Patch notes: The network changelog and its patch notes
Imported. Imported from Commit messages from the OpenVibers repositories on GitHub; originally by OpenVibers.
What shipped on OpenVibe on 2026-09-24: 79 changes to OpenVibe.Network, OpenVibe.Blog, OpenVibe.Host, OpenVibe.Live, OpenVibe.Games, OpenVibe.Tips and 9 more. Every line below is a commit message from the OpenVibers repositories, linked to the change itself.
Highlights
- OpenVibe.Blog: The network changelog and its patch notes: every OpenVibe site's shipped commits in one feed, published on the blog in batches. The worker reads each service's repository and current release from OpenVibe.Network's registry, takes the… (
32cb1aa)
OpenVibe.Network
- Unknown paths answer 404 (roadmap §2.5, D44): the apex sent the account hub (my.html) with 200 for any path, so openvibe.network/<anything> looked like a page. Every real page keeps its own route; the account hub answers only at its own… (
f87b514) - OpenID Connect discovery at the issuer (roadmap §4.1, §15.4): https://openvibe.network/.well-known/openid-configuration answered with the account page; discovery lived only at /oauth/.well-known/openid-configuration. The document is now… (
abee5dc) - Refresh tokens (roadmap §18.2(2)): oauth_tokens held each refresh token in clear, and presenting a rotated token again only failed. Now only its SHA-256 is stored; every token belongs to the family of the sign-in that issued it (family_id)… (
1cf0191) - Provider secrets from the environment first (roadmap §18.2(12)): the Resend API key and webhook secret, the Discord bot token and OAuth client secret, and the VAPID private key were read only from site_settings in plaintext. Each now has a… (
70050bc) - secrets-out-of-db.js --copy-to-env [--apply]: moves each provider secret the database holds and the env file does not set (an empty VAR= counts as unset) into /etc/openvibe/network.env as VAR=value, after keeping the previous file as… (
11e716d) - Internal-key retirement (register C-50/C-52): GET /internal/url-registry/resolved, GET /internal/coins/stats, POST /internal/resolve-anon, POST /internal/identity/legacy-map and POST /internal/link-account (the routes principal_usage still… (
829dafa) - Principals: openre, media and community hold live.lineage.resolve for audience openvibe.live (roadmap §10.5/§15.10, D20-R1), so OpenRe, Media and Community's Pulse can ask Live's canonical channel/owner resolver (GET|POST… (
80a841c) - openvibe-contracts v0.33.1: tools.tool.read is active (Tools serves GET /api/v1/tools on the gateway and every satellite), so the registry and /status show it as such; tools.tool@1 1.1.0 adds optional keywords and examples. Additive; pins… (
9a59212) - Registry (roadmap W2 D4, §5.1, §5.3): /api/v1/registry/categories and /featured answered 404. categories[/:id] groups every service by what it is, each with its rule, from Network's exposure overlay and site list: site, platform, library… (
9e64f60) - Admin settings: the 'prefer the environment variable' hint shows only for provider secrets, not for the VAPID public key (read environment-first too, but not a secret); the settings row says secret: true|false (
d063df1) - Follow notification links to the follower's channel (openvibe.live/@<username>); it linked to openvibe.network/user/<name>, a page Network never had (a 404 since unknown paths stopped answering the account page) (
43dd0c5) - openvibe-contracts v0.34.1 (Tools platform S7): sandbox apps hold tools.tool.read and tools.tool.run by default (the run API is live); the self-service catalog lists public capabilities only (partner ones like tools.net.probe are… (
1664d04) - SECURITY.md: how to report a vulnerability ([email protected], 7-day reply, scope, supported versions) (
26c0395) - Roadmap baseline regenerated from origin/main (2026-09-24): D20 remaining is the consumers' switch and OpenRe session lineage (Media owner_subject done, grants issued); new Live tables (channel_points_log, opencoin_admin_grants… (
89f0e44) - Community may publish its events (events.event.publish on openvibe.events); openvibe-contracts v0.35.0 (community.* payload contracts) (
1837cb8) - Tools grants: live, chat and community hold tools.tool.run and tools.job.read on openvibe.tools, so their Tools run API calls (kiosk page titles, audio conversion, save-as-paste) run on the service tier, never network probes (
cbe77e1) - Your recent tools on my.openvibe.network (the tools.usage module OpenVibe.Tools keeps, named from the public Tools registry, built with DOM nodes); Tools may index its tools in Search (search.document.write on openvibe.search) (
