Changelog
All notable changes to ARCLUX are documented here. Format based on Keep a Changelog; versioning follows SemVer (pre-1.0: minor bump = significant features).[0.3.1] — 2026-09-06
Fixed
- CLI —version on npm install —
resolveVersion()now walks up fromimport.meta.url(handlesdist/arclux.mjs → ../package.jsonnpm layout). Verified:npm pack → npm install → arclux --version → 0.3.1. Fixes0.0.0fallback. - doctor —help stale count —
10/18→ dynamicDETECTORS.length(20, includesorphanIntegration). Single source of truth, never stale. - Build break — removed duplicate resolver fragment that left
const programinsidetry(esbuildExpected "finally" but found "const").
[0.3.0] — 2026-09-05
Stable README + self-triggering MCP + engine honesty fixes. The “boring but brutal” release.Added
- MCP self-triggering —
SERVER_INSTRUCTIONS(workflow 4 langkah) + 16 trigger-first tool descriptions (FIRST/INSTEAD OF/BEFORE). AI agents now pick the right tool without being reminded. Exported + test-locked. - Two-pass call resolver — port of ManSio PR #20: verified import
1.0→ unique-global0.85→ external → explicit unresolved. Closes silent pick/drop (G1/G2/G4) and verifies exports (G5).ModuleInfo.unresolvedCallspreserves evidence. - Head freshness — port of ManSio #21/#22 line:
getHeadState+evaluateFreshness/reportFreshness(FRESH/STALE/INCONCLUSIVE),RepositoryMeta.buildHeadstamped in pipeline, re-anchored on cache hits. Doctor now shows freshness lamp. - Local fingerprint cache —
analyzeLocalPathnow uses content-hash cache (local:<path>). Hit = identical content, honest re-anchor; edit anywhere = miss by construction. In-memory (daemon/MCP/serve benefit), honest scope documented. - CLI RESULT block —
arclux analyzeprints modules/edges/deps/security + freshness;arclux doctorshows freshness lamp. Short lines, demo-safe. - Fair Evaluation Protocol —
ABOUT.md:repository → source → graph → build/test → runtime → conclusion+DONE/PLAN/ANALOGY/CLAIMdistinction. - Scene3D split —
scene3d.ts1577 lines →scene3d/17 domain modules (zero behavior change),planetary/stub ready for Blueprint 10. Verifiedtsc+build-game.mjs. - MMO polish — HUD fade+glow, menu hover/slide-in (Fase 7), bot harness headless 2-player (9 checks, tick/move/scan/attack/dock), landing CCTV + live stats.
Fixed
- BUG-1
folder_graphcircular JSON —folderGraphToJSON()(tree+folders+stats), MCP now JSON-safe. Repro test added. - BUG-3
semantic_diffbloat —detailsummary(default, file lists + counts) vsfull(legacy trees). 132 KB → summary, opt-in full. - BUG-2 orphan precision — pure-barrel exclude, re-export honesty (barrel-re-exported →
ambiguousnotunwired), noise skip (*.config.*,*.d.ts,vendor-ui/,_inbox/), dedupe byfilePath. Cross-packageserver.tscase fixed. - Builder drift —
packages/mcp/package.jsontypes etc. no longer rot; MCP tool list auto-discovers detectors/rules.
Changed
- README is now permanent — high-level, links to live docs (
PROGRES.md/ABOUT.md/docs site) instead of chasing numbers. Badges updated, install/usage evergreen, MCP self-triggering documented. - Versions bumped
0.2.0→0.3.0acrosspackage.json,apps/cli,apps/web,apps/vscode-extension,packages/mcp,CITATION.cff.
[0.2.1] — 2026-08-26
Added
- MCP server (32 tools) —
arclux mcpstarts the Model Context Protocol server; registry-driven auto-evolution (new detectors/rules appear automatically in tool descriptions). - Library / SDK exports —
import { analyzeRepository } from "arclux"exposes the full analysis engine programmatically (graphs, impact, search, security, rules, diagnostics) with typed.d.tsdeclarations, separate from the CLI bundle.
[0.2.1] — 2026-08-23
Added
- Published to npm as
arclux—npx arclux analyze .from anywhere. One-file esbuild bundle (self-contained, wasms shipped alongside) + treeSitterLoader resolves grammars from the package location when not in a dev checkout.
