Releases
v0.1.0
Compare
Sorry, something went wrong.
No results found
Changelog
fa8e3ba release-pipeline-02: sweep distribution posture to the release-exists state for the v0.1.0 tag cut (D-0122)
5eb62a3 docs-version-stamp-02: record seed-time doc stamping as D-0121 and give release-pipeline-02 its tag-time re-seed step
00344fa feature-clips: register the standing clip claims and close the item
4931e40 releasing-runbook: cross-reference operator runbook from release-pipeline backlog
c6ef5d4 encryption-key-path: boot fails closed on a key/database mismatch, and the key path becomes configurable alongside the DSN (D-0120)
434663f promote-adapter-activation: connect and register the live adapter on promote, closing the "adapter not found" gap (D-0119)
07164c8 fix(logs): stop quoting PM-spine section markers in runtime strings
0325a57 build: close the build-tag blind spot in the local gates
cf5258f fix(test): drop clarifications subtest orphaned by D-0118
96dc2b7 chore: tidy go.mod and mark unused test helper param
f25f044 fix(lint): drop ineffectual cfg initializer in db_test seedDatabase
804c47a onboarding-feature-removal: delete the onboarding and clarifications subsystems wholesale, prune not park (D-0118)
ddeea5d component-delete-graph-orphans-02: propagate D-0117 delete-cascade wording into the published growth-posture page
c7c391a component-delete-graph-orphans: cascade graph state on component delete, sweep pre-existing orphans, remove the Refresh buttons (D-0117)
a846dde observe-k8s-resolver: bind services to clusters by component type, fixing a joe_k8s resolver that never worked (D-0116)
f624ba5 db-persistence-backup-02: add joe db restore, and correct the manual restore procedure that silently restores the wrong database (D-0115)
7cc719f db-persistence-backup: add joe db backup, document the persistence story, and fix the Configuration tilde trap (D-0114)
95c7eb4 lint-embed-field-fix: drop the vestigial embedErr field the D-0113 prune left in the llmusage test fake
e5e3d41 mcp-tool-count-fix: correct the MCP roster count to seven on the public guide
291e7be knowledge-store-prune: delete the knowledge store, its doc-proposals arm, and embeddings from the tree (D-0113)
0e8cc31 knowledge-graph-guide-fixes: correct published link depth across guides and two concepts pages, drop the retired-tier meta-commentary, and file the knowledge-store prune (D-0112)
f57cb63 trim-unsupported-component-types: extend the D-0058 trim to the twelve types that fail the documentable gate, and delete the now-false "Not yet supported" docs paragraph (D-0111)
5b7aab9 iac-graph-ingestion: pin the graph as deterministic-only, park the three onboarding-era graph-write tools, and correct the stale Confidence docs (D-0110)
65e0842 knowledge-store-maturation: flip the tier-less create default to derived, park save_knowledge_entry, and correct the public copy to shipped truth (D-0109)
0a7bd9e rbac-engine-split-02: triage read-posture-visibility to Priority: next
58588df demo-bugfix-pins: pin the graph-ui-declutter fix, exempt two non-behavior fixes, and file the demo-runbook and dev-skill items
15a3dbb rbac-engine-split: build one governance-wired RBAC engine at the composition root and inject it into api.New; delete EnforcementMiddleware
b941269 sessions-admin-delete-affordance: file backlog item for admin delete discoverability gap
a4fdac7 ui-source-strings: rename remaining legacy "source" UI strings to component
19bd44a chat-stop-resend: add stop control, cancelled-turn marker, and resend
6b770ba graph-ui-declutter: remove dead per-node gear glyph and fictional node-type legend
a4ade60 fix: use Joe favicon in web UI instead of default Vite icon
2bcd17c fix-duplicate-declare-incident-02: append D-0105 recording the declare-affordance claim registry decision
732e11d fix-duplicate-declare-incident: one declare affordance on screen at a time
ae21572 observation-banner-docs-link: point at the deep-linked observation-mode docs page
a4914ac posture-prompt-conflation-02: close the per-tool read-only wording leg (D-0104)
10fd026 silent-tool-intent-dead-end: probe a tool-call-free response for an unfulfilled tool intent (D-0103)
bf3f506 k8s-get-thrash: reject a by-name k8s_get with an empty namespace before it reaches the API
3c1be9f posture-prompt-conflation: reword the observation posture to draw the read/mutate boundary explicitly
aa925ef feature-clips: make the demo-world orders workload camera-neutral
3a38bff web-ui-header-lockup: replace "Joe" wordmark with the Joe lockup in the sidebar header
7caf390 loop-budget-exhaustion: forced synthesis on iteration-cap exhaustion instead of hard-fail
9ca5a68 claude-instructions-report-format: wrap CC session reports in a single fenced code block for one-click copy
28df1a5 sessions-new-chat-blank: New chat button lands on a blank chat, not the last session
c1f82f0 backlog-priority-field: add optional Priority/Blocked-by lines and INDEX Priority column
f8002ac claude-instructions-report-format: instruct CC to write session reports as plain undecorated prose for the chat model
