Skip to content

Tags: AltimateAI/altimate-code

Tags

v0.12.4

Toggle v0.12.4's commit message

Verified

This commit was created on GitHub.com and signed with GitHub’s verified signature.
chore(release): v0.12.4 (#1387)

* fix(workspace): v0.12.4 release review — user-facing wording, adopted-binding comment

- Link / re-link messages in `link.ts` and the TUI workspace plugin no longer
  say "binding" or "pre-check" (End User review).
- `state.ts`: the `pinned` field's comment described memory mirroring to
  adopted bindings as an unfixed gap. It is intended: a project belongs to
  exactly one workspace, so new memory in a linked project belongs there; only
  the backfill of earlier memory waits for the user's Attach.
- `identity.ts`: import spacing.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_018fJ3X7pcGT4R9yzjsJnqsV

* release: v0.12.4

- CHANGELOG entry for 0.12.4.
- `release-v0.12.4-adversarial.test.ts`: snapshot attribution under traversal
  and lookalike segments, `snapshotCopyYields` type confusion, skip reasons and
  displayed skill ids never carrying raw errors or control characters, sync
  problem boundaries and the announce latch, the `serve` workspace route gate
  across header combinations, hidden-workspace conflicts, and the review's
  wording fixes.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_018fJ3X7pcGT4R9yzjsJnqsV

* fix(workspace): v0.12.4 release PR review — attach-path wording, portable tests

- The "not found" message after linking or re-linking now fits both paths:
  the chosen workspace may be gone (attach), or the project's link to it
  (re-link). It no longer sends an attach user to "pick Create". TUI picker,
  TUI inline attach, and `altimate-code link`.
- `state.ts`: the `pinned` comment no longer claims the field is unused;
  `identity.ts` reads it, and no write-permission check keys on it.
- `release-v0.12.4-adversarial.test.ts`: pass `""` for "no password" (an
  `undefined` argument selects the environment's `OPENCODE_SERVER_PASSWORD`),
  and build snapshot-path expectations from the platform's root and separator
  so the file passes on Windows.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_018fJ3X7pcGT4R9yzjsJnqsV

* fix(workspace): attribute a drive-root project's snapshot to `C:\`, not `C:`

`snapshotProjectOf` joined the path segments before the snapshot folder, so a
project opened at a Windows drive root came back as the bare drive `C:`, which
resolves to that drive's current directory rather than its root. It now returns
the platform's root (`/`, `C:\`, or a UNC share root) for a root-level project.
The function takes an optional path implementation so the Windows behaviour is
tested on every platform. Found in the v0.12.4 release PR review.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_018fJ3X7pcGT4R9yzjsJnqsV

* docs(changelog): v0.12.4 — Windows drive-root snapshot fix

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_018fJ3X7pcGT4R9yzjsJnqsV

* fix(workspace): v0.12.4 consensus review — link wording, stale comment, CHANGELOG accuracy

- The remaining user-visible link strings no longer say "bindings",
  "Binding" or "pre-check": the lookup warning and the "Workspace approved"
  spinner in `link.ts`, and the re-link guard's thrown error in both `link.ts`
  and the TUI plugin (both surfaces show a thrown error's message as-is).
- The not-found message after linking or re-linking also covers a workspace
  the account can no longer see: the server answers 404 for both.
- "Already linked — re-linking it instead" no longer stops the spinner with the
  error glyph right before a successful re-link.
- `state.ts`: the note that new memory mirrors to adopted bindings moves from
  `pinned` to `adopted`, and `resolveBinding`'s doc no longer says memory
  writes stay behind a real link — only the backfill of earlier memory does.
- CHANGELOG: the Windows drive-root bullet is removed. `path.win32.join`
  already normalised `C:` + `.altimate-code` to `C:\.altimate-code`, so no user
  could hit it; 03fbb9d is hardening for future callers that `resolve` or
  compare the value. The route-gate description now says `same-site` is refused
  too, and the TUI model fix reads "now keeps".
- Tests: the wording test covers the reworded strings and the not-found
  message's three sites; `snapshotProjectOf` pins lowercase-drive,
  forward-slash and `\\?\` long-path roots; the older root test in
  `skill.test.ts` is portable.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_018fJ3X7pcGT4R9yzjsJnqsV

---------

Co-authored-by: Claude Opus 5.5 <noreply@anthropic.com>

v0.12.3

Toggle v0.12.3's commit message

Verified

This commit was created on GitHub.com and signed with GitHub’s verified signature.
chore(release): v0.12.3 (#1362)

* fix: auto-register Altimate Base before `agent create` and `review` resolve a provider

Neither `altimate agent create` nor `altimate review` called
`FreeTier.autoRegisterWithin()` before resolving a provider, unlike the other
five entrypoints (`run`, `tui`, `serve`, `acp`, `web`). On a fresh install this
meant `agent create` leaked a raw upstream error mentioning "OpenCode" with no
remediation, and `review`'s AI lane silently produced zero findings with no
visible signal.

