# Notra Source index: https://www.usenotra.com/llms.txt ## Home # Notra Get recommended by AI engines. ## Your next customer is asking ChatGPT, Claude, Perplexity, Gemini, Grok or Kimi. Notra asks ChatGPT, Claude, Gemini and Perplexity the questions your buyers ask. You see whether you come up, who comes up instead, and what to write about it. Notra asks ChatGPT, Claude, Gemini and Perplexity the questions your buyers ask, tracks which AI agents read your site, and writes the content for the questions you lose. Primary CTA: [Start for free](https://app.usenotra.com/signup) ## Explore in Markdown - [Features](https://www.usenotra.com/features.md?ntr=WlbI_nEwqKdfSUkn) - [Pricing](https://www.usenotra.com/pricing.md?ntr=WlbI_nEwqKdfSUkn) - [Blog](https://www.usenotra.com/blog.md?ntr=WlbI_nEwqKdfSUkn) - [Changelog](https://www.usenotra.com/changelog.md?ntr=WlbI_nEwqKdfSUkn) ## Social Proof Used by teams that ship every week - [inth](https://inth.com?utm_source=notra) - [Databuddy](https://databuddy.cc?utm_source=notra) - [Stack Auth](https://stack-auth.com?utm_source=notra) ## Every number the dashboard shows you. These are the tables in the product, filled with sample data. No vanity score. Mentions, positions, share of voice, and the traffic behind them. ### Mention rate by engine Each prompt goes to each model you turn on, with web search and without. You get who mentioned you, where in the list, and whether that moved since the last scan. ### Share of voice Who gets recommended when you don't. Add direct and indirect competitors, plus the misspellings people use for them, and see the split per prompt, language and engine. ### AI traffic, attributed Hits from 66 known AI agents, sorted by what they were doing: training a model, building an index, reading a page to answer someone or a person clicking through. We don't count a fetch as a citation. ### Content Gaps to Write The questions where engines answer and you are not in the answer, ranked by how winnable they look. Write plans a guide, listicle or comparison and the draft lands in Content. ## See exactly what the engine said. Every scan keeps the whole answer. Open a prompt and read what each engine wrote, where you show up, and which pages it pulled to get there. ## Pricing Simple pricing that scales with what you track. Every plan comes with prompt tracking, traffic attribution and the writer. The difference is how many answers you track a month. Cancel whenever. See the dedicated pricing page: [Pricing](https://www.usenotra.com/pricing.md?ntr=WlbI_nEwqKdfSUkn) ## Common questions ### What is GEO? Generative Engine Optimization. Getting your brand into the answer when someone asks ChatGPT, Claude, Gemini or Perplexity what to buy. Notra measures where you stand and helps you move it. ### Which engines and models do you scan? ChatGPT, Claude, Gemini and Perplexity with web search, plus models from OpenAI, Anthropic, Google, Moonshot, Z.AI, DeepSeek, Mistral, Meta and Grok without search. You pick which ones run, and the model list refreshes as new releases ship. ### What counts as an AI answer tracked? One prompt asked to one engine in one language on one scan. Ten prompts across five engines in two languages, scanned every 48 hours, is about 1,500 answers a month. ### How does traffic tracking work? Do I need a script tag? No script tag. You add @usenotra/geo as a proxy or middleware in your Next.js, Nuxt or Netlify site. It posts a small request envelope to Notra, we do the matching on our side, and anything human is dropped before it is stored. ### Is a crawler fetch the same as a citation? No. Cited in answer means an assistant fetched the page while it was answering someone. Training crawlers and indexers get their own labels, and a Referral is a real person clicking through from an AI answer. We keep those apart on purpose. ### Do my prompts and answers get retained by the model providers? It is an add-on: +20% on Starter, Growth and Scale, included on Enterprise. With ZDR enforced, scans only go to models whose provider offers zero data retention. Not every model has a ZDR host, so those stay off unless you approve them for the project. ### Can Notra write the content too? Yes. Pick a gap, choose guide, listicle or comparison, and Write plans a brief from your brand identity, your sitemap and the competitors you track. You approve the brief, the draft opens in Content. ## Call to Action Find out what agents say about you Add a few prompts, run a scan, read the answers. Free to start. [Start for free](https://app.usenotra.com/signup) ## Features # Features Notra asks ChatGPT, Claude, Gemini and Perplexity the questions your buyers ask, tracks which AI agents read your site, and writes the content for the questions you lose. Every answer is kept, so you can read what each engine actually said. A crawler fetch and a citation are not the same thing, and Notra keeps them apart. ## What Notra tracks ### Prompts The buyer questions you want to show up for, in the words a buyer would use. Write them yourself, let Notra pull them from your website or import a CSV. Connect Google Search Console and Notra turns your real search queries into prompt suggestions every week. ### Engines and models ChatGPT, Claude, Gemini and Perplexity with web search. Models from OpenAI, Anthropic, Google, Moonshot, Z.AI, DeepSeek, Mistral, Meta and Grok without search. You pick which ones run and the list refreshes as new releases ship. ### Languages Run the same prompts in up to five languages. Each language gets its own mention rate, so you can see where you win in English and lose in German. ### Conversations Multi-turn chats of up to five turns, replayed against every engine with web search. The follow-up question is usually where the recommendation happens. ### Scans Scans run daily by default, or every 48 hours, 3 days, week, 2 weeks or 30 days. Every answer is stored in full with the searches the engine ran and the pages it cited. Zero data retention is available as an add-on for teams that need it. ## What the dashboard shows ### Mention rate by engine Each prompt goes to each model you turn on, with web search and without. You get who mentioned you, where in the list, and whether that moved since the last scan. ### Share of voice Who gets recommended when you don't. Add direct and indirect competitors, plus the misspellings people use for them, and see the split per prompt, language and engine. ### Answers Every scan keeps the whole answer. Open a prompt and read what each engine wrote, where you show up, and which pages it pulled to get there. ### Competitors Track up to 25 competitors with their domains and the misspellings people use for them. Open any of them to see mentions over time and the exact prompts and engines where they appear instead of you. ### Agent journeys Follow a single AI agent across your site: which pages it fetched, in what order and whether it asked for markdown. ## AI traffic, attributed Hits from 66 known AI agents, sorted by what they were doing: training a model, building an index, reading a page to answer someone or a person clicking through. We don't count a fetch as a citation. No script tag. You add the @usenotra/geo package as a proxy or middleware in your Next.js, Nuxt or Netlify site. It sends a small request envelope to Notra, matching happens on our side and anything human is dropped before it is stored. Every hit is labelled by purpose: model training, search index, cited in answer (an assistant read the page while answering someone) or referral (a person clicked through from an AI answer). ## Turning gaps into content ### Content Gaps to Write The questions where engines answer and you are not in the answer, ranked by how winnable they look. Write plans a guide, listicle or comparison and the draft lands in Content. ### Write Pick a gap and choose guide, listicle or comparison. Write plans a brief from your brand identity, your sitemap and the competitors you track. You approve the brief and the draft opens in Content, with real internal links and a FAQ section. ### Agent readiness A score out of 100 for how well AI agents can discover, understand and use your website, with a must-do and should-do checklist and copyable fix prompts for your coding agent. ### Agent feedback A public URL where AI agents and MCP tools can leave feedback about your product, no token needed. Notra classifies it and files it in an inbox. ## For developers - REST API with OpenAPI at https://api.usenotra.com/openapi.json, covering projects, prompts, scans, visibility, gaps, briefs, agent readiness and traffic. - OAuth 2.1 through oauth.usenotra.com or scoped API keys. - MCP server at https://mcp.usenotra.com/mcp. - @usenotra/geo on npm for traffic capture, agent classification and link tagging. - Docs at https://docs.usenotra.com. ## Studio The content automation that Notra started with is still here. Connect GitHub, Linear and Slack, and Notra drafts changelogs, launch posts and social updates in your brand voice, on a schedule or when something ships. ## Next Steps - [Pricing](https://www.usenotra.com/pricing.md?ntr=WlbI_nEwqKdfSUkn) - [Blog](https://www.usenotra.com/blog.md?ntr=WlbI_nEwqKdfSUkn) - [Changelog](https://www.usenotra.com/changelog.md?ntr=WlbI_nEwqKdfSUkn) - [Start for free](https://app.usenotra.com/signup) ## Pricing # Pricing Choose the right Notra plan for your team. Upgrade when you need more images, posts, or projects. ## Starter For founders shipping their first content engine. Price: $100/month CTA: [Get started](https://app.usenotra.com/signup) - 2,000 AI answers tracked / mo - 8 image generations / mo - 10 long-form posts / mo - Unlimited social posts - 1 project - 100 references (then $0.05 per reference / mo) - Standard support + Slack - ZDR available (+20%) ## Growth For teams publishing across channels every week. Price: $250/month CTA: [Get started](https://app.usenotra.com/signup) - 6,000 AI answers tracked / mo - 20 image generations / mo - 25 long-form posts / mo - Unlimited social posts - 3 projects - 500 references (then $0.04 per reference / mo) - Standard support + Slack - ZDR available (+20%) ## Scale For content teams running multiple brands at volume. Price: $550/month CTA: [Get started](https://app.usenotra.com/signup) - 12,000 AI answers tracked / mo - 45 image generations / mo - 50 long-form posts / mo - Unlimited social posts - 10 projects - 1,000 references (then $0.03 per reference / mo) - Priority support - ZDR available (+20%) ## Enterprise For large orgs with custom scale and compliance needs. Price: Contact us CTA: [Contact us](mailto:hello@usenotra.com) - Unlimited AI answers tracked - Unlimited image generations - Unlimited long-form posts - Unlimited social posts - Unlimited projects - Unlimited references - Dedicated support - ZDR included ## Feature Comparison ## AI visibility tracking - AI answers tracked / mo: Starter 2,000, Growth 6,000, Scale 12,000, Enterprise Custom - Prompts tracked: Starter Unlimited, Growth Unlimited, Scale Unlimited, Enterprise Unlimited - Models tracked: Starter All major, Growth All major, Scale All major, Enterprise All major ## Content - Image generations: Starter 8 / mo, Growth 20 / mo, Scale 45 / mo, Enterprise Unlimited - Long-form posts: Starter 10 / mo, Growth 25 / mo, Scale 50 / mo, Enterprise Unlimited - Social posts: Starter Unlimited, Growth Unlimited, Scale Unlimited, Enterprise Unlimited ## Projects - Projects: Starter 1, Growth 3, Scale 10, Enterprise Unlimited - References: Starter 100, Growth 500, Scale 1,000, Enterprise Unlimited - Reference overage: Starter $0.05 / ref, Growth $0.04 / ref, Scale $0.03 / ref, Enterprise Custom ## Security - Zero data retention: Starter +20%, Growth +20%, Scale +20%, Enterprise Included ## Data - Log retention: Starter 30 days, Growth 90 days, Scale 1 year, Enterprise Custom ## Support - Support: Starter Standard + Slack, Growth Standard + Slack, Scale Priority, Enterprise Dedicated ## Blog ### You ship constantly but never announce it — here's how to fix that URL: https://www.usenotra.com/blog/you-ship-constantly-but-never-announce-it-heres-how-to-fix-that.md Date: 2026-06-03T00:00:00.000Z You know the feeling. Your team closed 12 pull requests this week. A new feature went live. A painful bug that users kept hitting? Fixed. The API is faster. The onboarding flow is smoother. And yet... nothing. No tweet. No changelog entry. No LinkedIn post. The work just disappears into production. If this sounds familiar, you're not alone. A 2026 PersonaBox analysis found that shipping velocity has outpaced communication capacity at most software companies, with GitHub reporting a 29% year-over-year increase in merged PRs. Teams are shipping more than ever. They're just not telling anyone. So why does the announcement keep getting skipped? ## The real reason features go unannounced It's rarely laziness. It's friction. When a feature ships, the engineer who built it moves immediately to the next ticket. The product manager is already in sprint planning. The founder is fielding support emails. Nobody has a natural moment to stop and write a post about what just shipped — let alone turn it into something customers will actually care about. There's also a translation problem. Engineers know exactly what changed in the code. Customers need to know what changed in *their experience*. Bridging that gap takes time and a specific kind of writing skill that most engineering-led teams don't have sitting around. The result? A company that's legitimately improving its product every single week, but looks stagnant to the outside world. That perception gap is expensive. A Bain & Company study found that a 5% increase in customer retention can boost profits by 25% to 95%. Regular product announcements directly support retention — they reassure existing users that the product is alive and improving, and they give churned users a reason to come back. ## What actually helps ### Connect your announcement workflow to where the work already lives The highest-friction part of writing an announcement is gathering context. What shipped? Why does it matter? What does the user actually see now that's different? If you can answer those questions without asking anyone, you remove the biggest blocker. That means connecting your announcement process to GitHub, Linear, or Slack — wherever your team documents what they're building. Tools like [Notra](https://usenotra.com/) do exactly this. Notra monitors your GitHub PRs and Linear issues, identifies what's worth announcing, and generates a draft in your brand voice automatically. The [best automated changelog tools in 2026](https://usenotra.com/blog/best-automated-changelog-tools-in-2026) all share this philosophy: reduce the manual work of collecting context so the writing part becomes nearly instant.
Screenshot of https://www.usenotra.com
Screenshot of <a href="https://www.usenotra.com/">usenotra.com</a>
### Make "done" include a draft announcement One of the most practical changes a team can make is redefining what "done" means for a feature. Done isn't when the PR merges. Done is when there's a publishable draft explaining what shipped. You don't need a dedicated writer for this. You need a process — and ideally, automation that produces a first draft you can edit in five minutes. Once your team [automates marketing content from product updates](https://usenotra.com/blog/how-to-automate-your-marketing-content), announcements stop being a separate project and become a natural output of shipping. ### Train your tool on your actual brand voice Generic AI output is easy to spot, and your audience can tell. The tweets sound like they came from a press release. The changelog reads like a commit message. Neither actually communicates value. The fix is voice training. Notra, for example, lets you upload past tweets, blog posts, and launch content so the generated drafts match how your team actually writes — not some average of the internet. This matters more than most teams expect. When announcements sound like *you*, they get shared. When they sound robotic, they get ignored. This is also why [engineers are genuinely valuable for marketing](https://usenotra.com/blog/engineers-are-great-for-marketing) — their authentic, specific language about what they built is often more compelling than polished PR copy. ### Distribute across multiple channels without extra work A changelog entry is good. A changelog entry *plus* a tweet *plus* a LinkedIn post is better. Most teams skip the multi-channel distribution because it means rewriting the same update three times in three different formats. Automation solves this too. [Automating social media posts from GitHub commits](https://usenotra.com/blog/how-to-automate-social-media-posts-from-github-commits) means a single merged PR can trigger a ready-to-publish post for X and LinkedIn, a changelog entry, and a launch announcement draft — all from the same source. You review and publish. You don't start from scratch. ## The compounding effect of consistent visibility Here's the part that's easy to underestimate: announcements compound. One tweet about a new feature might get 200 impressions. But a team that posts every week, consistently, builds an audience that expects updates. Customers start paying attention. Prospects see momentum. Investors see execution. The product looks like it's being actively developed because — well, it is. The teams that stay visible aren't necessarily shipping more than you. They've just built a lightweight system that makes communication automatic. If your team ships frequently and communicates rarely, the gap between those two things is fixable. It's not a headcount problem. It's a workflow problem — and [AI tools for developer marketing](https://usenotra.com/blog/best-ai-tools-for-developer-marketing-in-2026) have made it easier than ever to close that gap without adding manual work to anyone's plate. Start small: connect one source (GitHub works well), generate one week's worth of updates, and see what comes out. You might be surprised how much your team has been shipping without anyone knowing about it. ### How Notra uses Upstash to run an AI content pipeline URL: https://www.usenotra.com/blog/how-notra-uses-upstash-to-run-an-ai-content-pipeline.md Date: 2026-05-28T00:00:00.000Z **TL;DR:** Notra is an AI tool that turns engineering activity (pushing into a GitHub repo, updating a linear ticket) into draft blog posts, changelogs, and social media updates. Notra deploys to Vercel, but some of the most important logic (scraping a site, calling an LLM, streaming tokens back to the browser) lasts longer than a single Vercel function could run. So Notra runs all of it on Upstash: Workflow for the long-running jobs, QStash for cron, Redis for shared state, Ratelimit for protection, and Realtime for streaming. ## What is Notra? [Notra](https://github.com/usenotra/notra) is one of the open-source projects we sponsor at [Upstash](https://upstash.com/). It connects to GitHub, Linear, and Slack, looks for activity, and uses AI to draft changelogs, blog posts, and social media posts. The drafts are then put in a dashboard for review. The pipeline has four stages: ingest activity, analyze context, generate a draft, and apply a brand voice. None of these are quick HTTP requests. For example, scraping a marketing site, calling an LLM with a week of GitHub data, and generating several drafts can easily take a few minutes per job. Upstash Workflow is built for exactly this: slow, long-running jobs that keep their state and don't time out on Vercel.
Workflow: Notice GitHub activity, analyze context, write draft, apply brand voice.
Workflow: Notice GitHub activity, analyze context, write draft, apply brand voice.
## Upstash Workflow: no more function timeouts The [brand analysis workflow](https://github.com/usenotra/notra/blob/main/apps/dashboard/src/app/api/workflows/brand-analysis/route.ts) is a good example. It runs in three steps: 1. Scrape the user's website with Firecrawl 2. Call Claude Haiku to extract brand info from the scraped content 3. Write the result to Postgres Each step is wrapped in a `context.run` call, so [Upstash Workflow](https://upstash.com/docs/workflow/getstarted) saves the result of that step before moving on to the next one. If the AI extraction times out at any point, the workflow automatically restarts and skips any steps that already finished. ```typescript export const { POST } = serve(async (context) => { const { organizationId, url } = context.requestPayload; const scrape = await context.run("scrape-website", () => scrapeWebsite(url)); const brand = await context.run("extract-brand-info", () => extractBrandInfo({ content: scrape.content }) ); await context.run("save-to-database", () => saveBrandSettings(organizationId, brand) ); }); ``` The same pattern as above also handles the rest of Notra's long-running work. Scheduled content runs have a dozen-plus steps for fetching integrations, reserving credits, calling the model, and sending notifications. Any of them can fail and retry without losing model output. ## QStash: per-user cron schedules Vercel Cron is one global schedule. Notra needs a schedule per user though, e.g. "every Monday at 9am", or "daily at midnight for user X". QStash schedules are created at runtime, so the dashboard just calls `client.schedules.create()` whenever a user saves a new content trigger. ```typescript import { Client } from "@upstash/qstash"; const client = new Client({ token: process.env.QSTASH_TOKEN! }); await client.schedules.create({ destination: `${appUrl}/api/workflows/schedule`, cron: "0 9 * * 1", // every monday 9am body: JSON.stringify({ triggerId }), }); ``` When the cron fires, [Upstash QStash](https://upstash.com/docs/qstash/overall/getstarted) POSTs to the schedule workflow with the trigger ID in the body. ## Upstash Redis: shared state for serverless Serverless functions don't share memory, so Notra uses Redis for everything that has to be visible across requests. For example job progress for the dashboard's progress bars, a short-lived cache of resolved GitHub and Linear integrations, and the chat's stream metadata. One really cool pattern is cancelling a running chat. The chat workflow runs inside Upstash Workflow, but the LLM call itself runs inside a single Node process with an `AbortController`. There's no easy way for a separate "stop" request to reach into that process and abort it, so the dashboard writes a flag into Redis and the workflow polls for it: ```typescript import { Redis } from "@upstash/redis"; const redis = Redis.fromEnv(); const abortKey = `chat:abort:${orgId}:${chatId}:${streamId}`; // dashboard's stop endpoint: await redis.set(abortKey, "1", { ex: 300 }); // Inside the workflow, polling every 500ms: setInterval(async () => { if ((await redis.get(abortKey)) === "1") abortController.abort(); }, 500); ``` The flag expires after 5 minutes, the workflow clears the active stream when it finishes, and the user sees the response stop within half a second. Just like that we can cancel a running stream from another process. ## Upstash Ratelimit: cheap protection per endpoint LLM calls can be (really) expensive. Notra wraps every expensive endpoint in `@upstash/ratelimit` with a sliding window. Different endpoints get different limits because they have different costs: brand analysis starts a paid Firecrawl crawl plus a Claude call, so it's limited to 2 per 10 minutes; a post update only hits Postgres, so it gets 60 allowed requests per minute. ```typescript import { Ratelimit } from "@upstash/ratelimit"; import { Redis } from "@upstash/redis"; const postGeneration = new Ratelimit({ redis: Redis.fromEnv(), limiter: Ratelimit.slidingWindow(10, "1 m"), prefix: "ratelimit:post-generation" }); const { success } = await postGeneration.limit(userId); if (!success) return new Response("Rate limited", { status: 429 }); ``` ## Upstash Realtime: streaming AI to the browser The chat needs to stream LLM tokens to the browser as they are generated. Notra uses Upstash Realtime instead of building a custom SSE layer. The chat workflow opens a channel per message, batches output chunks, and emits them; the browser subscribes through an authenticated Next.js route. ```typescript import { Realtime } from "@upstash/realtime"; import { Redis } from "@upstash/redis"; const realtime = new Realtime({ redis: Redis.fromEnv(), schema: { ai: { chunk: z.any() as z.ZodType } }, history: { maxLength: 1000, expireAfterSecs: 60 * 60 }, }); const channel = realtime.channel(`chat:${orgId}:${chatId}:${messageId}`); await channel.emit("ai.chunk", chunk); ``` Upstash Realtime also keeps the last 1,000 chunks for an hour, so if the user's network drops mid-stream the dashboard can reconnect and just replay the previous output. ## Why this stack works for serverless AI Every problem with running AI on serverless (function timeouts, per-tenant cron, shared state between requests, mid-stream cancellation, streaming output) has a small, obvious answer in this stack. For an AI product on Vercel, just these things already cover most of the infrastructure work. Thanks for reading! ### AI chat is open to everyone, with images, models, and a public API URL: https://www.usenotra.com/blog/ai-chat-is-open-to-everyone-with-images-models-and-a-public-api.md Date: 2026-05-05T23:54:42.367Z Notra's AI chat used to live behind a feature flag. Over the last two weeks, we tore that flag out, gave the chat a real backend, taught it to handle images, added a searchable model picker, and exposed the whole thing as a public API you can call from Discord, Slack, or anywhere else. If you have logged in recently, the chat in the sidebar is no longer a preview. It is the product. ## Open to everyone, and a lot less janky The first thing that changed is the feature flag is gone. The Databuddy `ai-chat-experiment` gate came out of the sidebar, the chat page, the content composer, and every chat workflow route ([4e31cafb](https://github.com/usenotra/notra/commit/4e31cafb46a5d9bc7d4287501f7d6ee5a301cb2a)). If you have a workspace, you have chat. We also spent a chunk of time on the small things that quietly make a chat feel cheap when they break: - The input now focuses the moment you start typing, instead of swallowing your first keystroke ([#308](https://github.com/usenotra/notra/pull/308)). - The command palette routes between conversations more predictably ([#307](https://github.com/usenotra/notra/pull/307)). - Switching chats and clicking "New chat" no longer pollutes the back button. If you are already on a chat route, navigation uses `replace`, so the back button takes you back to the dashboard instead of walking through every chat you opened ([#314](https://github.com/usenotra/notra/issues/314)). - The first-message URL sync no longer flashes a skeleton, attachments survive when you retry or edit a message, and long URLs in the input now wrap instead of blowing out the layout. There is also a new model picker. The plain dropdown is now a `Popover` plus `Command` combobox so you can search, and we added Kimi K2.6 and GPT-5.5 to the lineup with proper icons. ## Real persistence, real attachments Chat sessions used to live in Redis. That was fine when it was an experiment. It is not fine when people have actual conversations they want to keep. Chats now persist in Postgres in a `chat_sessions` table with a JSONB messages column, soft deletes via `deleted_at`, and indexes on `(organization_id)` and `(organization_id, deleted_at)`. The upsert is scoped to `deleted_at IS NULL` and uses `RETURNING`, so a delete that lands between a `SELECT` and `UPDATE` no longer writes to a tombstoned chat. Redis stays in the loop, but only for the ephemeral stuff: stream IDs, abort flags, last-stopped markers. On top of that, chat now accepts media. You can drag a file into the composer or paste an image straight from your clipboard ([#284](https://github.com/usenotra/notra/pull/284)). Images render at their natural aspect, not cropped into a forced thumbnail. Attachments are scoped per organization and stored under `organization/{orgId}/chat/` in R2, and the per-user auto-delete retention setting we shipped earlier is gone. Access control runs through the same org-membership check the rest of the dashboard uses, so an injected `activeOrganizationId` cannot reach into another workspace's files. ## A public Chats API, and Discord and Slack out of the box The bigger shift is that chat is no longer a dashboard-only thing. We extracted the chat backend out of `apps/dashboard` into `@notra/ai/chat` so any app can run it ([#318](https://github.com/usenotra/notra/pull/318)), then built a public API on top of it ([#319](https://github.com/usenotra/notra/pull/319)): ```http GET /v1/chats GET /v1/chats/{chatId} POST /v1/chats POST /v1/chats/{chatId} ``` `POST /v1/chats` always returns a streaming response now, instead of a 202 with a stream ID that only the dashboard could subscribe to. The minted chat ID comes back in the `X-Chat-Id` header and in the start chunk's `messageMetadata.chatId`, so external clients can resume the conversation cleanly. The piece we are most curious to see people use is `externalChannelId` ([#320](https://github.com/usenotra/notra/pull/320)). When you start a chat, you can tag it with a `{ source: "discord" | "slack" | "dashboard", id?: string }` tuple. Send another message with the same tuple and you land in the same chat session, atomically claimed via `INSERT ... ON CONFLICT DO NOTHING`: ```ts await fetch("https://api.usenotra.com/v1/chats", { method: "POST", headers: { Authorization: `Bearer ${apiKey}` }, body: JSON.stringify({ messages: [{ role: "user", content: "draft a changelog for last week" }], externalChannelId: { source: "discord", id: thread.id }, }), }); ``` A partial unique index on `(organization_id, external_channel_source, external_channel_id)` keeps the tuple from colliding across sources or workspaces, scoped to live rows. While we were in there, we also closed an authorization gap in `/api/realtime`: the middleware used to check that you had a session and ignore the channel array, which meant any authenticated user could subscribe to another tenant's `chat:::` stream. The middleware now enforces the exact channel shape, rejects wildcards, and verifies organization membership on every channel ([#325](https://github.com/usenotra/notra/pull/325)). ## What this unlocks The point of all this plumbing is that chat should feel like the same product whether you are in the dashboard, replying to a Discord thread, or wiring it into your own tool. The dashboard just happens to be the first client. We are working on first-party Discord and Slack adapters next, plus automatic model routing so you do not have to think about the picker at all. If you build something on top of `/v1/chats`, we want to hear about it. ### Best Automated Changelog Tools in 2026: A Developer's Guide URL: https://www.usenotra.com/blog/best-automated-changelog-tools-in-2026.md Date: 2026-05-02T00:00:00.000Z The best automated changelog tools in 2026 are **Notra** (connects to GitHub and generates changelogs, blog posts, and social content from commits), **release-please** (Google's open-source tool for conventional commit-based changelogs and releases), **git-cliff** (highly customizable open-source changelog generator), **Release Drafter** (GitHub Action for PR label-based release notes), **AutoChangelog** (AI-powered changelog generation), **GitSaga** (AI changelog and release notes), and **Changesets** (monorepo versioning and changelog tool). Each serves different needs: Notra is the only tool that extends changelog data into marketing content, release-please and git-cliff excel at pure changelog generation for free, Release Drafter works best for label-driven workflows, and Changesets shines in monorepo environments. ## **Why Automate Your Changelog?