ChangelogΒΆ
7.18.0.dev0 (unreleased)ΒΆ
Warning
This version is not released yet and is under active development.
Breaking: Remove the
lint-anchorscommand and the Docs workflow step running it. A Sphinx build reports the same broken fragment links asmyst.xref_missingwarnings.The
update-dep-graphjob moves from the release workflow to Autofix: it refreshes the graph on every push, for uv virtual projects too.Add
dependency-graph.updateto turn off the dependency graph updates.Fix
lint-reporeporting every bundled key missing from a[tool.pytest]section kept underini_options, and asking for native keys pytest refuses beside that table.Fix
lint-repoadvising to drop a bare[tool.lychee] excludeentry that no anchored form sits beside: it now names the anchored form to write instead.Fix
repomatic initdropping the comments beside a local key it keeps when re-syncing a tool config.Fix
repomatic initre-syncing a multi-line tool config array at a four-space indent, whichformat-pyprojectthen rewrote to two in its own pull request.Fix the setup guideβs R2 keys step describing a dashboard route the R2 page does not have: it now links the account token form.
Fix
fix-typosfailing oncertifiin a dependency graph that includesrequests: the bundledtyposconfig now accepts it.Fix
sync-workflow-pinsbumping the uv pin when it cannot read thesetup-uvchecksum table: it now holds the pin until the table reads again.Every setup guide step now reads like the token step: one lead sentence, numbered actions, form fields in a table, and the long explanations left in
docs/.job-timings,cancel-runsand theci-statusfallback now list runs with a date filter, so a stale run listing no longer feeds them weeks-old runs.cloudflare-r2 --offloadnow writes why it dropped a file as Markdown in the step summary, with code-formatted names and a docs link.The workflows reference now lists every
lint-repocheck, rendered from the check roster likelint-repo --help.The bundled
benchmark-updateskill now assesses every competitor cell of a row added since the last pass, and re-anchors pinned evidence links by content after a release.The bundled
babysit-ciandrepomatic-shipskills now run their local tests with thetestdependency group, which repositories without default groups need.New upstream page tracks the pull requests and issues repomatic sends to the projects it depends on.
7.17.1 (2026-09-30)ΒΆ
fix-typosnow checks hidden files and directories like.github/and.claude/, through the bundled[tool.typos]config.lint-repo --helpnow lists every check the command runs, rendered from the check roster.The setup guideβs R2 keys step now mirrors the Cloudflare Pages step, with the wrangler and dashboard routes and a dated token name.
ci-statusnow reads runs back from the branch tip, commit by commit, so a stale run listing no longer reports months-old runs as the latest.Fix the setup guideβs notes showing a literal
[!NOTE]or[!IMPORTANT]marker: GitHub renders no alert inside a stepβs collapsible block.lint-repono longer flags a PR template that opts out of the footer with the quotedfooter: 'false', whichpr-bodyhonors.Fix
repomatic initdropping the comments on the local array items it keeps when re-syncing a tool config, like each[tool.typos] extend-ignore-reentryβs.The bundled
repomatic-test-matrixskill now sayslint-repowarns about a runner outside the test matrices, rather than rejecting it.The bundled
babysit-ciandrepomatic-test-matrixskills and thegrunt-qaagent no longer read runs throughgh run list, which can list weeks-old runs as the newest.The bundled
repomatic-shipskill now keeps a parallel sessionβs edits out of its release commit, and runs its checks on that exact commit.
7.17.0 (2026-09-30)ΒΆ
Note
7.17.0 is available on π PyPI and π GitHub.
Breaking: The Docs workflowβs Cloudflare deploy now fails when it has to drop a file over 25 MiB, once the rest of the site is published. Declare
site.cloudflare-r2-bucketto serve such files instead.Add
cloudflare-r2and thesite.cloudflare-r2-bucketandsite.cloudflare-r2-domainkeys: the Docs workflowβs Cloudflare deploy now serves files over 25 MiB from that R2 bucket.lint-reponow warns about a tracked file over the 25 MiB Cloudflare Pages limit when no R2 bucket is declared.lint-repoand the setup guide now ask forCLOUDFLARE_R2_ACCESS_KEY_IDandCLOUDFLARE_R2_SECRET_ACCESS_KEYwhensite.cloudflare-r2-bucketis declared.The bundled
repomatic-depsskill now bisects a floor that rests on a behavior rather than an API, and reads deprecated calls off the test suiteβs warnings summary.The bundled
awesome-triageskill now closes a declined commercial submission with one fixed sponsorship phrase, and orders draft comments shortest first.The bundled
awesome-triageskill now traces a candidate to its primary source, and verifies every row of a small factual table.The bundled
repomatic-shipskill now keeps signed commits inside the sandbox when the sandbox settings allow the signing agentβs socket and files.The bundled
babysit-ciskill now fetches run logs inside the sandbox first, and leaves it only when theghcache write fails.The bundled
babysit-ciskill now reports a Cloudflare deploy that dropped a file over 25 MiB, and re-runs it only when the upload failed.The bundled
babysit-ciandrepomatic-shipskills now keep their failure catalog and two rare procedures inreferences/pages, read on demand.Raise the
tomlrtfloor to2.2.4.
7.16.3 (2026-09-30)ΒΆ
Note
7.16.3 is available on π PyPI and π GitHub.
lint-reponow warns when a seeded tool config (ruff,pytest,coverage,mypy,mdformat) lacks an entry its bundled template gained after the seeding.lint-reponow warns when a[tool.lychee] excludeentry is the bare form of one the bundled template has since anchored, which an ongoing sync grafts back beside its own replacement.update-docsnow lists each generated API page in its parenttoctree, so a new module no longer needs a hand edit.scan-virustotalgains--downloadand--repo, fetching the tagβs versioned binaries once its release lists them.The bundled
[tool.repomatic.gitignore] extra-contentdefault now ignores.wrangler/, the local statewranglerwrites in a checkout.The bundled
lychee.tomlnow excludesmedium.com, which returns 403 to anonymous crawlers but serves the full article to a browser.The bundled
awesome-templatecontributing guide andawesome-triageskill now separate a crawler-blocked403, which keeps its live URL behind a[tool.lychee]exclude, from a404, which gets archived.The bundled
sphinx-docsagent now warns that an incremental buildβs warning count covers only the pages it re-read.The bundled
sphinx-docsagent andsphinx-docs-syncskill now place developer setup on thecontributingpage, and flag a copy kept inreadme.mdorclaude.md.The bundled
sphinx-docsagent now compares two builds only under equal dependency groups, and requires a fully qualified reference in a base-class docstring.The bundled
qa-engineeragent now moves aCLAUDE.mdrule about one function, test or page beside that code.The bundled
repomatic-shipskill now names the transient empty run page a watcher must poll through rather than read as a finished suite.The bundled
repomatic-shipskill now classifies a version derived from a checked-in spec, whose bump breaks the recipe invoking it, and points a reading agent atgit show HEAD:<path>instead ofgit stash.The bundled
repomatic-shipskill now re-reads the tree after the last gate command, which can re-create a mutation already reverted.The bundled
repomatic-shipskill now builds the docs with--fresh-env, so a reference broken in an unchanged page still surfaces.The bundled
file-bug-reportskill now carries the evidence rules for an upstream report and the numbering behind a GitHub Actions log anchor.The bundled
babysit-ciskill now notes thatgh run rerun --failedalso re-runs the jobs skipped behind a failed or cancelled dependency.Generated workflows, the
lint-changelogannotations and the bundledtypos,uvandzizmorconfigurations now cite the published documentation in place ofclaude.md, which downstream repositories no longer receive.Raise the
click-extrafloor to9.3.Fix
scan-virustotalfailing when the freshly published release still lists no asset, which skipped the whole scan for that version.Fix
repomatic run --verifyexiting0when it had no path to verify, like a baretyposrun.The bundled
π€ cicontent rules no longer match.github, which pre-labelled every issue filed through an awesome listβs own new-link form.Fix the bundled
repomatic-auditskill claiminginitrefreshes a seededmypy,pytestorcoveragesection, which it never revisits.Fix the bundled
repomatic-shipskill claiming CI resolves the projectβs dependencies fresh, when its jobs install fromuv.lock.Fix the bundled
sphinx-docsagent pointing a rule at aclaude.mdsection, which downstream repositories do not receive.The
metricsandmetric_chartdocstrings now state that a star gained on a repositoryβs creation day replaces itscreatedanchor, so not every series carries one.The plugin page now warns that an account-enabled plugin also loads in the CLI, so pairing it with
init skillsregisters every skill twice.The plugin page now names the Desktop panel that takes the archive, the supported marketplace hosts, and where the off-by-default
Sync automaticallyswitch lives.The plugin page now records that the CLI compares
plugin.jsonrather than the catalog entry to detect an update, and that the Desktop app updates with no version change, both measured.The contributing page now carries the conventions for developing
repomaticitself: operation naming and contracts, and the rules for bundled agents and skills.The workflows page now explains the over-long entry and empty release warnings that the
lint-changelogannotations link to.Fix the plugin pageβs file-install command, which named an
agentscomponent instead ofsubagents.Fix stale statements on the workflows, security, test matrix, operation contracts and upstream development pages.
7.16.2 (2026-09-20)ΒΆ
Note
7.16.2 is available on π PyPI and π GitHub.
The bundled
babysit-ciskill now recognizes a runner that died mid-step, which ignores a cancel and leaves no log, and re-runs its job.The bundled
ruff.tomlnow ignoresD301, whose raw-docstring prefix breaks the\bmarker Click reads in a commandβs help text.Fix
verify-binarycrashing on a Linux binary linked with packed relocations, which requires theGLIBC_ABI_DT_RELRsymbol version.Fix
lint-changelogcalling a release gap confirmed live when the GitHub lookup failed, and calling a gap on PyPI alone unconfirmed.Fix the bundled
babysit-ciskill waiting for a whole run to end before reading a failed jobβs log, and fetching it without--allow-escape-sequences.Fix an
inittest that queried GitHub and failed for a distribution building a release inside the cooldown window.
7.16.1 (2026-09-19)ΒΆ
Note
7.16.1 is available on π PyPI and π GitHub.
Breaking: the bundled
repomatic-upgradeskill drops itsreviewandfixmodes. It now always applies its changes, uncommitted.Ship the test suite, and the repository files it reads, in the PyPI sdist, where tests needing a git checkout skip themselves.
sync-workflow-pinspull requests now label a uv pin stepped back onto thesetup-uvchecksum tableβͺ stepped back.sync-uv-lockpull requests now warn when the comment aboveexclude-newer-packagestill names an entry they cleared.The bundled
probe-workflowskill now keeps findings out of the retirement commit, gives a side-branch probe apushtrigger, and records two hostedmacos-26traps.The bundled
repomatic-upgradeskill now catches local edits to synced skills and subagents that the upgrade reverts, and passes--repotolint-reposo its API-backed checks run.The bundled
repomatic-upgradeskill now runs a changed jobβs released code on the repositoryβs own inputs, and regenerates a committed upgrade in a scratch clone to check it.The bundled
sphinx-docs-syncskill now builds the documentation and counts its warnings before auditing, and re-locksuv.lockwhen it adds a docs dependency.The bundled
upstream-auditskill now sweeps an authorβs issues and pull requests across GitHub, and resolves their states in one GraphQL query.Remove anecdotes naming past releases or other projectsβ threads from the bundled skills and the
sphinx-docsagent.Pause before retrying a truncated HTTP response, and retry it twice instead of once.
Fix
lint-repoasking for GitHub topics that multi-word keywords already declare:Weather forecastnow matches theweather-forecasttopic.Fix
lint-changelogreporting a release newer than its day-old cache as missing, and--fixmarking it unavailable, when the releaseβs section has no availability note yet.Fix
sync-workflow-pinsandlint-repoforastral-sh/setup-uvv10.1.0and newer: read its moved checksum table, and stop warning that an off-table uv installs unverified.Fix concurrent
repomatic run mdformatorshfmtcalls in one directory losing the temporary config another call wrote.Fix the bundled
sphinx-docsagent asking for arobots.txton a GitHub Pages project site, where crawlers never read it.
7.16.0 (2026-09-18)ΒΆ
Note
7.16.0 is available on π PyPI and π GitHub.
Breaking:
sample-metricsdrops--backfill-waybackand--import-csv, since GitHubβs star-history endpoint now rebuilds every curve. Readings they already wrote stay in the store.Breaking:
unsubscribe-threadsreplaces--batch-sizewith--max-unsubscribes, which caps unsubscribes instead of inspections. Theunsubscribeworkflowβsbatch-sizeinput is renamedmax-unsubscribesto match.Add
repomatic init --upgrade, which runs as the newest release past theminimum-release-agecooldown, so the upstream pin and every managed file move together.The
sync-repomaticjob now opens anUpgrade repomatic to vX.Y.Zpull request once a newer release clears the cooldown, listing the breaking changes it crosses. Opt out with[tool.repomatic] upstream-pin.sync = false.Add the
repomatic-upgradeskill, which reviews what a newerrepomaticrelease lets a downstream repository adopt, reuse or drop, then applies it.repomatic initand thesync-workflow-pinsandsync-repomaticpull requests now suggest the upgrade review after they move therepomaticpin.sample-metricsnow rebuilds every GitHub subjectβs weekly star curve from GitHubβs star-history endpoint, back to its first star, for any public repository rather than only administered ones.lint-reponow warns about labels a repository carries that no configured source declares, whichsync-labelsnever deletes on its own.Add
[tool.repomatic] notification.max-unsubscribesandnotification.months, whichrepomatic initbakes into the generated unsubscribe caller.unsubscribe-threadsnow fetches only notifications last updated before the cutoff, unsubscribes the oldest first, and resolves their states in GraphQL batches of 50.sync-workflow-pinsnow steps a uv pin back onto the checksum table of the pinnedastral-sh/setup-uv, so every job installs a verified uv.Raise the
click-extrafloor to9.1.Relative dates in the dependency tables and the
cloudflare-pagestoken-expiry warning now count hours within the same day, instead of readingjust nowor0 days away.Fix the unsubscribe reportβs phase-1 tables, whose first row carried an empty leading cell and last row two trailing ones.
The
unsubscribebacklog warning now links the workflowβs manual-run page, and no longer breaks its prose into short lines in the job summary.The bundled
repomatic-shipskill now runs a downstream repositoryβs local checks on therepomaticversion its workflows pin, so their tool versions match CI.The bundled
repomatic-shipskill now also checks hand-maintained registry blocks and the canary buildβs binary self-test, and filters run listings by creation date.The bundled
repomatic-shipskill now recommendsruff -- check --no-fixfor a read-only pass, smoke-tests theoxipngpin with--version, and takes:mirror:blocks from theupdate-docspull request.The bundled
repomatic-shipskill now reads a sub-agentβs report from its idle notification when the agent cannot send one.The bundled
repomatic-shipskill now runspyproject-fmtbeforeuv lockwhen a release touchespyproject.toml.The bundled
babysit-ciskill now caps a commit body at two lines and 25 words, and filters per-workflow run listings by creation date.Fix stale claims in the bundled
benchmark-update,brand-assets,github-housekeepingandsphinx-docs-syncskills and thesphinx-docsagent about star-history curves, undeclared labels, and logo andogp_imagewiring.Add a man-page index to the documentation, and cover
--man, the release tarball and regeneration on the installation page.Rename the installation pageβs
Try it,Install methodsandExecutablessections toTry it now,Installation methodsandBinaries. Their old anchors no longer resolve.Publish a sitemap, a
robots.txtand a custom 404 page, and stop publishing a copy of every documentation source under_sources/.Split the
Developmentsidebar section intoContributing,API reference,Release and hostingandProject.
7.15.0 (2026-09-07)ΒΆ
Note
7.15.0 is available on π PyPI and π GitHub.
Breaking: the
manpagesrelease job now renders throughclick-extra wrap --help-format man. The--manflag it used no longer writes roff.Breaking:
show-test-matrixnow lists one row per job by default, and--flatis gone. Pass the new--gridfor the compact two-axis pivot the command used to print.Breaking:
.claude/package-skills.shis gone. It packaged one ZIP per skill for the Claude Desktop Customize > Skills panel, which a plugin supersedes by carrying every skill and agent at once.Deprecated:
repomatic metadataprints a deprecation warning and will be removed in8.0.0. Useshow-metadata, which joinsshow-configandshow-test-matrix.Deprecated:
repomatic workflow lintprints a deprecation warning and will be removed in8.0.0. Uselint-workflows, a flat command replacing theworkflowgroup.Add the
probe-workflowskill: validate a claim about real-host behavior with a temporary GitHub Actions workflow, then retire it with its findings recorded in the retirement commit.lint-repogains amanpages-toolchaincheck, warning when a project opting into man pages locks aclick-extraits release job cannot render with.Add a
runner_archmetadata key, mapping every runner label in the full test matrix to its CPU architecture.Render each commandβs worked examples in a dedicated
Examplessection of its help screen and man page, with the command lines highlighted.Options taking a project-specific value now validate it, list the choices in
--helpand complete them in the shell:show-test-matrix,pr-body,pr-sync,update-dep-graph,ci-statusandjob-timings.Help-screen sections regroup around a new βCI & runnersβ section, and each section now lists its subcommands alphabetically.
Sharpen the one-line help descriptions of
show-metadata,prepare-release,lint-repo,run,fix-awesome-tocandcloudflare-pages.sync-runner-imagesnow rewrites a literalruns-on:as soon as a newer image supersedes it, instead of waiting for the old one to be deprecated.The
scan-virustotalpull request is now titledUpdate released binaries database, with a one-line body replacing its scan-records commentary.Release blockers now carry a
Clearscountdown, in both the release pull requestβs alert and a newlint-depscolumn, each linking the pull request of the job that lifts it.The release pull requestβs
Squash and mergealert drops from caution to warning, leaving caution for the blocker banner the release lane cannot catch in time.Trim the prose of the
bump-version,detect-squash-merge,prepare-release,sample-metrics,setup-guide-cloudflare-pages,setup-guide-token,sync-dep-sourcesandsync-runner-imagespull request templates.The Claude Code plugin marketplace now installs
.claude/through agit-subdirsource, which Claude Desktop and Cowork accept, and tracks the default branch so skill fixes land between releases. Adding the catalog at a tag still installs that release.The plugin manifest moved to
.claude/.claude-plugin/plugin.json, soclaude --plugin-dir .claudeloads the plugin straight from a checkout.Document the Intel macOS support policy:
macos-x64binaries ship for as long as GitHub Actions offers an Intel runner image to build them.Illustrate the readme and docs with live captures: the CLI help screen, an animated
sync-deps --dry-runsession, the test-matrix grid and a configuration example.Raise the
click-extrafloor to9, required by the newExampleshelp sections and themanpagesrelease job.Bump Nuitka from
4.1.3to4.2.Fix uvβs resolution summary scribbling over the
sync-depsprogress trail.Fix
repomatic runprinting a Python traceback for an unknown tool name. It is now a usage error listing every registered tool.Fix the
plugincomponent rewriting a settings fileformat-jsonhad already settled, which keptsync-repomaticand the autofix lane undoing each other. The wiring now compares the parsed document, not its text.Fix the generated
release.yamlending on a stray blank line, alone among the workflow callers.Fix
lint-repoasking for GitHub topics a project already declares: topics now match[project] keywordscase-insensitively, since GitHub lowercases every topic it stores.Fix
sync-runner-imagesproposing a probe for a runner image the repository already runs, which marked every test-matrix cell on that imagecontinue-on-error.Fix
run {tool} --verifycrashing with aFileExistsErroron a path resolving to the working directory, which now verifies the toolβs own default file set.The bundled
babysit-ci,probe-workflowandrepomatic-shipskills now read CI runs through the GitHub API, aftergh run listreported month-old runs as the newest.Fix stale references in the bundled
babysit-ci,repomatic-audit,repomatic-changelog,repomatic-shipandrepomatic-test-matrixskills: danglingclaude.mdpointers, a retiredlychee.tomlpath, an inverted binary-build condition and stale workflow names.The bundled
file-bug-reportskill now states when a GitHub permalink renders as a code snippet, and how to read a line range off the commit it pins.The bundled
babysit-ciandrepomatic-shipskills now treat a wall-clock budget failing on a shared runner as a test defect to fix, not transient infra to re-run.The bundled
repomatic-shipskill now warns thatactionlintandzizmorcan contradict each other, and says how to settle a conflict between them.Document the mdformat defect that silently deletes a backtick code span inside a Markdown imageβs alt-text.
7.14.0 (2026-08-27)ΒΆ
Note
7.14.0 is available on π PyPI and π GitHub.
Breaking: the
agentcomponent is gone, with theagent.locationconfig key and the bundledclaude.mdreference document.repomatic initno longer writes to a repositoryβs instructions file, which each repository now owns outright.Breaking:
CLOUDFLARE_ACCOUNT_IDis gone: the account derives fromCLOUDFLARE_API_TOKENalone.cloudflare-pages --account-idandlint-repo --has-cloudflare-account-idare removed with it.Breaking: the
debug.yamlworkflow is now opt-in, gated by a new[tool.repomatic] debug.synckey. A repository already carrying it keeps it by settingdebug.sync = true.Breaking: the
archfield ofrepomatic metadataβsbuild_targetsandnuitka_matrixoutput now readsx86_64andaarch64, notx64andarm64. Update any workflow branching onmatrix.arch.Breaking:
build_targetsandnuitka_matrixreplace theglibc_floorandmin_oskeys with a singlefloor, holding the same versions. A workflow readingmatrix.min_osneedsmatrix.floor.lint-repogains two checks:setup-uv-checksum-coverage, warning when CI installs the pinned uv unverified, andclassic-branch-protection, reporting a branch protection rule left beside a ruleset.show-test-matrixgains--row-axis,--col-axisand--flat, laying the grid out on any job key the matrix carries or listing one row per job.show-test-matrixstates how many jobs a cell stands for (β stable Γ5), and sorts its Python rows by release instead of job order.scan-virustotalandsample-metricspublish through one long-lived pull request that each run appends to, instead of committing to the default branch. No file-modifying job pushes there any more.Both gain
--carry-from, restoring the store from a remote branch first, so records pending in an open pull request are appended to rather than dropped.sample-metricsnames the phase (forward,reconstruct,importorwayback) in a new column of its report table, so one subject reads as one outcome per phase.cloudflare-pages --createis now idempotent: an existing Pages project is reused and reconciled against the declared settings, instead of failing on the APIβs409duplicate-name refusal.The Todo list documentation page lists the projectβs pending work: each deferred change is written as a
todoadmonition beside the code or prose it acts on.The
repomatic-shipskill now sweeps those admonitions: pending work the cycle introduced is written as one, and a todo whose upstream trigger fired is retired with the shim it guards.metadataand every glob-driven check now walk the repository tree once and skip.git/, instead of re-walking it on every lookup.ci-statuslocates every workflowβs newest run through one branch-wide listing instead of one query per workflow.Every HTTP fetch now identifies itself with a
repomatic/{version}user agent.sync-workflow-pinsno longer bumps the uv pin past what the pinnedastral-sh/setup-uvcan checksum-verify: the action silently skips validation for a version its bundled table does not list.show-configwraps its widest columns instead of running past 240 characters. A format unable to hold a wrapped cell, likegithuborcsv, stays unwrapped.list-skillsrenders a table honoring--table-format, replacing the hand-padded lines that ran to 500 characters.sync-runner-imagestakes--livelike every other command with a dry-run mode, replacing its odd--no-dry-runspelling.Dependency-update pull requests no longer list yanked or pre-release versions in their intermediate release notes.
The bundled
[tool.typos]config no longer checks SVG content: a terminal capture splits words across<text>runs, so correcting a fragment corrupts the image.The
lint-repostale gh-pages check now passes only on a confirmed404: any other API failure reports as skipped instead of green.Fix
lint-repoflagging everytest-matrix.excludeentry as stale on afull-includematrix, and the finding now names the missing axis values.Fix
lint-depsmissing a dependency floor declared with>when checking floors against the cooldown window.Fix
lint-depsasking an aggregate extra selecting the projectβs own extras for a version floor, which a project can never declare on itself.Fix
metadataleaving the checkout on a past commit with changes stashed when a mid-scan git command fails.Fix the
sample-metricschart crashing on a series whose peak is0or1.Fix
sample-metricsabandoning the tail of a sampling pass to GitHubβs secondary rate limit: theghplumbing now retries the refusal on a bounded backoff.sample-metrics --backfill-waybackgives up after ten consecutive refusals and reports to retry later, instead of spending every remaining captureβs retry schedule against an exhausted per-IP budget.Fix
show-test-matrixleaving a cell bare when several jobs share it: every state of astable, unstablecell now carries its own glyph.Fix the
plugincomponent writing tab-indented settings into a repository whose Biome config asks for spaces, which hadsync-repomaticandformat-jsonfighting each other. The indent now follows that config.Fix
initleaving behind the folder of a removed skill whoseSKILL.mdwas already gone: the tombstone addresses the file, so an empty folder outlived every later run.Fix
format-imagesdropping its optimization summary table from the PR body, lost in7.11.0when its two PR-publishing steps collapsed into one.The skills, subagents and plugin documentation pages group under an Agent tooling section and move to
/agent-skills,/subagentsand/claude-code-plugin, with the old URLs redirecting.The generated API reference moves off the guide pages and splits one page per module (
/repomatic.awesome_toc), instead of stacking a whole package onto one page. The guide pages keep their prose and link to it.The Python compatibility table of the install page marks a version a release neither declared nor excluded with
β, instead of counting it as unsupported.The
commit-messagespage and the bundled skills now hold a commit body to three cases: bundled orthogonal work, a link to a public record, or aCloses #Npointer.Fix the
excludeexample of the configuration page namingzizmor, which is not a component: copying it maderepomatic initfail.Fix stale guidance in the bundled skills: two module pointers the regroup broke, the scan history now published through a pull request, and a retired upstream contribution target.
Fix the dead
claude.mdsection cross-references the bundled skills and subagents carried, and guard against new ones.Sphinx linkcheck no longer reports every release-asset download URL as broken:
conf.pywithholds its github.com credential from those URLs, which GitHub redirects to a host that answers 401.Fix the dead links on the install and operation-contracts pages, and the API reference documenting every regrouped module twice.
7.13.0 (2026-08-17)ΒΆ
Note
7.13.0 is available on π PyPI and π GitHub.
Breaking: the
agentscomponent is renamedsubagents, its config keyagents.locationbecomingsubagents.location. Naming the old component in[tool.repomatic] includeorexcludefails the init; the old config key is ignored with a warning.Breaking:
repomatic init claudeis renamedrepomatic init agent, and its destination follows[tool.repomatic] agent.location(defaulting per[tool.repomatic.flavor] agent) rather than a fixed root-levelclaude.md, reaching instructions kept asAGENTS.mdor outside the root.Breaking: the
runner-imagescommand, its workflow job and its[tool.repomatic] runner-imagesconfig key are gone, along with the issue they maintained;sync-runner-imagescloses that issue on its first run.Breaking: the Cloudflare Pages deploy needs only
CLOUDFLARE_API_TOKEN: a token scoped toCloudflare Pages: Editresolves its own account, soCLOUDFLARE_ACCOUNT_IDbecomes an override for a credential spanning several accounts;cloudflare-pages --account-idprints the identifier for that case.Breaking: the VirusTotal scan history moves from
docs/assets/virustotal-scans.jsontovirustotal-scans.csv. The firstscan-virustotalrun after upgrading converts the old JSON on its own; delete the stale.jsonafterwards.New
[tool.repomatic] site.deployconfig choosing where the built site publishes:github-pages, the default, orcloudflare-pagesthroughwrangler pages deploy, withsite.cloudflare-projectnaming a Pages project that predates the repository.New
cloudflare-pagescommand reconciling the live Pages project against the declaredsite.*state:--check,--apply,--dump, and--createfor rebuilding from nothing. Warns a month before the API token expires, which Cloudflare never signals.New
cloudflare-pages --attach-domainserving a project at a custom domain, creating the proxiedCNAMErecord the bare API leaves missing.New
cloudflare-config-driftjob in the Docs workflow running that check apart from the deploy, so drift is loud without holding up publishing.lint-reponow fails a committed_redirectsfile that would lose rules to the Cloudflare Pages engineβs silent budget accounting, naming each URL a dropped rule leaves dead or silently misredirected.lint-reponow warns whenwrangler.tomlcontradicts the declared Cloudflare Pages project name or compatibility date, and checks a migrated site keeps its GitHub Pages custom domain pointing at the new host so publishedgithub.ioURLs keep redirecting.The Cloudflare deploy job now drops files over Direct Uploadβs 25 MiB per-file limit, naming each in the log, instead of failing the whole upload on the first one.
The Docs workflow now runs monthly, mirrored into downstream callers: a lapsed Cloudflare token becomes a red run, and link rot surfaces between pushes.
The Docs workflow no longer publishes Sphinxβs parse cache: doctrees now build in the runnerβs temp directory instead of riding the Pages upload, 118 MB of a 182 MB artifact on an autodoc-heavy project.
Every setup guide step is rewritten to the actions it asks for; the guide and
lint-reponow ask about whichever hostsite.deploynames, and the Cloudflare step hands out a pre-filled account-owned token form.New
sample-metricscommand recording what forges say about the repositories a project tracks into one committed CSV: star count, newest release or tag, and newest commit, read from GitHub, GitLab and Forgejo instances.sample-metricsrenders the accumulated history as themeable SVG charts, replacing the star-history embeds GitHubβs 2026 stargazer restriction broke. Star history recovers from per-star timestamps, archived pages with--backfill-wayback, or a star-history.com export with--import-csv.New
[tool.repomatic.metrics] chartsoptionscale = "logarithmic", measuring the vertical axis in powers of ten so series orders of magnitude apart stay legible on one chart.New opt-in
metrics.yamlworkflow running the sampler weekly and committing its store. Enable with[tool.repomatic] metrics.sync = trueand declare the repositories to follow in[tool.repomatic.metrics] subjects.New
sync-runner-imagescommand and weekly job opening a pull request that moves a deprecated runner image onto its successor, or probes a strictly newer one ascontinue-on-error. Decline a proposal for good with[tool.repomatic.sync-runner-images] ignore.New
job-timingscommand reporting median whole-job wall-clock per runner image, read from recent successful runs.lint-depsnow warns about a dependency floor comment running past[tool.repomatic] lint-deps.comment-word-thresholdwords, 40 by default.New
lint-anchorscommand checking every authored same-page fragment link against the anchors the built site actually carries, run by the Docs workflow before each deploy.New
pr-bodyandpr-syncoption--template-arg-file KEY=PATH, reading a template value from a file for a value with no ceiling on its size.New
git-commit-pushoption--all-changes, staging everything the working tree carries instead of a named path list.New bundled
repomatic-test-matrixskill deciding which Python versions, operating systems and runner images earn a test-matrix cell.Bundled guidance moves its release-repair, label-retirement and test-matrix procedures out of
claude.mdand into the skills that run them, leaving the always-loaded file carrying rules rather than checklists.The bundled
repomatic-shipskill now names all three shapes an unanswered hardware-key signing prompt produces, treating a silent hang as a missed prompt rather than a slow command.The bundled
sphinx-docsagentβs page roster gains theplugin,commit-messagesandhistorypages.The release PRβs unshippable-dependency warning is now a single line naming each package, each linked to the line declaring it, instead of a paragraph and a four-column table.
The binaries catalog now leaves the VirusTotal cell empty unless a scan record backs it, instead of linking every binary to an analysis page that was never created.
The bundled
[tool.typos]config now acceptsPNGsandPATCHed, which typos otherwise splits and rewrites toONGsandPATCHead.repomatic initno longer drops the comment documenting a bundled templateβs first key: six of the nine templates were losing their opening comment, the[tool.typos]proper-noun map among them.Fix
ci-status --helpcollapsing everything after its first example into one garbled line.update-dep-graphnow reads the rootβs direct dependencies fromuv.lock: uvβs SBOM export promoted a dependency-group package to a primary dependency whenever an extra pulled it in transitively.New Cloudflare Pages documentation page covering Direct Upload, token scoping and rotation, the drift check, and the redirects engineβs undocumented accounting. It opens on a runbook taking a bare domain name to a published site in seven commands.
This projectβs documentation moves to repomatic.net, and its links move with it: every reference now names the extensionless URL Cloudflare Pages serves. The old
kdeldycke.github.io/repomaticaddresses keep redirecting.
7.12.1 (2026-08-15)ΒΆ
Note
7.12.1 is available on π PyPI and π GitHub.
New
[tool.repomatic] sphinx.builderconfig choosing the Sphinx builder the Docs workflow deploys, so a project can publish extension-less URLs withdirhtml.The bundled
repomatic-shipskill now reads a green CI run as stale when supersession cancelled every run between it andHEAD, and ships a releaseβs own reflection findings in that same release.Bundled guidance now requires a duration baseline and per-job timestamps before calling a CI run hung, and
repomatic-shipno longer holds a green release waiting for a binary build.Fix stale guidance in the bundled agents and skills: the
update-docsjob credited to the wrong workflow, Furo logo and OpenGraph settings contradicting a working configuration, and arepomaticinvocation that fails outside the canonical repository.New
repomatic init claudecomponent projecting the audience-tagged sections of the bundledclaude.mdinto a repository, leaving every section that repository wrote for itself untouched.Bundled guidance now declares which repositories each
claude.mdsection applies to, and documents what a repository consuming repomatic owns: its workflow content, its pin, and its configuration.The bundled
repomatic-auditskill now reads those tags to tell a synced section from a repositoryβs own, instead of classifying each one by hand.Fix two stale claims in the bundled guidance: the workflow permissions contract is generated rather than hand-written, and PAT-gated
lint-repochecks report as skipped rather than failing the job.
7.12.0 (2026-08-14)ΒΆ
Note
7.12.0 is available on π PyPI and π GitHub.
New
ci-statuscommand reporting each workflowβs latest run and which of its failing jobs gate a merge, read from jobs rather than run conclusions.New
repomatic run <tool> --verifyreporting which files a formatter would rewrite, without touching the working tree.repomatic runnow resolves a toolβs targets itself when given no arguments, and skips a tool with no matching file instead of invoking it pathless.New repeatable
pr-sync --add-pathoption limiting what the pull request commits to a git pathspec list.lint-depsnow warns about declarations departing from version policy: upper bounds, missing floors, unsorted lists, misplaced type stubs, uncommented floors. Disabled with--no-policy.lint-depsnow names thelint-deps.allowexemption in the remedy it prints for a git source.sync-workflow-pinsnow backfills a missing--exclude-newer-packageexemption on a run that moves no version, instead of computing the splice and discarding it.lint-reponow fails when an inline upstream pin resolving under a cooldown carries no--exclude-newer-packageexemption, which takes everyneeds: metadatajob down with it.lint-reponow warns when anastral-sh/setup-uvstep declares noversion:input, or when steps across the repository pin more than one uv version.lint-reponow fails, andrepomatic initnow warns, when a workflow asksrepomatic metadatafor a key that no longer exists.lint-reponow warns when a Sphinx projectβs GitHub website field differs from the documentation URL declared in[project.urls].lint-changelognow warns about a released section holding no entry.runner-imagesnow watches every image the workflows name literally, not just the curated test axes.A bare
repomatic initnow re-syncs a tool config the repository already carries, so[tool.typos],[tool.uv]and[tool.bumpversion]follow the bundled template once adopted.Every job now caps its runtime with
timeout-minutes, so a hung job frees its runner in minutes instead of the platformβs 6-hour ceiling. Downstream callers inherit the caps.The Docs workflow now triggers on
readme.*.md, so a push touching only a translated readme no longer skips link checking.repomatic run actionlintnow ships a bundled config declaring theubuntu-26.04runner labels actionlint1.7.12predates.The bundled
lychee.tomlnow excludesbitdefender.com,npmjs.com,star-history.comandgithubstatus.com, which answer bots with 403, 405 or JavaScript rather than a link.cancel-runsnow spares a run whose head commit carries[changelog] Release, so a sweep of the default branch cannot kill a release matrix.Fix
ghre-downloading on every command instead of once per version: a binary nested in an archive subdirectory was stored under one cache key and looked up under another.Fix
repomatic initrealigning a workflowβs inlinerepomatic==X.Y.Zpin without the cooldown exemption beside it, leaving a command that cannot resolve the version just written.Fix
audit --fixdirtyinguv.lockwith a cooldown-override record when no upgrade was reachable, which opened afix-vulnerable-depspull request carrying no fix.Fix
repomatic initrestyling a locally added array item when it re-syncs a tool config, which hadsync-repomaticandformat-pyprojectendlessly opening pull requests undoing each other.A formatter exiting with its rewrite status while leaving every target unchanged is now reported as a crash, instead of passing for a successful reformat that never happened.
Fix stale guidance across the bundled skills: wrong
[tool.repomatic.workflow]key names, wrong workflow and job names forlint-depsandlint-changelog, which tools a bundled default actually covers, and downstream audits comparing againstmainrather than the adopted release.Fix the bundled
babysit-ciskill classifying a CI job by a leadingβ, which dropped every required job whose name carries no stability glyph from the failures it collects.
7.11.0 (2026-08-13)ΒΆ
Note
7.11.0 is available on π PyPI and π GitHub.
Breaking:
labels.content-rulesandlabels.file-rulesare now tables mapping each label to its patterns, like"π docs" = ["docs/**"]. The array-of-tables form and itsactions/labelerv5 matcher schema are gone; an un-migrated config is ignored with a warning.Breaking: the
file-labellerandcontent-labellerjobs merged into a singleapply-labelsjob. Update any required check orneeds:edge naming them.Breaking:
repomatic initandrepomatic workflow linttake--upstream-repofor the upstream toolkit;--reponow means theowner/nameslug everywhere, including onsync-labels.New
pr-synccommand replacingpeter-evans/create-pull-requestin every job: opens, refreshes or retires an automation PR from one--templateflag. Its PR closes even when the jobβsif:gate skips the rest of the step.New
lock-threadscommand replacingdessant/lock-threadsin the autolock job. It skips threads carrying theπ€ cilabel, so an issue repomatic maintains is no longer locked out of reopening when its condition recurs.New
apply-labelscommand replacingactions/labelerandgithub/issue-labelerin the labeller job. A ruleβs entry overrides the bundled default for that label, and an empty list disables it.The debug jobβs context dump no longer runs
crazy-max/ghaction-dump-context, and no longer installscgroup-toolsandcpuidto read them. It now reports the kernel, disk, CPU and memory of every runner using only what the image already ships.A bare content pattern is now a keyword, matched case-insensitively on word boundaries, so
"π bug" = ["bug", "error"]works as written; the/β¦/flagsform passes a regex through. Keyword lists used to be AND-joined and never fired.repomatic init labelsno longer writes.github/labeller-content-based.yamlor.github/labeller-file-based.yaml: the default rules live in the package, andrepomatic initnow prunes an unmodified committed copy automatically. Move customizations to[tool.repomatic.labels]; a hand-edited copy is left for review instead of deleted.The
sponsor-labelcommand now applies theπ sponsorlabel the registry defines, instead of a plural variant that exists in no repository and failed every labelling attempt.pr-syncnow clears a conversation lock standing in the way of retiring a stale automation PR, instead of dying on the refused close comment.sync-labelsnow hands labelmaker the canonical token (REPOMATIC_PAT, thenGH_TOKEN, thenGITHUB_TOKEN), so an environment carrying only the PAT syncs authenticated.Every re-lock (
sync-dep-sources,audit --fix) now passes the projectβs own[tool.uv] exclude-newerexplicitly, so CIβs ambientUV_EXCLUDE_NEWERcan no longer retime the lock.lint-reponow runs the branch-ruleset and immutable-releases checks it already defined but never invoked.apply-labelsno longer appliesπ sponsorfrom the words βfundingβ or βsponsorβ, or from a pull request touching.github/funding.yml: onlysponsor-labelsets it, from actual sponsorship.Every
ghcall now runs the registry-pinned, checksum-verified binary, falling back to$PATHwith a warning when it cannot be installed.Test jobs running an unreleased Python are now titled
py3.15-dev, so acontinue-on-errorcell states why it is allowed to fail.
7.10.0 (2026-08-12)ΒΆ
Note
7.10.0 is available on π PyPI and π GitHub.
Breaking: the
update-dep-graphjob moved fromautofix.yamlinto the release engine, its only firing moment being a release push. A required check orneeds:edge naming it under Autofix must follow.Breaking: manual version-bump commits now read
[changelog] Bump minor version to `vX.Y.0`: every version-machinery commit carries the[changelog]prefix, and anything matching the old unprefixed titles must follow.Breaking: the default test matrix moved to
ubuntu-26.04-armandubuntu-26.04, retiringubuntu-slim: every job now runs on a test-matrix runner. Pin the old images back withtest-matrix.replace.os = { "ubuntu-26.04-arm" = "ubuntu-24.04-arm" }.Breaking: a report emitted with
--output-format github-actionsnow travels as a file: the step output is named<key>_fileand holds a path, so a large report reaches a PR body intact. A workflow readingsteps.<id>.outputs.diff_tablemust read.diff_table_fileinstead.New
lint-depscommand and release-lane job, blocking a release whose dependencies do not all resolve from PyPI: git branches, forks, local paths, direct URLs and private indexes. Exempt a package with[tool.repomatic] lint-deps.allow.New
runner-imagesjob and CLI command, opening an issue that lists GitHubβs open runner-image announcements and flags the ones retiring an image the repo runs on. Opt out withrunner-images = false.New
is_python_packagemetadata key.sync-bumpversionnow gates on it instead ofis_python_project, so the job no longer opens[tool.bumpversion]PRs against a uv virtual project ([tool.uv] package = false).New
--prefix-fileoption onpr-body, and a matchingGHA_PR_BODY_PREFIX_FILEvariable, reading the body prefix from a file.Autofix jobs no longer run on version-bump pushes, which only re-checked machine-generated commits; drift stays covered by the next push and the weekly sweep.
repomatic initno longer writes the running versionβs workflow content beside a pin the cooldown held back: a repository that already carries workflows keeps them untouched until the release is adopted.The
repomatic-shipskill now reconciles bundled skills and agents as a third pass, judges a false-positive autofix PR against currentmain, and distinguishes a superseded intra-cycle measurement from a genuine contradiction.macOS Nuitka builds now hit their compile cache: ccache hashes paths relative to the runner root (
base_dir), so uvβs randomly-named cache path no longer changes the hashed compiler arguments every run.The tool runner now retries a download up to 3 times on transient network failures, instead of failing the job on a one-off TLS or truncation error.
Standalone binary tests now run for every healthy target when a sibling build fails, instead of being skipped wholesale.
Oversized step outputs are trimmed instead of killing the step that reads them with
Argument list too long.The setup guide issue now reopens when Actions SHA pinning is turned off, instead of closing while reporting every repository setting complete.
7.9.0 (2026-08-10)ΒΆ
Warning
The windows-x64 binary shipped without its .attestation.json sidecar: a transient TLS failure on the runner skipped the upload, and immutable releases lock the asset list. The attestation itself is registered, so gh attestation verify repomatic-7.9.0-windows-x64.exe --repo kdeldycke/repomatic still verifies against GitHubβs attestation service.
Note
7.9.0 is available on π PyPI and π GitHub.
Breaking:
REPOMATIC_PATnow requiresAdministration: Read-only, andlint-repofails without it. Regenerate the token with the setup guideβs pre-filled link; steps that cannot be verified now say so instead of vanishing.New
[tool.repomatic] nuitka.dev-targetsoption: an ordinary push now compiles binaries only for a canary subset,["linux-arm64"]by default. Release commits, a new weekly schedule and manual dispatches build the full 6-target fleet.lint-reponow also verifies versionlessreleases/latest/downloadURLs indocs/install.md, catching a renamed asset that leaves the guide pointing at a 404.sync-workflow-pinsnow walksnpx pkg@1.2.3version literals forward, not justnpm installanduvxpins.repomatic initnow realigns a workflowβs inlinerepomatic==X.Y.Zliteral onto the pin it writes into theuses:refs, in either direction.Nuitka compile caches now persist across runs, so a warm build skips most of the C compilation. Release commits and macOS builds opt out, so no published binary is influenced by cached objects.
Compile, binary-test and VirusTotal-scan jobs now carry execution timeouts, so a hung job frees its runner slot instead of squatting it for 6 hours.
Scheduled and manually dispatched release runs get their own concurrency group, so a later push no longer cancels them mid-build.
Binary self-tests on non-release pushes now run inside the compile job; the standalone per-target test jobs run on release commits only.
sync-gitignoreno longer discards rules added by hand to the committed.gitignore: it refuses to write when the rebuild would lose one, naming the rules. New--drop-orphansflag confirms an intended loss.The setup guide no longer asks a uv virtual project to register a PyPI Trusted Publisher, and
lint-repono longer checks one: both now gate on whether the project builds a distributable.Fix the broken-links issue never being filed:
docs.yamlran lychee throughxargs, which reported its βbroken links foundβ exit status as a crash.A
Bad credentials401 now fails immediately instead of retrying a token that cannot recover, so a revokedREPOMATIC_PATreports itself plainly rather than as a chain of unrelated check failures.New Nuitka compilation guide covering build targets, fleet cadence, compile caching, the LTO stance, and upstream workarounds.
New Build backends section in the packaging guide, covering the
[tool.setuptools]package-discovery shim a distribution needs when it builds auv-buildproject with setuptools.The documentation sidebar logo now follows Furoβs light and dark toggle, so the wordmark no longer renders near-black against the dark theme.
7.8.0 (2026-08-09)ΒΆ
Note
7.8.0 is available on π PyPI and π GitHub.
Breaking: the Codecov integration is removed, along with the
codecovcomponent, its.github/codecov.yaml, and thecoverage_cellsmetadata key.repomatic initprunes an untouched orphaned config; delete theCODECOV_TOKENsecret and coverage badge by hand.Breaking: attestation bundles now carry the full filename of the asset they attest, so
repomatic-manpages.attestation.jsonbecomesrepomatic-manpages.tar.gz.attestation.json. A repository declaring one extra asset gets<filename>.attestation.jsonin place of<package-name>-extra-assets.attestation.json.New
pack-attestationcommand names an attestation bundle after the asset it attests and prints the release upload list.New
coveragecomponent:repomatic init coveragewrites a[tool.coverage]section carrying branch coverage, report precision and areport.fail_underratchet, shipped disabled.lint-reponow warns when a release download URL indocs/install.mdnames a file its release does not carry.The bundled pytest config drops
--cov-branchand--cov-precisionfromaddopts, now carried by thecoveragecomponent. Existing[tool.pytest]sections are left alone; runrepomatic init coverageto pick the settings back up.The release laneβs
publish-releasejob now checks out the repository, so uploading binaries to the release no longer fails withFailed to spawn: repomatic.7.7.0shipped with no standalone executables because of it.lint-changelogre-confirms a release live before dropping its availability admonition, so a day-old cache no longer reports a just-published version as missing.The readmeβs logo is now an absolute URL, so it renders on the PyPI project page instead of 404ing.
The install guideβs executable table points at the last release that carries binaries, instead of a version whose upload lane failed.
7.7.0 (2026-08-09)ΒΆ
Note
7.7.0 is available on π PyPI and π GitHub.
Breaking: drop the
check-versioncommand: nothing invoked it, and workflows read theminor_bump_allowedandmajor_bump_allowedmetadata keys instead.Breaking: drop the
clean-unmodified-configscommand, superseded byrepomatic init --delete-unmodified.Breaking:
repomatic metadatano longer emits thetoml_files,changelog_bullet_word_threshold,nuitka_enabledandnuitka_nofollow_importskeys. No workflow consumed them; the three config fields are read directly by their subcommands.New
github-housekeepingskill backfills and curates labels and milestones across a repositoryβs full issue and PR history: taxonomy design, cache-backed bulk classification with review gates, AI-slop detection from closed-without-comment signals, and milestone assignment by changelog, git-tag, and release-date archaeology.New
pack-binariescommand materializes the versionless binary aliases and prints the release upload list, replacing the release engineβs shell loop: the asset naming convention now has one Python definition, shared with the install-guide freeze.New
--default-branchoption on thechangelogcommand, so a repository whose default branch is notmaingets a comparison URL that round-trips through the release freeze.initno longer writes the release lane (changelog.md,changelog.yaml,release.yaml, the PyPI publish action) into a uv virtual project ([tool.uv] package = false). Dependency locking, coverage and test tooling still apply.initnow lists eachawesome-templatefile it writes instead of one summary line, andinit labelsno longer reports its regenerated files as unmodified configs to clean up.Rename the Claude Code plugin release asset to
repomatic-claude-plugin.zip, asrepomatic-plugin.zipread as a plugin for repomatic./plugin installis unaffected.Attestation bundles are now named after the asset they cover (
repomatic-manpages.attestation.json) rather than the job that produced them, so the eight binary bundles no longer overwrite each other down to a single file.The VirusTotal detections chart now pins its CDN script with a Subresource Integrity digest, so a tampered copy is refused by the browser.
sync-workflow-pinsnow splices the--exclude-newer-packagecooldown exemption beside the inlinerepomatic==X.Y.Zpin it realigns, in the single spelling the release freeze writes and the post-release unfreeze recognizes.The changelogβs
[!CAUTION]admonition for a yanked release now quotes the reason PyPI recorded for the yank, when there is one.Changelog links are discovered under any capitalization of the PyPI
project_urlskey, matching how source URLs were already resolved.PyPI release lookups order same-day publications by PEP 440, so
1.10.0is no longer ranked below1.9.0.Dependency-update PR bodies omit the version comparison link when the upstream repository publishes no matching tags, instead of linking to a 404.
format-imagesnow installs and verifies itsoxipngbinary once per run instead of once per optimized image.Registry binary downloads and
update-checksumsnow carry a stall timeout, andupdate-checksumsrejects truncated bodies instead of recording their digest as the new canonical checksum.GitHub token validation now times out instead of hanging forever when the API is unreachable.
The
zsh_filesmetadata key now lists only shell scripts whose shebang names zsh, so a bash.shfile is no longer linted as Zsh.repomatic metadatano longer aborts on a src-layout project: a Nuitka entry point with no module file at the repository root is skipped with a warning.lint-reponow reports an unreadable rulesets API as a skipped branch-protection check rather than a failed one.The broken-links issue no longer claims broken links when lychee itself failed to run.
The release freeze now warns when it finds no changelog section for the version being released, instead of silently doing nothing.
lint-changelog --fixnow exits non-zero when it could not repair every problem it reported, instead of reporting success as soon as any one fix landed.lint-changelog --fixno longer stamps an undatable orphaned version with a0000-00-00placeholder date, and files a datable one in order even when every existing heading is a.devNdevelopment section.sync-uv-lockparsesuv.lockonce per phase instead of once per lookup, cutting several hundred milliseconds off each run.Fix downstream tool caches frozen at their first write: the reusable workflowsβ cache keys hashed a file that only exists upstream. Keys now rotate with the reusable workflowβs own commit SHA.
Fix
initmisreading a thin callerβs trailing comment or odd-indented job line as extra downstream jobs, which silently flipped the file onto the explicit-permissions contract or duplicated the managed jobβs tail below the regenerated lanes.Fix
initmishandling a consumerβs extra release jobs: the extraneeds:edges declared on thereleaselane were dropped, and a blank line accumulated above the jobs on every sync.Fix
init --output-dirscanning the current directory for unmodified configs, which made--delete-unmodifiedact on the wrong tree.Fix the generated
release.yamlemitting a bareneeds:(which GitHub rejects at startup) when every canonical edge is filtered out.Fix a
[tool.repomatic.workflow] pathsoverride emitting entries like**/*.pyunquoted when the canonical block held no quoted entry to copy, which parsed as a YAML alias and left the workflow silently ignored.Fix
repomatic metadatacrashing on a repository carrying a tag the version parser refuses, likev1.2.3_hotfix.Fix
sync-action-pinsandsync-workflow-pinssilently reverting each otherβs edits when onesync-depsrun bumps both kinds of pin in the same workflow file.Fix a mid-resolve failure of
sync-uv-lockleaving synced policy pins beside a stale lockfile for the CI job to commit: the project is now restored to its pre-run state on any error.Fix
sync-mailmapcrashing withUnboundLocalErroron a repository that has no.mailmapyet, the exact bootstrap its default--create-if-missingadvertises.Fix the sponsor labeller treating an empty
pull_requestevent payload as a pull request.Fix issue-filing jobs failing to record a new issue when
ghprints a notice above the issue URL.Fix
update-dep-graphfailing on Windows when a dependencyβs SBOM metadata contains non-ASCII characters.Fix
cache cleanscoping:--namespaceno longer wipes binaries and tool configs,--toolno longer wipes HTTP responses, and--max-agenow applies to cached configs instead of deleting them all.Fix
repomatic run mypyaborting withUnable to find lockfilein a repository without auv.lock: the tool now runs in an isolated, cooldown-gated environment when there is no lockfile to freeze.Fix binary tools executing a just-deleted staging copy when the cache write is lost (Docker overlay runners) or the cache root is unwritable: the fallback copy now survives for the whole process.
Fix the published plugin manifest declaring the post-release
.devNversion rather than the release it ships with.Fix image optimization leaving a
.bakfile in the working tree when interrupted.
7.6.0 (2026-08-08)ΒΆ
Note
7.6.0 is available on π PyPI and π GitHub.
Breaking: the
labelscomponent is now ephemeral:labels.tomland the two labeller YAMLs are staged only when named explicitly (repomatic init labels). A repository that committed them sees them reported as excluded files on disk, removable withinit --delete-excluded.New
fix-awesome-toccommand deletes the table-of-contents entries awesome-lint forbids fromreadme.mdand everyreadme.{lang}.mdbeside it, matching translated sections by position rather than by their English name.The bundled skills and agents are now published as a Claude Code plugin:
/plugin marketplace add kdeldycke/repomaticthen/plugin install repomatic@kdeldycke. Needs Claude Code 2.1.224 or later. Addresses #2378.New
pack-plugincommand builds the attestedrepomatic-plugin.zipasset every GitHub release now carries, with the marketplace URL pinned to the release tag.New
init plugincomponent merges the pluginβs marketplace and enablement keys into a repositoryβs.claude/settings.json, leaving every other setting untouched. New[tool.repomatic] settings.locationmoves the destination.lint-reponow checks a repositoryβs ownpr-body --template-filetemplates: they belong in.github/pr-templates/, must exist, and must carry atitleand a barefooter: false.A failed
extra-assetsjob now leaves the GitHub release as a draft instead of publishing it without the declared assets. A skipped job still publishes, so repositories declaring no extra assets are unaffected.sync-labelsnow exports to a scratch directory instead of the repository root, so it no longer leaves three untracked files behind. Both committed and downloadedextra-labels/files are applied, a download shadowing a committed file of the same name.The generated downstream
release.yamlnow carries the canonical deny-by-defaultpermissions: {}, so a consumer job appended below the managed lanes no longer runs with the repositoryβs default token scopes.The generated
release.yamlkeeps the extraneeds:edges a consumer declares on itsreleaselane, so a caller-side asset build can gate the engine. Edges naming a managed lane, a vanished job, or an upstream-only job are still dropped.Fix
initdowngrading the upstreamuses:pins of a repository that adopted a release still inside theminimum-release-agewindow. The cooldown now gates adoptions only, and a rollback to an older repomatic is honored.initno longer closes with βcommit the generated files and pushβ on a run that produced nothing but ephemeral output.Fix the broken-links and setup-guide jobs dying on a recurring issue that the
autolockworkflow had locked. A conversation lock blocking a close or reopen comment is now cleared and the write retried.Fix
repomatic runfinding no binary on a Linux distributionextra-platformscannot name, which broke every registry tool inside the AlmaLinux-based manylinux build container.Fix a crash when
pyproject.tomlis removed while being read, which now falls back to an empty configuration as documented.Re-lock
uv.lockin the release freeze commit, so a release no longer ships with its version ahead of its own lock entry. The desync made the Windows binary builds fail.
7.5.0 (2026-08-07)ΒΆ
Note
7.5.0 is available on π PyPI and π GitHub.
Breaking: bundled skills drop
modelanddisable-model-invocation, so every skill is now model-invocable and runs on the session model. The recommended model moved to the specβscompatibilityfield.Breaking: workflows now run the CLI from
uv.lockwithuv run --frozeninstead ofuvx --from ., so installs are hash-verified. The release freeze still pins downstream touvx 'repomatic==X.Y.Z'.minimum-release-agenow defaults to1 week(was8 days) and[tool.uv] exclude-newertracks it, closing the band whereuv.lockcould pin a version CI then refused to install.Reject a dependency floor naming a release still inside the cooldown window, which would ship a package that downstream repos and
uvxusers cannot resolve.Fix the
sync-*updaters adopting a release published on the cutoff day itself, which uv then refused to resolve because it applies the window to the hour rather than the day.sync-workflow-pinsnow warns when a pin already in the tree sits inside the cooldown, instead of only judging the version it is about to write.A
lint-repocheck that cannot read its GitHub API response now reports one βcould not query APIβ outcome instead of separate unreachable-API and unparsable-JSON messages.Fix
prepare-releaseandsync-github-releasesreading./changelog.mdinstead of the configuredchangelog.location.Fix a PR body templateβs
footer: falsebeing ignored, appending the attribution footer to a template that opted out of it.Fix template and skill frontmatter truncating at a value that embeds
---, dropping every field below it.Trim the hand-maintained example dumps from
metadataβs module andnuitka_matrixdocstrings, which had drifted from the values they claimed to show.Fix docstrings where a brace placeholder against a closing backtick rendered as a spurious role, swallowing the prose after it.
Every workflow now gates package installs behind the
minimum-release-agecooldown, so nouvx,uv pip install,npm installornpxresolves a release published inside the window.A thin caller carrying extra downstream jobs now gets a top-level
permissions: {}, and on its managed job the union of the scopes the reusable workflowβs jobs declare. Callers with no extra jobs are untouched.astral-sh/setup-uvsteps now pin the uv version, bumped bysync-workflow-pinsonce a release clears the cooldown, instead of installing the newest build satisfyingrequired-version.repomatic run mdformatprovisions its ownshfmtat the registry-pinned version, so formatting shell blocks in Markdown no longer needs a systemshfmt.New
path_toolsfield on a tool spec, naming registry tools whose binary must be onPATHwhile it runs.Fix
repomatic run mdformataborting on Windows ARM64, whereshfmtpublishes no binary: a companion missing for the platform is now skipped with a warning.Fix the macOS binary builds, which crashed in code signing once skills joined the bundled data: an
--include-data-dirsource holding symlinks is now staged symlink-free. Reported upstream as Nuitka/Nuitka#3994.The
format-markdownjob drops back to the leanubuntu-slimrunner, and its awesome-list fixup usessedinstead ofgawk.apt-getreplacesaptin every workflow step, with--no-install-recommendsthroughout.Add
ghto therepomatic runregistry. The release engineβs attestation check now uses it instead of adding GitHubβs RPM repository to the build container and installing an unpinnedgh.A toolβs
strip_componentsaccepts a per-platform mapping, likearchive_formatalready did.Add
oxipngto therepomatic runregistry, bumped to10.1.1.format-imagesnow uses the pinned, checksum-verified build instead of a hand-fetched.debinstalled withdpkg.Dependency-updater reports now close on the
Held back by cooldownsection, belowCooldown bypasses, so a PR opens on what the run changed instead of what it left alone.sync-tool-versionsleavesautofix.yamlfor a new upstream-onlyself-maintenance.yaml, and polls daily instead of weekly. Downstreamautofix.yamlloses the four steps it could never run.sync-tool-versionsnow also bumps the packages pinned alongside a tool in itsuvxenvironment, like mdformatβs plugin set, reporting them like every other row.Fix
get_source_urlreturning a bug-tracker or changelog sub-path instead of the repository root, and matchingproject_urlskeys case-sensitively.The bundled ruff config sets
output-prefer-rule-codes, so diagnostics reportISC004instead ofimplicit-string-concatenation-in-collection-literal. Requires ruff0.16.1.repomatic initholds the derived upstream workflow pin back to the newest release past theminimum-release-agecooldown;--no-cooldownpins the running version immediately.Commands honoring
--outputnow log their destination uniformly, always naming what is written instead of mixingSave updated results toand a subject-lessWrite to.Align bundled skills with the Agent Skills specification:
babysit-cigains its requirednamefield, andallowed-toolsmoves to the specβs space-separated form.Skills are now installed as whole folders, so one can ship the specβs optional
scripts/,references/andassets/directories alongside itsSKILL.md.Add
[tool.repomatic.flavor]withagentandcikeys, declaring the ecosystems a repository targets. Values are extra-platforms trait IDs.[tool.repomatic.labels.extra]entries now carrylabelmakerβs full per-label specification, addingrename-fromin-place renames, multi-color lists, and thecreate,update,enforce-caseandon-rename-clashknobs. An unknown field now warns instead of being dropped silently.New
release-assetsfilename list in[tool.repomatic]: each named asset is built by a caller-side job, attested like the compiled binaries, and attached to the release draft before publication locks it.The man-page tarball is now attested like the compiled binaries, with its sigstore bundle attached as a
manpages.attestation.jsonrelease asset.skills.locationandagents.locationnow default to the layout of the configuredflavor.agent, and still win when set explicitly.repomatic run mdformatdrops themdformat-ruffplugin and its separate ruff pin, and the bundled ruff config dropsextend-include: ruff formats fenced Python blocks in Markdown on its own.Teach the
repomatic-shipandbabysit-ciskills to act on the first failing CI job instead of waiting out full matrices, pay down pre-existing andβοΈ-probe test debt before the first push, and hold prose-only pushes while binary matrices drain.Chart the
/repomatic-shipconvergence loop (first-failing-job fixes, push timing, debt paydown) on the skills docs page.Re-base the release PR onto the current
mainHEAD after every build by also runningprepare-releaseonworkflow_run, so a reconciliation commit that misseschangelog.yamlβspaths:filter no longer leaves the PR stale./repomatic-topicspre-approves theAgenttool instead of the retiredTaskname.Add a
historydocumentation page retracing the project from its 2021 reusable-workflow origins through thegha-utilsCLI to therepomaticrename.Recenter the readme and the workflows page on the CLI-first design: workflows only trigger CLI commands, with local-run examples and links to the standalone binaries and history pages.
Document Agent Skills spec conformance, and
argument-hintas the single accepted deviation, on the skills documentation page.Correct the readme and benchmark page: both carried stale reusable-workflow counts, and listed
jpegoptimamong the toolsrepomatic runmanages when it never was.
7.4.1 (2026-08-01)ΒΆ
Note
7.4.1 is available on π PyPI and π GitHub.
Add two review links to the release PRβs
How-to releasechecklist: the draft dev pre-release and the full changes againstmain.Teach the
repomatic-shippre-push gate to read the latest conclusive ancestor CI run when HEADβs own runs are still in-flight, catching a pre-existing platform-gated failure before the first push.Lower the uv
required-versionfloor from>=0.12to>=0.11.15, the actual resolver minimum.Extend the
uvxscript-equals-package guard to thepipx run <script>install check, soπ¦ Package installno longer fails permanently for projects whose CLI script differs from their package name.
7.4.0 (2026-07-31)ΒΆ
Note
7.4.0 is available on π PyPI and π GitHub.
Breaking: Rename
update-deps-graphtoupdate-dep-graphacross the CLI command, autofix job, PR branch, and body template, aligning with thedependency-graphconfig key. Close any openupdate-deps-graphpull request; the next run reopens it on the new branch.Breaking:
repomatic initcomponent selectors are now case-sensitive, validated by the same code path as theexcludeandincludeconfiguration entries.Lower the compiled-binary OS floors: Linux glibc
2.28, built and self-tested inmanylinux_2_28containers (RHEL 8, Debian 10, Ubuntu 20.04 and later), and macOS11.0(Apple silicon) /10.15(Intel) via uvβs embedded python-build-standalone interpreter.Enforce each binaryβs OS floor at build time:
verify-binaryparses ELF, Mach-O and PE headers natively and no longer needs exiftool.Keep
tkinterand its Tcl/Tk stack out of compiled binaries via the new[tool.repomatic]nuitka.nofollow-importssetting (default["tkinter"], set to[]to bundle it).Emit man pages for repomaticβs own CLI on docs builds and attach a
repomatic-manpages.tar.gzasset to each release.Add
update-docs --checkto report out-of-date self-updating content and exit non-zero without writing, for CI drift detection. The docs update script must accept its own--checkflag to participate.Add a
check_sha_pinning_requiredlint check and setup-guide step for GitHubβssha_pinning_requiredActions setting, the platform-enforced backstop for action SHA pinning.Unify the
lint-repochecks on one tri-state result protocol: skipped checks now printβΉinstead of a misleadingβ.Key the CI tool-binary caches on
tool_registry.pyinstead of the whole runner module, so engine-only changes stop invalidating cached tools.Report
sync-depsandupdate-checksumsprogress as aβ/βtrail with a running tally and a timed summary.Warn about unknown
[tool.repomatic]keys once per project and process, instead of on every configuration re-load.Loosen the uv
required-versionpin to a lower bound (>=0.12), dropping the per-minor upper cap so uv can update across minors without a manual bump.Move the docs link checker from
ubuntu-slimtoubuntu-24.04-arm: the crawl outgrew the slim runnerβs 15-minute job cap.Extend the bundled lychee configuration with generic excludes: GitHub issue-comment fragments, release binary downloads, and DOI-to-Zenodo redirects.
Declare least-privilege permissions on the canonical
release.yaml, clearing the workflowcheck_workflow_permissionslint.Extend the
check_workflow_permissionslint to flag a reusable-workflow call inheriting an empty top-levelpermissions: {}without its own grants: the misconfiguration that aborts a run at startup.Block install-time scripts and apply the
minimum-release-agecooldown on every npm install ofawesome-lint, hardening both the runtime and CI-provisioning paths against supply-chain attacks.Surface
uv auditβs stderr when it exits without emitting JSON, replacing the bareproduced no outputerror.Keep
metadatafrom crashing when git refuses the repository (dubious ownership, unresolvable range): it now logs gitβs stderr and continues.Accept
sur(macOS Big Sur, Homebrewβsbig_surbottle tag) as a valid word in the bundled typos configuration, sofix-typosstops correcting it tosure.Document the minimum OS requirement of each binary target, and the distributions it opens execution to, in a new Minimum OS requirements section that downstream binaries pages link to.
Document how to verify a downloaded binaryβs build-provenance attestation with
gh attestation verifyon the installation page.Order the installation docsβ Python-compatibility table newest-first, so the latest release and Python version read from the upper-left.
Rename the binaries page chart markers to
binaries-chart/binaries-chart-end, aligning on click-extraβs<!-- name --> / <!-- name-end -->marker grammar; pages carrying older markers are migrated on their next refresh.Fix the click-extra
{matrix}directive link on the installation page, and realign page octicons with thesphinx-docsagentβs extended icon registry.Emit an absolute
og:imageURL for social previews:ogp_site_urlnow backsogp_imagein the docs configuration.Pin the install guideβs versioned CLI examples (
pkg@X.Y.Z,pkg==X.Y.Z) to the release in the prepare-release freeze step.Direct the
babysit-ciskill to announce its early exit and name the still-unverifiedrelease.yamlbinary run, instead of stopping on a silent idle.Harden the
repomatic-shipskill: forbid detachedMonitorpolling, read the whole unreleased changelog section at invocation, and align every convention description its docs pass corrects.Extend the
sphinx-docsagent andsphinx-docs-syncskill: the{click:run}--versiontrap, thin-schema combined CLI page, Cloudflare-blocked intersphinx probes, mdformat seed-block collapse, plus release-asset, self-healing-marker, and linkcheck audit guards.Note in the
repomatic-shipskill that changelog released sections are immutable, and that a workflow cache-key line-length fix cannot lifthashFiles()into a workflow-levelenv:.
7.3.1 (2026-07-28)ΒΆ
Note
7.3.1 is available on π PyPI and π GitHub.
Refresh the bundled pytest defaults to the canonical configuration:
importlibimport mode,tests/-restricted collection, theoncemarker, parallel runs viapytest-xdist, and--cov-report=xmlleft to the test workflowβs command line.Mark the
validate-archjob oftests.yamlas canonical-repository-only: downstream repos drop the job and itsbuild_targetsmetadata field when adapting the workflow.Point the
lint-changelognot found on PyPIwarning at its remedy: list intentionally-unpublished releases under[tool.repomatic] abandoned-versions.Fix the post-release re-trigger of
changelog.yaml: itsworkflow_runfilter still watched the pre-emojiBuild & releaseworkflow name and never fired.Fix
lint-changelog --fixtreating a published pre-release (X.Y.Z.dev0,rc,alpha,beta) as a missing changelog entry, which inserted a spurious section and rewrote the adjacent releaseβs comparison URL.Fix the
update-docsautofix job opening a duplicate of theformat-pyprojectpull request: it now reformatspyproject.tomlonly whenupdate-docschanged it.Skip the bare
uvx <script>invocation of the package-install smoke job when the CLI script is not named after its package.Restructure the
repomatic-shipskill: rules shared by every spawned agent move to a single section, and accumulated incident notes compress into their operative rules.Harden the
repomatic-shiprelease checks: dispatchrelease.yamlpast a content-skipped binary matrix, revert formatter moves whole, read the freeze scope from the regenerated release PR, and verify{click:run}blocks against the live CLI.Direct the
repomatic-shipdocs pass to advance version samples lagging the released tag up to it.Note in the
repomatic-shipandbabysit-ciskills that CI log fetches write under~/.cache/ghand need the sandbox off.
7.3.0 (2026-07-23)ΒΆ
Note
7.3.0 is available on π PyPI and π GitHub.
Breaking: Move the MyST docstring toolchain upstream to click-extra, now floored at
8.5: therepomatic.myst_docstringsSphinx extension becomesclick_extra.sphinx.myst_docstrings(pointconf.pyat the new module path), and theconvert-to-mystcommand becomesclick-extra convert-to-myst.Warn on unknown
[tool.repomatic]keys through click-extraβs schema layer, covering nested tables too; the warning now names keys in snake_case.Upload each release binary under a versionless alias, so the stable
releases/latest/downloadURLs keep resolving across releases.Mark the upstream toolkitβs lockstep-aligned pin with a
βοΈ lockstepdocs link in thesync-workflow-pinsPR table, instead of an emptyReleasedcell.Add a βοΈ emoji to the
Configurationsection heading of PR bodies, and swap theHeld back by cooldownsectionβs π emoji for βΈοΈ.Disable ruffβs
unsafe-fixesin the bundled defaults, so--fixand the autofix workflow only apply semantics-preserving fixes.Expose
GITHUB_TOKENto the Sphinx linkcheck step of the docs workflow, so a repoβsconf.pycan authenticate its github.com checks vialinkcheck_request_headers.Space out the Windows exiftool install with step-level retries, absorbing Chocolatey community-feed outages that punch through chocoβs own
--retry-count.Fix the
excludeandincludeconfiguration reference to listagentsamong the default-excluded components.Exclude
once-marked tests from every test-matrix cell and run them in a dedicated single-runneronce-testsjob with its own coverage upload.Teach the
repomatic-shipandbabysit-ciskills that the Nuitka binary matrix only exists on projects enabling[tool.repomatic] nuitka.enabled, and how to verify binary-less releases.Fix the
repomatic-shiplocal-gate tool recipes: passbiomeandshfmttheir args forms, and smoke checksum-pinned tools with no matching files via--versiononly.Broaden the
repomatic-shipreview scopes: version samples are audited against the last freeze commitβs file list, and platform-gated tests are reviewed with the inputs they consume.Require the
repomatic-shipsweep agents to message their final reports to the orchestrator, with one chase on a silent idle.Point the changelog over-length warning and the
repomatic-changelogskill at the canonical entry-length guideline URL, which downstreamCLAUDE.mdcopies lack.
7.2.0 (2026-07-16)ΒΆ
Note
7.2.0 is available on π PyPI and π GitHub.
Breaking: the
release-prepcommand is renamedprepare-release, matching the job, template, and PR branch it drives.Breaking: the
version-checkcommand is renamedcheck-version.Add
cancel-runs: cancels a branchβs in-progress and queued workflow runs, replacing the bash block incancel-runs.yaml; run listings now paginate past the first page.Add
[tool.repomatic] binaries.sync: set tofalseto stop the release pipeline from committing the binaries catalog and scan records to the default branch.Add
sync-dep-sources, a fifthsync-depsupdater: once the release named by a git-tracked dependencyβs.devfloor ships on PyPI, it drops the[tool.uv.sources]override, tightens the floor, and freezes the adopted release through the cooldown. Disable with[tool.repomatic] dep-sources.sync.Dialect,ArchiveFormat, andWorkflowFormatnow carry their dispatch as enum methods (serialize,extract,write_workflow).Rename cross-module internals to public names:
COMPONENTS_BY_NAME,is_source_repo,format_released,format_upload_date,date_to_utc_cutoff.The
sponsor-labellerjob inlabels.yamlis renamedsponsor-label, matching the CLI command it runs.Remove the dead
get_default_repoandlist_open_issueshelpers and the unusedREQUIRED_PAT_PERMISSIONSconstant.update-deps-graphnow keeps only directly-declared dependencies inside the--groupand--extraboxes, renders transitive dependencies as plain ovals, and counts an extraβs transitives as depth 2 under--level.The unsubscribe workflowβs GraphQL phase now re-validates each itemβs staleness client-side and reports the items it holds back.
The
unsubscribe.yamlworkflow now streams per-thread progress to the job log.Generated PR and issue bodies now use
##section headings, withRelease notesnested as a###subsection; release bodies embedded in dropdowns get their headings demoted below the per-version heading.Generated PR bodies drop the boilerplate
Descriptionsection, and theWorkflow metadatablock becomes a compact list led by aDocumentationlink to the jobβs section of the workflows reference.The
Cooldown bypassesPR section is now a single table:π§Ή cleared:,π frozen:, andπ§ unreleased:rows with aHeld untilexpiry column.Diff tables label added and removed packages with
π new:andποΈ removed:prefixes ahead of the version.sync-action-pinsandsync-workflow-pinsPR bodies now report an action or package pinned at several versions as a single row spanning from the oldest pin.The
update-docsjob now re-formatspyproject.tomlfiles withpyproject-fmtafter running the projectβs update script.GitHub Releases API reads now resolve their token like every other GitHub access (
REPOMATIC_PATfirst), instead of hitting the anonymous rate limit.PyPI, npm, and GitHub API lookups now retry once on a truncated response instead of crashing with
IncompleteRead.The release freeze and unfreeze steps now cover
.ymlworkflow files alongside.yaml.The gitignore.io template download now times out after 10 seconds instead of hanging on a stalled connection.
Version bumps no longer overwrite the
cff-version:schema field incitation.cffwhen it coincides with the package version.sync-action-pinsno longer rewritesuses:pins inside filesrepomatic initdeploys verbatim, like thepublish-pypicomposite action.The
run typosguidance now recommendsextend-ignore-reguards for encoded hashes and intentional-typo examples.Document the scan job contract and the release-lane direct-commit exception.
7.1.0 (2026-07-08)ΒΆ
Note
7.1.0 is available on π PyPI and π GitHub.
Breaking:
scan-virustotalno longer writes scan tables into GitHub release notes; the--update-releaseand--repooptions are removed, and--binaries-diris now required.Add
sync-binaries: regeneratesdocs/assets/binaries.csvand itsdocs/binaries.mdpage, a catalog of every released binary with download links, VirusTotal analyses, and a detection trend chart.sync-binaries --backfill-recordsrecovers detection snapshots from the VirusTotal tables of legacy release notes into the scan history file.The release pipeline now records each binaryβs
flagged / totalsnapshot indocs/assets/virustotal-scans.jsonand refreshes the binaries page instead of editing release notes.The documentation build gains
sphinx-datatables, rendering the binaries catalog as a searchable, sortable table; downstream repos can opt in with the same extension.Add
git-commit-push: commits files and pushes them, rebasing and retrying on rejection, for release jobs publishing generated files to the default branch.Add a global
--jobsoption controlling how many parallel workers commands may use, defaulting to one fewer than the hostβs logical CPUs.update-checksums,sync-tool-versions, andsync-depsnow download artifacts and resolve updates concurrently, sized by--jobs; Ctrl+C aborts the fan-out promptly and--verbosity DEBUGcollapses it to sequential.sync-uv-lockPR bodies gain aCooldown bypassessection: each activeexclude-newer-packagefreeze with the date it expires and is cleared frompyproject.toml, plus the entries the run froze or pruned.The
Held back by cooldowntable now also lists releases blocked by anexclude-newer-packagefreeze, not only those inside the globalexclude-newerwindow.update-docsgains a fourth phase refreshing self-updating{matrix}directive blocks indocs/andreadme.md; the Python compatibility matrix in the installation docs now renders from those markers instead of an in-repo generator.The CLI, configuration, and tool-runner references in the docs render live through the
click:tree,click:config, and{python:render}directives; the checked-in generated tables anddocs/docs_update.pyare removed.Each tool section in the tool-runner reference shows Stars and Last release badges; the separate
Comparisontable is removed.Require
click-extra >= 8.3, adding the--export-configoption,--theme autoterminal-background detection, and theclick:configSphinx directive.Label added and removed packages in dependency report tables consistently after the version, with π and ποΈ status emoji.
sync-workflow-pinsnow aligns the inlinerepomaticpin to the newestuses:ref version, bypassing the release-age cooldown.sync-action-pinsnow converges actions pinned at several versions onto the highest pin, even when no newer release clears the cooldown.Trim oversized PR and issue bodies to GitHubβs 65536-character limit, preserving the refresh tip, metadata block, and attribution footer.
Add the humanized age next to
Releaseddates infix-vulnerable-depsreports, matching the other dependency updaters.update-deps-graphnow places a package declared by several groups or extras in the box where most of its dependents live, drawing the duplicates with a dashed border and a dotted identity link to the real node.The setup guide and
lint-reponow flag a missingREPOMATIC_NOTIFICATIONS_PATsecret whennotification.unsubscribeis enabled.Exclude VirusTotal analysis links from lychee broken-link checks.
Update the
av-false-positiveskill to start from the scan history file and to record post-submission re-scans into it.The
babysit-ciandrepomatic-shipskills now mandate sleeps between CI polls and document GitHub API rate-limit exhaustion, whose symptoms masquerade as PAT permission errors.Fix
sync-uv-lockreportingNo dependency changesand writing no PR body when a run only prunes or freezes cooldown bypasses inpyproject.toml.Fix downstream manual dispatches of the
unsubscribeworkflow ignoring their inputs and always running live: generated thin callers now forwardworkflow_dispatchinputs to the reusable workflow.The
publish-pypicomposite action and theunsubscribeworkflow no longer trigger setup-uvβs cache-invalidation andEmpty workdir detectedwarnings on downstream runs, which execute without a checkout.The PR-creation steps of the changelog workflow now time out after 10 minutes instead of hanging when the GitHub API is rate-limit starved.
Fix the binary cache purging fresh entries whose release archive carries an old build date: cached binaries are now aged by their store time, not the archiveβs mtime.
repomatic runnow reports a truncated tool download asgot X of Y bytesinstead of a SHA-256 mismatch, which read as a stale checksum or a tampered artifact.Rebuild binaries on pushes that only touch
.github/workflows/_release-engine.yaml: the release workflow split left the engine lane outside the binary-affecting paths.Disable mouse zoom on the class inheritance diagrams of the documentationβs API sections, so they no longer hijack page scrolling; the fullscreen viewer keeps zoom.
7.0.0 (2026-07-02)ΒΆ
Note
7.0.0 is available on π PyPI and π GitHub.
Breaking: Remove the Renovate integration: the
renovate.yamlworkflow, the bundledrenovate.json5, thecheck-renovatecommand, and the Dependabot-to-Renovate migration are gone, replaced by self-hosted dependency updates (below). Downstream repos prune the orphaned files on their nextrepomatic init.Breaking:
repomatic update-checksumsis now registry-only: the workflow-file argument and the--registryflag are removed, so it only refreshes the binary tool checksums.Add
sync-deps, the single entry point for dependency updates: runs every enabled updater or a named subset in parallel and applies them in order, with a--dry-runpreview.Add
sync-tool-versions: bumps eachrepomatic runtool to its latest release past the cooldown and refreshes the binary tool checksums in the same pass.Add
sync-action-pins: bumps SHA-pinned GitHub Actions to their latest release past the cooldown, resolving each release tag to its commit SHA.Add
sync-workflow-pins: bumps the npm and PyPI version literals embedded in workflow YAML past the cooldown.Add
[tool.repomatic] minimum-release-age(default8 days), the shared stabilization cooldown for the sync updaters, plus per-updatertool-versions.sync,action-pins.sync, andworkflow-pins.synctoggles.repomatic runnow runs npm-backed tools, starting withawesome-lint, installed from the npm registry with per-tarball integrity and theminimum-release-agecooldown; thelint-awesomejob now callsrepomatic run awesome-lint.Add a
[tool.repomatic] changelog.archive-locationoption pointing at an archive file for older release sections, solint-changelogtreats archived versions as documented instead of flagging them as orphans.Dependency-updater PR bodies now share
sync-uv-lockβs format: a cooldown cutoff date, aHeld back by cooldownsection, and aRelease notesdropdown between them.repomatic runnow applies theminimum-release-agecooldown to the transitive dependencies of itsuvx-installed tools; binary anduv runtools stay pinned as before.The autofix workflow now runs the dependency updaters weekly on a schedule, so quiet repositories still pick up dependency, tool, and action-pin updates.
REPOMATIC_PATno longer requires theCommit statusespermission;lint-reponow warns when a token still grants it so it can be tightened.Drop the
pydrillerdependency: Git history operations now invoke thegitCLI directly, shrinking the install and compiled-binary footprint.repomatic runnow animates a spinner while downloading a tool whose server omits aContent-Length, where it previously showed nothing.The generated Python compatibility matrix in
install.mdnow covers pre-classifier releases, falling back torequires-python, Poetry, orsetup.pymetadata to infer supported versions.Fix
update-deps-graphrendering only one of several extras or dependency groups that share a directly-declared dependency; each now gets its own subgraph.Fix broken documentation links: the standalone-binary downloads (versionless 404s), the
pipxinstallation guide, and the GitHub matrix-strategy reference.
6.31.0 (2026-06-27)ΒΆ
Note
6.31.0 is available on π PyPI and π GitHub.
sync-uv-lockPRs now list newer releases held back by theexclude-newercooldown, with the date each ages out of the window.sync-uv-lockpackage tables now annotate each release date with a relative hint (2 days ago,in 3 days).Autofix PR bodies now document every relevant
[tool.repomatic]option in their Configuration section.The test workflow uploads coverage to Codecov from one runner per OS, not from every matrix cell.
Drop the Codecov Test Analytics (test results) upload and the
junit.xmlfile it generated.update-checksums --registrynow maintains binary tool checksums in a dedicatedrepomatic/tool_checksums.pymodule.Update
pyproject-fmtto2.25.1, which keeps comments inside inline tables whenformat-pyprojectreorders their keys.Fix the PyPI availability admonition missing from GitHub release notes.
Fix
repomatic run biomefailing with a SHA-256 mismatch: Biome2.5.0βs binary checksums were stale, breaking JSON, JavaScript, and TypeScript format jobs.Fix
[tool.repomatic] workflow.sync = falsebeing ignored: it now skips workflow sync like the other*.synctoggles.
6.30.0 (2026-06-24)ΒΆ
Note
6.30.0 is available on π PyPI and π GitHub.
Breaking: The test and release workflows now run
click-extra test-suite(thetest-planengine renamed in click-extra8.1), reading the suite from./tests/cli-test-suite.toml. Requiresclick-extra >= 8.1.repomatic lint-reponow fails when a workflowβs inlinerepomatic==X.Y.Zpin lags the version of itsuses:ref.The test workflow skips the Codecov upload on free-threaded Python (
3.14t), where codecov-cli cannot build itstest-results-parserextension.In generated dependency graphs, thick arrows now mark only the root packageβs direct dependencies; a transitive edge that points at a primary dependency stays thin, so optional extras no longer read as a primary dependency chain.
The release workflow now cancels superseded runs on rapid non-release pushes to
main, so intermediate commits no longer pile up redundant binary builds; release commits still run to completion.
6.29.0 (2026-06-22)ΒΆ
Note
6.29.0 is available on π PyPI and π GitHub.
Breaking: Remove the
repomatic test-plancommand and[tool.repomatic] test-planconfig. The declarative test-plan engine moved upstream to click-extra; runclick-extra test-planinstead, configured via[tool.click-extra.test-plan].Add
repomatic show-test-matrixto render the CI test matrix as a Python-version by OS grid in any--table-format.Add
repomatic init uvto sync the canonical[tool.uv]pins (required-version,exclude-newer) intopyproject.toml;sync-uv-lockapplies the same sync, so every machine resolvesuv.lockwith the same uv.Require
click-extra >= 8; themanpagesrelease job now usesclick-extra wrap --manto generate man pages.The binary download progress bar now respects
--no-progressand--accessible, hiding it when progress output is turned off.Move the Sphinx linkcheck output to
docs/_linkcheck/(mirroringdocs/_build/);broken-links --output-jsonnow defaults there and the generated.gitignoreexcludes it.repomatic runnow warns when--checktargets a post-processed formatter (currentlymdformat): check mode bypasses the fixup, so its exit status can mislead.sync-uv-locknow reverts a re-lock that changed no package versions, so uvβs machine-dependent re-spelling of equivalentuv.lockenvironment markers no longer opens empty sync PRs that ping-pong between contributors and CI.Documentation pages that cover a Python module now end with that moduleβs API reference.
Test the free-threaded
3.14tbuild as a stable single-runner smoke test instead of across the full cross-platform matrix;3.15stayscontinue-on-error.
6.28.1 (2026-06-19)ΒΆ
Note
6.28.1 is available on π PyPI and π GitHub.
Fix
test-matrix.full-includematrices emitting combinations thatexcludeshould have removed; they now follow GitHubβs documented include/exclude algorithm.
6.28.0 (2026-06-19)ΒΆ
Note
6.28.0 is available on π PyPI and π GitHub.
repomatic test-planruns its cases in parallel by default (one fewer than the CPU count); pass--jobs 1for sequential execution.Add
[tool.repomatic] test-matrix.full-includeconfig: declare full-matrix-only job rows as explicit combinations (each merged onto the shipped-config defaults), a readable alternative to a longtest-matrix.excludelist.Run the pull-request test matrix on
ubuntu-24.04-armfor faster Linux CI; the full test matrix still covers x86 Linux.repomatic metadatano longer prints spurious--overwriteor$GITHUB_OUTPUTwarnings when writing to stdout.Add a test-matrix guide to the docs: choosing matrix targets, a GitHub-runner speed inventory, and a worked example.
6.27.0 (2026-06-18)ΒΆ
Note
6.27.0 is available on π PyPI and π GitHub.
Breaking: Replace
fix-vulnerable-depswithaudit.repomatic auditreports vulnerable dependencies read-only;repomatic audit --fixperforms the previous upgrade behavior.Stop forcing
pyproject-fmttable expansion:project.urls,project.scripts, and similar sections now use its default compact (dotted-key) form.Recognize each bundled toolβs native config files more accurately (
biome,gitleaks,ruff,typos,zizmor, and others) and their config-file CLI flags.Preserve comments when materializing a
[tool.X]section frompyproject.tomlto a toolβs native TOML config file (like.gitleaks.toml), instead of dropping them.Update
pyproject-fmtto2.25.0, fixing theformat-pyprojectjob writing invalid TOML when it reformats[tool.repomatic.labels]rule tables.Align the bundled
[tool.bumpversion]and[tool.lychee]templates withpyproject-fmtβs canonical output, ending the reformatting pull-request loops they triggered.Fix cooldown bypasses (
[tool.uv] exclude-newer-package) never expiring:sync-uv-locknow freezes each one at its locked version instead of a latest-tracking"0 day"span, and prunes it once that version ages pastexclude-newer.Fix
uv.lockping-ponging on everysync-uv-lockrun:exclude-newer-packagefreezes are now explicit UTC timestamps, not bare dates that uv re-expands in the locking machineβs timezone.Fix the
repomatic.myst_docstringsSphinx extension corrupting two adjacent inline-code spans in a docstring when the second span starts with an underscore.Fix the
manpagesrelease job: attach the man-page tarball to the release draft before publishing, so it no longer fails under GitHub immutable releases.
6.26.0 (2026-06-17)ΒΆ
Note
6.26.0 is available on π PyPI and π GitHub.
Add
[tool.repomatic] nuitka.extrasconfig to sync listed[project.optional-dependencies]extras into the venv before the Nuitka build, so optional features land in the binary.Add
[tool.repomatic.labels]extra,file-rules, andcontent-rulesconfig for inline label definitions and labeller rules, replacing the silently-ignoredextra-file-rulesandextra-content-rulesfields.Stop version-bump PRs from upgrading dependencies: the bump and release jobs now run plain
uv lock, leaving dependency refreshes to thesync-uv-lockjob.Add a
[tool.repomatic] changelog.bullet-word-thresholdconfig:lint-changelogwarns (non-fatally) about unreleased changelog bullets longer than the threshold (40 words by default).
6.25.1 (2026-06-13)ΒΆ
Note
6.25.1 is available on π PyPI and π GitHub.
Fix
uvx repomatic@X.Y.Zfailing for end users withNo solution foundby dropping thebump-my-versiondependency and reading the current version natively from.bumpversion.tomlor[tool.bumpversion].Remove the
uv-overrides.txtfile and allUV_OVERRIDEworkflow env blocks.Render the Mermaid dependency graph in
docs/install.mdunder a newDefault dependenciessection.
6.25.0 (2026-06-13)ΒΆ
Note
6.25.0 is available on π PyPI and π GitHub.
Add man page generation to the release and docs pipelines via a
manpagesjob, activated by[tool.repomatic.manpages]config keys (script,asset-name); requiresclick-extra>=7.19.Validate
[project.scripts]entries when building the Nuitka matrix, rejecting path-shaped, empty, or malformed script names up front with a clear error.Replace the
tomlkitandtomlidependencies withtomlrtfor all TOML reads and comment-preserving writes.Annotate
ghand PAT permission check failures with the current githubstatus.com summary, and surface raw stderr on non-403 failures instead of misreporting missing scopes.Recognize friendly durations (
24 hours,30 minutes) and ISO 8601 durations (PT24H,P7D) in[tool.uv].exclude-newerwhen computing therepomatic sync-uv-lockcooldown.Fix
UV_OVERRIDEnot reaching Renovateβs child processes duringupdate-checksums.Add
[tool.repomatic] abandoned-versionstolint-changelog, reporting listed versions as skipped instead of warning that they are missing from PyPI.Tighten
/repomatic-shipβs pre-push gate withruff format --checkand arepomatic --versiondependency-resolution smoke run.
6.24.0 (2026-05-28)ΒΆ
Note
6.24.0 is available on π PyPI and π GitHub.
Publish to PyPI right after the wheel builds instead of waiting for the full release engine, by splitting the build into a
_release-build.yamllane thatrelease.yamlβspublish-pypijob depends on.
6.23.0 (2026-05-28)ΒΆ
Note
6.23.0 is available on π PyPI and π GitHub.
Split
release.yamlinto a thin entry workflow and a new reusable_release-engine.yamlengine; the entry keepspublish-pypiso PyPI Trusted Publisher OIDC resolves to each repoβs ownrelease.yaml.Remove the
release-publish-pypi-job.yamldata fragment;release.yamlis now the single source for thepublish-pypijob.Require
uv>=0.11.15for the vulnerability scan and parseuv audit --output-format jsondirectly, raising a clear error on unsupporteduvversions and deduplicating advisories across sources by alias.Refine
/repomatic-shipto re-consolidate the changelog after the babysit phase and re-dispatchchangelog.yamlafter a code-only fix push so the release PR stays current.Extend
/babysit-cito also monitorautofix.yaml, diagnosing and fixing crashed mechanical-fix jobs instead of leaving them red onmain.Fix
release.yamlβscompile-binariesandtest-binariesjobs aborting every non-release run withUnexpected value ''on projects withnuitka.enabled = false.
6.22.0 (2026-05-25)ΒΆ
Note
6.22.0 is available on π PyPI and π GitHub.
repomatic initnow prunes downstream orphans of renamed or removed skills, agents, and workflows; locally modified copies are reported for manual review, never deleted. Pass--keep-removedto report without deleting, or--delete-removed-modifiedto also delete modified ones./repomatic-shipnow closes with a reflect step that reviews the session for friction and proposes fixes to the upstreamrepomaticsource.Fix the downstream callerβs
publish-pypijob aborting every non-releaserelease.yamlrun withUnexpected value ''when itsstrategy.matrixis empty.Fix
/repomatic-shipand/babysit-cidropping theCo-Authored-By: Claudetrailer on their autonomous commits; both skills now require it self-containedly./babysit-cinow treats a workflow run that fails with no individual job failure as a real workflow-level error to investigate.Fix the documentation siteβs live CLI-help and example blocks rendering empty since
click-extra7.15.0 made execution directives opt-in.Seed each tool section in the tool-runner docs with a runnable
repomatic runexample and a minimal[tool.X]snippet.
6.21.0 (2026-05-25)ΒΆ
Note
6.21.0 is available on π PyPI and π GitHub.
Replace the
repomatic-releaseskill withrepomatic-ship, a release orchestrator that reconciles changelog, code, and docs, then commits, pushes, and babysits CI until the release PR is ready. Review-gated by default, fully autonomous under--dangerously-skip-permissions.Add a
modernizemode to therepomatic-depsskill that reads upgraded dependenciesβ changelogs and refactors code to adopt their new features, gating each change on the test suite.Extend the
babysit-ciskill to also monitor and triage the Nuitkacompile-binariesjob inrelease.yaml.Decouple the downstream callerβs
publish-pypijob from the runβs overall result: it now runs underalways()and gates on a newpackage_builtoutput, so a cleanly built wheel publishes even when an unrelated job fails.Remove the
repomatic-sync,repomatic-lint, andrepomatic-testskills, which only wrapped CLI commands CI already runs on every push.Fix the
bump-versionjob inchangelog.yamlleaving an orphan version-bump PR open after a competing bump merged intomain.Enable myst-parserβs
alertextension so GitHub-style alerts (> [!NOTE],> [!IMPORTANT]) render as admonitions on the documentation site.Give each tool section in the tool-runner docs a hand-maintained extra-docs region preserved across regenerations, seeded for Nuitka, and add Nuitka to the pageβs
[tool.X]-support table.
6.20.0 (2026-05-24)ΒΆ
Note
6.20.0 is available on π PyPI and π GitHub.
Breaking: remove
[tool.repomatic] nuitka.extra-args. Configure Nuitka flags through[tool.nuitka]inpyproject.tomlinstead (--include-data-files=SRC=DESTbecomesinclude-data-files = ["SRC=DEST"]).repomatic run nuitkanow installs the pinned Nuitka, reads[tool.nuitka]frompyproject.toml, and passes the section as CLI flags; Nuitka appears inrepomatic run --list.Build Nuitka binaries on Python 3.14.
Switch
[tool.typos]sync toONGOING: canonical proper-noun identifiers merge into a pre-existing[tool.typos]section instead of skipping it, preserving local keys and entries.Add
[[tool.bumpversion.files]]rules to the bundled template so downstream Python repos sync[tool.nuitka]βs numeric version keys without rewriting them on[project]bumps.Add
test-matrix.unstableconfig: matrix-key dicts (like{click-version = "main"}) that mark matching full-matrix combinationscontinue-on-errorin CI.Add a
lint-repocheck warning when a[tool.repomatic.test-matrix] excludeentry references a runner or Python version absent from the live matrix axes.Add
workflow_dispatchtriggers torelease.yamlandupdate-checksums.yamlfor manual re-runs.
6.19.0 (2026-05-21)ΒΆ
Note
6.19.0 is available on π PyPI and π GitHub.
Add
repomatic close-stale-bump-pr --part minor|majorto close orphan version-bump PRs left by races between thechangelog.yamlschedule and a competing push.Expand sponsor benefits in the awesome templateβs
contributing.md: sponsors get a dedicated entry in the matching section and a waiver on the licensing-marker requirement.Switch the
Sync uv.locksteps inchangelog.yamlfromuv synctouv lock --upgrade, folding pending transitive refreshes into the bump commit.Make
lint-changelog --fixrefuse to rewrite admonitions when an upstream GitHub or PyPI lookup looks unhealthy, instead of applying a corrupted view.Skip CI for automated version-bump operations across
tests.yaml,lint.yaml,labels.yaml, andrelease.yamlvia a unifiedmetadatagate.Reduce CI scheduling with
paths-ignore/paths:filters and per-job gates that skip lint jobs when no relevant files changed.Bump Biome from
2.4.14to2.4.15.
6.18.4 (2026-05-14)ΒΆ
Note
6.18.4 is available on π PyPI and π GitHub.
Replace
RepoScope.NON_AWESOMEwithPYTHON_ONLY, gating Python-flavored components on a PEP 621[project].nameso dotfiles repos carryingpyproject.tomlonly for[tool.*]config skip them by default.The bundled
release-publish-pypi-job.yamlfragment now participates in the@mainto@vX.Y.Zrewrite, so wheels built from a freeze commit ship with the pinned action ref.Bump Biome from
2.4.13to2.4.14and Lychee from0.24.1to0.24.2.Fix
fix-vulnerable-depsplacingexclude-newer-packageat the end of[tool.uv], which triggered a spuriousformat-pyprojectPR on the next run.
6.18.3 (2026-05-11)ΒΆ
Note
6.18.3 is available on π PyPI and π GitHub.
Fix
autofix.yamlβssetup-guidejob being skipped onworkflow_dispatchre-runs.Fix
release.yamlβspublish-pypijob running against downstream callers and failing PyPI trusted publishing with ajob_workflow_refmismatch.Switch the
compile-binariesjob from--onefileto--mode=onefile, the documented spelling since Nuitka 4.0.
6.18.2 (2026-05-08)ΒΆ
Note
6.18.2 is available on π PyPI and π GitHub.
Fix
release.yamluploading distributions to PyPI without PEP 740 attestations; the build job now signs each dist file and ships the.publish.attestationsidecars alongside it.
6.18.1 (2026-05-08)ΒΆ
Note
6.18.1 is available on π PyPI and π GitHub.
Fix the
publish-pypicomposite action verifying build attestations on every workspace file instead of just the downloaded distribution artifacts.
6.18.0 (2026-05-07)ΒΆ
Note
6.18.0 is available on π GitHub.
Warning
6.18.0 is not available on π PyPI.
Breaking: drop
PYPI_TOKENfrom therelease.yamlworkflow_call.secrets:interface. Regenerate the thin-caller workflow withrepomatic init workflowsand register a PyPI Trusted Publisher for your ownrelease.yaml.Add the
publish-pypicomposite action that publishes via OIDC Trusted Publishing with build-attestation verification; each downstream thin-caller now runs a generatedpublish-pypijob.Add a
check_pypi_trusted_publisherprobe tolint-repoand asetup-guide-pypi-trusted-publisherstep that points to a pre-filled PyPI publisher settings URL and stays open until the first OIDC-attested upload.Add
release_commits_matrixandpackage_nameoutputs to the reusablerelease.yamlso callers can drive their own matrix and gate jobs on a release commit.New composite actions under
.github/actions/now participate in@mainβ@vX.Y.Zref freeze/unfreeze without code changes.Fix
sync-repomaticproposing to delete.github/actions/publish-pypi/action.yamlwhen it matched the bundled default; the file must stay on disk for GitHub Actions to resolve theuses:path.
6.17.0 (2026-05-04)ΒΆ
Note
6.17.0 is available on π PyPI and π GitHub.
Add
--template-file <path>and--template-arg KEY=VALUEflags torepomatic pr-bodyso downstream repos can render project-specific PR templates without forking.--templateand--template-fileare mutually exclusive.Fix backslash-escaped brackets rendering literally in
docs/configuration.md**Type:**lines (likelist\[dict[str, str]\]).Fix doubled heading anchors on
docs/configuration.htmlanddocs/workflows.html(like#dev-release-sync-dev-release-sync).Collapse the most recent Python compatibility matrix row in
docs/install.mdto a major-version wildcard (like6.x) so the table stays stable across minor releases.
6.16.0 (2026-04-29)ΒΆ
Note
6.16.0 is available on π PyPI and π GitHub.
Add the
sphinx-docsagent to theagentscomponent, deployed byrepomatic init agentsor via[tool.repomatic] include = ["agents"].Add three
[tool.repomatic.workflow]knobs for customizingpaths:filters in generated thin callers:extra-pathsappends repo-specific entries,ignore-pathsstrips canonical entries absent downstream, andpathsreplaces a filter wholesale per workflow.Add a Python compatibility matrix to
docs/install.md, auto-generated from theProgramming Language :: Pythonclassifiers declared at every release tag.Render each commandβs
--helplive indocs/cli.mdvia{click:run}directives instead of captured plain-text help blocks.Replace the
Typecolumn in thedocs/configuration.mdsummary table with a one-line description derived from each optionβs docstring, and lead each per-option section with that one-liner.Detect vulnerable dependencies from the GitHub Advisory Database alongside the PyPA database:
fix-vulnerable-depsnow unionsuv auditwith Dependabot alerts and credits each entryβs source. Configurable via[tool.repomatic] vulnerable-deps.sources.Fix generated thin-caller fidelity: triggers mirror the canonical workflow verbatim instead of always injecting
workflow_dispatch, universal path entries are preserved, andrepomatic workflow lintnow flags extra triggers absent upstream.Fix
sync-uv-lockandfix-vulnerable-depsPR bodies showing1-01-01as theexclude-newercutoff whenpyproject.tomlconfigures a relative span like"1 week".Fix broken documentation links in all 18 PR body templates, now pointing at the published
configuration.htmlandworkflows.htmlanchors with each option name linked to its own anchor.Fix
release.yamldiscarding healthy binaries when one matrix cell crashed: thecompile-binariesmatrix setsfail-fast: falseandpublish-releaseuploads whatever built.Fix
update-docsβformat-markdownping-pong ondocs/cli.mdanddocs/configuration.md.Bump pinned
uvto0.11.8andmdformat-pelicanto1.0.0, fixing non-ASCII anchor links being percent-encoded on everyformat-markdownrun.
6.15.0 (2026-04-27)ΒΆ
Note
6.15.0 is available on π PyPI and π GitHub.
Decode percent-encoded non-ASCII characters in Markdown link destinations back to their original form, so non-ASCII anchors no longer get rewritten to
%XXon everyformat-markdownrun.Add πΈ/π licensing markers to the awesome-list contributing guide, issue template, and PR template (English and Chinese mirrors): πΈ for a paid version atop an OSS core, π for fully open-source.
Add the
agentscomponent torepomatic initfor deploying Claude Code agents (grunt-qa,qa-engineer) downstream. Excluded by default; opt in via[tool.repomatic] include = ["agents"]. Destination set by[tool.repomatic] agents.location.Add
docs/benchmark.mdcomparing repomatic against ten alternatives across template sync, repo governance, release automation, and changelog lifecycle.Switch MyST admonitions to backtick fences (
```{note}) instead of colon fences project-wide somdformatpreserves them; theconvert-to-mystcommand now emits backtick fences.Expand the
myst_docstringsSphinx extension: convert plain triple-backtick code fences and footnotes to reST, and run MyST-to-reST conversion beforesphinx_autodoc_typehints.Upgrade lychee to
0.24.1, which reads its[tool.lychee]config directly frompyproject.tomlso repomatic drops the TOML translation bridge.Fix
repomatic initreporting unchanged files as updated; re-running against an unchanged tree is now a true no-op.Fix
update-docsβformat-markdownping-pong ondocs/tool-runner.md.
6.14.0 (2026-04-20)ΒΆ
Note
6.14.0 is available on π PyPI and π GitHub.
Add a Sphinx documentation site (Furo theme, MyST-Parser) splitting the monolithic
readme.mdinto focused pages: installation, configuration, CLI parameters, reusable workflows, security, skills, and a tool runner tutorial. Deployed viadocs.yaml.Add the
repomatic.myst_docstringsSphinx extension andrepomatic.myst_converterutility, converting MyST markdown in docstrings to reST at build time sosphinx.ext.autodocworks unmodified.convert-to-mystrewrites source files in place.Add a
--sort-byoption to theshow-config,metadata --list-keys,run --list, andcache showcommands; each defaults to a natural sort column and accepts any column name.Add an incremental mode to the
brand-assetsskill: when base SVGs already exist, skip the design menu and fill gaps directly.Add a
check_stale_gh_pages_branchlint check and setup-guide instructions for deleting leftovergh-pagesbranches after switching to GitHub Actions deployment.Fix
Matrix.prune()keeping exclude directives that reference keys absent from the matrix axes, which GitHub Actions rejects.Fix the setup-guide Pages step for Sphinx projects: reopen the issue when Pages is unconfigured, and offer both first-time-enable and update commands.
Fix the
sponsor-labeljob inlabels.yamlmissing anactions/checkoutstep, which caused it to fail.
6.13.0 (2026-04-15)ΒΆ
Note
6.13.0 is available on π PyPI and π GitHub.
Add
nuitka.entry-pointsconfig option to select which[project.scripts]entries produce Nuitka binaries; aliases pointing to the same callable are deduplicated by default.Add two-phase VirusTotal scanning: an initial table with scan links, then a
--pollpass that fills in a Detections column offlagged / totalengine counts.Add
av-false-positiveskill to scan release binaries on VirusTotal and generate per-vendor false-positive submission files for flagged artifacts.Add
update-checksums.yamlworkflow that recomputes SHA-256 checksums for binary tools bumped by Renovate and commits the fix to the PR branch.Include release notes for every intermediate version in
sync-uv-lockPR bodies, not just the target version.Config
includeentries now bypassRepoScopefiltering, matching explicit CLI component naming; qualified entries likeskills/awesome-triageimplicitly select their parent component.Add baseline criteria for GitHub repositories in awesome list contributing guidelines: minimum 50 stars, not archived, and updated within 3 years.
Add
--min-savings-bytesoption toformat-images(default 1024) to skip images whose absolute byte savings are negligible.Add cross-platform binary support (macOS arm64/x64, Linux arm64/x64, Windows x64) for actionlint, biome, gitleaks, labelmaker, lychee, shfmt, and typos, plus ZIP archive extraction.
Show a progress bar during binary tool downloads when the server reports
Content-Length; interactive terminals only, silent in CI.Verify cached binaries with a two-layer integrity model: the registry checksum at download time and a
.sha256sidecar on every cache hit.Enable
[tool.actionlint]config support, translating it to.github/actionlint.yamlat invocation time.Cache downloaded tool binaries across CI runs with
actions/cache, keyed per tool, OS, and architecture.Replace
peaceiris/actions-gh-pageswith GitHubβs nativeactions/upload-pages-artifactandactions/deploy-pagesfor documentation deployment, plus alint-repocheck that the Pages source is set to GitHub Actions.Add
benchmark-updateskill to create and maintain competitive benchmark pages (docs/benchmark.md) withaudit,init,add, andrefresh-badgesmodes.Add
upstream-auditskill to create and maintain upstream contribution tracking pages (docs/upstream.md) withaudit,init,refresh, andsync-gitmodes.Upgrade the macOS Intel runner from
macos-15-inteltomacos-26-intelacross binary builds, the test matrix, and Nuitka compilation.Run the
lint-repoworkflow job on all repositories, not just Python projects, so generic checks apply to awesome lists too.Centralize GitHub token resolution with priority
REPOMATIC_PAT>GH_TOKEN>GITHUB_TOKENand automatic fallback toGITHUB_TOKENon an expired PAT;--has-patonsetup-guideandlint-reponow auto-detects fromREPOMATIC_PAT.Fix
exclude-newer-packagepruning inpyproject.tomlto remove orphaned comments and emitpyproject-fmt-compatible inline tables.Give a clear error when exiftool is not installed instead of a bare
FileNotFoundError, and verify it is on PATH after the Windows install step.Create parent directories for
--outputfile paths inrepomatic run, fixing lychee write errors when the output directory is missing.Sanitize
@mentions,#issuereferences, andgithub.comURLs in Lychee and Sphinx linkcheck output before embedding them in the broken-links issue.
6.12.0 (2026-04-13)ΒΆ
Note
6.12.0 is available on π PyPI and π GitHub.
Breaking: rename the
shell_filesmetadata key toshfmt_files, and exclude Zsh files and.shfiles with a Zsh shebang fromshfmtprocessing.Add
repomatic cachesubcommands (show,clean,path) and a global binary cache for downloaded tools; cached binaries are re-verified against their checksum and auto-purged after 30 days (configurable viaREPOMATIC_CACHE_MAX_AGE). Add--no-cachetorepomatic runto bypass it.Add an HTTP response cache for PyPI metadata and GitHub release bodies to avoid redundant API calls, plus
--namespaceonrepomatic cache cleanfor targeted cleanup.Route generated tool configs through the cache directory and pass them explicitly via
--config, instead of writing to/tmpor the repository root.Add
--version,--checksum, and--skip-checksumoptions torepomatic runto override the pinned tool version and SHA-256 verification at invocation time.Add structured logging to
repomatic run:--verbosity INFOreports config precedence, the full command, and exit code;DEBUGadds parsed config details.Add
skills.locationconfig option to override the Claude Code skills directory (default./.claude/skills/).Add
changelog.locationconfig option to override the changelog file path (default./changelog.md), honored by all CLI commands.Add
.claude/package-skills.shto package each Claude Code skill as a ZIP for manual upload to Claude Desktop.Sanitize
@mentions,#issuereferences, andgithub.comURLs in upstream release notes embedded insync-uv-lockPR bodies to prevent auto-linking and backlink cross-references.Use the
REPOMATIC_PATtoken in allpeter-evans/create-pull-requeststeps so created PRs trigger other workflows.Make the
uv syncstep inlint-typesconditional onis_python_project, so repos with Python files but no lockfile can still be type-checked.Fix
format-jsonfailing with a--config-patherror when a[tool.biome]section exists.Improve the
file-bug-reportskill to check organization-level community health files before per-repo files.
6.11.3 (2026-04-09)ΒΆ
Note
6.11.3 is available on π PyPI and π GitHub.
Add a
lint-repocheck warning when the GitHub Actions fork PR approval policy is weaker thanfirst_time_contributors, with a setup guide step to fix it.Add a
readme.mdsupply chain security section mapping Astralβs security practices to concrete repomatic implementations.Fix
rst_to_mystconversion leaving RST backslash escapes in headings and not wrapping dotted module names in backticks.Fix the
format-pyprojectautofix job failing with exit code 123.Disable the uv cache in the
publish-pypirelease job, which has no checkout and emitted spurious cache-miss warnings.
6.11.2 (2026-04-08)ΒΆ
Note
6.11.2 is available on π PyPI and π GitHub.
Add the
shfmtshell formatter to the tool runner (repomatic run shfmt).Add a
format-shellautofix job to auto-format shell scripts withshfmt.Replace the
crazy-max/ghaction-virustotalaction with a nativerepomatic scan-virustotalcommand, fixing the silently skipped release-body update.Deduplicate release attestations: Python packages are now attested once in
build-packageinstead of three times, and.gitignoreis no longer accidentally attested.
6.11.1 (2026-04-08)ΒΆ
Note
6.11.1 is available on π PyPI and π GitHub.
Parallelize the release workflow:
compile-binariesstarts right aftermetadata, andpublish-pypiruns concurrently withcreate-tagandcreate-release, with binary and attestation uploads deferred topublish-release.Fall back to the PyPI
project_urlschangelog link when a package has no GitHub Release, so release notes render a[Changelog]link instead of omitting the package.Fix the release workflow uploading the attestation bundle before the GitHub release draft existed.
Skip
exclude-newer-packageexemptions for packages whose fixed version already falls within theexclude-newercooldown window.Fix
--delete-excludednot detecting scope-excluded component files that still exist on disk.Fix awesome-template sync overwriting
pyproject.tomlinstead of merging, which stripped user-managed[tool.*]sections.Fix
repomatic init <component>silently ignoring an explicitly requested component when its scope did not match the repo.Fix
--delete-excludedremoving opt-in workflow files in the source repo by skipping config-key exclusions there.Fix the
format-pyprojectautofix step running with no input files and masking tool errors.
6.11.0 (2026-04-07)ΒΆ
Note
6.11.0 is available on π PyPI.
Warning
6.11.0 is not available on π GitHub.
Preserve extra downstream jobs when syncing thin-caller workflows; the managed job is regenerated in place while project-specific jobs, comments, and blank lines are kept.
Add a VirusTotal scanning job to the release workflow that uploads compiled binaries to seed AV databases. Requires the optional
VIRUSTOTAL_API_KEYrepository secret.Verify each attestation in CI right after
actions/attestwithgh attestation verify.Upload Sigstore attestation bundles (
.jsonl) as GitHub release assets for compiled binaries and Python packages, enabling offline verification.Add a
lint-repowarning whenVIRUSTOTAL_API_KEYis missing and Nuitka binary compilation is active.Add a VirusTotal API key setup step to the setup guide issue, shown only when Nuitka compilation is active.
Remove the one-time bumpversion dev-versioning migration code now that all downstream repos use PEP 440 dev versioning.
6.10.0 (2026-04-03)ΒΆ
Note
6.10.0 is available on π PyPI and π GitHub.
Breaking: Remove the
-oshort option frompr-bodyandformat-images; use--output.Add
brand-assetsskill to create and export project logo/banner SVG assets to light/dark PNG variants.Add
babysit-ciskill to monitor CI test workflows, diagnose failures, fix code, and loop until stable jobs pass.Add
file-bug-reportskill to write upstream bug reports from contribution guidelines, issue templates, and community norms.Add
test-matrix.replaceandtest-matrix.removeconfig to swap or drop axis values in the test matrices.Add
sync_mode=ONGOINGfor tool configs to repeatedly sync while preserving local additions, starting withsync-bumpversionkeeping local[[tool.bumpversion.files]]entries.Add
--output-format [markdown|github-actions]tosync-uv-lock,fix-vulnerable-deps,pr-body, andformat-images, replacing implicit$GITHUB_OUTPUTdetection.Add
.claude/scheduled_tasks.lockto the default.gitignoreextra content.Add a collapsible workflow metadata table (trigger, actor, commit, job, workflow, run link) to issue lifecycle comments.
Make the
setup-guideissue body a set of collapsible per-step sections with status indicators, and close it only once PAT, permissions, vulnerability alerts, and branch protection are all verified.Add
--release-notes/--no-release-notesand--table/--no-tableflags tosync-uv-lock, defaulting to a terminal table and reserving markdown for--output.Prune stale
exclude-newer-packageentries frompyproject.tomlbefore relocking insync-uv-lock.Make the
renovatecomponent opt-in, and excluderenovateandcodecovfrom awesome-list repositories.Remove Python
3.15t(free-threaded) from the default test matrix.Warn instead of crashing on unknown
[tool.repomatic]configuration keys.Echo
metadataoutput to stderr when--outputtargets a file, so computed matrices stay visible in CI logs.Add the
repomatic update-docscommand to runsphinx-apidoc, RST-to-MyST conversion, anddocs/docs_update.pyin one step.Add
docs.apidoc-extra-args,docs.apidoc-exclude, anddocs.update-scriptconfiguration options.Move the
sync-uv-lockjob fromrenovate.yamltoautofix.yamlso it runs on every push tomain.Fix a CLI crash when
test-matrix.variationsortest-matrix.replacecontain nested keys.
6.9.0 (2026-03-31)ΒΆ
Note
6.9.0 is available on π PyPI and π GitHub.
Breaking: Rename the
configsubcommand toshow-config(it now resolves typed[tool.repomatic]config via click-extra).Breaking: Remove the
prebake-versionandprebake-tag-shacommands; useclick-extra prebakeinstead.Add per-project test matrix configuration via
[tool.repomatic.test-matrix], supportingexclude,include, andvariations.Replace the
audit-depslint job with afix-vulnerable-depsautofix job that opens PRs upgrading vulnerable packages.Add a
codecovbundled component that syncs.github/codecov.yamlto suppress noisy PR comments.Support tool-runner config for tools that discover config from the working directory rather than a
--configflag.Move the mdformat
numberdefault to a bundledmdformat.tomlso downstream repos can override it.Expand PAT validation in
lint-repoandcheck-renovatewith repository scope, tag ruleset, and permission checks.Auto-exclude
changelog.mdfor awesome-list repositories.Migrate from
actions/attest-build-provenancetoactions/attest.Run granular PAT permission checks in
setup-guide, keeping the issue open with a diagnostic table when permissions are incomplete.Fix the
setup-guidejob so PAT detection works everywhere.Fix an infinite cycle between the
migrate-to-renovateandsync-repomaticjobs.Include git stderr in
git-tagCLI error messages.
6.8.0 (2026-03-27)ΒΆ
Note
6.8.0 is available on π PyPI and π GitHub.
Breaking: Rename
repomatic init --delete-redundantto--delete-unmodified, which now also removes config files identical to bundled defaults.Breaking: Remove the deprecated
WORKFLOW_UPDATE_GITHUB_PATsecret and its fallbacks; downstream repos must useREPOMATIC_PAT.Breaking: Stop persisting
[tool.ruff]defaults into downstreampyproject.toml; bundled ruff config is now injected at runtime when none exists.Breaking: Remove the
sync-renovatecommand, autofix job,renovate.syncconfig toggle, and PR body template;sync-repomaticand runtime materialization replace them.Breaking: Merge
/repomatic-deps-reviewinto/repomatic-deps, which now supportsgraphandreviewmodes.Move the test matrix definition into
repomatic metadataso it is available in job-levelif:conditions.Reduce CI jobs on pull requests by skipping release builds, experimental Python versions, and redundant verification tests; the full matrix still runs on push to
main.Make
excludeconfig additive to the default exclusions (labels,skills), and add anincludeconfig to force-include default-excluded components.Auto-exclude the
awesome-triageskill for non-awesome repositories.Add
--delete-excludedtorepomatic initto remove excluded files that still exist on disk.Replace the
sync-workflowsandclean-unmodified-configsautofix jobs with a singlesync-repomaticjob that syncs and prunes managed files in one PR.Add PAT capability and repo configuration checks to
lint-repo(Renovate config, Dependabot security updates off, vulnerability alerts on, PAT permissions).Add stale draft release detection to
lint-repo, warning about draft releases whose tag does not end with.dev0.Relax the abandoned-dependency threshold from 1 year to 2 years in the Renovate config.
Fix thin-caller generation rendering
workflow_dispatchinputs as Python dicts instead of YAML.Add the
/sphinx-docs-syncskill for cross-project Sphinx documentation comparison and synchronization.Add the
/translation-syncskill to detect and draft fixes for stalereadme.*.mdandcontributing.*.mdtranslations; auto-excluded for non-awesome repos.Streamline Dependabot guidance in the setup-guide issue.
Allow
repomatic initto accept qualifiedcomponent/fileselectors (likerepomatic init skills/repomatic-topics).Only auto-include the
awesome-templatecomponent forawesome-*repos when no explicit components are given.Add a package version diff table to
sync-uv-lockPRs, listing updated, added, and removed packages with PyPI links and collapsible release notes.Document file naming conventions in
claude.md: prefer.yamlover.ymland lowercase filenames, with a table of GitHub exceptions.Fix awesome-template URL rewriting to also process
.ymlfiles in.github/.Auto-exclude the
changelog.yaml,debug.yaml, andrelease.yamlworkflows forawesome-*repositories.Materialize the bundled
renovate.json5at runtime when absent, so downstream repos can safely delete their own copy.Pin GitHub Actions to SHA digests via Renovateβs
helpers:pinGitHubActionDigestsToSemverpreset.Add top-level
permissions: {}to all workflow files, requiring each job to declare its own minimal permissions.Fix
sync-repomaticdeleting the upstream repoβs own skills.Generalize the
opt_in_keyconfig option intoconfig_key/config_default.
6.7.0 (2026-03-24)ΒΆ
Note
6.7.0 is available on π PyPI and π GitHub.
Breaking: Remove the
sync-skills,workflow create, andworkflow synccommands;repomatic inithandles all three.Bundle awesome-template boilerplate files in
repomaticinstead of cloningkdeldycke/awesome-templateat runtime.Format every
pyproject.tomlin the repo in theformat-pyprojectjob, not just the root file.Add a branch protection checklist to the setup-guide issue, linking to a pre-filled ruleset creation form.
Add an opt-in
unsubscribe.yamlreusable workflow for scheduled cleanup of closed notification threads, enabled vianotification.unsubscribe = trueand requiringREPOMATIC_NOTIFICATIONS_PAT.Surface actual
ghCLI error messages inunsubscribe-threadswarnings.Enable
delete-branch: trueon allpeter-evans/create-pull-requestinvocations so stale automation PRs auto-close.Add
gitleaksto the tool runner with binary download and[tool.gitleaks]config bridge, and migratelint-secretstorepomatic run gitleaks.Move lychee config from
lychee.tomlto[tool.lychee]inpyproject.toml.Fix the
format-imagesjob by installingoxipngfrom its GitHub release.debso it runs onubuntu-slim.
6.6.0 (2026-03-23)ΒΆ
Note
6.6.0 is available on π PyPI and π GitHub.
Breaking: downstream repos with
yamllintorzizmorin their[tool.repomatic] excludelist must remove those entries.Remove
yamllintandzizmorinit components; the tool runner falls back to bundled default configs at runtime. Defaultexcludeis now["labels", "skills"].Add
repomatic clean-redundant-configscommand and autofix job that removes native config files identical to bundled defaults;repomatic initwarns about redundant configs on disk.Rename the
WORKFLOW_UPDATE_GITHUB_PATsecret toREPOMATIC_PAT; workflows accept both names. Old-name repos get a migration issue that auto-closes onceREPOMATIC_PATis detected.Add a
setup-guidetoggle to[tool.repomatic]to suppress the setup guide issue.Pre-fill the fine-grained PAT creation form via URL and provide
ghCLI commands for adding the secret, configuring Dependabot, and triggering a verify run.Add a
lint-repocheck that warns when the owner has GitHub Sponsors enabled but.github/FUNDING.ymlis missing.
6.5.0 (2026-03-23)ΒΆ
Note
6.5.0 is available on π PyPI and π GitHub.
Breaking: the old
init.excludeandworkflow.sync-excludekeys are no longer recognized and raise a hard error.Breaking: remove legacy
[tool.gha-utils]and[tool.repokit]config migration; rename old sections to[tool.repomatic]manually.Replace
init.excludeandworkflow.sync-excludewith a unifiedexcludekey: bare names exclude whole components,component/identifierentries exclude specific files.Add
repomatic run <tool>for unified tool invocation with managed config resolution (native file,[tool.X], bundled default, bare); use--listto see managed tools and their active config source.Register actionlint, autopep8, biome, bump-my-version, labelmaker, lychee, mdformat, mypy, pyproject-fmt, ruff, typos, yamllint, and zizmor with
repomatic run, and migrate all workflow tool invocations to it.Add a
yamllintinit component, excluded from init by default likezizmor.Add
repomatic update-checksums --registryto refresh SHA-256 hashes for binary tools.Add
[tool.lychee]and[tool.biome]config translation, so downstream repos can configure lychee and biome frompyproject.tomlwithout separate config files.
6.4.1 (2026-03-11)ΒΆ
Note
6.4.1 is available on π PyPI and π GitHub.
Add a
github-jsonoutput dialect torepomatic metadatathat bundles all keys into a singlemetadataoutput, accessed viafromJSON(needs.metadata.outputs.metadata).key_name.Add key filtering to
repomatic metadata: pass key names as arguments to output only those values.Add a
--list-keysflag torepomatic metadatato list all available keys with descriptions.Rename the
project-metadatajob and step IDs tometadataacross all workflows.Rename the
lintersinit component tozizmor; defaultinit.excludeis now["labels", "skills", "zizmor"].Remove the
sync-zizmorjob, CLI command, andzizmor.synctoggle;zizmor.yamlis now user-owned and created byrepomatic init zizmorif missing.Rename the
bump-versionsjob tobump-versioninchangelog.yaml.Upgrade zizmor to
1.23.0and re-enable thetemplate-injectionaudit.Fix
repomatic metadatalist values breaking GitHub Actions${{ }}interpolation: lists are now pre-formatted (file lists as quoted strings, plain lists space-separated, dict lists as JSON).Fix
repomatic workflow sync --format header-onlyerroring when a target workflow file is absent downstream; missing default files are skipped and named missing files warn instead.Enable parallel test execution by default via
--numprocesses=auto.
6.4.0 (2026-03-10)ΒΆ
Note
6.4.0 is available on π PyPI and π GitHub.
Rename
optimize-imagestoformat-images, aligning it with theformat-*naming convention, and add a matching PR body template.Allow
--prefixand--templateto be combined inrepomatic pr-body; the prefix is prepended before the rendered template.Add
awesome-template-sync,bumpversion-sync,dev-release-sync,gitignore-sync,labels-sync,mailmap-sync,uv-lock-sync, andzizmor-synctoggles to[tool.repomatic], so each sync operation can be individually disabled.Rename
sync-linter-configstosync-zizmor(andlinter-synctozizmor-sync), naming the sync job after the tool it syncs.Add a
repomatic sync-labelscommand wrappinglabelmakerwith toggle check, profile detection, and extra label file handling.Replace
AndreasAugustin/actions-template-syncwith a nativerepomatic sync-awesome-templatecommand.Add
repomatic init typosto sync the shared typos spell-checker config intopyproject.toml, with proper-noun corrections and<!-- typos:off -->/<!-- typos:on -->block markers.Skip Ruff config injection in
format-pythonfor non-Python projects, and skipsync-bumpversionfor non-Python projects.Use TOML sub-keys for grouped
[tool.repomatic]options (likenuitka.enabled,gitignore.location,test-plan.file); onlypypi-package-historystays flat.Add a
workflow-source-pathsoption to[tool.repomatic]: thin-caller and header-only workflows gainpaths:filters for the projectβs source directory, auto-derived from[project.name].Add a
repomatic configcommand that renders the[tool.repomatic]reference table.Add
### Configurationsections to PR body templates listing the relevant[tool.repomatic]options.
6.3.2 (2026-03-08)ΒΆ
Note
6.3.2 is available on π PyPI and π GitHub.
Add
--all-extrasto theuv syncstep intests.yamlto catch incompatibilities between optional dependency groups.Add a
test-package-installjob totests.yamlthat verifies every[project.scripts]entry point installs and runs viauvx,uv run --with, module invocation,uv tool install, andpipx run, from PyPI and GitHub. Add acli_scriptsmetadata output.Sync
customManagersto downstreamrenovate.json5so Renovate can update inline version pins in workflow files.Fix thin-caller generation stripping
pathsandpaths-ignorefilters, which incorrectly restricted CI triggers downstream.Fix the
optimize-imagesjob failing onubuntu-slimwhereoxipngis unavailable.Add a
citation.cffdate-releasedupdate to the bundledbumpversion.tomltemplate so downstream repos keep their release date in sync on version bumps.
6.3.1 (2026-03-07)ΒΆ
Note
6.3.1 is available on π PyPI and π GitHub.
Sync the
repomatic-auditskill to downstream repos.
6.3.0 (2026-03-06)ΒΆ
Note
6.3.0 is available on π PyPI and π GitHub.
repomatic initnow always overwrites managed files (workflows, configs, skills) by default; remove the--overwriteflag.changelog.mdis never overwritten once it exists.repomatic initoutput now distinguishes created, updated, and skipped files, and warns about excluded files still on disk.Auto-remove legacy
.claude/skills/gha-*/skill directories duringrepomatic init, completing thegha-utilstorepomaticrename.sync-bumpversion,sync-linter-configs, andsync-skillsnow report both created and updated files.sync-bumpversionnow replaces the whole[tool.bumpversion]section from the bundled template instead of applying incremental migrations.Use the short SHA in release workflow job names instead of the full commit hash.
6.2.1 (2026-03-06)ΒΆ
Note
6.2.1 is available on π PyPI and π GitHub.
Fix
actions/checkoutwiping downloaded Python package artifacts beforegh release createcould attach them, so release drafts now include the distribution files.Fix
fix-changelogmarking releases as not available on GitHub while the release was still a draft.
6.2.0 (2026-03-05)ΒΆ
Note
6.2.0 is available on π PyPI and π GitHub.
Add the
repomatic optimize-imagesCLI command (losslessoxipngfor PNG,jpegoptimfor JPEG), replacingcalibreapp/image-actions.Add the
sync-dev-releaseCLI command and workflow job to maintain a rolling dev pre-release on GitHub with the latest binaries and Python package.Add the
repomatic-topicsskill for optimizing GitHub repository topics for discoverability.Add a
lint-repocheck that warns when GitHub topics are not a subset ofpyproject.tomlkeywords.Add the
init-excludeconfig option to skip components duringrepomatic init, defaulting to["labels", "linters", "skills"];workflow-sync-excludenow also applies torepomatic init.Add
rename-fromrules to migrate all 9 default GitHub labels.Add the package version to compiled binary filenames (
repomatic-6.2.0-linux-arm64.bin).Automatically migrate
[tool.gha-utils]and[tool.repokit]config sections to[tool.repomatic]duringrepomatic init; commands fall back to legacy section names when[tool.repomatic]is absent.Support GitHub immutable releases by drafting releases then publishing them.
Replace
softprops/action-gh-releasewithgh release create; all release operations now use theghCLI.Freeze readme binary download URLs to versioned
/releases/download/vX.Y.Z/paths during releases.GitHub releases now include PyPI and GitHub availability links at creation time.
Fix Nuitka-compiled binaries silently producing no output when the entry point is a
__main__.pyinside a package.Fix
update-checksumsleaving stale SHA-256 hashes when the hash andsha256sum --checkkeyword span multiple lines.Fix Windows ARM64 test runners using x86_64 emulation by forcing native ARM64 Python via
UV_PYTHON.Fix
fix-changelogproducing a trailing blank line when the last changelog section is modified.
6.1.0 (2026-02-27)ΒΆ
Note
6.1.0 is available on π PyPI and π GitHub.
Add the
unsubscribe-threadsCLI command to unsubscribe from closed, inactive GitHub notification threads.Add the
prebake-versionCLI command to inject the Git commit hash into__version__before Nuitka compilation, so binaries report the exact commit they were built from (e.g.,6.1.0.dev0+abc1234).Add the
list-skillsCLI command to display all available Claude Code skills grouped by lifecycle phase.Add the
sync-github-releasesCLI command to sync GitHub release notes fromchangelog.md.Add the
pypi-package-historyconfig option solint-changelogfetches releases from former package names and generates correct PyPI URLs for renamed projects.lint-changelognow detects orphaned versions (git tags, GitHub releases, or PyPI packages with no changelog entry) and inserts placeholder sections in--fixmode.Rename the
lint-changelogworkflow job tofix-changelog; the CLI command remainslint-changelog.Make changelog entries and GitHub release bodies template-driven via
release-notes.mdandgithub-releases.md, so editing one template affects only its destination.Group CLI commands into sections (Project setup, Release & versioning, Sync, Linting & checks, GitHub issues & PRs) in help output.
Add next-step handoff suggestions to all Claude Code skills, and document skills with a grouped table and walkthrough in
readme.md.Generate thin caller workflows with explicit secret forwarding instead of
secrets: inherit.Move zizmor config from
.github/zizmor.ymltozizmor.yamlat repo root.
6.0.1 (2026-02-24)ΒΆ
Note
First release under the repomatic name on PyPI, after repokit was rejected for typo-squatting (see 6.0.0). The GitHub repository is kdeldycke/repomatic.
Note
6.0.1 is available on π PyPI and π GitHub.
Rename project from
repokittorepomatic. Rename GitHub repository fromkdeldycke/repokittokdeldycke/repomatic.
6.0.0 (2026-02-24)ΒΆ
Caution
This release was deleted from PyPI. It was supposed to be published as repokit, but PyPI flagged the name as typo-squatting the pre-existing repo-kit package.
Note
6.0.0 is available on π GitHub.
Warning
6.0.0 is not available on π PyPI.
Rename project from
gha-utilstorepokit. Rename GitHub repository fromkdeldycke/workflowstokdeldycke/repokit.
Earlier releasesΒΆ
Note
Releases 5.14.1 and earlier are recorded in the changelog archive.