Skip to content

Latest commit

 

History

History
853 lines (520 loc) · 88.8 KB

File metadata and controls

853 lines (520 loc) · 88.8 KB

Changelog

0.41.0 (2026-09-30)

⚠ BREAKING CHANGES

  • cli: remove the service-account mode alias; use --mode agent or JENTIC_MODE=agent (BC-12)
  • auth: retire sak_ service-account keys and drop the service-account tables (theme 8, phase 4); the upgrade migrates remaining service accounts to agents, and callers must switch to a jak_ key for each successor agent before upgrading
  • control: the toolkit tables are dropped. Before upgrading, run flatten-toolkits --verify --acknowledge on the 0.41 image and retire any live toolkit key on 0.40.x. broker.direct_bindings_enabled: false is no longer accepted.

Features

  • auth: retire sak_ service-account keys and drop the service-account tables (theme 8, phase 4); the upgrade migrates remaining service accounts to agents, and callers must switch to a jak_ key for each successor agent before upgrading (4c04ed9)
  • control: drop the toolkit tables (theme 5, phase 6b) (#1498) (bd5f490)

Bug Fixes

  • control: stop counting superseded successors as SA digest mismatches (#1497) (c48704a), closes #1416

Refactors

  • cli: collapse the service-account mode into agent (theme-8 D4) (#1410) (68871ff)
  • cli: remove the service-account mode alias; use --mode agent or JENTIC_MODE=agent (BC-12) (4c04ed9)

Build System

  • deps-dev: bump brace-expansion from 1.1.18 to 1.1.21 in /ui (#1496) (2d22c84)
  • deps: bump @tanstack/react-query from 5.102.8 to 5.103.2 in /ui (#1450) (aa267f5)
  • deps: bump pyjwt from 2.13.0 to 2.14.0 (#1493) (5666faf)
  • deps: bump tailwind-merge from 3.6.0 to 3.7.0 in /ui (#1449) (1700f01)
  • deps: bump the python group with 10 updates (#1494) (a23a2ed)
  • deps: bump urllib3 from 2.7.0 to 2.8.0 (#1501) (c50bb2e)

0.40.1 (2026-09-29)

Bug Fixes

  • broker: match credentials on the request's resolved server variables (#1486) (9fd4879)
  • broker: re-check agent and credential authorization when a queued execution runs (#1478) (8360645)
  • cli: run the MCP service account from a root-owned binary copy (#1482) (e096956)
  • control: store connect-session poll tokens hashed (#1477) (0381126)
  • helm: mount only the app secrets each surface reads (#1484) (3eda549)
  • registry: derive vendors from the registrable domain using the Public Suffix List (#1483) (0c240b4)
  • registry: hold server-host changes on credential-bound APIs for review (#1488) (60a1b61)
  • registry: index URLs per revision and serve only live revisions (#1487) (4d6b8a9)
  • registry: return the canonical API name from inspect (#1480) (d649879)
  • registry: suspend agent credential bindings when their API is deleted (#1485) (5ce38ae)

0.40.0 (2026-09-29)

⚠ BREAKING CHANGES

  • platform: credentials & approvals overhaul — retire access requests and service accounts, redesign Agents/Monitor UI (#1458)
  • remove toolkits — direct agent-credential bindings (theme 5, phases 0-6a) (#1370)

Features

  • admin: hard delete for OAuth clients (#1344) (52dc270)
  • auth: accept form-encoded bodies on /oauth/introspect (#564) (bb43ec9)
  • auth: inline agent creation on the zero-agents consent page (#1332) (be4cb75)
  • broker: unregistered_url_handler seam on AppContainer for discovery misses (#1281) (012d3f0)
  • cli: support multipart/form-data bodies in execute (#1317) (8348cf8)
  • config: EncryptionKey material sources (env/file) + one-shot config caching (#1286) (8fb8102)
  • helm: give the chart a production shape (#1396) (6d65741)
  • instance: expose the MCP broker URL via /instance and both MCP UIs (#1338) (5651b8e), closes #1249
  • mcp: serve import_api on the daemon-native /mcp mount (#1326) (4c5a602)
  • mcp: serve request_access on the daemon-native /mcp mount (#1331) (9cbef66)
  • mcp: serve the skill set as resources on the /mcp mount (#1335) (e0561fe)
  • platform: credentials & approvals overhaul — retire access requests and service accounts, redesign Agents/Monitor UI (#1458) (553b865)
  • registry: identity-scoped GET /governed-hosts digest endpoint (#1283) (2013cc3)
  • remove toolkits — direct agent-credential bindings (theme 5, phases 0-6a) (#1370) (5d154c5)
  • skills: per-audience jentic skill — router SKILL.md + lane references, served on every surface (#1336) (3d68fab)
  • ui: hard-delete OAuth clients from the danger zone + Disable/Enable vocabulary (#1346) (6ef8614)
  • ui: rebuild the OAuth clients settings surface (#1318) (01e4777)
  • ui: render agent_status dormancy marker on OAuth grant rows (#1358) (b7801b0)
  • ui: show the deployment's MCP endpoint on the Settings page (#1330) (6e80e40)

