Added
- Bare-core audit extraction phase 2: move audit command implementations and audit flags out of default CLI/SDK into pm-governance-audit item pm-vjk3
- Cursor pagination and bounded-output defaults for list/search/context at scale item pm-dfg0
- Notes/learnings repair parity: add --edit/--delete (and a real --stdin/--file input source) matching comments, so bad annotation entries are fixable via the CLI item pm-a2h3
Changed
- S3: move the --allow-audit-\* override flag family out of core command registrations into pm-governance-audit (enforcement stays core) item pm-7dcf
- S2: move the --audit linked-usage report mode off pm files/pm docs into pm-governance-audit item pm-27mv
- S1: relocate dedupe-audit/dedupe-merge/comments-audit/normalize implementations into pm-governance-audit and delete their public SDK exports item pm-79fr
Fixed
- Runtime-extension snapshot caches go stale in long-lived in-process embeddings (install invisible to next invocation) item pm-8fxc
- GH-518: reduce Complex Method in src/cli/commands/next.ts (CodeFactor, PR\#517 rank rendering) item pm-2gvp
Other
- Extract governance audit runtime from the default CLI and SDK item pm-w1c0
- S5: coverage migration + bare-core vs installed-plugin e2e verification for the audit extraction item pm-rxp1
- S4: purge audit surface from default SDK contracts, MCP tool definitions, completion, help, and docs; package declares its own contracts; re-measure token surface item pm-kg18
- Promote terminal-status and mutation runner primitives required by package-owned governance workflows item pm-yu6d
- Decision: extension-point mechanism and bare-core fallback semantics for extracted audit flags (D1+D2 of pm-vjk3) item pm-fg0b
- Scale benchmark harness: synthetic 10k/100k/1M-item workspace generator + latency/memory/token baseline for the read and claim hot paths item pm-mi2x
- Lazy-load @sentry/node off the command hot path (~850ms ESM load on every command, even when telemetry disabled) item pm-1ybs
- ADR: workspace scale-out strategy — indexed reads, storage fan-out, and bounded-output contracts for 100k-1M-item workspaces (proposed) item pm-bl8x
- Local test/coverage dev loop 17+min: replace per-call spawnSync CLI runner with synchronous worker-thread bridge item pm-kvd0
Added
- Promote plan workflow primitives to the public SDK: plan create/steps/dependencies/decisions/discoveries/validation/materialization item pm-je50
Fixed
- Restore 100% SDK workspace read-error coverage item pm-jw2a
- GH-510: macOS nightly red — withTempPmPath skips realpath canonicalization; init-path-guard probe-root assertion fails (/var vs /private/var) item pm-dprb
- GH-454: schema add-field accepts reserved built-in names silently; collision error names no partner item pm-b9ov
- GH-516: pm init seeds unrelated managed packages into fresh PM_GLOBAL_PATH workspaces item pm-b0se
- GH-448: boolean custom field is silently never persisted (data-loss class) item pm-sjfs
- GH-509: pm claim --next lacks candidate filters and race-loss walk — thread next filters + advance to next candidate item pm-fjxm
- Prevent Decision items from entering agent work lanes by default; allow explicit maintainer opt-in item pm-eqk0
- GH-513: pm next ready\[\] documented as ranked but not priority-ordered; no rank/score exposed item pm-1mwk
- Fix red main coverage gate: measure-agent-token-surface.mjs landed without a covering spec item pm-ksca
- GH-508: dedupe LegacyNoneCollectionNormalizer tables duplicated between create.ts and update.ts (CodeFactor) item pm-zuw8
- Release-readiness guard expects pre-sync version:check command after date-version synchronization item pm-pmmv
- Restore generated-loader docstrings and redact host path from tracker history item pm-9ugc
- Full coverage contention times out metadata content-filter integration case item pm-d30l
- GH-453: plan materialize --json response omits title/type/parent on materialized entries item pm-ypha
- GH-452: plan materialize dead-ends on types with required-on-create custom fields item pm-qd2h
- GH-507: recovery suggested_retry appends <value\> to missing boolean EXTENSION flags (contract arity ignored) item pm-9qcr
- GH-505: nested extension failures suggest irrelevant missing flags instead of preserving tracker recovery item pm-o71e
- GH-504: importer/exporter registered without options yields an unusable CLI command (no arg/flag contracts) item pm-0mjz
- GH-503: flattened extension-command aliases (csv-export, jira-sync) drop option contracts item pm-s9iu
