From 6ddebb88c7ae619fa9b78628825e4c305b1e35c0 Mon Sep 17 00:00:00 2001 From: Seongho Bae Date: Sun, 23 Aug 2026 15:57:44 +0900 Subject: [PATCH] docs: compile pending CHANGELOG.d fragments, bump to 2.21.1 9 CHANGELOG.d/ fragments (2.12.7 through 2.21.1) held real, already- drafted release notes for work merged since the last compiled version (2.12.6), but the compile step was never run -- found in the audit logged in #463. The fragments themselves are kept (this repo does not delete them after compiling; older fragments back to 0.71.2 are still present despite being reflected in CHANGELOG.md). Also adds the still-missing #460 entry to Unreleased, and bumps frontend/package.json, pyproject.toml, uv.lock, and lineageweave.__version__ to match -- the version fields matched CHANGELOG.md's stated 2.12.6 only because both had equally stalled, not because the release process was healthy. Two related, larger gaps stay logged in #463 rather than attempted here: CHANGELOG.md has no record at all for dozens of merged feat:/fix: PRs with no CHANGELOG.d fragment (this compile only covers what was already drafted), and one specific shipped feature (the durable post-content ingestion queue, ADR 0098) has neither a CHANGELOG.md entry nor a CHANGELOG.d fragment. --- CHANGELOG.md | 73 ++++++++++++++++++++++++++++++++++++++++ frontend/package.json | 2 +- lineageweave/__init__.py | 2 +- pyproject.toml | 2 +- uv.lock | 2 +- 5 files changed, 77 insertions(+), 4 deletions(-) diff --git a/CHANGELOG.md b/CHANGELOG.md index c8ed1a099..db19db95d 100644 --- a/CHANGELOG.md +++ b/CHANGELOG.md @@ -11,6 +11,79 @@ All notable changes to this project are documented here. Format follows - `make smoke` and `make seed` now run through the locked project `uv` environment, so local OIDC and synthetic-data workflows resolve the same pinned dependencies as CI. +- The session-expiry auth-error screen now shows a login-card-styled + recovery screen ("Your session has expired." / "Log in again", + preserving the return URL) instead of dumping the raw IdP error string + (e.g. Keycloak's literal "Token is not active") as bare, unstyled text. + +## [2.21.1] - 2026-08-23 + +### Fixed + +- Aligned ADR 0083 with the immutable `contextual-orchestrator` commit used + by the Compose image and added a regression check so the image and ADR + cannot drift apart again. + +## [2.21.0] - 2026-08-23 + +### Fixed + +- Restricted synthetic-seed cleanup to `DEMO-*` corporate entities so a real + PostgreSQL import cannot delete blank-context posts from a production + scope. + +## [2.13.1] - 2026-08-23 + +### Added + +- Extracted ~13 repeated inline hex colors in `App.css` (lineage-link + accents, R&R actor-type badges, relation-verification status badges) into + named design tokens in `styles/tokens.css`, each with a + `prefers-color-scheme: dark` variant. Dark mode previously left every + pastel badge exactly as light as it is in light mode (ADR 0099). + +### Fixed + +- Matched persisted post units to their source text instead of using + ordinal position, so a table or embedded image cannot shift the fallback + indentation of a later unresolved paragraph. +- Retained valid salient image regions for panel-level OCR and search, and + analyzed the parent image when locator coverage is partial so text + outside the returned panels stays searchable. +- Kept consecutive persisted rows in separate buyer-facing tables when the + source post contains more than one HTML table, preserving the authored + table boundary without changing source text or semantic row content. +- Kept leading spaces and ` ` available as diagnostics without + persisting them as authoritative structure; only declared + HTML/CSS/OOXML or list nesting now counts as explicit indentation. + Expected structure/embedding-channel failures stay retryable while + unexpected defects still propagate to the durable ingestion ledger. + +## [2.13.0] - 2026-08-23 + +### Added + +- Buyer GNB: Board, Customer master, Calendar, and Ask Agent. +- Direct related-post controls from lineage and Keyman/R&R evidence. +- Korean, English, Chinese, Japanese, and Vietnamese locale switching. + +### Changed + +- Moved analysis-run and period-report controls into collapsed advanced + review tools instead of the default buyer surface. + +## [2.12.7] - 2026-08-23 + +### Security + +- Required every accepted Semgrep SQL-composition suppression to use the + exact rule identifier and an adjacent written audit reason. +- Verified that schema-fixed eligibility/source-context fragments keep + request values in asyncpg parameters, and that synthetic-cleanup catalog + identifiers are quoted before execution while UUID values remain + parameters. +- Replaced the document-structure protocol no-op body with an explicit + `NotImplementedError` contract. ## [2.12.6] - 2026-08-20 diff --git a/frontend/package.json b/frontend/package.json index e2e996bbe..52d56ac0d 100644 --- a/frontend/package.json +++ b/frontend/package.json @@ -1,7 +1,7 @@ { "name": "frontend", "private": true, - "version": "2.12.6", + "version": "2.21.1", "type": "module", "scripts": { "dev": "vite", diff --git a/lineageweave/__init__.py b/lineageweave/__init__.py index 95330cb50..7a735700d 100644 --- a/lineageweave/__init__.py +++ b/lineageweave/__init__.py @@ -55,4 +55,4 @@ "sentence_excerpts", ] -__version__ = "2.12.6" +__version__ = "2.21.1" diff --git a/pyproject.toml b/pyproject.toml index cb4be2916..e426095dc 100644 --- a/pyproject.toml +++ b/pyproject.toml @@ -1,6 +1,6 @@ [project] name = "lineageweave" -version = "2.12.6" +version = "2.21.1" description = "Reconstructs git-branch-style lineage DAGs from scattered short records using multi-channel score fusion and LLM adjudication." readme = "README.md" license = { text = "MIT" } diff --git a/uv.lock b/uv.lock index 10bcf9ff1..023927e72 100644 --- a/uv.lock +++ b/uv.lock @@ -454,7 +454,7 @@ wheels = [ [[package]] name = "lineageweave" -version = "2.12.6" +version = "2.21.1" source = { editable = "." } dependencies = [ { name = "certifi" },