** Manual changelog maintenance is tedious and error-prone. Developers forget to document changes, product managers spend hours reconstructing what shipped, and marketing teams struggle to turn technical updates into customer-facing content. Automated changelog tools solve this by extracting information directly from your version control system—commit messages, PR descriptions, labels, and metadata—and formatting it into readable release notes. The best tools go further, offering customization, multi-format output, and integration with your existing workflow. ## **Notra: Changelog + Content Generation** **What it does:** Notra connects to your GitHub repository and automatically generates three types of content from your commits and pull requests: technical changelogs, blog-ready posts, and social media updates. It's designed for teams that want their development work to feed both internal documentation and external marketing. **Best for:** SaaS teams, product-led companies, and devrel professionals who need to turn shipped features into customer-facing content without manual rewriting. **Pricing:** Basic plan at $20/month, Pro at $50/month. Not open-source. **Setup complexity:** Low. Connect your GitHub account, select repositories, and Notra starts generating content. No configuration files or commit message conventions required (though it works better with good PR descriptions). **Output quality:** Notra uses AI to transform technical commits into human-readable narratives. The changelog is developer-friendly, while blog posts and social updates are written for end users. Quality depends on the richness of your PR descriptions—garbage in, garbage out still applies. **Limitations:** Currently GitHub-only (Linear and Slack integrations coming soon). Requires a subscription. If you only need a [CHANGELOG.md](http://CHANGELOG.md) file and nothing else, this is overkill. **Key differentiator:** Notra is the only tool in this list that treats your changelog as source material for multi-format content. Every other tool stops at generating the changelog itself. If your workflow includes writing blog posts about releases or announcing features on social media, Notra eliminates duplicate work. ## **release-please: Google's Conventional Commit Automation** **What it does:** release-please is an open-source tool from Google that automates [CHANGELOG.md](http://CHANGELOG.md) generation and GitHub release creation based on conventional commit messages. It also handles version bumping according to semantic versioning rules. **Best for:** Teams already using conventional commits, open-source projects, and organizations that want a zero-cost, battle-tested solution. **Pricing:** Free and open-source. **Setup complexity:** Medium. Requires adopting conventional commit format (`feat:`, `fix:`, `chore:`, etc.) and configuring a GitHub Action or CLI workflow. Initial setup takes 30-60 minutes, but it's set-and-forget afterward. **Output quality:** Excellent for technical changelogs. Output is clean, categorized by commit type, and includes links to commits and PRs. Not designed for non-technical audiences—this is a developer-to-developer changelog. **Limitations:** Strict dependency on conventional commits. If your team doesn't follow the format, the tool can't categorize changes properly. No content generation beyond the changelog. No support for platforms other than GitHub. **Why choose it:** If you want a free, reliable changelog generator and you're willing to enforce commit message discipline, release-please is hard to beat. It's used by major open-source projects and backed by Google's engineering team. ## **git-cliff: Highly Customizable Open-Source Generator** **What it does:** git-cliff is a command-line changelog generator written in Rust. It parses your git history and generates changelogs based on a configuration file that you fully control. You can customize grouping, filtering, formatting, and output templates. **Best for:** Teams that need fine-grained control over changelog format, projects with non-standard commit conventions, and developers who prefer config-driven tools. **Pricing:** Free and open-source. **Setup complexity:** Medium to high. The default configuration works out of the box, but the real power comes from customization. You'll need to write or adapt a `cliff.toml` config file to match your workflow. Documentation is thorough but requires time investment. **Output quality:** As good as your configuration. git-cliff can produce anything from simple bullet lists to complex, multi-section changelogs with custom Markdown formatting. It supports regex-based commit parsing, so you're not locked into conventional commits. **Limitations:** CLI-only, no built-in GitHub integration (though you can use it in GitHub Actions). Requires more upfront configuration than other tools. Not beginner-friendly. **Why choose it:** If you have specific changelog requirements that other tools don't support—custom grouping logic, non-standard commit formats, or unique output templates—git-cliff gives you the flexibility to build exactly what you need. ## **Release Drafter: GitHub Action for PR-Based Release Notes** **What it does:** Release Drafter is a GitHub Action that automatically drafts release notes based on pull request labels. When you merge PRs labeled `feature`, `bug`, `documentation`, etc., Release Drafter groups them into a draft release. **Best for:** Teams that use PR labels consistently, projects that prefer label-based categorization over commit message parsing. **Pricing:** Free and open-source. **Setup complexity:** Low. Add the GitHub Action to your repository, configure label mappings in a YAML file, and it starts working on the next merged PR. Setup takes 15-30 minutes. **Output quality:** Clean and organized, grouped by label category. Quality depends on how well your team labels PRs. The tool doesn't parse commit messages, so unlabeled PRs may fall into a generic "Other" category. **Limitations:** GitHub-only. Requires consistent PR labeling discipline. Doesn't generate a [CHANGELOG.md](http://CHANGELOG.md) file by default (though you can configure it to do so). No version bumping or semantic versioning automation. **Why choose it:** If your team already labels PRs and you want a low-friction way to generate release notes without changing commit message habits, Release Drafter is a solid choice. ## **AutoChangelog: AI-Powered Changelog Generation** **What it does:** AutoChangelog uses AI to analyze your git history and generate human-readable changelogs. It attempts to understand the context of changes and write descriptions that make sense to non-developers. **Best for:** Teams that want AI-assisted changelog writing without strict commit conventions. **Pricing:** Paid service (pricing varies by plan). **Setup complexity:** Low. Connect your repository and let the AI process your commits. **Output quality:** Variable. AI-generated content can be hit-or-miss depending on commit message quality and the complexity of changes. Works best when commits have descriptive messages. **Limitations:** Less control over output format compared to config-driven tools. AI interpretation may not always match your intent. Requires a subscription. **Why choose it:** If you want to experiment with AI-generated changelogs and your team doesn't follow strict commit conventions, AutoChangelog offers a low-effort entry point. ## **GitSaga: AI Changelog and Release Notes** **What it does:** GitSaga is another AI-powered tool that generates changelogs and release notes from your git history. Similar to AutoChangelog, it uses machine learning to interpret commits and write user-friendly descriptions. **Best for:** Teams looking for AI-assisted changelog generation with minimal configuration. **Pricing:** Paid service (pricing varies by plan). **Setup complexity:** Low. Connect your repository and configure basic settings. **Output quality:** Depends on the quality of your commit messages and PR descriptions. AI tools excel when given good source material. **Limitations:** Less transparency into how changes are categorized compared to rule-based tools. Subscription required. **Why choose it:** If you're interested in AI-generated changelogs and want an alternative to AutoChangelog, GitSaga is worth evaluating. ## **Changesets: Monorepo Versioning and Changelogs** **What it does:** Changesets is a tool designed for monorepos that handles versioning, changelog generation, and package publishing. Developers write "changeset" files describing their changes, and the tool aggregates them into changelogs and manages version bumps across multiple packages. **Best for:** Monorepo projects, JavaScript/TypeScript ecosystems, teams that need coordinated versioning across multiple packages. **Pricing:** Free and open-source. **Setup complexity:** Medium. Requires integrating Changesets into your workflow and training developers to write changeset files. Works best with npm/yarn/pnpm workspaces. **Output quality:** Excellent for monorepos. Changelogs are organized by package, and version bumping is handled automatically. Human-written changeset descriptions ensure quality. **Limitations:** Primarily designed for JavaScript/TypeScript monorepos. Requires developers to manually write changeset files (not fully automated from commits). Overkill for single-package projects. **Why choose it:** If you're managing a monorepo and need coordinated versioning and changelogs across multiple packages, Changesets is the industry standard. ## **Comparison Table** | **Tool** | **Pricing** | **Setup Complexity** | **Best For** | **Output Format** | **Automation Level** | | --- | --- | --- | --- | --- | --- | | **Notra** | $20-50/mo | Low | Multi-format content generation | Changelog + blog + social + image | High (AI-powered) | | **release-please** | Free | Medium | Conventional commit workflows | [CHANGELOG.md](http://CHANGELOG.md) + GitHub releases | High (rule-based) | | **git-cliff** | Free | Medium-High | Custom changelog requirements | Configurable Markdown | High (config-driven) | | **Release Drafter** | Free | Low | PR label-based workflows | GitHub release drafts | Medium (label-based) | | **AutoChangelog** | Paid | Low | AI-assisted changelog writing | Changelog | High (AI-powered) | | **GitSaga** | Paid | Low | AI-assisted changelog writing | Changelog + release notes | High (AI-powered) | | **Changesets** | Free | Medium | Monorepo versioning | Per-package changelogs | Medium (manual changesets) | ## **How to Choose the Right Tool** **If you only need a**[**CHANGELOG.md**](http://CHANGELOG.md)**file:** Use **release-please** (if you use conventional commits) or **git-cliff** (if you need custom formatting). Both are free, reliable, and widely used. **If you want changelog + marketing content:** Use **Notra**. It's the only tool that generates blog posts and social media updates from the same commit data. **If you're managing a monorepo:** Use **Changesets**. It's built specifically for multi-package versioning and changelog coordination. **If you use PR labels heavily:** Use **Release Drafter**. It integrates seamlessly with label-based workflows. **If you want to experiment with AI-generated changelogs:** Try **AutoChangelog** or **GitSaga**. Both offer AI-powered changelog writing without strict commit conventions. **If you need maximum customization:** Use **git-cliff**. Its config-driven approach lets you build exactly the changelog format you need. ## **Implementation Tips** Regardless of which tool you choose, follow these best practices: 1. **Write better commit messages.** Even the best automation can't fix vague commits like "fix stuff" or "updates." Use descriptive messages that explain what changed and why. 2. **Establish conventions early.** Whether it's conventional commits, PR labels, or changeset files, consistency is key. Document your conventions and enforce them in code review. 3. **Automate in CI/CD.** Integrate changelog generation into your CI/CD pipeline so it happens automatically on every release. Don't rely on developers remembering to run a script. 4. **Review before publishing.** Automated changelogs are a starting point, not a final draft. Review the output before publishing, especially for customer-facing release notes. 5. **Iterate on configuration.** Most tools improve with tuning. Start with defaults, then refine your configuration based on what works and what doesn't. ## **Frequently Asked Questions** ### **Do I need to use conventional commits for automated changelogs?** Not necessarily. Tools like **release-please** require conventional commits, but **git-cliff** supports custom regex patterns, **Release Drafter** uses PR labels, and **Notra** works with any commit format (though quality improves with better PR descriptions). Choose a tool that matches your existing workflow or be prepared to adopt new conventions. ### **Can I use these tools for private repositories?** Yes. All tools listed support private repositories. Open-source tools like **release-please**, **git-cliff**, and **Release Drafter** work with any GitHub repository (public or private). Paid tools like **Notra**, **AutoChangelog**, and **GitSaga** support private repos as part of their service. ### **What's the difference between a changelog and release notes?** Changelogs are typically technical, developer-focused lists of changes organized by version. Release notes are user-facing announcements that explain what's new in terms customers understand. Some tools (like **Notra**) generate both; others (like **release-please**) focus on technical changelogs. ### **Can I customize the changelog format?** Customization varies by tool. **git-cliff** offers the most flexibility with full template control. **release-please** and **Release Drafter** support configuration files for grouping and formatting. **Notra** handles formatting automatically via AI. **Changesets** uses human-written descriptions, so format is up to you. ### **Should I automate changelogs for a small project?** It depends. For solo projects or small teams, a simple tool like **Release Drafter** or **git-cliff** adds minimal overhead and saves time. For larger teams or customer-facing products, automation becomes essential. Even small projects benefit from consistent changelog practices as they grow. ## **Conclusion** The best automated changelog tool depends on your workflow, team size, and content needs. If you only need a technical [CHANGELOG.md](http://CHANGELOG.md), **release-please** and **git-cliff** are excellent free options. If you're managing a monorepo, **Changesets** is the standard. If you want your changelog to feed blog posts and social media, **Notra** is the only tool that extends beyond changelog generation. Start with your requirements: Do you need just a changelog, or do you need marketing content too? Are you willing to adopt commit conventions? Do you manage multiple packages? Answer these questions, and the right tool becomes clear. Most importantly, pick a tool and stick with it. Consistent changelog automation—even with a simple tool—beats manual changelog maintenance every time. ### Best AI Tools for Developer Marketing in 2026 URL: https://www.usenotra.com/blog/best-ai-tools-for-developer-marketing-in-2026.md Date: 2026-04-28T00:00:00.000Z The best AI tools for developer marketing in 2026 are **Notra** (auto-generates marketing content from GitHub activity), **Jasper** (enterprise AI content platform with brand voice controls), [**Copy.ai**](http://Copy.ai) (go-to-market workflow automation), **Buffer** (social scheduling with AI generation), **ContentBot** (AI content workflows and automation), and [**daily.dev**](http://daily.dev)**Ads** (developer audience targeting). Each serves a different part of the developer marketing stack, from content creation to distribution. Developer marketing is fundamentally different from traditional B2B marketing. Your audience is technical, skeptical of hype, and values substance over polish. They want to see what you've built, not just what you claim. That's why the right AI tools for developer marketing need to do more than generate generic blog posts—they need to understand technical workflows, respect developer culture, and help you turn actual product work into credible content. This guide breaks down the top AI tools that developer relations teams, product marketers, and SaaS founders are using in 2026 to automate content creation, maintain consistent publishing schedules, and reach technical audiences without burning out their teams. ## **What Makes a Good AI Tool for Developer Marketing?** Before diving into specific tools, here's what matters: - **Technical accuracy**: Can it handle code snippets, API changes, and technical concepts without hallucinating? - **Integration with dev tools**: Does it connect to GitHub, Linear, Jira, or other tools developers actually use? - **Authenticity**: Does the output sound like it was written by someone who understands the product, or like generic marketing fluff? - **Workflow efficiency**: Does it save time on the boring parts (formatting, repurposing) while leaving room for strategic thinking? - **Developer audience fit**: Does it help you create content that developers will actually read and share? Now let's look at the tools. ## **1. Notra — Turn Dev Activity Into Marketing Content** **What it does:** Notra connects directly to your GitHub repository and automatically generates changelogs, blog posts, and social media updates from your commits, pull requests, and releases. Instead of starting from a blank page, you start from what your team actually shipped. **Best for:** SaaS teams shipping regular updates who struggle to keep their changelog, blog, and social channels current. Especially valuable for small teams where developers are also responsible for communicating what they built. **Pricing:** Basic plan at $20/month, Pro at $50/month. **How it works for developer marketing:** Notra is the only tool on this list that treats your development activity as the source of truth for marketing content. Connect your GitHub repo, and it analyzes commits, PRs, and releases to generate: - **Changelogs** that are actually readable (not just a list of commit messages) - **Blog post drafts** about new features, with technical context intact - **Social media posts** announcing updates in a way that sounds human The output isn't perfect—you'll still need to edit and add strategic context—but it eliminates the "staring at a blank page" problem and ensures your marketing content is grounded in real product work. **Pros:** - Only tool that connects to GitHub as a content source - Eliminates manual changelog maintenance - Content is inherently authentic because it's based on actual work - Fast setup (connect GitHub, start generating) **Cons:** - Newer product with a focused feature set (no campaign management, SEO tools, etc.) - Currently limited to GitHub (Linear and Slack integrations coming) - Still requires editing—it's a starting point, not a publish button - Not ideal if you need long-form thought leadership unrelated to product updates **Developer marketing fit:** Excellent for product-led content and keeping technical audiences informed about what's new. Less useful for top-of-funnel educational content or brand campaigns. ## **2. Jasper — Enterprise AI Content Platform** **What it does:** Jasper is a comprehensive AI content platform designed for marketing teams. It offers brand voice customization, templates for dozens of content types, campaign workflows, and integrations with marketing tools. **Best for:** Larger marketing teams that need to produce high volumes of content across multiple channels while maintaining brand consistency. **Pricing:** Starts around $49/month for individuals; custom pricing for teams and enterprise. **How it works for developer marketing:** Jasper excels at creating polished marketing content at scale. You can train it on your brand voice, feed it product information, and generate blog posts, landing pages, email campaigns, and social content. For developer marketing, it's particularly useful for: - Educational blog content (tutorials, guides, comparisons) - Product marketing pages that need to explain technical concepts to non-technical buyers - Email nurture sequences for developer audiences The challenge with Jasper for developer marketing is that it's optimized for traditional marketing workflows. It won't pull from your GitHub activity or understand your codebase—you need to provide all context manually. **Pros:** - Mature platform with extensive templates and workflows - Strong brand voice controls - Good for high-volume content production - Integrates with marketing tools (SEO, analytics, CMS) **Cons:** - Expensive for small teams - Generic output without careful prompting and editing - No integration with developer tools - Can sound overly "marketing-y" if not carefully tuned for technical audiences **Developer marketing fit:** Good for educational content and product marketing pages. Less useful for product update content or highly technical documentation. ## **3.**[**Copy.ai**](http://Copy.ai)**— Go-to-Market Workflow Automation** **What it does:**[Copy.ai](http://Copy.ai) focuses on automating go-to-market workflows, from sales copy to blog content. It's designed to help teams move faster across the entire customer journey, with AI-powered templates for emails, landing pages, ads, and long-form content. **Best for:** Growth teams and product marketers who need to test messaging quickly and produce content across multiple channels. **Pricing:** Free plan available; paid plans start around $49/month. **How it works for developer marketing:**[Copy.ai](http://Copy.ai) is particularly strong at generating variations quickly. Need to test five different ways to explain your API? [Copy.ai](http://Copy.ai) can generate them in seconds. It's useful for: - A/B testing landing page copy - Generating social media variations - Drafting email sequences for developer onboarding - Creating ad copy for developer-focused campaigns Like Jasper, [Copy.ai](http://Copy.ai) doesn't integrate with developer tools, so you're feeding it information manually. The output tends to be more casual and conversational than Jasper, which can be a good fit for developer audiences if you edit carefully. **Pros:** - Fast iteration on messaging and copy - Good for testing multiple angles - More affordable than Jasper for small teams - Conversational tone works well for developer audiences **Cons:** - No developer tool integrations - Output can be repetitive without careful prompting - Less robust than Jasper for long-form content - Requires significant editing for technical accuracy **Developer marketing fit:** Good for messaging experimentation and social content. Less useful for technical documentation or product update content. ## **4. Buffer — Social Media Scheduling + AI Generation** **What it does:** Buffer is a social media management platform that now includes AI-powered content generation. Schedule posts across multiple platforms, analyze performance, and use AI to generate post ideas and variations. **Best for:** Teams that need to maintain a consistent social media presence across multiple platforms without a dedicated social media manager. **Pricing:** Free plan available; paid plans start around $6/month per channel. **How it works for developer marketing:** Buffer's strength is distribution, not creation. The AI features help you generate social posts and variations, but the real value is in the scheduling, analytics, and multi-platform management. For developer marketing: - Schedule announcements across Twitter, LinkedIn, and other platforms - Use AI to generate variations of product update posts - Analyze which types of content resonate with your developer audience - Maintain consistent posting without manual daily work Buffer's AI generation is less sophisticated than dedicated content tools, but it's good enough for social posts, especially when you're repurposing content from other sources (like blog posts or changelogs). **Pros:** - Excellent scheduling and analytics - Multi-platform support - Affordable for small teams - Simple AI generation for social posts **Cons:** - AI features are basic compared to dedicated content tools - Doesn't integrate with developer tools - Not useful for long-form content - Social-only (doesn't help with blog, changelog, etc.) **Developer marketing fit:** Essential for distribution, but you'll need other tools for content creation. Works well in combination with Notra (generate content) + Buffer (distribute it). ## **5. ContentBot — AI Content Automation and Workflows** **What it does:** ContentBot is an AI content automation platform focused on workflows and bulk content generation. It offers templates, SEO tools, and the ability to create content in multiple languages. **Best for:** Teams that need to produce large volumes of SEO-optimized content or manage content in multiple languages. **Pricing:** Plans start around $29/month; higher tiers for more content volume. **How it works for developer marketing:** ContentBot is particularly strong at SEO-focused content and bulk generation. For developer marketing, it's useful for: - Creating educational blog content optimized for search - Generating documentation or FAQ content at scale - Producing content in multiple languages for global developer audiences - Building out content hubs around specific topics The trade-off is that ContentBot's output can feel formulaic. It's optimized for volume and SEO, not for the authentic, technical voice that resonates with developers. **Pros:** - Good SEO tools and optimization - Bulk content generation - Multi-language support - Affordable for the feature set **Cons:** - Output can feel generic and formulaic - No integration with developer tools - Less sophisticated than Jasper or [Copy.ai](http://Copy.ai) for brand voice - Requires heavy editing for technical accuracy **Developer marketing fit:** Good for SEO-focused educational content and documentation. Less useful for product updates or thought leadership. ## **6.**[**daily.dev**](http://daily.dev)**Ads — Developer Audience Targeting** **What it does:**[daily.dev](http://daily.dev) is a platform where developers discover technical content, and [daily.dev](http://daily.dev) Ads lets you target that audience with sponsored content. It's not an AI content generation tool—it's a distribution channel—but it's worth including because reaching developers is half the battle. **Best for:** Developer tools and SaaS products that need to reach an engaged technical audience with educational or product content. **Pricing:** Self-serve ad platform with various budget options; typically starts around $500 minimum spend. **How it works for developer marketing:**[daily.dev](http://daily.dev) Ads lets you promote blog posts, product announcements, or educational content directly to developers who are already in "learning mode." You can target by technology, role, and interests. For developer marketing: - Promote technical blog posts to relevant audiences - Drive awareness for new features or products - Build credibility by showing up in a trusted developer content feed This isn't a content creation tool, but it's a powerful distribution channel that complements the content you create with the other tools on this list. **Pros:** - Highly targeted developer audience - Developers are in a content-consumption mindset - Good for building awareness and driving traffic - Transparent pricing and performance metrics **Cons:** - Requires budget (not organic) - You still need to create the content to promote - Performance depends on content quality - Not a content generation tool **Developer marketing fit:** Excellent for distribution and audience targeting. Use it to amplify content created with other tools. ## **Comparison Table** | **Tool** | **Best For** | **Pricing** | **Dev Tool Integration** | **Content Types** | **Key Strength** | | --- | --- | --- | --- | --- | --- | | **Notra** | Product update content | $20-50/mo | GitHub, Linear (Slack coming) | Changelogs, blog posts, social, marketing assets | Only tool that generates from dev activity | | **Jasper** | High-volume marketing content | $49+/mo | None | All marketing content types | Brand voice control, enterprise features | | [**Copy.ai**](http://Copy.ai) | GTM workflow automation | Free-$49/mo | None | Sales copy, ads, social, blog | Fast iteration and testing | | **Buffer** | Social media management | $6+/mo per channel | None | Social posts | Scheduling and analytics | | **ContentBot** | SEO content at scale | $29+/mo | None | Blog, SEO, documentation | Bulk generation, multi-language | | [**daily.dev**](http://daily.dev)**Ads** | Developer audience targeting | $500+ min spend | None | Sponsored content | Targeted developer reach | ## **How to Choose the Right Tool for Your Team** The best tool depends on your team size, content needs, and where you are in your developer marketing journey. **If you're a small team shipping regular updates:** Start with Notra to automate product update content, then add Buffer for distribution. This covers your baseline content needs (changelog, blog, social) without requiring a dedicated content person. **If you need high-volume educational content:** Jasper or ContentBot will help you produce blog posts, guides, and tutorials at scale. Expect to invest time in editing for technical accuracy and voice. **If you're experimenting with messaging:**[Copy.ai](http://Copy.ai) is excellent for testing different angles quickly. Use it to generate variations, then validate with your audience. **If you have budget for distribution:** Combine any of the content tools above with [daily.dev](http://daily.dev) Ads to reach a targeted developer audience. **If you're a solo founder or very small team:** Notra + Buffer is the most efficient stack. Notra generates content from your actual work, Buffer distributes it. Total cost: under $100/month. ## **The Reality of AI Tools for Developer Marketing** Here's what these tools won't do: they won't replace strategic thinking, deep technical knowledge, or authentic relationships with your developer community. They're automation tools, not magic. What they *will* do is eliminate the grunt work—the blank page problem, the manual changelog updates, the reformatting of the same announcement for five different platforms. They give you back time to focus on strategy, community engagement, and building relationships. The best developer marketing in 2026 combines AI efficiency with human expertise. Use AI to handle the repetitive parts, then add the context, nuance, and technical depth that only you can provide. ## **FAQ** ### **What's the difference between general AI writing tools and developer marketing tools?** General AI writing tools (like ChatGPT or Claude) are trained on broad content and don't understand developer workflows or tools. Developer marketing tools either integrate with dev tools (like Notra with GitHub) or are optimized for technical content and developer audiences. The difference shows up in accuracy, authenticity, and workflow efficiency. ### **Can AI tools write technical documentation?** AI tools can draft technical documentation, but they require significant human oversight for accuracy. Tools like ContentBot or Jasper can generate structure and basic explanations, but you'll need a human with technical knowledge to verify accuracy, add code examples, and ensure the documentation actually helps developers. For API documentation, tools that integrate with your codebase (like Swagger/OpenAPI generators) are more reliable than general AI writing tools. ### **How do I make AI-generated content sound less generic for developer audiences?** Three strategies: (1) Feed the AI specific examples of your product and technical details, not just generic descriptions. (2) Edit heavily for technical accuracy and remove marketing jargon. (3) Add code examples, real use cases, and specific technical details that only you know. Developers can spot generic AI content instantly—the fix is adding specificity and technical depth. ### **Should I use multiple AI tools or stick with one?** Most teams end up with a small stack: one tool for content creation, one for distribution. For example, Notra (content from dev activity) + Buffer (social distribution), or Jasper (educational content) + [daily.dev](http://daily.dev) Ads (targeted distribution). Using too many tools creates workflow complexity. Start with one or two, then add more only if you have a specific gap. ### **Are AI tools worth it for a small developer marketing team?** Yes, but choose carefully. A small team (1-2 people) benefits most from tools that automate repetitive work—like Notra for changelogs and product updates, or Buffer for social scheduling. Avoid tools that require extensive setup, training, or editing. The ROI comes from time saved on grunt work, not from generating massive volumes of mediocre content. --- **About Notra:** We help dev teams turn their daily work into publish-ready content. Connect your GitHub repo and automatically generate changelogs, blog posts, and social updates from your commits and releases. Learn more at [usenotra.com](http://usenotra.com). ### How to Automate Your Marketing Content from Product Updates URL: https://www.usenotra.com/blog/how-to-automate-your-marketing-content.md Date: 2026-04-27T00:00:00.000Z To automate marketing content from product updates, connect your development tools (GitHub, Linear, Jira) to an AI-powered content generation system that monitors shipped work and automatically creates changelogs, blog posts, and social updates. Tools like Notra pull directly from commit history and pull requests, while platforms like Jasper or Copy.ai can transform structured update notes into marketing copy, eliminating the manual bottleneck between shipping features and publishing content. The most effective approach combines source integration (capturing what shipped), AI transformation (turning technical changes into readable content), and distribution automation (publishing to your blog, changelog, and social channels). This guide walks through the problem, manual alternatives, and how to build a fully automated pipeline. ## The Product Update Marketing Gap SaaS teams ship constantly. Engineers merge pull requests daily. Product managers close tickets in Linear. Designers ship new components. But none of this activity automatically becomes marketing content. The result? Your changelog is weeks out of date. Your blog hasn't mentioned the last three feature releases. Your social media team doesn't know what shipped yesterday. Customers discover new features by accident. **Why the gap exists:** - **Engineers don't write marketing copy.** A commit message like "refactor auth flow, add OAuth2 support" doesn't translate to a customer-facing announcement. - **Product updates live in dev tools.** GitHub, Linear, and Slack contain all the context, but marketing teams don't monitor these channels. - **Manual content creation doesn't scale.** Writing a blog post for every feature release requires dedicated time no one has. - **Context gets lost in translation.