Bug Fixes

  • admin: scope job reads and cancellation to the owning actor (#1461) (db6293a)
  • admin: strict IdP email_verified parsing and guards on managing other users (#1462) (1b682d2)
  • auth: accept only first-party sessions on session continue (#1466) (30931e2)
  • auth: advertise revocation auth method none in the root RFC 8414 doc (#1328) (9152c0f)
  • auth: enforce a scope ceiling and owner scoping on agent writes (#1463) (b5f0e7f)
  • auth: keep grants dormant on agent disable and make listings honest (#1345) (5f93475)
  • auth: revoke oauth consent grants when an agent is archived (#1340) (27b4e97), closes #1233
  • auth: speak RFC 6749 §5.2 errors on the token endpoint (#1339) (9dd1f8a)
  • cli: don't block on idle non-TTY stdin in execute (#1354) (#1361) (5f07a67)
  • cli: keep credentials on their origin across redirects (#1469) (d3806c0)
  • cli: parse JSON-RPC envelope strictly in the MCP HTTP pre-auth check (#1467) (81b9e6e)
  • cli: refuse --token-file with --allow-unauthenticated on jentic mcp --http (#1329) (59b6dea)
  • cli: run local-agent probes without startup files and harden privileged file handling (#1472) (00ea3a2)
  • cli: stop TestListenerFromFD leaking a dup that closes recycled fds (#1350) (6aea232)
  • config,control: derive OAuth redirect_uri from public origin (#818) (#887) (9c1ad6f)
  • control: require credential ownership for binding rule writes and resume (#1471) (d33e7a9)
  • events: document and enforce event severity classification (#907) (#1397) (503e1cb)
  • logging: mask query-string values in outbound URL logs and spans (#1473) (1c7273f)
  • mcp: drop dangling next_tool pointers on the HTTP lane (#1327) (a418a70)
  • mcp: make served tool descriptions and actionable prose lane-true (#1347) (7898d11)
  • migrations: run the toolkit flatten and key retirement inside the migration run (#1411) (cd17532)
  • registry: resolve URL-index lookups to the canonical API name (#1460) (03da711)
  • security: classify embedded IPv4 and non-global ranges in egress checks (#1470) (062705b)
  • security: keep submitted and injected values out of error details (#1464) (ddc546b)
  • security: scope credential binds to the owner and bound the toolkit injection path (#1409) (976e312)
  • setup.sh: retry db readiness through postgres restart window (#1357) (2f9af4f)
  • tracing: keep exception text and request data out of exported spans (#1474) (521c9d9)
  • ui: make the agent rail a containing block to stop phantom page scroll (#1321) (e6c01c7)
  • upgrade: report elevated grants and cross-owner bindings carried over by the upgrade (#1465) (aab9827)

Documentation

  • api: align lifecycle vocabulary across endpoint summaries and docs (#1348) (5a11e00)
  • installation: production install guides, docs restructure, and CLI package channels (#1142) (96a2f6d)

Build System

  • deps-dev: bump @playwright/test in /ui in the testing group (#1364) (a5b903a)
  • deps-dev: bump @types/node in /ui in the types group (#1365) (a7d3eb3)
  • deps-dev: bump @types/node in /ui in the types group (#1391) (486fa86)
  • deps-dev: bump @types/node in /ui in the types group (#1447) (96589f0)
  • deps-dev: bump prettier from 3.9.6 to 3.9.8 in /ui (#1448) (e7e4415)
  • deps-dev: bump the python group with 2 updates (#1451) (e59359c)
  • deps-dev: bump the vite group in /ui with 5 updates (#1389) (eccc9d7)
  • deps-dev: bump typescript-eslint in /ui in the eslint group (#1363) (183eb0f)
  • deps-dev: bump typescript-eslint in /ui in the eslint group (#1446) (b937f68)
  • deps: bump anyio from 4.13.0 to 4.14.2 (#1395) (1f623aa)
  • deps: bump framer-motion from 13.2.0 to 13.4.0 in /ui (#1393) (4a394bf)
  • deps: bump lucide-react from 1.40.0 to 1.43.0 in /ui (#1366) (c522380)
  • deps: bump lucide-react from 1.43.0 to 1.47.0 in /ui (#1392) (7e8b00a)
  • deps: bump the python group with 3 updates (#1367) (57230b0)
  • deps: bump the python group with 4 updates (#1394) (1e48c2e)
  • deps: bump the react group across 1 directory with 5 updates (#1390) (0f5a9ec)

0.39.1 (2026-09-23)

Hotfix release cut from v0.39.0 (not main): bounds broker credential resolution to the toolkit an execution is authorized against, and picks up the anyio security update, without shipping main's in-flight work.

