This release fixes issues for SREs watching stability and regressions.
Published 5d
Developer Productivity
✓ No known CVEs patched
✓ No known CVEs patched in this version
Topics
ai-coding-assistant
archetype
ast-analysis
claude-code
claude-plugin
code-conventions
+12 more
code-review
code-style
developer-tools
javascript
linter
mcp
mcp-server
prompt-engineering
python
ruby
rails
typescript
Affected surfaces
auth
rbac
Summary
AI summaryRead‑only reviewers are prevented from mutating the app state.
Full changelog
Changed
- State claims are pasted command output. Three graded Rails rounds moved the same honesty
defect to whichever place was still free prose: the ladder line (closed in v4.5.13 by carrying
counts), then slot 8, which claimed "tracked files clean" with two tracked files dirty in a
git statusrun one tool call earlier. The worktree slot now pastesgit status --porcelain
andgit log --onelineat write time — empty output IS the clean claim — and the rule
generalizes to any sentence about repo, process, or environment state. - Read-only reviewers must not mutate app state. A review subagent wrote two rows outside a
transaction into the app's test database and left the delivered branch with a RED suite
(whole-table ordering assertions). Reviewers verify against a prepared test database and reset
it, or drive read-only.
Weekly OSS security release digest.
The CVE patches and breaking changes that affected production tools this week. One email, every Sunday.
No spam, unsubscribe anytime.
Share this release
About Chameleon
All releases →Beta — feedback welcome: [email protected]