Skip to content

Changelog#

All notable changes to oxo-flow are documented in this file.

The format follows Keep a Changelog and this project adheres to Semantic Versioning.

Changelog entries are automatically generated by git-cliff from conventional commit messages.

0.15.0 — 2026-08-24#

Bug Fixes#

  • frontend: Persona review — i18n gaps, TS fixes, CSV export, lint (@ShixiangWang)
  • web: Skip per-user AI provider rows with empty keys (@ShixiangWang)
  • ai: Echo DeepSeek reasoning_content back across multi-turn agent loops (@ShixiangWang)
  • frontend: Persona-discovered a11y/touch/UX issues (@ShixiangWang)
  • frontend: Persona-discovered AI/i18n/ApiDocs issues (@ShixiangWang)
  • web: Persona-discovered backend correctness issues (@ShixiangWang)
  • core: Re-tag the quay fallback image with the original spec (@ShixiangWang)
  • cli: Template -o treats a trailing slash as a directory intent (@ShixiangWang)
  • gallery: Container image references must exist and be registry-qualified (@ShixiangWang)
  • gallery: Complete the gallery — aux files for 09/11/14/15, real BWA-MEM2 in 05, template copies aux files (@ShixiangWang)
  • core+cli: Resolve campaign issues #159 #162 #163 (@ShixiangWang)
  • core: Cache-hit envs re-verify on disk; vanished envs invalidate and rebuild (@ShixiangWang)
  • ci: Linux desktop bundles get app-menu entry + icon (deb/rpm/AppImage) (@ShixiangWang)
  • ci: Desktop app icon, launcher entry, ad-hoc codesign (@ShixiangWang)
  • cli: Help-text drift + license --json machine output + 4 doc table rows (9c doc-consistency audit) (@ShixiangWang)
  • web: Dev-mode login role matches account; drop nonexistent serve --json doc row (@ShixiangWang)
  • Persona-testing LOW tail — ENOENT labeling, dry-run E011 annotation, cluster status guard, docs drift (#142) (@ShixiangWang)
  • core: #142 H5/M4/M5 — transform required inheritance, profile max_array_size, per-element array logs (@ShixiangWang)
  • Persona-testing findings #142 — silent-failure traps, audit-path bugs, docs batch (@ShixiangWang)

Documentation#

  • Document API authentication schemes in web-api.md (@ShixiangWang)
  • Sync web reference docs with serving/runtime changes (@ShixiangWang)
  • Use-environments how-it-works reflects content-hash env naming (@ShixiangWang)
  • run: Clarify --background scope — cluster runs inherit it, dry-run and other commands intentionally don't (#158 follow-up) (@ShixiangWang)
  • guide: Document web_role_matrix + web_integration test targets in contributing (@ShixiangWang)
  • lint: Fix two broken relative links to workflow-format.md (@ShixiangWang)

Features#

  • ui: Systematic visual polish, shared Modal/StatCard, a11y (@ShixiangWang)
  • web: Optimize HTTP serving layer (@ShixiangWang)
  • ai: Knowledge coverage — R/Bioconductor analysis tools now in the bioconda table (@ShixiangWang)
  • core: Docker backend retries bare image names against quay.io/biocontainers (@ShixiangWang)
  • eval: Three-layer AI evaluation benchmark — gold CSVs, capture/runner harness, knowledge grounding guard (@ShixiangWang)
  • ai: Knowledge freshness framework — in-repo generators, live sync, monthly auto-refresh (#153) (@ShixiangWang)
  • Background runs + verified concurrent reuse of shared workflows (#158) (@ShixiangWang)
  • core: Residual-placeholder guard — unresolved {sample}/{config.*}/… in a rendered command warns loudly (@ShixiangWang)
  • Usability round — 0-byte output warning, W021 script-edge lint, disk pre-flight (@ShixiangWang)
  • cli: Reference path migration with identical content skips the rebuild (@ShixiangWang)

Maintenance#

Other Changes#

  • Merge pull request #157 from Traitome/feat/web-ui-optimization (@ShixiangWang) (#157)
  • Merge pull request #175 from Traitome/fix/docker-fallback-retag (@ShixiangWang) (#175)
  • Merge pull request #174 from Traitome/feat/kb-r-ecosystem-coverage (@ShixiangWang) (#174)
  • Merge pull request #173 from Traitome/fix/docker-quay-fallback (@ShixiangWang) (#173)
  • Merge pull request #169 from Traitome/fix/template-output-dir-semantics (@ShixiangWang) (#169)
  • Merge pull request #171 from Traitome/feat/ai-eval-benchmark (@ShixiangWang) (#171)
  • Merge pull request #170 from Traitome/fix/gallery-container-image-refs (@ShixiangWang) (#170)
  • Merge pull request #168 from Traitome/fix/gallery-aux-and-placeholder (@ShixiangWang) (#168)
  • Merge pull request #166 from Traitome/fix/153-knowledge-freshness (@ShixiangWang) (#166)
  • Merge pull request #165 from Traitome/chore/schema-sync-drift-gate (@ShixiangWang) (#165)
  • Merge pull request #164 from Traitome/fix/campaign-issues-159-162-163 (@ShixiangWang) (#164)
  • Merge pull request #161 from Traitome/fix/158-background-docs (@ShixiangWang) (#161)
  • Merge pull request #160 from Traitome/fix/158-background-concurrency (@ShixiangWang) (#160)
  • Merge pull request #156 from Traitome/fix/env-cache-vanished-validation (@ShixiangWang) (#156)
  • Merge pull request #155 from Traitome/fix/linux-desktop-icon-entry (@ShixiangWang) (#155)
  • Merge pull request #154 from Traitome/fix/desktop-icon-and-dmg (@ShixiangWang) (#154)
  • Merge pull request #152 from Traitome/fix/cli-doc-consistency (@ShixiangWang) (#152)
  • Merge pull request #151 from Traitome/fix/web-matrix (@ShixiangWang) (#151)
  • Merge pull request #150 from Traitome/fix/residual-placeholder-guard (@ShixiangWang) (#150)
  • Merge pull request #149 from Traitome/fix/web-lane (@ShixiangWang) (#149)
  • Merge pull request #148 from Traitome/feat/ref-path-migration-exemption (@ShixiangWang) (#148)
  • Merge remote-tracking branch 'origin/main' into feat/ref-path-migration-exemption (@ShixiangWang)
  • Merge pull request #147 from Traitome/feat/usability-round-b6 (@ShixiangWang) (#147)
  • Merge pull request #146 from Traitome/fix/142-lowtail (@ShixiangWang) (#146)
  • Merge pull request #145 from Traitome/fix/142-doclinks (@ShixiangWang) (#145)
  • Merge pull request #143 from Traitome/fix/142-hub-items (@ShixiangWang) (#143)
  • Merge pull request #144 from Traitome/fix/142-persona (@ShixiangWang) (#144)

Performance#

  • frontend: Lazy editor panels, parallel run loading, client hardening (@ShixiangWang)
  • web: Fix runtime hot paths and API contract drift (@ShixiangWang)

Styling#

Testing#

  • e2e: Mock AI config in AI-dependent specs (@ShixiangWang)
  • Fix env-name hash test (distinct dirs for same-stem specs) + plain-names expectation with suffix (@ShixiangWang)
  • web: Deployment + 3-role simulation matrix (@ShixiangWang)

0.14.1 — 2026-08-22#

Bug Fixes#

  • info-test: Drop env-coupled git_remote assertion (#136 finding 29) (@ShixiangWang)
  • Audit #136 tier-2 — web cancel integrity, wait-loop races, LOW tail (#136) (@ShixiangWang)
  • cluster: Resolve #136 H-items — array chunking, non-SLURM polling, cap semantics, submit-time checkpoint (@ShixiangWang)
  • V0.13.1→v0.14.0 audit fixes — dispatch regressions, log masking, core safety, CI release integrity (#136) (@ShixiangWang)
  • cli: Keep-going changes scheduling, never the verdict — exit non-zero on required failures (#133) (@ShixiangWang)
  • core: Kill in-flight rule processes on abort — no more orphans (#131) (@ShixiangWang)

Documentation#

  • Cluster fairness — priority honored with aging, in-flight cancel, wait-visibility boundary (#134 follow-up) (@ShixiangWang)
  • Dag-engine — FIFO acquisition makes priority starvation impossible (the guarantee) (@ShixiangWang)

Features#

  • core: Cluster driver honors priority with fair-dispatch aging (#134) (@ShixiangWang)
  • core: FIFO-gated resource acquisition — the 100% no-starvation guarantee (#123) (@ShixiangWang)

Other Changes#

Testing#

  • Update the fourth keep-going exit-0 site (report --failed harness) (@ShixiangWang)
  • Assert the process is dead, not the pid file — #118 legitimately removes it (@ShixiangWang)
  • cli: Serialize logging tests over the process-global run-log slot (@ShixiangWang)
  • Bisect the CI-only abort-test failure — 10s window + verbose run log in panics (@ShixiangWang)
  • Surface the run's stderr in abort-test assertion failures (@ShixiangWang)
  • Widen the abort-test margin — slow must spawn before bad fails on slow CI runners (@ShixiangWang)

0.14.0 — 2026-08-21#

Documentation#

  • Dag-engine — fair dispatch prevents resource starvation (aging + submit cap) (@ShixiangWang)

Features#

  • cli: Fair dispatch — priority aging + -j submit cap; lint W019 empty outputs (@ShixiangWang)
  • core: Resource-pool wait diagnostics — name what a waiting rule needs and who holds it (@ShixiangWang)

Other Changes#

  • Merge pull request #130 from Traitome/fix/123-resource-wait-diagnostics (@ShixiangWang) (#130)

Refactoring#

  • cli: Extract age_ready_list as a pure, unit-tested function (@ShixiangWang)

Styling#

  • cli: Reword age_ready_list doc to satisfy clippy doc_lazy_continuation (@ShixiangWang)

0.13.1 — 2026-08-21#

Bug Fixes#

  • web: Cancel verifies real group death; de-flake web_integration family (#120) (@ShixiangWang)
  • core: Invalidate failed rules' outputs so stale files never skip a re-run (@ShixiangWang)
  • core: Conda env bin first in PATH inside conda run wrappers (@ShixiangWang)
  • core: Conda run --no-capture-output to kill the capture-poll hang (@ShixiangWang)
  • core: [[pairs]] members feed the merged config.samples_list (@ShixiangWang)
  • references: Use the documented checkpoint path + persist legacy adoption (@ShixiangWang)
  • cluster: A fresh dependency no longer stalls the driver (@andrewbudge)
  • core: Singularity setup pulls only when the SIF is absent — pull refuses to overwrite (@ShixiangWang)
  • core: Docker setup pulls only when the image is absent — concurrent rules sharing one image race in the daemon (@ShixiangWang)
  • core: Docker setup pulls only when the image is absent — concurrent rules sharing one image race in the daemon (@ShixiangWang)
  • Close #99 review gaps — cluster masking/B2 parity, AI recovery target, error-path masking (@ShixiangWang)
  • config: Promote sensitive-only inline configs; rule required defaults to true (@ShixiangWang)
  • wildcards: Substitute fan-out values into script and hook fields (@ShixiangWang)
  • references: Guard source content in the reference fingerprint (@ShixiangWang)
  • core: Container cgroup caps at physical RAM — swap counts for scheduling, not cgroups (@ShixiangWang)
  • core: Timeout diagnostic reads the holder pid from the lock file (@ShixiangWang)
  • core: Per-environment create locks with a bounded wait — no more global serialization (@ShixiangWang)
  • core: {effective_memory_mb} stays RAM-only — swap counts for scheduling, not tool sizing (@ShixiangWang)
  • core: Verify existing conda envs before re-running setup on a cold cache (@ShixiangWang)
  • core: Clamp docker/singularity cgroup --memory to the machine total (@ShixiangWang)
  • core: Export the base conda CA bundle during env setup (@ShixiangWang)
  • core: Never infer a rule edge to itself (@ShixiangWang)
  • core: Expand {config.x} placeholders before DAG edge matching (@ShixiangWang)
  • core: Container rules run under image bash when available; deterministic dir-creation errors (@ShixiangWang)
  • cli: Render {source} in reference build commands (@ShixiangWang)
  • core: Serialize conda env setup per environment key (@ShixiangWang)
  • core: Verify conda envs after setup; repair broken ones (@ShixiangWang)
  • core: Shared output strings link EVERY producer in the DAG (@ShixiangWang)
  • core: DAG template graphs include expand_inputs dataflow edges (@ShixiangWang)
  • core: Derive conda env name for setup, not just wrap (@ShixiangWang)
  • core: Clamp over-capacity rule requests instead of fast-failing (@ShixiangWang)
  • core: Resolve nested {config.x} references deterministically (#88) (@ShixiangWang) (#88)
  • ai: Unify AI config path + accurate provider labels (@ShixiangWang)

CI/CD#

  • Enable workflow_dispatch to drive the full release pipeline (@ShixiangWang)
  • frontend: E2e webServer timeout + feature-unification warm-up fix (@ShixiangWang)

Documentation#

  • readme: Bioconda version badge + systematic badge refresh (@ShixiangWang)
  • run: Fix glued heading in the --module section (@ShixiangWang)
  • run: Document automatic job arrays in cluster submission (#74 phase 3) (@ShixiangWang)
  • workflow-format: Teach the aggregation idiom — expand_inputs + {input} (@ShixiangWang)
  • Document sensitive masking and required=false continue-on-error semantics (@ShixiangWang)
  • Document script/hook fan-out substitution and reference content guard (@ShixiangWang)
  • run: Clarify profile names carry no built-in meaning (@ShixiangWang)
  • gallery: 16s run instruction — activate the QIIME2 env, drop the nonexistent --profile conda (@ShixiangWang)
  • gallery: Add the missing 16th workflow to the Learning Path (@ShixiangWang)
  • Purge stale root-doc content (README gallery, roadmap, limitations, releasing, agents, security) (@ShixiangWang)
  • Per-environment creation locks with bounded wait (@ShixiangWang)
  • Resource ceiling counts swap (--max-memory pins to RAM) (@ShixiangWang)
  • Container --memory clamping + env verify-before-setup behaviors (@ShixiangWang)
  • Harden the China mirrors guide with live-campaign findings (@ShixiangWang)
  • DAG edge inference expands {config.x} placeholders (from_rules_with_config) (@ShixiangWang)
  • Sync deadlock/resource semantics with the clamp change (@ShixiangWang)

Features#

  • info: Derive workflow git provenance in info --json (#124) (@ShixiangWang)
  • run-log: Per-run archived log with versioned header + report git sha (@ShixiangWang)
  • provenance: Record workflow git HEAD SHA in checkpoints (#115) (@ShixiangWang)
  • Partial module runs (--module) + git-pinned includes (#112 elasticity) (@ShixiangWang)
  • include: Typed interface contracts for workflow modules (#112 module slice) (@ShixiangWang)
  • cluster: Job arrays for scatter rules (issue #74 phase 3) (@ShixiangWang)
  • core: Singularity spec accepts a local SIF path (site-deployed images) (@ShixiangWang)
  • Workflow-global shell prelude (issue #92) + explicit null-stdin contract (issue #101) (@ShixiangWang)
  • Mask sensitive config values + wire rule-level required=false (#99 B1/B2) (@ShixiangWang)
  • core: Swap-aware resource detection — the ceiling is RAM + swap (@ShixiangWang)
  • core: Cross-process env-create mutex — serialize conda creates across runs (@ShixiangWang)
  • core: {effective_threads}/{effective_memory_mb} placeholders — tools size themselves to the machine (@ShixiangWang)
  • cluster-run: Report snapshot parity + cluster.md cross-ref (PR #93 follow-up) (@ShixiangWang)
  • Run --profile submits to a scheduler when the profile declares [cluster] (issue #74 phase 2) (@andrewbudge)
  • core: [[references]] entries can declare an environment (@ShixiangWang) (#90)
  • cli: Unify sample selection under --samples (@ShixiangWang)
  • cli: Info derives config descriptions from [config] comments (@ShixiangWang) (#86)

Maintenance#

  • deps: Bump h2 0.4→0.4.16, ignore RUSTSEC-2026-0258 for the aws-sdk's h2 0.3 (@ShixiangWang)

Other Changes#

  • Merge pull request #129 from Traitome/fix/120-flaky-web-cancel-tests (@ShixiangWang) (#129)
  • Merge pull request #128 from Traitome/ci/dispatch-release-pipeline (@ShixiangWang) (#128)
  • Merge pull request #126 from Traitome/docs/readme-badges-refresh (@ShixiangWang) (#126)
  • Merge pull request #127 from Traitome/feat/info-git-provenance (@ShixiangWang) (#127)
  • Merge pull request #125 from Traitome/feat/run-log-rotation (@ShixiangWang) (#125)
  • Merge pull request #122 from Traitome/feat/workflow-git-sha-provenance (@ShixiangWang) (#122)
  • Merge pull request #121 from Traitome/fix/118-failed-output-invalidation (@ShixiangWang) (#121)
  • Merge pull request #119 from Traitome/docs/fix-module-section-format (@ShixiangWang) (#119)
  • Merge pull request #117 from Traitome/fix/conda-env-path-precedence (@ShixiangWang) (#117)
  • Merge pull request #116 from Traitome/fix/conda-run-no-capture (@ShixiangWang) (#116)
  • Merge pull request #114 from Traitome/feat/112-module-runs-git-includes (@ShixiangWang) (#114)
  • Merge pull request #113 from Traitome/feat/112-include-contracts (@ShixiangWang) (#113)
  • Merge pull request #111 from Traitome/fix/pairs-samples-list (@ShixiangWang) (#111)
  • Merge pull request #110 from Traitome/feat/74-job-arrays (@ShixiangWang) (#110)
  • Merge pull request #109 from Traitome/fix/97-ref-checkpoint-path-persistence (@ShixiangWang) (#109)
  • Merge pull request #108 from Traitome/feat/local-sif-spec (@ShixiangWang) (#108)
  • Merge pull request #106 from andrewbudge/fix/driver-stall-deps-outside-to-run (@ShixiangWang) (#106)
  • Merge pull request #107 from Traitome/fix-singularity-pull-idempotent (@ShixiangWang) (#107)
  • Merge pull request #105 from Traitome/fix-docker-setup-race (@ShixiangWang) (#105)
  • Merge pull request #104 from Traitome/feat/92-shell-prelude-101-stdin (@ShixiangWang) (#104)
  • Merge pull request #103 from Traitome/fix/99-review-followup (@ShixiangWang) (#103)
  • Merge pull request #102 from Traitome/feat/99-sensitive-masking-required-rules (@ShixiangWang) (#102)
  • Merge pull request #100 from Traitome/fix/97-98-reference-content-scatter-script (@ShixiangWang) (#100)
  • Merge pull request #96 from Traitome/live-test-hardening (@ShixiangWang) (#96)
  • Merge pull request #95 from Traitome/live-test-hardening (@ShixiangWang) (#95)
  • Merge pull request #94 from Traitome/live-test-hardening (@ShixiangWang) (#94)
  • Merge pull request #91 from Traitome/live-test-hardening (@ShixiangWang) (#91)
  • Merge pull request #93 from andrewbudge/feat/run-profile-slurm (@ShixiangWang) (#93)

Styling#

  • core: Struct-init test helpers instead of Default + reassign (@ShixiangWang)
  • core: Collapse collapsible ifs (clippy -D warnings clean after rebase) (@ShixiangWang)

Testing#

  • core: Exercise the production lock-path derivation (@ShixiangWang)
  • core: Env-create lock test uses a temp dir, not the real HOME (@ShixiangWang)
  • Assert on the mamba backend's detected binary (@ShixiangWang)

0.13.0 — 2026-08-15#

Bug Fixes#

  • core: Pixi backend uses --manifest-path (workflow spec names the file) (@ShixiangWang)
  • cli: LSF dependency flag uses double quotes in submit.sh (@ShixiangWang)
  • core: Venv setup uses POSIX . instead of bash source (@ShixiangWang)
  • core: Container backends bind absolute host paths (@ShixiangWang)
  • core: Expand rule log-field wildcards per instance (@ShixiangWang)
  • core: E003 exempts [[values]]-declared parameter wildcards (@ShixiangWang)
  • web: Wire env badge colors to theme tokens and refresh SPA bundle (@ShixiangWang)
  • cli: Profile merge order + info accuracy + plan JSON surface (@ShixiangWang)
  • core: Harden v0.13 features found by release review (@ShixiangWang)
  • ci: Publish rpm and AppImage to releases; docs: complete release asset docs (@ShixiangWang)

CI/CD#

  • Publish stable-named latest CLI tarball in releases (@ShixiangWang)

Documentation#

  • Sync info and {log} docs with release-review behavior (@ShixiangWang)
  • Release-review documentation and CI fixes (@ShixiangWang)
  • [[values]] fan-out, scratch rules, reference templates, profile override, {log}, pairs_list, plan JSON (@ShixiangWang)
  • Editor setup how-to — .oxoflow files as TOML in VS Code and other editors (@ShixiangWang)

Features#

  • core: Reference builder templates + naming standard (@ShixiangWang)
  • core: Rule-level scratch workdir (scratch = true) (@ShixiangWang)
  • core: [[values]] parameter wildcards + reference builder wiring (@ShixiangWang)
  • core: Expanded-path DAG edge inference (@ShixiangWang)
  • cli: Add info command with per-key config derivation (@ShixiangWang)
  • cli: Route profile merge through core merge_profile (@ShixiangWang)
  • core: Inject config.pairs_list + profile override mode (@ShixiangWang)
  • cli: Unknown --flag hard error + dry-run --json plan export (@ShixiangWang)
  • core: {log} placeholder, array-config join, bash executor (@ShixiangWang)
  • ci: Desktop bundles carry a -desktop- infix in their names (@ShixiangWang)

Styling#

  • web: Environment badge colors as semantic theme tokens (@ShixiangWang)

Testing#

  • Gallery_07 asserts topo order semantically, not by tie-break (@ShixiangWang)

