## [4.5.1](https://github.com/abdelrahmannasr/yadflow/compare/v4.5.0...v4.5.1) (2026-10-06)


### Bug Fixes

* **docs:** a failed site build fails the Pages deploy ([32dd88f](https://github.com/abdelrahmannasr/yadflow/commit/32dd88f69dc1140977e1a2c126f94078aaa5f2ea))
* **docs:** doctor judges only the failure handling, on the wired platform (review 2) ([987a753](https://github.com/abdelrahmannasr/yadflow/commit/987a7532951f61aec530550e2a9cab9aa4e0795f))
* **docs:** escape the apostrophe that broke the overview site build ([fe7dcc8](https://github.com/abdelrahmannasr/yadflow/commit/fe7dcc81b2772dc577659e4afd2b85bec2bff81a))
* **docs:** name every failed site, quote GitLab lines as YAML, doctor warns on an old wired workflow (review 1) ([d525e87](https://github.com/abdelrahmannasr/yadflow/commit/d525e87961413a10ba16122dfc3811ac3d5361a7))
* **gitlab:** check the git-lfs download against its SHA-256 ([#327](https://github.com/abdelrahmannasr/yadflow/issues/327) review 1) ([01763a2](https://github.com/abdelrahmannasr/yadflow/commit/01763a25fdc47eea298592f3ab453341c2c14196))
* **gitlab:** install git-lfs in yad-gate-sync when the Product uses LFS ([#327](https://github.com/abdelrahmannasr/yadflow/issues/327)) ([fcb55fb](https://github.com/abdelrahmannasr/yadflow/commit/fcb55fb6a3c2d96be067cb7c027644424784181d))
* **windows:** leave the npm launcher name unquoted so npx finds itself ([#326](https://github.com/abdelrahmannasr/yadflow/issues/326)) ([b042848](https://github.com/abdelrahmannasr/yadflow/commit/b0428484f371a03cc5e722158481faf51004b519))

# [4.5.0](https://github.com/abdelrahmannasr/yadflow/compare/v4.4.0...v4.5.0) (2026-10-06)


### Bug Fixes

* **member:** E131 review 1 — links, twins, proof and pushes ([1179a97](https://github.com/abdelrahmannasr/yadflow/commit/1179a9731e4ff9f8d6b80f5aed82d5809bde5ed2))
* **member:** E131 review 2 — gate-live trust, account ids, clean-ups ([74d41f6](https://github.com/abdelrahmannasr/yadflow/commit/74d41f65a585fdf06639be87688f69353eb61916))
* **member:** E131 review 3 — trust only files the gate judged ([2f9af14](https://github.com/abdelrahmannasr/yadflow/commit/2f9af141e524ca7daacbce8c2799f56c72c6d75e))
* **member:** E131 review 4 — trust is read from origin's default branch ([43af9c4](https://github.com/abdelrahmannasr/yadflow/commit/43af9c4565c3bbfae7042d7765df62150fa64447))
* **member:** E131 review 5 — every change re-proves every email ([041937c](https://github.com/abdelrahmannasr/yadflow/commit/041937c936f5d9f29683ef6f9d4cc6fb93ad83bd))
* **member:** E131 review 6 — re-runs, origin/HEAD, partial lists ([e9bad00](https://github.com/abdelrahmannasr/yadflow/commit/e9bad002eff766705d193b1515baa3d39ae0c360))
* **standup:** E132 review 1 — gate rule, malformed ledgers, terminal safety ([a0e7d47](https://github.com/abdelrahmannasr/yadflow/commit/a0e7d4750e7b485582cded4b55dfcc212013a101))
* **standup:** E132 review 2 — missed twins of round 1 ([ba1ce61](https://github.com/abdelrahmannasr/yadflow/commit/ba1ce61b961decbea46298b714fd33f811fb264a))
* **standup:** E132 review 3 — paths, disputed accounts, left members ([add86cc](https://github.com/abdelrahmannasr/yadflow/commit/add86cca821ab29afa79838734a3b83621dd2330))
* **standup:** E132 review 4 — Windows paths, a name is plain text ([435225f](https://github.com/abdelrahmannasr/yadflow/commit/435225f48a21fe8a850ba65c0c7f1315df6bbb1e))
* **standup:** E132 review 5 — path names in square brackets ([7ac3cb2](https://github.com/abdelrahmannasr/yadflow/commit/7ac3cb265c309f0e707e6dae32076796a5e2c240))


### Features

* **join:** E131 join ends with yad member add ([3295429](https://github.com/abdelrahmannasr/yadflow/commit/3295429092b549707a03eecacddc50d15d1df77a))
* **member:** E131 team member files, proven by the platform ([3e60bb6](https://github.com/abdelrahmannasr/yadflow/commit/3e60bb62bb2edb467be4d5f8562b9fe1bac6ca0a))
* **standup:** yad standup — a daily status per team member (E132) ([00f32ce](https://github.com/abdelrahmannasr/yadflow/commit/00f32ce742166e8b82e796b3eef85b379edd4cee))

# [4.4.0](https://github.com/abdelrahmannasr/yadflow/compare/v4.3.0...v4.4.0) (2026-10-03)


### Bug Fixes

* **skill:** E51 review 1 — read the route the epic records, never a guess ([cefdb21](https://github.com/abdelrahmannasr/yadflow/commit/cefdb216139e4608961b83a5ec61f1ca6cb318c7))
* **skill:** E51 review 2 — say an epic's route is unknown; simplify the change-epic seed ([c5e6f0e](https://github.com/abdelrahmannasr/yadflow/commit/c5e6f0e12e56a768196088aff10d2eebd3f70293))
* **skill:** E52 flag a pick bound in place of yadflow's skill; list prints the catalogue's age ([a0b76f3](https://github.com/abdelrahmannasr/yadflow/commit/a0b76f30fd1d9fb3123977532ab0ef055daf89bf))
* **skill:** E52 review 1 — yadflow's skill must run last, plugin names, route view in list ([fcf675a](https://github.com/abdelrahmannasr/yadflow/commit/fcf675a6fe64788f3d0b2c12f8f7aad14eb6448c))
* **skill:** E52 review 2 — a bare bound name never matches a plugin-qualified pick ([4199fd3](https://github.com/abdelrahmannasr/yadflow/commit/4199fd332f36eb532f9aa4bd2a4f05a77bfa6cec))
* **skill:** E52 review 3 — a marketplace-spelled binding is the same pick ([04d7aaa](https://github.com/abdelrahmannasr/yadflow/commit/04d7aaafe640253dd0ecc48e922c993e0d7b3860))
* **toolbox:** E87 review 1 — CRLF, unseen tools, no Product, honest Repomix fallback ([dc3bd75](https://github.com/abdelrahmannasr/yadflow/commit/dc3bd7577271c5fb71fe5522e8a6d1f2c1fff575))
* **toolbox:** E87 review 10 — unclosed fence refused, frontmatter skipped ([577786c](https://github.com/abdelrahmannasr/yadflow/commit/577786c2ff939be1bf7565c9bc4f3b72d9569cd7))
* **toolbox:** E87 review 11 notes — frontmatter hides nothing, exact round trip ([b8bb924](https://github.com/abdelrahmannasr/yadflow/commit/b8bb924c5320f3fdf531f03fa968f77dc970f8c8))
* **toolbox:** E87 review 12 — a section can never cross the frontmatter ([cb1c111](https://github.com/abdelrahmannasr/yadflow/commit/cb1c11184fd2caea1e2f6b4c7082b65e5de462f3))
* **toolbox:** E87 review 13 notes — frontmatter closes at '--- ' or '...' ([df6c644](https://github.com/abdelrahmannasr/yadflow/commit/df6c644f639eaeef04b36eb1da2116b472452f39))
* **toolbox:** E87 review 14 — frontmatter needs a YAML key; no write leaves two copies ([20f3c75](https://github.com/abdelrahmannasr/yadflow/commit/20f3c75a231461d42566474d8be972e08edc59df))
* **toolbox:** E87 review 15 — check names the two-copy refusal too ([88757ac](https://github.com/abdelrahmannasr/yadflow/commit/88757acf9015dc8a8b2adae7137fdf1b8a151959))
* **toolbox:** E87 review 2 — connector-only sections, safer section finder ([00127ec](https://github.com/abdelrahmannasr/yadflow/commit/00127ecd4ae61c10cc5b34beaf32d42512d8ea05))
* **toolbox:** E87 review 3 — a removal works, a misread is refused by content ([a42bc78](https://github.com/abdelrahmannasr/yadflow/commit/a42bc78bc5a53ba1e9c17073615f9313bab3b66e))
* **toolbox:** E87 review 4 — one heading rule, a guard that quotes its line ([768b43a](https://github.com/abdelrahmannasr/yadflow/commit/768b43a7f8df84aeb1ca1d53818a421a1dca5ba2)), closes [#s](https://github.com/abdelrahmannasr/yadflow/issues/s)
* **toolbox:** E87 review 5 notes — fence-aware copy count, dividers, linear heading read ([d9eb679](https://github.com/abdelrahmannasr/yadflow/commit/d9eb6793ead27dfa9f76f60bc301a45df727a832)), closes [#s](https://github.com/abdelrahmannasr/yadflow/issues/s)
* **toolbox:** E87 review 6 — truly linear heading read, underline guard reads real headings ([83d0885](https://github.com/abdelrahmannasr/yadflow/commit/83d0885c9f8c6c216a35e740b365c6eebaca6b54)), closes [#s](https://github.com/abdelrahmannasr/yadflow/issues/s) [#hashtag](https://github.com/abdelrahmannasr/yadflow/issues/hashtag)
* **toolbox:** E87 review 7 — no slow pattern left in the section readers ([7201076](https://github.com/abdelrahmannasr/yadflow/commit/72010765951c569ea0c0cbc52b67c13f96c9f248))
* **toolbox:** E87 review 8 — a divider ends the block; the guard is checked against marked ([750187c](https://github.com/abdelrahmannasr/yadflow/commit/750187cecd34e8ff49c39e141424656781def287)), closes [#tag](https://github.com/abdelrahmannasr/yadflow/issues/tag)
* **toolbox:** E88 review 1 — refuse future and impossible vetting dates; pin every Repomix line ([20048b5](https://github.com/abdelrahmannasr/yadflow/commit/20048b562129a3860a521dc8a159cc8641dc3d9a))
* **toolbox:** E88 review 2 — install-line test fails closed; pin test covers npm install ([e955cbd](https://github.com/abdelrahmannasr/yadflow/commit/e955cbddc5d1d596c833dfb596b1536516b4d489))
* **toolbox:** E88 review 3 — a terms page that says license is not a licence file ([34edaf8](https://github.com/abdelrahmannasr/yadflow/commit/34edaf84f0a4a3d7338de1aae61964f975c6e2e3))
* **toolbox:** E88 review 4 — tell a licence file by where it lives, not its letter case ([4e9dbc0](https://github.com/abdelrahmannasr/yadflow/commit/4e9dbc0850ca9cba27ceba00e8b9dea777c1d1e6))
* **toolbox:** E88 review 5 — a repository's front page is not a licence file ([3f9fe15](https://github.com/abdelrahmannasr/yadflow/commit/3f9fe15a54a259c7c784a18b4e52e69ce50a7104))


### Features

* **skill:** E51 bind a skill for one route only ([654488c](https://github.com/abdelrahmannasr/yadflow/commit/654488c7e7d876fbe29122959f2befe1122ebffe))
* **skill:** E52 recommendation catalogue and yad skill recommend ([2b4fba0](https://github.com/abdelrahmannasr/yadflow/commit/2b4fba05a6e27af978dcaeb25fe61a0dc61c36b6))
* **toolbox:** E88 vet every toolbox tool, and pin Repomix to the vetted version ([e4026f3](https://github.com/abdelrahmannasr/yadflow/commit/e4026f3140428a6b80c1842e410c8174f5ecb205))
* **toolbox:** every skill that uses a tool declares its fallback (E87) ([8d4963e](https://github.com/abdelrahmannasr/yadflow/commit/8d4963e603e92be0fcbc616e98a5ea5939befbc4))

# [4.3.0](https://github.com/abdelrahmannasr/yadflow/compare/v4.2.0...v4.3.0) (2026-10-01)


### Bug Fixes

* **toolbox:** E85 review 1 — hint order, the folder check looks in, team-wide remove advice ([c7f6592](https://github.com/abdelrahmannasr/yadflow/commit/c7f65922cdad49e9816c4cbe81190283392c1df6))
* **toolbox:** E85 review 2 — look for tools at the top of the repo, read --dir's Product ([82fb5ed](https://github.com/abdelrahmannasr/yadflow/commit/82fb5ed6a1afcf364a9844d3faf2676bd4a84274))
* **toolbox:** E85 review 3 — a worktree is its own checkout; look at the deepest top ([4926799](https://github.com/abdelrahmannasr/yadflow/commit/4926799f6db758c7abb59029bd8e71923550c227))
* **toolbox:** E85 review 4 — find the checkout top under both spellings of a linked folder ([9728384](https://github.com/abdelrahmannasr/yadflow/commit/9728384c140178d55608d2ab2b67037a2f80140d))


### Features

* **toolbox:** offer the missing tools in setup, check, update and join (E85) ([53e06c6](https://github.com/abdelrahmannasr/yadflow/commit/53e06c6da8bf585ced68435b052d01ba4ca5e6fa))

# [4.2.0](https://github.com/abdelrahmannasr/yadflow/compare/v4.1.0...v4.2.0) (2026-10-01)


### Bug Fixes

* **toolbox:** a turned-off plugin is disabled, and ranges read only full versions (E84 review 1) ([56a9864](https://github.com/abdelrahmannasr/yadflow/commit/56a9864bf91b764b736c6da12b2d30cc1d1fd861))
* **toolbox:** add and remove report a shipped-tool edit through one function (E86 review 4) ([161ece4](https://github.com/abdelrahmannasr/yadflow/commit/161ece48cffd879fe0106747ae10698f7b5e67cf))
* **toolbox:** clearer remove and dead-copy wording (E86 review 5 notes) ([33ba0b7](https://github.com/abdelrahmannasr/yadflow/commit/33ba0b7bae11462d9b81a739df302fe20bbd2a7c))
* **toolbox:** npx before a turned-off plugin, Claude Code switches only, Windows PATH rules (E84 review 2) ([f052979](https://github.com/abdelrahmannasr/yadflow/commit/f052979a3018790c1d7c94fe5b761ce32bf15e55))
* **toolbox:** offer an undo only when the tool's use changed (E86 review 3) ([32e5105](https://github.com/abdelrahmannasr/yadflow/commit/32e5105bb83f856b9b37b8bc0e96e7bf15e396e1))
* **toolbox:** one remove clears everything under an id; add agrees with the list (E86 review 2) ([da75777](https://github.com/abdelrahmannasr/yadflow/commit/da75777496e4c705e52423c77c553f35e5c99002))
* **toolbox:** truthful edit messages, remove clears dead lines, --dir is the Product (E86 review 1) ([2159543](https://github.com/abdelrahmannasr/yadflow/commit/21595432d611e190c93d97fc707f27c432ba936f))


### Features

* **toolbox:** yad toolbox add, remove and check (E86) ([715cd4c](https://github.com/abdelrahmannasr/yadflow/commit/715cd4c6cc63ffdcfdc33c97a9d2df8078965b64))
* **toolbox:** yad toolbox list and the shipped toolbox of external tools (E84) ([3f5374b](https://github.com/abdelrahmannasr/yadflow/commit/3f5374b830c83782b884f48a7e760943bc2349d4))

# [4.1.0](https://github.com/abdelrahmannasr/yadflow/compare/v4.0.1...v4.1.0) (2026-10-01)


### Bug Fixes

* **detect:** a non-object mcpServers is a problem in every file (E50 review 3) ([d917c72](https://github.com/abdelrahmannasr/yadflow/commit/d917c7229f98c61b5904659b82ece3cf13612ce9))
* **detect:** read Codex TOML keys only, keep plugins inside their folder (E50 review 1) ([be11fd2](https://github.com/abdelrahmannasr/yadflow/commit/be11fd2fcad238f994a2a68db609ddd8db2a0c8b))
* **detect:** report plugin MCP paths that leave or miss, keep lines in order (E50 review 4) ([84c0a6a](https://github.com/abdelrahmannasr/yadflow/commit/84c0a6ae44458ba78cbc4c418b1c307090150a8e))
* **detect:** report unreadable settings and a non-object mcpServers (E50 review 2) ([a4f7f20](https://github.com/abdelrahmannasr/yadflow/commit/a4f7f20ba5728bcd33ed4a2498026ab3ef6baa43))
* **detect:** zero-width names, and a plugin that names .mcp.json itself (E50 review 5) ([6704c9d](https://github.com/abdelrahmannasr/yadflow/commit/6704c9db3ea5a03db968445ec9eb5b36922c4c55))


### Features

* **detect:** yad detect lists installed skills, agents, MCP servers and plugins (E50) ([ccd7142](https://github.com/abdelrahmannasr/yadflow/commit/ccd71428ac6e64624160b9b2cb867c4ec2522653))

## [4.0.1](https://github.com/abdelrahmannasr/yadflow/compare/v4.0.0...v4.0.1) (2026-09-30)


### Bug Fixes

* **cli:** point the error-code hint at the real error-code table ([76ee3d0](https://github.com/abdelrahmannasr/yadflow/commit/76ee3d071efc76a5029c2fc234c05eaefe31cd0b))

# [4.0.0](https://github.com/abdelrahmannasr/yadflow/compare/v3.18.1...v4.0.0) (2026-09-30)


* feat!: print Product, not hub, in output, --json and commit subjects (E124) ([b982530](https://github.com/abdelrahmannasr/yadflow/commit/b982530402dde171575407e82e72b8a2c405639a))
* feat!: read product.json first, and refuse two names that disagree (E122) ([2252296](https://github.com/abdelrahmannasr/yadflow/commit/22522969823c8a3525fa255c62a7a08c444b7450))
* feat!: rename the installed hub names to product, and name what is left (E123) ([91c62b6](https://github.com/abdelrahmannasr/yadflow/commit/91c62b6467d220a13b88970fd16b7bd42d740ffc))
* feat(checks)!: risk-route and hub-route print the approval count, not roles (E62) ([8754585](https://github.com/abdelrahmannasr/yadflow/commit/875458576c6800356980b302dd3366d0b7a5e02a))
* feat(checks)!: verified-commits checks signatures only; the author allowlist is gone (E62) ([67c0161](https://github.com/abdelrahmannasr/yadflow/commit/67c01612372f74e6c70b5af24636eae034fe34c7))
* feat(cli)!: every command answers --json in one envelope (E1) ([7862dfb](https://github.com/abdelrahmannasr/yadflow/commit/7862dfb7d496171bc5f8fa20e533ffc688c57f0e))
* feat(epic)!: shape 5 — the work-item type, and a chore may stand alone ([5eb24fb](https://github.com/abdelrahmannasr/yadflow/commit/5eb24fb04e5d6c686d92b69e4d1b8dd1ea41d46b))
* feat(gate)!: a team gate needs one approver, and approvals name the platform login (E62) ([3730b9c](https://github.com/abdelrahmannasr/yadflow/commit/3730b9cc4f58acede87f9a020ac1ded0b7cf1fdd))
* feat(gate)!: review and task PRs request no reviewers (E62) ([d9f3d76](https://github.com/abdelrahmannasr/yadflow/commit/d9f3d765cced1b50868197bf8622e891a2af0f3a))
* feat(gate)!: shape 9 — an approval's fingerprint leaves out the frontmatter status line ([226f9ec](https://github.com/abdelrahmannasr/yadflow/commit/226f9ec4b9c19bdd055a1f9094b5c95badd69864))
* feat(migrate)!: shape 8 — `yad migrate` moves the product level into foundation/ (E75) ([88e726f](https://github.com/abdelrahmannasr/yadflow/commit/88e726fe9b24737d02e2b7f32e167a60f09e6961))
* feat(setup)!: remove yad roster and stop collecting people in setup (E62) ([5eb6914](https://github.com/abdelrahmannasr/yadflow/commit/5eb69147c84aa6b83ddda2c3e394b4f183caca6a))
* feat(state)!: finish the hub to Product rename ([92a9750](https://github.com/abdelrahmannasr/yadflow/commit/92a9750e708ab130000872e09fd15ff68c4a3c00))
* feat(state)!: yad undefer re-opens a deferred step behind finished work (E41) ([518b7cc](https://github.com/abdelrahmannasr/yadflow/commit/518b7cc7c339f20cf417712b5e8da0e560312f29))
* feat(usage)!: yad usage lists people from activity, not from the roster (E62) ([0664996](https://github.com/abdelrahmannasr/yadflow/commit/0664996f4dae2f190fcd304cb259759054251a80))
* fix(docs)!: a failed docs build exits 1 and says which site failed ([381a000](https://github.com/abdelrahmannasr/yadflow/commit/381a0000754ff4eb9fec4856692d4627369d6420))


### Bug Fixes

* a broken shared registry never stops a join, and the .git check reads names as Windows does (E79 review 4) ([160ec83](https://github.com/abdelrahmannasr/yadflow/commit/160ec83512df1f6f50245f0f0f2714e7c3588230))
* a copyable hint never prints a registry name that starts with - (E81 review 10) ([8caa29d](https://github.com/abdelrahmannasr/yadflow/commit/8caa29d752d843f0ec16c1a79a030e532076cb73))
* a monorepo subfolder is present, refresh keeps to code-context, null entries are named (E81 review 1) ([f899a0d](https://github.com/abdelrahmannasr/yadflow/commit/f899a0dcb37f4f71851802c700ba02f9d2ed39c4))
* a workspace file sends only the Product's own registered repos to it, and stops the walk when it is not used (E80 review 1) ([2a01287](https://github.com/abdelrahmannasr/yadflow/commit/2a01287bb7fc30f4d2dc604273691ba20aec97e7))
* a worktree or nested repo inside a registered repo is its own checkout, never swapped for the repo's (E80 review 3) ([de05ebd](https://github.com/abdelrahmannasr/yadflow/commit/de05ebd33b5a21fe0c0d689fd9190ab99f4293c7))
* **agents:** answer Cursor in the protocol it actually reads ([d6d6175](https://github.com/abdelrahmannasr/yadflow/commit/d6d6175e71447e6ae735979631dd74802d3f0f13))
* **agents:** close the fifteen defects the deep review found ([cc42177](https://github.com/abdelrahmannasr/yadflow/commit/cc421772bceee0513a3ca30f382cdbb606de39d6))
* **agents:** close the five defects the E11 review found ([c4ca25f](https://github.com/abdelrahmannasr/yadflow/commit/c4ca25fd66d497157d2ee37707984b02f1c500b0))
* **agents:** close the four the audit had left open ([0e5dcd8](https://github.com/abdelrahmannasr/yadflow/commit/0e5dcd80a752f263a45865b3188edf57421818eb))
* **agents:** close the last three, and stop a comment claiming something false ([292a7b1](https://github.com/abdelrahmannasr/yadflow/commit/292a7b1c2b45457f230c39fc19f3db1535beb50d))
* **agents:** let the doctor see the script Cursor actually invokes ([a070911](https://github.com/abdelrahmannasr/yadflow/commit/a0709113dfca4b94608c0519157f0157060d3999))
* allow % in a URL's user and password for https only (E81 review 7) ([b1f05e4](https://github.com/abdelrahmannasr/yadflow/commit/b1f05e42453da655b0644032503fc4b6bec59db2))
* allow the file transport per URL, not per run (E81 review 4) ([fd88947](https://github.com/abdelrahmannasr/yadflow/commit/fd889479c6c99b3dbd6ac20ad0cfbdf592ec641d))
* an unreadable record is its own gate state, and the advice reads as steps (E124 review 5) ([8608e8e](https://github.com/abdelrahmannasr/yadflow/commit/8608e8ea6994607f3da8fef65b355823da257738))
* **artifact-status:** a "$" in a frontmatter value no longer corrupts the status flip ([545123a](https://github.com/abdelrahmannasr/yadflow/commit/545123a5889cf48910507872ba45607592650cd9))
* **capture:** continue origin's branch when there is no local one; name a refused push (E43 review 2) ([8e2c07d](https://github.com/abdelrahmannasr/yadflow/commit/8e2c07d32d1b6882c7b543b9b3c65f96ca67e919))
* **capture:** every git call takes the environment runCapture was given (E43) ([c347c94](https://github.com/abdelrahmannasr/yadflow/commit/c347c9460154e6b30472a3a1aae2869354a6fce4))
* **capture:** prune deleted capture branches; read [a-z] and list brackets as GitHub does (E43 review 3) ([2322dcb](https://github.com/abdelrahmannasr/yadflow/commit/2322dcb0321ff02f0ebf22ecfe61b2979236944d))
* **capture:** subfolder Products, staged-then-deleted files, a plain push, and a truer workflow scan (E43 review) ([14f0eeb](https://github.com/abdelrahmannasr/yadflow/commit/14f0eeb6e5fe9ce21bdfe5fb168ace88a41d7ad6))
* **capture:** take design-links.json and test-links.json with the artifacts (E44) ([ad4f2cf](https://github.com/abdelrahmannasr/yadflow/commit/ad4f2cfc1f134c3b17616348081795a09939049a))
* **checks:** a C-quoted path is an artifact change; warn on a rename-blind workflow (E47 review 4) ([e6af8df](https://github.com/abdelrahmannasr/yadflow/commit/e6af8df0f4dafd3ec593da44114b07c45b67f54a))
* **checks:** a claimed Contract-Change with no lock at all now FAILS ([2008eea](https://github.com/abdelrahmannasr/yadflow/commit/2008eea518b4e20052fb277301140d33a9793182))
* **checks:** a kept Product is read only when product-repo reaches nothing (E117) ([434f0c0](https://github.com/abdelrahmannasr/yadflow/commit/434f0c03d0ade65ec90f375e95cc129b59f97571))
* **checks:** a link.md's epic must be its story's own (E118) ([4f09325](https://github.com/abdelrahmannasr/yadflow/commit/4f09325f6e168db74ccc222ba0d8fc7feea30381))
* **checks:** a Product path starting with - is still walked twice (E117) ([a823dd5](https://github.com/abdelrahmannasr/yadflow/commit/a823dd56e8c13a7d94fb6874a21539fa286d97ec))
* **checks:** accept every integrity algorithm Corepack accepts in packageManager ([367947d](https://github.com/abdelrahmannasr/yadflow/commit/367947d8d9856138b531061e4b686057ee9f715f))
* **checks:** backfill-check folds every character a Mac folds into ASCII (E116) ([e913baa](https://github.com/abdelrahmannasr/yadflow/commit/e913baaf6c68e171e2e06f139c6b25bac9732b79))
* **checks:** backfill-check folds the Kelvin sign into k (E116) ([c5152c3](https://github.com/abdelrahmannasr/yadflow/commit/c5152c350ab1dd89e6906eac9433316be5ecf261))
* **checks:** backfill-check lists go through the stream, not the environment (E116) ([f2366f0](https://github.com/abdelrahmannasr/yadflow/commit/f2366f0c1433a05bae614956b66326223f2e51ab))
* **checks:** backfill-check pairs raw records, frees twins, checks links when specs are hidden (E116) ([6544926](https://github.com/abdelrahmannasr/yadflow/commit/654492634f9f65dbe702701ddaf8af038ba2beae))
* **checks:** backfill-check reads each spec by its object id (E116) ([6e44ae5](https://github.com/abdelrahmannasr/yadflow/commit/6e44ae576d547333bc1a256a1a3e473f8ddc5e1f))
* **checks:** backfill-check reads every spelling of the verified key (E116) ([81588e6](https://github.com/abdelrahmannasr/yadflow/commit/81588e62d71c60174fe678a8756d1a0806388554))
* **checks:** backfill-check reads the last verified: key, as YAML does (E116) ([36cb5cd](https://github.com/abdelrahmannasr/yadflow/commit/36cb5cda6a817b6a4d3504052058fa26c6eefb9d))
* **checks:** backfill-check reads the spec from the base and refuses links (E116) ([b63f5ac](https://github.com/abdelrahmannasr/yadflow/commit/b63f5ac706cd6155b5db63ffaf258dcd11d4269d))
* **checks:** cache the Corepack home alongside the dependency cache ([23d92bc](https://github.com/abdelrahmannasr/yadflow/commit/23d92bc8204063bbd7754bfd038585eeb6f705bb))
* **checks:** close configurable CI review findings ([6d90018](https://github.com/abdelrahmannasr/yadflow/commit/6d900183bbee5785f4ff0d5c868a6a55ce01a9b7))
* **checks:** close the gaps review 1 found in the Product and epic reads (E117, E118) ([a8d8178](https://github.com/abdelrahmannasr/yadflow/commit/a8d81780c35a651e30e51e5dcc0e30252ac50205))
* **checks:** close the gaps review 2 found in the Product reads (E117, E118) ([dcc5ea5](https://github.com/abdelrahmannasr/yadflow/commit/dcc5ea5667be4c52676656aef5723813edce4857))
* **checks:** close the gaps review 3 found in the Product reads (E117) ([fbb0768](https://github.com/abdelrahmannasr/yadflow/commit/fbb076848e5c1ba7f67ad34ff5d7b5b7d5d094e7))
* **checks:** compare the git folder as a folder, not a spelling (E117) ([2a824a8](https://github.com/abdelrahmannasr/yadflow/commit/2a824a83b4f8eb0129b1275ec8b45832d5f22d87))
* **checks:** contract-check fails a first spec whose product-repo reaches nothing (E119) ([a4738fc](https://github.com/abdelrahmannasr/yadflow/commit/a4738fce11d4b2e87ef6d03bcea865d22feb52dc))
* **checks:** contract-check folds every character a Mac folds into ASCII (E121) ([8422e70](https://github.com/abdelrahmannasr/yadflow/commit/8422e70e192f15c26053a94ccbf2ecb8c658d720))
* **checks:** E114 review 1 — one odd name per test, split lines, full hint ([df9f4dc](https://github.com/abdelrahmannasr/yadflow/commit/df9f4dcaf5736bfbd93a49c017ffae257e2b4ef6))
* **checks:** fail with guidance when corepack is missing for a declared packageManager ([3a9f576](https://github.com/abdelrahmannasr/yadflow/commit/3a9f5760bcca050d87008e414b856d5b307f30b8))
* **checks:** fold the long s into specs; say a file is a file (E115 review 2) ([373ba16](https://github.com/abdelrahmannasr/yadflow/commit/373ba16c81bc3c0eb5c56bb7adae48441b4f07a8))
* **checks:** give the same guidance when Corepack is present but stale ([0cdf4d1](https://github.com/abdelrahmannasr/yadflow/commit/0cdf4d157946d9185bfcc286ebddcdfb5d65a6aa))
* **checks:** hub-route reads whole risk tags; route output stops claiming an author check ([53bda97](https://github.com/abdelrahmannasr/yadflow/commit/53bda9717e75367940abab8ab033f3429c274e22))
* **checks:** keep a yarn/bun-declared repo with an npm lockfile on the npm path ([713e707](https://github.com/abdelrahmannasr/yadflow/commit/713e7074b6813de0e0fd6e12e970e8372a1309eb))
* **checks:** keep the gate jobs' variables off the host GitLab pipeline ([7cb2c35](https://github.com/abdelrahmannasr/yadflow/commit/7cb2c35a3011dbd8bf8d048f7aa02578ac54a1db))
* **checks:** keep the npm path when a repo carries both lockfiles ([67fbdb4](https://github.com/abdelrahmannasr/yadflow/commit/67fbdb4e2c82188b37b1d175260b48da17d5e051))
* **checks:** let a PR of step owner files alone through on a Product (E47 review 2) ([f7ff5b0](https://github.com/abdelrahmannasr/yadflow/commit/f7ff5b062a51b455a18190a31ccbd5488fe5785f))
* **checks:** list a rename by both paths in contract-check and backfill-check (E114) ([09bb4de](https://github.com/abdelrahmannasr/yadflow/commit/09bb4de3f36e0fec0eb247565fc2364a46b482b8))
* **checks:** list renames and unquoted paths in the hub-checks diff (E47 review 3) ([bc270e0](https://github.com/abdelrahmannasr/yadflow/commit/bc270e0583a7583ffccea94b9ecaa1a11498ec46))
* **checks:** make build-test-lint fail closed on a rejected package.json ([83241ee](https://github.com/abdelrahmannasr/yadflow/commit/83241eed61e4306853151e6105c0b7c8bdd06d55))
* **checks:** pass the worker cap to jest/vitest under pnpm without npm's `--` ([55db7ee](https://github.com/abdelrahmannasr/yadflow/commit/55db7eed85173472a17e7591636d7fc830a5a5b6))
* **checks:** read every NUL list with a newline in a name as ? (E121) ([2659211](https://github.com/abdelrahmannasr/yadflow/commit/2659211c94a28d52c7a25a956d8c75bab1dd61ec))
* **checks:** read package.json the way npm does before judging it ([8021c78](https://github.com/abdelrahmannasr/yadflow/commit/8021c7850d4f7d0887923165adc585fc27da260a))
* **checks:** read specs/ without case; name a failed tree read (E115 review 1) ([a9fb725](https://github.com/abdelrahmannasr/yadflow/commit/a9fb72599a5980e9f2e8307cb87eca9ae31f17ca))
* **checks:** read the changed list as bytes; check each workflow line (E47 review 5) ([edc850b](https://github.com/abdelrahmannasr/yadflow/commit/edc850b20495a13d376b6f01dc02db61658d4e27))
* **checks:** refuse a Product path inside the repo's own .git (E117) ([b726032](https://github.com/abdelrahmannasr/yadflow/commit/b7260323e1aebab247ad6367ea2bd1c6a6d4756d))
* **checks:** refuse a second spelling of contracts/ or a story folder (E115 review 3) ([debc7b6](https://github.com/abdelrahmannasr/yadflow/commit/debc7b68f8bbddf5634322228f633327aba8c50a))
* **checks:** refuse a symlink or submodule under specs/ in contract-check (E115) ([e93387a](https://github.com/abdelrahmannasr/yadflow/commit/e93387aa036cc40b9d6741291a1ef518a0d03e1b))
* **checks:** removing a contract slice under a lockless epic is allowed ([9d0b66a](https://github.com/abdelrahmannasr/yadflow/commit/9d0b66a412d19c6b222f9e3a24dbcac1a8bde4ad))
* **checks:** require lowercase Corepack digests ([4750b8b](https://github.com/abdelrahmannasr/yadflow/commit/4750b8b597bfdd4d7d2739a0525f91a2002e41a3))
* **checks:** restore dependency caching in the GitHub quality job, for pnpm too ([21c92f0](https://github.com/abdelrahmannasr/yadflow/commit/21c92f026aa590ec464eec7152af27ad2be9a49d))
* **checks:** risk-route reads an older risk-map check as "not counted", never as "nothing is high" ([a486d7b](https://github.com/abdelrahmannasr/yadflow/commit/a486d7b7b46ae95df03f3a372b72f72cc61c0e6a))
* **checks:** run the gate's lint/build/test through the pinned npm too ([8404da3](https://github.com/abdelrahmannasr/yadflow/commit/8404da326f8a19ae807c58808b6203572aadb9b4))
* **checks:** run the risk-map awk in the C locale so every awk reads bytes ([4d0d748](https://github.com/abdelrahmannasr/yadflow/commit/4d0d748e0ce575178cfa2d1a9f42df82a40caf16))
* **checks:** say what the story-spelling rule does not catch (E115 review 4) ([3d36c93](https://github.com/abdelrahmannasr/yadflow/commit/3d36c934406b148c3601c5a6bfdacd40abccbad3))
* **checks:** support configurable CI toolchains ([30557e4](https://github.com/abdelrahmannasr/yadflow/commit/30557e419a9fec5adca06a3ecb8ca09469b2a58a))
* **checks:** the first-spec FAIL fires only when the Product is not reached (E119) ([322ffe3](https://github.com/abdelrahmannasr/yadflow/commit/322ffe39fd2654aae5022898db3d3f71bd1d4f11))
* **checks:** the PR no longer chooses where the Product is read from (E117) ([68db03b](https://github.com/abdelrahmannasr/yadflow/commit/68db03b61269346a9c540f7fa39d4b37648f627b))
* **checks:** validate Corepack integrity metadata ([a6c3fd3](https://github.com/abdelrahmannasr/yadflow/commit/a6c3fd3d84a370f81477ed9b551bc29f5765296f))
* **checks:** walk the Product path again from where it really lands (E117) ([1b0726d](https://github.com/abdelrahmannasr/yadflow/commit/1b0726d04a83544beef2bdfd3aac32f395d373bd))
* **ci:** Pages write scopes move to the job; one pin per action major (review 1) ([92a51fe](https://github.com/abdelrahmannasr/yadflow/commit/92a51febd1146c7f90528855d67cfa8d1be81255))
* **ci:** pin every workflow action by commit SHA and make the default token read-only ([43254bb](https://github.com/abdelrahmannasr/yadflow/commit/43254bba2c5606831ba7328896326c83c3dd4a3e))
* **claims:** find the first capture's base in one git call, with no cap (E46 review 2) ([e4a6fcf](https://github.com/abdelrahmannasr/yadflow/commit/e4a6fcf2a33acba0c4b76b5ba54e99d740dcd1d7))
* **claims:** keep the once-an-hour memory across a push; own edits only; over-report a missing base (E46 review 1) ([7ab038d](https://github.com/abdelrahmannasr/yadflow/commit/7ab038d436fc9d46009fd31139bd7327083ebac3))
* **claims:** pin the first-capture search against the person's git config (E46 review 3) ([80db192](https://github.com/abdelrahmannasr/yadflow/commit/80db1926695f60884a47b6a72b5a79f634ac5519))
* **claims:** read the Yad-Base trailer with a pinned separator (E46 review 4) ([c026fef](https://github.com/abdelrahmannasr/yadflow/commit/c026fef2454f6a5799b6e0f8fe5a04ee6cbbad62))
* clean every printed path, one wording for the quote, and the door works from a Product subfolder (E49 review 2) ([85ea6a4](https://github.com/abdelrahmannasr/yadflow/commit/85ea6a4f5e99942aba7dd28fdd05605319cc241c))
* **cli:** a JSON refusal keeps what was done; every warning is collected (E1 review 1) ([41fce95](https://github.com/abdelrahmannasr/yadflow/commit/41fce957954e75bb64fb0ab4271270935e7dc2fc))
* **cli:** a later failure keeps its hint; every commit row has the same keys (E1 review 3) ([188b2de](https://github.com/abdelrahmannasr/yadflow/commit/188b2dec55ce8b25a9fa8fe8e471864141c1def4))
* **cli:** answer in JSON only when the running command is history (PR review 3) ([cdc8250](https://github.com/abdelrahmannasr/yadflow/commit/cdc8250b340693b5e80d8d49a26044305ec52a4a))
* **cli:** every line that names a skill asks the project, not the catalogue ([c085218](https://github.com/abdelrahmannasr/yadflow/commit/c08521818e951faddb04c4e26fe5639a70cc0f1b))
* **cli:** every sweep failure reaches the JSON; a refusal says what was committed (E1 review 2) ([dd7ef3e](https://github.com/abdelrahmannasr/yadflow/commit/dd7ef3e00713bdeba43b0870e70ac90ee4246bf7))
* **cli:** the history JSON error is exactly the documented refusal shape ([d20c9a3](https://github.com/abdelrahmannasr/yadflow/commit/d20c9a3ab7f83ed73139c62f4eb2622d8a44440d))
* **cli:** the review round — a write that ate a user's bindings, and five more ([3c63059](https://github.com/abdelrahmannasr/yadflow/commit/3c63059686c467c5a8b29367d1e7712472835b9b))
* **cli:** two more prototype holes, and yad-run reads the binding without a lane ([3a0a114](https://github.com/abdelrahmannasr/yadflow/commit/3a0a1146e2b50154a294cd8ae0e30dc0e4a2ee58))
* clone a registered repo only from a network address (E81 review 3) ([1582784](https://github.com/abdelrahmannasr/yadflow/commit/15827845f14329d1d592a01d68b8f3a9b122e19c))
* close the last one-key product.json hints, and refuse before touching .gitignore (E122 review 3) ([2b10f5b](https://github.com/abdelrahmannasr/yadflow/commit/2b10f5bd7568c5121adf72d5ab1f6e832c1029f9))
* **codeowners:** a GitLab heading's unreadable default owners are reported (E68 review 3) ([cd9a1f1](https://github.com/abdelrahmannasr/yadflow/commit/cd9a1f1c6628040ccf3c35efad0c49185039e73e))
* **codeowners:** a path typed in another case is still the top folder; a refusal is JSON under --json (E69 review 5) ([397ccaf](https://github.com/abdelrahmannasr/yadflow/commit/397ccaf9efdf8b6807a04721a2bd726b49398863))
* **codeowners:** a pattern crosses a folder name holding a line break; no set copy per rule (E69 review 3) ([7341d79](https://github.com/abdelrahmannasr/yadflow/commit/7341d79080cc0d5558929869afbbfb812f84853e))
* **codeowners:** an exclusion's extra words are not an owner problem; describe the GitLab defaults rule ([4f50303](https://github.com/abdelrahmannasr/yadflow/commit/4f50303ac1fa9d50ad830a1c3ff7813f2a39bfc5))
* **codeowners:** exact dead-line answer for escaped characters; fast for every common shape; refuse --write= (E69 review 2) ([c52b17d](https://github.com/abdelrahmannasr/yadflow/commit/c52b17db4ba7829bd59497cd60a8e00eb52c839f))
* **codeowners:** no address in a not-read reason; fast dead-line check; exact file name; top folder only (E69 review 1) ([036f907](https://github.com/abdelrahmannasr/yadflow/commit/036f9078f09f220a45de5f10a44bb9998a3c8a9d))
* **codeowners:** read the file list only when a CODEOWNERS exists; a list git cannot produce is not known ([a2f0cc8](https://github.com/abdelrahmannasr/yadflow/commit/a2f0cc8a626be7720aaf3b7c99118a93a34ff002))
* **dial:** close the holes the E34 review found ([2038d19](https://github.com/abdelrahmannasr/yadflow/commit/2038d19bf596ae958e3b51fb2b0bc3b2fbbd4860))
* **docs:** a new yad release no longer marks every docs site stale ([bdbbff1](https://github.com/abdelrahmannasr/yadflow/commit/bdbbff1eaaf7d89e7582d43dbbc11df52de84bd4))
* **docs:** only a deploy where every site built ends on a tick (review 2) ([68251be](https://github.com/abdelrahmannasr/yadflow/commit/68251beb3d9208011481e77587ba4ffc46d923cf))
* **docs:** raise the docs shell version to 0.0.2 for the brace-expansion bump ([74498a5](https://github.com/abdelrahmannasr/yadflow/commit/74498a545b96923b5096b7adf06631e96ae7e616))
* **docs:** the review round — right site folder, a real test, no green tick after a failed deploy ([9f868d8](https://github.com/abdelrahmannasr/yadflow/commit/9f868d8332679ab437c49b8e07fc3a5d15534faf))
* **doctor:** "on every change" also when a scoped rule could not be read (E70 review 6) ([36e52ff](https://github.com/abdelrahmannasr/yadflow/commit/36e52ffd80b74a43404924f1b8aab9a0133ec8b6))
* **doctor:** a 404 on a list never means "they do not exist" (E70 review 27) ([8bdf98f](https://github.com/abdelrahmannasr/yadflow/commit/8bdf98f64dbb1924768d161d8019813e4aecf7f4))
* **doctor:** a 404 on the rules is a host without rulesets, not a permission (E70 review 28) ([f80f92d](https://github.com/abdelrahmannasr/yadflow/commit/f80f92d4c468195730ef1a9c28089fb07dfbcf28))
* **doctor:** a belief from a 404 may remove an offer, never add certainty (E70 review 30) ([a3f653d](https://github.com/abdelrahmannasr/yadflow/commit/a3f653d15514a7842cadefcd16772235df7dfee9)), closes [#7386](https://github.com/abdelrahmannasr/yadflow/issues/7386) [#29576](https://github.com/abdelrahmannasr/yadflow/issues/29576)
* **doctor:** a branch yad cannot read settles nothing (E70 review 24) ([8d9a46a](https://github.com/abdelrahmannasr/yadflow/commit/8d9a46a1a2826b09634fcfdbce4e820e94882392))
* **doctor:** a colon, not a second dash, in the GitLab sentence (E70 review 11) ([9d8c835](https://github.com/abdelrahmannasr/yadflow/commit/9d8c83525a69945753250f9acbedbe469dcc609a))
* **doctor:** a floor counts rules, not labels (E70 review 23) ([3f7d124](https://github.com/abdelrahmannasr/yadflow/commit/3f7d124d6698973d599da54bf64724f4fb8bf23a))
* **doctor:** a GitLab rule with no name reads as "an approval rule" (E70 review 12) ([5ada04a](https://github.com/abdelrahmannasr/yadflow/commit/5ada04abb6356099a81280a910bc181a09b37dae))
* **doctor:** a hint hedges wherever its own message does (E70 review 31) ([e256f06](https://github.com/abdelrahmannasr/yadflow/commit/e256f06c50db96cfbab79dda4e91a63fcf91c456))
* **doctor:** a pointer only where something was unread, and numbers that agree (E70 review 16) ([2ff23f5](https://github.com/abdelrahmannasr/yadflow/commit/2ff23f53b12d0fa3f5d5d00766a90c4333d6dd80))
* **doctor:** a protection line states only what the platform answered (E70 review 3) ([453f646](https://github.com/abdelrahmannasr/yadflow/commit/453f6463040578c297c46f4cd22ba0521860c27f))
* **doctor:** a read that answered nothing says so, and one source is named once (E70 review 22) ([25eabe8](https://github.com/abdelrahmannasr/yadflow/commit/25eabe8d02778514bafdbf25b3698caac6a4b2f5))
* **doctor:** a rule keyed on a wording must say when it stops firing (E70 review 32b) ([6beeb6f](https://github.com/abdelrahmannasr/yadflow/commit/6beeb6f8c3c1f72f30c869559b763f6e3a6097e0))
* **doctor:** a sentence for a count read beside a protection that was not (E70 review 8) ([8421b00](https://github.com/abdelrahmannasr/yadflow/commit/8421b0060e54308632bbfacaf89149eabb9da98c))
* **doctor:** an id reads as an id, and no sentence pairs two dashes (E70 review 13) ([8a07f2b](https://github.com/abdelrahmannasr/yadflow/commit/8a07f2bd8b99785ed3bcdf192269113c7ac038c4))
* **doctor:** apply round 16's fixes to their twins as well (E70 review 17) ([f99db88](https://github.com/abdelrahmannasr/yadflow/commit/f99db8823e34dce8eb84c3bde8f87c04385d0f7f))
* **doctor:** ask for --overwrite-local only when a plain --fix would not do (E120 review 8) ([5950b89](https://github.com/abdelrahmannasr/yadflow/commit/5950b89def883390bafc0c3922ce4ad65d2f3131))
* **doctor:** compare artifacts the way every reader of the field does ([75688d9](https://github.com/abdelrahmannasr/yadflow/commit/75688d9208608c1626cbfdbcb274b0e2f3960979))
* **doctor:** decide the record's ahead/behind state by git, in one table (E120 review 5) ([1739cc5](https://github.com/abdelrahmannasr/yadflow/commit/1739cc5afff34d638376215c6da90d58aaf191bb))
* **doctor:** give the missing-default hint E109's two repository actions, from one string (E110) ([2e751a9](https://github.com/abdelrahmannasr/yadflow/commit/2e751a984e18a1faa007caee0488b11454292c33))
* **doctor:** judge an off-branch clone's record as it will be after the switch (E120 review 9) ([39025bd](https://github.com/abdelrahmannasr/yadflow/commit/39025bd09c92870aacdcacca38cb3906c29da502))
* **doctor:** name `gate repair --push` for a stranded step on a verified Product (E48 review 3) ([29f0340](https://github.com/abdelrahmannasr/yadflow/commit/29f0340be0d0bef0f5e3d40a18d0da645e352b80))
* **doctor:** name a product-link record committed but never pushed (E120 review 3) ([4db532a](https://github.com/abdelrahmannasr/yadflow/commit/4db532a2712670e63f6caba85aeffd108ee63030))
* **doctor:** name folders under epics/ that are not valid epic ids ([1e0e4ac](https://github.com/abdelrahmannasr/yadflow/commit/1e0e4ac6357f03def0362ef5201e39e352b3a40b))
* **doctor:** never read a count or "not protected" the platform did not prove (E70 review 1) ([4800bff](https://github.com/abdelrahmannasr/yadflow/commit/4800bffbbeb8bebdf8a20f228992c82d88a98028))
* **doctor:** never rule a cause out and then offer it again (E70 review 29) ([aeef14b](https://github.com/abdelrahmannasr/yadflow/commit/aeef14b152e6941e7681901ce633e87339b1435a))
* **doctor:** no silence over a broken record, and hints that work off the default branch (E120 review 6) ([97c714b](https://github.com/abdelrahmannasr/yadflow/commit/97c714b66429f3a9731fd0d853ab20fcaaff75f4))
* **doctor:** one clear step per repo in the product-link hint (E120 review 7) ([c117c3d](https://github.com/abdelrahmannasr/yadflow/commit/c117c3d2aa737df27c2a3167e2001dd8454654aa))
* **doctor:** point the legacy BMAD hints at what still works (E3) ([60df2dc](https://github.com/abdelrahmannasr/yadflow/commit/60df2dc168751f27bd6a892698f211550abd18b6))
* **doctor:** read a gate one bash command at a time (E114 review 2) ([06d3f69](https://github.com/abdelrahmannasr/yadflow/commit/06d3f69113e3b19f3b9cee1cf77a637999372775))
* **doctor:** read the GitLab branch itself; a rule on an unprotected branch is no hold (E70 review 2) ([90d8df9](https://github.com/abdelrahmannasr/yadflow/commit/90d8df9581ba9c7f21b528fc119a4fb00e75a774))
* **doctor:** restore a guard I wrongly called unreachable (E70 review 18) ([dabd9a1](https://github.com/abdelrahmannasr/yadflow/commit/dabd9a1042da5db52e51c48ba5671e833269ed87))
* **doctor:** satisfy eslint — split on ** instead of a NUL placeholder; no useless assignment (E43) ([aad5822](https://github.com/abdelrahmannasr/yadflow/commit/aad582240fa0b8f4a279b0221100fba967ced20d))
* **doctor:** say GitHub's flag the same way everywhere; fill the level table (E70 review 9) ([dca372b](https://github.com/abdelrahmannasr/yadflow/commit/dca372bd289461235cab097b08e87561f5f3c0c6))
* **doctor:** say only what this read leaves possible (E70 review 15) ([328cf0a](https://github.com/abdelrahmannasr/yadflow/commit/328cf0a6a32de5805b60f6f33ff159ba1c8c5d90))
* **doctor:** say the GitLab repository could not be read, not that your login cannot (E109) ([3a8ffa5](https://github.com/abdelrahmannasr/yadflow/commit/3a8ffa583d6ac7f15270a9c217c77be5700b585c))
* **doctor:** see a step that carries ONLY the new dial name ([8ad471f](https://github.com/abdelrahmannasr/yadflow/commit/8ad471f2d90ef4d90df6016b92b4064ce867631b))
* **doctor:** stop the theme checks reporting correct files ([c6c3a0c](https://github.com/abdelrahmannasr/yadflow/commit/c6c3a0c278ccad2734061e1bd04fbb8b578431f6))
* **doctor:** tell the two reach gaps apart, and check every partly read line (E70 review 25) ([31dcf1d](https://github.com/abdelrahmannasr/yadflow/commit/31dcf1d5fd0a6e7f55dc4ee249b9c9f277b00500))
* **doctor:** tell unpushed, on another branch and behind apart (E120 review 4) ([9356748](https://github.com/abdelrahmannasr/yadflow/commit/935674881340e9c47aaba04b77196b343368cd64))
* **doctor:** test the GitLab repository 404 on the shape GitLab really sends (E109) ([81f4001](https://github.com/abdelrahmannasr/yadflow/commit/81f4001f518ea9cd65f31bb93f265176244408a9))
* **doctor:** the banner needs no rule at all, and lint is green again (E70 review 5) ([7830496](https://github.com/abdelrahmannasr/yadflow/commit/783049648722440999cde7ca079f6d61f0cff536))
* **doctor:** the clause binds to the rule, not to the branch it names (E70 review 26) ([4ea1403](https://github.com/abdelrahmannasr/yadflow/commit/4ea140368d7d71451204f49304b71fba52c4bbf7))
* **doctor:** the joined GitLab phrase reads as a sentence (E70 review 10) ([f81a423](https://github.com/abdelrahmannasr/yadflow/commit/f81a423bf0b5a672e0441ebfa04f2ac3e7fd18d3))
* **doctor:** the last paired dashes, and a limit narrower than the code (E70 review 14) ([d67ae31](https://github.com/abdelrahmannasr/yadflow/commit/d67ae3144e6735db23e73b9a9daa54e29e99a0a4))
* **doctor:** the review round — a finding whose only remedy always failed ([2783186](https://github.com/abdelrahmannasr/yadflow/commit/27831861756450ed0067271a80f08062e3c35b44))
* **doctor:** the solo line carries the same facts; hedge what is not read (E70 review 4) ([7019585](https://github.com/abdelrahmannasr/yadflow/commit/7019585ec60deaa28f4217f52a531c8e2943e8fa))
* **doctor:** the split turns on what the read proved, not where the name came from (E70 review 32) ([3930636](https://github.com/abdelrahmannasr/yadflow/commit/3930636ea87f92275c19fa6751c4a5be1ba074c5))
* **doctor:** the tier framing belongs to a refusal, and the grid reaches every branch (E70 review 21) ([c2377ef](https://github.com/abdelrahmannasr/yadflow/commit/c2377ef37fd0ae9e11f9b6d7b4454c3db23c8e4c))
* **doctor:** two answers that disagree are not known; a rule elsewhere is not "no rules" (E70 review 7) ([b002fd8](https://github.com/abdelrahmannasr/yadflow/commit/b002fd89fe9d95b402cb422e7491093b89510b4d))
* drop the exact registry path from the warning, and clean C1 control characters too (E79 review 7) ([c70911c](https://github.com/abdelrahmannasr/yadflow/commit/c70911c5e199b2433325e3a4996b3fe240be42ad))
* **e120:** a record is ok only when committed as it stands (review 2) ([f2fc7de](https://github.com/abdelrahmannasr/yadflow/commit/f2fc7dec1435d009ead6966c831d4aa409871306))
* **e120:** a record right on disk reads ok, and --push still commits it (CI) ([a5cd7f5](https://github.com/abdelrahmannasr/yadflow/commit/a5cd7f541283a6715cc012bd57194f0684e2cdc8))
* **e120:** commit the record for sure, keep secrets out, keep local runs checking ([e96ed5d](https://github.com/abdelrahmannasr/yadflow/commit/e96ed5dc8b87938097fb35270d4b677c456377e3))
* **engine:** drop the profile field nothing read, and fix the test seam ([07af526](https://github.com/abdelrahmannasr/yadflow/commit/07af526629684ee5b5c53438b13e2983ccb82bfc))
* **epic:** close the holes the E42 review found ([574870f](https://github.com/abdelrahmannasr/yadflow/commit/574870f0d6ebfe1d0c5501daa74a7927662fc13e))
* **epic:** protect the reserved front-zero id, and stop a false type clash ([871f763](https://github.com/abdelrahmannasr/yadflow/commit/871f763bbf0df4ca92f4991b1456db00bb2aecec))
* every doctor command to copy takes registry text as one plain word (E81 review 11) ([e2d147a](https://github.com/abdelrahmannasr/yadflow/commit/e2d147addb163f5397b054f1e84b506b1732668c))
* **fold:** fold a staged deletion; refuse mid-merge and on a detached HEAD (E44 review 1) ([4391b1b](https://github.com/abdelrahmannasr/yadflow/commit/4391b1b1eb6d22990b672a0d3f64b5fb5e77c5ec))
* **fold:** name a case-only rename only when git shows the new spelling (E44 review 4) ([2a6395c](https://github.com/abdelrahmannasr/yadflow/commit/2a6395c7f9ae7c7d9ee8bf1877e4cb770b2197c0))
* **fold:** never run git add with an empty list; refuse a git rm --cached path (E44 review 2) ([cfbaefc](https://github.com/abdelrahmannasr/yadflow/commit/cfbaefc9d8334a20ddbd585b9c2c25a0d31992f7))
* **fold:** tell a case-only rename from git rm --cached (E44 review 3) ([a374fc3](https://github.com/abdelrahmannasr/yadflow/commit/a374fc314f266354cdf96200b54dfa631423d4c2))
* **fold:** the Product level is seeded under either spelling; truer words (E44 review 6) ([c711326](https://github.com/abdelrahmannasr/yadflow/commit/c71132643b8c3ca1fb1d0b5c3a4739d0b18209dd))
* **fold:** the verified seed rule asks ledger-guard's own question; a change-epic's seed rides along (E44) ([f0ee36d](https://github.com/abdelrahmannasr/yadflow/commit/f0ee36d60bad06ac0920b64d97bf16e9f19a7a06))
* **foundation:** close the holes the roadmap-status review found ([69392d4](https://github.com/abdelrahmannasr/yadflow/commit/69392d441b4212448e0e3092eb74dc313e1f19b2))
* **foundation:** skills that hand-apply the gate know the Foundation, and the preview lists every moved file ([8e20897](https://github.com/abdelrahmannasr/yadflow/commit/8e20897d56c4c047d207fffdd7a644ebb81ae149))
* **foundation:** the review round — one product level in the guard, and a move that cannot strand ([5bca4ba](https://github.com/abdelrahmannasr/yadflow/commit/5bca4baded95a108018a780fd0c6ec06f1b3c62b))
* **gate:** `gate status` counts approvals the way the gate counts them ([eda7429](https://github.com/abdelrahmannasr/yadflow/commit/eda7429d6454f93c3ce034456ab61ab6b5afa3a7))
* **gate:** `gate status` prints the shortfall, and honours a skip only where the gate does ([95c9c2a](https://github.com/abdelrahmannasr/yadflow/commit/95c9c2a49adfcea6f4e8daf13932d386d4c5a75a))
* **gate:** a hand-edited cap below 1 is not printed; the inherited test says what it checks (E72) ([49dcef7](https://github.com/abdelrahmannasr/yadflow/commit/49dcef760aa00a46ec157cba2f78b90f9103b77f))
* **gate:** a malformed record in the merged review's own epic no longer stops the merge ([24eec39](https://github.com/abdelrahmannasr/yadflow/commit/24eec393e6b8ddbdefe71944c0045bbccda2dc16))
* **gate:** a round keeps the fingerprint it opened with; one spelling across approvals and comments (E112 review 2) ([d7dbe57](https://github.com/abdelrahmannasr/yadflow/commit/d7dbe57d507f5c798236715e55b70ef42f273dbe))
* **gate:** a shared roster name is never matched by name; gate open stamps the old PR (E62) ([a2b15eb](https://github.com/abdelrahmannasr/yadflow/commit/a2b15eb0d4519a05abe77ebb2ff64b6039ce9ea9))
* **gate:** a short-lane review PR does not ask for a contract re-lock it cannot do ([4855f3a](https://github.com/abdelrahmannasr/yadflow/commit/4855f3afaf90a885d3e1ae1c4d1d133857d6d142))
* **gate:** an exact submission time beats the roster name table; usage and doctor follow the simulation ([4d2c55c](https://github.com/abdelrahmannasr/yadflow/commit/4d2c55c45c7409942287a1b8834f2c58da756e5d))
* **gate:** an exact submission time continues only that review's records, never the whole name ([beaa5e3](https://github.com/abdelrahmannasr/yadflow/commit/beaa5e35a3aa77e85207b00d271885bddbd69e39))
* **gate:** approve keeps the review record; one spelling per person; a round is one version (E112 review) ([6f44c18](https://github.com/abdelrahmannasr/yadflow/commit/6f44c1887ae2c846bdcd1c14cf276624a2be91b6))
* **gate:** claim and keep older records per review, so a closed step never deletes the other person's history ([1ed2070](https://github.com/abdelrahmannasr/yadflow/commit/1ed2070779055ccf610c0ad0012978183c7b08d0))
* **gate:** close the gaps the E18 review found ([69aa2cf](https://github.com/abdelrahmannasr/yadflow/commit/69aa2cfcf88db681dfb08cc89a200ef58a23a88a))
* **gate:** close the holes the E76 review found ([e460fb2](https://github.com/abdelrahmannasr/yadflow/commit/e460fb21f8efd9eb34ef1569361973a8297f3321))
* **gate:** eighth review round — "after the cap", one dead branch, two comments (E73) ([62e47c3](https://github.com/abdelrahmannasr/yadflow/commit/62e47c3181908e49bc69407775b51ad49951f083))
* **gate:** fifth review round — an approval anywhere is evidence, and every what-if line is conditional (E73) ([5b78858](https://github.com/abdelrahmannasr/yadflow/commit/5b788587187cdce397d36bb9efdbd772cadaaefc))
* **gate:** fourth review round — the floor wording on every surface, and a cap only ever lowers (E72) ([81dc0d8](https://github.com/abdelrahmannasr/yadflow/commit/81dc0d866118b167ca18d40531abf3ba53a856e8))
* **gate:** fourth review round — two kinds of line, each said once, and the GitLab gate bot is not a person (E73) ([622c6d6](https://github.com/abdelrahmannasr/yadflow/commit/622c6d66d35df22fde619e09cd69c0dc6de97e3d))
* **gate:** keep people under a shared roster name apart; read the PR number from its own segment ([b30ba90](https://github.com/abdelrahmannasr/yadflow/commit/b30ba9051a8a4d291b70bad18f47807ac4fee21b)), closes [#2048](https://github.com/abdelrahmannasr/yadflow/issues/2048)
* **gate:** old approvals stay with their person in every platform order (E62 review) ([8379656](https://github.com/abdelrahmannasr/yadflow/commit/83796566ca4f35452e717b63b9f08c7caf081d4f))
* **gate:** recognise old approvals exactly, and never pass one that is stale (E62 review) ([58fe6d2](https://github.com/abdelrahmannasr/yadflow/commit/58fe6d295dbfaa795f771c79e1be1f6f0a052800))
* **gate:** review round — the names check needs a login, and sees a team of one that reads as two (E73) ([65512d0](https://github.com/abdelrahmannasr/yadflow/commit/65512d0decc079c0a76867b8b05065fe3baef37f))
* **gate:** round-2 review — singular in open-pr's cap, and doc/test wording that still read as enforced (E72) ([64323b0](https://github.com/abdelrahmannasr/yadflow/commit/64323b0695792c7c9e6dc6ccc97fb56f516ff76a))
* **gate:** second review round — the silent-path test compares ledgers; doc conditions stated whole (E73) ([5580624](https://github.com/abdelrahmannasr/yadflow/commit/5580624d87dcf685eba6cdb2403ffce112b28974))
* **gate:** seventh review round — the smallest team is the larger of the logins and the names (E73) ([bcbdb32](https://github.com/abdelrahmannasr/yadflow/commit/bcbdb32d3a1d8646999e183aed3b67a481a3ad7d))
* **gate:** show the capacity cap and hold on the base alone until E73 (E72) ([3da8498](https://github.com/abdelrahmannasr/yadflow/commit/3da849895011ff19d1368499d825a2b9723a5583))
* **gate:** sixth review round — "no approval" names the window, and a name is "not matched to a login" (E73) ([d592818](https://github.com/abdelrahmannasr/yadflow/commit/d592818b24d4e78d9bf3563398a45fef87447d92))
* **gate:** the login stamp merges only proven reviews and never stops a merge ([5c80ce9](https://github.com/abdelrahmannasr/yadflow/commit/5c80ce95a0852fcb2d593c0edf7aac80d54f50fd))
* **gate:** the product-level move waits for its review, a clean checkout, and the default branch ([91193be](https://github.com/abdelrahmannasr/yadflow/commit/91193be19f652db23f6229026db9d81df0f5db4b))
* **gate:** the review-PR body is the one surface where the count LASTS, so the line dates itself ([6b378fc](https://github.com/abdelrahmannasr/yadflow/commit/6b378fc28a23543da2b67bc1bf27f07f29bded46))
* **gate:** third review round — no cap on a shortcut pass, one copy of the cap's words (E72) ([81d86c8](https://github.com/abdelrahmannasr/yadflow/commit/81d86c86cea311a66c6658ac951371cc82b9e405))
* **gate:** third review round — the silent-path test compares the PR records too; one prefix on every site (E73) ([7b3d874](https://github.com/abdelrahmannasr/yadflow/commit/7b3d874c207f103479dc5df84a398cec1ca9fbf4))
* **history:** a printed [@word](https://github.com/word) is always a real login; GitLab defaults only for an ownerless entry (E68 review 4) ([cadd82b](https://github.com/abdelrahmannasr/yadflow/commit/cadd82bf43c8adecde2aa5aab1dc156f7b7bf708))
* **history:** count as the gate counts; keep a thread's root; print every field safely (E20 review 2) ([a539bfc](https://github.com/abdelrahmannasr/yadflow/commit/a539bfc595d22bd5e574e04b02d7f1fbcd2efae6))
* **history:** follow the real thread, print only safe text, judge approvals as gate status does (E20 review) ([2654480](https://github.com/abdelrahmannasr/yadflow/commit/265448010a526656ef818f710ed2e7e63e7f682c))
* **history:** name an approver by the gate's test; refuse every flag it does not take (PR review 2) ([406dce6](https://github.com/abdelrahmannasr/yadflow/commit/406dce685068993e7e187dbd76e107c6897f0468))
* **history:** second-review findings for E68, and E67's address-shaped name ([86e34c0](https://github.com/abdelrahmannasr/yadflow/commit/86e34c025dd37e397f16e22fac35485cf52ccaa6))
* **history:** the whole-PR review — strict settings, JSON refusals, shape done, exact search (E20) ([e9e13ed](https://github.com/abdelrahmannasr/yadflow/commit/e9e13ed4202c723fe3563be4cd254981ecdeb14c))
* **history:** waive a step by the gate's own test, not its final state (E20 review 3) ([dd5665e](https://github.com/abdelrahmannasr/yadflow/commit/dd5665ede9f4fec14a2b20425e5a59e12cf78009))
* **hook:** fail open under sh -e, follow no GIT_DIR, and name the repair that commits (E48 review 1) ([2991086](https://github.com/abdelrahmannasr/yadflow/commit/29910861d1c76763f765b2483ea412e8eba5d899))
* **hooks:** advice for a stuck old entry that is true in every case (E113 review 7) ([6d7fff1](https://github.com/abdelrahmannasr/yadflow/commit/6d7fff14a4a3d5bd1cb99b5bd0484cd292a0f109))
* **hooks:** give a local-ledger guard entry advice that works at apply too (E113 review 6) ([d26b241](https://github.com/abdelrahmannasr/yadflow/commit/d26b241af186961a40ca50dac289e3d6e230e1f8))
* **hooks:** judge an old hook script against the files as this run leaves them (E113 review 2) ([9a5df22](https://github.com/abdelrahmannasr/yadflow/commit/9a5df224c6e7322a6aebcc9a78b57afee1a2f59a))
* **hooks:** keep an old hook script until its new entry is committed (E113 review 1) ([c4fb5b3](https://github.com/abdelrahmannasr/yadflow/commit/c4fb5b37e3171604be7376e793cebd0eb194f14b))
* **hooks:** name what keeps an old hook script, and read HEAD once (E113 review 3) ([f1b95fc](https://github.com/abdelrahmannasr/yadflow/commit/f1b95fc2f135c5f4572d9e21b32e614a1ef77565))
* **hooks:** one sentence of advice for a stuck old hook entry, at plan and apply (E113 review 5) ([ab22b93](https://github.com/abdelrahmannasr/yadflow/commit/ab22b9348b659130fc1237786a4d6766919a580f))
* **hooks:** tell a capture-off Product to remove a stuck capture entry (E113 review 8) ([353053a](https://github.com/abdelrahmannasr/yadflow/commit/353053a017c5a0dad46c881abead93d65a9a704b))
* **hooks:** tell a local-ledger Product to remove a stuck guard entry (E113 review 4) ([0e1eaa5](https://github.com/abdelrahmannasr/yadflow/commit/0e1eaa5009f8cd06c39832faa9642ece7881e17b))
* **hook:** the agent's refusal gets the same fixes, and doctor names a hook git skips (E48 review 2) ([9551b1a](https://github.com/abdelrahmannasr/yadflow/commit/9551b1a4166bd4174a6a35f6655bbf5e805d3b90))
* **hub-bridge:** the gate-sync fragments ship the major their release publishes ([01ac858](https://github.com/abdelrahmannasr/yadflow/commit/01ac8587d5affc4e0f87c27f935b18f1342683c5))
* **index:** clean a title before unquoting it; drop bidi controls (E111 review 4) ([5ff9755](https://github.com/abdelrahmannasr/yadflow/commit/5ff97552f2af139c9634e2d398f79089ecc271a0))
* **index:** commit the index only when git holds exactly what it read (E19 review) ([1b354bc](https://github.com/abdelrahmannasr/yadflow/commit/1b354bcf4a5881aa9c74cdc028dec2562bc8418e))
* **index:** drop control characters from a title (E111 review 3) ([65ac5f7](https://github.com/abdelrahmannasr/yadflow/commit/65ac5f7c567c041c2cb027676440698ddf9e1078))
* **index:** read a double-quoted title with JSON's escapes; pin every title rule (E111 review 2) ([0a6b820](https://github.com/abdelrahmannasr/yadflow/commit/0a6b82081d63f26953c54a67af14b31ccf164674))
* **index:** read a YAML-quoted title as YAML does, keep it one line (E111 review) ([972920f](https://github.com/abdelrahmannasr/yadflow/commit/972920ffa7e462da8d79ec747060fa57d9d82b83))
* join stays inside the workspace on disk, one bad entry fails alone, and init never takes over a code repo (E79 review 1) ([56f14ae](https://github.com/abdelrahmannasr/yadflow/commit/56f14ae7f90f4eddd6618bcf6a6f7e23947e850e))
* keep every URL form's host and user to safe characters (E81 review 6) ([61370c2](https://github.com/abdelrahmannasr/yadflow/commit/61370c28a911f4d39223a6eee2df6affc27415d7))
* keep the rename's own error when writeJSON's cleanup fails (E81 review 20) ([d5b860f](https://github.com/abdelrahmannasr/yadflow/commit/d5b860f66fce3e0c99739327e8662af49ba2fed7))
* keep writeJSON's own error when the temp cleanup fails (E81 review 19) ([b8d7640](https://github.com/abdelrahmannasr/yadflow/commit/b8d7640abc5b6fde91ef0c45a05e976c134912b4))
* ledger-guard reads a missing settings file quietly, and the roster hints name the file (E122 review 5) ([d00a117](https://github.com/abdelrahmannasr/yadflow/commit/d00a117d6cd535255b44b0ec3e61a38aa1774169))
* **ledger:** the lock loop could never give up — two `continue`s skipped the cap and the sleep ([e66eab6](https://github.com/abdelrahmannasr/yadflow/commit/e66eab61910eb3b4bd7c3f9ba50f9fa9c39b5fa9))
* **lifecycle:** place an epic in Build, and keep the discovery epic off the ladder ([1c01e0c](https://github.com/abdelrahmannasr/yadflow/commit/1c01e0c8cf7aa2410b12969e43e5e45b5402edf2))
* **migrate:** name every file the apply writes, and repair a half-made pair ([a3211e3](https://github.com/abdelrahmannasr/yadflow/commit/a3211e3dfc246bbe89ef3bc322fa6be29bd735bb))
* **migrate:** the --json preview names the product config's mirror partner ([1eb4738](https://github.com/abdelrahmannasr/yadflow/commit/1eb4738c64899db78fad46036603e2fc7b71f99c))
* **mode:** close the gaps the E10 review found ([afbeca4](https://github.com/abdelrahmannasr/yadflow/commit/afbeca4599f379e0e815a3bb48e253461f9d931a))
* **mode:** only a login's approval proves a second person; one wiring for the suggestion (E74) ([0bd132f](https://github.com/abdelrahmannasr/yadflow/commit/0bd132f7664645f56dcb182c29721f7a94713245))
* name a repos.json that does not parse instead of joining with no repos (E79 review 5) ([4a952e2](https://github.com/abdelrahmannasr/yadflow/commit/4a952e2dd80ea36b33aaa37c051da1f702980585))
* name the file in the last settings hints, refuse a pair that changed, and silence a missing settings file (E122 review 4) ([5aed634](https://github.com/abdelrahmannasr/yadflow/commit/5aed63409178e36954240e37ee11e53b1ab95e04))
* name the Product from the workspace folder instead of offering a second one, and match paths as the disk stores them (E80 review 2) ([71369b3](https://github.com/abdelrahmannasr/yadflow/commit/71369b3565d273ad6a2f6eb3bd3caa8f685e75f5))
* name the settings file a person should edit, and settle all pairs or none (E122 review 2) ([ccb8de4](https://github.com/abdelrahmannasr/yadflow/commit/ccb8de49a48397c14446faebf8c3d7ef1222abd5))
* name the settings file actually read, and keep risk-map advisory (E122 review 1) ([ab4fddc](https://github.com/abdelrahmannasr/yadflow/commit/ab4fddc495433cff0d013742f02086bea94b00a9))
* name the settings file on disk, and restore the old-name fallback (E124 review 1) ([cf24871](https://github.com/abdelrahmannasr/yadflow/commit/cf248716935eaebc9961ae8e9f8d8b27a123a9d0))
* never build a login command from a host that is not a plain host name (E81 review 13) ([0a09dc1](https://github.com/abdelrahmannasr/yadflow/commit/0a09dc11e047e483ea046720a9e505078e815ae5))
* never clone or register a repo path through a .git folder, and say what --dir is for each workspace verb (E79 review 2) ([6be43a2](https://github.com/abdelrahmannasr/yadflow/commit/6be43a274b392c405454d1a09d4f49143257d100))
* never write over an edited new name, keep one workflow running, and name a gate that rejects product (E123 review 1) ([d7dc72b](https://github.com/abdelrahmannasr/yadflow/commit/d7dc72bf0857ceda09db081be1b95647a20334c2))
* **next:** an off-route step is not an unknown one, and a phase is not a passed one ([7f08da2](https://github.com/abdelrahmannasr/yadflow/commit/7f08da218463caa7f630a464ba0423bba145c746))
* one plainHost test for every login command doctor prints (E81 review 14) ([8a25d94](https://github.com/abdelrahmannasr/yadflow/commit/8a25d947353538ce7b0ffe0f399d08082e791bab))
* one samePath for a git path against a Node path, and survive a missing .git/hooks (E48 review 5) ([156ec1e](https://github.com/abdelrahmannasr/yadflow/commit/156ec1e4d9d19e5cd22e454432b1eece6fac6ced))
* one terminal cleaner for every module that prints registry text (E81 review 12) ([805a4fd](https://github.com/abdelrahmannasr/yadflow/commit/805a4fd200c2465f9a491f44e81b60ed50605946))
* only the ledger door runs from a subfolder, and the sha — not an indent — keeps :: off a line (E49 review 3) ([9878423](https://github.com/abdelrahmannasr/yadflow/commit/987842384792905cbc15db429d5d3e3da76033e4))
* **open-pr:** no address, no cross-platform join, no quiet "nobody" (E68 review) ([0d7814e](https://github.com/abdelrahmannasr/yadflow/commit/0d7814e1021dfc73845e65e7403a6ea66d2f9b6d))
* **owners:** never fold an owner file; name off-chain files in doctor (E47 review 1) ([f23f606](https://github.com/abdelrahmannasr/yadflow/commit/f23f606f220aef583500c6f2a632ee8927307b6c))
* **people:** a mistyped future approval is not proof even beside a current commit (E74) ([c1b9d7c](https://github.com/abdelrahmannasr/yadflow/commit/c1b9d7c18963133fca92e2eaaa4fdcd76676986e))
* **people:** ask git for an absolute date, so the count really does read no clock (E71) ([e065734](https://github.com/abdelrahmannasr/yadflow/commit/e0657347462310ef315068a3e9f3ba52d08b2b0a))
* **people:** close the identity question — `source: 'bridge'` is the proof, and the keyspace is namespaced ([9e055d7](https://github.com/abdelrahmannasr/yadflow/commit/9e055d711a70c2a6b6798dc5f87ec8a53be45158))
* **people:** the review round — eleven ways a partial read still became a number ([edf858e](https://github.com/abdelrahmannasr/yadflow/commit/edf858e6d3b2f5bd29877fe04517d8bcd5c4cdc8))
* **people:** validate the date git hands back — a formatter is not a validator ([dc1249a](https://github.com/abdelrahmannasr/yadflow/commit/dc1249aeae31e107eec359494b95e2230a16a4eb))
* read any spelling of the profile mapping and branch, and never a comment (E123 review 3) ([67c3a55](https://github.com/abdelrahmannasr/yadflow/commit/67c3a559ae95dae1abae8f4561d5e04b073eca02))
* record the new name a kept rename installs, and say a profile gap only when it bites (E123 review 2) ([9c99014](https://github.com/abdelrahmannasr/yadflow/commit/9c990145a68596dddfa4c2534afae18f3615efda))
* refresh never writes through a .gitignore the Product commits as a link (E81 review 16) ([5d9a982](https://github.com/abdelrahmannasr/yadflow/commit/5d9a9822d73376c5f83a6fe880dd52adf075e67a))
* refresh stops at a linked .sdlc, --push included (E81 review 18) ([e79d64c](https://github.com/abdelrahmannasr/yadflow/commit/e79d64c503d3d96e8f1005b1560d4e815ecf2820))
* refuse a clone target with a link on its way, so a committed link cannot reach .git (E79 review 3) ([667d696](https://github.com/abdelrahmannasr/yadflow/commit/667d6964e9ceed75ce0ea1fb82b03d6cf7c324ea))
* refuse a control character anywhere in a registered git_url (E81 review 8) ([6edf593](https://github.com/abdelrahmannasr/yadflow/commit/6edf5937a094a827faf02454fa2f54803b0f2cd4))
* refuse any folder holding HEAD on the way to a registered subfolder (E81 review 2) ([0471334](https://github.com/abdelrahmannasr/yadflow/commit/04713341b8b3ea5ee55d59da82b9f818d6bfe2df))
* refuse encoded C1 and bidi characters; clean the last raw registry text (E81 review 9) ([7f7721b](https://github.com/abdelrahmannasr/yadflow/commit/7f7721b636fc19ed4736c6962ae3cd67726c3007))
* **release:** install an exact npm version, not npm@latest ([0bf8981](https://github.com/abdelrahmannasr/yadflow/commit/0bf89817da64f43f91fc281d42f76883c0f1a1ef))
* **release:** let a pre-release publish past its own test suite ([70286ce](https://github.com/abdelrahmannasr/yadflow/commit/70286ce833b300d02d2781ac589d727481f5e7eb))
* **release:** refuse to ship a file-shape change as anything but a major ([173dc9a](https://github.com/abdelrahmannasr/yadflow/commit/173dc9a76453b0e5e0ec2341ad05458b71d9a085))
* **release:** the release checks ask semantic-release what a commit releases ([c5de745](https://github.com/abdelrahmannasr/yadflow/commit/c5de7453ed41bb5a6bac514652a857b6db5d7f8a))
* **risk-map:** close ten review findings in the map, its check and its command ([aafc578](https://github.com/abdelrahmannasr/yadflow/commit/aafc578c43cc2282e5aa837f3f88768cd7e5e30d))
* **risk-map:** doctor's section sat under threadChecks' comment; stale comments and help alignment ([5258b54](https://github.com/abdelrahmannasr/yadflow/commit/5258b54f352ba1d0276bec098d766e233beee77a))
* **risk-map:** every pathspec is :(literal) — a map name describes a directory, it never tells git what to do ([6a4ef28](https://github.com/abdelrahmannasr/yadflow/commit/6a4ef28bb105b3129445cef925d420863b7f271b))
* **risk-map:** first-review findings — a quoted path, a move out, an older check, and a name's own spacing ([016ad87](https://github.com/abdelrahmannasr/yadflow/commit/016ad87d050b611d69b6fb7d48a850dfac17a2a7))
* **risk-map:** first-review findings — read the base map from any subfolder, and never exit 1 on a trailing comma ([e6ac49f](https://github.com/abdelrahmannasr/yadflow/commit/e6ac49f32f5944d2beddbe3adc0b1b4ee2ca3ed7))
* **risk-map:** four second-review findings in the PR check and the file list ([c5eb332](https://github.com/abdelrahmannasr/yadflow/commit/c5eb33293b9dde0bfc0509dbcba45e94116646b0))
* **risk-map:** second-review findings — a failing git step is "not counted", and the check runs from the repo root ([c51a882](https://github.com/abdelrahmannasr/yadflow/commit/c51a882bcac73561b216e936ff495158d050782a))
* **risk-map:** second-review findings — a newline in a file name, and a merge that hid a real author ([845a341](https://github.com/abdelrahmannasr/yadflow/commit/845a341e08495cfc81dc24998e7bd80190587a62))
* **risk-map:** third-review finding — a failing git ls-tree is "not counted", not "no map" ([efeffc0](https://github.com/abdelrahmannasr/yadflow/commit/efeffc0e4bf5edfadbcc2a67fbc6b6397e1a63c5))
* **risk-map:** third-review findings — bytes for every tool in the check, and only the map itself counts as deleted ([ac4569e](https://github.com/abdelrahmannasr/yadflow/commit/ac4569ec8dba85ea39a7659e8b6038e7a1025d89))
* **setup:** compare hook folders by their long name on Windows (E48) ([8f1ac56](https://github.com/abdelrahmannasr/yadflow/commit/8f1ac5617cf50b89ca8626e5d15ec645b2ff64a5))
* **setup:** keep a team's edit to .sdlc/config.yaml through yad update (E3) ([86b2034](https://github.com/abdelrahmannasr/yadflow/commit/86b20348a08bb0a82ce5de03bad0ec5347cbc15e))
* **setup:** read a core.hooksPath typed in another case as the default folder where the disk ignores case (E48 review 6) ([997f77d](https://github.com/abdelrahmannasr/yadflow/commit/997f77d39d76c49a7e5b63845c867484fb180437))
* **skills:** teach the skill layer that `ledger` is the switch ([d4622ab](https://github.com/abdelrahmannasr/yadflow/commit/d4622ab2293cfe49a36791f6cf51472b4d5701ad)), closes [#186](https://github.com/abdelrahmannasr/yadflow/issues/186)
* **skills:** the epic.md templates were unreadable by the gates they feed ([96922de](https://github.com/abdelrahmannasr/yadflow/commit/96922de4ae3e08efe8faee2cbff5abe6c468eabc))
* **skills:** the review gate must open the gate with the engine, not by hand ([f453509](https://github.com/abdelrahmannasr/yadflow/commit/f453509cbcdd0ec7fa9156af9324eb940846efb4))
* **skills:** yad-connect-repos frontmatter parses; two descriptions fit 1024 ([d6eaf55](https://github.com/abdelrahmannasr/yadflow/commit/d6eaf558d8296dbedacab3c70f9075d497222d56))
* **skip:** close the holes the E39 review found ([33eb17a](https://github.com/abdelrahmannasr/yadflow/commit/33eb17a85f982456549b225603db04747cd27d94))
* **skip:** close the holes the verified-skip review found ([311e1ca](https://github.com/abdelrahmannasr/yadflow/commit/311e1cab3f439fc3a4752d997bdb2260ac42bf47))
* **skip:** refuse a skip on a ledger CI owns on a verified Product ([b9b2d1a](https://github.com/abdelrahmannasr/yadflow/commit/b9b2d1a54f7a31deaf75746581beb3e217611555)), closes [#162](https://github.com/abdelrahmannasr/yadflow/issues/162)
* **state:** a corrupt ledger gets an error with a hint, not a stack trace ([2cda22d](https://github.com/abdelrahmannasr/yadflow/commit/2cda22d76328e373dfc46b072385b02715529b95))
* **state:** a gate write moves the recorded shape, not just the fields ([6906c57](https://github.com/abdelrahmannasr/yadflow/commit/6906c577251d96ddf583e5fb83dfb265eb985a86))
* **state:** a short lane has no optional steps, and that is not a broken chain ([136eec8](https://github.com/abdelrahmannasr/yadflow/commit/136eec83888d5915facdf80c9dd073ff56d95513))
* **state:** close the holes the E41 review found in re-open and debt ([9b8565e](https://github.com/abdelrahmannasr/yadflow/commit/9b8565e165869f5a6b10f5c46c887bc422ce78d2))
* **state:** keep the product-level role under BOTH spellings, and report drift ([1b9ac44](https://github.com/abdelrahmannasr/yadflow/commit/1b9ac441a6055f2b17422f11c0aee0a025c7b3ba))
* **state:** make the two names one file, in both directions ([0a842c7](https://github.com/abdelrahmannasr/yadflow/commit/0a842c74560d96c47064009b3ab4714f0f00ab7f))
* **state:** one rule for "this epic's route never had that step" ([b687048](https://github.com/abdelrahmannasr/yadflow/commit/b687048e49c7bcfa4f512c7e92de31e6dce8f0d7))
* **state:** read an unstamped file as shape 1, not as the engine's shape ([6d8c608](https://github.com/abdelrahmannasr/yadflow/commit/6d8c608215175fac98933ffee6f714471454a8d9))
* **state:** shape 6 stamps against the routes that existed when it landed ([939c862](https://github.com/abdelrahmannasr/yadflow/commit/939c86228b20540ad22c621c19b63e4859899647))
* **state:** the count reports, it does not hold a gate — yet (E7 review round) ([10bc3ff](https://github.com/abdelrahmannasr/yadflow/commit/10bc3ff06816ff6430bc47b8382363d57c6b9380))
* **state:** the review round — a live writer of `blocked` this change said did not exist ([7136b93](https://github.com/abdelrahmannasr/yadflow/commit/7136b930b10bba4e8ffe03d217e706409bd5153e))
* **state:** write the work-item type at the top of state.json, not the bottom ([195c03a](https://github.com/abdelrahmannasr/yadflow/commit/195c03aa96f5c12526b22d54c4db9ad9d4a4ef63))
* **test:** strip the publisher's git identity from the whole test process ([8660f56](https://github.com/abdelrahmannasr/yadflow/commit/8660f5611f1c9f24a67eeead4302c4acca260ba3))
* the --profile hub advice names every gate in the way, in every state (E124 review 4) ([5d125ec](https://github.com/abdelrahmannasr/yadflow/commit/5d125ece69967c3c76d923da2c05decd1c500140))
* the --profile hub advice reads each gate's real state (E124 review 3) ([f00c51e](https://github.com/abdelrahmannasr/yadflow/commit/f00c51e7a4ec54bb6c126797478088c06365d746))
* the --profile hub advice waits for a gate that refuses product, and a repo named product is shown by its path (E124 review 2) ([80518c5](https://github.com/abdelrahmannasr/yadflow/commit/80518c5cbd3af2209882167bb381731190d2336a))
* the clone sets GIT_ALLOW_PROTOCOL; a local source must exist (E81 review 5) ([7963220](https://github.com/abdelrahmannasr/yadflow/commit/796322023a6bc90b541f66b3c383e34b1957c791))
* the drift advice names yad migrate --apply, and one drift lookup serves all (review 1) ([f158fa1](https://github.com/abdelrahmannasr/yadflow/commit/f158fa1f8311a71e5346dbd51ee6627a231b3dae))
* the ledger override claims only what it can see, and no control character reaches the CI log (E49 review 1) ([da7a6d9](https://github.com/abdelrahmannasr/yadflow/commit/da7a6d96cf762e7d23f5f4ae3c44c5c2e9dc195d))
* the solo people count judges each registered path before git runs (E81 review 15) ([993698a](https://github.com/abdelrahmannasr/yadflow/commit/993698a17f2496985da6b8c6160c2e9eeba83449))
* the unreadable-registry warning gives the real reason, and a null registry is named too (E79 review 6) ([9f426eb](https://github.com/abdelrahmannasr/yadflow/commit/9f426eb3697e473bde80468e0be5946de4041404))
* the unreadable-settings cell says only what is true (E124 review 6) ([5d43189](https://github.com/abdelrahmannasr/yadflow/commit/5d431894e377065ca1d26316973fd6cfabc7d3c9))
* **thread:** an epic never owns an artifact its route has no step for ([6725c5a](https://github.com/abdelrahmannasr/yadflow/commit/6725c5ae9dde8e226f34ae1e1d5888fa86811641))
* **update:** install templates newly added to a wired repo on `yad update` ([8e8d92f](https://github.com/abdelrahmannasr/yadflow/commit/8e8d92f1265e2ed375bf0a53307270a25d8c33f3))
* **update:** take only yad's own wiring as proof a repo is wired ([3c90134](https://github.com/abdelrahmannasr/yadflow/commit/3c90134985eebb3b7faa91be2c45387d54851324))
* when a file's two names disagree, the gate advice says yad migrate first (E124 follow-up) ([75d2184](https://github.com/abdelrahmannasr/yadflow/commit/75d2184480acc0d285d7718533ab9bf9d65cf723))
* writeJSON's temp file is random and exclusive (E81 review 17) ([b5cbcd9](https://github.com/abdelrahmannasr/yadflow/commit/b5cbcd935a81534b5f749eeba13c36711fb7a471))


### Documentation

* the guides, sites and diagram say Product, and a guide to the hand changes (E124) ([883cd6f](https://github.com/abdelrahmannasr/yadflow/commit/883cd6f56378dc58bbbd1a9ebdba0048a1e35c9a))


### Features

* .yad-workspace.json — yad finds the Product from any repo in the workspace (E80) ([27a7579](https://github.com/abdelrahmannasr/yadflow/commit/27a75793c558d597840d01c9f7986e25e7a5c42a))
* **agents:** support agents beyond Claude Code, and guard Cursor too (E11) ([8481398](https://github.com/abdelrahmannasr/yadflow/commit/848139856c5d23cdf52b601d02f7155d5756d9b4))
* **capture:** yad capture snapshots Shape artifacts onto private yad/wip branches (E43) ([58b0181](https://github.com/abdelrahmannasr/yadflow/commit/58b0181f72fd88e97d391e0e52a46e8b5cdf1183))
* **checks:** check the Product out in CI where the record says (E120) ([b288326](https://github.com/abdelrahmannasr/yadflow/commit/b288326da2a72c3475d0cfafd2f8bc9540d0670d))
* **checks:** guard the Foundation ledger in foundation/ (E75) ([0608e41](https://github.com/abdelrahmannasr/yadflow/commit/0608e41f8a203a633b4ef2e3449711de9201890c)), closes [#162](https://github.com/abdelrahmannasr/yadflow/issues/162)
* **checks:** guard the Product index as CI-owned on a verified Product (E19) ([5396827](https://github.com/abdelrahmannasr/yadflow/commit/5396827650597341cd98e935c595c73899b4a61f))
* **checks:** read where the Product lives from .sdlc/product-link.json on the base (E120) ([6b9e7b1](https://github.com/abdelrahmannasr/yadflow/commit/6b9e7b1f293183b89fda9d1aa9b748bcd62bb7f6))
* **checks:** risk-map-check.sh warns on every PR where the risk map went stale ([bc2ada8](https://github.com/abdelrahmannasr/yadflow/commit/bc2ada8707a9499d5ef8afcb1e4259be02980eef))
* **claims:** yad claims — who else is editing which artifact, read from the capture branches (E46) ([6668441](https://github.com/abdelrahmannasr/yadflow/commit/66684416b5d3c1a2a04b069cd35b0d7f13e55ddb))
* **cli:** add `yad skill` to bind, list and unbind a step's skill ([7b4c9c6](https://github.com/abdelrahmannasr/yadflow/commit/7b4c9c6cdc2e5734a5f670b805003782d877674f))
* **cli:** the project chooses which skill runs a step (E6) ([a07746e](https://github.com/abdelrahmannasr/yadflow/commit/a07746e327056448f1c3566490cf7d17aa13122d))
* **cli:** warn before any command reads a project on a newer file shape ([f5695da](https://github.com/abdelrahmannasr/yadflow/commit/f5695da00299169f3bdb34913aa7c90448501510))
* **cli:** yad epic new — the engine writes an epic's lifecycle (E17) ([92e67d6](https://github.com/abdelrahmannasr/yadflow/commit/92e67d635efddcadbd8f4399dac27b0c56402cbe))
* **codeowners:** warn when CODEOWNERS is stale (E69) ([6c35d6a](https://github.com/abdelrahmannasr/yadflow/commit/6c35d6a2d854e089561b708c6441616117816cf6))
* **commit:** yad commit --manual --reason, the door past the ledger hook (E49) ([5b4081a](https://github.com/abdelrahmannasr/yadflow/commit/5b4081a5bea4423c90b41a5ad676e0c5987bf0d9))
* **defer:** yad defer --debt marks a deferral owed back, reminded until paid (E41) ([b20d57d](https://github.com/abdelrahmannasr/yadflow/commit/b20d57dc85abbb8509a6298bb5c98bff66cd827c))
* **defer:** yad defer and yad undefer set an optional step aside (E37) ([b6f2391](https://github.com/abdelrahmannasr/yadflow/commit/b6f2391df9feb0f9a0b9cf5af74eb928de138767))
* **dial:** yad dial, yad kill and yad unkill — the advance dial set freely (E34) ([56e8300](https://github.com/abdelrahmannasr/yadflow/commit/56e8300c37839f6a688d821f52ceee9ea682f219))
* **doctor:** keep the access cause open when GitLab names no default branch (E110) ([ddb8159](https://github.com/abdelrahmannasr/yadflow/commit/ddb8159c792e5bddb42fa135b68e25ab5774a073))
* **doctor:** name a leftover _bmad/sdlc/ folder (E3) ([5d7b1ab](https://github.com/abdelrahmannasr/yadflow/commit/5d7b1ab4632b5712226057a7d41a796070512bae))
* **doctor:** name the cause behind a GitLab branch 404 from its body (E109) ([64865d7](https://github.com/abdelrahmannasr/yadflow/commit/64865d71a8449453e05942f0dac69ec413b5e4c0))
* **doctor:** people:roster-unused says when the roster can go ([eb0c012](https://github.com/abdelrahmannasr/yadflow/commit/eb0c012963af43a15b62dc3c229cd32f7c791a3a))
* **doctor:** say whether each repo's branch requires an approval (E70) ([e93dd3b](https://github.com/abdelrahmannasr/yadflow/commit/e93dd3b7cbe4ed52fc1d9a9a7b91613c2bfe0cf8))
* **doctor:** warn checks:backfill-blind for an older backfill-check (E116) ([bfb82cf](https://github.com/abdelrahmannasr/yadflow/commit/bfb82cf2e0d956165c179a92a0e09fb46e8e97f9))
* **doctor:** warn when a step owner file does nothing (E47) ([b189abd](https://github.com/abdelrahmannasr/yadflow/commit/b189abdbc94aa0a36041d501b9cd09c5577d5a62))
* **engine:** lifecycle profiles, with today's chains written down (E5) ([44564d4](https://github.com/abdelrahmannasr/yadflow/commit/44564d44d826265138d6fdc1f5feee5ab5760988))
* **engine:** the step catalogue, validated in code (E4) ([c3823bf](https://github.com/abdelrahmannasr/yadflow/commit/c3823bf4bed067a91496fe79c8cd490088c9e71c))
* **epic:** `yad foundation new` — the engine seeds the Product level (E75) ([2cf2241](https://github.com/abdelrahmannasr/yadflow/commit/2cf2241556d8bfef4e6682460c51ab86319024e7))
* **epic:** the grouping theme tag (E31) ([bf8a31c](https://github.com/abdelrahmannasr/yadflow/commit/bf8a31c880c445dedd1b4abb78f6314971c1cacb))
* **epic:** yad epic new --parent seeds a threaded change-epic (E42) ([3786ae2](https://github.com/abdelrahmannasr/yadflow/commit/3786ae246ec9b5759de590c72a928e33e2ad7d96))
* **fold:** yad fold <epic> <step> — one clean commit per authoring step (E44) ([a4a5285](https://github.com/abdelrahmannasr/yadflow/commit/a4a52857c2536b83d954e6a313863ecb16ecf01d))
* **foundation:** yad foundation status reads roadmap features from the epic ledgers ([e6a4a85](https://github.com/abdelrahmannasr/yadflow/commit/e6a4a853b2f31204ed687b16f0bdba3dd68c245c))
* **gate:** approvals record the platform's evidence; GitLab's approval time is read ([0e16728](https://github.com/abdelrahmannasr/yadflow/commit/0e167282349f832128757caeda10200617b0a2d7)), closes [#156](https://github.com/abdelrahmannasr/yadflow/issues/156)
* **gate:** cap the approval count at the active people less one, and record every cap (E72) ([f99e77d](https://github.com/abdelrahmannasr/yadflow/commit/f99e77da98484623d6ed1cb270dcc1dea3a08c1f))
* **gate:** every surface that reports a gate prints the arithmetic ([0ac5617](https://github.com/abdelrahmannasr/yadflow/commit/0ac56179cd49ab3d66ee2e8642500cd3f420e27c))
* **gate:** print how many people there are to ask, on every surface a gate reports itself (E71) ([cfabed9](https://github.com/abdelrahmannasr/yadflow/commit/cfabed9521d431b043ab356b46f9f54ec306a005))
* **gate:** record how a step closed (E18) ([a1c9050](https://github.com/abdelrahmannasr/yadflow/commit/a1c905037061437ecdf6183df26f246cb8cb049b))
* **gate:** record the platform login on older records while the roster exists ([cc7b02f](https://github.com/abdelrahmannasr/yadflow/commit/cc7b02f36658c5517fcc49b3f464ca1cfeeff048))
* **gate:** rename the PR ledger too, and guard both names ([c0b8b00](https://github.com/abdelrahmannasr/yadflow/commit/c0b8b00bdf77203346127984f67cce95206ba054))
* **gate:** say on the closing record when solo mode waived the approvals (E10) ([f733e5e](https://github.com/abdelrahmannasr/yadflow/commit/f733e5e10a9b8ae3c6255e4e724122e9346ac64b))
* **gate:** say when a gate may not be met — reported, never enforced (E73) ([444b67c](https://github.com/abdelrahmannasr/yadflow/commit/444b67c0e77087d286fab60bd853e1f3272320c0))
* **gate:** the gate bot converts a verified Product's product level to foundation/ ([ad3bc94](https://github.com/abdelrahmannasr/yadflow/commit/ad3bc94b0a373bd131bb1609afd6cac610aeeef8))
* **gate:** warn when a Foundation section still holds only its template (E76) ([8a5be38](https://github.com/abdelrahmannasr/yadflow/commit/8a5be38404bcb022cf9e98b10d529815d6bc4ad4))
* **gate:** yad gate approve, comment and advance for a Product with no platform (E112) ([50f7618](https://github.com/abdelrahmannasr/yadflow/commit/50f7618aae85fb269578055e5e12d33e58643fab))
* **history:** yad history — list, show, search, all with --json (E20) ([c37c9fe](https://github.com/abdelrahmannasr/yadflow/commit/c37c9fe8c346855c3a04d6921438ccaade336d3f))
* **hook:** refuse a hand commit to the CI-owned ledger with a git pre-commit hook (E48) ([e2258b1](https://github.com/abdelrahmannasr/yadflow/commit/e2258b14f9c35af5057e109713c6407fae50b068))
* **hooks:** run the agent hooks as Node scripts, so Windows works without WSL (E113) ([887ceea](https://github.com/abdelrahmannasr/yadflow/commit/887ceeadabdb4f20482c3f3a5d29963c5fe74cc8))
* **index:** `yad index` rebuilds the front door on the default branch (E19) ([5b6dfd6](https://github.com/abdelrahmannasr/yadflow/commit/5b6dfd6f3ae01a5f9409fb63e59f32dad5ab429d))
* **index:** a title for every work item, carried by the Product index (E111) ([7ab7833](https://github.com/abdelrahmannasr/yadflow/commit/7ab78334eab64153e5d5e7a31939416ff4224f19))
* **index:** build the Product index from every work item's own files (E19) ([5024d61](https://github.com/abdelrahmannasr/yadflow/commit/5024d61807a4354c6969dedf1d0d87aa01e318c2))
* **index:** the gate, CI and migrate keep the index; doctor says when it is behind (E19) ([97aba2b](https://github.com/abdelrahmannasr/yadflow/commit/97aba2be1d3c934548c195a5d8b6b1647ba8910b))
* **lifecycle:** name the six phases, derived from the step ([1b77249](https://github.com/abdelrahmannasr/yadflow/commit/1b77249c197ca70df7f95270004ca94a6b930d6a))
* **mode:** suggest team mode when the count disagrees with solo (E74) ([4756ef9](https://github.com/abdelrahmannasr/yadflow/commit/4756ef92ecedfe0dda0e5bfa3f2785a10ac6424a))
* **mode:** yad mode solo|team sets who must approve, and records the change (E10) ([ce4077c](https://github.com/abdelrahmannasr/yadflow/commit/ce4077c5055812f61736924c2f76c903acd6db66))
* **open-pr:** suggest reviewers from history and CODEOWNERS (E68) ([9214ed9](https://github.com/abdelrahmannasr/yadflow/commit/9214ed90123d55ea1fed59541df9148b0b322ed9))
* **owners:** assign an authoring step to one person (E47) ([f9f9bda](https://github.com/abdelrahmannasr/yadflow/commit/f9f9bdaf31206d8ac4c7d46b4d512f23b1e816d2))
* **people:** count active people live, three windows, unknown is never a small number (E71) ([1b186a0](https://github.com/abdelrahmannasr/yadflow/commit/1b186a0125f3b5a1ece5edc85521e0b58596fd59))
* **platform:** a record names the login gh/glab reports, not the roster's (E62) ([6c2ef4e](https://github.com/abdelrahmannasr/yadflow/commit/6c2ef4ee4df6da9e8f9000055e1aa32359ded0bc))
* **repos:** write each code repo's product-link record, and warn when it is missing (E120) ([54f1fe3](https://github.com/abdelrahmannasr/yadflow/commit/54f1fe382d884aa2e72bb56c26197dd3e8e3c5c0))
* **risk-map:** a directory to risk-level map per code repo, with yad risk-map check|draft and a doctor section ([f3d8115](https://github.com/abdelrahmannasr/yadflow/commit/f3d811547360381409560583cce2e601f1e73cc4))
* **risk-map:** a high directory asks for an approver who has worked there lately (E67) ([28f4e58](https://github.com/abdelrahmannasr/yadflow/commit/28f4e58903432d4bb1cfa7e45529ad65f840c9b6))
* **risk-map:** a high directory on the base branch's map adds the high step (E66) ([ad6fcac](https://github.com/abdelrahmannasr/yadflow/commit/ad6fcaca496c7dbc377268a9771bdf18b3737e91))
* **setup:** install the module config into .sdlc/, not _bmad/sdlc/ (E3) ([da18dac](https://github.com/abdelrahmannasr/yadflow/commit/da18dacc1b02c9dba9f1079aeb26c89286805137))
* **setup:** let a scripted setup choose its agent directories ([8c13a06](https://github.com/abdelrahmannasr/yadflow/commit/8c13a0672a231b70646501a8b780da85bf503ff6))
* **skills:** the epic and change templates carry a theme ([8b0c71d](https://github.com/abdelrahmannasr/yadflow/commit/8b0c71ddeaec9ea189e663644f7353a1a3c8246a))
* **skills:** the skills call the engine instead of writing state.json (E17b) ([f0e0d77](https://github.com/abdelrahmannasr/yadflow/commit/f0e0d77eb97ae20a929f04d5bb4d947546c3d4bc))
* **skip:** yad skip <epic> <story> --repo skips a whole Build lane (E39) ([261e73e](https://github.com/abdelrahmannasr/yadflow/commit/261e73e360bb31cc35272d7c4f6a06394b713515))
* **skip:** yad skip and yad unskip name no step (E36) ([abbb4e0](https://github.com/abdelrahmannasr/yadflow/commit/abbb4e080fc2c21c61776f555a5b1c66e2359b53))
* **state:** a chore lane and a spike lane (E40) ([f521c22](https://github.com/abdelrahmannasr/yadflow/commit/f521c22487e5ad44b029e977ae6716925f4ec731))
* **state:** a Shape author step is not a gate because it is locked (E34) ([298546e](https://github.com/abdelrahmannasr/yadflow/commit/298546ef6ef67ea1c42cf01178aecc494bd938ef))
* **state:** a step is optional because the epic's ROUTE says so (E35) ([1641b46](https://github.com/abdelrahmannasr/yadflow/commit/1641b46e6fd3b57526862ce4448c4506ccdce4ec))
* **state:** a step's gate says how many people it needs (E7) ([314e709](https://github.com/abdelrahmannasr/yadflow/commit/314e70982a0b61927c0a379516d4233c08260b99))
* **state:** every ledger walker finds the Foundation (E75) ([bf86753](https://github.com/abdelrahmannasr/yadflow/commit/bf867537d17150633faa5a9014df2c4b1e59238c))
* **state:** give the product settings their new name, keeping the old one beside it ([8d0cf1b](https://github.com/abdelrahmannasr/yadflow/commit/8d0cf1b500a6a15fcbb5e53b7806966bf1457a90))
* **state:** record who writes the ledger as `ledger: verified | local` ([6623199](https://github.com/abdelrahmannasr/yadflow/commit/66231997156bb1ffa446ebb5edd28d8ebf8def91)), closes [#186](https://github.com/abdelrahmannasr/yadflow/issues/186)
* **state:** the Product level — Foundation in the model (E75) ([676bbd1](https://github.com/abdelrahmannasr/yadflow/commit/676bbd1ae4557e0c4eb744f62f75ada74969b36b))
* **state:** the step-state model, and shape 7 writes it (E38) ([4064067](https://github.com/abdelrahmannasr/yadflow/commit/40640673adae5f2065041d92d431fdda522b6b32))
* tell a repo named product apart, and name --profile hub in the team's workflows (E124 review 1) ([98fc15d](https://github.com/abdelrahmannasr/yadflow/commit/98fc15d345354c0df83ceae7d7aa4db5765c02b2))
* **unblock:** yad unblock clears a recorded blocker (E37) ([5ba73f5](https://github.com/abdelrahmannasr/yadflow/commit/5ba73f560923fcf297ab460a82cca26ee2c1feeb))
* **update:** name an edited gate-sync fragment left on another major ([b33f9e6](https://github.com/abdelrahmannasr/yadflow/commit/b33f9e61c51101f2e5ebb9756e185ece3ce7de74)), closes [#164](https://github.com/abdelrahmannasr/yadflow/issues/164)
* yad new, yad init and yad join — the three ways into a workspace (E79) ([dcccf67](https://github.com/abdelrahmannasr/yadflow/commit/dcccf670ffb4cb376aba6af26e602140328c00ea))
* yad repo clone fetches registered repos missing on this machine (E81) ([8a20504](https://github.com/abdelrahmannasr/yadflow/commit/8a20504f816ec556e55ec5db41b8f4350973e283))


