6.1.1

Superpowers 6.1.1 - リリースノート

2026年7月2日
Superpowers

日本語サマリー

Superpowers v6.1.1 リリースノート要約

⚠️ 破壊的変更・重要な修正

  • Codex の意図しない SessionStart hook の再登録を修正(セキュリティ/動作修正)
    • v6.1.0 で hook config を削除した結果、Codex が auto-discovery によって Claude Code 用の SessionStart hook を再登録し、trust prompt を発生させてしまう問題(Fall back バグ)を解消しました。
    • マニフェストで明示的に空のオブジェクト hooks: {} を宣言することで、auto-discovery を回避するように修正されています。

主な変更点

Codex

  • 不要なセッション開始用デッドコードを削除: 呼び出し元が存在しない hooks/session-start-codex と、それに伴う不要なテストケースを削除しました。
  • ドキュメントの修正: docs/porting-to-a-new-harness.md のシェルフックの記載を Codex から Cursor へと差し替え、docs/windows/polyglot-hooks.md の古い hooks-codex.json ポインタを修正しました。
  • 分類の修正: Codex プラグインのカテゴリが "Developer Tools" に修正されました。

Packaging

  • Codex パッケージビルドスクリプトを追加: Codex portal 用アーカイブ(デフォルトは .zip、オプションで tar.gz)を生成するメンテナースクリプト package-codex-plugin.sh を新設しました。
  • ビルドスクリプトの機能: タイムスタンプの正規化、実行権限の保持、OpenAI metadata の検証、dirty worktree からの実行拒否、およびバイト単位で同一のアーカイブ再構築(決定性の確保)を行います。また、パッケージ版マニフェストにも hooks: {} を引き継ぐことで、インストール時の hook auto-discovery を確実に防ぎます。
  • テストスイートの追加: 上記パッケージスクリプトの動作を保証するための新しいテストスイートを追加しました。

原文(Release Notes)

v6.1.1 (2026-07-02)

Codex

  • Codex no longer re-registers the Claude SessionStart hook. v6.1.0 removed the Codex hook config and its manifest hooks pointer, meaning to stop Codex from installing a SessionStart hook — but with no hooks field, Codex fell back to auto-discovering hooks/hooks.json, the Claude Code SessionStart hook that the marketplace ships from the repo root, and re-registered it along with its install-time trust prompt. The Codex manifest now declares an explicit empty hooks object (hooks: {}), which Codex reads as "no hooks" instead of reaching the auto-discovery fallback. An absent field, [], and an empty inline list all collapse back to the fallback, so the value has to be exactly {}.
  • Removed orphaned Codex session-start dead code. hooks/session-start-codex had no caller once the Codex hook config was deleted, so it and its redundant test cases are gone. The worked shell-hook example in docs/porting-to-a-new-harness.md moves from Codex — now native skill discovery with no session-start hook — to Cursor, a live shell-hook harness, and the stale hooks-codex.json pointer in docs/windows/polyglot-hooks.md is corrected. The Codex plugin category is also fixed to "Developer Tools".

Packaging

  • New package-codex-plugin.sh for building the Codex portal package. A maintainer script produces a deterministic Codex "portal" archive — .zip by default, tar.gz on request — that normalizes entry timestamps, preserves executable modes, verifies every packaged skill ships its OpenAI metadata, includes the app and composer icons, and refuses to run against a dirty worktree. The packaged manifest keeps the source hooks: {} object so a portal-installed plugin avoids the same SessionStart auto-discovery, and the script can rebuild a byte-identical archive from a saved metadata source. Covered by a new test suite.