Skip to content

v0.1.0

Choose a tag to compare

@github-actions github-actions released this 19 Jul 18:08

Changelog

  • fa8e3ba release-pipeline-02: sweep distribution posture to the release-exists state for the v0.1.0 tag cut (D-0122)
  • 5eb62a3 docs-version-stamp-02: record seed-time doc stamping as D-0121 and give release-pipeline-02 its tag-time re-seed step
  • 00344fa feature-clips: register the standing clip claims and close the item
  • 4931e40 releasing-runbook: cross-reference operator runbook from release-pipeline backlog
  • c6ef5d4 encryption-key-path: boot fails closed on a key/database mismatch, and the key path becomes configurable alongside the DSN (D-0120)
  • 434663f promote-adapter-activation: connect and register the live adapter on promote, closing the "adapter not found" gap (D-0119)
  • 07164c8 fix(logs): stop quoting PM-spine section markers in runtime strings
  • 0325a57 build: close the build-tag blind spot in the local gates
  • cf5258f fix(test): drop clarifications subtest orphaned by D-0118
  • 96dc2b7 chore: tidy go.mod and mark unused test helper param
  • f25f044 fix(lint): drop ineffectual cfg initializer in db_test seedDatabase
  • 804c47a onboarding-feature-removal: delete the onboarding and clarifications subsystems wholesale, prune not park (D-0118)
  • ddeea5d component-delete-graph-orphans-02: propagate D-0117 delete-cascade wording into the published growth-posture page
  • c7c391a component-delete-graph-orphans: cascade graph state on component delete, sweep pre-existing orphans, remove the Refresh buttons (D-0117)
  • a846dde observe-k8s-resolver: bind services to clusters by component type, fixing a joe_k8s resolver that never worked (D-0116)
  • f624ba5 db-persistence-backup-02: add joe db restore, and correct the manual restore procedure that silently restores the wrong database (D-0115)
  • 7cc719f db-persistence-backup: add joe db backup, document the persistence story, and fix the Configuration tilde trap (D-0114)
  • 95c7eb4 lint-embed-field-fix: drop the vestigial embedErr field the D-0113 prune left in the llmusage test fake
  • e5e3d41 mcp-tool-count-fix: correct the MCP roster count to seven on the public guide
  • 291e7be knowledge-store-prune: delete the knowledge store, its doc-proposals arm, and embeddings from the tree (D-0113)
  • 0e8cc31 knowledge-graph-guide-fixes: correct published link depth across guides and two concepts pages, drop the retired-tier meta-commentary, and file the knowledge-store prune (D-0112)
  • f57cb63 trim-unsupported-component-types: extend the D-0058 trim to the twelve types that fail the documentable gate, and delete the now-false "Not yet supported" docs paragraph (D-0111)
  • 5b7aab9 iac-graph-ingestion: pin the graph as deterministic-only, park the three onboarding-era graph-write tools, and correct the stale Confidence docs (D-0110)
  • 65e0842 knowledge-store-maturation: flip the tier-less create default to derived, park save_knowledge_entry, and correct the public copy to shipped truth (D-0109)
  • 0a7bd9e rbac-engine-split-02: triage read-posture-visibility to Priority: next
  • 58588df demo-bugfix-pins: pin the graph-ui-declutter fix, exempt two non-behavior fixes, and file the demo-runbook and dev-skill items
  • 15a3dbb rbac-engine-split: build one governance-wired RBAC engine at the composition root and inject it into api.New; delete EnforcementMiddleware
  • b941269 sessions-admin-delete-affordance: file backlog item for admin delete discoverability gap
  • a4fdac7 ui-source-strings: rename remaining legacy "source" UI strings to component
  • 19bd44a chat-stop-resend: add stop control, cancelled-turn marker, and resend
  • 6b770ba graph-ui-declutter: remove dead per-node gear glyph and fictional node-type legend
  • a4ade60 fix: use Joe favicon in web UI instead of default Vite icon
  • 2bcd17c fix-duplicate-declare-incident-02: append D-0105 recording the declare-affordance claim registry decision
  • 732e11d fix-duplicate-declare-incident: one declare affordance on screen at a time
  • ae21572 observation-banner-docs-link: point at the deep-linked observation-mode docs page
  • a4914ac posture-prompt-conflation-02: close the per-tool read-only wording leg (D-0104)
  • 10fd026 silent-tool-intent-dead-end: probe a tool-call-free response for an unfulfilled tool intent (D-0103)
  • bf3f506 k8s-get-thrash: reject a by-name k8s_get with an empty namespace before it reaches the API
  • 3c1be9f posture-prompt-conflation: reword the observation posture to draw the read/mutate boundary explicitly
  • aa925ef feature-clips: make the demo-world orders workload camera-neutral
  • 3a38bff web-ui-header-lockup: replace "Joe" wordmark with the Joe lockup in the sidebar header
  • 7caf390 loop-budget-exhaustion: forced synthesis on iteration-cap exhaustion instead of hard-fail
  • 9ca5a68 claude-instructions-report-format: wrap CC session reports in a single fenced code block for one-click copy
  • 28df1a5 sessions-new-chat-blank: New chat button lands on a blank chat, not the last session
  • c1f82f0 backlog-priority-field: add optional Priority/Blocked-by lines and INDEX Priority column
  • f8002ac claude-instructions-report-format: instruct CC to write session reports as plain undecorated prose for the chat model
  • 3fa0610 crd-gvr-resolution: fix CRD GVR spec format so k8s CRD discovery resolves (D-0094)
