Kyn v0.1.3¶
Kyn v0.1.3 is a reliability and usability release. It tightens policy validation, keeps machine-readable output clean, makes path and kin resolution safer, and expands the practical installation and CI documentation without broadening Kyn's focused scope.
Highlights¶
Safer, more precise policy evaluation¶
- Multi-name
kinExistsandkinMissingassertions now report only the kin that is actually missing. - Absolute, parent-traversing, and symlink-escaping paths are rejected when they leave
--cwd. - A family whose kin template resolves differently for source files in the same instance now fails explicitly instead of depending on changed-file order.
- Git repository probes and diffs have time and output bounds.
Clearer configuration failures¶
Kyn now rejects combinations that earlier builds accepted but could not evaluate faithfully:
- both
ifandwhenon one rule; - both
assertandrequireon one rule; groups.sourcetogether with legacy top-levelincludeorexcludefields;- named-group change selectors, assertion-side change selectors, and the unsupported
deletedstatus.
These cases return the existing configuration/usage exit code 2 with actionable context.
Valid v1 and v2 policies continue to work, and the v1-to-v2 migrator already avoids the
conflicting family shape.
Better command-line ergonomics¶
- Root help and
kyn initoutput now guide users through Review, Preview, Enforce, and Diagnose steps. - Generated commands are safe to copy in POSIX shells and PowerShell, including working directories containing spaces or shell-special characters.
--verbosediagnostics go to stderr, preserving valid JSON, SARIF, RDJSON, and Checkstyle on stdout.--summary-only --format jsonnow omits per-rule results as its name promises. Summary-only output is limited to text and JSON because SARIF, RDJSON, and Checkstyle require per-rule diagnostics; unsupported combinations fail with exit code2.- Empty change sets pass by default. Use
--fail-on-emptywhen CI should treat an empty input as an error. - Multi-line command examples now render with consistent indentation.
Distribution and documentation¶
- The documentation site now includes a platform-aware installation guide, a conceptual model, complete CLI/configuration references, troubleshooting, and tested frontend, Go API, Terraform, and CI recipes.
- Release automation uses a pinned GoReleaser version and its multi-platform Docker v2 pipeline while preserving existing GHCR tag contracts.
- Published binaries are compiled reproducibly with the patched Go 1.27.1 toolchain while Kyn keeps Go 1.22 as its supported minimum for consumers and contributors.
- Release automation can generate WinGet manifests for x64 and ARM64. The initial
DylanSteele.Kyncatalog submission remains under Microsoft review, so Scoop remains the recommended Windows package manager until it is admitted. make cinow runs formatting, golangci-lint, vet, unit tests, the 80% internal coverage gate, build, and end-to-end fixtures.
Upgrade notes¶
Review configurations that intentionally mixed legacy and v2 clause names or relied on
unsupported named-group/deleted-file semantics; they now fail early instead of being
partially ignored. If automation used --summary-only with SARIF, RDJSON, or Checkstyle,
remove that flag or select text/JSON. JSON consumers of kyn explain --summary-only should
expect summary fields without the per-rule results array. If an empty changeset must fail
your job, add --fail-on-empty.
Error classification is also more precise: Git repository/diff failures return runtime/provider
exit code 3; invalid options, configuration, change input, and family resolution return
usage/config exit code 2.
The CLI commands, report formats, deterministic ordering, and exit-code meanings remain stable. Kyn remains a stateless CLI; this release does not add daemon, plugin, PR-integration, or monorepo-graph features.
See the full changelog and the installation guide.