Skip to content

chore: release v2.0.6 - #602

Merged
hotlong merged 2 commits into
mainfrom
copilot/release-new-version-c79bf035-4040-4bdd-9204-dd1cfbd41bf9
Feb 11, 2026
Merged

hotlong merged 2 commits into
mainfrom
copilot/release-new-version-c79bf035-4040-4bdd-9204-dd1cfbd41bf9

Conversation

Copilot AI commented Feb 11, 2026 •

Copy link
Copy Markdown
Contributor

Patch release bumping all packages from 2.0.5 → 2.0.6 via changesets.

  • All 20 packages in the fixed versioning group bumped together
  • Per-package CHANGELOG.md entries auto-generated
  • Main CHANGELOG.md updated with [2.0.6] - 2026-02-11
  • Example packages received internal dependency version bumps

💬 We'd love your input! Share your thoughts on Copilot coding agent in our 2 minute survey.

@vercel

vercel Bot commented Feb 11, 2026 •

Copy link
Copy Markdown

The latest updates on your projects. Learn more about Vercel for GitHub.

Project Deployment Actions Updated (UTC)
objectstack-play Ready Ready Preview, Comment Feb 11, 2026 4:41am
spec Error Error Feb 11, 2026 4:41am

Request Review

Co-authored-by: hotlong <50353452+hotlong@users.noreply.github.com>
Copilot AI changed the title [WIP] Release a new version for changeset chore: release v2.0.6 Feb 11, 2026
Copilot AI requested a review from hotlong February 11, 2026 03:25
@hotlong
hotlong marked this pull request as ready for review February 11, 2026 03:34
Copilot AI review requested due to automatic review settings February 11, 2026 03:34
@hotlong
hotlong merged commit 08df653 into main Feb 11, 2026
1 of 3 checks passed

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull request overview

This is a routine patch release coordinated via changesets, bumping all 20 packages in the fixed versioning group from 2.0.5 to 2.0.6. The release follows the established changeset workflow with automated CHANGELOG generation.

Changes:

  • All 20 @objectstack/* packages in the fixed versioning group bumped to 2.0.6
  • Per-package CHANGELOG.md files auto-generated with dependency updates
  • Main CHANGELOG.md updated with [2.0.6] - 2026-02-11 entry
  • Example packages independently versioned (patch bumps for their internal dependency updates)

Reviewed changes

Copilot reviewed 53 out of 53 changed files in this pull request and generated no comments.

