Skip to content

Release history

Chameleon releases

All releases

166 shown

No immediate action
v4.5.16 New feature

Superpowers contract injection + subagent archetypes

No immediate action
v4.5.15 New feature

Chameleon + superpowers composition

Review required
v4.5.14 Bug fix
Auth RBAC

Read‑only reviewer enforcement

No immediate action
v4.5.13 Breaking risk

Plan step verification changes

v4.5.12 Breaking risk
Breaking changes
  • Changed behavior of "all/every/throughout" claim qualifiers to count from session records at write time instead of full aggregates.
Full changelog

Changed

  • deep-work universal claims are transcriptions. The Rails graded round implemented
    flawlessly and still dropped two dimensions to the same class: "read all 39 files" over a
    transcript showing 24, and "ast/exact throughout" over one fallback injection. Any
    "all/every/throughout" in the brief or report must be counted from the session record at
    write time or weakened to the honest subset — the fates-line discipline, generalized to
    every aggregate claim, in both completeness passes.
No immediate action
v4.5.11 Bug fix

False‑positive fixes

No immediate action
v4.5.10 Bug fix

Ruby string advisory fix

No immediate action
v4.5.9 Bug fix

Init non‑interactive fallback

Review required
v4.5.8 Bug fix
Auth Dependencies

Trust fix + fixture detection

No immediate action
v4.5.7 New feature

Proactive deep-work follow-ups

No immediate action
v4.5.6 New feature

Fixed 9-slot brief template

No immediate action
v4.5.5 Breaking risk

Fixed 8-slot deep-work template

No immediate action
v4.5.4 Breaking risk

Checklist updates

No immediate action
v4.5.3 Bug fix

deep-work behavior changes

No immediate action
v4.5.2 Bug fix

Constant path extraction fix

No immediate action
v4.4.55 Bug fix

ESLint flat-config parse fix

No immediate action
v4.4.54 Bug fix

RSpec spec witness fix

Config change
v4.4.53 Bug fix
Auth

/chameleon-journey confirmation fix

No immediate action
v4.4.51 Bug fix

Bash exit status fix

No immediate action
v4.4.52 Bug fix

Cohort name fix

No immediate action
v4.4.50 Bug fix

Malformed .eslintrc.json handling

No immediate action
v4.4.49 Bug fix

Inheritance lint fix

No immediate action
v4.4.48 Bug fix

Skill description update

No immediate action
v4.4.47 Bug fix

"One action, one job" gate fix

Review required
v4.4.46 Bug fix
Dependencies

False audit all-clear fix

No immediate action
v4.4.45 Bug fix

TEST_PAIRING_MIN_SAMPLE lowered

No immediate action
v4.4.44 Bug fix

Fixes src-layout collapse

No immediate action
v4.4.38 Bug fix

Fix controller DSL extraction

No immediate action
v4.4.37 Bug fix

Subscripted generics inheritance fix

No immediate action
v4.4.36 Bug fix

Generic base class normalization fix

No immediate action
v4.4.35 Bug fix

Torn-config repair banner fix

No immediate action
v4.4.34 Bug fix

NestJS naming + Python lint fix

Upgrade now
v4.4.33 Bug fix
RCE / SSRF

Fix raw_sql_concat interpolation handling

No immediate action
v4.4.32 Bug fix

Test function reuse nudge fix

Review required
v4.4.22 Bug fix
Auth RBAC

Glob parsing fix

No immediate action
v4.4.15 Bug fix

Auto-pass router fix

Review required
v4.4.14 Bug fix
Auth

Auth error parsing + auto‑pass fix

No immediate action
