Changelog

All notable changes to Soleur.

v3.304.1 — 2026-09-26

CI reliability: the lint-orphan-test-suites mutation battery is split into two --rows halves that run on separate shard legs, bringing the test-scripts worst leg back under the ~10-minute ceiling with a committed tiling guard.

v3.304.0 — 2026-09-26

  • Added cohort-status skill: pull-based cohort checkpoint view (activation, quiet testers, decision-log capture rate) sourced from the local .soleur/decisions.jsonl
  • Added emit-decision.sh + alpha-metrics.sh: tester-owned, metadata-only local decision log (field-allowlisted, SOLEUR_DISABLE_DECISION_LOG=1 opt out) and aggregate printer
  • Added arm-checkpoint.sh: operator wrapper that arms the 14-day checkpoint and 3-day quiet reminders with dated ids
  • Fixed welcome hook: first-session onboarding now fires for marketplace installs without writing a .claude/ sentinel into the project tree
  • Changed: web-platform cohort instrumentation — users.cohort_key, Bearer-gated PATCH /api/internal/cohort, ?cohort= analytics scope, cohort-quiet scheduled check posting domain-level reports

web-v0.303.1 — 2026-09-26

Fixed: dashboard cold-load blind spots — SW-proxied navigations now classify as documents (Server-Timing/no-store restored), authenticated APIs expose middleware timings, Sentry probe-header tracing armed, and four hot routes + identity resolution skip the redundant remote getUser() RTT.

web-v0.303.0 — 2026-09-26

  • Added cohort-status skill: pull-based cohort checkpoint view (activation, quiet testers, decision-log capture rate) sourced from the local .soleur/decisions.jsonl
  • Added emit-decision.sh + alpha-metrics.sh: tester-owned, metadata-only local decision log (field-allowlisted, SOLEUR_DISABLE_DECISION_LOG=1 opt out) and aggregate printer
  • Added arm-checkpoint.sh: operator wrapper that arms the 14-day checkpoint and 3-day quiet reminders with dated ids
  • Fixed welcome hook: first-session onboarding now fires for marketplace installs without writing a .claude/ sentinel into the project tree
  • Changed: web-platform cohort instrumentation — users.cohort_key, Bearer-gated PATCH /api/internal/cohort, ?cohort= analytics scope, cohort-quiet scheduled check posting domain-level reports

web-v0.302.11 — 2026-09-26

  • fix(web): repair persisted conversation engine binding markers

web-v0.302.10 — 2026-09-26

Dashboard section loads collapse the per-request Supabase auth tax (~4 RTTs → ~1) and unblock first paint; middleware-verified identity header removes duplicated auth calls in API handlers.

v3.303.9 — 2026-09-25

CI: push-to-main runs of infra-validation, tenant-integration, vendor-pin-verify, validate-vector-config, and skill-security-scan-corpus skip when the merge tree provably equals the green PR head tree — ~34 wall-min saved per qualifying merge.

Generated with Devin

v3.303.8 — 2026-09-25

CI/devx: five single-job PR gates folded into pr-quality-guards.yml — each push queues 5 fewer workflow runs (23→18); all required-check names preserved verbatim.

Generated with Devin

v3.303.7 — 2026-09-25

fix: C4 diagram editor reloads and reconciles the stale-save banner after a Concierge edit_c4_diagram save — no more manual page reload.

Generated with Devin (https://devin.ai)

v3.303.6 — 2026-09-25

CI/devx: file-scoped PR guards now skip on proof-only diffs (~1 runner-min/push; removes a flaky third-party action from the every-push path); required checks unchanged.

Test plan

  • [x] ci-path-gating.test.sh 30/30 (new pins)
  • [x] pr-fanout-ledger.test.sh 231/231
  • [x] actionlint clean (2 pre-existing info-level shellcheck notes only)
  • [x] This PR dogfoods the self-trigger path (touches both gated workflows → detects emit all-true → gates run)

Generated with Devin

v3.303.5 — 2026-09-25

CI/devx: infra-validation and constraint-gates PR runs now cancel at enqueue when superseded (~7k truncatable wall-min/window measured); pull_request_target and deliberate cancel:false workflows documented as excluded.

