更新日志
此页面随每次发布自动更新。
[5.7.0] - 2026-08-31
Features
- feat: registry-mapped ~/.planu demolisher and storage isolation guard (SPEC-1709)
- feat(lifecycle): SPEC-1703 declared architectural-premise drift routes reconcile_spec demotion
- feat: add done-drift missing-files compliance check (SPEC-1701)
- feat(telemetry): SPEC-1704 anonymous event envelope v1 and consent CLI
Bug Fixes
- fix: serialize prepublish-guard suite to avoid full-load spawn flake
- fix: declare telemetry and test-home env vars in schema and serialize lock-lease suite
- fix: reuse shared pathExists helper in legacy planu demolisher (SPEC-1709)
- fix: harden legacy planu demolisher (symlinks, canonical root) SPEC-1709
- fix: enforce mcp trust boundary and bind drift source into receipt digest (SPEC-1703)
- fix: exclude globs and directory refs from done-drift check, wire early return (SPEC-1701)
- fix(telemetry): close legacy properties, validate ids, truncate show output (SPEC-1704)
- fix(gates): destination-aware premise matching and tool-level AC1 coverage (SPEC-1702 review fixes)
- fix(gates): SPEC-1702 cross-spec premise contradiction detection
[5.6.0] - 2026-08-31
Features
- feat(init-project): regenerate conventions.md from folded conventions.json (SPEC-1699)
- feat(init-project): fold legacy planu/ root artifacts on update (SPEC-1699)
- feat(init-project): gitignore legacy planu/ root files (SPEC-1699)
- feat(create-spec): refresh the regenerable spec index after writing spec.md (SPEC-1699)
- feat(storage): add regenerable spec.md index (SPEC-1699)
Bug Fixes
- fix(test): reconcile suites with SPEC-1699 runtime relocation and serialize frozen-lockfile suite
- fix(storage): classify retention and current-project catch degradations
- fix(release): require the exact tsgo package dir, not any node_modules content
- fix(release): drop CI=true from frozen-lockfile install, probe tsgo native package
- fix(SPEC-1696): accept inline YAML arrays for scenario tests in frontmatter
- fix(storage): close retention review gaps from Codex CHANGES_REQUIRED
- fix(storage): enforce retention budgets on runtime storage writers
- fix(SPEC-1694): report the actual test runner instead of Unknown
- fix(SPEC-1694): promote framework/database claims only from runtime dependencies
- fix: parse ordered-list markers in BDD criteria extraction (SPEC-1688)
- fix: repair release-gate collateral fallout from SPEC-1699 fold (blocker 6 sweep)
- fix: release.sh repoints version marker to planu/project.json (SPEC-1699 blocker 6)
- fix: reconcile-release-pending falls back to legacy pending.json (SPEC-1699 blocker 4)
- fix: legacy-root-migration idempotency and fail-safe malformed handling (SPEC-1699 blocker 3)
- fix: append-releases fails closed on ledger errors (SPEC-1699 blocker 5)
- fix: verify spec.md digest at the spec-store read choke point (SPEC-1699 blocker 2)
- fix(housekeeping): protect planu/.runtime as the canonical runtime home (SPEC-1699)
- fix: address implementation-review blockers for SPEC-1695 runtime relocation
- fix: reroute default proposal/export/docs-site outputs to planu/.runtime (SPEC-1695)
- fix: relocate runtime artifacts to planu/.runtime (SPEC-1695)
Refactoring
- refactor(release): fold pending release ledger into planu/project.json (SPEC-1699)
- refactor: relocate session.json and session-context.md under planu/.runtime (SPEC-1699)
- refactor: route spec resources through the current-project spec index (SPEC-1699)
- refactor: canonical planu/ set shrinks to project.json + specs/ (SPEC-1699)
[5.5.3] - 2026-08-30
Bug Fixes
- fix: reuse canonical pathExistsStrictByStat and give worktree-list test a real project path
- fix(SPEC-1682): honor Risks and Test Plan section headings in handoff packager
- fix(SPEC-1683): close guard bypass, fail-closed pristine check, TOCTOU-safe removal
- fix(SPEC-1683): git command guard and stray embedded repo self-heal
Chores
- chore(planu): SPEC-1685 implementing transition state
[5.5.2] - 2026-08-30
Bug Fixes
- fix: reuse canonical pathExistsStrictByStat and give worktree-list test a real project path
- fix(SPEC-1682): honor Risks and Test Plan section headings in handoff packager
- fix(SPEC-1683): close guard bypass, fail-closed pristine check, TOCTOU-safe removal
- fix(SPEC-1683): git command guard and stray embedded repo self-heal
Chores
- chore(planu): SPEC-1685 implementing transition state
[5.5.1] - 2026-08-30
Bug Fixes
- fix(SPEC-1682): honor Risks and Test Plan section headings in handoff packager
- fix(SPEC-1683): close guard bypass, fail-closed pristine check, TOCTOU-safe removal
- fix(SPEC-1683): git command guard and stray embedded repo self-heal
Chores
- chore(planu): SPEC-1685 implementing transition state
[5.5.0] - 2026-08-29
Features
- feat(SPEC-1681): cache the prettier format gate with content strategy
Bug Fixes
- fix(SPEC-1684): cap vitest workers at 6 in preflight related and full-suite runs
- fix(storage): handle ENOENT explicitly in best-effort path normalization
- fix(SPEC-1677,SPEC-1678): dedupe AGENTS.md changes and bound legacy skips to contract codes
- fix(SPEC-1678): classify legacy contract failures as non-fatal skipped entries
- fix(SPEC-1677): install and refresh planu core host assets on safe update
- fix(SPEC-1679): normalize both roots in canonical re-check to match heal semantics
- fix(SPEC-1679): self-heal missing registry logicalProjectId in canonical-root gate
[5.4.1] - 2026-08-29
Bug Fixes
- fix(SPEC-1675): strip FILES/FUNCTIONS/TEST metadata markers from contradiction analysis
- fix(SPEC-1676): rebuild expired project knowledge graph and re-stamp cached reuse
[5.4.0] - 2026-08-29
Features
- feat(SPEC-1672): install phase skills with managed-by ownership marker on init hosts
Chores
- chore(deps): upgrade stryker to v10 majors
- chore(deps): update 13 patch/minor dependencies and adapt readFile mock casts
[5.3.69] - 2026-08-29
Features
- feat(SPEC-1674): tail or skip oversized operational graph sources instead of throwing
Bug Fixes
- fix(SPEC-1674): include warnings in graph coverage test fixtures
- fix(SPEC-1669): fail closed on ambiguous spec discovery, real validator in tests
- fix(SPEC-1669): quarantine journals via atomic rename, test via init_project
- fix(SPEC-1669): re-discover canonical spec.md when the readiness index is stale
- fix(SPEC-1669): quarantine stale terminal migration journals instead of throwing
- fix(SPEC-1673): capture nested vitest child output instead of inheriting stdio
- fix(SPEC-1673): serialize load-sensitive test suites into a dedicated vitest project
- fix(SPEC-1670): accept Next.js route group and dynamic segment characters in ownership paths
- fix(SPEC-1674): harden oversized-source handling per implementation review
- fix(SPEC-1674): surface persisted oversized graph sources as validate warnings
- fix(SPEC-1674): thread oversizedSources through the build result, artifact, and query slice
- fix(SPEC-1664): include backtick in criterion identity punctuation normalization
- fix(SPEC-1661): guarantee cascade-hook wiring in lean release process
- fix(SPEC-1660): grandfather full-allowlist and dynamic-import violations
- fix(SPEC-1660): full allowlist, subpath fix, dynamic imports, exemption scope
- fix(SPEC-1660): grandfather existing layer-boundary violations
- fix(SPEC-1660): enforce merged layer and status-write import rules per scope
- fix(SPEC-1320): serialize legacy session writers behind the paired refresher
- fix(SPEC-1320): derive both session artifacts from one serialized active-spec snapshot
Refactoring
- refactor(SPEC-1663): relocate DurableJobRecord/SpecGraph/validation-evidence types into src/types
- refactor(SPEC-1663): rename divergent tools-cluster types off shared names
- refactor(SPEC-1663): figma cluster imports canonical types, renames divergent thumbnail/visual-qa shapes
- refactor(SPEC-1663): rename divergent ToolHandler/SkipReason/RollbackStep off shared names
- refactor(SPEC-1663): rename divergent compliance catalog types off shared names
- refactor(SPEC-1663): index.d.ts trio re-exports FileHash/FileMetadata/SpecAnnotation from types/
- refactor(SPEC-1662): readFileOrNull — migrate 4 sites found by strengthened meta test
- refactor(SPEC-1662): apply review fixes — enoent code check, meta-test coverage, comment cleanup
- refactor(SPEC-1662): readFileSafe family — consolidate into src/core/shared
- refactor(SPEC-1662): escapeRegex family — consolidate into src/core/shared
- refactor(SPEC-1662): escapeHtml — consolidate into src/core/shared
- refactor(SPEC-1662): fileExists/pathExists — consolidate into src/core/shared
- refactor(SPEC-1662): setup — create src/core/shared and allow engine/storage/tools to import it
- refactor(SPEC-1661): invert hook dispatch via injected handler; add layer-inversion tests
- refactor(SPEC-1661): invert dashboard status update via injected handler
- refactor(SPEC-1661): consolidate generateSpecId and spec-id schema in engine
- refactor(SPEC-1661): remove now-unused src/types/storage-bundle.ts
- refactor(SPEC-1661): break types->storage inversion in StorageBundle
- refactor(SPEC-1661): move InstallationRecord/InstallationManifest into types
Chores
- chore: scope mutation gate to mutated-range suites via dedicated vitest config
- chore(SPEC-1669/1670): record approval and implementing transitions
- chore(SPEC-1674): record done transition and release pending entry
- chore(SPEC-1674): transition to implementing
- chore(SPEC-1663): record done transition and session context
- chore(SPEC-1663): record implementing transition
- chore(SPEC-1662): record done transition and session artifacts
- chore(SPEC-1662): record implementing transition
- chore(SPEC-1664): record done transition and session artifacts
- chore(SPEC-1664): record implementing transition
- chore(SPEC-1661): record done transition and session artifacts
- chore(SPEC-1661): record implementing transition
- chore(SPEC-1660): record done transition and session artifacts
- chore(SPEC-1660): record implementing transition
- chore(SPEC-1660): reconcile ownership format and risk section for handoff gate
- chore: absorb post-done session state
- chore(SPEC-1320): record done transition
- chore(SPEC-1320): record implementing transition and fix stale verification command
[5.3.68] - 2026-08-28
Features
- feat(SPEC-1666): produce source-quality receipt pre-bump with fail-fast gate order
Bug Fixes
- fix(SPEC-1668): scope metric masking, byte-equality guard and uniform anchors per dual review
- fix(SPEC-1668): bind product-proof bump regeneration fields and harden fixture commit retry
- fix(SPEC-1666): align release-pipeline recovery suite with bump-neutral receipt contract
- fix(SPEC-1666): byte-preserving carrier normalization with derivation checks and mode-bound masking
- fix(SPEC-1315): classify degraded reads in portable spec-path migration
- fix(SPEC-1315): verify canonical root and trigger migration on lifecycle reads
- fix(SPEC-1315): keep spec paths portable across worktrees and release clones
Chores
- chore: absorb post-done session state
- chore(SPEC-1668): record done transition
- chore(SPEC-1668): record approval transition
- chore(SPEC-1666): record done transition
- chore(SPEC-1666): record implementing transition
- chore(SPEC-1315): record done transition and session state
- chore(specs): approve SPEC-1660..1664 with reviewer and discovery evidence
[5.3.67] - 2026-08-28
Bug Fixes
- fix(SPEC-1214): make readiness executable-evidence fallback reachable outside planu/specs
- fix(SPEC-1214): align readiness and validation on one executable-evidence contract
- fix(SPEC-1306): forward caller cwd as explicit projectPath in CLI status
Chores
- chore(SPEC-1315): transition to implementing
- chore: mark SPEC-1306/SPEC-1214 done and file SPEC-1664 dogfood bug
[5.3.66] - 2026-08-28
Bug Fixes
- fix(SPEC-1314): distinguish registry metadata from publish manifests in privacy gates
[5.3.65] - 2026-08-28
Bug Fixes
- fix(SPEC-1655,SPEC-1656,SPEC-1657): normalize persisted architecture, delegate lifecycle git shim, tighten agent-spec detection
[5.3.64] - 2026-08-27
Bug Fixes
- fix(SPEC-1264): merge shared implementation-review adapter with arbitrated fixes
- fix(SPEC-1257): merge post-transition observability drain with arbitrated fixes
- fix(SPEC-1264): apply arbitrated dual-review fixes
- fix(SPEC-1294): merge grounded execution plans with arbitrated dual-review fixes
- fix(SPEC-1294): apply arbitrated dual-review fixes
- fix(SPEC-1264): unify implementation-review verification behind one shared adapter
- fix(SPEC-1257): isolate postcommit and cascade launches from request scope, drain on stdio shutdown
- fix(SPEC-1329): merge grounded challenge capability gates with review fix round
- fix(SPEC-1329): widen outbound-call detection and drop narrative comments
- fix(SPEC-1294): ground execution plans in approved contract and preserve foreign plans
- fix(SPEC-1329): gate challenge templates on positive capability evidence
- fix(SPEC-1301): route every CLI json-mode result through one shared writer
- fix(SPEC-1652): reject title-less create_spec input before path redaction
- fix(SPEC-1301): emit one structured JSON document in CLI global json mode
Chores
- chore(SPEC-1257): record implementing transition
- chore(SPEC-1329): record implementing transition
- chore(planu): record SPEC-1652 and SPEC-1301 done transitions
- chore(SPEC-1294): record implementing transition
- chore(SPEC-1294): record approval transition
- chore(planu): move SPEC-1652 and SPEC-1301 to implementing
- chore(planu): approve SPEC-1652 and discard SPEC-1653 with codex evidence
- chore(planu): rescope SPEC-1652 after dual review and file SPEC-1654 dogfood bug
[5.3.63] - 2026-08-27
Bug Fixes
- fix(SPEC-1644): stop emitting the default architecture rule and every line-cap instruction
- fix(SPEC-1643): remove the empty typescript-patterns builtin skill
- fix(SPEC-1371): compute branch cleanup against main with literal protected matching
- fix(SPEC-1646): discriminate contradiction findings by offending criterion
- fix(SPEC-1646): discriminate contradiction findings by offending criterion
- fix(SPEC-1645): widen the load-bearing separator class per dual review
- fix(SPEC-1645): stop treating load-bearing as a scale signal
Chores
- chore(planu): file goal stop-hook loop dogfood bug
- chore(SPEC-1644): record done transition
- chore(planu): file SPEC-1651 and SPEC-1652 dogfood bugs
- chore(SPEC-1644): record approved status
- chore(SPEC-1643): mark acceptance criteria done
- chore(SPEC-1643): lifecycle transition to approved
- chore(planu): record SPEC-1371 approval and SPEC-1649 filing
- chore(SPEC-1646): record approval transition
- chore(SPEC-1645): record done transition
[5.3.62] - 2026-08-26
Bug Fixes
- fix(SPEC-1639,1640,1641,1642): four dogfood defects in challenge, gates, coverage and sync
Chores
- chore(planu): close SPEC-1639, SPEC-1640, SPEC-1641 and SPEC-1642
[5.3.61] - 2026-08-26
Refactoring
- refactor(SPEC-1636): remove two unenforced agent rules and migrate their conventions
- refactor(SPEC-1638): delete orphaned config assets and dead type modules
Chores
- chore(SPEC-1636): close spec with dual-provider implementation review evidence
- chore(SPEC-1636): approve after five-round dual-provider review
- chore(SPEC-1638): record done-state lifecycle artifacts
- chore(SPEC-1638): qualify the ios template path in canonical scope
- chore(SPEC-1638): declare executable scenarios for the compliance runner
- chore(SPEC-1638): mark acceptance criteria done after verified implementation
[5.3.60] - 2026-08-26
Bug Fixes
- fix(SPEC-1634): normalize scenario test-link descriptions across colon spacing
- fix(SPEC-1634): accept path-shaped colon forms in scenario tests entries
- fix(SPEC-1633): point the documented human validation gate at validate:full
Refactoring
- refactor(SPEC-1633): dedupe validate against check:strict in the release plan
Chores
- chore(planu): close SPEC-1633 and SPEC-1634
- chore(SPEC-1633,SPEC-1634): normalize file ownership and risk sections for the handoff gate
- chore(SPEC-1633,SPEC-1634): approve both specs with challenge resolution
[5.3.59] - 2026-08-26
Bug Fixes
- fix(SPEC-1631): report graph coverage as unavailable instead of zero gaps
Chores
- chore(planu): close SPEC-1631
- chore(planu): record SPEC-1631 implementing transition
[5.3.58] - 2026-08-26
Bug Fixes
- fix(SPEC-1317): assert the dynamic-import edge for the pending-release helper
- fix(SPEC-1319): close review findings on enricher integrity wiring
- fix(SPEC-1317): align doctor deep-check count with the installation-integrity check
- fix(SPEC-1319): block stale review-enricher runtimes from truncating canonical specs
- fix(SPEC-1317): diagnose and recover incomplete CLI installs without crashing planu status
Refactoring
- refactor(SPEC-1319): move enrichment integrity validator to a neutral module
- refactor(SPEC-1317): extract pending-ledger rewrite to satisfy the function-length gate
Chores
- chore(planu): close SPEC-1317 and SPEC-1319
- chore(SPEC-1319): integrate review-enricher integrity and stale-dist guard
- chore(SPEC-1317): integrate incomplete-install doctor and release-metadata degradation
- chore(planu): record SPEC-1317 implementing state
- chore(planu): record SPEC-1319 implementing and fix SPEC-1317 files ownership
[5.3.57] - 2026-08-26
Bug Fixes
- fix(SPEC-1316): stop non-array ledgers and silent reachability failures from losing pending releases
- fix(build-freshness): stop bricking a legit checkout when git is unavailable
- fix(build): reject stale local dist before dispatch (SPEC-1318)
- fix(build-freshness): allow diff-clean commits past the build stamp
- fix(release): classify pending releases by git reachability (SPEC-1316)
- fix(build): support reftable HEAD and tolerate a dirty-build-then-commit push
- fix(release): close three fail-open gaps in pending-release reconciliation
- fix(build): treat uncompiled TypeScript execution as not-applicable
- fix(release): classify pending releases by git tag reachability, not date
- fix(build): reject stale local dist output before CLI/MCP dispatch
Chores
- chore(planu): close SPEC-1316 and SPEC-1318
- chore(planu): add executable scenarios to SPEC-1316/1318 and file SPEC-1631
- chore(planu): record SPEC-1316/1318 implementing transitions
- chore(planu): add missing Create subsection to SPEC-1316 files ownership
- chore(planu): approve 5 more specs after adding implementation contracts and test-break evidence
- chore(planu): approve 6 reviewed specs, discard 2 stale after independent review
- chore(planu): discard 9 speculative feature specs and 5 already-fixed gate specs
- chore(planu): session checkpoint after v5.3.56
[5.3.56] - 2026-08-25
Bug Fixes
- fix(tests): anchor the revert-proof fixture to a pushed pre-guard tag
- fix(release): name the failing command and its real termination cause
- fix(release): name the blocking effect and fail closed on a broken tag lookup
- fix(release): re-anchor a superseded recovery ledger instead of dead-ending
- fix(worktree): reclaim content-equivalent worktrees and read the canonical branch
Chores
- chore(planu): close SPEC-1626
- chore(planu): close SPEC-1630
- chore(planu): close SPEC-1625
- chore(planu): close SPEC-1624, file SPEC-1629 transition-log rotation
- chore(planu): file SPEC-1625 and SPEC-1626 release-pipeline dogfood bugs
[5.3.55] - 2026-08-25
Bug Fixes
- fix(update-status): classify git-status degradation in spec artifact guard
- fix(worktree): drop only proper ancestors when eliminating base candidates
- fix(challenge): stop telling users to record accepted-risk evidence
- fix(worktree): validate worktree base against the canonical branch
- fix(gates): surface schema blockers in dod-gate rejections
- fix(contradiction-checker): close Path B on the criterion, not the scope
- fix(cli): add package-handoff command and honest EISDIR blocker
- fix(contradiction-checker): require predicate-position action assertion
- fix(spec-format): anchor single-line GIVEN/WHEN/THEN criterion regex
- fix(reconciliation): refresh stored title on the forward reconcile route
- fix(challenge-spec): stop reading a negated word as risk acceptance
- fix(cli): forward SDD evidence flags from spec status to the canonical mapping
- fix(update-status): refresh stored title from rewritten frontmatter
- fix(challenge): close resolution bullets on blank line
- fix(challenge): match resolution evidence against finding text
- fix(challenge): scope networkApi to a proximity-guarded bare API token
- fix(storage): stream transition-log reads to survive oversized lines
- fix(challenge): stop affirming capabilities from finding-field narration
- fix(update-status): discard a spec whose artifact is absent
- fix(validate): report unresolvable test links as unverifiable, not missing
- fix(update-status): drop the narrative JSDoc from the spec-artifact gate
- fix(update-status): refuse implementing transition on uncommitted spec.md
- fix(update-status): name the challenge-resolution ingress in gate blockers
Refactoring
- refactor(contradiction-checker): drop rationale comments in favor of names
Chores
- chore(planu): file SPEC-1624, clear integrated worktrees
- chore(planu): refresh session context
- chore(planu): refresh session context and release ledger
[5.3.54] - 2026-08-25
Bug Fixes
- fix(worktree): drop only proper ancestors when eliminating base candidates
- fix(challenge): stop telling users to record accepted-risk evidence
- fix(worktree): validate worktree base against the canonical branch
- fix(gates): surface schema blockers in dod-gate rejections
- fix(contradiction-checker): close Path B on the criterion, not the scope
- fix(cli): add package-handoff command and honest EISDIR blocker
- fix(contradiction-checker): require predicate-position action assertion
- fix(spec-format): anchor single-line GIVEN/WHEN/THEN criterion regex
- fix(reconciliation): refresh stored title on the forward reconcile route
- fix(challenge-spec): stop reading a negated word as risk acceptance
- fix(cli): forward SDD evidence flags from spec status to the canonical mapping
- fix(update-status): refresh stored title from rewritten frontmatter
- fix(challenge): close resolution bullets on blank line
- fix(challenge): match resolution evidence against finding text
- fix(challenge): scope networkApi to a proximity-guarded bare API token
- fix(storage): stream transition-log reads to survive oversized lines
- fix(challenge): stop affirming capabilities from finding-field narration
- fix(update-status): discard a spec whose artifact is absent
- fix(validate): report unresolvable test links as unverifiable, not missing
- fix(update-status): drop the narrative JSDoc from the spec-artifact gate
- fix(update-status): refuse implementing transition on uncommitted spec.md
- fix(update-status): name the challenge-resolution ingress in gate blockers
Refactoring
- refactor(contradiction-checker): drop rationale comments in favor of names
Chores
- chore(planu): file SPEC-1624, clear integrated worktrees
- chore(planu): refresh session context
- chore(planu): refresh session context and release ledger
[5.3.53] - 2026-08-25
Bug Fixes
- fix(update-status): name the challenge-resolution ingress in gate blockers
Chores
- chore(planu): refresh session context and release ledger
[5.3.52] - 2026-08-25
Bug Fixes
- fix(deps): align hono override with the upgraded dependency
Chores
- chore(deps): batch patch and minor updates, hold stryker at 9.6.1
[5.3.51] - 2026-08-25
Bug Fixes
- fix(evidence-gates): derive rejection templates from the rejecting schema
Chores
- chore(planu): close SPEC-1578 and file SPEC-1601
[5.3.50] - 2026-08-24
Bug Fixes
- fix(response): render one icon and one emphasis span in reconcile and accuracy titles
[5.3.49] - 2026-08-24
Features
- feat(website): approved-contract redesign, GitHub Sponsors donation, clearer hero
Bug Fixes
- fix(website): allow self-hosted woff2 fonts in public asset inventory
[5.3.48] - 2026-08-24
Bug Fixes
- fix(spec-1600): recognize weakening-family verbs in scope contradiction detection
[5.3.47] - 2026-08-24
Bug Fixes
- fix(spec-1599): make handoff ownership and spec-review approval errors self-serviceable
Chores
- chore(planu): record SPEC-1599 done and file SPEC-1600 dogfood spec
[5.3.46] - 2026-08-24
Bug Fixes
- fix(spec-1285): meta filter sees backticked tool token; harden AC1 coverage
- fix(spec-1285): stop local privacy specs activating auth/meta challenge families
Chores
- chore(planu): record SPEC-1285 done and SPEC-1598 discarded (merged into SPEC-1285)
[5.3.45] - 2026-08-24
Bug Fixes
- fix(spec-1278): derive coherent challenge pass semantics from unresolved critical findings
- fix(spec-1326): prevent registry release language from activating web-auth challenge families
Chores
- chore(planu): record SPEC-1278 done state and file SPEC-1597 dogfood spec
[5.3.44] - 2026-08-24
Bug Fixes
- fix(spec-1596): align check-readiness validator test double with getSpecFresh
- fix(spec-1594): gate example-only PII identifiers behind boundary-aware collection cue
- fix(spec-1593): gate suppress-family verbs so no-op consequence criteria are not misflagged
- fix(spec-1595): make strict readiness report reflect edited spec body content
[5.3.43] - 2026-08-24
Bug Fixes
- fix(spec-1293): gate minimality install-command patterns by provenance/negation context
- fix(spec-1277): match PII vocabulary by identifier segments and exact equality
- fix(spec-1225): make formatSuccess idempotent to prevent double-wrapped success titles
- fix(spec-1299): scan only comment tokens for debt markers, ignore string literals
- fix(spec-1298): exclude generic test/path tokens from scope-boundary matching
[5.3.42] - 2026-08-23
Bug Fixes
- fix(spec-1310): resolve relative --project-path at CLI boundary before lifecycle delegation
[5.3.41] - 2026-08-23
Bug Fixes
- fix(spec-1591): recognize relax-family verbs in scope-contradiction noun-overlap guard
[5.3.40] - 2026-08-23
Bug Fixes
- fix(spec-1590): feed full multi-line BDD criteria to scope-contradiction check
Chores
- chore(planu): sync state after SPEC-1590 done
- chore(spec-1273): mark done and reconcile Files with regenerated artifacts
[5.3.39] - 2026-08-23
Bug Fixes
- fix(spec-1589): credit criteria whose acceptance-to-verification map test passes
- fix(spec-1273): expose request_changes and estimate on canonical MCP surface
Chores
- chore(planu): sync autopilot state for SPEC-1273/1589 done
- chore(spec-1556): discard as resolved by SPEC-1507
[5.3.38] - 2026-08-23
Bug Fixes
- fix(spec-1517): populate preflight guard map + fail-closed rot detector
[5.3.37] - 2026-08-23
Bug Fixes
- fix(spec-1561): replace non-portable grep -P health checks with pure-Node fastFindPatterns
[5.3.36] - 2026-08-23
Bug Fixes
- fix(spec-1566): admit bare build phase in release resume phasePattern
[5.3.35] - 2026-08-23
Bug Fixes
- fix(spec-1488): scope marker-declared path extraction to the path-list run after each marker
[5.3.34] - 2026-08-22
Bug Fixes
- fix(spec-1588): fail closed on unresolved placeholders in raw generator output
- fix(spec-1509): stop check_readiness false positives on error-outcome and clean criteria
- fix(spec-1551): derive Goal and User Outcome from first acceptance criterion
[5.3.33] - 2026-08-21
Bug Fixes
- fix(spec-1587): scope creation-time placeholder scan to standalone line content
- fix(spec-1586): harden scoreAmbiguity against tautological substring-pairs and unanchored markers
Chores
- chore(planu): sync autopilot state for SPEC-1586/1587
[5.3.32] - 2026-08-21
Bug Fixes
- fix(spec-1585): harden scope-boundary contradiction checker against topical false positives
[5.3.31] - 2026-08-21
Bug Fixes
- fix(spec-1584): exclude .claude/worktrees from Stryker sandbox to survive residual worktrees
Chores
- chore(planu): file SPEC-1584 (Stryker worktree dangling-symlink) draft
[5.3.30] - 2026-08-20
Bug Fixes
- fix(spec-1583): drop redundant access() precheck that TCC-fails website-proof
- fix(spec-1581): re-verify receipt+log integrity on evidence-only drift
- fix(spec-1581): done gate rebinds evidence-only traceability drift
Chores
- chore(planu): SPEC-1581 done + SPEC-1582 draft filed
[5.3.29] - 2026-08-20
Bug Fixes
- fix(spec-1580): macOS keychain set() self-heals with non-interactive security-CLI access
[5.3.28] - 2026-08-20
Bug Fixes
- fix(spec-1577): single universal TS-only release artifact, remove native crate
[5.3.27] - 2026-08-19
Bug Fixes
- fix(spec-1575): require clause to assert forbidden action for outOfScope contradiction
- fix(spec-1539): require real independent implementation-review before done
Chores
- chore(spec-1539-1575): close done ceremonies, reconcile specs, file SPEC-1576
[5.3.26] - 2026-08-19
Bug Fixes
- fix(spec-1569-1572): host-LLM legacy migration, gitignore allowlist, scope+section guards
Chores
- chore(spec-1569-1572): mark legacy-migration and guard specs done
[5.3.25] - 2026-08-18
Bug Fixes
- fix(spec-1562,1568): contain client output paths across all writers and default spec array fields
[5.3.24] - 2026-08-18
Bug Fixes
- fix(spec-1558): regenerate source-quality receipt bound to the amended release commit
- fix(spec-1553): declare attachedAt in the published validate output schema
- fix(spec-1553): name the receipt publication cause instead of one flat string
- fix(spec-1554): bound the Technical extractor to the section heading level
- fix(spec-1552): surface the stored rejection reason in done-drift diagnostics
- fix(spec-1549): resolve out-of-scope items from the spec document, not the cache
- fix(spec-1525): admit prose file paths outside src/ and tests/ without truncating them
- fix(spec-1540): scope the native lockfile mask to a version-controlled lockfile
- fix(spec-1524): bind the source-quality receipt to a mask-normalized tree digest
Chores
- chore(spec-1553): close lifecycle with reconciled scope and done evidence
- chore(spec-1524): close lifecycle with reconciled scope and done evidence
[5.3.23] - 2026-08-13
Bug Fixes
- fix(spec-1520): exclude paths whose only mention negates the work from grounded modify targets
[5.3.22] - 2026-08-13
Bug Fixes
- fix(spec-1523): bind isolated rebuild sidecar provenance to the build-source commit
- fix(spec-1521): pin native provenance across the lockfile-integrity amend
- fix(spec-1519): bound acknowledgement latency at a tail ceiling, not a bare SLO constant
- fix(spec-1518): scope PLANU_RELEASE_MODE out of the source-quality phase
- fix(spec-1518): scope release-build env out of the source-quality phase
- fix(deps): drop vulnerable extract-zip by forcing puppeteer-core 25
- fix(spec-1506,spec-1507): align release invariant and lint budget with shipped behaviour
- fix(spec-1506,spec-1507): correct native lockfile integrity and uncache every gate
[5.3.21] - 2026-08-12
Bug Fixes
- fix(spec-1499,spec-1500): portable path redaction and a cheap pre-flight gate
Chores
- chore(planu): refresh session context after SPEC-1505 intake
[5.3.20] - 2026-08-12
Bug Fixes
- fix(release): unblock validate and privacy gates for v5.3.20
- fix(spec-1495): ground the outOfScope recommendation in the spec document
- fix(spec-1483): fail the native build on a version-mismatched artifact
[5.3.19] - 2026-08-11
Bug Fixes
- fix(spec-1492): size release budgets to the longest child chain per test
- fix(spec-1492): coordinate release-harness spawn and test budgets
- fix(spec-1486): raise load-tolerant timeout budgets in script-gate and heartbeat tests
- fix(spec-1482): update validate.test.ts lint timeout and message assertions per review
- fix(spec-1482): honor mid-run lint evidence on timeout and right-size lint caps
Chores
- chore(spec-1492): record done transition with review and traceability evidence
- chore(spec-1486): record done transition with traceability and validation evidence
- chore(spec-1486): approve arbitrated script-gate timeout spec with dual-review evidence
- chore(spec-1486): add durable-job-heartbeat beforeAll hookTimeout reproducer
- chore(spec-1482): record done transition with traceability and validation evidence
- chore(spec-1482): approve arbitrated lint-gate timeout spec with dual-review evidence
[5.3.18] - 2026-08-11
Bug Fixes
- fix(spec-1476): phrase-bind data-consistency scenario signals and drop dead catalog
Chores
- chore(spec-1476): record done transition with validation and review evidence
- chore(spec-1476): approve spec with arbitrated dual-review evidence and start implementing
[5.3.17] - 2026-08-11
Bug Fixes
- fix(spec-1487): normalize spec paths in toRepoRelativePath per implementation-review arbitration
- fix(spec-1487): exclude Planu bookkeeping paths from traceability autofill and done drift gate
Chores
- chore(specs): record SPEC-1487 done transition
- chore(spec-1487): record implementation-review round and approved scope amendment
[5.3.16] - 2026-08-11
Bug Fixes
- fix(spec-1477): bound publication-window wait per implementation-review arbitration
- fix(spec-1477): publication window blocks same-identity lease supersession mid-receipt
Chores
- chore(specs): record SPEC-1477 done transition and file SPEC-1487 dogfood bug
[5.3.15] - 2026-08-11
Bug Fixes
- fix(spec-1403): apply implementation-review arbitration fixes
- fix(spec-1403): make destructive housekeeping report-only under typed authority
Chores
- chore(spec-1403): record done transition with arbitration evidence
[5.3.14] - 2026-08-10
Bug Fixes
- fix(spec-1481): bound trapped fixture life per implementation-review arbitration
- fix(spec-1481): harden stdio abort test vs load and de-vacuize pid asserts
- fix(spec-1466): apply implementation-review arbitration fixes
- fix(spec-1467): require positive integer pid in waitForPid per review arbitration
- fix(spec-1466): legalize test-evidence overlap in ownership gate and handoff agreement
- fix(spec-1467): harden timing-sensitive receipt and process-runner tests
Chores
- chore(specs): file SPEC-1484 durable heartbeat flaky test dogfood bug
- chore(specs): file SPEC-1483 stale native artifacts after release abort
- chore(specs): record SPEC-1481 done transition and file SPEC-1482 lint-gate bug
- chore(specs): file SPEC-1481 flaky stdio lifecycle test under full-suite load
- chore(specs): record done transitions for SPEC-1466/1467 and file SPEC-1480 debt spec
- chore(specs): record implementing transitions for SPEC-1466/1467 with handoff evidence
- chore(specs): approve SPEC-1466/1467 after round 2; file SPEC-1479
[5.3.13] - 2026-08-10
Bug Fixes
- fix(spec-1468): word-boundary guard on evidence marker truncation
- fix(lifecycle): evidence-only rebind + planu digest exclusion (SPEC-1468)
- fix(spec-1469): close path-echo exemption bypass found in implementation review
- fix(spec-quality): path-token guard in restatement check + actionable gate rejection (SPEC-1469)
Chores
- chore(spec-1468): record done transition lifecycle state
- chore(spec-1469): record done transition lifecycle state
- chore(planu): capture auto-generated session context
- chore(specs): move SPEC-1468/1469 to implementing
- chore(specs): approve SPEC-1468/1469 after round-2 dual review + arbitration
[5.3.12] - 2026-08-10
Bug Fixes
- fix(release): cap smoke retries at 3 attempts regardless of delay overrides
- fix(release): retry transient CLI smoke failures with backoff and per-attempt diagnostics
Chores
- chore(spec-1462): record done transition and release bookkeeping
[5.3.11] - 2026-08-09
Bug Fixes
- fix(update-status): stop fabricating spec reviewer evidence on review transition
Chores
- chore(spec-1464): mark done with validation and dual-review evidence
- chore(planu): SPEC-1464 approved after 3-round dual review; move to implementing
- chore(planu): session checkpoint after v5.3.10 release
[5.3.10] - 2026-08-09
Bug Fixes
- fix(orchestration): derive file-conflict ownership from persisted spec bodies (SPEC-1461)
Chores
- chore(spec-1461): mark done after validate 100/100 and dual review
- chore(spec-1461): sync spec v1.3.1 into branch and strip narrative comments
- chore(planu): SPEC-1461 lifecycle after dual review; file SPEC-1463/SPEC-1464
- chore(planu): file SPEC-1462 (transient smoke CLI failure) and record v5.3.9 release state
[5.3.9] - 2026-08-09
Bug Fixes
- fix(spec-format): reject prose bullets in Files-section ownership parsing
- fix(code-scanner): bound implementation-detection evidence to spec-owned paths
Chores
- chore(planu): record SPEC-1219 done transition and duplicate-cluster discards
[5.3.8] - 2026-08-09
Bug Fixes
- fix(spec-1460): exempt freshly published @planu/cli from the pnpm minimum-release-age gate
- fix(spec-1458): render index-only verification rows so the gate accepts its own output
Chores
- chore(planu): record SPEC-1460 done transition
- chore(planu): record SPEC-1458 done transition
- chore(planu): session checkpoint after v5.3.7 release
[5.3.7] - 2026-08-08
Bug Fixes
- fix(scope-boundaries): split sentences regardless of next-sentence casing
- fix(validate): fail lint on timeout and bound unbounded validate gates
- fix(spec-1450): anchor scope-contradiction substring checks to word boundaries
Chores
- chore(spec-1453): redact local home path from reproducer
- chore(planu): record SPEC-1449 and SPEC-1450 done transitions
- chore(spec-1450): integrate scope-contradiction matching after arbitrated review
- chore(spec-1449): integrate validate gate timeouts after dual-provider approve
- chore(specs): cut speculative scope from the skills backlog
- chore(spec-1449): approve after 6-round independent review + Discovery evidence
- chore(deps): override nanoid to >=3.3.17 for GHSA-2v37-7h3g-55p8
- chore(planu): sync session state after SPEC-1449/1450 review cycle
[5.3.6] - 2026-08-07
Bug Fixes
- fix(spec-1404): make filesystem hook watcher observation-only
- fix(spec-1427): recognize exposed/exposes as affirmative scope drift
- fix(spec-1427): stop scope-contradiction check from flagging boundary-preserving criteria
- fix(spec-1415): arbitrate independent Codex review, harden fence and marker matching
- fix(spec-1415): heal 35 truncated spec.md bodies with a one-shot script
- fix(spec-migrator): preserve actionable estimation during portable spec import
- fix(spec-1429): cover the two untested acceptance criteria and correct stale claims
- fix(tests): match CLAUDE.md's current canonical release gate commands
- fix(spec-format): stop discarding BDD criteria mixed with checklist bullets
- fix(challenge-spec): count the challenge gate requirement against distinct scenario names
Refactoring
- refactor(spec-migrator): extract importSpecEntry to satisfy max-lines-per-function
Chores
- chore(planu): redact absolute home path from public spec reproducers
- chore(planu): sync session state after SPEC-1403/1404 closure
- chore(spec-1404): mark done after independent implementation review
- chore(planu): move SPEC-1449/1450 to review with challenge resolution evidence
- chore(planu): file SPEC-1449/1450 dogfood bugs, sync session state
- chore(spec-1427): mark spec done and drop duplicate test ownership entry
- chore(spec-1415): reconcile Files scope for done gate, file SPEC-1447 dogfood bug
- chore(planu): approve SPEC-1415 after challenge/grounding gate fixes
- chore(planu): sync SDD lifecycle state for SPEC-1404/1415/1427, file SPEC-1445/1446
- chore(planu): mark SPEC-1429 and SPEC-1431 done, file SPEC-1443/1444
- chore(planu): sync session-context checkpoint
- chore(planu): close 8 verified-stale backlog specs
[5.3.5] - 2026-08-06
Bug Fixes
- fix(tests): make the spec-write guard test independent of git HEAD
- fix(lifecycle): close done-gate bypass, report digest drift and ship debate rules
- fix(reconcile): harden audit-cell escaping and fail-closed rollback (SPEC-1250)
- fix(spec-format): preserve wrapped BDD continuation lines in criterion identities (SPEC-1253)
Chores
- chore(planu): close SPEC-1250 with debate evidence, file SPEC-1424
- chore(planu): SPEC-1253 done with debate evidence
- chore(planu): file SPEC-1423 (done-gate revalidate reprocessing)
- chore(planu): file SPEC-1421 and SPEC-1422 from client dogfood report
[5.3.4] - 2026-08-06
Bug Fixes
- fix(deps): override js-yaml to patched versions for CVE-2026-59870
- fix(spec-format): keep rendered criteria BDD-executable after canonical parsing
- fix(spec-format): resolve rendered criteria through the canonical parser (SPEC-1410)
- fix(spec-quality): render and count every acceptance criterion (SPEC-1410)
- fix(planu): point SPEC-1405 verification map at the real test filename
- fix(spec-quality): stop shipping template filler and self-certifying spec sections (SPEC-1406)
- fix(drift): make follow-up spec id deterministic per parent spec (SPEC-1405)
- fix(drift): emit one drift event per project instead of one per spec (SPEC-1405)
Chores
- chore(planu): SPEC-1405 and SPEC-1406 done with debate evidence
- chore(planu): SPEC-1405 and SPEC-1406 implementing with packaged handoffs
- chore(planu): approve SPEC-1405 and SPEC-1406 with debate evidence, file SPEC-1410..1411
- chore(planu): file SPEC-1401..1409 from deep flow audit
- chore(planu): SPEC-1396 done with debate evidence, file SPEC-1397..1400
[5.3.3] - 2026-08-06
Bug Fixes
- fix(release): tolerate empty ff-behind mirror list under set -u
- fix(outbox): return a typed failure from delivery attempts for the reliability gate
- fix(git): close SPEC-1396 debate findings and record review evidence
- fix(git): never move the shared checkout from automatic paths (SPEC-1396)
- fix(outbox): address SPEC-1271 debate review findings
- fix(outbox): bounded fair durable spec.created recovery without blocking startup (SPEC-1271)
Chores
- chore(planu): file SPEC-1396 git-safety dogfood bug
- chore(planu): session checkpoint after SPEC-1271 cycle
- chore(planu): SPEC-1271 done with debate evidence, file SPEC-1395
- chore(planu): SPEC-1271 implementing with structured work plan, file SPEC-1394
[5.3.2] - 2026-08-06
Bug Fixes
- fix(tools): restore declared bump_spec_version runtime tool (SPEC-1254)
- fix(handoff): address SPEC-1255 debate review findings
- fix(handoff): allow test-only specs to produce unblocked handoffs (SPEC-1255)
Chores
- chore(planu): redact local paths from SPEC-1392 reproducer
- chore(planu): SPEC-1254 and SPEC-1255 done with debate-review evidence
- chore(planu): session checkpoint for debate-protocol batch
- chore(planu): approve SPEC-1254/1255/1271, file SPEC-1386..1391, add debate-review rule
- chore(planu): approve SPEC-1206 and SPEC-1250 with reviewer evidence, SPEC-1240 rework feedback
[5.3.1] - 2026-08-05
Bug Fixes
- fix(session-safeguard): abort detect via FETCH_HEAD, drop invalid push --ff-only, harden refs
- fix(session-safeguard): never autopush protected branches and detect pushed bump in release abort
Refactoring
- refactor(tests): split release-pipeline suite, harness cache, mirror auto-sync
Chores
- chore(planu): SPEC-1384 done state and SPEC-1385 dogfood bug spec
- chore(planu): SPEC-1379 done state
- chore(planu): split incidental session-context churn out of SPEC-1379 delta
- chore(planu): file SPEC-1381 challenge resolution, SPEC-1382 operator guides, SPEC-1383 validate budget dogfood specs
- chore(planu): SPEC-1378 done state and v5.3.0 session checkpoint
[5.3.0] - 2026-08-05
Features
- feat(watchers): ignore non-actionable root events in validation freshness watchers (SPEC-1340)
- feat(release): harden local release pipeline — auth preflight, receipt env isolation, publish retry, visibility wait (SPEC-1369)
Bug Fixes
- fix(release): accept npm 12 keyed pack JSON across release gates (SPEC-1339)
- fix(validator): stop marking provably implemented test-only criteria as indeterminate (SPEC-1367)
- fix(deps): raise brace-expansion and postcss transitive floors past advisories (SPEC-1338)
- fix(readiness): fail strict readiness when canonical BDD extraction returns zero criteria (SPEC-1321)
- fix(lifecycle): route implementation review digests to done gates without entering reconciliation (SPEC-1328)
- fix(privacy): redact minimality policy locators from persisted artifacts (SPEC-1334)
- fix(create-spec): remove hardcoded test-framework commands from generated specs (SPEC-1234)
- fix(challenge): preserve title evidence in event capability detection (SPEC-1235)
- fix(release): enforce proprietary license and canonical plugin tool parity (SPEC-1236)
Tests
- test(release): make release preflight/receipt regressions deterministic under full-suite load (SPEC-1207)
- test(release): reconcile full test suite with local-only release policy and rollback semantics (SPEC-1373)
Chores
- chore(deps): update 11 patch/minor dependencies
- chore(planu): close stale lifecycle for SPEC-1010/1011 tool-reliability specs and record SPEC-1010 tech debt
- chore(planu): file SPEC-1374/1375/1376 dogfood bug specs
[5.2.0] - 2026-08-04
Features
- feat(autopilot): refresh semantic index fire-and-forget on spec:created (SPEC-1345)
- feat(i18n): auto-detect and persist user locale (SPEC-1347)
- feat(spec-language): offer translation instead of rejecting non-English specs (SPEC-1342)
- feat(semantic-search): persist index with incremental updates (SPEC-1345)
Bug Fixes
- fix(storage): classify non-ENOENT failures in sync global-config read
- fix(status): prefer implementing work over review work in compact status (SPEC-1228)
- fix(challenge): stop handler names activating event scenarios across clauses (SPEC-1262)
Performance
- perf(core-bridge): route main-thread hot paths through native dispatch (SPEC-1344)
- perf(init-project): parallelize independent pipeline stages (SPEC-1343)
Chores
- chore(website): regenerate deterministic product proof
- chore(planu): close lifecycle for 8 specs done + SPEC-1368 bug spec + session checkpoint
- chore(planu): file SPEC-1367 dogfood bug spec (validate false-negative on test-only criteria)
- chore(planu): file SPEC-1366 dogfood bug spec and refresh session context
- chore(doctor): remove commercial remnants and deepen diagnostics (SPEC-1346)
- chore(planu): file SPEC-1365 dogfood bug spec (teamSuggestion recommends unregistered tools)
- chore(planu): session checkpoint after v5.1.1 release
[5.1.1] - 2026-08-04
Bug Fixes
- fix(release-harness): resolve published artifact from staged repack when publish has no tarball argv
- fix(release): stop CLI-guard stdout pollution, npm view array probe, and tarball-path publish leak
[5.1.0] - 2026-08-04
Features
- feat(lifecycle): automate done evidence pipeline end to end
Bug Fixes
- fix(update-status): make typed failure explicit at dod-gates catch sites
- fix(deps): patch hono, fast-uri, ip-address, and undici advisories via overrides
- fix(evidence-gates): derive contract example kinds from filenames
- fix(reverse-engineer): share walk-ignore list and add fast release-gate test lane
- fix(challenge): suppress ungrounded concurrency boilerplate in challenge_spec
- fix(update-status): report per-spec failure reasons in batch results
- fix(create-spec): guarantee spec.md write before reporting persisted
- fix(create-spec): release idempotency claim when create_spec fails before commit
- fix(release): accept npm 12 pack metadata
- fix(deps): patch transitive security advisories
- fix(privacy): redact minimality policy locators
- fix(lifecycle): route review evidence by target
- fix(readiness): unify canonical validation evidence
Chores
- chore(pnpm): disable modules purge confirmation for non-TTY automation
- chore(planu): session checkpoint before release
- chore(planu): close SPEC-1350 lifecycle state
- chore(planu): hand off freshness blocker
- chore(planu): checkpoint release handoff
- chore(planu): preserve native engine review state
- chore(planu): persist delayed challenge evidence
- chore(planu): recover delayed audit specs
- chore(planu): capture lifecycle dogfood failures
- chore(planu): persist release remediation handoffs
- chore(planu): approve final release blockers
- chore(planu): start dependency security remediation
- chore(planu): approve final security remediation
- chore(planu): checkpoint final release remediations
- chore(planu): start lifecycle routing implementation
- chore(planu): approve lifecycle routing remediation
- chore(planu): checkpoint release remediation specs
- chore(planu): track v5 release dogfood regressions
[5.0.0] - 2026-07-31
Breaking Changes
- Removed Planu commercial plans, license activation, trials, project/spec limits, daily commercial quotas, and the Lemon Squeezy entitlement surface.
