Releases: jimhoyd-com/urlcode
Release list
URLCode 0.6.6
What's Changed
- Declarative JSON error format, extension field references, Windows extension suites on PRs, V8 crash reproducers (#821, #822, #823, #824, #708) by @jimhoyd in #827
- init --no-mcp and EPERM diagnostics, fence-aware docs search, fixed-contract adapter recipe (#825, #826, #828) by @jimhoyd in #831
- docs(store): correct conditional-write limitations prose (epic #837 Stage A) by @jimhoyd in #838
- Expose native session identity to application function routes by @jimhoyd in #833
- feat(core): generic request-bound capability handoff for extensions (epic #837 Stage B) by @jimhoyd in #840
- Prove embedded Better Auth in one local URLCode site (#843) by @jimhoyd in #848
- Pass the operator's reviewed policy to inspection commands and the authoring MCP server (#834) by @jimhoyd in #849
- Run the authoring MCP server on the official MCP SDK (#846, stdio) by @jimhoyd in #850
- Remove the deprecated authoring MCP tool aliases by @jimhoyd in #851
- Serve the application MCP server with the official MCP SDK (#846, HTTP) by @jimhoyd in #852
- Install independent extension packages by npm spec or tarball (#844) by @jimhoyd in #853
- Replace auth and admin with a Better Auth extension (#841) by @jimhoyd in #854
- Remove the unused shared passkey relying-party ID from core by @jimhoyd in #855
- Inspect pinned inert documents offline (#844) by @jimhoyd in #856
- Validate request.body.schema as a bounded JSON Schema 2020-12 profile (#845) by @jimhoyd in #860
- Persist store collections in SQLite, one transaction per write (#835) by @jimhoyd in #858
- Store: result-aware retries, declarative transitions and host transactions (#835) by @jimhoyd in #862
- Artifact inspection: $id bases, $ref in data, documents in the release catalog (#857) by @jimhoyd in #864
- Store membership gates and cross-owner reads; the #843 proof runs on store (#863) by @jimhoyd in #865
- Store backup CLI, and extension targets in descriptors so recipes stop over-claiming (#859) by @jimhoyd in #869
- Key request.body by HTTP method (#845, #861) by @jimhoyd in #870
- Pointed body schema diagnostics for contradictory schemas and Ajv refusals (#861) by @jimhoyd in #871
- Transition controls on store screens (#863) by @jimhoyd in #872
- workerd parity: build first, raw GET/HEAD-with-body checks, dispatch-only workflow (#868) by @jimhoyd in #874
- Store: members CLI, audited membership, reassign memberships, enum filters; declared targets in validate/capabilities (#866, #867) by @jimhoyd in #876
- Store screens: If-Match on edits and deletes, stale-page message, browser coverage (#873) by @jimhoyd in #877
- Standard string formats in the body schema profile (#861) by @jimhoyd in #880
- Export an OpenAPI 3.1 description of the project's HTTP operations (#845) by @jimhoyd in #879
- Stage shadcn registry items and Agent Skills as data; opt-in materialization (#844) by @jimhoyd in #878
- Measure the SQLite store: throughput, commit cost and list ordering (#859) by @jimhoyd in #882
- Store: 'may' — the transitions the caller may run, on list and record answers (#873) by @jimhoyd in #884
- Ecosystem conformance: zod used directly, and URLCode hosted inside Hono (#841) by @jimhoyd in #887
- Store operator gaps: audited record moves, --actor, bounded filters, declared targets in explain/manifest/context/review (#875) by @jimhoyd in #885
- Delete the form-records extension (#883 slice 1) by @jimhoyd in #890
- Second independent auth provider: Auth.js behind the same principal/identity boundary (#841) by @jimhoyd in #886
- Embed URLCode in another host: createEmbeddedHandler shares core's request/response rules (#889) by @jimhoyd in #891
- Delete the forms, abuse and mail extensions (#883 slices 2-3) by @jimhoyd in #892
- OpenAPI accuracy: runtime headers and 405, auth 401/403 per method, mixed error scopes; standard formats for parameters (#881) by @jimhoyd in #894
- Delete store screens and the ui extension (#883 slices 4-5) by @jimhoyd in #895
- Key principal-provider behavior on providesPrincipal, not the name 'auth' (#888) by @jimhoyd in #893
- Remove extension asset mounts, contributions and form helpers left unused (#883 slice 6) by @jimhoyd in #896
- Measure URLCode's ownership after the #841 retirements (#883 slice 7) by @jimhoyd in #898
- Small follow-ups: undelivered audit reporting, review app.fetch, Worker header counts (#875, #889) by @jimhoyd in #897
- Trim own-file-only core exports; workerd parity never passes when it compared nothing by @jimhoyd in #899
- Store records as JSON Schema 2020-12; extensions describe their mounts for the OpenAPI export (#861, #881) by @jimhoyd in #900
- Installed-file record, bounded YAML for inert documents, and upgrading independent packages (#857) by @jimhoyd in #901
- Re-measure the core package budget after #900 and #901 (fixes main's CI) by @jimhoyd in #903
- Store: operator-configurable commit durability (#859) by @jimhoyd in #904
- Actionable missing context: env fallback, one runnable command; plan_feature list queries (#834) by @jimhoyd in #905
- Record the #841 agent workflow trial by @jimhoyd in #909
- Declare the URLCode extension contract every package is built for (#844) by @jimhoyd in #906
- Named project schemas shared by HTTP bodies and MCP tools, loadable from files offline (#845) by @jimhoyd in #907
- Authenticated fixtures reach audit readiness (#914) by @jimhoyd in #918
- Extension mounts own their namespace (overlaps name both routes); 405 before extension gates (#912, #915) by @jimhoyd in #919
- Trial fixes: init --with names version skew, pinned shipped README links, openapi --check, find-user (#911, #916, #917) by @jimhoyd in #921
- Work around the Node 24 V8 wasm abort in sandbox workers (#708) by @jimhoyd in #922
- Read-only inspection without the revision pin; plan-feature matches extension authoring surfaces (#910, #913) by @jimhoyd in #920
- Record signals in test/audit and assert them with expectSignals; dev --signal-sink (#917) by @jimhoyd in #923
- Store collections name project schemas; defaults and readOnlyProperties on the collection (#908) by @jimhoyd in #924
- Store: declared non-overlapping intervals and retry-safe host transactions (#902) by @jimhoyd in #925
- Store: declared transfers between records (#902) by @jimhoyd in #926
- Record the second agent workflow trial, with scheduling and credits tasks (#902) by @jimhoyd in #933
- Auth SQLite: WAL, busy timeout, BEGIN IMMEDIATE, database rate limit; 503 not false 401 (#927) by @jimhoyd in #934
- Store: a transfers collection's sum never changes on delete or create (#928) by @jimhoyd in #935
- Store: several serving processes on one host — declaration fence, setup refusal, single audit drainer (#927) by @jimhoyd in #936
- OpenAPI: a sign-in gate's 503 when the session cannot be verified by @jimhoyd in #939
- fix(docs,store): installed docs link only what the package ships (#931) by @jimhoyd in #937
- test(store): a Linux multi-process harness in CI, and per-process throttle/cache docs (#927) by @jimhoyd in #946
- Local review loop without re-pinn...