Test plan

  • [x] parity.test.sh 12/12 (template ↔ apps copy ↔ repo-root byte-parity incl. comments)
  • [x] pr-fanout-ledger.test.sh 231/231 (ledger row ↔ workflow block agreement, ternary group byte-exact)
  • [x] actionlint clean on all three workflow files
  • [x] Group-key semantics verified for both events (PR→ref, push→sha — main never cancelled)

Generated with Devin

v3.303.4 — 2026-09-25

Web Platform

  • Rotated the GHCR minter's Doppler service token and documented the rename-based rotation route in the Terraform comments and runbook.

Plugin

  • Raised the preflight declared-probe baseline to 30 for this plan's credentials_required probe.

v3.303.3 — 2026-09-25

  • WIP: feat-one-shot-8736-deploy-script-tests-parallel

v3.303.2 — 2026-09-25

Web Platform

  • The C4 diagram viewer explains a diagram whose saved layout has no views, instead of showing an empty canvas, and says how to redraw it.
  • The Concierge can re-render a diagram on request without touching its content.
  • KB upload, delete, rename and the C4 project read reject path segments that could escape the knowledge base.

v3.303.1 — 2026-09-25

CI/devx: test-scripts light shard rebalanced K=6 → K=7 (worst predicted leg ~10.2 min wall; leg 5 atomic-suite floor disclosed, split tracked in #8864).

Test plan

  • [x] Shard guard suites green (totality, manifest, mutations battery both halves, aggregator diagnosis, runtime coverage)
  • [x] K=7 leg-union enumerate parity (502 = 502, 0 dups)
  • [ ] Post-merge CI run: verify worst test-scripts leg wall-clock ~10 min via gh api (appended to measurements.md)

Generated with Devin

v3.303.0 — 2026-09-25

  • lint-shell-capture-exit gains S3 (armed-command dead status read) and S4 (test && act function-tail status leak) detectors; twelve live bugs found and fixed; scanner hardened for quote/paren/segment context.

v3.302.7 — 2026-09-25

Plugin

  • The grep -q pipe guard no longer flags a logical OR followed by a herestring, catches |&, and fails loudly if its own pattern stops compiling.
  • Plan sharp edges: a check rewritten as a negated grep must still fail on grep's exit 2.

v3.302.6 — 2026-09-25

  • Archived completed planning records for the pin-redeploy gate fix and the git-data dirty-journal fix.
  • New guidance for plan authors: quote scanner counts in acceptance criteria as deltas, not absolutes.

v3.302.5 — 2026-09-25

Plugin

  • social-distribute: automated-channel variants must be fact-checked against the checked post, and tweet/Bluesky counts computed from the final text.

Content

  • New blog post "Parked or Forgotten? How to Tell Before It Costs You", its OG image, and its scheduled distribution (X thread, Discord, Bluesky, LinkedIn) for 2026-09-26.
  • Content strategy updated for the founder angle of #8548.

Web Platform infra

  • One dated-slug blog redirect row.

v3.302.4 — 2026-09-25

  • chore(archive-kb): archive #8705 web-probes token rotation KB artifacts

v3.302.3 — 2026-09-25

  • test(hooks): a hook suite that cannot run because a required tool (jq, git, perl, realpath, python3, script) is missing now exits 3 with UNRESOLVED: <tool> missing … install <tool>. It no longer reports green having asserted nothing.
  • test(hooks): new hook-suite-dep-unresolved.test.sh runs every guarded hook suite with its tool removed and fails if any reports green.
  • docs: ADR-177 and ADR-188 addenda; .claude/hooks/README.md checklist for adding a hook suite.

v3.302.2 — 2026-09-25

  • fix(release): the deploy arm no longer clean-skips a due deploy when the runs search lags. It retries, falls back to the unfiltered run list, and only clean-skips when the SHA's own diff proves nothing deployable changed; otherwise it fails loudly with release_run_missing and pages with the re-run command.
  • Error annotations inside resolve-target command substitutions now reach the log, and every skip/block annotation carries a machine-readable [skip_reason=…].
  • ADR-217 addendum; drift-alert runbook, postmerge and ship references document release_run_missing recovery.

