This release fixes issues for SREs watching stability and regressions.
Published 1mo
Developer Productivity
✓ No known CVEs patched
✓ No known CVEs patched in this version
Topics
ai-coding-assistant
archetype
ast-analysis
claude-code
claude-plugin
code-conventions
+12 more
code-review
code-style
developer-tools
javascript
linter
mcp
mcp-server
prompt-engineering
python
ruby
rails
typescript
Affected surfaces
auth
Summary
AI summaryFixed multiple bugs affecting archetype renaming, JSON parsing, cluster witness wording, and empty file handling.
Full changelog
Four advisory/quality bugs found in an adversarial bug-hunt across TypeScript,
Ruby, and Python and their frameworks. None changes default-on block behavior.
Fixed
- Archetype renames rekey every conventions section.
apply_archetype_renames
rewrote only 6 of the 13 per-archetypeconventions.jsonsections, leaving
required_guards,test_pairing,error_handling,import_ordering,
body_shape,doc_coverage, andcallable_signaturesunder the OLD archetype
key after a rename. The per-edit hot path looks each up by the new name with no
alias, so the required-guards authz hint and the paired-test reminder were
silently dropped for every renamed archetype -- and renaming is the default init
step. The rekey now iterates all sections except a repo-level denylist
(REPO_LEVEL_CONVENTION_SECTIONS), so a future per-archetype section cannot
regress the same way. get_drift_statusfails open on a non-dict profile.json. A top-level JSON
array parsed past the existingexcept (OSError, ValueError)and the following
.get()raisedAttributeError, crashing a model-callable read tool instead of
failing open. The parse is now guarded with anisinstance(..., dict)check.- A
cluster-*grab-bag no longer says "mirror closely". An unnamed
cluster-*archetype has no single role, so its canonical witness can be
cross-role (an alembic migration served for a security module). The per-edit
lead now downgrades such a witness to a loose reference; named archetypes keep
the strong "mirror closely" lead. - Empty files are excluded from canonical selection. An empty/whitespace-only
file (a bare__init__.py) could be picked as a witness, and an all-empty
cluster picked a blank witness that then merged into a real archetype's
sub-buckets. Such files are now excluded from the canonical pool (an all-empty
cluster reports no clean canonical, like an all-generated one); files with real
content, including thin barrel re-exports, are unaffected.
Weekly OSS security release digest.
The CVE patches and breaking changes that affected production tools this week. One email, every Sunday.
No spam, unsubscribe anytime.
Share this release
About Chameleon
All releases →Beta — feedback welcome: [email protected]