Skip to content

Releases: jimhoyd-com/urlcode

URLCode 0.6.6

Choose a tag to compare

@github-actions github-actions released this 01 Oct 18:30
Immutable release. Only release title and notes can be modified.
cb008e0

What's Changed

  • Declarative JSON error format, extension field references, Windows extension suites on PRs, V8 crash reproducers (#821, #822, #823, #824, #708) by @jimhoyd in #827
  • init --no-mcp and EPERM diagnostics, fence-aware docs search, fixed-contract adapter recipe (#825, #826, #828) by @jimhoyd in #831
  • docs(store): correct conditional-write limitations prose (epic #837 Stage A) by @jimhoyd in #838
  • Expose native session identity to application function routes by @jimhoyd in #833
  • feat(core): generic request-bound capability handoff for extensions (epic #837 Stage B) by @jimhoyd in #840
  • Prove embedded Better Auth in one local URLCode site (#843) by @jimhoyd in #848
  • Pass the operator's reviewed policy to inspection commands and the authoring MCP server (#834) by @jimhoyd in #849
  • Run the authoring MCP server on the official MCP SDK (#846, stdio) by @jimhoyd in #850
  • Remove the deprecated authoring MCP tool aliases by @jimhoyd in #851
  • Serve the application MCP server with the official MCP SDK (#846, HTTP) by @jimhoyd in #852
  • Install independent extension packages by npm spec or tarball (#844) by @jimhoyd in #853
  • Replace auth and admin with a Better Auth extension (#841) by @jimhoyd in #854
  • Remove the unused shared passkey relying-party ID from core by @jimhoyd in #855
  • Inspect pinned inert documents offline (#844) by @jimhoyd in #856
  • Validate request.body.schema as a bounded JSON Schema 2020-12 profile (#845) by @jimhoyd in #860
  • Persist store collections in SQLite, one transaction per write (#835) by @jimhoyd in #858
  • Store: result-aware retries, declarative transitions and host transactions (#835) by @jimhoyd in #862
  • Artifact inspection: $id bases, $ref in data, documents in the release catalog (#857) by @jimhoyd in #864
  • Store membership gates and cross-owner reads; the #843 proof runs on store (#863) by @jimhoyd in #865
  • Store backup CLI, and extension targets in descriptors so recipes stop over-claiming (#859) by @jimhoyd in #869
  • Key request.body by HTTP method (#845, #861) by @jimhoyd in #870
  • Pointed body schema diagnostics for contradictory schemas and Ajv refusals (#861) by @jimhoyd in #871
  • Transition controls on store screens (#863) by @jimhoyd in #872
  • workerd parity: build first, raw GET/HEAD-with-body checks, dispatch-only workflow (#868) by @jimhoyd in #874
  • Store: members CLI, audited membership, reassign memberships, enum filters; declared targets in validate/capabilities (#866, #867) by @jimhoyd in #876
  • Store screens: If-Match on edits and deletes, stale-page message, browser coverage (#873) by @jimhoyd in #877
  • Standard string formats in the body schema profile (#861) by @jimhoyd in #880
  • Export an OpenAPI 3.1 description of the project's HTTP operations (#845) by @jimhoyd in #879
  • Stage shadcn registry items and Agent Skills as data; opt-in materialization (#844) by @jimhoyd in #878
  • Measure the SQLite store: throughput, commit cost and list ordering (#859) by @jimhoyd in #882
  • Store: 'may' — the transitions the caller may run, on list and record answers (#873) by @jimhoyd in #884
  • Ecosystem conformance: zod used directly, and URLCode hosted inside Hono (#841) by @jimhoyd in #887
  • Store operator gaps: audited record moves, --actor, bounded filters, declared targets in explain/manifest/context/review (#875) by @jimhoyd in #885
  • Delete the form-records extension (#883 slice 1) by @jimhoyd in #890
