45 Commits

Author SHA1 Message Date
przeprogramowani 2f4ebd3b75 docs: wymagania sieciowe dla urządzeń służbowych (allowlist PL+EN) (#53)
* docs: add corporate network allowlist for security/sysadmin teams

Polish sysadmin spec plus a machine-readable host list and a source-scan
test so new CLI destinations cannot land undocumented.

* chore(release): prepare v1.23.1

* docs: rewrite corporate allowlist in sysadmin language (PL+EN)

Plain host/port/protocol tables, matching English document, and an
allowlist test that covers both language files.

* docs: drop localhost from the corporate network allowlist

Public DNS names only; the source scan skips IP literals and
single-label hosts so local-dev URLs stay out of the sysadmin spec.

---------

Co-authored-by: Claude <noreply@anthropic.com>
2026-09-18 17:17:28 +02:00
Przemek Smyrdek 0831ef4207 chore(release): prepare v1.23.0 (#52)
Co-authored-by: Claude Opus 5 (1M context) <noreply@anthropic.com>
2026-09-18 11:53:39 +02:00
przeprogramowani 2525f86d88 chore(quality): integrate shared offline CLI gate (#47)
* chore(quality): integrate shared offline CLI gate

* chore(release): prepare v1.22.1

* docs(quality): record complete local gate and source provenance

---------

Co-authored-by: Claude <noreply@anthropic.com>
2026-09-17 10:57:35 +02:00
przeprogramowani 43d6a69088 fix(release): wait for npm metadata before verifying publish (#50)
* fix(release): wait for npm metadata before verifying publish

Direct publish-npm verified immediately after npm accepted 1.22.1,
while registry metadata still lacked dist.tarball. Poll until
integrity exists, then keep the strict pack/gitHead compare. When
the version is already on npm and matches the pack from cli_sha,
skip publish and only complete tag/Release.

* chore(release): prepare v1.22.2

---------

Co-authored-by: Claude <noreply@anthropic.com>
2026-09-16 18:22:01 +02:00
przeprogramowani 95fc5f4394 fix(skills): include idea-check in lesson setup (#48)
* fix(skills): include idea-check in lesson setup

* chore(release): prepare v1.22.1

---------

Co-authored-by: Claude <noreply@anthropic.com>
2026-09-15 17:04:35 +02:00
przeprogramowani 56484f5856 feat(skills): guide CLI setup, filtered downloads and safe updates (#41)
* feat(skills): guide CLI setup, named downloads and updates

* fix(skills): bound npm inventory checks on cold Windows runners

* fix(skills): align launch guide with 10xCards PRD journey

* fix(tests): make helper checks portable on Windows

* test(helpers): trace Windows npm pack startup

* fix(helpers): allow bounded Windows npm startup time

* fix(helpers): use released lesson-scoped skill filters

Correct setup/guide examples and sync ownership to match CLI 1.21.
Exercise the documented preview/write commands through CAC and the
real partial writer, preserving all three trees and the PRD schema.

Refs: https://github.com/przeprogramowani/10x-cli/pull/41

---------

Co-authored-by: Claude <noreply@anthropic.com>
2026-09-14 10:51:38 +02:00
przeprogramowani b2150bae85 fix(release): preserve exact commit evidence through squash and publication 2026-09-13 20:57:09 +02:00
github-actions[bot] f89f19506c chore(release): v1.20.0 2026-08-20 08:22:03 +00:00
github-actions[bot] 503a9cb179 chore(release): v1.19.1 2026-08-17 08:36:22 +00:00
github-actions[bot] cfb3c088f0 chore(release): v1.19.0 2026-08-16 21:25:56 +00:00
github-actions[bot] b63d26e92f chore(release): v1.18.0 2026-08-16 21:25:00 +00:00
github-actions[bot] 88b08e9812 chore(release): v1.17.0 2026-08-16 17:43:36 +00:00
github-actions[bot] 4b0e0ab236 chore(release): v1.16.0 2026-08-14 21:00:26 +00:00
github-actions[bot] 7787353da5 chore(release): v1.15.0 2026-08-14 10:44:25 +00:00
github-actions[bot] cea2845bc5 chore(release): v1.14.0 2026-08-14 10:41:25 +00:00
github-actions[bot] c15c274e75 chore(release): v1.13.0 2026-08-13 19:13:22 +00:00
Przemek Smyrdek 7fbe39eb5e feat: auto-register the surrounding product repo as first base repo (#27)
Running 'bench-kit init' from inside a product repo is the common flow,
so init now detects the git repo containing the invocation cwd (git
rev-parse --show-toplevel + origin remote + HEAD) and replaces the
template's demo-app placeholder in bench.config.yaml with that repo,
editing the YAML document in place so company-zone comments survive.
The detection also lands in instance.json (incl. HEAD as a candidate
pin for the first task). No detection, no origin, or detecting the
instance itself → the placeholder stays. Adds the 'yaml' dependency.

Co-authored-by: Claude Fable 5 <noreply@anthropic.com>
2026-08-13 20:55:12 +02:00
github-actions[bot] bf798bbe72 chore(release): v1.12.0 2026-08-13 18:37:27 +00:00
github-actions[bot] 80ab7ffa57 chore(release): v1.11.0 2026-07-29 09:09:34 +00:00
github-actions[bot] 6c3bf48122 chore(release): v1.10.0 2026-06-28 08:01:31 +00:00
github-actions[bot] 267f2fdd72 chore(release): v1.9.0 2026-06-20 13:04:22 +00:00
github-actions[bot] b52b1be6cc chore(release): v1.8.0 2026-06-02 07:31:25 +00:00
github-actions[bot] fbb0216743 chore(release): v1.7.0 2026-05-27 19:23:38 +00:00
github-actions[bot] b9d404c38a chore(release): v1.6.1 2026-05-18 14:07:04 +00:00
“mkczarkowski” c5ed0b6778 chore: lock dependencies to stable versions 2026-05-18 16:06:05 +02:00
github-actions[bot] aa19b7249c chore(release): v1.6.0 2026-05-17 19:56:10 +00:00
github-actions[bot] a88e7d1e0d chore(release): v1.5.0 2026-05-17 19:13:51 +00:00
github-actions[bot] 90a76d4247 chore(release): v1.4.0 2026-05-17 11:17:18 +00:00
github-actions[bot] 9b06113d9a chore(release): v1.3.2 2026-05-16 14:09:47 +00:00
github-actions[bot] 52b0c52ea9 chore(release): v1.3.1 2026-05-16 13:23:50 +00:00
github-actions[bot] 8ac793812c chore(release): v1.3.0 2026-05-16 08:38:02 +00:00
github-actions[bot] f2a06468d6 chore(release): v1.2.0 2026-05-09 13:10:52 +00:00
github-actions[bot] 2305f64048 chore(release): v1.1.0 2026-05-03 07:25:33 +00:00
“mkczarkowski” 075fd7ddef chore(skill-directory-bundle): prep CLI v1.0.0 release (p6)
Bump version 0.5.0 → 1.0.0 and add CHANGELOG entry for the directory-shaped
skill bundle. The CLI is functionally complete on master (commits 09a60c5,
afb9c48); this commit only stages the release metadata. `npm publish` is a
follow-up action — not run from this commit.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
2026-05-03 09:24:56 +02:00
github-actions[bot] 65b837e3fc chore(release): v0.6.0 2026-04-20 08:47:24 +00:00
github-actions[bot] 2047f6dad4 chore(release): v0.5.0 2026-04-16 13:40:05 +00:00
Przemek Smyrdek 3bab69841f feat: add 10x-cli-setup skill for README-driven CLI configuration (#1)
* feat: add 10x-cli-setup skill for README-driven CLI configuration

Add a skill that fetches the latest README from GitHub and walks users
through installing, authenticating, and configuring 10x-cli. Include
skills/ directory in npm package files.

Co-Authored-By: Claude Opus 4.6 (1M context) <noreply@anthropic.com>

* docs: add Agentic Installation section to README

Document how to install the 10x-cli-setup skill via skills.sh,
enabling AI agents to handle CLI setup automatically.

Co-Authored-By: Claude Opus 4.6 (1M context) <noreply@anthropic.com>

---------

Co-authored-by: Claude Opus 4.6 (1M context) <noreply@anthropic.com>
2026-04-16 15:39:24 +02:00
github-actions[bot] 90ee5c7dae chore(release): v0.4.0 2026-04-16 09:05:54 +00:00
github-actions[bot] 7a6c59fc75 chore(release): v0.3.0 2026-04-13 19:16:56 +00:00
“mkczarkowski” 29d81466db feat: add --print, --type, --name flags with filtered writes and atomic artifact fetch
Add three new flags to the `get` command:
- `--print` outputs artifact content to stdout instead of writing files
- `--type` filters by artifact type (skills, prompts, rules, configs)
- `--name` filters by artifact name (requires --type)

`--type`/`--name` work both with `--print` (stdout) and without (filtered
disk writes). The writer's new `partial` mode skips cleanup and manifest
updates so filtered writes never delete previously written artifacts.

Also adds `fetchArtifact()` for the /api/artifacts endpoint with full
Ed25519 signature verification, matching the existing `fetchLesson()` pattern.

Updates README with full command reference, multi-tool docs, and usage
examples. Adds repository/homepage/bugs to package.json so npm links
back to the GitHub repo.

Co-Authored-By: Claude Opus 4.6 (1M context) <noreply@anthropic.com>
2026-04-13 21:15:52 +02:00
github-actions[bot] 6c2dd35132 chore(release): v0.2.0 2026-04-13 17:53:55 +00:00
“mkczarkowski” 92d24ac4b4 fix(ci): add missing conventional-recommended-bump dependency and improve release error handling
The release workflow silently skipped every release because auto-version.mjs
imported conventional-recommended-bump which was never in devDependencies.
The error handler treated the import crash as "no bump needed." Now the
dependency is installed and the bump step distinguishes expected skip (exit 1)
from real crashes (any other non-zero exit).

Co-Authored-By: Claude Opus 4.6 (1M context) <noreply@anthropic.com>
2026-04-13 19:53:37 +02:00
“mkczarkowski” fc64cea7d9 security: harden supply chain, add request timeout, and document threat model
- Pin GitHub Actions by full SHA to prevent tag-swapping attacks
- Add .npmrc with ignore-scripts and 7-day minimum-release-age quarantine
- Add 30s default request timeout for API calls without caller signal
- Remove unused `open` dependency to reduce attack surface
- Strip OpenAPI source URL from generated types header
- Add SECURITY.md documenting threat model (T1–T8), review history, and
  design decisions
- Add persist-credentials: false to checkout action

Co-Authored-By: Claude Opus 4.6 (1M context) <noreply@anthropic.com>
2026-04-12 16:50:03 +02:00
“mkczarkowski” a68c743578 feat: serialize token refresh with file lock and pin CLI contracts via tests
Wrap the auth-guard refresh path in a proper-lockfile lock that re-reads
auth.json inside the critical section, so cooperating CLI processes (and
parallel in-process callers) racing on a near-expiry token can no longer
double-refresh — the late caller observes the rotated token and short-
circuits. Lock policy: 5 retries with 100–1000ms exponential backoff and
a 10s stale threshold, with auth_lock_timeout surfaced as a clean error
envelope on contention.

Add three test suites locking in invariants previously enforced only by
convention:
  - auth-guard-concurrency: in-process race, cross-process race via
    child_process.fork, stale-lock recovery, contention timeout
  - exit-codes: per-command exit-code matrix for auth login/--status
    /--logout, including the F1 fix (expired token in JSON mode → exit 3)
  - json-envelope: stdout envelope contract + leakage guard catching
    stray verbose markers, ANSI escapes, clack glyphs, multi-line output,
    and accidental email echo

Share auth-flow and @clack/prompts module mocks via tests/helpers/* so
mock.module registrations don't leak across test files in the same
bun test process; the mocks fall through to the real implementations
when no test state is configured, leaving auth-flow.test.ts untouched.

Co-Authored-By: Claude Opus 4.6 (1M context) <noreply@anthropic.com>
2026-04-11 15:04:20 +02:00
“mkczarkowski” b42b119050 feat:bootstrap the tool 2026-04-11 11:18:40 +02:00