BradGroux
0b14f27488
chore(release): bump version to 3.3.3
...
Patch correction release delivering:
- fix(stability): Complete Zod 4 API migration (#162 )
- fix(security): SSRF protection for webhook URLs (#165 )
- perf(websocket): Batch broadcasts to prevent event loop blocking (#167 )
- feat: Orchestrator Delegation Enforcement gate
- feat: Enforcement Gate Toast Notifications
- feat: Dashboard Enforcement Indicator
2026-03-01 14:00:13 -06:00
BradGroux
bd46ffb31a
chore(release): v3.3.2
...
- Bump all package versions to 3.3.2
- Update CHANGELOG with #155 (task↔agent sync), #156 (circuit breaker tests), #159 (sync auth hardening), #161 (sprint CLI+MCP)
- Update README version badge to 3.3.2
2026-03-01 13:08:51 -06:00
Brad Groux
ea9217c9fd
feat(cli+mcp): add sprint management commands and task --sprint flags ( #161 )
...
Add CLI sprint subcommands (list, create, update, delete, close, suggestions)
and MCP sprint tools for AI agent integration.
- New: cli/src/commands/sprints.ts - full sprint CRUD + archive workflow
- New: mcp/src/tools/sprints.ts - MCP tools for sprint management
- Add -S/--sprint flag to vk list, vk create, vk update
- Add sprint field to MCP list_tasks, create_task, update_task tools
- Wire sprint commands into CLI and MCP entry points
Based on sprint features from #80 by @mariozig, scoped to CLI/MCP surfaces only.
Co-authored-by: BradGroux <super.seth.vos@gmail.com>
2026-03-01 13:07:14 -06:00
Brad Groux
0d7dfb135c
chore: release v3.3.1
2026-02-28 09:57:48 -06:00
dependabot[bot]
12478768cc
chore: bump the production-dependencies group across 1 directory with 8 updates ( #154 )
...
Bumps the production-dependencies group with 8 updates in the / directory:
| Package | From | To |
| --- | --- | --- |
| [@types/node](https://github.com/DefinitelyTyped/DefinitelyTyped/tree/HEAD/types/node ) | `25.3.0` | `25.3.2` |
| [@typescript-eslint/eslint-plugin](https://github.com/typescript-eslint/typescript-eslint/tree/HEAD/packages/eslint-plugin ) | `8.56.0` | `8.56.1` |
| [@typescript-eslint/parser](https://github.com/typescript-eslint/typescript-eslint/tree/HEAD/packages/parser ) | `8.56.0` | `8.56.1` |
| [lint-staged](https://github.com/lint-staged/lint-staged ) | `16.2.7` | `16.3.0` |
| [multer](https://github.com/expressjs/multer ) | `2.0.2` | `2.1.0` |
| [simple-git](https://github.com/steveukx/git-js/tree/HEAD/simple-git ) | `3.32.1` | `3.32.3` |
| [autoprefixer](https://github.com/postcss/autoprefixer ) | `10.4.24` | `10.4.27` |
| [@modelcontextprotocol/sdk](https://github.com/modelcontextprotocol/typescript-sdk ) | `1.26.0` | `1.27.1` |
Updates `@types/node` from 25.3.0 to 25.3.2
- [Release notes](https://github.com/DefinitelyTyped/DefinitelyTyped/releases )
- [Commits](https://github.com/DefinitelyTyped/DefinitelyTyped/commits/HEAD/types/node )
Updates `@typescript-eslint/eslint-plugin` from 8.56.0 to 8.56.1
- [Release notes](https://github.com/typescript-eslint/typescript-eslint/releases )
- [Changelog](https://github.com/typescript-eslint/typescript-eslint/blob/main/packages/eslint-plugin/CHANGELOG.md )
- [Commits](https://github.com/typescript-eslint/typescript-eslint/commits/v8.56.1/packages/eslint-plugin )
Updates `@typescript-eslint/parser` from 8.56.0 to 8.56.1
- [Release notes](https://github.com/typescript-eslint/typescript-eslint/releases )
- [Changelog](https://github.com/typescript-eslint/typescript-eslint/blob/main/packages/parser/CHANGELOG.md )
- [Commits](https://github.com/typescript-eslint/typescript-eslint/commits/v8.56.1/packages/parser )
Updates `lint-staged` from 16.2.7 to 16.3.0