### BREAKING CHANGES

* after `yad update` renames the installed CI names, a
team's own files that name the old ones must be changed by hand — GitLab
`needs:` / `dependencies:` / `extends:` / `!reference` naming a
`yad-hub-*` job, GitHub `workflow_run:` triggers naming `yad-hub-checks`,
status badges, CODEOWNERS lines, and scripts that read `--json` names or
`SDLC_HUB_CONFIG` / `.sdlc/hub.json`. Every case, with a before and
after: docs/migrations/hub-to-product.md.
* `--json` names that said `hub` now say `product`, and
`jsonVersion` is 2. `yad doctor` check ids `hub`, `hub-git-url` and
`ci-tags:hub` are `product`, `product-git-url` and `ci-tags:product`;
`yad open-pr` answers `baseSource: "product"` and `stage:
"product-shape" | "product-tooling"`; `yad check` / `yad update` answer
`items[].scope: "product"` and `commits[].label: "product"`; and
`yad history show` answers `productConfigWhy` where it answered
`hubWhy`. The audit commits are `chore(product): …`. See the
"What moved in jsonVersion 2" table in docs/CLI.md.
* `yad update` renames the Product's
.github/workflows/yad-hub-checks.yml and .gitlab/ci/yad-hub-checks.yml to
yad-product-checks.yml, the GitLab jobs yad-hub-* to yad-product-*, and
the yad-hub-bridge skill to yad-product-bridge. GitHub job names (the
required checks) do not change. Your own CI that names an old name — a
GitLab needs:/dependencies:/extends:/!reference, a GitHub workflow_run:
trigger on yad-hub-checks, a status badge, a CODEOWNERS line — must be
changed by hand; `yad doctor` lists each by file and line (renamed-ref:).
* yadflow 4 reads .sdlc/product.json (and each epic's
product-prs.json) first; .sdlc/hub.json and hub-prs.json are read only when the
new name is absent, are still written until 5.0, and are deleted in 5.0. This
corrects docs/migrations/shape-3.md and the 4.0.0-next.1 notes, which said the
old names stay the ones read for another major. When both names exist and say
different things, every command refuses (YAD-STATE-008) and the gates fail;
run `yad migrate` to see the difference and `yad migrate --apply` (or
`--apply --keep product|hub`) to choose. Edit settings by hand in
.sdlc/product.json, then run `yad migrate --apply --keep product`. Gates now
honour SDLC_PRODUCT_CONFIG before SDLC_HUB_CONFIG.
* `yad docs build`, `yad docs deploy` and
`yad docs sync --refresh` now exit 1 when a site's npm install or build
fails, or when a site named with --epic/--overview was never generated;
`yad docs build` also exits 1 when npm is not on PATH. Under --json these
are refusals (`ok: false`) naming the site. A script that ran them and
ignored build failures will now stop.
* every `--json` answer is now the E1 envelope. `yad
history --json` carries `jsonVersion` instead of `schemaVersion`; `yad
thread --json` and the review bundles gain `ok`; `yad usage --json`
wraps the model (`--format json` still prints the bare model); a refusal
always has `error`, `code` and `hint`; `warnings` is always present. The
full list is in docs/CLI.md, "--json on every command".
* the ROUTE line of risk-route.sh and hub-route.sh
changed; anything parsing it must be updated.
* in a repo whose refreshed gate has landed, a Verified
commit from an email nobody listed now passes CI.
* `yad roster` is removed, and `yad setup` no longer
collects reviewers or repo owners.
* `yad usage --json` members carry no `role` or `rostered`,
and the `dormant` and `reviewer-not-reviewing` flags are no longer raised.
* review and task PRs no longer request reviewers
automatically.
* the owner/reviewer/domain-owner rule no longer holds a
team gate; one approver does. `defaultReviewers` and the roster shape
check are gone.
* file shape 10. An older yadflow reading a chain with a
re-opened step names that step the blocker of the work after it, and
re-opens that work when its review passes. See docs/migrations/shape-10.md.
* file shape 9. An older yadflow fingerprints the whole
file, so it reads every approval this release records on a file with a
`status:` line as stale. On a local ledger with mixed versions, that
holds an open gate for the teammate on the older release. Upgrade
everyone on the project together. A verified project runs
`yad migrate --apply` and commits the result; CI brings each state.json
to shape 9 at its next write.
* file shape 8. A migrated project keeps its product level
in `foundation/`, which a 3.x yadflow does not read. Upgrade everyone on
the project together. On a verified Product, run `yad update` so the
committed checks guard `foundation/`.
* **state:** shape 7 is the first file shape that changes a value in place
rather than adding a key beside an old one, so a 3.x CLI cannot read a migrated
project: it sees `todo` as an unknown status and reads `skipped` / `satisfied` as
"not done", which makes a UI-less epic or a change-epic look stuck. This release
reads every pre-shape-7 project correctly; run `yad migrate --preview` first and
upgrade everyone on the project. See docs/migrations/shape-7.md.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
* file shape 5. Run `yad migrate` to preview, then
`yad migrate --apply`. See docs/migrations/shape-5.md.
* project files change shape twice in this release, and both are
handled by one command. Shape 2 records who writes the ledger as
`"ledger": "verified" | "local"` in the product settings; shape 3 renames those
settings from `.sdlc/hub.json` to `.sdlc/product.json`, renames each epic's
`hub-prs.json` to `product-prs.json`, and gives every reviewer's product-level
role a second spelling. Nothing is taken away: every old name is still written
and is still the one read, so a check gate committed in your repository keeps
working whether or not you have run `yad update`. Run `npx yadflow@<version>
migrate` to preview — it writes nothing — then `yad migrate --apply`, which backs
up every file it rewrites. docs/migrations/shape-2.md and shape-3.md explain both.

Shape 2 shipped earlier as 3.19.0-next without declaring a break, which meant the
"run yad migrate first" banner never fired for it. This footer covers both.

# [4.0.0-next.4](https://github.com/abdelrahmannasr/yadflow/compare/v4.0.0-next.3...v4.0.0-next.4) (2026-09-30)


* feat!: print Product, not hub, in output, --json and commit subjects (E124) ([b982530](https://github.com/abdelrahmannasr/yadflow/commit/b982530402dde171575407e82e72b8a2c405639a))
* feat!: read product.json first, and refuse two names that disagree (E122) ([2252296](https://github.com/abdelrahmannasr/yadflow/commit/22522969823c8a3525fa255c62a7a08c444b7450))
* feat!: rename the installed hub names to product, and name what is left (E123) ([91c62b6](https://github.com/abdelrahmannasr/yadflow/commit/91c62b6467d220a13b88970fd16b7bd42d740ffc))


### Bug Fixes

* a broken shared registry never stops a join, and the .git check reads names as Windows does (E79 review 4) ([160ec83](https://github.com/abdelrahmannasr/yadflow/commit/160ec83512df1f6f50245f0f0f2714e7c3588230))
* a copyable hint never prints a registry name that starts with - (E81 review 10) ([8caa29d](https://github.com/abdelrahmannasr/yadflow/commit/8caa29d752d843f0ec16c1a79a030e532076cb73))
* a monorepo subfolder is present, refresh keeps to code-context, null entries are named (E81 review 1) ([f899a0d](https://github.com/abdelrahmannasr/yadflow/commit/f899a0dcb37f4f71851802c700ba02f9d2ed39c4))
* a workspace file sends only the Product's own registered repos to it, and stops the walk when it is not used (E80 review 1) ([2a01287](https://github.com/abdelrahmannasr/yadflow/commit/2a01287bb7fc30f4d2dc604273691ba20aec97e7))
* a worktree or nested repo inside a registered repo is its own checkout, never swapped for the repo's (E80 review 3) ([de05ebd](https://github.com/abdelrahmannasr/yadflow/commit/de05ebd33b5a21fe0c0d689fd9190ab99f4293c7))
* allow % in a URL's user and password for https only (E81 review 7) ([b1f05e4](https://github.com/abdelrahmannasr/yadflow/commit/b1f05e42453da655b0644032503fc4b6bec59db2))
* allow the file transport per URL, not per run (E81 review 4) ([fd88947](https://github.com/abdelrahmannasr/yadflow/commit/fd889479c6c99b3dbd6ac20ad0cfbdf592ec641d))
* an unreadable record is its own gate state, and the advice reads as steps (E124 review 5) ([8608e8e](https://github.com/abdelrahmannasr/yadflow/commit/8608e8ea6994607f3da8fef65b355823da257738))
* **checks:** a kept Product is read only when product-repo reaches nothing (E117) ([434f0c0](https://github.com/abdelrahmannasr/yadflow/commit/434f0c03d0ade65ec90f375e95cc129b59f97571))
* **checks:** a link.md's epic must be its story's own (E118) ([4f09325](https://github.com/abdelrahmannasr/yadflow/commit/4f09325f6e168db74ccc222ba0d8fc7feea30381))
* **checks:** a Product path starting with - is still walked twice (E117) ([a823dd5](https://github.com/abdelrahmannasr/yadflow/commit/a823dd56e8c13a7d94fb6874a21539fa286d97ec))
* **checks:** backfill-check folds every character a Mac folds into ASCII (E116) ([e913baa](https://github.com/abdelrahmannasr/yadflow/commit/e913baaf6c68e171e2e06f139c6b25bac9732b79))
* **checks:** backfill-check folds the Kelvin sign into k (E116) ([c5152c3](https://github.com/abdelrahmannasr/yadflow/commit/c5152c350ab1dd89e6906eac9433316be5ecf261))
* **checks:** backfill-check lists go through the stream, not the environment (E116) ([f2366f0](https://github.com/abdelrahmannasr/yadflow/commit/f2366f0c1433a05bae614956b66326223f2e51ab))
* **checks:** backfill-check pairs raw records, frees twins, checks links when specs are hidden (E116) ([6544926](https://github.com/abdelrahmannasr/yadflow/commit/654492634f9f65dbe702701ddaf8af038ba2beae))
* **checks:** backfill-check reads each spec by its object id (E116) ([6e44ae5](https://github.com/abdelrahmannasr/yadflow/commit/6e44ae576d547333bc1a256a1a3e473f8ddc5e1f))
* **checks:** backfill-check reads every spelling of the verified key (E116) ([81588e6](https://github.com/abdelrahmannasr/yadflow/commit/81588e62d71c60174fe678a8756d1a0806388554))
* **checks:** backfill-check reads the last verified: key, as YAML does (E116) ([36cb5cd](https://github.com/abdelrahmannasr/yadflow/commit/36cb5cda6a817b6a4d3504052058fa26c6eefb9d))
* **checks:** backfill-check reads the spec from the base and refuses links (E116) ([b63f5ac](https://github.com/abdelrahmannasr/yadflow/commit/b63f5ac706cd6155b5db63ffaf258dcd11d4269d))
* **checks:** close the gaps review 1 found in the Product and epic reads (E117, E118) ([a8d8178](https://github.com/abdelrahmannasr/yadflow/commit/a8d81780c35a651e30e51e5dcc0e30252ac50205))
* **checks:** close the gaps review 2 found in the Product reads (E117, E118) ([dcc5ea5](https://github.com/abdelrahmannasr/yadflow/commit/dcc5ea5667be4c52676656aef5723813edce4857))
* **checks:** close the gaps review 3 found in the Product reads (E117) ([fbb0768](https://github.com/abdelrahmannasr/yadflow/commit/fbb076848e5c1ba7f67ad34ff5d7b5b7d5d094e7))
* **checks:** compare the git folder as a folder, not a spelling (E117) ([2a824a8](https://github.com/abdelrahmannasr/yadflow/commit/2a824a83b4f8eb0129b1275ec8b45832d5f22d87))
* **checks:** contract-check fails a first spec whose product-repo reaches nothing (E119) ([a4738fc](https://github.com/abdelrahmannasr/yadflow/commit/a4738fce11d4b2e87ef6d03bcea865d22feb52dc))
* **checks:** contract-check folds every character a Mac folds into ASCII (E121) ([8422e70](https://github.com/abdelrahmannasr/yadflow/commit/8422e70e192f15c26053a94ccbf2ecb8c658d720))
* **checks:** read every NUL list with a newline in a name as ? (E121) ([2659211](https://github.com/abdelrahmannasr/yadflow/commit/2659211c94a28d52c7a25a956d8c75bab1dd61ec))
* **checks:** refuse a Product path inside the repo's own .git (E117) ([b726032](https://github.com/abdelrahmannasr/yadflow/commit/b7260323e1aebab247ad6367ea2bd1c6a6d4756d))
* **checks:** the first-spec FAIL fires only when the Product is not reached (E119) ([322ffe3](https://github.com/abdelrahmannasr/yadflow/commit/322ffe39fd2654aae5022898db3d3f71bd1d4f11))
* **checks:** the PR no longer chooses where the Product is read from (E117) ([68db03b](https://github.com/abdelrahmannasr/yadflow/commit/68db03b61269346a9c540f7fa39d4b37648f627b))
* **checks:** walk the Product path again from where it really lands (E117) ([1b0726d](https://github.com/abdelrahmannasr/yadflow/commit/1b0726d04a83544beef2bdfd3aac32f395d373bd))
* **ci:** Pages write scopes move to the job; one pin per action major (review 1) ([92a51fe](https://github.com/abdelrahmannasr/yadflow/commit/92a51febd1146c7f90528855d67cfa8d1be81255))
* **ci:** pin every workflow action by commit SHA and make the default token read-only ([43254bb](https://github.com/abdelrahmannasr/yadflow/commit/43254bba2c5606831ba7328896326c83c3dd4a3e))
* clean every printed path, one wording for the quote, and the door works from a Product subfolder (E49 review 2) ([85ea6a4](https://github.com/abdelrahmannasr/yadflow/commit/85ea6a4f5e99942aba7dd28fdd05605319cc241c))
* clone a registered repo only from a network address (E81 review 3) ([1582784](https://github.com/abdelrahmannasr/yadflow/commit/15827845f14329d1d592a01d68b8f3a9b122e19c))
* close the last one-key product.json hints, and refuse before touching .gitignore (E122 review 3) ([2b10f5b](https://github.com/abdelrahmannasr/yadflow/commit/2b10f5bd7568c5121adf72d5ab1f6e832c1029f9))
* **docs:** raise the docs shell version to 0.0.2 for the brace-expansion bump ([74498a5](https://github.com/abdelrahmannasr/yadflow/commit/74498a545b96923b5096b7adf06631e96ae7e616))
* **doctor:** ask for --overwrite-local only when a plain --fix would not do (E120 review 8) ([5950b89](https://github.com/abdelrahmannasr/yadflow/commit/5950b89def883390bafc0c3922ce4ad65d2f3131))
* **doctor:** decide the record's ahead/behind state by git, in one table (E120 review 5) ([1739cc5](https://github.com/abdelrahmannasr/yadflow/commit/1739cc5afff34d638376215c6da90d58aaf191bb))
* **doctor:** judge an off-branch clone's record as it will be after the switch (E120 review 9) ([39025bd](https://github.com/abdelrahmannasr/yadflow/commit/39025bd09c92870aacdcacca38cb3906c29da502))
* **doctor:** name `gate repair --push` for a stranded step on a verified Product (E48 review 3) ([29f0340](https://github.com/abdelrahmannasr/yadflow/commit/29f0340be0d0bef0f5e3d40a18d0da645e352b80))
* **doctor:** name a product-link record committed but never pushed (E120 review 3) ([4db532a](https://github.com/abdelrahmannasr/yadflow/commit/4db532a2712670e63f6caba85aeffd108ee63030))
* **doctor:** no silence over a broken record, and hints that work off the default branch (E120 review 6) ([97c714b](https://github.com/abdelrahmannasr/yadflow/commit/97c714b66429f3a9731fd0d853ab20fcaaff75f4))
* **doctor:** one clear step per repo in the product-link hint (E120 review 7) ([c117c3d](https://github.com/abdelrahmannasr/yadflow/commit/c117c3d2aa737df27c2a3167e2001dd8454654aa))
* **doctor:** tell unpushed, on another branch and behind apart (E120 review 4) ([9356748](https://github.com/abdelrahmannasr/yadflow/commit/935674881340e9c47aaba04b77196b343368cd64))
* drop the exact registry path from the warning, and clean C1 control characters too (E79 review 7) ([c70911c](https://github.com/abdelrahmannasr/yadflow/commit/c70911c5e199b2433325e3a4996b3fe240be42ad))
* **e120:** a record is ok only when committed as it stands (review 2) ([f2fc7de](https://github.com/abdelrahmannasr/yadflow/commit/f2fc7dec1435d009ead6966c831d4aa409871306))
* **e120:** a record right on disk reads ok, and --push still commits it (CI) ([a5cd7f5](https://github.com/abdelrahmannasr/yadflow/commit/a5cd7f541283a6715cc012bd57194f0684e2cdc8))
* **e120:** commit the record for sure, keep secrets out, keep local runs checking ([e96ed5d](https://github.com/abdelrahmannasr/yadflow/commit/e96ed5dc8b87938097fb35270d4b677c456377e3))
* every doctor command to copy takes registry text as one plain word (E81 review 11) ([e2d147a](https://github.com/abdelrahmannasr/yadflow/commit/e2d147addb163f5397b054f1e84b506b1732668c))
* **hook:** fail open under sh -e, follow no GIT_DIR, and name the repair that commits (E48 review 1) ([2991086](https://github.com/abdelrahmannasr/yadflow/commit/29910861d1c76763f765b2483ea412e8eba5d899))
* **hooks:** advice for a stuck old entry that is true in every case (E113 review 7) ([6d7fff1](https://github.com/abdelrahmannasr/yadflow/commit/6d7fff14a4a3d5bd1cb99b5bd0484cd292a0f109))
* **hooks:** give a local-ledger guard entry advice that works at apply too (E113 review 6) ([d26b241](https://github.com/abdelrahmannasr/yadflow/commit/d26b241af186961a40ca50dac289e3d6e230e1f8))
* **hooks:** judge an old hook script against the files as this run leaves them (E113 review 2) ([9a5df22](https://github.com/abdelrahmannasr/yadflow/commit/9a5df224c6e7322a6aebcc9a78b57afee1a2f59a))
* **hooks:** keep an old hook script until its new entry is committed (E113 review 1) ([c4fb5b3](https://github.com/abdelrahmannasr/yadflow/commit/c4fb5b37e3171604be7376e793cebd0eb194f14b))
* **hooks:** name what keeps an old hook script, and read HEAD once (E113 review 3) ([f1b95fc](https://github.com/abdelrahmannasr/yadflow/commit/f1b95fc2f135c5f4572d9e21b32e614a1ef77565))
* **hooks:** one sentence of advice for a stuck old hook entry, at plan and apply (E113 review 5) ([ab22b93](https://github.com/abdelrahmannasr/yadflow/commit/ab22b9348b659130fc1237786a4d6766919a580f))
* **hooks:** tell a capture-off Product to remove a stuck capture entry (E113 review 8) ([353053a](https://github.com/abdelrahmannasr/yadflow/commit/353053a017c5a0dad46c881abead93d65a9a704b))
* **hooks:** tell a local-ledger Product to remove a stuck guard entry (E113 review 4) ([0e1eaa5](https://github.com/abdelrahmannasr/yadflow/commit/0e1eaa5009f8cd06c39832faa9642ece7881e17b))
* **hook:** the agent's refusal gets the same fixes, and doctor names a hook git skips (E48 review 2) ([9551b1a](https://github.com/abdelrahmannasr/yadflow/commit/9551b1a4166bd4174a6a35f6655bbf5e805d3b90))
* join stays inside the workspace on disk, one bad entry fails alone, and init never takes over a code repo (E79 review 1) ([56f14ae](https://github.com/abdelrahmannasr/yadflow/commit/56f14ae7f90f4eddd6618bcf6a6f7e23947e850e))
* keep every URL form's host and user to safe characters (E81 review 6) ([61370c2](https://github.com/abdelrahmannasr/yadflow/commit/61370c28a911f4d39223a6eee2df6affc27415d7))
* keep the rename's own error when writeJSON's cleanup fails (E81 review 20) ([d5b860f](https://github.com/abdelrahmannasr/yadflow/commit/d5b860f66fce3e0c99739327e8662af49ba2fed7))
* keep writeJSON's own error when the temp cleanup fails (E81 review 19) ([b8d7640](https://github.com/abdelrahmannasr/yadflow/commit/b8d7640abc5b6fde91ef0c45a05e976c134912b4))
* ledger-guard reads a missing settings file quietly, and the roster hints name the file (E122 review 5) ([d00a117](https://github.com/abdelrahmannasr/yadflow/commit/d00a117d6cd535255b44b0ec3e61a38aa1774169))
* name a repos.json that does not parse instead of joining with no repos (E79 review 5) ([4a952e2](https://github.com/abdelrahmannasr/yadflow/commit/4a952e2dd80ea36b33aaa37c051da1f702980585))
* name the file in the last settings hints, refuse a pair that changed, and silence a missing settings file (E122 review 4) ([5aed634](https://github.com/abdelrahmannasr/yadflow/commit/5aed63409178e36954240e37ee11e53b1ab95e04))
* name the Product from the workspace folder instead of offering a second one, and match paths as the disk stores them (E80 review 2) ([71369b3](https://github.com/abdelrahmannasr/yadflow/commit/71369b3565d273ad6a2f6eb3bd3caa8f685e75f5))
* name the settings file a person should edit, and settle all pairs or none (E122 review 2) ([ccb8de4](https://github.com/abdelrahmannasr/yadflow/commit/ccb8de49a48397c14446faebf8c3d7ef1222abd5))
* name the settings file actually read, and keep risk-map advisory (E122 review 1) ([ab4fddc](https://github.com/abdelrahmannasr/yadflow/commit/ab4fddc495433cff0d013742f02086bea94b00a9))
* name the settings file on disk, and restore the old-name fallback (E124 review 1) ([cf24871](https://github.com/abdelrahmannasr/yadflow/commit/cf248716935eaebc9961ae8e9f8d8b27a123a9d0))
* never build a login command from a host that is not a plain host name (E81 review 13) ([0a09dc1](https://github.com/abdelrahmannasr/yadflow/commit/0a09dc11e047e483ea046720a9e505078e815ae5))
* never clone or register a repo path through a .git folder, and say what --dir is for each workspace verb (E79 review 2) ([6be43a2](https://github.com/abdelrahmannasr/yadflow/commit/6be43a274b392c405454d1a09d4f49143257d100))
* never write over an edited new name, keep one workflow running, and name a gate that rejects product (E123 review 1) ([d7dc72b](https://github.com/abdelrahmannasr/yadflow/commit/d7dc72bf0857ceda09db081be1b95647a20334c2))
* one plainHost test for every login command doctor prints (E81 review 14) ([8a25d94](https://github.com/abdelrahmannasr/yadflow/commit/8a25d947353538ce7b0ffe0f399d08082e791bab))
* one samePath for a git path against a Node path, and survive a missing .git/hooks (E48 review 5) ([156ec1e](https://github.com/abdelrahmannasr/yadflow/commit/156ec1e4d9d19e5cd22e454432b1eece6fac6ced))
* one terminal cleaner for every module that prints registry text (E81 review 12) ([805a4fd](https://github.com/abdelrahmannasr/yadflow/commit/805a4fd200c2465f9a491f44e81b60ed50605946))
* only the ledger door runs from a subfolder, and the sha — not an indent — keeps :: off a line (E49 review 3) ([9878423](https://github.com/abdelrahmannasr/yadflow/commit/987842384792905cbc15db429d5d3e3da76033e4))
* read any spelling of the profile mapping and branch, and never a comment (E123 review 3) ([67c3a55](https://github.com/abdelrahmannasr/yadflow/commit/67c3a559ae95dae1abae8f4561d5e04b073eca02))
* record the new name a kept rename installs, and say a profile gap only when it bites (E123 review 2) ([9c99014](https://github.com/abdelrahmannasr/yadflow/commit/9c990145a68596dddfa4c2534afae18f3615efda))
* refresh never writes through a .gitignore the Product commits as a link (E81 review 16) ([5d9a982](https://github.com/abdelrahmannasr/yadflow/commit/5d9a9822d73376c5f83a6fe880dd52adf075e67a))
* refresh stops at a linked .sdlc, --push included (E81 review 18) ([e79d64c](https://github.com/abdelrahmannasr/yadflow/commit/e79d64c503d3d96e8f1005b1560d4e815ecf2820))
* refuse a clone target with a link on its way, so a committed link cannot reach .git (E79 review 3) ([667d696](https://github.com/abdelrahmannasr/yadflow/commit/667d6964e9ceed75ce0ea1fb82b03d6cf7c324ea))
* refuse a control character anywhere in a registered git_url (E81 review 8) ([6edf593](https://github.com/abdelrahmannasr/yadflow/commit/6edf5937a094a827faf02454fa2f54803b0f2cd4))
* refuse any folder holding HEAD on the way to a registered subfolder (E81 review 2) ([0471334](https://github.com/abdelrahmannasr/yadflow/commit/04713341b8b3ea5ee55d59da82b9f818d6bfe2df))
* refuse encoded C1 and bidi characters; clean the last raw registry text (E81 review 9) ([7f7721b](https://github.com/abdelrahmannasr/yadflow/commit/7f7721b636fc19ed4736c6962ae3cd67726c3007))
* **release:** install an exact npm version, not npm@latest ([0bf8981](https://github.com/abdelrahmannasr/yadflow/commit/0bf89817da64f43f91fc281d42f76883c0f1a1ef))
* **setup:** compare hook folders by their long name on Windows (E48) ([8f1ac56](https://github.com/abdelrahmannasr/yadflow/commit/8f1ac5617cf50b89ca8626e5d15ec645b2ff64a5))
* **setup:** read a core.hooksPath typed in another case as the default folder where the disk ignores case (E48 review 6) ([997f77d](https://github.com/abdelrahmannasr/yadflow/commit/997f77d39d76c49a7e5b63845c867484fb180437))
* **skills:** yad-connect-repos frontmatter parses; two descriptions fit 1024 ([d6eaf55](https://github.com/abdelrahmannasr/yadflow/commit/d6eaf558d8296dbedacab3c70f9075d497222d56))
* the --profile hub advice names every gate in the way, in every state (E124 review 4) ([5d125ec](https://github.com/abdelrahmannasr/yadflow/commit/5d125ece69967c3c76d923da2c05decd1c500140))
* the --profile hub advice reads each gate's real state (E124 review 3) ([f00c51e](https://github.com/abdelrahmannasr/yadflow/commit/f00c51e7a4ec54bb6c126797478088c06365d746))
* the --profile hub advice waits for a gate that refuses product, and a repo named product is shown by its path (E124 review 2) ([80518c5](https://github.com/abdelrahmannasr/yadflow/commit/80518c5cbd3af2209882167bb381731190d2336a))
* the clone sets GIT_ALLOW_PROTOCOL; a local source must exist (E81 review 5) ([7963220](https://github.com/abdelrahmannasr/yadflow/commit/796322023a6bc90b541f66b3c383e34b1957c791))
* the drift advice names yad migrate --apply, and one drift lookup serves all (review 1) ([f158fa1](https://github.com/abdelrahmannasr/yadflow/commit/f158fa1f8311a71e5346dbd51ee6627a231b3dae))
* the ledger override claims only what it can see, and no control character reaches the CI log (E49 review 1) ([da7a6d9](https://github.com/abdelrahmannasr/yadflow/commit/da7a6d96cf762e7d23f5f4ae3c44c5c2e9dc195d))
* the solo people count judges each registered path before git runs (E81 review 15) ([993698a](https://github.com/abdelrahmannasr/yadflow/commit/993698a17f2496985da6b8c6160c2e9eeba83449))
* the unreadable-registry warning gives the real reason, and a null registry is named too (E79 review 6) ([9f426eb](https://github.com/abdelrahmannasr/yadflow/commit/9f426eb3697e473bde80468e0be5946de4041404))
* the unreadable-settings cell says only what is true (E124 review 6) ([5d43189](https://github.com/abdelrahmannasr/yadflow/commit/5d431894e377065ca1d26316973fd6cfabc7d3c9))
* when a file's two names disagree, the gate advice says yad migrate first (E124 follow-up) ([75d2184](https://github.com/abdelrahmannasr/yadflow/commit/75d2184480acc0d285d7718533ab9bf9d65cf723))
* writeJSON's temp file is random and exclusive (E81 review 17) ([b5cbcd9](https://github.com/abdelrahmannasr/yadflow/commit/b5cbcd935a81534b5f749eeba13c36711fb7a471))


### Documentation

* the guides, sites and diagram say Product, and a guide to the hand changes (E124) ([883cd6f](https://github.com/abdelrahmannasr/yadflow/commit/883cd6f56378dc58bbbd1a9ebdba0048a1e35c9a))


### Features

* .yad-workspace.json — yad finds the Product from any repo in the workspace (E80) ([27a7579](https://github.com/abdelrahmannasr/yadflow/commit/27a75793c558d597840d01c9f7986e25e7a5c42a))
* **checks:** check the Product out in CI where the record says (E120) ([b288326](https://github.com/abdelrahmannasr/yadflow/commit/b288326da2a72c3475d0cfafd2f8bc9540d0670d))
* **checks:** read where the Product lives from .sdlc/product-link.json on the base (E120) ([6b9e7b1](https://github.com/abdelrahmannasr/yadflow/commit/6b9e7b1f293183b89fda9d1aa9b748bcd62bb7f6))
* **commit:** yad commit --manual --reason, the door past the ledger hook (E49) ([5b4081a](https://github.com/abdelrahmannasr/yadflow/commit/5b4081a5bea4423c90b41a5ad676e0c5987bf0d9))
* **doctor:** warn checks:backfill-blind for an older backfill-check (E116) ([bfb82cf](https://github.com/abdelrahmannasr/yadflow/commit/bfb82cf2e0d956165c179a92a0e09fb46e8e97f9))
* **hook:** refuse a hand commit to the CI-owned ledger with a git pre-commit hook (E48) ([e2258b1](https://github.com/abdelrahmannasr/yadflow/commit/e2258b14f9c35af5057e109713c6407fae50b068))
* **hooks:** run the agent hooks as Node scripts, so Windows works without WSL (E113) ([887ceea](https://github.com/abdelrahmannasr/yadflow/commit/887ceeadabdb4f20482c3f3a5d29963c5fe74cc8))
* **repos:** write each code repo's product-link record, and warn when it is missing (E120) ([54f1fe3](https://github.com/abdelrahmannasr/yadflow/commit/54f1fe382d884aa2e72bb56c26197dd3e8e3c5c0))
* tell a repo named product apart, and name --profile hub in the team's workflows (E124 review 1) ([98fc15d](https://github.com/abdelrahmannasr/yadflow/commit/98fc15d345354c0df83ceae7d7aa4db5765c02b2))
* yad new, yad init and yad join — the three ways into a workspace (E79) ([dcccf67](https://github.com/abdelrahmannasr/yadflow/commit/dcccf670ffb4cb376aba6af26e602140328c00ea))
* yad repo clone fetches registered repos missing on this machine (E81) ([8a20504](https://github.com/abdelrahmannasr/yadflow/commit/8a20504f816ec556e55ec5db41b8f4350973e283))


### BREAKING CHANGES

* after `yad update` renames the installed CI names, a
team's own files that name the old ones must be changed by hand — GitLab
`needs:` / `dependencies:` / `extends:` / `!reference` naming a
`yad-hub-*` job, GitHub `workflow_run:` triggers naming `yad-hub-checks`,
status badges, CODEOWNERS lines, and scripts that read `--json` names or
`SDLC_HUB_CONFIG` / `.sdlc/hub.json`. Every case, with a before and
after: docs/migrations/hub-to-product.md.
* `--json` names that said `hub` now say `product`, and
`jsonVersion` is 2. `yad doctor` check ids `hub`, `hub-git-url` and
`ci-tags:hub` are `product`, `product-git-url` and `ci-tags:product`;
`yad open-pr` answers `baseSource: "product"` and `stage:
"product-shape" | "product-tooling"`; `yad check` / `yad update` answer
`items[].scope: "product"` and `commits[].label: "product"`; and
`yad history show` answers `productConfigWhy` where it answered
`hubWhy`. The audit commits are `chore(product): …`. See the
"What moved in jsonVersion 2" table in docs/CLI.md.
* `yad update` renames the Product's
.github/workflows/yad-hub-checks.yml and .gitlab/ci/yad-hub-checks.yml to
yad-product-checks.yml, the GitLab jobs yad-hub-* to yad-product-*, and
the yad-hub-bridge skill to yad-product-bridge. GitHub job names (the
required checks) do not change. Your own CI that names an old name — a
GitLab needs:/dependencies:/extends:/!reference, a GitHub workflow_run:
trigger on yad-hub-checks, a status badge, a CODEOWNERS line — must be
changed by hand; `yad doctor` lists each by file and line (renamed-ref:).
* yadflow 4 reads .sdlc/product.json (and each epic's
product-prs.json) first; .sdlc/hub.json and hub-prs.json are read only when the
new name is absent, are still written until 5.0, and are deleted in 5.0. This
corrects docs/migrations/shape-3.md and the 4.0.0-next.1 notes, which said the
old names stay the ones read for another major. When both names exist and say
different things, every command refuses (YAD-STATE-008) and the gates fail;
run `yad migrate` to see the difference and `yad migrate --apply` (or
`--apply --keep product|hub`) to choose. Edit settings by hand in
.sdlc/product.json, then run `yad migrate --apply --keep product`. Gates now
honour SDLC_PRODUCT_CONFIG before SDLC_HUB_CONFIG.

# [4.0.0-next.3](https://github.com/abdelrahmannasr/yadflow/compare/v4.0.0-next.2...v4.0.0-next.3) (2026-09-26)


### Bug Fixes

* **test:** strip the publisher's git identity from the whole test process ([8660f56](https://github.com/abdelrahmannasr/yadflow/commit/8660f5611f1c9f24a67eeead4302c4acca260ba3))

# [4.0.0-next.2](https://github.com/abdelrahmannasr/yadflow/compare/v4.0.0-next.1...v4.0.0-next.2) (2026-09-26)


### Bug Fixes

* **capture:** continue origin's branch when there is no local one; name a refused push (E43 review 2) ([8e2c07d](https://github.com/abdelrahmannasr/yadflow/commit/8e2c07d32d1b6882c7b543b9b3c65f96ca67e919))
* **capture:** every git call takes the environment runCapture was given (E43) ([c347c94](https://github.com/abdelrahmannasr/yadflow/commit/c347c9460154e6b30472a3a1aae2869354a6fce4))
* **capture:** prune deleted capture branches; read [a-z] and list brackets as GitHub does (E43 review 3) ([2322dcb](https://github.com/abdelrahmannasr/yadflow/commit/2322dcb0321ff02f0ebf22ecfe61b2979236944d))
* **capture:** subfolder Products, staged-then-deleted files, a plain push, and a truer workflow scan (E43 review) ([14f0eeb](https://github.com/abdelrahmannasr/yadflow/commit/14f0eeb6e5fe9ce21bdfe5fb168ace88a41d7ad6))
* **capture:** take design-links.json and test-links.json with the artifacts (E44) ([ad4f2cf](https://github.com/abdelrahmannasr/yadflow/commit/ad4f2cfc1f134c3b17616348081795a09939049a))
* **checks:** a C-quoted path is an artifact change; warn on a rename-blind workflow (E47 review 4) ([e6af8df](https://github.com/abdelrahmannasr/yadflow/commit/e6af8df0f4dafd3ec593da44114b07c45b67f54a))
* **checks:** E114 review 1 — one odd name per test, split lines, full hint ([df9f4dc](https://github.com/abdelrahmannasr/yadflow/commit/df9f4dcaf5736bfbd93a49c017ffae257e2b4ef6))
* **checks:** fold the long s into specs; say a file is a file (E115 review 2) ([373ba16](https://github.com/abdelrahmannasr/yadflow/commit/373ba16c81bc3c0eb5c56bb7adae48441b4f07a8))
* **checks:** let a PR of step owner files alone through on a Product (E47 review 2) ([f7ff5b0](https://github.com/abdelrahmannasr/yadflow/commit/f7ff5b062a51b455a18190a31ccbd5488fe5785f))
* **checks:** list a rename by both paths in contract-check and backfill-check (E114) ([09bb4de](https://github.com/abdelrahmannasr/yadflow/commit/09bb4de3f36e0fec0eb247565fc2364a46b482b8))
* **checks:** list renames and unquoted paths in the hub-checks diff (E47 review 3) ([bc270e0](https://github.com/abdelrahmannasr/yadflow/commit/bc270e0583a7583ffccea94b9ecaa1a11498ec46))
* **checks:** read specs/ without case; name a failed tree read (E115 review 1) ([a9fb725](https://github.com/abdelrahmannasr/yadflow/commit/a9fb72599a5980e9f2e8307cb87eca9ae31f17ca))
* **checks:** read the changed list as bytes; check each workflow line (E47 review 5) ([edc850b](https://github.com/abdelrahmannasr/yadflow/commit/edc850b20495a13d376b6f01dc02db61658d4e27))
* **checks:** refuse a second spelling of contracts/ or a story folder (E115 review 3) ([debc7b6](https://github.com/abdelrahmannasr/yadflow/commit/debc7b68f8bbddf5634322228f633327aba8c50a))
* **checks:** refuse a symlink or submodule under specs/ in contract-check (E115) ([e93387a](https://github.com/abdelrahmannasr/yadflow/commit/e93387aa036cc40b9d6741291a1ef518a0d03e1b))
* **checks:** say what the story-spelling rule does not catch (E115 review 4) ([3d36c93](https://github.com/abdelrahmannasr/yadflow/commit/3d36c934406b148c3601c5a6bfdacd40abccbad3))
* **claims:** find the first capture's base in one git call, with no cap (E46 review 2) ([e4a6fcf](https://github.com/abdelrahmannasr/yadflow/commit/e4a6fcf2a33acba0c4b76b5ba54e99d740dcd1d7))
* **claims:** keep the once-an-hour memory across a push; own edits only; over-report a missing base (E46 review 1) ([7ab038d](https://github.com/abdelrahmannasr/yadflow/commit/7ab038d436fc9d46009fd31139bd7327083ebac3))
* **claims:** pin the first-capture search against the person's git config (E46 review 3) ([80db192](https://github.com/abdelrahmannasr/yadflow/commit/80db1926695f60884a47b6a72b5a79f634ac5519))
* **claims:** read the Yad-Base trailer with a pinned separator (E46 review 4) ([c026fef](https://github.com/abdelrahmannasr/yadflow/commit/c026fef2454f6a5799b6e0f8fe5a04ee6cbbad62))
* **doctor:** read a gate one bash command at a time (E114 review 2) ([06d3f69](https://github.com/abdelrahmannasr/yadflow/commit/06d3f69113e3b19f3b9cee1cf77a637999372775))
* **doctor:** satisfy eslint — split on ** instead of a NUL placeholder; no useless assignment (E43) ([aad5822](https://github.com/abdelrahmannasr/yadflow/commit/aad582240fa0b8f4a279b0221100fba967ced20d))
* **fold:** fold a staged deletion; refuse mid-merge and on a detached HEAD (E44 review 1) ([4391b1b](https://github.com/abdelrahmannasr/yadflow/commit/4391b1b1eb6d22990b672a0d3f64b5fb5e77c5ec))
* **fold:** name a case-only rename only when git shows the new spelling (E44 review 4) ([2a6395c](https://github.com/abdelrahmannasr/yadflow/commit/2a6395c7f9ae7c7d9ee8bf1877e4cb770b2197c0))
* **fold:** never run git add with an empty list; refuse a git rm --cached path (E44 review 2) ([cfbaefc](https://github.com/abdelrahmannasr/yadflow/commit/cfbaefc9d8334a20ddbd585b9c2c25a0d31992f7))
* **fold:** tell a case-only rename from git rm --cached (E44 review 3) ([a374fc3](https://github.com/abdelrahmannasr/yadflow/commit/a374fc314f266354cdf96200b54dfa631423d4c2))
* **fold:** the Product level is seeded under either spelling; truer words (E44 review 6) ([c711326](https://github.com/abdelrahmannasr/yadflow/commit/c71132643b8c3ca1fb1d0b5c3a4739d0b18209dd))
* **fold:** the verified seed rule asks ledger-guard's own question; a change-epic's seed rides along (E44) ([f0ee36d](https://github.com/abdelrahmannasr/yadflow/commit/f0ee36d60bad06ac0920b64d97bf16e9f19a7a06))
* **gate:** a round keeps the fingerprint it opened with; one spelling across approvals and comments (E112 review 2) ([d7dbe57](https://github.com/abdelrahmannasr/yadflow/commit/d7dbe57d507f5c798236715e55b70ef42f273dbe))
* **gate:** approve keeps the review record; one spelling per person; a round is one version (E112 review) ([6f44c18](https://github.com/abdelrahmannasr/yadflow/commit/6f44c1887ae2c846bdcd1c14cf276624a2be91b6))
* **owners:** never fold an owner file; name off-chain files in doctor (E47 review 1) ([f23f606](https://github.com/abdelrahmannasr/yadflow/commit/f23f606f220aef583500c6f2a632ee8927307b6c))


### Features

* **capture:** yad capture snapshots Shape artifacts onto private yad/wip branches (E43) ([58b0181](https://github.com/abdelrahmannasr/yadflow/commit/58b0181f72fd88e97d391e0e52a46e8b5cdf1183))
* **claims:** yad claims — who else is editing which artifact, read from the capture branches (E46) ([6668441](https://github.com/abdelrahmannasr/yadflow/commit/66684416b5d3c1a2a04b069cd35b0d7f13e55ddb))
* **doctor:** warn when a step owner file does nothing (E47) ([b189abd](https://github.com/abdelrahmannasr/yadflow/commit/b189abdbc94aa0a36041d501b9cd09c5577d5a62))
* **fold:** yad fold <epic> <step> — one clean commit per authoring step (E44) ([a4a5285](https://github.com/abdelrahmannasr/yadflow/commit/a4a52857c2536b83d954e6a313863ecb16ecf01d))
* **gate:** yad gate approve, comment and advance for a Product with no platform (E112) ([50f7618](https://github.com/abdelrahmannasr/yadflow/commit/50f7618aae85fb269578055e5e12d33e58643fab))
* **owners:** assign an authoring step to one person (E47) ([f9f9bda](https://github.com/abdelrahmannasr/yadflow/commit/f9f9bdaf31206d8ac4c7d46b4d512f23b1e816d2))

# [4.0.0-next.1](https://github.com/abdelrahmannasr/yadflow/compare/v3.19.0-next.2...v4.0.0-next.1) (2026-09-24)


* feat(checks)!: risk-route and hub-route print the approval count, not roles (E62) ([8754585](https://github.com/abdelrahmannasr/yadflow/commit/875458576c6800356980b302dd3366d0b7a5e02a))
* feat(checks)!: verified-commits checks signatures only; the author allowlist is gone (E62) ([67c0161](https://github.com/abdelrahmannasr/yadflow/commit/67c01612372f74e6c70b5af24636eae034fe34c7))
* feat(cli)!: every command answers --json in one envelope (E1) ([7862dfb](https://github.com/abdelrahmannasr/yadflow/commit/7862dfb7d496171bc5f8fa20e533ffc688c57f0e))
* feat(epic)!: shape 5 — the work-item type, and a chore may stand alone ([5eb24fb](https://github.com/abdelrahmannasr/yadflow/commit/5eb24fb04e5d6c686d92b69e4d1b8dd1ea41d46b))
* feat(gate)!: a team gate needs one approver, and approvals name the platform login (E62) ([3730b9c](https://github.com/abdelrahmannasr/yadflow/commit/3730b9cc4f58acede87f9a020ac1ded0b7cf1fdd))
* feat(gate)!: review and task PRs request no reviewers (E62) ([d9f3d76](https://github.com/abdelrahmannasr/yadflow/commit/d9f3d765cced1b50868197bf8622e891a2af0f3a))
* feat(gate)!: shape 9 — an approval's fingerprint leaves out the frontmatter status line ([226f9ec](https://github.com/abdelrahmannasr/yadflow/commit/226f9ec4b9c19bdd055a1f9094b5c95badd69864))
* feat(migrate)!: shape 8 — `yad migrate` moves the product level into foundation/ (E75) ([88e726f](https://github.com/abdelrahmannasr/yadflow/commit/88e726fe9b24737d02e2b7f32e167a60f09e6961))
* feat(setup)!: remove yad roster and stop collecting people in setup (E62) ([5eb6914](https://github.com/abdelrahmannasr/yadflow/commit/5eb69147c84aa6b83ddda2c3e394b4f183caca6a))
* feat(state)!: finish the hub to Product rename ([92a9750](https://github.com/abdelrahmannasr/yadflow/commit/92a9750e708ab130000872e09fd15ff68c4a3c00))
* feat(state)!: yad undefer re-opens a deferred step behind finished work (E41) ([518b7cc](https://github.com/abdelrahmannasr/yadflow/commit/518b7cc7c339f20cf417712b5e8da0e560312f29))
* feat(usage)!: yad usage lists people from activity, not from the roster (E62) ([0664996](https://github.com/abdelrahmannasr/yadflow/commit/0664996f4dae2f190fcd304cb259759054251a80))
* fix(docs)!: a failed docs build exits 1 and says which site failed ([381a000](https://github.com/abdelrahmannasr/yadflow/commit/381a0000754ff4eb9fec4856692d4627369d6420))


### Bug Fixes

* **agents:** answer Cursor in the protocol it actually reads ([d6d6175](https://github.com/abdelrahmannasr/yadflow/commit/d6d6175e71447e6ae735979631dd74802d3f0f13))
* **agents:** close the fifteen defects the deep review found ([cc42177](https://github.com/abdelrahmannasr/yadflow/commit/cc421772bceee0513a3ca30f382cdbb606de39d6))
* **agents:** close the five defects the E11 review found ([c4ca25f](https://github.com/abdelrahmannasr/yadflow/commit/c4ca25fd66d497157d2ee37707984b02f1c500b0))
* **agents:** close the four the audit had left open ([0e5dcd8](https://github.com/abdelrahmannasr/yadflow/commit/0e5dcd80a752f263a45865b3188edf57421818eb))
* **agents:** close the last three, and stop a comment claiming something false ([292a7b1](https://github.com/abdelrahmannasr/yadflow/commit/292a7b1c2b45457f230c39fc19f3db1535beb50d))
* **agents:** let the doctor see the script Cursor actually invokes ([a070911](https://github.com/abdelrahmannasr/yadflow/commit/a0709113dfca4b94608c0519157f0157060d3999))
* **artifact-status:** a "$" in a frontmatter value no longer corrupts the status flip ([545123a](https://github.com/abdelrahmannasr/yadflow/commit/545123a5889cf48910507872ba45607592650cd9))
* **checks:** a claimed Contract-Change with no lock at all now FAILS ([2008eea](https://github.com/abdelrahmannasr/yadflow/commit/2008eea518b4e20052fb277301140d33a9793182))
* **checks:** hub-route reads whole risk tags; route output stops claiming an author check ([53bda97](https://github.com/abdelrahmannasr/yadflow/commit/53bda9717e75367940abab8ab033f3429c274e22))
* **checks:** removing a contract slice under a lockless epic is allowed ([9d0b66a](https://github.com/abdelrahmannasr/yadflow/commit/9d0b66a412d19c6b222f9e3a24dbcac1a8bde4ad))
* **checks:** risk-route reads an older risk-map check as "not counted", never as "nothing is high" ([a486d7b](https://github.com/abdelrahmannasr/yadflow/commit/a486d7b7b46ae95df03f3a372b72f72cc61c0e6a))
* **checks:** run the risk-map awk in the C locale so every awk reads bytes ([4d0d748](https://github.com/abdelrahmannasr/yadflow/commit/4d0d748e0ce575178cfa2d1a9f42df82a40caf16))
* **cli:** a JSON refusal keeps what was done; every warning is collected (E1 review 1) ([41fce95](https://github.com/abdelrahmannasr/yadflow/commit/41fce957954e75bb64fb0ab4271270935e7dc2fc))
* **cli:** a later failure keeps its hint; every commit row has the same keys (E1 review 3) ([188b2de](https://github.com/abdelrahmannasr/yadflow/commit/188b2dec55ce8b25a9fa8fe8e471864141c1def4))
* **cli:** answer in JSON only when the running command is history (PR review 3) ([cdc8250](https://github.com/abdelrahmannasr/yadflow/commit/cdc8250b340693b5e80d8d49a26044305ec52a4a))
* **cli:** every line that names a skill asks the project, not the catalogue ([c085218](https://github.com/abdelrahmannasr/yadflow/commit/c08521818e951faddb04c4e26fe5639a70cc0f1b))
* **cli:** every sweep failure reaches the JSON; a refusal says what was committed (E1 review 2) ([dd7ef3e](https://github.com/abdelrahmannasr/yadflow/commit/dd7ef3e00713bdeba43b0870e70ac90ee4246bf7))
* **cli:** the history JSON error is exactly the documented refusal shape ([d20c9a3](https://github.com/abdelrahmannasr/yadflow/commit/d20c9a3ab7f83ed73139c62f4eb2622d8a44440d))
* **cli:** the review round — a write that ate a user's bindings, and five more ([3c63059](https://github.com/abdelrahmannasr/yadflow/commit/3c63059686c467c5a8b29367d1e7712472835b9b))
* **cli:** two more prototype holes, and yad-run reads the binding without a lane ([3a0a114](https://github.com/abdelrahmannasr/yadflow/commit/3a0a1146e2b50154a294cd8ae0e30dc0e4a2ee58))
* **codeowners:** a GitLab heading's unreadable default owners are reported (E68 review 3) ([cd9a1f1](https://github.com/abdelrahmannasr/yadflow/commit/cd9a1f1c6628040ccf3c35efad0c49185039e73e))
* **codeowners:** a path typed in another case is still the top folder; a refusal is JSON under --json (E69 review 5) ([397ccaf](https://github.com/abdelrahmannasr/yadflow/commit/397ccaf9efdf8b6807a04721a2bd726b49398863))
* **codeowners:** a pattern crosses a folder name holding a line break; no set copy per rule (E69 review 3) ([7341d79](https://github.com/abdelrahmannasr/yadflow/commit/7341d79080cc0d5558929869afbbfb812f84853e))
* **codeowners:** an exclusion's extra words are not an owner problem; describe the GitLab defaults rule ([4f50303](https://github.com/abdelrahmannasr/yadflow/commit/4f50303ac1fa9d50ad830a1c3ff7813f2a39bfc5))
* **codeowners:** exact dead-line answer for escaped characters; fast for every common shape; refuse --write= (E69 review 2) ([c52b17d](https://github.com/abdelrahmannasr/yadflow/commit/c52b17db4ba7829bd59497cd60a8e00eb52c839f))
* **codeowners:** no address in a not-read reason; fast dead-line check; exact file name; top folder only (E69 review 1) ([036f907](https://github.com/abdelrahmannasr/yadflow/commit/036f9078f09f220a45de5f10a44bb9998a3c8a9d))
* **codeowners:** read the file list only when a CODEOWNERS exists; a list git cannot produce is not known ([a2f0cc8](https://github.com/abdelrahmannasr/yadflow/commit/a2f0cc8a626be7720aaf3b7c99118a93a34ff002))
* **dial:** close the holes the E34 review found ([2038d19](https://github.com/abdelrahmannasr/yadflow/commit/2038d19bf596ae958e3b51fb2b0bc3b2fbbd4860))
* **docs:** a new yad release no longer marks every docs site stale ([bdbbff1](https://github.com/abdelrahmannasr/yadflow/commit/bdbbff1eaaf7d89e7582d43dbbc11df52de84bd4))
* **docs:** only a deploy where every site built ends on a tick (review 2) ([68251be](https://github.com/abdelrahmannasr/yadflow/commit/68251beb3d9208011481e77587ba4ffc46d923cf))
* **docs:** the review round — right site folder, a real test, no green tick after a failed deploy ([9f868d8](https://github.com/abdelrahmannasr/yadflow/commit/9f868d8332679ab437c49b8e07fc3a5d15534faf))
* **doctor:** "on every change" also when a scoped rule could not be read (E70 review 6) ([36e52ff](https://github.com/abdelrahmannasr/yadflow/commit/36e52ffd80b74a43404924f1b8aab9a0133ec8b6))
* **doctor:** a 404 on a list never means "they do not exist" (E70 review 27) ([8bdf98f](https://github.com/abdelrahmannasr/yadflow/commit/8bdf98f64dbb1924768d161d8019813e4aecf7f4))
* **doctor:** a 404 on the rules is a host without rulesets, not a permission (E70 review 28) ([f80f92d](https://github.com/abdelrahmannasr/yadflow/commit/f80f92d4c468195730ef1a9c28089fb07dfbcf28))
* **doctor:** a belief from a 404 may remove an offer, never add certainty (E70 review 30) ([a3f653d](https://github.com/abdelrahmannasr/yadflow/commit/a3f653d15514a7842cadefcd16772235df7dfee9)), closes [#7386](https://github.com/abdelrahmannasr/yadflow/issues/7386) [#29576](https://github.com/abdelrahmannasr/yadflow/issues/29576)
* **doctor:** a branch yad cannot read settles nothing (E70 review 24) ([8d9a46a](https://github.com/abdelrahmannasr/yadflow/commit/8d9a46a1a2826b09634fcfdbce4e820e94882392))
* **doctor:** a colon, not a second dash, in the GitLab sentence (E70 review 11) ([9d8c835](https://github.com/abdelrahmannasr/yadflow/commit/9d8c83525a69945753250f9acbedbe469dcc609a))
* **doctor:** a floor counts rules, not labels (E70 review 23) ([3f7d124](https://github.com/abdelrahmannasr/yadflow/commit/3f7d124d6698973d599da54bf64724f4fb8bf23a))
* **doctor:** a GitLab rule with no name reads as "an approval rule" (E70 review 12) ([5ada04a](https://github.com/abdelrahmannasr/yadflow/commit/5ada04abb6356099a81280a910bc181a09b37dae))
* **doctor:** a hint hedges wherever its own message does (E70 review 31) ([e256f06](https://github.com/abdelrahmannasr/yadflow/commit/e256f06c50db96cfbab79dda4e91a63fcf91c456))
* **doctor:** a pointer only where something was unread, and numbers that agree (E70 review 16) ([2ff23f5](https://github.com/abdelrahmannasr/yadflow/commit/2ff23f53b12d0fa3f5d5d00766a90c4333d6dd80))
* **doctor:** a protection line states only what the platform answered (E70 review 3) ([453f646](https://github.com/abdelrahmannasr/yadflow/commit/453f6463040578c297c46f4cd22ba0521860c27f))
* **doctor:** a read that answered nothing says so, and one source is named once (E70 review 22) ([25eabe8](https://github.com/abdelrahmannasr/yadflow/commit/25eabe8d02778514bafdbf25b3698caac6a4b2f5))
* **doctor:** a rule keyed on a wording must say when it stops firing (E70 review 32b) ([6beeb6f](https://github.com/abdelrahmannasr/yadflow/commit/6beeb6f8c3c1f72f30c869559b763f6e3a6097e0))
* **doctor:** a sentence for a count read beside a protection that was not (E70 review 8) ([8421b00](https://github.com/abdelrahmannasr/yadflow/commit/8421b0060e54308632bbfacaf89149eabb9da98c))
* **doctor:** an id reads as an id, and no sentence pairs two dashes (E70 review 13) ([8a07f2b](https://github.com/abdelrahmannasr/yadflow/commit/8a07f2bd8b99785ed3bcdf192269113c7ac038c4))
* **doctor:** apply round 16's fixes to their twins as well (E70 review 17) ([f99db88](https://github.com/abdelrahmannasr/yadflow/commit/f99db8823e34dce8eb84c3bde8f87c04385d0f7f))
* **doctor:** compare artifacts the way every reader of the field does ([75688d9](https://github.com/abdelrahmannasr/yadflow/commit/75688d9208608c1626cbfdbcb274b0e2f3960979))
* **doctor:** give the missing-default hint E109's two repository actions, from one string (E110) ([2e751a9](https://github.com/abdelrahmannasr/yadflow/commit/2e751a984e18a1faa007caee0488b11454292c33))
* **doctor:** name folders under epics/ that are not valid epic ids ([1e0e4ac](https://github.com/abdelrahmannasr/yadflow/commit/1e0e4ac6357f03def0362ef5201e39e352b3a40b))
* **doctor:** never read a count or "not protected" the platform did not prove (E70 review 1) ([4800bff](https://github.com/abdelrahmannasr/yadflow/commit/4800bffbbeb8bebdf8a20f228992c82d88a98028))
* **doctor:** never rule a cause out and then offer it again (E70 review 29) ([aeef14b](https://github.com/abdelrahmannasr/yadflow/commit/aeef14b152e6941e7681901ce633e87339b1435a))
* **doctor:** point the legacy BMAD hints at what still works (E3) ([60df2dc](https://github.com/abdelrahmannasr/yadflow/commit/60df2dc168751f27bd6a892698f211550abd18b6))
* **doctor:** read the GitLab branch itself; a rule on an unprotected branch is no hold (E70 review 2) ([90d8df9](https://github.com/abdelrahmannasr/yadflow/commit/90d8df9581ba9c7f21b528fc119a4fb00e75a774))
* **doctor:** restore a guard I wrongly called unreachable (E70 review 18) ([dabd9a1](https://github.com/abdelrahmannasr/yadflow/commit/dabd9a1042da5db52e51c48ba5671e833269ed87))
* **doctor:** say GitHub's flag the same way everywhere; fill the level table (E70 review 9) ([dca372b](https://github.com/abdelrahmannasr/yadflow/commit/dca372bd289461235cab097b08e87561f5f3c0c6))
* **doctor:** say only what this read leaves possible (E70 review 15) ([328cf0a](https://github.com/abdelrahmannasr/yadflow/commit/328cf0a6a32de5805b60f6f33ff159ba1c8c5d90))
* **doctor:** say the GitLab repository could not be read, not that your login cannot (E109) ([3a8ffa5](https://github.com/abdelrahmannasr/yadflow/commit/3a8ffa583d6ac7f15270a9c217c77be5700b585c))
* **doctor:** see a step that carries ONLY the new dial name ([8ad471f](https://github.com/abdelrahmannasr/yadflow/commit/8ad471f2d90ef4d90df6016b92b4064ce867631b))
* **doctor:** stop the theme checks reporting correct files ([c6c3a0c](https://github.com/abdelrahmannasr/yadflow/commit/c6c3a0c278ccad2734061e1bd04fbb8b578431f6))
* **doctor:** tell the two reach gaps apart, and check every partly read line (E70 review 25) ([31dcf1d](https://github.com/abdelrahmannasr/yadflow/commit/31dcf1d5fd0a6e7f55dc4ee249b9c9f277b00500))
* **doctor:** test the GitLab repository 404 on the shape GitLab really sends (E109) ([81f4001](https://github.com/abdelrahmannasr/yadflow/commit/81f4001f518ea9cd65f31bb93f265176244408a9))
* **doctor:** the banner needs no rule at all, and lint is green again (E70 review 5) ([7830496](https://github.com/abdelrahmannasr/yadflow/commit/783049648722440999cde7ca079f6d61f0cff536))
* **doctor:** the clause binds to the rule, not to the branch it names (E70 review 26) ([4ea1403](https://github.com/abdelrahmannasr/yadflow/commit/4ea140368d7d71451204f49304b71fba52c4bbf7))
* **doctor:** the joined GitLab phrase reads as a sentence (E70 review 10) ([f81a423](https://github.com/abdelrahmannasr/yadflow/commit/f81a423bf0b5a672e0441ebfa04f2ac3e7fd18d3))
* **doctor:** the last paired dashes, and a limit narrower than the code (E70 review 14) ([d67ae31](https://github.com/abdelrahmannasr/yadflow/commit/d67ae3144e6735db23e73b9a9daa54e29e99a0a4))
* **doctor:** the review round — a finding whose only remedy always failed ([2783186](https://github.com/abdelrahmannasr/yadflow/commit/27831861756450ed0067271a80f08062e3c35b44))
* **doctor:** the solo line carries the same facts; hedge what is not read (E70 review 4) ([7019585](https://github.com/abdelrahmannasr/yadflow/commit/7019585ec60deaa28f4217f52a531c8e2943e8fa))
* **doctor:** the split turns on what the read proved, not where the name came from (E70 review 32) ([3930636](https://github.com/abdelrahmannasr/yadflow/commit/3930636ea87f92275c19fa6751c4a5be1ba074c5))
* **doctor:** the tier framing belongs to a refusal, and the grid reaches every branch (E70 review 21) ([c2377ef](https://github.com/abdelrahmannasr/yadflow/commit/c2377ef37fd0ae9e11f9b6d7b4454c3db23c8e4c))
* **doctor:** two answers that disagree are not known; a rule elsewhere is not "no rules" (E70 review 7) ([b002fd8](https://github.com/abdelrahmannasr/yadflow/commit/b002fd89fe9d95b402cb422e7491093b89510b4d))
* **engine:** drop the profile field nothing read, and fix the test seam ([07af526](https://github.com/abdelrahmannasr/yadflow/commit/07af526629684ee5b5c53438b13e2983ccb82bfc))
* **epic:** close the holes the E42 review found ([574870f](https://github.com/abdelrahmannasr/yadflow/commit/574870f0d6ebfe1d0c5501daa74a7927662fc13e))
* **epic:** protect the reserved front-zero id, and stop a false type clash ([871f763](https://github.com/abdelrahmannasr/yadflow/commit/871f763bbf0df4ca92f4991b1456db00bb2aecec))
* **foundation:** close the holes the roadmap-status review found ([69392d4](https://github.com/abdelrahmannasr/yadflow/commit/69392d441b4212448e0e3092eb74dc313e1f19b2))
* **foundation:** skills that hand-apply the gate know the Foundation, and the preview lists every moved file ([8e20897](https://github.com/abdelrahmannasr/yadflow/commit/8e20897d56c4c047d207fffdd7a644ebb81ae149))
* **foundation:** the review round — one product level in the guard, and a move that cannot strand ([5bca4ba](https://github.com/abdelrahmannasr/yadflow/commit/5bca4baded95a108018a780fd0c6ec06f1b3c62b))
* **gate:** `gate status` counts approvals the way the gate counts them ([eda7429](https://github.com/abdelrahmannasr/yadflow/commit/eda7429d6454f93c3ce034456ab61ab6b5afa3a7))
* **gate:** `gate status` prints the shortfall, and honours a skip only where the gate does ([95c9c2a](https://github.com/abdelrahmannasr/yadflow/commit/95c9c2a49adfcea6f4e8daf13932d386d4c5a75a))
* **gate:** a hand-edited cap below 1 is not printed; the inherited test says what it checks (E72) ([49dcef7](https://github.com/abdelrahmannasr/yadflow/commit/49dcef760aa00a46ec157cba2f78b90f9103b77f))
* **gate:** a malformed record in the merged review's own epic no longer stops the merge ([24eec39](https://github.com/abdelrahmannasr/yadflow/commit/24eec393e6b8ddbdefe71944c0045bbccda2dc16))
* **gate:** a shared roster name is never matched by name; gate open stamps the old PR (E62) ([a2b15eb](https://github.com/abdelrahmannasr/yadflow/commit/a2b15eb0d4519a05abe77ebb2ff64b6039ce9ea9))
* **gate:** a short-lane review PR does not ask for a contract re-lock it cannot do ([4855f3a](https://github.com/abdelrahmannasr/yadflow/commit/4855f3afaf90a885d3e1ae1c4d1d133857d6d142))
* **gate:** an exact submission time beats the roster name table; usage and doctor follow the simulation ([4d2c55c](https://github.com/abdelrahmannasr/yadflow/commit/4d2c55c45c7409942287a1b8834f2c58da756e5d))
* **gate:** an exact submission time continues only that review's records, never the whole name ([beaa5e3](https://github.com/abdelrahmannasr/yadflow/commit/beaa5e35a3aa77e85207b00d271885bddbd69e39))
* **gate:** claim and keep older records per review, so a closed step never deletes the other person's history ([1ed2070](https://github.com/abdelrahmannasr/yadflow/commit/1ed2070779055ccf610c0ad0012978183c7b08d0))
* **gate:** close the gaps the E18 review found ([69aa2cf](https://github.com/abdelrahmannasr/yadflow/commit/69aa2cfcf88db681dfb08cc89a200ef58a23a88a))
* **gate:** close the holes the E76 review found ([e460fb2](https://github.com/abdelrahmannasr/yadflow/commit/e460fb21f8efd9eb34ef1569361973a8297f3321))
* **gate:** eighth review round — "after the cap", one dead branch, two comments (E73) ([62e47c3](https://github.com/abdelrahmannasr/yadflow/commit/62e47c3181908e49bc69407775b51ad49951f083))
* **gate:** fifth review round — an approval anywhere is evidence, and every what-if line is conditional (E73) ([5b78858](https://github.com/abdelrahmannasr/yadflow/commit/5b788587187cdce397d36bb9efdbd772cadaaefc))
* **gate:** fourth review round — the floor wording on every surface, and a cap only ever lowers (E72) ([81dc0d8](https://github.com/abdelrahmannasr/yadflow/commit/81dc0d866118b167ca18d40531abf3ba53a856e8))
* **gate:** fourth review round — two kinds of line, each said once, and the GitLab gate bot is not a person (E73) ([622c6d6](https://github.com/abdelrahmannasr/yadflow/commit/622c6d66d35df22fde619e09cd69c0dc6de97e3d))
* **gate:** keep people under a shared roster name apart; read the PR number from its own segment ([b30ba90](https://github.com/abdelrahmannasr/yadflow/commit/b30ba9051a8a4d291b70bad18f47807ac4fee21b)), closes [#2048](https://github.com/abdelrahmannasr/yadflow/issues/2048)
* **gate:** old approvals stay with their person in every platform order (E62 review) ([8379656](https://github.com/abdelrahmannasr/yadflow/commit/83796566ca4f35452e717b63b9f08c7caf081d4f))
* **gate:** recognise old approvals exactly, and never pass one that is stale (E62 review) ([58fe6d2](https://github.com/abdelrahmannasr/yadflow/commit/58fe6d295dbfaa795f771c79e1be1f6f0a052800))
* **gate:** review round — the names check needs a login, and sees a team of one that reads as two (E73) ([65512d0](https://github.com/abdelrahmannasr/yadflow/commit/65512d0decc079c0a76867b8b05065fe3baef37f))
* **gate:** round-2 review — singular in open-pr's cap, and doc/test wording that still read as enforced (E72) ([64323b0](https://github.com/abdelrahmannasr/yadflow/commit/64323b0695792c7c9e6dc6ccc97fb56f516ff76a))
* **gate:** second review round — the silent-path test compares ledgers; doc conditions stated whole (E73) ([5580624](https://github.com/abdelrahmannasr/yadflow/commit/5580624d87dcf685eba6cdb2403ffce112b28974))
* **gate:** seventh review round — the smallest team is the larger of the logins and the names (E73) ([bcbdb32](https://github.com/abdelrahmannasr/yadflow/commit/bcbdb32d3a1d8646999e183aed3b67a481a3ad7d))
* **gate:** show the capacity cap and hold on the base alone until E73 (E72) ([3da8498](https://github.com/abdelrahmannasr/yadflow/commit/3da849895011ff19d1368499d825a2b9723a5583))
* **gate:** sixth review round — "no approval" names the window, and a name is "not matched to a login" (E73) ([d592818](https://github.com/abdelrahmannasr/yadflow/commit/d592818b24d4e78d9bf3563398a45fef87447d92))
* **gate:** the login stamp merges only proven reviews and never stops a merge ([5c80ce9](https://github.com/abdelrahmannasr/yadflow/commit/5c80ce95a0852fcb2d593c0edf7aac80d54f50fd))
* **gate:** the product-level move waits for its review, a clean checkout, and the default branch ([91193be](https://github.com/abdelrahmannasr/yadflow/commit/91193be19f652db23f6229026db9d81df0f5db4b))
* **gate:** the review-PR body is the one surface where the count LASTS, so the line dates itself ([6b378fc](https://github.com/abdelrahmannasr/yadflow/commit/6b378fc28a23543da2b67bc1bf27f07f29bded46))
* **gate:** third review round — no cap on a shortcut pass, one copy of the cap's words (E72) ([81d86c8](https://github.com/abdelrahmannasr/yadflow/commit/81d86c86cea311a66c6658ac951371cc82b9e405))
* **gate:** third review round — the silent-path test compares the PR records too; one prefix on every site (E73) ([7b3d874](https://github.com/abdelrahmannasr/yadflow/commit/7b3d874c207f103479dc5df84a398cec1ca9fbf4))
* **history:** a printed [@word](https://github.com/word) is always a real login; GitLab defaults only for an ownerless entry (E68 review 4) ([cadd82b](https://github.com/abdelrahmannasr/yadflow/commit/cadd82bf43c8adecde2aa5aab1dc156f7b7bf708))
* **history:** count as the gate counts; keep a thread's root; print every field safely (E20 review 2) ([a539bfc](https://github.com/abdelrahmannasr/yadflow/commit/a539bfc595d22bd5e574e04b02d7f1fbcd2efae6))
* **history:** follow the real thread, print only safe text, judge approvals as gate status does (E20 review) ([2654480](https://github.com/abdelrahmannasr/yadflow/commit/265448010a526656ef818f710ed2e7e63e7f682c))
* **history:** name an approver by the gate's test; refuse every flag it does not take (PR review 2) ([406dce6](https://github.com/abdelrahmannasr/yadflow/commit/406dce685068993e7e187dbd76e107c6897f0468))
* **history:** second-review findings for E68, and E67's address-shaped name ([86e34c0](https://github.com/abdelrahmannasr/yadflow/commit/86e34c025dd37e397f16e22fac35485cf52ccaa6))
* **history:** the whole-PR review — strict settings, JSON refusals, shape done, exact search (E20) ([e9e13ed](https://github.com/abdelrahmannasr/yadflow/commit/e9e13ed4202c723fe3563be4cd254981ecdeb14c))
* **history:** waive a step by the gate's own test, not its final state (E20 review 3) ([dd5665e](https://github.com/abdelrahmannasr/yadflow/commit/dd5665ede9f4fec14a2b20425e5a59e12cf78009))
* **hub-bridge:** the gate-sync fragments ship the major their release publishes ([01ac858](https://github.com/abdelrahmannasr/yadflow/commit/01ac8587d5affc4e0f87c27f935b18f1342683c5))
* **index:** clean a title before unquoting it; drop bidi controls (E111 review 4) ([5ff9755](https://github.com/abdelrahmannasr/yadflow/commit/5ff97552f2af139c9634e2d398f79089ecc271a0))
* **index:** commit the index only when git holds exactly what it read (E19 review) ([1b354bc](https://github.com/abdelrahmannasr/yadflow/commit/1b354bcf4a5881aa9c74cdc028dec2562bc8418e))
* **index:** drop control characters from a title (E111 review 3) ([65ac5f7](https://github.com/abdelrahmannasr/yadflow/commit/65ac5f7c567c041c2cb027676440698ddf9e1078))
* **index:** read a double-quoted title with JSON's escapes; pin every title rule (E111 review 2) ([0a6b820](https://github.com/abdelrahmannasr/yadflow/commit/0a6b82081d63f26953c54a67af14b31ccf164674))
* **index:** read a YAML-quoted title as YAML does, keep it one line (E111 review) ([972920f](https://github.com/abdelrahmannasr/yadflow/commit/972920ffa7e462da8d79ec747060fa57d9d82b83))
* **ledger:** the lock loop could never give up — two `continue`s skipped the cap and the sleep ([e66eab6](https://github.com/abdelrahmannasr/yadflow/commit/e66eab61910eb3b4bd7c3f9ba50f9fa9c39b5fa9))
* **lifecycle:** place an epic in Build, and keep the discovery epic off the ladder ([1c01e0c](https://github.com/abdelrahmannasr/yadflow/commit/1c01e0c8cf7aa2410b12969e43e5e45b5402edf2))
* **migrate:** name every file the apply writes, and repair a half-made pair ([a3211e3](https://github.com/abdelrahmannasr/yadflow/commit/a3211e3dfc246bbe89ef3bc322fa6be29bd735bb))
* **migrate:** the --json preview names the product config's mirror partner ([1eb4738](https://github.com/abdelrahmannasr/yadflow/commit/1eb4738c64899db78fad46036603e2fc7b71f99c))
* **mode:** close the gaps the E10 review found ([afbeca4](https://github.com/abdelrahmannasr/yadflow/commit/afbeca4599f379e0e815a3bb48e253461f9d931a))
* **mode:** only a login's approval proves a second person; one wiring for the suggestion (E74) ([0bd132f](https://github.com/abdelrahmannasr/yadflow/commit/0bd132f7664645f56dcb182c29721f7a94713245))
* **next:** an off-route step is not an unknown one, and a phase is not a passed one ([7f08da2](https://github.com/abdelrahmannasr/yadflow/commit/7f08da218463caa7f630a464ba0423bba145c746))
* **open-pr:** no address, no cross-platform join, no quiet "nobody" (E68 review) ([0d7814e](https://github.com/abdelrahmannasr/yadflow/commit/0d7814e1021dfc73845e65e7403a6ea66d2f9b6d))
* **people:** a mistyped future approval is not proof even beside a current commit (E74) ([c1b9d7c](https://github.com/abdelrahmannasr/yadflow/commit/c1b9d7c18963133fca92e2eaaa4fdcd76676986e))
* **people:** ask git for an absolute date, so the count really does read no clock (E71) ([e065734](https://github.com/abdelrahmannasr/yadflow/commit/e0657347462310ef315068a3e9f3ba52d08b2b0a))
* **people:** close the identity question — `source: 'bridge'` is the proof, and the keyspace is namespaced ([9e055d7](https://github.com/abdelrahmannasr/yadflow/commit/9e055d711a70c2a6b6798dc5f87ec8a53be45158))
* **people:** the review round — eleven ways a partial read still became a number ([edf858e](https://github.com/abdelrahmannasr/yadflow/commit/edf858e6d3b2f5bd29877fe04517d8bcd5c4cdc8))
* **people:** validate the date git hands back — a formatter is not a validator ([dc1249a](https://github.com/abdelrahmannasr/yadflow/commit/dc1249aeae31e107eec359494b95e2230a16a4eb))
* **release:** refuse to ship a file-shape change as anything but a major ([173dc9a](https://github.com/abdelrahmannasr/yadflow/commit/173dc9a76453b0e5e0ec2341ad05458b71d9a085))
* **release:** the release checks ask semantic-release what a commit releases ([c5de745](https://github.com/abdelrahmannasr/yadflow/commit/c5de7453ed41bb5a6bac514652a857b6db5d7f8a))
* **risk-map:** close ten review findings in the map, its check and its command ([aafc578](https://github.com/abdelrahmannasr/yadflow/commit/aafc578c43cc2282e5aa837f3f88768cd7e5e30d))
* **risk-map:** doctor's section sat under threadChecks' comment; stale comments and help alignment ([5258b54](https://github.com/abdelrahmannasr/yadflow/commit/5258b54f352ba1d0276bec098d766e233beee77a))
* **risk-map:** every pathspec is :(literal) — a map name describes a directory, it never tells git what to do ([6a4ef28](https://github.com/abdelrahmannasr/yadflow/commit/6a4ef28bb105b3129445cef925d420863b7f271b))
* **risk-map:** first-review findings — a quoted path, a move out, an older check, and a name's own spacing ([016ad87](https://github.com/abdelrahmannasr/yadflow/commit/016ad87d050b611d69b6fb7d48a850dfac17a2a7))
* **risk-map:** first-review findings — read the base map from any subfolder, and never exit 1 on a trailing comma ([e6ac49f](https://github.com/abdelrahmannasr/yadflow/commit/e6ac49f32f5944d2beddbe3adc0b1b4ee2ca3ed7))
* **risk-map:** four second-review findings in the PR check and the file list ([c5eb332](https://github.com/abdelrahmannasr/yadflow/commit/c5eb33293b9dde0bfc0509dbcba45e94116646b0))
* **risk-map:** second-review findings — a failing git step is "not counted", and the check runs from the repo root ([c51a882](https://github.com/abdelrahmannasr/yadflow/commit/c51a882bcac73561b216e936ff495158d050782a))
* **risk-map:** second-review findings — a newline in a file name, and a merge that hid a real author ([845a341](https://github.com/abdelrahmannasr/yadflow/commit/845a341e08495cfc81dc24998e7bd80190587a62))
* **risk-map:** third-review finding — a failing git ls-tree is "not counted", not "no map" ([efeffc0](https://github.com/abdelrahmannasr/yadflow/commit/efeffc0e4bf5edfadbcc2a67fbc6b6397e1a63c5))
* **risk-map:** third-review findings — bytes for every tool in the check, and only the map itself counts as deleted ([ac4569e](https://github.com/abdelrahmannasr/yadflow/commit/ac4569ec8dba85ea39a7659e8b6038e7a1025d89))
* **setup:** keep a team's edit to .sdlc/config.yaml through yad update (E3) ([86b2034](https://github.com/abdelrahmannasr/yadflow/commit/86b20348a08bb0a82ce5de03bad0ec5347cbc15e))
* **skills:** the epic.md templates were unreadable by the gates they feed ([96922de](https://github.com/abdelrahmannasr/yadflow/commit/96922de4ae3e08efe8faee2cbff5abe6c468eabc))
* **skills:** the review gate must open the gate with the engine, not by hand ([f453509](https://github.com/abdelrahmannasr/yadflow/commit/f453509cbcdd0ec7fa9156af9324eb940846efb4))
* **skip:** close the holes the E39 review found ([33eb17a](https://github.com/abdelrahmannasr/yadflow/commit/33eb17a85f982456549b225603db04747cd27d94))
* **skip:** close the holes the verified-skip review found ([311e1ca](https://github.com/abdelrahmannasr/yadflow/commit/311e1cab3f439fc3a4752d997bdb2260ac42bf47))
* **skip:** refuse a skip on a ledger CI owns on a verified Product ([b9b2d1a](https://github.com/abdelrahmannasr/yadflow/commit/b9b2d1a54f7a31deaf75746581beb3e217611555)), closes [#162](https://github.com/abdelrahmannasr/yadflow/issues/162)
* **state:** a corrupt ledger gets an error with a hint, not a stack trace ([2cda22d](https://github.com/abdelrahmannasr/yadflow/commit/2cda22d76328e373dfc46b072385b02715529b95))
* **state:** a gate write moves the recorded shape, not just the fields ([6906c57](https://github.com/abdelrahmannasr/yadflow/commit/6906c577251d96ddf583e5fb83dfb265eb985a86))
* **state:** a short lane has no optional steps, and that is not a broken chain ([136eec8](https://github.com/abdelrahmannasr/yadflow/commit/136eec83888d5915facdf80c9dd073ff56d95513))
* **state:** close the holes the E41 review found in re-open and debt ([9b8565e](https://github.com/abdelrahmannasr/yadflow/commit/9b8565e165869f5a6b10f5c46c887bc422ce78d2))
* **state:** keep the product-level role under BOTH spellings, and report drift ([1b9ac44](https://github.com/abdelrahmannasr/yadflow/commit/1b9ac441a6055f2b17422f11c0aee0a025c7b3ba))
* **state:** make the two names one file, in both directions ([0a842c7](https://github.com/abdelrahmannasr/yadflow/commit/0a842c74560d96c47064009b3ab4714f0f00ab7f))
* **state:** one rule for "this epic's route never had that step" ([b687048](https://github.com/abdelrahmannasr/yadflow/commit/b687048e49c7bcfa4f512c7e92de31e6dce8f0d7))
* **state:** shape 6 stamps against the routes that existed when it landed ([939c862](https://github.com/abdelrahmannasr/yadflow/commit/939c86228b20540ad22c621c19b63e4859899647))
* **state:** the count reports, it does not hold a gate — yet (E7 review round) ([10bc3ff](https://github.com/abdelrahmannasr/yadflow/commit/10bc3ff06816ff6430bc47b8382363d57c6b9380))
* **state:** the review round — a live writer of `blocked` this change said did not exist ([7136b93](https://github.com/abdelrahmannasr/yadflow/commit/7136b930b10bba4e8ffe03d217e706409bd5153e))
* **state:** write the work-item type at the top of state.json, not the bottom ([195c03a](https://github.com/abdelrahmannasr/yadflow/commit/195c03aa96f5c12526b22d54c4db9ad9d4a4ef63))
* **thread:** an epic never owns an artifact its route has no step for ([6725c5a](https://github.com/abdelrahmannasr/yadflow/commit/6725c5ae9dde8e226f34ae1e1d5888fa86811641))


