lgi://changelog
Changelog
Current v3.10.0.2
Versions
v3.9Refit
v3.9 is a refit pass: no new flagship tools, one thesis — better primitives at every layer. The development workflow gains machine-checked state, the application's repeated decisions get owned primitives with enforcement rails, the backlog gets an honest clearance, and the platform's recovery claims get drilled instead of assumed.
v3.9.5.2
20 Jul 2026
Changed
- Character skill saves, NPC station-name resolution, SDE streaming and mapping, and queued skill-name collection now have direct behavioral coverage, including real-Postgres integration tests for the database-bound paths.
- The version-start code-health audit now clears through real coverage without changing production behavior, Fallow thresholds, waivers, baselines, or suppressions.
v3.9.5.1
19 Jul 2026
Changed
- Development-performance, build-command, and design-principle documentation now matches the behavior and examples that actually shipped.
- Server-backed EVE image sizes, family support, and snapping now have one lower-level owner while generated URLs and image rendering remain unchanged.
- The saved-template view verdict is now local and distinctly named from its client controller state, with no runtime or user-visible change.
v3.9.4.1
19 Jul 2026
Added
- A least-privilege database runtime role and a versioned grants migration prepare the application to run day-to-day with far less database power than it holds today, so a leaked runtime credential can no longer reshape or wipe the schema. The change ships inactive; switching production over to it is a deliberate operator step.
- A dedicated migration connection setting lets schema changes run under a separate schema-owner credential, falling back to the existing setting so local and single-role setups are unchanged.
Changed
- Every finding from an external security deep-research review was verified against the live code and recorded in a new disposition register, with the confirmed items routed to the backlog; the one acted-on item is the database privilege separation above, documented in a new database-privilege runbook.
- Planning's mandatory adversarial review now runs at high effort instead of extra-high, matching the review-budget cap.
v3.9.3.8
19 Jul 2026
Changed
- The privacy page now explains in plain language what site and EVE data LGI.tools stores, how long usage and corporation-access records are retained, how rate limiting and browser storage work, what deletion controls remove, and how character transfers prevent inherited access.
- Public project documentation now reflects the five live tools, the current Neon and Convex responsibilities, honest App Router render modes, the authoritative EVE scope source, and the live Convex environment requirements.
- The pull-request template now follows the project's required reviewer-facing structure.
v3.9.3.5
19 Jul 2026
Added
- A daily report-only update watch now compares dependency majors, security advisories, and platform/EVE developer announcements against a committed acknowledged-state baseline, and opens a single GitHub digest issue only for deltas not already reported in an open digest.
- The watch runs as a paused-by-default scheduled cloud routine through a deterministic fail-closed collector: any fetch, query, or listing failure refuses the run instead of reporting a false all-clear, and the routine performs no repository writes.
Changed
- Changelog and dev-log navigation links no longer prefetch on viewport entry, so opening either document browser no longer renders every linked section in one burst.
- The header's EVE server-status read and the dev-log loader now store their cached results in shared storage across server instances, reducing repeated upstream work after cache expiry.
- Planning sessions now discuss the intended shape of a plan in plain English before drafting begins, alongside the existing plain-English summary at approval, and adversarial plan review is capped at one pass plus at most one rerun.
v3.9.3.4
18 Jul 2026
Added
- Local development can opt into a deterministic 20-site catalogue sample that preserves every site-type and wormhole-class pairing while production remains locked to the complete 69-site catalogue.
- The bounded `/sites` profiler now has a six-run counterbalanced suite with machine-checked full/sample catalogue identity, cold-request limits, and a sample-mode comparison gate.
Changed
- Sample-mode profiling cut the median cold `/sites` response from 1.36 s to 1.09 s and the median warm response from 519 ms to 241 ms without reproducing the historical watcher or swap stall.
- Planning workflows now accompany their formal reviewed artifacts with a short plain-English summary before asking for approval.
v3.9.3.3
18 Jul 2026
Fixed
- Unknown wormhole-site ids now terminate at the catalogue boundary with the shared 404 and noindex response, avoiding the production React recovery errors while valid site and social-image routes remain unchanged.