Added
Audit — the flagship featurePOST /api/audit: composition of runDoctor + securityAnalysis + attack surface, grouped into narrative chapters (severity-first)/[org]/[repo]/auditstandalone page + audit mode inside the script playground: STREAM (systemd-style boot, 55ms scan reveal built from real findings) × FOCUS (one finding at a time, file preview overlay) × GRAPH (camera flies per finding, cycle-path HUD)- Live audit on the 3D graph: severity halos breathe on flagged nodes as findings replay — driven from outside the renderer (zero core changes); auto-switches 2D→3D on launch
/api/security, /api/verify, /api/script
- Workspace tabs: Security · Verify · Health (Phase 2 scoring) · Calls
- Slash-command palette (11 commands), syntax-highlighted editor, JSON-tree output, transcript with per-run echo + ms, Ctrl+Enter
lib/navigation.tsregistry — sidebar, mobile bottom bar + More sheet, and the Ctrl+K command palette all render from one source- Pending spinners on every nav surface (useLinkStatus) — slow navigations never read as dead clicks
- View-mode toggle (auto/desktop/mobile) persisted per user
$ prompt prefixes, systemd
[ OK ] status tokens, steps(1) cursor blink, CRT scanlines
Fixed
- Audit halos never appeared (filePath missing from scene node objects — map now built from provider graph)
packages/dslfirst real typecheck surfaced 13 latent errors; 3 bindings were silently broken (search/diff/archdiff read fields that don’t exist)- Landing page claimed “2 languages” (actual: 27)
[0.2.0] — 2026-08-21
~1,020 commits sincev0.1.0-alpha. Still alpha — expect breaking changes.
Added
ARCLUX DSL — scripting languagearclux script <file.arclux>: lexer/parser/runtime/bindings for a purpose-built scripting language over the engine (packages/dsl)- Built-ins: analyze, doctor, check, graph, callgraph, impact, search, security, diff, archdiff + helpers (len, sum, filter, sort, exists, keys, values, env, cwd, extensions, checkids)
- Registry-driven:
extensions()/checkids()grow automatically when new parsers/detectors register — no DSL code changes needed
- New via shared tree-sitter loader + config-driven factory
(
makeTreeSitterParser): PHP, Ruby, Rust, C++, C#, Bash, C, Dart, Elixir, Kotlin, Lua, Objective-C, OCaml, Scala, Solidity, Swift, Vue, Zig, Elm, ReScript - Manifest parsers: package.json, go.mod, Cargo.toml, Gemfile, composer.json, csproj, gradle, pom.xml, requirements.txt
- Vendored elm wasm (
packages/parser/wasms/) — npm build is ABI-stale; loader checks vendored dir first - Fixed web-tree-sitter race: concurrent
Language.load()calls now serialized in the shared loader
- 20 architecture detectors (up from 18), including orphan-file classification (dead/unwired/ambiguous) and orphan-integration suggestions with confidence + evidence
- Security pipeline: secrets, unsafe patterns, sensitive-data flow, trust boundaries, attack surface, dependency risk
- Full-text + symbol search engine (
packages/search,/api/search) - Call graph across files; folder graph; export/import graphs
- Impact analysis: direct consumers + affected-files tree
- Always-on daemon with HTTP+SSE bridge (
/analysis,/impact,/events), persisted re-analysis history viapackages/db(RepoStore/AnalysisStore/IssueStore) - VS Code extension: status bar, Problems-panel diagnostics, trace impact
- Interactive shell REPL (
arclux shell) with watch mode - Source adapters: GitHub/GitLab URLs, archives, local paths — with SSRF guards (private-network/metadata endpoints refused) and source/evidence/ analysis boundaries
- Persistence layer wired: schema v1 + three stores used by the daemon
- Caching layer: file/repository/graph content-hash caches + CacheProvider stats/clear + MemoryCache
- Workspace, explorer, overview pages; graph focus view with history nav and expand-on-demand; activity page (commit history/contributors)
Changed
- Documentation fully synced to current reality (README, ABOUT, CONTEXT, docs-site Docusaurus + Mintlify, CITATION.cff)
- Repo description/topics updated on GitHub
Fixed
scripts/accidentally deleted from main (PR #528 stash-pop side effect) — restored, including both docs generators and log-progress.sh- web-tree-sitter concurrent grammar-load race (“Incompatible language version 0”)
Known limitations (honest)
- Per-file incremental re-index built but not wired into
buildIndex(daemon uses coarse full rebuilds) - 5 platform packages remain header-only stubs: observation, services, package-manager, ui, web-intake