Release History
This page is generated from the repository changelog so release documentation stays aligned with published versions.
All notable changes to BoardReadyOps are recorded here.
Unreleased
1.68.3 (2026-10-03)
Bug Fixes
- ci: add bounded cloud repository commissioning (#910) (e957b75)
- ci: bootstrap legacy rollout policy safely (#911) (a68635c)
- ci: expose aggregate deploy disk diagnostics (#907) (8df1080)
- ci: follow Compose base-file precedence (#912) (ae184cb)
- ci: harden release-policy mount verification (#914) (621fd85)
- ci: make low-space rollback retention selectable (#908) (a642074)
- ci: persist commissioned release policy across deploys (#913) (430ca08)
- ci: reclaim build cache before low-disk deploy (#932) (fc026e3)
- ci: unblock cloud deploy with opt-in rollback retention (#906) (6df9326)
- ci: verify security headers after production deploy (#933) (7c66f7a)
- cloud: repair repository action dispatch path (#904) (f616b53)
- deps: remediate current security advisories (#931) (e7735e9)
- deps: remove unpatched dev-only transitive advisories (#934) (6fc0bce)
- web: add baseline browser security headers (#923) (c945397)
- web: avoid unsupported ingestion default (#919) (932db3b)
- web: collapse duplicate contract setup preset (#929) (7963a49)
- web: contextualize repeated action labels (#925) (31869f4)
- web: explain run review release lifecycle (#935) (43c20ed)
- web: gate deliveries on validated revisions (#921) (765c9ad)
- web: make setup readiness actionable (#917) (1156d98)
- web: persist repository onboarding state (#915) (fca265c)
- web: route Workspace settings to access settings (#924) (a80146a)
- web: verify workspace member identities (#918) (d203dcf)
1.68.2 (2026-09-25)
Bug Fixes
1.68.1 (2026-09-24)
Bug Fixes
1.68.0 (2026-09-22)
Features
1.67.0 (2026-09-22)
Features
1.66.1 (2026-09-21)
Bug Fixes
1.66.0 (2026-09-18)
Features
1.65.1 (2026-09-18)
Bug Fixes
1.65.0 (2026-09-18)
Features
- manufacturing: implement footprint mount-type parsing and paste coverage rule (#784, #770) (#822) (10785fa)
1.64.0 (2026-09-15)
Features
- report: say that the SBOM's firmware scope is the repository, not a board (#814) (7e2e373), closes #798
Bug Fixes
1.63.0 (2026-09-15)
Features
1.62.1 (2026-09-15)
Bug Fixes
- web: say why a dashboard action failed, and typecheck the app that holds it (#810) (74d5b2f), closes #800
1.62.0 (2026-09-15)
Features
- cloud: scan firmware identifiers on a timer, and count what was not looked at (#808) (53772df), closes #755 #804
1.61.0 (2026-09-15)
Features
1.60.1 (2026-09-15)
Bug Fixes
1.60.0 (2026-09-15)
Features
- db: persist firmware dependencies, and send the BOMs that never arrived (#801) (46040a4), closes #800
1.59.0 (2026-09-15)
Features
1.58.0 (2026-09-15)
Features
1.57.0 (2026-09-15)
Features
1.56.0 (2026-09-15)
Features
Bug Fixes
1.55.0 (2026-09-15)
Features
Bug Fixes
1.54.0 (2026-09-15)
Features
1.53.0 (2026-09-15)
Features
Bug Fixes
1.52.0 (2026-09-15)
Features
1.51.0 (2026-09-15)
Features
1.50.1 (2026-09-15)
Bug Fixes
1.50.0 (2026-09-15)
Features
1.49.0 (2026-09-15)
Features
1.48.0 (2026-09-14)
Features
- cloud: let an operator resolve a workspace slug, and record the demo corpus licence (#760) (a3fae17)
1.47.1 (2026-09-14)
Bug Fixes
1.47.0 (2026-09-14)
Features
1.46.0 (2026-09-14)
Features
1.45.0 (2026-09-14)
Features
1.44.0 (2026-09-14)
Features
1.43.1 (2026-09-14)
Bug Fixes
1.43.0 (2026-09-14)
Features
- wire the product's real capabilities to the dashboard, and tell people what it finds (#729) (5192fcf)
1.42.1 (2026-09-10)
Bug Fixes
1.42.0 (2026-09-10)
Features
1.41.5 (2026-09-10)
Bug Fixes
1.41.4 (2026-09-10)
Bug Fixes
1.41.3 (2026-09-09)
Bug Fixes
1.41.2 (2026-09-09)
Bug Fixes
1.41.1 (2026-09-09)
Bug Fixes
1.41.0 (2026-09-09)
Features
1.40.1 (2026-09-08)
Bug Fixes
1.40.0 (2026-09-08)
Features
1.39.1 (2026-09-08)
Bug Fixes
- cloud: execute GitHub slash commands durably (#697) (ac74b8e)
- cloud: keep Check Run actions within GitHub limits (#693) (6163cc7)
- cloud: stop unconfigured runs before dispatch (#695) (e285059)
- cloud: wire zero-touch setup actions (#696) (eae2640)
1.39.0 (2026-09-08)
Features
- billing: implement Stripe subscription entitlement projection (W19) (#638) (3e4513b)
- bom: supply-watch provider resilience and pricing snapshot (W11) (#639) (12bc104)
- bom: turn /parts into a real component inventory (#667) (73718c7)
- cli: render a human-readable release certificate on release verify (#578) (5018566)
- cloud: github capability model and safe mutation foundation (PR 1) (#686) (e618967)
- cloud: let a tenant read their own audit log (#679) (69f15c1)
- cloud: let a workspace have more than one person in it (#677) (5c43423)
- cloud: make /deliveries show and issue the guest links it names (#672) (c0a289d)