  • Second independent auth provider: Auth.js behind the same principal/identity boundary (#841) by @jimhoyd in #886
  • Embed URLCode in another host: createEmbeddedHandler shares core's request/response rules (#889) by @jimhoyd in #891
  • Delete the forms, abuse and mail extensions (#883 slices 2-3) by @jimhoyd in #892
  • OpenAPI accuracy: runtime headers and 405, auth 401/403 per method, mixed error scopes; standard formats for parameters (#881) by @jimhoyd in #894
  • Delete store screens and the ui extension (#883 slices 4-5) by @jimhoyd in #895
  • Key principal-provider behavior on providesPrincipal, not the name 'auth' (#888) by @jimhoyd in #893
  • Remove extension asset mounts, contributions and form helpers left unused (#883 slice 6) by @jimhoyd in #896
  • Measure URLCode's ownership after the #841 retirements (#883 slice 7) by @jimhoyd in #898
  • Small follow-ups: undelivered audit reporting, review app.fetch, Worker header counts (#875, #889) by @jimhoyd in #897
  • Trim own-file-only core exports; workerd parity never passes when it compared nothing by @jimhoyd in #899
  • Store records as JSON Schema 2020-12; extensions describe their mounts for the OpenAPI export (#861, #881) by @jimhoyd in #900
  • Installed-file record, bounded YAML for inert documents, and upgrading independent packages (#857) by @jimhoyd in #901
  • Re-measure the core package budget after #900 and #901 (fixes main's CI) by @jimhoyd in #903
  • Store: operator-configurable commit durability (#859) by @jimhoyd in #904
  • Actionable missing context: env fallback, one runnable command; plan_feature list queries (#834) by @jimhoyd in #905
  • Record the #841 agent workflow trial by @jimhoyd in #909
  • Declare the URLCode extension contract every package is built for (#844) by @jimhoyd in #906
  • Named project schemas shared by HTTP bodies and MCP tools, loadable from files offline (#845) by @jimhoyd in #907
  • Authenticated fixtures reach audit readiness (#914) by @jimhoyd in #918
  • Extension mounts own their namespace (overlaps name both routes); 405 before extension gates (#912, #915) by @jimhoyd in #919
  • Trial fixes: init --with names version skew, pinned shipped README links, openapi --check, find-user (#911, #916, #917) by @jimhoyd in #921
  • Work around the Node 24 V8 wasm abort in sandbox workers (#708) by @jimhoyd in #922
  • Read-only inspection without the revision pin; plan-feature matches extension authoring surfaces (#910, #913) by @jimhoyd in #920
  • Record signals in test/audit and assert them with expectSignals; dev --signal-sink (#917) by @jimhoyd in #923
  • Store collections name project schemas; defaults and readOnlyProperties on the collection (#908) by @jimhoyd in #924
  • Store: declared non-overlapping intervals and retry-safe host transactions (#902) by @jimhoyd in #925
  • Store: declared transfers between records (#902) by @jimhoyd in #926
  • Record the second agent workflow trial, with scheduling and credits tasks (#902) by @jimhoyd in #933
  • Auth SQLite: WAL, busy timeout, BEGIN IMMEDIATE, database rate limit; 503 not false 401 (#927) by @jimhoyd in #934
  • Store: a transfers collection's sum never changes on delete or create (#928) by @jimhoyd in #935
  • Store: several serving processes on one host — declaration fence, setup refusal, single audit drainer (#927) by @jimhoyd in #936
  • OpenAPI: a sign-in gate's 503 when the session cannot be verified by @jimhoyd in #939
  • fix(docs,store): installed docs link only what the package ships (#931) by @jimhoyd in #937
  • test(store): a Linux multi-process harness in CI, and per-process throttle/cache docs (#927) by @jimhoyd in #946
  • Local review loop without re-pinn...
Read more

URLCode 0.6.5

Choose a tag to compare

@github-actions github-actions released this 27 Sep 17:09
Immutable release. Only release title and notes can be modified.
ef793e4

What's Changed

  • fix(core): abort the request signal when a streamed body is never read (#801) by @jimhoyd in #803
  • fix(core): a stream the runtime refuses also aborts its handler's signal (#802) by @jimhoyd in #804
  • Asset reference diagnostics, local agent bootstrap, SPA and headless-auth recipes, forms inline success (#805, #807, #808, #809, #810) by @jimhoyd in #813
  • Fixture cookie jar, init --adopt, hosted-assisted skill mode, headless ui docs (#806, #811, #812, #814) by @jimhoyd in #815
  • Audit covers extension asset mounts via a per-mount declaration, so ui-composed sites can report ready (#816) by @jimhoyd in #817
  • release: v0.6.5 by @jimhoyd in #818
  • Fix Windows file paths in the headless auth recipe test by @jimhoyd in #819

Full Changelog: v0.6.4...v0.6.5

URLCode 0.6.4

Choose a tag to compare

@github-actions github-actions released this 26 Sep 21:54
Immutable release. Only release title and notes can be modified.
b43f0b7

What's Changed

  • feat(core): studio opens the browser; review report shows changed files, a verdict, route marks and findings by @jimhoyd in #792
  • fix(examples): packaged examples' tests.commands run from a consumer copy (#789) by @jimhoyd in #794
  • Streaming responses for extensions and trusted functions, and the opt-in MCP streaming transport (#659, #626) by @jimhoyd in #796
  • Reload hand-off for exclusive extension resources so stateful sites hot-reload; contact-form signal docs and example version alignment (#777, #793, #795) by @jimhoyd in #798
  • fix(core): context and plan-feature forward --origin; emitted commands quote and locate the project (#791, #790) by @jimhoyd in #797
  • release: v0.6.4 by @jimhoyd in #799
  • Fix Windows cleanup of the stateful reload test by @jimhoyd in #800

Full Changelog: v0.6.3...v0.6.4

URLCode 0.6.3

Choose a tag to compare

@github-actions github-actions released this 26 Sep 15:42
Immutable release. Only release title and notes can be modified.
2383b12

What's Changed

Full Changelog: v0.6.2...v0.6.3

URLCode 0.6.2

Choose a tag to compare

@github-actions github-actions released this 26 Sep 03:13
Immutable release. Only release title and notes can be modified.
a7d7ce1

What's Changed

  • feat(forms): conditional required fields with requiredWhen by @jimhoyd in #707
  • fix(core): name the failing field in validation errors and keep extension RateLimit policies (#702, #696, #701) by @jimhoyd in #720
  • feat: auth owns the auth: shorthand, extension activation errors, body-schema length cap, MCP tool errors and 2025-11-25 (#710, #714, #713, #716, #719) by @jimhoyd in #726
  • feat: per-key quota, relative form date bounds, store-owned CRUD screen, capability-only extension installs (#703, #705, #709, #711) by @jimhoyd in #727
  • fix(cli): extensions add/remove preserve YAML formatting; list --strict accepts library-only add-ons; add-on authoring rules (#715, #718, #712) by @jimhoyd in #728
  • feat: operator alias origins for every same-origin check; release-pinned add-on agent catalog (#717, #721) by @jimhoyd in #730
  • feat(store,core): per-record ownership via an opaque extension principal (#331) by @jimhoyd in #734
  • feat(core): authoring fixture/diff tools, automatic host revision pin, clearer host and cache errors (#722, #723, #724, #725) by @jimhoyd in #735
  • feat: per-owner store limits and reassign, user-linked API keys, shared passkey domain, include-aware authoring tools (#731, #732, #729, #733) by @jimhoyd in #737
  • feat(form-records): new add-on saving a declared form into an owned store collection, with typed forms/store exports (#529) by @jimhoyd in #740
  • docs: prefer tested first-party extensions and guide external AI integration by @jimhoyd in #742
  • feat(forms,store,form-records): name off-page field errors; clear optional fields on edit; per-user list page (#739, #738) by @jimhoyd in #743
  • feat(core,auth): operator-facing extension activation warnings; auth warns when stored passkeys don't match the relying-party ID (#736) by @jimhoyd in #747
  • ci: add Windows and packed-integration legs to PRs that touch installer, manifest, release or integration paths (#744) by @jimhoyd in #748
  • Add urlcode report: a read-only review page for a project or a change by @jimhoyd in #749
  • Add urlcode studio: the review report served on localhost, rebuilt on every reload by @jimhoyd in #751
  • Point readers at urlcode studio and the review report by @jimhoyd in #752
  • refactor: split audit, abuse and mail into extensions; versioned auth/admin contract; core request helpers (#745, #746) by @jimhoyd in #754
  • fix(ui): confine presentation files to the ui directory by @jimhoyd in #758
  • Contribution provenance, full schema descriptions, worker teardown, host-aware MCP and agent-doc fixes (#753, #750, #708, #757, #755, #756, #540) by @jimhoyd in #761
  • MCP runners that execute project code require --allow-authoring; bounded docs search reaches installed add-on guides (#590, #759) by @jimhoyd in #762
  • release: v0.6.2 by @jimhoyd in #763
  • fix(mail): make the copy-escape symlink test cross-platform by @jimhoyd in #764
  • fix(audit): retry temp-dir cleanup on Windows EBUSY by @jimhoyd in #766
  • fix(admin): use fileURLToPath, not URL.pathname, for Windows-safe test paths by @jimhoyd in #767
  • chore: gated tmate debug step in ci.yml for #768 by @jimhoyd in #770
  • fix(audit): close the database before removing its test temp directory by @jimhoyd in #771
  • chore: revert temporary tmate debug step from ci.yml by @jimhoyd in #772
  • fix(audit): close reopened databases and hosts inline, before t.after cleanup by @jimhoyd in #773
  • fix(core): give worker-lifecycle's replacement-wait test a bounded, referenced timer by @jimhoyd in #774
  • fix: stabilize release verification and npm 10 packaging tests by @jimhoyd in #776

