor full static evidence.
Changed
- Changed Readiness to reuse the memoized immutable Skill Discovery projection from its existing shared
RepositorySnapshot; one command still performs one repository collection, one parse per artifact, one catalog and Agent Skills preparation, and at most one Discovery index preparation. - Documented authoritative adopted-mode coverage separately from descriptive partial coverage and explicitly unevaluated not-adopted/no-entrypoint coverage. Not-adopted repositories keep useful Skill and route inventory counts while publication and coverage remain neutral, warning-free policy checks. Partial coverage does not lower Readiness, and cyclic usable route components remain warning-level review evidence rather than automatic hard failures.
- Changed semantic diff to request its existing Readiness subset without preparing Skill Discovery for either ref; CI inherits the same projection boundary. Direct Readiness still prepares the memoized projection at most once, while BOM continues not to prepare or serialize Discovery Readiness.
- Kept the 0.23.0 checks visibility-only for scoring. They add no independent score weight, do not copy Discovery diagnostics into Readiness diagnostics, and therefore do not penalize existing authoritative evidence twice.
Compatibility
- Preserved Discovery route resolution, usability, eligibility, publication, adoption, reachability, unrouted classification, and cycle detection; preserved
renma.skill-index.v1,graph --view discovery, and every existing Discovery diagnostic ID, severity, wording, evidence, repair constraint, and verification step. - Updated only the intentional additive Readiness public JSON golden. Existing Readiness fields, scores, levels, diagnostic arrays, and package-version normalization remain unchanged.
- Semantic diff, CI report and optional gating, Trust Graph, Repository Context BOM, ownership, richer visualization, federation, runtime selection, execution, and telemetry integration remain deferred. Readiness adds no Discovery preparation to those deferred output contracts. No diff, CI, BOM, or gating fields were added.
0.22.6 - 2026-07-22
Changed
- Replaced catalog-to-Finding message parsing with producer-assigned stable diagnostic identities and an exhaustive typed conversion registry while preserving diagnostic wording and public JSON projections.
- Classified every production TypeScript module into an enforced dependency layer, including type-only imports and re-exports, with narrowly documented compatibility seams for established deep imports.
- Split the former broad
src/types.tshub into cohesive low-level contracts and an isolated composed scan-result type while retaining the establisheddist/types.jscompatibility facade. - Separated one collected repository core from explicit memoized projections. The complete caller-visible evidence graph and every prepared projection are runtime-immutable, including nested configuration, parsed evidence, Sets, and Maps, while catalog still avoids unrelated Discovery and security work and scan, Readiness, and BOM continue to reuse one collection.
- Pinned representative scan, catalog, graph, Skill Index, Readiness, and BOM JSON output to normalized 0.22.5 golden baselines, including catalog-only diagnostics and their established scan Finding and DiagnosticV2 projections.
- Consolidated CLI help, positional bounds, accepted options, defaults, command-specific parsing/execution, and expected error adapters behind a statically complete typed command registry without changing command output or exit behavior.
- Added one-pass catalog dependency indexes, typed ESLint checks for promise and switch safety, and a reusable temporary repository fixture builder while preserving rendered ordering and public serialization.
0.22.5 - 2026-07-21
Changed
- Internally modularized deterministic security destination analysis into logical-shell projection, lexical classification, operational association, and normalization/matching layers, with a shared compatibility corpus and seeded property tests. No CLI or diagnostic behavior change is intended.
0.22.4 - 2026-07-21
Added
- Added deterministic, stack-safe iterative strongly connected component detection over only usable representative resolved Skill-to-Skill continuation routes, including one-pass internal-route grouping, explicit self-loop handling, and one
DISCOVERY-ROUTE-CYCLEwarning per maximal cyclic component. Detection isO(V + E)apart from deterministic sorting. - Added complete sorted cycle member, Skill path, internal route, declaration index, and line evidence to each warning, with cycle-specific LLM repair constraints, human decision guidance, and graph, Skill Index, and scan verification steps.
- Linked each warning to every member Skill and internal route, preserved repository-wide cycle evidence under exact direct-neighborhood focus, and propagated the warning through scan, diagnostics v2, review bundles, Discovery graph diagnostics, and Skill Index diagnostics.
Changed
- Clarified the bundled release-prep Skill and Context to require
Renma v<version>as the GitHub Release title while retainingv<version>as the Git tag. - Limited network allowlist scanning of dotted local identifiers to lines with network actions while preserving upload allowlist detection for every supported upload action.
Fixed
- Hardened network and upload destination classification by separating lexical candidates from clause-associated operational targets. Local dotted paths, filenames, Renma identifiers, and command file arguments remain local; candidate text cannot create its own action signal; unsupported explicit URLs retain fail-closed permission intent; coordinated destination lists inherit one governing action; curl upload options work before or after the URL while backslash-continued commands retain exact token identity and source-line evidence and remain bounded to the candidate's shell command and
--nexttransfer; standalone&separates commands without treating&>or2>&1redirections as boundaries; transport-less IP and strong host candidates require an action; explicit URLs support IPv4, bracketed IPv6, internationalized and single-label hosts; and network and upload allowlist boundaries remain separate.
Compatibility
- Preserved reachability, minimum depth, source-entrypoint provenance, coverage, route resolution/usability, focus neighborhoods, Discovery graph schemas and edge rendering, and the exact
renma.skill-index.v1top-level shape. Cycles remain traversal-safe static review evidence and do not imply runtime recursion or require repair. - Readiness, semantic diff, CI report, Trust Graph, Repository Context BOM, ownership, init, scaffold, guide, suggestions, metadata, configuration, suppression, CI gating, and package version remain unchanged.
0.22.3 - 2026-07-20
Added
- Added the stdout-only
renma skill-index [path]command with default compact Markdown, canonicalrenma.skill-index.v1JSON,--json, and exact optional Skill ID or repository-relativeSKILL.mdpath focus. - Added a pure Skill Index report builder over one shared
RepositorySnapshotand its prepared Discovery index. The report preserves existing Skill, route, publication, adoption, reachability, coverage, structural-root, standalone, unrouted, focus, and diagnostic projection contracts without rescanning. - Added compact, deterministically capped Markdown for published entrypoints, direct continuations, authoritative coverage gaps, structural candidates, separate Discovery/repository diagnostics, and source-Skill continuation guidance.
- Documented broad and intermediate routers, workflow/orchestration Skills, specialized operational Skills, and the rule that workflow policy stays in the owning Skill body rather than continuation declaration order.
Compatibility
- Preserved every
graph --view discoveryJSON, Markdown, and Mermaid contract. The Skill Index adds no Mermaid format and does not add route cycles or new reachability semantics. - Readiness, semantic diff, CI report, Trust Graph, Repository Context BOM, ownership, init, scaffold, guide, suggestions, configuration, Skill metadata, and package version remain unchanged. The command creates no generated index or repository files.
0.22.2 - 2026-07-19
Added
- Added cycle-safe, deterministic multi-entrypoint reachability over only usable representative resolved Skill-to-Skill continuations, including per-Skill state, all reaching entrypoint IDs, and true minimum route depth.
- Added repository-scoped
not-evaluated,descriptive, andauthoritativecoverage modes; reachable, not-reached, and exact unrouted eligible-Skill ID arrays; and projection-scoped summary counts with repository-scoped coverage retained under exact focus. - Added
DISCOVERY-UNREACHABLE-ELIGIBLE-SKILLwarnings only for authoritative adopted-mode coverage gaps, with Skill identity evidence, constrained human repair choices, reachability-specific verification, scan/diagnostics-v2 propagation, and review-bundle support. - Extended Discovery JSON, Markdown, and Mermaid with coverage, reachability, unrouted facts, adopted-mode coverage gaps, and deterministic coverage comments while preserving existing route edge meaning.
Compatibility
- Existing Discovery resolution, usability, publication, adoption, structural-root, standalone, focus-neighborhood, warning, and exit-code contracts remain unchanged. No route-cycle diagnostic or new command was added, and
catalog.dependenciesremains separate. - Readiness, semantic diff, CI report, Trust Graph, Repository Context BOM, ownership, init, scaffold, guide, suggestions, and package version remain unchanged.
skill-indexremains a later report/CLI slice.
0.22.1 - 2026-07-19
Added
- Added the exact canonical Agent Skills
metadata.renma.published-entrypoint: "true"marker, publication eligibility and rejection evidence, and deterministic effective published-entrypoint projection without inferring publication from structural roots or routes. - Added strict
skill_discovery.adoptedrepository configuration and explicitnot-adopted,partial,incomplete, andadoptedstates. Coverage remains explicitlynot-evaluatedbecause reachability and coverage are deferred. - Added
DISCOVERY-INVALID-PUBLISHED-ENTRYPOINTandDISCOVERY-ENTRYPOINT-WITHOUT-USABLE-BOUNDARIESwarning diagnostics through scan, diagnostics v2, and review bundles. - Extended
graph --view discoveryJSON, Markdown, and Mermaid with adoption, publication evidence, explicit published entrypoints, and distinct entrypoint styling while preserving repository diagnostics separately.
Compatibility
- Discovery publication remains separate from structural-root facts and
catalog.dependencies. Existing graph views and Readiness, diff, CI report, Trust Graph, BOM, ownership, init, scaffold, guide, and suggestion contracts remain unchanged;renma initdoes not adopt Skill Discovery. - Reachability, coverage evaluation, unreachable-Skill diagnostics,
skill-index, and runtime Skill selection remain deferred.
0.22.0 - 2026-07-19
Added
- Added the canonical Agent Skills
metadata.renma.continues-withJSON-array string contract, exact Skill ID or repository-relative path resolution, route eligibility and usability evidence, deterministic duplicate handling, and structural-root facts. - Added warning diagnostics for invalid continuation declarations, unresolved or ambiguous routes, non-Skill targets, inactive targets, and duplicate declarations. Discovery diagnostics flow through repository snapshots, normal scan output, and diagnostics v2 repair guidance.
- Added
graph --view discoveryJSON, Markdown, and Mermaid projections with optional exact Skill ID/path focus over direct incoming and outgoing declared routes.
Compatibility
- Skill continuations remain separate from
catalog.dependencies; existing graph views and Readiness, diff, CI report, Trust Graph, BOM, ownership, init, scaffold, guidance, and suggestion behavior are unchanged. - Published entrypoints, repository-wide Discovery adoption, reachability, coverage,
skill-index, and downstream report integrations remain deferred.
0.21.0 - 2026-07-19
Added
- Added
renma init [root]to record explicit repository adoption with a minimalrenma.config.jsonwhile preserving existing conventional config files and keeping repository initialization separate from asset scaffolding.
Changed
- Expanded the GitHub Actions example to generate catalog, focused composition, and CI report artifacts, enforce scan and report failures, and maintain one CI report comment for same-repository pull requests while preserving artifacts as the fallback for fork pull requests.
0.20.2 - 2026-07-19
Added
- Added
SEC-SAFEGUARD-BYPASS-INSTRUCTIONfor explicit guidance that disables checks, weakens policy to pass diagnostics, suppresses warnings, bypasses or defers approval, selects a riskier permission fallback, or auto-executes after no user response. - Added
SEC-UNTRUSTED-CONTENT-AS-INSTRUCTIONfor instructions that make external pages, issue bodies, logs, tool output, attachments, or downloaded content executable authority without review. - Added
SEC-UNBOUNDED-EXTERNAL-SOURCE-TRAVERSALfor explicit recursive external-source walks with no local scope or termination boundary. The finding is low/advisory by default and medium/suspicious when combined with a local upload or sensitive-disclosure instruction.
Changed
- Adopted one shared CommonMark AST for general Markdown headings, links, images, and code-block structure. Normal repository scans reuse one primary parse per eligible Markdown artifact while preserving public JSON shapes and original-file line provenance. This reduces false positives from fenced and indented code, inline code, HTML comments, and malformed Markdown-like text; recognizes Setext and formatted headings plus tilde and longer fences; and keeps established inline image destinations in the existing link projection.
- Limited security content analysis to LLM-facing Markdown instructions and metadata. Scripts retain discovery, catalog, ownership, inherited-policy, Trust Graph, and BOM evidence, but executable contents require independent project-selected SAST and dependency scanning. Renma still diagnoses Markdown instructions that direct an agent to fetch, trust, execute, or invoke scripts unsafely.
- Strengthened Security Diagnostics with one primary CommonMark AST parse per eligible Markdown artifact and bounded reparsing only for visible prose recovered from raw flow HTML. Positioned paragraph and list-item boundaries prevent sibling or nested instructions from being combined, while heading, block quote, HTML-comment, inline-code, and code-block ranges drive approval proximity, action-span guards, emitted-action deduplication, operational fence routing, and deterministic original-line evidence for agent-facing artifacts.
