Changelog#
All notable changes to oxo-flow are documented in this file.
The format follows Keep a Changelog and this project adheres to Semantic Versioning.
Changelog entries are automatically generated by git-cliff from conventional commit messages.
[Unreleased]#
Features#
- engine: Runtime disk-pressure monitoring —
[engine] min_free_disk/reclaim_free_diskthresholds drive a Normal → Reclaim → Hold → abort ladder; completed temporary outputs are reclaimed mid-run (tombstoned, cascade-up on demand) and parked holds abort after a grace window (#843) - engine: Reclaim-dependent race fix — mid-run reclaim now requires each dependent to be checkpoint-completed and its declared outputs still on disk; a stale-completed dependent with missing outputs re-executes and keeps its inputs (
rule_outputs_existshared helper in core, reused by the CLI replay gate) (#843) - engine: Reclaim/sweep blind spots for
output_patternproducers — post-run temporary cleanup now expands wildcard outputs per recorded instance (only paths that ran and completed, with a warning instead of a silent no-op), the sweep detects consumers structurally (pattern producers register no DAG edges), and the mid-run reclaim gate accepts pattern-typed dependents whose recorded instance paths exist (#844) - engine: Reclaim gate resolves pattern-dependent domains by template name —
output_pattern_domainsare recorded under the producer's expansion template, so the mid-run gate now looks dependents up the same way (config-expanded pattern text never matched, which had voided the gate); a dependent with no recorded domains is treated as not proven done and blocks reclaim of its producer's inputs (#843) - engine: Spawn watchdog no longer raises false #685 ERRORs for queued rules — a Running rule still waiting in the resource pool is reported as a benign one-shot WARN (the scheduler's 60s blockage lines already carry holder/FIFO detail); the ERROR is reserved for rules not queued in the pool with no child process, the genuine lost-wakeup signature (#847)
- engine:
duration_msmeasures execution, not enqueue-to-completion —started_atis stamped only after the rule acquires its resources, and the queue wait is preserved separately in a newenqueued_atrecord field (mirroring the cluster driver'squeue_wait_secssplit), so parked rules no longer inflate reported runtimes (#850) - cli:
statussurfaces snapshot freshness — the human output prints oneState as of <N>s ago (checkpoint written <time> local)line under the banner (aWarning:variant past 5 minutes), and--jsongainscheckpoint_mtime(RFC 3339) plussnapshot_age_secs, so the invisible checkpoint-flush lag on live runs can no longer be mistaken for a stalled pipeline (#849) - cli: Pixi-manifest preflight in
validate/plan/dry-run — a rule's declared pixi manifest is resolved against the workflow directory and existence-checked up front, reported as errorE019(skipped undervalidate --as-include); dry-run's--jsongainsenv_manifest_issues; andrun's environment-readiness abort now splits its remediation — manifest not found → create/correct it at the resolved path, backend binary missing → install advice (#848)
0.23.1 — 2026-10-08#
Bug Fixes#
- preflight: SCI-AGG-RACE per-dimension output keying (#829) (#834) (@ShixiangWang) (#834)
- fingerprint: Fold file-backed environment content into rule fingerprints (#827) (@ShixiangWang) (#827)
- engine: One dup-ownership warning per parse instead of per sample (#825) (@ShixiangWang) (#825)
- config: Dedup identical / error on conflicting duplicate pair & group ids across sources (#824) (@ShixiangWang) (#824)
- vscode: Keep Report Issue URL verbatim through openExternal (#822) (@ShixiangWang) (#822)
CI/CD#
- Skip validation jobs whose subtree did not change (PR/push only) (#821) (@ShixiangWang) (#821)
Documentation#
- run: Document #826 backend preflight abort and #825 dup-ownership warning (#840) (@ShixiangWang) (#840)
- Document environment-file content in fingerprints and pixi cache key (#828) (@ShixiangWang) (#828)
- Drop title and frame heading from highlights (@ShixiangWang)
- Add CNS cover letter highlights (@ShixiangWang)
Features#
- workdir: Auto-link tool-convention index sidecars into workdir (#837) (#839) (@ShixiangWang) (#839)
- run: Link workflow-repo sources into workdir as symlinks (#837) (#838) (@ShixiangWang) (#838)
- run: Info hint when a succeeded rule's declared log is empty (#832) (#836) (@ShixiangWang) (#836)
- cli:
plansubcommand alias of dry-run (#831) (#835) (@ShixiangWang) (#835) - lint: W034 for input/output placeholders that never substitute (#830) (#833) (@ShixiangWang) (#833)
- run: Preflight environment backend availability before executing anything (#826) (@ShixiangWang) (#826)
0.23.0 — 2026-10-03#
Bug Fixes#
- vscode: Audit batch — publishing reliability, first-run UX, report issue (#817) (@ShixiangWang) (#817)
CI/CD#
- Cut wasted compute — rust-cache, docker layering+cache, dedup builds (#818) (@ShixiangWang) (#818)
Documentation#
- Mark VSCE_PAT as provisioned and align the PAT recipe (#816) (@ShixiangWang) (#816)
- skill: Point to the VS Code extension in the entry-point table (#815) (@ShixiangWang) (#815)
Features#
- vscode: AI generation can use the editor language model (#820) (@ShixiangWang) (#820)
- vscode: Graph format quick pick + auto-open graph after run (#809) (#814) (@ShixiangWang) (#814)
- vscode: Format-on-save setting (#808) (#813) (@ShixiangWang) (#813)
- vscode: Run CodeLens on [[rules]] headers (#807) (#812) (@ShixiangWang) (#812)
- vscode: #806 — Get Started walkthrough for first .oxoflow setup (#811) (@ShixiangWang) (#811)
0.22.0 — 2026-10-03#
Bug Fixes#
- ci: Commit the VS Code extension manifests during sync-version (#810) (@ShixiangWang) (#810)
- eval: Make the gold set review-ready — judge fidelity, consistency linter, verified repairs (#802) (@ShixiangWang) (#802)
Features#
- vscode: Show Run Status + Clean Outputs commands, editor-title buttons (#805) (@ShixiangWang) (#805)
- vscode: Task kind field, task-based AI generation, resource-scoped executable path (#804) (@ShixiangWang) (#804)
- vscode: VS Code extension with release-time VSIX publishing (Open VSX + Marketplace) (#803) (@ShixiangWang) (#803)
0.21.2 — 2026-10-02#
Bug Fixes#
- dag: Keep optional="any" rules in the plan when producers are when-gated false (#801) (@ShixiangWang) (#801)
- ai: Parse prompt-mandated headings in --ai-recover responses (#799) (@ShixiangWang) (#799)
- environment: Mamba backend wrap parity with conda — PATH re-export + conda-fallback --no-capture-output (#798) (@ShixiangWang) (#798)
- bundle: Include sub-workflow files in published bundles (#797) (@ShixiangWang) (#797)
- cli: Canonicalize hyphen-spelled config overrides onto declared keys (#794) (#795) (@ShixiangWang) (#795)
- validate: E018 — reject unrecognized bare identifiers in when conditions (issue #791) (#792) (@ShixiangWang) (#792)
- web: Is_configured now reflects env-discovered AI providers (#789) (@ShixiangWang) (#789)
- web: /api/auth/me does not recognize X-API-Key credentials (#788) (@ShixiangWang) (#788)
- core: Diff_workflows misses script field changes (#787) (@ShixiangWang) (#787)
- web: /api/metrics uptime_secs reported HOST boot time, not process uptime (#786) (@ShixiangWang) (#786)
- run: Fail fast on missing external source inputs — never exit 0 from stale credit (#782) (@ShixiangWang) (#782)
- template: Copy conda env files referenced by gallery templates 04-15 (#781) (@ShixiangWang) (#781)
- preflight: SCI-AGG-RACE missed races whose outputs use {config.*} paths (#779) (@ShixiangWang) (#779)
- docs: DAG edge inference is best-effort broad, not exact-string only (#776) (@ShixiangWang) (#776)
- report: Surface ScanStats::unreadable in Scan Notes (#774) (#775) (@ShixiangWang) (#775)
Documentation#
- publish: List included sub-workflow files in the bundle-contents inventory (#800) (@ShixiangWang) (#800)
- reference: Clarify named-IO placeholders + --samples implicit group in wildcards.md (@ShixiangWang)
- Document hyphen/underscore override-key canonicalization (issue #794) (#796) (@ShixiangWang) (#796)
- reference: Document E018 — when conditions reject unrecognized bare identifiers (#793) (@ShixiangWang) (#793)
- ai: Clarify translate draft-id vs saved pipeline_id semantics (#790) (@ShixiangWang) (#790)
- gallery-03: Show real validate output with expected missing-input warning (#785) (@ShixiangWang) (#785)
- gallery-16: All-samples-below-depth rarefaction failure + remedy (#784) (@ShixiangWang) (#784)
- run: Document the missing-source fail-fast gate (#783) (@ShixiangWang) (#783)
- Fix three stale output samples verified against live runs (#777) (@ShixiangWang) (#777)
Maintenance#
- knowledge: Automatic knowledge refresh 2026-10-01 (#780) (@ShixiangWang) (#780)
0.21.1 — 2026-10-01#
Bug Fixes#
- web: Abort-killed sibling rules surface as Skipped, not Pending forever (issue #767) (#769) (@ShixiangWang) (#769)
- web: Surface rule_runs stdout_tail alongside stderr_tail (issue #765) (#766) (@ShixiangWang) (#766)
- web: Make run reports failure-aware (issue #759) (#764) (@ShixiangWang) (#764)
- web: Surface checkpoint rule_runs exit codes and stderr tails (issue #758) (#763) (@ShixiangWang) (#763)
- core,web: Reserved [[values]] names rejected at parse; retry plan honest about pre-execution failures (issue #760) (#762) (@ShixiangWang) (#762)
- core,cli: Tolerate expand_inputs-baked absent inputs; clear stale outputs of failed rules (issues #757, #756) (#761) (@ShixiangWang) (#761)
- preflight: Drop unverifiable 'far inferior' quote in SCI-MUTECT2-TUMOR-ONLY (#755) (@ShixiangWang) (#755)
- bundle: Fall back to --workdir for sample/pairs discovery (#751) (#754) (@ShixiangWang) (#754)
- executor: Unique staged filename for checkpoint saves (#750) (@ShixiangWang) (#750)
- executor: Clear the spawn-time running mark on terminal skips (issue #747) (#748) (@ShixiangWang) (#748)
- web: Bound the remaining whole-log reads; status prefers the persisted running set (issue #734) (#746) (@ShixiangWang) (#746)
- core,cli: One memory grammar and explicit PBS/SGE units; RSS and split.n alignment (issue #740) (#745) (@ShixiangWang) (#745)
- core: One shared walltime parser across local executor and all cluster backends (issue #737) (#744) (@ShixiangWang) (#744)
- When-awareness round 2 across deep_check, config_impact, lint, and the web surface (issue #739) (#743) (@ShixiangWang) (#743)
- web: Quota collector counts [rules.resources].memory via effective_memory (issue #738) (#741) (@ShixiangWang) (#741)
- web: Stat-first gates on background pollers and startup recovery (issue #735) (#736) (@ShixiangWang) (#736)
- core: Deep-check skips when-gated-off rules via the engine evaluator (issue #717) (#731) (@ShixiangWang) (#731)
- web: Zip download skips non-regular files; mkfifo regression tests (#714 addendum) (#729) (@ShixiangWang) (#729)
- web: Diagnostics and report endpoints read a bounded execution.log tail (issue #710) (#727) (@ShixiangWang) (#727)
- core: LSF walltime renders verbatim when unparseable; memory shares the engine parser (issues #715, #716) (#726) (@ShixiangWang) (#726)
- web: Harden diagnostics pattern matching, share table with AI monitor (issues #708, #709) (#725) (@ShixiangWang) (#725)
- safety: Stat-first regular-file gates at residual read sites (#714) (#724) (@ShixiangWang) (#724)
- core: Stat-first is_regular_file gates in result.rs (issue #713) (#723) (@ShixiangWang) (#723)
- web: Build web DAGs with config-expanded rules (issue #707) (#721) (@ShixiangWang) (#721)
- cli: Resume banner reconciles when-gated-off rules (issue #690) (#711) (@ShixiangWang) (#711)
- core: Stat-first gate on when-atom file readers — FIFO would hang the scheduler loop (#706) (@ShixiangWang) (#706)
- checkpoint: #690 — when-gated-off rules no longer display as Failed (#699) (@ShixiangWang) (#699)
- readiness: Skip when-false rules — their inputs are phantom missing files (#698) (@ShixiangWang) (#698)
- web: Report run memory estimates in true MB via the engine parser (#697) (@ShixiangWang) (#697)
- checkpoint: Never open special files for checksums — FIFO hang at startup (#695) (#696) (@ShixiangWang) (#696)
- env: Classify conda link-stage failures before solver conflicts in setup hints (#694) (@ShixiangWang) (#694)
- core: Persist bounded stdout_tail in rule_runs — reports/AI see stdout too (#692) (@ShixiangWang) (#692)
Documentation#
- web-api: Align status/report/retry entries with merged behavior (#762/#766/#767/#769) (#770) (@ShixiangWang) (#770)
- status: Align when-gated-off output sample with CLI + fix run.md anchor (#753) (@ShixiangWang) (#753)
- publish: Correct bundle data-path semantics + parse-time discovery hint (#752) (@ShixiangWang) (#752)
- reference: Align reference pages with verified engine behavior (#722) (@ShixiangWang) (#722)
- tutorials: Fix two getting-started drift points verified against v0.21.0 (#718) (@ShixiangWang) (#718)
- commands: Audit-fix 18 reference pages against CLI implementation (#712) (@ShixiangWang) (#712)
- cli: Fix stale join() doc comment in config_comments (@ShixiangWang)
- Site-content audit round — verify claims against engine source and live runs (#704) (@ShixiangWang) (#704)
- guide: Ai session dir resolution + module cache @
naming (@ShixiangWang) - guide: Report.md auto-discovered filename follows format + MultiQC note (#703) (@ShixiangWang) (#703)
- guide: Correct metro section-order claim in graph.md (#702) (@ShixiangWang) (#702)
- guide: Align cluster scheduler strings and LSF memory example with engine (#701) (@ShixiangWang) (#701)
- guide: When-gated-off rules are skips, not failures — align all pages with #690 fix (#700) (@ShixiangWang) (#700)
Features#
- core: Configurable stdout/stderr tail size, default 64 KiB (#720) (@ShixiangWang) (#720)
Maintenance#
- deps: Bump utoipa from 5.5.0 to 6.0.0 (#773) (@dependabot[bot]) (#773)
- deps: Bump the cargo-minor-patch group with 3 updates (#772) (@dependabot[bot]) (#772)
- deps: Bump the npm-minor-patch group in /frontend with 5 updates (#771) (@dependabot[bot]) (#771)
- frontend: Bump brace-expansion past 3 HIGH DoS advisories (issue #732) (#733) (@ShixiangWang) (#733)
0.21.0 — 2026-09-28#
Bug Fixes#
- core: Recognize GNU-permuted rm flags in any position, not only trailing (#689) (@ShixiangWang) (#689)
- core: Spawn watchdog, authoritative running-set persistence, bounded setup-lock wait (#685) (#686) (@ShixiangWang) (#686)
- core: Harden shell-safety validator (short-circuit, permuted rm, symlink escape) (#674) (@ShixiangWang) (#674)
- cli: Scripts can read exit codes — validate/lint return Err, orphan-clean/touch propagate failures, bundle entrypoint contained (#681) (@ShixiangWang) (#681)
- web: Search visibility in SQL, webhook secret sealed, session cleanup wired; ci gains eval-tests (#684) (@ShixiangWang) (#684)
- frontend: Close SSE orphan leak, escape guided TOML, surface structured errors, client-layer robustness (#680) (@ShixiangWang) (#680)
- core: Mirror snapshot skips in missing_input_patterns, mode-aware remote optional staging, log events.jsonl write failures (#679) (@ShixiangWang) (#679)
- ai: Redirect-screened MCP client, credential precedence, empty-truncation guard, UTF-8-safe streaming, registry self-writes (#678) (@ShixiangWang) (#678)
- web: Remote runs honor cancellation and tolerate transient poll errors (#677) (@ShixiangWang) (#677)
- web: Six audit fixes — share expiry bound, resume guard, pagination contract, oauth token leak, zip disposition (#676) (@ShixiangWang) (#676)
- executor: Rm-validator stops at subshell close paren — unblocks varlociraptor get_known_variants (#675) (@ShixiangWang) (#675)
- core: Honor optional inputs in manifest snapshotting and detection (#633) (#638) (@ShixiangWang) (#638)
- web: Probe and expose the engine CLI version for run execution (#579) (#636) (@ShixiangWang) (#636)
- Whitelist workflow-file [ai] section so the documented activation path works (#634) (#635) (@ShixiangWang) (#635)
- ci: MD032 lint config must be a real plain-.jsonc file (#631) (@ShixiangWang) (#631)
- web: UI polish batch from browser audit (#578) (#630) (@ShixiangWang) (#630)
- report: Render all ReportContent variants in the built-in template (#629) (@ShixiangWang) (#629)
- web: Refetch run detail panes on terminal SSE events (#577) (#628) (@ShixiangWang) (#628)
- core: S3 backend — multipart uploads, timeouts, typed 404s (#575) (#627) (@ShixiangWang) (#627)
- web: Accept hostname binds in the standalone binary (#573) (#625) (@ShixiangWang) (#625)
- webhook: Strip credentialed URL from request errors, drop redirect replay (#574) (#626) (@ShixiangWang) (#626)
- web: End SSE streams on shutdown so graceful drain completes (#572) (#624) (@ShixiangWang) (#624)
- deploy: Make Docker CMD/healthcheck honor compose env, fix PostgreSQL comment (#570) (#622) (@ShixiangWang) (#622)
- web: Share serve/desktop startup steps with the standalone binary (#569) (#621) (@ShixiangWang) (#621)
- engine+deploy: W033 empty-scatter semantics (#616); compose env passthrough (#568) (#620) (@ShixiangWang) (#620)
- W033 empty-scatter semantics (#616), quality gates (#557), lock hygiene (#556), e2e fixes (#619) (@ShixiangWang) (#619)
- frontend: Infinite recursion in non-secure-context uuid fallback (#608 follow-up) (#612) (@ShixiangWang) (#612)
- checkpoint: Empty config-optional input must not manifest the whole workdir (#611) (@ShixiangWang) (#611)
- ci: :latest promotion hard-fails when the latest-release lookup fails (#552) (#610) (@ShixiangWang) (#610)
- frontend: Chat regenerate works; non-secure-context UUIDs; spec-compliant SSE parser (#550) (#608) (@ShixiangWang) (#608)
- frontend: 401 redirects to login; destructive-action failures surface (#549) (#607) (@ShixiangWang) (#607)
- frontend: DAG auto-layout derives parentIds from actual edges (#548) (#606) (@ShixiangWang) (#606)
- frontend: Close the three SPA state races (#547) (#605) (@ShixiangWang) (#605)
- frontend: Enable TypeScript strict mode (#546) (#604) (@ShixiangWang) (#604)
- web: GET /api/ai/config/user returns the stored row incl. advanced fields (#545) (#603) (@ShixiangWang) (#603)
- ai: Parse_verdict fail-safe; private capped session archives; full from-url grounding (#544) (#602) (@ShixiangWang) (#602)
- ai: A length-truncated completion feeds the retry loop, never ships (#543) (#601) (@ShixiangWang) (#601)
- ai: Fold the empty-round nudge into the Tool message (#542) (#600) (@ShixiangWang) (#600)
- cli: Six contract fixes — UTF-8 slice, flag precedence, local-source protection, workdir-scoped --output, ai --json document, ANSI-free stderr (#541) (#599) (@ShixiangWang) (#599)
- cli: Batch/clean exit codes reflect failures; SIGINT emits the JSON summary and webhook (#540) (#598) (@ShixiangWang) (#598)
- cli: AI narration goes to stderr; suppressed under --json (#539) (#597) (@ShixiangWang) (#597)
- cli: Resume honors the explicit checkpoint path argument (#538) (#596) (@ShixiangWang) (#596)
- expand: Escape the wrapper quote in baked when predicates (#537) (#595) (@ShixiangWang) (#595)
- cluster: Serialize driver events.jsonl/status.json with serde_json (#536) (#594) (@ShixiangWang) (#594)
- container: Pre-build inline conda specs under the runtime env name (#535) (#593) (@ShixiangWang) (#593)
- security: Quote client-controlled paths in generated shell; close backend boundary gaps (#534) (#592) (@ShixiangWang) (#592)
- checkpoint: Config_impact covers output_pattern/expand_inputs; per-group injected keys only (#533) (#591) (@ShixiangWang) (#591)
- environment: Fold spec content hash into file-backed env cache keys (#532) (#590) (@ShixiangWang) (#590)
- expand: When-only pair/group scope still fans out per combo (#531) (#589) (@ShixiangWang) (#589)
- diagnostics: Shared pair/group wildcard vocabulary; full fresh-wildcard registry (#530) (#588) (@ShixiangWang) (#588)
- diagnostics: Widen detector scan fields to the runtime expansion surface (#529) (#587) (@ShixiangWang) (#587)
- checkpoint: Canonical serialization for output_pattern_domains (#528) (#586) (@ShixiangWang) (#586)
- executor: Move bulk synchronous I/O off the tokio workers (#527) (#585) (@ShixiangWang) (#585)
- executor: Retry attempts accumulate output with an attempt boundary marker (#526) (#584) (@ShixiangWang) (#584)
- executor: Gate abort demotion on kill-snapshot membership; record signal evidence in SIGINT teardown (#525) (#583) (@ShixiangWang) (#583)
- executor: Kill auxiliary children on abort; blocking-pool kill sweep with post-abort re-snapshot (#524) (#582) (@ShixiangWang) (#582)
- security: Enforce rule field validation on the run path; overflow-safe memory parsing (#523) (#581) (@ShixiangWang) (#581)
- security: One-time SSE tickets replace ?token= in event-stream URLs (#522) (#567) (@ShixiangWang) (#567)
- security: Sandbox data/analyze, perceive, and validate base_dir to the user workspace (#521) (#566) (@ShixiangWang) (#566)
- security: Add logout + cascade sessions/API keys on user deletion (#520) (#565) (@ShixiangWang) (#565)
- security: Close six route-level authz/quota gaps (#519) (#564) (@ShixiangWang) (#564)
- security: Scope AI read_file to workspace; SSRF-screen MCP endpoints; readOnlyHint advisory (#518) (#562) (@ShixiangWang) (#562)
- security: Never return cluster ssh_key; seal at rest; admin-gate probe (#517) (#561) (@ShixiangWang) (#561)
- security: Pin session identity to canonical users.id; fail-closed role resolution (#516) (#560) (@ShixiangWang) (#560)
- security: Enforce ownership on /api/ai/explain, /interpret, /optimize (#515) (#559) (@ShixiangWang) (#559)
- security: Parse individually-quoted rm operands instead of blanket-rejecting (#514) (@ShixiangWang) (#514)
- abort: Distinguish abort-killed siblings from self-caused failures (issue #498) (#513) (@ShixiangWang) (#513)
- preflight: Strip shell comments before placeholder scans + suppress dir-output aggregation warning (#512) (@ShixiangWang) (#512)
- report: Make --plan workflow-discovery error non-circular (#505) (@ShixiangWang) (#505)
- serve: Reject unknown --mode values at parse time (#504) (@ShixiangWang) (#504)
- cluster: Ask squeue for long-form states (%T) + accept compact forms (#500) (@ShixiangWang) (#500)
- validate: Skip missing-input checks for when-gated-off rules (issue #493) (#497) (@ShixiangWang) (#497)
- executor: Name fatal signals in stderr + honest Cancelled records for abort-killed siblings (#496) (@ShixiangWang) (#496)
- ai: Honor OLLAMA_HOST as the ollama endpoint, not just a detection signal (#495) (@ShixiangWang) (#495)
- ai: Warn on unrecognized OXO_FLOW_AI_PROVIDER instead of silent fallthrough (#494) (@ShixiangWang) (#494)
- environment: Don't bind-mount shell-residue root tokens ('//') (#492) (@ShixiangWang) (#492)
- run-log: Capture invalidation/adoption diagnostics in the run log (issue #484) (#490) (@ShixiangWang) (#490)
- checkpoint: Don't clobber real benchmarks on 'outputs up-to-date' skip (issue #484) (#483) (@ShixiangWang) (#483)
- result: Resolve {config.*} in scan_run_outputs (issue #467 family) (#486) (@ShixiangWang) (#486)
- determinism: Sort the remaining user-visible nondeterministic outputs (issue #471) (#480) (@ShixiangWang) (#480)
- validate: Resolve {config.*} in W020/E010 missing-input checks (issue #467) (#478) (@ShixiangWang) (#478)
- modules: Resolve {config.*} in --module closure and include-contract validation (issue #468) (#479) (@ShixiangWang) (#479)
- validate: Build validate/lint DAGs with the parsed config values (issue #466) (#477) (@ShixiangWang) (#477)
- dag: Existence-aware -t closure — pre-built inputs survive when-false producers (#476) (@ShixiangWang) (#476)
- protected_output: Honor shell-glob patterns in both enforcement paths (issue #473) (#475) (@ShixiangWang) (#475)
- diagnostics: Independent v0.20.1..HEAD audit — engine-exact SCI-AGG-RACE, config-routed W033, deterministic provenance artifacts (#472) (@ShixiangWang) (#472)
- ai: Zero-config auto-detection + empty-key guards + unified Claude key chain (#465) (@ShixiangWang) (#465)
- preflight: #443 — plan-time warning for sample-fanned aggregation rules (#464) (@ShixiangWang) (#464)
- gallery: 12 cohort — SILENT stringency + BAM indexing for GATK chain (#449) (@ShixiangWang) (#449)
- gallery: Plain-bwa read-group tab handling + index BAM for mosdepth (11) (#448) (@ShixiangWang) (#448)
- info: Resolve {config.*} in input/output dirs before top-level extraction (#460) (@ShixiangWang) (#460)
- format: Deterministic key ordering + stop config_meta leaking into formatted TOML (#459) (@ShixiangWang) (#459)
- gallery: Real-path rmarkdown render + TOML escape gotcha in gallery 09 (#450) (@ShixiangWang) (#450)
CI/CD#
- Add cargo-deny and gitleaks quality gates, fix macro bench reliability metric (#618) (@ShixiangWang) (#618)
- Close four gate gaps — checksums pipefail+assert, deploy-smoke wired, Playwright CI reuse/visibility, SPA freshness check (#555) (#615) (@ShixiangWang) (#615)
Documentation#
- Fix four audit drifts — provider auto-detect default, desktop crate, env table, subcommand count (#682) (@ShixiangWang) (#682)
- ai: Drop duplicated sentence fragment left by #620 doc-link edit (#632) (@ShixiangWang) (#632)
- deploy: Correct TRUSTED_PROXY and weak-setup claims, add proxy limiter guidance (#571) (#623) (@ShixiangWang) (#623)
- Accuracy batch — OAuth env name, serve.md table, MD032 sweep, README/AGENTS/knowledge numbers (#551) (#609) (@ShixiangWang) (#609)
- web: Fix pause from_rule claim + document undo/redo JSON body (#511) (@ShixiangWang) (#511)
- tutorials: Env list/check stream note + binary size correction (#510) (@ShixiangWang) (#510)
- how-to: Correct conda wrapping form + init scaffold file list (#508) (@ShixiangWang) (#508)
- guide: Reference-audit corrections (batch exit codes, lint --quiet, dry-run warning, glossary S007/S008, web-api credentials, 31 subcommands) (#506) (@ShixiangWang) (#506)
- cluster: Cluster logs does not fall back to scontrol on sacct-less sites (#502) (@ShixiangWang) (#502)
- cluster: Pin the working directory in SLURM/PBS/SGE example scripts (#501) (@ShixiangWang) (#501)
- gallery: Demo-data provisioning + live-run results for 04/10 (#499) (@ShixiangWang) (#499)
- dag-engine: Drop removed detect_output_collisions — point at lint W033 (#491) (@ShixiangWang) (#491)
- Final audit nits — gpus wording, knowledge counts in-file, gallery-07 index sidecars (#488) (@ShixiangWang) (#488)
- troubleshooting: Fix conditional-workflow link depth — mkdocs --strict failed (#487) (@ShixiangWang) (#487)
- format: Annotate parsed-but-unenforced fields honestly (issue #469) (#481) (@ShixiangWang) (#481)
- Add Engineering Invariants to AGENTS.md (#474) (@ShixiangWang) (#474)
- temp_output: Rustdoc states the failure-only contract (#456) (#463) (@ShixiangWang) (#463)
- gallery-16: Live-tested caveats — sklearn classifier gate, metadata format, DADA2 IUPAC trap (#452) (@ShixiangWang) (#452)
- gallery-07: VQSR zero-variance failure mode from live test (#453) (@ShixiangWang) (#453)
- commands: Live-verified corrections for status/validate/lint/run/touch (#461) (@ShixiangWang) (#461)
- gallery: Input-provisioning Run sections + strandedness note for multiomics (#451) (@ShixiangWang) (#451)
- resource-budget: State cluster-path-only enforcement + max_jobs gap (#454) (@ShixiangWang) (#454)
- reference: Refresh bioconda knowledge counts + document EnvironmentSpec gpus semantics (#447) (@ShixiangWang) (#447)
- format: Mark pipe/input_function/checksum/format_hint as parsed-but-unimplemented (#446) (@ShixiangWang) (#446)
- variant-calling: Add reference-prep section (.dict) and declare GATK .tbi outputs (#445) (@ShixiangWang) (#445)
- first-workflow: Fix per-sample aggregation race — key multiqc to one sample (#444) (@ShixiangWang) (#444)
Features#
- #469: Resolve every documented-but-unenforced field — implement, remove, or finalize by design (#507) (@ShixiangWang) (#507)
- validate: Run the raw-file schema pass (S001–S006) on oxo-flow validate (#482) (@ShixiangWang) (#482)
- protected_output: Enforce protection in failure invalidation and clean (#462) (@ShixiangWang) (#462)
Maintenance#
- Aws-legacy-tripwire gate — self-enforcing advisory exemption (#688) (@ShixiangWang) (#688)
- Document AWS legacy-client advisory exposure and align deny.toml ignores (#683) (@ShixiangWang) (#683)
- Dependency hygiene and version single-sourcing (#556) (#617) (@ShixiangWang) (#617)
- dag: Remove the dormant detect_output_collisions check (W033 supersedes it) (#485) (@ShixiangWang) (#485)
Other Changes#
- Flag output collisions between rules writing the same path(s) (W033) (#455) (@ShixiangWang) (#455)
-
Resolve featureCounts strand false positive, dry-run --cache-dir, pilot summary dup (#442) (@ShixiangWang) (#442)#
Refactoring#
- tests: Extract tests/common — one canonical workspace_bin/spawn_server (#553) (#613) (@ShixiangWang) (#613)
Styling#
- Cargo fmt (#503) (@ShixiangWang) (#503)
Testing#
- web: Cover serve entrypoint + share base-path normalization (#672) (#687) (@ShixiangWang) (#687)
- web: OAuth callback negative paths, PG 503 contract, security-route negatives (#554) (#614) (@ShixiangWang) (#614)
- ancient: Pin explicit filetimes — write order is not mtime order on coarse-granularity filesystems (#509) (@ShixiangWang) (#509)
0.20.1 — 2026-09-24#
Bug Fixes#
- security: Harden workdir-aware rm -rf validation + env check display + zstd dedup (#440) (@ShixiangWang) (#440)
- dx: Operator-facing clarity — banner TTY gate, env check resolved binary, self-explanatory shell warnings (#439) (@ShixiangWang) (#439)
- checkpoint: #432 — staleness reasons, honest dry-run headline, status --workdir, touch overrides (#438) (@ShixiangWang) (#438)
- config: Discover input_groups files when a config override is absolute (#425) (#431) (@ShixiangWang) (#431)
- deps: Sqlx 0.9 — AssertSqlSafe audit annotations for dynamic SQL (#422) (@ShixiangWang) (#422)
- benches: Criterion 0.8 deprecates black_box — use std::hint::black_box (#423) (@ShixiangWang) (#423)
Documentation#
- Fix SKILL site URL, drop stale caveats, add RHEL graphviz install (#424) (@ShixiangWang) (#424)
Maintenance#
- deps: Bump the npm-minor-patch group across 1 directory with 12 updates (#417) (@dependabot[bot]) (#417)
- deps: Bump zstd from 0.13.3 to 0.14.0 (#421) (@dependabot[bot]) (#421)
- deps: Bump tower-http from 0.6.11 to 0.7.1 (#413) (@dependabot[bot]) (#413)
- deps: Bump bcrypt from 0.17.1 to 0.19.3 (#420) (@dependabot[bot]) (#420)
- deps: Bump criterion from 0.5.1 to 0.8.2 (#419) (@dependabot[bot]) (#419)
- deps: Bump the cargo-minor-patch group across 1 directory with 4 updates (#418) (@dependabot[bot]) (#418)
- deps: Bump toml_edit from 0.22.27 to 0.25.15+spec-1.1.0 (#408) (@dependabot[bot]) (#408)
- deps-dev: Bump @types/node from 24.13.2 to 26.6.2 in /frontend (#407) (@dependabot[bot]) (#407)
- deps: Group minor+patch updates in dependabot, ignore typescript 7 (@ShixiangWang)
Other Changes#
- Accept empty-string config overrides and enrich CLI/samplesheet errors (issue #430) (#437) (@ShixiangWang) (#437)
- Allow rm -rf of workdir-internal paths with absolute out_dir (issue #428) (#436) (@ShixiangWang) (#436)
- Remove --prune from conda/mamba env update fallbacks (issue #429) (#435) (@ShixiangWang) (#435)
- Fix relative-path resolution against --workdir (issue #427) (#434) (@ShixiangWang) (#434)
0.20.0 — 2026-09-23#
Bug Fixes#
- deps: Complete sha2 0.11 migration — hmac 0.13, sha1 0.11, hex::encode digests (#406) (@ShixiangWang) (#406)
- cluster: Real-scheduler conformance — LSF directives, OpenPBS arrays/polling + verification harness (#356) (@ShixiangWang) (#405)
- ci: Pin release-path checkouts to the synced commit and deploy versioned docs on dispatch releases (#392) (@ShixiangWang) (#392)
Documentation#
- real-cluster-matrix: Consolidate the setup lessons from the campaign (@ShixiangWang)
Maintenance#
- deps: Slow dependabot down to monthly checks (@ShixiangWang)
- deps-dev: Bump @playwright/test in /frontend (#404) (@dependabot[bot]) (#404)
- deps: Bump crc32fast from 1.5.1 to 1.5.2 (#401) (@dependabot[bot]) (#401)
- deps: Bump sysinfo from 0.38.4 to 0.39.6 (#400) (@dependabot[bot]) (#400)
- deps: Bump react-router-dom from 7.18.3 to 7.18.4 in /frontend (#399) (@dependabot[bot]) (#399)
- deps: Bump md-5 from 0.10.6 to 0.11.0 (#397) (@dependabot[bot]) (#397)
