Skip to content

Changelog#

All notable changes to oxo-flow are documented in this file.

The format follows Keep a Changelog and this project adheres to Semantic Versioning.

Changelog entries are automatically generated by git-cliff from conventional commit messages.

[Unreleased]#

Features#

  • engine: Runtime disk-pressure monitoring — [engine] min_free_disk / reclaim_free_disk thresholds drive a Normal → Reclaim → Hold → abort ladder; completed temporary outputs are reclaimed mid-run (tombstoned, cascade-up on demand) and parked holds abort after a grace window (#843)
  • engine: Reclaim-dependent race fix — mid-run reclaim now requires each dependent to be checkpoint-completed and its declared outputs still on disk; a stale-completed dependent with missing outputs re-executes and keeps its inputs (rule_outputs_exist shared helper in core, reused by the CLI replay gate) (#843)
  • engine: Reclaim/sweep blind spots for output_pattern producers — post-run temporary cleanup now expands wildcard outputs per recorded instance (only paths that ran and completed, with a warning instead of a silent no-op), the sweep detects consumers structurally (pattern producers register no DAG edges), and the mid-run reclaim gate accepts pattern-typed dependents whose recorded instance paths exist (#844)
  • engine: Reclaim gate resolves pattern-dependent domains by template name — output_pattern_domains are recorded under the producer's expansion template, so the mid-run gate now looks dependents up the same way (config-expanded pattern text never matched, which had voided the gate); a dependent with no recorded domains is treated as not proven done and blocks reclaim of its producer's inputs (#843)
  • engine: Spawn watchdog no longer raises false #685 ERRORs for queued rules — a Running rule still waiting in the resource pool is reported as a benign one-shot WARN (the scheduler's 60s blockage lines already carry holder/FIFO detail); the ERROR is reserved for rules not queued in the pool with no child process, the genuine lost-wakeup signature (#847)
  • engine: duration_ms measures execution, not enqueue-to-completion — started_at is stamped only after the rule acquires its resources, and the queue wait is preserved separately in a new enqueued_at record field (mirroring the cluster driver's queue_wait_secs split), so parked rules no longer inflate reported runtimes (#850)
  • cli: status surfaces snapshot freshness — the human output prints one State as of <N>s ago (checkpoint written <time> local) line under the banner (a Warning: variant past 5 minutes), and --json gains checkpoint_mtime (RFC 3339) plus snapshot_age_secs, so the invisible checkpoint-flush lag on live runs can no longer be mistaken for a stalled pipeline (#849)
  • cli: Pixi-manifest preflight in validate/plan/dry-run — a rule's declared pixi manifest is resolved against the workflow directory and existence-checked up front, reported as error E019 (skipped under validate --as-include); dry-run's --json gains env_manifest_issues; and run's environment-readiness abort now splits its remediation — manifest not found → create/correct it at the resolved path, backend binary missing → install advice (#848)

0.23.1 — 2026-10-08#

Bug Fixes#

CI/CD#

Documentation#

Features#

0.23.0 — 2026-10-03#

Bug Fixes#

  • vscode: Audit batch — publishing reliability, first-run UX, report issue (#817) (@ShixiangWang) (#817)

CI/CD#

Documentation#

Features#

0.22.0 — 2026-10-03#

Bug Fixes#

  • ci: Commit the VS Code extension manifests during sync-version (#810) (@ShixiangWang) (#810)
  • eval: Make the gold set review-ready — judge fidelity, consistency linter, verified repairs (#802) (@ShixiangWang) (#802)

Features#

  • vscode: Show Run Status + Clean Outputs commands, editor-title buttons (#805) (@ShixiangWang) (#805)
  • vscode: Task kind field, task-based AI generation, resource-scoped executable path (#804) (@ShixiangWang) (#804)
  • vscode: VS Code extension with release-time VSIX publishing (Open VSX + Marketplace) (#803) (@ShixiangWang) (#803)

0.21.2 — 2026-10-02#

Bug Fixes#

Documentation#

Maintenance#

0.21.1 — 2026-10-01#

Bug Fixes#

  • web: Abort-killed sibling rules surface as Skipped, not Pending forever (issue #767) (#769) (@ShixiangWang) (#769)
  • web: Surface rule_runs stdout_tail alongside stderr_tail (issue #765) (#766) (@ShixiangWang) (#766)
  • web: Make run reports failure-aware (issue #759) (#764) (@ShixiangWang) (#764)
  • web: Surface checkpoint rule_runs exit codes and stderr tails (issue #758) (#763) (@ShixiangWang) (#763)
  • core,web: Reserved [[values]] names rejected at parse; retry plan honest about pre-execution failures (issue #760) (#762) (@ShixiangWang) (#762)
  • core,cli: Tolerate expand_inputs-baked absent inputs; clear stale outputs of failed rules (issues #757, #756) (#761) (@ShixiangWang) (#761)
  • preflight: Drop unverifiable 'far inferior' quote in SCI-MUTECT2-TUMOR-ONLY (#755) (@ShixiangWang) (#755)
  • bundle: Fall back to --workdir for sample/pairs discovery (#751) (#754) (@ShixiangWang) (#754)
  • executor: Unique staged filename for checkpoint saves (#750) (@ShixiangWang) (#750)
  • executor: Clear the spawn-time running mark on terminal skips (issue #747) (#748) (@ShixiangWang) (#748)
  • web: Bound the remaining whole-log reads; status prefers the persisted running set (issue #734) (#746) (@ShixiangWang) (#746)
  • core,cli: One memory grammar and explicit PBS/SGE units; RSS and split.n alignment (issue #740) (#745) (@ShixiangWang) (#745)
  • core: One shared walltime parser across local executor and all cluster backends (issue #737) (#744) (@ShixiangWang) (#744)
  • When-awareness round 2 across deep_check, config_impact, lint, and the web surface (issue #739) (#743) (@ShixiangWang) (#743)
  • web: Quota collector counts [rules.resources].memory via effective_memory (issue #738) (#741) (@ShixiangWang) (#741)
  • web: Stat-first gates on background pollers and startup recovery (issue #735) (#736) (@ShixiangWang) (#736)
  • core: Deep-check skips when-gated-off rules via the engine evaluator (issue #717) (#731) (@ShixiangWang) (#731)
  • web: Zip download skips non-regular files; mkfifo regression tests (#714 addendum) (#729) (@ShixiangWang) (#729)
  • web: Diagnostics and report endpoints read a bounded execution.log tail (issue #710) (#727) (@ShixiangWang) (#727)
  • core: LSF walltime renders verbatim when unparseable; memory shares the engine parser (issues #715, #716) (#726) (@ShixiangWang) (#726)
  • web: Harden diagnostics pattern matching, share table with AI monitor (issues #708, #709) (#725) (@ShixiangWang) (#725)
  • safety: Stat-first regular-file gates at residual read sites (#714) (#724) (@ShixiangWang) (#724)
  • core: Stat-first is_regular_file gates in result.rs (issue #713) (#723) (@ShixiangWang) (#723)
  • web: Build web DAGs with config-expanded rules (issue #707) (#721) (@ShixiangWang) (#721)
  • cli: Resume banner reconciles when-gated-off rules (issue #690) (#711) (@ShixiangWang) (#711)
  • core: Stat-first gate on when-atom file readers — FIFO would hang the scheduler loop (#706) (@ShixiangWang) (#706)
  • checkpoint: #690 — when-gated-off rules no longer display as Failed (#699) (@ShixiangWang) (#699)
  • readiness: Skip when-false rules — their inputs are phantom missing files (#698) (@ShixiangWang) (#698)
  • web: Report run memory estimates in true MB via the engine parser (#697) (@ShixiangWang) (#697)
  • checkpoint: Never open special files for checksums — FIFO hang at startup (#695) (#696) (@ShixiangWang) (#696)
  • env: Classify conda link-stage failures before solver conflicts in setup hints (#694) (@ShixiangWang) (#694)
  • core: Persist bounded stdout_tail in rule_runs — reports/AI see stdout too (#692) (@ShixiangWang) (#692)

Documentation#

Features#

Maintenance#

0.21.0 — 2026-09-28#

Bug Fixes#

  • core: Recognize GNU-permuted rm flags in any position, not only trailing (#689) (@ShixiangWang) (#689)
  • core: Spawn watchdog, authoritative running-set persistence, bounded setup-lock wait (#685) (#686) (@ShixiangWang) (#686)
  • core: Harden shell-safety validator (short-circuit, permuted rm, symlink escape) (#674) (@ShixiangWang) (#674)
  • cli: Scripts can read exit codes — validate/lint return Err, orphan-clean/touch propagate failures, bundle entrypoint contained (#681) (@ShixiangWang) (#681)
  • web: Search visibility in SQL, webhook secret sealed, session cleanup wired; ci gains eval-tests (#684) (@ShixiangWang) (#684)
  • frontend: Close SSE orphan leak, escape guided TOML, surface structured errors, client-layer robustness (#680) (@ShixiangWang) (#680)
  • core: Mirror snapshot skips in missing_input_patterns, mode-aware remote optional staging, log events.jsonl write failures (#679) (@ShixiangWang) (#679)
  • ai: Redirect-screened MCP client, credential precedence, empty-truncation guard, UTF-8-safe streaming, registry self-writes (#678) (@ShixiangWang) (#678)
  • web: Remote runs honor cancellation and tolerate transient poll errors (#677) (@ShixiangWang) (#677)
  • web: Six audit fixes — share expiry bound, resume guard, pagination contract, oauth token leak, zip disposition (#676) (@ShixiangWang) (#676)
  • executor: Rm-validator stops at subshell close paren — unblocks varlociraptor get_known_variants (#675) (@ShixiangWang) (#675)
  • core: Honor optional inputs in manifest snapshotting and detection (#633) (#638) (@ShixiangWang) (#638)
  • web: Probe and expose the engine CLI version for run execution (#579) (#636) (@ShixiangWang) (#636)
  • Whitelist workflow-file [ai] section so the documented activation path works (#634) (#635) (@ShixiangWang) (#635)
  • ci: MD032 lint config must be a real plain-.jsonc file (#631) (@ShixiangWang) (#631)
  • web: UI polish batch from browser audit (#578) (#630) (@ShixiangWang) (#630)
  • report: Render all ReportContent variants in the built-in template (#629) (@ShixiangWang) (#629)
  • web: Refetch run detail panes on terminal SSE events (#577) (#628) (@ShixiangWang) (#628)
  • core: S3 backend — multipart uploads, timeouts, typed 404s (#575) (#627) (@ShixiangWang) (#627)
  • web: Accept hostname binds in the standalone binary (#573) (#625) (@ShixiangWang) (#625)
  • webhook: Strip credentialed URL from request errors, drop redirect replay (#574) (#626) (@ShixiangWang) (#626)
  • web: End SSE streams on shutdown so graceful drain completes (#572) (#624) (@ShixiangWang) (#624)
  • deploy: Make Docker CMD/healthcheck honor compose env, fix PostgreSQL comment (#570) (#622) (@ShixiangWang) (#622)
  • web: Share serve/desktop startup steps with the standalone binary (#569) (#621) (@ShixiangWang) (#621)
  • engine+deploy: W033 empty-scatter semantics (#616); compose env passthrough (#568) (#620) (@ShixiangWang) (#620)
  • W033 empty-scatter semantics (#616), quality gates (#557), lock hygiene (#556), e2e fixes (#619) (@ShixiangWang) (#619)
  • frontend: Infinite recursion in non-secure-context uuid fallback (#608 follow-up) (#612) (@ShixiangWang) (#612)
  • checkpoint: Empty config-optional input must not manifest the whole workdir (#611) (@ShixiangWang) (#611)
  • ci: :latest promotion hard-fails when the latest-release lookup fails (#552) (#610) (@ShixiangWang) (#610)
  • frontend: Chat regenerate works; non-secure-context UUIDs; spec-compliant SSE parser (#550) (#608) (@ShixiangWang) (#608)
  • frontend: 401 redirects to login; destructive-action failures surface (#549) (#607) (@ShixiangWang) (#607)
  • frontend: DAG auto-layout derives parentIds from actual edges (#548) (#606) (@ShixiangWang) (#606)
  • frontend: Close the three SPA state races (#547) (#605) (@ShixiangWang) (#605)
  • frontend: Enable TypeScript strict mode (#546) (#604) (@ShixiangWang) (#604)
  • web: GET /api/ai/config/user returns the stored row incl. advanced fields (#545) (#603) (@ShixiangWang) (#603)
  • ai: Parse_verdict fail-safe; private capped session archives; full from-url grounding (#544) (#602) (@ShixiangWang) (#602)
  • ai: A length-truncated completion feeds the retry loop, never ships (#543) (#601) (@ShixiangWang) (#601)
  • ai: Fold the empty-round nudge into the Tool message (#542) (#600) (@ShixiangWang) (#600)
  • cli: Six contract fixes — UTF-8 slice, flag precedence, local-source protection, workdir-scoped --output, ai --json document, ANSI-free stderr (#541) (#599) (@ShixiangWang) (#599)
  • cli: Batch/clean exit codes reflect failures; SIGINT emits the JSON summary and webhook (#540) (#598) (@ShixiangWang) (#598)
  • cli: AI narration goes to stderr; suppressed under --json (#539) (#597) (@ShixiangWang) (#597)
  • cli: Resume honors the explicit checkpoint path argument (#538) (#596) (@ShixiangWang) (#596)
  • expand: Escape the wrapper quote in baked when predicates (#537) (#595) (@ShixiangWang) (#595)
  • cluster: Serialize driver events.jsonl/status.json with serde_json (#536) (#594) (@ShixiangWang) (#594)
  • container: Pre-build inline conda specs under the runtime env name (#535) (#593) (@ShixiangWang) (#593)
  • security: Quote client-controlled paths in generated shell; close backend boundary gaps (#534) (#592) (@ShixiangWang) (#592)
  • checkpoint: Config_impact covers output_pattern/expand_inputs; per-group injected keys only (#533) (#591) (@ShixiangWang) (#591)
  • environment: Fold spec content hash into file-backed env cache keys (#532) (#590) (@ShixiangWang) (#590)
  • expand: When-only pair/group scope still fans out per combo (#531) (#589) (@ShixiangWang) (#589)
  • diagnostics: Shared pair/group wildcard vocabulary; full fresh-wildcard registry (#530) (#588) (@ShixiangWang) (#588)
  • diagnostics: Widen detector scan fields to the runtime expansion surface (#529) (#587) (@ShixiangWang) (#587)
  • checkpoint: Canonical serialization for output_pattern_domains (#528) (#586) (@ShixiangWang) (#586)
  • executor: Move bulk synchronous I/O off the tokio workers (#527) (#585) (@ShixiangWang) (#585)
  • executor: Retry attempts accumulate output with an attempt boundary marker (#526) (#584) (@ShixiangWang) (#584)
  • executor: Gate abort demotion on kill-snapshot membership; record signal evidence in SIGINT teardown (#525) (#583) (@ShixiangWang) (#583)
  • executor: Kill auxiliary children on abort; blocking-pool kill sweep with post-abort re-snapshot (#524) (#582) (@ShixiangWang) (#582)
  • security: Enforce rule field validation on the run path; overflow-safe memory parsing (#523) (#581) (@ShixiangWang) (#581)
  • security: One-time SSE tickets replace ?token= in event-stream URLs (#522) (#567) (@ShixiangWang) (#567)
  • security: Sandbox data/analyze, perceive, and validate base_dir to the user workspace (#521) (#566) (@ShixiangWang) (#566)
  • security: Add logout + cascade sessions/API keys on user deletion (#520) (#565) (@ShixiangWang) (#565)
  • security: Close six route-level authz/quota gaps (#519) (#564) (@ShixiangWang) (#564)
  • security: Scope AI read_file to workspace; SSRF-screen MCP endpoints; readOnlyHint advisory (#518) (#562) (@ShixiangWang) (#562)
  • security: Never return cluster ssh_key; seal at rest; admin-gate probe (#517) (#561) (@ShixiangWang) (#561)
  • security: Pin session identity to canonical users.id; fail-closed role resolution (#516) (#560) (@ShixiangWang) (#560)
  • security: Enforce ownership on /api/ai/explain, /interpret, /optimize (#515) (#559) (@ShixiangWang) (#559)
  • security: Parse individually-quoted rm operands instead of blanket-rejecting (#514) (@ShixiangWang) (#514)
  • abort: Distinguish abort-killed siblings from self-caused failures (issue #498) (#513) (@ShixiangWang) (#513)
  • preflight: Strip shell comments before placeholder scans + suppress dir-output aggregation warning (#512) (@ShixiangWang) (#512)
  • report: Make --plan workflow-discovery error non-circular (#505) (@ShixiangWang) (#505)
  • serve: Reject unknown --mode values at parse time (#504) (@ShixiangWang) (#504)
  • cluster: Ask squeue for long-form states (%T) + accept compact forms (#500) (@ShixiangWang) (#500)
  • validate: Skip missing-input checks for when-gated-off rules (issue #493) (#497) (@ShixiangWang) (#497)
  • executor: Name fatal signals in stderr + honest Cancelled records for abort-killed siblings (#496) (@ShixiangWang) (#496)
  • ai: Honor OLLAMA_HOST as the ollama endpoint, not just a detection signal (#495) (@ShixiangWang) (#495)
  • ai: Warn on unrecognized OXO_FLOW_AI_PROVIDER instead of silent fallthrough (#494) (@ShixiangWang) (#494)
  • environment: Don't bind-mount shell-residue root tokens ('//') (#492) (@ShixiangWang) (#492)
  • run-log: Capture invalidation/adoption diagnostics in the run log (issue #484) (#490) (@ShixiangWang) (#490)
  • checkpoint: Don't clobber real benchmarks on 'outputs up-to-date' skip (issue #484) (#483) (@ShixiangWang) (#483)
  • result: Resolve {config.*} in scan_run_outputs (issue #467 family) (#486) (@ShixiangWang) (#486)
  • determinism: Sort the remaining user-visible nondeterministic outputs (issue #471) (#480) (@ShixiangWang) (#480)
  • validate: Resolve {config.*} in W020/E010 missing-input checks (issue #467) (#478) (@ShixiangWang) (#478)
  • modules: Resolve {config.*} in --module closure and include-contract validation (issue #468) (#479) (@ShixiangWang) (#479)
  • validate: Build validate/lint DAGs with the parsed config values (issue #466) (#477) (@ShixiangWang) (#477)
  • dag: Existence-aware -t closure — pre-built inputs survive when-false producers (#476) (@ShixiangWang) (#476)
  • protected_output: Honor shell-glob patterns in both enforcement paths (issue #473) (#475) (@ShixiangWang) (#475)
  • diagnostics: Independent v0.20.1..HEAD audit — engine-exact SCI-AGG-RACE, config-routed W033, deterministic provenance artifacts (#472) (@ShixiangWang) (#472)
  • ai: Zero-config auto-detection + empty-key guards + unified Claude key chain (#465) (@ShixiangWang) (#465)
  • preflight: #443 — plan-time warning for sample-fanned aggregation rules (#464) (@ShixiangWang) (#464)
  • gallery: 12 cohort — SILENT stringency + BAM indexing for GATK chain (#449) (@ShixiangWang) (#449)
  • gallery: Plain-bwa read-group tab handling + index BAM for mosdepth (11) (#448) (@ShixiangWang) (#448)
  • info: Resolve {config.*} in input/output dirs before top-level extraction (#460) (@ShixiangWang) (#460)
  • format: Deterministic key ordering + stop config_meta leaking into formatted TOML (#459) (@ShixiangWang) (#459)
  • gallery: Real-path rmarkdown render + TOML escape gotcha in gallery 09 (#450) (@ShixiangWang) (#450)

