diff --git a/ROADMAP.md b/ROADMAP.md index ec2c8ac..e2eee6d 100644 --- a/ROADMAP.md +++ b/ROADMAP.md @@ -4,9 +4,9 @@ WebSSH is a self-hosted SSH and file workspace. This roadmap explains the direct the current release focus, and the evidence behind completed work. It is not a release-date promise or a replacement for issues, pull requests, and release notes. -Planning baseline: **2026-10-03**, commit -[`dc3d9bf`](https://github.com/bifrost0x/webssh/commit/dc3d9bf26f57cbeb440227afe13f9635c4d9f258). -Check the linked GitHub items for newer status. +Release status updated: **2026-10-05**, v2.5.0 at +[`07f4726`](https://github.com/bifrost0x/webssh/commit/07f472691e61eab6554dd6f75cf56fb8333964ba). +Check linked GitHub items for newer status. ## Product direction @@ -18,33 +18,26 @@ Check the linked GitHub items for newer status. These themes summarize the existing product and published release history; they do not add new feature commitments. -## Now: consolidate the post-2.4 changes +## Now: v2.5.0 published, deployment acceptance remains explicit -**Proposed next release: v2.5.0.** No release date is committed. Scope and version remain -subject to maintainer review. The latest published release at this baseline is -[v2.4.0](https://github.com/bifrost0x/webssh/releases/tag/v2.4.0). +[v2.5.0](https://github.com/bifrost0x/webssh/releases/tag/v2.5.0) delivers optional Warpgate support, workspace continuity, +host/command/mobile usability, tmux directory synchronization, paste/transcript fixes, +faster theme backgrounds and reviewed dependency updates. The +[release comparison](https://github.com/bifrost0x/webssh/compare/v2.4.0...v2.5.0) contains 17 merged PRs. -| Outcome | Implementation state at the baseline | Remaining delivery work | -|---|---|---| -| Optional Warpgate gateway authentication | [#238](https://github.com/bifrost0x/webssh/pull/238) merged; request [#237](https://github.com/bifrost0x/webssh/issues/237) closed | Final-candidate real-protocol acceptance; earlier evidence is revision-specific | -| Workspace continuity and tmux directory synchronization | [#231](https://github.com/bifrost0x/webssh/pull/231), [#233](https://github.com/bifrost0x/webssh/pull/233), [#234](https://github.com/bifrost0x/webssh/pull/234), [#235](https://github.com/bifrost0x/webssh/pull/235), [#236](https://github.com/bifrost0x/webssh/pull/236) merged | Focused multi-session and mobile canary | -| Correct paste input and saved transcripts | [#239](https://github.com/bifrost0x/webssh/pull/239), [#241](https://github.com/bifrost0x/webssh/pull/241) merged | Verify paste/control input and transcript behavior on the candidate | -| Clearer connection review and file actions | [#242](https://github.com/bifrost0x/webssh/pull/242) merged | Connection/key review and file-workspace smoke tests | -| Reviewed dependency and repository maintenance | [#232](https://github.com/bifrost0x/webssh/pull/232), [#243](https://github.com/bifrost0x/webssh/pull/243), [#246](https://github.com/bifrost0x/webssh/pull/246), [#247](https://github.com/bifrost0x/webssh/pull/247) merged | Fresh exact-candidate CI and both native image scans | +[Tag CI and native image publication](https://github.com/bifrost0x/webssh/actions/runs/37276528581) passed on `07f472691e61eab6554dd6f75cf56fb8333964ba`. +Both runtime architectures retain SBOM and provenance attestations. The release record is +[#248](https://github.com/bifrost0x/webssh/issues/248), and the +[v2.5.0 milestone](https://github.com/bifrost0x/webssh/milestone/11) is closed. -All of these changes are **merged but not included in the v2.4.0 tag**. -The [fixed-baseline comparison](https://github.com/bifrost0x/webssh/compare/v2.4.0...dc3d9bf26f57cbeb440227afe13f9635c4d9f258) -contains 13 merged PRs. Baseline [CI and native image publication](https://github.com/bifrost0x/webssh/actions/runs/37064319620) -passed; this does not complete every deployment-specific acceptance check. - -The open [release-readiness issue #248](https://github.com/bifrost0x/webssh/issues/248) -is the delivery gate. It remains open until candidate validation, release publication, -and versioned-image verification have evidence. A milestone is not shipped merely because -its implementation PRs are merged. +Publication was authorized with the reported real Warpgate, deployment canary, +upgrade/restore/rollback and applicable environment-specific acceptance still unverified. +These checks remain open in [#254](https://github.com/bifrost0x/webssh/issues/254); they are not counted as passed. +Warpgate remains disabled by default. No new feature release or date is committed. ## Next: choose from verified feedback -After this release, select a small scope from reproducible bugs, user feedback and validated +Select a small scope from reproducible bugs, user feedback and validated security/dependency findings. State the benefit, priority reason and acceptance criteria in an issue before assigning substantial work to the next milestone. @@ -73,17 +66,19 @@ deployment supported. Do not promote an idea into a promised release by listing | [v2.2.0](https://github.com/bifrost0x/webssh/releases/tag/v2.2.0) - [v2.2.1](https://github.com/bifrost0x/webssh/releases/tag/v2.2.1) | Terminal-first mobile, GitHub authentication and focused touch-scrolling correction | | [v2.3.0](https://github.com/bifrost0x/webssh/releases/tag/v2.3.0) | Mobile/input, account-linking, notes/transfers and validated security remediation | | [v2.4.0](https://github.com/bifrost0x/webssh/releases/tag/v2.4.0) | Responsive high-output multi-session recovery, directory sync and verified image promotion | +| [v2.5.0](https://github.com/bifrost0x/webssh/releases/tag/v2.5.0) | Optional Warpgate, workspace continuity, host/command/mobile usability, terminal correctness and faster backgrounds | ## How this is maintained - [Project history](docs/project-history.md): what shipped, documented reasons and lessons. - [Planning and release workflow](docs/project-planning.md): how issues, PRs and milestones fit together. -- [Milestones](https://github.com/bifrost0x/webssh/milestones): native release grouping, with ten historical milestones closed and v2.5.0 open. +- [Milestones](https://github.com/bifrost0x/webssh/milestones): native release grouping, with eleven published-release milestones closed. - [Retrospective mapping](docs/release-history.json): release/PR/issue membership, milestone numbers and backfill verification. The native milestone backfill was applied on 2026-10-04: 185 items assigned and verified. PR #98 was unavailable (HTTP 404) and is recorded as an exception in the -manifest. The release-readiness issue #248 remains open in v2.5.0. +manifest. The 2026-10-05 release update adds PRs #249-#252 to v2.5.0, closes +release-readiness issue #248 and retains the operational acceptance follow-up in #254. The historical mapping was reconstructed on 2026-10-03. It does not imply that these milestones or this roadmap existed at the time. Actual GitHub milestone creation and diff --git a/docs/project-history.md b/docs/project-history.md index 3963458..8909304 100644 --- a/docs/project-history.md +++ b/docs/project-history.md @@ -44,29 +44,32 @@ These belong to the first official release baseline, not invented pre-1.0 releas | [v2.2.1](https://github.com/bifrost0x/webssh/releases/tag/v2.2.1) / 2026-08-30 | Focused normal-history scrolling correction and direct mobile session tools | [#165](https://github.com/bifrost0x/webssh/pull/165): synthetic wheel events passed a unit check but did not trigger actual browser scrollback | 1 | | [v2.3.0](https://github.com/bifrost0x/webssh/releases/tag/v2.3.0) / 2026-09-11 | Session-duration controls, verified OIDC linking, mobile/copy/notes/transfer fixes and security remediation | [#202](https://github.com/bifrost0x/webssh/pull/202): validated repository security findings; [#208](https://github.com/bifrost0x/webssh/issues/208)/[#209](https://github.com/bifrost0x/webssh/pull/209): linking friction without weakening stable issuer/subject binding; [#210](https://github.com/bifrost0x/webssh/issues/210)/[#211](https://github.com/bifrost0x/webssh/pull/211): mobile input regression remained | 27 | | [v2.4.0](https://github.com/bifrost0x/webssh/releases/tag/v2.4.0) / 2026-09-21 | High-output multi-session rendering/recovery, terminal/files sync, hardened remote work and native-image release gates | [#221](https://github.com/bifrost0x/webssh/pull/221): hidden-pane rendering delayed ACKs and caused reconnect loops; [#223](https://github.com/bifrost0x/webssh/pull/223)-[#226](https://github.com/bifrost0x/webssh/pull/226): verify immutable image candidates without breaking deployment compatibility | 16 | +| [v2.5.0](https://github.com/bifrost0x/webssh/releases/tag/v2.5.0) / 2026-10-05 | Optional gateways and everyday workspace continuity | [#238](https://github.com/bifrost0x/webssh/pull/238): optional Warpgate; #231/#233/#242: workspace and connection usability; #234-#236/#239/#241: terminal correctness; #251: background loading; #252: dependency updates | 17 | -The 148 PRs in these release stages are assigned by their **first tagged inclusion**, +The 165 PRs in these release stages are assigned by their **first tagged inclusion**, not by the week in which they merged. The machine-readable [release history](release-history.json) lists every PR number, tag SHA, release URL, comparison and verified issue-to-implementation link. Direct commits are covered by the Git comparisons even though they have no PR to attach to a native milestone. -## After v2.4.0: implemented, not yet version-released +## v2.5.0 delivery and remaining acceptance -At baseline [`dc3d9bf`](https://github.com/bifrost0x/webssh/commit/dc3d9bf26f57cbeb440227afe13f9635c4d9f258), -13 additional PRs are merged. They cover workspace/tmux follow-ups, optional Warpgate, -paste/transcript correctness, connection/file usability and dependency maintenance. -See the [roadmap](../ROADMAP.md) and [release-readiness issue #248](https://github.com/bifrost0x/webssh/issues/248). +The original 2026-10-03 planning baseline contained 13 merged PRs after v2.4.0. +The published v2.5.0 tag adds #249, #250, #251 and #252, for 17 merged PRs in this release. +PR #253 was superseded by #252 and is not counted as a separately merged PR. -Two important distinctions: +[Tag CI](https://github.com/bifrost0x/webssh/actions/runs/37276528581) and native image publication passed on `07f472691e61eab6554dd6f75cf56fb8333964ba`. +The maintainer authorized publication after the remaining deployment acceptance was +explicitly reported. Real Warpgate, deployment canary, upgrade/recovery and applicable +environment-specific checks remain tracked in [#254](https://github.com/bifrost0x/webssh/issues/254). +Release closure does not mark those checks passed. -- [#237](https://github.com/bifrost0x/webssh/issues/237) is closed and - [#238](https://github.com/bifrost0x/webssh/pull/238) is merged, but Warpgate is not part of - the v2.4.0 tag. The proposed next milestone must remain open for release validation. -- [#245](https://github.com/bifrost0x/webssh/issues/245) was resolved by the reporter's - Warpgate PROXY-protocol configuration. It is support evidence, not a shipped WebSSH fix. - Likewise, [#62](https://github.com/bifrost0x/webssh/issues/62) was converted to a database - proposal discussion. Neither is counted as implementation delivered by a release. +[#237](https://github.com/bifrost0x/webssh/issues/237) and +[#238](https://github.com/bifrost0x/webssh/pull/238) first ship in v2.5.0, not v2.4.0. +[#245](https://github.com/bifrost0x/webssh/issues/245) was resolved by the reporter's +Warpgate PROXY-protocol configuration; it remains support evidence, not a shipped fix. +[#62](https://github.com/bifrost0x/webssh/issues/62) was converted to a database proposal +discussion and is likewise not counted as delivered implementation. ## Lessons for future planning @@ -89,5 +92,5 @@ These are retrospective recommendations, not invented historical decisions: No original release deadlines or complete private planning history were available. The table summarizes documented purposes rather than claiming a pre-existing strategy. Issue timelines show use of GitHub Projects, but this retrospective does not verify or -change the board's complete structure/status. Native milestone backfill is prepared in -the manifest and must be checked against the live GitHub milestone list before applying. +change the board's complete structure/status. The manifest preserves the dated native milestone backfill and subsequent release +updates. Check live GitHub metadata