- deps: Bump @codemirror/view from 6.43.1 to 6.43.12 in /frontend (#396) (@dependabot[bot]) (#396)
- deps: Bump uuid from 1.26.0 to 1.26.1 (#395) (@dependabot[bot]) (#395)
- knowledge: Automatic knowledge refresh 2026-09-16 (#394) (@ShixiangWang) (#394)
Refactoring#
- Dedupe helpers, slim dead code, docs+UI/i18n consistency pass (@ShixiangWang)
0.19.0 — 2026-09-16#
Documentation#
- Full-audit remediation + fix flaky web test DB init (#379) (@ShixiangWang) (#379)
Maintenance#
- deps: Bump tera from 1 to 2 (#391) (@ShixiangWang) (#391)
- deps: Bump aes-gcm from 0.10 to 0.11 (#390) (@ShixiangWang) (#390)
- deps: Bump lucide-react from 1.18.0 to 1.45.0 in /frontend (#389) (@dependabot[bot]) (#389)
- deps: Bump async_zip from 0.0.17 to 0.0.19 (#388) (@dependabot[bot]) (#388)
- deps: Bump @xyflow/react from 12.11.3 to 12.11.6 in /frontend (#387) (@dependabot[bot]) (#387)
- deps: Bump base64 from 0.22.1 to 0.23.1 (#386) (@dependabot[bot]) (#386)
- deps-dev: Bump eslint from 10.5.0 to 10.10.0 in /frontend (#385) (@dependabot[bot]) (#385)
- deps: Bump nix from 0.30.1 to 0.31.3 (#384) (@dependabot[bot]) (#384)
- deps: Bump react-router-dom from 7.18.2 to 7.18.3 in /frontend (#383) (@dependabot[bot]) (#383)
- deps-dev: Bump globals from 17.6.0 to 17.12.0 in /frontend (#381) (@dependabot[bot]) (#381)
- deps: Bump actions/checkout (#378) (@dependabot[bot]) (#378)
- deps: Add cargo + npm ecosystems to dependabot (#377) (@ShixiangWang) (#377)
- ci: Bump all actions to node24 majors + add dependabot (#376) (@ShixiangWang) (#376)
0.18.2 — 2026-09-15#
Bug Fixes#
- engine: #374 wildcard/when-gate semantics + #375 UX (lint noise, warn flood, input_groups) (@ShixiangWang)
- gallery: 08 bismark chain — --basename/--multicore conflict + dedup output path (#357) (#372) (@ShixiangWang) (#372)
- run: Per-parallel-group -j suggestion — evaluate each wave against its own heaviest rule (#361) (#369) (@ShixiangWang) (#369)
- env: Pixi wrap must carry the whole command inside pixi run (#354) (#367) (@ShixiangWang) (#367)
- bench: Add required pair_id to the parsing_bench pairs fixture (#360) (#366) (@ShixiangWang) (#366)
Documentation#
- workflow-format: Document directory outputs (trailing-slash idiom) (@ShixiangWang)
Features#
- cluster: Element-wise aftercorr chaining for straight scatter chains (#371) (@ShixiangWang) (#373)
Maintenance#
- deps: Rustls 0.23.43 -> 0.23.45 (RUSTSEC-2026-0285) (@ShixiangWang)
Other Changes#
- Commit the -j suggestion evaluation harness and results (#361) (#370) (@ShixiangWang) (#370)
- ai: Complete the interpretation benchmark — dry-run surface, 12 seeds, negative controls, three providers (#359) (#365) (@ShixiangWang) (#365)
- ai: Seeded-failure interpretation benchmark; feed rule outcomes + stderr to report --ai (#359) (#364) (@ShixiangWang) (#364)
Styling#
- Cargo fmt (fix CI on 250bacff/e89ffd8) (@ShixiangWang)
Testing#
- web: Production-scale SSE stress profile — 64 runs, 8 subscribers, slow consumer (#363) (#368) (@ShixiangWang) (#368)
0.18.1 — 2026-09-12#
Bug Fixes#
- ai: Model-axis harness calibration + degraded-delivery, transport hardening, and exploration-budget nudge (#353) (@ShixiangWang) (#353)
- core: Inline conda package lists install with the conda-forge channel (lifecycle-verified) (@ShixiangWang)
- core: Executable inline conda package lists + deterministic gate repair (83% → 98% generation pass) (#352) (@ShixiangWang) (#352)
- ai: Finish the unified generation harness — provider isolation, structured error paths, budget default, docs (#350) (@ShixiangWang) (#350)
- test: Make driver sbatch-missing test environment-independent (#348) (@ShixiangWang) (#348)
- ai: Raise Anthropic max_tokens ceiling for thinking backends; add generation frontier benchmark (#345) (@ShixiangWang) (#345)
- scheduler: Treat plan-absent deps as satisfied in ready_rules (#346) (@ShixiangWang) (#346)
Features#
- ai: Opt-in Scientist Team profile with ablation-driven guards; frontier intent expansion (#351) (@ShixiangWang) (#351)
- ai: Unify pipeline generation on one agent + orchestrator harness (#349) (@ShixiangWang) (#349)
0.18.0 — 2026-09-09#
Bug Fixes#
- Full-repo scan remediation — docs, scripts, configs, frontend types (@ShixiangWang)
- Full-repo audit remediation — all CRITICAL/HIGH and confirmed MEDIUM/LOW findings (#343) (@ShixiangWang) (#343)
- run: OR-per-output dead-node propagation for targeted plans (#341) (@ShixiangWang) (#341)
- run: Review round 2 — ref normalization, owner-prefixed caches, fast fail (@ShixiangWang)
- eval: Repair 27 dead provenance URLs in tool gold set (#172) (@ShixiangWang)
- Add recorded_as to remaining BenchmarkRecord test constructions (@ShixiangWang)
- Address review findings from #335 (W032 regex, serde error, F-1 benchmark marker, missing_inputs docs) (@ShixiangWang)
- bench: Suite.py accepts --iterations, uses [rules.resources] (W025) (@ShixiangWang)
- bench: Comparative harness actually runs all three engines (#67) (@ShixiangWang)
- metro: Engine rendering fixes — terminal-dest line, single-line merged labels with +N counter (#334) (@ShixiangWang) (#334)
- metro: Merged-section second line lists full module names (#332) (@ShixiangWang) (#332)
- display: Readable config descriptions and module map names (#329) (@ShixiangWang) (#329)
- web: Wire-contract CreateRunRequest + OpenAPI requestBody + empty-body pause/resume (@ShixiangWang)
- cli: Eval findings F-1/F-2/F-3 — resume up-to-date recording, default-run chunk cleanup, validate wildcard warning (@ShixiangWang)
Documentation#
- Restore code fence broken in contributing.md flaky-test section (@ShixiangWang)
- graph: Merged-section display is now two-line, not "+"-joined (#333) (@ShixiangWang) (#333)
- graph: Reading semantics — off-track, independent chains, merged-cyclic (#330) (@ShixiangWang) (#330)
- Fix W032 anchor to the config section slug (@ShixiangWang)
- Clarify status --timing data sources for CLI and web runs (@ShixiangWang)
- Document eval-finding behaviors — W032 lint, validate wildcard warning, typed run contract (@ShixiangWang)
Features#
- run: Accept owner/repo shorthand without gh: prefix (@ShixiangWang)
- metro: Two-line merged-section displays + canonical-hue avoidance (#331) (@ShixiangWang) (#331)
- graph: Production-ready graph subcommand — format matrix, metro polish (#328) (@ShixiangWang) (#328)
- lint: W032 flags secret-like config keys not declared sensitive (@ShixiangWang)
- cli: Config comment group propagation + include-tree description merge (#326) (@ShixiangWang) (#326)
- graph: Metro granularity ladder — process + module tiers, topological stations (#325) (@ShixiangWang) (#325)
Other Changes#
- Complete gold-set review sweep — annotate 257 rows, accept corrected rows (@ShixiangWang)
Refactoring#
- release: Single-source version sync script (#344) (@ShixiangWang) (#344)
Styling#
- Rustfmt after recorded_as insertion (@ShixiangWang)
0.17.2 — 2026-09-05#
Bug Fixes#
- Report the W021 script-edge warning once instead of once per rule (@ShixiangWang)
- config: Keep _REP
-suffixed group keys in the #246 sample-domain intersection (@ShixiangWang) - Clamp docker --cpus to host CPUs and mark cleaned transform chunks in provenance (@ShixiangWang)
- cluster: Harden SLURM lifecycle and streamline cluster CLI (@ShixiangWang)
CI/CD#
- release: Fix artifact download pattern to single wildcard (@ShixiangWang)
- release: Skip dockerbuild build records in artifact download (@ShixiangWang)
Documentation#
- graph: Describe post-#318 metro stage tiers and module-namespace sections (@ShixiangWang)
- Add transform cleanup caveat to skill QC stage from v0.17.1 live test (@ShixiangWang)
- Fix skill gate syntax and add version caveats from tx-ubuntu live test (@ShixiangWang)
- Add AI agent skill (SKILL.md) with site nav entry and meta extension (@ShixiangWang)
Features#
- Lint W031 — warn when a consumer expands a when-gated producer's output unconditionally (@ShixiangWang)
- Metro maps — module sections, stage lines, used_by expansion channels (#318) (@ShixiangWang) (#318)
- Add regex_extract(path, pattern, group?) runtime when-fn (@ShixiangWang)
0.17.1 — 2026-09-03#
Bug Fixes#
- Restore checkout for CI manifest smoke tests (#310) (@Copilot) (#310)
- GITHUB_ENV write is invisible to the same step in docker-publish-release (#304) (@ShixiangWang) (#304)
- Scan output_pattern as a [[values]] fan-out trigger (#296) (#302) (@ShixiangWang) (#302)
CI/CD#
Documentation#
- Fix schema phantom key, env check protocol, and landing-page claims (#306) (@ShixiangWang) (#306)
- Comprehensive accuracy audit of docs/guide against source and live CLI (#305) (@ShixiangWang) (#305)
- Rebuild the system architecture reference (#303) (@ShixiangWang) (#303)
Other Changes#
- Harden
eval/into a trial-aware, review-gated AI benchmark harness (#309) (@Copilot) (#309) - Refactor GitHub CI into reusable, artifact-driven workflows (#308) (@Copilot) (#308)
0.17.0 — 2026-09-02#
Bug Fixes#
- Close out #299 (-t when-gate pruning) and #300 (conda env diagnosis) (#301) (@ShixiangWang) (#301)
- Resolve all nine #297 review follow-ups (web/cli/CI) (#298) (@ShixiangWang) (#298)
- ci: Knowledge refresh survives an org PR-block (#291) (@ShixiangWang) (#291)
- Signal teardown checkpoint corruption; desktop opener injection; OCI version labels (#294) (@ShixiangWang) (#294)
- core: Close plan/execution gaps in expand when-gating, discovery, expand_inputs (#293) (@ShixiangWang) (#293)
- release: Sync-version patches excluded desktop crate + SPA version; unify macOS packaging (#292) (@ShixiangWang) (#292)
- ci: Release Docker image validation leg; verify tarballs under original asset names (#285) (@ShixiangWang) (#285)
- ci: Lowercase the ghcr.io image path (owner "Traitome" rejected) (@ShixiangWang)
-
276 lifecycle audit — substitution floor, rendered-command guard, provenance, publish, web inputs, UX (#278) (@ShixiangWang) (#278)#
- release: Docker rust:1.92-slim < MSRV 1.98; add docker-build CI gate (#277) (@ShixiangWang) (#277)
- core: [[values]] fan-out triggers on expand_inputs references too (#268 item 1) (#269) (@ShixiangWang) (#269)
- core: Scientific preflight skips when-gated-off rules (#263) (#264) (@ShixiangWang) (#264)
- core: SLURM settlement survives clusters without slurmdbd (#244) (#261) (@ShixiangWang) (#261)
- core,cli: Targeted run (-t) closes over the instantiated DAG (#247) (#259) (@ShixiangWang) (#259)
- cli: Warn on config drift between checkpoint snapshot and current run (#243) (#257) (@ShixiangWang) (#257)
- core: File_exists() in when resolves against base_dir, not process cwd (#241) (#256) (@ShixiangWang) (#256)
- 12-role persona audit remediation — CRITICAL wave (RCE / literal wildcards / cluster dependency gate) (#251) (@ShixiangWang) (#251)
- core: Cartesian_expand with empty values returns an empty product (#254) (#253) (@ShixiangWang) (#253)
- core: Input_groups prunes group keys outside the declared sample set (#246) (#248) (@ShixiangWang) (#248)
- core: Bake {meta.*} before plan-time when evaluation (#239) (@ShixiangWang) (#239)
- core: Phantom-instance guard for repeated wildcards + pair-when typo warning (#238) (@ShixiangWang) (#238)
- ai: SSRF guard for FetchUrlTool — block internal address space on every hop (#223) (@ShixiangWang) (#223)
- core: Adopt a safe-char default for wildcard values reaching shells (#226) (@ShixiangWang) (#226)
- cli: Batch/pull robustness — TOML-safe escaping, bounded downloads, graceful join errors (@ShixiangWang)
- frontend: Abort ChatUI stream on unmount/stop — no leaked fetch or burned tokens (@ShixiangWang)
- web: Enforce the auth boundary on the serve path too (@ShixiangWang)
- ai: Bound provider latency, honor UTF-8, restore promised backup (@ShixiangWang)
- web: Harden auth boundaries and remove panic paths in server tasks (@ShixiangWang)
- core: Report generators no longer panic under section filters (@ShixiangWang)
- cli: Close shell-injection gaps and scheduler panic paths (@ShixiangWang)
CI/CD#
- frontend: Npm audit gate + drop duplicate playwright dep; zero current advisories (@ShixiangWang)
Documentation#
- Fix three drift findings in the report/web reference pages (#295) (@ShixiangWang) (#295)
- Web-api.md covers every live route; AGENTS.md env table completes auth/dev/limits (#270) (@ShixiangWang) (#270)
- Wildcard.* vocabulary scope, references external-only, {meta} absence-guard idiom (#250) (@ShixiangWang) (#250)
- Plan-time file_exists semantics + abort sibling resume note (#242) (#245) (@ShixiangWang) (#245)
- Output_pattern — all-instances gate + resume partial-domain replay interaction (#236) (@ShixiangWang) (#236)
- agents: Describe pagination schemes as they are, not one imaginary envelope (@ShixiangWang)
- Clear stale version markers and pin bioconda counts to their source (@ShixiangWang)
- Resync AGENTS.md, README and guide with the code (@ShixiangWang)
Features#
- Data-dependent DAG pruning — when gates over runtime-produced files (#282) (#289) (@ShixiangWang) (#289)
- Sheet columns as group metadata — long-read dimension (#283) (#288) (@ShixiangWang) (#288)
- report: Rule-attached captions + MultiQC-style aggregate collector (#281) (#287) (@ShixiangWang) (#287)
- engine: Nf-core-style versions.yml — declared-software export + report section (#280) (#286) (@ShixiangWang) (#286)
- desktop: Native-window desktop shell (wry + tao) — macOS app no longer opens the browser (#279) (@ShixiangWang) (#279)
- release: Dedicated Docker release channel — prebuilt binaries, multi-arch (#284) (@ShixiangWang) (#284)
- core: [defaults] time_limit — default wall-time for every rule (#266) (@ShixiangWang) (#266)
- core: [[values]] values_from — config-driven fan-out dimensions (#265) (@ShixiangWang) (#265)
- core,cli: Wire [webhook] to the run path — workflow events (#227 item 1) (#262) (@ShixiangWang) (#262)
- core: Glob
*in input_groups patterns — segment-local wildcard (#246) (#260) (@ShixiangWang) (#260) - core: Len() in when conditions — gate on list non-emptiness (#252) (#255) (@ShixiangWang) (#255)
- core: Docker GPU passthrough via environment gpus field (#240) (@ShixiangWang) (#240)
- core: Pair-level
whengating + input_groups E003 exemption (#237) (@ShixiangWang) (#237) - core: Runtime-discovered output fan-out (output_pattern) (#235) (@ShixiangWang) (#235)
- core: Per-sample metadata_file + {meta.*} placeholders + metadata group_by (issue #227) (#234) (@ShixiangWang) (#234)
- core: Per-sample multi-file grouping primitive (input_groups) (#231) (@ShixiangWang) (#231)
- core: Workflow-level on_complete / on_error terminal hooks (#229) (@ShixiangWang) (#229)
- web: Router-layer 503 boundary for all /api/runs endpoints on PostgreSQL (#207 phase 1 completion) (#228) (@ShixiangWang) (#228)
- web: Encrypt AI provider keys at rest under OXO_FLOW_MASTER_KEY (#225) (@ShixiangWang) (#225)
- web: Dedicated sliding-window rate limit on POST /api/runs (#224) (@ShixiangWang) (#224)
- web: Structured 503 boundary for run execution on PostgreSQL deployments (@ShixiangWang)
- frontend: Per-route error boundaries — one page crash no longer resets the SPA (@ShixiangWang)
Maintenance#
- knowledge: Automatic knowledge refresh 2026-09-01 (#290) (@ShixiangWang) (#290)
- core: Dead-code sweep — remove unused types, variants, helpers, and globset dep (#268 item 3) (#273) (@ShixiangWang) (#273)
- build: Bump pinned toolchain to Rust 1.98.0, update lockfile (@ShixiangWang)
- repo: Tighten hygiene and align local gate with CI (@ShixiangWang)
Performance#
- web: Move synchronous file I/O off the async runtime (#268 item 4, web minor) (#275) (@ShixiangWang) (#275)
- core: Shared subtree walk in rss sampler; view-based freshness checksums (#268 item 4) (#274) (@ShixiangWang) (#274)
- core: Hoist loop-invariant config_values clone out of expansion loops (#268 item 4) (#272) (@ShixiangWang) (#272)
Refactoring#
- core: Split config.rs (9046 lines) into a config/ domain tree (#230) (@ShixiangWang) (#230)
Testing#
- Root-cause fixes for 4 verified flaky tests (#268 item 2) (#271) (@ShixiangWang) (#271)
- ci: Flaky-test governance — signal-grace window + capped retry (#249) (#258) (@ShixiangWang) (#258)
- core: Assert inferred input_groups DAG edges + doc the dir-pattern producer note (#233) (@ShixiangWang) (#233)