### Features

* **agents:** support agents beyond Claude Code, and guard Cursor too (E11) ([8481398](https://github.com/abdelrahmannasr/yadflow/commit/848139856c5d23cdf52b601d02f7155d5756d9b4))
* **checks:** guard the Foundation ledger in foundation/ (E75) ([0608e41](https://github.com/abdelrahmannasr/yadflow/commit/0608e41f8a203a633b4ef2e3449711de9201890c)), closes [#162](https://github.com/abdelrahmannasr/yadflow/issues/162)
* **checks:** guard the Product index as CI-owned on a verified Product (E19) ([5396827](https://github.com/abdelrahmannasr/yadflow/commit/5396827650597341cd98e935c595c73899b4a61f))
* **checks:** risk-map-check.sh warns on every PR where the risk map went stale ([bc2ada8](https://github.com/abdelrahmannasr/yadflow/commit/bc2ada8707a9499d5ef8afcb1e4259be02980eef))
* **cli:** add `yad skill` to bind, list and unbind a step's skill ([7b4c9c6](https://github.com/abdelrahmannasr/yadflow/commit/7b4c9c6cdc2e5734a5f670b805003782d877674f))
* **cli:** the project chooses which skill runs a step (E6) ([a07746e](https://github.com/abdelrahmannasr/yadflow/commit/a07746e327056448f1c3566490cf7d17aa13122d))
* **cli:** warn before any command reads a project on a newer file shape ([f5695da](https://github.com/abdelrahmannasr/yadflow/commit/f5695da00299169f3bdb34913aa7c90448501510))
* **cli:** yad epic new — the engine writes an epic's lifecycle (E17) ([92e67d6](https://github.com/abdelrahmannasr/yadflow/commit/92e67d635efddcadbd8f4399dac27b0c56402cbe))
* **codeowners:** warn when CODEOWNERS is stale (E69) ([6c35d6a](https://github.com/abdelrahmannasr/yadflow/commit/6c35d6a2d854e089561b708c6441616117816cf6))
* **defer:** yad defer --debt marks a deferral owed back, reminded until paid (E41) ([b20d57d](https://github.com/abdelrahmannasr/yadflow/commit/b20d57dc85abbb8509a6298bb5c98bff66cd827c))
* **defer:** yad defer and yad undefer set an optional step aside (E37) ([b6f2391](https://github.com/abdelrahmannasr/yadflow/commit/b6f2391df9feb0f9a0b9cf5af74eb928de138767))
* **dial:** yad dial, yad kill and yad unkill — the advance dial set freely (E34) ([56e8300](https://github.com/abdelrahmannasr/yadflow/commit/56e8300c37839f6a688d821f52ceee9ea682f219))
* **doctor:** keep the access cause open when GitLab names no default branch (E110) ([ddb8159](https://github.com/abdelrahmannasr/yadflow/commit/ddb8159c792e5bddb42fa135b68e25ab5774a073))
* **doctor:** name a leftover _bmad/sdlc/ folder (E3) ([5d7b1ab](https://github.com/abdelrahmannasr/yadflow/commit/5d7b1ab4632b5712226057a7d41a796070512bae))
* **doctor:** name the cause behind a GitLab branch 404 from its body (E109) ([64865d7](https://github.com/abdelrahmannasr/yadflow/commit/64865d71a8449453e05942f0dac69ec413b5e4c0))
* **doctor:** people:roster-unused says when the roster can go ([eb0c012](https://github.com/abdelrahmannasr/yadflow/commit/eb0c012963af43a15b62dc3c229cd32f7c791a3a))
* **doctor:** say whether each repo's branch requires an approval (E70) ([e93dd3b](https://github.com/abdelrahmannasr/yadflow/commit/e93dd3b7cbe4ed52fc1d9a9a7b91613c2bfe0cf8))
* **engine:** lifecycle profiles, with today's chains written down (E5) ([44564d4](https://github.com/abdelrahmannasr/yadflow/commit/44564d44d826265138d6fdc1f5feee5ab5760988))
* **engine:** the step catalogue, validated in code (E4) ([c3823bf](https://github.com/abdelrahmannasr/yadflow/commit/c3823bf4bed067a91496fe79c8cd490088c9e71c))
* **epic:** `yad foundation new` — the engine seeds the Product level (E75) ([2cf2241](https://github.com/abdelrahmannasr/yadflow/commit/2cf2241556d8bfef4e6682460c51ab86319024e7))
* **epic:** the grouping theme tag (E31) ([bf8a31c](https://github.com/abdelrahmannasr/yadflow/commit/bf8a31c880c445dedd1b4abb78f6314971c1cacb))
* **epic:** yad epic new --parent seeds a threaded change-epic (E42) ([3786ae2](https://github.com/abdelrahmannasr/yadflow/commit/3786ae246ec9b5759de590c72a928e33e2ad7d96))
* **foundation:** yad foundation status reads roadmap features from the epic ledgers ([e6a4a85](https://github.com/abdelrahmannasr/yadflow/commit/e6a4a853b2f31204ed687b16f0bdba3dd68c245c))
* **gate:** approvals record the platform's evidence; GitLab's approval time is read ([0e16728](https://github.com/abdelrahmannasr/yadflow/commit/0e167282349f832128757caeda10200617b0a2d7)), closes [#156](https://github.com/abdelrahmannasr/yadflow/issues/156)
* **gate:** cap the approval count at the active people less one, and record every cap (E72) ([f99e77d](https://github.com/abdelrahmannasr/yadflow/commit/f99e77da98484623d6ed1cb270dcc1dea3a08c1f))
* **gate:** every surface that reports a gate prints the arithmetic ([0ac5617](https://github.com/abdelrahmannasr/yadflow/commit/0ac56179cd49ab3d66ee2e8642500cd3f420e27c))
* **gate:** print how many people there are to ask, on every surface a gate reports itself (E71) ([cfabed9](https://github.com/abdelrahmannasr/yadflow/commit/cfabed9521d431b043ab356b46f9f54ec306a005))
* **gate:** record how a step closed (E18) ([a1c9050](https://github.com/abdelrahmannasr/yadflow/commit/a1c905037061437ecdf6183df26f246cb8cb049b))
* **gate:** record the platform login on older records while the roster exists ([cc7b02f](https://github.com/abdelrahmannasr/yadflow/commit/cc7b02f36658c5517fcc49b3f464ca1cfeeff048))
* **gate:** rename the PR ledger too, and guard both names ([c0b8b00](https://github.com/abdelrahmannasr/yadflow/commit/c0b8b00bdf77203346127984f67cce95206ba054))
* **gate:** say on the closing record when solo mode waived the approvals (E10) ([f733e5e](https://github.com/abdelrahmannasr/yadflow/commit/f733e5e10a9b8ae3c6255e4e724122e9346ac64b))
* **gate:** say when a gate may not be met — reported, never enforced (E73) ([444b67c](https://github.com/abdelrahmannasr/yadflow/commit/444b67c0e77087d286fab60bd853e1f3272320c0))
* **gate:** the gate bot converts a verified Product's product level to foundation/ ([ad3bc94](https://github.com/abdelrahmannasr/yadflow/commit/ad3bc94b0a373bd131bb1609afd6cac610aeeef8))
* **gate:** warn when a Foundation section still holds only its template (E76) ([8a5be38](https://github.com/abdelrahmannasr/yadflow/commit/8a5be38404bcb022cf9e98b10d529815d6bc4ad4))
* **history:** yad history — list, show, search, all with --json (E20) ([c37c9fe](https://github.com/abdelrahmannasr/yadflow/commit/c37c9fe8c346855c3a04d6921438ccaade336d3f))
* **index:** `yad index` rebuilds the front door on the default branch (E19) ([5b6dfd6](https://github.com/abdelrahmannasr/yadflow/commit/5b6dfd6f3ae01a5f9409fb63e59f32dad5ab429d))
* **index:** a title for every work item, carried by the Product index (E111) ([7ab7833](https://github.com/abdelrahmannasr/yadflow/commit/7ab78334eab64153e5d5e7a31939416ff4224f19))
* **index:** build the Product index from every work item's own files (E19) ([5024d61](https://github.com/abdelrahmannasr/yadflow/commit/5024d61807a4354c6969dedf1d0d87aa01e318c2))
* **index:** the gate, CI and migrate keep the index; doctor says when it is behind (E19) ([97aba2b](https://github.com/abdelrahmannasr/yadflow/commit/97aba2be1d3c934548c195a5d8b6b1647ba8910b))
* **lifecycle:** name the six phases, derived from the step ([1b77249](https://github.com/abdelrahmannasr/yadflow/commit/1b77249c197ca70df7f95270004ca94a6b930d6a))
* **mode:** suggest team mode when the count disagrees with solo (E74) ([4756ef9](https://github.com/abdelrahmannasr/yadflow/commit/4756ef92ecedfe0dda0e5bfa3f2785a10ac6424a))
* **mode:** yad mode solo|team sets who must approve, and records the change (E10) ([ce4077c](https://github.com/abdelrahmannasr/yadflow/commit/ce4077c5055812f61736924c2f76c903acd6db66))
* **open-pr:** suggest reviewers from history and CODEOWNERS (E68) ([9214ed9](https://github.com/abdelrahmannasr/yadflow/commit/9214ed90123d55ea1fed59541df9148b0b322ed9))
* **people:** count active people live, three windows, unknown is never a small number (E71) ([1b186a0](https://github.com/abdelrahmannasr/yadflow/commit/1b186a0125f3b5a1ece5edc85521e0b58596fd59))
* **platform:** a record names the login gh/glab reports, not the roster's (E62) ([6c2ef4e](https://github.com/abdelrahmannasr/yadflow/commit/6c2ef4ee4df6da9e8f9000055e1aa32359ded0bc))
* **risk-map:** a directory to risk-level map per code repo, with yad risk-map check|draft and a doctor section ([f3d8115](https://github.com/abdelrahmannasr/yadflow/commit/f3d811547360381409560583cce2e601f1e73cc4))
* **risk-map:** a high directory asks for an approver who has worked there lately (E67) ([28f4e58](https://github.com/abdelrahmannasr/yadflow/commit/28f4e58903432d4bb1cfa7e45529ad65f840c9b6))
* **risk-map:** a high directory on the base branch's map adds the high step (E66) ([ad6fcac](https://github.com/abdelrahmannasr/yadflow/commit/ad6fcaca496c7dbc377268a9771bdf18b3737e91))
* **setup:** install the module config into .sdlc/, not _bmad/sdlc/ (E3) ([da18dac](https://github.com/abdelrahmannasr/yadflow/commit/da18dacc1b02c9dba9f1079aeb26c89286805137))
* **setup:** let a scripted setup choose its agent directories ([8c13a06](https://github.com/abdelrahmannasr/yadflow/commit/8c13a0672a231b70646501a8b780da85bf503ff6))
* **skills:** the epic and change templates carry a theme ([8b0c71d](https://github.com/abdelrahmannasr/yadflow/commit/8b0c71ddeaec9ea189e663644f7353a1a3c8246a))
* **skills:** the skills call the engine instead of writing state.json (E17b) ([f0e0d77](https://github.com/abdelrahmannasr/yadflow/commit/f0e0d77eb97ae20a929f04d5bb4d947546c3d4bc))
* **skip:** yad skip <epic> <story> --repo skips a whole Build lane (E39) ([261e73e](https://github.com/abdelrahmannasr/yadflow/commit/261e73e360bb31cc35272d7c4f6a06394b713515))
* **skip:** yad skip and yad unskip name no step (E36) ([abbb4e0](https://github.com/abdelrahmannasr/yadflow/commit/abbb4e080fc2c21c61776f555a5b1c66e2359b53))
* **state:** a chore lane and a spike lane (E40) ([f521c22](https://github.com/abdelrahmannasr/yadflow/commit/f521c22487e5ad44b029e977ae6716925f4ec731))
* **state:** a Shape author step is not a gate because it is locked (E34) ([298546e](https://github.com/abdelrahmannasr/yadflow/commit/298546ef6ef67ea1c42cf01178aecc494bd938ef))
* **state:** a step is optional because the epic's ROUTE says so (E35) ([1641b46](https://github.com/abdelrahmannasr/yadflow/commit/1641b46e6fd3b57526862ce4448c4506ccdce4ec))
* **state:** a step's gate says how many people it needs (E7) ([314e709](https://github.com/abdelrahmannasr/yadflow/commit/314e70982a0b61927c0a379516d4233c08260b99))
* **state:** every ledger walker finds the Foundation (E75) ([bf86753](https://github.com/abdelrahmannasr/yadflow/commit/bf867537d17150633faa5a9014df2c4b1e59238c))
* **state:** give the product settings their new name, keeping the old one beside it ([8d0cf1b](https://github.com/abdelrahmannasr/yadflow/commit/8d0cf1b500a6a15fcbb5e53b7806966bf1457a90))
* **state:** the Product level — Foundation in the model (E75) ([676bbd1](https://github.com/abdelrahmannasr/yadflow/commit/676bbd1ae4557e0c4eb744f62f75ada74969b36b))
* **state:** the step-state model, and shape 7 writes it (E38) ([4064067](https://github.com/abdelrahmannasr/yadflow/commit/40640673adae5f2065041d92d431fdda522b6b32))
* **unblock:** yad unblock clears a recorded blocker (E37) ([5ba73f5](https://github.com/abdelrahmannasr/yadflow/commit/5ba73f560923fcf297ab460a82cca26ee2c1feeb))
* **update:** name an edited gate-sync fragment left on another major ([b33f9e6](https://github.com/abdelrahmannasr/yadflow/commit/b33f9e61c51101f2e5ebb9756e185ece3ce7de74)), closes [#164](https://github.com/abdelrahmannasr/yadflow/issues/164)


### BREAKING CHANGES

* `yad docs build`, `yad docs deploy` and
`yad docs sync --refresh` now exit 1 when a site's npm install or build
fails, or when a site named with --epic/--overview was never generated;
`yad docs build` also exits 1 when npm is not on PATH. Under --json these
are refusals (`ok: false`) naming the site. A script that ran them and
ignored build failures will now stop.
* every `--json` answer is now the E1 envelope. `yad
history --json` carries `jsonVersion` instead of `schemaVersion`; `yad
thread --json` and the review bundles gain `ok`; `yad usage --json`
wraps the model (`--format json` still prints the bare model); a refusal
always has `error`, `code` and `hint`; `warnings` is always present. The
full list is in docs/CLI.md, "--json on every command".
* the ROUTE line of risk-route.sh and hub-route.sh
changed; anything parsing it must be updated.
* in a repo whose refreshed gate has landed, a Verified
commit from an email nobody listed now passes CI.
* `yad roster` is removed, and `yad setup` no longer
collects reviewers or repo owners.
* `yad usage --json` members carry no `role` or `rostered`,
and the `dormant` and `reviewer-not-reviewing` flags are no longer raised.
* review and task PRs no longer request reviewers
automatically.
* the owner/reviewer/domain-owner rule no longer holds a
team gate; one approver does. `defaultReviewers` and the roster shape
check are gone.
* file shape 10. An older yadflow reading a chain with a
re-opened step names that step the blocker of the work after it, and
re-opens that work when its review passes. See docs/migrations/shape-10.md.
* file shape 9. An older yadflow fingerprints the whole
file, so it reads every approval this release records on a file with a
`status:` line as stale. On a local ledger with mixed versions, that
holds an open gate for the teammate on the older release. Upgrade
everyone on the project together. A verified project runs
`yad migrate --apply` and commits the result; CI brings each state.json
to shape 9 at its next write.
* file shape 8. A migrated project keeps its product level
in `foundation/`, which a 3.x yadflow does not read. Upgrade everyone on
the project together. On a verified Product, run `yad update` so the
committed checks guard `foundation/`.
* **state:** shape 7 is the first file shape that changes a value in place
rather than adding a key beside an old one, so a 3.x CLI cannot read a migrated
project: it sees `todo` as an unknown status and reads `skipped` / `satisfied` as
"not done", which makes a UI-less epic or a change-epic look stuck. This release
reads every pre-shape-7 project correctly; run `yad migrate --preview` first and
upgrade everyone on the project. See docs/migrations/shape-7.md.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
* file shape 5. Run `yad migrate` to preview, then
`yad migrate --apply`. See docs/migrations/shape-5.md.
* project files change shape twice in this release, and both are
handled by one command. Shape 2 records who writes the ledger as
`"ledger": "verified" | "local"` in the product settings; shape 3 renames those
settings from `.sdlc/hub.json` to `.sdlc/product.json`, renames each epic's
`hub-prs.json` to `product-prs.json`, and gives every reviewer's product-level
role a second spelling. Nothing is taken away: every old name is still written
and is still the one read, so a check gate committed in your repository keeps
working whether or not you have run `yad update`. Run `npx yadflow@<version>
migrate` to preview — it writes nothing — then `yad migrate --apply`, which backs
up every file it rewrites. docs/migrations/shape-2.md and shape-3.md explain both.

Shape 2 shipped earlier as 3.19.0-next without declaring a break, which meant the
"run yad migrate first" banner never fired for it. This footer covers both.

# [3.19.0-next.2](https://github.com/abdelrahmannasr/yadflow/compare/v3.19.0-next.1...v3.19.0-next.2) (2026-09-07)


### Bug Fixes

* **release:** let a pre-release publish past its own test suite ([70286ce](https://github.com/abdelrahmannasr/yadflow/commit/70286ce833b300d02d2781ac589d727481f5e7eb))

# [3.19.0-next.1](https://github.com/abdelrahmannasr/yadflow/compare/v3.18.1...v3.19.0-next.1) (2026-09-07)


### Bug Fixes

* **checks:** accept every integrity algorithm Corepack accepts in packageManager ([367947d](https://github.com/abdelrahmannasr/yadflow/commit/367947d8d9856138b531061e4b686057ee9f715f))
* **checks:** cache the Corepack home alongside the dependency cache ([23d92bc](https://github.com/abdelrahmannasr/yadflow/commit/23d92bc8204063bbd7754bfd038585eeb6f705bb))
* **checks:** close configurable CI review findings ([6d90018](https://github.com/abdelrahmannasr/yadflow/commit/6d900183bbee5785f4ff0d5c868a6a55ce01a9b7))
* **checks:** fail with guidance when corepack is missing for a declared packageManager ([3a9f576](https://github.com/abdelrahmannasr/yadflow/commit/3a9f5760bcca050d87008e414b856d5b307f30b8))
* **checks:** give the same guidance when Corepack is present but stale ([0cdf4d1](https://github.com/abdelrahmannasr/yadflow/commit/0cdf4d157946d9185bfcc286ebddcdfb5d65a6aa))
* **checks:** keep a yarn/bun-declared repo with an npm lockfile on the npm path ([713e707](https://github.com/abdelrahmannasr/yadflow/commit/713e7074b6813de0e0fd6e12e970e8372a1309eb))
* **checks:** keep the gate jobs' variables off the host GitLab pipeline ([7cb2c35](https://github.com/abdelrahmannasr/yadflow/commit/7cb2c35a3011dbd8bf8d048f7aa02578ac54a1db))
* **checks:** keep the npm path when a repo carries both lockfiles ([67fbdb4](https://github.com/abdelrahmannasr/yadflow/commit/67fbdb4e2c82188b37b1d175260b48da17d5e051))
* **checks:** make build-test-lint fail closed on a rejected package.json ([83241ee](https://github.com/abdelrahmannasr/yadflow/commit/83241eed61e4306853151e6105c0b7c8bdd06d55))
* **checks:** pass the worker cap to jest/vitest under pnpm without npm's `--` ([55db7ee](https://github.com/abdelrahmannasr/yadflow/commit/55db7eed85173472a17e7591636d7fc830a5a5b6))
* **checks:** read package.json the way npm does before judging it ([8021c78](https://github.com/abdelrahmannasr/yadflow/commit/8021c7850d4f7d0887923165adc585fc27da260a))
* **checks:** require lowercase Corepack digests ([4750b8b](https://github.com/abdelrahmannasr/yadflow/commit/4750b8b597bfdd4d7d2739a0525f91a2002e41a3))
* **checks:** restore dependency caching in the GitHub quality job, for pnpm too ([21c92f0](https://github.com/abdelrahmannasr/yadflow/commit/21c92f026aa590ec464eec7152af27ad2be9a49d))
* **checks:** run the gate's lint/build/test through the pinned npm too ([8404da3](https://github.com/abdelrahmannasr/yadflow/commit/8404da326f8a19ae807c58808b6203572aadb9b4))
* **checks:** support configurable CI toolchains ([30557e4](https://github.com/abdelrahmannasr/yadflow/commit/30557e419a9fec5adca06a3ecb8ca09469b2a58a))
* **checks:** validate Corepack integrity metadata ([a6c3fd3](https://github.com/abdelrahmannasr/yadflow/commit/a6c3fd3d84a370f81477ed9b551bc29f5765296f))
* **skills:** teach the skill layer that `ledger` is the switch ([d4622ab](https://github.com/abdelrahmannasr/yadflow/commit/d4622ab2293cfe49a36791f6cf51472b4d5701ad)), closes [#186](https://github.com/abdelrahmannasr/yadflow/issues/186)
* **state:** read an unstamped file as shape 1, not as the engine's shape ([6d8c608](https://github.com/abdelrahmannasr/yadflow/commit/6d8c608215175fac98933ffee6f714471454a8d9))
* **update:** install templates newly added to a wired repo on `yad update` ([8e8d92f](https://github.com/abdelrahmannasr/yadflow/commit/8e8d92f1265e2ed375bf0a53307270a25d8c33f3))
* **update:** take only yad's own wiring as proof a repo is wired ([3c90134](https://github.com/abdelrahmannasr/yadflow/commit/3c90134985eebb3b7faa91be2c45387d54851324))


### Features

* **state:** record who writes the ledger as `ledger: verified | local` ([6623199](https://github.com/abdelrahmannasr/yadflow/commit/66231997156bb1ffa446ebb5edd28d8ebf8def91)), closes [#186](https://github.com/abdelrahmannasr/yadflow/issues/186)

## [3.18.1](https://github.com/abdelrahmannasr/yadflow/compare/v3.18.0...v3.18.1) (2026-09-05)


### Bug Fixes

* **docs:** raise the template's react-router-dom floor to the patched version ([ca510d4](https://github.com/abdelrahmannasr/yadflow/commit/ca510d40d42600254aa39821de99ae5990698605))
* **docs:** ship the docs template with a patched react-router-dom ([28b6ff7](https://github.com/abdelrahmannasr/yadflow/commit/28b6ff768fb6b11799ab28e4e4d780aa6bfca5bc)), closes [hi#severity](https://github.com/hi/issues/severity)

# [3.18.0](https://github.com/abdelrahmannasr/yadflow/compare/v3.17.3...v3.18.0) (2026-09-05)


### Features

* **cli:** add yad migrate with preview, backup and report ([39dde87](https://github.com/abdelrahmannasr/yadflow/commit/39dde87b9f38936b05b6cd6243a67b9a2aea7fb9))
* **doctor:** report shape drift against the engine ([f2dc377](https://github.com/abdelrahmannasr/yadflow/commit/f2dc377815a1135b4015cff9f46f3384dc08ee56))
* **release:** publish majors to a next channel and warn before upgrading ([70d2334](https://github.com/abdelrahmannasr/yadflow/commit/70d23347021a3635e8d71f6465d516bd6e72322d))
* **state:** stamp schemaVersion 1 on every engine-written file ([872dde6](https://github.com/abdelrahmannasr/yadflow/commit/872dde61975b942e95670c60f329621802256ab8)), closes [#163](https://github.com/abdelrahmannasr/yadflow/issues/163)

## [3.17.3](https://github.com/abdelrahmannasr/yadflow/compare/v3.17.2...v3.17.3) (2026-09-03)

## [3.17.2](https://github.com/abdelrahmannasr/yadflow/compare/v3.17.1...v3.17.2) (2026-09-03)

## [3.17.1](https://github.com/abdelrahmannasr/yadflow/compare/v3.17.0...v3.17.1) (2026-09-02)

# [3.17.0](https://github.com/abdelrahmannasr/yadflow/compare/v3.16.3...v3.17.0) (2026-08-12)


### Bug Fixes

* **check:** leave an already-wired settings.json byte-identical ([1d50ed4](https://github.com/abdelrahmannasr/yadflow/commit/1d50ed4b173f7de2350344fc5facb1de19bd9c61))
* **check:** stop the hook wiring from damaging a file the team owns ([a348c99](https://github.com/abdelrahmannasr/yadflow/commit/a348c997ba3b87406addef4e5868bdd14406fa49))
* **doctor:** give an unparseable settings file its own advice ([0862875](https://github.com/abdelrahmannasr/yadflow/commit/08628750a3c8e8642075db0fc0712d217dacdeb4))
* **doctor:** report the ledger guard against what actually arms it ([a1ec4ba](https://github.com/abdelrahmannasr/yadflow/commit/a1ec4bafec8441b6bf8c0515bf4f1bd68cb00ef7))
* **hook:** read the seeded set the way the CI gate reads it ([38cd206](https://github.com/abdelrahmannasr/yadflow/commit/38cd206fc94256782a074a309fe6dbc2ae3ce135)), closes [#171](https://github.com/abdelrahmannasr/yadflow/issues/171)
* **hook:** resolve the command before suppressing the update notice ([44d8768](https://github.com/abdelrahmannasr/yadflow/commit/44d87683abbc8acff02b011b6ce47d140e8075d3))
* **hook:** survive an empty command array on bash 3.2 ([7fd6984](https://github.com/abdelrahmannasr/yadflow/commit/7fd698412d8229f312f62c2a21f299dad445700b))


### Features

* **check:** install and report the agent ledger guardrail ([8251d9f](https://github.com/abdelrahmannasr/yadflow/commit/8251d9f92740690ca7b3e27a0280f999593793f3))
* **hook:** refuse an agent the CI-owned ledger write, at the edit ([15291ce](https://github.com/abdelrahmannasr/yadflow/commit/15291ce2d73167cebeb5aba52920bdb078d6d0aa))

## [3.16.3](https://github.com/abdelrahmannasr/yadflow/compare/v3.16.2...v3.16.3) (2026-08-12)


### Bug Fixes

* **open-pr:** base the task PR on the repo default branch, not main ([63da011](https://github.com/abdelrahmannasr/yadflow/commit/63da011fd2c4b6e81940c646879cc692b634a877)), closes [#168](https://github.com/abdelrahmannasr/yadflow/issues/168)


### Performance Improvements

* **review:** stop probing the platform for an already-configured base ([0fc3de3](https://github.com/abdelrahmannasr/yadflow/commit/0fc3de34c7a522ec3463953778787f247ab28071)), closes [#191](https://github.com/abdelrahmannasr/yadflow/issues/191)

## [3.16.2](https://github.com/abdelrahmannasr/yadflow/compare/v3.16.1...v3.16.2) (2026-08-12)


### Bug Fixes

* **checkpoint:** make a --retro-ship dry run honest and side-effect free ([b03704f](https://github.com/abdelrahmannasr/yadflow/commit/b03704fb0564b1510dca121a24853758431f9374)), closes [112/#142](https://github.com/abdelrahmannasr/yadflow/issues/142) [#167](https://github.com/abdelrahmannasr/yadflow/issues/167)
* **checkpoint:** name the shard path and the fold step after --retro-ship ([64c33b3](https://github.com/abdelrahmannasr/yadflow/commit/64c33b37171ee1cebf540b7a66c35ee56cdc61a7)), closes [#167](https://github.com/abdelrahmannasr/yadflow/issues/167) [#167](https://github.com/abdelrahmannasr/yadflow/issues/167)
* **skills:** read build-log as the folded + shard union ([4302de2](https://github.com/abdelrahmannasr/yadflow/commit/4302de2e5f569989e8fc51c0a165aaae5abe1625)), closes [#167](https://github.com/abdelrahmannasr/yadflow/issues/167)

## [3.16.1](https://github.com/abdelrahmannasr/yadflow/compare/v3.16.0...v3.16.1) (2026-08-12)


### Bug Fixes

* **checkpoint:** guard --retro-ship per repo so a multi-repo story can be fully recorded ([d6d2fae](https://github.com/abdelrahmannasr/yadflow/commit/d6d2faeea91c0d59a00a532c0605f76c5b77eace)), closes [#166](https://github.com/abdelrahmannasr/yadflow/issues/166)
* **checkpoint:** validate the retro-ship repo instead of relying on the duplicate guard ([f1e085e](https://github.com/abdelrahmannasr/yadflow/commit/f1e085e89e4eb10fbf853647ab10c1912237daf8)), closes [#166](https://github.com/abdelrahmannasr/yadflow/issues/166) [#166](https://github.com/abdelrahmannasr/yadflow/issues/166) [#166](https://github.com/abdelrahmannasr/yadflow/issues/166)
* **ledger:** hold an exclusive lock across a ledger read-modify-write ([45b849a](https://github.com/abdelrahmannasr/yadflow/commit/45b849a7755a5bc58bc646e627218170a54b31bc)), closes [#166](https://github.com/abdelrahmannasr/yadflow/issues/166)

# [3.16.0](https://github.com/abdelrahmannasr/yadflow/compare/v3.15.5...v3.16.0) (2026-08-12)


### Bug Fixes

* **pr-template:** name GitLab's 2700-character description truncation ([475e2b7](https://github.com/abdelrahmannasr/yadflow/commit/475e2b7db8f0d24909ce5c874122f18dc6508985)), closes [#164](https://github.com/abdelrahmannasr/yadflow/issues/164)
* **update:** reject an unusable provenance record instead of ignoring it ([5107381](https://github.com/abdelrahmannasr/yadflow/commit/5107381ae2c08b261fddda76433cfc2a3fe3ea46)), closes [#188](https://github.com/abdelrahmannasr/yadflow/issues/188) [#164](https://github.com/abdelrahmannasr/yadflow/issues/164)


### Features

* **update:** never silently overwrite a locally modified managed file ([28d6ee4](https://github.com/abdelrahmannasr/yadflow/commit/28d6ee4c1af250415c3ad50d999a263ebe91cd83)), closes [#164](https://github.com/abdelrahmannasr/yadflow/issues/164)

## [3.15.5](https://github.com/abdelrahmannasr/yadflow/compare/v3.15.4...v3.15.5) (2026-08-12)


### Bug Fixes

* **bridge:** resolve the wired gate-sync pin from the repo, not a floating major ([8489bf5](https://github.com/abdelrahmannasr/yadflow/commit/8489bf5298f529868dc65085068882b59e89bbb5)), closes [#163](https://github.com/abdelrahmannasr/yadflow/issues/163) [#163](https://github.com/abdelrahmannasr/yadflow/issues/163)
* **checks:** require a platform for the ledger-guard bridge gate ([297d13a](https://github.com/abdelrahmannasr/yadflow/commit/297d13a0ebf26bec995ce64e0aacfa022b228e18)), closes [#185](https://github.com/abdelrahmannasr/yadflow/issues/185) [#186](https://github.com/abdelrahmannasr/yadflow/issues/186)
* **checks:** scope the ledger-guard bridge read to root-level keys ([4fb83a9](https://github.com/abdelrahmannasr/yadflow/commit/4fb83a968d4537e89a9367d72418aede9cf305f0)), closes [#186](https://github.com/abdelrahmannasr/yadflow/issues/186) [#186](https://github.com/abdelrahmannasr/yadflow/issues/186)

## [3.15.4](https://github.com/abdelrahmannasr/yadflow/compare/v3.15.3...v3.15.4) (2026-08-12)

## [3.15.3](https://github.com/abdelrahmannasr/yadflow/compare/v3.15.2...v3.15.3) (2026-08-11)


### Bug Fixes

* **bridge:** pass the PR head ref through env, not into the run script ([306f49f](https://github.com/abdelrahmannasr/yadflow/commit/306f49f569c5398bbfb36ce9aa3fb38d8341336c))
* **gate:** make the reconcile sweep converge instead of committing forever ([6bcb8fd](https://github.com/abdelrahmannasr/yadflow/commit/6bcb8fd8cd296b669bcf11226013fcd2e107f650)), closes [#163](https://github.com/abdelrahmannasr/yadflow/issues/163)
* **gate:** stage the merge commit from an allowlist, not the whole epic dir ([8142ddc](https://github.com/abdelrahmannasr/yadflow/commit/8142ddcce0f889505a29558c6664e42548d9d671))

## [3.15.2](https://github.com/abdelrahmannasr/yadflow/compare/v3.15.1...v3.15.2) (2026-08-11)


### Bug Fixes

* **checks:** exempt a new epic's ledger seed from ledger-guard ([ba923c2](https://github.com/abdelrahmannasr/yadflow/commit/ba923c2a3823e8bf17b2fc59b41f0160a3a11a19)), closes [#162](https://github.com/abdelrahmannasr/yadflow/issues/162)

## [3.15.1](https://github.com/abdelrahmannasr/yadflow/compare/v3.15.0...v3.15.1) (2026-08-11)


### Bug Fixes

* **checks:** close the silent-PASS holes the [#161](https://github.com/abdelrahmannasr/yadflow/issues/161) fix left open ([0f180ab](https://github.com/abdelrahmannasr/yadflow/commit/0f180abc72618fcd793ef6717fe1e128aa5ccfa5))
* **checks:** pin every changed contract slice, not just the first ([a79a946](https://github.com/abdelrahmannasr/yadflow/commit/a79a946aa37c08615741082bc638d006f7e80b76)), closes [#161](https://github.com/abdelrahmannasr/yadflow/issues/161)
* **checks:** read hub.json and the contract lock across line breaks ([43a618d](https://github.com/abdelrahmannasr/yadflow/commit/43a618d0822ed8576b9a164889bc53a52bbdf713)), closes [#161](https://github.com/abdelrahmannasr/yadflow/issues/161)

# [3.15.0](https://github.com/abdelrahmannasr/yadflow/compare/v3.14.0...v3.15.0) (2026-08-10)


### Features

* **testing:** add maestro as a testing-tool adapter ([7718b50](https://github.com/abdelrahmannasr/yadflow/commit/7718b502814ee8e0eb46f5e6f20342fc2471dbd7))

# [3.14.0](https://github.com/abdelrahmannasr/yadflow/compare/v3.13.2...v3.14.0) (2026-08-10)


### Features

* **next:** emit the action object with --json ([40d34dd](https://github.com/abdelrahmannasr/yadflow/commit/40d34ddba2492821700c7a877de28938faa74f3e))

## [3.13.2](https://github.com/abdelrahmannasr/yadflow/compare/v3.13.1...v3.13.2) (2026-08-10)


### Bug Fixes

* **doctor:** fail a done review gate that holds no approval ([b1b23df](https://github.com/abdelrahmannasr/yadflow/commit/b1b23df5426e8523cdb1d95221cb2291200c6249))

## [3.13.1](https://github.com/abdelrahmannasr/yadflow/compare/v3.13.0...v3.13.1) (2026-07-29)


### Bug Fixes

* **checks:** apply the Task-trailer rule to the thread gates too ([18aed8d](https://github.com/abdelrahmannasr/yadflow/commit/18aed8df958718483fe929cea84275ca86ae67be)), closes [#157](https://github.com/abdelrahmannasr/yadflow/issues/157)
* **checks:** do not build a /-rooted lock path when product-repo is absent ([0d2a214](https://github.com/abdelrahmannasr/yadflow/commit/0d2a214a30c7fc31ad087fa127277b50637a00de))
* **checks:** keep product-repo resolution backward-compatible and loud ([4c00c92](https://github.com/abdelrahmannasr/yadflow/commit/4c00c928642fbab4517805be14a1c6926f41b84c)), closes [#149](https://github.com/abdelrahmannasr/yadflow/issues/149) [#149](https://github.com/abdelrahmannasr/yadflow/issues/149)
* **checks:** resolve link.md product-repo the same way in every gate ([47c9b30](https://github.com/abdelrahmannasr/yadflow/commit/47c9b30548153ef5be607cf760c3e9ec9e73699f)), closes [#149](https://github.com/abdelrahmannasr/yadflow/issues/149)
* **checks:** spec-link resolves a Task trailer even on a maintenance commit ([d24dd83](https://github.com/abdelrahmannasr/yadflow/commit/d24dd83abadc63bb00e8c8d6d7c6008e32344db8)), closes [#157](https://github.com/abdelrahmannasr/yadflow/issues/157)
* **doctor:** refuse a decorative contract lock, and report a gate that went stale ([1ee3296](https://github.com/abdelrahmannasr/yadflow/commit/1ee3296dbddfdd308949b8013b3bf678f638fc80)), closes [#156](https://github.com/abdelrahmannasr/yadflow/issues/156)
* **gate:** bound the review-branch probe so it can never hang gate open ([afa5416](https://github.com/abdelrahmannasr/yadflow/commit/afa54167efd5879537c4bc19ab29531fe08ed31b))
* **gate:** hash the contract surface exactly as the documented recipe does ([f29e781](https://github.com/abdelrahmannasr/yadflow/commit/f29e78183b92c7baf33b46dbdfa7a4776aa06e4e)), closes [#156](https://github.com/abdelrahmannasr/yadflow/issues/156)
* **gate:** keep the recorded PR entry when --pr names that same PR ([b1febe1](https://github.com/abdelrahmannasr/yadflow/commit/b1febe184278109f0bafc2968648da362d68483a))
* **gate:** make a merged review PR reachable by hand ([4ccbd17](https://github.com/abdelrahmannasr/yadflow/commit/4ccbd1736640935175d63bac15a01a94e381b44e)), closes [#158](https://github.com/abdelrahmannasr/yadflow/issues/158)
* **gate:** never drop a done step's approval record on re-sync ([1a5e434](https://github.com/abdelrahmannasr/yadflow/commit/1a5e4348d00edd4e775a735a49fc0a86a3f0e391)), closes [#156](https://github.com/abdelrahmannasr/yadflow/issues/156)
* **gate:** re-bind approvals recorded before PR provenance existed ([6b7e816](https://github.com/abdelrahmannasr/yadflow/commit/6b7e816638a329d9365c6e727b2c12debdbd24aa)), closes [#156](https://github.com/abdelrahmannasr/yadflow/issues/156) [#156](https://github.com/abdelrahmannasr/yadflow/issues/156)
* **gate:** re-sync a re-opened review so its approvals re-bind ([28eabd2](https://github.com/abdelrahmannasr/yadflow/commit/28eabd222214ad2af7d18ef20c56795c9eb171d1)), closes [#156](https://github.com/abdelrahmannasr/yadflow/issues/156)
* **gate:** require the review branch on origin, and check before writing state ([27f0d92](https://github.com/abdelrahmannasr/yadflow/commit/27f0d92ce680c26df6ea7ff6510879a11f05d00f)), closes [#158](https://github.com/abdelrahmannasr/yadflow/issues/158)
* **gate:** stop a done-step re-sync from churning the ledger ([68462a6](https://github.com/abdelrahmannasr/yadflow/commit/68462a622753c0d30b458d22d9e1ad890ad8e61f)), closes [#156](https://github.com/abdelrahmannasr/yadflow/issues/156)
* **gate:** validate --pr and confirm it names this artifact's review ([f5d7773](https://github.com/abdelrahmannasr/yadflow/commit/f5d7773da474784a43cc3e24298da94c8f38bbdb)), closes [#7](https://github.com/abdelrahmannasr/yadflow/issues/7) [#158](https://github.com/abdelrahmannasr/yadflow/issues/158)
* **hub-bridge:** serialize the GitLab gate-sync job ([4294979](https://github.com/abdelrahmannasr/yadflow/commit/4294979f80cb4491d074fe27e74f9af454a2f62a)), closes [#156](https://github.com/abdelrahmannasr/yadflow/issues/156)

# [3.13.0](https://github.com/abdelrahmannasr/yadflow/compare/v3.12.2...v3.13.0) (2026-07-14)


### Features

* **checkpoint:** add --retro-ship to reconcile pre-tracking shipped stories ([#142](https://github.com/abdelrahmannasr/yadflow/issues/142)) ([d7988a3](https://github.com/abdelrahmannasr/yadflow/commit/d7988a335da7d675dd7b53456c12610c3f442d97)), closes [#112](https://github.com/abdelrahmannasr/yadflow/issues/112) [#112](https://github.com/abdelrahmannasr/yadflow/issues/112)

## [3.12.2](https://github.com/abdelrahmannasr/yadflow/compare/v3.12.1...v3.12.2) (2026-07-14)


### Bug Fixes

* **checks:** waive verified-commits signature for content-free merge commits ([1e73837](https://github.com/abdelrahmannasr/yadflow/commit/1e738372f821e93020069b565d40315cd7be2591)), closes [#138](https://github.com/abdelrahmannasr/yadflow/issues/138)

## [3.12.1](https://github.com/abdelrahmannasr/yadflow/compare/v3.12.0...v3.12.1) (2026-07-14)


### Bug Fixes

* **cli:** reject unsafe detected IDE targets and opencode write destinations ([792a40b](https://github.com/abdelrahmannasr/yadflow/commit/792a40b399b92f8db9d560e314110c432b98d93e)), closes [#134](https://github.com/abdelrahmannasr/yadflow/issues/134)
* **cli:** repair and validate persisted IDE targets ([81242ed](https://github.com/abdelrahmannasr/yadflow/commit/81242ed9a075ea067acb2f4497a745ee40e540a6))

# [3.12.0](https://github.com/abdelrahmannasr/yadflow/compare/v3.11.1...v3.12.0) (2026-07-11)


### Features

* render an epic's kind as its noun in next/thread/status ([42e80e1](https://github.com/abdelrahmannasr/yadflow/commit/42e80e19e20e129a2a3941c85db6777a66ab00cc))

## [3.11.1](https://github.com/abdelrahmannasr/yadflow/compare/v3.11.0...v3.11.1) (2026-07-11)


### Bug Fixes

* **gate:** close the authoring step when its review gate advances ([8baaed9](https://github.com/abdelrahmannasr/yadflow/commit/8baaed9416a063013b5e6acf1ae36c5a1b3c920b))
* **setup:** contain repo paths to the workspace so sibling repos connect ([265a7ae](https://github.com/abdelrahmannasr/yadflow/commit/265a7ae543fccf8697ff89726ecb1a6aadde62ce))

# [3.11.0](https://github.com/abdelrahmannasr/yadflow/compare/v3.10.1...v3.11.0) (2026-07-09)


### Features

* notify when a newer yadflow is published ([9b7a5bf](https://github.com/abdelrahmannasr/yadflow/commit/9b7a5bfca4f27ab08ce4e3e48f2ba331c3e8bfd5))

## [3.10.1](https://github.com/abdelrahmannasr/yadflow/compare/v3.10.0...v3.10.1) (2026-07-08)


### Bug Fixes

* re-run pr-template gate on an edited PR body ([17ad94a](https://github.com/abdelrahmannasr/yadflow/commit/17ad94a4881610b4b653700be50a4eddd7036c5d))
* stop yad repo refresh --push stranding the regenerated pack.md ([f0b5f4c](https://github.com/abdelrahmannasr/yadflow/commit/f0b5f4ce9f22afcd6078aae3ea1dd5a64885be35))

# [3.10.0](https://github.com/abdelrahmannasr/yadflow/compare/v3.9.4...v3.10.0) (2026-07-08)


### Bug Fixes

* **sdlc:** satisfy lint gate and cover the yad skip CLI ([838eabc](https://github.com/abdelrahmannasr/yadflow/commit/838eabc0ba597eaeac3e9249c514e3d479de4830))


### Features

* **sdlc:** make the ui-design step optional (skippable N/A) ([2bc5583](https://github.com/abdelrahmannasr/yadflow/commit/2bc5583b58626ee0cf8f8cc993a8566e4b206221))

## [3.9.4](https://github.com/abdelrahmannasr/yadflow/compare/v3.9.3...v3.9.4) (2026-07-07)

## [3.9.3](https://github.com/abdelrahmannasr/yadflow/compare/v3.9.2...v3.9.3) (2026-07-07)


_Maintenance release — CHANGELOG backfill and dependency-audit fixes (`chore`/`docs` commits carry no user-facing changes)._



## [3.9.2](https://github.com/abdelrahmannasr/yadflow/compare/v3.9.1...v3.9.2) (2026-07-06)


### Bug Fixes

* validate explicit `--task` id format in `yad commit` ([#116](https://github.com/abdelrahmannasr/yadflow/issues/116)) ([e3b0527](https://github.com/abdelrahmannasr/yadflow/commit/e3b05276b951dbeab6ce6bcb135e8228f73ede9d))



## [3.9.1](https://github.com/abdelrahmannasr/yadflow/compare/v3.9.0...v3.9.1) (2026-07-06)


### Bug Fixes

* carry ship-backed story status flip in `yad checkpoint` ([#114](https://github.com/abdelrahmannasr/yadflow/issues/114)) ([478230c](https://github.com/abdelrahmannasr/yadflow/commit/478230cdfccafbcc80913dd3b0a69262a45cbea6))


### Continuous Integration

* bump `github/codeql-action/upload-sarif` from 4.36.2 to 4.36.3 ([#111](https://github.com/abdelrahmannasr/yadflow/issues/111)) ([f384d67](https://github.com/abdelrahmannasr/yadflow/commit/f384d6715da3dbe2d5f9f785920df4fe06c666b8))



# [3.9.0](https://github.com/abdelrahmannasr/yadflow/compare/v3.8.1...v3.9.0) (2026-07-05)


### Features

* **cli:** add `yad repo refresh --push` to publish code-map refresh to the hub ([#110](https://github.com/abdelrahmannasr/yadflow/issues/110)) ([0e3697d](https://github.com/abdelrahmannasr/yadflow/commit/0e3697d0be4ec5d11c300be9b02e04468f07ba8c))


### Bug Fixes

* **cli:** retry the publish push when the index is unchanged; note the registry in docs ([55209c0](https://github.com/abdelrahmannasr/yadflow/commit/55209c01e50e3a635e7311acd1ad10e8c61c5534))



## [3.8.1](https://github.com/abdelrahmannasr/yadflow/compare/v3.8.0...v3.8.1) (2026-07-05)


### Bug Fixes

* **hub-bridge:** filter `glab api` output with jq in gate-sync ([#109](https://github.com/abdelrahmannasr/yadflow/issues/109)) ([352c681](https://github.com/abdelrahmannasr/yadflow/commit/352c681f9e5c6d43688410cfc5092c2382ec881e))


### Tests

* **hub-bridge:** discover gitlab templates dynamically in `--jq` guard ([78d526a](https://github.com/abdelrahmannasr/yadflow/commit/78d526adf2133cd94e6a6396ac7ec5ef3ce2551e))



# [3.8.0](https://github.com/abdelrahmannasr/yadflow/compare/v3.7.1...v3.8.0) (2026-07-05)


### Features

* **cli:** commit + push applied updates to the default branch (`yad update --push`) ([#107](https://github.com/abdelrahmannasr/yadflow/issues/107)) ([fa851c8](https://github.com/abdelrahmannasr/yadflow/commit/fa851c8784765d78df2fef153424ff9d46363731))


### Bug Fixes

* **cli:** address CodeRabbit review on `yad update --push` ([1b1b2f5](https://github.com/abdelrahmannasr/yadflow/commit/1b1b2f59ebda541acd8775a5af3f1c8044efcb57))


### Documentation

* document `yad update --push` and the `yad-update-guard` gate ([35df498](https://github.com/abdelrahmannasr/yadflow/commit/35df498f4a4d7da4d58e81052b6fce73ab438846))



## [3.7.1](https://github.com/abdelrahmannasr/yadflow/compare/v3.7.0...v3.7.1) (2026-07-04)


### Bug Fixes

* **ledger:** sanitize shard-name components against path traversal ([#106](https://github.com/abdelrahmannasr/yadflow/issues/106)) ([5d85286](https://github.com/abdelrahmannasr/yadflow/commit/5d85286591cc9e6c78e449551c82d87683accba5))


### Documentation

* name the trust-log shard and the half-applied-tidy skip rule ([2f594e0](https://github.com/abdelrahmannasr/yadflow/commit/2f594e030c35fe1025d0521de7b022e8f93b958a))



# [3.7.0](https://github.com/abdelrahmannasr/yadflow/compare/v3.6.1...v3.7.0) (2026-07-04)


### Features

* **cli:** wire `yad checkpoint` and `yad tidy up` into the CLI ([#105](https://github.com/abdelrahmannasr/yadflow/issues/105)) ([fe4770d](https://github.com/abdelrahmannasr/yadflow/commit/fe4770de87ebec394c3a29c78077a0baf7a924cc))
* **cli:** add `yad tidy up` to fold finished ledger shards ([59727f3](https://github.com/abdelrahmannasr/yadflow/commit/59727f32a7b5e3274c8fd96b8b39134b3acf6705))
* **cli:** add `yad checkpoint` to commit machine-written back-half state ([c09089c](https://github.com/abdelrahmannasr/yadflow/commit/c09089c698884ad39fc8cf66a7e28d8d44321668))
* **cli:** shard-then-fold storage for the back-half ledgers ([6182598](https://github.com/abdelrahmannasr/yadflow/commit/618259847e3dbdee5f00bce4fa2a5d64df0364a3))
* **cli:** add shared hub-commit default-branch guard helpers ([44290f6](https://github.com/abdelrahmannasr/yadflow/commit/44290f6109c806f077609fec352904efe801f830))


### Bug Fixes

* **cli:** read build-log through the shard union reader ([e7adbc3](https://github.com/abdelrahmannasr/yadflow/commit/e7adbc3a7dd942f2ba6dcc53f868a8f4c6f6969d))


### Refactors

* **cli:** extract `pushWithRebase` helper into lib, reuse in gate ([0cb4e26](https://github.com/abdelrahmannasr/yadflow/commit/0cb4e26c96b125accb67783a37c12a24e2b71ba2))


### Tests

* **cli:** cover checkpoint, sharded ledgers, tidy up, and concurrency ([131d46d](https://github.com/abdelrahmannasr/yadflow/commit/131d46d827ce8b61f5af584098b1dfeee0919d15))
* **cli:** point the concurrency test's bare remote HEAD at main for CI ([663ebac](https://github.com/abdelrahmannasr/yadflow/commit/663ebac306cd03f31f5bee01c38a7487171dcabe))


### Documentation

* document `yad checkpoint`, `yad tidy up`, and sharded ledgers ([322f90a](https://github.com/abdelrahmannasr/yadflow/commit/322f90af6dcf55b475bca80a31219f5a1cdade7b))
* **skills:** shard-then-fold writers/readers and checkpoint/tidy wiring ([b99c359](https://github.com/abdelrahmannasr/yadflow/commit/b99c3595013df8c90a8235d565fb693f2ca95fec))



## [3.6.1](https://github.com/abdelrahmannasr/yadflow/compare/v3.6.0...v3.6.1) (2026-07-04)


### Bug Fixes

* **gate:** include the Checklist section in the hub review-PR body ([#104](https://github.com/abdelrahmannasr/yadflow/issues/104)) ([3134f89](https://github.com/abdelrahmannasr/yadflow/commit/3134f89658a172a3a346cf0945f62e6fa63bac74))



# [3.6.0](https://github.com/abdelrahmannasr/yadflow/compare/v3.5.3...v3.6.0) (2026-07-03)


### Features

* **yad-stub:** mint stub genesis epics for brownfield defect intake ([#102](https://github.com/abdelrahmannasr/yadflow/issues/102)) ([7e6c4cd](https://github.com/abdelrahmannasr/yadflow/commit/7e6c4cd74f5a6e7f886115f7b9e5c0a571c2e408))
* wire stub anchors into change/backfill/reconcile flows ([54d20f1](https://github.com/abdelrahmannasr/yadflow/commit/54d20f10340831bca503f4246606b0181c74a2b0))


### Refactors

* **yad-stub:** centralize stub/anchor detection in one classifier ([5cc76b0](https://github.com/abdelrahmannasr/yadflow/commit/5cc76b08650e3d7fa03d2626ac0c36bdf9de730e))


### Chores

* **yad-stub:** register the skill (manifest, installer, config, count) ([1b63523](https://github.com/abdelrahmannasr/yadflow/commit/1b63523996bba43eb44c72d1b8a0cf5953e4e2d8))


### Documentation

* **yad-stub:** correct promote edge in the overview diagram ([fb3552e](https://github.com/abdelrahmannasr/yadflow/commit/fb3552e1f6ade7e3ec721932e6b69d8287517281))
* **yad-stub:** document the brownfield stub-epic flow ([f5b0730](https://github.com/abdelrahmannasr/yadflow/commit/f5b073029330e69b99a2e15fee6f53c1d94726f5))



## [3.5.3](https://github.com/abdelrahmannasr/yadflow/compare/v3.5.2...v3.5.3) (2026-07-03)


### Bug Fixes

* fill the PR spec dir and summary from the task and commit ([#101](https://github.com/abdelrahmannasr/yadflow/issues/101)) ([a402a54](https://github.com/abdelrahmannasr/yadflow/commit/a402a545715eeea8aef2dde5426eb7f2538687a0))



## [3.5.2](https://github.com/abdelrahmannasr/yadflow/compare/v3.5.1...v3.5.2) (2026-07-02)


### Documentation

* **readme:** sharpen positioning, compatibility, and onboarding ([#100](https://github.com/abdelrahmannasr/yadflow/issues/100)) ([62267ec](https://github.com/abdelrahmannasr/yadflow/commit/62267ec9b87389574acce9f18198c98db88fcfce))
* **readme:** add real setup-wizard GIF and wire it in ([488a2e4](https://github.com/abdelrahmannasr/yadflow/commit/488a2e48845a99a0890542919624d06198aeef15))
* **readme:** soften absolute approval claim, note solo exception ([eb8cab5](https://github.com/abdelrahmannasr/yadflow/commit/eb8cab58625185e079e761378ee5af1debd5f710))



## [3.5.1](https://github.com/abdelrahmannasr/yadflow/compare/v3.5.0...v3.5.1) (2026-07-02)


### Bug Fixes

* preserve roster and verified_authors on hub reconfigure ([#99](https://github.com/abdelrahmannasr/yadflow/issues/99)) ([84bd0af](https://github.com/abdelrahmannasr/yadflow/commit/84bd0affed378e9b6ed60fa2471816f7a585c9c7))



# [3.5.0](https://github.com/abdelrahmannasr/yadflow/compare/v3.4.2...v3.5.0) (2026-07-02)


### Features

* **usage:** add derived team-member usage & behavior report ([#98](https://github.com/abdelrahmannasr/yadflow/issues/98)) ([1813026](https://github.com/abdelrahmannasr/yadflow/commit/181302613b6585b696fbf3ee132a236543c7fd63))


### Bug Fixes

* **usage:** address CodeRabbit review on PR #98 ([e5e64fa](https://github.com/abdelrahmannasr/yadflow/commit/e5e64fa1c19de53b553a8679e76e8304c2001073))


### Documentation

* **usage:** document yad usage across CLI, team guide, README, phase-5 ([2fd262c](https://github.com/abdelrahmannasr/yadflow/commit/2fd262cc1f21a1e97549b41f0179af043272f21f))
* **usage:** document yad usage in the reference site and walkthrough ([dd58f89](https://github.com/abdelrahmannasr/yadflow/commit/dd58f89efb7cd73e5eb133af1ec67d92a1d12214))



## [3.4.2](https://github.com/abdelrahmannasr/yadflow/compare/v3.4.1...v3.4.2) (2026-07-02)


### Bug Fixes

* **doctor:** warn YAD-CFG-005 on hub.json missing git_url; stop misleading YAD-ENV-002 ([#96](https://github.com/abdelrahmannasr/yadflow/issues/96)) ([3f588af](https://github.com/abdelrahmannasr/yadflow/commit/3f588af2e01e117e661b08b5f5b8e069e41e887f))
* **setup:** write and backfill hub.json git_url from the origin remote ([c809358](https://github.com/abdelrahmannasr/yadflow/commit/c8093581319dcb9700b3dd0ebe930dbf784348ff))


### Documentation

* add YAD-CFG-005 to the CLI troubleshooting table + reference site ([4bb1bef](https://github.com/abdelrahmannasr/yadflow/commit/4bb1bef2fa27d6212d9ebc5aa7c11016ad8f38c2))



## [3.4.1](https://github.com/abdelrahmannasr/yadflow/compare/v3.4.0...v3.4.1) (2026-07-01)


### Documentation

* document the self issue reporter + correct skill count to 37 ([#95](https://github.com/abdelrahmannasr/yadflow/issues/95)) ([cc60190](https://github.com/abdelrahmannasr/yadflow/commit/cc60190b0e8b8ecc786203cd20caca186cc91890))



# [3.4.0](https://github.com/abdelrahmannasr/yadflow/compare/v3.3.1...v3.4.0) (2026-07-01)


### Features

* **report:** add self issue reporter with auto-scrubbed diagnostics ([#94](https://github.com/abdelrahmannasr/yadflow/issues/94)) ([cd70965](https://github.com/abdelrahmannasr/yadflow/commit/cd7096568995d52501a2e9b57a7ac091a22620f1))



## [3.3.1](https://github.com/abdelrahmannasr/yadflow/compare/v3.3.0...v3.3.1) (2026-07-01)


### Bug Fixes

* restore npm ci in github checks template ([#93](https://github.com/abdelrahmannasr/yadflow/issues/93)) ([c3079c2](https://github.com/abdelrahmannasr/yadflow/commit/c3079c246692188b5256550a74c6fa14d214c7a7))



# [3.3.0](https://github.com/abdelrahmannasr/yadflow/compare/v3.2.0...v3.3.0) (2026-07-01)


### Features

* **next:** surface build-half sub-steps in yad next ([#91](https://github.com/abdelrahmannasr/yadflow/issues/91)) ([603b129](https://github.com/abdelrahmannasr/yadflow/commit/603b1294194e436c35de842bc687ccb4f51c2075))


### Documentation

* **next:** include the tasks step in the build-chain blurbs ([362e6e8](https://github.com/abdelrahmannasr/yadflow/commit/362e6e8f873f33b23703ef9cca5e60723942afe3))



# [3.2.0](https://github.com/abdelrahmannasr/yadflow/compare/v3.1.0...v3.2.0) (2026-07-01)


### Features

* **review:** add yad-pair-review — guided two-way teaching walkthrough ([#90](https://github.com/abdelrahmannasr/yadflow/issues/90)) ([337cf9a](https://github.com/abdelrahmannasr/yadflow/commit/337cf9a0814f79f411db13a59af9afbdb64cf57d))


### Bug Fixes

* **review:** keep walkthrough STDOUT pure JSON (diagnostics to stderr) ([0d46455](https://github.com/abdelrahmannasr/yadflow/commit/0d46455919997ebcaa9b1f9929f5265023d05c5a))



# [3.1.0](https://github.com/abdelrahmannasr/yadflow/compare/v3.0.0...v3.1.0) (2026-06-30)


### Features

* **review:** add the Review Companion (front half) ([#89](https://github.com/abdelrahmannasr/yadflow/issues/89)) ([d45bf23](https://github.com/abdelrahmannasr/yadflow/commit/d45bf239fa27a7b84cba409a7fdc23f64f99753d))
* **review:** extend the companion + bridge to the back half (code PRs) ([1711ca9](https://github.com/abdelrahmannasr/yadflow/commit/1711ca9753f5eb67fad3fa5c828733e45ca9686f))
* **review:** config switch, pr-template tolerance, and docs for the companion ([13aafcd](https://github.com/abdelrahmannasr/yadflow/commit/13aafcd6f359d6a0c7c39c53f01fd75357ba6aeb))
* **cli:** install newly-added skills on `yad update` ([872b92c](https://github.com/abdelrahmannasr/yadflow/commit/872b92ce1ce2ff5e8154add48b6ebdfef0d87cd4))


### Bug Fixes

* **bridge:** harden reviewer routing on GitHub + GitLab ([8d9cf24](https://github.com/abdelrahmannasr/yadflow/commit/8d9cf24c10adf1403959fa44a30fd13f7b362fb9))
* **review:** address PR #89 code review (bridge/companion robustness) ([4864fae](https://github.com/abdelrahmannasr/yadflow/commit/4864fae0cb7131948509dc6786eae9eb18c80497))


### Tests

* **review:** cover reviewNudge bare-vs-engaged approval branch ([f350f6f](https://github.com/abdelrahmannasr/yadflow/commit/f350f6f8ac27755b584d4e4271e51a724d99d795))
* **e2e:** match the reconcile summary's new `0 new` field ([ca7df77](https://github.com/abdelrahmannasr/yadflow/commit/ca7df77aac5847c9d9c9ebb941d0e6bdc4ed1a67))



# [3.0.0](https://github.com/abdelrahmannasr/yadflow/compare/v2.18.1...v3.0.0) (2026-06-29)


### Features

* remove unused yad-review-comments skill ([#88](https://github.com/abdelrahmannasr/yadflow/issues/88)) ([da6ad60](https://github.com/abdelrahmannasr/yadflow/commit/da6ad608bedf86a58ad09c2aefbf5e6367a41ae4))
* **cli:** purge removed skills from existing installs ([8887d6d](https://github.com/abdelrahmannasr/yadflow/commit/8887d6d5598775986729c77f1500ac6773e4591e))


### Continuous Integration

* **release:** trigger a patch release on docs: commits ([#86](https://github.com/abdelrahmannasr/yadflow/issues/86)) ([df50181](https://github.com/abdelrahmannasr/yadflow/commit/df5018156f20baa6ebab5e0612e7ed86b2a5707c))


### Chores

* **deps:** Bump eslint from 10.5.0 to 10.6.0 ([#87](https://github.com/abdelrahmannasr/yadflow/issues/87)) ([204d807](https://github.com/abdelrahmannasr/yadflow/commit/204d8070a4a9327f90b66be2ce3365b88a66b114))



## [2.18.1](https://github.com/abdelrahmannasr/yadflow/compare/v2.18.0...v2.18.1) (2026-06-28)


### Bug Fixes

* publish updated README and tutorial site to npm ([a7cd251](https://github.com/abdelrahmannasr/yadflow/commit/a7cd251203819565bbde76dd47959ff92b12900c))


### Documentation

* sync overview site + generator spec with phase 6 (feature threads) + discovery ([#84](https://github.com/abdelrahmannasr/yadflow/issues/84)) ([661bc1a](https://github.com/abdelrahmannasr/yadflow/commit/661bc1a6d9f14dde781ee748bd088ed32bc4fb02))
* governance-first README + reference split + guided tutorial site ([#85](https://github.com/abdelrahmannasr/yadflow/issues/85)) ([eb59d7e](https://github.com/abdelrahmannasr/yadflow/commit/eb59d7e365a8434ee44dc6a8313ff31b3dd65a5f))



# [2.18.0](https://github.com/abdelrahmannasr/yadflow/compare/v2.17.0...v2.18.0) (2026-06-26)


### Features

* **change:** post-lock change management via feature threads (Phase 6) ([#83](https://github.com/abdelrahmannasr/yadflow/issues/83)) ([f8024d5](https://github.com/abdelrahmannasr/yadflow/commit/f8024d5808070656d1c3039905ada39096fe7d3b))



# [2.17.0](https://github.com/abdelrahmannasr/yadflow/compare/v2.16.1...v2.17.0) (2026-06-26)


### Features

* **discovery:** add yad-discovery project front-zero phase ([#82](https://github.com/abdelrahmannasr/yadflow/issues/82)) ([4bb2a92](https://github.com/abdelrahmannasr/yadflow/commit/4bb2a928ea37cbd7d7b21f7c28a96a20492f527e))



## [2.16.1](https://github.com/abdelrahmannasr/yadflow/compare/v2.16.0...v2.16.1) (2026-06-25)


### Bug Fixes

* **open-pr:** make build helpers stage-aware on the hub (closes #80) ([#81](https://github.com/abdelrahmannasr/yadflow/issues/81)) ([8d74e3d](https://github.com/abdelrahmannasr/yadflow/commit/8d74e3d267d4c056992d3bc6f5a2a7a15a66b431))



# [2.16.0](https://github.com/abdelrahmannasr/yadflow/compare/v2.15.0...v2.16.0) (2026-06-25)


### Features

* make hub pr-title/pr-template gates branch-aware so tooling PRs pass ([#79](https://github.com/abdelrahmannasr/yadflow/issues/79)) ([68050e0](https://github.com/abdelrahmannasr/yadflow/commit/68050e000010b4d98f304a7e5e1f6a39bc0c229c))



# [2.15.0](https://github.com/abdelrahmannasr/yadflow/compare/v2.14.0...v2.15.0) (2026-06-24)


### Features

* merge-driven review gate (Path B) — CI never pushes the review branch ([#78](https://github.com/abdelrahmannasr/yadflow/issues/78)) ([d4d983a](https://github.com/abdelrahmannasr/yadflow/commit/d4d983ab4efddb4e6ec259bb940b393e9237f9cf))


### Documentation

* **diagram:** label the bridge node merge-time to match Path B ([#77](https://github.com/abdelrahmannasr/yadflow/issues/77)) ([2d558f1](https://github.com/abdelrahmannasr/yadflow/commit/2d558f193e7fb6f2c9e98ca3efaf2d35c1482181))


### Chores

* **ci:** Bump actions/checkout from 4 to 7 ([#73](https://github.com/abdelrahmannasr/yadflow/issues/73)) ([1182bca](https://github.com/abdelrahmannasr/yadflow/commit/1182bca35a3d874c897bac10009a4531f04ea13c))
* **ci:** Bump ossf/scorecard-action from 2.4.2 to 2.4.3 ([#74](https://github.com/abdelrahmannasr/yadflow/issues/74)) ([acff68c](https://github.com/abdelrahmannasr/yadflow/commit/acff68c572e7f5db6067e2411ae781dbd4c59796))
* **ci:** Bump actions/upload-pages-artifact from 3 to 5 ([#75](https://github.com/abdelrahmannasr/yadflow/issues/75)) ([9e44647](https://github.com/abdelrahmannasr/yadflow/commit/9e44647b3345d18b08fb01e643f821946a964f88))
* Redesign review gate: CI owns the ledger (branch-during-review, main-at-merge) ([#76](https://github.com/abdelrahmannasr/yadflow/issues/76)) ([80dd65e](https://github.com/abdelrahmannasr/yadflow/commit/80dd65e2f6e064bda966c5d303768cdc809997df))



# [2.14.0](https://github.com/abdelrahmannasr/yadflow/compare/v2.13.0...v2.14.0) (2026-06-21)


### Features

* yad next driver, precondition guards, solo mode, and guided setup interview ([#72](https://github.com/abdelrahmannasr/yadflow/issues/72)) ([7125c9d](https://github.com/abdelrahmannasr/yadflow/commit/7125c9d80043cb282a7be4f08dfaa95ddf94594a))



# [2.13.0](https://github.com/abdelrahmannasr/yadflow/compare/v2.12.0...v2.13.0) (2026-06-16)


### Features

* **docs:** make the report the main documentation, mount the SPA under /app/ ([#71](https://github.com/abdelrahmannasr/yadflow/issues/71)) ([1993e4d](https://github.com/abdelrahmannasr/yadflow/commit/1993e4dc282df281474ca1923acd52dbd1262dcb))



# [2.12.0](https://github.com/abdelrahmannasr/yadflow/compare/v2.11.1...v2.12.0) (2026-06-16)


### Features

* **docs:** pipeline-shaped overview canvas + collapsible panels + content refresh ([#70](https://github.com/abdelrahmannasr/yadflow/issues/70)) ([da47b80](https://github.com/abdelrahmannasr/yadflow/commit/da47b8050ccd7aa1919bf4b364298a90cdd56012))


### Bug Fixes

* **checks:** harden spec-link + gitlab gate templates ([#69](https://github.com/abdelrahmannasr/yadflow/issues/69)) ([42f3949](https://github.com/abdelrahmannasr/yadflow/commit/42f3949841095624db03cb17f85db3138be8b93b))



## [2.11.1](https://github.com/abdelrahmannasr/yadflow/compare/v2.11.0...v2.11.1) (2026-06-16)


### Bug Fixes

* **doctor:** scope platform-CLI auth probe to the hub host ([#68](https://github.com/abdelrahmannasr/yadflow/issues/68)) ([3cb2801](https://github.com/abdelrahmannasr/yadflow/commit/3cb28011c80645e0ff42e544a9b3d933231daeb3))



# [2.11.0](https://github.com/abdelrahmannasr/yadflow/compare/v2.10.0...v2.11.0) (2026-06-15)


### Features

* add yad-sync-repos — switch every connected repo to its default branch + ff pull ([#67](https://github.com/abdelrahmannasr/yadflow/issues/67)) ([0abdcdf](https://github.com/abdelrahmannasr/yadflow/commit/0abdcdf80c8a0a6bfd8c94129fde90f1d35ec365))



# [2.10.0](https://github.com/abdelrahmannasr/yadflow/compare/v2.9.0...v2.10.0) (2026-06-15)


### Features

* **checks:** cap jest/vitest test workers in connected-repo CI gates ([#66](https://github.com/abdelrahmannasr/yadflow/issues/66)) ([7a16d51](https://github.com/abdelrahmannasr/yadflow/commit/7a16d51eb135c3240d3e94012f844c8b74210bd9))



# [2.9.0](https://github.com/abdelrahmannasr/yadflow/compare/v2.8.0...v2.9.0) (2026-06-15)


### Features

* **docs:** enhance interactive docs — clearer diagram, brand icon, dimmed stubs ([#65](https://github.com/abdelrahmannasr/yadflow/issues/65)) ([969a20d](https://github.com/abdelrahmannasr/yadflow/commit/969a20dc1e9778e1ffd0962e557f3e2c28dfd6ef))


### Chores

* **deps:** Bump eslint from 9.39.4 to 10.5.0 ([#63](https://github.com/abdelrahmannasr/yadflow/issues/63)) ([fc9512e](https://github.com/abdelrahmannasr/yadflow/commit/fc9512e286a51d1d910f873b472de5e014ea7373))



# [2.8.0](https://github.com/abdelrahmannasr/yadflow/compare/v2.7.0...v2.8.0) (2026-06-15)


### Features

* add `yad roster` command to manage the reviewer roster any time ([#64](https://github.com/abdelrahmannasr/yadflow/issues/64)) ([4d78225](https://github.com/abdelrahmannasr/yadflow/commit/4d78225ec25579b50d24d917f217212f4820728f))


### Documentation

* fold the legacy report into the overview site as report.html ([#55](https://github.com/abdelrahmannasr/yadflow/issues/55)) ([c7e4b65](https://github.com/abdelrahmannasr/yadflow/commit/c7e4b652a8abb6c114b901600a5376245d1eb653))


### Chores

* **ci:** Bump github/codeql-action from 3.36.2 to 4.36.2 ([#56](https://github.com/abdelrahmannasr/yadflow/issues/56)) ([78d6616](https://github.com/abdelrahmannasr/yadflow/commit/78d661642c1d1ead28ecb98eed0d84e9f573b846))
* **ci:** Bump actions/deploy-pages from 4 to 5 ([#57](https://github.com/abdelrahmannasr/yadflow/issues/57)) ([59b9d63](https://github.com/abdelrahmannasr/yadflow/commit/59b9d633f0c623be100623ce95bfa232781287c4))
* **ci:** Bump actions/setup-node from 4 to 6 ([#58](https://github.com/abdelrahmannasr/yadflow/issues/58)) ([420d454](https://github.com/abdelrahmannasr/yadflow/commit/420d454ccf08430b45e88938bbb8326224add2b7))
* **ci:** Bump actions/upload-artifact from 4.6.2 to 7.0.1 ([#60](https://github.com/abdelrahmannasr/yadflow/issues/60)) ([de00223](https://github.com/abdelrahmannasr/yadflow/commit/de0022307854e6b5970d710aab5be1a747447e28))
* **ci:** Bump actions/configure-pages from 5 to 6 ([#61](https://github.com/abdelrahmannasr/yadflow/issues/61)) ([335349a](https://github.com/abdelrahmannasr/yadflow/commit/335349a9b0693bb76a08a2b843c67ed0e796c0ae))
* **deps:** Bump semantic-release from 25.0.3 to 25.0.5 ([#59](https://github.com/abdelrahmannasr/yadflow/issues/59)) ([666d9fa](https://github.com/abdelrahmannasr/yadflow/commit/666d9fa3f6cd1f01c992fef700ea7430b4eaf27e))
* **deps:** Bump @eslint/js from 9.39.4 to 10.0.1 ([#62](https://github.com/abdelrahmannasr/yadflow/issues/62)) ([846afa8](https://github.com/abdelrahmannasr/yadflow/commit/846afa80745a8e9801de20f35e282f4fe9055ed4))



# [2.7.0](https://github.com/abdelrahmannasr/yadflow/compare/v2.6.0...v2.7.0) (2026-06-15)


### Features

* add interactive documentation skills + yad docs CLI ([#54](https://github.com/abdelrahmannasr/yadflow/issues/54)) ([4bf7a25](https://github.com/abdelrahmannasr/yadflow/commit/4bf7a25c38e28ef47704a8e2f5acec2f724e4e29))


### Bug Fixes

* publish per-epic docs sites in CI + check shell-version staleness ([9862646](https://github.com/abdelrahmannasr/yadflow/commit/9862646fbe910de8ad8248a5f1bb586a5604b18f))
* drop unused today param from runDocs (lint) ([1c255f1](https://github.com/abdelrahmannasr/yadflow/commit/1c255f1c848b9571502e29b142a07366612d638c))


### Refactors

* rename booking-derived identifiers in the overview site ([2e85892](https://github.com/abdelrahmannasr/yadflow/commit/2e8589213f39dedb8bebb9b8f86917f4389261a2))


### Continuous Integration

* wire the GitHub Pages workflow for the docs sites ([475f329](https://github.com/abdelrahmannasr/yadflow/commit/475f329641ff3ed215389d9e1f6f79338d9ef571))


### Documentation

* generate the yadflow SDLC-overview site ([67cf8de](https://github.com/abdelrahmannasr/yadflow/commit/67cf8de5a88f18660bb8c56721e2403832ad03b5))



# [2.6.0](https://github.com/abdelrahmannasr/yadflow/compare/v2.5.0...v2.6.0) (2026-06-15)


### Features

* add `yad ship` CLI to commit and open a PR/MR in one step ([#53](https://github.com/abdelrahmannasr/yadflow/issues/53)) ([c493e93](https://github.com/abdelrahmannasr/yadflow/commit/c493e93e5626eee590cd061c9e7dbc8047e78718))
* add yad-commit/yad-open-pr/yad-ship skills; rename Step E to yad-engineer-review ([c566567](https://github.com/abdelrahmannasr/yadflow/commit/c5665679e45f24ea53c682aca3a78eb52c9f984f))
* add commit-message/pr-title/pr-template pattern gates (code + hub) ([6658837](https://github.com/abdelrahmannasr/yadflow/commit/6658837d7685b826884b665a5e7661fd6ae99828))


### Bug Fixes

* allow scoped/breaking commit subjects + titles; parse only the trailer block ([63444c0](https://github.com/abdelrahmannasr/yadflow/commit/63444c08c1e33b4151c7389eb5e87f6ae682aee6))
* harden pattern-gate CI — pass PR title via env, write body to mktemp ([2415397](https://github.com/abdelrahmannasr/yadflow/commit/2415397f81280f459785b8fa9ca29007b473561b))
* let `yad ship` derive the PR title from the committed subject ([a5adba3](https://github.com/abdelrahmannasr/yadflow/commit/a5adba3212b236ffc5a2470b9ea50bf97c6c4138))


### Tests

* cover `yad ship` orchestration and the three pattern gates ([23190a3](https://github.com/abdelrahmannasr/yadflow/commit/23190a3c5fb4d48bc5f8f7c5ccb049e42ec9ca80))


### Builds

* register the new skills and wire the pattern-gate scripts ([7c5039e](https://github.com/abdelrahmannasr/yadflow/commit/7c5039ebbb5166cfc6d251ee7fc7f57674ce186d))


### Documentation

* document the commit/PR skills + pattern gates; bump skill count to 25 ([6a8aa71](https://github.com/abdelrahmannasr/yadflow/commit/6a8aa7120cf3c91156bb8367ae19c8cc37b82408))
* address CodeRabbit review on PR #53 ([71eaf6a](https://github.com/abdelrahmannasr/yadflow/commit/71eaf6a07f6c5da8f73285ec6cf8ba280a6a29d6))



# [2.5.0](https://github.com/abdelrahmannasr/yadflow/compare/v2.4.2...v2.5.0) (2026-06-14)


### Features

* per-scope roster roles + auto assignee/reviewer on PRs ([#52](https://github.com/abdelrahmannasr/yadflow/issues/52)) ([5ff066b](https://github.com/abdelrahmannasr/yadflow/commit/5ff066b2a83f63ddf25353ddaf0a088b91a6adb0))



## [2.4.2](https://github.com/abdelrahmannasr/yadflow/compare/v2.4.1...v2.4.2) (2026-06-14)


### Bug Fixes

* route GitLab CI gate jobs to tag-locked runners via $YAD_RUNNER_TAGS ([#51](https://github.com/abdelrahmannasr/yadflow/issues/51)) ([a0311c5](https://github.com/abdelrahmannasr/yadflow/commit/a0311c5af647f63968f3f34e8e6e6fa48b7423d8))



## [2.4.1](https://github.com/abdelrahmannasr/yadflow/compare/v2.4.0...v2.4.1) (2026-06-14)


### Bug Fixes

* migrate pre-2.0 sdlc-* skills during `yad setup` ([#49](https://github.com/abdelrahmannasr/yadflow/issues/49)) ([5b53e40](https://github.com/abdelrahmannasr/yadflow/commit/5b53e40480b3049d4efc596792f2630597d837fd))



# [2.4.0](https://github.com/abdelrahmannasr/yadflow/compare/v2.3.0...v2.4.0) (2026-06-14)


### Features

* add DeepTutor learning layer across all SDLC stages ([#48](https://github.com/abdelrahmannasr/yadflow/issues/48)) ([bd8d4ea](https://github.com/abdelrahmannasr/yadflow/commit/bd8d4eaaa0258242a62ed1b131f7e3f74506af64))
* make learning-layer output local-only (never committed or pushed) ([aa8f74e](https://github.com/abdelrahmannasr/yadflow/commit/aa8f74eb61855d3a663810a0c68cf8e37fbedd66))


### Bug Fixes

* address CodeRabbit review on PR #48 ([2f182f7](https://github.com/abdelrahmannasr/yadflow/commit/2f182f72b68e226196b6190802771b0e12b585f9))


### Continuous Integration

* wire the hub's gate-sync + verified-commits CI and stamp the CLI version ([#46](https://github.com/abdelrahmannasr/yadflow/issues/46)) ([c856398](https://github.com/abdelrahmannasr/yadflow/commit/c856398a213b17aebea9c46204dbf955b92ea9cf))


### Documentation

* changelog entries for #45 and #46 ([8e589aa](https://github.com/abdelrahmannasr/yadflow/commit/8e589aaaa56eaa9bdc6e1863994400a76cc5f6d8))
* document the learning layer and bump skill counts to 22 ([668cdb9](https://github.com/abdelrahmannasr/yadflow/commit/668cdb98feb31c4343c2c865d07c4d9665d0126c))



# [2.3.0](https://github.com/abdelrahmannasr/yadflow/compare/v2.2.0...v2.3.0) (2026-06-14)


### Features

* add parallel test-cases step with pluggable testing-tool connection ([#45](https://github.com/abdelrahmannasr/yadflow/issues/45)) ([19c282f](https://github.com/abdelrahmannasr/yadflow/commit/19c282f6bd737364bca122179b05de8ea94493a9))



# [2.2.0](https://github.com/abdelrahmannasr/yadflow/compare/v2.1.0...v2.2.0) (2026-06-14)


### Features

* add parallel test-cases step with pluggable testing-tool connection ([#45](https://github.com/abdelrahmannasr/yadflow/issues/45)) ([19c282f](https://github.com/abdelrahmannasr/yadflow/commit/19c282f6bd737364bca122179b05de8ea94493a9))


### Continuous Integration

* wire the hub's gate-sync + verified-commits CI and stamp the CLI version ([#46](https://github.com/abdelrahmannasr/yadflow/issues/46)) ([c856398](https://github.com/abdelrahmannasr/yadflow/commit/c856398a213b17aebea9c46204dbf955b92ea9cf))

# [2.1.0](https://github.com/abdelrahmannasr/yadflow/compare/v2.0.1...v2.1.0) (2026-06-13)


### Features

* yad doctor + structured YAD-* error codes with recovery hints ([#43](https://github.com/abdelrahmannasr/yadflow/issues/43)) ([94f9e9f](https://github.com/abdelrahmannasr/yadflow/commit/94f9e9f6ff6d6d3c83ed29f1cfcc97e32678615c))


### Bug Fixes

* address CodeRabbit review on the hardening PR ([7dbe9e3](https://github.com/abdelrahmannasr/yadflow/commit/7dbe9e358e731d69ecead6ecac9faa8377c37023))
* drop useless backtick escapes in a single-quoted doctor hint (lint) ([c0cf1a2](https://github.com/abdelrahmannasr/yadflow/commit/c0cf1a26c15fccc91df15013d6bac83892f2af25))


### Tests

* execute the spec-link, contract-check, build-test-lint, and risk-route gates directly ([7b217d0](https://github.com/abdelrahmannasr/yadflow/commit/7b217d0f01938f66fa4ea6a0fc6d7f0a04a3f9ff))
* e2e harness driving the installed tarball through a full gate cycle ([9a9dbde](https://github.com/abdelrahmannasr/yadflow/commit/9a9dbde8607d6890995217d76438a123bf4b2c22))


### Continuous Integration

* security signal bundle — SECURITY.md, audit gates, Scorecard, pinned actions ([2be8ba2](https://github.com/abdelrahmannasr/yadflow/commit/2be8ba207c8b50ae0c7cd559299867316801118c))
* coverage gate at 70% lines / 70% branches on the Node 22 leg ([742aa96](https://github.com/abdelrahmannasr/yadflow/commit/742aa96ecf80e409c0f465604803b65087b09bd7))
* add a macOS test leg; document platform support (Linux/macOS; Windows via WSL) ([952c624](https://github.com/abdelrahmannasr/yadflow/commit/952c624e3dc9529fd6a637454d4c568da5cd8170))
* add ESLint as a bug net (no formatter); remove the dead code it found ([3db66eb](https://github.com/abdelrahmannasr/yadflow/commit/3db66eb0e1812951bc44cc0e41b8d7d7122b95ea))


### Documentation

* GitHub community files — PR template (dogfooded), issue forms, code of conduct ([02e17b0](https://github.com/abdelrahmannasr/yadflow/commit/02e17b06c5c0d0d2fcb0eb40672400abc2eb4fd7))



## [2.0.1](https://github.com/abdelrahmannasr/yadflow/compare/v2.0.0...v2.0.1) (2026-06-13)


### Bug Fixes

* publish README with pre-rendered SVG diagrams so they display on npm ([05382f6](https://github.com/abdelrahmannasr/yadflow/commit/05382f6bfe27bb0604165692ca6fe1cdb74b9a35))


### Documentation

* pre-render README mermaid diagrams to SVG so they show on npm ([be3bce9](https://github.com/abdelrahmannasr/yadflow/commit/be3bce9e2c20949153984102149ac22a868ac9f9))



# [2.0.0](https://github.com/abdelrahmannasr/yadflow/compare/v1.4.0...v2.0.0) (2026-06-13)


### Features

* rename sdlc-* skills to yad-* and the CLI to yad; feature the report ([#42](https://github.com/abdelrahmannasr/yadflow/issues/42)) ([ea05f17](https://github.com/abdelrahmannasr/yadflow/commit/ea05f17085f992343fc9d1f25bde24c87815be1a))
* migrate pre-2.0 sdlc-* installs in place via yad update ([f85433f](https://github.com/abdelrahmannasr/yadflow/commit/f85433ff8fb4f54ce0c455abb2d72974f82fd507))


### Bug Fixes

* rewrite the root .gitlab-ci.yml include when migrating gitlab fragments ([75eeb3a](https://github.com/abdelrahmannasr/yadflow/commit/75eeb3acf4f2c77b43af4577fe5d1d3cc4285258))



# [1.4.0](https://github.com/abdelrahmannasr/yadflow/compare/v1.3.2...v1.4.0) (2026-06-12)


### Features

* rename npm package to yadflow ([#41](https://github.com/abdelrahmannasr/yadflow/issues/41)) ([1dd55e4](https://github.com/abdelrahmannasr/yadflow/commit/1dd55e4d403deeec344bb75b937ff24ccdaad64a))


### Chores

* update repo URLs after rename to abdelrahmannasr/yadflow ([297bb38](https://github.com/abdelrahmannasr/yadflow/commit/297bb38d5027a16f8ab635fda171419f65ac64f2))
* bump version to 1.0.2 ([ed03560](https://github.com/abdelrahmannasr/yadflow/commit/ed0356009923e3b9e226b43faee5ef7282ad2136))



## [1.3.2](https://github.com/abdelrahmannasr/yadflow/compare/v1.3.1...v1.3.2) (2026-06-11)


### Bug Fixes

* harden the ledger — atomic writes, fail-fast validation, CRLF-safe hashing, traversal guards ([#39](https://github.com/abdelrahmannasr/yadflow/issues/39)) ([71d1773](https://github.com/abdelrahmannasr/yadflow/commit/71d17735400b056ac666bbc75b55b13551032114))



## [1.3.1](https://github.com/abdelrahmannasr/yadflow/compare/v1.3.0...v1.3.1) (2026-06-10)


### Bug Fixes

* make test git commits immune to ambient GIT_AUTHOR/GIT_COMMITTER env ([#38](https://github.com/abdelrahmannasr/yadflow/issues/38)) ([ad92e52](https://github.com/abdelrahmannasr/yadflow/commit/ad92e525c1539a191cd3caffb12c4dc97e80b861))



# [1.3.0](https://github.com/abdelrahmannasr/yadflow/compare/v1.2.0...v1.3.0) (2026-06-10)


### Features

* **checks:** verified-commits gate — reject unverified commits from unverified users (hub + all repos) ([#37](https://github.com/abdelrahmannasr/yadflow/issues/37)) ([986bf28](https://github.com/abdelrahmannasr/yadflow/commit/986bf28e41b09478f99bff3de0ed40fe062d0cc0))



# [1.2.0](https://github.com/abdelrahmannasr/yadflow/compare/v1.1.1...v1.2.0) (2026-06-10)


### Features

* **gate:** event-driven gate sync — platform approve/request-changes/merge drives the ledger via hub CI ([#35](https://github.com/abdelrahmannasr/yadflow/issues/35)) ([e0adbd5](https://github.com/abdelrahmannasr/yadflow/commit/e0adbd512a016af5688c828702af73b20d953087))



## [1.1.1](https://github.com/abdelrahmannasr/yadflow/compare/v1.1.0...v1.1.1) (2026-06-09)


### Bug Fixes

* abort `sdlc open-pr` when the branch push fails ([#34](https://github.com/abdelrahmannasr/yadflow/issues/34)) ([2d32862](https://github.com/abdelrahmannasr/yadflow/commit/2d328628612dc906dcd28d78afa2183813cc1bc8))


### Documentation

* align the walkthroughs with the PR-driven gate and human repo refresh ([#31](https://github.com/abdelrahmannasr/yadflow/issues/31)) ([4e03ec1](https://github.com/abdelrahmannasr/yadflow/commit/4e03ec13ad291d64c5c5df7515d591b90b0b14de))
* backfill CHANGELOG for the 1.0.2–1.1.0 releases ([#32](https://github.com/abdelrahmannasr/yadflow/issues/32)) ([36c5f9d](https://github.com/abdelrahmannasr/yadflow/commit/36c5f9d027d3c25089a770ce28b170a9bb0c3a12))
* update package description to reflect the full workflow + CLI ([#33](https://github.com/abdelrahmannasr/yadflow/issues/33)) ([f461439](https://github.com/abdelrahmannasr/yadflow/commit/f4614393af195dad6d79bb1f21f6557994c7f5ba))



# [1.1.0](https://github.com/abdelrahmannasr/sdlc-workflow/compare/v1.0.3...v1.1.0) (2026-06-09)


### Features

* PR-driven review gate + build-helper CLI commands ([#30](https://github.com/abdelrahmannasr/sdlc-workflow/issues/30)) ([cc43319](https://github.com/abdelrahmannasr/sdlc-workflow/commit/cc4331903b2052b9835b0a6e3f21e148c809914c))

## [1.0.3](https://github.com/abdelrahmannasr/sdlc-workflow/compare/v1.0.2...v1.0.3) (2026-06-08)


### Bug Fixes

* install the missing analysis skill, and document the CLI + all 17 skills ([#29](https://github.com/abdelrahmannasr/sdlc-workflow/issues/29)) ([b968cbe](https://github.com/abdelrahmannasr/sdlc-workflow/commit/b968cbe0be0259746a332a10c5b79ffaf08a87be))

## [1.0.2](https://github.com/abdelrahmannasr/sdlc-workflow/compare/v1.0.1...v1.0.2) (2026-06-08)


### Bug Fixes

* drop @semantic-release/git so release works under branch protection ([#28](https://github.com/abdelrahmannasr/sdlc-workflow/issues/28)) ([4911773](https://github.com/abdelrahmannasr/sdlc-workflow/commit/491177359e6d2af291375884be3f86b3ac359f97))
* normalize package.json repository url ([#27](https://github.com/abdelrahmannasr/sdlc-workflow/issues/27)) ([1e8d93d](https://github.com/abdelrahmannasr/sdlc-workflow/commit/1e8d93d3c9cd5b89d3fa37f53cbfbe7f04126edb))

## [1.0.1](https://github.com/abdelrahmannasr/sdlc-workflow/compare/v1.0.0...v1.0.1) (2026-06-08)


### Bug Fixes

* read CLI version from package.json, not a hardcoded constant ([#26](https://github.com/abdelrahmannasr/sdlc-workflow/issues/26)) ([79a1e28](https://github.com/abdelrahmannasr/sdlc-workflow/commit/79a1e28d50d54e8b275d5f137ba456c7f4fcf76a))

# 1.0.0 (2026-06-08)


### Features

* add optional analysis front step and per-step authoring branches ([#19](https://github.com/abdelrahmannasr/sdlc-workflow/issues/19)) ([5821506](https://github.com/abdelrahmannasr/sdlc-workflow/commit/5821506db6a51ae4dfa6fc30c89670d037c109b1))
* add PR/MR templates, commit/check conventions, and a PR/MR review bridge ([#18](https://github.com/abdelrahmannasr/sdlc-workflow/issues/18)) ([e2d4747](https://github.com/abdelrahmannasr/sdlc-workflow/commit/e2d4747752bfb6dd58a16862f719596504e8ebcb))
* add sdlc gated-SDLC BMAD module with team review gate ([12367bc](https://github.com/abdelrahmannasr/sdlc-workflow/commit/12367bc0a67d5f8b252f9fd40f4c973dba85bf55))
* add sdlc setup/update/check CLI ([884b506](https://github.com/abdelrahmannasr/sdlc-workflow/commit/884b506e9bef8d47017ccb8e0e89f61eaecb6bf9))
* add sdlc setup/update/check CLI ([#21](https://github.com/abdelrahmannasr/sdlc-workflow/issues/21)) ([7d83224](https://github.com/abdelrahmannasr/sdlc-workflow/commit/7d8322478757047c2c34e244deb149d6c5ada852))
* add sdlc-backfill — Phase 3 Step G (existing-code specs) + README build half ([add5db7](https://github.com/abdelrahmannasr/sdlc-workflow/commit/add5db77d158bfa83b9eb8c8370ab888db429ca1))
* add sdlc-checks — Phase 3 Step C check gates ([f603ee5](https://github.com/abdelrahmannasr/sdlc-workflow/commit/f603ee5f2089ba5b698381303484404aff39322c))
* add sdlc-implement — Phase 3 Step B dev/implement step ([6605540](https://github.com/abdelrahmannasr/sdlc-workflow/commit/6605540fa196de075b12088922f8394c2c67fced)), closes [#1](https://github.com/abdelrahmannasr/sdlc-workflow/issues/1)
* add sdlc-pr-template — Phase 3 Step D PR/MR templates + risk routing ([f3c16cc](https://github.com/abdelrahmannasr/sdlc-workflow/commit/f3c16ccfca1cd9bc48e6fd2e10fa35bd20c65599)), closes [hi#risk](https://github.com/hi/issues/risk)
* add sdlc-run — Phase 4a (make the automation dial real, trust log, earn checks) ([d2c1a09](https://github.com/abdelrahmannasr/sdlc-workflow/commit/d2c1a09974ebbcac0be4cb6693c658c7a5fff775))
* add sdlc-ship — Phase 3 Step E AI review, engineer review, ship ([2f4fa42](https://github.com/abdelrahmannasr/sdlc-workflow/commit/2f4fa4258bbe9e04b554f2384fec3515603e6304))
* add sdlc-spec — Phase 3 Step A Spec Kit handoff ([69d1ef7](https://github.com/abdelrahmannasr/sdlc-workflow/commit/69d1ef7072912577b285b970ebff906252d0cd3c))
* complete gated-SDLC front half (Phase 2) ([76a2678](https://github.com/abdelrahmannasr/sdlc-workflow/commit/76a26781d79f322eb2a02313a4a74d6a3316192f))
* connect code repos to the hub and make the front phases code-aware ([#17](https://github.com/abdelrahmannasr/sdlc-workflow/issues/17)) ([0d4e033](https://github.com/abdelrahmannasr/sdlc-workflow/commit/0d4e03347ae7a48abf45016b7d0c21909ea28408))
* Phase 4b Step D — earn the implement→check hand-off + spec/tasks trust hooks ([e0ef03e](https://github.com/abdelrahmannasr/sdlc-workflow/commit/e0ef03e8772184c7db2d2fb52ce8c053ab5b7823))
* Phase 5 instrumentation — nudge-cost + fleet roll-up in sdlc-status ([68e417a](https://github.com/abdelrahmannasr/sdlc-workflow/commit/68e417a8340f04205ef856e83925ce1357c7bdbe))
