{"id":"pst_01M3AF8PXJRG76016JFH7AZTPP","url":"https://openvibe.blog/@openvibe/patch-notes-41-changes-across-21-sites","blog":{"id":"blg_01M362MF0EDJ7QHQTRD8A3Q981","handle":"openvibe","title":"The OpenVibe blog","url":"https://openvibe.blog/"},"title":"Patch notes: 41 changes across 21 sites","summary":"What shipped on OpenVibe on 2026-09-24: 41 changes to OpenVibe.Network, OpenVibe.Community, OpenVibe.Search, OpenVibe.Blog, OpenVibe.Media, OpenVibe.Chat and 15 more.","body_markdown":"What shipped on OpenVibe on 2026-09-24: 41 changes to OpenVibe.Network, OpenVibe.Community, OpenVibe.Search, OpenVibe.Blog, OpenVibe.Media, OpenVibe.Chat and 15 more. Every line below is a commit message from the OpenVibers repositories, linked to the change itself.\n\n## OpenVibe.Network\n\n[openvibe.network](https://openvibe.network) · [repository](https://github.com/OpenVibers/OpenVibe.Network)\n\n- openvibe-shared 1.11.1: the footer's shipped line follows each site's own service ([`b95d2d0`](https://github.com/OpenVibers/OpenVibe.Network/commit/b95d2d0f9a3efc907571dad444160be8404e2566))\n- Brand assets (/assets/*: logo, app icons, OG images) are readable cross-origin and cached for a day: helmet's Cross-Origin-Resource-Policy same-origin blocked the logo on every placeholder site ([`fce0931`](https://github.com/OpenVibers/OpenVibe.Network/commit/fce093120067fd990bdb0ea947aac7a9d7fbe807))\n- The registry reports each released library's latest published tag (read from GitHub at boot and hourly; the installed version until then, and whenever a lookup fails) instead of the version Network happens to install — it said openvibe-sdk… ([`eb9a161`](https://github.com/OpenVibers/OpenVibe.Network/commit/eb9a161727bcb18e9999198404091d79f5d40ff3))\n- openvibe-shared 1.12.0 (the navbar loads its siblings from its own origin) ([`6be9939`](https://github.com/OpenVibers/OpenVibe.Network/commit/6be993912c6bb99bdc13a52191b1e52072b3845b))\n- The moderation audit log (ADR-022): Network records chat.moderation.action (Chat and Live), community.moderation.action, tips.interaction.moderated and billing.staff.action from Events, once each inside the consumer's inbox transaction and… ([`b1b9f92`](https://github.com/OpenVibers/OpenVibe.Network/commit/b1b9f92ce10ab22ccdfb2ba3baad7de12ae7e40f))\n- The GitHub token is configurable in admin (Settings → GitHub, owner-only): GITHUB_TOKEN in the environment first, else the saved value; admin shows its source and last four characters and a Test that asks GitHub for the rate limit, never… ([`8c9fa75`](https://github.com/OpenVibers/OpenVibe.Network/commit/8c9fa75753e39dc561d36c684f6485e56aa2890e))\n- User tokens carry staff_map (the staff map version their staff_caps come from; Contracts 0.38.0, map 1.1.0), so services judge capabilities added later by the role instead of waiting for new tokens ([`196c76e`](https://github.com/OpenVibers/OpenVibe.Network/commit/196c76efcd3614c253ec590cb410dbfde152e75a))\n\n## OpenVibe.Community\n\n[openvibe.community](https://openvibe.community) · [repository](https://github.com/OpenVibers/OpenVibe.Community)\n\n- CI calls the shared test workflow (Track Q): OpenVibe.Shared .github/workflows/test.yml@f5e7e73 (install, node --check over server/ and scripts/, npm test, openvibe-contracts-check) instead of a copy of those steps ([`58fa49e`](https://github.com/OpenVibers/OpenVibe.Community/commit/58fa49ea54e5e03f63ead9fce1ee22c78590d91a))\n- The OpenVibe Frame and the shared update system on openvibe.community: the home shows what shipped and /updates is