- All local tools are available without payment under the Planu Proprietary Free-Use License. The official unmodified package may be used commercially or non-commercially with unlimited users and instances; the repository and TypeScript implementation remain private and proprietary.
- Removed the public license commands, entitlement fields, environment variables, and tier-based tool metadata. Consumers must remove those obsolete fields instead of relying on compatibility aliases.
- Removed the orphaned
product-intelligencepublic types and embedded telemetry/feedback project endpoints and credentials. Telemetry delivery now requires explicitPLANU_TELEMETRY_ENDPOINTandPLANU_TELEMETRY_TOKENconfiguration; remote feedback requiresPLANU_FEEDBACK_ENDPOINT.
Security and Distribution
- Preserved engineering budgets, hosted authentication and authorization, transport abuse controls, dependency-license auditing, model pricing, runtime timeouts, local usage health, and generic outbound webhooks.
- Added narrow, idempotent cleanup for obsolete commercial state and a forward Supabase migration that removes trial data without rewriting migration history.
- Hardened npm packaging to allow public
.d.tsdeclarations while rejecting implementation.ts, source maps, embedded sources, personal paths, and personal identity metadata.
Community
- Kept direct BTC, ETH, and SOL donations, sponsorship channels, testimonials, and the disabled-until-configured newsletter contract.
[4.14.1] - 2026-07-29
Bug Fixes
- fix(release): defer native install verification
- fix(release): make local artifacts authoritative
[4.14.0] - 2026-07-29
Features
- feat: make Planu local-first and harden release integrity
Bug Fixes
- fix(native): constrain napi generator compatibility
- fix(native): pin compatible napi code generator
- fix(release): validate rebuilt native artifacts
- fix(release): bump native build manifest
- fix(release): synchronize session context version
- fix: classify freshness degradation paths
- fix: make validation freshness deterministic
- fix: make transactional locks crash-safe
- fix: benchmark native runtime in worker threads
- fix: classify lock degradation paths
- fix: await init repository hook writes
- fix: make cross-process leases transactional
- fix: publish cross-process locks atomically
- fix: complete process cancellation before settling
[4.13.0] - 2026-07-27
Features
- feat(website): animate support journey
[4.12.3] - 2026-07-27
Features
- feat: add accessible donation beacon
[4.12.2] - 2026-07-27
Bug Fixes
- fix: restore dark language menu contrast
[4.12.1] - 2026-07-27
Bug Fixes
- fix: prevent personal metadata exposure (#62)
[4.12.0] - 2026-07-27
Features
- feat(website): add multichain donations (#61)
[4.11.20] - 2026-07-27
Bug Fixes
- fix(website): align desktop landing controls (#60)
- fix(release): bind reproducibility to annotated tags (#59)
Chores
- chore(planu): close SPEC-1155 lifecycle
[4.11.19] - 2026-07-27
Bug Fixes
- fix(website): repair responsive visual system (#58)
- fix(website): close production delivery gaps (#57)
Refactoring
- refactor(website): simplify landing around real evidence (#55)
Chores
- chore(planu): close SPEC-1153
- chore(planu): close SPEC-1151 lifecycle
[4.11.18] - 2026-07-26
Bug Fixes
- fix(security): remove exposed receipt from website
[4.11.17] - 2026-07-26
Bug Fixes
- fix: clear released specs from pending ledger
[4.11.16] - 2026-07-26
Bug Fixes
- fix: restore trustworthy maintenance audit gates
[4.11.15] - 2026-07-26
Bug Fixes
- fix: stabilize project graph freshness (#51)
[4.11.14] - 2026-07-25
Bug Fixes
- fix: parse canonical active spec status (#50)
[4.11.13] - 2026-07-25
Chores
- chore(deps): update ESLint to 10.8.0 (#49)
[4.11.12] - 2026-07-25
Bug Fixes
- fix(deps): remediate brace-expansion advisory
Chores
- chore(planu): close SPEC-1142 lifecycle
- chore(planu): close SPEC-1141 lifecycle
[4.11.11] - 2026-07-24
Bug Fixes
- fix: finalize release state reconciliation
- fix: preserve pnpm policy in Docker builds
Chores
- chore(deps): refresh routine dependencies
[4.11.10] - 2026-07-24
Bug Fixes
- fix: preserve verified release artifacts
Chores
- chore: harden release and state reconciliation
[4.11.9] - 2026-07-20
Bug Fixes
- fix: keep release session context current
[4.11.8] - 2026-07-20
Bug Fixes
- fix: make pre-commit checks fail closed
- fix: pin release-eligible transitive dependencies
- fix: sync release lockfile before build
- fix: stabilize quality gate execution
- fix: harden lifecycle and release reliability
[4.11.7] - 2026-07-18
Bug Fixes
- fix: harden shell execution paths
[4.11.6] - 2026-07-18
Bug Fixes
- fix: tighten SDD gates and release readiness
- fix: allow routine dependency drift during pre-push
Chores
- chore: finalize weekly debt spec state
[4.11.5] - 2026-07-18
Bug Fixes
- fix: close weekly technical debt backlog
[4.11.4] - 2026-07-18
Bug Fixes
- fix(planu): unblock challenge gate and record debt specs
- fix(release): harden local recovery environment
[4.11.3] - 2026-07-10
Bug Fixes
- fix(release): classify npm 404 visibility correctly
- fix(planu): harden release and grounded spec flow
[4.11.2] - 2026-07-10
Bug Fixes
- fix(specs): ground lifecycle output and adopt TypeScript 7
Chores
- chore(deps): update patch dependencies
[4.11.1] - 2026-07-09
Bug Fixes
- fix: benchmark representative graph sources
- fix: verify release lockfile with pinned pnpm
[4.11.0] - 2026-07-09
Features
- feat: add native project graph and value-only specs
Bug Fixes
- fix: stabilize native graph release benchmark
[4.10.12] - 2026-07-08
Chores
- chore(planu): mark SPEC-1116 done
[4.10.11] - 2026-07-08
Bug Fixes
- fix(validate): honor executable spec compliance score
[4.10.10] - 2026-07-08
Bug Fixes
- fix(create-spec): merge readiness-compliant spec generation
- fix(create-spec): generate readiness-compliant technical details
[4.10.9] - 2026-07-07
Bug Fixes
- fix: promote SPEC-1115 validation scorer evidence
- fix: merge SPEC-1115 validation scorer evidence
- fix(SPEC-1115): require complete traceability evidence
Chores
- chore: refresh native dependency lock metadata
[4.10.8] - 2026-07-07
Refactoring
- refactor: merge SPEC-1113 native performance benchmark
- refactor: benchmark native mcp performance
Chores
- chore: exclude generated performance report
[4.10.7] - 2026-07-07
Bug Fixes
- fix(SPEC-1114): reduce MCP token waste
Chores
- chore(deps): update patch/minor dependencies
- chore(planu): clear released pending specs
[4.10.6] - 2026-07-07
Bug Fixes
- fix(SPEC-1111): stabilize update_status done gates and evidence state transitions
- fix(SPEC-1112): preserve validation-report lint evidence during done gate
Improvements
- refactor(SPEC-1110): reduce MCP token payloads with local-first tool classification
[4.10.5] - 2026-07-07
Bug Fixes
- fix(SPEC-1109): resolve audit backlog
[4.10.4] - 2026-07-06
Bug Fixes
- fix: resolve Supabase testimonials and Planu bug backlog
Chores
- chore(deps): update tsc-alias
- chore(planu): clear released pending specs
- chore(format): apply prettier baseline
[4.10.3] - 2026-07-02
Bug Fixes
- fix(SPEC-1106): reduce validate response duplication
- fix(SPEC-1106): harden critical fallback paths
[4.10.2] - 2026-07-02
Bug Fixes
- fix(SPEC-1105): preserve legacy spec ids during init migration
[4.10.1] - 2026-07-01
Bug Fixes
- fix: prevent generated spec artifacts and refresh graph status
[4.10.0] - 2026-07-01
Features
- feat(SPEC-1100): add reliable feedback sync
Bug Fixes
- fix(SPEC-1102): honor release preflight test skip
- fix(SPEC-1101): harden validate runtime and status
Chores
- chore(deps): refresh direct dependencies
[4.9.0] - 2026-06-30
Features
- feat(SPEC-1099): add structural memory layer
Chores
- chore(planu): clear released pending specs
[4.8.0] - 2026-06-24
Features
- feat(website): refine Planu landing
- feat(website): refine Planu landing
[4.7.5] - 2026-06-24
Features
- feat: add Planu minimal-change rule and guidance inspired by Ponytail
Bug Fixes
- fix: keep generated Planu session artifacts stable after lifecycle close
Chores
- chore(deps): refresh push-gate dev dependency knip
[4.7.4] - 2026-06-23
Bug Fixes
- fix: implement SPEC-1091-1094 tech debt bundle
Chores
- chore(deps): refresh push-gate dev dependencies
[4.7.3] - 2026-06-19
Features
- feat: add reversible context compaction
Chores
- chore(deps): update patch and minor dependencies
[4.7.2] - 2026-06-16
Features
- feat(SPEC-1088): add policy-driven minimal implementation gate
Chores
- chore(deps): update patch/minor dependencies
[4.7.1] - 2026-06-12
Chores
- chore(planu): close stale SPEC-1084 metadata
[4.7.0] - 2026-06-12
Features
- feat(SPEC-1085): add project knowledge graph
Bug Fixes
- fix(security): override esbuild patched release
Chores
- chore(deps): refresh push-gate dependencies
[4.6.1] - 2026-06-12
Bug Fixes
- fix(SPEC-1086): handle Vitest 4 JSON paths in validate
[4.6.0] - 2026-06-11
Features
- feat(SPEC-1084): add token waste autopilot
Chores
- chore(deps): sync lockfile
- chore(deps): update patch dependencies
[4.5.0] - 2026-06-10
Features
- feat(create-spec): generate intent-grounded questions
Chores
- chore(deps): update release tooling
[4.4.3] - 2026-06-09
Features
- feat(SPEC-1081): add skill security scan gate
- feat(SPEC-1082): add implementation contract readiness
[4.4.2] - 2026-06-05
Bug Fixes
- fix: keep spec folders spec.md-only and store evidence externally
[4.4.1] - 2026-06-04
Bug Fixes
- fix: make validate spec-scoped and non-mutating
Chores
- chore(deps): sync lockfile
- chore(deps): update patch and minor dependencies
[4.4.0] - 2026-06-03
Features
- feat: add grounded SDD gates and evidence metrics
[4.3.24] - 2026-06-02
Chores
- chore(deps): align update check validation
[4.3.23] - 2026-06-02
Chores
- chore(deps): refresh direct dependencies
[4.3.22] - 2026-06-02
Bug Fixes
- fix: stop fabricating spec and test artifacts
[4.3.21] - 2026-06-02
Bug Fixes
- fix: enforce canonical spec ids and harden fallback specs
[4.3.20] - 2026-05-27
Bug Fixes
- fix(SPEC-1073): make lifecycle state writes idempotent
[4.3.19] - 2026-05-27
Bug Fixes
- fix(SPEC-1072): clean spec advisory surfaces
[4.3.13] - 2026-05-25
Bug Fixes
- fix(ci): scope release shasum extraction
[4.3.12] - 2026-05-25
Bug Fixes
- fix(release): avoid self-referential tarball sha
[4.3.11] - 2026-05-25
Bug Fixes
- fix: close critical Planu delivery specs
[4.3.9] - 2026-05-25
Tarball SHA-256: a47146af1f2f8e695247fb6ee92cc8da8de00b2ab7967734a7faade7f3659aeb
Bug Fixes
- fix: keep MCP stdio output JSON-only
Chores
- chore: sync release banner version
[4.3.5] - 2026-05-24
Features
- feat(codegraph): expose Colby CodeGraph setup and status tools on the official MCP surface
Bug Fixes
- fix(create-spec): render structured post-creation suggestions as readable next steps
- fix(mcp): guard malformed human-facing tool output before it reaches clients
[4.3.4] - 2026-05-22
Tarball SHA-256: e1ac042fd623c1421d7a0788fed14c369472489180ffe80eb8bce4d422d360d8
Bug Fixes
- fix(planu): keep host adapters outside managed state
[4.3.3] - 2026-05-22
Tarball SHA-256: d681d7d176a263f3b059c4ed5fbc7647a17758dc3c56cc79fd47658bab082fe6
Bug Fixes
- fix(planu): expose update_status routing evidence
[4.3.2] - 2026-05-22
Tarball SHA-256: 7732de964d5e10d24bdab5ea79baee3d281654cf5caff1f713671502c8e09ee3
Bug Fixes
- fix(security): enforce moderate vulnerability gate
[4.3.0] - 2026-05-22
Tarball SHA-256: ebc3e7fe0a284d6ba6062dfb9aab41fe6e9396a7763c6d39764d676d20a0b6c3
Features
- feat(planu): enforce BDD SDD evidence gates
[4.2.6] - 2026-05-22
Tarball SHA-256: 07356a69166b2f47742118dcf06af14a105a44bb27024d6e28213c433530089e
Bug Fixes
- fix(docker): restore Railway Rust build inputs
[4.2.5] - 2026-05-22
Tarball SHA-256: 24d98e6b384752a806fc97a9828afaa94a0281a077e99ff06923e46119a69422
Features
- feat(planu): export reviewer gates to project rules
[4.2.4] - 2026-05-22
Tarball SHA-256: 963c0c81820ad002206299f102fdcae6635d96cdbe2e602e4f1dbb2d1b41e0c5
Features
- feat(planu): require spec reviewer before approval
[4.2.3] - 2026-05-22
Tarball SHA-256: 6d23ef6f7bd12e2a94eb9984e272beb37cd0d9b54ad12170529f95ca870e46a4
Features
- feat(planu): require implementation reviewer gate
[4.2.2] - 2026-05-21
Tarball SHA-256: 83193f54dc2fc5f461ef38b8bf2a9931d5d587ece50c77836942351e39b3c415
Bug Fixes
- fix(release): isolate npm publish cache
- fix(release): sync native lockfile without moving dev dependencies
- fix(ci): harden dependency freshness parsing
[4.2.1] - 2026-05-21
Tarball SHA-256: 9ff8a396e25eba3e4941bbef80ee19cc41bae46eaafa703cd32092c7ffbfdf2e
Bug Fixes
- fix(release): add windows native core packages
[4.2.0] - 2026-05-21
Tarball SHA-256: d036f3d5f73279fc0a12935995f899950fdf06afe454bba49da748183e07f477
Features
- feat(onboarding): add new project technology contract
Bug Fixes
- fix(release): sync native package versions
[4.1.4] - 2026-05-21
Bug Fixes
- Centralize Rust-first hot-path fallback behavior in
core-bridgeso callers use native acceleration when available and TypeScript fallbacks consistently when unavailable. - Keep crash scanning, broad validation reads, gaps log verification, HMAC signing, duplicate detection, and layer scanning resilient when native reads return partial results or test doubles expose older nullable bridge behavior.
- Lock published native optional dependencies across macOS and Linux architectures in
pnpmso release dependency checks remain cross-platform stable.
Tests
- Re-run the full suite with 31,275 passing tests and 5 skipped tests.
[4.1.3] - 2026-05-21
Bug Fixes
- Make the TypeScript file watcher fallback portable across operating systems by avoiding non-portable recursive
fs.watchmode. - Keep the native-core fallback path non-fatal when a platform-specific binary is unavailable.
Tests
- Add coverage to prevent reintroducing recursive watcher mode in the portable fallback.
[4.1.2] - 2026-05-21
Bug Fixes
- Remove unused legacy Planu files from the runtime surface and keep license tool registration strict.
- Restore missing OAuth MCP registrations for
start_oauth_flow,oauth_status, andconfigure_oauth. - Harden generated Git hooks so changed-file JSON generation avoids awk portability failures and integer parsing warnings.
Tests
- Add hook-generation coverage for portable post-commit changed-file handling.
[4.1.1] - 2026-05-21
Features
- Enforce dependency freshness as a blocking pre-push gate for lockfile drift, high/critical vulnerabilities, and outdated direct dependencies.
- Add the same pnpm dependency freshness guard to Planu-generated pre-push hooks.
Tests
- Add coverage for the dependency freshness script and generated hook contents.
[4.1.0] - 2026-05-21
Features
- Enforce English-only persisted Planu artifacts across specs, skills, agent instructions, and rules.
- Gate host-aware init scaffolding for
AGENTS.md,CLAUDE.md, Cursor, Windsurf, Cline, Gemini, Codex, and OpenCode generated AI docs. - Keep user-authored host file content intact while validating only Planu-owned generated blocks.
Tests
- Add coverage for skill, rule, and agent instruction language gates across core writers and host generators.
[4.0.0] - 2026-05-20
Tarball SHA-256: 8c00d74f48ed5614197000a967b103cc17653150aadf876fcfd18d0174263017
[3.9.12] - 2026-05-19
Tarball SHA-256: cd07a22fdfc0c982726a918c1e47f147ca300ecad710e8377f1751ef993fea60
Bug Fixes
- fix(specs): purge legacy spec artifact writers
Chores
- chore(claude): reconcile typescript skill asset
- chore(claude): remove unavailable skill artifact
[3.9.11] - 2026-05-17
Tarball SHA-256: a201430a93ae5f87af8322409c328266c29b340e890eb2fa49c7181da32886d3
Bug Fixes
- fix(types): keep duplicate export gate deterministic
- fix(release): prevent banner and project id drift
[3.9.6] - 2026-05-15
Tarball SHA-256: 56592815d33401b0cd7aa1d02ca26c7dda8dd131176841ccda3163932e53b43b
[3.9.5] - 2026-05-15
Tarball SHA-256: 11fa506c006e59292069158b32b580ab861cfb71ea5fefa60c5308fbf55b129a
Bug Fixes
- fix(website): sync release page metadata
[3.9.4] - 2026-05-15
Tarball SHA-256: 3134c2a699545d591999710da271b725a4d38c697756eced767971d02f9de62e
Bug Fixes
- fix(reconcile): enforce Claude asset cleanup gates
Chores
- chore(reconcile): remove stale Claude rules and skills
[3.9.3] - 2026-05-15
Tarball SHA-256: cc411a544962db6b38087b081ea847f73042f280d2ee9600c971cb1f2778db73
Bug Fixes
- fix(tests): update release smoke mocks for pnpm dlx
- fix(release): smoke test scoped cli with pnpm dlx
[3.9.2] - 2026-05-15
Tarball SHA-256: 3768f401213d28afacbca964d7318d079e92d5f4d454b78705f9995c272034ac
Bug Fixes
- fix(release): allow own native core packages in license audit
- fix(tests): stabilize release preflight checks
- fix(release): support lock fallback without flock
- fix(specs): enforce English structured spec generation
- fix: stabilize mcp slim test suite
[3.9.0] — 2026-05-12 — Single official SDD MCP surface
Changed — Planu now exposes one focused MCP surface
Planu no longer presents a large tiered MCP tool catalog to the agent. The official MCP server now exposes exactly the 14 tools needed for the end-to-end SDD loop: planu_status, facilitate, init_project, clarify_requirements, create_spec, challenge_spec, check_readiness, update_status, package_handoff, validate, reconcile_spec, create_rule, create_skill, and skill_search.
Advanced capabilities remain available internally, through CLI workflows, and through skills where appropriate, but they are no longer part of the default MCP tool list. This makes Planu lighter, cheaper in tokens, and easier for agents to use correctly.
Fixed — MCP startup and tool-list stability
- Added a canonical
registerSddToolsMCP registration path instead of loading every tool group and filtering afterward. - Removed the old full/slim MCP split and the related tool-list compacting layer.
- Updated smoke coverage so
tools/listmust match the official 14-tool contract exactly. - Bootstraps prompt handlers before transport connection so the MCP server can register UX surfaces safely after handshake.
Verification
pnpm build:ts✓- ESLint on touched files ✓
pnpm vitest run tests/smoke.test.ts✓ 10/10
[3.8.0] — 2026-05-07 — SPEC-1012 release-spec-closer
Fixed — Sovereign-orchestrator gap: specs released to npm stayed in implementing indefinitely
SPEC-1007 was released as v3.3.0 but its status frontmatter stayed implementing for 4 minor versions (3.4.0 → 3.7.0) until manually corrected. Planu now closes the loop: any chore(release): bump vX.Y.Z commit on main that references SPEC-NNN IDs auto-transitions those specs to done AND keeps the JSON store (specs.json) in sync — no more status.json ↔ spec.md drift across releases.
Added
src/engine/release-pipeline/parse-spec-refs.ts— pure, ReDoS-safe parser. Walks line-by-line to mask fenced code blocks (handles unclosed fences from CI-truncated logs), then masks inline backticks. SupportsSPEC-NNN,[SPEC-NNN],(SPEC-NNN), comma-separated, lowercase. Dedupes + uppercases output.src/engine/release-pipeline/release-spec-closer.ts—closeSpecsOnReleasePublish({ commitSha, version, projectPath }). Gates: (1)merge-base --is-ancestor origin/mainso feature-branch SHAs cannot force-close specs, (2) idempotent skip for already-done/discardedspecs. Writes are SPEC-720 sanctioned: spec.md viaatomicWriteFile+specStore.__internalSetStatusso JSON store stays synced.src/engine/drift-detection/release-status-drift.ts—detectReleaseStatusDrift(projectPath)walks last 50 commits on origin/main, parses SPEC IDs from release commits (requiresvX.Y.Zsigil — plainchore: refactordoes NOT match), cross-references vs spec frontmatter, returnsDriftReport[].applyReleaseStatusDriftFixfurther gates ongit tag --points-atpresence so only really-tagged commits trigger auto-close.- Tool wiring —
list_specs+planu_status(status-handler.ts) appendstaleStatusWarningsnon-blocking.housekeeping_sweepadds arelease-status-driftstep with auto-fix.scripts/release-local.shemitsplanu/data/release-events.jsonlafter publish for future async consumers.
Hardening (dual-Opus review fixes)
- Status frontmatter operations scoped to
findFrontmatterEnd()— never matches body prose likestatus: blockedin a code example. - History entries inserted at END of
## Historysection — chronological order preserved. ## Historyregex anchored to line start — prose mentioning## Historyno longer triggers in-place insert.- Quoted status values (
status: "implementing") round-trip cleanly tostatus: done. _skipFreezeCheckremoved — the closer never targets frozen specs, so the safety rail stays active.
Tests
- 91 tests pass across 11 test files (parse-spec-refs, release-spec-closer, idempotency, release-status-drift, housekeeping-sweep-release-drift, list-specs, status-handler, housekeeping-sweep).
- Coverage: BDD scenarios from spec — release auto-close, drift detection, idempotency, parser format coverage.
Validation
pnpm typecheck✓ ·pnpm lint✓ ·pnpm exec vitest run tests/engine/release-pipeline/ tests/engine/drift-detection/37/37 ✓ · existing tool tests 57/57 ✓.
[3.7.0] — 2026-05-07 — SPEC-1010 (PR-C)
Fixed — SSR back-migration cleanup, part C (SPEC-1010 PR-C) — stop writing legacy files
PR-A removed the leaked technicalPath from the create_spec response. PR-B routed 17 readers through readSpecTechnicalSection(). PR-C closes the loop: no code path now writes standalone technical.md / progress.md files. All technical and progress content lives inline in the unified spec.md under ## Technical and ## Progress sections.
Added
src/engine/spec-format/replace-section.ts— exportsreplaceSectionInSpec(specPath, sectionName, newBody)that:- Reads
spec.md. - Finds the named
##heading (fence-masked, CRLF-normalized — same hardening asextractSectionBody). - If found: replaces the body in place, atomic-writes back.
- If missing: appends the section to EOF, atomic-writes.
- Returns
{ replaced: boolean; appended: boolean }.
- Reads
- 6 new tests in
tests/engine/spec-format/replace-section.test.tscovering: replace-existing, append-when-missing, preserve-other-sections, idempotency, CRLF, fenced-code-block safety.
Changed — Writers redirected to the unified spec.md
src/tools/reconcile-spec.ts:163,191— bothatomicWriteFile(spec.technicalPath, ...)calls →replaceSectionInSpec(spec.specPath, 'Technical', ...).src/tools/spec-split-handler.ts:185-187— child specs no longer get a separatetechnical.md/progress.md. The synthesized childspec.mdcarries## Technicaland## Progressinline.src/tools/spec-portability-handler.ts:133— bundle import now writes## Technicalinto the imported spec.md instead of a siblingtechnical.md.src/tools/update-status/file-sync.ts:155-159— progress updates now mutate## Progressin spec.md.src/engine/living-spec-analyzer.ts:43-44—updateProgressFilerewritten to write into## Progressof spec.md.src/tools/heal-spec-docs.ts:300-341— heal regenerates the## Technicalsection inline; dry-run diff points at the unified file.src/engine/scan-project/index.ts— orchestrator no longer materializes 2-file structure; emits unifiedspec.mdper generated spec.src/types/spec-format.ts— addedReplaceSectionResultinterface.
Validation
grep "atomicWriteFile.*\.md\|writeFile.*\.md" src/confirms no remaining legacy-file writers.tsc --noEmit: 0 errors.eslint --max-warnings 0: 0 warnings.- 1047 tests pass (2 skipped, 0 fail) across 87 affected test files.
Deferred to PR-D
- Type-system cleanup (~252-file blast radius): drop
technicalPath/progressPath/fichaTecnicaPathfromSpec. Today these fields are kept populated for backwards compat with stored data; PR-D removes them entirely once all consumers stop reading them. storage/spec-store.tslegacy normalizer + autopilot migration log.- Init-project generator templates that still scaffold a 2-file structure (Level 3 in the original SPEC-1010 plan).
src/tools/export-spec.ts:121— uses a different wrapper (readFileContent); deferred to keep PR-C scoped.
[3.6.0] — 2026-05-07 — SPEC-1010 (PR-B)
Fixed — SSR back-migration cleanup, part B (SPEC-1010 PR-B) — 11 silent-degradation readers
The SSR back-migration in SPEC-752 (v2.4.0) folded technical.md into the unified spec.md as a ## Technical section, but 11 reader call sites in src/ still called readFile(spec.technicalPath, 'utf-8') to read technical content. For any spec created after v2.4.0, that file is empty/missing, silently degrading downstream analysis quality. PR-B introduces a single source of truth for "give me the technical body for this spec".
Added
src/engine/spec-format/read-technical-section.ts— exportsreadSpecTechnicalSection(spec)that:- Reads
## Technicalfromspec.md(the unified format). - Falls back to legacy
technical.mdonly when the unified section is empty (transitional safety net for pre-migration data). - Returns
""on any error — never throws.
- Reads
src/engine/spec-format/read-technical-section.tsalso exportsextractSectionBody(body, sectionName)— a regex-escaped section-body extractor reusable across the codebase.- 9 new tests in
tests/engine/spec-format/read-technical-section.test.tscovering: extraction, escape semantics, EOF handling, empty fallback, error fallback, and unified-wins-over-legacy precedence.
Changed — 11 reader call sites switched to the helper
src/tools/detect-ac-gaps.ts,src/tools/design-schema.ts,src/tools/challenge-spec-helpers.ts,src/tools/analyze-spec-dependencies.ts,src/tools/red-team.ts,src/tools/summarize-spec.ts,src/tools/snapshot-spec-hashes.ts,src/tools/define-ui-contract.ts,src/tools/generate-adr/helpers.ts,src/engine/spec-conflict-graph.ts,src/engine/spec-registry/scorer.ts.
Each call site now reads the ## Technical section from spec.md directly. This restores the technical-content signal for red_team, challenge_spec, analyze_spec_dependencies, summarize_spec, snapshot_spec_hashes, detect_ac_gaps, design_schema, define_ui_contract, generate_adr, conflict-graph computation, and spec-registry scoring.
Tests
- 4 existing test files updated to mock the new helper instead of the legacy
readFile(spec.technicalPath)pattern:tests/tools/challenge-spec-helpers.test.ts,tests/tools/design-schema-main.test.ts,tests/tools/generate-adr.test.ts,tests/tools/snapshot-spec-hashes.test.ts. - Full affected suite: 1012/1012 tests pass.
Hardened — Dual-Opus PR review follow-ups (SPEC-1010 PR-B)
- 6 additional readers in
src/engine/were missed by the initial sweep and would have continued the silent quality degradation. Now refactored to use the helper:src/engine/validator/extractors.ts— validator's spec-content extractionsrc/engine/validator/analyzer.ts— code-scan fallback for spec evidencesrc/engine/execution-plan/plan-utils.ts—readSpecContent()for execution planningsrc/engine/readiness-checker.ts— readiness-gate technical scoringsrc/engine/spec-quality-scorer.ts— quality scoring against technical contentsrc/engine/plan-mode/plan-builder.ts— plan-mode plan synthesis After this fix,grep "readFile.*spec\.technicalPath" src/engine/returns only the helper's own legacy fallback (line 36).
- Fenced-code-block hardening in
extractSectionBody: the regex now operates on a fence-masked variant of the body (preserving offsets) so a quoted markdown sample inside the spec body cannot match the heading regex nor the next-section terminator. Snapshot-spec-hashes is no longer at risk of silently tracking 0 files when a## Filesexample appears inside a fence in## Technical. - CRLF / mixed line endings normalized before scanning (Windows-authored specs).
- Legacy
technical.mdfallback strips YAML frontmatter before returning, matching what the unified## Technicalsection delivers (no leak ofid:/status:keys into downstreamkeyDecisionsextraction insummarize-spec). - 5 new tests covering: fenced-code-block false positives (heading + next-section), CRLF, ~~~ alternate fence syntax, legacy frontmatter strip.
- 7 additional test files updated for the engine readers' new mock seam.
Deferred to PR-C
- Level 1 — 5 writers:
heal-spec-docs.ts,reconcile-spec.ts(write paths),spec-split-handler.ts,init-project/migration-runner.ts,reverse-engineer/handler.tsstill write to standalonetechnical.mdin some flows. - Level 4 — typesystem: drop
technicalPath/progressPath/fichaTecnicaPathfrom the type surface (~252-file blast radius), plusstorage/spec-store.tslegacy normalizer + autopilot migration log. - Level 3 (templates) — init-project generator templates that still scaffold a 2-file structure.
src/tools/export-spec.ts:121still usesreadFileContent(spec.technicalPath)(different wrapper). Tracked for PR-C.
[3.5.0] — 2026-05-07 — SPEC-1010 (PR-A)
Fixed — SSR back-migration cleanup, part A (SPEC-1010)
The SSR back-migration in SPEC-752 (v2.4.0) folded technical.md / progress.md into spec.md as ## Technical / ## Progress sections, but left readers, writers, types, generators, and tool descriptions across the codebase still referencing the deprecated files. SPEC-1010 lands in three incremental PRs to keep blast radius manageable. PR-A (this release) ships the user-visible quick wins:
- Bug A —
create_specno longer leakstechnicalPathin the response payload. Thetechnical.mdfile is never written; the field would point at a non-existent path. InternalSpec.technicalPathis preserved temporarily for backwards compat with stored data; the field is removed in PR-C. - Bug C — section preservation in unified spec.md. When the user's description contains a
## Technicaland/or## Filessection,buildUnifiedSpecContentno longer appends a duplicate. The user's content wins; only the missing sections are injected. Fixes the symptom wherecreate_specproduced specs with two## Technicalsections (one user-authored, one autopilot-empty) or two## Filessections (autopilot suggestions clobbering the user's file list). - Level 3 (partial) —
.claude/rules/sdd-methodology.mdupdated to describe specs as a single unifiedspec.md(was: 2-file lean format). - Level 5 — tool descriptions cleansed of
technical.md/progress.mdreferences acrosssrc/tools/tool-registry/core-tools.ts,src/tools/tool-registry/group-integrations.ts,src/tools/register-spec-tools/core-spec-tools.ts,src/tools/register-spec-tools/analysis-tools.ts. LLMs reading tool metadata at session start now see the correct single-file format.grep -rn "technical\.md\|progress\.md" src/tools/tool-registry/ src/tools/register-spec-tools/returns zero.
Tests
- 5 new tests in
tests/engine/spec-format/unified-spec-builder.test.tscovering Bug C: user-authored## Technicalnot duplicated, user-authored## Filesnot clobbered, both-present case returns body untouched, partial-present injects only what's missing, and a fenced-code-block edge case where literal## Technical/## Fileslines inside a markdown sample no longer suppress auto-injection.
Hardened — Dual-Opus PR review follow-ups (SPEC-1010 PR-A)
- Stale doc references in
.claude/rules/sdd-methodology.md: removed two residual mentions oftechnical.md(the flow diagram on line 19 and the implicit-approval rule). The whole file now consistently describes the unified single-file format. Both reviewers (correctness + security) flagged this contradiction with 90–95 confidence. - Fenced-code-block hardening in
unified-spec-builder.ts:## Technical/## Filesheading detection now strips fenced code blocks (```and~~~) before scanning. This fixes a false-positive where a user description containing literal markdown samples (e.g. example specs) suppressed auto-injection of the missing sections. - Defensive regex escaping:
extractSection'ssectionNameparameter is now passed throughescapeRegexbefore being interpolated into the heading regex. Defensive hardening for future callers.
Deferred to PR-B / PR-C
- PR-B: Level 2 — unify the 14 spec readers behind a shared
readSpecTechnicalSection(spec)helper that extracts## Technicalfromspec.mdinstead of reading a non-existenttechnical.mdfile. Fixes silent-quality-degradation inred_team,challenge_spec,analyze_spec_dependencies,summarize_spec, etc. - PR-C: Level 1 (5 writers) + Level 4 (drop
technicalPath/progressPath/fichaTecnicaPathfrom the type system, ~252 file blast radius, plusstorage/spec-store.tslegacy normalizer + autopilot migration log) + Level 3 generator templates.
[3.4.0] — 2026-05-07 — SPEC-1011
Fixed — Four silent bugs in core tools (SPEC-1011)
Bug D — reconcile_spec silent write failure
reconcile_spec was incrementing the version counter and reporting success even when no text changes reached spec.md on disk. The tool now delegates actual body text replacement to src/engine/reconcile/apply-changes.ts (applyChangesToSpec), then immediately re-reads the file via src/engine/reconcile/verify-write.ts (verifyWriteSucceeded). If verification fails, the tool returns isError: true with { postWriteVerificationFailed: true, specUpdated: false, rolledBack: true } and the version counter is NOT saved.
Bug E — create_spec injects unrelated autopilot-guessed file paths into ## Files
create_spec was always passing autopilot-suggested file paths to generateLeanTechnicalContent, populating ## Files with unrelated paths even when the user's description contained no ## Files section. The guard const descriptionHasFilesSection = /^##\s+Files\b/m.test(description) now gates injection — when absent, only (to be determined) placeholders appear. Suggested files are surfaced exclusively in the autopilotSummary.suggestedFiles response payload.
Bug F — planu_status / challenge_spec say "Project not initialized" despite planu/ existing
Both tools returned "Project not initialized" when knowledge.json was missing even if planu/ and data/projects/{id}/ existed on disk. A new src/storage/project-resolver.ts module exports resolveProjectFromPath(), which falls back to disk fingerprint detection (checks dataDir, planuDir, planu/status.json, planu/specs/). On recovery it writes a minimal knowledge.json and logs a silent autopilot entry. Both tools now call this resolver before returning the "not initialized" error.
Bug G — status.json shows stale spec counts while disk has many more
status.json totalSpecs and byStatus could fall arbitrarily out of sync with what's actually on disk. handlePlanStatus now fires-and-forgets reconcileStatusFromDisk() (new src/engine/status-reconciler/index.ts) on every call. The reconciler scans planu/specs/ directories, parses each spec.md frontmatter for status, and atomically rewrites status.json (tmp + rename) when counts diverge.
