Repository navigation
Tale v0.5.74
Highlights
- Connected tasks can follow the source's full business workflow. A source integration can
publish actions with required fields for verification, closure or reopening, including two
stages that share the same Tale column. People submit the complete form from the task's
details; the source checks their verified identity, permissions and business rules before
accepting the change. Pending requests and accepted or refused decisions remain visible after
a reload. The new API also projects source-approved completion and archival. Source projection
refuses a task with any pending captured native agent review; Tale's existing review decisions
must resolve or explicitly transfer that review first. Integrations must adopt this workflow
explicitly.
Tasks
· #4395 - Coding agents can use repository-scoped SSH keys with the native sandbox's OpenSSH and
netcat-openbsd, through its existing egress proxy and verified host keys. Credentialed turns
use the workspace owner's Git author name and email even when no GitHub connector token is
granted. Repository access still requires a named agent secret and an allowed network route;
a Member-started turn receives no agent secrets.
Project agents
· #4395 - Large boards, task lists and Home panels mount the rows near the current view instead of
every row. Task details start their reads together, load the first screen of activity first,
and defer reviewer and dependency pickers until needed. Long conversations leave older
messages dormant, reuse highlighted code, and load math rendering when a reply needs it.
Keyboard navigation keeps the focused task available across a long board lane's render
window.
Task views - Recovery after an outage or deployment is clearer. The browser checks application and
database readiness, refreshes failed reads when service returns, and leaves failed writes for
an explicit retry. Installed service workers can show the connection screen during a failed
navigation and detect recovery. Shared immutable assets let either application colour serve
files needed by tabs opened on the other colour; a missing module triggers one reload after
service is ready, with a manual reload action if the problem remains.
Troubleshooting
· #4385 - A mail draft stays locked while attachments upload and the message sends, including when its
compose pane is reopened. A failed send retains the draft for revision and retry; a successful
send clears the submitted draft. Project uploads also retain the current folder when an older
folder deletion finishes late, and switching projects clears the previous folder selection.
#4362,
#4364 - Failed reads no longer look like empty settings, a healthy runtime or a quiet period. This
covers personalization, Inbox availability, deployed automations, website status, MCP
organization access, pending retention, Documents folders, project agents, live task runs and
harness health and turns. Cloud-import setup keeps Connect unavailable until its checks
load successfully.
#4342,
#4360,
#4356,
#4359,
#4366,
#4346,
#4375,
#4371,
#4374,
#4370,
#4379,
#4378 - Authenticator entries and backup-code downloads can name the client, product and environment.
For example,TOTP_CLIENT_NAME=AcmewithTOTP_ENVIRONMENT=teproduces
Acme Tale Platform TE. Existing authenticator entries keep their saved names and secrets.
Environment reference
· #4380 - Sandbox runtime upgrades reuse a common toolchain and independent harness layers, reducing
duplicated image data when one harness changes. Headless Chromium remains available for
Playwright and its MCP launcher without a second browser download; the document tools and
managed harnesses remain baked into the image.
#4367
Upgrade notes
- Back up the application database, configuration, keys and external stores before deploying.
The backend applies additive migrations0151_task_external_status.sqland
0152_task_external_status_requests.sqlat startup. They add source projection receipts and
immutable human requests and decisions; they do not rewrite existing task history. Keep these
tables and their data during an image rollback: numbered migrations are forward-only.
Upgrade and recover - API contract 3.16.0 adds source workflow metadata and human intent to task status reads,
plusPUT /api/v1/projects/{id}/tasks/{taskId}/external-statusfor decisions already validated
by a custom source. Existing intake consumers retain their previous open/closed behavior
until they opt in. GitHub and GlitchTip issue tasks cannot use this projection route. Read the
current lifecycle revision, validate the actual person's complete request at the source, and
persist its decision before replying. Handle conflicts by rereading and validating the newer
intent; a retry must not overwrite it. Native human forms require a verified active account,
and API keys cannot impersonate a form submitter.
