Skip to content

Release History

This page is generated from the repository changelog so release documentation stays aligned with published versions.

All notable changes to BoardReadyOps are recorded here.

Unreleased

1.68.3 (2026-10-03)

Bug Fixes

  • ci: add bounded cloud repository commissioning (#910) (e957b75)
  • ci: bootstrap legacy rollout policy safely (#911) (a68635c)
  • ci: expose aggregate deploy disk diagnostics (#907) (8df1080)
  • ci: follow Compose base-file precedence (#912) (ae184cb)
  • ci: harden release-policy mount verification (#914) (621fd85)
  • ci: make low-space rollback retention selectable (#908) (a642074)
  • ci: persist commissioned release policy across deploys (#913) (430ca08)
  • ci: reclaim build cache before low-disk deploy (#932) (fc026e3)
  • ci: unblock cloud deploy with opt-in rollback retention (#906) (6df9326)
  • ci: verify security headers after production deploy (#933) (7c66f7a)
  • cloud: repair repository action dispatch path (#904) (f616b53)
  • deps: remediate current security advisories (#931) (e7735e9)
  • deps: remove unpatched dev-only transitive advisories (#934) (6fc0bce)
  • web: add baseline browser security headers (#923) (c945397)
  • web: avoid unsupported ingestion default (#919) (932db3b)
  • web: collapse duplicate contract setup preset (#929) (7963a49)
  • web: contextualize repeated action labels (#925) (31869f4)
  • web: explain run review release lifecycle (#935) (43c20ed)
  • web: gate deliveries on validated revisions (#921) (765c9ad)
  • web: make setup readiness actionable (#917) (1156d98)
  • web: persist repository onboarding state (#915) (fca265c)
  • web: route Workspace settings to access settings (#924) (a80146a)
  • web: verify workspace member identities (#918) (d203dcf)

1.68.2 (2026-09-25)

Bug Fixes

  • web: allow full Google preview snippets (#845) (d5014e6)

1.68.1 (2026-09-24)

Bug Fixes

1.68.0 (2026-09-22)

Features

  • complete 2026-09-22 assurance hardening program (#835) (2b26d04)

1.67.0 (2026-09-22)

Features

  • mfg: complete trustworthy release gate validation rules (#832) (f643d0f)

1.66.1 (2026-09-21)

Bug Fixes

  • ci: classify type-only mutation targets semantically (#829) (ad11cd7)

1.66.0 (2026-09-18)

Features

  • release: add verifiable hardware release passport v1 (#448) (#827) (ca84ca7)

1.65.1 (2026-09-18)

Bug Fixes

1.65.0 (2026-09-18)

Features

  • manufacturing: implement footprint mount-type parsing and paste coverage rule (#784, #770) (#822) (10785fa)

1.64.0 (2026-09-15)

Features

  • report: say that the SBOM's firmware scope is the repository, not a board (#814) (7e2e373), closes #798

Bug Fixes

  • cloud: name the repository in an advisory notification, not its UUID (#815) (27f64b6)

1.63.0 (2026-09-15)

Features

  • cloud: tell someone when a firmware advisory is found (#812) (f4194b7)

1.62.1 (2026-09-15)

Bug Fixes

  • web: say why a dashboard action failed, and typecheck the app that holds it (#810) (74d5b2f), closes #800

1.62.0 (2026-09-15)

Features

  • cloud: scan firmware identifiers on a timer, and count what was not looked at (#808) (53772df), closes #755 #804

1.61.0 (2026-09-15)

Features

  • cloud: ask OSV and NVD, without letting three answers become one (#803) (47deb14)

1.60.1 (2026-09-15)

Bug Fixes

  • core: stop a finding's fingerprint depending on the machine's locale (#805) (aae024f), closes #795

1.60.0 (2026-09-15)

Features

  • db: persist firmware dependencies, and send the BOMs that never arrived (#801) (46040a4), closes #800

1.59.0 (2026-09-15)

Features

  • report: give a pinned ESP-IDF version a CPE in the device SBOM (#797) (d89fd63), closes #785

1.58.0 (2026-09-15)

Features

  • report: put firmware dependencies in the device SBOM (#793) (3ed040f), closes #785

1.57.0 (2026-09-15)

Features

  • mfg: flag a copper side with no solder mask (#775) (58fb82a)

1.56.0 (2026-09-15)

Features

  • report: say whether an SBOM component's identifier can be looked up (#790) (538e961), closes #785

Bug Fixes

  • governance: keep the documentation label on documentation changes (#791) (a968b0c)

1.55.0 (2026-09-15)

Features

  • rules: read ESP-IDF dependencies and say which cannot be looked up (#786) (a7ff772), closes #785

Bug Fixes

  • ci: give the supply-chain trust check room to finish its fetches (#789) (49a0964), closes #787

1.54.0 (2026-09-15)

Features

  • cloud: tell a supply alert which boards it affects (#781) (3a34443)

1.53.0 (2026-09-15)

Features

  • db: answer which shipped boards contain a part (#778) (771c3d2)

Bug Fixes

  • report: add the evidence summary to the findings schema (#777) (4bd2829)

1.52.0 (2026-09-15)

Features

  • report: show whether the verdict was measured or inferred (#768) (b4ac1f3)

1.51.0 (2026-09-15)

Features

  • vendors: make a manufacturing profile say where its numbers came from (#773) (e8bc4c3)

1.50.1 (2026-09-15)

Bug Fixes

  • mfg: compare drill diameters instead of matching digits in text (#769) (e523cd0)

1.50.0 (2026-09-15)

Features

  • mfg: let a gerber file say what it is, instead of reading its name (#766) (05a63e0)

1.49.0 (2026-09-15)

Features

  • mfg: read the drill files instead of trusting their names (#764) (79482a3)

1.48.0 (2026-09-14)

Features

  • cloud: let an operator resolve a workspace slug, and record the demo corpus licence (#760) (a3fae17)

1.47.1 (2026-09-14)

Bug Fixes

  • web: say which namespace the slug collides in, and stop claiming a base-run diff (#750) (9ea60ee)