v4.4.13 Bug fix

Fixes version‑bump risk scoring

Review required
v4.4.12 Bug fix
Auth

Auth-loss probe fix

No immediate action
v4.4.11 Bug fix

False‑positive lint fixes

No immediate action
v4.4.10 Bug fix

Same‑role inheritance fix

No immediate action
v4.4.8 Bug fix

Inheritance false positives

No immediate action
v4.4.7 Bug fix

Lint fixes + secret filter

No immediate action
v4.4.9 New feature

Missing‑required‑method advisory

No immediate action
v4.4.6 Bug fix

Diff‑scoped conformance lint

No immediate action
v4.4.5 New feature

Class-bound method reuse nudge

Review required
v4.4.4 Bug fix
Auth

Secret detector false‑positive fix

No immediate action
v4.4.3 Bug fix

Lint false positives fixed

No immediate action
v4.4.2 Breaking risk

False‑positive fixes

No immediate action
v4.4.1 Bug fix

Lint + prewrite dedup fixes

No immediate action
v4.4.0 New feature

`response_format`, pagination, wire‑size guard

No immediate action
v4.2.0 Bug fix

Redux-slice trigger doc fix

Config change
v4.1.2 Bug fix
Auth

Gate fix for orphaned trust grants

No immediate action
v4.1.1 Bug fix

Bootstrap cleanup + torn profile handling

No immediate action
v4.1.0 Breaking risk

Removed VERIFY engine; cleaned dead code

Upgrade now
v4.0.1 Breaking risk
Auth

Pause marker HMAC enforcement + index.db path keying

No immediate action
v4.0.0 Bug fix

Scope‑line extraction fix

Review required
v3.4.0 Breaking risk
Auth RBAC

Async turn‑end review + resurface fix

No immediate action
v3.3.0 Breaking risk

Pipeline rename + writers removal

Review required
v3.2.0 Breaking risk
Auth Breaking upgrade

Idiom structured store

No immediate action
v3.1.4 Bug fix

CI check fix

Review required
v3.1.3 Mixed
Auth RBAC

Trust bypass + render crash fixes

Upgrade now
v3.1.2 Breaking risk
Auth Breaking upgrade RCE / SSRF

Daemon trust‑revalidate fix

Review required
v3.1.1 Breaking risk
Auth RBAC

Wiring fixes + Stop gists + dedup

No immediate action
v3.1.0 Breaking risk

Prevents double conventions block

Config change
v3.0.3 Bug fix

Stop idiom review fixes

Upgrade now
v3.0.2 Bug fix
Auth RBAC RCE / SSRF +1 more

P1 bug fixes

Upgrade now
v3.0.1 Bug fix
Auth RBAC

Secret-handling fixes + module enhancements

v3.0.0 Breaking risk
⚠ Upgrade required
  • Refresh operation repairs missing .chameleon/conventions.md mirror after upgrades or profile changes.
  • Kill switch CHAMELEON_CONVENTIONS_MD=0 disables the conventions file generation.
  • Cache for interpreter resolution can be disabled with CHAMELEON_INTERP_CACHE=0.
Breaking changes
  • MCP surface reduced from 48 tools to 19; all non‑comprehension tools now accessed via three dispatchers (chameleon_lifecycle, chameleon_review, chameleon_telemetry) with renamed actions.
  • Repository restructured: marketplace source points at ./plugin directory only; tests/, docs/, and dev tooling are excluded from installed plugin bundles.
Notable features
  • .chameleon/conventions.md added as a CLAUDE.md-channel mirror for bootstrap/refresh/teach‑unteach operations.
  • Multi‑convention effectiveness campaign published with full study instrumentation and results.
  • SessionStart injection reorders to lead context; `// chameleon-ignore` now scoped to human‑approved exceptions.
Full changelog

Added (2026-07-11)

