Phase 2 of #630. The rm_gate hook + drone rm now own destructive-delete
protection (cross-provider, path-aware, teaching), so the Claude-only blanket
deny is redundant AND harmful (it short-circuits before the hook, suppressing
the teaching message).
- setup.sh: removed Bash(rm -rf*) + Bash(rm -r *) from git_deny (new installs)
- bootstrap.py: removed Bash(rm -rf *) shipped via aipass init (project settings)
- doctor_wire.reconcile_stale_deny(): aipass doctor WARNs on stale rules;
--fix removes them (idempotent, preserves all else) — migration for existing
installs (the 'aipass update should be trusted' goal)
- .aipass/project_hooks.json template: added rm_gate (new projects get it)
Tests: 8 reconcile + 432 aipass total, seedgo 99%. CHANGELOG W23.
#625 (HIGH): drone @git merge passed --delete-branch to gh pr merge
unconditionally, so merging a dev->main PR DELETED the persistent dev branch
on the remote and left the tree on main (next commit silently on main). Now:
- merge looks up the PR head ref and only appends --delete-branch for
non-protected branches; dev/main are never deleted. Unknown head ref fails
SAFE (no delete) — devpulse hardening on top of @drone's protected-branch set.
- after merge, return the working tree to dev (loud warning if it can't).
- branches_handler runs git fetch --prune before git branch -r (no more
'cached lies' reporting deleted branches as live).
- new drone @git prune-temp cleans merged temp PR branches (citizen/*).
#623: status/diff append a '(showing <branch> scope — use --all for full repo)'
footer when scoped, so an empty scoped view isn't mistaken for a clean repo.
Blank-output sub-item not reproducible — documented.
@drone built fixes 1-5 (FPLAN-0236); devpulse added the unknown-head-ref
fail-safe + test and verified independently. drone suite 716 pass, seedgo 99%.
Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
resolve_branch() validated branch path containment against the primary
registry root even when the branch was found via the AIPASS_HOME fallback,
so external projects (Vera, Daemon) were blocked from calling @api and any
other AIPass branch with 'path escapes project root'.
Add get_branch_with_registry() (non-breaking sibling to get_branch_by_name)
that returns the branch plus the registry it was found in. resolve_branch()
now validates containment against that registry's root. Security preserved:
each branch stays contained within its own declaring registry; genuine
escapes still blocked. 4 new cross-project resolver tests, 58 resolver
tests pass, drone suite 702 pass, seedgo @drone 99%.
Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
Cluster was getting busy; dropped the OSS Health monitor badge to keep the
top row focused (Status/Python/License/PyPI/Feedback/codecov/Scorecard).
Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
Removed 5 stale Phase-0/Phase-4 bypasses (verified seedgo passes without them
now that aipass is fully built). Restored 3 aipass.py entries (cli/debug_print/
introspection) with accurate current reasons — thin command router, not a
module. Metadata description updated to current operational state. 58→53 entries.
424 tests pass, seedgo 99%.
Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
Was orphaned in its own centered block between the logo and demo gif, and the
only badge in raw HTML. Moved up with the other 7 badges and converted to
markdown for consistency. Grouped with codecov/OSS-Health (security-health).
Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
aipass is a user-facing binary — 'aipass doctor' must run the health check,
not describe itself. All 7 modules (doctor, doctor_fix, doctor_wire, handoff,
help_chat, init_flow, profile) hit a no-args→introspection gate (a standard
meant for 'drone @branch <module>' discovery). Bare invocation now runs the
command or shows usage; introspection moved to --info. seedgo introspection
standard bypassed for these binary-invoked modules (documented). 424 tests pass.
Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
PLANS.central.json only held Flow's own plans (location==FLOW_ROOT filter),
so every dashboard refresh overwrote each branch's real active_plans with 0.
Central is now comprehensive — all plans grouped per-branch. Devpulse shows
its 12 open plans again. +1 regression test (734 pass).
Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
- publish.yml: new github-release job runs after PyPI publish, extracts the
top CHANGELOG section as release notes, attaches dist, creates the Release
via gh. Same v* tag now drives PyPI + GitHub Release.
- CHANGELOG W22 entry
- bootstrap.py: write hooks.json from template at init, union-merge on update (preserves user on/off), remove dead _ship_hooks/HOOKS_TO_SHIP
- doctor.py: check .aipass/hooks.json presence
- .aipass/project_hooks.json: base template (all 14 handlers)
- .aipass/.gitignore: whitelist template so it ships in clones
- +13 tests, 421 pass, seedgo 99%