1.47.0 (2026-09-14)

Features

  • web: send the landing page somewhere the product is running (#743) (e453b42)

1.46.0 (2026-09-14)

Features

  • web: page the long lists and name what the short ones assume (#740) (e956f4d)

1.45.0 (2026-09-14)

Features

  • web: answer four questions the product left hanging (#738) (3430a90)

1.44.0 (2026-09-14)

Features

  • web: let people undo what the create forms made (#732) (6b41836)

1.43.1 (2026-09-14)

Bug Fixes

  • web: stop the review search field collapsing to nothing (#733) (7de4e57)

1.43.0 (2026-09-14)

Features

  • wire the product's real capabilities to the dashboard, and tell people what it finds (#729) (5192fcf)

1.42.1 (2026-09-10)

Bug Fixes

  • web: give labelled panels region semantics (#726) (1686379)

1.42.0 (2026-09-10)

Features

  • web: complete settings administration (#724) (f5f5b8d)

1.41.5 (2026-09-10)

Bug Fixes

  • web: polish billing copy and setup touch targets (#722) (3548d5a)

1.41.4 (2026-09-10)

Bug Fixes

1.41.3 (2026-09-09)

Bug Fixes

  • ci: skip lint-fast on release-please transients (#718) (85db042)

1.41.2 (2026-09-09)

Bug Fixes

  • core: avoid code construction in process fixture (#716) (40949de)

1.41.1 (2026-09-09)

Bug Fixes

1.41.0 (2026-09-09)

Features

  • cloud: auto-probe repository setup after merge (#706) (44b625a)

1.40.1 (2026-09-08)

Bug Fixes

  • cloud: terminalize release prepare setup rejection (#704) (6bceac2)

1.40.0 (2026-09-08)

Features

  • cloud: wire durable release preparation (#702) (908b832)

1.39.1 (2026-09-08)

Bug Fixes

  • cloud: execute GitHub slash commands durably (#697) (ac74b8e)
  • cloud: keep Check Run actions within GitHub limits (#693) (6163cc7)
  • cloud: stop unconfigured runs before dispatch (#695) (e285059)
  • cloud: wire zero-touch setup actions (#696) (eae2640)

1.39.0 (2026-09-08)

Features

  • billing: implement Stripe subscription entitlement projection (W19) (#638) (3e4513b)
  • bom: supply-watch provider resilience and pricing snapshot (W11) (#639) (12bc104)
  • bom: turn /parts into a real component inventory (#667) (73718c7)
  • cli: render a human-readable release certificate on release verify (#578) (5018566)
  • cloud: github capability model and safe mutation foundation (PR 1) (#686) (e618967)
  • cloud: let a tenant read their own audit log (#679) (69f15c1)
  • cloud: let a workspace have more than one person in it (#677) (5c43423)
  • cloud: make /deliveries show and issue the guest links it names (#672) (c0a289d)
  • cloud: one-click repository setup and remediation pr engine (PR 2) (#687) (592923a)
  • cloud: review and workflow-aware lifecycle webhooks and hooks (#690) (19fd05f)
  • core: map findings to GitHub Check Run annotations (W15) (#604) (e19304e)
  • core: show which release-diff items changed and fix an undercount bug (#579) (1bbd169)
  • core: wire GitHub Check Run annotations end to end from findings (#623) (9608455)
  • db: query which boards currently reference an MPN (W11) (#611) (28c3931)
  • db: thread the GitHub webhook delivery id onto release_runs (W29) (#615) (6a2ae84)
  • evidence: show the real evidence ledger instead of describing one (#666) (1865346)
  • governance: add independent clean-room reproducible-build verification (#593) (a3a0019)
  • governance: canonical PASS/FAIL/CONDITIONAL/UNKNOWN decision vocabulary (W06) (#602) (b1bd928)
  • kicad: close W03 hostile-input size/DoS guard gap (#625) (4df5df3)
  • release: add provenance fields to the generation manifest (W04) (#612) (1f541fb)
  • release: classify worsened/improved findings in release diffs (W08) (#608) (fd16684)
  • release: signing-key rotation, revocation & trust-store model (W07) (#603) (4bee976)
  • release: wire --trust-store into release verify CLI (W07) (#605) (9bc607a)
  • rules: show the 44 checks the engine runs (#676) (38c50a4)
  • web: add authenticated Unlighthouse UI audits (#629) (7cd6efe)
  • web: add CSV/JSONL audit export formats and tamper-evidence digest (#622) (0f53357)
  • web: add dead-letter admin dashboard (#635) (3016dee)
  • web: enforce separation of duties on review approvals (W14) (#610) (c6a486a)
  • web: give the run readiness score its own copper accent (#627) (49c28ec)
  • web: migrate UI to Tailwind and shadcn design system (#654) (abe5f8e)
  • web: premium UI — new brand, design system, and real data behind the settings and review surfaces (#657) (899c39a)
  • web: premium UI — preset switcher, YAML highlighting, micro-interactions (#656) (b7af0b2)
  • web: rate-limit failed bearer-token authentication attempts (#620) (2f69f61)
  • web: refine premium product UI (#633) (7b90cee)
  • web: support GitHub Check Run annotations with pagination (W15) (#598) (5d014b4)
  • web: systematize the brand mark's brass accent as a design token (#626) (8a7d6b6)