before making further assignments. diff --git a/docs/project-planning.md b/docs/project-planning.md index a578a3e..8626749 100644 --- a/docs/project-planning.md +++ b/docs/project-planning.md @@ -51,11 +51,12 @@ interpret their combined count as distinct features delivered. interactive authentication and a default-off administration gate. The request is closed and the PR merged, but neither belongs to v2.4.0 because the tag predates their merge. -The proposed v2.5.0 scope groups that implementation with the related workspace fixes. -[#248](https://github.com/bifrost0x/webssh/issues/248) remains open for exact-candidate -protocol checks, canary, upgrade/recovery, publication and image verification. This makes -the distinction between **implemented** and **shipped** visible without reopening the -resolved feature request or making a PR that repeats code already in `main`. +The published [v2.5.0 release](https://github.com/bifrost0x/webssh/releases/tag/v2.5.0) includes that implementation and the +related workspace fixes. [#248](https://github.com/bifrost0x/webssh/issues/248) records +the exact candidate, publication and image verification. The maintainer authorized +publication with the reported deployment acceptance still unverified; those checks +remain open in [#254](https://github.com/bifrost0x/webssh/issues/254). Publication and operational acceptance are +recorded separately, without repeating implementation PRs or marking unrun checks passed. ## Record decisions and blockers @@ -95,15 +96,21 @@ CI/security gates cannot be silently waived. No automation or automatic merge is The initial [release-history manifest](release-history.json) is a dated, reviewable snapshot of ten published releases and the proposed next scope. It includes prepared native milestone descriptions, 161 merged PR mappings and 24 verified issue links. -The candidate entry has no tag or publication date because it is not a release. +The original backfill result is retained in the manifest. Later releases extend the +history; `candidate` is null when no next version has been selected. Applied on **2026-10-04**: ten historical milestones are closed and the proposed -[v2.5.0 milestone](https://github.com/bifrost0x/webssh/milestone/11) is open. +[v2.5.0 milestone](https://github.com/bifrost0x/webssh/milestone/11) was open at that time. The backfill assigned and verified 160 PRs, 24 implementation-linked issues and the open release gate #248 (185 items). PR #98 returned HTTP 404 through the API and signed-in browser and could not be assigned. The original 161-PR reconstruction is preserved; the manifest records the exception and native milestone numbers. +Published on **2026-10-05**: v2.5.0 adds PRs #249-#252 to the original scope. +The release milestone and #248 are closed after tag/image verification. The current +manifest contains eleven releases and 165 merged PR mappings; deferred deployment +acceptance remains open in #254. The original backfill counts above are not rewritten. + For historical backfill: 1. Read all existing native milestones before creating anything; reuse matching versions diff --git a/docs/release-history.json b/docs/release-history.json index 5bb3872..4bdfd50 100644 --- a/docs/release-history.json +++ b/docs/release-history.json @@ -5,7 +5,7 @@ "baseline_commit": "dc3d9bf26f57cbeb440227afe13f9635c4d9f258", "native_milestone_backfill": "applied_with_exceptions", "method": "First tagged release containing each merged PR's merge_commit_sha, with every compare page retrieved. The first release includes all prior verified PR merges. Issues require an explicit implementation link.", - "expected_merged_pr_count": 161, + "expected_merged_pr_count": 165, "expected_implementation_linked_issue_count": 24, "historical": [ { @@ -419,49 +419,59 @@ 230 ], "issues": [] + }, + { + "title": "v2.5.0", + "state": "closed", + "goal": "Consolidate gateway support and workspace/terminal fixes into a verified release", + "previous_release": "v2.4.0", + "compare_url": "https://github.com/bifrost0x/webssh/compare/v2.4.0...v2.5.0", + "description": "Published v2.5.0 on 2026-10-05. Workspace continuity, optional Warpgate, host/command/mobile usability, tmux/paste/transcript fixes, faster backgrounds and dependency updates.\n\nRelease: https://github.com/bifrost0x/webssh/releases/tag/v2.5.0\nTag commit: 07f472691e61eab6554dd6f75cf56fb8333964ba\nTag CI: https://github.com/bifrost0x/webssh/actions/runs/37276528581\n\n17 merged PRs, assigned by first tagged inclusion. Superseded #253 is included through #252 and is not counted as a merged PR.\n\nThe maintainer authorized publication with explicitly reported deployment acceptance still unverified; follow-up: https://github.com/bifrost0x/webssh/issues/254. Required CI/security gates passed. Deferred checks are not marked passed.", + "pull_requests": [ + 231, + 232, + 233, + 234, + 235, + 236, + 238, + 239, + 241, + 242, + 243, + 246, + 247, + 249, + 250, + 251, + 252 + ], + "issues": [ + { + "number": 240, + "implemented_by": 241, + "evidence": "explicit closing reference in pull request body" + }, + { + "number": 237, + "implemented_by": 238, + "evidence": "maintainer implementation comment in issue #237 and PR #238" + }, + { + "number": 248, + "evidence": "release publication and image verification record; deferred operational acceptance tracked in #254" + } + ], + "published_at": "2026-10-05T07:23:00Z", + "tag_commit": "07f472691e61eab6554dd6f75cf56fb8333964ba", + "release_url": "https://github.com/bifrost0x/webssh/releases/tag/v2.5.0", + "rationale_summary": "Improve everyday workspace and connection workflows, add optional Warpgate support, and deliver terminal correctness and dependency updates.", + "milestone_number": 11, + "validation_followup": 254, + "image_digest": "sha256:5cd320c7e48ab805dcb5a78950ed1ac41015e7f9ac0c97dd880e84308021312a", + "tag_workflow_url": "https://github.com/bifrost0x/webssh/actions/runs/37276528581" } ], - "candidate": { - "title": "v2.5.0", - "state": "open", - "status": "proposed_not_released", - "goal": "Consolidate gateway support and workspace/terminal fixes into a verified release", - "baseline_commit": "dc3d9bf26f57cbeb440227afe13f9635c4d9f258", - "previous_release": "v2.4.0", - "compare_url": "https://github.com/bifrost0x/webssh/compare/v2.4.0...dc3d9bf26f57cbeb440227afe13f9635c4d9f258", - "description": "Proposed next release, no date commitment. Code after v2.4.0 is merged but not yet released under this version.\n\nGoal: consolidate optional Warpgate support, workspace/tmux continuity, paste/transcript correctness and reviewed dependency updates into a verified versioned release.\n\nRelease gate: [#248](https://github.com/bifrost0x/webssh/issues/248). Keep this issue open until exact-candidate validation, publication and versioned image/attestation verification are recorded.\n\nBaseline: dc3d9bf26f57cbeb440227afe13f9635c4d9f258 (2026-10-03), 13 merged PRs since v2.4.0. Native CI passed: https://github.com/bifrost0x/webssh/actions/runs/37064319620 . Scope/version remains adjustable by the maintainer.\n\nNo new features, release date or automatic merge commitment.", - "pull_requests": [ - 231, - 232, - 233, - 234, - 235, - 236, - 238, - 239, - 241, - 242, - 243, - 246, - 247 - ], - "issues": [ - { - "number": 240, - "implemented_by": 241, - "evidence": "explicit closing reference in pull request body" - }, - { - "number": 237, - "implemented_by": 238, - "evidence": "maintainer implementation comment in issue #237 and PR #238" - }, - { - "number": 248, - "evidence": "open release acceptance checklist" - } - ] - }, "excluded_issues": [ { "number": 62, @@ -565,5 +575,25 @@ } ], "verification": "All 185 accessible planned items matched their intended milestone through the GitHub API. Browser milestone overview confirmed 10 closed and 1 open. Release-readiness issue #248 remains open. No due dates were added." - } + }, + "candidate": null, + "updated_on": "2026-10-05", + "release_updates": [ + { + "version": "v2.5.0", + "published_at": "2026-10-05T07:23:00Z", + "tag_commit": "07f472691e61eab6554dd6f75cf56fb8333964ba", + "milestone_number": 11, + "milestone_state": "closed", + "assigned_additional_pull_requests": [ + 249, + 250, + 251, + 252 + ], + "closed_release_gate": 248, + "open_validation_followup": 254, + "note": "The native_milestone_backfill_result block remains the original dated 2026-10-04 snapshot." + } + ] }