Skip to content

v0.1.1

Latest

Choose a tag to compare

@fmind fmind released this 29 Jul 09:23
1f7c933

[0.1.1] - 2026-07-29

🚀 Features

  • (mise) Add cluster:overrides task + document gate sequencing for agents
  • (bridge) Add durable delegation recovery (#395)
  • (federation) Add constrained laptop profile (#399)
  • (postgres) Add permission-aware knowledge store (#413)
  • (infra) Add vetted MCP catalog (#415)
  • (bridge) Add actionable failure notices (#417)
  • (bridge) Add in-room agent gallery (#422)
  • (models) Add governed model catalog (#420)
  • (bridge) Add plaintext command fallback (#428)
  • (bridge) Add guided room welcome (#432)
  • (infra) Scaffold governed agents (#433)
  • (bridge) Stage model classification signal (#435)
  • (matrix) Add finite retention policy pack (#441)
  • (bridge) Record reply quality reactions (#440)
  • (matrix) Define snapshot-backed media storage (#437)
  • (matrix) Add opt-in Ketesa admin console (#444)
  • (agents) Audit version in effect (#438)
  • (agentgateway) Enforce MCP tool quotas (#445)
  • (bridge) Add delayed task dead-man switch (#443)
  • (knowledge) Add sovereign ingestion pipeline (#486)
  • (federation) Sign cross-org usage receipts (#446)
  • (knowledge) Add incremental Git/Markdown connector (#492)
  • (federation) Add partner onboarding conformance preflight (#351) (#539)
  • (models) Add sovereign embeddings + reranker runtime (#540)
  • (bridge) Scan agent replies for leaked secrets before room post (#541)
  • (eval) Add sovereign LLM-as-judge scoring lane (#547)
  • (bridge) Persist interactive task controls (#577)
  • (activitypub) Negotiate outbound signature profiles (#610)
  • (bridge) Govern conversation memory (#723)
  • (observability) Add opt-in synthetic delegation canary (#912)
  • (observability) Opt-in sovereign alert delivery to Matrix (#456) (#914)
  • (federation) Partner trust registry — single validated source of truth (#349) (#915)
  • (federation) Cross-org break-glass containment + evidence pack + abuse intake (#350) (#916)
  • (federation) Signed bilateral agreement as the enforcement source (#353) (#917)
  • (federation) Time-bounded partner trust — review windows + expiry gate + alert (#463) (#918)
  • (bridge) Multi-JWK AgentCard verification for zero-downtime key rotation (part of #352) (#920)
  • (agents) Mise run agent:test — offline single-agent golden pre-PR loop (#372) (#921)
  • (identity) Wire Keycloak→MAS OIDC backchannel logout (#278) (#922)
  • (audit) Content-bounded Synapse/MAS audit projectors + closed schemas (Part of #418) (#930)
  • (audit) Closed fgentic.admin_action.v1 record schema + contract (Part of #455) (#931)
  • (audit) Cursor + dedup reconciliation for the audit collector (Part of #418) (#932)
  • (audit) Read-only collector roles with column-level grants (Part of #418) (#933)
  • (audit) Pinned source queries + collector orchestration (Part of #418) (#934)
  • (audit) Crash-safe collector cycle orchestration (Part of #418) (#935)
  • (bridge) Verify AgentCard overlap set + revocation in sign-agent-card tool (#939)
  • (audit) Content-bounded admin-action projector + collector offline core (Part of #455) (#940)
  • (federation) Model AgentCard key-rotation overlap + revocation in the trust registry (part of #352) (#941)
  • (federation) Serve + prove AgentCard key-rotation overlap window in the fed lab (part of #352) (#942)
  • (activitypub) Reconcile AP gateway on demo profile (offline infra; runtime interop proof pending) (#938)
  • (bridge) Per-room token budgets with in-room feedback (#947)
  • (group-sync) GitOps IdP-group to managed Matrix room reconciler (offline core) (#948)
  • (scripts) Ownership-guarded agent-retire cleanup script (Part of #453) (#951)
  • (identity) Break-glass administration offline core (Part of #467) (#952)
  • (release) Adopter BOM + drift-verify gate, upgrade-notes convention, support statement (Part of #188) (#953)
  • (airgap) BOM-driven artifact mirror + fully-qualified image refs + disconnected-install docs (Part of #457) (#954)
  • (federation) Route pinned fediverse handles (#960)
  • (bridge) Versioned ai.fgentic.a2a result metadata on terminal agent notices + joint-ops blueprint (Part of #167) (#965)
  • (bridge) Bind agents to exact managed rooms (#693)
  • (agentgateway) Classification-aware model residency enforcement, fail-closed (Part of #339) (#982)
  • (evaluation) Citation-faithfulness check over the sovereign judge lane, fail-closed (Part of #358) (#992)
  • (moderation) Opt-in Draupnir policy-list moderation component + docs (Part of #136) (#996)
  • (knowledge) Add typed retrieval identity carrier (#1538)
  • (knowledge) Add permission-aware retrieval service (#1545)
  • (knowledge) Add retrieval identity projector (#1549)
  • (knowledge) Add retrieval gateway boundary (#1550)
  • (knowledge) Enforce retrieval delivery boundary (#1551)
  • (identity) Add offboarding reconciler (#1552)
  • (bridge) Gate consequential tools with room approval (#1553)

🐛 Bug Fixes

  • (demo) Fit constrained laptop resources (#330)
  • (k3d) Stop failed network policy reconciliation (#388)
  • (ci) Serialize app toolchain installs (#394)
  • (gke) Grant agentgateway Vertex access (#402)
  • (a2a) Bind local clients to configured routes (#410)
  • (docs) Remove stale roadmap ceiling (#421)
  • (bridge) Avoid locking remote round trips (#424)
  • (infra) Recover interrupted cluster teardown (#423)
  • (tasks) Make check:terraform hermetic against a poisoned backend cache (#545)
  • (models) Bind rollouts to snapshot pins (#555)
  • (observability) Scrape sovereign model runtimes (#557)
  • (identity) Fail-close Keycloak namespace (#564)
  • (security) Fail-close admin namespace (#567)
  • (observability) Scrape Keycloak metrics (#569)
  • (observability) Order Keycloak after monitor CRDs (#572)
  • (gateway) Restrict route namespace delegation (#574)
  • (observability) Order OTel after monitor CRDs (#576)
  • (observability) Order gateway after tracing backend (#582)
  • (models) Restrict model scrape peers (#590)
  • (kagent) Remove unused monitoring access (#593)
  • (agentgateway) Bind metrics scrape peer (#597)
  • (kagent) Restrict managed-agent egress peers (#600)
  • (observability) Restrict OTLP producer peers (#602)
  • (flux) Scope observability DAG edges by profile (#609)
  • (observability) Restrict Grafana ingress (#619)
  • (observability) Isolate metrics control APIs (#623)
  • (activitypub) Block private federation fetches (#620)
  • (observability) Restrict kube-state-metrics ingress (#626)
  • (postgres) Restrict CNPG instance ingress (#630)
  • (cert-manager) Isolate controller metrics ingress (#633)
  • (gateway) Isolate Traefik internal ingress (#636)
  • (cnpg) Isolate operator metrics ingress (#639)
  • (scripts) Fail closed on validation producers (#642)
  • (activitypub) Require fresh bound inbound signatures (#645)
  • (cert-manager) Isolate webhook metrics (#644)
  • (scripts) Fail closed on Trivy cleanup inventory (#646)
  • (scripts) Validate check producer status (#650)
  • (scripts) Validate federation producer status (#652)
  • (scripts) Validate federation helper producers (#656)
  • (scripts) Validate demo secret producers (#658)
  • (flux) Bind metrics ingress to Prometheus (#657)
  • (scripts) Validate demo federation producers (#660)
  • (kagent) Bind ingress to exact callers (#661)
  • (scripts) Validate demo cluster producers (#665)
  • (terraform) Validate authorized IPv4 CIDRs (#667)
  • (terraform) Compose admin console DNS (#670)
  • (terraform) Validate GKE location (#672)
  • (terraform) Scope Cloud DNS API (#676)
  • (terraform) Order Cloud DNS setup (#679)
  • (terraform) Grant GKE node role (#682)
  • (terraform) Enforce backup retention horizon (#685)
  • (terraform) Pin state recovery window (#688)
  • (terraform) Enable managed-zone DNSSEC (#691)
  • (terraform) Protect managed DNS zone (#695)
  • (terraform) Enable bounded VPC flow logs (#698)
  • (terraform) Validate GKE node count (#701)
  • (terraform) Bound GKE authorized network ranges (#704)
  • (docs) Reject navigation drift (#707)
  • (terraform) Keep GKE workload logs local (#708)
  • (terraform) Bound GKE authorized network list (#710)
  • (terraform) Label GKE reference cluster (#713)
  • (terraform) Validate GKE cluster names (#715)
  • (terraform) Validate composed VPC names (#719)
  • (terraform) Block service external IPs (#722)
  • (ci) Include root integration contract (#726)
  • (terraform) Keep workload metrics sovereign (#727)
  • (terraform) Disable legacy GKE auth (#731)
  • (terraform) Validate GCP project IDs (#734)
  • (terraform) Validate bootstrap project IDs (#738)
  • (terraform) Validate Cloud DNS zone names (#741)
  • (terraform) Scope Cloud NAT egress (#744)
  • (terraform) Protect backup bucket from destroy (#748)
  • (flux) Protect CNPG cluster from prune (#752)
  • (observability) Alert on unhealthy CNPG backups (#758)
  • (observability) Alert on platform certificate health (#762)
  • (observability) Monitor Flux reconciliation (#766)
  • (observability) Alert on CNPG degradation (#770)
  • (observability) Alert on sustained gateway 5xx (#774)
  • (ci) Isolate workflow shell contexts (#778)
  • (observability) Alert on sustained vLLM queueing (#779)
  • (terraform) Validate GCS bucket names (#783)
  • (terraform) Validate platform domain (#786)
  • (terraform) Validate GCP locations (#790)
  • (terraform) Protect recent backups (#797)
  • (observability) Scope Flux error alert (#801)
  • (terraform) Validate GKE machine type input (#804)
  • (models) Bound demo request bodies (#809)
  • (models) Bound demo body read time (#812)
  • (models) Bound demo JSON parser errors (#815)
  • (models) Enforce strict demo JSON (#818)
  • (models) Narrow loader download egress (#822)
  • (models) Bound demo request concurrency (#826)
  • (ci) Prevent nested NetworkPolicy installs (#828)
  • (security) Deny all service external IPs (#830)
  • (docs) Update MkDocs Material to 9.7.7 (#846)
  • (docs) Reject stale uv locks before builds (#850)
  • (docs) Gate OKF directory-index completeness (#852)
  • (docs) Validate OKF frontmatter as strict YAML (#854)
  • (docs) Gate stable specification identifiers (#856)
  • (trivy) Bind metrics scrape peer to the Prometheus workload (#898)
  • (grafana) Scope sidecar RBAC to monitoring ConfigMaps (#897)
  • (security) Fail-close the enabled knowledge namespace (#902)
  • (postgres) Bind schema-job DNS egress to kube-dns (#903)
  • (ci) Preserve typed secret arguments in demo lifecycle (#906)
  • (ci) Make federation preflight fixtures scheduler-resilient (#907)
  • (ci) Serialize the two Terraform checks in the aggregate (#911)
  • (ci) Retry positive NetworkPolicy reachability probes (#913)
  • (agentgateway) Bound rate-limit temporary storage (#834)
  • (federation) Isolate break-glass mutation to a scratch tree to end the check:fed-registry race (#943)
  • (observability) Bound Matrix alert webhook intake (#957)
  • (observability) Bound delegation canary Matrix intake (#966)
  • (knowledge) Reject ambiguous embedding responses (#971)
  • (bridge) Upgrade gRPC-Go vulnerability (#979)
  • (knowledge) Bound connector acquisition responses (#976)
  • (release) Regenerate BOM after CD bridge image digest pin
  • (ci) Regenerate release/bom.yaml in the bridge CD digest pin (Fixes #984, #986) (#994)
  • (agentgateway) Correct missing-header residency behavior to match the real gateway (Part of #339) (#995)
  • (activitypub) Authenticate subscription undo (#999)
  • (knowledge) Keep connector rejections content-free (#997)
  • (observability) Stabilize alert socket tests (#1005)
  • (observability) Scope canary Synapse egress (#1011)
  • (bridge) Expose room token budgets in chart (#1009)
  • (security) Scope alert receiver network peers (#1016)
  • (observability) Target canary ESS Service endpoint (#1021)
  • (security) Disable service-link injection (#1040)
  • (infra) Bound raw deployment revision history (#1044)
  • (models) Bound loader ephemeral storage (#1051)
  • (knowledge) Hash shared connector ACL once (#1058)
  • (ci) Update zizmor to 1.28.0 (#1057)
  • (knowledge) Reject malformed Matrix ACL server names (#1060)
  • (ci) Exclude generated docs environment from Trivy (#1062)
  • (knowledge) Validate artifact path before download (#1064)
  • (knowledge) Validate status Unicode before download (#1071)
  • (knowledge) Contain malformed Unicode downstream (#1074)
  • (observability) Bound Matrix alert notices (#1079)
  • (observability) Normalize canary reply classification (#1082)
  • (observability) Validate canary deadline (#1086)
  • (observability) Validate alert listen port (#1090)
  • (observability) Distinguish unknown alert status (#1093)
  • (observability) Bound Matrix alert responses (#1096)
  • (observability) Enforce canary reply deadline (#1100)
  • (observability) Bound Matrix alert delivery time (#1106)
  • (observability) Alert when canary schedule telemetry disappears (#1112)
  • (ci) Classify nightly smoke failure tracker (#1115)
  • (knowledge) Reject invalid response framing whitespace (#1207)
  • (knowledge) Align acquisition chunked decoding (#1211)
  • (knowledge) Validate Ready condition generation (#1215)
  • (models) Serialize model-cache publication (#1227)
  • (knowledge) Enforce acquisition request deadlines (#1235)
  • (knowledge) Contain raced connector paths (#1243)
  • (audit) Couple source contracts to ESS pin (#1245)
  • (models) Order model cache publications (#1247)
  • (models) Reserve cache publication markers (#1253)
  • (models) Distrust symlink-backed cache markers (#1256)
  • (models) Repair malformed cache markers (#1260)
  • (models) Reject hard-linked cache locks (#1264)
  • (knowledge) Reject hard-linked acquisition locks (#1268)
  • (terraform) Reject reserved bucket names (#1271)
  • (terraform) Reject reserved project IDs (#1275)
  • (terraform) Reject remaining reserved project ID words (#1279)
  • (models) Bound serving readiness marker reads (#1283)
  • (terraform) Restrict anonymous GKE API access (#1287)
  • (terraform) Block insecure GKE RBAC bindings (#1289)
  • (terraform) Disable insecure kubelet port (#1295)
  • (models) Scope vLLM loader download egress (#1315)
  • (docs) Declare Open Knowledge Format v0.2 (#1317)
  • (alerting) Bound receiver ephemeral storage (#1319)
  • (admin) Bound Ketesa ephemeral storage (#1321)
  • (agentgateway) Bound quota-store log storage (#1323)
  • (models) Bound demo LLM ephemeral storage (#1327)
  • (docs) Recognize reserved OKF logs (#1326)
  • (canary) Bound probe ephemeral storage (#1329)
  • (agentgateway) Bound proxy ephemeral storage (#1333)
  • (docs) Require entries in OKF log date groups (#1332)
  • (keycloak) Bound identity-plane ephemeral storage (#1335)
  • (docs) Count only rendered OKF index links (#1337)
  • (gateway) Bound Traefik ephemeral storage (#1339)
  • (postgres) Bound CNPG operator ephemeral storage (#1343)
  • (docs) Ignore collapsed OKF disclosure content (#1342)
  • (cert-manager) Bound controller ephemeral storage (#1346)
  • (observability) Bound tracing ephemeral storage (#1349)
  • (kagent) Bound platform ephemeral storage (#1356)
  • (models) Bound vLLM engine ephemeral storage (#1360)
  • (observability) Bound metrics stack storage (#1364)
  • (postgres) Bound database pod ephemeral storage (#1367)
  • (flux) Bound controller ephemeral storage (#1371)
  • (terraform) Bound state version retention (#1377)
  • (models) Require canonical serving snapshots (#1382)
  • (models) Reject unterminated HTTP request lines (#1480)
  • (docs) Validate local heading fragments (#1489)
  • (docs) Reject duplicate heading identifiers (#1493)
  • (docs) Reject duplicate rendered element identifiers (#1500)
  • (docs) Reject invalid rendered identifiers (#1506)
  • (docs) Reject empty rendered link targets (#1511)
  • (ci) Scope supply-chain permissions to publisher (#1534)
  • (ci) Wait for MCP quota config (#1540)
  • (cnpg) Tolerate local API latency (#1544)
  • (ci) Stop transient infra faults from failing main (#1547)
  • (ci) Resolve the gate receipt against the merge result, not the head (#1555)

⚡ Performance

  • (dev) Streamline portable local development (#390)
  • (hooks) Move the repository gates from commit to push
  • (mise) Cache the six checks whose inputs are provably bounded
  • Stop re-running gates CI can prove already ran, and move to Dependabot (#1554)

📚 Documentation

  • Document the protect-main branch-protection ruleset
  • Focus the roadmap on the Definitive v1 cut line and widen agent autonomy (#317)
  • Align tagline, document policies layer, clarify track-based pickup
  • Fix the #316 focus-board link and note app-scoped mise tasks
  • (models) Record the Vertex default decision (#401)
  • (adr) Bind permission-aware retrieval identity (#407)
  • Add per-layer exit strategy (#414)
  • Add incumbent chat coexistence guide (#416)
  • Add adopter decision brief (#425)
  • (observability) Define Matrix identity audit contract (#419)
  • Add persona onboarding guides (#426)
  • (identity) Accept managed-room authorization (#427)
  • Add inbound migration guide (#429)
  • Add day-2 operations handbook (#430)
  • (observability) Define cost showback boundaries (#436)
  • (security) Add auditor control dossier (#439)
  • (agents) Add hosted coding-agent runbook (#448)
  • (skills) Add an 'adding an optional layer' recipe to flux-gitops (#542)
  • (agents) Keep Codex instructions within 28 KiB (#551)
  • (site) Prepare GitHub Pages publishing (#570)
  • (community) Add adopter case-study pipeline (#581)
  • (agents) Document golden eval fixtures (#594)
  • (adr) Retain Bash acceptance rigs (#599)
  • (readme) Complete repository layout (#604)
  • (skills) Align index frontmatter rule (#608)
  • (community) Draft A2A integration submission (#674)
  • (community) Prepare CNCF Landscape entry (#678)
  • (community) Prepare kagent integration pitch (#683)
  • (community) Draft AGNTCon Europe proposal (#686)
  • (community) Prepare launch announcement (#690)
  • (community) Prepare CNCF Sandbox dossier (#694)
  • (community) Reserve newcomer issue pool (#697)
  • (ci) Document release SBOM authentication (#700)
  • (demo) Add recording runbook (#703)
  • (security) Define advisory release process (#711)
  • (operations) Document nightly smoke triage (#858)
  • (community) Add support routing (#864)
  • (readme) Surface support routes (#870)
  • (contributing) Link conduct and support routes (#872)
  • (support) Link structured discussion forms (#874)
  • (agents) Add app-level AGENTS.md for synapse-federation-policy (#904)
  • (activitypub) Move AGENTS commands near the top (#905)
  • (security) External security audit readiness package (part of #459) (#924)
  • (extend) Forking-free bridge chart + agent-pack pattern (Refs #190) (#925)
  • (agents) Retire-an-agent runbook + emergency-disable path (Part of #453) (#928)
  • (audit) Update infra/audit README to the complete offline collector logic (#936)
  • (readme) Reflect ActivityPub demo composition (#973)
  • (fediverse) Reflect demo group composition (#977)
  • (retention) Document conversation reset controls (#981)
  • Refresh grounding, slack, and ESS/mautrix pin claims to shipped state (Fixes #987, #988, #989) (#993)
  • (audit) Describe durable question lifecycle (#998)
  • (agent-reference) Mark embeddings runtime shipped (#1001)
  • (agent-reference) Reflect federation lab topology (#1004)
  • (models) Mark embedding runtime delivered (#1007)
  • (models) Sync vllm cpu pin (#1012)
  • (adr) Sync mautrix appservice pin (#1014)
  • (architecture) Sync kube-prometheus-stack pin (#1019)
  • (readme) Make Keycloak pin exact (#1024)
  • (agents) Document release artifact root (#1029)
  • (adr) Record ShellCheck debt completion (#1032)
  • (design) Sync D20 implementation status (#1034)
  • (design) Refresh kagent D11 evidence (#1036)
  • (stack) Refresh Goose integration evidence (#1039)
  • (site) Align publication wording with gate (#1084)
  • (readme) Lead with client-safe commands (#1088)
  • (security) Link published release contract (#1094)
  • (community) Document PR merge gates (#1108)
  • (ci) Enforce exact-head merge gates (#1111)
  • (grounding) Document regular-file trust boundary (#1225)
  • (identity) Align MAS reference with ESS 26.7.0 (#1249)
  • (federation) Align Synapse callback contract (#1254)
  • (layout) Document the canonical agent pack (#1267)
  • (layout) Inventory repository knowledge ACL (#1273)
  • (ci) Synchronize GitHub Actions inventory (#1277)
  • (agents) Restore instruction headroom (#1307)
  • Record open-standard foundation alignment (ADR 0022 AGNTCY + OTel note) (#1437)
  • (adr) Propose governed user-agent memory (#1026)
  • (adr) Propose authenticated query-embedding egress for retrieval (#333) (#544)
  • Reserve needs-human for cost/cloud/external gates, not design decisions (#1533)
  • Cut scope/v1.0, bind work provenance, and land the docs-site home
  • (site) Clarify contribution indexing contract (#1543)
  • Replace the multi-worktree lane model with one local session (#1546)
  • (architecture) Prepare sovereign RFP reference (#1542)
  • Reclaim bridge instruction-budget headroom (#1548)
  • (local-cluster) Document safe disk reclaim and cluster batching
  • Link the published documentation site (#1556)

🧪 Testing

  • (federation) Add authenticated A2A TCK gate (#391)
  • (mcp) Honor negotiated protocol version (#408)
  • (ci) Add deterministic agent golden gate (#431)
  • (agents) Gate in-repo authoring contracts (#434)
  • (security) Fuzz the owned untrusted-input parsers (#461) (#543)
  • (docs) Gate public repository links (#860)
  • (tooling) Gate documented mise tasks (#862)
  • (community) Gate discussion route drift (#876)
  • (docs) Validate same-repository links (#878)
  • (community) Gate issue-form routes (#880)
  • (agents) Gate skill documentation drift (#882)
  • (flux) Assert per-profile dependsOn closure across all overlays (#899)
  • (agents) Validate project skill metadata offline (Fixes #883) (#937)
  • (federation) Multi-party 3-org joint-ops room (org D) in the fed lab (#944)
  • (federation) Bind per-route azp to its usage-receipt signer in check:fed-registry (follow-up to #354) (#945)
  • (bridge) Model-outage and synapse-restart dependency drills (#946)
  • (docs) Validate contextual mise commands (#958)
  • (docs) Synchronize public app inventories (#963)
  • (community) Validate links embedded in GitHub forms (#1118)
  • (community) Reject duplicate YAML keys (#1148)
  • (community) Reject ambiguous form labels (#1152)
  • (community) Reject duplicate template names (#1156)
  • (community) Validate form project references (#1159)
  • (community) Reject reserved dropdown choice (#1164)
  • (community) Validate effective form references (#1168)
  • (community) Reject password-bearing form labels (#1172)
  • (community) Reject hidden short forms (#1175)
  • (community) Reject ignored yaml forms (#1178)
  • (community) Reject template filename collisions (#1184)
  • (community) Require Markdown template metadata (#1188)
  • (community) Reject ambiguous Markdown template metadata (#1192)
  • (community) Enforce pull request template sections (#1195)
  • (community) Reject discussion filename collisions (#1198)
  • Enforce pull request verification checklist (#1202)
  • Gate model-cache publication contracts (#1204)
  • (docs) Gate the workflow inventory (#1281)
  • (docs) Reject stale workflow inventory (#1285)
  • (agents) Gate the project skill inventory (#1291)
  • (docs) Reject duplicate workflow inventory entries (#1293)
  • (docs) Scope public app inventories (#1299)
  • (docs) Gate instruction measurements (#1313)
  • (docs) Reject external Markdown source symlinks (#1347)
  • (community) Reject external structured-form sources (#1351)
  • (community) Reject external chooser config sources (#1353)
  • (community) Reject external Markdown template sources (#1357)
  • (community) Discover dangling structured-form sources (#1361)
  • (ci) Reject non-hermetic workflow sources (#1365)
  • (community) Reject external pull-request templates (#1369)
  • (docs) Reject external skill metadata sources (#1373)
  • (docs) Reject external app inventory configs (#1378)
  • (docs) Reject external instruction sources (#1381)
  • (docs) Reject external MkDocs config sources (#1385)
  • (docs) Reject external frontmatter sources (#1389)
  • (docs) Reject external identifier sources (#1394)
  • (docs) Reject external skill inventory documents (#1412)
  • (docs) Reject duplicate MkDocs configuration keys (#1414)
  • (docs) Reject recursive YAML aliases (#1416)
  • (docs) Preserve MkDocs scalar types (#1420)
  • (docs) Reject external skill directories (#1422)
  • (docs) Validate directory-linked skill links (#1426)
  • (docs) Reject unresolved skill symlinks (#1430)
  • (docs) Reject external skill resources (#1440)
  • (docs) Validate tasks in directory-linked skills (#1444)
  • (community) Validate documented mise tasks (#1448)
  • (docs) Align public task entrypoints (#1452)
  • (ci) Validate workflow mise task references (#1454)
  • (docs) Share public Markdown sources (#1458)
  • (docs) Reuse repository source boundary (#1462)
  • (community) Validate Markdown issue templates (#1467)
  • (docs) Validate app README guidance (#1474)
  • (community) Reject invalid chooser contact URLs (#1516)
  • (community) Validate upload accept extensions (#1518)
  • (community) Reject defaulted n/a options (#1520)
  • (community) Reject blank form attributes (#1524)
  • (community) Type-check Markdown metadata (#1530)
  • (community) Validate Markdown collections (#1532)

⚙️ Build & CI

  • Stop publishing the mutable :latest bridge image tag
  • Authenticate Syft to the private GHCR image in the release SBOM job
  • Cache external charts with retry in check:manifests (#326)
  • Pin mise to 2026.7.11 (2026.7.12 broke npm renovate install, blocking all PRs) (#950)

🧹 Miscellaneous

  • (bridge) Pin deploy image to the v0.1.0 build [skip ci]
  • (apps) Standardize module paths and image tags on fmind-ai
  • (bridge) Pin image sha-49867dd [skip ci]
  • (bridge) Pin image sha-cd62b84 [skip ci]
  • (bridge) Pin image sha-8535d32 [skip ci]
  • (agents) Prepare cloud and worktree environments (#404)
  • (bridge) Pin image sha-d81150c [skip ci]
  • (agents) Coordinate parallel sessions (#412)
  • (bridge) Pin image sha-cd849ac [skip ci]
  • (bridge) Pin image sha-879734a [skip ci]
  • (bridge) Pin image sha-0b08fa4 [skip ci]
  • (bridge) Pin image sha-4791209 [skip ci]
  • (bridge) Pin image sha-67931d4 [skip ci]
  • (bridge) Pin image sha-58213e0 [skip ci]
  • (bridge) Pin image sha-4b58634 [skip ci]
  • (bridge) Pin image sha-3bf058e [skip ci]
  • (bridge) Pin image sha-02015b9 [skip ci]
  • (bridge) Pin image sha-4147ba1 [skip ci]
  • (bridge) Pin image sha-cfa5be4 [skip ci]
  • (bridge) Pin image sha-6207d2c [skip ci]
  • (bridge) Pin image sha-819a9c4 [skip ci]
  • (models) Prepare residency policy handoff (#449)
  • (bridge) Pin image sha-35ad88e [skip ci]
  • (bridge) Pin image sha-e2a0063 [skip ci]
  • (bridge) Pin image sha-850f5d2 [skip ci]
  • (bridge) Pin image sha-706608e [skip ci]
  • (ci) Pin runners to ubuntu-24.04 before the ubuntu-latest 26.04 roll (#546)
  • (bridge) Pin image sha-7cbd7fb [skip ci]
  • (bridge) Pin image sha-9fa671b [skip ci]
  • (gateway) Advance coupled compatibility pins (#548)
  • (scripts) Enforce ShellCheck and shfmt gates (#549)
  • (tooling) Add k9s for cluster debugging (#553)
  • (observability) Restrict OTLP ingestion (#579)
  • (security) Bind backends to Traefik pods (#584)
  • (observability) Restrict telemetry clients (#587)
  • (bridge) Pin image sha-8730cf2 [skip ci]
  • (hooks) Format ActivityPub gateway (#592)
  • (observability) Bump kube-prometheus-stack (#612)
  • (scripts) Lock ShellCheck debt inventory (#611)
  • (flux) Bump cert-manager to v1.21.0 (#613)
  • (scripts) Resolve SC2250 findings (#614)
  • (matrix) Bump ESS stack to 26.7.0 (#603)
  • (models) Bump vllm cpu image to v0.25.1 (#615)
  • (scripts) Resolve SC2248 findings (#616)
  • (scripts) Resolve SC1003 findings (#618)
  • (scripts) Justify generated fixture sources (#621)
  • (scripts) Make case defaults explicit (#624)
  • (scripts) Justify indirect fixture calls (#627)
  • (scripts) Justify subshell fixture isolation (#629)
  • (scripts) Justify literal fixture expansions (#632)
  • (scripts) Justify fail-closed fixture substitutions (#638)
  • (flux) Update controllers to 2.9.2 (#641)
  • (observability) Update stack to 87.17.0 (#649)
  • (models) Align embedding vllm runtime (#653)
  • (infra) Update local K3s patch (#664)
  • (ci) Prepare Cosign 3 verification (#668)
  • (bridge) Pin image sha-78a620e [skip ci]
  • (ci) Gate workflows with zizmor (#716)
  • (bridge) Pin image sha-8f283b7 [skip ci]
  • (tooling) Pin root mise tools (#721)
  • (bridge) Pin image sha-d36abb4 [skip ci]
  • (ci) Bound workflow job runtimes (#730)
  • (bridge) Pin image sha-336a646 [skip ci]
  • (ci) Enforce workflow job timeouts (#735)
  • (ci) Enforce workflow concurrency (#740)
  • (ci) Harden checkout credentials (#745)
  • (ci) Enforce explicit Actions permission maps (#749)
  • (ci) Enforce literal pinned Actions runners (#753)
  • (ci) Require named GitHub Actions steps (#756)
  • (ci) Require digest-pinned Actions container images (#760)
  • (ci) Enforce Bash pipefail in workflows (#763)
  • (bridge) Pin image sha-e0f129a [skip ci]
