2026-06-13 12:26:27 -04:00
# Changelog
## [unreleased]
### Added
2026-06-14 11:24:36 -04:00
- pytest test suite covering dashboard core, app security, and VRAM detection (#add -pytest-test-suite)
- Root `pyproject.toml` with optional test/dashboard dependency groups (#add -pytest-test-suite)
- `AGENTS.md` with build/test commands and conventions (#developer -experience-gitea-ci)
- `.gitea/workflows/ci.yml` running py_compile, pytest, and shell script syntax checks (#developer -experience-gitea-ci)
- `templates/README.md` documenting the task template examples (#developer -experience-gitea-ci)
2026-06-13 12:26:27 -04:00
- Blocked phase column between Verification and Resolution on dashboard (#additive -extension-model)
- Framework self-enforcement rules in .rules.md and system-prompt.md (#framework -self-enforcement)
- Additive extension model: projects extend via extensions/ dir, never copy framework files (#additive -extension-model)
- CHANGELOG.md for release notes tracking (#changelog )
- Framework audit: comprehensive self-consistency check with RESEARCH.md (#framework -audit)
### Changed
2026-06-14 11:24:36 -04:00
- All prompts now use the canonical task path `{project}/.automaton/tasks/{task-name}/` (#standardize -task-path-conventions)
- `scripts/vram_detect.sh` rewritten as `scripts/vram_detect.py` for testability and correctness (#rewrite -vram-detection-python)
- `tasks/dashboard-spec.md` reconciled with the implemented web dashboard (#reconcile -dashboard-spec)
- `automaton/dashboard/README.md` and help modal shortcuts now match the web UI (#reconcile -dashboard-spec)
2026-06-13 12:26:27 -04:00
- prompts/orchestrate.md: always reads prompts/contracts/scripts from global, project extensions are additive (#additive -extension-model)
- prompts/onboarding.md: removed diff/merge upgrade, replaced with migration check (#additive -extension-model)
2026-06-13 21:09:57 -04:00
- README.md: updated upgrade docs for new additive model (#additive -extension-model); added Dashboard section (#dashboard -task-review)
2026-06-13 12:26:27 -04:00
- scripts/update.sh: simplified to plain git pull (#additive -extension-model)
- .rules.md: converted from template to concrete rules with Task-Driven Development, VRAM-aware sizing, Changelog, and Self-Improvement sections (#framework -self-enforcement)
- system-prompt.md: added instruction to read global .rules.md (#framework -self-enforcement)
2026-06-13 21:09:57 -04:00
- automaton/dashboard/ui/app.py: added review API endpoints (GET/POST /api/task/{name}/review), spec_content in responses, unquote() for URL-encoded task names, path traversal fix (#dashboard -task-review, #spec -in-detail)
- automaton/dashboard/html/dashboard.js: review UI (badges, buttons, filter), artifact badges, specification display, modal conversion, textarea replacement, display group for approved planning tasks (#dashboard -task-review, #artifact -badges, #spec -in-detail, #task -detail-modal, #review -textarea)
- automaton/dashboard/html/styles.css: review components, artifact badges, modal layout, textarea styles (#dashboard -task-review, #artifact -badges, #task -detail-modal, #review -textarea)
- automaton/dashboard/html/index.html: review filter, pending count, modal overlay (#dashboard -task-review, #task -detail-modal)
- automaton/dashboard/core/task.py: fixed state machine priority — IMPLEMENTATION.md now correctly detected, DOC_REVIEW checked before BUG_REPORT (#implement -task)
- automaton/dashboard/core/board.py: fixed KanbanBoard — added missing COLUMNS and __init__ (#implement -task)
- automaton/dashboard/core/refresh.py: improved inotify error handling with explicit fallback messages (#implement -task)
### Fixed
2026-06-14 11:24:36 -04:00
- VRAM detection: undefined headroom, hardcoded JSON headroom, and code-block config parsing (#rewrite -vram-detection-python)
- VRAM detection: 10KB file-read limit now enforced for API config files (#rewrite -vram-detection-python)
- Dashboard static file serving: replaced string-prefix path traversal check with `Path.relative_to()` (#harden -dashboard-security-scripts)
- Dashboard task name validation: restricted to `[A-Za-z0-9_-]+` (#harden -dashboard-security-scripts)
- `scripts/update.sh` : now warns and aborts on uncommitted changes before pulling (#harden -dashboard-security-scripts)
- README/install.sh: replaced placeholder repository URL with real Gitea URL (#harden -dashboard-security-scripts)
2026-06-13 21:09:57 -04:00
- State machine: IMPLEMENTATION.md was never checked in determine_task_state(), tasks showed as RESEARCH (#implement -task)
- State machine: DOC_REVIEW checked after BUG_REPORT — wrong priority order (#implement -task)
- Path traversal: review API accepted task names with ../ allowing writes outside tasks directory (#dashboard -task-review)
- URL encoding: task names with spaces in API paths were not decoded (#implement -task)
- Review parsing: comment extraction used fragile conditional, falsy comments (e.g., "0") skipped (#implement -task)
- Board display: approved planning tasks stayed in Planning column instead of advancing to Design (#dashboard -task-review)
2026-06-14 11:24:36 -04:00
### Removed
- `automaton/dashboard/themes.py` (vestigial ANSI theme stub) (#reconcile -dashboard-spec)
- `automaton/dashboard/core/refresh.py` (half-implemented file watcher; dashboard uses JS polling) (#remove -file-system-watcher)
- `templates/contract-template.md` (unused) (#developer -experience-gitea-ci)
- `automaton/dashboard/pyproject.toml` (consolidated into root `pyproject.toml` ) (#add -pytest-test-suite)
2026-06-13 21:09:57 -04:00
### Migration
- Project migration script for old-model projects: scripts/migrate-project.sh (#project -migration)
- Project migration detection in onboarding.md (#project -migration)