This release includes breaking changes for platform teams planning a safe upgrade.
✓ No known CVEs patched in this version
Topics
+12 more
Affected surfaces
Summary
AI summaryFixed Alembic migration detection and Prisma schema change nudging, corrected Redux slice over‑matching, improved coordinator monorepo onboarding.
Full changelog
Whole-plugin QA across every supported framework (Rails, Django, DRF, Flask,
FastAPI, Next.js, NestJS) and the standalone components (daemon, MCP stdio,
statusline, merge driver). Framework detection, framework-aware guidance,
bootstrap, and the enforcement/hook stack all verified correct on the released
build; the co-change advisory rules had three framework gaps, now fixed.
Fixed
- Alembic migrations weren't recognized by the model-migration co-change rule.
_is_django_migrationmatched only/migrations/, so on any FastAPI/SQLAlchemy
repo (Alembic's standardalembic/versions/layout) the rule silently
auto-disabled and a new model without a migration was never nudged — despite the
message advertising "SQLAlchemy: add the Alembic revision". Now mirrors the
archetype layer's alembic-aware classifier. cochange-prisma-migrationcould never fire. A.prismafile resolves to
languageNoneand was skipped before rule matching; the 8-file trigger floor
also disabled it (Prisma repos have oneschema.prisma); and the schema change
is an edit, not a new file. Now recognizes.prismaas a TS-ecosystem artifact,
supports a per-rule trigger floor (1 for Prisma), and fires opt-in rules on an
edit — so editingschema.prismawithout a migration is nudged._is_redux_sliceover-matched.'slice' in namefalse-fired
cochange-slice-storeonimageSlicer.ts/pizzaSlices.ts/backslice.ts;
tightened to the Redux ToolkitfooSlice.tsconvention (capital-S suffix token).- Coordinator-monorepo onboarding. A pnpm/turbo/nx root with no first-class
source bootstraps its workspaces but writes no root profile
(status: "success_workspaces_only"), so/chameleon-trustat the root failed
with a contradictory "run /chameleon-init first".trust_profilenow detects a
coordinator root and points the user at the bootstrapped workspaces, and the
init skill documents the per-workspace trust flow and the coordinator-root
turn-end limitation.
Known limitations (scoped follow-ups)
- The turn-end Stop safety net does not run for a pure-coordinator monorepo root
(Claude Code's cwd is the profile-less root); per-edit guidance still works. - A cross-workspace existence break (a removed export imported only across a
workspace boundary) is not flagged, because per-workspace reverse indexes don't
record sibling-workspace importers.
Weekly OSS security release digest.
The CVE patches and breaking changes that affected production tools this week. One email, every Sunday.
No spam, unsubscribe anytime.
Share this release
About Chameleon
All releases →Beta — feedback welcome: [email protected]