v3.302.1 — 2026-09-25

  • Fixed test-all.sh enumerate modes (--print-affected-set, --enumerate, --enumerate-commands) spinning indefinitely when the checkout is deleted mid-run: fail-fast deleted-worktree guard, per- registration graceful deadline, and a hard wall-clock watchdog (SOLEUR_ENUM_DEADLINE_S, default 900s).
  • Fixed lint-orphan-test-suites.sh dropping the enumerate child's error output on failure — ERROR:/FATAL: lines are now relayed.

v3.302.0 — 2026-09-25

  • New soleur_scratch_session_begin scratch allocator + .soleur-owned ownership markers for producers.
  • Shared tmp classifier + scripts/soleur-tmp-purge.sh operator tool (dry-run/apply/restore/drain, ledgered quarantine).
  • tmpfs-guard.sh Reaper 3 covering /tmp and /var/tmp; session-start sweep in worktree-manager.sh; optional systemd timer.

Generated with Devin

v3.301.1 — 2026-09-25

  • content-writer: blog drafts follow the brand guide's new ### Blog channel note. Posts are written for non-technical founders and open with their problem. A deterministic jargon scan (Phase 2.4) flags backticks, code tags, --flags and visible issue numbers.
  • Brand guide: the blog now uses the General register. Technical builders are reached through HN, GitHub, Discord and the docs.

v3.301.0 — 2026-09-25

Web Platform

  • The operator is now emailed when an agent spawn dead-letters for one of six paged reasons: acknowledgment_persist_failed, anthropic_request_rejected, leader_class_disabled, leader_refused, leader_response_truncated, leader_tool_invalid. The founder copy "CTO has been notified" is now true.
  • Other dead-letter reasons are recorded as Sentry warnings with reason tags, without paging.
  • Sentry no longer receives a raw founder id from any spawn event, including the Inngest middleware's event-data extra.
  • A failed terminal failure_reason write is now reported to Sentry instead of being logged only.

Plugin

  • plan-sharp-edges.md and review/SKILL.md now require that a "never appears in the event" claim is checked against every contributor to the event, not only the call arguments.

v3.300.4 — 2026-09-25

  • Inngest bootstrap images can no longer be published or auto-pinned from a tag whose commit is not on main. The pin-bump also verifies that the image was built from that exact commit, and holds (does not auto-merge) images that carry no provenance label.
  • Recovery guidance: when a tag is refused, cut a NEW, higher version on main. Never delete or re-use the tag that main currently pins.

web-v0.302.9 — 2026-09-25

CI: push-to-main runs of infra-validation, tenant-integration, vendor-pin-verify, validate-vector-config, and skill-security-scan-corpus skip when the merge tree provably equals the green PR head tree — ~34 wall-min saved per qualifying merge.

Generated with Devin

web-v0.302.8 — 2026-09-25

  • lint-shell-capture-exit: detect dead status reads after multi-line if/while/case/group closers and leak tails in all POSIX function shapes; quote/comment/substitution parsing reworked to a carried context stack; x=pre$?-style prefix reads detected.

web-v0.302.7 — 2026-09-25

CI/devx: five single-job PR gates folded into pr-quality-guards.yml — each push queues 5 fewer workflow runs (23→18); all required-check names preserved verbatim.

Generated with Devin

View all releases on GitHub →

Frequently Asked Questions

How often is Soleur updated?

Soleur ships continuously — updates are released when ready and tagged with semantic versioning. There is no fixed release schedule. Changes range from new agents and skills to bug fixes and documentation improvements.

How do I upgrade Soleur?

Run claude plugin update soleur@soleur-marketplace, then restart Claude Code — plugin changes apply on restart, so the update is not picked up until you do. If you installed with --scope project or --scope local, pass the same scope. Check the changelog or GitHub releases page for details on what changed.

Does Soleur use semantic versioning?

Yes. Soleur follows semantic versioning — major versions for breaking changes, minor versions for new agents or skills, and patch versions for bug fixes and documentation updates. Version labels are set during PR review and applied automatically at merge.

Stay in the loop

Monthly updates about Soleur — new agents, skills, and what we're building next.