verify / verify (push) Successful in 3m2s
Sanitized allowlisted snapshot of private source 0acd276fb3423405daf7fff26dedc92b8281e2bd. Adds organization, team, invitation, resource hierarchy, scoped access, and audited break-glass foundations while preserving Preview 1. AI-Assistance: OpenAI Codex assisted implementation, testing, security review, and release preparation. Signed-off-by: Cole Speelman <crspeelman@gmail.com>
1.1 KiB
1.1 KiB
Changelog
v0.1.0-preview.2 — 2026-08-17
- Add storage-neutral organizations, teams, projects, environments, services, single-use invitations, and independently scoped access roles.
- Separate platform-level authentication roles from organization data access.
- Add expiring break-glass grants with transactional organization-visible audit events and a no-CGO SQLite implementation.
- Keep
v0.1.0-preview.1immutable; applications adopt these additive packages by explicitly selecting Preview 2.
v0.1.0-preview.1 — 2026-08-16
- Establish independent request metadata, logging, browser security, abuse, authentication, SQLite, and analytics package boundaries.
- Add a minimal 0BSD
net/httpstarter. - Fail closed when unsafe requests lack same-origin evidence or authentication middleware is constructed with invalid cookie/service configuration.
- Bound untrusted request-record byte and duration fields before aggregation.
- Support Linux as the maintained release platform; native Windows is not a release gate or compatibility promise.
No compatibility promise is made before a stable release.