CI/CD#

  • Add cargo-deny and gitleaks quality gates, fix macro bench reliability metric (#618) (@ShixiangWang) (#618)
  • Close four gate gaps — checksums pipefail+assert, deploy-smoke wired, Playwright CI reuse/visibility, SPA freshness check (#555) (#615) (@ShixiangWang) (#615)

Documentation#

  • Fix four audit drifts — provider auto-detect default, desktop crate, env table, subcommand count (#682) (@ShixiangWang) (#682)
  • ai: Drop duplicated sentence fragment left by #620 doc-link edit (#632) (@ShixiangWang) (#632)
  • deploy: Correct TRUSTED_PROXY and weak-setup claims, add proxy limiter guidance (#571) (#623) (@ShixiangWang) (#623)
  • Accuracy batch — OAuth env name, serve.md table, MD032 sweep, README/AGENTS/knowledge numbers (#551) (#609) (@ShixiangWang) (#609)
  • web: Fix pause from_rule claim + document undo/redo JSON body (#511) (@ShixiangWang) (#511)
  • tutorials: Env list/check stream note + binary size correction (#510) (@ShixiangWang) (#510)
  • how-to: Correct conda wrapping form + init scaffold file list (#508) (@ShixiangWang) (#508)
  • guide: Reference-audit corrections (batch exit codes, lint --quiet, dry-run warning, glossary S007/S008, web-api credentials, 31 subcommands) (#506) (@ShixiangWang) (#506)
  • cluster: Cluster logs does not fall back to scontrol on sacct-less sites (#502) (@ShixiangWang) (#502)
  • cluster: Pin the working directory in SLURM/PBS/SGE example scripts (#501) (@ShixiangWang) (#501)
  • gallery: Demo-data provisioning + live-run results for 04/10 (#499) (@ShixiangWang) (#499)
  • dag-engine: Drop removed detect_output_collisions — point at lint W033 (#491) (@ShixiangWang) (#491)
  • Final audit nits — gpus wording, knowledge counts in-file, gallery-07 index sidecars (#488) (@ShixiangWang) (#488)
  • troubleshooting: Fix conditional-workflow link depth — mkdocs --strict failed (#487) (@ShixiangWang) (#487)
  • format: Annotate parsed-but-unenforced fields honestly (issue #469) (#481) (@ShixiangWang) (#481)
  • Add Engineering Invariants to AGENTS.md (#474) (@ShixiangWang) (#474)
  • temp_output: Rustdoc states the failure-only contract (#456) (#463) (@ShixiangWang) (#463)
  • gallery-16: Live-tested caveats — sklearn classifier gate, metadata format, DADA2 IUPAC trap (#452) (@ShixiangWang) (#452)
  • gallery-07: VQSR zero-variance failure mode from live test (#453) (@ShixiangWang) (#453)
  • commands: Live-verified corrections for status/validate/lint/run/touch (#461) (@ShixiangWang) (#461)
  • gallery: Input-provisioning Run sections + strandedness note for multiomics (#451) (@ShixiangWang) (#451)
  • resource-budget: State cluster-path-only enforcement + max_jobs gap (#454) (@ShixiangWang) (#454)
  • reference: Refresh bioconda knowledge counts + document EnvironmentSpec gpus semantics (#447) (@ShixiangWang) (#447)
  • format: Mark pipe/input_function/checksum/format_hint as parsed-but-unimplemented (#446) (@ShixiangWang) (#446)
  • variant-calling: Add reference-prep section (.dict) and declare GATK .tbi outputs (#445) (@ShixiangWang) (#445)
  • first-workflow: Fix per-sample aggregation race — key multiqc to one sample (#444) (@ShixiangWang) (#444)

Features#

  • #469: Resolve every documented-but-unenforced field — implement, remove, or finalize by design (#507) (@ShixiangWang) (#507)
  • validate: Run the raw-file schema pass (S001–S006) on oxo-flow validate (#482) (@ShixiangWang) (#482)
  • protected_output: Enforce protection in failure invalidation and clean (#462) (@ShixiangWang) (#462)

Maintenance#

Other Changes#

  • Flag output collisions between rules writing the same path(s) (W033) (#455) (@ShixiangWang) (#455)
  • Resolve featureCounts strand false positive, dry-run --cache-dir, pilot summary dup (#442) (@ShixiangWang) (#442)#

Refactoring#

  • tests: Extract tests/common — one canonical workspace_bin/spawn_server (#553) (#613) (@ShixiangWang) (#613)

Styling#

Testing#

  • web: Cover serve entrypoint + share base-path normalization (#672) (#687) (@ShixiangWang) (#687)
  • web: OAuth callback negative paths, PG 503 contract, security-route negatives (#554) (#614) (@ShixiangWang) (#614)
  • ancient: Pin explicit filetimes — write order is not mtime order on coarse-granularity filesystems (#509) (@ShixiangWang) (#509)

0.20.1 — 2026-09-24#

Bug Fixes#

  • security: Harden workdir-aware rm -rf validation + env check display + zstd dedup (#440) (@ShixiangWang) (#440)
  • dx: Operator-facing clarity — banner TTY gate, env check resolved binary, self-explanatory shell warnings (#439) (@ShixiangWang) (#439)
  • checkpoint: #432 — staleness reasons, honest dry-run headline, status --workdir, touch overrides (#438) (@ShixiangWang) (#438)
  • config: Discover input_groups files when a config override is absolute (#425) (#431) (@ShixiangWang) (#431)
  • deps: Sqlx 0.9 — AssertSqlSafe audit annotations for dynamic SQL (#422) (@ShixiangWang) (#422)
  • benches: Criterion 0.8 deprecates black_box — use std::hint::black_box (#423) (@ShixiangWang) (#423)

Documentation#

Maintenance#

Other Changes#

0.20.0 — 2026-09-23#

Bug Fixes#

  • deps: Complete sha2 0.11 migration — hmac 0.13, sha1 0.11, hex::encode digests (#406) (@ShixiangWang) (#406)
  • cluster: Real-scheduler conformance — LSF directives, OpenPBS arrays/polling + verification harness (#356) (@ShixiangWang) (#405)
  • ci: Pin release-path checkouts to the synced commit and deploy versioned docs on dispatch releases (#392) (@ShixiangWang) (#392)

Documentation#

  • real-cluster-matrix: Consolidate the setup lessons from the campaign (@ShixiangWang)

Maintenance#

Refactoring#

  • Dedupe helpers, slim dead code, docs+UI/i18n consistency pass (@ShixiangWang)

0.19.0 — 2026-09-16#

Documentation#

Maintenance#

0.18.2 — 2026-09-15#

Bug Fixes#

  • engine: #374 wildcard/when-gate semantics + #375 UX (lint noise, warn flood, input_groups) (@ShixiangWang)
  • gallery: 08 bismark chain — --basename/--multicore conflict + dedup output path (#357) (#372) (@ShixiangWang) (#372)
  • run: Per-parallel-group -j suggestion — evaluate each wave against its own heaviest rule (#361) (#369) (@ShixiangWang) (#369)
  • env: Pixi wrap must carry the whole command inside pixi run (#354) (#367) (@ShixiangWang) (#367)
  • bench: Add required pair_id to the parsing_bench pairs fixture (#360) (#366) (@ShixiangWang) (#366)

Documentation#

  • workflow-format: Document directory outputs (trailing-slash idiom) (@ShixiangWang)

Features#

Maintenance#

  • deps: Rustls 0.23.43 -> 0.23.45 (RUSTSEC-2026-0285) (@ShixiangWang)

Other Changes#

  • Commit the -j suggestion evaluation harness and results (#361) (#370) (@ShixiangWang) (#370)
  • ai: Complete the interpretation benchmark — dry-run surface, 12 seeds, negative controls, three providers (#359) (#365) (@ShixiangWang) (#365)
  • ai: Seeded-failure interpretation benchmark; feed rule outcomes + stderr to report --ai (#359) (#364) (@ShixiangWang) (#364)

Styling#

Testing#

  • web: Production-scale SSE stress profile — 64 runs, 8 subscribers, slow consumer (#363) (#368) (@ShixiangWang) (#368)

0.18.1 — 2026-09-12#

Bug Fixes#

  • ai: Model-axis harness calibration + degraded-delivery, transport hardening, and exploration-budget nudge (#353) (@ShixiangWang) (#353)
  • core: Inline conda package lists install with the conda-forge channel (lifecycle-verified) (@ShixiangWang)
  • core: Executable inline conda package lists + deterministic gate repair (83% → 98% generation pass) (#352) (@ShixiangWang) (#352)
  • ai: Finish the unified generation harness — provider isolation, structured error paths, budget default, docs (#350) (@ShixiangWang) (#350)
  • test: Make driver sbatch-missing test environment-independent (#348) (@ShixiangWang) (#348)
  • ai: Raise Anthropic max_tokens ceiling for thinking backends; add generation frontier benchmark (#345) (@ShixiangWang) (#345)
  • scheduler: Treat plan-absent deps as satisfied in ready_rules (#346) (@ShixiangWang) (#346)

Features#

  • ai: Opt-in Scientist Team profile with ablation-driven guards; frontier intent expansion (#351) (@ShixiangWang) (#351)
  • ai: Unify pipeline generation on one agent + orchestrator harness (#349) (@ShixiangWang) (#349)

0.18.0 — 2026-09-09#

Bug Fixes#

  • Full-repo scan remediation — docs, scripts, configs, frontend types (@ShixiangWang)
  • Full-repo audit remediation — all CRITICAL/HIGH and confirmed MEDIUM/LOW findings (#343) (@ShixiangWang) (#343)
  • run: OR-per-output dead-node propagation for targeted plans (#341) (@ShixiangWang) (#341)
  • run: Review round 2 — ref normalization, owner-prefixed caches, fast fail (@ShixiangWang)
  • eval: Repair 27 dead provenance URLs in tool gold set (#172) (@ShixiangWang)
  • Add recorded_as to remaining BenchmarkRecord test constructions (@ShixiangWang)
  • Address review findings from #335 (W032 regex, serde error, F-1 benchmark marker, missing_inputs docs) (@ShixiangWang)
  • bench: Suite.py accepts --iterations, uses [rules.resources] (W025) (@ShixiangWang)
  • bench: Comparative harness actually runs all three engines (#67) (@ShixiangWang)
  • metro: Engine rendering fixes — terminal-dest line, single-line merged labels with +N counter (#334) (@ShixiangWang) (#334)
  • metro: Merged-section second line lists full module names (#332) (@ShixiangWang) (#332)
  • display: Readable config descriptions and module map names (#329) (@ShixiangWang) (#329)
  • web: Wire-contract CreateRunRequest + OpenAPI requestBody + empty-body pause/resume (@ShixiangWang)
  • cli: Eval findings F-1/F-2/F-3 — resume up-to-date recording, default-run chunk cleanup, validate wildcard warning (@ShixiangWang)

