Skip to content

Releases: nekoguntai-castle/sanctuary

v0.8.71

Choose a tag to compare

@nekoguntai nekoguntai released this 10 Sep 08:52

27600f0 fix(upgrade-test): pin legacy-runtime-env pre-ownership (#1054)
666bb07 fix(upgrade-test): pin optional-profiles pre-ownership and report failed source installs (#1053)
8313dbe diag(grafana): report the rejected volume identity before refusing (#1052)
52a94a1 fix(upgrade-test): pick extended fixture authority by source ownership (#1051)
ebbdc90 fix(upgrade-test): re-register lane images after the force rebuild gate (#1050)
5fe419e chore: prepare release v0.8.71 (#1049)
ca3b5ef docs(ci): close reliability follow-up plan (#1048)
15ce9cd feat(ownership): harden recovery observation (#1047)
2d6b008 fix(ci): converge fleet lifecycle starts (#1046)
47dd9ba fix(ci): add durable progress and exact-commit status (#1045)
591ad7c fix(ci): reserve finalization time with shared subject deadlines
8fafeed fix(ci): preserve bounded preflight observation outcomes (#1043)
8d1d024 chore: untrack the Claude Code hooks as per-machine tooling (#1042)
476aa43 fix(deps): pin deepmerge-ts 8.0.2 via overrides and make override pins real (#1041)
36d9b77 fix(trezor-proof): validate the forwarder host and always tear the forwarder down (#1040)
9a8921b ci(ownership): label CI stacks with the runner owner-container so the host reaper can reclaim them (#1037)
f0ef823 ci(release-lanes): run install smoke on PRs and the release lanes nightly (#1035)
3e2a1f1 docs(ci): describe the runner fleet and the per-host builder divergence (#1034)
5620ef8 fix(install-test): recreate the backend without rebuilding its image (#1033)
9ffc96f ci(cleanup): let subject-managed lanes install fresh so they build with the layer cache (#1031)
8d93f5c fix(ownership): upgrade an ownership-aware source release in place under coordinated cleanup (#1030)
361a561 fix(deps): force toml@4.2.0 via npm overrides and drop its two audit waivers (#1029)
98f0954 fix(ci): harden release lanes against the v0.8.70 failure modes (#1027)
2bde0bc docs(release): record the v0.8.70 release report and close the RC handoff (#1026)
e629ea3 fix(release): accept lightweight RC tags in promotion and date v0.8.70 from its tag (#1025)

v0.8.70

Choose a tag to compare

@nekoguntai nekoguntai released this 05 Sep 19:16

eb135cb fix(ownership): retain unowned same-project leftovers during upgrades (#1024)
be71af0 fix(ci): repair the four v0.8.70-rc7 lane and start.sh regressions (#1023)
7f5ef72 fix(ci): record replay cleanup daemon errors and budget the combined install-test job (#1022)
43751b2 fix(ci): stamp provenance labels on replay images built from any source tree (#1021)
a58ffec fix(ci): accept historical replay image labels and bound fresh-install lock waits (#1019)
bb6e381 fix(ci): accept fully qualified repo tags from the containerd image store (#1018)
8dfa832 fix(ci): repair the RC-only lanes and start.sh --rebuild regressions found by v0.8.70-rc2 (#1017)
e9fde67 fix(ci): repair the two RC-only lanes that regressed on v0.8.70-rc1 (#1016)
61850cd chore: prepare release v0.8.70 (#1011)
fb0c760 ci: name post-verification runner faults, register the node-status e2e spec, close out the dashboard plan (#1010)
525369c feat(dashboard): make the Node Status card mode-aware and truthful (#1008)
2cab474 feat(bitcoin): align failover routing with priority and add operational node status (#1007)
a8153ea ci(verify-vectors): skip funds-safety proofs for documentation-only changes (#1006)
dc9c310 docs(tasks): record lost-authority stale-stack cleanup completion (#1005)
38822b9 fix(ownership): compare recovery scope resources in canonical order (#1004)
5d4e383 fix(ownership): refresh recovery authority after observation (#1003)
d70fd17 fix(ci): preserve coordinated install runtime (#1002)
a75f3d9 feat(ownership): add lost-authority recovery cleanup (#1001)
34eb890 docs: close ownership cleanup implementation (#1000)
e574aaf Fix manifest-bound legacy Grafana volume authority (#999)
a32808d fix(ci): normalize Podman image reference evidence (#998)
22570fa fix(ci): witness Docker image references from listings (#997)
f706499 fix(ci): align fresh install cleanup authority (#996)
8d518f3 Register exact host artifact execution (#995)
3ce2c78 Converge cleanup callsites and prove exact resource cleanup (#994)
313bf4c Ownership exact cleanup execution and receipts (#993)
60c6dad Ownership inventory and signed dry-run planning (#992)
cfbd9f8 fix(ownership): initialize strict Compose identity (#991)
cdf3de0 Ownership manifests and producer stamping (#990)
65a3ba8 feat(ownership): define cleanup evidence contract (#989)

v0.8.69

Choose a tag to compare

@nekoguntai nekoguntai released this 31 Aug 02:15

ee8baab test(e2e): stabilize mobile overflow gate
d984aab fix(release): gate stable promotion on accepted evidence
ba399ac fix(release): prove replay database TCP readiness
282ba90 Harden v0.8.69 release preflight evidence (#985)
d64ad0d Fix v0.8.69 canary receipt live-fleet contract (#984)
898f257 test(release): retain transient probe evidence (#983)
7743eb0 test(release): tolerate transient resource telemetry misses (#982)
d1e1b11 test(release): stabilize context memory receipt (#981)
de4c6b7 fix(sync): bound maximum transaction consumption (#980)
3b300b0 fix(ui): align event-driven sync and dashboard loading (#979)
4b3ffb2 fix(release): retain maximum fixture weight (#978)
4ede8a0 fix(sync): skip inapplicable field repairs (#977)
73d17e5 fix(release): stop qualified RC10 observation (#976)
993ae09 fix(worker): restore cgroup-aware V8 limits (#975)
5be2d0c fix(release): build combined replay fixture once (#974)
ac662ba fix(release): bound maximum fixture preparation (#973)
ab8039e fix(release): close RC13 replay evidence gaps (#972)
0358cd0 fix(ci): probe replay through published Docker host (#971)
be29b09 fix(ci): stage replay files through daemon (#970)
8b287d6 fix(sync): close RC11 persistence release gaps
5c1d190 fix(sync): bound high-fanout wallet evidence (#968)
9786db4 fix upgrades retaining stale backend routes (#967)
c1b5751 fix(sync): isolate high-fanout transaction evidence (#966)
bb5fe03 fix(sync): order Electrum subscription baselines (#965)
8bedece fix(sync): bound Electrum history responses (#964)
2953c91 fix: bound dead-letter reconciliation sweeps (#963)
0dd31ba fix: bound Electrum sync processing (#962)
0dc52c6 fix: isolate wallet sync Electrum traffic (#961)
d7a2a4b fix(diagnostics): make pseudonymization portable (#960)
cd1156b fix(release): make offline bundles loadable (#958)
5b5f87a Prepare v0.8.69 release (#957)
a94b903 Allow prepared release changelog headings (#956)
1ec9cf0 Harden release preparation and canary policy (#955)
8243fd0 feat: surface wallet sync execution progress (#954)
aebb64e feat(sync): expose whole-pipeline diagnostics (#953)
c24e0e6 fix(install): gate release rebuild verification (#952)
2d1f3e7 feat(sync): expose truthful wallet progress (#951)
68d7a14 feat(sync): add stage telemetry and diagnostics (#950)
38d2b71 fix(sync): bound wallet remote work (#949)

v0.8.68

Choose a tag to compare

@nekoguntai nekoguntai released this 26 Aug 21:24

40aae34 Prepare Sanctuary v0.8.68 (#948)

v0.8.66

Choose a tag to compare

@nekoguntai nekoguntai released this 21 Aug 20:45

331bcb8 ci: make static quality gates truthful (#871)
80048b2 fix(ci): size the install-test port block for the offsets callers actually use (#872)
19ee80e chore: bump version to 0.8.66 (#870)
18a7fec docs: close rationalization implementation plan (#869)
666ee4c Phase 6C: fail closed on LLM config sync (#868)
090c5c9 Phase 6B: centralize wallet activity query keys (#867)
6b36584 Phase 6A: isolate startup cache warming (#866)
f26c0b1 Phase 5: consolidate strict E2E API simulation (#865)
a3ab6cb Phase 4: centralize sync publication (#864)
8257512 Phase 3: neutralize sync job contracts (#863)
c45ac24 Phase 2: unify wallet sync attempt lifecycle (#862)
e4df8aa Phase 1: persist structured wallet sync state (#861)
06c1a36 Phase 0: enforce architecture boundary ratchets (#860)
32278d7 fix(sync): stop lock contention completing as a silent no-op (#857)
ee568e7 fix(sync): make the retry ladder advance and survive a restart (#858)
115cf8b fix(infra): stop leaking sync locks on an unconfirmed release (#856)
1a319a0 fix(sync): carry the evidence-rejection reason into the persisted error (#855)
97216fe fix(ui): stop the sync tooltip being clipped by its card (#859)
c1edd82 fix(support): make wallet-sync diagnostics tell the truth (#854)
2a14f80 fix(ci): stop install/upgrade lanes binding ports the kernel owns (#853)