** By the time someone decides to write about a feature, the engineer who built it has moved on, and details are fuzzy. The gap between shipping and publishing grows wider as your team ships faster. ## The Manual Approach (And Why It Fails) Most teams start with a manual workflow: 1. **Weekly sync meeting** where engineering reviews what shipped 2. **Product manager takes notes** and drafts a changelog entry 3. **Marketing team reviews** and decides which updates warrant a blog post 4. **Someone writes the post** (usually the PM or a technical writer) 5. **Edits and approvals** cycle through Slack 6. **Publication** happens 2-3 weeks after the feature shipped **Problems with this approach:** - **Time lag:** Features are old news by the time content publishes - **Inconsistency:** Only "big" features get coverage; incremental improvements are ignored - **Bottleneck:** The PM or writer becomes a single point of failure - **Context loss:** Details fade; screenshots and examples require recreation - **Opportunity cost:** Hours spent writing could be spent building This works for teams shipping monthly. It breaks down at weekly or daily release cadences. ## Automation Approaches: A Comparison | Approach | Tools Required | Time Investment | Content Quality | Best For | | --- | --- | --- | --- | --- | | **Fully Manual** | Google Docs, Slack | 4-6 hours/week | High (with skilled writer) | Teams shipping monthly | | **Semi-Automated** | Notion + Jasper/Copy.ai | 2-3 hours/week | Medium-High | Teams with structured release notes | | **Fully Automated** | Notra, GitHub Actions + AI | 30 min/week (review) | Medium (improving) | Teams shipping daily/weekly | The right approach depends on your release cadence, team size, and content volume needs. ## Step-by-Step: Building an Automated Content Pipeline ### Step 1: Centralize Your Product Update Data Before you can automate content creation, you need a single source of truth for what shipped. **Option A: Use your existing dev tools** - GitHub releases and pull requests - Linear completed issues with "shipped" status - Jira tickets marked "Done" **Option B: Create a structured changelog** - Maintain a `CHANGELOG.md` file in your repo - Use conventional commits to auto-generate entries - Tag releases with semantic versioning **Best practice:** Don't create a new system. Pull from where your team already works. ### Step 2: Extract Structured Data from Dev Activity Raw commit messages and PR descriptions aren't marketing-ready. You need to extract: - **What changed:** Feature name, component affected - **Why it matters:** User benefit, problem solved - **Who it's for:** User segment, use case - **Visual proof:** Screenshots, demos, code examples **Manual extraction:** Weekly review meeting where PM documents these details **Automated extraction:** Tools that parse PR descriptions, commit messages, and linked issues **Notra approach:** Connects directly to GitHub, reads PR metadata, and uses AI to identify user-facing changes vs. internal refactors. Automatically categorizes updates (new feature, improvement, bug fix) and extracts customer impact from PR descriptions. ### Step 3: Transform Technical Updates into Marketing Copy 88: This is where AI content tools excel. You're not writing from scratch, you're transforming structured data into readable prose. **Tools for this step:** - **Notra:** Purpose-built for dev-to-marketing transformation. Reads GitHub activity and generates changelog entries, blog post drafts, and social updates in your brand voice. Understands technical context (knows that "add OAuth2 support" means "customers can now sign in with Google"). - **Jasper:** General-purpose AI writer. Good for expanding brief update notes into full blog posts. Requires manual input of what shipped. Strong for long-form content but needs human-provided context. - **Copy.ai:** Similar to Jasper. Excels at generating multiple variations (useful for social posts). Doesn't integrate with dev tools, you paste in release notes and get marketing copy out. - **ContentBot:** Workflow automation for content. Can integrate with Zapier to trigger content generation when a new GitHub release publishes. Requires setup but handles distribution too. **Key difference:** Generic AI writers (Jasper, Copy.ai) need you to tell them what shipped. Notra pulls that information directly from your dev tools, eliminating the manual input step. ### Step 4: Review and Refine AI-Generated Content AI-generated content needs human review. Budget 30-60 minutes per week for: - **Accuracy check:** Did the AI correctly describe what shipped? - **Tone adjustment:** Does it match your brand voice? - **Context addition:** Add customer quotes, usage stats, or strategic context the AI can't know - **Visual assets:** Add screenshots, GIFs, or demo videos **Pro tip:** Create a brand voice guide and example posts. Tools like Notra and Jasper can learn your style and reduce editing time. ### Step 5: Automate Distribution Once content is approved, automate publishing: - **Blog posts:** Auto-publish to your CMS (WordPress, Webflow, Astro) - **Changelog:** Update your public changelog page - **Social media:** Schedule posts to Twitter, LinkedIn via Buffer or Hootsuite - **Email:** Trigger a "What's New" email to customers **Notra workflow:** Generates content, you review in the dashboard, click "Publish," and it pushes to your blog and changelog simultaneously. Social posts go to a queue for scheduling. **Alternative workflow:** Use Zapier to connect your changelog tool → Buffer (social) + Mailchimp (email) + WordPress (blog). ## Recommended Tool Stack by Use Case ### For teams shipping daily (startups, dev tools) - **Source:** Notra connected to GitHub - **Review:** Notra dashboard (30 min/week) - **Distribution:** Notra auto-publish + Buffer for social **Why:** Eliminates manual data entry. Content generation keeps pace with shipping. ### For teams shipping weekly (SaaS products) - **Source:** GitHub releases + Linear completed issues - **Transform:** Jasper or Copy.ai (paste in release notes) - **Distribution:** Manual publish to blog, Buffer for social **Why:** Weekly cadence allows time for manual content creation. AI speeds up writing but doesn't need full automation. ### For teams with dedicated content writers - **Source:** Notion database of shipped features - **Transform:** Writer uses AI as drafting assistant - **Distribution:** Standard CMS workflow **Why:** Human writer maintains quality and strategic messaging. AI reduces drafting time. ## Common Pitfalls to Avoid **1. Automating before you have a content strategy**Don't automate bad content. Define your changelog format, blog post structure, and social voice first. Then automate the execution. **2. Publishing AI content without review**AI makes mistakes. It might misunderstand technical changes or hallucinate features. Always review before publishing. **3. Ignoring internal vs. external updates**Not every commit is customer-facing. Refactors, dependency updates, and internal tools shouldn't become blog posts. Use filters or manual review to separate signal from noise. **4. Over-relying on generic AI tools**Tools like ChatGPT or Claude can write marketing content, but they don't know what you shipped. You'll spend more time explaining context than you save on writing. **5. Forgetting to update your automation**As your product evolves, your content needs change. Review your automation quarterly to ensure it still serves your goals. ## Measuring Success Track these metrics to know if automation is working: - **Time saved:** Hours per week spent on update content (before vs. after) - **Publish frequency:** Changelog updates per month, blog posts about features - **Content freshness:** Days between feature ship and published announcement - **Engagement:** Views, shares, and clicks on update content - **Customer awareness:** Support tickets asking "does this feature exist?" (should decrease) **Benchmark:** Teams using Notra report reducing update content time from 4-6 hours/week to under 1 hour, while increasing publish frequency by 3x. ## FAQ ### Can AI really write good marketing content from code commits? AI can transform structured information (PR descriptions, issue summaries) into readable content, but quality depends on input quality. If your team writes detailed PR descriptions explaining user impact, AI-generated content will be strong. If your commits say "fix bug" with no context, AI output will be generic. The best results come from tools like Notra that understand technical context and can infer user impact from code changes. ### Do I still need a content writer if I automate product updates? Yes, but their role shifts. Instead of writing every changelog entry, they focus on strategic content (customer stories, thought leadership, feature deep-dives) while automation handles routine update announcements. Writers become editors and strategists rather than production workers. ### How do I prevent AI from publishing inaccurate information? Always include a human review step. Set up your workflow so AI-generated content goes to a draft state or review queue, not directly to production. Tools like Notra include approval workflows. For critical announcements (security updates, breaking changes), require manual review by engineering and product leads. ### What's the difference between Notra and using ChatGPT to write updates? ChatGPT requires you to manually tell it what shipped, you paste in commit messages or write a summary. Notra connects directly to GitHub, automatically detects what shipped, categorizes changes, and generates content without manual input. ChatGPT is a general writing tool; Notra is purpose-built for the dev-to-marketing workflow. ### Can I automate content for multiple products or repositories? Yes. Most automation tools support multiple sources. Notra can connect to multiple GitHub repos and generate separate changelogs for each product. You can also create unified "company updates" that combine changes across repos. Set up filters to control which repos feed which content channels. ### How much does it cost to automate product update content? **DIY approach:** Free (GitHub Actions + ChatGPT API) to $50/month (Zapier + AI writing tool)\\**Notra:** $20-50/month depending on plan\\**Enterprise tools:** $200-500/month (Jasper, Copy.ai, ContentBot) Compare this to the cost of 4-6 hours/week of PM or writer time ($400-800/month at typical SaaS salaries). Automation pays for itself if you ship weekly or more frequently. --- ## Start Automating Today 212: The gap between shipping and publishing doesn't have to exist. With the right tools and workflow, every feature you ship can automatically become a changelog entry, blog post, and social update, without adding work to your team's plate. **Quick start:** 1. Audit your current process: How long does it take to publish update content? 2. Choose your automation level: Fully automated (Notra), semi-automated (Jasper + manual input), or assisted (AI as drafting tool) 3. Set up integrations: Connect your dev tools to your content tools 4. Define review workflow: Who approves AI-generated content before it publishes? 5. Measure and iterate: Track time saved and content quality over 30 days 222: If you're shipping daily or weekly and struggling to keep your changelog and blog current, [Notra](https://www.usenotra.com?ntr=WlbI_nEwqKdfSUkn) is built specifically for this problem. Connect GitHub, review AI-generated content, and publish, all in one workflow. The best marketing content is the content that actually gets published. Automation makes that possible. ### How to Automate Social Media Posts from GitHub Commits URL: https://www.usenotra.com/blog/how-to-automate-social-media-posts-from-github-commits.md Date: 2026-04-24T00:00:00.000Z You can automate social media posts from GitHub commits by connecting your repository to a content generation tool that monitors commit activity and transforms technical changes into platform-ready posts. The most direct approaches are: (1) dedicated tools like Notra that auto-generate posts from GitHub activity, (2) workflow automation platforms like Zapier or n8n paired with AI APIs, or (3) custom GitHub Actions scripts that trigger on commits and call social media APIs. Each method trades setup complexity for customization depth. ## **Why Developers Need This Automation** Most development teams ship code daily—bug fixes, new features, performance improvements—but their social media accounts stay silent. The disconnect is simple: developers optimize for shipping, not storytelling. Writing a LinkedIn post about yesterday's commit feels like context-switching overhead. The manual approach breaks down fast. Copying commit messages into Twitter threads takes 10–15 minutes per post, and commit messages written for teammates ("fix: resolve null pointer in auth flow") don't translate to user-facing narratives. Teams that try to maintain a posting cadence manually abandon it within weeks. Automation solves this by treating shipped work as the content source. Every merged PR, closed issue, or tagged release becomes a candidate for a social post—no separate content calendar required. ## **Comparison: Three Automation Approaches** | **Method** | **Setup Time** | **Customization** | **Cost** | **Best For** | | --- | --- | --- | --- | --- | | **Notra** | 5 minutes | Medium (AI tone profiles, content types) | $20–50/mo | Teams wanting zero-maintenance automation with GitHub, Linear, Slack | | **Zapier + ChatGPT API** | 30–60 minutes | High (full prompt control, custom filters) | $20/mo Zapier + $10–30/mo OpenAI | Developers comfortable with API workflows who want full control | | **GitHub Actions + Custom Script** | 2–4 hours | Very High (code-level control) | Free (within GitHub limits) | Engineering teams with specific formatting needs or on-prem requirements | | **Buffer/Hootsuite (manual)** | N/A | Full manual control | $6–30/mo | Teams that want scheduling only, not generation | The key trade-off: dedicated tools like Notra handle the entire pipeline (monitoring → generation → formatting → posting), while DIY approaches give you granular control at the cost of maintenance burden. ## **Method 1: Using Notra (Fastest Setup)** Notra is purpose-built for this workflow. It connects directly to GitHub, monitors your selected repositories, and auto-generates social posts, changelogs, and blog updates from commits, PRs, and releases. ### **Step-by-step setup** **1. Connect your GitHub account** Sign up at [app.usenotra.com](https://app.usenotra.com/) and authorize GitHub access. Notra requests read-only permissions for repository metadata and commit history. **2. Select repositories to track** Choose which repos should trigger content generation. You can include public repos for open-source projects or private repos for SaaS product updates. Most teams start with 1–2 core repositories. **3. Configure content types** Notra offers three output formats: - **Social Posts** — short-form updates for Twitter, LinkedIn, Threads - **Changelogs** — structured release notes with grouped changes - **Blog Posts** — long-form articles explaining feature launches - **Marketing Assets**— marketing assets you can edit directly in [figma](https://figma.com/) or [paper](https://paper.design/) Enable the formats you need. Social posts are the most common starting point. **4. Set tone and frequency** Define how technical or user-friendly the generated content should be. Options range from "developer-focused" (preserves technical terminology) to "customer-facing" (translates features into benefits). Set posting frequency: immediate (every significant commit), daily digest, or weekly rollup. **5. Review and publish** Notra generates drafts automatically. Review them in the dashboard, edit if needed, and publish directly to connected social accounts or copy to your scheduling tool. ### **What Notra handles automatically** - Filters out trivial commits (dependency updates, typo fixes) - Groups related commits into coherent narratives - Adapts tone for different platforms (LinkedIn gets longer context, Twitter gets punchier phrasing) - Includes relevant links back to GitHub releases or documentation **Limitations**: Notra is optimized for GitHub-centric workflows. If your team uses Jira or Azure DevOps as the primary source of truth, you'll need to wait for those integrations (Linear and Slack are coming soon) or use a more flexible automation platform. ## **Method 2: Zapier + ChatGPT API (DIY Flexibility)** This approach gives you full control over filtering, formatting, and posting logic. You'll build a Zap that triggers on new GitHub commits, sends commit data to ChatGPT for rewriting, and posts the result to social media. ### **Step-by-step setup** **1. Create a Zapier account** Sign up at [zapier.com](https://zapier.com/). You'll need at least the Starter plan ($19.99/mo) for multi-step Zaps and premium app access. **2. Set up the GitHub trigger** - Create a new Zap - Choose **GitHub** as the trigger app - Select **New Commit** as the event - Connect your GitHub account and choose the repository to monitor - Test the trigger to confirm Zapier can read recent commits **3. Add a filter step** Insert a **Filter** action to skip commits you don't want to post about: - Skip commits with messages containing "chore:", "docs:", "test:", or "ci:" - Skip commits from bots (author contains "dependabot" or "renovate") - Only proceed if the commit message length > 20 characters This prevents your social feed from filling with dependency updates and typo fixes. **4. Format the prompt for ChatGPT** Add a **Formatter** step to build the AI prompt: ```text Rewrite this GitHub commit into a short LinkedIn post (2-3 sentences) that explains what changed and why it matters to users: Commit message: {{commit_message}} Files changed: {{files_changed}} Repository: {{repo_name}} Tone: professional but conversational. Focus on user benefits, not technical implementation. ``` **5. Call the OpenAI API** Add a **Webhooks by Zapier** action: - Method: POST - URL: `https://api.openai.com/v1/chat/completions` - Headers: - `Authorization: Bearer YOUR_OPENAI_API_KEY` - `Content-Type: application/json` - Body (JSON): ```json { "model": "gpt-4", "messages": [ {"role": "user", "content": "{{formatted_prompt}}"} ], "max_tokens": 150, "temperature": 0.7 } ``` Test this step to confirm you're getting a rewritten post back. **6. Post to social media** Add a final action for your target platform: - **LinkedIn**: Use the LinkedIn integration, select "Create Share Update," paste the AI-generated text - **Twitter**: Use the Twitter integration, select "Create Tweet," paste the text - **Multiple platforms**: Add parallel actions for each network **7. Turn on the Zap** Activate the Zap. From now on, every new commit that passes your filters will automatically generate and post a social update. ### **Customization ideas** - Add a **Delay** step to batch commits from the same day into a single post - Use **Paths** to route feature commits to LinkedIn and bug fixes to Twitter - Store generated posts in a Google Sheet for manual review before posting - Include commit author names to tag team members in posts **Cost breakdown**: Zapier Starter ($19.99/mo) + OpenAI API (~$0.002 per post with GPT-4, roughly $5–10/mo for 50–100 posts) = ~$25–30/mo total. ## **Method 3: GitHub Actions (Free, Code-Required)** If you're comfortable writing scripts, GitHub Actions lets you build a fully custom pipeline that runs inside your repository's CI/CD environment. ### **High-level workflow** 1. Create a `.github/workflows/social-post.yml` file 2. Trigger the workflow on `push` events to your main branch 3. Use the GitHub API to fetch commit details 4. Call an AI API (OpenAI, Anthropic, or a local model) to rewrite the commit 5. Post to social media via platform APIs (Twitter API, LinkedIn API) ### **Sample GitHub Actions workflow** ```yaml name: Auto-post commits to social media on: push: branches: - main jobs: post-to-social: runs-on: ubuntu-latest steps: - name: Get commit message id: commit run: echo "message=${{ github.event.head_commit.message }}" >> $GITHUB_OUTPUT - name: Generate social post id: generate run: | curl -X POST https://api.openai.com/v1/chat/completions \ -H "Authorization: Bearer ${{ secrets.OPENAI_API_KEY }}" \ -H "Content-Type: application/json" \ -d '{ "model": "gpt-4", "messages": [{"role": "user", "content": "Rewrite this commit as a tweet: ${{ steps.commit.outputs.message }}"}], "max_tokens": 100 }' > response.json echo "post=$(jq -r '.choices[0].message.content' response.json)" >> $GITHUB_OUTPUT - name: Post to Twitter run: | # Use Twitter API v2 with your bearer token curl -X POST https://api.twitter.com/2/tweets \ -H "Authorization: Bearer ${{ secrets.TWITTER_BEARER_TOKEN }}" \ -H "Content-Type: application/json" \ -d '{"text": "${{ steps.generate.outputs.post }}"}' ``` Store your API keys in GitHub Secrets (Settings → Secrets and variables → Actions). **Pros**: No monthly fees, runs entirely in your infrastructure, full control over logic. **Cons**: Requires maintaining code, handling API rate limits, and debugging workflow failures. ## **Which Method Should You Choose?** **Choose Notra if:** - You want automation running in under 10 minutes - Your team uses GitHub as the primary source of truth - You prefer a managed service over maintaining scripts - You also need changelogs or blog posts generated from the same activity **Choose Zapier + ChatGPT if:** - You need to connect multiple data sources (GitHub + Jira + Slack) - You want full control over AI prompts and filtering logic - You're comfortable with no-code automation platforms - You already use Zapier for other workflows **Choose GitHub Actions if:** - You have engineering resources to build and maintain the pipeline - You need on-premises or air-gapped deployment - You want zero recurring costs - You need highly custom formatting or platform-specific logic ## **Frequently Asked Questions** ### **Which social media platforms can I automate posts to?** Most automation tools support Twitter (X), LinkedIn, Facebook, and Instagram. Notra currently supports Twitter and LinkedIn, with Instagram and Threads coming soon. Zapier supports 20+ social platforms including Reddit, Discord, and Telegram. GitHub Actions can post to any platform with a public API. ### **Can AI write good technical social posts, or do they sound generic?** AI-generated posts are only as good as the input data and prompt. Generic commit messages ("fix bug") produce generic posts. Detailed commits ("Add real-time collaboration to the editor using WebSockets, reducing sync latency from 2s to 200ms") give AI enough context to write compelling posts. The best results come from teams that already write clear, user-focused commit messages. ### **How much does this cost compared to hiring a social media manager?** A part-time social media manager costs $1,500–3,000/month. Notra costs $29–99/month. Zapier + ChatGPT costs ~$25–30/month. GitHub Actions is free within GitHub's usage limits. The trade-off: automation handles volume and consistency, but human managers add strategic thinking, community engagement, and brand voice refinement. ### **How do I prevent sensitive commits from being posted publicly?** Use filtering rules to exclude commits with specific keywords ("internal", "security", "hotfix"), commits to private branches, or commits from specific authors. Notra and Zapier both support conditional logic. For GitHub Actions, add an `if` condition to check commit message content before posting. Always review generated posts before publishing if your repository contains any sensitive information. ### **How often should I post? Won't daily commits spam my followers?** Frequency depends on your audience and commit volume. SaaS companies shipping daily often batch commits into weekly digests. Open-source projects with active communities can post daily highlights. Start with weekly rollups, monitor engagement, and adjust. Most tools let you set minimum thresholds (e.g., only post if 5+ commits landed that day). ### **What if my commit messages are too technical for social media?** AI rewriting solves this, but the quality depends on how much context you provide. If your commits say "refactor auth module," the AI has little to work with. If they say "refactor auth module to support OAuth 2.1, enabling Google and GitHub login," the AI can write "We just added Google and GitHub login to make signing in faster." Consider adopting conventional commits with body text that explains user impact. ### **Can I customize the tone for different platforms?** Yes. Notra offers tone profiles (technical, conversational, promotional). Zapier lets you write different prompts for different platforms using Paths. GitHub Actions gives you full control—you can call the AI API multiple times with platform-specific prompts and post different versions to LinkedIn vs. Twitter. ### **Do I need to review every post before it goes live?** That depends on your risk tolerance. Teams with strict brand guidelines review every post. Fast-moving startups often auto-post and fix mistakes retroactively. A middle ground: auto-post to a private Slack channel for team review, then manually approve before publishing. Notra and Zapier both support "draft mode" where posts are generated but not published until you approve them. ## **Start Automating Your Developer Activity** The gap between shipping code and talking about it is a visibility problem, not a content problem. Your team already produces the raw material—commits, PRs, releases—every day. Automation turns that activity into a consistent social media presence without adding overhead. If you want the fastest path from commits to posts, try [Notra](https://www.usenotra.com/?ntr=WlbI_nEwqKdfSUkn)—it's built specifically for this workflow and handles GitHub, changelogs, and social posts in one place. If you need more control or want to integrate other data sources, start with a Zapier + ChatGPT setup and iterate from there. The best time to start was the day you shipped your first feature. The second-best time is today. ### Engineers are great for Marketing URL: https://www.usenotra.com/blog/engineers-are-great-for-marketing.md Date: 2026-04-09T10:55:44.000Z Part of why [Vercel](https://vercel.com/) stays top of mind is that many employees consistently share what they are building on Twitter and engage with users and customers. We see the same pattern at [**Anomaly**](https://anoma.ly/) (behind OpenCode), which has hired engineers like [Ryan Vogel](https://x.com/ryanvogel), [Kit Langton](https://x.com/kitlangton), and [Rhys Sullivan](https://x.com/RhysSullivan) who actively talk about their work, and even at larger companies like [Cloudflare](https://cloudflare.com), where engineers such as [Dillon Mulroy](https://x.com/dillon_mulroy) stream on Twitch and regularly post updates publicly on Twitter. Helping shape a product or feature also creates a personal connection between the company and the product because people get to *see* the work happen. They learn the "why" behind decisions, follow the tradeoffs, and feel like they are part of the journey. **That does a few powerful things:** - It builds trust. When you share progress, you also share your process. - It shortens feedback loops. Users reply with context, edge cases, and ideas while you are still building. - It makes distribution feel natural. You are not "marketing". You are documenting. ### Why this trend accelerates with AI As iteration speed increases with the use of Artificial Intelligence, more and more companies will want to turn their internal shipping velocity into outward-facing distribution. This is why engineers are such an underrated distribution channel. **If you are building a developer product, you already have the raw material for great marketing:** - PRs and shipped features - interesting implementation details - benchmarks and performance wins - the small but real customer problems you solved The challenge is that most teams do not have time to turn all that into content consistently. That is the issue we are trying to solve with Notra: take the work you already do in GitHub or Linear and turn it into clear, on-brand updates that you can publish everywhere. We don’t want to fuel the dead internet theory; we want to help real humans talk about the work they or their agents do every day. Because good communication is **very** important! --- **Disclaimer** - This is not a scientific claim, and it is not backed by formal research or a strict scientific standard. - It is our belief based on what we have observed while building developer products. - This belief is a big part of why we are building Notra: to help teams turn real shipping activity into consistent, authentic distribution. ### Notra moves to paid trials and says goodbye to free URL: https://www.usenotra.com/blog/paid-trials-goodbye-free.md Date: 2026-04-05T17:52:33.815Z We shipped a pricing change this week. Basic is $20/month with $12 of included usage, and Pro is $50/month with $32 of included usage. Notra no longer has a free tier, though it might return in the future if our economics allow it. ## From free to trial A free tier hides the signal. You can't tell if someone isn't using the product because it doesn't work for them or because they have no reason to try. A trial with a real endpoint changes that calculation. The users who pay after three days are different. They see value, and they act. The plan is straightforward. Basic is $20/month with $12 of included usage. Pro is $50/month with $32 of included usage. Usage funds the actual work: running a changelog generation, drafting a blog post, creating social media content. If you run out, you can top up without changing plans. ## Why we did this Free tiers feel generous when your growth metrics are the only metric. But they hide the cost of what we're actually building. Syncing with GitHub and Linear, running LLMs on every generation, storing and versioning your content. That costs money. ### More control, less waste: on-demand content and brand voice learning URL: https://www.usenotra.com/blog/more-control-less-waste-on-demand-content-and-brand-voice-learning.md Date: 2026-03-13T23:09:06.983Z When we built Notra, we made one big bet: that most teams would rather automate what goes to their audience than hand-tweak it every time. Still true. But we missed something. Not every ship deserves coverage. Not every commit is worth mentioning. And automatic is not helpful if the output does not sound like you. This week we shipped three things that change how you generate content. They come down to one idea: you decide what gets made and how it sounds. ## Generate what you actually want to ship For the first two months, Notra worked like this: set up a trigger, the AI looks at everything since last time, drafts appear. Fine if you wanted broad coverage. Broke down when you wanted to be selective. We got requests like this. "I want a changelog for our three customer-facing repos only. Not internal tools. And only commits from the last five days, not a month." Or: "I'm building a blog post about performance improvements. Let me hand-pick which PRs matter instead of including everything." So we rebuilt the generate flow. When you create content on-demand now, you see a preview first. The commits, PRs, and releases Notra found. You check boxes for what belongs in your story. Toggle releases on or off. Pick a time window. Scope to specific repos. Nothing fancy. But now you control scope instead of hoping the AI guesses right. The backend work was real. The preview endpoint fetches your data (paginated, because large repos will kill you if you're not careful), and those filters travel with your generate request so the AI only sees what you picked. ## Your voice, not a generic one The other gap we kept hearing: content that looked good but sounded like nobody. Teams would edit our drafts because the tone felt off. Not wrong. Just not theirs. This week we shipped brand voice learning. Add references from your Twitter account (or paste custom text), and Notra's agents study them first, before generating anything. They are matching not just word choice, but rhythm, how you structure sentences, what ideas you prioritize. The reference system runs on Twitter OAuth with encrypted token storage. Connect one click. Bulk import your last 20 tweets. Pick which ones define your voice. Add custom examples for platforms we don't auto-pull from. You also get platform scoping. A tweet reference can teach Twitter posts and blog writing. A blog excerpt teaches blog generation only. Granular control over what shapes the AI's output. ## Instant publish for your schedule Generated content usually lands as draft. You review it, maybe edit it, then publish. For teams running daily schedules, that review step is one more thing to get to. We added a toggle on triggers: "Auto-publish on this trigger." Turn it on and content hits published status immediately when generated instead of sitting in draft. On-demand content from your dashboard stays draft by default (you probably want to eyeball something you asked for), but scheduled runs can go straight to live. ## What comes next We are working on automatic voice detection. Load your references and we infer your tone without you tagging them. We are also improving the data filtering so complex filters compose. You should be able to say things like "commits from the API team in the last week, excluding docs changes" and have it just work. The real goal is that Notra disappears. You point it at your data. It learns how you sound. The drafts that show up sound like you wrote them. ## Notra Changelog ### MCP integrations, blog redesign, and content wizard URL: https://www.usenotra.com/changelog/notra/mcp-integrations-blog-redesign-and-content-wizard.md Date: 2026-06-02T00:00:00.000Z This week shipped some key pieces for your development workflow. MCP server integrations now let you connect custom tools with encrypted headers and runtime loading. The Integrations page got a full redesign with category tabs and MCP promoted to a first-class integration. We redesigned the blog with author profile pages and dynamic per-post OG images. Code blocks now highlight on the server side and have copy buttons. The Create Content flow is now a three-step wizard (Formats, Activity, Brand Identity), and the landing page got a refresh with a 3D mega menu and gradients across all pages. We also added an Image content type so you can generate brand-matched repository images from chat or schedules. Several security fixes and UX improvements round out the week. ## Highlights ### MCP Server Integrations with encrypted headers and runtime tool loading Organization-scoped MCP servers with encrypted header storage, connection testing from the dashboard, and runtime tool loading for chat and standalone agents. Tools show in chat with dynamic blocks and server favicons. (#369) ### Integrations page redesigned with category filters and MCP promotion New top-level tabs (All, Input, Output, Extensions) replace section-based organization. MCP is now a first-class integration card linking to a dedicated /integrations/mcp page. Added unified "Connect" buttons with hotkey across GitHub, Linear, and MCP. (#370) ### Blog author pages and dynamic OpenGraph images Added /blog/author/\[slug\] profile pages with role and social links. Each blog post now gets a dynamic OG image with the title, author avatar, and role. Both posts and author pages use true ISR for fast incremental updates. (#367) ### Blog code highlighting with server-side rendering and copy buttons Code blocks highlight server-side with Shiki using dual light/dark themes. A copy button appears on hover and copies the snippet to clipboard with a toast confirmation. (#366) ### Landing page redesign with mega menu and smooth animations Reusable SiteShell component brings the hero gradient to every page. The navbar mega menu uses a dub-style 3D scale-in effect, and caret color inherits the trigger text. Offscreen sections use content-visibility for performance. (#364) ## More Updates ### Features & Enhancements - **Create Content as 3-step wizard** (#348) - Formats, Activity, and Brand Identity steps. Multi-format and multi-identity generation fans out as parallel requests. Commit previews now show GitHub login when available. - **Create Schedule as dialog** (#349) - Daily/Weekly/Monthly tabs, time picker, day-of-week/day-of-month selectors, and a live summary card with next run and local timezone. Auto-publish hidden and forced off for LinkedIn/Tweet. - **Image content type** (#375) - Generate brand-matched repository images through content creation and chat. Supports revisions from chat with sandbox snapshots and records usage for billing. - **Figma and Paper export for image content** (#377) - Copy buttons on image detail pages for exporting to design tools via Kiwi clipboard helpers. - **Author profile pages for blog posts** (#367) - Profiles at /blog/author/\[slug\] with avatar, role, and icon-only social links (brand icons with globe fallback for unknown platforms). - **True ISR for blog and author pages** (#367) - Both now prerender at build and regenerate on a timer instead of serving dynamically. - **Chat media uploads** (#306) - Attach images and documents to conversations. Scoped to org with org membership checks and R2 persistence. - **Chat post persistence** (#328) - Save, edit, regenerate, and publish posts directly from chat previews with draft tracking. - **Structured onboarding flow** (#310) - Three-step wizard: workspace setup, social connection (X/Twitter), then pricing. Deferred brand analysis dispatch. - **X thread builder free tool** - No signup required. Draft, reorder, and personalize threads with drag-and-drop and per-post char counter. Linked from footer Free Tools. - **Knip static analysis** (#330) - Caught unused exports and dead files across web, dashboard, and API. Integrated into CI. - **Chat model picker with search** - Popover combobox with searchable models. Added Kimi K2.6 and GPT-5.5 support. - **CLI auth handshake** - New /dashboard page and API routes (POST /api/cli/sessions/\[sessionId\]/authorize, GET /api/cli/sessions/\[sessionId\]) for Notra CLI authorization. Mints scoped Unkey API keys. ### Performance & Infrastructure - **AI Gateway Auto-Caching** - Enabled automatic caching for improved response times on content generation. - **TanStack Form + Zod for dialogs** (#350) - Migrated schedule and content dialogs to form framework. Deferred validation runs only on submit; buttons stay enabled until clicked. - **Chat backend extracted to @notra/ai package** (#318, #319) - Chat history, schemas, types, metadata helpers, and abort polling now reusable across apps/api and apps/dashboard via configureChat({ redis }). - **Shared content generation infrastructure** (#321) - Consolidated language rules, brand identity, factuality, tool guidance, and humanizer blocks. Reduces prompt duplication across changelog, blog-post, and linkedin builders. - **Refactored chat tool helpers to Zod schemas** (#371) - Stronger typing for tool requests and approvals. - **Repo image generation improvements** - XML-based agent prompt following Claude best practices. Recovery pass when output.html is missing. - **Repo image via content workflow** (#375) - Removed standalone /\[slug\]/repo-image page. Image generation now flows through content UI and chat. - **Event trigger creation as dialog** (#351) - ResponsiveDialog matching schedule/content chrome. EventTypeCard for release vs push, GitHub-only repos, and brand voice controls. - **CLI sessions with 5-minute expiry** (#316) - One-shot poll via plaintext Verifications table for temporary API key handoff. ### Security & Bug Fixes - **Reject executable skill frontmatter** (#373) - Skill files with language markers like ---js are now rejected. Parser enforces plain YAML only via gray-matter with explicit language setting. - **Linear webhook payload validation** (#335) - Zod schema enforces valid structure before processing; invalid payloads logged and rejected. - **Realtime channel authorization per-org** (#325) - Multi-tenant leak fixed. ACL now enforces exact channel shape, rejects wildcards, and requires org membership for all subscribed channels. - **Linear OAuth state validation per-org** (#327) - Validateion on authorize and callback. Session userId must match oauthState userId; org membership checked both times. State deleted only after auth passes. - **SSRF protection for IPv4-mapped IPv6** (#326) - Hardened URL validation. Detects ::ffff: IPv4-mapped and ::/96 IPv4-compatible addresses and checks them against reserved ranges. - **Skill frontmatter validation** - Empty frontmatter and missing name/description now rejected. Partial unique constraint on (name, organization\_id, is\_system). - **Fixed null-state crash in trigger editor** (#315) - Prevents crashes when triggers are partially configured. - **Validate Linear webhook structure** - Reject malformed payloads before routing to handlers. - **Prevent concurrent chat delete race** - Deleted chats no longer accept appended messages; upsert checks deleted\_at IS NULL. - **Guard GitHub integration token rotation** (#315) - Repository rename now editable; validates new owner/repo pair against GitHub and rejects duplicates. ### Internal Changes - **Notification settings restructured** (#335) - Config-driven toggle components, owner recipient summary, loading skeletons. - **Onboarding website field optional** (#331) - Brand analysis skipped unless a website is provided. - **Chat availability expanded** - Removed ai-chat-experiment flag; chat now available to everyone. - **Humanizer skill content inlined** (#301) - Seeding no longer depends on reading files at runtime. - **Unsaved changes toast lifecycle fix** (#301) - Toast dismisses only when hasChanges flips to false. - **Brand identity favicon in chat tool blocks** (#307) - Dynamic tool icons show brand favicon when available. - **Modal dialog unification** - Consistent chrome for schedule, content, and event creation with matching ResponsiveDialog, footer status, and validation patterns. - **TCC tracing for AI SDK runs** (#324) - Added observability for agent execution. - **Offline-first Databuddy analytics** - Masking slugs and skipping reserved routes in telemetry. - **Better-auth integration improvements** - Session context from request headers; organization context resolved for redirects. ### Documentation - **Switched docs to Luma** - Restructured with Guides, API Reference, and Devtools sections. Simplified navigation and clearer information hierarchy. - **Added quickstart guide** - Step-by-step setup walkthrough for new users. - **Merged mintlify content** - Integrated concepts, automation, content types, organization, webhooks, and API reference pages. - **llms.txt discovery** - Advertises /llms.txt and /llms-full.txt on every page for AI agent discoverability. - **RSS 2.0 feed for blog** - Auto-discovery via Atom link tag in page head. - **Removed em dashes from docs** - Replaced with standard punctuation throughout all documentation files. ### Integration API, Billing, and Analytics URL: https://www.usenotra.com/changelog/notra/integration-api-billing-and-analytics.md Date: 2026-04-07T09:01:07.589Z This week brought three major additions to Notra: the ability to delete integrations via API, a restructured billing model with trial periods and credit top-ups, and better analytics tracking for content generation workflows. Development teams can now manage their GitHub and Linear connections programmatically, while teams exploring Notra have access to a 14-day trial on the new Basic plan. Analytics improvements let us track whether content is being generated automatically or manually, helping teams understand their usage patterns. ## Highlights ### Programmatic integration deletion You can now delete GitHub or Linear integrations directly via API with a new `DELETE /integrations/{integrationId}` endpoint that automatically disables and unschedules any related automation triggers. (Author: [@mezotv](https://github.com/mezotv/)) ### Billing restructure with trial periods and credit top-ups The free plan is now Basic, available as a 14-day trial with options to purchase additional AI credits in preset amounts. This gives new teams time to evaluate Notra before committing to a paid plan. (Author: [@mezotv](https://github.com/mezotv/)) ### Customer portal access for subscription management Users can now manage their active subscriptions directly from the billing page without leaving Notra, improving the self-service experience for teams on paid plans. ### Analytics tracking for content generation modes We now distinguish between automatic (scheduled or event-driven) and manual content generation in our analytics, helping you understand which workflows your team relies on most. (Author: [@mezotv](https://github.com/mezotv/)) ## More Updates ### Features & Enhancements - **Add customer portal button to billing page**[#224](https://github.com/usenotra/notra/pull/224) - Allows subscription management without leaving the app. (Author: [@mezotv](https://github.com/mezotv/)) ### Infrastructure - **Disable routine Dependabot updates** - Reduces noise in the repository while keeping security updates on schedule. ### Async API, write-scoped keys, Framer integration URL: https://www.usenotra.com/changelog/notra/async-api-write-scoped-keys-framer-integration.md Date: 2026-03-22T09:01:46.193Z Over the past week, we shipped async API endpoints for content generation, write-scoped API keys with granular permissions, and security improvements. Developers can now trigger content generation in the background, poll job status, and integrate generation directly into their workflows. This enables scheduled content jobs, batch operations, and automation pipelines. We also added Framer integration with an interactive four-step setup, improved brand voice consistency across all generated content types, and added API security headers to protect against common vulnerabilities. You can now connect public GitHub repositories without requiring personal access tokens, edit your own API tokens from settings, and manage access permissions at a granular level. ## Highlights ### Async API content generation with job polling Trigger content generation asynchronously and check job status in your own workflows. Enables scheduled content, batch operations, and seamless integration into automation tooling. ### Write-scoped API keys and post deletion Create read-only or read-write API keys with granular permissions. The new DELETE endpoint lets you remove posts programmatically. ### Framer integration Connect Notra to Framer projects with an interactive setup guide. Generate content right from your Framer workspace in four steps. ### Brand voice consistency across content types Your brand voice is now enforced across all generated content, from changelogs to blog posts to social updates. ### API security headers Added HTTP security headers to protect API responses against common web vulnerabilities. ## More Updates ### Features & Enhancements - **Connect public GitHub repos without a token** - Use any public repository without needing personal access tokens. - **Searchable brand voice selector** - Replaced the dropdown with a searchable combobox for faster lookup when managing multiple voices. (Author: [@mezotv](https://github.com/mezotv/)) - **Edit your own API tokens** - Rotate or update authentication tokens directly from settings. ### Infrastructure - **Extract AI logic into shared packages/ai**[#207](https://github.com/usenotra/notra/pull/207) - Refactored all AI agents, prompts, tools, and utilities into a dedicated module for code reuse across dashboard and API. (Author: [@mezotv](https://github.com/mezotv/)) - **Autumn SDK v2 migration** - Upgraded to Autumn v2 for improved compatibility with the latest SDK features. ### On-Demand Content Generation with Fine-Grained Control URL: https://www.usenotra.com/changelog/notra/on-demand-content-generation-with-fine-grained-control.md Date: 2026-03-13T23:29:10.418Z This week shipped features that give teams much better control over content generation. You can now generate changelogs, blog posts, and tweets on-demand while picking exactly which commits, PRs, and releases to include. Brand voice imports pull directly from your X accounts via OAuth, and there's a new blog generator for longer-form storytelling across four tones. Triggers can auto-publish instead of always creating drafts, saving manual review work. We also made generation progress visible with skeleton cards, added a fail tool so agents tell you why they can't generate, and improved error logging throughout the dashboard. ## Highlights ### On-demand content with selective source filtering Generate changelogs, blog posts, and tweets on-demand. Choose which commits, PRs, and releases to include, and set a custom lookback window per generation. ### Multi-source brand voice import via Twitter OAuth Import tweet examples directly from connected X accounts, with pinned tweets prioritized first. Add custom text references alongside imports. ### Blog post generator with narrative tones New output type for long-form storytelling. Choose from casual, conversational, professional, or formal tones, separate from changelog format. ### Instant publish toggle for triggers Schedules can now auto-publish generated content instead of always creating drafts, cutting manual review for teams running frequent generations. ### Multiple social posts per generation Twitter and LinkedIn agents create multiple distinct drafts from a single run when the data warrants it. Workflow notifications list all created posts. ## More Updates ### Features & Enhancements - **Support multiple social posts per generation**[#198](https://github.com/usenotra/notra/pull/198) - Twitter and LinkedIn agents can create multiple drafts from a single run with updated workflow notifications. (Author: [@mezotv](https://github.com/mezotv/)) - **Add instant publish toggle for triggers**[#205](https://github.com/usenotra/notra/pull/205) - Enable auto-publish on schedules and event triggers for immediate post creation with "published" status. (Author: [@mezotv](https://github.com/mezotv/)) - **Warn about affected triggers when deleting brand voice**[#197](https://github.com/usenotra/notra/pull/197) - Prevent orphaned schedules by disabling triggers that reference a deleted voice, with a preview shown before deletion. (Author: [@mezotv](https://github.com/mezotv/)) - **Add connected accounts section to settings**[#194](https://github.com/usenotra/notra/pull/194) - View and manage connected X/Twitter accounts directly in organization settings with one-click disconnect. (Author: [@mezotv](https://github.com/mezotv/)) - **Track active content generations with skeleton cards**[#196](https://github.com/usenotra/notra/pull/196) - See real-time progress for running generators on dashboard and content pages via skeleton placeholders and toast notifications. (Author: [@mezotv](https://github.com/mezotv/)) ### Developer Experience - **Add fail tool for AI agents**[#195](https://github.com/usenotra/notra/pull/195) - Agents gracefully fail with a reason shown in logs and emails when no data is available. (Author: [@mezotv](https://github.com/mezotv/)) - **Improve logs UI and add error visibility**[#195](https://github.com/usenotra/notra/pull/195) - Error messages display under log entry titles, actions column added with reference ID copy, integration type labeling fixed. (Author: [@mezotv](https://github.com/mezotv/)) - **Add getBrandReferences tool to all AI agents**[#188](https://github.com/usenotra/notra/pull/188) - All agents call the brand voice API first to match your writing style before generating. (Author: [@mezotv](https://github.com/mezotv/)) ### Bug Fixes - **Fix webhook logging for on-demand content** - On-demand content now appears in Logs page after creation. (Author: [@mezotv](https://github.com/mezotv/)) - **Split missing header vs unsupported event type in webhook handler** - Clearer error logging helps distinguish config issues from actual unsupported events. - **Fix API content routes with org-scoped keys**[#204](https://github.com/usenotra/notra/pull/204) - API routes properly align with org-scoped API keys. ### Infrastructure - **Use Bun in Docker image**[#203](https://github.com/usenotra/notra/pull/203) - Docker builds now use Bun for faster startup times. - **Expose environment port for deployment**[#203](https://github.com/usenotra/notra/pull/203) - Server reads port from process.env for cloud deployments. - **Changelog and Showcase refactor**[#199](https://github.com/usenotra/notra/pull/199) - Marketing site displays product changelog using Notra's own SDK with timeline view and detail pages. (Author: [@mezotv](https://github.com/mezotv/)) ## Example Company Changelogs ## Assistant UI: Assistant UI Changelog - March 8-15, 2026 URL: https://www.usenotra.com/changelog/assistant-ui/react-ink-react-native-and-template-reliability.md Date: 2026-03-15 Over the past week, we've been shipping hard on multi-platform support, reliability improvements, and template polish. React developers and teams building AI chat interfaces got several meaningful upgrades, including better cross-platform component APIs, new building blocks for terminal apps, and fixes that squash real bugs in production scenarios. ## Highlights ### React Ink now gets ErrorPrimitive for better error handling We added a missing piece to the React Ink toolkit - the ErrorPrimitive component. If you're building terminal chat UIs, this gives you a clean way to display tool errors and validation failures in the same way the web components do. ### react-ink-markdown joins the toolkit as a standalone package Rendering Markdown in terminal interfaces just got simpler. The new package works with React Ink and gives you a markdown renderer that feels native to the terminal, without wrestling with a web component library. ### React Native's component API got a complete refactor The component API for React Native is now more consistent with the web components. This means less mental overhead switching between platforms and better code reuse across your web and mobile implementations. ### Templates actually work with AssistantChatTransport now The with-ai-sdk-v6 example and starter templates were out of sync. We rewrote them so the backend correctly handles system prompts and tool forwarding from the client - making the example match what the docs promise. ### Prevent accidental double-submit on form interactions Added a guard that stops duplicate message sends when users rapidly interact with the input. This is a small fix with big reliability impact for production apps. ## More Updates ### Features & Enhancements - **Multi-agent support** - Build apps that coordinate multiple AI agents in conversation threads - **resumeRun moved to stable** - The API for resuming interrupted assistant runs is no longer marked experimental - **Heat graph component** - New visualization component for displaying metrics and patterns over time - **React Ink and React Native runtime support** - Official support for both platforms in the core package - **React Ink ToolFallback component** - Dedicated component for rendering when tool execution fails in terminal contexts - **Brand page and footer link** - New pages for company branding and information - **New quote component in registry** - Added to the component registry for testimonials and callouts ### Bug Fixes - **Fixed attachment tile rendering** - Removed duplicate DOM IDs and corrected the attachment source check across all templates - **LangGraph proxy now preserves CORS** - Fixed cross-origin browser support while safely stripping encoding headers in the proxy route - **CLI project creation is more robust** - Safer plugin resolution, correct transform sequencing, and better error messages - **Removed invalid interactive nesting in Clerk template** - Fixed accessible markup issues in the cloud-clerk starter - **Template links now have proper rel attributes** - Added rel="noopener noreferrer" to external links in threadlist sidebars - **Removed unused animation dependencies** - Cleaned up framer-motion from templates that weren't using it - **Fixed docs header breakpoints and nav links** - Responsive header now displays correctly and includes all navigation items - **User-Agent header now allowed in docs** - Unblocked requests that include this common header ### Testing & Reliability - **Regression test for Vite compatibility** - Added a test that catches unguarded process.env access, which was crashing all Vite users and got reintroduced twice - **Core no longer requires Zod at runtime** - Removed the static Zod import that was breaking non-Node environments even though it was marked optional; now uses Standard Schema duck-typing instead ### Documentation & Examples - **Updated with-ai-sdk-v6 example** - Docs, env vars, and metadata now match the OpenAI-based implementation - **Cloud redesign blog post** - New blog entry documenting the Assistant UI Cloud updates - **Cloud AI SDK docs** - Launched standalone persistence hooks documentation - **React Native landing page** - New dedicated page for React Native support and guides - **React Ink docs** - Documentation for building terminal chat interfaces - **Added new testimonials** - Neon, Y Combinator, yagudaev, and VoltAgent logos on the homepage - **SVG logo compatibility fixes** - All 10 company logos now work reliably on GitHub by converting text to paths and removing incompatible SVG features - **Docs SVG optimization** - Reduced SVG payload across docs by 14KB using SVGO - **Fixed README logo rendering** - Increased display height for readability and added proper link targets ### Infrastructure & CI - **Semver check with cascade analysis** - New CI gate that detects breaking version bumps and analyzes downstream impact on dependent packages, with environment-based approval flow - **Enhanced release summary** - Pre-publish workflow that shows version changes, breaking bumps, downstream impact, and included commits for the exact release SHA - **Version PR unblocked from Semver Check** - Added synthetic passing check for the changesets bot-generated version PR which couldn't trigger workflows naturally - **Excluded .next/dev from Turbo build cache** - CI build artifacts now exclude the dev cache directory - **Improved CI for development dependencies** - Better handling of dependency updates in CI workflows - **Removed fork PR review support from Claude Code Review** - Security hardening to prevent unintended code review on untrusted forks - **Expo CI workflow** - New CI coverage for React Native Expo example - **Added EXPO_PUBLIC_CHAT_ENDPOINT_URL environment variable** - Required env var for the Expo example is now set in CI ### Platform Improvements - **Consolidation of runtime implementations** - Refactored platform-specific code to reduce duplication across React, React Native, React Ink, and Expo - **Updated Expo example** - Now uses react-ai-sdk and includes tool UI components - **Examples integration endpoint** - Added API endpoint configuration to examples for proper LLM backend integration ## cmux: cmux Changelog - March 8-15, 2026 URL: https://www.usenotra.com/changelog/cmux/claude-lifecycle-fixes-workspace-close-behavior-and-themes.md Date: 2026-03-15 Version 0.62.2 brings substantial improvements to workspace management, sidebar customization, and theme support. The release fixes stale Claude sidebar status with better lifecycle tracking and PID-aware cleanup, resolves critical window closing behavior so Cmd+W properly closes workspaces and windows, and adds a new `cmux themes` command for interactive theme management with persistent overrides. You can now adjust sidebar width constraints for more compact layouts, search across all surfaces with enhanced Cmd+P functionality, and enjoy improved dictation support and clipboard handling for image pasting. Bug fixes address command palette navigation, socket listener reliability, workspace creation crashes, and cwd inheritance in splits. The release also enhances settings UI clarity, adds Discord community links, and includes better error recovery for daemon RPC calls with throttled restart logic. ## Highlights ### Claude sidebar status lifecycle and stale process cleanup Fix persistent "Needs input" and permission-grant statuses with new lifecycle hooks, PID-aware tracking, and a 30-second sweep timer to clear dead processes. ### Cmd+W closes workspaces and windows as expected Explicit close gestures (Cmd+W, tab X button) now close the workspace and window when closing the last terminal, while internal closes (process exit, panel moves) keep the workspace alive with a replacement shell. ### Interactive cmux themes command New `cmux themes` CLI with list, set, clear operations; interactive picker with live preview; persistent light/dark overrides stored in Application Support with hot-reload. ### Socket listener falls back to user-scoped path Socket moves to Application Support with automatic fallback to per-user `/tmp/cmux-.sock` on permission errors; improves reliability across different system states. ### Smaller sidebar widths with centralized clamping Reduce sidebar minimum from 186 to 180 pixels for more compact layouts; unified drag and persistence clamping prevents inconsistent behavior. ## More Updates ### Bug Fixes - **Fix stale Claude sidebar status: add missing hooks, OSC suppression, PID sweep** [#1306](https://github.com/manaflow-ai/cmux/pull/1306) - Injects 6 hooks covering full Claude lifecycle; adds PID tracking with 30s stale-process sweep; suppresses duplicate OSC notifications when Claude is active. (Author: [@lawrencecchen](https://github.com/lawrencecchen/)) - **Make Cmd+W close window when closing last terminal** [#1395](https://github.com/manaflow-ai/cmux/pull/1395) - Cmd+W and tab X button now close the workspace on last surface; internal closes spawn replacement shell. (Author: [@austinywang](https://github.com/austinywang/)) - **Fix split cwd inheritance while shell cwd is stale** [#1403](https://github.com/manaflow-ai/cmux/pull/1403) - Preserves split cwd when shell cwd hasn't updated yet. (Author: [@austinywang](https://github.com/austinywang/)) - **Fix crash when creating a new workspace** [#1391](https://github.com/manaflow-ai/cmux/pull/1391) - Snapshot TabManager state at workspace creation start to prevent Combine-backed re-entrant publishes. (Author: [@austinywang](https://github.com/austinywang/)) - **Honor shell state for close confirmation** [#1386](https://github.com/manaflow-ai/cmux/pull/1386) - Close confirmation respects actual shell state instead of cached status. (Author: [@lawrencecchen](https://github.com/lawrencecchen/)) - **Fix omnibar backspace/arrow key loss after prefix deletion** [#1413](https://github.com/manaflow-ai/cmux/pull/1413) - Replace SwiftUI TextField with AppKit NSTextField for omnibar so navigation commands survive prefix scope changes. (Author: [@austinywang](https://github.com/austinywang/)) - **Fix macOS dictation NSTextInputClient conformance** [#1410](https://github.com/manaflow-ai/cmux/pull/1410) - Restore proper dictation support and caret rect anchoring. (Author: [@lawrencecchen](https://github.com/lawrencecchen/)) - **Fix terminal Cmd+V clipboard payload handling** [#1305](https://github.com/manaflow-ai/cmux/pull/1305) - Support RTFD attachments, JPEG UTIs, and fallback payloads for robust image pasting. (Author: [@lawrencecchen](https://github.com/lawrencecchen/)) - **Fix VS Code command palette to open desktop app** [#1389](https://github.com/manaflow-ai/cmux/pull/1389) - Correct target for VS Code integration. (Author: [@austinywang](https://github.com/austinywang/)) - **Fix main CI regressions** [#1458](https://github.com/manaflow-ai/cmux/pull/1458) - Dynamic text input selector for Xcode 16.2 compatibility; refresh app-support config tests. (Author: [@lawrencecchen](https://github.com/lawrencecchen/)) - **Fix bundled Ghostty theme picker helper packaging** [#1459](https://github.com/manaflow-ai/cmux/pull/1459) - Build and bundle universal Ghostty helper in release builds so `cmux themes` works in shipped versions. (Author: [@lawrencecchen](https://github.com/lawrencecchen/)) - **Fix crash when adding a workspace into an orphaned window context** [#1380](https://github.com/manaflow-ai/cmux/pull/1380) - Skip orphaned workspace creation contexts. (Author: [@lawrencecchen](https://github.com/lawrencecchen/)) ### Features & Enhancements - **Add cmux themes command** [#1334](https://github.com/manaflow-ai/cmux/pull/1334) - New `cmux themes list/set/clear` CLI with interactive picker, live preview, separate light/dark defaults, and persistent override stored in Application Support with hot-reload. (Author: [@lawrencecchen](https://github.com/lawrencecchen/)) - **Fallback stable socket listener to a user-scoped path** [#1351](https://github.com/manaflow-ai/cmux/pull/1351) - Socket moves to Application Support; falls back to per-user path on bind failure; keeps active path in health checks to prevent false unhealthy states. (Author: [@lawrencecchen](https://github.com/lawrencecchen/)) - **Allow smaller sidebar widths** [#1420](https://github.com/manaflow-ai/cmux/pull/1420) - Lower minimum from 186 to 180 px; unify drag and persisted-width clamping for consistent behavior. (Author: [@lawrencecchen](https://github.com/lawrencecchen/)) - **Add Cmd+P all-surface search option** [#1382](https://github.com/manaflow-ai/cmux/pull/1382) - Search across all surfaces from command palette. (Author: [@lawrencecchen](https://github.com/lawrencecchen/)) - **Exit split zoom when jumping to unread** [#1401](https://github.com/manaflow-ai/cmux/pull/1401) - Cmd+Shift+U now exits split zoom mode. (Author: [@lawrencecchen](https://github.com/lawrencecchen/)) - **Fix command palette command-mode shortcut and navigation** [#1417](https://github.com/manaflow-ai/cmux/pull/1417) - Correct arrow key handling in command mode. (Author: [@austinywang](https://github.com/austinywang/)) - **Bundle Ghostty themes in cmux** [#1314](https://github.com/manaflow-ai/cmux/pull/1314) - Bundle Ghostty themes alongside the app. (Author: [@lawrencecchen](https://github.com/lawrencecchen/)) - **Fix Pure prompt duplication in Ghostty zsh integration** [#1316](https://github.com/manaflow-ai/cmux/pull/1316) - Fix Pure hidden-CR prompt redraw issues. (Author: [@lawrencecchen](https://github.com/lawrencecchen/)) - **Add subtitle to App Icon setting to clarify it's not a theme toggle** [#1367](https://github.com/manaflow-ai/cmux/pull/1367) - Adds "Dock and app switcher" subtitle and visual appearance picker with thumbnail previews; helps users distinguish from theme toggle. (Author: [@lawrencecchen](https://github.com/lawrencecchen/)) - **Keep workspaces open when closing the last surface** [#1315](https://github.com/manaflow-ai/cmux/pull/1315) - Internal/programmatic closes spawn replacement shell. (Author: [@lawrencecchen](https://github.com/lawrencecchen/)) - **Add minimal sidebar detail toggles** [#1312](https://github.com/manaflow-ai/cmux/pull/1312) - New settings for sidebar detail visibility. (Author: [@lawrencecchen](https://github.com/lawrencecchen/)) - **Add settings to disable pane ring and flash** [#1217](https://github.com/manaflow-ai/cmux/pull/1217) - Toggles for unread pane ring and pane flash notifications. (Author: [@lawrencecchen](https://github.com/lawrencecchen/)) - **Add menu bar visibility setting** [#1330](https://github.com/manaflow-ai/cmux/pull/1330) - Option to hide cmux from the menu bar. (Author: [@lawrencecchen](https://github.com/lawrencecchen/)) - **Summarize multi-workspace close confirmation** [#1329](https://github.com/manaflow-ai/cmux/pull/1329) - Better confirmation text when closing multiple workspaces; honors sidebar multi-select. (Author: [@lawrencecchen](https://github.com/lawrencecchen/)) - **Include current_directory and custom_color in list-workspaces output** [#544](https://github.com/manaflow-ai/cmux/pull/544) - Expose workspace working directory and tab color in CLI output. (Author: [@arieltobiana](https://github.com/arieltobiana/)) - **Add VoiceOver traits to pickers, reorder settings** [#1372](https://github.com/manaflow-ai/cmux/pull/1372) - Improved accessibility; reorder settings. (Author: [@lawrencecchen](https://github.com/lawrencecchen/)) - **Add Discord link to help menu** [#1366](https://github.com/manaflow-ai/cmux/pull/1366) - Link to community server. (Author: [@lawrencecchen](https://github.com/lawrencecchen/)) - **Add /nightly page** [#1378](https://github.com/manaflow-ai/cmux/pull/1378) - Localized nightly build landing page for all 18 locales. (Author: [@lawrencecchen](https://github.com/lawrencecchen/)) ### Infrastructure - **Throttle repeated socket listener start failures** [#1415](https://github.com/manaflow-ai/cmux/pull/1415) - Avoid thrashing on daemon RPC startup failures. (Author: [@lawrencecchen](https://github.com/lawrencecchen/)) - **Tag CLI Sentry events with app release** [#1408](https://github.com/manaflow-ai/cmux/pull/1408) - Better error tracking. (Author: [@lawrencecchen](https://github.com/lawrencecchen/)) - **Fix GhosttyKit checksum drift in CI** [#1405](https://github.com/manaflow-ai/cmux/pull/1405) - Prevent checksum regressions. (Author: [@lawrencecchen](https://github.com/lawrencecchen/)) - **Share last-surface close flow between X and Cmd+W** [#1346](https://github.com/manaflow-ai/cmux/pull/1346) - Unified code path. (Author: [@lawrencecchen](https://github.com/lawrencecchen/)) - **Add workspace stress profiling and reduce switch churn** [#1218](https://github.com/manaflow-ai/cmux/pull/1218) - Performance optimization. (Author: [@lawrencecchen](https://github.com/lawrencecchen/)) - **Fix internal drag regressions from bundle type declarations** [#1379](https://github.com/manaflow-ai/cmux/pull/1379) - Restore internal drag type exports. (Author: [@lawrencecchen](https://github.com/lawrencecchen/)) - **Build only universal nightly artifacts** [#1332](https://github.com/manaflow-ai/cmux/pull/1332) - CI optimization. (Author: [@lawrencecchen](https://github.com/lawrencecchen/)) ## Sim: Sim Changelog - March 8-15, 2026 URL: https://www.usenotra.com/changelog/sim/google-ads-ashby-webhooks-and-fathom-ai.md Date: 2026-03-15 This week brought three new integrations, critical security patches, and solid improvements across webhook reliability. Google Ads and Fathom AI are now available for workflows, Ashby webhooks finally work, and we patched some serious SSRF vulnerabilities. There's also a batch of fixes for block duplication, internal workflow calls, and various integrations. ## Highlights ### Google Ads integration for campaign and performance data Pull campaign and ad metrics directly into your workflows using GAQL queries. Full OAuth support and input validation included. ([#3360](https://github.com/simstudioai/sim/pull/3360)) ### Ashby webhooks for real-time hiring events Capture application submissions, stage changes, and offers as workflow triggers. Webhook setup and teardown happen automatically. ([#3548](https://github.com/simstudioai/sim/pull/3548)) ### Fathom AI Notetaker integration Record and analyze meetings, extract action items, and match them to your CRM. ([#3531](https://github.com/simstudioai/sim/pull/3531)) ### Webhook deduplication and custom acknowledgment Prevent duplicate processing with idempotency keys and configure how webhooks acknowledge receipt. ([#3525](https://github.com/simstudioai/sim/pull/3525)) ### SSRF security fixes for database and webhook tools Blocked Server-Side Request Forgery attacks on database connections and webhook endpoints. Localhost is properly blocked for user-supplied URLs, and redirects are validated. ([#3500](https://github.com/simstudioai/sim/pull/3500)) ## More Updates ### Security - **SSRF protection on redirects** - HTTP redirect validation now enforces the same SSRF rules as the initial request. (Author: [@waleedlatif1](https://github.com/waleedlatif1/)) ### Features & Enhancements - **Non-polling webhooks off trigger.dev** [#3527](https://github.com/simstudioai/sim/pull/3527) - Faster webhook handling without an external dependency. (Author: [@icecrasher321](https://github.com/icecrasher321/)) - **Slack tools include email addresses** [#3509](https://github.com/simstudioai/sim/pull/3509) - Get user and list users now return email for matching users across your workspace. (Author: [@waleedlatif1](https://github.com/waleedlatif1/)) - **Jira search returns full issue data** [#3544](https://github.com/simstudioai/sim/pull/3544) - Search/JQL endpoint now includes all fields by default instead of just IDs. (Author: [@waleedlatif1](https://github.com/waleedlatif1/)) - **Grain integration updated** [#3556](https://github.com/simstudioai/sim/pull/3556) - Switched to stable API version and improved webhook verification. (Author: [@icecrasher321](https://github.com/icecrasher321/)) ### Bug Fixes - **Fixed block duplication remapping** [#3533](https://github.com/simstudioai/sim/pull/3533) - Duplicating, copying, or importing workflows now correctly updates condition and router block IDs so edges connect properly. (Author: [@waleedlatif1](https://github.com/waleedlatif1/)) - **Fixed internal workflow Response blocks** [#3551](https://github.com/simstudioai/sim/pull/3551) - Child workflow calls now receive standard success/output format instead of hijacked response data. (Author: [@waleedlatif1](https://github.com/waleedlatif1/)) - **Fixed trace span metadata from condition blocks** [#3534](https://github.com/simstudioai/sim/pull/3534) - Condition blocks no longer leak agent timing, token counts, or costs into the trace. (Author: [@waleedlatif1](https://github.com/waleedlatif1/)) - **Fixed Gmail RFC 2047 encoding** [#3526](https://github.com/simstudioai/sim/pull/3526) - Long email subjects with non-Latin characters now encode correctly. (Author: [@waleedlatif1](https://github.com/waleedlatif1/)) - **Fixed Jira issue key field** [#3547](https://github.com/simstudioai/sim/pull/3547) - Manual issue key input no longer clears when you change projects. (Author: [@waleedlatif1](https://github.com/waleedlatif1/)) - **Fixed Slack webhook modal responses** [#3492](https://github.com/simstudioai/sim/pull/3492) - Returning an empty 200 response now closes modals cleanly. (Author: [@waleedlatif1](https://github.com/waleedlatif1/)) - **Removed redundant webhook database queries** [#3523](https://github.com/simstudioai/sim/pull/3523) - Webhook execution no longer unnecessarily looks up credentials multiple times. (Author: [@waleedlatif1](https://github.com/waleedlatif1/)) ### Infrastructure - **Canvas middle-mouse panning** [#3542](https://github.com/simstudioai/sim/pull/3542) - Pan the workflow canvas using the middle mouse button in cursor mode. (Author: [@waleedlatif1](https://github.com/waleedlatif1/)) ### Internal Changes - **Parallel AI integration updated** [#3501](https://github.com/simstudioai/sim/pull/3501) - Updated to match the latest API schema. (Author: [@waleedlatif1](https://github.com/waleedlatif1/)) - **Condition ID code clarity** [#3546](https://github.com/simstudioai/sim/pull/3546) - Made the hyphen separator explicit in condition ID handling. (Author: [@waleedlatif1](https://github.com/waleedlatif1/)) ## Airweave: Airweave Changelog - March 7-14, 2026 URL: https://www.usenotra.com/changelog/airweave/connect-widget-sharepoint-online-and-github-prs.md Date: 2026-03-14 This release adds Airweave Connect, a new embeddable widget for integrating data source connections directly into your application, alongside major connector expansions and monitoring improvements. The Connect playground gives you a live sandbox for configuration and code generation. SharePoint Online is now fully supported with ACL extraction and targeted browsing and sync. The GitHub connector can now index merged pull requests and review comments. Temporal heartbeats carry structured progress data instead of strings, giving you better visibility into sync operations. ## Highlights ### Airweave Connect: Embeddable widget and session API Developers can now embed interactive data source connection flows directly in their apps. The Connect widget handles OAuth flows, folder/site selection, and real-time sync with minimal setup. New APIs support session management, connection creation, and analytics tracking. Full customization for theme, branding, and allowed integrations. ### SharePoint Online connector with ACL and browse tree Native SharePoint Online support via Microsoft Graph with per-file access control lists. Users can browse and select specific sites, drives, and folders before syncing instead of ingesting everything. Includes Entra ID and SharePoint site group expansion with cycle detection. Incremental sync via per-drive delta tokens preserves bandwidth. ### GitHub merged PRs and review comments The GitHub connector now indexes merged pull requests, inline review comments, and changed file lists. New `sync_pull_requests` config flag (default off) enables optional PR syncing. Incremental cursor tracks the last updated PR timestamp for efficient updates. ### Temporal activity heartbeats with structured progress data Heartbeat payloads now carry phase, elapsed time, entity counts (inserted, updated, deleted, kept), and optional stall detection instead of opaque strings. Improves debugging visibility in the Temporal UI and preserves context on activity failure. ### Connect Playground: Interactive configuration and code generation Live preview environment for testing the Connect widget with adjustable theme, session mode, collection picker, and source filters. Export configuration as Python, TypeScript, React, or Vanilla JS snippets with a single click. Also exportable as Markdown, llms.txt, Cursor Rules, or Claude format. ## More Updates ### Features & Enhancements - **Boolean config fields render as toggles** [#1582](https://github.com/airweave-ai/airweave/pull/1582) - Source configuration UI now displays boolean settings (like `sync_pull_requests`) as toggle switches instead of text inputs, improving usability. (Author: [@felixschmetz](https://github.com/felixschmetz/)) - **Zoom connector OAuth client ID configured** [#1590](https://github.com/airweave-ai/airweave/pull/1590) - Zoom connector now has dev environment OAuth credentials set, enabling local testing. (Author: [@viralpraxis](https://github.com/viralpraxis/)) ### Bug Fixes - **Fixed Auth0 pagination in user sync** [#1587](https://github.com/airweave-ai/airweave/pull/1587) - Management API pagination now handles users with 50+ organization memberships correctly using per_page=100 and iteration through all pages. (Author: [@orhanrauf](https://github.com/orhanrauf/)) - **Fixed user refresh selectinload preventing 422 on login** [#1583](https://github.com/airweave-ai/airweave/pull/1583) - Login now uses explicit selectinload queries instead of bare refresh, preventing failed organization serialization. (Author: [@orhanrauf](https://github.com/orhanrauf/)) - **Deep-copy entities before embedding to avoid mutation race** [#1605](https://github.com/airweave-ai/airweave/pull/1605) - Fixed concurrent execution bug where ChunkEmbedProcessor mutations corrupted entity data in parallel handlers. (Author: [@felixschmetz](https://github.com/felixschmetz/)) - **Fixed MissingGreenlet in async ORM operations** [#1588](https://github.com/airweave-ai/airweave/pull/1588) - Snapshot ORM scalars before UoW commits to prevent lazy-load access after expiration in org membership and user provisioning flows. (Author: [@orhanrauf](https://github.com/orhanrauf/)) - **Fixed Connect test page URL detection** [#1616](https://github.com/airweave-ai/airweave/pull/1616) - Test page now derives iframe and API URLs from hostname instead of hardcoding localhost, enabling deployment to non-localhost environments. (Author: [@orhanrauf](https://github.com/orhanrauf/)) - **Removed incorrect Connect CORS origin** [#1615](https://github.com/airweave-ai/airweave/pull/1615) - Dropped non-existent connect.airweave.ai subdomain from CORS allowlist, keeping only the valid app.airweave.ai production origin. (Author: [@orhanrauf](https://github.com/orhanrauf/)) ### Infrastructure - **Migrated Python runtime to 3.13** [#1534](https://github.com/airweave-ai/airweave/pull/1534) - Updated all Dockerfiles, CI, and `pyproject.toml` to Python 3.13 for toolchain consistency and modern async features. (Author: [@hiddeco](https://github.com/hiddeco/)) - **Auth0 user ID updated on login instead of 409 conflict** [#1581](https://github.com/airweave-ai/airweave/pull/1581) - Removed account conflict error path; email is now the source of truth for user identity and auth0_id is updated on login. (Author: [@orhanrauf](https://github.com/orhanrauf/)) - **Fixed organization feature flag schema validation** [#1579](https://github.com/airweave-ai/airweave/pull/1579) - Unknown feature flags in cached/API responses are now filtered before schema validation, preventing 422 errors on deprecated flags. (Author: [@orhanrauf](https://github.com/orhanrauf/)) ### Internal Changes - **Refactored Temporal service singletons to protocol DI** - Legacy singleton imports in core/temporal_service.py and platform/temporal/schedule_service.py replaced with constructor-injected protocol services across activities and endpoints. - **Simplified processor strategy pattern** - Removed ProcessingRequirement enum and single-valued ContentProcessor indirection; ChunkEmbedProcessor now inlined directly in DestinationHandler. - **Eliminated source table and db_sync** - Source definitions now served exclusively from in-memory SourceRegistry; removed database table, CRUD layer, and runtime sync. - **Enhanced source and collection repositories with injected dependencies** - Moved collection status computation and ephemeral attachment into repository layer using injected SourceRegistry for federated lookups. ## Char: Char Changelog - March 7-14, 2026 URL: https://www.usenotra.com/changelog/char/onboarding-polish-image-previews-and-meeting-summaries.md Date: 2026-03-14 Over the past week, we've focused on improving your onboarding experience, tightening up audio handling in the desktop app, and shipping a bunch of behind-the-scenes improvements to make note-taking and meeting summaries work better. Whether you're just getting started or managing thousands of notes, this batch brings real workflow improvements for privacy-focused teams. ## Highlights ### Polished onboarding with permission clarity and visual design The onboarding flow now shows exactly what permissions Char needs and why, with task-based copy that replaces generic labels. We added a background video for visual context, refined permission states to show what's done versus what still needs action, and made the Apple Calendar connection flow clearer so you know exactly what you're authorizing. ### Images in session previews and resizable image nodes You can now see images right in your session preview cards without opening the full note. Blog and desktop editors both now support resizable images with persistent width settings, so your visual layouts stay consistent as you move between editing and published views. ### Better live transcription streaming without data leaks Fixed an issue where starting a new recording back-to-back could leave stray transcript data from the previous session. The desktop app now properly cleans up state when you stop and start recording again. ### Improved AI meeting summaries with topic-specific sections Your meeting notes now get better AI-generated section headers. We told the system to stop using generic section names like "Overview" and instead generate actual topic titles that reflect what you discussed. Your summaries read more like real notes now, less like templates. ### Desktop settings redesigned as your primary settings home App settings are now the main settings view on desktop. Account and billing controls moved to the top of the app settings page, so you've got one clear place to manage everything without bouncing between tabs. ## More Updates ### Features & Enhancements - **Support multiple calendar connections at once** [#4481](https://github.com/fastrepl/char/pull/4481) - You can now connect multiple calendar accounts and sync from all of them. (Author: [@goranmoomin](https://github.com/goranmoomin/)) - **Add calendar button with future items indicator** [#4508](https://github.com/fastrepl/char/pull/4508) - A floating button appears when you scroll back to the top and have upcoming events, giving you quick access to your calendar view. (Author: [@ComputelessComputer](https://github.com/ComputelessComputer/)) - **Refresh drafts after creating a new post** [#4526](https://github.com/fastrepl/char/pull/4526) - New blog posts and articles show up immediately without a manual page refresh. (Author: [@ComputelessComputer](https://github.com/ComputelessComputer/)) - **Normalize blog markdown imports and YouTube embeds** [#4527](https://github.com/fastrepl/char/pull/4527) - YouTube embeds from Google Docs now import cleanly, and underlined links stop getting mangled. (Author: [@ComputelessComputer](https://github.com/ComputelessComputer/)) - **Improved header listen button styling** [#4522](https://github.com/fastrepl/char/pull/4522) - The listen button is slightly larger with better visual feedback. (Author: [@ComputelessComputer](https://github.com/ComputelessComputer/)) - **Chat header handles longer titles without overflow** [#4506](https://github.com/fastrepl/char/pull/4506) - Long chat group names truncate cleanly instead of breaking the layout. (Author: [@ComputelessComputer](https://github.com/ComputelessComputer/)) - **Cleaner chat auto-scroll control** [#4507](https://github.com/fastrepl/char/pull/4507) - Chat auto-scroll behaves more predictably when you scroll manually. (Author: [@ComputelessComputer](https://github.com/ComputelessComputer/)) ### Bug Fixes - **Deduplicate calendar event participants during sync** [#4521](https://github.com/fastrepl/char/pull/4521) - If you're both the organizer and an attendee, the event no longer creates duplicate participant entries in your note. Also fixed missing self-participant detection when event data is incomplete. (Author: [@ComputelessComputer](https://github.com/ComputelessComputer/)) - **Display Nango connection email addresses in account settings** - You can now see which email addresses are connected for your calendar and integration accounts. (Author: [@goranmoomin](https://github.com/goranmoomin/)) - **Fix admin delete modal styling** [#4574](https://github.com/fastrepl/char/pull/4574) - Admin content deletion now shows proper dialog styling and surfaces any errors with a toast message. (Author: [@ComputelessComputer](https://github.com/ComputelessComputer/)) - **Admin GitHub token refresh on expiry** [#4568](https://github.com/fastrepl/char/pull/4568) - If your GitHub auth expires while you're editing content, you're redirected to sign in and can pick up where you left off. (Author: [@ComputelessComputer](https://github.com/ComputelessComputer/)) - **Fix admin post creation failure handling** [#4550](https://github.com/fastrepl/char/pull/4550) - New post inputs stay open until creation succeeds, and newly created drafts auto-open so you can keep editing. (Author: [@ComputelessComputer](https://github.com/ComputelessComputer/)) - **Prevent organizer duplication in calendar sync** - Calendar events no longer add you twice when you're the organizer but also listed as an attendee. (Author: [@goranmoomin](https://github.com/goranmoomin/)) - **Grammar fix in user tip message** [#4519](https://github.com/fastrepl/char/pull/4519) - Fixed subject-verb agreement in rotating tip text. (Author: [@ComputelessComputer](https://github.com/ComputelessComputer/)) - **Remove non-breaking spaces from session markdown** [#4516](https://github.com/fastrepl/char/pull/4516) - Session exports no longer include stray formatting characters. (Author: [@goranmoomin](https://github.com/goranmoomin/)) - **Prevent session preview during tab close dialog** [#4505](https://github.com/fastrepl/char/pull/4505) - Session cards don't display when you have a tab close confirmation dialog open. (Author: [@ComputelessComputer](https://github.com/ComputelessComputer/)) - **Preserve GIFs in published blog content** [#4556](https://github.com/fastrepl/char/pull/4556) - Animated GIFs no longer get optimized into static images. (Author: [@ComputelessComputer](https://github.com/ComputelessComputer/)) - **Fix note input placeholder styling and hints** [#4510](https://github.com/fastrepl/char/pull/4510) - Note placeholders now clearly explain how your notes guide AI summary generation, with command hints appearing in subsequent paragraphs. (Author: [@ComputelessComputer](https://github.com/ComputelessComputer/)) - **Undo delete toast positioning** [#4513](https://github.com/fastrepl/char/pull/4513) - The undo delete toast and session status message no longer overlap. (Author: [@ComputelessComputer](https://github.com/ComputelessComputer/)) - **Fix publish PR tab opening** [#4557](https://github.com/fastrepl/char/pull/4557) - When you publish a new article, the PR link opens in a new tab correctly. (Author: [@ComputelessComputer](https://github.com/ComputelessComputer/)) - **Correct SelectTrigger alignment in STT provider dropdown** [#4528](https://github.com/fastrepl/char/pull/4528) - Text in the speech-to-text provider selector now aligns properly. (Author: [@ComputelessComputer](https://github.com/ComputelessComputer/)) - **Handle macOS app rename during updates** [#4491](https://github.com/fastrepl/char/pull/4491) - If you're using a nightly build on macOS, the app renames correctly during the Hyprnote-to-Char transition. (Author: [@yujonglee](https://github.com/yujonglee/)) ### Infrastructure - **Move echo cancellation to audio crate with better API** [#4547](https://github.com/fastrepl/char/pull/4547) - Refactored audio echo cancellation (AEC) into a dedicated module with cleaner APIs for desktop and transcription contexts. (Author: [@yujonglee](https://github.com/yujonglee/)) - **Unify media library around a catalog model** [#4558](https://github.com/fastrepl/char/pull/4558) - Admin media library now backs storage assets with a catalog layer that keeps Mux video metadata and fallback paths in sync. (Author: [@ComputelessComputer](https://github.com/ComputelessComputer/)) - **Merge transcribe-cli into apps/cli** - Consolidated CLI tooling for faster builds and simpler maintenance. (Author: [@yujonglee](https://github.com/yujonglee/)) - **Migrate to Vite 8** - Updated build tool for better performance and stability. (Author: [@yujonglee](https://github.com/yujonglee/)) ### Testing - **Add analytics funnel tracking specification** [#4538](https://github.com/fastrepl/char/pull/4538) - Documented user journey tracking across acquisition, onboarding, activation, and subscription conversion stages with PostHog event specs. (Author: [@ComputelessComputer](https://github.com/ComputelessComputer/)) ### Documentation - **Add verification workflow to AGENTS.md** [#4524](https://github.com/fastrepl/char/pull/4524) - Development guidelines now include post-edit verification steps for typecheck and formatting. (Author: [@ComputelessComputer](https://github.com/ComputelessComputer/)) - **Clarify account value proposition copy** [#4540](https://github.com/fastrepl/char/pull/4540) - Rewrote the signed-out account description to focus on hosted AI, sync, personalization, and integrations value. (Author: [@ComputelessComputer](https://github.com/ComputelessComputer/)) - **Replace highlight markup with HTML underlines** [#4541](https://github.com/fastrepl/char/pull/4541) - Updated blog editor and documentation to use standard underline tags instead of custom '++' markup. (Author: [@ComputelessComputer](https://github.com/ComputelessComputer/)) - **Emit HTML underline tags in Tiptap markdown** [#4539](https://github.com/fastrepl/char/pull/4539) - Underline formatting now serializes as proper `` tags for better downstream compatibility. (Author: [@ComputelessComputer](https://github.com/ComputelessComputer/)) ### Internal Changes - **Transcription Rust port and CLI improvements** - Core transcription logic ported to Rust with various CLI refinements. (Author: [@yujonglee](https://github.com/yujonglee/)) - **Extract shared changelog package** - Changelog rendering logic now shared between web and desktop. (Author: [@yujonglee](https://github.com/yujonglee/)) - **Keep Zustand store state during Vite HMR** - Development experience improved during hot reloads. (Author: [@yujonglee](https://github.com/yujonglee/)) - **Transcript tab cleanups and refactors** - Improved organization and clarity of transcript-related code. (Author: [@yujonglee](https://github.com/yujonglee/)) - **UI improvements for timeline and folders** - Various refinements to sidebar and navigation UI. (Author: [@yujonglee](https://github.com/yujonglee/)) ## Confident AI: Confident AI Changelog - March 7-14, 2026 URL: https://www.usenotra.com/changelog/confident-ai/auth-fixes-new-integrations-and-metric-configurability.md Date: 2026-03-14 This week brought fixes for authentication blockers, new integrations, and improved configurability across evaluation metrics. The platform now supports keyless Azure authentication, makes evaluation model selection customizable via environment variables, and adds comprehensive AgentCore framework integration with documentation. ## Highlights ### AzureOpenAI keyless authentication now works correctly Credential validation is now deferred to the OpenAI SDK instead of failing early, allowing Azure AD and managed identity configurations to work as intended. This eliminates a blocker for engineers using keyless authentication patterns in Azure environments. ### Environment variable configuration for evaluation models Evaluation model selection can now be set via environment variables, reducing configuration boilerplate and making it easier to standardize model choices across evaluation jobs. ### AgentCore framework integration and documentation Full integration support for AgentCore with complete documentation and test coverage, enabling teams building agent applications to evaluate their systems within the DeepEval platform. ## More Updates ### Bug Fixes - **Fixed KnowledgeRetentionMetric validation error** [#2513](https://github.com/confident-ai/deepeval/pull/2513) - Corrected double-wrapped Knowledge object unpacking that was causing crashes. (Author: [@dgomez04](https://github.com/dgomez04/)) - **Fixed CrewAI tool handling with unexpected thread pool events** [#2547](https://github.com/confident-ai/deepeval/pull/2547) - Resolved crashes when handling unexpected thread pool event arrivals. (Author: [@A-Vamshi](https://github.com/A-Vamshi/)) ### Features & Enhancements - **Made top_logprobs configurable in ConversationalGEval** [#2549](https://github.com/confident-ai/deepeval/pull/2549) - Added missing configuration option for consistency with GEval. (Author: [@SzymonCogiel](https://github.com/SzymonCogiel/)) - **Removed OpenTelemetry configuration from AgentCore** [#2545](https://github.com/confident-ai/deepeval/pull/2545) - Simplified AgentCore integration and added iterator usage documentation. (Author: [@A-Vamshi](https://github.com/A-Vamshi/)) - **Added comprehensive AgentCore documentation and tests** [#2544](https://github.com/confident-ai/deepeval/pull/2544) - Full integration guide and test coverage for AgentCore framework. (Author: [@A-Vamshi](https://github.com/A-Vamshi/)) ## Corsair: Corsair Changelog - March 7-14, 2026 URL: https://www.usenotra.com/changelog/corsair/sentry-pagerduty-and-amplitude-integrations.md Date: 2026-03-14 This week brought three significant new integrations to Corsair: Sentry for error tracking, PagerDuty for incident management, and Amplitude for analytics. We also shipped MCP (Model Context Protocol) support, enabling AI agents to work seamlessly with Claude and other MCP-compatible tools through a standardized interface. Key reliability improvements include graceful handling of decryption errors and better error recovery during setup. These changes expand Corsair's reach into critical DevOps and observability workflows, making it easier for AI systems to safely interact with the tools your teams depend on every day. ## Highlights ### Sentry integration for real-time error tracking AI agents can now ingest and act on error data from Sentry with webhook support, database persistence, and proper type safety. (Author: [@mukul7661](https://github.com/mukul7661/)) ### PagerDuty incident integration with email routing New PagerDuty plugin enables agents to receive and respond to incidents, complete with email address support and improved webhook handling. (Author: [@mukul7661](https://github.com/mukul7661/)) ### Amplitude analytics events and cohort sync Amplitude plugin lets agents sync user events and cohort data to your analytics platform with database persistence and error handling. (Author: [@mukul7661](https://github.com/mukul7661/)) ### MCP package for standardized AI agent tooling New @corsair/mcp package and @corsair/ui provide Model Context Protocol support, enabling agents to work with Claude and other MCP tools through a consistent interface. (Author: [@mukul7661](https://github.com/mukul7661/)) ### Graceful error recovery on credential decryption Data encryption now fails gracefully instead of crashing, preventing silent errors when decryption keys or encrypted values are invalid. (Author: [@devjain32](https://github.com/devjain32/)) ## More Updates ### Features & Enhancements - **Agent introspection support** - Agents can now discover and introspect available tools at runtime. (Author: [@devjain32](https://github.com/devjain32/)) - **Backfill functionality** - Added support for backfilling historical data. (Author: [@devjain32](https://github.com/devjain32/)) ### Infrastructure - **MCP package config publishing** - Updated @corsair/mcp and @corsair/ui packages to public npm registry configuration. (Author: [@devjain32](https://github.com/devjain32/)) - **TypeScript configuration updates** - Enhanced tsconfig for improved type checking and module resolution. (Author: [@devjain32](https://github.com/devjain32/)) ## Emdash: Emdash Changelog - March 7-14, 2026 URL: https://www.usenotra.com/changelog/emdash/pr-search-ssh-recovery-and-terminal-improvements.md Date: 2026-03-14 Over the past week, we've shipped five significant features, multiple critical stability fixes, and a bunch of smaller UX improvements that should make your workflow smoother. If you've been waiting for better terminal search, SSH reconnection handling, or cleaner PR review flows, this release has what you need. ## Highlights ### Server-side PR search and filter presets Open PRs now supports server-side filtering with preset tabs (All Open, Needs My Review, My PRs, Draft) and arbitrary GitHub search queries. Load times are faster, and you can use full GitHub PR search syntax. ### SSH sessions auto-restart after reconnection When your SSH connection drops and reconnects, terminal sessions now resume automatically. The PTY session is re-established without losing your scrollback or requiring a new task. ### Comments popover returns with in-memory drafts Comments are back, but simpler and faster. We ditched the database and now keep draft comments in memory per task and worktree, which means multi-agent variants stay isolated and the feature stays lightweight. ### Terminal Cmd/Ctrl+F search You can now search terminal output on the fly. Hit Cmd+F or Ctrl+F in any terminal to highlight matches, step through results, and dismiss with Escape. ### Expandable mini-terminal modal The right-sidebar terminal now expands to full-screen on demand. The session and scrollback stay intact when you toggle back to compact mode. ## More Updates ### Features & Enhancements - **Add VS Code Insiders as separate Open In app** [#1460](https://github.com/generalaction/emdash/pull/1460) - Splits Insiders out from regular VS Code with dedicated bundle ID and CLI commands. (Author: [@millar](https://github.com/millar/)) - **Add terminal font size setting** [#1405](https://github.com/generalaction/emdash/pull/1405) - Font size control now available in Settings alongside the font family picker. (Author: [@naaa760](https://github.com/naaa760/)) - **Make auto-inferred task names toggleable** [#1413](https://github.com/generalaction/emdash/pull/1413) - Added Settings toggle to control automatic task name generation. (Author: [@singhvibhanshu](https://github.com/singhvibhanshu/)) - **Extract and display changelog entry published date** [#1465](https://github.com/generalaction/emdash/pull/1465) - Changelog entries now show when they were published. - **Add Xcode support to Open In** [#1446](https://github.com/generalaction/emdash/pull/1446) - Open files directly in Xcode. - **Add VSCodium support to Open In** [#1445](https://github.com/generalaction/emdash/pull/1445) - VSCodium now available as an Open In option. - **Add Android Studio support to Open In** [#1437](https://github.com/generalaction/emdash/pull/1437) - Android developers can now open projects in Android Studio. - **Add in-app changelog notifications** [#1450](https://github.com/generalaction/emdash/pull/1450) - Updates are highlighted in the home screen with a changelog card. - **Add Cmd/Ctrl shortcuts for agent tabs** [#1362](https://github.com/generalaction/emdash/pull/1362) - Switch between agent tabs with keyboard shortcuts. (Author: [@rabanspiegel](https://github.com/rabanspiegel/)) - **Add file and directory management functions** [#1348](https://github.com/generalaction/emdash/pull/1348) - New rename, mkdir, and rmdir operations for both local and remote filesystems. (Author: [@yashdev9274](https://github.com/yashdev9274/)) - **Add staging, commit & push, and file revert to sidebar** [#1349](https://github.com/generalaction/emdash/pull/1349) - Version control actions now live in the Changes sidebar. (Author: [@jschwxrz](https://github.com/jschwxrz/)) - **Add initial prompt support via -i flag** [#1387](https://github.com/generalaction/emdash/pull/1387) - Pass an initial prompt to agents on task creation. (Author: [@naaa760](https://github.com/naaa760/)) ### Bug Fixes - **Fix PR review on fork PRs** [#1454](https://github.com/generalaction/emdash/pull/1454) - Ensure local branch exists before checking out fork PRs for review. (Author: [@jschwxrz](https://github.com/jschwxrz/)) - **Fix kanban board card display** [#1452](https://github.com/generalaction/emdash/pull/1452) - Board now shows task data correctly instead of blank cards. (Author: [@jschwxrz](https://github.com/jschwxrz/)) - **Improve diff sidebar presentation** [#1451](https://github.com/generalaction/emdash/pull/1451) - Better visual handling of deleted files in the diff viewer. (Author: [@jschwxrz](https://github.com/jschwxrz/)) - **Fix diff viewer git status pipeline** [#1433](https://github.com/generalaction/emdash/pull/1433) - Hardened parsing and improved large-file rendering. (Author: [@jschwxrz](https://github.com/jschwxrz/)) - **Use PTY-based renderer for lifecycle terminal output** [#1425](https://github.com/generalaction/emdash/pull/1425) - Lifecycle scripts now render with proper terminal colors and formatting. (Author: [@ckafrouni](https://github.com/ckafrouni/)) - **Prevent Create PR button overflow in narrow sidebar** [#1420](https://github.com/generalaction/emdash/pull/1420) - Button no longer overflows on smaller viewports. (Author: [@naaa760](https://github.com/naaa760/)) - **Prevent session ID collision for non-worktree tasks** [#1436](https://github.com/generalaction/emdash/pull/1436) - Non-worktree tasks now get fresh session UUIDs instead of colliding. (Author: [@Simonstorms](https://github.com/Simonstorms/)) - **Improve update error state wording and styling** [#1474](https://github.com/generalaction/emdash/pull/1474) - Better messaging when updates fail. - **Hide Open PRs section while loading** [#1419](https://github.com/generalaction/emdash/pull/1419) - Cleaner loading state instead of spinner. - **Close in-app editor when opening settings** [#1422](https://github.com/generalaction/emdash/pull/1422) - Editor mode is exited before opening Settings. (Author: [@shreyaspapi](https://github.com/shreyaspapi/)) - **Close in-app editor when opening diff from Changes panel** [#1374](https://github.com/generalaction/emdash/pull/1374) - Keeps editor and diff views from conflicting. (Author: [@naaa760](https://github.com/naaa760/)) - **Start remote PTY in worktree dir and auto-start agent** [#1373](https://github.com/generalaction/emdash/pull/1373) - SSH remote terminals now open in the correct directory. (Author: [@naaa760](https://github.com/naaa760/)) - **Resolve tmux to absolute path before spawning** [#1470](https://github.com/generalaction/emdash/pull/1470) - Fixes PTY spawning when tmux is not in PATH. - **Fix terminal keyboard shortcuts passthrough** [#1411](https://github.com/generalaction/emdash/pull/1411) - App shortcuts like Cmd/Ctrl+. now fire from terminal panes. (Author: [@ckafrouni](https://github.com/ckafrouni/)) - **Create task under correct project using + button** [#1406](https://github.com/generalaction/emdash/pull/1406) - Tasks created from sidebar + button now go to the correct project. (Author: [@naaa760](https://github.com/naaa760/)) - **Use default provider for PR review tasks** [#1453](https://github.com/generalaction/emdash/pull/1453) - PR review tasks now respect your default agent provider. - **Fix stale worktree reserves** [#1403](https://github.com/generalaction/emdash/pull/1403) - Prevents orphaned worktree reservations from blocking new tasks. (Author: [@jschwxrz](https://github.com/jschwxrz/)) - **Prevent TaskModal content overflow on small viewports** [#1371](https://github.com/generalaction/emdash/pull/1371) - Modal stays usable on narrow screens. - **Collapse right sidebar on home screen by default** [#1355](https://github.com/generalaction/emdash/pull/1355) - Cleaner home screen presentation. ### Security - **Harden SSH command validation** [#1350](https://github.com/generalaction/emdash/pull/1350) - Stricter shell control character checks and prefix matching. (Author: [@bhaktofmahakal](https://github.com/bhaktofmahakal/)) - **Pin app-builder-lib minimatch for mac packaging** [#1391](https://github.com/generalaction/emdash/pull/1391) - Patches vulnerable minimatch resolutions to restore Mac releases. ### Infrastructure - **Add Forgejo integration** [#1308](https://github.com/generalaction/emdash/pull/1308) - Emdash now supports Forgejo-hosted repositories. (Author: [@Codycody31](https://github.com/Codycody31/)) ## nao Labs: nao Labs Changelog - March 7-14, 2026 URL: https://www.usenotra.com/changelog/nao-labs/database-profiling-microsoft-fabric-and-teams-integration.md Date: 2026-03-14 This week brings foundational improvements to analytics discovery and enterprise deployment options. Database profiling enables data teams to understand table characteristics within nao's context system, Microsoft Fabric support adds SQL Analytics endpoints for Fabric customers, and Microsoft Teams deployment lets business users query data directly in their workspace. We also shipped context window visualization so you can see exactly how much context your queries consume, an improved chat interface with data context shortcuts, and KPI card support for quick metric views. ## Highlights ### Database profiling for warehouse discovery Added profiling accessor across DuckDB, PostgreSQL, and MSSQL warehouses. The profiling feature generates summary statistics, column information, and top values for tables, automatically included in the agent context. Teams can configure refresh policies to balance context freshness against query costs. ### Microsoft Fabric Data Warehouse and SQL Analytics Endpoint support New database connector for Microsoft Fabric with four authentication modes: SQL password, Azure CLI, Azure Interactive (browser-based AD), and service principal. Handles ODBC token injection, pandas 2.0+ compatibility, and proper system schema filtering for production reliability. ### Microsoft Teams bot deployment channel Deployed nao as a Microsoft Teams bot, enabling business users to query data without leaving their workspace. The bot supports chat, story sharing, and image rendering within Teams native UI, filling the gap between web and Slack integrations. ### Context window visualization in chat input Added real-time context token tracking as a donut ring in the chat input bar. Shows current token usage against the model's limit, helping teams understand how much context remains before hitting truncation. Updates dynamically as context is added or cleared. ### Enhanced chat input with data context menu Added a plus menu in chat input for inserting Story mode, available skills, and database table mentions. Includes a context picker that reads your databases folder, making it faster to reference specific tables without typing. ## More Updates ### Features & Enhancements - **KPI cards for quick metric display** [#379](https://github.com/getnao/nao/pull/379) - Agents can now render key performance indicators as data cards in chat and stories, complementing the existing