• v0.18.1 5298e6d6c0

    v0.18.1 Stable

    hexajon released this 2026-07-22 17:51:20 +00:00 | 69 commits to main since this release

    Signed by hexajon
    GPG key ID: 6E62A0A72715C1F6

    Changelog

    Features

    • fab96f4 feat(docs): every generated reference page opens with a plain-English summary
    • 7967f8a feat(finish): rerun promise pinned end to end; stale index.lock self-heals or teaches
    • 9476f0a feat(releases): asset download lists every downloaded file with sizes
    • 155bd0f feat(ssh): auth-side SSH preflight - key presence, known_hosts steer, identity probe
    • f5a5797 feat(ssh): protocol mode - persisted git-protocol choice at auth login
    • 5298e6d feat(ssh): typed degradation errors for API-dependent commands in ssh-only mode

    Bug Fixes

    • 7a771c2 fix(actions): unshadow the per-run artifact listing as run-artifacts; guard sibling name collisions
    • f3d886b fix(ci): drop the workflow permissions field - Forgejo ignores it with a warning
    • 09d8653 fix(finish): leftover trailer names files and tree path (#309)
    • f5230ad fix(git): stale-lock recovery covers commit and worktree-add legs; re-stat before removal
    • 02df6e1 fix(guides): remove fabricated flags from tour pages
    • 9480d73 fix(mcp): worktrees rebase summary back under the anti-bloat ceiling
    • 50f1056 fix(prune): deletion output names every deleted branch; preview-first hint for the widened --remote set
    • 0b7b9ff fix(security): bind host-agnostic tokens to a recorded forge host
    • 4ae93bc fix(security): foreign-guard use-ssh dir=, 0600 analytics log, no exec of user-writable stale candidates, redact 403 hint
    • b1a79dd fix(ssh): strip control chars from the probe greeting; success line names the trust boundary
    • b9179ca fix(users): emails delete confirmation names the deleted addresses

    Documentation

    • 947154f docs(#315): backtick-quote angle-bracket placeholders in prose
    • 68a8287 docs(guides): add install.md as canonical install home; slim README to headline one-liner
    • 9b0e1fd docs(guides): move README workflow tours into docs/guides (#316)
    • aba7ae1 docs(install): adopt the voiced Take a Seat install guide as the canonical text
    • 6e3ac7b docs(install): restore the update --verify drift-repair pointer
    • 3cb9148 docs(mcp): restore the two trimmed description fragments; hyphen frees the byte budget
    • ba1b31f docs(public): neutralize private forge hostname in fixtures; retire Gemini from all live client listings
    • c9dc42b docs(public): reword decision attributions to neutral voice; neutralize private example paths
    • ee75221 docs(security): updater trust model + sudoers caveat in SECURITY.md; honest ADR 0027 residual-risk boundary
    • 13aceba docs: canonical install guide at docs/guides/install.md; README leans on madtea.lol
    • abdb2aa docs: mark legacy pre-migration tracker refs as non-autolinking (legacy tracker NNNN)
    • 3c42976 docs: short ADR titles, dead-tracker purge, and render fixes from the docs-site review

    Other

    • 1125c31 harden(mcp): structurally repo-scope the dir= report client
    • 55f5c2e sec(auth): OAuth-minted PATs default to least privilege - Standard tier + read:organization
    • 75dfab1 ux(branch): success lines state the delete was safe - merged, and where the commits live
    Downloads