- [Release notes](https://github.com/lint-staged/lint-staged/releases )
- [Changelog](https://github.com/lint-staged/lint-staged/blob/main/CHANGELOG.md )
- [Commits](https://github.com/lint-staged/lint-staged/compare/v16.2.7...v16.3.0 )
Updates `multer` from 2.0.2 to 2.1.0
- [Release notes](https://github.com/expressjs/multer/releases )
- [Changelog](https://github.com/expressjs/multer/blob/main/CHANGELOG.md )
- [Commits](https://github.com/expressjs/multer/compare/v2.0.2...v2.1.0 )
Updates `simple-git` from 3.32.1 to 3.32.3
- [Release notes](https://github.com/steveukx/git-js/releases )
- [Changelog](https://github.com/steveukx/git-js/blob/main/simple-git/CHANGELOG.md )
- [Commits](https://github.com/steveukx/git-js/commits/simple-git@3.32.3/simple-git )
Updates `autoprefixer` from 10.4.24 to 10.4.27
- [Release notes](https://github.com/postcss/autoprefixer/releases )
- [Changelog](https://github.com/postcss/autoprefixer/blob/main/CHANGELOG.md )
- [Commits](https://github.com/postcss/autoprefixer/compare/10.4.24...10.4.27 )
Updates `@modelcontextprotocol/sdk` from 1.26.0 to 1.27.1
- [Release notes](https://github.com/modelcontextprotocol/typescript-sdk/releases )
- [Commits](https://github.com/modelcontextprotocol/typescript-sdk/compare/v1.26.0...v1.27.1 )
---
updated-dependencies:
- dependency-name: "@types/node"
dependency-version: 25.3.2
dependency-type: direct:development
update-type: version-update:semver-patch
dependency-group: production-dependencies
- dependency-name: "@typescript-eslint/eslint-plugin"
dependency-version: 8.56.1
dependency-type: direct:development
update-type: version-update:semver-patch
dependency-group: production-dependencies
- dependency-name: "@typescript-eslint/parser"
dependency-version: 8.56.1
dependency-type: direct:development
update-type: version-update:semver-patch
dependency-group: production-dependencies
- dependency-name: lint-staged
dependency-version: 16.3.0
dependency-type: direct:development
update-type: version-update:semver-minor
dependency-group: production-dependencies
- dependency-name: multer
dependency-version: 2.1.0
dependency-type: direct:production
update-type: version-update:semver-minor
dependency-group: production-dependencies
- dependency-name: simple-git
dependency-version: 3.32.3
dependency-type: direct:production
update-type: version-update:semver-patch
dependency-group: production-dependencies
- dependency-name: autoprefixer
dependency-version: 10.4.27
dependency-type: direct:development
update-type: version-update:semver-patch
dependency-group: production-dependencies
- dependency-name: "@modelcontextprotocol/sdk"
dependency-version: 1.27.1
dependency-type: direct:production
update-type: version-update:semver-minor
dependency-group: production-dependencies
...
Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2026-02-28 09:50:16 -06:00
dependabot[bot]
ce91073654
chore: bump @types/node to 25.3.0 (dependabot #142 )
...
Bumps [@types/node](https://github.com/DefinitelyTyped/DefinitelyTyped/tree/HEAD/types/node ) from 22.19.7 to 25.3.0.
- [Release notes](https://github.com/DefinitelyTyped/DefinitelyTyped/releases )
- [Commits](https://github.com/DefinitelyTyped/DefinitelyTyped/commits/HEAD/types/node )
---
updated-dependencies:
- dependency-name: "@types/node"
dependency-version: 25.3.0
dependency-type: direct:development
update-type: version-update:semver-major
...
Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2026-02-20 02:07:04 -06:00
dependabot[bot]
f18f6c285f
chore: bump commander to 14.0.3 (dependabot #136 )
...
Bumps [commander](https://github.com/tj/commander.js ) from 12.1.0 to 14.0.3.
- [Release notes](https://github.com/tj/commander.js/releases )
- [Changelog](https://github.com/tj/commander.js/blob/master/CHANGELOG.md )
- [Commits](https://github.com/tj/commander.js/compare/v12.1.0...v14.0.3 )
---
updated-dependencies:
- dependency-name: commander
dependency-version: 14.0.3
dependency-type: direct:production
update-type: version-update:semver-major
...
Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2026-02-20 01:59:08 -06:00
Brad Groux
97181e678d
feat: v3.3.0 — Task Dependencies, Crash Recovery, Observational Memory, Agent Filter
...
## New Features (4x10 cross-model verified)
### #122 — Task Dependencies Graph
- Bidirectional dependency model (depends_on/blocks)
- DFS cycle detection traversing both directions
- Recursive dependency graph API
- Batch-loaded traversal (eliminated N+1 queries)
- Zod validation on dependency routes
- Full keyboard + ARIA accessibility
### #123 — Crash-Recovery Checkpointing
- Save/resume/clear API for sub-agent state persistence
- Secret sanitization (20+ key patterns + regex value detection)
- 1MB size limit, 24h expiry, resume counter
- Array sanitization (nested objects + primitive strings)
- NaN timestamp handling
- ARIA-accessible checkpoint UI
### #124 — Observational Memory
- CRUD observations per task (decision/blocker/insight/context)
- Importance scoring (1-10) with paginated full-text search
- XSS prevention via sanitizeCommentText()
- ARIA-accessible range slider + decorative icon handling
### #125 — Agent Filter
- GET /api/tasks?agent=name query parameter
- Input sanitized (trim + 100 char cap)
- JSDoc/OpenAPI documented
All features scored 10/10 across security, reliability, performance,
and accessibility. Cross-model verified (Sonnet authored, Codex reviewed).
2026-02-14 23:48:49 -06:00
Brad Groux
c53fca9a75
chore: bump version to v3.2.1
2026-02-12 05:41:49 -06:00
Brad Groux
5163e8debe
chore: bump version to v3.2.0 + update CHANGELOG
2026-02-11 10:31:41 -06:00
Brad Groux
711ad608b5
chore: bump version to v3.1.0
2026-02-10 08:12:45 -06:00
Brad Groux
f50c8a594c
fix(ci): add shared build step + fix all type errors across server/cli
...
- Add 'Build shared' step to Lint & Type Check job in CI workflow
- Add explicit type annotations to ~50 parameters across server + CLI
- Fix docker-paths test to properly mock filesystem operations
- Verified: clean install → shared build → lint/typecheck/test/build all passing
2026-02-08 14:29:55 -06:00
Brad Groux
5c17972bfb
fix(ci): mock docker paths fs calls + add CLI type annotations
...
- Mock fs.mkdir in docker-paths test (EACCES on Linux runners)
- Mock fs.existsSync with smart logic for pnpm-workspace.yaml detection
- Add explicit type annotations to all CLI commands (27 implicit any types)
- Verified: pnpm lint, typecheck, test (1252 tests), build all passing
2026-02-08 14:04:33 -06:00
Brad Groux
8e8e928380
feat: add CLI usage reporting commands ( closes #50 )
2026-02-05 17:53:52 -06:00
Brad Groux
931d437b67
chore: Release v1.6.0
...
## Highlights
- Activity Page Redesign — Full-width status history, clickable navigation, color-coded badges
- Task Templates UI (#39 ) — Full management interface for templates
- Analytics API (#43 ) — Timeline and aggregate metrics endpoints
- Status Transition Hooks — Quality gates for task status changes
- 7 GitHub Issues Closed (#47 , #48 , #49 , #51 , #53 , #56 , #82 )
## Changes
- Bump all packages to 1.6.0
- Update CHANGELOG.md with comprehensive release notes
- Update README.md version badge and roadmap
- Update FEATURES.md with new sections:
- Task Templates (v1.6.0)
- Analytics API (v1.6.0)
- Dashboard Filter Bar (v1.6.0)
- Redesigned Activity Feed section
- Activity page: purple for sub-agent, amber for in-progress, blue for done
- Status badges: uniform width, color-coded by status type
2026-02-04 22:11:13 -06:00
Brad Groux
89d6efbe6e
feat(cli): US-1611 vk setup — guided onboarding wizard
...
New CLI command that validates environment and helps new users get started:
- Checks Node version (requires >=18)
- Verifies server is running and accessible
- Tests API authentication
- Optionally creates a welcome task with next steps
- Supports --json output for automation
- Supports --skip-task to skip sample task creation
Updated docs/GETTING-STARTED.md to reference the new command.
Credit: BoardKit Orchestrator (Monika Voutov) for the wizard pattern inspiration.
Closes #71
2026-02-04 09:14:01 -06:00
Brad Groux
a87c28decf
docs: align versioning to v1.4.1 (packages, README, changelog)
2026-02-03 01:51:21 -06:00
Brad Groux
6356a5e15e
feat: backlog board, dashboard overhaul, UI/UX refinements ( #65 , #66 )
...
Backlog Board (#65 ):
- BacklogRepository, BacklogService, API routes (/api/backlog/*)
- BacklogPage with inline expand/collapse, promote/demote actions
- CLI commands: vk backlog list|promote|demote|delete
- Activity events for demote/promote operations
- 47 tasks moved to backlog (sales, DM-Web, HubSpot, Customer.io)
Dashboard Overhaul:
- Recovered DashboardFilterBar from crashed branch (preset pills, custom date range, project filter)
- New metrics: Cost per Task, Agent Utilization (status-history-based)
- Fixed success rate calculation (backward-compat for status vs success field)
- Backfilled 23 estimated run.tokens events
- Task Activity per Day replaces Runs per Day chart
- Removed Sprint Velocity, Blocked Breakdown, period dropdowns
- Fixed ErrorsDrillDown empty state
Board & Sidebar:
- 5th column sidebar: Agent Status Panel (always visible), Recent Status Changes, Budget
- Clickable task names/IDs in agent status
- Removed planning column entirely (status, type, schemas, UI, CLI, MCP)
- Archive button in task detail panel (next to Delete)
- Select button moved to FilterBar row
Activity Page (#66 ):
- Removed tabs, side-by-side layout: Activity Feed (2/3) + Status History (1/3)
- Daily summary spans top
UI/UX:
- Command palette (Cmd+K)
- Theme toggle (Moon/Sun) in header
- Main padding increased, removed chat icon
- Cleaned up dead code (VelocityChart, MetricCard, unused imports)
- Fixed conditional hooks in CommandPalette
2026-02-02 04:56:47 -06:00
Brad Groux
8302375051
feat: Add backlog board feature (Issue #65 )
...
- Add BacklogRepository for file-based storage in tasks/backlog/
- Add BacklogService with promote/demote logic
- Add backlog API routes (list, create, update, delete, promote, demote)
- Add BacklogPage component with search, filtering, and bulk actions
- Add backlog navigation with task count badge in header
- Add 'Move to Backlog' action to bulk actions bar
- Add CLI commands: backlog list/add/promote/demote/delete/count
- Add activity types for task_promoted and task_demoted events
- Backlog tasks are stored separately and not loaded by main task service
- Tasks can be promoted from backlog to active board (status -> todo)
- Tasks can be demoted from active board to backlog
2026-02-02 02:20:14 -06:00
Brad Groux
dc6bd85405
fix: replace all remaining 'Review' references with 'Blocked'
...
- BulkActionsBar: dropdown option 'Review' → 'Blocked'
- NotificationsTab: 'Review Needed' → 'Blocked' label/description
- constants.ts: remove obsolete 'review' status label
- summary CLI: 'Review' → 'Blocked' in standup output
- notification-service: fix misleading comment
- summary-service: fix misleading comment
Closes task_20260201_wOFjfL
2026-02-01 15:18:34 -06:00
Brad Groux
583d74b38d
feat(v1.4): planning status + verification checklists ( #40 #38 )
2026-02-01 02:45:57 -06:00
Brad Groux
cf413bbd64
feat(cli): add workflow commands - vk begin/done/block/unblock, time tracking, comments, agent status, projects ( #44 )
2026-02-01 02:05:40 -06:00
Brad Groux
9369ca8bcf
docs: update all documentation for v1.2.0 + v1.3.0
...
- Bump all package versions to 1.3.0
- README: version badge, blocked column, new feature highlights
- CHANGELOG: full v1.2.0 and v1.3.0 entries
- FEATURES.md: GitHub sync, activity feed, standup summary sections
- FEATURES.md: storage architecture, API envelope docs, new CLI commands
- FEATURES.md: updated API endpoints table and response format docs
2026-01-31 23:33:37 -06:00
Brad Groux
879b095096
v1.3.0: Visibility & Automation ( #21 , #33 , #34 )
...
- Bidirectional GitHub Issues sync (#21 )
- GitHubSyncService with polling, label-based field mapping, circuit breaker
- Inbound: import issues with 'kanban' label as tasks
- Outbound: push status changes and comments back to GitHub
- Config/state persistence, 5 new API endpoints
- CLI: vk github sync/status/config/mappings
- TaskGitHub interface added to shared types
- Activity feed view (#33 )
- Full-page chronological feed with day grouping
- Filter bar: agent, type, date range (combinable)
- Compact vs detailed view toggle
- Infinite scroll via IntersectionObserver
- Real-time WebSocket updates with animation
- Agent field added to Activity, MAX_ACTIVITIES 1000→5000
- New ViewContext for board/activity navigation
- Daily standup summary generation (#34 )
- GET /api/summary/standup with date, format params
- JSON, markdown, and plain text output formats
- Sections: completed, in-progress, blocked, upcoming, stats
- CLI: vk summary standup with --yesterday, --date, --json flags
- 12 new tests for standup logic
Closes #21 , closes #33 , closes #34
2026-01-31 23:15:08 -06:00
Brad Groux
a7877e57b5
v1.2.0: Foundation Hardening ( #2 , #6 , #32 )
...
- Standardize API response envelope and error format (#2 )
- Add UnauthorizedError, ForbiddenError, BadRequestError, InternalError classes
- Add pagination support with sendPaginated() helper
- Standardize all 11 route files to use error classes (zero ad-hoc patterns)
- Standardize auth middleware error responses
- Abstract file storage behind repository interface (#6 )
- Extend storage interfaces: Activity, Template, StatusHistory, ManagedList, Telemetry
- Implement file-based adapters in FileStorageProvider
- Add fs-helpers.ts as centralized filesystem access layer
- Remove direct fs imports from all 10 service/route files
- Complete blocked task status implementation (#32 )
- Fix MCP tools Zod/JSON schema definitions
- Fix MCP active tasks filter
- Fix CLI help text and status color formatting
Closes #2 , closes #6 , closes #32
2026-01-31 23:03:10 -06:00
Brad Groux
0c0f5b344d
security+quality: final codebase review fixes
...
Security (critical):
- Remove shell:true from preview-service spawn (command injection fix)
- Replace exec() with execFile() in github-service (no shell interpolation)
- Add SIGKILL fallback after SIGTERM timeout in worktree-service
Stability:
- Add process cleanup handlers (SIGTERM/SIGINT) for preview servers
- Add MAX_PREVIEW_SERVERS=5 limit to prevent resource exhaustion
- Memoize WebSocket context value to prevent unnecessary re-renders
Code quality:
- Remove hardcoded 'Brad' author → 'User' (3 files)
- Replace hardcoded localhost:3001 URLs with API_BASE (AttachmentsSection)
- Fix SECURITY-AUDIT.md date (2025 → 2026)
- Add license/repository/author to all 6 package.json files
Data hygiene:
- Untrack all runtime data files (.veritas-kanban/*.json, telemetry, activity)
- Simplify .gitignore: .veritas-kanban/* except .gitkeep
- Removed ~15,700 lines of runtime data from git history
2026-01-29 06:13:10 -06:00
Brad Groux
3edffec98c
chore: bump version to 1.0.0, add CHANGELOG
...
- Bump all 6 package.json files from 0.1.0 to 1.0.0
- Add CHANGELOG.md with full feature summary
- Git history scrubbed of security.json (JWT secret)
2026-01-29 01:42:04 -06:00
Brad Groux
39eccf3556
feat: Sprint US-1200 Refactoring batch — 13 tasks complete
...