- cloud: one-click repository setup and remediation pr engine (PR 2) (#687) (592923a)
- cloud: review and workflow-aware lifecycle webhooks and hooks (#690) (19fd05f)
- core: map findings to GitHub Check Run annotations (W15) (#604) (e19304e)
- core: show which release-diff items changed and fix an undercount bug (#579) (1bbd169)
- core: wire GitHub Check Run annotations end to end from findings (#623) (9608455)
- db: query which boards currently reference an MPN (W11) (#611) (28c3931)
- db: thread the GitHub webhook delivery id onto release_runs (W29) (#615) (6a2ae84)
- evidence: show the real evidence ledger instead of describing one (#666) (1865346)
- governance: add independent clean-room reproducible-build verification (#593) (a3a0019)
- governance: canonical PASS/FAIL/CONDITIONAL/UNKNOWN decision vocabulary (W06) (#602) (b1bd928)
- kicad: close W03 hostile-input size/DoS guard gap (#625) (4df5df3)
- release: add provenance fields to the generation manifest (W04) (#612) (1f541fb)
- release: classify worsened/improved findings in release diffs (W08) (#608) (fd16684)
- release: signing-key rotation, revocation & trust-store model (W07) (#603) (4bee976)
- release: wire --trust-store into release verify CLI (W07) (#605) (9bc607a)
- rules: show the 44 checks the engine runs (#676) (38c50a4)
- web: add authenticated Unlighthouse UI audits (#629) (7cd6efe)
- web: add CSV/JSONL audit export formats and tamper-evidence digest (#622) (0f53357)
- web: add dead-letter admin dashboard (#635) (3016dee)
- web: enforce separation of duties on review approvals (W14) (#610) (c6a486a)
- web: give the run readiness score its own copper accent (#627) (49c28ec)
- web: migrate UI to Tailwind and shadcn design system (#654) (abe5f8e)
- web: premium UI — new brand, design system, and real data behind the settings and review surfaces (#657) (899c39a)
- web: premium UI — preset switcher, YAML highlighting, micro-interactions (#656) (b7af0b2)
- web: rate-limit failed bearer-token authentication attempts (#620) (2f69f61)
- web: refine premium product UI (#633) (7b90cee)
- web: support GitHub Check Run annotations with pagination (W15) (#598) (5d014b4)
- web: systematize the brand mark's brass accent as a design token (#626) (8a7d6b6)
Bug Fixes
- action: give the action the token its own defaults need (#671) (7a72a8f)
- ci: bound production build cache growth (#682) (19b0ff7)
- ci: fail closed on stale cloud deploy topology (#645) (01783d9)
- ci: fix process cancellation test flakiness and resolve web code smells (#655) (4ed1364)
- ci: reset cloud-deploy checkout to origin/main instead of ff-only merge (#651) (064a96c)
- ci: resolve remaining SonarQube regex-backtracking findings (#583) (bf1ec3e)
- ci: restore QA nightly browser and visual checks (#647) (1ba315a)
- ci: retire superseded runtime images so the deploy host stops growing (#670) (79c28d5)
- ci: stop cloud-deploy from building into a full disk (#662) (56167cc)
- cloud: clear the SonarCloud and Codecov findings on this branch (#668) (0aa7b50)
- cloud: drop the anchored alternation, and stop a test that could pass vacuously (#669) (0d2862e)
- cloud: scope the v2 workspace API to the caller's own workspaces (#659) (15a7f31)
- contracts: schema-by-schema security triage of runner-protocol .strict() (W02) (#600) (f58cb50)
- core: address CI/SonarQube follow-ups for release-diff detail (#580) (aa55c7d)
- core: combine sequential Array#push() calls and mark AuditReport fields readonly (#585) (3d3e107)
- core: reduce cognitive complexity below SonarQube's threshold of 15 (#584) (c157a88)
- core: resolve SonarQube RELIABILITY findings (regex backtracking, Unicode APIs) (#582) (4cd2c70)
- db: clean up fixture rows in artifact-deletion-store-postgres.test.ts (#613) (9d60028)
- db: resolve SonarCloud nested-ternary finding in priceBreaks parsing (W11) (#642) (bb84613)
- deps: patch full OSV scan vulnerabilities (#632) (a767cd2)
- docs: clarify GitHub App permission updates (#684) (aa516bd)
- docs: correct 10 stale file references in the execution ledger, add a permanent guard (#576) (bbd3f62)
- docs: generate the rule reference from the registry, not a copy of it (#673) (b2ae2f1)
- docs: reject stale canary workflow pins (#683) (026de21)
- docs: unbreak docs-build, and say which token broke it (#664) (253e540)
- governance: add missing trailing newline to .mergify.yml (#591) (93c5f6b)
- governance: harden Mergify ruleset integration (#588) (2ffe792)
- governance: honest master spec provenance + reconciled W00 baseline (#590) (9cec676)
- governance: regenerate NOTICE, correct false verify-baseline claim (#592) (519896f)
- governance: warn on unrecognized webhook env-var names (W28) (#601) (85df05f)
- report: show no-BOM-changes note when every BOM row is unchanged (#581) (dac2411)