Found by the Chaos Gremlin (Support Engineer) persona during the v0.12.3
release review — both confirmed P0s, verified against the actual failure
path, not indirect reasoning.

Wires both call sites with the same `autoRegisterWithin(undefined, () => void
printDisclosureOnceForHeadless(true))` pattern already used by run/acp/web,
and extends the entrypoint-late-notice-wiring pin test to cover both new call
sites.

* fix: surface startup feedback during the TUI's auto-register wait

`tui.ts`'s up-to-3s auto-register wait gave zero terminal output — on a fresh
install this reads as a hang on the very first launch (End User persona,
v0.12.3 release review, P1).

Gates a "Connecting to Altimate Base…" status line behind a 300ms delay so
the common already-registered/fast path never flashes it.

* docs: fix stale consent-gate wording flagged by the v0.12.3 release review

Two independent findings (CTO and PM personas):

- `altimate-base-disclosure.ts`'s header comment still described the
  disclosure as something "a user actually consents against before any Base
  credential is minted" — stale since this release removed the consent gate
  entirely. It's now a post-registration notice, not a pre-credential prompt.
- README's "Step 1: Choose an LLM provider (required before anything works)"
  directly contradicted the next sentence, which explains a fresh install
  registers Altimate Base automatically if you skip this step.

* chore: remove a duplicate altimate_change marker in server.ts

Found while auditing the "Kilo Code Review" FAILURE check on PR #1361 (CTO
and Tech Lead personas flagged it as an open loose end): every one of the
bot's 9 findings was already fixed by a later commit in the same PR, and this
harmless leftover duplicate `// altimate_change end` was noticed in the same
import block along the way.

* test: adversarial coverage for v0.12.3 release fixes

Covers the new code from this release's review fixes: ordering/scoping
invariants for the autoRegisterWithin() wiring in agent.ts/review.ts (must
run before the provider is resolved, must stay outside review.ts's latency
timer, must be unconditional regardless of --no-ai), the tui.ts feedback
timer's delay bounds and try/finally cleanup, and a regression guard against
the duplicate marker comment.

* revert: restore the second altimate_change end marker in server.ts

Not a duplicate. The two consecutive `// altimate_change end` lines close two
separate blocks that happen to end at the same point: the outer "Altimate-only
server endpoints" block (opened at the `McpRoutes` import) and the inner
"registration must invalidate BOTH instance registries" block (opened at the
InstanceStore import). Removing one left the outer block's start unpaired,
which the marker-integrity test (test/upstream/bridge-merge.test.ts,
test/branding/upstream-merge-guard.test.ts) caught in CI on PR #1362 —
correctly, since I'd broken a real invariant while "cleaning up" what looked
like leftover cruft without running the actual test that verifies pairing.

* test: drop the mistaken duplicate-marker regression guard

Followed the previous commit's correction — the "duplicate marker" this test
pinned against was never a duplicate, so the test encoded the same wrong
assumption. Removed rather than fixed forward, since there's nothing left to
assert once the premise is gone.

* docs: changelog for v0.12.3

v0.12.2

Toggle v0.12.2's commit message

Verified

This commit was created on GitHub.com and signed with GitHub’s verified signature.
chore(release): v0.12.2 — changelog entry for #1353 (#1355)

#1353 (synced memory blocks get a title) merged to main between the beta
and the release PR; the [0.12.2] entry now lists it. The changelog ships
inside the binary, so it has to be in the tagged commit.


