Changelog

Every release, straight from the changesets. Newest first.

v1.14.0
minor

--run no longer executes every @example block, and the install/timeout path is no longer a hang or a script runner.

  • Go polarity: examples without a // => assertion are type-checked and skipped at run time. Execution is opt-in via the assertion itself.
  • Install: --ignore-scripts on npm/pnpm/yarn/bun, plus trustedDependencies: [] in the harness package.json so Bun's default-trusted list cannot run lifecycle scripts. Local packages are staged with scripts stripped first — npm still runs the target's prepare while packing a directory, even with --ignore-scripts. Failed installs are not retried with scripts enabled.
  • Timeout: examples spawn detached; the process group is SIGKILL'd on timeout; the promise resolves on 'exit' (with a hard deadline) so a pipe-holding grandchild cannot stall --run.
  • Untrusted packages (outside the local workspace, or --untrusted): macOS sandbox-exec denies network and credential paths; node --permission sits underneath as defense in depth. Other platforms refuse rather than run unsandboxed. Own-package / CI is unsandboxed so real SDK examples can still call APIs.
  • Env allowlist (PATH, HOME, TMPDIR, LANG) on install and example spawns.
  • --yes or examples.run in config is required for --run when not a TTY.
  • Docs: --run no longer claims to execute "in a sandbox." The warning now says it installs the package.
v1.13.0
minor

Bump @openpkg-ts/sdk to ^0.51.0 and @openpkg-ts/spec to ^0.50.0, up from ^0.43.0.

No drift API changes, but extracted specs change: x-ts-type property coverage, x-ts-declared, inlineTags, typeParameters, JSON Schema 2020-12 output, and the declaration-keyed resolveTypeId collision fix all come through from the extractor.

v1.12.2
patch

drift scan --docs-map now runs standalone in docs-only repos: when every page in the map carries its own spec (or entry), no package entry point is required — previously scan exited 2 with "Could not detect entry point" in repos with no TypeScript package (the exact shape of a docs site gating SDK pages against committed specs). In standalone mode the output contains only docsCoverage; package coverage/lint/health are omitted.

Also: --annotations now emits workspace-relative file= paths (GitHub only anchors annotations to the Files Changed view for relative paths), and the SDK key-coverage analysis accepts types-only specs (no exports array) without crashing.

v1.12.1
patch

Fix version resolution in the published bundle: meta.version reported 0.0.0 from dist (and fed the spec-cache key, neutering version-based invalidation). Name-checked lookup now works from both src and dist layouts.

v1.12.0
minor

Docs-page key-coverage mode: diff a spec type's option keys against what a docs page actually documents

  • SDK analysis/key-coverage: extractDocumentedKeys (table keys — plain/linked/dotted/<br/>-embedded — with heading-scoped sections) + computeKeyCoverage (gaps/ghosts/inversions). Ghosts resolve against ALL spec types (sub-config tables aren't false ghosts); inversion replacements auto-derive from @deprecated Use X instead metadata.
  • CLI drift scan --docs-map <file>: key-coverage gate — FAIL any ghost, FAIL gaps above the committed baselineGaps ratchet, WARN inversions. --annotations on scan emits GitHub Actions ::error/::warning. JSON Schema ships at @driftdev/cli/schemas/drift.docs-map.schema.json.
  • CLI drift docs-map stub (deterministic scaffold: pages ↔ types ranked by key overlap) and drift docs-map baseline (ratchet tightening — never raises).
  • Prose-drift false-positive fix: member calls on receivers provably bound to non-package types (external-derived like const app = express(), untyped callback params like res) are no longer flagged; params annotated with a package type are still validated.
  • Spec cache keys now include the CLI version — an upgraded extractor never serves stale specs.
  • New skill drift-docs-map (agent bootstraps the map, human commits, machine runs it).