1.3.1
1.3.1 Latest
New Features
- add Apollo browser lane (#1906)
- remind on stalled runtimes
- log hosted reasoning effort (#1912)
- accept phone-call result policy
- count Telegram and email message volume
- route Telegram phone call results
- recommend bounded longitudinal trials
- expose connected micronutrient totals
- diagnose slow snapshot starts
- support deterministic set removal
- confirm deterministic member actions
- add deterministic member actions
- add Telegram rich content cards
- add bounded dense resource features
- model activity health resources
- clarify account deletion handoff
- model sparse health resources
- model sparse health resources
- send cards after meal and workout updates
- add pattern illustrations and compact mobile table
- render response cards as Telegram rich messages (#1657)
- add App Store handoff to shared cards
- recognize group funding supporters
- add shared card app handoff
- add challenge standings response card (#1463)
- add member-owned device provider applications (#1484)
- activate proposed goal support on yes
- run a weekly goal support audit
- preserve detail for single images
- make the first check-in operational
- make repeated-plan follow-through proactive
- shard changelog entries
- alert on stalled hosted runtimes
- add default appointment reminders (#1586)
- edit Murph personality from settings and chat
- add personal health patterns (#1563)
- render compact table card images
- let Murph search Health Commons knowledge (#1556)
- publish August changelog and completion gate
- publish weekly changelog
- add named-diet guidance tranche (#1540)
- answer group usage progress directly
- simplify referral options
- add provider logos to wearable relay cards (#1432)
- start Family setup safely from group chat (#1527)
- refine body composition guidance (#1512)
- extend group reply cadence (#1514)
- add static nutrition image fallback
- add Family Max seats
- add structured iMessage workout sessions
- add private training dashboard
- send generated Murph avatars (#1458)
- footer vitals with live status, split Murph link columns, drop homepage trial copy
- retire sent export packs simply
- footer vitals with live status, split Murph link columns, drop homepage trial copy
- monthly revenue bar chart with source breakdown on ops growth (#1442)
- Codex headline stack and capability standing order in runtime dossier
- plainer runtime headline and drop dead provider-choice link
- gate Venice claims behind provider flag and sharpen runtime copy
- let Murph link to private custom runs
- shade biomarker reference ranges
- show repeated daily experiment cadence
- enrich referral landing and cut the CTA footnote
- enable bounded Gmail and Outlook sends
- persist bounded Codex memory artifacts (#1294)
- add Stripe failure email alerts
- add cold-start control telemetry
- expose code-owned first-read automation action
- own first-read automation prompt in code
- schedule first personal read
- add cold-start control telemetry
- trace cold provider start path
- show trial start attribution
- trace R2 restore read latency
- add recovery readiness insight candidate
- add companion account admission boundary
- choose full audits for large PRs
- add status page footer link (#1328)
- add Apple Health relay wearables (#1316)
- add explicit shareable signup referral links (#1299)
- use official weather alerts
- add weather health context
- retire generated image captures after 14 days
- add Zepp Apple Health onboarding
- share initial onboarding across clients
- add bring-your-own inference
- show the composed contact channel card in the design catalog
- render the physical-notes capability flag in deploys
- raise group daily text limit to 400
- include feedback summaries in daily digest email
- add support email link to site footer
- publish July 31 changelog
- pass canonical native signup timezone
- preserve native signup timezone
- admit native signup through hosted lifecycle
- reuse hosted onboarding for companion signup
- complete real-data voice flow
- adapt voice capture to coverage
- process voice walkthroughs privately
- refine voice walkthrough feedback
- simplify empty state walkthrough
- use real habitat data
- explorable environment page with guides, share, and print report
- grade-first Habitat environment page
- take delegated initiative
- add product feedback digest
- add composable physical notes [physical-notes-applied]
- bound onboarding follow-up automation
- add mobile sponsorship drawer
- route bounded Sol subagents to Terra
- log launch consent declines (#1185)
- explain empty referral state
- add capped group sponsorship
- auto-send pasted signup phones
- publish July 30 changelog
- pace group replies
- polish assistant provider picker
- share iOS app link in groups
- ground sponsorship songs in group context
- compact model provider choice
- ground obscure group references
- add group member plan
- render trailing Linq links natively
Bug Fixes
- align system mailbox frontier ownership
- propagate assistant blocks to system work
- preserve foreground retry quiet window (#2005)
- preserve group email fanout identity
- scope Junction provider limit
- preserve transport dedupe identity
- preserve actionable blocked wakes
- preserve blocked recovery wakes
- close hosted recovery gaps
- bound native web build wedges
- preserve coupled sleep normalization
- narrow legacy media fallback
- simplify reminder generations
- drain grouped image completions
- keep exhausted purchase returns visible
- retry foreground after system handoff
- resume stalled hosted reconciliation
- preserve usage recovery precedence
- restore Starter usage from Ops (#1982)
- preserve retry completion quiet window
- simplify Vercel build ownership (#1988)
- preserve stale workout identity
- let successful Vercel builds complete (#1986)
- preserve workout clarification context
- normalize optional anchor lists
- address usage recovery review findings
- preserve bounded reply anchors
- require workout closure intent
- bound optional auto-reply history
- preserve trusted completion quiet window
- avoid inferred workout end times
- keep system work off reminder quiet window
- preserve device reminder context
- reconcile due wake successors before sleeping
- preserve references for media reminders
- retain aggregate reminder continuation
- preserve reminder context across live sessions
- preserve reminder barrier during canonical writes
- add reminder context references
- preserve foreground quiet window
- preserve foreground checkpoint priority
- retain later assistant wake through checkpoint
- serialize outbox projection recovery
- encode native E2E database options (#1972)
- stabilize native iOS hosted E2E activation (#1969)
- declare native E2E database runtime (#1967)
- publish canonical search metadata (#1935)
- register screenshots telemetry path
- isolate native iOS Junction identity (#1943)
- bound foreground reply state reads
- keep phone results behind foreground replies
- preserve tracked result receipts after provider acceptance
- preserve member action outcome receipts
- make message-volume receipts converge
- keep Telegram exercise routines in one card
- preserve rollback metric evidence
- ignore sparse database error ports
- recover definitive result delivery failures
- recover no-effect result exhaustion
- recover pre-provider result exhaustion
- hold process ownership through descendant reaping on cancellation
- retain phone result crypto preparation
- stop stale carried wakes from shadowing fresh due work (#1931)
- keep phone recovery hints best effort
- move the production build deadline into the package-build process owner
- keep the build watchdog in the caller's process group and prove fail-closed discard
- isolate phone recovery sibling obligations
- keep production Webpack compiles cold and bound them with a build watchdog
- settle all phone recovery obligations
- bound dormant phone recovery cadence
- recover dropped phone result wakes
- update vault bundle size budget (#1930)
- guarantee late phone result recovery
- complete phone recovery release gates
- make phone recovery workflow single-owner
- bound Telegram route recovery rearm
- ratchet reviewed runner bundle growth
- honor stored phone-call completion policy
- preserve transfer follow-up recovery
- scope phone-result foreground delivery
- prevent phone-call result starvation
- preserve Telegram reply grouping
- recover no-send phone-call result retries
- preempt reminder maintenance at deadline
- anchor callback retry after failure
- preserve established webhook ordering
- dedupe planned experiment sessions
- keep direct route fallback Telegram-only
- preserve phone call conversation authority
- preserve phone-call result confirmation recovery
- preserve planned experiment occurrence
- recover missed device sync wake signals
- preserve first phone call result
- bound pending webhook retries by setup lifecycle
- complete Junction webhook source recovery
- preserve unrelated lock graph
- require confirmed phone reconciliation wake
- preserve Telegram reminder reply targets
- accept equivalent mailbox timestamps
- retain parsed database metric evidence
- preserve durable webhook work across source races
- consume superseded setup webhooks
- terminate expired setup webhook retries
- require positive Junction source proof
- clarify native E2E controller trust boundary
- recover pending Junction webhooks
- count repeated results in sidebar
- preserve cold wake trace
- address native iOS E2E review findings
- recover call results independently of usage
- keep telemetry evidence consistent
- consume superseded setup webhooks
- return repairable card validation hints (#1849)
- preserve database metric gap evidence
- keep phone delivery checkpoints foreground
- terminate expired setup webhook retries
- preserve reminder-backed experiment provenance
- suppress Telegram signup outreach (#1889)
- move native iOS hosted E2E scripts to root
- checkpoint phone result delivery claims
- import initial activation before conversation turn (#1864)
- recover pre-provider call result attempts
- scope wake cleanup deadline
- recover stale phone-call result callbacks
- durably confirm phone-call result delivery
- harden phone-call result completion contract
- close phone-call result routing races
- keep phone call delivery migration expandable
- make telegram call result delivery durable
- keep Stripe receipts retryable during claims
- complete Stripe claim authority cutover
- prioritize telegram phone call results
- preserve phone call result authority
- harden Stripe effect compatibility cutover
- accept workerd public ECDH JWKs (#1868)
- refresh pre-assistant system mailbox
- classify scheduled call route loss
- persist phone call fallback results
- harden repository and worktree lifecycle
- scope activation completeness to system lane
- use stable Chrome for WHOOP canary
- notify foreground cleanup outcomes
- report uncertain cleanup truthfully
- preserve cleanup result delivery
- sanitize direct wake log inputs
- harden frontend verification workflows
- remove redundant failure class
- support larger tracked workouts (#1730)
- notify failed phone call cleanup
- keep Queue stages out of provider responses
- classify activation within shared prefetch
- recover slow direct wakes
- keep failure classes evidence-based
- settle every terminal phone call outcome
- expose queue transport failure stage
- recognize quoted search commands
- isolate concurrent ReviewGPT packaging
- classify command failures safely
- admit initial activation before idle checkpoint
- align personalized trial boundaries
- preserve reminder runtime authority
- harden ReviewGPT lane prompt continuity
- prepare CLI artifacts for diff tests
- unify source lifecycle authority
- preserve micronutrient evidence semantics
- stabilize cold-start recovery proof
- preserve hosted source identity
- reject ambiguous workout action targets
- raise runner bundle cap by ten percent (#1827)
- resolve Product UX review findings
- complete Frog handoff recovery
- align runner bundle budget
- restore runner bundle and assistant gates (#1828)
- preserve complete provider days
- centralize recovery proof ownership
- retain sparse repair beside retry
- bind workout actions to positional identity
- preserve exact local runtime semantics
- preserve local OpenAI response semantics
- carry forward workout reps only
- invalidate incompatible build cache
- route local sandbox by provider identity
- bind cards to action revision
- restore reliable Vercel builds
- keep saved experiment history off core routes
- restore first-time Apple Health connections (#1813)
- keep unrelated temp clones from blocking commits (#1803)
- restore Spotlight marker after hooks
- preserve local E2E shell execution
- preserve Frog post-push handoff proof
- resolve completed action replays
- preserve shared Spotlight exclude ownership
- make metric runner rollback floor durable
- stabilize manual metric corrections
- honor image opt-outs during safety guidance
- include exercise images by default
- honor report order across timezone changes
- reject lossy rich tags
- preserve causal order for metric corrections
- scope bounded food search
- arbitrate current sender at dispatch
- retire departed browser vault loads
- persist member action replay marker
- preserve literal rich fallback text
- close Frog publication authority races
- restore shared Spotlight precedence
- confirm queued reminder delivery
- preserve browser vault recovery states
- bound reminder silence evidence
- preserve native worktree materialization
- claim one current sender decision
- authorize deterministic set removal
- scope reminder evidence to session
- publish worktree authority on completion
- require notice-capable group protocol
- honor fresh source lifecycle
- expire cold history marker
- preserve ranked food search bounds
- replay committed metric reports
- finish worktree setup cleanup
- preserve late snapshot wake control
- mark bounded conversation history
- keep current sender terminal outcome sticky
- reuse active set prescriptions (#1795)
- keep browser vault query buildable
- harden set removal replay
- separate hosted source state
- keep foreground wake ahead of snapshot telemetry
- unify worktree setup lifecycle
- reconcile group wearable values
- resume foreground after completion failure
- bound product label search work
- resolve repeated sets from canonical plans (#1790)
- preserve native worktree failure semantics
- recover ambiguous device cleanup
- preserve recurring reminder context
- retain failures across late wakes
- harden reported metric handoff
- order current sender clarification transitions
- prefer established hosted source
- preserve first failure provenance
- unify Junction source identity
- exclude worktrees before checkout
- keep R2 cause handling local
- harden direct R2 retry classification
- preserve safety-critical reminders
- stabilize replayed snapshot identity
- preserve exact current-sender ordering
- read deployed scalar precursor
- preserve presign HTTP failures
- preserve account source identity
- retry direct snapshot R2 uploads
- ratchet group share runner budget (#1784)
- replay ambiguous snapshot completion
- ratchet runner bundle budget
- bound snapshot orphan alarm scheduling
- retry snapshot presign transport failures
- unify calendar source aliases
- quiet unanswered recurring reminders
- preserve calendar source aliases
- reject lossy calendar responses
- preserve unsupported workout results
- reject partial calendar repairs
- bound deployment-safe Junction progress
- restore bounded scalar continuations
- align continuation CI contracts
- complete Junction timeseries continuations
- keep hidden workout notes out of cards
- preserve calendar repairs across reconnect
- recover automation timing verification (#1763)
- hydrate exact workout editor snapshots
- preserve partial workout set preconditions
- preserve unrelated workout set fields
- keep member action crypto outside transactions
- require unique member action targets
- bound Junction timeseries continuations
- bound deterministic member action completion
- retain Junction calendar repairs
- preserve safe fallback entities
- disable automatic rich entities
- preserve rename-out audit context
- persist Junction calendar refreshes
- reject unconsumed private directives
- reject subject-led private clauses
- refresh displaced Junction days
- preserve concurrent current-sender asks
- bind sparse revisions to provider day
- route sparse corrections by provider day
- validate invalid DST retries
- checkpoint timeseries resources
- bound Junction timeseries progress
- honor DST recovery withdrawal
- preserve semantic card ownership
- bound Junction correction cadence
- reject unknown edge delivery clauses
- honor leading private clauses
- correlate renamed DST retries
- keep current-sender terminals importable
- preserve DST recovery across conflict
- replay expired current-sender completions
- retain workout progress through day
- compose DST recovery obligations
- preserve Junction temporal precision
- preserve private fallback convergence
- retain pre-rename recovery alias
- bind workout retry progress to day
- prevent handoff recovery starvation
- canonicalize DST recovery targets
- confirm missing database counters
- scope Telegram routine repair guidance
- preserve Telegram routine cards on resend
- preserve workout stream retry backoff
- bind current sender requests before personal read
- reconcile Junction compact sets
- bound workout stream continuation retries
- keep sparse backfill activation authoritative
- keep reconnect reset web-owned
- reopen weight history on reconnect
- preserve compact stream ownership
- warn when account disconnect affects Dexcom
- keep interval features on start day
- explain unavailable Dexcom recovery
- preserve floating days before import
- require channel-native plan presentation
- bound dense resource persistence
- share recovery state policy
- preserve midnight intervals
- validate sync watermark horizon
- reuse established importer entrypoint
- unify Dexcom recovery authority
- preserve resumed history obligations
- derive closed-day webhook routing
- settle DST clarification lifecycle
- preserve existing Dexcom recovery
- bind Composio writes to member identity
- preserve full-sync watermark
- retry transient database telemetry collection (#1715)
- keep deletion controls independent
- isolate the default browser lane
- preserve bounded opt-in boundary
- preserve foreground priority during device apply
- retain DST clarification date
- preserve floating daily buckets
- make current-sender audience reviewer-owned
- complete sparse activation journey
- stabilize sparse provider row identity
- align aggregate completeness boundaries
- preserve bounded resource semantics
- preserve relative reminder date
- stabilize weight replay and history
- add bounded resource opt-ins
- allow runner CLI reads
- anchor hosted timing and writes
- preserve group email eligibility limit
- release consumed pending group pin
- preserve restricted vault execution
- reject malformed group email grants
- prewarm Starter roots before enrollment commit
- default eligible response cards
- bound group email graph reads
- preserve restricted maintenance shell access
- bind manual family abandonment claim
- clarify automation and voice inputs
- restrict one-shot codex threads
- bound source detail to GPT-5.6
- expose device snapshot status test seam
- bind family recovery to checkout claim
- require exact refs for sender actions
- preserve source detail across OpenAI models
- preserve changelog summary boundaries
- simplify Terra changelog wording
- isolate timing source attribution
- clarify Terra image detail scope
- widen shared-card handoff dialog
- simplify device apply authority
- strengthen shared-card dialog hierarchy
- soften shared-card cancel action
- stack shared-card handoff actions
- scope mailbox completeness to projection
- preserve completed family checkout recovery
- preserve unscoped companion source authority
- bound device runtime apply fanout
- replay the exact family checkout claim
- keep family invites out of Stripe checkout
- separate runtime source authority bound
- make hosted timing inspection authoritative
- keep pending setup roots retryable on missing verify keys
- resolve relative days in the named timezone
- prove mailbox prefix completeness
- preserve invite recovery billing intent
- resolve one-shot schedules in the user timezone
- rehydrate trusted image completions
- preserve paged device status guidance
- make family invite recovery actionable
- preserve family invite through checkout cancellation
- freeze supporter publication at settlement
- harden consented share refresh scheduling
- isolate group email terminal settlement
- preserve supporter consent across rollback
- preserve family invite through sign-in
- interrupt initial system mailbox fetch
- close bounded snapshot audit gaps
- remove unneeded nonce rollout migration
- preserve causal notification usage
- harden pending group preparation retries
- yield before system mailbox import
- bind supporter aliases to settlement consent
- preserve family invite recovery identity
- verify first route admission
- bind causal mailbox audience
- align App Store action label
- bound device snapshot and status reads
- batch Linq message edit preparation
- normalize assertion nonce expiry during rollout
- protect supporter recognition
- slim homepage phone on mobile
- expose system handled frontier
- harden family draft invite recovery
- enforce hard runtime cutover
- batch pending group candidate reads
- latch late handoff adoption
- preserve container isolation without SSH
- bound Linq roster database fanout
- preserve mailbox retry ownership
- remove container SSH access
- fail closed at browser nonce expiry
- release terminal handoffs
- preserve card text recovery
- prevent overlapping message handoffs
- preserve rollback occurrence identity
- harden shared card handoff
- expose safe mailbox retry diagnostics
- bind ReviewGPT PR context
- preserve recording item on host abort
- label card previews by type
- preserve wake after system replica refresh
- keep explicit refresh under one pending owner
- bind vault approval audience
- return retryable pending setup crypto failures
- keep outcome attribution on canonical line
- recover abandoned family drafts
- end session polling at handoff deadline
- retain legacy changelog declaration ownership
- bind avatar reuse to delivered bytes
- preserve provider icon clearance
- prove Terra image detail boundary
- preserve consent action accessibility
- preserve rollback wire proof
- exclude zero-rep attempts from best
- preserve explicit vault file routes
- bound original image detail
- canonicalize Linq send routes
- hide patterns from sidebar (#1620)
- preserve pending group setup on crypto errors
- coalesce system mailbox rechecks
- recognize deleted active workouts
- honor durable topic opt-outs in weekly checks
- persist topic-specific support boundaries
- preserve explicit legacy goal-check stops
- authorize recurring goal-support delivery
- match health data settings actions
- keep merged changelog within schema
- preserve rollback proof
- retain generated delivery evidence
- harden public song authorization
- fence satisfied deferred refreshes
- refresh canonical device replica
- bind handoff refresh to requested workout
- keep non-device system record aborts retryable
- prewarm Linq reaction mailbox roots
- yield device recording to foreground
- align health data settings row
- publish system device replica
- clarify fragment fallbacks and metadata edits
- make durable send terminal
- include canonical cardio workouts
- verify generated avatar references
- order reconnect cleanup behind dirty marker
- checkpoint system mailbox device unit
- harden runtime progress alerts
- keep nutrition goals inside card
- let provider own card chrome
- bound card text against kerning
- preserve manual sleep correction authority
- retire legacy newsletter wake safely
- defer steering after image completion
- show effective style defaults
- bind training refresh ownership
- recover legacy referral audience authority
- checkpoint device recovery before handoff
- preserve consent ordering for dirty payloads
- prefer installed Brave for managed lanes (#1594)
- exclude worktrees from Spotlight (#1590)
- size table rows from exact font
- close training review edge cases
- keep prompt guidance within budget
- order repeated manual sleep corrections
- render workout checkmark without font fetch (#1599)
- latch foreground system preemption
- preserve style ownership and group application
- restrict resumed completion capabilities
- restrict completion native capabilities
- retain post-record device wake
- complete training handoff semantics
- defer system recording for foreground wake
- preserve workout card words
- complete generic scheduled delivery
- prevent browser vault refresh starvation
- validate manual sleep share corrections
- harden training refresh and progress
- preserve response card boundaries
- share manual sleep-stage corrections
- register workout card study
- preserve direct notification audience authority
- isolate generated image completions
- let Messages own static table chrome
- accept later generated image delivery for avatars
- stop browser vault refresh starvation
- keep Android relay guidance text only
- tighten workout card device UX
- include Codex alignment owner
- qualify hosted web search availability
- reuse workspace Codex for WHOOP canary
- make group sleep challenge reads current (#1565)
- advance training replica generation
- include Codex pin in audit context
- refresh private training after handoff
- allow hosted Codex web search egress
- install Codex for WHOOP canary
- cover static card review gaps
- preserve weekly insight fallback
- preserve android deploy flag contract
- complete generated avatar release proof
- explain capacity conflicts
- repair growth sponsorship metrics query (#1572)
- make training refresh truthful
- preserve static workout card semantics
- preserve exact Android deploy gate
- preserve generated image provenance
- refresh legacy training replicas
- drain thread routing crypto work
- keep pitch metrics rate-led
- project Android gate into hosted turns
- release provider-final reservations
- refresh pitch traction metrics
- keep training dashboard hidden
- bound reversal restoration
- bound active projection scans
- align recurring delivery projection
- retain accepted image delivery evidence
- require image delivery before avatar reuse
- close Family billing race windows
- align one-shot timing projection
- preserve accepted image reply ownership
- preserve timezone on schedule patches
- refund late Family-sponsored invoices
- reserve sponsorship refill slots
- reserve usage credit grant slots at checkout
- record provider-final checkout release
- bound grant admission
- keep feedback claims within production guarantees
- invalidate retired scheduled log retries
- preserve independent sleep consents
- enforce media effect rollback floor
- preserve explicitly requested scopes
- distinguish event trigger timing
- keep scheduled email claims within authorization
- preserve media ownership evidence
- fence start-paid billing status
- commit retier cleanup before rethrow
- attest physical media ownership
- preserve adopted retry occurrences
- prevent Linq authority KMS replay
- make optional sharing easy to clear
- leave referral destinations to their owner
- narrow Telegram sender admission reads
- harden hosted billing edge cases
- preserve cadence across non-timing edits
- preserve mixed-intent replies
- keep changelog visuals tied to product owners
- bind media to primary Linq effect
- compact native session wire
- make Family checkout invitation-free
- simplify referral recovery language
- prewarm observed thread route roots
- retain workout context in email summaries
- preserve recognized sender setup preflight
- preserve contentless pending thread owner
- preserve eligible pending thread owners
- verify deliverable schedule timing
- preserve recurring schedule timezones
- preserve fresh input on recovery read failure
- bound restored completion cohort
- separate Family status read recovery
- align thread crypto preflight access
- preserve thread preflight across content guards
- keep changelog actions production-faithful
- align thread crypto with runtime access
- finalize Mobvoi connection guidance
- fence consent offer generations
- skip thread crypto for ignored groups
- order legacy classification after consent
- preserve generated image reply binding
- ratchet runner bundle budget (#1545)
- use Mobvoi logo and trim connect copy
- close persisted card contract gaps
- bound control response bodies
- harden consent offer ownership
- restore image completion ordering
- recover Family Max chat invitations
- retry late thread winners before mailbox work
- attribute Codex model reroutes
- serialize thread route creation across key versions
- preserve recurring schedule timezones
- resolve changelog specialist findings
- preserve truthful workout progress
- clarify referral link rewards
- scope runner rpc diagnostics to phase failures
- preserve generated image fallback provenance
- bound reconnect recovery
- repair exact-head verification
- make training actions state-aware
- harden group consent offers
- require group usage progress contract
- preserve runner diagnostics across rpc
- prove every training page state
- harden card command reconciliation
- match image completion by group route
- prepare self-authored thread routes once
- converge on late thread route winner
- register family setup telemetry
- complete group newsletter sharing prompts
- improve group sharing and weekly context
- render real training design study
- preserve safe source failure codes
- neutralize unassessed calorie progress
- reuse resolved thread route for preparation
- register family setup telemetry
- resolve Family Max review gaps
- preserve minute referral settlement
- preserve thread routing preparation authority
- preserve generated image continuity
- mirror native nutrition balloon
- use canonical failure authority
- preserve image completion admission order
- prioritize ready image completions
- preserve failure phase metadata
- preserve active checkpoint handoffs (#1472)
- allow retention crypto reads for paused members (#1493)
- bound the personalized send to the turn waiting on it (#1488)
- log connected-app provider failures (#1507)
- preserve accepted failure phase
- align runtime with Codex 0.147
- preserve complete Family plan database contract
- prioritize ready image completions
- finalize iMessage card contracts
- preserve static nutrition semantics
- harden training dashboard read model
- retire superseded Family plan constraint migration
- bound browser assertion nonce database work (#1500)
- classify group tool cancellation accurately
- align training view with live workout model
- use canonical public origin (#1489)
- prepare safe group usage reader rollout
- pace database health alerts hourly (#1480)
- preserve referral claim origin proof (#1492)
- preserve partial database telemetry (#1469)
- enforce sponsorship creative invariants (#1490)
- show referral rewards only in Murph days (#1487)
- make repeated workout tallies occurrence-aware (#1455)
- align browser assertion nonce horizon
- share footer counter and show online status
- footer availability copy says no reported issues, add component and homepage proof
- make first-contact shell prewarm consent-safe (#1476)
- bound callback nonce database work
- prewarm clinical mailbox encryption
- move clinical OAuth sealing before transaction
- move clinical OAuth sealing before transaction
- keep cleanup receipts out of delivery effects
- keep export cleanup from blocking sends
- close Murph Max review gaps
- freeze active referral reward labels
- footer availability copy says no reported issues, add component and homepage proof
- classify PgBouncer max-client rejection
- preserve referral credit receipts
- make container route ownership the whole durable-thread authority
- let a thread container assert its own durable Linq thread
- stop signed-out dashboard visitors from starting a vault load
- stop warning on latency traces the runtime never ingressed
- hold hero floater labels at one tone
- build hosted-execution before production migrations
- honor custom-inference flag, member-choice copy, and runtime-label contrast
- harden Max plan integration
- include authority-bearing scheduled children in the delivery cohort
- derive the scheduled-delivery cohort from durable cron state
- align referral credit rounding
- scope admission lock bound to webhooks and decode adapter-pg lock timeouts
- restore referral credit truth
- prove standby key material usability
- stop serverless OG and share-card routes 500ing on missing assets
- reject ambiguous hosted keyring JSON
- bound webhook admission locks and map transaction expiry to retryable 503
- derive runtime-log subject keys from a storage-free leaf module
- silence pg concurrent-query deprecation noise in web runtime
- carry runtime-log retirement through phone-transfer census and E2E harness
- deliver the whole current-pass cron cohort at the discovering wake
- use a Workers-supported redirect mode in database-health fetches
- keep funding locators private
- validate raw hosted standby payloads
- canonicalize funding target aliases
- prove hosted standby generation usability
- validate funding recovery origin
- validate hosted crypto standby keyrings
- keep published biomarker comparators neutral
- require exhaustion recovery link
- validate hosted crypto keyrings
- forward hosted crypto keyrings
- route hosted app-card fallback warning to the durable runtime log
- remove room-model authored byte cap
- classify Postgres 53300 connection-slot rejections in pool telemetry
- simplify funding recovery
- drop redundant caveat block from sensitive action approval screen
- bound malformed provider JSON in Linq fallback warning and update callback expectations
- shorten usage banner copy to Murph is paused
- align home usage tests and design catalog with banner recovery
- drain due automations in one inputless background pass
- forward hosted crypto keyrings
- restore interactive iMessage response cards
- decouple room memory from prompt byte size
- keep paused trial recovery Pulse-only
- isolate private funding page state
- restore interactive iMessage response cards
- keep Core hidden during paused Pulse recovery
- set the referral landing subhead to the in-your-corner line
- align paused trial recovery proof
- restore paused Pulse trial recovery
- rewrite referral landing subhead and drop the capability grid
- preserve paused Pulse recovery action
- anchor growth activity to durable receipt
- ship patched Ink in release tarball
- lower group idle compaction threshold
- keep sponsored recovery factual
- recover sponsored groups at usage limit
- gate scheduled images by delivery route
- reject unusable Linq reservation headers
- retry scheduled clinical launcher
- validate referral claim origin
- protect accepted checkout replays
- preserve accepted preference source order
- retain pre-provider provenance through direct materialization
- keep Stripe field parsing runtime-neutral
- preserve referral claim recovery
- keep terminal checkout refunds receipt-owned
- align scheduled preference and launcher owners
- harden referral lock ordering
- preserve Stripe request correlation in alerts
- disclose skipped current lookup
- reject side-effect imports of pruned zod
- retain Linq ambiguity through direct materialization
- satisfy Stripe request contracts
- align weekly scout with finite schema
- retain live zod runtime while pruning variants
- verify Family authority before Stripe cleanup
- serialize signup referral settlement
- alert on paid Family mutation failures
- keep replay ownership in the outbox
- close legacy scout bypass
- harden scheduled preference authority
- reserve pending referral capacity
- serialize Family subscription cleanup
- preserve Linq reservation ambiguity across final send
- close final release credential gaps
- contain approval lifecycle study
- bound focused provider concepts
- report denied approvals truthfully
- alert on subscription action failures
- preserve referral cap ordering
- remove free-form provider questions
- cover release authority containers
- keep cancellation off runner boot path
- preserve tool request delivery context
- resolve scheduled authority review findings
- keep file cancellation outcomes truthful
- permit the first read at completion
- package explicit specialist evidence
- retain Family wake across newer events
- scope Linq defer provenance to delivery
- close referral final review gaps
- complete release credential classification
- close private question boundary
- harden pending file cancellation
- preserve Linq reservation provenance
- alert on bound Family redirect failures
- harden Stripe request contracts
- close release credential holder gaps
- preserve selected inference
- preserve Stripe capacity wake replay
- complete referral review proof
- bind first read to completion
- close CLI Zod declaration graph
- prove public question boundaries
- remove group-only call preview flow
- preserve medical owner wording
- repair referral review candidate
- key first-read replay to exact occurrence
- preserve Stripe alert occurrence identity
- require Temporal launch ownership
- make group setup completion authoritative
- canonicalize group setup effect
- order and dedupe group recovery
- keep group recovery account-private
- clarify inactive group sender recovery
- declare hosted Zod type dependency
- filter non-startup Temporal wakes
- converge Stripe billing cleanup state
- own Stripe alerts at billing action boundary
- cover release credential serializations
- dedupe resolved cold-start cohorts
- retain zod declaration builds
- satisfy safe logging guard
- register Stripe billing design study
- distinguish avatar rejection from uncertainty
- keep legacy cold-start rows unclassified
- keep Stripe failure alerts occurrence-scoped
- narrow Stripe recovery invariants
- harden Stripe paid access transitions
- consume exhausted Linq attachment occurrences
- enforce zod runtime ownership
- bind cold-start identity to fence owner
- preserve lazy tool request ordering
- mark avatar transport outcome unconfirmed
- unblock hosted web production deploy
- bound Linq upload retries end to end
- correlate direct cold starts exactly
- keep cold-start telemetry causal
- correlate direct cold starts exactly
- restore paused Pulse billing
- reserve the first-read slug on patch
- contextualize every product note
- keep first-read promise honest and scope clean
- resolve growth activity review findings
- close group icon diagnostic boundary
- honor first-read cancellation at execution
- preserve explicit first-read cancellation
- align first-read dedupe and replay policy
- reactivate only the fixed bounded one-shot
- preserve once-only first-read semantics
- do not let generic close suppress first read
- protect derived first-read slug
- collapse release secret classification
- make first-read scheduling and outreach explicit
- protect fixed first-read automation from prompt edits
- harden first-read prompt and identity
- record Linq group icon outcomes
- contain Linq attachment recovery
- keep cold-start telemetry causal
- preserve deletion guard through bucket retirement
- harden release secret guard boundaries
- retry linq attachment uploads
- halve the persona picker tone step dialog width
- require inactive receipt operation
- bound completion receipt fallback
- separate image continuation identity from launch scope
- record exact container completion
- resume image completions on origin session
- cover trial attribution entry paths
- retain only current browser vault replicas
- bind cold timing to fresh input
- consume cold-path timing once
- prioritize interesting product notes
- erase retiring OC copies
- cover expanded browser work
- preserve renewed replica cleanup obligations
- guard browser progress availability
- make browser progress turn-local
- clean stale browser vault replicas
- preserve consent action accessibility
- align consent actions
- preserve observable onboarding progress
- preserve onboarding return prerequisites
- suppress admission welcome side effects
- constrain compact onboarding resume routing
- serialize meal activation with sponsored access
- preserve compact onboarding routing
- distinguish scheduled call start failures
- materialize approved sleep policy scope
- recheck meal activation authority
- stabilize native admission recovery
- keep scheduled call retries truthful
- preserve legacy sleep policy on rollback
- prioritize first-contact conversation wake
- keep scheduled calls on Linq
- preserve legacy sleep consent
- require meal enrollment activation
- complete Android account admission flow
- preserve consent action contrast
- register consent action design proof
- clarify withdraw consent action
- ratchet runner bundle budget
- order meal capture enrollment authority
- ratchet hosted runner bundle budget
- unify sleep stage permissions
- prevent native memory accounting replay
- make scheduled call retries idempotent
- retain disabled native memory infrastructure
- preserve late Linq context for card delivery
- make support escalation attempt terminal
- keep context selection atomic
- keep Murph instructions within coverage budget
- preserve codex child thread cap
- preserve thread bindings across active turns
- preserve Murph-written support issue
- split codex child usage by turn
- keep auto replies on trusted thread routes
- measure compact table wire payload
- close remaining usage reset rollout gaps
- separate tracked table transcript authority
- remove native memory egress
- close usage reset review gaps
- fail closed on malformed support escalations
- harden usage reset epoch ownership
- mark Venice stable cache prefix
- harden usage reset epoch ownership
- disable native Codex memory generation
- shorten Venice provider option copy (#1319)
- render nutrition cards with HTTPS layout (#1312)
- constrain direct support issue handoff
- require verified direct support scope
- send explicit support escalations directly
- keep alert guidance within prompt budget
- suppress all generic alert recovery
- remove conflicting alert retry guidance
- close Prisma owner on every sync exit
- harden official weather alert context
- preserve consent across support opt-in merge
- keep connect recovery canonical
- keep weather alerts direct-only
- rank Zepp by adoption evidence
- preserve generated capture persistence context
- unify generated capture persistence ownership
- clear result marker before refresh
- keep support guidance within prompt budget
- keep support escalation consent truthful
- harden generated capture retention persistence
- serialize first-run foreground flows
- preserve due wake checkpoint ordering
- make checkpoint frontier diagnostics exact
- keep optional phone enrichment nonblocking
- preserve foreground priority across checkpoint races
- require informed support escalation consent
- make canonical state the only gate
- keep principal-bound consent retry stable
- finalize pending attachment wait
- skip waits for unrelated attachments
- bound pending attachment wait
- preserve changelog settings intent
- preserve first-visit onboarding from connect
- wait for pending attachment evidence
- close cross-platform review gaps
- isolate guide-only source state
- preserve Zepp guide semantics
- register onboarding design evidence
- cover persisted onboarding skip in design preview
- polish settings status layouts
- reset usage on plan upgrades
- register settings design proof
- polish settings status layouts
- reuse known photo references before asking again (#1289)
- require informed support escalation consent
- disconnect only the selected wearable source (#1274)
- include issue in support escalation alerts
- preserve usage denial semantics (#1283)
- preserve canonical phone on auth retry
- preserve live auth authority on retry
- make live bindings atomic
- keep identity recovery on one snapshot
- validate live identity rebinding
- dedupe Linq recovery capacity claims (#1275)
- preserve Zepp setup guide literal type
- compact only the new prompt body
- keep Zepp guidance within prompt budget
- run assistant prompt test from package root
- prepare Prisma before focused web tests
- apply Zepp ordering assertion to both catalog cases
- keep Linq provider failure reasons readable in operational alerts (#1268)
- never estimate messages remaining (#1265)
- recover matching verified email login
- compact oversized provider reads and surface failure codes to the assistant (#1259)
- keep claim recovery to internal repair
- make a confirmed recovery the answer, not a side note
- disclose recovered sends and bound the recovery lookup
- avoid synthetic group attribution
- keep attributed rows in the digest
- restore member attribution at the callback boundary
- recover stranded complimentary claims and clarify refusals
- close the unknown Linq group recovery follow-ups (#1257)
- stop retrying a phone transfer the provider already finished (#1255)
- validate Linq inventory snapshots and surface total contact-card outages (#1253)
- recover unknown Linq groups through signup (#1221)
- keep initial-visit redirect for members created before first web auth (#1243)
- reach inactive group invite reactors (#1222)
- skip group reaction attestations in growth senders (#1249)
- tighten phone link action label, icon, and spacing
- revoke relinquished Linq inventory ids and prove abort passthrough
- keep digest per-kind counts truthful past display cap
- reject malformed physical-note recipients safely
- validate home-line routing in phone-transfer census
- accept Stripe-owned pending SetupIntent on trial retirement
- date display-name audit by caller time
- keep contact-card cron alive past unowned provider lines
- declare sourceProviderSlug on junction initial jobs
- map casing requests to room tone (#1239)
- defer late turns during shutdown
- checkpoint staged images before shutdown
- give phone-transfer census a thirty-second transaction budget
- tolerate runtime bookkeeping in phone-transfer census
- normalize bound image completions
- fully redact compound blood-pressure readings
- distinguish image shutdown cancellation