Full Changelog: v0.6.1...v0.6.2

URLCode 0.6.1

Choose a tag to compare

@github-actions github-actions released this 25 Sep 01:00
Immutable release. Only release title and notes can be modified.
94d8429

What's Changed

  • Add revision-pinned agent catalog by @jimhoyd in #674
  • build(release): Release prepares the bump branch; the publisher becomes Publish by @jimhoyd in #675
  • build(release): name the workflows Create release and Publish release by @jimhoyd in #679
  • fix(mcp): validate Origin and MCP-Protocol-Version; document the exact mount URL by @jimhoyd in #685
  • fix(core): explain_error suggests list_capabilities, not its legacy alias by @jimhoyd in #683
  • fix(forms): validate date and datetime-local field submissions by @jimhoyd in #684
  • Add component-owned agent tooling descriptors by @jimhoyd in #686
  • fix(core): allowlist artifact package.json keys and restore node_modules on a refused add/remove by @jimhoyd in #688
  • Expose installed add-on agent tooling to MCP by @jimhoyd in #690
  • feat(mcp): declare title and tool annotations by @jimhoyd in #687
  • Add agent references for shipped extensions by @jimhoyd in #692
  • Give extension requests and hooks a request context: route env and request id by @jimhoyd in #691
  • feat(forms): date and datetime-local minimum/maximum bounds by @jimhoyd in #697
  • feat(forms): confirmation can show opted-in submitted fields (#527) by @jimhoyd in #700
  • fix(core): upgrade checks artifact inertness and reports a failed rollback reinstall by @jimhoyd in #694
  • fix(core): name the failing field in invalid extension config errors by @jimhoyd in #695
  • Refuse an unexpected Host on a loopback-bound server (DNS-rebinding defence) by @jimhoyd in #699
  • feat(auth): per-credential quota on bearer routes (#572) by @jimhoyd in #704
  • release: v0.6.1 by @jimhoyd in #706

Full Changelog: v0.6.0...v0.6.1

URLCode 0.6.0

Choose a tag to compare

@github-actions github-actions released this 24 Sep 19:11
Immutable release. Only release title and notes can be modified.
7c01f46

