9.7 KiB
9.7 KiB
Changelog
All notable changes to AIPass will be documented in this file.
The format is based on Keep a Changelog,
and this project uses Calendar Versioning in the format
YYYY.WNN (year and ISO week number).
[2026.W22] - 2026-05-30
Added
drone @hooks status— read-only viewer for a project's hook config: master switch, every hook's enabled state per event group, matchers, and an enabled/total summary. Resolves the project's.aipass/hooks.jsonby walking up from CWD. (DPLAN-0190 Phase B)- Hooks activate in every project —
aipass initnow writes.aipass/hooks.json, so new projects fire the hook engine out of the box (previously: no config shipped, 0 hooks fired).aipass init updateunion-merges the template, preserving any per-hook on/off choices the user made.aipass doctornow checks for the config's presence. Dead hook-script shipping (_ship_hooks) removed. (DPLAN-0190 Phase A) - README logo — centered logo image replaces plain
# AIPassheader. Newassets/logo.pngadded to the repo. - OpenSSF Scorecard —
.github/workflows/scorecard.ymlruns the official OSSF Scorecard action on push tomainand weekly. Publishes a public security health score at scorecard.dev with a README badge. Actions pinned by SHA. - GitHub Releases —
publish.ymlnow cuts a GitHub Release on eachv*tag, with notes pulled from the top CHANGELOG section and the built dist attached. PyPI publish + GitHub Release now fire from the same tag. - Registry descriptions — all 13 branches now have one-liner descriptions
in
AIPASS_REGISTRY.json.drone systemsshows what each agent does instead of blank lines. Closes #607.
Changed
- Security gates fully project-aware — both the edit gate and the
subagent stop gate now derive the package name dynamically from CWD instead
of hardcoding
src/aipass/. Cross-branch write protection and branch detection work for anysrc/<package>/<branch>/project; previously the subagent gate silently no-opped outside AIPass. 9 new external-project tests. Closes #605. - Hooks branch promoted to service — registry profile changed from
"AIPass Workshop" to "library" so it appears in
drone systemsalongside the other 12 services. - Hooks branch hardened to 100% seedgo — the @hooks citizen took full
ownership of its branch: every handler verified wired + firing, README
rewritten (two-tier provider/project model, dynamic-dispatch design, event
table), 2 stale tests resolved (253 pass). Dead-code/unused-function flags
documented as architectural bypasses — the 15 handlers are invoked
dynamically via
importlibfromhooks.jsonpaths, never statically imported. (DPLAN-0191)
Release
- Version 2.5.0 published to PyPI. Trusted publishing via GitHub Actions
(
publish.ymltriggers onv*tags — no manual twine upload needed). The same tag now also cuts a GitHub Release with these notes attached.
Removed
- Gemini CLI full removal — deleted
.gemini/directory (5 files) andGEMINI.md. Stripped all references fromsetup.sh(~50 lines),README.md,bug-report.yml,aipass init(bootstrap/scaffold/test), hooks (README/prompt/passport), and prax monitoring (~300 lines). 21 files changed, -927 lines. Closes #608.
[2026.W21] - 2026-05-25
First weekly release. AIPass now follows a Sunday release cadence: changes
accumulate on dev throughout the week and merge to main as a single
versioned release with notes.
Added
- Hook engine — a new centralized dispatch system for all hook execution. A thin bridge receives events from the AI provider (Claude, Codex, etc.) and routes them through a single Python engine that reads per-project configuration, executes the appropriate handlers, and logs every invocation. Replaces 14 standalone shell/Python scripts with native handler modules organized by domain: prompt injection, security enforcement, lifecycle management, and notifications.
- Per-project hook configuration via
.aipass/hooks.json. Each project can enable, disable, or customize individual hooks without touching provider-level settings. Previously hooks fired globally with no per-project control. - Audio feedback on hook events using Piper TTS. All 14 handlers
produce distinct spoken audio cues so operators can monitor sessions
without watching the terminal. A shared sound module
(
hooks/apps/sound.py) providesspeak()andplay()with built-in mute support. Toggle withdrone @hooks hooksound on|off— muting silences all 14 handlers without skipping their functional logic. - Hooks agent — the 13th citizen in the AIPass registry, owning all hook infrastructure: the engine, bridge, handlers, and configuration schema.