- restore free-text summaries for anonymous feedback
- bind effects to exact authority
- allowlist avatar provider diagnostics
- harden group avatar provider delivery
- serialize live-steer drains
- distinguish abort before Lob dispatch
- release note reservation on pre-dispatch abort
- honor participant-backed group access for notes
- validate note artwork before reserving capacity
- remove prose from anonymous feedback
- anonymize product feedback by default
- require explicit wrong-line resend
- preserve edited onboarding schedules
- classify ordinary child recheck turns
- repeat wrong-line redirects daily
- harden physical note availability and replay
- bound late child rechecks
- keep habitat guidance within prompt budget
- register environment print telemetry
- align environment design fixtures
- ratchet combined runner bundle
- harden voice maintenance flow
- ratchet hosted runner bundle budget
- make environment grading honest
- make zero-data state the real report
- allow same-origin microphone capture
- anonymize product feedback by default
- bound live steering to provider coverage
- keep image diagnostics failure-scoped
- harden sponsorship layouts
- recheck late child results
- harden image failure recovery
- lock prior phone during transfer
- migrate the immediate onboarding predecessor
- complete physical-note safety gates
- open group sponsorship directly
- keep onboarding follow-up generic
- surface OpenAI image failure details
- minimize phone transfer failure logging
- bind group note approval to exact input [physical-note-authority-applied]
- require exact group approval for physical notes
- harden feedback digest delivery
- fence phone transfer billing authority
- expose referral details as buttons
- expose provider-valid physical-note bounds
- align physical-note address bounds with Lob
- keep wake signal off reply path
- make physical-note replays durable
- preserve image descriptions in delivery
- distinguish referral details
- preserve onboarding follow-up authority
- preserve generic usage options
- refresh generated skill hash
- render neutral fallback caveat
- exclude stale physical-note correction hunk
- keep group funding direct at any capacity
- scope onboarding decision contract
- make onboarding follow-up authority explicit
- disclose neutral progress-card fallback
- preserve Linq group receipt policy
- keep phone transfer retirement retryable
- harden phone transfer retirement fence
- isolate exact usage purchase returns
- reconcile transferred phone accounts
- package biomarker direction asset
- close onboarding recovery lifecycle gaps
- preserve frozen usage purchase recovery
- preserve Linq rich-link retry integrity
- apply physical notes with native exclusions
- integrate physical notes with current owners
- stream physical notes bootstrap patches
- calibrate group challenge stakes
- support Venice Responses Lite tools
- defer cross-model child routing
- recover incomplete Linq rich links
- preserve resumed latency traces
- keep subagent usage lookup off reply path
- disclose sponsorship activation charge
- make phone transfer sync authoritative
- narrow persona tone dialog
- defer V2 subagent model lookup
- stack onboarding tone options
- attribute routed subagent usage
- reconcile transferred phone links
- keep consent handoff terminal
- bind Privy reauth to app session
- harden phone link reauthentication
- clarify phone linking recovery states
- bind Privy reauth to app session
- harden phone link reauthentication
- align sponsorship amount hierarchy
- always publish explicit native access offers
- derive resumed latency before query bounds
- simplify sponsorship choices
- preserve group tool call arity
- cancel group Ask replay with its turn
- bound Assistant Ask wake handoff
- refine usage activity states
- update GPT-5.6 allowance pricing
- recover Linq rich-link delivery
- resume latency alerts after usage access
- clarify phone linking recovery states
- fail closed on mixed group routes
- complete usage design proof
- safely link phone accounts (#1187)
- enforce sponsorship cap during recovery
- tighten empty referral copy
- clarify empty referral copy
- bind direct email replies to owner (#1050)
- harden usage-denied latency exclusion
- query workflow through public testkit
- expose expanded usage history study
- close Linq rich-link replay window
- clarify provider storage copy (#1179)
- exclude usage-denied latency alerts
- canonicalize private response images
- linearize sponsorship need at admission
- avoid unnecessary sponsorship refills
- harden sponsorship review proof
- make sponsorship migration deploy-safe
- keep sponsorship caps payer-private
- preserve provider and settings truth
- wake hosted provider handoffs durably
- prioritize provider handoff over future wakes
- hand off hosted provider changes before next reply
- preflight external Temporal worker
- keep Privy restart session gated
- keep public phone paste manual
- pace R2 500 recovery
- finish R2 500 reconciliation
- scope pasted phone auto-send
- finish Privy session recovery
- preserve pain reasoning in group email
- wait for Privy session identity
- reconcile R2 copy HTTP 500
- finalize group reply cadence
- reconcile group cadence review
- reconcile Privy session hydration
- bound Venice privacy disclosure
- package current product specs
- understand pain context before restricting activity
- pin sponsor songs to fifteen seconds
- reread hosted source authority
- finalize homepage auth readiness
- keep auth controls truthful while Privy loads
- preserve webhook source admission
- keep tool descriptions within budget
- scope purchased credit history
- complete account deletion KMS repair
- restrict Vercel telemetry to explicit routes (#1153)
- keep homepage auth usable while Privy loads
- complete safe R2 retry guard
- drain R2 copy responses
- reject signed R2 redirects
- normalize account deletion KMS keys
- label AI usage disclosures
- retry safe R2 preconnect failures
- gate speculative Codex preparation
- constrain onboarding card widths
- keep onboarding steps on a horizontal track
- fence Codex workspace boundaries
- serialize Codex preparation boundaries
- unify Pulse trial scheduling guards
- resolve reviewed disclosure review findings
- derive trial guards from locked state
- retain multiple held GIF frames
- distinguish pending provider changes
- harden reviewed disclosure continuation
- resume reviewed group disclosures
- preserve receipt-correlated group recovery retries
- bind group trial and display authority
- sample GIFs by playback duration
- keep provider dialog reachable
- harden Privy readiness recovery
- share auth dialog header predicate
- reuse auth dialog header in catalog
- harden reviewed disclosure continuation
- keep auth-active dialog header visible
- close group plan review gaps
- resume reviewed group disclosures
- keep Privy readiness failure generic
- gate homepage auth on Privy readiness
- normalize GIFs into bounded filmstrips
- complete email-only Family acceptance
- preserve signed plan authority
- allow email-only Family acceptance
- preserve partial receipt state
- keep incomplete Linq signup partials absorbing
- close Linq rich-link identity gaps
- track Linq rich-link delivery parts
- enforce live Junction source admission
- preserve established local accounts
- consolidate source admission
- scope shared Junction setup
- finish callback proof remediation
- bind browser callbacks
- enforce hosted callback hostname
- bind device OAuth callback to owner
Documentation
- record scheduled recovery fix
- preserve release guard wording (#2003)
- close pr 1887 remediation plan
- record native E2E retry priority
- describe native E2E queue guard
- complete usage recovery plan
- clarify native E2E KMS boundary
- close runtime wake churn work
- note scheduled support recovery
- record sync recovery
- define reminder context rollback floor
- add workout reminder changelog
- note reliable reminder timing
- close phone call reliability plan
- remove routine changelog entry
- complete all-channel message volume plan
- note Telegram routine cards
- close sparse database port alert work
- collapse the production build-runner contract to one prose owner
- finalize phone-call writer rollout
- close phone-call policy reader plan
- drain phone-call starts before cutover
- harden phone-call writer cutover
- correct phone-call policy rollout
- record phone-call retry review
- close Junction webhook recovery plan
- add all-channel message volume changelog
- close database metric observability work
- note clearer workout saves
- complete direct wake recovery
- add Junction recovery changelog
- require backward-compatible card rollouts
- address native harness review findings
- add Product UX calibration examples
- close WHOOP canary recovery
- align phone call architecture contract
- close command failure diagnostics plan
- record queue diagnostic review retrospective
- complete Junction fidelity review
- note personalized next trials
- close micronutrient expansion plan
- record round 27 candidate proof
- record member-actions base proof
- record startup readiness budget
- record final Frog base proof
- close deterministic member actions plan
- announce connected meal nutrients
- record round 26 integrated proof
- record Frog current-base proof
- complete Product UX workflow
- add product UX planning and proof
- close hosted runtime e2e repair
- correct protected auth proof count
- record runner bundle byte mismatch
- record round 24 integrated proof
- remove stale active plan index entry
- fix completed PR plan index
- close Vercel build reliability plan
- follow archived review plan
- close food timeout plan
- unify metric rollback ownership
- note default exercise images
- record private integration pass
- record round 18 pass
- record trusted round 15 evidence
- record food timeout verification
- note reliable food lookups
- add faster dashboard changelog
- announce manual daily metric corrections
- define scalar cursor rollout
- note quieter recurring reminders
- record visual review packaging gaps
- complete Telegram rich content work
- record rich fallback review decision
- complete audit package trim
- announce direct Messages workout entry
- note flexible Telegram layouts
- close query-shaped database reads
- keep handoff proof scoped to plan
- close Linq delivery query plan
- track query-shape completion
- clarify Junction collection limits
- close database monitor retry plan
- close Telegram routine card repair
- note routine card resends
- close channel-native plan presentation
- link channel-native plan changelog
- close Composio identity repair
- note restored connected app actions
- close device snapshot status bounds plan
- note deletion web handoff
- note group audience routing
- note clearer personal patterns
- close Linq diagnostic compaction index
- close legacy trial checkout cleanup plan
- normalize Linq index task
- normalize Linq index task
- record pending-group merge verification
- record current-main device snapshot integration
- close wearable timing telemetry plan
- close group-share freshness work
- cite OpenAI model expansion
- record device apply verification
- record pending-group review retrospective
- complete PR 1420 merge readiness
- complete Codex runtime hard-cut plan
- archive browser assertion nonce plan
- record runtime hard-cut verification
- archive callback nonce plan
- link referral recovery fixes
- record shared-card device proof gate
- align shared-card handoff contract
- close container SSH removal plan
- add mobile homepage changelog entry
- clarify callback nonce expiry boundary
- record suppressed PR synchronize checks
- stop moving-base CI loops
- complete generated avatar byte binding
- close shared card handoff plan
- announce clearer card previews
- link shared card handoff PR
- complete changelog fragment rollout
- add family recovery changelog
- complete fanout review guidance
- resolve fanout prompt review
- track fanout review plan
- review database collection fanout
- clarify static fallback catalog
- refresh generated avatar proof
- close generated image avatar continuity
- note scheduled card route recovery
- close hosted runtime progress alert
- note sharper single-photo review
- record health data row polish
- require agents to commit Frog friction logs (#1604)
- close assistant audience authority work
- close settings and chat plan
- record round 11 remediation
- close workout card device remediation
- close Android visibility gate plan
- note model-free wearable recovery
- align Android deploy variable scope
- update sleep challenge changelog
- record round 11 candidate proof
- add referral recovery changelog
- record personality verification evidence
- publish personality settings changelog
- note cleaner workout cards
- close hosted web-search 403 plan
- index Codex pin ownership
- clarify independent Codex pins
- close bounded settlement plan
- announce restored web search
- record bounded capacity contract
- remove stale merged measurement
- record round 10 merged proof
- record follow-up verification
- require short database transactions
- preserve newsletter schedule timezone contract
- announce reliable reminder timing
- close automation timezone repair
- record round 9 candidate proof
- allow GitHub design proof attachments
- record merged runner measurement
- close Stripe billing hardening plan
- record round 8 continuation
- pause at ReviewGPT hard cap
- define bounded settlement contract
- record rollback floor proof
- complete Family Max chat remediation
- close image completion preemption plan
- record scheduled-call render proof
- clarify Family Max rollback floor
- record physical media proof
- record hard-cap remediation proof
- record Telegram admission KMS fix
- record tuple verification
- record exact thread routing proof
- update thread route snapshot proof
- archive dirty classification plan
- record thread route root prewarm proof
- update latest thread routing proof
- record provider input impact
- close group usage status plan
- close Codex 0.147 review plan
- refresh release index
- record round four review disposition
- record merged candidate verification
- close runtime failure diagnostics plan
- record provider input impact
- record round three review dispositions
- register expanded changelog study
- record exact-head changelog proof
- archive Family Max execution plan
- record static card review completion
- clarify completion route identity
- define Family Max rollback floor
- complete Vercel cron cadence plan
- record corrected cron verification
- record exact provider input measurement
- record static card review gates
- record PR 1381 candidate proof
- align static caption contract
- record final card verification
- catalog database transaction starvation risks
- add training dashboard design proof
- archive footer online follow-up plan
- fix computer journey ownership
- specify member-owned device provider applications
- record footer review disposition
- archive homepage footer completion plan
- disclose footer status-page processing
- close export pack retirement task
- document Max rollout order
- archive hosted crypto standby preload
- label inference choice study
- disclose footer status-page processing
- complete unified group funding contract
- show neutral published comparator study
- align biomarker chart design guidance
- keep published biomarker comparators non-semantic
- define biomarker reference range bands
- anchor biomarker range band study
- require hosted env deployment parity
