Repository navigation
Releases: Andarius/trame
Release list
v0.13.0
What's Changed
- feat(web): Notion-style selection toolbar by @Andarius in #60
- feat(web): Enter splits list items; stories drag between projects by @Andarius in #61
- feat(watch): page-scoped comment watchers, started from the page header by @Andarius in #62
- feat(hub): merge same-title duplicate projects on push by @Andarius in #63
- feat(specs)!: session specs become real pages (protocol 4) by @Andarius in #64
- feat(web): story status drives sidebar, pickers and board lanes by @Andarius in #65
- feat(cli): tramecli — one compiled agent CLI by @Andarius in #66
- refactor(mcp): page/comment tools delegate to the tramecli writers by @Andarius in #67
- feat(cli): tramecli-only agent docs — /trame:watch installed and curl-free by @Andarius in #68
- chore!: drop the migration shims and dead compat paths by @Andarius in #69
- docs(cli): comment help states the meta stats requirement by @Andarius in #70
- fix(setup): always point tramecli at the build it just compiled by @Andarius in #71
- feat(page): dated {{trame:...}} marks on todo lines by @Andarius in #72
- chore(watch): drop the .plan-trame.json fallback by @Andarius in #73
- chore: release v0.13.0 by @Andarius in #74
Full Changelog: v0.12.0...v0.13.0
v0.12.0
What's Changed
- feat(deployments): show the commits behind each pending deploy by @Andarius in #43
- feat(page): interactive markdown lists + safer block editing by @Andarius in #44
- feat(sessions): full-screen ticket view with specs, filters and agent marks by @Andarius in #45
- feat(sessions): {{tab}}/{{fold}} spec sections, specs exposed to agents by @Andarius in #46
- feat(page): {{tab}} strips and {{fold}} accordions with slash commands by @Andarius in #47
- feat(sessions): session <-> page-item links by @Andarius in #48
- feat(comments): agent comments always name their model by @Andarius in #49
- fix(web): PrChip cache TTL + truncating labels; drop dead prState by @Andarius in #51
- fix(comments): normalize the meta.model fallback; skill documents required meta by @Andarius in #54
- chore: release v0.12.0 by @Andarius in #55
Full Changelog: v0.11.0...v0.12.0
v0.11.0
What's Changed
- feat(udb): full-width page databases, cleaner cell expand buttons by @Andarius in #41
- chore: release v0.11.0 by @Andarius in #42
Full Changelog: v0.10.0...v0.11.0
v0.10.0
v0.10.0 — sync v3 page tree, AI sessions, database display upgrades
The project is now trame (repo, data dir, remote), the legacy
clients/objectives model is gone, and everything anchors to the one pages tree.
Sync v3 & page tree
- Sync protocol 3: the frozen
clientsentity andobjective_idcolumns
are dropped; hubs and other machines must update before sync resumes. - Sidebar roots split into Projects / Shared with me / Unfiled; pages owned
by another hub user group apart. - Page writer merges revised Markdown into existing blocks so unchanged blocks
keep their ids (and comment anchors); pasted-image assets served from
/api/assets/<id>;/trame:plan-*commands for the plan feedback loop. - Project pages roll up sessions from their child stories.
AI Sessions
- Claude Sessions becomes AI Sessions: browse local transcripts from any
LLM agent CLI, with a source picker, brand icons, per-project colors, and
one-click filters on project, status, and source. - Resume is copy-to-clipboard of the resume command (terminal launchers
removed); ghostty/KDE tab quirks fixed along the way.
Databases
- Units on numbers — fixed suffix (
2.1 s) or resolved per row from a
sibling select/text column (e.g. a Currency column). - Value-dependent color — fixed swatch, continuous good→bad scale (auto or
manual range, low/high-is-good), or threshold rules; applied as tinted text,
pill, dot, cell wash, or the bar/ring fill. - Hidden columns per view tab — ⊟ Columns popover + Hide in the column
menu; hidden columns keep working in filters, sorts, and formulas. - Full-text modal — text cells expand into a markdown modal with
click-to-edit.
Pages & editor
- Markdown rendered in page text blocks; bare PR/MR links become state
chips (GitHub + GitLab viaglab, including stacked-PR detection). - Pill color autocomplete when typing
{{in page blocks. - Light mode.
Docs & install
- Docs move to an Astro Starlight site (
docs-site/,just docs) with guided
data-model and sync-flow walkthroughs; release notes live there too. - Curl-able quickstart script installs the packaged release per platform.
v0.9.0
v0.9.0 — HTML blocks: interactive docs inside pages
Pages can now embed self-contained interactive HTML documents — option pickers,
forms, little tools — rendered live, with a data channel back to the page.
HTML blocks
/htmlin the page editor: paste a complete HTML doc or import a.html
file. Rendered in a sandboxed iframe (allow-scripts, never
allow-same-origin): scripts run, but the doc has no cookies, no app API, no
parent DOM, no network identity. 512 KB doc cap with a clear error.- Data back: the doc calls
window.trame.send(data)and the result is
persisted on the block (64 KB cap), synced like any page edit, and shown as a
datachip in the block header (hover to inspect, click to copy). On reload
the block replays saved data via atrame:initevent so the doc restores its
state. - Sizing: auto-height via the bridge; drag the strip under a block to pin a
height,autoto unpin.
Agents
trame_html(MCP): drop an interactive doc onto a page — append, replace
an existing block, or create a new page around it.trame_html_datareads
back what the user picked. An agent can now ask a visual question and read the
answer — no clipboard round-trip.
Public links
- HTML blocks render in shared
/l/<token>pages through the same sandboxed
iframe with auto-height. The data-back channel is off there — public viewers
see the doc, they can't write to the block.
v0.8.0
What's Changed
- feat(hub): route share links through the host's Traefik by @Andarius in #24
- fix(hub): route share links by PathPrefix (front proxy rewrites Host) by @Andarius in #25
- feat: agent review comments, watcher, presence & any-model attribution (v0.8.0) by @Andarius in #26
Full Changelog: v0.7.0...v0.8.0
v0.7.0
v0.7.0 — public shareable links
Share a page with anyone via a plain URL: a read-only browser view of the page's
subtree — no account, no app install. Complements v0.6's guest sharing (which stays
the path for people who should edit and comment).
Links
- Create + copy from the Share modal: mints a capability URL (
…/l/<token>);
revoke from the same place — the URL stops working on the next sync pass. - What visitors see: the page and its sub-pages (navigable), text/heading/todo
blocks, and attached databases as tables. Comments and folder blocks are never
rendered. Server-side HTML, escaped,noindex. - Security by construction: only the sha-256 of the token is stored or synced;
links are served by a dedicated hub port (:8444) whose only routes are/l/*—
the reverse proxy you point at the internet can never reach the sync API. - Pretty domains: set
linkBasein settings.json (orTRACKER_LINK_BASE) and
copied links use your public domain; front the hub's :8444 with any reverse proxy
that holds a real certificate (a Synology's Let's Encrypt cert works nicely).
v0.6.0
v0.6.0 — share pages with guests
Trame becomes multi-user: invite a guest and share individual pages with them — live,
not as a file. Guests see exactly what you share (the page, its sub-pages, comments, and
attached databases) and nothing else; edits and comments flow both ways in seconds over
the v0.5 realtime sync. Members are unaffected: your own devices still see everything.
Sharing
- Share modal on every page: grant a guest viewer (read-only) or editor
(edit + comment + database rows) access to the page's subtree; change the role or
revoke from the same place. Revoking purges the guest's local copy on their next sync. - Guest onboarding is one command on the hub:
docker exec tracker-api deno run -A --config /srv/hub/api/deno.json /srv/hub/api/main.ts invite "Name" their-node-id
— prints a token they drop into their settings.json alongside the hub URL. - Enforced at the API, both directions: guests pull only granted subtrees (grants
arriving late back-fill history; revocations tombstone it away), and every push is
authorized per mutation — viewers can't write, editors only inside their subtrees,
and comment authorship is pinned to the caller. - Comments everywhere now carry the author's synced profile identity.
Also
- The direct Postgres port is gone from the default hub topology (laptops sync
exclusively through the authenticated API since v0.5);just psqltunnels over ssh. mintbinds a device to its user on the hub — required under access control, and it
removes the client-side claim (fresh installs bind correctly before their first sync).- The old file-based page sharing is still there, renamed Export.
v0.5.0
v0.5.0 — realtime sync through a hub API
The hub grows from "just Postgres" into an API server in front of Postgres — the
foundation for multi-user collaboration (design: docs/hub-api.md). Sync can now ride an
authenticated HTTPS changeset protocol with realtime push, while the existing
direct-Postgres path keeps working unchanged: both transports coexist, per device,
behind a flag.
Realtime sync (opt-in)
- Hub API server (
hub/api, Deno + Hono beside the Postgres container): a versioned
POST /sync— mutations up, changes down — with per-device opaque bearer tokens and
TLS terminated by Deno using the existing private-CA certs. Mint a device token on the
hub, setsyncViaApi/hubApi/hubApiTokeninsettings.json, and the 15s sync rides
the API instead of raw SQL. Default off — nothing changes until you opt in. - WS nudges: the API listens to Postgres once and pushes "something changed" over a
WebSocket; the app then syncs immediately. Edits from another device appear in ~2s
instead of on the next poll. The socket carries no data — a dropped connection costs
latency, never correctness — and the poll stays as the fallback. - Writes push fast too: a local edit schedules a sync ~1.5s later (debounced), so
device-to-device latency is seconds in both directions. - Change log: every write on hub and laptops is captured by triggers into a
change_log(monotonic revision = the API's pull cursor). Legacy direct-SQL writes are
captured the same way, so mixed fleets stay consistent during the transition.
Identity
- Users and devices are first-class: a synced
usersprofile (name/avatar) and a
devicestable mapping each machine to its user. Comments now carry a durable
author_idand pages anowner_id, backfilled for existing data. Setting "Your name"
in ⚙ Settings updates the synced profile — other machines render it even before
configuring their own.
Configuration
TRACKER_CLIENTSenv var replaces the hardcoded client-name mapping used by the
session importers and/trame:track(empty → everything files under Side-projects).
Deploy
hub/deploy.shnow re-applies the idempotentschema.sqlon every deploy (schema
changes finally reach an existing hub) and restarts the API container so it picks up
the copied source. The compose stack gains thetracker-apiservice on:8443,
DB access scoped to the docker subnet inpg_hba.
v0.4.1
v0.4.1 — security hardening and data-integrity fixes
A patch release for v0.4.0: it closes two credential/CSRF holes in the local API and the
deployments plugin, and fixes several ways the new features could lose or hide data.
Recommended for everyone running v0.4.0, especially with the deployments plugin enabled.
Security
- Forge credentials are bound to their host.
GITLAB_TOKENand theglabCLI could be
borrowed by a caller-supplied base URL, so a request naming an arbitrary host was answered
with the token in aprivate-tokenheader. Ambient credentials now only apply to the host
you configured; a custom host must carry its own token. (v0.4.0 bound the saved PAT — this
completes it for the environment and CLI paths.) - The local API rejects cross-origin requests.
/apispawns terminals, opens files and
approves deployments; a page on another origin couldn't read the response but could still
fire the side effect (including via DNS rebinding). Cross-origin is only ever asserted,
never assumed: the/trame:trackwriter, the MCP server and other header-less clients are
unaffected, as is the Vite dev proxy.
Fixes
- Deleting a board column no longer hides later cards. The session default, the Claude/Codex
importers and the tracking skills all emit fixed keys (active…); an unknown key is now
remapped to a surviving column instead of leaving the card in no column at all. - Two devices adding the same column converge. Status ids are derived from their key (the
same reason the built-ins ship with fixed ids), so offline nodes no longer fork duplicate
columns on sync. Re-adding a deleted column revives it. $trame-track//trame:trackinstall correctly for everyone. The writer path is now
substituted for your checkout at install time —just install-cmd/just install-skill
(don't copy the files by hand).- Page sharing keeps databases usable. Imported view tabs had their sorts, filters,
group-by and aggregates silently dropped because they still referenced the exporter's
property ids; every reference is now remapped. Project colors also survive the round-trip. - Deleting a page deletes its inline comments instead of leaving them synced and readable.
- The deployments panel fills as soon as you enable the plugin, rather than sitting on
"Loading…" until the next idle poll (up to 5 minutes). - Un-ignoring a Claude session sticks — the pre-0.4 ignore list is cleaned up too.
- A comment on a page's last remaining block no longer orphans.
- The Claude session hook serializes its writes, so two prompts landing at once can't drop
another working directory's entry.
Tests / CI
deno test now runs in CI (and just ci) — it was added in v0.4.0 but gated nothing. New unit
coverage for the cross-origin guard, credential host-binding, status remapping and identity,
and the page-share view/color round-trip.
Upgrading
No migration; no schema change.