Skip to content

Releases: BitcoinErrorLog/pubky-app

Shop v0.6.46

Choose a tag to compare

@BitcoinErrorLog BitcoinErrorLog released this 05 Oct 11:32
210f307

Shop v0.6.46

Date: 2026-10-05 (WEST)
Commit: 210f3077a84413d4773ade8697e6c00cb38be776 (release/shop-v0.6.8)
Vercel deployment: dpl_3W4rsYx8o3aioaDRxqaQubdHcxVp — https://pubky-marketplace-production-4jis1q3he-synonymdev.vercel.app
Staging deployment: dpl_qpzEKjgn6iWoXmrFHcHeu5UgGD3a — https://pubky-marketplace-staging-a95cmpek0-synonymdev.vercel.app
Previous production (rollback target): dpl_6WZZ8rfxCHRBizeiDywSVJYiLqwE (v0.6.45)

Included work

  • #187 (pubky-marketplace #67): Messages and the listing conversation no longer wait without limit on the messaging connection check. Saved conversations are listed as soon as the page opens. After 20 seconds, a slow check shows a "taking longer than usual" message instead of a blank placeholder. A retried check joins the one already running. A buyer who never muted anyone no longer sees the missing mute list logged as an error.
  • #187 (pubky-marketplace #70): The address forms for delivery addresses, checkout and pickup details ask for the country first. The country starts at the browser's language region (for example en-GB gives GB) and falls back to US. Saved addresses keep their own country, and address suggestions follow the chosen country.
  • #185: Approving a sign-in in Pubky Ring now completes when you return to the browser, even if the approval took longer than a few seconds.
  • #184: On Android Chrome, the Pubky Ring and Bitkit buttons inside Payment settings now open their apps instead of doing nothing.
  • #183: On browsers that cannot create the Bitkit sign-in or sign-up code, the page no longer shows a "Could not generate QR" error. The Bitkit option offers a reload, and Pubky Ring still works.
  • #186: The mobile edit-listing stepper VRT scene is now deterministic (test only).

Verification

  • Review: Kimi audit of the #187 diff returned SHIP. Its one P2 (a status read that timed out could swallow the republished-key notice) was fixed, and the delta re-audit returned SHIP. The Sol review returned no verdict on two attempts.
  • Release gate: PREPUSH OK 972d4e549fc67caa9adc7834a81ba4d16820523f 655 full. The merged commit has the same tree (d12c2b7).
    • Related unit tests: 486 files and 8,133 tests passed.
    • Linux VRT: 64 specs passed in Chromium and Firefox.
    • CI on #187 passed: all 5 sharded unit-test jobs, vrt-marketplace, vrt-core, the Next.js build, launch-e2e and Code Quality.
  • Staging, with two throwaway staging accounts: 15/15.
    • Country is the first address field, and an en-GB browser starts at GB.
    • A direct conversation opens to the composer, and a sent message is accepted.
    • The saved conversation is listed in 1.1 s, before the sync pass starts. With 1200 ms of added latency per request, it is listed at 11.4 s, before the sync pass's first request.
    • "Message seller" opens its dialog and leaves the loading state in 1.5 s.
    • No mute-list 404 is logged as an error.
  • Production #67/#70 proof (buyer test seat): 9/9.
    • Country is first, and an en-GB browser starts at GB.
    • The marketplace inbox settles in 3.9 s and Messages in 2.6 s.
    • 0 mute-list 404 errors are logged, down from 29 on v0.6.45 in the same run.
    • Sessions were revoked.
    • Before the deploy, the same script on v0.6.45 failed the Country and mute-list checks, so the checks discriminate.
  • Signed-in production release proof: 25/26.
    • Ring and Bitkit sign-in, Activity and sign-out all passed, and every run session was revoked.
    • Step 4 (PayPal checkout fixture) did not run because PAYPAL_TEST_EMAIL was not available to this run.

