You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
GitHub OAuth support — added GitHub as a sign-in provider alongside Discord (GITHUB_ID / GITHUB_SECRET), enabling GitHub auth for cloud and self-hosted deployments
Notification Providers
Multi-provider notifications — teams can now configure external alerting providers for operational events (email, campaign, domain, and error notifications)
Supported providers — Discord, Slack, Microsoft Teams, Telegram, and Custom Webhook are now supported with provider-specific configuration
Notification provider schema — added NotificationProvider model to store provider type, config, status, and team linkage
Notification log schema — added NotificationLog model to store per-dispatch delivery outcomes and failure details
Notification provider API — added notificationProvider tRPC router with list, getById, create, update, delete, test, getLogs, and getStats
Notification dispatcher services — added provider dispatch and event emission services (notification-provider-service.ts and notification-emitter.ts)
Notifications settings page — added /settings/notifications UI for provider management, testing, logs, and usage guidance
Admin plan assignment flow — added adminAssignPlan to let cloud admins assign plans to teams either as complimentary grants or Stripe checkout-link driven assignments
Admin team billing controls — admin team settings now supports dailyEmailLimit = -1 for unlimited daily sending
Billing / Plan Source-of-Truth
Perks derived from shared plan constants — apps/web/src/lib/constants/payments.ts now generates plan perks from @bytesend/lib PLANS rather than static duplicated data
Billing plan cards from shared plans — /settings/billing plan options now derive from the shared PLANS map to avoid UI/config drift
CI / Automation
Issue summary workflow — added .github/workflows/issue-summary.yml to automatically summarize newly opened issues
Stale cleanup workflow — added .github/workflows/stale-cleanup.yml to clean up inactive issues and pull requests
CodeQL workflow — introduced .github/workflows/codeql.yml and enabled develop branch triggers
JavaScript SDK release workflow — added .github/workflows/npm-release.yml to build and publish the bytesend-js package from packages/sdk changes on main (plus manual dispatch)
Python SDK release workflow — added .github/workflows/pypi-release.yml to build and publish the bytesend-python package from packages/python-sdk on pushes to main and manual dispatch
Community / Governance
Repository security policy — added .github/SECURITY.md with supported versions, private reporting process, and response expectations
Code of Conduct — added .github/CODE_OF_CONDUCT.md (Contributor Covenant v2.1)
Contributing guide — added .github/CONTRIBUTING.md with development workflow, PR expectations, and testing checklist
Support guide — added .github/SUPPORT.md with support channels and security-report routing
GitHub Templates
PR template — added .github/PULL_REQUEST_TEMPLATE.md to standardize change summaries, testing notes, and release-impact checks
Issue template config — added .github/ISSUE_TEMPLATE/config.yml with contact links and blank-issue controls
New issue forms — added .github/ISSUE_TEMPLATE/feature.yml and .github/ISSUE_TEMPLATE/docs.yml
Changed
Plans & Pricing
BASIC plan updated — aligned plan limits/pricing model by setting BASIC to CA$20/mo with 100,000 monthly emails, 30 members, and 12 domains
LIFETIME plan updated — aligned lifetime limits to current plan progression at CA$199 one-time with 500,000 monthly emails, 100 members, and 30 domains
Settings UX
Settings navigation restructured — removed Team inner General/Members subtabs and promoted them to top-level Settings navigation
General tab behavior — /settings now serves as the General overview (team profile and core team settings)
Members tab split-out — members management moved to dedicated /settings/members tab alongside billing/usage-related settings
Usage resource breakdowns — usage view now includes explicit domain, webhook, and member usage breakdowns with limit context
SMTP Server
SMTP server vendored into monorepo — apps/smtp-server is now tracked directly in this repository (no gitlink/submodule-style entry), simplifying versioning and release consistency
Authentication compatibility fallback — SMTP auth now supports the API-driven custom team username flow while retaining a legacy fallback username candidate for older client configurations
Documentation
SMTP docs refreshed for monorepo paths — clone/build/deployment documentation now references NodeByteLTD/ByteSend and apps/smtp-server paths throughout
SMTP quickstart clarified — get-started docs now direct users to use their configured SMTP username (default bytesend) rather than implying only a fixed username
Core docs/readme refresh — updated main README and docs navigation/content pages for current monorepo structure and self-hosting guidance (apps/docs/README.md, apps/docs/docs.json, local/docker/self-hosting guide pages)
Feature docs expansion — added new guides for GitHub OAuth, API authentication, plans/pricing, plan management, admin operations, and notification providers (apps/docs/guides/*)
Mintlify branding refresh — updated apps/docs/docs.json theme colors/navigation and expanded apps/docs/introduction.mdx to surface new billing, alerting, and auth capabilities