0.12.0 — 2026-08-15#

Bug Fixes#

  • web: Normalize base_path in the standalone web binary (@ShixiangWang)
  • web: Inject at the START of , always (@ShixiangWang)
  • web: Pbsnodes attribute lines leaked in as node names (@ShixiangWang)
  • web: Validate usernames at the POST /api/users entry point (@ShixiangWang)
  • report: Dashboard never divides instances by rule count (@ShixiangWang)
  • Upgrade-compatibility and mount-path hardening (review follow-ups) (@ShixiangWang)
  • web: Quota release on every terminal path + daily reset + terminal-state guards (@ShixiangWang)
  • core: Cluster driver settles jobs that leave the live queue (@ShixiangWang)
  • core: Staged remote keys must not escape the staging tree (@ShixiangWang)
  • web: Tenant isolation gaps in audit, AI cache, chat tools, pipeline read (@ShixiangWang)
  • web: Remote SSH command injection via cluster fields (@ShixiangWang)
  • web: Username/path traversal in workspace paths, symlink leak in zip downloads (@ShixiangWang)
  • web: Scheduler probe must honor exit status, not spawn success (@ShixiangWang)
  • scripts: Deploy-smoke hpc scenario authenticates before /api/hpc (@ShixiangWang)
  • web: Complete LSF/SGE status collection in hpc.rs (@ShixiangWang)
  • cli: Comment stale scaffold template placeholders + sync --strict help text (#83) (@ShixiangWang)
  • cli: --acct optional-JobID panic, array-task batch pref, test gaps (#83 P1-13) (@ShixiangWang)
  • cli: Restore --workdir checkpoint precedence, template autoescape + path resolution, json/md gate (#83 P1-1/P0-9) (@ShixiangWang)
  • web: Don't cache the shared-runtime AI provider fallback — a runtime provider swap must take effect immediately (chat_agent_integration caught a stale cached scripted provider) (@ShixiangWang)
  • executor: Honest per-process CPU docs + flake-guard assertion + SeqCst (#83 P1-13) (@ShixiangWang)
  • report: Commit the actual report_metrics split — orphan adapters.rs now compiled (#83 P1-5) (@ShixiangWang)
  • report: Sample-matrix engine-real instance naming, filter-path panic guard, STAR % parsing (#83 P1-5) (@ShixiangWang)
  • Cluster submit expands wildcards, captures real job ids, surfaces walltime (#74 phase 1) (#84) (@andrewbudge) (#84)
  • ci: Make the e2e suite actually pass — rate-limit escape hatch, guest nav, canvas-mode pinning (@ShixiangWang)
  • web: Dashboard runs-envelope adaptation + fmt normalization; docs: README DAG stack (React Flow + d3-dag, not cytoscape) (@ShixiangWang)
  • deploy-smoke: Binary discovery for deployed servers; scoped cleanup (@ShixiangWang)
  • Runs list — clickable rows, detail scrolls into view, paging (issue #79 P2) (@ShixiangWang)
  • Eliminate CSP unsafe-eval violations — vega-interpreter for report charts (issue #79 P2) (@ShixiangWang)
  • storage: Make s3-storage compile — head() NotFound returns None, sync client init, drop dead match arm (#80) (@ShixiangWang)
  • Storage_resolver local-only (cfg branches land with the feature opt-in); snapshot 4-arg call (#78) (@ShixiangWang)
  • gallery: Declare optional classifier config in the 16S QIIME2 template (#79 E005) (@ShixiangWang)
  • /api/health reports the real deployment mode (issue #79 P1-03 family) (@ShixiangWang)
  • Status single-source, UI wiring, AI delivery, editor guards (issue #79 R-02/03/04/06/07/09/10) (@ShixiangWang)
  • Web platform security triad — rate limit, audit trail, admin auth (issue #79 P1-04/05/06) (@ShixiangWang)
  • One run = one process group; honest crash recovery (issue #79 P1-01/P1-02) (@ShixiangWang)
  • web: Retry SQLite pool init on transient disk I/O errors (CI runner flakes) (@ShixiangWang)
  • frontend: Replace Date.now with crypto.randomUUID; silence fast-refresh on showToast export (@ShixiangWang)
  • web: Single ordered chat event channel — no select-in-yield, boxed outcome (@ShixiangWang)
  • ai: Coalesce tool_result blocks per Anthropic's pairing rule — second live finding (@ShixiangWang)
  • ai: Claude backend emits tool_use blocks — found by live round-trip (@ShixiangWang)
  • web: Restore DB-persisted AI config at startup; chat_messages table (@ShixiangWang)
  • web: Revert kind field on legacy handler's local edge type (@ShixiangWang)
  • web: Attribute pipeline ownership to acting user; compute real effective AI config (@ShixiangWang)
  • web: Verify and consume OAuth state server-side (@ShixiangWang)
  • web: Unify audit_logs schema across init paths; insert_run fills all columns (@ShixiangWang)
  • web: Unify run status vocabulary on completed (@ShixiangWang)
  • Embed template gallery from crate-local templates/ so cargo publish works (issue #76 P1-3 follow-up) (@ShixiangWang)

CI/CD#

  • Drop broken step PATH override in e2e job (env context PATH is empty in Actions) (@ShixiangWang)
  • Frontend build + e2e job gates the web UI (@ShixiangWang)

Documentation#

  • Webhook signature schemes, audit admin-only scope, retry/pause terminal guards (@ShixiangWang)
  • Production deployment — systemd unit + nginx reverse proxy (@ShixiangWang)
  • Drop stale v0.10.x version prefixes from feature intros (@ShixiangWang)
  • Fix ACMG Tier III 'Uncertain significance' wording (#83) (@ShixiangWang)
  • Report capabilities — metrics parsing, template wiring, auto-snapshots (#83 Task 5) (@ShixiangWang)
  • Point the API reference at the code-generated spec; drop the stale hand-maintained openapi.yaml (@ShixiangWang)
  • Per-user AI credentials resolution + canvas comment preservation (@ShixiangWang)
  • Deploy modes — OXO_FLOW_DISABLE_RATE_LIMIT testing escape hatch (@ShixiangWang)
  • Link oxo-flow-community catalog from README and guide nav (@ShixiangWang)
  • Desktop app — SPA assets ship prebuilt in static/ (rebuild for latest UI) (@ShixiangWang)
  • Drop remaining clinical-grade claims about oxo-flow itself (#83 P0-1) (@ShixiangWang)
  • Report documentation sweep — honest claims, new flags, new sections (#83) (@ShixiangWang)
  • Collaboration — share landing pages, enforced visibility, version history (@ShixiangWang)
  • Sync web docs with the v0.11 hardening (files/instances/webhooks/API keys/retry semantics/share landing/remote cluster execution/multi-tenancy/guided mode) (@ShixiangWang)
  • Release asset table for desktop bundles (dmg/deb/rpm/AppImage) (@ShixiangWang)
  • Dry-run usage/parity note + status timing example with peak RSS column (@ShixiangWang)
  • Sync command pages with the alignment audit + new ai command page (#67) (@ShixiangWang)
  • China network mirrors reference — snapshot findings, recommended stack, re-runnable probe script (#67) (@ShixiangWang)
  • Staging/pairs-reentry/HMAC/cluster-logs/diagnostics sync for #80 + #67 (@ShixiangWang)
  • Design for #80 follow-up — S3 toolchain bump, remote staging, pairs re-entry (#80) (@ShixiangWang)
  • Execution backends, storage invalidation, checkpoint re-entry (#78) (@ShixiangWang)
  • Deployment modes reflect verified behavior (sub-path mount, run-control truth, user/audit management) (@ShixiangWang)
  • Implementation plan for issue #78 — 19 tasks across P1/P2/P3 (@ShixiangWang)
  • Refresh stale test counts; clarify parity contract comment (@ShixiangWang)
  • Design spec for issue #78 — static plan + pluggable executors (P1/P2/P3) (@ShixiangWang)
  • Document tombstones in checkpoint format (status + glossary) (@ShixiangWang)
  • Remove web evaluation report — superseded by issue #79 (@ShixiangWang)
  • Sync consistency work across run/dry-run/troubleshooting (@ShixiangWang)
  • Add web simulated-user evaluation report (12 personas, 5-dimension verdict) (@ShixiangWang)
  • Add web simulated-user evaluation design (@ShixiangWang)
  • Mark web design spec complete — merged to main (@ShixiangWang)
  • All phases complete — spec status finalized (@ShixiangWang)
  • Live AI verification done — real Claude loop validated end-to-end (@ShixiangWang)
  • Final phase-status annotation in the web spec (@ShixiangWang)
  • Annotate P2/P3 completion and deviations in the web spec (@ShixiangWang)
  • P3 AI assistant implementation plan (@ShixiangWang)
  • Dag edit API extended ops + web canvas how-to guide (@ShixiangWang)
  • P2 graphical editor implementation plan (@ShixiangWang)
  • Annotate P0 fixes in web design spec (@ShixiangWang)
  • P0 execution-truth implementation plan (@ShixiangWang)
  • Web full-lifecycle design spec — graphical editor, grounded AI, execution truth fixes (@ShixiangWang)

