Skip to content

Update dependency github:yvgude/lean-ctx to v3.11.2 - #2313

Open
renovate[bot] wants to merge 3 commits into
mainfrom
renovate/github-yvgude-lean-ctx-3.x
Open

renovate[bot] wants to merge 3 commits into
mainfrom
renovate/github-yvgude-lean-ctx-3.x

Conversation

@renovate

@renovate renovate Bot commented Sep 24, 2026 •

Copy link
Copy Markdown
Contributor

ℹ️ Note

This PR body was truncated due to platform limits.

This PR contains the following updates:

Package Type Update Change
github:yvgude/lean-ctx tools minor v3.8.8 → v3.11.2

Release Notes

yvgude/lean-ctx (github:yvgude/lean-ctx)

v3.11.2

Compare Source

Updater and security hotfix for 3.11.1. Agent Tools protocol, configuration and data formats are unchanged.

Upgrade notes
  • Updating from 3.11.0 or 3.11.1 needs one manual step. Their built-in updater stops after downloading and verifying a release with Failed to complete durable update transaction: prepared transaction is missing its integrity digest, and scheduled automatic updates fail the same way. Nothing is changed or damaged: the installed binary keeps running. Install this release once through the channel you installed with — curl -fsSL https://leanctx.com/install.sh | sh, brew upgrade lean-ctx, npm i -g lean-ctx-bin@latest, cargo install lean-ctx --force or your AUR helper — and lean-ctx update and automatic updates work again from then on.
  • Windows on 3.11.0 (#​2039): the 3.11.0 updater also needs the external cosign tool and looks for it under that exact name; installing cosign does not help, because its update then stops at the error above. Extract the Windows ZIP of this release over your lean-ctx.exe, or update through npm. From 3.11.1 on, no external tool is needed.
Security
  • The home jail scope opens projects, not your home directory. 3.11.1 admitted every path below ~ for reading, so a prompt-injected agent could pull loose personal files (~/Documents/taxes.pdf, ~/Downloads, ~/Desktop) into the model context. A path is now admitted only when a folder between it and ~ holds a project marker (.git, Cargo.toml, package.json, go.mod, pyproject.toml, Makefile, …). Every repository below ~ stays readable; anything else needs lean-ctx allow-path <dir>, and the refusal says so.
  • redirect_exclude from an untrusted workspace is withheld (#​2034). Paths in redirect_exclude skip the native-read hook redirect and with it the redaction that path applies. In 3.11.1 a repository's own .lean-ctx.toml could extend the list even when the workspace was not trusted, so a cloned repository could opt its reads out (for example with ["**"]) on hosts where the read redirect is active. Such a list is now ignored with a [SECURITY] warning until you run lean-ctx trust; the global config and LEAN_CTX_HOOK_EXCLUDE still apply.
Fixed
  • Codex threads recorded while ChatGPT routing was on stay resumable. Codex stamps model_provider = "leanctx-chatgpt" into every such thread and refuses to resume it once that provider is missing (Model provider 'leanctx-chatgpt' not found). lean-ctx doctor --fix, proxy runs and stale-proxy cleanup deleted the [model_providers.leanctx-chatgpt] block by name, including the direct one users restored by hand. Cleanup now only touches a block that targets the local proxy, and repoints it at https://chatgpt.com/backend-api/codex instead of deleting it; a block aimed anywhere else is kept verbatim and no longer reported as routed or broken.
  • ctx_multi_repo action=search without a query says so. While a content policy was active, the call was refused with the cross-project policy message instead of query is required for search.
  • No downgrade as "update". Without an explicit version, lean-ctx update and scheduled updates only install a release newer than the running build; a build ahead of GitHub's latest release was offered, and on a schedule installed, the older release. lean-ctx update <version> and --pin still install any version on purpose.
  • GitHub API rate limit (#​2037): the updater now sends GITHUB_TOKEN, GH_TOKEN or LEAN_CTX_GITHUB_TOKEN when set (only to api.github.com, without following redirects), raising GitHub's limit from 60 requests per hour per IP address to 5000. An exhausted quota now says so, with the reset time and the fix, instead of http status: 403; a rejected token reports 401 Bad credentials. The background version check uses the same client.
  • lean-ctx update and lean-ctx update --rollback complete again. The updater sealed each prepared transaction with its integrity digest when writing it to disk, but then executed the unsealed copy, which the integrity check rejected every time. The updater now executes exactly the sealed transaction it persisted. A new test runs the real prepare → execute → recover path on a stand-in binary.
  • macOS: the update signature is applied before the swap. The updater re-signed the installed binary after moving it into place (#​356, so the TCC grant survives), which changed its bytes after the transaction had recorded them; the update then stopped with "active binary does not match prepared target". The staged binary is now signed first, and the receipt records exactly the bytes that are installed; the release manifest and archive digests still record its provenance.
  • A reinstall no longer blocks later updates. A failed 3.11.0/3.11.1 run leaves a prepared transaction behind; after a manual reinstall the updater refused every update with "active binary matches neither prepared state". Recovery now recognizes a transaction that a build at least as new as its target has superseded and removes its staged files without touching the binary. Likewise, an update receipt from a different, earlier version no longer refuses updates ("current binary differs from the active receipt"); the updater starts a new receipt from the running binary. A binary that differs from a receipt of the same version is still refused.
Upgrade
lean-ctx update                 # recommended (auto-downloads + refreshes shell hooks)
cargo install lean-ctx          # or
npm update -g lean-ctx-bin      # or
brew upgrade lean-ctx

Note: After upgrading via cargo/npm/brew, run lean-ctx setup to refresh shell aliases. lean-ctx update does this automatically.

Full Changelog: yvgude/lean-ctx@v3.11.1...v3.11.2

v3.11.1

Compare Source

Highlights
  • Agents can read across all your projects at once: the path jail now admits every project below your home directory for reading by default, while writes stay in the session's own project and ~/.ssh, ~/.aws, ~/.config, other top-level dot directories, ~/Library, ~/AppData and ~/snap stay closed.
  • Each agent session binds to the project it was started in. Setup no longer pins one project into an agent's global MCP config, and existing pins are removed.
Upgrade notes
  • Path jail scope: the new path_jail_scope setting defaults to "home": reads anywhere below your home directory outside the protected zones; writes only in the session's project, host-declared roots and allow entries. Set lean-ctx config set path_jail_scope project to keep the previous single-project boundary. The setting is global-only; a project-local .lean-ctx.toml cannot change it. With an implausible $HOME (/, a single path component, not owned by you) the scope falls back to project. path_jail = false still disables the jail.
  • Protected zones are a hard deny in both scopes: a project root or allow entry that only contains a zone (for example a dotfiles repository at ~) no longer opens ~/.ssh and the like; add an entry inside the zone (lean-ctx allow-path ~/.config/myapp) if a tool must reach it.
  • Project pins: earlier lean-ctx setup / doctor --fix runs and MCP-start hook refreshes copied the installing session's LEAN_CTX_PROJECT_ROOT and LEAN_CTX_EXTRA_ROOTS into user-global agent configs (~/.codex/config.toml, ~/.grok/config.toml, global JSON MCP entries), so every later session of that agent opened the same project. The Codex and Grok entries are cleaned on the next agent refresh; lean-ctx doctor reports remaining pins under "Project binding" and lean-ctx doctor --fix removes them line by line, keeping key order and comments (a pin that shares a line with other keys is listed for a manual edit). LEAN_CTX_EXTRA_ROOTS values move into extra_roots; per-project entries in ~/.claude.json are left alone. Restart the agent once afterwards.
  • Telemetry: the daily aggregates report more (see Changed), and setup no longer asks: setup and the first interactive command after this update print a three-line notice instead. Turn telemetry off any time with lean-ctx telemetry off, DO_NOT_TRACK=1 or LEAN_CTX_TELEMETRY=off; an explicit opt-out made since 3.11.0 stays in effect, and lean-ctx telemetry show prints the exact payload. What the server keeps, including a keyed network hash and the network operator's public name derived from the connection (never the IP address), and how long, is described at leanctx.com/privacy.
Security
  • Agent shells can no longer loosen lean-ctx itself. lean-ctx is on the default shell allowlist, so an agent could run lean-ctx yolo --yes, lean-ctx allow <cmd>, lean-ctx allow-path <dir>, lean-ctx trust, lean-ctx security open, lean-ctx security secrets off or lean-ctx config set <security key> through ctx_shell (or a hook-rewritten Bash call) and then do what the jail or the allowlist had just refused. Those subcommands are now blocked in agent shells with a message to ask the user; listing (--list, status, config show), narrowing (--remove) and tightening (secure, untrust, security secrets on) still run. Run the blocked commands in your own terminal.
  • Path jail writes: the new home scope opens other projects for reading only; writes outside the session's project need an explicit lean-ctx allow-path, so an agent in one repository cannot plant another repository's Git hooks or a binary on your PATH.
Added
  • lean-ctx allow-path <dir> admits one directory for reading and writing — outside your home directory, a sibling project to edit, or one protected location — effective on the next tool call without a restart. --list shows the jail scope and added directories; --remove takes one out. It refuses /, the home directory and any directory containing it.
  • lean-ctx security status shows the active jail scope, and lean-ctx doctor reports global project pins.
Changed
  • A refused path names the one command that admits it (lean-ctx allow-path <dir>, offered for the enclosing project) for the user to run in their terminal. The previous hints to open a new IDE window or set an env var that the running server cannot see are gone.
  • When a stale LEAN_CTX_PROJECT_ROOT pin is still set and the MCP server starts inside a different real project, the session binds to that project and logs a warning. Host-specific roots (CLAUDE_PROJECT_DIR, workspace folders) keep their precedence.
  • Telemetry reports where and how long LeanCTX runs, as coarse ranges. The daily heartbeat adds the runtime environment (local, container, Codespaces, Gitpod, Replit, cloud agent, CI), the installation age (under an hour … 30+ days) and the number of active days in the last 30 (1 … 15+), each as a closed value. They let usage numbers separate people from short-lived agent sandboxes. No machine, account, network or path information is sent. The disclosure lists the new category, so every installation sees the one-time notice again; DO_NOT_TRACK=1, LEAN_CTX_TELEMETRY=off and lean-ctx telemetry off still turn telemetry off.
  • The install channel is detected. It was unknown for every installation because no build set it; it now follows the location of the running executable (npm, Homebrew, cargo, PyPI, AUR, release binary). Only the channel name is sent.
  • Telemetry reports token savings and per-tool latency. The daily tool aggregate adds the day's total tool-output tokens before and after compression, and each built-in tool's summed latency. Counts only; no content.
  • Telemetry includes the daily usage record and why tools fail. The batch carries the last 90 days of the installation's own lean-ctx gain record (operations and tokens before/after compression per day, lifetime totals, month of first use), so usage through shell hooks and before telemetry is counted. Failed tool calls are reported by class (invalid input, not found, permission, policy, timeout, edit conflict, too large, unavailable), together with the five most frequent error messages per tool and day as templates: the client replaces every quoted text, path, file name, number, identifier, URL and e-mail address with a placeholder before anything is sent, and drops a message entirely when no safe wording remains. Shell commands that exit non-zero are now reported as command instead of internal.