3fa0610 crd-gvr-resolution: fix CRD GVR spec format so k8s CRD discovery resolves (D-0094)
40ffe1d refresher-rbac-degradation: k8s refresher degrades per-resource-type on forbidden (D-0093)
14f430b source-log-sweep: rename stale "source" wording to "component" (D-0021), fix double-wrapped k8s list-secrets error
539a917 feature-clips: two-phase orders workload for ~5-min symptoms without CrashLoopBackOff
ebbedbb releasing-runbook: add operator release runbook at docs/RELEASING.md
16de344 release-pipeline-01: flip goreleaser to publish-on-tag with a structural UI-staging guarantee
ca5a62b history-scrub-02: record the content-side history rewrite and neutralize residual copy
1c91b3b history-scrub: record executed git-history scrub (former-employer email rewrite + binary-blob purge)
8832e33 site-claims-refresh: add Configuration and Operations register sections and make the D-0077 obligation bidirectional
a26f49d Merge pull request #18 from jaimegago/dependabot/go_modules/go_modules-a3c8a40308
745d87a db-retention-story: document the session-sweeper retention and unbounded-growth posture for operators
e686b4f contributing-guide: add repo-root CONTRIBUTING.md grounded in the live tree
19a5ab3 postgres-backend-truth: walk back the PostgreSQL-backend overclaim in public and reference docs
aec5ce9 Merge remote-tracking branch 'origin/main' into db-crypto-bump
82a132c update-model-rec-convention: switch project-instructions model recommendation from tiers to model-name + effort level
f73a840 fix-lint-parked-routes: silence unused linter on parked D-0081 route registrars
301562b readme-hero: add themed logo lockup and hero tagline to root README
3ea9544 readme-rewrite: rewrite root README from scratch against the live tree
49aaca8 create-echo-readmodel: project the POST /components 201 echo through componentView
75f67ca llm-observed-health-surface: add backlog item for LLM observed-health surface and index it
dac098b datastore-uri-credential-provider: reclassify kafka as discrete-field SASL and record parse-but-never-apply gap
bfbda39 build(deps): bump golang.org/x/crypto
7ed44a8 Merge pull request #17 from jaimegago/dependabot/go_modules/go_modules-57bd245098
e6172bb observation-wording-triage: reframe the mutation-surface paragraph as registered-but-floor-denied, and record D-0082
8e23544 discovery-clarifications-pipeline: park onboarding, clarifications, and manual-refresh HTTP routes for launch
5e55360 graph-node-taxonomy: correct the graph node model to components-as-anchors plus discovered resources, and relocate the curated/derived authority to the knowledge store
e1cc973 incident-regime-wording: replace rhetorical meta-commentary in the deferred section with plain scope statement
40b50cb docs-triage: cite D-0022 for denial precedence in code comments; state observation as the boot default in docs/reference
950cf32 project-instructions: add per-prompt model-recommendation directive for emitted Claude Code prompts
5e44d31 slack-client-stance: record D-0079 classifying the Slack bot as a first-party REST API client, not a fourth input surface
ad2889f machine-callers-phrasing: distinguish shipped machine clients from example external callers
83bac0a write-floor-page-copy: reword the observation/write-floor Concepts page to classify tools by capability and drop forthcoming-full-mode phrasing
02eb330 components-page-restructure: open the Components index with a definitional intro and move the per-type tables to a connectable-systems child page
c48b96c safety-page-03: create the joeagent.dev site-claims register and wire the drift-detection obligation
7034244 feature-clips: land the demo-world public example (examples/demo-world/)
12af87d safety-page-05: record the missing no-MCP-client guard test as an open backlog item
f399f86 safety-page-06: correct the MCP server-direction safety claim
0d5eeeb skills-governance-hardening: admin-gate the mutating skills HTTP endpoints
deef666 safety-page-04: record skills-governance hardening as an open backlog item
ad44075 safety-page-01: add the incident-command (ICS) lineage to the incident-regime concept page
dd0eb94 console-brand-tokens: add deferred backlog item for the operator console brand token layer
93c2b7e orphaned-tool-registration-cleanup: delete two-binary-era local-tool residue from the safety layer
1cf9e4b observation-default-01: correct docs/public boot-posture and full-mode copy to D-0073 truth
2304341 observation-default: invert boot write-floor default to observation; refuse JOE_MODE=full
687f7ec read-posture-latch: posture-gate the Policies admin UI; correct the hide-zoned-era-UI scope
bd44912 docs-public-refit-02: add Hugo aliases for the two published URLs killed by the D-0070 renames (D-0071)
133cc1a fix: resolve repo audit findings across backend, frontend, and docs
8e55ce1 docs-public-refit: rework capabilities into the action-model page, rename Integrations→Components, retitle the components concept page, and fix launch copy
deaa249 build(deps): bump golang.org/x/net
0b66360 sysinfo-tool-removal: delete the system_info shared tool; shared tools are outward network diagnostics only
