Skip to content

What changed, in plain language.

This page is for users and operators reviewing changes before an update.

This page is generated from the repository changelog, the same record used for release notes. This summary does not replace the complete fixes and migration details in the source file.

In progress

Unreleased

Changed

  • Proved the collaboration-and-safety cohort across truthful invitation recovery, atomic Workspace and Organization deletion, accepted ownership transfer, permission-safe audit exports, and responsive, localized Daily email and temporary Mute controls.
  • Shared one local Turbo task cache across OpenPost worktrees with a 2 GiB total cap, removed immutable editor models and audio from frontend cache archives, linked those files across generated web, Go embed, and Android trees, and omitted them from CI checkouts that do not build the application. CI keeps exact-run frontend caches ephemeral so source-map uploads still execute.
  • Organization Owners can now select and permanently delete any owned Organization without Workspace access after a complete preview, exact-name confirmation, and recent authentication; unconfirmed Paddle subscriptions, outstanding checkouts, pending ownership transfer, provider-scheduled work, other provider work, and cleanup remain explicit blockers, canceled checkouts cannot resume and retain an opaque boundary that terminates late Paddle subscriptions, failure is atomic, affected access, credentials, current and evidenced historical invitation email Jobs, ownership-expiry or notification Jobs end on success, and only content-free lifecycle and required billing evidence remains.
  • Updated `golang.org/x/image` to 0.45.0 to fix excessive memory allocation while validating VP8L images.
  • Added temporary account-wide and Workspace notification Mutes on both Notifications and Settings, with visible absolute end times and an idempotent end-now action. Mutes pause optional Immediate and Daily email without changing saved preferences, conservatively suppress pre-upgrade queued optional mail whose Workspace scope is unknown, resolve the Workspace scope first when scopes overlap, expire automatically, keep in-app notifications immediate, and never suppress Transactional security, access, invitation, or critical billing email. Workspace-bound credentials receive only their Workspace Mutes when they reconcile state. Database upgrades apply migration 100 automatically.

42 more entries in the full changelog.

Fixed

  • Kept the generated public Nix module example on `ghcr.io/getopenpost/openpost:latest` even when the linked deployment source pins a verified release digest.
  • Restored marketing and documentation page views by requiring their production PostHog build settings, routed hosted browser telemetry through the managed first-party proxy, added matching page-leave events and privacy-limited Core Web Vitals, and kept route templates in SDK-owned URL properties.
  • "Create another" after first Activation now opens a clean composer instead of retaining the published text and draft identity.
  • Made direct documentation builds restore their ignored OpenAPI inputs from the tracked canonical spec before VitePress starts, so clean deployment checkouts cannot depend on generated local files.
View source record

Release

v3.11.0

Added

  • Added one canonical hosted-plan catalogue and an expiring signed purchase choice that keeps exact pricing and trial terms through password signup, email verification, refresh, and identity-provider signup without defaulting invalid selections to Founder.
  • Added an explicit first-Workspace confirmation that shows the selected plan and trial terms, atomically binds the named Workspace to one checkout attempt, and resumes that attempt after refresh without creating duplicates.

Fixed

  • Kept thread remove controls above their textareas, tightened publication-history and meme-picker overlays to their content, highlighted the active sidebar draft, removed the redundant AI alt-text review note, and retried one safe transient Memegen catalog read.
  • Restored release gating after the hosted purchase-flow merge by accepting formatter-safe provider-catalog sources and checking marketing links and trial copy against the canonical purchase terms.
View source record

Release

v3.10.1

Fixed

  • Qualified PostgreSQL provider-delivery upserts so the durable write fence reaches the provider instead of failing before every publication request.

Changed

  • Pruned completed and currently out-of-scope audit-remediation entries so the backlog contains only active or explicitly deferred work.
View source record

Release

v3.10.0

Changed

  • Added a repository map, an agent workflow router, and a read-only doctor for local workflow artifacts and configured GitHub triage labels.

Fixed

  • Updated the marketing browser contract to verify the fictional workflow disclosure after removal of the unproved customer-logo rail.
  • Made the changed-file pre-push formatter load the Svelte parser explicitly so marketing component changes are checked instead of blocking every push.
  • Removed unproved customer-logo usage claims, labeled generated personas and workflows as fictional examples, and added a dated register that validates proof-claim owners, evidence, review dates, and expiry.
  • Kept failed conversation read-state writes visible and retryable instead of clearing unread state locally, and made Android releases fail closed rather than publishing an unsigned APK under the installable asset name.
  • Bound hosted checkout completion to its opaque billing attempt, persisted a validated same-origin return path with the selected plan and period, and made that path one-time so unrelated subscriptions, refreshes, and replay cannot redirect a user.

8 more entries in the full changelog.

View source record

Need every migration, fix, and release note?

The repository changelog is the authoritative technical record.

Open on GitHub