{"id":"pst_01M3D0R961QR0H122QQ06J96NN","url":"https://openvibe.blog/@openvibe/patch-notes-47-changes-across-22-sites","blog":{"id":"blg_01M362MF0EDJ7QHQTRD8A3Q981","handle":"openvibe","title":"The OpenVibe blog","url":"https://openvibe.blog/"},"title":"Patch notes: 47 changes across 22 sites","summary":"What shipped on OpenVibe on 2026-09-25: 47 changes to OpenVibe.Media, OpenVibe.Community, OpenVibe.Network, OpenVibe.Live, OpenVibe.Tools, OpenVibe.AI and 16 more.","body_markdown":"What shipped on OpenVibe on 2026-09-25: 47 changes to OpenVibe.Media, OpenVibe.Community, OpenVibe.Network, OpenVibe.Live, OpenVibe.Tools, OpenVibe.AI and 16 more. Every line below is a commit message from the OpenVibers repositories, linked to the change itself.\n\n## Highlights\n\n- **OpenVibe.Chat:** Chat rooms (WS-I task 4, first release): anyone signed in starts a room (public or private, up to 10 each); members, mods and owner roles, invitations, blocking, slow mode, unread counts; history and posting over /api/chat/rooms and live… ([`27852af`](https://github.com/OpenVibers/OpenVibe.Chat/commit/27852aff3b5fb03beafb148f8639fcc75ea7e010))\n- **OpenVibe.Community:** Forum boards next to feeds: each space is a forum (vBulletin/SMF style: a grouped board index with topics, posts and the last post; topic tables with replies, views and the last post, sticky first, bumped by replies; posts beside the… ([`a1c3b23`](https://github.com/OpenVibers/OpenVibe.Community/commit/a1c3b23f7d3a1330e94e028dce1637655f1cfa6f))\n- **OpenVibe.Media:** Readiness levels (WS-G task 5): every media object answers metadata, bytes_verified and playable, read from the object row and its copies' recorded checks (server/objects/readiness.js). bytes_verified needs a copy that is present with a… ([`8b1abf0`](https://github.com/OpenVibers/OpenVibe.Media/commit/8b1abf09759469768a68d5c55d63565bf0cc8330))\n\n## OpenVibe.Media\n\n[openvibe.media](https://openvibe.media) · [repository](https://github.com/OpenVibers/OpenVibe.Media)\n\n- Sign-out everywhere reaches openvibe.media (WS-B task 4, SDK 0.9.1): POST /internal/events (MEDIA_INBOUND_EVENTS_SECRET, signature v2, never through the proxy) applies network.user.token_valid_after into the SDK revocation store; the… ([`4c3fdac`](https://github.com/OpenVibers/OpenVibe.Media/commit/4c3fdac15fe4b7a45da4d558372e81f6ae9958ad))\n- Sign-out everywhere deliveries verify: POST /internal/events is mounted before express.json(), which consumed the raw body its signature is over (every delivery answered 401). The test holds the order ([`c140b32`](https://github.com/OpenVibers/OpenVibe.Media/commit/c140b32e5f42c1e2b31046bed23e9a7f220d4ac5))\n- Readiness levels (WS-G task 5): every media object answers metadata, bytes_verified and playable, read from the object row and its copies' recorded checks (server/objects/readiness.js). bytes_verified needs a copy that is present with a… ([`8b1abf0`](https://github.com/OpenVibers/OpenVibe.Media/commit/8b1abf09759469768a68d5c55d63565bf0cc8330))\n- Storage orphan report (WS-G task 8), report only: server/vod/orphans-report.js buildStorageReport compares what storage holds with what the database names and lists files under the data directories and B2/R2 keys that no row names (with… ([`95a449d`](https://github.com/OpenVibers/OpenVibe.Media/commit/95a449d0243a56f6f2c1670da505744c37a69973))\n- Retention