  • (ci) Enforce artifact hygiene (#767)
  • (ci) Require actionable artifact inputs (#771)
  • (ci) Remove obsolete zizmor suppressions (#775)
  • (bridge) Pin image sha-ca0ff2d [skip ci]
  • (ci) Make workflow intent explicit (#782)
  • (bridge) Pin image sha-bb6b2e9 [skip ci]
  • (community) Route contributors through issue forms (#787)
  • (ci) Upgrade GitHub Pages actions (#798)
  • (ci) Verify mise action downloads (#800)
  • (bridge) Pin image sha-cde4d6e [skip ci]
  • (ci) Upgrade attest action (#803)
  • (bridge) Pin image sha-877e90a [skip ci]
  • (ci) Validate Renovate configuration (#806)
  • (ci) Skip bridge root tool install (#810)
  • (ci) Scope CD release toolchain (#816)
  • (bridge) Pin image sha-7e3728c [skip ci]
  • (ci) Scope fuzz Go toolchain (#820)
  • (ci) Scope NetworkPolicy toolchain (#825)
  • (ci) Scope smoke scanner toolchain (#833)
  • (ci) Scope smoke policy toolchain (#836)
  • (ci) Scope smoke demo toolchain (#839)
  • (ci) Enforce scoped mise setup (#841)
  • (ci) Require bare mise-action tool keys (#843)
  • (docs) Update ty to 0.0.61 (#848)
  • (community) Structure discussions (#866)
  • (community) Route discussion intake (#868)
  • (images) Refresh official Debian rebuild digests (#900)
  • (scripts) Consolidate byte-identical shell helpers into lib.sh (#901)
  • (images) Move both apps to static-debian13 distroless base (#908)
  • (bridge) Pin image sha-7c029a9 [skip ci]
  • (tooling) Pin kubectl 1.35.0 → 1.36.2 (#909)
  • (bridge) Pin image sha-15a2d98 [skip ci]
  • (tooling) Pin every mise tool exactly, drop 'latest' (#910)
  • (bridge) Pin image sha-9faa42f [skip ci]
  • (bridge) Pin image sha-856b1ff [skip ci]
  • (bridge) Pin image sha-7b7537d [skip ci]
  • (security) OpenSSF Scorecard workflow + Best Practices self-assessment (part of #460) (#923)
  • (bridge) Pin image sha-bb11ad9 [skip ci]
  • (bridge) Pin image sha-975d9ec [skip ci]
  • (hooks) Format matrix group sync (#970)
  • (bridge) Pin image sha-95c5af6 [skip ci]
  • (bridge) Pin image sha-c00e997 [skip ci]
  • (bridge) Pin image sha-d021b34 [skip ci]
  • (bridge) Pin image sha-b75ec8d [skip ci]
  • (docs) Update ty to 0.0.63 (#1045)
  • (docs) Update Ruff to 0.16.0 (#1048)
  • (ci) Refresh GitHub Actions release pins (#1053)
  • (bridge) Pin image sha-6e94eb6 [skip ci]
  • (ci) Update Renovate to 43.279.0 (#1066)
  • (ci) Update uv to 0.11.32 (#1068)
  • (ci) Update Flux CLI to 2.9.3 (#1072)
  • (ci) Update kubectl to 1.36.3 (#1076)
  • (ci) Update SOPS to 3.13.3 (#1080)
  • (ci) Pin mise runtime across workflows (#1098)
  • (community) Require bug report redaction (#1102)
  • (community) Expose PR merge gates (#1105)
  • (ci) Update helm-unittest to 1.1.2 (#1229)
  • (ci) Update Renovate to 43.280.3 (#1233)
  • (ci) Update Docker login action to v4.5.1 (#1237)
  • (bridge) Pin image sha-53955c6 [skip ci]
  • (ci) Update mise action to v4.2.3 (#1240)
  • (bridge) Pin image sha-477e415 [skip ci]
  • (ci) Update Renovate to 43.280.4 (#1242)
  • (flux) Format local bootstrap manifests (#1539)
  • (bridge) Pin image sha-9a9e5cb [skip ci]
  • (bridge) Pin image sha-d8b9836 [skip ci]
  • (bridge) Pin image sha-0b82ec7 [skip ci]
  • (bridge) Pin image sha-97fdfd9 [skip ci]
  • (bridge) Pin image sha-8b17edb [skip ci]
  • (bridge) Pin image sha-656ab31 [skip ci]
  • (bridge) Pin image sha-dacf071 [skip ci]

The complete generated changelog, including legacy non-Conventional commits grouped as Other, is preserved in the immutable tag: CHANGELOG.md.