- web: drop non-interactive tabIndex flagged by SonarCloud (S6845) (#636) (f8bb770)
- web: give every control a 44px touch target, and clear the last two Sonar findings (#660) (bfcad0f)
- web: give the selected PCB canvas marker a real visual state (#628) (2665abd)
- web: keep setup YAML rows stable (#681) (dab9e0b)
- web: rate limit operator token authentication (#643) (6df0c1e)
- web: repair invisible diff-pill text and unlabeled installation fallback (#652) (d231437)
- web: return 404 for missing records, and clear the SonarCloud findings on #657 (#658) (ba57c4d)
- web: return 404 not 500 for unresolvable review ids without a database (#618) (17f720b)
- web: stop seven pages scrolling sideways on phones and tablets (#661) (82a691c)
Performance
1.38.0 (2026-09-01)
Features
- cloud: add order-independent decision fingerprint (#572) (9451f07)
- contracts: add snapshot guard against silent public schema drift (#568) (e514fb0)
- persistent agentic QA/E2E/a11y/visual audit infrastructure (#563) (f45050e)
Bug Fixes
- ci: bump verified KiCad and Node.js patch baselines (#566) (cf2ba5b)
- ci: point cloud-deploy.yml at the real production topology (#550) (cfadd7c)
- core: strip a leading UTF-8 BOM when reading text files (#575) (a8bce03)
- deps: pin browserslist past GHSA high-severity advisory (#567) (26aa9c7)
- deps: pin mysql2 past GHSA-rgwj-5xj2-c3m3 (#564) (0831efc)
- review: accessible Dialog primitive, policy delete confirm, cancel reset (#555) (85c4920)
- review: resolve quality gate findings, redos patterns, and complexity (#552) (5939a1c)
- review: stop policy metrics overclaiming enforcement scope/state (#556) (7676d86)
- review: UI/UX audit P0/P1 fixes — policy gate, discussion persistence, a11y, URL tabs (#554) (f1a9a15)
- web: active nav state, duplicate H1s, count accuracy (P2 batch) (#557) (8123c4f)
- web: add browser titles to settings pages missing them (P3-02) (#560) (885a6e6)
- web: dedupe run page generateMetadata (SonarCloud duplication gate) (#562) (78d642f)
- web: fake search hint, run repo link, missing 404 H1s (P2 batch) (#558) (1873a59)
- web: give run sub-pages section-specific browser titles (P3-04) (#561) (e674849)
- web: persist sidebar collapse state across navigation (#559) (8674f74)
1.37.0 (2026-08-30)
Features
Bug Fixes
- governance: sync merge gates with live ruleset (#541) (b2b4c9f)
- web: expose trust destination in landing nav (#540) (0371cb3)
1.36.0 (2026-08-30)
Features
- docs: add agent discovery surfaces (#536) (4ca4b65)
- docs: add agent-aware edge negotiation (#539) (45f5132)
- marketplace: prepare GitHub Marketplace listing, webhook intake, and legal documentation (#524) (d3b63cd)
- web: add public agent discovery and SEO metadata (#535) (d8aa8d0)
Bug Fixes
- ci: avoid Windows toolchain shell injection (#532) (da4df1f)
- ci: honor full production soak duration (#533) (40b6220)
- ci: repair Mergify file label rules (#531) (bd88079)
- cloud: enforce Marketplace cancellation lifecycle (46d2bca)
- docs: align Marketplace permission model (#530) (16d94de)
- review: persist governance state and harden approval decisions (#527) (2911a14)
- web: align governance copy with evidence model (#528) (0b77922)
1.35.0 (2026-08-27)
Features
- core: look up component lifecycle through Nexar under customer credentials (#495) (727a468)
- core: resolve component intelligence per installation (#492) (a2fa189)
- core: run the supply watch pass on a schedule, gated by the plan (#490) (30edd36)
- core: store per-installation provider credentials, encrypted at rest (#493) (debc6ae)
- governance: persist and enforce organization review policies (#520) (0fbbb5c)
- report: answer the question the run page was opened to answer (#499) (c54bed6)
- report: give customers a dashboard of the repositories being watched (#498) (9dcbee5)
- report: give the ledger a daylight palette (#508) (d239fee)
- report: let customers supply their own component provider credentials (#496) (7c583a6)
- report: say it in plain words, and put the spacing back on the scale (#500) (fb324a6)
- review: add the missing finding-assignment UI control (#521) (f2fa98c)
- review: Hardware Review & Evidence OS (#518) (411fbf4)
- web: Foundry Editorial product redesign (#523) (f35addc)
Bug Fixes
- billing: close timing-unsafe Stripe signature check merged in #518 (#519) (fdffd5a)
- ci: admit a quarantined release instead of failing the whole task (#510) (e7d0647)
- core: stop rescheduling a reconciliation item past its attempt budget (#506) (e68e851)
- db: fix a review-creation bug that made new reviews impossible (#522) (19cdc00)
- report: finish the copy pass the first one left half done (#504) (356d9d6)
- report: give a signed-in reader a way into their dashboard (#503) (96776cd)
- report: rewrite the copy on the screens nobody curls (#507) (c1f477b)