Documentation#

  • Restore code fence broken in contributing.md flaky-test section (@ShixiangWang)
  • graph: Merged-section display is now two-line, not "+"-joined (#333) (@ShixiangWang) (#333)
  • graph: Reading semantics — off-track, independent chains, merged-cyclic (#330) (@ShixiangWang) (#330)
  • Fix W032 anchor to the config section slug (@ShixiangWang)
  • Clarify status --timing data sources for CLI and web runs (@ShixiangWang)
  • Document eval-finding behaviors — W032 lint, validate wildcard warning, typed run contract (@ShixiangWang)

Features#

  • run: Accept owner/repo shorthand without gh: prefix (@ShixiangWang)
  • metro: Two-line merged-section displays + canonical-hue avoidance (#331) (@ShixiangWang) (#331)
  • graph: Production-ready graph subcommand — format matrix, metro polish (#328) (@ShixiangWang) (#328)
  • lint: W032 flags secret-like config keys not declared sensitive (@ShixiangWang)
  • cli: Config comment group propagation + include-tree description merge (#326) (@ShixiangWang) (#326)
  • graph: Metro granularity ladder — process + module tiers, topological stations (#325) (@ShixiangWang) (#325)

Other Changes#

  • Complete gold-set review sweep — annotate 257 rows, accept corrected rows (@ShixiangWang)

Refactoring#

Styling#

0.17.2 — 2026-09-05#

Bug Fixes#

  • Report the W021 script-edge warning once instead of once per rule (@ShixiangWang)
  • config: Keep _REP-suffixed group keys in the #246 sample-domain intersection (@ShixiangWang)
  • Clamp docker --cpus to host CPUs and mark cleaned transform chunks in provenance (@ShixiangWang)
  • cluster: Harden SLURM lifecycle and streamline cluster CLI (@ShixiangWang)

CI/CD#

  • release: Fix artifact download pattern to single wildcard (@ShixiangWang)
  • release: Skip dockerbuild build records in artifact download (@ShixiangWang)

Documentation#

  • graph: Describe post-#318 metro stage tiers and module-namespace sections (@ShixiangWang)
  • Add transform cleanup caveat to skill QC stage from v0.17.1 live test (@ShixiangWang)
  • Fix skill gate syntax and add version caveats from tx-ubuntu live test (@ShixiangWang)
  • Add AI agent skill (SKILL.md) with site nav entry and meta extension (@ShixiangWang)

Features#

  • Lint W031 — warn when a consumer expands a when-gated producer's output unconditionally (@ShixiangWang)
  • Metro maps — module sections, stage lines, used_by expansion channels (#318) (@ShixiangWang) (#318)
  • Add regex_extract(path, pattern, group?) runtime when-fn (@ShixiangWang)

0.17.1 — 2026-09-03#

Bug Fixes#

CI/CD#

  • Native multi-arch Docker release publish (drop QEMU thrash) (#307) (@Copilot) (#307)

Documentation#

Other Changes#

  • Harden eval/ into a trial-aware, review-gated AI benchmark harness (#309) (@Copilot) (#309)
  • Refactor GitHub CI into reusable, artifact-driven workflows (#308) (@Copilot) (#308)

0.17.0 — 2026-09-02#

Bug Fixes#

  • Close out #299 (-t when-gate pruning) and #300 (conda env diagnosis) (#301) (@ShixiangWang) (#301)
  • Resolve all nine #297 review follow-ups (web/cli/CI) (#298) (@ShixiangWang) (#298)
  • ci: Knowledge refresh survives an org PR-block (#291) (@ShixiangWang) (#291)
  • Signal teardown checkpoint corruption; desktop opener injection; OCI version labels (#294) (@ShixiangWang) (#294)
  • core: Close plan/execution gaps in expand when-gating, discovery, expand_inputs (#293) (@ShixiangWang) (#293)
  • release: Sync-version patches excluded desktop crate + SPA version; unify macOS packaging (#292) (@ShixiangWang) (#292)
  • ci: Release Docker image validation leg; verify tarballs under original asset names (#285) (@ShixiangWang) (#285)
  • ci: Lowercase the ghcr.io image path (owner "Traitome" rejected) (@ShixiangWang)
  • 276 lifecycle audit — substitution floor, rendered-command guard, provenance, publish, web inputs, UX (#278) (@ShixiangWang) (#278)#

  • release: Docker rust:1.92-slim < MSRV 1.98; add docker-build CI gate (#277) (@ShixiangWang) (#277)
  • core: [[values]] fan-out triggers on expand_inputs references too (#268 item 1) (#269) (@ShixiangWang) (#269)
  • core: Scientific preflight skips when-gated-off rules (#263) (#264) (@ShixiangWang) (#264)
  • core: SLURM settlement survives clusters without slurmdbd (#244) (#261) (@ShixiangWang) (#261)
  • core,cli: Targeted run (-t) closes over the instantiated DAG (#247) (#259) (@ShixiangWang) (#259)
  • cli: Warn on config drift between checkpoint snapshot and current run (#243) (#257) (@ShixiangWang) (#257)
  • core: File_exists() in when resolves against base_dir, not process cwd (#241) (#256) (@ShixiangWang) (#256)
  • 12-role persona audit remediation — CRITICAL wave (RCE / literal wildcards / cluster dependency gate) (#251) (@ShixiangWang) (#251)
  • core: Cartesian_expand with empty values returns an empty product (#254) (#253) (@ShixiangWang) (#253)
  • core: Input_groups prunes group keys outside the declared sample set (#246) (#248) (@ShixiangWang) (#248)
  • core: Bake {meta.*} before plan-time when evaluation (#239) (@ShixiangWang) (#239)
  • core: Phantom-instance guard for repeated wildcards + pair-when typo warning (#238) (@ShixiangWang) (#238)
  • ai: SSRF guard for FetchUrlTool — block internal address space on every hop (#223) (@ShixiangWang) (#223)
  • core: Adopt a safe-char default for wildcard values reaching shells (#226) (@ShixiangWang) (#226)
  • cli: Batch/pull robustness — TOML-safe escaping, bounded downloads, graceful join errors (@ShixiangWang)
  • frontend: Abort ChatUI stream on unmount/stop — no leaked fetch or burned tokens (@ShixiangWang)
  • web: Enforce the auth boundary on the serve path too (@ShixiangWang)
  • ai: Bound provider latency, honor UTF-8, restore promised backup (@ShixiangWang)
  • web: Harden auth boundaries and remove panic paths in server tasks (@ShixiangWang)
  • core: Report generators no longer panic under section filters (@ShixiangWang)
  • cli: Close shell-injection gaps and scheduler panic paths (@ShixiangWang)

CI/CD#

  • frontend: Npm audit gate + drop duplicate playwright dep; zero current advisories (@ShixiangWang)

Documentation#

  • Fix three drift findings in the report/web reference pages (#295) (@ShixiangWang) (#295)
  • Web-api.md covers every live route; AGENTS.md env table completes auth/dev/limits (#270) (@ShixiangWang) (#270)
  • Wildcard.* vocabulary scope, references external-only, {meta} absence-guard idiom (#250) (@ShixiangWang) (#250)
  • Plan-time file_exists semantics + abort sibling resume note (#242) (#245) (@ShixiangWang) (#245)
  • Output_pattern — all-instances gate + resume partial-domain replay interaction (#236) (@ShixiangWang) (#236)
  • agents: Describe pagination schemes as they are, not one imaginary envelope (@ShixiangWang)
  • Clear stale version markers and pin bioconda counts to their source (@ShixiangWang)
  • Resync AGENTS.md, README and guide with the code (@ShixiangWang)

Features#

Maintenance#

  • knowledge: Automatic knowledge refresh 2026-09-01 (#290) (@ShixiangWang) (#290)
  • core: Dead-code sweep — remove unused types, variants, helpers, and globset dep (#268 item 3) (#273) (@ShixiangWang) (#273)
  • build: Bump pinned toolchain to Rust 1.98.0, update lockfile (@ShixiangWang)
  • repo: Tighten hygiene and align local gate with CI (@ShixiangWang)

Performance#

  • web: Move synchronous file I/O off the async runtime (#268 item 4, web minor) (#275) (@ShixiangWang) (#275)
  • core: Shared subtree walk in rss sampler; view-based freshness checksums (#268 item 4) (#274) (@ShixiangWang) (#274)
  • core: Hoist loop-invariant config_values clone out of expansion loops (#268 item 4) (#272) (@ShixiangWang) (#272)

Refactoring#

Testing#

0.16.0 — 2026-08-27#

Bug Fixes#

  • core: Config toggles no longer invalidate when-only rules with unchanged gates (#198) (@ShixiangWang)
  • core: Unbound wildcard keys in when-conditions now evaluate false (was permissive true) (#199) (@ShixiangWang) (#199)
  • cli: Background run logs are ANSI-free and deduplicated (@ShixiangWang)
  • core+cli+web: Reliability audit #194 — atomic checkpoint, single-writer run log, SIGTERM grace, narrative+event archiving, checksum reuse, rotation, cleanup (@ShixiangWang)
  • core: Metro export — stage-inference accuracy + stage-cycle breaker (@ShixiangWang)
  • core: Escape Mermaid/metro syntax meta-characters and fix metro indentation (@ShixiangWang)
  • singularity: Pull %-encoded HTTP URIs into the engine-derived artifact name (@ShixiangWang)
  • gallery: Bwa read-group CL corruption + per-tool stringency flags + 14/15 copy-paste bugs (@ShixiangWang)
  • Resolve issue #181 code-quality, docs, and frontend cleanup (@ShixiangWang)
  • ci: Re-point the tag to the synced commit on tag-push releases (@ShixiangWang)
  • frontend: Persona review — i18n gaps, TS fixes, CSV export, lint (@ShixiangWang)
  • web: Skip per-user AI provider rows with empty keys (@ShixiangWang)
  • ai: Echo DeepSeek reasoning_content back across multi-turn agent loops (@ShixiangWang)
  • frontend: Persona-discovered a11y/touch/UX issues (@ShixiangWang)
  • frontend: Persona-discovered AI/i18n/ApiDocs issues (@ShixiangWang)
  • web: Persona-discovered backend correctness issues (@ShixiangWang)
  • core: Re-tag the quay fallback image with the original spec (@ShixiangWang)
  • cli: Template -o treats a trailing slash as a directory intent (@ShixiangWang)
  • gallery: Container image references must exist and be registry-qualified (@ShixiangWang)
  • gallery: Complete the gallery — aux files for 09/11/14/15, real BWA-MEM2 in 05, template copies aux files (@ShixiangWang)
  • core+cli: Resolve campaign issues #159 #162 #163 (@ShixiangWang)
  • core: Cache-hit envs re-verify on disk; vanished envs invalidate and rebuild (@ShixiangWang)
  • ci: Linux desktop bundles get app-menu entry + icon (deb/rpm/AppImage) (@ShixiangWang)
  • ci: Desktop app icon, launcher entry, ad-hoc codesign (@ShixiangWang)
  • cli: Help-text drift + license --json machine output + 4 doc table rows (9c doc-consistency audit) (@ShixiangWang)
  • web: Dev-mode login role matches account; drop nonexistent serve --json doc row (@ShixiangWang)
  • Persona-testing LOW tail — ENOENT labeling, dry-run E011 annotation, cluster status guard, docs drift (#142) (@ShixiangWang)
  • core: #142 H5/M4/M5 — transform required inheritance, profile max_array_size, per-element array logs (@ShixiangWang)
  • Persona-testing findings #142 — silent-failure traps, audit-path bugs, docs batch (@ShixiangWang)

CI/CD#

  • docs: Preserve landing page + static assets across mike deploys; landing links point at /latest/ (@ShixiangWang)
  • docs: Mike-based doc versioning (issue #176) (@ShixiangWang)

Documentation#

  • Durability guarantees, cache_key semantics, sensitive masking forms (@ShixiangWang)
  • Mention nf-metro online playground in graph command docs (@ShixiangWang)
  • Repoint all traitome.github.io links from /documentation/ to /latest/ (README + ai_status + landing page) (@ShixiangWang)
  • Document API authentication schemes in web-api.md (@ShixiangWang)
  • Sync web reference docs with serving/runtime changes (@ShixiangWang)
  • Use-environments how-it-works reflects content-hash env naming (@ShixiangWang)
  • run: Clarify --background scope — cluster runs inherit it, dry-run and other commands intentionally don't (#158 follow-up) (@ShixiangWang)
  • guide: Document web_role_matrix + web_integration test targets in contributing (@ShixiangWang)
  • lint: Fix two broken relative links to workflow-format.md (@ShixiangWang)

Features#

  • cluster: Record what a cluster job actually cost (@andrewbudge)
  • core: Wildcard. placeholders render in shells (#201) (@ShixiangWang) (#201)
  • core: Optional="any" alternative-input mode + skip propagation to dependents (#200) (@ShixiangWang) (#200)
  • core,cli: Issue #194 round 2 — content cache, atomic moves, upload verification, masking variants, mid-run manifest checks (@ShixiangWang)
  • core: Container registry mirror mapping (OXO_REGISTRY_MIRRORS) (#192) (@ShixiangWang) (#192)
  • core: Wildcard-scoped when — snakemake-style per-sample DAG morphing (#187) (@ShixiangWang) (#187)
  • cli: Add mermaid and metro graph export formats (@ShixiangWang)
  • Close issue #67 follow-ups — SSE broadcast verification + env-ai matching tests (@ShixiangWang)
  • ui: Systematic visual polish, shared Modal/StatCard, a11y (@ShixiangWang)
  • web: Optimize HTTP serving layer (@ShixiangWang)
  • ai: Knowledge coverage — R/Bioconductor analysis tools now in the bioconda table (@ShixiangWang)
  • core: Docker backend retries bare image names against quay.io/biocontainers (@ShixiangWang)
  • eval: Three-layer AI evaluation benchmark — gold CSVs, capture/runner harness, knowledge grounding guard (@ShixiangWang)
  • ai: Knowledge freshness framework — in-repo generators, live sync, monthly auto-refresh (#153) (@ShixiangWang)
  • Background runs + verified concurrent reuse of shared workflows (#158) (@ShixiangWang)
  • core: Residual-placeholder guard — unresolved {sample}/{config.*}/… in a rendered command warns loudly (@ShixiangWang)
  • Usability round — 0-byte output warning, W021 script-edge lint, disk pre-flight (@ShixiangWang)
  • cli: Reference path migration with identical content skips the rebuild (@ShixiangWang)

Maintenance#

Performance#

  • frontend: Lazy editor panels, parallel run loading, client hardening (@ShixiangWang)
  • web: Fix runtime hot paths and API contract drift (@ShixiangWang)

Styling#

Testing#

  • cli: Deterministic mtimes in empty_checkpoint freshness test (#193) (@ShixiangWang) (#193)
  • web: Fix ownership-isolation flake — slow run so admin cancel lands mid-run (@ShixiangWang)
  • e2e: Mock AI config in AI-dependent specs (@ShixiangWang)
  • Fix env-name hash test (distinct dirs for same-stem specs) + plain-names expectation with suffix (@ShixiangWang)
  • web: Deployment + 3-role simulation matrix (@ShixiangWang)