Bug Fixes

  • action: give the action the token its own defaults need (#671) (7a72a8f)
  • ci: bound production build cache growth (#682) (19b0ff7)
  • ci: fail closed on stale cloud deploy topology (#645) (01783d9)
  • ci: fix process cancellation test flakiness and resolve web code smells (#655) (4ed1364)
  • ci: reset cloud-deploy checkout to origin/main instead of ff-only merge (#651) (064a96c)
  • ci: resolve remaining SonarQube regex-backtracking findings (#583) (bf1ec3e)
  • ci: restore QA nightly browser and visual checks (#647) (1ba315a)
  • ci: retire superseded runtime images so the deploy host stops growing (#670) (79c28d5)
  • ci: stop cloud-deploy from building into a full disk (#662) (56167cc)
  • cloud: clear the SonarCloud and Codecov findings on this branch (#668) (0aa7b50)
  • cloud: drop the anchored alternation, and stop a test that could pass vacuously (#669) (0d2862e)
  • cloud: scope the v2 workspace API to the caller's own workspaces (#659) (15a7f31)
  • contracts: schema-by-schema security triage of runner-protocol .strict() (W02) (#600) (f58cb50)
  • core: address CI/SonarQube follow-ups for release-diff detail (#580) (aa55c7d)
  • core: combine sequential Array#push() calls and mark AuditReport fields readonly (#585) (3d3e107)
  • core: reduce cognitive complexity below SonarQube's threshold of 15 (#584) (c157a88)
  • core: resolve SonarQube RELIABILITY findings (regex backtracking, Unicode APIs) (#582) (4cd2c70)
  • db: clean up fixture rows in artifact-deletion-store-postgres.test.ts (#613) (9d60028)
  • db: resolve SonarCloud nested-ternary finding in priceBreaks parsing (W11) (#642) (bb84613)
  • deps: patch full OSV scan vulnerabilities (#632) (a767cd2)
  • docs: clarify GitHub App permission updates (#684) (aa516bd)
  • docs: correct 10 stale file references in the execution ledger, add a permanent guard (#576) (bbd3f62)
  • docs: generate the rule reference from the registry, not a copy of it (#673) (b2ae2f1)
  • docs: reject stale canary workflow pins (#683) (026de21)
  • docs: unbreak docs-build, and say which token broke it (#664) (253e540)
  • governance: add missing trailing newline to .mergify.yml (#591) (93c5f6b)
  • governance: harden Mergify ruleset integration (#588) (2ffe792)
  • governance: honest master spec provenance + reconciled W00 baseline (#590) (9cec676)
  • governance: regenerate NOTICE, correct false verify-baseline claim (#592) (519896f)
  • governance: warn on unrecognized webhook env-var names (W28) (#601) (85df05f)
  • report: show no-BOM-changes note when every BOM row is unchanged (#581) (dac2411)
  • web: drop non-interactive tabIndex flagged by SonarCloud (S6845) (#636) (f8bb770)
  • web: give every control a 44px touch target, and clear the last two Sonar findings (#660) (bfcad0f)
  • web: give the selected PCB canvas marker a real visual state (#628) (2665abd)
  • web: keep setup YAML rows stable (#681) (dab9e0b)
  • web: rate limit operator token authentication (#643) (6df0c1e)
  • web: repair invisible diff-pill text and unlabeled installation fallback (#652) (d231437)
  • web: return 404 for missing records, and clear the SonarCloud findings on #657 (#658) (ba57c4d)
  • web: return 404 not 500 for unresolvable review ids without a database (#618) (17f720b)
  • web: stop seven pages scrolling sideways on phones and tablets (#661) (82a691c)

Performance

  • web: benchmark run listing pagination (#644) (bf95ebc)

1.38.0 (2026-09-01)

Features

  • cloud: add order-independent decision fingerprint (#572) (9451f07)
  • contracts: add snapshot guard against silent public schema drift (#568) (e514fb0)
  • persistent agentic QA/E2E/a11y/visual audit infrastructure (#563) (f45050e)

Bug Fixes

  • ci: bump verified KiCad and Node.js patch baselines (#566) (cf2ba5b)
  • ci: point cloud-deploy.yml at the real production topology (#550) (cfadd7c)
  • core: strip a leading UTF-8 BOM when reading text files (#575) (a8bce03)
  • deps: pin browserslist past GHSA high-severity advisory (#567) (26aa9c7)
  • deps: pin mysql2 past GHSA-rgwj-5xj2-c3m3 (#564) (0831efc)
  • review: accessible Dialog primitive, policy delete confirm, cancel reset (#555) (85c4920)
  • review: resolve quality gate findings, redos patterns, and complexity (#552) (5939a1c)
  • review: stop policy metrics overclaiming enforcement scope/state (#556) (7676d86)
  • review: UI/UX audit P0/P1 fixes — policy gate, discussion persistence, a11y, URL tabs (#554) (f1a9a15)
  • web: active nav state, duplicate H1s, count accuracy (P2 batch) (#557) (8123c4f)
  • web: add browser titles to settings pages missing them (P3-02) (#560) (885a6e6)
  • web: dedupe run page generateMetadata (SonarCloud duplication gate) (#562) (78d642f)
  • web: fake search hint, run repo link, missing 404 H1s (P2 batch) (#558) (1873a59)
  • web: give run sub-pages section-specific browser titles (P3-04) (#561) (e674849)
  • web: persist sidebar collapse state across navigation (#559) (8674f74)

1.37.0 (2026-08-30)

Features

  • storage: preview artifact expiry candidates (#542) (a6a32e7)

Bug Fixes

  • governance: sync merge gates with live ruleset (#541) (b2b4c9f)
  • web: expose trust destination in landing nav (#540) (0371cb3)

1.36.0 (2026-08-30)

Features

  • docs: add agent discovery surfaces (#536) (4ca4b65)
  • docs: add agent-aware edge negotiation (#539) (45f5132)
  • marketplace: prepare GitHub Marketplace listing, webhook intake, and legal documentation (#524) (d3b63cd)
  • web: add public agent discovery and SEO metadata (#535) (d8aa8d0)

Bug Fixes

  • ci: avoid Windows toolchain shell injection (#532) (da4df1f)
  • ci: honor full production soak duration (#533) (40b6220)
  • ci: repair Mergify file label rules (#531) (bd88079)
  • cloud: enforce Marketplace cancellation lifecycle (46d2bca)
  • docs: align Marketplace permission model (#530) (16d94de)
  • review: persist governance state and harden approval decisions (#527) (2911a14)
  • web: align governance copy with evidence model (#528) (0b77922)

1.35.0 (2026-08-27)