  • .chameleon/conventions.md — the CLAUDE.md-channel mirror. Bootstrap,
    refresh, and teach/unteach now maintain a rendered conventions file for the
    repo to wire into Claude's memory channel. Measured motive: the identical
    rules were followed 100% via this channel vs 40% as a hook advisory (see
    tests/effectiveness/results-published/migration-ab-2026-07-11.md).
    /chameleon-init offers three consent-gated wirings, none of which edit an
    existing file by default: a one-line .claude/rules/chameleon-conventions.md
    (auto-loads for the whole team), CLAUDE.local.md (personal), or a
    CLAUDE.md import on explicit preference. Kill switch
    CHAMELEON_CONVENTIONS_MD=0. A refresh repairs a missing mirror
    (_profile_needs_rederive), and any engine upgrade already forces the full
    re-derive that writes it — existing profiles gain the file on their first
    refresh after upgrading.
  • Multi-convention effectiveness campaign published (30 tasks x TS/Ruby/
    Python x 4 arms x 2 models, deterministic scorer, the repo's own
    cluster-bootstrap bar): chameleon 1.00 conformance on every task, every
    language, both models; bar MET vs no-plugin on both models; MET vs
    stale-CLAUDE.md on haiku; ceiling-tie vs perfectly-maintained CLAUDE.md.
    Instruments committed (tests/study_*.py); all results in
    tests/effectiveness/results-published/ (including the null dogfood
    retrospective and the unfavorable single-convention run, per policy).
  • Judge-panel calibration gate computed: kappa 1.000 on the 13-pair golden
    set (Fable-reference labels, provenance in
    tests/effectiveness/golden/LABELS_PROVENANCE.md — not human labels).

Changed (2026-07-11)

  • SessionStart injection reorders: the <chameleon-conventions> block now
    leads the context (before the skill text) and carries explicit
    anti-majority framing ("existing files may be mid-migration; never infer a
    convention from sibling-file majority against a rule here").
  • The // chameleon-ignore escape hatch is scoped to human-approved
    exceptions in both the import-preference deny reason and the
    using-chameleon skill: the model must not self-approve an override because
    existing files still use the blocked pattern.
  • pr-review gains a mechanical dependency demotion sweep before verdict
    rendering (a new-dependency's name alone can never be a BLOCK/FIX).

Fixed (2026-07-11)

  • Journey act 12b phase-41 checker read the raw stream-json transcript, so
    line-based assertions saw escaped \n — a structural false positive that
    failed the dependency-ACK check on every run. Both historical "failures"
    re-adjudicate as passes; live re-run green.

Breaking (v3)

  • MCP surface folded from 48 tools to 19. The 16 comprehension/conformance
    tools stay top-level (detect_repo, get_pattern_context, get_archetype,
    get_canonical_excerpt, get_rules, lint_file, search_codebase,
    describe_codebase, get_callers, get_callees, get_blast_radius,
    query_symbol_importers, get_crossfile_context, get_contract_breaks,
    get_duplication_candidates, explain_edit); the remaining 32 operator
    tools become actions on three dispatchers, called as
    <dispatcher>(action="<old tool name>", params={...original arguments, names and values unchanged...}):

    | Old top-level tool | New dispatcher / action |
    |---|---|
    | bootstrap_repo | chameleon_lifecycle(action="bootstrap_repo") |
    | refresh_repo | chameleon_lifecycle(action="refresh_repo") |
    | trust_profile | chameleon_lifecycle(action="trust_profile") |
    | list_profiles | chameleon_lifecycle(action="list_profiles") |
    | merge_profiles | chameleon_lifecycle(action="merge_profiles") |
    | teach_profile | chameleon_lifecycle(action="teach_profile") |
    | teach_profile_structured | chameleon_lifecycle(action="teach_profile_structured") |
    | teach_competing_import | chameleon_lifecycle(action="teach_competing_import") |
    | unteach_competing_import | chameleon_lifecycle(action="unteach_competing_import") |
    | propose_archetype_renames | chameleon_lifecycle(action="propose_archetype_renames") |
    | apply_archetype_renames | chameleon_lifecycle(action="apply_archetype_renames") |
    | disable_session | chameleon_lifecycle(action="disable_session") |
    | pause_session | chameleon_lifecycle(action="pause_session") |
    | get_autopass_verdict | chameleon_review(action="get_autopass_verdict") |
    | refute_finding | chameleon_review(action="refute_finding") |
    | record_review_verdict | chameleon_review(action="record_review_verdict") |
    | record_finding_fate | chameleon_review(action="record_finding_fate") |
    | get_review_history | chameleon_review(action="get_review_history") |
    | scan_dependency_changes | chameleon_review(action="scan_dependency_changes") |
    | dep_audit | chameleon_review(action="dep_audit") |
    | get_status | chameleon_telemetry(action="get_status") |
    | get_drift_status | chameleon_telemetry(action="get_drift_status") |
    | get_drift_antipatterns | chameleon_telemetry(action="get_drift_antipatterns") |
    | get_shadow_report | chameleon_telemetry(action="get_shadow_report") |
    | get_override_audit | chameleon_telemetry(action="get_override_audit") |
    | get_longitudinal_signals | chameleon_telemetry(action="get_longitudinal_signals") |
    | get_finding_fate_stats | chameleon_telemetry(action="get_finding_fate_stats") |
    | get_idiom_coverage | chameleon_telemetry(action="get_idiom_coverage") |
    | check_idiom_candidates | chameleon_telemetry(action="check_idiom_candidates") |
    | get_prose_rule_candidates | chameleon_telemetry(action="get_prose_rule_candidates") |
    | daemon_status | chameleon_telemetry(action="daemon_status") |
    | doctor | chameleon_telemetry(action="doctor") |

