Brad Groux
446def7e8d
Add configurable board columns
...
Adds configurable board columns and dynamic task statuses across the board, server validation, summaries, CLI, MCP, and docs.
Closes #640 .
2026-06-05 11:44:10 -05:00
Brad Groux
d796c3df27
Add session template recommendations ( #638 )
2026-06-05 10:53:40 -05:00
Brad Groux
c3716c1a85
Add agent host routing health ( #636 )
2026-06-05 10:06:17 -05:00
Brad Groux
0b33699684
Add editable time breakdown exports ( #635 )
2026-06-05 09:43:04 -05:00
Brad Groux
f6f0bd31ca
Add source-backed evidence timeline ( #634 )
2026-06-05 09:24:54 -05:00
Brad Groux
ad151ab5cc
Apply desktop remote destination policy ( #629 )
CI / Lint & Type Check (push) Waiting to run
CI / Workspace Unit Tests (push) Waiting to run
CI / Build (push) Waiting to run
CI / Security Audit (push) Waiting to run
2026-06-05 02:45:56 -05:00
Brad Groux
00ba51f252
Restrict work product source link schemes ( #628 )
2026-06-05 00:14:46 -07:00
Brad Groux
b93adbcb9f
Redact settings webhook URLs ( #623 )
...
* Redact settings webhook URLs
* Use full settings fixtures in route coverage
2026-06-04 22:35:50 -07:00
Brad Groux
0a0e751a38
Enforce local agent control capability ( #619 )
2026-06-04 21:28:58 -07:00
Brad Groux
973be6bcf3
Require execute permission for Codex review ( #618 )
2026-06-04 21:15:56 -07:00
Brad Groux
854b6429ed
Add agent health classifier ( #592 )
2026-06-04 17:27:54 -07:00
Brad Groux
438301dd1e
Add watcher continuation policy gates ( #591 )
CI / Lint & Type Check (push) Waiting to run
CI / Workspace Unit Tests (push) Waiting to run
CI / Build (push) Waiting to run
CI / Security Audit (push) Waiting to run
2026-06-04 16:01:16 -07:00
Brad Groux
2cd7fe2ad2
Add prompt template import command
2026-06-04 01:01:14 -07:00
Brad Groux
68fb90a939
Add saved board views
2026-06-03 23:50:37 -07:00
Brad Groux
ea352fcac9
Add orchestrator pipelines and product modes
...
Add first-class orchestrator pipeline metadata, OpenClaw audit recipe support, persisted product modes, and the related UI, docs, and regression coverage.
2026-06-03 07:34:51 -07:00
Brad Groux
7fac1b8977
Add skill risk gates
2026-06-03 07:02:44 -07:00
Brad Groux
a9217784b3
Add skill security scanner ( #538 )
2026-06-03 06:33:05 -07:00
Brad Groux
4274171a8a
Add skill capability profiles
2026-06-03 06:09:29 -07:00
Brad Groux
abfac7c446
Add governance decision traces
2026-06-03 05:45:59 -07:00
Brad Groux
62f258052c
Add v5 maintenance center ( #535 )
2026-06-03 05:02:57 -07:00
Brad Groux
fd96f73408
Harden v5 security review surfaces ( #531 )
2026-06-03 03:55:22 -07:00
Brad Groux
58f39ea2b5
Implement secure device pairing sessions
...
Add signed pairing-code exchange, hashed device session secrets, identity device session management, desktop pairing onboarding, docs, and regression coverage.
2026-06-03 02:02:22 -07:00
Brad Groux
17799f3f72
Add workflow recipe authoring and dry-run linting
...
Adds workflow recipe authoring, visual/YAML dry-run linting, and output/schedule metadata for v5 workflows.
2026-06-03 01:12:57 -07:00
Brad Groux
de5183ed0e
Capture agent stream and retry trace events ( #523 )
CI / Lint & Type Check (push) Waiting to run
CI / Workspace Unit Tests (push) Waiting to run
CI / Build (push) Waiting to run
CI / Security Audit (push) Waiting to run
2026-06-03 00:12:15 -07:00
Brad Groux
7b64a5388b
Add work product maintenance preview ( #522 )
2026-06-02 23:59:05 -07:00
Brad Groux
8d854a1786
Add task readiness start gate ( #517 )
2026-06-02 22:54:42 -07:00
Brad Groux
f4146b9b1f
Add agent timeline links and entry points
...
Enrich agent run timeline navigation and linked evidence from dashboard, workflow, notification, approval, and work-product surfaces.
2026-06-02 22:22:26 -07:00
Brad Groux
af7e68c541
Add agent run timeline replay view
2026-06-02 14:22:27 -07:00
Brad Groux
28aee90b82
feat: add actor attribution and optimistic concurrency
...