  • Upgrades turn on telemetry that was only off by the old default. Before 3.11 telemetry was opt-in, so telemetry.enabled = false without a recorded choice is re-enabled once on upgrade, and the one-time notice explains it. An opt-out made since 3.11 (lean-ctx telemetry off, declining in setup, and now also lean-ctx config set telemetry.enabled false) is recorded as explicit and never overridden; DO_NOT_TRACK=1 and LEAN_CTX_TELEMETRY=off always win, and a read-only config is left untouched.
  • Telemetry counts which LeanCTX features are used. A daily feature_aggregate reports how often each CLI command runs (lean-ctx pack export → cli.pack.export, graph build, index build-full, telemetry off …) and every graph, BM25 and semantic index build with its failures. Commands and verbs come from a fixed registry; arguments, paths and queries never become part of a code, and hot-path commands (shell hooks, -c, read, grep, statusline) are not counted.
  • Telemetry names 21 more AI clients. Cline, Roo Code, Kilo Code, Continue, OpenCode, Goose, Amp, Augment, JetBrains, Warp, Trae, Qwen Code, Crush, Claude Desktop, ChatGPT, LM Studio, Copilot CLI, Visual Studio, Neovim, Emacs and Factory are reported as their own family, and none separates installations used only through the CLI and shell hooks from an unrecognised MCP client (other). The client's name is never sent, and what LeanCTX offers each client over MCP is unchanged.
  • Setup no longer asks about telemetry. Setup and the first interactive command after an install or update show a three-line notice instead: telemetry is on, how to turn it off (lean-ctx telemetry off, or enabled = false under [telemetry] in the config.toml it names) and where to see what is sent. The full list stays on lean-ctx telemetry on|off and the payload on lean-ctx telemetry show. An earlier explicit choice is kept.
Fixed
  • ctx_shell output capture works in your project. Redirects and tee (> build.log, >> notes.txt, | tee out.txt) were refused everywhere except /tmp, $TMPDIR and write_allow_paths; the project root stayed refused even when listed, and allow_paths / extra_roots were not consulted. Capture may now also go to the session's project and the jail's allow entries. /, ~, its ancestors and read_only_roots are never capture targets; downloads (curl -o, wget, dd of=) keep the scratch-only rule.
  • ctx_shell no longer relocates, queues or throttles your builds. Three multi-agent build settings were on by default: agents.shared_cargo_target pointed every cargo build/test run through ctx_shell at <data dir>/build-cache/cargo-target, so ./target kept a stale binary; agents.serialize_build_commands made each build wait for builds from other sessions on the machine; agents.cargo_build_jobs = 3 capped cargo at three jobs. All three are now opt-in (false, false, 0) and documented in the config reference under [agents]. Set them again in config.toml if you relied on the shared cache.
  • ctx_shell walk hint judges each invocation on its own (#​2027). A scoped grep -r … tariff followed by a stdin-reading grep in the same command line (…; echo x | grep -c x, | grep -v _test) was treated as a recursive walk of the working directory, so the hint named .claude/worktrees/, node_modules/ or .venv/ although nothing entered them. Only invocations that walk (find, or a grep-like with its own -r/-R) now contribute search roots. With raw: true the hint is no longer appended, matching the verbatim promise.
  • lean-ctx update and enable-gpu no longer require a cosign binary. 3.11.0 verified release signatures by running cosign, so on machines without it every binary update and enable-gpu stopped with "cosign is unavailable; refusing unsigned release". The updater now verifies the keyless signature in-process: the certificate must chain to the embedded Sigstore Fulcio root, carry a valid SCT from the Sigstore CT log, name the release workflow at the exact release tag with the GitHub Actions OIDC issuer, and sign the file. When cosign is installed it still runs as an additional check (Rekor transparency log). 3.11.0 installations cannot self-update to this release unless cosign is on PATH (winget install -e --id Sigstore.Cosign, brew install cosign, or a binary from github.com/sigstore/cosign/releases); alternatively reinstall with the install script (macOS/Linux), npm, Homebrew or Cargo, or replace the binary from the release archive.
  • Semantic index builds keep their progress. Embeddings were written only after the last chunk, and lean-ctx index build-semantic gave up after 10 minutes, which ended the process and discarded the work — on CPU-only machines and with larger models the index was never built. Builds now save finished files every minute and on errors, Ctrl-C or memory aborts, the next run resumes where the last one stopped, and the CLI waits until the build finishes. index status and doctor report an interrupted build as partial with the resume command.
  • ctx_index builds the semantic index in the background. build-semantic and build-full no longer block the tool call, wait for the BM25 index instead of embedding an empty or stale one, and a per-project lock keeps two processes from building the same semantic index at once.
  • CLAUDE.md is read in full. Automatic ctx_read modes (and redirected native reads) returned a large CLAUDE.md as a headings-only map, because only SKILL.md, AGENTS.md and a few rule files were treated as instructions. CLAUDE.md, CLAUDE.local.md, GEMINI.md, copilot-instructions.md, .windsurfrules, and documents under .claude/agents/ and .claude/commands/ are now always delivered complete.
  • redirect_exclude works again. The key was loaded but never applied, so listing a file there changed nothing. Matching paths (globs on the trailing path components, e.g. CLAUDE.md, *.json, docs/**) now skip the native-read hook redirect and are returned in full by automatic ctx_read modes; LEAN_CTX_HOOK_EXCLUDE (comma-separated) takes precedence, as documented since 2.17.4.
  • lean-ctx index build / build-full no longer stop after 5 minutes while graph and BM25 are still building, which ended the process before the index was saved. A build worker that fails unexpectedly now always releases its slot, so the command reports the failure instead of waiting.
Upgrade
lean-ctx update                 # recommended (auto-downloads + refreshes shell hooks)
cargo install lean-ctx          # or
npm update -g lean-ctx-bin      # or
brew upgrade lean-ctx