7476354 mcp-client-rejection: expand the guarantee section to cite OASIS and Joe's open-source verifiability on the public Joe-and-MCP page
ab0ae11 mcp-client-rejection: revise the two MCP-guarantee sections on the public Joe-and-MCP page to cover read-only zones alongside observation mode
d7581fe mcp-client-rejection: record the by-construction rejection of Joe as an MCP client (D-0067)
a72d3a1 capability-map: add a Capabilities Concepts page mapping Joe's read-only capability surface; relocate the web_search narrative to Concepts; correct the observation-mode default claims
71b9c4d agent-identity-doc-04: retire and delete the kubeconfig-exec credential provider (slice D)
0fc7b28 web-search-tool: add a Go-native web_search shared Read tool behind a SearchProvider abstraction
0233f84 agent-identity-doc-03: add Entra-exchange as the second Kubernetes auth method (transport-agnostic, minted bearer token)
b4c11e4 agent-identity-doc-02: rewrite Kubernetes transport to a hand-built rest.Config with static-bearer auth (no kubeconfig ingestion)
71bed36 agent-identity-doc-01: enforce per-component uniqueness of static credential env-var names
7f586dc agent-identity-doc: capture Joe's agent-identity and authentication stance as design-of-record in a held, non-published draft
5a10cd6 quickstart-out-of-cluster-kubeconfig: make the host kubeconfig an explicit, assumed prerequisite
cb8adb5 quickstart-register-before-asking: connect a component before the one question, and surface the component-credential prerequisite
a5facd9 component-registration-guide: add UI-driven Kubernetes register-and-promote how-to; Quickstart includes one component
9cddbb2 trim-deadonarrival-component-types: remove six non-functional types from the registrable set at the single authoritative seam
a71c5d5 register-component-config-default: persist config-less registrations by normalizing absent config to "{}" at the shared seam
a8dac00 healthz-endpoint-surface: file standards-anchored, decision-ready backlog item for an unauthenticated health-probe surface
b898ddf unauth-health-surface: investigate unauthenticated deployment-grade health surface
c208394 docs-public-establishment-pass-08: close out the thread and reconcile /status auth tier
d5d0ee4 docs-public-establishment-pass-07: fill API Reference (reference) from live route registration
6f33d71 docs-public-establishment-pass-06: fill Operations (how-to) with break-glass folded in
8921fd3 docs-public-establishment-pass-05: fill Guides (how-to) — one page per feature area
f95db28 docs-public-establishment-pass-04: route Integrations by runtime vs boot-config activation
49b6a36 docs-public-establishment-pass-03: fill Configuration (reference) and Integrations (how-to)
0afac35 revert-return-path: remove return-path routing conventions
7251432 docs-public-establishment-pass-02: fill Install and Build (how-to) and Quickstart (tutorial)
c7efe9e return-path-conventions: add slug-echo and spot-code return-path routing conventions
44bed99 docs-public-establishment-pass-01: stand up docs/public surface; write Overview and Concepts
808f601 llm-instrumentation-rewire: remove dead LLMMiddleware metrics path, wire NewInstrumentedAdapter into BuildLLMChain
194c508 docs-reference-audit-05: resolve the final 13 reference-doc misalignments and close the campaign
0e57b2e public-docs-feature-inventory: verified inventory of what Joe actually ships
b1c2494 docs-reference-audit-04: retire dated accessor-promotion-state-axis investigation, absorb survivors into security-in-layers
1b21fd9 openai-compat-adapter-01: gitignore .env so local API keys are never committed
83de41e docs-reference-audit-03: retire two direct-HTTP-mutation investigation docs, absorb survivors into security-in-layers
64059c7 openai-compat-adapter-01: add key-gated live integration test; record live verification
2cff829 docs-reference-audit-02: rewrite security-in-layers.md to the live tool surface
e5bbc0b docs-reference-audit-01: rewrite operational-modes-ui-status.md to the live write-floor model
68c99f8 openai-compat-adapter: add generic OpenAI-compatible LLM adapter
ed53c32 docs-reference-audit: audit docs/reference against the live tree; file 67 misalignments
f0eb570 Revise Joe architecture documentation
c074c31 docs-tree-restructure: reorganize docs into project/reference/backlog-investigations; archive process-exhaust externally
1120082 case-study-kiro-redo: queue Kiro case-study redo and preserve old content as a stale snapshot
f8d7a52 docs-reconcile-security-consolidation: delete JOE_SECURITY.md + JOE_RBAC_IMPLEMENTATION.md, consolidate on security-in-layers.md
6b6acbf docs-reconcile-testing-strategy: delete testing-strategy.md, redirect refs to as-built test/ harness
9abf23b docs-reconcile-narrative-ops-02: reconcile web-ui.md to the live tree
3d33335 docs-reconcile-narrative-ops-01: reconcile operations.md to the live tree
9fefa9e docs-reconcile-narrative-light: six surgical single-claim corrections across narrative docs
7ed72ac docs-reconcile-historical-annotations: add as-of/superseded banners to five KEEP docs
