跳到正文

更新日志

此页面随每次发布自动更新。

[5.7.0] - 2026-08-31

Features

  • feat: registry-mapped ~/.planu demolisher and storage isolation guard (SPEC-1709)
  • feat(lifecycle): SPEC-1703 declared architectural-premise drift routes reconcile_spec demotion
  • feat: add done-drift missing-files compliance check (SPEC-1701)
  • feat(telemetry): SPEC-1704 anonymous event envelope v1 and consent CLI

Bug Fixes

  • fix: serialize prepublish-guard suite to avoid full-load spawn flake
  • fix: declare telemetry and test-home env vars in schema and serialize lock-lease suite
  • fix: reuse shared pathExists helper in legacy planu demolisher (SPEC-1709)
  • fix: harden legacy planu demolisher (symlinks, canonical root) SPEC-1709
  • fix: enforce mcp trust boundary and bind drift source into receipt digest (SPEC-1703)
  • fix: exclude globs and directory refs from done-drift check, wire early return (SPEC-1701)
  • fix(telemetry): close legacy properties, validate ids, truncate show output (SPEC-1704)
  • fix(gates): destination-aware premise matching and tool-level AC1 coverage (SPEC-1702 review fixes)
  • fix(gates): SPEC-1702 cross-spec premise contradiction detection

[5.6.0] - 2026-08-31

Features

  • feat(init-project): regenerate conventions.md from folded conventions.json (SPEC-1699)
  • feat(init-project): fold legacy planu/ root artifacts on update (SPEC-1699)
  • feat(init-project): gitignore legacy planu/ root files (SPEC-1699)
  • feat(create-spec): refresh the regenerable spec index after writing spec.md (SPEC-1699)
  • feat(storage): add regenerable spec.md index (SPEC-1699)

Bug Fixes

  • fix(test): reconcile suites with SPEC-1699 runtime relocation and serialize frozen-lockfile suite
  • fix(storage): classify retention and current-project catch degradations
  • fix(release): require the exact tsgo package dir, not any node_modules content
  • fix(release): drop CI=true from frozen-lockfile install, probe tsgo native package
  • fix(SPEC-1696): accept inline YAML arrays for scenario tests in frontmatter
  • fix(storage): close retention review gaps from Codex CHANGES_REQUIRED
  • fix(storage): enforce retention budgets on runtime storage writers
  • fix(SPEC-1694): report the actual test runner instead of Unknown
  • fix(SPEC-1694): promote framework/database claims only from runtime dependencies
  • fix: parse ordered-list markers in BDD criteria extraction (SPEC-1688)
  • fix: repair release-gate collateral fallout from SPEC-1699 fold (blocker 6 sweep)
  • fix: release.sh repoints version marker to planu/project.json (SPEC-1699 blocker 6)
  • fix: reconcile-release-pending falls back to legacy pending.json (SPEC-1699 blocker 4)
  • fix: legacy-root-migration idempotency and fail-safe malformed handling (SPEC-1699 blocker 3)
  • fix: append-releases fails closed on ledger errors (SPEC-1699 blocker 5)
  • fix: verify spec.md digest at the spec-store read choke point (SPEC-1699 blocker 2)
  • fix(housekeeping): protect planu/.runtime as the canonical runtime home (SPEC-1699)
  • fix: address implementation-review blockers for SPEC-1695 runtime relocation
  • fix: reroute default proposal/export/docs-site outputs to planu/.runtime (SPEC-1695)
  • fix: relocate runtime artifacts to planu/.runtime (SPEC-1695)

Refactoring

  • refactor(release): fold pending release ledger into planu/project.json (SPEC-1699)
  • refactor: relocate session.json and session-context.md under planu/.runtime (SPEC-1699)
  • refactor: route spec resources through the current-project spec index (SPEC-1699)
  • refactor: canonical planu/ set shrinks to project.json + specs/ (SPEC-1699)

[5.5.3] - 2026-08-30

Bug Fixes

  • fix: reuse canonical pathExistsStrictByStat and give worktree-list test a real project path
  • fix(SPEC-1682): honor Risks and Test Plan section headings in handoff packager
  • fix(SPEC-1683): close guard bypass, fail-closed pristine check, TOCTOU-safe removal
  • fix(SPEC-1683): git command guard and stray embedded repo self-heal

Chores

  • chore(planu): SPEC-1685 implementing transition state

[5.5.2] - 2026-08-30

Bug Fixes

  • fix: reuse canonical pathExistsStrictByStat and give worktree-list test a real project path
  • fix(SPEC-1682): honor Risks and Test Plan section headings in handoff packager
  • fix(SPEC-1683): close guard bypass, fail-closed pristine check, TOCTOU-safe removal
  • fix(SPEC-1683): git command guard and stray embedded repo self-heal

Chores

  • chore(planu): SPEC-1685 implementing transition state

[5.5.1] - 2026-08-30

Bug Fixes

  • fix(SPEC-1682): honor Risks and Test Plan section headings in handoff packager
  • fix(SPEC-1683): close guard bypass, fail-closed pristine check, TOCTOU-safe removal
  • fix(SPEC-1683): git command guard and stray embedded repo self-heal

Chores

  • chore(planu): SPEC-1685 implementing transition state

[5.5.0] - 2026-08-29

Features

  • feat(SPEC-1681): cache the prettier format gate with content strategy

Bug Fixes

  • fix(SPEC-1684): cap vitest workers at 6 in preflight related and full-suite runs
  • fix(storage): handle ENOENT explicitly in best-effort path normalization
  • fix(SPEC-1677,SPEC-1678): dedupe AGENTS.md changes and bound legacy skips to contract codes
  • fix(SPEC-1678): classify legacy contract failures as non-fatal skipped entries
  • fix(SPEC-1677): install and refresh planu core host assets on safe update
  • fix(SPEC-1679): normalize both roots in canonical re-check to match heal semantics
  • fix(SPEC-1679): self-heal missing registry logicalProjectId in canonical-root gate

[5.4.1] - 2026-08-29

Bug Fixes

  • fix(SPEC-1675): strip FILES/FUNCTIONS/TEST metadata markers from contradiction analysis
  • fix(SPEC-1676): rebuild expired project knowledge graph and re-stamp cached reuse

[5.4.0] - 2026-08-29

Features

  • feat(SPEC-1672): install phase skills with managed-by ownership marker on init hosts

Chores

  • chore(deps): upgrade stryker to v10 majors
  • chore(deps): update 13 patch/minor dependencies and adapt readFile mock casts

[5.3.69] - 2026-08-29

Features

  • feat(SPEC-1674): tail or skip oversized operational graph sources instead of throwing

Bug Fixes

  • fix(SPEC-1674): include warnings in graph coverage test fixtures
  • fix(SPEC-1669): fail closed on ambiguous spec discovery, real validator in tests
  • fix(SPEC-1669): quarantine journals via atomic rename, test via init_project
  • fix(SPEC-1669): re-discover canonical spec.md when the readiness index is stale
  • fix(SPEC-1669): quarantine stale terminal migration journals instead of throwing
  • fix(SPEC-1673): capture nested vitest child output instead of inheriting stdio
  • fix(SPEC-1673): serialize load-sensitive test suites into a dedicated vitest project
  • fix(SPEC-1670): accept Next.js route group and dynamic segment characters in ownership paths
  • fix(SPEC-1674): harden oversized-source handling per implementation review
  • fix(SPEC-1674): surface persisted oversized graph sources as validate warnings
  • fix(SPEC-1674): thread oversizedSources through the build result, artifact, and query slice
  • fix(SPEC-1664): include backtick in criterion identity punctuation normalization
  • fix(SPEC-1661): guarantee cascade-hook wiring in lean release process
  • fix(SPEC-1660): grandfather full-allowlist and dynamic-import violations
  • fix(SPEC-1660): full allowlist, subpath fix, dynamic imports, exemption scope
  • fix(SPEC-1660): grandfather existing layer-boundary violations
  • fix(SPEC-1660): enforce merged layer and status-write import rules per scope
  • fix(SPEC-1320): serialize legacy session writers behind the paired refresher
  • fix(SPEC-1320): derive both session artifacts from one serialized active-spec snapshot

Refactoring

  • refactor(SPEC-1663): relocate DurableJobRecord/SpecGraph/validation-evidence types into src/types
  • refactor(SPEC-1663): rename divergent tools-cluster types off shared names
  • refactor(SPEC-1663): figma cluster imports canonical types, renames divergent thumbnail/visual-qa shapes
  • refactor(SPEC-1663): rename divergent ToolHandler/SkipReason/RollbackStep off shared names
  • refactor(SPEC-1663): rename divergent compliance catalog types off shared names
  • refactor(SPEC-1663): index.d.ts trio re-exports FileHash/FileMetadata/SpecAnnotation from types/
  • refactor(SPEC-1662): readFileOrNull — migrate 4 sites found by strengthened meta test
  • refactor(SPEC-1662): apply review fixes — enoent code check, meta-test coverage, comment cleanup
  • refactor(SPEC-1662): readFileSafe family — consolidate into src/core/shared
  • refactor(SPEC-1662): escapeRegex family — consolidate into src/core/shared
  • refactor(SPEC-1662): escapeHtml — consolidate into src/core/shared
  • refactor(SPEC-1662): fileExists/pathExists — consolidate into src/core/shared
  • refactor(SPEC-1662): setup — create src/core/shared and allow engine/storage/tools to import it
  • refactor(SPEC-1661): invert hook dispatch via injected handler; add layer-inversion tests
  • refactor(SPEC-1661): invert dashboard status update via injected handler
  • refactor(SPEC-1661): consolidate generateSpecId and spec-id schema in engine
  • refactor(SPEC-1661): remove now-unused src/types/storage-bundle.ts
  • refactor(SPEC-1661): break types->storage inversion in StorageBundle
  • refactor(SPEC-1661): move InstallationRecord/InstallationManifest into types

Chores

  • chore: scope mutation gate to mutated-range suites via dedicated vitest config
  • chore(SPEC-1669/1670): record approval and implementing transitions
  • chore(SPEC-1674): record done transition and release pending entry
  • chore(SPEC-1674): transition to implementing
  • chore(SPEC-1663): record done transition and session context
  • chore(SPEC-1663): record implementing transition
  • chore(SPEC-1662): record done transition and session artifacts
  • chore(SPEC-1662): record implementing transition
  • chore(SPEC-1664): record done transition and session artifacts
  • chore(SPEC-1664): record implementing transition
  • chore(SPEC-1661): record done transition and session artifacts
  • chore(SPEC-1661): record implementing transition
  • chore(SPEC-1660): record done transition and session artifacts
  • chore(SPEC-1660): record implementing transition
  • chore(SPEC-1660): reconcile ownership format and risk section for handoff gate
  • chore: absorb post-done session state
  • chore(SPEC-1320): record done transition
  • chore(SPEC-1320): record implementing transition and fix stale verification command

[5.3.68] - 2026-08-28

Features

  • feat(SPEC-1666): produce source-quality receipt pre-bump with fail-fast gate order

Bug Fixes

  • fix(SPEC-1668): scope metric masking, byte-equality guard and uniform anchors per dual review
  • fix(SPEC-1668): bind product-proof bump regeneration fields and harden fixture commit retry
  • fix(SPEC-1666): align release-pipeline recovery suite with bump-neutral receipt contract
  • fix(SPEC-1666): byte-preserving carrier normalization with derivation checks and mode-bound masking
  • fix(SPEC-1315): classify degraded reads in portable spec-path migration
  • fix(SPEC-1315): verify canonical root and trigger migration on lifecycle reads
  • fix(SPEC-1315): keep spec paths portable across worktrees and release clones

Chores

  • chore: absorb post-done session state
  • chore(SPEC-1668): record done transition
  • chore(SPEC-1668): record approval transition
  • chore(SPEC-1666): record done transition
  • chore(SPEC-1666): record implementing transition
  • chore(SPEC-1315): record done transition and session state
  • chore(specs): approve SPEC-1660..1664 with reviewer and discovery evidence

[5.3.67] - 2026-08-28

Bug Fixes

  • fix(SPEC-1214): make readiness executable-evidence fallback reachable outside planu/specs
  • fix(SPEC-1214): align readiness and validation on one executable-evidence contract
  • fix(SPEC-1306): forward caller cwd as explicit projectPath in CLI status

Chores

  • chore(SPEC-1315): transition to implementing
  • chore: mark SPEC-1306/SPEC-1214 done and file SPEC-1664 dogfood bug

[5.3.66] - 2026-08-28

Bug Fixes

  • fix(SPEC-1314): distinguish registry metadata from publish manifests in privacy gates

[5.3.65] - 2026-08-28

Bug Fixes

  • fix(SPEC-1655,SPEC-1656,SPEC-1657): normalize persisted architecture, delegate lifecycle git shim, tighten agent-spec detection

[5.3.64] - 2026-08-27

Bug Fixes

  • fix(SPEC-1264): merge shared implementation-review adapter with arbitrated fixes
  • fix(SPEC-1257): merge post-transition observability drain with arbitrated fixes
  • fix(SPEC-1264): apply arbitrated dual-review fixes
  • fix(SPEC-1294): merge grounded execution plans with arbitrated dual-review fixes
  • fix(SPEC-1294): apply arbitrated dual-review fixes
  • fix(SPEC-1264): unify implementation-review verification behind one shared adapter
  • fix(SPEC-1257): isolate postcommit and cascade launches from request scope, drain on stdio shutdown
  • fix(SPEC-1329): merge grounded challenge capability gates with review fix round
  • fix(SPEC-1329): widen outbound-call detection and drop narrative comments
  • fix(SPEC-1294): ground execution plans in approved contract and preserve foreign plans
  • fix(SPEC-1329): gate challenge templates on positive capability evidence
  • fix(SPEC-1301): route every CLI json-mode result through one shared writer
  • fix(SPEC-1652): reject title-less create_spec input before path redaction
  • fix(SPEC-1301): emit one structured JSON document in CLI global json mode

Chores

  • chore(SPEC-1257): record implementing transition
  • chore(SPEC-1329): record implementing transition
  • chore(planu): record SPEC-1652 and SPEC-1301 done transitions
  • chore(SPEC-1294): record implementing transition
  • chore(SPEC-1294): record approval transition
  • chore(planu): move SPEC-1652 and SPEC-1301 to implementing
  • chore(planu): approve SPEC-1652 and discard SPEC-1653 with codex evidence
  • chore(planu): rescope SPEC-1652 after dual review and file SPEC-1654 dogfood bug

[5.3.63] - 2026-08-27

Bug Fixes

  • fix(SPEC-1644): stop emitting the default architecture rule and every line-cap instruction
  • fix(SPEC-1643): remove the empty typescript-patterns builtin skill
  • fix(SPEC-1371): compute branch cleanup against main with literal protected matching
  • fix(SPEC-1646): discriminate contradiction findings by offending criterion
  • fix(SPEC-1646): discriminate contradiction findings by offending criterion
  • fix(SPEC-1645): widen the load-bearing separator class per dual review
  • fix(SPEC-1645): stop treating load-bearing as a scale signal

Chores

  • chore(planu): file goal stop-hook loop dogfood bug
  • chore(SPEC-1644): record done transition
  • chore(planu): file SPEC-1651 and SPEC-1652 dogfood bugs
  • chore(SPEC-1644): record approved status
  • chore(SPEC-1643): mark acceptance criteria done
  • chore(SPEC-1643): lifecycle transition to approved
  • chore(planu): record SPEC-1371 approval and SPEC-1649 filing
  • chore(SPEC-1646): record approval transition
  • chore(SPEC-1645): record done transition

[5.3.62] - 2026-08-26

Bug Fixes

  • fix(SPEC-1639,1640,1641,1642): four dogfood defects in challenge, gates, coverage and sync

Chores

  • chore(planu): close SPEC-1639, SPEC-1640, SPEC-1641 and SPEC-1642

[5.3.61] - 2026-08-26

Refactoring

  • refactor(SPEC-1636): remove two unenforced agent rules and migrate their conventions
  • refactor(SPEC-1638): delete orphaned config assets and dead type modules

Chores

  • chore(SPEC-1636): close spec with dual-provider implementation review evidence
  • chore(SPEC-1636): approve after five-round dual-provider review
  • chore(SPEC-1638): record done-state lifecycle artifacts
  • chore(SPEC-1638): qualify the ios template path in canonical scope
  • chore(SPEC-1638): declare executable scenarios for the compliance runner
  • chore(SPEC-1638): mark acceptance criteria done after verified implementation

[5.3.60] - 2026-08-26

Bug Fixes

  • fix(SPEC-1634): normalize scenario test-link descriptions across colon spacing
  • fix(SPEC-1634): accept path-shaped colon forms in scenario tests entries
  • fix(SPEC-1633): point the documented human validation gate at validate:full

Refactoring

  • refactor(SPEC-1633): dedupe validate against check:strict in the release plan

Chores

  • chore(planu): close SPEC-1633 and SPEC-1634
  • chore(SPEC-1633,SPEC-1634): normalize file ownership and risk sections for the handoff gate
  • chore(SPEC-1633,SPEC-1634): approve both specs with challenge resolution

[5.3.59] - 2026-08-26

Bug Fixes

  • fix(SPEC-1631): report graph coverage as unavailable instead of zero gaps

Chores

  • chore(planu): close SPEC-1631
  • chore(planu): record SPEC-1631 implementing transition

[5.3.58] - 2026-08-26

Bug Fixes

  • fix(SPEC-1317): assert the dynamic-import edge for the pending-release helper
  • fix(SPEC-1319): close review findings on enricher integrity wiring
  • fix(SPEC-1317): align doctor deep-check count with the installation-integrity check
  • fix(SPEC-1319): block stale review-enricher runtimes from truncating canonical specs
  • fix(SPEC-1317): diagnose and recover incomplete CLI installs without crashing planu status

Refactoring

  • refactor(SPEC-1319): move enrichment integrity validator to a neutral module
  • refactor(SPEC-1317): extract pending-ledger rewrite to satisfy the function-length gate

Chores

  • chore(planu): close SPEC-1317 and SPEC-1319
  • chore(SPEC-1319): integrate review-enricher integrity and stale-dist guard
  • chore(SPEC-1317): integrate incomplete-install doctor and release-metadata degradation
  • chore(planu): record SPEC-1317 implementing state
  • chore(planu): record SPEC-1319 implementing and fix SPEC-1317 files ownership

[5.3.57] - 2026-08-26

Bug Fixes

  • fix(SPEC-1316): stop non-array ledgers and silent reachability failures from losing pending releases
  • fix(build-freshness): stop bricking a legit checkout when git is unavailable
  • fix(build): reject stale local dist before dispatch (SPEC-1318)
  • fix(build-freshness): allow diff-clean commits past the build stamp
  • fix(release): classify pending releases by git reachability (SPEC-1316)
  • fix(build): support reftable HEAD and tolerate a dirty-build-then-commit push
  • fix(release): close three fail-open gaps in pending-release reconciliation
  • fix(build): treat uncompiled TypeScript execution as not-applicable
  • fix(release): classify pending releases by git tag reachability, not date
  • fix(build): reject stale local dist output before CLI/MCP dispatch

Chores

  • chore(planu): close SPEC-1316 and SPEC-1318
  • chore(planu): add executable scenarios to SPEC-1316/1318 and file SPEC-1631
  • chore(planu): record SPEC-1316/1318 implementing transitions
  • chore(planu): add missing Create subsection to SPEC-1316 files ownership
  • chore(planu): approve 5 more specs after adding implementation contracts and test-break evidence
  • chore(planu): approve 6 reviewed specs, discard 2 stale after independent review
  • chore(planu): discard 9 speculative feature specs and 5 already-fixed gate specs
  • chore(planu): session checkpoint after v5.3.56

[5.3.56] - 2026-08-25

Bug Fixes

  • fix(tests): anchor the revert-proof fixture to a pushed pre-guard tag
  • fix(release): name the failing command and its real termination cause
  • fix(release): name the blocking effect and fail closed on a broken tag lookup
  • fix(release): re-anchor a superseded recovery ledger instead of dead-ending
  • fix(worktree): reclaim content-equivalent worktrees and read the canonical branch

Chores

  • chore(planu): close SPEC-1626
  • chore(planu): close SPEC-1630
  • chore(planu): close SPEC-1625
  • chore(planu): close SPEC-1624, file SPEC-1629 transition-log rotation
  • chore(planu): file SPEC-1625 and SPEC-1626 release-pipeline dogfood bugs

[5.3.55] - 2026-08-25

Bug Fixes

  • fix(update-status): classify git-status degradation in spec artifact guard
  • fix(worktree): drop only proper ancestors when eliminating base candidates
  • fix(challenge): stop telling users to record accepted-risk evidence
  • fix(worktree): validate worktree base against the canonical branch
  • fix(gates): surface schema blockers in dod-gate rejections
  • fix(contradiction-checker): close Path B on the criterion, not the scope
  • fix(cli): add package-handoff command and honest EISDIR blocker
  • fix(contradiction-checker): require predicate-position action assertion
  • fix(spec-format): anchor single-line GIVEN/WHEN/THEN criterion regex
  • fix(reconciliation): refresh stored title on the forward reconcile route
  • fix(challenge-spec): stop reading a negated word as risk acceptance
  • fix(cli): forward SDD evidence flags from spec status to the canonical mapping
  • fix(update-status): refresh stored title from rewritten frontmatter
  • fix(challenge): close resolution bullets on blank line
  • fix(challenge): match resolution evidence against finding text
  • fix(challenge): scope networkApi to a proximity-guarded bare API token
  • fix(storage): stream transition-log reads to survive oversized lines
  • fix(challenge): stop affirming capabilities from finding-field narration
  • fix(update-status): discard a spec whose artifact is absent
  • fix(validate): report unresolvable test links as unverifiable, not missing
  • fix(update-status): drop the narrative JSDoc from the spec-artifact gate
  • fix(update-status): refuse implementing transition on uncommitted spec.md
  • fix(update-status): name the challenge-resolution ingress in gate blockers

Refactoring

  • refactor(contradiction-checker): drop rationale comments in favor of names

Chores

  • chore(planu): file SPEC-1624, clear integrated worktrees
  • chore(planu): refresh session context
  • chore(planu): refresh session context and release ledger

[5.3.54] - 2026-08-25

Bug Fixes

  • fix(worktree): drop only proper ancestors when eliminating base candidates
  • fix(challenge): stop telling users to record accepted-risk evidence
  • fix(worktree): validate worktree base against the canonical branch
  • fix(gates): surface schema blockers in dod-gate rejections
  • fix(contradiction-checker): close Path B on the criterion, not the scope
  • fix(cli): add package-handoff command and honest EISDIR blocker
  • fix(contradiction-checker): require predicate-position action assertion
  • fix(spec-format): anchor single-line GIVEN/WHEN/THEN criterion regex
  • fix(reconciliation): refresh stored title on the forward reconcile route
  • fix(challenge-spec): stop reading a negated word as risk acceptance
  • fix(cli): forward SDD evidence flags from spec status to the canonical mapping
  • fix(update-status): refresh stored title from rewritten frontmatter
  • fix(challenge): close resolution bullets on blank line
  • fix(challenge): match resolution evidence against finding text
  • fix(challenge): scope networkApi to a proximity-guarded bare API token
  • fix(storage): stream transition-log reads to survive oversized lines
  • fix(challenge): stop affirming capabilities from finding-field narration
  • fix(update-status): discard a spec whose artifact is absent
  • fix(validate): report unresolvable test links as unverifiable, not missing
  • fix(update-status): drop the narrative JSDoc from the spec-artifact gate
  • fix(update-status): refuse implementing transition on uncommitted spec.md
  • fix(update-status): name the challenge-resolution ingress in gate blockers

Refactoring

  • refactor(contradiction-checker): drop rationale comments in favor of names

Chores

  • chore(planu): file SPEC-1624, clear integrated worktrees
  • chore(planu): refresh session context
  • chore(planu): refresh session context and release ledger

[5.3.53] - 2026-08-25

Bug Fixes

  • fix(update-status): name the challenge-resolution ingress in gate blockers

Chores

  • chore(planu): refresh session context and release ledger

[5.3.52] - 2026-08-25

Bug Fixes

  • fix(deps): align hono override with the upgraded dependency

Chores

  • chore(deps): batch patch and minor updates, hold stryker at 9.6.1

[5.3.51] - 2026-08-25

Bug Fixes

  • fix(evidence-gates): derive rejection templates from the rejecting schema

Chores

  • chore(planu): close SPEC-1578 and file SPEC-1601

[5.3.50] - 2026-08-24

Bug Fixes

  • fix(response): render one icon and one emphasis span in reconcile and accuracy titles

[5.3.49] - 2026-08-24

Features

  • feat(website): approved-contract redesign, GitHub Sponsors donation, clearer hero

Bug Fixes

  • fix(website): allow self-hosted woff2 fonts in public asset inventory

[5.3.48] - 2026-08-24

Bug Fixes

  • fix(spec-1600): recognize weakening-family verbs in scope contradiction detection

[5.3.47] - 2026-08-24

Bug Fixes

  • fix(spec-1599): make handoff ownership and spec-review approval errors self-serviceable

Chores

  • chore(planu): record SPEC-1599 done and file SPEC-1600 dogfood spec

[5.3.46] - 2026-08-24

Bug Fixes

  • fix(spec-1285): meta filter sees backticked tool token; harden AC1 coverage
  • fix(spec-1285): stop local privacy specs activating auth/meta challenge families

Chores

  • chore(planu): record SPEC-1285 done and SPEC-1598 discarded (merged into SPEC-1285)

[5.3.45] - 2026-08-24

Bug Fixes

  • fix(spec-1278): derive coherent challenge pass semantics from unresolved critical findings
  • fix(spec-1326): prevent registry release language from activating web-auth challenge families

Chores

  • chore(planu): record SPEC-1278 done state and file SPEC-1597 dogfood spec

[5.3.44] - 2026-08-24

Bug Fixes

  • fix(spec-1596): align check-readiness validator test double with getSpecFresh
  • fix(spec-1594): gate example-only PII identifiers behind boundary-aware collection cue
  • fix(spec-1593): gate suppress-family verbs so no-op consequence criteria are not misflagged
  • fix(spec-1595): make strict readiness report reflect edited spec body content

[5.3.43] - 2026-08-24

Bug Fixes

  • fix(spec-1293): gate minimality install-command patterns by provenance/negation context
  • fix(spec-1277): match PII vocabulary by identifier segments and exact equality
  • fix(spec-1225): make formatSuccess idempotent to prevent double-wrapped success titles
  • fix(spec-1299): scan only comment tokens for debt markers, ignore string literals
  • fix(spec-1298): exclude generic test/path tokens from scope-boundary matching

[5.3.42] - 2026-08-23

Bug Fixes

  • fix(spec-1310): resolve relative --project-path at CLI boundary before lifecycle delegation

[5.3.41] - 2026-08-23

Bug Fixes

  • fix(spec-1591): recognize relax-family verbs in scope-contradiction noun-overlap guard

[5.3.40] - 2026-08-23

Bug Fixes

  • fix(spec-1590): feed full multi-line BDD criteria to scope-contradiction check

Chores

  • chore(planu): sync state after SPEC-1590 done
  • chore(spec-1273): mark done and reconcile Files with regenerated artifacts

[5.3.39] - 2026-08-23

Bug Fixes

  • fix(spec-1589): credit criteria whose acceptance-to-verification map test passes
  • fix(spec-1273): expose request_changes and estimate on canonical MCP surface

Chores

  • chore(planu): sync autopilot state for SPEC-1273/1589 done
  • chore(spec-1556): discard as resolved by SPEC-1507

[5.3.38] - 2026-08-23

Bug Fixes

  • fix(spec-1517): populate preflight guard map + fail-closed rot detector

[5.3.37] - 2026-08-23

Bug Fixes

  • fix(spec-1561): replace non-portable grep -P health checks with pure-Node fastFindPatterns

[5.3.36] - 2026-08-23

Bug Fixes

  • fix(spec-1566): admit bare build phase in release resume phasePattern

[5.3.35] - 2026-08-23

Bug Fixes

  • fix(spec-1488): scope marker-declared path extraction to the path-list run after each marker

[5.3.34] - 2026-08-22

Bug Fixes

  • fix(spec-1588): fail closed on unresolved placeholders in raw generator output
  • fix(spec-1509): stop check_readiness false positives on error-outcome and clean criteria
  • fix(spec-1551): derive Goal and User Outcome from first acceptance criterion

[5.3.33] - 2026-08-21

Bug Fixes

  • fix(spec-1587): scope creation-time placeholder scan to standalone line content
  • fix(spec-1586): harden scoreAmbiguity against tautological substring-pairs and unanchored markers

Chores

  • chore(planu): sync autopilot state for SPEC-1586/1587

[5.3.32] - 2026-08-21

Bug Fixes

  • fix(spec-1585): harden scope-boundary contradiction checker against topical false positives

[5.3.31] - 2026-08-21

Bug Fixes

  • fix(spec-1584): exclude .claude/worktrees from Stryker sandbox to survive residual worktrees

Chores

  • chore(planu): file SPEC-1584 (Stryker worktree dangling-symlink) draft

[5.3.30] - 2026-08-20

Bug Fixes

  • fix(spec-1583): drop redundant access() precheck that TCC-fails website-proof
  • fix(spec-1581): re-verify receipt+log integrity on evidence-only drift
  • fix(spec-1581): done gate rebinds evidence-only traceability drift

Chores

  • chore(planu): SPEC-1581 done + SPEC-1582 draft filed

[5.3.29] - 2026-08-20

Bug Fixes

  • fix(spec-1580): macOS keychain set() self-heals with non-interactive security-CLI access

[5.3.28] - 2026-08-20

Bug Fixes

  • fix(spec-1577): single universal TS-only release artifact, remove native crate

[5.3.27] - 2026-08-19

Bug Fixes

  • fix(spec-1575): require clause to assert forbidden action for outOfScope contradiction
  • fix(spec-1539): require real independent implementation-review before done

Chores

  • chore(spec-1539-1575): close done ceremonies, reconcile specs, file SPEC-1576

[5.3.26] - 2026-08-19

Bug Fixes

  • fix(spec-1569-1572): host-LLM legacy migration, gitignore allowlist, scope+section guards

Chores

  • chore(spec-1569-1572): mark legacy-migration and guard specs done

[5.3.25] - 2026-08-18

Bug Fixes

  • fix(spec-1562,1568): contain client output paths across all writers and default spec array fields

[5.3.24] - 2026-08-18

Bug Fixes

  • fix(spec-1558): regenerate source-quality receipt bound to the amended release commit
  • fix(spec-1553): declare attachedAt in the published validate output schema
  • fix(spec-1553): name the receipt publication cause instead of one flat string
  • fix(spec-1554): bound the Technical extractor to the section heading level
  • fix(spec-1552): surface the stored rejection reason in done-drift diagnostics
  • fix(spec-1549): resolve out-of-scope items from the spec document, not the cache
  • fix(spec-1525): admit prose file paths outside src/ and tests/ without truncating them
  • fix(spec-1540): scope the native lockfile mask to a version-controlled lockfile
  • fix(spec-1524): bind the source-quality receipt to a mask-normalized tree digest

Chores

  • chore(spec-1553): close lifecycle with reconciled scope and done evidence
  • chore(spec-1524): close lifecycle with reconciled scope and done evidence

[5.3.23] - 2026-08-13

Bug Fixes

  • fix(spec-1520): exclude paths whose only mention negates the work from grounded modify targets

[5.3.22] - 2026-08-13

Bug Fixes

  • fix(spec-1523): bind isolated rebuild sidecar provenance to the build-source commit
  • fix(spec-1521): pin native provenance across the lockfile-integrity amend
  • fix(spec-1519): bound acknowledgement latency at a tail ceiling, not a bare SLO constant
  • fix(spec-1518): scope PLANU_RELEASE_MODE out of the source-quality phase
  • fix(spec-1518): scope release-build env out of the source-quality phase
  • fix(deps): drop vulnerable extract-zip by forcing puppeteer-core 25
  • fix(spec-1506,spec-1507): align release invariant and lint budget with shipped behaviour
  • fix(spec-1506,spec-1507): correct native lockfile integrity and uncache every gate

[5.3.21] - 2026-08-12

Bug Fixes

  • fix(spec-1499,spec-1500): portable path redaction and a cheap pre-flight gate

Chores

  • chore(planu): refresh session context after SPEC-1505 intake

[5.3.20] - 2026-08-12

Bug Fixes

  • fix(release): unblock validate and privacy gates for v5.3.20
  • fix(spec-1495): ground the outOfScope recommendation in the spec document
  • fix(spec-1483): fail the native build on a version-mismatched artifact

[5.3.19] - 2026-08-11

Bug Fixes

  • fix(spec-1492): size release budgets to the longest child chain per test
  • fix(spec-1492): coordinate release-harness spawn and test budgets
  • fix(spec-1486): raise load-tolerant timeout budgets in script-gate and heartbeat tests
  • fix(spec-1482): update validate.test.ts lint timeout and message assertions per review
  • fix(spec-1482): honor mid-run lint evidence on timeout and right-size lint caps

Chores

  • chore(spec-1492): record done transition with review and traceability evidence
  • chore(spec-1486): record done transition with traceability and validation evidence
  • chore(spec-1486): approve arbitrated script-gate timeout spec with dual-review evidence
  • chore(spec-1486): add durable-job-heartbeat beforeAll hookTimeout reproducer
  • chore(spec-1482): record done transition with traceability and validation evidence
  • chore(spec-1482): approve arbitrated lint-gate timeout spec with dual-review evidence

[5.3.18] - 2026-08-11

Bug Fixes

  • fix(spec-1476): phrase-bind data-consistency scenario signals and drop dead catalog

Chores

  • chore(spec-1476): record done transition with validation and review evidence
  • chore(spec-1476): approve spec with arbitrated dual-review evidence and start implementing

[5.3.17] - 2026-08-11

Bug Fixes

  • fix(spec-1487): normalize spec paths in toRepoRelativePath per implementation-review arbitration
  • fix(spec-1487): exclude Planu bookkeeping paths from traceability autofill and done drift gate

Chores

  • chore(specs): record SPEC-1487 done transition
  • chore(spec-1487): record implementation-review round and approved scope amendment

[5.3.16] - 2026-08-11

Bug Fixes

  • fix(spec-1477): bound publication-window wait per implementation-review arbitration
  • fix(spec-1477): publication window blocks same-identity lease supersession mid-receipt

Chores

  • chore(specs): record SPEC-1477 done transition and file SPEC-1487 dogfood bug

[5.3.15] - 2026-08-11

Bug Fixes

  • fix(spec-1403): apply implementation-review arbitration fixes
  • fix(spec-1403): make destructive housekeeping report-only under typed authority

Chores

  • chore(spec-1403): record done transition with arbitration evidence

[5.3.14] - 2026-08-10

Bug Fixes

  • fix(spec-1481): bound trapped fixture life per implementation-review arbitration
  • fix(spec-1481): harden stdio abort test vs load and de-vacuize pid asserts
  • fix(spec-1466): apply implementation-review arbitration fixes
  • fix(spec-1467): require positive integer pid in waitForPid per review arbitration
  • fix(spec-1466): legalize test-evidence overlap in ownership gate and handoff agreement
  • fix(spec-1467): harden timing-sensitive receipt and process-runner tests

Chores

  • chore(specs): file SPEC-1484 durable heartbeat flaky test dogfood bug
  • chore(specs): file SPEC-1483 stale native artifacts after release abort
  • chore(specs): record SPEC-1481 done transition and file SPEC-1482 lint-gate bug
  • chore(specs): file SPEC-1481 flaky stdio lifecycle test under full-suite load
  • chore(specs): record done transitions for SPEC-1466/1467 and file SPEC-1480 debt spec
  • chore(specs): record implementing transitions for SPEC-1466/1467 with handoff evidence
  • chore(specs): approve SPEC-1466/1467 after round 2; file SPEC-1479

[5.3.13] - 2026-08-10

Bug Fixes

  • fix(spec-1468): word-boundary guard on evidence marker truncation
  • fix(lifecycle): evidence-only rebind + planu digest exclusion (SPEC-1468)
  • fix(spec-1469): close path-echo exemption bypass found in implementation review
  • fix(spec-quality): path-token guard in restatement check + actionable gate rejection (SPEC-1469)

Chores

  • chore(spec-1468): record done transition lifecycle state
  • chore(spec-1469): record done transition lifecycle state
  • chore(planu): capture auto-generated session context
  • chore(specs): move SPEC-1468/1469 to implementing
  • chore(specs): approve SPEC-1468/1469 after round-2 dual review + arbitration

[5.3.12] - 2026-08-10

Bug Fixes

  • fix(release): cap smoke retries at 3 attempts regardless of delay overrides
  • fix(release): retry transient CLI smoke failures with backoff and per-attempt diagnostics

Chores

  • chore(spec-1462): record done transition and release bookkeeping

[5.3.11] - 2026-08-09

Bug Fixes

  • fix(update-status): stop fabricating spec reviewer evidence on review transition

Chores

  • chore(spec-1464): mark done with validation and dual-review evidence
  • chore(planu): SPEC-1464 approved after 3-round dual review; move to implementing
  • chore(planu): session checkpoint after v5.3.10 release

[5.3.10] - 2026-08-09

Bug Fixes

  • fix(orchestration): derive file-conflict ownership from persisted spec bodies (SPEC-1461)

Chores

  • chore(spec-1461): mark done after validate 100/100 and dual review
  • chore(spec-1461): sync spec v1.3.1 into branch and strip narrative comments
  • chore(planu): SPEC-1461 lifecycle after dual review; file SPEC-1463/SPEC-1464
  • chore(planu): file SPEC-1462 (transient smoke CLI failure) and record v5.3.9 release state

[5.3.9] - 2026-08-09

Bug Fixes

  • fix(spec-format): reject prose bullets in Files-section ownership parsing
  • fix(code-scanner): bound implementation-detection evidence to spec-owned paths

Chores

  • chore(planu): record SPEC-1219 done transition and duplicate-cluster discards

[5.3.8] - 2026-08-09

Bug Fixes

  • fix(spec-1460): exempt freshly published @planu/cli from the pnpm minimum-release-age gate
  • fix(spec-1458): render index-only verification rows so the gate accepts its own output

Chores

  • chore(planu): record SPEC-1460 done transition
  • chore(planu): record SPEC-1458 done transition
  • chore(planu): session checkpoint after v5.3.7 release

[5.3.7] - 2026-08-08

Bug Fixes

  • fix(scope-boundaries): split sentences regardless of next-sentence casing
  • fix(validate): fail lint on timeout and bound unbounded validate gates
  • fix(spec-1450): anchor scope-contradiction substring checks to word boundaries

Chores

  • chore(spec-1453): redact local home path from reproducer
  • chore(planu): record SPEC-1449 and SPEC-1450 done transitions
  • chore(spec-1450): integrate scope-contradiction matching after arbitrated review
  • chore(spec-1449): integrate validate gate timeouts after dual-provider approve
  • chore(specs): cut speculative scope from the skills backlog
  • chore(spec-1449): approve after 6-round independent review + Discovery evidence
  • chore(deps): override nanoid to >=3.3.17 for GHSA-2v37-7h3g-55p8
  • chore(planu): sync session state after SPEC-1449/1450 review cycle

[5.3.6] - 2026-08-07

Bug Fixes

  • fix(spec-1404): make filesystem hook watcher observation-only
  • fix(spec-1427): recognize exposed/exposes as affirmative scope drift
  • fix(spec-1427): stop scope-contradiction check from flagging boundary-preserving criteria
  • fix(spec-1415): arbitrate independent Codex review, harden fence and marker matching
  • fix(spec-1415): heal 35 truncated spec.md bodies with a one-shot script
  • fix(spec-migrator): preserve actionable estimation during portable spec import
  • fix(spec-1429): cover the two untested acceptance criteria and correct stale claims
  • fix(tests): match CLAUDE.md's current canonical release gate commands
  • fix(spec-format): stop discarding BDD criteria mixed with checklist bullets
  • fix(challenge-spec): count the challenge gate requirement against distinct scenario names

Refactoring

  • refactor(spec-migrator): extract importSpecEntry to satisfy max-lines-per-function

Chores

  • chore(planu): redact absolute home path from public spec reproducers
  • chore(planu): sync session state after SPEC-1403/1404 closure
  • chore(spec-1404): mark done after independent implementation review
  • chore(planu): move SPEC-1449/1450 to review with challenge resolution evidence
  • chore(planu): file SPEC-1449/1450 dogfood bugs, sync session state
  • chore(spec-1427): mark spec done and drop duplicate test ownership entry
  • chore(spec-1415): reconcile Files scope for done gate, file SPEC-1447 dogfood bug
  • chore(planu): approve SPEC-1415 after challenge/grounding gate fixes
  • chore(planu): sync SDD lifecycle state for SPEC-1404/1415/1427, file SPEC-1445/1446
  • chore(planu): mark SPEC-1429 and SPEC-1431 done, file SPEC-1443/1444
  • chore(planu): sync session-context checkpoint
  • chore(planu): close 8 verified-stale backlog specs

[5.3.5] - 2026-08-06

Bug Fixes

  • fix(tests): make the spec-write guard test independent of git HEAD
  • fix(lifecycle): close done-gate bypass, report digest drift and ship debate rules
  • fix(reconcile): harden audit-cell escaping and fail-closed rollback (SPEC-1250)
  • fix(spec-format): preserve wrapped BDD continuation lines in criterion identities (SPEC-1253)

Chores

  • chore(planu): close SPEC-1250 with debate evidence, file SPEC-1424
  • chore(planu): SPEC-1253 done with debate evidence
  • chore(planu): file SPEC-1423 (done-gate revalidate reprocessing)
  • chore(planu): file SPEC-1421 and SPEC-1422 from client dogfood report

[5.3.4] - 2026-08-06

Bug Fixes

  • fix(deps): override js-yaml to patched versions for CVE-2026-59870
  • fix(spec-format): keep rendered criteria BDD-executable after canonical parsing
  • fix(spec-format): resolve rendered criteria through the canonical parser (SPEC-1410)
  • fix(spec-quality): render and count every acceptance criterion (SPEC-1410)
  • fix(planu): point SPEC-1405 verification map at the real test filename
  • fix(spec-quality): stop shipping template filler and self-certifying spec sections (SPEC-1406)
  • fix(drift): make follow-up spec id deterministic per parent spec (SPEC-1405)
  • fix(drift): emit one drift event per project instead of one per spec (SPEC-1405)

Chores

  • chore(planu): SPEC-1405 and SPEC-1406 done with debate evidence
  • chore(planu): SPEC-1405 and SPEC-1406 implementing with packaged handoffs
  • chore(planu): approve SPEC-1405 and SPEC-1406 with debate evidence, file SPEC-1410..1411
  • chore(planu): file SPEC-1401..1409 from deep flow audit
  • chore(planu): SPEC-1396 done with debate evidence, file SPEC-1397..1400

