2.2.1
ECC 2.2.1 - リリースノート
2026年9月8日
ECC
日本語サマリー
ECC 2.2.1 リリースノート要約
ECC 2.2.1 は ECC 2.2 向けのバグ・セキュリティ修正パッチです。v2.2.0 の履歴は不変のまま維持されます。
⚠️ セキュリティ・データ保護の修正
- GateGuard / governance capture が破壊的な PowerShell コマンド(ネイティブ PowerShell ツールパス含む)を検出。変数代入による隠蔽を防止(#2961)
- 相対 GateGuard 除外 glob をプロジェクトルート内に制限。絶対パスでの除外は引き続きサポート(#2921)
- インストーラが追跡対象外のユーザー所有ファイルとの衝突を拒否。失敗したインストールでは実際に書き込んだファイルのみ所有権ハッシュを更新(#2964)
- アンインストールが
ECC_DRY_RUN=1を尊重(レガシー Codex パス含む)。無効な dry-run 値は拒否(#2952) - Observer analysis は処理が未成功・未確認の場合、exit code 0 だけでは観測データをアーカイブしない(#2971)
- Yarn lockfile の
tomlを 4.3.0 に更新し、影響のある古い解決を排除
その他の重要な変更
- Hooks / インストール:手動 Claude インストールが ECC 所有の hook エントリを Claude settings に登録。修復・アンインストール時も無関係な設定を保持。アトミックな設定更新と同時編集の再試行に対応(#2992)
- フックエントリポイントが大きな JSON ペイロードを UTF-8 安全かつ境界付きで読み込み、サイレントな切り捨てを防止(#2924)
- Pi アダプタが実際の Node ランタイムを選択(コンパイル済み OMP ホストの再帰実行を解消、#2909)
- Claude セットアップが
gitを事前チェックし、前提不足を早期検出 - ドキュメント整備:公開コマンドを
ecc-universalに統一、AdaL アダプタはnpx ecc-universal doctor --target adalを使用。Itô ワークフローにecc ito accept <ticket-id>とito_acceptMCP tool を追記
スコープと制限
- プラグインの依存モジュールは自動インストールされない(DB・スキーマ検証機能は宣言された依存関係が必要)
- アップグレード時に既存の管理ファイルは置換されるため、意図的な編集は事前にバックアップ推奨
アップグレード
npm install -g ecc-universal@2.2.1
ecc doctor
初回・ガイド付きセットアップは npx ecc-universal setup、Claude marketplace パス(/plugin install ecc@ecc)も引き続きサポートされます。
原文(Release Notes)
ECC 2.2.1
ECC 2.2.1 is a bug and security patch for ECC 2.2. It keeps the published
v2.2.0history immutable. These notes describe the prepared patch; publication and signing evidence are tracked separately in the release checklist.Security and data protection
- GateGuard and governance capture recognize destructive PowerShell commands, including the native PowerShell tool path. Dynamic command handling prevents later variable assignments from concealing earlier unresolved invocations (#2961).
- Relative GateGuard exemption globs stay within the project root. Explicit absolute exemptions remain supported (#2921).
- Installer writes reject collisions with untracked user-owned files. Failed installs refresh ownership hashes only for files they actually wrote, preserving the previous ownership hashes of untouched managed files (#2964).
- Guided setup revalidates its preview before ownership filtering, so files appearing between preview and apply cause a clear retry instead of a false success. Existing identical user files stay outside ECC ownership.
- Uninstall respects
ECC_DRY_RUN=1, including legacy Codex paths, and rejects invalid dry-run values instead of silently allowing deletion (#2952).- Observer analysis retains observations on unsuccessful or unconfirmed processing. Exit code zero alone no longer permits archival (#2971).
- The Yarn lockfile updates
tomlto 4.3.0, matching the npm lockfile and removing the affected older resolution.Hooks and installation
- Manual Claude installs register ECC-owned hook entries in Claude settings. Repair, consent changes, and uninstall reconcile those entries while preserving unrelated settings. Atomic settings updates check directory identity and retry detected concurrent edits (#2992).
- Direct hook entrypoints handle larger JSON payloads with bounded, UTF-8-safe reads instead of silently truncating valid inputs. Existing production wrapper limits remain unchanged (#2924).
- The Pi adapter selects an actual Node runtime instead of recursively executing a compiled OMP host as Node (#2909).
- Installer listing and control-pane help avoid eager third-party dependency loading. Features that require absent runtime packages report the missing dependency explicitly (#2994).
- Autonomous harness setup documentation replaces nonexistent package names and unsupported CLI flags with documented interfaces, and distinguishes session scheduling from a durable external scheduler (#2957).
Installer and release-surface hardening
- Public and packaged install docs now consistently point at the published
ecc-universalcommands instead of stale or unrelated package names.- The AdaL adapter docs use the correct
npx ecc-universal doctor --target adalcommand.- Claude setup preflights
gitbefore provider-specific work starts, so missing prerequisites fail fast with the right action.- Guided setup dry runs use isolated HOME, config, XDG, temp, and Windows app data roots to avoid ambient host state affecting review or tests.
- The exact packed artifact now has stronger lifecycle coverage for Claude and Kimi setup, update, doctor, repeat install, uninstall, and dry-run flows.
- Identifier regression coverage blocks stale
ecc,ecc-install, and other mismatched release-path commands from creeping back into user-facing docs.Current-main documentation included in this patch
- The canonical Itô workflow now documents
ecc ito accept <ticket-id>and theito_acceptMCP tool.- Acceptance is explicitly bounded to buyer-authority routing. It routes the active desk quote to human review and does not claim to place a trade.
Provenance boundary
v2.2.1is intended to be a signed annotated tag on exact greenmain.v2.2.0remains the immutable historical unsigned exception. Do not move, recreate, or reuse that tag.Scope and limitations
- Plugin dependency handling does not bundle or automatically install missing modules. Database and schema-validation features require their declared runtime dependencies.
- Ownership protection covers untracked collisions and failed-install checkpoints. Successful upgrades retain the existing contract for replacing previously managed files. Back up intentional edits before upgrading.
- This patch does not introduce new harness platforms or claim that every open community issue is resolved.
Upgrade
After the release workflow publishes 2.2.1 and verifies registry integrity, install or update the package, then run the same ECC command path you already use. Until publication completes, the exact-version command below returns E404.
npm install -g ecc-universal@2.2.1 ecc doctorFor first-time or guided terminal setup:
npx ecc-universal setupThe native Claude marketplace path remains supported:
/plugin marketplace add https://github.com/affaan-m/ECC /plugin install ecc@ecc