  • 40ffe1d refresher-rbac-degradation: k8s refresher degrades per-resource-type on forbidden (D-0093)
  • 14f430b source-log-sweep: rename stale "source" wording to "component" (D-0021), fix double-wrapped k8s list-secrets error
  • 539a917 feature-clips: two-phase orders workload for ~5-min symptoms without CrashLoopBackOff
  • ebbedbb releasing-runbook: add operator release runbook at docs/RELEASING.md
  • 16de344 release-pipeline-01: flip goreleaser to publish-on-tag with a structural UI-staging guarantee
  • ca5a62b history-scrub-02: record the content-side history rewrite and neutralize residual copy
  • 1c91b3b history-scrub: record executed git-history scrub (former-employer email rewrite + binary-blob purge)
  • 8832e33 site-claims-refresh: add Configuration and Operations register sections and make the D-0077 obligation bidirectional
  • a26f49d Merge pull request #18 from jaimegago/dependabot/go_modules/go_modules-a3c8a40308
  • 745d87a db-retention-story: document the session-sweeper retention and unbounded-growth posture for operators
  • e686b4f contributing-guide: add repo-root CONTRIBUTING.md grounded in the live tree
  • 19a5ab3 postgres-backend-truth: walk back the PostgreSQL-backend overclaim in public and reference docs
  • aec5ce9 Merge remote-tracking branch 'origin/main' into db-crypto-bump
  • 82a132c update-model-rec-convention: switch project-instructions model recommendation from tiers to model-name + effort level
  • f73a840 fix-lint-parked-routes: silence unused linter on parked D-0081 route registrars
  • 301562b readme-hero: add themed logo lockup and hero tagline to root README
  • 3ea9544 readme-rewrite: rewrite root README from scratch against the live tree
  • 49aaca8 create-echo-readmodel: project the POST /components 201 echo through componentView
  • 75f67ca llm-observed-health-surface: add backlog item for LLM observed-health surface and index it
  • dac098b datastore-uri-credential-provider: reclassify kafka as discrete-field SASL and record parse-but-never-apply gap
  • bfbda39 build(deps): bump golang.org/x/crypto
  • 7ed44a8 Merge pull request #17 from jaimegago/dependabot/go_modules/go_modules-57bd245098
  • e6172bb observation-wording-triage: reframe the mutation-surface paragraph as registered-but-floor-denied, and record D-0082
  • 8e23544 discovery-clarifications-pipeline: park onboarding, clarifications, and manual-refresh HTTP routes for launch
  • 5e55360 graph-node-taxonomy: correct the graph node model to components-as-anchors plus discovered resources, and relocate the curated/derived authority to the knowledge store
  • e1cc973 incident-regime-wording: replace rhetorical meta-commentary in the deferred section with plain scope statement
  • 40b50cb docs-triage: cite D-0022 for denial precedence in code comments; state observation as the boot default in docs/reference
  • 950cf32 project-instructions: add per-prompt model-recommendation directive for emitted Claude Code prompts
  • 5e44d31 slack-client-stance: record D-0079 classifying the Slack bot as a first-party REST API client, not a fourth input surface
  • ad2889f machine-callers-phrasing: distinguish shipped machine clients from example external callers
  • 83bac0a write-floor-page-copy: reword the observation/write-floor Concepts page to classify tools by capability and drop forthcoming-full-mode phrasing
  • 02eb330 components-page-restructure: open the Components index with a definitional intro and move the per-type tables to a connectable-systems child page
  • c48b96c safety-page-03: create the joeagent.dev site-claims register and wire the drift-detection obligation
  • 7034244 feature-clips: land the demo-world public example (examples/demo-world/)
  • 12af87d safety-page-05: record the missing no-MCP-client guard test as an open backlog item
  • f399f86 safety-page-06: correct the MCP server-direction safety claim
  • 0d5eeeb skills-governance-hardening: admin-gate the mutating skills HTTP endpoints
  • deef666 safety-page-04: record skills-governance hardening as an open backlog item
  • ad44075 safety-page-01: add the incident-command (ICS) lineage to the incident-regime concept page
  • dd0eb94 console-brand-tokens: add deferred backlog item for the operator console brand token layer
  • 93c2b7e orphaned-tool-registration-cleanup: delete two-binary-era local-tool residue from the safety layer
  • 1cf9e4b observation-default-01: correct docs/public boot-posture and full-mode copy to D-0073 truth
  • 2304341 observation-default: invert boot write-floor default to observation; refuse JOE_MODE=full
  • 687f7ec read-posture-latch: posture-gate the Policies admin UI; correct the hide-zoned-era-UI scope
  • bd44912 docs-public-refit-02: add Hugo aliases for the two published URLs killed by the D-0070 renames (D-0071)
  • 133cc1a fix: resolve repo audit findings across backend, frontend, and docs
  • 8e55ce1 docs-public-refit: rework capabilities into the action-model page, rename Integrations→Components, retitle the components concept page, and fix launch copy
  • deaa249 build(deps): bump golang.org/x/net
  • 0b66360 sysinfo-tool-removal: delete the system_info shared tool; shared tools are outward network diagnostics only
  • 7476354 mcp-client-rejection: expand the guarantee section to cite OASIS and Joe's open-source verifiability on the public Joe-and-MCP page