Bug Fixes

  • broker: bound credential resolution to the selected toolkit (#1401)

Build System

  • deps: bump anyio from 4.13.0 to 4.14.2 (#1395)

0.39.0 (2026-09-08)

⚠ BREAKING CHANGES

  • auth: deployments that relied on the old default (DCR clients auto-approved at registration) must now either set server.mcp.oauth.auto_approve_clients: true explicitly or approve pending clients through the admin queue.

Features

  • auth: approval-in-flow page for pending OAuth clients on /authorize (#1264) (a44cee6)
  • auth: default MCP OAuth DCR to admin approval, not auto-approve (#1247) (dccb57d)
  • auth: local-account login form on the /authorize flow (#1285) (4850b2b)
  • auth: platform-consistent styling for OAuth pages (login + consent) (#1314) (1bfe7fd)
  • auth: platform-session reuse on /authorize (identity-ladder rung 1) (#1300) (aec21ce)
  • auth: RFC 7009 token revocation for MCP OAuth clients (closes G11) (#1237) (29a98b3)

Bug Fixes

  • auth: accept RFC 8252 private-use redirect schemes on the anonymous DCR door (#1246) (5e243ce)
  • auth: DCR dedupe re-attach honors the D7 client gate (#1313) (2f9fd5b)
  • auth: dedupe software_id-less DCR registrations by name + redirect set (#1261) (5917ed6)
  • auth: include the RFC 6749 §5.1 scope member in every token response (#1262) (749cbc4)
  • auth: omit unset optional members from OAuth responses (#1259) (25f10b7)
  • auth: omit unset optional metadata from the anonymous DCR response (#1250) (749fa18)
  • config: remove static placeholder secret defaults from the shipped image (#1255) (305f4e2)
  • deploy: mount app-secrets on admin/registry and share the parts-mode jwt_secret (#1258) (b485fb6)
  • mcp: answer 405, not the 401 challenge, to credential-less GET /mcp (#1257) (464de56), closes #1256

Refactors

  • admin: factor credential check out of AuthService.login into authenticate (#1282) (38f4cb9)

Documentation

  • auth: document Ed25519 key requirement in RegisterRequest schema (#566) (5817943)
  • comments: remove how-it-used-to-be context from code comments (#1248) (2096b7c)

Build System

  • deps-dev: bump @testing-library/react in /ui in the testing group (#1269) (8fbd113)
  • deps-dev: bump @testing-library/user-event (#1291) (3d3d5cd)
  • deps-dev: bump @types/node (#1294) (ce15862)
  • deps-dev: bump @types/node in /ui in the types group (#1270) (7451e1c)
  • deps-dev: bump @types/react-dom in /ui in the react group (#1290) (14a2d76)
  • deps-dev: bump @vitejs/plugin-react in /ui in the vite group (#1265) (403128e)
  • deps-dev: bump globals from 17.11.0 to 17.12.0 in /ui (#1272) (418dde7)
  • deps-dev: bump ruff from 0.16.5 to 0.16.6 in the python group (#1292) (3d88796)
  • deps-dev: bump sharp from 0.35.3 to 0.35.4 in /ui (#1274) (124d32a)
  • deps-dev: bump the vite group across 1 directory with 4 updates (#1289) (62ea866)
  • deps-dev: bump typescript-eslint (#1288) (eee0585)
  • deps: bump @tanstack/react-query from 5.102.3 to 5.102.8 in /ui (#1273) (04ffce1)
  • deps: bump framer-motion from 13.1.1 to 13.2.0 in /ui (#1293) (dd4f04a)
  • deps: bump lucide-react from 1.32.0 to 1.39.0 in /ui (#1271) (2333432)
  • deps: bump lucide-react from 1.39.0 to 1.40.0 in /ui (#1295) (24d05cd)
  • deps: bump react-router in /ui in the react group (#1268) (a0417d2)
  • deps: bump the python group with 5 updates (#1275) (2e27ff7)

0.38.0 (2026-09-03)