- audit iOS and Android companion parity
- record final hosted card proof
- record final card verification
- record response card verification
- close Ink throttle import plan
- record Ink runner bundle proof
- record response card verification
- disclose Ink runner artifact impact
- archive Zepp execution plan
- close runner image compaction plan
- record Ink import proof
- close sponsored funding recovery
- close Linq attachment recovery plan
- record final scheduled tool audit
- close Stripe failure alert plan
- archive hosted billing browser plan
- close Junction runtime payload plan
- disclose occurrence continuity reset
- record Junction dependency ownership
- record Junction runtime proof
- close PR 1393 audit plan
- complete Zod runtime pruning
- revise Junction runtime removal
- document thread rotation rollout
- record final review remediation
- record dynamic tool retrospective
- refresh zod prune proof
- close Zod startup plan
- record post-merge Zod proof
- complete cold-phase telemetry
- close cold-start observability plan
- complete runtime receipt rollout
- clarify growth snapshot failure boundary
- close outbox scan plan
- record growth completion blockers
- classify Stripe alert review lenses
- record Linq recovery verification
- register growth activity design study
- preserve product-spec index newline
- index the first personal read
- specify the first personal read contract
- enforce safe OC retirement order
- complete growth attribution rollout
- record native deferred tool discovery boundary
- add native image runtime deletion candidate
- add Codex-native runtime deletion audit
- record telemetry final proof
- clarify telemetry fallback reads
- record outbox review evidence
- correct runner image measurement
- complete compact onboarding routing
- close Android companion admission plan
- record admission review retrospective
- record compact onboarding shrink
- close meal enrollment ordering plan
- update compact onboarding evidence
- close post-enrollment prewarm plan
- complete single sleep permission plan
- complete scheduled phone call plan
- record sleep permission rollback contract
- record scheduled call merge verification
- select compact onboarding router
- add first-contact fast welcome
- index meal enrollment ordering contract
- close native memory restoration plan
- record scheduled phone call verification
- fix support plan history link
- close usage reset capacity epoch plan
- complete size-aware context plan
- close support escalation email plan
- approve bounded table fragments
- close written support issue plan
- complete Venice prompt-cache fix
- close native memory disablement
- close support escalation plan
- establish incident.io response workflow (#1327)
- record support escalation retrospective
- preserve PR verification lessons
- order support escalation rollout safely
- record structured support alert proof
- record exact support escalation proof
- remove obsolete support rollout gate
- close weather health context plan
- refresh support measurement base proof
- align support escalation index
- record direct support escalation proof
- publish official local alert context
- align Turbopack verification owners
- track weather health context
- complete generated capture retention plan
- record generated retention review disposition
- complete support input attribution
- align support escalation disclosure
- record support composition review
- record support consent verification
- update support prompt measurements
- record stacked review evidence
- record support review corrections
- close hosted reply latency diagnostics plan
- record Zepp review retrospective
- coordinate support escalation rollout
- clarify physical-note retention
- clarify settings design proof
- publish August 1 through 4 changelog
- record support alert rollout window
- place Privy rebind invariant
- single-owner the summary-content policy
- reconcile feedback redaction to best-effort position
- close group avatar provider failure plan
- align private avatar contract
- document avatar capability rollout
- complete anonymous feedback privacy plan
- record physical-note pre-dispatch abort boundary
- archive image failure plan
- record final physical-note admission invariants
- close onboarding follow-up plan
- align daily redirect contract index
- close daily redirect plan
- record closed feedback prompt impact
- close late child result rechecks
- record feedback privacy verification
- close detailed feedback plan
- add current group funding release
- record phone transfer concurrency proof
- plan native companion signup
- add environment design proof
- close real-data implementation plan
- record feedback privacy verification
- close detailed feedback plan
- index immediate group funding controls
- align group funding route contract
- record rebased prompt verification
- refresh provider input measurement
- close product feedback digest plan
- complete progress-card asset fix
- bind later group note sends to exact approval
- record reminder wake ownership
- close group funding availability plan
- record high-resolution design proof
- complete Venice Responses Lite fix
- index phone transfer security invariant
- close phone account linking plan
- close phone account linking plan
- label referral design study
- close Assistant Ask handoff port plan
- run ReviewGPT stages in parallel
- complete unified group access offers
- require frontend simplicity (#1182)
- finalize private image delivery plan
- close capped sponsorship plan
- record sponsorship completion proof
- remove stale public worker replay claim
- align private rollback ownership
- close public Temporal cleanup plan
- close pasted phone auto-send
- register phone handoff design study
- close provider dialog polish plan
- keep live scenario docs canonical
- refresh product sense index
- close sponsor song prompt plan
- document bounded copy retry
- close Codex warm latency plan
- close disclosure gate retrospective
- close compact provider setting
- close Privy readiness remediation plan
- point local development at Murph Cloud
- name the private Murph Cloud checkout
- show paid plan confirmations
- record callback acceptance
- record verification fallback blocker
Changelog
Full Changelog: v1.3.0...HEAD
- Fix release boundaries and PR gate preflight (#2013) (7efea87)
- Add a farewell after account deletion (#2012) (fbb74db)
- feat(review-gpt): add Apollo browser lane (#1906) (f926d91)
- Restore Cloudflare runner CPU and memory (#2011) (862b69f)
- Restore account deletion after storage retirement (#2007) (6dd05f8)
- test(hosted): close assistant block edge coverage (71aab6d)
- fix(runtime): align system mailbox frontier ownership (c7e2ad9)
- docs(changelog): record scheduled recovery fix (0f272e6)
- fix(hosted): propagate assistant blocks to system work (96a04bd)
- test(assistant): cover remapped Linq thread context (#2004) (302d665)
- docs(workflow): preserve release guard wording (#2003) (8b6ba3e)
- fix(runtime): preserve foreground retry quiet window (#2005) (ab1e5a0)
- Unblock hosted runtime wake fix deployment (#2006) (fdec2cd)
- test(ci): align direct Vercel build contract and archive plan (#1989) (0f282db)
- chore(workflow): require PR deployment concerns (e24f388)
- docs: close pr 1887 remediation plan (144bec0)
- fix(assistant): preserve group email fanout identity (5f09fbf)
- fix(sync): scope Junction provider limit (a0438ce)
- fix(assistant): preserve transport dedupe identity (58ea9d4)
- fix(sync): preserve actionable blocked wakes (739fd1c)
- docs(frog): record native E2E retry priority (3ae7732)
- docs: describe native E2E queue guard (d8b4871)
- docs: complete usage recovery plan (5744072)
- docs: clarify native E2E KMS boundary (34eb8ff)
- fix(sync): preserve blocked recovery wakes (2350d44)
- docs(plan): close runtime wake churn work (96e9d02)
- ci: preserve native iOS E2E queue (e6bc135)
- test(web): align WAF assertion with main (ef832c3)
- ci: preserve native iOS E2E queue (471fdf1)
- test(web): normalize WAF build command (9eeca55)
- fix(sync): close hosted recovery gaps (332ef5d)
- fix(e2e): bound native web build wedges (a8101e7)
- fix(sync): preserve coupled sleep normalization (0e703f5)
- fix(assistant): narrow legacy media fallback (31b1c0f)
- fix(web): simplify reminder generations (b9fb07e)
- feat(web): remind on stalled runtimes (c8a2774)
- fix(runtime): drain grouped image completions (aa046f1)
- Make runner the device-sync failure-log owner (#1883) (dd2ee39)
- fix(web): keep exhausted purchase returns visible (39fd271)
- docs(changelog): note scheduled support recovery (c2c7770)
- test(web): align WAF order assertion (a8fac4c)
- docs(changelog): record sync recovery (3dac287)
- fix(hosted): retry foreground after system handoff (2050659)
- fix(sync): resume stalled hosted reconciliation (b2f2699)
- fix(web): preserve usage recovery precedence (3b315b4)
- Prove runner memory command parity (#1880) (78845b3)
- fix(web): restore Starter usage from Ops (#1982) (ba3278d)
- fix(runtime): preserve retry completion quiet window (d6a55c7)
- fix(ci): simplify Vercel build ownership (#1988) (d00feda)
- Add bounded command-family turn profiles (#1878) (efc3cf5)
- fix: preserve stale workout identity (dd753c8)
- fix(ci): let successful Vercel builds complete (#1986) (e6b65d0)
- Reduce device webhook database work (#1974) (6eef19b)
- Complete stale assistant-wake device recovery (#1985) (842a2b0)
- test(assistant): narrow reply history fixtures (407b372)
- fix: preserve workout clarification context (fc3bd67)
- Recover queued device sync after stale assistant wakes (#1984) (e1007a0)
- fix(assistant): normalize optional anchor lists (93b22cd)
- fix(web): address usage recovery review findings (e9fafaf)
- fix(assistant): preserve bounded reply anchors (b391948)
- fix: require workout closure intent (f7d411c)
- fix(assistant): bound optional auto-reply history (e7bdd9d)
- Link usage recovery changelog (508a95c)
- fix(runtime): preserve trusted completion quiet window (de2c608)
- Improve usage recovery UX (81f5d63)
- fix: avoid inferred workout end times (8797c5b)
- Keep connected-health syncs bounded (#1980) (0c5eb68)
- fix(runtime): keep system work off reminder quiet window (451f251)
- fix: preserve device reminder context (17f88bc)
- fix(runtime): reconcile due wake successors before sleeping (09d9bfc)
- fix: preserve references for media reminders (1494bb7)
- fix(assistant-runtime): retain aggregate reminder continuation (67f5d41)
- docs: define reminder context rollback floor (502ab4a)
- fix: preserve reminder context across live sessions (26140b1)
- fix(assistant-runtime): preserve reminder barrier during canonical writes (38eb513)
- test: align assistant delivery expectation (9b385fb)
- chore: refresh cli generated schema (f423275)
- docs: add workout reminder changelog (a45ae0d)
- fix: add reminder context references (e4222a1)
- fix(assistant-runtime): preserve foreground quiet window (a2e7865)
- fix(assistant-runtime): preserve foreground checkpoint priority (981526e)
- test(assistant-runtime): require durable reminder handoff (f66d5c7)
- docs(changelog): note reliable reminder timing (cfa7a46)
- Halve Cloudflare runner resources (#1978) (e5ca79d)
- fix(runtime): retain later assistant wake through checkpoint (ab1b9aa)
- docs: close phone call reliability plan (05e3706)
- test(runtime): remove stale result barrier expectations (afa52ad)
- fix(runtime): serialize outbox projection recovery (182c72d)
- Ratchet measured runner bundle budget (#1976) (9181bd3)
- Bound assistant session routing index growth (#1910) (09cd7d2)
- refactor(repo): simplify provider request guard (#1752) (d6cfc0f)
- fix(ci): encode native E2E database options (#1972) (f3a54f1)
- fix(ci): stabilize native iOS hosted E2E activation (#1969) (0577af5)
- Improve sponsorship limit confirmation (#1955) (4aa043a)
- fix(ci): declare native E2E database runtime (#1967) (98d1168)
- CI: preserve native iOS E2E failure stages (#1961) (7022329)
- test(hosted): fix wake boundary assertions (#1953) (90f603a)
- Stop ReviewGPT from auditing PR body discrepancies (#1958) (87d54c4)
- chore(web): follow screenshot telemetry exclusion (a4fc21d)
- fix(web): publish canonical search metadata (#1935) (a212ee2)
- chore(ci): drop superseded review assertions (cc5bd0f)
- fix(web): register screenshots telemetry path (b376afd)
- Keep Family usage purchase receipt visible (b0f7c98)
- ci: activate native iOS hosted sweep (3797bef)
- fix(ci): isolate native iOS Junction identity (#1943) (e66d70a)
- test(ci): follow review workflow ownership (0b1f674)
- test(ci): align review loop coverage (eef4751)
- chore(review): require material production harm (#1951) (8b07522)
- fix(runtime): bound foreground reply state reads (bf72e7c)
- test(ci): align review prompt coverage (2a4357c)
- Fix first-time automation inspection recovery (#1936) (ecce6e2)
- Diagnose Junction workout-stream 500 failures (#1946) (792667f)
- Fix quiet usage return edge cases (c91c46d)
- fix: keep phone results behind foreground replies (4dde351)
- refactor(runtime): keep the owned mailbox port (586a71f)
- Log ReviewGPT lane-count precedence friction (2ffa73e)
- Unify signed-out connected source actions (#1937) (f0cb12a)
- Fix usage return continuation ownership (092c354)
- docs: remove routine changelog entry (ebf608e)
- test(cli): allow prompt line wrapping in review assertion (747a6b6)
- Fix Settings usage return edge cases (0dd304e)
- fix: preserve tracked result receipts after provider acceptance (6d69157)
- test(web): respect inert screenshot studies in overflow check (ad9d9cd)
- fix(runtime): preserve member action outcome receipts (cbd508c)
- Update quiet usage design assertion (14557e2)
- Add quiet usage return changelog (8dd852b)
- Remove Settings usage success modal (1187deb)
- docs: complete all-channel message volume plan (947e253)
- test: prove message-volume receipt recovery (7d9f989)
- test(assistant): make routine card proof deterministic (2e7167a)
- test(web): freeze training week bucket clock (440e5c6)
- test: complete message-volume callback mocks (7a515b2)
- test(assistant): prove routine card repair behavior (681d25e)
- fix: make message-volume receipts converge (35d1ac1)
- test(assistant): preserve routine fallback detail (f904ea1)
- docs(changelog): note Telegram routine cards (1c2bc39)
- fix(assistant): keep Telegram exercise routines in one card (cd9a671)
- chore(workflow): simplify Product UX review (c82040b)
- docs(plan): close sparse database port alert work (88d2442)
- refactor(cloudflare): collapse database metric confirmation (fb4ad99)
- fix(cloudflare): preserve rollback metric evidence (7d8a484)
- fix(cloudflare): ignore sparse database error ports (09a93f7)
- fix: recover definitive result delivery failures (5dbad42)
- fix: recover no-effect result exhaustion (237d888)
- test: freeze training week clock (62f04d8)
- fix: recover pre-provider result exhaustion (ccde0fd)
- feat: log hosted reasoning effort (#1912) (fe778eb)
- fix(web): hold process ownership through descendant reaping on cancellation (51ce69a)
- fix: retain phone result crypto preparation (7c7e131)
- refactor(web): delete the redundant post-success Webpack-cache discard and stale watchdog ownership prose (1b92fc9)
- fix(runtime): stop stale carried wakes from shadowing fresh due work (#1931) (79cdf76)
- fix: keep phone recovery hints best effort (b3c74bf)
- fix(web): move the production build deadline into the package-build process owner (f6caaa6)
- docs(web): collapse the production build-runner contract to one prose owner (d8767b9)