  • ab0ae11 mcp-client-rejection: revise the two MCP-guarantee sections on the public Joe-and-MCP page to cover read-only zones alongside observation mode
  • d7581fe mcp-client-rejection: record the by-construction rejection of Joe as an MCP client (D-0067)
  • a72d3a1 capability-map: add a Capabilities Concepts page mapping Joe's read-only capability surface; relocate the web_search narrative to Concepts; correct the observation-mode default claims
  • 71b9c4d agent-identity-doc-04: retire and delete the kubeconfig-exec credential provider (slice D)
  • 0fc7b28 web-search-tool: add a Go-native web_search shared Read tool behind a SearchProvider abstraction
  • 0233f84 agent-identity-doc-03: add Entra-exchange as the second Kubernetes auth method (transport-agnostic, minted bearer token)
  • b4c11e4 agent-identity-doc-02: rewrite Kubernetes transport to a hand-built rest.Config with static-bearer auth (no kubeconfig ingestion)
  • 71bed36 agent-identity-doc-01: enforce per-component uniqueness of static credential env-var names
  • 7f586dc agent-identity-doc: capture Joe's agent-identity and authentication stance as design-of-record in a held, non-published draft
  • 5a10cd6 quickstart-out-of-cluster-kubeconfig: make the host kubeconfig an explicit, assumed prerequisite
  • cb8adb5 quickstart-register-before-asking: connect a component before the one question, and surface the component-credential prerequisite
  • a5facd9 component-registration-guide: add UI-driven Kubernetes register-and-promote how-to; Quickstart includes one component
  • 9cddbb2 trim-deadonarrival-component-types: remove six non-functional types from the registrable set at the single authoritative seam
  • a71c5d5 register-component-config-default: persist config-less registrations by normalizing absent config to "{}" at the shared seam
  • a8dac00 healthz-endpoint-surface: file standards-anchored, decision-ready backlog item for an unauthenticated health-probe surface
  • b898ddf unauth-health-surface: investigate unauthenticated deployment-grade health surface
  • c208394 docs-public-establishment-pass-08: close out the thread and reconcile /status auth tier
  • d5d0ee4 docs-public-establishment-pass-07: fill API Reference (reference) from live route registration
  • 6f33d71 docs-public-establishment-pass-06: fill Operations (how-to) with break-glass folded in
  • 8921fd3 docs-public-establishment-pass-05: fill Guides (how-to) — one page per feature area
  • f95db28 docs-public-establishment-pass-04: route Integrations by runtime vs boot-config activation
  • 49b6a36 docs-public-establishment-pass-03: fill Configuration (reference) and Integrations (how-to)
  • 0afac35 revert-return-path: remove return-path routing conventions
  • 7251432 docs-public-establishment-pass-02: fill Install and Build (how-to) and Quickstart (tutorial)
  • c7efe9e return-path-conventions: add slug-echo and spot-code return-path routing conventions
  • 44bed99 docs-public-establishment-pass-01: stand up docs/public surface; write Overview and Concepts
  • 808f601 llm-instrumentation-rewire: remove dead LLMMiddleware metrics path, wire NewInstrumentedAdapter into BuildLLMChain
  • 194c508 docs-reference-audit-05: resolve the final 13 reference-doc misalignments and close the campaign
  • 0e57b2e public-docs-feature-inventory: verified inventory of what Joe actually ships
  • b1c2494 docs-reference-audit-04: retire dated accessor-promotion-state-axis investigation, absorb survivors into security-in-layers
  • 1b21fd9 openai-compat-adapter-01: gitignore .env so local API keys are never committed
  • 83de41e docs-reference-audit-03: retire two direct-HTTP-mutation investigation docs, absorb survivors into security-in-layers
  • 64059c7 openai-compat-adapter-01: add key-gated live integration test; record live verification
  • 2cff829 docs-reference-audit-02: rewrite security-in-layers.md to the live tool surface
  • e5bbc0b docs-reference-audit-01: rewrite operational-modes-ui-status.md to the live write-floor model
  • 68c99f8 openai-compat-adapter: add generic OpenAI-compatible LLM adapter
  • ed53c32 docs-reference-audit: audit docs/reference against the live tree; file 67 misalignments
  • f0eb570 Revise Joe architecture documentation
  • c074c31 docs-tree-restructure: reorganize docs into project/reference/backlog-investigations; archive process-exhaust externally
  • 1120082 case-study-kiro-redo: queue Kiro case-study redo and preserve old content as a stale snapshot
  • f8d7a52 docs-reconcile-security-consolidation: delete JOE_SECURITY.md + JOE_RBAC_IMPLEMENTATION.md, consolidate on security-in-layers.md
  • 6b6acbf docs-reconcile-testing-strategy: delete testing-strategy.md, redirect refs to as-built test/ harness
  • 9abf23b docs-reconcile-narrative-ops-02: reconcile web-ui.md to the live tree
  • 3d33335 docs-reconcile-narrative-ops-01: reconcile operations.md to the live tree
  • 9fefa9e docs-reconcile-narrative-light: six surgical single-claim corrections across narrative docs
  • 7ed72ac docs-reconcile-historical-annotations: add as-of/superseded banners to five KEEP docs
  • 5efa480 docs-reconcile-artifact-cleanup: untrack .vscode/settings.json and extend .gitignore artifact set
  • 9573ea2 docs-reconcile-sweep: read-only audit of docs/ with a committed reconciliation plan