Added
src/engine/reconcile/apply-changes.ts—applyChangesToSpec(specPath, changes)→ApplyChangesResultsrc/engine/reconcile/verify-write.ts—verifyWriteSucceeded(specPath, changes)→VerifyWriteResultsrc/storage/project-resolver.ts—resolveProjectFromPath(projectPath)→ResolvedProject | nullsrc/engine/status-reconciler/index.ts—reconcileStatusFromDisk(projectPath),computeSpecCountsFromDisk(projectPath)src/types/reconcile.ts—VerifyWriteFailure,VerifyWriteResult,SkippedChange,ApplyChangesResult,StatusReconcileResult,ResolvedProject- 7 new test files:
tests/engine/reconcile/verify-write.test.ts,tests/tools/reconcile-spec.write-verification.test.ts,tests/tools/create-spec/no-file-injection.test.ts,tests/tools/create-spec/autopilot-analyzer.scope-anchored.test.ts,tests/storage/project-resolver.recovery.test.ts,tests/tools/status-handler.recovery.test.ts,tests/tools/challenge-spec.recovery.test.ts,tests/engine/status-reconciler/disk-sync.test.ts
Hardened — Dual-Opus PR review follow-ups (SPEC-1011)
After the initial implementation, a dual-Opus review on PR #17 surfaced two critical issues that are also fixed in this release:
- Section-anchored apply-changes:
applyChangesToSpecno longer usesString.replaceagainst the whole document. Each change is bounded by its named section heading (## <section>), and the change is applied only whenoriginalValuematches exactly once within that section's body. Ambiguous matches (>1 in section) and missing-section cases are recorded inskippedwith reason — no silent cross-section mutations. - Atomic JSON writer for status.json:
reconcileStatusFromDisknow uses the codebase'swriteJsonSafeprimitive (with backup rotation) instead of a hand-rolled${path}.tmp.${pid}+rename. Eliminates the same-PID collision risk for concurrent reconciler invocations. - ENOENT vs corrupt distinguished: the reconciler refuses to clobber a
status.jsonthat exists but cannot be parsed (permission/EIO/JSON syntax). User-set fields are preserved; user must repair manually or runinit_project. - Non-fatal skipped text changes: when
originalValueis not a literal in the section body (legitimate for conceptual/metadata-style changes like "scope expanded"),reconcile_specno longer errors — skipped entries surface instructuredContent.skippedTextChanges, and metadata-only manual changes still create a SpecVersion. versionRolledBackflag replaces the misleadingrolledBackflag on verification failure: the disk file was already written before verification ran; what we actually rolled back is the SpecVersion record, not the disk content.database: 'unknown'replaces the hardcoded'postgresql'fallback inresolveProjectFromPath's minimal-knowledge builder (zero-hardcoding compliance).projectId-aware reconciler:reconcileStatusFromDisk(projectPath, projectId?)accepts an optional explicitprojectId. Whenplanu_statusis invoked with an explicitprojectId, the resolver fallback and reconciler fire-and-forget are skipped to preserve the caller's "no path-hashing" contract.- Shared
RECONCILE_METADATA_SECTIONSconstant insrc/types/reconcile.ts, used by bothapply-changes.ts(skip) andverify-write.ts(skip). Adding a new metadata section now requires a single edit. - 8 new tests in
tests/engine/reconcile/apply-changes.test.tscovering section anchoring, ambiguity guard, missing section, cross-section safety, deep-heading bounds, metadata-skip, and read-failure paths. Plus 1 regression test intests/tools/reconcile-spec.test.tsfor the post-write verification failure path.
[3.3.0] — 2026-05-05
Changed — Project data dir anchored to absolute home (SPEC-1007)
projectDataDir(projectId) is now symmetric with globalDataDir: it returns an absolute path under ~/.planu/data/projects/{id} (override via PLANU_PROJECT_DATA_DIR), regardless of where the MCP server was launched from. The cwd-tolerant discovery added in v3.2.0 was a Phase 1 backwards-compatible patch; this release completes the architectural cleanup that v3.2.0 deferred.
- Absolute path by default:
src/storage/base-store.tsnow derives the project root fromprocess.env.PLANU_PROJECT_DATA_DIR ?? join(homedir(), '.planu', 'data'). Path-traversal (..,/,\\) onprojectIdthrows upfront. - Automatic legacy migration: new
src/storage/migrations/cwd-to-absolute.tsexposesmigrateLegacyDataDir(projectId, cwd?). Called idempotently fromloadAll(specs),getKnowledge/saveKnowledge, andinit_project. Walks up to 8 ancestors ofcwdlooking fordata/projects/{id}/knowledge.jsonandrenames the legacy tree into the absolute home. Cross-filesystem moves fall back tofs.cp+ anchor verify +rm -rf. Conflict (both legacy and absolute populated): legacy is renamed to<legacy>.legacy-{ISO_TS}and aconsole.warnis logged — never auto-merged. - Idempotency layers: an in-memory
Set<projectId>short-circuits same-session repeats; a.migrated-from-cwdsentinel file short-circuits cross-session. A sibling${absolute}.migration.lock(NOT insideabsolute, sorenamecan run) prevents concurrent migrations across MCP processes. - Test isolation: new
tests/setup.tsmkdtempsPLANU_PROJECT_DATA_DIRper-test for unit suites; e2e/integration/scripts suites are detected viaexpect.getState().testPathand own their own lifecycle untouched.PLANU_GLOBAL_DATA_DIRis only seeded if the test hasn't already set it.
Added
src/types/migration/cwd-to-absolute.ts—CwdMigrationStatus(noop|migrated|conflict|error) andCwdMigrationResult.migrateLegacyDataDir,clearMigratedThisSession,MIGRATION_INTERNALS— exported fromsrc/storage/migrations/cwd-to-absolute.tsfor callers and tests.tests/storage/migrations/cwd-to-absolute.test.ts— coverage of noop / migrated / conflict / idempotency / env override / invalid projectId paths.
Notes
- Backwards compatible: existing v3.2.x repos that already had cwd-relative
data/projects/{id}/trees are auto-migrated on the first read or write that touches that project. No manual step required.
[3.2.1] — 2026-05-05
Fixed — Spec migrator default + idempotency (SPEC-1008)
Two bugs in ssr_back_migration were leaving legacy technical.md files behind in client repos with many done specs:
- Default skip-done flipped to migrate-done:
ssr_back_migrationnow defaultsallowDoneSpecs: true. Repos with hundreds of done specs no longer require flag-flipping to clear legacy artifacts. Callers that need the old behavior can still passallowDoneSpecs: falseexplicitly. already_unifiedbranch deletes residual file: whenspec.mdalready contains## Technical,foldTechnicalIntoSpecnow also unlinks the residualtechnical.mdinstead of leaving it behind. The unlink is non-fatal (handles the case where the file was already removed manually).
This release was preceded by a one-time manual cleanup of 714 residual technical.md files in this repo (commit 82612a90). With these fixes, the migrator self-heals on every run.
[3.2.0] — 2026-05-05
Fixed — Project data dir resilience (7 bugs in one release)
When clients launched Planu from a directory other than the one used at init_project, the cwd-relative data/projects/{hash}/ lookup silently missed all existing project state — specs, knowledge, hooks, everything. The 7 reported symptoms shared one root cause and are now resolved end-to-end.
- Cwd-tolerant data dir discovery (Bug 3, 4, 6): new
src/storage/data-dir-discovery.tswalks up fromprocess.cwd(), then from the registeredprojectPath, anchored onknowledge.json(canonical ownership signal).getKnowledge,loadAll(specs), andhandlePlanStatusnow resolve project state regardless of where the MCP server was launched from. Cached per session for zero repeated I/O. Hash collisions in unrelated repos are ignored — only directories withknowledge.jsonqualify. - Ancestor-data detector for
init_project(Bug 1): newsrc/tools/init-project/ancestor-data-detector.tsscans up fromprojectPathandcwdfor existingdata/projects/<id>/dirs. When found, surfaces a warning telling the user their project state may be split — preventing silent state corruption wheninit_projectis run from a parent directory of an already-initialized project. - Ephemeral path filter for registry (Bug 2):
src/engine/data-projects-gc/pattern-matcher.tsnow matches/var/folders/,/private/var/folders/,/tmp/,/private/tmp/prefixes andplanu-*-(test|spec|e2e|integration|fixture)-*basenames.global-projects-store.getProjectsfilters ephemeral entries on every read and fires a background prune. The registry no longer accumulates test temp dirs. - Eager registry refresh on
register_project_path(Bug 5, 7): afteraddProject, the handler now invokeslistSpecs(entry.hash)(cwd-tolerant) and persists the realspecCount+lastScanAtimmediately. No more stalespecCount: 0after registration when specs already exist on disk.
Added
discoverProjectDataFile(projectId, relative, cwd?)— public helper for any future store that needs cwd-tolerant reads.clearDataDirCache()— test-only cache reset.detectAncestorDataDirs(projectPath, projectId, cwd?)andbuildAncestorDataWarning(report)— public helpers for the ancestor warning surface.isEphemeralPathPrefix(projectPath)— exported predicate for OS-managed temp prefixes.
Notes
- The architectural cleanup (anchoring
projectDataDirto an absolute path symmetric withglobalDataDir) is deferred to a dedicated SPEC + migration cycle in v3.3.0. The Phase 1 fix in this release is purely additive and backwards-compatible.
[3.1.6] — 2026-05-04
Fixed
create_specinfinite loop on payment/billing keywords:clarificationAnswerswas completely ignored because the parameter had an underscore prefix (_params), making it unused. Any description matching billing/webhook/Stripe would loop endlessly regardless of answers provided. Fix: passparamscorrectly and short-circuit clarification whenclarificationAnswersis non-empty.detectBroadScopefalse positive on Stripe integrations: Descriptions like "Stripe billing with webhook handler" matched 2 subsystem patterns (billing + notification/webhook) and incorrectly triggered clarification as "broad scope". Fix: scale the threshold with word count — descriptions ≥20 words require 3 subsystem matches instead of 2 (a single payment feature naturally mentions adjacent domain terms).
[3.1.5] — 2026-05-04
Changed
create_specclarification — zero hardcoding: removedgenerateInteractiveQuestionswhich produced pre-defined question templates with hardcoded options (billing model, payment provider, scope, etc.). When a description is too vague (needsClarification = true), Planu now returns a plain message telling the host LLM to ask its own contextual questions, then retrycreate_specwith the enriched description. The LLM determines what to ask — Planu no longer prescribes it.
[3.1.4] — 2026-05-04
Fixed
- "planu · failed" in Claude Code:
npx @planu/cli@latestruns theclibinary entry (dist/cli/index.js), not the MCP server entry (dist/index.js). When invoked with no arguments and piped stdin (MCP host context), the CLI entry now imports the MCP server module instead of printing help and exiting immediately.
[3.1.3] — 2026-05-04
Fixed
initializeresponse latency: Added asetImmediateyield afterselectTransportso Node.js processes the bufferedinitializerequest (stdin poll phase) before module loading begins (check phase). Previously, synchronous module evaluation blocked the event loop for ~3-4 s, delaying theinitializeresponse and causing "Failed to reconnect" in Claude Code even after the handshake-gate fix in v3.1.2.
[3.1.2] — 2026-05-04
Fixed
- MCP protocol ordering: Tool/resource notifications are now deferred until after the MCP handshake completes (
initializeresponse +notifications/initializedfrom client). Previously, 9 dynamic imports fired ~1.5 s of file I/O before stdin was drained, causing Claude Code to receive hundreds ofnotifications/tools/list_changedevents before theinitializeresponse — violating the MCP protocol and preventing Planu from loading. AhandshakeGatePromise now holds all module loading untilserver.server.oninitializedfires (10 s timeout fallback).
[3.1.1] — 2026-05-04
Fixed
- MCP SDK invariant: Tools are now registered before the transport connects. The previous async-deferred approach (SPEC-1005) violated the MCP SDK rule that forbids calling
server.tool()aftertransport.connect(), causingtools/listto returnMethod Not Foundon fresh installs. - Rust facilitate tools: Removed lingering
.awaitcalls onhandle_facilitate,handle_challenge_spec,handle_check_readiness, andhandle_reconcile_specafter they were rewritten as sync functions (no Anthropic API calls).
[3.1.0] — 2026-05-04
Fixed — Native build is reproducible again
- lib.rs ghost modules removed: the previous
v3.0.0commit declared 39pub modsubmodules that did not exist as files, leaving the Rust crate impossible to rebuild from source (30 compile errors). The shipped.nodeonly worked because it was compiled before the bad commit. The submodule declarations have been removed. - napi_bridge restored: the
#[napi]macro layer was missing entirely. Addedrust/planu-core/src/napi_bridge.rsexposing the 22 hot-path functions (file scan, hash, drift, regex grep, dedup, vector ops, HMAC chain) to Node via napi-rs. pnpm build:rustactually works: the script previously referenced a non-existentplanu-clicargo crate. Now invokesnapi buildagainstplanu-corecorrectly.- 390 MB of
target/purged from git: 1,594 cargo build artifacts had been committed by accident. Addedrust/**/target/to.gitignoreand untracked the leak.
Added — Cross-platform distribution (6 targets with native binary, 2 with TS fallback)
- Native acceleration on 6 platforms via napi-rs
optionalDependencies(turbo/swc-style):@planu/core-darwin-arm64(M1/M2/M3 Macs)@planu/core-darwin-x64(Intel Macs)@planu/core-linux-x64-gnu(Ubuntu/Debian/Fedora x64)@planu/core-linux-arm64-gnu(AWS Graviton, Pi 5 64-bit)@planu/core-linux-x64-musl(Alpine Docker x64)@planu/core-linux-arm64-musl(Alpine Docker ARM)
- Windows uses the TypeScript fallback in v3.1.0. Cross-compiling a fully-vendored MSVC toolchain from macOS hit limits we did not want to paper over with broken binaries. Windows users still get the same correctness — just without the Rust speedup on hot paths. A Linux GHA matrix can supply Windows binaries in v3.2 without changing the loader.
- Platform autodetection in the loader:
core-bridge.tsdetects musl vs glibc (4-tier check:/etc/alpine-release→process.report→/usr/bin/ldd→/lib/ld-musl-*), ARM vs x64, and resolves the matching subpackage at runtime. HonorsPLANU_NATIVE_PATHenv override. Falls back through legacy paths for backward compat. - Multi-tier loader: env override → local platform-tagged
.node→ legacy unsuffixed.node→@planu/core-*npm subpackage → TypeScript fallback. Each tier degrades gracefully so Planu works on any Node 24+ environment, even ones without prebuilt binaries. - Vendored Rust deps:
reqwestusesrustls-tlsinstead of native-tls. No system OpenSSL needed on Alpine, Windows ARM, or any musl target. Removed unusedgit2dependency that pulled in OpenSSL transitively. - Local cross-build pipeline — releases are produced from a developer machine (no CI needed):
pnpm build:rust— host target (default)pnpm build:rust:all— all 6 supported targets viacargo-zigbuildpnpm build:rust:check-tools— verify zig + cargo-zigbuild + rustup targetsbash scripts/setup-cross-toolchain.sh— one-shot installer for the cross-toolchainpnpm release:publish— full release pipeline (typecheck → lint → tests → build all → npm publish 6 subpackages + main)
- Real TS fallbacks for all 14 wrappers (not silent
[]):tsScanAndHashFiles,tsScanProjectMetadata,tsScanSpecAnnotations,tsCheckAcCoverage,tsFindFilesByName,tsFindFilesByExt,tsReadFiles,tsCosineSimilarity,tsHnswSearchFlat,tsHmacSign(HMAC-SHA256, byte-identical to Rust),tsHmacVerify,tsFindPatterns,tsGetProjectDataPath,tsAppendGapEntry. Cross-verified that Rust and TS produce the same output for every function on darwin-arm64.
Fixed — Hardening from in-flight code review
tsHmacSignwas usingcreateHash(plain SHA-256), not HMAC — meaning reviewer tokens signed by Rust would fail TS verification (and vice versa). Now usescreateHmac('sha256', secret)to match the Rusthmac::Hmac<Sha256>exactly. Cross-compatibility verified end-to-end.- Cargo
panic = "abort"removed from release profile — would have aborted the host Node process on any Rust panic. Reverted tounwind(default) so napi captures panics and converts them to JS exceptions. - musl detection was fragile on Alpine distroless (no
/usr/bin/ldd). Layered four detection signals; any positive wins. napi build --use-cross zigbuildis napi-rs v2 syntax that silently no-ops on v3. Switched to--cross-compile(the v3 alias for cargo-zigbuild routing).- Smoke test in
release-local.shusedrequire()in an ESM project. Rewritten withimport. release-local.shnow refuses to publish if the count of built.nodebinaries does not match the count ofoptionalDependencies(override withALLOW_PARTIAL_PUBLISH=1). Prevents shipping a broken main package whose subpackages 404 onnpm install.
Changed — Honest performance positioning
- The previous
v3.0.0was marketed as "100% Rust migration" / "The Rust Revolution". That is not what shipped and was misleading. Reality: ~22 hot-path functions are accelerated via napi-rs, and the rest of Planu (487 tools, MCP server, transports, CLI, storage, hosts) remains TypeScript. This is the same hybrid model used by Vercel turbo, swc, and parcel. v3.1.0reframes the work honestly as "native acceleration for hot paths". Rust gives outsized wins on large repos (fast_detect_drift_parallel20–60×,fast_find_duplicate_blocks10–30×,fast_find_patterns5–20×) but is invisible on small/medium projects where LLM and disk I/O dominate latency. SeeBENCHMARKS.mdfor measured numbers.- No more silent data loss: 14 of 22 wrappers in
core-bridge.tspreviously returned[]when the native binary was missing, masking failures as empty results. Each wrapper now has a real TypeScript fallback (tsScanAndHashFiles,tsScanProjectMetadata,tsFindPatterns, …). Linux/Windows users with no prebuilt binary now get correct results, just slower.
Removed
semantic-releaseand CI-driven publishing: per project policy, releases are local-only. Removed therelease:mainscript and disabled (but kept for reference).github/workflows/release-rust.yml.- 39 ghost
pub moddeclarations fromrust/planu-core/src/lib.rs.
[3.0.0] — 2026-05-02
Added — The Rust Revolution (SPEC-1004)
- Native Rust Engine: High-performance core library (
planu-core.node) integrated via NAPI-RS. - 10x Faster Project Scanning: Parallel directory walking, hashing, and regex extraction using Rust's
Rayonandignorecrates. Large monorepos that took seconds to scan now initialize in milliseconds. - Instant Drift Detection: OS-level file watcher powered by Rust's
notifycrate. Sub-millisecond reaction to code changes with 0% CPU overhead while idling. - Parallel AC Coverage: Layer 3 Drift Monitor (Acceptance Criteria matching) now runs in native threads, eliminating event-loop blockages during validation.
Changed — Security & Format Unification
- Atomic Integrity (SPEC-718): Officially closed and enforced. Every
spec.mdwrite is now atomic (tmp + fsync + rename), making Planu indestructible against crashes. - Freeze-on-done Enforcement (SPEC-747): Specs in
donestatus are now immutable by default. Manual edits are blocked by Git Pre-commit hooks and runtime guards. Edits require an explicitbump_spec_versioncall, ensuring a professional audit trail. - Unified Spec Format (SPEC-768): Multi-file specs are dead. Legacy
technical.mdandprogress.mdare auto-folded into a single, context-efficientspec.md. Reduces AI context window consumption by ~40%. - Tool-to-Skill Migration (SPEC-658): Migrated 5 heavyweight workflow tools (
implement_plan,run_healing_loop,multi_teammate_review,generate_orchestration_plan,execute_sdd_flow) to loadable Skills. Reduces system prompt size by ~1,500 tokens.
Fixed
list_specsschema validation error: Fixed regression wherestructuredContentfailed strict MCP schema validation in summary mode. All required properties are now explicitly returned.
[2.12.3] — 2026-04-30
Fixed
- create_release does not auto-trigger housekeeping (SPEC-790): Added fire-and-forget
housekeeping_sweepcall ingithub-release-handler.tsafter the release cascade completes. Branches, worktrees, and stashes are now cleaned up automatically after every release.
[2.12.2] — 2026-04-30
Fixed
- Housekeeping sweep misses fix/spec-XXX branches (SPEC-791): Extended
DEFAULT_PATTERNSinfind-stale-branches.tsto detectfix/spec-*,chore/spec-*,refactor/spec-*, anddocs/spec-*branches in addition to the previously supportedfeat/spec-*. Previously, onlyfeat/spec-*andtmp-*branches were scanned, leaving cherry-pickedfix/spec-*branches orphaned.
[2.12.1] — 2026-04-30
Added — Structured error contract (SPEC-902)
- Error recovery registry: 8 baseline rules mapping error codes (ENOENT, EACCES, EAGAIN, ECONNREFUSED, etc.) to actionable recovery tool calls (
init_project,workspace_alerts,verify_integrations) StructuredErrorcontract: all tool errors now return{what, why, nextAction}with sanitized messages (no raw stack traces, no home paths)withErrorContractHOF: middleware wrapping tool handlers with structured error output- Idempotent wrapping: already-structured errors pass through unchanged
error-recovery.json: configurable registry with code/regex pattern matching
Changed — Error handling
safe-handler.tscatch block now uses structured error contract instead of legacystandardError()license-gate.tswrappers now accept optionalextraparameter for consistency
[2.11.0] — 2026-04-30
Fixed — Release pipeline & spec lifecycle
create_releaseunsupported--jsonflag (SPEC-788):gh release createdoes not support--json(onlyview/listdo). Removed--json url,tagNamefrom the command and now parse the release URL from stdout's last line. Added regression test to prevent reintroduction.workspace_healthreturningtotalProjects=0(SPEC-789): Fixed project discovery fallback inbuildWorkspaceHealthsototalProjectsmatcheslist_registered_projectswhen registry is empty but projects exist on disk.- Auto-migrate legacy
technical.md(SPEC-768):list_specsandinit_projectnow auto-run SSR back-migration to fold legacytechnical.md/progress.mdinto unifiedspec.md. Non-blocking, idempotent, zero overhead when specs are already unified.
Added — Security & durability foundations
- Atomic writes globally (SPEC-718): All spec lifecycle write operations (
spec.md,technical.md,progress.md, hook scripts) now route throughatomicWriteFile(tmp + fsync + rename). Prevents partial writes on crash or kill. Already fully deployed across 15+ files. - Reviewer token signed identity (SPEC-722):
approve_specnow enforces planner ≠ reviewer via HMAC-signed tokens.issue_reviewer_tokengenerates a signed token from aplannerToken.verifyReviewerTokenvalidates signature, sessionId mismatch, modelId mismatch, and 7-day TTL. Multi-teammate review panel support included. Legacy review mode available viaplanu.jsonflag with deprecation warning.
[2.10.0] — 2026-04-29
Added — 7 new MCP tools (493 → 499)
opencode_host_adapter(SPEC-966): Detect OpenCode workspace markers (opencode.json,.opencode/,~/.opencode/,OPENCODE_HOME), scaffold config files (.opencode/rules/planu-workflow.md,.opencode/skills/planu-sdd.md,AGENTS.md), and provide coach rules for OpenCode-specific SDD conventions.dependency_health(SPEC-967): Scanpackage.jsonfor dependency issues — unused, missing, outdated, peer conflicts, and duplicates. Returns categorized report with severity and suggested actions.type_safety_gate(SPEC-968): Block spec status transitions todonewhen codebase contains TypeScriptanytypes or@ts-ignorecomments. Configurable severity (warning/error) and min-count threshold.force_status_analytics(SPEC-969): TrackforceStatus/forceApproveusage per project. Warns when >20% of specs have forced transitions. Generatesquality-exceptions.mdsummary. Increases minimum reason length to 100 chars for forced transitions.detect_duplication(SPEC-970): Token-based code duplication detection using sliding window + SHA-256 hashing. Finds exact and near-duplicate blocks across source files. Returns ranked matches with file paths and line numbers.spec_obesity_healer(SPEC-971): Heal bloated specs (>500 lines) by removing generic injected criteria (OWASP, GDPR, performance), HTML artifacts, and[REQUIRED]/[RECOMMENDED]scrape markers. Dry-run by default with backup before modification. Anti-loop guard skips specs created after 2026-04-01.host_tool_filter/ Codex unavailable tools (SPEC-972): FilterAGENTS.mdtool declarations by host capability. Auto-detects interactive tools (AskUserQuestion, file dialogs) and omits them for non-interactive hosts. Registry-based withcodex.jsonandopencode.jsonhost configs.challenge_specmandatory gate (SPEC-964): Blocksdraft → reviewtransition ifchallengeReportis missing. Requires ≥3 stress-test scenarios addressed. High-risk specs require all 5 focus areas.challenge_specpersists report to spec file.
Fixed
- ESLint/typecheck compliance for all SPEC-966 to SPEC-972 implementations
- Async/await compatibility in OpenCode adapter and spec obesity healer handlers
- Registered
opencode_host_adapterandspec_obesity_healerinlicense-plans.json
[2.9.0] — 2026-04-29
Added — 3 new MCP tools (490 → 493)
architecture_lint(SPEC-961): Scan project codebase for Clean Architecture and SOLID principle violations. Detects handler/route files exceeding 50 lines, Prisma imports outside repository layer, business logic in handlers, and multi-layer imports. Returns scored report with per-rule breakdown.solid_check(SPEC-962): Dedicated SOLID principles scanner with per-principle scoring (0-100). Covers SRP (multiple classes, too many exports), OCP (long switch statements), ISP (large interfaces), and DIP (direct dependency instantiation).verify_integrations(SPEC-965): Ping configured external API integrations before marking a spec as done. Validates HTTP status codes, Content-Type headers, and JSON schema responses. Reads endpoints from.planu/integrations.jsonor explicit args. Reports latency per endpoint.
Fixed — Critical bugs discovered via dogfooding
list_specsschema validation error:ListSpecsOutputSchemawas missing 5 optional properties (humanSummary,branchInfo,autopilotSummary,migrationIssues,interactiveQuestions) thathandleListSpecsinjected intostructuredContent. Zod v4 Mini generates"additionalProperties": falseby default, causing AJV to reject responses withdata must NOT have additional properties. All missing fields now declared.spec_health_checkscoring 0/100 for valid specs:computeSpecHealthonly looked fordescriptionandacceptanceCriteriaon the in-memorySpecobject, but real specs store these in the markdown file. Now readsspec.mdfrom disk, strips YAML frontmatter, and extracts criteria from body (## Acceptance Criteria, checkbox- [ ], BDDGiven/When/Then) and frontmatter (criteria:,scenarios:).- Auth criteria (401/403/429) in frontend specs:
generate_spec_from_apiwas injecting backend auth criteria into frontend/UI specs (Storybook, design tasks).buildACsnow acceptsBuildACsOptionswithtarget/tagsand skips 401/403/429 whentarget ∈ {frontend, ios, android}or tags includeui,storybook,design,component.
Added — 10 gap specs from user feedback analysis
- SPEC-961 (P0) —
architecture_lint✅ implemented this session. - SPEC-962 (P0) —
solid_check✅ implemented this session. - SPEC-964 (P0) —
challenge_specmandatory gate. - SPEC-965 (P0) —
verify_integrations✅ implemented this session. - SPEC-966 (P0) — OpenCode host adapter.
- SPEC-967 (P1) —
dependency_health. - SPEC-968 (P1) —
type_safety_gate. - SPEC-969 (P2) —
forceStatusanalytics. - SPEC-970 (P2) —
detect_duplication. - SPEC-971 (P2) —
spec_obesity_healer. - SPEC-972 (bugfix) — Codex unavailable tools filter.
[2.8.0] — 2026-04-28
Fixed — Spec quality + housekeeping batch (SPEC-764, 783, 784, 785)
housekeeping_sweepdetects cherry-picked branches via Planu status cross-reference (SPEC-764): when a branch is cherry-picked into main (the standard pattern for parallel worktree sessions in Planu), git assigns a new SHA sogit cherry/git branch --mergedreports it asnot_merged. New Pass 2 cross-references SPEC IDs extracted from branch names (feat/SPEC-NNN-*) and tip commit messages (feat(spec-NNN)) againstplanu/specs/SPEC-NNN-*/spec.mdfrontmatter status. Branches whose SPEC isdoneordiscardedare surfaced with reasonspec-done. Pass 2 is no-op (zero git calls) when no skipped branches exist. New helpers:extractSpecIdFromName,extractSpecIdFromCommit,lookupSpecStatus,applySpecDonePass. 95.86% statement coverage, 15 new tests.handleAgentTeamSynthesiswrites to unified spec.md ## Technical section (SPEC-783): SPEC-697 path was still globbing for an externaltechnical.mdfile that SPEC-709/SPEC-752 removed. After unified migration, agent team findings were silently dropped. Now: locatespec.md, extract## Technicalsection body, fold synthesized findings viasynthesizeFindings, replace section in-place with atomic write. Append fresh## Technicalif missing. TriggerrunSsrBackMigrationfirst when legacytechnical.mdis still on disk. Actionable error when spec.md not found.readiness-checkerrejects placeholder and too-shallow ## Technical sections (SPEC-784): new issue codesTECHNICAL_PLACEHOLDER_DETECTEDandTECHNICAL_TOO_SHALLOW(severity blocker). DetectorsdetectTechnicalPlaceholder(regex/See\s+?.+?\s+(?:technical|spec)\.md/i) anddetectTechnicalTooShallow(body < 500 chars AND zero file paths) wired intocheckReadinessInternalandcheckSpecReadiness. SPEC-769 readiness gate honors blockers via existingforceApproveflow. 99.11% statement coverage, 93.57% branches, 20 new tests.spec-validatorREQUIRED_SECTIONS aligned with current generator output (SPEC-785):update_status(approved)was failing withSPEC_FORMAT_INVALIDon every freshly created spec because the validator demanded## Goal,## Out of scope, and atechnical.mdfile — none of whichcreate_specemits post-SPEC-709/SPEC-630.REQUIRED_SECTIONSreduced to['## Problem', '## Acceptance criteria', '## Technical']. NewOPTIONAL_SECTIONS_WITH_INFOfor## Goaland## Out of scope(severity info, not blocker). YAMLoutOfScope:frontmatter satisfies the out-of-scope requirement as alternative to the markdown section. Backward-compat: legacy specs with both sections pass silently. 6 new tests.
Added — Dogfood bug specs filed in this session
- SPEC-783 P1 —
create-specagent-team-synthesis path obsolete after SPEC-709 unified migration (filed + implemented + shipped this session). - SPEC-784 P0 —
check_readinessmust reject placeholder ## Technical sections (filed + implemented + shipped this session). - SPEC-785 P0 — spec format validator requires sections
create_specdoes not generate (filed + implemented + shipped this session). - SPEC-786 P0 (approved, pending implementation) —
validatematcher false-negatives on BDD criteria with literal string match. - SPEC-787 P1 (approved, pending implementation) —
validate.lintCheckreports false issue count vspnpm lint.
Updated — SPEC-766 (approved, pending implementation)
## Technicalsection enriched inline with 13.9 KB of detail: file plan (CREATE/MODIFY), TypeScript signatures (SpecContentGenerator,OpusGenerator,FallbackGenerator,ApiKeyResolver,QualityValidator,AnthropicLike), 4-layer API key resolution chain, anti-loop guards (request shape + system prompt + response inspection), retry policy, fixtures, test stubs, frontmatter additions, approval gate integration. Replaces the placeholder pointer that pre-existed in the file. Implementation deferred to dedicated session due to scope (architectural, 39.2h, touchescreate-spec.tscore).
[2.7.0] — 2026-04-28
Fixed — Dogfood bug batch (SPEC-774, 775, 776, 777, 778, 780, 781)
forceApprovenow bypasses both readiness AND format gates (SPEC-780): previouslyforceApprove: trueskipped the readiness gate but theSPEC_FORMAT_INVALIDvalidator still blocked the transition. Now both gates honor the bypass and emit suppressed errors asqualityWarnings[]in the spec frontmatter.update_statusderives projectId from projectPath (SPEC-775): regression test added confirming behavior parity betweenprojectId-only andprojectPath-only calls. Already worked thanks to SPEC-509/341.- Cascade hooks surface failures + new
session-contexthook (SPEC-776): replaced silent.catch(() => {})instatusJsonHookwith structuredappendAutopilotLogEntrywrites. NewsessionContextHookregeneratessession-context.mdon every status transition AND onrelease_completed. NewverifyStateFilesdrift detector surfaces alerts inworkspace_alertswith fix command. - Readiness checker recognizes proper test annotations (SPEC-777):
parseFrontmatterScenariosnow handles both object (- path: "...") and string (- "tests/foo.test.ts") formats.extractCriteriaLinescaptures full## Acceptance criteriabody text. NewextractFilePathsandextractFunctionNameshelpers detect paths/identifiers in code spans, afterFILES:markers, comma-separated lists, and BDD paragraphs. create_specautopilot file suggestions are now context-aware (SPEC-778): replaced generic project scan with keyword-relevance scorer (extractKeywords+scoreFile+findRelevantFiles). Score=0 → empty suggestions with honest "No related files detected" message. Out-of-scope items also filtered by relevance — no more "OAuth2/MFA" suggestions for unrelated specs.create_specchar-limit hint + async analysis (SPEC-781): tool description text now states "Max 10000 chars; use reconcile_spec for larger". Friendly error replaces cryptic Zod message when limit hit. Heavy autopilot analysis moved torunAutopilotAsync(fire-and-forget) — synchronous response returns within seconds withpendingAnalysis: true.workspace_alertssurfaces in-progress analyses with auto-clear when.analysis.jsonlands.
Added — create_release stuck-spec gate (SPEC-774)
- Block release when specs are stuck:
create_releasenow runsdetectStuckSpecs(projectPath)before any release logic. A spec is stuck whenstatus ∈ {approved, implementing}AND itsbranchis ingit branch --merged main. Default behavior: returnisError: truelisting each stuck spec with fix hintupdate_status(done, specId=...). forceRelease: truebypass: proceeds with release, appends## Status Driftsection to release notes, audit logged vialogForceReleaseAudit.autoFixDrift: trueauto-close: callsautoCloseStuckSpecfor each stuck spec before releasing, summarizes in release output.- Single git call for any spec count:
buildMergedBranchSetrunsgit branch --merged mainONCE; per-spec lookup isSet.has()O(1).
Added — Universal rules catalog + on-demand rule/skill creation (SPEC-779)
- 3 new MCP tools (487 → 490):
create_rule,create_skill,reconcile_universal_rules— host-aware writers (Claude Code: file-per-rule; Codex: AGENTS.md block markers; Gemini:.gemini/conventions.mdblocks). - Universal rules catalog at
src/engine/universal-rules/catalog.tsships 4 rules to every Planu-using project oninit_project:planu-dogfood-bugs(NEW),planu-workflow,planu-modes,agent-teams. - User-edit detector:
reconcile_universal_ruleschecks content-hash vs.planu-rules-manifest.jsoninstall-time hash — preserves user-modified rules untouched. - Manifest tracking: every install records
{ id, path, hostId, hashAtInstall, installedAt }in.planu-rules-manifest.jsonfor atomic reconciliation.
Added — Project rule: dogfood-bug → spec immediately (.claude/rules/planu-dogfood-bugs.md)
- STRICT rule: any bug observed while using Planu becomes a detailed
create_specin the same turn (FILES + FUNCTIONS + BDD + Sonnet-ready order). No deferring to backlog. - 8 specs filed and shipped this session following the rule for the first time: 774, 775, 776, 777, 778, 779, 780, 781.
[2.6.0] — 2026-04-28
Added — Autopilot pipeline log persistence (SPEC-772)
- Autopilot cascade results persisted to JSONL: every cascade hook execution now writes a
passorfailentry todata/projects/<hash>/autopilot-log.jsonl(fire-and-forget). Fields:specId,hookName,result,error?,timestamp,durationMs. - Log rotation at 500 entries:
appendAutopilotLogEntrytrims the oldest entries so the JSONL file never exceeds 500 lines. workspace_alertssurfaces autopilot failures from last 24h: in addition to stale specs, the tool now readsautopilot-log.jsonlacross all registered projects and reports any hook failures in a dedicated "Autopilot Hook Failures" table — no more silent cascade errors.- Fast hook support in cascade runner:
CascadeHookgains an optionalfast: booleanflag. Hooks markedfast: trueare awaited synchronously (up to 2s budget) and their results returned inRunCascadeResult.fastHookResultsfor inclusion in theupdate_statusresponse. autopilotValidateWarninginupdate_statusresponse: whenvalidateScore < 70, the response now includes an explicitautopilotValidateWarningmessage pointing the user toworkspace_alertsfor details — validate failures are no longer silent.- New types:
AutopilotLogEntry,FastHookResultadded tosrc/types/. - 42 new tests: event-bus log persistence (9), cascade runner fast/slow split (4), storage rotation (7), workspace alerts surfacing (5), existing tests updated with mocks to prevent disk writes.
[2.5.2] — 2026-04-28
Improved — Test suite optimization (SPEC-763)
- Fake timers for drift-watcher and budget tests (AC1/AC2): replaced real
setTimeoutwaits withvi.useFakeTimers()+vi.advanceTimersByTimeAsync()— these two test files no longer hold up the suite with real wall-clock delays. - Integration fixture reduced from 2,000 to 50 files (AC3):
create-spec-timeout.test.tstriggers its budget timeout by wall time (viawithBudget), not by file count. 50 dummy files are sufficient;MAX_SCAN_FILES = 500in the analyzer ensures the budget fires before any scan limit. - 5 duplicate test descriptions resolved (AC4): unique
it()names acrossspec.test.ts,spec-compliance-runner.test.ts,specs.test.ts,testimonial-handler.test.ts, andmulti-teammate-review.test.ts— fixes misleading test output and enables proper deduplication by reporters. vi.mockhoisted to module level (AC5):portal-page-detector.test.tsmoved itsvi.mock('node:fs/promises', ...)call from inside adescribeblock to the top of the file — this is the required location for Vitest to correctly intercept the module before imports resolve.
[2.5.1] — 2026-04-28
Added — Housekeeping cleans ephemeral spec artifacts
- SPEC-762 — Ephemeral spec artifact cleanup:
housekeeping_sweepnow scansplanu/specs/SPEC-*/and removesrisk-register.md,implementation-brief.md, andprompt.mdfrom specs with terminal status (doneordiscarded). These files are generated automatically by the Planu autopilot during planning phases but have no value after a spec is completed. Dry-run mode (default) reports what would be deleted without acting;dryRun: falsedeletes them. The stage is best-effort and never blocks the sweep.
Improved — Test performance
maxWorkersdoubled from 4 to 8 — uses available CPUs on dev machinescleanOnRerun: truein coverage config — avoids stale coverage cachetest:coverageexcludestests/integration/**(2 000-file disk fixture); newtest:integrationscript runs the integration suite separately
[2.5.0] — 2026-04-27
Added — Superpowers integration + bundled version self-healing
SPEC-755 — Brainstorming conflict resolution:
init_projectnow injects aspec-locationsection into CLAUDE.md that explicitly routes all specs to Planu viacreate_spec. Overrides the brainstorming skill's default of writing todocs/superpowers/specs/.housekeeping_sweepgains anorphanBrainstormingMarkdownsstage that finds and removes markdown files accidentally created in that directory.SPEC-756 — Bundled version gap auto-fix: Planu detects when a Superpowers plugin bundles an outdated
@planu/cliversion (checked against npm registry). When a gap is found, a direct@planu/cli@latestMCP entry is injected into the project's.mcp.json(or~/.claude/claude.json) so the client automatically uses the latest version on next restart. The check runs fire-and-forget ininit_project,list_specs, andproject_overview— never blocks tool response.
Fixed
register-spec-toolssnapshot updated to 26 tools (reflectsgraph_specs,audit_specs_drift,ssr_back_migrationadded in v2.4.0 but missing from the snapshot).
[2.4.0] — 2026-04-27
Added — UX & Reliability gaps captured from real-world drift incidents
This release closes 4 high-friction UX and reliability gaps observed during the v2.3.0 rollout. All 4 specs were authored after concrete incidents (status.json corruption, legacy multi-file specs blocking SSR, residual zombie shells in Claude Code, leftover branches/worktrees post-release). The fixes are minimal, additive, and never break existing flows.
SPEC-751 —
housekeeping_sweepauto-cleanup: detects stale local branches that have been merged or cherry-picked intomain(usinggit cherry main <branch>for cherry-pick equivalence), prunable worktrees, and orphan stashes. Runs indryRunby default; surfaces a coach reminder afterupdate_status(done)and aftercreate_release.housekeepingevent type added to the hash-chained transition log so cleanups are auditable.SPEC-752 — SSR back-migration (
ssr_back_migrationtool): folds legacytechnical.mdandprogress.mdfiles into the unifiedspec.md## Technical/## Progresssections. Respects SPEC-747 freeze (skipsdonespecs unlessallowDoneSpecs: true). Closes the residual writer path:runTechnicalEnrichernow writes ONLY tospec.md, never re-createstechnical.md. Dry-run reporting + per-spec mutation log.SPEC-753 —
project_overview+ status.json self-healing: single-call state query (project_overview) replaces the multi-tool dance ofplanu_status + list_specs + filesystem reads. Returns counts by status, top pending specs, version sync, drift score, stale-implementing detector, pending cleanup.reconcile_status_jsonrepairs status.json drift from spec.md frontmatters with three resolution strategies (frontmatter-winsdefault,status-wins,newest-wins). Self-healing layer auto-quarantines corrupt status.json files toplanu/.broken/status-<ts>.jsonand rebuilds from frontmatters.proper-lockfile-style file lock prevents concurrent-write races.status_reconciledevent added to transition log.SPEC-754 — Shell hygiene coach reminder: appends a one-line KillShell reminder to the response of
update_status({ to: 'done' })when the host isclaude-code. Closes the "14 zombie shells in Tareas panel after 8h SDD session" feedback. i18n parity enforced (coach.shell_hygiene.kill_backgroundin en/es). No new tools, no detection — minimal viable intervention at the natural completion milestone.
Fixed
- Cherry-pick orchestration during release used
git merge-base --is-ancestorto detect already-included branches; this missed cherry-picked branches because their commits have different SHAs. Now usesgit cherry main <branch>(the canonical patch-equivalence test). Documented in SPEC-751. runTechnicalEnricherwas the only remaining writer totechnical.mdafter SPEC-630 unified the spec format. Closed in SPEC-752 Scenario 5 — enricher now writes ONLY to spec.md.workspace_overviewpreviously had no concept of single-project state. Newproject_overview(SPEC-753) is the single-call replacement; the existing cross-projectworkspace_overviewis unchanged.
Stats
- 4 specs implemented across 3 parallel worktree-isolated Sonnet workers
- ~2700 LOC source + tests added
- 131 new targeted tests — all green
- 4 new tools (
housekeeping_sweep,ssr_back_migration,project_overview,reconcile_status_json) bring total from 483 → 487 - Lint clean, typecheck clean, snapshot regenerated
[2.3.0] — 2026-04-26
Added — Observability + Sandbox + Audit + Resiliency (Plan v2 Bloques 6+7+8)
This release adds 11 specs from Plan v2 — Bloques 6 (Observability + Sandbox), 7 (Maintenance + Audit), and 8 (Resiliency + Coach + Test Architect). All extensions are additive; no breaking changes. Together they close the drift-detection loop: every tool call is observed (telemetry + budget + sandbox), every spec edit is freezable on done, every drift is auditable, and the dashboard shows a single drift-score number.
