Releases: blitzcraftlabs/atlas
Release list
Atlas 1.2.1
Atlas 1.2.1
Atlas 1.2.1 is a stable public-contract release. Breaking public CLI, project, upgrade, or distribution contracts requires a major version.
Changes
[1.2.1] - 2026-09-25
Changed
- Ship working Docker build files to generated Atlas consumers and add safe upgrade handling for
repository-level Docker infrastructure. - Harden Atlas distribution builds so clean-room CLI builds prepare required workspace dependencies
and cached builds restore required npm package metadata and legal files.
Security
- Use cryptographically secure Web Vitals session identifiers instead of Math.random() so telemetry
grouping IDs meet security scanning expectations in supported browsers.
Release identity
- Tag:
v1.2.1 - Commit:
f252fe17aa3382d27eb7a41dc11d3af9deac5f59 - Product: Atlas repository/platform snapshot (not independent npm packages)
- SBOM:
atlas-sbom-f252fe17aa3382d27eb7a41dc11d3af9deac5f59.spdx.json(SPDX 2.3 snapshot ofpnpm-lock.yaml)
Support and limitations
- Supported line: current Atlas release plus the immediately previous supported production release.
- No LTS programme at this stage.
- Internal
@atlas/*workspace packages remainprivateand are not published to npm. @blitzcraftlabs/atlasis the public npm package identity. npm distribution occurs after the canonical GitHub Release; registry availability is verified separately. The first npm publication was a human-authenticated publish of@blitzcraftlabs/atlas@1.0.1from canonicalv1.0.1. Later releases use GitHub Actions OIDC / npm Trusted Publishing (release.yml).- This GitHub Release does not include signed provenance, SLSA attestation, or a formal security audit. npm Trusted Publishing attaches npm provenance to later
@blitzcraftlabs/atlaspublishes; that is not a GitHub Release attestation and is not SLSA. - After 1.0, breaking public-contract changes use a major bump. Compatible features use minor; fixes use patch.
License: Apache-2.0. See LICENSE and docs/how-we-build/releases-and-governance.md.
Atlas 1.2.0
Atlas 1.2.0
Atlas 1.2.0 is a stable public-contract release. Breaking public CLI, project, upgrade, or distribution contracts requires a major version.
Changes
[1.2.0] - 2026-09-22
Changed
- Add
atlas enablefor opt-in consumer tooling, and fix first-commit hooks plus Playwright
alignment. Published npm 1.1.0 does not includeenable. This changeset is how that command (and
the consumer-tooling follow-ups) enter the next CLI release. Generated enable invocations keep
<next-cli-release>until this Version PR assigns a version that is not in
CLI_RELEASES_WITHOUT_ENABLE; they pin that assigned CLI forenableeven when a consumer
baseline is still 1.1.0. Doctor/generate stay on the consumer baseline. Do not treatenableas
live on npm until that release is published.
Release identity
- Tag:
v1.2.0 - Commit:
48792f0a8610e2f879d8833c7349714f6b3fa90b - Product: Atlas repository/platform snapshot (not independent npm packages)
- SBOM:
atlas-sbom-48792f0a8610e2f879d8833c7349714f6b3fa90b.spdx.json(SPDX 2.3 snapshot ofpnpm-lock.yaml)
Support and limitations
- Supported line: current Atlas release plus the immediately previous supported production release.
- No LTS programme at this stage.
- Internal
@atlas/*workspace packages remainprivateand are not published to npm. @blitzcraftlabs/atlasis the public npm package identity. npm distribution occurs after the canonical GitHub Release; registry availability is verified separately. The first npm publication was a human-authenticated publish of@blitzcraftlabs/atlas@1.0.1from canonicalv1.0.1. Later releases use GitHub Actions OIDC / npm Trusted Publishing (release.yml).- This GitHub Release does not include signed provenance, SLSA attestation, or a formal security audit. npm Trusted Publishing attaches npm provenance to later
@blitzcraftlabs/atlaspublishes; that is not a GitHub Release attestation and is not SLSA. - After 1.0, breaking public-contract changes use a major bump. Compatible features use minor; fixes use patch.
License: Apache-2.0. See LICENSE and docs/how-we-build/releases-and-governance.md.
Atlas 1.1.0
Atlas 1.1.0
Atlas 1.1.0 is a stable public-contract release. Breaking public CLI, project, upgrade, or distribution contracts requires a major version.
Changes
[1.1.0] - 2026-09-19
Added
atlas initnow ships a portable GitHub Actions workflow at.github/workflows/ci.yml. It runs
on GitHub-hosted Ubuntu (Doctor, lint, typecheck, tests, production build) and is consumer-owned
after generation. It is not Atlas maintainer CI and does not include Playwright E2E.
Changed
- Stabilize reference harness control mutations, keep reset preview cache consistent with server
state, retain Playwright traces on CI failure, and drop unused Next.jsoptimizeCssfrom starter
config so consumer and maintainer CI no longer depend on missing Critters. - Generate a portable GitHub Actions CI workflow in projects created by
atlas init.
Fixed
- Serialize reference harness persona/scenario/reset mutations so completion feedback cannot be
overwritten by overlapping controls or slow users-preview requests. - Remove unused Next.js
experimental.optimizeCssfrom starter and reference apps (it required
critters, which is not a dependency). - Run starter and reference Playwright suites sequentially on both CI runner profiles, and upload
reports/traces for both apps.
Release identity
- Tag:
v1.1.0 - Commit:
c7b81406234929ce6b1237c41b57dc93976fe078 - Product: Atlas repository/platform snapshot (not independent npm packages)
- SBOM:
atlas-sbom-c7b81406234929ce6b1237c41b57dc93976fe078.spdx.json(SPDX 2.3 snapshot ofpnpm-lock.yaml)
Support and limitations
- Supported line: current Atlas release plus the immediately previous supported production release.
- No LTS programme at this stage.
- Internal
@atlas/*workspace packages remainprivateand are not published to npm. @blitzcraftlabs/atlasis the public npm package identity. npm distribution occurs after the canonical GitHub Release; registry availability is verified separately. The first npm publication was a human-authenticated publish of@blitzcraftlabs/atlas@1.0.1from canonicalv1.0.1. Later releases use GitHub Actions OIDC / npm Trusted Publishing (release.yml).- This GitHub Release does not include signed provenance, SLSA attestation, or a formal security audit. npm Trusted Publishing attaches npm provenance to later
@blitzcraftlabs/atlaspublishes; that is not a GitHub Release attestation and is not SLSA. - After 1.0, breaking public-contract changes use a major bump. Compatible features use minor; fixes use patch.
License: Apache-2.0. See LICENSE and docs/how-we-build/releases-and-governance.md.
Atlas 1.0.1
Atlas 1.0.1
Atlas 1.0.1 is a stable public-contract release. Breaking public CLI, project, upgrade, or distribution contracts requires a major version.
Changes
[1.0.1] - 2026-09-19
Changed
- Polish the public launch surface so Atlas 1.0.1 can be the first npm-published version. Canonical
GitHub v1.0.0 remains the immutable first stable platform release.
Release identity
- Tag:
v1.0.1 - Commit:
b69635467f944ee529de84636504ec29864c080a - Product: Atlas repository/platform snapshot (not independent npm packages)
- SBOM:
atlas-sbom-b69635467f944ee529de84636504ec29864c080a.spdx.json(SPDX 2.3 snapshot ofpnpm-lock.yaml)
Support and limitations
- Supported line: current Atlas release plus the immediately previous supported production release.
- No LTS programme at this stage.
- Internal
@atlas/*workspace packages remainprivateand are not published to npm. @blitzcraftlabs/atlasis the public npm package identity. npm distribution occurs after the canonical GitHub Release; registry availability is verified separately. The first npm publication requires the documented human bootstrap, while later releases may use Trusted Publishing.- This GitHub Release does not include signed provenance, SLSA attestation, or a formal security audit. npm Trusted Publishing may attach npm provenance to later
@blitzcraftlabs/atlaspublishes; that is not a GitHub Release attestation and is not SLSA. - After 1.0, breaking public-contract changes use a major bump. Compatible features use minor; fixes use patch.
License: Apache-2.0. See LICENSE and docs/how-we-build/releases-and-governance.md.
Atlas 1.0.0
Atlas 1.0.0
Atlas 1.0.0 is the first supported public distribution. The 0.x GitHub releases were the platform-development/proving line; they are not the public npm contract. Public CLI, generated-project, upgrade, and distribution contracts are now treated as stable. Breaking public-contract changes after 1.0 require a major version. Internal implementation may still evolve.
Changes
[1.0.0] - 2026-09-17
Security
- Atlas 1.0 is the first supported public distribution. The 0.x GitHub releases were the
platform-development and proving line. 1.0.0 is the first supported public npm contract for
@blitzcraftlabs/atlas. Public CLI, generated-project, upgrade, and distribution contracts are
now treated as stable; breaking those contracts after 1.0 requires a major version. Internal
implementation may keep evolving without a major release. 1.0 includes the production-proven Atlas
platform model already shipped on the 0.x proving line:atlas init, deterministic bootstrap
assets, clean-room consumer lifecycle, Doctor, generators, context, upgrade/version lifecycle, UI
quality gates, and security/release governance. It also prepares fail-closed npm Trusted
Publishing after GitHub Releases, including a one-time first publish of the exact canonical
v1.0.0tarball. The package is not on the registry yet. Do not treat
pnpm dlx @blitzcraftlabs/atlasas live untilpnpm distribution:verify-registry 1.0.0passes.
