
ImageAI's Sprite CLI ships, and we closed 23 review findings
Four PRs this week: a full Sprite CLI for ImageAI (v0.49.0), a 23-finding auth and chat cleanup in the ChameleonLabs app, a tilde bug in our PR reviewer and an automated docs refresh.
Four PRs merged the week ending 2026-09-12
One of them is big (the ImageAI Sprite CLI), one is the kind of cleanup nobody sees but everybody benefits from, and two are small fixes to the machinery that keeps us honest. Here's what shipped.
ImageAI: the whole Sprite workflow, from the command line
ImageAI 0.49.0 landed with a complete Sprite CLI. Everything you could do in the Sprite tab (create a project, edit it, generate frames, process them, export) now runs without opening the GUI. There are 36 named operations, and each one exposes a JSON request schema and returns machine-readable results. So you can script it, pipe it or hand it to an agent and let it do the work.
A few things we care about here. The CLI uses the same project format and the same core processing as the Sprite tab, so a project you start on the command line opens in the GUI and vice versa (no second code path that drifts). All seven export formats and all eight engine presets are covered. Frame undo/redo is persistent, media replacement is transactional, and the project writer takes a lock so two processes can't clobber each other's saves.
We're a little nerdy-proud of this one. 🤓 That's what makes it something you can build on. Would you use a sprite pipeline that runs headless? We'd like to know.
ChameleonLabs: 23 review findings, closed
We ran a full-codebase review of the ChameleonLabs app and came out with 23 findings, plus the authentication-cookie disclosures from #306. PR #307 fixes all of them in one pass. The short version of what changed:
- Auth now enforces OAuth verification, onboarding and referral app identity where it didn't before.
- Chat respects project and model boundaries, and turn accounting is durable.
- Workflow attempts are correlated, so you can trace one run end to end.
- Course rendering, quota display and embedded chat flows are repaired.
The remediation includes regression coverage, so the findings stay fixed. Reviews like this aren't fun to read. Closing them is.
Two fixes to the machinery
Small bug, real lesson. Our automated PR reviewer stopped running inside the actual repo clone. Root cause: two config sources defined the clone root. The service unit's CODE_DIR drove the sync and clone steps. The backend's YAML code_dir drove the review's working directory. The YAML value was ~/code, and nobody expanded the tilde. So it stayed relative to the service's working directory, the backend found no clone there and fell into a mkdir fallback that only existed for tests. The review never ran in the repo clone.
PR #304 expands the path and closes #303. The real fix is the one we keep relearning: one setting, one source. Two places for the same value will drift.
PR #299 is a docs refresh from cl-librarian, our automated doc bot. The ModelPicker component changed, so the librarian regenerated the user-facing docs that mention it. Nobody had to remember. That's the whole point.
Thoughts on any of this? Send them.
