Releases: AgentFeedback/agentfeedback
Release list
v3.0.0: AgentFeedback: new home, new names, fresh start
The project moved to github.com/AgentFeedback/agentfeedback
and is the open-source, self-hostable AgentFeedback
(agentfeedback.dev); a hosted version with the
same API runs at agentfeedback.io. Every name
changes and v3 is a fresh start: no migration from or compatibility with
2.x deployments and skill installs. The HTTP API (1.1), payloads and hash forms are unchanged.
- Skills
agent-feedback→agentfeedback4.0 and
agent-feedback-triage→agentfeedback-triage3.0: new directory and
invocation names (/agentfeedback-triage). Client environment variables
keep their names (AGENT_FEEDBACK_*); the spool moves to~/.cache/agentfeedbackand triage digests to
${TMPDIR:-/tmp}/agentfeedback-triage/. The skills work against a
self-hosted service orhttps://api.agentfeedback.io. - Service: Go module
github.com/agentfeedback/agentfeedback; binary
agentfeedback(cmd/agentfeedback,/opt/agentfeedback, runs as user
agentfeedback); imageghcr.io/agentfeedback/agentfeedback; default
database/data/agentfeedback.db; metrics renamedagentfeedback_*
(agentfeedback_submissions_unprocessed,agentfeedback_db_bytes,
agentfeedback_sqlite_busy_total). - Deploy: stack directory
infra/agentfeedback, compose service
agentfeedback, volumeagentfeedback-data, server directory
~/agentfeedback, variablesAGENTFEEDBACK_IMAGEand
AGENTFEEDBACK_BIND_ADDRESS. - Removed: the 1.x PostgreSQL export script and migration and uninstall
docs, and thedocs/agent-usage.mdredirect. - CI lowercases the image name (the org name has capitals).
v2.2.1: Documentation sweep
Docs and skill documentation only; the service and scripts behave as in
v2.2.0.
- Skill
agent-feedback-triage2.1: the optional clustering contract
moved toreference/clustering.md, read only when clustering is used, and
repeated rules were collapsed: SKILL.md is a third shorter per invocation.
Install the whole directory, includingreference/. Resolutions now start
with their verdict (FIXED,INVALID,DUPLICATE-OF-<id>). Fixed: the
close-out commands' path to the sibling skill, digest exit codes, the
meaning ofunchangedversusupdated, and cluster.py's statuses, reasons
and exit codes. - Skill
agent-feedback(contract unchanged): corrected themachine
override,--sweepage/lock/outcome behaviour, backlog-warning scope, TSV
column 5,slotsusage, 1xx/3xx outcomes, export digest tools, and added
AGENT_FEEDBACK_TRIAGE_ROOTS. - api.md states its version (1.1), the non-JSON responses and the
include=payloadrow shape. - operate.md: the retention purge runs as root, backups create
their directory,opensslandDEPLOY_DIRare documented, and uninstall
covers the triage variables. CLAUDE.mdroutes to develop.md, the single home for
commands, rules and gates; the README quickstart checks out the latest tag
and keeps an existing key.
v2.2.0: Triage skill renamed; batched, measured clustering
- Skill
feedback-triageis nowagent-feedback-triage2.0. The
invocation name and the install directory change: update installers,
links and prompts that nameskills/feedback-triage, and remove the old
copy (operate.md lists both names). Digests move to
${TMPDIR:-/tmp}/agent-feedback-triage/. No service/API or storage changes. - The triage skill is direct invocation only:
disable-model-invocation: true
(Claude Code) and a description that forbids loading it from phrasing
about the queue. Invoke it as/agent-feedback-triageor by name. - Docs: install guidance for the triage skill, the rule to re-measure after
anycluster.pyprompt, threshold or batching change, and the eval
script's disclosure boundary in security.md. cluster.pybatches comparisons: up to 8 reports per request, every pair
asked once over a shared state, so 24 reports need 15 requests instead of
276 (which exceeded the old cap and skipped advice). One request per pair
remains the fallback for batch sizes below 4 and for chunks over the
model's token budget; a pair too large alone is marked unassessed without
a request. One invalid answer in a batch marks only that pair.--max-pairsis replaced by--max-requests(default 200); the old
flag is rejected because its unit changed. New--batch-size(default 8).- Probability sums tolerate the model's per-option two-decimal rounding.
- Calibration recorded in the skill: on 112 labelled pairs, no different
pair was grouped at the 0.8 threshold; consent, dry-run, key handling and
complete-link grouping are unchanged.scripts/eval-cluster.pyrepeats
the measurement and refuses to send any report whose exact remote was not
approved with--allow-repo. - Go module dependency updates (indirect only).
v2.1.0: Optional advisory triage clustering
- Skill
feedback-triage1.1 adds a Python 3.9+ helper that compares
report mechanisms through TypeSafe and suggests clusters. The manual
workflow remains the default; no service/API or storage changes. - Disclosure requires explicit approval for each exact repository identity.
Preview is local; unapproved or unidentified reports are never sent.
No credential is copied, no queue item is marked, and no report is removed. - Advice retains source IDs, the digest hash and individual probabilities.
