Repository navigation
chore: version packages - #129
Merged
Merged
Conversation
Codecov Report✅ All modified and coverable lines are covered by tests. 🚀 New features to boost your workflow:
|
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
This PR was opened by the Changesets release GitHub action. When you're ready to do a release, you can merge this and the packages will be published to npm automatically. If you're not ready to do a release yet, that's fine, whenever you add more changesets to master, this PR will be updated.
Releases
agentsmesh@0.41.0
Minor Changes
3bbf68b: Lessons are harder to lose and easier to use correctly, after a full manual QA pass.
Team merges: if git could not start the lessons merge driver, it kept only your side of
lessons.jsonwith no conflict markers, and every check still passed. Nowlessons validate,checkandgenerate --checkfail while the file is missing the other branch's lessons, and tell you to runagentsmesh lessons resolvebeforegit add. The driver is also only saved when git can start it later (npx caches and package-script bin folders on PATH no longer count, and the npx form needs agentsmesh at the repository root or installed globally).lessons resolvenow works again after you fix a broken side by hand in the file.The recall hook never breaks your tool: a log file it cannot write, or a bad line in a log, no longer makes it fail or lose a lesson for the session. A failed read (for example reading a file that does not exist yet) is no longer counted against a later write. A multi-file patch shows each warned rule once and stays under the size cap. Invisible and look-alike characters can no longer fake the end of the recalled-lessons block. An unreadable graph is now also reported when a session starts with no prompt. The hook does nothing in a folder with no lessons project, such as your home folder.
The
lessonsCLI works from any subfolder of a project, like git. It refuses an unquoted multi-word rule (instead of saving only its first word) and a single-value flag given twice. Re-adding a lesson says what changed. A regex the linear engine cannot run is dropped with aDEAD_COMMAND_PATTERNwarning when the lesson has another trigger, or refused asUNRECALLABLE_LESSON(exit 2) when it is the only one. Every lessons command, and every MCP lessons tool, now explains an unreadable graph (merge conflict, bad JSON,SCHEMA_INVALID, newer version) instead of printing parser output. A negated glob (!path) is flagged as broad. A lessons write that lost its lock (the process was paused past the 60 s stale window) refuses to save instead of erasing a later write, and a lock dated in the future no longer blocks writers.MCP lessons tools never create a lessons graph in your home folder or outside a project: they use the nearest lessons folder, then
agentsmesh.yaml, then the git repository root, and otherwise refuse writes withNO_PROJECT.lessons_showaccepts a lesson id,lessons_querywithalwayshonorssessionandno_dedup, and refused writes returnVALIDATION_FAILEDwith the finding codes.Installed pack hooks are no longer lost: two packs on the same event are combined, a pack adds to an extend's hooks for that event, and a local
hooks.yamlevent keeps the pack's hooks after its own. Before,agentsmesh init --lessons(which adds the recall hook locally) silently removed installed pack hooks for the same event. Extends layers still override per event, as documented. To drop a pack hook, uninstall the pack or leavehooksout of its features.2cb8b48: The MCP server now tells every client about lessons when it connects, and says something true in both states.
Where a project has lessons, the server hands over the same recall and capture contract that
init --lessonswrites into your instruction file. That matters for a plugin: a plugin can ship skills and servers but never your instruction file, so a plugin-only install previously had no standing instruction at all and recall depended on the agent opening the skill first. The obligations are phrased in tool names rather than shell commands, since a client reaching the server this way may have no shell.Where a project has no lessons, the server says so plainly and explains how to start one. It does not name a graph file you do not have, does not point at a skill you never installed, and mandates nothing. This matters because the server also carries the configuration tools and is documented on its own: most people who wire it up never opted into lessons, and they should not be told to query a memory that cannot answer.
cea0c7e: Lessons now hold up for teams, for more tools, and against a graph you did not write yourself.