Other
- Coverage to 100%: src/core, src/mcp, and src/sdk modules item pm-krwu
- Baseline agent token cost of the CLI surface: measure pm --help, per-command help, and contracts payload sizes before consolidation item pm-a22j
- Research and document the July 2026 native ChatGPT/Codex plugin implementation plan item pm-n28t
- Align all plugin and package manifests to date-based versioning with release-time sync item pm-hxsv
Added
- pm claim --next: atomically claim the next actionable item so parallel agents each get distinct work item pm-114v
Fixed
- Dangling dependency references: accepted at create/update, skipped by validate, and treated as satisfied by pm next (silent unblock) item pm-ol5v
- Classify tracker-not-initialized Sentry CommandErrors as expected handled CLI errors item pm-w7jq
- GH-498: pm comments rejects --body — accept it as an alias for --add and hint on unknown options item pm-z32q
- GH-500: suggested_retry renders boolean flags with a "<value\>" placeholder — literal suggestion fails item pm-6y58
- pm next repeats the recommended item verbatim as ready\[0\] — emit an id reference instead item pm-hfg5
- pm next recommends another agent's assigned in_progress item as 'resume to finish' — recommendation must be caller-aware item pm-yl6c
- GH-489: pm next summary reports blocked: 0 while blocked items exist — blocked companion list missing item pm-l0bu
- GH-501: pm init <path\> roots a tracker that workspace discovery cannot find — tracker_not_initialized loop right after init item pm-69nl
- GH-496: extension flags declared list:true don't accumulate repeated occurrences — host maps to scalar, Commander last-wins drops values item pm-kfq5
- Reserved item-field name collisions are invisible to SDK lint/preflight/harness item pm-ghf1
- Repeated --ac flags on create/update silently keep only the last acceptance criterion item pm-b84u
- GH-497: pm create --template silently drops tags and custom type-option fields — only built-ins (priority/assignee) apply item pm-l6rz
- pm create/update --dep silently normalizes malformed shorthand into dangling dependency ids (related:pm-x26a -\> pm-related:pm-x26a) item pm-zazb
- contracts-snapshot gate is environment-dependent: fixture baked in installed-extension contracts, failing CI on extension version drift or absence item pm-zcjy
- GH-495: extension context pm_root ignores root-layout trackers (falls back to non-existent .agents/pm) item pm-kvev
- pm close never stamps closed_at, so changelog and release-notes bucketing always falls back to updated_at item pm-m4iu
Other
- Repo-wide 100% docstring coverage: public API + data contracts (gate-enforced) item pm-4ak1
- Docstring gate: extend static-quality-gate to enforce public-API + data-contract coverage repo-wide item pm-5566
- Docstrings: src/types (shared data model interfaces + consts) item pm-uxmf
- Docstrings: src/sdk (public SDK surface + cli-contracts) item pm-uwu0
- Docstrings: packages/\* (module docs + exported/public surface for all 11 shipped packages) item pm-qely
- Docstrings: src/core/extensions (extension-types + loader/runtime contracts) item pm-mswi
- Docstrings: src/cli/commands (largest surface — command option/result interfaces) item pm-m0uc
- Docstrings: src/core (search, schema, test, history, telemetry, governance, store, item, and remaining core modules) item pm-768v
- Docstrings: src/cli (non-commands), src/mcp, src/ root modules item pm-2vb2
- Untrack vendored pm-changelog extension dist from git (installed npm artifact, restored by changelog:pm:install) item pm-sod3
- Refresh CodeQL Actions and reject incompatible Node 26 type-contract bump item pm-2a9n
Added
- GH-473: pm install prints a post-install verification summary item pm-yjim
Fixed
- Sentry release gate misclassifies handled duplicate-import refusal as a blocking runtime error item pm-io4t
- GH-488: path-target pm init emits executable tracker-scoped follow-up commands item pm-x26a
- Declarative extension install: activation failure is misreported and scaffold next_steps break when @unbrained/pm-cli is unresolvable item pm-3wsi
- Project package install with --pm-path can write extensions into the caller workspace item pm-qt5d
- GH-482: Node 24 nightly coverage gate flake — readdir-order-dependent branch at front-matter-cache.ts:505 item pm-gume
- Context evaluation runner and CI gate: rank-aware quality metrics plus token-budget regression checks item pm-xmp5
- Token-cost regression gate: CI budget check over a representative command-output corpus item pm-cu1i