Known limitations

  • An empty inbox still shows its skeleton until the first sync settles. Only stored conversations are listed early.
  • A brand-new account still logs the 404 for its first settings.json, last_read and v1 private-entry reads. Those are outside #67.

Tester notice

Tester notice: reload is enough. This tag did not change the Dexie version; log out and back in once only if your last visit was on an older Dexie version.

Shop v0.6.45

Choose a tag to compare

@BitcoinErrorLog BitcoinErrorLog released this 01 Oct 15:29
a20e8f8

Shop v0.6.45

Date: 2026-10-01 (WEST)
Commit: a20e8f85b2e33ad9801cdd8ef76ad4d338d101c1
Vercel deployment: dpl_6WZZ8rfxCHRBizeiDywSVJYiLqwE — https://pubky-marketplace-production-av9vx97tn-synonymdev.vercel.app

Included work

  • #181: Passport “Continue with Google” sign-in, enabled by default.
  • #182: contact messaging-key pinning and change warnings; encrypted local message history and queued messages; bounded background synchronization.

Verification

  • Release gate: PREPUSH OK a20e8f85b2e33ad9801cdd8ef76ad4d338d101c1 31 full.
  • Unit suite: 1,065 files / 16,801 tests passed; 2 skipped.
  • Linux marketplace VRT: Chromium and Firefox each passed 53 files / 468 tests.
  • Signed-in production proof: 34/34; Ring and Bitkit sign-in passed.
  • “Continue with Google” opened passport.pubky.app; the popup was closed without approval.
  • Ring sign-in loaded Messages without a key-changed banner. The fresh proof profile had no local existing-contact rows, so an existing-contact conversation could not be exercised.
  • Three signed-in repeat loads reached the first listing in a 273 ms median, 42 ms slower than v0.6.44’s 231 ms median but still below 0.3 seconds.
  • Fixture listings, homeserver records, Nexus records, service projections, payment rail, carts, and all release/performance sessions were cleaned.

Tester notice

Tester notice: reload. This release encrypts existing local message history on first load; reload every other open Shop tab after updating.

Shop v0.6.44

Choose a tag to compare

@BitcoinErrorLog BitcoinErrorLog released this 01 Oct 13:53
59c44ad

Shop v0.6.44

Date: 2026-10-01 (WEST)
Commit: 59c44adb5f82065608510f29e90c32a1a344ac5e
Vercel deployment: dpl_BZVeXJRgJcjjfqWMqZaZP4rFzaiu — https://pubky-marketplace-production-ihadqot19-synonymdev.vercel.app

Included work

  • #179: desktop listing-editor step rails remain pinned below the main header after scrolling.
  • #180 / #64: a buyer’s first message reaches sellers with large or newly changed follower sets; background delivery runs while either person has any Shop page open; queued-message copy explains waits and failures.

Verification

  • Release gate: PREPUSH OK 59c44adb5f82065608510f29e90c32a1a344ac5e 36 full.
  • Unit suite: 1,058 files / 16,640 tests passed; 2 skipped.
  • Linux marketplace VRT: Chromium and Firefox each passed 53 files / 464 tests.
  • Signed-in production proof: 34/34.
  • Production editor rails stayed at the 144 px header offset after scrolling at 1280 px and 1920 px.
  • Three signed-in repeat loads reached the first listing in a 231 ms median (203–251 ms), not worse than the prior 240 ms measurement.
  • No messaging-related request started before the first listing in any measured run.
  • Fixture listings, homeserver records, Nexus records, service projections, payment rail, carts, and all release/performance sessions were cleaned.

Tester notice

Tester notice: reload is enough. Log out and back in once if your last visit was on an older Dexie build.

Shop v0.6.43

Choose a tag to compare

@BitcoinErrorLog BitcoinErrorLog released this 01 Oct 12:22
7d882b1

Shop v0.6.43

Date: 2026-10-01 (WEST)
Commit: 7d882b12d86c0bc903831b4adc60089190fb98e0
Vercel deployment: dpl_EetJjA2XMrGjxn5H3VVpM218fxYV — https://pubky-marketplace-production-43zchx4ei-synonymdev.vercel.app

Included work

  • #172: team handoff documentation, onboarding, repository release scripts, and release runbook.
  • #173: Ring cookie sign-in requests the union of Shop and pubky.app scopes so neither site strips the other.
  • #174: address suggestions wait through the service’s six-second OpenStreetMap budget.
  • #175: social route link-out is available behind NEXT_PUBLIC_SOCIAL_HOST; it remains off because that variable is unset.
  • #176: order cards show “Placed …”; editor step rails use header-aware offsets; Bitkit sign-up and sign-out copy is corrected.
  • #177: marketplace sign-out cards distinguish Ring and grant sign-out behavior.
  • #178: a listing publish acknowledged by the homeserver is not reported as failed while read-back catches up.

Verification

  • Release gate: PREPUSH OK 7d882b12d86c0bc903831b4adc60089190fb98e0 28 full.
  • Unit suite: 1,054 files / 16,597 tests passed; 2 skipped.
  • Linux marketplace VRT: Chromium and Firefox each passed 52 files / 460 tests on the final run.
  • Signed-in production proof: 34/34.
  • Ring QR carried the exact union capability set; Bitkit retained the Shop-only grant set.
  • The production order card visibly rendered “Placed …”.
  • Fixture listings, homeserver records, Nexus records, service projections, payment rail, cart, and all run sessions were cleaned.

Known limitation

  • The mobile editor step rail stayed below the 96 px mobile header in the production browser check. The desktop rails did not remain below the 144 px header after scrolling; they measured above the viewport (top=-527). This requires a follow-up despite the isolated and final Linux VRT passing.

Tester notice

Tester notice: reload is enough. Log out and back in once if your last visit was on an older Dexie build.

Shop v0.6.42

Choose a tag to compare

@BitcoinErrorLog BitcoinErrorLog released this 01 Oct 07:51
0942682

Shop v0.6.42

Date: 2026-10-01 (WEST)
Commit: 094268228375a5398cb548b5fcdfcafd259aee04
Vercel deployment: dpl_BwAyyMd6RHfG3Q7d9DFr2Hvdx25T — https://pubky-marketplace-production-al697c7fx-synonymdev.vercel.app

User-visible changes

  • Confirmed-deleted listing pages say “This listing was removed.” Other loading failures retain the generic unavailable message.
  • Messaging retry backoff restarts when a conversation opens, becomes visible, or is retried.

Operator actions

  • Removed NEXT_PUBLIC_VIBE_SESSION_BRIDGE_ORIGIN and NEXT_PUBLIC_VIBE_ID from the Vercel production build environment. Their previous values are recorded in the release evidence for restoration.

Verification

  • Release gate: PREPUSH OK 094268228375a5398cb548b5fcdfcafd259aee04 26 full.
  • Unit suite: 1,047 files / 16,451 tests passed; 2 skipped.
  • Linux marketplace VRT: Chromium and Firefox each passed 51 files / 450 tests.
  • Bridge-aware signed-in production proof: 38/38.
  • Signed-out production reached its first listing in 1,523 ms with zero pubky.app bridge frames and zero bridge requests.
  • Ring cookie sign-in and Bitkit grant sign-in both passed.
  • Deleted listings 676aca2a… and 57e6a861… both rendered “This listing was removed.”
  • Fixture listing, PayPal rail, cart, and every run session were removed or revoked.

Tester notice

Tester notice: reload is enough. Log out and back in once if your last visit was on an older Dexie build.

Shop v0.6.41

Choose a tag to compare

@BitcoinErrorLog BitcoinErrorLog released this 30 Sep 16:15
5fbcfe8

Shop v0.6.41

Date: 2026-09-30 (WEST)
Commit: 5fbcfe80defd3427138ef6cbd78cbfac202e638d
Vercel deployment: dpl_CtNtAxknCEvPWfP3SXC5VnFasbr6 — https://pubky-marketplace-production-jo74zooxq-synonymdev.vercel.app

User-visible changes

  • Repeat marketplace visits no longer wait behind an unused service-worker navigation preload.
  • The catalog is cached for five minutes, seller shop names load in parallel, first-visit precaching is limited to the app shell, and the promo no longer shifts the listing grid.

Verification

  • Release gate: PREPUSH OK 5fbcfe80defd3427138ef6cbd78cbfac202e638d 26 full.
  • Unit suite: 1,045 files / 16,418 tests passed; 2 skipped.
  • Linux marketplace VRT: Chromium and Firefox each passed 51 files / 450 tests.
  • Signed-in production proof: 42/42; fixture listing, PayPal rail, cart, and sessions cleaned.
  • Three repeat-load runs per profile:
    • signed out desktop median to first listing: 216 ms;
    • signed out mobile Fast 4G: 722 ms;
    • signed in desktop: 240 ms, down from 6.9 s;
    • signed in mobile Fast 4G: 712 ms, down from 7.8 s.
  • Signed-in performance sessions were signed out and revoked; audit found zero active sessions from the run.

Tester notice

Tester notice: reload is enough. Log out and back in once if your last visit was on an older Dexie build.

Shop v0.6.40

Choose a tag to compare

@BitcoinErrorLog BitcoinErrorLog released this 30 Sep 15:42
05c4761

Shop v0.6.40

Date: 2026-09-30 (WEST)
Commit: 05c47611c371939ba197fd6f2d6543aadc9b2749
Vercel deployment: dpl_FLrsgHvd1MDSbkPDbLhxMipvws7h — https://pubky-marketplace-production-52bxbpto5-synonymdev.vercel.app

User-visible changes

  • Bitcoin checkout shows a Bitcoin badge, clearer payment-seen status, and an H:MM:SS seller-confirmation countdown.
  • Delete waits for session restoration in a freshly loaded tab.
  • Deleted-listing sync responses are accepted and intended to show “This listing was removed.”

Verification

  • Release gate: PREPUSH OK 05c47611c371939ba197fd6f2d6543aadc9b2749 26 full.
  • Unit suite: 1,042 files / 16,402 tests passed; 2 skipped.
  • Linux marketplace VRT: Chromium and Firefox each passed 51 files / 450 tests.
  • Signed-in production proof: 42/42; fixture listing, PayPal rail, cart, and sessions cleaned.

Production follow-up

  • A real signed-in owner-page check for two deleted proof-seat listings still rendered “Listing unavailable — This listing could not be loaded,” not “This listing was removed.”
  • No proof-seat order currently has a live Bitcoin seller-confirmation deadline, so the production countdown check remains unverified without fabricating a payment event.

Tester notice

Tester notice: reload is enough. Log out and back in once if your last visit was on an older Dexie build.

Shop v0.6.39

Choose a tag to compare

@BitcoinErrorLog BitcoinErrorLog released this 30 Sep 14:49
aaa0070

Shop v0.6.39

Date: 2026-09-30 (WEST)
Commit: aaa0070841cfe9e4258f8f0fa4fd53bab3115b03
Vercel deployment: dpl_2SCYUzhTeHJoqzeypSNgspDZogcE — https://pubky-marketplace-production-36hi9evdc-synonymdev.vercel.app

User-visible fixes

  • Publishing and editing accept default optional values: blank region, Final sale, and no item specifics.
  • Deleted listings are not re-registered for checkout when an owner page opens. Registration is serialized per listing and missing records stop retrying until saved again.
  • /llms.txt advertises the live marketplace Nexus index.

Operator actions

  • Requires marketplace-service 14dca9c0fd1c2524ac99faa5be32791cd416af84, deployed in production.

Verification

  • Release gate: PREPUSH OK aaa0070841cfe9e4258f8f0fa4fd53bab3115b03 29 full.
  • Unit suite: 16,374 passed and 2 skipped; two unrelated load-sensitive timeouts passed twice when each file ran alone.
  • Linux marketplace VRT: Chromium 51 files / 450 tests passed. Two unrelated Firefox MarketplaceSell timeouts passed twice when that file ran alone.
  • Signed-in production proof: 42/42.
  • Production composer published the proof fixture with region blank, default Final sale, and no item specifics.
  • /llms.txt points INDEX at nexusd-production-7108.
  • Fixture listing, PayPal rail, cart, and every run session were removed or revoked; Shop, Nexus, service projection, payment-config, and session checks passed.

Tester notice

Tester notice: reload is enough. Log out and back in once if your last visit was on an older Dexie build.

Shop v0.6.38

Choose a tag to compare

@BitcoinErrorLog BitcoinErrorLog released this 30 Sep 10:55
13dd76c

Shop v0.6.38

Date: 2026-09-30 (WEST)
Commit: 13dd76c3090fa1a94f1978b6848a33cf2e6476aa
Vercel deployment: dpl_ACrPmDrNEWQGk4M3G6PqVkVGJpu3 — https://pubky-marketplace-production-a4flnu9qj-synonymdev.vercel.app

User-visible fixes

  • Address line 1 now suggests addresses from OpenStreetMap data in checkout, saved addresses, and seller pickup settings. The browser contacts only the marketplace service, OpenStreetMap is credited, and manual address entry remains available.

Operator actions

  • Requires marketplace-service 14dca9c0fd1c2524ac99faa5be32791cd416af84, deployed in production.

Known limitations

  • Deleted-listing re-registration handling is scheduled for Shop v0.6.39 and is not included.

Verification

  • Release gate: PREPUSH OK 13dd76c3090fa1a94f1978b6848a33cf2e6476aa 0 full.
  • Unit tests: 1,040 files; 16,306 passed; 2 skipped.
  • Linux marketplace VRT: Chromium 51 files / 450 tests and Firefox 51 files / 450 tests.
  • Signed-in production proof: 42/42.
  • Buyer-seat checkout showed suggestions from POST /v0/address/suggest and retained manually typed address text.
  • Fixture listing, PayPal rail, carts, and every run session were removed or revoked; Shop, Nexus, service projection, payment-config, and session checks passed.

Tester notice

Tester notice: reload is enough. Log out and back in once if your last visit was on an older Dexie build.

Shop v0.6.37

Choose a tag to compare

@BitcoinErrorLog BitcoinErrorLog released this 30 Sep 05:54
e6cebae

Shop v0.6.37

Date: 2026-09-30 (WEST)
Commit: e6cebae1cff520a6bd5ed650dedd179e041d7c11
Prior release: shop-v0.6.36 (b6da31b211401fccb0fe55d599b75f732211f2cf)
Prior production deployment: dpl_b1bh2udVKp2xVdE3EtqXTp5ZjaHn → https://shop.pubky.app

User-visible fixes

  • Checkout reads seller payment methods as yes/no availability only; a seller PayPal email no longer reaches the browser before the buyer binds PayPal to their own order.
  • Signing out of Shop in one tab, or opening the sign-in dialog in a signed-out tab, no longer deletes a newer sign-in, Seller Studio approval, Lock Server connection, or messaging session another tab saved. Signing out still signs this browser out; switching accounts removes what the previous account left.

Operator actions

  • marketplace-service: Privacy half for payment-config remains pending on service PR #74 (not merged or deployed in this cut).

Known limitations

  • Full service-side payment-config privacy enforcement still depends on deploying marketplace-service after PR #74 merges.

Verification status

  • Local release-head proof: typecheck, lint, unit tests (1040 files / 16281 passed), CI-parity marketplace VRT (102 files / 896 passed, chromium+firefox, Linux baselines matched). Touched-file Prettier clean. Git tree clean at tag SHA.
  • Signed-in production proof: not run in this lane (parent runs release-proof.mjs with PAYPAL_TEST_EMAIL in process environment only).

Tester notice

Tester notice: reload is enough. Log out and back in once if your last visit was on an older Dexie build (this tag did not bump Dexie).