diff --git a/CHANGELOG.md b/CHANGELOG.md index ee2f6b3..302179f 100644 --- a/CHANGELOG.md +++ b/CHANGELOG.md @@ -6,6 +6,28 @@ Accuracy figures inside a released entry are the numbers measured **at that rele left as written. The current numbers live on the [evidence page](https://usefixmap.vercel.app/evidence), which is generated from the recorded results rather than transcribed by hand. +## 0.8.4 - 2026-08-02 + +### Fixed + +- `fixmap doctor` now detects when npm requested an exact FixMap version but executed a different local or ancestor installation. It reports both versions and exits non-zero instead of calling the shadowed process healthy (#437). +- The reproducible installation path now uses an isolated npm prefix and invokes that prefix's shim directly. The previous npm exec recommendation could itself be redirected to an older ancestor installation on Windows. + +### Evidence + +- Reproduced the failure against the published v0.8.3 package with a real 0.8.1 ancestor install before changing source. +- Added regression coverage for mismatched, matching, and non-exact npm package requests. All 417 workspace tests, typechecking, lint, production builds, the production security audit, Action bundle parity, smoke tests, held-out/external/adversarial gates, and the scanner benchmark pass. + +### Installation + +```bash +npm install --global @aryam/fixmap@0.8.4 +fixmap doctor +fixmap --version +``` + +The npm packages, MCP Registry entry, GitHub tag/release, Action tag, and production site must all resolve to 0.8.4 before the release is considered complete. + ## 0.8.3 - 2026-08-02 ### Fixed diff --git a/README.md b/README.md index 8fed622..9e4b939 100644 --- a/README.md +++ b/README.md @@ -73,8 +73,8 @@ npx -y @aryam/fixmap@latest doctor Remove the stale copy with `npm uninstall -g @aryam/fixmap`, or test an exact version in an isolated prefix and invoke that prefix's shim directly. This PowerShell sequence cannot be redirected to an older package in the current directory or one of its parents: ```powershell -$fixmapPrefix = Join-Path $env:TEMP "fixmap-cli-0.8.3" -npm install --global --prefix $fixmapPrefix @aryam/fixmap@0.8.3 +$fixmapPrefix = Join-Path $env:TEMP "fixmap-cli-0.8.4" +npm install --global --prefix $fixmapPrefix @aryam/fixmap@0.8.4 & "$fixmapPrefix\fixmap.cmd" --version ``` @@ -278,8 +278,8 @@ npx -y @aryam/fixmap@latest doctor ```text # FixMap Doctor -- ok Running version: 0.8.3 -- PROBLEM Global install: 0.3.1 (this process is 0.8.3) +- ok Running version: 0.8.4 +- PROBLEM Global install: 0.3.1 (this process is 0.8.4) A globally installed fixmap shadows the version npx was asked for. Run `npm uninstall -g @aryam/fixmap` or update the global installation. For a clean pinned run, use the isolated-prefix command above. @@ -362,7 +362,7 @@ jobs: with: fetch-depth: 0 - id: fixmap - uses: aryamthecodebreaker/FixMap@v0.8.3 + uses: aryamthecodebreaker/FixMap@v0.8.4 with: github-token: ${{ secrets.GITHUB_TOKEN }} ``` @@ -373,7 +373,7 @@ To close the plan→edit→verify loop without leaving GitHub, save the plan as ```yaml - id: plan - uses: aryamthecodebreaker/FixMap@v0.8.3 + uses: aryamthecodebreaker/FixMap@v0.8.4 with: format: json - run: echo '${{ steps.plan.outputs.report }}' > fixmap-plan.json @@ -383,7 +383,7 @@ To close the plan→edit→verify loop without leaving GitHub, save the plan as path: fixmap-plan.json # In a later run, after the fix is pushed: - - uses: aryamthecodebreaker/FixMap@v0.8.3 + - uses: aryamthecodebreaker/FixMap@v0.8.4 with: mode: verify report-path: fixmap-plan.json @@ -466,6 +466,10 @@ Read the full [benchmark methodology and scanner measurements](docs/BENCHMARKS.m npm run evaluate:heldout ``` +## What changed in v0.8.4 + +v0.8.4 closes the last installation defect found by the independent post-release audit. Doctor now exits non-zero when npm records an exact requested FixMap version but a local or ancestor `node_modules` installation runs a different version. The installation guide no longer calls npm exec unambiguous in that state; its reproducible path uses an isolated prefix and invokes that prefix's shim directly (#437). + ## What changed in v0.8.3 v0.8.3 corrects MCP comparison validation after an independent audit reproduced #398 