- fix(web): keep the build watchdog in the caller's process group and prove fail-closed discard (04d96dd)
- fix: isolate phone recovery sibling obligations (d858853)
- fix(web): keep production Webpack compiles cold and bound them with a build watchdog (ffb6522)
- fix: settle all phone recovery obligations (c6c9f6f)
- fix: bound dormant phone recovery cadence (b68baa2)
- fix: recover dropped phone result wakes (59b849a)
- Introduce Murph on the referral share card (#1928) (21e6e54)
- test: align production build memory guard (b53f633)
- fix(cloudflare): update vault bundle size budget (#1930) (5082925)
- fix: guarantee late phone result recovery (fbbd73e)
- fix: complete phone recovery release gates (45ad42f)
- fix: make phone recovery workflow single-owner (0bbb45b)
- fix: bound Telegram route recovery rearm (3c3bf15)
- Prefer Rich Messages for structured Telegram replies (#1926) (a7c14dd)
- fix: ratchet reviewed runner bundle growth (682f961)
- docs: finalize phone-call writer rollout (0d8fefb)
- docs: close phone-call policy reader plan (099c573)
- docs: drain phone-call starts before cutover (80dca9e)
- Update ReviewGPT to 0.5.133 (#1927) (ad58a86)
- docs: harden phone-call writer cutover (8b8db3c)
- Fix ambiguous live-workout set confirmations (#1925) (6afc002)
- docs: correct phone-call policy rollout (7f6d028)
- fix: honor stored phone-call completion policy (f24bd3b)
- Serve share-card images from ungrouped segments (#1922) (736219e)
- feat: accept phone-call result policy (0d6ce3f)
- fix: preserve transfer follow-up recovery (fcb5cd9)
- test: restore legacy changelog ownership (2b4b12e)
- Share cards for referral, connect, and group funding links (#1920) (7525887)
- fix: scope phone-result foreground delivery (3df2942)
- test: align phone-result checkpoint coverage (925e7c4)
- fix: prevent phone-call result starvation (b5eba26)
- fix: preserve Telegram reply grouping (d814b9d)
- docs: record phone-call retry review (0d2d57f)
- fix: recover no-send phone-call result retries (9ef7b42)
- chore: drop unrelated lockfile churn (c21a35a)
- fix: preempt reminder maintenance at deadline (74deeff)
- fix: anchor callback retry after failure (2b9c9d0)
- docs: close Junction webhook recovery plan (073835d)
- Fix WHOOP canary rendered consent action (#1915) (0ce266d)
- test: align all-channel message volume contracts (aa0d5c1)
- Generalize workout CSV imports (#1769) (e5e7a4c)
- chore(review-gpt): update to 0.5.132 (9269392)
- fix(device-sync): preserve established webhook ordering (f22e46a)
- fix: dedupe planned experiment sessions (bc57634)
- fix(assistant): keep direct route fallback Telegram-only (27ddf8a)
- test: complete planned occurrence release proof (fbbbadd)
- fix: preserve phone call conversation authority (d6f6fe2)
- docs: add all-channel message volume changelog (f7673fd)
- chore: inherit review-gpt update from main (f70a8ff)
- fix: preserve phone-call result confirmation recovery (8edba58)
- feat: count Telegram and email message volume (4c80ae8)
- fix: preserve planned experiment occurrence (9c53764)
- test(assistant): prove unknown direct routes stay closed (9cb39a4)
- fix: recover missed device sync wake signals (bca8329)
- docs(plan): close database metric observability work (18e4aa3)
- Run managed health scouts on Sol (#1896) (3e0dca0)
- fix: preserve first phone call result (9df6ec7)
- docs(changelog): note clearer workout saves (e348499)
- Index pending image completions for hot replies (#1905) (bdc2b85)
- docs(plan): complete direct wake recovery (a2c0c5e)
- fix(device-sync): bound pending webhook retries by setup lifecycle (f138af4)
- test: prove ReviewGPT conversation stabilization (538b18c)
- fix: complete Junction webhook source recovery (8dd9451)
- test(web): align Stripe effect unit fixture (b6c78fc)
- Batch queued device webhook admission (#1888) (4ee98ad)
- fix(review): preserve unrelated lock graph (50c95f6)
- fix: require confirmed phone reconciliation wake (f96b901)
- test: cover ReviewGPT 0.5.132 behavior (62cf86b)
- fix: preserve Telegram reminder reply targets (682e9a0)
- chore: update ReviewGPT to 0.5.132 and guard timing options (#1900) (fa95278)
- chore(tooling): update ReviewGPT to 0.5.132 (74d0ddb)
- fix(runtime): accept equivalent mailbox timestamps (b65c714)
- chore(tooling): update ReviewGPT to 0.5.132 (388db5f)
- chore: update ReviewGPT to 0.5.132 (d14db02)
- fix Stripe effect authority revalidation (e4a7fee)
- Fix malformed optional Junction workout streams (#1895) (6ad251b)
- test: allow native E2E workflow_run handoff (b271626)
- fix: retain parsed database metric evidence (3654b84)
- chore: update ReviewGPT attachment verifier (941398c)
- fix: preserve durable webhook work across source races (285bd07)
- test(device-sync): prove replacement setup webhook fencing (7b19f56)
- fix(device-sync): consume superseded setup webhooks (b994965)
- fix(device-sync): terminate expired setup webhook retries (4ea36b1)
- Compact snapshot lifecycle logs (#1882) (3d244e9)
- test: include phone call origin migration (6bfed0c)
- chore: update ReviewGPT to 0.5.131 (#1899) (aa9f4f0)
- test(review): align ReviewGPT 0.5.131 contracts (ab89c7e)
- chore(ci): expose safe WHOOP auth diagnostics (#1874) (0273fd4)
- fix: require positive Junction source proof (1002e57)
- fix: clarify native E2E controller trust boundary (2d852c9)
- test: align ReviewGPT release audit with 0.5.131 (a210489)
- test: align ReviewGPT release guard (f24365b)
- chore(review-gpt): update to 0.5.131 (2529a93)
- Add Vonneumann ReviewGPT browser lane (#1897) (3b3f54a)
- Dedicated OG share card for approval links (#1893) (8fb49f1)
- docs: add Junction recovery changelog (1bf41b8)
- fix: recover pending Junction webhooks (871988b)
- chore: update ReviewGPT to 0.5.131 (743a4dd)
- fix: count repeated results in sidebar (a2cde5b)
- Trace generated-audio phase timing (#1881) (bb0f740)
- chore(review): update ReviewGPT to 0.5.131 (9e5418e)
- fix(hosted-runtime): preserve cold wake trace (e7a4386)
- fix: address native iOS E2E review findings (15afec6)
- chore: harden final review verification (92e6be9)
- chore(tooling): update ReviewGPT to 0.5.131 (c7021f7)
- fix: recover call results independently of usage (214b8d0)
- chore: update ReviewGPT to 0.5.131 (7f586f4)
- Add bounded repair hints for invalid dynamic tools (#1876) (ba684f8)
- test(device-sync): prove replacement setup webhook fencing (928c2cd)
- fix(cloudflare): keep telemetry evidence consistent (1cc8273)
- fix(device-sync): consume superseded setup webhooks (d6b8ab1)
- Measure repeated provider-input tool output (#1877) (32a8e24)
- fix(assistant): return repairable card validation hints (#1849) (5854b51)
- fix(cloudflare): preserve database metric gap evidence (b739864)
- Require motion-proof video evidence for UI state-transition PRs (#1884) (04588e0)
- fix: keep phone delivery checkpoints foreground (0c92088)
- Bound Linq health and vault-share collection work (#1732) (49438f9)
- Bound hosted cleanup and retain completion owners (#1746) (b4e7ae2)
- Preserve staged mailbox progress and harden hosted gates (#1879) (4c0cba5)
- fix(device-sync): terminate expired setup webhook retries (ce71867)
- Retain direct welcome context (380ecea)
- fix: preserve reminder-backed experiment provenance (f8327db)
- fix(hosted): suppress Telegram signup outreach (#1889) (f60d656)
- fix: move native iOS hosted E2E scripts to root (6d41b49)
- docs(imessage): require backward-compatible card rollouts (3ca8761)
- fix: checkpoint phone result delivery claims (303442f)
- fix(hosted): import initial activation before conversation turn (#1864) (5281d17)
- fix: recover pre-provider call result attempts (6471b2f)
- fix(hosted-runtime): scope wake cleanup deadline (c335c55)
- Bound cross-session context latency before MRF replies (#1801) (d532be5)
- test: add production-faithful native iOS E2E (d02972c)
- ci: add native iOS hosted E2E gate (f552f04)
- docs: address native harness review findings (ca9404a)
- plan: design native companion e2e harness (7c5f5d4)
- fix: recover stale phone-call result callbacks (41f5c43)
- fix: durably confirm phone-call result delivery (fcedbad)
- fix: harden phone-call result completion contract (a9d718f)
- fix: close phone-call result routing races (13cd9c4)
- fix: keep phone call delivery migration expandable (c7adf05)
- fix: make telegram call result delivery durable (af8744d)
- Prepare direct Telegram routing before transactions (#1718) (5694ee8)
- fix(web): keep Stripe receipts retryable during claims (2ec4bea)
- docs(workflow): add Product UX calibration examples (af84e9e)
- fix(web): complete Stripe claim authority cutover (84f291a)
- fix: prioritize telegram phone call results (fac0543)
- fix: preserve phone call result authority (7832ae0)
- fix(web): harden Stripe effect compatibility cutover (6a65af6)
- chore: sync friction log (b3a2272)
- test(hosted): guarantee retry barrier cleanup (85bc0f4)
- fix(cloudflare): accept workerd public ECDH JWKs (#1868) (fe0f58e)
- fix(runtime): refresh pre-assistant system mailbox (6a595a0)
- test(hosted): make direct wake retry e2e deterministic (c505eb9)
- fix: classify scheduled call route loss (b178d4d)
- test(hosted-runtime): prove bounded wake retry recovery (00ff7be)
- Lower personal and automatic compaction thresholds (#1844) (193debf)
- docs(plan): close WHOOP canary recovery (b0f23a5)
- fix: persist phone call fallback results (9d7917f)
- docs: align phone call architecture contract (d1cf327)
- feat: route Telegram phone call results (79ebf8b)
- fix(repo): harden repository and worktree lifecycle (9c01ab2)
- fix(hosted): scope activation completeness to system lane (3911ef9)
- fix(ci): use stable Chrome for WHOOP canary (cdf2d53)
- fix(phone-calls): notify foreground cleanup outcomes (ce8d051)
- fix(phone-calls): report uncertain cleanup truthfully (9394c26)
- docs: close command failure diagnostics plan (d4d76ad)
- docs: record queue diagnostic review retrospective (20e2628)
- refactor(device-sync): collapse Queue diagnostic vocabulary (f2fd5c6)
- fix(phone-calls): preserve cleanup result delivery (c92037c)
- fix(hosted-runtime): sanitize direct wake log inputs (c25e77c)
- fix(web): harden frontend verification workflows (e7da6c7)
- fix(assistant): remove redundant failure class (7738e52)
- fix(cards): support larger tracked workouts (#1730) (6aad526)
- fix: notify failed phone call cleanup (e7e48b9)
- fix(device-sync): keep Queue stages out of provider responses (8e1d318)
- fix(hosted): classify activation within shared prefetch (cd0a56b)
- fix(hosted-runtime): recover slow direct wakes (fed98f9)
- fix(assistant): keep failure classes evidence-based (3354b5c)
- docs(plan): complete Junction fidelity review (92920ed)
- fix: settle every terminal phone call outcome (0cf20c6)
- test(device-sync): close Queue failure proof gaps (ac7cd57)
- Classify incomplete rotations at OAuth boundary (911b7a9)
- fix(device-sync): expose queue transport failure stage (6c9e1e9)
- test(hosted): keep ordinary system wake checkpoint-gated (780063d)
- fix(assistant): recognize quoted search commands (bc3aab4)
- Fence incomplete provider token rotations (8d02e32)
- fix phone call result routing and stop settlement (07a7703)
- fix(review): isolate concurrent ReviewGPT packaging (091cf0e)
- fix(assistant): classify command failures safely (0d60604)
- fix(hosted): admit initial activation before idle checkpoint (7e65478)
- fix(assistant): align personalized trial boundaries (947ab2d)
- Preserve refresh cleanup authority (21b4678)
- fix: preserve reminder runtime authority (836f462)
- fix(review): harden ReviewGPT lane prompt continuity (6dac6d7)
- test(hosted): cover member action wake priority (2ac44a3)
- Update biomarker verification record (4110158)
- Fence ambiguous refreshes before account suspension (0d4fa28)
- fix(ci): prepare CLI artifacts for diff tests (88c2282)
- docs(changelog): note personalized next trials (a9693ed)
- Preserve stale biomarker recovery (c55c1f8)
- test: classify phone call stop intent metadata (27eef1a)
- chore(cloudflare): ratchet reviewed runner graph (471093d)
- feat(assistant): recommend bounded longitudinal trials (9e86801)
- docs: close micronutrient expansion plan (c3e1063)
- docs(plan): record round 27 candidate proof (6ceaa92)
- fix(device-sync): unify source lifecycle authority (4a48981)
- fix(nutrition): preserve micronutrient evidence semantics (1572d3e)
- docs: record member-actions base proof (898f33f)
- fix durable phone call termination (8af3864)
- Serialize token refresh with account suspension (fdf253e)
- docs(hosted): record startup readiness budget (fde9fd1)
- docs: record final Frog base proof (7014a91)
- Revert "test: align ReviewGPT 0.5.127 audit" (9c26465)
- test: align ReviewGPT 0.5.127 audit (a309d90)
- docs: close deterministic member actions plan (e14c4e2)
- fix(hosted): stabilize cold-start recovery proof (55f6a31)
- Cover quiet biomarker refresh states (8ce61c5)
- test: cover ReviewGPT idle cleanup (#1839) (4d7db20)
- docs(changelog): announce connected meal nutrients (58f64db)
- feat(nutrition): expose connected micronutrient totals (89b9a53)
- chore(ci): mirror current runner budget (a85c2f2)
- align outbox occurrence expectation (28ea5b8)
- docs(plan): record round 26 integrated proof (47ad016)
- test(hosted): use canonical one-shot schedule (8ee41c0)
- fix(assistant-runtime): preserve hosted source identity (5c36f59)
- fix: reject ambiguous workout action targets (251691a)
- record phone call verification evidence (0500a85)
- docs: record Frog current-base proof (667cf4c)
- chore: update ReviewGPT to 0.5.127 (#1832) (36089c2)
- docs(workflow): complete Product UX workflow (ff15d00)
- fix(cloudflare): raise runner bundle cap by ten percent (#1827) (aae480e)
- Update ReviewGPT to 0.5.127 (ad63998)
- fix(workflow): resolve Product UX review findings (9ac06e8)
- add phone call follow-up changelog (691a3dc)
- fix phone call status and result delivery (c2d9af1)
- Preserve recovery fences and guidance (70c4093)
- fix: complete Frog handoff recovery (5b67b3f)
- ratchet reminder runner bundle budget (e04f422)
- fix(ci): align runner bundle budget (1b59a1d)
- docs(workflow): add product UX planning and proof (3f6d5bf)
- docs(plan): close hosted runtime e2e repair (5f0386c)
- fix(ci): restore runner bundle and assistant gates (#1828) (a01593c)
- fix(device-sync): preserve complete provider days (7540e2a)
- test(device-sync): make retained claim order explicit (b237bea)
- docs(plan): correct protected auth proof count (92968a2)
- test(hosted): align protected auth provider identity (e76811f)
- test: refresh merged integration fixtures (5488384)
- docs(friction): record runner bundle byte mismatch (bfda3ef)
- Add biomarker loading changelog (9e05a98)
- document reliable experiment reminders (68a05a3)
- Improve biomarker result loading (38a98fb)
- harden reminder wake and reply paths (a4115e7)
- fix reminders and experiment reply authority (d4993cb)
- test(cloudflare): ratchet integrated runner total (5b50c65)
- chore: refresh runner bundle ratchets (e315a71)
- Require reconnect after stale token refresh (9c70962)
- docs(plan): record round 24 integrated proof (f728238)
- fix(hosted): centralize recovery proof ownership (21e7dc0)
- fix(device-sync): retain sparse repair beside retry (739dc8f)
- fix: bind workout actions to positional identity (cb3d126)
- Preserve credentials during stale lease recovery (7aa34d9)
- docs: remove stale active plan index entry (966ea86)
- docs: fix completed PR plan index (d864c88)
- fix(hosted): preserve exact local runtime semantics (efb4651)
- docs: close Vercel build reliability plan (bab3bfa)