chart tools. (Author: [@cainemerrick98](https://github.com/cainemerrick98/)) - **Editable titles with AI-assisted naming** [#442](https://github.com/getnao/nao/pull/442) - Chat conversations now have editable titles in the header, with optional AI-generated suggestions for quick naming. (Author: [@Bl3f](https://github.com/Bl3f/)) - **Email notifications on story sharing** [#438](https://github.com/getnao/nao/commit/0b017274969bd15b4634a554451510f7d8d184b8) - When users share a story, recipients receive an email notification with access details. (Author: [@MatLBS](https://github.com/MatLBS/)) - **GitHub and Slack community links in sidebar** [#435](https://github.com/getnao/nao/pull/435) - Added direct links to GitHub repository and Slack community in the sidebar for easier access to help and discussions. (Author: [@Rish-it](https://github.com/Rish-it/)) - **Stacked bar chart validation improvement** [#417](https://github.com/getnao/nao/commit/16a7a709377fe5ea764382863fdb2e87e5d77201) - Enhanced validation for stacked bar charts to require at least two data series with clearer error messaging. (Author: [@cainemerrick98](https://github.com/cainemerrick98/)) - **AI-powered annotations in CLI templates** [#382](https://github.com/getnao/nao/commit/6b598fbff64f955652b86391f012f08c94270b76) - CLI now supports AI-generated summaries and annotations in templates, with gating for interactive mode. (Author: [@Flamki](https://github.com/Flamki/)) - **LLM model configuration responsive layout** [#450](https://github.com/getnao/nao/commit/7e40ff1153713b81cc12664af98e89c63a1517b3) - LLM configuration sections now adapt to different screen sizes for better mobile and tablet experience. (Author: [@MatLBS](https://github.com/MatLBS/)) - **Improved Slack and Teams setup forms** [#436](https://github.com/getnao/nao/commit/6728e3fb56adeb9365a07b66933f5e38cc42c115) - Streamlined setup flows for Slack and Teams integrations with better guidance. (Author: [@MatLBS](https://github.com/MatLBS/)) - **AWS region support in CLI** [#420](https://github.com/getnao/nao/commit/f7248b528e5cfc908630bf78b2cd512fa08990d0) - CLI now accepts AWS_REGION environment variable for deployments across different AWS regions. (Author: [@Bl3f](https://github.com/Bl3f/)) - **CLI config validation flow** [#411](https://github.com/getnao/nao/commit/da10d798356ff8de601d9b05e5da90859386dbb2) - Running `nao init` with an invalid existing config now runs the update flow instead of erroring out. (Author: [@varunguleriaCodes](https://github.com/varunguleriaCodes/)) - **User menu text truncation** [#453](https://github.com/getnao/nao/commit/fb306a433c54687524250da66fe856fdc4f38386) - Fixed long email and username display in sidebar user menu to prevent layout overflow. (Author: [@MatLBS](https://github.com/MatLBS/)) ### Infrastructure - **Automated documentation updates** [#428](https://github.com/getnao/nao/commit/4dcaccd80db96767c23d3b5468cebd3ef6c416f4) - Documentation reference updates are now automated via GitHub Actions to stay in sync with code changes. (Author: [@Bl3f](https://github.com/Bl3f/)) - **PR preview deployments** [#437](https://github.com/getnao/nao/pull/437) - Automatically deploy preview environments for each pull request at preview.getnao.io subdomains. Previews include seeded test data and update on every push. (Author: [@Bl3f](https://github.com/Bl3f/)) - **Teams bot integration in usage analytics** [#444](https://github.com/getnao/nao/commit/7c4351053098dbb4a4ce48e0d2b221fb9b1fb1d3) - Added Microsoft Teams as a third series in the messages usage chart alongside Web and Slack. Also made Fabric dependencies lazy-load to prevent import errors when unixodbc is unavailable. (Author: [@MatLBS](https://github.com/MatLBS/)) - **Timezone awareness in system prompts** [#427](https://github.com/getnao/nao/commit/6c31254556491f809b73686d779d369680b66b19) - System prompt now includes user timezone information for better date/time understanding in queries. Fetches timezone from Slack when available. (Author: [@Bl3f](https://github.com/Bl3f/)) - **Analytics event tracking improvements** [#445](https://github.com/getnao/nao/commit/b98ec1458e2fd97addedc75ce2e73cb606668e4c) - Fixed event correlation across frontend and backend by linking project_id and domain_host throughout the event pipeline, including Teams service and Slack events. (Author: [@paulpriyanshu](https://github.com/paulpriyanshu/)) ### Bug Fixes - **Message feedback routing** - Fixed feedback submission to correctly route to the intended message ID. (Author: [@socallmebertille](https://github.com/socallmebertille/)) - **User message alignment** - Fixed user messages to display right-aligned in chat conversations. (Author: [@MatLBS](https://github.com/MatLBS/)) ### Testing - **Database profiling integration tests** - Added comprehensive integration tests for profiling implementations across DuckDB, MSSQL, PostgreSQL, and BigQuery warehouses. ### Documentation - **Stacked bar validation messaging** - Improved error messages for stacked bar chart validation to guide users toward correct chart configuration. ## Onyx: Onyx Changelog - March 7-14, 2026 URL: https://www.usenotra.com/changelog/onyx/voice-mode-opensearch-and-admin-redesign.md Date: 2026-03-14 This week brings voice mode with real-time speech-to-text and text-to-speech, OpenSearch enabled by default for all new installs, and a redesigned admin Users interface with granular user management, role controls, and group editing. You'll also find OIDC PKCE support hardening the authentication flow, extended file preview capabilities, configurable user upload limits, and a security patch for the flatted dependency. The admin sidebar has been reorganized with a new search feature, and custom tool error handling is improved with better timeline visualization. ## Highlights ### Voice mode with streaming speech-to-text and text-to-speech Real-time voice interaction now works end-to-end with gapless sentence-level streaming TTS synced to message generation, live mic recording with live transcription and waveform display, and per-user voice preferences for auto-send and playback speed. Admin panel includes provider setup for OpenAI, ElevenLabs, and Azure TTS, with SSRF protections and SSML escaping. (Author: [@jessicasingh7](https://github.com/jessicasingh7/)) ### OpenSearch enabled by default for all deployments New Onyx installs now use OpenSearch indexing and retrieval out of the box across Docker Compose and Helm deployments, with automatic service startup and correctly configured JVM heap sizes. Existing self-hosted and AWS-managed setups can opt out via environment variables. (Author: [@acaprau](https://github.com/acaprau/)) ### Redesigned admin Users interface with granular controls The Users page now ships with server-side pagination, inline role editing, row-level actions with confirmation modals, filters by role/group/status, an invite modal for bulk user creation, and a group membership editor. SCIM management has been integrated into the new page. (Author: [@nmgarza5](https://github.com/nmgarza5/)) ### OIDC Proof Key for Code Exchange (PKCE) support OIDC login flow now supports PKCE (S256) with verifier cookies and state validation before token redemption, gated by `OIDC_PKCE_ENABLED` for staged rollout. Global error handlers return consistent JSON responses for token exchange failures. (Author: [@justin-tahara](https://github.com/justin-tahara/)) ### Extended file preview with more text and data formats In-app file preview now supports plaintext, logs, configs, TSV, and additional YAML variants (text/yaml, text/x-yaml, application/yaml), with smarter MIME/extension detection and replaced TextViewModal with a unified PreviewModal text variant. (Author: [@jmelahman](https://github.com/jmelahman/)) ## More Updates ### Security - **Patched CVE-2026-32141 in flatted dependency** [#9350](https://github.com/onyx-dot-app/onyx/pull/9350) - Dev-only dependency bump to resolve reported vulnerability. (Author: [@nmgarza5](https://github.com/nmgarza5/)) ### Features & Enhancements - **Configurable user file upload size limits** [#9157](https://github.com/onyx-dot-app/onyx/pull/9157) - Added `MAX_USER_FILE_UPLOAD_SIZE_MB` setting for controlling upload constraints. (Author: [@justin-tahara](https://github.com/justin-tahara/)) - **Frontend precheck for oversized uploads** [#9159](https://github.com/onyx-dot-app/onyx/pull/9159) - Early validation prevents large file submissions from reaching backend. (Author: [@justin-tahara](https://github.com/justin-tahara/)) - **Backend enforcement of user upload limits** [#9158](https://github.com/onyx-dot-app/onyx/pull/9158) - Server-side validation for project and chat upload paths respects configured limits. (Author: [@justin-tahara](https://github.com/justin-tahara/)) - **Custom tool error handling and timeline UI improvements** [#9189](https://github.com/onyx-dot-app/onyx/pull/9189) - Better error messages and visual timeline for custom tool execution feedback. (Author: [@Subash-Mohan](https://github.com/Subash-Mohan/)) - **Admin sidebar refresh with new sections and search** [#9344](https://github.com/onyx-dot-app/onyx/pull/9344) - Reorganized sidebar with search capability and disabled enterprise-only tabs. (Author: [@raunakab](https://github.com/raunakab/)) - **Progress bars and UI icon additions** [#9349](https://github.com/onyx-dot-app/onyx/pull/9349) - Added new icons (progress bars, curate, user variant) to component library. (Author: [@raunakab](https://github.com/raunakab/)) - **LLM provider dropdown fixes and voice setup modal** [#9264](https://github.com/onyx-dot-app/onyx/pull/9264) - Improved FE provider workflow for voice mode configuration. (Author: [@justin-tahara](https://github.com/justin-tahara/)) - **LineItemButton component addition** [#9137](https://github.com/onyx-dot-app/onyx/pull/9137) - New UI component for list-based interactions. (Author: [@raunakab](https://github.com/raunakab/)) ### Bug Fixes - **Prevented removal and hiding of default model** [#9131](https://github.com/onyx-dot-app/onyx/pull/9131) - Models cannot be deleted if they are the system default. (Author: [@Danelegend](https://github.com/Danelegend/)) - **Filtering embedding models in litellm provider** [#9347](https://github.com/onyx-dot-app/onyx/pull/9347) - Blocks embedding models from appearing in chat LLM selection. (Author: [@Danelegend](https://github.com/Danelegend/)) - **SharePoint pages 400 list expand error** [#9321](https://github.com/onyx-dot-app/onyx/pull/9321) - Fixed expand parameter in SharePoint page enumeration. (Author: [@evan-onyx](https://github.com/evan-onyx/)) - **Skip classic SharePoint site pages** [#9318](https://github.com/onyx-dot-app/onyx/pull/9318) - Connector no longer attempts to fetch unsupported classic site pages. (Author: [@evan-onyx](https://github.com/evan-onyx/)) - **Slack bot admin pages broken links** [#9168](https://github.com/onyx-dot-app/onyx/pull/9168) - Restored navigation on admin slack bot configuration pages. (Author: [@nmgarza5](https://github.com/nmgarza5/)) - **Voice error sanitization and replay on revisit** [#9326](https://github.com/onyx-dot-app/onyx/pull/9326) - Error messages no longer expose internals; voice playback resumes correctly when returning to chat. (Author: [@jessicasingh7](https://github.com/jessicasingh7/)) - **Fallback doc access for externally owned drive items** [#9053](https://github.com/onyx-dot-app/onyx/pull/9053) - Microsoft connector handles permission failures for shared external documents. (Author: [@wenxi-onyx](https://github.com/wenxi-onyx/)) - **InputComboBox filter value reset on open** [#9287](https://github.com/onyx-dot-app/onyx/pull/9287) - Dropdown no longer clears search text when expanded. (Author: [@jmelahman](https://github.com/jmelahman/)) - **InputSelect text selection prevention** [#9292](https://github.com/onyx-dot-app/onyx/pull/9292) - Clicking dropdown no longer selects background text. (Author: [@jmelahman](https://github.com/jmelahman/)) - **CSV inline display responsiveness** [#9242](https://github.com/onyx-dot-app/onyx/pull/9242) - Tables now reflow correctly on narrow viewports. (Author: [@jmelahman](https://github.com/jmelahman/)) - **Comma literal parsing in CSV uploads** [#9245](https://github.com/onyx-dot-app/onyx/pull/9245) - Quoted commas in CSV fields no longer cause parsing errors. (Author: [@jmelahman](https://github.com/jmelahman/)) - **Modal centering on smaller screens** [#9250](https://github.com/onyx-dot-app/onyx/pull/9250) - Breakpoint adjustment keeps modals centered on mobile devices. (Author: [@jmelahman](https://github.com/jmelahman/)) - **API memory allocator switch to jemalloc** [#9196](https://github.com/onyx-dot-app/onyx/pull/9196) - Reduces memory fragmentation in API container by replacing glibc allocator. (Author: [@Bo-Onyx](https://github.com/Bo-Onyx/)) - **Prevent deep-copy during document indexing** [#9275](https://github.com/onyx-dot-app/onyx/pull/9275) - Improves indexing performance by avoiding unnecessary object duplication. (Author: [@Danelegend](https://github.com/Danelegend/)) - **OpenSearch update clears empty projects and personas** [#8845](https://github.com/onyx-dot-app/onyx/pull/8845) - Removes stale project/persona references from index on document updates. (Author: [@acaprau](https://github.com/acaprau/)) - **Safari search results shrinking issue** [#9126](https://github.com/onyx-dot-app/onyx/pull/9126) - Layout no longer collapses on macOS Safari. (Author: [@jmelahman](https://github.com/jmelahman/)) - **Chat content padding fix** [#9216](https://github.com/onyx-dot-app/onyx/pull/9216) - Spacing corrected for message display area. (Author: [@jmelahman](https://github.com/jmelahman/)) - **Code interpreter default base URL** [#9215](https://github.com/onyx-dot-app/onyx/pull/9215) - Sets sensible default for `CODE_INTERPRETER_BASE_URL` in Docker deployments. (Author: [@jmelahman](https://github.com/jmelahman/)) - **OnyxError response shape correction** [#9214](https://github.com/onyx-dot-app/onyx/pull/9214) - API now returns `detail` instead of `message` for consistency. (Author: [@nmgarza5](https://github.com/nmgarza5/)) - **SQLAlchemy batch user insert sentinel mismatch** [#9300](https://github.com/onyx-dot-app/onyx/pull/9300) - Fixes ORM comparison error when inserting multiple users at once. (Author: [@nmgarza5](https://github.com/nmgarza5/)) - **Consolidated search state machine** [#9234](https://github.com/onyx-dot-app/onyx/pull/9234) - Simplifies search request handling logic. (Author: [@raunakab](https://github.com/raunakab/)) - **Jira group sync endpoint update** [#9241](https://github.com/onyx-dot-app/onyx/pull/9241) - Connector uses correct endpoint for fetching group memberships. (Author: [@evan-onyx](https://github.com/evan-onyx/)) - **MCP tools endpoint CE compatibility** [#9193](https://github.com/onyx-dot-app/onyx/pull/9193) - Community Edition deployments no longer error when MCP fetches indexed documents. (Author: [@wenxi-onyx](https://github.com/wenxi-onyx/)) - **Craft webapp route conflict** [#9283](https://github.com/onyx-dot-app/onyx/pull/9283) - Renamed endpoint to prevent HMR and asset request interference. (Author: [@rohoswagger](https://github.com/rohoswagger/)) - **Helm User Auth secret default behavior** [#9325](https://github.com/onyx-dot-app/onyx/pull/9325) - User authentication secret now disabled by default in Helm deployments. (Author: [@justin-tahara](https://github.com/justin-tahara/)) - **SensitiveValue event hook** [#9177](https://github.com/onyx-dot-app/onyx/pull/9177) - Secrets are properly wrapped before event logging. (Author: [@wenxi-onyx](https://github.com/wenxi-onyx/)) - **Available context tokens management** [#9174](https://github.com/onyx-dot-app/onyx/pull/9174) - Moves token budgeting from controller to hook, removes arbitrary 50% cap. (Author: [@wenxi-onyx](https://github.com/wenxi-onyx/)) - **Proxied webapp asset and HMR reload leaks** [#9255](https://github.com/onyx-dot-app/onyx/pull/9255) - Craft development mode no longer leaks asset requests and hot-reload listeners. (Author: [@rohoswagger](https://github.com/rohoswagger/)) - **Discord connector async resource cleanup** [#9203](https://github.com/onyx-dot-app/onyx/pull/9203) - Properly awaits async operations in cleanup sequence. (Author: [@wenxi-onyx](https://github.com/wenxi-onyx/)) - **MCP tools fetch when no LLMs configured** [#9173](https://github.com/onyx-dot-app/onyx/pull/9173) - Skips unnecessary MCP initialization when system has no LLMs. (Author: [@wenxi-onyx](https://github.com/wenxi-onyx/)) - **PostHog SSL upgrade on local redirect** [#9175](https://github.com/onyx-dot-app/onyx/pull/9175) - Development server handles SSL redirects correctly. (Author: [@wenxi-onyx](https://github.com/wenxi-onyx/)) - **Favicon relative path preference** [#9307](https://github.com/onyx-dot-app/onyx/pull/9307) - Avoids absolute path issues in reverse proxy setups. (Author: [@jmelahman](https://github.com/jmelahman/)) - **App padding inside overflow container** [#9206](https://github.com/onyx-dot-app/onyx/pull/9206) - Layout padding no longer causes unexpected overflow. (Author: [@jmelahman](https://github.com/jmelahman/)) - **Preview modal fade background color matching** [#9221](https://github.com/onyx-dot-app/onyx/pull/9221) - Modal background now matches code block background for visual consistency. (Author: [@jmelahman](https://github.com/jmelahman/)) - **Storybook component references** [#9244](https://github.com/onyx-dot-app/onyx/pull/9244) - Fixed case-sensitivity and icon naming in Storybook stories. (Author: [@nmgarza5](https://github.com/nmgarza5/)) ### Infrastructure - **OpenSearch environment variable configurability** [#9243](https://github.com/onyx-dot-app/onyx/pull/9243) - Allows tuning hybrid search subquery hit count via `OPENSEARCH_HYBRID_SUBQUERY_HITS`. (Author: [@acaprau](https://github.com/acaprau/)) - **OpenSearch Vespa migration page size control** [#9239](https://github.com/onyx-dot-app/onyx/pull/9239) - `OPENSEARCH_VESPA_MIGRATION_CHUNK_SIZE` lets operators control batch sizes during migration. (Author: [@acaprau](https://github.com/acaprau/)) - **Release tag workflow improvements** [#9278](https://github.com/onyx-dot-app/onyx/pull/9278) - Better semver tagging logic for Docker Hub `latest` tag. (Author: [@wenxi-onyx](https://github.com/wenxi-onyx/)) - **Docker Compose OpenSearch container settings** [#9277](https://github.com/onyx-dot-app/onyx/pull/9277) - Unsets ulimits in dev environment for compatibility. (Author: [@jmelahman](https://github.com/jmelahman/)) - **LiteLLM models endpoint integration** [#8418](https://github.com/onyx-dot-app/onyx/pull/8418) - Backend can now fetch available models from LiteLLM provider. (Author: [@Danelegend](https://github.com/Danelegend/)) ### Internal Changes - **Prisma hierarchy node pruning** [#9066](https://github.com/onyx-dot-app/onyx/pull/9066) - Removes orphaned hierarchy nodes during indexing. (Author: [@evan-onyx](https://github.com/evan-onyx/)) - **SharePoint deduplication logic** [#9254](https://github.com/onyx-dot-app/onyx/pull/9254) - Prevents duplicate document creation in SharePoint connector. (Author: [@evan-onyx](https://github.com/evan-onyx/)) - **EncryptedBase cache_okay declaration** [#9253](https://github.com/onyx-dot-app/onyx/pull/9253) - SQLAlchemy type system declarations for encrypted columns. (Author: [@wenxi-onyx](https://github.com/wenxi-onyx/)) - **EncryptedJson cache_okay marking** [#9252](https://github.com/onyx-dot-app/onyx/pull/9252) - Marks encrypted JSON fields as safe for compilation cache. (Author: [@wenxi-onyx](https://github.com/wenxi-onyx/)) - **Width CSS class refactor** [#9146](https://github.com/onyx-dot-app/onyx/pull/9146) - Changes default width utility from `w-auto` to `w-fit` for improved layout. (Author: [@raunakab](https://github.com/raunakab/)) - **File preview modal improvements** [#9259](https://github.com/onyx-dot-app/onyx/pull/9259) - Additional polish for file preview display. (Author: [@jmelahman](https://github.com/jmelahman/)) - **Unnecessary multitenant migration check removed** [#9172](https://github.com/onyx-dot-app/onyx/pull/9172) - Simplifies migration logic. (Author: [@wenxi-onyx](https://github.com/wenxi-onyx/)) - **Decryption utility update** [#9176](https://github.com/onyx-dot-app/onyx/pull/9176) - Improves secret handling utilities. (Author: [@wenxi-onyx](https://github.com/wenxi-onyx/)) ### Testing - **Playwright test-only flag cleanup** [#9336](https://github.com/onyx-dot-app/onyx/pull/9336) - Removed debug `.only` directive from test suite. (Author: [@jmelahman](https://github.com/jmelahman/)) - **Storybook build and deploy CI** [#9205](https://github.com/onyx-dot-app/onyx/pull/9205) - Added GitHub Actions workflow to publish component library. (Author: [@nmgarza5](https://github.com/nmgarza5/)) - **Component story library** [#9194](https://github.com/onyx-dot-app/onyx/pull/9194) - Comprehensive Storybook stories for all UI components. (Author: [@nmgarza5](https://github.com/nmgarza5/)) - **Storybook infrastructure setup** [#9195](https://github.com/onyx-dot-app/onyx/pull/9195) - Initial Storybook configuration and tooling. (Author: [@nmgarza5](https://github.com/nmgarza5/)) - **Model server nightly test fixes** [#9236](https://github.com/onyx-dot-app/onyx/pull/9236) - Corrected deprecated OpenAI model references in tests. (Author: [@jmelahman](https://github.com/jmelahman/)) - **Removed deprecated o1 model tests** [#9280](https://github.com/onyx-dot-app/onyx/pull/9280) - Cleaned up test suite for retired OpenAI models. (Author: [@nmgarza5](https://github.com/nmgarza5/)) - **LLM model state cache integration test** [#9142](https://github.com/onyx-dot-app/onyx/pull/9142) - Added integration test for model state caching behavior. (Author: [@justin-tahara](https://github.com/justin-tahara/)) - **Release branch Playwright runs** [#9233](https://github.com/onyx-dot-app/onyx/pull/9233) - Triggers browser automation tests on release branches. (Author: [@jmelahman](https://github.com/jmelahman/)) ### Documentation - **Greptile custom context improvements** [#9319](https://github.com/onyx-dot-app/onyx/pull/9319) - Enhanced documentation context for codebase search. (Author: [@justin-tahara](https://github.com/justin-tahara/)) - **Cherry-pick workflow documentation** [#9329](https://github.com/onyx-dot-app/onyx/pull/9329) - CODEOWNERS file for cherry-pick release process. (Author: [@justin-tahara](https://github.com/justin-tahara/)) - **Cherry-pick workflow improvements** [#9316](https://github.com/onyx-dot-app/onyx/pull/9316) - Enhanced cherry-pick automation. (Author: [@justin-tahara](https://github.com/justin-tahara/)) - **Slack cherry-pick notification** [#9331](https://github.com/onyx-dot-app/onyx/pull/9331) - Notifies Slack channel on successful PR cherry-pick. (Author: [@justin-tahara](https://github.com/justin-tahara/)) - **Cherry-pick whitelist for approved users** [#9330](https://github.com/onyx-dot-app/onyx/pull/9330) - Restricts cherry-pick permissions to designated team members. (Author: [@justin-tahara](https://github.com/justin-tahara/)) ## Pangolin: Pangolin Changelog - March 7-14, 2026 URL: https://www.usenotra.com/changelog/pangolin/email-ip-banning-and-certificate-sync-fixes.md Date: 2026-03-14 This week, Pangolin released security enhancements and critical infrastructure fixes designed to strengthen access control and operational reliability. Administrators now have the ability to ban specific email addresses and IP ranges, adding a direct control mechanism for access decisions alongside identity and device verification. A longstanding issue affecting wildcard SSL certificate synchronization has been resolved, ensuring that certificate renewals properly sync from your provider without interruption. Additionally, a critical dashboard domain validation bug has been patched, stopping the redirect loops that occurred when resources were misconfigured with the dashboard's own domain. Complementing these changes, dialog rendering has been refined to ensure proper max-height enforcement, preventing interface overflow and maintaining a polished user experience. These updates collectively improve your zero-trust infrastructure's security posture and operational stability. ## Highlights ### Email and IP banning for access control Block specific email addresses and IP ranges to add a decisive layer of access control when other identity factors don't cut it. ### Wildcard certificate sync fixed Wildcard SSL certificate renewals now properly pull from your provider instead of stalling out, preventing validation failures on wildcard domain connections. ### Dashboard domain conflicts resolved Stopped resources from being created with the dashboard's own domain, which was causing endless redirect loops when this mistake happened. ### Dialog rendering refinements Fixed Credenza dialog max-height so dialogs stay within their containers instead of overflowing. ## More Updates ### Features & Enhancements - **Email and IP banning** - Block specific email addresses and IP ranges to restrict access. (Author: [@oschwartz10612](https://github.com/oschwartz10612/)) ### Bug Fixes - **Wildcard certificate sync restored** - Wildcard SSL certificate updates now pull correctly. (Author: [@oschwartz10612](https://github.com/oschwartz10612/)) - **Fixed dashboard domain conflicts** [#2603](https://github.com/fosrl/pangolin/pull/2603) - Added validation to prevent resources from being created with the dashboard's domain, eliminating redirect loops. (Author: [@Fizza-Mukhtar](https://github.com/Fizza-Mukhtar/)) - **Dialog max-height fixed** - Credenza dialogs now respect container boundaries. (Author: [@shreyaspapi](https://github.com/shreyaspapi/)) ## Superagent: Superagent Changelog - March 7-14, 2026 URL: https://www.usenotra.com/changelog/superagent/model-failover-and-provider-parity.md Date: 2026-03-14 The Superagent SDK now supports automatic model failover for production resilience and includes comprehensive model type definitions across all major providers. The fallback model feature transparently handles transient provider errors, letting applications switch to backup models without manual intervention or code changes. Updated model types bring TypeScript and Python SDKs into parity with the latest models from OpenAI, Anthropic, Google, Bedrock, Vercel, Groq, OpenRouter, and Fireworks, backed by refined test architecture for faster iteration and more reliable validation. ## Highlights ### Automatic Model Failover for Provider Resilience When primary models hit transient errors (429, 500, 502, 503), the SDK automatically retries with a fallback model you specify. This unblocks production deployments during high-demand periods without requiring code changes. ### Comprehensive Model Type Definitions All major provider models are now in the TypeScript and Python SDKs with full type support for autocomplete and type-checking, matching the latest available releases. ### Unified Unit Test Architecture Consolidated 39 per-provider integration tests into parameterized unit tests that mock provider calls. Tests run instantly with deterministic results, eliminating external dependencies. ## More Updates ### Features & Enhancements - **Fallback model support for resilience** [#1136](https://github.com/superagent-ai/superagent/pull/1136) - Added fallbackModel/fallback_model option to GuardOptions, RedactOptions, and ScanOptions in both TypeScript and Python SDKs. The SDK retries failed requests to your specified backup model for automatic failover on retryable HTTP errors. (Author: [@homanp](https://github.com/homanp/)) - **Updated model types across providers** [#1137](https://github.com/superagent-ai/superagent/pull/1137) - Added latest model releases from OpenAI, Anthropic, Google, Bedrock, Vercel, Groq, OpenRouter, and Fireworks with Literal-based type unions in the Python SDK for autocomplete and type-checking parity with TypeScript. (Author: [@homanp](https://github.com/homanp/)) ## Unsloth AI: Unsloth AI Changelog - March 7-14, 2026 URL: https://www.usenotra.com/changelog/unsloth-ai/studio-setup-embedding-training-and-flex-attention.md Date: 2026-03-14 Over the past week, Unsloth has focused on studio infrastructure optimization, expanding model training capabilities to embeddings and audio, and strengthening dataset handling. The team accelerated local setup time by 8x through uv integration and improved build times with GPU architecture detection. A new dataset conversion advisor uses multi-pass LLM inference to intelligently map non-conversational datasets, while expanded security controls disable remote code execution by default. Audio and embedding model training pipelines are now production-ready alongside fixes for Flex Attention on Blackwell GPUs, better VLM dataset detection, and subprocess isolation for clean version switching. ## Highlights ### Studio setup 8x faster with uv and GPU-optimized builds Replaced pip with the Rust-based uv package manager (reducing Python dependencies from 2m 28s to 18s) and added GPU compute capability detection with Ninja compiler support, cutting total setup time from 4m 35s to under 2 minutes. ### Embedding model training with sentence transformers Added end-to-end training pipeline for embedding models using FastSentenceTransformer and MultipleNegativesRankingLoss, with automatic LoRA support and 5 pre-configured models (all-MiniLM-L6-v2, bge-m3, gte-modernbert-base, and others). ### AI-driven dataset conversion for non-conversational data Multi-pass LLM advisor intelligently detects dataset type, generates user/assistant templates with column mappings, and produces contextual system prompts for datasets like SNLI and SQuAD without manual intervention. ### Flex Attention now works on Blackwell GPUs Fixed flex attention backward kernel shared memory limits on Blackwell+ GPUs (sm_120 and above), re-enabling a 1.3x speedup previously disabled as a workaround. ### Remote code execution disabled by default for model loading Switched HuggingFace model loading to disable trust_remote_code by default in seed dataset inspection and AI-assist model hint lookup, with explicit UI toggle for users who need custom model code. ## More Updates ### Security - **Disabled remote code execution in model loading endpoints** - Prevents untrusted Hugging Face repositories from executing arbitrary code during inference and dataset checks. (Author: [@danielhanchen](https://github.com/danielhanchen/)) - **Prevent browser autofill in HF token fields** - Added autocomplete="off" to prevent credential managers from auto-filling sensitive API tokens. ### Features & Enhancements - **Audio model training support** - Pure audio models (Orpheus, SparkTTS, Whisper) and audio-VLM models (Gemma3n) with automatic train_on_completions unchecking. (Author: [@rolandtannous](https://github.com/rolandtannous/)) - **Streaming HF datasets with manual slice** - Streams only rows up to slice_end instead of downloading full dataset, saving bandwidth for large dataset subsets. (Author: [@rolandtannous](https://github.com/rolandtannous/)) - **ShareGPT+image VLM format support** - Detect and convert vision conversations with `` placeholders in ChatML/ShareGPT format. (Author: [@rolandtannous](https://github.com/rolandtannous/)) - **Better image column detection** - Scores candidates by resolvability (PIL > dict > URL > path), probes multiple candidates, and detects list-of-strings captions. (Author: [@rolandtannous](https://github.com/rolandtannous/)) - **GGUF shard downloading for split models** - Download all shards for multi-part quantized models (e.g., 7B Q8_0) instead of just the first file. (Author: [@rolandtannous](https://github.com/rolandtannous/)) - **ROCm/PyTorch version combinations** - Added support for more ROCm and PyTorch variants (rocm711-torch291 on Linux). (Author: [@sstamenk](https://github.com/sstamenk/)) - **Chat sequence slider** - UI control to adjust sequence length in inference playground. (Author: [@Shine1i](https://github.com/Shine1i/)) - **trust_remote_code UI toggle** - Users can now explicitly opt-in to loading custom model code from Hugging Face. (Author: [@sshah229](https://github.com/sshah229/)) ### Bug Fixes - **Fixed VLM model config llm_int8_skip_modules on transformers 5.x** - Dynamic quant checkpoints now respect skip patterns when prefix mismatch occurs. (Author: [@danielhanchen](https://github.com/danielhanchen/)) - **Fixed data-designer plugin editable install for Colab** - Changed to non-editable install so kernel can find package files immediately in live sessions. (Author: [@LeoBorcherding](https://github.com/LeoBorcherding/)) - **Fixed eval_loss broken after subprocess isolation refactor** - Restored eval_enabled signal for eval-only progress and dataset splitting. (Author: [@rolandtannous](https://github.com/rolandtannous/)) - **Fixed negative dataset slice boundaries in embedding worker** - Use explicit None checks instead of falsy `or` for slice_start and slice_end. (Author: [@rolandtannous](https://github.com/rolandtannous/)) - **Fixed GGUF variant matching to prevent superset collisions** - Use word-boundary regex so "Q8_0" doesn't match "IQ8_0"; discover shards by shared prefix instead of variant matches. (Author: [@rolandtannous](https://github.com/rolandtannous/)) - **Fixed gated embedding model authentication** - Forward hf_token to FastSentenceTransformer and key cache by token tuple. (Author: [@rolandtannous](https://github.com/rolandtannous/)) - **Fixed Windows training hang** - Added triton-windows support and scoped dataloader_num_workers=0 to Windows + transformers 5.x. (Author: [@rolandtannous](https://github.com/rolandtannous/)) - **Fixed nvm/npmrc prefix conflict in setup.sh** - Resolved npm configuration conflicts during setup. (Author: [@rolandtannous](https://github.com/rolandtannous/)) - **Fixed chat template error handling** - Better error messages for chat template issues. (Author: [@rolandtannous](https://github.com/rolandtannous/)) - **Fixed dataset preview preferring tabular over archives** - Tier 1 check-format now selects parquet over zip, preventing wrong column detection for VLM datasets. (Author: [@rolandtannous](https://github.com/rolandtannous/)) - **Fixed dropdown and tooltip UI layering** - Increased tooltip z-index to appear above dropdowns. (Author: [@Imagineer99](https://github.com/Imagineer99/)) ### Performance Improvements - **Cached packed sequence metadata to reduce D2H syncs** - Packing metadata cached per device to avoid repeated device-to-host copies across transformer layers. (Author: [@ruixiangw](https://github.com/ruixiangw/)) - **TRL 0.28+ compatibility** - Updated loss computation for completion_mask, removed deprecated sync/reload weights calls, patched RPC for newer TRL versions. (Author: [@Datta0](https://github.com/Datta0/)) ### Infrastructure - **Setup.sh GPU architecture detection and Ninja build** - Auto-detects GPU compute capability via nvidia-smi, limits CMAKE_CUDA_ARCHITECTURES, uses Ninja for better parallelism, and adds --threads=0 for multi-threaded compilation. - **Setup.ps1 combined build targets** - Single cmake --build invocation for llama-server and llama-quantize on Windows to improve MSBuild parallelism. - **Subprocess isolation for training, inference, and export** - Automatic transformers