Generated by git-cliff from the commit history (pdm run release-notes); do not edit by hand.
A release marked NO-ROLLBACK adds an event type or a persisted enum value: once it has
written one, the previous image cannot serve the journal, so fix forward (ADR 0007, runbook).
[Unreleased]
Other
- Fix CI workflow: unquoted commas in a flow-mapping step name
- Playwright browser level and per-template unit tests
- Production-readiness and feedback-loop tasks
- Review fixes (checkpoint T05–T16)
- Claude settings allowlist, SessionStart, PostToolUse and Stop hooks
- TG1 review fixes: vault concurrency, claim safety, erasure durability, lawful basis
- Allowlist a fake-hash assertion flagged by detect-secrets
- Move persistence to PostgreSQL (ADR 0009)
- Review fixes (checkpoint T17–T21)
- Postgres plan review fixes (ADR 0009)
- Fix CodeQL workflow: real action SHA, gate on SARIF for a private repo
- Import UI mockups, tokens and screen inventory
- Review fixes (checkpoint TPG1–TPG9)
- Review fixes (checkpoint T22–T27)
- Allowlist a fake commit SHA in the CI script test
- Review fixes (checkpoint T28–T33)
- Allowlist test passwords flagged by detect-secrets
Tasks (bootstrap)
- T01: scaffold, lockfile, stubs, CI
- T02: settings and logging
- T03: architecture test support, test quality, naming
- T04: CLAUDE.md and README
- T05: kernel primitives: events, registry, clock, ids, email
- T06: EventStore port, in-memory store, contract
- T07: event codec, event-module discovery, codec property
- T08: fold, event bus, AggregateStore, version retry
- T09: SqliteEventStore
- T10: projection rebuild and ensure_projections
- T11: composition v1, db init, projections rebuild
- T12: M1 architecture tests
- T13: currency, money, group refusals
- T14: splits: allocate, split modes, payers, lines
- T15: settlement: greedy, exact DP, simplify
- T16: settlement: pairwise debts
- TF5: stable secrets check
- TF6: CI hardening: diff-cover on push, pip-audit, full-tree secret scan
- TF7: Code scanning (CodeQL) and dependabot
- TF8: doc/sdlc.md: phases, branch protection, DoR/DoD
- TF9: ADR log
- TF10: /review skill
- TF11: PR/issue templates, CODEOWNERS, SECURITY.md
- TG1: PII, erasure and event-schema design (ADR 0002, 0007, 0008)
- TG1a: person vault, erasure log, side_write seam, PII and schema-evolution rules
- T17: user aggregate (UserRegistered(user_id), stream user-<user_id>)
- T18: account and session services over fakes
- T19: Argon2 hasher and SQLite session store
- T20: user directory read side
- T21: composition root (M3): Services, service factories, onboarding
- TPG1: Postgres test harness
- TPG2: settings, local Postgres and library rules
- TPG3: Alembic migrations and schema state
- TPG4: PostgresEventStore, journal lock and codec rules
- TPG5: Postgres person vault and session store
- TPG6: kernel cutover to PostgreSQL, SQLite journal/vault/session/directory deleted
- TPG7: db migrate, qa-reset and developer docs
- TPG8: erasure log in the journal database
- TPG9: SQLite gone: rules, allowlists and docs
- T22: group models and events
- T23: group aggregate: lifecycle and membership
- T24: group aggregate: expenses and payments
- T25: group aggregate: debt-simplification toggle
- T26: GroupService with client-id idempotency
- T27: group state-machine property
- TF15: mutation testing workflow
- TF12: board and CI scripts for gh-enabled use
- T28: group read ports and group projection
- TF13: /work skill and stations
- T29: ledger projection and reader
- TF14: ralph loop and gates
- T30: activity rows and reader
- T31: GroupQueryService
- TF15a: raise mutation score for money and splits
- T32: composition and onboarding (M5)
- T33: rebuild equivalence and qa seed
- TG2: re-evaluate skipped review items (ADRs 0010-0013)
- TG3: i18n foundation (en, pl)
- TG4: email port, adapters and public origin
- TG5: credentials: verify, reset, change, rehash
- T34: web app skeleton, headers, errors, health