Skip to content

uphold 1.14.0: a command seam that reads what will really run, and an unknown that is no longer a pass - #132

Merged
HackingGate merged 1 commit into
mainfrom
release-1-14-0
Sep 2, 2026
Merged

uphold 1.14.0: a command seam that reads what will really run, and an unknown that is no longer a pass#132
HackingGate merged 1 commit into
mainfrom
release-1-14-0

Conversation

@HackingGate

Copy link
Copy Markdown
Owner

Point the documented pins at 1.14.0 and bump the crate version.

Minor, not patch. This release carries names a policy written against 1.13.0
cannot use: the bundled set mismatched-author; api:* as a matchable verb on
the gh and glab shim tables, so a forge call that carries a body is read the
way gh pr create is; unresolved on a [[shim]] table, whose default refuses
before exec where a scope could not be evaluated; and refuse_unknown,
foreign_hosts and redact_matches on the private-name family.

It also closes four seams that reported a pass they had not established. The
MCP hook seam consulted no prose rule, so every prose_regexp was dark exactly
where an agent publishes. Five command lines walked past the shim, four of
them ending in exit 0 with nothing printed. A blob no charset decodes was read
as clean rather than refused. A forge host nobody could ask about produced no
finding, no report and no exit code.

Landed in this release: #116, #117, #123, #124, #126, #129, #131.

A policy written against 1.13.0 loads unchanged, and every new name has to be
named or inherited to run. Two things do change for a consumer who only bumps
a rev or a ref: the seam fixes above start refusing text and command lines
that used to pass unexamined, and the four published Go ids are triggered by
the module rather than by the file that changed, at all four stages rather
than at pre-commit alone.

https://claude.ai/code/session_01HEudouCNhFHK6UPEWcWqXd

… unknown that is no longer a pass

Point the documented pins at 1.14.0 and bump the crate version.

Minor, not patch. This release carries names a policy written against 1.13.0
cannot use: the bundled set mismatched-author; api:* as a matchable verb on
the gh and glab shim tables, so a forge call that carries a body is read the
way gh pr create is; unresolved on a [[shim]] table, whose default refuses
before exec where a scope could not be evaluated; and refuse_unknown,
foreign_hosts and redact_matches on the private-name family.

It also closes four seams that reported a pass they had not established. The
MCP hook seam consulted no prose rule, so every prose_regexp was dark exactly
where an agent publishes. Five command lines walked past the shim, four of
them ending in exit 0 with nothing printed. A blob no charset decodes was read
as clean rather than refused. A forge host nobody could ask about produced no
finding, no report and no exit code.

Landed in this release: #116, #117, #123, #124, #126, #129, #131.

A policy written against 1.13.0 loads unchanged, and every new name has to be
named or inherited to run. Two things do change for a consumer who only bumps
a rev or a ref: the seam fixes above start refusing text and command lines
that used to pass unexamined, and the four published Go ids are triggered by
the module rather than by the file that changed, at all four stages rather
than at pre-commit alone.

Claude-Session: https://claude.ai/code/session_01HEudouCNhFHK6UPEWcWqXd
@coderabbitai

coderabbitai Bot commented Sep 2, 2026

Copy link
Copy Markdown

Warning

Review limit reached

Next included review available in 23 minutes.

Check out review usage here.

View limit details

Limit details: You’ve used the included review currently available.

You've used all free OSS reviews for now. Wait for the free limit to reset to keep reviewing this public repository.

Learn how review limits work.

Review configuration:

⚙️ Run configuration

Configuration used: defaults

Review profile: CHILL

Plan: Team

Run ID: 5320560a-1a95-422b-a440-d513e2ddff9d

📥 Commits

Reviewing files that changed from the base of the PR and between aea8ba8 and 3140f41.

⛔ Files ignored due to path filters (1)
  • Cargo.lock is excluded by !**/*.lock
📒 Files selected for processing (3)
  • Cargo.toml
  • README.md
  • hooks/lefthook.yml

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

@codecov-commenter

Copy link
Copy Markdown

Codecov Report

✅ All modified and coverable lines are covered by tests.
✅ Project coverage is 93.43%. Comparing base (aea8ba8) to head (3140f41).

Additional details and impacted files
@@           Coverage Diff           @@
##             main     #132   +/-   ##
=======================================
  Coverage   93.43%   93.43%           
=======================================
  Files          38       38           
  Lines       14414    14414           
=======================================
  Hits        13467    13467           
  Misses        947      947           

☔ View full report in Codecov by Harness.
📢 Have feedback on the report? Share it here.

🚀 New features to boost your workflow:
  • ❄️ Test Analytics: Detect flaky tests, report on failures, and find test suite problems.

@HackingGate
HackingGate merged commit bb35122 into main Sep 2, 2026
12 checks passed
@HackingGate
HackingGate deleted the release-1-14-0 branch September 2, 2026 12:29
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants