Skip to content

Commit 5aba6bf

Browse files
authored
v4: @pacphi/agentic-kit — npm-installable cross-platform kit (ak setup/status/sync/uninstall), shell kit removed, CI matrix + npm release (#14)
* feat!: v4 — npm-installable cross-platform ruflo-kit; shell kit removed BREAKING: install.sh/uninstall.sh/shell functions/bash bin scripts are gone. The kit is now 'npm i -g' + one Node >=22 CLI with four porcelain verbs (setup/status/sync/uninstall) and an x-plumbing namespace, per the definitive command surface. Zero runtime dependencies (node:sqlite, node:test). - src/lib: paths (XDG/%APPDATA%), exec (argv-only, .cmd shims), settings (backup-first merges), blocks (sentinel upsert/strip, CRLF-safe, user- extensible registry w/ declarative detectors in kit.json), sqlite, daemons (pidfile-first + ps/CIM sweep), versions (drift cache), mcp (family enumeration + deny rules), natives, rvf (FLVR quarantine), statusline (footer inject; template extracted verbatim from the shell heredoc), heal - commands: status (dashboard, --json/--hint), sync (plan->apply->prove, --dry-run/--no-upgrade), setup (machine+project), uninstall (incl. legacy shell-kit migration); x: daemon-gc, mcp, reference, verify, improvement-eval - docs: BACKGROUND/TROUBLESHOOTING/CONDITIONAL-BLOCKS/README archived as 2026-07-14-shell-kit-*; new short README + npm-command TROUBLESHOOTING - claude/ templates re-pointed at ruflo-kit verbs; installed CLAUDE.md blocks reconciled via 'x reference sync' - tests: 19 node:test units + statusline suite (reads the extracted template) Verified live: status caught real drift (3.29.0 release, natives regression after the aidefence install, recurring FLVR brain.rvf corruption); sync converged it; x verify learning/security green; golden parity vs the bash patch-native checker before its removal. * ci: 3-OS × Node 22/24/26 matrix, nightly live-drift lane, npm release workflow - ci.yml: unit + statusline tests (zero-dep, no install step) + a sandboxed-HOME CLI smoke (status --json shape, managed-block round-trip, uninstall --dry-run) on ubuntu/macos/windows × Node 22/24/26 - nightly.yml: installs REAL latest ruflo+agentic-qe (allow-scripts) and gates on the kit being able to heal them (sync --no-upgrade → status; x verify security/learning) — catches upstream drift like ruvnet/ruflo#2670 the day it ships - release.yml: tag-driven npm publish with provenance; NPM_TOKEN repo secret; tag↔package.json version guard; prereleases → 'next' dist-tag, releases → 'latest' (github.ref_name passed via env, no inline event interpolation) * ci: bump actions/checkout v4→v7, actions/setup-node v4→v6 (latest as of 2026-07) * ci: add Dependabot config (weekly grouped updates for github-actions + npm) * build: adopt pnpm for repo tooling (packageManager pnpm@11.13.0, action-setup v6, pnpm publish --provenance) Runtime surface deliberately stays npm: the kit heals npm-managed global ruflo/agentic-qe trees (lib/heal.mjs, paths.mjs globalRoot) — that is the target environment, and the nightly lane keeps simulating it with npm i -g. pnpm-managed-globals support is a tracked follow-up. * feat: rename to @pacphi/agentic-kit with 'ak' alias; repo → pacphi/agentic-kit - package: @pacphi/agentic-kit, bins agentic-kit + ak (AutoKitteh's 'ak' noted in README as a known PATH neighbor; full command always works) - GitHub repo renamed (old ruflo-machine-ref URLs redirect) - command references swept to 'ak …' across src/, bin help, README, TROUBLESHOOTING, claude/ templates (republished to the live CLAUDE.md); archive files stay frozen - config dir migrates ~/.config/ruflo → ~/.config/agentic-kit (read-fallback in loadKitConfig; saves land at the new path); uninstall's legacy cleanup keeps targeting the ruflo-era dir and now removes all shell-era ruflo-* bins - compat surfaces intentionally unchanged: CLAUDE.md sentinel slugs (ruflo-*), statusline ruflo-seg marker, runtime npm calls
1 parent ffe25cf commit 5aba6bf

58 files changed

Lines changed: 3473 additions & 3990 deletions

Some content is hidden

Large Commits have some content hidden by default. Use the searchbox below for content that may be hidden.

‎.github/dependabot.yml‎

Lines changed: 25 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,25 @@
1+
version: 2
2+
updates:
3+
# Keep the pinned action majors current (checkout, setup-node, …).
4+
- package-ecosystem: github-actions
5+
directory: /
6+
schedule:
7+
interval: weekly
8+
day: monday
9+
groups:
10+
actions:
11+
patterns: ['*']
12+
labels: [dependencies, ci]
13+
14+
# The kit is deliberately zero-dependency (node:sqlite, node:test) — this
15+
# watches package.json anyway so anything added later gets updates, and
16+
# engine-range advisories still surface.
17+
- package-ecosystem: npm
18+
directory: /
19+
schedule:
20+
interval: weekly
21+
day: monday
22+
groups:
23+
npm:
24+
patterns: ['*']
25+
labels: [dependencies]

‎.github/workflows/ci.yml‎

Lines changed: 47 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,47 @@
1+
name: ci
2+
3+
on:
4+
push:
5+
branches: [main, npm-kit]
6+
pull_request:
7+
workflow_dispatch:
8+
9+
jobs:
10+
test:
11+
name: test (${{ matrix.os }}, node ${{ matrix.node }})
12+
runs-on: ${{ matrix.os }}
13+
strategy:
14+
fail-fast: false
15+
matrix:
16+
os: [ubuntu-latest, macos-latest, windows-latest]
17+
node: [22, 24, 26]
18+
steps:
19+
- uses: actions/checkout@v7
20+
- uses: pnpm/action-setup@v6 # version comes from package.json packageManager
21+
- uses: actions/setup-node@v6
22+
with:
23+
node-version: ${{ matrix.node }}
24+
25+
# Zero runtime dependencies — no install step by design.
26+
- name: Unit + statusline tests
27+
run: pnpm test
28+
29+
- name: CLI smoke (sandboxed HOME)
30+
shell: bash
31+
env:
32+
# Isolate every home-relative write (kit.json, CLAUDE.md, settings).
33+
HOME: ${{ runner.temp }}/kit-home
34+
USERPROFILE: ${{ runner.temp }}\kit-home
35+
APPDATA: ${{ runner.temp }}\kit-home\AppData\Roaming
36+
run: |
37+
mkdir -p "$HOME"
38+
node bin/agentic-kit.mjs --version
39+
node bin/agentic-kit.mjs --help --all > /dev/null
40+
# status must emit valid JSON and exit deterministically even on a
41+
# machine with no ruflo installed (rows degrade to warn/fail).
42+
node bin/agentic-kit.mjs status --json > status.json || true
43+
node -e "const s=require('./status.json'); if(!Array.isArray(s.rows)||!s.overall) throw new Error('bad status JSON'); console.log('status rows:', s.rows.length, 'overall:', s.overall)"
44+
# managed-block engine round-trip against the sandbox HOME
45+
node bin/agentic-kit.mjs x reference sync
46+
node -e "const fs=require('fs'),os=require('os'),p=require('path').join(os.homedir(),'.claude','CLAUDE.md'); const t=fs.readFileSync(p,'utf8'); for (const s of ['ruflo-preamble','ruflo-reference']) if(!t.includes('<!-- BEGIN '+s+' -->')) throw new Error('missing block '+s); console.log('blocks OK')"
47+
node bin/agentic-kit.mjs uninstall --dry-run