Features

  • auth: /mcp-scoped RFC 8414 + RFC 9728 discovery + 401 resource_metadata (3a-4) (#1221) (fef9aa4)
  • auth: anonymous DCR front door + awaiting-approval page (3a-2) (#1219) (7b83f69)
  • auth: consent→agent binding with oauth_client_grants + grant-channel tokens (3a-3) (#1220) (76bdacf)
  • auth: OAuth client registry, agent JWKS PUT, and token provenance (#1151) (288978e)
  • auth: public secret-less OAuth clients + approval lifecycle (3a-1) (#1218) (6a3604e)
  • cli: add execute + get_execution_result MCP tools with broker hardening (#1186) (30fbc9c)
  • cli: add jentic mcp stdio server skeleton with pre-auth tools (#1209) (d3f9bc4)
  • cli: add search_apis + inspect_operation MCP discovery tools (#1183) (2602274)
  • cli: add search_catalog + import_api + request_access MCP tools (#1213) (70b91b2)
  • cli: auto-register MCP entries per runtime with optional isolation (#1191) (a3a6ea5)
  • cli: official CLI container image + MCP registry entry (2-E4 PR A+B) (#1224) (1f203d0)
  • cli: serve skills as MCP resources with hosted/bundled provenance (#1192) (9ab637c)
  • mcp: daemon-native Streamable HTTP /mcp mount (phase-3 items 1-3) (#1230) (9856c3f)
  • mcp: HTTP-transport session telemetry + docs/advertisement (phase-3 items 6+8) (#1232) (d262d6f)
  • mcp: isolated local daemon mode — jentic mcp --http + --connect relay (phase-3 item 9) (#1234) (250ff66)
  • telemetry: add Origin.MCP + MCP session/config events (#1178) (241c609)
  • ui: OAuth approval queue + per-agent connected-clients panel (3a-5) (#1223) (5c83bfa)
  • ui: per-agent MCP config card + sessions list + origin filter (#1210) (d6e9eb5)

Bug Fixes

  • auth: revoke OAuth client grants on agent ownership transfer (G10, #1222) (#1231) (5737f99)
  • cli: pin CA on cobra execute and refuse redirects on the broker leg (#1217) (25ec336)
  • cli: route token mint through pinned CA transport + attribution hook (closes #1205) (#1215) (84e866a)
  • db: linearize admin migration heads after parallel merges (#1211) (298b24f)
  • ui: use --url in the DCR quickstart register snippet (closes #1204) (#1216) (c555e2e)

Refactors

  • cli: extract agentops from cmd for reuse (#1179) (0923f06)

Documentation

  • deploy: buyer-facing AWS Marketplace install guide (#1187) (8fa0e5c)
  • web: advertise jentic mcp in llms.txt + same-host hardening recipes (#1180) (3955d5f)

Build System

  • deps-dev: bump @testing-library/user-event (#1197) (1e58ced)
  • deps-dev: bump @types/node (#1198) (e70094f)
  • deps-dev: bump @types/react-dom (#1196) (ed78328)
  • deps-dev: bump browserslist from 4.28.2 to 4.28.8 in /ui (#1226) (a856092)
  • deps-dev: bump the python group with 3 updates (#1202) (6cd37e1)
  • deps-dev: bump the vite group in /ui with 2 updates (#1193) (428fe17)
  • deps: bump @tanstack/react-query from 5.101.4 to 5.102.3 in /ui (#1199) (31133e1)
  • deps: bump framer-motion from 13.1.0 to 13.1.1 in /ui (#1200) (bcf0c34)

0.37.4 (2026-08-28)

Bug Fixes

  • deploy: set JENTIC__APPS=broker on the Marketplace broker pod (#1182) (6d2c883)
  • entitlement: use Count entitlements and release the checkout seat (#1184) (a451813)

0.37.3 (2026-08-28)

Bug Fixes

  • docker: venv-install the wheel in the per-service images too (#1172) (c2f6669)

0.37.2 (2026-08-28)

Bug Fixes

  • docker: move shipped images off Debian's won't-fix glibc CVEs (#1170) (a0bfee7)

0.37.1 (2026-08-27)

Bug Fixes

  • ci: drop stale placeholder assertion from the Marketplace chart gate (#1166) (a0c363f)
  • helm: bake un-prefixed image tags into the Marketplace chart (#1169) (67fb464)

0.37.0 (2026-08-27)

Features

  • helm: generate the bundled-DB passwords too — zero-touch Marketplace install (#1163) (bece9f0)

Bug Fixes

  • helm: stamp explicit per-service image tags into the baked Marketplace chart (#1164) (5e4ab87)

0.36.0 (2026-08-27)

Features

  • helm: generate all mandatory app secrets, not just the keyset (#1160) (aaf72ec)

Bug Fixes

  • ci: create the cli/vX.Y.Z tag via the REST API, not git push (#1162) (7fcedbd)

0.35.0 (2026-08-27)

Features

  • helm: chart-managed credential-encryption keyset (global.encryption) (#1159) (90dfd00)

Bug Fixes

  • helm: AWS-parseable image format for the Marketplace psql reference (#1156) (a493b2b)

0.34.0 (2026-08-27)

Features

  • helm: pass AWS Marketplace chart validation (#1155) (7bb2526)

Bug Fixes

  • docker: harden the Marketplace postgres mirror to pass the Trivy gate (#1153) (e8d0092)

0.33.0 (2026-08-27)

Features

  • ci: publish the Helm chart to Marketplace ECR as an OCI artifact (#1145) (c15eab8)
  • helm: first-party bundled Postgres on the official image (#1150) (2005f18)
  • helm: make the Marketplace listing RDS-only, park the postgres mirror (#1143) (7e4b244)
  • helm: Marketplace launch wiring — service account + license secret (#1149) (e55318e)

Bug Fixes

  • ci: docker login before cosign signs the Marketplace chart (#1148) (ef56ec6)

0.32.1 (2026-08-26)

Bug Fixes

  • auth: re-check actor status on every token verdict so disable kills outstanding tokens (#1137) (4dd7acd)

0.32.0 (2026-08-25)

Features

Bug Fixes

  • install: build the server from source for a non-release Docker install (#1093) (0acd0a8)
  • registry: accept canonical vendor/name/version slugs in search api filters (#1083) (af5c094), closes #1080
  • registry: make trailing-slash paths matchable in the broker URL index (#1096) (8b83d6d), closes #1085

Build System

  • deps-dev: bump @testing-library/user-event (#1103) (4f7af70)
  • deps-dev: bump @types/pg (#1104) (dcb9450)
  • deps-dev: bump the eslint group across 1 directory with 5 updates (#1072) (3ab5469)
  • deps-dev: bump the vite group in /ui with 4 updates (#1102) (4edfa3b)
  • deps: bump lucide-react from 1.31.0 to 1.32.0 in /ui (#1105) (3f21e2a)
  • deps: bump the python group with 19 updates (#1107) (1d6a5c3)

0.31.1 (2026-08-18)

Bug Fixes

  • docs: repair the agent onboarding front door and add a drift guard (#1071) (148b122)
  • registry: Flow-3 concurrency follow-ups — A4b supersede target + notify durability (#940, #941) (#1048) (535d1e3)
  • registry: rollback base state-fidelity (#939) + auth layering guard (#938) (#1047) (a7f8b9b)
  • security: patch util-linux CVE-2026-53615 in the app image base (#1060) (7b212e2)

Refactors

  • registry: search-strategy shadowing guard (#958) + sha-less spec_digest collision (#780) (#1045) (9eaec98)

Documentation

  • add llms.txt, and an install-and-use section to AGENTS.md (#1052) (087b800)
  • readme: fix first-run admin flow guides (#1068) (96c4e7b)
  • readme: rewrite the front door for discovery and first-run success (#1051) (59eff46)

Build System

  • deps-dev: bump @testing-library/user-event (#1073) (91c6445)
  • deps-dev: bump globals from 17.9.0 to 17.11.0 in /ui (#1074) (5f9f07f)

0.31.0 (2026-08-14)

Features

  • auth: add agent ownership-claim primitive (#1042) (6b5337a)
  • helm: AWS Marketplace values + required DB password guards (#1039) (7e26cea)

0.30.3 (2026-08-12)

Bug Fixes

  • broker: gate background jobs on enabled apps, not DB presence (#1028) (b6cf312)

0.30.2 (2026-08-12)

Bug Fixes

  • auth: build OIDC callback URI from canonical base URL (#1026) (1c2934b)

0.30.1 (2026-08-12)

Bug Fixes

  • config: coerce indexed env vars into lists (#1023) (a4bc4fb)

0.30.0 (2026-08-11)

Features

  • auth: add SSO login seams — Google provider, provisioning hook, superset verifier (#1021) (2795a05)

0.29.1 (2026-08-10)

Bug Fixes

  • reference: key prefixed included-router routes by their full path (#1018) (9805994)

0.29.0 (2026-08-07)

Features

  • workspace: make API revisions & overlays legible in the workspace UI (#1002) (5b011f0)

Bug Fixes

  • ingest: keep bare YAML dates as strings so specs stay JSON-serializable (#983) (42a8f38)
  • ingest: keep non-finite YAML/JSON floats as strings so specs stay JSON-serializable (#987) (5bd79cd)
  • ingest: wrap parser escapes so malformed spec content fails cleanly (#989) (bc48601)

0.28.1 (2026-08-06)

Bug Fixes

  • install.sh: make the piped re-exec source URL overridable (#972) (e124104)
  • skills: sync #911 reuse guidance into the jentic skill source (#977) (0c153b8)

0.28.0 (2026-08-06)

Features

  • access-requests: surface existing-toolkit reuse on the provision path (#897) (#911) (6136c24)
  • app: in-app update banner for new releases (#964) (322a7ef)

Documentation

  • .github: align the PR template with the shared description convention (#968) (f94bc3e)
  • plans: move implementation plans to the jentic-one-plans repo (#967) (7095f73)

0.27.0 (2026-08-05)

Features

  • cli: make jentic run launch Codex, Cursor, and Hermes as isolated agents (#935) (d05f6c7)
  • cli: run local coding agents as a dedicated unix user (#853) (8052479)
  • credentials: add AWS SigV4 credential type (#776) (#888) (a11025a)
  • skills: distribute a served skill set to agents (#966) (49345b7)

0.26.0 (2026-08-04)

Features

  • cli: guard docker-backed commands against a stopped daemon (#942) (7ddbb09)
  • flow3: close the overlay-update reconciliation loop (#937) (d24dcd7)
  • flow3: jitter the catalog update-sweep interval to de-phase replicas (#917) (6c5b755)
  • flow3: overlay-loop legibility, hygiene & lifecycle follow-ups (#955) (8b33d88)
  • flow3: standalone catalog-update scanner + update-available surfaces (#912) (c152bb6)
  • overlays: persist superseded_revision_id at materialize time (A5a) (#918) (95b8c14)
  • overlays: purpose-scoped overlays:confirm gate (#916) (cc7b218)
  • overlays: re-materialize a confirmed overlay on edit (D1, #927) (#956) (2e11149)
  • persist catalog identity (api_id) and title API surfaces from it (#852) (73cb558)
  • seams: add register_pipeline_stage — ingest pipeline extension seam (#957) (d1472c9)

Bug Fixes

  • cli: distinguish "docker not installed" from a stopped daemon (#961) (2d2da92), closes #954
  • cli: gate the stack update on its own recorded ref (#944) (6de0631)
  • cli: honor --ref when building the stack (#950) (abbe0a8)
  • cli: let Ctrl-C cancel the Docker-daemon probe's cold-start wait (#960) (a239f78), closes #953
  • cli: stop start coming up on an unmigrated database (#952) (0526a10)
  • monitoring: include the current partial minute in usage aggregates (#915) (e414d1c)
  • web: revalidate the SPA shell and cache hashed assets immutably (#946) (8fdbc2f)

0.25.0 (2026-07-31)

Features

  • act on access-request satisfaction hints across reviewer and fulfilment surfaces (#902) (c86f4d1)
  • catalog: notify when a registered API's upstream spec changes (Flow 3 MVP) (#893) (a042885)
  • overlay: materialize confirmed overlays onto the served spec (#904) (2964069)
  • ui: rail day separators, proactive failure surfacing, and monitor event drill-in (#873) (db65dd8)

Bug Fixes

  • broker: derive a valid trace_id at the execute edge instead of raw headers (#905) (eff4d7c)
  • catalog: rank whole-word api_id matches above substring matches (#872) (46a919a)
  • install.sh: default to the latest release tag, not main (#909) (741854f), closes #908
  • ui: reset catalog scroll to top on new search or filter (#850) (7303a1c)

Refactors

  • ui: share the detail-console grammar across toolkit, agent, and SA consoles (718da62)

Documentation

  • skill: drop obsolete import-workflow injection guards (#889) (2ea0591)

0.24.0 (2026-07-31)

⚠ BREAKING CHANGES

  • broker/auth: self-contained JWTs presented at the broker edge must now embed an actor_type claim of "agent" or "service_account" (alongside sub and exp). External trusted (JWKS) issuers must update their minting before upgrading; a token without actor_type — previously treated as an agent — is now refused with a 401.

Features

  • access-requests: composite multi-item access requests end to end (#869) (33c7e23)
  • access-requests: surface already-satisfied items and adopt existing artifacts in fulfilment wizard (#885) (5d6ecfe)
  • ui: rebuild the agents pages as an identity console (#878) (73c632b)

Bug Fixes

  • broker/auth: typed token errors, fail-closed actor_type, refusal logging (#880) (44268e6)
  • credentials: honest updated_at, immutable api_key binding, vendor-wide reuse (#881) (76d156b)
  • ingest: resolve effective operation security op-level-else-document-level (#886) (3961336)

Documentation

  • skills: add contribute-spec-fix skill (overlay fix -> PR -> optional local apply) (774a56e)
  • skills: add import-new-api skill (new-API import flow) (572f950)

0.23.0 (2026-07-29)

Features

  • broker: execute credential attribution + upstream passthrough fidelity (#791) (0379a0d)
  • control: expose public GET /instance backend-identity endpoint (#702) (#733) (0a2fed7)
  • release: publish app image to GHCR + document self-hosted deploy (#732) (7ac00a0)
  • theme-3 access-request residuals + broker visibility (#778) (#792) (d4a6408)
  • toolkits: rebuild the toolkit pages as a tabbed safety console (1ab0e34)

Bug Fixes

  • cli/install,broker: reuse secrets on reinstall; map DecryptionError to 424 (#794) (3138814)

0.22.0 (2026-07-29)

Features

  • access-requests: filer-owner enrichment, widened UI type, shared queue helpers (#858) (5c55059)
  • ui: rebuild dashboard into layered gateway-health overview (#859) (1c22567)

