Skip to content

chore(deps-dev): bump @unbrained/pm-cli from 2026.8.6 to 2026.8.11 - #40

Closed
dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/npm_and_yarn/unbrained/pm-cli-2026.8.11
Closed

dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/npm_and_yarn/unbrained/pm-cli-2026.8.11

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Aug 14, 2026 •

Copy link
Copy Markdown
Contributor

Bumps @unbrained/pm-cli from 2026.8.6 to 2026.8.11.

Release notes

Sourced from @​unbrained/pm-cli's releases.

v2026.8.11

@​unbrained/pm-cli 2026.8.11

Source range: v2026.8.10...v2026.8.11

Changelog

Added

  • pm gate: named assertion bundles bound to lifecycle triggers, returning one structured verdict document instead of prose, so local and hosted enforcement run identical semantics (pm-wn6wot)
  • Assurance verdicts are appended to the immutable record, so what was enforced when, and who relaxed a bound, is replayable and provable rather than reconstructed from CI logs (pm-91xeam)
  • pm assert: a bound over a measurement carrying polarity, scope, lifetime, enforcement level, and a required negative control, so every guarantee states which direction it can fail in (pm-lyfu7b)
  • pm measure: a named population over the workspace declared as data, with a composable source vocabulary and derived arithmetic so a bound can be denominated in the unit it actually means (pm-2lex4r)
  • Refusal reachability: every error code declares the states it owns, and an entrypoint-level probe proves each state is still reachable as that typed code rather than as an untyped fault (pm-elmpav)
  • Source-to-item traceability: derive which tracked work produced any given file or line, so an agent can ask why this code exists and get an evidence-backed answer (pm-f86lth)
  • Automatic semantic session attribution: infer bounded topic and role from claimed work and harness context without per-call identity flags (pm-3zgh2c)

Fixed

  • Unknown-option recovery names three of six commands that accept the flag, capped silently and in arbitrary order, so the hint excludes the right answer while reading as exhaustive (pm-yqe0mo)
  • Subcommand-token error contract: one unknown-subcommand code with nearest-match recovery across every subcommand family (pm-185870)
  • pm get cannot report linked files, tests, or docs in any projection, so the one command an agent uses to rebuild an item's context silently reports them as absent (pm-tld20c)

Security

  • Refresh compatible 2026-08-08 development dependencies (pm-8l1m5t)

PM Tracker Evidence

Closed pm items in release window: 175 By type: Task=22, Plan=12, Decision=1, Feature=17, Issue=42, Epic=60, Chore=21 By status: closed=175

Selected release-related tracker items:

  • pm-1hkq [Epic/closed] Health drift and vectorization integrity
  • pm-bckz [Epic/closed] TOON item storage migration
  • pm-67uh [Epic/closed] Auto-enable semantic search when local Ollama is available
  • pm-mudv [Epic/closed] Universal terminal compatibility hardening
  • pm-va6e [Epic/closed] Deadline/date parsing compatibility hardening
  • pm-g6a2 [Epic/closed] Status alias compatibility hardening
  • pm-my6o [Epic/closed] External audit issue remediation and compatibility hardening
  • pm-ote [Epic/closed] Release readiness refactor
  • pm-jiw [Epic/closed] Milestone 6 - Hardening + Release Readiness
  • pm-qa2h [Issue/closed] auto-release.yml workflow_dispatch silently overrides explicit push=false to true
  • pm-kcba [Issue/closed] Auto Release 2026-06-01 tagged v2026.6.1 but npm publish never completed (latest npm = 2026.5.31)
  • pm-8l1m5t [Chore/closed] Refresh compatible 2026-08-08 development dependencies

v2026.8.10

@​unbrained/pm-cli 2026.8.10

... (truncated)

Changelog

Sourced from @​unbrained/pm-cli's changelog.

2026.8.11 - 2026-08-11

Added

  • pm gate: named assertion bundles bound to lifecycle triggers, returning one structured verdict document instead of prose, so local and hosted enforcement run identical semantics (pm-wn6wot)
  • Assurance verdicts are appended to the immutable record, so what was enforced when, and who relaxed a bound, is replayable and provable rather than reconstructed from CI logs (pm-91xeam)
  • pm assert: a bound over a measurement carrying polarity, scope, lifetime, enforcement level, and a required negative control, so every guarantee states which direction it can fail in (pm-lyfu7b)
  • pm measure: a named population over the workspace declared as data, with a composable source vocabulary and derived arithmetic so a bound can be denominated in the unit it actually means (pm-2lex4r)
  • Refusal reachability: every error code declares the states it owns, and an entrypoint-level probe proves each state is still reachable as that typed code rather than as an untyped fault (pm-elmpav)
  • Source-to-item traceability: derive which tracked work produced any given file or line, so an agent can ask why this code exists and get an evidence-backed answer (pm-f86lth)
  • Automatic semantic session attribution: infer bounded topic and role from claimed work and harness context without per-call identity flags (pm-3zgh2c)

