What's Changed
- ci: bump the actions group with 2 updates by @dependabot[bot] in #261
- deps: bump github.com/aws/smithy-go from 1.27.1 to 1.27.2 in /services/audit in the gomod group across 1 directory by @dependabot[bot] in #259
- deps: bump uuid from 14.0.0 to 14.0.1 in the npm-production group by @dependabot[bot] in #260
- release-validation: v2026.06.20-rc.1 report by @RAWx18 in #262
- chore(playbooks): align Codex mapping output with claude-code and copilot by @Ashutoshx7 in #264
- feat(#206): tighten GitHub Copilot mapping playbook guidance by @Ashutoshx7 in #263
- deps: bump knip from 6.17.1 to 6.17.2 in the npm-development group by @dependabot[bot] in #266
- deps: bump the gomod group across 3 directories with 1 update by @dependabot[bot] in #265
- deps: bump the npm-production group with 3 updates by @dependabot[bot] in #267
- feat(#225): make Inkwell OCR look like a real document-AI platform by @Ashutoshx7 in #268
- feat: enhance OpenAI Codex policy playbook (#210) by @Mohammad-Ali-Haider in #269
- deps: bump the npm-development group across 1 directory with 15 updates by @dependabot[bot] in #276
- ci: bump the actions group with 7 updates by @dependabot[bot] in #273
- deps: bump the gomod group across 2 directories with 2 updates by @dependabot[bot] in #272
- deps: bump the docker group across 3 directories with 3 updates by @dependabot[bot] in #271
- deps: bump the npm-production group across 1 directory with 9 updates by @dependabot[bot] in #275
- fix(web): verify clipboard write before confirming copy (#281) by @Ashutoshx7 in #305
- test(engine): assert dispatcher handler parity with the catalog (#296) by @Ashutoshx7 in #309
- fix(api): degrade gracefully on unparseable STS responses (#294) by @Ashutoshx7 in #310
- fix(infra): remove temp pgpass file on migrate exit (#297) by @Ashutoshx7 in #308
- fix(infra): isolate and clean up Helm validate temp artifacts (#299) by @Ashutoshx7 in #306
- fix(go): propagate caller context through the verification flow by @Ashutoshx7 in #312
- fix(web): add consistent focus-visible rings to interactive controls by @Ashutoshx7 in #311
- fix(web): announce DataTable sort state with aria-sort/aria-label (#284) by @Ashutoshx7 in #313
- fix(infra): cap CPU/memory on runtime-compose app services (#298) by @Ashutoshx7 in #307
- fix(gateway): generate traceparent independently of request ids by @Mohammad-Ali-Haider in #301
- fix(audit): count persisted replay files after dir sync errors by @leemeo3 in #315
- fix(web): keep application rename failures recoverable by @ahfoysal in #316
- fix(testing): handle Go test runs when race detection is unavailable by @Mohammad-Ali-Haider in #317
- deps: bump the pip group across 1 directory with 2 updates by @dependabot[bot] in #319
- deps: bump the gomod group across 2 directories with 4 updates by @dependabot[bot] in #321
- deps: bump the npm-development group with 10 updates by @dependabot[bot] in #322
- ci: bump the actions group with 9 updates by @dependabot[bot] in #320
- deps: bump the npm-production group with 11 updates by @dependabot[bot] in #323
- fix(fastmcp): preserve auth error hints by @Mohammad-Ali-Haider in #318
- deps: bump the gomod group across 1 directory with 2 updates by @dependabot[bot] in #325
- fix(sdk): include governed transport options in cache key by @Mohammad-Ali-Haider in #324
- refactor(web): centralize Console API error classification (#283) by @Ashutoshx7 in #314
- fix(ts-sdk): contain gateway authority to base path by @Mohammad-Ali-Haider in #326
- Fix ts empty application labels by @Mohammad-Ali-Haider in #327
- deps: bump the docker group across 3 directories with 3 updates by @dependabot[bot] in #328
- ci: bump the actions group with 4 updates by @dependabot[bot] in #330
- deps: bump the gomod group across 5 directories with 5 updates by @dependabot[bot] in #329
- deps: bump the npm-development group with 8 updates by @dependabot[bot] in #331
- deps: bump the npm-production group with 5 updates by @dependabot[bot] in #332
- deps: bump the docker group across 2 directories with 3 updates by @dependabot[bot] in #358
- deps: bump the npm-production group with 5 updates by @dependabot[bot] in #362
- deps: bump the gomod group across 1 directory with 3 updates by @dependabot[bot] in #359
- deps: bump the npm-development group with 8 updates by @dependabot[bot] in #361
- fix(runtime): exit cleanly after readiness checks by @Mohammad-Ali-Haider in #357
- ci: bump the actions group with 10 updates by @dependabot[bot] in #360
- deps: bump the docker group across 2 directories with 2 updates by @dependabot[bot] in #373
- deps: bump the npm-production group with 14 updates by @dependabot[bot] in #377
- deps: bump the npm-development group across 1 directory with 7 updates by @dependabot[bot] in #374
- ci: bump the actions group with 7 updates by @dependabot[bot] in #375
- refactor: rename the Operator's AI "provider" to "model endpoint" by @Ashutoshx7 in #378
- deps: bump the npm-production group with 4 updates by @dependabot[bot] in #379
- deps: bump the gomod group across 1 directory with 4 updates by @dependabot[bot] in #380
- test: assert fail-closed denial of unknown provider kinds in the Go STS by @Ashutoshx7 in #372
- refactor: retire the provider credential plugin manifest spec (#341) by @Ashutoshx7 in #368
- fix: stop mid-stream failover from corrupting the Operator answer stream by @Ashutoshx7 in #371
- fix(api): enforce provider revocation host allowlist by @Mohammad-Ali-Haider in #363
- fix: support spaces in Windows setup paths by @Slo-Pix in #365
- test(sts): tighten unknown provider denial coverage by @Ashutoshx7 in #382
- deps: bump the docker group across 3 directories with 2 updates by @dependabot[bot] in #383
- deps: bump the gomod group across 2 directories with 5 updates by @dependabot[bot] in #391
- deps: bump the npm-production group across 1 directory with 14 updates by @dependabot[bot] in #394
- ci: bump the actions group with 7 updates by @dependabot[bot] in #386
- deps: bump the npm-development group across 1 directory with 13 updates by @dependabot[bot] in #393
- fix: enable bounded Operator provider retries by @Ashutoshx7 in #396
- fix: deprioritize recently failing Operator providers by @Ashutoshx7 in #397
- fix: persist Operator run token usage by @Ashutoshx7 in #398
- test(api): cover governed Operator boot wiring by @Ashutoshx7 in #400
- fix(operator): stop model work on cancelled runs by @Ashutoshx7 in #399
- [Operator] Record passive LLM provider health signals by @Ashutoshx7 in #395
New Contributors
Full Changelog: v2026.06.21...v1.0.0