  • d8772a3 tool-class-break-tests: backlog the two unpinned tool action-class break-tests
  • a8f7fee arch-doc-staleness: rewrite joe-architecture.md and security-in-layers.md against the live tree
  • 3f96f32 post-joefile-cleanup-02: align security/architecture docs to live register_component + D-0021 + .joe removal
  • f4f2a97 post-joefile-cleanup: drop dead discovery stub, fix register_source doc drift, derive migration step counts
  • 21d9925 read-posture-latch-02: separate the agent:core read surface from the read posture
  • 10530a1 joefile-removal: delete the .joe/ repository-ingestion path
  • f62c6f6 read-posture-latch: persisted install-wide read posture (team_flat default, zoned full-mode)
  • 6d94b18 rbac-v2: seed the Full RBAC v2 backlog item (role indirection, group subjects, granular permissions)
  • f973e26 credential-reject-single-source: archive resolved single-sourcing residual
  • e11da53 admin-nav-consolidation-01: move Credentials under the Admin subgroup
  • e2ac1f9 admin-nav-consolidation: record D-0039 (consolidated admin-surface model)
  • 41d7814 admin-nav-consolidation: inline Sessions governance for admins
  • c43be16 admin-nav-consolidation: inline Components admin affordances
  • 8ea43c9 admin-nav-consolidation: single expandable Admin nav subgroup
  • 06958f0 admin-nav-consolidation: split Admin tab-host into per-surface routes
  • 69ae416 launch-ui-polish: remove stray section-reference fragment from retention copy
  • bd5a617 launch-ui-polish: persistent ADMIN badge in the sidebar identity area
  • d6d782a launch-ui-polish: make chat the default landing surface, retire fabricated-data dashboard
  • b57dbdf chat-input-visibility: pin chat input below observation banner
  • 58ec87b context-usage-display: chat token badge as context-window utilization (input X of window Y)
  • ab40685 build-version-instrumentation: single buildinfo source, /version endpoint, joe_build_info gauge, goreleaser scaffold
  • d3973da pm-convention-capture: specify session-tracking convention in docs/pm-convention.md, version-control claude.ai project instructions, log D-0035
  • 9f43dde backlog-index-init: create docs/backlog/INDEX.md and done/ archive directory
  • f91f220 backlog-triage: diagnose done/obsolete/open status of pre-existing backlog files
  • a1db2d9 jpk-retirement: rehome unique JPK items to spines and retire the file
  • 26adc7b claude-md-drift-correction: verify provider set + structural edge-type/migration counts, add session-subsystem invariant, log D-0032
  • a53cb07 edge-type-count-arbitration: resolve 19-vs-20 edge-type count against source
  • f9c3430 jpk-migration-triage: read-only triage of JOE_PROJECT_KNOWLEDGE.md before retirement
  • 0c41292 pm-spine-wiring: wire decision-log + backlog pointers and adopt session-tracking convention
  • 1b8e222 docs(sessions): P2 client-side interim note + P3/content-search backlog
  • 563bad2 feat(ui): shared filter+sort controls on both session views
  • d793bd0 feat(ui): client-side session filter+sort pure functions
  • 86a5b89 feat(ui): two-view sessions split — Conversations vs Incidents
  • ec61fbb feat(ui): pure groupSessions transform for the sessions two-view split
  • 02804dd feat(ui): decode incident_involved on the session list schema
  • 142b795 feat(api): surface incident-involved flag + linked master title on the session list
  • 0522f0e docs(sessions): design doc for the two-view incidents/conversations split
  • e9ca9b1 fix(ui): pin the incident-mode banner so it survives transcript scroll
  • 477e8a6 fix(ui): gate chat incident chrome by session role × regime, not regime alone
  • 186086a feat(api): surface linked/active incident master title to the client
  • 1b52e7f feat(ui): pure incident-affordance function from session role × regime
  • 141b736 docs(comments): cite migration 025 for incident CHECK constraints
  • e8468fe docs(sessions): correct false 'B001 inventory reports landed' claim
  • f42fdaf docs(backlog): defer cross-incident relink of former incident master
  • 5fcf660 test(ui): add required type field to Session fixtures
  • adb296f docs: require verifying UI features in the running app
  • 66c0607 fix(incident): mark incident session in UI and add resolve flow
  • 91c4595 fix(ui): don't strand the Chat tab on a read-only foreign session
  • acd75a6 fix(ui): refetch session history on mount so mid-stream navigation doesn't hide persisted turns
  • d9a2a9e feat(sessions): B008 session UI surfaces + §12.5 reword (§12.10)
  • a9e3354 feat(sessions): B007c session archive provider + transitions + wiring (§12.6)
  • b3349c9 Merge pull request #16 from jaimegago/worktree-dependabot-fixes
  • 352937e fix(ui): bump vite to 8.0.16 and undici to 7.28.0 (dependabot)
  • 2013e07 feat(sessions): B007b retention sweeper + login-flow drain (§12.5)
  • e1e88e9 feat(sessions): B007a session trash/retention lifecycle store (§12.5)
  • 7690cce feat(sessions): B006 admin session governance namespace (§12.8)
  • d40e7ed feat(sessions): B005 per-user sessions API on the seam (§12.8)
  • 2ee64bf feat(sessions): B004 incident declaration promote-in-place (§12.3)
  • 28bcc47 feat(sessions): B003 dedicated session authorization seam (§12.7)
  • 75bc545 docs(sessions): add §12 clean-room session redesign (B001)
  • 4afacde docs(knowledge): correct learn-from-sessions status to dormant/orphaned
  • 83e3a29 fix(adapters): redact credentials from MongoDB URIs in error/status messages
  • 8cbd941 feat(store): B002 session storage-schema rewrite (§12.4)
  • a6c85ed docs(backlog): record learn-from-sessions fate as deferred future feature
  • 9dbe674 test(e2e): configure service account so harness boots under identity guard
  • 8889b09 feat(ui): Skills admin tab — expose loaded skills, source, and quarantine controls
  • d651a1a feat(ui): operator toggle for per-type autonomous reads (A002)
  • 6fa0107 feat(ui,api,credential): component promotion/arm surface + locator-safe read model (A002)
  • 78e7a62 feat(ui,api): operator-facing component registration form (A002)
  • 3a9c029 docs(backlog): record registry-auth-pair credential-provider gap (deferred from A003)
  • ba23db5 fix(credential): back artifactory out of the W2 static-token wired set
  • b1412be feat(credential): extend wired-type registry to the A003-W2 static-token set
  • 25c8cd1 feat(gitops,registry,security): resolve adapter tokens through credential seam (A003-W2)
  • 14c581b feat(alerting): resolve adapter tokens through credential seam (A003-W2)
  • 0ba9a51 feat(observability): resolve adapter tokens through credential seam (A003-W2)
  • 504baa7 feat(components): add the governed component promotion endpoint (A003 Stream P)
  • 580315c feat(credential): export credential-bearing field set; single-source componentgov denylist (A003 commit-one)
  • f65879f feat(coreagent): govern register_component as credential-less + audited, still ActionRead (A003-G)
  • 86081d1 feat(components): govern component DELETE with same-tx audit and full-row clear (A003-G)
  • 74ad4a2 feat(components): govern component CREATE as a credential-less promotion boundary (A003-G)
  • a72b850 feat(credential): declare wired-type registry for the provider seam (A003-W1)
  • f99d332 feat(gitlab): resolve token through credential-provider seam at Connect (A003-W1)
  • fed76d0 docs(backlog): record redis in datastore credential entry as discrete-field carve-out
  • bc05f32 docs(backlog): record deferred credential-provider gaps (A003 promotion boundary)
  • 6b03444 feat(coreagent): floor autonomous refresh reads under agent:core RBAC (A001-COREGOV)
  • e748055 docs(decisions): record D-0027 refuse-to-start on absent identity (JOE-IDBOOT)
  • b5a030a docs(investigations): add read-only identity/RBAC investigation notes
  • 19113a9 feat(boot): refuse to start without a usable identity configuration (JOE-IDBOOT)
  • ac55772 refactor(api): build accessor policy engine via shared RBACEnabled predicate
  • da5a412 feat(config): add shared RBACEnabled engine-enable predicate (JOE-IDBOOT)
  • 343f32a feat(ui): credential authz/connectivity status surface (D-0026 unit 3)
  • 5a15ace feat(credential): per-component credential status API (D-0026 unit 3)
  • 2e2982a docs(backlog): record tilde-expansion helper unification target (D-0026)
  • 7f1c979 docs(credential): record GitHub dual-source token precedence (D-0026)
  • a0dadeb test(credential): guard duplicated tilde-expansion helpers against divergence
  • 33cf46f fix(credential): expand ~ in kubeconfig-exec Probe path (D-0026 unit-1 fix)
  • c22f768 feat(credential): wire credential provider into GitHub and k8s Connect (D-0026 unit 2)
  • adaf531 feat(credential): add credential-provider package (D-0026 unit 1)
  • 42927fe add investigation docs
  • d62ab05 docs(backlog): record azure Connect skeleton gap (deferred, D-0026)
  • bddb8ff docs(decisions): add D-0026 credential provider abstraction ADR
  • 18d0f85 refactor(api): remove vestigial direct-HTTP managed-system routes; move auth/RBAC assertions onto the accessor seam
  • 81be86b Revise security findings punchlist for route deletions
  • f678b60 Add security findings and cleanup punch-list
  • 120b5fe Fix formatting issue in security architecture document
  • 82a6c81 Document credential resolution in security architecture
  • 2db1a3e docs: drop stale review-agent mentions from llmusage test comments
  • c987182 refactor(rbac): complete source→component rename in rbac + admin handlers
  • dbb9b38 refactor: remove orphaned two-binary-era review-agent subsystem
  • 93f95de fix(sessionmodel): make captain transfer swap atomic in one tx (D-0025)
  • 7bf0bc2 fix(sessionmodel): detach active captain on incident resolve (D-0024)
  • 1a21d4c Document incident regime and captain gate in architecture
  • 4062f5f Add security architecture direction document
  • 4a67b0f refactor: rename "source" → "component" entity (D-0021)
  • be61824 fix(ui): stop cold-load principal purge from stranding app-shell banner queries
  • 445f84a feat(prompts): add write-floor posture line to task system prompt
  • 3ba60f8 feat(ui): add observation-mode banner bound to GET /api/v1/mutate-status
  • fd2a5c8 refactor(api): rename posture endpoint to mutate-status with corrected contract
  • 75e23bc feat(api): add read-only write-posture endpoint (tri-state)
  • 4971b43 docs(backlog): record deferred posture-endpoint write-grants signal (full-mode only)
  • f6de84b docs(backlog): record deferred denial-feedback pop-up UI item
  • 27e6b8a docs(backlog): record full-capabilities-mode RBAC track (fail-closed empty RBAC + agent:core principal)
  • 3af687d docs(claude): refresh safety invariants — write floor, denial precedence, DB-backed panic state