Features

  • core: look up component lifecycle through Nexar under customer credentials (#495) (727a468)
  • core: resolve component intelligence per installation (#492) (a2fa189)
  • core: run the supply watch pass on a schedule, gated by the plan (#490) (30edd36)
  • core: store per-installation provider credentials, encrypted at rest (#493) (debc6ae)
  • governance: persist and enforce organization review policies (#520) (0fbbb5c)
  • report: answer the question the run page was opened to answer (#499) (c54bed6)
  • report: give customers a dashboard of the repositories being watched (#498) (9dcbee5)
  • report: give the ledger a daylight palette (#508) (d239fee)
  • report: let customers supply their own component provider credentials (#496) (7c583a6)
  • report: say it in plain words, and put the spacing back on the scale (#500) (fb324a6)
  • review: add the missing finding-assignment UI control (#521) (f2fa98c)
  • review: Hardware Review & Evidence OS (#518) (411fbf4)
  • web: Foundry Editorial product redesign (#523) (f35addc)

Bug Fixes

  • billing: close timing-unsafe Stripe signature check merged in #518 (#519) (fdffd5a)
  • ci: admit a quarantined release instead of failing the whole task (#510) (e7d0647)
  • core: stop rescheduling a reconciliation item past its attempt budget (#506) (e68e851)
  • db: fix a review-creation bug that made new reviews impossible (#522) (19cdc00)
  • report: finish the copy pass the first one left half done (#504) (356d9d6)
  • report: give a signed-in reader a way into their dashboard (#503) (96776cd)
  • report: rewrite the copy on the screens nobody curls (#507) (c1f477b)
  • report: rewrite the footer that sits under every page (#505) (ae3eacc)
  • report: show signed-in state on the landing page (#497) (25cdd28)
  • standalone Docker image was silently missing pg (#517) (278a570)

1.34.0 (2026-08-25)

Features

  • board identity, BOM snapshots, and continuous supply watch (#480) (0010b8f)
  • cloud: add production readiness soak monitor (#466) (113d57c)
  • core: meter supply watch enrolment against the plan (#489) (b35a0d6)
  • deliver premium product UI experience (#475) (92b194a)
  • docs: brand the canonical documentation site (#474) (715b3c1)
  • release: authorize dashboard viewers so private runs are reachable (#481) (1fc4f46)
  • unify premium product experience (#469) (94326b0)
  • web: add terminal circuit-board marketing landing page (#468) (a5399d4)

Bug Fixes

  • ci: align Mergify queue and merge conditions (#472) (fd02e60)
  • ci: force serial Mergify in-place checks (#473) (f1abda9)
  • ci: make Mergify queue checks single-step (#470) (2d99fee)
  • core: complete Check Runs for terminal runs that never reported (#483) (5e19ec0)
  • core: let a signed result correct a verdict that was only inferred (#484) (d4edd2c)
  • core: stop blanking installation identity, and make db:migrate run on Windows (#488) (7d0792b)
  • report: show sign-in state in every navigation bar (#482) (01cf6d5)
  • test: honor fixture runRules in unit helpers (#471) (a1d7aa7)
  • use typed error for invalid environment values (#476) (0aa398c)

1.33.0 (2026-08-22)

Features

  • add PR-native hardware change impact v1 (#464) (6674db5)

1.32.1 (2026-08-22)

Bug Fixes

  • core: simplify release artifact collection (#462) (9fbf080)

1.32.0 (2026-08-21)

Features

  • cloud: add production maintenance service (#457) (202f4b3)

Bug Fixes

  • ci: bind target SHA in Actions OIDC audience (#454) (a3fd3bf)
  • ci: keep maintenance contract portable (#460) (03cae04)
  • ci: make Renovate validation hermetic (#459) (35419cc)
  • core: trust scoped production checkout (#458) (eadca80)

1.31.6 (2026-08-19)

Bug Fixes

  • deps: make Renovate store isolation hermetic (#436) (f41d620)
  • deps: stabilize Renovate CI runtime (#438) (3e790e0)

1.31.5 (2026-08-19)

Bug Fixes

  • deps: isolate Renovate pnpm store (#435) (6b10f95)
  • deps: keep Renovate updates deterministic (#433) (536ef54)

1.31.4 (2026-08-19)

Bug Fixes

  • cloud: retire stale production origin defaults (#427) (6bd0c5b)

1.31.3 (2026-08-18)

Bug Fixes

  • cloud: keep pg external in runtime bundles (#423) (9c7c1b4)

1.31.2 (2026-08-18)

Bug Fixes

  • ci: speed up clean-tree content scans (#413) (1a6631b)

1.31.1 (2026-08-17)

Bug Fixes

  • deps: update dependency next to v16.2.12 (#405) (7e08e2f)

1.31.0 (2026-08-17)

Features

  • core: persist artifact evidence metadata (#391) (e1acd38)
  • core: surface artifact deletion lifecycle (#360) (1f080b8), closes #26
  • report: link dashboard to GitHub Actions runs (#358) (e58fcdb)

Bug Fixes

  • ci: fail pre-push checks closed (#397) (df7723c)
  • ci: force Mergify in-place queue checks (#366) (e2a346c)
  • ci: isolate source guards from mutation runs (#407) (aadfa8a)
  • ci: reduce compatibility drift complexity (#372) (d25671b)
  • ci: reduce i18n check complexity (#373) (ff9d203)
  • ci: reduce synthetic canary complexity (#386) (2c47cc6)
  • ci: reduce worker fleet load complexity (#374) (505a686)
  • ci: regenerate dependency artifacts in Renovate (#406) (341098e)
  • ci: remediate Sonar and Mergify findings (#364) (3ee4b08)
  • ci: resolve npm pack via Node installation (#367) (48f9a9d)
  • ci: retry transient Corepack bootstrap (#356) (2d6a8ca)
  • ci: simplify npm pack metadata branching (#399) (9e6a3e7)
  • cli: keep fix plan sorting immutable (#394) (a506d10)
  • cli: reduce DNP fix planning complexity (#369) (4024ac6)
  • cli: reduce run command complexity (#375) (46d13ff)
  • core: keep pcb area sorting immutable (#396) (711a152)
  • core: keep release file sorting immutable (#401) (c922131)
  • core: keep runner fleet sorting immutable (#393) (4065c7f)
  • core: keep sexpr stack traversal immutable (#395) (918fcb8)
  • core: preserve verified runner artifacts (#359) (4757691), closes #26
  • core: reduce artifact capability complexity (#380) (b781ca5)
  • core: reduce artifact stream complexity (#381) (593e778)
  • core: reduce artifact upload complexity (#379) (fe04596)
  • core: reduce BOM MPN fix complexity (#384) (d4b99e1)
  • core: reduce check-run reconciliation complexity (#382) (075b330)
  • core: reduce lifecycle executor complexity (#371) (2df087b)
  • core: reduce repository setup complexity (#378) (e0d47b5)
  • core: reduce repository setup probe complexity (#385) (0eaa50c)
  • core: reduce result route complexity (#387) (ad9f6af)
  • core: reduce run summary complexity (#370) (27dbc18)
  • core: reduce runner claim complexity (#376) (94a2a61)
  • core: reduce runner worker complexity (#383) (9aa6860)
  • core: reduce setup probe callback complexity (#368) (ae00c9d)
  • core: reduce Sonar complexity in core parsers (#365) (49b1e83)
  • core: reduce webhook lifecycle complexity (#377) (734a8e9)
  • core: simplify runner request text comparison (#400) (0a4dea9)
  • core: simplify STM32 designator fallback (#398) (d661c44)
  • core: use semantic live status output (#392) (10d5248)
  • deps: patch deepmerge-ts in Prisma config (#409) (7d3e2d5)
  • deps: remove vulnerable extract-zip path (#408) (800ebcd)
  • deps: update vulnerable nanoid to 3.3.18 (#402) (48be1f9)

1.30.3 (2026-08-09)

Bug Fixes

  • cli: add metadata-only runner artifact mode (#352) (5a7fba3)
  • cli: cancel in-flight runner analysis on shutdown (#351) (6fb5ee9), refs #41
  • core: clean crash-orphaned runner workspaces (#353) (39af849)
  • deps: pin patched nanoid transitive (#350) (37cb00c)
  • release: harden npm trusted publishing (#348) (fffa1cd), refs #334
  • release: pin npm publish to main workflow identity (#354) (78aeeb4), refs #334

1.30.2 (2026-08-08)

Bug Fixes

  • ci: harden toolchain bootstrap isolation (#342) (204ebf5)
  • ci: restore dependency vulnerability gates (#336) (257f16e)
  • ci: use Git-compatible null config paths (#340) (2944474)

1.30.1 (2026-08-05)

Bug Fixes

  • core: preserve directory symlinks in portable copies (#328) (157b4a5)
  • quality: resolve SonarQube code smells and refactor cognitive complexity (#320) (48eaf5c)

1.30.0 (2026-08-03)

Features

1.29.0 (2026-08-02)

Features

  • core: permanently revoke runner registrations (#316) (7a21f27), refs #41

1.28.0 (2026-08-02)

Features

  • cloud: expose aggregate runner fleet health (#314) (71e0f3b), refs #41

1.27.1 (2026-08-02)

Bug Fixes

1.27.0 (2026-08-02)

Features

1.26.1 (2026-08-02)

Bug Fixes

  • cloud: bind target callbacks to exact revision (#306) (8f8c476), refs #154

1.26.0 (2026-08-02)

Features

1.25.1 (2026-08-01)

Bug Fixes

  • ci: keep release pull request history verified (#298) (a00cde0)
  • ci: satisfy release rewrite reliability checks (#299) (4b89274)
  • core: retain bounded control-plane history (#295) (7218206)

1.25.0 (2026-08-01)

Features

  • core: validate representative control-plane load (#293) (75c38ea)
  • core: verify PostgreSQL backup restores (#290) (ea38a8b)

Bug Fixes

  • ci: pin readiness workflow to v1.24.1 (#288) (1d8bd78)
  • core: make backup verification CLI runnable (#291) (01c42c3)

1.24.1 (2026-08-01)

Bug Fixes

  • core: force safe-mode workspace cleanup (#284) (a4e7a0f)
  • core: purge terminal ephemeral records (#282) (27b1de4)
  • core: restrict safe-mode runtime extensions (#286) (5d49715), refs #42
  • core: surface trust restrictions in GitHub (#285) (8eb870d), refs #42
  • web: bind dashboard reads to tenant scope (#287) (6812cef)

1.24.0 (2026-07-31)

Features

Bug Fixes

  • core: bind callbacks to trust snapshots (#281) (485ff4e)
  • core: bind runner leases to trust snapshots (#278) (a9691f0), refs #42
  • core: expire stale control-plane credentials (#280) (96013db)
  • core: fail private dashboards closed (#276) (cb9cfdc)
  • core: purge expired runner request nonces (#277) (2d8ce0f), refs #44
  • core: suppress safe-mode artifact uploads (#279) (aa0a83d), refs #42

1.23.0 (2026-07-30)

Features

1.22.0 (2026-07-29)

Features

1.21.0 (2026-07-29)

Features

  • core: configure artifact capability expiry (#261) (d40b366), relates to #44
  • core: configure webhook retention (#259) (62db74f), relates to #44

1.20.0 (2026-07-29)

Features

  • core: add tenant-scoped audit export (#252) (dd5868e)
  • core: audit artifact download starts (#254) (32454f9)
  • core: audit GitHub App lifecycle changes (#255) (ba36ebd)
  • core: audit installation suspension lifecycle (#256) (588ed06)
  • core: audit replaced artifact records (#258) (7c111e1)
  • core: expose release decision audit summary (#257) (7cf8ed8)

1.19.0 (2026-07-27)

Features

  • ci: add cloud coverage and monorepo verification (#230) (78e1ab5)
  • ci: add reproducible repository toolchain (#228) (71a694f), closes #220
  • ci: add synthetic target-repository canaries (#238) (8e73aee)
  • cloud: emit control-plane SLI snapshots (#214) (a61e88a)
  • core: add control-plane SLO alerting (#235) (7eb6bb7)
  • core: add tenant-scoped dead-letter operator API (#233) (d696f20)
  • core: add versioned release-run transitions (#242) (9b4e6aa)
  • core: guard Check Run creation transitions (#245) (4dba216)
  • core: guard release-run supersession (#247) (2266b4c)
  • core: guard runner lease transitions (#249) (1aae59b)
  • core: guard runner result transitions (#248) (3ebca30)
  • core: guard workflow dispatch transitions (#244) (710fbbb)
  • core: guard workflow reconciliation transitions (#246) (9749ce6)
  • core: reconcile GitHub Check Run drift (#236) (2d07e25)
  • core: reconcile missed GitHub workflow callbacks (#234) (1f8253d)
  • core: reconcile webhook inbox and lifecycle job drift (#237) (284b483)

Bug Fixes

  • ci: harden supply-chain and container policies (#231) (a7b5ed0)
  • ci: make NOTICE verification immutable (#223) (9262984)
  • ci: persist solo-maintainer review policy (#232) (1e7adcf)
  • deps: patch OSV dependency findings (#240) (4078861)
  • deps: update dependency next to v16.2.11 [security] (#229) (63d0771)
  • governance: require reviewed main pull requests (#224) (4cae73f)
  • governance: restore signed commit enforcement (#225) (7a44e1f)
  • security: add aggregate merge gate (#226) (02038db)

1.18.0 (2026-07-22)

Features

  • db: add reconciliation operations foundation (#212) (d419695)

1.17.0 (2026-07-22)

Features

  • cloud: harden crash-recoverable worker runtime (#210) (a7a2f41), closes #189

1.16.0 (2026-07-22)

Features

  • cloud: dispatch transactional outbox effects (#208) (3146836), closes #188
  • db: add atomic release-run outbox producer (#207) (e8721d1)
  • db: add transactional outbox foundation (#205) (e919758)

Bug Fixes

  • deps: patch Hono adapter and sharp advisories (#209) (9ca259c)

1.15.0 (2026-07-22)

Features

  • security: adopt tokenless OSV dependency scanning (#203) (8429fe3)

1.14.0 (2026-07-21)

Features

  • ci: add dependency and security automation (#193) (63e259e)
  • ci: expand Codecov observability (#201) (ae27422)
  • ci: provision admin database URL (#183) (b5c9ab3)
  • ci: run readiness in target repositories (843d0ca)
  • ci: standardize workflow security linting (#202) (a073226)
  • core: durably accept GitHub webhooks (#198) (cd1f6a9)
  • core: establish VPS-independent cloud runtime foundation (#192) (ac58985)
  • report: improve PR readiness output (#200) (6909e6b)

Bug Fixes

  • ci: enable repository config scoping (27e40cf)
  • ci: enable repository project scoping (6c1fc5c)
  • ci: pin resolvable Renovate action (#195) (b75e4c1)
  • ci: support rollout policy files (#186) (6c2a7b2)

1.13.0 (2026-07-14)

Features

  • cli: add customer self-hosted runner loop (#180) (68307be)

Bug Fixes

1.12.1 (2026-07-13)

Bug Fixes

1.12.0 (2026-07-13)

Features

  • runner: add execution routing policy (#171) (3bcea5f)

1.11.0 (2026-07-13)

Features

  • runner: add artifact capability and upload routes (#160) (3ea6e42)
  • runner: add artifact upload capability store (#159) (921c4b0)
  • runner: add self-hosted activation endpoint (#164) (72c1e8c)
  • runner: add self-hosted enrollment store (#163) (7cfaadf)
  • runner: add signed claim and lease routes (#158) (3c99ecf)
  • runner: add signed lease protocol foundation (#155) (5ecae92)
  • runner: add signed terminal result route (#162) (c26a459)
  • runner: add transactional lease store (#157) (e520dda)
  • runner: authorize signed terminal results (#161) (94b0e5f)

1.10.0 (2026-07-12)

Features

Bug Fixes

  • core: tolerate unavailable readiness comments (#148) (f3cc4ec)

1.9.0 (2026-07-12)

Features

  • core: persist versioned runner results (#144) (8f8b6b9)

1.8.4 (2026-07-11)

Bug Fixes

  • release: use publisher token for GHCR (#142) (7efd10c)

1.8.3 (2026-07-11)

Bug Fixes

  • core: bind runner results to execution attempts (#140) (4074403)

1.8.2 (2026-07-11)

Bug Fixes

  • core: persist runner results atomically (#137) (f3b83df)
  • core: reject superseded runner results (#139) (7d67ea3)

1.8.1 (2026-07-11)

Bug Fixes

1.8.0 (2026-07-11)

Features

  • adapters: add Zephyr, ESP-IDF, and STM32CubeMX firmware contract adapters (#74) (1580cdc), closes #40
  • add cloud database bootstrap migrations (#68) (6596105)
  • add GitHub App lifecycle persistence ports (#65) (46c0228)
  • add readiness runner workflow (f0c5daf)
  • add readiness workflow lifecycle dispatch hooks (70a1d8c)
  • add self-hosted cloud skeleton (#61) (56a571d)
  • bom: add approved alternates schema and suppress single-source risk for documented substitutes (#75) (8ea5063), closes #36
  • bom: add bom.risk-score rule and BOM supply-chain risk summary (#76) (7451205), closes #37
  • bom: add component identity normalization and conflict detection (#78) (2af8e5a)
  • bom: lifecycle status abstraction and unknown-lifecycle rule (closes #38) (10e58cb)
  • bom: supplier intelligence plugin interface and static provider (closes #39) (7451dec)
  • core: render hosted release run details (#113) (f5ca4a3)
  • core: rule pack architecture with defineRulePack and 5 built-in presets (closes #50, closes #51) (5080332)
  • core: serve signed artifact downloads (#115) (5bbf126)
  • create PR readiness check run lifecycle (94944ed)
  • db: add self-hosted runner registration foundation (#118) (55c64c8)
  • db: add tenant-scoped audit log foundation (#119) (5b5abec)
  • docs: shareable public demo scenarios with pre-generated reports (closes #49) (29db629)
  • github-app: add private repo and fork PR safe mode (#117) (e967381)
  • normalize GitHub App lifecycle events (#64) (5c60432)
  • persist GitHub webhook lifecycle actions (#66) (ab060c1)
  • persist GitHub webhook lifecycle actions (#67) (2b88cc5)
  • release: add prototype/pilot/production release modes (#77) (0e15675), closes #31
  • release: add release manifest schema, checksums.txt, and manifest coverage verification (#81) (eb647b6)
  • release: run diff comparison and release history trend analysis (closes #27, closes #29) (5da9e97)
  • report: standardize report contracts with evidence schema, SARIF tags, and JUnit timestamp (#79) (4717933)
  • rules: add manufacturing.package-completeness rule (#80) (1b6d13a), closes #30
  • runner: add fail-closed runner mode configuration (#120) (2bfd090)
  • runner: sign callbacks and publish product readiness output (#116) (f812274)
  • vendors: add generic preset profiles for prototype, assembly-ready, and production (#82) (8b0c06c), closes #32
  • wire web runner client into GitHub webhook lifecycle (1589257), closes #21

Bug Fixes

  • add runtime JS check run client (cb6dae6)
  • ci: make release preflight reproducible (#131) (8e86187)
  • ci: use release token for release pull requests (#129) (160aa63)
  • copy scripts into web Docker deps stage (#70) (cc86032)
  • core: authenticate runner callbacks with GitHub OIDC (#128) (7a3b6cf)
  • core: support file-backed runtime secrets (#126) (9a6d679)
  • core: tolerate unavailable readiness comments (#127) (ed83e7b)
  • github-app: make release rollout opt-in by config (#109) (eeb9f6e)
  • make cloud releases immutable (#124) (875baf8)
  • make webhook lifecycle store resolvable by Next (#69) (44a219c)
  • quiet idempotent deploy cleanup (#125) (7bf4078)
  • relink repository installation on upsert (7ec3820)
  • restrict BoardReadyOps checks to enabled repositories (ccec5d4)
  • return pg query results (79bf78b)
  • upsert PR webhook state before enqueue (#98) (6a00f94)

1.7.2 (2026-06-28)

Bug Fixes

  • ci: rebuild dist in release-please regeneration step (a8283df)
  • release: prevent version leaks from breaking the release pipeline (1def6ea)

1.7.1 (2026-06-27)

Bug Fixes

  • resolve GC duplicate code, coverage thresholds, stale dist bundle (680f751)

1.7.0 (2026-06-24)

Features

  • expand vendor fabrication profiles (12ae7b5), closes #236
  • harden release channels and add agent planning output (#241) (bc6ad51)
  • harden report finding identity (#248) (bc4a02f)
  • harden waiver governance (974fa56)
  • run KiCad jobsets during release prepare (#246) (d82d847)

1.6.2 (2026-06-23)

Documentation

  • regenerate release history for the 1.6.x releases (#230) (5d06ca0)

1.6.0 (2026-06-23)

Features

  • action: add app-style release review pull request comment (#228) (f9f6960)
  • adapters: add firmware contract adapter ecosystem with Arduino adapter (#225) (2aae098)
  • bom: add RoHS/REACH compliance intelligence (#224) (7d1a1db)
  • cli: add generate command for first-party KiCad outputs (#211) (1e81a46)
  • core: add configurable release policy engine (#219) (a73a832)
  • core: add waivers and approval workflow (#220) (61507fa)
  • release: add manufacturer handoff package command (#215) (42fb449), closes #196
  • release: add release prepare workflow command (#212) (b52c947)
  • release: add release-to-release diff engine (#218) (1ad6cdd), closes #199
  • release: add signed manifest provenance and verification (#222) (a9e0945)
  • release: upgrade evidence bundle to structured v2 release record (#214) (99495b9), closes #195
  • report: add explainable vendor readiness score (#216) (f7f4314)
  • report: turn the HTML report into a release dashboard (#217) (d3263d0), closes #198
  • rules: expand DFM/DFA rule corpus (#223) (f343017)

Bug Fixes

  • ci: align coverage trigger with measured paths and harden a11y check (#221) (b9db68c)

Documentation

1.5.2 (2026-06-21)

Documentation

1.5.1 (2026-06-21)

Bug Fixes

  • docs: restore header source contrast (830eb2d)
  • docs: restore header source contrast (cb47479)

1.5.0 (2026-06-21)

Features

Bug Fixes

Performance

  • reduce bundles and enforce headroom budgets (#176) (db415e6)

Documentation

  • clarify release readiness positioning (#182) (b59bfbb)
  • improve dark navigation accessibility (#187) (31d0c9f)

Tests

  • expand mutation gates for parsers and manufacturing rules (#181) (71be7f6)

CI

1.4.6 (2026-06-16)

Bug Fixes

  • cli: remove unused exports flagged by knip (830415a)

1.4.5 (2026-06-15)

Bug Fixes

  • deps: resolve transitive npm audit findings (47845c0)
  • deps: update esbuild to 0.28.1 to fix GHSA-gv7w-rqvm-qjhr (high) (ef014e0)
  • resolve CHANGELOG, pnpm 11.5.3, action output paths, refresh docs (f4ab558)

Code Refactoring

  • cli,report,docs: split oversized modules, retire kicad plugin, refresh release docs (936ec68)

1.4.4 (2026-06-09)

Bug Fixes

  • add --repo flag to gh workflow run in release-please to avoid dispatch failure (3190ec0)
  • ci: use INPUT_* env vars, align Node 24, build local tarball for PRs (b5d85ba)

Documentation

  • update stale version references to v1.4.3 (6f66c4b)

CI

  • align branch protection ruleset with live GitHub configuration (c1eb9e3)

1.4.3 (2026-06-05)

Bug Fixes

  • ci: restore npm publish release handoff (#120) (45c41a0)
  • ci: skip floating tags for manual npm backfills (6fcb644)
  • ci: support historical npm backfills (#121) (0975629)
  • regenerate dist bundles and release history for v1.4.2 (#112) (4dd98c5)

1.4.2 (2026-06-04)

Bug Fixes

  • regenerate dist bundles and release history for v1.4.1 (2734365)

1.4.1 (2026-06-03)

Bug Fixes

  • restore Unreleased section in CHANGELOG.md (1c0da85)
  • restore Unreleased section in CHANGELOG.md (05fbc8d)
  • simulate unavailable kicad-cli in gate requirement test (c19c0fc)
  • simulate unavailable kicad-cli in gate requirement test (69d26b5)

CI

  • add branch protection ruleset for main (a21a4ef)
  • add branch protection ruleset for main (9f0367c)
  • add branch protection ruleset for main (#107) (a21a4ef)

1.4.0 (2026-06-03)

Features

  • cli: define stable JSON diagnostics contract with status and exitCode (b90be1a)

Bug Fixes

  • align UV_VERSION in publish-npm.yml and disable prerelease in release-please-config (c64f1e3)
  • repair CHANGELOG Unreleased positioning and regenerate dist/docs (b90be1a)
  • repair CHANGELOG Unreleased positioning and regenerate dist/docs after release-please merge (d83cfb4)
  • skip kicad-plugin integration tests when plugin dir not present (327deca)
  • update action-inputs-docs generator source to v1.3.0 so gc passes (aa49679)

Code Refactoring

  • split more-coverage.test.ts into domain-specific coverage files (b86b10b)

CI

  • docs: replace manual Pages deploy with actions/deploy-pages@v5.0.0 (161e58c)
  • pin all workflow runners from ubuntu-latest to ubuntu-24.04 (f60294f)
  • remove 4 redundant workflow files consolidated into security.yml and ci.yml (79706e5)

1.3.0 (2026-06-03)

Features

  • cli: define stable JSON diagnostics contract with status and exitCode (#103) (8147a1d)

1.2.3 (2026-06-03)

Bug Fixes

  • stabilize v1.2.2 release CI (dist, KiCad metadata, CHANGELOG) (adb7bb1)

CI

  • ci: add governance workflow concurrency (b1a735e), closes #100

1.2.2 (2026-06-02)

Bug Fixes

  • stabilize v1.2.1 release automation (#95) (3b493dd), closes #89

Documentation

  • Normalize release history, generated plugin SDK API docs, and stale-doc verification (#50).

CI

  • Update UV_VERSION 0.9.14 to 0.11.16 (#58).
  • Upgrade pnpm 11.1.3 to 11.3.0 (#60).
  • Remove KiCad 9.x from integration and container matrices (#59).
  • Enforce zizmor advisory scan by removing continue-on-error (#61).
  • Extract docs Python dependencies to docs/requirements.txt (#62).

1.2.1 (2026-06-02)

Bug Fixes

  • ci: normalize compatibility matrix drift (#82) (793e8ce)

Documentation

  • plan docs toolchain lifecycle (#86) (fe20a0e)
  • release: normalize release history and sdk api (#87) (d5e0bad)

Tests

  • ci: stabilize Vitest timeout on Windows (#81) (d38c8b1)

1.2.0 (2026-05-30)

CI

  • Add manual npm publish dispatch and release-tag retry paths (11113be, 2132170, 6b9b9e0).
  • Make npm publish retry idempotent and harden manual tag repair (7aacbed, a791ffe).
  • Add manual container publish dispatch for already-published versions (704b2ec).

Documentation

  • Record v1.1.0 package parity verification (#69).

Dependencies

  • Update knip to v6.14.2 and pin dependency versions (#71, 3724c78).
  • Update non-major Vitest and coverage packages to v4.1.7 (#76).

Maintenance

  • Refresh generated NOTICE artifacts after dependency updates (f56bfac, 7e4cbba).

1.1.0 (2026-05-26)

Features

  • Add fabrication diffs in PR comments and validate the GitHub Action marketplace listing (0d9dc32, 85a4dc7).
  • Add CLI fix automation, doctor diagnostics, and i18n infrastructure (dad705b, 514d606, #21).
  • Add finding remediation metadata, gate semantics, suppressions, baselines, structured logging, notifier hooks, and multi-project workspace support (1bca167, 8c8a9bf, 846357f, 6b10f13, c535bed, 8c27166).
  • Add plugin SDK and loader plus the KiCad PCM editor plugin (0589294, 96eb42a).
  • Add binary distribution and full container Action release pipelines (485c25c, 71f83b0).
  • Add accessible HTML reports, CycloneDX hardware SBOM output, enriched SARIF context, richer rule metadata, and manufacturing output explanations (#20, #31, #17, 0773732, 533938c).

Bug Fixes

  • Emit configured JUnit reports (ee4846f).

Documentation

  • Add license compliance notices, structure verifier documentation, and contributing governance docs (6087066, cf14cf7, 95852af).
  • Record clean consumer channel verification, reference synchronization, and copy-paste audit gates (5667f1b, 4efcd6d, d3e74b0).

Tests

  • Align CLI version expectations, add fixture regression coverage, cover cross-platform paths, enforce docs accessibility, and add coverage and mutation gates (90478fc, e692578, #19, da3a370, 9446b77).

CI

1.0.2 (2026-05-21)

Maintenance

1.0.1 (2026-05-21)

Maintenance

  • Normalize npm package metadata and publish the v1.0.1 package correction (2cd39e6, 02ff84a).

1.0.0 (2026-05-21)

Added

  • Initial BoardReadyOps CLI and GitHub Action release for KiCad hardware production-readiness checks.
  • KiCad DRC/ERC normalization, BOM checks, pinmap validation, manufacturing checks, design sanity checks, release preflight rules, and JSON/SARIF/Markdown/JUnit report outputs.
  • Node 24 GitHub Action runtime, committed CLI/action bundles, coverage gates, mutation testing, property tests, SBOM generation, Gitleaks, OSV, CodeQL, Scorecard, Trivy, and npm provenance release workflows.