Fixed

  • Unknown-option recovery names three of six commands that accept the flag, capped silently and in arbitrary order, so the hint excludes the right answer while reading as exhaustive (pm-yqe0mo)
  • Subcommand-token error contract: one unknown-subcommand code with nearest-match recovery across every subcommand family (pm-185870)
  • pm get cannot report linked files, tests, or docs in any projection, so the one command an agent uses to rebuild an item's context silently reports them as absent (pm-tld20c)

Security

  • Refresh compatible 2026-08-08 development dependencies (pm-8l1m5t)

2026.8.10 - 2026-08-10

Added

  • GH-472: create error for missing required custom fields lists the field names (pm-4bzq)
  • Provenance records distinguish unavailable configuration from resolver failures (pm-lu6sca)

Fixed

  • GH-959 recurrence: snapshot restore planning races lease-expiry fixture cleanup (pm-usq49n)
  • GH-960: structured diagnostic notices preserve machine-readable JSON envelopes (pm-embm6t)
  • GH-956: lossless acceptance-criteria replacement and unmatched-removal failure contract (pm-lppm6y)
  • GH-954: fail-fast dependency target validation with explicit forward-reference intent (pm-x3dq0l)
  • Preserve executable recovery semantics across terminators, nested aliases, and tracker scope (pm-szn67i)
  • Measure source replication against an independently discovered denominator (pm-b84irw)
  • GH-515: pm test --add reorders linked tests — --only-last can execute a non-newest command (pm-x2vx)
  • GH-490: unknown-command suggester ranks substring hits over synonyms/edit distance — pm log suggests 'extension catalog' (pm-g543)
  • GH-441: type-aware create help mislabels applicable flags as required (ignores create-mode) (pm-qmjx)
  • GH-519: close recovery bundle suggests --validate-close "<value>" for an enum flag and hides the real resolution-fields blocker (pm-ulqu)
  • GH-950: item-addressing commands reject a consistent --id alias and misroute recovery (pm-mkinft)
  • GH-951: required-field policy can force fabricated relationship edges (pm-st7wgu)
  • GH-953: close recovery suggested_retry is not executable and drops supplied flags (pm-p316vn)
  • A sandboxed fixture records provenance from the host harness environment, so the suite is green on CI and deterministically red for any agent running it locally (pm-xgah3a)
  • The session-role dimension is wired to a boolean child-session flag, so every nested claude-code invocation records the role literally as "1" and fleet analytics will group real work under a meaningless label (pm-eq9dlw)
  • GH-921/GH-922: merge-decision receipts are not durable in fresh-clone CI (pm-1j5j21)
  • GH-948: version-skewed pm invocations silently rewrite the tracked merge fence during unrelated commands (pm-l56d0o)
  • A measurement ratchet bound stops enforcing the moment its owner reaches a terminal status, so every guarded population goes unbounded exactly when its fix ships (pm-5z9plz)
  • The docs tree grows one file per shipped contract, so 39 of 51 documents are stubs and the SDK's story is split across twelve files (pm-9hv1o7)

... (truncated)

Commits
  • eb641cb chore(release): cut 2026.8.11
  • 39d60f2 SDK assurance: measurements, assertions, lifecycle gates, and durable verdict...
  • 3791ff1 Make assurance a first-class part of the record instead of a pile of scripts
  • e9bc5f0 Merge pull request #968 from unbraind/feat/sdk-refusal-recovery-contracts
  • e6a2ca5 fix(sdk): harden refusal recovery review contracts
  • f1c7b3e fix(cli): remove obsolete plan recovery parameter
  • 30255a0 feat(sdk): unify refusal recovery and reachability contracts
  • 07b5200 Make a blocked release name its own cause, and link the project origin into t...
  • 4091f60 SDK semantic work context and evidence-backed source traceability (#965)
  • fd6680a Record release-health and provenance verification evidence
  • Additional commits viewable in compare view

Dependabot compatibility score

Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.


Dependabot commands and options

You can trigger Dependabot actions by commenting on this PR:

  • @dependabot rebase will rebase this PR
  • @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
  • @dependabot show <dependency name> ignore conditions will show all of the ignore conditions of the specified dependency
  • @dependabot ignore this major version will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this minor version will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this dependency will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)

Summary by cubic

Upgrade dev tool @unbrained/pm-cli from 2026.8.6 to 2026.8.11 to pick up CLI fixes, new assurance features, and a dev-deps security refresh. No runtime impact; only developer/CI workflows may see changes.

  • Only package-lock.json changes; transitive bump to @toon-format/toon@4.1.1.
  • Upstream highlights: new lifecycle gates with structured verdicts and durable assurance records; unified unknown-subcommand handling and improved option hints; pm get now returns linked files/tests/docs.
  • No required migration. If we use pm in local or CI scripts, run them once to confirm stricter gate/assert semantics and updated error messages don’t affect flow.

Written for commit 6e7fa8c. Summary will update on new commits.