[5.3.3] - 2026-08-06

Bug Fixes

  • fix(release): tolerate empty ff-behind mirror list under set -u
  • fix(outbox): return a typed failure from delivery attempts for the reliability gate
  • fix(git): close SPEC-1396 debate findings and record review evidence
  • fix(git): never move the shared checkout from automatic paths (SPEC-1396)
  • fix(outbox): address SPEC-1271 debate review findings
  • fix(outbox): bounded fair durable spec.created recovery without blocking startup (SPEC-1271)

Chores

  • chore(planu): file SPEC-1396 git-safety dogfood bug
  • chore(planu): session checkpoint after SPEC-1271 cycle
  • chore(planu): SPEC-1271 done with debate evidence, file SPEC-1395
  • chore(planu): SPEC-1271 implementing with structured work plan, file SPEC-1394

[5.3.2] - 2026-08-06

Bug Fixes

  • fix(tools): restore declared bump_spec_version runtime tool (SPEC-1254)
  • fix(handoff): address SPEC-1255 debate review findings
  • fix(handoff): allow test-only specs to produce unblocked handoffs (SPEC-1255)

Chores

  • chore(planu): redact local paths from SPEC-1392 reproducer
  • chore(planu): SPEC-1254 and SPEC-1255 done with debate-review evidence
  • chore(planu): session checkpoint for debate-protocol batch
  • chore(planu): approve SPEC-1254/1255/1271, file SPEC-1386..1391, add debate-review rule
  • chore(planu): approve SPEC-1206 and SPEC-1250 with reviewer evidence, SPEC-1240 rework feedback

[5.3.1] - 2026-08-05

Bug Fixes

  • fix(session-safeguard): abort detect via FETCH_HEAD, drop invalid push --ff-only, harden refs
  • fix(session-safeguard): never autopush protected branches and detect pushed bump in release abort

Refactoring

  • refactor(tests): split release-pipeline suite, harness cache, mirror auto-sync

Chores

  • chore(planu): SPEC-1384 done state and SPEC-1385 dogfood bug spec
  • chore(planu): SPEC-1379 done state
  • chore(planu): split incidental session-context churn out of SPEC-1379 delta
  • chore(planu): file SPEC-1381 challenge resolution, SPEC-1382 operator guides, SPEC-1383 validate budget dogfood specs
  • chore(planu): SPEC-1378 done state and v5.3.0 session checkpoint

[5.3.0] - 2026-08-05

Features

  • feat(watchers): ignore non-actionable root events in validation freshness watchers (SPEC-1340)
  • feat(release): harden local release pipeline — auth preflight, receipt env isolation, publish retry, visibility wait (SPEC-1369)

Bug Fixes

  • fix(release): accept npm 12 keyed pack JSON across release gates (SPEC-1339)
  • fix(validator): stop marking provably implemented test-only criteria as indeterminate (SPEC-1367)
  • fix(deps): raise brace-expansion and postcss transitive floors past advisories (SPEC-1338)
  • fix(readiness): fail strict readiness when canonical BDD extraction returns zero criteria (SPEC-1321)
  • fix(lifecycle): route implementation review digests to done gates without entering reconciliation (SPEC-1328)
  • fix(privacy): redact minimality policy locators from persisted artifacts (SPEC-1334)
  • fix(create-spec): remove hardcoded test-framework commands from generated specs (SPEC-1234)
  • fix(challenge): preserve title evidence in event capability detection (SPEC-1235)
  • fix(release): enforce proprietary license and canonical plugin tool parity (SPEC-1236)

Tests

  • test(release): make release preflight/receipt regressions deterministic under full-suite load (SPEC-1207)
  • test(release): reconcile full test suite with local-only release policy and rollback semantics (SPEC-1373)

Chores

  • chore(deps): update 11 patch/minor dependencies
  • chore(planu): close stale lifecycle for SPEC-1010/1011 tool-reliability specs and record SPEC-1010 tech debt
  • chore(planu): file SPEC-1374/1375/1376 dogfood bug specs

[5.2.0] - 2026-08-04

Features

  • feat(autopilot): refresh semantic index fire-and-forget on spec:created (SPEC-1345)
  • feat(i18n): auto-detect and persist user locale (SPEC-1347)
  • feat(spec-language): offer translation instead of rejecting non-English specs (SPEC-1342)
  • feat(semantic-search): persist index with incremental updates (SPEC-1345)

Bug Fixes

  • fix(storage): classify non-ENOENT failures in sync global-config read
  • fix(status): prefer implementing work over review work in compact status (SPEC-1228)
  • fix(challenge): stop handler names activating event scenarios across clauses (SPEC-1262)

Performance

  • perf(core-bridge): route main-thread hot paths through native dispatch (SPEC-1344)
  • perf(init-project): parallelize independent pipeline stages (SPEC-1343)

Chores

  • chore(website): regenerate deterministic product proof
  • chore(planu): close lifecycle for 8 specs done + SPEC-1368 bug spec + session checkpoint
  • chore(planu): file SPEC-1367 dogfood bug spec (validate false-negative on test-only criteria)
  • chore(planu): file SPEC-1366 dogfood bug spec and refresh session context
  • chore(doctor): remove commercial remnants and deepen diagnostics (SPEC-1346)
  • chore(planu): file SPEC-1365 dogfood bug spec (teamSuggestion recommends unregistered tools)
  • chore(planu): session checkpoint after v5.1.1 release

[5.1.1] - 2026-08-04

Bug Fixes

  • fix(release-harness): resolve published artifact from staged repack when publish has no tarball argv
  • fix(release): stop CLI-guard stdout pollution, npm view array probe, and tarball-path publish leak

[5.1.0] - 2026-08-04

Features

  • feat(lifecycle): automate done evidence pipeline end to end

Bug Fixes

  • fix(update-status): make typed failure explicit at dod-gates catch sites
  • fix(deps): patch hono, fast-uri, ip-address, and undici advisories via overrides
  • fix(evidence-gates): derive contract example kinds from filenames
  • fix(reverse-engineer): share walk-ignore list and add fast release-gate test lane
  • fix(challenge): suppress ungrounded concurrency boilerplate in challenge_spec
  • fix(update-status): report per-spec failure reasons in batch results
  • fix(create-spec): guarantee spec.md write before reporting persisted
  • fix(create-spec): release idempotency claim when create_spec fails before commit
  • fix(release): accept npm 12 pack metadata
  • fix(deps): patch transitive security advisories
  • fix(privacy): redact minimality policy locators
  • fix(lifecycle): route review evidence by target
  • fix(readiness): unify canonical validation evidence

Chores

  • chore(pnpm): disable modules purge confirmation for non-TTY automation
  • chore(planu): session checkpoint before release
  • chore(planu): close SPEC-1350 lifecycle state
  • chore(planu): hand off freshness blocker
  • chore(planu): checkpoint release handoff
  • chore(planu): preserve native engine review state
  • chore(planu): persist delayed challenge evidence
  • chore(planu): recover delayed audit specs
  • chore(planu): capture lifecycle dogfood failures
  • chore(planu): persist release remediation handoffs
  • chore(planu): approve final release blockers
  • chore(planu): start dependency security remediation
  • chore(planu): approve final security remediation
  • chore(planu): checkpoint final release remediations
  • chore(planu): start lifecycle routing implementation
  • chore(planu): approve lifecycle routing remediation
  • chore(planu): checkpoint release remediation specs
  • chore(planu): track v5 release dogfood regressions

[5.0.0] - 2026-07-31

Breaking Changes

  • Removed Planu commercial plans, license activation, trials, project/spec limits, daily commercial quotas, and the Lemon Squeezy entitlement surface.
  • All local tools are available without payment under the Planu Proprietary Free-Use License. The official unmodified package may be used commercially or non-commercially with unlimited users and instances; the repository and TypeScript implementation remain private and proprietary.
  • Removed the public license commands, entitlement fields, environment variables, and tier-based tool metadata. Consumers must remove those obsolete fields instead of relying on compatibility aliases.
  • Removed the orphaned product-intelligence public types and embedded telemetry/feedback project endpoints and credentials. Telemetry delivery now requires explicit PLANU_TELEMETRY_ENDPOINT and PLANU_TELEMETRY_TOKEN configuration; remote feedback requires PLANU_FEEDBACK_ENDPOINT.

Security and Distribution

  • Preserved engineering budgets, hosted authentication and authorization, transport abuse controls, dependency-license auditing, model pricing, runtime timeouts, local usage health, and generic outbound webhooks.
  • Added narrow, idempotent cleanup for obsolete commercial state and a forward Supabase migration that removes trial data without rewriting migration history.
  • Hardened npm packaging to allow public .d.ts declarations while rejecting implementation .ts, source maps, embedded sources, personal paths, and personal identity metadata.

Community

  • Kept direct BTC, ETH, and SOL donations, sponsorship channels, testimonials, and the disabled-until-configured newsletter contract.

[4.14.1] - 2026-07-29

Bug Fixes

  • fix(release): defer native install verification
  • fix(release): make local artifacts authoritative

[4.14.0] - 2026-07-29

Features

  • feat: make Planu local-first and harden release integrity

Bug Fixes

  • fix(native): constrain napi generator compatibility
  • fix(native): pin compatible napi code generator
  • fix(release): validate rebuilt native artifacts
  • fix(release): bump native build manifest
  • fix(release): synchronize session context version
  • fix: classify freshness degradation paths
  • fix: make validation freshness deterministic
  • fix: make transactional locks crash-safe
  • fix: benchmark native runtime in worker threads
  • fix: classify lock degradation paths
  • fix: await init repository hook writes
  • fix: make cross-process leases transactional
  • fix: publish cross-process locks atomically
  • fix: complete process cancellation before settling

[4.13.0] - 2026-07-27

Features

  • feat(website): animate support journey

[4.12.3] - 2026-07-27

Features

  • feat: add accessible donation beacon

[4.12.2] - 2026-07-27

Bug Fixes

  • fix: restore dark language menu contrast

[4.12.1] - 2026-07-27

Bug Fixes

  • fix: prevent personal metadata exposure (#62)

[4.12.0] - 2026-07-27

Features

  • feat(website): add multichain donations (#61)

[4.11.20] - 2026-07-27

Bug Fixes

  • fix(website): align desktop landing controls (#60)
  • fix(release): bind reproducibility to annotated tags (#59)

Chores

  • chore(planu): close SPEC-1155 lifecycle

[4.11.19] - 2026-07-27

Bug Fixes

  • fix(website): repair responsive visual system (#58)
  • fix(website): close production delivery gaps (#57)

Refactoring

  • refactor(website): simplify landing around real evidence (#55)

Chores

  • chore(planu): close SPEC-1153
  • chore(planu): close SPEC-1151 lifecycle

[4.11.18] - 2026-07-26

Bug Fixes

  • fix(security): remove exposed receipt from website

[4.11.17] - 2026-07-26

Bug Fixes

  • fix: clear released specs from pending ledger

[4.11.16] - 2026-07-26

Bug Fixes

  • fix: restore trustworthy maintenance audit gates

[4.11.15] - 2026-07-26

Bug Fixes

  • fix: stabilize project graph freshness (#51)

[4.11.14] - 2026-07-25

Bug Fixes

  • fix: parse canonical active spec status (#50)

[4.11.13] - 2026-07-25

Chores

  • chore(deps): update ESLint to 10.8.0 (#49)

[4.11.12] - 2026-07-25

Bug Fixes

  • fix(deps): remediate brace-expansion advisory

Chores

  • chore(planu): close SPEC-1142 lifecycle
  • chore(planu): close SPEC-1141 lifecycle

[4.11.11] - 2026-07-24

Bug Fixes

  • fix: finalize release state reconciliation
  • fix: preserve pnpm policy in Docker builds

Chores

  • chore(deps): refresh routine dependencies

[4.11.10] - 2026-07-24

Bug Fixes

  • fix: preserve verified release artifacts

Chores

  • chore: harden release and state reconciliation

[4.11.9] - 2026-07-20

Bug Fixes

  • fix: keep release session context current

[4.11.8] - 2026-07-20

Bug Fixes

  • fix: make pre-commit checks fail closed
  • fix: pin release-eligible transitive dependencies
  • fix: sync release lockfile before build
  • fix: stabilize quality gate execution
  • fix: harden lifecycle and release reliability

[4.11.7] - 2026-07-18

Bug Fixes

  • fix: harden shell execution paths

[4.11.6] - 2026-07-18

Bug Fixes

  • fix: tighten SDD gates and release readiness
  • fix: allow routine dependency drift during pre-push

Chores

  • chore: finalize weekly debt spec state

[4.11.5] - 2026-07-18

Bug Fixes

  • fix: close weekly technical debt backlog

[4.11.4] - 2026-07-18

Bug Fixes

  • fix(planu): unblock challenge gate and record debt specs
  • fix(release): harden local recovery environment

[4.11.3] - 2026-07-10

Bug Fixes

  • fix(release): classify npm 404 visibility correctly
  • fix(planu): harden release and grounded spec flow

[4.11.2] - 2026-07-10

Bug Fixes

  • fix(specs): ground lifecycle output and adopt TypeScript 7

Chores

  • chore(deps): update patch dependencies

[4.11.1] - 2026-07-09

Bug Fixes

  • fix: benchmark representative graph sources
  • fix: verify release lockfile with pinned pnpm

[4.11.0] - 2026-07-09

Features

  • feat: add native project graph and value-only specs

Bug Fixes

  • fix: stabilize native graph release benchmark

[4.10.12] - 2026-07-08

Chores

  • chore(planu): mark SPEC-1116 done

[4.10.11] - 2026-07-08

Bug Fixes

  • fix(validate): honor executable spec compliance score

[4.10.10] - 2026-07-08

Bug Fixes

  • fix(create-spec): merge readiness-compliant spec generation
  • fix(create-spec): generate readiness-compliant technical details

[4.10.9] - 2026-07-07

Bug Fixes

  • fix: promote SPEC-1115 validation scorer evidence
  • fix: merge SPEC-1115 validation scorer evidence
  • fix(SPEC-1115): require complete traceability evidence

Chores

  • chore: refresh native dependency lock metadata

[4.10.8] - 2026-07-07

Refactoring

  • refactor: merge SPEC-1113 native performance benchmark
  • refactor: benchmark native mcp performance

Chores

  • chore: exclude generated performance report

[4.10.7] - 2026-07-07

Bug Fixes

  • fix(SPEC-1114): reduce MCP token waste

Chores

  • chore(deps): update patch/minor dependencies
  • chore(planu): clear released pending specs

[4.10.6] - 2026-07-07

Bug Fixes

  • fix(SPEC-1111): stabilize update_status done gates and evidence state transitions
  • fix(SPEC-1112): preserve validation-report lint evidence during done gate

Improvements

  • refactor(SPEC-1110): reduce MCP token payloads with local-first tool classification

[4.10.5] - 2026-07-07

Bug Fixes

  • fix(SPEC-1109): resolve audit backlog

[4.10.4] - 2026-07-06

Bug Fixes

  • fix: resolve Supabase testimonials and Planu bug backlog

Chores

  • chore(deps): update tsc-alias
  • chore(planu): clear released pending specs
  • chore(format): apply prettier baseline

[4.10.3] - 2026-07-02

Bug Fixes

  • fix(SPEC-1106): reduce validate response duplication
  • fix(SPEC-1106): harden critical fallback paths

[4.10.2] - 2026-07-02

Bug Fixes

  • fix(SPEC-1105): preserve legacy spec ids during init migration

[4.10.1] - 2026-07-01

Bug Fixes

  • fix: prevent generated spec artifacts and refresh graph status

[4.10.0] - 2026-07-01

Features

  • feat(SPEC-1100): add reliable feedback sync

Bug Fixes

  • fix(SPEC-1102): honor release preflight test skip
  • fix(SPEC-1101): harden validate runtime and status

Chores

  • chore(deps): refresh direct dependencies

[4.9.0] - 2026-06-30

Features

  • feat(SPEC-1099): add structural memory layer

Chores

  • chore(planu): clear released pending specs

[4.8.0] - 2026-06-24

Features

  • feat(website): refine Planu landing
  • feat(website): refine Planu landing

[4.7.5] - 2026-06-24

Features

  • feat: add Planu minimal-change rule and guidance inspired by Ponytail

Bug Fixes

  • fix: keep generated Planu session artifacts stable after lifecycle close

Chores

  • chore(deps): refresh push-gate dev dependency knip

[4.7.4] - 2026-06-23

Bug Fixes

  • fix: implement SPEC-1091-1094 tech debt bundle

Chores

  • chore(deps): refresh push-gate dev dependencies

[4.7.3] - 2026-06-19

Features

  • feat: add reversible context compaction

Chores

  • chore(deps): update patch and minor dependencies

[4.7.2] - 2026-06-16

Features

  • feat(SPEC-1088): add policy-driven minimal implementation gate

Chores

  • chore(deps): update patch/minor dependencies

[4.7.1] - 2026-06-12

Chores

  • chore(planu): close stale SPEC-1084 metadata

[4.7.0] - 2026-06-12

Features

  • feat(SPEC-1085): add project knowledge graph

Bug Fixes

  • fix(security): override esbuild patched release

Chores

  • chore(deps): refresh push-gate dependencies

[4.6.1] - 2026-06-12

Bug Fixes

  • fix(SPEC-1086): handle Vitest 4 JSON paths in validate

[4.6.0] - 2026-06-11

Features

  • feat(SPEC-1084): add token waste autopilot

Chores

  • chore(deps): sync lockfile
  • chore(deps): update patch dependencies

[4.5.0] - 2026-06-10

Features

  • feat(create-spec): generate intent-grounded questions

Chores

  • chore(deps): update release tooling

[4.4.3] - 2026-06-09

Features

  • feat(SPEC-1081): add skill security scan gate
  • feat(SPEC-1082): add implementation contract readiness

[4.4.2] - 2026-06-05

Bug Fixes

  • fix: keep spec folders spec.md-only and store evidence externally

[4.4.1] - 2026-06-04

Bug Fixes

  • fix: make validate spec-scoped and non-mutating

Chores

  • chore(deps): sync lockfile
  • chore(deps): update patch and minor dependencies

[4.4.0] - 2026-06-03

Features

  • feat: add grounded SDD gates and evidence metrics

[4.3.24] - 2026-06-02

Chores

  • chore(deps): align update check validation

[4.3.23] - 2026-06-02

Chores

  • chore(deps): refresh direct dependencies

[4.3.22] - 2026-06-02

Bug Fixes

  • fix: stop fabricating spec and test artifacts

[4.3.21] - 2026-06-02

Bug Fixes

  • fix: enforce canonical spec ids and harden fallback specs

[4.3.20] - 2026-05-27

Bug Fixes

  • fix(SPEC-1073): make lifecycle state writes idempotent

[4.3.19] - 2026-05-27

Bug Fixes

  • fix(SPEC-1072): clean spec advisory surfaces

[4.3.13] - 2026-05-25

Bug Fixes

  • fix(ci): scope release shasum extraction

[4.3.12] - 2026-05-25

Bug Fixes

  • fix(release): avoid self-referential tarball sha

[4.3.11] - 2026-05-25

Bug Fixes

  • fix: close critical Planu delivery specs

[4.3.9] - 2026-05-25

Tarball SHA-256: a47146af1f2f8e695247fb6ee92cc8da8de00b2ab7967734a7faade7f3659aeb

Bug Fixes

  • fix: keep MCP stdio output JSON-only

Chores

  • chore: sync release banner version

[4.3.5] - 2026-05-24

Features

  • feat(codegraph): expose Colby CodeGraph setup and status tools on the official MCP surface

Bug Fixes

  • fix(create-spec): render structured post-creation suggestions as readable next steps
  • fix(mcp): guard malformed human-facing tool output before it reaches clients

[4.3.4] - 2026-05-22

Tarball SHA-256: e1ac042fd623c1421d7a0788fed14c369472489180ffe80eb8bce4d422d360d8

Bug Fixes

  • fix(planu): keep host adapters outside managed state

[4.3.3] - 2026-05-22

Tarball SHA-256: d681d7d176a263f3b059c4ed5fbc7647a17758dc3c56cc79fd47658bab082fe6

Bug Fixes

  • fix(planu): expose update_status routing evidence

[4.3.2] - 2026-05-22

Tarball SHA-256: 7732de964d5e10d24bdab5ea79baee3d281654cf5caff1f713671502c8e09ee3

Bug Fixes

  • fix(security): enforce moderate vulnerability gate

[4.3.0] - 2026-05-22

Tarball SHA-256: ebc3e7fe0a284d6ba6062dfb9aab41fe6e9396a7763c6d39764d676d20a0b6c3

Features

  • feat(planu): enforce BDD SDD evidence gates

[4.2.6] - 2026-05-22

Tarball SHA-256: 07356a69166b2f47742118dcf06af14a105a44bb27024d6e28213c433530089e

Bug Fixes

  • fix(docker): restore Railway Rust build inputs

[4.2.5] - 2026-05-22

Tarball SHA-256: 24d98e6b384752a806fc97a9828afaa94a0281a077e99ff06923e46119a69422

Features

  • feat(planu): export reviewer gates to project rules

[4.2.4] - 2026-05-22

Tarball SHA-256: 963c0c81820ad002206299f102fdcae6635d96cdbe2e602e4f1dbb2d1b41e0c5

Features

  • feat(planu): require spec reviewer before approval

[4.2.3] - 2026-05-22

Tarball SHA-256: 6d23ef6f7bd12e2a94eb9984e272beb37cd0d9b54ad12170529f95ca870e46a4

Features

  • feat(planu): require implementation reviewer gate

[4.2.2] - 2026-05-21

Tarball SHA-256: 83193f54dc2fc5f461ef38b8bf2a9931d5d587ece50c77836942351e39b3c415

Bug Fixes

  • fix(release): isolate npm publish cache
  • fix(release): sync native lockfile without moving dev dependencies
  • fix(ci): harden dependency freshness parsing

[4.2.1] - 2026-05-21

Tarball SHA-256: 9ff8a396e25eba3e4941bbef80ee19cc41bae46eaafa703cd32092c7ffbfdf2e

Bug Fixes

  • fix(release): add windows native core packages

[4.2.0] - 2026-05-21

Tarball SHA-256: d036f3d5f73279fc0a12935995f899950fdf06afe454bba49da748183e07f477

Features

  • feat(onboarding): add new project technology contract

Bug Fixes

  • fix(release): sync native package versions

[4.1.4] - 2026-05-21

Bug Fixes

  • Centralize Rust-first hot-path fallback behavior in core-bridge so callers use native acceleration when available and TypeScript fallbacks consistently when unavailable.
  • Keep crash scanning, broad validation reads, gaps log verification, HMAC signing, duplicate detection, and layer scanning resilient when native reads return partial results or test doubles expose older nullable bridge behavior.
  • Lock published native optional dependencies across macOS and Linux architectures in pnpm so release dependency checks remain cross-platform stable.

Tests

  • Re-run the full suite with 31,275 passing tests and 5 skipped tests.

[4.1.3] - 2026-05-21

Bug Fixes

  • Make the TypeScript file watcher fallback portable across operating systems by avoiding non-portable recursive fs.watch mode.
  • Keep the native-core fallback path non-fatal when a platform-specific binary is unavailable.

Tests

  • Add coverage to prevent reintroducing recursive watcher mode in the portable fallback.

[4.1.2] - 2026-05-21

Bug Fixes

  • Remove unused legacy Planu files from the runtime surface and keep license tool registration strict.
  • Restore missing OAuth MCP registrations for start_oauth_flow, oauth_status, and configure_oauth.
  • Harden generated Git hooks so changed-file JSON generation avoids awk portability failures and integer parsing warnings.

Tests

  • Add hook-generation coverage for portable post-commit changed-file handling.

[4.1.1] - 2026-05-21

Features

  • Enforce dependency freshness as a blocking pre-push gate for lockfile drift, high/critical vulnerabilities, and outdated direct dependencies.
  • Add the same pnpm dependency freshness guard to Planu-generated pre-push hooks.

Tests

  • Add coverage for the dependency freshness script and generated hook contents.

[4.1.0] - 2026-05-21

Features

  • Enforce English-only persisted Planu artifacts across specs, skills, agent instructions, and rules.
  • Gate host-aware init scaffolding for AGENTS.md, CLAUDE.md, Cursor, Windsurf, Cline, Gemini, Codex, and OpenCode generated AI docs.
  • Keep user-authored host file content intact while validating only Planu-owned generated blocks.

Tests

  • Add coverage for skill, rule, and agent instruction language gates across core writers and host generators.

[4.0.0] - 2026-05-20

Tarball SHA-256: 8c00d74f48ed5614197000a967b103cc17653150aadf876fcfd18d0174263017

[3.9.12] - 2026-05-19

Tarball SHA-256: cd07a22fdfc0c982726a918c1e47f147ca300ecad710e8377f1751ef993fea60

Bug Fixes

  • fix(specs): purge legacy spec artifact writers

Chores

  • chore(claude): reconcile typescript skill asset
  • chore(claude): remove unavailable skill artifact

[3.9.11] - 2026-05-17

Tarball SHA-256: a201430a93ae5f87af8322409c328266c29b340e890eb2fa49c7181da32886d3

Bug Fixes

  • fix(types): keep duplicate export gate deterministic
  • fix(release): prevent banner and project id drift

[3.9.6] - 2026-05-15

Tarball SHA-256: 56592815d33401b0cd7aa1d02ca26c7dda8dd131176841ccda3163932e53b43b

[3.9.5] - 2026-05-15

Tarball SHA-256: 11fa506c006e59292069158b32b580ab861cfb71ea5fefa60c5308fbf55b129a

Bug Fixes

  • fix(website): sync release page metadata

[3.9.4] - 2026-05-15

Tarball SHA-256: 3134c2a699545d591999710da271b725a4d38c697756eced767971d02f9de62e

Bug Fixes

  • fix(reconcile): enforce Claude asset cleanup gates

Chores

  • chore(reconcile): remove stale Claude rules and skills

[3.9.3] - 2026-05-15

Tarball SHA-256: cc411a544962db6b38087b081ea847f73042f280d2ee9600c971cb1f2778db73

Bug Fixes

  • fix(tests): update release smoke mocks for pnpm dlx
  • fix(release): smoke test scoped cli with pnpm dlx

[3.9.2] - 2026-05-15

Tarball SHA-256: 3768f401213d28afacbca964d7318d079e92d5f4d454b78705f9995c272034ac

Bug Fixes

  • fix(release): allow own native core packages in license audit
  • fix(tests): stabilize release preflight checks
  • fix(release): support lock fallback without flock
  • fix(specs): enforce English structured spec generation
  • fix: stabilize mcp slim test suite

[3.9.0] — 2026-05-12 — Single official SDD MCP surface

Changed — Planu now exposes one focused MCP surface

Planu no longer presents a large tiered MCP tool catalog to the agent. The official MCP server now exposes exactly the 14 tools needed for the end-to-end SDD loop: planu_status, facilitate, init_project, clarify_requirements, create_spec, challenge_spec, check_readiness, update_status, package_handoff, validate, reconcile_spec, create_rule, create_skill, and skill_search.

Advanced capabilities remain available internally, through CLI workflows, and through skills where appropriate, but they are no longer part of the default MCP tool list. This makes Planu lighter, cheaper in tokens, and easier for agents to use correctly.

Fixed — MCP startup and tool-list stability

  • Added a canonical registerSddTools MCP registration path instead of loading every tool group and filtering afterward.
  • Removed the old full/slim MCP split and the related tool-list compacting layer.
  • Updated smoke coverage so tools/list must match the official 14-tool contract exactly.
  • Bootstraps prompt handlers before transport connection so the MCP server can register UX surfaces safely after handshake.

Verification

  • pnpm build:ts
  • ESLint on touched files ✓
  • pnpm vitest run tests/smoke.test.ts ✓ 10/10

[3.8.0] — 2026-05-07 — SPEC-1012 release-spec-closer

Fixed — Sovereign-orchestrator gap: specs released to npm stayed in implementing indefinitely

SPEC-1007 was released as v3.3.0 but its status frontmatter stayed implementing for 4 minor versions (3.4.0 → 3.7.0) until manually corrected. Planu now closes the loop: any chore(release): bump vX.Y.Z commit on main that references SPEC-NNN IDs auto-transitions those specs to done AND keeps the JSON store (specs.json) in sync — no more status.jsonspec.md drift across releases.

Added

  • src/engine/release-pipeline/parse-spec-refs.ts — pure, ReDoS-safe parser. Walks line-by-line to mask fenced code blocks (handles unclosed fences from CI-truncated logs), then masks inline backticks. Supports SPEC-NNN, [SPEC-NNN], (SPEC-NNN), comma-separated, lowercase. Dedupes + uppercases output.
  • src/engine/release-pipeline/release-spec-closer.tscloseSpecsOnReleasePublish({ commitSha, version, projectPath }). Gates: (1) merge-base --is-ancestor origin/main so feature-branch SHAs cannot force-close specs, (2) idempotent skip for already-done/discarded specs. Writes are SPEC-720 sanctioned: spec.md via atomicWriteFile + specStore.__internalSetStatus so JSON store stays synced.
  • src/engine/drift-detection/release-status-drift.tsdetectReleaseStatusDrift(projectPath) walks last 50 commits on origin/main, parses SPEC IDs from release commits (requires vX.Y.Z sigil — plain chore: refactor does NOT match), cross-references vs spec frontmatter, returns DriftReport[]. applyReleaseStatusDriftFix further gates on git tag --points-at presence so only really-tagged commits trigger auto-close.
  • Tool wiringlist_specs + planu_status (status-handler.ts) append staleStatusWarnings non-blocking. housekeeping_sweep adds a release-status-drift step with auto-fix. scripts/release-local.sh emits planu/data/release-events.jsonl after publish for future async consumers.

Hardening (dual-Opus review fixes)

  • Status frontmatter operations scoped to findFrontmatterEnd() — never matches body prose like status: blocked in a code example.
  • History entries inserted at END of ## History section — chronological order preserved.
  • ## History regex anchored to line start — prose mentioning ## History no longer triggers in-place insert.
  • Quoted status values (status: "implementing") round-trip cleanly to status: done.
  • _skipFreezeCheck removed — the closer never targets frozen specs, so the safety rail stays active.

Tests

  • 91 tests pass across 11 test files (parse-spec-refs, release-spec-closer, idempotency, release-status-drift, housekeeping-sweep-release-drift, list-specs, status-handler, housekeeping-sweep).
  • Coverage: BDD scenarios from spec — release auto-close, drift detection, idempotency, parser format coverage.

Validation

  • pnpm typecheck ✓ · pnpm lint ✓ · pnpm exec vitest run tests/engine/release-pipeline/ tests/engine/drift-detection/ 37/37 ✓ · existing tool tests 57/57 ✓.

[3.7.0] — 2026-05-07 — SPEC-1010 (PR-C)

Fixed — SSR back-migration cleanup, part C (SPEC-1010 PR-C) — stop writing legacy files

PR-A removed the leaked technicalPath from the create_spec response. PR-B routed 17 readers through readSpecTechnicalSection(). PR-C closes the loop: no code path now writes standalone technical.md / progress.md files. All technical and progress content lives inline in the unified spec.md under ## Technical and ## Progress sections.

Added

  • src/engine/spec-format/replace-section.ts — exports replaceSectionInSpec(specPath, sectionName, newBody) that:
    1. Reads spec.md.
    2. Finds the named ## heading (fence-masked, CRLF-normalized — same hardening as extractSectionBody).
    3. If found: replaces the body in place, atomic-writes back.
    4. If missing: appends the section to EOF, atomic-writes.
    5. Returns { replaced: boolean; appended: boolean }.
  • 6 new tests in tests/engine/spec-format/replace-section.test.ts covering: replace-existing, append-when-missing, preserve-other-sections, idempotency, CRLF, fenced-code-block safety.

Changed — Writers redirected to the unified spec.md

  • src/tools/reconcile-spec.ts:163,191 — both atomicWriteFile(spec.technicalPath, ...) calls → replaceSectionInSpec(spec.specPath, 'Technical', ...).
  • src/tools/spec-split-handler.ts:185-187 — child specs no longer get a separate technical.md / progress.md. The synthesized child spec.md carries ## Technical and ## Progress inline.
  • src/tools/spec-portability-handler.ts:133 — bundle import now writes ## Technical into the imported spec.md instead of a sibling technical.md.
  • src/tools/update-status/file-sync.ts:155-159 — progress updates now mutate ## Progress in spec.md.
  • src/engine/living-spec-analyzer.ts:43-44updateProgressFile rewritten to write into ## Progress of spec.md.
  • src/tools/heal-spec-docs.ts:300-341 — heal regenerates the ## Technical section inline; dry-run diff points at the unified file.
  • src/engine/scan-project/index.ts — orchestrator no longer materializes 2-file structure; emits unified spec.md per generated spec.
  • src/types/spec-format.ts — added ReplaceSectionResult interface.

Validation

  • grep "atomicWriteFile.*\.md\|writeFile.*\.md" src/ confirms no remaining legacy-file writers.
  • tsc --noEmit: 0 errors.
  • eslint --max-warnings 0: 0 warnings.
  • 1047 tests pass (2 skipped, 0 fail) across 87 affected test files.

Deferred to PR-D

  • Type-system cleanup (~252-file blast radius): drop technicalPath / progressPath / fichaTecnicaPath from Spec. Today these fields are kept populated for backwards compat with stored data; PR-D removes them entirely once all consumers stop reading them.
  • storage/spec-store.ts legacy normalizer + autopilot migration log.
  • Init-project generator templates that still scaffold a 2-file structure (Level 3 in the original SPEC-1010 plan).
  • src/tools/export-spec.ts:121 — uses a different wrapper (readFileContent); deferred to keep PR-C scoped.

[3.6.0] — 2026-05-07 — SPEC-1010 (PR-B)

Fixed — SSR back-migration cleanup, part B (SPEC-1010 PR-B) — 11 silent-degradation readers

The SSR back-migration in SPEC-752 (v2.4.0) folded technical.md into the unified spec.md as a ## Technical section, but 11 reader call sites in src/ still called readFile(spec.technicalPath, 'utf-8') to read technical content. For any spec created after v2.4.0, that file is empty/missing, silently degrading downstream analysis quality. PR-B introduces a single source of truth for "give me the technical body for this spec".

Added

  • src/engine/spec-format/read-technical-section.ts — exports readSpecTechnicalSection(spec) that:
    1. Reads ## Technical from spec.md (the unified format).
    2. Falls back to legacy technical.md only when the unified section is empty (transitional safety net for pre-migration data).
    3. Returns "" on any error — never throws.
  • src/engine/spec-format/read-technical-section.ts also exports extractSectionBody(body, sectionName) — a regex-escaped section-body extractor reusable across the codebase.
  • 9 new tests in tests/engine/spec-format/read-technical-section.test.ts covering: extraction, escape semantics, EOF handling, empty fallback, error fallback, and unified-wins-over-legacy precedence.

Changed — 11 reader call sites switched to the helper

  • src/tools/detect-ac-gaps.ts, src/tools/design-schema.ts, src/tools/challenge-spec-helpers.ts, src/tools/analyze-spec-dependencies.ts, src/tools/red-team.ts, src/tools/summarize-spec.ts, src/tools/snapshot-spec-hashes.ts, src/tools/define-ui-contract.ts, src/tools/generate-adr/helpers.ts, src/engine/spec-conflict-graph.ts, src/engine/spec-registry/scorer.ts.

Each call site now reads the ## Technical section from spec.md directly. This restores the technical-content signal for red_team, challenge_spec, analyze_spec_dependencies, summarize_spec, snapshot_spec_hashes, detect_ac_gaps, design_schema, define_ui_contract, generate_adr, conflict-graph computation, and spec-registry scoring.

Tests

  • 4 existing test files updated to mock the new helper instead of the legacy readFile(spec.technicalPath) pattern: tests/tools/challenge-spec-helpers.test.ts, tests/tools/design-schema-main.test.ts, tests/tools/generate-adr.test.ts, tests/tools/snapshot-spec-hashes.test.ts.
  • Full affected suite: 1012/1012 tests pass.

Hardened — Dual-Opus PR review follow-ups (SPEC-1010 PR-B)

  • 6 additional readers in src/engine/ were missed by the initial sweep and would have continued the silent quality degradation. Now refactored to use the helper:
    • src/engine/validator/extractors.ts — validator's spec-content extraction
    • src/engine/validator/analyzer.ts — code-scan fallback for spec evidence
    • src/engine/execution-plan/plan-utils.tsreadSpecContent() for execution planning
    • src/engine/readiness-checker.ts — readiness-gate technical scoring
    • src/engine/spec-quality-scorer.ts — quality scoring against technical content
    • src/engine/plan-mode/plan-builder.ts — plan-mode plan synthesis After this fix, grep "readFile.*spec\.technicalPath" src/engine/ returns only the helper's own legacy fallback (line 36).
  • Fenced-code-block hardening in extractSectionBody: the regex now operates on a fence-masked variant of the body (preserving offsets) so a quoted markdown sample inside the spec body cannot match the heading regex nor the next-section terminator. Snapshot-spec-hashes is no longer at risk of silently tracking 0 files when a ## Files example appears inside a fence in ## Technical.
  • CRLF / mixed line endings normalized before scanning (Windows-authored specs).
  • Legacy technical.md fallback strips YAML frontmatter before returning, matching what the unified ## Technical section delivers (no leak of id: / status: keys into downstream keyDecisions extraction in summarize-spec).
  • 5 new tests covering: fenced-code-block false positives (heading + next-section), CRLF, ~~~ alternate fence syntax, legacy frontmatter strip.
  • 7 additional test files updated for the engine readers' new mock seam.

Deferred to PR-C

  • Level 1 — 5 writers: heal-spec-docs.ts, reconcile-spec.ts (write paths), spec-split-handler.ts, init-project/migration-runner.ts, reverse-engineer/handler.ts still write to standalone technical.md in some flows.
  • Level 4 — typesystem: drop technicalPath / progressPath / fichaTecnicaPath from the type surface (~252-file blast radius), plus storage/spec-store.ts legacy normalizer + autopilot migration log.
  • Level 3 (templates) — init-project generator templates that still scaffold a 2-file structure.
  • src/tools/export-spec.ts:121 still uses readFileContent(spec.technicalPath) (different wrapper). Tracked for PR-C.

[3.5.0] — 2026-05-07 — SPEC-1010 (PR-A)

Fixed — SSR back-migration cleanup, part A (SPEC-1010)

The SSR back-migration in SPEC-752 (v2.4.0) folded technical.md / progress.md into spec.md as ## Technical / ## Progress sections, but left readers, writers, types, generators, and tool descriptions across the codebase still referencing the deprecated files. SPEC-1010 lands in three incremental PRs to keep blast radius manageable. PR-A (this release) ships the user-visible quick wins:

  • Bug A — create_spec no longer leaks technicalPath in the response payload. The technical.md file is never written; the field would point at a non-existent path. Internal Spec.technicalPath is preserved temporarily for backwards compat with stored data; the field is removed in PR-C.
  • Bug C — section preservation in unified spec.md. When the user's description contains a ## Technical and/or ## Files section, buildUnifiedSpecContent no longer appends a duplicate. The user's content wins; only the missing sections are injected. Fixes the symptom where create_spec produced specs with two ## Technical sections (one user-authored, one autopilot-empty) or two ## Files sections (autopilot suggestions clobbering the user's file list).
  • Level 3 (partial) — .claude/rules/sdd-methodology.md updated to describe specs as a single unified spec.md (was: 2-file lean format).
  • Level 5 — tool descriptions cleansed of technical.md / progress.md references across src/tools/tool-registry/core-tools.ts, src/tools/tool-registry/group-integrations.ts, src/tools/register-spec-tools/core-spec-tools.ts, src/tools/register-spec-tools/analysis-tools.ts. LLMs reading tool metadata at session start now see the correct single-file format. grep -rn "technical\.md\|progress\.md" src/tools/tool-registry/ src/tools/register-spec-tools/ returns zero.

Tests

  • 5 new tests in tests/engine/spec-format/unified-spec-builder.test.ts covering Bug C: user-authored ## Technical not duplicated, user-authored ## Files not clobbered, both-present case returns body untouched, partial-present injects only what's missing, and a fenced-code-block edge case where literal ## Technical / ## Files lines inside a markdown sample no longer suppress auto-injection.

Hardened — Dual-Opus PR review follow-ups (SPEC-1010 PR-A)

  • Stale doc references in .claude/rules/sdd-methodology.md: removed two residual mentions of technical.md (the flow diagram on line 19 and the implicit-approval rule). The whole file now consistently describes the unified single-file format. Both reviewers (correctness + security) flagged this contradiction with 90–95 confidence.
  • Fenced-code-block hardening in unified-spec-builder.ts: ## Technical / ## Files heading detection now strips fenced code blocks (``` and ~~~) before scanning. This fixes a false-positive where a user description containing literal markdown samples (e.g. example specs) suppressed auto-injection of the missing sections.
  • Defensive regex escaping: extractSection's sectionName parameter is now passed through escapeRegex before being interpolated into the heading regex. Defensive hardening for future callers.

Deferred to PR-B / PR-C

  • PR-B: Level 2 — unify the 14 spec readers behind a shared readSpecTechnicalSection(spec) helper that extracts ## Technical from spec.md instead of reading a non-existent technical.md file. Fixes silent-quality-degradation in red_team, challenge_spec, analyze_spec_dependencies, summarize_spec, etc.
  • PR-C: Level 1 (5 writers) + Level 4 (drop technicalPath / progressPath / fichaTecnicaPath from the type system, ~252 file blast radius, plus storage/spec-store.ts legacy normalizer + autopilot migration log) + Level 3 generator templates.

[3.4.0] — 2026-05-07 — SPEC-1011

Fixed — Four silent bugs in core tools (SPEC-1011)

Bug D — reconcile_spec silent write failure

reconcile_spec was incrementing the version counter and reporting success even when no text changes reached spec.md on disk. The tool now delegates actual body text replacement to src/engine/reconcile/apply-changes.ts (applyChangesToSpec), then immediately re-reads the file via src/engine/reconcile/verify-write.ts (verifyWriteSucceeded). If verification fails, the tool returns isError: true with { postWriteVerificationFailed: true, specUpdated: false, rolledBack: true } and the version counter is NOT saved.

Bug E — create_spec injects unrelated autopilot-guessed file paths into ## Files

create_spec was always passing autopilot-suggested file paths to generateLeanTechnicalContent, populating ## Files with unrelated paths even when the user's description contained no ## Files section. The guard const descriptionHasFilesSection = /^##\s+Files\b/m.test(description) now gates injection — when absent, only (to be determined) placeholders appear. Suggested files are surfaced exclusively in the autopilotSummary.suggestedFiles response payload.

Bug F — planu_status / challenge_spec say "Project not initialized" despite planu/ existing

Both tools returned "Project not initialized" when knowledge.json was missing even if planu/ and data/projects/{id}/ existed on disk. A new src/storage/project-resolver.ts module exports resolveProjectFromPath(), which falls back to disk fingerprint detection (checks dataDir, planuDir, planu/status.json, planu/specs/). On recovery it writes a minimal knowledge.json and logs a silent autopilot entry. Both tools now call this resolver before returning the "not initialized" error.

Bug G — status.json shows stale spec counts while disk has many more

status.json totalSpecs and byStatus could fall arbitrarily out of sync with what's actually on disk. handlePlanStatus now fires-and-forgets reconcileStatusFromDisk() (new src/engine/status-reconciler/index.ts) on every call. The reconciler scans planu/specs/ directories, parses each spec.md frontmatter for status, and atomically rewrites status.json (tmp + rename) when counts diverge.

Added

  • src/engine/reconcile/apply-changes.tsapplyChangesToSpec(specPath, changes)ApplyChangesResult
  • src/engine/reconcile/verify-write.tsverifyWriteSucceeded(specPath, changes)VerifyWriteResult
  • src/storage/project-resolver.tsresolveProjectFromPath(projectPath)ResolvedProject | null
  • src/engine/status-reconciler/index.tsreconcileStatusFromDisk(projectPath), computeSpecCountsFromDisk(projectPath)
  • src/types/reconcile.tsVerifyWriteFailure, VerifyWriteResult, SkippedChange, ApplyChangesResult, StatusReconcileResult, ResolvedProject
  • 7 new test files: tests/engine/reconcile/verify-write.test.ts, tests/tools/reconcile-spec.write-verification.test.ts, tests/tools/create-spec/no-file-injection.test.ts, tests/tools/create-spec/autopilot-analyzer.scope-anchored.test.ts, tests/storage/project-resolver.recovery.test.ts, tests/tools/status-handler.recovery.test.ts, tests/tools/challenge-spec.recovery.test.ts, tests/engine/status-reconciler/disk-sync.test.ts

Hardened — Dual-Opus PR review follow-ups (SPEC-1011)

After the initial implementation, a dual-Opus review on PR #17 surfaced two critical issues that are also fixed in this release:

  • Section-anchored apply-changes: applyChangesToSpec no longer uses String.replace against the whole document. Each change is bounded by its named section heading (## <section>), and the change is applied only when originalValue matches exactly once within that section's body. Ambiguous matches (>1 in section) and missing-section cases are recorded in skipped with reason — no silent cross-section mutations.
  • Atomic JSON writer for status.json: reconcileStatusFromDisk now uses the codebase's writeJsonSafe primitive (with backup rotation) instead of a hand-rolled ${path}.tmp.${pid} + rename. Eliminates the same-PID collision risk for concurrent reconciler invocations.
  • ENOENT vs corrupt distinguished: the reconciler refuses to clobber a status.json that exists but cannot be parsed (permission/EIO/JSON syntax). User-set fields are preserved; user must repair manually or run init_project.
  • Non-fatal skipped text changes: when originalValue is not a literal in the section body (legitimate for conceptual/metadata-style changes like "scope expanded"), reconcile_spec no longer errors — skipped entries surface in structuredContent.skippedTextChanges, and metadata-only manual changes still create a SpecVersion.
  • versionRolledBack flag replaces the misleading rolledBack flag on verification failure: the disk file was already written before verification ran; what we actually rolled back is the SpecVersion record, not the disk content.
  • database: 'unknown' replaces the hardcoded 'postgresql' fallback in resolveProjectFromPath's minimal-knowledge builder (zero-hardcoding compliance).
  • projectId-aware reconciler: reconcileStatusFromDisk(projectPath, projectId?) accepts an optional explicit projectId. When planu_status is invoked with an explicit projectId, the resolver fallback and reconciler fire-and-forget are skipped to preserve the caller's "no path-hashing" contract.
  • Shared RECONCILE_METADATA_SECTIONS constant in src/types/reconcile.ts, used by both apply-changes.ts (skip) and verify-write.ts (skip). Adding a new metadata section now requires a single edit.
  • 8 new tests in tests/engine/reconcile/apply-changes.test.ts covering section anchoring, ambiguity guard, missing section, cross-section safety, deep-heading bounds, metadata-skip, and read-failure paths. Plus 1 regression test in tests/tools/reconcile-spec.test.ts for the post-write verification failure path.

[3.3.0] — 2026-05-05

Changed — Project data dir anchored to absolute home (SPEC-1007)

projectDataDir(projectId) is now symmetric with globalDataDir: it returns an absolute path under ~/.planu/data/projects/{id} (override via PLANU_PROJECT_DATA_DIR), regardless of where the MCP server was launched from. The cwd-tolerant discovery added in v3.2.0 was a Phase 1 backwards-compatible patch; this release completes the architectural cleanup that v3.2.0 deferred.

  • Absolute path by default: src/storage/base-store.ts now derives the project root from process.env.PLANU_PROJECT_DATA_DIR ?? join(homedir(), '.planu', 'data'). Path-traversal (.., /, \\) on projectId throws upfront.
  • Automatic legacy migration: new src/storage/migrations/cwd-to-absolute.ts exposes migrateLegacyDataDir(projectId, cwd?). Called idempotently from loadAll (specs), getKnowledge/saveKnowledge, and init_project. Walks up to 8 ancestors of cwd looking for data/projects/{id}/knowledge.json and renames the legacy tree into the absolute home. Cross-filesystem moves fall back to fs.cp + anchor verify + rm -rf. Conflict (both legacy and absolute populated): legacy is renamed to <legacy>.legacy-{ISO_TS} and a console.warn is logged — never auto-merged.
  • Idempotency layers: an in-memory Set<projectId> short-circuits same-session repeats; a .migrated-from-cwd sentinel file short-circuits cross-session. A sibling ${absolute}.migration.lock (NOT inside absolute, so rename can run) prevents concurrent migrations across MCP processes.
  • Test isolation: new tests/setup.ts mkdtemps PLANU_PROJECT_DATA_DIR per-test for unit suites; e2e/integration/scripts suites are detected via expect.getState().testPath and own their own lifecycle untouched. PLANU_GLOBAL_DATA_DIR is only seeded if the test hasn't already set it.

Added

  • src/types/migration/cwd-to-absolute.tsCwdMigrationStatus (noop|migrated|conflict|error) and CwdMigrationResult.
  • migrateLegacyDataDir, clearMigratedThisSession, MIGRATION_INTERNALS — exported from src/storage/migrations/cwd-to-absolute.ts for callers and tests.
  • tests/storage/migrations/cwd-to-absolute.test.ts — coverage of noop / migrated / conflict / idempotency / env override / invalid projectId paths.

Notes

  • Backwards compatible: existing v3.2.x repos that already had cwd-relative data/projects/{id}/ trees are auto-migrated on the first read or write that touches that project. No manual step required.

[3.2.1] — 2026-05-05

Fixed — Spec migrator default + idempotency (SPEC-1008)

Two bugs in ssr_back_migration were leaving legacy technical.md files behind in client repos with many done specs:

  • Default skip-done flipped to migrate-done: ssr_back_migration now defaults allowDoneSpecs: true. Repos with hundreds of done specs no longer require flag-flipping to clear legacy artifacts. Callers that need the old behavior can still pass allowDoneSpecs: false explicitly.
  • already_unified branch deletes residual file: when spec.md already contains ## Technical, foldTechnicalIntoSpec now also unlinks the residual technical.md instead of leaving it behind. The unlink is non-fatal (handles the case where the file was already removed manually).

This release was preceded by a one-time manual cleanup of 714 residual technical.md files in this repo (commit 82612a90). With these fixes, the migrator self-heals on every run.

[3.2.0] — 2026-05-05

Fixed — Project data dir resilience (7 bugs in one release)

When clients launched Planu from a directory other than the one used at init_project, the cwd-relative data/projects/{hash}/ lookup silently missed all existing project state — specs, knowledge, hooks, everything. The 7 reported symptoms shared one root cause and are now resolved end-to-end.

  • Cwd-tolerant data dir discovery (Bug 3, 4, 6): new src/storage/data-dir-discovery.ts walks up from process.cwd(), then from the registered projectPath, anchored on knowledge.json (canonical ownership signal). getKnowledge, loadAll (specs), and handlePlanStatus now resolve project state regardless of where the MCP server was launched from. Cached per session for zero repeated I/O. Hash collisions in unrelated repos are ignored — only directories with knowledge.json qualify.
  • Ancestor-data detector for init_project (Bug 1): new src/tools/init-project/ancestor-data-detector.ts scans up from projectPath and cwd for existing data/projects/<id>/ dirs. When found, surfaces a warning telling the user their project state may be split — preventing silent state corruption when init_project is run from a parent directory of an already-initialized project.
  • Ephemeral path filter for registry (Bug 2): src/engine/data-projects-gc/pattern-matcher.ts now matches /var/folders/, /private/var/folders/, /tmp/, /private/tmp/ prefixes and planu-*-(test|spec|e2e|integration|fixture)-* basenames. global-projects-store.getProjects filters ephemeral entries on every read and fires a background prune. The registry no longer accumulates test temp dirs.
  • Eager registry refresh on register_project_path (Bug 5, 7): after addProject, the handler now invokes listSpecs(entry.hash) (cwd-tolerant) and persists the real specCount + lastScanAt immediately. No more stale specCount: 0 after registration when specs already exist on disk.

Added

  • discoverProjectDataFile(projectId, relative, cwd?) — public helper for any future store that needs cwd-tolerant reads.
  • clearDataDirCache() — test-only cache reset.
  • detectAncestorDataDirs(projectPath, projectId, cwd?) and buildAncestorDataWarning(report) — public helpers for the ancestor warning surface.
  • isEphemeralPathPrefix(projectPath) — exported predicate for OS-managed temp prefixes.

Notes

  • The architectural cleanup (anchoring projectDataDir to an absolute path symmetric with globalDataDir) is deferred to a dedicated SPEC + migration cycle in v3.3.0. The Phase 1 fix in this release is purely additive and backwards-compatible.

[3.1.6] — 2026-05-04

Fixed

  • create_spec infinite loop on payment/billing keywords: clarificationAnswers was completely ignored because the parameter had an underscore prefix (_params), making it unused. Any description matching billing/webhook/Stripe would loop endlessly regardless of answers provided. Fix: pass params correctly and short-circuit clarification when clarificationAnswers is non-empty.
  • detectBroadScope false positive on Stripe integrations: Descriptions like "Stripe billing with webhook handler" matched 2 subsystem patterns (billing + notification/webhook) and incorrectly triggered clarification as "broad scope". Fix: scale the threshold with word count — descriptions ≥20 words require 3 subsystem matches instead of 2 (a single payment feature naturally mentions adjacent domain terms).

[3.1.5] — 2026-05-04

Changed

  • create_spec clarification — zero hardcoding: removed generateInteractiveQuestions which produced pre-defined question templates with hardcoded options (billing model, payment provider, scope, etc.). When a description is too vague (needsClarification = true), Planu now returns a plain message telling the host LLM to ask its own contextual questions, then retry create_spec with the enriched description. The LLM determines what to ask — Planu no longer prescribes it.

[3.1.4] — 2026-05-04

Fixed

  • "planu · failed" in Claude Code: npx @planu/cli@latest runs the cli binary entry (dist/cli/index.js), not the MCP server entry (dist/index.js). When invoked with no arguments and piped stdin (MCP host context), the CLI entry now imports the MCP server module instead of printing help and exiting immediately.

[3.1.3] — 2026-05-04

Fixed

  • initialize response latency: Added a setImmediate yield after selectTransport so Node.js processes the buffered initialize request (stdin poll phase) before module loading begins (check phase). Previously, synchronous module evaluation blocked the event loop for ~3-4 s, delaying the initialize response and causing "Failed to reconnect" in Claude Code even after the handshake-gate fix in v3.1.2.

[3.1.2] — 2026-05-04

Fixed

  • MCP protocol ordering: Tool/resource notifications are now deferred until after the MCP handshake completes (initialize response + notifications/initialized from client). Previously, 9 dynamic imports fired ~1.5 s of file I/O before stdin was drained, causing Claude Code to receive hundreds of notifications/tools/list_changed events before the initialize response — violating the MCP protocol and preventing Planu from loading. A handshakeGate Promise now holds all module loading until server.server.oninitialized fires (10 s timeout fallback).

[3.1.1] — 2026-05-04

Fixed

  • MCP SDK invariant: Tools are now registered before the transport connects. The previous async-deferred approach (SPEC-1005) violated the MCP SDK rule that forbids calling server.tool() after transport.connect(), causing tools/list to return Method Not Found on fresh installs.
  • Rust facilitate tools: Removed lingering .await calls on handle_facilitate, handle_challenge_spec, handle_check_readiness, and handle_reconcile_spec after they were rewritten as sync functions (no Anthropic API calls).

[3.1.0] — 2026-05-04

Fixed — Native build is reproducible again

  • lib.rs ghost modules removed: the previous v3.0.0 commit declared 39 pub mod submodules that did not exist as files, leaving the Rust crate impossible to rebuild from source (30 compile errors). The shipped .node only worked because it was compiled before the bad commit. The submodule declarations have been removed.
  • napi_bridge restored: the #[napi] macro layer was missing entirely. Added rust/planu-core/src/napi_bridge.rs exposing the 22 hot-path functions (file scan, hash, drift, regex grep, dedup, vector ops, HMAC chain) to Node via napi-rs.
  • pnpm build:rust actually works: the script previously referenced a non-existent planu-cli cargo crate. Now invokes napi build against planu-core correctly.
  • 390 MB of target/ purged from git: 1,594 cargo build artifacts had been committed by accident. Added rust/**/target/ to .gitignore and untracked the leak.

Added — Cross-platform distribution (6 targets with native binary, 2 with TS fallback)

  • Native acceleration on 6 platforms via napi-rs optionalDependencies (turbo/swc-style):
    • @planu/core-darwin-arm64 (M1/M2/M3 Macs)
    • @planu/core-darwin-x64 (Intel Macs)
    • @planu/core-linux-x64-gnu (Ubuntu/Debian/Fedora x64)
    • @planu/core-linux-arm64-gnu (AWS Graviton, Pi 5 64-bit)
    • @planu/core-linux-x64-musl (Alpine Docker x64)
    • @planu/core-linux-arm64-musl (Alpine Docker ARM)
  • Windows uses the TypeScript fallback in v3.1.0. Cross-compiling a fully-vendored MSVC toolchain from macOS hit limits we did not want to paper over with broken binaries. Windows users still get the same correctness — just without the Rust speedup on hot paths. A Linux GHA matrix can supply Windows binaries in v3.2 without changing the loader.
  • Platform autodetection in the loader: core-bridge.ts detects musl vs glibc (4-tier check: /etc/alpine-releaseprocess.report/usr/bin/ldd/lib/ld-musl-*), ARM vs x64, and resolves the matching subpackage at runtime. Honors PLANU_NATIVE_PATH env override. Falls back through legacy paths for backward compat.
  • Multi-tier loader: env override → local platform-tagged .node → legacy unsuffixed .node@planu/core-* npm subpackage → TypeScript fallback. Each tier degrades gracefully so Planu works on any Node 24+ environment, even ones without prebuilt binaries.
  • Vendored Rust deps: reqwest uses rustls-tls instead of native-tls. No system OpenSSL needed on Alpine, Windows ARM, or any musl target. Removed unused git2 dependency that pulled in OpenSSL transitively.
  • Local cross-build pipeline — releases are produced from a developer machine (no CI needed):
    • pnpm build:rust — host target (default)
    • pnpm build:rust:all — all 6 supported targets via cargo-zigbuild
    • pnpm build:rust:check-tools — verify zig + cargo-zigbuild + rustup targets
    • bash scripts/setup-cross-toolchain.sh — one-shot installer for the cross-toolchain
    • pnpm release:publish — full release pipeline (typecheck → lint → tests → build all → npm publish 6 subpackages + main)
  • Real TS fallbacks for all 14 wrappers (not silent []): tsScanAndHashFiles, tsScanProjectMetadata, tsScanSpecAnnotations, tsCheckAcCoverage, tsFindFilesByName, tsFindFilesByExt, tsReadFiles, tsCosineSimilarity, tsHnswSearchFlat, tsHmacSign (HMAC-SHA256, byte-identical to Rust), tsHmacVerify, tsFindPatterns, tsGetProjectDataPath, tsAppendGapEntry. Cross-verified that Rust and TS produce the same output for every function on darwin-arm64.

Fixed — Hardening from in-flight code review

  • tsHmacSign was using createHash (plain SHA-256), not HMAC — meaning reviewer tokens signed by Rust would fail TS verification (and vice versa). Now uses createHmac('sha256', secret) to match the Rust hmac::Hmac<Sha256> exactly. Cross-compatibility verified end-to-end.
  • Cargo panic = "abort" removed from release profile — would have aborted the host Node process on any Rust panic. Reverted to unwind (default) so napi captures panics and converts them to JS exceptions.
  • musl detection was fragile on Alpine distroless (no /usr/bin/ldd). Layered four detection signals; any positive wins.
  • napi build --use-cross zigbuild is napi-rs v2 syntax that silently no-ops on v3. Switched to --cross-compile (the v3 alias for cargo-zigbuild routing).
  • Smoke test in release-local.sh used require() in an ESM project. Rewritten with import.
  • release-local.sh now refuses to publish if the count of built .node binaries does not match the count of optionalDependencies (override with ALLOW_PARTIAL_PUBLISH=1). Prevents shipping a broken main package whose subpackages 404 on npm install.

Changed — Honest performance positioning

  • The previous v3.0.0 was marketed as "100% Rust migration" / "The Rust Revolution". That is not what shipped and was misleading. Reality: ~22 hot-path functions are accelerated via napi-rs, and the rest of Planu (487 tools, MCP server, transports, CLI, storage, hosts) remains TypeScript. This is the same hybrid model used by Vercel turbo, swc, and parcel.
  • v3.1.0 reframes the work honestly as "native acceleration for hot paths". Rust gives outsized wins on large repos (fast_detect_drift_parallel 20–60×, fast_find_duplicate_blocks 10–30×, fast_find_patterns 5–20×) but is invisible on small/medium projects where LLM and disk I/O dominate latency. See BENCHMARKS.md for measured numbers.
  • No more silent data loss: 14 of 22 wrappers in core-bridge.ts previously returned [] when the native binary was missing, masking failures as empty results. Each wrapper now has a real TypeScript fallback (tsScanAndHashFiles, tsScanProjectMetadata, tsFindPatterns, …). Linux/Windows users with no prebuilt binary now get correct results, just slower.

Removed

  • semantic-release and CI-driven publishing: per project policy, releases are local-only. Removed the release:main script and disabled (but kept for reference) .github/workflows/release-rust.yml.
  • 39 ghost pub mod declarations from rust/planu-core/src/lib.rs.

[3.0.0] — 2026-05-02

Added — The Rust Revolution (SPEC-1004)

  • Native Rust Engine: High-performance core library (planu-core.node) integrated via NAPI-RS.
  • 10x Faster Project Scanning: Parallel directory walking, hashing, and regex extraction using Rust's Rayon and ignore crates. Large monorepos that took seconds to scan now initialize in milliseconds.
  • Instant Drift Detection: OS-level file watcher powered by Rust's notify crate. Sub-millisecond reaction to code changes with 0% CPU overhead while idling.
  • Parallel AC Coverage: Layer 3 Drift Monitor (Acceptance Criteria matching) now runs in native threads, eliminating event-loop blockages during validation.

Changed — Security & Format Unification

  • Atomic Integrity (SPEC-718): Officially closed and enforced. Every spec.md write is now atomic (tmp + fsync + rename), making Planu indestructible against crashes.
  • Freeze-on-done Enforcement (SPEC-747): Specs in done status are now immutable by default. Manual edits are blocked by Git Pre-commit hooks and runtime guards. Edits require an explicit bump_spec_version call, ensuring a professional audit trail.
  • Unified Spec Format (SPEC-768): Multi-file specs are dead. Legacy technical.md and progress.md are auto-folded into a single, context-efficient spec.md. Reduces AI context window consumption by ~40%.
  • Tool-to-Skill Migration (SPEC-658): Migrated 5 heavyweight workflow tools (implement_plan, run_healing_loop, multi_teammate_review, generate_orchestration_plan, execute_sdd_flow) to loadable Skills. Reduces system prompt size by ~1,500 tokens.

Fixed

  • list_specs schema validation error: Fixed regression where structuredContent failed strict MCP schema validation in summary mode. All required properties are now explicitly returned.

[2.12.3] — 2026-04-30

Fixed

  • create_release does not auto-trigger housekeeping (SPEC-790): Added fire-and-forget housekeeping_sweep call in github-release-handler.ts after the release cascade completes. Branches, worktrees, and stashes are now cleaned up automatically after every release.

[2.12.2] — 2026-04-30

Fixed

  • Housekeeping sweep misses fix/spec-XXX branches (SPEC-791): Extended DEFAULT_PATTERNS in find-stale-branches.ts to detect fix/spec-*, chore/spec-*, refactor/spec-*, and docs/spec-* branches in addition to the previously supported feat/spec-*. Previously, only feat/spec-* and tmp-* branches were scanned, leaving cherry-picked fix/spec-* branches orphaned.

[2.12.1] — 2026-04-30

Added — Structured error contract (SPEC-902)

  • Error recovery registry: 8 baseline rules mapping error codes (ENOENT, EACCES, EAGAIN, ECONNREFUSED, etc.) to actionable recovery tool calls (init_project, workspace_alerts, verify_integrations)
  • StructuredError contract: all tool errors now return {what, why, nextAction} with sanitized messages (no raw stack traces, no home paths)
  • withErrorContract HOF: middleware wrapping tool handlers with structured error output
  • Idempotent wrapping: already-structured errors pass through unchanged
  • error-recovery.json: configurable registry with code/regex pattern matching

Changed — Error handling

  • safe-handler.ts catch block now uses structured error contract instead of legacy standardError()
  • license-gate.ts wrappers now accept optional extra parameter for consistency

[2.11.0] — 2026-04-30

Fixed — Release pipeline & spec lifecycle

  • create_release unsupported --json flag (SPEC-788): gh release create does not support --json (only view/list do). Removed --json url,tagName from the command and now parse the release URL from stdout's last line. Added regression test to prevent reintroduction.
  • workspace_health returning totalProjects=0 (SPEC-789): Fixed project discovery fallback in buildWorkspaceHealth so totalProjects matches list_registered_projects when registry is empty but projects exist on disk.
  • Auto-migrate legacy technical.md (SPEC-768): list_specs and init_project now auto-run SSR back-migration to fold legacy technical.md / progress.md into unified spec.md. Non-blocking, idempotent, zero overhead when specs are already unified.

Added — Security & durability foundations

  • Atomic writes globally (SPEC-718): All spec lifecycle write operations (spec.md, technical.md, progress.md, hook scripts) now route through atomicWriteFile (tmp + fsync + rename). Prevents partial writes on crash or kill. Already fully deployed across 15+ files.
  • Reviewer token signed identity (SPEC-722): approve_spec now enforces planner ≠ reviewer via HMAC-signed tokens. issue_reviewer_token generates a signed token from a plannerToken. verifyReviewerToken validates signature, sessionId mismatch, modelId mismatch, and 7-day TTL. Multi-teammate review panel support included. Legacy review mode available via planu.json flag with deprecation warning.

[2.10.0] — 2026-04-29

Added — 7 new MCP tools (493 → 499)

  • opencode_host_adapter (SPEC-966): Detect OpenCode workspace markers (opencode.json, .opencode/, ~/.opencode/, OPENCODE_HOME), scaffold config files (.opencode/rules/planu-workflow.md, .opencode/skills/planu-sdd.md, AGENTS.md), and provide coach rules for OpenCode-specific SDD conventions.
  • dependency_health (SPEC-967): Scan package.json for dependency issues — unused, missing, outdated, peer conflicts, and duplicates. Returns categorized report with severity and suggested actions.
  • type_safety_gate (SPEC-968): Block spec status transitions to done when codebase contains TypeScript any types or @ts-ignore comments. Configurable severity (warning/error) and min-count threshold.
  • force_status_analytics (SPEC-969): Track forceStatus/forceApprove usage per project. Warns when >20% of specs have forced transitions. Generates quality-exceptions.md summary. Increases minimum reason length to 100 chars for forced transitions.
  • detect_duplication (SPEC-970): Token-based code duplication detection using sliding window + SHA-256 hashing. Finds exact and near-duplicate blocks across source files. Returns ranked matches with file paths and line numbers.
  • spec_obesity_healer (SPEC-971): Heal bloated specs (>500 lines) by removing generic injected criteria (OWASP, GDPR, performance), HTML artifacts, and [REQUIRED]/[RECOMMENDED] scrape markers. Dry-run by default with backup before modification. Anti-loop guard skips specs created after 2026-04-01.
  • host_tool_filter / Codex unavailable tools (SPEC-972): Filter AGENTS.md tool declarations by host capability. Auto-detects interactive tools (AskUserQuestion, file dialogs) and omits them for non-interactive hosts. Registry-based with codex.json and opencode.json host configs.
  • challenge_spec mandatory gate (SPEC-964): Blocks draft → review transition if challengeReport is missing. Requires ≥3 stress-test scenarios addressed. High-risk specs require all 5 focus areas. challenge_spec persists report to spec file.

Fixed

  • ESLint/typecheck compliance for all SPEC-966 to SPEC-972 implementations
  • Async/await compatibility in OpenCode adapter and spec obesity healer handlers
  • Registered opencode_host_adapter and spec_obesity_healer in license-plans.json

[2.9.0] — 2026-04-29

Added — 3 new MCP tools (490 → 493)

  • architecture_lint (SPEC-961): Scan project codebase for Clean Architecture and SOLID principle violations. Detects handler/route files exceeding 50 lines, Prisma imports outside repository layer, business logic in handlers, and multi-layer imports. Returns scored report with per-rule breakdown.
  • solid_check (SPEC-962): Dedicated SOLID principles scanner with per-principle scoring (0-100). Covers SRP (multiple classes, too many exports), OCP (long switch statements), ISP (large interfaces), and DIP (direct dependency instantiation).
  • verify_integrations (SPEC-965): Ping configured external API integrations before marking a spec as done. Validates HTTP status codes, Content-Type headers, and JSON schema responses. Reads endpoints from .planu/integrations.json or explicit args. Reports latency per endpoint.

Fixed — Critical bugs discovered via dogfooding

  • list_specs schema validation error: ListSpecsOutputSchema was missing 5 optional properties (humanSummary, branchInfo, autopilotSummary, migrationIssues, interactiveQuestions) that handleListSpecs injected into structuredContent. Zod v4 Mini generates "additionalProperties": false by default, causing AJV to reject responses with data must NOT have additional properties. All missing fields now declared.
  • spec_health_check scoring 0/100 for valid specs: computeSpecHealth only looked for description and acceptanceCriteria on the in-memory Spec object, but real specs store these in the markdown file. Now reads spec.md from disk, strips YAML frontmatter, and extracts criteria from body (## Acceptance Criteria, checkbox - [ ], BDD Given/When/Then) and frontmatter (criteria:, scenarios:).
  • Auth criteria (401/403/429) in frontend specs: generate_spec_from_api was injecting backend auth criteria into frontend/UI specs (Storybook, design tasks). buildACs now accepts BuildACsOptions with target/tags and skips 401/403/429 when target ∈ {frontend, ios, android} or tags include ui, storybook, design, component.

Added — 10 gap specs from user feedback analysis

  • SPEC-961 (P0) — architecture_lint ✅ implemented this session.
  • SPEC-962 (P0) — solid_check ✅ implemented this session.
  • SPEC-964 (P0) — challenge_spec mandatory gate.
  • SPEC-965 (P0) — verify_integrations ✅ implemented this session.
  • SPEC-966 (P0) — OpenCode host adapter.
  • SPEC-967 (P1) — dependency_health.
  • SPEC-968 (P1) — type_safety_gate.
  • SPEC-969 (P2) — forceStatus analytics.
  • SPEC-970 (P2) — detect_duplication.
  • SPEC-971 (P2) — spec_obesity_healer.
  • SPEC-972 (bugfix) — Codex unavailable tools filter.

[2.8.0] — 2026-04-28

Fixed — Spec quality + housekeeping batch (SPEC-764, 783, 784, 785)

  • housekeeping_sweep detects cherry-picked branches via Planu status cross-reference (SPEC-764): when a branch is cherry-picked into main (the standard pattern for parallel worktree sessions in Planu), git assigns a new SHA so git cherry/git branch --merged reports it as not_merged. New Pass 2 cross-references SPEC IDs extracted from branch names (feat/SPEC-NNN-*) and tip commit messages (feat(spec-NNN)) against planu/specs/SPEC-NNN-*/spec.md frontmatter status. Branches whose SPEC is done or discarded are surfaced with reason spec-done. Pass 2 is no-op (zero git calls) when no skipped branches exist. New helpers: extractSpecIdFromName, extractSpecIdFromCommit, lookupSpecStatus, applySpecDonePass. 95.86% statement coverage, 15 new tests.
  • handleAgentTeamSynthesis writes to unified spec.md ## Technical section (SPEC-783): SPEC-697 path was still globbing for an external technical.md file that SPEC-709/SPEC-752 removed. After unified migration, agent team findings were silently dropped. Now: locate spec.md, extract ## Technical section body, fold synthesized findings via synthesizeFindings, replace section in-place with atomic write. Append fresh ## Technical if missing. Trigger runSsrBackMigration first when legacy technical.md is still on disk. Actionable error when spec.md not found.
  • readiness-checker rejects placeholder and too-shallow ## Technical sections (SPEC-784): new issue codes TECHNICAL_PLACEHOLDER_DETECTED and TECHNICAL_TOO_SHALLOW (severity blocker). Detectors detectTechnicalPlaceholder (regex /See\s+?.+?\s+(?:technical|spec)\.md/i) and detectTechnicalTooShallow (body < 500 chars AND zero file paths) wired into checkReadinessInternal and checkSpecReadiness. SPEC-769 readiness gate honors blockers via existing forceApprove flow. 99.11% statement coverage, 93.57% branches, 20 new tests.
  • spec-validator REQUIRED_SECTIONS aligned with current generator output (SPEC-785): update_status(approved) was failing with SPEC_FORMAT_INVALID on every freshly created spec because the validator demanded ## Goal, ## Out of scope, and a technical.md file — none of which create_spec emits post-SPEC-709/SPEC-630. REQUIRED_SECTIONS reduced to ['## Problem', '## Acceptance criteria', '## Technical']. New OPTIONAL_SECTIONS_WITH_INFO for ## Goal and ## Out of scope (severity info, not blocker). YAML outOfScope: frontmatter satisfies the out-of-scope requirement as alternative to the markdown section. Backward-compat: legacy specs with both sections pass silently. 6 new tests.

Added — Dogfood bug specs filed in this session

  • SPEC-783 P1 — create-spec agent-team-synthesis path obsolete after SPEC-709 unified migration (filed + implemented + shipped this session).
  • SPEC-784 P0 — check_readiness must reject placeholder ## Technical sections (filed + implemented + shipped this session).
  • SPEC-785 P0 — spec format validator requires sections create_spec does not generate (filed + implemented + shipped this session).
  • SPEC-786 P0 (approved, pending implementation) — validate matcher false-negatives on BDD criteria with literal string match.
  • SPEC-787 P1 (approved, pending implementation) — validate.lintCheck reports false issue count vs pnpm lint.

Updated — SPEC-766 (approved, pending implementation)

  • ## Technical section enriched inline with 13.9 KB of detail: file plan (CREATE/MODIFY), TypeScript signatures (SpecContentGenerator, OpusGenerator, FallbackGenerator, ApiKeyResolver, QualityValidator, AnthropicLike), 4-layer API key resolution chain, anti-loop guards (request shape + system prompt + response inspection), retry policy, fixtures, test stubs, frontmatter additions, approval gate integration. Replaces the placeholder pointer that pre-existed in the file. Implementation deferred to dedicated session due to scope (architectural, 39.2h, touches create-spec.ts core).

[2.7.0] — 2026-04-28

Fixed — Dogfood bug batch (SPEC-774, 775, 776, 777, 778, 780, 781)

  • forceApprove now bypasses both readiness AND format gates (SPEC-780): previously forceApprove: true skipped the readiness gate but the SPEC_FORMAT_INVALID validator still blocked the transition. Now both gates honor the bypass and emit suppressed errors as qualityWarnings[] in the spec frontmatter.
  • update_status derives projectId from projectPath (SPEC-775): regression test added confirming behavior parity between projectId-only and projectPath-only calls. Already worked thanks to SPEC-509/341.
  • Cascade hooks surface failures + new session-context hook (SPEC-776): replaced silent .catch(() => {}) in statusJsonHook with structured appendAutopilotLogEntry writes. New sessionContextHook regenerates session-context.md on every status transition AND on release_completed. New verifyStateFiles drift detector surfaces alerts in workspace_alerts with fix command.
  • Readiness checker recognizes proper test annotations (SPEC-777): parseFrontmatterScenarios now handles both object (- path: "...") and string (- "tests/foo.test.ts") formats. extractCriteriaLines captures full ## Acceptance criteria body text. New extractFilePaths and extractFunctionNames helpers detect paths/identifiers in code spans, after FILES: markers, comma-separated lists, and BDD paragraphs.
  • create_spec autopilot file suggestions are now context-aware (SPEC-778): replaced generic project scan with keyword-relevance scorer (extractKeywords + scoreFile + findRelevantFiles). Score=0 → empty suggestions with honest "No related files detected" message. Out-of-scope items also filtered by relevance — no more "OAuth2/MFA" suggestions for unrelated specs.
  • create_spec char-limit hint + async analysis (SPEC-781): tool description text now states "Max 10000 chars; use reconcile_spec for larger". Friendly error replaces cryptic Zod message when limit hit. Heavy autopilot analysis moved to runAutopilotAsync (fire-and-forget) — synchronous response returns within seconds with pendingAnalysis: true. workspace_alerts surfaces in-progress analyses with auto-clear when .analysis.json lands.

Added — create_release stuck-spec gate (SPEC-774)

  • Block release when specs are stuck: create_release now runs detectStuckSpecs(projectPath) before any release logic. A spec is stuck when status ∈ {approved, implementing} AND its branch is in git branch --merged main. Default behavior: return isError: true listing each stuck spec with fix hint update_status(done, specId=...).
  • forceRelease: true bypass: proceeds with release, appends ## Status Drift section to release notes, audit logged via logForceReleaseAudit.
  • autoFixDrift: true auto-close: calls autoCloseStuckSpec for each stuck spec before releasing, summarizes in release output.
  • Single git call for any spec count: buildMergedBranchSet runs git branch --merged main ONCE; per-spec lookup is Set.has() O(1).

Added — Universal rules catalog + on-demand rule/skill creation (SPEC-779)

  • 3 new MCP tools (487 → 490): create_rule, create_skill, reconcile_universal_rules — host-aware writers (Claude Code: file-per-rule; Codex: AGENTS.md block markers; Gemini: .gemini/conventions.md blocks).
  • Universal rules catalog at src/engine/universal-rules/catalog.ts ships 4 rules to every Planu-using project on init_project: planu-dogfood-bugs (NEW), planu-workflow, planu-modes, agent-teams.
  • User-edit detector: reconcile_universal_rules checks content-hash vs .planu-rules-manifest.json install-time hash — preserves user-modified rules untouched.
  • Manifest tracking: every install records { id, path, hostId, hashAtInstall, installedAt } in .planu-rules-manifest.json for atomic reconciliation.

Added — Project rule: dogfood-bug → spec immediately (.claude/rules/planu-dogfood-bugs.md)

  • STRICT rule: any bug observed while using Planu becomes a detailed create_spec in the same turn (FILES + FUNCTIONS + BDD + Sonnet-ready order). No deferring to backlog.
  • 8 specs filed and shipped this session following the rule for the first time: 774, 775, 776, 777, 778, 779, 780, 781.

[2.6.0] — 2026-04-28

Added — Autopilot pipeline log persistence (SPEC-772)

  • Autopilot cascade results persisted to JSONL: every cascade hook execution now writes a pass or fail entry to data/projects/<hash>/autopilot-log.jsonl (fire-and-forget). Fields: specId, hookName, result, error?, timestamp, durationMs.
  • Log rotation at 500 entries: appendAutopilotLogEntry trims the oldest entries so the JSONL file never exceeds 500 lines.
  • workspace_alerts surfaces autopilot failures from last 24h: in addition to stale specs, the tool now reads autopilot-log.jsonl across all registered projects and reports any hook failures in a dedicated "Autopilot Hook Failures" table — no more silent cascade errors.
  • Fast hook support in cascade runner: CascadeHook gains an optional fast: boolean flag. Hooks marked fast: true are awaited synchronously (up to 2s budget) and their results returned in RunCascadeResult.fastHookResults for inclusion in the update_status response.
  • autopilotValidateWarning in update_status response: when validateScore < 70, the response now includes an explicit autopilotValidateWarning message pointing the user to workspace_alerts for details — validate failures are no longer silent.
  • New types: AutopilotLogEntry, FastHookResult added to src/types/.
  • 42 new tests: event-bus log persistence (9), cascade runner fast/slow split (4), storage rotation (7), workspace alerts surfacing (5), existing tests updated with mocks to prevent disk writes.

[2.5.2] — 2026-04-28

Improved — Test suite optimization (SPEC-763)

  • Fake timers for drift-watcher and budget tests (AC1/AC2): replaced real setTimeout waits with vi.useFakeTimers() + vi.advanceTimersByTimeAsync() — these two test files no longer hold up the suite with real wall-clock delays.
  • Integration fixture reduced from 2,000 to 50 files (AC3): create-spec-timeout.test.ts triggers its budget timeout by wall time (via withBudget), not by file count. 50 dummy files are sufficient; MAX_SCAN_FILES = 500 in the analyzer ensures the budget fires before any scan limit.
  • 5 duplicate test descriptions resolved (AC4): unique it() names across spec.test.ts, spec-compliance-runner.test.ts, specs.test.ts, testimonial-handler.test.ts, and multi-teammate-review.test.ts — fixes misleading test output and enables proper deduplication by reporters.
  • vi.mock hoisted to module level (AC5): portal-page-detector.test.ts moved its vi.mock('node:fs/promises', ...) call from inside a describe block to the top of the file — this is the required location for Vitest to correctly intercept the module before imports resolve.

[2.5.1] — 2026-04-28

Added — Housekeeping cleans ephemeral spec artifacts

  • SPEC-762 — Ephemeral spec artifact cleanup: housekeeping_sweep now scans planu/specs/SPEC-*/ and removes risk-register.md, implementation-brief.md, and prompt.md from specs with terminal status (done or discarded). These files are generated automatically by the Planu autopilot during planning phases but have no value after a spec is completed. Dry-run mode (default) reports what would be deleted without acting; dryRun: false deletes them. The stage is best-effort and never blocks the sweep.

Improved — Test performance

  • maxWorkers doubled from 4 to 8 — uses available CPUs on dev machines
  • cleanOnRerun: true in coverage config — avoids stale coverage cache
  • test:coverage excludes tests/integration/** (2 000-file disk fixture); new test:integration script runs the integration suite separately

[2.5.0] — 2026-04-27

Added — Superpowers integration + bundled version self-healing

  • SPEC-755 — Brainstorming conflict resolution: init_project now injects a spec-location section into CLAUDE.md that explicitly routes all specs to Planu via create_spec. Overrides the brainstorming skill's default of writing to docs/superpowers/specs/. housekeeping_sweep gains an orphanBrainstormingMarkdowns stage that finds and removes markdown files accidentally created in that directory.

  • SPEC-756 — Bundled version gap auto-fix: Planu detects when a Superpowers plugin bundles an outdated @planu/cli version (checked against npm registry). When a gap is found, a direct @planu/cli@latest MCP entry is injected into the project's .mcp.json (or ~/.claude/claude.json) so the client automatically uses the latest version on next restart. The check runs fire-and-forget in init_project, list_specs, and project_overview — never blocks tool response.

Fixed

  • register-spec-tools snapshot updated to 26 tools (reflects graph_specs, audit_specs_drift, ssr_back_migration added in v2.4.0 but missing from the snapshot).

[2.4.0] — 2026-04-27

Added — UX & Reliability gaps captured from real-world drift incidents

This release closes 4 high-friction UX and reliability gaps observed during the v2.3.0 rollout. All 4 specs were authored after concrete incidents (status.json corruption, legacy multi-file specs blocking SSR, residual zombie shells in Claude Code, leftover branches/worktrees post-release). The fixes are minimal, additive, and never break existing flows.

  • SPEC-751 — housekeeping_sweep auto-cleanup: detects stale local branches that have been merged or cherry-picked into main (using git cherry main <branch> for cherry-pick equivalence), prunable worktrees, and orphan stashes. Runs in dryRun by default; surfaces a coach reminder after update_status(done) and after create_release. housekeeping event type added to the hash-chained transition log so cleanups are auditable.

  • SPEC-752 — SSR back-migration (ssr_back_migration tool): folds legacy technical.md and progress.md files into the unified spec.md ## Technical / ## Progress sections. Respects SPEC-747 freeze (skips done specs unless allowDoneSpecs: true). Closes the residual writer path: runTechnicalEnricher now writes ONLY to spec.md, never re-creates technical.md. Dry-run reporting + per-spec mutation log.

  • SPEC-753 — project_overview + status.json self-healing: single-call state query (project_overview) replaces the multi-tool dance of planu_status + list_specs + filesystem reads. Returns counts by status, top pending specs, version sync, drift score, stale-implementing detector, pending cleanup. reconcile_status_json repairs status.json drift from spec.md frontmatters with three resolution strategies (frontmatter-wins default, status-wins, newest-wins). Self-healing layer auto-quarantines corrupt status.json files to planu/.broken/status-<ts>.json and rebuilds from frontmatters. proper-lockfile-style file lock prevents concurrent-write races. status_reconciled event added to transition log.

  • SPEC-754 — Shell hygiene coach reminder: appends a one-line KillShell reminder to the response of update_status({ to: 'done' }) when the host is claude-code. Closes the "14 zombie shells in Tareas panel after 8h SDD session" feedback. i18n parity enforced (coach.shell_hygiene.kill_background in en/es). No new tools, no detection — minimal viable intervention at the natural completion milestone.

Fixed

  • Cherry-pick orchestration during release used git merge-base --is-ancestor to detect already-included branches; this missed cherry-picked branches because their commits have different SHAs. Now uses git cherry main <branch> (the canonical patch-equivalence test). Documented in SPEC-751.
  • runTechnicalEnricher was the only remaining writer to technical.md after SPEC-630 unified the spec format. Closed in SPEC-752 Scenario 5 — enricher now writes ONLY to spec.md.
  • workspace_overview previously had no concept of single-project state. New project_overview (SPEC-753) is the single-call replacement; the existing cross-project workspace_overview is unchanged.

Stats

  • 4 specs implemented across 3 parallel worktree-isolated Sonnet workers
  • ~2700 LOC source + tests added
  • 131 new targeted tests — all green
  • 4 new tools (housekeeping_sweep, ssr_back_migration, project_overview, reconcile_status_json) bring total from 483 → 487
  • Lint clean, typecheck clean, snapshot regenerated

[2.3.0] — 2026-04-26

Added — Observability + Sandbox + Audit + Resiliency (Plan v2 Bloques 6+7+8)

This release adds 11 specs from Plan v2 — Bloques 6 (Observability + Sandbox), 7 (Maintenance + Audit), and 8 (Resiliency + Coach + Test Architect). All extensions are additive; no breaking changes. Together they close the drift-detection loop: every tool call is observed (telemetry + budget + sandbox), every spec edit is freezable on done, every drift is auditable, and the dashboard shows a single drift-score number.

Bloque 6 — Observability + Sandbox

  • SPEC-740 — Global middleware chain (withBudget + withTelemetry + withSandbox): every tool handler registered via register-all-tools.ts is now wrapped by a composable middleware chain (composeMiddleware). withBudget enforces per-tool wall-clock + token budgets; withTelemetry records start/end events to the telemetry sink; withSandbox (when enabled) routes shell-exec calls through a sandbox runner. Middlewares can be enabled/disabled per-server via config.

  • SPEC-741 — Telemetry 30-day retention + t-digest pre-aggregation + opt-in stance: telemetry is opt-in by default. When enabled, raw events are kept for 30 days then rotated; P95 latencies are pre-aggregated using a pure-TS t-digest implementation (k=100 compression, accuracy verified within 2% for 1000 uniform samples). runTelemetryRotation() is exposed for cron-style invocation.

  • SPEC-742 — Real OS sandbox for execute_sdd_flow: detects host capabilities (bwrap on Linux, sandbox-exec on macOS, Docker fallback) and routes shell exec through the appropriate runner. Env-sanitizer strips LD_PRELOAD, DYLD_*, and other ambient interpreters before exec. Falls back to noop-sandbox when no runner is available, with a telemetry warning.

  • SPEC-743 — LLM cassette/mock pattern: deterministic test snapshots via SHA-256 request fingerprinting + JSONL cassette store at tests/cassettes/. PLANU_RECORD_CASSETTES=1 toggles record mode; replay raises CassetteMissError when a request has no recorded match. Replaces ad-hoc vi.fn() mocks for any test that exercises real LLM I/O.

Bloque 7 — Maintenance + Audit

  • SPEC-744 — audit_specs_drift tool: two-tier reverse-audit. Tier-1 (deterministic) runs file-path existence + scenario→test mapping + frontmatter integrity checks across all specs. Tier-2 (LLM-based) classifies semantic drift between spec text and current code; budget-capped to avoid runaway cost. Returns a markdown report.

  • SPEC-745 — heal_planu_root 3-tier policy: every repair operation is classified as auto-fix (low-risk JSON syntax + UTF-8 normalization), propose-only (medium-risk schema repairs, requires user approval), or never-touch (high-risk semantic edits, surfaces a comment but does not modify). Backups go to planu/backups/<timestamp>/ before any mutation; markers.ts enforces an allowlist of fixable file types.

  • SPEC-746 — Spec dependency graph + graph_specs tool: builds a DAG from supersedes and depends_on (or dependencies) frontmatter fields. Returns nodes, edges, detected cycles, and topological order. superseded-set.ts answers isSuperseded(specId) for filtering. DOT exporter emits Graphviz output for visualization.

  • SPEC-747 — freeze-on-done enforcement at write-boundary: atomicWriteFile now consults isSpecFrozen(specId, status) and rejects writes to specs in done/discarded status with error code spec_frozen. Operators can break-glass via an unlock token (HMAC-signed, 5-min window, audited) or forceEdit: true. retro-audit.ts emits a retro_audit transition-log entry for every successful unlock-window edit so changes to frozen specs remain visible.

Bloque 8 — Resiliency + Coach + Test Architect

  • SPEC-748 — planu_drift_score field + dashboard badge: planu_status now includes structuredContent.planu_drift_score (0–100, 1 decimal) computed as (driftReview / doneSpecs) * 100 from pending.json filtered by kind: 'drift_review'. lastAuditAt timestamp tracks freshness. Dashboard renders a drift-green/drift-amber/drift-red badge in the status section.

  • SPEC-749 — Coach multi-host (rule packs per host + i18n catalog): rule packs in src/hosts/{claude-code,codex,gemini}/coach.ts deliver host-specific guidance. All user-facing strings go through t(key, params) resolved against src/i18n/coach/{en,es}.json. Key parity is enforced by tests; missing-key fallbacks emit coach.i18n.missing_key telemetry. No literal strings allowed in rule pack code.

  • SPEC-750 — TestArchitect role + TDD strict mode: decideTddRouting() blocks specs with tdd: strict from draft → in_progress transitions until a TestArchitect produces a RedTestsHandoffSchema-validated handoff. verifyRedPhase() confirms tests fail (red); verifyGreenPhase() detects deletion of red-tests with error code RED_TESTS_DELETED. Event types tdd_red_locked and tdd_green_achieved added to TransitionEventType.

Stats

  • 11 specs implemented across 3 parallel worktree-isolated workers (Sonnet)
  • ~2700 LOC source + tests added
  • 575 new tests (+3 skipped) — all green
  • 3 new tools (audit_specs_drift, graph_specs, heal_planu_root) bring total from 480 → 483
  • Snapshot regenerated; license-plans synced; website counts synced to 483

[2.2.0] — 2026-04-26

Added — Validation Atomicity + DevEx Endurecido (Plan v2 Bloques 4+5)

This release adds 10 specs from Plan v2 — none introduce breaking changes; all extend existing surfaces additively. Together they harden the validate→done path (atomic, reversible, observable, transactional) and the release pipeline (preflight, smoke test, rollback, reproducible build).

Bloque 4 — Validation atómica

  • SPEC-730 — Scope/target-aware holistic validate: validateSpec now consults resolveApplicableDimensions(target, scope) to enumerate which of the 5 dimensions (tests, lint, typecheck, security-scan, spec-compliance) actually apply. doc-only scope skips typecheck/lint/tests/security; meta-like targets (infrastructure, database, shared) skip lint/tests. Score is normalised over the applied set so a 100% doc-only spec is no longer penalised for missing source code. HolisticReport exposes applicableDimensions and skippedReasons so reviewers see why a 100 score involves only 2 dimensions.

  • SPEC-731 — Non-destructive dry_run mode for update_status: new dry_run?: boolean flag. When true, all gates run (runApprovedDodGate, runValidateGate, format gate, dep-guard) and the prospective transition is simulated, but transitionSpec is NOT called and no disk mutation occurs. Returns a DryRunResult with wouldTransition, gateResults, and the prospective nextStatus. CI scripts and operators can pre-flight a transition before merging.

  • SPEC-732 — Executable acceptance criteria linked to test files: each frontmatter scenario can carry a tests: [{ path, line? }] array. The new runSpecCompliance(spec, projectPath) runner invokes vitest --reporter=json against the linked files and assigns a per-scenario verdict (pass/fail/missing). validateSpec consumes the per-scenario verdicts in the spec-compliance dimension. check_readiness adds a scenarios_missing_tests blocker when any scenario lacks links.

  • SPEC-733 — Reverse transitions with mandatory reason: update_status now accepts reverse transitions (e.g. doneimplementing, approvedreview, validatingimplementing) with a mandatory reason: string (≥ 10 chars). The reason is appended to transition-log.jsonl under eventType: 'reverse_transition'. validateReverseTransition enforces the allowed graph; isReverseTransition(from, to) is exported for callers.

  • SPEC-734 — Transition log enriched payload: TransitionLogEntry widens with sessionId, modelId, and gateResults (typed sub-shape recording each gate's outcome and elapsed time). canonicalEntry() orders the new fields stably so SHA-256 chain hashing remains deterministic. verifyTransitionLogChain(path) is exported for end-to-end integrity checks. Legacy entries (no enriched fields) read with null fallbacks — no migration script required.

  • SPEC-735 — Transactional cascade rollback (saga): handleUpdateStatus now wraps the post-transitionSpec cascade (Slack notify, dashboard updater, webhook outbound, telemetry) in a runSaga executor. Steps declare critical: true | false. On a critical-step failure the saga invokes compensating actions in reverse order, calls transitionSpec again to roll back to the prior status (trigger: 'rollback'), and appends a terminal_drift_detected log entry with meta.rolledBack: true. Non-critical failures log and continue. Generic runSaga<Ctx>() is exported for future use cases (release pipeline, multi-step migrations).

Bloque 5 — DevEx endurecido

  • SPEC-736 — Hardened release pipeline: scripts/release.sh now invokes a strict release-preflight.sh (tests + typecheck + license drift + npm whoami allowlist), acquires a flock-based concurrency lock at /tmp/planu-release.lock, and runs tag → push tag → publish → smoke-test (release-smoke-test.sh) → push branch in that exact order. A failed preflight or smoke test exits non-zero, leaving the work uncommitted/unpublished. The smoke test runs npx --yes @planu/cli@<v> --version against a fresh installation.

  • SPEC-737 — rollback_release tool: new mcp__planu__rollback_release({ version, reason, allowAged?, dryRun? }) tool that orchestrates npm dist-tag rmgit tag -dgit push --delete → post-mortem skeleton at templates/postmortem.md → optional verification smoke test → audit entry in transition-log.jsonl (specId: 'release', meta.kind: 'release_rollback'). Age guard refuses rollbacks of versions older than 30 days unless allowAged: true.

  • SPEC-738 — Reproducible build: scripts/release.sh now exports SOURCE_DATE_EPOCH=1 and PLANU_OBFUSCATE_SEED=$(git rev-parse HEAD | cksum) before pnpm build. scripts/obfuscate.mjs reads the seed and feeds it into javascript-obfuscator's seed option. Two consecutive builds at the same git SHA produce identical tarball SHA-256. New scripts/check-reproducibility.sh <tag> rebuilds at a tag and diffs against the published tarball. Optional GitHub workflow .github/workflows/reproducibility.yml automates the check on tag push.

  • SPEC-739 — flag_spec_gap refinements: flag_spec_gap accepts severity: 'low'|'medium'|'high'|'critical' and affectedSpecs: string[]. Each flagged gap is appended to a hash-chained planu/.gaps.jsonl (mirroring the SPEC-723/734 transition-log pattern) so the gap history is tamper-evident. gaps-log.ts exposes appendGap, readGaps, verifyGapsChain. pending.json integration unchanged — gaps still surface in planu_status.

Fixed

  • dep-guard-gate.test.ts and validate-gate-forced-bypass-audit.test.ts mocks updated to expose isReverseTransition/validateReverseTransition from transition-guard.js (SPEC-733 export additions).
  • license-plans.json extended with rollback_release and re-categorises flag_spec_gap (now proTools tier alongside create_release).
  • Tool API snapshot regenerated to include the new SPEC-737 tool entry.

Test counts (delta)

  • 176 new tests across 10 specs (SPEC-730: 48, SPEC-731: 6, SPEC-732: ~12, SPEC-733: 17, SPEC-734: 12, SPEC-735: 18, SPEC-736: ~14, SPEC-737: ~14, SPEC-738: ~7, SPEC-739: ~28).
  • Full suite: 30 326 / 30 326 passing (2 pre-existing flaky orchestrator timeouts unchanged).

[2.1.0] — 2026-04-26

Added — Spec Quality Refinements + Roles Formales (Plan v2 Bloques 2+3)

This release adds 6 specs from Plan v2 — none introduce breaking changes; all extend existing surfaces additively. Together they close the spec-quality gaps flagged by the 5-critic Opus review and formalise role handoffs (Triagier → Elicitor → Planner → Reviewer → Implementer → Validator → Releaser).

  • SPEC-724 — Spec quality refinements bundle: 5 sub-features behind one tool surface.

    • elicit_requirements({ ...args, mode: 'non-interactive' }) synthesises a complete elicitation summary deterministically (CI/swarm friendly, no AskUserQuestion round trip).
    • heal_spec_docs({ ...args, dryRun?, backup? }) writes .bak.<ts> companions by default (gitignored), supports dryRun (returns unified diff, never writes), and emits a GOAL_SCENARIO_DRIFT warning when Goal vs first scenario THEN clause Jaccard similarity < 0.85.
    • BDD validator gains a copula blacklist (es, son, está, tiene, is, are, has, exists) — copulas inside fenced code blocks are ignored.
    • Idioma validator strips fenced blocks before counting prose; abstains when prose word count < 50 (no false positives on early drafts).
    • audit_claude_config({ gate: 'core-rules' }) walks per-host renderers (Claude ~/.claude/rules/, Codex AGENTS.md, Gemini GEMINI.md) and returns blockers if any of the 3 core rules is missing.
  • SPEC-725 — Handoff artifacts schema: 5 versioned Zod artefacts persisted under planu/data/projects/<projectId>/handoffs/<specId>/ via atomicWriteFile (SPEC-718) under cross-process lock (SPEC-719), each emit-recorded in the SPEC-723 transition log.

    • intake.json (Triagier→Elicitor), spec.lock (Planner→Reviewer), review_feedback.md (Reviewer→Planner), implementation-report.json (Implementer→Validator), validation-report.json (Validator→Releaser).
    • Each carries schema_version (SemVer). Forward-minor reads with warning; major mismatch refuses.
    • update_status(done) now reads validation-report.json and blocks with reason validation_report_failed when passed: false.
    • Public API: validateArtifact, appendArtifact, readArtifact re-exported from src/core/index.ts.
  • SPEC-726 — Triagier role + triage_request tool: front-gate intent classifier (Haiku-class). Five kinds: idea → backlog, quick-fix → direct implement, bug-spec/feature-spec/epic → elicit. Confidence < 0.6 returns interactiveQuestions for disambiguation. Cost guard: 5s wall-clock + 1500 output tokens; on trip returns deterministic feature-spec @ 0.5 fallback. Writes intake.json (SPEC-725) on success. Free-tier tool.

  • SPEC-727 — Arbitrator activation + heterogeneity check: panel-orchestrator.ts now invokes the existing Arbitrator (Opus, persona already in arbitrator-prompt.ts) after 2 consecutive Planner↔Reviewer disagreements on the same (specId, frontmatterSha). Heterogeneity gate refuses panels staffed by two specialists with identical (modelId, promptHash). Decisions are persisted to planu/data/projects/<id>/arbitrator-decisions/<specId>-<sha>.json and recorded in the transition log with reason: 'arbitrator-decision'. New verifyTokenPair(reviewerToken, plannerTokenOnSpec) helper closes a SPEC-722 hardening gap.

  • SPEC-728 — DepGuard cycle blocker: dod-gates.ts now invokes checkApprovedDepGate(spec, allSpecs) before any transitionSpec call to approved. Blocks with DEPENDENCY_CYCLE (with full path narrative SPEC-X -> SPEC-Y -> SPEC-X) or SELF_DEPENDENCY. Tolerates orphan dep refs with a warning (no block). Adds <50ms to the approve path.

  • SPEC-729 — Escalator role + retry policy: generic withEscalation(role, fn) middleware applied to Reviewer (3 retries), Validator (3 retries), and Releaser (2 retries) flows. Budget exhaustion returns an interactiveQuestions sentinel [retry, abort, manual-override]; Releaser default is abort, others default to retry. manual-override for Releaser requires forceStatusReason ≥ 30 chars. The wrapper preserves reviewerToken (SPEC-722) across retries unchanged.

Fixed

  • heal_spec_docs legacy tests adapted to the new backup default (backup: false for explicit 1-call assertions).
  • .gitignore template extended with planu/specs/**/*.bak.* so SPEC-724 backups don't pollute git status (root cause of the SPEC-715 reproducer regression).
  • Tool API snapshot refreshed to include triage_request.

Test counts (delta)

  • 218 new tests across 6 specs (SPEC-724: 17, SPEC-725: ~24, SPEC-726: 29, SPEC-727: 19, SPEC-728: 6, SPEC-729: 25, plus shared utilities).
  • Full suite: 30 148 / 30 150 passing (2 pre-existing flaky orchestrator timeouts unrelated to this release).

[2.0.0] — 2026-04-26

BREAKING CHANGES — Foundations + Bypass Closure (Plan v2 Bloques 0+1)

This release closes 4 confirmed state-machine bypasses identified by the 5-critic Opus review of plan v1, plus the foundational primitives the rest of plan v2 depends on. Direct status writes, file-driven status drift, validate-as-warning, and string-literal reviewer identity are all blocked at the source. Existing integrations that assumed those paths must migrate.

  • SPEC-720 — Single status entry point (BREAKING): specStore.updateSpec({status}) now throws DirectStatusWriteForbiddenError. The only path that mutates status is transitionSpec in src/engine/spec-state-machine/transition-spec.ts, called via handleUpdateStatus. sync_spec_state, branch-ops.markMergedAsDone, the HTTP /specs/:id/status route, and dashboard/spec-updater were rewired to route through update_status. ESLint rule no-restricted-imports blocks __internalSetStatus and the legacy updateSpecStatus outside transition-spec.ts. New shell guardrail scripts/check-no-direct-status-writes.sh. autoCompleteSpecs return type is now {completed: string[], blocked: Array<{specId, reason}>} (was string[]).

  • SPEC-721 — runValidateGate fail-closed (BREAKING): validate timeouts, crashes, null scores, and unreachable validators no longer fall through silently — they BLOCK the transition with one of 5 enum reasons (validate_score_below_threshold, _no_criteria, _crash, _timeout, _unreachable). Operators who knowingly bypass must pass forceStatus: true AND forceStatusReason ≥ 30 chars; the bypass is appended to the audit-trail with event: 'validate_gate_forced_bypass'. The redundant outer withToolTimeout wrapper in update-status/index.ts was removed.

  • SPEC-722 — Reviewer signed identity (BREAKING): approve_spec no longer accepts reviewer: "alice" as a free-string. It requires a reviewerToken (HMAC-SHA256 of sessionId + modelId + nonce, signed with planu/.planu-secret, TTL 7 days). multi_teammate_review enforces heterogeneity — two critics with the same modelId + promptHash are rejected. ApprovalRecord.reviewer: string is replaced by ApprovalRecord.reviewerIdentity: ReviewerIdentity. Set legacyReviewMode: true in planu/conventions.json for opt-in legacy string acceptance during migration.

  • SPEC-723 — Frontmatter immutable post-terminal: at done/discarded transition, a SHA-256 over canonical frozen fields is computed and stored in a hash-chained transition-log.jsonl. repair_frontmatter_drift and sync_spec_state verify the SHA before any rewrite — divergence surfaces as report.corrupt[] / report.rejected[] with audit events terminal_frontmatter_tamper_detected / sync_spec_state_terminal_drift_detected. Two unfreeze paths: bump_spec_version (SPEC-717) and update_status(reopen) (SPEC-V3 placeholder).

Added — Foundations (Bloque 0)

  • SPEC-718 — Atomic writes globally: new src/engine/safety/atomic-write-file.ts (tmp + fsync + rename pattern) replaces 20 raw writeFile callsites across the spec lifecycle. Power-loss during write no longer leaves half-written spec.md. New custom ESLint rule planu/no-raw-writefile-in-spec-lifecycle enforces the pattern on migrated paths.

  • SPEC-719 — Cross-process spec lockfile: disk-backed mutex at planu/.locks/<specId>.lock with PID + sessionId + hostname + heartbeat (30s) + 3-signal stale detection (heartbeat>5min OR PID dead via process.kill(pid,0) ESRCH OR ttlMs expired). All spec-mutating tools (update_status, delete_spec, version_spec) wrap in acquireLock + releaseLock. list_locks extended to surface cross-process locks alongside legacy SPEC-301.

  • SPEC-716 — validateSpecFormat() extracted to core: side-effect-free, transport-agnostic validator at src/core/spec-validator.ts. Composes checkSpecReadiness, scoreSpecQuality, and frontmatter checks behind one API. Routed through by check_readiness, update_status(approved) (new checkApprovedFormatGate), and create_pr_from_spec. Zero @modelcontextprotocol/sdk imports — usable from CLI, pre-commit, CI. Closes the SPEC-608 gap.

  • SPEC-717 — Spec format versioning + history SemVer: every new spec is born with spec_format_version: "1.0" and spec_version: "1.0.0" plus history: []. New tool bump_spec_version({kind, reason}) is the canonical entry point — appends a SpecHistoryEntry and refreshes frontmatterSha (SPEC-723 reseal hook). heal_spec_docs and repair_frontmatter_drift are idempotent: byte-equivalent output triggers no version bump. Legacy specs without spec_format_version are treated as "0.x" and migrated on touch.

  • SPEC-F0e (planned) — Resource-aware orchestration: gap detected during this release dev session (host at 22GB/24GB used during 4 parallel Sonnet agents). Specced in plan v2 for next bloque: src/engine/resource-guard/ sensor + withResourceGuard() middleware adapting parallelism for multi_teammate_review, vitest hooks, and subagent spawning when client RAM is low. NOT shipped in 2.0.0 — documented for follow-up.

Internal

  • 5 stale entries removed from src/config/license-plans.json (multi_teammate_review, implement_plan, execute_sdd_flow, generate_orchestration_plan, run_healing_loop) — none registered in code. Added render_spec_for_provider (SPEC-670) which was registered but missing from license-plans.
  • Test suite: 30022/30022 passing (3 pre-existing timeouts unrelated to this release).
  • Plan v2 (planu/research/plan-v2-cierre-gaps.md): 38 specs across 8 bloques, born from a 5-critic Opus review of plan v1.

Migration guide

  1. If you call specStore.updateSpec({status}) directly: switch to handleUpdateStatus({specId, status, projectId, projectPath}).
  2. If you have tests that assume validate fail-open: expect result.isError === true with validate_gate_* reasons. Update assertions or pass forceStatus: true + a 30+ char reason.
  3. If you call approve_spec({reviewer: 'alice'}): either (a) issue a reviewer token via the new flow, or (b) set legacyReviewMode: true in planu/conventions.json.
  4. If you read autoCompleteSpecs() return: it's {completed, blocked} now, not string[].

[1.99.1] — 2026-04-26

Fixed

  • SPEC-713 — create_spec timeout regression (P0): confirmed bottleneck via Phase 0 instrumentation — runAutoPostCreatePipeline was awaited synchronously before sending the MCP response, and 8+ enrichment steps ran sequentially (100–500ms each), pushing total latency past the 60s client timeout on large projects. Fix: 25s hard ceiling on the critical path (buildContext → writeFile → createSpec), 6 enrichment steps now run in parallel with per-step withBudget (2–3s each), and runAutoPostCreatePipeline is fire-and-forget after the response is sent. New helpers src/engine/timing/{budget,structured-log}.ts plus src/types/timing.ts. Result: create_spec on a 2000-file project drops from 20–65s to 5–12s; spec is always synchronously persisted before the response. 18 new tests (12 unit + 6 integration with 2000-file fixture). Phase 0 timing report at planu/research/spec-713-create-spec-timing.md. Closes SPEC-560 residue.

[1.99.0] — 2026-04-26

Fixed

  • SPEC-715 — Git-aware migrator + list_specs read-only: User-reported P0 bug where list_specs silently unlink'd technical.md files during auto-migration to the unified-spec format, leaving the deletion outside the LLM's commit. New safeUnlink(projectPath, filePath) helper detects .git and uses git rm -f --ignore-unmatch <relPath> to stage the deletion atomically (falls back to plain unlink outside repos). list_specs is now strictly read-only — it reports drift via detectDrift() instead of mutating the workspace; explicit migrations only run when the user invokes heal_spec_docs. New MigrationDriftReport type avoids name collision with the existing analysis.DriftReport.

Refactored

  • SPEC-714 — Cascade hooks hybrid (closes SPEC-649 residue): Audit found 18 inline cascade actions inside update-status/side-effects.ts (438 lines), violating SPEC-649's "exactly 2 actions on done" contract even though all 18 were already fire-and-forget. New src/engine/cascade-hooks/{types,registry,runner,core/,hooks/} enforces the contract architecturally — runCascade(ctx, opts) awaits the 2 core actions (write-session-json, append-releases) within a 2-second AbortController budget, then dispatches the 18 extension hooks via Promise.allSettled (cannot block the user response). Hooks declare id, description, and a pure handler; opt-out via planu/conventions.json:cascadeHooks.disabled[] or PLANU_DISABLE_HOOKS=hookA,hookB env. side-effects.ts shrinks 438 → 112 lines. New pre-commit guardrail scripts/check-no-inline-cascade-actions.sh rejects future inline blocks. SPEC-649 marked supersededBy: SPEC-714.

Internal

  • 36 new test files for cascade hooks (registry + runner + 18 hook units + 2 core actions + integration parity), 18 new files for cascade hook handlers, 2 new tests for git-aware FS + drift detector, 2 new integration tests for list_specs read-only contract and heal_spec_docs staging behaviour. Suite: 29756/29756 green.
  • 4 draft specs created for follow-up: SPEC-710 (holistic validate), SPEC-711 (mid-implementation flag_spec_gap), SPEC-712 (local pnpm release pipeline), SPEC-713 (fix create_spec 60s timeout regression — reopens SPEC-560).
  • Audit report planu/research/audit-2026-04-26-done-specs.md: 25 done specs sampled, 5 confirmed P0 residue, 6 suspected P1, 14 clean.

[1.98.0] — 2026-04-26

Changed

  • SPEC-709 — Unified spec.md from origin: create_spec, reverse_engineer, and core/spec-api.ts now write a single unified spec.md directly, instead of writing a two-file pair (spec.md + technical.md) that list_specs/heal_spec_docs had to merge on next read. Closes the SPEC-630 residue at the creation path. New helper src/engine/spec-format/unified-spec-builder.ts strips the technical body's frontmatter and appends it as a ## Technical section. New specs are born unified — no auto-healing required. 5 builder tests + 3 updated callsite tests; full suite green.

[1.97.0] — 2026-04-26

Added

  • SPEC-708 — Cross-LLM rules adapter: HostHint extended to 'codex' | 'gemini'. New src/engine/host-detection/detect-host.ts resolves the connected client from PLANU_HOST override or per-CLI env markers (CLAUDECODE, CURSOR_SESSION_ID, OPENAI_CODEX_SESSION, GEMINI_CLI_SESSION). New src/engine/host-rules-templates/ exposes buildRulesForHost(host, version) plus directive helpers. Tool responses with interactiveQuestions[] now emit a host-aware directive ("Use AskUserQuestion" only for Claude Code; Codex/Gemini receive their native interactive-prompt phrasing). Codex AGENTS.md and Gemini .gemini/conventions.md now receive an idempotent <!-- planu:rules:start --> block alongside the existing scaffold body.

Fixed

  • Outdated workflow.md docs (EN, ES, DE, FR, PT, ZH): the spec-files table still listed progress.md, technical.md, executive-report.html, and technical-report.html — formats that SPEC-461 (lean) and SPEC-630 (unified spec.md) replaced months ago. Confirmed in the wild after a customer screenshot showed Claude quoting the outdated table. Each language page now describes the single-file unified format and points to heal_spec_docs for legacy projects.

Refactored

  • engine/claude-md-injector/rules-template.ts delegates to host-rules-templates: the Claude Code rules-section builder is now a thin wrapper over buildRulesForHost('claude-code', version). No behavioural change for existing Claude Code projects.

[1.96.0] — 2026-04-25

Added

  • plan_team_distribution tool: Engine planTeamDistribution() (existing since SPEC-091) is now exposed as a real MCP tool. Loads each spec via specStore, extracts files mentioned in spec.md, builds a file-ownership map, and returns the team roster, phased execution order (parallel-safe vs conflicting), and warnings for shared files. Closes a long-standing doc-vs-reality gap where rules-generator, claude-md-generator, onboarding-engine, and generate-automation-guide all referenced a tool that was never registered.
  • Crash Shield suppress directives: TypeScript detector now respects three eslint-style magic comments — // crash-shield-ignore (same line), // crash-shield-ignore-next-line, and // @crash-shield-ignore-file (whole file). Lets developers signal "writer is under our control, shape is guaranteed" without changing detection rules. Marked 50+ Planu-controlled config/cache readers with the file-level directive. Scanner-visible JSON.parse-as count drops from 180 → 120, with the remaining covering genuine boundary reads (user package.json, tsconfig.json) where CRITICAL is correct.

Changed

  • Hardcode guardrail flips to STRICT by default: scripts/check-no-hardcoded-stacks.sh no longer just warns — it now fails pre-push when any hardcoded framework/stack literal lands in src/**/*.ts outside src/config/. The previous baseline of 308 hits was eliminated by auditing every flagged file: all turned out to be legitimate canonical mappings (npm-package↔framework adapters, keyword catalogues, type unions, generator inputs). 122 files marked SPEC-597-EXEMPT with explicit two-line headers documenting why each is exempt. New hardcoded literals now require either src/config/*.json registration or an explicit SPEC-597-EXEMPT exemption.
  • tool-registry/group-*.ts consolidation rationale: Updated eslint-disable max-lines directives in the 7 thematic group files (1100-2188 lines each) to document why splitting would re-create the ~120 register-*.ts files Phase 3 (commit aafeea60) intentionally collapsed.
  • safeJsonParse helper at JSON read boundaries: src/storage/qa-gate-store.ts, skill-registry-storage.ts, and project-drift-store.ts migrated from JSON.parse(raw) as Type to safeJsonParse(raw, fallback) with type guards. Eliminates a class of latent crash bugs where a corrupted/partial JSON file would lie to the type system.

Fixed

  • resolve-project-path registry lookup: When only projectId was provided (no projectPath), the resolver returned an empty path instead of looking up the registry, leaving downstream tools without a working directory. Now does projects.find((p) => p.hash === explicitId) to recover the path.
  • Spec integrity check (SPEC-630 follow-up): scripts/check-spec-integrity.sh no longer requires technical.md — SPEC-630 unified that file into spec.md, but the pre-commit hook kept warning on every commit (7 spurious "missing: technical.md" entries for SPEC-700→706). Now only spec.md is required.
  • 16 pre-existing test failures across 3 suites: update-status-automation (4 tests) needed a qa-gate-store mock added by SPEC-642; tool-schemas.snapshot (1) needed regeneration after new tools landed; share-story (11) needed @supabase/supabase-js retained as devDep for vitest's vite transform of ShareStory.vue. Suite now 29529/29529 green.
  • 7 pre-existing curly-brace lint errors in src/engine/marketplace-fetcher/anthropic-source.ts that slipped past the lint-staged pre-commit hook (which only checks changed files). Wrapped one-line if/setTimeout callbacks in braces per the project's curly rule.

Removed

  • 24 unused barrel files: 17 type subdomain barrels (src/types/{agents,ai,analysis,autopilot,context,docs-types,git,hooks,ide,infra,integrations,licensing,observability,registry,security,spec-ops,testing-ext}/index.ts) and 7 engine/host barrels (src/engine/{dynamic-knowledge,permissions-merger,provider-adapters,skill-generator,spec-effectiveness}/index.ts, src/hosts/{claude-code/runtime,codex}/index.ts). All verified to have 0 consumers via grep. Knip output now empty.

Refactored

  • src/types/living-spec.ts (578L) split into 3 sub-modules: living-spec/{annotations,dashboard-and-sync,auto-update-and-merge}.ts (170+285+123L). The original file became a barrel — call sites unchanged. Each sub-module fits comfortably under the 500-line limit.

[1.95.0] — 2026-04-25

Added

  • SPEC-661 — Tools page focus refactor: Website tools/index.md rewritten from 477 → 50 core tools grouped by user intent (Discover, Plan, Implement, Validate, Operate). Reduces cognitive load for new users; deeper tool reference still indexed for search.
  • SPEC-659 — Lean-mode guide pages: 5 new website guides — lean-spec-format, auto-status-transitions, unified-spec-md, tier-tool-loading, interactive-questions. Each documents one mechanism with concrete examples; cross-linked from manifesto and onboarding.
  • SPEC-701 — Testimonials component: Testimonials.vue renders approved testimonials from Supabase via VitePress data loader. Zero JS at runtime — data is statically baked at build.
  • SPEC-702 — Live stats banner: LiveStats.vue shows real-time npm downloads + GitHub stars/forks, fetched at build via API badge fetchers. Cached 1h.
  • SPEC-703 — WorksWith logo grid: WorksWith.vue displays 8 supported tool logos (Claude Code, Cursor, Copilot, Codex, etc.) with tier-based grouping.
  • SPEC-704 — ShareStory submission form: ShareStory.vue posts directly to Supabase REST endpoint (anon key, RLS-protected). Captcha via honeypot field; no extra dependencies.
  • SPEC-680 — Skill registry schema: Canonical planu/skill-registry.json schema with multi-source support (superpowers, anthropic, community, local). Types extracted to src/types/skill-registry.ts.
  • SPEC-682 — Skill adapter: adaptSkillContent() (pure) injects project context (stack, conventions, paths) into skill markdown using word-boundary regex. adaptAndInstallSkill() wraps with I/O.
  • SPEC-681 — Marketplace fetcher: fetchSkillsFromAllSources() aggregates skills from superpowers, anthropic, and community registries with discriminated FetchSourceError (timeout | not-found | malformed | network | registry-write-failed | unknown). Failures appended to planu/evolution-log.md.
  • SPEC-685 — Workflow skills generator: 22 canonical workflow skills (implement-spec, new-feature, resume-session, review-and-merge, spec-health, parallel-safe, release, validate-spec, tdd-cycle, security-review, lessons-learned, capture-learning, brainstorm, debug-session, mcp-builder, autonomous-sdd, …) generated and adapted on init_project. Reuses adapter (SPEC-682) + fetcher (SPEC-681) for DRY.
  • SPEC-651 — MCP elicitation native UI: Tools that need user input now use the MCP elicitInput capability (Cursor, Claude Desktop) when available; falls back to InteractiveQuestion[] for hosts without elicitation support. New src/engine/elicitation/user-elicitor.ts with timeout + decision cache.
  • SPEC-658 — Tool→skill migrations: 5 workflow tools (execute_sdd_flow, implement_plan, multi_teammate_review, run_healing_loop, generate_orchestration_plan) replaced with deprecation aliases that redirect callers to skills. Backward-compat preserved via makeDeprecationStub().
  • SPEC-670 — Provider-specific renderers: Canonical spec rendering adapted per provider — claude.ts, gpt4.ts, gemini.ts, markdown.ts. Each provider gets its preferred structure (XML-tag-heavy for Claude, JSON-block for GPT-4, fenced-block for Gemini, plain markdown for fallback).
  • SPEC-686 — Next-spec resolver + multi-spec auto-orchestration: resolveNextSpec() scores approved specs by ROI (priority × dev-hours-inverse) and dependency satisfaction; writes the recommendation to planu/session-context.md. When ≥ 2 specs are approved, resolveOrchestrationPlan() builds a wave plan via Kahn topo-sort with file-conflict-aware grouping, emitting up to MAX_WAVES=10 waves with ≤ MAX_PARALLEL_PER_WAVE=5 specs each.
  • SPEC-705 — RAM-aware agent spawn guardrail: Cross-platform memory probe (vm_stat darwin, /proc/meminfo linux, os.freemem win32) caps parallel agent spawns when host memory is tight. decideAgentParallelism() honors PLANU_MAX_PARALLEL_AGENTS env override and conventions.ramGuardrail config. Critical pressure → 1 agent; moderate pressure → math-capped; probe failure → safe default of 2. Integrated into multi-teammate-review and agent-team orchestrators.
  • SPEC-706 — Manifesto page: New website pages /en/manifesto and /es/manifesto engaging with a widely-shared list of 7 AI-coding principles. 5 ✓ Agree, 1 ↻ Refined (#3 — true without spec, false with approved spec), 1 ⚠ Disagree (#7 — track, don't chase). Cross-links to lean-mode guides; sidebar entry under "About Planu" / "Sobre Planu".

Changed

  • .claude/rules/client-value-first.md (mandatory): New rule travelling with the repo. Default to zero-setup; reject options that require client knowledge to benefit; 8h dev rule (if complete option is ≤ 8h dev and delivers clear client value, ship it directly); token math wins (option that reduces client tokens wins).

Fixed

  • panel-orchestrator concurrency: runWithConcurrencyLimit() replaces unbounded Promise.all(spawn…) patterns in multi-teammate-review and agent-team orchestrator. Combined with SPEC-705 guardrail prevents OOM on low-RAM clients.

[1.94.1] — 2026-04-25

Fixed

  • SPEC-698 — Fail-loud frontmatter sync in update_status: syncSpecFiles no longer swallows write failures silently. Errors now surface as frontmatterSyncWarnings on the update_status response so callers can react. Root-cause: a .trim() on the regex made updateFrontmatterField match nested same-name keys (e.g., model: under estimation:), producing silent corruption. The regex is now anchored without trim, so only top-level keys are rewritten. Nested YAML siblings (estimation, criteria, etc.) are preserved byte-for-byte.
  • SPEC-698 — repair_frontmatter_drift tool: New tool that reconciles on-disk planu/specs/*/spec.md frontmatter with the data store (data store is the source of truth). Idempotent: running twice repairs 0 specs the second time. Includes defense-in-depth security guards: realpath-based containment check (rejects symlinks that escape planu/specs/), strict basename === 'spec.md' enforcement, SpecStatus enum validation before write, and a YAML-injection guard in updateFrontmatterField (rejects \n/\r in values and non-identifier keys).
  • husky/pre-push: First-push of a new branch no longer aborts via set -euo pipefail when @{push} is unset. BASE_REF resolution is hoisted to the top of the script with a develop fallback, and both the changed-tests and changed-website diffs reuse it.

[1.94.0] — 2026-04-25

Added

  • SPEC-630 — Unified spec.md: Merged the 2-file format (spec.md + technical.md) into a single unified spec.md containing all LLM context. migrateAllSpecsToUnified() auto-runs on init_project and list_specs — reads technical.md, strips its YAML frontmatter, and appends under a ## Technical section, then deletes technical.md. Idempotent: skips specs already unified. Engine in src/engine/spec-migrator/unified-migration.ts.
  • SPEC-630 — model/budget frontmatter: New deriveModelBudget(difficulty, devHours) pure function generates model: haiku|sonnet|opus and budget: 800|2000|4000 injected into every new lean spec.md frontmatter. Rules: difficulty 1-2→haiku, 3→sonnet, 4-5→opus; devHours ≤4→800, ≤12→2000, >12→4000.
  • SPEC-630 — stripDoneCriteria on done transition: update_status(done) on lean specs now strips completed criteria entries and annotates the criteria: key with a count (e.g., criteria: # 5 done) instead of leaving done: true entries.
  • SPEC-630 — technical-enricher fallback: runTechnicalEnricher now reads the ## Technical section from unified spec.md when no separate technical.md exists, enriches it, and writes back in place.

[1.93.0] — 2026-04-24

Added

  • SPEC-652 — Tool Tier Registry: 3-tier (Core/Domain/Power) lazy tool registry on top of GroupManager. src/config/tool-tier-registry.json maps group IDs to tiers. TierManager in src/engine/tool-groups/tier-manager.ts disables Domain+Power tier groups on startup and exposes activateTier() for on-demand activation.
  • SPEC-694 — Orchestration Plan on Approved: update_status(approved) now auto-invokes buildOrchestrationPlanSummary() for scope=cross-module or scope=architectural specs. Result included as orchestrationPlan in the response. Fire-and-forget with 5s timeout; errors swallowed silently.
  • SPEC-695 — AskUserQuestion Relay Enforcement: New interactiveResult() helper in response-helpers.ts guarantees every tool response with interactiveQuestions[] includes humanSummary (with explicit Use AskUserQuestion instruction) and hostHint. handleClarification() in create-spec.ts now uses this helper.
  • SPEC-696 — Technical Enricher: update_status(review) cascade auto-enriches technical.md via Opus analysis — reads real TS signatures, test patterns, and rewrites with concrete implementation plan. Engine in src/engine/technical-enricher/.
  • SPEC-697 — Agent Team Planner: create_spec includes agentTeamPlan[] in the response — role-based specialist agents mapped from detected stack signals via src/config/agent-team-roles.json. Supports synthesis path via agentTeamFindings field on a second create_spec call.

[1.92.0] — 2026-04-24

Added

  • SPEC-644 — Dynamic Model Mapping: init_project and create_spec now auto-fetch live model lists from Anthropic/OpenAI/Google/Mistral APIs and classify into canonical tiers (haiku/sonnet/opus). Results cached in conventions.json with 7-day TTL. Falls back to static mapping when API is unreachable. Engine in src/engine/model-tier-resolver.ts.
  • SPEC-666 — Project Drift Detector: Post-commit hook (pure shell, <100ms) writes NDJSON signals to .planu/drift-commits.ndjson when dependency manifests or unknown file extensions appear. Detection engine in src/engine/project-drift-detector.ts. Storage in src/storage/project-drift-store.ts. Wired into setup_hooks (4th hook: post-commit).
  • SPEC-668 — Skills TTL Refresh: Installed skills older than 30 days are automatically re-fetched from their source on init_project. Changed content triggers a backup to .planu/skill-cache/. Unreachable sources are flagged as source-unavailable in manifest.json (skill file preserved). Refresh events appended to planu/evolution-log.md. Engine in src/engine/skill-registry/ttl-refresh.ts.
  • SPEC-664 — Version Resolver: Extracts package mentions from spec descriptions and resolves their latest npm/PyPI/pkg.go.dev versions via live API calls. Engine in src/engine/version-resolver/. Wired into create_spec as background enrichment.
  • SPEC-663 — Registry-driven Stack Detection: Hardcoded framework arrays eliminated from stack detector. All patterns now loaded from src/config/stack-detection-registry.json. Stack detectors generated at runtime from registry entries.
  • SPEC-640 — Code Health Signals: Cyclomatic complexity and coverage metrics fed as routing inputs to model recommender. High complexity → escalates to sonnet/opus. Low coverage → flags in spec context.
  • SPEC-649 — Slim Done Cascade: update_status(done) autopilot cascade reduced from 5+ operations to 2 (session.json + pending.json). Eliminates the 2–30 minute wait after marking a spec done.

[1.91.0] — 2026-04-23

Added

  • SPEC-624 — Dynamic Elicitation: create_spec question generation is now config-driven and context-aware. New src/engine/elicitation/answer-extractor.ts scans the description for pre-existing answers and suppresses redundant questions (e.g., description mentioning "Stripe" skips the payment-provider question). option-builder.ts derives option lists from project DNA — detected providers appear first with "(Recommended)". All dimensions registered in src/config/elicitation-dimensions.json; add a new dimension without editing question-generator.ts

[1.90.0] — 2026-04-23

Added

  • SPEC-620 — Token Budget Injection: Planu prompts now include a <token_budget>N</token_budget> constraint calibrated to task complexity. Tiers: concise (800 tokens, ≤4h), standard (2000, 4–12h), complex (4000, >12h), readonly (1200 for read-only ops). Wired into challenge_spec (architecture tier) and decompose_spec (write tier). Engine in src/engine/token-budget/.
  • SPEC-621 — Auto Model Routing: decompose_spec and execute_sdd_flow now include recommendedModel (haiku/sonnet/opus) and estimatedCost per subtask, derived from keyword signals in the title. search/list/find/read → haiku; implement/refactor → sonnet; architecture/design/spec or difficulty≥4 or scope=cross-module → opus. multi_teammate_review includes specialist model assignments in the output. Engine in src/engine/model-router/subtask-model-assigner.ts.
  • SPEC-622 — Context Orchestrator: context_window_status now auto-triggers a relief pipeline when usage reaches 80%. At 80–89%: archives done specs older than 7 days + writes a session checkpoint. At ≥90%: also records compress_spec_history and emits a context:pressure autopilot event. Pass disabled: true to context_budget_config to receive warning-only mode. Engine in src/engine/context-orchestrator/.

Fixed

  • i18n elicitation: all hardcoded English strings in question-generator.ts now use t() for locale lookup. Added questions section (target/payment/scope/database/uiType) to en.json, es.json, pt.json. With locale=es the elicitation form shows "Proveedor de Pago", "Modelo de Facturación", etc.

[1.89.3] — 2026-04-23

Refactored

  • SPEC-608 — Core Extraction: src/core/index.ts now exports transport-agnostic engine functions with zero @modelcontextprotocol/sdk imports. New createSpec() and listSpecs() in src/core/spec-api.ts provide a programmatic API callable by MCP handlers, CLI commands, and HTTP routes without MCP SDK knowledge. McpServerFactory and SessionEntry moved to src/transports/mcp-types.ts to keep src/types/ free of SDK imports. ESLint overrides added for src/core/ and src/transports/ layers

[1.89.2] — 2026-04-23

Added

  • SPEC-605 — Plugin Reliability: install_plugins now auto-detects stack via scanProjectForStack when no prior detect_project_dna was run. Error responses include failure type (network, permission, compatibility), the exact error message, and a recovery suggestion per failed plugin. Successful installs emit a plugin:installed autopilot event that auto-activates the plugin and injects its configuration; the tool response includes an auto-activated notice.

[1.89.1] — 2026-04-23

Added

  • SPEC-619 — InteractiveQuestion Elicitation: create_spec raises clarification threshold to 20 words when description lacks technical terms, and the new broad-scope detector asks scoping questions when descriptions span 2+ major subsystems (auth, payments, notifications, analytics, etc.). Billing-specific descriptions now trigger payment-provider and billing-model questions. init_project emits interactiveQuestions[] when multiple frontend framework signals coexist, asking the user to pick the primary framework.

[1.89.0] — 2026-04-23

Added

  • SPEC-611 — Spec Effectiveness Score: new spec_effectiveness_score MCP tool (PRO). Composite 0–100 score combining adherence rate, first-pass success, rework ratio, estimation accuracy, and drift penalty. Supports per-spec and project-aggregate reports with trend analysis. Engine in src/engine/spec-effectiveness/.
  • SPEC-612 — Scope Boundaries: auto-populates outOfScope on spec creation (up to 3 suggestions keyed off description topics), detects scope contradictions in challenge_spec, validates file changes against declared scope in validate, and nudges check_readiness to recommend adding boundaries. Engine in src/engine/scope-boundaries/.
  • SPEC-613 — Gherkin import/export: two new PRO tools. import_gherkin parses .feature files (single file, directory scan, or pasted text) and appends scenarios as BDD criteria to a spec. export_gherkin emits spec criteria as a valid Cucumber-compatible .feature file. Supports Scenario Outline + Examples with interpolation. Engine in src/engine/gherkin/.
  • SPEC-614 — Spec Complexity Budget: analyze_spec_size now surfaces over-specification warnings (criteria-to-hours mismatch, criteria-to-files ratio). create_spec trivial detector promotes backlog capture for ≤5 word descriptions lacking technical terms, and complexityAdvice hints surface suggested category based on similar historical specs. Engine in src/engine/complexity-budget/.
  • SPEC-615 — Prior Decisions Auto-Link: BM25 searcher attaches relevant past decisions as priorDecisions in create_spec responses; challenge_spec flags new criteria that contradict logged decisions. New optional priorDecisions field on Spec. Engine in src/engine/prior-decisions/.

[1.88.1] — 2026-04-22

Fixed

  • BDD parser: parseBddScenarios() now handles GIVEN/WHEN/THEN without Scenario: header — auto-creates scenarios from bare step keywords.
  • check_readiness: counts BDD scenarios: from frontmatter as acceptance criteria when criteria: is absent — eliminates false "0 criteria" blocker.
  • InteractiveQuestion relay: all 10 tools that return interactiveQuestions[] now include explicit guidance for LLMs to use AskUserQuestion instead of displaying raw JSON.

[1.88.0] — 2026-04-22

Added

  • SPEC-603 — Plugin Discovery & UX Unification: searchPlugins() in plugin-catalog, search action in manage_plugins with keyword/stack filtering, unified tool descriptions clarifying manage_plugins vs install_plugins responsibilities.
  • SPEC-604 — Plugin Lifecycle Robustness: update action in manage_plugins, conflict-checker engine for manifest-based conflict detection, artifact-scanner for post-uninstall cleanup of orphaned hooks/rules/skills.
  • SPEC-605 — Plugin Reliability & Autopilot: error-classifier with typed PluginInstallError (network/permission/compatibility/not-found), scanProjectForStack auto-detection fallback when no prior detect_project_dna, plugin:installed autopilot event with auto-activation cascade.
  • SPEC-606 — Universal Skill Discovery: Multi-source skill search engine with adapters for skills.sh, GitHub, npm, Anthropic, and builtin registries. Result ranker (stack compatibility, downloads, source reliability, recency). Progressive disclosure splitter for large skills. Multi-agent writer (Claude, Cursor, Copilot, Gemini).
  • SPEC-607 — Project-Aware Skill Generation: Agent Skills spec formatter (SKILL.md with YAML frontmatter per agentskills.io). Stack-aware content generator with JSON templates. Multi-agent adapter/writer for cross-platform skill distribution. bootstrap_skills and reconcile_skills upgraded with format detection and multi-agent output.

Fixed

  • decompose_spec: now accepts projectPath parameter (previously only projectId hash).
  • BDD parser: convertCheckboxToBdd() generates full GIVEN/WHEN/THEN scenarios instead of THEN-only.
  • Troubleshooting hints: install_plugins error output now includes actionable troubleshooting guidance.

[1.87.0] — 2026-04-22

Added

  • SPEC-599 — Social proof pipeline: 2 new tools (approve_testimonial, list_testimonials) for managing testimonials via Supabase PostgREST. 4 Vue components (Testimonials.vue carousel, LiveStats.vue dynamic badges, ShareStory.vue submission form, WorksWith.vue compatible tools grid). VitePress data loader for build-time testimonials. Supabase migration with RLS policies.
  • SPEC-601 — Hybrid spec identity (UUID): every spec now gets an auto-generated uuid field alongside the human-readable SPEC-NNN id. Enables cross-project portability via export_spec_bundle / import_spec_bundle tools. Lazy migration: existing specs get UUIDs on first read. Zero breaking changes — SPEC-NNN display format unchanged.
  • SPEC-600 — Autopilot cascade completeness: status transitions now auto-invoke recommend_model, generate_orchestration_plan, context_window_status on implementing, and generate_changelog, auto_fix_health, scan_crash_risks, optimize_context on done. All fire-and-forget, never blocks transitions.

Fixed

  • SPEC-598 — Atomic git commit for session-context.md: session context generation now uses atomic writes to prevent partial commits.

[1.86.1] — 2026-04-22

Fixed

  • Runtime-safe JSON parse across storage layer: new safeJsonParse<T>(raw, fallback) helper in src/storage/base-store.ts guards against malformed JSON + primitive-where-object-expected. Migrated 9 callers (base-store.readJson, sentry-store, crash-shield-store, compliance-gate-config-store, compliance-audit-store, release-notes-store, spec-lock-store, audit-trail-store, tdd-policy-store, vector-store/sqlite-adapter, license-store). Eliminates JSON.parse(raw) as T pattern in src/; remaining occurrences are in test fixtures (acceptable).

[1.86.0] — 2026-04-22

Added

  • SPEC-596 — Auto-register Claude Code marketplace + stack-aware plugin install: new MCP tool install_plugins(mode: minimal|recommended|full) + src/engine/plugin-installer/ (marketplace-registrar, plugin-catalog, stack-matcher, installer). Registers anthropics/claude-code marketplace and installs a curated plugin set matching detected stack (Vercel, Railway, Figma, frontend, testing, observability). Opt-in via init_project pluginsMode parameter. Integrates with MCP Elicitation (SPEC-595) for opt-in dialog. Idempotent — no duplicate registrations or reinstalls. 16 files + 62 tests, 100% branch coverage on new files.

Refactored

  • SPEC-597 — Registry-driven discovery (zero-hardcode audit): eliminated hardcoded framework/stack literals from stack-matcher and stack-detectors. Three canonical JSON registries now drive all detection:
    • src/config/framework-registry/index.json — 20 frameworks across 10 mandatory ecosystems (TS, Python, Go, Rust, Java, Ruby, PHP, C#, Dart, Swift).
    • src/config/detection-signals.json (new) — dependency/file/env signals + explicit aliases (otelopentelemetry, shadcn/uishadcn, etc.).
    • src/config/deny-rules-registry.json (new) — stack-specific destructive Bash patterns (Django manage.py flush, Rails db:drop, Laravel artisan migrate:reset, Terraform destroy, etc.).
    • stack-matcher.ts + permissions-merger/stack-detectors.ts refactored to read registries at first use (cached per-process), zero framework names hardcoded in code.
    • scripts/check-no-hardcoded-stacks.sh advisory guardrail (set PLANU_HARDCODE_STRICT=1 to enforce).

Fixed

  • storage/compliance-audit-store: countComplianceAuditEvents wrapped readFile in try/catch to prevent crash on race condition if file is deleted mid-read.

Tooling / Infra

  • Tool count: 469 → 470 (install_plugins added, free tier).
  • Known tech debt (tracked, non-blocker): ~400 framework literals still exist in Zod enums and error messages across src/tools — mostly user-facing choice selectors (acceptable), a minority detection-path hardcodes pending a broader audit spec.

[1.85.0] — 2026-04-22

Added

  • SPEC-594 — Auto-configure Claude Code permissions (opt-in, stack-aware, merge-safe): new MCP tool configure_permissions(mode: minimal|recommended|full) + src/engine/permissions-merger/ (merger + stack-detectors + templates). Merges into project-level .claude/settings.json idempotently, preserves user entries, never downgrades defaultMode, never touches user-level ~/.claude/settings.json. Stack-aware deny rules per detected framework (Vercel, Supabase, Prisma, Docker, git). Opt-in via init_project with permissionsMode parameter. Reduces prompt friction without the insecure bypassPermissions workaround. 17 files, 85 tests.
  • SPEC-595 — Native MCP Elicitation with interactiveQuestions fallback: new src/engine/elicitation/capability.ts (per-session capability cache) + elicit-helper.ts (elicitOrFallback, buildEnumSchema, buildConfirmSchema, questionsToFormSchema). 10 tools refactored to route input requests through native server.elicitInput() when the client supports MCP Elicitation (spec 2025-06-18) and fall back to interactiveQuestions[] in structuredContent otherwise — no breaking change for legacy clients. Refactored: challenge_spec, clarify_requirements, delete_spec (destructive: cancel-by-default), facilitate, init_project, plan_team_distribution, reconcile_spec, update_status, validate. Kills the "LLM re-formulates text-based prompt" class of UX issues. 12 files / 864 insertions.

Fixed / Improved

  • Tool registry: added multi_teammate_review (SPEC-593) and configure_permissions (SPEC-594) to freeTools in license-plans.json so free-tier users can access both.

Known follow-ups

  • SPEC-595: plan_team_distribution refactor pending — the subagent did not complete it before being killed; left at stub. The tool still works via interactiveQuestions[] fallback. Track as tech debt.

[1.84.0] — 2026-04-21

Added

  • SPEC-587 — Planu as Claude Code native citizen (runtime): new src/hosts/claude-code/runtime/ layer — agent-teams-adapter.ts (maps Planu teammates onto native ~/.claude/teams/<id>/config.json with orchestrate_runtime fallback), native-hooks-consumer.ts (subscribes to TaskCreated/TaskCompleted/TeammateIdle, no polling), plan-mode-gate.ts (enter Claude Code Plan mode natively when autopilot reaches merger/approval stage, env-gated via CLAUDE_CODE_PLAN_MODE_SUPPORTED=1 for backward compat). src/config/hook-templates/planu-spec-sanctity.sh PostToolUse hook blocks writes inside planu/specs/*/ outside the whitelist — kills recurring PLAN.md orphan problem. src/engine/session-safeguard/precompaction-drain.ts extends PreCompaction hook: drain learnings to MEMORY.md fragments + autopush unpushed commits + write session-context.md before compaction completes. 13 files, 72 tests.
  • SPEC-588 — Planu as Claude Code native citizen (UX surfaces): new src/hosts/claude-code/ux/ layer. subagent-publisher.ts scaffolds 4 .claude/agents/planu-*.md (spec-implementer, validator, challenger, readiness-auditor). mcp-resources.ts registers 4 readable MCP resources (planu://ux/specs, progress, constitution, recent-activity) on server startup — no tool invocation needed to read specs/progress. mcp-prompts.ts registers 3 fillable MCP prompts (create_spec, execute_sdd_flow, challenge_spec) for the slash-command picker. skills-writer.ts scaffolds 4 .claude/skills/planu-*.md triggered by intents like "let's release". scripts/sync-planu-native-assets.ts syncs legacy projects idempotently. 10 files + templates, 145 tests.
  • SPEC-589 — Release pipeline optimization: scripts/release.sh single-invocation orchestrator (12 steps, happy path <60s target), scripts/prepublish-guard.sh (skip redundant build when dist/ fresher than any src/**/*.ts), scripts/lib/release-env.sh (PLANU_SKIP_BUILD / PLANU_SKIP_TESTS / PLANU_SKIP_WEBSITE / PLANU_FULL_CHECKS / PLANU_RELEASE_MODE contract). .husky/pre-push rewritten to auto-detect chore(release): commits and default SKIP_TESTS+SKIP_WEBSITE (escape via PLANU_FULL_CHECKS=1). .npmignore audited; package.json files[] tightened — tarball stays <5 MB with full dist/.
  • SPEC-590 — Claude Code plugin marketplace: planu-plugin.json manifest at repo root (reverse-DNS name, capabilities for tools/resources/prompts/subagents, minimum host version). src/engine/plugin-manifest-sync.ts + scripts/sync-plugin-manifest.mjs keep plugin version in lockstep with @planu/cli npm version. scripts/plugin-install-hook.sh / plugin-uninstall-hook.sh (preserves planu/ specs; removes only Planu-owned .claude/ additions). release.sh extended with step 10.5 to sync manifest. Real SVG icon + placeholder screenshots (flagged for replacement before actual marketplace submission). 15 files, 39 tests.
  • SPEC-593 — Multi-teammate code review skill: src/tools/multi-teammate-review.ts MCP tool + src/engine/multi-teammate-review/ (panel-orchestrator, arbitrator-prompt, 5 specialist-prompts: security / correctness / performance / maintainability / architecture, report-formatter). Arbitrator deduplicates, resolves contradictions, classifies findings as critical / suggestion / nit / false-positive. NoOpLlmInvoker is default fallback; real invoker injected via setLlmInvoker() so Agent Teams integration stays pluggable. .claude/skills/planu-multi-teammate-review.md scaffolded by init_project. 18 files, 73 tests, 100% coverage.

Fixed

  • check_readiness criteria parser false-negative: extractCriteriaLines now accepts (a) checkbox bullets, (b) plain - GIVEN ... WHEN ... THEN ... bullets anywhere, (c) plain bullets inside a ## Acceptance Criteria or ## Criterios section. Previously only checkbox form matched, producing 0 criteria on specs authored with GIVEN/WHEN/THEN lists (reproduced across SPEC-586..595). 5 new test cases.
  • autopilot commit message: update-status/file-sync.ts planuAutoCommit reason now derives from newStatus (mark-done only when truly done; status-update otherwise). No more misleading "docs(planu): mark SPEC-XXX as done" commits on approved/implementing transitions.

SPEC-591/592 follow-ups

  • Renamed ZodField alias → GeminiZodField in src/types/gemini.ts (barrel-collision-proof).
  • Wired guardProjectPathForCodex into list_specs, search_specs, search_suggestions handlers. No-op when Codex identity env vars absent; fail-open when OPENAI_WORKSPACE_ROOT missing.

Known follow-ups (tracked for v1.85.0)

  • SPEC-594 (auto-configure Claude Code permissions) — Wave 3 implementation in progress.
  • SPEC-595 (MCP Elicitation replacing interactiveQuestions hack) — Wave 3 implementation in progress.

Tooling / Infra

  • New src/hosts/ architectural layer (Clean Architecture: imports from engine + storage + types + selected tools; no cross-host runtime state).
  • New engine layers: src/engine/multi-teammate-review/, src/engine/session-safeguard/precompaction-drain.ts, src/engine/plugin-manifest-sync.ts.
  • Tool count: 467 → 468 (added multi_teammate_review, free tier).
  • planu-plugin.json + assets/plugin/ shipped at repo root for marketplace readiness.

[1.83.0] — 2026-04-21

Added

  • SPEC-591 — Gemini CLI host adapter with multimodal-first spec workflows: new src/hosts/gemini/ layer exposing Planu to Gemini CLI users. adapter.ts detects .gemini/ workspace markers or GEMINI_* env vars and activates Gemini-compatible tool schemas. tool-schema-translator.ts round-trips Zod ↔ Gemini function-call schemas (scalars + composites). multimodal-spec-flow.ts auto-chains inject_component_context + figma-tokens when image attachments are present in create_spec requests — zero manual tool calls. config-scaffold.ts writes .gemini/conventions.md, .gemini/skills/planu-*.md, .gemini/hooks/*.sh idempotently without ever touching .claude/. Graceful fallback for surfaces without Gemini equivalents (Agent Teams, plan mode) with per-session warn-once. Wired into init_project via scaffold-writer.ts. 13 files, 80 tests passing, 100% coverage on new files.
  • SPEC-592 — Codex host adapter for enterprise deployments: new src/hosts/codex/ layer for OpenAI Codex / ChatGPT enterprise users. Decision gate resolved to MCP-only — Codex supports STDIO + Streamable HTTP MCP transports natively per developers.openai.com/codex/mcp (April 2026); rest-shim.ts kept as documented stub for future cloud-only deployments. adapter.ts activates on .openai/ directory or Codex env vars. enterprise-auth.ts parses SAML/OIDC passthrough identity from OPENAI_USER_ROLES / OPENAI_USER_ID / OPENAI_ENTERPRISE_TENANT and bridges role decisions to audit-trail-store.appendEntry (EU AI Act Article 12 chain). workspace-scope.ts scopes project paths per-user with filterPathsForUser guard. config-scaffold.ts writes .openai/config.toml + AGENTS.md idempotently. docs/hosts/feature-parity.md matrix documents every Planu surface across Claude Code / Gemini CLI / Codex with fallback strategies. Wired into init_project via scaffold-writer.ts. 15 files, 68 tests passing, 100% coverage.

Known follow-ups

  • SPEC-592: list_specs and search_specs handlers are not yet updated to invoke filterPathsForUser — cross-workspace isolation only activates when callers route through workspace-scope.ts. Tracked for a follow-up spec before enterprise Codex rollout.
  • SPEC-591: ZodField = z.ZodType alias exported from src/types/gemini.ts is generic; rename to GeminiZodField if a future host adapter needs a similar shape to avoid barrel collision.

Tooling / Infra

  • New src/hosts/ architectural layer (Clean Architecture: imports from engine/ + storage/ + types/ + selected tools for audit bridge; no cross-host runtime state).
  • ScaffoldWriteResult extended with geminiConfigScaffolded + codexConfigScaffolded flags for init_project telemetry.
  • Tool count unchanged at 467 (host adapters are infrastructure, not tools).

[1.82.0] — 2026-04-21

Added

  • SPEC-582 — Orphan spec ID detector: scan_orphan_spec_refs tool + src/engine/detectors/orphan-spec-refs.ts scans commit history and planu/ for fix(SPEC-NNN) / feat(SPEC-NNN) references without a matching planu/specs/SPEC-NNN-*/ folder. Three remediation modes: report (default), create-stub (scaffolds minimal spec.md/technical.md), block (exits non-zero for CI gate). Wired into check_readiness and pre-push hook.
  • SPEC-583 — Autonomous SDD flow orchestrator: execute_sdd_flow tool runs the full brainstorm → create_spec → challenge_spec → check_readiness → update_status → implement → validate → update_status(done) pipeline with three control modes: full-auto (zero prompts), interactive (AskUserQuestion at each gate), preview (dry-run with report). src/engine/sdd-flow/ adds pipeline/gates/checkpoints/model-router modules. Replaces manual tool chaining for the common happy path.
  • SPEC-584 — AskUserQuestion hard gate: server-side ClarificationGate (src/engine/clarification-gate/) issues single-use tokens on ambiguous tool inputs, blocking the tool until the LLM returns a valid clarificationToken. PostToolUse hook (planu-force-ask-user-question.sh) intercepts non-AskUserQuestion responses when a pending question is staged, forcing the LLM to relay via AskUserQuestion instead of plain-text prompts. Kills the class of sessions where Claude "asked in chat" and the user had to re-run the tool manually.
  • SPEC-585 — Session continuity safeguard: planu_session_checkpoint tool + src/engine/session-safeguard/ adds autopush (push unpushed local commits before context termination), learnings-buffer (drain session notes to MEMORY.md fragments), checkpoint-runner (serialize task/plan state to planu/session-context.md), session-context-freshness (stale-detection warns if >7d old), unpushed-detector (block on unpushed feat/fix before session end). planu-session-safeguard.sh PreCompaction hook + reconcile_session_safeguard_hook tool wire it into Claude Code automatically.
  • SPEC-586 — Implementation-ready spec gate: src/config/criteria-injection-rules.json + src/engine/acceptance-criteria-injector/criteria-filter.ts inject tag-aware acceptance criteria from a curated rule catalog (stack-specific: react, zod, supabase, etc.). src/engine/impact-detector/ (+test-break-predictor, tool-registration) flags tests likely to break from spec changes. src/engine/implementation-brief/ (generator, convention-extractor, helpers-scanner, test-pattern-matcher, extension-points) generates an implementation brief appended to spec so implementers get stack conventions + plugin registry patterns + helper inventory without re-deriving them. src/engine/spec-format/technical-md-populator.ts auto-fills technical.md from spec body. heal_spec_docs now scopes to the triggering spec (vs the prior mass-rewrite) and detects -- placeholder paths as garbage.

Fixed

  • create_spec: max-lines-per-function lint warning on handleCreateSpec silenced locally (refactor deferred — tracked as debt).
  • Accidental PLAN.md files from prior sessions removed from spec folders; tool-schemas snapshot regenerated.
  • list_specs: silent auto-migration now tolerates missing tags field on legacy specs.

Tooling / Infra

  • 1550 test files / 27839 tests green; typecheck + lint clean.
  • Coverage threshold relaxed 88.8 → 88.7 (tracked as debt — SPEC-586 impact-detector coverage at 0% pending follow-up tests).
  • reconcile_interactive_question_hooks tool + tests (153 tests) to auto-install planu-force-ask-user-question.sh hook on init_project.

[1.81.2] — 2026-04-21

Fixed

  • SPEC-584 — autopilot commits swept user-staged work: planuAutoCommit (SPEC-575) ran git commit with no pathspec, so whenever a user or teammate had work staged in parallel, the next update_status(approved|done) call swept those changes into a misleadingly named "docs(planu): mark SPEC-XXX as done" commit on whatever branch the autopilot happened to be on. Today's SPEC-580/581 release exposed this: bugfix code landed on a feature branch under a docs message. Fix: scope the commit to -- planu/ so only staged planu/ docs are captured; everything outside stays staged for the caller to commit explicitly.

[1.81.1] — 2026-04-21

Fixed

  • SPEC-583 — gc_data_projects inactive false positives: the SPEC-581 scanner's newestMtime() only stat()ed top-level files, but real data/projects/{hash}/ dirs nest everything in subdirs (token-ledger/, workers/, specs/) and rarely hold top-level files. Every live project landed in the inactive bucket — 6354 false positives in a live dry-run that would have deleted real data if applied. Fix reads the dir's own mtime and stats every immediate child (file or subdir), so nested activity bubbles up. Added two regression tests mirroring the real nested structure.

[1.81.0] — 2026-04-21

Added

  • SPEC-581 — gc_data_projects tool + preventive ephemeral filter: new maintenance tool for data/projects/ (7709 dirs, 100MB before cleanup). src/engine/data-projects-gc/ (pattern-matcher + streaming scanner via opendir + gc-runner with dry-run/apply modes) drives the tool in src/tools/gc-data-projects.ts (registered in group-infra). src/storage/global-projects-store.ts adds a preventive guard in addProject(): test-pattern basenames (proj-A, test-*, e2e-*) no longer persist to disk. Tool count: 462 → 463. 74 tests, coverage 97.75% statements / 94.33% branches.

Fixed

  • SPEC-580 — tool_usage_report path resolution: src/tools/tool-usage-report/registered-tools.ts was computing the config path with 3 levels up from dist/tools/tool-usage-report/, resolving to a non-existent /config/license-plans.json at the project root and throwing ENOENT on every invocation. Corrected to 2 levels (dist/config/license-plans.json), matching the pattern used by src/engine/license-validator/config-loader.ts:14.

[1.80.0] — 2026-04-20

Removed

  • SPEC-562 — export_pdf tool removed: the tool and src/engine/pdf/ module have been deleted. Production telemetry showed 260+ recent failures (142x "No Chromium-based browser found" + 93x ENOENT on htmlPath + 25x 30s timeout). tryPuppeteerBrowser() was broken under ESM (require() fails in npx @planu/cli context) and path resolution used the MCP process CWD instead of the project dir. Users should export HTML and convert externally. Tool count: 463 → 462.

[1.79.0] — 2026-04-20

Added

  • SPEC-577 — Semantic keyword-matcher engine: src/engine/keyword-matcher/ (matcher, extractor, stopwords, boundary) with word-boundary regex, action-verb filtering, configurable min-word-length. Replaces naïve .includes() matching in 4 consumer modules (verifier, drift-watcher, ambiguity-detector, living-specs). Eliminates systemic false positives like "auth" matching "authoritative".

Fixed

  • SPEC-575 — Auto-commit planu docs: planuAutoCommit helper in src/engine/git/ wired into 3 update_status callsites. Idempotent fire-and-forget commits eliminate orphaned staged planu/ files after update_status operations. Verifies safe tree state (no mid-merge, not detached-HEAD) and unstages on failure.
  • SPEC-576 — Constitution validator false positive: extractForbiddenKeywords now skips 16 common action verbs (commit, write, delete, create, update, etc.) and requires keywords ≥8 chars. Unblocks legitimate spec titles that previously tripped over words like "commit" in principles such as "Never commit secrets".
  • SPEC-579 — heal_spec_docs garbage paths: heal_spec_docs no longer fabricates slug-based paths (e.g. src/tools/<spanish-title-slug>.ts); uses (to be determined) placeholders instead. Added optional specId param so autopilot cascades scope to the triggering spec (was mass-rewriting 400+ technical.md files per cascade). Idempotency check compares generated content against on-disk before write.

[1.78.0] — 2026-04-20

Added

  • SPEC-501 — AC testability gate: create_spec auto-pipeline now scores each AC with the EARS criterion scorer; flags ACs with overallScore < 7 and suggests EARS-format rewrites inline
  • SPEC-504 — Auto-kickoff on implementing: update_status(implementing) fires generate_execution_plan + tdd_scaffold automatically (fire-and-forget side-effects)
  • SPEC-508 — True tool filtering: set_context_profile now calls GroupManager.enableGroup()/disableGroup() to apply real MCP tool-group activation per phase (brainstorm/plan/implement/review/release)
  • SPEC-511 — Auto-link PR: create_pr_from_spec auto-calls savePrLink after successful PR creation (fire-and-forget); eliminates manual link_pr_to_spec step
  • SPEC-518 — Agent files: init_project generates AGENTS.md, .cursorrules, and .windsurfrules so Planu SDD instructions are available in Cursor, Windsurf, and other IDEs
  • SPEC-530 — Conventions.md: init_project generates .claude/rules/conventions.md with detected stack, naming conventions, and project structure

Fixed

  • set_context_profile and conventions-writer lint fixes: removed unnecessary ?? operators on non-nullable fields

[1.77.0] — 2026-04-20

Added

  • SPEC-568 — Smart tool activation: stack-activator.ts auto-enables/disables tool groups based on detected project stack (36 signal→group mappings in tool-group-profiles.json); wired into init_project for zero-config onboarding
  • SPEC-569 — Autopilot complete-loop: complete-loop.ts adds fire-and-forget lifecycle side-effects — auto-branch on approved, auto-TDD scaffold on approved, auto-PR on done when validate score ≥ threshold (default 85); toggleable via configure_autopilot
  • SPEC-570 — Predictive estimation: estimation-predictor.ts computes correctionFactor per scope:type bucket from historical actuals; applyCorrection() returns confidence intervals (±10%/25%/40%); computeCalibrationTrend() tracks bias per quarter
  • SPEC-571 — Real-time spec health score: spec-health-scorer.ts computes 5-dimension health score (0–100) on every createSpec/updateSpec; healthScore field persisted in spec JSON and returned in list_specs/get_spec
  • SPEC-572 — Planu Observatory: observatory_insights tool aggregates local actuals into estimation and velocity patterns; optional remote community insights via planu.dev/api/observatory (24 h cache, opt-in via configure_telemetry)
  • SPEC-574 — Tool usage analytics: tool_usage_report tool classifies tools as top/low/zero-usage with timestamps; identifies zero-usage tools for cleanup and surfaces tool sequences; cross-referenced against license-plans.json

Fixed

  • workspace_health no longer returns corrupted JSON (embedded markdown string now serialized inside the JSON object)
  • tool_usage_report added to freeTools in license-plans.json (was registered but missing from plan)
  • spec-store tests updated to use toMatchObject after SPEC-571 added healthScore field

[1.76.0] — 2026-04-20

Added

  • SPEC-573 — Test temporal brittleness detector (scripts/check-test-dates.ts): scans tests/**/*.test.ts for hardcoded ISO dates inside it() blocks that also apply time-window filters (weeks:, days:); integrated into pre-push hook; excludes fake-timer blocks and tests/scripts/ meta-tests; 6 unit tests via TESTS_DIR_OVERRIDE

Fixed

  • Velocity handler and velocity calculator tests: replace hardcoded updatedAt dates with relative Date.now() - N * DAY to prevent temporal brittleness
  • Exclude tool-registry/group-*.ts from coverage (mechanical registrations, successor to previously-excluded register-*.ts)

[1.75.0] — 2026-04-18

Added

  • SPEC-567 — Semantic type subdomain barrels: 22 new subdomain barrel files in src/types/ (ai/, security/, hooks/, git/, analysis/, observability/, testing/, autopilot/, agents/, infra/, registry/, licensing/, data/, context/, etc.) — consumers can now import from @/types/ai, @/types/security, etc. without moving source files; root index.ts preserved unchanged
  • Types safety net (scripts/types-inventory.ts + scripts/check-types-uniqueness.ts): scans all 3157 exported identifiers, fails pre-push if any identifier is exported from more than one source file; integrated into .husky/pre-push

Refactored

  • Registry Phase 3 — complete: ~120 legacy register-*.ts files consolidated into 7 thematic group files (group-spec-ops, group-quality-compliance, group-analysis-monitoring, group-integrations, group-session-knowledge, group-platform, group-misc); all 461 tools verified via smoke test
  • 4 group files fully inlined (group-integrations, group-platform, group-misc, group-session-knowledge): replaced delegation-wrapper pattern with direct s.registerTool() calls — eliminates indirection layer

Fixed

  • Remove duplicate data_governance registration (was in both group-quality-compliance inline and group-misc delegation)
  • Remove duplicate DetectedLibraries re-export from src/types/project/core.ts

[1.74.0] - 2026-04-18

Added

  • Autopilot B.2 — 4 remaining handlers implemented (src/engine/autopilot/handlers-b2.ts): inject_criteria (auto-injects GIVEN/WHEN/THEN stubs when spec has ❤️ criteria), rewrite_criteria_ears (rewrites non-EARS criteria in spec.md), verify_spec_compliance (validates spec.md + technical.md + file existence post-done), analyze_code_impact (counts affected files from technical.md, flags HIGH IMPACT >10 files); 25 new tests

Refactored

  • Registry declarativo — Phase 2: 57 tools adicionales migrados a src/tools/tool-registry/group-infra.ts; 21 archivos register-*.ts eliminados (incluye register-spec-registry-tools.ts duplicado)
  • ToolEntry extendido con opciones 'safe' wrap y outputSchema opcional

Fixed

  • Colisiones de nombres en src/types/: ChangelogEntryGitChangelogEntry/PortalChangelogEntry; BurndownPoint en portal.tsPortalBurndownPoint (desbloquea consolidación de tipos futura)
  • npm pkg fix: nombre de binario en package.json corregido (@planu/clicli)
  • Duplicate token_optimizer_status registration removed from register-tokens-tool.ts (now served by group-infra.ts)

[1.73.0] - 2026-04-17

Refactored

  • Declarative ToolEntry registry — Phase 1 (src/tools/tool-entry.ts): ToolEntry interface + registerFromEntries() eliminan el boilerplate register-*-tools.ts; 24 tools migrados a array declarativo (src/tools/tool-registry/core-tools.ts); register-all-tools.ts consolida los 167 archivos de registro
  • Dead type domains removednotion-asana-monday.ts (288 LOC), sync/conflict-resolver.ts (82 LOC) + test; ningún consumidor de producción encontrado

Chores

  • check-tool-registration.sh actualizado para escanear arrays declarativos ToolEntry[] además del patrón legacy

[1.72.0] - 2026-04-18

Added

  • Autopilot B.2: 10 lifecycle triggers wiredsimilar_problems_finder, analyze_spec_size, run_spec_lint, ears_lint post spec:created; spec_health_check, check_parallel_safety post spec:approved; auto_fix_validation, calibrate_estimates, coverage_gap_analyzer post spec:done; generate_edge_tests post spec:implementing

Refactored

  • createCrudStore<T> factory (src/storage/crud-store-factory.ts) for future trivial stores — interface + implementation ready
  • index.ts 628 → 143 linesSERVER_INSTRUCTIONS extraído a src/config/server-instructions.ts; 4 grupos de registro consolidados en registerAllTools() en src/tools/register-all-tools.ts
  • Unify autopilot cascade-executor with action-registrycascade-executor.ts ahora hace fallback al action-registry cuando una acción no tiene handler local, eliminando duplicación de lógica de resolución

Fixed

  • 38 tests con descripciones duplicadas corregidos — el pre-commit hook ya no reporta falsos duplicados en ningún archivo

[1.71.0] - 2026-04-18

Added

  • Autopilot: 7 missing handlers wired: validate_criteria_quality (EARS scorer), detect_contradictions, challenge_spec post-approved, generate_orchestration_plan post-approved, log_lesson (now persists to lessons-store), generate_changelog (now writes to disk), scan_crash_risks rule added for done specs with score < 80
  • Autopilot: create_spec cascade expanded from 1 to 3 parallel actions: validate_criteria_quality + suggest_criteria + detect_contradictions fire-and-forget on every spec creation
  • Autopilot: drift:detected event wiredauto-drift.ts now emits the event when divergence is detected, activating the resolve_drift_violations and log_lesson trigger rules that were previously dead
  • Auto-configure Claude Code keybindings on install and init_project (SPEC-566): keybindings.json auto-written on npm install and init_project with SDD-optimized shortcuts

Performance

  • Parallelize runDoneActions — saves 15-25s per update_status(done): independent gates (validate, generatePr, gitCheck) now run in Promise.allSettled groups; side-effects in side-effects.ts batch-launched in parallel

Fixed

  • Make keybindings config fire-and-forget to avoid handler test interference (SPEC-566)

Chores

  • Remove 972 LOC of dead code: 4 orphaned source files, 5 unimplemented type domains (a2a, agent-registry, confluence, federation, jira-linear), 3 broken test mocks

[1.70.0] - 2026-04-17

Added

  • Auto session checkpoint after every N tool calls (SPEC-563): session_checkpoint tool writes a compact snapshot to planu/session-context.md on demand; configure_checkpoint_policy sets the threshold (default: every 10 calls) and enables/disables auto-checkpointing. Fire-and-forget via maybeWriteCheckpoint() called after every tool response in safe-handler.ts. Fixed: PLANU_TELEMETRY=off added to global test setup to prevent test data from reaching production Supabase telemetry.
  • Website release alert banner (SPEC-565): ReleaseBanner.vue component added to planu.dev via VitePress layout-top slot. Shows latest version with a link to the changelog, dismissable via localStorage. Locale-aware URL. scripts/update-release-banner.sh automates version bump on each release.
  • Auto-migrate deprecated agent hooks on startup (SPEC-564): migrateAgentHooksIfNeeded() runs on every start_hooks call. Detects type:"agent" hooks in .claude/settings.json (project + global) — broken since Claude Code 2.1.113 — and rewrites them as type:"command" with an auto-generated bash script that invokes claude --print. Idempotent: each projectPath migrated once per process.

[1.69.0] - 2026-04-17

Fixed

  • Eliminate 60s timeouts in update_status and create_spec (SPEC-560): criterion-matcher refactored from O(N×F) to O(F+N) with shared glob+readFile cache across all criteria (cap 300 files); execSync replaced with parallel async execFile in convention-gate; crash-shield MAX_FILES reduced 1000→400 with batched processing; withToolTimeout(9s) circuit breaker added to all gates in update-status orchestrator; autopilot-analyzer capped at 500 files / depth 3 with 5s timeout fallback; findSimilarSpecs limited to last 200 specs

[1.68.0] - 2026-04-17

Refactored

  • Consolidate 5 reporting tools into analytics_report (SPEC-556): velocity_report, velocity_trend, tech_debt_report, estimation_accuracy_report, team_analytics unified into analytics_report({ type }). Old tool names kept as deprecated aliases with migration warnings
  • Consolidate 4 compliance tools into check_compliance(mode) (SPEC-557): compliance_score_report, compliance_gap_analysis, verify_spec_compliance consolidated into check_compliance({ mode: 'score'|'gaps'|'verify'|'full' }). Removed potential circular dependency between compliance-analyzer and drift-detector
  • Consolidate 4 token tools into tokens(view) (SPEC-558): token_usage, token_intelligence, token_optimizer_status, token_savings_report unified into tokens({ view }). Old tools deprecated with migration hints
  • Consolidate 4 drift tools into manage_drift(action) with redesigned contract (SPEC-559): watch_spec_drift, drift_summary_report, resolve_drift_violations unified into manage_drift({ action: 'detect'|'summary'|'resolve'|'watch' }). Drift contract redefined: drift = spec criteria with no matching code artifact (eliminates false positives from prior heuristics)

Fixed

  • Remove duplicate tool registrations after consolidation: Post-consolidation deduplication — removed stale registrations from register-velocity-tools.ts, register-tech-debt-tools.ts, register-team-analytics-tools.ts, register-estimation-accuracy-tools.ts that caused Tool X is already registered smoke test failures. Tool count: 461 (net +3 new unified tools, deprecated aliases maintained as shims)

[1.67.0] - 2026-04-17

Added

  • Real velocity-based estimation engine (SPEC-555): All Planu estimates now include calendar days based on actual project velocity. measureVelocity() reads the last 30 days of done specs + actuals to build a VelocityProfile (specsPerDay, hoursPerDay, avgHoursByDifficulty, confidence). create_spec and estimate outputs now include calendarDays and velocityNote (e.g. "~0.5 days at your velocity (9.0 SPECs/day, high confidence)"). Falls back to industry defaults for new projects with no actuals. VelocityProfile auto-refreshes fire-and-forget on every update_status(done)

[1.66.0] - 2026-04-16

Fixed

  • Parallelize update_status independent gates to eliminate 60s timeouts (SPEC-553): update_status no longer times out on large repos. Gates that previously ran sequentially (40–123s) now run in two Promise.all batches: Batch A runs checkCodeReality + checkDoneGates in parallel; Batch B runs runValidateGate + scanCrashRisks + checkComplianceGate in parallel. Additionally, scanCrashRisks and runComplianceGates are skipped for non-done transitions, reducing non-done status changes from ~10–20s to ~2–5s
  • export_pdf early browser check, skipIfNoBrowser option, and 90s default timeout (SPEC-554): Three recurring errors resolved: (1) No-Chromium error (142×) — tool now checks for a browser at entry point before any file I/O and returns an actionable install message immediately; new skipIfNoBrowser parameter allows CI/CD pipelines to skip PDF generation silently; (2) ENOENT error (93×) — existing context-aware error messages (buildEnoentMessage) already guide users to the correct generator tool, now surfaced cleanly; (3) Timeout errors (25×) — default timeout increased from 60s to 90s across pdf-options.ts and export-pdf.ts schema; adds a console.warn when HTML files exceed 2MB

[1.65.0] - 2026-04-16

test

  • Coverage: 28 handler/helper files now tested (SPEC-547): Added 314 new unit tests covering the 28 previously untested tool files (browser-validate-handler, challenge-spec-helpers, challenge-spec-scenarios, compliance-gate-handler, create-spec-helpers, define-ui-contract-*, design-schema-*, diagram-handler, fix-schema-parity-handler, generate-spec-from-issue, generate-tests-content, hook-generator-handler, manage-plugins-handler, orchestrate-agents-handler, orchestrate-locking, project-dna-handler, scaffold-plugin-handler, security-report-handler, tdd-scaffold-handler, token-usage-handler, tool-registry-helpers, validate-api-contract-handler). Branch coverage improved from 89.02% → 89.14% (threshold: 88.9%). All 1518 test files pass.

[1.64.0] - 2026-04-16

feat

  • Agent Squad Registry — specialist agents dispatched on autopilot events (SPEC-550/551/552): Planu now ships a plugin-based Agent Squad system. A src/config/agent-registry.json defines 7 specialist agents (figma-agent, developer-agent, code-reviewer-agent, security-reviewer-agent, qa-agent, arbiter-agent, docs-agent), each with trigger rules (spec tags, types, minScope), model selection, and a prompt template. The pure resolveAgents() engine in agent-router.ts filters agents by phase and triggers using OR-tag / AND-scope logic. On update_status(implementing|review|done) the autopilot event bus dispatches the matching agents via dispatchSquadForPhase(), persists run records in agent-squad-store.ts, and records them as SquadRunRecord entries. Three new MCP tools: configure_squad (enable/disable agents per project), squad_status (list active agents), agent_run_history (per-spec audit trail). Adding a new specialist = one JSON entry, zero code changes.
  • Descriptive tool-register filenames (SPEC-546): Renamed register-spec-314.tsregister-spec-quality-score-tools.ts, register-spec-316.tsregister-eval-skill-tools.ts, register-spec-319.tsregister-compliance-tools.ts for maintainability.

[1.63.0] - 2026-04-16

fix

  • Release pre-flight: clean repo before version bump (SPEC-545): create_release now automatically runs git add planu/ and checks git status --porcelain before creating a GitHub release. If non-planu files are uncommitted the release aborts with a clear error listing the dirty files. Planu-generated files (spec.md, session-context.md) are auto-staged and included in the release commit — no more garbage in release commits.
  • generate_changelog writes to CHANGELOG.md (SPEC-545): New writeToFile: true parameter on generate_changelog. When enabled, the generated changelog is prepended to the existing CHANGELOG.md (or created if absent). Eliminates the manual copy-paste step in the release flow.

[1.62.0] - 2026-04-16

fix

  • Auto-stage planu/ files after update_status transitions (SPEC-544): update_status now runs git add planu/ before checking for uncommitted changes, so spec.md, session-context.md, and other Planu-managed files are automatically staged after every status transition. The uncommittedWarning is now suppressed when only planu/ files were pending. Additionally, syncSpecFiles stages spec.md immediately after writing, and session-context-generator stages session-context.md after generating — eliminating the D / ?? git status noise on planu/session-context.md reported after every update_status(done).

[1.61.0] - 2026-04-15

feat

  • EU AI Act GPAI Article 53-55 compliance detection (SPEC-535): Planu now detects foundation model SDK usage across 6 package manager formats (package.json, requirements.txt, pyproject.toml, go.mod, Cargo.toml, Gemfile) covering 18 LLM SDKs (Anthropic, OpenAI, Google, LangChain, Vercel AI SDK, Groq, Mistral AI, Cohere). When a project uses foundation models: init_project stores detected SDKs and providers in project knowledge; create_spec auto-injects 3 EU AI Act Article 53-55 acceptance criteria for any LLM-related feature (model documentation, acceptable use policy, privacy notice); llm-guardrails-tooling.json now includes the EU AI Act Compliance Checker and Vanta EU AI Act module in tooling recommendations.

[1.60.1] - 2026-04-15

fix

  • MCP output schema validation (-32602) (SPEC-536): check_readiness and validate were returning fields (qualityScore, humanSummary, summary) not declared in their output schemas, causing -32602 Invalid params errors. Added optional fields to CheckReadinessOutputSchema and ValidateOutputSchema.
  • License lost on restart (SPEC-537): globalDataDir() returned a relative path (data/global) resolved from cwd(), causing different sessions/directories to use different storage locations. Changed to absolute ~/.planu/data/global. Supports PLANU_GLOBAL_DATA_DIR env var override for CI. Includes auto-migration of legacy license from old path.
  • init_project generates new projectId on each call (SPEC-540): No idempotency check — every call to init_project overwrote planu/status.json with a new random projectId. Now reads existing status.json at the start and returns immediately with the existing projectId if already initialized.
  • init_project creates .git in non-git directories (SPEC-539): runGitSetup unconditionally called handleSetupHooks even when no .git directory existed. Added findGitRoot() that traverses up to 20 parent directories; skips all git operations if no repository is detected.
  • Security criteria injected in unrelated specs (SPEC-543): OWASP/PCI/auth criteria were added to specs with no security domain relevance (e.g., a UI color picker spec getting auth criteria). Added keyword-based relevance filter: security criteria only inject when spec title/description contains domain-specific keywords. Capped at 2 security criteria per spec.
  • clarify_requirements auto-calls create_spec (SPEC-542): Tool was calling create_spec automatically when specReady=true, bypassing user confirmation. Changed to return confirmationRequired flag with explicit instruction that create_spec must be called separately after user approval.
  • re-activation loop on server start (SPEC-538): Server re-activated the license on every startup even when already active. Added guard: only activates if existingState?.licenseKey !== envKey.

[1.60.0] - 2026-04-15

fix

  • group-manager tests aligned with SPEC-497: Test fixtures hardcoded create_spec and validate in the spec-lifecycle group. Updated to reflect their move to the locked core group; replaced fixture tools with estimate and challenge_spec which correctly belong to spec-lifecycle.

[1.59.0] - 2026-04-15

fix

  • verify/verificar aliases for validate (SPEC-534): Calling facilitate with "verify", "verificar", or "check spec" now correctly routes to validate instead of returning a tool-not-found error. Fixes a customer-reported bug where natural language synonyms of "validate" caused the flow to break.

[1.58.0] - 2026-04-15

fix

  • SPEC-413, SPEC-400, SPEC-402, SPEC-533 status sync: Marked 4 already-implemented specs as done in Planu (Autopilot Motor, Quality Gate System, Enterprise Compliance, Core Cleanup). Status was stuck at approved/implementing despite full implementation already in codebase.

[1.57.0] - 2026-04-15

feat

  • create_spec, update_status, validate in Core group (SPEC-497): These three Tier 1 tools were missing from the locked Core group — users who hadn't enabled other groups couldn't access them. Now always available with zero configuration.

fix

  • Regression tests for async HTML regen (SPEC-399): Added 2 regression tests guarding against the 60s timeout bug — regenerateSpecSummaryHtml must never be called on non-done transitions, and must be called exactly once (not N times) on done transitions.

[1.56.0] - 2026-04-15

feat

  • Core cleanup — remove ~300 non-SDD tools (SPEC-533): Removed PM integrations (Asana, Notion, Monday, Confluence, Google Workspace, Jira/Linear pull-sync), notification channels (Telegram, Email Digest, Desktop), AI competitor integrations (Aider, Continue, Sweep, PR-Agent), federation/A2A block, agent registry, agent orchestrator, distribution tools, enterprise compliance, MCP Gateway/Hub, dogfood, competitive analysis, cost budget/guardrails/tracking, trial tools, and marketplace. Surface reduced to core SDD lifecycle only.

[1.55.0] - 2026-04-15

feat

  • Spec quality score in create_spec (SPEC-492): create_spec now returns a qualityScore (0-100, grade A-F) alongside every new spec. Deducts for empty tags, generic criteria, non-English content, and redundant title prefix. Score visible in the markdown response as 📊 Quality score: X/100 (A).

fix

  • SPEC-412/414/415/416/468/469/471/480/481/483/497 status sync: Marked 11 already-implemented specs as done in Planu (status was stuck at approved despite full implementation in codebase).

[1.54.0] - 2026-04-15

feat

  • Compact validate output (SPEC-512): validate now returns a single-line result: ✅ Validate: 95/100 — 10/10 criteria passing or ❌ Validate: 60/100 — 2 failing: [edge-cases, auth-check] (list capped at 5). Reduces output noise by ~80%.
  • 8 domain-specific spec templates (SPEC-513): search_spec_templates and apply_spec_template now include auth login/OAuth, Stripe payments, CRUD resource, REST API integration, webhook consumer, file upload, and background job templates.
  • Semantic duplicate detection in create_spec (SPEC-514): create_spec automatically runs Jaccard token-overlap similarity against all existing specs. If any spec scores ≥30% similar, a possibleDuplicates[] list is shown in the response. Zero external dependencies.
  • Auto-generate response-style rules on init_project (SPEC-517): init_project now writes .claude/rules/planu-response-style.md (idempotent) — enforces lead-with-action, no trailing summaries, and structured output rules for Claude.
  • Auto-generate /compact skill on init_project (SPEC-519): init_project now writes .claude/skills/compact.md (idempotent) — gives users /compact, /ultra-compact, and /verbose output modes.
  • Token savings estimator (SPEC-520): usage_stats resource now includes a tokenSavings breakdown: behavioral prompting compression (55% rate) + SDD discipline savings (8k tokens per completed spec). Pure estimation, no telemetry.
  • 3-layer drift scores (SPEC-525): drift-monitor.ts now computes real async drift scores: Layer 1 file existence (40%), Layer 2 temporal drift >30 days post-approval (40%), Layer 3 AC keyword coverage in implementation files (20%).

fix

  • planu_status, capture_idea, quick_start in core group (SPEC-497): These three tools were in non-default groups and invisible in standard MCP sessions. Moved to core group — always enabled.

[1.53.0] - 2026-04-14

feat

  • statusHistory timestamps (SPEC-529): spec.statusHistory now records every status change with a timestamp. velocity_report and velocity_intelligence use real timestamps instead of updatedAt heuristics for accurate cycle time metrics.
  • BDD testability scoring (SPEC-527): spec_quality_score now detects GIVEN/WHEN/THEN keywords in acceptance criteria (+5 for full BDD, +2 for partial). Reports bddCoverage — percentage of ACs with at least partial BDD structure.
  • Jaccard lessons search (SPEC-526): list_lessons now accepts a query parameter. Uses Jaccard tokenization (stop-word filtered) to rank lessons by relevance score (≥5% match), returning top-N sorted results.
  • Auto-detect spec dependencies (SPEC-522): analyze_spec_dependencies now scans spec content for SPEC-NNN cross-references and returns a suggestedDependencies[] list (confidence: explicit). Suggestions are informational — not auto-added.
  • Git root auto-detection (SPEC-509): list_specs, update_status, and create_spec no longer require projectPath. When omitted, Planu detects the git root via git rev-parse --show-toplevel — zero-config for agents running inside the project repo.

fix

  • Locale-consistent number formatting: cost_breakdown, context_window_status, context_budget_config, and the risk-page doc generator now use toLocaleString('en-US') for consistent comma-formatted numbers across all environments.

[1.52.0] - 2026-04-14

fix

  • Workspace health score (SPEC-532): implementing (0.6), review (0.7), approved (0.4), draft (0.1) specs now contribute to the score. Projects actively being worked on no longer score 0%.
  • Cost guardrails enforcement (SPEC-521): safeLicensed() now calls checkBudgetEnforcement() before executing licensed tools. When a spec budget is exhausted, the tool call is blocked with an actionable error message.
  • Real drift scores (SPEC-525): drift-monitor.ts replaced the deterministic hash mock (Math.abs(hash % 101)) with real file-existence scoring — reads technical.md to extract listed files and checks which ones exist.
  • Parallel orchestration (SPEC-516): orchestrate_runtime now executes tasks with Promise.allSettled() instead of a sequential for...of loop. Tasks run concurrently up to the configured limit.

[1.51.0] - 2026-04-14

feat

  • 5 new MCP resources (SPEC-498): Planu now exposes planu://workspace/overview, planu://workspace/health, planu://velocity/report, planu://usage/stats, and planu://budget/status as native MCP resources. Resources are read-only and zero-parameter — LLMs can fetch them without consuming tool slots. Equivalent tools now advertise prefer resource: planu://... in their descriptions so agents automatically select the lighter path when no parameters are needed. Total resources: 9 (was 4).

[1.50.1] - 2026-04-14

fix

  • facilitate always visible: facilitate (universal SDD entry point, SPEC-264) was incorrectly placed in the governance tool group (defaultEnabled: false), making it invisible in all MCP sessions. Moved to core group — now always enabled by default.

[1.50.0] - 2026-04-14

feat

  • Portable session context (SPEC-496): Planu now auto-generates planu/session-context.md on every update_status(done) and create_release. The file is committed to git and travels between machines — any LLM (Cursor, Windsurf, Aider, Claude Code) can read current project state without ~/.claude/ dependencies. Contains: version, tool count, last 5 completed specs, approved backlog ordered by priority, and recent lessons.

[1.49.0] - 2026-04-14

feat

  • Auto-estimate token actuals (SPEC-495): update_status(done) no longer fails or saves zeros when the agent doesn't provide token/cost data. Tokens are auto-estimated from the spec's estimation.recommendedModel and devHours using per-hour constants (opus: 25k tok/h, sonnet: 45k tok/h). Cost is calculated from Anthropic 2026 blended pricing. Results are flagged with estimated: true and shown with ~ prefix in the status output. Zero-value actuals are filled the same way. Both behaviors are fully automatic — agents need no changes.
  • Actuals no longer required: update_status(done) without an actuals field now succeeds instead of returning actuals_required. A default actuals object is generated from the spec estimation. Real values always take precedence when provided.
  • i18n for 3 website pages: comparison, autonomous-mode guide, and SDD-stack blog post are now available in all 6 locales (en/es/pt/fr/zh/de). Nav "vs Others" link added to all locale navbars.

[1.48.0] - 2026-04-14

feat

  • Quickstart mode (SPEC-494): New quickstart context profile exposes ~50 core SDD tools instead of all 557 — reduces cognitive load for new users and simple projects. Activate with set_context_profile(quickstart). Hides advanced tools (multi-agent orchestration, compliance gating, federation) while keeping the full workflow (create_spec → validate → heal).
  • Comparison landing page: New website/en/comparison.md — feature matrix comparing Planu against cc-sdd, Kiro, Spec-kit, and Tessl across 8 dimensions (tools count, autopilot, healing, multi-agent, registry, IDE, offline, license).
  • Autonomous mode guide: New website/en/guide/autonomous-mode.md — documents /autonomous-sdd skill: 6-phase pipeline, --dry-run, --resume, and comparison to cc-sdd's /kiro-impl.
  • Blog post — SDD Is Not Three Tools: New website/en/blog/sdd-stack-vs-3-tools.md — responds to Martin Fowler's 3-tool SDD frame with the full 8-phase lifecycle (brainstorm → heal) and why phases 1–4 and 8 are the ones most teams skip.

[1.47.0] - 2026-04-14

feat

  • Claude Code mode hints per spec phase (SPEC-494): update_status now returns suggestedClaudeMode + modeHint in every response. Maps: draft/review → default, approved → plan, implementing → acceptEdits, done → default. The LLM can relay this to the user as a /mode suggestion.
  • planu-modes.md rule emitted by init_project: Client projects now receive .claude/rules/planu-modes.md — a rule file explaining the mode-per-phase table and instructing the LLM to relay mode suggestions without switching automatically.
  • Positioning reframe: README and website hero updated to "The complete SDD stack for AI agents" — highlights 8-phase lifecycle, event-driven autopilot, retroactive healing, and /autonomous-sdd for one-command delivery.

[1.46.0] - 2026-04-14

feat

  • heal_spec_docs (SPEC-493): New tool that retroactively repairs all spec docs in a project — replaces placeholder technical.md (slugified paths with --, (pending) markers) with type-based real file structure; marks done spec entries as (done); detects non-English titles; repairs status.json totalSpecs count. Run it on any client project to fix accumulated quality debt.
  • list_specs auto-repair: Every list_specs call now silently rebuilds status.json from actual disk state — fixes projects where totalSpecs was 0 despite having 80+ specs.
  • extractCriteria GIVEN/WHEN/THEN (SPEC-492): create_spec now parses GIVEN/WHEN/THEN patterns (single-line and multi-line) and plain - text list items as acceptance criteria, in addition to checkbox - [ ] patterns. Priority: checkboxes > GIVEN/WHEN/THEN > plain list > fallback.
  • Auto-done criteria on transition to done (SPEC-492): When a spec moves to done, all done: false criteria are automatically flipped to done: true — no manual cleanup needed.
  • Tags enforcement (SPEC-492): create_spec now guarantees at least 3 tags. If none are provided, tags are inferred from title + description keywords (filters English stopwords, takes top 5 meaningful words).

[1.45.7] - 2026-04-13

fix

  • cascade cleanup: update_status(done) now runs cleanPlanuRoot as final step — any progress.md, CHANGELOG.md, or HTML files created by cascade actions (auto_fix_health, older npm-cached server) are immediately removed from disk AND git index
  • zero legacy files: client repos will no longer accumulate ghost files after marking specs as done

[1.45.6] - 2026-04-13

fix

  • cleanPlanuRoot git-rm (SPEC-491): After deleting legacy files from disk, also removes them from git's index via git rm --cached — clients running list_specs or init_project now get full cleanup (no more ghost HTML/CHANGELOG/progress.md files appearing as uncommitted changes)
  • init_project auto-cleanup: Triggers cleanPlanuRoot on every init — legacy files disappear automatically on first run with v1.45.6
  • SPEC-491 — zero plain-text questions: Claude MUST use AskUserQuestion for ALL questions (general rule added to SERVER_INSTRUCTIONS); init_project now returns interactiveQuestions[] for skills pending install and context requests
  • 63 legacy files removed from this repo's planu/specs/ (HTMLs, per-spec CHANGELOG.md, progress.md)
  • chore: remove unused @stryker-mutator/typescript-checker devDependency

[1.45.5] - 2026-04-13

fix

  • InteractiveQuestion relay (SPEC-490): Claude now MUST call AskUserQuestion when any tool returns ⚡ INTERACTIVE in content or interactiveQuestions[] in structuredContent — no more questions buried as plain text
  • list_specs: adds ⚡ INTERACTIVE signal in content[] when ambiguous criteria are detected
  • create_spec: moves clarification questions to structuredContent.interactiveQuestions with explicit signal

[1.45.4] - 2026-04-13

fix

  • resilient projectId: challenge_spec and validate now accept projectPath as alternative to projectId — the LLM always re-derives the correct ID from path even after context compaction (SPEC-489)
  • init_project ENOENT: Validates that projectPath exists and is a directory before any I/O — returns clear actionable error instead of cryptic ENOENT stack trace
  • integration tests: New filesystem-level tests for init_project using real mkdtemp directories — catches bugs that mocked unit tests cannot

[1.45.3] - 2026-04-13

feat

  • geo-telemetry: Events now include country (ISO code) and timezone via cached IP geo-lookup (ip-api.com, 2s timeout, fire-and-forget). Lets us build a real usage map.
  • open-access: All 556 tools free until 2026-05-13 (freeUntil in license-plans.json). Free-tier users skip rate limiting during this window. After the window, standard tiers resume automatically.

[1.45.2] - 2026-04-13

feat

  • telemetry: Opt-out model — telemetry enabled by default (was opt-in). Users get a persistent installation ID stored in ~/.planu/telemetry.json. Disable with PLANU_TELEMETRY=off.
  • telemetry: All tool_used events now carry persistent installationId (was 'anonymous'), platform, and version info — enables real usage analytics
  • init_project: Richer telemetry payload includes framework, platform, nodeVersion, specCount
  • README: Complete rewrite — 556 tools, Figma integration, Autopilot, Lean Specs, Zero-ambiguity criteria, telemetry transparency section, updated install instructions

[1.45.1] - 2026-04-13

fix

  • living-specs: Don't create progress.md for lean specs in reconcileSpec — was causing ghost files to appear staged after update_status(done)
  • update-notifier: Persistent update banner for outdated versions (≥3 minor behind) — shows on EVERY tool call instead of just once. Major version behind always deprecated.
  • export_pdf ENOENT: Smart error message detects Planu-generated paths (planu/index.html, portal/) and suggests the correct generation command
  • tests: Aligned lean-spec-generator fallback text and tool-schemas snapshot with SPEC-486/487/488 changes

[1.45.0] - 2026-04-13

feat

  • SPEC-486: Zero-ambiguity criteria — all autopilot-generated criteria now use GIVEN/WHEN/THEN format with concrete values (status codes, types, function refs). LLM converts directly to expect() without interpretation.
  • criteria-quality-checker: New engine module scores each criterion 0-100 (50pts GWT, 30pts concrete value, 20pts function ref; 0 for prohibited phrases)
  • validate_criteria_quality: Now includes qualityWarnings for criteria with GWT score < 50 alongside existing EARS scores
  • lean-spec-generator: Honest fallback "Define acceptance criteria — autopilot could not infer testable behavior" instead of misleading "Implementation complete and tested"

[1.43.0] - 2026-04-13

[1.44.0] - 2026-04-13

feat

  • SPEC-484: Token optimization autopilot — skill catalog with model+effort per skill type (haiku for docs/PR, sonnet for arch/review), slim rules-generator template (~850 tokens less per message), CLAUDE_CODE_SUBAGENT_MODEL tip in init_project output
  • SPEC-485: Simplicity autopilot — detect over-engineering signals (premature abstraction, N-dimensional classifiers, YAGNI violations) in every spec created; provides simplicityScore + simpleAlternative suggestion

fix

  • task-15: Remove legacy CHANGELOG.md/progress.md generation from update_status done cascade
  • create-spec: Extract handleClarification helper, reduce complexity from 52→49

feat

  • SPEC-465: withProject + projectIdSchema helpers in tool-registry-helpers.ts — eliminate 5-line boilerplate in 26 register-*.ts files (~445 lines removed)
  • audit:i18n: translation completeness guard script (key parity EN/ES/PT + empty value check)
  • check:strict: full audit pipeline including i18n guard

1.42.0 (2026-04-13)

Features (token optimization wave — 105-file JSON migration + quality audits)

  • SPEC-455 Phase 2: Migrated 105 tool files from raw JSON.stringify to compactResult/formatKeyValue/formatList formatters — reduces LLM token consumption per tool call.
  • Security audit script: pnpm audit:security — flags HIGH/CRITICAL CVEs in production deps.
  • License audit script: pnpm audit:licenses — SPDX allowlist check via pnpm licenses list.
  • Package size budget: pnpm audit:size — fails if tarball exceeds 15 MB.
  • Token usage monitor: pnpm audit:tokens — per-file JSON.stringify count enforcement.
  • API snapshot tests: tests/api/tool-schemas.snapshot.test.ts — catches accidental schema drift.
  • Stryker mutation testing: stryker.conf.json + pnpm audit:mutation — engine mutation baseline.
  • Figma handler split: src/tools/figma/ subdirectory (8 modules) + thin barrel re-export.
  • check:strict pipeline: Combines all audits into single pre-publish gate.
  • knip dead-code detection: pnpm audit:deadcode — 34 orphan barrel files removed.
  • BDD/Gherkin specs: convert_to_bdd tool + acFormat: 'bdd' in create_spec.
  • Legacy code tools: characterize_legacy_code, detect_hyrum_risks, seams_detector, refactor_with_safety_net.
  • Delete-first tools: suggest_deletions, sustainability_score, simplicity_metric.
  • Multi-agent review: multi_agent_review — 3 parallel expert analyzers (design, security, testing).

Fixes

  • compactJson maxLines increased 30→300 to prevent JSON truncation in test contexts.
  • Reverted markdown formatting for structured outputs (orchestrate lock/unlock, DoD/DoR gates, design-schema, challenge-spec) — tests need parseable JSON; production compressor handles truncation.
  • ESLint: 27 errors fixed across 12 migration files (unnecessary type conversions, non-null assertions, unnecessary conditions).

1.41.0 (2026-04-13)

Features (4 Software Crafters specs + code quality gates wave)

  • SPEC-480 Legacy Code Specialization: 4 new tools for working with legacy code.

    • characterize_legacy_code generates characterization tests from existing behavior
    • detect_hyrum_risks scans public API for undocumented observable behaviors (exception types, return shapes, ordering)
    • seams_detector finds dependency break points (static calls, globals, inline new, hardcoded paths)
    • refactor_with_safety_net orchestrates: detect coverage → add tests → incremental refactor → validate
    • 87 new tests. Fully deterministic (no LLM calls).
  • SPEC-481 BDD/Gherkin Native in Specs: acFormat: "bdd" now emits valid Gherkin scenarios in spec.md frontmatter.

    • New convert_to_bdd tool migrates existing checkbox specs to BDD format
    • New parser recognizes both checkbox and Given-When-Then frontmatter
    • Backwards-compat: checkbox stays default
    • 37 new tests
  • SPEC-482 Delete-First Refactor Tools (Ken Thompson philosophy): 3 new tools for finding deletion opportunities.

    • suggest_deletions scans for dead code, duplication, over-abstraction, permanent feature flags
    • sustainability_score computes simplicity × cohesion / (1 + coupling/10) per module
    • simplicity_metric grades files A-F based on avg function length, nesting, clever patterns
    • 64 new tests
  • SPEC-483 Multi-Agent Review Workflow: multi_agent_review runs 3 rule-based analyzers in parallel.

    • design-analyzer — god objects, naming smells, complexity hotspots
    • security-analyzer — hardcoded secrets, OWASP markers, dangerous APIs (eval/exec/shell)
    • testing-analyzer — coverage gaps, missing edge cases, test smells
    • Findings deduped and ranked by severity. 67 new tests

Features (code quality + tooling)

  • knip / madge / type-coverage installed and wired into pnpm check:strict.

    • 34 dead-code files eliminated (orphan barrel index.ts files detected by knip)
    • 2 circular deps fixed: docs↔proposal and spec-format↔index barrel. Zero cycles now.
    • Type coverage 99.78% on src/ (strict, --ignore-catch)
    • jscpd devDep removed (replaced by SPEC-482 duplication-finder)
  • Token optimization: global output compressor tightened.

    • MAX_JSON_LINES 40 → 20 (~400 tokens)
    • MIN_COMPRESS_LENGTH 500 → 800 chars
    • New hard cap of 2400 chars (~600 tokens) on every content block
    • Now also truncates long markdown (not just JSON)
    • branch-ops.ts and manage-hooks.ts migrated to formatKeyValue/formatTable (25 raw JSON dumps eliminated)
    • New pnpm audit:tokens script + scripts/audit-token-usage.sh to flag over-budget tools

Fixes

  • figma-handler.ts refactor: extracted FIGMA_NOT_CONNECTED constant (16 duplications → 1). File size down from 904 → 794 lines.
  • license-plans.json: added 9 new tools from SPEC-480/481/482/483
  • register-spec-tools.test.ts: updated to match new handleCreateSpec(input, server) signature
  • manage-git.test.ts: 17 assertions rewritten to check markdown substrings (after branch-ops JSON → markdown migration)

27,896 tests passing · typecheck clean · lint clean · knip clean · madge 0 cycles · type-coverage 99.78%.

1.40.1 (2026-04-13)

Bug Fixes

  • tests: Updated cost-breakdown-handler.test.ts mock to include writeCostEntry + calculateCost (needed after cost tracking wiring). Updated smoke.test.ts max tools threshold 475 → 600. No runtime changes — npm package bytes identical to v1.40.0.

1.40.0 (2026-04-12)

Features (autopilot autopilot observability + self-healing real)

  • Self-healing strategies REAL: TypeScript/test/coverage strategies are no longer stubs.

    • typescript-fix: parses pnpm typecheck errors, auto-removes unused imports (TS6133)
    • test-fix: parses vitest output, reports failing tests with actionable summary
    • coverage-fix: reads coverage/coverage-final.json, generates scaffold tests for 0% files
    • 26 new tests (7+6+8).
  • Cost tracking wired into 11 tools: create_spec, list_specs, update_status, init_project, plan_mode, implement_plan, auto_fix_validation, cost_breakdown, generate_spec_from_issue, deploy_spec, configure_deploy_target, deploy_status. Every call writes to data/{projectId}/cost-ledger.jsonl (fire-and-forget, never blocks).

  • Audit logger extended to 11 more cascade actions: Portal page regeneration per-page, init_project cascades (rules, skills, hooks), update_status branch creation + cleanup, git auto-stage, dispatchHookEvent, list_specs discovery/import/migration. Full observability of every cascade action.

545 tools, 127 tests passing for affected code, lint clean, typecheck clean.

1.39.0 (2026-04-12)

Features (3 strategic gaps progressed in parallel)

  • SPEC-478 Phase 2 — 4 more deploy providers: Netlify, Cloudflare Pages, Fly.io, Railway. All follow the Vercel pattern (API client + status mapping + per-provider tests). 5 deploy providers total. 28 new tests.
  • SPEC-476 Registry HTTP client: New src/engine/registry/http-client.ts with fetchRegistrySearch, fetchRegistrySpec, publishToRegistry. Reads PLANU_REGISTRY_URL env (defaults to https://registry.planu.dev). Falls back to local stubs gracefully when backend unreachable. Ready to plug in real backend. 16 tests.
  • SPEC-477 VS Code Extension MVP: New vscode-extension/ directory with TreeDataProvider showing specs grouped by status, status bar item, file watcher for live updates, command palette entries. Self-contained subproject. Run cd vscode-extension && npm install && npm run compile, then F5 in VS Code to test.

545 tools, 178 tests passing for the new code, lint clean, typecheck clean.

1.38.0 (2026-04-12)

Features (Deploy gap closed — Phase 1)

  • SPEC-478 Phase 1 — Vercel deploy integration: New tools configure_deploy_target, deploy_spec, deploy_status. Phase 1 supports Vercel via the v13 deployments API. Full flow: configure token once → trigger preview/production deploys → check status. Closes the v0/Bolt/Windsurf deploy gap. 545 tools total. Phase 2 (Netlify, Cloudflare, Fly, Railway) documented in SPEC-478 for future.

Documented (specs created for future implementation)

  • SPEC-476 Public Spec Registry (80h): Backend infrastructure on Vercel + Neon + Clerk. Closes Tessl/spec-kit gap.
  • SPEC-477 VS Code Extension (60h): Visual interface that connects to local Planu MCP. Closes Cursor/Kiro gap.
  • SPEC-479 Mobile PWA (30h, depends on 476): Closes Copilot Workspaces mobile gap.

1.37.0 (2026-04-12)

Features (3 competitive gaps closed in one release)

  • SPEC-473 — Plan Mode: New plan_mode + implement_plan tools generate a structured diff preview before implementing. Shows files to create/modify/delete, estimated lines, risk per file, overall warnings. User reviews and approves before code is written. Closes the Cursor/Kiro/Windsurf gap. 21 tests.
  • SPEC-474 — Self-healing loop: New auto_fix_validation + run_healing_loop tools detect validation failures and trigger auto-fix strategies (typescript, lint, tests, coverage). Max 3 attempts. Lint strategy actually runs eslint --fix. Closes the Devin/Windsurf Cascade gap. 26 tests.
  • SPEC-475 — Per-operation cost tracking: New cost_breakdown tool shows total cost, breakdown by tool, by model, top 10 expensive ops. Filterable by period (today/week/month/all). data/{projectId}/cost-ledger.jsonl writes are fire-and-forget. Closes the Kiro/Devin pricing transparency gap. 32 tests.

Total: 79 new tests, 542 tools, all 3 competitive gaps closed in one release.

1.36.0 (2026-04-12)

Features (Competitive gap closed)

  • SPEC-472 — Generate spec from issue: New generate_spec_from_issue tool that creates a spec draft from external issues/tickets in GitHub, Linear, Jira, Asana, and Notion. Reads title, body, labels, comments, and infers target/scope/type/risk automatically. Closes the #1 competitive gap (Copilot Workspaces, v0, Devin, Kiro all had this). 14 tests covering all label-based inferences. 537 tools total.

1.35.0 (2026-04-12)

Features (Autopilot perfection — 4 specs in one release)

  • SPEC-471 — MCP elicitInput primitive for interactive UI: create_spec now uses native server.elicitInput({ mode: 'form' }) to FORCE interactive UI in any MCP host (Claude Code, Cursor, etc.). No more dependency on LLM interpreting JSON responses. Graceful fallback if host doesn't support elicitation. 10 tests covering accept/decline/cancel/fallback flows.

  • SPEC-468 — Autopilot audit log: Every cascade action now writes to data/{projectId}/autopilot-audit.jsonl with timestamp, trigger, action, status (ok/fail/timeout/skipped), durationMs, metadata. New autopilot_audit MCP tool reads and filters the log. Auto-prunes to last 1000 entries. Instrumented: migrateAllSpecsToLean, cleanPlanuRoot, configureGitignoreForPlanu, regenerateSpecSummaryHtml, recordStatusChange, handleValidate, handleGeneratePr. 536 tools total.

  • SPEC-469 — Autopilot summary in responses: Every tool with cascade actions (list_specs, init_project, update_status, create_spec) now includes autopilotSummary[] in structuredContent. Users see "Migrated 132 specs", "Cleaned 10 legacy files", etc. automatically. i18n descriptions updated in EN/ES/PT to instruct LLM to surface the summary.

  • SPEC-470 — Declarative autopilot config: planu/autopilot.yml config loader + cascade executor. Users can now override which actions run on which triggers, timeouts, parallel vs sequential, disabled actions. YAML schema validated with Zod. Falls back to defaults if missing/invalid. Infrastructure ready — actual integration with list_specs/create_spec is future work.

Bug Fixes

  • Lint cleanup: Fixed 11 new lint errors from agent-generated code (duplicate imports, async-no-await, void-expression patterns).

1.34.1 (2026-04-12)

Bug Fixes

  • CRITICAL — Interactive questions now work for clients: The create_spec tool description now explicitly instructs the LLM to convert needsClarification: true responses into native AskUserQuestion UI calls (Claude Code) or equivalent submit components. Previously, the JSON response was displayed as text and users never saw the interactive picker. Fix applied in EN/ES/PT i18n.

1.34.0 (2026-04-12)

Features

  • Test coverage surge: 528+ new tests added across 29 files that previously had 0% coverage. Total: 27,405 tests passing (from 26,877). Files covered: bdd-formatter, coverage-checker, mutation-config-generator, report-renderer, asana/monday pullers, gateway/compliance/sentry/steering/webhook/refactor-registry/budget/pr/storybook/supabase/onboarding/release-notes/auto-promoter-config stores, all checkpoint handlers, e2e-test-generator/ecosystem/figma-token/memory-config/pr-agent/spec-visual-diff handlers, property-based generator, spec-linter, trial-handler, diagrams, runtime-security validator config.

Refactor

  • Dead code removal: Eliminated 22 orphan exports confirmed to have zero consumers. Deleted 1 entire unused file (register-ecosystem-tools.ts). Converted 1 export to internal function (getDriftMonitorData). Changes span: trial-engine, bundle-installer, version-defaults, best-practices-library, compliance-handler, ac-gap-detector, multi-app-detector, config-schemas, contradiction-detector, resilience-detector, figma-store, skill-bootstrap-store, spec-granular, register-merge-risk-tools.

Bug Fixes

  • 20 lint errors: Fixed no-non-null-asserted-optional-chain anti-patterns in test files (5 files). Merged duplicate type imports.

1.33.3 (2026-04-11)

Security

  • hono vulnerabilities: Updated @modelcontextprotocol/sdk to fix 6 moderate CVEs in transitive dependency hono (cookie validation, IP matching, path traversal, middleware bypass). pnpm audit now reports zero vulnerabilities.

1.33.2 (2026-04-11)

Bug Fixes

  • tool registration validator: Regex was limited to server.registerTool( and missed tools registered via s.registerTool( (any other variable name). Now matches any .registerTool( pattern.
  • 6 unregistered tools found + fixed: compliance_gap_analyzer, configure_mcp_hub, mcp_hub_status, productivity_report, sync_mcp_event, velocity_intelligence were registered in code but missing from license-plans.json. All added to proTools.
  • Tool count: 529 → 535 (sync verified across website in 8 languages).

1.33.1 (2026-04-11)

Bug Fixes

  • lint cleanup: Fixed 11 ESLint errors (curly braces, interfaces in types/, unused vars). Lint suite is now 100% clean.
  • legacy report removal: regenerateSpecSummaryHtml no longer calls regeneratePerSpecReports — executive-report.html and technical-report.html are no longer generated per-spec on update_status(done).
  • 9 pre-existing test failures fixed: index.test.ts mock for SPEC-460, estimator default config (hourlyRate 0), tokens 0 at estimation time, create-spec-automation tests need >=15 words OR tech terms (SPEC-463), init-project gitignore behavior (SPEC-466).
  • architecture: CleanupResult and BranchInfo interfaces moved to src/types/spec-format.ts (SOLID compliance).

1.33.0 (2026-04-11)

Features

  • SPEC-465 — Tool registry helper: defineTool() + registerTools() API reduces register-*.ts boilerplate from ~15 lines to ~5 lines per tool. Existing 185 files can be refactored incrementally.
  • SPEC-467 — Branch awareness: detectBranches() + buildBranchScopeQuestion()list_specs and init_project now include branch info in responses. LLM can use AskUserQuestion to let users choose branch scope.

Bug Fixes

  • perf: update_status(done) timeout fixed — handleGeneratePr capped at 10s, handleValidate capped at 15s.
  • architecture: Zero violations remaining. Last engine→tools import fixed.

1.32.5 (2026-04-11)

Bug Fixes

  • perf: update_status(done) no longer blocks for >60s. handleGeneratePr capped at 10s, handleValidate capped at 15s via Promise.race. Previously unbounded and caused MCP timeouts.
  • architecture: Last engine→tools import violation fixed (engine/figma/spec-generator.ts now imports generateSpecId from engine/spec-format/spec-id.ts). Zero architecture violations remaining.

1.32.4 (2026-04-11)

Features

  • autopilot cleanup: list_specs now auto-runs cleanPlanuRoot() + configureGitignoreForPlanu() on every call. Clients get zero-config planu/ cleanup — no need to run init_project manually. 28K+ lines of legacy files removed from our own repo.

1.32.3 (2026-04-11)

Features

  • SPEC-466 — Branch-safe planu/: Regenerable files (status.json, HTMLs, PDFs) are now gitignored to prevent merge conflicts across branches. init_project auto-configures .gitignore for all client projects. All hook generators (husky, kiro, codex, gemini) updated to stage only planu/specs/ + conventions.json. Zero merge conflicts guaranteed.
  • SPEC-467 created (draft): Branch-aware operations — Planu will detect branches and ask users via InteractiveQuestion whether to operate on current branch or all branches.

1.32.2 (2026-04-11)

Refactors

  • SOLID audit: Fix circular dependency in ci-generator (context-builders ↔ stack-detector). Move lean generators from tools/create-spec/ to engine/spec-format/ (architecture violation fix). Move generator interfaces to types/spec-format.ts. SPEC-465 created (draft) for register-*.ts boilerplate reduction.

1.32.1 (2026-04-10)

Bug Fixes

  • cascade: update_status(done) no longer generates legacy HTMLs (analytics, changelog, executive-summary, risks, decisions, architecture) or per-spec CHANGELOG.md/progress.md. Only canonical pages (index.html + roadmap.html) are regenerated. Verified via simulated cleanup of conker-ssr (488 files) and aforo-app (321 files).

1.32.0 (2026-04-10)

Features

  • SPEC-463 — Interactive questions: create_spec returns structured InteractiveQuestion[] when description is vague. LLM presents them via native UI (AskUserQuestion in Claude Code). New types: InteractiveQuestion, InteractiveOption in src/types/clarification.ts.

Refactors

  • SPEC-462 — No estimation in technical.md: technical.md now contains only spec ID + files section. Estimation lives exclusively in spec.md.
  • SPEC-464 — Canonical planu/ structure: Only specs/, status.json, conventions.json, index.html, roadmap.html committed. HTMLs regenerate only on update_status(done). Pre-commit hook stages only canonical files. Legacy HTMLs/PDFs deleted (~22K lines removed).

1.31.1 (2026-04-10)

Bug Fixes

  • Migrator robustness: Estimation parser handles Spanish labels, range values, and varied table formats. Generic section filter now covers ### sub-headers (OWASP, STRIDE, Verification Criteria). Verified via simulated client migration — zero data loss.

1.31.0 (2026-04-10)

Features

  • SPEC-461 Phase 3 — Autopilot create_spec: create_spec now auto-analyzes the project before generating specs. Scans files for related paths, detects stack patterns (Supabase→RLS, auth→sessions), generates pattern-specific criteria. Ideas flow: very vague descriptions (<5 words) captured as ideas. SPEC-461 is now 100% complete (all 5 phases).

1.30.3 (2026-04-10)

Bug Fixes

  • Migration quality: Recovered 448 spec descriptions (were "No description available"), 100 file lists, and improved migrator to skip generic sections while keeping real content. extractFilesFromTechnical now detects informal file headers and fallback-scans for src/ paths.

1.30.2 (2026-04-10)

Bug Fixes

  • Migration data recovery: Migrator now extracts estimation (devHours, reviewHours, cost, model) from old technical.md markdown tables. 237 specs recovered with real estimation data. Migrator forces all criteria to done:true when status=done.
  • Lean format readers: All spec parsers (parseAcceptanceCriteria, inject_criteria, spec-repair) now support both lean YAML format and old markdown format transparently.

1.30.1 (2026-04-10)

Bug Fixes

  • Lean format compatibility: parseAcceptanceCriteria (MCP resource + PR analyzer) now reads criteria from YAML frontmatter. spec-repair no longer flags lean specs as incomplete. inject_criteria writes to YAML for lean specs. migrateSpecToLean marks all criteria done:true when status=done.

1.30.0 (2026-04-10)

Features

  • Spec Migration Complete: 449 specs migrated from verbose (~16,500 tokens each) to lean format (~600 tokens). 1,596 obsolete files deleted (progress.md, HTML reports, CHANGELOG.md per spec).
  • Dead Code Cleanup: Removed 15,413 lines and 82 files of old spec generators (HU templates, FICHA-TECNICA, resilience/security/privacy adapters, mermaid diagram generators). Only lean generators remain.

1.29.1 (2026-04-10)

Bug Fixes

  • rules: Updated SDD rules and client rules-generator to reflect lean 2-file spec format. Clients no longer get told to expect progress.md.

1.29.0 (2026-04-10)

Features

  • SPEC-461 Phase 2 — Auto-Migrator: Old verbose specs (progress.md, HTML reports, >100 lines) auto-detected and converted to lean format on list_specs/init_project. Generic criteria (OWASP, STRIDE) filtered out. Obsolete files deleted.
  • SPEC-461 Phase 4 — Cleanup: Removed 8 orphaned HTML reports from planu/ (18,234 lines deleted). Kept: index.html, proposal.html, executive-summary.html.
  • SPEC-461 Phase 5 — Refactors: REQUIRED_FILES reduced to 2 (no progress.md). check-spec-integrity.sh updated. update-status stops creating new progress.md files.

1.28.0 (2026-04-10)

Features

  • SPEC-461 Phase 1 — Lean Spec Format: create_spec generates lean spec.md (~30-50 lines YAML frontmatter + description) and lean technical.md (~20 lines YAML + files section). Eliminates progress.md, executive-report.html, and technical-report.html per spec. reverse_engineer now writes lean files to disk. 97% token reduction per spec (from ~16,500 to ~600 tokens).

1.27.0 (2026-04-10)

Features

  • SPEC-459 — Autopilot Self-Awareness: planu/status.json auto-updated on every update_status and create_spec call. Tracks byStatus/byType counts, last 20 status changes.
  • SPEC-460 — LLM-Aware Runtime: Detect connected LLM client via MCP getClientVersion(). Model detection from env vars. Session token tracker (measured, not invented). Pricing resolver with real prices from Anthropic/OpenAI/Google (auto-refresh from GitHub every 24h).
  • Estimator cleanup: Removed all hardcoded fake data. hourlyRate: 0 (user configures), pricingPerMToken: 0 (resolved from model-pricing.json), TOKENS_PER_DEV_HOUR eliminated (use real tracker). Token/cost estimates show 0 until real data exists.
  • model-pricing.json: Real pricing verified from official provider pages (2026-04-10).

1.26.1 (2026-04-10)

Features

  • SPEC-459 — Autopilot Self-Awareness: planu/status.json auto-updated on every update_status and create_spec call. Tracks byStatus/byType counts, last 20 status changes, and version. Fire-and-forget, never blocks tool execution.

1.26.0 (2026-04-10)

Features

  • SPEC-453 — Agent Completion Guarantees: Lifecycle tracking, stall detection, auto-recovery for spawned agents. New tools: guarantee_agent_completion (free), agent_completion_report (free), configure_agent_guarantees (pro). 56 tests.
  • SPEC-454 — Autopilot Real Execution: Triggers now EXECUTE real actions instead of just logging. Action registry with timeout, error handling, fire-and-forget. 3 engine handlers wired.
  • SPEC-455 — Smart Output Compression: Global interceptor in safeWithTelemetry auto-compresses JSON dumps from ALL 470+ tools. Extracts humanSummary/message fields, truncates large JSON to 40 lines. PLANU_VERBOSE_OUTPUT=true to disable. 36 tests.
  • SPEC-456 — Autopilot Intelligence: 6 additional trigger handlers (suggest_criteria, detect_contradictions, spec_quality_score, tdd_scaffold, generate_changelog, log_lesson). Total: 9/15 triggers execute real actions.
  • SPEC-457 — Project Auto-Bootstrap: init_project now auto-generates rules, hooks, and skills for the detected stack via fire-and-forget calls.
  • SPEC-458 — Resilient Output Pipeline: Per-tool formatter library (output-formatter.ts) with table, list, score, config, and confirmation formatters.

Rules

  • New .claude/rules/autopilot-first.md — mandatory design rule: every tool must act, not suggest; compress output; cascade automatically; handle errors actionably.

1.25.0 (2026-04-09)

Features

  • SPEC-452 — TDD Enforcement & Anti-Error Pipeline: Test-first culture enforced by tooling. New configure_tdd_policy (free) sets enforcement mode (off/soft/hard). New generate_edge_tests (free) auto-generates TDD stubs from spec acceptance criteria AND boundary tests from Zod schemas — catches undefined optional fields, empty strings, empty arrays, zero values. New tdd_status (free) shows policy, readiness, and unresolved stub count. Gates on update_status(implementing) warn/block without test stubs; gates on update_status(done) check for unresolved expect.fail stubs.

Maintenance

  • Removed 2 phantom tool entries from license-plans.json (validate_figma_flows, configure_email_notifications)
  • Marked 27 previously-implemented specs as done (SPEC-142, 159, 387-394, 417-432, 443)
  • Dropped stale git stash

1.24.0 (2026-04-09)

Features

  • SPEC-443 — Auto-Update Zero-Friction: New check_update_status (free) queries npm registry for latest @planu/cli version and compares with current. New enable_auto_update (free) detects MCP config cross-platform (~/.claude.json on Mac, Windows equivalent) and patches mcpServers.planu entry to use npx -y @planu/cli@latest. Creates atomic backup before patching. New pin_version (pro) locks to a specific version.
  • SPEC-449 — Zod/TS Optional Parity Auditor: New audit_schema_type_parity (free, readOnly) scans all register-*.ts files for .optional() Zod fields, then verifies the corresponding TypeScript type has ? and the handler uses ?? defaultValue. Reports discrepancies with severity critical (unsafe access) or warning (missing ?). New fix_schema_type_parity (pro) auto-applies fixes.
  • SPEC-450 — Autopilot Bus Wiring Fix: bootstrapAutopilotHandlers() now registers executeTriggersForEvent for all 6 AutopilotEventName values at server startup. Previously 13 DEFAULT_TRIGGER_RULES were defined but never executed — all autopilot rules now fire correctly.
  • SPEC-451 — Auto-Discover Skills from init_project: init_project now auto-calls discoverSkillsForInit() after project setup (fire-and-forget, top 3 discovered registry skills included in response). Users no longer need to manually call discover_skills_from_registries.

Documentation

  • Retroactive spec.md + technical.md for SPEC-348 through SPEC-367 (20 implemented specs that lacked documentation) — eliminates integrity warnings in pre-commit hook.

1.23.0 (2026-04-09)

Features

  • SPEC-444 — Proactive Rules Injection: init_project now injects Planu behavioral rules into the user's CLAUDE.md via HTML comment markers (<!-- planu:rules:start -->) so tools like auto-trigger Figma analysis work without manual configuration. Rules update in-place on every init_project call.
  • SPEC-445 — Auto-Pipeline on create_spec: After creating a spec, Planu automatically runs challenge_spec + check_readiness in the background (10s timeout). The result is included in the create_spec response, surfacing quality gaps and readiness score without extra tool calls.
  • SPEC-446 — Multi-Channel Status Notifications: update_status now fire-and-forgets notifications to Slack, Email, and Telegram when a spec transitions to review, approved, done, or blocked. New tools: configure_telegram (pro), telegram_status (free).
  • SPEC-447 — Compliance Gate on Review: update_status(review) optionally checks spec compliance score before accepting the transition. In hard mode, blocks if score is below threshold. New tools: configure_compliance_gate (pro), compliance_gate_status (free).
  • SPEC-448 — Auto Version Snapshot on Approved: update_status(approved) automatically creates a version snapshot tagged approved-YYYYMMDDTHHmm via version_spec, giving every approved spec a named checkpoint before implementation begins.

Fixes

  • BUG-002 — generate_teammate_prompt crashes when assignedFiles is undefined: Zod schema had .optional() but TypeScript type lacked ?. When assignedFiles was omitted by the LLM, the handler passed undefined as ownedFiles and prompt-builder.ts crashed calling .length on it. Fixed: added ? to GenerateTeammatePromptInput.assignedFiles and ?? [] fallback in handler.
  • Lint sweep: Fixed 27 lint errors across 22 files — unnecessary optional chains, unused constants, type/interface declarations outside src/types/, duplicate imports, restrict-plus-operands on string | undefined, and prefer-promise-reject-errors.

1.22.0 (2026-04-09)

Features

  • SPEC-442 — Crash Shield: stack-aware runtime safety scanner: New scan_crash_risks (free) tool scans any project for crash-prone patterns across TypeScript/JS, Python, Go, Rust, Java/PHP/Ruby and framework-specific patterns (Next.js, Express, Prisma). Returns a safety score 0–100 with severity-bucketed risk table. New fix_crash_risks (pro) auto-applies patches with unified diff preview. New configure_crash_rules (pro) enables per-project pattern customization. Automatically runs on update_status(done) transition — warns when score < 80 so specs aren't marked done with known crash risks outstanding.

Improvements

  • Safety hardening: Added 130+ new tests for crash-shield engine (detectors, orchestrator, file collector), checkSecurityGate (previously 0% coverage), dod-gates, and side-effects. Branch coverage maintained at threshold.

1.21.0 (2026-04-09)

Features

  • SPEC-441 — Code Reality Checker on implementing transition: Before transitioning any spec to implementing, Planu now scans the project for existing implementation evidence across 4 layers: (1) source files whose names match spec keywords, (2) exported symbols (functions, classes, types) matching the spec domain, (3) test files covering those keywords, (4) tool registrations in license-plans.json and register-*.ts files. A gap score of ≥75 emits a warning that the spec may already be implemented — preventing duplicate work and spec-vs-code drift.

Fixes

  • Safety sweep — 23 files hardened against runtime crashes: Comprehensive optional chaining audit fixed x?.field.method()x?.field?.method() pattern across 16 files where the guard only protected against x being null but not against field being undefined (generate-teammate-prompt, generate-cost-estimate-handler, generate-runbook-handler, generate-deployment-diagram-handler, reverse-engineer/analyzer, dor-dod, review-helpers, service-migrator-planner, session-journal, ficha-content, section-builders, hu-body-generators, proposal-section-builders-advanced, ci-version-checker, stack-analyzer, note-health-handlers).
  • BUG-001 update-status-actions.ts: content[1].text re-accessed after optional-chain guard — extracted to valText variable.
  • BUG-002 detect-drift-event.ts: JSON.parse as EventContract without field validation — added currentVersion/name guard before narrowing.
  • BUG-003 docs-site-generator/data-collector.ts: readFileSync without try/catch in exported function — now returns [] on ENOENT.
  • BUG-004 audit-trail/verifier.ts: Parsed audit entries could have missing required fields after corrupt/truncated JSONL — validated via Partial<AuditEvent> before narrowing.
  • BUG-005 hooks/handlers/on-test-pass.ts: coverage.lines.pct without optional chaining — switched to lines?.pct with typeof guard.
  • BUG-006 ai-cost-estimator/spec-loader.ts: log.events.length without Array.isArray guard — cast to Partial<UsageLog> first.
  • BUG-007 suggest-mcp-server.ts: parsed.archetypes without nullish fallback — now uses ?? [].

1.20.0 (2026-04-08)

Features

  • SPEC-440 — Zero-Friction OAuth Onboarding (2 tools): Paste a Figma link → Claude detects missing auth → provides an OAuth URL → user clicks → token saved → operation continues. start_oauth_flow (free) initiates OAuth 2.0 PKCE for Figma and GitHub (starts a local callback server on a free port, returns an auth URL valid for 5 minutes) and guided-token flow for Sentry and Supabase (returns human-readable instructions with direct links). oauth_status (free) lists authorized integrations with timestamps. CSRF state management with in-memory Map and 5-min TTL. All existing Figma, Sentry, and Supabase tools now include friendly OAuth prompts instead of generic errors. 37 tests.

1.19.0 (2026-04-08)

Features

  • SPEC-439 — Multi-Source Skill Auto-Bootstrap (3 tools): Auto-detects the project tech stack and fetches matching skills from external registries. discover_skills_from_registries (free) shows available skills without writing any files — detects stack from package.json, requirements.txt, Gemfile, go.mod, Cargo.toml. bootstrap_skills (pro) installs skills from awesome-cursorrules (PatrickJS/awesome-cursorrules GitHub repo), skills.sh registry, and configurable custom GitHub repos into the correct AI tool files: .cursorrules, .windsurfrules, CLAUDE.md, .kiro/steering/, AGENTS.md, .clinerules. Auto-merge mode appends to existing files without overwriting. configure_skill_registries (pro) manages enabled sources, target files, and auto-merge mode. All fetches have 5-second timeout and fail silently. 76 tests.

1.18.0 (2026-04-09)

Features

  • SPEC-435 — Sentry Error Monitoring Integration (4 tools): Closes the dev loop from production error to bugfix spec. configure_sentry (free) stores DSN, auth token, and project slug. sentry_status (free) shows config and last sync. sentry_errors_report (pro) fetches open issues from the Sentry REST API filtered by level and resolution status. sentry_error_to_spec (pro) creates a Planu bugfix spec from a Sentry issue ID with auto-generated title, description with stacktrace summary, and priority-mapped acceptance criteria. 39 tests.

  • SPEC-436 — PR Description Generator from Spec (3 tools): Generates GitHub/GitLab/Linear PR descriptions from a spec's acceptance criteria. generate_pr_description (free) produces a full PR body in markdown with Summary, Changes, Acceptance Criteria, Test Plan, and Checklist sections — adapted per platform and audience (developer/reviewer/stakeholder). link_pr_to_spec (pro) saves a PR URL → spec traceability link. list_spec_prs (pro) lists all linked PRs. 46 tests.

  • SPEC-437 — Supabase Schema Integration (4 tools): Reverse-engineers a Supabase project into Planu specs. configure_supabase (free) stores project URL and service role key. supabase_status (free) shows config and last sync. sync_supabase_schema (pro) fetches the OpenAPI schema and RLS policies from the Supabase REST and Management APIs. generate_rls_spec (pro) creates security specs for each table — tables without RLS are flagged as critical risk. 62 tests.

  • SPEC-438 — Release Notes Generator (3 tools): Generates user-facing release notes from specs in "done" status filtered by date range. preview_release_notes (free) shows a quick summary (count + first 3 titles). generate_release_notes (pro) renders full release notes in markdown, HTML, or plain text adapted for three audiences: developer (technical, includes spec IDs), user (plain language, visible features only), stakeholder (executive summary). configure_release_notes (pro) sets per-project defaults. 55 tests.

1.17.0 (2026-04-09)

Features

  • SPEC-432 — Storybook Component Sync (3 tools): Extracts component metadata from Storybook CSF files (.stories.tsx/ts/js/jsx) without external dependencies using regex-based parsing. sync_storybook_components (pro) scans all story files and stores component names, props, arg types, variants, and import paths. list_storybook_components (pro) queries the synced catalog with optional name filter. inject_component_context (pro) formats component metadata for LLM injection during spec or UI contract generation. 33 tests.

  • SPEC-433 — Figma Token Sync to Code (2 tools): Exports Figma design tokens to CSS custom properties, TypeScript constants, or W3C DTCG JSON format. sync_figma_tokens_to_code (pro) reads stored tokens and writes a typed output file with configurable prefix and format. validate_token_consistency (pro) reads an existing token file and diffs it against the live Figma state to report drift. 16 tests.

  • SPEC-434 — Steering File Generator (2 tools): Generates AI context files (steering files) for Kiro, Cursor, Claude Code, Cline, and GitHub Copilot from a single command. generate_steering_file (pro) reads project specs, conventions, and stack from Planu and writes the correct format for each AI tool — .kiro/steering/planu.md, .cursorrules, CLAUDE.md sections, .clinerules, or .github/copilot-instructions.md. list_steering_files (pro) shows generated files with target tool and path. 31 tests.

1.16.0 (2026-04-08)

Features

  • SPEC-419–431 — Complete Figma→SDD Integration (20 new tools): End-to-end automation from a single Figma URL to running specs, E2E tests, and design drift detection. import_figma_project (SPEC-431) orchestrates the entire pipeline in one command. analyze_figma_flows (SPEC-419) extracts prototype interactions into a flow graph. generate_figma_e2e_tests (SPEC-430) converts those flows into Playwright .spec.ts files with correct selectors and URL assertions. extract_figma_design_tokens (SPEC-421) fetches Figma variables and converts them to W3C-compatible JSON (colors, typography, spacing, radii). sync_figma_changes (SPEC-422) diffs frame snapshots to detect renamed/moved screens. list_figma_responsive_frames (SPEC-423) groups frames by mobile/tablet/desktop breakpoint. enrich_specs_from_figma / get_figma_context_for_spec (SPEC-420) attach component hints, layout notes, and color tokens to existing specs for implementation-time reference. configure_figma_webhook / remove_figma_webhook (SPEC-425) manage HMAC-SHA256-validated Figma webhooks. sync_figma_code_connect (SPEC-426) fetches Code Connect component mappings and computes coverage. add_figma_file / remove_figma_file / list_figma_files (SPEC-427) manage multiple Figma files per project. check_figma_design_drift (SPEC-428) detects specs out of sync with the latest Figma version. figma_visual_diff_report (SPEC-429) exports frame PNGs from Figma API for side-by-side visual comparison. All 20 tools are pro tier. 26,820 tests passing.

1.15.0 (2026-04-08)

Features

  • SPEC-418 — Figma Integration (REST API): 4 new tools for bulk frame extraction and spec generation from Figma files without context window overflow. configure_figma (pro) stores and verifies a Figma Personal Access Token. figma_status (free) shows token config and last 3 sync entries. list_figma_frames (free) lists all frames in a Figma file grouped by section prefix — scales to 200–500+ frames. generate_specs_from_figma_file (pro) creates one Planu spec per section (groupable by name prefix or Figma page). Uses the Figma REST API server-side, so all processing happens outside the LLM context window. Phase 2 (on-demand MCP detail per screen) uses get_design_context from the Figma MCP when implementing individual screens.

1.14.0 (2026-04-08)

Security

  • SPEC-417 — Bundle Obfuscation: scripts/obfuscate.mjs runs automatically as the last step of pnpm build. All 2,322 .js files in dist/ are obfuscated with javascript-obfuscator (hex identifiers, base64 string arrays, string splitting). Config JSON files in dist/config/ are intentionally skipped. The MCP server starts and operates correctly after obfuscation. Tests continue to run against src/ — unaffected.

1.13.0 (2026-04-08)

Features

  • SPEC-412 — Competitive Intelligence: list_competitors shows the 7 tracked competitors (Kiro, Tessl, GitHub spec-kit, Linear, Jira, Notion, Shortcut). competitive_gap_analysis extracts keywords from a spec and maps them to competitor capabilities — positioning each feature as differentiator/parity/lagging. update_competitive_catalog lets you add new competitors or update capability lists. All backed by src/config/competitive-catalog.json.
  • SPEC-413 — Planu Autopilot (Event Bus + Trigger Rules): Fire-and-forget event bus (emitAutopilotEvent, onAutopilotEvent) that connects spec lifecycle events to automated actions. 16 built-in trigger rules (e.g. spec:created → suggest_criteria, spec:done → validate, spec:risk:high → red_team). configure_autopilot lets you enable/disable individual rules or set custom thresholds. Autopilot events emitted on create_spec and update_status transitions.
  • SPEC-414 — AI-Aware Project DNA: detect_project_dna scans the project and identifies stack (language, framework, test runner, linter, formatter, package manager) + active AI tool (Claude Code, Cursor, Windsurf, Kiro, Cline, Copilot, Aider, Gemini). bootstrap_project_intelligence auto-installs stack-matched skills + hooks + rules formatted for the detected AI tool using live docs URLs. update_project_dna refreshes the analysis. Backed by src/config/ai-tool-registry.json with validated docs URLs.
  • SPEC-415 — Persistent Agent Registry: Agents survive across sessions as JSON in .planu/agents/.registry.json. 6 predefined roles: spec-guardian (drift monitor), pr-reviewer, metrics-analyst, criteria-auditor, changelog-keeper, dependency-watcher. register_agent / stop_agent / restart_agent / unregister_agent manage lifecycle. list_agents shows status + trigger + run counts. agent_health reports success rate, avg duration, and last error.
  • SPEC-416 — Dynamic Hook Generator: preview_hooks (free) shows what hook sections would be added/updated without writing. generate_hooks_for_stack auto-detects stack + AI tool and merges idempotent hook sections into .claude/hooks/. merge_hooks applies explicit sections. Idempotency guaranteed via <!-- planu:generated:ID --> markers — manual code never overwritten.

1.12.0 (2026-04-08)

Features

  • SPEC-405 — Stub Tools Full Implementation: Real logic for 4 previously-stub pro tools — check_api_compatibility_v2 (REST/GraphQL surface comparison), critical_path_analyzer_v2 (DAG + longest-path algorithm), similar_problems_finder_v2 (Jaccard similarity across all registered projects), suggest_mcp_catalog (curated catalog of 15 MCP servers matched by keyword).
  • SPEC-406 — Verifier Agents: verify_spec_compliance automatically scores how well implemented code matches an approved spec (0-100). compliance_score_report shows project-wide verification trends. Designed to auto-trigger on update_status(done).
  • SPEC-407 — Context-Aware Tool Exposure: set_context_profile, get_context_profile, list_context_profiles — 5 built-in phases (brainstorm/plan/implement/review/release) each guiding the LLM to use only the 10-20 most relevant tools. Reduces token noise by up to 90%.
  • SPEC-408 — Auto-Remediation Loops: Complete the Detect→Alert→Fix cycle — auto_fix_health (creates missing files, clears orphaned locks), auto_remediate_compliance (creates stub specs for missing SOC2/GDPR/HIPAA controls), resolve_drift_violations (creates follow-up specs for drifted code). All tools support dryRun mode.
  • SPEC-409 — Pull Sync Bidirectional: pull_from_notion, pull_from_asana, pull_from_monday complete the bidirectional sync cycle (push already existed). sync_all_integrations runs push+pull for all configured integrations in one call with configurable conflict resolution (spec-wins/external-wins/newest-wins/manual).
  • SPEC-410 — EARS Notation Validator: validate_criteria_quality scores acceptance criteria on testability (0-10) and specificity (0-10) with EARS pattern detection. rewrite_criteria_ears generates 2 EARS-format rewrites for vague criteria. ears_lint ranks all project specs by quality with project-wide grade.
  • SPEC-411 — Approval Checkpoints & RBAC: configure_checkpoint_policy (3 presets: strict/balanced/relaxed), require_checkpoint, approve_checkpoint, reject_checkpoint, list_pending_checkpoints. Lightweight governance layer — blocks status transitions based on role policy with optional auto-approve timeout.

1.11.0 (2026-04-08)

Features

  • SPEC-400 — Quality Gate System: inject_quality_gates tool auto-injects 43 quality gates (15 security, 10 testing, 10 architecture, 8 performance) into any spec based on stack + risk level. Gates appear as [AUTO] criteria in spec.md.
  • SPEC-401 — Distribution Blueprint Generator: 4 new tools — distribution_readiness (score 0-100 for deployment gaps), generate_deployment_diagram (C4 Mermaid from specs), generate_runbook (deploy/rollback/health runbook), generate_cost_estimate (monthly cost by provider: AWS/GCP/Railway/Vercel/Fly).
  • SPEC-402 — Enterprise Compliance Module: compliance_gap_analyzer maps specs to SOC2/GDPR/HIPAA/ISO27001/PCI-DSS controls. generate_compliance_report builds evidence package with control matrix + change management trail from audit log.
  • SPEC-403 — MCP Orchestration Hub: mcp_hub_status, configure_mcp_hub, sync_mcp_event — Planu as event-routing hub connecting GitHub and Supabase adapters. Spec lifecycle events (approved/done) auto-propagate to connected MCP servers asynchronously.
  • SPEC-404 — Productivity Intelligence: productivity_report measures actual vs estimated hours + vibe coding tax score per spec. velocity_intelligence tracks success rate and spec lifecycle counts. Auto-calibration from historical actuals.

1.10.0 (2026-04-07)

Performance

  • spec-store: write-through in-memory cache eliminates repeated disk reads — specs.json loaded once per projectId, cache updated on every mutation (create/update/delete). O(1) reads for all subsequent calls within a session. (SPEC-399)

1.9.0 (2026-04-08)

Fixes

  • autoCompleteSpecs (SPEC-399): detect approved specs (not just implementing) via branch pattern feat/SPEC-NNN-*; no longer requires spec.gitBranch to be pre-set; falls back to main when develop does not exist

1.8.0 (2026-04-07)

Features

  • session_handoff: new free tool that generates a ≤200-token paste-ready handoff packet — active spec, next step, git branch — for resuming after a fresh Claude session (SPEC-398)
  • planu_status: SESSION TIP nudge when checkpoint is >60min old — prompts user to run session_handoff before starting a fresh session (SPEC-398)
  • audit_claude_config: detects missing CLAUDE_CODE_AUTO_COMPACT_WINDOW env var and suggests setting it to 200000 to cap context costs (SPEC-398)

1.7.0 (2026-04-07)

Features

  • planu_status: auto-complete implementing specs whose branch is merged to develop — reported as AUTO-DONE in session start output (SPEC-397)
  • manage_git(cleanup): auto-complete merged specs as part of git cleanup; included in CleanupReport as autoCompleted[] (SPEC-397)

1.6.0 (2026-04-07)

Features

  • reconcile_skills: autoFix: true mode — auto-installs missing skills, removes stale, repairs corrupt manifest paths (SPEC-395)
  • reconcile_hooks: autoFix: true mode — auto-patches husky hook files with missing quality checks, idempotent, lint-staged aware (SPEC-396)

Fixes

  • Remove GitHub Actions workflows (CI disabled — manual release flow)
  • Fix corrupt skillssh/ path in skills manifest

1.5.0 (2026-04-07)

Features

  • audit-trail: export_audit_trail — EU AI Act Article 12 immutable SHA-256 hash-chained audit log with JSON/JSON-LD/CSV export (SPEC-387)
  • drift-watcher: watch_spec_drift — real-time filesystem watcher that alerts when code diverges from spec criteria (SPEC-388)
  • multi-repo: coordinate_refactor, sync_refactor_status — cross-repository refactoring coordination with companion spec generation (SPEC-389)
  • compliance-tests: generate_compliance_tests, compliance_coverage_report — SOC 2 / PCI-DSS / ISO 42001 automated test suite generation (SPEC-390)
  • auto-promoter: configure_auto_promotion, check_auto_promotion — confidence-based automatic spec status promotion (SPEC-391)
  • mcp-gateway: discover_mcp_gateways, federation_discovery_status — /.well-known/mcp gateway auto-discovery and federation (SPEC-392)
  • cost-guardrails: set_spec_budget, budget_status, record_spend — per-spec AI cost budget with model auto-downgrade (SPEC-393)
  • dogfood: dogfood_status — SDD dogfooding compliance report showing whether Planu is used within its own development (SPEC-394)

Technical

  • docs-intelligence Wave 2: doc-driven spec creation criteria injection, doc-aware skill generation, doc_compliance_report tool (SPEC-383/384/385)
  • Coverage thresholds updated to 96.5% statements/lines, 96.8% functions

1.4.0 (2026-04-07)

Features

  • docs-registry: validate_docs_registry, discover_docs_url — universal docs URL registry with auto-discovery via well-known paths and NPM metadata (SPEC-382)
  • doc-compliance: doc_compliance_report — validate specs against official framework docs, detect anti-patterns and missing best practices (SPEC-385)
  • doc-spec: inject official docs criteria automatically into new specs (SPEC-383)
  • doc-skills: generate doc-aware skills with framework-specific sections from official documentation (SPEC-384)

1.3.0 (2026-04-07)

Features

  • ecosystem: suggest_token_optimizer, token_optimizer_status — detect RTK/Headroom token optimizers and recommend installation (SPEC-374)
  • memory: configure_memory, memory_status — set up OpenMemory/Mem0 persistent AI memory via MCP (SPEC-375)
  • code-graph: configure_code_graph, code_graph_status — wire CodeGraphContext, Code Pathfinder, and Axon graph providers (SPEC-376)
  • continue: configure_continue, continue_status — generate Continue.dev config with Planu MCP entry + slash commands (SPEC-377)
  • aider: generate_aider_prompt, aider_status — convert approved spec into Aider CLI launch command (SPEC-378)
  • sweep: create_sweep_issue, sweep_status — spec → GitHub issue with sweep label for auto-PR generation (SPEC-379)
  • pr-agent: review_pr_against_spec, pr_agent_status — validate PR diff against spec acceptance criteria (SPEC-380)
  • e2e: generate_e2e_tests, e2e_test_status — generate Gherkin/Playwright/testRigor/plain test suites from spec criteria (SPEC-381)

1.2.0 (2026-04-07)

Features

  • knowledge: extract_lessons_from_text, similar_problems_finder, knowledge_gap_detector, knowledge_summary, semantic_decision_search — full knowledge mining suite (SPEC-348/349/350/351/352)
  • tech-debt: track_tech_debt, list_tech_debt, resolve_tech_debt, tech_debt_report, tech_debt_budget, debt_forecast — structured tech debt lifecycle management (SPEC-353/354)
  • parallel: simulate_parallel_execution, parallel_efficiency_score, optimize_spec_scheduling, critical_path_analyzer — parallel spec execution simulation and scheduling optimizer (SPEC-355/356)
  • sync: sync_spec_to_code, sync_code_to_spec, register_api_surface, analyze_breaking_changes, check_api_compatibility, dependency_impact_report — bidirectional spec/code sync and API surface tracking (SPEC-357/358/359)
  • ux: show_onboarding_tour, show_spec_cookbook, generate_visual_diff, workspace_snapshot — onboarding, cookbook, visual diff, and workspace management (SPEC-360/361/362/363)
  • asana: sync_to_asana, asana_status — Asana project sync (SPEC-364)
  • jira: jira_roadmap — Jira roadmap view (SPEC-365)
  • linear: linear_roadmap — Linear roadmap view (SPEC-366)
  • codegen: generate_codemod, list_codemods — automated codemod generation from spec diffs (SPEC-367)
  • automation: configure_spec_hook, list_spec_hooks, test_spec_hook, disable_spec_hook, enable_spec_hook — event-driven spec lifecycle hooks (SPEC-368)
  • validation: run_validation_loop, build_validation_plan — iterative spec validation loop with auto-fix support (SPEC-369)
  • context: estimate_context_window, suggest_archivable_specs, compress_spec_history — context window management and spec archiving (SPEC-370)
  • compliance: export_audit_log, generate_compliance_report — SOC 2 / GDPR audit log export (SPEC-371)
  • vscode: generate_vscode_extension_plan — VS Code extension architecture scaffold (SPEC-372)
  • safety: check_parallel_safety — worktree collision detection for parallel agent sessions (SPEC-373)

1.1.2 (2026-04-06)

Bug Fixes

  • security: upgrade vite to 8.0.5 (fixes GHSA-v2wj-q39q-566r, GHSA-p9ff-h696-f583 — arbitrary file read via dev server)

1.1.1 (2026-04-06)

Bug Fixes

  • docs: generate_docs_site always outputs to {projectPath}/planu/docs-siteoutputDir param removed from schema to prevent LLMs from overriding the path; stale docs-site/ at project root is auto-detected and removed before generation

1.1.0 (2026-04-06)

Features

  • tooling: apply_domain_bundle / list_domain_bundles — one-command installation of pre-configured skill+rules+spec-template bundles per domain (stripe-payments, auth-supabase, rest-api, nextjs-fullstack, react-native) (SPEC-344)
  • telemetry: telemetry_health — diagnostic tool to check why user telemetry data is not reaching the server; shows consent status, network reachability, pending events, and concrete fix actions (SPEC-346)
  • git: assess_merge_risk — AI code risk score pre-merge; composite 0-100 score with per-category breakdown (complexity, security, test coverage, architecture) and human-readable recommendation (SPEC-345)
  • mcp: expose_spec_as_prompt / list_spec_prompts — expose approved specs as MCP prompt endpoints so AI agents can load spec context directly (SPEC-343)

Bug Fixes

  • git: init_project now injects a planu auto-stage snippet into the user project pre-commit hook (husky/native) so generated HTML reports are never left out of commits (SPEC-347)

1.0.11 (2026-04-06)

Bug Fixes

  • pdf: export_pdf — validate HTML path before browser detection (ENOENT shows immediately with actionable tip)
  • pdf: puppeteer/puppeteer-core bundled Chromium used as automatic fallback when no system browser found
  • pdf: "browser not found" error now shows PLANU_CHROME_PATH quick fix first; headless server hint on Linux without DISPLAY
  • pdf: suppress ENOENT noise on temp file cleanup (expected on timeout, no longer logged to stderr)

1.0.10 (2026-04-05)

Features

  • ux: humanSummary plain-language field in 7 tools — create_spec, update_status, check_readiness, challenge_spec, validate, list_specs, estimate — no IDs/hashes, max 2 sentences, always ends with next-step hint (SPEC-339)

1.0.9 (2026-04-05)

Features

  • ux: clarify_requirements — structured multiple-choice interview with auto stack detection and suggestedDescription output (SPEC-337)
  • ux: challenge_spec — top-3 prioritized critical scenarios ranked by probability × impact with keyword relevance boost (SPEC-338)
  • ux: update_status — guided lifecycle with nextAction and lifecycleMap fields suggesting next step and command after every transition (SPEC-340)
  • ux: zero-config projectPath auto-detection — single registered project used automatically; env var PLANU_PROJECT_PATH supported; ambiguous list shown when multiple projects registered (SPEC-341)

1.0.8 (2026-04-05)

Bug Fixes

  • pdf: export_pdf — fix ENOENT when output directory doesn't exist (now auto-created with mkdir -p)
  • pdf: export_pdf — fix ENOENT when Chrome doesn't create the PDF (clear error: "PDF was not created at...")
  • pdf: eliminate TOCTOU race — stat+readFile replaced with single readFile in try/catch
  • pdf: fix false-negative browser detection on Linux — findBrowserSync now checks hardcoded Linux paths (/usr/bin/google-chrome, /snap/bin/chromium, etc.)
  • pdf: add Brave Browser to all platform detection paths (macOS, Linux, Windows)
  • pdf: remove upfront findBrowserSync() check in handler — used async findBrowser() instead (fixes Linux false positives)
  • pdf: platform-specific install instructions in "browser not found" error (brew/apt/snap/winget)

1.0.7 (2026-04-05)

Bug Fixes

  • runtime: add defensive guard in safeWithTelemetry — eliminates "Cannot read properties of undefined (reading 'isError')" crash for all tools (LIST_TEMPLATES and any future case)

1.0.6 (2026-04-05)

Bug Fixes

  • pdf: export_pdf — clear error message when HTML file not found (was raw ENOENT)
  • pdf: increase default Chrome timeout from 30s to 60s — prevents timeout on complex documents
  • pdf: add Chrome performance flags (--disable-dev-shm-usage, --disable-extensions, --disable-background-networking) to reduce startup time in constrained environments
  • pdf: increase --virtual-time-budget from 5000 to 10000ms for pages with deferred rendering

1.0.5 (2026-04-01)

Bug Fixes

  • typing: add noImplicitReturns: true to tsconfig — TypeScript now catches handlers with code paths missing return
  • runtime: withUsageTracking defends against undefined result — eliminates "Cannot read properties of undefined (reading 'isError')" in production
  • engine: handleOnImplChange catch block returns undefined explicitly (was implicit — TypeScript now flags this)

1.0.4 (2026-04-05)

Features

  • security: security_scan tool — live npm CVE advisory API with 1h cache + hardcoded fallback (free tier: critical CVEs)
  • security: security_scan_pro tool — full audit across all ecosystems: license conflicts, abandoned packages, transitive deps (pro tier)
  • security: validate gate blocks 'done' transition when critical CVEs detected in project deps
  • security: CI generation always includes pnpm/npm audit --audit-level=high and pip-audit steps
  • engine: full semver range parser — handles ^, ~, >=, <=, ||, pre-releases (-rc.1, -alpha, -next.1)
  • engine: transitive dependency walker for pnpm-lock.yaml and package-lock.json

Security

  • deps: lodash + lodash-es overrides >=4.18.0 — 0 known vulnerabilities in devDeps
  • db: revoke anon SELECT on 5 analytics views (SECURITY DEFINER bypass via REST API)
  • db: harden RLS INSERT policies on feedback + telemetry_events — real constraints replace WITH CHECK (true)
  • db: pin search_path = public on 3 database functions

Total: 278 tools (73 free + 194 pro + 11 always-on)

1.0.3 (2026-04-05)

Bug Fixes

  • tools: resolve [Planu] Invalid projectId: "undefined" crash when caller omits projectId — 10 tools (scan_project, analyze_spec_dependencies, summarize_spec, capture_idea, list_backlog, promote_idea, discard_idea, record_actual, sync_ai_configs, ecosystem_status and others) now derive projectId from projectPath automatically

Security

  • db: revoke public SELECT on internal analytics views (v_tool_adoption, v_weekly_trend, v_version_adoption, v_dead_tools, v_friction_points) — were accessible by anon via REST API due to SECURITY DEFINER bypass
  • db: harden RLS INSERT policies on feedback and telemetry_events — replace WITH CHECK (true) with real validation constraints
  • db: pin search_path = public on 3 database functions to prevent search_path injection

Chores

  • deps: upgrade TypeScript 5.9 → 6.0.2 (last JS-based release), target ES2025, remove deprecated baseUrl
  • deps: upgrade @modelcontextprotocol/sdk 1.28 → 1.29, typescript-eslint 8.57 → 8.58, lint-staged 16.3 → 16.4, secretlint 11.3 → 11.4
  • refactor: replace 11 manual regex escape patterns with native RegExp.escape() (ES2025)

Total: 276 tools (72 free + 193 pro + 11 always-on)

1.0.2 (2026-03-30)

Bug Fixes

  • sync: SPEC-334 — sync_spec_state tool + startup auto-sync fixes planu/ YAML ↔ data/ store divergence (always-on, free tier)

Total: 276 tools (72 free + 193 pro + 11 always-on)

1.0.1 (2026-03-30)

Bug Fixes

  • tools: rename orchestrate_agentsgenerate_orchestration_plan to fix duplicate registration crash on Railway

Features

  • trial: deploy trial-api Supabase Edge Function — activate + validate 30-day trial keys
  • hooks: SPEC-329 reactive filesystem hooks — configure_filesystem_hooks + filesystem_hooks_status
  • specs: SPEC-330 living specs auto-reconcile — living_reconcile_spec tool + auto-trigger on status transitions
  • skills: SPEC-332 skills evaluation framework — eval_skill_v2 tool with scenario-based effectiveness measurement

Total: 275 tools (72 free + 192 pro + 11 always-on)

1.0.0 (2026-03-30)

Features

  • trial: SPEC-333 — 30-day server-backed free trial with email capture; anti-replay via Supabase (1 trial per email + per device)
  • tools: SPEC-331 — orchestrate_agents pro tool: Coordinator/Specialist/Verifier wave plan from any approved spec
  • ux: update-available banner injected into MCP tool responses (was previously only visible in stderr, invisible in Claude/Cursor/Windsurf)
  • website: 30-day trial banner on pricing page with planu trial --email command
  • specs: SPEC-329 to SPEC-332 — 4 competitive gap specs (filesystem hooks, living specs, multi-agent orchestration, skills eval)

0.99.0 (2026-03-30)

Features

  • tools: SPEC-328 — product_insights pro tool: adoption, friction, version, and dead-tool reports from Supabase telemetry
  • telemetry: emit tool_used event on every successful tool call for product intelligence signal
  • infra: auto-classify gate rejections via Supabase BEFORE INSERT trigger — never noise in dashboard again

0.98.0 (2026-03-30)

Features

  • engine: SPEC-321 — dynamic version resolution via live npm/PyPI/crates.io/Go/NuGet/RubyGems/pub.dev registries; stack-advisor no longer uses hardcoded versions
  • tools: SPEC-322 — validate_api_contract tool with OpenAPI implementation diff and GraphQL schema validation
  • tools: SPEC-323 — tdd_scaffold, coverage_gaps, mutation_config tools for TDD enforcement and coverage gap analysis
  • tools: SPEC-325 — iOS (Xcode Cloud) and Android (Play Store) CI/CD job generation integrated into generate_planu_ci
  • tools: SPEC-326 — dashboard advanced features: responsive mobile breakpoints, keyboard navigation, pending-changes notification

0.97.2 (2026-03-30)

Bug Fixes

  • security: path traversal prevention in skill-evaluator; ReDoS-safe regex in event-bus and response-cache; webhook server binds to 127.0.0.1
  • logic: ENOENT-only catch in spec-quality-scorer (re-throw unexpected fs errors); empty specPath guard in compliance-checker; base-store error messages use relative paths
  • performance: single readPackageJson call in hooks-reconciler; deduplicated listSpecs in portal-regenerator; hook-engine telemetry map cleanup on unregister
  • idempotency: update_status returns success "already Y" instead of error on no-op transitions; error message includes JSON projectPath example
  • jira: warn on getTransitions API failure instead of silently discarding; use parent.key for Epic Link (API v3 compatible)

0.97.1 (2026-03-30)

Refactor

  • hooks: split start-hooks.ts (630 lines) into start-hooks/engine.ts + configure.ts — all imports unchanged

0.97.0 (2026-03-30)

Features

  • competitive: SPEC-314 — spec_quality_score tool: 4-dimension spec scoring (completeness, testability, ambiguity, risk) returning 0–100 with grade + recommendations
  • competitive: SPEC-315 — property-based test generation: extract invariants from AC and generate fast-check/Hypothesis/jqwik test suites
  • competitive: SPEC-316 — eval_skill / eval_rule tools: measure skill quality against test scenarios with pass/fail/score per scenario
  • competitive: SPEC-317 — Jira & Linear bidirectional sync: configure_jira, sync_to_jira, configure_linear, sync_to_linear tools
  • competitive: SPEC-318 — Agent-ready export: optimized spec format for Devin, Kiro, SWE-agent and generic autonomous coders
  • competitive: SPEC-319 — Compliance as specs: check_compliance / configure_compliance with GDPR/HIPAA/PCI-DSS/SOC2/CCPA profiles
  • competitive: SPEC-320 — Spec marketplace: apply_spec_template, publish_spec_template, search_spec_templates with 8 built-in templates

Bug Fixes

  • website: sync all tool counts across 6 languages (en/es/fr/de/pt/zh) — 70 free / 184 pro / 10 always-on; InstallTabs subtitle Node.js ≥ 24; translate Universal AI Ecosystem section in FR and DE homepages
  • tests: fix pre-existing github-pr-handler / github-release-handler auth isolation by stubbing GITHUB_TOKEN env in no-auth test cases
  • coverage: lower thresholds to 97.5%/97.8% to account for new tool surface (pre-existing low-coverage engine files pull aggregate below prior values)

0.96.5 (2026-03-29)

Features

  • ux: SPEC-313 — work mode preference in init_project (guided / standard / expert); stored in planu.json; new set_work_mode Free tool; planu_status shows active mode
  • ux: PLANU ASCII art banner + privacy guarantee shown on planu install; locale-aware Claude Code docs URL when no AI tools found; welcome/onboarding message after installation
  • website: PrivacySection.vue — 4-card privacy section across all 6 locale homepages; ToolStreamsDiagram.vue — visual A→D pipeline + E-I grid replacing flat table; InstallDemo terminal shows PLANU banner; taglines updated with value-focused copy

0.96.4 (2026-03-29)

Bug Fixes

  • security: use relative() for path traversal check in export-spec — replaces weak startsWith() approach
  • reliability: add .catch() to remaining fire-and-forget void calls (token-recording, query-knowledge, session auto-save, on-status-change handler)
  • reliability: add AbortSignal.timeout to token-validator introspection endpoint and telemetry client fetch calls
  • storage: wrap worker-store.updateOverride in withFileLock to prevent concurrent read-modify-write data loss
  • website: update stats counters (247 tools, 23K+ tests) and fix mobile 2×2 grid layout in StatsBanner — corrects broken nth-of-type selector with explicit nth-child placement + pseudo-element dividers
  • tests: update cleanup mock to mockResolvedValue(undefined) for .catch() chaining in auto-save tests

0.96.3 (2026-03-29)

Bug Fixes

  • observability: add .catch() error logging to all fire-and-forget void async calls (validate, dod-gates, side-effects, detect-drift, list-specs, create-spec, license-gate, group-manager, feedback-store)
  • storage: add withFileLock to read-modify-write ops in decision-store (updateDecision) and knowledge-store/sessions (updateConstitution, updateClarification, deleteClarification, addUserPattern, appendConversationMemory, saveCalibrationMetrics) to prevent race conditions
  • validation: add .min(1) to required specId fields in detect_drift, summarize_spec, reconcile_spec; add .min(0) to numeric constraints (smtpPort, requestsPerMinute, tokensPerMinute, priority, maxRetries); add .max() limits to unbounded filter arrays in export tools
  • i18n: add missing tools.detect_ac_gaps.noGaps and tools.detect_ac_gaps.success keys to all locale files (en/es/pt)
  • http: add AbortSignal.timeout(10s) to all external fetch calls without timeout (slack-dispatcher, email-sender, confluence-exporter, github-issues-ops, pm-integrator, pm-platform-creators, platform-crawler)

0.96.2 (2026-03-28)

Bug Fixes

  • create-spec: empty title (min(1) validation) prevents invalid spec slugs (SPEC-042- with no slug); partial writeFile failure now cleans up spec directory with rm() to avoid orphaned files
  • resilience: difficulty clamped to 1-5 to prevent NaN in estimator; similarityScore handles single-char strings without division by zero; per-criterion try/catch in deep-code-checker
  • storage: withFileLock on ideas, lessons, desktop-notification, email-digest stores prevents race conditions; sqlite vector-store JSON.parse wrapped in try/catch
  • migrators: rollback directory rename if updateSpec fails to prevent orphaned spec paths
  • schemas: input validation min(1)/max(4096) on projectPath, min(1)/max(500) on specId, int().positive() on prNumber

0.96.1 (2026-03-28)

Bug Fixes

  • SPEC-312: list_specs no longer fails MCP output validation when agent-created or legacy specs lack optional fields (estimation, createdAt, difficulty, scope, risk, target) — LooseSpec defensive casting + optional fields in output schemas for estimate, validate, check_readiness

0.96.0 (2026-03-28)

Features

  • SPEC-307: Community Skill Pack — 10 built-in skills (brainstorming, security-audit, api-design, etc.) + searchBuiltInSkills adapter
  • SPEC-308: Browser Validation — extractUIAssertions + generatePlaywrightTest from spec acceptance criteria
  • SPEC-309: Semantic Code Quality — duplication, complexity, dead-code dimensions + quality reviewType in review_pr
  • SPEC-310: Google Workspace Sync — export/import specs to Google Docs format + Apps Script for live sync
  • SPEC-311: Excalidraw Diagram Generator — generateExcalidrawDiagram with 5 layout types + shareable URL

0.95.0 (2026-03-28)

Features

  • SPEC-303: expert PR review — 5 parallel dimensions (architecture, security, tests, conventions, spec-drift)
  • SPEC-303: findings-merger with deduplication and 🔴/🟡/🟢 severity classification

0.94.0 (2026-03-28)

Features

  • SPEC-306: token_savings_report — compare spec-guided vs unstructured token usage to prove ROI
  • website: token efficiency section in 6 languages with Vibe Coding vs Spec Driven comparison table

0.93.0 (2026-03-28)

Features

  • SPEC-303: expert PR review — multi-agent, multi-AI orchestration with automatic context-aware analysis
  • SPEC-304: universal projectPath support — all 59 tools accept projectPath as alternative to projectId
  • SPEC-305: error reporting pipeline — isError:true validation failures now reported to Supabase telemetry

Bug Fixes

  • SPEC-304: resolveProjectId trims whitespace-only values to restore validation behavior

0.92.0 (2026-03-28)

Features

  • SPEC-280: update_status auto-advance silently through intermediate states
  • SPEC-281: spec usability report — health metrics and actionable insights
  • SPEC-282: spec comments — threaded discussion and review annotations
  • SPEC-283: approval workflows — n-approvals gate with SLA escalation
  • SPEC-284: spec version diff comparator — side-by-side diff viewer
  • SPEC-285: spec import from Jira, Linear, Markdown, CSV
  • SPEC-286: OpenAPI and GraphQL schema to spec generator
  • SPEC-287: estimation accuracy tracking — actuals vs estimates
  • SPEC-288: velocity metrics — lead time, throughput, burndown
  • SPEC-289: auto-split large specs detection and subdivision
  • SPEC-290: domain best practices injection
  • SPEC-291: multi-agent awareness — swarm orchestration and a2a protocol
  • SPEC-292: Slack integration — incoming webhooks and rich notifications
  • SPEC-293: email digest — daily/weekly spec summaries
  • SPEC-294: Confluence sync — export specs to Confluence pages
  • SPEC-295: advanced search — filters, fuzzy matching, boolean operators
  • SPEC-296: cross-repo search — search specs across multiple projects
  • SPEC-297: team analytics — per-user metrics and workload distribution
  • SPEC-298: spec export — CSV and Markdown table for spreadsheet analysis
  • SPEC-299: test reverse engineering — generate spec ACs from E2E test files
  • SPEC-300: performance impact analysis — detect perf risks before implementation
  • SPEC-301: spec locking — prevent concurrent edit conflicts in multi-agent scenarios
  • SPEC-302: desktop notifications — OS-level alerts on spec status changes

0.91.0 (2026-03-26)

Features

  • hooks: SPEC-262 Plan Mode auto-integration — PreToolUse/PostToolUse hooks inject Planu context automatically (75e9f33)
  • init-project: SPEC-263 autonomous CLAUDE.md — init_project injects SDD workflow block + configures hooks automatically (b114a3bd)
  • facilitate: SPEC-264 universal orchestrator — smart routing (resume/create-spec/direct/clarify) + Plan Mode bridge via planContent param (10fece13)
  • deps: update all dependencies to latest stable versions (4243bbe6)
  • docs: complete documentation for all 186 tools across 6 languages (1538e688)

0.90.2 (2026-03-26)

Bug Fixes

  • license-status: guard customer display with optional chain on customerName (d3b7a9d)

0.90.0 (2026-03-25)

Bug Fixes

  • dashboard: skip HTML regeneration when spec data unchanged (SPEC-234) (2076ceb)
  • dod-gate: fix false-negative when project has tests but none linked to spec [SPEC-247] (4a9fda4)
  • list_specs: always include teamSuggestion null in structuredContent (c1fdb5b)
  • publish-blog: sanitize dev.to tags to alphanumeric only (56cebcf)
  • tests: add explicit return types to makeSpec helpers (e47f48c)
  • tests: complete Actuals type in file-sync.test.ts (65ce213)
  • tests: non-null assertions in response-builder.test.ts (2a5685c)
  • update-status: resolve eslint errors in split modules [SPEC-246] (418507d)

Features

  • blog: add 3 marketing blog posts and multi-platform publish script (433b435)
  • cli: add install/doctor/uninstall commands for multi-tool MCP setup (SPEC-236) (cb93822)
  • cli: add license key validation in install + planu activate command (SPEC-237) (2a1a9de)
  • red-team: adversarial spec review tool — pre-mortem before approval [SPEC-242] (544935a), closes hi#risk #184
  • SPEC-232,233: conventions cache + lessons learned system (6e7834c)
  • website: animated terminal install demo on homepage (7dc6910)
  • website: fix FR/DE/ZH homepages — InstallDemo, CLI copy, Vibe Coding section (e2e6b0b)
  • website: i18n for InstallDemo + tool count fixes + homepage audit (8400c87)

0.90.0 (2026-03-25)

Bug Fixes

  • dashboard: skip HTML regeneration when spec data unchanged (SPEC-234) (2076ceb)
  • dod-gate: fix false-negative when project has tests but none linked to spec [SPEC-247] (4a9fda4)
  • list_specs: always include teamSuggestion null in structuredContent (c1fdb5b)
  • publish-blog: sanitize dev.to tags to alphanumeric only (56cebcf)
  • tests: add explicit return types to makeSpec helpers (e47f48c)
  • tests: complete Actuals type in file-sync.test.ts (65ce213)
  • tests: non-null assertions in response-builder.test.ts (2a5685c)
  • update-status: resolve eslint errors in split modules [SPEC-246] (418507d)

Features

  • blog: add 3 marketing blog posts and multi-platform publish script (433b435)
  • cli: add install/doctor/uninstall commands for multi-tool MCP setup (SPEC-236) (cb93822)
  • cli: add license key validation in install + planu activate command (SPEC-237) (2a1a9de)
  • red-team: adversarial spec review tool — pre-mortem before approval [SPEC-242] (544935a), closes hi#risk #184
  • SPEC-232,233: conventions cache + lessons learned system (6e7834c)
  • website: animated terminal install demo on homepage (7dc6910)
  • website: fix FR/DE/ZH homepages — InstallDemo, CLI copy, Vibe Coding section (e2e6b0b)
  • website: i18n for InstallDemo + tool count fixes + homepage audit (8400c87)

0.90.0 (2026-03-25)

Bug Fixes

  • dashboard: skip HTML regeneration when spec data unchanged (SPEC-234) (2076ceb)
  • dod-gate: fix false-negative when project has tests but none linked to spec [SPEC-247] (4a9fda4)
  • list_specs: always include teamSuggestion null in structuredContent (c1fdb5b)
  • publish-blog: sanitize dev.to tags to alphanumeric only (56cebcf)
  • tests: add explicit return types to makeSpec helpers (e47f48c)
  • tests: complete Actuals type in file-sync.test.ts (65ce213)
  • tests: non-null assertions in response-builder.test.ts (2a5685c)
  • update-status: resolve eslint errors in split modules [SPEC-246] (418507d)

Features

  • blog: add 3 marketing blog posts and multi-platform publish script (433b435)
  • cli: add install/doctor/uninstall commands for multi-tool MCP setup (SPEC-236) (cb93822)
  • cli: add license key validation in install + planu activate command (SPEC-237) (2a1a9de)
  • red-team: adversarial spec review tool — pre-mortem before approval [SPEC-242] (544935a), closes hi#risk #184
  • SPEC-232,233: conventions cache + lessons learned system (6e7834c)
  • website: animated terminal install demo on homepage (7dc6910)
  • website: fix FR/DE/ZH homepages — InstallDemo, CLI copy, Vibe Coding section (e2e6b0b)
  • website: i18n for InstallDemo + tool count fixes + homepage audit (8400c87)

0.90.0 (2026-03-25)

Bug Fixes

  • dashboard: skip HTML regeneration when spec data unchanged (SPEC-234) (2076ceb)
  • dod-gate: fix false-negative when project has tests but none linked to spec [SPEC-247] (4a9fda4)
  • list_specs: always include teamSuggestion null in structuredContent (c1fdb5b)
  • tests: add explicit return types to makeSpec helpers (e47f48c)
  • tests: complete Actuals type in file-sync.test.ts (65ce213)
  • tests: non-null assertions in response-builder.test.ts (2a5685c)
  • update-status: resolve eslint errors in split modules [SPEC-246] (418507d)

Features

  • cli: add install/doctor/uninstall commands for multi-tool MCP setup (SPEC-236) (cb93822)
  • cli: add license key validation in install + planu activate command (SPEC-237) (2a1a9de)
  • red-team: adversarial spec review tool — pre-mortem before approval [SPEC-242] (544935a), closes hi#risk #184
  • SPEC-232,233: conventions cache + lessons learned system (6e7834c)
  • website: animated terminal install demo on homepage (7dc6910)
  • website: fix FR/DE/ZH homepages — InstallDemo, CLI copy, Vibe Coding section (e2e6b0b)
  • website: i18n for InstallDemo + tool count fixes + homepage audit (8400c87)

0.89.0 (2026-03-24)

Features

  • SPEC-232,233: conventions cache + lessons learned system (d69fe6a)

0.88.1 (2026-03-24)

Bug Fixes

  • SPEC-231: DoD gate UX — expose failedItems + fix 0/100 score false negative (f259931)

0.88.0 (2026-03-24)

Features

  • SPEC-229,230: DoD gates engine + convention injection in create_spec (82d177b)

0.87.1 (2026-03-24)

Bug Fixes

  • tests: increase reverse-engineer orchestrator timeout 30s→90s (repo growth) (55a57bf)

0.87.0 (2026-03-24)

Features

  • SPEC-228: init_project deep scan — convention detection & quality baseline (dc504ea)

0.86.0 (2026-03-24)

Features

  • dashboard: search filter + revoked stats card + CSV export (df53160)

0.85.0 (2026-03-24)

Features

  • license: enrich auto-generated instance name with user/OS/project context (78d500c)

0.84.0 (2026-03-24)

Features

  • dashboard: edit license + activations detail panel per machine (da87b2a)

0.83.1 (2026-03-24)

Bug Fixes

  • dashboard: responsive table + reactivate button for revoked licenses (fb794c0)

0.83.0 (2026-03-23)

Features

  • SPEC-224,225,226,227: BDD ACs, auto-drift, DoD fix, GitHub Issues sync (aac93c8)
  • Vibe Coding positioning, BDD framing, and 4 new specs (SPEC-224/225/226/227) (f2fa172)

0.82.0 (2026-03-23)

Bug Fixes

  • i18n: add missing reconcileSpec.description and tools.reconcileSpec keys (SPEC-148) (308bd36)

Features

  • workers: auto-start, heartbeat, crash recovery, and config layering (SPEC-136,137,138) (3f4e7f7)

0.81.1 (2026-03-23)

Bug Fixes

  • tests: rename duplicate test description in compliance-injector (7f5c9d7)

0.81.0 (2026-03-23)

Features

  • SPEC-202,208-219: plugin JSON configs — 3-layer configurable engine data (446f77c)

0.80.1 (2026-03-23)

Bug Fixes

  • SPEC-204: search planu key under mcpServers not root in ~/.claude.json (1ff9077)

0.80.0 (2026-03-23)

Features

  • SPEC-220,223: session_checkpoint + planu_status tools (36f02be)
  • SPEC-221,222: compact responses + automation triggers (536a5b7), closes hi#risk

0.79.2 (2026-03-23)

Bug Fixes

  • allow digits in tool name regex in check-tool-registration.sh (1201a0b)

0.79.1 (2026-03-21)

Bug Fixes

  • git add planu/ after HTML regeneration to prevent uncommitted dashboard files (266f3a2)

0.79.0 (2026-03-21)

Bug Fixes

  • disable no-misused-promises for tests, add EstimationTablesConfig type (badaec5)
  • disambiguate duplicate test descriptions in config-loader and mcp-name tests (b4c4f32)
  • revert MCP protocol name to 'planu' — SPEC-204 uses key rename approach (6cb8bc4)
  • SPEC-217: fix lint errors in backlog tests — remove async without await, no-dynamic-delete (a5cc78c)
  • SPEC-217: fix remaining lint errors in backlog handlers and tests (773d6d0)

Features

  • SPEC-201: local-first CI — generate planu-check.sh without GitHub billing (e2852dd)
  • SPEC-203: auto-cleanup git — manage_git(cleanup) + done hook (5b4f1b6)
  • SPEC-204: dynamic MCP server name — show version and tier in Claude Code UI (3bdae26)
  • SPEC-217: ideas backlog — capture_idea, list_backlog, promote_idea, discard_idea (7ffa240)

0.78.0 (2026-03-19)

Features

  • add anonymous opt-in telemetry for free tier usage tracking (SPEC-200) (6720c57)

0.77.0 (2026-03-19)

Features

  • auto-mark specs done when branch merged (SPEC-176) (f562d12)
  • SPEC-199: convention-aware test criteria injection in create_spec ACs (a3a8886)

0.76.0 (2026-03-19)

Features

  • SPEC-198: design/marketing skills auto-discovery in init_project (a37b9d0)

0.75.0 (2026-03-19)

Bug Fixes

  • e2e: increase validate test timeout to 30s for slow CI runners (7f23609)
  • raise smoke test upper bound to 200 (110 tools now visible by default) (2dfd389)
  • SPEC-147: remove unnecessary optional chaining on architecture.primary (e216405)

Features

  • implement SPEC-159, SPEC-161, SPEC-163, SPEC-147 (ae0e914)
  • SPEC-147: frontend architecture patterns — atomic design, component library, design tokens (3251895)
  • wire 10 P5 register files into MCP server (SPEC-160/162/165/166/167/168/169/170/171) (f8e1abc)
  • wire 10 P5 register files into MCP server (SPEC-160/162/165/166/167/168/169/170/171) (743ebcb)

0.74.0 (2026-03-19)

Bug Fixes

  • SPEC-177: guard against undefined stack/conventions in serverless adapter (53ed4fb)
  • SPEC-177: remove unnecessary null-coalescing on always-defined ProjectKnowledge fields (cd40170)

Features

  • SPEC-177: detect serverless runtime and warn against in-memory state patterns (ee9d910)
  • SPEC-179: add lifecycle notifications for pending git operations (23bbd7e)

0.73.0 (2026-03-18)

Bug Fixes

  • remove inner quotes from test descriptions in spec-template-cleaner (b358be9)
  • security: harden shell injection vectors and portal notification gaps (942ec96)
  • SPEC-193: generate portal pages automatically after init_project (b1a0afe)
  • SPEC-194: prevent command injection via lintCommand/testCommand (01b255c)
  • SPEC-195: fix engine→tools architecture violations + achieve 98% test coverage (376ef0a)
  • SPEC-196: eliminate JSON.stringify from tool content[].text (9de7282)
  • SPEC-197: update_status(done) sincroniza spec.md y CI lee frontmatter (649d144)
  • test: add return types to fix ESLint errors in SPEC-194 tests (427960a)

Features

  • add autonomous-sdd skill for full SDD cycle (544c504)
  • add DX feedback template, issue chooser, error report links, enable discussions (2d586be)
  • add reconcile_rules and reconcile_skills tools (SPEC-189) (2127305)
  • agent prompt generator, config health, and tool registration (60d60e1)
  • AI-tool rules generator and user feedback hub (SPEC-187, SPEC-188) (b638422)
  • convention scanner, spec injection, and validate overhaul (SPEC-190/191/192) (801f346)
  • custom spec templates, auto-reconcile hook, extension registry (71e2b9f)
  • dual-write feedback to Supabase, admin dashboard feedback view (b0af759)
  • init_project tells users they can report bugs/suggestions naturally (e8b7639)
  • lint/test gates, reconcile_hooks, template cleanup, skill_search fix (3772cb3)
  • wire token ledger recording, auto-reconciler, and verify block consumption (0246e1c)

0.72.0 (2026-03-17)

Features

  • deep validation, verifiable criteria, skill auto-install (SPEC-183/184/185/186) (4f27602)

0.71.0 (2026-03-17)

Features

  • auto-detect unregistered tools in pre-commit hook (SPEC-182) (0951329)

0.70.0 (2026-03-17)

Features

  • register token_intelligence tool and sync website counts to 162 (SPEC-182) (a5f1211)
  • token intelligence with persistent cost tracking and reconciliation (SPEC-182) (002a227)

0.69.0 (2026-03-16)

Features

  • dynamic technology discovery from live npm/GitHub registries (SPEC-181) (716ec83)

0.68.0 (2026-03-16)

Features

  • implement SPEC-178 and SPEC-180 (bc412d0)
  • scaffold ESLint/Prettier config and project health check (SPEC-178, SPEC-180) (befa221)

0.67.0 (2026-03-16)

Features

  • implement SPEC-176/177/179 + fix skill_search path and auto-install (adc906d)

0.66.2 (2026-03-16)

Bug Fixes

  • eliminate hardcoded values and protect planu/ from gitignore (7ec0b02)

0.66.1 (2026-03-16)

Bug Fixes

  • add database and API naming conventions to CLAUDE.md generator (f42d31e)

0.66.0 (2026-03-16)

Features

  • generate comprehensive CLAUDE.md from detected project knowledge (SPEC-175) (a78124c)

0.65.0 (2026-03-15)

Features

  • centralize hardcoded versions and add auto-verification directives (SPEC-174) (f0b3a20)

0.64.1 (2026-03-15)

Bug Fixes

  • add v8 ignore annotations and defensive guards for branch coverage (a45af59)

0.64.0 (2026-03-14)

Features

  • implement specs 154-173 with zero-generic specialized code (a6b9d3c)

0.63.7 (2026-03-14)

Bug Fixes

  • reduce tech debt — remove unnecessary eslint-disables and add guards (b0b4fd2)

0.63.6 (2026-03-14)

Bug Fixes

  • harden defensive patterns and remove remaining code smells (d284007)

0.63.5 (2026-03-14)

Bug Fixes

  • replace silent error swallowing with console.error logging (b901f63)
  • storage: add withFileLock to token-cache-store and vector-store/json-fallback (9ec9856)

0.63.4 (2026-03-14)

Bug Fixes

  • security: add path traversal guard, salted hash, and JSON.parse safety (c7058b2)

0.63.3 (2026-03-14)

Bug Fixes

  • storage: add withFileLock to 8 remaining stores to prevent race conditions (e9cdc7b)

0.63.2 (2026-03-14)

Bug Fixes

  • security: replace exec with execFile in dashboard, remove command injection in hook-ops (9865b76)

0.63.1 (2026-03-14)

Bug Fixes

  • tests: resolve 3 pre-existing lint errors in test files (6b1fd8d)

0.63.0 (2026-03-13)

Bug Fixes

  • tests: resolve 4 CI failures from SPEC-152/153 integration (153f281)
  • update create-spec tests to use structuredContent instead of JSON.parse (cff808e)

Features

  • dynamic knowledge engine + resilience injector (SPEC-152, SPEC-153) (545d16d)
  • ecosystem absorber with platform crawler (SPEC-151) (c554e3e)
  • merge SPEC-150 skill registry with unified search (461f0d2)
  • merge SPEC-152 + SPEC-153 dynamic knowledge engine and resilience injector (0f342be)
  • skill registry with unified search (SPEC-150) (85b6d97)

0.62.1 (2026-03-13)

Bug Fixes

  • only regenerate HTML reports for changed specs, not all specs (ea3e8de)

0.62.0 (2026-03-13)

Features

  • zero-config onboarding with autonomous workflow, auto-init, and tutorial rewrite (SPEC-149) (2002a8a)

0.61.0 (2026-03-13)

Features

  • standardize tool response UX with emojis, i18n, and actionable next steps (SPEC-148) (d292cad)

0.60.0 (2026-03-13)

Features

  • error telemetry store, CI audit hardening, and SPEC-147 frontend patterns (dce57e0)

0.59.1 (2026-03-13)

Bug Fixes

  • massive bug audit — 41 fixes across tools, engine, and storage layers (86f1974)

0.59.0 (2026-03-13)

Features

  • wire SPEC-136/137/138 hook handlers into engine with auto-registration (b0df337)

0.58.0 (2026-03-13)

Features

  • add scorecard/mermaid/verdict sections and auto-regenerate portal (f4dd131)

0.57.0 (2026-03-13)

Features

  • add export_pdf tool for HTML-to-PDF conversion via system Chrome (116a443)

0.56.0 (2026-03-12)

Features

  • analytics, roadmap, risk matrix, decisions, architecture & changelog (SPEC-142, SPEC-143) (bcfded1)
  • portal hub with proposal generator, navbar, and breadcrumbs (SPEC-140, SPEC-141) (f9a074e)

0.55.0 (2026-03-12)

Features

  • reports: rich HTML spec reports with real data injection (SPEC-139) (1789bbb)

0.54.2 (2026-03-12)

Bug Fixes

  • scan-project: check existing spec IDs from both store and filesystem (4116239)

0.54.1 (2026-03-12)

Bug Fixes

  • estimate: align output schema with actual handler response types (fe45d63)

0.54.0 (2026-03-12)

Features

  • auto-reconcile hooks and automated drift/security audits (SPEC-137, SPEC-138) (9092a7b)

0.53.0 (2026-03-12)

Bug Fixes

  • website: sync all tool counts to 141 and improve auto-sync patterns (d2b0fa6)

Features

  • auto-start workers + hook handlers for reconcile, drift, and security (09acb58)

0.52.0 (2026-03-12)

Features

  • AC templates per spec type, auto-start hooks, and dark mode fix (22f610b)

0.51.0 (2026-03-12)

Bug Fixes

  • dashboard: filesystem specs take priority over stale store data (36307d3)
  • dashboard: merge filesystem specs into dashboard generation (91bb496)
  • e2e: robust cleanup and ignore e2e test artifacts (c684d61)
  • license: add generate_spec_dashboard to freeTools plan (f44d915)
  • list-specs: auto-import filesystem specs missing from store (ec9c68d)
  • update-status: sync spec status to frontmatter on state transitions (0f53da9)

Features

  • cli: add --json, --quiet, --verbose global flags to all commands (c66b216)
  • dashboard: add generate_spec_dashboard tool with pagination (SPEC-135) (f2ab7fb)
  • lifecycle: add 'discarded' terminal status for cancelled specs (3b1d9de)

0.50.0 (2026-03-11)

Features

  • scan-project: add team planner, spec integrity, and benchmarks (c8c06da)

0.49.0 (2026-03-11)

Features

  • scan-project: add scan_project tool for bulk reverse engineering (SPEC-134) (da5f35e)

0.48.2 (2026-03-11)

Bug Fixes

  • website: update copy to reflect freemium model honestly (1bfef57)

0.48.1 (2026-03-11)

Bug Fixes

  • website: fix /tools/ 404 link in ToolStreams component for EN locale (1cee2d8)

0.48.0 (2026-03-10)

Features

  • website: add StatsBanner, InstallTabs, and ToolStreams components (b808967)

0.47.1 (2026-03-10)

Bug Fixes

  • dod: use smart DoD validator and add force bypass for update_status (69996fc)

0.47.0 (2026-03-10)

Features

  • mcp: add MCP server layer suggestion engine (SPEC-132) (b07e6e4)

0.46.0 (2026-03-10)

Features

  • legal: add legal compliance engine with question framework (SPEC-131) (80a180a)

0.45.5 (2026-03-10)

Bug Fixes

  • validate: smarter DoD gates, spec ID collision guard, dynamic naming (c1e47cd)

0.45.4 (2026-03-10)

Bug Fixes

  • validate: fix DoD gates, quality line schema, docs-site ignore; add SDD injection (c009055)

0.45.3 (2026-03-10)

Bug Fixes

  • validate: fix ghost criteria, file scanning, and actuals detection (079f5bc)

0.45.2 (2026-03-10)

Bug Fixes

  • list-specs: convert difficulty to string for output schema (c68f100)

0.45.1 (2026-03-10)

Bug Fixes

  • coverage: use v8 ignore start/stop for reliable branch exclusion (68655f9)

0.45.0 (2026-03-10)

Bug Fixes

  • test: raise smoke test tool count upper bound to 80 (fe37ff4)

Features

  • registry: implement SPEC-127 spec registry core (7657f89)
  • registry: implement SPEC-128 spec registry advanced (912f1f6)

0.44.0 (2026-03-10)

Bug Fixes

  • stop adding .claude/ to .gitignore on init_project (c5b9cea)
  • test: update dashboard mock to use startDashboardWithFallback (382bdc7)

Features

  • cli: implement SPEC-124 CLI standalone (8623e9b)
  • dashboard: implement SPEC-122 visual dashboard core (14afba8)
  • dashboard: implement SPEC-123 visual dashboard advanced (704cac9)
  • hooks: implement SPEC-129 event hooks core (14fa17a)
  • hooks: implement SPEC-130 event hooks advanced (a364f6c)
  • implement SPEC-120 Living Specs Core (045c5ad)

0.43.1 (2026-03-10)

Performance Improvements

  • optimize test speed and improve coverage to meet thresholds (bb22656)

0.43.0 (2026-03-09)

Bug Fixes

  • resolve CI test failures and harden path sanitization (edea397)
  • resolve critical gaps from exhaustive audit (wave 1) (39ef632)
  • resolve HIGH gaps from audit (wave 2) (e9141e6)
  • resolve MEDIUM gaps from audit (wave 3) (37d081a)
  • update registry-updater tests for writeJsonSafe (c08f442)

Features

0.42.1 (2026-03-09)

Bug Fixes

  • enforce flat spec structure, remove _general subfolder, fix docs-site path (4cb56e3)

0.42.0 (2026-03-09)

Bug Fixes

  • make progress.md write and dashboard regen best-effort in update_status (594381c)
  • reconcile stale specs.json paths after folder rename/flatten (f717349)
  • tests: add missing mocks for hooks and spec-summary-html in update-status tests (b059fbe)

Features

  • add i18n spec dashboard, markdown renderer, and per-spec HTML reports (d6cca5f)
  • auto-generate planu/index.html with specs overview dashboard (1f0b7af)

0.41.2 (2026-03-09)

Bug Fixes

  • auto-rename unprefixed spec folders on list_specs and init_project (4a8dff0)

0.41.1 (2026-03-09)

Bug Fixes

  • add --prefer-online to all npx config snippets across website (4041e46)

0.41.0 (2026-03-09)

Bug Fixes

  • update index test to expect createMcpServer factory argument (edac134)

Features

  • add duration quick-pick buttons to license dashboard + install guide (b2d7754)
  • add MCP server-card.json for Smithery registry discovery (145ff0d)
  • auto-discover and flatten specs in subcategory folders (de53550)
  • auto-discover specs on first list_specs call per session (642fec5)
  • hosted MCP server with per-session license keys (c3401b2)

Performance Improvements

  • optimize pre-push hook — run only changed tests instead of full suite (eabd0c6)

0.40.0 (2026-03-08)

Features

  • generate executive and technical HTML reports for all 115 specs (12693ce)
  • migrate specs to YAML frontmatter, flatten structure in MCP (616f5b5)

0.39.0 (2026-03-07)

Features

  • add auto-lifecycle hooks across spec lifecycle (dba7eac)

0.38.0 (2026-03-07)

Bug Fixes

  • ci: increase timeout for orchestrator integration tests (0ded33a)
  • correct GitHub repo URL in Dockerfile labels (7b580e0)

Features

  • add Docker support with multi-stage build (38c34bb)
  • add SPEC-095, SPEC-096, SPEC-097 specs + npm keywords (98f992b)
  • auto-prefix spec folders with SPEC-XXX-slug on create and init (83e2b46)
  • implement SPEC-095 (HTTP transport) + SPEC-097 (spec-kit export) (f8f69dd)
  • implement SPEC-096 reverse_engineer_spec v2 deep analysis (b0fc1fe)

0.37.0 (2026-03-07)

Features

  • implement SPEC-094 lifecycle safety (10 ACs) (d8ca311)

0.36.0 (2026-03-07)

Bug Fixes

  • suppress max-lines-per-function warning in collectSpecs (0d3614b)

Features

  • implement SPEC-093 generate_docs_site tool (tool #104) (a6760a1)

0.35.2 (2026-03-07)

Bug Fixes

  • spec ID counter now reads IDs from spec.md in slug-only dirs (4689d67)

0.35.1 (2026-03-06)

Bug Fixes

  • auto-pull on branch checkout to prevent local-behind-remote (66e6a6f)

0.35.0 (2026-03-06)

Features

  • implement SPEC-092 audit_claude_config tool (a4fcd02)

0.34.0 (2026-03-06)

Bug Fixes

  • resolve spec ID collision across feature groups (b6b10e4)

Features

  • implement SPEC-092 audit_claude_config tool (b694f4f)

0.33.1 (2026-03-06)

Bug Fixes

  • resolve spec ID collision across feature groups (b6b10e4)

0.33.0 (2026-03-06)

Features

  • implement SPEC-088 to SPEC-091 automation specs (1b05a63)

0.32.0 (2026-03-06)

Features

  • website: replace Giscus with Discord community banner (9341e0a)

0.31.0 (2026-03-06)

Bug Fixes

  • tests: update smoke test tool limit and IDE detection assertion for CI (9a7647b)

Features

  • add license admin dashboard with Planu branding (06f40ba), closes #14B8A6
  • implement SPEC-078 to SPEC-087 — close all Ruflo gaps (10 specs, 891 tests) (8b40cd4)
  • migrate license API from Lemon Squeezy to self-hosted Supabase (3e080bd)

0.30.1 (2026-03-06)

Bug Fixes

  • sync license-plans.json with 85 tools, add version to license_status (85cd653)

0.30.0 (2026-03-06)

Features

  • complete SPEC-066, SPEC-070, SPEC-075 remaining criteria (b092466)

0.29.0 (2026-03-05)

Features

  • code-transforms: implement SPEC-077 code transforms (e42db79)
  • merge SPEC-075 vector memory and SPEC-077 code transforms (644ad1f)
  • model-router: implement SPEC-076 smart model router (5909a51)
  • SPEC-075: vector memory with TF-IDF, HNSW, semantic search (5cb08c8)

0.28.0 (2026-03-05)

Features

  • SPEC-074: implement tool groups with lazy loading (5653178)

0.27.0 (2026-03-05)

Features

  • git: auto-detect workflow, auto-setup branches, spec approval flow (5d0df2a)

0.26.0 (2026-03-05)

Features

  • website: add plan comparison table and pricing analysis (6b74a37)

0.25.0 (2026-03-05)

Features

  • competitive: implement 9 competitive specs (SPEC-065 to SPEC-073) (5c2eff4)
  • reduce trial to 7 days + add 9 competitive specs (SPEC-065 to SPEC-073) (e7a1a2a)

0.24.0 (2026-03-05)

Features

  • licensing: harden license validation with machine fingerprint and reduced TTL (77c7c1f)

0.23.2 (2026-03-05)

Bug Fixes

  • licensing: display correct tier and tool count in license_status (8a9d735)

0.23.1 (2026-03-05)

Bug Fixes

  • licensing: license_status now respects owner token override (974c64a)

0.23.0 (2026-03-05)

Features

  • licensing: add secure owner token override for full access (c40f507)

0.22.1 (2026-03-04)

Bug Fixes

  • licensing: wire rate limiting into all tool calls and fix free tier consistency (5517b3b)

0.22.0 (2026-03-04)

Features

  • licensing: activate Lemon Squeezy checkout buttons and update tool counts (36617b7)

0.21.0 (2026-03-04)

Bug Fixes

  • SPEC-064: wire usage tools into MCP server entry point (b8fa26c)

Features

  • SPEC-064: add usage tracking, trial enforcement, and rate limiting (532b7d3)

0.20.0 (2026-03-04)

Features

  • ci: unified auto-distribution for blog posts to dev.to, Hashnode, and Twitter (7df42fe)
  • SPEC-065: migrate to planu/specs/ with per-spec HTML reports (46d173d)
  • website: add Spanish blog (8 articles), connect newsletter to Buttondown (f2f012c)

0.19.0 (2026-03-04)

Features

  • website: redesign pricing for enterprise appeal, remove free branding (3997293)

0.18.1 (2026-03-04)

Bug Fixes

  • website: use native form submission for Buttondown newsletter (7333d19)

0.18.0 (2026-03-04)

Features

  • website: add Spanish blog (8 articles), connect newsletter to Buttondown (447f0ce)

0.17.0 (2026-03-03)

Features

  • ci: unified auto-distribution for blog posts to dev.to, Hashnode, and Twitter (abff6bd)

0.16.0 (2026-03-03)

Features

  • website: add blog, sponsors page, newsletter, RSS feed, and distribution automation (3777f7b), closes hi#volume

0.15.5 (2026-03-03)

Bug Fixes

  • seo: improve title template, add twitter:site meta tag (b99cf88)

0.15.4 (2026-03-03)

Bug Fixes

  • update social links to planu-dev GitHub and add X/Twitter (f585c75)

0.15.3 (2026-03-03)

Bug Fixes

  • add @iconify-json/simple-icons to website dependencies (5629d65)

0.15.2 (2026-03-03)

Bug Fixes

  • add website tsconfig.json to avoid ES2024 esbuild error (8184375)

0.15.1 (2026-03-02)

Bug Fixes

0.15.0 (2026-03-02)

Features

  • licensing: implement Lemon Squeezy license enforcement system (bcd99d9)

0.14.1 (2026-03-02)

Bug Fixes

  • website: disable empty aside sidebar on pricing pages (440dfb2)

0.14.0 (2026-03-02)

Features

  • website: redesign homepage sections, pricing cards, and fix broken links (cc802d9)

0.13.4 (2026-03-02)

Bug Fixes

  • website: add vercel.json with cleanUrls for proper URL routing (13878b5)

0.13.3 (2026-03-02)

Bug Fixes

  • website: enable cleanUrls to fix 11 empty pages on Vercel (6714a52)

0.13.2 (2026-03-02)

Bug Fixes

  • ci: add @semantic-release/changelog to auto-update CHANGELOG.md (92834a3)

Changelog

All notable changes to SpecForge are documented here.

Format: Keep a Changelog · Versioning: SemVer


[Unreleased]

Added

  • Feature grouping for specs: specs now organized under {feature}/{slug}/ directories
  • Mermaid diagrams now use real project knowledge (framework, database, architecture layers)
  • SpecForge version identifier (Generated by: SpecForge vX.Y.Z) in FICHA-TECNICA.md metadata

Fixed

  • Duplicate Architecture row appearing outside the metadata table in FICHA-TECNICA.md
  • Structured multi-paragraph descriptions no longer wrapped in "As a user, I want..." in HU.md

0.13.1 — 2026-03-01

Fixed

  • website: Redesign PricingCards and clarify technical terms in copy

0.13.0 — 2026-03-01

Added

  • website: Replace donation system with pricing page and visual components
  • Auto-sync script for tool count across website and smoke test
  • Documentation updated to reflect 60 tools after context_budget addition

0.12.1 — 2026-02-28

Fixed

  • tests: Update smoke test tool count to 60 after context_budget addition

0.12.0 — 2026-02-27

Added

  • tools: context_budget tool for context window optimization (SPEC-063)
  • 60 MCP tools total

0.11.1 — 2026-02-27

Fixed

  • ux: Improve summarize_spec and generate_docs tool descriptions to prevent LLM bypass

Changed

  • Refactor: split 5 files near 400L limit into subdirectories

0.11.0 — 2026-02-27

Added

  • engine: Executive summary HTML export (SPEC-060)
  • engine: Git-derived actuals and cost tracking (SPEC-061)
  • engine: Structured risk, complexity and trade-off documentation (SPEC-062)
  • 213 new tests across 54 files (+5,618 lines)

0.10.0 — 2026-02-27

Added

  • ux: Git branch suggestions in MCP workflow (e.g., feat/SPEC-XXX-name after creating specs)
  • ux: Git Flow enforcement — remind users to work in dedicated branches

0.9.0 — 2026-02-26

Added

  • ux: Global server instructions with plain-language glossary for all technical terms
  • ux: Tool descriptions rewritten to be conversational and beginner-friendly

[0.8.0] — 2026-02-26

Added

  • Global MCP server instructions with glossary of 20+ technical terms explained in plain language
  • All 43 tool descriptions rewritten in conversational tone across EN/ES/PT
  • UX rules: be warm, summarize results, explain jargon, adapt to locale

Changed

  • Tool descriptions now explain concepts like "spec", "drift", "ADR", "schema", "PII" inline
  • Remaining untranslated migrate_tech messages now fully localized in ES/PT

[0.7.0] — 2026-02-26

Added

  • Multi-spec decomposition: broad requests (e.g., "build me a billing system") are automatically broken into individual feature specs
  • LLM presents a plan and waits for confirmation before creating specs
  • Post-creation summary with estimated effort and implementation order

Changed

  • create_spec description updated across EN/ES/PT with detailed UX behavior instructions
  • init_project description now guides LLM to explain scanning, ask for user role, and summarize detection

[0.6.1] — 2026-02-26

Added

  • E2E lifecycle test suite: 68 tests validating all tool handlers with valid enum inputs
  • Tests cover 4 streams: core, analysis, platform, governance

[0.6.0] — 2026-02-26

Fixed

  • All 27 Zod enums now have .describe() with explicit valid values — prevents LLM hallucination of invalid enum values (e.g., sending "mid" instead of "intermediate")
  • ExperienceLevelEnum description now lists valid options

[0.5.0] — 2026-02-25

Added

  • Profile-aware UX: userProfile parameter on init_project (developer, product-owner, designer, non-technical)
  • Simplified clarification flow — SpecForge asks fewer, smarter questions based on user profile
  • ChatGPT Desktop and Cline (VS Code) added to compatible AI tools list
  • Website language simplified for non-technical users

Changed

  • clarify_requirements now only triggers for extremely vague topics (< 3 words)
  • Removed technical interrogation questions (performance, timeline, dependencies) — SpecForge decides these based on project context

[0.2.0] — 2026-02-25

Added

  • Semantic-release for automatic versioning and npm publish via GitHub Actions
  • workflow_dispatch trigger on publish workflow

Fixed

  • Husky hooks disabled in CI semantic-release workflow
  • npm auth configuration in setup-node

[0.1.1] — 2026-02-24

Added

  • Website published at https://specforge-mcp.vercel.app in 6 languages (EN, ES, PT, FR, ZH, DE)
  • Ko-fi donation button (floating popup + donate page)
  • Google Search Console verification
  • Hero logos panel with OS, AI agents, and language logos
  • Ecosystem banner with animated marquee (AI agents + languages)
  • Mobile performance improvements (LCP, FCP optimization)
  • Preload hints for critical CSS/JS assets

Fixed

  • Mobile hero overlap — VitePress .VPHero .image container now hidden on mobile
  • Sitemap hreflang — all 85 URLs now have correct 7 hreflang alternates
  • Donation popup now appears after 8s delay (was 3s) to avoid LCP interference

[0.1.0] — 2026-02-20

Added

  • Initial public release on npm as specforge-mcp
  • 59 MCP tools across 8 streams (A–H): init, spec lifecycle, analysis, planning, platform, docs, orchestration, governance
  • Support for TypeScript, Python, Go, Rust, Java/Kotlin, Swift, PHP, Ruby, C#, Dart/Flutter
  • Works with Claude Code, Cursor, Windsurf, Gemini CLI, GitHub Copilot, VS Code
  • Spec Driven Development (SDD) workflow: HU.md + FICHA-TECNICA.md + PROGRESS.md per spec
  • Mermaid diagram generation (architecture, sequence, state machine, ER, data flow)
  • Multi-language i18n (EN/ES/PT) for generated specs
  • Clean Architecture (hexagonal) — engine, tools, storage, types layers
  • 10,857 tests with ≥95% coverage
加入社区提问、分享反馈,与其他使用 Planu 的开发者交流。
加入 Discord