holds (WS-G task 10), on the existing media_holds (no second table): a note column (added to existing databases), placed_by/placed_at in every answer (created_by/created_at kept), and staff routes on the app-key admin router… ([`a63bb3a`](https://github.com/OpenVibers/OpenVibe.Media/commit/a63bb3a04e0cb9521a18282a6b64acc20b8a4b25))\n- scripts/export-legacy-refs.js: which med_ object stands behind each legacy reference under a prefix (read-only), for services moving to object ids (C-24, Community's screenshot pastes) ([`9cf52c0`](https://github.com/OpenVibers/OpenVibe.Media/commit/9cf52c0c26aa67663b1b876a68fa96ec252f65c8))\n- export-legacy-refs --from-pastes <app>: each paste row's own object (pastes.object_id), keyed legacy:<app>:paste:<slug>, also when the object is filed under another legacy name (screenshots that were also avatars) ([`e027ac5`](https://github.com/OpenVibers/OpenVibe.Media/commit/e027ac5c0798163e88a0c0a1c16ca873fa9f58ed))\n\n## OpenVibe.Community\n\n[openvibe.community](https://openvibe.community) · [repository](https://github.com/OpenVibers/OpenVibe.Community)\n\n- community.profile on Network (Contracts 0.41.0 user module, WS-B task 9): threads, replies, comments and public pastes a person wrote (deleted, AI and private not counted), first and last activity; a 5-minute scan of authors whose rows… ([`8be21c2`](https://github.com/OpenVibers/OpenVibe.Community/commit/8be21c246120ecd8b115be3797d0c1fb0abea3fb))\n- Categories, feature requests and a public Roadmap space (WS-J tasks 1 and 8): categories per space (Feedback: Ideas, Bugs, Questions), filters by category and status, Feedback threads are requests (open to votes, statuses set by staff)… ([`834a14d`](https://github.com/OpenVibers/OpenVibe.Community/commit/834a14df434bddce85328f7a4f6448374d310be0))\n- Images on forum posts as med_ references (WS-J task 2): up to 4 PNG/JPEG/GIF/WebP images (by content, 8 MB, metadata stripped) per thread or reply, stored through OpenVibe.Media's Object API v2 (init, content, complete) as public objects… ([`8708672`](https://github.com/OpenVibers/OpenVibe.Community/commit/87086722d58da38729ca48b194a97488aec1ee34))\n- Forum boards next to feeds: each space is a forum (vBulletin/SMF style: a grouped board index with topics, posts and the last post; topic tables with replies, views and the last post, sticky first, bumped by replies; posts beside the… ([`a1c3b23`](https://github.com/OpenVibers/OpenVibe.Community/commit/a1c3b23f7d3a1330e94e028dce1637655f1cfa6f))\n- Roadmap: media reliability item says what shipped (verified-before-play, holds, the monthly stray-file report) and what is left ([`4dde6e9`](https://github.com/OpenVibers/OpenVibe.Community/commit/4dde6e96451b7640d51080cdae0179cae783a1c6))\n- C-24: screenshot pastes name media objects. New screenshots (and censored replacements) are OpenVibe.Media v2 objects (kind screenshot, unlisted, owned by the person when signed in; the v1 file store only without Community's service… ([`5355423`](https://github.com/OpenVibers/OpenVibe.Community/commit/53554230c31ff2a86d08ef03762d21807ecc2921))\n\n## OpenVibe.Network\n\n[openvibe.network](https://openvibe.network) · [repository](https://github.com/OpenVibers/OpenVibe.Network)\n\n- Grant media and tools events.subscription.manage: they subscribe to network.user.token_valid_after (sign-out everywhere) ([`6b93ae0`](https://github.com/OpenVibers/OpenVibe.Network/commit/6b93ae09566f16b35f7c5764d98e02b3fca67677))\n- User modules (Contracts 0.41.0, WS-B task 9): a service reading another's namespace sees only the fields readers lists for it; stored records read at the current version through the namespace's migrations and are stored at it on the next… ([`707504c`](https://github.com/OpenVibers/OpenVibe.Network/commit/707504c28df1b17b7e206167e13b1ae7fbf21afb))\n- my.openvibe.network AI & Data tab: AI preferences (style, length, perspective, keep what I ask AI) saved to the ai.preferences module OpenVibe.AI reads; every module record kept with the account listed with who keeps it, each deletable… ([`f17223b`](https://github.com/OpenVibers/OpenVibe.Network/commit/f17223b2b54bb5e1cc080d488841294aaec61d31))\n- Home page sites come from the frame's list (open only when the service serves its own domain): nine sites (Chat, Codes, Blog and Wiki joined), Opening next lists only what is not open yet, counts in words, JSON-LD and llms.txt follow; the… ([`bcc05bf`](https://github.com/OpenVibers/OpenVibe.Network/commit/bcc05bf0b52f3da7ace58c9ad726121f3604ab62))\n- Contracts 0.41.1 (plain-language module descriptions); the AI & Data tab names who keeps each record (OpenVibe.Chat, OpenVibe.Tools…) ([`c47ad2f`](https://github.com/OpenVibers/OpenVibe.Network/commit/c47ad2fc209a91e878c660171c8c4786e409b44f))\n- Manifest-derived registry (WS-C task 1, Contracts 0.42.0): the loopback addresses, exposure states and the frame's site list come from the service manifests (internalOrigin, exposure, site); INTERNAL, READY_PATHS, EXPOSURE and RAW_SITES… ([`ca0b63e`](https://github.com/OpenVibers/OpenVibe.Network/commit/ca0b63ef79580e3b74ad8dcdf02830c3d67ba2a5))\n\n## OpenVibe.Live\n\n[openvibe.live](https://openvibe.live) · [repository](https://github.com/OpenVibers/OpenVibe.Live)\n\n- User modules (Contracts 0.41.0, WS-B task 9): Live writes live.profile and live.stats to Network (server/auth/module-summaries.js: a 5-minute scan of ended streams and new followers, a daily refresh of the 30-day window, written only when… ([`c3c95db`](https://github.com/OpenVibers/OpenVibe.Live/commit/c3c95dba44e0f6030dc2df288a5bdcd47af5efa6))\n- Pins: openvibe-sdk 0.7.0 → 0.9.1, openvibe-contracts 0.41.0 → 0.42.0; CI uses the shared workflows at 423fe51, which run the pin-drift check (WS-C task 5) ([`6e74ed3`](https://github.com/OpenVibers/OpenVibe.Live/commit/6e74ed30eb378cb0887fb09f0ab14279076764ca))\n- Live follows the OpenVibe account (WS-B task 2, Contracts 0.43.0): subject_projection kept from Network's network.user.updated (POST /internal/network-events; the subscribe script's --network asks for it), and the linked account follows… ([`f705029`](https://github.com/OpenVibers/OpenVibe.Live/commit/f7050296e8ec0a076f4331bbabf303e80ca1115a))\n\n## OpenVibe.Tools\n\n[openvibe.tools](https://openvibe.tools) · [repository](https://github.com/OpenVibers/OpenVibe.Tools)\n\n- Sign-out everywhere across Tools (WS-B task 4, SDK 0.9.1): the gateway consumes network.user.token_valid_after (POST /internal/events, TOOLS_EVENTS_SECRET, signature v2, never through the proxy) into a shared SQLite file… ([`ab20dc4`](https://github.com/OpenVibers/OpenVibe.Tools/commit/ab20dc44413370f9be11ee2678e9eafb6376cc12))\n- Sign-out everywhere cutoffs live in apps/gateway/data (the