Bug Fixes

  • auth: fail closed on missing or unknown actor_type in verify_token (#863) (ecd5c17)
  • auth: repair expired-token login race and add sliding web sessions (#857) (d716c15)

0.21.0 (2026-07-28)

Features

  • cli: delegate Homebrew-managed CLI updates to brew upgrade (#855) (a6cdd4e)
  • cli: refuse self-update of Homebrew-managed installs (#854) (c9375ca)
  • ui: reorder toolkit hierarchy and enable two-way agent↔toolkit binding (#797) (ccd9441), closes #636 #637 #607 #591

Bug Fixes

  • cli: skill-install funnel — honest list, non-TTY default, ratified scopes (#824) (a4fdedb)
  • monitor: show exact day-aligned windows in the Execution Volume chart (f8963e3)

Documentation

  • monitor: correct stale trend-length and NULL-key comments (0a60457)
  • onboarding: disambiguate self-hosted Jentic One from the Jentic cloud platform (#851) (2a5ccfd)
  • skill: stopped-instance branch, backend-identity check, honest rule proposals (#843) (45444f3)

0.20.0 (2026-07-27)

Features

  • ui: live agent-registration surfaces, agent-named toolkits, generated reference docs (#807) (cb0a20a)
  • ui: port the jentic-mini Monitor Overview onto GET /monitoring/usage (#808) (ba30d1f), closes #386
  • web: serve the onboarding skill and llms.txt from the deployment (#810) (463d583)

Bug Fixes

  • deploy,app,tests: make the Helm smoke matrix green and gate releases on it (#793) (72df0f3)
  • smoke: skip harness tests when smoke-upstream is not deployed (77554a4)
  • ui: upgrade react-router to v8 (#811) (af6fd24)
  • web: sync the served onboarding skill with the CLI embed (#822) (7fb89f6)

0.19.0 (2026-07-24)

Features

  • control: generic access-filter seam for extension read scoping (#769) (8ca6267)

0.18.0 (2026-07-24)

Features

  • access-requests: provisioning-plan access request (#757) (138cb42)

Bug Fixes

0.17.0 (2026-07-24)

Features

  • admin: derive expired invite state at read time (#782) (2456eef)
  • ui: discovery, import entry point, and simpler delete confirm (#767) (650265c)

Bug Fixes

  • registry: restore operation inputs (parameters + requestBody) on import (#773) (f82b8c7), closes #768

0.16.0 (2026-07-23)

Features

  • auth: invite-redemption page for finishing account creation (#734) (d758df4)
  • cli: make jenticctl update version/tag-driven and default confirm to Yes (#766) (591a327)

0.15.3 (2026-07-22)

Bug Fixes

  • install.sh: re-exec under full bash from POSIX-mode /bin/sh (#764) (b98f205)
  • registry: preserve path params for RFC 6570 reserved-expansion paths (e.g. {+property}) (#759) (#762) (fb03462)

0.15.2 (2026-07-22)

Bug Fixes

  • update: resolve v-prefixed release tags for bare-semver refs (#760) (107d530)

0.15.1 (2026-07-22)

Bug Fixes

  • broker: parse permission-rule JSON columns on the SQLite read path (#756) (74f1a5e)
  • build: exclude generated src/jentic_one/static from Docker context (#729) (83403a1), closes #654
  • control: widen credentials.api_version and map DB data errors to 4xx (#722) (b0da8d0), closes #690
  • install: reliably add ~/.jentic/bin to PATH (#730) (97e0b8f)
  • registry,control,broker: stop stranded credentials colliding on API re-import (#643) (#728) (16287d5)
  • ui: use a dedicated muted token for input placeholder text (#736) (4d79812), closes #673

0.15.0 (2026-07-21)

Features

  • auth: resolve toolkit binding names in /me whoami (#686) (#726) (45c4683)

Bug Fixes

  • admin: generate agent-toolkit-binding ids app-side on SQLite (#715) (d8e2006)
  • auth: add token_endpoint_auth_signing_alg_values_supported to OAuth metadata (#712) (7926e6d)
  • broker: hint at region/server-variable mismatch on upstream 401/403 (#638) (#717) (9098a71)
  • broker: make no_toolkit_binding directive recommend credential-first order (#720) (1292b1e), closes #683
  • cli: make broker default host bare to avoid double scheme (#724) (be0c945), closes #657
  • control: let a bound agent read its toolkit and its credentials (#665, #682) (#718) (5f68945)
  • control: let a bound agent write to its toolkit and 403 (not 404) when scope-hidden (#725) (16bdbdb), closes #682
  • control: normalize credential api_vendor/api_name to registry slug (#719) (083d871), closes #656
  • registry: make spec re-import idempotent and surface readable errors (#721) (2b93cfd), closes #688
  • registry: reload API view after promote-over-live to avoid MissingGreenlet (#723) (0eb426d), closes #642

Documentation

  • control,broker: clarify permission rules and broker path format (#576) (a00a974)
  • intake: point de-dup at the candidate_issues list, not a live search (#649) (9269ba6)

0.14.3 (2026-07-20)

CI/CD

  • release: force patch release to republish v0.14.2 artifacts (#710) (af65126)

0.14.2 (2026-07-20)

Bug Fixes

  • access-requests: replace leaked <missing> placeholder with actionable field error (#565) (674ce8a)

0.14.1 (2026-07-20)

Bug Fixes

  • auth: prevent SQLite deadlock in JWT assertion token exchange (#580) (44a577d)
  • auth: set owner_id on DCR agent approval for toolkit visibility (#563) (b6f0025)

0.14.0 (2026-07-20)

Features

  • ci: add ux and ax experience labels to intake taxonomy (#590) (2061eb1)
  • cli: export tree builders + core.Run for downstream CLI composition (#661) (8563dec)
  • credentials: Tier-1 credentials revamp, health, audit & toolkit surfaces (#499) (918c9dc)
  • oss: migrate david contributions (40627bc)
  • oss: migrate manuel jentic contributions (db3cb26)
  • oss: migrate renton mcneill contributions (2654c92)
  • scopes: add catalog:import scope, default-on for agents (6b53c7d)
  • scopes: add catalog:import scope, default-on for agents (1b263c1)
  • ui: add extraRoutes seam to App for downstream SPA composition (#664) (61e720a)
  • ui: align fonts, design tokens, navigation, and page shell with jentic-webapp (#408) (5f88bc4)
  • ui: Monitor page with cross-linked traces/jobs (#477) (558bd7b), closes #457
  • workspace+discover: unified Discover surface and Workspace management (#447) (619a294)

Bug Fixes

  • auth: retry DCR admin-DB write on transient SQLite lock (#548) (066d2c4)
  • broker: drop PBAC and identity caches from 30s to 3s to reduce staleness window (#545) (3cd1bd7)
  • ci: shorten ax label description to under 100 chars (#598) (db2c87a)
  • ci: workflow missing dep (99f9d60)
  • cli: fail fast when docker daemon is unreachable (85ee0db)
  • cli: resolve uv venv and ui build issues for local installs (92fbbc2)
  • cli: resolve uv venv and ui build issues for local installs (7e3beae), closes #535
  • cli: stop telemetry consent prompt swallowing the first Enter (#546) (a113237)
  • db: eliminate SQLite "database is locked" via BEGIN IMMEDIATE (f2d2fb1)
  • github: intake output-guard + Slack notification polish (#582) (6131e3e)
  • install: sync build source by fetch+reset so a rewritten main can't dead-end install (b84bca4)
  • install: sync build source by fetch+reset so a rewritten main can't dead-end install (7b28f93)
  • readme: remove bad link (0749ba3)
  • search: include active IMPORTED revisions in lexical search (30bb463)
  • search: include active IMPORTED revisions in lexical search (78c09b9)
  • search: render FTS config as regconfig so Postgres lexical search works (172f76e)
  • search: render the FTS config as regconfig so Postgres lexical search works (e555e02)
  • security: resolve token scopes live from actor grants (57b5a59)
  • security: resolve token scopes live from actor grants (f2d5283), closes #531
  • sqlite: eliminate "database is locked" via write-scoped BEGIN IMMEDIATE (6c8d556)
  • sqlite: scope BEGIN IMMEDIATE to writes, not reads (c648e13)
  • test_postgres_lexical.py: silence mypy no-untyped-call on stmt.compile (9a80e1f)
  • uninstall: remove docker data volume by name on purge (#547) (bc06be0)
  • update trivy-action version (fa81d98)
  • use master branch for trivy action (c9a1ff0)

Refactors

  • auth: encode token lifecycle via is_ephemeral column (7efb160)
  • compose.go: use postgres:16 instead of pgvector image (#549) (97826eb)
  • install: satisfy gosec on UI build/copy helpers (79f4bf5)
  • oss: migrate to opensourceable codebase (77c923f)
  • seams: add pluggable extension points across backend, CLI, and UI (#562) (61d67e6)
  • token_resolver.py: use SQLAlchemy Boolean type for is_ephemeral (ce1a8ff)

Documentation

  • add public beta warning and quick start to README (c98d162)
  • add public beta warning banner to README (dd00a81)
  • explicitly name jenticctl in quick start (9072f32)
  • hoist quick start install command to top of README (383add4)
  • skill: reflect catalog:import default-grant for cataloged imports (#550) (4098999)

Build System

  • release: implement the beta-blocking release automation (release-please + GoReleaser) (#667) (39b20c1)