References
Internal references expanded — added .references/README.md, smtp-auth-and-operations.md, release-playbook.md, and repository-governance.md
Webhook reference improvements — expanded .references/webhook-architecture.md with operations checklist, common failure modes, and change-safety notes
GitHub Templates
Issue form upgrades — revamped bug/marketing/SMTP templates with clearer triage metadata, reproducibility fields, and validation checkboxes
Workflows
PR labeling workflow rename — renamed the workflow file to label-prs.yml
Label action token update — updated token reference in .github/workflows/label.yml
Website test workflow tuning — adjusted website test workflow behavior
Docker manifest recreation safety — docker publish now removes existing manifests before create, preventing rerun failures on previously published tags
Docker remote tag cleanup — docker publish now removes pre-existing remote tags/manifests with docker buildx imagetools rm before publishing platform images/manifests, avoiding is a manifest list rerun failures
Website tests pnpm version alignment — removed hardcoded pnpm version from .github/workflows/website-test.yml so CI uses the repository packageManager version (pnpm@9.0.0)
Docker publish tag strategy hardening — .github/workflows/docker-publish.yml now publishes ref-aware tags (latest, develop, version tag, and commit SHA) with matching multi-arch manifests
Manual Docker publish branch support — wired workflow_dispatch branch input into checkout and tag resolution so manual runs build/publish the selected branch
Labeler rules refresh — updated .github/labeler.yml to align automated PR labeling with the current repository structure
Actions runtime forward-compatibility — added FORCE_JAVASCRIPT_ACTIONS_TO_NODE24=true across workflows to avoid Node 20 JavaScript action deprecation breakage
Fixed
Suppressions
Suppression removal reliability — improved suppression deletion flow to handle non-canonical casing/inputs more robustly in dashboard and backend paths
Limits / Usage
Usage limit consistency — fixed plan usage limit handling to align dashboard/service behavior with shared plan constants
Marketing Site
Contact CTA destination — changed the marketing contact link from email to Discord
CI / Tests
Domain-service unit test import stability — apps/web/src/server/service/domain-service.ts now initializes DNS resolvers with runtime-safe fallbacks (promises API or callback API), preventing ERR_INVALID_ARG_TYPE when DNS methods are partially mocked in tests
Usage unit test expectation alignment — apps/web/src/lib/usage.unit.test.ts now derives expected costs from exported usage constants instead of stale hardcoded values
Workspace SDK resolution in Vitest — apps/web/vitest.config.ts now aliases bytesend-js to packages/sdk/index.ts during tests so unit suites do not depend on prebuilt SDK dist artifacts
Contact-service unit test isolation — apps/web/src/server/service/contact-service.unit.test.ts now mocks LimitService.checkContactsLimit to avoid transitive TeamService cache dependencies and prevent brittle failures
Campaign security test alignment — apps/web/src/server/api/routers/campaign-security.trpc.test.ts updated for current plan access expectations
SMTP Server
SMTP Dockerfile context compatibility — apps/smtp-server/Dockerfile no longer expects pnpm-lock.yaml in app-only build contexts and now uses an app-local install path that works with the apps/smtp-server Docker build context
SMTP container entrypoint correction — fixed runtime command in apps/smtp-server/Dockerfile to execute dist/server.js from the container working directory
SMTP Docker Corepack compatibility — pinned Docker image pnpm activation in apps/smtp-server/Dockerfile to pnpm@9.0.0 (instead of latest) to avoid Corepack bootstrap/runtime failures in CI builds
SMTP package manager metadata — added packageManager: pnpm@9.0.0 to apps/smtp-server/package.json so Corepack does not auto-inject newer pnpm versions during container installs
Security
SES callback SSRF hardening — apps/web/src/app/api/ses_callback/route.ts no longer fetches user-provided SubscribeURL directly; it now constructs a trusted AWS SNS confirmation URL from validated TopicArn/Token components before issuing the request
SES callback log-safety hardening — replaced ad-hoc request/parse logging in apps/web/src/app/api/ses_callback/route.ts with constant-format structured logs to avoid tainted-format-string risks from untrusted payload fields
SPF verification sanitization fix — apps/web/src/server/service/domain-service.ts now parses SPF TXT mechanisms and validates include: domains (amazonses.com or subdomains) instead of broad substring checks
DKIM key strength upgrade — apps/web/src/server/aws/ses.ts now generates 2048-bit RSA keys (up from 1024-bit)
Stripe seed secret logging removal — packages/scripts/stripe-seed.ts no longer logs any portion of STRIPE_SECRET_KEY
Python webhook example exception exposure fix — packages/python-sdk/example/webhook-test-project/receiver.py now returns a generic verification failure message and avoids exposing exception text to clients
Workflow least-privilege permissions — .github/workflows/website-test.yml now sets explicit permissions with contents: read