Changelog

520releases across 9 months

Every PAPI release, cycle by cycle. Each one pushes back against project drift.

Get started free

September 202618 releases

v0.402.25

  • Spike — evaluate in-process MCP serving for v1 (drop the data-proxy hop); NO-GO with measured transport delta
  • Consolidate supabase/migrations — each migration file now replays on its own connection
  • Ad_hoc "do this now" work goes straight to Building with a real handoff (two-phase create-first)
  • Pre-build board check — surface existing / duplicate / conflicting / already-Done / In-Progress work before writing code
  • Project-level strategy review — one team retrospective across all members' last 5 cycles
  • Icp_classified fires again for the newest signup cohort (server emit + edge funnel mirror)
  • Wire an evaluator for CONNECT STOPS BEING THE WALL so orient computes the S5 activation gate
  • Exit-criteria evaluators key on a stable project-scoped key (backfill migration applied to production)
  • Make the disposable Supabase/Podman production-path test stack boot reliably on macOS and run it in CI
  • Team contribution table — explain the "Defects surfaced" and "Tool mix" columns
  • Health integrity check read a compact board that hides build_handoff — false RED on a healthy cycle
  • Cap papi-dashboard.service heap + add 4 GiB VPS swap headroom
  • Reconcile production migration-ledger drift (papi-main-01)
  • Deploy v0.402.22 to papi-main-01 (self-hosted activation)

v0.402.23

  • Accepted project invitation does not create project membership
  • Remove account-wide default project persistence and enforce repository-local project identity
  • Lift raw-SQL escape hatches behind the PapiAdapter seam
  • Delete ProxyPapiAdapter's pass-through wrappers
  • Deepen the data-proxy edge with shared plumbing for executeAdapterMethod
  • Hosted queryBoard drops the epic and reviewed filters

v0.402.22

  • Fix hosted createCycle clobbering a teammate's same-numbered cycle
  • Never resurrect a completed cycle or rewrite its metadata on plan re-apply
  • Broaden assertSingleActiveCycle phantom detection beyond goals-empty cycles
  • Split hub tab data loading — each tab (Overview/Cycle/Team/Projects/Backlog) fetches only its own endpoints, not all 18 upfront
  • VPS swap fully exhausted (2GB/2GB) — investigate capacity headroom / add memory or swap
  • Greenfield setup promises a starter backlog it never generates — new projects always end setup with 0 tasks
  • Hub data load OOM-kills the dashboard process — every in-flight request returns a Caddy 502
  • Cross-member state leaks into per-member plan gates — stale-review gate and cycle lineage are not scoped to the planning member
  • Guard commitReleaseProjection's cycles upsert against rewriting a completed cycle

v0.402.21

  • Keep MCP tool schemas compatible with strict providers such as ZCode by removing unsupported schema keywords before advertising tools
  • Let release managers finish an already-merged release from a clean checkout at the exact origin/main commit, including when a merged cycle branch remains in another worktree

v0.402.20

  • Pin the canonical admin origin in the Content Security Policy so production RSC requests do not depend on an optional build variable

v0.402.19

  • Allow the canonical admin origin in the Content Security Policy so admin React Server Component requests are not blocked

v0.402.18

  • Scope review_list to the caller's assignments and active cycle by default, while preserving the shared queue behind explicit team scope
  • Show cycle, assignee, and reviewer context for pending and rework reviews

v0.402.17

  • Preserve and reconcile deployment verification receipts during workspace releases
  • Require durable BUILD HANDOFF evidence before cycle tasks can be completed or released
  • Verify all 17 critical production routes through one typed production qualification contract

v0.402.16

  • Scope release readiness, evidence, handoff, and metrics checks to the caller's exact server-stored cycle roster
  • Prevent another contributor's legacy tasks from blocking a same-numbered cycle release

v0.402.15

  • Register per-user, per-computer hosted workspace bindings so remote PAPI writes resolve the correct local directory
  • Route workspace binding, task creation, and task status transitions through one canonical production implementation
  • Remove source-scraped parity gates and reclassify mocked integration/smoke tests as unit coverage
  • Enforce real production-path evidence for parity, integration, hosted, smoke, E2E, and production-path claims

v0.402.14

  • Credentials must name their project: nullable api_keys.project_id + project-scoped key minting + resolution precedence + scoped Reset
  • MCP tooling for project self-service — let a stuck user's own LLM resolve friction directly
  • FTUE: new users don't understand cycle/plan or that PAPI isn't agentic
  • GitHub connect: can't link multiple GitHub accounts, and repo-link attempted via chat didn't actually persist
  • Board page doesn't update in real time like Hub/Cycle does
  • Persist deployment verification when release reconciles an already-merged contributor PR

v0.402.12

  • Launch release qualification on Windows
  • Batch the hub's 18 concurrent data fetches to cut peak memory
  • Admin OAuth login loop + hub blanking on one failed fetch
  • Scope admin redirect to getpapi.ai host, not admin.getpapi.ai
  • Hub 502s from unbounded queries + admin route 404

v0.402.11

  • Recognize durable build report evidence in health

v0.402.10

  • Cycle 39: protect release integrity and rollout evidence
  • Cycle 39: harden PAPI project scope resolution

v0.402.9

  • One shared Task-vocabulary normalizer module (priority/complexity/effort)
  • Move shared helpers out of tools/ to restore the dependency direction
  • Fail closed when cycle scope is unavailable
  • Scope health reads to selected cycle
  • Normalize worktree dependency marker paths
  • Project dashboard history reads
  • Remove redundant complete inventory counts

v0.402.6

  • Hosted headerless MCP calls now honor exactly one access-validated persisted project default before returning an ambiguity prompt.
  • Missing or duplicate hosted defaults remain fail-closed, with regression coverage for cross-project isolation.

v0.402.5

  • Hosted project defaults now persist only after access validation, preserving fail-closed cross-project isolation.
  • Hosted project switching now gives truthful stateless reconnect guidance and regression coverage.

v0.402.4

  • Make the self-hosted edge deploy backup loop safe when the remote shared-module directory is newly created and empty.