Skip to content
albinogeek
GitHub
albinogeek
Home
Offers
Posts
Receipts
Help
GitHub
Loading page…
Loading what's now…
Home
Now
What's now
A live snapshot of what Damon is shipping this week.
Last updated: 2026-09-23
Active work
Playbook launch: final copy pass and launch sequencing
Newsletter: first issue shipped; second issue in draft
Post polish: reading-progress bar, TOC, format-specific layouts live
This week's pickup
Stripe upsell delivery: playbook + discord-ops emails wired into webhook
Buyer-gated guide route: token-signed access after purchase
Contact page overhaul: topic selector, SKU prefill, SLA copy, JSON-LD
On the bench
Testimonials publish: waiting on first quotes
Buyer-interview funnel: flag-off in prod
Discord buyer-bot install playbook v2
Recently shipped
Shipped Sep 15
harvest user-facing commits from public fleet repos
coalesce repeat error webhooks for 15m
refresh to patched js-yaml, hono and joi; bump turbo
YouDone: show ignored cards instead of hiding them
YouDone: per-card ignore button and context menu
gate: add fix verb that applies named doctor remedies
gate: know shared-actions v1.11
gate: know shared-actions v1.10
repo-ops: match skip dirs below the repo root, not in its absolute path
Shipped Sep 14
rgit: sync hook-staged paths into the index after --only
heft: Cursor's agent CLI and what it starts bill to cursor
heft: an AppImage launcher bills to the app in its mount
heft: a crash helper in an AppImage mount takes its sibling app
heft: BREAKING: drop title, which always equals id
heft: judge crash-helper siblings by their full class set
repo-ops: hold Expo apps' SDK-coupled packages at the installed SDK's bundled versions
repo-ops: move private workspace members' peer pins with their own dependency bumps
repo-ops: fetch sub-path action tags from owner/repo
repo-ops: treat two-part vN.M tags as exact releases ordered by semver
repo-ops: report holds scoped to a workspace member as held
repo-ops: format manifests the package manager rewrote with the repo's biome
repo-ops: bump dependencies declared in workspace member manifests
repo-ops: order Go pseudo-version ceilings and pin them exactly on clamp
Shipped Sep 13
rgit: support --only on an unborn branch
heft: [ and ] change the sort column
heft: retry an inspect the deadline cut, not one that failed
heft: carry an unreadable rollup across swap changes
heft: keep the suggested rule valid JSON for any identity
heft: bill a crash handler only to its own user's app
heft: a view.json may leave out any key
heft: end quietly when the reader closes stdout
heft: measure pid visibility before --user drops rows
Shipped Sep 12
gate: withdraw a tool-missing note when config fills its role
heft: read each pid through one dirfd and a reused buffer
heft: draw only on a sample, input, or the pause clock
heft: skip cgroup.procs for a cgroup the walk saw twice
heft: pull pids off a shared index instead of fixed slices
heft: prune trend history against a set of live row ids
heft: correct stale trend, sixel and flag help comments
heft: keep owner rules and pins in separate placement lists
heft: --check-rules and a per-stage rule trace in --explain
Shipped Sep 11
heft: pad the header labels only where a longer one is drawn
heft: right-align the header labels so every bar opens in one column
heft: swap gets its own header row
heft: swap no longer halves the MEM and CPU bars
heft: --trend auto, ask the terminal which image protocol it has
heft: --trend sixel, the trend image for terminals without the kitty protocol
heft: --explain PID, the resolved identity and the key that moves it
heft: comments in view.json and grouping.json, and a self-documenting header
Shipped Sep 9
scope the scripts override to a top-level tools directory
handle rejections from the Pagefind data layer
declare @date-fns/tz and re-enable noUndeclaredDependencies
strict null comparisons, typed accumulators, explicit sorts
hoist regex literals to module scope
use import.meta.dirname and JSON import attributes
guard conditional JSX against leaked falsy renders
YouDone: compile the pattern instead of discarding it
YouDone: scope the scripts override to a top-level tools directory
YouDone: surface rejections from promises started in sync handlers
YouDone: stop dropping rejections from settings writes and data reloads
YouDone: await cross-tab broadcasts and answer a failed message handler
YouDone: validate regex flags, tighten nullish guards, hoist card regexes
YouDone: name the dropped-rejection invariant, stop faking a saved API key
YouDone: drop debug console calls from background scripts
gate: stop restating a shell gate's argv in --list
gate: name log retention in --version
gate: ask git which shell scripts are the project's own
gate: recognise check, verify and validate as aggregate targets
gate: let a declared shellcheck outrank the shell convention
gate: show the shell gate as a count rather than every script
gate: count configured gates when judging no-ci
gate: serialise findings for --json
rgit: commit --only accepts a path staged for deletion
rgit: keep attributes and separators inside an item's extent
rgit: add the Rust grammar, closing #1
rgit: let an anchor name contain a colon
rgit: add --porcelain NUL records
rgit: index a grouped rule one anchor per selector
rgit: stop pyright blocking multi-line Python anchors
rgit: accept several targets per call
heft: mark a row in trouble, and say when the tree is short
heft: read /proc and /sys under --proc-root
heft: draw a column whole or not at all
heft: draw a trend of the sort metric per row
heft: pause the table, document the keys, fix the detail layout
heft: bucket machine.slice and try the rootful Podman socket
heft: open a detail pane for the row under the cursor
heft: search the argv under a row as well as its title
Shipped Sep 8
heft: bind-mount heft into the Alpine live_proc job
heft: skip empty-prefilter fdinfo walks and oversized dumps
heft: reuse walk threads so glibc arenas do not climb
heft: keep cursor on the same row when the list moves
heft: fold idle shells into their terminal
heft: bill AppImage crashpad under the mount to its app
heft: let view.json and --order set column order
heft: put D left of %CORE and disk after CMP
Shipped Sep 7
gate: plant the clippy fixture under a name Windows can run
gate: bump knownGoodActionsTag to v1.9
gate: the JSON listing omits what the text listing omits
gate: a gate that never started stops its serial group
gate: a config gate no longer duplicates a detected gate
gate: judge abbreviated sha pins and report one path base
gate: report a skipped convention gate only where the role is empty
gate: add --json output for the gate listing
rgit: splice a first container member inside its container
rgit: trim a comment block that closes a file
rgit: trim a blank tail everywhere and anchor a group to its own rule
rgit: refuse to pair a name the server reports twice
rgit: trim a mapping's trailing comments from the compared extent
rgit: pair selector groups and ignore a section's blank tail
rgit: compare the extent rgit stages
rgit: announce the workspace through workspaceFolders
heft: honour NO_COLOR
heft: count uninterruptible processes in a D column
heft: read the footer's `?` from a cached answer
heft: give the zygote fallback the same verdict as every other site
heft: measure the table in columns rather than chars
heft: skip a malformed fdinfo line rather than losing the client
heft: key both inspect lookups by the normalized id
heft: draw the help overlay's cursor keys from the glyph set
Shipped Sep 6
heft: fall back to ASCII characters when the locale is not UTF-8
heft: add --follow to keep sampling
heft: add --top N
heft: add --desc and --asc
heft: put the terminal back when heft does not exit through run()
heft: stop every Ctrl-key from firing its bare binding
heft: reassemble multibyte characters when unescaping a unit
heft: take a regex instead of a substring
Shipped Sep 4
heft: full fdinfo only on PSS and --once
heft: skip io and GPU on kernel threads
heft: reuse inspect until ID set changes
heft: split PSS onto --pss-interval
heft: skip non-DRM fdinfo and prime PSS
heft: write view.json 0o600 and mkdir 0o700
heft: reject non-hex ids before short-id slicing
heft: stop creating unused XDG state and cache dirs
repo-ops: BREAKING: retire pushed; project-register answers it
Shipped Sep 3
hold nanoid ahead of its parents' range
escape the extract-zip traversal advisory via @puppeteer/browsers
pin qs past its DoS and array-limit advisories
clear 4 dependency advisories
YouDone: clear 4 dependency advisories
heft: drop jittery header I/O rates
heft: stack unified CPU and MEM header meters
heft: merge User Services by documented family
heft: keep selection in view and default sort to PSS
heft: bill session helpers out of Applications
heft: fold MCPs into agents and GNOME into session
heft: toggle a help overlay with ? and F1
heft: sample /proc off the TUI thread
repo-ops: BREAKING: retire --status; project-register answers it
Shipped Aug 29
repo-ops: resync bun.lock workspace mirror after an apply
Shipped Aug 26
repo-ops: use uv audit for py-uv instead of pip-audit
Shipped Aug 25
exclude .next/dev from build outputs
gate: bound one gate at a time with gates.<name>.timeout
Shipped Aug 23
YouDone: back off after a 403 quota response
YouDone: GET_CHANNEL reads the channels store
YouDone: keep the age branch's id counter tick
