> ## Documentation Index
> Fetch the complete documentation index at: https://arclux-os.mintlify.site/llms.txt
> Use this file to discover all available pages before exploring further.

# Changelog

> Release history — Keep a Changelog + SemVer

# Changelog

All notable changes to ARCLUX are documented here. Format based on
[Keep a Changelog](https://keepachangelog.com/); versioning follows
[SemVer](https://semver.org/) (pre-1.0: minor bump = significant features).

## \[0.3.1] — 2026-09-06

### Fixed

* **CLI --version on npm install** — `resolveVersion()` now walks up from `import.meta.url` (handles `dist/arclux.mjs → ../package.json` npm layout). Verified: `npm pack → npm install → arclux --version → 0.3.1`. Fixes `0.0.0` fallback.
* **doctor --help stale count** — `10/18` → dynamic `DETECTORS.length` (20, includes `orphanIntegration`). Single source of truth, never stale.
* **Build break** — removed duplicate resolver fragment that left `const program` inside `try` (esbuild `Expected "finally" but found "const"`).

## \[0.3.0] — 2026-09-05

Stable README + self-triggering MCP + engine honesty fixes. The “boring but brutal” release.

### Added

* **MCP self-triggering** — `SERVER_INSTRUCTIONS` (workflow 4 langkah) + 16 trigger-first tool descriptions (`FIRST`/`INSTEAD OF`/`BEFORE`). AI agents now pick the right tool without being reminded. Exported + test-locked.
* **Two-pass call resolver** — port of ManSio PR #20: verified import `1.0` → unique-global `0.85` → external → explicit unresolved. Closes silent pick/drop (G1/G2/G4) and verifies exports (G5). `ModuleInfo.unresolvedCalls` preserves evidence.
* **Head freshness** — port of ManSio #21/#22 line: `getHeadState` + `evaluateFreshness`/`reportFreshness` (`FRESH`/`STALE`/`INCONCLUSIVE`), `RepositoryMeta.buildHead` stamped in pipeline, re-anchored on cache hits. Doctor now shows freshness lamp.
* **Local fingerprint cache** — `analyzeLocalPath` now uses content-hash cache (`local:<path>`). Hit = identical content, honest re-anchor; edit anywhere = miss by construction. In-memory (daemon/MCP/serve benefit), honest scope documented.
* **CLI RESULT block** — `arclux analyze` prints modules/edges/deps/security + freshness; `arclux doctor` shows freshness lamp. Short lines, demo-safe.
* **Fair Evaluation Protocol** — `ABOUT.md`: `repository → source → graph → build/test → runtime → conclusion` + `DONE`/`PLAN`/`ANALOGY`/`CLAIM` distinction.
* **Scene3D split** — `scene3d.ts` 1577 lines → `scene3d/` 17 domain modules (zero behavior change), `planetary/` stub ready for Blueprint 10. Verified `tsc` + `build-game.mjs`.
* **MMO polish** — HUD fade+glow, menu hover/slide-in (Fase 7), bot harness headless 2-player (9 checks, tick/move/scan/attack/dock), landing CCTV + live stats.

### Fixed

* **BUG-1 `folder_graph` circular JSON** — `folderGraphToJSON()` (tree+folders+stats), MCP now JSON-safe. Repro test added.
* **BUG-3 `semantic_diff` bloat** — `detail` `summary` (default, file lists + counts) vs `full` (legacy trees). 132 KB → summary, opt-in full.
* **BUG-2 orphan precision** — pure-barrel exclude, re-export honesty (barrel-re-exported → `ambiguous` not `unwired`), noise skip (`*.config.*`, `*.d.ts`, `vendor-ui/`, `_inbox/`), dedupe by `filePath`. Cross-package `server.ts` case fixed.
* **Builder drift** — `packages/mcp/package.json` types etc. no longer rot; MCP tool list auto-discovers detectors/rules.

### Changed

* **README is now permanent** — high-level, links to live docs (`PROGRES.md`/`ABOUT.md`/docs site) instead of chasing numbers. Badges updated, install/usage evergreen, MCP self-triggering documented.
* Versions bumped `0.2.0` → `0.3.0` across `package.json`, `apps/cli`, `apps/web`, `apps/vscode-extension`, `packages/mcp`, `CITATION.cff`.

## \[0.2.1] — 2026-08-26

### Added

* **MCP server (32 tools)** — `arclux mcp` starts the Model Context
  Protocol server; registry-driven auto-evolution (new detectors/rules
  appear automatically in tool descriptions).
* **Library / SDK exports** — `import { analyzeRepository } from "arclux"`
  exposes the full analysis engine programmatically (graphs, impact,
  search, security, rules, diagnostics) with typed `.d.ts` declarations,
  separate from the CLI bundle.

## \[0.2.1] — 2026-08-23

### Added

* **Published to npm as `arclux`** — `npx arclux analyze .` from anywhere.
  One-file esbuild bundle (self-contained, wasms shipped alongside) +
  treeSitterLoader resolves grammars from the package location when not
  in a dev checkout.

Web experience wave — the engine is unchanged, the surface caught up.

