Repository navigation
feat: update + diff — no skill changes on disk without a visible diff (0.14.0) - #96
Merged
Merged
Conversation
… (0.14.0) kitbash update refetches each skill's pinned source and prints the full review before applying: manifest deltas with permission escalations flagged, the changed-file list, and a unified diff of every readable file. Install's four safety lints and [policy] are re-enforced and not bypassable by --yes; non-interactive runs never auto-apply; local edits are detected via the lockfile hash before being overwritten; a renamed source is refused. kitbash diff is the same review read-only: one argument against the pinned source, two arguments between any two skills (installed name, path, or source@ref). Exit codes follow diff(1): 0 same, 1 different, 2 trouble. Shared LCS diff engine in src/diff.ts (CRLF-normalized, binary and symlink entries listed but not line-diffed). 21 new e2e checks. Docs aligned: CLI page still described the 0.6.0 surface (wrong exit codes, removed -v alias, flat help listing, nine adapters).
|
The latest updates on your projects. Learn more about Vercel for GitHub.
|
This branch was successfully deployed
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Closes the v0.2 exit criterion: no code path exists where a skill's instructions change on disk without a human seeing a diff.
kitbash update
Refetches each skill's pinned source (
kitbash.lock) and prints the complete review before touching anything:permissions.network: no → YES ⚠ escalation)+/-/~, binaries and symlinks listed but not line-diffed)Three properties are deliberate:
visible-text,dynamic-context,remote-exec,secrets) re-run against the new version and block the update regardless of--yes— a skill must clear the same gate to change on disk as to arrive.[policy]is re-enforced: a new version declaring a denied permission or exceedingmax_budgetcannot arrive by update.install, a non-interactive run never auto-applies. No TTY + no--yes→ the diff prints, nothing changes, exit 1.Also: local edits are detected via the lockfile hash and called out before being overwritten; a source that renames its skill is refused (
remove+installinstead).kitbash diff
The same review, read-only. One argument diffs an installed skill against a fresh fetch of its pinned source ("what would update do?"); two arguments diff any two skills — installed name, local path, or fetchable source, so
kitbash diff prereview gh:owner/repo/skills/prereview@v2works before anything is installed. Exit codes follow diff(1):0identical,1different,2trouble.Implementation
src/diff.ts(new): zero-dependency LCS unified diff with hunk headers, common prefix/suffix trim, CRLF normalization (matching the lockfile hasher), and a whole-block fallback past ~4M DP cells. Manifest delta + file-change walker reusewalk()fromlock.ts.commands.ts:cmdUpdate,cmdDiff, sharedprintSkillDiff, and the install hard-gate filter extracted tofilterHardFailsso install and update enforce the identical set.--yes, policy block, rename refusal, two-target compare, exit codes.Docs
README, roadmap (v0.2 items ticked), CHANGELOG 0.14.0, site CLI + index pages. The CLI docs page was still describing the 0.6.0 surface — flat help listing, unknown command exiting 1 (it exits 2 with a did-you-mean), planned commands exiting 2 (they exit 7), a
-valias removed in 0.11.0, and a nine-adapter list missingzed— all corrected while adding theupdate/diffsections.Version bumped to 0.14.0; site restamped via
site/build.mjs; benchmark deterministic (npm run benchproduces no diff).