v0.2.0Public Preview
Shared detector engine with Review Skills, per-ecosystem Review Packs, a persistent Findings Ledger, and optional external analyzers.
Key Highlights & Additions
- Review Skills for files, diffs, and architecture over one shared detector engine, with per-ecosystem Review Packs and criteria resolution against the repository's own stack and conventions.
- Findings carry column, rubric-based severity and confidence, why the pattern matters, a concrete fix, and the code before/after.
- Code-aware detectors: patterns inside strings and comments do not match; secret detection flags known credential formats and high-entropy values.
- Findings Ledger in .debuggatha/ledger.json with a five-state lifecycle and atomic writes shared by the CLI, MCP server, and editor.
- Baseline (baseline create|show|clear) so later reviews report only what is new, plus inline suppression via debuggatha-ignore comments.
- External analyzers run as separate processes — gitleaks, Biome, ESLint, Ruff, ktlint, detekt, PHPStan, Clippy, OSV-Scanner — enabled only by the person running the review.
- Optional semantic pass (--semantic ollama|lmstudio): a local model raises suspicions kept only when they quote the exact line; code goes only to localhost or the client's own model.
- MCP server with titled, output-schema tools, stdio and Streamable HTTP transports, and the review-flow / fix-findings prompts.
- VS Code extension with diagnostics, a findings view, hover, quick fixes, and reviews in their own cancellable process.
- CLI and MCP server published to npm as @sxnnyside/debuggatha-cli and @sxnnyside/debuggatha-mcp.