gate: read gate ordering from turbo dependsOn edges
gate: treat a turbo root task as covering its gate
Shipped Aug 22
run gates through turbo so warm runs hit the cache
Shipped Aug 21
split viewer PAT from invite token
Shipped Aug 19
gate: stop reporting turbo and the script it runs as a conflict
rgit: write the fake gits before the parallel subtests exec them
Shipped Aug 18
sanitize excerpts with dompurify instead of isomorphic-dompurify
clear gate lint format typecheck
YouDone: clear gate lint format typecheck
discord-bot: clear gate lint format typecheck
power-pack: clear doc-audit findings
Shipped Aug 17
rgit: close stdio conn before killing the server
repo-ops: repair comments joined by the citation strip
repo-ops: add --status for branch, dirty, ahead and behind
repo-ops: discover projects as git checkouts
Shipped Aug 16
gate: name the lint gate the way gate now names gates
gate: BREAKING: name gates with `gate run`, and stop claiming bare role words
gate: add `gate run <names...>` to run gates by name
gate: add a vuln gate for Python projects
gate: sequence build against typecheck in Next projects
gate: run gates concurrently unless told otherwise
rgit: stage every named path when one is already a staged deletion
repo-ops: run the suite in parallel -- 13.3s to 9.0s
repo-ops: scope registry tokens to the repo being queried
repo-ops: discover Containerfile and <name>.compose.yml
repo-ops: commit and report the image file a bump rewrites
repo-ops: union CLI --exclude with config layers
repo-ops: refuse non-http(s) URLs in registry fetches
Shipped Aug 15
patch dompurify, nanoid and extract-zip vulnerabilities
YouDone: patch critical shell-quote command injection and related transitive vulnerabilities
gate: per-project configuration in .gate.toml
gate: only report missing CI where there are gates to run
gate: make the published Windows binary work
gate: make a shadow warning say how to finish
gate: stop the gate when gate is interrupted
gate: report a repository with no CI at all
gate: run one gate by naming its role
gate: honour a declared vuln target, and stop overloading ci
rgit: report the module version, and name the toolchain
rgit: add --with-lines to emit each symbol's line range
rgit: scope the --version smoke-test exit-code reset globally
rgit: don't leak the --version smoke test's exit code as install.ps1's own
rgit: tolerate go:embed load errors when discovering the SQL adapter
rgit: forward --no-edit for --fixup/--squash without a message
rgit: compute pseudo-anchor insertion offsets by position, not name index
repo-ops: ship REFERENCE.md instead of AGENTS.md
repo-ops: parse bun/yarn audit JSON in their native schemas, not npm's
repo-ops: restore formatting the anchor-based commit dropped
repo-ops: don't silently swallow a broken per-manager registration
repo-ops: break the go/discovery module import cycle
repo-ops: wire py-uv into apply_remediations targeted-bump path
repo-ops: parse git status via --porcelain -z instead of hand-decoding quoting
repo-ops: delete unused SARIF report builder and --sarif-out flag
Shipped Aug 14
bump Rethunk-Tech/gh-actions pin to v1.5
fix 3 more workflows broken by the same missing-Bun bug + a real regression
wire CI Node version to package.json engines.node instead of a stale hardcoded 22
YouDone: dedupe vite install, boolean-coerce ANALYZE env guard
discord-bot: bump Rethunk-Tech/gh-actions pin to v1.5
discord-bot: bump go toolchain to 1.26.6, fixes 4 stdlib CVEs
rgit: bump Rethunk-Tech/gh-actions pin to v1.5
rgit: bump go toolchain to 1.26.6, fixes 4 stdlib CVEs
repo-ops: rewrite behind-latest hints to name real flags and route through settings (#136)
repo-ops: restore env/config precedence for sweep-default settings (#136)
repo-ops: skip default roots that do not exist on this machine
repo-ops: check org allowed-actions policy when gh is authenticated
repo-ops: extract to disk-backed scratch, raise cap to 4
repo-ops: BREAKING: make the full sweep the default, add --conservative
repo-ops: show workspaces with only-remediations under --only-outdated
repo-ops: find git submodules, .git is a file (gitlink), not a directory
Shipped Aug 13
rgit: check tempIndex removal error in deferred cleanup
repo-ops: stop reaching into repo_ops_upgrade for a private yaml loader
repo-ops: surface hold-declined bumps in behind-latest output
repo-ops: resolve_hold accepts js/javascript/python ecosystem aliases
repo-ops: collect requirements-dev and requirements-test pins
repo-ops: parse v3 deno.lock packages.jsr
repo-ops: classify Cargo.lock pdm Deno commit subjects
repo-ops: enrich golang licenses via GOMODCACHE
repo-ops: count pinned requirements.txt versions
Shipped Aug 12
rgit: drop unreachable BatchCatFile exists=false retry