## Summary
- adds task/comment/workflow revision metadata, ETag headers, and stale-write 409 conflict responses
- records actors on task, comment, activity, audit, and workflow API mutations
- sends cached revisions from web task/comment mutations and reloads the current task on conflicts
- documents the conflict contract and adds route/API regression coverage
## Verification
- `VERITAS_DISABLE_WATCHERS=1 node_modules/.bin/vitest run server/src/__tests__/routes/tasks-coverage.test.ts server/src/__tests__/routes/optimistic-concurrency.test.ts`
- `node_modules/.bin/prettier --check server/src/__tests__/routes/tasks-coverage.test.ts`
- `pnpm --filter @veritas-kanban/server typecheck`
- `git diff --check`
- PR checks: Build, Lint & Type Check, Security Audit, Workspace Unit Tests
2026-05-31 10:54:53 -05:00
Brad Groux
cb70bc42f9
fix: tighten agent approval RBAC guards
...
CI / Lint & Type Check (push) Waiting to run
CI / Workspace Unit Tests (push) Waiting to run
CI / Build (push) Waiting to run
CI / Security Audit (push) Waiting to run
## Summary
- splits agent register, permission, and routing route guards so read-like POSTs stay available without treating all agent self-service POSTs as read-only safe
- requires task:write for agent approval requests, telemetry:write for agent registration writes, and admin:manage for approval review/routing configuration/permission elevation
- mirrors the route guard changes in the shared CLI/MCP permission preflight map
- expands REST, CLI, and MCP authorization tests for read-only mutation denial and scoped agent approval requests
Closes #336 .
## Verification
- VERITAS_DISABLE_WATCHERS=1 node_modules/.bin/vitest run server/src/__tests__/routes/v1-permission-guards.test.ts cli/src/__tests__/api-permissions.test.ts mcp/src/__tests__/api-permissions.test.ts
- node scripts/check-permission-coverage.mjs
- pnpm --filter @veritas-kanban/shared build
- pnpm --filter @veritas-kanban/server typecheck
- pnpm --filter @veritas-kanban/cli typecheck
- pnpm --filter @veritas-kanban/mcp build
- pnpm build
- pnpm lint:budget
- pnpm audit --prod --audit-level=high
- node_modules/.bin/prettier --check server/src/routes/v1/permissions.ts server/src/routes/v1/index.ts shared/src/utils/api-permissions.ts server/src/__tests__/routes/v1-permission-guards.test.ts cli/src/__tests__/api-permissions.test.ts mcp/src/__tests__/api-permissions.test.ts docs/security.md
- git diff --check
## Notes
- pnpm audit --prod --audit-level=high passes the high-severity gate and still reports 3 moderate existing vulnerabilities.
- pnpm lint:budget passed with 705 warnings under the 714 warning budget.
- pnpm --filter @veritas-kanban/mcp typecheck is not available because the package has no typecheck script; pnpm --filter @veritas-kanban/mcp build covers TypeScript compilation.
2026-05-31 05:53:32 -05:00
Brad Groux
3f5c9a03af
feat: enforce CLI and MCP token permissions
...
## Summary
- adds a shared client-side API permission mapper and guarded API client for CLI and MCP calls
- exposes a non-secret /api/auth/context endpoint for scoped token preflight
- routes CLI and MCP task lookup helpers through the guarded client
- preflights direct summary text fetches that bypass the JSON API helper
- adds focused CLI and MCP token authorization coverage and documents the behavior
Refs #336 .
## Verification
- pnpm --filter @veritas-kanban/shared build
- pnpm --filter @veritas-kanban/cli typecheck
- pnpm --filter @veritas-kanban/mcp build
- pnpm --filter @veritas-kanban/server typecheck
- focused CLI and MCP api-permissions tests
- pnpm lint:budget
- pnpm audit --prod --audit-level=high
- pnpm build
- GitHub Actions: Build, Lint & Type Check, Security Audit, Workspace Unit Tests
2026-05-31 04:35:10 -05:00
Brad Groux
b502872b49
feat: add durable work product foundation
...
Summary:
- adds typed durable work product render contracts
- adds SQLite work_products, work_product_versions, and work_product_search storage
- adds create, list, refine, archive, restore, preview, and export APIs
- wires work products into task-scoped APIs and keyword search
- adds redacted preview/export behavior and SQLite regression coverage
- documents the work product API and SQLite schema
Verification:
- CI: Build
- CI: Lint & Type Check
- CI: Security Audit
- CI: Workspace Unit Tests
- ./node_modules/.bin/prettier --check README.md docs/SQLITE-SCHEMA.md docs/features/work-products.md shared/src/types/work-product.types.ts shared/src/types/index.ts server/src/schemas/work-product-schemas.ts server/src/storage/sqlite/migrations.ts server/src/storage/sqlite/work-product-repository.ts server/src/services/work-product-service.ts server/src/routes/work-products.ts server/src/routes/v1/index.ts server/src/routes/search.ts server/src/services/search-service.ts server/src/__tests__/storage/sqlite-work-products.test.ts
- pnpm --filter @veritas-kanban/server test -- sqlite-work-products
- pnpm typecheck
- pnpm lint:budget
- pnpm --filter @veritas-kanban/server test
- pnpm build
- pnpm audit --prod --audit-level=high
- git diff --check
Part of #403 .
Part of #332 .
2026-05-31 01:31:00 -05:00
Brad Groux
39d9b907d3
feat: add SQLite task artifact metadata
...
## Summary
- adds SQLite migration 0012 for normalized task attachment and task deliverable metadata
- mirrors attachment validation, hash/path, retention, owner/session, and cleanup fields from task JSON into queryable SQLite rows
- adds deliverable provenance fields for model/source run/redaction/version metadata and stores them in SQLite
- updates task artifact schema docs and adds repository coverage for child row sync
Part of #332 .
## Verification
- CI: Build
- CI: Lint & Type Check
- CI: Security Audit
- CI: Workspace Unit Tests
- `pnpm --filter @veritas-kanban/server test -- sqlite-task-repository`
- `pnpm typecheck`
- `pnpm lint:budget`
- `pnpm --filter @veritas-kanban/server test`
- `pnpm build`
- `pnpm audit --prod --audit-level=high`
- `./node_modules/.bin/prettier --check docs/SQLITE-SCHEMA.md server/src/__tests__/storage/sqlite-task-repository.test.ts server/src/routes/task-deliverables.ts server/src/schemas/deliverable-schemas.ts server/src/services/attachment-service.ts server/src/services/clawdbot-agent-service.ts server/src/storage/sqlite/migrations.ts server/src/storage/sqlite/task-repository.ts shared/src/types/task.types.ts shared/src/types/task.types.d.ts`
- `git diff --check`
## Notes
- Attachment binary blobs remain on disk; this slice persists metadata in SQLite for query, migration, backup/import, and cleanup workflows.
2026-05-31 00:47:56 -05:00
Brad Groux
d3976f1d74
chore: harden audit findings and release QA
...
Add release validation and scheduled QA workflows.
Harden webhook URL handling, API helper edge cases, and runtime version reporting.
Split heavy web bundles, centralize view metadata, and stabilize full-suite tests.
2026-05-16 18:59:40 -05:00
Brad Groux
578269963a
Clarify setup paths and integration auth
...
Clarify setup paths, integration auth behavior, and communication docs.
2026-05-13 14:21:30 -05:00
Brad Groux
7bf8df6666
feat: add codex cloud delegation ( #315 )
2026-05-05 21:53:47 -05:00
Brad Groux
42fb759cca
feat: add codex sdk sessions ( #314 )
2026-05-05 21:44:29 -05:00
Brad Groux
bd6c1744e1
feat: add codex cli agent execution
...
Adds built-in Codex agent configuration and local codex exec support through the Veritas agent lifecycle.
2026-05-05 21:20:27 -05:00
Brad Groux
a211b484ba
feat: inject veritas retrieval context
2026-05-04 03:03:36 -05:00
Brad Groux
450ee469ce
feat(shared): export governance, policy, and workflow types ( #252 ) ( #256 )
...
- Add shared/src/types/governance.ts — re-exports decision, drift, feedback, and scoring types from their canonical files
- Add shared/src/types/policy.ts — re-exports policy types from policy.types.ts
- Add shared/src/types/workflow.ts — extracts WorkflowDefinition, WorkflowRun, WorkflowStep, StepRunStatus and related types from server/src/types/workflow.ts into shared
- Update shared/src/types/index.ts to barrel-export workflow types
- Update shared/package.json with subpath exports for governance, policy, and workflow type paths
Closes #252
Co-authored-by: Brad Groux <bradgroux@users.noreply.github.com>
2026-03-23 20:16:11 -05:00
Brad Groux
415a095d31
feat: Prompt Template Registry with Version Control ( #184 ) ( #220 )
...
* feat: prompt template registry with version control (#184 )
- Add PromptTemplate, PromptVersion, PromptUsage, PromptStats types
- Implement prompt-registry service with full CRUD, versioning, and usage tracking
- Add prompt-registry REST endpoints with preview rendering and statistics
- Create React Query hooks (usePromptTemplates, usePromptStats, etc.)
- Implement multi-tab PromptRegistry component with Templates, Versions, Usage, Stats, Preview tabs
- Add INTEGRATION.md documenting manual merge points for existing files
- Supports variable interpolation {{variable_name}} and changelog tracking
- File-based storage pattern consistent with existing template system
* fix: export prompt-registry types from shared barrel
* fix: handle optional changelog in prompt version
* fix: handle optional content field in version creation
* fix: remove unused imports and variables in prompt registry
* fix: remove all unused imports in prompt registry web files
* ci: trigger checks (retry)
---------
Co-authored-by: Brad Groux <bradgroux@users.noreply.github.com>
2026-03-21 11:16:59 -05:00
Brad Groux
d0a2ee4922
feat: Global System Health Status Bar ( #185 ) ( #221 )
...