Features#

  • web: Rule timeline — the terminal-native signature element (@ShixiangWang)
  • web: Quota endpoint reports the acting user's usage (@ShixiangWang)
  • cli: Run auto-snapshot + --r-data TSV export + report --diff/--acct (#83 P1-14/P1-15/P1-6/P1-13) (@ShixiangWang)
  • cli: Zero-arg report discovery, --run/--failed/--plan, template wiring (#83 P1-1/P0-9/P2-7) (@ShixiangWang)
  • web: Code-generated OpenAPI 3.1 spec via utoipa (issue #82 P1-13) (@ShixiangWang)
  • executor: Sampled CPU-seconds metering → BenchmarkRecord + honest CPU column (#83 P1-13) (@ShixiangWang)
  • web: Preserve TOML comments/formatting in canvas edits (issue #82 P2-3) (@ShixiangWang)
  • web: Per-user AI provider runtime isolation (deferred #82 item) (@ShixiangWang)
  • report: Metrics adapters for fastp/flagstat/STAR/featureCounts/bcftools/kraken2 + rule×sample matrix (#83 P1-5) (@ShixiangWang)
  • web: Remote cluster execution over SSH — stage/launch/poll/pull (#82 deployment modes) (@ShixiangWang)
  • report: Execution-truth reporting — WS1 honesty + WS2 checkpoint facts + WS3 single contract (#83) (@ShixiangWang)
  • web: #81 backlog — validate parity, CLI command exposure, misc fixes (@ShixiangWang)
  • web: Polish — dark mode, TOML highlighting, quota enforcement, error-line jumps (#82 P1-9/P2) (@ShixiangWang)
  • web: API contract & cleanup — diff contract, pagination, webhooks, API keys, rule-level SSE (#82 P1-3/P1-4/P1-10/P1-12/P1-13/P1-18) (@ShixiangWang)
  • web: Beginner layer — guided builder, task-oriented home, i18n zh, role-trimmed nav (#82 P1-5/P1-7/P1-8/P1-15) (@ShixiangWang)
  • web: Share closure + pipeline version history (#82 P0-6/P1-14) (@ShixiangWang)
  • web: Run-loop closure — real retry, logs view, instances, cancel, telemetry (#82 P0-3/P0-7/P1-1/P1-2/P1-19) (@ShixiangWang)
  • web: File service layer — download/preview/zip results, multipart upload (#82 P0-1/P0-2) (@ShixiangWang)
  • web: Multi-tenancy isolation — ownership scoping on every run/pipeline/control endpoint (#82 P0-4/P0-5) (@ShixiangWang)
  • ci: GitHub release ships desktop bundles — macOS .app/.dmg, Linux .deb/.rpm/.AppImage (@ShixiangWang)
  • cli: Alignment audit — status --timing memory columns, touch --workdir + workflow-dir base, test execution flags, resume -k/--timeout, batch --json honored, -d short unified (#67 follow-up) (@ShixiangWang)
  • cli: Dry-run parity with run — --arg/KEY=VALUE/--sample/--rerun/--resume-failed, shared override helpers, executor freshness gate in the preview (4 new parity scenarios) (@ShixiangWang)
  • Deployment smoke suite (7 scenarios) + config-file defaults for CLI serve (@ShixiangWang)
  • Instance-level dry-run preview in the web UI (issue #79 P2) (@ShixiangWang)
  • executor: Sampled peak-RSS metering → BenchmarkRecord + diagnostics resource_bottlenecks at ≥80% of declared limit (#67) (@ShixiangWang)
  • cli: Cluster logs — last stub resolved via ExecutorBackend::logs (sacct/qstat/qacct/bacct), mock-scheduler tested (#67) (@ShixiangWang)
  • webhook: Real HMAC-SHA256 signatures (RFC 4231 verified), legacy keyed-sha256 behind signature_scheme (#67) (@ShixiangWang)
  • reentry: [[pairs]]-driven checkpoint re-entry — manifest pairs, pair_id identity, E015 conflict, E016 collision, E014 extended (#80) (@ShixiangWang)
  • storage: Remote staging/upload — etag-keyed cache, pattern substitution on a rule copy, upload-after-validate, MinIO E2E (#80) (@ShixiangWang)
  • storage: S3-storage compiles and works live — env config, path-style opt-in, resolver registration, MinIO etag E2E (#80) (@ShixiangWang)
  • ui: Design system v2 — terminal-vernacular identity (issue #79 aesthetics) (@ShixiangWang)
  • Platform config file + SSH cluster connections (web) — ai/ssh customization surface (@ShixiangWang)
  • Desktop packaging — single-file .app/.dmg/.deb via cargo-bundle; serve env vars + --open (@ShixiangWang)
  • cli: Dry-run previews deterministic re-entry reconstruction (#78) (@ShixiangWang)
  • cli: Checkpoint re-entry hook in the run loop (#78) (@ShixiangWang)
  • core: Checkpoint re-entry — manifest surface, template re-expansion, records (#78) (@ShixiangWang)
  • cli: Thread StorageResolver into manifest snapshots; graceful remote-input degradation (#78) (@ShixiangWang)
  • core: Etag-aware remote manifest snapshot + unified manifests_match (#78) (@ShixiangWang)
  • core: Remote manifest entries (scheme/key/etag/size), backward compatible (#78) (@ShixiangWang)
  • core: StorageBackend::head + RemoteStat — S3 ETag / GCS md5Hash (#78) (@ShixiangWang)
  • 16S amplicon gallery template (QIIME2 backbone) — issue #79 R-10 domain gap (@ShixiangWang)
  • core: BackendDriver — submit/poll loop with queue cap and failure propagation (#78) (@ShixiangWang)
  • Sub-path deployment — --base-path actually mounts the app (issue #79 deployment modes) (@ShixiangWang)
  • core: ExecutorBackend trait + ClusterExecutor with shared job-id/status parsing (#78) (@ShixiangWang)
  • core: ScheduledPlan + ScheduledRule — executor-agnostic static plan (#78) (@ShixiangWang)
  • Temporary rules with tombstone + lazy cascade-up; configurable cache aging (@ShixiangWang)
  • Close the dry-run/run consistency gaps + content-hash invalidation (@ShixiangWang)
  • web: Run-diagnosis chat tools; tool errors emit ToolResult events (@ShixiangWang)
  • frontend: My Pipelines page (open/export/delete), pipeline loading, login page (@ShixiangWang)
  • web: Chat prompt enforces TOML array I/O and direct validation fixes; 6 rounds (@ShixiangWang)
  • web: Report Q&A and visualization answer from real run data (@ShixiangWang)
  • web: Run options dialog — samples, targets, keep-going, max jobs; template loading (@ShixiangWang)
  • frontend: Chat renders grounded tool-call cards (@ShixiangWang)
  • web: Chat runs the grounded agent loop with real streaming events (@ShixiangWang)
  • ai: Orchestrator event sink and cancellation (@ShixiangWang)
  • ai: Streaming chat for openai-compatible providers (@ShixiangWang)
  • frontend: React Flow canvas editor — palette, inspector, edge kinds, monitor reuse; drop cytoscape (@ShixiangWang)
  • web: Null patch key removes field in dag edit API (@ShixiangWang)
  • web: Dag nodes carry environment and full serialized rule (@ShixiangWang)
  • web: Knowledge search endpoints for the editor palette (@ShixiangWang)
  • web: Dag edges tagged file vs declared (@ShixiangWang)
  • web: Dag edit API supports full rule specs via TOML-patch update_rule (@ShixiangWang)
  • web: Node status derived from engine checkpoint; drop dead run_nodes table (@ShixiangWang)
  • web: Cancel/pause/resume signal the live run process group (@ShixiangWang)
  • web: Executor registers run process group, defers to cancel state (@ShixiangWang)
  • web: Process-group registry for real run control (@ShixiangWang)

Maintenance#

  • Bump rust-toolchain 1.92.0 → 1.97.1 (aws-sdk MSRV 1.94.1; #80) (@ShixiangWang)
  • frontend: Zero lint errors; lint joins the CI frontend gate (@ShixiangWang)

Other Changes#

Refactoring#

  • cli: Group report command args into ReportArgs (clippy too_many_arguments under -D warnings) (@ShixiangWang)
  • Clippy-clean chat degradation buffer + audit module layout (@ShixiangWang)
  • cli: Cluster submit renders via ExecutorBackend; P1 acceptance tests (#78) (@ShixiangWang)
  • web: Remove legacy handlers, legacy router, and 20-user simulation tests (5k+ lines) (@ShixiangWang)
  • web: Delete legacy handlers modules and 20-user simulation tests; hpc_status moved to observability (@ShixiangWang)
  • frontend: Delete dead Runs page and SSEClient; fix lint in new components (@ShixiangWang)

Styling#

  • web: Breathing running badge + last hardcoded color in Share (@ShixiangWang)
  • web: Replace hardcoded hex colors with theme tokens (@ShixiangWang)
  • web: Rustfmt hpc.rs probe condition (CI fmt gate) (@ShixiangWang)
  • Type alias for the per-user AI row (clippy complex-type) (@ShixiangWang)
  • Type alias for the per-user AI row (clippy complex-type) (@ShixiangWang)
  • Clippy — clamp, let-chains, vec literals, type aliases, Option::map (workspace clean except #83 WIP) (@ShixiangWang)
  • Cargo fmt normalization (config loader, preview handler, dry-run test) (@ShixiangWang)
  • web: Collapse nested if in preview extraction (clippy -D warnings); docs: remote-glob wording (#67) (@ShixiangWang)
  • Drop blank lines left by the audit tests-module move (@ShixiangWang)
  • ai: Drop duplicate test import (@ShixiangWang)
  • web: Drop needless into on strings (@ShixiangWang)
  • ai: Collapse nested ifs in stream usage capture (@ShixiangWang)

Testing#

  • Update constructors for the enriched validate envelope; hpc route now requires auth in hpc mode (#82 P0-5) (@ShixiangWang)
  • web: Initialize both DB layers in router tests (audit middleware from #79 inserts via legacy pool) (@ShixiangWang)
  • BackendDriver checkpoint re-entry — round-2 execution via mock scheduler (#78) (@ShixiangWang)
  • Mock SLURM scheduler fixtures for cluster CI (issue #78/#74) (@ShixiangWang)
  • Parity contract matrix guards run/dry-run consistency (issue #77) (@ShixiangWang)
  • Upsert AI config row in restore test (parallel-safe) (@ShixiangWang)
  • Merge scripted-provider chat scenarios into one sequential test (registry is process-wide) (@ShixiangWang)
  • Async-aware lock for scripted-provider chat tests (@ShixiangWang)
  • Pipelines page title in legacy specs (@ShixiangWang)
  • Oauth state test self-initializes the infra pool (was order-dependent) (@ShixiangWang)
  • Root web integration expects completed status vocabulary (@ShixiangWang)

0.11.0 — 2026-08-13#

Bug Fixes#

  • Embed template gallery from crate-local templates/ so cargo publish works (issue #76 P1-3 follow-up) (@ShixiangWang)
  • Scientific review of gallery examples — RG escaping, env mismatches, (@ShixiangWang)
  • Scientific review of top-level examples — read groups, DAG races, env mismatch (@ShixiangWang)
  • Embed the template gallery in the binary — template works from installed releases (issue #76) (@ShixiangWang)
  • Web run flags reach the CLI executor — issue #69 follow-up (@ShixiangWang)
  • AI provider robustness — tool-call repair, overflow recovery, bounded results (issue #73, Phase 1 + 2.4) (@ShixiangWang)
  • Checkpoint reuse validates input manifests — issue #72 (@ShixiangWang)
  • Deep checks respect --workdir; drop duplicated #70 lock test (@ShixiangWang)
  • Allow too_many_arguments on dry_run_command (clippy -D warnings) (@ShixiangWang)
  • Resolve readiness paths against the workflow dir, not the process CWD (issue #63) (@ShixiangWang)
  • Actionable error for run flags swallowed by trailing overrides (issue #71) (@ShixiangWang)
  • MCP tool bridges register under def name (issue #61) (@ShixiangWang)
  • Avoid panic on non-UTF-8 CLI arguments (@ShixiangWang)
  • Post-merge review of #59 — bundle manifest source, tempdir cleanup, honest tests (@ShixiangWang)
  • Bundle gate probes stdin, and lint test code in CI (@andrewbudge)
  • Move modules deserializer before test module (items after a test module lint) (@ShixiangWang)
  • Examples — GATK best-practice alignment flags and BQSR known-sites (@ShixiangWang)
  • Web — run persistence, export by ID, SSE completion, legacy DB migration (@ShixiangWang)
  • Cli — JSON output, help texts, report --ai fallback, pixi env create (@ShixiangWang)
  • Ai knowledge — graph integrity test, dangling edge, honest counts (@ShixiangWang)
  • Engine — resource-group fast-fail, deferred chunk cleanup, config-var expansion (@ShixiangWang)
  • Transform operator — chunk extension, GatherVcfs args, cleanup implementation (@ShixiangWang)
  • Scientific correctness of examples and workflow-format docs (@ShixiangWang)
  • Gallery examples — sample expansion and output paths in multiomics & scRNA-seq (@ShixiangWang)
  • Resolve_config_list splits comma-joined strings; samples_list usable in expand_inputs (@ShixiangWang)
  • Rnaseq gallery — multiqc must not depend on index_bam (@ShixiangWang)
  • Diff now detects defaults, pairs, and sample group changes (@ShixiangWang)
  • Dry-run -j suggestion capped by DAG width — professional parallelism advice (@ShixiangWang)
  • Resource pool waits for availability instead of failing; professional -j suggestion (@ShixiangWang)
  • Dry-run lists rules in parallel-group order, not arbitrary topo order (@ShixiangWang)
  • Apply_defaults must respect rule-level resources.threads/memory (@ShixiangWang)
  • Deduplicate downstream rules in graph tree view (@ShixiangWang)

CI/CD#

  • Tolerate already-synced versions on re-tag (sync-version idempotency) (@ShixiangWang)
  • Install release target into the pinned toolchain (macOS builds) (@ShixiangWang)

Documentation#

  • Changelog for v0.11.0 — repository workflows, checkpoint-aware dry-run, AI explain/robustness, command consolidation (@ShixiangWang)
  • Update subcommand count to 29 in README, CONTRIBUTING, AGENTS (issue #76 follow-up) (@ShixiangWang)
  • Update guides for command consolidation — status timing view, export compose, removed commands, profile mechanism (issue #76) (@ShixiangWang)
  • Unify gallery embed style and ship the referenced environment specs (@ShixiangWang)
  • Cross-link dry-run checkpoint preview from run pilot flow and DAG skip checklist (issue #66 follow-up) (@ShixiangWang)
  • Mark rule hooks and optional as parsed-but-not-enforced (issue #75) (@ShixiangWang)
  • Fix 'ai status' references after ai action-space change (issue #65) (@ShixiangWang)
  • Ai explain + provider robustness reference (issues #65, #73) (@ShixiangWang)
  • Sync #72 input-manifest invalidation into troubleshooting, DAG skip guide, and glossary (@ShixiangWang)
  • Cross-link validate/env to test --deep (D002/D003 cover env files and PATH binaries, issue #64 follow-up) (@ShixiangWang)
  • Finish #68/#70 doc sweep — validate path base, clean lock guard, run --workdir scenario (@ShixiangWang)
  • Complete help descriptions for every command, subcommand, and argument (@ShixiangWang)
  • Sync #63 readiness + --samples ready into run/dry-run/test/cohort how-to (@ShixiangWang)
  • Link gallery concept explanations to reference docs (@ShixiangWang)
  • Explain expand_inputs in WGS gallery with reference links (@ShixiangWang)
  • Sync config-change invalidation into run/resume/status/architecture/workflow-format (@ShixiangWang)
  • Teach wildcards fan-out vs fan-in for beginners (@ShixiangWang)
  • Sync #60 pilot workflow into quickstart, cohort how-to, and wgs gallery (@ShixiangWang)
  • Use sk- placeholder form for API keys (no bare sk-... patterns) (@ShixiangWang)
  • Run --bundle gate semantics — non-interactive sessions and --json require --yes; fix --profile row (@ShixiangWang)
  • Comprehensive audit — sync all pages with engine behavior and science (@ShixiangWang)
  • Sync gallery pages with scientific fixes in examples (@ShixiangWang)
  • How-to audit — align 12 guides with engine behavior; fix example resources (@ShixiangWang)
  • Gallery index — clarify graph (template) vs dry-run (expanded) DAG (@ShixiangWang)
  • Explain {input} vs {input[0]} equivalence and when to use each (@ShixiangWang)
  • Clarify gather routing is declared via scatter.gather, not inferred (@ShixiangWang)
  • Document gather inference reliability in complex scatter-gather (@ShixiangWang)
  • Fix multiomics -j advice — resource pool schedules by thread capacity (@ShixiangWang)
  • Unify -j values with professional suggestion; clarify optional input/output (@ShixiangWang)
  • Note ToolRegistry non-Clone limitation in create_context (@ShixiangWang)
  • Document four embedded AI knowledge sources in ai-cli.md (@ShixiangWang)
  • Document env create --ai in AI CLI command reference (@ShixiangWang)
  • Environment-management — add missing mamba and modules sections (@ShixiangWang)
  • Rewrite variant-calling tutorial with professional paired tumor-normal design (@ShixiangWang)
  • Quickstart — output directories are auto-created, remove mkdir boilerplate (@ShixiangWang)
  • Remove stale INFO log line from quickstart run output (@ShixiangWang)
  • Extend custom-scripts example to two chained script rules (@ShixiangWang)
  • Rewrite custom-scripts tutorial with runnable example and params explanation (@ShixiangWang)
  • Multiqc aggregates only the two QC rounds; clarify parallel scheduling (@ShixiangWang)
  • Fix tutorial DAG — multiqc had no real dependencies with directory inputs (@ShixiangWang)
  • Move Wildcard Patterns admonition out of TOML code block (@ShixiangWang)
  • Fix markdown list rendering in quickstart web UI section (@ShixiangWang)

Features#

  • Repository workflows — pull/run clone git repos directly (no bundle required) (@ShixiangWang)
  • Consolidate commands — status absorbs history, export gains compose, remove history/package/profile/watch (issue #76) (@ShixiangWang)
  • Value recovery from the dead-code audit — optional rules, hook (@ShixiangWang)
  • Dry-run checkpoint preview — rerun blast radius and protected scope (issue #66) (@ShixiangWang)
  • Web runs link to saved pipelines with persistent workdirs — issue #69 (@ShixiangWang)
  • Ai explain — three-layer workflow explanation (issue #65) (@ShixiangWang)
  • --workdir on dry-run/test/clean/report/resume; validate uses workflow dir (issue #68) (@ShixiangWang)
  • Workdir lock prevents concurrent-run checkpoint races (issue #70) (@ShixiangWang)
  • Test --deep pipeline health checks (issue #64) (@ShixiangWang)
  • Checkpoint remembers its workdir; resume re-runs from it (issue #68) (@ShixiangWang)
  • Sample readiness + --samples ready for incremental data arrival (issue #63) (@ShixiangWang)
  • Config-change impact analysis — precise checkpoint invalidation (issue #62) (@ShixiangWang)
  • Custom skills Phase 2 (MCP tool skills) + Phase 3 (SKILL.md) — issue #61 (@ShixiangWang)
  • Banner header for run logs; fix help art glyphs (@ShixiangWang)
  • User-defined custom skills — Phase 1 secure minimal loop (issue #61) (@ShixiangWang)
  • AI preflight & pilot summary (issue #60 Phase 2) — scientific constraints + scale-up projection (@ShixiangWang)
  • Pilot subset (--samples) and forced re-run (--rerun) for fast-fail exploration (@ShixiangWang)
  • Graph --expanded shows runtime DAG; simplify wgs-germline config (@ShixiangWang)
  • Report --ai adds plain-language result interpretation (@ShixiangWang)
  • Env create --ai supports pixi backend; ToolRegistry made shareable (@ShixiangWang)
  • Embed pipeline knowledge graph (78 skills, 470 transitions) + token-cost optimizations (@ShixiangWang)
  • Embed 562 bioSkills Agent Skills + lookup_skill AI tool (@ShixiangWang)
  • Embed full Bioconda CLI database (6103 tools) for AI tool lookup (@ShixiangWang)
  • Add help text to all CLI arguments and options (@ShixiangWang)
  • AI-powered environment spec generation (env create --ai) (@ShixiangWang)

Other Changes#

  • Merge PR #59: fix bundle confirmation gate + lint test code in CI (@ShixiangWang) (#59)

Refactoring#

  • Gallery docs embed via snippet includes; CLI embeds all 15 templates (@ShixiangWang)
  • Single-tier examples — top-level workflows folded into the gallery (11–15) (@ShixiangWang)
  • Remove 74 dead items across the workspace — audited symbol-by-symbol (@ShixiangWang)
  • Truncate fingerprint-mismatch list in the config-change summary (@ShixiangWang)
  • Finish issue #61 review cleanups (@ShixiangWang)
  • Change system resource log from INFO to DEBUG, display memory in GB (@ShixiangWang)

Testing#

  • Deep verification of embedded knowledge sources + fixes (@ShixiangWang)

0.10.2 — 2026-08-12#

Bug Fixes#

  • Use macro-based archive building for format-agnostic publish (@ShixiangWang)
  • Reserve signatures in manifest, harden bundle extraction path (@andrewbudge)
  • Resolve clippy lints (collapsible_if, needless_borrow, unused vars) (@ShixiangWang)
  • Correct Andrew Budge GitHub username in contributors section (@ShixiangWang)
  • Wgs_germline combine_gvcfs sample expansion (@ShixiangWang)
  • Modernize examples and sync gallery docs (@ShixiangWang)
  • Broken transform chunk paths and wgs_germline sample source (@ShixiangWang)

Documentation#

  • Add --format, --bundle, --yes to publish.md and run.md (@ShixiangWang)
  • Document pluggable report section system in report.md and workflow-format.md (@ShixiangWang)
  • Comprehensive audit and fix of all documentation (83 issues) (@ShixiangWang)
  • Modernize homepage examples and fix capability claims (@ShixiangWang)
  • Add contributors section to README with GitHub-style avatar display (@ShixiangWang)

Features#

  • Archive format abstraction (.tar.gz + .tar.zst), pull docs, confirmation gate (@ShixiangWang)
  • Add bundle execution confirmation gate with --yes flag (@ShixiangWang)
  • Add per-rule resource summary to bundle manifest (@ShixiangWang)
  • Pluggable report section system with domain auto-detection (@ShixiangWang)
  • Compose support, conda package specifiers, clinical compliance report (@ShixiangWang)

Other Changes#

  • Merge branch 'fix/bundle-manifest-and-temp-hardening' (@ShixiangWang) (#58)
  • Merge branch 'main' of https://github.com/Traitome/oxo-flow (@ShixiangWang)

0.10.1 — 2026-08-11#

Bug Fixes#

  • Cluster partition rendering, forbid(unsafe) in AI crate, and env detection (@ShixiangWang)
  • AI analysis precision, debug expansion, and keep_going propagation (@ShixiangWang)
  • AI Companion prompt syntax, token tracking, and setup UX (@ShixiangWang)

Documentation#

  • Clarify web UI entry point in Quick Start and Deployment sections (@ShixiangWang)
  • Move Three-Mode Deployment after Web API section (@ShixiangWang)
  • Add transform-operator gallery page for 10th workflow (@ShixiangWang)
  • Simplify README, fix stale facts across all documentation (@ShixiangWang)
  • System check and optimize README.md (@ShixiangWang)
  • Comprehensive DAG execution documentation overhaul (@ShixiangWang)

Features#

  • PDF report support, secret scanning, Vega-Lite dashboard, and security docs (@ShixiangWang)

Performance#

  • Event-driven fine-grained scheduler replaces group barriers (@ShixiangWang)

0.10.0 — 2026-08-10#

Bug Fixes#

  • Async validate_command to prevent nested runtime crash (@ShixiangWang)

Documentation#

Features#

  • Oxo-flow ai test + ai setup + ai status subcommands (@ShixiangWang)
  • Verify DeepSeek both API formats + update docs (@ShixiangWang)
  • AiRuntime wired as single entry point for template command (@ShixiangWang)
  • L3 Agent + scope config + skill discovery wired into commands (@ShixiangWang)
  • AI session tracking + ai status command (@ShixiangWang)
  • AI auto-detection from workflow [ai] section (@ShixiangWang)
  • Professional AI prompts + debug --ai + lint --ai (@ShixiangWang)
  • Phase 5 — MCP bridge + Skill system (@ShixiangWang)
  • Phase 4 — scope-level AI config + AI plugin system (@ShixiangWang)
  • Phase 3 — AI error recovery on run failures (@ShixiangWang)
  • Phase 2 — AI-powered dry-run and validate analysis (@ShixiangWang)
  • Web crate migration + AI CLI documentation (@ShixiangWang)
  • Phase 1 — oxo-flow-ai crate + AI-powered template generation (@ShixiangWang)

Maintenance#

0.9.4 — 2026-08-09#

Features#

  • Typed config values + full ConfigDef runtime enforcement (@ShixiangWang)
  • Enforce ConfigDef choices validation + sensitive masking (@ShixiangWang)

0.9.3 — 2026-08-09#

Bug Fixes#

  • Support arguments.* references in when conditions (@ShixiangWang)
  • Propagate rule failures transitively, count skips once (@andrewbudge)
  • Propagate rule failures transitively, count skips once (@andrewbudge)
  • Sanitize remaining error leaks in execution and workflow handlers (@ShixiangWang)
  • Sanitize error messages, dynamic share URLs, deployment tests (@ShixiangWang)
  • Auth session persistence and FK constraint (@ShixiangWang)
  • API maturity, accessibility, and cross-page state persistence (@ShixiangWang)
  • Security hardening and web UI production readiness (@ShixiangWang)

Features#

  • PostgreSQL backend activation + OpenAPI 3.1 spec regeneration (@ShixiangWang)

Maintenance#

  • Fmt + clippy compliance for [arguments]→[config] merge (@ShixiangWang)
  • Repository cleanup — fmt, port consistency, stale files (@ShixiangWang)

Other Changes#

  • PR #56 — fix transitive failure propagation and skip counting (@ShixiangWang) (#56)
  • PR #56 — fix transitive failure propagation and skip counting (@ShixiangWang)

Refactoring#

  • Finish [arguments]→[config] merge — tests, CLI flags, format (@ShixiangWang)
  • Merge [arguments] into upgraded [config] block (@ShixiangWang)

Testing#

  • Comprehensive browser UI + real-world scenario tests (@ShixiangWang)
  • Multi-user lifecycle Playwright tests + PostgreSQL backend (@ShixiangWang)

0.9.2 — 2026-08-08#

Bug Fixes#

Documentation#

  • Comprehensive sample/pair discovery documentation (@ShixiangWang)

Features#

  • Optional pair control for tumor-only CNV and unmatched scenarios (@ShixiangWang)
  • Comprehensive sample/pair discovery with --sample flag (@ShixiangWang)
  • Comprehensive index auto-build with 9 types + samples_list (@ShixiangWang)
  • Integrate [[references]] with Reference Discovery API (@ShixiangWang)
  • Add [[references]] auto-index building to engine (@ShixiangWang)

Other Changes#

  • Merge branch 'main' of https://github.com/Traitome/oxo-flow (@ShixiangWang)

0.9.1 — 2026-08-07#

Documentation#

  • Update all documentation for #50 (workflow args) and #51 (publish) (@ShixiangWang)

Features#

  • Add [arguments] block with --arg CLI flag for workflow parameters (@ShixiangWang)

Other Changes#

  • Merge branch 'main' of https://github.com/Traitome/oxo-flow (@ShixiangWang)

0.9.0 — 2026-08-07#

Bug Fixes#

Features#

  • Add --with-lockfiles flag to publish for conda reproducibility (@ShixiangWang)
  • Record container refs in manifest, warn on missing env files (@ShixiangWang)
  • Add --bundle flag to run, add pull subcommand (@ShixiangWang)
  • Rewrite publish to emit verifiable .tar.zst archive (@ShixiangWang)
  • Enable true parallel execution with -j flag (@ShixiangWang)
  • Wire output validation, add MambaBackend, fix container CWD (@ShixiangWang)

Other Changes#

Refactoring#

Testing#

  • Add edge case tests for publish/run --bundle/pull (@ShixiangWang)

0.8.1 — 2026-06-22#

Bug Fixes#

  • Optimize Dockerfile and standardize project email to w_shixiang@163.com (@ShixiangWang)
  • Remove duplicate HTML document and correctly place Web API section (@ShixiangWang)

Documentation#

  • Add oxo-flow bioRxiv preprint to citation sections (@ShixiangWang)
  • Simplify CLI/API to concise intro + doc links (@ShixiangWang)
  • Comprehensive CLI (31cmds) + API (48eps) with search, collapse, categories (@ShixiangWang)
  • Tone down clinical-grade reporting → reproducible/reporting (@ShixiangWang)

Performance#

  • Avoid sysinfo System::new_all() when only one metric is needed (#46) (@andrewbudge) (#46)

0.8.0 — 2026-06-14#

Bug Fixes#

  • Resolve all audit findings — Makefile tabs, suite.py shadowing, version refs, Snakemake (@ShixiangWang)

Documentation#

  • Add CONTRIBUTING.md and SECURITY.md (@ShixiangWang)
  • Overhaul landing page — AI Companion, current API, React stack (@ShixiangWang)
  • Overhaul README — AI Companion, current API, clean duplicates (@ShixiangWang)
  • Deployment guide, AI provider env vars, UI polish (@ShixiangWang)
  • Add cloud storage reference doc, update LIMITATIONS.md and nav (@ShixiangWang)

Features#

  • AI config API, runtime provider switching, Docker deployment, UI polish (@ShixiangWang)
  • Docker deployment, custom AI URLs, frontend serving (@ShixiangWang)
  • AI provider abstraction with Claude/OpenAI/Ollama support (@ShixiangWang)
  • AI-native pipeline platform with structured results and web frontend (@ShixiangWang)
  • core: Implement real S3/GCS storage backends, expand webhook & plugin tests, add benchmarks (@ShixiangWang)

Maintenance#

Other Changes#

Performance#

  • bench: Restructure benchmarks into modular suite with 35 micro-benchmarks (@ShixiangWang)

0.7.0 — 2026-05-25#

Bug Fixes#

  • Resolve doc/code discrepancies found in consistency audit (@ShixiangWang)
  • Use serde serialization for format_workflow, fix example workflows (@ShixiangWang)
  • Resolve all remaining code audit issues across core, web, and plugin (@ShixiangWang)
  • --as-include skips E010, fix double GPU flag, escape report HTML, respect rule retries (@ShixiangWang)
  • Respect rule-level retries field in execution retry loop (@ShixiangWang)
  • Complete security patterns, validate export/package format args (@ShixiangWang)
  • Resolve 5 feature gaps from production readiness audit (@ShixiangWang)
  • Wildcard constraints filter instead of fail, optional rules warn on missing input (@ShixiangWang)
  • Improve target resolution UX and environment listing, fix CI issues (@ShixiangWang)
  • web: Resolve 6 bugs from production readiness audit (@ShixiangWang)
  • Resolve CLI unwrap risks and Core config expect improvements (@ShixiangWang)
  • web: Comprehensive test-driven fixes for 9 issues found (@ShixiangWang)
  • container: Add CMD to Dockerfile for better UX (@ShixiangWang)
  • container: Add cargo install + fallback to Singularity def oxo-flow installation (@ShixiangWang)
  • container: Use cargo install + GitHub release fallback for Dockerfiles (@ShixiangWang)
  • web: Prevent XSS via workflow name in onclick handlers (@ShixiangWang)

Documentation#

  • Complete rewrite of JSON Schema, fix all CLI and format doc gaps (@ShixiangWang)
  • Add missing rule fields, env_groups, genome_build to workflow format spec (@ShixiangWang)
  • web: Add multi-user web system design specification (@ShixiangWang)
  • web: Add security model and DELETE endpoint to web API docs (@ShixiangWang)

Features#

  • Light theme, license upload web UI, and CLI license command (@ShixiangWang)
  • web: Embed default academic license with commercial notice (@ShixiangWang)
  • web: Comprehensive multi-user web system with User Mgmt, HPC, Templates (@ShixiangWang)
  • web: Add HPC scheduler integration for Slurm/PBS monitoring (@ShixiangWang)
  • web: Add scheduled workflow runs with cron support (@ShixiangWang)
  • web: Add P2 Enterprise Governance and Template Library features (@ShixiangWang)
  • web: Modularize handlers and add maud templates (@ShixiangWang)
  • web: Add optional id field to SaveWorkflowRequest for upsert support (@ShixiangWang)
  • container: Add oxo-flow binary installation to Dockerfile and Singularity def (@ShixiangWang)
  • web: Add New Workflow button, auto-clear save name, UX polish (@ShixiangWang)
  • web: Add Dockerfile export button and modal to editor (@ShixiangWang)
  • web: Replace prompt() login with modal sign-in form (@ShixiangWang)
  • web: Add workflow deletion, SSE live updates, and editor templates (@ShixiangWang)
  • web: Add CLI arg parsing to web binary, update full API docs (@ShixiangWang)
  • web: Add GET /api/workflows/saved/{id} endpoint and Load-to-Editor (@ShixiangWang)
  • web: Professional dark-themed Command Center SPA frontend (@ShixiangWang)
  • web: Full workflow lifecycle API, workspace isolation, and 20-user simulation (@ShixiangWang)

Maintenance#

  • Fix all 16 unused-variable warnings in simulation_20users (@ShixiangWang)
  • Fix make ci - remove orphan comments, fix clippy warnings (@ShixiangWang)
  • web: Remove 15 orphan doc comments after handler dedup (@ShixiangWang)
  • Remove e2e-playwright test suite (@ShixiangWang)
  • Update e2e gitignore for logs and lock file (@ShixiangWang)
  • Update Cargo.lock for web crate clap dependency (@ShixiangWang)

Refactoring#

  • web: Remove 1101 dup lines, dead maud templates, partials (@ShixiangWang)
  • web: Remove 31 duplicate handlers, add DAG viz + template CRUD UI (@ShixiangWang)
  • web: Split frontend into index.html + app.js (@ShixiangWang)

Testing#

  • web: Add Playwright E2E tests for multi-user web system (@ShixiangWang)
  • web: Add 20 real-world user scenario tests from expert perspectives (@ShixiangWang)
  • container: Add tests for oxo-flow install in Dockerfile and Singularity def (@ShixiangWang)
  • web: Add E2E lifecycle tests for save/load/delete and full run cycle (@ShixiangWang)

0.6.1 — 2026-05-24#

Bug Fixes#

  • Replace silent checkpoint save failures with tracing warnings (@ShixiangWang)
  • Resource detection, checkpoint skip, error cascade, and validation improvements (@ShixiangWang)
  • Workspace tests use tempdir for CI reliability (@ShixiangWang)
  • Allow ':' in rule names and add include E2E tests (@ShixiangWang)
  • Parse conda env name from YAML content, not file stem (@ShixiangWang)

Documentation#

  • Fix README accuracy, serve base_path passthrough, and broken links (@ShixiangWang)
  • Add missing history command reference page (@ShixiangWang)
  • Update plugin-system.md to reflect full implementation (@ShixiangWang)
  • Fix plugin-system.md to reflect actual implementation status (@ShixiangWang)
  • Update command count to 31 (added history command) (@ShixiangWang)
  • Add CLI reference pages for all 29 commands (@ShixiangWang)

Features#

  • Subprocess-based dynamic plugin loading (@ShixiangWang)
  • Full plugin system with discovery, TOML integration, signatures (@ShixiangWang)
  • Retry persistence, plugin traits, i18n reports, input tests (@ShixiangWang)
  • Output verification with sizes, watch --run flag (@ShixiangWang)
  • History command, clean confirmation, plugin design doc (@ShixiangWang)
  • Dry-run execution hint, deadlock diagnosis improvement (@ShixiangWang)
  • Auto-create output dirs, watch dry-run, error test coverage (@ShixiangWang)
  • Progress ETA, dry-run input status, colored diff, error tests (@ShixiangWang)
  • Dry-run resource summary, output verification, deprecated cleanup (@ShixiangWang)
  • Input file existence check and --quiet banner suppression (@ShixiangWang)
  • Enhance dry-run output and update CITATION.cff (@ShixiangWang)
  • Transform operator tests and complete priority items (@ShixiangWang)
  • Resource exhaustion hints and enhanced test command (@ShixiangWang)
  • Env error hints, web crate tests, and improved init template (@ShixiangWang)
  • Improve oxo-flow init template with shell reference and China mirrors (@ShixiangWang)

Maintenance#

  • Fix stale version references and documentation consistency (@ShixiangWang)

Other Changes#

0.6.0 — 2026-05-21#

Bug Fixes#

  • Landing page rendering, badges, and stale content (@ShixiangWang)
  • Publish command crash and documentation accuracy (@ShixiangWang)

Documentation#

  • Add BLIT citation and optimize landing page badges (@ShixiangWang)
  • Refactor clinical reporting and synchronize CLI commands in README (@ShixiangWang)

Other Changes#

0.5.5 — 2026-05-20#

Bug Fixes#

  • Resolve bugs found by 30-user simulation testing (@ShixiangWang)
  • Resolve critical bugs, integrate security code, add tests, update deps, and fix README (@ShixiangWang)

Documentation#

  • Fix remaining stale subcommand count and add cargo install instruction (@ShixiangWang)

Features#

  • Auto-create output directories and add dry-run shell safety checks (@ShixiangWang)

Other Changes#

Styling#

  • Fix cargo fmt formatting in output directory creation (@ShixiangWang)

0.5.4 — 2026-05-19#

CI/CD#

  • Remove Venus from build/publish/release pipeline (@ShixiangWang)

Documentation#

Maintenance#

  • Completely remove Venus from oxo-flow repository (@ShixiangWang)
  • Remove Venus CLI integration tests, gitignore oxo-flow-venus (@ShixiangWang)
  • Remove Venus integration tests after extraction (@ShixiangWang)
  • Extract Venus into standalone repository oxo-flow-venus (@ShixiangWang)

Other Changes#

0.5.3 — 2026-05-18#

Bug Fixes#

  • Resolve clippy errors for Rust 1.95 and update test (@ShixiangWang)
  • Include schema file within CLI crate to fix cargo package build (#42) (@Copilot) (#42)

Documentation#

Features#

  • rule: Add Dir variant to FilePatterns for directory input (@ShixiangWang)
  • executor: Implement optional rule skip logic (@ShixiangWang)
  • rule: Add optional field for skip-on-missing behavior (@ShixiangWang)
  • format: Add validation for undefined env_group references (@ShixiangWang)
  • config: Add env_groups for shared environments (@ShixiangWang)
  • executor: Add auto-scaling helper functions (@ShixiangWang)
  • rule: Add AutoScale type for resource auto-scaling (@ShixiangWang)
  • config: Add reference_dir field with auto-derivation (@ShixiangWang)
  • cli: Implement --as-include validation mode (@ShixiangWang)
  • cli: Add --as-include flag to validate command (@ShixiangWang)
  • core: Enhance clinical workflow support and permissive wildcard expansion (@ShixiangWang)

Maintenance#

Testing#

0.5.2 — 2026-05-18#

Bug Fixes#

  • Suppress rustls-webpki audit warnings from aws-sdk-s3 transitive deps (@ShixiangWang)
  • Allow $(…) in shell templates; validate wildcard injection; fix dry-run when; fix example workflows (#40) (@Copilot) (#40)

Documentation#

  • Audit and clean up documentation, resolve implementation inconsistencies (@ShixiangWang)
  • Clean up and fix issues in all .md files (#41) (@Copilot) (#41)

Features#

  • 100% resolution of 40-user comprehensive testing — security, storage, CLI, docs (@ShixiangWang)
  • Achieve 100% resolution of 100-user comprehensive review (@ShixiangWang)
  • Resolve top 10 priority actions from 100-user comprehensive review (@ShixiangWang)
  • Switch to rustls, optimize hot paths, update docs and deps (@ShixiangWang)
  • Comprehensive 30-expert review, dependency upgrades, performance optimizations, and documentation updates (@ShixiangWang)
  • Implement Phase 9.6 roadmap items and performance optimizations (@ShixiangWang)
  • 30-expert user journey review, performance optimizations, and documentation improvements (@ShixiangWang)
  • Implement named inputs and outputs for rules (@ShixiangWang)
  • Address simulated user reviews and comprehensive optimization (@ShixiangWang)

Maintenance#

Other Changes#

Performance#

  • Optimize wildcard expansion engine and consolidate Phase 9.6 (@ShixiangWang)

0.5.1 — 2026-05-17#

Bug Fixes#

  • cli: Add 'default' alias for profile show and 'check' alias for config stats (@ShixiangWang)
  • docs: Add pairs_file/pairs_pattern/sample_groups_file to how-to guides (@ShixiangWang)
  • docs: Use absolute GitHub URLs for example workflow links (@ShixiangWang)

Documentation#

  • Add metadata field to pairs table documentation (@ShixiangWang)

Features#

  • batch: Implement true parallel execution with Semaphore (@ShixiangWang)
  • config: Add pairs_pattern for auto-discovering pairs from filesystem (@ShixiangWang)
  • config: Add pairs_file and sample_groups_file support (@ShixiangWang)
  • ci: Auto-update docs version references on version bump (@ShixiangWang)

0.5.0 — 2026-05-16#

Bug Fixes#

  • Correct cargo-audit config format (@ShixiangWang)
  • Address all issues from 30-expert review (@ShixiangWang)
  • venus: Add interpreter_map to generated workflow metadata (@ShixiangWang)
  • security: Relax shell validation for &&, ||, and pipes (@ShixiangWang)
  • executor: Remove duplicate resource release on failure (@ShixiangWang)
  • Simplify build_script_command to avoid clippy warning (@ShixiangWang)

CI/CD#

Documentation#

Features#

  • cli: Add batch subcommand for parallel task execution (@ShixiangWang)
  • Complete rule lifecycle hooks, environment injection, and custom interpreters (@ShixiangWang)
  • config: Fix namespace prefixing for depends_on in included rules (@ShixiangWang)
  • cli: Add progress bar for run command execution tracking (@ShixiangWang)
  • cli: Add --pending-timeout option to cluster submit (@ShixiangWang)
  • cli: Add --orphans option to clean command (@ShixiangWang)
  • lint: Add hook command safety validation (W020-W022) (@ShixiangWang)
  • executor: Implement script execution with interpreter detection and sequential shell+script (@ShixiangWang)
  • Add interpreter and interpreter_map fields for script execution (@ShixiangWang)
  • Add disk space pre-flight check and resource summary (@ShixiangWang)
  • scheduler: Implement ResourceHint memory estimation (@ShixiangWang)
  • executor: Add structured logging for resource allocation (@ShixiangWang)
  • cluster: Enhance GPU spec translation for SLURM/PBS/SGE (@ShixiangWang)
  • scheduler: Add system capacity validation with warnings (@ShixiangWang)
  • executor: Add process group timeout and cleanup on failure (@ShixiangWang)
  • executor: Use sysinfo for cross-platform memory detection (@ShixiangWang)
  • Add sysinfo, nix, fs2 dependencies for resource management (@ShixiangWang)
  • core: Implement unified transform operator for scatter-gather (@ShixiangWang)

Maintenance#

Other Changes#

Refactoring#

  • Add #[must_use] attributes to interpreter functions (@ShixiangWang)

Testing#

  • batch: Add comprehensive unit tests and update docs nav (@ShixiangWang)
  • executor: Add tests for interpreter detection and script execution (@ShixiangWang)

0.4.2 — 2026-05-16#

Bug Fixes#

  • validation: Exempt pairs/sample_groups wildcards from E003 (@ShixiangWang)
  • web: Replace panic with graceful error handling in executor (@ShixiangWang)
  • cli: Apply defaults and templates in dry-run and debug commands (@ShixiangWang)
  • cli: Properly return exit codes on cluster command failures and handle empty checkpoints (@ShixiangWang)

Documentation#

  • Fix installation package name and add security limitations (@ShixiangWang)
  • Add config get/set commands and explain dependencies metric (@ShixiangWang)
  • Update outdated CLI documentation (@ShixiangWang)

Features#

Other Changes#

0.4.1 — 2026-05-16#

Bug Fixes#

  • executor: Implement retry loop and hooks execution (@ShixiangWang)

0.4.0 — 2026-05-16#

Bug Fixes#

  • Expand placeholders in cluster submit scripts (@ShixiangWang)
  • Address critical bugs from user simulation testing (@ShixiangWang)
  • Remove unused helper functions and fix unused_mut warning (@ShixiangWang)
  • Add async mutex guard for thread-safe database initialization (@ShixiangWang)
  • Use process-specific temp database for tests (@ShixiangWang)
  • Resolve test database initialization race condition (@ShixiangWang)
  • Walltime tests and add 'd' suffix support (@ShixiangWang)
  • Add partition field to Resources Default and update tests (@ShixiangWang)
  • web: Resolve modal CSS priority issue and complete UI functions (@ShixiangWang)

Documentation#

Features#

  • Implement persistent checkpointing, fix modular includes, and reduce TOML noise (@ShixiangWang)
  • Add 81 new comprehensive tests for oxo-flow (145 total, covering CLI, core, Venus, bioinformatics) (#39) (@Copilot) (#39)
  • clinical: SHA-256 checksums and provenance persistence (@ShixiangWang)
  • validation: Integrate validate_format() and secret scanning (@ShixiangWang)
  • container: Add GPU support for container generation (@ShixiangWang)
  • cluster: Add GPU directives, per-rule walltime, modules, logs (@ShixiangWang)
  • bioinformatics: Address bioinformatics expert review (@ShixiangWang)
  • web: Implement critical Web API enhancements (@ShixiangWang)
  • Implement advanced user features (@ShixiangWang)
  • Address all issues from junior user review and generalize terminology (@ShixiangWang)
  • Implement WC-01 tumor-normal pairing, WC-02 sample groups, WF-01 conditional rules (#38) (@Copilot) (#38)
  • Make workflow argument optional for run and dry-run commands (@ShixiangWang)
  • Target-based partial workflow execution for run and dry-run (#37) (@Copilot) (#37)
  • Implement 20-persona dev plan Phase 1 and enhance CLI security/usability (@ShixiangWang)
  • Add ANSI colors and fix box alignment in ASCII graph output (@ShixiangWang)
  • cli: Add ASCII terminal graph output for oxo-flow graph (@ShixiangWang)
  • web: Complete industrial-grade Web UI system (Phase 10) (@ShixiangWang)