### Added

**Audit — the flagship feature**

* `POST /api/audit`: composition of runDoctor + securityAnalysis +
  attack surface, grouped into narrative chapters (severity-first)
* `/[org]/[repo]/audit` standalone page + audit mode inside the script
  playground: STREAM (systemd-style boot, 55ms scan reveal built from
  real findings) × FOCUS (one finding at a time, file preview overlay)
  × GRAPH (camera flies per finding, cycle-path HUD)
* **Live audit on the 3D graph**: severity halos breathe on flagged
  nodes as findings replay — driven from outside the renderer (zero
  core changes); auto-switches 2D→3D on launch

**Web/CLI parity routes**: `/api/security`, `/api/verify`, `/api/script`

* Workspace tabs: Security · Verify · Health (Phase 2 scoring) · Calls

**Script playground v2 — opencode-style terminal**

* Slash-command palette (11 commands), syntax-highlighted editor,
  JSON-tree output, transcript with per-run echo + ms, Ctrl+Enter

**Navigation system**

* `lib/navigation.ts` registry — sidebar, mobile bottom bar + More
  sheet, and the Ctrl+K command palette all render from one source
* Pending spinners on every nav surface (useLinkStatus) — slow
  navigations never read as dead clicks
* View-mode toggle (auto/desktop/mobile) persisted per user

**Terminal craft**: JetBrains Mono, `$` prompt prefixes, systemd
`[ OK ]` status tokens, steps(1) cursor blink, CRT scanlines

### Fixed

* Audit halos never appeared (filePath missing from scene node
  objects — map now built from provider graph)
* `packages/dsl` first real typecheck surfaced 13 latent errors; 3
  bindings were silently broken (search/diff/archdiff read fields
  that don't exist)
* Landing page claimed "2 languages" (actual: 27)

## \[0.2.0] — 2026-08-21

\~1,020 commits since `v0.1.0-alpha`. Still alpha — expect breaking changes.

### Added

**ARCLUX DSL — scripting language**

* `arclux script <file.arclux>`: lexer/parser/runtime/bindings for a
  purpose-built scripting language over the engine (`packages/dsl`)
* Built-ins: analyze, doctor, check, graph, callgraph, impact, search,
  security, diff, archdiff + helpers (len, sum, filter, sort, exists,
  keys, values, env, cwd, extensions, checkids)
* Registry-driven: `extensions()` / `checkids()` grow automatically when
  new parsers/detectors register — no DSL code changes needed

**Language support: 5 → 27 languages**

* New via shared tree-sitter loader + config-driven factory
  (`makeTreeSitterParser`): PHP, Ruby, Rust, C++, C#, Bash, C, Dart,
  Elixir, Kotlin, Lua, Objective-C, OCaml, Scala, Solidity, Swift, Vue,
  Zig, Elm, ReScript
* Manifest parsers: package.json, go.mod, Cargo.toml, Gemfile,
  composer.json, csproj, gradle, pom.xml, requirements.txt
* Vendored elm wasm (`packages/parser/wasms/`) — npm build is ABI-stale;
  loader checks vendored dir first
* Fixed web-tree-sitter race: concurrent `Language.load()` calls now
  serialized in the shared loader

**Analysis & intelligence**

* 20 architecture detectors (up from 18), including orphan-file
  classification (dead/unwired/ambiguous) and orphan-integration
  suggestions with confidence + evidence
* Security pipeline: secrets, unsafe patterns, sensitive-data flow,
  trust boundaries, attack surface, dependency risk
* Full-text + symbol search engine (`packages/search`, `/api/search`)
* Call graph across files; folder graph; export/import graphs
* Impact analysis: direct consumers + affected-files tree

**Platform & delivery**

* Always-on daemon with HTTP+SSE bridge (`/analysis`, `/impact`,
  `/events`), persisted re-analysis history via `packages/db`
  (RepoStore/AnalysisStore/IssueStore)
* VS Code extension: status bar, Problems-panel diagnostics, trace impact
* Interactive shell REPL (`arclux shell`) with watch mode
* Source adapters: GitHub/GitLab URLs, archives, local paths — with SSRF
  guards (private-network/metadata endpoints refused) and source/evidence/
  analysis boundaries
* Persistence layer wired: schema v1 + three stores used by the daemon
* Caching layer: file/repository/graph content-hash caches +
  CacheProvider stats/clear + MemoryCache

**Web dashboard**

* Workspace, explorer, overview pages; graph focus view with history nav
  and expand-on-demand; activity page (commit history/contributors)

### Changed

* Documentation fully synced to current reality (README, ABOUT, CONTEXT,
  docs-site Docusaurus + Mintlify, CITATION.cff)
* Repo description/topics updated on GitHub

### Fixed

* `scripts/` accidentally deleted from main (PR #528 stash-pop side
  effect) — restored, including both docs generators and log-progress.sh
* web-tree-sitter concurrent grammar-load race ("Incompatible language
  version 0")

### Known limitations (honest)

* Per-file incremental re-index built but not wired into `buildIndex`
  (daemon uses coarse full rebuilds)
* 5 platform packages remain header-only stubs: observation, services,
  package-manager, ui, web-intake

## \[0.1.0-alpha] — 2026-08-07

Initial public baseline: TypeScript/JavaScript/Python/Go/Java parsing,
dependency graph, impact analysis, 18 detectors, CLI + early web UI.


This documentation is built and hosted on [Mintlify](https://mintlify.com), a developer documentation platform.