0.14.1 — 2026-08-22#

Bug Fixes#

  • info-test: Drop env-coupled git_remote assertion (#136 finding 29) (@ShixiangWang)
  • Audit #136 tier-2 — web cancel integrity, wait-loop races, LOW tail (#136) (@ShixiangWang)
  • cluster: Resolve #136 H-items — array chunking, non-SLURM polling, cap semantics, submit-time checkpoint (@ShixiangWang)
  • V0.13.1→v0.14.0 audit fixes — dispatch regressions, log masking, core safety, CI release integrity (#136) (@ShixiangWang)
  • cli: Keep-going changes scheduling, never the verdict — exit non-zero on required failures (#133) (@ShixiangWang)
  • core: Kill in-flight rule processes on abort — no more orphans (#131) (@ShixiangWang)

Documentation#

  • Cluster fairness — priority honored with aging, in-flight cancel, wait-visibility boundary (#134 follow-up) (@ShixiangWang)
  • Dag-engine — FIFO acquisition makes priority starvation impossible (the guarantee) (@ShixiangWang)

Features#

  • core: Cluster driver honors priority with fair-dispatch aging (#134) (@ShixiangWang)
  • core: FIFO-gated resource acquisition — the 100% no-starvation guarantee (#123) (@ShixiangWang)

Testing#

  • Update the fourth keep-going exit-0 site (report --failed harness) (@ShixiangWang)
  • Assert the process is dead, not the pid file — #118 legitimately removes it (@ShixiangWang)
  • cli: Serialize logging tests over the process-global run-log slot (@ShixiangWang)
  • Bisect the CI-only abort-test failure — 10s window + verbose run log in panics (@ShixiangWang)
  • Surface the run's stderr in abort-test assertion failures (@ShixiangWang)
  • Widen the abort-test margin — slow must spawn before bad fails on slow CI runners (@ShixiangWang)

0.14.0 — 2026-08-21#

Documentation#

  • Dag-engine — fair dispatch prevents resource starvation (aging + submit cap) (@ShixiangWang)

Features#

  • cli: Fair dispatch — priority aging + -j submit cap; lint W019 empty outputs (@ShixiangWang)
  • core: Resource-pool wait diagnostics — name what a waiting rule needs and who holds it (@ShixiangWang)

Refactoring#

  • cli: Extract age_ready_list as a pure, unit-tested function (@ShixiangWang)

Styling#

  • cli: Reword age_ready_list doc to satisfy clippy doc_lazy_continuation (@ShixiangWang)

0.13.1 — 2026-08-21#

Bug Fixes#

  • web: Cancel verifies real group death; de-flake web_integration family (#120) (@ShixiangWang)
  • core: Invalidate failed rules' outputs so stale files never skip a re-run (@ShixiangWang)
  • core: Conda env bin first in PATH inside conda run wrappers (@ShixiangWang)
  • core: Conda run --no-capture-output to kill the capture-poll hang (@ShixiangWang)
  • core: [[pairs]] members feed the merged config.samples_list (@ShixiangWang)
  • references: Use the documented checkpoint path + persist legacy adoption (@ShixiangWang)
  • cluster: A fresh dependency no longer stalls the driver (@andrewbudge)
  • core: Singularity setup pulls only when the SIF is absent — pull refuses to overwrite (@ShixiangWang)
  • core: Docker setup pulls only when the image is absent — concurrent rules sharing one image race in the daemon (@ShixiangWang)
  • core: Docker setup pulls only when the image is absent — concurrent rules sharing one image race in the daemon (@ShixiangWang)
  • Close #99 review gaps — cluster masking/B2 parity, AI recovery target, error-path masking (@ShixiangWang)
  • config: Promote sensitive-only inline configs; rule required defaults to true (@ShixiangWang)
  • wildcards: Substitute fan-out values into script and hook fields (@ShixiangWang)
  • references: Guard source content in the reference fingerprint (@ShixiangWang)
  • core: Container cgroup caps at physical RAM — swap counts for scheduling, not cgroups (@ShixiangWang)
  • core: Timeout diagnostic reads the holder pid from the lock file (@ShixiangWang)
  • core: Per-environment create locks with a bounded wait — no more global serialization (@ShixiangWang)
  • core: {effective_memory_mb} stays RAM-only — swap counts for scheduling, not tool sizing (@ShixiangWang)
  • core: Verify existing conda envs before re-running setup on a cold cache (@ShixiangWang)
  • core: Clamp docker/singularity cgroup --memory to the machine total (@ShixiangWang)
  • core: Export the base conda CA bundle during env setup (@ShixiangWang)
  • core: Never infer a rule edge to itself (@ShixiangWang)
  • core: Expand {config.x} placeholders before DAG edge matching (@ShixiangWang)
  • core: Container rules run under image bash when available; deterministic dir-creation errors (@ShixiangWang)
  • cli: Render {source} in reference build commands (@ShixiangWang)
  • core: Serialize conda env setup per environment key (@ShixiangWang)
  • core: Verify conda envs after setup; repair broken ones (@ShixiangWang)
  • core: Shared output strings link EVERY producer in the DAG (@ShixiangWang)
  • core: DAG template graphs include expand_inputs dataflow edges (@ShixiangWang)
  • core: Derive conda env name for setup, not just wrap (@ShixiangWang)
  • core: Clamp over-capacity rule requests instead of fast-failing (@ShixiangWang)
  • core: Resolve nested {config.x} references deterministically (#88) (@ShixiangWang) (#88)
  • ai: Unify AI config path + accurate provider labels (@ShixiangWang)

CI/CD#

  • Enable workflow_dispatch to drive the full release pipeline (@ShixiangWang)
  • frontend: E2e webServer timeout + feature-unification warm-up fix (@ShixiangWang)

Documentation#

  • readme: Bioconda version badge + systematic badge refresh (@ShixiangWang)
  • run: Fix glued heading in the --module section (@ShixiangWang)
  • run: Document automatic job arrays in cluster submission (#74 phase 3) (@ShixiangWang)
  • workflow-format: Teach the aggregation idiom — expand_inputs + {input} (@ShixiangWang)
  • Document sensitive masking and required=false continue-on-error semantics (@ShixiangWang)
  • Document script/hook fan-out substitution and reference content guard (@ShixiangWang)
  • run: Clarify profile names carry no built-in meaning (@ShixiangWang)
  • gallery: 16s run instruction — activate the QIIME2 env, drop the nonexistent --profile conda (@ShixiangWang)
  • gallery: Add the missing 16th workflow to the Learning Path (@ShixiangWang)
  • Purge stale root-doc content (README gallery, roadmap, limitations, releasing, agents, security) (@ShixiangWang)
  • Per-environment creation locks with bounded wait (@ShixiangWang)
  • Resource ceiling counts swap (--max-memory pins to RAM) (@ShixiangWang)
  • Container --memory clamping + env verify-before-setup behaviors (@ShixiangWang)
  • Harden the China mirrors guide with live-campaign findings (@ShixiangWang)
  • DAG edge inference expands {config.x} placeholders (from_rules_with_config) (@ShixiangWang)
  • Sync deadlock/resource semantics with the clamp change (@ShixiangWang)

Features#

  • info: Derive workflow git provenance in info --json (#124) (@ShixiangWang)
  • run-log: Per-run archived log with versioned header + report git sha (@ShixiangWang)
  • provenance: Record workflow git HEAD SHA in checkpoints (#115) (@ShixiangWang)
  • Partial module runs (--module) + git-pinned includes (#112 elasticity) (@ShixiangWang)
  • include: Typed interface contracts for workflow modules (#112 module slice) (@ShixiangWang)
  • cluster: Job arrays for scatter rules (issue #74 phase 3) (@ShixiangWang)
  • core: Singularity spec accepts a local SIF path (site-deployed images) (@ShixiangWang)
  • Workflow-global shell prelude (issue #92) + explicit null-stdin contract (issue #101) (@ShixiangWang)
  • Mask sensitive config values + wire rule-level required=false (#99 B1/B2) (@ShixiangWang)
  • core: Swap-aware resource detection — the ceiling is RAM + swap (@ShixiangWang)
  • core: Cross-process env-create mutex — serialize conda creates across runs (@ShixiangWang)
  • core: {effective_threads}/{effective_memory_mb} placeholders — tools size themselves to the machine (@ShixiangWang)
  • cluster-run: Report snapshot parity + cluster.md cross-ref (PR #93 follow-up) (@ShixiangWang)
  • Run --profile submits to a scheduler when the profile declares [cluster] (issue #74 phase 2) (@andrewbudge)
  • core: [[references]] entries can declare an environment (@ShixiangWang) (#90)
  • cli: Unify sample selection under --samples (@ShixiangWang)
  • cli: Info derives config descriptions from [config] comments (@ShixiangWang) (#86)

Maintenance#

  • deps: Bump h2 0.4→0.4.16, ignore RUSTSEC-2026-0258 for the aws-sdk's h2 0.3 (@ShixiangWang)

Styling#

  • core: Struct-init test helpers instead of Default + reassign (@ShixiangWang)
  • core: Collapse collapsible ifs (clippy -D warnings clean after rebase) (@ShixiangWang)

Testing#

  • core: Exercise the production lock-path derivation (@ShixiangWang)
  • core: Env-create lock test uses a temp dir, not the real HOME (@ShixiangWang)
  • Assert on the mamba backend's detected binary (@ShixiangWang)

0.13.0 — 2026-08-15#

Bug Fixes#

  • core: Pixi backend uses --manifest-path (workflow spec names the file) (@ShixiangWang)
  • cli: LSF dependency flag uses double quotes in submit.sh (@ShixiangWang)
  • core: Venv setup uses POSIX . instead of bash source (@ShixiangWang)
  • core: Container backends bind absolute host paths (@ShixiangWang)
  • core: Expand rule log-field wildcards per instance (@ShixiangWang)
  • core: E003 exempts [[values]]-declared parameter wildcards (@ShixiangWang)
  • web: Wire env badge colors to theme tokens and refresh SPA bundle (@ShixiangWang)
  • cli: Profile merge order + info accuracy + plan JSON surface (@ShixiangWang)
  • core: Harden v0.13 features found by release review (@ShixiangWang)
  • ci: Publish rpm and AppImage to releases; docs: complete release asset docs (@ShixiangWang)

CI/CD#

  • Publish stable-named latest CLI tarball in releases (@ShixiangWang)

Documentation#

  • Sync info and {log} docs with release-review behavior (@ShixiangWang)
  • Release-review documentation and CI fixes (@ShixiangWang)
  • [[values]] fan-out, scratch rules, reference templates, profile override, {log}, pairs_list, plan JSON (@ShixiangWang)
  • Editor setup how-to — .oxoflow files as TOML in VS Code and other editors (@ShixiangWang)

Features#

  • core: Reference builder templates + naming standard (@ShixiangWang)
  • core: Rule-level scratch workdir (scratch = true) (@ShixiangWang)
  • core: [[values]] parameter wildcards + reference builder wiring (@ShixiangWang)
  • core: Expanded-path DAG edge inference (@ShixiangWang)
  • cli: Add info command with per-key config derivation (@ShixiangWang)
  • cli: Route profile merge through core merge_profile (@ShixiangWang)
  • core: Inject config.pairs_list + profile override mode (@ShixiangWang)
  • cli: Unknown --flag hard error + dry-run --json plan export (@ShixiangWang)
  • core: {log} placeholder, array-config join, bash executor (@ShixiangWang)
  • ci: Desktop bundles carry a -desktop- infix in their names (@ShixiangWang)

Styling#

  • web: Environment badge colors as semantic theme tokens (@ShixiangWang)

Testing#

  • Gallery_07 asserts topo order semantically, not by tie-break (@ShixiangWang)

0.12.0 — 2026-08-15#

Bug Fixes#

  • web: Normalize base_path in the standalone web binary (@ShixiangWang)
  • web: Inject at the START of , always (@ShixiangWang)
  • web: Pbsnodes attribute lines leaked in as node names (@ShixiangWang)
  • web: Validate usernames at the POST /api/users entry point (@ShixiangWang)
  • report: Dashboard never divides instances by rule count (@ShixiangWang)
  • Upgrade-compatibility and mount-path hardening (review follow-ups) (@ShixiangWang)
  • web: Quota release on every terminal path + daily reset + terminal-state guards (@ShixiangWang)
  • core: Cluster driver settles jobs that leave the live queue (@ShixiangWang)
  • core: Staged remote keys must not escape the staging tree (@ShixiangWang)
  • web: Tenant isolation gaps in audit, AI cache, chat tools, pipeline read (@ShixiangWang)
  • web: Remote SSH command injection via cluster fields (@ShixiangWang)
  • web: Username/path traversal in workspace paths, symlink leak in zip downloads (@ShixiangWang)
  • web: Scheduler probe must honor exit status, not spawn success (@ShixiangWang)
  • scripts: Deploy-smoke hpc scenario authenticates before /api/hpc (@ShixiangWang)
  • web: Complete LSF/SGE status collection in hpc.rs (@ShixiangWang)
  • cli: Comment stale scaffold template placeholders + sync --strict help text (#83) (@ShixiangWang)
  • cli: --acct optional-JobID panic, array-task batch pref, test gaps (#83 P1-13) (@ShixiangWang)
  • cli: Restore --workdir checkpoint precedence, template autoescape + path resolution, json/md gate (#83 P1-1/P0-9) (@ShixiangWang)
  • web: Don't cache the shared-runtime AI provider fallback — a runtime provider swap must take effect immediately (chat_agent_integration caught a stale cached scripted provider) (@ShixiangWang)
  • executor: Honest per-process CPU docs + flake-guard assertion + SeqCst (#83 P1-13) (@ShixiangWang)
  • report: Commit the actual report_metrics split — orphan adapters.rs now compiled (#83 P1-5) (@ShixiangWang)
  • report: Sample-matrix engine-real instance naming, filter-path panic guard, STAR % parsing (#83 P1-5) (@ShixiangWang)
  • Cluster submit expands wildcards, captures real job ids, surfaces walltime (#74 phase 1) (#84) (@andrewbudge) (#84)
  • ci: Make the e2e suite actually pass — rate-limit escape hatch, guest nav, canvas-mode pinning (@ShixiangWang)
  • web: Dashboard runs-envelope adaptation + fmt normalization; docs: README DAG stack (React Flow + d3-dag, not cytoscape) (@ShixiangWang)
  • deploy-smoke: Binary discovery for deployed servers; scoped cleanup (@ShixiangWang)
  • Runs list — clickable rows, detail scrolls into view, paging (issue #79 P2) (@ShixiangWang)
  • Eliminate CSP unsafe-eval violations — vega-interpreter for report charts (issue #79 P2) (@ShixiangWang)
  • storage: Make s3-storage compile — head() NotFound returns None, sync client init, drop dead match arm (#80) (@ShixiangWang)
  • Storage_resolver local-only (cfg branches land with the feature opt-in); snapshot 4-arg call (#78) (@ShixiangWang)
  • gallery: Declare optional classifier config in the 16S QIIME2 template (#79 E005) (@ShixiangWang)
  • /api/health reports the real deployment mode (issue #79 P1-03 family) (@ShixiangWang)
  • Status single-source, UI wiring, AI delivery, editor guards (issue #79 R-02/03/04/06/07/09/10) (@ShixiangWang)
  • Web platform security triad — rate limit, audit trail, admin auth (issue #79 P1-04/05/06) (@ShixiangWang)
  • One run = one process group; honest crash recovery (issue #79 P1-01/P1-02) (@ShixiangWang)
  • web: Retry SQLite pool init on transient disk I/O errors (CI runner flakes) (@ShixiangWang)
  • frontend: Replace Date.now with crypto.randomUUID; silence fast-refresh on showToast export (@ShixiangWang)
  • web: Single ordered chat event channel — no select-in-yield, boxed outcome (@ShixiangWang)
  • ai: Coalesce tool_result blocks per Anthropic's pairing rule — second live finding (@ShixiangWang)
  • ai: Claude backend emits tool_use blocks — found by live round-trip (@ShixiangWang)
  • web: Restore DB-persisted AI config at startup; chat_messages table (@ShixiangWang)
  • web: Revert kind field on legacy handler's local edge type (@ShixiangWang)
  • web: Attribute pipeline ownership to acting user; compute real effective AI config (@ShixiangWang)
  • web: Verify and consume OAuth state server-side (@ShixiangWang)
  • web: Unify audit_logs schema across init paths; insert_run fills all columns (@ShixiangWang)
  • web: Unify run status vocabulary on completed (@ShixiangWang)
  • Embed template gallery from crate-local templates/ so cargo publish works (issue #76 P1-3 follow-up) (@ShixiangWang)

