In progress
Unreleased
Changed
- Bounded the local Turbo task cache at 512 MiB through the serialized root task runner and Devenv cache tools, and stopped persisting revision-specific Turbo build archives in GitHub Actions, preventing local growth and cumulative CI cache generations while retaining recent local cache hits.
- Organization Owners can now select and permanently delete any owned Organization without Workspace access after a complete preview, exact-name confirmation, and recent authentication; unconfirmed Paddle subscriptions, outstanding checkouts, pending ownership transfer, provider-scheduled work, other provider work, and cleanup remain explicit blockers, canceled checkouts cannot resume and retain an opaque boundary that terminates late Paddle subscriptions, failure is atomic, affected access, credentials, current and evidenced historical invitation email Jobs, ownership-expiry or notification Jobs end on success, and only content-free lifecycle and required billing evidence remains.
- Updated `golang.org/x/image` to 0.45.0 to fix excessive memory allocation while validating VP8L images.
- Added temporary account-wide and Workspace notification Mutes on both Notifications and Settings, with visible absolute end times and an idempotent end-now action. Mutes pause optional Immediate and Daily email without changing saved preferences, conservatively suppress pre-upgrade queued optional mail whose Workspace scope is unknown, resolve the Workspace scope first when scopes overlap, expire automatically, keep in-app notifications immediate, and never suppress Transactional security, access, invitation, or critical billing email. Workspace-bound credentials receive only their Workspace Mutes when they reconcile state. Database upgrades apply migration 100 automatically.
- Organization Owners can now select an Organization without Workspace access, see its current Owner, and nominate an active member after recent authentication and exact confirmation; a nominee can resolve the standalone action without Workspace access. Every ownership read and action enforces the Organization identity and SSO assurance decision without requiring Workspace access, and the transport-independent initiation service requires an unscoped browser credential and consumes one recent-authentication grant. The durable, expiring Transactional action uses semantic English and Portuguese notification content, clears and suppresses actions whenever transfer state cannot be loaded or its URL changes, preserves the current Owner through decline, expiry, or revocation, records every reached initiation failure in domain-owned audit evidence, exposes ownership transfers in the Organization audit filter, and atomically moves creator and subscription authority plus the Owner role to the accepting nominee while demoting the prior Owner to Administrator. Database upgrades apply migration 097 automatically; no operator action is required.
41 more entries in the full changelog.
Fixed
- Kept the generated public Nix module example on `ghcr.io/getopenpost/openpost:latest` even when the linked deployment source pins a verified release digest.
- Restored marketing and documentation page views by requiring their production PostHog build settings, routed hosted browser telemetry through the managed first-party proxy, added matching page-leave events and privacy-limited Core Web Vitals, and kept route templates in SDK-owned URL properties.
- "Create another" after first Activation now opens a clean composer instead of retaining the published text and draft identity.
- Made direct documentation builds restore their ignored OpenAPI inputs from the tracked canonical spec before VitePress starts, so clean deployment checkouts cannot depend on generated local files.