Do not bootstrap npm with0.5.0.
Release identity
- Tag:
v1.0.0 - Commit:
f4931a5b7d1c66523f03f6111fae038bf1180d56 - Product: Atlas repository/platform snapshot (not independent npm packages)
- SBOM:
atlas-sbom-f4931a5b7d1c66523f03f6111fae038bf1180d56.spdx.json(SPDX 2.3 snapshot ofpnpm-lock.yaml)
Support and limitations
- Supported line: current Atlas release plus the immediately previous supported production release.
- No LTS programme at this stage.
- Internal
@atlas/*workspace packages remainprivateand are not published to npm. @blitzcraftlabs/atlasis the public npm package identity. npm distribution occurs after the canonical GitHub Release; registry availability is verified separately. The first npm publication requires the documented human bootstrap, while later releases may use Trusted Publishing.- This GitHub Release does not include signed provenance, SLSA attestation, or a formal security audit. npm Trusted Publishing may attach npm provenance to later
@blitzcraftlabs/atlaspublishes; that is not a GitHub Release attestation and is not SLSA. - After 1.0, breaking public-contract changes use a major bump. Compatible features use minor; fixes use patch.
License: Apache-2.0. See LICENSE and docs/how-we-build/releases-and-governance.md.
Atlas 0.5.0
Atlas 0.5.0
Atlas 0.5.0 is a pre-1.0 repository/platform snapshot release.
Changes
[0.5.0] - 2026-09-17
Changed
- Prepare
@blitzcraftlabs/atlasas Atlas's public npm CLI package. Theatlasbinary, pack
allowlist, and GitHub Release workflow stay the same; this change makes the package identity and
metadata publication-ready without publishing to the registry. - Load production upgrade snapshots from the installed
@blitzcraftlabs/atlaspackage instead of a
consumerreleases/tree, and fail closed for unsupported or missing packaged release evidence. - Build
@atlas/projectbefore generating a production release snapshot so Version PRs succeed
afterpnpm install --frozen-lockfilewithout a prior workspace build.
Release identity
- Tag:
v0.5.0 - Commit:
76b53af2265f0797ad2977800e8d76a0897aa1de - Product: Atlas repository/platform snapshot (not independent npm packages)
- SBOM:
atlas-sbom-76b53af2265f0797ad2977800e8d76a0897aa1de.spdx.json(SPDX 2.3 snapshot ofpnpm-lock.yaml)
Support and limitations
- Supported line: current Atlas release on
mainafter the latest intentional version merge. - No LTS programme at this stage.
- Internal
@atlas/*workspace packages remainprivateand are not published to npm. @blitzcraftlabs/atlasis the public CLI package identity; this GitHub Release workflow does not publish it to the npm registry.- This release does not include signed provenance, SLSA attestation, or a formal security audit.
- Pre-1.0 APIs, templates, and upgrade mechanics may still evolve; breaking changes use a minor bump.
License: Apache-2.0. See LICENSE and docs/how-we-build/releases-and-governance.md.
Atlas 0.4.0
Atlas 0.4.0
Atlas 0.4.0 is a pre-1.0 repository/platform snapshot release.
Changes
[0.4.0] - 2026-09-15
Changed
- Declare
@types/nodeon@atlas/uiand include Node in the UI typecheck tsconfig so generated
projects do not depend on source-monorepo hoisting or omitted Vite types. - Add empty-directory
atlas init <project>so an installed CLI can materialize a consumer project
from packaged bootstrap assets.
Fixed
- Make repository dependency scanning resilient to source files that disappear during concurrent
generator validation, while continuing to fail on real filesystem and import-analysis errors.
Release identity
- Tag:
v0.4.0 - Commit:
9da16d0daceade115f93cbd4441d1a05fbf8dcde - Product: Atlas repository/platform snapshot (not independent npm packages)
- SBOM:
atlas-sbom-9da16d0daceade115f93cbd4441d1a05fbf8dcde.spdx.json(SPDX 2.3 snapshot ofpnpm-lock.yaml)
Support and limitations
- Supported line: current Atlas release on
mainafter the latest intentional version merge. - No LTS programme at this stage.