the shared log (openvibe-shared/frame 1.11.1), the footer links it, and the shared navbar signs out through this site… ([`58f1b3b`](https://github.com/OpenVibers/OpenVibe.Community/commit/58f1b3b58ed7ff963dd42bee929ff9fadef09c27))\n- The OpenVibe Frame from this site's own pinned copy: /shared/* is served by openvibe-shared/serve (1.12.0) and every page references it by content hash (/shared/<file>?v=<hash>), so this site's pin decides what its pages run and its navbar… ([`8772c78`](https://github.com/OpenVibers/OpenVibe.Community/commit/8772c784e78136a9ec7b9a86b0011ef3eef43fff))\n- Staff actions on someone else's content publish community.moderation.action for the network's moderation audit log (ADR-022): paste edit, visibility change, delete, censor, bulk and fork cleanup, comment and post removal, thread delete… ([`bd3a551`](https://github.com/OpenVibers/OpenVibe.Community/commit/bd3a551a9b90957c2771ba8ac20fc8bb42f4788e))\n\n## OpenVibe.Search\n\n[search.openvibe.network](https://search.openvibe.network) · [repository](https://github.com/OpenVibers/OpenVibe.Search)\n\n- The OpenVibe Frame on search.openvibe.network: the shared navbar, footer and themes (scripts only from this site or openvibe.network; the init is the same-origin /frame-init.js reading a JSON config, so the CSP still allows no inline… ([`b168c70`](https://github.com/OpenVibers/OpenVibe.Search/commit/b168c70f99bd0de02bf2930fc459fb919f5a0676))\n- The network's app icon on the search page (link tags only; its inline script would break the no-inline-script CSP), so browsers stop asking for a missing /favicon.ico ([`0db444f`](https://github.com/OpenVibers/OpenVibe.Search/commit/0db444ffe94388bea1a22279223f15f0238d91fc))\n- The OpenVibe Frame from this site's own pinned copy: /shared/* is served by openvibe-shared/serve (1.12.0) and every page references it by content hash (/shared/<file>?v=<hash>), so this site's pin decides what its pages run and its navbar… ([`ae94086`](https://github.com/OpenVibers/OpenVibe.Search/commit/ae9408617bf67296e82ef103d77f8b1cc47e28c4))\n- Search page: the app icon's link tags without the web-app manifest (this service serves none, and its CSP has no manifest-src) ([`bef5188`](https://github.com/OpenVibers/OpenVibe.Search/commit/bef51886b571f90fd36d0df5da356c6da72da261))\n\n## OpenVibe.Blog\n\n[openvibe.blog](https://openvibe.blog) · [repository](https://github.com/OpenVibers/OpenVibe.Blog)\n\n- The OpenVibe Frame from this site's own pinned copy: /shared/* is served by openvibe-shared/serve (1.12.0) and every page references it by content hash (/shared/<file>?v=<hash>), so this site's pin decides what its pages run and its navbar… ([`7d9d197`](https://github.com/OpenVibers/OpenVibe.Blog/commit/7d9d197db226f53c19d30de2506dbd19c8ba7e84))\n- The changelog's GitHub token: CHANGELOG_GITHUB_TOKEN, else the network's (admin → Settings → GitHub), asked of Network's /internal/integrations/github-token with Blog's service token (network.integration.github.read) and kept ten minutes… ([`ea6b788`](https://github.com/OpenVibers/OpenVibe.Blog/commit/ea6b788b130f3d9e3b6dd16ef679feec85c88423))\n- Staff powers from the contracts staff map (WS-D, ADR-022; Contracts 0.38.0): moderation on any blog is staff.content.moderate (global_mod and up, was admin only), the official blog's ownership is staff.editorial.manage (admin); no role… ([`f0451df`](https://github.com/OpenVibers/OpenVibe.Blog/commit/f0451dff7a39b8fce99895afcd35d94758adb331))\n\n## OpenVibe.Media\n\n[openvibe.media](https://openvibe.media) · [repository](https://github.com/OpenVibers/OpenVibe.Media)\n\n- CI calls the shared test workflow (Track Q): OpenVibe.Shared test.yml@e8b0caf (install, node --check, npm test, openvibe-contracts-check; ffmpeg where the tests need it) instead of a copy of those steps ([`28372f7`](https://github.com/OpenVibers/OpenVibe.Media/commit/28372f7728e8aefca7dd608b796d2c0a67f3500d))\n- The OpenVibe Frame and the shared update system on openvibe.media: page-chrome.js is page-frame.js (frameScripts) on openvibe-shared/frame 1.11.1; the index shows what shipped and /updates is the shared log; the footer links it; the shared… ([`3733437`](https://github.com/OpenVibers/OpenVibe.Media/commit/3733437c5feed6c4fd7d65872eb0cbe12f63bbff))\n- The OpenVibe Frame from this site's own pinned copy: /shared/* is served by openvibe-shared/serve (1.12.0) and every page references it by content hash (/shared/<file>?v=<hash>), so this site's pin decides what its pages run and its navbar… ([`3c3ddf5`](https://github.com/OpenVibers/OpenVibe.Media/commit/3c3ddf5140db36f3d59ddd11403ca2cc7a521658))\n\n## OpenVibe.Chat\n\n- Network-token auth in Chat (WS-I task 3): a Network session JWT is verified here with the Network's key and resolved through the ctx_users projection by subject (new index), carrying the token's staff_caps and a role that only ever raises… ([`3ebc5a1`](https://github.com/OpenVibers/OpenVibe.Chat/commit/3ebc5a113e57ef1dd8f0a327db9d5b6ebb369c00))\n- GET /metrics: chat_auth_resolutions{via=local|live|rejected}, where sign-ins were decided since start ([`6b68f57`](https://github.com/OpenVibers/OpenVibe.Chat/commit/6b68f57a79de7e3af759268c3557509d4b0a0ad4))\n\n## OpenVibe.Live\n\n[openvibe.live](https://openvibe.live) · [repository](https://github.com/OpenVibers/OpenVibe.Live)\n\n- What shipped on Live comes from the network's shared system (openvibe-shared 1.11.1 shipped.js, fed by the network changelog of deployed commits): the hero one-liner, the home Recent Changes (same day groups, same expand button) and… ([`a49efd5`](https://github.com/OpenVibers/OpenVibe.Live/commit/a49efd5efd5986a680e4631c65dd17946e69edd9))\n- openvibe-shared 1.12.0 (the navbar loads its siblings from this site's own /shared/ copy) ([`7b2b2f4`](https://github.com/OpenVibers/OpenVibe.Live/commit/7b2b2f4ccd8abb52c426db2e6ae887e3c6208263))\n\n## OpenVibe.Tools\n\n[openvibe.tools](https://openvibe.tools) · [repository](https://github.com/OpenVibers/OpenVibe.Tools)\n\n- The shared update system on openvibe.tools: the home shows what shipped and /updates is the shared log (openvibe-shared/frame shipped()/updatesBody(), same markup as every OpenVibe site), the footer links it, /updates is in the sitemap… ([`e46e1d2`](https://github.com/OpenVibers/OpenVibe.Tools/commit/e46e1d25c914442e07e3bf045d88519a68d4e1df))\n- The Tools gateway serves its own pinned OpenVibe Frame files at /shared/* (openvibe-shared/serve 1.12.0) and its server-rendered pages reference them by content hash ([`2b5104f`](https://github.com/OpenVibers/OpenVibe.Tools/commit/2b5104f4f0c88dc28f636a4ecdb99654fc30b2d6))\n\n## OpenVibe.Wiki\n\n[openvibe.wiki](https://openvibe.wiki) · [repository](https://github.com/OpenVibers/OpenVibe.Wiki)\n\n- The OpenVibe Frame from this site's own pinned copy: /shared/* is served by openvibe-shared/serve (1.12.0) and every page references it by content hash (/shared/<file>?v=<hash>), so this site's pin decides what its pages run and its navbar… ([`8571aa1`](https://github.com/OpenVibers/OpenVibe.Wiki/commit/8571aa10aecb665535b277726c60df025b6cfd84))\n- Staff powers from the contracts staff map (WS-D, ADR-022; Contracts 0.38.0): owning and creating official spaces is staff.editorial.manage (admin; global_mods no longer own official spaces), not a role list. test/staff-map.test.js fails on… ([`e0d58e0`](https://github.com/OpenVibers/OpenVibe.Wiki/commit/e0d58e024e6dcc65988a5baa39955925986b052d))\n\n## OpenVibe.Billing\n\n[billing.openvibe.network](https://billing.openvibe.network) · [repository](https://github.com/OpenVibers/OpenVibe.Billing)\n\n- The staff console shows what shipped on Billing, server-rendered (it loads no scripts, so the shared widget cannot run there): the newest network-changelog entry, read from Network's loopback proxy at most once a minute in the background… ([`af1d30e`](https://github.com/OpenVibers/OpenVibe.Billing/commit/af1d30e3f7d53e16760765ac64f5d73095c1f5cc))\n\n## OpenVibe.Codes\n\n[openvibe.codes](https://openvibe.codes) · [repository](https://github.com/OpenVibers/OpenVibe.Codes)\n\n- The OpenVibe Frame from this site's own pinned copy: /shared/* is served by openvibe-shared/serve (1.12.0) and every page references it by content hash (/shared/<file>?v=<hash>), so this site's pin decides what its pages run and its navbar… ([`4dc695b`](https://github.com/OpenVibers/OpenVibe.Codes/commit/4dc695b77dfc278313c3923ed1dc2edddb42d2ef))\n\n## OpenVibe.Coupons\n\n[openvibe.coupons](https://openvibe.coupons) · [repository](https://github.com/OpenVibers/OpenVibe.Coupons)\n\n- The OpenVibe Frame from this site's own pinned copy: /shared/* is served by openvibe-shared/serve (1.12.0) and every page references it by content hash (/shared/<file>?v=<hash>), so this site's pin decides what its pages run and its navbar… ([`c9cf59f`](https://github.com/OpenVibers/OpenVibe.Coupons/commit/c9cf59f3d4b871e808364093a13071853794f467))\n\n## OpenVibe.Deals\n\n[openvibe.deals](https://openvibe.deals) · [repository](https://github.com/OpenVibers/OpenVibe.Deals)\n\n- The OpenVibe Frame from this site's own pinned copy: /shared/* is served by openvibe-shared/serve (1.12.0) and every page references it by content hash (/shared/<file>?v=<hash>), so this site's pin decides what its pages run and its navbar… ([`829013c`](https://github.com/OpenVibers/OpenVibe.Deals/commit/829013ce1481f2942229eebcbee42efdb7fbf4b1))\n\n## OpenVibe.Games\n\n[openvibe.games](https://openvibe.games) · [repository](https://github.com/OpenVibers/OpenVibe.Games)\n\n- The OpenVibe Frame on openvibe.games: public/chrome.js is frame.js (__ovgFrame, ovg-frame-hidden, ovg-frame-toggle); the portal shows what shipped (the network's shared shipped views) and the footer's Updates link opens the Games log on… ([`3fe7f7b`](https://github.com/OpenVibers/OpenVibe.Games/commit/3fe7f7b899ee2b1019ebc7211a1abb3f65da9aa6))\n\n## OpenVibe.Host\n\n[openvibe.host](https://openvibe.host) · [repository](https://github.com/OpenVibers/OpenVibe.Host)\n\n- The OpenVibe Frame from this site's own pinned copy: /shared/* is served by openvibe-shared/serve (1.12.0) and every page references it by content hash (/shared/<file>?v=<hash>), so this site's pin decides what its pages run and its navbar… ([`0a2baea`](https://github.com/OpenVibers/OpenVibe.Host/commit/0a2baeaa20da7da8b66ff60bfe68f9c0da2fdbdc))\n\n## OpenVibe.News\n\n[openvibe.news](https://openvibe.news) · [repository](https://github.com/OpenVibers/OpenVibe.News)\n\n- The OpenVibe Frame from this site's own pinned copy: /shared/* is served by openvibe-shared/serve (1.12.0) and every page references it by content hash (/shared/<file>?v=<hash>), so this site's pin decides what its pages run and its navbar… ([`9dd0229`](https://github.com/OpenVibers/OpenVibe.News/commit/9dd02292ae737343695b68abe255fbc40a020b0d))\n\n## OpenRe.Stream\n\n[openre.stream](https://openre.stream) · [repository](https://github.com/OpenVibers/OpenRe.Stream)\n\n- The OpenVibe Frame from this site's own pinned copy: /shared/* is served by openvibe-shared/serve (1.12.0) and every page references it by content hash (/shared/<file>?v=<hash>), so this site's pin decides what its pages run and its navbar… ([`d7330c5`](https://github.com/OpenVibers/OpenRe.Stream/commit/d7330c5f4ae9b1b47a1da13ecb401d114f144692))\n\n## OpenVibe.Reviews\n\n[openvibe.reviews](https://openvibe.reviews) · [repository](https://github.com/OpenVibers/OpenVibe.Reviews)\n\n- The OpenVibe Frame from this site's own pinned copy: /shared/* is served by openvibe-shared/serve (1.12.0) and every page references it by content hash (/shared/<file>?v=<hash>), so this site's pin decides what its pages run and its navbar… ([`13f4628`](https://github.com/OpenVibers/OpenVibe.Reviews/commit/13f46289b7435501ad73636ae6bfdf4ae48f7be0))\n\n## OpenVibe.Tips\n\n[openvibe.tips](https://openvibe.tips) · [repository](https://github.com/OpenVibers/OpenVibe.Tips)\n\n- The OpenVibe Frame from this site's own pinned copy: /shared/* is served by openvibe-shared/serve (1.12.0) and every page references it by content hash (/shared/<file>?v=<hash>), so this site's pin decides what its pages run and its navbar… ([`c0b4c87`](https://github.com/OpenVibers/OpenVibe.Tips/commit/c0b4c87d48f783b6ad65ceda169759c95448c146))\n\n## OpenVibe.Trade\n\n[openvibe.trade](https://openvibe.trade) · [repository](https://github.com/OpenVibers/OpenVibe.Trade)\n\n- The OpenVibe Frame from this site's own pinned copy: /shared/* is served by openvibe-shared/serve (1.12.0) and every page references it by content hash (/shared/<file>?v=<hash>), so this site's pin decides what its pages run and its navbar… ([`c40092a`](https://github.com/OpenVibers/OpenVibe.Trade/commit/c40092a910efcc8f5fb21623b064868d5a4a7b32))\n\n## OpenVibe.VIP\n\n[openvibe.vip](https://openvibe.vip) · [repository](https://github.com/OpenVibers/OpenVibe.VIP)\n\n- The OpenVibe Frame from this site's own pinned copy: /shared/* is served by openvibe-shared/serve (1.12.0) and every page references it by content hash (/shared/<file>?v=<hash>), so this site's pin decides what its pages run and its navbar… ([`86e6996`](https://github.com/OpenVibers/OpenVibe.VIP/commit/86e6996ce1f83010b7d43752eb4642bd57d018fd))\n\n---\n\nPatch notes are put together automatically when enough changes have shipped, or when a large feature lands. See every site's own updates page for the live list.","revision":1,"state":"published","visibility":"public","published_at":"2026-09-24T19:46:19.194Z","revised_at":"2026-09-24T19:46:19.189Z","author":{"subject":"usr_01KKT9AC60KM7CRTB3WN1Z8P56","name":"goosely","username":"goosely"},"authorship":{"mode":"imported","workflow":null,"reviewed":false,"disclosure":{"mode":"imported","short":"Imported","long":"Imported from Commit messages from the OpenVibers repositories on GitHub; originally by OpenVibers."}},"tags":["patch-notes","network","community","search","blog","media","chat","live","tools","wiki","billing"],"categories":[],"series":{"title":"Patch notes","url":"https://openvibe.blog/@openvibe/series/patch-notes","position":null},"media":[],"citations":[],"indexability":{"indexable":true,"robots":"index, follow","reasons":[]}}