- report: rewrite the footer that sits under every page (#505) (ae3eacc)
- report: show signed-in state on the landing page (#497) (25cdd28)
- standalone Docker image was silently missing pg (#517) (278a570)
1.34.0 (2026-08-25)
Features
- board identity, BOM snapshots, and continuous supply watch (#480) (0010b8f)
- cloud: add production readiness soak monitor (#466) (113d57c)
- core: meter supply watch enrolment against the plan (#489) (b35a0d6)
- deliver premium product UI experience (#475) (92b194a)
- docs: brand the canonical documentation site (#474) (715b3c1)
- release: authorize dashboard viewers so private runs are reachable (#481) (1fc4f46)
- unify premium product experience (#469) (94326b0)
- web: add terminal circuit-board marketing landing page (#468) (a5399d4)
Bug Fixes
- ci: align Mergify queue and merge conditions (#472) (fd02e60)
- ci: force serial Mergify in-place checks (#473) (f1abda9)
- ci: make Mergify queue checks single-step (#470) (2d99fee)
- core: complete Check Runs for terminal runs that never reported (#483) (5e19ec0)
- core: let a signed result correct a verdict that was only inferred (#484) (d4edd2c)
- core: stop blanking installation identity, and make db:migrate run on Windows (#488) (7d0792b)
- report: show sign-in state in every navigation bar (#482) (01cf6d5)
- test: honor fixture runRules in unit helpers (#471) (a1d7aa7)
- use typed error for invalid environment values (#476) (0aa398c)
1.33.0 (2026-08-22)
Features
1.32.1 (2026-08-22)
Bug Fixes
1.32.0 (2026-08-21)
Features
Bug Fixes
- ci: bind target SHA in Actions OIDC audience (#454) (a3fd3bf)
- ci: keep maintenance contract portable (#460) (03cae04)
- ci: make Renovate validation hermetic (#459) (35419cc)
- core: trust scoped production checkout (#458) (eadca80)
1.31.6 (2026-08-19)
Bug Fixes
- deps: make Renovate store isolation hermetic (#436) (f41d620)
- deps: stabilize Renovate CI runtime (#438) (3e790e0)
1.31.5 (2026-08-19)
Bug Fixes
- deps: isolate Renovate pnpm store (#435) (6b10f95)
- deps: keep Renovate updates deterministic (#433) (536ef54)
1.31.4 (2026-08-19)
Bug Fixes
1.31.3 (2026-08-18)
Bug Fixes
1.31.2 (2026-08-18)
Bug Fixes
1.31.1 (2026-08-17)
Bug Fixes
1.31.0 (2026-08-17)
Features
- core: persist artifact evidence metadata (#391) (e1acd38)
- core: surface artifact deletion lifecycle (#360) (1f080b8), closes #26
- report: link dashboard to GitHub Actions runs (#358) (e58fcdb)
Bug Fixes
- ci: fail pre-push checks closed (#397) (df7723c)
- ci: force Mergify in-place queue checks (#366) (e2a346c)
- ci: isolate source guards from mutation runs (#407) (aadfa8a)
- ci: reduce compatibility drift complexity (#372) (d25671b)
- ci: reduce i18n check complexity (#373) (ff9d203)
- ci: reduce synthetic canary complexity (#386) (2c47cc6)
- ci: reduce worker fleet load complexity (#374) (505a686)
- ci: regenerate dependency artifacts in Renovate (#406) (341098e)
- ci: remediate Sonar and Mergify findings (#364) (3ee4b08)
- ci: resolve npm pack via Node installation (#367) (48f9a9d)
- ci: retry transient Corepack bootstrap (#356) (2d6a8ca)
- ci: simplify npm pack metadata branching (#399) (9e6a3e7)
- cli: keep fix plan sorting immutable (#394) (a506d10)
- cli: reduce DNP fix planning complexity (#369) (4024ac6)
- cli: reduce run command complexity (#375) (46d13ff)
- core: keep pcb area sorting immutable (#396) (711a152)
- core: keep release file sorting immutable (#401) (c922131)
- core: keep runner fleet sorting immutable (#393) (4065c7f)
- core: keep sexpr stack traversal immutable (#395) (918fcb8)
- core: preserve verified runner artifacts (#359) (4757691), closes #26
- core: reduce artifact capability complexity (#380) (b781ca5)
- core: reduce artifact stream complexity (#381) (593e778)
- core: reduce artifact upload complexity (#379) (fe04596)
- core: reduce BOM MPN fix complexity (#384) (d4b99e1)
- core: reduce check-run reconciliation complexity (#382) (075b330)
- core: reduce lifecycle executor complexity (#371) (2df087b)
- core: reduce repository setup complexity (#378) (e0d47b5)
- core: reduce repository setup probe complexity (#385) (0eaa50c)
- core: reduce result route complexity (#387) (ad9f6af)
- core: reduce run summary complexity (#370) (27dbc18)
- core: reduce runner claim complexity (#376) (94a2a61)
- core: reduce runner worker complexity (#383) (9aa6860)
- core: reduce setup probe callback complexity (#368) (ae00c9d)
- core: reduce Sonar complexity in core parsers (#365) (49b1e83)
- core: reduce webhook lifecycle complexity (#377) (734a8e9)
- core: simplify runner request text comparison (#400) (0a4dea9)
- core: simplify STM32 designator fallback (#398) (d661c44)
- core: use semantic live status output (#392) (10d5248)
- deps: patch deepmerge-ts in Prisma config (#409) (7d3e2d5)
- deps: remove vulnerable extract-zip path (#408) (800ebcd)
- deps: update vulnerable nanoid to 3.3.18 (#402) (48be1f9)
1.30.3 (2026-08-09)
Bug Fixes
- cli: add metadata-only runner artifact mode (#352) (5a7fba3)
- cli: cancel in-flight runner analysis on shutdown (#351) (6fb5ee9), refs #41
- core: clean crash-orphaned runner workspaces (#353) (39af849)
- deps: pin patched nanoid transitive (#350) (37cb00c)
- release: harden npm trusted publishing (#348) (fffa1cd), refs #334
- release: pin npm publish to main workflow identity (#354) (78aeeb4), refs #334
1.30.2 (2026-08-08)
Bug Fixes
- ci: harden toolchain bootstrap isolation (#342) (204ebf5)
- ci: restore dependency vulnerability gates (#336) (257f16e)
- ci: use Git-compatible null config paths (#340) (2944474)
1.30.1 (2026-08-05)
Bug Fixes
- core: preserve directory symlinks in portable copies (#328) (157b4a5)
- quality: resolve SonarQube code smells and refactor cognitive complexity (#320) (48eaf5c)
1.30.0 (2026-08-03)
Features
1.29.0 (2026-08-02)
Features
1.28.0 (2026-08-02)
Features
1.27.1 (2026-08-02)
Bug Fixes
- release: make binary uploads resumable (#311) (e026df9), closes #310
- release: repair assets for older tags (#313) (df3186b), closes #310
1.27.0 (2026-08-02)
Features
1.26.1 (2026-08-02)
Bug Fixes
1.26.0 (2026-08-02)
Features
1.25.1 (2026-08-01)
Bug Fixes
- ci: keep release pull request history verified (#298) (a00cde0)
- ci: satisfy release rewrite reliability checks (#299) (4b89274)
- core: retain bounded control-plane history (#295) (7218206)
1.25.0 (2026-08-01)
Features
- core: validate representative control-plane load (#293) (75c38ea)
- core: verify PostgreSQL backup restores (#290) (ea38a8b)
Bug Fixes
- ci: pin readiness workflow to v1.24.1 (#288) (1d8bd78)
- core: make backup verification CLI runnable (#291) (01c42c3)
1.24.1 (2026-08-01)
Bug Fixes
- core: force safe-mode workspace cleanup (#284) (a4e7a0f)
- core: purge terminal ephemeral records (#282) (27b1de4)
- core: restrict safe-mode runtime extensions (#286) (5d49715), refs #42
- core: surface trust restrictions in GitHub (#285) (8eb870d), refs #42
- web: bind dashboard reads to tenant scope (#287) (6812cef)
1.24.0 (2026-07-31)
Features
- core: add reconnectable run refresh (#273) (d3c1a01)
- core: handle GitHub App setup handoff (#274) (e8d01b1), closes #16
- core: persist release-run trust mode (#272) (00a5c1b)
Bug Fixes
- core: bind callbacks to trust snapshots (#281) (485ff4e)
- core: bind runner leases to trust snapshots (#278) (a9691f0), refs #42
- core: expire stale control-plane credentials (#280) (96013db)
- core: fail private dashboards closed (#276) (cb9cfdc)
- core: purge expired runner request nonces (#277) (2d8ce0f), refs #44
- core: suppress safe-mode artifact uploads (#279) (aa0a83d), refs #42
1.23.0 (2026-07-30)
Features
- cloud: add repository setup and readiness flow (#269) (66f6f45)
- scale run investigation dashboard (#266) (cf8327a), closes #221
1.22.0 (2026-07-29)
Features
1.21.0 (2026-07-29)
Features
- core: configure artifact capability expiry (#261) (d40b366), relates to #44
- core: configure webhook retention (#259) (62db74f), relates to #44
1.20.0 (2026-07-29)
Features
- core: add tenant-scoped audit export (#252) (dd5868e)
- core: audit artifact download starts (#254) (32454f9)
- core: audit GitHub App lifecycle changes (#255) (ba36ebd)
- core: audit installation suspension lifecycle (#256) (588ed06)
- core: audit replaced artifact records (#258) (7c111e1)
- core: expose release decision audit summary (#257) (7cf8ed8)
1.19.0 (2026-07-27)
Features
- ci: add cloud coverage and monorepo verification (#230) (78e1ab5)
- ci: add reproducible repository toolchain (#228) (71a694f), closes #220
- ci: add synthetic target-repository canaries (#238) (8e73aee)
- cloud: emit control-plane SLI snapshots (#214) (a61e88a)
- core: add control-plane SLO alerting (#235) (7eb6bb7)
- core: add tenant-scoped dead-letter operator API (#233) (d696f20)
- core: add versioned release-run transitions (#242) (9b4e6aa)
- core: guard Check Run creation transitions (#245) (4dba216)
- core: guard release-run supersession (#247) (2266b4c)
- core: guard runner lease transitions (#249) (1aae59b)
- core: guard runner result transitions (#248) (3ebca30)
- core: guard workflow dispatch transitions (#244) (710fbbb)
- core: guard workflow reconciliation transitions (#246) (9749ce6)
- core: reconcile GitHub Check Run drift (#236) (2d07e25)
- core: reconcile missed GitHub workflow callbacks (#234) (1f8253d)
- core: reconcile webhook inbox and lifecycle job drift (#237) (284b483)
Bug Fixes
- ci: harden supply-chain and container policies (#231) (a7b5ed0)
- ci: make NOTICE verification immutable (#223) (9262984)
- ci: persist solo-maintainer review policy (#232) (1e7adcf)
- deps: patch OSV dependency findings (#240) (4078861)
- deps: update dependency next to v16.2.11 [security] (#229) (63d0771)
- governance: require reviewed main pull requests (#224) (4cae73f)
- governance: restore signed commit enforcement (#225) (7a44e1f)
- security: add aggregate merge gate (#226) (02038db)
1.18.0 (2026-07-22)
Features
1.17.0 (2026-07-22)
Features
1.16.0 (2026-07-22)
Features
- cloud: dispatch transactional outbox effects (#208) (3146836), closes #188
- db: add atomic release-run outbox producer (#207) (e8721d1)
- db: add transactional outbox foundation (#205) (e919758)
Bug Fixes
1.15.0 (2026-07-22)
Features
1.14.0 (2026-07-21)
Features
- ci: add dependency and security automation (#193) (63e259e)
- ci: expand Codecov observability (#201) (ae27422)
- ci: provision admin database URL (#183) (b5c9ab3)
- ci: run readiness in target repositories (843d0ca)
- ci: standardize workflow security linting (#202) (a073226)
- core: durably accept GitHub webhooks (#198) (cd1f6a9)
- core: establish VPS-independent cloud runtime foundation (#192) (ac58985)
- report: improve PR readiness output (#200) (6909e6b)
Bug Fixes
- ci: enable repository config scoping (27e40cf)
- ci: enable repository project scoping (6c1fc5c)
- ci: pin resolvable Renovate action (#195) (b75e4c1)
- ci: support rollout policy files (#186) (6c2a7b2)
1.13.0 (2026-07-14)
Features
Bug Fixes
1.12.1 (2026-07-13)
Bug Fixes
- ci: restore clean web Docker builds (#179) (0bfb14e)
- ci: restore Sonar main quality gate (#177) (31299d0)
1.12.0 (2026-07-13)
Features
1.11.0 (2026-07-13)
Features
- runner: add artifact capability and upload routes (#160) (3ea6e42)
- runner: add artifact upload capability store (#159) (921c4b0)
- runner: add self-hosted activation endpoint (#164) (72c1e8c)
- runner: add self-hosted enrollment store (#163) (7cfaadf)
- runner: add signed claim and lease routes (#158) (3c99ecf)
- runner: add signed lease protocol foundation (#155) (5ecae92)
- runner: add signed terminal result route (#162) (c26a459)
- runner: add transactional lease store (#157) (e520dda)
- runner: authorize signed terminal results (#161) (94b0e5f)
1.10.0 (2026-07-12)
Features
Bug Fixes
1.9.0 (2026-07-12)
Features
1.8.4 (2026-07-11)
Bug Fixes
1.8.3 (2026-07-11)
Bug Fixes
1.8.2 (2026-07-11)
Bug Fixes
- core: persist runner results atomically (#137) (f3b83df)
- core: reject superseded runner results (#139) (7d67ea3)
1.8.1 (2026-07-11)
Bug Fixes
- ci: accept npm 12 pack metadata (#134) (552596d)
- ci: parse npm 12 package maps (#135) (ab72c61)
- ci: verify npm tarballs directly (#132) (741df47)
1.8.0 (2026-07-11)
Features
- adapters: add Zephyr, ESP-IDF, and STM32CubeMX firmware contract adapters (#74) (1580cdc), closes #40
- add cloud database bootstrap migrations (#68) (6596105)
- add GitHub App lifecycle persistence ports (#65) (46c0228)
- add readiness runner workflow (f0c5daf)
- add readiness workflow lifecycle dispatch hooks (70a1d8c)
- add self-hosted cloud skeleton (#61) (56a571d)
- bom: add approved alternates schema and suppress single-source risk for documented substitutes (#75) (8ea5063), closes #36
- bom: add bom.risk-score rule and BOM supply-chain risk summary (#76) (7451205), closes #37
- bom: add component identity normalization and conflict detection (#78) (2af8e5a)
- bom: lifecycle status abstraction and unknown-lifecycle rule (closes #38) (10e58cb)
- bom: supplier intelligence plugin interface and static provider (closes #39) (7451dec)
- core: render hosted release run details (#113) (f5ca4a3)
- core: rule pack architecture with defineRulePack and 5 built-in presets (closes #50, closes #51) (5080332)
- core: serve signed artifact downloads (#115) (5bbf126)
- create PR readiness check run lifecycle (94944ed)
- db: add self-hosted runner registration foundation (#118) (55c64c8)
- db: add tenant-scoped audit log foundation (#119) (5b5abec)
- docs: shareable public demo scenarios with pre-generated reports (closes #49) (29db629)
- github-app: add private repo and fork PR safe mode (#117) (e967381)
- normalize GitHub App lifecycle events (#64) (5c60432)
- persist GitHub webhook lifecycle actions (#66) (ab060c1)
- persist GitHub webhook lifecycle actions (#67) (2b88cc5)
- release: add prototype/pilot/production release modes (#77) (0e15675), closes #31
- release: add release manifest schema, checksums.txt, and manifest coverage verification (#81) (eb647b6)
- release: run diff comparison and release history trend analysis (closes #27, closes #29) (5da9e97)
- report: standardize report contracts with evidence schema, SARIF tags, and JUnit timestamp (#79) (4717933)
- rules: add manufacturing.package-completeness rule (#80) (1b6d13a), closes #30
- runner: add fail-closed runner mode configuration (#120) (2bfd090)
- runner: sign callbacks and publish product readiness output (#116) (f812274)
- vendors: add generic preset profiles for prototype, assembly-ready, and production (#82) (8b0c06c), closes #32
- wire web runner client into GitHub webhook lifecycle (1589257), closes #21
Bug Fixes
- add runtime JS check run client (cb6dae6)
- ci: make release preflight reproducible (#131) (8e86187)
- ci: use release token for release pull requests (#129) (160aa63)
- copy scripts into web Docker deps stage (#70) (cc86032)
- core: authenticate runner callbacks with GitHub OIDC (#128) (7a3b6cf)
- core: support file-backed runtime secrets (#126) (9a6d679)
- core: tolerate unavailable readiness comments (#127) (ed83e7b)
- github-app: make release rollout opt-in by config (#109) (eeb9f6e)
- make cloud releases immutable (#124) (875baf8)
- make webhook lifecycle store resolvable by Next (#69) (44a219c)
- quiet idempotent deploy cleanup (#125) (7bf4078)
- relink repository installation on upsert (7ec3820)
- restrict BoardReadyOps checks to enabled repositories (ccec5d4)
- return pg query results (79bf78b)
- upsert PR webhook state before enqueue (#98) (6a00f94)
1.7.2 (2026-06-28)
Bug Fixes
- ci: rebuild dist in release-please regeneration step (a8283df)
- release: prevent version leaks from breaking the release pipeline (1def6ea)
1.7.1 (2026-06-27)
Bug Fixes
- resolve GC duplicate code, coverage thresholds, stale dist bundle (680f751)
1.7.0 (2026-06-24)
Features
- expand vendor fabrication profiles (12ae7b5), closes #236
- harden release channels and add agent planning output (#241) (bc6ad51)
- harden report finding identity (#248) (bc4a02f)
- harden waiver governance (974fa56)
- run KiCad jobsets during release prepare (#246) (d82d847)
1.6.2 (2026-06-23)
Documentation
1.6.0 (2026-06-23)
Features
- action: add app-style release review pull request comment (#228) (f9f6960)
- adapters: add firmware contract adapter ecosystem with Arduino adapter (#225) (2aae098)
- bom: add RoHS/REACH compliance intelligence (#224) (7d1a1db)
- cli: add generate command for first-party KiCad outputs (#211) (1e81a46)
- core: add configurable release policy engine (#219) (a73a832)
- core: add waivers and approval workflow (#220) (61507fa)
- release: add manufacturer handoff package command (#215) (42fb449), closes #196
- release: add release prepare workflow command (#212) (b52c947)
- release: add release-to-release diff engine (#218) (1ad6cdd), closes #199
- release: add signed manifest provenance and verification (#222) (a9e0945)
- release: upgrade evidence bundle to structured v2 release record (#214) (99495b9), closes #195
- report: add explainable vendor readiness score (#216) (f7f4314)
- report: turn the HTML report into a release dashboard (#217) (d3263d0), closes #198
- rules: expand DFM/DFA rule corpus (#223) (f343017)
Bug Fixes
Documentation
1.5.2 (2026-06-21)
Documentation
- add DeepWiki badge (f790a0a)
1.5.1 (2026-06-21)
Bug Fixes
1.5.0 (2026-06-21)
Features
- add first DFM and DFA rules (#175) (18e4095)
- add hierarchical schematic graph (#172) (f0de008), closes #157
- add release evidence bundles (131d6b6)
- add release evidence bundles (f2210e8)
- add typed KiCad project model (#170) (c3fc247), closes #156
- add vendor profiles (3bd1034)
- add vendor profiles (4615be6)
- core: add plugin permission model (#185) (b2ea35d)
- rules: add firmware pin contract check (#186) (6be16a3)
Bug Fixes
Performance
Documentation
- clarify release readiness positioning (#182) (b59bfbb)
- improve dark navigation accessibility (#187) (31d0c9f)
Tests
CI
- avoid blocking on stale review threads (#184) (15f0522)
- route checks by change risk (#183) (c4654b4)
1.4.6 (2026-06-16)
Bug Fixes
- cli: remove unused exports flagged by knip (830415a)
1.4.5 (2026-06-15)
Bug Fixes
- deps: resolve transitive npm audit findings (47845c0)
- deps: update esbuild to 0.28.1 to fix GHSA-gv7w-rqvm-qjhr (high) (ef014e0)
- resolve CHANGELOG, pnpm 11.5.3, action output paths, refresh docs (f4ab558)
Code Refactoring
- cli,report,docs: split oversized modules, retire kicad plugin, refresh release docs (936ec68)
1.4.4 (2026-06-09)
Bug Fixes
- add --repo flag to gh workflow run in release-please to avoid dispatch failure (3190ec0)
- ci: use INPUT_* env vars, align Node 24, build local tarball for PRs (b5d85ba)
Documentation
- update stale version references to v1.4.3 (6f66c4b)
CI
- align branch protection ruleset with live GitHub configuration (c1eb9e3)
1.4.3 (2026-06-05)
Bug Fixes
- ci: restore npm publish release handoff (#120) (45c41a0)
- ci: skip floating tags for manual npm backfills (6fcb644)
- ci: support historical npm backfills (#121) (0975629)
- regenerate dist bundles and release history for v1.4.2 (#112) (4dd98c5)
1.4.2 (2026-06-04)
Bug Fixes
- regenerate dist bundles and release history for v1.4.1 (2734365)
1.4.1 (2026-06-03)
Bug Fixes
