Skip to content

Kyn v0.1.3

Kyn v0.1.3 is a reliability and usability release. It tightens policy validation, keeps machine-readable output clean, makes path and kin resolution safer, and expands the practical installation and CI documentation without broadening Kyn's focused scope.

Highlights

Safer, more precise policy evaluation

  • Multi-name kinExists and kinMissing assertions now report only the kin that is actually missing.
  • Absolute, parent-traversing, and symlink-escaping paths are rejected when they leave --cwd.
  • A family whose kin template resolves differently for source files in the same instance now fails explicitly instead of depending on changed-file order.
  • Git repository probes and diffs have time and output bounds.

Clearer configuration failures

Kyn now rejects combinations that earlier builds accepted but could not evaluate faithfully:

  • both if and when on one rule;
  • both assert and require on one rule;
  • groups.source together with legacy top-level include or exclude fields;
  • named-group change selectors, assertion-side change selectors, and the unsupported deleted status.

These cases return the existing configuration/usage exit code 2 with actionable context. Valid v1 and v2 policies continue to work, and the v1-to-v2 migrator already avoids the conflicting family shape.

Better command-line ergonomics

  • Root help and kyn init output now guide users through Review, Preview, Enforce, and Diagnose steps.
  • Generated commands are safe to copy in POSIX shells and PowerShell, including working directories containing spaces or shell-special characters.
  • --verbose diagnostics go to stderr, preserving valid JSON, SARIF, RDJSON, and Checkstyle on stdout.
  • --summary-only --format json now omits per-rule results as its name promises. Summary-only output is limited to text and JSON because SARIF, RDJSON, and Checkstyle require per-rule diagnostics; unsupported combinations fail with exit code 2.
  • Empty change sets pass by default. Use --fail-on-empty when CI should treat an empty input as an error.
  • Multi-line command examples now render with consistent indentation.

Distribution and documentation

  • The documentation site now includes a platform-aware installation guide, a conceptual model, complete CLI/configuration references, troubleshooting, and tested frontend, Go API, Terraform, and CI recipes.
  • Release automation uses a pinned GoReleaser version and its multi-platform Docker v2 pipeline while preserving existing GHCR tag contracts.
  • Published binaries are compiled reproducibly with the patched Go 1.27.1 toolchain while Kyn keeps Go 1.22 as its supported minimum for consumers and contributors.
  • Release automation can generate WinGet manifests for x64 and ARM64. The initial DylanSteele.Kyn catalog submission remains under Microsoft review, so Scoop remains the recommended Windows package manager until it is admitted.
  • make ci now runs formatting, golangci-lint, vet, unit tests, the 80% internal coverage gate, build, and end-to-end fixtures.

Upgrade notes

Review configurations that intentionally mixed legacy and v2 clause names or relied on unsupported named-group/deleted-file semantics; they now fail early instead of being partially ignored. If automation used --summary-only with SARIF, RDJSON, or Checkstyle, remove that flag or select text/JSON. JSON consumers of kyn explain --summary-only should expect summary fields without the per-rule results array. If an empty changeset must fail your job, add --fail-on-empty.

Error classification is also more precise: Git repository/diff failures return runtime/provider exit code 3; invalid options, configuration, change input, and family resolution return usage/config exit code 2.

The CLI commands, report formats, deterministic ordering, and exit-code meanings remain stable. Kyn remains a stateless CLI; this release does not add daemon, plugin, PR-integration, or monorepo-graph features.

See the full changelog and the installation guide.