- GH-484: pm update --blocked-by silently overwrites prior blockers instead of appending item pm-q6gx
- GH-485: pm search rewrites quoted status:all hybrid queries into --status and drops keywords item pm-2ldo
Other
- Pre-install package-owned command names should hint the owning package install command item pm-b3e9
- Context relevance scorer contract: pluggable SDK weighting, deterministic default model, and extension override path item pm-h3no
Added
- GH-442: lean pm contracts --summary mode for cheap agent bootstrap (25KB -\> 1-3KB) item pm-vxxm
- GH-470: pm list --today and --recent shorthand filters for recently active items item pm-bfma
Added
- GH-467: isolated package/extension diagnostics — project-scoped doctor and smoke tests without global pm state leaking in item pm-6abs
- GH-474: pm search --limit support in hybrid mode item pm-alnj
Fixed
- Triage: close GH-455 with shipped evidence once the Ollama embedding auto-default fix releases item pm-hq0r
Other
- Expose package lifecycle primitives through public SDK helpers item pm-kffw
- Expose sentry telemetry gate as package script alias item pm-w86l
- ADR: 2026-06-07 deep review + remediation pass (never-block, MCP/version coherence, docs/CI hardening) item pm-96wm
- GH-476: pm context rejects --max-items with an untargeted unknown_option (alias or recovery hint) item pm-5h9g
Added
- Promote query/read primitives to the public SDK: list, get, search, context, next, aggregate, stats item pm-rjqr
- Promote item lifecycle primitives to the public SDK: create, update, close, claim/release, copy, delete, restore, focus item pm-98cz
Fixed
- SDK client.run() rejects structured payloads for create: raw {type,title} fails with 'Missing required option --title' item pm-395t
- GH-427: Windows Node 24 nightly fails — POSIX-only error-code assertions (EACCES/EISDIR) in restore-command and history-rewrite specs item pm-lt6n
- pm plan create silently ignores the root --id-only flag (prints full plan envelope) item pm-oz0k
- Annotation --add silently stores flag-like tokens as content: pm notes <id\> --add --stdin records the literal note "--stdin" item pm-vcu7
- Bare extension command group (pm changelog / pm graph) exits 0 with zero output instead of rendering group help item pm-1k57
- pm extension --install pm-<alias\> / @unbrained/pm-<alias\> fails with 'Local extension source does not exist' instead of suggesting the bundled catalog alias item pm-jqd2
- GH-463: linked PM tracker-read tests should auto-remediate or suggest --auto-pm-context item pm-6e1d
- GH-455: pm health auto-selects an uninstalled Ollama embedding model then fails vector refresh item pm-aems
- Relative lancedb vector-store path resolves against process cwd, creating nested .agents/pm/.agents/pm stores item pm-og1v
Other
- GH-458: claim/start-task reject --assignee with an untargeted recovery hint (alias or better hint) item pm-qfte
- GH-468: clarify or publish the pm SDK npm package coordinates (@unbrained/pm-sdk is 404) item pm-25d0
- 2026-07-07 ecosystem audit \#16: all-status review, long-horizon gap items (merge semantics, event stream, policy roles, flow metrics) item pm-su60
- 2026-07-06 ecosystem audit \#15: WIP hygiene, GH/commit coverage verification, grammar+SDK domain completions, horizon-4 planning item pm-pvij
- chore: 2026-07-06 ecosystem audit \#14 — WIP status hygiene (docstring family reset) + stale in-progress detection backlog item pm-6a1g
- chore: 2026-07-06 ecosystem audit \#13 — Semgrep-issue metadata backfill, scale-out initiative pm-9rxu, composability contract set item pm-lgim
- 2026-07-06 ecosystem audit \#12: GH-467..474 backlog coverage + code-scanning capability epic item pm-3rgp
- pm install should accept multiple package targets (help already advertises \[targets...\]) item pm-hj9h
- Triage: close stale dogfood reports GH-436 (pm next/focus) and GH-440 (context --fields) with shipped evidence item pm-7cx8
- Unblock dependabot PRs: @types/node 26 type error, pnpm release-age cooldown, codeql-action lockstep group item pm-2czc
Added
- Expose SDK runAction and PmClient execution surface for programmatic integrations item pm-xzhz
Other
- ADR: the pm SDK is the single public API — CLI and MCP are presentation layers (proposed) item pm-muhw
Added
- Architecture boundary ratchet: prevent new CLI/MCP private core imports while SDK promotion shrinks the baseline item pm-8778
- Lock contention auto-retry: bounded jittered wait before lock_conflict so parallel agent mutations self-heal item pm-2muu