- web: Contract for the PG runs boundary; capability matrix; audit degrade (#232) (@ShixiangWang) (#232)
0.16.0 — 2026-08-27#
Bug Fixes#
- core: Config toggles no longer invalidate when-only rules with unchanged gates (#198) (@ShixiangWang)
- core: Unbound wildcard keys in when-conditions now evaluate false (was permissive true) (#199) (@ShixiangWang) (#199)
- cli: Background run logs are ANSI-free and deduplicated (@ShixiangWang)
- core+cli+web: Reliability audit #194 — atomic checkpoint, single-writer run log, SIGTERM grace, narrative+event archiving, checksum reuse, rotation, cleanup (@ShixiangWang)
- core: Metro export — stage-inference accuracy + stage-cycle breaker (@ShixiangWang)
- core: Escape Mermaid/metro syntax meta-characters and fix metro indentation (@ShixiangWang)
- singularity: Pull %-encoded HTTP URIs into the engine-derived artifact name (@ShixiangWang)
- gallery: Bwa read-group CL corruption + per-tool stringency flags + 14/15 copy-paste bugs (@ShixiangWang)
- Resolve issue #181 code-quality, docs, and frontend cleanup (@ShixiangWang)
- ci: Re-point the tag to the synced commit on tag-push releases (@ShixiangWang)
- frontend: Persona review — i18n gaps, TS fixes, CSV export, lint (@ShixiangWang)
- web: Skip per-user AI provider rows with empty keys (@ShixiangWang)
- ai: Echo DeepSeek reasoning_content back across multi-turn agent loops (@ShixiangWang)
- frontend: Persona-discovered a11y/touch/UX issues (@ShixiangWang)
- frontend: Persona-discovered AI/i18n/ApiDocs issues (@ShixiangWang)
- web: Persona-discovered backend correctness issues (@ShixiangWang)
- core: Re-tag the quay fallback image with the original spec (@ShixiangWang)
- cli: Template -o treats a trailing slash as a directory intent (@ShixiangWang)
- gallery: Container image references must exist and be registry-qualified (@ShixiangWang)
- gallery: Complete the gallery — aux files for 09/11/14/15, real BWA-MEM2 in 05, template copies aux files (@ShixiangWang)
- core+cli: Resolve campaign issues #159 #162 #163 (@ShixiangWang)
- core: Cache-hit envs re-verify on disk; vanished envs invalidate and rebuild (@ShixiangWang)
- ci: Linux desktop bundles get app-menu entry + icon (deb/rpm/AppImage) (@ShixiangWang)
- ci: Desktop app icon, launcher entry, ad-hoc codesign (@ShixiangWang)
- cli: Help-text drift + license --json machine output + 4 doc table rows (9c doc-consistency audit) (@ShixiangWang)
- web: Dev-mode login role matches account; drop nonexistent serve --json doc row (@ShixiangWang)
- Persona-testing LOW tail — ENOENT labeling, dry-run E011 annotation, cluster status guard, docs drift (#142) (@ShixiangWang)
- core: #142 H5/M4/M5 — transform required inheritance, profile max_array_size, per-element array logs (@ShixiangWang)
- Persona-testing findings #142 — silent-failure traps, audit-path bugs, docs batch (@ShixiangWang)
CI/CD#
- docs: Preserve landing page + static assets across mike deploys; landing links point at /latest/ (@ShixiangWang)
- docs: Mike-based doc versioning (issue #176) (@ShixiangWang)
Documentation#
- Durability guarantees, cache_key semantics, sensitive masking forms (@ShixiangWang)
- Mention nf-metro online playground in graph command docs (@ShixiangWang)
- Repoint all traitome.github.io links from /documentation/ to /latest/ (README + ai_status + landing page) (@ShixiangWang)
- Document API authentication schemes in web-api.md (@ShixiangWang)
- Sync web reference docs with serving/runtime changes (@ShixiangWang)
- Use-environments how-it-works reflects content-hash env naming (@ShixiangWang)
- run: Clarify --background scope — cluster runs inherit it, dry-run and other commands intentionally don't (#158 follow-up) (@ShixiangWang)
- guide: Document web_role_matrix + web_integration test targets in contributing (@ShixiangWang)
- lint: Fix two broken relative links to workflow-format.md (@ShixiangWang)
Features#
- cluster: Record what a cluster job actually cost (@andrewbudge)
- core: Wildcard.
placeholders render in shells (#201) (@ShixiangWang) (#201) - core: Optional="any" alternative-input mode + skip propagation to dependents (#200) (@ShixiangWang) (#200)
- core,cli: Issue #194 round 2 — content cache, atomic moves, upload verification, masking variants, mid-run manifest checks (@ShixiangWang)
- core: Container registry mirror mapping (OXO_REGISTRY_MIRRORS) (#192) (@ShixiangWang) (#192)
- core: Wildcard-scoped when — snakemake-style per-sample DAG morphing (#187) (@ShixiangWang) (#187)
- cli: Add mermaid and metro graph export formats (@ShixiangWang)
- Close issue #67 follow-ups — SSE broadcast verification + env-ai matching tests (@ShixiangWang)
- ui: Systematic visual polish, shared Modal/StatCard, a11y (@ShixiangWang)
- web: Optimize HTTP serving layer (@ShixiangWang)
- ai: Knowledge coverage — R/Bioconductor analysis tools now in the bioconda table (@ShixiangWang)
- core: Docker backend retries bare image names against quay.io/biocontainers (@ShixiangWang)
- eval: Three-layer AI evaluation benchmark — gold CSVs, capture/runner harness, knowledge grounding guard (@ShixiangWang)
- ai: Knowledge freshness framework — in-repo generators, live sync, monthly auto-refresh (#153) (@ShixiangWang)
- Background runs + verified concurrent reuse of shared workflows (#158) (@ShixiangWang)
- core: Residual-placeholder guard — unresolved {sample}/{config.*}/… in a rendered command warns loudly (@ShixiangWang)
- Usability round — 0-byte output warning, W021 script-edge lint, disk pre-flight (@ShixiangWang)
- cli: Reference path migration with identical content skips the rebuild (@ShixiangWang)
Maintenance#
- Merge main into feat/web-ui-optimization (@ShixiangWang)
- Sync CLI workflow schema with the docs copy + drift gate in make ci (@ShixiangWang)
- Retrigger CI (take 2) (@ShixiangWang)
- Retrigger CI on the clean exemption head (@ShixiangWang)
Performance#
- frontend: Lazy editor panels, parallel run loading, client hardening (@ShixiangWang)
- web: Fix runtime hot paths and API contract drift (@ShixiangWang)
Styling#
- Cargo fmt (@ShixiangWang)
- Cargo fmt (@ShixiangWang)
- config: Remove duplicated #[test] attribute on the H5 inheritance test (@ShixiangWang)
Testing#
- cli: Deterministic mtimes in empty_checkpoint freshness test (#193) (@ShixiangWang) (#193)
- web: Fix ownership-isolation flake — slow run so admin cancel lands mid-run (@ShixiangWang)
- e2e: Mock AI config in AI-dependent specs (@ShixiangWang)
- Fix env-name hash test (distinct dirs for same-stem specs) + plain-names expectation with suffix (@ShixiangWang)
- web: Deployment + 3-role simulation matrix (@ShixiangWang)
0.14.1 — 2026-08-22#
Bug Fixes#
- info-test: Drop env-coupled git_remote assertion (#136 finding 29) (@ShixiangWang)
- Audit #136 tier-2 — web cancel integrity, wait-loop races, LOW tail (#136) (@ShixiangWang)
- cluster: Resolve #136 H-items — array chunking, non-SLURM polling, cap semantics, submit-time checkpoint (@ShixiangWang)
- V0.13.1→v0.14.0 audit fixes — dispatch regressions, log masking, core safety, CI release integrity (#136) (@ShixiangWang)
- cli: Keep-going changes scheduling, never the verdict — exit non-zero on required failures (#133) (@ShixiangWang)
- core: Kill in-flight rule processes on abort — no more orphans (#131) (@ShixiangWang)
Documentation#
- Cluster fairness — priority honored with aging, in-flight cancel, wait-visibility boundary (#134 follow-up) (@ShixiangWang)
- Dag-engine — FIFO acquisition makes priority starvation impossible (the guarantee) (@ShixiangWang)
Features#
- core: Cluster driver honors priority with fair-dispatch aging (#134) (@ShixiangWang)
- core: FIFO-gated resource acquisition — the 100% no-starvation guarantee (#123) (@ShixiangWang)
Testing#
- Update the fourth keep-going exit-0 site (report --failed harness) (@ShixiangWang)
- Assert the process is dead, not the pid file — #118 legitimately removes it (@ShixiangWang)
- cli: Serialize logging tests over the process-global run-log slot (@ShixiangWang)
- Bisect the CI-only abort-test failure — 10s window + verbose run log in panics (@ShixiangWang)
- Surface the run's stderr in abort-test assertion failures (@ShixiangWang)
- Widen the abort-test margin — slow must spawn before bad fails on slow CI runners (@ShixiangWang)
0.14.0 — 2026-08-21#
Documentation#
- Dag-engine — fair dispatch prevents resource starvation (aging + submit cap) (@ShixiangWang)
Features#
- cli: Fair dispatch — priority aging + -j submit cap; lint W019 empty outputs (@ShixiangWang)
- core: Resource-pool wait diagnostics — name what a waiting rule needs and who holds it (@ShixiangWang)
Refactoring#
- cli: Extract age_ready_list as a pure, unit-tested function (@ShixiangWang)
Styling#
- cli: Reword age_ready_list doc to satisfy clippy doc_lazy_continuation (@ShixiangWang)
0.13.1 — 2026-08-21#
Bug Fixes#
- web: Cancel verifies real group death; de-flake web_integration family (#120) (@ShixiangWang)
- core: Invalidate failed rules' outputs so stale files never skip a re-run (@ShixiangWang)
- core: Conda env bin first in PATH inside conda run wrappers (@ShixiangWang)
- core: Conda run --no-capture-output to kill the capture-poll hang (@ShixiangWang)
- core: [[pairs]] members feed the merged config.samples_list (@ShixiangWang)
- references: Use the documented checkpoint path + persist legacy adoption (@ShixiangWang)
- cluster: A fresh dependency no longer stalls the driver (@andrewbudge)
- core: Singularity setup pulls only when the SIF is absent — pull refuses to overwrite (@ShixiangWang)
- core: Docker setup pulls only when the image is absent — concurrent rules sharing one image race in the daemon (@ShixiangWang)
- core: Docker setup pulls only when the image is absent — concurrent rules sharing one image race in the daemon (@ShixiangWang)
- Close #99 review gaps — cluster masking/B2 parity, AI recovery target, error-path masking (@ShixiangWang)
- config: Promote sensitive-only inline configs; rule
requireddefaults to true (@ShixiangWang) - wildcards: Substitute fan-out values into script and hook fields (@ShixiangWang)
- references: Guard source content in the reference fingerprint (@ShixiangWang)
- core: Container cgroup caps at physical RAM — swap counts for scheduling, not cgroups (@ShixiangWang)
- core: Timeout diagnostic reads the holder pid from the lock file (@ShixiangWang)
- core: Per-environment create locks with a bounded wait — no more global serialization (@ShixiangWang)
- core: {effective_memory_mb} stays RAM-only — swap counts for scheduling, not tool sizing (@ShixiangWang)
- core: Verify existing conda envs before re-running setup on a cold cache (@ShixiangWang)
- core: Clamp docker/singularity cgroup --memory to the machine total (@ShixiangWang)
- core: Export the base conda CA bundle during env setup (@ShixiangWang)
- core: Never infer a rule edge to itself (@ShixiangWang)
- core: Expand {config.x} placeholders before DAG edge matching (@ShixiangWang)
- core: Container rules run under image bash when available; deterministic dir-creation errors (@ShixiangWang)
- cli: Render {source} in reference build commands (@ShixiangWang)
- core: Serialize conda env setup per environment key (@ShixiangWang)
- core: Verify conda envs after setup; repair broken ones (@ShixiangWang)
- core: Shared output strings link EVERY producer in the DAG (@ShixiangWang)
- core: DAG template graphs include expand_inputs dataflow edges (@ShixiangWang)
- core: Derive conda env name for setup, not just wrap (@ShixiangWang)
- core: Clamp over-capacity rule requests instead of fast-failing (@ShixiangWang)
- core: Resolve nested {config.x} references deterministically (#88) (@ShixiangWang) (#88)
- ai: Unify AI config path + accurate provider labels (@ShixiangWang)
CI/CD#
- Enable workflow_dispatch to drive the full release pipeline (@ShixiangWang)
- frontend: E2e webServer timeout + feature-unification warm-up fix (@ShixiangWang)
Documentation#
- readme: Bioconda version badge + systematic badge refresh (@ShixiangWang)
- run: Fix glued heading in the --module section (@ShixiangWang)
- run: Document automatic job arrays in cluster submission (#74 phase 3) (@ShixiangWang)
- workflow-format: Teach the aggregation idiom — expand_inputs + {input} (@ShixiangWang)
- Document sensitive masking and required=false continue-on-error semantics (@ShixiangWang)
- Document script/hook fan-out substitution and reference content guard (@ShixiangWang)
- run: Clarify profile names carry no built-in meaning (@ShixiangWang)
- gallery: 16s run instruction — activate the QIIME2 env, drop the nonexistent --profile conda (@ShixiangWang)
- gallery: Add the missing 16th workflow to the Learning Path (@ShixiangWang)
- Purge stale root-doc content (README gallery, roadmap, limitations, releasing, agents, security) (@ShixiangWang)
- Per-environment creation locks with bounded wait (@ShixiangWang)
- Resource ceiling counts swap (--max-memory pins to RAM) (@ShixiangWang)
- Container --memory clamping + env verify-before-setup behaviors (@ShixiangWang)
- Harden the China mirrors guide with live-campaign findings (@ShixiangWang)
- DAG edge inference expands {config.x} placeholders (from_rules_with_config) (@ShixiangWang)
- Sync deadlock/resource semantics with the clamp change (@ShixiangWang)
Features#
- info: Derive workflow git provenance in info --json (#124) (@ShixiangWang)
- run-log: Per-run archived log with versioned header + report git sha (@ShixiangWang)
- provenance: Record workflow git HEAD SHA in checkpoints (#115) (@ShixiangWang)
- Partial module runs (--module) + git-pinned includes (#112 elasticity) (@ShixiangWang)
- include: Typed interface contracts for workflow modules (#112 module slice) (@ShixiangWang)
- cluster: Job arrays for scatter rules (issue #74 phase 3) (@ShixiangWang)
- core: Singularity spec accepts a local SIF path (site-deployed images) (@ShixiangWang)
- Workflow-global shell prelude (issue #92) + explicit null-stdin contract (issue #101) (@ShixiangWang)
- Mask sensitive config values + wire rule-level required=false (#99 B1/B2) (@ShixiangWang)
- core: Swap-aware resource detection — the ceiling is RAM + swap (@ShixiangWang)
- core: Cross-process env-create mutex — serialize conda creates across runs (@ShixiangWang)
- core: {effective_threads}/{effective_memory_mb} placeholders — tools size themselves to the machine (@ShixiangWang)
- cluster-run: Report snapshot parity + cluster.md cross-ref (PR #93 follow-up) (@ShixiangWang)
- Run --profile submits to a scheduler when the profile declares [cluster] (issue #74 phase 2) (@andrewbudge)
- core: [[references]] entries can declare an environment (@ShixiangWang) (#90)
- cli: Unify sample selection under --samples (@ShixiangWang)
- cli: Info derives config descriptions from [config] comments (@ShixiangWang) (#86)
Maintenance#
- deps: Bump h2 0.4→0.4.16, ignore RUSTSEC-2026-0258 for the aws-sdk's h2 0.3 (@ShixiangWang)
Styling#
- core: Struct-init test helpers instead of Default + reassign (@ShixiangWang)
- core: Collapse collapsible ifs (clippy -D warnings clean after rebase) (@ShixiangWang)
Testing#
- core: Exercise the production lock-path derivation (@ShixiangWang)
- core: Env-create lock test uses a temp dir, not the real HOME (@ShixiangWang)
- Assert on the mamba backend's detected binary (@ShixiangWang)
0.13.0 — 2026-08-15#
Bug Fixes#
- core: Pixi backend uses --manifest-path (workflow spec names the file) (@ShixiangWang)
- cli: LSF dependency flag uses double quotes in submit.sh (@ShixiangWang)
- core: Venv setup uses POSIX . instead of bash source (@ShixiangWang)
- core: Container backends bind absolute host paths (@ShixiangWang)
- core: Expand rule log-field wildcards per instance (@ShixiangWang)
- core: E003 exempts [[values]]-declared parameter wildcards (@ShixiangWang)
- web: Wire env badge colors to theme tokens and refresh SPA bundle (@ShixiangWang)
- cli: Profile merge order + info accuracy + plan JSON surface (@ShixiangWang)
- core: Harden v0.13 features found by release review (@ShixiangWang)
- ci: Publish rpm and AppImage to releases; docs: complete release asset docs (@ShixiangWang)
CI/CD#
- Publish stable-named latest CLI tarball in releases (@ShixiangWang)