- Refined the existing bulk sharing, overbroad context, redaction, secret material, and upload rules to distinguish local reads, prompt/context attachment, stdout/log output, and external upload.
process.env.NAMEis no longer treated as a.envfile reference, while actual.envpaths remain detectable.
Compatibility
- Security diagnostics remain repository-governance checks over already discovered agent-facing instructions. This change adds no language-specific SAST, dependency or workflow scanning, runtime enforcement, command or network execution, LLM call, telemetry, automatic repair, suppression, or policy relaxation. Passing a scan is not a safety proof.
- Renma analyzes the security posture of LLM-facing Markdown instructions and metadata. It does not perform language-specific analysis of referenced or embedded executable scripts; use appropriate SAST and dependency-scanning tools for executable code.
0.20.1 - 2026-07-16
Added
- Added pure Declared Impact resolution over the prepared Declared Composition index. A focused asset now resolves its reverse transitive closure through explicit required/optional Context and Lens declarations plus Lens
applies_to, with stable-ID deduplication, direct/transitive status, and required/optional affected Skill summaries. - Added a
DeclaredImpactIndexwith incoming resolved declarations layered over the unchanged forwardDeclaredCompositionIndex. Incoming entries retain source asset, target asset, raw dependency, normalized relationship, declaration form and index, source path, line evidence, and kind mismatches. Reverse traversal uses(asset ID, membership)state and edge provenance rather than enumerating every dependent-to-focus path. - Added
graph --view impact --focus <asset-id-or-path>with complete JSON, change-review-oriented Markdown, and original-declaration-direction Mermaid output. Invalid incoming declarations remain visible without establishing a valid impact route. - Added the focused Declared Impact contract, graph view comparison, practical change-review guidance, and resolver, graph, CLI, renderer, cycle, invalid-declaration, and high-path-count DAG tests.
Changed
- Added separate composition and impact index preparation so composition and scan do not build reverse incoming declarations. Impact construction appends to mutable target buckets internally, then exposes deterministically sorted read-only collections.
- Updated graph help and documentation to distinguish the repository-wide full graph, direct focused neighborhood, forward Declared Composition, and reverse Declared Impact.
Compatibility
- Existing CLI behavior, graph views and documented JSON fields, composition reports and diagnostics, Lens freshness, authoring projections, BOM, Trust Graph, Readiness, and Security Profile
extendssemantics remain unchanged. The exportedDeclaredCompositionIndexkeeps its 0.20.0 field shape; theDeclaredImpactIndex,impactview and report, and impact graph edge membership field are separate additions. - Declared Impact does not claim runtime usage, actual breakage, required file changes, optional selection, test requirements, or semantic relevance. Renma performs no network access, LLM call, runtime selection, prompt assembly, telemetry collection, or repository rewrite for this query.
0.20.0 - 2026-07-16
Added
- Added a pure Declared Composition resolver over the existing catalog. It expands explicit required/optional Context and Lens declarations plus Lens
applies_to, propagates optional membership, deduplicates by stable asset ID, retains required and optional predecessor-edge provenance, and keeps storage proportional to declarations instead of possible paths. - Added separate required and optional unresolved declarations, independent source- and target-kind mismatches, completeness flags, strongly connected required and optional cycles, normalized transitive conflicts, lifecycle findings, and freshness summaries. A fully resolved cycle remains complete while
cycleFreeis false; conflicts never select a winner. - Added
graph --view composition --focus <asset-id-or-path>with deterministic JSON, compact Markdown, and required-versus-optional Mermaid projections. Dependency graph edges now retain additive declaration form, declaration index, and line-level source evidence. - Added scan findings
META-DEPENDENCY-SOURCE-KIND-MISMATCH,META-DEPENDENCY-TARGET-KIND-MISMATCH,META-DUPLICATE-DECLARED-DEPENDENCY,COMPOSITION-REQUIRED-CYCLE,COMPOSITION-OPTIONAL-CYCLE,COMPOSITION-DECLARED-CONFLICT, andCOMPOSITION-OPTIONAL-CONFLICT, with actionable diagnostics v2 guidance. - Added top-level conditional normative
externalTraversalRulesto the Skill authoring source. The rules distinguish named source reading from recursive traversal and require bounded logical-identity, visited-source, relevance, termination, safety-cap, cycle, access-failure, and unresolved-boundary behavior in authored Skills when recursion is possible.
Changed
- Extended the existing freshness rules and diagnostic IDs to Context Lenses.
- Reused one prepared Declared Composition index across scan roots, limited per-root governance work to reached assets, consumed complete root reports incrementally, deduplicated declaration transitions per resulting membership, promoted shared SCC diagnostics to required whenever any root requires them while retaining optional roots, and rendered SCC members with actual declaration edges instead of a fabricated sorted path.
- Documented that Renma models explicit composition rather than natural-language inheritance, declaration order has no precedence, stable IDs resolve once while all declaration evidence remains, cycles terminate finitely, and
extendsstays limited to typed overlay/profile contracts. - Rendered external traversal rules after metadata rules and before illustration usage, preserving the 0.19.2 separation of normative protocol, conditional normative guidance, illustration rules, non-normative illustrations, compact prompt, and complete JSON projections.
Compatibility
- Existing commands, graph views, output fields, lifecycle semantics, Security Profile
extendsresolution, Trust Graph v2, Repository Context BOM v2, Readiness, deterministic stdout, and read-only/non-network/non-LLM boundaries remain intact. New graph fields, the composition view, authoring field, and diagnostics are additive. - Renma still does not select or execute Skills, select or load runtime Context, assemble prompts, coordinate Workflows, fetch or crawl external sources, call an LLM, infer undeclared composition, resolve conflicts automatically, or rewrite repository assets.
0.19.2 - 2026-07-15
Changed
- Structurally separated the normative 0.19.1 authoring protocol from a deterministic top-level collection of non-normative, intentionally incomplete illustrations.
interactionnow contains protocol rules only; the previous example fields and special top-level API object have no compatibility aliases in the independently unversioned guide JSON projection. - Added normative illustration-usage rules: apply the protocol directly to the current request and evidence, never choose or copy the closest illustration, ignore illustrations when useful, and combine individual decision patterns only when their conditions are independently present. Renma adds no illustration classifier, selector, similarity matcher, or Skill-type template.
