ArkGate
4.8.25

Current

Weekly accumulate.

ArkGate 4.8.25 is on npm latest. Weekly accumulate over 4.8.24 (#342, #344–#350). No required config migration: a config that loads in 4.8.24 still loads. That is Contener · Guiar · Ordenar.

Upgrade

Install 4.8.25

npm install -D arkgate@4.8.25
npx arkgate upgrade --json
npx arkgate-check --doctor

No required config migration. No schema bump. Does not close K01 or Z09. This mother config still does not turn ArkOrder on.

Minimum version 4.8.25 for the new config fields (childSlices.arkRulesFile, pinned sliceAliases). arkgate 4.8.24 and older reject them at config load. Pin 4.8.25 in the write hook and CI first.

What shipped

Probe the rule. Name the copy. Name the orphan.

Per-slice rules file (#342)

childSlices.arkRulesFile points a slice at its own ArkRules file. Pinned sliceAliases ship with it (#341). Both need 4.8.25.

--probe-invariants

A test title that names a rule proves the test exists, not that it would fail if the rule broke. The probe copies the project, runs the covering tests, then small changes inside the symbol. Your files are never changed. Each invariant reads killed, survived, not-reached, inconclusive, or unprobeable. Not a score. --write saves .ark/invariant-probe.json.

Promotion reads the probe

A fresh survived or not-reached row blocks --promote to enforced (probe-survived). A stale, killed, inconclusive, or missing result changes nothing. Catalog id INVARIANT_PROBE_SURVIVED is advisory and never in the check. The probe runs only when you start it.

Copies across a wall

--doctor --all lists near-identical code on two sides of a slice wall, in two child slices, or in two layers (CROSS_WALL_DUPLICATE, CROSS_LAYER_DUPLICATE). Copies inside one slice are counted, never listed. Verdict and factsHash do not change. Never a score.

Files nothing imports

A governed file with no importer shows under doctor.orphanModules (ORPHAN_MODULE). Exports nothing imports by name are UNUSED_EXPORT. Both are advisory. Entry points can come from an optional .ark/entry-points.json. Compact status prints one count line at most.

Owners and trust

Optional layers[].owners and requireLayerOwners. Absence is silent; when the flag is on, doctor names the first house without an owner and the write gate denies a write into it. Optional layers[].trustBoundary (public, auth, admin, internal) is display only. Owners and trust are stripped from policyHash the way stewards are. The require flag stays in the hash. No schemaVersion bump.

Also in status

Friendly next steps. Not a fail.

  • Empty Domain while the UI holds the rules (noDomainFrontend). Silent when there is no frontend, Domain already has files, or the UI bag is too thin.
  • A domain doc in play with no states → transitions table, and a narrow statusTransitionCatalog when Domain-role code already names a closed status vocabulary.
  • Soft ADR note when --require-gates is on and the tree has no docs/adr/ or docs/decisions/ yet. Policy weaken still uses --policy-ack.
  • INVARIANT_CATALOG_EMPTY when arkRules is on, Domain has code, and invariants[] is empty. Advisory unless a domain structure rule is already enforced.

Behavior changes

Read these before you upgrade.

  • Cursor hard-write evidence now requires the host-native failClosed: true flag. A Write/StrReplace hook without it is fail-open: doctor and --require-write-hook say so and do not claim a hard block. Required CI is still the shared merge line.
  • writes-via-aggregate flags tagged-template SQL writes (UPDATE, MERGE, TRUNCATE). Comments, FOR UPDATE, and DO UPDATE SET stay silent (#344, #343).
  • --policy-base and MCP policy-delta judge an advisory → enforced promotion with the declared coverage.coverageRoots, the same way --promote does.
  • The write hook and ark-check agree on overlapping layer globs (#237). An include that matches files but classifies none is no longer a green check (ANALYSIS_COVERS_NO_FILES); the hook denies those files (CONFIG_UNCLASSIFIED_FILES).
  • Library arkgate start no longer writes Next captions when the tree has no Next (#213). Cold --doctor no longer treats a full governed list as --changed (#212). A new ark.config.json writes $schema at arkgate@4 (#211). Doctor counts a fail-closed Ark check behind unconditional needs: jobs as a merge gate.
  • brace-expansion is overridden to 5.0.12 (#350). The package no longer ships bin/lib/ark-order-invariants.mjs, bin/lib/ark-order-error.mjs, or bin/lib/stable-hash.mjs. ArkOrder invariants still ship in arkgate/order. Compact --doctor names ArkRules only when the arkRules map is on.

Honesty

What stayed the same.

No schemaVersion bump. Does not close K01 or Z09. The probe never runs from the write hook, MCP, ESLint, the GitHub Action, or --strict-merge, and it refuses to combine with them. Import rules still hold at write and at merge. Required CI is still the hard line. ArkOrder stays opt-in.

Maintainer source: CHANGELOG.md ↗