gateway unit's ReadWritePaths; /opt/openvibe.tools/data was unwritable and every delivery answered 500), in a rollback journal so the read-only apps under ProtectSystem=strict can… ([`f4926b0`](https://github.com/OpenVibers/OpenVibe.Tools/commit/f4926b0e6010c285825b02306c99338729eb108a))\n- Favourite tools (tools.usage v2, Contracts 0.41.0, WS-B task 9): the launcher's Your tools shows starred tools first with a star on each card, PUT/DELETE /api/v1/me/favorites/:tool, /api/v1/me/recent-tools returns favorites; every… ([`df821b3`](https://github.com/OpenVibers/OpenVibe.Tools/commit/df821b3bbfa92ddf261725da9a23161829fd98c8))\n\n## OpenVibe.AI\n\n[ai.openvibe.network](https://ai.openvibe.network) · [repository](https://github.com/OpenVibers/OpenVibe.AI)\n\n- AI's user modules (Contracts 0.41.0, WS-B task 9): a run on a person's behalf follows their ai.preferences (style, length and perspective reach the system prompt; history: false keeps neither the input nor a cache entry; shaped output is… ([`e2847c9`](https://github.com/OpenVibers/OpenVibe.AI/commit/e2847c9517068e41c7da852189c10affa7d6da8a))\n- Pins: openvibe-contracts 0.41.0 → 0.42.0, openvibe-sdk 0.7.0 → 0.9.1, openvibe-shared 1.7.0 → 1.12.0; CI runs the pin-drift check (shared test and security workflows at 423fe51) ([`53f7765`](https://github.com/OpenVibers/OpenVibe.AI/commit/53f7765ada302d05e517902440ad530c29e1dc2e))\n\n## OpenVibe.Chat\n\n[openvibe.chat](https://openvibe.chat) · [repository](https://github.com/OpenVibers/OpenVibe.Chat)\n\n- Chat rooms (WS-I task 4, first release): anyone signed in starts a room (public or private, up to 10 each); members, mods and owner roles, invitations, blocking, slow mode, unread counts; history and posting over /api/chat/rooms and live… ([`27852af`](https://github.com/OpenVibers/OpenVibe.Chat/commit/27852aff3b5fb03beafb148f8639fcc75ea7e010))\n- Chat owns chat.tts_defaults, chat.dm_settings and chat.presence_prefs (Contracts 0.41.0, WS-B task 9): one module store per namespace (server/prefs/module-store.js), /api/chat/tts-settings, /dm-settings and /presence beside /preferences… ([`2bdb0cf`](https://github.com/OpenVibers/OpenVibe.Chat/commit/2bdb0cfec1e5ed5b2e30440f36ae7222fd1a10ec))\n\n## OpenVibe.Events\n\n[events.openvibe.network](https://events.openvibe.network) · [repository](https://github.com/OpenVibers/OpenVibe.Events)\n\n- CI calls the shared test workflow (Track Q): OpenVibe.Shared test.yml@e8b0caf (install, node --check, npm test, openvibe-contracts-check; ffmpeg where the tests need it) instead of a copy of those steps ([`eb68bb7`](https://github.com/OpenVibers/OpenVibe.Events/commit/eb68bb7afc6bacf6beeb2eb8c306e3ac092a38a6))\n- Pins: openvibe-contracts 0.33.0 → 0.42.0, openvibe-shared 1.6.0 → 1.12.0; CI runs the pin-drift check (shared test and security workflows at 423fe51) ([`7074fb6`](https://github.com/OpenVibers/OpenVibe.Events/commit/7074fb60cbfd16b8f558639b776c68e07cbee9b9))\n\n## OpenVibe.Host\n\n[openvibe.host](https://openvibe.host) · [repository](https://github.com/OpenVibers/OpenVibe.Host)\n\n- Restore drills: the first production R2 eviction drill (Media VOD 2178) passed: served from B2 with the R2 cache evicted, R2 restored after ([`ca3df9a`](https://github.com/OpenVibers/OpenVibe.Host/commit/ca3df9ae6ac8669e7b246bc8506442ecbc107c40))\n- Pins: openvibe-contracts 0.38.0 → 0.42.0, openvibe-sdk 