  • e797f74 fix(safety): wire write floor into user-task executor + captaingate (D-0022)
  • 7f10972 feat(safety): enforce denial precedence floor > incident > RBAC by check order (D-0022)
  • bb37bfd refactor(safety): consolidate panic state to the DB row; delete panic.state file (D-0018)
  • 6208985 docs(decisions): record D-0021 source→component rename; add adapter-dispatch consolidation backlog
  • c8e0cdf feat(safety): boot-resolved, runtime-immutable write floor (D-0018)
  • bee601c docs(decisions): correct run_command characterization in D-0020 durability note
  • c1dc99f refactor(durability): decouple crash-resume from action class — opt-in NeedsDurability per tool (D-0020 follow-up)
  • 360fdff fix(auth): scope web UI cache to identity; dev insecure_cookies flag
  • 0ce4825 feat(chat): org-wide read model for sessions; fix restore + auto-title
  • e530fc8 docs(decisions): D-0020 follow-up — note persisted three-valued tier as deferred cleanup debt
  • 6ae0133 refactor(safety): collapse three-tier action classification to binary Read/Mutate (D-0020, refines D-0018/D-0019)
  • 7e0b393 fix(safety): reclassify tool tiers by the managed-system write definition (D-0018/D-0019)
  • e4a1d0e docs(decisions): D-0019 — Joe's trust model (two postures, graduated capability, fail-closed-empty-RBAC); design decision, implementation pending, companion to D-0018
  • b528170 docs(decisions): D-0018 — read-only write floor as boot-resolved, runtime-immutable security boundary (design decision, implementation pending)
  • 7284424 fix(chat): keep New Session button available in read-only sessions
  • 076e9bd fix(captain): bind transfer confirm/cancel to the handshake parties
  • 589c81b fix(chat): stop session-recovery from resetting live chats to "New chat"
  • 3b27fe3 feat(ui): safe-mode banner and typed denial message
  • fbe9a77 feat(safety): typed safe-mode tool denial with stable error_code
  • 67478ee fix(chat): restore last-viewed session when returning to /chat
  • a1e808f fix(chat): give auto-title call enough tokens for reasoning models
  • 8a356d3 feat(chat): inline session title editing in the chat header
  • 5f9807d feat(sessions): list public sessions shared by other users
  • 6c5d742 docs(claude): drop Co-Authored-By trailer from commits
  • 79e6efa feat(chat): show session title as page header, claude.ai-style
  • 017b334 fix(chat): de-duplicate terminal answer echo in assistant turn
  • 1158972 feat(sessions): chat session incident linkage (Phase 4)
  • c0fb2be docs: retire internal launch audits; record D-0016; repoint comment citations
  • b82f903 feat(sessions): chat session sharing (private/public)
  • 7753556 refactor(llm): remove dead ChatStream streaming interface
  • 6814284 feat(sessions): browse tab + auto-titles (chat sessions Phase 2)
  • 146c240 refactor: unify background-loop shutdown on context cancellation
  • 67de84f refactor(netcheck): drop redundant result channel in port fan-out
  • 86ae073 refactor(coreagent): remove dead Agent.stopCh channel
  • 4ee8b4b hide graph page from ui
  • 52ffa01 test(llmusage): make cost-gate window tests time-of-day independent
  • e150743 feat(sessions)!: owner-scoped Web UI chat on the new session model
  • 7725718 fix(sources): make Test Connection real and fix Remove flow
  • 59ac8dd fix(store): apply SQLite pragmas per-connection via DSN
  • 0ee8a6a feat(ui): identity/RBAC admin management surface (Stage 5)
  • b7518c9 refactor(cli)!: remove zone/admin operator CLI; REST is sole RBAC writer
  • 7af4326 feat(api): identity/RBAC admin REST surface (Stage 3)
  • c606ee5 feat(auth): provisioning hooks + disabled-at-mint enforcement (Stage 2)
  • bf6d1f9 feat(rbac): identity registry + transactional admin-mutation audit (Stage 1)
  • 7747373 fix(ui): add required zones field to stale current-user test fixtures
  • 5fcefc8 docs(decisions): D-0015 — context-management architecture decisions of record
  • b66f4aa feat(audit): write a context-overflow audit row for parity with the runaway ceiling
  • 9ecee64 feat(ui): context-budget control on the LLM Settings page
  • fa5aa41 update docs
  • 91cd63a fix(deps): patch Dependabot vulnerabilities
  • 664b3f7 docs: fix README drift and split reference into /docs
  • e331d88 docs(decisions): D-0014 — close Stream G guard gap + operator-surface blockers
  • 1620cd9 feat(chat): differentiated write-failure feedback (typed error codes)
  • 636ce0b feat(ui): active-incident banner in the app shell
  • a6d7773 feat(ui): access-pending empty state for zero-zone users
  • 76c2ed2 feat(api): extend /me with the caller's reachable zones
  • 09202ec feat(cli): joe incident subcommand (status/declare/resolve/list)
  • 9e1ece1 test(llmusage): skip-staged regression net for ChatStream/Embed recording
  • 1debfc3 test(ui): route-level RequireAdmin gate test for /llm-settings
  • 0469a54 test(api): structural gate+audit guards for /api/v1/llm/ admin surface (D-0013)
  • c25666b feat(llm): per-message ingestion truncation + typed context-overflow status
  • 507d288 fix(audit): record admin RBAC mutations — close the admin-audit gap from D-0012 (D-0013)
  • 3a039ec feat(llm): token-based context budget, model capabilities table, explicit output cap
  • 326f32f fix(security): admin-gate the RBAC admin API (privilege escalation)
  • 881554d fix(llm): keep cost recording + gating across runtime model swaps
  • 41994a1 fix(webui): loud-degrade UI-less binary; pin embed-path and Mount contracts
  • f25ee26 feat(ui): stream agentic turns in web chat; remove non-agentic /api/v1/chat
  • a2d530a refactor: collapse joe-core into single joe binary
  • 753ac45 refactor: delete REPL, reverse-RPC delegation, and local-tool tree
  • cfee948 fix(e2e): use valid-length dummy GEMINI_API_KEY so joe-core boots
  • d5133c0 fix(audit): make FailurePosture log the real outcome at fail-open sites
  • 9af56f8 docs(security): add break-glass access operator how-to
  • d95e4b7 feat(joe-core): honor --config flag and JOE_CONFIG env, add sign-on e2e test
  • cb4da6b feat(auth): audit admin-bootstrap privilege escalation — H3 follow-up
  • c299b91 feat(auth): break-glass auth-login auditing — Stream H3
  • 1acb07f fix(ui): serve OIDC-enabled signal on a public endpoint so the logged-out shell shows the OIDC button — Stream H2 follow-up
  • fe676c5 feat(ui): OIDC human login in the Web UI — Stream H2
  • 621dac0 feat(webui): serve the Web UI same-origin from joe-core via go:embed — Stream H1.5
  • 3d453f8 feat(ui): web UI authentication — dev-token login + logged-out shell (Stream H1)
  • 8a1db1c feat(ui): admin-gated LLM Settings page — Stream G phase G6
  • 5e4569d feat(llmsettings): surface effective enforced limit in settings GET — Stream G phase G5 addendum
  • 53650d6 feat(api): admin-gated LLM instrumentation HTTP API — Stream G phase G5
  • 79f17b5 feat(llmsettings): storage-backed limits + atomic settings mutations — Stream G phase G4
  • 08171c2 feat(llmusage): pre-call cost-window gate with fail-open read — Stream G phase G3b
  • 21c3ac4 feat(agentloop): session token ceiling backstop — Stream G phase G3a
  • 9e94c77 feat(identity): fixed-width usage timestamp + typed terminal-error sentinels — Stream G phase G3-prep
  • 33cf9c4 feat(llmusage): per-call LLM usage recorder — Stream G phase G2
  • 88de3d5 feat(identity): LLM instrumentation schema + cost-currency config — Stream G phase G1
  • e18b122 feat(identity): dynamic admin capability evaluated at decision time — Phase H
  • 3e3d99c feat(identity): shared §C captain gate on the agentloop — Phase G
  • 8e73061 feat(identity): append-only audit + bug #3 fix — Phase F
  • d01eb7d feat(identity): remove loopback, accessor governs the loop — Phase E
  • adf8a84 feat(identity): named service-account keys — Phase D
  • c23af98 feat(identity): set-shaped IsAllowed + real ctx principal — Phase B
  • 7a7d646 feat(identity): guarded accessor below the transport — Phase A
  • f173351 docs(readme): correct Quick Start + architecture for Phase 2 — B3
  • 02b4cfb feat(config): auto-select LLM provider from available key — B2
  • d521582 docs(license): add Apache-2.0 LICENSE + NOTICE; replace README TBD — B1
  • 4bb1227 Merge Phase 2: single agentic runtime into main
  • 4f6f991 refactor(phase-2): relocate loop to internal/agentloop; record D-0003; mark Phase 2 complete — Change 7
  • 432291a test(phase-2): end-to-end thin-client path + structural guards — Change 6
  • 3f4b2af feat(phase-2): CLI becomes a thin streaming client — Change 5
  • c8fb70d feat(phase-2): local-tool callback path over the stream — Change 4
  • 7eebaf2 feat(phase-2): SSE streaming task endpoint + client consumer — Change 3
  • 1f740f7 feat(phase-2): model control-plane API + swappable LLM adapter — Change 2
  • e030dff docs(phase-2): implementation notes for single-agentic-runtime collapse
  • b11398d feat(phase-1): incremental-autonomy inert seams + R-OVR force-yield — Change 12
  • 3c980ab feat(phase-1): hard-delete cascade tests + §5b-5 expunge guard — Change 11
  • aff30cc feat(phase-1): captain-session gate insertion in executor wrapper — Change 10
  • e816733 feat(phase-1): SessionMiddleware + §D5 durable executor wrapper — Change 9
  • cae2ddc feat(phase-1): captain-session gate primitive — Change 8
  • 0b0e7d0 feat(phase-1): run lifecycle HTTP API — Change 7
  • 7a7fb9d feat(phase-1): captain attach + transfer state machine — Change 6
  • b78e177 feat(phase-1): session/run durable state — Changes 1–5
  • f6c62ee docs: add phase 0 session model and reconciled plan of record
  • e1a4b59 docs: add refactor plan check point
  • d6f1e6b Update joe-dataflow.md
  • 4407293 Improve documentation for .joe/ files
  • 6b1f304 Merge pull request #6 from jaimegago/dependabot/go_modules/go_modules-4c23bf149f
  • 2eb3cc4 chore(deps): bump github.com/slack-go/slack
  • d64c03d docs(readme): document skills system and bump golangci-lint to v2.12.2
  • cf62834 feat(skills): policy-driven quarantine + approval workflow (Phase 4)
  • eb7393d feat(skills): hot reload + reload endpoint + trusted-source mode (Phase 3)
  • 44a24be chore(deps): patch 31 dependabot vulnerabilities
  • 74f7367 ci: replace golangci-lint install script with official action
  • 8c10aa3 feat(skills): add joe skills CLI for git-based install/list/remove/update
  • fc20108 feat(skills): implement Agent Skills consumer (Phase 1)
  • 8b532ee add joe skills design doc
  • 77350d3 Clarify Core Safety Principles and trust progression
  • 6548052 Fix formatting inconsistencies in JOE_SECURITY.md
  • a2d21ad docs(CLAUDE.md): add Applicable Skills section and remove repo-level skill copies
  • 24ac6c9 docs: fix stale references and add missing sections across all human docs
  • dd3fcda feat(prompts): add safety reasoning articulation to TaskSystem prompt
