v0.4.0
gjoa's settings surface lands: a single about:gjoa hub with a curated LibreWolf-Inspired privacy profile*, the about:sovereignty egress trust panel, and a relational code-graph over gjoa's own source — plus four inherited-egress vectors closed and new patch/knob/projector pre-build gates. Built on Firefox 152.0.1.
Features
- knobs: preflight Gate N + real egress costs + PROFILES↔registry sync (#109)
- projector: relational code-graph over gjoa's own source (#108)
- verify: live about-pages + settings-pointer check via Marionette (#106)
- release: release-notes takes an optional end-ref (backfill past releases) (#105)
- settings: thin about:preferences pointer -> about:gjoa (no FF patch) (#101)
- settings: own the surface — about:gjoa settings hub (knobs promoted) (#100)
- knobs: LibreWolf-Inspired privacy profile + about:knobs dashboard (#83 core) (#99)
- build: pin the beagle compiler ref (visible drift + baked provenance) (#98)
- release: factual release-notes generator + CI-placeholder backstop (#97)
- sovereignty: publish the egress audit tools (open audit = the credibility) (#95)
- sovereignty: regenerate the egress manifest at import time (#94)
- sovereignty: about:sovereignty egress trust panel (#93)
- sovereignty: opt-in maximal-egress-lockdown toggle (default off) (#92)
- projector: rename-recovery — confidence-scored structural anchor matcher (#74 tail) (#83)
- projector: JS-on-Fram live store — round-trip through Fram + Datalog queries (#75) (#82)
- projector: JS-on-Fram — lossless CST -> Fram-format claim records (#75) (#81)
- tools: Firefox-API seam ratchet — drift monitor for the chrome API surface (#73) (#80)
- projector: claim-doc fallback for patch 0011 in the build (Phase 5 integration) (#79)
- projector: JS lossless-CST round-trip reflector + identity-anchored set-body (Phase 5 pilot) (#78)
- tools: Phase 3 — conflict forecast (pre-bump blast-radius, no build) (#75)
Security & hardening
- prefs: close 4 Firefox inherited-egress vectors (#91)
- prep: validate version in pin-firefox before URL/path use (#89)
- supply-chain: GPG-mandatory pin creation + fix gpg-absent crash (#88)
- tabs: load picker favicons via page-icon: cache, not the page URL (#87)
- prep: validate version strings + reject claim-doc path traversal (#86)
Fixes
- drawer: remove dead js/import lines emitting invalid import() into chrome (#90)
Refactors
- compression dedup — shared NAV-JS + sh helper (#85)
- chrome: cross-module declare-extern Any -> real :require imports (#77)
Docs
- why-beagle: cover the modern beagle/fram/claims affordances + link from README (#107)
- readme: sharper headline — the power-user extension stack is native (#104)
- readme: clarify the build flavors — portable builds ARE for sharing (#103)
- readme: compress + polish; add sailboat logo + new-tab screenshot (#102)
Chores
- sovereignty: drop arrow-objlit workaround (beagle PR #8 fixed it) (#96)
- prep: if-with-nil-else -> when/when-not (18 sites) (#84)
- harden externs — typed stdlib statics + prune dead Any-externs (#76)
Generated from the merged commit log — factual changelog, not announcement copy.
* LibreWolf-Inspired is a curated subset of LibreWolf's privacy defaults — not LibreWolf itself (its compile-time disables and ~20 C++ patches aren't here). The trade-offs are shown on the profile in about:gjoa.