0.5.0 → 0.9.1; CI runs the pin-drift check (shared test and security workflows at 423fe51) ([`9e753aa`](https://github.com/OpenVibers/OpenVibe.Host/commit/9e753aafd70e9549af44db030fa4117fc3a1c0ef))\n\n## OpenVibe.Wiki\n\n[openvibe.wiki](https://openvibe.wiki) · [repository](https://github.com/OpenVibers/OpenVibe.Wiki)\n\n- wiki.projects on Network (Contracts 0.41.0 user module, WS-B task 9): the spaces a person owns or edits (public ones named, others counted); a space or role change marks the people concerned in the same transaction (a removed role too) and… ([`1c94ea3`](https://github.com/OpenVibers/OpenVibe.Wiki/commit/1c94ea3df6be56c9ae07d2fec043a3c9868a9ac0))\n- Pins: openvibe-contracts 0.41.0 → 0.42.0, openvibe-sdk 0.5.0 → 0.9.1; CI runs the pin-drift check (shared test and security workflows at 423fe51) ([`58e40a9`](https://github.com/OpenVibers/OpenVibe.Wiki/commit/58e40a9898b36b06c3c40298f377d194e4bd0399))\n\n## OpenVibe.Billing\n\n[billing.openvibe.network](https://billing.openvibe.network) · [repository](https://github.com/OpenVibers/OpenVibe.Billing)\n\n- Pins: openvibe-contracts 0.38.0 → 0.42.0, openvibe-shared 1.7.0 → 1.12.0; CI runs the pin-drift check (shared test and security workflows at 423fe51) ([`fe42144`](https://github.com/OpenVibers/OpenVibe.Billing/commit/fe42144cb36ba1f22c052c265a94c93024afbbcf))\n\n## OpenVibe.Codes\n\n[openvibe.codes](https://openvibe.codes) · [repository](https://github.com/OpenVibers/OpenVibe.Codes)\n\n- Pins: openvibe-contracts 0.38.0 → 0.42.0, openvibe-sdk 0.5.0 → 0.9.1; test/docs.test.js expects the new pinned tags (it asserts the pinned versions on purpose); CI runs the pin-drift check (shared test and security workflows at 423fe51) ([`5bfd3f9`](https://github.com/OpenVibers/OpenVibe.Codes/commit/5bfd3f99cd88996d4a3fb0cb08717c0ba31bff53))\n\n## OpenVibe.Coupons\n\n[openvibe.coupons](https://openvibe.coupons) · [repository](https://github.com/OpenVibers/OpenVibe.Coupons)\n\n- Pins: openvibe-contracts 0.38.0 → 0.42.0, openvibe-sdk 0.5.0 → 0.9.1; CI runs the pin-drift check (shared test and security workflows at 423fe51) ([`b00d21e`](https://github.com/OpenVibers/OpenVibe.Coupons/commit/b00d21e49de0068a3aeadc73cf66ce0aee3af97c))\n\n## OpenVibe.Deals\n\n[openvibe.deals](https://openvibe.deals) · [repository](https://github.com/OpenVibers/OpenVibe.Deals)\n\n- Pins: openvibe-contracts 0.38.0 → 0.42.0, openvibe-sdk 0.5.0 → 0.9.1; CI runs the pin-drift check (shared test and security workflows at 423fe51) ([`6f83a1a`](https://github.com/OpenVibers/OpenVibe.Deals/commit/6f83a1a2fd27b2d575b7956e01a084a041aafc69))\n\n## OpenVibe.Games\n\n[openvibe.games](https://openvibe.games) · [repository](https://github.com/OpenVibers/OpenVibe.Games)\n\n- games.progress.summary on Network (Contracts user module, WS-B task 9): when a signed-in character leaves, Games folds the session into the person's summary (best total skill level, playtime, last world; achievements never written… ([`091fdd6`](https://github.com/OpenVibers/OpenVibe.Games/commit/091fdd61921a13578d7bcf177701a9b8a4025579))\n\n## OpenVibe.News\n\n[openvibe.news](https://openvibe.news) · [repository](https://github.com/OpenVibers/OpenVibe.News)\n\n- Pins: openvibe-contracts 0.38.0 → 0.42.0, openvibe-sdk 0.5.0 → 0.9.1; CI runs the pin-drift check (shared test and security workflows at 423fe51) ([`6baef52`](https://github.com/OpenVibers/OpenVibe.News/commit/6baef5283e1196027e184d874110ff23c89b64cd))\n\n## OpenVibe.Reviews\n\n[openvibe.reviews](https://openvibe.reviews) · [repository](https://github.com/OpenVibers/OpenVibe.Reviews)\n\n- Pins: openvibe-contracts 0.38.0 → 0.42.0, openvibe-sdk 0.5.0 → 0.9.1; CI runs the pin-drift check (shared test and security workflows at 423fe51) ([`017c430`](https://github.com/OpenVibers/OpenVibe.Reviews/commit/017c430f9b319214bb61b7d08c23fba5a672a8ae))\n\n## OpenVibe.Search\n\n[search.openvibe.network](https://search.openvibe.network) · [repository](https://github.com/OpenVibers/OpenVibe.Search)\n\n- Pins: openvibe-contracts 0.33.0 → 0.42.0; CI runs the pin-drift check (shared test and security workflows at 423fe51) ([`f5b1f97`](https://github.com/OpenVibers/OpenVibe.Search/commit/f5b1f973106919b25a44789806e10ed093b488ef))\n\n## OpenVibe.Sources\n\n[sources.openvibe.network](https://sources.openvibe.network) · [repository](https://github.com/OpenVibers/OpenVibe.Sources)\n\n- Pins: openvibe-contracts 0.33.0 → 0.42.0, openvibe-shared 1.7.0 → 1.12.0; CI runs the pin-drift check (shared test and security workflows at 423fe51) ([`c6aa73a`](https://github.com/OpenVibers/OpenVibe.Sources/commit/c6aa73a19c94d81a98e1176b4bf7662a87757c20))\n\n## OpenVibe.Tips\n\n[openvibe.tips](https://openvibe.tips) · [repository](https://github.com/OpenVibers/OpenVibe.Tips)\n\n- Pins: openvibe-contracts 0.33.0 → 0.42.0, openvibe-sdk 0.5.0 → 0.9.1; CI runs the pin-drift check (shared test and security workflows at 423fe51) ([`39026a0`](https://github.com/OpenVibers/OpenVibe.Tips/commit/39026a0f6ca3c7bb1858d331fef0cfdfafe499d2))\n\n## OpenVibe.Trade\n\n[openvibe.trade](https://openvibe.trade) · [repository](https://github.com/OpenVibers/OpenVibe.Trade)\n\n- Pins: openvibe-contracts 0.38.0 → 0.42.0, openvibe-sdk 0.5.0 → 0.9.1; CI runs the pin-drift check (shared test and security workflows at 423fe51) ([`c2dc255`](https://github.com/OpenVibers/OpenVibe.Trade/commit/c2dc255d4eefd946bf58fb3d7aa836497ae0bdaa))\n\n## OpenVibe.VIP\n\n[openvibe.vip](https://openvibe.vip) · [repository](https://github.com/OpenVibers/OpenVibe.VIP)\n\n- Pins: openvibe-contracts 0.38.0 → 0.42.0, openvibe-sdk 0.5.0 → 0.9.1; CI runs the pin-drift check (shared test and security workflows at 423fe51) ([`0e32f1d`](https://github.com/OpenVibers/OpenVibe.VIP/commit/0e32f1d4d17e191c040f95a4c5b1d9acb863c48b))\n\n---\n\nPatch notes are put together automatically when enough changes have shipped, or when a large feature lands. See every site's own updates page for the live list.","revision":1,"state":"published","visibility":"public","published_at":"2026-09-25T19:30:24.067Z","revised_at":"2026-09-25T19:30:24.066Z","author":{"subject":"usr_01KKT9AC60KM7CRTB3WN1Z8P56","name":"goosely","username":"goosely"},"authorship":{"mode":"imported","workflow":null,"reviewed":false,"disclosure":{"mode":"imported","short":"Imported","long":"Imported from Commit messages from the OpenVibers repositories on GitHub; originally by OpenVibers."}},"tags":["patch-notes","media","community","network","live","tools","ai","chat","events","host","wiki"],"categories":[],"series":{"title":"Patch notes","url":"https://openvibe.blog/@openvibe/series/patch-notes","position":null},"media":[],"citations":[],"indexability":{"indexable":true,"robots":"index, follow","reasons":[]}}