- Dashboard plugin for devpulse — aggregates git status, session history, and dispatch state into a single startup view. Wired into the session startup protocol so branch managers see current state immediately.
- External log routing — prax now accepts structured log entries from any branch, not just its own modules. Hook executions, dispatches, and agent activity all flow into the central monitoring log.
Changed
- Provider settings fully migrated to bridge pattern. All hook entries in the Claude provider configuration now call the bridge dispatcher instead of individual scripts. Each hook produces its own system-reminder to the model, preserving prompt injection fidelity (a single merged bridge was found to break prompt delivery due to Claude Code's output persistence threshold).
- setup.sh rewritten to install hooks via the bridge pattern. The old version hardcoded 14 script paths; the new version writes a single bridge call per event type and validates that the bridge module exists.
- Documentation sweep across
.claude/README.md,SECURITY.md, the global prompt, and branch-level docs to reflect the new hook architecture. References to legacy.claude/hooks/scripts replaced with the native handler locations. aipass init updatenow correctly preserves user-customized hook settings during project updates instead of overwriting them.- Seedgo snapshot tests rebuilt — the provider hooks snapshot fixture and extraction logic were structurally broken (silently passing with zero results). Both the fixture format and the test assertions have been corrected.
- Test suite updated for hook migration —
test_git_gate.pyimports from the new handler module;test_bootstrap.pyno longer asserts that project initialization ships standalone hook scripts (it no longer does).
Fixed
- Settings merge on project update —
aipass init updatewas clobbering user hook configurations. The merge logic now layers AIPass defaults under existing user settings. - Python 3.10 test collision — a module/function name collision caused mock patch targets to fail on Python 3.10. Test targets corrected.
- Dead code removal — removed an unused CLI
__main__.pyentrypoint and cleaned up.gitignoreentries that were masking tracked files. - Codecov patch threshold lowered to 50% to reflect the project's current coverage baseline and stop false-negative CI failures.
Removed
- 18 standalone hook scripts in
.claude/hooks/disabled (renamed with(disabled)suffix). Their logic now lives in native handler modules undersrc/aipass/hooks/apps/handlers/. The old files remain on disk for reference but are no longer executed. drone hook-soundsplugin disabled. Sound control moved to hooks branch asdrone @hooks hooksound on|offwith full mute support for all 14 handlers (the old plugin only controlled 4).
Infrastructure
- Provider manifest migrated to bridge pattern.
provider_manifest.jsonnow stores bridge commands ($AIPASS_HOME/...bridges/claude.py EventType) instead of standalone script names.doctor_wire.pyauto-wires bridge entries directly — no longer copies scripts to~/.claude/hooks/or generatessys.executablepaths. Doctor checks validate commands exist in provider settings instead of checking for script files on disk. - README v3 — rewritten for external users. Tighter problem/solution framing, collapsible agent details, Gemini CLI removed (untested), user-project perspective throughout.
- Inline handoff (
aipass init runStep 11) — new default stays in the current terminal viaos.execvpinstead of opening a new window. Users choose "stay here" or "new window." Enables single-terminal demo recordings. Closes #610. - Project-aware global prompt — the global prompt loader now detects
whether CWD is inside AIPass or an external project. External projects
receive their own lighter prompt (from
.aipass/aipass_global_prompt.md) instead of the full AIPass-internal playbook. Fixesdrone @praxerrors in new projects. - Project CLAUDE.md template —
aipass initnow generates a project-specific CLAUDE.md from.aipass/project_CLAUDE.mdinstead of copying the AIPass-internal one. Removes the startup protocol reference todrone @prax dashboard refreshwhich doesn't exist in external projects. - Gemini CLI removed from
aipass initCLI choices and handoff options. GEMINI.md no longer created for new projects. Gemini CLI is being retired upstream. - Demo GIF added to
assets/demo.gifand referenced in README.
This is the first CHANGELOG entry. Prior work is documented in the repository's commit history and branch session logs.