Skip to content

0.3.2: gate screener clear behind --allow-destructive, pin HEY main 9dfe00f, README consistency test + badges - #13

Merged
tangentus merged 1 commit into
mainfrom
screener-clear-gate-hey-9dfe00f
Oct 9, 2026
Merged

tangentus merged 1 commit into
mainfrom
screener-clear-gate-hey-9dfe00f

Conversation

@tangentus

Copy link
Copy Markdown
Contributor

Finishes the remaining 0.3.2 work before publishing (version stays 0.3.2; its CHANGELOG entry is updated).

1. screener clear needs an explicit opt-in

On HEY main, screener clear moves everything waiting in the Screener to Trash (every sender) with no confirmation. It now goes through the same gate as --allow-send/--allow-secret:

  • DESTRUCTIVE_COMMANDS in src/policy.js. Without --allow-destructive (or HEY_AXI_ALLOW_DESTRUCTIVE=1) it is refused with exit 2 and error: destructive command blocked. HEY isn't run. The refusal says what the command would do and suggests screener list plus per-sender screener deny.
  • --allow-destructive is a hey-axi switch: it is never forwarded to HEY, and =false is refused.
  • Per-command help, examples, top-level --help, the skill and the README explain the flag. There's a CHANGELOG line and an upgrade note.
  • test/destructive-gate.test.js covers this with the fake HEY.

2. HEY coverage reference: 8bf9310 → 9dfe00f (2026-10-06)

  • src/manifest.json was regenerated with npm run manifest:main from basecamp/hey-cli at 9dfe00f (#545). Commands and flags are identical to 8bf9310; only the version and commit metadata changed.
  • README, CHANGELOG, the skill, comments and tests now name the new commit.
  • This is pinned on purpose. The newer HEY main commits are 06d51ac (#548, adds hey thread update --name, not yet approved here), 0e4feac (#542, TUI only) and 73938bb (#546, CI only). Against current main, the drift check reports exactly one surface change, + command thread update (flags: --name), so the upstream drift job is expected to fail until that command is adopted.

4. README consistency test and badges

  • test/readme.test.js checks the README's command count against the manifest and router. It also checks the HEY version, commit link, short sha and date against the manifest and coverageLabel, and checks the badges.
  • npm version and CI badges sit next to the skills.sh badge.

npm test and npm run skill:check pass locally.

…ain 9dfe00f, README consistency test and badges (0.3.2)
@tangentus
tangentus merged commit 611399d into main Oct 9, 2026
3 of 4 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant