Repository navigation
Releases: passioncode-ai/passioncode
Releases · passioncode-ai/passioncode
Release list
v0.1.33 — PassionCode.ai
Changed
- Fabric Agent Adapter is pinned at
v0.9.0(it wasv0.8.3).building-fabric-servicesships the dashboard
kit forfabric-dashboard/0.1(Fabric Agent Contract DEC-0036): one stylesheet and one script that keep a
service's dashboard usable from 360 CSS px inside a host pane beside the agent console, seven WCAG AA themes in
light and dark that follow the host'sfabric_appearancecookie,dashboard_kit.py, the layout probe
check_dashboard_layout.mjsand the probe ruledashboard.declared. The adapter plugin gains its first hook:
at session start it prints one line in a repository whose dashboard has no kit or an older one, and nothing
elsewhere. The default contract pin moves toa83bec6; bundles issued under the earlier revisions stay valid.
v0.1.32 — PassionCode.ai
Changed
- Fabric Agent Adapter is pinned at
v0.8.3(it wasv0.8.1). Its default contract pin moves to Fabric
Agent Contractmain52da526(DEC-0032 through DEC-0035).creating-fabric-agentsand
adapting-projects-to-fabricnow propose an agent's own operator channel (fabric-operator-channel/0.1, rule
OC-11) once, when the agent has human stops ornotify: trueevents: they list the operator's steps, record
the answer (accepted,declinedorlater) and never create a bot, store a token or enable the channel
themselves. For a channel bound in a group shared with other bots they name rules OC-14 through OC-17 (silent
unless addressed; a bare/commandis not addressed). The Python service kit runs on Windows and Linux
(systemdandtask-schedulermanagers, Windows paths and token files). Bundles issued under the earlier
contract revisions stay valid.
v0.1.31 — PassionCode.ai
Changed
- Fabric Agent Adapter is pinned at
v0.8.1(it wasv0.8.0). Its default contract pin moves to Fabric
Agent Contractmain623bf61(DEC-0025 through DEC-0031: settings backups, runner routes, spending limits,
activity telemetry, devices — optional surfaces the kits do not emit yet), andMcp-Namevalues outside plain
ASCII use the MCP 2026-07-28 Base64 sentinel. Bundles issued under the earlier contract revisions stay valid.
v0.1.30 — PassionCode.ai
Changed
- Fabric Agent Adapter is pinned at
v0.8.0(it wasv0.6.3). Its service kit meets the
organization's lifecycle contract (0.7.0: a launchd install respects an operator's disable, an
ExitTimeOutdefault), agents can report what they spend (make_usage_receipt,usage_report,
Fabric Agent Contract DEC-0021), and a service may keep its MCP credential apart from the host's
token (DEC-0024). Bundles issued under the earlier contract revisions stay valid. - Observatory Log is pinned at
v0.18.0(plugin 0.18.0; it wasv0.17.3), the Project
Observatory 0.18.0 skills. That release installs only updates whoseSHA256SUMSis signed by
the organization's release key, so the hook's daily update of an older engine now refuses an
unsigned or foreign-signed release instead of installing it.
v0.1.29 — PassionCode.ai
Changed
-
Observatory Log is pinned at
v0.17.3(plugin 0.17.3; it wasv0.16.0). Its
SessionStart hook keeps Project Observatory current:- for an engine at 0.17.0 or later, it schedules the engine's hourly maintenance job where
it is missing; - for an engine from 0.7.0 to 0.16.0, which has no updater of its own, it installs the newer
release once a day with that engine'sfull update --apply, unless the person turned
automatic updates off.
Both run detached, at most every six hours or once a day, and never hold up a session.
- for an engine at 0.17.0 or later, it schedules the engine's hourly maintenance job where
v0.1.28 — PassionCode.ai
The launcher meets the organization's
product lifecycle contract:
findings F13, F14, F15 and F17 of the 2026-10-03 lifecycle audit. Observatory Log moves to
Project Observatory 0.16.0.
Changed
- Observatory Log is pinned at
v0.16.0(plugin 0.16.0; it wasv0.15.0, plugin 0.15.0),
the Project Observatory 0.16.0 skills. The skills' text is unchanged and follows the release:
agent memory now checks an access binding on every call, embeds remotely only with the
operator's per-project consent, and can be erased with a receipt (full forget).
Fixed
- One update at a time (LC-03, F14).
update,restoreanduninstalltake
~/.passioncode/update.lock; a second one refuses with exit 1 and names the holder, so a
background update and a manual one no longer interleave theirclaude pluginwrites. - One
npm viewfor sessions started together (F13). The SessionStart hook claims
~/.passioncode/probe.pendingbefore it starts the probe; the probe removes it after recording,
and a marker older than five minutes is taken over. - Releases no longer accumulate (LC-11, LC-15, F15). An update keeps the release it installed
and the one it replaced, and removes older releases and partial copies left by a killed update
(prunestep; a dry run plans it). - A release proves its provenance (F17).
vendor --releaserefuses a member whose tag does not
name the plugin version it carries. A member whose repository's tags version another product
may declarerefVersions: "repository"with the pluginversionit expects; the bytes at that
tag must carry that version, and the manifest recordsrefVersionsso the pair reads as the
repository's release, not the plugin's. No member declares it yet: at the current pins every tag
names its plugin version (Observatory Logv0.16.0carries 0.16.0), and whether Observatory Log
should use it when the two diverge again is the open operator decision PC-04. AGENTS.mdgains a## Lifecyclesection: the background footprint with the SessionStart
hook's cost and cadence (LC-09) and build retention (LC-15).
v0.1.27 — PassionCode.ai
Changed
- Fabric Agent Adapter is pinned at
v0.6.3(it wasv0.6.2).building-fabric-services
andcreating-fabric-agentssay that every credential an agent or service uses comes from
Project Observatory, by name:use_secret.py run --vault-onlyfor an agent,use_secret.py servefor a long-running service, never a.envor a key file beside it.
v0.1.26 — PassionCode.ai
Changed
- Observatory Log is pinned at
v0.15.0(plugin 0.15.0; it wasv0.13.0, plugin 0.14.0),
the Project Observatory 0.15.0 skills.handling-secretsgains the header door:use_secret.py headerhands one HTTP MCP server's bearer to Claude Code'sheadersHelper, from the vault only
and only to the server the slot is bound to withvault.py bind --header-for. Agents and
services take every credential from Observatory by name (use_secret.py run --vault-only).
v0.1.25 — PassionCode.ai
Changed
working-in-passioncodefollows the amended release-approval rule (knowledge rules §11,
operator decision 2026-10-03): any member ofrelease-approversmay approve a release run,
including the person who pushed the tag. Unchanged: approval is a person's act and an agent
never approves a release run, signing happens only in CI, admins cannot bypass,v*tags
only, and a published release is never rewritten.
v0.1.24 — PassionCode.ai
Changed
-
working-in-passioncodecarries the release-signing rule (knowledge rules §11):- a published build is signed only in CI, in the repository's
releaseenvironment, through
passioncode-ai/.github@v1; - it is approved by
release-approversbut not by the tag's author; - no release key lives on a laptop;
- an agent never approves a release it started;
- a published release is never rewritten.
The engine line now names its CI release.
- a published build is signed only in CI, in the repository's