Note: After upgrading via cargo/npm/brew, run lean-ctx setup to refresh shell aliases. lean-ctx update does this automatically.

Full Changelog: yvgude/lean-ctx@v3.11.0...v3.11.1

v3.11.0

Compare Source

Highlights
  • (Preview) Context Gateway admission screens supported reads, derived stores, and supported proxy requests by default, and reports when content was not fully inspected.
  • Semantic code views use language-server evidence when available, label uncertain relationships, and avoid linking same-named symbols across language families.
  • The optional Claude Code mod shapes large native Bash output, wakes a turn when a watched background job finishes, and restores lean-ctx session context after compaction.
  • CLI reads use the same path boundary as MCP reads, command help is side-effect free, and multi-word shell allowlist entries are scoped to their subcommand.
  • Anonymous telemetry v2 reports bounded usage aggregates without prompts, source text, paths, commands, or tool arguments, with explicit opt-outs.
  • Windows indexing accepts legacy UTF-16 and Windows-1252 text, and Windows CUDA embeddings report missing CUDA 12/cuDNN 9 libraries by name.
  • (Preview) The Context Store links one task's plan, delivery and outcome, measures read strategies per workload, and records a learned read policy in shadow unless you opt in.
  • lean-ctx pack --limit produces a bounded context bundle, and lean-ctx index why explains why a file is or is not indexed.
Upgrade notes
  • Context Gateway (Preview): admission is on by default. Set LEAN_CTX_CONTEXT_GATEWAY=off for one run, or set context_gateway.enabled = false in the global config to disable it persistently. The CLI lean-ctx read path used by shell hooks is outside gateway admission unless a policy pack is active; output redaction still applies.
  • Telemetry: v2 is on by default. Setup now asks "Keep anonymous telemetry on? [Y/n]" and lists what is sent; answering n stores an explicit opt-out that every later upgrade keeps. Earlier versions did not store a declined prompt, so an installation that declined before 3.11.0 is on after the upgrade: the first interactive command shows a one-time notice with the full list, and lean-ctx telemetry off turns it off. Disable it any time with DO_NOT_TRACK=1, LEAN_CTX_TELEMETRY=off, or lean-ctx telemetry off; an earlier explicit opt-out remains in effect. CI jobs (CI, GITHUB_ACTIONS, GITLAB_CI, and other common CI markers) never collect or send telemetry; LEAN_CTX_TELEMETRY_IN_CI=1 opts a non-CI machine with such a marker back in. Use lean-ctx telemetry status|show|history|purge-local|delete-remote|reset-id to inspect or manage its payload and ledger.
  • Indexes: GRAPH_ENGINE_VERSION and graph INDEX_VERSION are now 7. Existing graph indexes rebuild before use; do not reuse a version 6 graph.
  • Semantic mode: semantic_mode = "auto" is the default. It uses running language servers or a live IDE; it does not start servers unless semantic_mode = "eager" is selected in a trusted workspace. Use semantic_mode = "off" to disable semantic enrichment.
  • Shell allowlist: multi-word entries now match the exact command unless they end in *. For example, use "git status *" for prefix matching. Set shell_allowlist_subcommand_scoping = false to restore the former base-binary matching.
  • Other new defaults: intelligence_runtime.context_policy_apply = false. Each stdio MCP server targets mcp_max_rss_mb = 512 (raise it, or set LEAN_CTX_MCP_MAX_RSS_MB, for very large indexes); mcp_idle_exit_minutes = 0 keeps idle servers running. The engine-context-store-v1 contract and context-gateway-v1 vocabulary are experimental, not stable compatibility promises.
  • Claude Code mod: the mod is installed explicitly. When active, set its keep_hook_context option to retain lean-ctx hook context, or shape_native_output to disable native Bash shaping.
  • Removed runtime paths: automatic model routing is gone; a leftover proxy.routing.tiers table is ignored and reported by lean-ctx doctor. Rust embedders importing removed internal modules must move to ContextEngine or lean-ctx-sdk.
  • Removed shell cache: the opt-in shell output cache was removed; legacy config files still load, but shell_cache_enabled no longer enables cached results.
Security
  • lean-ctx -c and -t enforce the shell allowlist under pass-through (#​2004). An agent process can inherit LEAN_CTX_WRAPPED from a wrapped parent; lean-ctx -c then passed the command through raw and skipped the allowlist, so a command ctx_shell blocks ran through the Bash-hook rewrite. Pass-through now skips only compression; the allowlist applies on every route, with the same warn-only rule for an interactive terminal.
  • Graph summaries are admitted before indexing. The graph index no longer stores each file's first source line verbatim; summaries pass admission, and files with secret-like paths receive no summary. The graph index version advances to 7.
  • Context Gateway admission (Preview). Reads through ctx_read in every mode, plus its shared readers, pass built-in secret, checksum-validated PII, prompt-injection, and classification checks before caching, compression, rendering, or indexing. Search, recovery, and provider paths use admitted content as well. Redactions and withheld reads report reason codes without exposing values; blocking evaluates the original text and withholds content if a redaction leaves a detectable value behind.
    • BM25/trigram indexes, dense snippets, caches, archives and their full-text index, tee/reference results, project knowledge, handoffs, and provider artifacts store admitted text only. Policy changes invalidate affected indexes and caches; recovery is rechecked under the current policy.
    • The local BYOK proxy applies admission to parsed content for supported Anthropic, OpenAI Chat/Responses (including WebSocket), Gemini, and Bedrock request paths, including token-count probes. Provider-sealed fields are not rewritten. Media, malformed bodies, partial scans under max_inspected_bytes, detector timeouts, and invalid custom patterns are reported as not fully inspected; governed/sovereign modes withhold those cases. Restricted content is not sent to a remote model.
    • lean-ctx inspect reports receipt-backed sources, detector coverage, and delivered/withheld outcomes. Receipts include the policy digest and returned-byte digest; tampered receipts are not displayed. context_gateway.hud = auto keeps pure-redaction counts out of the installed Claude Code status line.
  • Secret redaction covers more forms. Detection now includes AWS session keys, fine-grained GitHub and GitLab tokens, Anthropic/OpenAI keys, JWTs, Slack/Stripe/npm tokens, private-key blocks, URL-encoded and JSON-escaped values, and secrets split by zero-width or full-width characters. UUIDs and already-masked values are left intact. MCP resources, prompts, lean-ctx call, the agent-tools CLI, and the embed crate use the same output-redaction path.
  • Recovery handles are verified before use. Tee, archive, reference-store, and context-ledger handles are checked for resolution, expiry, digest match, and path escape without exposing content; policy refusals are reported as unavailable to the model rather than as broken handles.
  • CLI reads and shell allowlists enforce their stated boundaries (#​1901, #​1903, #​1906, #​1419, #​1930).
    • lean-ctx read uses the MCP ctx_read PathJail and secret-path rules. Broad roots are refused unless path_jail = false; relative paths resolve from the current directory. Shell rewrites leave refused reads on the native command, and worktrees under .claude/worktrees are treated as projects.
    • lean-ctx COMMAND --help prints help without running the command; only handlers with verified side-effect-free help receive the flag. upgrade --check only checks.
    • Multi-word allowlist entries such as "git status" match that command only; add a trailing * for a prefix. Binary-specific entries take precedence over project-root auto-allow. lean-ctx doctor reports entries whose meaning changed or is shadowed; the compatibility switch is trust-gated.
