Changelog

520releases across 9 months

Every PAPI release, cycle by cycle. Each one pushes back against project drift.

Get started free

September 202618 releases

v0.402.55

More complete build history

  • Ad-hoc build reports retain commit and file evidence.
  • Accepted work carried between cycles can be found without rebuilding it.
Full detail
  • Preserve commit and file evidence in ad-hoc build reports and find accepted carried-forward reports without requiring a rebuild or release override.

v0.402.54

Explicit release targets and reliable deployment

  • Release plans identify the approved work and exact commit before publication.
  • Deployment checks authentication before transferring files.
Full detail
  • Explicit release targets and reliable Windows deployment
  • Require a precise release plan naming the approved PR, caller cycle and exact commit; reject mismatches before release work and preserve accepted carried-forward build evidence.
  • Consistently use Windows OpenSSH for edge deployment and verify authentication before staging or copying files.

v0.402.53

Clearer guidance and traceable task creation

  • Optional tutorial mode explains each workflow step and suggests one next action; control it in Settings or through your connected agent.
  • Task details show the creation tool, client and available model attribution, keeping reported names distinct from runtime evidence.
  • Exact dependency versions and verified release artifacts make builds reproducible, with Podman supported for local database tests.
Full detail
  • Cycle 58 — Reproducible dependencies, task attribution, and optional guidance
  • Pin dependencies, runtimes, actions and container images to exact versions; verify release provenance and support local Podman qualification without Docker Desktop.
  • Persist task creation tool, client, agent and model evidence, and show consistent attribution in dashboard task details and MCP output.
  • Add persistent personal tutorial mode with new-account defaults, Settings and MCP controls, and one next action based on saved workflow progress.

v0.402.52

Backup restore checks can run repeatedly

  • Scheduled restore checks use the newest completed backup and clear publications left by the previous isolated restore.
  • Each drill uses fresh temporary storage, cleans up its own output, and preserves existing files in the parent directory.
  • Missing packaged skills and invalid release summaries are caught before compilation and in hosted checks.
Full detail
  • Isolate hosted MCP child from audit database settings
  • Enforce skill and changelog integrity before builds
  • Make scheduled drills safely repeatable
  • Clear publications before replay
  • Map vibetycoon-derive and prompts-ui-aesthetics in the test inventory
  • Rebuild /projects/vibetycoon as a visual build-in-public insights page
  • Require tracked source in test inventory
  • Recover legacy successful dependency stamps
  • Recover missing warm dependencies and check docs locally
  • Include ranked prior work from history search
  • Record runtime model evidence
  • Qualify final tag against prior release
  • Build artifact from published version tag
  • Make aesthetics a real acceptance criterion in plan and review
  • Collapse the design skills into one project-agnostic design skill
  • Genericize the shipped design-critique skill

v0.402.51

One design skill, real aesthetics, and a rebuilt insights page

  • Four overlapping design skills are now one project-agnostic skill with less conflicting guidance and better UI output.
  • Aesthetics is a real acceptance criterion: every UI task names a reference target and a perceptual outcome with a screenshot.
  • The Vibe Tycoon insights page is rebuilt with velocity charts, teammate breakdowns, and a compact task ledger.
  • Build prompts now follow each project's own design guidance without including PAPI-specific instructions.
Full detail
  • Cycle 394 — Design system consolidation & insights rebuild
  • 58 files changed, +4,968 / −1,487
  • Per task

  • | Task | Files | + | − | Summary |
  • |------|-------|---|---|---------|
  • | **** — Rebuild /projects/vibetycoon as a visual build-in-public insights page | 13 | +1,772 | −383 | Hero + Play Store CTA, proof strip, sticky rail, road-to-launch timeline, velocity charts, per-teammate insights, model/module breakdowns, learnings ledger, compact task ledger, strategy reviews. Seven Recharts surfaces on a shared chart theme. |
  • | **** — Collapse the four overlapping design skills into one implementation skill | 21 | +275 | −603 | Four design skills (design-critique, frontend-design, impeccable, site-audit) consolidated into one project-agnostic design skill with Exploration/Implementation modes. All references updated across manifest, SHIPPED_SKILLS, agent, hook, design-bundle, sync-skills, and tests. |
  • | **** — Genericize the shipped design-critique skill and fix its self-contradictions | 3 | +249 | −347 | Removed PapiUI-specific fonts, colours, routes, and incidents. Fixed X/7 → X/8 verdict table rot. Superseded by within the same cycle. |
  • | **** — Remove contradictory design guidance from server-injected build prompts | 4 | +79 | −269 | Deleted the PapiUI-specific MODULE_INSTRUCTIONS map entirely (AD-78). getBuilderInstructions now returns only project-declared conventions. No-cross-project-leak test rewritten to assert the leak surface is gone. |
  • | **** — Make aesthetics an acceptance criterion in build and review | 3 | +35 | −0 | PLAN_FRAGMENT_UI now requires a named reference-grade target and a perceptual outcome with screenshot in every UI task's acceptance criteria. REVIEW_RUBRIC gains an aesthetics dimension; blocklist pass is NOT acceptance. |
  • | **** — Generate the drastic redesign concepts (landing + dashboard) for owner selection | 11 | +1,933 | −1 | 5 landing + 4 dashboard self-contained HTML concepts under docs/design/redesign-c394/. Palette/type/layout uniqueness verified across all 9. Owner reviewed; accepted as exploration output. |
  • Full details: CHANGELOG.md

v0.402.50

  • Fix Cycle 56 release board read and bump 0.402.50
  • Close cycles explicitly
  • Reduce duplicate release builds and record approval-to-live time
  • Orchestrate measured app-only VPS releases
  • Reuse release qualification and include proxy changelog in tag

v0.402.47

Find the right PAPI history faster

  • Search registered documents by relevance and see excerpts only from documents you can access.
  • Search learnings, build reports, and task history without scanning the whole project.
  • The dashboard now warns about likely duplicate tasks before you create one.
Full detail
  • Search registered documents by relevance, with excerpts that respect document visibility.
  • Search learnings, build reports, and task history through an indexed, bounded query.
  • Show duplicate-task warnings in the dashboard before a task is created.
  • Evaluated pg_trgm for duplicate matching; retained the corrected matcher because the comparison did not show a quality gain.

v0.402.42

Screenshots on tasks, and you can now move a task off someone else's name

  • Attach a screenshot when you create a task. It uploads, and the reference travels with the task to every teammate and to the agent that builds it.
  • The project owner can reassign a task another member holds, instead of being told it is already theirs.
  • CI stopped locking itself out: one change to a dependency file no longer blocks every other pull request for the rest of the day.
Full detail
  • Attach images to dashboard tasks and surface them to the handoff builder
  • Reassign a task held by another team member (owner/release-manager transfer fix)
  • Keep CI green: the warm dependency budget is now keyed on the dependency fingerprint, not the calendar

v0.402.41

Cancel is the delete, and the admin console is split in two

  • Cancelling a task now says plainly what it does: the task leaves the board and its history stays.
  • The admin Users page is the user directory only, and the usage analytics moved to their own page.
  • An account on a granted trial no longer skews the admin console usage and retention numbers.
  • A build handoff missing required sections is refused up front, naming exactly what to add.
Full detail
  • Reject incomplete ad_hoc handoffs and allow recovery after review
  • Eval harness with golden fixtures for planner output and BUILD HANDOFF quality
  • Replace mocked invitation-acceptance route tests with production-path coverage
  • Trial mechanism (code or admin toggle) that doesn't pollute activation/paid metrics
  • Add a task delete, or document cancel as the delete
  • Split the relocated /admin/users page - Users directory on /admin/users, telemetry analytics on their own route

v0.402.38

A bookmarkable admin Users page, and an undo for project resets

  • Clicking Users in the ops console now opens a real, bookmarkable /admin/users URL instead of internal tab state.
  • Typing a project name to confirm a destructive action is now consistent everywhere: case and stray spaces no longer make one screen accept what another rejects.
  • An execution reset is reversible: after resetting a project you can undo it within 24 hours and get each task's previous status back.
Full detail
  • UX-N · Account security and destructive-action safety — sessions, audit log, undo on reset, 2FA
  • Establish a tuned auditd execution and persistence-monitoring baseline on the self-hosted PAPI VPS
  • Evaluate Sysmon for Linux as an optional process-to-network correlation layer for PAPI
  • Give admin console tabs real routes (e.g. /admin/users) instead of internal-only tab state
  • Decision proposed: Native-hook adapters may trigger existing MCP calls; no native plugin reimplements PAPI logic on any framework
  • Reconcile REVIEW_RISK_TIER_GLOBS against diff-inspector's TRIGGER_SURFACE_GLOBS with a drift guard
  • Update content-pack and patch-notes skills off the decommissioned Supabase MCP to the VPS DB path
  • Extend the Supabase-MCP to VPS-DB skill sweep to friction-promote, winback, deployment-completeness-audit

v0.402.37

Team invitations that complete, with Resend and per-invite states

  • Invite teammates from Settings › Team by email or with a shareable link, and see every pending invite in one list.
  • Lost an invite link? Resend it in one click. The old link stops working the moment the new one is created.
  • Each invite now shows its state: sent, link opened, accepted, or ended, plus recent activity.
  • Back-to-back reviews cannot collide anymore. The first verdict wins; stale ones are refused cleanly.
Full detail
  • Team invitations are owner-only at the database layer, survive email-provider failures with an honest delivery status, and no longer get blocked by expired invites.
  • Owners can resend an outstanding invitation with a fresh link, and see per-invitation lifecycle states (sent, opened, accepted, ended) with recent activity.
  • Review verdicts are first-wins: repeat or conflicting verdicts are rejected instead of reopening finished work, and the review list points at the claim step where the adapter serves it.
  • Orient scoping on shared projects is now proven end to end: your cycle results only, with no cross-person leakage.

v0.402.35

Orient surfaces new capabilities, and build_execute warns before you collide

  • Orient now flags a shipped cycle's new capabilities as an actionable alert instead of blending them into passive planning notes.
  • Starting a build now warns if another active session is already on the same task or the same files, before you begin.
  • Claim and build tool descriptions now point to session presence, so an AI client notices its teammates without being told separately.
Full detail
  • Orient now flags a shipped cycle's new capabilities as an actionable alert instead of blending them into passive planning notes.
  • Starting a build now warns if another active session is already on the same task or the same files, before you begin.
  • Claim and build tool descriptions now point to session presence, so an AI client notices its teammates without being told separately.

v0.402.33

See who else is active on a shared project

  • Any session can announce what it's working on and see everyone else active on the project, so two people don't quietly collide on the same task or files.
  • A claim that goes quiet, from a crashed or closed session, shows up as stale instead of looking active forever.
  • Hub tabs show a loading state on first activation instead of flashing an empty board or pool.
  • The installable skills package grew to 13, including a security audit and an autonomous-cycle skill.
Full detail
  • Any session can announce presence and see who else is active on a shared project — what they're working on, and a heads-up before touching the same files.
  • Claims now go stale visibly instead of sitting invisible forever after a crashed or closed session.
  • Hub tabs show a loading state on first activation instead of flashing an empty board or pool.
  • The installable skills package grew to 13, including a security audit and an autonomous-cycle skill.

v0.402.32

File ideas without accidentally starting the work

  • File backlog ideas without the coding session drifting into implementation.
  • Keep duplicate checks, project receipts, and references in place when filing.
  • Explicit build and fix requests still continue through the normal implementation path.
  • The published skill package now carries the same intake guard as the authored skill.
Full detail
  • File backlog ideas without the coding session drifting into implementation.
  • Keep duplicate checks, project receipts, and references in place when filing.
  • Explicit build and fix requests still continue through the normal implementation path.
  • The published skill package now carries the same intake guard as the authored skill.

v0.402.31

Task transfers are safer, and project decisions are easier to understand

  • Task transfers now use project member IDs, so contributor email addresses are not exposed or mistaken for identities.
  • When a workspace is already linked to another project, the service now returns a clear conflict instead of leaving the result ambiguous.
  • Decision views now show the read-only conflict vote tally, so teams can see where a proposed decision stands.
  • Newly discovered issues are clearly relayed to the project owner, making follow-up harder to miss.
Full detail
  • Task transfers now use project member IDs, so contributor email addresses are not exposed or mistaken for identities.
  • When a workspace is already linked to another project, the service now returns a clear conflict instead of leaving the result ambiguous.
  • Decision views now show the read-only conflict vote tally, so teams can see where a proposed decision stands.
  • Newly discovered issues are clearly relayed to the project owner, making follow-up harder to miss.

v0.402.30

  • Extend /verify skill to execute-and-evidence QA — run the software, capture screenshots/output, attach evidence to review_submit
  • Release directive must include the changelog-summaries append (Step 6) so /changelog is never left raw
  • Overview tab has no per-panel loading states — reads as frozen for a long time on large projects
  • Team "Recent activity" attributes actions to "human" instead of naming the actual actor
  • Guard PAPI_TEST_DATABASE_URL in the ci-full lane so it can never target a shared DB
  • Scope the acceptance gate to risk-tier tasks so routine builds cannot dead-end
  • Confirm-flag race on parallel/batched MCP writes — sibling calls in the same connection don't see the just-set "project_context_confirmed" memory
  • Promote.sh activation silently dies on a full /tmp tmpfs — free root disk does not save it, and the error misdirects
  • Close Cycle 389 discovered issues (6 fixes)

v0.402.29

  • Fix the production dashboard build (Next route-type export violation + tests pulled into the build's type-check) — every release deploy was blocked
  • Consolidate the recovery-email candidate resolution into one lib module instead of a route module and a route-imports-route

v0.402.28

  • Per-member intake → upstream rollup — each friend's own AI submits answers into the shared brief
  • Auto-detect & propose Conventions — admission rule paired with AD_REJECTION_RULES, mint path at build_execute completion and idea submission
  • Orient Board summary reads "0 tasks — board may need reloading" on a completed cycle with a populated backlog
  • Settings project deletion returns an internal error
  • Accepted project invitation does not create project membership
  • Review_submit has no structural guarantee of a real review for non-risk-tier tasks — only self-attestation
  • Share the ICP signal vocabulary between classifyIcp and the data-proxy icp_classified mirror
  • Move the Gestalt Pre-Build Check into the papi-build skill and de-gate it from cycle 6