for agents/docs/llms.txtv0.7.54 · 11 Oct 2026

Docs / Guides

Update sgit-ai to 0.21.0

A page for an agent, or a person running agents, that has been told "read this and update". Ten minutes. sgit-ai 0.21.0 was published to PyPI on 10 October 2026. It includes everything in 0.19.0 and 0.20.0, so coming from 0.18.0 or older this is the only page you need. Your daily loop does not change: pull, work, commit, push. What changes is what sgit now refuses to do, and a set of history commands you have been missing.

1. Update and check

$ sgit update          # wraps: pip install --upgrade sgit-ai
$ sgit version
sgit-ai v0.21.0

If sgit version still shows an older number, you have more than one Python environment; run python -m pip install --upgrade sgit-ai in the one your harness uses, then check again. Installation has the rest. Your existing clones need nothing: the first command in each one records the server it uses and moves its bookkeeping to the 0.21.0 layout.

2. What now refuses, and what to do

0.21.0 is a security release. Each of these used to work, or work silently and do damage. Each refusal names the file or branch and says what to do; none changes anything before it stops.

You seeWhyWhat to do
warning: skipped symlink <path> on commitsgit never stores, follows or writes through a link. A link to .sg_vault/local/vault_key used to commit the vault key itselfNothing. Commit the real file if you meant to. A tracked file replaced by a link keeps its committed version; status and pull name it
cannot read <file> (Permission denied); nothing was changedA file sgit cannot open used to read as deleted, and a commit removed it for everyoneClose the program holding it or fix its permissions, then run the command again
a refusal naming SGIT_DEFAULT_BASE_URLThe variable used to silently redirect a vault, with your token and write key, to whatever host it namedName the server once: sgit --base-url <url> <command> (the flag goes before a group too), or sgit remote add origin <url>. Vaults made by 0.21.0 already record it
a commit refused over a zip that holds a keyA backup zip (or any zip) holding a vault key or a private signing key would hand it to every readerDelete it, or move it out of the vault folder. sgit commit --allow-secret-file <path> commits one on purpose
a branch named '<name>' already exists on the server on pushA teammate pushed a branch with that name first; yours used to land where nobody could see itsgit branch rename <name> <new-name>, then sgit push
the named branch was REWOUND; push exits 1Someone force-pushed, or the server served an old pointerDo not accept it on your own; tell the vault owner. If it was deliberate: sgit pull --accept-rewind, which keeps your own unpushed commits and drops the removed ones
this vault needs sgit-ai >= X.Y.ZThe owner raised the vault's minimum clientsgit update, then retry
a pull, clone or push refused over an unsigned commitThe vault requires signed commits (signatures-required)Tell the vault owner. If your clone has no signing key (it says UNSIGNED when you commit), clone the vault again
'abcdef1' is not a valid tag name, or a revision refused as ambiguousA tag named like a commit id would shadow itPick another name. For an existing short-hex tag write tag:<name>, or the full commit id
sgit: 'log' is now sgit history log (exit 2)Commands moved into groups in earlier releasesUse the name it prints

3. New commands worth knowing

All local, all safe to try. Every example below is output from 0.21.0 on the live dev server, 11 October 2026.

History, the way git users expect it

$ sgit history log --grep more --stat
  f7a8b9646ae9 (HEAD)  add more  ~1  [blobs:+1]
      M  notes.md

$ sgit history show HEAD~1
commit obj-cas-imm-bb27e943d81d
parent obj-cas-imm-326e87100964
    first notes
+ notes.md  (8 bytes)

Undo, amend, revert

$ sgit history undo
Undone: this clone's head is back at f7a8b9646ae9 (was d9c5d05ea052).
  1 file(s) restored, 0 removed. Run it again to redo; sgit history reflog shows every move.

$ sgit history reflog -n 3
  @{0}  f7a8b9646ae9  2026-10-11 15:54:26  add more  (was d9c5d05ea052)
  @{1}  d9c5d05ea052  2026-10-11 15:54:25  local mistake  (was f7a8b9646ae9)
  @{2}  f7a8b9646ae9  2026-10-11 15:54:09  add more  (was bb27e943d81d)
CommandWhat it doesWhen
sgit history undomoves this clone's head back to before its last move, restoring the files; run again to redoa local commit you regret, before pushing
sgit history reflogevery move of this clone's head (local, last 1,000); sgit history reset <id> brings one backafter a reset, an accepted rewind or a bad merge
sgit commit --amend [-m …]replaces the last commit; refused once it is on the servera typo in the message, a forgotten file
sgit history revert --as-commit --commit <rev>a new, signed commit that inverts an earlier one (git's revert)undoing a pushed change for everyone

Plain sgit history revert still restores files without committing, as before.

Tags, branches, safer force

$ sgit vault tag create v1.0 -m "first release"
Tagged f7a8b9646ae9 as v1.0, signed by this clone.
$ sgit vault tag list
  ✓ v1.0  f7a8b9646ae9  2026-10-11 15:54 UTC  first release

4. If you are the vault owner

Nothing changes for a vault until you raise it. 0.21.0 is the first release where the history-integrity features are safe for a team of writers.

$ sgit vault format --set 2 --min-client 0.21.0 --feature signatures-required
Vault format updated and written to the server.
  …
  Format:      2  (new objects get 32-hex ids)
  Min client:  0.21.0   (this client: v0.21.0)
  Features:    ids-128, signatures-required, signed-since-82bcf306a04a

The whole model (the gate, 128-bit ids, rewinds, signatures) is in History integrity.

5. Mixed teams: 0.20.0 and 0.21.0 on one vault

Clone, pull, commit and push work in both directions, and every commit verifies (checked live on 10 and 11 October). Two things to know:

If anyone on your team is still on 0.20.0 or older: after sgit vault uninit, delete the *__uninit.zip it leaves in the folder before the next sgit commit. On those versions the zip, which holds the vault key, is committed like any other file. 0.21.0 names it so it is never committed, and refuses any zip holding a key.

6. If you want the detail