v0.8.65

Choose a tag to compare

@nekoguntai nekoguntai released this 20 Aug 13:20

049cd1b chore(release): suspend the wallet-safety human attestation gate (#852)
31b25dc chore: bump version to 0.8.65 (#851)
d76439a fix(ci): make wallet-safety canary attribution deterministic (#844) (#850)
e3e3765 fix(architecture): give generated graph nodes stable path-derived ids (#847)
a22a4b8 feat(transactions): finish the tab affordances the plan names (#849)
1e48060 docs(plans): record what shipped in #846 and what is still open (#848)
71c93e6 feat(transactions): drag panels back into the strip and reorder tabs (#845)
e3b677c fix(sync): show why a sync failed and stop resync silently no-opping (#846)
df6f988 feat(transactions): detach a transaction tab into a floating panel (#843)
4bd1d1b feat(transactions): open transaction details in closable sub-tabs (#842)
7c65ff7 feat(transactions): shrink the statistics header when it would wrap (#841)
1c9eeb5 fix(ci): make the install unit suites able to fail (#840)

v0.8.64

Choose a tag to compare

@nekoguntai nekoguntai released this 19 Aug 22:07

0628cd4 fix(test): sweep the out-of-band Grafana containers cleanup cannot see (#839)
1696cfe fix(release): accept the RC run at the same commit and stop capping upgrades at 120m (#838)
3a8b71d fix(ops): settle the Grafana migration terminal state before asserting it (#836)
92480b2 fix(ci): remove duplicated PR upgrade carve-out from the scope classifier (#835)
c51ca9d chore: bump version to 0.8.64 (#834)
848a1f7 feat(release): make the wallet-safety audit review satisfiable by one maintainer (#833)
cdb509f feat(transactions): expand transaction detail inline instead of reserving a pane (#832)
ce47097 fix(wallets): let legacy wallets recover their descriptor policy (#831)
d8a6cc0 fix(sync): restore wallet sync for wallets predating canonical evidence (#829)
048d69f fix(approvals): enforce approval on broadcast and persist requests atomically (#827)
948fef8 fix: use physical maintenance table names (#826)
bd3a640 fix: keep wallet UI data network-correct (#825)
a9db402 fix: enforce live websocket authorization (#824)
ca7d537 fix(release): classify Grafana migration bundle asset (#823)

v0.8.63

Choose a tag to compare

@nekoguntai nekoguntai released this 14 Aug 00:51

9e78816 fix: translate Tor config path for upgrade tests (#822)
cee017f fix: generate Prisma client for RC evidence (#821)
0dc9911 fix: build shared package for RC evidence (#820)
49fcce9 fix: align wallet audit release evidence (#819)
da50d8b chore: prepare v0.8.63 release (#818)
f581720 Harden hardware evidence release gate (#817)
6c70a97 Authenticate receive evidence before persistence (#816)
9953843 Harden hardware signer identity boundaries (#815)
874b17f wallet: lock complete primary-source address corpora (#814)
a48e2e4 PR2: harden address derivation coordinates (#813)
47230f2 PR1: enforce exact script-aware send fees (#812)
734393f PR0: default-deny unverified signer capabilities (#811)
60d89be ci(wallet-safety): lock permanent proof and release evidence (#810)
5d61489 feat(wallet-safety): add opt-in metadata remediation (#809)
f09a9fd feat(wallet-safety): prove Jade Plus conformance (#808)
a719887 feat(wallets): approve Jade authentication boundary (#807)
9cd6627 fix(ci): load Ledger proof image from Buildx (#806)
ce90e6c feat(wallets): prove Ledger signing conformance (#805)
6826d9a feat(wallets): prove Trezor signing conformance (#804)
e60da21 feat(wallets): prove Taproot key-path finalization (#803)
daa0825 feat(wallets): bind PSBT signing to exact accounts
4fbf484 feat(wallets): enforce signed intent and UTXO safety (#801)
35acd4e ci: enforce full server test typecheck (#800)
e642d85 test: align remaining test fixture contracts (#799)
eacf3c4 test: align service DTO fixture contracts (#798)
96e4485 test: repair runtime service type contracts (#797)
a7a46f2 Align wallet and sync test contracts (#796)
8713566 test: repair Express and OpenAPI contracts (#795)
28166c4 Restore Bitcoin test contract type safety (#794)
798a461 test: restore full server typecheck aliases (#793)
f4c760b Build independent address derivation proof matrix (#792)
0d992f5 Harden descriptor semantics and wallet imports (#790)
718a85a Wallet safety: canonical policy and address coordinates (#789)
cba0dc1 Add versioned wallet safety audit gates (#788)
1bfbaaf Enforce atomic descriptor policy boundaries (#787)
9fe4f8f Enforce hardware wallet identity evidence (#786)
64ca311 feat(wallets): bind exact signer account identity (#783)
43e774d Harden Grafana migration recovery and CI ownership (#785)
2f8f8d7 Fence send ownership, refresh capabilities, and harden BIP21 (#784)
073ff01 Make restored runtime state converge atomically
357dbe7 Fail closed on unverified hardware wallet flows (#781)
d91189c Fix atomic session revocation and refresh lineage
2cdbcd0 docs: close iteration 10 remediation plan
a175121 fix(monitoring): make Grafana migration daemon portable
d669f8a fix(frontend): fence wallet state and send amounts
c2dead5 fix(auth): make password change session revocation atomic
78dbce1 docs: close iteration 9 delivery plan
472de62 fix: require Grafana migration quiescence
ebdf124 fix: isolate Tor Payjoin ingress
e5f49fb fix: serialize intelligence preference ownership
08529e7 fix: isolate wallet AI query ownership
b31df93 fix: migrate Grafana to an independent credential (#770)
cf2921f Fix Intelligence ownership and chat contracts (#769)
5e18ab3 Fix Wallet Detail route ownership (#768)
e31e63d fix: isolate device detail route ownership (#767)
9d3f215 fix(release): close the two gaps #765 left, and widen the default-drift guard (#766)
a19d35d fix(release): make publish-release-assets resolve provider config like its shell half (#765)
20e07ec ci: parallelize independent upgrade lanes (#764)

