Skip to content

Fencier v0.1 release candidate + audit.include_patch fix - #1

Merged
DerMayer1 merged 2 commits into
mainfrom
agent/fencier-v0-1-release-candidate
Jul 27, 2026
Merged

DerMayer1 merged 2 commits into
mainfrom
agent/fencier-v0-1-release-candidate

Conversation

@DerMayer1

@DerMayer1 DerMayer1 commented Jul 27, 2026 •

Copy link
Copy Markdown
Owner

Summary

Brings the v0.1 release candidate to main and fixes a documented-but-dead policy flag found while auditing the README against the actual implementation.

Two commits, reviewable independently:

  • 093b307 — v0.1 release candidate: standalone CLI bundling, real doctor diagnostics, secret-safe --json output, and scripts/release-check.mjs install-from-tarball validation.
  • 438d878 — makes audit.include_patch actually work, plus doc corrections.

The include_patch bug

audit.include_patch was validated by the schema, shipped in the default fencier.yaml, documented in the README policy example, and asserted in a test — but no code ever read it. Setting it to true did nothing; patches were never written under any configuration.

The plumbing was almost there: collectGitDiff already ran git diff and threw the patch away after extracting added lines.

  • git.ts — collectGitDiff returns { files, patch } and takes an includePatch option. The --unified=0 scan patch is kept for secret detection; a second diff with default context runs only when a reviewable patch is requested, and only when audits are actually being written (--no-audit skips it).
  • audit.ts — the flag is enforced in one place (createAuditEvent), then rendered as a ```diff section in Markdown and a patch key in JSON.
  • cli.ts — threads the patch through.

Security note for reviewers

The patch is the only unmasked part of an audit. With include_patch: true, a diff that adds a secret writes it to .fencier/audits/ in plaintext. Every other audit field stays masked, --json verify output is unchanged, and the default remains false. The tradeoff is documented in the README security section, docs/security.md, and inline in the generated report.

Docs

Added three commands missing from the README reference: codex install, codex fix-audit brief, codex skill path.

Testing

  • pnpm run ci green — lint, typecheck, 51 tests (up from 48), build.
  • pnpm release:check passes — packs, installs from tarball, exercises doctor / init / skills / PASS / FAIL.
  • Manually verified in throwaway repos: default writes no patch; include_patch: true writes it to both formats.
  • Dogfooded — fencier verify on this change reports PASS / LOW.

New coverage: git.ts returns patch text only when asked, and audits omit/include the patch per the policy flag in both formats.

DerMayer1 and others added 2 commits July 26, 2026 02:23
The audit.include_patch policy flag was validated by the schema,
shipped in the default fencier.yaml, and documented in the README,
but no code ever read it. Setting it to true had no effect: patches
were never written under any configuration.

collectGitDiff already ran `git diff` and discarded the patch text
after extracting added lines. It now returns { files, patch } and
takes an includePatch option, re-reading the diff with default
context so the stored patch is reviewable (the scan patch uses
--unified=0 and has no context lines). The extra git call only runs
when audits are actually being written.

writeAuditReports gates the patch on policy.audit.include_patch in
one place, then emits it as a ```diff section in Markdown and a
patch key in JSON.

The patch is the only unmasked part of an audit, so a diff that adds
a secret now stores it in .fencier/audits/ in plaintext when the flag
is on. Documented in the README security section, docs/security.md,
and inline in the generated report. The default stays false.

Also documents three commands missing from the README reference:
codex install, codex fix-audit brief, and codex skill path.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
@DerMayer1
DerMayer1 merged commit 5f78e5c into main Jul 27, 2026
1 check passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant