v1.1.0
Post–1.0.0 release: parallel review pipeline hardening, install-wide ops visibility, findings quality, security triage, and product docs with UI screenshots.
Added
- Parallel specialists + structured rationale → senior verifier — roles on a unit always run
concurrently (Promise.all) with a barrier before the next stage; findings may carry
reasoning(plusevidence.type=reasoning). Verifier is a principal-SWE batch pass
(keep/drop/severity) using rationale + packed context. Migration013_finding_reasoning.sql. - Session timing ledger —
session.audit.timings/metadata.timings: wall clock per pipeline
stage, per unit, rollups (longest stage/unit/specialist,byStageMs, tool time). Session report
Timing / bottlenecks section; worker logsstage=X done …+ end-of-job summary. - Live specialist heartbeats — SSE
specialist_runstarted / running (interval
STEW_SPECIALIST_HEARTBEAT_MS, default 15s) / completed / failed. Session blade Live specialists
banner with per-role elapsed timers. - Platform ops analytics —
GET /v1/platform/analytics?days=N(platform operators) for
install-wide success rate, p50/p95 latency, stage averages, specialist role stats, worker queue,
tokens. UI: Settings → Platform ops (/settings/platform/ops). Distinct from tenant Analytics. - GitHub Code Scanning SARIF upload — PR gate publishes via
code-scanning/sarifs(gzip+base64).
STEW_PUBLISH_SARIF(env → platform runtime → org → default On). Requires code scanning enabled
andsecurity_events: write. - Three-level finding confidence — product
confidence, specialistmodelConfidence,
optionaltokenConfidence(logprobs). UI/SARIF/suggested-fix gate use product confidence.
Migration012_finding_confidence_layers.sql. - Suggested code fixes —
suggestedFix/suggestion/existingCodeon findings; Findings UI,
reports, SARIF, PR comments. Min confidence gateSTEW_SUGGESTED_FIX_MIN_CONFIDENCE(default 0.75).
Migrations011_finding_suggested_fix.sql. - Install-wide platform runtime store —
GET/PUT /v1/platform/runtime-config; org may only
override suggested code fixes when platform policy is Unset. - Product docs —
docs/UI_GUIDE.md(screenshot tour),docs/README.md,
docs/REVIEW_PIPELINE.md, session audit notes; screenshots underdocs/screenshots/(kebab-case).
Changed
- Job queue is Postgres-only — removed file-backed
FileJobQueue/jobs.json.
DATABASE_URLrequired for multi-replica safety; NATS/Rabbit/Pulsar remain optional wake-up brokers. - Specialist timeouts —
STEW_SPECIALIST_TIMEOUT_MS(default 8m); truncated runs emit coverage-gap
findings (steward.specialist_timeout), auditcoverageGaps, UI TIMEOUT ledger — never a silent
clean empty scan. LLM retries:STEW_LLM_MAX_RETRIES+STEW_LLM_REQUEST_TIMEOUT_MS. - Session stage pipeline UI — per-stage durations, live active step, skipped optional stages,
timing bars; audit JSON download only under Review audit (not duplicated on Review report). - Members UI — role capability help; Keycloak vs local create-user copy clarified.
- Runtime UI — Unset / Off / On for booleans; platform vs org scope clearly labeled.
- Codesteward Graph image — default
ghcr.io/codesteward/codesteward-graph. - README — self-host focused; docs links to UI guide + pipeline.
- Local sandbox defaults to in-place repo read (
STEW_SANDBOX_COPY=1for full tree copy).
Fixed
- GitHub clone host — map
api.github.com/GITHUB_API_URLto git hosthttps://github.com
(resolveGithubGitHost); exact hostnames only (no substring SSRF). Hardened clone args
(assertSafeGitArg,--on clone). - Keycloak first install user — first OIDC JIT user on empty store gets
platformAdmin+ product
admin(parity with local bootstrap). - Code scanning triage — crypto temp passwords; Confluence CQL/HTML strip; remove unused
vulnerablediffpackage (GHSA-73rr-hh4g-fpgx); rootSECURITY.md; CodeQL quality cleanups. - Keycloak login path — no fallback to local password form when IdP is configured (break-glass
only/login?local=1). - Workspace GC — delete
{STEW_WORKSPACE_DIR}/{sessionId}clones after terminal status
(STEW_WORKSPACE_KEEP=1to retain). - Container permissions — entrypoint chowns data/workspace volumes for non-root
steward. - LocalSandbox spawn — handle ENOENT; prefer
/bin/bashor/bin/sh; no worker process crash. - Resume UI — failure branding only on terminal status; resume clears prior error.
- CI / release — Trivy 0.72.0; Semgrep GCM
authTagLength; zizmor cache-poisoning fixes;
multi-stage Docker; drop SaaS-billing image from public CI/release; CodeQL action v4. - GitHub connector icon visible on light theme (
currentColor). - Plan-gate UI for audit log / SCIM; SCIM org entitlement; platform GitHub App enforce UX.
Migrations
Operators with Postgres should run migrations through 011–013 (suggested fix, confidence layers,
finding reasoning) if upgrading from 1.0.0:
pnpm migrate
# or: pnpm --filter @codesteward/db run migrateUpgrade notes
- Ensure
DATABASE_URLis set (file job queue removed). - Run DB migrations 011–013.
- Rebuild/redeploy API, worker, and UI images (or
pnpm -r run build). - Optional: set
STEW_PLATFORM_ADMIN_EMAILSfor additional platform operators under Keycloak. - Helm: set image tag
1.1.0(chartappVersionupdated).
Container images
docker pull ghcr.io/codesteward/codesteward:1.1.0
docker pull ghcr.io/codesteward/codesteward/ui:1.1.0App image runs API by default (SERVICE=api). Worker:
docker run --rm -e SERVICE=worker ghcr.io/codesteward/codesteward:1.1.0Images are signed with cosign keyless via GitHub OIDC.
Verify with:
cosign verify ghcr.io/codesteward/codesteward:1.1.0 \
--certificate-identity-regexp 'https://github.com/Codesteward/codesteward/.*' \
--certificate-oidc-issuer https://token.actions.githubusercontent.com