CI/CD#

  • Drop broken step PATH override in e2e job (env context PATH is empty in Actions) (@ShixiangWang)
  • Frontend build + e2e job gates the web UI (@ShixiangWang)

Documentation#

  • Webhook signature schemes, audit admin-only scope, retry/pause terminal guards (@ShixiangWang)
  • Production deployment — systemd unit + nginx reverse proxy (@ShixiangWang)
  • Drop stale v0.10.x version prefixes from feature intros (@ShixiangWang)
  • Fix ACMG Tier III 'Uncertain significance' wording (#83) (@ShixiangWang)
  • Report capabilities — metrics parsing, template wiring, auto-snapshots (#83 Task 5) (@ShixiangWang)
  • Point the API reference at the code-generated spec; drop the stale hand-maintained openapi.yaml (@ShixiangWang)
  • Per-user AI credentials resolution + canvas comment preservation (@ShixiangWang)
  • Deploy modes — OXO_FLOW_DISABLE_RATE_LIMIT testing escape hatch (@ShixiangWang)
  • Link oxo-flow-community catalog from README and guide nav (@ShixiangWang)
  • Desktop app — SPA assets ship prebuilt in static/ (rebuild for latest UI) (@ShixiangWang)
  • Drop remaining clinical-grade claims about oxo-flow itself (#83 P0-1) (@ShixiangWang)
  • Report documentation sweep — honest claims, new flags, new sections (#83) (@ShixiangWang)
  • Collaboration — share landing pages, enforced visibility, version history (@ShixiangWang)
  • Sync web docs with the v0.11 hardening (files/instances/webhooks/API keys/retry semantics/share landing/remote cluster execution/multi-tenancy/guided mode) (@ShixiangWang)
  • Release asset table for desktop bundles (dmg/deb/rpm/AppImage) (@ShixiangWang)
  • Dry-run usage/parity note + status timing example with peak RSS column (@ShixiangWang)
  • Sync command pages with the alignment audit + new ai command page (#67) (@ShixiangWang)
  • China network mirrors reference — snapshot findings, recommended stack, re-runnable probe script (#67) (@ShixiangWang)
  • Staging/pairs-reentry/HMAC/cluster-logs/diagnostics sync for #80 + #67 (@ShixiangWang)
  • Design for #80 follow-up — S3 toolchain bump, remote staging, pairs re-entry (#80) (@ShixiangWang)
  • Execution backends, storage invalidation, checkpoint re-entry (#78) (@ShixiangWang)
  • Deployment modes reflect verified behavior (sub-path mount, run-control truth, user/audit management) (@ShixiangWang)
  • Implementation plan for issue #78 — 19 tasks across P1/P2/P3 (@ShixiangWang)
  • Refresh stale test counts; clarify parity contract comment (@ShixiangWang)
  • Design spec for issue #78 — static plan + pluggable executors (P1/P2/P3) (@ShixiangWang)
  • Document tombstones in checkpoint format (status + glossary) (@ShixiangWang)
  • Remove web evaluation report — superseded by issue #79 (@ShixiangWang)
  • Sync consistency work across run/dry-run/troubleshooting (@ShixiangWang)
  • Add web simulated-user evaluation report (12 personas, 5-dimension verdict) (@ShixiangWang)
  • Add web simulated-user evaluation design (@ShixiangWang)
  • Mark web design spec complete — merged to main (@ShixiangWang)
  • All phases complete — spec status finalized (@ShixiangWang)
  • Live AI verification done — real Claude loop validated end-to-end (@ShixiangWang)
  • Final phase-status annotation in the web spec (@ShixiangWang)
  • Annotate P2/P3 completion and deviations in the web spec (@ShixiangWang)
  • P3 AI assistant implementation plan (@ShixiangWang)
  • Dag edit API extended ops + web canvas how-to guide (@ShixiangWang)
  • P2 graphical editor implementation plan (@ShixiangWang)
  • Annotate P0 fixes in web design spec (@ShixiangWang)
  • P0 execution-truth implementation plan (@ShixiangWang)
  • Web full-lifecycle design spec — graphical editor, grounded AI, execution truth fixes (@ShixiangWang)

Features#

  • web: Rule timeline — the terminal-native signature element (@ShixiangWang)
  • web: Quota endpoint reports the acting user's usage (@ShixiangWang)
  • cli: Run auto-snapshot + --r-data TSV export + report --diff/--acct (#83 P1-14/P1-15/P1-6/P1-13) (@ShixiangWang)
  • cli: Zero-arg report discovery, --run/--failed/--plan, template wiring (#83 P1-1/P0-9/P2-7) (@ShixiangWang)
  • web: Code-generated OpenAPI 3.1 spec via utoipa (issue #82 P1-13) (@ShixiangWang)
  • executor: Sampled CPU-seconds metering → BenchmarkRecord + honest CPU column (#83 P1-13) (@ShixiangWang)
  • web: Preserve TOML comments/formatting in canvas edits (issue #82 P2-3) (@ShixiangWang)
  • web: Per-user AI provider runtime isolation (deferred #82 item) (@ShixiangWang)
  • report: Metrics adapters for fastp/flagstat/STAR/featureCounts/bcftools/kraken2 + rule×sample matrix (#83 P1-5) (@ShixiangWang)
  • web: Remote cluster execution over SSH — stage/launch/poll/pull (#82 deployment modes) (@ShixiangWang)
  • report: Execution-truth reporting — WS1 honesty + WS2 checkpoint facts + WS3 single contract (#83) (@ShixiangWang)
  • web: #81 backlog — validate parity, CLI command exposure, misc fixes (@ShixiangWang)
  • web: Polish — dark mode, TOML highlighting, quota enforcement, error-line jumps (#82 P1-9/P2) (@ShixiangWang)
  • web: API contract & cleanup — diff contract, pagination, webhooks, API keys, rule-level SSE (#82 P1-3/P1-4/P1-10/P1-12/P1-13/P1-18) (@ShixiangWang)
  • web: Beginner layer — guided builder, task-oriented home, i18n zh, role-trimmed nav (#82 P1-5/P1-7/P1-8/P1-15) (@ShixiangWang)
  • web: Share closure + pipeline version history (#82 P0-6/P1-14) (@ShixiangWang)
  • web: Run-loop closure — real retry, logs view, instances, cancel, telemetry (#82 P0-3/P0-7/P1-1/P1-2/P1-19) (@ShixiangWang)
  • web: File service layer — download/preview/zip results, multipart upload (#82 P0-1/P0-2) (@ShixiangWang)
  • web: Multi-tenancy isolation — ownership scoping on every run/pipeline/control endpoint (#82 P0-4/P0-5) (@ShixiangWang)
  • ci: GitHub release ships desktop bundles — macOS .app/.dmg, Linux .deb/.rpm/.AppImage (@ShixiangWang)
  • cli: Alignment audit — status --timing memory columns, touch --workdir + workflow-dir base, test execution flags, resume -k/--timeout, batch --json honored, -d short unified (#67 follow-up) (@ShixiangWang)
  • cli: Dry-run parity with run — --arg/KEY=VALUE/--sample/--rerun/--resume-failed, shared override helpers, executor freshness gate in the preview (4 new parity scenarios) (@ShixiangWang)
  • Deployment smoke suite (7 scenarios) + config-file defaults for CLI serve (@ShixiangWang)
  • Instance-level dry-run preview in the web UI (issue #79 P2) (@ShixiangWang)
  • executor: Sampled peak-RSS metering → BenchmarkRecord + diagnostics resource_bottlenecks at ≥80% of declared limit (#67) (@ShixiangWang)
  • cli: Cluster logs — last stub resolved via ExecutorBackend::logs (sacct/qstat/qacct/bacct), mock-scheduler tested (#67) (@ShixiangWang)
  • webhook: Real HMAC-SHA256 signatures (RFC 4231 verified), legacy keyed-sha256 behind signature_scheme (#67) (@ShixiangWang)
  • reentry: [[pairs]]-driven checkpoint re-entry — manifest pairs, pair_id identity, E015 conflict, E016 collision, E014 extended (#80) (@ShixiangWang)
  • storage: Remote staging/upload — etag-keyed cache, pattern substitution on a rule copy, upload-after-validate, MinIO E2E (#80) (@ShixiangWang)
  • storage: S3-storage compiles and works live — env config, path-style opt-in, resolver registration, MinIO etag E2E (#80) (@ShixiangWang)
  • ui: Design system v2 — terminal-vernacular identity (issue #79 aesthetics) (@ShixiangWang)
  • Platform config file + SSH cluster connections (web) — ai/ssh customization surface (@ShixiangWang)
  • Desktop packaging — single-file .app/.dmg/.deb via cargo-bundle; serve env vars + --open (@ShixiangWang)
  • cli: Dry-run previews deterministic re-entry reconstruction (#78) (@ShixiangWang)
  • cli: Checkpoint re-entry hook in the run loop (#78) (@ShixiangWang)
  • core: Checkpoint re-entry — manifest surface, template re-expansion, records (#78) (@ShixiangWang)
  • cli: Thread StorageResolver into manifest snapshots; graceful remote-input degradation (#78) (@ShixiangWang)
  • core: Etag-aware remote manifest snapshot + unified manifests_match (#78) (@ShixiangWang)
  • core: Remote manifest entries (scheme/key/etag/size), backward compatible (#78) (@ShixiangWang)
  • core: StorageBackend::head + RemoteStat — S3 ETag / GCS md5Hash (#78) (@ShixiangWang)
  • 16S amplicon gallery template (QIIME2 backbone) — issue #79 R-10 domain gap (@ShixiangWang)
  • core: BackendDriver — submit/poll loop with queue cap and failure propagation (#78) (@ShixiangWang)
  • Sub-path deployment — --base-path actually mounts the app (issue #79 deployment modes) (@ShixiangWang)
  • core: ExecutorBackend trait + ClusterExecutor with shared job-id/status parsing (#78) (@ShixiangWang)
  • core: ScheduledPlan + ScheduledRule — executor-agnostic static plan (#78) (@ShixiangWang)
  • Temporary rules with tombstone + lazy cascade-up; configurable cache aging (@ShixiangWang)
  • Close the dry-run/run consistency gaps + content-hash invalidation (@ShixiangWang)
  • web: Run-diagnosis chat tools; tool errors emit ToolResult events (@ShixiangWang)
  • frontend: My Pipelines page (open/export/delete), pipeline loading, login page (@ShixiangWang)
  • web: Chat prompt enforces TOML array I/O and direct validation fixes; 6 rounds (@ShixiangWang)
  • web: Report Q&A and visualization answer from real run data (@ShixiangWang)
  • web: Run options dialog — samples, targets, keep-going, max jobs; template loading (@ShixiangWang)
  • frontend: Chat renders grounded tool-call cards (@ShixiangWang)
  • web: Chat runs the grounded agent loop with real streaming events (@ShixiangWang)
  • ai: Orchestrator event sink and cancellation (@ShixiangWang)
  • ai: Streaming chat for openai-compatible providers (@ShixiangWang)
  • frontend: React Flow canvas editor — palette, inspector, edge kinds, monitor reuse; drop cytoscape (@ShixiangWang)
  • web: Null patch key removes field in dag edit API (@ShixiangWang)
  • web: Dag nodes carry environment and full serialized rule (@ShixiangWang)
  • web: Knowledge search endpoints for the editor palette (@ShixiangWang)
  • web: Dag edges tagged file vs declared (@ShixiangWang)
  • web: Dag edit API supports full rule specs via TOML-patch update_rule (@ShixiangWang)
  • web: Node status derived from engine checkpoint; drop dead run_nodes table (@ShixiangWang)
  • web: Cancel/pause/resume signal the live run process group (@ShixiangWang)
  • web: Executor registers run process group, defers to cancel state (@ShixiangWang)
  • web: Process-group registry for real run control (@ShixiangWang)

Maintenance#

  • Bump rust-toolchain 1.92.0 → 1.97.1 (aws-sdk MSRV 1.94.1; #80) (@ShixiangWang)
  • frontend: Zero lint errors; lint joins the CI frontend gate (@ShixiangWang)

Refactoring#

  • cli: Group report command args into ReportArgs (clippy too_many_arguments under -D warnings) (@ShixiangWang)
  • Clippy-clean chat degradation buffer + audit module layout (@ShixiangWang)
  • cli: Cluster submit renders via ExecutorBackend; P1 acceptance tests (#78) (@ShixiangWang)
  • web: Remove legacy handlers, legacy router, and 20-user simulation tests (5k+ lines) (@ShixiangWang)
  • web: Delete legacy handlers modules and 20-user simulation tests; hpc_status moved to observability (@ShixiangWang)
  • frontend: Delete dead Runs page and SSEClient; fix lint in new components (@ShixiangWang)

Styling#

  • web: Breathing running badge + last hardcoded color in Share (@ShixiangWang)
  • web: Replace hardcoded hex colors with theme tokens (@ShixiangWang)
  • web: Rustfmt hpc.rs probe condition (CI fmt gate) (@ShixiangWang)
  • Type alias for the per-user AI row (clippy complex-type) (@ShixiangWang)
  • Type alias for the per-user AI row (clippy complex-type) (@ShixiangWang)
  • Clippy — clamp, let-chains, vec literals, type aliases, Option::map (workspace clean except #83 WIP) (@ShixiangWang)
  • Cargo fmt normalization (config loader, preview handler, dry-run test) (@ShixiangWang)
  • web: Collapse nested if in preview extraction (clippy -D warnings); docs: remote-glob wording (#67) (@ShixiangWang)
  • Drop blank lines left by the audit tests-module move (@ShixiangWang)
  • ai: Drop duplicate test import (@ShixiangWang)
  • web: Drop needless into on strings (@ShixiangWang)
  • ai: Collapse nested ifs in stream usage capture (@ShixiangWang)