- Consolidated the minimal-clarification, report-first-progression, and source-backed-boundary patterns under one illustration type. The fictional Product API remains fully contained in one source-backed illustration; its API, schema, timeout, retry, and response details are not universal Skill requirements.
- Reinforced that Context Assets, Context Lenses, scripts, support files, external sources, runtime network access, and Skill splits each require independent justification. Future review findings remain runtime task unknowns rather than automatic authoring blockers.
- Made top-level verification domain-neutral and conditional, while retaining Context, URL, access, fallback, and security checks inside the source-backed illustration. The default prompt now renders compact illustration decisions; JSON retains detailed optional structures for external consumers.
Compatibility
- Existing command syntax, formats, exit codes, deterministic stdout-only behavior, repository independence, and non-editing/non-network/non-LLM boundaries remain unchanged. The additive guide JSON projection still has no independently versioned schema, so removed example fields have no compatibility-only duplicates inside the normative interaction object.
- The 0.19.1 creation gate, question batching, queued blockers, conservative repairs, re-entry, and persistence semantics are unchanged.
0.19.1 - 2026-07-15
Added
- Added an interactive, truth-seeking authoring protocol to the existing structured
renma guide skillsource. The default prompt now tells the consuming LLM to investigate qualified user, artifact, repository, and authoritative-source evidence; distinguish confirmed facts from proposals and unresolved human truth; separately classify Blocking, Reversible default, and Deferred progression; distinguish authoring decisions from runtime task unknowns; separate authoring-time from runtime source access; ask focused question batches while retaining queued blockers; pass and re-enter a creation gate; classify post-validation actions conservatively; and persist only reviewed decisions. - Added minimal-trigger and fictional Example Product API clarification examples plus focused regression coverage for prompt ordering, the additive JSON interaction projection, decision classes, question rules, creation gates, handoff, boundary-change re-entry, uniquely supported repairs, repeated-context constraints, unknown scope and disposition, progression and question batching, stage-dependent blockers, persistence, determinism, and non-editing behavior.
Changed
- Clarified the authoring boundary: Renma prints a deterministic protocol while the consuming LLM conducts the conversation, the user supplies domain and governance truth, and a human approves meaningful decisions.
- Delayed platform-native Skill authoring guidance until after the Renma clarification gate and limited it to semantic refinement within the agreed scaffold and asset structure. Newly discovered boundary changes return to the clarification gate instead of silently changing repository structure.
- Clarified that deterministic findings are not automatically deterministic repairs. Repeated-context consolidation and unsupported-field meaning require investigation or human review unless evidence uniquely determines a safe patch.
- Reduced duplicated prompt workflow and artifact prose so the interaction object remains the normative owner of truth, gate, validation, persistence, and handoff behavior.
- Clarified that authoring proceeds when no Blocking decision remains, while visible safe reversible defaults and Deferred decisions may remain without becoming Confirmed. Unrelated branching blockers prompt a proposed boundary reconsideration rather than an automatic Skill split.
- Clarified that runtime task unknowns are findings rather than automatic authoring blockers, runtime-stage blocking follows the authored handling policy without adding task-instance facts to the creation gate, “do not guess” still permits independent analysis, related raw gaps should be clustered into decision themes, and Example Product API runtime knowledge is rendered once.
Compatibility
- Existing
guidecommands, options, exit codes, stdout-only behavior, and prompt/JSON derivation remain unchanged. The JSON projection adds only theinteractionobject and still has no separately versioned schema. - Renma remains non-interactive and adds no task input, session state, LLM call, automatic creation, repair, runtime selection, or decision-state metadata.
0.19.0 - 2026-07-14
Added
- Added deterministic
renma guide skillprompt and JSON authoring guidance derived from one structured rule source. The command includes the installed version, requires no repository, writes only to stdout, and performs no filesystem, network, or LLM operations. - Added focused guide regression coverage for formats, determinism, version reporting, non-editing behavior, help, argument validation, load-bearing authoring invariants, and the compact fictional Example Product API Skill-plus-Context example.
Changed
- Changed new-Skill authoring priority to establish Renma asset, metadata, Context, source-of-truth, and file-responsibility boundaries before using platform-native guidance to refine Skill semantics.
- Updated Skill scaffold prompts and next steps to direct authors through
renma guide skill, justified Context decisions, scan, catalog and graph evidence, reruns, and human review. - Clarified that source-of-truth status alone can justify a Context Asset, structured output alone does not justify a script, and every support file needs a distinct current responsibility.
Compatibility
- Existing commands and JSON contracts remain unchanged.
guideis additive and intentionally has no separately versioned public JSON schema in this release.
0.18.3 - 2026-07-14
Added
- Added focused regression coverage for repository markers and guard directories, cross-command classification evidence, historical and canonical parent-Skill resolution, inherited governance provenance, structured command displays, and snapshot reuse.
- Added an internal architecture guide describing repository snapshots, resolution and evidence stages, decisions, renderers, fail-closed boundaries, and compatibility constraints.
Changed
- Centralized target document and repository evidence used by
inspectandsuggest-metadata, including boundary resolution, metadata-refined classification, parent-Skill resolution, ownership, and policy provenance. - Made repository snapshots retain shared classification, parent-Skill, and security-policy indexes so downstream commands do not reinterpret the same files independently.
- Changed Readiness to derive graph and scan results from one repository snapshot instead of discovering and parsing the repository twice.
- Separated metadata-suggestion decision types and typed owner-conflict logic from human wording. Human prompt and inspect text rendering now live behind focused renderer boundaries while legacy module exports remain available.
- Added design comments for repository guards, outer-boundary precedence, ownership non-inference, parent inheritance, application gates, and repository-rooted migration collision checks.
- Removed the inspect command/renderer type cycle by placing their shared DTOs in a neutral evidence module while preserving command-module type exports.
- Reused one Skill parent index for snapshot catalog ownership, target parent resolution, and governance enrichment; ambiguous and unresolved repository boundary evidence now also remain distinct internally.
- Moved the remaining pure metadata-suggestion decisions into the decision layer without moving filesystem checks, next-action construction, or rendering into it.
Compatibility
- CLI names, arguments, exit codes, JSON property names, enum values, finding and diagnostic IDs, severity, scoring, migration direction, package entry paths, and previously packaged deep-module entrypoints remain compatible with 0.18.2. The package adds only the new internal modules and architecture guide.