Maintenance#

Other Changes#

0.3.1 — 2026-05-13#

Bug Fixes#

  • Address all 32 review issues across security, code quality, pipeline correctness, and docs (#34) (@Copilot) (#34)

Documentation#

  • Sync docs changelog with root CHANGELOG.md via snippets include (#35) (@Copilot) (#35)

Features#

  • web: Add request and active workflow metrics with frontend auto-refresh (@ShixiangWang)

Other Changes#

Refactoring#

0.3.0 — 2026-04-07#

Bug Fixes#

  • Template variable substitution, DOT graph labels, and optional env check workflow (@Copilot)

Features#

  • Enhance error types, re-export public API, docs update (@Copilot)
  • wildcard: Add regex constraint validation and pattern-to-regex file discovery (@Copilot)
  • Add reference database tracking, data lineage, and extended job states (@Copilot)
  • core: Add GpuSpec, ResourceHint, and new Rule fields with builder methods (@Copilot)

Other Changes#

  • Merge pull request #32 from Traitome/copilot/update-oxo-flow-evaluation-report (@Copilot) (#32)
  • Merge pull request #30 from Traitome/copilot/oxo-flow-project-evaluation-report (@ShixiangWang) (#30)
  • Add debug subcommand and project root detection utility (@Copilot)
  • Initial plan (@Copilot)
  • Merge pull request #28 from Traitome/copilot/fix-template-variable-replacement-bug (@ShixiangWang) (#28)
  • Initial plan (@Copilot)

Refactoring#

  • Address code review comments - use imported HashMap and all_known_backends() (@Copilot)

0.2.0 — 2026-04-06#

Bug Fixes#

  • Path traversal protection in touch, overflow protection in duration parsing (@Copilot)

CI/CD#

  • Add Windows ARM64, i686 Windows, and ARMv7 Linux release targets (@Copilot)

Features#

  • Add Rule depends_on/retry_delay/workdir/hooks, DAG critical_path, format diff/lint codes (@Copilot)

Other Changes#

  • Merge pull request #26 from Traitome/copilot/add-ci-automation-release-support (@ShixiangWang) (#26)
  • Merge pull request #21 from Traitome/copilot/fix-267392264-1201351505-31179d07-4ceb-4491-a557-c277d32cfe31 (@ShixiangWang) (#21)
  • Add comprehensive tests for new features (@Copilot)
  • Fix summary statistics to match actual opinion counts (89 total) (@Copilot)
  • Add comprehensive expert panel evaluation TODO.md (@Copilot)
  • Initial plan (@Copilot)

0.1.3 — 2026-04-06#

Bug Fixes#

  • Rename venus crate to oxo-flow-venus to avoid crates.io name conflict (@Copilot)

Other Changes#

  • Merge pull request #25 from Traitome/copilot/update-package-name-to-oxo-flow-venus (@ShixiangWang) (#25)
  • Initial plan (@Copilot)

0.1.2 — 2026-04-06#

Bug Fixes#

  • Add version to workspace path deps for crates.io publishing (@Copilot)

Other Changes#

0.1.1 — 2026-04-06#

CI/CD#

  • Replace deprecated macos-13 with macos-latest cross-compiling to x86_64 (@Copilot)
  • Fix release and crates.io publish being blocked by cancelled builds (@Copilot)

Documentation#

  • Fix number formatting (1 000 → 1,000) (@Copilot)
  • Update landing page to accurately reflect repository state (@Copilot)

Other Changes#

0.1.0 — 2026-04-06#

Bug Fixes#

  • Address code review feedback - XSS, event handling, credential docs (@Copilot)
  • Address code review feedback - improve test comments, fix bismark path, add escape docs (@Copilot)

Build#

  • Use workspace version inheritance for all crates, update CI sync-version (@Copilot)

CI/CD#

  • Skip heavy build jobs on pull_request events to prevent slow/cancelled runs (@Copilot)
  • Optimize CI workflow for reliable builds and crates.io publishing (@Copilot)

Documentation#

  • Add missing documentation files referenced in TODO.md (@Copilot)
  • Replace TODO.md with comprehensive 30-expert evaluation report (@Copilot)
  • Update TODO.md to mark completed items (@Copilot)
  • Add complete documentation website with MkDocs Material, landing page, tutorials, command reference, and architecture docs (@Copilot)
  • Fix grammar in quickstart tutorial (@Copilot)
  • Create complete documentation website (@Copilot)
  • Add CHANGELOG, CITATION, CODE_OF_CONDUCT, CONTRIBUTING, cliff.toml, and CI/CD pipeline (@Copilot)

Features#

  • web: Add in-memory rate limiter and graceful shutdown (@Copilot)
  • container: Add multi-stage builds, rootless support, healthcheck, and docker run command (@Copilot)
  • core: Add type system features - WorkflowState, RuleBuilder, newtypes, clinical types (@Copilot)
  • Integrate oxo-license, add auth/login system, export/cluster CLI subcommands (@Copilot)
  • core: Add comprehensive enhancements to oxo-flow-core (@Copilot)
  • Enhance scientific messaging, add gallery to README/docs, add CLI integration tests (@Copilot)
  • Add workflow gallery with 8 examples from basic to multi-omics, docs, and tests (@Copilot)
  • Remove all Snakemake references, establish innovation-first messaging (@Copilot)
  • Add validation, provenance, diagnostics, and DAG metrics improvements (@Copilot)
  • web: Add embedded frontend, new API endpoints, SSE, and base path support (@Copilot)
  • cli: Add Format, Lint, Profile, and Config subcommands (@Copilot)
  • core: Add resolve_includes, execution group validation, conditional execution, schema verification, and enhanced formatting (@Copilot)
  • Add scatter/gather, when, temp/protected output, input_function, retries, include, execution groups (@Copilot)
  • Add format module for .oxoflow validation, linting, and formatting (@Copilot)
  • Add request ID middleware, export endpoint, and CLI retry/timeout flags (@Copilot)
  • Add priority scheduling, clinical report sections, and CNV/MSI/TMB pipeline steps (@Copilot)
  • executor: Implement retry logic, timeout enforcement, and output validation (@Copilot)
  • core: Add error variants, apply_defaults, parallel_groups, rule validate (@Copilot)
  • cli: Enhance clean, init, add completions and verbose flag (@Copilot)
  • container: Add pixi support, extra_packages, compose file, and improved singularity defs (@Copilot)
  • web: Add CORS, run, version, and clean endpoints (@Copilot)
  • venus: Add VenusPipelineBuilder and .oxoflow generation (@Copilot)
  • web: Add full REST API with validate, parse, DAG, dry-run, and report endpoints (@Copilot)
  • report: Add Tera template engine and clinical report components (@Copilot)
  • Add cluster execution backends and executor checkpointing (@Copilot)
  • environment: Add setup/teardown commands, cache keys, and EnvironmentCache (@Copilot)
  • Initialize oxo-flow project with core library, CLI, web, and venus pipeline (@Copilot)

Maintenance#

  • Update Rust edition from 2021 to 2024 and fix clippy/fmt issues (@Copilot)

Other Changes#

  • Merge pull request #16 from Traitome/copilot/resolve-todo-issues (@ShixiangWang) (#16)
  • Add 303 implementation notes to TODO.md; update README, CONTRIBUTING docs (@Copilot)
  • Phase 7: Add 32 new tests (clinical types, builder, security, stress, format, container) (@Copilot)
  • Add validation and security features to oxo-flow-core (@Copilot)
  • Add core safety attributes: forbid(unsafe_code), CLI flags, #[must_use] (@Copilot)
  • Initial plan (@Copilot)
  • Merge pull request #13 from Traitome/copilot/optimize-ci-workflow-release-files (@ShixiangWang) (#13)
  • Merge pull request #14 from Traitome/copilot/collect-feedback-from-experts (@ShixiangWang) (#14)
  • Add comprehensive TODO.md with 300+ expert opinions from 30 simulated domain experts (@Copilot)
  • Merge pull request #11 from Traitome/copilot/create-oxo-flow-system-design (@ShixiangWang) (#11)
  • Merge pull request #10 from Traitome/copilot/create-oxo-flow-system-design (@ShixiangWang) (#10)
  • Add comprehensive TODO.md with 300 expert review items across 30 domain perspectives (@Copilot)
  • Merge pull request #9 from Traitome/copilot/implement-oxo-flow-system-design (@ShixiangWang) (#9)
  • Add TODO.md with 30 expert opinions (150 action items) (@Copilot)
  • Delete TODO.md (@ShixiangWang)
  • Merge pull request #8 from Traitome/copilot/update-workflow-gallery-and-documentation (@ShixiangWang) (#8)
  • Merge pull request #7 from Traitome/copilot/update-roadmap-implementation-again (@ShixiangWang) (#7)
  • Add ..Default::default() to all Rule constructors for new fields (@Copilot)
  • Initial plan (@Copilot)
  • Merge pull request #5 from Traitome/copilot/update-roadmap-and-implement-features (@ShixiangWang) (#5)
  • Replace README.md with comprehensive documentation (@Copilot)
  • Add binary targets for oxo-flow-web and venus, create dual license files (@Copilot)
  • Merge pull request #4 from Traitome/copilot/update-roadmap-and-release-process (@ShixiangWang) (#4)
  • Add TODO.md with 30-expert evaluation and action items (@Copilot)
  • Update (@ShixiangWang)
  • Merge pull request #3 from Traitome/copilot/implement-oxo-flow-core-library (@ShixiangWang) (#3)
  • Add paired_tumor_normal example, integration tests, and root package for workspace-level tests (@Copilot)
  • 30-expert evaluation: comprehensive upgrades - error variants, config defaults, DAG parallel groups, rule validation, executor retry/timeout, priority scheduling, clinical reports, Venus CNV/MSI/TMB, web export/request-ID, CLI retry/timeout flags, examples, integration tests - 231 tests passing (@Copilot)
  • Comprehensive multi-expert evaluation upgrades: executor env integration, Venus FilterMutectCalls/Strelka2, web API CORS/run/clean/version endpoints, container multi-stage builds, CLI clean/completions/init enhancements, Venus pipeline files, 200 tests passing (@Copilot)
  • Add comprehensive tests for web, venus, and environment modules (@Copilot)
  • Add FilterMutectCalls, Strelka2, known_sites to Venus pipeline (@Copilot)
  • Add environment integration to executor and retry/timeout config fields (@Copilot)
  • Merge pull request #2 from Traitome/copilot/update-roadmap-with-expert-feedback (@ShixiangWang) (#2)
  • Phase 7-8: Venus pipeline builder, CLI status/clean commands, enhanced example workflow, ROADMAP update (@Copilot)
  • Merge pull request #1 from Traitome/copilot/add-core-library-oxo-flow (@ShixiangWang) (#1)
  • Initial commit (@ShixiangWang)

Testing#

  • Add 30 CLI binary integration tests for oxo-flow, venus, and oxo-flow-web (@Copilot)