URLCode 0.6.5
What's Changed
- fix(core): abort the request signal when a streamed body is never read (#801) by @jimhoyd in #803
- fix(core): a stream the runtime refuses also aborts its handler's signal (#802) by @jimhoyd in #804
- Asset reference diagnostics, local agent bootstrap, SPA and headless-auth recipes, forms inline success (#805, #807, #808, #809, #810) by @jimhoyd in #813
- Fixture cookie jar, init --adopt, hosted-assisted skill mode, headless ui docs (#806, #811, #812, #814) by @jimhoyd in #815
- Audit covers extension asset mounts via a per-mount declaration, so ui-composed sites can report ready (#816) by @jimhoyd in #817
- release: v0.6.5 by @jimhoyd in #818
- Fix Windows file paths in the headless auth recipe test by @jimhoyd in #819
Full Changelog: v0.6.4...v0.6.5
URLCode 0.6.4
What's Changed
- feat(core): studio opens the browser; review report shows changed files, a verdict, route marks and findings by @jimhoyd in #792
- fix(examples): packaged examples' tests.commands run from a consumer copy (#789) by @jimhoyd in #794
- Streaming responses for extensions and trusted functions, and the opt-in MCP streaming transport (#659, #626) by @jimhoyd in #796
- Reload hand-off for exclusive extension resources so stateful sites hot-reload; contact-form signal docs and example version alignment (#777, #793, #795) by @jimhoyd in #798
- fix(core): context and plan-feature forward --origin; emitted commands quote and locate the project (#791, #790) by @jimhoyd in #797
- release: v0.6.4 by @jimhoyd in #799
- Fix Windows cleanup of the stateful reload test by @jimhoyd in #800
Full Changelog: v0.6.3...v0.6.4
URLCode 0.6.3
What's Changed
- Dev reload follows the extension pin, host file reaches commands and runners, and 0.6.2 docs/recipe corrections with checks (#777, #778, #784, #540, #103, #779–#783, #785) by @jimhoyd in #786
- docs: record that the form-records evidence gate was superseded (#760) by @jimhoyd in #787
- release: v0.6.3 by @jimhoyd in #788
Full Changelog: v0.6.2...v0.6.3
URLCode 0.6.2
What's Changed
- feat(forms): conditional required fields with requiredWhen by @jimhoyd in #707
- fix(core): name the failing field in validation errors and keep extension RateLimit policies (#702, #696, #701) by @jimhoyd in #720
- feat: auth owns the auth: shorthand, extension activation errors, body-schema length cap, MCP tool errors and 2025-11-25 (#710, #714, #713, #716, #719) by @jimhoyd in #726
- feat: per-key quota, relative form date bounds, store-owned CRUD screen, capability-only extension installs (#703, #705, #709, #711) by @jimhoyd in #727
- fix(cli): extensions add/remove preserve YAML formatting; list --strict accepts library-only add-ons; add-on authoring rules (#715, #718, #712) by @jimhoyd in #728
- feat: operator alias origins for every same-origin check; release-pinned add-on agent catalog (#717, #721) by @jimhoyd in #730
- feat(store,core): per-record ownership via an opaque extension principal (#331) by @jimhoyd in #734
- feat(core): authoring fixture/diff tools, automatic host revision pin, clearer host and cache errors (#722, #723, #724, #725) by @jimhoyd in #735
- feat: per-owner store limits and reassign, user-linked API keys, shared passkey domain, include-aware authoring tools (#731, #732, #729, #733) by @jimhoyd in #737
- feat(form-records): new add-on saving a declared form into an owned store collection, with typed forms/store exports (#529) by @jimhoyd in #740
- docs: prefer tested first-party extensions and guide external AI integration by @jimhoyd in #742
- feat(forms,store,form-records): name off-page field errors; clear optional fields on edit; per-user list page (#739, #738) by @jimhoyd in #743
- feat(core,auth): operator-facing extension activation warnings; auth warns when stored passkeys don't match the relying-party ID (#736) by @jimhoyd in #747
- ci: add Windows and packed-integration legs to PRs that touch installer, manifest, release or integration paths (#744) by @jimhoyd in #748
- Add urlcode report: a read-only review page for a project or a change by @jimhoyd in #749