against the published v0.8.2 package. `fixmap_compare` now rejects a truncated `{ "contextFiles": [] }` object, validates optional rank, score, and confidence fields when present, and still accepts complete reports that legitimately found zero context files. No ranking behavior or evaluation result changed. diff --git a/apps/web/package.json b/apps/web/package.json index c913ca5..f8401c5 100644 --- a/apps/web/package.json +++ b/apps/web/package.json @@ -15,7 +15,7 @@ "typecheck": "tsc --noEmit" }, "dependencies": { - "@aryam/fixmap-core": "0.8.3", + "@aryam/fixmap-core": "0.8.4", "@phosphor-icons/react": "^2.1.10", "next": "16.2.11", "react": "19.2.7", diff --git a/package-lock.json b/package-lock.json index ea270f7..ab45c35 100644 --- a/package-lock.json +++ b/package-lock.json @@ -1,12 +1,12 @@ { "name": "fixmap-workspace", - "version": "0.8.3", + "version": "0.8.4", "lockfileVersion": 3, "requires": true, "packages": { "": { "name": "fixmap-workspace", - "version": "0.8.3", + "version": "0.8.4", "license": "MIT", "workspaces": [ "packages/*", @@ -30,7 +30,7 @@ "name": "@fixmap/web", "version": "0.0.0", "dependencies": { - "@aryam/fixmap-core": "0.8.3", + "@aryam/fixmap-core": "0.8.4", "@phosphor-icons/react": "^2.1.10", "next": "16.2.11", "react": "19.2.7", @@ -8553,18 +8553,18 @@ }, "packages/action": { "name": "@fixmap/action", - "version": "0.8.3", + "version": "0.8.4", "license": "MIT", "dependencies": { - "@aryam/fixmap-core": "0.8.3" + "@aryam/fixmap-core": "0.8.4" } }, "packages/cli": { "name": "@aryam/fixmap", - "version": "0.8.3", + "version": "0.8.4", "license": "MIT", "dependencies": { - "@aryam/fixmap-core": "0.8.3", + "@aryam/fixmap-core": "0.8.4", "@modelcontextprotocol/sdk": "1.30.0" }, "bin": { @@ -8576,7 +8576,7 @@ }, "packages/core": { "name": "@aryam/fixmap-core", - "version": "0.8.3", + "version": "0.8.4", "license": "MIT", "devDependencies": {}, "engines": { diff --git a/package.json b/package.json index 017fbf1..8947c87 100644 --- a/package.json +++ b/package.json @@ -1,6 +1,6 @@ { "name": "fixmap-workspace", - "version": "0.8.3", + "version": "0.8.4", "private": true, "description": "Local-first repo context for coding agents: paste a GitHub issue URL to get ranked files, test routes, and risks.", "license": "MIT", diff --git a/packages/action/package.json b/packages/action/package.json index 0ebfe8a..4793b44 100644 --- a/packages/action/package.json +++ b/packages/action/package.json @@ -1,6 +1,6 @@ { "name": "@fixmap/action", - "version": "0.8.3", + "version": "0.8.4", "description": "GitHub Action wrapper for FixMap pull request reports.", "private": true, "license": "MIT", @@ -11,6 +11,6 @@ "typecheck": "tsc -p tsconfig.json --noEmit" }, "dependencies": { - "@aryam/fixmap-core": "0.8.3" + "@aryam/fixmap-core": "0.8.4" } } diff --git a/packages/cli/package.json b/packages/cli/package.json index e0f0a9f..4aa3f89 100644 --- a/packages/cli/package.json +++ b/packages/cli/package.json @@ -1,6 +1,6 @@ { "name": "@aryam/fixmap", - "version": "0.8.3", + "version": "0.8.4", "mcpName": "io.github.aryamthecodebreaker/fixmap", "description": "Local-first CLI and MCP server mapping GitHub issue URLs, tasks, and diffs to ranked files, tests, and risks.", "license": "MIT", @@ -46,7 +46,7 @@ "typecheck": "tsc -p tsconfig.json --noEmit" }, "dependencies": { - "@aryam/fixmap-core": "0.8.3", + "@aryam/fixmap-core": "0.8.4", "@modelcontextprotocol/sdk": "1.30.0" }, "engines": { diff --git a/packages/core/package.json b/packages/core/package.json index 1b118ae..a3cf043 100644 --- a/packages/core/package.json +++ b/packages/core/package.json @@ -1,6 +1,6 @@ { "name": "@aryam/fixmap-core", - "version": "0.8.3", + "version": "0.8.4", "description": "Deterministic local-first repository scanner, context ranker, and report renderer for coding agents.", "license": "MIT", "repository": { diff --git a/server.json b/server.json index 123b706..b3bcc5c 100644 --- a/server.json +++ b/server.json @@ -6,12 +6,12 @@ "url": "https://github.com/aryamthecodebreaker/FixMap", "source": "github" }, - "version": "0.8.3", + "version": "0.8.4", "packages": [ { "registryType": "npm", "identifier": "@aryam/fixmap", - "version": "0.8.3", + "version": "0.8.4", "transport": { "type": "stdio" },