* fix(rules): continue --no-course-rules when markers need repair
Malformed, duplicate, or out-of-order sentinels still fail-close on a
default rules write, but opt-out no longer aborts the whole lesson.
Default get now returns a rules_markers_need_repair envelope instead of
a stack dump.
* chore(release): prepare v1.23.1
---------
Co-authored-by: Claude <noreply@anthropic.com>
* docs: add corporate network allowlist for security/sysadmin teams
Polish sysadmin spec plus a machine-readable host list and a source-scan
test so new CLI destinations cannot land undocumented.
* chore(release): prepare v1.23.1
* docs: rewrite corporate allowlist in sysadmin language (PL+EN)
Plain host/port/protocol tables, matching English document, and an
allowlist test that covers both language files.
* docs: drop localhost from the corporate network allowlist
Public DNS names only; the source scan skips IP literals and
single-label hosts so local-dev URLs stay out of the sysadmin spec.
---------
Co-authored-by: Claude <noreply@anthropic.com>
Register a `kiro` profile that writes artifacts under `.kiro/` (skills,
prompts, config templates) and co-owns the root `AGENTS.md` for course
rules alongside codex, devin-desktop and generic. Content is delivered in
the generic variant because the delivery API exposes no `kiro` transform
yet.
Auto-detection reports Kiro from `.kiro/.10x-cli-manifest.json`,
`.kiro/steering/`, `.kiro/specs/`, `.kiro/hooks/`, `.kiro/settings/` or a
bare `.kiro/` directory. Every branch is `strong`: the directory name is
Kiro-specific with no plausible false positive, so a Kiro workspace never
loses the `AGENTS.md` confidence tie to codex and `PROFILE_ORDER` needs no
reshuffle. The profile takes its place in the resolution order ahead of
generic.
Extend `--tool` help text for `get` and `sync`, document the new paths,
the `.kiro/config-templates/` staging caveat and the exact limits of
`AGENTS.md` co-ownership (byte-identical rules only, so `kiro` pairs with
generic but reports `incompatible_shared_owner` next to codex or
devin-desktop) in the platform support reference and README, and cover the
profile in the detection, profile, tool-switch, writer and install-contract
test suites — including the divergent-content case that must fail closed.
The bundled `skills/10x-cli-guide/SKILL.md` is deliberately left unchanged:
`helpers install` is create-only and exits 1 on a byte difference, so a
documentation-only edit there would break every existing install.
The bootstrap decides the depth (`baseRepoClone.depth`: 1 = HEAD only,
null = full history); this side only executes it. `--deep` on
`bench-kit init` sends `deepClone: true` in the request.
`--depth` is silently ignored for a local path, so a shallow clone goes
through a `file://` URL: that gives up object hardlinking, which is the
point — one commit's objects instead of the whole history. Origin is
re-pointed at the registered remote as before, so `git fetch
--unshallow` in the clone adds the history later.
Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
* feat(skills): guide CLI setup, named downloads and updates
* fix(skills): bound npm inventory checks on cold Windows runners
* fix(skills): align launch guide with 10xCards PRD journey
* fix(tests): make helper checks portable on Windows
* test(helpers): trace Windows npm pack startup
* fix(helpers): allow bounded Windows npm startup time
* fix(helpers): use released lesson-scoped skill filters
Correct setup/guide examples and sync ownership to match CLI 1.21.
Exercise the documented preview/write commands through CAC and the
real partial writer, preserving all three trees and the PRD schema.
Refs: https://github.com/przeprogramowani/10x-cli/pull/41
---------
Co-authored-by: Claude <noreply@anthropic.com>
* docs(10xdevs4-cli-access): record membership gates and bootstrap context (p1)
Add canonical access plan, accepted decisions and supporting context.
Record phase 1 verification, Toolkit revision and remaining evidence gaps.
* docs(10xdevs4-cli-access): record course access gates and scoped review (p2)
Update canonical Progress, change status, evidence and implementation review.
Record Toolkit revisions, inherited typecheck limitation and phase 3 prerequisites.
* docs(10xdevs4-cli-access): persist reviewed revisions and phase 3 boundary
Record final reviewed Toolkit and CLI context revisions.
Persist Progress attribution and unresolved W04/W05/W08 prerequisites.
Keep phases 3–6, phase 7 and Manual criteria open.
* docs(10xdevs4-cli-access): record squash-safe source prerequisite
Record PR #30, verified gates, permanent-pin lessons and the remaining merge dependency.
Keep phase 3 and all manual rollout criteria pending.
* docs(10xdevs4-cli-access): record source prerequisite review
Record independent review of PR #30 and verified CI evidence.
Keep the master pin and delivery phase completion pending.
* docs(10xdevs4-cli-access): distinguish candidate checks from final master pins
Record passing pre-merge v4 checks and defer workflow suspension.
Keep the final v3 maintenance pin dependent on the resulting master SHA.
* feat: prepare v4 course delivery and protected project sync
Capture the reviewed implementation and manual rehearsal for draft PR review. Master source prerequisites, full clean verification and coordinated Windows CI remain open; production rollout is separate.
* fix: keep paid CI evidence private and converge cumulative sync
* docs: record merged source prerequisite and passing clean gate
* fix: preserve generated API type line endings on Windows
---------
Co-authored-by: Claude <noreply@anthropic.com>
The bench-kit command is feature-complete (zone-aware update, agent-tool
profiles, safe init defaults shipped in v1.17.0), so the experimental
opt-in has served its purpose. The command now registers unconditionally,
shows up in --help, and is documented in the README; the gating module
and its error envelope (experimental_locked) are removed.
Co-authored-by: Claude Fable 5 <noreply@anthropic.com>
Writes skills to .gemini/skills/<name>/SKILL.md (native Gemini path),
prompts to .gemini/prompts/<name>.md, configs to .gemini/config-templates/,
and rules to GEMINI.md. Auto-detection picks up GEMINI.md (strong),
.gemini/.10x-cli-manifest.json (strong), or a bare .gemini/ (medium).
Also fixes drift in the --tool help string and README tables where
windsurf was missing; regenerates api-types after API picked up both
gemini and windsurf in SUPPORTED_TOOLS.
Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
* feat: add 10x-cli-setup skill for README-driven CLI configuration
Add a skill that fetches the latest README from GitHub and walks users
through installing, authenticating, and configuring 10x-cli. Include
skills/ directory in npm package files.
Co-Authored-By: Claude Opus 4.6 (1M context) <noreply@anthropic.com>
* docs: add Agentic Installation section to README
Document how to install the 10x-cli-setup skill via skills.sh,
enabling AI agents to handle CLI setup automatically.
Co-Authored-By: Claude Opus 4.6 (1M context) <noreply@anthropic.com>
---------
Co-authored-by: Claude Opus 4.6 (1M context) <noreply@anthropic.com>
Add three new flags to the `get` command:
- `--print` outputs artifact content to stdout instead of writing files
- `--type` filters by artifact type (skills, prompts, rules, configs)
- `--name` filters by artifact name (requires --type)
`--type`/`--name` work both with `--print` (stdout) and without (filtered
disk writes). The writer's new `partial` mode skips cleanup and manifest
updates so filtered writes never delete previously written artifacts.
Also adds `fetchArtifact()` for the /api/artifacts endpoint with full
Ed25519 signature verification, matching the existing `fetchLesson()` pattern.
Updates README with full command reference, multi-tool docs, and usage
examples. Adds repository/homepage/bugs to package.json so npm links
back to the GitHub repo.
Co-Authored-By: Claude Opus 4.6 (1M context) <noreply@anthropic.com>
- Auto-version from conventional commits (auto-version.mjs) with git-diff
gate: only releases when src/ or package.json actually changed
- 5-platform binary builds (linux x64/arm64, macOS x64/arm64, windows)
- npm publish with auth token wiring
- GitHub Release with auto-generated notes and binary attachments
- Smoke tests for package tarball and auto-version script
- Hardened: top-level permissions: {}, env bindings (no expression injection),
persist-credentials only where needed for git push
Co-Authored-By: Claude Opus 4.6 (1M context) <noreply@anthropic.com>