- Add urlcode studio: the review report served on localhost, rebuilt on every reload by @jimhoyd in #751
- Point readers at urlcode studio and the review report by @jimhoyd in #752
- refactor: split audit, abuse and mail into extensions; versioned auth/admin contract; core request helpers (#745, #746) by @jimhoyd in #754
- fix(ui): confine presentation files to the ui directory by @jimhoyd in #758
- Contribution provenance, full schema descriptions, worker teardown, host-aware MCP and agent-doc fixes (#753, #750, #708, #757, #755, #756, #540) by @jimhoyd in #761
- MCP runners that execute project code require --allow-authoring; bounded docs search reaches installed add-on guides (#590, #759) by @jimhoyd in #762
- release: v0.6.2 by @jimhoyd in #763
- fix(mail): make the copy-escape symlink test cross-platform by @jimhoyd in #764
- fix(audit): retry temp-dir cleanup on Windows EBUSY by @jimhoyd in #766
- fix(admin): use fileURLToPath, not URL.pathname, for Windows-safe test paths by @jimhoyd in #767
- chore: gated tmate debug step in ci.yml for #768 by @jimhoyd in #770
- fix(audit): close the database before removing its test temp directory by @jimhoyd in #771
- chore: revert temporary tmate debug step from ci.yml by @jimhoyd in #772
- fix(audit): close reopened databases and hosts inline, before t.after cleanup by @jimhoyd in #773
- fix(core): give worker-lifecycle's replacement-wait test a bounded, referenced timer by @jimhoyd in #774
- fix: stabilize release verification and npm 10 packaging tests by @jimhoyd in #776
Full Changelog: v0.6.1...v0.6.2
URLCode 0.6.1
What's Changed
- Add revision-pinned agent catalog by @jimhoyd in #674
- build(release): Release prepares the bump branch; the publisher becomes Publish by @jimhoyd in #675
- build(release): name the workflows Create release and Publish release by @jimhoyd in #679
- fix(mcp): validate Origin and MCP-Protocol-Version; document the exact mount URL by @jimhoyd in #685
- fix(core): explain_error suggests list_capabilities, not its legacy alias by @jimhoyd in #683
- fix(forms): validate date and datetime-local field submissions by @jimhoyd in #684
- Add component-owned agent tooling descriptors by @jimhoyd in #686
- fix(core): allowlist artifact package.json keys and restore node_modules on a refused add/remove by @jimhoyd in #688
- Expose installed add-on agent tooling to MCP by @jimhoyd in #690
- feat(mcp): declare title and tool annotations by @jimhoyd in #687
- Add agent references for shipped extensions by @jimhoyd in #692
- Give extension requests and hooks a request context: route env and request id by @jimhoyd in #691
- feat(forms): date and datetime-local minimum/maximum bounds by @jimhoyd in #697
- feat(forms): confirmation can show opted-in submitted fields (#527) by @jimhoyd in #700
- fix(core): upgrade checks artifact inertness and reports a failed rollback reinstall by @jimhoyd in #694
- fix(core): name the failing field in invalid extension config errors by @jimhoyd in #695
- Refuse an unexpected Host on a loopback-bound server (DNS-rebinding defence) by @jimhoyd in #699
- feat(auth): per-credential quota on bearer routes (#572) by @jimhoyd in #704
- release: v0.6.1 by @jimhoyd in #706
Full Changelog: v0.6.0...v0.6.1
URLCode 0.6.0
What's Changed
- docs: point at extension-bundles@v0.5.9, not the stale v0.5.1 by @jimhoyd in #521
- fix: warn in nextSteps when --with pins deprecated npm extensions by @jimhoyd in #523
- Make the AI starter truly minimal by @jimhoyd in #525
- fix: make urlcode init --with bundle-only, auto-resolving extension-bundles@v by @jimhoyd in #526
- Clarify Actions workflow roles and gates by @jimhoyd in #535
- fix(auth): raise password-hash contention wait budget for slow CI runners (#506) by @jimhoyd in #536
- fix(ui): make isMarkup survive cross-bundle module instance boundaries (#524) by @jimhoyd in #537
- fix(core): improve extension-bundle discovery, error messages, and docs (#530, #534, #531) by @jimhoyd in #538
- fix(store,forms): guard stale-lock reclaim and refresh the CSRF binding cookie by @jimhoyd in #593
- ci: cut duplicated CI work and widen the core boundary check by @jimhoyd in #596
- docs: drift sweep for starter, init --with, versions and monorepo prose by @jimhoyd in #597
- fix(auth,core): client keys, reset budget, waitlist notice, audit deployment advisories by @jimhoyd in #604
- fix: bound author regex cost in the pattern guard, agents policy and forms by @jimhoyd in #598
- fix(core): make extension bundle verification failures diagnosable (#579) by @jimhoyd in #601
- docs: use apex URLCode AI MCP endpoint by @jimhoyd in #578
- Declarative-first recipes, review signals and planner ranking by @jimhoyd in #605
- fix: agent guidance truth and implementation-derived consistency checks by @jimhoyd in #606
- fix(core): actionable authoring errors, strict request fixtures and JSON 422s by @jimhoyd in #607
- fix(core): show function and reload errors in dev, and real errors over MCP by @jimhoyd in #602
- ci: scope workspace verification to releases by @jimhoyd in #609
- fix: align the starter and local-install path with the running release by @jimhoyd in #600
- ci: scope expensive PR smoke checks by @jimhoyd in #611
- ci: align workflow display names by @jimhoyd in #612
- ci: separate extension and compatibility proofs by @jimhoyd in #613
- docs: stabilize llms bundle header by @jimhoyd in #619
- fix(store): let the short-link click counter update a readOnly collection by @jimhoyd in #620
- refactor: isolate CI and release verification seams by @jimhoyd in #622
- fix(core): refuse non-default compression config and relabel route throttle on serverless by @jimhoyd in #623
- feat(core): add public @jimhoyd/urlcode/skills export by @jimhoyd in #627
- fix: express constant middleware-recipe/cookbook responses via respond by @jimhoyd in #630
- docs: onboarding docs sweep — concepts page, task-first index, split YAML reference by @jimhoyd in #621
- fix(core): canonical verb-first MCP tool vocabulary with legacy aliases (#590) by @jimhoyd in #633
- fix(core): bind extension catalog commit field to attestation source digest by @jimhoyd in #636
- feat(auth): bearer/API-key authentication by @jimhoyd in #635
- fix(auth): close register-duplicate session cookie leak, scope sign-in-code issuance per client (#548) by @jimhoyd in #641
- fix(forms): use core's shared pattern guard instead of a drifted copy by @jimhoyd in #624
- feat(ui): publish ui-presentation as a separate signed catalog entry (#522) by @jimhoyd in #643
- chore: collapse release path to core-only and prune unused release/CI tooling by @jimhoyd in #642
- feat(mcp): add a declarative MCP tool server extension package by @jimhoyd in #625
- CLI: --version, per-command help, and TTY-readable dev/serve/init output by @jimhoyd in #628
- docs: consolidate production-gate lists and move dated backlogs out of the public tree by @jimhoyd in #632
- fix: route bundle-only sites to a bundle-aware CLI, not npx urlcode-ui/urlcode-auth by @jimhoyd in #644
- fix(core): let a client register .mcp.json before urlcode init runs (#542) by @jimhoyd in #634
- fix: exclude examples/*/dist build artifacts from npm pack by @jimhoyd in #631
- core: offline extension-bundle acquisition (cache-first, --bundle-release-path) by @jimhoyd in #637
- refactor: consolidate CLI, bundle, and agent asset seams by @jimhoyd in #646
- ci,build: pin the 22.13 package floor, share tsconfigs, phase in checkJs by @jimhoyd in #640
- fix(core): consolidate shipped-skill file list between skills.ts and agent-context.ts by @jimhoyd in #648
- feat: add safe extension release trains by @jimhoyd in #647
- ui: compile kitCss from Tailwind and ship a French kit catalogue by @jimhoyd in #649
- fix(core): distinguish identifier references from literal data in constant-response heuristic by @jimhoyd in #650
- chore: consolidate duplicated CI-report and release-template helpers (#569) by @jimhoyd in #652
- core,auth: expose an authorized extension's principal to route function/middleware context by @jimhoyd in #653
- Add create-extension scaffolding CLI with --from fork support by @jimhoyd in #655
- feat(mcp): resources/prompts, outputSchema, and list pagination (#626) by @jimhoyd in #654
- fix(core): skip Node's own strictContentLength self-check on 22.13.0-22.14.x by @jimhoyd in #657
- feat(mcp): promote mcp to init --with and the signed extension-bundles release by @jimhoyd in #656
- refactor: simplify extension catalog releases by @jimhoyd in #658
- fix(auth): correct false sync-test claim in check-sqlite.mjs comment by @jimhoyd in #660
- chore: rename extension release workflows by @jimhoyd in #661
- refactor: rename extension artifacts by @jimhoyd in #662
- refactor!: one add-on shape, composeHost, site layout, extensions/artifacts add/remove by @jimhoyd in #663
- build(release)!: merge a version bump, main releases itself by @jimhoyd in #664
- feat: urlcode upgrade by @jimhoyd in #665
- release: v0.6.0 by @jimhoyd in #667
- fix: Windows test and path failures from the 0.6.0 release matrix by @jimhoyd in #668
- fix(core): mcp imports agent-context from source, not the built package by @jimhoyd in #669
- test: close the served site before removing it in the add-on integration test by @jimhoyd in #673
Full Changelog: v0.5.9...v0.6.0
@jimhoyd/urlcode 0.5.9
Changes
No package behavior changes were recorded for this release.
Stability
This is a stable release published to npm's latest channel. Stability is package-specific; packages do not need matching version numbers.
Recommended tested stack
These exact archives were tested together: isolated core install, dependency tree and public import; no publication or live host test. Compatibility is declared by each package's peerDependencies; the table reports both the tested versions and those declared requirements.
| Package | Tested version | npm channel | Declared peer requirements |
|---|---|---|---|
@jimhoyd/urlcode |
0.5.9 |
stable (latest) |
typescript >=6.0.3 <7.0.0 |
npm install --save-exact @jimhoyd/urlcode@0.5.9The signed train.json asset is the machine-readable receipt for this combination.
Verification
Signed artifacts for cfad1ea64ccefeef7b2b584a2b67bc3dc7132c02. Verify a downloaded archive with:
gh attestation verify <tarball> --repo jimhoyd-com/urlcode@jimhoyd/urlcode 0.5.8
Changes
No package behavior changes were recorded for this release.
Stability
This is a stable release published to npm's latest channel. Stability is package-specific; packages do not need matching version numbers.
Recommended tested stack
These exact archives were tested together: isolated core install, dependency tree and public import; no publication or live host test. Compatibility is declared by each package's peerDependencies; the table reports both the tested versions and those declared requirements.
| Package | Tested version | npm channel | Declared peer requirements |
|---|---|---|---|
@jimhoyd/urlcode |
0.5.8 |
stable (latest) |
typescript >=6.0.3 <7.0.0 |
npm install --save-exact @jimhoyd/urlcode@0.5.8The signed train.json asset is the machine-readable receipt for this combination.
Verification
Signed artifacts for 35b5c7b017d544beecb556d1787764cc13844d41. Verify a downloaded archive with:
gh attestation verify <tarball> --repo jimhoyd-com/urlcode@jimhoyd/urlcode 0.5.6
Changes
No package behavior changes were recorded for this release.
Stability
This is a stable release published to npm's latest channel. Stability is package-specific; packages do not need matching version numbers.
Recommended tested stack
These exact archives were tested together: isolated core install, dependency tree and public import; no publication or live host test. Compatibility is declared by each package's peerDependencies; the table reports both the tested versions and those declared requirements.
| Package | Tested version | npm channel | Declared peer requirements |
|---|---|---|---|
@jimhoyd/urlcode |
0.5.6 |
stable (latest) |
typescript >=6.0.3 <7.0.0 |
npm install --save-exact @jimhoyd/urlcode@0.5.6The signed train.json asset is the machine-readable receipt for this combination.
Verification
Signed artifacts for d93996926d291ec0a013a9c302ceba5aa542401b. Verify a downloaded archive with:
gh attestation verify <tarball> --repo jimhoyd-com/urlcode