Teams: two branches that both capture lessons now merge cleanly. The git merge driver merges each lesson field by field, and every clone gets the driver the next time it runs
agentsmesh generate(orinit --lessons), so it no longer depends on one person's setup. If a merge still leaves conflict markers, the newagentsmesh lessons resolvecombines both sides.agentsmesh checkandgenerate --checknow fail whenlessons.jsoncannot be read (a merge conflict, a corrupt file, a newer schema), instead of passing while recall is silently off. The lessons lock no longer loses a lesson when many agents write at once. A fresh clone no longer prunes lessons whose files are merely not created yet: a glob counts as dead only when git history shows its file was deleted or renamed. Generated recall hooks runnpx --no --offline agentsmeshwhen the project depends on agentsmesh, so teammates without a global install still get recall.More tools: the recall hook now answers Gemini CLI's
BeforeAgent, Cursor'ssessionStartandpostToolUseFailure, and GitHub Copilot'ssessionStartandpostToolUseFailure. Codexapply_patchedits get recall for the files they touch, subagents get their own session dedup, and the hook and MCP server find the lessons project from a subdirectory. Target descriptors (including plugins) can declarehookContextEventsso recall is only wired to events whose output reaches the model.Capture and effectiveness: failures are read from the field Claude Code actually sends, keyed on the command that really ran, and user interrupts are no longer counted. A
--trigger-filepath outside the project is rejected instead of being stored where it could never fire. The outcome log is on by default (turn it off with"outcomeLog": falsein.agentsmesh/lessons/config.jsonorAGENTSMESH_LESSONS_OUTCOME_LOG=0), and a lesson counts as missed only when the same action fails again in the same session within 30 minutes, sovalidateandstatsstop flagging lessons that work.Safety: recalled rules are delivered one per line inside a
<recalled-lessons>block, with ids, and every CLI and MCP answer is size-capped, so a hostile rule cannot pose as a system message or flood the context.file_globtriggers use a linear-time matcher over a safe glob subset; other glob syntax is rejected withUNSAFE_GLOB_PATTERNand never matches, so a crafted glob can no longer stall recall.recallLimitandrecallMaxTokensin config.json are capped at 50 and 8000,lessons query --alwayshas the same budget as the hook, and legacy migration refuses index paths outside.agentsmesh/lessons/.98cb625: Upgrade notes. Most projects need to do nothing, but check these after you upgrade:
agentsmesh generateonce. Hooks for Gemini CLI, GitHub Copilot, Cursor and Windsurf, lessons recall hooks, and hooks from installed packs can be generated differently now, soagentsmesh generate --checkreports drift until you regenerate.agentsmesh lessons validate. Some lesson file triggers no longer match anything, andlessons validateandagentsmesh lintnow report them asUNSAFE_GLOB_PATTERNerrors:**inside a name (src/**.ts, writesrc/**/*.ts), extglobs (+(a|b), write{a,b}) and ranges ({1..3}, write{1,2,3}).Bash,Edit,WriteandReadreach Gemini's own tools (before, they matched nothing there), but a partial Gemini name such asshellno longer matches: use the full name (run_shell_command) or the Claude Code name (Bash). AUserPromptSubmithook now also runs on Gemini, asBeforeAgent.SessionStartandPostToolUseFailurehooks now also reach GitHub Copilot, andPostToolUseFailurehooks reach Cursor..agentsmesh/lessons/outcome-log.jsonl, local and gitignored) is on by default, and turning telemetry off no longer stops it. Turn it off with"outcomeLog": falsein.agentsmesh/lessons/config.jsonorAGENTSMESH_LESSONS_OUTCOME_LOG=0.agentsmesh lessonsexits 2 for a flag with an empty value, so a script that runs--cmd "$CMD"fails whenCMDis empty..agentsmesh/packs/<name>/are removed, asrefreshalready did. Keep your own changes in.agentsmesh/, outsidepacks/.Patch Changes
579a6c5:
agentsmesh checknow gives the fix that matches the drift it found, instead of always saying "Run 'agentsmesh merge' to resolve, or 'agentsmesh generate --force' to accept current state." For canonical or generated-output drift (including the stale hashes amergecan leave) it points to plainagentsmesh generate; only changed locked features (collaboration.strategy: lock) get thegenerate --forceadvice. A.agentsmesh/.lockwith git conflict markers is now reported as a lock conflict with theagentsmesh mergefix (andlockConflict: truein--json, in the MCPchecktool result, and in theLockSyncReportreturned by the programmaticcheck()), instead of "Not initialized for collaboration".499f7c7: The
