Immutable
release. Only release title and notes can be modified.
What's Changed
- Declarative JSON error format, extension field references, Windows extension suites on PRs, V8 crash reproducers (#821, #822, #823, #824, #708) by @jimhoyd in #827
- init --no-mcp and EPERM diagnostics, fence-aware docs search, fixed-contract adapter recipe (#825, #826, #828) by @jimhoyd in #831
- docs(store): correct conditional-write limitations prose (epic #837 Stage A) by @jimhoyd in #838
- Expose native session identity to application function routes by @jimhoyd in #833
- feat(core): generic request-bound capability handoff for extensions (epic #837 Stage B) by @jimhoyd in #840
- Prove embedded Better Auth in one local URLCode site (#843) by @jimhoyd in #848
- Pass the operator's reviewed policy to inspection commands and the authoring MCP server (#834) by @jimhoyd in #849
- Run the authoring MCP server on the official MCP SDK (#846, stdio) by @jimhoyd in #850
- Remove the deprecated authoring MCP tool aliases by @jimhoyd in #851
- Serve the application MCP server with the official MCP SDK (#846, HTTP) by @jimhoyd in #852
- Install independent extension packages by npm spec or tarball (#844) by @jimhoyd in #853
- Replace auth and admin with a Better Auth extension (#841) by @jimhoyd in #854
- Remove the unused shared passkey relying-party ID from core by @jimhoyd in #855
- Inspect pinned inert documents offline (#844) by @jimhoyd in #856
- Validate request.body.schema as a bounded JSON Schema 2020-12 profile (#845) by @jimhoyd in #860
- Persist store collections in SQLite, one transaction per write (#835) by @jimhoyd in #858
- Store: result-aware retries, declarative transitions and host transactions (#835) by @jimhoyd in #862
- Artifact inspection: $id bases, $ref in data, documents in the release catalog (#857) by @jimhoyd in #864
- Store membership gates and cross-owner reads; the #843 proof runs on store (#863) by @jimhoyd in #865
- Store backup CLI, and extension targets in descriptors so recipes stop over-claiming (#859) by @jimhoyd in #869
- Key request.body by HTTP method (#845, #861) by @jimhoyd in #870
- Pointed body schema diagnostics for contradictory schemas and Ajv refusals (#861) by @jimhoyd in #871
- Transition controls on store screens (#863) by @jimhoyd in #872
- workerd parity: build first, raw GET/HEAD-with-body checks, dispatch-only workflow (#868) by @jimhoyd in #874
- Store: members CLI, audited membership, reassign memberships, enum filters; declared targets in validate/capabilities (#866, #867) by @jimhoyd in #876
- Store screens: If-Match on edits and deletes, stale-page message, browser coverage (#873) by @jimhoyd in #877
- Standard string formats in the body schema profile (#861) by @jimhoyd in #880
- Export an OpenAPI 3.1 description of the project's HTTP operations (#845) by @jimhoyd in #879
- Stage shadcn registry items and Agent Skills as data; opt-in materialization (#844) by @jimhoyd in #878
- Measure the SQLite store: throughput, commit cost and list ordering (#859) by @jimhoyd in #882
- Store: 'may' — the transitions the caller may run, on list and record answers (#873) by @jimhoyd in #884
- Ecosystem conformance: zod used directly, and URLCode hosted inside Hono (#841) by @jimhoyd in #887
- Store operator gaps: audited record moves, --actor, bounded filters, declared targets in explain/manifest/context/review (#875) by @jimhoyd in #885
- Delete the form-records extension (#883 slice 1) by @jimhoyd in #890
- Second independent auth provider: Auth.js behind the same principal/identity boundary (#841) by @jimhoyd in #886
- Embed URLCode in another host: createEmbeddedHandler shares core's request/response rules (#889) by @jimhoyd in #891
- Delete the forms, abuse and mail extensions (#883 slices 2-3) by @jimhoyd in #892
- OpenAPI accuracy: runtime headers and 405, auth 401/403 per method, mixed error scopes; standard formats for parameters (#881) by @jimhoyd in #894
- Delete store screens and the ui extension (#883 slices 4-5) by @jimhoyd in #895
- Key principal-provider behavior on providesPrincipal, not the name 'auth' (#888) by @jimhoyd in #893
- Remove extension asset mounts, contributions and form helpers left unused (#883 slice 6) by @jimhoyd in #896
- Measure URLCode's ownership after the #841 retirements (#883 slice 7) by @jimhoyd in #898
- Small follow-ups: undelivered audit reporting, review app.fetch, Worker header counts (#875, #889) by @jimhoyd in #897
