openplanr 2.2641.2
Minor Changes
The sync, sprint and status skills reach GitHub and Linear through your coding agent's own connection, or the GitHub CLI when it is signed in, and name the connection to add when one is missing. They no longer use the Linear token that
openplanr linearstores;openplanr linearkeeps working in a terminal. Afteropenplanr sprint apply, the sprint skill updates the issue linked to each changed item.Breaking:
openplanr report --push slackis removed, together with thedistribution.slackWebhookUrlanddistribution.slackChannelsettings, so the repository config holds no webhook secret. It ships in a minor release as a deliberate exception to the major-release rule, because the push kept a webhook secret in a committed file.--push githubis unchanged, and a rejected target now stops the command before anything is written or pushed. If your config had a webhook URL, revoke the webhook in Slack, since the URL sat in a committed file, then delete it from.planr/config.json.
Patch Changes
openplanr rules generatekeeps apostrophes in the agent descriptions it lists inCLAUDE.md, so "the project's stack" no longer renders as "the projects stack".The database agent no longer reads
DB_PASSWORDor passes any password or connection string. It connects only where the database client signs in on its own: a PostgreSQL service with~/.pgpass, a MySQL login path, MongoDB OIDC, X.509 or AWS authentication or a local server without authentication, or a trusted MSSQL connection. Without one, it asks you to set one up or run the scan yourself.delegateclassifies credentials by syntax. Member references such asconfig!.apiKeyin code, type annotations ending in;or,, and self-describing test values such astest_secret_must_be_…now reach the delegated agent unchanged, while recognizable credentials, private keys and credential files stay blocked. A blocked source lists masked findings with location, rule and confidence; for an optional source they appear only in the prepare preview, never in the delegated context. After you confirm that a specific finding is not a credential,prepareaccepts it throughcredentialResolutionsfor those exact bytes only, and the preview lists every accepted resolution.delegatechecks a local model server without sending a token: it no longer reads or sendsLM_STUDIO_API_KEY,LM_API_TOKENor the ClaudeANTHROPIC_AUTH_TOKEN. A server that requires sign-in is reported as not checked, and the run can still start with the delegated agent's own sign-in.The Claude Code plugin pre-approves no tools: the seven Operate review skills drop their
allowed-toolsgrant, so the package qualifies as instructions-only and every write follows your normal permission prompts. An Operate lens run on its own now creates the same.planr/operate/<date>-<slug>/cycleplanr-operatecreates, with a one-lens roster, so the dashboard lists it.Role agents are simpler and current: descriptions no longer route by task file names or pipeline step numbers, legacy role names are gone, and most roles inherit the session's tools. The QA agent denies the file-editing tools and the DevOps agent keeps no shell; both boundaries are documented as what the host enforces. Plan decomposes a story into coherent, independently verifiable tasks split by ownership instead of a fixed one-or-two-task count.
Local Studio and review servers take their control token in a dedicated header. A Studio started by the previous version is still listed, reused, exported from and stopped. Older OpenPlanr versions cannot use a Studio started by this one, so stop running Studios with
openplanr server stop --all --yesbefore switching to an older version, including an oldernpxrun or a project-local install. If an older version reports "Local Studio owner state is unsafe or malformed", stop the Studio with this version. If no Studio is running, delete thestate-*.jsonandinstance-*.jsonfiles in~/.planr/artifact-daemon/(underPLANR_HOMEwhen it is set).openplanr spec syncrecognizes aspecIdwritten without quotes, adds a missing one after an unquotedid, and reports a repair only when it makes one. It previously reported addingspecIdto every story and task the plan skill writes while leaving the files unchanged.Local Studio previews now give prototypes the bounded prototype-state API and each screen's logical id, so prototypes that keep state across screens work in local review. Stored artifacts are unchanged.
openplanr github synctreats an open issue as matching every status exceptdone, so pulling no longer resets in-progress or planning items topending. A closed issue marks its itemdone, and an issue reopened after its item was done marks itin-progress.openplanr github pushcloses the issue of a closed backlog item instead of reopening it, and leaves the issue of a promoted one as it is.openplanr linear pusherrors list every pushable prefix, includingQT-andBL-.