Files
DevRunbook release export cfd2804e27
Managed validation / full (push) Successful in 3m18s
Publish DevRunbook source
2026-09-03 04:09:17 +02:00

62 lines
3.8 KiB
Markdown

# Build-pack changelog
## DevRunbook 0.1.0-rc.1 — 2026-07-27
- Delivered the complete self-hosted modular monolith: local authentication,
workspace authorization, 28 built-in playbooks, searchable library,
repository profiles, deterministic composer, immutable runs and all export
formats.
- Added bounded read-only Gitea discovery/snapshots with encrypted tokens and
explicit degraded operation when the forge is unavailable.
- Added Prompt Lab authoring, validation, review, evaluation, immutable
publication and package import/export.
- Added personal collections, session revocation, single-use invitations,
password-confirmed personal-data operations, operations/audit console and
reference-aware artifact retention.
- Added nine forward migrations, migration preflight, safe backup/empty-target
restore tooling, Unraid deployment assets and operator documentation.
- Qualified 10,000-version search/detail performance, a clean-room install,
backup/restore, production browser flows and final runtime/security scans.
- Runtime web and worker images no longer contain npm, Corepack or Yarn.
- Completed post-audit accessibility qualification with Axe coverage of six
critical authenticated surfaces in desktop and narrow viewports, one-main
landmarks, keyboard/touch targets, 200% reflow and reduced motion.
- Added an operator system overview with app/schema versions, database and
artifact sizes, disk headroom, failed jobs, last Gitea sync and explicit
observed-backup evidence; raw identifiers remain under technical details.
- Hardened Compose with read-only application roots, dropped capabilities,
PID/memory limits and bounded tmpfs; added HSTS and removed framework
disclosure.
- Corrected readiness and upgrade preflight for the ninth migration and proved
restart persistence plus isolated PostgreSQL dump/restore.
Known limitations: Gitea is read-only; product telemetry and arbitrary command
execution are disabled; operational log rotation is owned by the Docker logging
layer; audit pruning is manual; release evidence covers `linux/amd64`.
## 1.2.0 — 2026-07-27
- Added `START_HERE_CODEX.md` with an exact operator workflow for the Codex app, CLI and IDE extension.
- Added `CODEX_EXECUTION_PROTOCOL.md` governing the lead thread, subagents, worktrees, browser verification, progress evidence and resume behavior.
- Added a current Codex-native workflow reference covering layered AGENTS.md guidance, skills/plugins, MCP, subagents, worktrees, browser use, automations and web research.
- Added an executable offline reference composer and 28 byte-stable golden rendered prompt fixtures.
- Added a schema and manifest for golden prompt fixtures and extended build-pack validation to verify them.
- Added an exact bootstrap repository contract, root commands and first vertical-slice architectural proof.
- Added a schema-validated, pre-populated 68-requirement final release evidence matrix.
- Selected Better Auth as the preferred self-hosted authentication implementation, subject to Milestone 0 compatibility verification.
- Strengthened the master prompt, milestone gates, state baseline and pack review for a lower-ambiguity autonomous implementation start.
## 1.1.0
- Closed the gap between the 72-item roadmap catalog and runtime content by adding 28 publishable P0 packages.
- Added exact condition, package-file, capability and digest contracts.
- Expanded the domain, API, identity, configuration and first-run specifications.
- Added reference SQL, canonical examples and requirements traceability.
- Hardened the offline validator and packaging checks.
- Clarified that P1/P2 entries are authored backlog, not falsely validated playbooks.
## 1.0.0
- Initial DevRunbook product and implementation specification.
- Added six normative example packages and 72 catalog concepts.