- Scan diagnostics continue to expose structural parent candidates while repository-aware commands may enrich the same classification to
resolved,missing, orambiguous. This stage distinction avoids changing existing diagnostic JSON. - Blocked historical Skill migrations continue to retain partial diagnostic candidate maps for 0.18.2 JSON compatibility.
decisionStatus: "blocked"remains the authoritative hard stop, and no applicable canonical frontmatter or patch instruction is emitted.
0.18.2 - 2026-07-13
Added
- Added one deterministic asset-classification evidence model shared by discovery,
inspect,suggest-metadata, and relevant scan diagnostics. JSON now separates stablematchedRuleandreasonCodefields from human-readable explanations, includes concise competing-rule evidence, and keeps classification separate from ownership and policy governance. - Added explicit suggestion
decisionStatus, structured decision evidence, cross-platform next actions with separate command/argv/display fields, and the successfulno-proposalmode.
Changed
inspectnow reports classification for cataloged assets, files with missing metadata, repository tools, and unknown files. When catalog evidence exists, it reports declared or inherited ownership and policy separately.suggest-metadatanow uses the shared classifier. Ordinary Skill-local support produces no independent retrofit proposal unless an explicit supported override is supplied; existing local metadata remains supported.- Repository classification resolves an explicit caller root first, then the nearest safe
.gitor Renma config marker, then an unambiguous structural boundary. Being below the current working directory is no longer treated as repository-root evidence. - Skill entrypoint classification and migration now use the resolved repository-relative path consistently. Filesystem collision checks rebase the repository-relative migration target against that resolved root, so invoking Renma from a nested repository's parent behaves like invoking it inside the repository.
- Skill-local classification now records a structural parent candidate separately from catalog-backed
resolved,missing, orambiguousparent evidence. Missing and ambiguous parents block inheritance claims and metadata proposals until the layout is reviewed.
Fixed
- Prevented nested
references/,profiles/,examples/,scripts/, orassets/names from overriding the recognizedcontexts/**or legacycontext/**boundary. - Prevented
references/**,tools/**, andskills/**/tools/**from being misclassified as independently governed Context Assets or canonical local support. - Repository paths with multiple plausible structural roots now fail closed as
repository-boundary-ambiguous; unresolved and ambiguous suggestions no longer manufacture ascan .action against the caller's current directory. - Marker-free structural fallback now treats
profiles,references,examples,scripts, andassetsonly as ambiguity guards. Those directory names never establish a repository root without a strong boundary, explicit root, or repository marker. - An explicit owner equal to an existing canonical
metadata.renma.ownernow returnsno-proposalandno-change-recommendedwithout candidate metadata or frontmatter.
Compatibility
- The
inspectJSON outline addsrepositoryBoundary,classification, andgovernance.repositoryBoundarypreserves resolved or unresolved boundary evidence, including ambiguity candidates when present.suggest-metadataJSON addsclassification,decisionStatus,decision, andnextActions, and may returnsuggestedMode: "no-proposal". Relevant diagnosticdetailsmay addclassification. The new JSON fields are additive, but the command behavior is intentionally refined: targets that previously represented a successful no-change result may now usesuggestedMode: "no-proposal", and Skill-local inheritance is reported only after one parent resolves. Consumers should branch ondecisionStatus, treat unknown futuresuggestedModevalues conservatively, and executenextActions[].invocation.commandwithinvocation.argsrather than parsingdisplay. Finding severity, scan thresholds, Readiness scoring, Agent Skills migration direction, and supported explicit local metadata remain unchanged.
0.18.1 - 2026-07-13
Added
- Added
token_budget_override,token_budget_rationale, and optionaltoken_budget_reviewed_atmetadata for recording a declared human decision that a support asset should remain intentionally long. Invalid, ambiguous, incomplete, orphaned, or unnecessary decision metadata emitsQUAL-INVALID-TOKEN-BUDGET-OVERRIDEand never suppresses the default budget. Only Markdown-parser-eligible support assets can declare the bundle, and override limits must be positive safe integers represented exactly. - Added the blocking
CONTEXT-LENS-TARGET-NOT-CONTEXTdiagnostic. Context Lensapplies_totargets must now resolve specifically to Context Assets; Skills, support assets, and other Context Lenses are rejected.
Changed
- Changed support-asset token guidance to ask for a split-versus-intentionally- long user decision. Semantic splitting remains preferred when it preserves coherence and execution order; a valid declared decision provides an effective limit for intentionally coherent or ordered long-form assets.
- Clarified Skill, Context Asset, Context Lens, Skill-local support, and external runtime responsibilities across canonical documentation, CLI help, scaffolds, and examples. Context Lens guidance now requires declared Context, rejects persona-only authoring as insufficient, uses canonical Agent Skills relationship metadata, and preserves focused workflows without changing Renma's deterministic runtime boundary.
0.18.0 - 2026-07-12
Added
- Added the internal
renma-qualityprofile family. The emitted profile identifier is derived from the Renma package version asrenma-quality@<package version>. Added canonical threshold documentation with units, provenance, rationale, false-positive risks, and future-configurability status. - Added one deterministic Unicode-aware
estimated_tokensimplementation for Skill, content-asset, reuse-candidate, and repeated-context analysis. - Added first-class
scriptandassetartifact kinds under both supported Skill roots, including original-byte hashes, sizes, text/binary classification, Markdown eligibility, and catalog, graph, Trust Graph, and BOM inventory. - Added direct, one-index-hop, deep-chain, unreachable, and missing-path static support reachability for references, scripts, assets, profiles, and examples.
- Added
renma scaffold skill --resources references,scripts,assets; file mode creates only selected empty directories, while prompt and JSON modes report the selected resource contract without writing files. - Added BOM and Trust Graph v2 as the first supported long-term schema contracts. Renma 0.18.0 does not provide a v1 compatibility mode; the earlier experimental v1 surface was removed before broader adoption.
- Added normalized ownership provenance and static local-resource relationship edges across catalog, graph, readiness, BOM, and Trust Graph output.
Changed
- Replaced the thin-router model with focused workflow entrypoints. Ordered procedures, completion criteria, and short command examples are valid in
SKILL.md; progressive disclosure is reviewed by semantic destination. - Changed Skill body advisories to low above 2,000 and medium above 5,000 estimated tokens. Changed content advisories to Context 4,000, Reference 5,000, Profile 2,000, and Example 2,500 estimated tokens.
- Changed metadata advisories to 48 frontmatter lines, 4,096 frontmatter characters, and 256 characters per prose-like list item, with practical exemptions for IDs, repository paths, and URLs.
- Changed reusable Context eligibility to 60 lines or 800 estimated tokens plus four reusable signals. Changed shared-reference eligibility to 80 lines or 1,200 estimated tokens plus three reusable headings and four reusable phrases. Ordinary workflow headings and constraint words do not qualify.
- Changed repeated headings to require three files and token shingles to 40 estimated tokens in three files. Exact-section, exact-code, and per-category caps retain their established defaults.
- Changed Readiness to
workflow.skills_focused, removed the five-point existence penalty for deprecated/archived assets, and reduced subjective workflow advisory weights while preserving blocking graph and diagnostic failures. - Deprecated
metadata.renma.when-to-useandmetadata.renma.when-not-to-usefor new Skill authoring. They remain recognized for governance and migration preservation; portabledescriptionis the Skill discovery source of truth.
Fixed
- Stopped overcounting Japanese one character at a time in quality rules and undercounting unspaced Japanese as one token in repeated-context analysis.
- Stopped decoding images, PDFs, fonts, and other opaque assets as UTF-8 Markdown or exposing binary bytes in diagnostic snippets.
- Stopped non-Markdown text scripts and assets from contributing frontmatter, headings, links, fences, or repeated-context evidence.
- Fixed nearest-Skill support ownership, nested Skill boundaries, explicit path reachability, extensionless and spaced paths, and oversized-file existence evidence.
- Prevented script and asset bytes from declaring policy. Skill-local scripts and assets inherit the nearest unambiguous Skill policy for inventory and provenance reporting, while binary files and ordinary output assets stay opaque.
- Rejected files reached through leaf or ancestor symbolic links, including Skill-local directory links that point elsewhere inside or outside the repository.
- Added explicit local, inherited, effective, and missing-effective policy inventory provenance for non-Markdown scripts without interpreting script bytes as security policy metadata.
- Added balanced-parenthesis Markdown destination parsing and single-pass decoding for encoded filename characters.
- Stopped treating a command, Procedure/Steps/Setup headings, ordered workflow wording, or 450/700-word counts as evidence of a bad Skill.
- Stopped recommending Context Assets as the default destination for Skill-specific procedures, variants, edge cases, scripts, and output resources.
- Stopped repeated links to the same specification or source from producing maintenance findings by default.
Removed
- Removed default emission of
QUAL-SHORT-DESCRIPTION,LAYOUT-SKILL-NOT-THIN,LAYOUT-SKILL-EXECUTABLE-COMMAND, andMAINT-REPEATED-LINK. - Removed the Readiness
layout.skills_thincontract and the unconditional lifecycle-status penalty.
Compatibility
- No public quality-threshold configuration was added to
renma.config.json. The versioned internal profile is shaped for possible later overrides after usage evidence. ArtifactKind, catalog entries, graph nodes, Trust Graph asset properties, and Repository Context BOM assets addscript/assetand binary-safety evidence. Consumers that exhaustively match kinds or exact-normalize these schemas must update for 0.18.0.- Scaffold file, prompt, and JSON contracts add selected resource directories; existing invocations without
--resourcescreate no extra directories. - Agent Skills specification errors remain separate from Renma advisories:
descriptionis required, a string, and 1-1,024 characters; 150 characters is not an Agent Skills minimum.
Migration
LAYOUT-SKILL-NOT-THIN->QUAL-SKILL-MIXED-RESPONSIBILITYwhen reusable knowledge evidence exists, otherwise no finding.LAYOUT-SKILL-EXECUTABLE-COMMAND-> no layout finding; security, unresolved-helper, path-escape, and large-inline-implementation checks remain.QUAL-SHORT-DESCRIPTION-> Agent Skills description validity plusRN-SKILL-DESCRIPTION-MISSING-CAPABILITY,RN-SKILL-DESCRIPTION-MISSING-USAGE-BOUNDARY, andRN-SKILL-DESCRIPTION-OMITS-SELECTION-BOUNDARYwhere applicable.MAINT-REPEATED-LINK-> no maintenance finding by default.- Readiness
layout.skills_thin->workflow.skills_focused. - Rebaseline exact catalog, graph, Trust Graph, BOM, Readiness, scaffold JSON, and package-content fixtures against the 0.18.0 schemas before release.
0.17.0 - 2026-07-11
Added
- Added platform-neutral, Skill-specific next steps to scaffold file and prompt output, including the authoring-review, scan, fix, rerun, and human-review loop.
- Added Skill-specific
suggest-metadataprompt guidance that separates whole-Skill authoring review from metadata or one-way migration suggestions and keeps blocked migrations conservative. - Added a documentation index with reading paths for workflows, format contracts, governance references, product design, architecture, and roadmap material.
- Added the interactive-placeholder onboarding example and package-content verification for version-matched README documentation and examples.
Changed
- Clarified that platform-native guidance owns general Skill design while Renma complements it with repository-specific governance and validation.
- Consolidated the README around product identity, boundaries, primary workflows, quick start, command orientation, a canonical example, and documentation navigation.
- Made the authoring guide the canonical new-Skill and existing-Skill workflow, including safe generator boundaries and an optional Codex
skill-creatorexample. - Reworked the user manual and compatibility guide around actual CLI behavior, review responsibilities, scan/fix/rerun validation, and blocked migration recovery.
- Rewrote the roadmap around the shipped 0.16.0 baseline, the 0.17.0 usability release, and proposed 0.18.0 graph-based Skill discovery; removed stale release sequencing from architecture and design.
- Made canonical nested Skills under both
skills/**and.agents/skills/**participate consistently in Readiness, thin-Skill, graph, support, and parent-Skill checks. - Allowed valid Skill-local Agent Skills support directories without path-only disallowed-layout findings; reusable Context and shared-helper promotion remains evidence-based and human-reviewed.
- Normalized expected CLI target and option errors, enforced command-specific options and positional arity, and rejected partial positive-integer values.
- Retained
layout.tool_namespaceandlayout.workflow_aliasesas validated compatibility-only input; they no longer force path-only migration of valid Skill-local support.
Fixed
- Corrected Readiness false-positive
readyresults for nested Skills with missing workflow guidance. - Updated the Context Lens example to current 0.17.0 quality with conservative local policy, complete workflow guidance, and clean scan/readiness output.