Show a summary per file
File Description
packages/spec/package.json Version bump to 2.0.6 (protocol specification package)
packages/spec/CHANGELOG.md Added 2.0.6 release entry
packages/types/package.json Version bump to 2.0.6 (shared TypeScript types)
packages/types/CHANGELOG.md Added 2.0.6 release entry with spec dependency update
packages/core/package.json Version bump to 2.0.6 (microkernel core)
packages/core/CHANGELOG.md Added 2.0.6 release entry with spec dependency update
packages/client/package.json Version bump to 2.0.6 (client SDK)
packages/client/CHANGELOG.md Added 2.0.6 release entry with spec/core dependency updates
packages/client-react/package.json Version bump to 2.0.6 (React hooks)
packages/client-react/CHANGELOG.md Added 2.0.6 release entry with spec/core/client dependency updates
packages/cli/package.json Version bump to 2.0.6 (command line interface)
packages/cli/CHANGELOG.md Added 2.0.6 release entry with multiple dependency updates
packages/metadata/package.json Version bump to 2.0.6 (metadata service)
packages/metadata/CHANGELOG.md Added 2.0.6 release entry with spec/core/types dependency updates
packages/objectql/package.json Version bump to 2.0.6 (ObjectQL engine)
packages/objectql/CHANGELOG.md Added 2.0.6 release entry with spec/core/types dependency updates
packages/runtime/package.json Version bump to 2.0.6 (core runtime)
packages/runtime/CHANGELOG.md Added 2.0.6 release entry with spec/core/types/rest dependency updates
packages/rest/package.json Version bump to 2.0.6 (REST API server)
packages/rest/CHANGELOG.md Added 2.0.6 release entry with spec/core dependency updates
packages/plugins/plugin-auth/package.json Version bump to 2.0.6 (authentication plugin)
packages/plugins/plugin-auth/CHANGELOG.md Added 2.0.6 release entry with spec/core dependency updates
packages/plugins/plugin-security/package.json Version bump to 2.0.6 (security plugin)
packages/plugins/plugin-security/CHANGELOG.md Added 2.0.6 release entry with spec/core dependency updates
packages/plugins/plugin-msw/package.json Version bump to 2.0.6 (MSW plugin)
packages/plugins/plugin-msw/CHANGELOG.md Added 2.0.6 release entry with multiple dependency updates
packages/plugins/plugin-hono-server/package.json Version bump to 2.0.6 (Hono server adapter)
packages/plugins/plugin-hono-server/CHANGELOG.md Added 2.0.6 release entry with spec/core dependency updates
packages/plugins/driver-memory/package.json Version bump to 2.0.6 (in-memory driver)
packages/plugins/driver-memory/CHANGELOG.md Added 2.0.6 release entry with spec/core dependency updates
packages/adapters/hono/package.json Version bump to 2.0.6 (Hono adapter)
packages/adapters/hono/CHANGELOG.md Added 2.0.6 release entry with runtime dependency update
packages/adapters/nestjs/package.json Version bump to 2.0.6 (NestJS adapter)
packages/adapters/nestjs/CHANGELOG.md Added 2.0.6 release entry with runtime dependency update
packages/adapters/nextjs/package.json Version bump to 2.0.6 (Next.js adapter)
packages/adapters/nextjs/CHANGELOG.md Added 2.0.6 release entry with runtime dependency update
apps/studio/package.json Version bump to 2.0.6 (admin interface)
apps/studio/CHANGELOG.md Added 2.0.6 release entry with multiple dependency updates
apps/docs/package.json Version bump to 2.0.6 (documentation site)
apps/docs/CHANGELOG.md Added 2.0.6 release entry
examples/plugin-bi/package.json Independent version bump to 1.2.7
examples/plugin-bi/CHANGELOG.md Added 1.2.7 entry with spec dependency update
examples/minimal-auth/package.json Independent version bump to 1.0.3
examples/minimal-auth/CHANGELOG.md Added 1.0.3 entry with multiple dependency updates
examples/metadata-objectql/package.json Independent version bump to 0.1.3
examples/metadata-objectql/CHANGELOG.md Added 0.1.3 entry with multiple dependency updates
examples/app-todo/package.json Independent version bump to 1.2.7
examples/app-todo/CHANGELOG.md Added 1.2.7 entry with multiple dependency updates
examples/app-host/package.json Independent version bump to 1.2.7
examples/app-host/CHANGELOG.md Added 1.2.7 entry with multiple dependency updates
examples/app-crm/package.json Independent version bump to 1.2.7
examples/app-crm/CHANGELOG.md Added 1.2.7 entry with spec dependency update
CHANGELOG.md Added [2.0.6] - 2026-02-11 entry and updated unreleased comparison link

akarma-synetal pushed a commit to akarma-synetal/framework that referenced this pull request Oct 7, 2026
…ts that decided them (objectstack-ai#20737)

Part of objectstack-ai#20596
Clause-②: no

## What changed

This is the ninth stage of the `domain:services` lane of the
dead-citation sweep. It covers `packages/plugins/plugin-audit/src/**`
and nothing else. By the seat's census at the claim (`5900808881`), it
is the largest package in the lane that no in-flight work holds. Later
stages cover the other packages, so this PR says `Part of` and the card
stays open.

Every comment or docblock site in scope that cited a tracker number
answering 404 has been rewritten in ruling C+D's form C (comment
5749154545 on objectstack-ai#19123), by the method of stages 1 to 8 (PR objectstack-ai#20609 as
`422db788a`, PR objectstack-ai#20626 as `b80ab579d`, PR objectstack-ai#20634 as `4d04b6be3`, PR
objectstack-ai#20658 as `9a4b2bb38`, PR objectstack-ai#20693 as `0e9ad74fb`, PR objectstack-ai#20708 as
`9b384f63a`, PR objectstack-ai#20717 as `cbaf04c1f`, PR objectstack-ai#20729 as `d2820876f`). That
is **56 sites on 55 lines in 16 files, covering 16 numbers**:

- 23 census sites (every census site this package has);
- 32 sites in test comments, which the census defers;
- 1 site the gate's grammar cannot see: the slash-joined second number
in `objectstack-ai#9719/objectstack-ai#9798` (`comment-access-hooks.ts:35`).

Each rewritten line now cites the commit in `origin/main` history that
decided what the line describes, and says in its own words what was
decided: **15 distinct shas**. No number in this package has an ADR or
ruling record of its own in the repository (a grep of `docs/adr/` for
all 16 finds none; the rest of `docs/` cites `objectstack-ai#11507` and `objectstack-ai#11374` only
as evidence, in an audit table and a QA checklist), so every anchor is a
commit, per ruling C's order. No number was dropped.

Only comments changed. Every touched source file keeps its line count
(56 lines out, 56 in, over 16 files), so no line citation into these
files moves. 1 of those 56 lines holds no dead citation: it is a reflow
line, listed under Wordings below. No code token moves (see the guard
below).

**No citation number is added.** Every tracker number on an added line
was already on the line it replaces: `objectstack-ai#10101` (3 lines), `objectstack-ai#8287` (3),
`objectstack-ai#5928` (2), `objectstack-ai#9974` (2), `objectstack-ai#4630` (2), and `objectstack-ai#8144`, `objectstack-ai#9719`, `objectstack-ai#12069`
and `objectstack-ai#19054` once each. Each resolves. Over the whole diff, added minus
removed is 0 for every number, and no number is new to the diff. No PR
number is the citation on an added line: the two `PR #N` spellings in
scope became their pull request's squash commit.

23 dead sites are left on purpose, all of them string literals (see the
list below).

One more file: a `patch` changeset for `@objectstack/plugin-audit`,
because some of the rewritten docblocks and inline comments ship (see
Changeset below).

## Census: `plugin-audit`, before and after

**Instrument (A1).** The gate's own `node
scripts/check-issue-citations.mjs --census --json`, read-only and
unchanged. The count below is its `allocated-but-absent` findings under
`packages/plugins/plugin-audit/`. Each run counts as a reading only
because its board frontier equals the newest issue number, read by a
separate request just before and just after the run.

| reading | tree | board | whole-repo `allocated-but-absent` |
plugin-audit sites | lines | files | numbers |
|---|---|---|---|---|---|---|---|
| before | base `d2820876f`, run 2026-09-29T23:11:55Z to 23:15:11Z |
enumerated, 186 pages, frontier objectstack-ai#20735 (newest objectstack-ai#20735 before and after),
18,562 numbers | 1,110 | **23** | 22 | 6 | 12 |
| after | head `a9a4ea478`, run 23:26:11Z to 23:29:20Z | enumerated, 186
pages, frontier objectstack-ai#20735 (newest objectstack-ai#20735 before and after), 18,562 numbers
| 1,087 | **0** | 0 | 0 | 0 |

The before count matches the seat's census at the claim and A1 (23
sites). The whole-repo drop is 23, exactly this diff's census sites. The
`resolves` tally is 32,995 in both runs, and `resolves-as-pull-request`
(1,984) and `cross-repo-unjudged` (995) did not move either. The after
run was taken on `a9a4ea478`; the head `d6e67afa5` adds only the
changeset. No run was truncated or discarded: both enumerations read 186
pages at the newest frontier.

**Supplementary instrument, the whole scope.** The census does not read
test files or strings, and this stage's scope includes test comments. So
a second reading runs the gate's own exported `extractCitations`
(whole-file and comment-prose projections) and `namesThisRepository`
over every `.ts` file under `plugin-audit/src` (45 files). It takes its
verdicts from the before census's own board reading rather than from a
second enumeration: a number is dead when that census reported it
`allocated-but-absent`, and alive when that census judged it on this
board anywhere (its `--list` extraction, 37,084 citations over 2,613
files) and did not report it. The 10 numbers the census never saw,
because they stand only in test files or strings here, were read one by
one on the issues endpoint: 7 answer 200 (`objectstack-ai#602`, `objectstack-ai#1532`, `objectstack-ai#4186`,
`objectstack-ai#7291`, `objectstack-ai#7333`, `objectstack-ai#16312`, `objectstack-ai#20494`), and `objectstack-ai#8852`, `objectstack-ai#12143` and
`objectstack-ai#12147` answer 404, on the pulls endpoint too.

| reading | citations | dead | src comment | test comment | src string |
test string |
|---|---|---|---|---|---|---|
| before, `d2820876f` | 655 | **77** | 23 | 32 | 5 | 17 |
| after, `a9a4ea478` | 600 | **22** | 0 | 0 | 5 | 17 |

Its src-comment column equals the census's 23, which is the control on
the second instrument. The 572 live citations and the 6 cross-repo
citations are the same in both readings, and the drop of 55 citations is
exactly the rewritten sites the gate's grammar sees. A third, raw
reading (every `#` followed by 2 to 6 digits, whatever surrounds it)
finds 672 occurrences and 79 dead before, 616 and 23 after. Beyond the
gate's grammar it sees 2 dead sites before (the `objectstack-ai#9719/objectstack-ai#9798` comment,
rewritten, and the `[objectstack-ai#8203/objectstack-ai#11507]` test title, left) and 1 after (that
title). Its only unjudged tokens are `objectui#10520`, `cloud#340`,
`cloud#1395` and the decision-batch ordinal `objectstack-ai#153`.

## Per-number table

Sites and files count every dead occurrence in scope at the base
(comments and strings, tests included). `rewritten / left` counts the
sites rewritten and the sites left. Each anchor was read in its message
and diff, not only its subject, and `git blame` at the base puts every
rewritten line in its anchor commit or in a later commit that descends
from it (`merge-base --is-ancestor` exit 0 for all 56 line and anchor
pairs).

| number | sites / files | rewritten / left | anchor: what it decided |
|---|---|---|---|
| `objectstack-ai#11507` | 26/8 | 10/16 | `88b9d749a`: `sys_activity.type` is declared
an open, author-extensible vocabulary whose options are the built-in
set, per the maintainer ruling of 2026-08-24, direction 4. Its body
names `objectstack-ai#11507` twice. The spec stages' anchor |
| `objectstack-ai#8707` | 12/2 | 9/3 | `1408fe385`: an audit row is stamped from the
record's own organization, not the actor's, applying the maintainer's
ruling on `objectstack-ai#8287`; the precedence flips to `recordOrgId ??
sess.tenantId`, and the organization column is resolved from the schema
(`resolveRecordOrganizationField`, first written in this file). Its
subject names it. Stage 7's anchor |
| `objectstack-ai#9798` | 8/2 | 7/1 | `c7655d472` (PR objectstack-ai#9993): the `sys_comment`
access-hook registration declares the whole-operation dispatch `objectstack-ai#9719`
built, so the `objectstack-ai#4630` unscoped multi-delete refusal reaches the handler
through the wired engine; the update half is split out. Its body ends
with the closing line for `objectstack-ai#9798`. The `lint` stage's anchor |
| `objectstack-ai#16829` | 7/3 | 6/1 | `8d4690b8f`: the read-audit ledger write
declares `preserveAudit`, so a record-view row keeps the VIEW instant;
`isSystem` is kept for the readonly strip, and the new integration pin
runs the real stamp hook. Its body ends with the closing line for
`objectstack-ai#16829`. New to the sweep |
| `objectstack-ai#6575` | 4/2 | 4/0 | `69787f07b`: the hook registration surface gains
`excludeObjects` ("global except these objects"), refusing `'*'` and
blank members on it. The squash commit of the pull request that was
`objectstack-ai#6575` (404 on the pulls endpoint too); `objectstack-ai#5928`, the card it answers,
stays beside it. New to the sweep |
| `objectstack-ai#11374` | 4/3 | 3/1 | `f64668d3c`, the squash commit of `objectstack-ai#12143`, for
the two object comments: sourced bounds on the keyed text columns
`sys_activity.record_id` and `sys_audit_log.record_id` (255, the
physical `id` column), route A. `3954fb7df`, for the test's statement of
the rule: the route A ruling that keyed identity columns declare a
sourced `maxLength`; its subject names `objectstack-ai#11374 route A`. Both are stage
4's anchors for the sibling lines in `plugin-security` |
| `objectstack-ai#10091` | 3/3 | 3/0 | `da891e0ef` (PR objectstack-ai#10169): `sys_attachment`'s
`beforeUpdate` gate, uploader or parent editor, with the attach rule on
the NEW parent when a row is re-pointed. Its body names `objectstack-ai#10091`. Stage
6's anchor |
| `objectstack-ai#14927` | 3/2 | 3/0 | `ab489388b` (PR objectstack-ai#17450): a lost audit row is
reported once per cause, keyed on the error `code`, and the datasource
remedy prints only for the missing-table cause; its message records that
the measured `ERR_SYSTEM_WRITE_ORGANIZATION_REQUIRED` refusal had sent
its operator to a working datasource. It names `objectstack-ai#14927` in its diff only
(the 3 lines it wrote). New to the sweep |
| `objectstack-ai#8778` | 3/1 | 2/1 | `7901b2dd2` (PR objectstack-ai#8905): the stamp-only
`tenancy.organizationField`, option A per the maintainer ruling on
`objectstack-ai#8778`. Its subject names it. The anchor of stages 4, 6 and 7 |
| `objectstack-ai#6523` | 2/2 | 2/0 | `aa4b90d9a` (PR objectstack-ai#7068): enforcement contracts
take the full `ExecutionContext`. Its subject names `objectstack-ai#6523` |
| `objectstack-ai#6206` | 2/2 | 2/0 | `aa4b90d9a`: the same commit, whose body applies
"the objectstack-ai#6206 ruling default (converge on the full envelope, keep no
per-site subset contracts)", written as the full-envelope ruling, the
form of stages 2, 6 and 7 |
| `objectstack-ai#8852` | 1/1 | 1/0 | `51bb277ef`: the `sys_activity.type` writer
census; its message records the objectui mirror as unguarded in both
directions, filed as `objectstack-ai#8852`, and not asserted here because this package
cannot import objectui. The commit that wrote the line. New to the sweep
|
| `objectstack-ai#11674` | 1/1 | 1/0 | `1cba33f16` (PR objectstack-ai#11961): the load-time warning
and the ordering constraint documented at the four pointer-pair sites.
Its subject names it; blame puts the line in it. Stage 7's anchor |
| `objectstack-ai#12147` | 1/1 | 1/0 | `945e91a13`: the class-level keyed-text-bounds
gate over every `*.object.ts`, retiring the per-package rule this file
carried. It names `objectstack-ai#12147` in its diff only. Stage 4's anchor for the
sibling file |
| `objectstack-ai#12143` | 1/1 | 1/0 | `f64668d3c`: the squash commit of the pull
request that was `objectstack-ai#12143` (404 on both endpoints), where the
dependency-graph measurement was made. Stage 4's anchor |
| `objectstack-ai#11671` | 1/1 | 1/0 | `09b4f4e4e` (PR objectstack-ai#12557): records which source
revision a generated translation leaf was filled from. The anchor the
identical `translations/index.ts` line already carries in five packages
on `main` |

Every cited sha matches exactly one commit (`git rev-parse
--disambiguate`, count 1 for each of the 15), and every one is an
ancestor of the base (`merge-base --is-ancestor`, exit 0 for all 15;
control leg: stage 1's landing `422db788a` exit 0; the history is
complete, `--is-shallow-repository` false, 15,143 commits). Each of the
16 numbers answers 404 on the issues endpoint.

## Wordings to check

- **Bracket tags.** `[#N]` became `[commit SHA]`; `[#N route A]` became
`[commit f64668d, route A]`, the form stage 4 gave the sibling lines;
`[objectstack-ai#8707 / objectstack-ai#10101]` and `[objectstack-ai#8144 / objectstack-ai#8707 / objectstack-ai#10101]` keep the live numbers
beside the sha.
- **`sys-activity.object.ts:59-60`.** 「Maintainer ruling 2026-08-24 on /
objectstack-ai#11507 (direction 4 of the four that card framed)」 became 「Maintainer
ruling 2026-08-24, / executed by commit 88b9d74 (direction 4 of the
four weighed)」. Line 59 is the one reflow line: only its last word
changed, and it carries no number. 「that card」 would have lost its
referent.
- **「re-open objectstack-ai#11507」**, `sys-activity.object.ts:92` and
`activity-type-vocabulary-enforcement.test.ts:332`, became 「re-open the
ruling (commit 88b9d74)」: a card that answers 404 cannot be re-opened,
and the instruction is about the decision.
- **`sys-activity-type-open-vocabulary.test.ts:14`**, the attribution
above a verbatim maintainer ruling: 「on objectstack-ai#11507 (direction 4 of the four
the card framed)」 became 「on the card behind commit 88b9d74 (direction
4 of the four it framed)」, so line 15's 「Recorded on the card as:」 keeps
its referent. Line 15, which carries the ruling 「四维分析一致的,接手你的建议。」, and
the quoted block under it are untouched.
- **Headings.** 「what the ruling on objectstack-ai#11507 changed」 and 「the objectstack-ai#11507
ruling」 became 「the open-vocabulary ruling (commit 88b9d74)」; 「objectstack-ai#11507
— the declaration」 became 「Commit 88b9d74 — the declaration」.
- **PR numbers.** 「objectstack-ai#5928 / PR objectstack-ai#6575」 (`audit-writers.ts:193`) and
「(objectstack-ai#5928, PR objectstack-ai#6575)」 (`audit-hook-object-scope.test.ts:19`) became
`commit 69787f0` beside the kept `objectstack-ai#5928`; 「measured on PR objectstack-ai#12143」
(`plugin-keyed-text-bounds.test.ts:21`) became 「measured on commit
f64668d」.
- **The `objectstack-ai#8707` ruling phrases**, `audit-writers.test.ts:1882` and
`:1922`. 「the ORDER the objectstack-ai#8707 ruling set」 became 「the ORDER commit
1408fe3 set」, and 「objectstack-ai#8707's ruling reasons about」 became 「commit
1408fe3 reasons about」: the ruling was the maintainer's on `objectstack-ai#8287`,
which stays on those lines, and `1408fe385`'s message carries the
reasoning. `audit-writers.ts:1402` 「because objectstack-ai#8707 reordered」 became
「because commit 1408fe3 reordered」, the flip its message states.
- **`objectstack-ai#14927`, three lines.** 「the cause measured on objectstack-ai#14927」 became 「the
cause commit ab48938 records」 (`audit-writers.ts:789`,
`audit-writers.test.ts:1211`), and 「The measured objectstack-ai#14927 misdirection」
became 「The misdirection commit ab48938 records」
(`audit-writers.test.ts:1370`).
- **`sys-activity-type-vocabulary.test.ts:91`.** 「Filed as objectstack-ai#8852;」
became 「Commit 51bb277 recorded it;」.
- **`comment-access-hooks.test.ts:404-405`.** 「the objectstack-ai#6523 contract's unit
is the envelope / and objectstack-ai#6206 forbids」 became 「the unit of commit
aa4b90d's contract is the envelope / and the full-envelope ruling
forbids」; `comment-access-hooks.ts:222` 「(objectstack-ai#6523 / the objectstack-ai#6206 ruling)」
became 「(commit aa4b90d / the full-envelope ruling)」.
- **`audit-writers.test.ts:1648`**, a section rule: the trailing rule
was shortened from 10 characters to 2 so the line stays near its old
width. `:1653` 「That day is objectstack-ai#8778」 became 「That day came with commit
7901b2d」.
- **`read-audit.test.ts:43`.** 「precisely how / objectstack-ai#16829 shipped」 became
「precisely how / the defect fixed by commit 8d4690b shipped」.
- **`comment-access-hooks.ts:35`**, the gate-invisible site:
「(objectstack-ai#9719/objectstack-ai#9798 built」 became 「(objectstack-ai#9719/commit c7655d4 built」.

## The 23 sites left

- **Source strings, 5 sites**, all `objectstack-ai#11507`: the `sys_activity.type`
field's `description` (`objects/sys-activity.object.ts:121`) and its
four generated copies
(`translations/{en,es-ES,ja-JP,zh-CN}.objects.generated.ts:125`). They
are runtime strings, all five are held by the shrink-only
`doc-authoring-prose-id` baseline, and the generated files are left as
A5 says. They ship in `dist` (see Changeset).
- **Test strings, 18 sites**, left as stages 1 to 8 left theirs:
- `describe` / `it` titles:
`activity-type-vocabulary-enforcement.test.ts:315` (the gate-invisible
`[objectstack-ai#8203/objectstack-ai#11507]`), `sys-activity-type-open-vocabulary.test.ts:70`
(`objectstack-ai#11507`), `audit-writers.test.ts:1420`, `:1659` (two sites, `objectstack-ai#8707`
and `objectstack-ai#8778`) and `:1873` (`objectstack-ai#8707`), `comment-access-hooks.test.ts:690`
(`objectstack-ai#9798`), `plugin-keyed-text-bounds.test.ts:90` (`objectstack-ai#11374`),
`read-audit-view-instant-preservation.integration.test.ts:121`
(`objectstack-ai#16829`);
- assertion and hint messages, all `objectstack-ai#11507`:
`activity-type-vocabulary-enforcement.test.ts:249`, `:352`, `:355`,
`:378`, `:380`, and `sys-activity-type-open-vocabulary.test.ts:83`,
`:90`, `:110`, `:152`.
- No quoted maintainer ruling in this package carries a dead number. The
package's generated `*.source-hashes.generated.ts` headers carry none
either (PR objectstack-ai#20656 fixed their producer).

## Mechanical guard: no code token moves

The guard compares the TypeScript parser's leaf nodes, with comments as
trivia and JSDoc nodes never visited, base `d2820876f` against head.
Template literals are therefore read in context. It ran over all 16
touched `.ts` files.