- docs(index): follow archived review plan (4a52fdd)
- Update ReviewGPT and bound refresh recovery (0a76d57)
- chore: update ReviewGPT to 0.5.126 (00cc6be)
- chore(review): update ReviewGPT to 0.5.126 (273cdef)
- test(frog): isolate synthetic git hooks (92fb082)
- test(web): execute production build cache transitions (c213d2e)
- Harden account deletion recovery fences (f73f0db)
- chore(frog): record fast specialist attestation gap (530e547)
- test(hosted): close integration fixture plan (bec62c2)
- Align Junction continuation coverage (17e9d9a)
- test(hosted): fix specialist fixture findings (fc5b4b5)
- test(hosted): refresh integration gate fixtures (0b03394)
- fix(hosted): preserve local OpenAI response semantics (db091b1)
- chore(web): restore production-only deploys (fb30bdd)
- Archive PR 1705 execution plan (85ed4db)
- test(device-sync): strengthen minified first-connect coverage (#1820) (379643a)
- refactor: delegate marker restoration to Git (214875c)
- Update ReviewGPT to 0.5.126 (#1817) (ca5515f)
- fix(assistant): carry forward workout reps only (b867b4f)
- fix(web): invalidate incompatible build cache (8a23b1b)
- Fix Junction continuation repair ownership (f7e0722)
- fix(hosted): route local sandbox by provider identity (eb209d0)
- fix(workouts): bind cards to action revision (5219a37)
- Fix Starter activation hard navigation (#1809) (0855fcb)
- chore(web): override preview ignore step (2cbf82d)
- chore(web): force Webpack preview [vercel deploy] (4d887ed)
- chore(web): allow the Webpack proof branch (a212c3b)
- fix(web): restore reliable Vercel builds (8cdf521)
- Use 180-minute ReviewGPT handoff waits (#1712) (4c4a7c2)
- Correct device-sync recovery proof for v2 snapshots (#1812) (5d2a092)
- test(hosted): stabilize hosted integration scenarios (8805ac5)
- fix: keep saved experiment history off core routes (d6f7b73)
- fix(device-sync): restore first-time Apple Health connections (#1813) (ea9d023)
- fix: keep unrelated temp clones from blocking commits (#1803) (dc14e99)
- fix: restore Spotlight marker after hooks (e8af1f1)
- test(web): use verifier-compatible authority fixture (7845cc7)
- test(hosted): refresh crypto concurrency fixtures (458e97c)
- test(hosted): update Junction user fixture (1be6c4c)
- fix(hosted): preserve local E2E shell execution (6822ef2)
- test(cloudflare): use scoped browser vault fixture key (f09af1f)
- docs: close food timeout plan (ffb76e7)
- fix: preserve Frog post-push handoff proof (8d78e2c)
- docs: unify metric rollback ownership (2a8cf03)
- fix(workouts): resolve completed action replays (00433e9)
- fix: preserve shared Spotlight exclude ownership (94d8e40)
- fix: make metric runner rollback floor durable (fe5dc25)
- fix: stabilize manual metric corrections (1ac36a7)
- test(cloudflare): scope Telegram rich tool expectation (50383cb)
- fix(assistant): honor image opt-outs during safety guidance (ded1719)
- docs(changelog): note default exercise images (132c44f)
- fix(assistant): include exercise images by default (f2f2615)
- fix: honor report order across timezone changes (58d254b)
- docs(review): record private integration pass (41f6278)
- test(web): restore onboarding crypto signer mock (7ecf12b)
- docs(review): record round 18 pass (dad0a41)
- fix(telegram): reject lossy rich tags (11f5fe6)
- fix: preserve causal order for metric corrections (9824ee2)
- fix(web): scope bounded food search (88bdebf)
- test(device-sync): prove recovery at workspace owner (2b110b7)
- fix(assistant): arbitrate current sender at dispatch (7c4adde)
- fix: retire departed browser vault loads (a2e0d54)
- fix(workouts): persist member action replay marker (59fb03f)
- fix(telegram): preserve literal rich fallback text (83264bf)
- fix: close Frog publication authority races (6b3d824)
- fix: restore shared Spotlight precedence (d94827f)
- test(assistant): restore notification input type (d75adcf)
- fix(assistant): confirm queued reminder delivery (363bb3e)
- fix: preserve browser vault recovery states (7c89af4)
- fix(assistant): bound reminder silence evidence (e3b78e8)
- Fix hosted provider canary browser recovery (#1791) (ce96967)
- refactor(contracts): simplify Telegram rich parser (81a5e8f)
- fix: preserve native worktree materialization (0488f9a)
- fix(assistant): claim one current sender decision (c0b9cec)
- fix(workouts): authorize deterministic set removal (3b3ee55)
- Update ReviewGPT to 0.5.125 (#1807) (7856e5a)
- fix(assistant): scope reminder evidence to session (5e9eb71)
- fix: publish worktree authority on completion (d2537ac)
- Fix required browser vault demand recovery (21aa87f)
- docs(review): record trusted round 15 evidence (9325e4b)
- Align contact key rotation fixtures (857fc46)
- fix(hosted): require notice-capable group protocol (4ab8266)
- fix(device-sync): honor fresh source lifecycle (c36c0d4)
- fix(assistant): expire cold history marker (ab68db9)
- Buffer device webhook bursts through encrypted queues (#1766) (157c9a5)
- Fix biomarker vault test capabilities (b0fa4c0)
- fix(web): preserve ranked food search bounds (58cf6be)
- fix: replay committed metric reports (eb47e06)
- test: accept native SIGINT reporting (b07d887)
- fix: finish worktree setup cleanup (8734084)
- Reratch runner bundle after main reconciliation (e276e42)
- test(device-sync): prove closed-loop quiescence (f8f89d1)
- Keep browser replica build off runner startup (f1ec1b9)
- fix: preserve late snapshot wake control (469104f)
- fix(assistant): mark bounded conversation history (8fc985a)
- Remove AgentMail integration (#1751) (8528005)
- fix(hosted): keep current sender terminal outcome sticky (80d2af6)
- fix(assistant): reuse active set prescriptions (#1795) (d030da1)
- Fix Cloudflare workspace lockfile (0cd9ede)
- test: pin Frog review fixture package manager (0f1441c)
- fix: keep browser vault query buildable (09f6383)
- fix(workouts): harden set removal replay (6e59e5b)
- fix(device-sync): separate hosted source state (d57ca41)
- fix: keep foreground wake ahead of snapshot telemetry (9c65420)
- fix(tooling): unify worktree setup lifecycle (985b351)
- test: add browser vault loading design proof (99bb891)
- Harden Frog review authority and recovery (e31081d)
- fix(assistant): reconcile group wearable values (b549455)
- fix(snapshot): resume foreground after completion failure (9056b72)
- docs: record food timeout verification (5c73666)
- docs(web): note reliable food lookups (03fc554)
- fix(web): bound product label search work (b21ed73)
- fix(assistant): resolve repeated sets from canonical plans (#1790) (5590921)
- Page pooled database connection errors to operator phones (#1764) (07fd237)
- fix(tooling): preserve native worktree failure semantics (4a689d2)
- fix: recover ambiguous device cleanup (dc654ea)
- fix(assistant): preserve recurring reminder context (df9cbfd)
- docs: add faster dashboard changelog (571044b)
- fix(snapshot): retain failures across late wakes (15f17db)
- perf: reduce authenticated browser vault startup cost (7d38d0e)
- fix: harden reported metric handoff (64dce92)
- Make homepage vault preparation payload-free (#1793) (965e454)
- Constrain hosted device-sync cadence publication (#1799) (0468218)
- fix(assistant): order current sender clarification transitions (1de8980)
- fix(device-sync): prefer established hosted source (d596df2)
- refactor(hosted): separate current sender result destination (48662ed)
- fix(snapshot): preserve first failure provenance (03a1b7c)
- test(tooling): cover worktree materialization failure (a07e3d2)
- merge(snapshot): preserve stacked retry behavior (a4e7114)
- Require minimal-fix complexity dispositions from ReviewGPT (#1792) (fc95478)
- fix(device-sync): unify Junction source identity (9dfa8d3)
- test(snapshot): cover monitoring boundaries (5d49fe7)
- fix(tooling): exclude worktrees before checkout (abefbcf)
- feat(runtime): diagnose slow snapshot starts (fde4f34)
- fix(cloudflare): keep R2 cause handling local (baea3d2)
- docs(changelog): announce manual daily metric corrections (6525d30)
- Add durable member-reported daily metrics (8fe2180)
- fix(cloudflare): harden direct R2 retry classification (1faa3cc)
- Prepare direct Linq routing before database transactions (#1724) (8e02e66)
- fix(assistant): preserve safety-critical reminders (216474a)
- fix(cloudflare): stabilize replayed snapshot identity (84b6605)
- fix: preserve exact current-sender ordering (4909763)
- test(cloudflare): prove orphan scheduling after ownership loss (731d1fc)
- Clarify Frog review correction scope (f3a2842)
- Include Frog skill in review evidence (d7bdbec)
- test(cloudflare): prove bounded snapshot completion replay (eb37696)
- docs(junction): define scalar cursor rollout (14c52c0)
- Teach Murph connected insulin and basal calories (#1777) (4b69ac4)
- fix(junction): read deployed scalar precursor (0d75699)
- fix(cloudflare): preserve presign HTTP failures (10f8076)
- fix(device-sync): preserve account source identity (b5a3e06)
- fix(cloudflare): retry direct snapshot R2 uploads (51f7c84)
- Record Frog activation retrospective (c515ea1)
- fix(cloudflare): ratchet group share runner budget (#1784) (aabb83e)
- fix(cloudflare): replay ambiguous snapshot completion (bcbf58d)
- fix(cloudflare): ratchet runner bundle budget (36c20a9)
- fix(cloudflare): bound snapshot orphan alarm scheduling (c6035ca)
- Activate local Frog autofix (745591d)
- fix(cloudflare): retry snapshot presign transport failures (b73f850)
- Fix hosted browser canary navigation (#1778) (3820f5b)
- refactor(junction): remove duplicate timeseries progress (2abcd16)
- Preserve every source in group health shares (#1765) (67d4a3c)
- Fix current-sender clarification delivery (09bb51f)
- chore: sync friction log (#1640) (0668f2c)
- Restore scheduled device-sync wakes (#1776) (b967976)
- Restore lighter homepage topic labels (#1774) (0c8ccd7)
- feat(workouts): support deterministic set removal (8786581)
- Bound account deletion database critical sections (91d4a6b)
- fix(device-sync): unify calendar source aliases (5bd5c29)
- fix hosted-local KMS canary fixtures (#1773) (a6ac654)
- Fix cold-restored dirty job acknowledgements (#1771) (56e19cd)
- docs(changelog): note quieter recurring reminders (7f1b972)
- fix(assistant): quiet unanswered recurring reminders (b9faa59)
- Fix clarification response parsing (222c7f7)
- fix(device-sync): preserve calendar source aliases (d6523d2)
- fix(device-sync): reject lossy calendar responses (c674598)
- Restore scalar Junction continuation progress (c5b4fa1)
- Revert "refactor(junction): keep scalar continuation progress" (63e391b)
- fix: preserve unsupported workout results (f7dbb0a)
- Adopt official provider SDK clients (#1762) (1826c3c)
- refactor(junction): keep scalar continuation progress (9e7108b)
- docs(friction): record visual review packaging gaps (1d87cde)
- fix(device-sync): reject partial calendar repairs (ff453d6)
- fix(device-sync): bound deployment-safe Junction progress (d2e352d)
- fix(junction): restore bounded scalar continuations (0c7b365)
- fix(junction): align continuation CI contracts (e8ffae2)
- test(device-sync): align continuation coverage (d05aa31)
- Import Strong and Hevy workout CSV exports (#1734) (2e4ff9d)
- Fix hosted device-sync wake ownership (#1736) (e71d8de)
- fix(device-sync): complete Junction timeseries continuations (9150a7d)
- fix: keep hidden workout notes out of cards (cb41c4a)
- Fix natural group answer audience routing (2e1a87b)
- fix(device-sync): preserve calendar repairs across reconnect (d846f58)
- fix: recover automation timing verification (#1763) (e4fb6ce)
- fix: hydrate exact workout editor snapshots (819a49d)
- Send companion signup first outreach (#1761) (284e478)
- fix: preserve partial workout set preconditions (6e2a69e)
- fix: preserve unrelated workout set fields (3ba0b47)
- fix: keep member action crypto outside transactions (c11c9db)
- fix: require unique member action targets (87e4988)
- fix(device-sync): bound Junction timeseries continuations (22d73d0)
- docs(plan): complete Telegram rich content work (a07df8c)
- test: freeze member action completion contracts (b40974e)
- docs(plan): record rich fallback review decision (3cb0dd2)
- fix: bound deterministic member action completion (c2572fb)
- fix(device-sync): retain Junction calendar repairs (37d3447)
- fix(telegram): preserve safe fallback entities (746350b)
- Complete bounded Junction timeseries continuations (b7991f4)
- Enable every canonical Junction timeseries by default (00bb111)
- Bound Junction timeseries collection units (7076605)
- fix(telegram): disable automatic rich entities (df80063)
- Give reminder gate unique automation identities (3849cee)
- feat: confirm deterministic member actions (c572940)
- Improve assistant awareness of connected health data (d6f09c0)
- docs(plan): complete audit package trim (9caeec5)
- fix(review): preserve rename-out audit context (d8b8257)
- fix(device-sync): persist Junction calendar refreshes (d666150)
- fix(web): reject unconsumed private directives (c00df25)
- chore(review): trim audit package context (966b207)
- Extend scheduled reminder gate timeout (4ee010e)
- Clarify connected health release guidance (a375916)
- fix(web): reject subject-led private clauses (be74273)
- Improve assistant awareness of connected health data (bca7395)
- fix(device-sync): refresh displaced Junction days (ad501e8)
- Strengthen scheduled reminder timing proof (92dcac9)
- test(contracts): preserve Junction default expectations (af8e5e0)
- Cover reminder fixture alignment guard (1a8b16c)
- Update scheduled reminder deploy gate (62e0989)
- fix(assistant): preserve concurrent current-sender asks (12634c5)
- test(importers): preserve Junction opt-in expectations (42a47da)
- Explain physical-note printer rejections (#1671) (bcc7732)
- Fix group health-share refresh after wearable sync (#1726) (87cb2eb)
- fix(importers): bind sparse revisions to provider day (73b23bf)
- fix(device-sync): route sparse corrections by provider day (3bb9553)
- Record merged PostgreSQL verification (9213a81)
- Update PostgreSQL crypto test fixture (a132687)
- fix(reminders): validate invalid DST retries (e59eb27)
- Record merged S review baseline (d0b24a3)
- fix(device-sync): checkpoint timeseries resources (9a5c2bf)
- Add Stripe effect compatibility cutover (80e8555)
- fix(device-sync): bound Junction timeseries progress (ddf3b24)
- fix(reminders): honor DST recovery withdrawal (a5dbfb3)
- fix(assistant): preserve semantic card ownership (b3e1181)
- test: freeze member action mailbox kind (d42621f)
- Fix pending group health sharing (#1688) (db66c6f)
- fix(device-sync): bound Junction correction cadence (62dfddb)
- refactor: keep member actions outside assistant prompts (4efbf2f)
- docs: announce direct Messages workout entry (e8e168f)
- test(assistant): prove edge delivery admission (505b418)
- feat: add deterministic member actions (a84623a)
- docs(changelog): note flexible Telegram layouts (29b9eae)
- feat(assistant): add Telegram rich content cards (0f74a52)
- fix(assistant): reject unknown edge delivery clauses (1b15c26)
- fix(assistant): honor leading private clauses (d760987)
- Make Junction history frequency-aware (#1693) (69edc83)
- Preserve private Assistant Ask continuity (#1683) (49d870c)
- test(web): isolate query-shape migration fixture (5c09332)
- docs(plan): close query-shaped database reads (b7a30f9)
- Prepare mailbox and identity crypto before transactions (#1737) (023ec1b)
- Bound hosted runtime latency monitor query (#1735) (66b927c)
- fix(reminders): correlate renamed DST retries (886a4aa)
- fix(assistant): keep current-sender terminals importable (38f2dff)