    Rationale: a context-lean tool surface — a session now loads 19 tool schemas
    instead of 48; the underlying Python functions keep their names and
    signatures, so direct imports (tests, QA batteries) are unaffected.

Changed

  • Repository restructured around an installable plugin/ dir. The
    marketplace source now points at ./plugin (plugin.json, .mcp.json, hooks/,
    skills/, agents/, bin/, mcp/, and the runtime scripts ts_dump.mjs,
    prism_dump.rb, libcst_dump.py, chameleon-merge-driver.sh, setup.sh), so a
    marketplace install copies only the runtime surface instead of the whole
    repo (previously ~4.9MB of tests/ and docs/ shipped with every install).
    tests/, docs/, and dev tooling (bump-version.sh, prune-plugin-cache.sh, ...)
    stay outside the installed plugin; the release tarball likewise now packs
    plugin/ + README/LICENSE/CHANGELOG only. No runtime behavior change —
    everything in-plugin resolves via CLAUDE_PLUGIN_ROOT as before.
  • Interpreter resolution is cached and the per-edit ladder is bounded. The
    resolved interpreter argv persists to a version-keyed cache (validated on
    read), and per-edit hooks cap the uv probe at 5s — bounded even where
    timeout(1) is absent (Git Bash, coreutils-less macOS), previously uncapped.
    Kill switch CHAMELEON_INTERP_CACHE=0.
  • pr-review skill split for progressive disclosure: a lean SKILL.md plus
    lazy references/*.md, and the fixed reviewer/scout roles are now packaged
    agents/ (chameleon:pattern-reviewer, code-scout, web-researcher).

Fixed

  • The daemon now starts under deep plugin-data paths. AF_UNIX caps
    sun_path at ~104 bytes, so a deep CHAMELEON_PLUGIN_DATA made every bind
    fail and the latency daemon silently never engaged (hooks fell back
    in-process forever). The socket moved to a short user-private
    <tmpdir>/chameleon-<uid>/d-<hash>.sock; pidfile and logs stay in the data
    dir.
  • Python test files no longer bucket into production role archetypes.
    python_role_for_path routed tests/api/routes/test_x.py to route, so the
    per-edit hook injected a production route canonical when editing a test; it now
    gates on the canonical test-path detector first.
  • Python linter config is read from sub-project dirs (a monorepo backend/ pyproject.toml), matching the TypeScript workspace-config fallback.
  • Skill-surface fixes: the refresh skill's re-lock call now passes the
    required path; receiving-code-review gained an argument-hint; the
    pr-review fan-out claim about reviewer tool grants is now an enforced in-agent
    directive rather than an unenforceable grant statement.
No immediate action
v2.69.0 Bug fix