‎.github/workflows/nightly.yml‎

Lines changed: 52 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,52 @@
1+
name: nightly-live
2+
3+
# Installs the REAL latest ruflo + agentic-qe and runs the kit's checks against
4+
# them — catches upstream drift the day it ships (e.g. the 3.28 aidefence drop,
5+
# ruvnet/ruflo#2670). Scheduled + manual only; failures here mean "upstream
6+
# changed", not "this repo broke".
7+
on:
8+
schedule:
9+
- cron: '17 6 * * *'
10+
workflow_dispatch:
11+
12+
jobs:
13+
live:
14+
name: live (${{ matrix.os }})
15+
runs-on: ${{ matrix.os }}
16+
strategy:
17+
fail-fast: false
18+
matrix:
19+
os: [ubuntu-latest, macos-latest]
20+
steps:
21+
- uses: actions/checkout@v7
22+
- uses: actions/setup-node@v6
23+
with:
24+
node-version: 22
25+
26+
# Deliberately npm, not pnpm: this simulates the kit's TARGET environment —
27+
# ruflo/agentic-qe installed via `npm i -g`, whose trees the kit heals with
28+
# npm (lib/heal.mjs). pnpm-managed globals are a separate follow-up.
29+
- name: Install latest ruflo + agentic-qe (native build scripts allowed)
30+
run: npm install -g --allow-scripts=ruflo,agentic-qe,@claude-flow/cli,better-sqlite3,hnswlib-node,agentdb,agentic-flow,argon2,onnxruntime-node,sharp,protobufjs,@google/genai,tldjs,vibium ruflo@latest agentic-qe@latest
31+
32+
- name: Kit heals a fresh install (sync --no-upgrade)
33+
env:
34+
HOME: ${{ runner.temp }}/kit-home
35+
run: |
36+
mkdir -p "$HOME"
37+
node bin/agentic-kit.mjs sync --no-upgrade || true
38+
node bin/agentic-kit.mjs status --json > status.json || true
39+
node -e "
40+
const s = require('./status.json');
41+
console.log(JSON.stringify(s, null, 2));
42+
// Upstream-drift gate: natives + security must be healable to ok.
43+
const bad = s.rows.filter(r => r.level === 'fail' && ['natives','security'].includes(r.subsystem));
44+
if (bad.length) { console.error('UPSTREAM DRIFT:', bad.map(b => b.message).join(' | ')); process.exit(1); }
45+
"
46+
47+
- name: Deep proofs against the live packages
48+
env:
49+
HOME: ${{ runner.temp }}/kit-home
50+
run: |
51+
node bin/agentic-kit.mjs x verify security
52+
node bin/agentic-kit.mjs x verify learning

‎.github/workflows/release.yml‎

Lines changed: 47 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,47 @@
1+
name: release
2+
3+
# Publishes to npm when a version tag is pushed (v4.0.0, v4.1.0-alpha.1, …).
4+
# Requires the NPM_TOKEN repository secret (npm "Automation" token: repo
5+
# Settings → Secrets and variables → Actions → New repository secret).
6+
# The tag must match package.json's version — the guard below enforces it.
7+
on:
8+
push:
9+
tags: ['v*']
10+
11+
permissions:
12+
contents: read
13+
id-token: write # npm provenance attestation
14+
15+
jobs:
16+
publish:
17+
runs-on: ubuntu-latest
18+
steps:
19+
- uses: actions/checkout@v7
20+
- uses: pnpm/action-setup@v6 # version comes from package.json packageManager
21+
- uses: actions/setup-node@v6
22+
with:
23+
node-version: 22
24+
registry-url: https://registry.npmjs.org
25+
26+
- name: Test gate
27+
run: pnpm test
28+
29+
- name: Tag ↔ package.json version guard
30+
env:
31+
REF_NAME: ${{ github.ref_name }}
32+
run: |
33+
PKG_VERSION=$(node -p "require('./package.json').version")
34+
if [ "v$PKG_VERSION" != "$REF_NAME" ]; then
35+
echo "tag $REF_NAME does not match package.json version v$PKG_VERSION" >&2
36+
exit 1
37+
fi
38+
39+
- name: Publish to npm registry (with provenance)
40+
env:
41+
NODE_AUTH_TOKEN: ${{ secrets.NPM_TOKEN }}
42+
run: |
43+
# prereleases (…-alpha.N) go to the 'next' dist-tag; releases to 'latest'
44+
case "$(node -p "require('./package.json').version")" in
45+
*-*) pnpm publish --provenance --access public --tag next --no-git-checks ;;
46+
*) pnpm publish --provenance --access public --no-git-checks ;;
47+
esac

‎.gitignore‎

Lines changed: 3 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -38,3 +38,6 @@ CLAUDE.md.pre-ruflo
3838
*.rvf.lock
3939
*.rvf.idmap.json
4040
*.rvf.manifest.json
41+
42+
# package-manager artifacts (repo is zero-dependency; lockfile IS tracked)
43+
node_modules/

0 commit comments

Comments
 (0)