What's Changed

  • docs: point at extension-bundles@v0.5.9, not the stale v0.5.1 by @jimhoyd in #521
  • fix: warn in nextSteps when --with pins deprecated npm extensions by @jimhoyd in #523
  • Make the AI starter truly minimal by @jimhoyd in #525
  • fix: make urlcode init --with bundle-only, auto-resolving extension-bundles@v by @jimhoyd in #526
  • Clarify Actions workflow roles and gates by @jimhoyd in #535
  • fix(auth): raise password-hash contention wait budget for slow CI runners (#506) by @jimhoyd in #536
  • fix(ui): make isMarkup survive cross-bundle module instance boundaries (#524) by @jimhoyd in #537
  • fix(core): improve extension-bundle discovery, error messages, and docs (#530, #534, #531) by @jimhoyd in #538
  • fix(store,forms): guard stale-lock reclaim and refresh the CSRF binding cookie by @jimhoyd in #593
  • ci: cut duplicated CI work and widen the core boundary check by @jimhoyd in #596
  • docs: drift sweep for starter, init --with, versions and monorepo prose by @jimhoyd in #597
  • fix(auth,core): client keys, reset budget, waitlist notice, audit deployment advisories by @jimhoyd in #604
  • fix: bound author regex cost in the pattern guard, agents policy and forms by @jimhoyd in #598
  • fix(core): make extension bundle verification failures diagnosable (#579) by @jimhoyd in #601
  • docs: use apex URLCode AI MCP endpoint by @jimhoyd in #578
  • Declarative-first recipes, review signals and planner ranking by @jimhoyd in #605
  • fix: agent guidance truth and implementation-derived consistency checks by @jimhoyd in #606
  • fix(core): actionable authoring errors, strict request fixtures and JSON 422s by @jimhoyd in #607
  • fix(core): show function and reload errors in dev, and real errors over MCP by @jimhoyd in #602
  • ci: scope workspace verification to releases by @jimhoyd in #609
  • fix: align the starter and local-install path with the running release by @jimhoyd in #600
  • ci: scope expensive PR smoke checks by @jimhoyd in #611
  • ci: align workflow display names by @jimhoyd in #612
  • ci: separate extension and compatibility proofs by @jimhoyd in #613
  • docs: stabilize llms bundle header by @jimhoyd in #619
  • fix(store): let the short-link click counter update a readOnly collection by @jimhoyd in #620
  • refactor: isolate CI and release verification seams by @jimhoyd in #622
  • fix(core): refuse non-default compression config and relabel route throttle on serverless by @jimhoyd in #623
  • feat(core): add public @jimhoyd/urlcode/skills export by @jimhoyd in #627
  • fix: express constant middleware-recipe/cookbook responses via respond by @jimhoyd in #630
  • docs: onboarding docs sweep — concepts page, task-first index, split YAML reference by @jimhoyd in #621
  • fix(core): canonical verb-first MCP tool vocabulary with legacy aliases (#590) by @jimhoyd in #633
  • fix(core): bind extension catalog commit field to attestation source digest by @jimhoyd in #636
  • feat(auth): bearer/API-key authentication by @jimhoyd in #635
  • fix(auth): close register-duplicate session cookie leak, scope sign-in-code issuance per client (#548) by @jimhoyd in #641
  • fix(forms): use core's shared pattern guard instead of a drifted copy by @jimhoyd in #624
  • feat(ui): publish ui-presentation as a separate signed catalog entry (#522) by @jimhoyd in #643
  • chore: collapse release path to core-only and prune unused release/CI tooling by @jimhoyd in #642
  • feat(mcp): add a declarative MCP tool server extension package by @jimhoyd in #625
  • CLI: --version, per-command help, and TTY-readable dev/serve/init output by @jimhoyd in #628
  • docs: consolidate production-gate lists and move dated backlogs out of the public tree by @jimhoyd in #632
  • fix: route bundle-only sites to a bundle-aware CLI, not npx urlcode-ui/urlcode-auth by @jimhoyd in #644
  • fix(core): let a client register .mcp.json before urlcode init runs (#542) by @jimhoyd in #634
  • fix: exclude examples/*/dist build artifacts from npm pack by @jimhoyd in #631
  • core: offline extension-bundle acquisition (cache-first, --bundle-release-path) by @jimhoyd in #637
  • refactor: consolidate CLI, bundle, and agent asset seams by @jimhoyd in #646
  • ci,build: pin the 22.13 package floor, share tsconfigs, phase in checkJs by @jimhoyd in #640
  • fix(core): consolidate shipped-skill file list between skills.ts and agent-context.ts by @jimhoyd in #648
  • feat: add safe extension release trains by @jimhoyd in #647
  • ui: compile kitCss from Tailwind and ship a French kit catalogue by @jimhoyd in #649
  • fix(core): distinguish identifier references from literal data in constant-response heuristic by @jimhoyd in #650
  • chore: consolidate duplicated CI-report and release-template helpers (#569) by @jimhoyd in #652
  • core,auth: expose an authorized extension's principal to route function/middleware context by @jimhoyd in #653
  • Add create-extension scaffolding CLI with --from fork support by @jimhoyd in #655
  • feat(mcp): resources/prompts, outputSchema, and list pagination (#626) by @jimhoyd in #654
  • fix(core): skip Node's own strictContentLength self-check on 22.13.0-22.14.x by @jimhoyd in #657
  • feat(mcp): promote mcp to init --with and the signed extension-bundles release by @jimhoyd in #656
  • refactor: simplify extension catalog releases by @jimhoyd in #658
  • fix(auth): correct false sync-test claim in check-sqlite.mjs comment by @jimhoyd in #660
  • chore: rename extension release workflows by @jimhoyd in #661
  • refactor: rename extension artifacts by @jimhoyd in #662
  • refactor!: one add-on shape, composeHost, site layout, extensions/artifacts add/remove by @jimhoyd in #663
  • build(release)!: merge a version bump, main releases itself by @jimhoyd in #664
  • feat: urlcode upgrade by @jimhoyd in #665
  • release: v0.6.0 by @jimhoyd in #667
  • fix: Windows test and path failures from the 0.6.0 release matrix by @jimhoyd in #668
  • fix(core): mcp imports agent-context from source, not the built package by @jimhoyd in #669
  • test: close the served site before removing it in the add-on integration test by @jimhoyd in #673

Full Changelog: v0.5.9...v0.6.0

@jimhoyd/urlcode 0.5.9

Choose a tag to compare

@github-actions github-actions released this 23 Sep 17:31
Immutable release. Only release title and notes can be modified.
cfad1ea

Changes

No package behavior changes were recorded for this release.

Stability

This is a stable release published to npm's latest channel. Stability is package-specific; packages do not need matching version numbers.

Recommended tested stack

These exact archives were tested together: isolated core install, dependency tree and public import; no publication or live host test. Compatibility is declared by each package's peerDependencies; the table reports both the tested versions and those declared requirements.

Package Tested version npm channel Declared peer requirements
@jimhoyd/urlcode 0.5.9 stable (latest) typescript >=6.0.3 <7.0.0
npm install --save-exact @jimhoyd/urlcode@0.5.9

The signed train.json asset is the machine-readable receipt for this combination.

Verification

Signed artifacts for cfad1ea64ccefeef7b2b584a2b67bc3dc7132c02. Verify a downloaded archive with:

gh attestation verify <tarball> --repo jimhoyd-com/urlcode

@jimhoyd/urlcode 0.5.8

Choose a tag to compare

@github-actions github-actions released this 23 Sep 14:44
Immutable release. Only release title and notes can be modified.
35b5c7b

Changes

No package behavior changes were recorded for this release.

Stability

This is a stable release published to npm's latest channel. Stability is package-specific; packages do not need matching version numbers.

Recommended tested stack

These exact archives were tested together: isolated core install, dependency tree and public import; no publication or live host test. Compatibility is declared by each package's peerDependencies; the table reports both the tested versions and those declared requirements.

Package Tested version npm channel Declared peer requirements
@jimhoyd/urlcode 0.5.8 stable (latest) typescript >=6.0.3 <7.0.0
npm install --save-exact @jimhoyd/urlcode@0.5.8

The signed train.json asset is the machine-readable receipt for this combination.

Verification

Signed artifacts for 35b5c7b017d544beecb556d1787764cc13844d41. Verify a downloaded archive with:

gh attestation verify <tarball> --repo jimhoyd-com/urlcode

@jimhoyd/urlcode 0.5.6

Choose a tag to compare

@github-actions github-actions released this 22 Sep 17:59
Immutable release. Only release title and notes can be modified.
d939969

Changes

No package behavior changes were recorded for this release.

Stability

This is a stable release published to npm's latest channel. Stability is package-specific; packages do not need matching version numbers.

Recommended tested stack

These exact archives were tested together: isolated core install, dependency tree and public import; no publication or live host test. Compatibility is declared by each package's peerDependencies; the table reports both the tested versions and those declared requirements.

Package Tested version npm channel Declared peer requirements
@jimhoyd/urlcode 0.5.6 stable (latest) typescript >=6.0.3 <7.0.0
npm install --save-exact @jimhoyd/urlcode@0.5.6

The signed train.json asset is the machine-readable receipt for this combination.

Verification

Signed artifacts for d93996926d291ec0a013a9c302ceba5aa542401b. Verify a downloaded archive with:

gh attestation verify <tarball> --repo jimhoyd-com/urlcode