Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
47 changes: 21 additions & 26 deletions ROADMAP.md
Original file line number Diff line number Diff line change
Expand Up @@ -4,9 +4,9 @@ WebSSH is a self-hosted SSH and file workspace. This roadmap explains the direct
the current release focus, and the evidence behind completed work. It is not a release-date
promise or a replacement for issues, pull requests, and release notes.

Planning baseline: **2026-10-03**, commit
[`dc3d9bf`](https://github.com/bifrost0x/webssh/commit/dc3d9bf26f57cbeb440227afe13f9635c4d9f258).
Check the linked GitHub items for newer status.
Release status updated: **2026-10-05**, v2.5.0 at
[`07f4726`](https://github.com/bifrost0x/webssh/commit/07f472691e61eab6554dd6f75cf56fb8333964ba).
Check linked GitHub items for newer status.

## Product direction

Expand All @@ -18,33 +18,26 @@ Check the linked GitHub items for newer status.
These themes summarize the existing product and published release history; they do not
add new feature commitments.

## Now: consolidate the post-2.4 changes
## Now: v2.5.0 published, deployment acceptance remains explicit

**Proposed next release: v2.5.0.** No release date is committed. Scope and version remain
subject to maintainer review. The latest published release at this baseline is
[v2.4.0](https://github.com/bifrost0x/webssh/releases/tag/v2.4.0).
[v2.5.0](https://github.com/bifrost0x/webssh/releases/tag/v2.5.0) delivers optional Warpgate support, workspace continuity,
host/command/mobile usability, tmux directory synchronization, paste/transcript fixes,
faster theme backgrounds and reviewed dependency updates. The
[release comparison](https://github.com/bifrost0x/webssh/compare/v2.4.0...v2.5.0) contains 17 merged PRs.

| Outcome | Implementation state at the baseline | Remaining delivery work |
|---|---|---|
| Optional Warpgate gateway authentication | [#238](https://github.com/bifrost0x/webssh/pull/238) merged; request [#237](https://github.com/bifrost0x/webssh/issues/237) closed | Final-candidate real-protocol acceptance; earlier evidence is revision-specific |
| Workspace continuity and tmux directory synchronization | [#231](https://github.com/bifrost0x/webssh/pull/231), [#233](https://github.com/bifrost0x/webssh/pull/233), [#234](https://github.com/bifrost0x/webssh/pull/234), [#235](https://github.com/bifrost0x/webssh/pull/235), [#236](https://github.com/bifrost0x/webssh/pull/236) merged | Focused multi-session and mobile canary |
| Correct paste input and saved transcripts | [#239](https://github.com/bifrost0x/webssh/pull/239), [#241](https://github.com/bifrost0x/webssh/pull/241) merged | Verify paste/control input and transcript behavior on the candidate |
| Clearer connection review and file actions | [#242](https://github.com/bifrost0x/webssh/pull/242) merged | Connection/key review and file-workspace smoke tests |
| Reviewed dependency and repository maintenance | [#232](https://github.com/bifrost0x/webssh/pull/232), [#243](https://github.com/bifrost0x/webssh/pull/243), [#246](https://github.com/bifrost0x/webssh/pull/246), [#247](https://github.com/bifrost0x/webssh/pull/247) merged | Fresh exact-candidate CI and both native image scans |
[Tag CI and native image publication](https://github.com/bifrost0x/webssh/actions/runs/37276528581) passed on `07f472691e61eab6554dd6f75cf56fb8333964ba`.
Both runtime architectures retain SBOM and provenance attestations. The release record is
[#248](https://github.com/bifrost0x/webssh/issues/248), and the
[v2.5.0 milestone](https://github.com/bifrost0x/webssh/milestone/11) is closed.

All of these changes are **merged but not included in the v2.4.0 tag**.
The [fixed-baseline comparison](https://github.com/bifrost0x/webssh/compare/v2.4.0...dc3d9bf26f57cbeb440227afe13f9635c4d9f258)
contains 13 merged PRs. Baseline [CI and native image publication](https://github.com/bifrost0x/webssh/actions/runs/37064319620)
passed; this does not complete every deployment-specific acceptance check.

The open [release-readiness issue #248](https://github.com/bifrost0x/webssh/issues/248)
is the delivery gate. It remains open until candidate validation, release publication,
and versioned-image verification have evidence. A milestone is not shipped merely because
its implementation PRs are merged.
Publication was authorized with the reported real Warpgate, deployment canary,
upgrade/restore/rollback and applicable environment-specific acceptance still unverified.
These checks remain open in [#254](https://github.com/bifrost0x/webssh/issues/254); they are not counted as passed.
Warpgate remains disabled by default. No new feature release or date is committed.

## Next: choose from verified feedback

After this release, select a small scope from reproducible bugs, user feedback and validated
Select a small scope from reproducible bugs, user feedback and validated
security/dependency findings. State the benefit, priority reason and acceptance criteria in
an issue before assigning substantial work to the next milestone.

Expand Down Expand Up @@ -73,17 +66,19 @@ deployment supported. Do not promote an idea into a promised release by listing
| [v2.2.0](https://github.com/bifrost0x/webssh/releases/tag/v2.2.0) - [v2.2.1](https://github.com/bifrost0x/webssh/releases/tag/v2.2.1) | Terminal-first mobile, GitHub authentication and focused touch-scrolling correction |
| [v2.3.0](https://github.com/bifrost0x/webssh/releases/tag/v2.3.0) | Mobile/input, account-linking, notes/transfers and validated security remediation |
| [v2.4.0](https://github.com/bifrost0x/webssh/releases/tag/v2.4.0) | Responsive high-output multi-session recovery, directory sync and verified image promotion |
| [v2.5.0](https://github.com/bifrost0x/webssh/releases/tag/v2.5.0) | Optional Warpgate, workspace continuity, host/command/mobile usability, terminal correctness and faster backgrounds |

## How this is maintained

- [Project history](docs/project-history.md): what shipped, documented reasons and lessons.
- [Planning and release workflow](docs/project-planning.md): how issues, PRs and milestones fit together.
- [Milestones](https://github.com/bifrost0x/webssh/milestones): native release grouping, with ten historical milestones closed and v2.5.0 open.
- [Milestones](https://github.com/bifrost0x/webssh/milestones): native release grouping, with eleven published-release milestones closed.
- [Retrospective mapping](docs/release-history.json): release/PR/issue membership, milestone numbers and backfill verification.

The native milestone backfill was applied on 2026-10-04: 185 items assigned and
verified. PR #98 was unavailable (HTTP 404) and is recorded as an exception in the
manifest. The release-readiness issue #248 remains open in v2.5.0.
manifest. The 2026-10-05 release update adds PRs #249-#252 to v2.5.0, closes
release-readiness issue #248 and retains the operational acceptance follow-up in #254.

The historical mapping was reconstructed on 2026-10-03. It does not imply that these
milestones or this roadmap existed at the time. Actual GitHub milestone creation and
Expand Down
35 changes: 19 additions & 16 deletions docs/project-history.md
Original file line number Diff line number Diff line change
Expand Up @@ -44,29 +44,32 @@ These belong to the first official release baseline, not invented pre-1.0 releas
| [v2.2.1](https://github.com/bifrost0x/webssh/releases/tag/v2.2.1) / 2026-08-30 | Focused normal-history scrolling correction and direct mobile session tools | [#165](https://github.com/bifrost0x/webssh/pull/165): synthetic wheel events passed a unit check but did not trigger actual browser scrollback | 1 |
| [v2.3.0](https://github.com/bifrost0x/webssh/releases/tag/v2.3.0) / 2026-09-11 | Session-duration controls, verified OIDC linking, mobile/copy/notes/transfer fixes and security remediation | [#202](https://github.com/bifrost0x/webssh/pull/202): validated repository security findings; [#208](https://github.com/bifrost0x/webssh/issues/208)/[#209](https://github.com/bifrost0x/webssh/pull/209): linking friction without weakening stable issuer/subject binding; [#210](https://github.com/bifrost0x/webssh/issues/210)/[#211](https://github.com/bifrost0x/webssh/pull/211): mobile input regression remained | 27 |
| [v2.4.0](https://github.com/bifrost0x/webssh/releases/tag/v2.4.0) / 2026-09-21 | High-output multi-session rendering/recovery, terminal/files sync, hardened remote work and native-image release gates | [#221](https://github.com/bifrost0x/webssh/pull/221): hidden-pane rendering delayed ACKs and caused reconnect loops; [#223](https://github.com/bifrost0x/webssh/pull/223)-[#226](https://github.com/bifrost0x/webssh/pull/226): verify immutable image candidates without breaking deployment compatibility | 16 |
| [v2.5.0](https://github.com/bifrost0x/webssh/releases/tag/v2.5.0) / 2026-10-05 | Optional gateways and everyday workspace continuity | [#238](https://github.com/bifrost0x/webssh/pull/238): optional Warpgate; #231/#233/#242: workspace and connection usability; #234-#236/#239/#241: terminal correctness; #251: background loading; #252: dependency updates | 17 |

The 148 PRs in these release stages are assigned by their **first tagged inclusion**,
The 165 PRs in these release stages are assigned by their **first tagged inclusion**,
not by the week in which they merged. The machine-readable
[release history](release-history.json) lists every PR number, tag SHA, release URL,
comparison and verified issue-to-implementation link. Direct commits are covered by the
Git comparisons even though they have no PR to attach to a native milestone.

## After v2.4.0: implemented, not yet version-released
## v2.5.0 delivery and remaining acceptance

At baseline [`dc3d9bf`](https://github.com/bifrost0x/webssh/commit/dc3d9bf26f57cbeb440227afe13f9635c4d9f258),
13 additional PRs are merged. They cover workspace/tmux follow-ups, optional Warpgate,
paste/transcript correctness, connection/file usability and dependency maintenance.
See the [roadmap](../ROADMAP.md) and [release-readiness issue #248](https://github.com/bifrost0x/webssh/issues/248).
The original 2026-10-03 planning baseline contained 13 merged PRs after v2.4.0.
The published v2.5.0 tag adds #249, #250, #251 and #252, for 17 merged PRs in this release.
PR #253 was superseded by #252 and is not counted as a separately merged PR.