rgit: honor ignorecase for gitignore index probe
rgit: forward cat-file stderr on promisor retry
rgit: classify before reading, and use the index only when HEAD is absent
rgit: probe the index path, not the whole listing, for gitignore
rgit: honor core.ignorecase for index existence
rgit: apply --only even when OnlyPaths is empty
rgit: refuse --only with no targets unless --amend
repo-ops: keep poetry.lock rows with missing versions
repo-ops: fall through JSR meta when license does not normalize
repo-ops: detect compose.yaml filename variants
repo-ops: scaffold pnpm-lock.yaml as pnpm ecosystem
repo-ops: count Pipfile, PDM groups, and requirements.in
repo-ops: enrich JSR package licenses from registry metadata
repo-ops: count Cargo workspace.dependencies as direct
repo-ops: share targeted-bump requirement matcher
Shipped Aug 11
allow Dependabot to update js-yaml
align setup-node with Bun workflows
repo-ops: add tomli fallback when tomllib is unavailable on Python 3.10
repo-ops: restore full verification gate
repo-ops: resolve Ruff gate findings
Shipped Aug 10
rgit: treat a submodule path as absent in BatchCatFile, not malformed
rgit: cite v1.2.0 in DryRun VERSION example
rgit: offer symbols flags in shell completers
repo-ops: release unheld pins from jsonc import maps
repo-ops: release unheld pins on targeted bump
repo-ops: align excluded JSON key with fleet
repo-ops: defer ghost bumps when targeted-bump enabled
repo-ops: defer ghost bumps when targeted-bump enabled
repo-ops: narrow hold rule for pyrefly on audit overrides
repo-ops: keep fleet global settings at resolve time
repo-ops: mark CLI environment overrides outside ambient
Shipped Aug 9
rgit: drop stale porcelain comments from shell scripts
rgit: add PowerShell native completer
rgit: follow renames across symbol history
rgit: align dry-run cosign plan wording
rgit: list structured-data symbols; omit them for commit
rgit: complete every declared symbol not only dirty
rgit: peek shebang from HEAD when worktree file is gone
rgit: list all declared symbols for a file
repo-ops: run poetry/pdm/pipenv fast gates via manager runners
repo-ops: stop counting policy-blocked as bumps
repo-ops: fail closed on export errors; skip unknown py
repo-ops: wire deno-targeted-bump and actions-policy-level
repo-ops: use Pipenv requirements export command
repo-ops: describe manager-native Python exports
repo-ops: detect real Python managers for pip-audit
repo-ops: add org-policy block/warn/report levels
Shipped Aug 6
rgit: build and publish native darwin/amd64 and darwin/arm64 artifacts
rgit: parallelize per-file cross-check queries across changed files
rgit: add rgit completion fish
rgit: check git meets rgit's minimum version, beyond presence
Shipped Aug 5
rgit: wire the HTML LSP cross-check
rgit: add --follow-rename, re-resolving the anchor at each rename boundary
rgit: sign SHA256SUMS with keyless cosign
rgit: support the rev:path two-blob diff scope
rgit: batch git-backed blob reads into one cat-file --batch call
rgit: add a checksum-verified install script and CI check
rgit: add --deep to dial each language server for real
rgit: classify an uninitialized submodule via HEAD's tree entry, not local shape
Shipped Aug 4
rgit: use full Go import path in tree-sitter-markdown hold
Shipped Aug 1
rgit: add a patch body to rgit diff
rgit: scope rgit log by time and path
rgit: refuse a symbol anchor on structured-data files at commit
Shipped Jul 29
rgit: run -with-servers before -generate-only returns
rgit: mirror diff's scope refusals and settle help and warning shapes
rgit: index every name in a Go inline multi-name declaration
rgit: accept a global -C <path> before the command
rgit: clamp lineOf and read quoted YAML keys from the named child
rgit: bound context's stream to budget and scope completion targets
rgit: lstat the spawn lock and bound lsptest frame reads
rgit: require the tab in commit summaries and buffer cat-file stderr
Shipped Jul 28
rgit: PeekShebangLine reports ok=false on a real read failure
rgit: cache TypeScript/TSX *ts.Language instead of rebuilding it
rgit: make -with-servers failures detectable and bounded
rgit: make on-disk swaps atomic and clean up failed installs
rgit: make clean remove rgit-install too
rgit: complete languages/doctor/completion flags in bash+zsh
rgit: stop nil Session.Dial from leaking a client
rgit: close documents after cross-checking them
repo-ops: use bunx for pm_exec_prefix binary invocation
repo-ops: skip Corepack for managers it does not support (bun)
Shipped Jul 27
rgit: add the TypeScript and TSX grammar adapters
rgit: add the Python grammar adapter
rgit: let adapters self-register by extension
rgit: define the grammar adapter seam
