overlock
Updates mentioning overlock. See the repository ↗ for commits and releases.
Leaner builds and stricter gates across the libraries
overlock and use-everywhere now build with tsdown instead of tsup (overlock 0.10.1, use-everywhere 1.0.1). The published output keeps its shape: same entry points, formats, filenames and types. overlock’s tarball is smaller, because code shared by its two entries is no longer duplicated.
Every library’s CI now gates on knip and sherif. knip fails on unused files, exports and dependencies. sherif fails when two packages in a workspace disagree on a dependency’s version. The first pass removed internal exports nothing imported (overlock 0.10.2,
@use-everywhere/core1.0.2), none of them part of the public API.Jonatan Kruszewski
overlock 0.10.0
overlock check --staged --stage-recordstages the record of a run into the commit that run judged. Without it, the evidence for a change always trailed one commit behind the change, and a repository collecting records never had a clean working tree.It is a flag, not a config key, because only a pre-commit hook’s run has a commit to join. Staging is the one write overlock makes, and it happens only when you pass this flag. If
.overlockis ignored, the record stays on disk and overlock says so on stderr.Jonatan Kruszewski
overlock 0.9.2
The Claude Code hook now stops only once for a suppression the patch wrote about itself. Before, every later turn on the branch stopped again on the same claim.
The hook now remembers what it has already put to a person, per repository and branch. Changing the reason, or adding another suppression, still stops once. Findings nobody suppressed still stop every turn until they are fixed.
Jonatan Kruszewski
overlock 0.9.1
Crafted input can no longer stall a run. Four parsers backtracked quadratically on text the patch author controls, and each now reads in linear time:
- an
Overlock-Allow:trailer; - a
diff --githeader; - an unterminated string literal;
- an
excludeentry.
Every result is the same as before.
Jonatan Kruszewski
- an
overlock 0.9.0
A new
excludesetting leaves other tools’ evidence directories out of the patch, such as.bastingor.saidso. They are treated the way.overlockalready was. Without it, those directories changed the patch fingerprint on every turn and grew captured diffs recursively.Entries are literal paths from the repository root. Globs, pathspec magic,
..and filesystem paths are refused, so the setting can only ever narrow what overlock looks at.Jonatan Kruszewski
overlock 0.8.0
overlock can now keep a record of what it judged. Evaluation records are opt-in and stored in the repository under
.overlock. Each one holds:- the exact patch fingerprint and a snapshot of it;
- the final hook decision;
- the evidence as it was before any suppression applied.
Those records feed new tooling: import artifacts from other runs, review outcomes independently, report across deduplicated evaluations, and replay a labelled corpus. The replay checks detection and blocking as two separate questions.
Repeated detections in the old ledger no longer count as verified catches, so the deprecated
meetsBarnow always returnsfalse.Jonatan Kruszewski
overlock 0.7.1
SUITE_SCOPE_NARROWEDno longer blocks a pull request that adds a package. A newvitest.config.tsread as an exclude list that grew, so every new package was reported as a narrowed suite, athigh.A config file that already existed still fires, including when it gains an
excludekey it never had.Jonatan Kruszewski
overlock is open source
I open-sourced overlock, a CLI that catches changes that make tests pass by weakening them: an
it.skip, an assertion loosened totoBeDefined(), a coverage threshold lowered. It was built for coding agents, which will happily take that route to a green suite.Run it with
npx overlock, or as a Claude Code Stop hook, an MCP server or a GitHub Action. Thirteen rules, no network calls, zero runtime dependencies.Jonatan Kruszewski
overlock 0.7.0
overlock now catches tests switched off in CI config, not just in test files. Two new rules:
TEST_GATE_DISABLED: a failing suite stops failing the build —continue-on-error: true,|| true,--passWithNoTests, or the test step deleted.SUITE_SCOPE_NARROWED: the runner collects fewer tests — anincludepattern removed, anexcludepattern added, a filter flag on the test command.
A rule can also be turned off per repository with
"severity": { "RULE_ID": "off" }. What it would have reported is still counted in the verdict line, so switching a rule off never hides silently.Backwards compatible: existing configs and flags behave as they did.
Jonatan Kruszewski
No entries match those filters.