- Workspace packages remain
privateand are not published to npm. - This release does not include signed provenance, SLSA attestation, or a formal security audit.
- Pre-1.0 APIs, templates, and upgrade mechanics may still evolve; breaking changes use a minor bump.
License: Apache-2.0. See LICENSE and docs/how-we-build/releases-and-governance.md.
Atlas 0.3.0
Atlas 0.3.0
Atlas 0.3.0 is a pre-1.0 repository/platform snapshot release.
Changes
[0.3.0] - 2026-09-14
Changed
- Package a versioned Atlas bootstrap asset tree inside the CLI so an installed tarball can locate
the supported starter baseline without the monorepo. - Make the Atlas CLI independently packable by internalizing the project-contract runtime so a
tarball can install and run outside the monorepo without unpublished workspace dependencies.
Release identity
- Tag:
v0.3.0 - Commit:
4238c3821989101f5bad6126e4ca4641d732fb44 - Product: Atlas repository/platform snapshot (not independent npm packages)
- SBOM:
atlas-sbom-4238c3821989101f5bad6126e4ca4641d732fb44.spdx.json(SPDX 2.3 snapshot ofpnpm-lock.yaml)
Support and limitations
- Supported line: current Atlas release on
mainafter the latest intentional version merge. - No LTS programme at this stage.
- Workspace packages remain
privateand are not published to npm. - This release does not include signed provenance, SLSA attestation, or a formal security audit.
- Pre-1.0 APIs, templates, and upgrade mechanics may still evolve; breaking changes use a minor bump.
License: Apache-2.0. See LICENSE and docs/how-we-build/releases-and-governance.md.
Atlas 0.2.1
Atlas 0.2.1
Atlas 0.2.1 is a pre-1.0 repository/platform snapshot release.
Changes
[0.2.1] - 2026-09-12
Fixed
- Fix release publication after an existing canonical release so post-release
maincommits no-op
when the published tag is a proven ancestor instead of attempting to retag it.
Release identity
- Tag:
v0.2.1 - Commit:
223cae4dc15f3c22221c6d6cef157d1d9242635d - Product: Atlas repository/platform snapshot (not independent npm packages)
- SBOM:
atlas-sbom-223cae4dc15f3c22221c6d6cef157d1d9242635d.spdx.json(SPDX 2.3 snapshot ofpnpm-lock.yaml)
Support and limitations
- Supported line: current Atlas release on
mainafter the latest intentional version merge. - No LTS programme at this stage.
- Workspace packages remain
privateand are not published to npm. - This release does not include signed provenance, SLSA attestation, or a formal security audit.
- Pre-1.0 APIs, templates, and upgrade mechanics may still evolve; breaking changes use a minor bump.
License: Apache-2.0. See LICENSE and docs/how-we-build/releases-and-governance.md.
Atlas 0.2.0
Atlas 0.2.0
0.1.0 was a historical internal snapshot. No public v0.1.0 tag or GitHub Release was published.
0.2.0 is the first canonical public GitHub Release. Atlas remains pre-1.0.
Changes
[0.2.0] - 2026-09-12
Added
- Repository-level release governance: Apache-2.0 license, versioning policy, support expectations,
breaking-change process, Version PR workflow, and fail-closed GitHub Release publication. - Public documentation aligned to the Apache-2.0 GitHub repository: clone/fork access, contribution
model, and durable evidence in place of private-era issue numbers.
Changed
- Improve search input styling, badge alignment, and server-safe theme boot constants.
Fixed
- Repair release automation so Version PRs validate at the new Atlas line and fail-closed GitHub
Release publication can create the first canonical publicvX.Y.Ztag after the Version PR
merges.
Security
- Make Atlas security checks blocking: HIGH/CRITICAL dependency policy, pinned Actions and Gitleaks,
SPDX snapshots, and a published threat model.
Release identity
- Tag:
v0.2.0 - Commit:
cbd5828acf7f8bc60cd64e6b9da68011c84d8a61 - Product: Atlas repository/platform snapshot (not independent npm packages)
- SBOM:
atlas-sbom-cbd5828acf7f8bc60cd64e6b9da68011c84d8a61.spdx.json(SPDX 2.3 snapshot ofpnpm-lock.yaml)
Support and limitations
- Supported line: current Atlas release on
mainafter the latest intentional version merge. - No LTS programme at this stage.
- Workspace packages remain
privateand are not published to npm. - This release does not include signed provenance, SLSA attestation, or a formal security audit.
- Pre-1.0 APIs, templates, and upgrade mechanics may still evolve; breaking changes use a minor bump.
License: Apache-2.0. See LICENSE and docs/how-we-build/releases-and-governance.md.