This release includes 1 breaking change for platform teams planning a safe upgrade.
✓ No known CVEs patched in this version
Topics
+14 more
Affected surfaces
Summary
AI summaryClose behavior now distinguishes cited references from actual deliveries.
Full changelog
The gate treated every PR number in a close as a delivery claim, so a review/triage/audit close that merely CITED another task's PR was judged against it. Default is now CITED: delivery must come from delivery_ref, a Branch: line, a Delivered: line, or a shipping verb adjacent to the ref ('merged as PR #6', 'landed in #13'); negations rejected. A cited ref is not resolved, not refused, not stamped.
The asymmetry is deliberate and the cheap side is ANNOUNCED — the close warns which refs were set aside, names both escapes, and emits a task.merge-gate-reported-on audit row; citations are skipped BEFORE the 5-ref cap so they cannot crowd out the real delivery. Pinned invariant: a close naming its own merged+green delivery plus two cited OPEN PRs closes clean, unrefused AND unstamped.
Breaking Changes
- Changed default close logic: cited PR numbers are no longer treated as delivery claims; delivery must originate from delivery_ref, Branch:, Delivered:, or a shipping verb adjacent to the ref. Negations are rejected.
Weekly OSS security release digest.
The CVE patches and breaking changes that affected production tools this week. One email, every Sunday.
No spam, unsubscribe anytime.
Share this release
About 5dive
All releases →Related context
Related tools
Earlier breaking changes
- v0.11.22 council amend now requires constitutional-class motion for constitution changes
- v0.11.9 CLI now only OFFERS a veto to the genesis principal; EXERCISE requires authenticated tap.
- v0.11.5 Raw bench add/rm of the primary council is refused.
- v0.11.5 `council init` now requires sudo and seeds the primary council bench.
- v0.10.7 Changes delegated-push grant to be BUILDER-SCOPED, limiting push permissions.
Beta — feedback welcome: [email protected]