Two important distinctions:
[Tag CI](https://github.com/bifrost0x/webssh/actions/runs/37276528581) and native image publication passed on `07f472691e61eab6554dd6f75cf56fb8333964ba`.
The maintainer authorized publication after the remaining deployment acceptance was
explicitly reported. Real Warpgate, deployment canary, upgrade/recovery and applicable
environment-specific checks remain tracked in [#254](https://github.com/bifrost0x/webssh/issues/254).
Release closure does not mark those checks passed.

- [#237](https://github.com/bifrost0x/webssh/issues/237) is closed and
[#238](https://github.com/bifrost0x/webssh/pull/238) is merged, but Warpgate is not part of
the v2.4.0 tag. The proposed next milestone must remain open for release validation.
- [#245](https://github.com/bifrost0x/webssh/issues/245) was resolved by the reporter's
Warpgate PROXY-protocol configuration. It is support evidence, not a shipped WebSSH fix.
Likewise, [#62](https://github.com/bifrost0x/webssh/issues/62) was converted to a database
proposal discussion. Neither is counted as implementation delivered by a release.
[#237](https://github.com/bifrost0x/webssh/issues/237) and
[#238](https://github.com/bifrost0x/webssh/pull/238) first ship in v2.5.0, not v2.4.0.
[#245](https://github.com/bifrost0x/webssh/issues/245) was resolved by the reporter's
Warpgate PROXY-protocol configuration; it remains support evidence, not a shipped fix.
[#62](https://github.com/bifrost0x/webssh/issues/62) was converted to a database proposal
discussion and is likewise not counted as delivered implementation.

## Lessons for future planning

Expand All @@ -89,5 +92,5 @@ These are retrospective recommendations, not invented historical decisions:
No original release deadlines or complete private planning history were available. The
table summarizes documented purposes rather than claiming a pre-existing strategy.
Issue timelines show use of GitHub Projects, but this retrospective does not verify or
change the board's complete structure/status. Native milestone backfill is prepared in
the manifest and must be checked against the live GitHub milestone list before applying.
change the board's complete structure/status. The manifest preserves the dated native milestone backfill and subsequent release
updates. Check live GitHub metadata before making further assignments.
21 changes: 14 additions & 7 deletions docs/project-planning.md
Original file line number Diff line number Diff line change
Expand Up @@ -51,11 +51,12 @@ interpret their combined count as distinct features delivered.
interactive authentication and a default-off administration gate. The request is closed
and the PR merged, but neither belongs to v2.4.0 because the tag predates their merge.

The proposed v2.5.0 scope groups that implementation with the related workspace fixes.
[#248](https://github.com/bifrost0x/webssh/issues/248) remains open for exact-candidate
protocol checks, canary, upgrade/recovery, publication and image verification. This makes
the distinction between **implemented** and **shipped** visible without reopening the
resolved feature request or making a PR that repeats code already in `main`.
The published [v2.5.0 release](https://github.com/bifrost0x/webssh/releases/tag/v2.5.0) includes that implementation and the
related workspace fixes. [#248](https://github.com/bifrost0x/webssh/issues/248) records
the exact candidate, publication and image verification. The maintainer authorized
publication with the reported deployment acceptance still unverified; those checks
remain open in [#254](https://github.com/bifrost0x/webssh/issues/254). Publication and operational acceptance are
recorded separately, without repeating implementation PRs or marking unrun checks passed.

## Record decisions and blockers

Expand Down Expand Up @@ -95,15 +96,21 @@ CI/security gates cannot be silently waived. No automation or automatic merge is
The initial [release-history manifest](release-history.json) is a dated, reviewable
snapshot of ten published releases and the proposed next scope. It includes prepared
native milestone descriptions, 161 merged PR mappings and 24 verified issue links.
The candidate entry has no tag or publication date because it is not a release.
The original backfill result is retained in the manifest. Later releases extend the
history; `candidate` is null when no next version has been selected.

Applied on **2026-10-04**: ten historical milestones are closed and the proposed
[v2.5.0 milestone](https://github.com/bifrost0x/webssh/milestone/11) is open.
[v2.5.0 milestone](https://github.com/bifrost0x/webssh/milestone/11) was open at that time.
The backfill assigned and verified 160 PRs, 24 implementation-linked issues and the
open release gate #248 (185 items). PR #98 returned HTTP 404 through the API and
signed-in browser and could not be assigned. The original 161-PR reconstruction
is preserved; the manifest records the exception and native milestone numbers.

Published on **2026-10-05**: v2.5.0 adds PRs #249-#252 to the original scope.
The release milestone and #248 are closed after tag/image verification. The current
manifest contains eleven releases and 165 merged PR mappings; deferred deployment
acceptance remains open in #254. The original backfill counts above are not rewritten.

For historical backfill:

1. Read all existing native milestones before creating anything; reuse matching versions
Expand Down
Loading
Loading