diff --git a/CHANGELOG.md b/CHANGELOG.md index 09c39fb2..dfd5591e 100644 --- a/CHANGELOG.md +++ b/CHANGELOG.md @@ -9,6 +9,28 @@ The dashboard's **What's New** rail reads this file at request time entries. Keep entries terse — one line per item under each version date, grouped by `Added` / `Changed` / `Fixed` / `Removed`. +## [2026-08-25] — v0.33.0 · Identity and managed runtime control + +### Added + +- **Forge supports complete local, external, and hybrid identity lifecycles.** Instance policy controls credentials and provider presentation while one canonical user can manage local passwords, linked sign-in identities, profile pictures, recovery, invitations, and audited account state. +- **Restricted projects have explicit human access roles.** Viewer, Contributor, and Manager grants stay tenant-scoped and flow through issues, resources, search, dashboards, analytics, notifications, realtime updates, and direct links without existence leaks. +- **External credentials require owner consent and principal grants.** Users, agents, API keys, and workspace automation receive explicit workspace/project capabilities that remain bounded by current project access, key narrowing, mapping state, and provider authority. +- **Managed runtime diagnostics preserve execution-plane truth.** Manual verification and self-tests run through the worker, retain bounded executor/trigger history, and include a reference worker-egress Compose topology. +- **Hermes operators receive versioned runtime helpers.** Releases ship checksum-validated `forge-presence` and `forge-provision` artifacts; presence is a least-privilege, script-only heartbeat that stays silent on success. + +### Changed + +- **Generic OIDC explicitly enforces PKCE, state, and nonce.** Identity linking warns that the provider attaches to the signed-in user, and a separately designated break-glass administrator provides an audited recovery path. +- **Personal and session API keys follow live human authorization.** Suspension, membership removal, role demotion, project-grant revocation, and key narrowing take effect on the next request while agent and plugin keys remain independent service principals. +- **Runtime presentation uses adapter and transport identity.** Hermes managed runtimes show Runs API provenance instead of generic remote-webhook copy, and chat surfaces report one actionable reachability fault. + +### Fixed + +- **Credential and project grants cannot widen underlying access.** Artifact, attachment, canvas, context, plan, run, notification, realtime, GitHub, and derived surfaces share the same project privacy floor, including unfiled GUEST behavior. +- **Runtime failures end diagnostics deterministically.** Worker exceptions record sanitized terminal evidence instead of leaving permanent pending rows, and BODY completion-comment requirements are enforced end to end. +- **Hermes MCP requests are WAF-friendly and diagnosable.** The platform adapter sends a stable Forge User-Agent and records sanitized HTTP status/error classes without leaking response bodies or secrets. + ## [2026-07-30] — v0.32.0 · Session-scoped MCP delivery ### Added diff --git a/DEVLOG.md b/DEVLOG.md index ff3e727e..f6843521 100644 --- a/DEVLOG.md +++ b/DEVLOG.md @@ -2,6 +2,19 @@ > Append-only session log. Read at session start. Update at session end. +## 2026-08-25 — v0.33.0 release preparation + +- Squash-merged AXI-180 / PR #96, AXI-181 / PR #97, and AXI-182 / PR #98 to + `main` after exact-head GitHub CI passed and actionable review findings were + resolved. +- Prepared the `0.33.0` package bump and curated release notes for full local, + hybrid, and SSO identity management; restricted project and integration + authorization; standards-correct OIDC; worker-plane diagnostics; and + versioned Hermes runtime helpers. +- The release PR owns the version and immutable tag. Production deployment and + live verification remain separate and are not authorized by this release + task. + ## 2026-08-25 — Generic OIDC and recovery identity hardening - Required PKCE, state, and nonce checks explicitly for every generic OIDC @@ -39,6 +52,7 @@ accepts only a live BODY comment, and added one managed-runtime acceptance path spanning assignment, external dispatch, inbox acknowledgement, output start, final BODY comment, and terminal completion. + ## 2026-08-25 — Restricted projects and explicit integration grants - Added workspace-visible and restricted projects with explicit Viewer, @@ -68,6 +82,7 @@ integration ceiling after defaults are resolved, and now revokes derived grants when credential source, exact app binding, or capability ceilings change. + ## 2026-08-25 — Canonical local and external user identity foundation - Added a provider-neutral instance authentication policy for local-only, diff --git a/package.json b/package.json index c41bff05..f263f0a9 100644 --- a/package.json +++ b/package.json @@ -1,6 +1,6 @@ { "name": "forge", - "version": "0.32.0", + "version": "0.33.0", "private": true, "description": "Forge — a fast, minimalist, keyboard-driven project management platform with pluggable agents.", "license": "MIT",