This release includes breaking changes for platform teams planning a safe upgrade.
✓ No known CVEs patched in this version
Topics
+2 more
Summary
AI summaryFixed detection and wiring issues making digital-health-pack functional.
Changes in this release
| Type | Severity | Summary | CVE |
|---|---|---|---|
| Bugfix | Medium |
Fixes detection bug for digital-health-pack in README keyword mining. Fixes detection bug for digital-health-pack in README keyword mining. Source: llm_adapter@2026-05-29 Confidence: high |
— |
| Bugfix | Medium |
Registers five missing gates for digital-health-pack in ARCHETYPES.md. Registers five missing gates for digital-health-pack in ARCHETYPES.md. Source: llm_adapter@2026-05-29 Confidence: high |
— |
| Bugfix | Medium |
Adds missing HANDOFF block and applies_to metadata to digital-health-reviewer. Adds missing HANDOFF block and applies_to metadata to digital-health-reviewer. Source: llm_adapter@2026-05-29 Confidence: high |
— |
| Bugfix | Medium |
Adds e2e fixture digital-health-wearable and removes pack from exception allowlist. Adds e2e fixture digital-health-wearable and removes pack from exception allowlist. Source: llm_adapter@2026-05-29 Confidence: high |
— |
| Bugfix | Medium |
Introduces new threat‑model template TM-digital-health.md. Introduces new threat‑model template TM-digital-health.md. Source: llm_adapter@2026-05-29 Confidence: low |
— |
| Bugfix | Medium |
Adds EVAL files for HITL boundary, supplement safety, and mental‑health crisis scenarios. Adds EVAL files for HITL boundary, supplement safety, and mental‑health crisis scenarios. Source: llm_adapter@2026-05-29 Confidence: low |
— |
Full changelog
Fixed: digital-health-pack was non-functional + fully wired it
digital-health-pack (Wave 4) was registered in the pack registry but only
half-wired, so it could never actually auto-attach:
- Detection bug (user-facing):
detect.tsmineReadmeKeywordsonly emitted
Wave 1-3 pack-trigger terms, so none of digital-health's keywords (wearable,
HRV, HealthKit, mental health, supplement AI, physician HITL, RPM, …) were
ever surfaced — the pack was undetectable from any README. Added all Wave 4
terms, kept in sync withpacks.tsSIGNALS.keywords. - Gates: registered the 5 pack gates (
gate:wellness-vs-samd,
gate:hitl-design,gate:wearable-api-access,gate:supplement-safety,
gate:mental-health-protocol) inARCHETYPES.mdDomain Overlays + the
human-gate summary (corrected the stale "13 gates / Wave 1-3" labels). - Reviewers: added the missing
<!-- HANDOFF -->block to
digital-health-reviewer; addedapplies_to+ HANDOFF to
healthcare-reviewer. - Threat model: new
TM-digital-health.mdtemplate. - EVAL: added
EVAL-digital-health-hitl-boundary,
EVAL-digital-health-supplement-safety,
EVAL-digital-health-mental-health-crisis. - Test coverage: new
digital-health-wearablee2e fixture; removed the
pack from the packs-e2e documented-exception allowlist. Every registered
pack now has a fixture (11/11), packs-e2e 531/531 assertions pass.
Weekly OSS security release digest.
The CVE patches and breaking changes that affected production tools this week. One email, every Sunday.
No spam, unsubscribe anytime.
Share this release
About great_cto
Engineering-management layer of 34 specialist AI agents covering the full SDLC (architect, PM, senior-dev, reviewer, QA, security, devops, L3-support + 18 archetype-specific reviewers) with auto-detected archetypes and compliance gates (PCI-DSS, HIPAA, FedRAMP, GDPR, EU AI Act). Runs in Claude Code, Cursor, Codex CLI, Aider, and Continue via AGENTS.md + MCP. MIT.
Related context
Related tools
Earlier breaking changes
- v2.32.0 Removed AgentShield scanner and its CLI commands.
Beta — feedback welcome: [email protected]