Testing#

  • Update constructors for the enriched validate envelope; hpc route now requires auth in hpc mode (#82 P0-5) (@ShixiangWang)
  • web: Initialize both DB layers in router tests (audit middleware from #79 inserts via legacy pool) (@ShixiangWang)
  • BackendDriver checkpoint re-entry — round-2 execution via mock scheduler (#78) (@ShixiangWang)
  • Mock SLURM scheduler fixtures for cluster CI (issue #78/#74) (@ShixiangWang)
  • Parity contract matrix guards run/dry-run consistency (issue #77) (@ShixiangWang)
  • Upsert AI config row in restore test (parallel-safe) (@ShixiangWang)
  • Merge scripted-provider chat scenarios into one sequential test (registry is process-wide) (@ShixiangWang)
  • Async-aware lock for scripted-provider chat tests (@ShixiangWang)
  • Pipelines page title in legacy specs (@ShixiangWang)
  • Oauth state test self-initializes the infra pool (was order-dependent) (@ShixiangWang)
  • Root web integration expects completed status vocabulary (@ShixiangWang)

0.11.0 — 2026-08-13#

Bug Fixes#

  • Embed template gallery from crate-local templates/ so cargo publish works (issue #76 P1-3 follow-up) (@ShixiangWang)
  • Scientific review of gallery examples — RG escaping, env mismatches, (@ShixiangWang)
  • Scientific review of top-level examples — read groups, DAG races, env mismatch (@ShixiangWang)
  • Embed the template gallery in the binary — template works from installed releases (issue #76) (@ShixiangWang)
  • Web run flags reach the CLI executor — issue #69 follow-up (@ShixiangWang)
  • AI provider robustness — tool-call repair, overflow recovery, bounded results (issue #73, Phase 1 + 2.4) (@ShixiangWang)
  • Checkpoint reuse validates input manifests — issue #72 (@ShixiangWang)
  • Deep checks respect --workdir; drop duplicated #70 lock test (@ShixiangWang)
  • Allow too_many_arguments on dry_run_command (clippy -D warnings) (@ShixiangWang)
  • Resolve readiness paths against the workflow dir, not the process CWD (issue #63) (@ShixiangWang)
  • Actionable error for run flags swallowed by trailing overrides (issue #71) (@ShixiangWang)
  • MCP tool bridges register under def name (issue #61) (@ShixiangWang)
  • Avoid panic on non-UTF-8 CLI arguments (@ShixiangWang)
  • Post-merge review of #59 — bundle manifest source, tempdir cleanup, honest tests (@ShixiangWang)
  • Bundle gate probes stdin, and lint test code in CI (@andrewbudge)
  • Move modules deserializer before test module (items after a test module lint) (@ShixiangWang)
  • Examples — GATK best-practice alignment flags and BQSR known-sites (@ShixiangWang)
  • Web — run persistence, export by ID, SSE completion, legacy DB migration (@ShixiangWang)
  • Cli — JSON output, help texts, report --ai fallback, pixi env create (@ShixiangWang)
  • Ai knowledge — graph integrity test, dangling edge, honest counts (@ShixiangWang)
  • Engine — resource-group fast-fail, deferred chunk cleanup, config-var expansion (@ShixiangWang)
  • Transform operator — chunk extension, GatherVcfs args, cleanup implementation (@ShixiangWang)
  • Scientific correctness of examples and workflow-format docs (@ShixiangWang)
  • Gallery examples — sample expansion and output paths in multiomics & scRNA-seq (@ShixiangWang)
  • Resolve_config_list splits comma-joined strings; samples_list usable in expand_inputs (@ShixiangWang)
  • Rnaseq gallery — multiqc must not depend on index_bam (@ShixiangWang)
  • Diff now detects defaults, pairs, and sample group changes (@ShixiangWang)
  • Dry-run -j suggestion capped by DAG width — professional parallelism advice (@ShixiangWang)
  • Resource pool waits for availability instead of failing; professional -j suggestion (@ShixiangWang)
  • Dry-run lists rules in parallel-group order, not arbitrary topo order (@ShixiangWang)
  • Apply_defaults must respect rule-level resources.threads/memory (@ShixiangWang)
  • Deduplicate downstream rules in graph tree view (@ShixiangWang)

CI/CD#

  • Tolerate already-synced versions on re-tag (sync-version idempotency) (@ShixiangWang)
  • Install release target into the pinned toolchain (macOS builds) (@ShixiangWang)

Documentation#

  • Changelog for v0.11.0 — repository workflows, checkpoint-aware dry-run, AI explain/robustness, command consolidation (@ShixiangWang)
  • Update subcommand count to 29 in README, CONTRIBUTING, AGENTS (issue #76 follow-up) (@ShixiangWang)
  • Update guides for command consolidation — status timing view, export compose, removed commands, profile mechanism (issue #76) (@ShixiangWang)
  • Unify gallery embed style and ship the referenced environment specs (@ShixiangWang)
  • Cross-link dry-run checkpoint preview from run pilot flow and DAG skip checklist (issue #66 follow-up) (@ShixiangWang)
  • Mark rule hooks and optional as parsed-but-not-enforced (issue #75) (@ShixiangWang)
  • Fix 'ai status' references after ai action-space change (issue #65) (@ShixiangWang)
  • Ai explain + provider robustness reference (issues #65, #73) (@ShixiangWang)
  • Sync #72 input-manifest invalidation into troubleshooting, DAG skip guide, and glossary (@ShixiangWang)
  • Cross-link validate/env to test --deep (D002/D003 cover env files and PATH binaries, issue #64 follow-up) (@ShixiangWang)
  • Finish #68/#70 doc sweep — validate path base, clean lock guard, run --workdir scenario (@ShixiangWang)
  • Complete help descriptions for every command, subcommand, and argument (@ShixiangWang)
  • Sync #63 readiness + --samples ready into run/dry-run/test/cohort how-to (@ShixiangWang)
  • Link gallery concept explanations to reference docs (@ShixiangWang)
  • Explain expand_inputs in WGS gallery with reference links (@ShixiangWang)
  • Sync config-change invalidation into run/resume/status/architecture/workflow-format (@ShixiangWang)
  • Teach wildcards fan-out vs fan-in for beginners (@ShixiangWang)
  • Sync #60 pilot workflow into quickstart, cohort how-to, and wgs gallery (@ShixiangWang)
  • Use sk- placeholder form for API keys (no bare sk-... patterns) (@ShixiangWang)
  • Run --bundle gate semantics — non-interactive sessions and --json require --yes; fix --profile row (@ShixiangWang)
  • Comprehensive audit — sync all pages with engine behavior and science (@ShixiangWang)
  • Sync gallery pages with scientific fixes in examples (@ShixiangWang)
  • How-to audit — align 12 guides with engine behavior; fix example resources (@ShixiangWang)
  • Gallery index — clarify graph (template) vs dry-run (expanded) DAG (@ShixiangWang)
  • Explain {input} vs {input[0]} equivalence and when to use each (@ShixiangWang)
  • Clarify gather routing is declared via scatter.gather, not inferred (@ShixiangWang)
  • Document gather inference reliability in complex scatter-gather (@ShixiangWang)
  • Fix multiomics -j advice — resource pool schedules by thread capacity (@ShixiangWang)
  • Unify -j values with professional suggestion; clarify optional input/output (@ShixiangWang)
  • Note ToolRegistry non-Clone limitation in create_context (@ShixiangWang)
  • Document four embedded AI knowledge sources in ai-cli.md (@ShixiangWang)
  • Document env create --ai in AI CLI command reference (@ShixiangWang)
  • Environment-management — add missing mamba and modules sections (@ShixiangWang)
  • Rewrite variant-calling tutorial with professional paired tumor-normal design (@ShixiangWang)
  • Quickstart — output directories are auto-created, remove mkdir boilerplate (@ShixiangWang)
  • Remove stale INFO log line from quickstart run output (@ShixiangWang)
  • Extend custom-scripts example to two chained script rules (@ShixiangWang)
  • Rewrite custom-scripts tutorial with runnable example and params explanation (@ShixiangWang)
  • Multiqc aggregates only the two QC rounds; clarify parallel scheduling (@ShixiangWang)
  • Fix tutorial DAG — multiqc had no real dependencies with directory inputs (@ShixiangWang)
  • Move Wildcard Patterns admonition out of TOML code block (@ShixiangWang)
  • Fix markdown list rendering in quickstart web UI section (@ShixiangWang)

Features#

  • Repository workflows — pull/run clone git repos directly (no bundle required) (@ShixiangWang)
  • Consolidate commands — status absorbs history, export gains compose, remove history/package/profile/watch (issue #76) (@ShixiangWang)
  • Value recovery from the dead-code audit — optional rules, hook (@ShixiangWang)
  • Dry-run checkpoint preview — rerun blast radius and protected scope (issue #66) (@ShixiangWang)
  • Web runs link to saved pipelines with persistent workdirs — issue #69 (@ShixiangWang)
  • Ai explain — three-layer workflow explanation (issue #65) (@ShixiangWang)
  • --workdir on dry-run/test/clean/report/resume; validate uses workflow dir (issue #68) (@ShixiangWang)
  • Workdir lock prevents concurrent-run checkpoint races (issue #70) (@ShixiangWang)
  • Test --deep pipeline health checks (issue #64) (@ShixiangWang)
  • Checkpoint remembers its workdir; resume re-runs from it (issue #68) (@ShixiangWang)
  • Sample readiness + --samples ready for incremental data arrival (issue #63) (@ShixiangWang)
  • Config-change impact analysis — precise checkpoint invalidation (issue #62) (@ShixiangWang)
  • Custom skills Phase 2 (MCP tool skills) + Phase 3 (SKILL.md) — issue #61 (@ShixiangWang)
  • Banner header for run logs; fix help art glyphs (@ShixiangWang)
  • User-defined custom skills — Phase 1 secure minimal loop (issue #61) (@ShixiangWang)
  • AI preflight & pilot summary (issue #60 Phase 2) — scientific constraints + scale-up projection (@ShixiangWang)
  • Pilot subset (--samples) and forced re-run (--rerun) for fast-fail exploration (@ShixiangWang)
  • Graph --expanded shows runtime DAG; simplify wgs-germline config (@ShixiangWang)
  • Report --ai adds plain-language result interpretation (@ShixiangWang)
  • Env create --ai supports pixi backend; ToolRegistry made shareable (@ShixiangWang)
  • Embed pipeline knowledge graph (78 skills, 470 transitions) + token-cost optimizations (@ShixiangWang)
  • Embed 562 bioSkills Agent Skills + lookup_skill AI tool (@ShixiangWang)
  • Embed full Bioconda CLI database (6103 tools) for AI tool lookup (@ShixiangWang)
  • Add help text to all CLI arguments and options (@ShixiangWang)
  • AI-powered environment spec generation (env create --ai) (@ShixiangWang)

Other Changes#

  • Merge PR #59: fix bundle confirmation gate + lint test code in CI (@ShixiangWang) (#59)

Refactoring#

  • Gallery docs embed via snippet includes; CLI embeds all 15 templates (@ShixiangWang)
  • Single-tier examples — top-level workflows folded into the gallery (11–15) (@ShixiangWang)
  • Remove 74 dead items across the workspace — audited symbol-by-symbol (@ShixiangWang)
  • Truncate fingerprint-mismatch list in the config-change summary (@ShixiangWang)
  • Finish issue #61 review cleanups (@ShixiangWang)
  • Change system resource log from INFO to DEBUG, display memory in GB (@ShixiangWang)

Testing#

  • Deep verification of embedded knowledge sources + fixes (@ShixiangWang)

0.10.2 — 2026-08-12#

Bug Fixes#

  • Use macro-based archive building for format-agnostic publish (@ShixiangWang)
  • Reserve signatures in manifest, harden bundle extraction path (@andrewbudge)
  • Resolve clippy lints (collapsible_if, needless_borrow, unused vars) (@ShixiangWang)
  • Correct Andrew Budge GitHub username in contributors section (@ShixiangWang)
  • Wgs_germline combine_gvcfs sample expansion (@ShixiangWang)
  • Modernize examples and sync gallery docs (@ShixiangWang)
  • Broken transform chunk paths and wgs_germline sample source (@ShixiangWang)

Documentation#

  • Add --format, --bundle, --yes to publish.md and run.md (@ShixiangWang)
  • Document pluggable report section system in report.md and workflow-format.md (@ShixiangWang)
  • Comprehensive audit and fix of all documentation (83 issues) (@ShixiangWang)
  • Modernize homepage examples and fix capability claims (@ShixiangWang)
  • Add contributors section to README with GitHub-style avatar display (@ShixiangWang)

Features#

  • Archive format abstraction (.tar.gz + .tar.zst), pull docs, confirmation gate (@ShixiangWang)
  • Add bundle execution confirmation gate with --yes flag (@ShixiangWang)
  • Add per-rule resource summary to bundle manifest (@ShixiangWang)
  • Pluggable report section system with domain auto-detection (@ShixiangWang)
  • Compose support, conda package specifiers, clinical compliance report (@ShixiangWang)

0.10.1 — 2026-08-11#

Bug Fixes#

  • Cluster partition rendering, forbid(unsafe) in AI crate, and env detection (@ShixiangWang)
  • AI analysis precision, debug expansion, and keep_going propagation (@ShixiangWang)
  • AI Companion prompt syntax, token tracking, and setup UX (@ShixiangWang)

Documentation#

  • Clarify web UI entry point in Quick Start and Deployment sections (@ShixiangWang)
  • Move Three-Mode Deployment after Web API section (@ShixiangWang)
  • Add transform-operator gallery page for 10th workflow (@ShixiangWang)
  • Simplify README, fix stale facts across all documentation (@ShixiangWang)
  • System check and optimize README.md (@ShixiangWang)
  • Comprehensive DAG execution documentation overhaul (@ShixiangWang)

Features#

  • PDF report support, secret scanning, Vega-Lite dashboard, and security docs (@ShixiangWang)

Performance#

  • Event-driven fine-grained scheduler replaces group barriers (@ShixiangWang)

0.10.0 — 2026-08-10#

Bug Fixes#

  • Async validate_command to prevent nested runtime crash (@ShixiangWang)

Documentation#

Features#

  • Oxo-flow ai test + ai setup + ai status subcommands (@ShixiangWang)
  • Verify DeepSeek both API formats + update docs (@ShixiangWang)
  • AiRuntime wired as single entry point for template command (@ShixiangWang)
  • L3 Agent + scope config + skill discovery wired into commands (@ShixiangWang)
  • AI session tracking + ai status command (@ShixiangWang)
  • AI auto-detection from workflow [ai] section (@ShixiangWang)
  • Professional AI prompts + debug --ai + lint --ai (@ShixiangWang)
  • Phase 5 — MCP bridge + Skill system (@ShixiangWang)
  • Phase 4 — scope-level AI config + AI plugin system (@ShixiangWang)
  • Phase 3 — AI error recovery on run failures (@ShixiangWang)
  • Phase 2 — AI-powered dry-run and validate analysis (@ShixiangWang)
  • Web crate migration + AI CLI documentation (@ShixiangWang)
  • Phase 1 — oxo-flow-ai crate + AI-powered template generation (@ShixiangWang)

