feat(#1430): versioned capability manifest + native stamping (ADR-1244 Phase 1) (#1436)

* feat(#1430): versioned capability manifest + native stamping (ADR-1244 Phase 1)

Make the capability manifest versioned — the data substrate the Capability
Ecosystem (ADR-1244) keys off:

- capability.json gains a REQUIRED semver `version` plus the optional
  ecosystem envelope (`engines.gsd`, `compatVersions`, `integrity`,
  `provenance`); the build-time conformance validator enforces them via a new
  `validateVersionEnvelope()` (exported for the Phase 2 runtime overlay).
- All 32 native capabilities stamped with `version` (= package version,
  lockstep) + `engines.gsd`; `sync-manifest-versions.cjs` gains a glob sweep
  that keeps them in sync, and the issue-844 regression guard is extended.
- Strict SemVer 2.0.0 grammar blocks metacharacter/space/unicode smuggling in
  version strings; range/integrity fields are shape-validated (satisfaction
  and the load-time gate are deferred to Phase 2/4).
- Capability rel-paths emitted forward-slash for cross-platform git correctness.

Closes #1430

Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>

* docs(#1430): add changeset for versioned capability manifest

Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>

---------

Co-authored-by: Claude Opus 4.8 <noreply@anthropic.com>
This commit is contained in:
Tom Boucher
2026-06-18 10:45:53 -04:00
committed by GitHub
parent 8040a6bac0
commit 2421cf1b4a
40 changed files with 1321 additions and 115 deletions

View File

@@ -1470,6 +1470,7 @@ describe('S1: fragment.path traversal guard', () => {
JSON.stringify({
id: 'planning-advice',
role: 'feature',
version: '1.0.0',
title: 'Planning advice',
description: 'Synthetic fixture for fragment path materialization.',
tier: 'full',
@@ -1515,6 +1516,7 @@ describe('S1: fragment.path traversal guard', () => {
JSON.stringify({
id: 'research',
role: 'feature',
version: '1.0.0',
title: 'Research',
description: 'Synthetic fixture for step fragment materialization.',
tier: 'standard',
@@ -1702,7 +1704,7 @@ describe('C3: role:runtime body validation', () => {
// configHome is now an object (Decision 1), artifactLayout is { global, local } (Decision 3),
// commandStyle is closed enum (Decision 4), hooksSurface is closed enum (Decision 5).
const VALID_RUNTIME_CAP = {
id: 'cursor', role: 'runtime', title: 'Cursor', description: 'Cursor IDE runtime',
id: 'cursor', role: 'runtime', version: '1.0.0', title: 'Cursor', description: 'Cursor IDE runtime',
tier: 'standard', requires: [],
runtime: {
configHome: { kind: 'dot-home', name: '.cursor', env: ['CURSOR_CONFIG_DIR'] },
@@ -2886,6 +2888,7 @@ function makeCommandCap(id, commands) {
return {
id,
role: 'feature',
version: '1.0.0',
title: 'Test cap ' + id,
description: 'Synthetic capability for ADR-959 command tests.',
tier: 'full',
@@ -3085,6 +3088,7 @@ function makeRuntimeCap(overrides) {
return {
id: 'test-rt',
role: 'runtime',
version: '1.0.0',
title: 'Test Runtime',
description: 'A synthetic runtime capability for testing.',
tier: 'core',