2026.7.23

Added

  • SDK relationship registry and graph-query primitives: custom typed edges, adjacency, paths, closures, impact, and bounded subgraphs elemento pm-ju83
  • Context relevance signal feature store: derived recency, graph, claim, risk, deadline, knowledge-density, and semantic-match signals elemento pm-3hps

Fixed

Other

  • Capstone: zero the SDK import-boundary baseline — flip remaining CLI/MCP private-core imports to SDK primitives and harden the ratchet into a hard boundary gate elemento pm-9x6e

2026.7.22

Fixed

  • GH-576: unknown-command help probes return structured non-zero errors elemento pm-bu1m
  • Sentry PM-CLI-2G: make merge-driver installation permission failures actionable elemento pm-bnmlsc
  • Sentry PM-CLI-2F: classify manifest-proven torn bundle call-time TypeError elemento pm-pz7xtx
  • Compatibility gate rejects compact legacy create envelopes after release promotion elemento pm-pkdpyz
  • Sentry PM-CLI-2E: directory-shaped settings.json crashes CLI bootstrap elemento pm-k0nl2w
  • Sentry PM-CLI-2D: storage-integrity history scan reads .jsonl directories as files elemento pm-o1c53b
  • GH-551: dependency seeds accept global source_kind and preserve cross-workspace IDs elemento pm-topu
  • GH-595: list JSON always emits total/has_more/truncated/next_cursor and omits unset filters elemento pm-wrss
  • GH-623: opt-in post-merge history reconciliation hook and one-command verify repair elemento pm-mfkv92
  • GH-553/GH-584: CodeFactor unnecessary-spread findings — restructure flagged spread sites (class owner) elemento pm-zt1c
  • GH-574: flattened extension alias subcommands still drop option contracts after GH-503/GH-550 fixes (empty --help, valid options rejected as positionals) elemento pm-7ufz

Security

  • Dependabot alert \#42: brace-expansion CPU denial of service (GHSA-3jxr-9vmj-r5cp) elemento pm-f5hy2n

Other

  • GitHub analyzer follow-up: GH-628 unnecessary spread, GH-629 duplicate blocks, and GH-630 unsafe optional chaining elemento pm-aw59hb
  • GH-582: runRegisteredListCommand flagged Complex Method by CodeFactor — extract option-assembly helpers in register-list-query.ts elemento pm-zwya

2026.7.21

Added

  • Graph planning & structural analytics: critical-path slack, betweenness/closeness centrality, and articulation points/bridges elemento pm-efuo34
  • CLI+MCP surface for atomic bulk item mutations: JSON mutation batch on stdin over commitItemMutations elemento pm-xm7c
  • GH-438: accept a full item JSON document on stdin for pm create / pm update elemento pm-kipd
  • GH-435: lean JSON output mode omitting null/empty fields (~50% token cut for --json) elemento pm-cfed
  • GH-437: make lean mutation output the CLI default (parity with MCP compact envelope) elemento pm-nilh
  • GH-443: lean error mode — drop constant required/why boilerplate from structured errors elemento pm-g9xk

2026.7.20

Added

  • Tracker merge semantics: field-aware merge guidance, history-chain-safe JSONL merging, and post-merge reconciliation for multi-branch agent workflows elemento pm-g5sx
  • GH-613: public SDK bulk item-mutation helper on commitWorkspaceTransaction — atomic create/update/close batches without hand-rolled step+compensation wiring elemento pm-y9hq
  • GH-612: additive --add-ac/--remove-ac forms for acceptance criteria — replace-only --ac clobbers concurrent branch edits elemento pm-xh82
  • GH-599: git merge driver + documented workflow for append-only history/\*.jsonl (concurrent appends fork the hash chain) elemento pm-wc1r

Fixed

  • Merge-driver fence completeness: relationships/\*.jsonl event stores uncovered and schema-added custom type folders silently drop driver coverage elemento pm-i4fx
  • MERGE_SAFETY.md documented an invalid config invocation: 'pm config set project ids.token_length 6' exits 2 (scope must precede the verb) elemento pm-46octv
  • GH-601: SDK mutation option bags and projected list items are Record<string,unknown\> — typos and wrong types compile clean under strict elemento pm-x29o
  • GH-600: item id generation not collision-safe across branches/concurrent agents (4 base36 chars, local-disk-only uniqueness) elemento pm-pibw
  • GH-615: pm notes --message without content is a silent no-op — apply the GH-588 empty-comment guard to the notes twin elemento pm-iedg
  • GH-602: SDK .d.ts require @types/node but package does not declare it — tsc errors inside node_modules for consumers; plus shipped JSDoc defects elemento pm-n1xx
  • GH-596: update-many --ids must report nonexistent requested IDs elemento pm-ukml
  • GH-597: reject empty append text without false updated_at freshness elemento pm-d9g9
  • Nightly macOS+Windows red post-PR\#568: staging-base selection compares realpath'd source against non-canonical temp dir — staging lands inside source, fs.cp EINVAL self-copy elemento pm-hvt3
  • fix: nightly windows/Node24 red — vcs-extension spec asserts POSIX 'relationships/events.jsonl' against native default store path elemento pm-34yf
  • GH-607: validate reports ok:true / checked_items:0 on structurally-unparseable item .toon — silently skips what pm get hard-errors on elemento pm-cxyv
  • GH-598: pm init .gitignore block hardcodes .agents/pm/ prefix — custom-root workspaces commit runtime cache and conflict on every merge elemento pm-4uqm

Other

  • Adopt collision-resistant id entropy in the pm-cli repository (ids.token_length 4 -\> 6) elemento pm-88cy
  • Adopt PR\#614 merge safety in the pm-cli repository itself: pm merge install, committed .gitattributes fence, CI storage-integrity + strict history-verify gates, transactions GC schedule elemento pm-iwsj

2026.7.19

Added

  • Public SDK transaction boundary: atomic multi-item + relationship-event commit primitive elemento pm-4e12
  • Beyond-PM SDK exemplar spike: minimal VCS-style changeset workflow as a pm package (custom schema + event-sourced history + hooks) elemento pm-xtrd

Fixed

  • Workspace-transaction journals: .agents/pm/transactions/ outside the init gitignore block with no retention or GC elemento pm-8xod
  • GH-609: settings.json/schema/\*.json have no merge driver; validate reports ok:true by silently falling back to defaults on unparseable config elemento pm-xdn6
  • GH-611: delete/modify merge silently resurrects deleted items and leaves conflict markers in history/\*.jsonl while validate stays green elemento pm-wwfd
  • GH-604: pm history <id\> --verify exits 0 when verification.ok is false; no --strict-exit — unusable as a merge-safety gate elemento pm-ol3p
  • GH-608: concurrent edits to different fields always conflict on the shared updated_at scalar (no field-level .toon merge) elemento pm-m3nl
  • GH-603: history-repair cements cross-author data loss after a lossy merge — reverting patch discards the other author's mutation, validate fully green elemento pm-gpo7
  • GH-606: concurrent note/tag appends hard-conflict the .toon item file; stale count headers corrupt the item beyond parsing elemento pm-9q2t
  • GH-588: pm comment --message exits 0 recording nothing — comment invocation without any comment text must fail fast elemento pm-yp56
  • GH-589: pm next --assignee X answers from anonymous-caller perspective and pm claim conflates assignment with claim elemento pm-cj9v
  • GH-591: pm context agenda events re-embed full item payloads already listed in the same response (~35% of brief output) elemento pm-6m1i
  • GH-592: tracker_not_initialized recovery re-suggests pm init even when a --pm-path tracker exists — following it silently splits workspace state elemento pm-tmhs
  • GH-586: graph audit severity and code summaries mix finding and affected-item units elemento pm-um4g
  • GH-590: cycle-creating blocked_by mutations succeed silently — items deadlock out of pm next with no inline feedback elemento pm-i6pi
  • GH-585: extension alias collision diagnostics for core command groups elemento pm-v1yo

2026.7.18

Fixed

  • MCP nested options accept unknown keys silently (pm_deps options.dep no-ops) — extend pm-qxwu top-level warning into options objects elemento pm-upi0
  • Sentry PM-CLI-2C: classify Node MaxListeners runtime warnings as warning-level diagnostics elemento pm-qpfv
  • GH-578: align pm context and pm list-blocked with edge-aware pm next semantics elemento pm-uxkf
  • pm deps context format reports missing_count without enumerating missing references and disagrees with tree format elemento pm-8kch

Security

  • CodeQL alert 27: js/polynomial-redos in sdk/test/linked-command-detection.ts trailing-dash prefix trim elemento pm-8og4

Other

  • As an agent, I can traverse why an item exists, what it affects, what blocks it, and its evidence chain from one bounded graph query elemento pm-8xr8

2026.7.17

Added

  • SDK-only exemplar: minimal custom PM CLI package proving the universal-tool story end-to-end elemento pm-cbwg
  • Promote execution and diagnostics primitives to the public SDK: linked-test running and test-run lifecycle, search eval harness, telemetry stats/export elemento pm-oslr

Fixed

  • cli/main.ts commander program is a module-level singleton: dynamically registered extension commands/flags persist across in-process invocations elemento pm-qfdd
  • Windows packed-extension install regression exceeds the generic Vitest timeout elemento pm-ph3i

2026.7.16

Other

  • 2026-07-15 full CLI SDK and ecosystem manual audit and optimization plan (review pass 91) elemento pm-45lr

2026.7.15

Added

  • Promote governance, validation, health, and maintenance primitives to the public SDK: validate, health, gc, changelog/reporting hooks elemento pm-oxrw
  • GH-444: ergonomic author attribution — global --author, init author_default, unknown-author advisory elemento pm-cpja
  • Promote schema, config, profile, and init primitives to the public SDK: full workspace customization programmatically elemento pm-3mna
  • Promote package & extension lifecycle primitives to the public SDK: install, upgrade, extension list/enable/disable, managed-package state elemento pm-x6jf
  • Promote annotation and link primitives to the public SDK: comments, notes, learnings, files, docs, deps, append metadata elemento pm-zwpp
  • Point-in-time read projection: pm get --at <version\|timestamp\> renders reconstructed historical item state without mutating elemento pm-hib1

Fixed

  • Linked-test item reference parser skips item IDs after value-bearing flags elemento pm-jhg9
  • Sentry PM-CLI-2B: external extension subprocess cannot resolve pm executable elemento pm-d4ns
  • Sentry PM-CLI-29: external Neo4j command reports missing configuration as a high pm-cli error elemento pm-7n5a
  • Nightly windows/Node24: package-manifest SDK-surface exemption uses POSIX endsWith — governance-audit runtime.ts check fails on backslash paths elemento pm-u5zr
  • GH-522: Windows nightly red — init next-steps hints POSIX-quote native Windows paths (quoteCommandArg backslash escaping) elemento pm-b24b
  • GH-567: macOS+Windows nightly red — extension-install copy self-nesting check misses symlinked/short-name temp paths (realpath fallback asymmetry) elemento pm-0fhw
  • Adopt CodSpeed continuous CPU benchmarking in CI: review/land PR\#564 and establish the per-PR perf-regression signal elemento pm-yh6t
  • GH-562: pm init rejects --id-prefix/--prefix flag though id prefix is only positional elemento pm-nmzx
  • GH-560: extension renderer overrides diverge between SDK harness and real CLI output elemento pm-as4a
  • GH-557: contract layer intercepts -h/--help before variadic-positional handlers, blocking legitimate positional content elemento pm-albl
  • GH-547: SDK exporters and renderers cannot suppress host rendering of handled output elemento pm-f38n
  • GH-550: extension list flags are erased at the real CLI boundary elemento pm-evav
  • GH-558: export canonical item-to-context-relevance candidate derivation from the public SDK elemento pm-qyc6
  • GH-555: remove unnecessary spread in relationship registry ordering assertion elemento pm-ofgc
  • Validate lifecycle cycles using ordering relationship kinds only elemento pm-6irg