agentsmesh lessonscommands handle bad input clearly instead of quietly doing the wrong thing.A flag that needs a value but gets none now fails with exit 2 and "--flag needs a value". Before, it was ignored:
deprecate X --superseded-bydeprecated without the supersede link, andquery --sessionskipped dedup. A value that starts with--can be passed as--flag=value(for example--rule="--no-verify is forbidden"), and the error for an unknown "flag" that is really text says so.prune --cap abcno longer falls back to the default cap.lessons help [subcommand]works.lessons adduses exit 2 for every input error, with messages that name the flag:--scopeother thanalways, a topic id that is not kebab-case (it suggests one),--new-topicwithout a non-blank--topic-summary, and an unsafe--trigger-fileglob, which is now refused before any trigger id is made. A change the graph validator refuses also exits 2, and the message is plain:Refused to save the lessons graph: … Nothing was written.Internal names such asmutateLessonsGraph:no longer show in messages. Repeated--evidencerefs are stored once. The 2000-character rule limit counts characters, so an emoji counts once.--trigger-fileis stored in one form: surrounding spaces and a leading./are dropped, so./src/a.tsreuses thesrc/a.tstrigger. A relative path that climbs out of the project (../x.ts), the project root, or an existing folder is rejected with a clear reason; for a folder it suggestsfolder/**. The same applies to the MCPlessons_addtool. A--trigger-cmdwith a\u{…}escape is rejected, as the docs said.querysays when a legacyindex.yamlstore could not be migrated, instead of printing only "(no matches)".import-md --migrated-atmust be a real date.AGENTSMESH_LESSONS_TELEMETRYandAGENTSMESH_LESSONS_OUTCOME_LOGalso accepttrue/false,yes/noandon/off.lessons querywarns whenconfig.jsonhas a switch that is nottrue/false(such as"outcomeLog": "no") or is not a JSON object.Smaller fixes:
show <lesson>includes the rationale,journalmarks deprecated and superseded lessons,validate --jsonnames the error codes, messages end with a period, the--idshelp text says what it does, and the docs keyword example uses one--trigger-kwper keyword.b2bfc56: The lessons recall hook, the lessons.json merge driver and the lessons logs handle more edge cases correctly.
Recall hook: it reads a payload over 1 MB to the end before ignoring it, so the host no longer gets a broken pipe, and it reads JSON that starts with a UTF-8 BOM. An event name it does not know (such as Gemini's
BeforeTool) now does nothing instead of answering asPostToolUse; a payload with no event name is still a tool call. Copilot's VS Code compatibleSessionStart(withinitial_prompt) gets task recall. The project now comes from the touched file first, so in a monorepo a package's own lessons apply to its files, and acwdoutside the project no longer hides it. A decomposed (NFD) path matches its glob. On a prompt, the note about hidden matches is back: at most 5 keyword rules are shown, the always-on lessons keep their own budget, and the hook says what either cap left out. The recurrence warning counts only failures from the last 24 hours (it used to count every failure ever, "failed 833×"). A Cursorpermission_deniedis not recorded as a failure, a failed command's nudge no longer suggests a file glob, and recalls running at the same time no longer lose each other's session dedup entries.Logs and files: an append after a line cut off mid-write starts a new line instead of gluing two records, the logs are capped by size (a single huge line is dropped) and readers read only the newest part, a read-only
lessons.jsonis not written over and a save keeps its file mode, a.lessons.lockthat is a file gets a clear message instead ofENOTDIR, a UTF-8 BOM inlessons.jsonorconfig.jsonis ignored, a writer waiting on a busy lock says once who holds it, and old temp files and stale lock folders are cleaned up.Merge: a trigger or topic deleted on one branch stays deleted when the other branch did not change it and no lesson uses it.