- Real run: 19,445 base leaf tokens, **0 files with a token change**
(exit 0).
- Comment control in `audit-writers.ts` (「the cause commit ab48938
records」 to 「… recorded」): 0 files changed, as expected (exit 0).
- Positive control, a code token added in `audit-writers.ts`
(`createRecordOrganizationResolver(engine)` given `as any`): DIFFER
(exit 1).
- Positive control, one digit changed inside a kept test title
(`audit-writers.test.ts:1873`, `objectstack-ai#8707` to `objectstack-ai#8708`): DIFFER (exit 1).

Every mutation went through `scripts/ablation-replace.mjs`, and each
landed (anchor 1 to 0, blob changed). Each restore was proven
byte-identical to the HEAD blob (`2dbd2059e8f5`, `8ec28790da22`), with
`git diff HEAD` empty and a clean tree afterwards.

## Changeset

This change ships bytes, so a `patch` changeset for
`@objectstack/plugin-audit`
(`.changeset/20596-plugin-audit-provenance-anchors.md`) is included. Its
body is stage 8's, word for word, with the package name changed.

Measured on the built package (A3): `files[]` is `dist`, `README.md` and
`CHANGELOG.md`. After the build, part of the rewritten prose reaches
`dist`: `c7655d472` twice in each of `dist/index.js` and `index.mjs` and
once in each of `index.d.ts` and `index.d.mts` (the
`CommentAccessEngine` option docblock is on an exported interface);
`88b9d749a` and `f64668d3c` twice, and `1cba33f16` and `8d4690b8f` once,
in each JS file (the object-definition comments and a `read-audit.ts`
comment). The comments in `audit-writers.ts` and `translations/index.ts`
do not reach `dist` (0 for each of their anchors). Positive controls:
the unchanged line 「below carries into the contract; this comment
carries the reasoning.」, in the same docblock as the shipped rewrite at
`sys-activity.object.ts:60`, is found once in each JS file, and the
unchanged line beside the shipped rewrite at
`comment-access-hooks.ts:77` once in each declaration file. A
never-written negative phrase appears nowhere in `dist`. Of the 16 dead
numbers, only `objectstack-ai#11507` is left in `dist`, 5 times in each JS file: the
kept `description` string and its four generated copies.

## Gates (head `d6e67afa5`)

- **Citation judging, as CI runs it:** `pnpm check:issue-citations`
(self-test, 114 cases, 8 batteries) exits 0. `node
scripts/check-issue-citations.mjs` exits 0: the diff-scoped run judged
11 citations across 6 files, and all 11 resolve (they are the live
numbers that already stood on the rewritten lines).
- **Doc authoring:** `pnpm check:doc-authoring` exits 0; the
sibling-package prose-id baseline holds (808 pinned sites, no growth),
which includes the five kept `objectstack-ai#11507` strings.
- **Derived gates:** `node scripts/pm/dispatch-gates.mjs --commands
--repo objectstack-ai/objectstack` at `d6e67afa5` derived 64 commands:
all 57 derived at dispatch, plus `check:dispatcher-error-vocabulary`,
`check:engine-double-contract`, `check:objectql-double-limit`,
`check:query-options-erasure`, `check:type-check-coverage`,
`check:type-check-debt` and `check:where-matcher`. Each ran with its
exit code captured before any pipe, and all 64 exit 0. `--ran`, fed each
command with its exit code, reports 64 run, 0 NOT MEASURED (a derived
zero), 0 unrun, and exits 0. A full `turbo run build` of `./packages/*`
and `./packages/*/*` ran first under the shared verify lock (71 of 71
tasks, exit 0), so no gate hit an unbuilt workspace.
- The derivation warns that its tree is 3 commits behind `origin/main`
and that one input, `scripts/engine-double-contract.pinned.json`,
changed there: `main` added one pinned row for
`packages/objectql/src/protocol-packaged-dashboard-base.test.ts`, a file
outside this diff. The family is in the 64 either way and exits 0 on
this tree.
- **Roster families the derivation lists outside its commands** (their
rosters sit in directories this diff touches): `node
scripts/check-changeset-fixed.mjs`, `pnpm check:authz-resolver`, `pnpm
check:error-code-casing` and `pnpm check:filter-alias-parity`, each exit
0.
- **Tests and typecheck, under the verify lock:**
- `pnpm --filter @objectstack/plugin-audit test`: 26 files pass and 366
tests pass. `vitest list --filesOnly` names 26 files, all the tracked
test files, the 10 touched ones included.
- `pnpm --filter @objectstack/plugin-audit typecheck` exits 0. `tsc
--listFiles`: `tsconfig.json` holds the 6 touched source files (19 `src`
files; it excludes tests), and `tsconfig.test.json`, which the script's
`check:test-typecheck` step compiles, holds all 45 files under `src/`,
all 16 touched files included.
- **Lint, as a proven narrowing:** `eslint --no-inline-config --format
json` over the 16 touched `.ts` files gives 16 files, 0 errors and 0
warnings. All 16 are in eslint's own population (`isPathIgnored` is
false for each; a `dist` file, as the control, is ignored).
`eslint.config.mjs` never enables type-aware linting (no
`parserOptions.project`, as its own lines 327-328 state), so a comment
edit here cannot move the verdict on any untouched file. The repo-wide
`pnpm lint` is CI's run.
- **Control bytes:** `pnpm check:nul-bytes` exits 0, and a raw scan of
the 17 changed files for control bytes finds none.