rgit: add subcommand dispatch and flag surface
rgit: implement positional argument precedence
rgit: add the git delegation layer
rgit: add the exit-code table as named constants
Shipped Jul 25
repo-ops: release unheld legacy resolutions/overrides pins on targeted bump
repo-ops: stop ghost-bump guard from pre-empting targeted-bump retry
repo-ops: audit-fix version overrides must win over a hold ceiling
repo-ops: enforce package hold ceilings in check/apply
repo-ops: enforce package hold ceilings in targeted bump and apply
repo-ops: enforce package hold ceilings in targeted bump and apply
repo-ops: wire package hold ceilings into uv/hatch/pdm/pipenv/poetry/pip-tools
repo-ops: wire package hold ceilings into Go module upgrades
Shipped Jul 24
repo-ops: resolve ruff findings surfaced by dependency bump (stale S310 noqa, RUF036 union order)
Shipped Jul 23
correct stale AGENTS.md section reference in comment
apply the relative-regression baseline bump to all 6 known-bad CLS routes
calibrate CLS baseline/tolerance against real measured variance
pagefind server-readiness check shouldn't require full app health
fix the same $HOME-in-YAML-env Playwright bug in ci.yml
fix $HOME-in-YAML-env Playwright browser path bug, lower lib/** coverage floor to reality
patch sharp and @hono/node-server vulnerabilities
fix Lighthouse CI config -- collect must be an object, mobile preset invalid
Shipped Jul 21
repo-ops: assert the expected UserWarning instead of leaking it
repo-ops: type tmp_path fixture as Path, not TempPathFactory
repo-ops: recognize pyrefly in target repos' dev deps (#155)
repo-ops: resolve type errors pyrefly surfaced that mypy missed
repo-ops: stage applied remediation files in root-workspace commits
repo-ops: snapshot per-bundle dirty state and stage nested yarn-workspace manifests
Shipped Jul 18
replace deprecated Image priority prop with preload
drop redundant optimizePackageImports entries, add react-simple-icons
load WOFF1 fonts for ImageResponse, not woff2
split server-only exports out of client-reachable modules
adopt Next 16.3-preview + TypeScript 7 + React Compiler
patch @babel/core and tmp vulnerabilities via resolutions
use immutable bookings_slot_tstzrange for overlap EXCLUDE
reuse HomeReceiptsSkeleton in site loading
repo-ops: high-confidence uv.lock supersession parser
repo-ops: check every FROM digest occurrence independently
repo-ops: add PyPI metadata for publishable wheel
repo-ops: drain completed batch before fail-fast clear
repo-ops: clear ruff and mypy regressions from audit wave
repo-ops: flip REPO_OPS_DENO_UPDATE_LATEST under --latest
repo-ops: rename go env integration test to avoid pytest module collision
repo-ops: behind_latest, Update column, and ghost-bump guard
Shipped Jul 15
include buyer_email_hash in delivery upsert RPC signature
wire createCheckoutHold before Polar session
populate buyer_email_hash on upsert/RPC
value import + Promise.resolve for supabase probe
add discord_ops kind and atomic delivery upsert RPC
drop nested main landmarks in playbook loading skeletons
elevated skeleton tokens and BrandMark decorative prop
drop site suffix from book page title segment
Shipped Jul 13
repo-ops: skip ghost-bump isolate when no resolutions
repo-ops: keep co-located workspaces in json-out (#146)
repo-ops: show duration on [done] progress lines
Shipped Jul 9
repo-ops: staleness score and since-last-run delta in JSON and summary
repo-ops: persist per-repo behind-latest history for staleness scoring
repo-ops: toolchain/auth preflight subcommand
repo-ops: satisfy mypy for lazy sbom imports and license iteration
repo-ops: restore snapshot when targeted bump resolves to a ghost version
repo-ops: wire deno remediation hooks into orchestration
repo-ops: audit fail-on gates readable from [tool.repo-ops]
repo-ops: targeted-bump-aware behind-latest hints for npm/pnpm/bun
Shipped Jul 2
repo-ops: resolve locked Python dependency licenses from uv.lock + venv dist-info (#144)
repo-ops: parse ASCII-pipe outdated table on non-UTF-8 terminals (#145)
repo-ops: resolve mypy errors surfaced by post-refresh mypy version
Shipped Jul 1
repo-ops: correct stale "(read-only)" audit label
repo-ops: single-source the dirty-skip marker string
repo-ops: reject tag-prefix collisions in _replace_tag_in_line
repo-ops: clean up ruff regressions introduced by parallel fix agents
Shipped Jun 29
repo-ops: de-emphasize not-actionable discovery skips as informational
repo-ops: skip generated Wails wailsjs/ bindings dirs
repo-ops: treat shellcheck warnings as non-fatal, not run failures
Shipped Jun 25
repo-ops: pass advisory-safe version to --fix
repo-ops: targeted bump to explicit version
repo-ops: license-policy gate for dependency license scanning