API reference
· #4395 - For an integration adopting these forms, deploy Tale first, then its compatible source schema
and service, then its bridge worker. Preserve source and Tale receipts and decision history
through rollback. Stop the bridge before returning to an older application, and verify that
any downgraded source or worker can read the retained records before restarting it. Older Tale
versions ignore the new tables and can resume the legacy intake status policy. - Use the matching sandbox, egress and runtime images when enabling SSH coding access; changing
the application alone does not update an already pinnedSANDBOX_RUNTIME_IMAGE. Drain active
work through the normal deployment procedure. Grant only the repository key the agent needs,
keep its private bytes in the secret environment andssh-agent, and retain host-key
verification. The new tools use the existing egress policy and grant no repository access by
themselves.
Sandbox and SSH configuration - The generated deployment and repository Compose definitions include
static-assets. Custom
Compose setups must mount the same volume at/app/static-assetson every web replica. Web
readiness waits for publication; retired assets remain available for seven days after their
last refresh. During the first upgrade from a version without this support, old replicas
still lack the shared fallback. A first browser visit during an outage also needs the edge's
unavailable page because no service worker is installed yet.
Handover and recovery TOTP_CLIENT_NAMEis optional: 1–40 letters, digits, spaces or&,',.,+,-, trimmed.
Unset, orTale, names new entriesTale Platform.TOTP_ENVIRONMENTstill accepts 1–32
letters, digits, underscores or hyphens; unset orpradds no environment suffix. Invalid
values prevent backend startup. Supply these settings to the web and backend roles when
customizing them. They change newly generated setup links and downloaded backup-code names,
without rotating secrets or renaming entries already saved on a device.
Domain identity
API contract changes
The contract moved from 3.15.0 to 3.16.0 (139 → 141 operations). Read the API reference's versioning section before upgrading a pinned client.
Added operations:
GET /api/v1/projects/{id}/tasks/{taskId}/statusPUT /api/v1/projects/{id}/tasks/{taskId}/external-status
Removed operations: none.
Changelog
3.16.0 — 2026-10-05: task /status reads a lifecycle activity revision, verified member provenance and the accepted external projection receipt. Custom sources opt into /external-status to project business decisions they already validated, including completion and atomic archival. Exact source binding, conditional native revision and monotonic source lifecycle ordering protect concurrent native moves; no Tale approval is claimed and captured native agent reviews remain protected. Additive.
What's Changed
- fix(platform): stop stale folders from steering project file uploads by @yannickmonney in #4364
- fix(platform): surface MCP organization read failures by @yannickmonney in #4366
- fix(platform): recover failed Inbox availability discovery by @yannickmonney in #4360
- fix(platform): recover deployed automation reads by @yannickmonney in #4356
- fix(platform): allow retry after failed website status sync by @yannickmonney in #4359
- fix(platform): surface pending retention read failures by @yannickmonney in #4346
- fix(sandbox): reduce runtime image and upgrade disk usage by @yannickmonney in #4367
- fix(platform): name a failed harness-health read, not a healthy runtime by @yannickmonney in #4370
- fix(platform): freeze the compose draft while it sends by @yannickmonney in #4362
- fix(platform): name the client and product in authenticator entries by @yannickmonney in #4380
- fix(platform): distinguish unavailable personalization preferences by @yannickmonney in #4342
- fix(platform): retain task subject on live-run read failure by @yannickmonney in #4374
- fix(platform): name a failed folder-list read on the Documents hub by @yannickmonney in #4375
- fix(platform): surface project agent read failures by @yannickmonney in #4371
- fix(platform): name a failed cloud-import setup check, hold Connect by @yannickmonney in #4378
- fix(platform): name a failed harness turns read, not a quiet period by @yannickmonney in #4379
- fix(platform): make availability recovery reliable by @yannickmonney in #4385
- fix(platform): land every delete on its overview page by @yannickmonney in #4381
- fix(deps): update dependency proxy-addr to v2.0.8 [security] by @renovate[bot] in #4418
- feat(platform): state every backend domain's rules in a spec that tests hold by @larryro in #4420
- fix(platform): synchronize external task lifecycles by @yannickmonney in #4395
- docs: author release notes for v0.5.74 by @yannickmonney in #4399
- fix(docs): unify documentation entry points and site navigation by @yannickmonney in #4408
- fix(deps): patch release audit vulnerabilities by @yannickmonney in #4423
Full Changelog: v0.5.73...v0.5.74