Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
8 changes: 8 additions & 0 deletions .agents/pm/history/pm-github-m8vj.jsonl
Original file line number Diff line number Diff line change
@@ -0,0 +1,8 @@
{"ts":"2026-08-24T09:40:00.486Z","author":"harness:claude-code","author_source":"asserted","agent_harness":"claude-code","agent_instance":"365e646596cb83e6152b34c6","agent_provenance":{"model":null,"effort":{"value":"xhigh","source":"environment"},"role":{"value":"implementer","source":"argv"},"topic":null},"op":"create","patch":[{"op":"add","path":"/metadata/id","value":"pm-github-m8vj"},{"op":"add","path":"/metadata/title","value":"The changelog gate stamps an untagged version with the current date, so its verdict flips every midnight with no commit"},{"op":"add","path":"/metadata/description","value":"pm-changelog synthesises a pending release window for a version that has no matching git tag and stamps it with the current UTC date rather than anything derived from the input. The release workflow tags only after npm publish succeeds, and publish has been failing fleet wide since 2026-08-21, so this package currently carries an untagged version and is on that clock dependent path. The exposure is masked today only by a coincidence, because the package version and today's date are the same calendar day, and it fails on any later day with no commit having changed. Verified on pm-ops where the version date and today's date differ, which makes the comparison decisive: an untagged 2026.8.22 generates heading 2026.8.22 - 2026-08-24 without the flag and 2026.8.22 - 2026-08-22 with it. The remedy needs no new code because pm-changelog 2026.8.17 already ships --date-from-version, and zero of twenty packages passed it. Applied to every invocation of the generator in this package rather than only to the scripts whose names begin with changelog, because the release workflow invokes it directly and generation and check must not disagree. Site audit: package.json sites 2 flagged 2; .github/workflows/release.yml sites 3 flagged 3;"},{"op":"add","path":"/metadata/type","value":"Issue"},{"op":"add","path":"/metadata/status","value":"open"},{"op":"add","path":"/metadata/priority","value":1},{"op":"add","path":"/metadata/tags","value":["changelog","gates","release"]},{"op":"add","path":"/metadata/created_at","value":"2026-08-24T09:40:00.486Z"},{"op":"add","path":"/metadata/updated_at","value":"2026-08-24T09:40:00.486Z"},{"op":"add","path":"/metadata/author","value":"harness:claude-code"}],"before_hash":"3cc22dff72be7b14824654a7a64ea62b04799939b2fee54c1b5f52ca60bf6df0","after_hash":"066eb8244d63baf8616bcf83677c1e530dc047b3fad71f90deb30d12abfaf722","item_hash_version":2,"message":"","context":{"agent_provenance_outcomes":{"model":{"status":"failed","reason":"resolver_failed","resolver":"claude_session_file","rule_version":"v1"},"version":{"status":"failed","reason":"resolver_failed","resolver":"claude_session_file","rule_version":"v1"}}}}
{"ts":"2026-08-24T09:40:01.787Z","author":"harness:claude-code","author_source":"asserted","agent_harness":"claude-code","agent_instance":"365e646596cb83e6152b34c6","agent_provenance":{"model":null,"effort":{"value":"xhigh","source":"environment"},"role":null,"topic":null},"op":"files_add","patch":[{"op":"replace","path":"/metadata/updated_at","value":"2026-08-24T09:40:01.787Z"},{"op":"add","path":"/metadata/files","value":[{"path":"package.json","scope":"project","note":"every pm-changelog invocation here now derives the no-tag release date from the calendar version"}]}],"before_hash":"066eb8244d63baf8616bcf83677c1e530dc047b3fad71f90deb30d12abfaf722","after_hash":"e3b168699b37cb331584f1f5b651777c5a5447420ea49b82f5a03e304b6015f2","item_hash_version":2,"context":{"agent_provenance_outcomes":{"model":{"status":"failed","reason":"resolver_failed","resolver":"claude_session_file","rule_version":"v1"},"version":{"status":"failed","reason":"resolver_failed","resolver":"claude_session_file","rule_version":"v1"}}}}
{"ts":"2026-08-24T09:40:02.297Z","author":"harness:claude-code","author_source":"asserted","agent_harness":"claude-code","agent_instance":"365e646596cb83e6152b34c6","agent_provenance":{"model":null,"effort":{"value":"xhigh","source":"environment"},"role":null,"topic":null},"op":"files_add","patch":[{"op":"add","path":"/metadata/files/1","value":{"path":".github/workflows/release.yml","scope":"project","note":"every pm-changelog invocation here now derives the no-tag release date from the calendar version"}},{"op":"replace","path":"/metadata/updated_at","value":"2026-08-24T09:40:02.297Z"}],"before_hash":"e3b168699b37cb331584f1f5b651777c5a5447420ea49b82f5a03e304b6015f2","after_hash":"a255a62396aece893428674d595de84fe6c051c64f648924dff74a51470eb18b","item_hash_version":2,"context":{"agent_provenance_outcomes":{"model":{"status":"failed","reason":"resolver_failed","resolver":"claude_session_file","rule_version":"v1"},"version":{"status":"failed","reason":"resolver_failed","resolver":"claude_session_file","rule_version":"v1"}}}}