  • 747a97f feat(config): support JOE_DATABASE_DSN env var to override database path
  • 60c85d3 feat(api): make status endpoint version settable via build-time ldflags
  • 090dac3 feat(api): log full task response text at INFO level for auditing
  • 1b3ca9e docs: remove stale/duplicate docs, update milestones with Phase 12
  • ecc8ccd refactor(prompts): extract all LLM prompt strings into internal/prompts package
  • d3efdac fix(safety): surface full namespace-zone mapping for zone boundary reasoning
  • 6559722 feat(safety): add explicit zone boundary articulation in refusal responses
  • 20addc8 feat(safety): add deterministic namespace scope enforcement and secret redaction
  • d7db451 chore: untrack .claude/settings.local.json
  • 386d9de feat(safety): add zone boundary enforcement to task executor
  • 4ba75ed add .claude to gitignore
  • 723c547 feat(api): add task execution endpoint with agentic loop over HTTP
  • 2e3cecd fix: lint
  • 232b686 feat(mcp): replace backend-specific tools with category-based tools (service+question, no source_id)
  • 8b1a624 move to double binary
  • 0117a09 update doc
  • 2c32fe1 fix nginx test
  • 950121f fix test
  • 85006a8 test: fix helm
  • 6d59b12 fix lint
  • 502f8ac cicd: lint
  • e4e6bd0 test:mass coverage improvement
  • 80a81fd readiness for adding postgres
  • 4246c85 fix: db issues with joecore ha
  • f87ea41 go mod tidy
  • 1329261 fix: remove CGO dep
  • 42ba927 feat(front): general improvement using claude skill
  • 0c65afe docs: add go backend, front dev skills
  • 074470a fix: ui
  • 7ca259d feat: web ui v1
  • fb2b962 docs: ui
  • 0cd6a9b feat: phase 11
  • 02134e9 add git ignore
  • cc4483b feat: phase 9
  • f9935ea fix: code quality
  • 1367252 fix(test): flaky
  • 862c282 feat: security RBAC
  • d7c258f fix: lint
  • 4abc31e dev: move echo to test only
  • 44f3220 feat(test): add unit + integration
  • a2ce69c docs: moving things around
  • 3af8c2a docs update mcp server
  • 166665b docs: update kiro study
  • 4c2334c docs: security update
  • 9b6b7f4 feat: phase 8
  • d3becc4 fix: minor leftover
  • b951bbf feat: phase 6.13 (artifacts repos)
  • 397582d docs: phase 8 plan,lint
  • d70dacf docs: update milestones
  • 92439a7 feat: phase 7 done
  • f979bfb docs: update CLAUDE instructions
  • 58e8555 feat: finish phase 6
  • 1a852df fix: disable md warnings
  • 391c356 fix: lint
  • 0e7c44f feat: 6.12
  • 8b82527 feat: phase 6.11
  • 2fb031a feat: 6.10
  • ca8e3c3 fix: change traces defaut output
  • 84bb4a1 feat: phase 6.7
  • e6fa445 fix: lint, refactor some test to table driven
  • 93fd72c feat: phase 6.7
  • 2cb5545 fix: api bug
  • 591db3d feat: phase 6.6
  • bd9f305 feat: phase 6.5
  • d697aee fix: lint
  • 47b3703 fix: tests
  • 2aa6eac fix: overall code quality
  • 649389f test: improve unit to >80% all pkgs
  • be2f323 test: add unit coverage
  • 15b7772 fix: go standards alignment
  • 9715e65 fix: lint
  • bc6cafc fix: minor
  • 332e4a1 fix: lint
  • 52889e5 docs: history of collab with LLMs
  • 945bdeb docs: add troubleshooting tools
  • c7b8f30 docs: update add more adapters
  • 039e589 feat: phase 6.2
  • 3dd232f feat: phase 6.1
  • b3c5098 docs: update
  • 597099b docs: update milestones, delete completed
  • 884b711 fix: minor sec
  • 372000f feat(sec): step 5.5 done
  • 0da8f1c feat(sec): 5.5 step 4
  • 23bc98e feat(sec): add 5.5 step 3
  • 6253764 feat(sec): lint
  • c63171d feat(sec): phase 5.2
  • 3e99864 feat(sec): phase 5.2 of security in layers
  • e91046b feat(sec): add security by layers
  • a0861b5 fix: lint, test
  • 80b4d36 feat: phase 5 done
  • 3ee65ad feat: clarifications system
  • 698d5db feat: phase 2
  • fc9e272 docs: update
  • ebb1ba8 feat: phase 5 finish in progress
  • dd39167 test: improve
  • c724d3c test: improve cmd
  • 9faee51 test: improve cmd
  • d217304 fix: harness e2e
  • e6ebdcf fix: improve error handling
  • c269148 fix: improve http api
  • 5ac8058 fix: tests
  • 7152e0b fix: lint, tests
  • e0bf18b feat(obs): add telemetry
  • aa97b63 fix: minor
  • fa1289d fix: lint
  • cccd3e9 refactor: improve code quality
  • 09faded fix: aws constants
  • dd0e7b7 fix: improve AWS adapters code quality
  • a522ab0 feat: add aws adapters
  • 154cf66 feat: phase 5 core agent
  • 38803ac docs: update LLM instructions
  • 2a94eb0 test: fix units
  • b1f0b7a fix: phase 4 "why is pod foo broken" validated
  • 721eada feat: add git adapter
  • 51d0e74 fix: graph nodeid query
  • ec90b60 docs: update, phase 3 done
  • 71240a1 fix: ci again
  • 2ec9ab1 ci: fix lint
  • f07b082 ci: fix lint
  • 15d315c test: fix github ci lint
  • 3763b5f feat: add k8s adapter
  • 1f7be62 feat: add graph in sql
  • 79777df feat: add graph store
  • 7f7b423 test: update doc
  • 9f806ea test: update instrumentation
  • f9827ea fix: lint
  • 00cf795 test: add comprehensive testing (e2e, integration, observability)
  • 43de4fe feat: add sql store
  • b96d755 fix: based on claude code quality analysis
  • 0a255e7 chore: linter
  • ee4f7b2 feat: add joe client tools
  • 26f2bca fix: add more logging
  • 94c707a feat: add /model command
  • e9c24e9 refactor: joe is now 2 components
  • 4860beb docs: update core docs, 2 components
  • 97cbf25 fix: echo tool
  • d023b56 feat: poc echo tool
  • c6c393c chore: remove binary
  • 06313dc feat: add support for gemini
  • f09e093 feat(first): let's go Joe!