v0.8.62

Choose a tag to compare

@nekoguntai nekoguntai released this 09 Aug 02:59

d05d29d chore: bump version to 0.8.62 (#763)
0114fe5 docs: close out the API response validation plan, declining Tier B (#762)
71efbff test: extract the useDashboardData mock harness so the file can grow again (#761)
fc9c574 feat(api): validate the price, xpub and RBF responses, completing Tier A (#760)
9320841 feat(api): validate the responses a user signs against (#759)
3259e23 feat(api): validate the wallet and UTXO responses (#757)
4d60bd6 feat(api): validate the fee estimates response, and give apiClient the means to (#756)
4447768 fix(release): stop a cleanup trap turning a passing suite red (#754)
9b273b4 ci: report how long a lane actually waits for the runner lock (#755)
4679d5b chore(ci): drop the three Podman upgrade adapters now v0.8.61 has shipped (#752)
2c6e41d fix(ci): stop the e2e lock guard counting comments as invocations (#753)
ded1f3c feat(dashboard): finish the error surfacing, and name the rule the four cards share (#751)
a040d68 feat(dashboard): stop failed requests looking like empty answers (#750)

v0.8.61

Choose a tag to compare

@nekoguntai nekoguntai released this 08 Aug 10:33

90de4b9 chore: bump version to 0.8.61 (#747)
a24d052 fix(ops): make a failed or stale backup visible outside the journal (#748)
89f9175 fix(ci): give container-health and auth-flow a lane image tag (#746)
ddd26d9 fix(ci): make the image purge fail closed instead of purging the shared tag (#744)
c43541f chore(ci): drop two upgrade adapters that no longer match anything (#743)
1a59102 fix(ci): make the migration wait able to observe an exited container (#742)
72ae860 fix(send): stop substituting 1 sat/vB for a fee rate we were never given (#738)
daa834e ci: run the upgrade baseline on PRs that change the upgrade harness (#737)
9df3214 fix(dashboard): stop formatFeeRate throwing when a rate is not a number (#736)
52f7820 fix(ci): hold the e2e lock for the whole lifetime of a lane's stack (#719) (#730)
5db74b3 fix(dashboard): measure the fee flash against the rate it last showed (#733)
5b9127d fix(ui): stop the tooltip CSS and its markup fighting over transform (#731)
a47d650 chore(ci): let an audit exception stand until its finding goes away (#734)
063478f test(ci): reconcile tests/install against what actually runs it (#729)
e5c74c8 fix(ci): give each install lane its own image tag (#728)
e0b6cdc fix(dashboard): align fee tier names under the rates they name (#726)
989af56 fix(test): isolate local integration runs per checkout (#727)
a65c439 fix(release): measure notes from the previous stable tag (#725)
373efdd test(upgrade): make the restart-staleness gate deterministic (#723)
40ece9f ci: stop the integration lane retrying assertion failures (#722)
435627d ci: drop the stale react-router audit exception (#724)