{"ts":"2026-08-24T09:40:02.702Z","author":"harness:claude-code","author_source":"asserted","agent_harness":"claude-code","agent_instance":"365e646596cb83e6152b34c6","agent_provenance":{"model":null,"effort":{"value":"xhigh","source":"environment"},"role":null,"topic":null},"op":"tests_add","patch":[{"op":"replace","path":"/metadata/updated_at","value":"2026-08-24T09:40:02.702Z"},{"op":"add","path":"/metadata/tests","value":[{"command":"npm run changelog:check","path":"package.json","scope":"project","note":"regenerates the changelog and compares it; without the flag the heading date is stamped from the clock and the comparison fails on any day after generation"}]}],"before_hash":"a255a62396aece893428674d595de84fe6c051c64f648924dff74a51470eb18b","after_hash":"69f77d3a5ae50ea79a9a842e87334f495ffe39621090444ae4b22fad198442f7","item_hash_version":2,"context":{"agent_provenance_outcomes":{"model":{"status":"failed","reason":"resolver_failed","resolver":"claude_session_file","rule_version":"v1"},"version":{"status":"failed","reason":"resolver_failed","resolver":"claude_session_file","rule_version":"v1"}}}}
{"ts":"2026-08-24T10:03:32.888Z","author":"harness:claude-code","author_source":"asserted","agent_harness":"claude-code","agent_instance":"365e646596cb83e6152b34c6","agent_provenance":{"model":null,"effort":{"value":"xhigh","source":"environment"},"role":null,"topic":null},"op":"tests_add","patch":[{"op":"add","path":"/metadata/tests/1","value":{"command":"bash scripts/verify-release-changelog-date.sh","path":"scripts/verify-release-changelog-date.sh","scope":"project","note":"exercises the release workflow path that npm run changelog:check does not: asserts every generator invocation in every tracked file carries the flag, and shows the same probe version yielding its own calendar date with the flag and today's date without it"}},{"op":"replace","path":"/metadata/updated_at","value":"2026-08-24T10:03:32.888Z"}],"before_hash":"69f77d3a5ae50ea79a9a842e87334f495ffe39621090444ae4b22fad198442f7","after_hash":"b64266e44f22744ea47d754bbb56149b69cc30665202a7fa44c9008ee563ee2e","item_hash_version":2,"context":{"agent_provenance_outcomes":{"model":{"status":"failed","reason":"resolver_failed","resolver":"claude_session_file","rule_version":"v1"},"version":{"status":"failed","reason":"resolver_failed","resolver":"claude_session_file","rule_version":"v1"}}}}
{"ts":"2026-08-24T10:03:33.311Z","author":"harness:claude-code","author_source":"asserted","agent_harness":"claude-code","agent_instance":"365e646596cb83e6152b34c6","agent_provenance":{"model":null,"effort":{"value":"xhigh","source":"environment"},"role":null,"topic":null},"op":"files_add","patch":[{"op":"add","path":"/metadata/files/2","value":{"path":"scripts/verify-release-changelog-date.sh","scope":"project","note":"executable proof for the release workflow invocations, which the package.json changelog check never reaches"}},{"op":"replace","path":"/metadata/updated_at","value":"2026-08-24T10:03:33.311Z"}],"before_hash":"b64266e44f22744ea47d754bbb56149b69cc30665202a7fa44c9008ee563ee2e","after_hash":"80ccd79861a5cf611f73a0852db5cdaaf80e084ee496c6cdba9a61636d58de5d","item_hash_version":2,"context":{"agent_provenance_outcomes":{"model":{"status":"failed","reason":"resolver_failed","resolver":"claude_session_file","rule_version":"v1"},"version":{"status":"failed","reason":"resolver_failed","resolver":"claude_session_file","rule_version":"v1"}}}}
{"ts":"2026-08-24T10:03:33.732Z","author":"harness:claude-code","author_source":"asserted","agent_harness":"claude-code","agent_instance":"365e646596cb83e6152b34c6","agent_provenance":{"model":null,"effort":{"value":"xhigh","source":"environment"},"role":null,"topic":null},"op":"comment_add","patch":[{"op":"replace","path":"/metadata/updated_at","value":"2026-08-24T10:03:33.732Z"},{"op":"add","path":"/metadata/comments","value":[{"created_at":"2026-08-24T10:03:33.732Z","author":"harness:claude-code","text":"CodeRabbit was right that the linked test only covered the package.json invocation and never reached the direct pm-changelog commands in the release workflow. Added an executable check that does both halves. The static half enumerates every tracked file containing a generator invocation and asserts each file's flagged count is not below its site count, which fails when any single site loses the flag; verified by removing the flag from one of two release.yml sites and watching it report one of two and exit non-zero. The behavioural half runs the generator twice on the same probe version 2026.1.2, deliberately chosen so its calendar date cannot coincide with today, and asserts the heading is 2026.1.2 - 2026-01-02 with the flag and 2026.1.2 - 2026-08-24 without it, so the test states the defect rather than merely asserting the fix."}]}],"before_hash":"80ccd79861a5cf611f73a0852db5cdaaf80e084ee496c6cdba9a61636d58de5d","after_hash":"9e1140c4269961557871f0cbcd6e87b26f7456712915da4596a184c4bb765508","item_hash_version":2,"context":{"agent_provenance_outcomes":{"model":{"status":"failed","reason":"resolver_failed","resolver":"claude_session_file","rule_version":"v1"},"version":{"status":"failed","reason":"resolver_failed","resolver":"claude_session_file","rule_version":"v1"}}}}