## Acceptance notes

- **The gate-invisible spellings, grepped as the claim asked.**
`CITATION_RE` refuses a hyphen after the digits and a `/` before the `#`
(objectstack-ai#20636), and `NON_CITATION_HEADS` excuses a number after the word
「option」. In this package:
  - `#N-word`: none.
- `#A/#B`: 11 lines, the claim's 11, over 14 distinct numbers. Two
second numbers are dead: `objectstack-ai#9798` in `comment-access-hooks.ts:35`,
rewritten, and `objectstack-ai#11507` in the test title
`activity-type-vocabulary-enforcement.test.ts:315`, left as a string.
The other 12 numbers resolve.
  - `option #N`: none.
The raw scan agrees: nothing dead beyond the gate is left outside a kept
string.
- **The kept `description` string is a runtime string with a dead
number.** `sys_activity.type`'s `description` ships to the metadata API,
the i18n bundles and `dist`, and ends 「(maintainer ruling 2026-08-24,
objectstack-ai#11507)」. It and its four generated copies are held by the
`doc-authoring-prose-id` baseline, so they belong to the runtime-string
lane (form D), not to this stage, as stages 1, 2 and 4 left theirs.
- **「This card」 phrases are left.** 46 lines in 21 files of this package
speak of 「this card」, 「that card」 or 「the card」. They carry no number
and neither instrument sees them. Two were rewritten here because the
rewrite on their own line removed their referent
(`sys-activity.object.ts:60`,
`sys-activity-type-open-vocabulary.test.ts:14`); the rest are unchanged,
as in stage 8.
- **Dead `objectstack-ai#11507` and `objectstack-ai#11374` outside the census surface.**
`docs/qa/platform-checklist/areas/records-forms.json` (4 lines) and
`docs/audits/gate-census-2026-09.md` (1 line) cite them as evidence.
`docs/` is outside this stage's surface; noted for objectstack-ai#20556, the carrier
of dead citations outside `packages/spec/src`.
- **The census instrument did not truncate in this stage.** Both
enumerations read 186 pages at the newest frontier.
- **Anchors the next stages can reuse**, each checked here: `objectstack-ai#16829` →
`8d4690b8f`; `objectstack-ai#6575` → `69787f07b`; `objectstack-ai#14927` → `ab489388b`; `objectstack-ai#8852` →
`51bb277ef`; `objectstack-ai#9798` → `c7655d472`; `objectstack-ai#11507` → `88b9d749a`.
- **Base.** The branch is on `main` at `d2820876f`. `main` has since
moved three commits (`f05919b82`, `99786f930`, `1940afdaf`). They touch
`packages/spec`, `packages/metadata-protocol`, one new
`packages/objectql` test file, a design doc, three changesets and
`scripts/engine-double-contract.pinned.json` (one added row for that
test file), and no file under `plugin-audit`,
`scripts/check-issue-citations.mjs` or `.changeset/config.json`, so no
merge was taken; the merge queue rebuilds on the merged generation.

---
_Generated by [Claude
Code](https://claude.ai/code/session_01XY5uCwTjZj7884yYtyur4H)_

---------

Co-authored-by: Claude <noreply@anthropic.com>

This branch had an error being deployed

1 failed and 1 active deployments
Preview – objectstack-play — 863ac2fb Deployed Feb 11, 2026 by vercel[bot]
Preview – spec — 863ac2fb Deployed Feb 11, 2026 by vercel[bot]
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants