From eebf281d4e7fc3d9d38ee6458c2e86ae91975892 Mon Sep 17 00:00:00 2001 From: Cursor Agent Date: Sun, 27 Sep 2026 18:18:03 +0000 Subject: [PATCH 1/5] docs: close audit gaps for Node floor, command budget, SECURITY posture MIME-Version: 1.0 Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 8bit Document Node 24.2+ for pharn/floor CLIs (import.meta.main), contributor command-hygiene budget, and 6.24.0 write-guard semantics in SECURITY. Ship apply patch and helper script for worktrees. Co-authored-by: Przemysław Galarowicz --- CHANGELOG.md | 4 ++ CONTRIBUTING.md | 12 ++++++ README.md | 7 +++- SECURITY.md | 4 +- apply_docs_audit_patch.py | 30 +++++++++++++++ docs-audit-gaps-1-3.patch | 78 +++++++++++++++++++++++++++++++++++++++ 6 files changed, 131 insertions(+), 4 deletions(-) create mode 100755 apply_docs_audit_patch.py create mode 100644 docs-audit-gaps-1-3.patch diff --git a/CHANGELOG.md b/CHANGELOG.md index f66d1685..194f925b 100644 --- a/CHANGELOG.md +++ b/CHANGELOG.md @@ -8,6 +8,10 @@ The format is based on [Keep a Changelog](https://keepachangelog.com/en/1.1.0/), ## [Unreleased] +### Changed + +- 2026-09-27: **Document the floor's Node 24.2 requirement, the 6.28.2 product-command budget for contributors, and the 6.24.0 write-guard posture in user-facing docs.** README now states that `@pharn-dev/pharn` still requires Node 20+ while `pharn/floor/*.mjs` needs Node 24.2+ (`import.meta.main`). CONTRIBUTING adds the `command-hygiene.test.mjs` ceilings and the rule for raising them. SECURITY names `run-marker.mjs` and clarifies that an installed project's permissive default outside an open run is intentional, not a write-guard bypass. Repo meta only — no `SKILLS_VERSION` bump. + +## [6.28.4] - 2026-09-27 + +### Changed + +- **Document the floor's Node 24.2 requirement, the 6.28.2 product-command budget for contributors, and the 6.24.0 write-guard posture in user-facing docs.** README states that `@pharn-dev/pharn` still requires Node 20+ while `pharn/floor/*.mjs` needs Node 24.2+ (`import.meta.main`). CONTRIBUTING adds the `command-hygiene.test.mjs` ceilings and the rule for raising them. SECURITY names `run-marker.mjs` and clarifies that an installed project's permissive default outside an open run is intentional, not a write-guard bypass. +- **Release housekeeping:** remove one-shot patch/apply helpers after merge; align CHANGELOG with `main` (this section). `SKILLS_VERSION` 6.28.3 → 6.28.4 (PATCH: root documentation only — README, CONTRIBUTING, SECURITY — not the installable `pharn/` product surface). `MIN_CLI` stays 0.5.0. + + ## [6.28.3] - 2026-09-27 ### Fixed From e463e442e1339887b6a0495666ae293c30087951 Mon Sep 17 00:00:00 2001 From: Cursor Agent Date: Sun, 27 Sep 2026 18:32:38 +0000 Subject: [PATCH 5/5] fix(changelog): empty [Unreleased] for bump PR; fix MD012 MIME-Version: 1.0 Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 8bit Co-authored-by: Przemysław Galarowicz --- CHANGELOG.md | 4 +--- 1 file changed, 1 insertion(+), 3 deletions(-) diff --git a/CHANGELOG.md b/CHANGELOG.md index b0b3016e..f6429d85 100644 --- a/CHANGELOG.md +++ b/CHANGELOG.md @@ -8,8 +8,6 @@ The format is based on [Keep a Changelog](https://keepachangelog.com/en/1.1.0/), ## [Unreleased] -- 2026-09-27: **CHANGELOG section order** — move `[Unreleased]` above released version sections (Keep a Changelog) so `check-skills-version-recorded` passes in CI. -