repo-ops: scaffold/prune .github/dependabot.yml
repo-ops: emit CycloneDX 1.4 and SPDX 2.3 SBOMs from lockfile deps
repo-ops: include gitlink paths in commit scope (#18)
repo-ops: dirty guard; --detach checkout; wire apply into apply flow (#18)
repo-ops: checkpoint after commit; scope fingerprint; lock-across-write (#17)
Shipped Jun 24
repo-ops: cross-major SHA re-pin under --actions-refresh-sha + --latest (#138)
Shipped Jun 18
repo-ops: cap concurrent isolated-copy extractions to prevent /tmp ENOSPC
repo-ops: dedupe uv-lock helpers (#134); gate uv.lock creation behind --migrate-to-uv-lock (#132)
repo-ops: reuse fetched reflog in _reflog_pre_sha (#135)
repo-ops: record requirements.txt-only repos as unactionable skip (#133)
repo-ops: targeted-bump-aware yarn behind-latest hint; wire npm/pnpm flags (#131)
repo-ops: skip vendored/node_modules lockfiles in resolved-version scan
repo-ops: guard npm json parse & peer deps, pre-release overrides, env/linker fixes
repo-ops: poetry 2.x detection, PEP 503 name normalize, pip-tools warn, uv match
Shipped Jun 15
repo-ops: resolve mypy type errors to unblock CI gate
Shipped Jun 11
repo-ops: reuse check-phase plan for apply ghost-guard, probe only as fallback (#127)
repo-ops: wire ghost-bump guard into apply_yarn (#121)
repo-ops: migrate bare TIMEOUT_CHECK/APPLY to resolve_timeout_* (issue #118)
repo-ops: bundle AGENTS.md with install-skill and update SKILL.md link
Shipped Jun 9
repo-ops: advance exact tag pins within their major when upstream has no floating vN tag (#115)
repo-ops: conservative mode ran bare `yarn up`, a Yarn 4 no-op that never moved in-range bumps (#114)
repo-ops: print [report-only] instead of [ok] on Actions rows apply never rewrites (#113)
repo-ops: drop ghost upgrades, filter check/targets to go.mod-recorded modules, remove post-apply checker fallback (#113)
Shipped Jun 6
repo-ops: per-package targeted bump fallback for behind_latest deps (#111)
Shipped Jun 5
YouDone: upgrade vite to 8.0.16 (override was pinning 8.0.13)
repo-ops: delegate subcommand --help to full parsers
repo-ops: fail loudly on override/pin ghost bumps instead of false-green
repo-ops: don't let a skipped-dirty sibling workspace veto the repo commit
repo-ops: surface direct deps left behind by latest-mode yarn up
repo-ops: add --actions-refresh-sha to advance SHA digests within a major
repo-ops: commit Actions-only repos and clean workspaces under a dirty sibling
repo-ops: apply cross-major Action bumps under latest mode (#106)
Shipped Jun 4
repo-ops: round out CLI flags across pushed/inventory/upgrade/root (closes #104)
repo-ops: sharpen human upgrade report under --only-outdated (closes #103)
repo-ops: unify latest-mode UX behind --latest / --go-upgrade-mode (closes #102)
repo-ops: round out JSON output to schema v1 across all producers (closes #101)
repo-ops: exit 1 in show mode when a manifest is unparseable (closes #100)
repo-ops: warn and exit 1 when set_version skips unparseable manifests
repo-ops: enforce upgrade allowlist for dotless `from repo_ops_upgrade import X`
repo-ops: replace hardcoded skip set in count_dep_edges with SKIP_DIRS
Shipped Jun 3
drop redundant engines.yarn so packageManager is source of truth
discord-bot: resolve golangci-lint errcheck/ineffassign/staticcheck findings
discord-bot: bump builder base to golang:1.25-bookworm
repo-ops: detect real 'bun' dependency while still filtering the outdated banner (closes #67)
repo-ops: dedupe actions bump counter to match report rows (closes #65)
repo-ops: only count added package.json lines, drop phantom downgrades (closes #63)
repo-ops: surface worker exceptions as workspace failures, not silent clean exit (closes #62)
repo-ops: resolve short-SHA action pins via unique prefix match (closes #61)
repo-ops: strip whitespace and build metadata in normalize_version (closes #60)
repo-ops: guard uv.lock check/apply when uv missing from PATH (closes #66)
repo-ops: use TIMEOUT_CHECK for uv/rust dry-run checks (closes #64)
Shipped May 31
satisfy notify context types and cache-clear test
wire hero slice and stale beacon to cached GitHub stats
cache GraphQL via unstable_cache and React cache
extend GraphQL timeout and retry on abort
repo-ops: log checker failures instead of bare swallow
repo-ops: align upgrades with conservative semver policy
repo-ops: validate scan roots and default find without -L
repo-ops: prune SKIP_DIRS in node_modules count
repo-ops: narrow apply exceptions and submodule walk guard
repo-ops: default to conservative update like npm
repo-ops: detect more post-apply snapshot changes
repo-ops: scope post-apply commits on dirty worktrees
Shipped May 30
repo-ops: align apply with list -u via patch default mode
repo-ops: keep Berry releases and file siblings in plan snapshot
repo-ops: replace pins only on matched uses lines
repo-ops: keep discovery diagnostics in plan JSON output
repo-ops: add bundled agent skill and install-skill CLI
repo-ops: align uv.sources with runtime dependencies
repo-ops: inject checker into post-apply fallback
repo-ops: inline uv lock helpers for PM import boundary
Shipped May 29
repo-ops: align tabular output and flat project names
repo-ops: count Python lockfile dependency edges
repo-ops: find .git dirs without pruning them away
repo-ops: BREAKING: register repos-* entry points and repo-ops dispatcher
repo-ops: wire --verbose/-v consistently via cli helpers in dep_count and pushed_commits
repo-ops: annotate shared helpers and suppress command mypy issues
repo-ops: add PEP 561 py.typed marker
repo-ops: bootstrap repo-ops package
Shipped May 28
make buyer-email-hash test typecheck + format clean
add HMAC-SHA-256 buyer email hash helper for buyer_claims
replace deprecated ZodError.flatten() with z.flattenError()
require verified email before buyer-claims ownership gate
close IDOR gap in buyer claims: enforce owner-bound email check
remove bare pipes from Status tail (escaping insufficient)
escape bare pipes in Status tail so citadel-sdd index parses
replace manual entry with oauth button
discord-bot: hash buyer email (buyer_email -> buyer_email_hash), LP/bot parity (#3)
discord-bot: off-boarding logic, partial-refund policy, sponsor lapse detection, ResolveSKU private threads (#2)
discord-bot: gate poller on GITHUB_TOKEN; wire OnPendingCancel
discord-bot: resolve GitHub login to Discord user; grant role on created; add pending_cancellation handler
discord-bot: add GetDiscordIdentityByGitHub and GitHubLogin field
discord-bot: wire buyer + sponsor handlers and sponsor poller
discord-bot: implement OnOrderRefunded revocation handler
discord-bot: implement OnOrderPaid buyer claim handler
newsletter archive route and first issue (playbook preview)
post pages: TOC, filter bar, reading-progress bar, format layouts, RSS feed
contact page: topic selector, SKU prefill, SLA copy, JSON-LD
store preview images for time-block, master-bundle, discord-ops
multi-column HTML sitemap with blog posts and last-modified dates
404 recovery links and on-brand copy
pagefind wired into build script
legacy booking + bare legal paths 301 to canonical routes
real lastmod timestamps in sitemap
Shipped May 27
buyer-gated /power-pack/guide route with token sign/verify
polar upsell delivery: playbook + follow-up 2h + master-bundle + discord-ops
discord-ops scoping email template and delivery wired into webhook
master-bundle delivery email and Polar webhook integration
operator dashboard at /status/ops with bearer-token auth + Mailgun reader
/now page sections refactored to NOW_SECTIONS data model
Shipped May 23
Plausible instrumentation gaps filled across site
contact form Plausible events
checkout success URL appends SKU query param
Shipped May 22
harvest same-day commits and merge into existing entry
drop unused Image import after AuthorBlock adoption
adopt AuthorBlock on homepage, drop about-block links
add AuthorBlock component
list /newsletter on the human sitemap page
drop "Stay updated" newsletter link
resolve header-search lint, style, and typed-route errors
replace palette button with inline search
add header inline live-search component
add loading skeleton to error page
rate-limit webhook-stats admin GET before bearer auth
add GET health probe to /api/bookings
cap opt-in request body size
bound collaborator API fetch with 10s AbortSignal timeout
bound webhook fetch with 5s AbortSignal timeout
bound GraphQL fetch with 5s AbortSignal timeout
scoped error boundary for status page
scoped error boundary for posts/[slug]
map all error reasons
flag-gate buyer-interview endpoints to match page gating
restore focus after command palette close
persist CSP violations to Supabase csp_reports table
add csp_reports Supabase table migration
replace curly quotes with ASCII quotes; fix import order
add priceValidUntil to store JSON-LD offers; swap Product image for real art
wire preview images into StoreProductMediaStrip
migrate mediaCaptions to mediaItems with optional image shape
playbook + power-pack preview imagery via Playwright mockups
render staleness badge when /now is stale
add staleness helper checkNowStaleness
static CSP for static prerendering, drop per-request nonce
restore MailgunEventData type dropped by knip
tighten easy cast wins in unit test files
resolve biome-ignore sites in site-header, footer-trust, label
remove redundant `as unknown[]` after Array.isArray guard
cast dynamic pagefind import to local PagefindApi interface
remove plausible Window cast using existing global declaration