{"ts":"2026-08-24T10:05:45.234Z","author":"harness:claude-code","author_source":"asserted","agent_harness":"claude-code","agent_instance":"365e646596cb83e6152b34c6","agent_provenance":{"model":null,"effort":{"value":"xhigh","source":"environment"},"role":null,"topic":null},"op":"comment_add","patch":[{"op":"add","path":"/metadata/comments/1","value":{"created_at":"2026-08-24T10:05:45.234Z","author":"harness:claude-code","text":"CodeRabbit was right that the linked test only covered the package.json invocation and never reached the direct pm-changelog commands in the release workflow. Added an executable check that does both halves. The static half enumerates every tracked file containing a generator invocation and asserts each file's flagged count is not below its site count, which fails when any single site loses the flag; verified by removing the flag from one of two release.yml sites and watching it report one of two and exit non-zero. The behavioural half runs the generator twice on the same probe version 2026.1.2, deliberately chosen so its calendar date cannot coincide with today, and asserts the heading is 2026.1.2 - 2026-01-02 with the flag and 2026.1.2 - 2026-08-24 without it, so the test states the defect rather than merely asserting the fix."}},{"op":"replace","path":"/metadata/updated_at","value":"2026-08-24T10:05:45.234Z"}],"before_hash":"9e1140c4269961557871f0cbcd6e87b26f7456712915da4596a184c4bb765508","after_hash":"d1057927d8aa62d5d4af3f1ef64fb62badb3a4784ad3b8976ea11858b1032997","item_hash_version":2,"context":{"agent_provenance_outcomes":{"model":{"status":"failed","reason":"resolver_failed","resolver":"claude_session_file","rule_version":"v1"},"version":{"status":"failed","reason":"resolver_failed","resolver":"claude_session_file","rule_version":"v1"}}}}
21 changes: 21 additions & 0 deletions .agents/pm/issues/pm-github-m8vj.toon
Original file line number Diff line number Diff line change
@@ -0,0 +1,21 @@
id: pm-github-m8vj
title: "The changelog gate stamps an untagged version with the current date, so its verdict flips every midnight with no commit"
description: "pm-changelog synthesises a pending release window for a version that has no matching git tag and stamps it with the current UTC date rather than anything derived from the input. The release workflow tags only after npm publish succeeds, and publish has been failing fleet wide since 2026-08-21, so this package currently carries an untagged version and is on that clock dependent path. The exposure is masked today only by a coincidence, because the package version and today's date are the same calendar day, and it fails on any later day with no commit having changed. Verified on pm-ops where the version date and today's date differ, which makes the comparison decisive: an untagged 2026.8.22 generates heading 2026.8.22 - 2026-08-24 without the flag and 2026.8.22 - 2026-08-22 with it. The remedy needs no new code because pm-changelog 2026.8.17 already ships --date-from-version, and zero of twenty packages passed it. Applied to every invocation of the generator in this package rather than only to the scripts whose names begin with changelog, because the release workflow invokes it directly and generation and check must not disagree. Site audit: package.json sites 2 flagged 2; .github/workflows/release.yml sites 3 flagged 3;"
type: Issue
status: open
priority: 1
tags[3]: changelog,gates,release
created_at: "2026-08-24T09:40:00.486Z"
updated_at: "2026-08-24T10:05:45.234Z"
author: "harness:claude-code"
comments[2]{created_at,author,text}:
"2026-08-24T10:03:33.732Z","harness:claude-code","CodeRabbit was right that the linked test only covered the package.json invocation and never reached the direct pm-changelog commands in the release workflow. Added an executable check that does both halves. The static half enumerates every tracked file containing a generator invocation and asserts each file's flagged count is not below its site count, which fails when any single site loses the flag; verified by removing the flag from one of two release.yml sites and watching it report one of two and exit non-zero. The behavioural half runs the generator twice on the same probe version 2026.1.2, deliberately chosen so its calendar date cannot coincide with today, and asserts the heading is 2026.1.2 - 2026-01-02 with the flag and 2026.1.2 - 2026-08-24 without it, so the test states the defect rather than merely asserting the fix."
