# Build-pack changelog ## DevRunbook 0.1.0-rc.1 — 2026-07-27 - Delivered the complete self-hosted modular monolith: local authentication, workspace authorization, 28 built-in playbooks, searchable library, repository profiles, deterministic composer, immutable runs and all export formats. - Added bounded read-only Gitea discovery/snapshots with encrypted tokens and explicit degraded operation when the forge is unavailable. - Added Prompt Lab authoring, validation, review, evaluation, immutable publication and package import/export. - Added personal collections, session revocation, single-use invitations, password-confirmed personal-data operations, operations/audit console and reference-aware artifact retention. - Added nine forward migrations, migration preflight, safe backup/empty-target restore tooling, Unraid deployment assets and operator documentation. - Qualified 10,000-version search/detail performance, a clean-room install, backup/restore, production browser flows and final runtime/security scans. - Runtime web and worker images no longer contain npm, Corepack or Yarn. - Completed post-audit accessibility qualification with Axe coverage of six critical authenticated surfaces in desktop and narrow viewports, one-main landmarks, keyboard/touch targets, 200% reflow and reduced motion. - Added an operator system overview with app/schema versions, database and artifact sizes, disk headroom, failed jobs, last Gitea sync and explicit observed-backup evidence; raw identifiers remain under technical details. - Hardened Compose with read-only application roots, dropped capabilities, PID/memory limits and bounded tmpfs; added HSTS and removed framework disclosure. - Corrected readiness and upgrade preflight for the ninth migration and proved restart persistence plus isolated PostgreSQL dump/restore. Known limitations: Gitea is read-only; product telemetry and arbitrary command execution are disabled; operational log rotation is owned by the Docker logging layer; audit pruning is manual; release evidence covers `linux/amd64`. ## 1.2.0 — 2026-07-27 - Added `START_HERE_CODEX.md` with an exact operator workflow for the Codex app, CLI and IDE extension. - Added `CODEX_EXECUTION_PROTOCOL.md` governing the lead thread, subagents, worktrees, browser verification, progress evidence and resume behavior. - Added a current Codex-native workflow reference covering layered AGENTS.md guidance, skills/plugins, MCP, subagents, worktrees, browser use, automations and web research. - Added an executable offline reference composer and 28 byte-stable golden rendered prompt fixtures. - Added a schema and manifest for golden prompt fixtures and extended build-pack validation to verify them. - Added an exact bootstrap repository contract, root commands and first vertical-slice architectural proof. - Added a schema-validated, pre-populated 68-requirement final release evidence matrix. - Selected Better Auth as the preferred self-hosted authentication implementation, subject to Milestone 0 compatibility verification. - Strengthened the master prompt, milestone gates, state baseline and pack review for a lower-ambiguity autonomous implementation start. ## 1.1.0 - Closed the gap between the 72-item roadmap catalog and runtime content by adding 28 publishable P0 packages. - Added exact condition, package-file, capability and digest contracts. - Expanded the domain, API, identity, configuration and first-run specifications. - Added reference SQL, canonical examples and requirements traceability. - Hardened the offline validator and packaging checks. - Clarified that P1/P2 entries are authored backlog, not falsely validated playbooks. ## 1.0.0 - Initial DevRunbook product and implementation specification. - Added six normative example packages and 72 catalog concepts.