- As a new teammate or onboarding agent, I want accurate docs, one-command onboarding, and automated date-based releases, so that I can become productive quickly and ship safely item pm-ixm6
- As a coding agent, I want keyword, semantic, and hybrid search with inline field filters, so that I can find relevant prior context before creating new work and never duplicate an item item pm-nnro
Fixed
- pm claim silently steals items already assigned to another agent — claim must be atomic test-and-set for multi-agent work distribution item pm-8t5x
- Extension activation adds ~200ms to every command when bundled packages are installed item pm-4oww
- pm close <id\> -m 'text' still hard-blocks with close_reason_required: accept --message text as close-reason fallback (like closed pm-7x8d did for --resolution) item pm-9hry
- Extension installs are dead-on-arrival in CommonJS host projects: installed extension dirs lack package.json type:module item pm-r0m4
- beads/todos import-export runtime broken from real npm installs: runtime-loader imports .ts under node_modules (type-strip refused) item pm-ejy7
Other
- Bundle GH-433 self-parent guard, Windows nightly lock proof, and pnpm 11 bootstrap hardening item pm-q1ke
- Inventory the CLI-to-core call graph: map every command to core modules and classify logic for SDK promotion item pm-lodl
- 2026-07-04 ecosystem audit \#4: coverage matrix, governance capability epic & relationship modeling item pm-osea
- As a future maintainer, I want every significant architectural decision recorded as an ADR with context, decision, and consequences, so that I can understand why the system is built the way it is item pm-xugp
- As a maintainer extending pm with agents, I want CodeFactor A+ enforced by ratcheted static gates, so that the codebase stays maintainable no matter how many agents contribute item pm-r0z2
- As an MCP-connected agent, I want narrow pm\_\* tools kept in lockstep with the CLI via machine-readable contracts, so that I get drift-free, discoverable operations over the same primitives item pm-wo7x
- As a coding agent bootstrapping any project, I want to define custom item types, statuses, fields, workflows, and profiles via config, so that pm fits the project's domain without code changes item pm-0zuv
- As a maintainer, I want consent-aware local telemetry and health diagnostics, so that I can observe how pm is used and detect problems without leaking any project data item pm-gnya
- As one of many parallel agents, I want atomic claim and lock semantics with bounded auto-retry, so that we each get distinct work and never corrupt shared tracker state item pm-miju
- As an agent gating on tracker quality, I want pm validate and pm health to surface every data-quality gap with a machine-executable remediation, so that I can keep context trustworthy and rebuild it from pm alone item pm-tra4
- As a third-party author, I want an SDK to compose, validate, test, and ship a pm extension or package, so that pm can be customized and optimized for any project without forking item pm-m2kl
- As a coding agent, I want every mutation to be atomic and fully replayable from an append-only history, so that I can trust the tracker's state and recover any prior context at any time item pm-hu11
- As a coding agent, I want every pm command to be self-describing and to never block without a machine-actionable recovery path, so that I can operate the full item lifecycle with zero out-of-band context item pm-nh73
- Backfill full-context bodies (and comments/deps/risk) on all active items so context is rebuildable from pm CLI alone item pm-o043
- Sandbox audit fixes: package describe accepts npm package name; pm context <id\> routes to pm get item pm-ayn7
- 2026-07-04 full pm-backlog audit: reconcile pm items with entire ecosystem (code, tests, docs, ideas, decisions) item pm-y904
- GH-426: reduce complex method in compatibility-check.spec runCurrentPmCommand item pm-24o5
- SDK testing-helper input validation: runRegisteredCommandForTest positional misuse crashes; createExtensionTestHarness accepts non-extension module silently item pm-2exf
Security
- Extreme mandatory quality gates: strict ESLint everywhere, jscpd strict/zero-threshold, suppressions budget, Trivy/ShellCheck/PSScriptAnalyzer/actionlint CI, admin-proof branch protection item pm-7wmq
Other
- Test meaningfulness audit: strengthen hollow assertions, de-mock thin specs, convert contract source-mirrors to behavior item pm-4i73