Documentation#
- Sync info and {log} docs with release-review behavior (@ShixiangWang)
- Release-review documentation and CI fixes (@ShixiangWang)
- [[values]] fan-out, scratch rules, reference templates, profile override, {log}, pairs_list, plan JSON (@ShixiangWang)
- Editor setup how-to — .oxoflow files as TOML in VS Code and other editors (@ShixiangWang)
Features#
- core: Reference builder templates + naming standard (@ShixiangWang)
- core: Rule-level scratch workdir (scratch = true) (@ShixiangWang)
- core: [[values]] parameter wildcards + reference builder wiring (@ShixiangWang)
- core: Expanded-path DAG edge inference (@ShixiangWang)
- cli: Add
infocommand with per-key config derivation (@ShixiangWang) - cli: Route profile merge through core merge_profile (@ShixiangWang)
- core: Inject config.pairs_list + profile override mode (@ShixiangWang)
- cli: Unknown --flag hard error + dry-run --json plan export (@ShixiangWang)
- core: {log} placeholder, array-config join, bash executor (@ShixiangWang)
- ci: Desktop bundles carry a -desktop- infix in their names (@ShixiangWang)
Styling#
- web: Environment badge colors as semantic theme tokens (@ShixiangWang)
Testing#
- Gallery_07 asserts topo order semantically, not by tie-break (@ShixiangWang)
0.12.0 — 2026-08-15#
Bug Fixes#
- web: Normalize base_path in the standalone web binary (@ShixiangWang)
- web: Inject
at the START of , always (@ShixiangWang) - web: Pbsnodes attribute lines leaked in as node names (@ShixiangWang)
- web: Validate usernames at the POST /api/users entry point (@ShixiangWang)
- report: Dashboard never divides instances by rule count (@ShixiangWang)
- Upgrade-compatibility and mount-path hardening (review follow-ups) (@ShixiangWang)
- web: Quota release on every terminal path + daily reset + terminal-state guards (@ShixiangWang)
- core: Cluster driver settles jobs that leave the live queue (@ShixiangWang)
- core: Staged remote keys must not escape the staging tree (@ShixiangWang)
- web: Tenant isolation gaps in audit, AI cache, chat tools, pipeline read (@ShixiangWang)
- web: Remote SSH command injection via cluster fields (@ShixiangWang)
- web: Username/path traversal in workspace paths, symlink leak in zip downloads (@ShixiangWang)
- web: Scheduler probe must honor exit status, not spawn success (@ShixiangWang)
- scripts: Deploy-smoke hpc scenario authenticates before /api/hpc (@ShixiangWang)
- web: Complete LSF/SGE status collection in hpc.rs (@ShixiangWang)
- cli: Comment stale scaffold template placeholders + sync --strict help text (#83) (@ShixiangWang)
- cli: --acct optional-JobID panic, array-task batch pref, test gaps (#83 P1-13) (@ShixiangWang)
- cli: Restore --workdir checkpoint precedence, template autoescape + path resolution, json/md gate (#83 P1-1/P0-9) (@ShixiangWang)
- web: Don't cache the shared-runtime AI provider fallback — a runtime provider swap must take effect immediately (chat_agent_integration caught a stale cached scripted provider) (@ShixiangWang)
- executor: Honest per-process CPU docs + flake-guard assertion + SeqCst (#83 P1-13) (@ShixiangWang)
- report: Commit the actual report_metrics split — orphan adapters.rs now compiled (#83 P1-5) (@ShixiangWang)
- report: Sample-matrix engine-real instance naming, filter-path panic guard, STAR % parsing (#83 P1-5) (@ShixiangWang)
- Cluster submit expands wildcards, captures real job ids, surfaces walltime (#74 phase 1) (#84) (@andrewbudge) (#84)
- ci: Make the e2e suite actually pass — rate-limit escape hatch, guest nav, canvas-mode pinning (@ShixiangWang)
- web: Dashboard runs-envelope adaptation + fmt normalization; docs: README DAG stack (React Flow + d3-dag, not cytoscape) (@ShixiangWang)
- deploy-smoke: Binary discovery for deployed servers; scoped cleanup (@ShixiangWang)
- Runs list — clickable rows, detail scrolls into view, paging (issue #79 P2) (@ShixiangWang)
- Eliminate CSP unsafe-eval violations — vega-interpreter for report charts (issue #79 P2) (@ShixiangWang)
- storage: Make s3-storage compile — head() NotFound returns None, sync client init, drop dead match arm (#80) (@ShixiangWang)
- Storage_resolver local-only (cfg branches land with the feature opt-in); snapshot 4-arg call (#78) (@ShixiangWang)
- gallery: Declare optional classifier config in the 16S QIIME2 template (#79 E005) (@ShixiangWang)
- /api/health reports the real deployment mode (issue #79 P1-03 family) (@ShixiangWang)
- Status single-source, UI wiring, AI delivery, editor guards (issue #79 R-02/03/04/06/07/09/10) (@ShixiangWang)
- Web platform security triad — rate limit, audit trail, admin auth (issue #79 P1-04/05/06) (@ShixiangWang)
- One run = one process group; honest crash recovery (issue #79 P1-01/P1-02) (@ShixiangWang)
- web: Retry SQLite pool init on transient disk I/O errors (CI runner flakes) (@ShixiangWang)
- frontend: Replace Date.now with crypto.randomUUID; silence fast-refresh on showToast export (@ShixiangWang)
- web: Single ordered chat event channel — no select-in-yield, boxed outcome (@ShixiangWang)
- ai: Coalesce tool_result blocks per Anthropic's pairing rule — second live finding (@ShixiangWang)
- ai: Claude backend emits tool_use blocks — found by live round-trip (@ShixiangWang)
- web: Restore DB-persisted AI config at startup; chat_messages table (@ShixiangWang)
- web: Revert kind field on legacy handler's local edge type (@ShixiangWang)
- web: Attribute pipeline ownership to acting user; compute real effective AI config (@ShixiangWang)
- web: Verify and consume OAuth state server-side (@ShixiangWang)
- web: Unify audit_logs schema across init paths; insert_run fills all columns (@ShixiangWang)
- web: Unify run status vocabulary on completed (@ShixiangWang)
- Embed template gallery from crate-local templates/ so cargo publish works (issue #76 P1-3 follow-up) (@ShixiangWang)
CI/CD#
- Drop broken step PATH override in e2e job (env context PATH is empty in Actions) (@ShixiangWang)
- Frontend build + e2e job gates the web UI (@ShixiangWang)
Documentation#
- Webhook signature schemes, audit admin-only scope, retry/pause terminal guards (@ShixiangWang)
- Production deployment — systemd unit + nginx reverse proxy (@ShixiangWang)
- Drop stale v0.10.x version prefixes from feature intros (@ShixiangWang)
- Fix ACMG Tier III 'Uncertain significance' wording (#83) (@ShixiangWang)
- Report capabilities — metrics parsing, template wiring, auto-snapshots (#83 Task 5) (@ShixiangWang)
- Point the API reference at the code-generated spec; drop the stale hand-maintained openapi.yaml (@ShixiangWang)
- Per-user AI credentials resolution + canvas comment preservation (@ShixiangWang)
- Deploy modes — OXO_FLOW_DISABLE_RATE_LIMIT testing escape hatch (@ShixiangWang)
- Link oxo-flow-community catalog from README and guide nav (@ShixiangWang)
- Desktop app — SPA assets ship prebuilt in static/ (rebuild for latest UI) (@ShixiangWang)
- Drop remaining clinical-grade claims about oxo-flow itself (#83 P0-1) (@ShixiangWang)
- Report documentation sweep — honest claims, new flags, new sections (#83) (@ShixiangWang)
- Collaboration — share landing pages, enforced visibility, version history (@ShixiangWang)
- Sync web docs with the v0.11 hardening (files/instances/webhooks/API keys/retry semantics/share landing/remote cluster execution/multi-tenancy/guided mode) (@ShixiangWang)
- Release asset table for desktop bundles (dmg/deb/rpm/AppImage) (@ShixiangWang)
- Dry-run usage/parity note + status timing example with peak RSS column (@ShixiangWang)
- Sync command pages with the alignment audit + new ai command page (#67) (@ShixiangWang)
- China network mirrors reference — snapshot findings, recommended stack, re-runnable probe script (#67) (@ShixiangWang)
- Staging/pairs-reentry/HMAC/cluster-logs/diagnostics sync for #80 + #67 (@ShixiangWang)
- Design for #80 follow-up — S3 toolchain bump, remote staging, pairs re-entry (#80) (@ShixiangWang)
- Execution backends, storage invalidation, checkpoint re-entry (#78) (@ShixiangWang)
- Deployment modes reflect verified behavior (sub-path mount, run-control truth, user/audit management) (@ShixiangWang)
- Implementation plan for issue #78 — 19 tasks across P1/P2/P3 (@ShixiangWang)
- Refresh stale test counts; clarify parity contract comment (@ShixiangWang)
- Design spec for issue #78 — static plan + pluggable executors (P1/P2/P3) (@ShixiangWang)
- Document tombstones in checkpoint format (status + glossary) (@ShixiangWang)
- Remove web evaluation report — superseded by issue #79 (@ShixiangWang)
- Sync consistency work across run/dry-run/troubleshooting (@ShixiangWang)
- Add web simulated-user evaluation report (12 personas, 5-dimension verdict) (@ShixiangWang)
- Add web simulated-user evaluation design (@ShixiangWang)
- Mark web design spec complete — merged to main (@ShixiangWang)
- All phases complete — spec status finalized (@ShixiangWang)
- Live AI verification done — real Claude loop validated end-to-end (@ShixiangWang)
- Final phase-status annotation in the web spec (@ShixiangWang)
- Annotate P2/P3 completion and deviations in the web spec (@ShixiangWang)
- P3 AI assistant implementation plan (@ShixiangWang)
- Dag edit API extended ops + web canvas how-to guide (@ShixiangWang)
- P2 graphical editor implementation plan (@ShixiangWang)
- Annotate P0 fixes in web design spec (@ShixiangWang)
- P0 execution-truth implementation plan (@ShixiangWang)
- Web full-lifecycle design spec — graphical editor, grounded AI, execution truth fixes (@ShixiangWang)
Features#
- web: Rule timeline — the terminal-native signature element (@ShixiangWang)
- web: Quota endpoint reports the acting user's usage (@ShixiangWang)
- cli: Run auto-snapshot + --r-data TSV export + report --diff/--acct (#83 P1-14/P1-15/P1-6/P1-13) (@ShixiangWang)
- cli: Zero-arg report discovery, --run/--failed/--plan, template wiring (#83 P1-1/P0-9/P2-7) (@ShixiangWang)
- web: Code-generated OpenAPI 3.1 spec via utoipa (issue #82 P1-13) (@ShixiangWang)
- executor: Sampled CPU-seconds metering → BenchmarkRecord + honest CPU column (#83 P1-13) (@ShixiangWang)
- web: Preserve TOML comments/formatting in canvas edits (issue #82 P2-3) (@ShixiangWang)
- web: Per-user AI provider runtime isolation (deferred #82 item) (@ShixiangWang)
- report: Metrics adapters for fastp/flagstat/STAR/featureCounts/bcftools/kraken2 + rule×sample matrix (#83 P1-5) (@ShixiangWang)
- web: Remote cluster execution over SSH — stage/launch/poll/pull (#82 deployment modes) (@ShixiangWang)
- report: Execution-truth reporting — WS1 honesty + WS2 checkpoint facts + WS3 single contract (#83) (@ShixiangWang)
- web: #81 backlog — validate parity, CLI command exposure, misc fixes (@ShixiangWang)
- web: Polish — dark mode, TOML highlighting, quota enforcement, error-line jumps (#82 P1-9/P2) (@ShixiangWang)
- web: API contract & cleanup — diff contract, pagination, webhooks, API keys, rule-level SSE (#82 P1-3/P1-4/P1-10/P1-12/P1-13/P1-18) (@ShixiangWang)
- web: Beginner layer — guided builder, task-oriented home, i18n zh, role-trimmed nav (#82 P1-5/P1-7/P1-8/P1-15) (@ShixiangWang)
- web: Share closure + pipeline version history (#82 P0-6/P1-14) (@ShixiangWang)
- web: Run-loop closure — real retry, logs view, instances, cancel, telemetry (#82 P0-3/P0-7/P1-1/P1-2/P1-19) (@ShixiangWang)
- web: File service layer — download/preview/zip results, multipart upload (#82 P0-1/P0-2) (@ShixiangWang)
- web: Multi-tenancy isolation — ownership scoping on every run/pipeline/control endpoint (#82 P0-4/P0-5) (@ShixiangWang)
- ci: GitHub release ships desktop bundles — macOS .app/.dmg, Linux .deb/.rpm/.AppImage (@ShixiangWang)
- cli: Alignment audit — status --timing memory columns, touch --workdir + workflow-dir base, test execution flags, resume -k/--timeout, batch --json honored, -d short unified (#67 follow-up) (@ShixiangWang)
- cli: Dry-run parity with run — --arg/KEY=VALUE/--sample/--rerun/--resume-failed, shared override helpers, executor freshness gate in the preview (4 new parity scenarios) (@ShixiangWang)
- Deployment smoke suite (7 scenarios) + config-file defaults for CLI serve (@ShixiangWang)
- Instance-level dry-run preview in the web UI (issue #79 P2) (@ShixiangWang)
- executor: Sampled peak-RSS metering → BenchmarkRecord + diagnostics resource_bottlenecks at ≥80% of declared limit (#67) (@ShixiangWang)
- cli: Cluster logs — last stub resolved via ExecutorBackend::logs (sacct/qstat/qacct/bacct), mock-scheduler tested (#67) (@ShixiangWang)
- webhook: Real HMAC-SHA256 signatures (RFC 4231 verified), legacy keyed-sha256 behind signature_scheme (#67) (@ShixiangWang)
- reentry: [[pairs]]-driven checkpoint re-entry — manifest pairs, pair_id identity, E015 conflict, E016 collision, E014 extended (#80) (@ShixiangWang)
- storage: Remote staging/upload — etag-keyed cache, pattern substitution on a rule copy, upload-after-validate, MinIO E2E (#80) (@ShixiangWang)
- storage: S3-storage compiles and works live — env config, path-style opt-in, resolver registration, MinIO etag E2E (#80) (@ShixiangWang)
- ui: Design system v2 — terminal-vernacular identity (issue #79 aesthetics) (@ShixiangWang)
- Platform config file + SSH cluster connections (web) — ai/ssh customization surface (@ShixiangWang)
- Desktop packaging — single-file .app/.dmg/.deb via cargo-bundle; serve env vars + --open (@ShixiangWang)
- cli: Dry-run previews deterministic re-entry reconstruction (#78) (@ShixiangWang)
- cli: Checkpoint re-entry hook in the run loop (#78) (@ShixiangWang)
- core: Checkpoint re-entry — manifest surface, template re-expansion, records (#78) (@ShixiangWang)
- cli: Thread StorageResolver into manifest snapshots; graceful remote-input degradation (#78) (@ShixiangWang)
- core: Etag-aware remote manifest snapshot + unified manifests_match (#78) (@ShixiangWang)
- core: Remote manifest entries (scheme/key/etag/size), backward compatible (#78) (@ShixiangWang)
- core: StorageBackend::head + RemoteStat — S3 ETag / GCS md5Hash (#78) (@ShixiangWang)
- 16S amplicon gallery template (QIIME2 backbone) — issue #79 R-10 domain gap (@ShixiangWang)
- core: BackendDriver — submit/poll loop with queue cap and failure propagation (#78) (@ShixiangWang)
- Sub-path deployment — --base-path actually mounts the app (issue #79 deployment modes) (@ShixiangWang)
- core: ExecutorBackend trait + ClusterExecutor with shared job-id/status parsing (#78) (@ShixiangWang)
- core: ScheduledPlan + ScheduledRule — executor-agnostic static plan (#78) (@ShixiangWang)
- Temporary rules with tombstone + lazy cascade-up; configurable cache aging (@ShixiangWang)
- Close the dry-run/run consistency gaps + content-hash invalidation (@ShixiangWang)
- web: Run-diagnosis chat tools; tool errors emit ToolResult events (@ShixiangWang)
- frontend: My Pipelines page (open/export/delete), pipeline loading, login page (@ShixiangWang)
- web: Chat prompt enforces TOML array I/O and direct validation fixes; 6 rounds (@ShixiangWang)
- web: Report Q&A and visualization answer from real run data (@ShixiangWang)
- web: Run options dialog — samples, targets, keep-going, max jobs; template loading (@ShixiangWang)
- frontend: Chat renders grounded tool-call cards (@ShixiangWang)
- web: Chat runs the grounded agent loop with real streaming events (@ShixiangWang)
- ai: Orchestrator event sink and cancellation (@ShixiangWang)
- ai: Streaming chat for openai-compatible providers (@ShixiangWang)
- frontend: React Flow canvas editor — palette, inspector, edge kinds, monitor reuse; drop cytoscape (@ShixiangWang)
- web: Null patch key removes field in dag edit API (@ShixiangWang)
- web: Dag nodes carry environment and full serialized rule (@ShixiangWang)
- web: Knowledge search endpoints for the editor palette (@ShixiangWang)
- web: Dag edges tagged file vs declared (@ShixiangWang)
- web: Dag edit API supports full rule specs via TOML-patch update_rule (@ShixiangWang)
- web: Node status derived from engine checkpoint; drop dead run_nodes table (@ShixiangWang)
- web: Cancel/pause/resume signal the live run process group (@ShixiangWang)
- web: Executor registers run process group, defers to cancel state (@ShixiangWang)
- web: Process-group registry for real run control (@ShixiangWang)
Maintenance#
