Skip to content

feat: update + diff — no skill changes on disk without a visible diff (0.14.0) - #96

Merged
singhharsh1708 merged 1 commit into
mainfrom
feat/update-diff
Aug 7, 2026
Merged

singhharsh1708 merged 1 commit into
mainfrom
feat/update-diff

Conversation

@singhharsh1708

Copy link
Copy Markdown
Owner

Closes the v0.2 exit criterion: no code path exists where a skill's instructions change on disk without a human seeing a diff.

kitbash update

Refetches each skill's pinned source (kitbash.lock) and prints the complete review before touching anything:

  • manifest field deltas, with permission escalations flagged (permissions.network: no → YES ⚠ escalation)
  • the changed-file list (+/-/~, binaries and symlinks listed but not line-diffed)
  • a unified diff of every readable file

Three properties are deliberate:

  1. The four install safety lints (visible-text, dynamic-context, remote-exec, secrets) re-run against the new version and block the update regardless of --yes — a skill must clear the same gate to change on disk as to arrive.
  2. [policy] is re-enforced: a new version declaring a denied permission or exceeding max_budget cannot arrive by update.
  3. Unlike install, a non-interactive run never auto-applies. No TTY + no --yes → the diff prints, nothing changes, exit 1.

Also: local edits are detected via the lockfile hash and called out before being overwritten; a source that renames its skill is refused (remove + install instead).

kitbash diff

The same review, read-only. One argument diffs an installed skill against a fresh fetch of its pinned source ("what would update do?"); two arguments diff any two skills — installed name, local path, or fetchable source, so kitbash diff prereview gh:owner/repo/skills/prereview@v2 works before anything is installed. Exit codes follow diff(1): 0 identical, 1 different, 2 trouble.

Implementation

  • src/diff.ts (new): zero-dependency LCS unified diff with hunk headers, common prefix/suffix trim, CRLF normalization (matching the lockfile hasher), and a whole-block fallback past ~4M DP cells. Manifest delta + file-change walker reuse walk() from lock.ts.
  • commands.ts: cmdUpdate, cmdDiff, shared printSkillDiff, and the install hard-gate filter extracted to filterHardFails so install and update enforce the identical set.
  • 21 new e2e checks covering: up-to-date, read-only diff, non-interactive refusal, apply + re-pin, safety-lint block despite --yes, policy block, rename refusal, two-target compare, exit codes.

Docs

README, roadmap (v0.2 items ticked), CHANGELOG 0.14.0, site CLI + index pages. The CLI docs page was still describing the 0.6.0 surface — flat help listing, unknown command exiting 1 (it exits 2 with a did-you-mean), planned commands exiting 2 (they exit 7), a -v alias removed in 0.11.0, and a nine-adapter list missing zed — all corrected while adding the update/diff sections.

Version bumped to 0.14.0; site restamped via site/build.mjs; benchmark deterministic (npm run bench produces no diff).

… (0.14.0)

kitbash update refetches each skill's pinned source and prints the full
review before applying: manifest deltas with permission escalations
flagged, the changed-file list, and a unified diff of every readable
file. Install's four safety lints and [policy] are re-enforced and not
bypassable by --yes; non-interactive runs never auto-apply; local edits
are detected via the lockfile hash before being overwritten; a renamed
source is refused.

kitbash diff is the same review read-only: one argument against the
pinned source, two arguments between any two skills (installed name,
path, or source@ref). Exit codes follow diff(1): 0 same, 1 different,
2 trouble.

Shared LCS diff engine in src/diff.ts (CRLF-normalized, binary and
symlink entries listed but not line-diffed). 21 new e2e checks. Docs
aligned: CLI page still described the 0.6.0 surface (wrong exit codes,
removed -v alias, flat help listing, nine adapters).
@vercel

vercel Bot commented Aug 7, 2026

Copy link
Copy Markdown

The latest updates on your projects. Learn more about Vercel for GitHub.

Project Deployment Actions Updated (UTC)
kitbash Ready Ready Preview Aug 7, 2026 6:59am

@github-actions github-actions Bot added documentation Docs, spec, RFCs, README, site dependencies Dependency or action version bumps labels Aug 7, 2026
@singhharsh1708
singhharsh1708 merged commit 902d47b into main Aug 7, 2026
8 checks passed

This branch was successfully deployed

1 active deployment
Preview — 87c828ab Deployed Aug 7, 2026 by vercel[bot]
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Dependency or action version bumps documentation Docs, spec, RFCs, README, site

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant