{
  "updatedAt": "2026-09-11T17:07:56.845313+00:00",
  "previousSourceRevision": "7ff34500e37ef15a5f5c5b85f4a791a60f29788d",
  "sourceRevision": "f5b07085937319e91c6b83c289bbe933801f3760",
  "changes": [
    {
      "id": "A02",
      "feature": "Native email registration and magic-link login",
      "previousStatus": "blocked",
      "status": "partial",
      "change": "Administrator-configured Resend is enabled. The recipient confirmed delivery; a real console browser sign-in request returned 202 and created a fresh 15-minute challenge. Email-link consumption and a new-user registration journey were not exercised by that live check."
    },
    {
      "id": "A07",
      "feature": "Project creation and repository settings",
      "previousStatus": "partial",
      "status": "partial",
      "change": "Project creation and repository settings are wired. Source defaults and retention/checkpoint policy now have explicit flows, but the generic project update remains repository-focused and arbitrary field updates are not supported."
    },
    {
      "id": "A10",
      "feature": "Verified source archive upload from browser",
      "previousStatus": "ui",
      "status": "unverified",
      "change": "The browser now uploads actual archive bytes, verifies the digest, finalizes the source and publishes its index. Settings accepts a File instead of passing only filename/size. Code, adapter tests and the release are present; a fresh live browser upload-to-first-run journey remains unqualified."
    },
    {
      "id": "A11",
      "feature": "Source index publication and context discovery",
      "previousStatus": "ui",
      "status": "unverified",
      "change": "Browser upload now publishes the verified archive index and source selection pins its identity. CLI/API paths remain available. The full fresh browser source/index/agent journey still needs live acceptance."
    },
    {
      "id": "R02",
      "feature": "Run form semantics: source, environment and advanced options",
      "previousStatus": "partial",
      "status": "partial",
      "change": "Run admission now carries selected source/ref, environment, leased secrets, label, ephemeral retention, checkpoint and email options. Saved tasks bind their configuration ID; unsupported optimization goals are rejected. The resource/runtime UI remains limited and the complete live option matrix is not qualified."
    },
    {
      "id": "R03",
      "feature": "Run cost quotes and cancellation cost feedback",
      "previousStatus": "stub",
      "status": "unverified",
      "change": "The fixed €0.50 quote is replaced by the current billing catalogue and requested resources/duration. Cancellation leaves unknown settlement explicit. Regression tests and deployment are complete; browser quote-to-actual-settlement acceptance remains to be run."
    },
    {
      "id": "R04",
      "feature": "Complete run history and search",
      "previousStatus": "partial",
      "status": "unverified",
      "change": "Run history and search now use server pagination, including records beyond the old latest-100 limit. Tests cover 124 visible runs, tenant isolation, sorting and labels. A live large-history browser journey remains unqualified."
    },
    {
      "id": "R06",
      "feature": "Run provenance and environment detail presentation",
      "previousStatus": "partial",
      "status": "partial",
      "change": "Run details now use recorded source, environment and region, mask leased secrets, expose unknown cache outcomes and calculate artifact retention from expiry. Some account-member/trigger labels and wider metadata views remain simplified."
    },
    {
      "id": "R10",
      "feature": "Pipeline step retry/resume and GitHub checks UI",
      "previousStatus": "stub",
      "status": "partial",
      "change": "Whole-pipeline retry now creates a new run from the original immutable definition, commit and resources, with idempotent receipt recovery. Per-step retry/resume and GitHub check controls remain separate unsupported operations."
    },
    {
      "id": "R12",
      "feature": "SBOM and provenance document downloads",
      "previousStatus": "partial",
      "status": "unverified",
      "change": "SBOM and provenance downloads now retrieve the actual build documents, check their stored/browser digests, enforce access and retention, and preserve exact JSON bytes. Tests and deployment are present; a real browser build-to-download journey remains unqualified."
    },
    {
      "id": "R16",
      "feature": "Generic integration and webhook management",
      "previousStatus": "stub",
      "status": "partial",
      "change": "Repository-specific integration settings now expose verified identity, GitLab webhook setup/rotation, enable/disable and delivery outcomes. Generic webhooks, notification rules and generic test/connect adapters remain disabled."
    },
    {
      "id": "R17",
      "feature": "GitLab CI project binding and triggers",
      "previousStatus": "partial",
      "status": "partial",
      "change": "GitLab project binding and triggers now distinguish equal project IDs on different hosts/projects, validate Tag Push Hook events and recheck authority during admission. PostgreSQL and browser component tests passed; live private-provider browser acceptance remains open."
    },
    {
      "id": "W11",
      "feature": "Browser workspace terminal and checkpoint terminal",
      "previousStatus": "ui",
      "status": "unverified",
      "change": "Existing workspace terminals and the checkpoint debug UI use authenticated session-gateway admission. Checkpoint selection, resource/cost ceiling, shell and lease settings are preserved, reload reads the original receipt, and Stop cancels the debug job. Real browser attach/reconnect remains unqualified."
    },
    {
      "id": "W15",
      "feature": "Storage inventory, retention editor and external backup bucket",
      "previousStatus": "partial",
      "status": "partial",
      "change": "Storage inventory remains bounded and the generic storage retention/bucket adapters remain disabled. Owners can now edit project artifact retention/checkpoint policy through Settings; checkpoint retention uses observed expiry and cannot revive expired payloads."
    },
    {
      "id": "S07",
      "feature": "Durable multi-turn agent and workspace admission",
      "previousStatus": "blocked",
      "status": "blocked",
      "change": "Durable session, interaction and private-workspace components are deployed, but effective durable admission remains disabled. Native single-task execution is separately enabled. Production controller integration and broader durable failure/recovery acceptance remain open."
    },
    {
      "id": "S08",
      "feature": "Full production Codex runner with authenticated tools",
      "previousStatus": "blocked",
      "status": "blocked",
      "change": "The standalone Codex adapter, guest, journal and approval/command bridge have local qualification. The full production runner controller is not completed or selectable; an enabled personal ChatGPT connection does not establish full Codex workspace execution."
    },
    {
      "id": "S12",
      "feature": "Agent approve-and-push, take-over and report archive actions",
      "previousStatus": "stub",
      "status": "partial",
      "change": "Reviewed Git publication and session archive now have working server/client paths. Publication pins reviewed files/base commit and reconciles an uncertain provider response without another write; archive fences outstanding publication. A synthetic live GitLab provider test passed and cleaned up its branch. Full browser-to-provider acceptance and the separate take-over workflow remain open."
    },
    {
      "id": "S15",
      "feature": "Email agent completion and approval notifications",
      "previousStatus": "blocked",
      "status": "unverified",
      "change": "Resend delivery is now enabled and a real test was received. Agent/run notifications use durable outbox records, stable send identity, access rechecks and read/opt-out suppression. Real completion/approval notification delivery was not exercised by the generic test or sign-in request."
    },
    {
      "id": "S17",
      "feature": "Downloaded CLI and VS Code extension distribution",
      "previousStatus": "done",
      "status": "done",
      "change": "Public CLI/extension distribution remains available with versioned download metadata and dated checksum/acceptance evidence. The refreshed public observation records the current manifest; distribution does not certify every physical client workflow."
    },
    {
      "id": "G04",
      "feature": "General egress and unified policy enforcement",
      "previousStatus": "partial",
      "status": "partial",
      "change": "The Resend incident exposed missing Cilium DNS observation for FQDN allowlists. The deployed DNS policy now makes the existing Resend/GitHub/OAuth destination rules effective, and repository checks cover every Snabb FQDN rule. General cross-entrypoint egress/revocation assurance remains broader than this fix."
    },
    {
      "id": "G08",
      "feature": "Service status, capacity, uptime and incidents display",
      "previousStatus": "stub",
      "status": "partial",
      "change": "The hardcoded Operational/100% uptime display is replaced by current worker state, observed region/capacity and explicit unknown 30-day uptime. This is a worker availability snapshot; retained incident history and live status subscriptions are not implemented."
    },
    {
      "id": "O01",
      "feature": "Current application deployment readiness",
      "previousStatus": "done",
      "status": "done",
      "change": "The fresh snapshot records 20 application deployments and MinIO at requested readiness. Public readiness endpoints are recorded separately. This is point-in-time health, not uptime or complete workflow qualification."
    },
    {
      "id": "O06",
      "feature": "Latest pipeline and fixed-revision release qualification",
      "previousStatus": "partial",
      "status": "done",
      "change": "Pipeline 5394 passed all 30 jobs at d8c9f75, including runtime build, worker/runtime promotion, application deployment and both live canaries. All 20 application deployments are ready at this same revision. New local P1 fixes require their own qualified release."
    },
    {
      "id": "O07",
      "feature": "Main/deployed source reconciliation and remaining branch",
      "previousStatus": "done",
      "status": "partial",
      "change": "All 20 application deployments now run the fully qualified d8c9f75 revision. Main f5b0708 adds documentation only. Independent feature branch review and the remaining P1 work continue; the progress branch is intentionally separate."
    },
    {
      "id": "O08",
      "feature": "Accurate product capability and release documentation",
      "previousStatus": "partial",
      "status": "partial",
      "change": "The audit now incorporates password and Resend qualification, deployed upload/run/action wiring and current pipeline state. It retains distinct code/UI/deployment/usability/evidence dimensions. Some legacy feature flags, overview values, disabled adapters and old implementation-ledger checkpoints still need reconciliation."
    },
    {
      "id": "A17",
      "feature": "Direct password setup, sign-in and sign-out",
      "previousStatus": "not inventoried in the initial bundle",
      "status": "done",
      "change": "One-time password setup, salted scrypt, shared PostgreSQL attempt limits, session revocation and administrator eligibility are deployed. An isolated real browser fixture verified setup/replay rejection, login, secure cookies, sign-out, cross-origin denial and non-admin rejection."
    },
    {
      "id": "G12",
      "feature": "Admin Resend configuration and test delivery",
      "previousStatus": "not inventoried in the initial bundle",
      "status": "done",
      "change": "The complete Settings page now binds after insertion. The saved key is write-only in Vault, sender changes require a fresh test, provider failures are safe and specific, uncertain retries survive reload, and a successful new test gets a new identity. Delivery was confirmed by the authorized recipient and enabled with an audit record."
    }
  ]
}