- restore Unreleased section in CHANGELOG.md (1c0da85)
- restore Unreleased section in CHANGELOG.md (05fbc8d)
- simulate unavailable kicad-cli in gate requirement test (c19c0fc)
- simulate unavailable kicad-cli in gate requirement test (69d26b5)
CI
- add branch protection ruleset for main (a21a4ef)
- add branch protection ruleset for main (9f0367c)
- add branch protection ruleset for main (#107) (a21a4ef)
1.4.0 (2026-06-03)
Features
- cli: define stable JSON diagnostics contract with status and exitCode (b90be1a)
Bug Fixes
- align UV_VERSION in publish-npm.yml and disable prerelease in release-please-config (c64f1e3)
- repair CHANGELOG Unreleased positioning and regenerate dist/docs (b90be1a)
- repair CHANGELOG Unreleased positioning and regenerate dist/docs after release-please merge (d83cfb4)
- skip kicad-plugin integration tests when plugin dir not present (327deca)
- update action-inputs-docs generator source to v1.3.0 so gc passes (aa49679)
Code Refactoring
- split more-coverage.test.ts into domain-specific coverage files (b86b10b)
CI
- docs: replace manual Pages deploy with actions/deploy-pages@v5.0.0 (161e58c)
- pin all workflow runners from ubuntu-latest to ubuntu-24.04 (f60294f)
- remove 4 redundant workflow files consolidated into security.yml and ci.yml (79706e5)
1.3.0 (2026-06-03)
Features
1.2.3 (2026-06-03)
Bug Fixes
- stabilize v1.2.2 release CI (dist, KiCad metadata, CHANGELOG) (adb7bb1)
CI
1.2.2 (2026-06-02)
Bug Fixes
Documentation
- Normalize release history, generated plugin SDK API docs, and stale-doc verification (#50).
CI
- Update UV_VERSION 0.9.14 to 0.11.16 (#58).
- Upgrade pnpm 11.1.3 to 11.3.0 (#60).
- Remove KiCad 9.x from integration and container matrices (#59).
- Enforce zizmor advisory scan by removing
continue-on-error(#61). - Extract docs Python dependencies to
docs/requirements.txt(#62).
1.2.1 (2026-06-02)
Bug Fixes
Documentation
- plan docs toolchain lifecycle (#86) (fe20a0e)
- release: normalize release history and sdk api (#87) (d5e0bad)
Tests
1.2.0 (2026-05-30)
CI
- Add manual npm publish dispatch and release-tag retry paths (11113be, 2132170, 6b9b9e0).
- Make npm publish retry idempotent and harden manual tag repair (7aacbed, a791ffe).
- Add manual container publish dispatch for already-published versions (704b2ec).
Documentation
- Record v1.1.0 package parity verification (#69).
Dependencies
- Update knip to v6.14.2 and pin dependency versions (#71, 3724c78).
- Update non-major Vitest and coverage packages to v4.1.7 (#76).
Maintenance
1.1.0 (2026-05-26)
Features
- Add fabrication diffs in PR comments and validate the GitHub Action marketplace listing (0d9dc32, 85a4dc7).
- Add CLI fix automation, doctor diagnostics, and i18n infrastructure (dad705b, 514d606, #21).
- Add finding remediation metadata, gate semantics, suppressions, baselines, structured logging, notifier hooks, and multi-project workspace support (1bca167, 8c8a9bf, 846357f, 6b10f13, c535bed, 8c27166).
- Add plugin SDK and loader plus the KiCad PCM editor plugin (0589294, 96eb42a).
- Add binary distribution and full container Action release pipelines (485c25c, 71f83b0).
- Add accessible HTML reports, CycloneDX hardware SBOM output, enriched SARIF context, richer rule metadata, and manufacturing output explanations (#20, #31, #17, 0773732, 533938c).
Bug Fixes
- Emit configured JUnit reports (ee4846f).
Documentation
- Add license compliance notices, structure verifier documentation, and contributing governance docs (6087066, cf14cf7, 95852af).
- Record clean consumer channel verification, reference synchronization, and copy-paste audit gates (5667f1b, 4efcd6d, d3e74b0).
Tests
- Align CLI version expectations, add fixture regression coverage, cover cross-platform paths, enforce docs accessibility, and add coverage and mutation gates (90478fc, e692578, #19, da3a370, 9446b77).
CI
- Enforce compatibility matrix drift, action example pinning, Node version coverage, Scorecard publishing, Trivy pin repair, binary release asset hardening, and release self-validation (#33, 02b55c5, aa52ed6, 800feb1, d8e7ac4, a049987, 8e5bdbd, 42a4a5d).
1.0.2 (2026-05-21)
Maintenance
- Refresh generated artifacts and mark the CLI bundle executable (1cdcdcf, c77df5c).
- Align release metadata for v1.0.2 (15e7890, 9210bca).
1.0.1 (2026-05-21)
Maintenance
1.0.0 (2026-05-21)
Added
- Initial BoardReadyOps CLI and GitHub Action release for KiCad hardware production-readiness checks.
- KiCad DRC/ERC normalization, BOM checks, pinmap validation, manufacturing checks, design sanity checks, release preflight rules, and JSON/SARIF/Markdown/JUnit report outputs.
- Node 24 GitHub Action runtime, committed CLI/action bundles, coverage gates, mutation testing, property tests, SBOM generation, Gitleaks, OSV, CodeQL, Scorecard, Trivy, and npm provenance release workflows.