- Included README-linked architecture, design, roadmap, documentation, and examples in the npm package.
- Stopped treating documented Skill-local support paths as stale and resolved
scripts/**helper commands against an unambiguous owning Skill using repository snapshot evidence.
Compatibility
- Preserved scaffold and
suggest-metadataJSON field shapes, stdout-only prompt behavior, and non-editing metadata suggestions. - Kept Skill-specific guidance out of Context Asset and Context Lens scaffold and suggestion output.
0.16.0 - 2026-07-11
Added
- Added Agent Skills specification validation to
scan, including stable diagnostics for entrypoint naming, frontmatter, metadata, and body requirements. - Added deterministic migration assistance to
suggest-metadatafor pre-0.16 Skill entrypoints and metadata, with conflict detection and canonical candidate validation. - Added comprehensive Agent Skills compatibility and migration documentation, canonical authoring guidance, and a Context Lens example for boundary-value spec review.
Changed
- Required operational Skills to use specification-valid Agent Skills frontmatter with Renma extensions under flat, string-valued
metadata.renma.*keys. - Updated catalog, graph, ownership, readiness, BOM, security, scaffold, and reporting consumers to use canonical Skill metadata while retaining legacy forms only as migration input.
- Expanded the README, architecture, design, user manual, security guidance, and example repository for the 0.16.0 Skill format and repository model.
Fixed
- Corrected the repository-owned release-prep Skill syntax and kept its operational workflow in the required release context.
0.15.2 - 2026-07-10
Added
- Added an authoritative Repository Context BOM v1 contract document covering schema compatibility, snapshot consistency, reproducibility, provenance, and future consumed-context evidence boundaries.
- Added a normalized BOM v1 contract-shape test that pins stable JSON fields, nested shapes, deterministic ordering, and scope declarations.
Changed
- Hardened
renma bomso graph, readiness, diagnostics, Context Lens evidence, security posture, and security policy inventory are derived from the same collected repository snapshot as catalog assets. - Captured referenced helper and dependency path existence in
RepositorySnapshotso snapshot-derived BOM and scan reports do not query the live filesystem during rule evaluation. - Clarified
--omit-generated-atas a same-environment reproducibility option that removes only the run-timegeneratedAtfield and does not normalize freshness metadata, absolute paths, file moves, UTC evaluation date changes, or cross-runner portability.
0.15.1 - 2026-07-10
Added
- Added command-specific CLI help for every command, including purpose, use cases, boundaries, examples, next steps, and relevant options for human and coding-agent workflows.
Changed
- Expanded top-level CLI help with Renma's deterministic governance boundaries, start-here workflows, and command-selection questions.
- Clarified command-specific option help with accepted output formats, defaults, owner behavior, scaffold output modes, and BOM timestamp/path boundaries.
- Improved CLI usage errors to point to the relevant command help page where applicable.
0.15.0 - 2026-07-09
Added
- Added
renma bomfor a declared Repository Context BOM that combines catalog assets, graph dependency resolution, readiness evidence, diagnostics, security posture, and security policy inventory. - Added JSON and Markdown BOM output with explicit scope metadata stating that runtime usage is false and telemetry is not collected.
- Added
renma bom --omit-generated-atfor BOM artifacts that omit run-time generation timestamps.
Changed
- Reused one shared repository evidence snapshot for BOM catalog assets and graph dependencies.
- Escaped repository-derived BOM Markdown table cells for safer PR-friendly output.
0.14.1 - 2026-07-08
Added
- Added repository configuration for Renma's own release and governance checks.
Changed
- Improved diagnostic messages, docs, and examples for discovery and security policy guidance.
0.14.0 - 2026-07-08
Added
- Added
renma trust-graphfor deterministic Trust Graph evidence over catalog, dependency, owner, lifecycle, security policy, and diagnostic signals. - Added
trustGraphto JSON scan output for downstream CI and tooling consumers.
0.13.2 - 2026-07-08
Added
- Added
renma suggest-metadatafor deterministic metadata retrofit prompts and JSON payloads for existing assets. - Added documentation and tests for safe metadata retrofit workflows, including explicit owner handling and preservation of existing asset content.
0.13.1 - 2026-07-08
Added
- Added owner-grouped ownership reports and
renma ownership --owner <owner>filtering for owner-specific JSON and Markdown output.
Changed
- Clarified ownership policy so missing
ownermetadata is accepted as unowned coverage information instead of becoming a default scan finding.
0.13.0 - 2026-07-07
Added
- Added LLM-actionable diagnostics v2 in scan JSON output with typed
repairConstraints, structuredverificationSteps, concisellmHintguidance, stable codes, and source locations. - Added deterministic review bundles that group related diagnostics by duplicate IDs, unresolved references, orphaned context assets, and shared dependency/reference sources.
- Added documentation and tests for v2 diagnostic metadata, review bundles, suppression handling, and compatibility with existing scan findings.
0.12.0 - 2026-07-07
Added
- Added deterministic Context Lens governance summaries for scan, catalog JSON, readiness, and inspect output.
- Added stable coded Context Lens diagnostics for missing required fields, duplicate IDs, unresolved targets, path normalization mismatches, unsupported kind/scope/version values, empty or governance-meaningless definitions, malformed frontmatter, and deprecated field aliases.
- Added readiness integration with a
context_lens.governancecheck and additivesummary.contextLensJSON output. - Added inspect output that reports Context Lens detected state, lens counts, diagnostic counts, representative diagnostic code, definition paths, and target references.
- Added Context Lens authoring examples, CI guidance, invalid diagnostic examples, and a multi-lens fixture.
Changed
- Stabilized Context Lens as deterministic repository governance: Renma verifies declared lens definitions and relationships without runtime selection, prompt assembly, context injection, external tool signal imports, or automatic LLM judgment.
0.11.1 - 2026-07-06
Added
- Added
renma graph --view layeredfor Mermaid graph output that groups skills, context lenses, contexts, support assets, and unresolved targets into readable layers. - Added
renma graph --view lensas an alias for the layered context-lens graph view.
Changed
- Focused graph output for context lenses now clearly preserves inbound skill lens references and outbound
applies_tocontext edges in the layered view.