- Trim own-file-only core exports; workerd parity never passes when it compared nothing by @jimhoyd in #899
- Store records as JSON Schema 2020-12; extensions describe their mounts for the OpenAPI export (#861, #881) by @jimhoyd in #900
- Installed-file record, bounded YAML for inert documents, and upgrading independent packages (#857) by @jimhoyd in #901
- Re-measure the core package budget after #900 and #901 (fixes main's CI) by @jimhoyd in #903
- Store: operator-configurable commit durability (#859) by @jimhoyd in #904
- Actionable missing context: env fallback, one runnable command; plan_feature list queries (#834) by @jimhoyd in #905
- Record the #841 agent workflow trial by @jimhoyd in #909
- Declare the URLCode extension contract every package is built for (#844) by @jimhoyd in #906
- Named project schemas shared by HTTP bodies and MCP tools, loadable from files offline (#845) by @jimhoyd in #907
- Authenticated fixtures reach audit readiness (#914) by @jimhoyd in #918
- Extension mounts own their namespace (overlaps name both routes); 405 before extension gates (#912, #915) by @jimhoyd in #919
- Trial fixes: init --with names version skew, pinned shipped README links, openapi --check, find-user (#911, #916, #917) by @jimhoyd in #921
- Work around the Node 24 V8 wasm abort in sandbox workers (#708) by @jimhoyd in #922
- Read-only inspection without the revision pin; plan-feature matches extension authoring surfaces (#910, #913) by @jimhoyd in #920
- Record signals in test/audit and assert them with expectSignals; dev --signal-sink (#917) by @jimhoyd in #923
- Store collections name project schemas; defaults and readOnlyProperties on the collection (#908) by @jimhoyd in #924
- Store: declared non-overlapping intervals and retry-safe host transactions (#902) by @jimhoyd in #925
- Store: declared transfers between records (#902) by @jimhoyd in #926
- Record the second agent workflow trial, with scheduling and credits tasks (#902) by @jimhoyd in #933
- Auth SQLite: WAL, busy timeout, BEGIN IMMEDIATE, database rate limit; 503 not false 401 (#927) by @jimhoyd in #934
- Store: a transfers collection's sum never changes on delete or create (#928) by @jimhoyd in #935
- Store: several serving processes on one host — declaration fence, setup refusal, single audit drainer (#927) by @jimhoyd in #936
- OpenAPI: a sign-in gate's 503 when the session cannot be verified by @jimhoyd in #939
- fix(docs,store): installed docs link only what the package ships (#931) by @jimhoyd in #937
- test(store): a Linux multi-process harness in CI, and per-process throttle/cache docs (#927) by @jimhoyd in #946
- Local review loop without re-pinning; plan-feature ignores incidental words; booking and credits recipes (#932) by @jimhoyd in #942
- feat(store): interval length and step, members-gated create, projected readers (#929) by @jimhoyd in #943
- fix(core,docs): installed strings and llms indexes link this release's docs (#938) by @jimhoyd in #950
- feat(core,auth,store,audit)!: hermetic test runs with declared seeds; expectJson; resolved captures in failures (#930) by @jimhoyd in #947
- feat(core,auth,audit): refuse a second host and a network filesystem without the store (#941) by @jimhoyd in #949
- Record the third agent workflow trial: booking, credits and approval by @jimhoyd in #967
- test(store): measure the plumbing declared intervals and transfers remove (#902 item 6) by @jimhoyd in #965
- fix(scripts): pack-addons refuses unbuilt add-ons (#960) by @jimhoyd in #969
- fix(core,docs): packed schema, YAML and llms text names only pages that ship (#948) by @jimhoyd in #963
- feat(mcp): authoring runners review an edited extension site locally (#940) by @jimhoyd in #962
- feat(store)!: named readers mounts (#944) and a step grid with an origin (#945) by @jimhoyd in #966
- Trial-3 CLI friction: hermetic local review, one committed route count, pin-free --local-review, method-level coverage notes by @jimhoyd in #970
- Disk-full evidence for store, auth and audit; the auth mount answers 503 when Better Auth fails on storage by @jimhoyd in #968
- fix(store): deterministic operator-audit lease; package budgets as measurement plus margin (#971) by @jimhoyd in #975
- fix(core): plan-feature offers booking and credits recipes only on their own terms (#957) by @jimhoyd in #981
- OpenAPI: a sign-in gate may answer 503; not every provider does by @jimhoyd in #982