Bloque 6 — Observability + Sandbox
SPEC-740 — Global middleware chain (
withBudget+withTelemetry+withSandbox): every tool handler registered viaregister-all-tools.tsis now wrapped by a composable middleware chain (composeMiddleware).withBudgetenforces per-tool wall-clock + token budgets;withTelemetryrecords start/end events to the telemetry sink;withSandbox(when enabled) routes shell-exec calls through a sandbox runner. Middlewares can be enabled/disabled per-server via config.SPEC-741 — Telemetry 30-day retention + t-digest pre-aggregation + opt-in stance: telemetry is opt-in by default. When enabled, raw events are kept for 30 days then rotated; P95 latencies are pre-aggregated using a pure-TS t-digest implementation (k=100 compression, accuracy verified within 2% for 1000 uniform samples).
runTelemetryRotation()is exposed for cron-style invocation.SPEC-742 — Real OS sandbox for
execute_sdd_flow: detects host capabilities (bwrapon Linux,sandbox-execon macOS, Docker fallback) and routes shell exec through the appropriate runner. Env-sanitizer stripsLD_PRELOAD,DYLD_*, and other ambient interpreters before exec. Falls back tonoop-sandboxwhen no runner is available, with a telemetry warning.SPEC-743 — LLM cassette/mock pattern: deterministic test snapshots via SHA-256 request fingerprinting + JSONL cassette store at
tests/cassettes/.PLANU_RECORD_CASSETTES=1toggles record mode; replay raisesCassetteMissErrorwhen a request has no recorded match. Replaces ad-hocvi.fn()mocks for any test that exercises real LLM I/O.
Bloque 7 — Maintenance + Audit
SPEC-744 —
audit_specs_drifttool: two-tier reverse-audit. Tier-1 (deterministic) runs file-path existence + scenario→test mapping + frontmatter integrity checks across all specs. Tier-2 (LLM-based) classifies semantic drift between spec text and current code; budget-capped to avoid runaway cost. Returns a markdown report.SPEC-745 —
heal_planu_root3-tier policy: every repair operation is classified as auto-fix (low-risk JSON syntax + UTF-8 normalization), propose-only (medium-risk schema repairs, requires user approval), or never-touch (high-risk semantic edits, surfaces a comment but does not modify). Backups go toplanu/backups/<timestamp>/before any mutation;markers.tsenforces an allowlist of fixable file types.SPEC-746 — Spec dependency graph +
graph_specstool: builds a DAG fromsupersedesanddepends_on(ordependencies) frontmatter fields. Returns nodes, edges, detected cycles, and topological order.superseded-set.tsanswersisSuperseded(specId)for filtering. DOT exporter emits Graphviz output for visualization.SPEC-747 —
freeze-on-doneenforcement at write-boundary:atomicWriteFilenow consultsisSpecFrozen(specId, status)and rejects writes to specs indone/discardedstatus with error codespec_frozen. Operators can break-glass via an unlock token (HMAC-signed, 5-min window, audited) orforceEdit: true.retro-audit.tsemits aretro_audittransition-log entry for every successful unlock-window edit so changes to frozen specs remain visible.
Bloque 8 — Resiliency + Coach + Test Architect
SPEC-748 —
planu_drift_scorefield + dashboard badge:planu_statusnow includesstructuredContent.planu_drift_score(0–100, 1 decimal) computed as(driftReview / doneSpecs) * 100frompending.jsonfiltered bykind: 'drift_review'.lastAuditAttimestamp tracks freshness. Dashboard renders adrift-green/drift-amber/drift-redbadge in the status section.SPEC-749 — Coach multi-host (rule packs per host + i18n catalog): rule packs in
src/hosts/{claude-code,codex,gemini}/coach.tsdeliver host-specific guidance. All user-facing strings go throught(key, params)resolved againstsrc/i18n/coach/{en,es}.json. Key parity is enforced by tests; missing-key fallbacks emitcoach.i18n.missing_keytelemetry. No literal strings allowed in rule pack code.SPEC-750 — TestArchitect role + TDD strict mode:
decideTddRouting()blocks specs withtdd: strictfromdraft → in_progresstransitions until a TestArchitect produces aRedTestsHandoffSchema-validated handoff.verifyRedPhase()confirms tests fail (red);verifyGreenPhase()detects deletion of red-tests with error codeRED_TESTS_DELETED. Event typestdd_red_lockedandtdd_green_achievedadded toTransitionEventType.
Stats
- 11 specs implemented across 3 parallel worktree-isolated workers (Sonnet)
- ~2700 LOC source + tests added
- 575 new tests (+3 skipped) — all green
- 3 new tools (
audit_specs_drift,graph_specs,heal_planu_root) bring total from 480 → 483 - Snapshot regenerated; license-plans synced; website counts synced to 483
[2.2.0] — 2026-04-26
Added — Validation Atomicity + DevEx Endurecido (Plan v2 Bloques 4+5)
This release adds 10 specs from Plan v2 — none introduce breaking changes; all extend existing surfaces additively. Together they harden the validate→done path (atomic, reversible, observable, transactional) and the release pipeline (preflight, smoke test, rollback, reproducible build).
Bloque 4 — Validation atómica
SPEC-730 — Scope/target-aware holistic validate:
validateSpecnow consultsresolveApplicableDimensions(target, scope)to enumerate which of the 5 dimensions (tests, lint, typecheck, security-scan, spec-compliance) actually apply.doc-onlyscope skips typecheck/lint/tests/security; meta-like targets (infrastructure, database, shared) skip lint/tests. Score is normalised over the applied set so a 100% doc-only spec is no longer penalised for missing source code.HolisticReportexposesapplicableDimensionsandskippedReasonsso reviewers see why a 100 score involves only 2 dimensions.SPEC-731 — Non-destructive
dry_runmode forupdate_status: newdry_run?: booleanflag. When true, all gates run (runApprovedDodGate,runValidateGate, format gate, dep-guard) and the prospective transition is simulated, buttransitionSpecis NOT called and no disk mutation occurs. Returns aDryRunResultwithwouldTransition,gateResults, and the prospectivenextStatus. CI scripts and operators can pre-flight a transition before merging.SPEC-732 — Executable acceptance criteria linked to test files: each frontmatter scenario can carry a
tests: [{ path, line? }]array. The newrunSpecCompliance(spec, projectPath)runner invokesvitest --reporter=jsonagainst the linked files and assigns a per-scenario verdict (pass/fail/missing).validateSpecconsumes the per-scenario verdicts in thespec-compliancedimension.check_readinessadds ascenarios_missing_testsblocker when any scenario lacks links.SPEC-733 — Reverse transitions with mandatory reason:
update_statusnow accepts reverse transitions (e.g.done→implementing,approved→review,validating→implementing) with a mandatoryreason: string(≥ 10 chars). The reason is appended totransition-log.jsonlundereventType: 'reverse_transition'.validateReverseTransitionenforces the allowed graph;isReverseTransition(from, to)is exported for callers.SPEC-734 — Transition log enriched payload:
TransitionLogEntrywidens withsessionId,modelId, andgateResults(typed sub-shape recording each gate's outcome and elapsed time).canonicalEntry()orders the new fields stably so SHA-256 chain hashing remains deterministic.verifyTransitionLogChain(path)is exported for end-to-end integrity checks. Legacy entries (no enriched fields) read withnullfallbacks — no migration script required.SPEC-735 — Transactional cascade rollback (saga):
handleUpdateStatusnow wraps the post-transitionSpeccascade (Slack notify, dashboard updater, webhook outbound, telemetry) in arunSagaexecutor. Steps declarecritical: true | false. On a critical-step failure the saga invokes compensating actions in reverse order, callstransitionSpecagain to roll back to the prior status (trigger: 'rollback'), and appends aterminal_drift_detectedlog entry withmeta.rolledBack: true. Non-critical failures log and continue. GenericrunSaga<Ctx>()is exported for future use cases (release pipeline, multi-step migrations).
Bloque 5 — DevEx endurecido
SPEC-736 — Hardened release pipeline:
scripts/release.shnow invokes a strictrelease-preflight.sh(tests + typecheck + license drift + npm whoami allowlist), acquires a flock-based concurrency lock at/tmp/planu-release.lock, and runstag → push tag → publish → smoke-test (release-smoke-test.sh) → push branchin that exact order. A failed preflight or smoke test exits non-zero, leaving the work uncommitted/unpublished. The smoke test runsnpx --yes @planu/cli@<v> --versionagainst a fresh installation.SPEC-737 —
rollback_releasetool: newmcp__planu__rollback_release({ version, reason, allowAged?, dryRun? })tool that orchestratesnpm dist-tag rm→git tag -d→git push --delete→ post-mortem skeleton attemplates/postmortem.md→ optional verification smoke test → audit entry intransition-log.jsonl(specId: 'release',meta.kind: 'release_rollback'). Age guard refuses rollbacks of versions older than 30 days unlessallowAged: true.SPEC-738 — Reproducible build:
scripts/release.shnow exportsSOURCE_DATE_EPOCH=1andPLANU_OBFUSCATE_SEED=$(git rev-parse HEAD | cksum)beforepnpm build.scripts/obfuscate.mjsreads the seed and feeds it intojavascript-obfuscator'sseedoption. Two consecutive builds at the same git SHA produce identical tarball SHA-256. Newscripts/check-reproducibility.sh <tag>rebuilds at a tag and diffs against the published tarball. Optional GitHub workflow.github/workflows/reproducibility.ymlautomates the check on tag push.SPEC-739 —
flag_spec_gaprefinements:flag_spec_gapacceptsseverity: 'low'|'medium'|'high'|'critical'andaffectedSpecs: string[]. Each flagged gap is appended to a hash-chainedplanu/.gaps.jsonl(mirroring the SPEC-723/734 transition-log pattern) so the gap history is tamper-evident.gaps-log.tsexposesappendGap,readGaps,verifyGapsChain.pending.jsonintegration unchanged — gaps still surface inplanu_status.
Fixed
dep-guard-gate.test.tsandvalidate-gate-forced-bypass-audit.test.tsmocks updated to exposeisReverseTransition/validateReverseTransitionfromtransition-guard.js(SPEC-733 export additions).license-plans.jsonextended withrollback_releaseand re-categorisesflag_spec_gap(nowproToolstier alongsidecreate_release).- Tool API snapshot regenerated to include the new SPEC-737 tool entry.
Test counts (delta)
- 176 new tests across 10 specs (SPEC-730: 48, SPEC-731: 6, SPEC-732: ~12, SPEC-733: 17, SPEC-734: 12, SPEC-735: 18, SPEC-736: ~14, SPEC-737: ~14, SPEC-738: ~7, SPEC-739: ~28).
- Full suite: 30 326 / 30 326 passing (2 pre-existing flaky orchestrator timeouts unchanged).
[2.1.0] — 2026-04-26
Added — Spec Quality Refinements + Roles Formales (Plan v2 Bloques 2+3)
This release adds 6 specs from Plan v2 — none introduce breaking changes; all extend existing surfaces additively. Together they close the spec-quality gaps flagged by the 5-critic Opus review and formalise role handoffs (Triagier → Elicitor → Planner → Reviewer → Implementer → Validator → Releaser).
SPEC-724 — Spec quality refinements bundle: 5 sub-features behind one tool surface.
elicit_requirements({ ...args, mode: 'non-interactive' })synthesises a complete elicitation summary deterministically (CI/swarm friendly, noAskUserQuestionround trip).heal_spec_docs({ ...args, dryRun?, backup? })writes.bak.<ts>companions by default (gitignored), supportsdryRun(returns unified diff, never writes), and emits aGOAL_SCENARIO_DRIFTwarning when Goal vs first scenario THEN clause Jaccard similarity < 0.85.- BDD validator gains a copula blacklist (
es,son,está,tiene,is,are,has,exists) — copulas inside fenced code blocks are ignored. - Idioma validator strips fenced blocks before counting prose; abstains when prose word count < 50 (no false positives on early drafts).
audit_claude_config({ gate: 'core-rules' })walks per-host renderers (Claude~/.claude/rules/, CodexAGENTS.md, GeminiGEMINI.md) and returns blockers if any of the 3 core rules is missing.
SPEC-725 — Handoff artifacts schema: 5 versioned Zod artefacts persisted under
planu/data/projects/<projectId>/handoffs/<specId>/viaatomicWriteFile(SPEC-718) under cross-process lock (SPEC-719), each emit-recorded in the SPEC-723 transition log.intake.json(Triagier→Elicitor),spec.lock(Planner→Reviewer),review_feedback.md(Reviewer→Planner),implementation-report.json(Implementer→Validator),validation-report.json(Validator→Releaser).- Each carries
schema_version(SemVer). Forward-minor reads with warning; major mismatch refuses. update_status(done)now readsvalidation-report.jsonand blocks with reasonvalidation_report_failedwhenpassed: false.- Public API:
validateArtifact,appendArtifact,readArtifactre-exported fromsrc/core/index.ts.
SPEC-726 — Triagier role +
triage_requesttool: front-gate intent classifier (Haiku-class). Five kinds:idea→ backlog,quick-fix→ direct implement,bug-spec/feature-spec/epic→ elicit. Confidence < 0.6 returnsinteractiveQuestionsfor disambiguation. Cost guard: 5s wall-clock + 1500 output tokens; on trip returns deterministicfeature-spec @ 0.5fallback. Writesintake.json(SPEC-725) on success. Free-tier tool.SPEC-727 — Arbitrator activation + heterogeneity check: panel-orchestrator.ts now invokes the existing Arbitrator (Opus, persona already in
arbitrator-prompt.ts) after 2 consecutive Planner↔Reviewer disagreements on the same(specId, frontmatterSha). Heterogeneity gate refuses panels staffed by two specialists with identical(modelId, promptHash). Decisions are persisted toplanu/data/projects/<id>/arbitrator-decisions/<specId>-<sha>.jsonand recorded in the transition log withreason: 'arbitrator-decision'. NewverifyTokenPair(reviewerToken, plannerTokenOnSpec)helper closes a SPEC-722 hardening gap.SPEC-728 — DepGuard cycle blocker:
dod-gates.tsnow invokescheckApprovedDepGate(spec, allSpecs)before anytransitionSpeccall toapproved. Blocks withDEPENDENCY_CYCLE(with full path narrativeSPEC-X -> SPEC-Y -> SPEC-X) orSELF_DEPENDENCY. Tolerates orphan dep refs with a warning (no block). Adds <50ms to the approve path.SPEC-729 — Escalator role + retry policy: generic
withEscalation(role, fn)middleware applied to Reviewer (3 retries), Validator (3 retries), and Releaser (2 retries) flows. Budget exhaustion returns aninteractiveQuestionssentinel[retry, abort, manual-override]; Releaser default isabort, others default toretry.manual-overridefor Releaser requiresforceStatusReason ≥ 30chars. The wrapper preservesreviewerToken(SPEC-722) across retries unchanged.
Fixed
heal_spec_docslegacy tests adapted to the newbackupdefault (backup: falsefor explicit 1-call assertions)..gitignoretemplate extended withplanu/specs/**/*.bak.*so SPEC-724 backups don't pollutegit status(root cause of the SPEC-715 reproducer regression).- Tool API snapshot refreshed to include
triage_request.
Test counts (delta)
- 218 new tests across 6 specs (SPEC-724: 17, SPEC-725: ~24, SPEC-726: 29, SPEC-727: 19, SPEC-728: 6, SPEC-729: 25, plus shared utilities).
- Full suite: 30 148 / 30 150 passing (2 pre-existing flaky orchestrator timeouts unrelated to this release).
[2.0.0] — 2026-04-26
BREAKING CHANGES — Foundations + Bypass Closure (Plan v2 Bloques 0+1)
This release closes 4 confirmed state-machine bypasses identified by the 5-critic Opus review of plan v1, plus the foundational primitives the rest of plan v2 depends on. Direct status writes, file-driven status drift, validate-as-warning, and string-literal reviewer identity are all blocked at the source. Existing integrations that assumed those paths must migrate.
SPEC-720 — Single status entry point (BREAKING):
specStore.updateSpec({status})now throwsDirectStatusWriteForbiddenError. The only path that mutates status istransitionSpecinsrc/engine/spec-state-machine/transition-spec.ts, called viahandleUpdateStatus.sync_spec_state,branch-ops.markMergedAsDone, the HTTP/specs/:id/statusroute, anddashboard/spec-updaterwere rewired to route throughupdate_status. ESLint ruleno-restricted-importsblocks__internalSetStatusand the legacyupdateSpecStatusoutsidetransition-spec.ts. New shell guardrailscripts/check-no-direct-status-writes.sh.autoCompleteSpecsreturn type is now{completed: string[], blocked: Array<{specId, reason}>}(wasstring[]).SPEC-721 —
runValidateGatefail-closed (BREAKING): validate timeouts, crashes, null scores, and unreachable validators no longer fall through silently — they BLOCK the transition with one of 5 enum reasons (validate_score_below_threshold,_no_criteria,_crash,_timeout,_unreachable). Operators who knowingly bypass must passforceStatus: trueANDforceStatusReason ≥ 30 chars; the bypass is appended to the audit-trail withevent: 'validate_gate_forced_bypass'. The redundant outerwithToolTimeoutwrapper inupdate-status/index.tswas removed.SPEC-722 — Reviewer signed identity (BREAKING):
approve_specno longer acceptsreviewer: "alice"as a free-string. It requires areviewerToken(HMAC-SHA256 ofsessionId + modelId + nonce, signed withplanu/.planu-secret, TTL 7 days).multi_teammate_reviewenforces heterogeneity — two critics with the samemodelId + promptHashare rejected.ApprovalRecord.reviewer: stringis replaced byApprovalRecord.reviewerIdentity: ReviewerIdentity. SetlegacyReviewMode: trueinplanu/conventions.jsonfor opt-in legacy string acceptance during migration.SPEC-723 — Frontmatter immutable post-terminal: at
done/discardedtransition, a SHA-256 over canonical frozen fields is computed and stored in a hash-chainedtransition-log.jsonl.repair_frontmatter_driftandsync_spec_stateverify the SHA before any rewrite — divergence surfaces asreport.corrupt[]/report.rejected[]with audit eventsterminal_frontmatter_tamper_detected/sync_spec_state_terminal_drift_detected. Two unfreeze paths:bump_spec_version(SPEC-717) andupdate_status(reopen)(SPEC-V3 placeholder).
Added — Foundations (Bloque 0)
SPEC-718 — Atomic writes globally: new
src/engine/safety/atomic-write-file.ts(tmp + fsync + rename pattern) replaces 20 rawwriteFilecallsites across the spec lifecycle. Power-loss during write no longer leaves half-written spec.md. New custom ESLint ruleplanu/no-raw-writefile-in-spec-lifecycleenforces the pattern on migrated paths.SPEC-719 — Cross-process spec lockfile: disk-backed mutex at
planu/.locks/<specId>.lockwith PID + sessionId + hostname + heartbeat (30s) + 3-signal stale detection (heartbeat>5min OR PID dead viaprocess.kill(pid,0)ESRCH OR ttlMs expired). All spec-mutating tools (update_status,delete_spec,version_spec) wrap inacquireLock + releaseLock.list_locksextended to surface cross-process locks alongside legacy SPEC-301.SPEC-716 —
validateSpecFormat()extracted to core: side-effect-free, transport-agnostic validator atsrc/core/spec-validator.ts. ComposescheckSpecReadiness,scoreSpecQuality, and frontmatter checks behind one API. Routed through bycheck_readiness,update_status(approved)(newcheckApprovedFormatGate), andcreate_pr_from_spec. Zero@modelcontextprotocol/sdkimports — usable from CLI, pre-commit, CI. Closes the SPEC-608 gap.SPEC-717 — Spec format versioning + history SemVer: every new spec is born with
spec_format_version: "1.0"andspec_version: "1.0.0"plushistory: []. New toolbump_spec_version({kind, reason})is the canonical entry point — appends aSpecHistoryEntryand refreshesfrontmatterSha(SPEC-723 reseal hook).heal_spec_docsandrepair_frontmatter_driftare idempotent: byte-equivalent output triggers no version bump. Legacy specs withoutspec_format_versionare treated as"0.x"and migrated on touch.SPEC-F0e (planned) — Resource-aware orchestration: gap detected during this release dev session (host at 22GB/24GB used during 4 parallel Sonnet agents). Specced in plan v2 for next bloque:
src/engine/resource-guard/sensor +withResourceGuard()middleware adapting parallelism formulti_teammate_review, vitest hooks, and subagent spawning when client RAM is low. NOT shipped in 2.0.0 — documented for follow-up.
Internal
- 5 stale entries removed from
src/config/license-plans.json(multi_teammate_review,implement_plan,execute_sdd_flow,generate_orchestration_plan,run_healing_loop) — none registered in code. Addedrender_spec_for_provider(SPEC-670) which was registered but missing from license-plans. - Test suite: 30022/30022 passing (3 pre-existing timeouts unrelated to this release).
- Plan v2 (
planu/research/plan-v2-cierre-gaps.md): 38 specs across 8 bloques, born from a 5-critic Opus review of plan v1.
Migration guide
- If you call
specStore.updateSpec({status})directly: switch tohandleUpdateStatus({specId, status, projectId, projectPath}). - If you have tests that assume validate fail-open: expect
result.isError === truewithvalidate_gate_*reasons. Update assertions or passforceStatus: true+ a 30+ char reason. - If you call
approve_spec({reviewer: 'alice'}): either (a) issue a reviewer token via the new flow, or (b) setlegacyReviewMode: trueinplanu/conventions.json. - If you read
autoCompleteSpecs()return: it's{completed, blocked}now, notstring[].
[1.99.1] — 2026-04-26
Fixed
- SPEC-713 —
create_spectimeout regression (P0): confirmed bottleneck via Phase 0 instrumentation —runAutoPostCreatePipelinewas awaited synchronously before sending the MCP response, and 8+ enrichment steps ran sequentially (100–500ms each), pushing total latency past the 60s client timeout on large projects. Fix: 25s hard ceiling on the critical path (buildContext → writeFile → createSpec), 6 enrichment steps now run in parallel with per-stepwithBudget(2–3s each), andrunAutoPostCreatePipelineis fire-and-forget after the response is sent. New helperssrc/engine/timing/{budget,structured-log}.tsplussrc/types/timing.ts. Result:create_specon a 2000-file project drops from 20–65s to 5–12s; spec is always synchronously persisted before the response. 18 new tests (12 unit + 6 integration with 2000-file fixture). Phase 0 timing report atplanu/research/spec-713-create-spec-timing.md. Closes SPEC-560 residue.
[1.99.0] — 2026-04-26
Fixed
- SPEC-715 — Git-aware migrator +
list_specsread-only: User-reported P0 bug wherelist_specssilentlyunlink'dtechnical.mdfiles during auto-migration to the unified-spec format, leaving the deletion outside the LLM's commit. NewsafeUnlink(projectPath, filePath)helper detects.gitand usesgit rm -f --ignore-unmatch <relPath>to stage the deletion atomically (falls back to plainunlinkoutside repos).list_specsis now strictly read-only — it reports drift viadetectDrift()instead of mutating the workspace; explicit migrations only run when the user invokesheal_spec_docs. NewMigrationDriftReporttype avoids name collision with the existinganalysis.DriftReport.
Refactored
- SPEC-714 — Cascade hooks hybrid (closes SPEC-649 residue): Audit found 18 inline cascade actions inside
update-status/side-effects.ts(438 lines), violating SPEC-649's "exactly 2 actions on done" contract even though all 18 were already fire-and-forget. Newsrc/engine/cascade-hooks/{types,registry,runner,core/,hooks/}enforces the contract architecturally —runCascade(ctx, opts)awaits the 2 core actions (write-session-json,append-releases) within a 2-secondAbortControllerbudget, then dispatches the 18 extension hooks viaPromise.allSettled(cannot block the user response). Hooks declareid,description, and a pure handler; opt-out viaplanu/conventions.json:cascadeHooks.disabled[]orPLANU_DISABLE_HOOKS=hookA,hookBenv.side-effects.tsshrinks 438 → 112 lines. New pre-commit guardrailscripts/check-no-inline-cascade-actions.shrejects future inline blocks. SPEC-649 markedsupersededBy: SPEC-714.
Internal
- 36 new test files for cascade hooks (registry + runner + 18 hook units + 2 core actions + integration parity), 18 new files for cascade hook handlers, 2 new tests for git-aware FS + drift detector, 2 new integration tests for
list_specsread-only contract andheal_spec_docsstaging behaviour. Suite: 29756/29756 green. - 4 draft specs created for follow-up: SPEC-710 (holistic
validate), SPEC-711 (mid-implementationflag_spec_gap), SPEC-712 (localpnpm releasepipeline), SPEC-713 (fixcreate_spec60s timeout regression — reopens SPEC-560). - Audit report
planu/research/audit-2026-04-26-done-specs.md: 25 done specs sampled, 5 confirmed P0 residue, 6 suspected P1, 14 clean.
[1.98.0] — 2026-04-26
Changed
- SPEC-709 — Unified
spec.mdfrom origin:create_spec,reverse_engineer, andcore/spec-api.tsnow write a single unifiedspec.mddirectly, instead of writing a two-file pair (spec.md+technical.md) thatlist_specs/heal_spec_docshad to merge on next read. Closes the SPEC-630 residue at the creation path. New helpersrc/engine/spec-format/unified-spec-builder.tsstrips the technical body's frontmatter and appends it as a## Technicalsection. New specs are born unified — no auto-healing required. 5 builder tests + 3 updated callsite tests; full suite green.
[1.97.0] — 2026-04-26
Added
- SPEC-708 — Cross-LLM rules adapter:
HostHintextended to'codex' | 'gemini'. Newsrc/engine/host-detection/detect-host.tsresolves the connected client fromPLANU_HOSToverride or per-CLI env markers (CLAUDECODE,CURSOR_SESSION_ID,OPENAI_CODEX_SESSION,GEMINI_CLI_SESSION). Newsrc/engine/host-rules-templates/exposesbuildRulesForHost(host, version)plus directive helpers. Tool responses withinteractiveQuestions[]now emit a host-aware directive ("Use AskUserQuestion" only for Claude Code; Codex/Gemini receive their native interactive-prompt phrasing). CodexAGENTS.mdand Gemini.gemini/conventions.mdnow receive an idempotent<!-- planu:rules:start -->block alongside the existing scaffold body.
Fixed
- Outdated workflow.md docs (EN, ES, DE, FR, PT, ZH): the spec-files table still listed
progress.md,technical.md,executive-report.html, andtechnical-report.html— formats that SPEC-461 (lean) and SPEC-630 (unifiedspec.md) replaced months ago. Confirmed in the wild after a customer screenshot showed Claude quoting the outdated table. Each language page now describes the single-file unified format and points toheal_spec_docsfor legacy projects.
Refactored
engine/claude-md-injector/rules-template.tsdelegates to host-rules-templates: the Claude Code rules-section builder is now a thin wrapper overbuildRulesForHost('claude-code', version). No behavioural change for existing Claude Code projects.
[1.96.0] — 2026-04-25
Added
plan_team_distributiontool: EngineplanTeamDistribution()(existing since SPEC-091) is now exposed as a real MCP tool. Loads each spec viaspecStore, extracts files mentioned inspec.md, builds a file-ownership map, and returns the team roster, phased execution order (parallel-safe vs conflicting), and warnings for shared files. Closes a long-standing doc-vs-reality gap where rules-generator, claude-md-generator, onboarding-engine, and generate-automation-guide all referenced a tool that was never registered.- Crash Shield suppress directives: TypeScript detector now respects three eslint-style magic comments —
// crash-shield-ignore(same line),// crash-shield-ignore-next-line, and// @crash-shield-ignore-file(whole file). Lets developers signal "writer is under our control, shape is guaranteed" without changing detection rules. Marked 50+ Planu-controlled config/cache readers with the file-level directive. Scanner-visible JSON.parse-as count drops from 180 → 120, with the remaining covering genuine boundary reads (user package.json, tsconfig.json) where CRITICAL is correct.
Changed
- Hardcode guardrail flips to STRICT by default:
scripts/check-no-hardcoded-stacks.shno longer just warns — it now fails pre-push when any hardcoded framework/stack literal lands insrc/**/*.tsoutsidesrc/config/. The previous baseline of 308 hits was eliminated by auditing every flagged file: all turned out to be legitimate canonical mappings (npm-package↔framework adapters, keyword catalogues, type unions, generator inputs). 122 files markedSPEC-597-EXEMPTwith explicit two-line headers documenting why each is exempt. New hardcoded literals now require eithersrc/config/*.jsonregistration or an explicitSPEC-597-EXEMPTexemption. tool-registry/group-*.tsconsolidation rationale: Updatedeslint-disable max-linesdirectives in the 7 thematic group files (1100-2188 lines each) to document why splitting would re-create the ~120register-*.tsfiles Phase 3 (commit aafeea60) intentionally collapsed.safeJsonParsehelper at JSON read boundaries:src/storage/qa-gate-store.ts,skill-registry-storage.ts, andproject-drift-store.tsmigrated fromJSON.parse(raw) as TypetosafeJsonParse(raw, fallback)with type guards. Eliminates a class of latent crash bugs where a corrupted/partial JSON file would lie to the type system.
Fixed
resolve-project-pathregistry lookup: When onlyprojectIdwas provided (noprojectPath), the resolver returned an empty path instead of looking up the registry, leaving downstream tools without a working directory. Now doesprojects.find((p) => p.hash === explicitId)to recover the path.- Spec integrity check (SPEC-630 follow-up):
scripts/check-spec-integrity.shno longer requirestechnical.md— SPEC-630 unified that file intospec.md, but the pre-commit hook kept warning on every commit (7 spurious "missing: technical.md" entries for SPEC-700→706). Now onlyspec.mdis required. - 16 pre-existing test failures across 3 suites:
update-status-automation(4 tests) needed aqa-gate-storemock added by SPEC-642;tool-schemas.snapshot(1) needed regeneration after new tools landed;share-story(11) needed@supabase/supabase-jsretained as devDep for vitest's vite transform ofShareStory.vue. Suite now 29529/29529 green. - 7 pre-existing curly-brace lint errors in
src/engine/marketplace-fetcher/anthropic-source.tsthat slipped past the lint-staged pre-commit hook (which only checks changed files). Wrapped one-line if/setTimeout callbacks in braces per the project'scurlyrule.
Removed
- 24 unused barrel files: 17 type subdomain barrels (
src/types/{agents,ai,analysis,autopilot,context,docs-types,git,hooks,ide,infra,integrations,licensing,observability,registry,security,spec-ops,testing-ext}/index.ts) and 7 engine/host barrels (src/engine/{dynamic-knowledge,permissions-merger,provider-adapters,skill-generator,spec-effectiveness}/index.ts,src/hosts/{claude-code/runtime,codex}/index.ts). All verified to have 0 consumers via grep. Knip output now empty.
Refactored
src/types/living-spec.ts(578L) split into 3 sub-modules:living-spec/{annotations,dashboard-and-sync,auto-update-and-merge}.ts(170+285+123L). The original file became a barrel — call sites unchanged. Each sub-module fits comfortably under the 500-line limit.
[1.95.0] — 2026-04-25
Added
- SPEC-661 — Tools page focus refactor: Website
tools/index.mdrewritten from 477 → 50 core tools grouped by user intent (Discover, Plan, Implement, Validate, Operate). Reduces cognitive load for new users; deeper tool reference still indexed for search. - SPEC-659 — Lean-mode guide pages: 5 new website guides —
lean-spec-format,auto-status-transitions,unified-spec-md,tier-tool-loading,interactive-questions. Each documents one mechanism with concrete examples; cross-linked from manifesto and onboarding. - SPEC-701 — Testimonials component:
Testimonials.vuerenders approved testimonials from Supabase via VitePress data loader. Zero JS at runtime — data is statically baked at build. - SPEC-702 — Live stats banner:
LiveStats.vueshows real-time npm downloads + GitHub stars/forks, fetched at build via API badge fetchers. Cached 1h. - SPEC-703 — WorksWith logo grid:
WorksWith.vuedisplays 8 supported tool logos (Claude Code, Cursor, Copilot, Codex, etc.) with tier-based grouping. - SPEC-704 — ShareStory submission form:
ShareStory.vueposts directly to Supabase REST endpoint (anon key, RLS-protected). Captcha via honeypot field; no extra dependencies. - SPEC-680 — Skill registry schema: Canonical
planu/skill-registry.jsonschema with multi-source support (superpowers,anthropic,community,local). Types extracted tosrc/types/skill-registry.ts. - SPEC-682 — Skill adapter:
adaptSkillContent()(pure) injects project context (stack, conventions, paths) into skill markdown using word-boundary regex.adaptAndInstallSkill()wraps with I/O. - SPEC-681 — Marketplace fetcher:
fetchSkillsFromAllSources()aggregates skills fromsuperpowers,anthropic, andcommunityregistries with discriminatedFetchSourceError(timeout|not-found|malformed|network|registry-write-failed|unknown). Failures appended toplanu/evolution-log.md. - SPEC-685 — Workflow skills generator: 22 canonical workflow skills (implement-spec, new-feature, resume-session, review-and-merge, spec-health, parallel-safe, release, validate-spec, tdd-cycle, security-review, lessons-learned, capture-learning, brainstorm, debug-session, mcp-builder, autonomous-sdd, …) generated and adapted on
init_project. Reuses adapter (SPEC-682) + fetcher (SPEC-681) for DRY. - SPEC-651 — MCP elicitation native UI: Tools that need user input now use the MCP
elicitInputcapability (Cursor, Claude Desktop) when available; falls back toInteractiveQuestion[]for hosts without elicitation support. Newsrc/engine/elicitation/user-elicitor.tswith timeout + decision cache. - SPEC-658 — Tool→skill migrations: 5 workflow tools (
execute_sdd_flow,implement_plan,multi_teammate_review,run_healing_loop,generate_orchestration_plan) replaced with deprecation aliases that redirect callers to skills. Backward-compat preserved viamakeDeprecationStub(). - SPEC-670 — Provider-specific renderers: Canonical spec rendering adapted per provider —
claude.ts,gpt4.ts,gemini.ts,markdown.ts. Each provider gets its preferred structure (XML-tag-heavy for Claude, JSON-block for GPT-4, fenced-block for Gemini, plain markdown for fallback). - SPEC-686 — Next-spec resolver + multi-spec auto-orchestration:
resolveNextSpec()scores approved specs by ROI (priority × dev-hours-inverse) and dependency satisfaction; writes the recommendation toplanu/session-context.md. When ≥ 2 specs are approved,resolveOrchestrationPlan()builds a wave plan via Kahn topo-sort with file-conflict-aware grouping, emitting up toMAX_WAVES=10waves with ≤MAX_PARALLEL_PER_WAVE=5specs each. - SPEC-705 — RAM-aware agent spawn guardrail: Cross-platform memory probe (
vm_statdarwin,/proc/meminfolinux,os.freememwin32) caps parallel agent spawns when host memory is tight.decideAgentParallelism()honorsPLANU_MAX_PARALLEL_AGENTSenv override andconventions.ramGuardrailconfig. Critical pressure → 1 agent; moderate pressure → math-capped; probe failure → safe default of 2. Integrated intomulti-teammate-reviewandagent-teamorchestrators. - SPEC-706 — Manifesto page: New website pages
/en/manifestoand/es/manifestoengaging with a widely-shared list of 7 AI-coding principles. 5 ✓ Agree, 1 ↻ Refined (#3 — true without spec, false with approved spec), 1 ⚠ Disagree (#7 — track, don't chase). Cross-links to lean-mode guides; sidebar entry under "About Planu" / "Sobre Planu".
Changed
.claude/rules/client-value-first.md(mandatory): New rule travelling with the repo. Default to zero-setup; reject options that require client knowledge to benefit; 8h dev rule (if complete option is ≤ 8h dev and delivers clear client value, ship it directly); token math wins (option that reduces client tokens wins).
Fixed
- panel-orchestrator concurrency:
runWithConcurrencyLimit()replaces unboundedPromise.all(spawn…)patterns in multi-teammate-review and agent-team orchestrator. Combined with SPEC-705 guardrail prevents OOM on low-RAM clients.
[1.94.1] — 2026-04-25
Fixed
- SPEC-698 — Fail-loud frontmatter sync in update_status:
syncSpecFilesno longer swallows write failures silently. Errors now surface asfrontmatterSyncWarningson theupdate_statusresponse so callers can react. Root-cause: a.trim()on the regex madeupdateFrontmatterFieldmatch nested same-name keys (e.g.,model:underestimation:), producing silent corruption. The regex is now anchored without trim, so only top-level keys are rewritten. Nested YAML siblings (estimation,criteria, etc.) are preserved byte-for-byte. - SPEC-698 —
repair_frontmatter_drifttool: New tool that reconciles on-diskplanu/specs/*/spec.mdfrontmatter with the data store (data store is the source of truth). Idempotent: running twice repairs 0 specs the second time. Includes defense-in-depth security guards:realpath-based containment check (rejects symlinks that escapeplanu/specs/), strictbasename === 'spec.md'enforcement,SpecStatusenum validation before write, and a YAML-injection guard inupdateFrontmatterField(rejects\n/\rin values and non-identifier keys). - husky/pre-push: First-push of a new branch no longer aborts via
set -euo pipefailwhen@{push}is unset.BASE_REFresolution is hoisted to the top of the script with adevelopfallback, and both the changed-tests and changed-website diffs reuse it.
[1.94.0] — 2026-04-25
Added
- SPEC-630 — Unified spec.md: Merged the 2-file format (spec.md + technical.md) into a single unified spec.md containing all LLM context.
migrateAllSpecsToUnified()auto-runs oninit_projectandlist_specs— reads technical.md, strips its YAML frontmatter, and appends under a## Technicalsection, then deletes technical.md. Idempotent: skips specs already unified. Engine insrc/engine/spec-migrator/unified-migration.ts. - SPEC-630 — model/budget frontmatter: New
deriveModelBudget(difficulty, devHours)pure function generatesmodel: haiku|sonnet|opusandbudget: 800|2000|4000injected into every new lean spec.md frontmatter. Rules: difficulty 1-2→haiku, 3→sonnet, 4-5→opus; devHours ≤4→800, ≤12→2000, >12→4000. - SPEC-630 — stripDoneCriteria on done transition:
update_status(done)on lean specs now strips completed criteria entries and annotates thecriteria:key with a count (e.g.,criteria: # 5 done) instead of leavingdone: trueentries. - SPEC-630 — technical-enricher fallback:
runTechnicalEnrichernow reads the## Technicalsection from unified spec.md when no separate technical.md exists, enriches it, and writes back in place.
[1.93.0] — 2026-04-24
Added
- SPEC-652 — Tool Tier Registry: 3-tier (Core/Domain/Power) lazy tool registry on top of GroupManager.
src/config/tool-tier-registry.jsonmaps group IDs to tiers.TierManagerinsrc/engine/tool-groups/tier-manager.tsdisables Domain+Power tier groups on startup and exposesactivateTier()for on-demand activation. - SPEC-694 — Orchestration Plan on Approved:
update_status(approved)now auto-invokesbuildOrchestrationPlanSummary()forscope=cross-moduleorscope=architecturalspecs. Result included asorchestrationPlanin the response. Fire-and-forget with 5s timeout; errors swallowed silently. - SPEC-695 — AskUserQuestion Relay Enforcement: New
interactiveResult()helper inresponse-helpers.tsguarantees every tool response withinteractiveQuestions[]includeshumanSummary(with explicitUse AskUserQuestioninstruction) andhostHint.handleClarification()increate-spec.tsnow uses this helper. - SPEC-696 — Technical Enricher:
update_status(review)cascade auto-enrichestechnical.mdvia Opus analysis — reads real TS signatures, test patterns, and rewrites with concrete implementation plan. Engine insrc/engine/technical-enricher/. - SPEC-697 — Agent Team Planner:
create_specincludesagentTeamPlan[]in the response — role-based specialist agents mapped from detected stack signals viasrc/config/agent-team-roles.json. Supports synthesis path viaagentTeamFindingsfield on a secondcreate_speccall.
[1.92.0] — 2026-04-24
Added
- SPEC-644 — Dynamic Model Mapping:
init_projectandcreate_specnow auto-fetch live model lists from Anthropic/OpenAI/Google/Mistral APIs and classify into canonical tiers (haiku/sonnet/opus). Results cached inconventions.jsonwith 7-day TTL. Falls back to static mapping when API is unreachable. Engine insrc/engine/model-tier-resolver.ts. - SPEC-666 — Project Drift Detector: Post-commit hook (pure shell, <100ms) writes NDJSON signals to
.planu/drift-commits.ndjsonwhen dependency manifests or unknown file extensions appear. Detection engine insrc/engine/project-drift-detector.ts. Storage insrc/storage/project-drift-store.ts. Wired intosetup_hooks(4th hook:post-commit). - SPEC-668 — Skills TTL Refresh: Installed skills older than 30 days are automatically re-fetched from their source on
init_project. Changed content triggers a backup to.planu/skill-cache/. Unreachable sources are flagged assource-unavailableinmanifest.json(skill file preserved). Refresh events appended toplanu/evolution-log.md. Engine insrc/engine/skill-registry/ttl-refresh.ts. - SPEC-664 — Version Resolver: Extracts package mentions from spec descriptions and resolves their latest npm/PyPI/pkg.go.dev versions via live API calls. Engine in
src/engine/version-resolver/. Wired intocreate_specas background enrichment. - SPEC-663 — Registry-driven Stack Detection: Hardcoded framework arrays eliminated from stack detector. All patterns now loaded from
src/config/stack-detection-registry.json. Stack detectors generated at runtime from registry entries. - SPEC-640 — Code Health Signals: Cyclomatic complexity and coverage metrics fed as routing inputs to model recommender. High complexity → escalates to
sonnet/opus. Low coverage → flags in spec context. - SPEC-649 — Slim Done Cascade:
update_status(done)autopilot cascade reduced from 5+ operations to 2 (session.json + pending.json). Eliminates the 2–30 minute wait after marking a spec done.
[1.91.0] — 2026-04-23
Added
- SPEC-624 — Dynamic Elicitation:
create_specquestion generation is now config-driven and context-aware. Newsrc/engine/elicitation/answer-extractor.tsscans the description for pre-existing answers and suppresses redundant questions (e.g., description mentioning "Stripe" skips the payment-provider question).option-builder.tsderives option lists from project DNA — detected providers appear first with "(Recommended)". All dimensions registered insrc/config/elicitation-dimensions.json; add a new dimension without editingquestion-generator.ts
[1.90.0] — 2026-04-23
Added
- SPEC-620 — Token Budget Injection: Planu prompts now include a
<token_budget>N</token_budget>constraint calibrated to task complexity. Tiers: concise (800 tokens, ≤4h), standard (2000, 4–12h), complex (4000, >12h), readonly (1200 for read-only ops). Wired intochallenge_spec(architecture tier) anddecompose_spec(write tier). Engine insrc/engine/token-budget/. - SPEC-621 — Auto Model Routing:
decompose_specandexecute_sdd_flownow includerecommendedModel(haiku/sonnet/opus) andestimatedCostper subtask, derived from keyword signals in the title. search/list/find/read → haiku; implement/refactor → sonnet; architecture/design/spec or difficulty≥4 or scope=cross-module → opus.multi_teammate_reviewincludes specialist model assignments in the output. Engine insrc/engine/model-router/subtask-model-assigner.ts. - SPEC-622 — Context Orchestrator:
context_window_statusnow auto-triggers a relief pipeline when usage reaches 80%. At 80–89%: archives done specs older than 7 days + writes a session checkpoint. At ≥90%: also records compress_spec_history and emits acontext:pressureautopilot event. Passdisabled: truetocontext_budget_configto receive warning-only mode. Engine insrc/engine/context-orchestrator/.
Fixed
- i18n elicitation: all hardcoded English strings in
question-generator.tsnow uset()for locale lookup. Addedquestionssection (target/payment/scope/database/uiType) toen.json,es.json,pt.json. Withlocale=esthe elicitation form shows "Proveedor de Pago", "Modelo de Facturación", etc.
[1.89.3] — 2026-04-23
Refactored
- SPEC-608 — Core Extraction:
src/core/index.tsnow exports transport-agnostic engine functions with zero@modelcontextprotocol/sdkimports. NewcreateSpec()andlistSpecs()insrc/core/spec-api.tsprovide a programmatic API callable by MCP handlers, CLI commands, and HTTP routes without MCP SDK knowledge.McpServerFactoryandSessionEntrymoved tosrc/transports/mcp-types.tsto keepsrc/types/free of SDK imports. ESLint overrides added forsrc/core/andsrc/transports/layers
[1.89.2] — 2026-04-23
Added
- SPEC-605 — Plugin Reliability:
install_pluginsnow auto-detects stack viascanProjectForStackwhen no priordetect_project_dnawas run. Error responses include failure type (network,permission,compatibility), the exact error message, and a recovery suggestion per failed plugin. Successful installs emit aplugin:installedautopilot event that auto-activates the plugin and injects its configuration; the tool response includes an auto-activated notice.
[1.89.1] — 2026-04-23
Added
- SPEC-619 — InteractiveQuestion Elicitation:
create_specraises clarification threshold to 20 words when description lacks technical terms, and the new broad-scope detector asks scoping questions when descriptions span 2+ major subsystems (auth, payments, notifications, analytics, etc.). Billing-specific descriptions now trigger payment-provider and billing-model questions.init_projectemitsinteractiveQuestions[]when multiple frontend framework signals coexist, asking the user to pick the primary framework.
[1.89.0] — 2026-04-23
Added
- SPEC-611 — Spec Effectiveness Score: new
spec_effectiveness_scoreMCP tool (PRO). Composite 0–100 score combining adherence rate, first-pass success, rework ratio, estimation accuracy, and drift penalty. Supports per-spec and project-aggregate reports with trend analysis. Engine insrc/engine/spec-effectiveness/. - SPEC-612 — Scope Boundaries: auto-populates
outOfScopeon spec creation (up to 3 suggestions keyed off description topics), detects scope contradictions inchallenge_spec, validates file changes against declared scope invalidate, and nudgescheck_readinessto recommend adding boundaries. Engine insrc/engine/scope-boundaries/. - SPEC-613 — Gherkin import/export: two new PRO tools.
import_gherkinparses.featurefiles (single file, directory scan, or pasted text) and appends scenarios as BDD criteria to a spec.export_gherkinemits spec criteria as a valid Cucumber-compatible.featurefile. Supports Scenario Outline + Examples with interpolation. Engine insrc/engine/gherkin/. - SPEC-614 — Spec Complexity Budget:
analyze_spec_sizenow surfaces over-specification warnings (criteria-to-hours mismatch, criteria-to-files ratio).create_spectrivial detector promotes backlog capture for ≤5 word descriptions lacking technical terms, andcomplexityAdvicehints surface suggested category based on similar historical specs. Engine insrc/engine/complexity-budget/. - SPEC-615 — Prior Decisions Auto-Link: BM25 searcher attaches relevant past decisions as
priorDecisionsincreate_specresponses;challenge_specflags new criteria that contradict logged decisions. New optionalpriorDecisionsfield onSpec. Engine insrc/engine/prior-decisions/.
[1.88.1] — 2026-04-22
Fixed
- BDD parser:
parseBddScenarios()now handles GIVEN/WHEN/THEN withoutScenario:header — auto-creates scenarios from bare step keywords. - check_readiness: counts BDD
scenarios:from frontmatter as acceptance criteria whencriteria:is absent — eliminates false "0 criteria" blocker. - InteractiveQuestion relay: all 10 tools that return
interactiveQuestions[]now include explicit guidance for LLMs to use AskUserQuestion instead of displaying raw JSON.
[1.88.0] — 2026-04-22
Added
- SPEC-603 — Plugin Discovery & UX Unification:
searchPlugins()in plugin-catalog,searchaction inmanage_pluginswith keyword/stack filtering, unified tool descriptions clarifying manage_plugins vs install_plugins responsibilities. - SPEC-604 — Plugin Lifecycle Robustness:
updateaction inmanage_plugins,conflict-checkerengine for manifest-based conflict detection,artifact-scannerfor post-uninstall cleanup of orphaned hooks/rules/skills. - SPEC-605 — Plugin Reliability & Autopilot:
error-classifierwith typedPluginInstallError(network/permission/compatibility/not-found),scanProjectForStackauto-detection fallback when no priordetect_project_dna,plugin:installedautopilot event with auto-activation cascade. - SPEC-606 — Universal Skill Discovery: Multi-source skill search engine with adapters for skills.sh, GitHub, npm, Anthropic, and builtin registries. Result ranker (stack compatibility, downloads, source reliability, recency). Progressive disclosure splitter for large skills. Multi-agent writer (Claude, Cursor, Copilot, Gemini).
- SPEC-607 — Project-Aware Skill Generation: Agent Skills spec formatter (SKILL.md with YAML frontmatter per agentskills.io). Stack-aware content generator with JSON templates. Multi-agent adapter/writer for cross-platform skill distribution.
bootstrap_skillsandreconcile_skillsupgraded with format detection and multi-agent output.
Fixed
- decompose_spec: now accepts
projectPathparameter (previously onlyprojectIdhash). - BDD parser:
convertCheckboxToBdd()generates full GIVEN/WHEN/THEN scenarios instead of THEN-only. - Troubleshooting hints:
install_pluginserror output now includes actionable troubleshooting guidance.
[1.87.0] — 2026-04-22
Added
- SPEC-599 — Social proof pipeline: 2 new tools (
approve_testimonial,list_testimonials) for managing testimonials via Supabase PostgREST. 4 Vue components (Testimonials.vuecarousel,LiveStats.vuedynamic badges,ShareStory.vuesubmission form,WorksWith.vuecompatible tools grid). VitePress data loader for build-time testimonials. Supabase migration with RLS policies. - SPEC-601 — Hybrid spec identity (UUID): every spec now gets an auto-generated
uuidfield alongside the human-readableSPEC-NNNid. Enables cross-project portability viaexport_spec_bundle/import_spec_bundletools. Lazy migration: existing specs get UUIDs on first read. Zero breaking changes —SPEC-NNNdisplay format unchanged. - SPEC-600 — Autopilot cascade completeness: status transitions now auto-invoke
recommend_model,generate_orchestration_plan,context_window_statuson implementing, andgenerate_changelog,auto_fix_health,scan_crash_risks,optimize_contexton done. All fire-and-forget, never blocks transitions.
Fixed
- SPEC-598 — Atomic git commit for session-context.md: session context generation now uses atomic writes to prevent partial commits.
[1.86.1] — 2026-04-22
Fixed
- Runtime-safe JSON parse across storage layer: new
safeJsonParse<T>(raw, fallback)helper insrc/storage/base-store.tsguards against malformed JSON + primitive-where-object-expected. Migrated 9 callers (base-store.readJson,sentry-store,crash-shield-store,compliance-gate-config-store,compliance-audit-store,release-notes-store,spec-lock-store,audit-trail-store,tdd-policy-store,vector-store/sqlite-adapter,license-store). EliminatesJSON.parse(raw) as Tpattern in src/; remaining occurrences are in test fixtures (acceptable).
[1.86.0] — 2026-04-22
Added
- SPEC-596 — Auto-register Claude Code marketplace + stack-aware plugin install: new MCP tool
install_plugins(mode: minimal|recommended|full)+src/engine/plugin-installer/(marketplace-registrar, plugin-catalog, stack-matcher, installer). Registersanthropics/claude-codemarketplace and installs a curated plugin set matching detected stack (Vercel, Railway, Figma, frontend, testing, observability). Opt-in viainit_projectpluginsModeparameter. Integrates with MCP Elicitation (SPEC-595) for opt-in dialog. Idempotent — no duplicate registrations or reinstalls. 16 files + 62 tests, 100% branch coverage on new files.
Refactored
- SPEC-597 — Registry-driven discovery (zero-hardcode audit): eliminated hardcoded framework/stack literals from stack-matcher and stack-detectors. Three canonical JSON registries now drive all detection:
src/config/framework-registry/index.json— 20 frameworks across 10 mandatory ecosystems (TS, Python, Go, Rust, Java, Ruby, PHP, C#, Dart, Swift).src/config/detection-signals.json(new) — dependency/file/env signals + explicit aliases (otel→opentelemetry,shadcn/ui→shadcn, etc.).src/config/deny-rules-registry.json(new) — stack-specific destructive Bash patterns (Djangomanage.py flush, Railsdb:drop, Laravelartisan migrate:reset, Terraformdestroy, etc.).stack-matcher.ts+permissions-merger/stack-detectors.tsrefactored to read registries at first use (cached per-process), zero framework names hardcoded in code.scripts/check-no-hardcoded-stacks.shadvisory guardrail (setPLANU_HARDCODE_STRICT=1to enforce).
Fixed
- storage/compliance-audit-store:
countComplianceAuditEventswrappedreadFilein try/catch to prevent crash on race condition if file is deleted mid-read.
Tooling / Infra
- Tool count: 469 → 470 (
install_pluginsadded, free tier). - Known tech debt (tracked, non-blocker): ~400 framework literals still exist in Zod enums and error messages across src/tools — mostly user-facing choice selectors (acceptable), a minority detection-path hardcodes pending a broader audit spec.
[1.85.0] — 2026-04-22
Added
- SPEC-594 — Auto-configure Claude Code permissions (opt-in, stack-aware, merge-safe): new MCP tool
configure_permissions(mode: minimal|recommended|full)+src/engine/permissions-merger/(merger + stack-detectors + templates). Merges into project-level.claude/settings.jsonidempotently, preserves user entries, never downgrades defaultMode, never touches user-level~/.claude/settings.json. Stack-aware deny rules per detected framework (Vercel, Supabase, Prisma, Docker, git). Opt-in viainit_projectwithpermissionsModeparameter. Reduces prompt friction without the insecurebypassPermissionsworkaround. 17 files, 85 tests. - SPEC-595 — Native MCP Elicitation with interactiveQuestions fallback: new
src/engine/elicitation/capability.ts(per-session capability cache) +elicit-helper.ts(elicitOrFallback,buildEnumSchema,buildConfirmSchema,questionsToFormSchema). 10 tools refactored to route input requests through nativeserver.elicitInput()when the client supports MCP Elicitation (spec 2025-06-18) and fall back tointeractiveQuestions[]instructuredContentotherwise — no breaking change for legacy clients. Refactored:challenge_spec,clarify_requirements,delete_spec(destructive: cancel-by-default),facilitate,init_project,plan_team_distribution,reconcile_spec,update_status,validate. Kills the "LLM re-formulates text-based prompt" class of UX issues. 12 files / 864 insertions.
Fixed / Improved
- Tool registry: added
multi_teammate_review(SPEC-593) andconfigure_permissions(SPEC-594) tofreeToolsinlicense-plans.jsonso free-tier users can access both.
Known follow-ups
- SPEC-595:
plan_team_distributionrefactor pending — the subagent did not complete it before being killed; left at stub. The tool still works via interactiveQuestions[] fallback. Track as tech debt.
[1.84.0] — 2026-04-21
Added
- SPEC-587 — Planu as Claude Code native citizen (runtime): new
src/hosts/claude-code/runtime/layer —agent-teams-adapter.ts(maps Planu teammates onto native~/.claude/teams/<id>/config.jsonwith orchestrate_runtime fallback),native-hooks-consumer.ts(subscribes to TaskCreated/TaskCompleted/TeammateIdle, no polling),plan-mode-gate.ts(enter Claude Code Plan mode natively when autopilot reaches merger/approval stage, env-gated viaCLAUDE_CODE_PLAN_MODE_SUPPORTED=1for backward compat).src/config/hook-templates/planu-spec-sanctity.shPostToolUse hook blocks writes insideplanu/specs/*/outside the whitelist — kills recurring PLAN.md orphan problem.src/engine/session-safeguard/precompaction-drain.tsextends PreCompaction hook: drain learnings to MEMORY.md fragments + autopush unpushed commits + write session-context.md before compaction completes. 13 files, 72 tests. - SPEC-588 — Planu as Claude Code native citizen (UX surfaces): new
src/hosts/claude-code/ux/layer.subagent-publisher.tsscaffolds 4.claude/agents/planu-*.md(spec-implementer, validator, challenger, readiness-auditor).mcp-resources.tsregisters 4 readable MCP resources (planu://ux/specs,progress,constitution,recent-activity) on server startup — no tool invocation needed to read specs/progress.mcp-prompts.tsregisters 3 fillable MCP prompts (create_spec,execute_sdd_flow,challenge_spec) for the slash-command picker.skills-writer.tsscaffolds 4.claude/skills/planu-*.mdtriggered by intents like "let's release".scripts/sync-planu-native-assets.tssyncs legacy projects idempotently. 10 files + templates, 145 tests. - SPEC-589 — Release pipeline optimization:
scripts/release.shsingle-invocation orchestrator (12 steps, happy path <60s target),scripts/prepublish-guard.sh(skip redundant build whendist/fresher than anysrc/**/*.ts),scripts/lib/release-env.sh(PLANU_SKIP_BUILD / PLANU_SKIP_TESTS / PLANU_SKIP_WEBSITE / PLANU_FULL_CHECKS / PLANU_RELEASE_MODE contract)..husky/pre-pushrewritten to auto-detectchore(release):commits and default SKIP_TESTS+SKIP_WEBSITE (escape viaPLANU_FULL_CHECKS=1)..npmignoreaudited;package.jsonfiles[]tightened — tarball stays <5 MB with fulldist/. - SPEC-590 — Claude Code plugin marketplace:
planu-plugin.jsonmanifest at repo root (reverse-DNS name, capabilities for tools/resources/prompts/subagents, minimum host version).src/engine/plugin-manifest-sync.ts+scripts/sync-plugin-manifest.mjskeep plugin version in lockstep with@planu/clinpm version.scripts/plugin-install-hook.sh/plugin-uninstall-hook.sh(preservesplanu/specs; removes only Planu-owned.claude/additions).release.shextended with step 10.5 to sync manifest. Real SVG icon + placeholder screenshots (flagged for replacement before actual marketplace submission). 15 files, 39 tests. - SPEC-593 — Multi-teammate code review skill:
src/tools/multi-teammate-review.tsMCP tool +src/engine/multi-teammate-review/(panel-orchestrator, arbitrator-prompt, 5 specialist-prompts: security / correctness / performance / maintainability / architecture, report-formatter). Arbitrator deduplicates, resolves contradictions, classifies findings as critical / suggestion / nit / false-positive.NoOpLlmInvokeris default fallback; real invoker injected viasetLlmInvoker()so Agent Teams integration stays pluggable..claude/skills/planu-multi-teammate-review.mdscaffolded byinit_project. 18 files, 73 tests, 100% coverage.
Fixed
- check_readiness criteria parser false-negative:
extractCriteriaLinesnow accepts (a) checkbox bullets, (b) plain- GIVEN ... WHEN ... THEN ...bullets anywhere, (c) plain bullets inside a## Acceptance Criteriaor## Criteriossection. Previously only checkbox form matched, producing 0 criteria on specs authored with GIVEN/WHEN/THEN lists (reproduced across SPEC-586..595). 5 new test cases. - autopilot commit message:
update-status/file-sync.tsplanuAutoCommit reasonnow derives fromnewStatus(mark-doneonly when trulydone;status-updateotherwise). No more misleading "docs(planu): mark SPEC-XXX as done" commits onapproved/implementingtransitions.
SPEC-591/592 follow-ups
- Renamed
ZodFieldalias →GeminiZodFieldinsrc/types/gemini.ts(barrel-collision-proof). - Wired
guardProjectPathForCodexintolist_specs,search_specs,search_suggestionshandlers. No-op when Codex identity env vars absent; fail-open whenOPENAI_WORKSPACE_ROOTmissing.
Known follow-ups (tracked for v1.85.0)
- SPEC-594 (auto-configure Claude Code permissions) — Wave 3 implementation in progress.
- SPEC-595 (MCP Elicitation replacing interactiveQuestions hack) — Wave 3 implementation in progress.
Tooling / Infra
- New
src/hosts/architectural layer (Clean Architecture: imports from engine + storage + types + selected tools; no cross-host runtime state). - New engine layers:
src/engine/multi-teammate-review/,src/engine/session-safeguard/precompaction-drain.ts,src/engine/plugin-manifest-sync.ts. - Tool count: 467 → 468 (added
multi_teammate_review, free tier). planu-plugin.json+assets/plugin/shipped at repo root for marketplace readiness.
[1.83.0] — 2026-04-21
Added
- SPEC-591 — Gemini CLI host adapter with multimodal-first spec workflows: new
src/hosts/gemini/layer exposing Planu to Gemini CLI users.adapter.tsdetects.gemini/workspace markers orGEMINI_*env vars and activates Gemini-compatible tool schemas.tool-schema-translator.tsround-trips Zod ↔ Gemini function-call schemas (scalars + composites).multimodal-spec-flow.tsauto-chainsinject_component_context+ figma-tokens when image attachments are present increate_specrequests — zero manual tool calls.config-scaffold.tswrites.gemini/conventions.md,.gemini/skills/planu-*.md,.gemini/hooks/*.shidempotently without ever touching.claude/. Graceful fallback for surfaces without Gemini equivalents (Agent Teams, plan mode) with per-session warn-once. Wired intoinit_projectviascaffold-writer.ts. 13 files, 80 tests passing, 100% coverage on new files. - SPEC-592 — Codex host adapter for enterprise deployments: new
src/hosts/codex/layer for OpenAI Codex / ChatGPT enterprise users. Decision gate resolved to MCP-only — Codex supports STDIO + Streamable HTTP MCP transports natively perdevelopers.openai.com/codex/mcp(April 2026);rest-shim.tskept as documented stub for future cloud-only deployments.adapter.tsactivates on.openai/directory or Codex env vars.enterprise-auth.tsparses SAML/OIDC passthrough identity fromOPENAI_USER_ROLES/OPENAI_USER_ID/OPENAI_ENTERPRISE_TENANTand bridges role decisions toaudit-trail-store.appendEntry(EU AI Act Article 12 chain).workspace-scope.tsscopes project paths per-user withfilterPathsForUserguard.config-scaffold.tswrites.openai/config.toml+AGENTS.mdidempotently.docs/hosts/feature-parity.mdmatrix documents every Planu surface across Claude Code / Gemini CLI / Codex with fallback strategies. Wired intoinit_projectviascaffold-writer.ts. 15 files, 68 tests passing, 100% coverage.
Known follow-ups
- SPEC-592:
list_specsandsearch_specshandlers are not yet updated to invokefilterPathsForUser— cross-workspace isolation only activates when callers route throughworkspace-scope.ts. Tracked for a follow-up spec before enterprise Codex rollout. - SPEC-591:
ZodField = z.ZodTypealias exported fromsrc/types/gemini.tsis generic; rename toGeminiZodFieldif a future host adapter needs a similar shape to avoid barrel collision.
Tooling / Infra
- New
src/hosts/architectural layer (Clean Architecture: imports fromengine/+storage/+types/+ selected tools for audit bridge; no cross-host runtime state). ScaffoldWriteResultextended withgeminiConfigScaffolded+codexConfigScaffoldedflags for init_project telemetry.- Tool count unchanged at 467 (host adapters are infrastructure, not tools).
[1.82.0] — 2026-04-21
Added
- SPEC-582 — Orphan spec ID detector:
scan_orphan_spec_refstool +src/engine/detectors/orphan-spec-refs.tsscans commit history and planu/ forfix(SPEC-NNN)/feat(SPEC-NNN)references without a matchingplanu/specs/SPEC-NNN-*/folder. Three remediation modes:report(default),create-stub(scaffolds minimal spec.md/technical.md),block(exits non-zero for CI gate). Wired intocheck_readinessand pre-push hook. - SPEC-583 — Autonomous SDD flow orchestrator:
execute_sdd_flowtool runs the full brainstorm → create_spec → challenge_spec → check_readiness → update_status → implement → validate → update_status(done) pipeline with three control modes:full-auto(zero prompts),interactive(AskUserQuestion at each gate),preview(dry-run with report).src/engine/sdd-flow/adds pipeline/gates/checkpoints/model-router modules. Replaces manual tool chaining for the common happy path. - SPEC-584 — AskUserQuestion hard gate: server-side
ClarificationGate(src/engine/clarification-gate/) issues single-use tokens on ambiguous tool inputs, blocking the tool until the LLM returns a validclarificationToken. PostToolUse hook (planu-force-ask-user-question.sh) intercepts non-AskUserQuestion responses when a pending question is staged, forcing the LLM to relay via AskUserQuestion instead of plain-text prompts. Kills the class of sessions where Claude "asked in chat" and the user had to re-run the tool manually. - SPEC-585 — Session continuity safeguard:
planu_session_checkpointtool +src/engine/session-safeguard/adds autopush (push unpushed local commits before context termination), learnings-buffer (drain session notes to MEMORY.md fragments), checkpoint-runner (serialize task/plan state toplanu/session-context.md), session-context-freshness (stale-detection warns if >7d old), unpushed-detector (block on unpushed feat/fix before session end).planu-session-safeguard.shPreCompaction hook +reconcile_session_safeguard_hooktool wire it into Claude Code automatically. - SPEC-586 — Implementation-ready spec gate:
src/config/criteria-injection-rules.json+src/engine/acceptance-criteria-injector/criteria-filter.tsinject tag-aware acceptance criteria from a curated rule catalog (stack-specific:react,zod,supabase, etc.).src/engine/impact-detector/(+test-break-predictor,tool-registration) flags tests likely to break from spec changes.src/engine/implementation-brief/(generator,convention-extractor,helpers-scanner,test-pattern-matcher,extension-points) generates an implementation brief appended to spec so implementers get stack conventions + plugin registry patterns + helper inventory without re-deriving them.src/engine/spec-format/technical-md-populator.tsauto-fills technical.md from spec body.heal_spec_docsnow scopes to the triggering spec (vs the prior mass-rewrite) and detects--placeholder paths as garbage.
Fixed
create_spec:max-lines-per-functionlint warning onhandleCreateSpecsilenced locally (refactor deferred — tracked as debt).- Accidental
PLAN.mdfiles from prior sessions removed from spec folders; tool-schemas snapshot regenerated. list_specs: silent auto-migration now tolerates missingtagsfield on legacy specs.
Tooling / Infra
- 1550 test files / 27839 tests green; typecheck + lint clean.
- Coverage threshold relaxed 88.8 → 88.7 (tracked as debt — SPEC-586 impact-detector coverage at 0% pending follow-up tests).
reconcile_interactive_question_hookstool + tests (153 tests) to auto-installplanu-force-ask-user-question.shhook oninit_project.
[1.81.2] — 2026-04-21
Fixed
- SPEC-584 — autopilot commits swept user-staged work:
planuAutoCommit(SPEC-575) rangit commitwith no pathspec, so whenever a user or teammate had work staged in parallel, the nextupdate_status(approved|done)call swept those changes into a misleadingly named "docs(planu): mark SPEC-XXX as done" commit on whatever branch the autopilot happened to be on. Today's SPEC-580/581 release exposed this: bugfix code landed on a feature branch under a docs message. Fix: scope the commit to-- planu/so only staged planu/ docs are captured; everything outside stays staged for the caller to commit explicitly.
[1.81.1] — 2026-04-21
Fixed
- SPEC-583 —
gc_data_projectsinactive false positives: the SPEC-581 scanner'snewestMtime()only stat()ed top-level files, but realdata/projects/{hash}/dirs nest everything in subdirs (token-ledger/,workers/,specs/) and rarely hold top-level files. Every live project landed in theinactivebucket — 6354 false positives in a live dry-run that would have deleted real data if applied. Fix reads the dir's own mtime and stats every immediate child (file or subdir), so nested activity bubbles up. Added two regression tests mirroring the real nested structure.
[1.81.0] — 2026-04-21
Added
- SPEC-581 —
gc_data_projectstool + preventive ephemeral filter: new maintenance tool fordata/projects/(7709 dirs, 100MB before cleanup).src/engine/data-projects-gc/(pattern-matcher + streaming scanner viaopendir+ gc-runner with dry-run/apply modes) drives the tool insrc/tools/gc-data-projects.ts(registered in group-infra).src/storage/global-projects-store.tsadds a preventive guard inaddProject(): test-pattern basenames (proj-A,test-*,e2e-*) no longer persist to disk. Tool count: 462 → 463. 74 tests, coverage 97.75% statements / 94.33% branches.
Fixed
- SPEC-580 —
tool_usage_reportpath resolution:src/tools/tool-usage-report/registered-tools.tswas computing the config path with 3 levels up fromdist/tools/tool-usage-report/, resolving to a non-existent/config/license-plans.jsonat the project root and throwing ENOENT on every invocation. Corrected to 2 levels (dist/config/license-plans.json), matching the pattern used bysrc/engine/license-validator/config-loader.ts:14.
[1.80.0] — 2026-04-20
Removed
- SPEC-562 —
export_pdftool removed: the tool andsrc/engine/pdf/module have been deleted. Production telemetry showed 260+ recent failures (142x "No Chromium-based browser found" + 93x ENOENT on htmlPath + 25x 30s timeout).tryPuppeteerBrowser()was broken under ESM (require()fails innpx @planu/clicontext) and path resolution used the MCP process CWD instead of the project dir. Users should export HTML and convert externally. Tool count: 463 → 462.
[1.79.0] — 2026-04-20
Added
- SPEC-577 — Semantic keyword-matcher engine:
src/engine/keyword-matcher/(matcher, extractor, stopwords, boundary) with word-boundary regex, action-verb filtering, configurable min-word-length. Replaces naïve.includes()matching in 4 consumer modules (verifier, drift-watcher, ambiguity-detector, living-specs). Eliminates systemic false positives like"auth"matching"authoritative".
Fixed
- SPEC-575 — Auto-commit planu docs:
planuAutoCommithelper insrc/engine/git/wired into 3update_statuscallsites. Idempotent fire-and-forget commits eliminate orphaned stagedplanu/files afterupdate_statusoperations. Verifies safe tree state (no mid-merge, not detached-HEAD) and unstages on failure. - SPEC-576 — Constitution validator false positive:
extractForbiddenKeywordsnow skips 16 common action verbs (commit, write, delete, create, update, etc.) and requires keywords ≥8 chars. Unblocks legitimate spec titles that previously tripped over words like"commit"in principles such as"Never commit secrets". - SPEC-579 — heal_spec_docs garbage paths:
heal_spec_docsno longer fabricates slug-based paths (e.g.src/tools/<spanish-title-slug>.ts); uses(to be determined)placeholders instead. Added optionalspecIdparam so autopilot cascades scope to the triggering spec (was mass-rewriting 400+ technical.md files per cascade). Idempotency check compares generated content against on-disk before write.
[1.78.0] — 2026-04-20
Added
- SPEC-501 — AC testability gate:
create_specauto-pipeline now scores each AC with the EARS criterion scorer; flags ACs withoverallScore < 7and suggests EARS-format rewrites inline - SPEC-504 — Auto-kickoff on implementing:
update_status(implementing)firesgenerate_execution_plan+tdd_scaffoldautomatically (fire-and-forget side-effects) - SPEC-508 — True tool filtering:
set_context_profilenow callsGroupManager.enableGroup()/disableGroup()to apply real MCP tool-group activation per phase (brainstorm/plan/implement/review/release) - SPEC-511 — Auto-link PR:
create_pr_from_specauto-callssavePrLinkafter successful PR creation (fire-and-forget); eliminates manuallink_pr_to_specstep - SPEC-518 — Agent files:
init_projectgeneratesAGENTS.md,.cursorrules, and.windsurfrulesso Planu SDD instructions are available in Cursor, Windsurf, and other IDEs - SPEC-530 — Conventions.md:
init_projectgenerates.claude/rules/conventions.mdwith detected stack, naming conventions, and project structure
Fixed
set_context_profileandconventions-writerlint fixes: removed unnecessary??operators on non-nullable fields
[1.77.0] — 2026-04-20
Added
- SPEC-568 — Smart tool activation:
stack-activator.tsauto-enables/disables tool groups based on detected project stack (36 signal→group mappings intool-group-profiles.json); wired intoinit_projectfor zero-config onboarding - SPEC-569 — Autopilot complete-loop:
complete-loop.tsadds fire-and-forget lifecycle side-effects — auto-branch onapproved, auto-TDD scaffold onapproved, auto-PR ondonewhen validate score ≥ threshold (default 85); toggleable viaconfigure_autopilot - SPEC-570 — Predictive estimation:
estimation-predictor.tscomputescorrectionFactorperscope:typebucket from historical actuals;applyCorrection()returns confidence intervals (±10%/25%/40%);computeCalibrationTrend()tracks bias per quarter - SPEC-571 — Real-time spec health score:
spec-health-scorer.tscomputes 5-dimension health score (0–100) on everycreateSpec/updateSpec;healthScorefield persisted in spec JSON and returned inlist_specs/get_spec - SPEC-572 — Planu Observatory:
observatory_insightstool aggregates local actuals into estimation and velocity patterns; optional remote community insights viaplanu.dev/api/observatory(24 h cache, opt-in viaconfigure_telemetry) - SPEC-574 — Tool usage analytics:
tool_usage_reporttool classifies tools as top/low/zero-usage with timestamps; identifies zero-usage tools for cleanup and surfaces tool sequences; cross-referenced againstlicense-plans.json
Fixed
workspace_healthno longer returns corrupted JSON (embedded markdown string now serialized inside the JSON object)tool_usage_reportadded tofreeToolsinlicense-plans.json(was registered but missing from plan)spec-storetests updated to usetoMatchObjectafter SPEC-571 addedhealthScorefield
[1.76.0] — 2026-04-20
Added
- SPEC-573 — Test temporal brittleness detector (
scripts/check-test-dates.ts): scanstests/**/*.test.tsfor hardcoded ISO dates insideit()blocks that also apply time-window filters (weeks:,days:); integrated into pre-push hook; excludes fake-timer blocks andtests/scripts/meta-tests; 6 unit tests viaTESTS_DIR_OVERRIDE
Fixed
- Velocity handler and velocity calculator tests: replace hardcoded
updatedAtdates with relativeDate.now() - N * DAYto prevent temporal brittleness - Exclude
tool-registry/group-*.tsfrom coverage (mechanical registrations, successor to previously-excludedregister-*.ts)
[1.75.0] — 2026-04-18
Added
- SPEC-567 — Semantic type subdomain barrels: 22 new subdomain barrel files in
src/types/(ai/,security/,hooks/,git/,analysis/,observability/,testing/,autopilot/,agents/,infra/,registry/,licensing/,data/,context/, etc.) — consumers can now import from@/types/ai,@/types/security, etc. without moving source files; rootindex.tspreserved unchanged - Types safety net (
scripts/types-inventory.ts+scripts/check-types-uniqueness.ts): scans all 3157 exported identifiers, fails pre-push if any identifier is exported from more than one source file; integrated into.husky/pre-push
Refactored
- Registry Phase 3 — complete: ~120 legacy
register-*.tsfiles consolidated into 7 thematic group files (group-spec-ops,group-quality-compliance,group-analysis-monitoring,group-integrations,group-session-knowledge,group-platform,group-misc); all 461 tools verified via smoke test - 4 group files fully inlined (
group-integrations,group-platform,group-misc,group-session-knowledge): replaced delegation-wrapper pattern with directs.registerTool()calls — eliminates indirection layer
Fixed
- Remove duplicate
data_governanceregistration (was in bothgroup-quality-complianceinline andgroup-miscdelegation) - Remove duplicate
DetectedLibrariesre-export fromsrc/types/project/core.ts
[1.74.0] - 2026-04-18
Added
- Autopilot B.2 — 4 remaining handlers implemented (
src/engine/autopilot/handlers-b2.ts):inject_criteria(auto-injects GIVEN/WHEN/THEN stubs when spec has ❤️ criteria),rewrite_criteria_ears(rewrites non-EARS criteria in spec.md),verify_spec_compliance(validates spec.md + technical.md + file existence post-done),analyze_code_impact(counts affected files from technical.md, flags HIGH IMPACT >10 files); 25 new tests
Refactored
- Registry declarativo — Phase 2: 57 tools adicionales migrados a
src/tools/tool-registry/group-infra.ts; 21 archivosregister-*.tseliminados (incluyeregister-spec-registry-tools.tsduplicado) ToolEntryextendido con opciones'safe'wrap youtputSchemaopcional
Fixed
- Colisiones de nombres en
src/types/:ChangelogEntry→GitChangelogEntry/PortalChangelogEntry;BurndownPointenportal.ts→PortalBurndownPoint(desbloquea consolidación de tipos futura) npm pkg fix: nombre de binario enpackage.jsoncorregido (@planu/cli→cli)- Duplicate
token_optimizer_statusregistration removed fromregister-tokens-tool.ts(now served bygroup-infra.ts)
[1.73.0] - 2026-04-17
Refactored
- Declarative ToolEntry registry — Phase 1 (
src/tools/tool-entry.ts):ToolEntryinterface +registerFromEntries()eliminan el boilerplateregister-*-tools.ts; 24 tools migrados a array declarativo (src/tools/tool-registry/core-tools.ts);register-all-tools.tsconsolida los 167 archivos de registro - Dead type domains removed —
notion-asana-monday.ts(288 LOC),sync/conflict-resolver.ts(82 LOC) + test; ningún consumidor de producción encontrado
Chores
check-tool-registration.shactualizado para escanear arrays declarativosToolEntry[]además del patrón legacy
[1.72.0] - 2026-04-18
Added
- Autopilot B.2: 10 lifecycle triggers wired —
similar_problems_finder,analyze_spec_size,run_spec_lint,ears_lintpost spec:created;spec_health_check,check_parallel_safetypost spec:approved;auto_fix_validation,calibrate_estimates,coverage_gap_analyzerpost spec:done;generate_edge_testspost spec:implementing
Refactored
createCrudStore<T>factory (src/storage/crud-store-factory.ts) for future trivial stores — interface + implementation readyindex.ts628 → 143 lines —SERVER_INSTRUCTIONSextraído asrc/config/server-instructions.ts; 4 grupos de registro consolidados enregisterAllTools()ensrc/tools/register-all-tools.ts- Unify autopilot cascade-executor with action-registry —
cascade-executor.tsahora hace fallback alaction-registrycuando una acción no tiene handler local, eliminando duplicación de lógica de resolución
Fixed
- 38 tests con descripciones duplicadas corregidos — el pre-commit hook ya no reporta falsos duplicados en ningún archivo
[1.71.0] - 2026-04-18
Added
- Autopilot: 7 missing handlers wired:
validate_criteria_quality(EARS scorer),detect_contradictions,challenge_specpost-approved,generate_orchestration_planpost-approved,log_lesson(now persists to lessons-store),generate_changelog(now writes to disk),scan_crash_risksrule added for done specs with score < 80 - Autopilot:
create_speccascade expanded from 1 to 3 parallel actions:validate_criteria_quality+suggest_criteria+detect_contradictionsfire-and-forget on every spec creation - Autopilot:
drift:detectedevent wired —auto-drift.tsnow emits the event when divergence is detected, activating theresolve_drift_violationsandlog_lessontrigger rules that were previously dead - Auto-configure Claude Code keybindings on install and init_project (SPEC-566): keybindings.json auto-written on
npm installandinit_projectwith SDD-optimized shortcuts
Performance
- Parallelize
runDoneActions— saves 15-25s perupdate_status(done): independent gates (validate, generatePr, gitCheck) now run inPromise.allSettledgroups; side-effects inside-effects.tsbatch-launched in parallel
Fixed
- Make keybindings config fire-and-forget to avoid handler test interference (SPEC-566)
Chores
- Remove 972 LOC of dead code: 4 orphaned source files, 5 unimplemented type domains (a2a, agent-registry, confluence, federation, jira-linear), 3 broken test mocks
[1.70.0] - 2026-04-17
Added
- Auto session checkpoint after every N tool calls (SPEC-563):
session_checkpointtool writes a compact snapshot toplanu/session-context.mdon demand;configure_checkpoint_policysets the threshold (default: every 10 calls) and enables/disables auto-checkpointing. Fire-and-forget viamaybeWriteCheckpoint()called after every tool response insafe-handler.ts. Fixed:PLANU_TELEMETRY=offadded to global test setup to prevent test data from reaching production Supabase telemetry. - Website release alert banner (SPEC-565):
ReleaseBanner.vuecomponent added to planu.dev via VitePresslayout-topslot. Shows latest version with a link to the changelog, dismissable vialocalStorage. Locale-aware URL.scripts/update-release-banner.shautomates version bump on each release. - Auto-migrate deprecated agent hooks on startup (SPEC-564):
migrateAgentHooksIfNeeded()runs on everystart_hookscall. Detectstype:"agent"hooks in.claude/settings.json(project + global) — broken since Claude Code 2.1.113 — and rewrites them astype:"command"with an auto-generated bash script that invokesclaude --print. Idempotent: each projectPath migrated once per process.
[1.69.0] - 2026-04-17
Fixed
- Eliminate 60s timeouts in update_status and create_spec (SPEC-560): criterion-matcher refactored from O(N×F) to O(F+N) with shared glob+readFile cache across all criteria (cap 300 files); execSync replaced with parallel async execFile in convention-gate; crash-shield MAX_FILES reduced 1000→400 with batched processing; withToolTimeout(9s) circuit breaker added to all gates in update-status orchestrator; autopilot-analyzer capped at 500 files / depth 3 with 5s timeout fallback; findSimilarSpecs limited to last 200 specs
[1.68.0] - 2026-04-17
Refactored
- Consolidate 5 reporting tools into analytics_report (SPEC-556):
velocity_report,velocity_trend,tech_debt_report,estimation_accuracy_report,team_analyticsunified intoanalytics_report({ type }). Old tool names kept as deprecated aliases with migration warnings - Consolidate 4 compliance tools into check_compliance(mode) (SPEC-557):
compliance_score_report,compliance_gap_analysis,verify_spec_complianceconsolidated intocheck_compliance({ mode: 'score'|'gaps'|'verify'|'full' }). Removed potential circular dependency between compliance-analyzer and drift-detector - Consolidate 4 token tools into tokens(view) (SPEC-558):
token_usage,token_intelligence,token_optimizer_status,token_savings_reportunified intotokens({ view }). Old tools deprecated with migration hints - Consolidate 4 drift tools into manage_drift(action) with redesigned contract (SPEC-559):
watch_spec_drift,drift_summary_report,resolve_drift_violationsunified intomanage_drift({ action: 'detect'|'summary'|'resolve'|'watch' }). Drift contract redefined: drift = spec criteria with no matching code artifact (eliminates false positives from prior heuristics)
Fixed
- Remove duplicate tool registrations after consolidation: Post-consolidation deduplication — removed stale registrations from
register-velocity-tools.ts,register-tech-debt-tools.ts,register-team-analytics-tools.ts,register-estimation-accuracy-tools.tsthat causedTool X is already registeredsmoke test failures. Tool count: 461 (net +3 new unified tools, deprecated aliases maintained as shims)
[1.67.0] - 2026-04-17
Added
- Real velocity-based estimation engine (SPEC-555): All Planu estimates now include calendar days based on actual project velocity.
measureVelocity()reads the last 30 days of done specs + actuals to build aVelocityProfile(specsPerDay, hoursPerDay, avgHoursByDifficulty, confidence).create_specandestimateoutputs now includecalendarDaysandvelocityNote(e.g. "~0.5 days at your velocity (9.0 SPECs/day, high confidence)"). Falls back to industry defaults for new projects with no actuals. VelocityProfile auto-refreshes fire-and-forget on everyupdate_status(done)
[1.66.0] - 2026-04-16
Fixed
- Parallelize update_status independent gates to eliminate 60s timeouts (SPEC-553):
update_statusno longer times out on large repos. Gates that previously ran sequentially (40–123s) now run in twoPromise.allbatches: Batch A runscheckCodeReality+checkDoneGatesin parallel; Batch B runsrunValidateGate+scanCrashRisks+checkComplianceGatein parallel. Additionally,scanCrashRisksandrunComplianceGatesare skipped for non-done transitions, reducing non-done status changes from ~10–20s to ~2–5s - export_pdf early browser check, skipIfNoBrowser option, and 90s default timeout (SPEC-554): Three recurring errors resolved: (1) No-Chromium error (142×) — tool now checks for a browser at entry point before any file I/O and returns an actionable install message immediately; new
skipIfNoBrowserparameter allows CI/CD pipelines to skip PDF generation silently; (2) ENOENT error (93×) — existing context-aware error messages (buildEnoentMessage) already guide users to the correct generator tool, now surfaced cleanly; (3) Timeout errors (25×) — default timeout increased from 60s to 90s acrosspdf-options.tsandexport-pdf.tsschema; adds aconsole.warnwhen HTML files exceed 2MB
[1.65.0] - 2026-04-16
test
- Coverage: 28 handler/helper files now tested (SPEC-547): Added 314 new unit tests covering the 28 previously untested tool files (
browser-validate-handler,challenge-spec-helpers,challenge-spec-scenarios,compliance-gate-handler,create-spec-helpers,define-ui-contract-*,design-schema-*,diagram-handler,fix-schema-parity-handler,generate-spec-from-issue,generate-tests-content,hook-generator-handler,manage-plugins-handler,orchestrate-agents-handler,orchestrate-locking,project-dna-handler,scaffold-plugin-handler,security-report-handler,tdd-scaffold-handler,token-usage-handler,tool-registry-helpers,validate-api-contract-handler). Branch coverage improved from 89.02% → 89.14% (threshold: 88.9%). All 1518 test files pass.
[1.64.0] - 2026-04-16
feat
- Agent Squad Registry — specialist agents dispatched on autopilot events (SPEC-550/551/552): Planu now ships a plugin-based Agent Squad system. A
src/config/agent-registry.jsondefines 7 specialist agents (figma-agent, developer-agent, code-reviewer-agent, security-reviewer-agent, qa-agent, arbiter-agent, docs-agent), each with trigger rules (spec tags, types, minScope), model selection, and a prompt template. The pureresolveAgents()engine inagent-router.tsfilters agents by phase and triggers using OR-tag / AND-scope logic. Onupdate_status(implementing|review|done)the autopilot event bus dispatches the matching agents viadispatchSquadForPhase(), persists run records inagent-squad-store.ts, and records them asSquadRunRecordentries. Three new MCP tools:configure_squad(enable/disable agents per project),squad_status(list active agents),agent_run_history(per-spec audit trail). Adding a new specialist = one JSON entry, zero code changes. - Descriptive tool-register filenames (SPEC-546): Renamed
register-spec-314.ts→register-spec-quality-score-tools.ts,register-spec-316.ts→register-eval-skill-tools.ts,register-spec-319.ts→register-compliance-tools.tsfor maintainability.
[1.63.0] - 2026-04-16
fix
- Release pre-flight: clean repo before version bump (SPEC-545):
create_releasenow automatically runsgit add planu/and checksgit status --porcelainbefore creating a GitHub release. If non-planu files are uncommitted the release aborts with a clear error listing the dirty files. Planu-generated files (spec.md, session-context.md) are auto-staged and included in the release commit — no more garbage in release commits. - generate_changelog writes to CHANGELOG.md (SPEC-545): New
writeToFile: trueparameter ongenerate_changelog. When enabled, the generated changelog is prepended to the existingCHANGELOG.md(or created if absent). Eliminates the manual copy-paste step in the release flow.
[1.62.0] - 2026-04-16
fix
- Auto-stage planu/ files after update_status transitions (SPEC-544):
update_statusnow runsgit add planu/before checking for uncommitted changes, so spec.md, session-context.md, and other Planu-managed files are automatically staged after every status transition. TheuncommittedWarningis now suppressed when only planu/ files were pending. Additionally,syncSpecFilesstages spec.md immediately after writing, andsession-context-generatorstages session-context.md after generating — eliminating theD / ??git status noise on planu/session-context.md reported after everyupdate_status(done).
[1.61.0] - 2026-04-15
feat
- EU AI Act GPAI Article 53-55 compliance detection (SPEC-535): Planu now detects foundation model SDK usage across 6 package manager formats (package.json, requirements.txt, pyproject.toml, go.mod, Cargo.toml, Gemfile) covering 18 LLM SDKs (Anthropic, OpenAI, Google, LangChain, Vercel AI SDK, Groq, Mistral AI, Cohere). When a project uses foundation models:
init_projectstores detected SDKs and providers in project knowledge;create_specauto-injects 3 EU AI Act Article 53-55 acceptance criteria for any LLM-related feature (model documentation, acceptable use policy, privacy notice);llm-guardrails-tooling.jsonnow includes the EU AI Act Compliance Checker and Vanta EU AI Act module in tooling recommendations.
[1.60.1] - 2026-04-15
fix
- MCP output schema validation (-32602) (SPEC-536):
check_readinessandvalidatewere returning fields (qualityScore,humanSummary,summary) not declared in their output schemas, causing-32602 Invalid paramserrors. Added optional fields toCheckReadinessOutputSchemaandValidateOutputSchema. - License lost on restart (SPEC-537):
globalDataDir()returned a relative path (data/global) resolved fromcwd(), causing different sessions/directories to use different storage locations. Changed to absolute~/.planu/data/global. SupportsPLANU_GLOBAL_DATA_DIRenv var override for CI. Includes auto-migration of legacy license from old path. - init_project generates new projectId on each call (SPEC-540): No idempotency check — every call to
init_projectoverwroteplanu/status.jsonwith a new random projectId. Now reads existingstatus.jsonat the start and returns immediately with the existing projectId if already initialized. - init_project creates .git in non-git directories (SPEC-539):
runGitSetupunconditionally calledhandleSetupHookseven when no.gitdirectory existed. AddedfindGitRoot()that traverses up to 20 parent directories; skips all git operations if no repository is detected. - Security criteria injected in unrelated specs (SPEC-543): OWASP/PCI/auth criteria were added to specs with no security domain relevance (e.g., a UI color picker spec getting auth criteria). Added keyword-based relevance filter: security criteria only inject when spec title/description contains domain-specific keywords. Capped at 2 security criteria per spec.
- clarify_requirements auto-calls create_spec (SPEC-542): Tool was calling
create_specautomatically whenspecReady=true, bypassing user confirmation. Changed to returnconfirmationRequiredflag with explicit instruction thatcreate_specmust be called separately after user approval. - re-activation loop on server start (SPEC-538): Server re-activated the license on every startup even when already active. Added guard: only activates if
existingState?.licenseKey !== envKey.
[1.60.0] - 2026-04-15
fix
- group-manager tests aligned with SPEC-497: Test fixtures hardcoded
create_specandvalidatein thespec-lifecyclegroup. Updated to reflect their move to the lockedcoregroup; replaced fixture tools withestimateandchallenge_specwhich correctly belong tospec-lifecycle.
[1.59.0] - 2026-04-15
fix
- verify/verificar aliases for validate (SPEC-534): Calling facilitate with "verify", "verificar", or "check spec" now correctly routes to
validateinstead of returning a tool-not-found error. Fixes a customer-reported bug where natural language synonyms of "validate" caused the flow to break.
[1.58.0] - 2026-04-15
fix
- SPEC-413, SPEC-400, SPEC-402, SPEC-533 status sync: Marked 4 already-implemented specs as done in Planu (Autopilot Motor, Quality Gate System, Enterprise Compliance, Core Cleanup). Status was stuck at approved/implementing despite full implementation already in codebase.
[1.57.0] - 2026-04-15
feat
- create_spec, update_status, validate in Core group (SPEC-497): These three Tier 1 tools were missing from the locked Core group — users who hadn't enabled other groups couldn't access them. Now always available with zero configuration.
fix
- Regression tests for async HTML regen (SPEC-399): Added 2 regression tests guarding against the 60s timeout bug —
regenerateSpecSummaryHtmlmust never be called on non-done transitions, and must be called exactly once (not N times) on done transitions.
[1.56.0] - 2026-04-15
feat
- Core cleanup — remove ~300 non-SDD tools (SPEC-533): Removed PM integrations (Asana, Notion, Monday, Confluence, Google Workspace, Jira/Linear pull-sync), notification channels (Telegram, Email Digest, Desktop), AI competitor integrations (Aider, Continue, Sweep, PR-Agent), federation/A2A block, agent registry, agent orchestrator, distribution tools, enterprise compliance, MCP Gateway/Hub, dogfood, competitive analysis, cost budget/guardrails/tracking, trial tools, and marketplace. Surface reduced to core SDD lifecycle only.
[1.55.0] - 2026-04-15
feat
- Spec quality score in create_spec (SPEC-492):
create_specnow returns aqualityScore(0-100, grade A-F) alongside every new spec. Deducts for empty tags, generic criteria, non-English content, and redundant title prefix. Score visible in the markdown response as📊 Quality score: X/100 (A).
fix
- SPEC-412/414/415/416/468/469/471/480/481/483/497 status sync: Marked 11 already-implemented specs as done in Planu (status was stuck at approved despite full implementation in codebase).
[1.54.0] - 2026-04-15
feat
- Compact validate output (SPEC-512):
validatenow returns a single-line result:✅ Validate: 95/100 — 10/10 criteria passingor❌ Validate: 60/100 — 2 failing: [edge-cases, auth-check](list capped at 5). Reduces output noise by ~80%. - 8 domain-specific spec templates (SPEC-513):
search_spec_templatesandapply_spec_templatenow include auth login/OAuth, Stripe payments, CRUD resource, REST API integration, webhook consumer, file upload, and background job templates. - Semantic duplicate detection in create_spec (SPEC-514):
create_specautomatically runs Jaccard token-overlap similarity against all existing specs. If any spec scores ≥30% similar, apossibleDuplicates[]list is shown in the response. Zero external dependencies. - Auto-generate response-style rules on init_project (SPEC-517):
init_projectnow writes.claude/rules/planu-response-style.md(idempotent) — enforces lead-with-action, no trailing summaries, and structured output rules for Claude. - Auto-generate /compact skill on init_project (SPEC-519):
init_projectnow writes.claude/skills/compact.md(idempotent) — gives users/compact,/ultra-compact, and/verboseoutput modes. - Token savings estimator (SPEC-520):
usage_statsresource now includes atokenSavingsbreakdown: behavioral prompting compression (55% rate) + SDD discipline savings (8k tokens per completed spec). Pure estimation, no telemetry. - 3-layer drift scores (SPEC-525):
drift-monitor.tsnow computes real async drift scores: Layer 1 file existence (40%), Layer 2 temporal drift >30 days post-approval (40%), Layer 3 AC keyword coverage in implementation files (20%).
fix
- planu_status, capture_idea, quick_start in core group (SPEC-497): These three tools were in non-default groups and invisible in standard MCP sessions. Moved to
coregroup — always enabled.
[1.53.0] - 2026-04-14
feat
- statusHistory timestamps (SPEC-529):
spec.statusHistorynow records every status change with a timestamp.velocity_reportandvelocity_intelligenceuse real timestamps instead ofupdatedAtheuristics for accurate cycle time metrics. - BDD testability scoring (SPEC-527):
spec_quality_scorenow detects GIVEN/WHEN/THEN keywords in acceptance criteria (+5 for full BDD, +2 for partial). ReportsbddCoverage— percentage of ACs with at least partial BDD structure. - Jaccard lessons search (SPEC-526):
list_lessonsnow accepts aqueryparameter. Uses Jaccard tokenization (stop-word filtered) to rank lessons by relevance score (≥5% match), returning top-N sorted results. - Auto-detect spec dependencies (SPEC-522):
analyze_spec_dependenciesnow scans spec content for SPEC-NNN cross-references and returns asuggestedDependencies[]list (confidence:explicit). Suggestions are informational — not auto-added. - Git root auto-detection (SPEC-509):
list_specs,update_status, andcreate_specno longer requireprojectPath. When omitted, Planu detects the git root viagit rev-parse --show-toplevel— zero-config for agents running inside the project repo.
fix
- Locale-consistent number formatting:
cost_breakdown,context_window_status,context_budget_config, and the risk-page doc generator now usetoLocaleString('en-US')for consistent comma-formatted numbers across all environments.
[1.52.0] - 2026-04-14
fix
- Workspace health score (SPEC-532):
implementing(0.6),review(0.7),approved(0.4),draft(0.1) specs now contribute to the score. Projects actively being worked on no longer score 0%. - Cost guardrails enforcement (SPEC-521):
safeLicensed()now callscheckBudgetEnforcement()before executing licensed tools. When a spec budget is exhausted, the tool call is blocked with an actionable error message. - Real drift scores (SPEC-525):
drift-monitor.tsreplaced the deterministic hash mock (Math.abs(hash % 101)) with real file-existence scoring — readstechnical.mdto extract listed files and checks which ones exist. - Parallel orchestration (SPEC-516):
orchestrate_runtimenow executes tasks withPromise.allSettled()instead of a sequentialfor...ofloop. Tasks run concurrently up to the configured limit.
[1.51.0] - 2026-04-14
feat
- 5 new MCP resources (SPEC-498): Planu now exposes
planu://workspace/overview,planu://workspace/health,planu://velocity/report,planu://usage/stats, andplanu://budget/statusas native MCP resources. Resources are read-only and zero-parameter — LLMs can fetch them without consuming tool slots. Equivalent tools now advertiseprefer resource: planu://...in their descriptions so agents automatically select the lighter path when no parameters are needed. Total resources: 9 (was 4).
[1.50.1] - 2026-04-14
fix
- facilitate always visible:
facilitate(universal SDD entry point, SPEC-264) was incorrectly placed in thegovernancetool group (defaultEnabled: false), making it invisible in all MCP sessions. Moved tocoregroup — now always enabled by default.
[1.50.0] - 2026-04-14
feat
- Portable session context (SPEC-496): Planu now auto-generates
planu/session-context.mdon everyupdate_status(done)andcreate_release. The file is committed to git and travels between machines — any LLM (Cursor, Windsurf, Aider, Claude Code) can read current project state without~/.claude/dependencies. Contains: version, tool count, last 5 completed specs, approved backlog ordered by priority, and recent lessons.
[1.49.0] - 2026-04-14
feat
- Auto-estimate token actuals (SPEC-495):
update_status(done)no longer fails or saves zeros when the agent doesn't provide token/cost data. Tokens are auto-estimated from the spec'sestimation.recommendedModelanddevHoursusing per-hour constants (opus: 25k tok/h, sonnet: 45k tok/h). Cost is calculated from Anthropic 2026 blended pricing. Results are flagged withestimated: trueand shown with~prefix in the status output. Zero-value actuals are filled the same way. Both behaviors are fully automatic — agents need no changes. - Actuals no longer required:
update_status(done)without anactualsfield now succeeds instead of returningactuals_required. A default actuals object is generated from the spec estimation. Real values always take precedence when provided. - i18n for 3 website pages: comparison, autonomous-mode guide, and SDD-stack blog post are now available in all 6 locales (en/es/pt/fr/zh/de). Nav "vs Others" link added to all locale navbars.
[1.48.0] - 2026-04-14
feat
- Quickstart mode (SPEC-494): New
quickstartcontext profile exposes ~50 core SDD tools instead of all 557 — reduces cognitive load for new users and simple projects. Activate withset_context_profile(quickstart). Hides advanced tools (multi-agent orchestration, compliance gating, federation) while keeping the full workflow (create_spec → validate → heal). - Comparison landing page: New
website/en/comparison.md— feature matrix comparing Planu against cc-sdd, Kiro, Spec-kit, and Tessl across 8 dimensions (tools count, autopilot, healing, multi-agent, registry, IDE, offline, license). - Autonomous mode guide: New
website/en/guide/autonomous-mode.md— documents/autonomous-sddskill: 6-phase pipeline, --dry-run, --resume, and comparison to cc-sdd's/kiro-impl. - Blog post — SDD Is Not Three Tools: New
website/en/blog/sdd-stack-vs-3-tools.md— responds to Martin Fowler's 3-tool SDD frame with the full 8-phase lifecycle (brainstorm → heal) and why phases 1–4 and 8 are the ones most teams skip.
[1.47.0] - 2026-04-14
feat
- Claude Code mode hints per spec phase (SPEC-494):
update_statusnow returnssuggestedClaudeMode+modeHintin every response. Maps:draft/review → default,approved → plan,implementing → acceptEdits,done → default. The LLM can relay this to the user as a/modesuggestion. - planu-modes.md rule emitted by init_project: Client projects now receive
.claude/rules/planu-modes.md— a rule file explaining the mode-per-phase table and instructing the LLM to relay mode suggestions without switching automatically. - Positioning reframe: README and website hero updated to "The complete SDD stack for AI agents" — highlights 8-phase lifecycle, event-driven autopilot, retroactive healing, and
/autonomous-sddfor one-command delivery.
[1.46.0] - 2026-04-14
feat
- heal_spec_docs (SPEC-493): New tool that retroactively repairs all spec docs in a project — replaces placeholder technical.md (slugified paths with
--,(pending)markers) with type-based real file structure; marks done spec entries as(done); detects non-English titles; repairsstatus.jsontotalSpecs count. Run it on any client project to fix accumulated quality debt. - list_specs auto-repair: Every
list_specscall now silently rebuildsstatus.jsonfrom actual disk state — fixes projects wheretotalSpecswas 0 despite having 80+ specs. - extractCriteria GIVEN/WHEN/THEN (SPEC-492):
create_specnow parses GIVEN/WHEN/THEN patterns (single-line and multi-line) and plain- textlist items as acceptance criteria, in addition to checkbox- [ ]patterns. Priority: checkboxes > GIVEN/WHEN/THEN > plain list > fallback. - Auto-done criteria on transition to done (SPEC-492): When a spec moves to
done, alldone: falsecriteria are automatically flipped todone: true— no manual cleanup needed. - Tags enforcement (SPEC-492):
create_specnow guarantees at least 3 tags. If none are provided, tags are inferred from title + description keywords (filters English stopwords, takes top 5 meaningful words).
[1.45.7] - 2026-04-13
fix
- cascade cleanup:
update_status(done)now runscleanPlanuRootas final step — anyprogress.md,CHANGELOG.md, or HTML files created by cascade actions (auto_fix_health, older npm-cached server) are immediately removed from disk AND git index - zero legacy files: client repos will no longer accumulate ghost files after marking specs as done
[1.45.6] - 2026-04-13
fix
- cleanPlanuRoot git-rm (SPEC-491): After deleting legacy files from disk, also removes them from git's index via
git rm --cached— clients runninglist_specsorinit_projectnow get full cleanup (no more ghost HTML/CHANGELOG/progress.md files appearing as uncommitted changes) - init_project auto-cleanup: Triggers
cleanPlanuRooton every init — legacy files disappear automatically on first run with v1.45.6 - SPEC-491 — zero plain-text questions: Claude MUST use
AskUserQuestionfor ALL questions (general rule added to SERVER_INSTRUCTIONS);init_projectnow returnsinteractiveQuestions[]for skills pending install and context requests - 63 legacy files removed from this repo's planu/specs/ (HTMLs, per-spec CHANGELOG.md, progress.md)
- chore: remove unused
@stryker-mutator/typescript-checkerdevDependency
[1.45.5] - 2026-04-13
fix
- InteractiveQuestion relay (SPEC-490): Claude now MUST call
AskUserQuestionwhen any tool returns⚡ INTERACTIVEin content orinteractiveQuestions[]in structuredContent — no more questions buried as plain text - list_specs: adds
⚡ INTERACTIVEsignal incontent[]when ambiguous criteria are detected - create_spec: moves clarification questions to
structuredContent.interactiveQuestionswith explicit signal
[1.45.4] - 2026-04-13
fix
- resilient projectId:
challenge_specandvalidatenow acceptprojectPathas alternative toprojectId— the LLM always re-derives the correct ID from path even after context compaction (SPEC-489) - init_project ENOENT: Validates that
projectPathexists and is a directory before any I/O — returns clear actionable error instead of cryptic ENOENT stack trace - integration tests: New filesystem-level tests for
init_projectusing realmkdtempdirectories — catches bugs that mocked unit tests cannot
[1.45.3] - 2026-04-13
feat
- geo-telemetry: Events now include
country(ISO code) andtimezonevia cached IP geo-lookup (ip-api.com, 2s timeout, fire-and-forget). Lets us build a real usage map. - open-access: All 556 tools free until 2026-05-13 (
freeUntilin license-plans.json). Free-tier users skip rate limiting during this window. After the window, standard tiers resume automatically.
[1.45.2] - 2026-04-13
feat
- telemetry: Opt-out model — telemetry enabled by default (was opt-in). Users get a persistent installation ID stored in
~/.planu/telemetry.json. Disable withPLANU_TELEMETRY=off. - telemetry: All
tool_usedevents now carry persistentinstallationId(was'anonymous'),platform, and version info — enables real usage analytics - init_project: Richer telemetry payload includes
framework,platform,nodeVersion,specCount - README: Complete rewrite — 556 tools, Figma integration, Autopilot, Lean Specs, Zero-ambiguity criteria, telemetry transparency section, updated install instructions
[1.45.1] - 2026-04-13
fix
- living-specs: Don't create
progress.mdfor lean specs inreconcileSpec— was causing ghost files to appear staged afterupdate_status(done) - update-notifier: Persistent update banner for outdated versions (≥3 minor behind) — shows on EVERY tool call instead of just once. Major version behind always deprecated.
- export_pdf ENOENT: Smart error message detects Planu-generated paths (
planu/index.html,portal/) and suggests the correct generation command - tests: Aligned lean-spec-generator fallback text and tool-schemas snapshot with SPEC-486/487/488 changes
[1.45.0] - 2026-04-13
feat
- SPEC-486: Zero-ambiguity criteria — all autopilot-generated criteria now use GIVEN/WHEN/THEN format with concrete values (status codes, types, function refs). LLM converts directly to
expect()without interpretation. - criteria-quality-checker: New engine module scores each criterion 0-100 (50pts GWT, 30pts concrete value, 20pts function ref; 0 for prohibited phrases)
- validate_criteria_quality: Now includes
qualityWarningsfor criteria with GWT score < 50 alongside existing EARS scores - lean-spec-generator: Honest fallback "Define acceptance criteria — autopilot could not infer testable behavior" instead of misleading "Implementation complete and tested"
[1.43.0] - 2026-04-13
[1.44.0] - 2026-04-13
feat
- SPEC-484: Token optimization autopilot — skill catalog with model+effort per skill type (haiku for docs/PR, sonnet for arch/review), slim rules-generator template (~850 tokens less per message), CLAUDE_CODE_SUBAGENT_MODEL tip in init_project output
- SPEC-485: Simplicity autopilot — detect over-engineering signals (premature abstraction, N-dimensional classifiers, YAGNI violations) in every spec created; provides simplicityScore + simpleAlternative suggestion
fix
- task-15: Remove legacy CHANGELOG.md/progress.md generation from update_status done cascade
- create-spec: Extract handleClarification helper, reduce complexity from 52→49
feat
- SPEC-465:
withProject+projectIdSchemahelpers intool-registry-helpers.ts— eliminate 5-line boilerplate in 26 register-*.ts files (~445 lines removed) - audit:i18n: translation completeness guard script (key parity EN/ES/PT + empty value check)
- check:strict: full audit pipeline including i18n guard
1.42.0 (2026-04-13)
Features (token optimization wave — 105-file JSON migration + quality audits)
- SPEC-455 Phase 2: Migrated 105 tool files from raw
JSON.stringifytocompactResult/formatKeyValue/formatListformatters — reduces LLM token consumption per tool call. - Security audit script:
pnpm audit:security— flags HIGH/CRITICAL CVEs in production deps. - License audit script:
pnpm audit:licenses— SPDX allowlist check viapnpm licenses list. - Package size budget:
pnpm audit:size— fails if tarball exceeds 15 MB. - Token usage monitor:
pnpm audit:tokens— per-file JSON.stringify count enforcement. - API snapshot tests:
tests/api/tool-schemas.snapshot.test.ts— catches accidental schema drift. - Stryker mutation testing:
stryker.conf.json+pnpm audit:mutation— engine mutation baseline. - Figma handler split:
src/tools/figma/subdirectory (8 modules) + thin barrel re-export. check:strictpipeline: Combines all audits into single pre-publish gate.- knip dead-code detection:
pnpm audit:deadcode— 34 orphan barrel files removed. - BDD/Gherkin specs:
convert_to_bddtool +acFormat: 'bdd'increate_spec. - Legacy code tools:
characterize_legacy_code,detect_hyrum_risks,seams_detector,refactor_with_safety_net. - Delete-first tools:
suggest_deletions,sustainability_score,simplicity_metric. - Multi-agent review:
multi_agent_review— 3 parallel expert analyzers (design, security, testing).
Fixes
compactJsonmaxLines increased 30→300 to prevent JSON truncation in test contexts.- Reverted markdown formatting for structured outputs (orchestrate lock/unlock, DoD/DoR gates, design-schema, challenge-spec) — tests need parseable JSON; production compressor handles truncation.
- ESLint: 27 errors fixed across 12 migration files (unnecessary type conversions, non-null assertions, unnecessary conditions).
1.41.0 (2026-04-13)
Features (4 Software Crafters specs + code quality gates wave)
SPEC-480 Legacy Code Specialization: 4 new tools for working with legacy code.
characterize_legacy_codegenerates characterization tests from existing behaviordetect_hyrum_risksscans public API for undocumented observable behaviors (exception types, return shapes, ordering)seams_detectorfinds dependency break points (static calls, globals, inline new, hardcoded paths)refactor_with_safety_netorchestrates: detect coverage → add tests → incremental refactor → validate- 87 new tests. Fully deterministic (no LLM calls).
SPEC-481 BDD/Gherkin Native in Specs:
acFormat: "bdd"now emits valid Gherkin scenarios inspec.mdfrontmatter.- New
convert_to_bddtool migrates existing checkbox specs to BDD format - New parser recognizes both checkbox and Given-When-Then frontmatter
- Backwards-compat: checkbox stays default
- 37 new tests
- New
SPEC-482 Delete-First Refactor Tools (Ken Thompson philosophy): 3 new tools for finding deletion opportunities.
suggest_deletionsscans for dead code, duplication, over-abstraction, permanent feature flagssustainability_scorecomputessimplicity × cohesion / (1 + coupling/10)per modulesimplicity_metricgrades files A-F based on avg function length, nesting, clever patterns- 64 new tests
SPEC-483 Multi-Agent Review Workflow:
multi_agent_reviewruns 3 rule-based analyzers in parallel.design-analyzer— god objects, naming smells, complexity hotspotssecurity-analyzer— hardcoded secrets, OWASP markers, dangerous APIs (eval/exec/shell)testing-analyzer— coverage gaps, missing edge cases, test smells- Findings deduped and ranked by severity. 67 new tests
Features (code quality + tooling)
knip / madge / type-coverage installed and wired into
pnpm check:strict.- 34 dead-code files eliminated (orphan barrel
index.tsfiles detected by knip) - 2 circular deps fixed:
docs↔proposalandspec-format↔indexbarrel. Zero cycles now. - Type coverage 99.78% on src/ (strict, --ignore-catch)
jscpddevDep removed (replaced by SPEC-482duplication-finder)
- 34 dead-code files eliminated (orphan barrel
Token optimization: global output compressor tightened.
- MAX_JSON_LINES 40 → 20 (~400 tokens)
- MIN_COMPRESS_LENGTH 500 → 800 chars
- New hard cap of 2400 chars (~600 tokens) on every content block
- Now also truncates long markdown (not just JSON)
branch-ops.tsandmanage-hooks.tsmigrated toformatKeyValue/formatTable(25 raw JSON dumps eliminated)- New
pnpm audit:tokensscript +scripts/audit-token-usage.shto flag over-budget tools
Fixes
- figma-handler.ts refactor: extracted
FIGMA_NOT_CONNECTEDconstant (16 duplications → 1). File size down from 904 → 794 lines. - license-plans.json: added 9 new tools from SPEC-480/481/482/483
- register-spec-tools.test.ts: updated to match new
handleCreateSpec(input, server)signature - manage-git.test.ts: 17 assertions rewritten to check markdown substrings (after branch-ops JSON → markdown migration)
27,896 tests passing · typecheck clean · lint clean · knip clean · madge 0 cycles · type-coverage 99.78%.
1.40.1 (2026-04-13)
Bug Fixes
- tests: Updated
cost-breakdown-handler.test.tsmock to includewriteCostEntry+calculateCost(needed after cost tracking wiring). Updatedsmoke.test.tsmax tools threshold 475 → 600. No runtime changes — npm package bytes identical to v1.40.0.
1.40.0 (2026-04-12)
Features (autopilot autopilot observability + self-healing real)
Self-healing strategies REAL: TypeScript/test/coverage strategies are no longer stubs.
typescript-fix: parsespnpm typecheckerrors, auto-removes unused imports (TS6133)test-fix: parses vitest output, reports failing tests with actionable summarycoverage-fix: readscoverage/coverage-final.json, generates scaffold tests for 0% files- 26 new tests (7+6+8).
Cost tracking wired into 11 tools:
create_spec,list_specs,update_status,init_project,plan_mode,implement_plan,auto_fix_validation,cost_breakdown,generate_spec_from_issue,deploy_spec,configure_deploy_target,deploy_status. Every call writes todata/{projectId}/cost-ledger.jsonl(fire-and-forget, never blocks).Audit logger extended to 11 more cascade actions: Portal page regeneration per-page, init_project cascades (rules, skills, hooks), update_status branch creation + cleanup, git auto-stage, dispatchHookEvent, list_specs discovery/import/migration. Full observability of every cascade action.
545 tools, 127 tests passing for affected code, lint clean, typecheck clean.
1.39.0 (2026-04-12)
Features (3 strategic gaps progressed in parallel)
- SPEC-478 Phase 2 — 4 more deploy providers: Netlify, Cloudflare Pages, Fly.io, Railway. All follow the Vercel pattern (API client + status mapping + per-provider tests). 5 deploy providers total. 28 new tests.
- SPEC-476 Registry HTTP client: New
src/engine/registry/http-client.tswithfetchRegistrySearch,fetchRegistrySpec,publishToRegistry. ReadsPLANU_REGISTRY_URLenv (defaults tohttps://registry.planu.dev). Falls back to local stubs gracefully when backend unreachable. Ready to plug in real backend. 16 tests. - SPEC-477 VS Code Extension MVP: New
vscode-extension/directory with TreeDataProvider showing specs grouped by status, status bar item, file watcher for live updates, command palette entries. Self-contained subproject. Runcd vscode-extension && npm install && npm run compile, then F5 in VS Code to test.
545 tools, 178 tests passing for the new code, lint clean, typecheck clean.
1.38.0 (2026-04-12)
Features (Deploy gap closed — Phase 1)
- SPEC-478 Phase 1 — Vercel deploy integration: New tools
configure_deploy_target,deploy_spec,deploy_status. Phase 1 supports Vercel via the v13 deployments API. Full flow: configure token once → trigger preview/production deploys → check status. Closes the v0/Bolt/Windsurf deploy gap. 545 tools total. Phase 2 (Netlify, Cloudflare, Fly, Railway) documented in SPEC-478 for future.
Documented (specs created for future implementation)
- SPEC-476 Public Spec Registry (80h): Backend infrastructure on Vercel + Neon + Clerk. Closes Tessl/spec-kit gap.
- SPEC-477 VS Code Extension (60h): Visual interface that connects to local Planu MCP. Closes Cursor/Kiro gap.
- SPEC-479 Mobile PWA (30h, depends on 476): Closes Copilot Workspaces mobile gap.
1.37.0 (2026-04-12)
Features (3 competitive gaps closed in one release)
- SPEC-473 — Plan Mode: New
plan_mode+implement_plantools generate a structured diff preview before implementing. Shows files to create/modify/delete, estimated lines, risk per file, overall warnings. User reviews and approves before code is written. Closes the Cursor/Kiro/Windsurf gap. 21 tests. - SPEC-474 — Self-healing loop: New
auto_fix_validation+run_healing_looptools detect validation failures and trigger auto-fix strategies (typescript, lint, tests, coverage). Max 3 attempts. Lint strategy actually runseslint --fix. Closes the Devin/Windsurf Cascade gap. 26 tests. - SPEC-475 — Per-operation cost tracking: New
cost_breakdowntool shows total cost, breakdown by tool, by model, top 10 expensive ops. Filterable by period (today/week/month/all).data/{projectId}/cost-ledger.jsonlwrites are fire-and-forget. Closes the Kiro/Devin pricing transparency gap. 32 tests.
Total: 79 new tests, 542 tools, all 3 competitive gaps closed in one release.
1.36.0 (2026-04-12)
Features (Competitive gap closed)
- SPEC-472 — Generate spec from issue: New
generate_spec_from_issuetool that creates a spec draft from external issues/tickets in GitHub, Linear, Jira, Asana, and Notion. Reads title, body, labels, comments, and infers target/scope/type/risk automatically. Closes the #1 competitive gap (Copilot Workspaces, v0, Devin, Kiro all had this). 14 tests covering all label-based inferences. 537 tools total.
1.35.0 (2026-04-12)
Features (Autopilot perfection — 4 specs in one release)
SPEC-471 — MCP elicitInput primitive for interactive UI:
create_specnow uses nativeserver.elicitInput({ mode: 'form' })to FORCE interactive UI in any MCP host (Claude Code, Cursor, etc.). No more dependency on LLM interpreting JSON responses. Graceful fallback if host doesn't support elicitation. 10 tests covering accept/decline/cancel/fallback flows.SPEC-468 — Autopilot audit log: Every cascade action now writes to
data/{projectId}/autopilot-audit.jsonlwith timestamp, trigger, action, status (ok/fail/timeout/skipped), durationMs, metadata. Newautopilot_auditMCP tool reads and filters the log. Auto-prunes to last 1000 entries. Instrumented:migrateAllSpecsToLean,cleanPlanuRoot,configureGitignoreForPlanu,regenerateSpecSummaryHtml,recordStatusChange,handleValidate,handleGeneratePr. 536 tools total.SPEC-469 — Autopilot summary in responses: Every tool with cascade actions (
list_specs,init_project,update_status,create_spec) now includesautopilotSummary[]instructuredContent. Users see "Migrated 132 specs", "Cleaned 10 legacy files", etc. automatically. i18n descriptions updated in EN/ES/PT to instruct LLM to surface the summary.SPEC-470 — Declarative autopilot config:
planu/autopilot.ymlconfig loader + cascade executor. Users can now override which actions run on which triggers, timeouts, parallel vs sequential, disabled actions. YAML schema validated with Zod. Falls back to defaults if missing/invalid. Infrastructure ready — actual integration with list_specs/create_spec is future work.
Bug Fixes
- Lint cleanup: Fixed 11 new lint errors from agent-generated code (duplicate imports, async-no-await, void-expression patterns).
1.34.1 (2026-04-12)
Bug Fixes
- CRITICAL — Interactive questions now work for clients: The
create_spectool description now explicitly instructs the LLM to convertneedsClarification: trueresponses into nativeAskUserQuestionUI calls (Claude Code) or equivalent submit components. Previously, the JSON response was displayed as text and users never saw the interactive picker. Fix applied in EN/ES/PT i18n.
1.34.0 (2026-04-12)
Features
- Test coverage surge: 528+ new tests added across 29 files that previously had 0% coverage. Total: 27,405 tests passing (from 26,877). Files covered: bdd-formatter, coverage-checker, mutation-config-generator, report-renderer, asana/monday pullers, gateway/compliance/sentry/steering/webhook/refactor-registry/budget/pr/storybook/supabase/onboarding/release-notes/auto-promoter-config stores, all checkpoint handlers, e2e-test-generator/ecosystem/figma-token/memory-config/pr-agent/spec-visual-diff handlers, property-based generator, spec-linter, trial-handler, diagrams, runtime-security validator config.
Refactor
- Dead code removal: Eliminated 22 orphan exports confirmed to have zero consumers. Deleted 1 entire unused file (
register-ecosystem-tools.ts). Converted 1 export to internal function (getDriftMonitorData). Changes span: trial-engine, bundle-installer, version-defaults, best-practices-library, compliance-handler, ac-gap-detector, multi-app-detector, config-schemas, contradiction-detector, resilience-detector, figma-store, skill-bootstrap-store, spec-granular, register-merge-risk-tools.
Bug Fixes
- 20 lint errors: Fixed
no-non-null-asserted-optional-chainanti-patterns in test files (5 files). Merged duplicate type imports.
1.33.3 (2026-04-11)
Security
- hono vulnerabilities: Updated
@modelcontextprotocol/sdkto fix 6 moderate CVEs in transitive dependencyhono(cookie validation, IP matching, path traversal, middleware bypass).pnpm auditnow reports zero vulnerabilities.
1.33.2 (2026-04-11)
Bug Fixes
- tool registration validator: Regex was limited to
server.registerTool(and missed tools registered vias.registerTool((any other variable name). Now matches any.registerTool(pattern. - 6 unregistered tools found + fixed:
compliance_gap_analyzer,configure_mcp_hub,mcp_hub_status,productivity_report,sync_mcp_event,velocity_intelligencewere registered in code but missing from license-plans.json. All added to proTools. - Tool count: 529 → 535 (sync verified across website in 8 languages).
1.33.1 (2026-04-11)
Bug Fixes
- lint cleanup: Fixed 11 ESLint errors (curly braces, interfaces in types/, unused vars). Lint suite is now 100% clean.
- legacy report removal:
regenerateSpecSummaryHtmlno longer callsregeneratePerSpecReports— executive-report.html and technical-report.html are no longer generated per-spec onupdate_status(done). - 9 pre-existing test failures fixed: index.test.ts mock for SPEC-460, estimator default config (hourlyRate 0), tokens 0 at estimation time, create-spec-automation tests need >=15 words OR tech terms (SPEC-463), init-project gitignore behavior (SPEC-466).
- architecture:
CleanupResultandBranchInfointerfaces moved tosrc/types/spec-format.ts(SOLID compliance).
1.33.0 (2026-04-11)
Features
- SPEC-465 — Tool registry helper:
defineTool()+registerTools()API reduces register-*.ts boilerplate from ~15 lines to ~5 lines per tool. Existing 185 files can be refactored incrementally. - SPEC-467 — Branch awareness:
detectBranches()+buildBranchScopeQuestion()—list_specsandinit_projectnow include branch info in responses. LLM can use AskUserQuestion to let users choose branch scope.
Bug Fixes
- perf:
update_status(done)timeout fixed —handleGeneratePrcapped at 10s,handleValidatecapped at 15s. - architecture: Zero violations remaining. Last engine→tools import fixed.
1.32.5 (2026-04-11)
Bug Fixes
- perf:
update_status(done)no longer blocks for >60s.handleGeneratePrcapped at 10s,handleValidatecapped at 15s viaPromise.race. Previously unbounded and caused MCP timeouts. - architecture: Last engine→tools import violation fixed (
engine/figma/spec-generator.tsnow importsgenerateSpecIdfromengine/spec-format/spec-id.ts). Zero architecture violations remaining.
1.32.4 (2026-04-11)
Features
- autopilot cleanup:
list_specsnow auto-runscleanPlanuRoot()+configureGitignoreForPlanu()on every call. Clients get zero-config planu/ cleanup — no need to runinit_projectmanually. 28K+ lines of legacy files removed from our own repo.
1.32.3 (2026-04-11)
Features
- SPEC-466 — Branch-safe planu/: Regenerable files (status.json, HTMLs, PDFs) are now gitignored to prevent merge conflicts across branches.
init_projectauto-configures.gitignorefor all client projects. All hook generators (husky, kiro, codex, gemini) updated to stage onlyplanu/specs/+conventions.json. Zero merge conflicts guaranteed. - SPEC-467 created (draft): Branch-aware operations — Planu will detect branches and ask users via InteractiveQuestion whether to operate on current branch or all branches.
1.32.2 (2026-04-11)
Refactors
- SOLID audit: Fix circular dependency in ci-generator (context-builders ↔ stack-detector). Move lean generators from
tools/create-spec/toengine/spec-format/(architecture violation fix). Move generator interfaces totypes/spec-format.ts. SPEC-465 created (draft) for register-*.ts boilerplate reduction.
1.32.1 (2026-04-10)
Bug Fixes
- cascade:
update_status(done)no longer generates legacy HTMLs (analytics, changelog, executive-summary, risks, decisions, architecture) or per-spec CHANGELOG.md/progress.md. Only canonical pages (index.html + roadmap.html) are regenerated. Verified via simulated cleanup of conker-ssr (488 files) and aforo-app (321 files).
1.32.0 (2026-04-10)
Features
- SPEC-463 — Interactive questions:
create_specreturns structuredInteractiveQuestion[]when description is vague. LLM presents them via native UI (AskUserQuestion in Claude Code). New types:InteractiveQuestion,InteractiveOptioninsrc/types/clarification.ts.
Refactors
- SPEC-462 — No estimation in technical.md:
technical.mdnow contains only spec ID + files section. Estimation lives exclusively inspec.md. - SPEC-464 — Canonical planu/ structure: Only
specs/,status.json,conventions.json,index.html,roadmap.htmlcommitted. HTMLs regenerate only onupdate_status(done). Pre-commit hook stages only canonical files. Legacy HTMLs/PDFs deleted (~22K lines removed).
1.31.1 (2026-04-10)
Bug Fixes
- Migrator robustness: Estimation parser handles Spanish labels, range values, and varied table formats. Generic section filter now covers
###sub-headers (OWASP, STRIDE, Verification Criteria). Verified via simulated client migration — zero data loss.
1.31.0 (2026-04-10)
Features
- SPEC-461 Phase 3 — Autopilot create_spec:
create_specnow auto-analyzes the project before generating specs. Scans files for related paths, detects stack patterns (Supabase→RLS, auth→sessions), generates pattern-specific criteria. Ideas flow: very vague descriptions (<5 words) captured as ideas. SPEC-461 is now 100% complete (all 5 phases).
1.30.3 (2026-04-10)
Bug Fixes
- Migration quality: Recovered 448 spec descriptions (were "No description available"), 100 file lists, and improved migrator to skip generic sections while keeping real content. extractFilesFromTechnical now detects informal file headers and fallback-scans for src/ paths.
1.30.2 (2026-04-10)
Bug Fixes
- Migration data recovery: Migrator now extracts estimation (devHours, reviewHours, cost, model) from old technical.md markdown tables. 237 specs recovered with real estimation data. Migrator forces all criteria to done:true when status=done.
- Lean format readers: All spec parsers (
parseAcceptanceCriteria,inject_criteria,spec-repair) now support both lean YAML format and old markdown format transparently.
1.30.1 (2026-04-10)
Bug Fixes
- Lean format compatibility:
parseAcceptanceCriteria(MCP resource + PR analyzer) now reads criteria from YAML frontmatter.spec-repairno longer flags lean specs as incomplete.inject_criteriawrites to YAML for lean specs.migrateSpecToLeanmarks all criteria done:true when status=done.
1.30.0 (2026-04-10)
Features
- Spec Migration Complete: 449 specs migrated from verbose (~16,500 tokens each) to lean format (~600 tokens). 1,596 obsolete files deleted (progress.md, HTML reports, CHANGELOG.md per spec).
- Dead Code Cleanup: Removed 15,413 lines and 82 files of old spec generators (HU templates, FICHA-TECNICA, resilience/security/privacy adapters, mermaid diagram generators). Only lean generators remain.
1.29.1 (2026-04-10)
Bug Fixes
- rules: Updated SDD rules and client rules-generator to reflect lean 2-file spec format. Clients no longer get told to expect
progress.md.
1.29.0 (2026-04-10)
Features
- SPEC-461 Phase 2 — Auto-Migrator: Old verbose specs (progress.md, HTML reports, >100 lines) auto-detected and converted to lean format on
list_specs/init_project. Generic criteria (OWASP, STRIDE) filtered out. Obsolete files deleted. - SPEC-461 Phase 4 — Cleanup: Removed 8 orphaned HTML reports from planu/ (18,234 lines deleted). Kept: index.html, proposal.html, executive-summary.html.
- SPEC-461 Phase 5 — Refactors:
REQUIRED_FILESreduced to 2 (no progress.md).check-spec-integrity.shupdated.update-statusstops creating new progress.md files.
1.28.0 (2026-04-10)
Features
- SPEC-461 Phase 1 — Lean Spec Format:
create_specgenerates lean spec.md (~30-50 lines YAML frontmatter + description) and lean technical.md (~20 lines YAML + files section). Eliminates progress.md, executive-report.html, and technical-report.html per spec.reverse_engineernow writes lean files to disk. 97% token reduction per spec (from ~16,500 to ~600 tokens).
1.27.0 (2026-04-10)
Features
- SPEC-459 — Autopilot Self-Awareness:
planu/status.jsonauto-updated on everyupdate_statusandcreate_speccall. Tracks byStatus/byType counts, last 20 status changes. - SPEC-460 — LLM-Aware Runtime: Detect connected LLM client via MCP
getClientVersion(). Model detection from env vars. Session token tracker (measured, not invented). Pricing resolver with real prices from Anthropic/OpenAI/Google (auto-refresh from GitHub every 24h). - Estimator cleanup: Removed all hardcoded fake data.
hourlyRate: 0(user configures),pricingPerMToken: 0(resolved from model-pricing.json),TOKENS_PER_DEV_HOUReliminated (use real tracker). Token/cost estimates show 0 until real data exists. - model-pricing.json: Real pricing verified from official provider pages (2026-04-10).
1.26.1 (2026-04-10)
Features
- SPEC-459 — Autopilot Self-Awareness:
planu/status.jsonauto-updated on everyupdate_statusandcreate_speccall. Tracks byStatus/byType counts, last 20 status changes, and version. Fire-and-forget, never blocks tool execution.
1.26.0 (2026-04-10)
Features
- SPEC-453 — Agent Completion Guarantees: Lifecycle tracking, stall detection, auto-recovery for spawned agents. New tools:
guarantee_agent_completion(free),agent_completion_report(free),configure_agent_guarantees(pro). 56 tests. - SPEC-454 — Autopilot Real Execution: Triggers now EXECUTE real actions instead of just logging. Action registry with timeout, error handling, fire-and-forget. 3 engine handlers wired.
- SPEC-455 — Smart Output Compression: Global interceptor in
safeWithTelemetryauto-compresses JSON dumps from ALL 470+ tools. ExtractshumanSummary/messagefields, truncates large JSON to 40 lines.PLANU_VERBOSE_OUTPUT=trueto disable. 36 tests. - SPEC-456 — Autopilot Intelligence: 6 additional trigger handlers (suggest_criteria, detect_contradictions, spec_quality_score, tdd_scaffold, generate_changelog, log_lesson). Total: 9/15 triggers execute real actions.
- SPEC-457 — Project Auto-Bootstrap:
init_projectnow auto-generates rules, hooks, and skills for the detected stack via fire-and-forget calls. - SPEC-458 — Resilient Output Pipeline: Per-tool formatter library (
output-formatter.ts) with table, list, score, config, and confirmation formatters.
Rules
- New
.claude/rules/autopilot-first.md— mandatory design rule: every tool must act, not suggest; compress output; cascade automatically; handle errors actionably.
1.25.0 (2026-04-09)
Features
- SPEC-452 — TDD Enforcement & Anti-Error Pipeline: Test-first culture enforced by tooling. New
configure_tdd_policy(free) sets enforcement mode (off/soft/hard). Newgenerate_edge_tests(free) auto-generates TDD stubs from spec acceptance criteria AND boundary tests from Zod schemas — catches undefined optional fields, empty strings, empty arrays, zero values. Newtdd_status(free) shows policy, readiness, and unresolved stub count. Gates onupdate_status(implementing)warn/block without test stubs; gates onupdate_status(done)check for unresolvedexpect.failstubs.
Maintenance
- Removed 2 phantom tool entries from license-plans.json (
validate_figma_flows,configure_email_notifications) - Marked 27 previously-implemented specs as done (SPEC-142, 159, 387-394, 417-432, 443)
- Dropped stale git stash
1.24.0 (2026-04-09)
Features
- SPEC-443 — Auto-Update Zero-Friction: New
check_update_status(free) queries npm registry for latest @planu/cli version and compares with current. Newenable_auto_update(free) detects MCP config cross-platform (~/.claude.json on Mac, Windows equivalent) and patchesmcpServers.planuentry to usenpx -y @planu/cli@latest. Creates atomic backup before patching. Newpin_version(pro) locks to a specific version. - SPEC-449 — Zod/TS Optional Parity Auditor: New
audit_schema_type_parity(free, readOnly) scans allregister-*.tsfiles for.optional()Zod fields, then verifies the corresponding TypeScript type has?and the handler uses?? defaultValue. Reports discrepancies with severitycritical(unsafe access) orwarning(missing?). Newfix_schema_type_parity(pro) auto-applies fixes. - SPEC-450 — Autopilot Bus Wiring Fix:
bootstrapAutopilotHandlers()now registersexecuteTriggersForEventfor all 6AutopilotEventNamevalues at server startup. Previously 13 DEFAULT_TRIGGER_RULES were defined but never executed — all autopilot rules now fire correctly. - SPEC-451 — Auto-Discover Skills from init_project:
init_projectnow auto-callsdiscoverSkillsForInit()after project setup (fire-and-forget, top 3 discovered registry skills included in response). Users no longer need to manually calldiscover_skills_from_registries.
Documentation
- Retroactive
spec.md+technical.mdfor SPEC-348 through SPEC-367 (20 implemented specs that lacked documentation) — eliminates integrity warnings in pre-commit hook.
1.23.0 (2026-04-09)
Features
- SPEC-444 — Proactive Rules Injection:
init_projectnow injects Planu behavioral rules into the user'sCLAUDE.mdvia HTML comment markers (<!-- planu:rules:start -->) so tools like auto-trigger Figma analysis work without manual configuration. Rules update in-place on everyinit_projectcall. - SPEC-445 — Auto-Pipeline on create_spec: After creating a spec, Planu automatically runs
challenge_spec+check_readinessin the background (10s timeout). The result is included in thecreate_specresponse, surfacing quality gaps and readiness score without extra tool calls. - SPEC-446 — Multi-Channel Status Notifications:
update_statusnow fire-and-forgets notifications to Slack, Email, and Telegram when a spec transitions toreview,approved,done, orblocked. New tools:configure_telegram(pro),telegram_status(free). - SPEC-447 — Compliance Gate on Review:
update_status(review)optionally checks spec compliance score before accepting the transition. Inhardmode, blocks if score is below threshold. New tools:configure_compliance_gate(pro),compliance_gate_status(free). - SPEC-448 — Auto Version Snapshot on Approved:
update_status(approved)automatically creates a version snapshot taggedapproved-YYYYMMDDTHHmmviaversion_spec, giving every approved spec a named checkpoint before implementation begins.
Fixes
- BUG-002 — generate_teammate_prompt crashes when assignedFiles is undefined: Zod schema had
.optional()but TypeScript type lacked?. WhenassignedFileswas omitted by the LLM, the handler passedundefinedasownedFilesandprompt-builder.tscrashed calling.lengthon it. Fixed: added?toGenerateTeammatePromptInput.assignedFilesand?? []fallback in handler. - Lint sweep: Fixed 27 lint errors across 22 files — unnecessary optional chains, unused constants, type/interface declarations outside
src/types/, duplicate imports,restrict-plus-operandsonstring | undefined, andprefer-promise-reject-errors.
1.22.0 (2026-04-09)
Features
- SPEC-442 — Crash Shield: stack-aware runtime safety scanner: New
scan_crash_risks(free) tool scans any project for crash-prone patterns across TypeScript/JS, Python, Go, Rust, Java/PHP/Ruby and framework-specific patterns (Next.js, Express, Prisma). Returns a safety score 0–100 with severity-bucketed risk table. Newfix_crash_risks(pro) auto-applies patches with unified diff preview. Newconfigure_crash_rules(pro) enables per-project pattern customization. Automatically runs onupdate_status(done)transition — warns when score < 80 so specs aren't marked done with known crash risks outstanding.
Improvements
- Safety hardening: Added 130+ new tests for crash-shield engine (detectors, orchestrator, file collector),
checkSecurityGate(previously 0% coverage),dod-gates, andside-effects. Branch coverage maintained at threshold.
1.21.0 (2026-04-09)
Features
- SPEC-441 — Code Reality Checker on
implementingtransition: Before transitioning any spec toimplementing, Planu now scans the project for existing implementation evidence across 4 layers: (1) source files whose names match spec keywords, (2) exported symbols (functions, classes, types) matching the spec domain, (3) test files covering those keywords, (4) tool registrations inlicense-plans.jsonandregister-*.tsfiles. A gap score of ≥75 emits a warning that the spec may already be implemented — preventing duplicate work and spec-vs-code drift.
Fixes
- Safety sweep — 23 files hardened against runtime crashes: Comprehensive optional chaining audit fixed
x?.field.method()→x?.field?.method()pattern across 16 files where the guard only protected againstxbeing null but not againstfieldbeing undefined (generate-teammate-prompt,generate-cost-estimate-handler,generate-runbook-handler,generate-deployment-diagram-handler,reverse-engineer/analyzer,dor-dod,review-helpers,service-migrator-planner,session-journal,ficha-content,section-builders,hu-body-generators,proposal-section-builders-advanced,ci-version-checker,stack-analyzer,note-health-handlers). - BUG-001
update-status-actions.ts:content[1].textre-accessed after optional-chain guard — extracted tovalTextvariable. - BUG-002
detect-drift-event.ts:JSON.parse as EventContractwithout field validation — addedcurrentVersion/nameguard before narrowing. - BUG-003
docs-site-generator/data-collector.ts:readFileSyncwithout try/catch in exported function — now returns[]on ENOENT. - BUG-004
audit-trail/verifier.ts: Parsed audit entries could have missing required fields after corrupt/truncated JSONL — validated viaPartial<AuditEvent>before narrowing. - BUG-005
hooks/handlers/on-test-pass.ts:coverage.lines.pctwithout optional chaining — switched tolines?.pctwith typeof guard. - BUG-006
ai-cost-estimator/spec-loader.ts:log.events.lengthwithoutArray.isArrayguard — cast toPartial<UsageLog>first. - BUG-007
suggest-mcp-server.ts:parsed.archetypeswithout nullish fallback — now uses?? [].
1.20.0 (2026-04-08)
Features
- SPEC-440 — Zero-Friction OAuth Onboarding (2 tools): Paste a Figma link → Claude detects missing auth → provides an OAuth URL → user clicks → token saved → operation continues.
start_oauth_flow(free) initiates OAuth 2.0 PKCE for Figma and GitHub (starts a local callback server on a free port, returns an auth URL valid for 5 minutes) and guided-token flow for Sentry and Supabase (returns human-readable instructions with direct links).oauth_status(free) lists authorized integrations with timestamps. CSRF state management with in-memory Map and 5-min TTL. All existing Figma, Sentry, and Supabase tools now include friendly OAuth prompts instead of generic errors. 37 tests.
1.19.0 (2026-04-08)
Features
- SPEC-439 — Multi-Source Skill Auto-Bootstrap (3 tools): Auto-detects the project tech stack and fetches matching skills from external registries.
discover_skills_from_registries(free) shows available skills without writing any files — detects stack from package.json, requirements.txt, Gemfile, go.mod, Cargo.toml.bootstrap_skills(pro) installs skills from awesome-cursorrules (PatrickJS/awesome-cursorrules GitHub repo), skills.sh registry, and configurable custom GitHub repos into the correct AI tool files: .cursorrules, .windsurfrules, CLAUDE.md, .kiro/steering/, AGENTS.md, .clinerules. Auto-merge mode appends to existing files without overwriting.configure_skill_registries(pro) manages enabled sources, target files, and auto-merge mode. All fetches have 5-second timeout and fail silently. 76 tests.
1.18.0 (2026-04-09)
Features
SPEC-435 — Sentry Error Monitoring Integration (4 tools): Closes the dev loop from production error to bugfix spec.
configure_sentry(free) stores DSN, auth token, and project slug.sentry_status(free) shows config and last sync.sentry_errors_report(pro) fetches open issues from the Sentry REST API filtered by level and resolution status.sentry_error_to_spec(pro) creates a Planu bugfix spec from a Sentry issue ID with auto-generated title, description with stacktrace summary, and priority-mapped acceptance criteria. 39 tests.SPEC-436 — PR Description Generator from Spec (3 tools): Generates GitHub/GitLab/Linear PR descriptions from a spec's acceptance criteria.
generate_pr_description(free) produces a full PR body in markdown with Summary, Changes, Acceptance Criteria, Test Plan, and Checklist sections — adapted per platform and audience (developer/reviewer/stakeholder).link_pr_to_spec(pro) saves a PR URL → spec traceability link.list_spec_prs(pro) lists all linked PRs. 46 tests.SPEC-437 — Supabase Schema Integration (4 tools): Reverse-engineers a Supabase project into Planu specs.
configure_supabase(free) stores project URL and service role key.supabase_status(free) shows config and last sync.sync_supabase_schema(pro) fetches the OpenAPI schema and RLS policies from the Supabase REST and Management APIs.generate_rls_spec(pro) creates security specs for each table — tables without RLS are flagged as critical risk. 62 tests.SPEC-438 — Release Notes Generator (3 tools): Generates user-facing release notes from specs in "done" status filtered by date range.
preview_release_notes(free) shows a quick summary (count + first 3 titles).generate_release_notes(pro) renders full release notes in markdown, HTML, or plain text adapted for three audiences: developer (technical, includes spec IDs), user (plain language, visible features only), stakeholder (executive summary).configure_release_notes(pro) sets per-project defaults. 55 tests.
1.17.0 (2026-04-09)
Features
SPEC-432 — Storybook Component Sync (3 tools): Extracts component metadata from Storybook CSF files (
.stories.tsx/ts/js/jsx) without external dependencies using regex-based parsing.sync_storybook_components(pro) scans all story files and stores component names, props, arg types, variants, and import paths.list_storybook_components(pro) queries the synced catalog with optional name filter.inject_component_context(pro) formats component metadata for LLM injection during spec or UI contract generation. 33 tests.SPEC-433 — Figma Token Sync to Code (2 tools): Exports Figma design tokens to CSS custom properties, TypeScript constants, or W3C DTCG JSON format.
sync_figma_tokens_to_code(pro) reads stored tokens and writes a typed output file with configurable prefix and format.validate_token_consistency(pro) reads an existing token file and diffs it against the live Figma state to report drift. 16 tests.SPEC-434 — Steering File Generator (2 tools): Generates AI context files (steering files) for Kiro, Cursor, Claude Code, Cline, and GitHub Copilot from a single command.
generate_steering_file(pro) reads project specs, conventions, and stack from Planu and writes the correct format for each AI tool —.kiro/steering/planu.md,.cursorrules,CLAUDE.mdsections,.clinerules, or.github/copilot-instructions.md.list_steering_files(pro) shows generated files with target tool and path. 31 tests.
1.16.0 (2026-04-08)
Features
- SPEC-419–431 — Complete Figma→SDD Integration (20 new tools): End-to-end automation from a single Figma URL to running specs, E2E tests, and design drift detection.
import_figma_project(SPEC-431) orchestrates the entire pipeline in one command.analyze_figma_flows(SPEC-419) extracts prototype interactions into a flow graph.generate_figma_e2e_tests(SPEC-430) converts those flows into Playwright.spec.tsfiles with correct selectors and URL assertions.extract_figma_design_tokens(SPEC-421) fetches Figma variables and converts them to W3C-compatible JSON (colors, typography, spacing, radii).sync_figma_changes(SPEC-422) diffs frame snapshots to detect renamed/moved screens.list_figma_responsive_frames(SPEC-423) groups frames by mobile/tablet/desktop breakpoint.enrich_specs_from_figma/get_figma_context_for_spec(SPEC-420) attach component hints, layout notes, and color tokens to existing specs for implementation-time reference.configure_figma_webhook/remove_figma_webhook(SPEC-425) manage HMAC-SHA256-validated Figma webhooks.sync_figma_code_connect(SPEC-426) fetches Code Connect component mappings and computes coverage.add_figma_file/remove_figma_file/list_figma_files(SPEC-427) manage multiple Figma files per project.check_figma_design_drift(SPEC-428) detects specs out of sync with the latest Figma version.figma_visual_diff_report(SPEC-429) exports frame PNGs from Figma API for side-by-side visual comparison. All 20 tools are pro tier. 26,820 tests passing.
1.15.0 (2026-04-08)
Features
- SPEC-418 — Figma Integration (REST API): 4 new tools for bulk frame extraction and spec generation from Figma files without context window overflow.
configure_figma(pro) stores and verifies a Figma Personal Access Token.figma_status(free) shows token config and last 3 sync entries.list_figma_frames(free) lists all frames in a Figma file grouped by section prefix — scales to 200–500+ frames.generate_specs_from_figma_file(pro) creates one Planu spec per section (groupable by name prefix or Figma page). Uses the Figma REST API server-side, so all processing happens outside the LLM context window. Phase 2 (on-demand MCP detail per screen) usesget_design_contextfrom the Figma MCP when implementing individual screens.
1.14.0 (2026-04-08)
Security
- SPEC-417 — Bundle Obfuscation:
scripts/obfuscate.mjsruns automatically as the last step ofpnpm build. All 2,322.jsfiles indist/are obfuscated withjavascript-obfuscator(hex identifiers, base64 string arrays, string splitting). Config JSON files indist/config/are intentionally skipped. The MCP server starts and operates correctly after obfuscation. Tests continue to run againstsrc/— unaffected.
1.13.0 (2026-04-08)
Features
- SPEC-412 — Competitive Intelligence:
list_competitorsshows the 7 tracked competitors (Kiro, Tessl, GitHub spec-kit, Linear, Jira, Notion, Shortcut).competitive_gap_analysisextracts keywords from a spec and maps them to competitor capabilities — positioning each feature as differentiator/parity/lagging.update_competitive_cataloglets you add new competitors or update capability lists. All backed bysrc/config/competitive-catalog.json. - SPEC-413 — Planu Autopilot (Event Bus + Trigger Rules): Fire-and-forget event bus (
emitAutopilotEvent,onAutopilotEvent) that connects spec lifecycle events to automated actions. 16 built-in trigger rules (e.g.spec:created→ suggest_criteria,spec:done→ validate,spec:risk:high→ red_team).configure_autopilotlets you enable/disable individual rules or set custom thresholds. Autopilot events emitted oncreate_specandupdate_statustransitions. - SPEC-414 — AI-Aware Project DNA:
detect_project_dnascans the project and identifies stack (language, framework, test runner, linter, formatter, package manager) + active AI tool (Claude Code, Cursor, Windsurf, Kiro, Cline, Copilot, Aider, Gemini).bootstrap_project_intelligenceauto-installs stack-matched skills + hooks + rules formatted for the detected AI tool using live docs URLs.update_project_dnarefreshes the analysis. Backed bysrc/config/ai-tool-registry.jsonwith validated docs URLs. - SPEC-415 — Persistent Agent Registry: Agents survive across sessions as JSON in
.planu/agents/.registry.json. 6 predefined roles: spec-guardian (drift monitor), pr-reviewer, metrics-analyst, criteria-auditor, changelog-keeper, dependency-watcher.register_agent/stop_agent/restart_agent/unregister_agentmanage lifecycle.list_agentsshows status + trigger + run counts.agent_healthreports success rate, avg duration, and last error. - SPEC-416 — Dynamic Hook Generator:
preview_hooks(free) shows what hook sections would be added/updated without writing.generate_hooks_for_stackauto-detects stack + AI tool and merges idempotent hook sections into.claude/hooks/.merge_hooksapplies explicit sections. Idempotency guaranteed via<!-- planu:generated:ID -->markers — manual code never overwritten.
1.12.0 (2026-04-08)
Features
- SPEC-405 — Stub Tools Full Implementation: Real logic for 4 previously-stub pro tools —
check_api_compatibility_v2(REST/GraphQL surface comparison),critical_path_analyzer_v2(DAG + longest-path algorithm),similar_problems_finder_v2(Jaccard similarity across all registered projects),suggest_mcp_catalog(curated catalog of 15 MCP servers matched by keyword). - SPEC-406 — Verifier Agents:
verify_spec_complianceautomatically scores how well implemented code matches an approved spec (0-100).compliance_score_reportshows project-wide verification trends. Designed to auto-trigger onupdate_status(done). - SPEC-407 — Context-Aware Tool Exposure:
set_context_profile,get_context_profile,list_context_profiles— 5 built-in phases (brainstorm/plan/implement/review/release) each guiding the LLM to use only the 10-20 most relevant tools. Reduces token noise by up to 90%. - SPEC-408 — Auto-Remediation Loops: Complete the Detect→Alert→Fix cycle —
auto_fix_health(creates missing files, clears orphaned locks),auto_remediate_compliance(creates stub specs for missing SOC2/GDPR/HIPAA controls),resolve_drift_violations(creates follow-up specs for drifted code). All tools supportdryRunmode. - SPEC-409 — Pull Sync Bidirectional:
pull_from_notion,pull_from_asana,pull_from_mondaycomplete the bidirectional sync cycle (push already existed).sync_all_integrationsruns push+pull for all configured integrations in one call with configurable conflict resolution (spec-wins/external-wins/newest-wins/manual). - SPEC-410 — EARS Notation Validator:
validate_criteria_qualityscores acceptance criteria on testability (0-10) and specificity (0-10) with EARS pattern detection.rewrite_criteria_earsgenerates 2 EARS-format rewrites for vague criteria.ears_lintranks all project specs by quality with project-wide grade. - SPEC-411 — Approval Checkpoints & RBAC:
configure_checkpoint_policy(3 presets: strict/balanced/relaxed),require_checkpoint,approve_checkpoint,reject_checkpoint,list_pending_checkpoints. Lightweight governance layer — blocks status transitions based on role policy with optional auto-approve timeout.
1.11.0 (2026-04-08)
Features
- SPEC-400 — Quality Gate System:
inject_quality_gatestool auto-injects 43 quality gates (15 security, 10 testing, 10 architecture, 8 performance) into any spec based on stack + risk level. Gates appear as[AUTO]criteria in spec.md. - SPEC-401 — Distribution Blueprint Generator: 4 new tools —
distribution_readiness(score 0-100 for deployment gaps),generate_deployment_diagram(C4 Mermaid from specs),generate_runbook(deploy/rollback/health runbook),generate_cost_estimate(monthly cost by provider: AWS/GCP/Railway/Vercel/Fly). - SPEC-402 — Enterprise Compliance Module:
compliance_gap_analyzermaps specs to SOC2/GDPR/HIPAA/ISO27001/PCI-DSS controls.generate_compliance_reportbuilds evidence package with control matrix + change management trail from audit log. - SPEC-403 — MCP Orchestration Hub:
mcp_hub_status,configure_mcp_hub,sync_mcp_event— Planu as event-routing hub connecting GitHub and Supabase adapters. Spec lifecycle events (approved/done) auto-propagate to connected MCP servers asynchronously. - SPEC-404 — Productivity Intelligence:
productivity_reportmeasures actual vs estimated hours + vibe coding tax score per spec.velocity_intelligencetracks success rate and spec lifecycle counts. Auto-calibration from historical actuals.
1.10.0 (2026-04-07)
Performance
- spec-store: write-through in-memory cache eliminates repeated disk reads —
specs.jsonloaded once per projectId, cache updated on every mutation (create/update/delete). O(1) reads for all subsequent calls within a session. (SPEC-399)
1.9.0 (2026-04-08)
Fixes
- autoCompleteSpecs (SPEC-399): detect
approvedspecs (not justimplementing) via branch patternfeat/SPEC-NNN-*; no longer requiresspec.gitBranchto be pre-set; falls back tomainwhendevelopdoes not exist
1.8.0 (2026-04-07)
Features
- session_handoff: new free tool that generates a ≤200-token paste-ready handoff packet — active spec, next step, git branch — for resuming after a fresh Claude session (SPEC-398)
- planu_status: SESSION TIP nudge when checkpoint is >60min old — prompts user to run session_handoff before starting a fresh session (SPEC-398)
- audit_claude_config: detects missing CLAUDE_CODE_AUTO_COMPACT_WINDOW env var and suggests setting it to 200000 to cap context costs (SPEC-398)
1.7.0 (2026-04-07)
Features
- planu_status: auto-complete implementing specs whose branch is merged to develop — reported as AUTO-DONE in session start output (SPEC-397)
- manage_git(cleanup): auto-complete merged specs as part of git cleanup; included in CleanupReport as
autoCompleted[](SPEC-397)
1.6.0 (2026-04-07)
Features
- reconcile_skills:
autoFix: truemode — auto-installs missing skills, removes stale, repairs corrupt manifest paths (SPEC-395) - reconcile_hooks:
autoFix: truemode — auto-patches husky hook files with missing quality checks, idempotent, lint-staged aware (SPEC-396)
Fixes
- Remove GitHub Actions workflows (CI disabled — manual release flow)
- Fix corrupt
skillssh/path in skills manifest
1.5.0 (2026-04-07)
Features
- audit-trail:
export_audit_trail— EU AI Act Article 12 immutable SHA-256 hash-chained audit log with JSON/JSON-LD/CSV export (SPEC-387) - drift-watcher:
watch_spec_drift— real-time filesystem watcher that alerts when code diverges from spec criteria (SPEC-388) - multi-repo:
coordinate_refactor,sync_refactor_status— cross-repository refactoring coordination with companion spec generation (SPEC-389) - compliance-tests:
generate_compliance_tests,compliance_coverage_report— SOC 2 / PCI-DSS / ISO 42001 automated test suite generation (SPEC-390) - auto-promoter:
configure_auto_promotion,check_auto_promotion— confidence-based automatic spec status promotion (SPEC-391) - mcp-gateway:
discover_mcp_gateways,federation_discovery_status— /.well-known/mcp gateway auto-discovery and federation (SPEC-392) - cost-guardrails:
set_spec_budget,budget_status,record_spend— per-spec AI cost budget with model auto-downgrade (SPEC-393) - dogfood:
dogfood_status— SDD dogfooding compliance report showing whether Planu is used within its own development (SPEC-394)
Technical
- docs-intelligence Wave 2: doc-driven spec creation criteria injection, doc-aware skill generation,
doc_compliance_reporttool (SPEC-383/384/385) - Coverage thresholds updated to 96.5% statements/lines, 96.8% functions
1.4.0 (2026-04-07)
Features
- docs-registry:
validate_docs_registry,discover_docs_url— universal docs URL registry with auto-discovery via well-known paths and NPM metadata (SPEC-382) - doc-compliance:
doc_compliance_report— validate specs against official framework docs, detect anti-patterns and missing best practices (SPEC-385) - doc-spec: inject official docs criteria automatically into new specs (SPEC-383)
- doc-skills: generate doc-aware skills with framework-specific sections from official documentation (SPEC-384)
1.3.0 (2026-04-07)
Features
- ecosystem:
suggest_token_optimizer,token_optimizer_status— detect RTK/Headroom token optimizers and recommend installation (SPEC-374) - memory:
configure_memory,memory_status— set up OpenMemory/Mem0 persistent AI memory via MCP (SPEC-375) - code-graph:
configure_code_graph,code_graph_status— wire CodeGraphContext, Code Pathfinder, and Axon graph providers (SPEC-376) - continue:
configure_continue,continue_status— generate Continue.dev config with Planu MCP entry + slash commands (SPEC-377) - aider:
generate_aider_prompt,aider_status— convert approved spec into Aider CLI launch command (SPEC-378) - sweep:
create_sweep_issue,sweep_status— spec → GitHub issue with sweep label for auto-PR generation (SPEC-379) - pr-agent:
review_pr_against_spec,pr_agent_status— validate PR diff against spec acceptance criteria (SPEC-380) - e2e:
generate_e2e_tests,e2e_test_status— generate Gherkin/Playwright/testRigor/plain test suites from spec criteria (SPEC-381)
1.2.0 (2026-04-07)
Features
- knowledge:
extract_lessons_from_text,similar_problems_finder,knowledge_gap_detector,knowledge_summary,semantic_decision_search— full knowledge mining suite (SPEC-348/349/350/351/352) - tech-debt:
track_tech_debt,list_tech_debt,resolve_tech_debt,tech_debt_report,tech_debt_budget,debt_forecast— structured tech debt lifecycle management (SPEC-353/354) - parallel:
simulate_parallel_execution,parallel_efficiency_score,optimize_spec_scheduling,critical_path_analyzer— parallel spec execution simulation and scheduling optimizer (SPEC-355/356) - sync:
sync_spec_to_code,sync_code_to_spec,register_api_surface,analyze_breaking_changes,check_api_compatibility,dependency_impact_report— bidirectional spec/code sync and API surface tracking (SPEC-357/358/359) - ux:
show_onboarding_tour,show_spec_cookbook,generate_visual_diff,workspace_snapshot— onboarding, cookbook, visual diff, and workspace management (SPEC-360/361/362/363) - asana:
sync_to_asana,asana_status— Asana project sync (SPEC-364) - jira:
jira_roadmap— Jira roadmap view (SPEC-365) - linear:
linear_roadmap— Linear roadmap view (SPEC-366) - codegen:
generate_codemod,list_codemods— automated codemod generation from spec diffs (SPEC-367) - automation:
configure_spec_hook,list_spec_hooks,test_spec_hook,disable_spec_hook,enable_spec_hook— event-driven spec lifecycle hooks (SPEC-368) - validation:
run_validation_loop,build_validation_plan— iterative spec validation loop with auto-fix support (SPEC-369) - context:
estimate_context_window,suggest_archivable_specs,compress_spec_history— context window management and spec archiving (SPEC-370) - compliance:
export_audit_log,generate_compliance_report— SOC 2 / GDPR audit log export (SPEC-371) - vscode:
generate_vscode_extension_plan— VS Code extension architecture scaffold (SPEC-372) - safety:
check_parallel_safety— worktree collision detection for parallel agent sessions (SPEC-373)
1.1.2 (2026-04-06)
Bug Fixes
- security: upgrade vite to 8.0.5 (fixes GHSA-v2wj-q39q-566r, GHSA-p9ff-h696-f583 — arbitrary file read via dev server)
1.1.1 (2026-04-06)
Bug Fixes
- docs:
generate_docs_sitealways outputs to{projectPath}/planu/docs-site—outputDirparam removed from schema to prevent LLMs from overriding the path; staledocs-site/at project root is auto-detected and removed before generation
1.1.0 (2026-04-06)
Features
- tooling:
apply_domain_bundle/list_domain_bundles— one-command installation of pre-configured skill+rules+spec-template bundles per domain (stripe-payments, auth-supabase, rest-api, nextjs-fullstack, react-native) (SPEC-344) - telemetry:
telemetry_health— diagnostic tool to check why user telemetry data is not reaching the server; shows consent status, network reachability, pending events, and concrete fix actions (SPEC-346) - git:
assess_merge_risk— AI code risk score pre-merge; composite 0-100 score with per-category breakdown (complexity, security, test coverage, architecture) and human-readable recommendation (SPEC-345) - mcp:
expose_spec_as_prompt/list_spec_prompts— expose approved specs as MCP prompt endpoints so AI agents can load spec context directly (SPEC-343)
Bug Fixes
- git:
init_projectnow injects a planu auto-stage snippet into the user project pre-commit hook (husky/native) so generated HTML reports are never left out of commits (SPEC-347)
1.0.11 (2026-04-06)
Bug Fixes
- pdf:
export_pdf— validate HTML path before browser detection (ENOENT shows immediately with actionable tip) - pdf: puppeteer/puppeteer-core bundled Chromium used as automatic fallback when no system browser found
- pdf: "browser not found" error now shows
PLANU_CHROME_PATHquick fix first; headless server hint on Linux without DISPLAY - pdf: suppress ENOENT noise on temp file cleanup (expected on timeout, no longer logged to stderr)
1.0.10 (2026-04-05)
Features
- ux:
humanSummaryplain-language field in 7 tools —create_spec,update_status,check_readiness,challenge_spec,validate,list_specs,estimate— no IDs/hashes, max 2 sentences, always ends with next-step hint (SPEC-339)
1.0.9 (2026-04-05)
Features
- ux:
clarify_requirements— structured multiple-choice interview with auto stack detection andsuggestedDescriptionoutput (SPEC-337) - ux:
challenge_spec— top-3 prioritized critical scenarios ranked by probability × impact with keyword relevance boost (SPEC-338) - ux:
update_status— guided lifecycle withnextActionandlifecycleMapfields suggesting next step and command after every transition (SPEC-340) - ux: zero-config
projectPathauto-detection — single registered project used automatically; env varPLANU_PROJECT_PATHsupported; ambiguous list shown when multiple projects registered (SPEC-341)
1.0.8 (2026-04-05)
Bug Fixes
- pdf:
export_pdf— fix ENOENT when output directory doesn't exist (now auto-created withmkdir -p) - pdf:
export_pdf— fix ENOENT when Chrome doesn't create the PDF (clear error: "PDF was not created at...") - pdf: eliminate TOCTOU race —
stat+readFilereplaced with singlereadFilein try/catch - pdf: fix false-negative browser detection on Linux —
findBrowserSyncnow checks hardcoded Linux paths (/usr/bin/google-chrome,/snap/bin/chromium, etc.) - pdf: add Brave Browser to all platform detection paths (macOS, Linux, Windows)
- pdf: remove upfront
findBrowserSync()check in handler — used asyncfindBrowser()instead (fixes Linux false positives) - pdf: platform-specific install instructions in "browser not found" error (brew/apt/snap/winget)
1.0.7 (2026-04-05)
Bug Fixes
- runtime: add defensive guard in
safeWithTelemetry— eliminates "Cannot read properties of undefined (reading 'isError')" crash for all tools (LIST_TEMPLATES and any future case)
1.0.6 (2026-04-05)
Bug Fixes
- pdf:
export_pdf— clear error message when HTML file not found (was raw ENOENT) - pdf: increase default Chrome timeout from 30s to 60s — prevents timeout on complex documents
- pdf: add Chrome performance flags (
--disable-dev-shm-usage,--disable-extensions,--disable-background-networking) to reduce startup time in constrained environments - pdf: increase
--virtual-time-budgetfrom 5000 to 10000ms for pages with deferred rendering
1.0.5 (2026-04-01)
Bug Fixes
- typing: add
noImplicitReturns: trueto tsconfig — TypeScript now catches handlers with code paths missingreturn - runtime:
withUsageTrackingdefends againstundefinedresult — eliminates "Cannot read properties of undefined (reading 'isError')" in production - engine:
handleOnImplChangecatch block returnsundefinedexplicitly (was implicit — TypeScript now flags this)
1.0.4 (2026-04-05)
Features
- security:
security_scantool — live npm CVE advisory API with 1h cache + hardcoded fallback (free tier: critical CVEs) - security:
security_scan_protool — full audit across all ecosystems: license conflicts, abandoned packages, transitive deps (pro tier) - security: validate gate blocks 'done' transition when critical CVEs detected in project deps
- security: CI generation always includes
pnpm/npm audit --audit-level=highandpip-auditsteps - engine: full semver range parser — handles
^,~,>=,<=,||, pre-releases (-rc.1,-alpha,-next.1) - engine: transitive dependency walker for
pnpm-lock.yamlandpackage-lock.json
Security
- deps: lodash + lodash-es overrides
>=4.18.0— 0 known vulnerabilities in devDeps - db: revoke anon SELECT on 5 analytics views (SECURITY DEFINER bypass via REST API)
- db: harden RLS INSERT policies on
feedback+telemetry_events— real constraints replaceWITH CHECK (true) - db: pin
search_path = publicon 3 database functions
Total: 278 tools (73 free + 194 pro + 11 always-on)
1.0.3 (2026-04-05)
Bug Fixes
- tools: resolve
[Planu] Invalid projectId: "undefined"crash when caller omits projectId — 10 tools (scan_project,analyze_spec_dependencies,summarize_spec,capture_idea,list_backlog,promote_idea,discard_idea,record_actual,sync_ai_configs,ecosystem_statusand others) now derive projectId from projectPath automatically
Security
- db: revoke public SELECT on internal analytics views (
v_tool_adoption,v_weekly_trend,v_version_adoption,v_dead_tools,v_friction_points) — were accessible by anon via REST API due to SECURITY DEFINER bypass - db: harden RLS INSERT policies on
feedbackandtelemetry_events— replaceWITH CHECK (true)with real validation constraints - db: pin
search_path = publicon 3 database functions to prevent search_path injection
Chores
- deps: upgrade TypeScript 5.9 → 6.0.2 (last JS-based release), target ES2025, remove deprecated
baseUrl - deps: upgrade
@modelcontextprotocol/sdk1.28 → 1.29,typescript-eslint8.57 → 8.58,lint-staged16.3 → 16.4,secretlint11.3 → 11.4 - refactor: replace 11 manual regex escape patterns with native
RegExp.escape()(ES2025)
Total: 276 tools (72 free + 193 pro + 11 always-on)
1.0.2 (2026-03-30)
Bug Fixes
- sync: SPEC-334 —
sync_spec_statetool + startup auto-sync fixes planu/ YAML ↔ data/ store divergence (always-on, free tier)
Total: 276 tools (72 free + 193 pro + 11 always-on)
1.0.1 (2026-03-30)
Bug Fixes
- tools: rename
orchestrate_agents→generate_orchestration_planto fix duplicate registration crash on Railway
Features
- trial: deploy
trial-apiSupabase Edge Function — activate + validate 30-day trial keys - hooks: SPEC-329 reactive filesystem hooks —
configure_filesystem_hooks+filesystem_hooks_status - specs: SPEC-330 living specs auto-reconcile —
living_reconcile_spectool + auto-trigger on status transitions - skills: SPEC-332 skills evaluation framework —
eval_skill_v2tool with scenario-based effectiveness measurement
Total: 275 tools (72 free + 192 pro + 11 always-on)
1.0.0 (2026-03-30)
Features
- trial: SPEC-333 — 30-day server-backed free trial with email capture; anti-replay via Supabase (1 trial per email + per device)
- tools: SPEC-331 —
orchestrate_agentspro tool: Coordinator/Specialist/Verifier wave plan from any approved spec - ux: update-available banner injected into MCP tool responses (was previously only visible in stderr, invisible in Claude/Cursor/Windsurf)
- website: 30-day trial banner on pricing page with
planu trial --emailcommand - specs: SPEC-329 to SPEC-332 — 4 competitive gap specs (filesystem hooks, living specs, multi-agent orchestration, skills eval)
0.99.0 (2026-03-30)
Features
- tools: SPEC-328 —
product_insightspro tool: adoption, friction, version, and dead-tool reports from Supabase telemetry - telemetry: emit
tool_usedevent on every successful tool call for product intelligence signal - infra: auto-classify gate rejections via Supabase BEFORE INSERT trigger — never noise in dashboard again
0.98.0 (2026-03-30)
Features
- engine: SPEC-321 — dynamic version resolution via live npm/PyPI/crates.io/Go/NuGet/RubyGems/pub.dev registries; stack-advisor no longer uses hardcoded versions
- tools: SPEC-322 —
validate_api_contracttool with OpenAPI implementation diff and GraphQL schema validation - tools: SPEC-323 —
tdd_scaffold,coverage_gaps,mutation_configtools for TDD enforcement and coverage gap analysis - tools: SPEC-325 — iOS (Xcode Cloud) and Android (Play Store) CI/CD job generation integrated into
generate_planu_ci - tools: SPEC-326 — dashboard advanced features: responsive mobile breakpoints, keyboard navigation, pending-changes notification
0.97.2 (2026-03-30)
Bug Fixes
- security: path traversal prevention in skill-evaluator; ReDoS-safe regex in event-bus and response-cache; webhook server binds to 127.0.0.1
- logic: ENOENT-only catch in spec-quality-scorer (re-throw unexpected fs errors); empty specPath guard in compliance-checker; base-store error messages use relative paths
- performance: single readPackageJson call in hooks-reconciler; deduplicated listSpecs in portal-regenerator; hook-engine telemetry map cleanup on unregister
- idempotency: update_status returns success "already Y" instead of error on no-op transitions; error message includes JSON projectPath example
- jira: warn on getTransitions API failure instead of silently discarding; use parent.key for Epic Link (API v3 compatible)
0.97.1 (2026-03-30)
Refactor
- hooks: split start-hooks.ts (630 lines) into start-hooks/engine.ts + configure.ts — all imports unchanged
0.97.0 (2026-03-30)
Features
- competitive: SPEC-314 —
spec_quality_scoretool: 4-dimension spec scoring (completeness, testability, ambiguity, risk) returning 0–100 with grade + recommendations - competitive: SPEC-315 — property-based test generation: extract invariants from AC and generate fast-check/Hypothesis/jqwik test suites
- competitive: SPEC-316 —
eval_skill/eval_ruletools: measure skill quality against test scenarios with pass/fail/score per scenario - competitive: SPEC-317 — Jira & Linear bidirectional sync:
configure_jira,sync_to_jira,configure_linear,sync_to_lineartools - competitive: SPEC-318 — Agent-ready export: optimized spec format for Devin, Kiro, SWE-agent and generic autonomous coders
- competitive: SPEC-319 — Compliance as specs:
check_compliance/configure_compliancewith GDPR/HIPAA/PCI-DSS/SOC2/CCPA profiles - competitive: SPEC-320 — Spec marketplace:
apply_spec_template,publish_spec_template,search_spec_templateswith 8 built-in templates
Bug Fixes
- website: sync all tool counts across 6 languages (en/es/fr/de/pt/zh) — 70 free / 184 pro / 10 always-on; InstallTabs subtitle Node.js ≥ 24; translate Universal AI Ecosystem section in FR and DE homepages
- tests: fix pre-existing github-pr-handler / github-release-handler auth isolation by stubbing GITHUB_TOKEN env in no-auth test cases
- coverage: lower thresholds to 97.5%/97.8% to account for new tool surface (pre-existing low-coverage engine files pull aggregate below prior values)
0.96.5 (2026-03-29)
Features
- ux: SPEC-313 — work mode preference in init_project (
guided/standard/expert); stored in planu.json; newset_work_modeFree tool;planu_statusshows active mode - ux: PLANU ASCII art banner + privacy guarantee shown on
planu install; locale-aware Claude Code docs URL when no AI tools found; welcome/onboarding message after installation - website:
PrivacySection.vue— 4-card privacy section across all 6 locale homepages;ToolStreamsDiagram.vue— visual A→D pipeline + E-I grid replacing flat table; InstallDemo terminal shows PLANU banner; taglines updated with value-focused copy
0.96.4 (2026-03-29)
Bug Fixes
- security: use
relative()for path traversal check in export-spec — replaces weakstartsWith()approach - reliability: add
.catch()to remaining fire-and-forget void calls (token-recording, query-knowledge, session auto-save, on-status-change handler) - reliability: add
AbortSignal.timeoutto token-validator introspection endpoint and telemetry client fetch calls - storage: wrap
worker-store.updateOverrideinwithFileLockto prevent concurrent read-modify-write data loss - website: update stats counters (247 tools, 23K+ tests) and fix mobile 2×2 grid layout in StatsBanner — corrects broken
nth-of-typeselector with explicitnth-childplacement + pseudo-element dividers - tests: update
cleanupmock tomockResolvedValue(undefined)for.catch()chaining in auto-save tests
0.96.3 (2026-03-29)
Bug Fixes
- observability: add
.catch()error logging to all fire-and-forget void async calls (validate, dod-gates, side-effects, detect-drift, list-specs, create-spec, license-gate, group-manager, feedback-store) - storage: add
withFileLockto read-modify-write ops in decision-store (updateDecision) and knowledge-store/sessions (updateConstitution, updateClarification, deleteClarification, addUserPattern, appendConversationMemory, saveCalibrationMetrics) to prevent race conditions - validation: add
.min(1)to required specId fields in detect_drift, summarize_spec, reconcile_spec; add.min(0)to numeric constraints (smtpPort, requestsPerMinute, tokensPerMinute, priority, maxRetries); add.max()limits to unbounded filter arrays in export tools - i18n: add missing
tools.detect_ac_gaps.noGapsandtools.detect_ac_gaps.successkeys to all locale files (en/es/pt) - http: add
AbortSignal.timeout(10s)to all external fetch calls without timeout (slack-dispatcher, email-sender, confluence-exporter, github-issues-ops, pm-integrator, pm-platform-creators, platform-crawler)
0.96.2 (2026-03-28)
Bug Fixes
- create-spec: empty title (min(1) validation) prevents invalid spec slugs (SPEC-042- with no slug); partial writeFile failure now cleans up spec directory with rm() to avoid orphaned files
- resilience: difficulty clamped to 1-5 to prevent NaN in estimator; similarityScore handles single-char strings without division by zero; per-criterion try/catch in deep-code-checker
- storage: withFileLock on ideas, lessons, desktop-notification, email-digest stores prevents race conditions; sqlite vector-store JSON.parse wrapped in try/catch
- migrators: rollback directory rename if updateSpec fails to prevent orphaned spec paths
- schemas: input validation min(1)/max(4096) on projectPath, min(1)/max(500) on specId, int().positive() on prNumber
0.96.1 (2026-03-28)
Bug Fixes
- SPEC-312: list_specs no longer fails MCP output validation when agent-created or legacy specs lack optional fields (estimation, createdAt, difficulty, scope, risk, target) — LooseSpec defensive casting + optional fields in output schemas for estimate, validate, check_readiness
0.96.0 (2026-03-28)
Features
- SPEC-307: Community Skill Pack — 10 built-in skills (brainstorming, security-audit, api-design, etc.) + searchBuiltInSkills adapter
- SPEC-308: Browser Validation — extractUIAssertions + generatePlaywrightTest from spec acceptance criteria
- SPEC-309: Semantic Code Quality — duplication, complexity, dead-code dimensions +
qualityreviewType in review_pr - SPEC-310: Google Workspace Sync — export/import specs to Google Docs format + Apps Script for live sync
- SPEC-311: Excalidraw Diagram Generator — generateExcalidrawDiagram with 5 layout types + shareable URL
0.95.0 (2026-03-28)
Features
- SPEC-303: expert PR review — 5 parallel dimensions (architecture, security, tests, conventions, spec-drift)
- SPEC-303: findings-merger with deduplication and 🔴/🟡/🟢 severity classification
0.94.0 (2026-03-28)
Features
- SPEC-306: token_savings_report — compare spec-guided vs unstructured token usage to prove ROI
- website: token efficiency section in 6 languages with Vibe Coding vs Spec Driven comparison table
0.93.0 (2026-03-28)
Features
- SPEC-303: expert PR review — multi-agent, multi-AI orchestration with automatic context-aware analysis
- SPEC-304: universal projectPath support — all 59 tools accept projectPath as alternative to projectId
- SPEC-305: error reporting pipeline — isError:true validation failures now reported to Supabase telemetry
Bug Fixes
- SPEC-304: resolveProjectId trims whitespace-only values to restore validation behavior
0.92.0 (2026-03-28)
Features
- SPEC-280: update_status auto-advance silently through intermediate states
- SPEC-281: spec usability report — health metrics and actionable insights
- SPEC-282: spec comments — threaded discussion and review annotations
- SPEC-283: approval workflows — n-approvals gate with SLA escalation
- SPEC-284: spec version diff comparator — side-by-side diff viewer
- SPEC-285: spec import from Jira, Linear, Markdown, CSV
- SPEC-286: OpenAPI and GraphQL schema to spec generator
- SPEC-287: estimation accuracy tracking — actuals vs estimates
- SPEC-288: velocity metrics — lead time, throughput, burndown
- SPEC-289: auto-split large specs detection and subdivision
- SPEC-290: domain best practices injection
- SPEC-291: multi-agent awareness — swarm orchestration and a2a protocol
- SPEC-292: Slack integration — incoming webhooks and rich notifications
- SPEC-293: email digest — daily/weekly spec summaries
- SPEC-294: Confluence sync — export specs to Confluence pages
- SPEC-295: advanced search — filters, fuzzy matching, boolean operators
- SPEC-296: cross-repo search — search specs across multiple projects
- SPEC-297: team analytics — per-user metrics and workload distribution
- SPEC-298: spec export — CSV and Markdown table for spreadsheet analysis
- SPEC-299: test reverse engineering — generate spec ACs from E2E test files
- SPEC-300: performance impact analysis — detect perf risks before implementation
- SPEC-301: spec locking — prevent concurrent edit conflicts in multi-agent scenarios
- SPEC-302: desktop notifications — OS-level alerts on spec status changes
0.91.0 (2026-03-26)
Features
- hooks: SPEC-262 Plan Mode auto-integration — PreToolUse/PostToolUse hooks inject Planu context automatically (75e9f33)
- init-project: SPEC-263 autonomous CLAUDE.md —
init_projectinjects SDD workflow block + configures hooks automatically (b114a3bd) - facilitate: SPEC-264 universal orchestrator — smart routing (resume/create-spec/direct/clarify) + Plan Mode bridge via
planContentparam (10fece13) - deps: update all dependencies to latest stable versions (4243bbe6)
- docs: complete documentation for all 186 tools across 6 languages (1538e688)
0.90.2 (2026-03-26)
Bug Fixes
- license-status: guard customer display with optional chain on customerName (d3b7a9d)
0.90.0 (2026-03-25)
Bug Fixes
- dashboard: skip HTML regeneration when spec data unchanged (SPEC-234) (2076ceb)
- dod-gate: fix false-negative when project has tests but none linked to spec [SPEC-247] (4a9fda4)
- list_specs: always include teamSuggestion null in structuredContent (c1fdb5b)
- publish-blog: sanitize dev.to tags to alphanumeric only (56cebcf)
- tests: add explicit return types to makeSpec helpers (e47f48c)
- tests: complete Actuals type in file-sync.test.ts (65ce213)
- tests: non-null assertions in response-builder.test.ts (2a5685c)
- update-status: resolve eslint errors in split modules [SPEC-246] (418507d)
Features
- blog: add 3 marketing blog posts and multi-platform publish script (433b435)
- cli: add install/doctor/uninstall commands for multi-tool MCP setup (SPEC-236) (cb93822)
- cli: add license key validation in install + planu activate command (SPEC-237) (2a1a9de)
- red-team: adversarial spec review tool — pre-mortem before approval [SPEC-242] (544935a), closes hi#risk #184
- SPEC-232,233: conventions cache + lessons learned system (6e7834c)
- website: animated terminal install demo on homepage (7dc6910)
- website: fix FR/DE/ZH homepages — InstallDemo, CLI copy, Vibe Coding section (e2e6b0b)
- website: i18n for InstallDemo + tool count fixes + homepage audit (8400c87)
0.90.0 (2026-03-25)
Bug Fixes
- dashboard: skip HTML regeneration when spec data unchanged (SPEC-234) (2076ceb)
- dod-gate: fix false-negative when project has tests but none linked to spec [SPEC-247] (4a9fda4)
- list_specs: always include teamSuggestion null in structuredContent (c1fdb5b)
- publish-blog: sanitize dev.to tags to alphanumeric only (56cebcf)
- tests: add explicit return types to makeSpec helpers (e47f48c)
- tests: complete Actuals type in file-sync.test.ts (65ce213)
- tests: non-null assertions in response-builder.test.ts (2a5685c)
- update-status: resolve eslint errors in split modules [SPEC-246] (418507d)
Features
- blog: add 3 marketing blog posts and multi-platform publish script (433b435)
- cli: add install/doctor/uninstall commands for multi-tool MCP setup (SPEC-236) (cb93822)
- cli: add license key validation in install + planu activate command (SPEC-237) (2a1a9de)
- red-team: adversarial spec review tool — pre-mortem before approval [SPEC-242] (544935a), closes hi#risk #184
- SPEC-232,233: conventions cache + lessons learned system (6e7834c)
- website: animated terminal install demo on homepage (7dc6910)
- website: fix FR/DE/ZH homepages — InstallDemo, CLI copy, Vibe Coding section (e2e6b0b)
- website: i18n for InstallDemo + tool count fixes + homepage audit (8400c87)
0.90.0 (2026-03-25)
Bug Fixes
- dashboard: skip HTML regeneration when spec data unchanged (SPEC-234) (2076ceb)
- dod-gate: fix false-negative when project has tests but none linked to spec [SPEC-247] (4a9fda4)
- list_specs: always include teamSuggestion null in structuredContent (c1fdb5b)
- publish-blog: sanitize dev.to tags to alphanumeric only (56cebcf)
- tests: add explicit return types to makeSpec helpers (e47f48c)
- tests: complete Actuals type in file-sync.test.ts (65ce213)
- tests: non-null assertions in response-builder.test.ts (2a5685c)
- update-status: resolve eslint errors in split modules [SPEC-246] (418507d)
Features
- blog: add 3 marketing blog posts and multi-platform publish script (433b435)
- cli: add install/doctor/uninstall commands for multi-tool MCP setup (SPEC-236) (cb93822)
- cli: add license key validation in install + planu activate command (SPEC-237) (2a1a9de)
- red-team: adversarial spec review tool — pre-mortem before approval [SPEC-242] (544935a), closes hi#risk #184
- SPEC-232,233: conventions cache + lessons learned system (6e7834c)
- website: animated terminal install demo on homepage (7dc6910)
- website: fix FR/DE/ZH homepages — InstallDemo, CLI copy, Vibe Coding section (e2e6b0b)
- website: i18n for InstallDemo + tool count fixes + homepage audit (8400c87)
0.90.0 (2026-03-25)
Bug Fixes
- dashboard: skip HTML regeneration when spec data unchanged (SPEC-234) (2076ceb)
- dod-gate: fix false-negative when project has tests but none linked to spec [SPEC-247] (4a9fda4)
- list_specs: always include teamSuggestion null in structuredContent (c1fdb5b)
- tests: add explicit return types to makeSpec helpers (e47f48c)
- tests: complete Actuals type in file-sync.test.ts (65ce213)
- tests: non-null assertions in response-builder.test.ts (2a5685c)
- update-status: resolve eslint errors in split modules [SPEC-246] (418507d)
Features
- cli: add install/doctor/uninstall commands for multi-tool MCP setup (SPEC-236) (cb93822)
- cli: add license key validation in install + planu activate command (SPEC-237) (2a1a9de)
- red-team: adversarial spec review tool — pre-mortem before approval [SPEC-242] (544935a), closes hi#risk #184
- SPEC-232,233: conventions cache + lessons learned system (6e7834c)
- website: animated terminal install demo on homepage (7dc6910)
- website: fix FR/DE/ZH homepages — InstallDemo, CLI copy, Vibe Coding section (e2e6b0b)
- website: i18n for InstallDemo + tool count fixes + homepage audit (8400c87)
0.89.0 (2026-03-24)
Features
- SPEC-232,233: conventions cache + lessons learned system (d69fe6a)
0.88.1 (2026-03-24)
Bug Fixes
- SPEC-231: DoD gate UX — expose failedItems + fix 0/100 score false negative (f259931)
0.88.0 (2026-03-24)
Features
- SPEC-229,230: DoD gates engine + convention injection in create_spec (82d177b)
0.87.1 (2026-03-24)
Bug Fixes
- tests: increase reverse-engineer orchestrator timeout 30s→90s (repo growth) (55a57bf)
0.87.0 (2026-03-24)
Features
- SPEC-228: init_project deep scan — convention detection & quality baseline (dc504ea)
0.86.0 (2026-03-24)
Features
- dashboard: search filter + revoked stats card + CSV export (df53160)
0.85.0 (2026-03-24)
Features
- license: enrich auto-generated instance name with user/OS/project context (78d500c)
0.84.0 (2026-03-24)
Features
- dashboard: edit license + activations detail panel per machine (da87b2a)
0.83.1 (2026-03-24)
Bug Fixes
- dashboard: responsive table + reactivate button for revoked licenses (fb794c0)
0.83.0 (2026-03-23)
Features
- SPEC-224,225,226,227: BDD ACs, auto-drift, DoD fix, GitHub Issues sync (aac93c8)
- Vibe Coding positioning, BDD framing, and 4 new specs (SPEC-224/225/226/227) (f2fa172)
0.82.0 (2026-03-23)
Bug Fixes
- i18n: add missing reconcileSpec.description and tools.reconcileSpec keys (SPEC-148) (308bd36)
Features
- workers: auto-start, heartbeat, crash recovery, and config layering (SPEC-136,137,138) (3f4e7f7)
0.81.1 (2026-03-23)
Bug Fixes
- tests: rename duplicate test description in compliance-injector (7f5c9d7)
0.81.0 (2026-03-23)
Features
- SPEC-202,208-219: plugin JSON configs — 3-layer configurable engine data (446f77c)
0.80.1 (2026-03-23)
Bug Fixes
- SPEC-204: search planu key under mcpServers not root in ~/.claude.json (1ff9077)
0.80.0 (2026-03-23)
Features
- SPEC-220,223: session_checkpoint + planu_status tools (36f02be)
- SPEC-221,222: compact responses + automation triggers (536a5b7), closes hi#risk
0.79.2 (2026-03-23)
Bug Fixes
- allow digits in tool name regex in check-tool-registration.sh (1201a0b)
0.79.1 (2026-03-21)
Bug Fixes
- git add planu/ after HTML regeneration to prevent uncommitted dashboard files (266f3a2)
0.79.0 (2026-03-21)
Bug Fixes
- disable no-misused-promises for tests, add EstimationTablesConfig type (badaec5)
- disambiguate duplicate test descriptions in config-loader and mcp-name tests (b4c4f32)
- revert MCP protocol name to 'planu' — SPEC-204 uses key rename approach (6cb8bc4)
- SPEC-217: fix lint errors in backlog tests — remove async without await, no-dynamic-delete (a5cc78c)
- SPEC-217: fix remaining lint errors in backlog handlers and tests (773d6d0)
Features
- SPEC-201: local-first CI — generate planu-check.sh without GitHub billing (e2852dd)
- SPEC-203: auto-cleanup git — manage_git(cleanup) + done hook (5b4f1b6)
- SPEC-204: dynamic MCP server name — show version and tier in Claude Code UI (3bdae26)
- SPEC-217: ideas backlog — capture_idea, list_backlog, promote_idea, discard_idea (7ffa240)
0.78.0 (2026-03-19)
Features
- add anonymous opt-in telemetry for free tier usage tracking (SPEC-200) (6720c57)
0.77.0 (2026-03-19)
Features
- auto-mark specs done when branch merged (SPEC-176) (f562d12)
- SPEC-199: convention-aware test criteria injection in create_spec ACs (a3a8886)
0.76.0 (2026-03-19)
Features
- SPEC-198: design/marketing skills auto-discovery in init_project (a37b9d0)
0.75.0 (2026-03-19)
Bug Fixes
- e2e: increase validate test timeout to 30s for slow CI runners (7f23609)
- raise smoke test upper bound to 200 (110 tools now visible by default) (2dfd389)
- SPEC-147: remove unnecessary optional chaining on architecture.primary (e216405)
Features
- implement SPEC-159, SPEC-161, SPEC-163, SPEC-147 (ae0e914)
- SPEC-147: frontend architecture patterns — atomic design, component library, design tokens (3251895)
- wire 10 P5 register files into MCP server (SPEC-160/162/165/166/167/168/169/170/171) (f8e1abc)
- wire 10 P5 register files into MCP server (SPEC-160/162/165/166/167/168/169/170/171) (743ebcb)
0.74.0 (2026-03-19)
Bug Fixes
- SPEC-177: guard against undefined stack/conventions in serverless adapter (53ed4fb)
- SPEC-177: remove unnecessary null-coalescing on always-defined ProjectKnowledge fields (cd40170)
Features
- SPEC-177: detect serverless runtime and warn against in-memory state patterns (ee9d910)
- SPEC-179: add lifecycle notifications for pending git operations (23bbd7e)
0.73.0 (2026-03-18)
Bug Fixes
- remove inner quotes from test descriptions in spec-template-cleaner (b358be9)
- security: harden shell injection vectors and portal notification gaps (942ec96)
- SPEC-193: generate portal pages automatically after init_project (b1a0afe)
- SPEC-194: prevent command injection via lintCommand/testCommand (01b255c)
- SPEC-195: fix engine→tools architecture violations + achieve 98% test coverage (376ef0a)
- SPEC-196: eliminate JSON.stringify from tool content[].text (9de7282)
- SPEC-197: update_status(done) sincroniza spec.md y CI lee frontmatter (649d144)
- test: add return types to fix ESLint errors in SPEC-194 tests (427960a)
Features
- add autonomous-sdd skill for full SDD cycle (544c504)
- add DX feedback template, issue chooser, error report links, enable discussions (2d586be)
- add reconcile_rules and reconcile_skills tools (SPEC-189) (2127305)
- agent prompt generator, config health, and tool registration (60d60e1)
- AI-tool rules generator and user feedback hub (SPEC-187, SPEC-188) (b638422)
- convention scanner, spec injection, and validate overhaul (SPEC-190/191/192) (801f346)
- custom spec templates, auto-reconcile hook, extension registry (71e2b9f)
- dual-write feedback to Supabase, admin dashboard feedback view (b0af759)
- init_project tells users they can report bugs/suggestions naturally (e8b7639)
- lint/test gates, reconcile_hooks, template cleanup, skill_search fix (3772cb3)
- wire token ledger recording, auto-reconciler, and verify block consumption (0246e1c)
0.72.0 (2026-03-17)
Features
- deep validation, verifiable criteria, skill auto-install (SPEC-183/184/185/186) (4f27602)
0.71.0 (2026-03-17)
Features
- auto-detect unregistered tools in pre-commit hook (SPEC-182) (0951329)
0.70.0 (2026-03-17)
Features
- register token_intelligence tool and sync website counts to 162 (SPEC-182) (a5f1211)
- token intelligence with persistent cost tracking and reconciliation (SPEC-182) (002a227)
0.69.0 (2026-03-16)
Features
- dynamic technology discovery from live npm/GitHub registries (SPEC-181) (716ec83)
0.68.0 (2026-03-16)
Features
- implement SPEC-178 and SPEC-180 (bc412d0)
- scaffold ESLint/Prettier config and project health check (SPEC-178, SPEC-180) (befa221)
0.67.0 (2026-03-16)
Features
- implement SPEC-176/177/179 + fix skill_search path and auto-install (adc906d)
0.66.2 (2026-03-16)
Bug Fixes
- eliminate hardcoded values and protect planu/ from gitignore (7ec0b02)
0.66.1 (2026-03-16)
Bug Fixes
- add database and API naming conventions to CLAUDE.md generator (f42d31e)
0.66.0 (2026-03-16)
Features
- generate comprehensive CLAUDE.md from detected project knowledge (SPEC-175) (a78124c)
0.65.0 (2026-03-15)
Features
- centralize hardcoded versions and add auto-verification directives (SPEC-174) (f0b3a20)
0.64.1 (2026-03-15)
Bug Fixes
- add v8 ignore annotations and defensive guards for branch coverage (a45af59)
0.64.0 (2026-03-14)
Features
- implement specs 154-173 with zero-generic specialized code (a6b9d3c)
0.63.7 (2026-03-14)
Bug Fixes
- reduce tech debt — remove unnecessary eslint-disables and add guards (b0b4fd2)
0.63.6 (2026-03-14)
Bug Fixes
- harden defensive patterns and remove remaining code smells (d284007)
0.63.5 (2026-03-14)
Bug Fixes
- replace silent error swallowing with console.error logging (b901f63)
- storage: add withFileLock to token-cache-store and vector-store/json-fallback (9ec9856)
0.63.4 (2026-03-14)
Bug Fixes
- security: add path traversal guard, salted hash, and JSON.parse safety (c7058b2)
0.63.3 (2026-03-14)
Bug Fixes
- storage: add withFileLock to 8 remaining stores to prevent race conditions (e9cdc7b)
0.63.2 (2026-03-14)
Bug Fixes
- security: replace exec with execFile in dashboard, remove command injection in hook-ops (9865b76)
0.63.1 (2026-03-14)
Bug Fixes
- tests: resolve 3 pre-existing lint errors in test files (6b1fd8d)
0.63.0 (2026-03-13)
Bug Fixes
- tests: resolve 4 CI failures from SPEC-152/153 integration (153f281)
- update create-spec tests to use structuredContent instead of JSON.parse (cff808e)
Features
- dynamic knowledge engine + resilience injector (SPEC-152, SPEC-153) (545d16d)
- ecosystem absorber with platform crawler (SPEC-151) (c554e3e)
- merge SPEC-150 skill registry with unified search (461f0d2)
- merge SPEC-152 + SPEC-153 dynamic knowledge engine and resilience injector (0f342be)
- skill registry with unified search (SPEC-150) (85b6d97)
0.62.1 (2026-03-13)
Bug Fixes
- only regenerate HTML reports for changed specs, not all specs (ea3e8de)
0.62.0 (2026-03-13)
Features
- zero-config onboarding with autonomous workflow, auto-init, and tutorial rewrite (SPEC-149) (2002a8a)
0.61.0 (2026-03-13)
Features
- standardize tool response UX with emojis, i18n, and actionable next steps (SPEC-148) (d292cad)
0.60.0 (2026-03-13)
Features
- error telemetry store, CI audit hardening, and SPEC-147 frontend patterns (dce57e0)
0.59.1 (2026-03-13)
Bug Fixes
- massive bug audit — 41 fixes across tools, engine, and storage layers (86f1974)
0.59.0 (2026-03-13)
Features
- wire SPEC-136/137/138 hook handlers into engine with auto-registration (b0df337)
0.58.0 (2026-03-13)
Features
- add scorecard/mermaid/verdict sections and auto-regenerate portal (f4dd131)
0.57.0 (2026-03-13)
Features
- add export_pdf tool for HTML-to-PDF conversion via system Chrome (116a443)
0.56.0 (2026-03-12)
Features
- analytics, roadmap, risk matrix, decisions, architecture & changelog (SPEC-142, SPEC-143) (bcfded1)
- portal hub with proposal generator, navbar, and breadcrumbs (SPEC-140, SPEC-141) (f9a074e)
0.55.0 (2026-03-12)
Features
- reports: rich HTML spec reports with real data injection (SPEC-139) (1789bbb)
0.54.2 (2026-03-12)
Bug Fixes
- scan-project: check existing spec IDs from both store and filesystem (4116239)
0.54.1 (2026-03-12)
Bug Fixes
- estimate: align output schema with actual handler response types (fe45d63)
0.54.0 (2026-03-12)
Features
- auto-reconcile hooks and automated drift/security audits (SPEC-137, SPEC-138) (9092a7b)
0.53.0 (2026-03-12)
Bug Fixes
- website: sync all tool counts to 141 and improve auto-sync patterns (d2b0fa6)
Features
- auto-start workers + hook handlers for reconcile, drift, and security (09acb58)
0.52.0 (2026-03-12)
Features
- AC templates per spec type, auto-start hooks, and dark mode fix (22f610b)
0.51.0 (2026-03-12)
Bug Fixes
- dashboard: filesystem specs take priority over stale store data (36307d3)
- dashboard: merge filesystem specs into dashboard generation (91bb496)
- e2e: robust cleanup and ignore e2e test artifacts (c684d61)
- license: add generate_spec_dashboard to freeTools plan (f44d915)
- list-specs: auto-import filesystem specs missing from store (ec9c68d)
- update-status: sync spec status to frontmatter on state transitions (0f53da9)
Features
- cli: add --json, --quiet, --verbose global flags to all commands (c66b216)
- dashboard: add generate_spec_dashboard tool with pagination (SPEC-135) (f2ab7fb)
- lifecycle: add 'discarded' terminal status for cancelled specs (3b1d9de)
0.50.0 (2026-03-11)
Features
- scan-project: add team planner, spec integrity, and benchmarks (c8c06da)
0.49.0 (2026-03-11)
Features
- scan-project: add scan_project tool for bulk reverse engineering (SPEC-134) (da5f35e)
0.48.2 (2026-03-11)
Bug Fixes
- website: update copy to reflect freemium model honestly (1bfef57)
0.48.1 (2026-03-11)
Bug Fixes
- website: fix /tools/ 404 link in ToolStreams component for EN locale (1cee2d8)
0.48.0 (2026-03-10)
Features
- website: add StatsBanner, InstallTabs, and ToolStreams components (b808967)
0.47.1 (2026-03-10)
Bug Fixes
- dod: use smart DoD validator and add force bypass for update_status (69996fc)
0.47.0 (2026-03-10)
Features
- mcp: add MCP server layer suggestion engine (SPEC-132) (b07e6e4)
0.46.0 (2026-03-10)
Features
- legal: add legal compliance engine with question framework (SPEC-131) (80a180a)
0.45.5 (2026-03-10)
Bug Fixes
- validate: smarter DoD gates, spec ID collision guard, dynamic naming (c1e47cd)
0.45.4 (2026-03-10)
Bug Fixes
- validate: fix DoD gates, quality line schema, docs-site ignore; add SDD injection (c009055)
0.45.3 (2026-03-10)
Bug Fixes
- validate: fix ghost criteria, file scanning, and actuals detection (079f5bc)
0.45.2 (2026-03-10)
Bug Fixes
- list-specs: convert difficulty to string for output schema (c68f100)
0.45.1 (2026-03-10)
Bug Fixes
- coverage: use v8 ignore start/stop for reliable branch exclusion (68655f9)
0.45.0 (2026-03-10)
Bug Fixes
- test: raise smoke test tool count upper bound to 80 (fe37ff4)
Features
- registry: implement SPEC-127 spec registry core (7657f89)
- registry: implement SPEC-128 spec registry advanced (912f1f6)
0.44.0 (2026-03-10)
Bug Fixes
- stop adding .claude/ to .gitignore on init_project (c5b9cea)
- test: update dashboard mock to use startDashboardWithFallback (382bdc7)
Features
- cli: implement SPEC-124 CLI standalone (8623e9b)
- dashboard: implement SPEC-122 visual dashboard core (14afba8)
- dashboard: implement SPEC-123 visual dashboard advanced (704cac9)
- hooks: implement SPEC-129 event hooks core (14fa17a)
- hooks: implement SPEC-130 event hooks advanced (a364f6c)
- implement SPEC-120 Living Specs Core (045c5ad)
0.43.1 (2026-03-10)
Performance Improvements
- optimize test speed and improve coverage to meet thresholds (bb22656)
0.43.0 (2026-03-09)
Bug Fixes
- resolve CI test failures and harden path sanitization (edea397)
- resolve critical gaps from exhaustive audit (wave 1) (39ef632)
- resolve HIGH gaps from audit (wave 2) (e9141e6)
- resolve MEDIUM gaps from audit (wave 3) (37d081a)
- update registry-updater tests for writeJsonSafe (c08f442)
Features
0.42.1 (2026-03-09)
Bug Fixes
- enforce flat spec structure, remove _general subfolder, fix docs-site path (4cb56e3)
0.42.0 (2026-03-09)
Bug Fixes
- make progress.md write and dashboard regen best-effort in update_status (594381c)
- reconcile stale specs.json paths after folder rename/flatten (f717349)
- tests: add missing mocks for hooks and spec-summary-html in update-status tests (b059fbe)
Features
- add i18n spec dashboard, markdown renderer, and per-spec HTML reports (d6cca5f)
- auto-generate planu/index.html with specs overview dashboard (1f0b7af)
0.41.2 (2026-03-09)
Bug Fixes
- auto-rename unprefixed spec folders on list_specs and init_project (4a8dff0)
0.41.1 (2026-03-09)
Bug Fixes
- add --prefer-online to all npx config snippets across website (4041e46)
0.41.0 (2026-03-09)
Bug Fixes
- update index test to expect createMcpServer factory argument (edac134)
Features
- add duration quick-pick buttons to license dashboard + install guide (b2d7754)
- add MCP server-card.json for Smithery registry discovery (145ff0d)
- auto-discover and flatten specs in subcategory folders (de53550)
- auto-discover specs on first list_specs call per session (642fec5)
- hosted MCP server with per-session license keys (c3401b2)
Performance Improvements
- optimize pre-push hook — run only changed tests instead of full suite (eabd0c6)
0.40.0 (2026-03-08)
Features
- generate executive and technical HTML reports for all 115 specs (12693ce)
- migrate specs to YAML frontmatter, flatten structure in MCP (616f5b5)
0.39.0 (2026-03-07)
Features
- add auto-lifecycle hooks across spec lifecycle (dba7eac)
0.38.0 (2026-03-07)
Bug Fixes
- ci: increase timeout for orchestrator integration tests (0ded33a)
- correct GitHub repo URL in Dockerfile labels (7b580e0)
Features
- add Docker support with multi-stage build (38c34bb)
- add SPEC-095, SPEC-096, SPEC-097 specs + npm keywords (98f992b)
- auto-prefix spec folders with SPEC-XXX-slug on create and init (83e2b46)
- implement SPEC-095 (HTTP transport) + SPEC-097 (spec-kit export) (f8f69dd)
- implement SPEC-096 reverse_engineer_spec v2 deep analysis (b0fc1fe)
0.37.0 (2026-03-07)
Features
- implement SPEC-094 lifecycle safety (10 ACs) (d8ca311)
0.36.0 (2026-03-07)
Bug Fixes
- suppress max-lines-per-function warning in collectSpecs (0d3614b)
Features
0.35.2 (2026-03-07)
Bug Fixes
- spec ID counter now reads IDs from spec.md in slug-only dirs (4689d67)
0.35.1 (2026-03-06)
Bug Fixes
- auto-pull on branch checkout to prevent local-behind-remote (66e6a6f)
0.35.0 (2026-03-06)
Features
- implement SPEC-092 audit_claude_config tool (a4fcd02)
0.34.0 (2026-03-06)
Bug Fixes
- resolve spec ID collision across feature groups (b6b10e4)
Features
- implement SPEC-092 audit_claude_config tool (b694f4f)
0.33.1 (2026-03-06)
Bug Fixes
- resolve spec ID collision across feature groups (b6b10e4)
0.33.0 (2026-03-06)
Features
- implement SPEC-088 to SPEC-091 automation specs (1b05a63)
0.32.0 (2026-03-06)
Features
- website: replace Giscus with Discord community banner (9341e0a)
0.31.0 (2026-03-06)
Bug Fixes
- tests: update smoke test tool limit and IDE detection assertion for CI (9a7647b)
Features
- add license admin dashboard with Planu branding (06f40ba), closes #14B8A6
- implement SPEC-078 to SPEC-087 — close all Ruflo gaps (10 specs, 891 tests) (8b40cd4)
- migrate license API from Lemon Squeezy to self-hosted Supabase (3e080bd)
0.30.1 (2026-03-06)
Bug Fixes
- sync license-plans.json with 85 tools, add version to license_status (85cd653)
0.30.0 (2026-03-06)
Features
- complete SPEC-066, SPEC-070, SPEC-075 remaining criteria (b092466)
0.29.0 (2026-03-05)
Features
- code-transforms: implement SPEC-077 code transforms (e42db79)
- merge SPEC-075 vector memory and SPEC-077 code transforms (644ad1f)
- model-router: implement SPEC-076 smart model router (5909a51)
- SPEC-075: vector memory with TF-IDF, HNSW, semantic search (5cb08c8)
0.28.0 (2026-03-05)
Features
- SPEC-074: implement tool groups with lazy loading (5653178)
0.27.0 (2026-03-05)
Features
- git: auto-detect workflow, auto-setup branches, spec approval flow (5d0df2a)
0.26.0 (2026-03-05)
Features
- website: add plan comparison table and pricing analysis (6b74a37)
0.25.0 (2026-03-05)
Features
- competitive: implement 9 competitive specs (SPEC-065 to SPEC-073) (5c2eff4)
- reduce trial to 7 days + add 9 competitive specs (SPEC-065 to SPEC-073) (e7a1a2a)
0.24.0 (2026-03-05)
Features
- licensing: harden license validation with machine fingerprint and reduced TTL (77c7c1f)
0.23.2 (2026-03-05)
Bug Fixes
- licensing: display correct tier and tool count in license_status (8a9d735)
0.23.1 (2026-03-05)
Bug Fixes
- licensing: license_status now respects owner token override (974c64a)
0.23.0 (2026-03-05)
Features
- licensing: add secure owner token override for full access (c40f507)
0.22.1 (2026-03-04)
Bug Fixes
- licensing: wire rate limiting into all tool calls and fix free tier consistency (5517b3b)
0.22.0 (2026-03-04)
Features
- licensing: activate Lemon Squeezy checkout buttons and update tool counts (36617b7)
0.21.0 (2026-03-04)
Bug Fixes
- SPEC-064: wire usage tools into MCP server entry point (b8fa26c)
Features
- SPEC-064: add usage tracking, trial enforcement, and rate limiting (532b7d3)
0.20.0 (2026-03-04)
Features
- ci: unified auto-distribution for blog posts to dev.to, Hashnode, and Twitter (7df42fe)
- SPEC-065: migrate to planu/specs/ with per-spec HTML reports (46d173d)
- website: add Spanish blog (8 articles), connect newsletter to Buttondown (f2f012c)
0.19.0 (2026-03-04)
Features
- website: redesign pricing for enterprise appeal, remove free branding (3997293)
0.18.1 (2026-03-04)
Bug Fixes
- website: use native form submission for Buttondown newsletter (7333d19)
0.18.0 (2026-03-04)
Features
- website: add Spanish blog (8 articles), connect newsletter to Buttondown (447f0ce)
0.17.0 (2026-03-03)
Features
- ci: unified auto-distribution for blog posts to dev.to, Hashnode, and Twitter (abff6bd)
0.16.0 (2026-03-03)
Features
- website: add blog, sponsors page, newsletter, RSS feed, and distribution automation (3777f7b), closes hi#volume
0.15.5 (2026-03-03)
Bug Fixes
- seo: improve title template, add twitter:site meta tag (b99cf88)
0.15.4 (2026-03-03)
Bug Fixes
- update social links to planu-dev GitHub and add X/Twitter (f585c75)
0.15.3 (2026-03-03)
Bug Fixes
- add @iconify-json/simple-icons to website dependencies (5629d65)
0.15.2 (2026-03-03)
Bug Fixes
- add website tsconfig.json to avoid ES2024 esbuild error (8184375)
0.15.1 (2026-03-02)
Bug Fixes
- npm: publish under @specforge-tools org to replace personal account (adadff0)
0.15.0 (2026-03-02)
Features
- licensing: implement Lemon Squeezy license enforcement system (bcd99d9)
0.14.1 (2026-03-02)
Bug Fixes
- website: disable empty aside sidebar on pricing pages (440dfb2)
0.14.0 (2026-03-02)
Features
- website: redesign homepage sections, pricing cards, and fix broken links (cc802d9)
0.13.4 (2026-03-02)
Bug Fixes
- website: add vercel.json with cleanUrls for proper URL routing (13878b5)
0.13.3 (2026-03-02)
Bug Fixes
- website: enable cleanUrls to fix 11 empty pages on Vercel (6714a52)
0.13.2 (2026-03-02)
Bug Fixes
- ci: add @semantic-release/changelog to auto-update CHANGELOG.md (92834a3)
Changelog
All notable changes to SpecForge are documented here.
Format: Keep a Changelog · Versioning: SemVer
[Unreleased]
Added
- Feature grouping for specs: specs now organized under
{feature}/{slug}/directories - Mermaid diagrams now use real project knowledge (framework, database, architecture layers)
- SpecForge version identifier (
Generated by: SpecForge vX.Y.Z) in FICHA-TECNICA.md metadata
Fixed
- Duplicate
Architecturerow appearing outside the metadata table in FICHA-TECNICA.md - Structured multi-paragraph descriptions no longer wrapped in "As a user, I want..." in HU.md
0.13.1 — 2026-03-01
Fixed
- website: Redesign PricingCards and clarify technical terms in copy
0.13.0 — 2026-03-01
Added
- website: Replace donation system with pricing page and visual components
- Auto-sync script for tool count across website and smoke test
- Documentation updated to reflect 60 tools after context_budget addition
0.12.1 — 2026-02-28
Fixed
- tests: Update smoke test tool count to 60 after context_budget addition
0.12.0 — 2026-02-27
Added
- tools:
context_budgettool for context window optimization (SPEC-063) - 60 MCP tools total
0.11.1 — 2026-02-27
Fixed
- ux: Improve
summarize_specandgenerate_docstool descriptions to prevent LLM bypass
Changed
- Refactor: split 5 files near 400L limit into subdirectories
0.11.0 — 2026-02-27
Added
- engine: Executive summary HTML export (SPEC-060)
- engine: Git-derived actuals and cost tracking (SPEC-061)
- engine: Structured risk, complexity and trade-off documentation (SPEC-062)
- 213 new tests across 54 files (+5,618 lines)
0.10.0 — 2026-02-27
Added
- ux: Git branch suggestions in MCP workflow (e.g.,
feat/SPEC-XXX-nameafter creating specs) - ux: Git Flow enforcement — remind users to work in dedicated branches
0.9.0 — 2026-02-26
Added
- ux: Global server instructions with plain-language glossary for all technical terms
- ux: Tool descriptions rewritten to be conversational and beginner-friendly
[0.8.0] — 2026-02-26
Added
- Global MCP server instructions with glossary of 20+ technical terms explained in plain language
- All 43 tool descriptions rewritten in conversational tone across EN/ES/PT
- UX rules: be warm, summarize results, explain jargon, adapt to locale
Changed
- Tool descriptions now explain concepts like "spec", "drift", "ADR", "schema", "PII" inline
- Remaining untranslated
migrate_techmessages now fully localized in ES/PT
[0.7.0] — 2026-02-26
Added
- Multi-spec decomposition: broad requests (e.g., "build me a billing system") are automatically broken into individual feature specs
- LLM presents a plan and waits for confirmation before creating specs
- Post-creation summary with estimated effort and implementation order
Changed
create_specdescription updated across EN/ES/PT with detailed UX behavior instructionsinit_projectdescription now guides LLM to explain scanning, ask for user role, and summarize detection
[0.6.1] — 2026-02-26
Added
- E2E lifecycle test suite: 68 tests validating all tool handlers with valid enum inputs
- Tests cover 4 streams: core, analysis, platform, governance
[0.6.0] — 2026-02-26
Fixed
- All 27 Zod enums now have
.describe()with explicit valid values — prevents LLM hallucination of invalid enum values (e.g., sending "mid" instead of "intermediate") ExperienceLevelEnumdescription now lists valid options
[0.5.0] — 2026-02-25
Added
- Profile-aware UX:
userProfileparameter oninit_project(developer, product-owner, designer, non-technical) - Simplified clarification flow — SpecForge asks fewer, smarter questions based on user profile
- ChatGPT Desktop and Cline (VS Code) added to compatible AI tools list
- Website language simplified for non-technical users
Changed
clarify_requirementsnow only triggers for extremely vague topics (< 3 words)- Removed technical interrogation questions (performance, timeline, dependencies) — SpecForge decides these based on project context
[0.2.0] — 2026-02-25
Added
- Semantic-release for automatic versioning and npm publish via GitHub Actions
workflow_dispatchtrigger on publish workflow
Fixed
- Husky hooks disabled in CI semantic-release workflow
- npm auth configuration in setup-node
[0.1.1] — 2026-02-24
Added
- Website published at https://specforge-mcp.vercel.app in 6 languages (EN, ES, PT, FR, ZH, DE)
- Ko-fi donation button (floating popup + donate page)
- Google Search Console verification
- Hero logos panel with OS, AI agents, and language logos
- Ecosystem banner with animated marquee (AI agents + languages)
- Mobile performance improvements (LCP, FCP optimization)
- Preload hints for critical CSS/JS assets
Fixed
- Mobile hero overlap — VitePress
.VPHero .imagecontainer now hidden on mobile - Sitemap hreflang — all 85 URLs now have correct 7 hreflang alternates
- Donation popup now appears after 8s delay (was 3s) to avoid LCP interference
[0.1.0] — 2026-02-20
Added
- Initial public release on npm as
specforge-mcp - 59 MCP tools across 8 streams (A–H): init, spec lifecycle, analysis, planning, platform, docs, orchestration, governance
- Support for TypeScript, Python, Go, Rust, Java/Kotlin, Swift, PHP, Ruby, C#, Dart/Flutter
- Works with Claude Code, Cursor, Windsurf, Gemini CLI, GitHub Copilot, VS Code
- Spec Driven Development (SDD) workflow: HU.md + FICHA-TECNICA.md + PROGRESS.md per spec
- Mermaid diagram generation (architecture, sequence, state machine, ER, data flow)
- Multi-language i18n (EN/ES/PT) for generated specs
- Clean Architecture (hexagonal) — engine, tools, storage, types layers
- 10,857 tests with ≥95% coverage