Security

  • Add OSSF Scorecard supply-chain security workflow with published results and SARIF code-scanning upload elemento pm-k7dp

Other

  • validate_history_unknown_author_events: legacy/actionable split for immutable unknown-author history events + first-party automation author coverage elemento pm-demq
  • Ship DeepSource, DeepScan, and Scrutinizer CI free-OSS analyzer configurations with documented activation elemento pm-3a68
  • ADR: relationship graph semantics — typed directional, ordering, provenance, evidence, and associative edges with schema-extensible invariants elemento pm-4jqm

2026.7.14

Added

  • Promote history-stream maintenance primitives to the public SDK: history-redact, history-repair, history-compact (audited rewrite, re-anchor, checkpoint/prune) elemento pm-4a7m
  • Context usage feedback signal: served-then-acted-on outcomes strengthen relevance scoring (retrieval-practice effect) elemento pm-uwfs

Changed

  • Replace obsolete front-matter vocabulary with item metadata terminology elemento pm-hq28

Fixed

  • Sentry no longer captures deliberate Ctrl+C/Ctrl+D interrupts as error-level events (AbortError, PM-CLI-27) elemento pm-ksv2
  • pm get --full omits children for Plan parents while pm list --parent returns them elemento pm-y4z5
  • Intentional package CommandError outcomes create high-severity Sentry issues (PM-CLI-16) elemento pm-7071
  • Extension install self-copy guard: reject source-inside-destination layouts before fs.cp EINVAL (PM-CLI-28) elemento pm-8myl
  • Torn-install bundle transients block scheduled releases: boot-time chunk-integrity self-check + distinct error code for gate classification elemento pm-wfvq
  • GH-446: pm get omits schedule facet (events/start_at/end_at/location) for Meeting/Event/Reminder elemento pm-x1g5
  • GH-533: create/update accept empty --title — required-title contract inconsistent between omitted and empty string elemento pm-7je0
  • GH-535: pm deps omits dangling parent references (missing_count:0, missing:false) contradicting validate's dangling_reference_count elemento pm-p9sc
  • GH-542: MCP pm_copy nests title/message under options while sibling tools declare flat camelCase params — own suite triggers unexpected-arg warnings elemento pm-hno5
  • GH-532: --estimated-minutes accepts negative numbers and floats — missing non-negative-integer range validation elemento pm-jh9t
  • GH-534: no-op update reports phantom changed_fields in --json while TOON reports empty, and changed_field_count is always null in JSON elemento pm-45mb
  • GH-526: aggregate --sum/--avg accept unknown field names and silently report 0 elemento pm-96vo
  • GH-530: list --status <invalid\> silently returns count 0 — validate against the status domain like --type and search status: elemento pm-kj4k
  • GH-544: linked-file path anchoring — files/docs add/glob/discover/validate-paths resolve at process.cwd() while validate --check-files anchors at the workspace root elemento pm-chyh
  • Separate active dangling dependency warnings from terminal historical reference diagnostics elemento pm-2ler

Other

  • Docstring coverage regressed below achieved-100% by PR\#536 extraction files; quality:static floors never ratcheted and mask drift; drop dead closure-pattern export elemento pm-fb3i
  • PR review helper: watch GitHub checks and enforce thread-scoped replies elemento pm-0fxa
  • Token-budget context packer: diversity-aware selection, projection degradation, and bounded output for pm context/next elemento pm-55ra
  • Complete public linked-resource SDK primitives and actionable dependency governance elemento pm-jcvg