Fixed journey-harness assertions

Review required
v2.68.0 Breaking risk
Breaking upgrade Auth

Linked worktree profile mapping fix

Review required
v2.67.0 Bug fix
Auth

SessionStart + archetype fixes

Review required
v2.59.0 Breaking risk
Auth RBAC

RECALL stage + adversarial verification

No immediate action
v2.58.0 Mixed

Ruff config handling + stale hint removal

No immediate action
v2.57.1 Bug fix

Repair stale schema indexes

Review required
v2.57.0 Breaking risk

VERIFY refutes findings

No immediate action
v2.56.1 New feature

README updates + proof number fix

No immediate action
v2.56.0 New feature

Expert hiring + worktree improvements

No immediate action
v2.55.0 New feature

/chameleon-deep-work skill

Review required
v2.54.0 Security relevant
Dependencies

Supply-chain scanner evasion closed

Review required
v2.53.0 Breaking risk
Auth RBAC

Dead code removal

No immediate action
v2.52.0 Breaking risk

Fixes removed‑export false positives

No immediate action
v2.51.0 Breaking risk

Absolute‑import check + Ruby search

Review required
v2.50.0 Breaking risk

Stale schema fixes

Review required
v2.49.0 Mixed
Auth RCE / SSRF

TypeScript DI call edges

No immediate action
v2.48.0 Breaking risk

Eight advisory gap fixes

Review required
v2.47.0 Breaking risk
Auth RBAC

Cross-workspace existence advisory

Config change
v2.46.0 Breaking risk
Breaking upgrade

Cross‑file existance BLOCK

Review required
v2.45.0 New feature
Auth RBAC

Surfaced‑finding ledger

Review required
v2.44.0 New feature
Auth RBAC

Session-governance signals

Review required
v2.43.0 New feature
Auth

Escalation tiering for judge and refuter

No immediate action
v2.42.0 New feature

Per-arm worker model + archetype_facts

No immediate action
v2.41.0 New feature

Barrel chase resolution

Review required
v2.40.0 New feature
Auth RBAC

Inbound caller‑contract injection

Review required
v2.39.1 Bug fix

Block count crash fix + budget unification

Review required
v2.39.0 New feature
Auth RBAC

Multi-root Stop backstop

Review required
v2.38.32 Security relevant
Auth

Credential deny enforcement + index reporting fix

Review required
v2.38.31 New feature
Auth RCE / SSRF

Timeout checks + MCP validation

No immediate action
v2.38.30 Bug fix

Advisory defect fixes

Review required
v2.38.28 Breaking risk
Breaking upgrade

Migration detection fixes + monorepo onboarding

No immediate action
v2.38.27 Bug fix

Non-string argument crash fixes

No immediate action
v2.38.22 Bug fix

Scoped idiom review + bugfixes

Review required
v2.38.21 Breaking risk

Monorepo workspace advisory fixes

Review required
v2.38.20 Breaking risk
Auth RBAC RCE / SSRF

Advisory fixes

Upgrade now
v2.38.19 Bug fix
Auth RBAC RCE / SSRF

Injection fixes

No immediate action
v2.38.18 Bug fix

Round‑3 refuter now emits verdicts

No immediate action
v2.38.17 Breaking risk

Three defect fixes

Review required
v2.38.15 Bug fix
Crypto / TLS Dependencies

Crypto gate + TS hash + install script + contract

Review required
v2.38.14 Breaking risk
Auth RBAC

Control‑byte injection fixes

No immediate action
v2.38.13 Bug fix

False positive import detection fix

No immediate action
v2.38.12 Bug fix

Stale-index fixes

No immediate action
v2.38.11 Bug fix

Duplication re‑flag fix

Upgrade now
v2.38.10 Security relevant
Auth RBAC

Canonical witness leak

No immediate action
v2.38.9 Breaking risk

Stale index fix + reviewer health

Upgrade now
v2.38.8 Breaking risk
Auth RCE / SSRF

PreToolUse bypass fix + edge hardening

Review required
v2.38.7 Bug fix
Dependencies

COMMITTED sentinel fix

Review required
v2.38.6 Bug fix
Auth

Next.js page/layout guidance

No immediate action
v2.38.5 Breaking risk

Critical bug fixes

No immediate action
v2.38.4 Breaking risk