version switching between tasks without rebuilding shared state. - **Added AGPL-3.0 SPDX headers** - Compliance headers added to all studio source files. - **Enhanced pip check for known third-party conflicts** - Made pip check non-fatal for expected conflicts, preventing setup failures. ### Internal Changes - **Refactored advisor from 4-pass to 3-pass LLM** - Removed Pass 3 self-scoring, trust Pass 2 output directly for better reliability. - **Column mapping refactor** - Advisor now generates column-to-role mappings instead of templates, then constructs conversations by grouping and concatenating column values by role. - **Model type derivation** - Backend now surfaces unified model_type field ("text" | "vision" | "audio" | "embeddings") instead of scattered boolean flags. - **Dataset upload to multipart/form-data** - Switched from base64 JSON to streamed multipart uploads with client-side file size validation. - **UI preferences store for chart settings** - Centralized chart styling and formatting configuration with new preferences store. - **Structlog integration for production logging** - Migrated print statements to structured logging across workers and backend. ## Autumn: Autumn Changelog - February 21-28, 2026 URL: https://www.usenotra.com/changelog/autumn/tinybird-cdc-and-entity-scoped-prepaid-pricing.md Date: 2026-02-28 This week brought significant improvements to billing infrastructure, data pipelines, and operational reliability. Prepaid tiered pricing now works entity-scoped with proper Stripe integration, while a new Tinybird CDC pipeline enables real-time analytics across 17 Postgres tables. Developer experience improved with multi-worktree support, and infrastructure got cleaner with the removal of ClickHouse in favor of Tinybird. Concurrency and cache consistency saw major upgrades through atomic Redis updates and lazy entitlement resets, while memory diagnostics moved to Axiom for better observability. ## Highlights ### Entity-scoped prepaid tiered pricing with inline Stripe prices Prepaid tiers now support per-entity pricing calculations using inline Stripe price\_data, letting each entity have independent tier math while preserving metadata across subscriptions and schedules. Checkout and scheduled switches handle quantities correctly for entity items. ### Complete Tinybird CDC for real-time analytics A new real-time Change Data Capture pipeline syncs 17 Postgres tables to Tinybird with Elixir transformations, ReplacingMergeTree deduplication, and comprehensive backfill tooling. Includes an interactive CLI, idempotent chunked backfills, and specialized scripts for tables without standard timestamp fields. ### Multi-worktree local development Developers can now run multiple instances side-by-side with the new `bun dx` command, which auto-assigns port offsets and skips workers for non-primary instances. CORS validation in dev allows any localhost:port for flexibility while prod stays allowlisted. ### Lazy customer entitlement resets on read Entitlement resets now happen automatically when fetching a customer or reading cache, using an atomic Postgres function and Redis Lua script to prevent double-resets. Eliminates manual reset workflows and keeps cache in sync with database state. ### Atomic cache updates replacing cache invalidation New Redis Lua scripts update customer data and entity records in-place instead of deleting and regenerating cache. Reduces cache misses, improves concurrency for concurrent operations like track-after-clear, and keeps FullCustomer cache consistent across regions. ## More Updates ### Features & Enhancements - **Filter API responses to hide internal fields** [#836](https://github.com/useautumn/autumn/pull/836) - Added middleware that strips internal billing fields from preview responses; dashboard requests bypass the filter. (Author: [@johnyeocx](https://github.com/johnyeocx/)) - **Stripe discounts in attach dropdown** [#819](https://github.com/useautumn/autumn/pull/819) - Expanded the attach UI to include Stripe discount objects. (Author: [@charlietlamb](https://github.com/charlietlamb/)) - **Link line items to Stripe products via metadata** - Stripe subscriptions and schedules now track product references through item metadata and price fields. (Author: [@johnyeocx](https://github.com/johnyeocx/)) ### Bug Fixes - **Fixed empty events table rendering** [#824](https://github.com/useautumn/autumn/pull/824) - Charts no longer break when the events table is empty. (Author: [@SirTenzin](https://github.com/SirTenzin/)) - **Fixed customer balance UI display** [#816](https://github.com/useautumn/autumn/pull/816) - Balance information now renders correctly in the customer detail view. (Author: [@johnyeocx](https://github.com/johnyeocx/)) - **Fixed balance sub-row display for granted amounts** [#780](https://github.com/useautumn/autumn/pull/780) - Sub-rows now consistently show /granted values. (Author: [@charlietlamb](https://github.com/charlietlamb/)) - **Fixed impersonation flow** [#793](https://github.com/useautumn/autumn/pull/793) - User impersonation no longer leaves stale state. (Author: [@charlietlamb](https://github.com/charlietlamb/)) ### Infrastructure - **Removed ClickHouse, gated analytics on Tinybird** [#836](https://github.com/useautumn/autumn/pull/836) - Deleted ClickHouse infrastructure (2,500+ lines) and migrated error codes to Tinybird equivalents. (Author: [@johnyeocx](https://github.com/johnyeocx/)) - **Memory diagnostics via Axiom logger** [#798](https://github.com/useautumn/autumn/pull/798) - Server and worker processes now periodically log memory metrics (RSS, heap, external) to Axiom with `type: "memory_log"` for easy filtering and alerting. (Author: [@joejohnson123[bot]](https://github.com/joejohnson123%5Bbot%5D/)) - **SIGUSR2 heap snapshot handler** [#798](https://github.com/useautumn/autumn/pull/798) - Sending SIGUSR2 to a process now triggers a heap snapshot that gets sent to Discord for on-demand diagnostics. (Author: [@atmn](https://github.com/atmn/)) ### Testing - **Added frontend unit tests** [#820](https://github.com/useautumn/autumn/pull/820) - Vite unit test GitHub Action now runs on each commit for frontend reliability. (Author: [@charlietlamb](https://github.com/charlietlamb/)) - **Added server unit tests in CI** [#801](https://github.com/useautumn/autumn/pull/801) - Server unit tests now run in GitHub Actions. (Author: [@charlietlamb](https://github.com/charlietlamb/)) - **Added tests for setup payment endpoint** - Comprehensive tests validate setup payment v2 flow including attach parameters. (Author: [@charlietlamb](https://github.com/charlietlamb/)) - **Added tests for CORS origin validation** [#842](https://github.com/useautumn/autumn/pull/842) - Unit tests ensure localhost origin handling works correctly in dev and prod. (Author: [@charlietlamb](https://github.com/charlietlamb/)) ### Internal Changes - **Removed unused legacy pipe** [#825](https://github.com/useautumn/autumn/pull/825) - Cleaned up old list transformation code. (Author: [@SirTenzin](https://github.com/SirTenzin/)) - **CusService now requires context parameter** [#802](https://github.com/useautumn/autumn/pull/802) - getFull and getByVercelId now take ctx for consistent transaction handling across all call sites. (Author: [@johnyeocx](https://github.com/johnyeocx/)) - **Refactored test structure** [#812](https://github.com/useautumn/autumn/pull/812) - Reorganized tests into integration/ subdirectories and consolidated overlapping test cases. (Author: [@johnyeocx](https://github.com/johnyeocx/)) - **Moved Sequin code to others/ folder** [#841](https://github.com/useautumn/autumn/pull/841) - Refactored monorepo structure to keep CDC transformation code separate. (Author: [@SirTenzin](https://github.com/SirTenzin/)) - **Dependency updates** - Hono bumped from 4.11.7 to 4.11.10. (Author: [@dependabot[bot]](https://github.com/dependabot%5Bbot%5D/)) ## Better Auth: Better Auth Changelog - February 21-28, 2026 URL: https://www.usenotra.com/changelog/better-auth/otp-race-fix-api-keys-and-d1-support.md Date: 2026-02-28 Over the past week, the team shipped a critical OTP race condition fix that prevented reuse attacks across concurrent requests. Major feature work includes organization-scoped API keys with multi-configuration support (plugin now at `@better-auth/api-key`), user enumeration protection during signup, and a new /update-session endpoint for custom session fields. Infrastructure improvements address the Drizzle adapter's date handling, add Cloudflare D1 Workers support, and migrate to Prisma v7. The updates also include ID token persistence fixes for OAuth token refresh, improved session broadcasting across browser tabs, and stricter auth\_time claim stability per OpenID Connect specs. Bug fixes cover cookie handling, SIWE validation, and better error codes. Extensive work on CI reliability, test timeouts, and documentation including a new landing page. ## Highlights ### Critical: OTP race condition allows reuse across concurrent requests Concurrent POST requests could verify the same OTP multiple times before deletion, bypassing single-use constraints and enabling account takeover. Fixed using atomic delete-before-verify across all OTP endpoints (email-otp, sign-in, password reset). [#8067](https://github.com/better-auth/better-auth/pull/8067) (Author: [@Oluwatobi-Mustapha](https://github.com/Oluwatobi-Mustapha/)) ### API Keys now scoped to organizations with multi-config support The api-key plugin now lives at `@better-auth/api-key` and supports multiple configurations per instance. Keys can be owned by organizations instead of just users. Schema changes: `userId` becomes `referenceId`, plus new `configId` and `references` fields. [#4210](https://github.com/better-auth/better-auth/pull/4210) (Author: [@ping-maxwell](https://github.com/ping-maxwell/)) ### User enumeration prevention during signup When email verification or manual signup is enabled, duplicate email attempts now return success without creating a session. Eliminates timing attacks that leak registered accounts. Optional `onExistingUserSignUp` callback for notifying account owners. [#8091](https://github.com/better-auth/better-auth/pull/8091) (Author: [@bytaesu](https://github.com/bytaesu/)) ### ID token persistence in getAccessToken auto-refresh `getAccessToken` was returning a new `idToken` from token refresh but not persisting it, leaving identity claims stale in storage. Now saved alongside access and refresh tokens. [#8211](https://github.com/better-auth/better-auth/pull/8211) (Author: [@GautamBytes](https://github.com/GautamBytes/)) ### Built-in Cloudflare D1 database support Added Kysely dialect for Cloudflare D1. BetterAuth now runs natively on Workers without custom adapters. Auto-detection via batch/exec/prepare method checks. [#7519](https://github.com/better-auth/better-auth/pull/7519) (Author: [@bytaesu](https://github.com/bytaesu/)) ## More Updates ### Security - **Keep auth\_time stable across ID token refresh** [#8134](https://github.com/better-auth/better-auth/pull/8134) - Per OpenID Connect Core 1.0, auth\_time must not change when tokens refresh. Captures original login time and carries it through token rotation. Requires migration: add nullable authTime column to oauthRefreshToken. (Author: [@grant0417](https://github.com/grant0417/)) ### Features & Enhancements - **POST /update-session endpoint** [#8084](https://github.com/better-auth/better-auth/pull/8084) - Update custom session fields and refresh the session cookie. (Author: [@himself65](https://github.com/himself65/)) - **CLI upgrade command** [#8204](https://github.com/better-auth/better-auth/pull/8204) - `npx auth upgrade` scans package.json for better-auth deps, fetches latest versions, shows a table, and installs pinned versions. (Author: [@himself65](https://github.com/himself65/)) ### Bug Fixes - **Session changes broadcast to other tabs** [#8177](https://github.com/better-auth/better-auth/pull/8177) - Sign-out and user updates now post to other open tabs so useSession stays in sync. Fixes dead-code broadcast function. (Author: [@Abhinav-kodes](https://github.com/Abhinav-kodes/)) - **Drizzle adapter date handling crash** [#8105](https://github.com/better-auth/better-auth/pull/8105) - Removed input transformation that stringified dates before insert. Dates now convert only on read. (Author: [@ping-maxwell](https://github.com/ping-maxwell/)) - **Drizzle camelCase key mapping** [#8176](https://github.com/better-auth/better-auth/pull/8176) - Schema introspection now handles camelCase column names on PostgreSQL. (Author: [@jonathan-teamstatus](https://github.com/jonathan-teamstatus/)) - **Prevent unnecessary cookie leak in Next.js** [#8193](https://github.com/better-auth/better-auth/pull/8193) - Remove spurious cookie from response headers. (Author: [@ping-maxwell](https://github.com/ping-maxwell/)) - **Multi-session setActive validation** [#8121](https://github.com/better-auth/better-auth/pull/8121) - setActive now requires multi-session cookies enabled. (Author: [@Oluwatobi-Mustapha](https://github.com/Oluwatobi-Mustapha/)) - **Delete expired Expo cookies** [#8090](https://github.com/better-auth/better-auth/pull/8090) - Properly remove expired cookies instead of storing empty values. (Author: [@bytaesu](https://github.com/bytaesu/)) - **Fix bearer token cookie merging** [#8089](https://github.com/better-auth/better-auth/pull/8089) - Use semicolon to merge multiple Set-Cookie headers. (Author: [@bytaesu](https://github.com/bytaesu/)) - **Handle undefined two-factor options** [#8162](https://github.com/better-auth/better-auth/pull/8162) - verifyTwoFactor no longer crashes when options are missing. (Author: [@okisdev](https://github.com/okisdev/)) - **Remove chainId validation limit** [#8123](https://github.com/better-auth/better-auth/pull/8123) - SIWE no longer rejects newer networks with high chain IDs. (Author: [@orshih6](https://github.com/orshih6/)) - **Use invalid\_grant for refresh token errors** [#8103](https://github.com/better-auth/better-auth/pull/8103) - Return correct OAuth error code. (Author: [@luchersou](https://github.com/luchersou/)) - **Respect freshAge in deleteUser** [#8174](https://github.com/better-auth/better-auth/pull/8174) - User deletion now checks freshAge requirement. (Author: [@bytaesu](https://github.com/bytaesu/)) - **Export getAccountCookie** [#8181](https://github.com/better-auth/better-auth/pull/8181) - Cookie helper available from better-auth/cookies for stateless flows. (Author: [@bytaesu](https://github.com/bytaesu/)) - **Fix Next.js module resolution** [#8178](https://github.com/better-auth/better-auth/pull/8178) - Use explicit .js extension in next/headers imports. (Author: [@Jordanburch101](https://github.com/Jordanburch101/)) - **Fix Stripe success URL** [#8095](https://github.com/better-auth/better-auth/pull/8095) - Use checkout session ID for redirect. (Author: [@bytaesu](https://github.com/bytaesu/)) - **Dynamic baseUrl context properties** [#8170](https://github.com/better-auth/better-auth/pull/8170) - All auth context properties now available when baseUrl is dynamic. (Author: [@Engerim](https://github.com/Engerim/)) ### Infrastructure - **Prisma v7 migration** [#8166](https://github.com/better-auth/better-auth/pull/8166) - Updated prisma-adapter and CLI. Changed: datasourceUrl now passed to PrismaClient constructor; call `prisma generate` explicitly after db push. (Author: [@himself65](https://github.com/himself65/)) - **Expo SDK 55 compatibility** [#8213](https://github.com/better-auth/better-auth/pull/8213) - Updated expo-constants, expo-linking, expo-network, expo-web-browser to SDK 55; widened expo-network peerDependency. (Author: [@himself65](https://github.com/himself65/)) - **Per-job CI concurrency groups** [#8215](https://github.com/better-auth/better-auth/pull/8215) - Test matrix jobs can now run in parallel. (Author: [@himself65](https://github.com/himself65/)) - **CI timeout and test splitting** [#8210](https://github.com/better-auth/better-auth/pull/8210), [#8209](https://github.com/better-auth/better-auth/pull/8209), [#8208](https://github.com/better-auth/better-auth/pull/8208) - Reduced flakiness in SSO, API key, OAuth provider, and Stripe tests. - **Dependency upgrades** [#8183](https://github.com/better-auth/better-auth/pull/8183) - fast-xml-parser and other packages. (Author: [@himself65](https://github.com/himself65/)) - **Package.json alignment** [#8131](https://github.com/better-auth/better-auth/pull/8131) - Added missing READMEs and aligned package fields across monorepo. (Author: [@himself65](https://github.com/himself65/)) - **Node 24 as default** [#8129](https://github.com/better-auth/better-auth/pull/8129) - Bumped minimum Node version. (Author: [@himself65](https://github.com/himself65/)) - **Bump pnpm** [#8130](https://github.com/better-auth/better-auth/pull/8130) - Updated package manager. (Author: [@himself65](https://github.com/himself65/)) ### Documentation - **New documentation and landing page** [#8195](https://github.com/better-auth/better-auth/pull/8195) - Moved landing site into main repository. (Author: [@ping-maxwell](https://github.com/ping-maxwell/)) - **Legacy /docs/errors redirect** [#8160](https://github.com/better-auth/better-auth/pull/8160) - Old error documentation links point to new structure. (Author: [@bytaesu](https://github.com/bytaesu/)) - **Convex schema generation** [#8141](https://github.com/better-auth/better-auth/pull/8141) - Clarified confusing setup steps. - **Homepage SVG paths** [#8200](https://github.com/better-auth/better-auth/pull/8200) - Fixed broken image references. - **Community plugins** [#8138](https://github.com/better-auth/better-auth/pull/8138), [#8182](https://github.com/better-auth/better-auth/pull/8182) - Added better-auth-razorpay, better-auth-payu, and better-auth-audit-logs. - **Admin plugin Electron docs** [#8171](https://github.com/better-auth/better-auth/pull/8171) - Added image proxy callout. - **Captcha ERROR\_CODES export** [#8136](https://github.com/better-auth/better-auth/pull/8136) - Error codes now importable. (Author: [@marcellosso](https://github.com/marcellosso/)) - **Description and code alignment** [#8132](https://github.com/better-auth/better-auth/pull/8132) - Fixed documentation inconsistencies. (Author: [@bytaesu](https://github.com/bytaesu/)) - **Electron build config** [#8126](https://github.com/better-auth/better-auth/pull/8126) - Improved tooling. (Author: [@jslno](https://github.com/jslno/)) - **Electron OAuth redirect** [#8143](https://github.com/better-auth/better-auth/pull/8143) - Fixed OAuth flow for Electron apps. (Author: [@jslno](https://github.com/jslno/)) ## Langfuse: Langfuse Changelog - February 21-28, 2026 URL: https://www.usenotra.com/changelog/langfuse/rbac-bypass-patch-and-dashboard-query-scheduler.md Date: 2026-02-28 This week brought four critical improvements across security, authentication, and dashboard performance. The most significant change fixes a privilege escalation vulnerability in RBAC logic, while a separate authentication fix ensures newly created users retain proper project access on self-hosted instances. Dashboard query scheduling is now active to prevent backend concurrency issues, and developers using the Observations V2 API will get proper type hints in their IDEs instead of loose `Record` types. ## Highlights ### Prototype-chain RBAC bypass patch A vulnerability in the `hasOrganizationAccess` and `hasProjectAccess` checks allowed attackers to poison the JavaScript prototype chain and escalate privileges. The fix ensures only own properties are evaluated in role checks, blocking prototype-chain attacks. (Author: [@maxdeichmann](https://github.com/maxdeichmann/)) ### Fixed project membership role downgrades on signup New users on self-hosted instances were being incorrectly downgraded from OWNER to VIEWER at the project level, preventing API key management and other owner actions. The fix respects the rbac-project-roles entitlement and ensures proper role assignment during initialization. (Author: [@Steffen911](https://github.com/Steffen911/)) ### Dashboard query scheduler reduces backend load Uncontrolled concurrent dashboard queries were overloading the backend. A new query scheduler now limits concurrent queries based on time range, prioritizing interactive loads and preventing query pile-ups during slow periods. (Author: [@nimarb](https://github.com/nimarb/)) ### Typed Observations API for better IDE support The Observations V2 response data field now has proper TypeScript types instead of `Record`. SDK users get autocomplete and catch type errors at build time rather than runtime. (Author: [@sumerman](https://github.com/sumerman/)) ### ClickHouse query optimization with bloom filters Added bloom filter indexes on model names and enabled cache prewarming in events tables to speed up common filter operations. (Author: [@sumerman](https://github.com/sumerman/)) ## More Updates ### Security - **Block AWS metadata IPv6 endpoint** [#12296](https://github.com/langfuse/langfuse/pull/12296) - Webhook outbound requests now block the AWS metadata service IPv6 endpoint to prevent instance metadata disclosure. (Author: [@maxdeichmann](https://github.com/maxdeichmann/)) ### Bug Fixes - **Fixed events table position-in-trace calculation** [#12329](https://github.com/langfuse/langfuse/pull/12329) - Refactored trace position queries to read from events\_core for accurate row ordering. (Author: [@nimarb](https://github.com/nimarb/)) - **Fixed evaluation automation column resolution** [#12269](https://github.com/langfuse/langfuse/pull/12269) - Added missing observation columns to CTE to prevent ClickHouse errors when eval automations filter on latency, cost, or token usage fields. (Author: [@sumerman](https://github.com/sumerman/)) - **Fixed dashboard Trace Name filtering** [#12298](https://github.com/langfuse/langfuse/pull/12298) - Corrected filtering on aggregated trace names to use HAVING clause instead of falling through to observation-level filters. (Author: [@sumerman](https://github.com/sumerman/)) - **Fixed default widget view selection in V4 beta** [#12297](https://github.com/langfuse/langfuse/pull/12297) - New dashboard widgets respect V4 beta settings on creation instead of defaulting to v2. (Author: [@Copilot](https://github.com/Copilot/)) - **Fixed empty arrayOptions URL roundtrip** [#12229](https://github.com/langfuse/langfuse/pull/12229) - Correct decoding of empty array filters when sharing filtered dashboard URLs. (Author: [@gnsals0904](https://github.com/gnsals0904/)) - **Fixed traces view for rootless traces** [#12307](https://github.com/langfuse/langfuse/pull/12307) - Improved visibility of projects with orphaned observations by adjusting trace view to show more relevant data. (Author: [@sumerman](https://github.com/sumerman/)) - **Fixed inline eval filter state remount** [#12255](https://github.com/langfuse/langfuse/pull/12255) - Prevent eval filter state from stale closures when changing filter targets. (Author: [@marliessophie](https://github.com/marliessophie/)) - **Re-added user and session metrics to V4 dashboard** [#12317](https://github.com/langfuse/langfuse/pull/12317) - V4 dashboard queries now include uniqueUserIds and uniqueSessionIds calculations. (Author: [@sumerman](https://github.com/sumerman/)) - **Fixed cost and usage queries missing version parameter** [#12235](https://github.com/langfuse/langfuse/pull/12235) - ModelUsageChart now passes metricsVersion prop so cost queries use fast v2 path instead of legacy observations table. (Author: [@sumerman](https://github.com/sumerman/)) - **Docker Redis named volume support** [#12258](https://github.com/langfuse/langfuse/pull/12258) - Docker Compose now creates a named volume for Redis instead of anonymous volumes, preventing clutter on repeated starts. (Author: [@Steffen911](https://github.com/Steffen911/)) - **Prisma migration schema compatibility** [#12209](https://github.com/langfuse/langfuse/pull/12209) - Made pending\_deletions index migration work with custom PostgreSQL schemas by removing hardcoded schema prefixes. (Author: [@sumerman](https://github.com/sumerman/)) - **Fixed model prices Claude version handling** [#12219](https://github.com/langfuse/langfuse/pull/12219) - Made Claude version identifier optional in price calculations. (Author: [@hassiebp](https://github.com/hassiebp/)) - **Google adapter thinking config pass-through** [#12211](https://github.com/langfuse/langfuse/pull/12211) - LLM connections now allow passing thinking config for Google adapters via provider options. (Author: [@hassiebp](https://github.com/hassiebp/)) - **OpenTelemetry event timestamp defaults** [#12200](https://github.com/langfuse/langfuse/pull/12200) - Add default timestamps for OpenTelemetry events when not provided. (Author: [@maxdeichmann](https://github.com/maxdeichmann/)) - **Fixed eval V4 beta hook destructuring** [#12214](https://github.com/langfuse/langfuse/pull/12214) - Correct unpacking of V4 beta context in eval components. (Author: [@marliessophie](https://github.com/marliessophie/)) - **Fixed arrayOptions checkbox filter matching** [#12206](https://github.com/langfuse/langfuse/pull/12206) - Use positive matching logic for arrayOptions filters to improve consistency. (Author: [@gnsals0904](https://github.com/gnsals0904/)) ### Features & Enhancements - **Multi-tenant SSO token endpoint auth method override** [#12270](https://github.com/langfuse/langfuse/pull/12270) - Supports tokenEndpointAuthMethod field in multi-tenant SSO configs to match static provider capabilities, enabling client\_secret\_post and other OAuth methods. (Author: [@Steffen911](https://github.com/Steffen911/)) - **Webhook payloads include triggering user info** [#12074](https://github.com/langfuse/langfuse/pull/12074) - Webhook and GitHub dispatch events now include optional user field with triggering user's id, name, and email for audit and integration workflows. (Author: [@rushabhvaria](https://github.com/rushabhvaria/)) - **Dashboard widget definition versioning** [#12239](https://github.com/langfuse/langfuse/pull/12239) - Track and validate widget definition versions for dashboard backwards compatibility and migration support. (Author: [@sumerman](https://github.com/sumerman/)) - **ClickHouse Cloud sign-in provider** [#12115](https://github.com/langfuse/langfuse/pull/12115) - Added dedicated ClickHouse Cloud auth provider for Langfuse Cloud deployments with custom branding. (Author: [@Steffen911](https://github.com/Steffen911/)) - **Extended thinking support in playground and evals** [#12233](https://github.com/langfuse/langfuse/pull/12233) - Playground and evaluation UI now handle model thinking blocks for models that use extended thinking. (Author: [@nimarb](https://github.com/nimarb/)) - **Pydantic root span input/output mapping** [#12068](https://github.com/langfuse/langfuse/pull/12068) - UI traces now map Pydantic input/output data to the root span for clearer visibility. (Author: [@jannikmaierhoefer](https://github.com/jannikmaierhoefer/)) - **Trace table hover data display** [#12237](https://github.com/langfuse/langfuse/pull/12237) - Show full trace data on hover even when row height is compact for better readability. (Author: [@aditya-mitra](https://github.com/aditya-mitra/)) - **Eval automations show evaluation prompt on hover** [#12208](https://github.com/langfuse/langfuse/pull/12208) - Evaluators now display the evaluation prompt template on hover for quick reference and debugging. (Author: [@aditya-mitra](https://github.com/aditya-mitra/)) - **LiveKit trace attribute parsing** [#10771](https://github.com/langfuse/langfuse/pull/10771) - OpenTelemetry spans from LiveKit are now parsed and displayed with proper trace tree hierarchy. (Author: [@jannikmaierhoefer](https://github.com/jannikmaierhoefer/)) - **Experiments feature pages with admin checks** [#12064](https://github.com/langfuse/langfuse/pull/12064) - Gated experiments feature for Langfuse Cloud admins with routing and permission validation. (Author: [@marliessophie](https://github.com/marliessophie/)) - **API scores return execution trace ID** [#12254](https://github.com/langfuse/langfuse/pull/12254) - Evaluation API responses now include the execution trace ID for easier tracking and correlation. (Author: [@hassiebp](https://github.com/hassiebp/)) ### Performance Improvements - **ClickHouse query condition caching** [#12251](https://github.com/langfuse/langfuse/pull/12251) - Enable query condition cache for analytics queries to reduce duplicated processing. (Author: [@sumerman](https://github.com/sumerman/)) - **Event property scan optimization** [#12221](https://github.com/langfuse/langfuse/pull/12221) - Reduce ClickHouse scan size for event property filters by using GREATEST function instead of OR chains. (Author: [@Steffen911](https://github.com/Steffen911/)) - **Environment filter caching re-enabled** [#12286](https://github.com/langfuse/langfuse/pull/12286) - Re-enable environment filter caching to improve query performance. (Author: [@nimarb](https://github.com/nimarb/)) - **Dual write parallelization** [#12225](https://github.com/langfuse/langfuse/pull/12225) - Speed up event ingestion by parallelizing inserts across storage backends. (Author: [@Steffen911](https://github.com/Steffen911/)) - **Optimized trace position calculation** [#12137](https://github.com/langfuse/langfuse/pull/12137) - Refactored events table scores query to use flat queries instead of heavy aggregation for faster filtering and display. (Author: [@nimarb](https://github.com/nimarb/)) ### Documentation - **Observation-level evals positioning** [#12293](https://github.com/langfuse/langfuse/pull/12293) - Updated docs to position observation-level evals as the preferred evaluation strategy. (Author: [@marliessophie](https://github.com/marliessophie/)) - **Agent framework integration guide** [#12243](https://github.com/langfuse/langfuse/pull/12243) - Updated agents.md integration documentation. (Author: [@nimarb](https://github.com/nimarb/)) ### Infrastructure - **Docker build image turbo version pinning** [#12265](https://github.com/langfuse/langfuse/pull/12265) - Pin turbo version in Docker build images to ensure consistent builds. (Author: [@maxdeichmann](https://github.com/maxdeichmann/)) - **DataDog observability enhancement** [#12091](https://github.com/langfuse/langfuse/pull/12091) - Enhanced DataDog spans with HTTP status code tracing. (Author: [@coffee4tw](https://github.com/coffee4tw/)) - **Cloud release script** [#12312](https://github.com/langfuse/langfuse/pull/12312) - Added release script for cloud deployments. (Author: [@hassiebp](https://github.com/hassiebp/)) ### Internal Changes - **Bcrypt timing consistency** [#12321](https://github.com/langfuse/langfuse/pull/12321) - Equalize bcrypt computation time on invalid credential paths to prevent timing attacks. (Author: [@maxdeichmann](https://github.com/maxdeichmann/)) - **Secondary eval execution queue** [#12252](https://github.com/langfuse/langfuse/pull/12252) - Introduced secondary evaluation queue for improved workload distribution. (Author: [@maxdeichmann](https://github.com/maxdeichmann/)) - **Admin access webhook dispatch** [#12207](https://github.com/langfuse/langfuse/pull/12207) - Send webhooks for admin access events to improve audit trails. (Author: [@maxdeichmann](https://github.com/maxdeichmann/)) - **React resizable panels upgrade** [#12238](https://github.com/langfuse/langfuse/pull/12238) - Updated layout library to v4 with sticky layout fixes. (Author: [@nimarb](https://github.com/nimarb/)) - **Fern SDK version upgrades** [#11267](https://github.com/langfuse/langfuse/pull/11267) - Updated Fern API generation tool for SDK generation. (Author: [@hassiebp](https://github.com/hassiebp/)) - **Fernapi package update** [#12256](https://github.com/langfuse/langfuse/pull/12256) - Updated fernapi dependency. (Author: [@Steffen911](https://github.com/Steffen911/)) - **Trace data propagation window** [#12191](https://github.com/langfuse/langfuse/pull/12191) - Restrict trace data propagation to recent data only. (Author: [@Steffen911](https://github.com/Steffen911/)) - **Event table score display** [#12264](https://github.com/langfuse/langfuse/pull/12264) - Added score columns to events table UI. (Author: [@nimarb](https://github.com/nimarb/)) - **Billing page copy update** [#12314](https://github.com/langfuse/langfuse/pull/12314) - Adjusted wording on billing pages. (Author: [@jannikmaierhoefer](https://github.com/jannikmaierhoefer/)) - **V4 UI beta banner** [#12266](https://github.com/langfuse/langfuse/pull/12266) - Added notification banner for V4 dashboard beta users. (Author: [@hassiebp](https://github.com/hassiebp/)) - **UI banner styling** [#12283](https://github.com/langfuse/langfuse/pull/12283) - Fine-tuned V4 banner spacing. (Author: [@hassiebp](https://github.com/hassiebp/)) - **Anthropic adapter headers support** [#12284](https://github.com/langfuse/langfuse/pull/12284) - Allow custom headers in Anthropic LLM adapter configuration. (Author: [@hassiebp](https://github.com/hassiebp/)) ## OpenClaw: OpenClaw Changelog - February 21-28, 2026 URL: https://www.usenotra.com/changelog/openclaw/prompt-injection-fix-secrets-management-and-android-feishu-expansion.md Date: 2026-02-28 This week closes a prompt injection vulnerability in context compaction, adds external secrets management with exec providers and SOPS support, and significantly expands Android device integration and Feishu document capabilities. The Feishu improvements include markdown table rendering, document chunking, media extraction, and full CRUD operations on tables. Android now supports motion detection, pedometer, calendar, contacts, and device diagnostics. Security fixes harden auth boundaries across channels, tighten system.run approval binding, and prevent unauthorized DM command execution. ## Highlights ### External secrets management framework Credential handling moves off inline .env files. The new architecture supports exec-based providers (1Password, Vault, secretive), file-backed configs, and SOPS integration for automated secret lifecycle management without process restarts. ### Feishu documents with markdown tables and full CRUD operations Document write/append now renders markdown tables as native Feishu tables, chunks large payloads to avoid API errors, supports positional insertion and color markup, and enables comprehensive table operations: merge cells, insert/delete rows and columns, embed media. ### Post-compaction prompt injection vulnerability removed The Layer 3 audit injection created fake system messages after context compaction to force file reads. Deleted entirely. Layers 1 and 2 (compaction summary and AGENTS.md context refresh) remain intact for legitimate recovery. Fixes #27697, #26851, #20484, #22339, #25600. ### Android device capabilities: motion, pedometer, calendar, contacts, camera, diagnostics New handlers unlock motion activity classification, step counting, calendar read, contact queries, photo access, notification actions, and device status reporting. Completes parity with Node.js device API surface. ### Cron job delivery hardened with explicit account routing and session isolation Fixed main-target cron jobs to deliver notifications by passing target=last heartbeat flag. Added --account flag for delivery