- feat(mcp): in-process run_tests and get_context's commands use the local review (#964) by @jimhoyd in #983
- test(core): over-long body input is refused on length, asserted structurally instead of by a 50 ms bound by @jimhoyd in #985
- feat(store): editable/deletable states and unique values across owners (#952, #953) by @jimhoyd in #984
- feat(store): order and filter store lists in SQL (#951) by @jimhoyd in #986
- Host lease survives clock skew and fails closed; sign-out confirms the session is gone by @jimhoyd in #991
- docs(core): capacity flags, trusted module state and one event catalogue held to events (#995) by @jimhoyd in #997
- test(core): host-lease test closes its connections before removing the directory (Windows EBUSY) by @jimhoyd in #999
- Store recipes: store-approval; booking and credits on slot grids, create.members and a unique-handle directory (#956, #957) by @jimhoyd in #992
- fix(store): owner ids only to members; transfers independent of the recipient; issuers need members (#972, #973, #974) by @jimhoyd in #998
- Store: refuse lone surrogates at every JSON boundary, drop the textual \ud list fallback, and let editable gate increments by @jimhoyd in #996
- Record the fourth agent workflow trial: recipes adopted, rounds 3/0/0 by @jimhoyd in #1005
- docs: store and extension storage docs match the code (#993) by @jimhoyd in #1004
- fix(docs): CLI and local-review docs match the code; extension fast checks run without a pin (#994) by @jimhoyd in #1007
- fix(docs): guidance-claims check catches negative key claims (#1008) by @jimhoyd in #1009
- fix: plan-feature before init, packed core ships its pinned catalog, extensions add updates empty-project guidance (#1000, #1002, #1003) by @jimhoyd in #1011
- fix(recipes): auth-gated recipes sign in through the real auth extension (#1001) by @jimhoyd in #1012
- fix(auth): a passing local-review validate no longer prints Better Auth's schema-check error (#1013) by @jimhoyd in #1017
- fix(core,auth): host lease verify always reads the table; auth verifies inside every Better Auth write (#1010) by @jimhoyd in #1018
- fix(store): activation refuses stored balances outside the declaration; principals are principal ids (#1015) by @jimhoyd in #1020
- fix: refuse lone surrogates in MCP arguments, auth bodies, seeds and fixtures (#1016) by @jimhoyd in #1022
- feat(recipes): recipes add --project merges a recipe into an existing site by @jimhoyd in #1023
- feat(mcp): merge_recipe merges a recipe into the served project (#1024) by @jimhoyd in #1027
- fix: refuse lone surrogates in project config, policy and audit input; invalid UTF-8 in MCP framing (#1021) by @jimhoyd in #1025
- fix(auth): hermetic runs allow ten times each rate limit (#1019) by @jimhoyd in #1026
- fix(mcp): answer malformed JSON lines with -32700; merge_recipe names project-relative paths by @jimhoyd in #1031
- fix(core): hermetic runs enforce the data handover and clean up their directories (#976, #977) by @jimhoyd in #987
- fix(mcp): answer non-message JSON on stdio with -32600 (#1032) by @jimhoyd in #1033
- test: every test script preloads the shared scratch temp directory (#1030) by @jimhoyd in #1034
- chore(deps): Bump actions/download-artifact from 4.3.0 to 8.0.1 by @dependabot[bot] in #1035
- chore(deps): Bump node from
582460fto662933cin /packaging/container by @dependabot[bot] in #1036 - chore(deps-dev): Bump @types/node from 26.6.2 to 26.6.3 by @dependabot[bot] in #1037
- chore(deps-dev): Bump typescript-eslint from 8.70.0 to 8.70.1 by @dependabot[bot] in #1038
- Preserve native Better Auth request body formats by @jimhoyd in #1042
- Bind trusted dependency review evidence to operator revisions by @jimhoyd in #1043
- refactor(core): share the node:http body reader and reserved header set (#1041 items 9-11) by @jimhoyd in #1045
- Remove urlcode import/export, benchmark and verify --online (#1041) by @jimhoyd in #1048
- One serving process per database: replace the host lease with an OS lock by @jimhoyd in #1050
- fix(core): a refused oversized body reaches the client as 413, not a reset (#1046) by @jimhoyd in #1053
- feat(openapi): describe principal providers' credentials truthfully (#1047) by @jimhoyd in #1054
- feat(auth): honour the owner's Better Auth database and sign-in methods (#1052 S5) by @jimhoyd in #1057
- refactor(core): move the SQLite helpers to @jimhoyd/urlcode/sqlite (#1052 S2) by @jimhoyd in #1055
- test(proofs): native-storage proof, the owner's own database behind auth: true (#1052 S7) by @jimhoyd in #1060
- build: fail check:code on merge-conflict markers in any tracked file by @jimhoyd in #1061
- fix(auth): seeds run validateUserInfo and database hooks in a hermetic seed context (#1058) by @jimhoyd in #1059
- feat: provider-neutral scaffold, review and agent guidance (#1052 S6) by @jimhoyd in #1063
- fix(core): name the binding and variable when a granted env or secret is unset by @jimhoyd in #1064
- fix(build): resolve workspace imports to source through a development condition (#1056) by @jimhoyd in #1065
- feat(store): audit log in the store with a core tap; name is the role; cut ownerless (#1052 S4, #1041) by @jimhoyd in #1066
- docs: bundled store/auth are defaults, not URLCode rules (#1052 S1) by @jimhoyd in #1068
- feat(store): count, report and warn about audit events a slow sink lost (#1067) by @jimhoyd in #1070
- fix(auth): operator commands poll for the write lock beside a busy server by @jimhoyd in #1071
- fix(store): operator commands poll for the write lock beside a busy server (#1072) by @jimhoyd in #1073
- fix(core): one-server lock refusal names the owner-choice path (#1052) by @jimhoyd in #1069
- refactor(sqlite): one shared operator write-lock poll for store and auth by @jimhoyd in #1074
- build: built-in changed-files step replaces ci-plan.ts; actions allowlist enforced by @jimhoyd in #1049
- docs(framework): record the #1041 reuse-audit result by @jimhoyd in #1075
- docs: remove stale benchmark, lock-refusal and sqlite-helper prose after recent merges by @jimhoyd in #1076
- docs(framework): correct stale trusted-dependency-review claim (epic #837) by @jimhoyd in #1080
- refactor: remove dead code left by recent cuts by @jimhoyd in #1083
- fix(core): a refused upload's lingering connection drains, runs no further request and does not hold shutdown by @jimhoyd in #1084
- refactor(store): one baseline schema, refuse older store databases, drop auth_servers cleanup (#1078) by @jimhoyd in #1085
- Fix Node 22 packing and store recipe verification failures by @jimhoyd in #1079
- fix(store,ci): audit lost = pruned before any sink peeked it; CI checks the workspace package list by @jimhoyd in #1094
- fix(auth): keep Better Auth's origin and CSRF checks on under NODE_ENV=test or TEST by @jimhoyd in #1097
- fix(ci): merge-queue and nightly exact-commit runs include the packed integration (#1089) by @jimhoyd in #1099
- fix(sandbox): enforce the 32 MiB guest heap with a WebAssembly memory cap (#1092) by @jimhoyd in #1100
- fix(mcp): serialize a handler result before reporting its outcome (#1087) by @jimhoyd in #1101
- fix(store): reassign moves each record's updatedAt, and so its ETag (#1088) by @jimhoyd in #1102
- feat(authoring): plan-feature names the multi-record write gap; docs search reads verified independent add-ons (#1086, #1090) by @jimhoyd in #1104
- Reconcile live contract drift (#1091); generate the middleware recipe's modules from the cookbook (#1095) by @jimhoyd in #1103
- docs(skills): one authored copy of the sections the two authoring skills share by @jimhoyd in #1107
- fix(sandbox): fixed-size guest memory and sliced body hand-over; every body up to 16 MiB arrives (#1096) by @jimhoyd in #1109
- refactor(mcp): one fixture-execution core behind run_tests and run_test (#1095) by @jimhoyd in #1113
- perf(addons): extensions add/remove load the project once before and once after the edit (#1105) by @jimhoyd in #1110
- feat(capabilities): function discovery carries the cookbook handler example (#1106) by @jimhoyd in #1111
- fix(mcp): run_tests runs fixtures behind the operator host's plugins (#1112) by @jimhoyd in #1115
- fix(init): a coding-agent client's .claude/ or .codex/ no longer blocks init in place (#1114) by @jimhoyd in #1117
- test: run independent CLI subprocess cases concurrently to cut suite wall time by @jimhoyd in #1108
- Make the store contention test independent of runner throughput by @jimhoyd in #1116
- Shared Markdown fence/link readers, strict newestVersion, middleware Vary merging, package contributor guides (#1118, #1119, #1120, #1121) by @jimhoyd in #1122
- fix(test): separate adapter startup and bound root concurrency by @jimhoyd in #1124
- release: v0.6.6 by @jimhoyd in #1125
- fix(test): bound extension CLI subtest concurrency by @jimhoyd in #1127
- fix(test): make ecosystem imports and shutdown checks portable by @jimhoyd in #1129
Full Changelog: v0.6.5...v0.6.6