Groups require agreement for every member pair, not transitive matches.
Uncertain, unavailable and invalid answers fall back to manual triage;
bounded requests preserve partial results without dropping reports.
v2.0.0: SQLite, generic events, triage skill
Breaking operational contract, compatible API.
- Storage: PostgreSQL replaced by SQLite (
modernc.org/sqlite, pure Go).
One container, one named volume, no database service. Physical backups via
feedback backup, logical viaGET /api/v1/export; restore and migration
viafeedback import(all-or-nothing, header/count/digest verified, hashes
recomputed,--familyfilter, ids never reused). See
operate.md
for the 1.x migration procedure;scripts/export-v1-postgres.shproduces
the import file from a 1.x deployment with ids, timestamps, processing state
and hashes preserved. - API 1.1 (api.md): additive.
familyandpayload_hashon
every record,POST /api/v1/events,resolutionwhen marking processed,
keyset pagination (before_id,has_more,next_before_id,total),
include=payload,GET /api/v1/export, six-digit timestamps. Every 1.0
request and response field is unchanged. - Service: stdlib
net/http, Prometheus with bounded labels plus backlog,
database size and busy counters. OpenTelemetry, chi, sqlc and the
PostgreSQL-specific configuration are gone.GRACEFUL_SHUTDOWN_TIMEOUT
default is now 30s; the fixed 5s drain sleep is removed. Payloads are
returned byte-exact (large integers no longer round). - Deployment:
scripts/deploy.sh <sha>installs the compose file,
preserves the host.env, pins the image there and runsdocker compose pull && up. Requires the GHCR package to be pullable by the host. The
cranestreaming path is gone. - Skill
agent-feedback3.0: newsubmit-event.sh;process.sh list
pages through the whole queue and takes--include-processed(the old
--allerrors),donetakes--resolution;query.sh export;
submit-review.sh --sweepscansREVIEW_LOG_DIRand
AGENT_FEEDBACK_REVIEW_DIRSonly (set the latter where hardcoded cache
paths were relied on). Fixes: spool persistence is verified (an unwritable
spool now fails loudly instead of reportingspooled), review receipts are
validated before a run is marked submitted, large prose no longer passes
through argv,--dry-runapplies the server's validation, rejected spool
files are kept 30 days as documented. - New skill
feedback-triage1.0: end-to-end queue processing with one
consolidated interview.scripts/digest.shpulls and groups the open queue. - Docs rewritten for agents first: README route table,
api.md,
operate.md,develop.md,security.md. Template-era documents removed;
docs/agent-usage.mdredirects toapi.md.
Upgrade: follow the migration procedure; the 1.x PostgreSQL volume is not
read by 2.x. Producers need skill 3.0 only for the new features; 2.1 clients
keep working against the 2.0.0 service.
v1.0.1: Public documentation and release workflow
Public documentation and release workflow
- Replaced the long README with a 56-line overview and linked setup, security, development, deployment, and operations guides.
- Added guarded annotated-tag/stable-release tooling and documented SemVer publication for every delivered change.
- Updated Go to toolchain 1.27.1, stable Go dependencies, container bases, and GitHub Actions.
- Aligned the service version with v1.0.1 and expanded private environment-file ignores.
Compatibility
No API or database migration changes. Companion skill version 2.1 is unchanged. Back up before upgrades; deploy the CI-published commit-SHA image (source release tags are not container tags).
Verification
Local service check gate, PostgreSQL-backed race/integration tests, 55 hermetic client checks, and 35 live HTTP checks passed. The documented Compose build/start, first submission/list, readiness, and teardown were exercised in isolation. Publication tooling requires successful CI on this exact commit before tagging.
Publication audit
Reachable history was checked for secrets, unintended private details, and AI authorship attribution. No additional sensitive content requiring a rewrite was identified; v1.0.0 remains unchanged. Scanning cannot establish the absence of all secrets, and existing clones/caches cannot be erased by a history rewrite.
v1.0.0 initial release
First stable release of agent-feedback: a self-hosted Go/PostgreSQL inbox for AI coding-agent review results and tooling/documentation friction reports.
Included
- JSON REST API for immutable submissions, deduplication, filtering, retrieval, and processed-state tracking.
- Companion Bash skill with credential redaction, local failed-write spooling, recovery, and querying.
- Public setup and API documentation, deployment configuration, backup/recovery guidance, and MIT licensing.
- Linux/amd64 and Linux/arm64 container builds.
Verification
The tagged commit passed CI: formatting/vet/build and generated SQL cleanliness, PostgreSQL race/integration tests, live HTTP contract checks, ShellCheck, hermetic client tests, and multi-architecture container publication.
CI: https://github.com/foae/agent-feedback/actions/runs/34053149811
Deployment
This service is intended for a single trust domain, not an internet-facing multi-tenant service. Read the README security and privacy guidance before collecting real telemetry. The companion skill has its own version number.
Container image for this release: ghcr.io/foae/agent-feedback:e7069aa265122aa4865993ae016760d0874b65b0
Known maintenance item
GitHub Actions reports Node.js 20 deprecation warnings for existing action versions; all jobs passed. Updating those action versions is separate from the readiness fix.