0.11.0 - 2026-07-05
Added
- Added experimental
context_lensassets, including defaultlenses/**/*.mddiscovery, cataloging, graph edges, and authoring docs. - Added
requires_lens,optional_lens, andapplies_tometadata relationships for static skill-to-lens-to-context graphs. - Added
inspectandscaffold context_lenssupport for lens metadata, relationships, and deterministic starter files. - Added context lens diagnostics for missing purpose or
applies_tometadata, orphaned active lenses, and active lenses that apply to inactive contexts.
Changed
- Updated docs and examples for the context lens model, including clearer boundaries around runtime selection, prompt assembly, and context injection.
0.10.0 - 2026-07-05
Added
- Added metadata budget diagnostics for oversized frontmatter and long metadata list items.
- Added shared context usage-boundary diagnostics for missing or placeholder
when_to_useandwhen_not_to_usemetadata. - Added shared context language diagnostics for vague wording, relative currentness wording, and prompt/runtime-selection wording.
- Added shared context lifecycle diagnostics for deprecated assets, invalid
superseded_bytargets, and supersession cycles. - Added context conflict graph diagnostics for invalid
conflictsmetadata and skills that require conflicting contexts.
Changed
- Simplified security policy frontmatter handling around canonical snake_case metadata keys.
- Expanded diagnostics documentation for metadata budgets and shared context governance checks.
0.9.0 - 2026-07-03
Added
- Added security posture summaries to readiness and CI reports, derived from existing security findings and
riskClassmetadata. - Added effective security policy inventory summaries for readiness and CI reporting, derived from asset policy metadata, security profiles, and repository security config.
- Added security-aware semantic diff summaries that compare security finding posture and effective policy inventory across revisions.
Changed
- Kept security posture reporting non-gating in v1; readiness score, readiness level, scan
fail_on, and CI status semantics remain unchanged. - Kept policy inventory reporting non-gating in v1; scan
fail_on, readiness score/level, and CI status semantics remain unchanged. - Kept security-aware diff reporting non-gating in v1; scan
fail_on, readiness score/level, and CI status semantics remain unchanged.
0.8.1 - 2026-07-03
Added
- Added a GitHub Actions workflow that publishes the npm package from version tags via npm trusted publishing.
0.8.0 - 2026-07-03
Added
- Added
riskClassto security scan findings so reviewers can distinguishviolation,suspicious, andadvisoryresults without changing severity thresholds. - Added scan review signal docs and security policy taxonomy guidance for
severity,confidence, andriskClass.
Changed
- Surfaced risk classes in text scan output, readiness reports, semantic diffs, and CI reports.
- Added npm version and download badges to the README.
Fixed
- Made semantic diff cleanup preserve primary snapshot errors while retrying temporary directory removal.
0.7.0 - 2026-07-02
Changed
- Refined deterministic security diagnostics for agent-facing context assets without adding package or CI workflow scanning.
- Reduced false positives for guarded or defensive security guidance around destructive commands, privileged commands, remote script execution, unpinned installs, and external uploads.
- Clarified the 0.7.0-and-later roadmap: security diagnostics stabilization first, security posture summaries next, Trust Graph as deterministic repository evidence, and Repository Context BOM as a declared manifest rather than runtime usage telemetry.
- Added a user-manual quickstart for security policy metadata and reusable security profiles.
- Expanded the user manual with metadata authoring guidance, security policy examples, reusable security profile guidance, and common security diagnostic fixes for the 0.7.0 line.
- Added a first-skill authoring walkthrough that shows how to use scaffold, inspect, scan, graph, readiness, and LLM-assisted repair loops to create and refine skills.
- Added guidance for deriving related router skills from existing skills, including an Appium setup example.
- Split the expanded user manual into focused authoring and security policy guides while keeping the user manual as the CLI entrypoint.
0.6.1 - 2026-06-29
Changed
- Updated the release-prep workflow to allow local version commits and annotated tags when release finalization is requested.
- Moved release-prep validation mechanics into a deterministic tool script to reduce skill/context token usage.
0.6.0 - 2026-06-29
Added
- Added freshness diagnostics for context assets.
- Added suppressions for managing accepted diagnostics.
- Added the project changelog to document release history.
- Added a release-prep skill and context asset that dogfood Renma reports during release preparation.
Changed
- Centralized diagnostic IDs in one module.
- Simplified the example spec and improved example README documentation.
- Updated package metadata so published packages include the changelog, license, and README.
- Clarified README layout and redaction wording so Renma's own scan reports stay clean.
0.5.1 - 2026-06-27
Changed
- Modified README documentation.
- Included minor maintenance updates after the
0.5.0release.
0.5.0 - 2026-06-26
Added
- Added a bundled example context repository.
- Added field-level metadata and dependency evidence.
- Added command documentation guardrails to keep user-facing CLI docs aligned with implementation.
- Added smoke coverage for the example repository.
Changed
- Improved CI report output.
- Linked the example repository from README and the User Manual.
- Expanded documentation and test coverage for the new example, metadata behavior, and docs synchronization.
0.4.0 - 2026-06-25
Added
- Added scaffolding support for new context repository assets.
- Added focused graph views.
- Added scaffold output modes for file, prompt, and JSON output.
Changed
- Improved metadata parsing for deterministic block-list fields.
- Required explicit owners for file scaffolding to avoid committing placeholder ownership.
0.3.0 - 2026-06-24
Added
- Added security policy diagnostics and related configuration enhancements.
- Added checks for approved domains, disallowed commands, and contradictory policy guidance.
- Added security profiles in
renma.config.json. - Added simple block-list parsing for selected security policy fields.
Changed
- Updated project planning documentation for the security policy work.
- Kept artifact-local explicit denials stricter than inherited repository or profile allowances.
0.2.0 - 2026-06-23
Added
- Added repeated-context diagnostics.
- Added semantic diff reporting.
- Added CI report generation.
- Added a GitHub Actions example for generating and uploading a Renma CI report.
Changed
- Updated planning documentation for security-related work.
0.1.1 - 2026-06-22
Tag-only release. No GitHub Release entry was published for this version.
Changed
- Polished README and documentation.
- Updated package metadata for the early npm package release.
0.1.0 - 2026-06-22
Added
- Added the initial Renma CLI for scanning agent-facing context repositories.
- Added catalog, ownership, graph, readiness, and reporting commands.
- Added workflow diagnostics for clarity, required inputs, completion criteria, optional context, and summaries.
- Added metadata governance, advisory diagnostics, local path checks, and semantic split suggestions.
- Added the initial project documentation, architecture notes, package metadata, tests, and license.