Changed
- Every Claude subagent now runs as a task-scoped headless GPT-5.6 Sol worker, with high, medium, and low effort replacing the former Opus, Sonnet, and Haiku seats and the selected model effort visible in the background-task title.
- Every session, version, version-audit, and audit-remediation plan now receives a fresh extra-high adversarial review before approval, while approved-plan persistence remains session-terminal.
Removed
- The standalone delegated-session workflow skill and its generic full-session executor are gone.
v3.9.3.2
18 Jul 2026
Added
- One shared resolver now decides which EVE image rendition every surface shows: call sites state their intent — show the item, the product hero, what a build node runs, or an industry job — and receive the resolved image, with a lint rail keeping future rendition decisions inside the resolver.
Changed
- The industry landing page's rows now show images with the typographic monogram as fallback: recents and templates show the blueprint scroll, active and corporation job rows show the product being built, and favorites keep their icon and mark with a small star beside the name.
- Blueprint rows in global search and its recent-selections list now show the blueprint scroll rather than the produced item's icon.
- Job rows without a reported product fall back to the blueprint image being run rather than showing no image.
v3.9.3.1
18 Jul 2026
Added
- A drive-session workflow skill records the model-routing and delegated-execution rules for development sessions: which model plans, executes, reviews, and verifies each lifecycle stage, and the acceptance gate the orchestrating session owns.
Changed
- The development backlog was re-verified end to end: every remaining entry carries a confirmed size and trigger, entries whose work is scheduled inside v3.9 now name their owning session, and the closed fallow code-health record collapsed to an archive pointer.
Removed
- Five stale backlog entries whose work had already shipped — asset-tracking wiring, the shared image pipeline migration, agent-guide cleanup, fallow-trial cleanup, and the slot-count readout gap — were deleted with their superseding releases named in the history.
v3.9.2.10
17 Jul 2026
Changed
- The internal token-vending reply now carries only the access token; unread expiry, character, and scope fields no longer ride the wire.
Removed
- The token service's divergent whitespace-only scope parser is gone; stored scope strings have exactly one decoder in the scope-health path.
v3.9.2.9
17 Jul 2026
Changed
- Feature and application code can now import Base UI and sonner only through their sanctioned shared UI wrappers.
- Durable lint fixtures protect the wrapper allowlist, the sole toast owner, and the ban on the deprecated Base UI package.
v3.9.2.8
17 Jul 2026
Changed
- Planner price-confidence rows and aggregate shortfall counts now use the shared exact stale-after boundary instead of maintaining separate comparisons.
- The planner still confirms the complete price set on view, with its confidence labels, reasons, and rendering behavior unchanged.
v3.9.2.7
17 Jul 2026
Changed
- A living primitive ledger now maps 52 decision-owning surfaces across UI, API, data, infrastructure, agent workflow, and trust boundaries, with every enforcement rail or deliberate absence recorded explicitly.
- The closing primitive audit records the delivered lifecycle verdicts and required overlap, pass-through, and zero-consumer judgments; three evidence-backed follow-up verdicts are approved as separately planned slices.
v3.9.2.6
17 Jul 2026
Changed
- Dataset declarations remain with their separate privacy, growth, and ESI placement owners, while one schema-index gate now reports every missing declaration as a complete checklist.
- Foreign keys to user and character identities must use the sanctioned key shapes, preventing novel column names from slipping past the purge registry.
v3.9.2.5
17 Jul 2026
Changed
- Recurring interaction checks now run through one shared Playwright harness with isolated desktop/mobile contexts, standard diagnostics, named checks, mock setup, screenshots, and a combined report.
- Sixteen durable probe definitions replace the scattered one-off launchers, cutting the tracked probe surface by more than half while preserving the recurring UX evidence.
- The workflow drift gate now warns about scratch probe scripts left outside the durable definitions directory so they can be removed at close-out.
Removed
- Twenty-eight genuine, superseded, or retired standalone probe launchers were removed.
v3.9.2.4
17 Jul 2026
Changed
- Every API route now proves its request classification and typed response contract through one completeness gate; schema-less handlers declare whether they take no caller input or only query/path input.
- Client API calls must pass named endpoint declarations from their owning contract modules, with lint rejecting inline endpoint objects that bypass that convention.
v3.9.2.3
17 Jul 2026
Changed
- Every externally refreshed dataset now declares its storage, verified upstream cache window, freshness model, refresh owner, and durable mirrors in one typed registry with a fail-closed placement gate.
- Personal refreshes, affiliation checks, market-price expiry stamps, and market-history boundary checks now derive their freshness decisions from the registry, with lint preventing duplicated dataset windows and feature-local staleness modules.
Removed
- Six mirrored freshness gates and the separate market-price expiry constant were removed.
v3.9.2.2
17 Jul 2026
Changed
- Every cron endpoint now declares its wake class, lock policy, recording policy, and work to one shared lifecycle shell, with the schedule rail rejecting sub-daily jobs that lack an idle-silent declaration.
- The 15-minute deferred-refresh drain now uses Redis due-work and recent-budget-exhaustion signals to skip healthy Neon no-ops, while unknown Redis state and one daily heal slot preserve durable queue recovery.
Removed
- The legacy cron runner and the final route-local auth, lock, response, and telemetry assembly were removed.
v3.9.2.1
17 Jul 2026
Changed
- Real-Postgres suites now share one lifecycle-owning harness for reachability gating, disposable migrated-schema clones, request-path DB steering, identity seeds, resets, and teardown.
- All existing DB suites use the shared primitive, and lint rejects direct Postgres clients or embedded connection strings in those suites.
v3.9.1.7
17 Jul 2026
Changed
- Every exported production interface now states its contract, ownership, units, or caller obligations in a concise interface comment.
- Lint now requires those comments across production source, validates their TSDoc syntax, and rejects source-level TODO and FIXME markers.
v3.9.1.6
16 Jul 2026
Changed
- The workflow drift gate now derives active session contracts and paired runtime skill paths from their existing registries, removing version-boundary list maintenance without weakening missing-file or orphan detection.
- Policy phrase guards now use narrower sentence-bounded patterns, backed by fixture coverage and a seeded fail-closed regression matrix.
v3.9.1.5
16 Jul 2026
Changed
- Release identity, public pull-request privacy, and version-archive fidelity are now mechanically verified at their existing workflow gates.
- Post-merge lifecycle reconciliation now follows the resolver-selected branch and proves the reconciled release state before the next delivery.
v3.9.1.4
16 Jul 2026
Changed
- Cheap code-health baseline claims and Watch promotion thresholds are now recomputed at close-out, surfacing stale counts, deleted measurement targets, and tripped triggers without changing audit classifications automatically.
- Development guides, lifecycle plans, agent skills, and their verification utilities are now version-controlled and reviewed with application changes, while machine-local settings, generated artifacts, and credentials remain private.
v3.9.1.3
16 Jul 2026
Changed
- The workflow drift gate now catches contradictory lifecycle evidence across session plans, roadmap delivery, audit findings, the health baseline, and the current handoff while keeping snapshot-timing lag non-blocking.
- Internal documentation paths and the committed environment example are checked against the live workspace and typed environment registry, with every finding anchored to its source file and line.
v3.9.1.2
16 Jul 2026
Changed
- The lifecycle resolver now enforces exact terminal statuses and the 3.9 plan/contract marker vocabularies, reporting ambiguous or invalid values with their source artifact while keeping legacy artifacts exempt.
- Session contracts that require browser review now carry that gate into the execution pause, and an opt-in git snapshot reports branch, worktree, and main-sync drift as non-blocking warnings without changing default resolver output.
v3.9.1.1
16 Jul 2026
Changed
- The development lifecycle's decisions now each have exactly one owning document and a machine-readable form: watch triggers, plan markers, and contract gates use exact closed vocabularies that upcoming workflow checks can read.
- Planning sessions are now session-terminal: a session that produced an approved plan never executes it, so plan approval and implementation always get separate sessions.
- Stale internal references left by earlier refactors were reconciled, and the engineering guide now specifies the repository-wide interface comment standard ahead of its enforcement.
Removed
- An already-archived internal UI audit document was removed from the repository.