1de2e22) - Network issues staff capabilities in user tokens (D05, ADR-022): staff members' access tokens (login and OAuth) carry staff_caps from the contracts staff map, and the owner carries is_owner; people who are not staff carry neither, so their… (
dde3374) - AI may publish its ai.run.* events (events.event.publish on openvibe.events) (
cbca807) - Blog may run its AI workflows (ai.run.create and ai.run.read in the blog namespace on openvibe.ai) for Draft with AI (
fba96a0) - Recently shipped across OpenVibe on the home page: openvibe-shared v1.8.0 (served as /shared/shipped.js for every site) renders the network changelog from openvibe.blog, each change linked to its commit and the latest Patch notes post… (
6e794b9) - CORS: every first-party domain the service manifests declare is an allowed origin (exact https origins, never a wildcard). openvibe.blog, openvibe.wiki and openvibe.codes were missing from the hard-coded list, so the shared navbar's… (
90cd58e) - What shipped, network-wide: /api/v1/changelog proxies OpenVibe.Blog's changelog (60 s cache, stale on failure, public CORS) so every site's shared widget reads it from openvibe.network; /updates renders the whole network's log (server-side… (
0b3b2e3) - The OpenVibe Frame: server/chrome is server/frame; /api/frame and /api/frame/hit (the /api/chrome names stay as aliases for openvibe-shared older than 1.11.0); chrome_cache/chrome_hits are renamed frame_cache/frame_hits once on boot, rows… (
7571ba7)
OpenVibe.Blog
- SECURITY.md: how to report a vulnerability ([email protected], 7-day reply, scope, supported versions) (
2c716a2) - openvibe-publishing v0.2.2 (shares the openvibe-shared v1.5.1 copy instead of installing v1.0.0 alongside) (
a994d8a) - An edit that does not send citations keeps them: the /write editor does not resend a post's citations, so every edit made there dropped them from the new revision. Sending a list (even an empty one) still replaces them. lifecycle test (
0784b42) - VIP client from openvibe-sdk/vip (v0.7.0): the copy of openvibe-vip/client is replaced by the SDK's published seam, same API and fail-closed behaviour; server/vip/vip-client.js re-exports it so callers are unchanged (
eae013f) - CI calls the shared test workflow (Track Q): OpenVibe.Shared .github/workflows/test.yml@f5e7e73 (install, node --check over server/ and scripts/, npm test, openvibe-contracts-check) instead of a copy of those steps (
36b6f59) - Draft with AI (W13, proof flow 5): a member who may write on a blog asks OpenVibe.AI's blog.draft_post (openvibe-publishing v0.3.0 ai client, Blog's service token) for a draft from a topic, brief, tone and audience; the answer becomes an… (
4d522ca) - The network changelog and its patch notes: every OpenVibe site's shipped commits in one feed, published on the blog in batches. The worker reads each service's repository and current release from OpenVibe.Network's registry, takes the… (
32cb1aa) - changelog: Network's /api/v1/registry/releases lists services under 'services' (the test stub now answers in that shape) (
58d2e45) - changelog: every site's updates log — commit authors, a page cursor (before), a one-time import of each site's last CHANGELOG_HISTORY commits (never pending, never in a post), the recent patch notes posts and a per-site summary in the… (
dc3f3a1) - The shared update system and one account UI: the home shows what shipped, /updates is the shared log, the footer (now initialised in the browser too) links it; the shared navbar handles sign in/out with logoutUrl ending this site's… (
528f917) - The OpenVibe Frame: openvibe-shared/frame (formerly chrome-ssr) and 1.11.0; openvibe-publishing 0.3.2 (one copy of openvibe-shared) (
e4d201c)
OpenVibe.Host
- SECURITY.md: how to report a vulnerability ([email protected], 7-day reply, scope, supported versions) (
ff1c02e) - Docs: ovhost deploys 20 services and runs the backups and drills (README said no deploy used it); cutover runbook gains the DNS steps (lower TTL a day ahead, record the old records, 30-minute watch, decommission after twice the old TTL)… (
f8ac37d) - Restore drills for AI, Games and Tools pass on the host (2026-09-24): AI's drill spec (AI_ENABLED=0, every provider key and seam blanked, no service secret, events or whisper; configuration counts) is new; Games' and Tools' reviewed specs… (
438b642) - CI calls the shared test workflow (Track Q): OpenVibe.Shared test.yml@e8b0caf (install, node --check, npm test, openvibe-contracts-check; ffmpeg where the tests need it) instead of a copy of those steps (
f7fdbcc) - C-76 retired: Live runs the release layout since 2026-09-24 05:51 UTC; inventory example reads Live's release (repo current, owner root, runAs ubuntu); Live drill row in the release layout (
8b720df) - Metrics collection (Track O): scripts/prometheus-config.js renders a Prometheus scrape config from the host inventory (one loopback job per service port, declared extra processes such as the Tools satellites, node-exporter; metrics:false… (
6ff101e) - Tests follow Live's release layout (C-76): the example inventory's live entry reads /opt/openvibe.live/current as root with runAs ubuntu, and the live drill test's simulated host has the release unit and files under current/ (
22e9f1c) - Alert rules (Track O): deploy/prometheus/openvibe-rules.yml (target down 5 min, 5xx above 5% for 10 min, root disk under 10%, memory under 8%), loaded through rule_files in the rendered config; firing alerts at 127.0.0.1:9090/api/v1/alerts (
25e6fc0) - The shared update system and one account UI, on the OpenVibe Frame (openvibe-shared 1.11.0, openvibe/frame): the home shows what shipped, /updates is the shared log and the footer links it; the shared navbar handles sign in and out… (
d5fb2dc)
OpenVibe.Live
- Crawlable pages for the Content and Moments feeds (D44): /content?page=N and /moments?page=N render page N of the cursor feed in the initial HTML (following N-1 cursors, each page cached, 20 deep), self-canonical, with newer/older… (
d4ccdfb) - VIP first for subscriber perks (W10, proof flow 3): with Billing as the money authority, whether a viewer is subscribed to a channel (channel state, chat and AI perks) is OpenVibe.VIP's entitlement answer through openvibe-sdk/vip (v0.7.0)… (
e08bbec) - CI calls the shared test workflow (Track Q): OpenVibe.Shared test.yml@e8b0caf (install, node --check over server/, scripts/ and public/js/, npm test with the size budgets, openvibe-contracts-check) instead of a copy of those steps (
862bc47) - Unit description matches production (no 'Free' copy) in both the in-place and release units (
9f7f36c) - release.json names the release in the release layout: the service user cannot run git in a root-owned release worktree, so the manifest said 0000000 (open tabs could not tell releases apart); RELEASE_COMMIT, else the <time>-<sha> release… (
f15023a) - Production runs the release layout (C-76 done 2026-09-24 05:51 UTC): deploy from /opt/openvibe.live/current; the old checkout files are stale; release ids come from the directory name; the host inventory runs git for Live as root (
9c5aa64) - Kiosk companion and hardware scripts moved to OpenVibe.Extensions (ADR-023, W18): browser-extension/ and hardware/ keep only redirect READMEs pointing at OpenVibe.Extensions kiosk-companion/ and hardware/ (moved unchanged at 9c5aa64) (
ce6a733) - Restore 'shipped' on the home page, /updates and chat deploy notices: since the release layout (C-76) the release worktree is root-owned, so git refused the service user ('dubious ownership') and all three read nothing; their read-only git… (
654ad1a)
OpenVibe.Games
- SECURITY.md: how to report a vulnerability ([email protected], 7-day reply, scope, supported versions) (
7c4d6bf) - openvibe-contracts v0.34.3 (was v0.8.0) and openvibe-sdk v0.6.0 (was v0.2.2); CI runs openvibe-contracts-check for the server (
4e5bc50) - Release manifest and private metrics (Track R D43, Track O): GET /release.json answers the deployed commit (RELEASE_SHA, else read from .git without a child process), openvibe-sdk/contracts versions and components in the shape every… (
35a06a0) - dist-types for observability/release (tsc --build) (
f4f3f40) - Prometheus text metrics (Track O): GET /metrics (loopback only) answers the snapshot as games_* gauges in Prometheus text when the scraper asks (Accept text/plain or OpenMetrics, or ?format=prometheus); JSON stays the default (
c318513)
OpenVibe.Tips
- SECURITY.md: how to report a vulnerability ([email protected], 7-day reply, scope, supported versions) (
847d22a) - STATUS.json describes production: the running release and pins, what is deployed, the Live import that has run, and what is still owner-blocked (
fb110b9) - CI calls the shared test workflow (Track Q): OpenVibe.Shared .github/workflows/test.yml@f5e7e73 (install, node --check over server/ and scripts/, npm test, openvibe-contracts-check) instead of a copy of those steps (
da7273b) - The shared update system and one account UI, on the OpenVibe Frame (openvibe-shared 1.11.0, openvibe/frame): the home shows what shipped, /updates is the shared log and the footer links it; the shared navbar handles sign in and out… (
f5c0783)
OpenVibe.VIP
- SECURITY.md: how to report a vulnerability ([email protected], 7-day reply, scope, supported versions) (
a0a8f75) - STATUS.json describes production: the running release and pins, what is deployed, the Live import that has run, and what is still owner-blocked (
aa2fba9) - CI calls the shared test workflow (Track Q): OpenVibe.Shared .github/workflows/test.yml@f5e7e73 (install, node --check over server/ and scripts/, npm test, openvibe-contracts-check) instead of a copy of those steps (
ee7abc6) - The shared update system and one account UI, on the OpenVibe Frame (openvibe-shared 1.11.0, openvibe/frame): the home shows what shipped, /updates is the shared log and the footer links it; the shared navbar handles sign in and out… (
dcb7546)
OpenVibe.Codes
- CI calls the shared test workflow (Track Q): OpenVibe.Shared test.yml@e8b0caf (install, node --check, npm test, openvibe-contracts-check; ffmpeg where the tests need it) instead of a copy of those steps (
e82321b) - The shared update system and one account UI, on the OpenVibe Frame (openvibe-shared 1.11.0, openvibe/frame): the home shows what shipped, /updates is the shared log and the footer links it; the shared navbar handles sign in and out… (
df5e0a4)
OpenVibe.Coupons
- CI calls the shared test workflow (Track Q): OpenVibe.Shared .github/workflows/test.yml@f5e7e73 (install, node --check over server/ and scripts/, npm test, openvibe-contracts-check) instead of a copy of those steps (
da3e594) - The shared update system and one account UI, on the OpenVibe Frame (openvibe-shared 1.11.0, openvibe/frame): the home shows what shipped, /updates is the shared log and the footer links it; the shared navbar handles sign in and out… (
9308083)
OpenVibe.Deals
- CI calls the shared test workflow (Track Q): OpenVibe.Shared .github/workflows/test.yml@f5e7e73 (install, node --check over server/ and scripts/, npm test, openvibe-contracts-check) instead of a copy of those steps (
e50a4d0) - The shared update system and one account UI, on the OpenVibe Frame (openvibe-shared 1.11.0, openvibe/frame): the home shows what shipped, /updates is the shared log and the footer links it; the shared navbar handles sign in and out… (
c2ad40a)
OpenVibe.News
- CI calls the shared test workflow (Track Q): OpenVibe.Shared .github/workflows/test.yml@f5e7e73 (install, node --check over server/ and scripts/, npm test, openvibe-contracts-check) instead of a copy of those steps (
a108ad3) - The shared update system and one account UI, on the OpenVibe Frame (openvibe-shared 1.11.0, openvibe/frame): the home shows what shipped, /updates is the shared log and the footer links it; the shared navbar handles sign in and out… (
b3e752b)
OpenVibe.Trade
- CI calls the shared test workflow (Track Q): OpenVibe.Shared .github/workflows/test.yml@f5e7e73 (install, node --check over server/ and scripts/, npm test, openvibe-contracts-check) instead of a copy of those steps (
ff9afd0) - The shared update system and one account UI, on the OpenVibe Frame (openvibe-shared 1.11.0, openvibe/frame): the home shows what shipped, /updates is the shared log and the footer links it; the shared navbar handles sign in and out… (
62e21fc)
OpenVibe.Wiki
- The shared update system and one account UI: home shows what shipped (openvibe-shared chrome-ssr shipped()), /updates is the shared log, the footer links it; the shared navbar handles sign in/out (logoutUrl ends this site's session) and… (
fdcea62) - The OpenVibe Frame: openvibe-shared/frame (formerly chrome-ssr) and 1.11.0; openvibe-publishing 0.3.2 (one copy of openvibe-shared) (
1f54de7)
OpenRe.Stream
- The shared update system and one account UI, on the OpenVibe Frame (openvibe-shared 1.11.0, openvibe/frame): the home shows what shipped, /updates is the shared log and the footer links it; the shared navbar handles sign in and out… (
ea87a94)
OpenVibe.Reviews
- The shared update system and one account UI, on the OpenVibe Frame (openvibe-shared 1.11.0, openvibe/frame): the home shows what shipped, /updates is the shared log and the footer links it; the shared navbar handles sign in and out… (
54c4d71)
Patch notes are put together automatically when enough changes have shipped, or when a large feature lands. See every site's own updates page for the live list.
Comments
Comments could not be loaded from OpenVibe.Community right now. Reload later.