- Bump rust-toolchain 1.92.0 → 1.97.1 (aws-sdk MSRV 1.94.1; #80) (@ShixiangWang)
- frontend: Zero lint errors; lint joins the CI frontend gate (@ShixiangWang)
Refactoring#
- cli: Group report command args into ReportArgs (clippy too_many_arguments under -D warnings) (@ShixiangWang)
- Clippy-clean chat degradation buffer + audit module layout (@ShixiangWang)
- cli: Cluster submit renders via ExecutorBackend; P1 acceptance tests (#78) (@ShixiangWang)
- web: Remove legacy handlers, legacy router, and 20-user simulation tests (5k+ lines) (@ShixiangWang)
- web: Delete legacy handlers modules and 20-user simulation tests; hpc_status moved to observability (@ShixiangWang)
- frontend: Delete dead Runs page and SSEClient; fix lint in new components (@ShixiangWang)
Styling#
- web: Breathing running badge + last hardcoded color in Share (@ShixiangWang)
- web: Replace hardcoded hex colors with theme tokens (@ShixiangWang)
- web: Rustfmt hpc.rs probe condition (CI fmt gate) (@ShixiangWang)
- Type alias for the per-user AI row (clippy complex-type) (@ShixiangWang)
- Type alias for the per-user AI row (clippy complex-type) (@ShixiangWang)
- Clippy — clamp, let-chains, vec literals, type aliases, Option::map (workspace clean except #83 WIP) (@ShixiangWang)
- Cargo fmt normalization (config loader, preview handler, dry-run test) (@ShixiangWang)
- web: Collapse nested if in preview extraction (clippy -D warnings); docs: remote-glob wording (#67) (@ShixiangWang)
- Drop blank lines left by the audit tests-module move (@ShixiangWang)
- ai: Drop duplicate test import (@ShixiangWang)
- web: Drop needless into on strings (@ShixiangWang)
- ai: Collapse nested ifs in stream usage capture (@ShixiangWang)
Testing#
- Update constructors for the enriched validate envelope; hpc route now requires auth in hpc mode (#82 P0-5) (@ShixiangWang)
- web: Initialize both DB layers in router tests (audit middleware from #79 inserts via legacy pool) (@ShixiangWang)
- BackendDriver checkpoint re-entry — round-2 execution via mock scheduler (#78) (@ShixiangWang)
- Mock SLURM scheduler fixtures for cluster CI (issue #78/#74) (@ShixiangWang)
- Parity contract matrix guards run/dry-run consistency (issue #77) (@ShixiangWang)
- Upsert AI config row in restore test (parallel-safe) (@ShixiangWang)
- Merge scripted-provider chat scenarios into one sequential test (registry is process-wide) (@ShixiangWang)
- Async-aware lock for scripted-provider chat tests (@ShixiangWang)
- Pipelines page title in legacy specs (@ShixiangWang)
- Oauth state test self-initializes the infra pool (was order-dependent) (@ShixiangWang)
- Root web integration expects completed status vocabulary (@ShixiangWang)
0.11.0 — 2026-08-13#
Bug Fixes#
- Embed template gallery from crate-local templates/ so cargo publish works (issue #76 P1-3 follow-up) (@ShixiangWang)
- Scientific review of gallery examples — RG escaping, env mismatches, (@ShixiangWang)
- Scientific review of top-level examples — read groups, DAG races, env mismatch (@ShixiangWang)
- Embed the template gallery in the binary — template works from installed releases (issue #76) (@ShixiangWang)
- Web run flags reach the CLI executor — issue #69 follow-up (@ShixiangWang)
- AI provider robustness — tool-call repair, overflow recovery, bounded results (issue #73, Phase 1 + 2.4) (@ShixiangWang)
- Checkpoint reuse validates input manifests — issue #72 (@ShixiangWang)
- Deep checks respect --workdir; drop duplicated #70 lock test (@ShixiangWang)
- Allow too_many_arguments on dry_run_command (clippy -D warnings) (@ShixiangWang)
- Resolve readiness paths against the workflow dir, not the process CWD (issue #63) (@ShixiangWang)
- Actionable error for run flags swallowed by trailing overrides (issue #71) (@ShixiangWang)
- MCP tool bridges register under def name (issue #61) (@ShixiangWang)
- Avoid panic on non-UTF-8 CLI arguments (@ShixiangWang)
- Post-merge review of #59 — bundle manifest source, tempdir cleanup, honest tests (@ShixiangWang)
- Bundle gate probes stdin, and lint test code in CI (@andrewbudge)
- Move modules deserializer before test module (items after a test module lint) (@ShixiangWang)
- Examples — GATK best-practice alignment flags and BQSR known-sites (@ShixiangWang)
- Web — run persistence, export by ID, SSE completion, legacy DB migration (@ShixiangWang)
- Cli — JSON output, help texts, report --ai fallback, pixi env create (@ShixiangWang)
- Ai knowledge — graph integrity test, dangling edge, honest counts (@ShixiangWang)
- Engine — resource-group fast-fail, deferred chunk cleanup, config-var expansion (@ShixiangWang)
- Transform operator — chunk extension, GatherVcfs args, cleanup implementation (@ShixiangWang)
- Scientific correctness of examples and workflow-format docs (@ShixiangWang)
- Gallery examples — sample expansion and output paths in multiomics & scRNA-seq (@ShixiangWang)
- Resolve_config_list splits comma-joined strings; samples_list usable in expand_inputs (@ShixiangWang)
- Rnaseq gallery — multiqc must not depend on index_bam (@ShixiangWang)
- Diff now detects defaults, pairs, and sample group changes (@ShixiangWang)
- Dry-run -j suggestion capped by DAG width — professional parallelism advice (@ShixiangWang)
- Resource pool waits for availability instead of failing; professional -j suggestion (@ShixiangWang)
- Dry-run lists rules in parallel-group order, not arbitrary topo order (@ShixiangWang)
- Apply_defaults must respect rule-level resources.threads/memory (@ShixiangWang)
- Deduplicate downstream rules in graph tree view (@ShixiangWang)
CI/CD#
- Tolerate already-synced versions on re-tag (sync-version idempotency) (@ShixiangWang)
- Install release target into the pinned toolchain (macOS builds) (@ShixiangWang)
Documentation#
- Changelog for v0.11.0 — repository workflows, checkpoint-aware dry-run, AI explain/robustness, command consolidation (@ShixiangWang)
- Update subcommand count to 29 in README, CONTRIBUTING, AGENTS (issue #76 follow-up) (@ShixiangWang)
- Update guides for command consolidation — status timing view, export compose, removed commands, profile mechanism (issue #76) (@ShixiangWang)
- Unify gallery embed style and ship the referenced environment specs (@ShixiangWang)
- Cross-link dry-run checkpoint preview from run pilot flow and DAG skip checklist (issue #66 follow-up) (@ShixiangWang)
- Mark rule hooks and optional as parsed-but-not-enforced (issue #75) (@ShixiangWang)
- Fix 'ai status' references after ai action-space change (issue #65) (@ShixiangWang)
- Ai explain + provider robustness reference (issues #65, #73) (@ShixiangWang)
- Sync #72 input-manifest invalidation into troubleshooting, DAG skip guide, and glossary (@ShixiangWang)
- Cross-link validate/env to test --deep (D002/D003 cover env files and PATH binaries, issue #64 follow-up) (@ShixiangWang)
- Finish #68/#70 doc sweep — validate path base, clean lock guard, run --workdir scenario (@ShixiangWang)
- Complete help descriptions for every command, subcommand, and argument (@ShixiangWang)
- Sync #63 readiness + --samples ready into run/dry-run/test/cohort how-to (@ShixiangWang)
- Link gallery concept explanations to reference docs (@ShixiangWang)
- Explain expand_inputs in WGS gallery with reference links (@ShixiangWang)
- Sync config-change invalidation into run/resume/status/architecture/workflow-format (@ShixiangWang)
- Teach wildcards fan-out vs fan-in for beginners (@ShixiangWang)
- Sync #60 pilot workflow into quickstart, cohort how-to, and wgs gallery (@ShixiangWang)
- Use sk-
placeholder form for API keys (no bare sk-... patterns) (@ShixiangWang) - Run --bundle gate semantics — non-interactive sessions and --json require --yes; fix --profile row (@ShixiangWang)
- Comprehensive audit — sync all pages with engine behavior and science (@ShixiangWang)
- Sync gallery pages with scientific fixes in examples (@ShixiangWang)
- How-to audit — align 12 guides with engine behavior; fix example resources (@ShixiangWang)
- Gallery index — clarify graph (template) vs dry-run (expanded) DAG (@ShixiangWang)
- Explain {input} vs {input[0]} equivalence and when to use each (@ShixiangWang)
- Clarify gather routing is declared via scatter.gather, not inferred (@ShixiangWang)
- Document gather inference reliability in complex scatter-gather (@ShixiangWang)
- Fix multiomics -j advice — resource pool schedules by thread capacity (@ShixiangWang)
- Unify -j values with professional suggestion; clarify optional input/output (@ShixiangWang)
- Note ToolRegistry non-Clone limitation in create_context (@ShixiangWang)
- Document four embedded AI knowledge sources in ai-cli.md (@ShixiangWang)
- Document env create --ai in AI CLI command reference (@ShixiangWang)
- Environment-management — add missing mamba and modules sections (@ShixiangWang)
- Rewrite variant-calling tutorial with professional paired tumor-normal design (@ShixiangWang)
- Quickstart — output directories are auto-created, remove mkdir boilerplate (@ShixiangWang)
- Remove stale INFO log line from quickstart run output (@ShixiangWang)
- Extend custom-scripts example to two chained script rules (@ShixiangWang)
- Rewrite custom-scripts tutorial with runnable example and params explanation (@ShixiangWang)
- Multiqc aggregates only the two QC rounds; clarify parallel scheduling (@ShixiangWang)
- Fix tutorial DAG — multiqc had no real dependencies with directory inputs (@ShixiangWang)
- Move Wildcard Patterns admonition out of TOML code block (@ShixiangWang)
- Fix markdown list rendering in quickstart web UI section (@ShixiangWang)
Features#
- Repository workflows — pull/run clone git repos directly (no bundle required) (@ShixiangWang)
- Consolidate commands — status absorbs history, export gains compose, remove history/package/profile/watch (issue #76) (@ShixiangWang)
- Value recovery from the dead-code audit — optional rules, hook (@ShixiangWang)
- Dry-run checkpoint preview — rerun blast radius and protected scope (issue #66) (@ShixiangWang)
- Web runs link to saved pipelines with persistent workdirs — issue #69 (@ShixiangWang)
- Ai explain — three-layer workflow explanation (issue #65) (@ShixiangWang)
- --workdir on dry-run/test/clean/report/resume; validate uses workflow dir (issue #68) (@ShixiangWang)
- Workdir lock prevents concurrent-run checkpoint races (issue #70) (@ShixiangWang)
- Test --deep pipeline health checks (issue #64) (@ShixiangWang)
- Checkpoint remembers its workdir; resume re-runs from it (issue #68) (@ShixiangWang)
- Sample readiness + --samples ready for incremental data arrival (issue #63) (@ShixiangWang)
- Config-change impact analysis — precise checkpoint invalidation (issue #62) (@ShixiangWang)
- Custom skills Phase 2 (MCP tool skills) + Phase 3 (SKILL.md) — issue #61 (@ShixiangWang)
- Banner header for run logs; fix help art glyphs (@ShixiangWang)
- User-defined custom skills — Phase 1 secure minimal loop (issue #61) (@ShixiangWang)
- AI preflight & pilot summary (issue #60 Phase 2) — scientific constraints + scale-up projection (@ShixiangWang)
- Pilot subset (--samples) and forced re-run (--rerun) for fast-fail exploration (@ShixiangWang)
- Graph --expanded shows runtime DAG; simplify wgs-germline config (@ShixiangWang)
- Report --ai adds plain-language result interpretation (@ShixiangWang)
- Env create --ai supports pixi backend; ToolRegistry made shareable (@ShixiangWang)
- Embed pipeline knowledge graph (78 skills, 470 transitions) + token-cost optimizations (@ShixiangWang)
- Embed 562 bioSkills Agent Skills + lookup_skill AI tool (@ShixiangWang)
- Embed full Bioconda CLI database (6103 tools) for AI tool lookup (@ShixiangWang)
- Add help text to all CLI arguments and options (@ShixiangWang)
- AI-powered environment spec generation (env create --ai) (@ShixiangWang)
Other Changes#
- Merge PR #59: fix bundle confirmation gate + lint test code in CI (@ShixiangWang) (#59)
Refactoring#
- Gallery docs embed via snippet includes; CLI embeds all 15 templates (@ShixiangWang)
- Single-tier examples — top-level workflows folded into the gallery (11–15) (@ShixiangWang)
- Remove 74 dead items across the workspace — audited symbol-by-symbol (@ShixiangWang)
- Truncate fingerprint-mismatch list in the config-change summary (@ShixiangWang)
- Finish issue #61 review cleanups (@ShixiangWang)
- Change system resource log from INFO to DEBUG, display memory in GB (@ShixiangWang)
Testing#
- Deep verification of embedded knowledge sources + fixes (@ShixiangWang)
0.10.2 — 2026-08-12#
Bug Fixes#
- Use macro-based archive building for format-agnostic publish (@ShixiangWang)
- Reserve signatures in manifest, harden bundle extraction path (@andrewbudge)
- Resolve clippy lints (collapsible_if, needless_borrow, unused vars) (@ShixiangWang)
- Correct Andrew Budge GitHub username in contributors section (@ShixiangWang)
- Wgs_germline combine_gvcfs sample expansion (@ShixiangWang)
- Modernize examples and sync gallery docs (@ShixiangWang)
- Broken transform chunk paths and wgs_germline sample source (@ShixiangWang)
Documentation#
- Add --format, --bundle, --yes to publish.md and run.md (@ShixiangWang)
- Document pluggable report section system in report.md and workflow-format.md (@ShixiangWang)
- Comprehensive audit and fix of all documentation (83 issues) (@ShixiangWang)
- Modernize homepage examples and fix capability claims (@ShixiangWang)
- Add contributors section to README with GitHub-style avatar display (@ShixiangWang)
Features#
- Archive format abstraction (.tar.gz + .tar.zst), pull docs, confirmation gate (@ShixiangWang)
- Add bundle execution confirmation gate with --yes flag (@ShixiangWang)
- Add per-rule resource summary to bundle manifest (@ShixiangWang)
- Pluggable report section system with domain auto-detection (@ShixiangWang)
- Compose support, conda package specifiers, clinical compliance report (@ShixiangWang)
0.10.1 — 2026-08-11#
Bug Fixes#
- Cluster partition rendering, forbid(unsafe) in AI crate, and env detection (@ShixiangWang)
- AI analysis precision, debug expansion, and keep_going propagation (@ShixiangWang)
- AI Companion prompt syntax, token tracking, and setup UX (@ShixiangWang)
Documentation#
- Clarify web UI entry point in Quick Start and Deployment sections (@ShixiangWang)
- Move Three-Mode Deployment after Web API section (@ShixiangWang)
- Add transform-operator gallery page for 10th workflow (@ShixiangWang)
- Simplify README, fix stale facts across all documentation (@ShixiangWang)
- System check and optimize README.md (@ShixiangWang)
- Comprehensive DAG execution documentation overhaul (@ShixiangWang)
Features#
- PDF report support, secret scanning, Vega-Lite dashboard, and security docs (@ShixiangWang)
Performance#
- Event-driven fine-grained scheduler replaces group barriers (@ShixiangWang)
0.10.0 — 2026-08-10#
Bug Fixes#
- Async validate_command to prevent nested runtime crash (@ShixiangWang)
Documentation#
- Add ai test/setup subcommands to command reference (@ShixiangWang)
- Update all project docs + CI for oxo-flow-ai crate (@ShixiangWang)
- Finalize design spec — all phases verified (@ShixiangWang)
- Complete AI CLI command reference + E2E verification (@ShixiangWang)
- Update design spec with simplification phase (@ShixiangWang)
- Finalize design spec — all 5 phases complete (@ShixiangWang)
- Update AI CLI guide + design spec for Phases 1-3 (@ShixiangWang)
- Update design spec with Phase 2 implementation log (@ShixiangWang)
- AI-native CLI comprehensive design document (@ShixiangWang)
Features#
- Oxo-flow ai test + ai setup + ai status subcommands (@ShixiangWang)
- Verify DeepSeek both API formats + update docs (@ShixiangWang)
- AiRuntime wired as single entry point for template command (@ShixiangWang)
- L3 Agent + scope config + skill discovery wired into commands (@ShixiangWang)
- AI session tracking + ai status command (@ShixiangWang)
- AI auto-detection from workflow [ai] section (@ShixiangWang)
- Professional AI prompts + debug --ai + lint --ai (@ShixiangWang)
- Phase 5 — MCP bridge + Skill system (@ShixiangWang)
- Phase 4 — scope-level AI config + AI plugin system (@ShixiangWang)
- Phase 3 — AI error recovery on run failures (@ShixiangWang)
- Phase 2 — AI-powered dry-run and validate analysis (@ShixiangWang)
- Web crate migration + AI CLI documentation (@ShixiangWang)
- Phase 1 — oxo-flow-ai crate + AI-powered template generation (@ShixiangWang)
Maintenance#
- Fix ci audit step with --no-fetch fallback (@ShixiangWang)
- Cargo update — semver-compatible dependency bumps (@ShixiangWang)
0.9.4 — 2026-08-09#
Features#
- Typed config values + full ConfigDef runtime enforcement (@ShixiangWang)
- Enforce ConfigDef choices validation + sensitive masking (@ShixiangWang)
0.9.3 — 2026-08-09#
Bug Fixes#
- Support arguments.* references in when conditions (@ShixiangWang)
- Propagate rule failures transitively, count skips once (@andrewbudge)
- Propagate rule failures transitively, count skips once (@andrewbudge)
- Sanitize remaining error leaks in execution and workflow handlers (@ShixiangWang)
- Sanitize error messages, dynamic share URLs, deployment tests (@ShixiangWang)
- Auth session persistence and FK constraint (@ShixiangWang)
- API maturity, accessibility, and cross-page state persistence (@ShixiangWang)
- Security hardening and web UI production readiness (@ShixiangWang)
Features#
- PostgreSQL backend activation + OpenAPI 3.1 spec regeneration (@ShixiangWang)
Maintenance#
- Fmt + clippy compliance for [arguments]→[config] merge (@ShixiangWang)
- Repository cleanup — fmt, port consistency, stale files (@ShixiangWang)
Other Changes#
- PR #56 — fix transitive failure propagation and skip counting (@ShixiangWang) (#56)
- PR #56 — fix transitive failure propagation and skip counting (@ShixiangWang)
Refactoring#
- Finish [arguments]→[config] merge — tests, CLI flags, format (@ShixiangWang)
- Merge [arguments] into upgraded [config] block (@ShixiangWang)
Testing#
- Comprehensive browser UI + real-world scenario tests (@ShixiangWang)
- Multi-user lifecycle Playwright tests + PostgreSQL backend (@ShixiangWang)
0.9.2 — 2026-08-08#
Bug Fixes#
- Add references property to CLI-bundled schema (@ShixiangWang)
Documentation#
- Comprehensive sample/pair discovery documentation (@ShixiangWang)
Features#
- Optional pair control for tumor-only CNV and unmatched scenarios (@ShixiangWang)
- Comprehensive sample/pair discovery with --sample flag (@ShixiangWang)
- Comprehensive index auto-build with 9 types + samples_list (@ShixiangWang)
- Integrate [[references]] with Reference Discovery API (@ShixiangWang)
- Add [[references]] auto-index building to engine (@ShixiangWang)
0.9.1 — 2026-08-07#
Documentation#
- Update all documentation for #50 (workflow args) and #51 (publish) (@ShixiangWang)
Features#
- Add [arguments] block with --arg CLI flag for workflow parameters (@ShixiangWang)
0.9.0 — 2026-08-07#
Bug Fixes#
- Respect --target in parallel execution, clean up warnings (@ShixiangWang)
- Remove redundant references in format! arguments (#54) (@Copilot) (#54)
- Drop redundant borrow in ai_provider Authorization header (#53) (@andrewbudge) (#53)
- Publish now scans [rules.environment] for env files (#52) (@andrewbudge) (#52)
- Fail fast when a rule exceeds the --max-memory/--max-threads cap (#49) (@andrewbudge) (#49)
- Make 'run' output honest on non-TTY and under --keep-going (#48) (@andrewbudge) (#48)
Features#
- Add --with-lockfiles flag to publish for conda reproducibility (@ShixiangWang)
- Record container refs in manifest, warn on missing env files (@ShixiangWang)
- Add --bundle flag to run, add pull subcommand (@ShixiangWang)
- Rewrite publish to emit verifiable .tar.zst archive (@ShixiangWang)
- Enable true parallel execution with -j flag (@ShixiangWang)
- Wire output validation, add MambaBackend, fix container CWD (@ShixiangWang)
Other Changes#
- Update Cargo.lock (@ShixiangWang)
Refactoring#
- Remove unused per-rule workdir field (@ShixiangWang)
Testing#
- Add edge case tests for publish/run --bundle/pull (@ShixiangWang)
0.8.1 — 2026-06-22#
Bug Fixes#
- Optimize Dockerfile and standardize project email to w_shixiang@163.com (@ShixiangWang)
- Remove duplicate HTML document and correctly place Web API section (@ShixiangWang)
Documentation#
- Add oxo-flow bioRxiv preprint to citation sections (@ShixiangWang)
- Simplify CLI/API to concise intro + doc links (@ShixiangWang)
- Comprehensive CLI (31cmds) + API (48eps) with search, collapse, categories (@ShixiangWang)
- Tone down clinical-grade reporting → reproducible/reporting (@ShixiangWang)
Performance#
- Avoid sysinfo System::new_all() when only one metric is needed (#46) (@andrewbudge) (#46)
0.8.0 — 2026-06-14#
Bug Fixes#
- Resolve all audit findings — Makefile tabs, suite.py shadowing, version refs, Snakemake (@ShixiangWang)
Documentation#
- Add CONTRIBUTING.md and SECURITY.md (@ShixiangWang)
- Overhaul landing page — AI Companion, current API, React stack (@ShixiangWang)
- Overhaul README — AI Companion, current API, clean duplicates (@ShixiangWang)
- Deployment guide, AI provider env vars, UI polish (@ShixiangWang)
- Add cloud storage reference doc, update LIMITATIONS.md and nav (@ShixiangWang)
Features#
- AI config API, runtime provider switching, Docker deployment, UI polish (@ShixiangWang)
- Docker deployment, custom AI URLs, frontend serving (@ShixiangWang)
- AI provider abstraction with Claude/OpenAI/Ollama support (@ShixiangWang)
- AI-native pipeline platform with structured results and web frontend (@ShixiangWang)
- core: Implement real S3/GCS storage backends, expand webhook & plugin tests, add benchmarks (@ShixiangWang)
Maintenance#
- Add remaining frontend config files (@ShixiangWang)
Other Changes#
- Feat/v0.8 deterministic core (#45) (@ShixiangWang) (#45)
- Add macro/comparative benchmarks, bump version to 0.8.0 (@ShixiangWang)
Performance#
- bench: Restructure benchmarks into modular suite with 35 micro-benchmarks (@ShixiangWang)
0.7.0 — 2026-05-25#
Bug Fixes#
- Resolve doc/code discrepancies found in consistency audit (@ShixiangWang)
- Use serde serialization for format_workflow, fix example workflows (@ShixiangWang)
- Resolve all remaining code audit issues across core, web, and plugin (@ShixiangWang)
- --as-include skips E010, fix double GPU flag, escape report HTML, respect rule retries (@ShixiangWang)
- Respect rule-level retries field in execution retry loop (@ShixiangWang)
- Complete security patterns, validate export/package format args (@ShixiangWang)
- Resolve 5 feature gaps from production readiness audit (@ShixiangWang)
- Wildcard constraints filter instead of fail, optional rules warn on missing input (@ShixiangWang)
- Improve target resolution UX and environment listing, fix CI issues (@ShixiangWang)
- web: Resolve 6 bugs from production readiness audit (@ShixiangWang)
- Resolve CLI unwrap risks and Core config expect improvements (@ShixiangWang)
- web: Comprehensive test-driven fixes for 9 issues found (@ShixiangWang)
- container: Add CMD to Dockerfile for better UX (@ShixiangWang)
- container: Add cargo install + fallback to Singularity def oxo-flow installation (@ShixiangWang)
- container: Use cargo install + GitHub release fallback for Dockerfiles (@ShixiangWang)
- web: Prevent XSS via workflow name in onclick handlers (@ShixiangWang)
Documentation#
- Complete rewrite of JSON Schema, fix all CLI and format doc gaps (@ShixiangWang)
- Add missing rule fields, env_groups, genome_build to workflow format spec (@ShixiangWang)
- web: Add multi-user web system design specification (@ShixiangWang)
- web: Add security model and DELETE endpoint to web API docs (@ShixiangWang)
Features#
- Light theme, license upload web UI, and CLI license command (@ShixiangWang)
- web: Embed default academic license with commercial notice (@ShixiangWang)
- web: Comprehensive multi-user web system with User Mgmt, HPC, Templates (@ShixiangWang)
- web: Add HPC scheduler integration for Slurm/PBS monitoring (@ShixiangWang)
- web: Add scheduled workflow runs with cron support (@ShixiangWang)
- web: Add P2 Enterprise Governance and Template Library features (@ShixiangWang)
- web: Modularize handlers and add maud templates (@ShixiangWang)
- web: Add optional id field to SaveWorkflowRequest for upsert support (@ShixiangWang)
- container: Add oxo-flow binary installation to Dockerfile and Singularity def (@ShixiangWang)
- web: Add New Workflow button, auto-clear save name, UX polish (@ShixiangWang)
- web: Add Dockerfile export button and modal to editor (@ShixiangWang)
- web: Replace prompt() login with modal sign-in form (@ShixiangWang)
- web: Add workflow deletion, SSE live updates, and editor templates (@ShixiangWang)
- web: Add CLI arg parsing to web binary, update full API docs (@ShixiangWang)
- web: Add GET /api/workflows/saved/{id} endpoint and Load-to-Editor (@ShixiangWang)
- web: Professional dark-themed Command Center SPA frontend (@ShixiangWang)
- web: Full workflow lifecycle API, workspace isolation, and 20-user simulation (@ShixiangWang)
Maintenance#
- Fix all 16 unused-variable warnings in simulation_20users (@ShixiangWang)
- Fix make ci - remove orphan comments, fix clippy warnings (@ShixiangWang)
- web: Remove 15 orphan doc comments after handler dedup (@ShixiangWang)
- Remove e2e-playwright test suite (@ShixiangWang)
- Update e2e gitignore for logs and lock file (@ShixiangWang)
- Update Cargo.lock for web crate clap dependency (@ShixiangWang)
Refactoring#
- web: Remove 1101 dup lines, dead maud templates, partials (@ShixiangWang)
- web: Remove 31 duplicate handlers, add DAG viz + template CRUD UI (@ShixiangWang)
- web: Split frontend into index.html + app.js (@ShixiangWang)
Testing#
- web: Add Playwright E2E tests for multi-user web system (@ShixiangWang)
- web: Add 20 real-world user scenario tests from expert perspectives (@ShixiangWang)
- container: Add tests for oxo-flow install in Dockerfile and Singularity def (@ShixiangWang)
- web: Add E2E lifecycle tests for save/load/delete and full run cycle (@ShixiangWang)
0.6.1 — 2026-05-24#
Bug Fixes#
- Replace silent checkpoint save failures with tracing warnings (@ShixiangWang)
- Resource detection, checkpoint skip, error cascade, and validation improvements (@ShixiangWang)
- Workspace tests use tempdir for CI reliability (@ShixiangWang)
- Allow ':' in rule names and add include E2E tests (@ShixiangWang)
- Parse conda env name from YAML content, not file stem (@ShixiangWang)
Documentation#
- Fix README accuracy, serve base_path passthrough, and broken links (@ShixiangWang)
- Add missing history command reference page (@ShixiangWang)
- Update plugin-system.md to reflect full implementation (@ShixiangWang)
- Fix plugin-system.md to reflect actual implementation status (@ShixiangWang)
- Update command count to 31 (added history command) (@ShixiangWang)
- Add CLI reference pages for all 29 commands (@ShixiangWang)
Features#
- Subprocess-based dynamic plugin loading (@ShixiangWang)
- Full plugin system with discovery, TOML integration, signatures (@ShixiangWang)
- Retry persistence, plugin traits, i18n reports, input tests (@ShixiangWang)
- Output verification with sizes, watch --run flag (@ShixiangWang)
- History command, clean confirmation, plugin design doc (@ShixiangWang)
- Dry-run execution hint, deadlock diagnosis improvement (@ShixiangWang)
- Auto-create output dirs, watch dry-run, error test coverage (@ShixiangWang)
- Progress ETA, dry-run input status, colored diff, error tests (@ShixiangWang)
- Dry-run resource summary, output verification, deprecated cleanup (@ShixiangWang)
- Input file existence check and --quiet banner suppression (@ShixiangWang)
- Enhance dry-run output and update CITATION.cff (@ShixiangWang)
- Transform operator tests and complete priority items (@ShixiangWang)
- Resource exhaustion hints and enhanced test command (@ShixiangWang)
- Env error hints, web crate tests, and improved init template (@ShixiangWang)
- Improve oxo-flow init template with shell reference and China mirrors (@ShixiangWang)
Maintenance#
- Fix stale version references and documentation consistency (@ShixiangWang)
Other Changes#
- Update (@ShixiangWang)
0.6.0 — 2026-05-21#
Bug Fixes#
- Landing page rendering, badges, and stale content (@ShixiangWang)
- Publish command crash and documentation accuracy (@ShixiangWang)
Documentation#
- Add BLIT citation and optimize landing page badges (@ShixiangWang)
- Refactor clinical reporting and synchronize CLI commands in README (@ShixiangWang)
Other Changes#
- Test/real data validation (#43) (@ShixiangWang) (#43)
0.5.5 — 2026-05-20#
Bug Fixes#
- Resolve bugs found by 30-user simulation testing (@ShixiangWang)
- Resolve critical bugs, integrate security code, add tests, update deps, and fix README (@ShixiangWang)
Documentation#
- Fix remaining stale subcommand count and add cargo install instruction (@ShixiangWang)
Features#
- Auto-create output directories and add dry-run shell safety checks (@ShixiangWang)
Other Changes#
- Consolidate AI agent docs into AGENTS.md (@ShixiangWang)
- Update README.md (@ShixiangWang)
Styling#
- Fix cargo fmt formatting in output directory creation (@ShixiangWang)
0.5.4 — 2026-05-19#
CI/CD#
- Remove Venus from build/publish/release pipeline (@ShixiangWang)
Documentation#
- Add Venus extraction design spec (@ShixiangWang)
Maintenance#
- Completely remove Venus from oxo-flow repository (@ShixiangWang)
- Remove Venus CLI integration tests, gitignore oxo-flow-venus (@ShixiangWang)
- Remove Venus integration tests after extraction (@ShixiangWang)
- Extract Venus into standalone repository oxo-flow-venus (@ShixiangWang)
Other Changes#
- Update Cargo.lock (@ShixiangWang)
0.5.3 — 2026-05-18#
Bug Fixes#
- Resolve clippy errors for Rust 1.95 and update test (@ShixiangWang)
- Include schema file within CLI crate to fix cargo package build (#42) (@Copilot) (#42)
Documentation#
- Add missing documentation for optional rules, directory input, and E010 test (@ShixiangWang)
- Document new features in README (@ShixiangWang)
- Add implementation plan for oxo-flow optimizations (@ShixiangWang)
- Add oxo-flow optimizations design spec (@ShixiangWang)
- Add circRNA pipeline implementation plan (@ShixiangWang)
- Add circRNA pipeline design specification (@ShixiangWang)
Features#
- rule: Add Dir variant to FilePatterns for directory input (@ShixiangWang)
- executor: Implement optional rule skip logic (@ShixiangWang)
- rule: Add optional field for skip-on-missing behavior (@ShixiangWang)
- format: Add validation for undefined env_group references (@ShixiangWang)
- config: Add env_groups for shared environments (@ShixiangWang)
- executor: Add auto-scaling helper functions (@ShixiangWang)
- rule: Add AutoScale type for resource auto-scaling (@ShixiangWang)
- config: Add reference_dir field with auto-derivation (@ShixiangWang)
- cli: Implement --as-include validation mode (@ShixiangWang)
- cli: Add --as-include flag to validate command (@ShixiangWang)
- core: Enhance clinical workflow support and permissive wildcard expansion (@ShixiangWang)
Maintenance#
- Fix clippy warnings and ensure CI passes (@ShixiangWang)
Testing#
- config: Add tests for reference_dir derivation (@ShixiangWang)
- cli: Add tests for --as-include validation (@ShixiangWang)
0.5.2 — 2026-05-18#
Bug Fixes#
- Suppress rustls-webpki audit warnings from aws-sdk-s3 transitive deps (@ShixiangWang)
- Allow $(…) in shell templates; validate wildcard injection; fix dry-run when; fix example workflows (#40) (@Copilot) (#40)
Documentation#
- Audit and clean up documentation, resolve implementation inconsistencies (@ShixiangWang)
- Clean up and fix issues in all .md files (#41) (@Copilot) (#41)
Features#
- 100% resolution of 40-user comprehensive testing — security, storage, CLI, docs (@ShixiangWang)
- Achieve 100% resolution of 100-user comprehensive review (@ShixiangWang)
- Resolve top 10 priority actions from 100-user comprehensive review (@ShixiangWang)
- Switch to rustls, optimize hot paths, update docs and deps (@ShixiangWang)
- Comprehensive 30-expert review, dependency upgrades, performance optimizations, and documentation updates (@ShixiangWang)
- Implement Phase 9.6 roadmap items and performance optimizations (@ShixiangWang)
- 30-expert user journey review, performance optimizations, and documentation improvements (@ShixiangWang)
- Implement named inputs and outputs for rules (@ShixiangWang)
- Address simulated user reviews and comprehensive optimization (@ShixiangWang)
Maintenance#
- Fix lint and formatting issues from CI (@ShixiangWang)
Other Changes#
- Add auth, CORS & schema; remove reviews (@ShixiangWang)
Performance#
- Optimize wildcard expansion engine and consolidate Phase 9.6 (@ShixiangWang)
0.5.1 — 2026-05-17#
Bug Fixes#
- cli: Add 'default' alias for profile show and 'check' alias for config stats (@ShixiangWang)
- docs: Add pairs_file/pairs_pattern/sample_groups_file to how-to guides (@ShixiangWang)
- docs: Use absolute GitHub URLs for example workflow links (@ShixiangWang)
Documentation#
- Add metadata field to pairs table documentation (@ShixiangWang)
Features#
- batch: Implement true parallel execution with Semaphore (@ShixiangWang)
- config: Add pairs_pattern for auto-discovering pairs from filesystem (@ShixiangWang)
- config: Add pairs_file and sample_groups_file support (@ShixiangWang)
- ci: Auto-update docs version references on version bump (@ShixiangWang)
0.5.0 — 2026-05-16#
Bug Fixes#
- Correct cargo-audit config format (@ShixiangWang)
- Address all issues from 30-expert review (@ShixiangWang)
- venus: Add interpreter_map to generated workflow metadata (@ShixiangWang)
- security: Relax shell validation for &&, ||, and pipes (@ShixiangWang)
- executor: Remove duplicate resource release on failure (@ShixiangWang)
- Simplify build_script_command to avoid clippy warning (@ShixiangWang)
CI/CD#
- Block pipeline on security audit failures (@ShixiangWang)
Documentation#
- Update version references from 0.4.1 to 0.4.2 (@ShixiangWang)
- Update CLI subcommand count and add batch references (@ShixiangWang)
- Add 30-expert comprehensive assessment report (@ShixiangWang)
- Docs update (@ShixiangWang)
- Add 30-expert assessment report (@ShixiangWang)
- Improve quickstart graph visualization section (@ShixiangWang)
- Fix duplicate [rules.resources] TOML syntax error (@ShixiangWang)
- Add script execution and all missing Rule fields to workflow format reference (@ShixiangWang)
- Add non-shell language support design spec (@ShixiangWang)
- Add resource management section to workflow format reference (@ShixiangWang)
- Create resource tuning best practices guide (@ShixiangWang)
- Add resource management implementation plan (@ShixiangWang)
- Add resource management review design spec (@ShixiangWang)
- design: Add transform operator design spec (@ShixiangWang)
Features#
- cli: Add batch subcommand for parallel task execution (@ShixiangWang)
- Complete rule lifecycle hooks, environment injection, and custom interpreters (@ShixiangWang)
- config: Fix namespace prefixing for depends_on in included rules (@ShixiangWang)
- cli: Add progress bar for run command execution tracking (@ShixiangWang)
- cli: Add --pending-timeout option to cluster submit (@ShixiangWang)
- cli: Add --orphans option to clean command (@ShixiangWang)
- lint: Add hook command safety validation (W020-W022) (@ShixiangWang)
- executor: Implement script execution with interpreter detection and sequential shell+script (@ShixiangWang)
- Add interpreter and interpreter_map fields for script execution (@ShixiangWang)
- Add disk space pre-flight check and resource summary (@ShixiangWang)
- scheduler: Implement ResourceHint memory estimation (@ShixiangWang)
- executor: Add structured logging for resource allocation (@ShixiangWang)
- cluster: Enhance GPU spec translation for SLURM/PBS/SGE (@ShixiangWang)
- scheduler: Add system capacity validation with warnings (@ShixiangWang)
- executor: Add process group timeout and cleanup on failure (@ShixiangWang)
- executor: Use sysinfo for cross-platform memory detection (@ShixiangWang)
- Add sysinfo, nix, fs2 dependencies for resource management (@ShixiangWang)
- core: Implement unified transform operator for scatter-gather (@ShixiangWang)
Maintenance#
- Ignore hello.txt from example workflow output (@ShixiangWang)
Other Changes#
- Remove Windows CI job and platform references (@ShixiangWang)
- Update README.md (@ShixiangWang)
- Add oxo-flow logo SVGs (@ShixiangWang)
- Add cargo audit configuration (@ShixiangWang)
- executor: Validate interpreter paths for safety (@ShixiangWang)
- executor: Block absolute paths outside workdir (@ShixiangWang)
- executor: Validate hook commands for injection prevention (@ShixiangWang)
- executor: Add validate_shell_safety to block dangerous patterns (@ShixiangWang)
- Add pre_exec hook and cleanup/resource changes (@ShixiangWang)
Refactoring#
- Add #[must_use] attributes to interpreter functions (@ShixiangWang)
Testing#
- batch: Add comprehensive unit tests and update docs nav (@ShixiangWang)
- executor: Add tests for interpreter detection and script execution (@ShixiangWang)
0.4.2 — 2026-05-16#
Bug Fixes#
- validation: Exempt pairs/sample_groups wildcards from E003 (@ShixiangWang)
- web: Replace panic with graceful error handling in executor (@ShixiangWang)
- cli: Apply defaults and templates in dry-run and debug commands (@ShixiangWang)
- cli: Properly return exit codes on cluster command failures and handle empty checkpoints (@ShixiangWang)
Documentation#
- Fix installation package name and add security limitations (@ShixiangWang)
- Add config get/set commands and explain dependencies metric (@ShixiangWang)
- Update outdated CLI documentation (@ShixiangWang)
Features#
- cli: Add config get and set commands (@ShixiangWang)
Other Changes#
- Update README.md (@ShixiangWang)
0.4.1 — 2026-05-16#
Bug Fixes#
- executor: Implement retry loop and hooks execution (@ShixiangWang)
0.4.0 — 2026-05-16#
Bug Fixes#
- Expand placeholders in cluster submit scripts (@ShixiangWang)
- Address critical bugs from user simulation testing (@ShixiangWang)
- Remove unused helper functions and fix unused_mut warning (@ShixiangWang)
- Add async mutex guard for thread-safe database initialization (@ShixiangWang)
- Use process-specific temp database for tests (@ShixiangWang)
- Resolve test database initialization race condition (@ShixiangWang)
- Walltime tests and add 'd' suffix support (@ShixiangWang)
- Add partition field to Resources Default and update tests (@ShixiangWang)
- web: Resolve modal CSS priority issue and complete UI functions (@ShixiangWang)
Documentation#
- Redesign test suite for self-contained execution (@ShixiangWang)
- Add comprehensive test suite with 120+ scenarios (@ShixiangWang)
- Mark junior user review issues as resolved (@ShixiangWang)
Features#
- Implement persistent checkpointing, fix modular includes, and reduce TOML noise (@ShixiangWang)
- Add 81 new comprehensive tests for oxo-flow (145 total, covering CLI, core, Venus, bioinformatics) (#39) (@Copilot) (#39)
- clinical: SHA-256 checksums and provenance persistence (@ShixiangWang)
- validation: Integrate validate_format() and secret scanning (@ShixiangWang)
- container: Add GPU support for container generation (@ShixiangWang)
- cluster: Add GPU directives, per-rule walltime, modules, logs (@ShixiangWang)
- bioinformatics: Address bioinformatics expert review (@ShixiangWang)
- web: Implement critical Web API enhancements (@ShixiangWang)
- Implement advanced user features (@ShixiangWang)
- Address all issues from junior user review and generalize terminology (@ShixiangWang)
- Implement WC-01 tumor-normal pairing, WC-02 sample groups, WF-01 conditional rules (#38) (@Copilot) (#38)
- Make workflow argument optional for run and dry-run commands (@ShixiangWang)
- Target-based partial workflow execution for
runanddry-run(#37) (@Copilot) (#37) - Implement 20-persona dev plan Phase 1 and enhance CLI security/usability (@ShixiangWang)
- Add ANSI colors and fix box alignment in ASCII graph output (@ShixiangWang)
- cli: Add ASCII terminal graph output for oxo-flow graph (@ShixiangWang)
- web: Complete industrial-grade Web UI system (Phase 10) (@ShixiangWang)
Maintenance#
- Audit cleanup and modernization (@ShixiangWang)
- Remove comprehensive test suite document (@ShixiangWang)
- Update Cargo.lock for sha2 dependency (@ShixiangWang)
Other Changes#
- Remove obsolete design docs (@ShixiangWang)
- Add multi-expert design review documents (@ShixiangWang)
0.3.1 — 2026-05-13#
Bug Fixes#
- Address all 32 review issues across security, code quality, pipeline correctness, and docs (#34) (@Copilot) (#34)
Documentation#
Features#
- web: Add request and active workflow metrics with frontend auto-refresh (@ShixiangWang)
Other Changes#
- Add Graphviz install docs and update build cmd (@ShixiangWang)
- Add CLI docs, bump docs to v0.3.0 (@ShixiangWang)
- Update README.md (@ShixiangWang)
- Update README.md (@ShixiangWang)
Refactoring#
- Apply expert review optimizations (@ShixiangWang)
- Remove TODO.md as all items are completed (@ShixiangWang)
0.3.0 — 2026-04-07#
Bug Fixes#
- Template variable substitution, DOT graph labels, and optional env check workflow (@Copilot)
Features#
- Enhance error types, re-export public API, docs update (@Copilot)
- wildcard: Add regex constraint validation and pattern-to-regex file discovery (@Copilot)
- Add reference database tracking, data lineage, and extended job states (@Copilot)
- core: Add GpuSpec, ResourceHint, and new Rule fields with builder methods (@Copilot)
Other Changes#
- Add debug subcommand and project root detection utility (@Copilot)
- Initial plan (@Copilot)
- Initial plan (@Copilot)
Refactoring#
- Address code review comments - use imported HashMap and all_known_backends() (@Copilot)
0.2.0 — 2026-04-06#
Bug Fixes#
- Path traversal protection in touch, overflow protection in duration parsing (@Copilot)
CI/CD#
- Add Windows ARM64, i686 Windows, and ARMv7 Linux release targets (@Copilot)
Features#
- Add Rule depends_on/retry_delay/workdir/hooks, DAG critical_path, format diff/lint codes (@Copilot)
Other Changes#
- Add comprehensive tests for new features (@Copilot)
- Fix summary statistics to match actual opinion counts (89 total) (@Copilot)
- Add comprehensive expert panel evaluation TODO.md (@Copilot)
- Initial plan (@Copilot)
0.1.3 — 2026-04-06#
Bug Fixes#
- Rename venus crate to oxo-flow-venus to avoid crates.io name conflict (@Copilot)
Other Changes#
- Initial plan (@Copilot)
0.1.2 — 2026-04-06#
Bug Fixes#
- Add version to workspace path deps for crates.io publishing (@Copilot)
Other Changes#
- Initial plan (@Copilot)
0.1.1 — 2026-04-06#
CI/CD#
- Replace deprecated macos-13 with macos-latest cross-compiling to x86_64 (@Copilot)
- Fix release and crates.io publish being blocked by cancelled builds (@Copilot)
Documentation#
- Fix number formatting (1 000 → 1,000) (@Copilot)
- Update landing page to accurately reflect repository state (@Copilot)
Other Changes#
0.1.0 — 2026-04-06#
Bug Fixes#
- Address code review feedback - XSS, event handling, credential docs (@Copilot)
- Address code review feedback - improve test comments, fix bismark path, add escape docs (@Copilot)
Build#
- Use workspace version inheritance for all crates, update CI sync-version (@Copilot)
CI/CD#
- Skip heavy build jobs on pull_request events to prevent slow/cancelled runs (@Copilot)
- Optimize CI workflow for reliable builds and crates.io publishing (@Copilot)
Documentation#
- Add missing documentation files referenced in TODO.md (@Copilot)
- Replace TODO.md with comprehensive 30-expert evaluation report (@Copilot)
- Update TODO.md to mark completed items (@Copilot)
- Add complete documentation website with MkDocs Material, landing page, tutorials, command reference, and architecture docs (@Copilot)
- Fix grammar in quickstart tutorial (@Copilot)
- Create complete documentation website (@Copilot)
- Add CHANGELOG, CITATION, CODE_OF_CONDUCT, CONTRIBUTING, cliff.toml, and CI/CD pipeline (@Copilot)
Features#
- web: Add in-memory rate limiter and graceful shutdown (@Copilot)
- container: Add multi-stage builds, rootless support, healthcheck, and docker run command (@Copilot)
- core: Add type system features - WorkflowState, RuleBuilder, newtypes, clinical types (@Copilot)
- Integrate oxo-license, add auth/login system, export/cluster CLI subcommands (@Copilot)
- core: Add comprehensive enhancements to oxo-flow-core (@Copilot)
- Enhance scientific messaging, add gallery to README/docs, add CLI integration tests (@Copilot)
- Add workflow gallery with 8 examples from basic to multi-omics, docs, and tests (@Copilot)
- Remove all Snakemake references, establish innovation-first messaging (@Copilot)
- Add validation, provenance, diagnostics, and DAG metrics improvements (@Copilot)
- web: Add embedded frontend, new API endpoints, SSE, and base path support (@Copilot)
- cli: Add Format, Lint, Profile, and Config subcommands (@Copilot)
- core: Add resolve_includes, execution group validation, conditional execution, schema verification, and enhanced formatting (@Copilot)
- Add scatter/gather, when, temp/protected output, input_function, retries, include, execution groups (@Copilot)
- Add format module for .oxoflow validation, linting, and formatting (@Copilot)
- Add request ID middleware, export endpoint, and CLI retry/timeout flags (@Copilot)
- Add priority scheduling, clinical report sections, and CNV/MSI/TMB pipeline steps (@Copilot)
- executor: Implement retry logic, timeout enforcement, and output validation (@Copilot)
- core: Add error variants, apply_defaults, parallel_groups, rule validate (@Copilot)
- cli: Enhance clean, init, add completions and verbose flag (@Copilot)
- container: Add pixi support, extra_packages, compose file, and improved singularity defs (@Copilot)
- web: Add CORS, run, version, and clean endpoints (@Copilot)
- venus: Add VenusPipelineBuilder and .oxoflow generation (@Copilot)
- web: Add full REST API with validate, parse, DAG, dry-run, and report endpoints (@Copilot)
- report: Add Tera template engine and clinical report components (@Copilot)
- Add cluster execution backends and executor checkpointing (@Copilot)
- environment: Add setup/teardown commands, cache keys, and EnvironmentCache (@Copilot)
- Initialize oxo-flow project with core library, CLI, web, and venus pipeline (@Copilot)
Maintenance#
- Update Rust edition from 2021 to 2024 and fix clippy/fmt issues (@Copilot)
Other Changes#
- Add 303 implementation notes to TODO.md; update README, CONTRIBUTING docs (@Copilot)
- Phase 7: Add 32 new tests (clinical types, builder, security, stress, format, container) (@Copilot)
- Add validation and security features to oxo-flow-core (@Copilot)
- Add core safety attributes: forbid(unsafe_code), CLI flags, #[must_use] (@Copilot)
- Initial plan (@Copilot)
- Add comprehensive TODO.md with 300+ expert opinions from 30 simulated domain experts (@Copilot)
- Add comprehensive TODO.md with 300 expert review items across 30 domain perspectives (@Copilot)
- Add TODO.md with 30 expert opinions (150 action items) (@Copilot)
- Delete TODO.md (@ShixiangWang)
- Add ..Default::default() to all Rule constructors for new fields (@Copilot)
- Initial plan (@Copilot)
- Replace README.md with comprehensive documentation (@Copilot)
- Add binary targets for oxo-flow-web and venus, create dual license files (@Copilot)
- Add TODO.md with 30-expert evaluation and action items (@Copilot)
- Update (@ShixiangWang)
- Add paired_tumor_normal example, integration tests, and root package for workspace-level tests (@Copilot)
- 30-expert evaluation: comprehensive upgrades - error variants, config defaults, DAG parallel groups, rule validation, executor retry/timeout, priority scheduling, clinical reports, Venus CNV/MSI/TMB, web export/request-ID, CLI retry/timeout flags, examples, integration tests - 231 tests passing (@Copilot)
- Comprehensive multi-expert evaluation upgrades: executor env integration, Venus FilterMutectCalls/Strelka2, web API CORS/run/clean/version endpoints, container multi-stage builds, CLI clean/completions/init enhancements, Venus pipeline files, 200 tests passing (@Copilot)
- Add comprehensive tests for web, venus, and environment modules (@Copilot)
- Add FilterMutectCalls, Strelka2, known_sites to Venus pipeline (@Copilot)
- Add environment integration to executor and retry/timeout config fields (@Copilot)
- Phase 7-8: Venus pipeline builder, CLI status/clean commands, enhanced example workflow, ROADMAP update (@Copilot)
- Initial commit (@ShixiangWang)
Testing#
- Add 30 CLI binary integration tests for oxo-flow, venus, and oxo-flow-web (@Copilot)