Completed refactors:
- RF-02: Fix dependency vulnerabilities (xlsx → exceljs, Hono updates)
- RF-05: Add React error boundaries (FeatureErrorBoundary wrapper)
- RF-06: Server error handling middleware (AppError classes, asyncHandler)
- RF-10: Split shared types.ts into domain modules (6 files)
- RF-11: Consolidate frontend API layer (hooks now use api.ts)
- RF-13: TaskConfigContext — eliminate prop drilling
- RF-14: Split god components (GitSection, TaskDetailPanel, CreateTaskDialog, DiffViewer)
- RF-16: Frontend accessibility (ARIA labels, sr-only text)
- RF-17: Modularize CLI (899 → commands/ structure)
- RF-18: Modularize MCP (843 → tools/ structure)
- RF-19: Create shared API client library
- RF-21: Server performance (batch loading, memory limits, timeouts, graceful shutdown)
- RF-23: Extract shared utilities (path, format, constants)
Stats: ~59 files changed, significant code reduction through modularization
2026-01-28 06:08:59 -06:00
Brad Groux
575035d69b
refactor: Replace direct spawn with Clawdbot sessions API integration
...
- Created ClawdbotAgentService that delegates to Veritas main session
- Agent requests written to .veritas-kanban/agent-requests/ as JSON
- Added /api/agents/pending endpoint for Veritas to poll
- Added /api/agents/:taskId/complete callback endpoint
- CLI commands: agents:pending, agents:complete, agents:status
- Removed PTY process management - Clawdbot handles it
Flow:
1. Kanban UI → POST /api/agents/:taskId/start
2. Server writes request to agent-requests/{taskId}.json
3. Veritas polls agents:pending or checks manually
4. Veritas calls sessions_spawn with task prompt
5. Sub-agent works in worktree, commits changes
6. Veritas calls /api/agents/:taskId/complete
7. Task updated, notifications sent
2026-01-26 11:20:28 -06:00
Brad Groux
809bf4d94e
feat(US-505): Teams notification integration
...
- New /api/notifications endpoints (create, list, pending, mark-sent, check, clear)
- Notification types: agent_complete, agent_failed, needs_review, task_done, high_priority, error, milestone, info
- CLI commands: notify, notify:check, notify:pending, notify:list, notify:clear
- MCP tools: create_notification, get_pending_notifications, check_notifications
- Notifications stored in .veritas-kanban/notifications.json
- Teams-formatted output with icons and task links
2026-01-26 04:34:41 -06:00
Brad Groux
7d7e92e2ce
feat(US-504): Memory system sync
...
- New /api/summary endpoint (status counts, projects, high-priority)
- New /api/summary/recent endpoint (recently completed tasks)
- New /api/summary/memory endpoint (markdown formatted for memory files)
- CLI: vk summary - show kanban overview
- CLI: vk memory - get memory-formatted summary
- CLI: vk memory -o <file> - append to memory file
- MCP: get_summary, get_memory_summary tools
2026-01-26 04:29:03 -06:00
Brad Groux
6112517ee7
feat(US-503): Veritas sub-agent integration
...
- Added 'veritas' agent type for automation tasks
- New automation field on tasks (sessionKey, spawnedAt, completedAt, result)
- New API endpoints:
- POST /api/automation/:id/start - start automation task
- POST /api/automation/:id/complete - complete automation task
- GET /api/automation/pending - list pending automation tasks
- GET /api/automation/running - list running automation tasks
- CLI commands: automation:pending, automation:start, automation:complete, automation:running
- MCP tools: list_pending_automation, list_running_automation, start_automation, complete_automation
2026-01-26 04:26:28 -06:00
Brad Groux
bec40a05de
feat(US-501): CLI for task management
...
- vk list: list tasks with filters (status, type, project)
- vk show: display task details
- vk create: create new tasks
- vk update: modify task fields
- vk start: start agent on task
- vk stop: stop running agent
- vk archive: archive completed task
- vk delete: delete task
- JSON output option for all commands
- Partial ID matching support
2026-01-26 04:17:52 -06:00