Maintenance#

0.9.4 — 2026-08-09#

Features#

  • Typed config values + full ConfigDef runtime enforcement (@ShixiangWang)
  • Enforce ConfigDef choices validation + sensitive masking (@ShixiangWang)

0.9.3 — 2026-08-09#

Bug Fixes#

  • Support arguments.* references in when conditions (@ShixiangWang)
  • Propagate rule failures transitively, count skips once (@andrewbudge)
  • Propagate rule failures transitively, count skips once (@andrewbudge)
  • Sanitize remaining error leaks in execution and workflow handlers (@ShixiangWang)
  • Sanitize error messages, dynamic share URLs, deployment tests (@ShixiangWang)
  • Auth session persistence and FK constraint (@ShixiangWang)
  • API maturity, accessibility, and cross-page state persistence (@ShixiangWang)
  • Security hardening and web UI production readiness (@ShixiangWang)

Features#

  • PostgreSQL backend activation + OpenAPI 3.1 spec regeneration (@ShixiangWang)

Maintenance#

  • Fmt + clippy compliance for [arguments]→[config] merge (@ShixiangWang)
  • Repository cleanup — fmt, port consistency, stale files (@ShixiangWang)

Other Changes#

  • PR #56 — fix transitive failure propagation and skip counting (@ShixiangWang) (#56)
  • PR #56 — fix transitive failure propagation and skip counting (@ShixiangWang)

Refactoring#

  • Finish [arguments]→[config] merge — tests, CLI flags, format (@ShixiangWang)
  • Merge [arguments] into upgraded [config] block (@ShixiangWang)

Testing#

  • Comprehensive browser UI + real-world scenario tests (@ShixiangWang)
  • Multi-user lifecycle Playwright tests + PostgreSQL backend (@ShixiangWang)

0.9.2 — 2026-08-08#

Bug Fixes#

Documentation#

  • Comprehensive sample/pair discovery documentation (@ShixiangWang)

Features#

  • Optional pair control for tumor-only CNV and unmatched scenarios (@ShixiangWang)
  • Comprehensive sample/pair discovery with --sample flag (@ShixiangWang)
  • Comprehensive index auto-build with 9 types + samples_list (@ShixiangWang)
  • Integrate [[references]] with Reference Discovery API (@ShixiangWang)
  • Add [[references]] auto-index building to engine (@ShixiangWang)

0.9.1 — 2026-08-07#

Documentation#

  • Update all documentation for #50 (workflow args) and #51 (publish) (@ShixiangWang)

Features#

  • Add [arguments] block with --arg CLI flag for workflow parameters (@ShixiangWang)

0.9.0 — 2026-08-07#

Bug Fixes#

Features#

  • Add --with-lockfiles flag to publish for conda reproducibility (@ShixiangWang)
  • Record container refs in manifest, warn on missing env files (@ShixiangWang)
  • Add --bundle flag to run, add pull subcommand (@ShixiangWang)
  • Rewrite publish to emit verifiable .tar.zst archive (@ShixiangWang)
  • Enable true parallel execution with -j flag (@ShixiangWang)
  • Wire output validation, add MambaBackend, fix container CWD (@ShixiangWang)

Other Changes#

Refactoring#

Testing#

  • Add edge case tests for publish/run --bundle/pull (@ShixiangWang)

0.8.1 — 2026-06-22#

Bug Fixes#

  • Optimize Dockerfile and standardize project email to w_shixiang@163.com (@ShixiangWang)
  • Remove duplicate HTML document and correctly place Web API section (@ShixiangWang)

Documentation#

  • Add oxo-flow bioRxiv preprint to citation sections (@ShixiangWang)
  • Simplify CLI/API to concise intro + doc links (@ShixiangWang)
  • Comprehensive CLI (31cmds) + API (48eps) with search, collapse, categories (@ShixiangWang)
  • Tone down clinical-grade reporting → reproducible/reporting (@ShixiangWang)

Performance#

  • Avoid sysinfo System::new_all() when only one metric is needed (#46) (@andrewbudge) (#46)

0.8.0 — 2026-06-14#

Bug Fixes#

  • Resolve all audit findings — Makefile tabs, suite.py shadowing, version refs, Snakemake (@ShixiangWang)

Documentation#

  • Add CONTRIBUTING.md and SECURITY.md (@ShixiangWang)
  • Overhaul landing page — AI Companion, current API, React stack (@ShixiangWang)
  • Overhaul README — AI Companion, current API, clean duplicates (@ShixiangWang)
  • Deployment guide, AI provider env vars, UI polish (@ShixiangWang)
  • Add cloud storage reference doc, update LIMITATIONS.md and nav (@ShixiangWang)

Features#

  • AI config API, runtime provider switching, Docker deployment, UI polish (@ShixiangWang)
  • Docker deployment, custom AI URLs, frontend serving (@ShixiangWang)
  • AI provider abstraction with Claude/OpenAI/Ollama support (@ShixiangWang)
  • AI-native pipeline platform with structured results and web frontend (@ShixiangWang)
  • core: Implement real S3/GCS storage backends, expand webhook & plugin tests, add benchmarks (@ShixiangWang)

Maintenance#

Other Changes#

Performance#

  • bench: Restructure benchmarks into modular suite with 35 micro-benchmarks (@ShixiangWang)

0.7.0 — 2026-05-25#

Bug Fixes#

  • Resolve doc/code discrepancies found in consistency audit (@ShixiangWang)
  • Use serde serialization for format_workflow, fix example workflows (@ShixiangWang)
  • Resolve all remaining code audit issues across core, web, and plugin (@ShixiangWang)
  • --as-include skips E010, fix double GPU flag, escape report HTML, respect rule retries (@ShixiangWang)
  • Respect rule-level retries field in execution retry loop (@ShixiangWang)
  • Complete security patterns, validate export/package format args (@ShixiangWang)
  • Resolve 5 feature gaps from production readiness audit (@ShixiangWang)
  • Wildcard constraints filter instead of fail, optional rules warn on missing input (@ShixiangWang)
  • Improve target resolution UX and environment listing, fix CI issues (@ShixiangWang)
  • web: Resolve 6 bugs from production readiness audit (@ShixiangWang)
  • Resolve CLI unwrap risks and Core config expect improvements (@ShixiangWang)
  • web: Comprehensive test-driven fixes for 9 issues found (@ShixiangWang)
  • container: Add CMD to Dockerfile for better UX (@ShixiangWang)
  • container: Add cargo install + fallback to Singularity def oxo-flow installation (@ShixiangWang)
  • container: Use cargo install + GitHub release fallback for Dockerfiles (@ShixiangWang)
  • web: Prevent XSS via workflow name in onclick handlers (@ShixiangWang)

Documentation#

  • Complete rewrite of JSON Schema, fix all CLI and format doc gaps (@ShixiangWang)
  • Add missing rule fields, env_groups, genome_build to workflow format spec (@ShixiangWang)
  • web: Add multi-user web system design specification (@ShixiangWang)
  • web: Add security model and DELETE endpoint to web API docs (@ShixiangWang)

Features#

  • Light theme, license upload web UI, and CLI license command (@ShixiangWang)
  • web: Embed default academic license with commercial notice (@ShixiangWang)
  • web: Comprehensive multi-user web system with User Mgmt, HPC, Templates (@ShixiangWang)
  • web: Add HPC scheduler integration for Slurm/PBS monitoring (@ShixiangWang)
  • web: Add scheduled workflow runs with cron support (@ShixiangWang)
  • web: Add P2 Enterprise Governance and Template Library features (@ShixiangWang)
  • web: Modularize handlers and add maud templates (@ShixiangWang)
  • web: Add optional id field to SaveWorkflowRequest for upsert support (@ShixiangWang)
  • container: Add oxo-flow binary installation to Dockerfile and Singularity def (@ShixiangWang)
  • web: Add New Workflow button, auto-clear save name, UX polish (@ShixiangWang)
  • web: Add Dockerfile export button and modal to editor (@ShixiangWang)
  • web: Replace prompt() login with modal sign-in form (@ShixiangWang)
  • web: Add workflow deletion, SSE live updates, and editor templates (@ShixiangWang)
  • web: Add CLI arg parsing to web binary, update full API docs (@ShixiangWang)
  • web: Add GET /api/workflows/saved/{id} endpoint and Load-to-Editor (@ShixiangWang)
  • web: Professional dark-themed Command Center SPA frontend (@ShixiangWang)
  • web: Full workflow lifecycle API, workspace isolation, and 20-user simulation (@ShixiangWang)

Maintenance#

  • Fix all 16 unused-variable warnings in simulation_20users (@ShixiangWang)
  • Fix make ci - remove orphan comments, fix clippy warnings (@ShixiangWang)
  • web: Remove 15 orphan doc comments after handler dedup (@ShixiangWang)
  • Remove e2e-playwright test suite (@ShixiangWang)
  • Update e2e gitignore for logs and lock file (@ShixiangWang)
  • Update Cargo.lock for web crate clap dependency (@ShixiangWang)

Refactoring#

  • web: Remove 1101 dup lines, dead maud templates, partials (@ShixiangWang)
  • web: Remove 31 duplicate handlers, add DAG viz + template CRUD UI (@ShixiangWang)
  • web: Split frontend into index.html + app.js (@ShixiangWang)

Testing#

  • web: Add Playwright E2E tests for multi-user web system (@ShixiangWang)
  • web: Add 20 real-world user scenario tests from expert perspectives (@ShixiangWang)
  • container: Add tests for oxo-flow install in Dockerfile and Singularity def (@ShixiangWang)
  • web: Add E2E lifecycle tests for save/load/delete and full run cycle (@ShixiangWang)

0.6.1 — 2026-05-24#

Bug Fixes#

  • Replace silent checkpoint save failures with tracing warnings (@ShixiangWang)
  • Resource detection, checkpoint skip, error cascade, and validation improvements (@ShixiangWang)
  • Workspace tests use tempdir for CI reliability (@ShixiangWang)
  • Allow ':' in rule names and add include E2E tests (@ShixiangWang)
  • Parse conda env name from YAML content, not file stem (@ShixiangWang)

Documentation#

  • Fix README accuracy, serve base_path passthrough, and broken links (@ShixiangWang)
  • Add missing history command reference page (@ShixiangWang)
  • Update plugin-system.md to reflect full implementation (@ShixiangWang)
  • Fix plugin-system.md to reflect actual implementation status (@ShixiangWang)
  • Update command count to 31 (added history command) (@ShixiangWang)
  • Add CLI reference pages for all 29 commands (@ShixiangWang)

Features#

  • Subprocess-based dynamic plugin loading (@ShixiangWang)
  • Full plugin system with discovery, TOML integration, signatures (@ShixiangWang)
  • Retry persistence, plugin traits, i18n reports, input tests (@ShixiangWang)
  • Output verification with sizes, watch --run flag (@ShixiangWang)
  • History command, clean confirmation, plugin design doc (@ShixiangWang)
  • Dry-run execution hint, deadlock diagnosis improvement (@ShixiangWang)
  • Auto-create output dirs, watch dry-run, error test coverage (@ShixiangWang)
  • Progress ETA, dry-run input status, colored diff, error tests (@ShixiangWang)
  • Dry-run resource summary, output verification, deprecated cleanup (@ShixiangWang)
  • Input file existence check and --quiet banner suppression (@ShixiangWang)
  • Enhance dry-run output and update CITATION.cff (@ShixiangWang)
  • Transform operator tests and complete priority items (@ShixiangWang)
  • Resource exhaustion hints and enhanced test command (@ShixiangWang)
  • Env error hints, web crate tests, and improved init template (@ShixiangWang)
  • Improve oxo-flow init template with shell reference and China mirrors (@ShixiangWang)

Maintenance#

  • Fix stale version references and documentation consistency (@ShixiangWang)

Other Changes#

0.6.0 — 2026-05-21#

Bug Fixes#

  • Landing page rendering, badges, and stale content (@ShixiangWang)
  • Publish command crash and documentation accuracy (@ShixiangWang)

Documentation#

  • Add BLIT citation and optimize landing page badges (@ShixiangWang)
  • Refactor clinical reporting and synchronize CLI commands in README (@ShixiangWang)

Other Changes#

0.5.5 — 2026-05-20#

Bug Fixes#

  • Resolve bugs found by 30-user simulation testing (@ShixiangWang)
  • Resolve critical bugs, integrate security code, add tests, update deps, and fix README (@ShixiangWang)

Documentation#

  • Fix remaining stale subcommand count and add cargo install instruction (@ShixiangWang)

Features#

  • Auto-create output directories and add dry-run shell safety checks (@ShixiangWang)

Other Changes#

Styling#

  • Fix cargo fmt formatting in output directory creation (@ShixiangWang)

0.5.4 — 2026-05-19#

CI/CD#

  • Remove Venus from build/publish/release pipeline (@ShixiangWang)

Documentation#

Maintenance#

  • Completely remove Venus from oxo-flow repository (@ShixiangWang)
  • Remove Venus CLI integration tests, gitignore oxo-flow-venus (@ShixiangWang)
  • Remove Venus integration tests after extraction (@ShixiangWang)
  • Extract Venus into standalone repository oxo-flow-venus (@ShixiangWang)

Other Changes#

0.5.3 — 2026-05-18#

Bug Fixes#

  • Resolve clippy errors for Rust 1.95 and update test (@ShixiangWang)
  • Include schema file within CLI crate to fix cargo package build (#42) (@Copilot) (#42)

Documentation#

Features#

  • rule: Add Dir variant to FilePatterns for directory input (@ShixiangWang)
  • executor: Implement optional rule skip logic (@ShixiangWang)
  • rule: Add optional field for skip-on-missing behavior (@ShixiangWang)
  • format: Add validation for undefined env_group references (@ShixiangWang)
  • config: Add env_groups for shared environments (@ShixiangWang)
  • executor: Add auto-scaling helper functions (@ShixiangWang)
  • rule: Add AutoScale type for resource auto-scaling (@ShixiangWang)
  • config: Add reference_dir field with auto-derivation (@ShixiangWang)
  • cli: Implement --as-include validation mode (@ShixiangWang)
  • cli: Add --as-include flag to validate command (@ShixiangWang)
  • core: Enhance clinical workflow support and permissive wildcard expansion (@ShixiangWang)

Maintenance#

Testing#

0.5.2 — 2026-05-18#

Bug Fixes#

  • Suppress rustls-webpki audit warnings from aws-sdk-s3 transitive deps (@ShixiangWang)
  • Allow $(…) in shell templates; validate wildcard injection; fix dry-run when; fix example workflows (#40) (@Copilot) (#40)

Documentation#

  • Audit and clean up documentation, resolve implementation inconsistencies (@ShixiangWang)
  • Clean up and fix issues in all .md files (#41) (@Copilot) (#41)

Features#

  • 100% resolution of 40-user comprehensive testing — security, storage, CLI, docs (@ShixiangWang)
  • Achieve 100% resolution of 100-user comprehensive review (@ShixiangWang)
  • Resolve top 10 priority actions from 100-user comprehensive review (@ShixiangWang)
  • Switch to rustls, optimize hot paths, update docs and deps (@ShixiangWang)
  • Comprehensive 30-expert review, dependency upgrades, performance optimizations, and documentation updates (@ShixiangWang)
  • Implement Phase 9.6 roadmap items and performance optimizations (@ShixiangWang)
  • 30-expert user journey review, performance optimizations, and documentation improvements (@ShixiangWang)
  • Implement named inputs and outputs for rules (@ShixiangWang)
  • Address simulated user reviews and comprehensive optimization (@ShixiangWang)

Maintenance#

Other Changes#

Performance#

  • Optimize wildcard expansion engine and consolidate Phase 9.6 (@ShixiangWang)

0.5.1 — 2026-05-17#

Bug Fixes#

  • cli: Add 'default' alias for profile show and 'check' alias for config stats (@ShixiangWang)
  • docs: Add pairs_file/pairs_pattern/sample_groups_file to how-to guides (@ShixiangWang)
  • docs: Use absolute GitHub URLs for example workflow links (@ShixiangWang)

Documentation#

  • Add metadata field to pairs table documentation (@ShixiangWang)

Features#

  • batch: Implement true parallel execution with Semaphore (@ShixiangWang)
  • config: Add pairs_pattern for auto-discovering pairs from filesystem (@ShixiangWang)
  • config: Add pairs_file and sample_groups_file support (@ShixiangWang)
  • ci: Auto-update docs version references on version bump (@ShixiangWang)

0.5.0 — 2026-05-16#

Bug Fixes#

  • Correct cargo-audit config format (@ShixiangWang)
  • Address all issues from 30-expert review (@ShixiangWang)
  • venus: Add interpreter_map to generated workflow metadata (@ShixiangWang)
  • security: Relax shell validation for &&, ||, and pipes (@ShixiangWang)
  • executor: Remove duplicate resource release on failure (@ShixiangWang)
  • Simplify build_script_command to avoid clippy warning (@ShixiangWang)

CI/CD#

Documentation#

Features#

  • cli: Add batch subcommand for parallel task execution (@ShixiangWang)
  • Complete rule lifecycle hooks, environment injection, and custom interpreters (@ShixiangWang)
  • config: Fix namespace prefixing for depends_on in included rules (@ShixiangWang)
  • cli: Add progress bar for run command execution tracking (@ShixiangWang)
  • cli: Add --pending-timeout option to cluster submit (@ShixiangWang)
  • cli: Add --orphans option to clean command (@ShixiangWang)
  • lint: Add hook command safety validation (W020-W022) (@ShixiangWang)
  • executor: Implement script execution with interpreter detection and sequential shell+script (@ShixiangWang)
  • Add interpreter and interpreter_map fields for script execution (@ShixiangWang)
  • Add disk space pre-flight check and resource summary (@ShixiangWang)
  • scheduler: Implement ResourceHint memory estimation (@ShixiangWang)
  • executor: Add structured logging for resource allocation (@ShixiangWang)
  • cluster: Enhance GPU spec translation for SLURM/PBS/SGE (@ShixiangWang)
  • scheduler: Add system capacity validation with warnings (@ShixiangWang)
  • executor: Add process group timeout and cleanup on failure (@ShixiangWang)
  • executor: Use sysinfo for cross-platform memory detection (@ShixiangWang)
  • Add sysinfo, nix, fs2 dependencies for resource management (@ShixiangWang)
  • core: Implement unified transform operator for scatter-gather (@ShixiangWang)

Maintenance#

Other Changes#

Refactoring#

  • Add #[must_use] attributes to interpreter functions (@ShixiangWang)

Testing#

  • batch: Add comprehensive unit tests and update docs nav (@ShixiangWang)
  • executor: Add tests for interpreter detection and script execution (@ShixiangWang)

0.4.2 — 2026-05-16#

Bug Fixes#

  • validation: Exempt pairs/sample_groups wildcards from E003 (@ShixiangWang)
  • web: Replace panic with graceful error handling in executor (@ShixiangWang)
  • cli: Apply defaults and templates in dry-run and debug commands (@ShixiangWang)
  • cli: Properly return exit codes on cluster command failures and handle empty checkpoints (@ShixiangWang)

Documentation#

  • Fix installation package name and add security limitations (@ShixiangWang)
  • Add config get/set commands and explain dependencies metric (@ShixiangWang)
  • Update outdated CLI documentation (@ShixiangWang)

Features#

Other Changes#

0.4.1 — 2026-05-16#

Bug Fixes#

  • executor: Implement retry loop and hooks execution (@ShixiangWang)

0.4.0 — 2026-05-16#

Bug Fixes#

  • Expand placeholders in cluster submit scripts (@ShixiangWang)
  • Address critical bugs from user simulation testing (@ShixiangWang)
  • Remove unused helper functions and fix unused_mut warning (@ShixiangWang)
  • Add async mutex guard for thread-safe database initialization (@ShixiangWang)
  • Use process-specific temp database for tests (@ShixiangWang)
  • Resolve test database initialization race condition (@ShixiangWang)
  • Walltime tests and add 'd' suffix support (@ShixiangWang)
  • Add partition field to Resources Default and update tests (@ShixiangWang)
  • web: Resolve modal CSS priority issue and complete UI functions (@ShixiangWang)

Documentation#

Features#

  • Implement persistent checkpointing, fix modular includes, and reduce TOML noise (@ShixiangWang)
  • Add 81 new comprehensive tests for oxo-flow (145 total, covering CLI, core, Venus, bioinformatics) (#39) (@Copilot) (#39)
  • clinical: SHA-256 checksums and provenance persistence (@ShixiangWang)
  • validation: Integrate validate_format() and secret scanning (@ShixiangWang)
  • container: Add GPU support for container generation (@ShixiangWang)
  • cluster: Add GPU directives, per-rule walltime, modules, logs (@ShixiangWang)
  • bioinformatics: Address bioinformatics expert review (@ShixiangWang)
  • web: Implement critical Web API enhancements (@ShixiangWang)
  • Implement advanced user features (@ShixiangWang)
  • Address all issues from junior user review and generalize terminology (@ShixiangWang)
  • Implement WC-01 tumor-normal pairing, WC-02 sample groups, WF-01 conditional rules (#38) (@Copilot) (#38)
  • Make workflow argument optional for run and dry-run commands (@ShixiangWang)
  • Target-based partial workflow execution for run and dry-run (#37) (@Copilot) (#37)
  • Implement 20-persona dev plan Phase 1 and enhance CLI security/usability (@ShixiangWang)
  • Add ANSI colors and fix box alignment in ASCII graph output (@ShixiangWang)
  • cli: Add ASCII terminal graph output for oxo-flow graph (@ShixiangWang)
  • web: Complete industrial-grade Web UI system (Phase 10) (@ShixiangWang)

Maintenance#

Other Changes#

0.3.1 — 2026-05-13#

Bug Fixes#

  • Address all 32 review issues across security, code quality, pipeline correctness, and docs (#34) (@Copilot) (#34)

Documentation#

  • Sync docs changelog with root CHANGELOG.md via snippets include (#35) (@Copilot) (#35)

Features#

  • web: Add request and active workflow metrics with frontend auto-refresh (@ShixiangWang)

Other Changes#

Refactoring#

0.3.0 — 2026-04-07#

Bug Fixes#

  • Template variable substitution, DOT graph labels, and optional env check workflow (@Copilot)

Features#

  • Enhance error types, re-export public API, docs update (@Copilot)
  • wildcard: Add regex constraint validation and pattern-to-regex file discovery (@Copilot)
  • Add reference database tracking, data lineage, and extended job states (@Copilot)
  • core: Add GpuSpec, ResourceHint, and new Rule fields with builder methods (@Copilot)

Other Changes#

Refactoring#

  • Address code review comments - use imported HashMap and all_known_backends() (@Copilot)

0.2.0 — 2026-04-06#

Bug Fixes#

  • Path traversal protection in touch, overflow protection in duration parsing (@Copilot)

CI/CD#

  • Add Windows ARM64, i686 Windows, and ARMv7 Linux release targets (@Copilot)

Features#

  • Add Rule depends_on/retry_delay/workdir/hooks, DAG critical_path, format diff/lint codes (@Copilot)

Other Changes#

  • Add comprehensive tests for new features (@Copilot)
  • Fix summary statistics to match actual opinion counts (89 total) (@Copilot)
  • Add comprehensive expert panel evaluation TODO.md (@Copilot)
  • Initial plan (@Copilot)

0.1.3 — 2026-04-06#

Bug Fixes#

  • Rename venus crate to oxo-flow-venus to avoid crates.io name conflict (@Copilot)

Other Changes#

0.1.2 — 2026-04-06#

Bug Fixes#

  • Add version to workspace path deps for crates.io publishing (@Copilot)

Other Changes#

0.1.1 — 2026-04-06#

CI/CD#

  • Replace deprecated macos-13 with macos-latest cross-compiling to x86_64 (@Copilot)
  • Fix release and crates.io publish being blocked by cancelled builds (@Copilot)

Documentation#

  • Fix number formatting (1 000 → 1,000) (@Copilot)
  • Update landing page to accurately reflect repository state (@Copilot)

Other Changes#

0.1.0 — 2026-04-06#

Bug Fixes#

  • Address code review feedback - XSS, event handling, credential docs (@Copilot)
  • Address code review feedback - improve test comments, fix bismark path, add escape docs (@Copilot)

Build#

  • Use workspace version inheritance for all crates, update CI sync-version (@Copilot)

CI/CD#

  • Skip heavy build jobs on pull_request events to prevent slow/cancelled runs (@Copilot)
  • Optimize CI workflow for reliable builds and crates.io publishing (@Copilot)

Documentation#

  • Add missing documentation files referenced in TODO.md (@Copilot)
  • Replace TODO.md with comprehensive 30-expert evaluation report (@Copilot)
  • Update TODO.md to mark completed items (@Copilot)
  • Add complete documentation website with MkDocs Material, landing page, tutorials, command reference, and architecture docs (@Copilot)
  • Fix grammar in quickstart tutorial (@Copilot)
  • Create complete documentation website (@Copilot)
  • Add CHANGELOG, CITATION, CODE_OF_CONDUCT, CONTRIBUTING, cliff.toml, and CI/CD pipeline (@Copilot)

Features#

  • web: Add in-memory rate limiter and graceful shutdown (@Copilot)
  • container: Add multi-stage builds, rootless support, healthcheck, and docker run command (@Copilot)
  • core: Add type system features - WorkflowState, RuleBuilder, newtypes, clinical types (@Copilot)
  • Integrate oxo-license, add auth/login system, export/cluster CLI subcommands (@Copilot)
  • core: Add comprehensive enhancements to oxo-flow-core (@Copilot)
  • Enhance scientific messaging, add gallery to README/docs, add CLI integration tests (@Copilot)
  • Add workflow gallery with 8 examples from basic to multi-omics, docs, and tests (@Copilot)
  • Remove all Snakemake references, establish innovation-first messaging (@Copilot)
  • Add validation, provenance, diagnostics, and DAG metrics improvements (@Copilot)
  • web: Add embedded frontend, new API endpoints, SSE, and base path support (@Copilot)
  • cli: Add Format, Lint, Profile, and Config subcommands (@Copilot)
  • core: Add resolve_includes, execution group validation, conditional execution, schema verification, and enhanced formatting (@Copilot)
  • Add scatter/gather, when, temp/protected output, input_function, retries, include, execution groups (@Copilot)
  • Add format module for .oxoflow validation, linting, and formatting (@Copilot)
  • Add request ID middleware, export endpoint, and CLI retry/timeout flags (@Copilot)
  • Add priority scheduling, clinical report sections, and CNV/MSI/TMB pipeline steps (@Copilot)
  • executor: Implement retry logic, timeout enforcement, and output validation (@Copilot)
  • core: Add error variants, apply_defaults, parallel_groups, rule validate (@Copilot)
  • cli: Enhance clean, init, add completions and verbose flag (@Copilot)
  • container: Add pixi support, extra_packages, compose file, and improved singularity defs (@Copilot)
  • web: Add CORS, run, version, and clean endpoints (@Copilot)
  • venus: Add VenusPipelineBuilder and .oxoflow generation (@Copilot)
  • web: Add full REST API with validate, parse, DAG, dry-run, and report endpoints (@Copilot)
  • report: Add Tera template engine and clinical report components (@Copilot)
  • Add cluster execution backends and executor checkpointing (@Copilot)
  • environment: Add setup/teardown commands, cache keys, and EnvironmentCache (@Copilot)
  • Initialize oxo-flow project with core library, CLI, web, and venus pipeline (@Copilot)

Maintenance#

  • Update Rust edition from 2021 to 2024 and fix clippy/fmt issues (@Copilot)

Other Changes#

  • Add 303 implementation notes to TODO.md; update README, CONTRIBUTING docs (@Copilot)
  • Phase 7: Add 32 new tests (clinical types, builder, security, stress, format, container) (@Copilot)
  • Add validation and security features to oxo-flow-core (@Copilot)
  • Add core safety attributes: forbid(unsafe_code), CLI flags, #[must_use] (@Copilot)
  • Initial plan (@Copilot)
  • Add comprehensive TODO.md with 300+ expert opinions from 30 simulated domain experts (@Copilot)
  • Add comprehensive TODO.md with 300 expert review items across 30 domain perspectives (@Copilot)
  • Add TODO.md with 30 expert opinions (150 action items) (@Copilot)
  • Delete TODO.md (@ShixiangWang)
  • Add ..Default::default() to all Rule constructors for new fields (@Copilot)
  • Initial plan (@Copilot)
  • Replace README.md with comprehensive documentation (@Copilot)
  • Add binary targets for oxo-flow-web and venus, create dual license files (@Copilot)
  • Add TODO.md with 30-expert evaluation and action items (@Copilot)
  • Update (@ShixiangWang)
  • Add paired_tumor_normal example, integration tests, and root package for workspace-level tests (@Copilot)
  • 30-expert evaluation: comprehensive upgrades - error variants, config defaults, DAG parallel groups, rule validation, executor retry/timeout, priority scheduling, clinical reports, Venus CNV/MSI/TMB, web export/request-ID, CLI retry/timeout flags, examples, integration tests - 231 tests passing (@Copilot)
  • Comprehensive multi-expert evaluation upgrades: executor env integration, Venus FilterMutectCalls/Strelka2, web API CORS/run/clean/version endpoints, container multi-stage builds, CLI clean/completions/init enhancements, Venus pipeline files, 200 tests passing (@Copilot)
  • Add comprehensive tests for web, venus, and environment modules (@Copilot)
  • Add FilterMutectCalls, Strelka2, known_sites to Venus pipeline (@Copilot)
  • Add environment integration to executor and retry/timeout config fields (@Copilot)
  • Phase 7-8: Venus pipeline builder, CLI status/clean commands, enhanced example workflow, ROADMAP update (@Copilot)
  • Initial commit (@ShixiangWang)

Testing#

  • Add 30 CLI binary integration tests for oxo-flow, venus, and oxo-flow-web (@Copilot)