Skip to content

Releases: ticoteam/tico

v0.3.21

Choose a tag to compare

@github-actions github-actions released this 04 Oct 19:02
2489c89

Added

  • Archive and restore KPIs through the owner interface, API and CLI while preserving definitions, readings and audit history. Archived KPIs leave active lists and freshness work by default; historical views remain available.

Fixed

  • Authenticate company desktop updates with the selected hub session, allow signed storage redirects without forwarding hub cookies, and retain updater signature verification and configured public runner feeds.
  • Keep mail doctor read-only and support supervisor-mediated credentials without reading the supervisor key. Missing labels are reported with a separate repair hint.
  • Derive company publisher OIDC trust from current GitHub repository settings, including immutable subjects, while restricting trust to this repository's version tags.
  • Keep older matching Done tasks reachable when the first globally paginated page contains only other task types.

Upgrade notes

  • Update the server, runners and company desktop. Older shells unable to authenticate the company update feed need the documented recovery bridge or a verified manual company install; publication alone does not prove automatic updating.
  • KPI archival is an explicit authorized action; no existing KPI definitions are automatically archived.

v0.3.20

Choose a tag to compare

@github-actions github-actions released this 04 Oct 16:16
47b4a09

Fixed

  • Let authorized development tests use disposable synthetic databases while keeping live team state behind the shared API and honoring task-specific restrictions.
  • BotOps accepts assigned bot-maintenance work with the requester's existing rights and records its own blockers without requiring a new human instruction. Notices still cannot override a human request.
  • BotOps isolates provider sessions by task and conversation by default, preventing unrelated jobs from sharing model history.
  • Repeated stalls create a distinct, reusable diagnostic for each task. BotOps's own stalls and unavailable BotOps route to a human, and Health reports escalated public tasks with no progress.

Upgrade notes

  • Update both server and runner. BotOps starts separate provider sessions; existing task and chat records remain available. Paused routines stay paused.

v0.3.19

Choose a tag to compare

@github-actions github-actions released this 04 Oct 00:34
160d1bb

Added

  • Choose harness, model, effort and named subscription separately, and filter usage by those settings (#62, #67).
  • View approximate weekly subscription usage and reset information, refresh supported Codex readings, and distinguish sign-in health from stale or unknown usage (#68, #69).
  • Search bot templates, copy individual chat messages, and let bot managers mark setup complete from the bot page (#63, #74, #79).
  • Let administrators explicitly grant repository creation to selected bots (#78).

Changed

  • Simplify chat attachments, computer cards, settings navigation and subscription controls; hide archived repositories by default (#61, #64, #65, #66, #73).
  • Remove Overview from mobile bottom navigation and use inline chat for Goal Manager (#75, #76).

Fixed

  • Include the copy-message icon in the shipped font and preserve updates explicitly marked unread while viewing the feed (#80).
  • Preserve subscription identity, assignments and usage history when renaming, and keep subscription bindings fixed throughout active runs and fallback (#70, #71).
  • Correct release-candidate navigation and browser regressions (#72).
  • Honor task blockers and bound stalled-task retries so blocked work does not repeatedly restart (#77).

Upgrade notes

  • Update both server and runner for the subscription changes. Named profiles begin a fresh provider session after the binding upgrade; app conversations remain intact.
  • Weekly usage is approximate, may include activity outside Tico, and is not a spending cap. Replacing credentials inside an active login directory is outside the per-run binding guarantee.

v0.3.18

Choose a tag to compare

@github-actions github-actions released this 03 Oct 07:46
fda7b28

Fixed

  • Ready tasks can complete after missed push deliveries when bounded GitHub ancestry checks verify their merged PRs are included in the running release, preserving pending-PR, open-subtask and human-change safeguards (#59).

Documentation

  • Manual GitHub App setup guidance requires an Active webhook and the Push event subscription, explains how to check delivery, and clarifies that enabling events does not restore missed history (#59).

v0.3.17

Choose a tag to compare

@github-actions github-actions released this 03 Oct 07:27
0e0c38c

Fixed

  • The bot page uses the existing Updates icon for its updates tab, including on mobile (#55).
  • Model changes from More > Bot settings open the shared confirmation and checkpoint-progress dialog instead of silently reverting the selection (#56).
  • Docker server and runner images include validated source commit and repository provenance for deployment-based task completion. Local journey image builds pass the same provenance arguments (#57).

v0.3.16

Choose a tag to compare

@github-actions github-actions released this 03 Oct 06:53
6644da6

Fixed

  • Task details show worktree error explanations inline, readable on touch screens and with a keyboard, with long paths wrapping to fit (#53).

v0.3.15

Choose a tag to compare

@github-actions github-actions released this 03 Oct 06:13
8cc95a0

Added

  • Overview turns the company into an interactive building with department floors, human and bot teammates, and reported bot status. It is available first in desktop and mobile navigation; Updates remains the default. The night scene has department signs on the back walls, direct floor exploration, reduced-motion support and an accessible roster when 3D is unavailable.

Changed

  • GitHub Actions builds and publishes artifacts without Python, browser or Docker smoke-test jobs.
  • Company apps show short initials beside the macOS menu-bar icon, with an optional private label override; stable app identities and update feeds are preserved.
  • Company download links open the described installer directly. Generic apps are labeled as requiring manual setup and no longer appear in company-app banners.

Fixed

  • Kanban columns keep a readable minimum width and scroll horizontally within the board, while empty columns remain compact.
  • macOS windows use a native title bar; switching to the right rail no longer deadlocks, and window restoration accounts for title-bar height and Retina scaling.
  • Unrelated chat messages no longer resolve questions on other tasks. Direct replies resolve only their referenced question; task replies stay within their task.

v0.3.14

Choose a tag to compare

@github-actions github-actions released this 03 Oct 03:32

Changed

  • Task rows no longer show circular status icons. Status appears once in each column or section header, with labels retained in ungrouped views and task details.

Fixed

  • Apply current task visibility to routine history, task comments, answers, file reviews and cached responses.
  • Keep Done separate from Closed: comments that wake an assignee bot do not grant permission to close its task, and occupied pipeline steps cannot silently change their status meaning. Done tasks offer an explicit Close action.
  • Removing a routine preserves unrelated queued work and already claimed occurrences.
  • Task details preserve unsent answers through property saves, ignore stale file and link responses, and keep phone file previews full width.
  • Deliver replies to distinct inputs even when the answer text matches an earlier reply, while avoiding duplicate sends from the same attempt.
  • Redact quoted secrets and private URL hosts in reviewed support diagnostics, without increasing log volume.
  • Preserve committed WAL data in a separate failed-update recovery copy before restoring a rollback snapshot.
  • Retrying a completed task returns its existing result while the computer still owns the attempt and retains access.

v0.3.13

v0.3.13 Pre-release
Pre-release

Choose a tag to compare

@github-actions github-actions released this 03 Oct 01:45

Added

  • Whoever wrote a task comment can change its text or delete it: POST /api/v2/tasks/{tid}/comments/{mid} and
    .../delete in the stable API, hub task comment-edit and hub task comment-delete, and MCP hub_task_comment_edit
    and hub_task_comment_delete. Neither wakes anyone. Deleted text is omitted from future supported reads, and
    the audit log keeps only change metadata. Copies already delivered to people, bots or external services remain. The task view shows "edited" beside an edited comment.
  • Service keys: a key another system, such as your product's backend, uses to file, update, close and reopen tasks,
    and nothing else. POST /api/v2/inbound/tasks takes the system's own key for each piece of work and makes one task
    match what it says now, so calls may come in any order and twice. The owner and the admins manage keys with
    hub service-key create|list|revoke (or /api/v2/service-keys); there is no Settings page for them yet
    (docs/service-keys.md).
  • Task types can let every bot comment and create subtasks (read), or also move, reassign and link tasks (work),
    through Settings → Types, the API, CLI and MCP. Ordinary company tasks are readable by default; these settings
    grant additional actions and never bypass a private task's participants.
  • A task can be renamed: title on POST /api/v2/tasks/{id}, hub_task_update and hub task update --title, for
    whoever may change its other fields. The new title gets the checks a new task's title would, is kept in the task's
    history, and becomes the subject of the task's own conversation.
  • Ticket numbers: a mover can make a custom type numbered, and each task created on it or moved onto it gets the
    team's next number (one sequence for the whole team), kept for good. A mover can keep an imported ticket's number
    (number on create, or once on a task that has none). #18945 names the task wherever an id does, and
    GET /api/v2/tasks?number=18945 finds it.
  • A task has a place within its step, step_rank: a task that enters a step joins its end (its top with top), and
    the people on it and movers can move it. GET /api/v2/tasks takes type and step filters and sort=step, the
    board filtered to a type orders its columns that way, and hub task list and hub_task_list take the same.
  • GET /api/v2/tasks?updated_since=<time> returns only the tasks changed after that time, for a client that polls, and
    brief=true leaves out their bodies and acceptance criteria.

Fixed

  • Completing a task keeps it Done, including self-requested bot tasks and recurring work. Closing is a separate decision; completed tasks no longer close automatically with age or when the next routine runs.
  • Tasks opened from a teammate page use the full shared task detail, including files, questions, comments and code links. On phones it fills the screen, and Back returns to the teammate page.
  • A task's updated time moves when a file is attached to it or archived, a link is removed, a linked pull request
    changes state, or a question on it is asked or answered, as it already did for its fields, comments and new links.

Changed

  • A task on a custom type is a ticket on that type's board, not an ask: the rule for a request to a person (a title
    that starts with a verb, the ask first, under 120 words) applies to General tasks only, in the API, MCP, hub and
    the dry run. A ticket still needs a title.
  • A bot's ticket on a custom type keeps its reference numbers and all-caps words: the plain-English title check
    applies to General tasks only.
  • Tickets on a numbered type stay out of their owner's Needs you, and the desktop count, unless one carries a question
    for that person; a declined ticket stays out of its requester's. General tasks and other types are listed as before.

Security

  • New ordinary tasks are readable by company people and bots. Private tasks limit future access to the requester and current assignee; bot defaults also protect requests assigned to sensitive bots. Existing known ordinary work remains visible; sensitive or ambiguous origins upgrade privately while retaining messages and attachments.

v0.3.12

Choose a tag to compare

@github-actions github-actions released this 03 Oct 00:48

Added

  • Imported meetings wait in a personal Pending queue before sharing, with approve, dismiss and restore actions, batch sharing, per-person auto-share, a Team review default, and CLI/MCP review tools.
  • Private company desktop apps built on version tags, with encrypted CI artifacts and automatic updates from their own Tico server.
  • Owners can set a public team icon in Settings or through the API and CLI.

Improved

  • Granola retries rate limits sooner, reports current sync counts and account status, and keeps sign-in responsive during background sync. Regenerated summaries update only notes that have not been edited by a person.
  • Meetings bulk review applies to the visible rows, so a filtered view cannot accidentally share hidden meetings.
  • Tasks always show one selected type. General and Dev tickets sit beside search, with other types in the arrow menu; switching views, clearing filters, creating tasks and pinning views retain the selected type.
  • The team chart refreshes groups, people and bots during normal polling, so changes made by BotOps or another session appear without a reload while preserving collapsed groups.
  • Help puts Support in the existing resizable right rail, with continuing conversations, a simpler overview, platform descriptions and an inline glossary.
  • New support requests include editable, redacted diagnostics by default. Replies can attach a fresh capture; rejected attachments are never silently dropped.
  • Support diagnostics group repeated server failures, include safe exception locations, runner heartbeat/recovery context and bounded browser failure counts, and report missing capture coverage without verbose logging.

Fixed

  • Listening uses a valid local question override consistently and reports invalid overrides without exposing their contents. Health shows invalid Listening categories, and repeated configuration checks avoid duplicate warnings.
  • Oversized multipart headers return a consistent upload error and release temporary files. Linux runner configuration checks handle GNU and BSD file metadata tools consistently.
  • The team chart shows personal branches only to their operator, labeled Your branch. Original bots remain visible in their groups; administrators can still inspect other branches through the branch picker and Settings.
  • Human desktop downloads prefer valid company builds even when older than the server; company updater feeds reject generic manifests.
  • S3 attachments and desktop downloads share the first credential source that passes a bounded write check, with optional explicit selection. Uploads wait for a writable source and keep that identity through multipart cleanup. Health reports the source and denied permission; failed checks retry every 30 minutes, and denied reads try other sources before retained local copies. Concurrent probes and download manifest fetches share bounded work, including delayed credential discovery.

Changed

  • Fireflies is no longer offered for new imports. Existing meetings, notes, recordings, file versions and historical source filters remain available.

Security

  • Backport the GLib string iterator pointer fix used by the Linux desktop app, with a checked vendored source and an optimized regression test.