2.2.2
ECC 2.2.2 - リリースノート
2026年9月30日
ECC
日本語サマリー
ECC 2.2.2 リリースノート要約
セキュリティ修正
- 依存パッケージの更新:
lru→ 0.18.2 (RUSTSEC-2026-0253)、js-yaml→ 4.3.2 (GHSA-2883-xcg3-v3hh)
主な変更点
pi/core/プロファイルの新設: ビルド不要・拡張なし・hooks なし・ネットワーク依存なしの自己完結型パッケージ (ecc-pi-core)。123 のキュレーション済み skills と 24 の prompt コマンドを収録- 決定論的なビルド:
scripts/build-pi-core.jsがmanifests/pi-core.jsonの include/exclude リストから生成。除外対象の理由はpi/core/CURATION.mdに記載 - 安全性チェック強化: 許可リスト外の URL ホスト、pipe-to-shell、fetch-and-run、secrets/token、絶対パスのホームディレクトリ、symlink、不正な SKILL.md frontmatter、重複スキル名があるとビルド失敗
- CI 検証: PR ごとに pi/core を再ビルドし、
PI_OFFLINE=1で完全オフラインでのロードを検証。リリース時にVERSIONとタグの一致を確認 - Memory / MCP 修正: 不完全な memory 読み取りとレコード不在の区別、ディレクトリ走査失敗の分類、memory MCP ping への予約済み
_metaパラメータの受け入れ - Hooks / Windows 互換性:
hooks.jsonが Claude Code の schema 準拠、メタデータを検証済み sidecar へ移設。Windows の linter パスと ESLint 9 をサポート、Windows device ID 欠損への耐性を追加 - パッケージング: コンパイル済み OpenCode payload を npm パッケージに明示的に同梱
- その他: Epic sync のラベルフィルタリング、Rails スキル検出・請求書税計算順序の修正、Serply / Squish カタログエントリの削除
破壊的変更
- 明示的な破壊的変更はなし(
councilスキルはカタログ名衝突回避のため pi/core 内でecc-councilとして同梱)
原文(Release Notes)
ECC 2.2.2
ECC 2.2.2 adds
pi/core, a curated Pi-native skills+prompts-only profile built for downstream packagers that mirror GitHub Releases, plus a set of packaging, memory, hooks, and Windows compatibility fixes.Pi core profile
pi/core/is a self-contained package (ecc-pi-core) that downstream mirrors of the release tarball can copy directly: no build step, no extensions, no hooks, no runtime downloads, and no network or SaaS dependencies.
- 123 curated skills (language and framework patterns, testing/TDD, code review, non-offensive security review, planning, refactoring, docs, and git/PR workflows) and 24 prompt commands that are pure prompt workflows.
- Generated deterministically from the explicit include/exclude lists in
manifests/pi-core.jsonbyscripts/build-pi-core.jsand committed, so the release tarball contains it verbatim.pi/core/CURATION.mdlists every excluded skill and command with its reason; thecouncilskill ships asecc-councilinside pi/core to avoid catalog name clashes.- The build fails on safety violations: non-allowlisted URL hosts, pipe-to-shell or fetch-and-run download forms, secrets or tokens, absolute per-user home paths, symlinks, invalid SKILL.md frontmatter, and duplicate skill names.
- CI rebuilds pi/core on every PR and verifies it is up to date, then installs the Pi coding agent CLI and proves the profile loads fully offline (
PI_OFFLINE=1), asserting that every curated command actually registers.- The release workflow additionally verifies that
VERSIONmatches the tag and that pi/core is current before publishing.Downstream consumption: poll
/releases, downloadarchive/refs/tags/vX.Y.Z.tar.gz, pin its sha256, copypi/core/, and load it offline withpi --offline --skill pi/core/skills --prompt-template pi/core/commands.Packaging
- The compiled OpenCode payload is explicitly included in the npm package, and packing is verified from a clean state with lifecycle scripts enabled.
Memory and MCP
- Incomplete memory reads are distinguished from missing records, and directory traversal failures are classified.
- The reserved
_metaparameter is accepted on memory MCP ping requests.Hooks and Windows compatibility
hooks.jsonstays within Claude Code's schema; stable hook metadata moved into a validated sidecar.- The no-verify guard handles stuck optional values and long-option prefixes.
- Windows linter paths and ESLint 9 are supported, and settings updates tolerate missing Windows device IDs while retaining full-precision inode checks.
Workflow guidance, catalog, and dependency security
- Epic sync filters issues by label; dependency bumps no longer document auto-merge; naming and Boolean guidance is language-neutral; the
prp-prcommand alias is distinguished; Rails skill discovery, invoice tax calculation order, and framework documentation were corrected; Serply and Squish catalog entries were removed.lruupdated to 0.18.2 (RUSTSEC-2026-0253) andjs-yamlto 4.3.2 (GHSA-2883-xcg3-v3hh).