Review in cubic

Bumps [@unbrained/pm-cli](https://github.com/unbraind/pm-cli) from 2026.8.6 to 2026.8.11.
- [Release notes](https://github.com/unbraind/pm-cli/releases)
- [Changelog](https://github.com/unbraind/pm-cli/blob/main/CHANGELOG.md)
- [Commits](unbraind/pm-cli@v2026.8.6...v2026.8.11)

---
updated-dependencies:
- dependency-name: "@unbrained/pm-cli"
  dependency-version: 2026.8.11
  dependency-type: direct:development
  update-type: version-update:semver-patch
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot dependabot Bot added dependencies Pull requests that update a dependency file javascript Pull requests that update javascript code labels Aug 14, 2026
@greptile-apps

greptile-apps Bot commented Aug 14, 2026

Copy link
Copy Markdown

PR author is in the excluded authors list.

@unbraind

Copy link
Copy Markdown
Owner

@greptile-apps — 👍 on the status note: Greptile is configured to exclude Dependabot-authored PRs, so this PR carries no Greptile findings and there is nothing advisory to triage. My disposition is close, not merge, for two independent reasons: (1) the fleet pins @unbrained/pm-cli exactly 2026.8.15, and this PR's 2026.8.11 predates the completeness-receipt envelope the fleet tooling requires; (2) both CI jobs fail at pm health --strict-exit — the 2026.8.11 CLI reports telemetry_queue_pending (flush http_403) and provenance_value_domain_invalid warnings against the same tracker data that is green on main with 2026.8.6. Full rationale in the close comment.

@unbraind

Copy link
Copy Markdown
Owner

Closing as stale: this bump would regress the deliberate @unbrained/pm-cli pin, and its CI cannot be made green within policy.

What I verified before closing:

  • Fleet decision: @unbrained/pm-cli is pinned exactly 2026.8.15 in devDependencies with a >=2026.8.15 peer floor across the fleet. Target 2026.8.11 is below that pin, and below the version where pm list-all --json started carrying the completeness-receipt envelope (completeness.status, omission_receipt.has_omissions) that the fleet's pm-changelog tooling now refuses to run without — pm-github's own changelog:check / release:notes gates execute pm-changelog against the CLI pinned here, so 2026.8.11 would leave this repo under the floor the fleet just standardized on.
  • Three declarations, one fact: merging a pm-cli bump requires moving manifest.json pm_min_version (currently 2026.7.28), the peerDependencies floor (currently >=2026.8.3), and the devDependencies pin in lockstep. Doing that to 2026.8.11 would understate the real 2026.8.15 floor to all three installers — the wrong fact, stated three times.
  • CI is red at pm health --strict-exit (both test (22) and test (26)): warnings telemetry_queue_pending:3 (last flush failed telemetry_flush_http_403) and provenance_value_domain_invalid:claude-code:role:single_digit:23. main is green on the identical tracker data with the 2026.8.6 CLI, so these warnings come from the 2026.8.11 binary's own stricter reporting — i.e. the bump itself surfaces them. Telemetry/observability configuration is out of bounds for a dependency PR (and for this automation run), so there is no in-scope path to green here.
  • Nothing newer exists to take instead: 2026.8.15 is latest upstream today; the fleet exact-pin supersedes this bump entirely.

When a version greater than 2026.8.15 is published, a fresh proposal can be evaluated normally — with pm_min_version, peer floor, and pin moved in lockstep.

@unbraind unbraind closed this Aug 15, 2026
@dependabot @github

dependabot Bot commented on behalf of github Aug 15, 2026

Copy link
Copy Markdown
Contributor Author

OK, I won't notify you again about this release, but will get in touch when a new version is available. If you'd rather skip all updates until the next major or minor version, let me know by commenting @dependabot ignore this major version or @dependabot ignore this minor version. You can also ignore all major, minor, or patch releases for a dependency by adding an ignore condition with the desired update_types to your config file.

If you change your mind, just re-open this PR and I'll resolve any conflicts on it.

@dependabot
dependabot Bot deleted the dependabot/npm_and_yarn/unbrained/pm-cli-2026.8.11 branch August 15, 2026 15:10
@greptile-apps

greptile-apps Bot commented Aug 15, 2026

Copy link
Copy Markdown

Understood — the close rationale is clean and self-contained. A couple of observations for the record:

On the version mismatch: Closing rather than merging is the right call. A bump that's already behind the fleet's exact pin (2026.8.15) has no path to being useful, and merging an intermediate version would just create churn in package-lock.json with no net benefit.

On the provenance_value_domain_invalid CI failure: Worth noting for whoever investigates the 2026.8.11 regression separately — provenance_value_domain_invalid surfacing on a fresh runner against data that's green on main is a pattern consistent with the pm health gate reading provenance records from clone-local or gitignored paths. If the health check's pass/fail depends on state that doesn't travel with a clean checkout, the gate is structurally blind to the failure class it appears to enforce (it would always be green on main's CI runner, not because the data is valid, but because the relevant state is absent). That's a separate issue from this PR but worth surfacing upstream if it isn't already tracked.

Nothing actionable here from a review standpoint — closing is correct.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file javascript Pull requests that update javascript code

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant