Release notes
Tenon release notes explain what changed, what users need to do, and how to verify an upgrade.
Only capabilities included in a public distribution belong here. Plans, internal ADRs, and unmerged experiments are not presented as shipped work.
v1.0.1 · 2026-07-26
Normal-chat entry contract
product/identity.jsonnow declaresentrySkill: "tenon"as the only public entry.- Codex normal chat invokes
tenon:tenon; no secondary entry alias is retained. - Root
AGENTS.mdand the Codex static adapter consume one generated managed block. tenon doctorverifies the entry Skill and reports an enabled conflicting workflow plugin as a red finding.tenon setup --codex -yremoves that exact retired registration through the official Codex plugin manager before activating Tenon.
Repository and release hygiene
- CI and Release scan every tracked path and text file for restricted external reference identities.
- Matching is case-insensitive, has no exemptions, and diagnostics never echo a restricted identity.
- The same checks run before the release payload is built.
Upgrade
Run tenon update --codex, then tenon setup --codex --auto-update -y. Open a new Codex session and run tenon doctor --json.
v1.0.0 · 2026-07-26
Governed document locale
- New Changes pin governed documents to
zh-CNby default. tenon init,tenon document scaffold, and the default OpenSpec fallback share one Document Presentation Registry.- Users can explicitly select
--document-locale en. - A pinned Change cannot silently switch locale.
- Historical Changes infer locale from the writing system used by existing H1 headings.
- Mixed or ambiguous signals fail loudly and require an explicit locale.
Execution modes
- Discussion handles ordinary conversation without a state machine.
- Simple uses
change → verify → doneand does not create the full OpenSpec chain. - Default uses
open → explore → spec ⇄ build ⇄ verify → ship → archive. - Free binds an explicit workflow without adding a domain Track.
- Custom follows only its declared DAG, Skills, gates, and document contract.
Documentation site
- The repository README defaults to Chinese and links to
README.en.md. - The site exposes Chinese at the root and the English mirror under
/en/. - Local search is built from the public content manifest.
- GitHub Pages deploys only from
main. - Pull requests build and verify but do not deploy.
- The artifact is checked against a closed allowlist and scanned for sensitive material.
llms.txtindexes only public pages.- Internal ADRs, Superpowers plans, review receipts, and local control-plane state are excluded.
Installation and updates
- Install for Codex with
tenon setup --codex. - Install for Claude with
tenon setup --claude. - Update with the matching
tenon update --codexortenon update --claude. - The managed runtime is content-addressed and the stable launcher targets a verified release.
- A failed update preserves the previous release for
tenon runtime repair --rollback. - Dashboard listens on
127.0.0.1:18765by default.
Upgrade checklist
- Inspect the repository working tree.
- Run the update command for the selected host.
- Run
tenon runtime status. - Run
tenon doctor. - Run
tenon list --jsonin the project. - Confirm Dashboard uses
127.0.0.1:18765.
Verification
tenon --helplists the command families.tenon runtime statusreports the active runtime.tenon doctorreports no missing bundled Skills.- Repeated
tenon setup --codexremains idempotent. - Updating does not rewrite canonical Change state.
- A new test Change creates Chinese proposal, design, and tasks files.
- An explicitly English Change keeps newly scaffolded documents in English.
Compatibility
The canonical Change codec does not gain a locale field. Locale lives in the rollback-compatible .pipeline-document-locale.json sidecar.
Rollback
Run tenon runtime status, then use tenon runtime repair --rollback to return to the previous verified content-addressed release.
Runtime rollback does not remove project Changes, OpenSpec documents, or evidence ledgers.
Next action
Read Updates, recovery, and uninstall for the complete maintenance and recovery workflow.