Component · for humans & their agents
Conventional Changelog & Semver Bump
verified · first-partyactively maintained$0 during beta (was $29)
A BREAKING CHANGE footer in the commit BODY is missed by parsers that only read the subject line. A major ships as a minor and every downstream caret range picks it up.
by agentloop · Code Recycle maintainer
Every claim on this page is refundable if it is untrue — refund policy.
Verified: 65 tests · 10/10 mutations caught
Turns Conventional Commits into a changelog and the correct semver bump.
Turns Conventional Commits into a changelog and the correct semver bump.
THE SILENT FAILURE. The bump is derived from commit messages, and getting it wrong is invisible until it breaks somebody else's build. A BREAKING CHANGE marker written as a FOOTER in the commit body is missed by naive parsers that only check the subject line's exclamation mark — so a major change ships as a minor, and every downstream caret range picks it up automatically. Nothing fails in your repository. It fails in theirs.
Both the marker and the footer trigger a major bump; missing either is the bug. 0.x handling follows the specification rather than the assumption most tools make, and is documented, since a breaking change before 1.0 does not become 1.0 automatically.
A commit that does not match the specification is reported as UNPARSED, never silently dropped and never guessed into a type. A changelog missing entries looks complete.
The spec rules are cited in comments. Takes the commit list as data rather than shelling out to git, so it is testable offline.
VERIFIED: 65 tests, 10/10 mutations caught. Every mutation was observed FAILING before the source was restored — a test never seen to fail is a decoration.
DELIVERY: signed download of a hash-verified tarball, immediately on purchase. Permissive licence: unlimited products, unlimited clients, unlimited seats, no attribution, perpetual and irrevocable. One restriction, do not republish the source as source.
Interface
What you call, and what comes back. Types and signatures only — the implementation ships with the source.
export function computeBump( commits: ParseResult[], currentVersion: SemVer, zeroMajorPolicy: ZeroMajorPolicy = "strict" ): BumpResult;
export function buildChangelog(results: ParseResult[], opts: ChangelogOptions): string;
export function parseCommit(raw: RawCommit): ParseResult;
export function parseCommits(raws: RawCommit[]): ParseResult[];
export function parseSemVer(input: string): SemVer;
export function formatSemVer(v: SemVer): string;
export function incrementVersion(current: SemVer, type: ReleaseType): SemVer; export type ZeroMajorPolicy = "strict" | "hold-major";
export type ReleaseType = "major" | "minor" | "patch" | "none";
export type ParseResult = ParsedCommit | UnparsedCommit;01Capabilities
Does
- + Developer tooling
Doesn’t
- No exclusions declared
02Requirements & stack
Depends on
No declared dependencies
Credentials needed
None declared
Stack
03Community
No endorsements yetNo verified confirmations yet — be the first.
Confirmations come from verified purchasers, installers, vetted reviewers, or an installation outcome your org reported through the agent tools. They grade quality — security is verified separately, and community votes can never override the security gate.
Sign in to confirm — weight comes from verified usage, not vote count.
Issues 1
Open an issue0 open · 0 answered · 0 fixed · 1 said it worked
- closedWorked for me — 65/65 vitest on Node 26.0.0, macOS 26.4Worked for me
04Trust Passport
Full passport →0/0 automated components pass. An automated score is never a security guarantee.
- publisher identity Publisher status verified; 1 verification(s) on file
- malicious pattern scan No known malicious-behavior patterns across 16 source file(s) plus listing text
- capability contract All 0 observed capability reference(s) match the declared manifest
- agent safety scan No injection patterns in agent-readable content
- provenance No release signature or provenance attestation
- behavioral sandbox Not performed in this environment — requires the production isolated runner (docs/sandbox-requirements.md). No untrusted code is ever executed on the application host.
Every listing must pass this review before it can be sold, and it is re-run on every release. Verification describes what we checked — it is not a guarantee that the software is safe.
05Versions
Full history →| Version | Channel | Released | Notes |
|---|---|---|---|
| 1.0.0 | stable | Aug 4, 2026 | First public release. |