lessons resolverefuses to save a result with errors when it had to rebuild the sides from conflict markers (and keeps the markers), warns when the markers have no merge base, counts lessons after same-id renames, and names the right next step for a merge, rebase, cherry-pick or revert (none outside git). The merge driver falls back to the bare command when npx is missing but agentsmesh is on PATH.initandgenerateask you to re-runinit --lessonswhen the recall hook command in hooks.yaml no longer matches the project's agentsmesh dependency, andgenerateno longer repeats "Kept your own lessons.json merge driver" on every run.e2f4219: Installing a changed pack again now updates it in place. Before, if the source dropped a folder (say
commands/), runningagentsmesh installagain with the same--namefailed with "Auto-generated pack name … collides", and without--nameit added a second pack from the same source that kept the removed files. Now the install finds the pack from the same source,--targetand--as(by--name, by feature set, or the one pack that covers the whole source). When both cover the whole source, it replaces the pack's contents likerefresh, so files removed at the source go away. A picked subset still merges, and packs split by--path,--asor pick stay separate. A re-install without--namealso keeps the pack's name (it used to rename a local pack to an auto-generated name), and--dry-runshows the pack it would update. A--namethat belongs to a pack from another source now fails with a clear message that names the pack.Skill folders are no longer dropped because of their name. A source with
rules/next toskills/my_skill/orskills/S1/used to look like a lone rules folder, so its skills, README and LICENSE were skipped without a word. Any skill folder name now counts, except names that start with.or_.mcp.json,hooks.yaml,permissions.yamlandignoreat the root of a source without.agentsmesh/are still not installed (settings install only from a source's.agentsmesh/folder), but install now prints one warning that names each skipped file.7857ff1: The MCP
checkandgeneratetools now tell the same story as the CLI.checkruns the same check asagentsmesh check, so an unreadable.agentsmesh/lessons/lessons.json(a merge conflict, bad JSON, a schema error or a newer version) is now reported in a newlessonsGraphErrorfield, with the same text as the CLI JSONerror, instead of looking like a clean result.generatesetslockfileUpdatedonly when the run really rewrote.agentsmesh/.lock; a run that changes nothing leaves the lock alone and now saysfalse.b7ab200: Internal-only: removed dead code and collapsed duplicated generators. Two exported helpers had no caller outside their own tests since the commit that introduced them, and one install helper was fully superseded by a more general sibling. Fifteen targets each carried the same four-line ignore generator differing only in a path constant, and the pack writer and merger each repeated the same copy-into-subdirectory loop three times; both now call one shared helper. No behaviour changes: every generated artifact is byte-identical.
ab63a79:
agentsmesh generateno longer rewrites.agentsmesh/.lockwhen nothing changed. Before, a run that printed "Nothing changed" still wrote a newgenerated_at, so the git tree was dirty after everygenerateand each teammate's run showed a lock diff. Now the lock is rewritten only when itschecksums,extends,packsoroutputschange; otherwise the file stays byte-for-byte the same.generated_at,generated_byandlib_versionnow describe the last run that changed the lock.check,generate --checkandwatchwork as before.cab70b6: On Windows, agentsmesh now copes when another process is removing or reading the same lock folder or file at that moment. A command waiting for a busy lock (for example
generate,installor a lessons write) no longer crashes withEPERM, and lessons recalls running at the same time no longer lose a session dedup entry. ShortEPERM,EACCESandEBUSYerrors are retried for a moment, as renames already were; an error that does not clear still stops the command.