NestJS controller advisory

Review required
v2.38.3 Bug fix
RCE / SSRF

Eval/exec detection fixes

No immediate action
v2.38.2 Bug fix

pr-review Sonnet fixes

No immediate action
v2.38.1 Bug fix

Repo‑relative file_path handling

No immediate action
v2.38.0 Mixed

pr-review enhancements + receiving-code-review checks

Review required
v2.37.0 New feature
Auth RCE / SSRF Dependencies +1 more

pr-review routing + adjudication grounding

No immediate action
v2.36.3 New feature

`scripts/setup.sh` addition

Review required
v2.36.2 Bug fix
Auth RBAC

Repair corrupted config files + fix Python extractor

No immediate action
v2.36.1 Maintenance

Routine maintenance and dependency updates.

No immediate action
v2.36.0 New feature

Conformance-comprehension profile + tools

No immediate action
v2.35.0 New feature

Nearby signatures default-on

Review required
v2.34.2 Bug fix
Auth

Gitignored file profiling fix

No immediate action
v2.34.1 Bug fix

paths_glob fix for Python 3.11

No immediate action
v2.34.0 Bug fix

Derivation‑pipeline bug fixes

Review required
v2.33.3 Bug fix
Auth

Fix inconsistent backstop arming

Upgrade now
v2.33.2 Security relevant
Auth RCE / SSRF

Fixes no_repo trust issue

Review required
v2.33.1 Bug fix
Auth

Non-code eval block fix

Config change
v2.33.0 Breaking risk
Breaking upgrade Auth

Default enforcement blocks

Review required
v2.32.3 Bug fix
Auth

Archetype rename + JSON parse fixes

No immediate action
v2.32.2 Bug fix

Archetype rename locking fix

No immediate action
v2.32.1 Bug fix

Lock block‑and‑retry

No immediate action
v2.32.0 Bug fix

Isolate build_candidate_index failure

Review required
v2.31.0 Breaking risk
Auth RBAC RCE / SSRF

Ruby blast radius + autopass fix

No immediate action
v2.30.0 Breaking risk

Telemetry fix + dup index bound + idioms order +

No immediate action
v2.29.2 Bug fix

Retry‑shortly on teach conflicts

Review required
v2.29.1 Security relevant
Auth

Identity‑reassignment detection

Review required
v2.29.0 Breaking risk
Auth RBAC

One-time trust + injection screening

No immediate action
v2.28.0 Maintenance

Language support documentation update

No immediate action
v2.27.0 New feature

Python parity features

No immediate action
v2.25.0 New feature

Off‑pattern counterexamples

No immediate action
v2.23.0 New feature

Match-quality calibrated witness

Review required
v2.22.5 Bug fix
Auth RCE / SSRF

Hardening fixes

Upgrade now
v2.22.4 Bug fix
Auth Breaking upgrade

Enforcement failure fix

No immediate action
v2.22.3 Bug fix

Worktree profile/trust resolution

Review required
v2.22.2 Breaking risk
Auth

doctor checks stop-backstop

Review required
v2.22.0 New feature
Auth Dependencies

Transitive caller impact

Review required
v2.21.0 New feature
Dependencies

Supply‑chain checks + contract diffs + definition hydration

Review required
v2.20.0 New feature
Auth RBAC

Degraded delivery + drift counterexamples

Review required
v2.19.0 Security relevant
RCE / SSRF

Security hardening

Review required
v2.18.0 Breaking risk
Auth Breaking upgrade

Python >=3.11 requirement for hooks

No immediate action
v2.17.0 New feature

Class contract extraction

No immediate action
v2.16.0 New feature

Three‑round grounding loop with refuter

No immediate action
v2.15.1 New feature

Defect checklist for correctness reviewer

Review required
v2.14.1 Breaking risk

Multi-lens review timeout fix

Review required
v2.15.0 New feature
Breaking upgrade Auth

Default production-ref fetch

No immediate action
v2.14.0 New feature

Semantic duplication reduction

No immediate action
v2.13.2 Bug fix

Ruby test command fix

Upgrade now
v2.13.1 Bug fix
Auth Breaking upgrade

Production‑ref fix + archetype rename bug

Beta — feedback welcome: [email protected]