* feat: global system health status bar (#185 )
* fix: export system-health types from shared barrel
---------
Co-authored-by: Brad Groux <bradgroux@users.noreply.github.com>
2026-03-21 11:12:04 -05:00
Brad Groux
4e6d331a33
feat: User Feedback Loop with Sentiment Analytics ( #182 ) ( #222 )
...
* feat: user feedback loop with sentiment analytics (#182 )
* fix: export feedback types from shared barrel
* fix: TS errors in feedback panel and API client
* fix: tooltip formatter type compatibility
* ci: retry flaky test
---------
Co-authored-by: Brad Groux <bradgroux@users.noreply.github.com>
2026-03-21 10:56:36 -05:00
Brad Groux
45cfc822e4
feat: Behavioral Drift Detection & Alerting ( #181 ) ( #218 )
...
* Implement drift detection and alerting
* fix: correct type predicate in drift service filter
* fix: resolve DriftMonitor formatter type and DriftAlertFilters cast
* fix: add rm export to fs-helpers for drift-service cleanup
* ci: trigger workflow
* chore: trigger ci
* fix: ViewContext union syntax error
* fix: add rm to docker-paths test node:fs/promises mock
---------
Co-authored-by: bradgroux <bradgroux@users.noreply.github.com>
2026-03-21 09:33:34 -05:00
Brad Groux
ac64785326
feat: Decision Audit Trail with Assumption Tracking ( #179 ) ( #216 )
...
* feat: add decision audit trail with assumption tracking
* fix: mock node:fs/promises in tests for fs-helpers compat
* fix: add full fs/promises mock in docker-paths test
* fix: add mkdir to node:fs/promises mock in jwt-rotation test
* ci: trigger workflow
* chore: trigger ci
* fix: ViewContext union syntax, expand fs/promises mock
---------
Co-authored-by: bradgroux <bradgroux@users.noreply.github.com>
2026-03-21 09:28:35 -05:00
Brad Groux
50f76f811a
feat: Agent Output Evaluation & Scoring Framework ( #180 ) ( #217 )
...
* Implement scoring evaluation framework
* fix: resolve TypeScript errors in ScoreExplorer component
---------
Co-authored-by: bradgroux <brad@digitalmeld.io>
Co-authored-by: Brad Groux <bradgroux@users.noreply.github.com>
2026-03-21 09:13:24 -05:00
Brad Groux
1a2476257e
feat: Agent Policy & Guard Engine ( #178 ) ( #215 )
...
* Implement policy guard engine for agent actions
* fix: wrap policy routes with asyncHandler for type safety
* fix: prevent unhandled rejection race in security test cleanup
---------
Co-authored-by: bradgroux <bradgroux@users.noreply.github.com>
2026-03-21 09:03:01 -05:00
Brad Groux
9d453a09f6
feat(squad-chat): add Adaptive Card support to squad messages ( #214 )
...
Add optional 'card' field (Record<string, unknown>) to SquadMessage and
SquadMessageInput types, allowing callers to attach Adaptive Card v1.5
JSON payloads to squad chat messages.
Changes:
- shared: Add card? to SquadMessage and SquadMessageInput interfaces
- routes/chat: Add card to zod validation schema and passthrough
- chat-service: Accept and spread card into squad message object
- squad-webhook: Include card in webhook payload type and forwarding
The card field flows through the full pipeline: API validation → storage
→ API response → WebSocket broadcast → webhook forwarding. Cards are
transient (not serialized to markdown logs) and intended for real-time
delivery to Teams via Adaptive Card attachments.
Co-authored-by: Brad Groux <bradgroux@users.noreply.github.com>
2026-03-20 21:10:59 -05:00
Brad Groux
adbcfc930b
fix: resolve TypeScript build errors ( #177 )
...
- Add RunMode type and QaGateState interface to shared task.types.ts
- Add runMode and qaGate optional fields to Task and UpdateTaskInput interfaces
- Mirror changes in shared/src/types/task.types.d.ts (used by web bundler)
- Add RunModeGateSection.tsx component (was untracked, causing web build failure)
- Add qa-gate.test.ts and dependency-cycle.test.ts (untracked test files)
Co-authored-by: Brad Groux <bradgroux@users.noreply.github.com>
2026-03-19 22:09:46 -05:00
V.K. Watson
9657e731b6
fix: guard updatedTask null check in task routes
...
also clean up observations section build warning
2026-02-20 01:51:45 -06:00