Claude-Session: https://claude.ai/code/session_012Q51zFUmPg1WwtS5CrGJE6

Co-authored-by: Claude Opus 5 <noreply@anthropic.com>

v0.12.2-beta.1

Toggle v0.12.2-beta.1's commit message

Verified

This commit was created on GitHub.com and signed with GitHub’s verified signature.
chore(release): v0.12.2-beta.1 (#1347)

* chore(release): v0.12.2-beta.1

Beta of the six workspace-pilot and configuration fixes merged after v0.12.1
(#1341 #1342 #1343 #1344 #1345 #1346). Publishes to the npm `beta` dist-tag;
`latest` stays at 0.12.1.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_012Q51zFUmPg1WwtS5CrGJE6

* chore(release): v0.12.2-beta.1 — correct the docs path in the changelog entry

(bot review)

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_012Q51zFUmPg1WwtS5CrGJE6

---------

Co-authored-by: Claude Opus 5 <noreply@anthropic.com>

v0.12.1

Toggle v0.12.1's commit message

Verified

This commit was created on GitHub.com and signed with GitHub’s verified signature.
chore(release): v0.12.1 (#1338)

* fix(workspace): close the v0.12.1 release-review findings on the pin/identity seam

Five-persona review of v0.12.0..main. #1320 (IDE pin) and #1330
(identity every turn) changed `resolveBindingOutcome` from opposite sides
and were never reviewed together; every item here is on that seam.

- A pin served from the offline grace window is marked `stale`, so the
  identity section says "last known" for it as it already did for a
  cached link. `pinValidation` is bounded like the other caches.
- Identity's memo is keyed on the credential digest as well as the
  tenant and host — two accounts on one tenant no longer share an entry
  (the pin cache in `state.ts` already did this).
- Under a pin, identity's deadline fallback never reaches for the
  project's own cached link — the workspace the pin exists to override.
- A pinned session is described as pinned by the IDE extension, with the
  caveat that warehouse tool routing still follows the project's own
  link (#1337); the unknown copy no longer promises that retrying helps.
- The persistent `shell` tool strips the same host markers as `bash`
  (`ALTIMATE_CODE_SERVE`, the pin trio, headless, non-interactive) via a
  shared `stripHostMarkers`, so a nested `serve` cannot inherit a pin.
- `pin.ts` states the extension contract: a pin is fixed for the life of
  the process; a panel switch means relaunching `serve`.
- Docs: the three pin variables and `ALTIMATE_CODE_SERVE` in cli.md, and
  a note on the identity line and the pin under "Workspaces (pilot)".

Tests: pinned-session copy, pin-aware fallback, same-tenant credential
switch, grace-path stale, host-marker stripping. Each guard was deleted
once to confirm its test fails.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_012Q51zFUmPg1WwtS5CrGJE6

* fix(workspace): pin ids are decimal digits; the identity cap fits every shape

Two defects the v0.12.1 adversarial tests found.

- `readPin` took any string `Number()` parses — "1e3", "0x10", "1.0" —
  as an id. The extension never writes those; only decimal digits (with
  surrounding whitespace) are a pin now, the rest fail closed as before.
- `MAX_SECTION_CHARS` (1,000) was below the pinned-and-stale identity copy
  with a budget-sized label (1,238), so `render` failed closed and dropped
  the name — and for the plain stale shape (1,078) too. Raised to 1,500;
  a test renders every shape with the worst-case label and checks the
  name survives.

Adds `test/skill/release-v0.12.1-adversarial.test.ts`: hostile pin
environments, root traversal (including the documented symlink bypass),
host-marker stripping by exact name, and the identity copy across
pin × stale × unbound.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_012Q51zFUmPg1WwtS5CrGJE6

* release: v0.12.1

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_012Q51zFUmPg1WwtS5CrGJE6

* test: the #937 env-plumbing guard checks stripHostMarkers behaviourally

It grepped bash.ts for the literal `delete mergedEnv["ALTIMATE_NON_INTERACTIVE"]`,
which moved into the shared `stripHostMarkers` in this release. The contract
it protected — the non-interactive marker is stripped, auto-answer is kept —
is now asserted on the function.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_012Q51zFUmPg1WwtS5CrGJE6

* fix(workspace): address the bot and multi-model review on the v0.12.1 release PR

- `stripHostMarkers` deletes every spelling of a marker on Windows, where
  environment names are case-insensitive, and the exact name elsewhere.
  The nested `altimate_change` markers around its call site are gone.
- `shell.ts` exposes `shellChildEnv` so the persistent shell's child
  environment is tested on values, not on this file's source text.
- `readPin` treats a whitespace-only id, name or root as a broken pin.
- Identity keeps the resolver behind the deadline even when no complete
  account is configured: the resolver's own credential read is looser
  than `accountScope` and can still reach the network.
- The adversarial test file no longer mutates `XDG_STATE_HOME`; the
  preload already isolates state and nothing here reads it.
- Docs: `ALTIMATE_CODE_SERVE` is set by `serve` itself, not only by the
  extension; ordinary and pinned sessions described separately.
- CHANGELOG narrows the credential-scoping claim to the layer this
  release fixes: the resolver's own five-minute caches are still keyed
  by tenant and host (tracked separately).

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_012Q51zFUmPg1WwtS5CrGJE6

* docs(changelog): point the resolver-scope caveat at #1339

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_012Q51zFUmPg1WwtS5CrGJE6

* test: keep the source guard for ALTIMATE_AUTO_ANSWER beside the behavioural one

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_012Q51zFUmPg1WwtS5CrGJE6

* fix(workspace): identity renders unknown without the resolver when no complete account is configured

Nothing can verify a link without a credential, and the resolver's looser
credential read would otherwise reach the network from that path with no
memo, no single-flight and a synchronous git probe. Test asserts the
resolver is not called. Also: the shell child-env test now exercises the
default `process.env` base the production call site relies on.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_012Q51zFUmPg1WwtS5CrGJE6

* test: read PATH or Path in the shell child-env test (Windows)

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_012Q51zFUmPg1WwtS5CrGJE6

---------

Co-authored-by: Claude Opus 5 <noreply@anthropic.com>

v0.12.0

Toggle v0.12.0's commit message

Verified

This commit was created on GitHub.com and signed with GitHub’s verified signature.
chore(release): v0.12.0 (#1327)

* fix(workspace): close the release-review findings for v0.12.0

Five-persona pre-release review of v0.11.2..main; every actionable item
lands here so the release carries the fixes, not a follow-up.

- `skill publish` is registered only under `ALTIMATE_WORKSPACE=1`, like
  `link`: a user outside the pilot saw it in `--help` and was told to run
  a `link` command that does not exist for them. `skill list` now hints
  the command when the pilot is on.
- The publish junk filter refuses the credential shapes that arrive by
  copy or habit — private keys and certificates (`id_rsa`, `*.pem`,
  `*.key`, `*.p12`, …), `.npmrc`/`.netrc`/`.pypirc`, `credentials.json`,
  `secrets.*`, and the `.ssh`/`.aws`/`.gnupg`/`.altimate` directories.
  Still a filename blocklist: a `config.yaml` holding a token ships.
  Directory names are case-folded, as file names already were.
- `ownership.test.ts` passed an empty env to `bunGlobalRoot`: it read the
  real `BUN_INSTALL`, so the two tests were red on any machine where bun
  had ever installed this package globally.
- Docs: `skill publish` and the "Publish to workspace" action in
  skills.md; a "Workspaces (pilot)" note in cli.md covering `link`,
  `/workspace` and `skill publish`.
- A garbled comment in `link.ts`.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_012Q51zFUmPg1WwtS5CrGJE6

* release: v0.12.0

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_012Q51zFUmPg1WwtS5CrGJE6

* fix(release): address cubic on the v0.12.0 release PR

- skills.md: the publish filter matches names only and never scans
  contents; say so instead of listing exclusions as if complete.
- adversarial test: an object-literal `__proto__` sets the prototype, so
  the marker never carried the key; build it by parsing and assert it is
  there.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_012Q51zFUmPg1WwtS5CrGJE6

* fix(release): address Kilo on the v0.12.0 release PR

- The TUI "Publish to workspace" row is pilot-gated like the CLI command;
  the docs claimed it already was.
- `/workspace` docs and changelog describe what Refresh and Sync do
  (pull workspace skills and memory in; re-send local memory) instead of
  a "sync skills" the menu does not offer.
- Adversarial test: directory links carry a type for Windows runners; the
  `bunGlobalRoot` expectation is built with `path.join`.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_012Q51zFUmPg1WwtS5CrGJE6

---------

Co-authored-by: Claude Opus 5 <noreply@anthropic.com>

v0.11.2

Toggle v0.11.2's commit message
release: v0.11.2

v0.11.1

Toggle v0.11.1's commit message
release: v0.11.1

Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_012uzYijGHdhxvpUzhgWxayo

v0.11.0

Toggle v0.11.0's commit message

Verified

This commit was created on GitHub.com and signed with GitHub’s verified signature.
release: v0.11.0 (#1290)

Claude-Session: https://claude.ai/code/session_01H8gZMvZunXzx4LPSZzCafq

Co-authored-by: Claude Sonnet 5 <noreply@anthropic.com>

v0.11.0-beta.5

Toggle v0.11.0-beta.5's commit message

Verified

This commit was created on GitHub.com and signed with GitHub’s verified signature.
feat: expose Altimate Base registration over HTTP for non-TUI hosts (#…

…1266)

Co-authored-by: Claude Opus 5 (1M context) <noreply@anthropic.com>