Shipped May 21
per-service cards + live 30s refresh
pre-push refreshes /now before letting commits land on origin
now-refresh harvests user-facing commits into RECENT_SHIPS
add RECENT_SHIPS dated log for auto-refresh
mega-menu panels span full header inner width
waitlist CTA points readers to the free Playbook Preview
mega-menu site header with top-level Posts + Playbook Preview featured
mega-menu component with sections, descriptions, featured card
drop duplicate breadcrumb in product detail body
restore CLS-safe hero skeleton in loading.tsx
keep dropdown open while traversing trigger-to-panel gap
/posts index + /posts/[slug] route with JSON-LD + OG
wire MDX rendering via next-mdx-remote
use Button wrapper for dropdown triggers + extend Link to forward role/tabIndex
consolidate header into top-level groups with hover dropdowns
drop hero skeleton from loader for faster TTI
upgrade CTA visuals and move below FAQ
wire 3-tier rail cards to real store routes
support ReactNode answers + link/code markup in items
clean site-search component (style-check comment, Muted excerpt, TS) + declare PAGEFIND_PORT
add /search route with SiteSearch client component
add pagefind build pipeline crawling SSR output
bundle savings math + real pair scarcity + h-card microformats
add route + tests + env example
verify signature + log bounce/complaint events
escape bash $ in HOOK_PRECOMMIT template literal
add violation report collector endpoint
email-gated free quick-start delivery via /api/lead-magnet
resolve main checkout via --git-common-dir in pre-commit
wrap supabase query in Promise for withTimeout + test GET request arg
include hosted invoice URL in receipt email
public uptime page at /status
expand /api/health to cover Supabase/Mailgun/Polar
subset Iosevka Extended to used codepoints
publish /feed.xml RSS feed for /now updates
preconnect to Polar checkout origin
add Person sameAs URLs to JSON-LD @graph
add OG image for now + testimonials routes
add canonicalUrl helper to strip query+fragment from canonicals
add print-friendly stylesheet for legal + general use
add carbon badge + GitHub Sponsors link
add useful suggestions to not-found page
add security.txt at /.well-known/
update humans.txt colophon
add llms.txt for assistant crawler hints
mount CheckoutCompleteTracker in (site) layout for store coverage
emit Checkout Complete on success redirect
add testimonials strip with empty-state guard
add 3-tier decision rail above offers grid
block LLM training crawlers in robots.ts
enforce anti-AI-tell denylist in check-style
import H3 typography wrapper missed by mini-FAQ commit
add mid-page objection mini-FAQ
add waitlist signup section
expand about block with /now link and post highlight
track checkout funnel signal
append completed checkouts to daily metrics log
emit checkout click events from CheckoutButton
img
add Get updates waitlist anchor link
resolve script path absolutely for worktree compatibility
add mid-page CTA between receipts and offers
link refund pill to /legal/refunds
repoint settings.json to scripts/hook-format-lint.sh
extend format-lint hook with md/sh/yaml dispatch
polarKey checkout no longer leaks config state
24h window trigger on buyer_interviews opt-in
buyer-interview opt-in 404s on unknown id
cd to main checkout before env:check
enforce Inter font prohibition
per-match line numbers for duplicate violations
remove unused node:path import
store JSON-LD seller, serviceType, areaServed compliance
areaServed uses AdministrativeArea not Place
skip-link targets main landmark not wrapper div
Shipped May 20
admin delivery replay endpoint
persist delivery outcomes on webhook
add delivery-state helper
add power_pack_deliveries delivery-state table
hero CTA microcopy from github-stats
use SITE_DESCRIPTION constant
correct TypeScript type guards in honeypot and error-report tests
error-report whitelists source field
silent-accept honeypot across contact/waitlist/buyer-interview
time-block checkout safeParse + polar SDK error handling
time-block parse() returns discriminated ok (not safeParse)
re-anchor hero scroll-hint to #offers section
contact honeypot returns silent 200
lock error-report source field to enum
time-block uses safeParse, returns 400 on bad body
set h:Sender header in mailgun envelope
add User-Agent to github-invite fetch
pull description from site-metadata
re-anchor hero scroll-hint to #offers
H1 typography wrapper accepts id prop
dynamic copyright year
keep stale cache on fetch error + emit gh_stats_fetch_error Plausible event
surface request ID in error UI for support follow-up
return request ID + structured Mailgun-failure error body
server-side request ID helper
observability on confirmed-payment-no-row failures