5efa480 docs-reconcile-artifact-cleanup: untrack .vscode/settings.json and extend .gitignore artifact set
9573ea2 docs-reconcile-sweep: read-only audit of docs/ with a committed reconciliation plan
d8772a3 tool-class-break-tests: backlog the two unpinned tool action-class break-tests
a8f7fee arch-doc-staleness: rewrite joe-architecture.md and security-in-layers.md against the live tree
3f96f32 post-joefile-cleanup-02: align security/architecture docs to live register_component + D-0021 + .joe removal
f4f2a97 post-joefile-cleanup: drop dead discovery stub, fix register_source doc drift, derive migration step counts
21d9925 read-posture-latch-02: separate the agent:core read surface from the read posture
10530a1 joefile-removal: delete the .joe/ repository-ingestion path
f62c6f6 read-posture-latch: persisted install-wide read posture (team_flat default, zoned full-mode)
6d94b18 rbac-v2: seed the Full RBAC v2 backlog item (role indirection, group subjects, granular permissions)
f973e26 credential-reject-single-source: archive resolved single-sourcing residual
e11da53 admin-nav-consolidation-01: move Credentials under the Admin subgroup
e2ac1f9 admin-nav-consolidation: record D-0039 (consolidated admin-surface model)
41d7814 admin-nav-consolidation: inline Sessions governance for admins
c43be16 admin-nav-consolidation: inline Components admin affordances
8ea43c9 admin-nav-consolidation: single expandable Admin nav subgroup
06958f0 admin-nav-consolidation: split Admin tab-host into per-surface routes
69ae416 launch-ui-polish: remove stray section-reference fragment from retention copy
bd5a617 launch-ui-polish: persistent ADMIN badge in the sidebar identity area
d6d782a launch-ui-polish: make chat the default landing surface, retire fabricated-data dashboard
b57dbdf chat-input-visibility: pin chat input below observation banner
58ec87b context-usage-display: chat token badge as context-window utilization (input X of window Y)
ab40685 build-version-instrumentation: single buildinfo source, /version endpoint, joe_build_info gauge, goreleaser scaffold
d3973da pm-convention-capture: specify session-tracking convention in docs/pm-convention.md, version-control claude.ai project instructions, log D-0035
9f43dde backlog-index-init: create docs/backlog/INDEX.md and done/ archive directory
f91f220 backlog-triage: diagnose done/obsolete/open status of pre-existing backlog files
a1db2d9 jpk-retirement: rehome unique JPK items to spines and retire the file
26adc7b claude-md-drift-correction: verify provider set + structural edge-type/migration counts, add session-subsystem invariant, log D-0032
a53cb07 edge-type-count-arbitration: resolve 19-vs-20 edge-type count against source
f9c3430 jpk-migration-triage: read-only triage of JOE_PROJECT_KNOWLEDGE.md before retirement
0c41292 pm-spine-wiring: wire decision-log + backlog pointers and adopt session-tracking convention
1b8e222 docs(sessions): P2 client-side interim note + P3/content-search backlog
563bad2 feat(ui): shared filter+sort controls on both session views
d793bd0 feat(ui): client-side session filter+sort pure functions
86a5b89 feat(ui): two-view sessions split — Conversations vs Incidents
ec61fbb feat(ui): pure groupSessions transform for the sessions two-view split
02804dd feat(ui): decode incident_involved on the session list schema
142b795 feat(api): surface incident-involved flag + linked master title on the session list
0522f0e docs(sessions): design doc for the two-view incidents/conversations split
e9ca9b1 fix(ui): pin the incident-mode banner so it survives transcript scroll
477e8a6 fix(ui): gate chat incident chrome by session role × regime, not regime alone
186086a feat(api): surface linked/active incident master title to the client
1b52e7f feat(ui): pure incident-affordance function from session role × regime
141b736 docs(comments): cite migration 025 for incident CHECK constraints
e8468fe docs(sessions): correct false 'B001 inventory reports landed' claim
f42fdaf docs(backlog): defer cross-incident relink of former incident master
5fcf660 test(ui): add required type field to Session fixtures
adb296f docs: require verifying UI features in the running app
66c0607 fix(incident): mark incident session in UI and add resolve flow
91c4595 fix(ui): don't strand the Chat tab on a read-only foreign session
acd75a6 fix(ui): refetch session history on mount so mid-stream navigation doesn't hide persisted turns
d9a2a9e feat(sessions): B008 session UI surfaces + §12.5 reword (§12.10)
a9e3354 feat(sessions): B007c session archive provider + transitions + wiring (§12.6)
b3349c9 Merge pull request #16 from jaimegago/worktree-dependabot-fixes
352937e fix(ui): bump vite to 8.0.16 and undici to 7.28.0 (dependabot)
2013e07 feat(sessions): B007b retention sweeper + login-flow drain (§12.5)
e1e88e9 feat(sessions): B007a session trash/retention lifecycle store (§12.5)
7690cce feat(sessions): B006 admin session governance namespace (§12.8)
d40e7ed feat(sessions): B005 per-user sessions API on the seam (§12.8)
2ee64bf feat(sessions): B004 incident declaration promote-in-place (§12.3)
28bcc47 feat(sessions): B003 dedicated session authorization seam (§12.7)
75bc545 docs(sessions): add §12 clean-room session redesign (B001)
4afacde docs(knowledge): correct learn-from-sessions status to dormant/orphaned
83e3a29 fix(adapters): redact credentials from MongoDB URIs in error/status messages
8cbd941 feat(store): B002 session storage-schema rewrite (§12.4)
a6c85ed docs(backlog): record learn-from-sessions fate as deferred future feature
9dbe674 test(e2e): configure service account so harness boots under identity guard
8889b09 feat(ui): Skills admin tab — expose loaded skills, source, and quarantine controls
d651a1a feat(ui): operator toggle for per-type autonomous reads (A002)
6fa0107 feat(ui,api,credential): component promotion/arm surface + locator-safe read model (A002)
78e7a62 feat(ui,api): operator-facing component registration form (A002)
3a9c029 docs(backlog): record registry-auth-pair credential-provider gap (deferred from A003)
ba23db5 fix(credential): back artifactory out of the W2 static-token wired set
b1412be feat(credential): extend wired-type registry to the A003-W2 static-token set
25c8cd1 feat(gitops,registry,security): resolve adapter tokens through credential seam (A003-W2)
14c581b feat(alerting): resolve adapter tokens through credential seam (A003-W2)
0ba9a51 feat(observability): resolve adapter tokens through credential seam (A003-W2)
504baa7 feat(components): add the governed component promotion endpoint (A003 Stream P)
580315c feat(credential): export credential-bearing field set; single-source componentgov denylist (A003 commit-one)
f65879f feat(coreagent): govern register_component as credential-less + audited, still ActionRead (A003-G)
86081d1 feat(components): govern component DELETE with same-tx audit and full-row clear (A003-G)
74ad4a2 feat(components): govern component CREATE as a credential-less promotion boundary (A003-G)
a72b850 feat(credential): declare wired-type registry for the provider seam (A003-W1)
f99d332 feat(gitlab): resolve token through credential-provider seam at Connect (A003-W1)
fed76d0 docs(backlog): record redis in datastore credential entry as discrete-field carve-out
bc05f32 docs(backlog): record deferred credential-provider gaps (A003 promotion boundary)
6b03444 feat(coreagent): floor autonomous refresh reads under agent:core RBAC (A001-COREGOV)
e748055 docs(decisions): record D-0027 refuse-to-start on absent identity (JOE-IDBOOT)
b5a030a docs(investigations): add read-only identity/RBAC investigation notes
19113a9 feat(boot): refuse to start without a usable identity configuration (JOE-IDBOOT)
ac55772 refactor(api): build accessor policy engine via shared RBACEnabled predicate
da5a412 feat(config): add shared RBACEnabled engine-enable predicate (JOE-IDBOOT)
343f32a feat(ui): credential authz/connectivity status surface (D-0026 unit 3)
5a15ace feat(credential): per-component credential status API (D-0026 unit 3)
2e2982a docs(backlog): record tilde-expansion helper unification target (D-0026)
7f1c979 docs(credential): record GitHub dual-source token precedence (D-0026)
a0dadeb test(credential): guard duplicated tilde-expansion helpers against divergence
33cf46f fix(credential): expand ~ in kubeconfig-exec Probe path (D-0026 unit-1 fix)
c22f768 feat(credential): wire credential provider into GitHub and k8s Connect (D-0026 unit 2)
adaf531 feat(credential): add credential-provider package (D-0026 unit 1)
42927fe add investigation docs
d62ab05 docs(backlog): record azure Connect skeleton gap (deferred, D-0026)
bddb8ff docs(decisions): add D-0026 credential provider abstraction ADR
18d0f85 refactor(api): remove vestigial direct-HTTP managed-system routes; move auth/RBAC assertions onto the accessor seam
81be86b Revise security findings punchlist for route deletions
f678b60 Add security findings and cleanup punch-list
120b5fe Fix formatting issue in security architecture document
82a6c81 Document credential resolution in security architecture
2db1a3e docs: drop stale review-agent mentions from llmusage test comments
c987182 refactor(rbac): complete source→component rename in rbac + admin handlers
dbb9b38 refactor: remove orphaned two-binary-era review-agent subsystem
93f95de fix(sessionmodel): make captain transfer swap atomic in one tx (D-0025)
7bf0bc2 fix(sessionmodel): detach active captain on incident resolve (D-0024)
1a21d4c Document incident regime and captain gate in architecture
4062f5f Add security architecture direction document
4a67b0f refactor: rename "source" → "component" entity (D-0021)
be61824 fix(ui): stop cold-load principal purge from stranding app-shell banner queries
445f84a feat(prompts): add write-floor posture line to task system prompt
3ba60f8 feat(ui): add observation-mode banner bound to GET /api/v1/mutate-status
fd2a5c8 refactor(api): rename posture endpoint to mutate-status with corrected contract
75e23bc feat(api): add read-only write-posture endpoint (tri-state)
4971b43 docs(backlog): record deferred posture-endpoint write-grants signal (full-mode only)
f6de84b docs(backlog): record deferred denial-feedback pop-up UI item
27e6b8a docs(backlog): record full-capabilities-mode RBAC track (fail-closed empty RBAC + agent:core principal)
3af687d docs(claude): refresh safety invariants — write floor, denial precedence, DB-backed panic state
e797f74 fix(safety): wire write floor into user-task executor + captaingate (D-0022)
7f10972 feat(safety): enforce denial precedence floor > incident > RBAC by check order (D-0022)
bb37bfd refactor(safety): consolidate panic state to the DB row; delete panic.state file (D-0018)
6208985 docs(decisions): record D-0021 source→component rename; add adapter-dispatch consolidation backlog
c8e0cdf feat(safety): boot-resolved, runtime-immutable write floor (D-0018)
bee601c docs(decisions): correct run_command characterization in D-0020 durability note
c1dc99f refactor(durability): decouple crash-resume from action class — opt-in NeedsDurability per tool (D-0020 follow-up)
360fdff fix(auth): scope web UI cache to identity; dev insecure_cookies flag
0ce4825 feat(chat): org-wide read model for sessions; fix restore + auto-title
e530fc8 docs(decisions): D-0020 follow-up — note persisted three-valued tier as deferred cleanup debt
6ae0133 refactor(safety): collapse three-tier action classification to binary Read/Mutate (D-0020, refines D-0018/D-0019)
7e0b393 fix(safety): reclassify tool tiers by the managed-system write definition (D-0018/D-0019)
e4a1d0e docs(decisions): D-0019 — Joe's trust model (two postures, graduated capability, fail-closed-empty-RBAC); design decision, implementation pending, companion to D-0018
b528170 docs(decisions): D-0018 — read-only write floor as boot-resolved, runtime-immutable security boundary (design decision, implementation pending)
7284424 fix(chat): keep New Session button available in read-only sessions
076e9bd fix(captain): bind transfer confirm/cancel to the handshake parties
589c81b fix(chat): stop session-recovery from resetting live chats to "New chat"
3b27fe3 feat(ui): safe-mode banner and typed denial message
fbe9a77 feat(safety): typed safe-mode tool denial with stable error_code
67478ee fix(chat): restore last-viewed session when returning to /chat
a1e808f fix(chat): give auto-title call enough tokens for reasoning models
8a356d3 feat(chat): inline session title editing in the chat header
5f9807d feat(sessions): list public sessions shared by other users
6c5d742 docs(claude): drop Co-Authored-By trailer from commits
79e6efa feat(chat): show session title as page header, claude.ai-style
017b334 fix(chat): de-duplicate terminal answer echo in assistant turn
1158972 feat(sessions): chat session incident linkage (Phase 4)
c0fb2be docs: retire internal launch audits; record D-0016; repoint comment citations
b82f903 feat(sessions): chat session sharing (private/public)
7753556 refactor(llm): remove dead ChatStream streaming interface
6814284 feat(sessions): browse tab + auto-titles (chat sessions Phase 2)
146c240 refactor: unify background-loop shutdown on context cancellation
67de84f refactor(netcheck): drop redundant result channel in port fan-out
86ae073 refactor(coreagent): remove dead Agent.stopCh channel
4ee8b4b hide graph page from ui
52ffa01 test(llmusage): make cost-gate window tests time-of-day independent
e150743 feat(sessions)!: owner-scoped Web UI chat on the new session model
7725718 fix(sources): make Test Connection real and fix Remove flow
59ac8dd fix(store): apply SQLite pragmas per-connection via DSN
0ee8a6a feat(ui): identity/RBAC admin management surface (Stage 5)
b7518c9 refactor(cli)!: remove zone/admin operator CLI; REST is sole RBAC writer
7af4326 feat(api): identity/RBAC admin REST surface (Stage 3)
c606ee5 feat(auth): provisioning hooks + disabled-at-mint enforcement (Stage 2)
bf6d1f9 feat(rbac): identity registry + transactional admin-mutation audit (Stage 1)
7747373 fix(ui): add required zones field to stale current-user test fixtures
5fcefc8 docs(decisions): D-0015 — context-management architecture decisions of record
b66f4aa feat(audit): write a context-overflow audit row for parity with the runaway ceiling
9ecee64 feat(ui): context-budget control on the LLM Settings page
fa5aa41 update docs
91cd63a fix(deps): patch Dependabot vulnerabilities
664b3f7 docs: fix README drift and split reference into /docs
e331d88 docs(decisions): D-0014 — close Stream G guard gap + operator-surface blockers
1620cd9 feat(chat): differentiated write-failure feedback (typed error codes)
636ce0b feat(ui): active-incident banner in the app shell
a6d7773 feat(ui): access-pending empty state for zero-zone users
76c2ed2 feat(api): extend /me with the caller's reachable zones
09202ec feat(cli): joe incident subcommand (status/declare/resolve/list)
9e1ece1 test(llmusage): skip-staged regression net for ChatStream/Embed recording
1debfc3 test(ui): route-level RequireAdmin gate test for /llm-settings
0469a54 test(api): structural gate+audit guards for /api/v1/llm/ admin surface (D-0013)
c25666b feat(llm): per-message ingestion truncation + typed context-overflow status
507d288 fix(audit): record admin RBAC mutations — close the admin-audit gap from D-0012 (D-0013)
3a039ec feat(llm): token-based context budget, model capabilities table, explicit output cap
326f32f fix(security): admin-gate the RBAC admin API (privilege escalation)
881554d fix(llm): keep cost recording + gating across runtime model swaps
41994a1 fix(webui): loud-degrade UI-less binary; pin embed-path and Mount contracts
f25ee26 feat(ui): stream agentic turns in web chat; remove non-agentic /api/v1/chat
a2d530a refactor: collapse joe-core into single joe binary
753ac45 refactor: delete REPL, reverse-RPC delegation, and local-tool tree
cfee948 fix(e2e): use valid-length dummy GEMINI_API_KEY so joe-core boots
d5133c0 fix(audit): make FailurePosture log the real outcome at fail-open sites
9af56f8 docs(security): add break-glass access operator how-to
d95e4b7 feat(joe-core): honor --config flag and JOE_CONFIG env, add sign-on e2e test
cb4da6b feat(auth): audit admin-bootstrap privilege escalation — H3 follow-up
c299b91 feat(auth): break-glass auth-login auditing — Stream H3
1acb07f fix(ui): serve OIDC-enabled signal on a public endpoint so the logged-out shell shows the OIDC button — Stream H2 follow-up
fe676c5 feat(ui): OIDC human login in the Web UI — Stream H2
621dac0 feat(webui): serve the Web UI same-origin from joe-core via go:embed — Stream H1.5
3d453f8 feat(ui): web UI authentication — dev-token login + logged-out shell (Stream H1)
8a1db1c feat(ui): admin-gated LLM Settings page — Stream G phase G6
5e4569d feat(llmsettings): surface effective enforced limit in settings GET — Stream G phase G5 addendum
53650d6 feat(api): admin-gated LLM instrumentation HTTP API — Stream G phase G5
79f17b5 feat(llmsettings): storage-backed limits + atomic settings mutations — Stream G phase G4
08171c2 feat(llmusage): pre-call cost-window gate with fail-open read — Stream G phase G3b
21c3ac4 feat(agentloop): session token ceiling backstop — Stream G phase G3a
9e94c77 feat(identity): fixed-width usage timestamp + typed terminal-error sentinels — Stream G phase G3-prep
33cf9c4 feat(llmusage): per-call LLM usage recorder — Stream G phase G2
88de3d5 feat(identity): LLM instrumentation schema + cost-currency config — Stream G phase G1
e18b122 feat(identity): dynamic admin capability evaluated at decision time — Phase H
3e3d99c feat(identity): shared §C captain gate on the agentloop — Phase G
8e73061 feat(identity): append-only audit + bug #3 fix — Phase F
d01eb7d feat(identity): remove loopback, accessor governs the loop — Phase E
adf8a84 feat(identity): named service-account keys — Phase D
c23af98 feat(identity): set-shaped IsAllowed + real ctx principal — Phase B
7a7d646 feat(identity): guarded accessor below the transport — Phase A
f173351 docs(readme): correct Quick Start + architecture for Phase 2 — B3
02b4cfb feat(config): auto-select LLM provider from available key — B2
d521582 docs(license): add Apache-2.0 LICENSE + NOTICE; replace README TBD — B1
4bb1227 Merge Phase 2: single agentic runtime into main
4f6f991 refactor(phase-2): relocate loop to internal/agentloop; record D-0003; mark Phase 2 complete — Change 7
432291a test(phase-2): end-to-end thin-client path + structural guards — Change 6
3f4b2af feat(phase-2): CLI becomes a thin streaming client — Change 5
c8fb70d feat(phase-2): local-tool callback path over the stream — Change 4
7eebaf2 feat(phase-2): SSE streaming task endpoint + client consumer — Change 3
1f740f7 feat(phase-2): model control-plane API + swappable LLM adapter — Change 2
e030dff docs(phase-2): implementation notes for single-agentic-runtime collapse
b11398d feat(phase-1): incremental-autonomy inert seams + R-OVR force-yield — Change 12
3c980ab feat(phase-1): hard-delete cascade tests + §5b-5 expunge guard — Change 11
aff30cc feat(phase-1): captain-session gate insertion in executor wrapper — Change 10
e816733 feat(phase-1): SessionMiddleware + §D5 durable executor wrapper — Change 9
cae2ddc feat(phase-1): captain-session gate primitive — Change 8
0b0e7d0 feat(phase-1): run lifecycle HTTP API — Change 7
7a7fb9d feat(phase-1): captain attach + transfer state machine — Change 6
b78e177 feat(phase-1): session/run durable state — Changes 1–5
f6c62ee docs: add phase 0 session model and reconciled plan of record
e1a4b59 docs: add refactor plan check point
d6f1e6b Update joe-dataflow.md
4407293 Improve documentation for .joe/ files
6b1f304 Merge pull request #6 from jaimegago/dependabot/go_modules/go_modules-4c23bf149f
2eb3cc4 chore(deps): bump github.com/slack-go/slack
d64c03d docs(readme): document skills system and bump golangci-lint to v2.12.2
cf62834 feat(skills): policy-driven quarantine + approval workflow (Phase 4)
eb7393d feat(skills): hot reload + reload endpoint + trusted-source mode (Phase 3)
44a24be chore(deps): patch 31 dependabot vulnerabilities
74f7367 ci: replace golangci-lint install script with official action
8c10aa3 feat(skills): add joe skills CLI for git-based install/list/remove/update
fc20108 feat(skills): implement Agent Skills consumer (Phase 1)
8b532ee add joe skills design doc
77350d3 Clarify Core Safety Principles and trust progression
6548052 Fix formatting inconsistencies in JOE_SECURITY.md
a2d21ad docs(CLAUDE.md): add Applicable Skills section and remove repo-level skill copies
24ac6c9 docs: fix stale references and add missing sections across all human docs
dd3fcda feat(prompts): add safety reasoning articulation to TaskSystem prompt
747a97f feat(config): support JOE_DATABASE_DSN env var to override database path
60c85d3 feat(api): make status endpoint version settable via build-time ldflags
090dac3 feat(api): log full task response text at INFO level for auditing
1b3ca9e docs: remove stale/duplicate docs, update milestones with Phase 12
ecc8ccd refactor(prompts): extract all LLM prompt strings into internal/prompts package
d3efdac fix(safety): surface full namespace-zone mapping for zone boundary reasoning
6559722 feat(safety): add explicit zone boundary articulation in refusal responses
20addc8 feat(safety): add deterministic namespace scope enforcement and secret redaction
d7db451 chore: untrack .claude/settings.local.json
386d9de feat(safety): add zone boundary enforcement to task executor
4ba75ed add .claude to gitignore
723c547 feat(api): add task execution endpoint with agentic loop over HTTP
2e3cecd fix: lint
232b686 feat(mcp): replace backend-specific tools with category-based tools (service+question, no source_id)
8b1a624 move to double binary
0117a09 update doc
2c32fe1 fix nginx test
950121f fix test
85006a8 test: fix helm
6d59b12 fix lint
502f8ac cicd: lint
e4e6bd0 test:mass coverage improvement
80a81fd readiness for adding postgres
4246c85 fix: db issues with joecore ha
f87ea41 go mod tidy
1329261 fix: remove CGO dep
42ba927 feat(front): general improvement using claude skill
0c65afe docs: add go backend, front dev skills
074470a fix: ui
7ca259d feat: web ui v1
fb2b962 docs: ui
0cd6a9b feat: phase 11
02134e9 add git ignore
cc4483b feat: phase 9
f9935ea fix: code quality
1367252 fix(test): flaky
862c282 feat: security RBAC
d7c258f fix: lint
4abc31e dev: move echo to test only
44f3220 feat(test): add unit + integration
a2ce69c docs: moving things around
3af8c2a docs update mcp server
166665b docs: update kiro study
4c2334c docs: security update
9b6b7f4 feat: phase 8
d3becc4 fix: minor leftover
b951bbf feat: phase 6.13 (artifacts repos)
397582d docs: phase 8 plan,lint
d70dacf docs: update milestones
92439a7 feat: phase 7 done
f979bfb docs: update CLAUDE instructions
58e8555 feat: finish phase 6
1a852df fix: disable md warnings
391c356 fix: lint
0e7c44f feat: 6.12
8b82527 feat: phase 6.11
2fb031a feat: 6.10
ca8e3c3 fix: change traces defaut output
84bb4a1 feat: phase 6.7
e6fa445 fix: lint, refactor some test to table driven
93fd72c feat: phase 6.7
2cb5545 fix: api bug
591db3d feat: phase 6.6
bd9f305 feat: phase 6.5
d697aee fix: lint
47b3703 fix: tests
2aa6eac fix: overall code quality
649389f test: improve unit to >80% all pkgs
be2f323 test: add unit coverage
15b7772 fix: go standards alignment
9715e65 fix: lint
bc6cafc fix: minor
332e4a1 fix: lint
52889e5 docs: history of collab with LLMs
945bdeb docs: add troubleshooting tools
c7b8f30 docs: update add more adapters
039e589 feat: phase 6.2
3dd232f feat: phase 6.1
b3c5098 docs: update
597099b docs: update milestones, delete completed
884b711 fix: minor sec
372000f feat(sec): step 5.5 done
0da8f1c feat(sec): 5.5 step 4
23bc98e feat(sec): add 5.5 step 3
6253764 feat(sec): lint
c63171d feat(sec): phase 5.2
3e99864 feat(sec): phase 5.2 of security in layers
e91046b feat(sec): add security by layers
a0861b5 fix: lint, test
80b4d36 feat: phase 5 done
3ee65ad feat: clarifications system
698d5db feat: phase 2
fc9e272 docs: update
ebb1ba8 feat: phase 5 finish in progress
dd39167 test: improve
c724d3c test: improve cmd
9faee51 test: improve cmd
d217304 fix: harness e2e
e6ebdcf fix: improve error handling
c269148 fix: improve http api
5ac8058 fix: tests
7152e0b fix: lint, tests
e0bf18b feat(obs): add telemetry
aa97b63 fix: minor
fa1289d fix: lint
cccd3e9 refactor: improve code quality
09faded fix: aws constants
dd0e7b7 fix: improve AWS adapters code quality
a522ab0 feat: add aws adapters
154cf66 feat: phase 5 core agent
38803ac docs: update LLM instructions
2a94eb0 test: fix units
b1f0b7a fix: phase 4 "why is pod foo broken" validated
721eada feat: add git adapter
51d0e74 fix: graph nodeid query
ec90b60 docs: update, phase 3 done
71240a1 fix: ci again
2ec9ab1 ci: fix lint
f07b082 ci: fix lint
15d315c test: fix github ci lint
3763b5f feat: add k8s adapter
1f7be62 feat: add graph in sql
79777df feat: add graph store
7f7b423 test: update doc
9f806ea test: update instrumentation
f9827ea fix: lint
00cf795 test: add comprehensive testing (e2e, integration, observability)
43de4fe feat: add sql store
b96d755 fix: based on claude code quality analysis
0a255e7 chore: linter
ee4f7b2 feat: add joe client tools
26f2bca fix: add more logging
94c707a feat: add /model command
e9c24e9 refactor: joe is now 2 components
4860beb docs: update core docs, 2 components
97cbf25 fix: echo tool
d023b56 feat: poc echo tool
c6c393c chore: remove binary
06313dc feat: add support for gemini
f09e093 feat(first): let's go Joe!
You can’t perform that action at this time.