"2026-08-24T10:05:45.234Z","harness:claude-code","CodeRabbit was right that the linked test only covered the package.json invocation and never reached the direct pm-changelog commands in the release workflow. Added an executable check that does both halves. The static half enumerates every tracked file containing a generator invocation and asserts each file's flagged count is not below its site count, which fails when any single site loses the flag; verified by removing the flag from one of two release.yml sites and watching it report one of two and exit non-zero. The behavioural half runs the generator twice on the same probe version 2026.1.2, deliberately chosen so its calendar date cannot coincide with today, and asserts the heading is 2026.1.2 - 2026-01-02 with the flag and 2026.1.2 - 2026-08-24 without it, so the test states the defect rather than merely asserting the fix."
files[3]{path,scope,note}:
package.json,project,every pm-changelog invocation here now derives the no-tag release date from the calendar version
.github/workflows/release.yml,project,every pm-changelog invocation here now derives the no-tag release date from the calendar version
scripts/verify-release-changelog-date.sh,project,"executable proof for the release workflow invocations, which the package.json changelog check never reaches"
tests[2]{command,path,scope,note}:
"npm run changelog:check",package.json,project,regenerates the changelog and compares it; without the flag the heading date is stamped from the clock and the comparison fails on any day after generation
bash scripts/verify-release-changelog-date.sh,scripts/verify-release-changelog-date.sh,project,"exercises the release workflow path that npm run changelog:check does not: asserts every generator invocation in every tracked file carries the flag, and shows the same probe version yielding its own calendar date with the flag and today's date without it"
body: ""
6 changes: 3 additions & 3 deletions .github/workflows/release.yml
Original file line number Diff line number Diff line change
Expand Up @@ -108,9 +108,9 @@ jobs:
shell: bash
run: |
set -euo pipefail
npx pm-changelog --pm-root .agents/pm --mode replace --output CHANGELOG.md --all-release-tags --release-version-from-package --item-url-base https://github.com/unbraind/pm-github/blob/main/.agents/pm --respect-item-release --pm-bin ./node_modules/.bin/pm --github-step-summary
npx pm-changelog --pm-root .agents/pm --mode replace --output CHANGELOG.md --all-release-tags --release-version-from-package --item-url-base https://github.com/unbraind/pm-github/blob/main/.agents/pm --respect-item-release --pm-bin ./node_modules/.bin/pm --check
npx pm-changelog --pm-root .agents/pm --stdout --since-previous-tag --until-release-tag --release-version-from-package --item-url-base https://github.com/unbraind/pm-github/blob/main/.agents/pm --respect-item-release --pm-bin ./node_modules/.bin/pm > RELEASE_NOTES.md
npx pm-changelog --pm-root .agents/pm --mode replace --output CHANGELOG.md --all-release-tags --release-version-from-package --date-from-version --item-url-base https://github.com/unbraind/pm-github/blob/main/.agents/pm --respect-item-release --pm-bin ./node_modules/.bin/pm --github-step-summary
npx pm-changelog --pm-root .agents/pm --mode replace --output CHANGELOG.md --all-release-tags --release-version-from-package --date-from-version --item-url-base https://github.com/unbraind/pm-github/blob/main/.agents/pm --respect-item-release --pm-bin ./node_modules/.bin/pm --check
npx pm-changelog --pm-root .agents/pm --stdout --since-previous-tag --until-release-tag --release-version-from-package --date-from-version --item-url-base https://github.com/unbraind/pm-github/blob/main/.agents/pm --respect-item-release --pm-bin ./node_modules/.bin/pm > RELEASE_NOTES.md

- name: Run release checks
if: steps.decide.outputs.should_release == 'true'
Expand Down
Loading