- docs: keep handoff proof scoped to plan (26383ef)
- test(web): prove bounded replay and handoff limits (3f3ba3e)
- chore(ci): ratchet Junction runner bundle budget (5bce9cf)
- Bound image-heavy Linq responses and retain rejection diagnostics (#1731) (b13281d)
- fix(reminders): preserve DST recovery across conflict (1147c25)
- fix(assistant): replay expired current-sender completions (fa30174)
- test(web): align query-shape release fixtures (e44c599)
- docs: close Linq delivery query plan (7b5de67)
- docs(plan): track query-shape completion (a99bac2)
- Complete provider-owned Composio API client (07d5837)
- fix(device-sync): retain workout progress through day (9515e4f)
- fix(reminders): compose DST recovery obligations (9e78c05)
- test(web): bind Linq plan proof to production SQL (bbc6f5f)
- test: prove bodyless Composio revoke (145eddd)
- fix(importers): preserve Junction temporal precision (2ba3a59)
- test(web): update hosted migration inventory proof (66156d0)
- fix(assistant): preserve private fallback convergence (28fee9b)
- Use provider-owned Composio API types (6632e32)
- fix(reminders): retain pre-rename recovery alias (6f043b3)
- fix(device-sync): bind workout retry progress to day (debf32a)
- fix(web): prevent handoff recovery starvation (cb96351)
- docs(device-sync): clarify Junction collection limits (be56677)
- refactor: unify device runtime secret preparation (7a004ae)
- fix(reminders): canonicalize DST recovery targets (36eeb85)
- Update ops usage design catalog label (50f1cad)
- docs: close database monitor retry plan (d8524a0)
- Complete hot collection read bounds (a7a7e3c)
- Enable Junction timeseries resources by default (414b290)
- test(cloudflare): cover counter confirmation boundaries (8008ecb)
- perf(web): bound signup failure liveness reads (9d099c1)
- fix(cloudflare): confirm missing database counters (b55a487)
- test(web): preserve WHOOP mock query shape (4386d60)
- docs(plan): close Telegram routine card repair (de68de1)
- fix(assistant): scope Telegram routine repair guidance (5929c7a)
- docs(changelog): note routine card resends (24a3905)
- fix(assistant): preserve Telegram routine cards on resend (b62b39b)
- fix(device-sync): preserve workout stream retry backoff (790f8c4)
- fix(assistant): bind current sender requests before personal read (3203a0e)
- fix(device-sync): reconcile Junction compact sets (9b84e5b)
- fix(device-sync): bound workout stream continuation retries (acb2bf3)
- fix(device-sync): keep sparse backfill activation authoritative (7857801)
- fix(junction): keep reconnect reset web-owned (a3c6f59)
- fix(junction): reopen weight history on reconnect (ee58cc4)
- fix(junction): preserve compact stream ownership (f1b2e0f)
- fix(web): warn when account disconnect affects Dexcom (12d1de5)
- docs: close channel-native plan presentation (253d28f)
- fix(junction): keep interval features on start day (f09436e)
- style: format routine presentation e2e (6791e23)
- test: complete routine catalog e2e fixture (43105ba)
- test: cover channel-native routine journeys (6930c39)
- fix(device-sync): explain unavailable Dexcom recovery (e9ed066)
- fix(junction): preserve floating days before import (d506a2d)
- refactor(device-sync): keep Dexcom recovery unavailable (4633792)
- docs: link channel-native plan changelog (4d65ae0)
- fix: require channel-native plan presentation (cf9a11d)
- test(web): cover multi-group patterns mobile layout (5f566fb)
- fix(junction): bound dense resource persistence (ff22383)
- test(junction): cover duration unit conversions (347517d)
- fix(device-sync): share recovery state policy (fe3dfe9)
- fix(junction): preserve midnight intervals (0ba5a4c)
- docs(plan): close Composio identity repair (f5fff56)
- test(connected-apps): cover scheduled write authority (7c8cabe)
- fix(junction): validate sync watermark horizon (9290267)
- fix(junction): reuse established importer entrypoint (a691c40)
- fix(device-sync): unify Dexcom recovery authority (2976fea)
- fix(junction): preserve resumed history obligations (f0cef67)
- fix(junction): derive closed-day webhook routing (25b2d64)
- feat(junction): add bounded dense resource features (4f06f61)
- Set-bound terminal account deletion (132a3ce)
- Recover legacy trial activation replay (99f5526)
- fix(reminders): settle DST clarification lifecycle (e7d78d4)
- Preserve ops usage boundary members (8d01afc)
- fix(web): preserve existing Dexcom recovery (c564b30)
- feat(junction): model activity health resources (23fe3e0)
- close scheduled wearable wake compatibility (2928014)
- test(web): cover Outlook calendar member binding (b53d4f6)
- docs(changelog): note restored connected app actions (6f33016)
- fix(web): bind Composio writes to member identity (b6ede04)
- fix(junction): preserve full-sync watermark (0f96455)
- Separate Junction interval and daily ownership (c42b825)
- fix(cloudflare): retry transient database telemetry collection (#1715) (0a11d66)
- Bound checkpoint latency collection writes (9feb6a8)
- align wearable recovery changelog proof (9c75c4e)
- record wearable recovery compatibility (41ac682)
- fix scheduled wearable wake compatibility (662dd85)
- test(review-gpt): make browser default proof hermetic (10b56dd)
- Bound operator usage dashboard reads (115b7ef)
- fix(web): keep deletion controls independent (06cf9fc)
- Expose Dexcom availability in design catalog (b75a3de)
- Correct query-shape replay and capacity races (25c694e)
- Prepare account deletion targets before terminal locks (5468f11)
- Document modern Dexcom availability (7cfdf43)
- Mark modern Dexcom connection as coming soon (55b2bbf)
- fix(review-gpt): isolate the default browser lane (2ae0b37)
- fix(junction): preserve bounded opt-in boundary (d7e893c)
- docs: close device snapshot status bounds plan (ac772e6)
- Index-bound Family owner seat admission (6c91620)
- fix: preserve foreground priority during device apply (ca9a3cc)
- fix(reminders): retain DST clarification date (3b35c04)
- fix(junction): preserve floating daily buckets (980e931)
- Set-write checkpoint publication latency milestones (14fb07c)
- docs(changelog): note deletion web handoff (7a2d240)
- fix(assistant): make current-sender audience reviewer-owned (fb96571)
- feat(web): clarify account deletion handoff (c1c80d8)
- Store Junction tags neutrally (#1697) (b59adeb)
- fix(junction): complete sparse activation journey (f6ac790)
- fix(junction): stabilize sparse provider row identity (b06ade4)
- feat(junction): model sparse health resources (f4c6068)
- Scope Junction revision reconciliation (c267861)
- Preserve activity and sleep summary detail (#1704) (1451b6f)
- Persist exact Stripe activation replay pointers (9bb154b)
- Narrow referral and handoff recovery reads (215b07e)
- Bound WHOOP capacity graph reads (e394891)
- Index bounded group and message-volume reads (95d5422)
- Bound Family owner invite history reads (afbc8b7)
- Converge Junction fidelity ownership (f2d1113)
- Preserve Junction body composition facts (#1695) (41931c9)
- Preserve Junction menstrual and profile facts (#1694) (cc66e5e)
- fix(junction): align aggregate completeness boundaries (1c21a0f)
- Repair hosted conversation progress handling (#1664) (8f7080a)
- Record exact-head device status proof (b99c1c2)
- Collapse device status snapshot fanout (682e0d8)
- Document device apply body-limit retrospective (bc9084e)
- Harden Junction fidelity reconciliation (3148b12)
- Match iMessage fallback cards to native layouts (#1650) (9d89dfd)
- Fix Environment Browser Vault convergence (#1676) (05988dd)
- test(hosted): add authenticated Playwright smoke (#1595) (e8cd079)
- test(cloudflare): repair scheduled card fixture (#1709) (56caa36)
- fix(junction): preserve bounded resource semantics (7929001)
- Fix Junction fidelity reconciliation gaps (0eaa684)
- feat(junction): model sparse health resources (821d33a)
- fix(assistant): preserve relative reminder date (7953593)
- Split device apply callbacks by body size (e9b5c75)
- Preserve bounded Junction timeseries fidelity (871b4c6)
- fix(junction): stabilize weight replay and history (2d5c06a)
- docs(changelog): note group audience routing (b7a58b1)
- refactor(assistant): unify current-sender requests (dc6542d)
- fix(junction): add bounded resource opt-ins (666a7b6)
- Fix pending-group prep retention (1774dc8)
- ci: emit pull-request synchronize (4c52129)
- ci: trigger exact-head checks (b086d08)
- test(cloudflare): execute permission CLI shim (f518f11)
- fix(hosted): allow runner CLI reads (1af68d3)
- test(cloudflare): expose permission read failures (0131218)
- test(cloudflare): target automation read smoke (e9b6716)
- fix(reminders): anchor hosted timing and writes (9e7b987)
- test(assistant): split restricted shell proof on CI (56c3acb)
- chore: complete group email graph bounds (541f118)
- chore(agent): complete Starter KMS prewarm plan (23c60b5)
- feat(assistant): send cards after meal and workout updates (e8c32e7)
- test(assistant): keep permission shell proof portable (42c782c)
- fix(hosted): preserve group email eligibility limit (bde164c)
- docs(changelog): note clearer personal patterns (6bcfef3)
- feat(web): add pattern illustrations and compact mobile table (9ea202d)
- fix(web): release consumed pending group pin (c71c1c4)
- fix(assistant): preserve restricted vault execution (a82e84a)
- test(web): prove Starter crypto retry rollback (21b8c93)
- docs(plan): close Linq diagnostic compaction index (ab8781f)
- fix(hosted): reject malformed group email grants (143b5a0)
- docs: close legacy trial checkout cleanup plan (9867991)
- fix(web): prewarm Starter roots before enrollment commit (c17eba3)
- fix(assistant): default eligible response cards (08080b9)
- fix(hosted): bound group email graph reads (72c8d9f)
- fix(assistant): preserve restricted maintenance shell access (411f78c)
- Merge origin/main into codex/linq-canonical-send-route (8679d24)
- test(assistant): tighten automation guidance proof (e68c8fb)
- test(web): prove legacy subscription checkout rejection (b3446e2)
- test(cloudflare): gate routine card advertisement by channel (#1684) (b367263)
- fix(web): bind manual family abandonment claim (35a3fe3)
- docs(plan): normalize Linq index task (b6ad6a6)
- perf(web): index Linq diagnostic compaction (aa9c34f)
- fix(assistant): clarify automation and voice inputs (406a760)
- fix(assistant): restrict one-shot codex threads (c18c57a)
- fix(assistant): bound source detail to GPT-5.6 (bacf0e9)
- feat: render response cards as Telegram rich messages (#1657) (00930ae)
- docs(plan): normalize Linq index task (411c164)
- perf(web): index Linq diagnostic compaction (aba5284)
- test: cover device snapshot status export (1b41ed5)
- refactor(web): remove legacy trial checkout cleanup (e8b5f94)
- Sync Oura tags into Personal Patterns (#1673) (c8cb63e)
- Fix Personal Patterns for normalized wearable data (#1668) (01faae3)
- docs: record pending-group merge verification (6e2b588)
- docs: record current-main device snapshot integration (445afb1)
- fix: expose device snapshot status test seam (6e5b043)
- test(assistant): align support authority fixtures (02c54f3)
- docs: close wearable timing telemetry plan (8b583c1)
- Assert one-candidate feedback guard (0f49def)
- Preserve one-candidate feedback semantics (da69660)
- Test proactive product frustration guidance (2cd03b0)
- Make Murph log explicit product frustration proactively (f69e09e)
- fix(web): bind family recovery to checkout claim (480be87)
- docs(plan): close group-share freshness work (57a28ac)
- test(assistant): derive schedule fixtures from production (66c28e2)
- docs(changelog): cite OpenAI model expansion (a3b4ba9)
- fix(assistant): require exact refs for sender actions (a4b7677)
- fix(assistant): preserve source detail across OpenAI models (e40694e)
- fix(web): preserve changelog summary boundaries (f65ca62)
- fix(web): simplify Terra changelog wording (c8a0a1d)
- fix(device-sync): isolate timing source attribution (1eb14d0)
- fix(web): clarify Terra image detail scope (54842fa)
- fix: widen shared-card handoff dialog (4a6627e)
- Fix invalid pending setup recovery fallback (589856e)
- Attribute wearable timing telemetry by source (d4c7c4d)
- fix: simplify device apply authority (9ef5f44)
- fix: strengthen shared-card dialog hierarchy (0449795)
- test(hosted): match landed frontier proof (64a6dff)
- test(hosted): compose mailbox frontier proof (7358845)
- fix: soften shared-card cancel action (43349a1)
- fix: stack shared-card handoff actions (c861975)
- test: prove device apply load bounds (ae71406)
- fix(runtime): scope mailbox completeness to projection (718049e)
- fix(web): preserve completed family checkout recovery (cca9041)
- Update live-steer timing assertion (eff517e)
- docs: record device apply verification (c6da952)
- fix: preserve unscoped companion source authority (0ad8abb)
- fix: bound device runtime apply fanout (81d7a0f)
- Fix delayed relative reminder resolution (216e8eb)
- fix(web): replay the exact family checkout claim (2c5931e)
- Fix retained vault export during Oura processing (#1655) (2642475)
- docs: record pending-group review retrospective (3ed7582)
- test(hosted): wait on group route container (575aaf3)
- test(reminders): expect read-only inspect guidance (d1c98de)
- fix(web): keep family invites out of Stripe checkout (47b3f11)
- fix: separate runtime source authority bound (dc444c2)
- fix(reminders): make hosted timing inspection authoritative (ea2d405)
- refactor(crypto): centralize root signature validation (3055a06)
- fix(web): keep pending setup roots retryable on missing verify keys (71a2c0d)
- test(runtime): fail closed on missing mailbox frontier (2f2fdda)
- docs(plan): complete PR 1420 merge readiness (a7ff335)
- fix(reminders): resolve relative days in the named timezone (4e0a397)
- fix(runtime): prove mailbox prefix completeness (85444e3)
- Archive completed Linq message edit batching plan (33e2674)
- test(web): remove stale billing browser helper (f6f988d)
- fix(web): preserve invite recovery billing intent (eb30693)
- test(runtime): bind wearable replay receipt to trigger (3bf3124)
- fix(reminders): resolve one-shot schedules in the user timezone (333cda2)
- fix(runtime): rehydrate trusted image completions (943761f)
- fix: preserve paged device status guidance (7518388)
- fix(web): make family invite recovery actionable (300963d)
- fix(web): preserve family invite through checkout cancellation (4b24d4a)
- fix(web): freeze supporter publication at settlement (e4aeb06)
- fix(runtime): harden consented share refresh scheduling (3a4604d)
- test(device-sync): trust durable mailbox settlement (92b360b)
- fix(runtime): isolate group email terminal settlement (1416a68)
- Harden Linq edit preparation contention (dc974e4)
- fix(web): preserve supporter consent across rollback (5314298)
- docs: complete Codex runtime hard-cut plan (3efe9ab)
- docs: archive browser assertion nonce plan (f6e9fd8)
- test: cover custom inference reasoning capability (32b6239)
- fix(web): preserve family invite through sign-in (90c4c09)
- fix(hosted): interrupt initial system mailbox fetch (1d39ae6)
- chore(plan): close causal audience recovery (49a812c)
- Bound Linq roster database work with fixed set reads and one reconciliation statement, including live authority revalidation and cap-32 PostgreSQL proof. (87e2637)
- Finalize Retell transfers after the human leg ends (#1363) (6091261)
- fix: close bounded snapshot audit gaps (89c6241)
- docs: record runtime hard-cut verification (045858c)
- fix(web): remove unneeded nonce rollout migration (e24d8d1)
- fix(runtime): preserve causal notification usage