    • PowerShell statements are split and checked at their executable commands, including conditions, expressions, and script-block bodies. Only read-only .NET members count as inert; file writers, process starters, and compilers remain blocked. Under bash or zsh, operators and script blocks keep their native meaning; only single inert operands are treated as inert PowerShell.
Added
  • mcp_idle_exit_minutes (LEAN_CTX_MCP_IDLE_EXIT_MINUTES, default 0 =
    off) ends a stdio MCP server after that many idle minutes. It is opt-in
    because Codex does not restart exited MCP servers. stdin EOF and a dead
    parent already end the server.
  • Gateway proof registry and source planning. A proof registry maps admission cases and bypass checks to their tests, and the release gate can refuse while a proof entry is open. engine context-plan-sources omits caller-supplied sources unrelated to the task even when budget remains; it drops stop words, splits identifiers, and keeps sources related by task terms. lean-ctx inspect shows receipt-derived redaction, withholding, and source-use facts. A local claims catalog records what the release can say and what it does not claim.
  • Per-host gateway coverage. lean-ctx doctor reports whether each configured host is enforced, partial, MCP-only/not observable, or unsupported; partial means lean-ctx tools and rewritten shell commands are covered while host-native file tools can bypass admission, and not_observable means MCP-only. lean-ctx inspect shows the same coverage. The generated matrix does not claim observation without an integration that provides it. Claude Code traffic is enforced only with an Anthropic API key; Pro/Max sign-in cannot be proxied. Credential-forwarding journeys for Claude Code /v1/messages and Codex subscription /backend-api/codex/responses show a tool-result credential withheld while the rest of the turn proceeds.
  • Claude Code mod (#​1981, #​1986, #​1989, #​1991, #​1997, #​1998). lean-ctx claude-mod install|status|uninstall manages an embedded local plugin for Claude Code 2.1.287 or later; interactive setup offers installation, while non-interactive setup and update only refresh an existing install. MCP is marked always-load, and the mod shapes native Bash output of at least 2,000 characters with fail-open behavior. The shell deny lets Bash(run_in_background) through only when the exact command passes the enforced allowlist; ctx_shape remains an internal hook rather than a listed tool.
    • A configurable set of tool descriptions is front-loaded while the rest is deferred. A watched ctx_shell background job wakes the model once instead of requiring status polling; the mod also answers a bare sleep N while a job is watched.
    • SessionStart/UserPromptSubmit attachments authored by lean-ctx are removed to avoid repeating the same guidance; other hooks and non-lean-ctx text pass through. Use keep_hook_context to opt out. /leanctx shows session-only request, token, ToolSearch, wake, and dropped-context counts; it does not persist them or send telemetry.
    • Before main-conversation compaction, the mod saves session state and asks the summarizer to keep recovery handles and still-reporting job IDs. The first following prompt carries that state once; user compaction instructions and subagent compactions are preserved. Plugin versions include a content hash, and doctor recognizes Claude Code's normalized cache directory name.
  • Semantic code intelligence (#​1976, #​1979, #​1983, #​1990, #​1996). Tree-sitter remains the baseline; semantic_mode = auto uses an already-running language server or live IDE to verify uncertain structure, with bounded background refreshes that do not interrupt a backend call. Call edges carry evidence and are shown as verified, resolved, or heuristic; ambiguous callees do not bind to the alphabetically first match. Per-language capability status appears in ctx_graph status and lean-ctx doctor.
    • ctx_impact propagates exact and weaker name-match paths separately. ctx_repomap uses verified graph call edges or caller-scope resolution, and an ambiguous name or vetoed guess does not become a link. Calls are bound within the caller's language family.
    • implements and extends relations are collected where a backend offers them; references are checked on demand by ctx_impact rather than stored as graph edges. TypeScript 7 projects use tsc --lsp --stdio; older projects use typescript-language-server.
    • A VS Code/Cursor/Windsurf extension bridges the editor's existing language features through a per-workspace, token-protected, read-only local navigation endpoint. It does not edit files, start servers, or displace a live server or IDE.
  • Context Store (Preview; experimental contract engine-context-store-v1). One task's plan → delivery → outcome lineage, joined from the execution ledger and Decision Receipts and scoped per tenant/project, is shown by lean-ctx inspect --task and lean-ctx engine context-lineage; missing links are listed as gaps rather than filled in.
    • Read-strategy evidence per workload: quality, security (deliveries without full inspection) and runtime friction (re-reads, expansions, failed edits after a compressed read) are measured per task, and anything unmeasured is reported as unmeasured. Available through lean-ctx autopilot evidence, lean-ctx engine context-policy-evidence and lean-ctx eval frontier --save-evidence.
    • lean-ctx autopilot policy status|promote|monitor|rollback keeps a promoted read-strategy policy (active plus last stable) supplied by the optional licensed runtime. Planning records it in shadow only; intelligence_runtime.context_policy_apply = true applies it, and security rules and explicit user choices still take precedence.
    • The context kernel also draws on the BM25 search index and the code graph; it never builds or refreshes an index while planning. Surprise, graph proximity and redundancy are measured from the candidate set.
  • lean-ctx pack --limit (#​1885). Writes a deterministic, self-contained XML bundle under a hard character or token cap, ranking files by the task and import graph. It can include current curated knowledge, with that material counted inside the cap; secret-bearing files and secret-like paths are withheld. Emit modes, output files, clipboard, stats, include/ignore globs, and ctx_pack action=bundle are supported. Exit 1 means even the frame could not fit; exit 2 means invalid flags.
  • Browser OAuth for HTTP MCP servers (#​1391). lean-ctx addon auth NAME supports OAuth 2.1 discovery, registration, PKCE, loopback redirect, token attachment, and refresh; --status, --logout, and --no-browser are available. Credentials are encrypted per server using the macOS Keychain, Windows Credential Manager, or a Linux 0600 key file. OAuth declarations on stdio servers or alongside an Authorization header are refused.
  • lean-ctx index why FILE. Explains which indexing rule included or excluded a file, reports encoding and BM25 chunk/freshness information for eligible files, supports --json, and exits 1 for an excluded file. MCP: ctx_index action=why path=FILE.
  • Windows CUDA embeddings. The x86_64 Windows CUDA build is installed and retained by enable-gpu and update. CUDA 12/cuDNN 9 libraries can be loaded from installed pip wheels, the CUDA Toolkit, or the cuDNN installer without changing PATH; CPU-fallback diagnostics name missing DLLs and explain that CUDA 13 alone does not provide CUDA 12 DLLs.
  • Clearer ONNX Runtime setup diagnostics. ORT_DYLIB_PATH errors identify whether the variable is absent or malformed and explain process versus MCP configuration scope. Hints identify JSON control characters, quotes, and unexpanded %VAR%, $VAR, or ~ values. lean-ctx embeddings status reports the selected runtime, version check, and execution-provider policy, with platform-specific setup guidance.
Changed
  • Bounded memory for long-lived MCP servers. Each stdio MCP server now
    has a per-process RSS target, mcp_max_rss_mb (default 512 MB,
    LEAN_CTX_MCP_MAX_RSS_MB). The guardian uses the lower of it and
    max_ram_percent, which on large machines was several GB per process. A
    Codex app-server that keeps one server per loaded thread therefore no longer
    accumulates ~1 GB instances.
  • Idle MCP servers release their caches. After the memory_cleanup TTL
    without a tool call, a server drops its read cache and resident indexes
    without waiting for the next call. A running call or background job keeps
    it busy. The release logs process memory and live heap before and after.
  • macOS: the memory guard measures physical footprint. It now uses the
    figure Activity Monitor shows instead of resident size, which leaves out
    pages the memory compressor has taken. An idle server measured 40 MB
    resident while still holding a ~180 MB heap. Footprint is read through
    proc_pid_rusage, which also replaces a ps spawn per sample.
  • Quieter, cheaper guardian. Eviction rounds that reclaim nothing back off
    (1 s → 60 s, then a five-minute pause) at every pressure level, not only
    Critical. Sampling stays at one second, so a rise to a higher level still
    evicts at once. Pressure lines log on a level change and at most once a
    minute after that; a baseline above a small cap used to log every second.
  • Bundled MCP SDK 1.32.1 in the pi extension (#​2017). @modelcontextprotocol/sdk 1.30.0 → 1.32.1, proxy-addr 2.0.8 and source-map-js 1.2.2; THIRD_PARTY_NOTICES and the asset manifest record the new versions and digests.
  • One capability registry. Capability IDs remain stable lookup names, while one registry determines which capabilities are backed by the local source tree and how their availability is described.
  • Local use remains accountless. Signing in alone no longer enables shared agent-presence or lease paths; a single developer's local Runtime remains available without an account.
  • Quality evidence reports its limits (#​1905). Eval/A-B/footprint/frontier reports label runs with fewer than 30 paired tasks or without bootstrap as underpowered; --gate fails those runs. --mechanism is for small wiring fixtures, fails only on regression, and cannot support a quality claim. Non-regression is reported as NON-INFERIOR, and schema v2 reports evidence tiers from mechanism through production; fixture recordings are mechanism evidence only. Shadow reports identify their baseline as simulated and describe outcome acceptance relative to that baseline.
    • Footprint pruning requires powered real-model evidence. --export and --compare evaluate the same tasks against a baseline. eval frontier compares strategies against one baseline and guards against leaking gold answers into task metadata.
    • quality-lab uses representation_grade, which describes representation fidelity rather than task quality. Its receipt reports retention, recovery, security, and task-quality dimensions, with unmeasured dimensions shown as UNMEASURED; --gate also fails when a critical fact is lost. quality_floor and max_context_tokens remain offline-only; other profile constraint fields are not read.
  • Prompt-cache requests stay stable (#​1912). Complexity-driven thinking blocks stay consistent across turns, are capped at half of max_tokens, and respect the client's OpenAI reasoning_effort; requests with max_tokens below 2048 do not receive an injected block. Unchanged or reverted proxy requests forward the client's original bytes, and rewritten gzip/zstd bodies are re-encoded. A warm conversation does not alternate between compressed and uncompressed system prompts.
  • Anonymous telemetry v2 is on by default. The former opt-in heartbeat is replaced by a typed batch. It sends version, platform, a random installation ID, client family, integration/embedding state, bounded daily built-in-tool call/failure counts, and coarse session/sync/error aggregates; tool calls are now counted in production. It never sends prompts, code, file contents, paths, commands, tool arguments, or foreign MCP tool names. Counters are per UTC day; resends replace daily totals. An unreadable config fails closed and prior opt-outs remain effective. Setup, telemetry on and a one-time notice on the first interactive command show the same list of what is sent; a declined setup prompt is stored as an explicit opt-out; CI jobs never collect or send.
  • Agent registration records presence without a session cap (#​1765). New sessions keep their explicit role and available tools regardless of how many other sessions are present. Build and test commands remain serialized where they run; cargo_build_jobs and shared_cargo_target still apply. agents.max_concurrent_mutating_workers remains readable for compatibility but is no longer used.
  • Public copy is consistent across shipped surfaces (#​1987). README, current documentation, package descriptions, help, and skill templates now use one product category and state implementation and evidence boundaries consistently. Measurement documentation distinguishes local hash-chain integrity from an explicitly signed batch export and describes what each comparison measures.
  • Compression holdout is available as an opt-in measurement (#​1977). proxy.compression_holdout / LEAN_CTX_PROXY_COMPRESSION_HOLDOUT defaults to 0; a deterministic conversation cohort forwards the control arm without input compression and records token counts for both arms. The report is pending until each arm has 30 turns, then reports a reduction with a Welch 95% interval. Quality remains unknown in every state, and the holdout does not change thresholds or policy.
Removed
  • Automatic model routing. Intent-tier selection, routing-quality fallback, Thompson-sampling feedback, the OCLA ModelRouter, built-in router registry/API/health entries, routing evals, experiment arms, and routing savings are removed. A released runtime package can still be recognized, but its model-ranking capability is not invoked. Existing routing ledger events and previously recorded history remain readable/exportable; operator-written aliases, outbound allow/deny policy, model ceilings, budgets, rate limits, and reasoning budgets remain. A stale proxy.routing.tiers table is ignored and reported by lean-ctx doctor.
  • Unused modules and unsupported proof claims (#​1914, #​1915, #​1923). Uncalled internals were removed, including core::solution_rules, predictive_prefetch, multiscale_index, context_column, adaptive_chunking, cognitive_load, graph_features, progressive_compression, structural_diff, structural_tokenizer, adaptive_compression, agent_attribution, cache_diagnostics, chain_compression, content_handle, cross_customer_learning, delta_response, evidence_classification, evidence_flow, fleet_analytics, json_sample, negative_knowledge, query_aware, rule_scorer, session_budget, token_calibration, the unused context-kernel feedback, learning and attribution modules, the marginal-information gate, attention placement, MDL selector, gamma cover, predictive-coding deltas, attention-weighted context assembly, U-curve attention model, semantic chunk reorder, and io_boundary::read_file_scanned.
    • The execution ledger and work graph are kept: they back the Context Store lineage and Decision Receipts.
    • No CLI command, MCP tool, configuration key, or contract was removed by these module deletions. Rust embedders that imported the internal paths must drop those imports; core::solution_types and the OCP export adapter remain. The supported embedding surfaces are ContextEngine and lean-ctx-sdk.
    • ctx_verify action=proof no longer reports Lean4 or FormallyVerified; its highest level is PolicyChecked. Empty BM25 indexes report empty, and graph metadata-file size is no longer presented as graph-index size. review no longer sets the no-op layout.enabled; no layout driver or regulated role is available, and regulated redaction belongs to policy-pack filters. Documentation and source comments no longer claim cognitive-mode savings or Jira access without evidence.
  • Opt-in shell result cache (#​1982). Cached shell results are removed because command output depends on workspace state outside the old cache key; old config files still load.
Fixed
  • Parallel reads no longer time out on file locks (#​2016). Every completed ctx_read persists its ledger entry before it is acknowledged; 16 parallel reads on Windows queued past the 750 ms lock wait and failed with a misleading "agent registry lock" error. Ledger persistence now waits up to 10 s, lock errors name the lock file, and concurrent first tool calls register the session's bus presence once instead of racing.
  • Runtime install no longer reports Busy for a lock it just released (#​2019). A child process forked by another thread briefly shares the install and configuration locks; install now retries for up to 2 s before reporting Busy.
  • ctx_read honours the documented bare multi-select (#​2000). mode="3,7-9" selects those lines like lines:3,7-9 instead of falling through to a full read; malformed comma payloads still reach the unknown-mode path.
  • Control flow inside a shell function body passes the allowlist (#​2002). A function body is expanded like a top-level line, so for, if, while and case are control flow and only the commands inside them are checked; the block message no longer contains a stray run of spaces.
  • A heredoc after a multi-line quoted string is recognised (#​2003). The heredoc scanner keeps the quote state across lines, so echo "a⏎b"; cat <<'EOF' no longer gates the heredoc body as commands; an apostrophe in a comment cannot hide a later heredoc.
  • A directory override never touches the real install (#​2007). With LEAN_CTX_CONFIG_DIR, LEAN_CTX_DATA_DIR, LEAN_CTX_STATE_DIR or LEAN_CTX_CACHE_DIR set, startup layout healing no longer moves the default ~/.lean-ctx or XDG config files or writes the layout pin; previously a scratch run renamed the real ~/.lean-ctx/config.toml to config.toml.superseded.
  • MCP startup no longer waits on recently used files (#​2006). Collecting the cache-warming history resolved every recently touched file synchronously before the server answered initialize; with the project on a network drive that took 95-150 s. It now runs on the warming thread before that thread takes the cache lock, and each session's project root is resolved once instead of once per file. Daily background housekeeping removes orphaned session save locks and prunes stores above 300 sessions by session_retention_days (at least 1 day; the newest session per project and the latest pointer are kept).
  • ctx_expand(id=) works without a status poll (#​2005). A finished background job is archived on expand; a running job is reported as still running and an unknown ID as nonexistent, instead of "unavailable or expired" for all three.
  • gain no longer presents an estimate as a bill saving. When the provider request path is not observed, lean-ctx gain reports provider bill impact as unknown, labels gross tool-output savings as a local estimate, and leaves ROI unavailable. ctx_gain exposes the evidence type, provider-path observability, and null net bill impact when it cannot be observed.
  • Other gateways keep their endpoint (#​1972). Install, uninstall, cleanup, doctor, and supported host wiring treat only configured, UID-derived, or historical lean-ctx ports as lean-ctx endpoints. Other local or remote URLs are preserved unless --force is used; Codex no longer receives a duplicate base URL.
  • lean-ctx-status reflects OFF (#​1971). Bash, zsh, and fish read the value of LEAN_CTX_ENABLED; the command exits 0 for ON and 1 for OFF/DISABLED.
  • Raw tail windows stay bounded (#​1965). mode=-N, raw=true returns the requested final lines verbatim, like lines:-N, rather than the whole file.
  • Package upgrades refresh stale shell hooks (#​1959). On MCP server start, existing stale hook files are refreshed without rewriting shell rc files; disabled hooks are skipped, and present env.sh and _lc PATH shims are refreshed with bash/zsh hooks.
  • Background maintenance preserves config edits (#​1934). It writes only timestamps it changed and writes nothing when none changed, so concurrent config set or editor changes are not overwritten. Test configuration is passed directly instead of leaking through process-wide state.
  • Read stubs are only reused by the caller that received them (#​1904, #​1909). Delivery IDs are per process rather than shared across Claude Code processes. A content-free “already in your context” stub is returned only when delivery to that conversation is known; Claude Code subagent re-reads return compressed content. Relayed content must match the requested view. LEAN_CTX_SCOPE opts back in for integrations that run one agent per process.
  • Compressed reads do not expand output or silently lose facts (#​1910, #​1911). Auto mode falls back to bare file content when a mode cannot shrink it; explicit modes keep their notice. Over-budget reads name the truncation and raw=true. Cache entries distinguish auto from explicit modes. Entropy filtering is deterministic and uses file-relative thresholds; higher aggressiveness drops more. Terse shell/tool output falls back when compression would lose critical status, error, count, or location facts. Proxy CCR handles resolve in ctx_expand, map exports preserve nested Rust generics, and repeated edit failures escalate to full mode.
  • The agent surface reports callable operations (#​1913). Agent cards list tools that are available through the public tool endpoints, authentication descriptions match enforced /a2a checks, and task cancellation is limited to the caller's own task. Agent action schemas follow the dispatcher's actions; the inactive OclaBus no-op was removed.
  • Windows timeouts stop child processes (#​1920). ctx_shell, ctx_execute, and sandbox commands run in a private job object, so timeout, cancellation, or an unexpected lean-ctx exit ends the process tree. Deliberately started background processes still survive a normally completed command, as on Unix.
  • Integration tests use an isolated data directory. The cargo test --test main binary uses a per-process temporary data directory unless LEAN_CTX_DATA_DIR is set, and clears ambient agent-scope variables.
  • Hook rewrites preserve visible content (#​1916, #​1917, #​1918). Read dedup is per agent; a named file can be searched up to 64 MB, skipped files and timeouts are reported, and lean-ctx grep exits 2 when the search was incomplete or errored. Unquoted shell globs are expanded by the shell before a whole-command rewrite; quoted patterns keep the direct rewrite.
  • Parallel first reads no longer fail on cache contention. Tokenizer and path-protection config load before the cache lock; if a read cannot obtain the lock in time, its content is returned without caching.
  • Legacy Windows text encodings are indexed. UTF-16 LE/BE, UTF-8 with or without a BOM, lossy UTF-8, and Windows-1252 are decoded with line numbers preserved. NUL-byte binary detection no longer rejects UTF-16 text; run lean-ctx index build once to add affected files.
  • Pip ONNX Runtime libraries are found. lean-ctx locates onnxruntime and onnxruntime-gpu libraries in active environments, PYTHONPATH, user sites, and system sites without running an interpreter. ORT_DYLIB_PATH accepts a containing directory, and versioned library names are recognized.
  • Write refusals, batch reads, and zero-hit search are precise (#​1995; fixes #​1992, #​1993, #​1994). Redirect/tee/heredoc/download refusals explain the read-before-write path and are unchanged by smaller commands or raw=true. Batch ctx_read appends kernel enrichment once after the summary and never in raw mode; supplements stop on line boundaries, and out-of-project episodes are not offered. ctx_search zero-hit output reports its scanned scope, index-pruned files count as covered, empty scopes explain why, and comma-separated include values are glob lists.
  • Wide project source directories are valid scan roots (#​1985; tracked in #​1984). A broad directory inside a marked project can be searched using its ancestor project marker; directories without a marker in their ancestry remain protected.
  • Shell and proxy outputs are not replayed from stale state (#​1982). Shell commands run again against current workspace state. Proxy dedup is stateless across requests and replaces output

❗ Important

✂ PR body was truncated to here.


Configuration

📅 Schedule: (UTC)

  • Branch creation
    • At any time (no schedule defined)
  • Automerge
    • At any time (no schedule defined)

🚦 Automerge: Disabled by config. Please merge this manually once you are satisfied.

♻ Rebasing: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox.

🔕 Ignore: Close this PR and you won't be reminded about this update again.


  • If you want to rebase/retry this PR, check this box

This PR was generated by Mend Renovate. View the repository job log.

@renovate renovate Bot added the 📦 dependencies Pull requests that update a dependency file label Sep 24, 2026
@github-actions github-actions Bot added this to the v10.0.7 milestone Sep 24, 2026
@codacy-production

codacy-production Bot commented Sep 24, 2026 •

Copy link
Copy Markdown

Up to standards ✅

🟢 Issues 0 issues

Results:
0 new issues

View in Codacy

🟢 Metrics 0 complexity · 0 duplication

Metric Results
Complexity 0
Duplication 0

View in Codacy

NEW Get contextual insights on your PRs based on Codacy's metrics, along with PR and Jira context, without leaving GitHub. Enable AI reviewer
TIP This summary will be updated as you push new changes.

@renovate
renovate Bot force-pushed the renovate/github-yvgude-lean-ctx-3.x branch 2 times, most recently from b2cf3b2 to 9bfe341 Compare September 25, 2026 23:26
@renovate renovate Bot changed the title Update dependency github:yvgude/lean-ctx to v3.10.2 Update dependency github:yvgude/lean-ctx to v3.10.3 Sep 25, 2026
@renovate
renovate Bot force-pushed the renovate/github-yvgude-lean-ctx-3.x branch from 7baadbd to 35c0c6d Compare September 26, 2026 13:44
@renovate renovate Bot changed the title Update dependency github:yvgude/lean-ctx to v3.10.3 Update dependency github:yvgude/lean-ctx to v3.10.4 Sep 26, 2026
@renovate
renovate Bot force-pushed the renovate/github-yvgude-lean-ctx-3.x branch from 9ae7008 to 5eb3b5d Compare September 27, 2026 21:30
@renovate renovate Bot changed the title Update dependency github:yvgude/lean-ctx to v3.10.4 Update dependency github:yvgude/lean-ctx to v3.10.5 Sep 27, 2026
@renovate
renovate Bot force-pushed the renovate/github-yvgude-lean-ctx-3.x branch 2 times, most recently from d5f9276 to dfcf68c Compare October 5, 2026 17:12
@renovate
renovate Bot force-pushed the renovate/github-yvgude-lean-ctx-3.x branch from d330738 to 499da2b Compare October 8, 2026 11:15
@renovate renovate Bot changed the title Update dependency github:yvgude/lean-ctx to v3.10.5 Update dependency github:yvgude/lean-ctx to v3.11.0 Oct 8, 2026
@github-actions

github-actions Bot commented Oct 8, 2026 •

Copy link
Copy Markdown

Test Results

0 tests  ±0   0 ✅ ±0   0s ⏱️ ±0s
0 suites ±0   0 💤 ±0 
0 files   ±0   0 ❌ ±0 

Results for commit ed2277c. ± Comparison against base commit 5795b5f.

♻️ This comment has been updated with latest results.

@renovate renovate Bot changed the title Update dependency github:yvgude/lean-ctx to v3.11.0 Update dependency github:yvgude/lean-ctx to v3.11.1 Oct 9, 2026
@renovate
renovate Bot force-pushed the renovate/github-yvgude-lean-ctx-3.x branch from 3655d31 to 8d83429 Compare October 9, 2026 16:09
@renovate renovate Bot changed the title Update dependency github:yvgude/lean-ctx to v3.11.1 Update dependency github:yvgude/lean-ctx to v3.11.2 Oct 10, 2026
@renovate
renovate Bot force-pushed the renovate/github-yvgude-lean-ctx-3.x branch from 48b0c00 to 8564427 Compare October 10, 2026 00:52
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

📦 dependencies Pull requests that update a dependency file

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants