Skip to content

What changed, in plain language.

This page is for users and operators reviewing changes before an update.

This page is generated from the repository changelog, the same record used for release notes. This summary does not replace the complete fixes and migration details in the source file.

In progress

Unreleased

Changed

  • Bounded the local Turbo task cache at 512 MiB through the serialized root task runner and Devenv cache tools, and stopped persisting revision-specific Turbo build archives in GitHub Actions, preventing local growth and cumulative CI cache generations while retaining recent local cache hits.
  • Organization Owners can now select and permanently delete any owned Organization without Workspace access after a complete preview, exact-name confirmation, and recent authentication; unconfirmed Paddle subscriptions, outstanding checkouts, pending ownership transfer, provider-scheduled work, other provider work, and cleanup remain explicit blockers, canceled checkouts cannot resume and retain an opaque boundary that terminates late Paddle subscriptions, failure is atomic, affected access, credentials, current and evidenced historical invitation email Jobs, ownership-expiry or notification Jobs end on success, and only content-free lifecycle and required billing evidence remains.
  • Updated `golang.org/x/image` to 0.45.0 to fix excessive memory allocation while validating VP8L images.
  • Added temporary account-wide and Workspace notification Mutes on both Notifications and Settings, with visible absolute end times and an idempotent end-now action. Mutes pause optional Immediate and Daily email without changing saved preferences, conservatively suppress pre-upgrade queued optional mail whose Workspace scope is unknown, resolve the Workspace scope first when scopes overlap, expire automatically, keep in-app notifications immediate, and never suppress Transactional security, access, invitation, or critical billing email. Workspace-bound credentials receive only their Workspace Mutes when they reconcile state. Database upgrades apply migration 100 automatically.
  • Organization Owners can now select an Organization without Workspace access, see its current Owner, and nominate an active member after recent authentication and exact confirmation; a nominee can resolve the standalone action without Workspace access. Every ownership read and action enforces the Organization identity and SSO assurance decision without requiring Workspace access, and the transport-independent initiation service requires an unscoped browser credential and consumes one recent-authentication grant. The durable, expiring Transactional action uses semantic English and Portuguese notification content, clears and suppresses actions whenever transfer state cannot be loaded or its URL changes, preserves the current Owner through decline, expiry, or revocation, records every reached initiation failure in domain-owned audit evidence, exposes ownership transfers in the Organization audit filter, and atomically moves creator and subscription authority plus the Owner role to the accepting nominee while demoting the prior Owner to Administrator. Database upgrades apply migration 097 automatically; no operator action is required.

41 more entries in the full changelog.

Fixed

  • Kept the generated public Nix module example on `ghcr.io/getopenpost/openpost:latest` even when the linked deployment source pins a verified release digest.
  • Restored marketing and documentation page views by requiring their production PostHog build settings, routed hosted browser telemetry through the managed first-party proxy, added matching page-leave events and privacy-limited Core Web Vitals, and kept route templates in SDK-owned URL properties.
  • "Create another" after first Activation now opens a clean composer instead of retaining the published text and draft identity.
  • Made direct documentation builds restore their ignored OpenAPI inputs from the tracked canonical spec before VitePress starts, so clean deployment checkouts cannot depend on generated local files.
View source record

Release

v3.11.0

Added

  • Added one canonical hosted-plan catalogue and an expiring signed purchase choice that keeps exact pricing and trial terms through password signup, email verification, refresh, and identity-provider signup without defaulting invalid selections to Founder.
  • Added an explicit first-Workspace confirmation that shows the selected plan and trial terms, atomically binds the named Workspace to one checkout attempt, and resumes that attempt after refresh without creating duplicates.

Fixed

  • Kept thread remove controls above their textareas, tightened publication-history and meme-picker overlays to their content, highlighted the active sidebar draft, removed the redundant AI alt-text review note, and retried one safe transient Memegen catalog read.
  • Restored release gating after the hosted purchase-flow merge by accepting formatter-safe provider-catalog sources and checking marketing links and trial copy against the canonical purchase terms.
View source record

Release

v3.10.1

Fixed

  • Qualified PostgreSQL provider-delivery upserts so the durable write fence reaches the provider instead of failing before every publication request.

Changed

  • Pruned completed and currently out-of-scope audit-remediation entries so the backlog contains only active or explicitly deferred work.
View source record

Release

v3.10.0

Changed

  • Added a repository map, an agent workflow router, and a read-only doctor for local workflow artifacts and configured GitHub triage labels.

Fixed

  • Updated the marketing browser contract to verify the fictional workflow disclosure after removal of the unproved customer-logo rail.
  • Made the changed-file pre-push formatter load the Svelte parser explicitly so marketing component changes are checked instead of blocking every push.
  • Removed unproved customer-logo usage claims, labeled generated personas and workflows as fictional examples, and added a dated register that validates proof-claim owners, evidence, review dates, and expiry.
  • Kept failed conversation read-state writes visible and retryable instead of clearing unread state locally, and made Android releases fail closed rather than publishing an unsigned APK under the installable asset name.
  • Bound hosted checkout completion to its opaque billing attempt, persisted a validated same-origin return path with the selected plan and period, and made that path one-time so unrelated subscriptions, refreshes, and replay cannot redirect a user.

8 more entries in the full changelog.

View source record

Need every migration, fix, and release note?

The repository changelog is the authoritative technical record.

Open on GitHub