Changelog
321releases tagged feature
Every PAPI release carrying the feature tag. What shipped, when.
Get started freeMarch 202618 releases
- Add retry on display_id collision in dashboard review submit
- Exclude scripts/ from tsconfig to fix Vercel type-check
- Only build prompts entry on Vercel — skip full server bundle
- Split tsup config so prompts entry builds without adapter deps
- Add server package build to Vercel build pipeline
- Add prompts subpath export to MCP server package
- Add display_id to dashboard review submission
- Wire SSE into cockpit for instant dashboard refresh
- Surface task comments in build_list and board_view output
- Add request-scoped memoization to dashboard data-provider
- Fix N+1 queries in loadProjectsFromDb and completeBuild over-fetch
- Protect Deferred phases from auto-propagation regression
- Tighten mapSupabaseResult — require mapper, restore length guard
- Idea tool similarity gate — block creation and require user confirmation
- Enforce full-depth strategy review output with two-phase delivery
- Prevent phase auto-update from regressing manually-set statuses
- Add project bootstrap from portfolio page
- Add cockpit polling and focus revalidation
- Replace allowlist gate with email-verified check
- Secure multi-tenant write paths
- Skip .papi commits when directory is gitignored
- API key management UI — generate, view, and revoke keys
- Email signup + sign-in with confirmation flow
- Provider-aware user_profiles trigger for email auth
- Provider-aware auth — support email alongside GitHub OAuth
- Preserve Supabase session cookies through middleware
- Separate auth layout — login/onboard without app nav
- Redirect unauthenticated root URL to landing page
- Personalised MCP config on setup page for logged-in users
- Setup verification endpoint + dashboard status indicator
- Onboarding flow audit & redesign document
- Security: remove hardcoded proxy key and shared-secret auth from data-proxy
- Landing page branding: Visual refresh with improved imagery and brand identity
- Landing page messaging: Sharpen value proposition and above-the-fold clarity
- Dashboard API: decision_events endpoint for AD timeline and relationship views
- Surface pending AD state on dashboard and flag in planner
- Fix pre-existing next build type error in stress test createTask call
- Setup page: add orientation context, completion state, error guidance
- Strategy page: decision staleness signals, relationships, connected narrative across tabs
- Doc Registry Phase 1: Foundation — Schema, Registry Service, Auto-Detection
- Complete taxonomy migration: rename Sprint* interfaces/types in pg-papi-adapter.ts and data-proxy
- Strategy review apply persistence — retry lost reviews next session
- Strategy review: replace cycle-count staleness with drift-based staleness for briefs, ADs, and North Star
- Strategy review: link recommendations to action items with status tracking
- Track build iteration count (pushbacks before review) as rework metric
- Strategy review: include non-task git commits in context to catch ad-hoc work
- Orient: include npm published version vs local version check — flag dist-tag drift
- Fix process.env.PAPI_PROJECT_DIR mutation race condition in API routes
- Npm security audit — verify package config, 2FA, access controls
- Validate /api/intelligence model and maxTokens to prevent cost abuse
- Add PAPI_LIGHT_MODE config for branchless builds
- Create /security-audit skill for codebase-wide reviews
- Fix planner cycle sizing, rec expiry, scope pre-check
- Add block action to board_deprioritise + planner blocked-task instructions
- Add PRE-BUILD VERIFICATION to BUILD HANDOFFs
- Drop -alpha suffix from npm package versions so latest dist-tag advances
- Add Strict-Transport-Security header to next.config.ts
- Data proxy: per-user API keys with project ownership verification
- Scope onboard endpoint to prevent cross-user project enumeration and claiming races
- Remove hardcoded project UUIDs from brain-supabase.ts
- Create waitlist_signups migration (table has no migration, was created manually)
- Cockpit shows 'Released' instead of 'ready for release' for completed cycles
- Security: restrict admin telemetry to owner-only, not any authenticated user
- Allow authenticated dashboard sessions to access admin telemetry
- Add missing NOT NULL fields to dashboard createBuildReport
- Cascade user_id on project claim + fix ensure-schema gaps
- Board empty states, hide filters when empty, remove CLI jargon
- Security: remove user_id IS NULL fallback — strict user isolation
- Data isolation — scope DB queries by user_id + onboarding gate
- Security: restrict OAuth login to allowlisted GitHub accounts
- Security: strip x-papi-* headers from incoming requests to prevent spoofing
- Unify API route auth to support GitHub OAuth sessions
- Revert "Revert "fix: guard ProjectProvider against non-array API responses""
- Revert "fix: guard ProjectProvider against non-array API responses"
- Guard ProjectProvider against non-array API responses
- Use correct theme tokens in admin page — fixes production render
- Add Admin link to dashboard navigation under More menu
- Add funnel analytics tracking to landing and setup pages
- Configure dogfood logging for external users during setup
- MCP telemetry infrastructure — track tool calls, projects, milestones
- Landing page: CTA hierarchy, scroll incentive, social proof with real numbers
- Landing page CTA hierarchy, scroll incentive, social proof
- Mobile responsive pass: fix critical breakage on cockpit, board, and analytics
- Mobile responsive pass — cockpit, board, analytics