routing. Prevented false-positive delivery states for queued announces. Cleared delivery routing metadata on isolated session creation. ## More Updates ### Security - **Removed post-compaction audit injection vulnerability** - Deleted Layer 3 audit that injects fake system messages via prompt injection after context compaction. Preserves legitimate Layers 1 and 2 recovery flows. Fixes #27697, #26851, #20484, #22339, #25600. - **External secrets management framework** - Provider-based architecture supporting exec-backed, file-backed, and SOPS providers for credential lifecycle management without inline .env storage. - **Harden node system.run approvals against symlink rebind attacks** - Tighten exec approval binding to prevent execution of attacker-controlled symlinked binaries. - **Enforce v1 node exec approval binding and generate host env policy** - Centralize system.run binding logic and environment variable generation for consistent approval enforcement. - **Feishu webhook rate-limit state bounding** - Limit unauthenticated webhook rate-limit tracking to prevent memory exhaustion attacks on public endpoints. - **Explicit group auth boundaries across all channels** - Reject dmPolicy=\\"allowlist\\" with empty allowFrom across Telegram, Discord, Slack, Signal, IRC, iMessage, BlueBubbles, Teams, Google Chat, WhatsApp; add doctor warnings with remediation. - **Prevent unauthorized open-mode DM commands via hardened auth composition** - Centralize dm/group allowlist policy composition to prevent command injection in open-mode DMs. - **Preserve turn-origin messageChannel in agent runs** - Prevent session confusion and unauthorized message routing via proper origin tracking. - **Harden plugin route auth path canonicalization** - Prevent directory traversal in plugin routes via strict path normalization. - **Typing lifecycle and cross-channel suppression hardening** - Enforce proper typing indicator cleanup across channel boundaries. - **Harden compaction and reset safety** - Add regression tests and guards for agent compaction and workspace reset operations. - **Mattermost monitor media SSRF fallback** - Avoid raw fetch in media download fallback path. - **Teams file-consent timeout hardening** - Complete file upload async handling with proper timeout enforcement. - **BlueBubbles attachment SSRF host whitelisting** - Allow explicitly configured hosts for attachment downloads. ### Features & Enhancements - **Feishu Docx table creation and image/file upload actions** - Full Feishu document operations with native table support, file attachment operations, and seamless image upload. - **Feishu markdown table and positional insert support** - Render GFM markdown tables as native Feishu tables with adaptive column widths; add positional markdown insertion after block IDs. - **Feishu color markup and table operations** - Apply color/bold via [red]text[/red] markup syntax; merge cells, insert/delete rows and columns. - **Feishu embedded post media extraction** - Extract and download embedded video/media files from rich text posts. - **Feishu parent/root message context for quotes** - Add ParentMessageId and RootMessageId to inbound context; parse interactive card content in quoted messages. - **Feishu group sender allowlist support** - Global groupSenderAllowFrom for sender-level group access control independent of message channel policy. - **Feishu wildcard group policy fallback** - Honor channels.feishu.groups[\\"\*\\"] fallback with exact-match and case-insensitive precedence. - **Feishu local image path auto-conversion** - Auto-convert local image path text to image message type in outbound dispatch. - **Feishu merge\_forward message parsing** - Parse merged forwarded messages for full conversation context. - **Feishu reaction event support** - Created and deleted reaction events now trigger inbound message context updates. - **Feishu DM skip reply-to reference** - Use message.create instead of message.reply in DMs to avoid visible quote references while preserving typing indicators. - **Feishu ocx chat ID session routing fix** - Properly distinguish group vs DM sessions using chat\_mode field instead of ID prefix assumptions. - **Feishu replyInThread configuration** - Route message replies to threads when configured. - **Feishu code block and share\_chat message parsing** - Extract text from code blocks and shared chat references. - **Feishu interactive card action callback support** - Handle card.action.trigger callbacks from interactive cards. - **Feishu streaming card header support** - Optional colored header parameter for streaming cards matching non-streaming card appearance. - **Feishu WebSocket proxy agent support** - Pass HttpsProxyAgent to WSClient for proxy environment WebSocket connectivity. - **Feishu large document chunking** - Chunk markdown for write/append to avoid API 400 errors; skip heading detection in fenced code blocks. - **Feishu quota optimization flags** - New configuration options for quota-aware operation. - **Feishu user\_id fallback for sender identity** - Fall back to user\_id when open\_id is unavailable. - **Feishu audio opus format for voice bubbles** - Send opus audio format for feishu voice bubble support. - **Feishu document auto-permission grant** - Automatically grant document permissions to requesting users. - **Feishu media payload attachment sending** - Send media payloads as document attachments for proper file handling. - **Feishu probeFeishu result caching** - Cache API probe results with 10-minute TTL to reduce redundant API calls. - **Feishu typing indicator error logging** - Replace console.log with runtime log for typing indicator failures. - **Feishu group policy enforcement gaps** - Respect groupConfig.enabled flag; fix log messages for group allowlist rejection. - **Feishu sequential block insertion** - Insert document blocks sequentially to preserve order when writing/appending large documents. - **Android voice reliability enhancements** - Rotate playback token per assistant reply; retry talk config after transient failures; cancel in-flight speech when speaker muted. - **Android voice speaker toggle** - Add speaker toggle in voice tab for audio output routing control. - **Android voice final reply speaking** - Speak final voice replies in mic capture flow for complete audio interaction. - **Android capability discovery and device handlers** - Motion activity classification, pedometer tracking, calendar queries, contact reading, photo access, system notifications. - **Android device diagnostics and notification actions** - Expose device status, battery, and notification action commands via node runtime. - **Android camera list and device selection** - List available cameras and select camera device for capture operations. - **Android canvas capability refresh** - Refresh scoped canvas URLs for new A2UI sessions with proper parameter binding. - **Device timestamp context** - Add human-readable timestamp field to conversation info JSON for time-aware agents. - **Cron account routing** - Add --account flag for explicit delivery account routing in cron jobs. - **Android onboarding enforcement** - Enforce custom model context minimum in onboarding; block onboarding advance until special setup completion; add missing capability setup surfaces. - **German locale support (de)** - Add German language support. - **Tool call name whitespace normalization** - Normalize whitespace-padded tool call names before dispatch. - **Browser URL alias support** - Accept url alias for open and navigate actions. - **Codex model API schema** - Add openai-codex-responses to ModelApiSchema for proper Codex routing. - **TTS voice-bubble channel coverage** - Enable opus format and voice bubbles for Feishu and WhatsApp. - **External link verification in signup flows** - Email-link completion flows with clear status handling. - **Device-auth v2 migration diagnostics** - Add specific detail codes for device auth migration issues. - **MiniMax provider authHeader default** - Default authHeader to true for MiniMax API provider. - **Slack /agentstatus alias** - Native Slack alias support for agent status command. ### Bug Fixes - **Ollama autodiscovery hardening** - Auto-discover Ollama models without API key; demote zero-models warn log to debug. - **Ollama context window unification** - Inject num\_ctx for OpenAI-compatible transport; discover per-model context; cap discovery concurrency. - **Ollama skip discovery when explicit models configured** - Prevent redundant discovery when explicit model list already exists. - **Ollama API provider default to native** - Default explicit-model provider API to native ollama instead of OpenAI compat mode. - **LanceDB custom baseUrl and dimensions support** - Add custom OpenAI BaseURL and embedding dimensions for vector search configuration. - **Browser navigate renderer swap targetId resolution** - Resolve correct targetId after Chrome renderer swap (e.g., chrome-extension to https). - **Browser URL alias support** - Accept url alias for open and navigate tool schemas. - **Podman Quadlet setup fixes** - Fix sed escaping in path substitution; add User mapping to resolve container UID mismatches. - **Model reasoning preservation in fallback** - Preserve reasoning output during provider fallback resolution. - **Google Gemini OAuth provider handling** - Add google provider to reasoning tag detection; add forward-compat fallback for gemini-3.1 models. - **Google Fonts CSP allowlist** - Allow Google Fonts stylesheet and font CDN origins in Control UI CSP. - **Ollama CLI apiKey config without provider** - Seed Ollama provider on apiKey config set. - **Browser fill field type default** - Default missing fill field type to 'text' for form interactions. - **Node default canvas node resolution** - Resolve default node when multiple canvas-capable nodes connected. - **Cron main-target session wake routing** - Pass heartbeat target=last for main-session cron jobs to restore notification delivery. - **Cron delivery state false-positives** - Mark queued announce paths as undelivered instead of delivered when no direct send confirmed. - **Cron completion direct send gating** - Enable direct send for text-only announce delivery completion. - **Cron session isolation and delivery state clearing** - Clear delivery routing metadata when creating isolated cron sessions. - **Cron messaging tool gating** - Disable messaging tool when delivery.mode is none. - **Cron delivery target resolution** - Condition requireExplicitMessageTarget on resolved delivery to prevent tool errors. - **Cron next wake scheduling for isolated jobs** - Schedule nextWakeAtMs correctly for isolated sessionTarget cron jobs. - **Browser sandbox docker no-sandbox rollout** - Enable no-sandbox mode in browser Docker container. - **Browser relay reconnect resilience** - Improve relay connection resilience for browser transport. - **Android notification wake deduping** - Skip heartbeat wake on deduped notifications to prevent duplicate processing. - **Android notification session canonicalization** - Canonicalize notification wake session routing. - **Android notification scope to session** - Scope notification wakeups to proper session context. - **Android voice final reply speaking in mic flow** - Speak final voice replies during talk-mode interaction. - **Android motion sampling stabilization** - Stabilize motion sampling and gate pedometer command properly. - **Android camera invoke parameter JSON parsing** - Parse camera and screen invoke params as JSON objects. - **Telegram allowlist DM migration** - Repair DM allowlist migrations across account channels. - **Telegram reply media context** - Include replied media files in reply context for forwarded messages. - **Telegram stop-created preview finalization** - Refactor preview finalization to prevent duplicate sends on edit failure. - **Telegram outbound chunking** - Enforce shared outbound chunking and preserve whitespace in HTML retry chunking. - **Discord thread binding lifecycle** - Migrate thread bindings to idle and max-age lifecycle with proper persistence. - **Discord slash command options validation** - Validate Discord slash command option payloads. - **Discord /acp native option payload** - Avoid invalid /acp option payload generation. - **Matrix sender label preservation** - Preserve sender labels in Matrix BodyForAgent context. - **NextCloud Talk account lifecycle** - Keep startAccount pending until abort to prevent restart loops. - **Google Chat account lifecycle** - Keep startAccount pending until abort to prevent restart loops. - **Gateway TLS probe with self-signed certificates** - Support wss:// scheme in gateway status probe for TLS-enabled bind=lan. - **Gateway auto-discovery of OpenClaw-managed services** - Detect OPENCLAW\_LAUNCHD\_LABEL and OPENCLAW\_SYSTEMD\_UNIT for supervised mode. - **Gateway stale PID cleanup before restart** - Clean stale gateway PIDs before triggerOpenClawRestart to prevent port conflicts. - **Gateway delivery recovery backoff eligibility** - Fix delivery queue blockage by continuing on backoff overrun instead of breaking. - **LaunchD CA certificate propagation** - Add NODE\_EXTRA\_CA\_CERTS to LaunchAgent environment for TLS verification. - **LaunchD ThrottleInterval** - Add ThrottleInterval plist entry to prevent launchd restart loops. - **CLI gateway --force resilience** - Make gateway --force resilient to lsof EACCES failures. - **CLI gateway run --auth help** - List all supported auth modes in gateway run help. - **Plugin npm pack recovery** - Recover npm pack archive when stdout is empty. - **Plugin npm install error clearing** - Clear npm install error when npm package not found. - **Node24 executable name support** - Accept node24 in argv reparse for Node.js 24 compatibility. - **Compaction reasoning preservation** - Preserve reasoning in model fallback resolution during compaction. - **Compaction opaque identifier preservation** - Preserve opaque identifiers in compaction summaries. - **Memory readonly sync recovery** - Support readonly sync recovery for remote memory access. - **Delivery queue head-of-line blocking fix** - Change break to continue in backoff recovery to prevent permanent blockage. - **Session outbound context forwarding** - Forward resolved session context in agent delivery for proper routing. - **Assistant usage snapshot preservation** - Preserve assistant usage snapshots during compaction cleanup. - **TUI streamed text preservation during tool transitions** - Preserve already-streamed assistant text when tool calls are triggered. - **Chat timestamp context** - Make agents time-aware with message timestamps in conversation info. - **Android clipboard output cleanup** - Clear relevant-memories scaffolding from web UI. - **Gemini 3 Pro tier normalization** - Normalize bare gemini-3-pro model IDs to include -low or -high tier for Antigravity API. - **Gemini 3.1 forward-compat models** - Add forward-compat fallback for gemini-3.1-pro and gemini-3.1-flash models in Google CLI OAuth. - **OpenAI Responses server-side compaction** - Auto-enable compaction support for OpenAI Responses. - **Custom provider onboarding verification timeout** - Increase timeout from 10s to 30s and reduce max\_tokens from 1024 to 1 for local model verification. - **Codex transport websocket-first default** - Default codex transport to websocket-first for improved reliability. - **Outside-workspace error distinction** - Distinguish outside-workspace errors from not-found in fs-safe for clear user messages. - **File system path traversal safety** - Handle outside-workspace error in media store with proper scoping. - **Feishu proxy SSRF bypass** - Add Feishu proxy agent pass-through for SSRF guard while respecting explicit proxies. - **Gateway webUI CSP Google Fonts issue** - Remove CSP-blocked Google Fonts import that was never loading. - **Onboard custom model context enforcement** - Enforce minimum custom model context in onboarding flow. - **Docker CLI symlink fix** - Replace npm link with root CLI symlink for permission-safe CLI access. - **Windows path namespace normalization** - Normalize namespaced paths for proper containment checks. - **Browser application error wrapping** - Stop wrapping application errors with generic \\"Can't reach\\" message. ### Performance Improvements - **Android mic conversation update churn reduction** - Reduce unnecessary conversation state updates during microphone interaction. - **Feishu cron probeFeishu result caching** - Cache probe results with 10-minute TTL to reduce redundant Feishu API calls. ### Infrastructure - **Update server-cron.ts and models-config.providers.ts** - Maintenance updates to cron and model configuration. - **appcast sparkle version floor enforcement** - Enforce lane floor for calver appcast entries to prevent downgrade loops. - **macOS Sparkle build monotonicity** - Make default Sparkle build version monotonic across same-day releases. - **CI Windows timeout configuration** - Add timeout for Windows checks job to prevent hangs. - **Dependabot npm deprecation warning fixes** - Remove global Google auth pnpm overrides; make @discordjs/opus optional peer. - **npm global install deprecation** - Reduce npm deprecation warnings through dependency pinning and peer configuration. - **CI DNS resolution health check** - Monitor CI GitHub App token health. - **Gateway config reference alignment** - Expand config reference coverage for channels plugins and providers. - **Security policy documentation** - Clarify command-risk reports and obfuscation parity scope. ### Testing & Documentation - **Regression test suite expansion** - Add extensive regression coverage for compaction, reset, auth boundaries, device capabilities, and mail flows. - **Android integration test infrastructure** - Full integration test suite for live Android device capabilities with preconditions and pitfall documentation. - **Feishu docx test mocking** - Add documentBlockDescendant mock for feishu docx tests. - **GitHub issue templates** - Add regression bug template with routing for issue triage. - **ACP operator playbook expansion** - Expand /acp operator documentation with complete playbook. - **Device auth migration diagnostics documentation** - Add troubleshooting guide for device auth v2 migration. - **SOPS migration and secrets documentation** - Complete secrets reference, CLI guide, and migration documentation. - **Docker Dependabot interval** - Keep Docker Dependabot updates weekly for security patches. ## Autumn: Autumn Changelog - February 14-21, 2026 URL: https://www.usenotra.com/changelog/autumn/sdk-publishing-and-billing-flow-fixes.md Date: 2026-02-21 This week focused on SDK publishing infrastructure, critical bug fixes in billing and payment flows, and backend reorganization to support more flexible feature routing. Several pricing and invoice handling issues were resolved, along with improved attachment parameter configuration. ## Highlights ### SDK publish workflow stabilized Implemented secure OIDC trusted publishing with NPM version validation, ensuring reliable automated SDK releases to npm with proper dependency verification. ### Pricing table currency regression fixed Corrected display and calculation of currency values in pricing tables, restoring correct local currency formatting across checkout flows. ### Invoice mode parameter handling improved Updated attach checkpoint to properly handle invoice mode parameters, fixing edge cases where payment method requirements weren't correctly evaluated. ### Balance subrow calculation corrected Fixed balance row calculation issues in ledger displays, ensuring accurate financial data presentation in customer account statements. ### RPC feature router architecture introduced Refactored backend action handlers into a feature router pattern, aligning RPC handlers with product actions for more maintainable feature development. ## More Updates ### Bug Fixes - **Fixed balance subrow display issue** - Corrected calculation and rendering of balance subrows in account ledgers. (Author: [@charlietlamb](https://github.com/charlietlamb/)) - **Fixed pricing table currency display** - Resolved regression where currency values weren't rendering correctly in pricing tables. (Author: [@SirTenzin](https://github.com/SirTenzin/)) - **Fixed Vercel deployment status check** - Corrected status readiness detection in Vercel integration. (Author: [@SirTenzin](https://github.com/SirTenzin/)) - **Fixed invoice mode without payment method** - Updated invoice checkout to handle cases where payment method is not required. (Author: [@johnyeocx](https://github.com/johnyeocx/)) ### Features & Enhancements - **Finalized attach v2 checkout parameters** - Completed parameter validation and routing for attach v2 endpoints. (Author: [@johnyeocx](https://github.com/johnyeocx/)) - **Added discounts to legacy attach upgrade flow** - Extended discount support to legacy attachment upgrade scenarios. (Author: [@charlietlamb](https://github.com/charlietlamb/)) - **Improved billing error handling** - Enhanced error messages and status handling in billing operations. (Author: [@charlietlamb](https://github.com/charlietlamb/)) - **Added mobile support to date/time inputs** - Extended date and time input components with mobile-friendly interactions. (Author: [@charlietlamb](https://github.com/charlietlamb/)) ### Internal Changes - **Refactored product actions to internal structure** - Reorganized product action handlers under internal/product/actions for clearer code organization. (Author: [@SirTenzin](https://github.com/SirTenzin/)) - **Aligned plan RPC handlers with actions paths** - Standardized RPC handler paths to match product actions structure. (Author: [@SirTenzin](https://github.com/SirTenzin/)) - **Updated drizzle-orm tsconfig path** - Explicitly configured drizzle-orm resolution in server TypeScript configuration. (Author: [@johnyeocx](https://github.com/johnyeocx/)) - **Fixed imports for SDK compatibility** - Corrected import paths for proper SDK module resolution. (Author: [@johnyeocx](https://github.com/johnyeocx/)) ### Infrastructure & Testing - **Implemented OIDC trusted publishing** - Configured NPM package publishing with OpenID Connect for secure CI/CD token handling. (Author: [@johnyeocx](https://github.com/johnyeocx/)) - **Ensured NPM minimum version requirement** - Added version constraint (npm >= 11.5.1) for trusted publishing support. (Author: [@johnyeocx](https://github.com/johnyeocx/)) - **Added SQS client restart capability** - Improved queue client resilience with restart logic for connection failures. (Author: [@johnyeocx](https://github.com/johnyeocx/)) - **Lowered SQS client restart threshold** - Tuned restart conditions for more responsive queue client recovery. (Author: [@johnyeocx](https://github.com/johnyeocx/)) ## Better Auth: Better Auth Changelog - February 14-21, 2026 URL: https://www.usenotra.com/changelog/better-auth/mcp-cli-and-oauth-hardening.md Date: 2026-02-21 Over the past week, Better Auth shipped tooling improvements, security hardening, and expanded OAuth support. The team released an auth CLI, added legacy OAuth client support, and merged several stability fixes for session handling, rate limiting, and email verification flows. Two beta releases went out (v1.5.0-beta.14 and beta.15). ## Highlights ### Framework-agnostic MCP auth client New `@better-auth/mcp` package lets you run auth workflows in any environment that supports Model Context Protocol, not just Node/Deno runtimes. ### Auth command-line interface The `auth init` CLI walks you through configuration without manual file edits, making first-run setup faster for new projects. (Author: [@jslno](https://github.com/jslno/)) ### Legacy OAuth support for clients without PKCE Servers can now accept older OAuth clients that don't implement PKCE. This matters for integrations with enterprise systems built before PKCE became standard. (Author: [@OscarCornish](https://github.com/OscarCornish/)) ### Email OTP user enumeration fix Sign-up flows with email OTP now avoid revealing whether an email is registered, preventing attackers from harvesting valid accounts. (Author: [@jslno](https://github.com/jslno/)) ### Dynamic auth baseURL with allowedHosts Configure the auth endpoint as a function instead of a string, letting middleware rewrite URLs based on the incoming request. Pairs with `allowedHosts` to validate origins. (Author: [@Paola3stefania](https://github.com/Paola3stefania/)) ## More Updates ### Features & Enhancements - **Added Railway OAuth provider** [#7730](https://github.com/better-auth/better-auth/pull/7730) - Simplifies authentication for Railway-hosted apps. (Author: [@kadumedim](https://github.com/kadumedim/)) - **Shared redirectURI option for OIDC** [#7818](https://github.com/better-auth/better-auth/pull/7818) - OIDC providers can now use a single redirect URL instead of configuring per-provider. (Author: [@Paola3stefania](https://github.com/Paola3stefania/)) - **Allow manual token exchange in Electron** [#7976](https://github.com/better-auth/better-auth/pull/7976) - Desktop apps can now complete OAuth without relying on built-in browser handling. (Author: [@jslno](https://github.com/jslno/)) - **Support callback for trusted providers** [#7904](https://github.com/better-auth/better-auth/pull/7904) - Trusted provider lists can now be computed dynamically rather than hardcoded. (Author: [@Siumauricio](https://github.com/Siumauricio/)) - **Stripe schedule-at-period-end for plan changes** [#8064](https://github.com/better-auth/better-auth/pull/8064) - Defer subscription changes until billing cycle ends instead of applying immediately. (Author: [@bytaesu](https://github.com/bytaesu/)) - **Stripe subscription schedule tracking** [#8070](https://github.com/better-auth/better-auth/pull/8070) - Store pending schedule IDs so you can query subscription change status. (Author: [@bytaesu](https://github.com/bytaesu/)) ### Bug Fixes - **Phone number callback on password reset** [#8046](https://github.com/better-auth/better-auth/pull/8046) - Password resets now trigger SMS verification callbacks. (Author: [@jslno](https://github.com/jslno/)) - **Merge trusted origins from plugin init** [#8056](https://github.com/better-auth/better-auth/pull/8056) - Plugins can now extend the trusted origin list without overwriting existing entries. (Author: [@jslno](https://github.com/jslno/)) - **Rate limit hardening for phone-number** [#8006](https://github.com/better-auth/better-auth/pull/8006) - Tightened default rate limits and fixed phone-number window configuration. (Author: [@Paola3stefania](https://github.com/Paola3stefania/)) - **Delete-user verification email encoding** [#8007](https://github.com/better-auth/better-auth/pull/8007) - Callback URLs in delete-user emails now encode properly. (Author: [@Paola3stefania](https://github.com/Paola3stefania/)) - **Cookie retrieval relaxation for getSessionCookie** [#8008](https://github.com/better-auth/better-auth/pull/8008) - Session retrieval is more lenient with cookie variants. (Author: [@jslno](https://github.com/jslno/)) - **Supabase search\_path escaping** [#8051](https://github.com/better-auth/better-auth/pull/8051) - Fixed schema path handling when `$user` variables are present. (Author: [@Bekacru](https://github.com/Bekacru/)) - **OAuth provider response field naming** [#7811](https://github.com/better-auth/better-auth/pull/7811) - OAuth consent and continue endpoints now return `url` instead of `uri`. (Author: [@bytaesu](https://github.com/bytaesu/)) - **OAuth provider consent scope narrowing** [#7873](https://github.com/better-auth/better-auth/pull/7873) - Users can now reduce requested scopes at consent time. (Author: [@gustavovalverde](https://github.com/gustavovalverde/)) - **Wildcard trusted origins in Expo deep links** [#8013](https://github.com/better-auth/better-auth/pull/8013) - Expo deep link cookie injection now supports wildcard patterns. (Author: [@bytaesu](https://github.com/bytaesu/)) - **OAuth client missing timestamps** [#7851](https://github.com/better-auth/better-auth/pull/7851) - OAuth client creation/update dates now populate correctly. (Author: [@dvanmali](https://github.com/dvanmali/)) - **Line item price on Stripe upgrade** [#8066](https://github.com/better-auth/better-auth/pull/8066) - Plan upgrades properly replace old line items instead of duplicating. (Author: [@bytaesu](https://github.com/bytaesu/)) - **Stripe metadata on schedule update** [#8069](https://github.com/better-auth/better-auth/pull/8069) - Metadata injects on schedule updates, not creation. (Author: [@bytaesu](https://github.com/bytaesu/)) - **Stripe subscription cancel callback** [#8032](https://github.com/better-auth/better-auth/pull/8032) - Cancellation callbacks now use the correct customer ID. (Author: [@bytaesu](https://github.com/bytaesu/)) - **Stripe API fallback for customer search** [#7965](https://github.com/better-auth/better-auth/pull/7965) - Uses `customers.list` when the newer `customers.search` API is unavailable. (Author: [@bytaesu](https://github.com/bytaesu/)) - **OAuth provider invalid\_client on secret mismatch** [#8030](https://github.com/better-auth/better-auth/pull/8030) - Returns standard `invalid_client` error when encrypted secret verification fails. (Author: [@bytaesu](https://github.com/bytaesu/)) - **Apple and Google ID token error handling** [#8011](https://github.com/better-auth/better-auth/pull/8011) - Explicit error handling for ID token verification failures. (Author: [@Paola3stefania](https://github.com/Paola3stefania/)) - **Captcha error codes in middleware** [#7991](https://github.com/better-auth/better-auth/pull/7991) - Middleware responses now include error codes for captcha failures. (Author: [@himself65](https://github.com/himself65/)) - **Organization member refetch on role change** [#7989](https://github.com/better-auth/better-auth/pull/7989) - Active member and role data refresh when switching organizations. (Author: [@bytaesu](https://github.com/bytaesu/)) - **Tsconfig exclusion in package builds** [#7967](https://github.com/better-auth/better-auth/pull/7967) - Published packages no longer include tsconfig.json. (Author: [@GautamBytes](https://github.com/GautamBytes/)) - **Client type inference for response fields** [#7986](https://github.com/better-auth/better-auth/pull/7986) - Top-level user and session responses now infer additional custom fields correctly. (Author: [@bytaesu](https://github.com/bytaesu/)) - **Optional chaining in admin hooks** [#8026](https://github.com/better-auth/better-auth/pull/8026) - Admin hooks safely handle missing user context. (Author: [@jslno](https://github.com/jslno/)) - **Mongo adapter ObjectID handling** [#7977](https://github.com/better-auth/better-auth/pull/7977) - Foreign key updates now store as ObjectID in MongoDB. (Author: [@ping-maxwell](https://github.com/ping-maxwell/)) - **SSO CJS import fix** [#8041](https://github.com/better-auth/better-auth/pull/8041) - SSO plugin now imports CommonJS dependencies correctly. (Author: [@himself65](https://github.com/himself65/)) - **Database required attribute inference** [#7996](https://github.com/better-auth/better-auth/pull/7996) - The `required` flag infers properly from default values. (Author: [@jslno](https://github.com/jslno/)) - **Electron secure image fetch** [#7844](https://github.com/better-auth/better-auth/pull/7844) - Electron retrieves user images securely regardless of CSP. (Author: [@jslno](https://github.com/jslno/)) ### Performance Improvements - **Playwright optimization in E2E tests** [#8073](https://github.com/better-auth/better-auth/pull/8073) - E2E CI now caches Playwright browsers for faster runs. - **Docker Compose healthchecks** [#8010](https://github.com/better-auth/better-auth/pull/8010) - CI services start faster with explicit health checks. ### Documentation - **Added test-utils plugin to navigation** [#7958](https://github.com/better-auth/better-auth/pull/7958) - Test utilities docs are now discoverable in the sidebar. (Author: [@janhesters](https://github.com/janhesters/)) - **Admin plugin getUser endpoint docs** [#8072](https://github.com/better-auth/better-auth/pull/8072) - Documented the `getUser` method in the admin plugin. (Author: [@kebench](https://github.com/kebench/)) - **Admin Roles plugin wording clarification** [#7522](https://github.com/better-auth/better-auth/pull/7522) - Improved clarity in role setup instructions. (Author: [@Anjellyrika](https://github.com/Anjellyrika/)) - **Account linking example fix** [#8035](https://github.com/better-auth/better-auth/pull/8035) - Corrected the account linking code snippet. (Author: [@rosano](https://github.com/rosano/)) - **Safari ITP third-party cookie docs** [#7980](https://github.com/better-auth/better-auth/pull/7980) - Documented ITP behavior and workarounds. (Author: [@ping-maxwell](https://github.com/ping-maxwell/)) - **Fumadocs search engine upgrade** [#7984](https://github.com/better-auth/better-auth/pull/7984) - Docs now use Fumadocs' built-in Orama search. (Author: [@bytaesu](https://github.com/bytaesu/)) ### Infrastructure - **Release workflow GitHub dispatch** [#8004](https://github.com/better-auth/better-auth/pull/8004) - Release automation now dispatches from GitHub instead of external service. (Author: [@Bekacru](https://github.com/Bekacru/)) - **Package version bumps** [#8037](https://github.com/better-auth/better-auth/pull/8037) - All packages bumped to v1.5.0-beta.16. (Author: [@Bekacru](https://github.com/Bekacru/)) - **CLI beta URL configuration** [#7997](https://github.com/better-auth/better-auth/pull/7997) - CLI uses beta URLs for pre-release builds and resolves import paths. (Author: [@Bekacru](https://github.com/Bekacru/)) ### Testing - **OAuth consent response assertion updates** [#8029](https://github.com/better-auth/better-auth/pull/8029) - Test assertions updated to check `url` instead of `uri`. (Author: [@bytaesu](https://github.com/bytaesu/)) - **Client output snapshot validation** [#7979](https://github.com/better-auth/better-auth/pull/7979) - Added checks for client output integrity. (Author: [@himself65](https://github.com/himself65/)) ### Dependency Updates - **Hono 4.11.7 to 4.11.10** [#8074](https://github.com/better-auth/better-auth/pull/8074) - **SvelteKit 2.50.1 to 2.52.2** [#8075](https://github.com/better-auth/better-auth/pull/8075) - **fast-xml-parser 5.3.3 to 5.3.6** [#8034](https://github.com/better-auth/better-auth/pull/8034) ## Langfuse: Langfuse Changelog - February 14-21, 2026 URL: https://www.usenotra.com/changelog/langfuse/dashboard-query-optimizations-and-v4-event-ingestion.md Date: 2026-02-21 This week brings significant performance improvements to dashboard queries, expanded event table capabilities, and developer-focused enhancements. Major work completed includes optimizing v2 metrics queries with uniq(trace\_id) aggregation for blazing-fast dashboard tiles, implementing bloom filter indexes on user\_id and session\_id columns for faster row lookups, and adding head-based opt-in support for direct writes into v4 event tables. Dashboard widgets can now switch query paths based on feature flags, observation table filtering now supports level-based selection, and prompt management gains folder deletion functionality. These improvements directly improve query speed, reduce dashboard load times, and provide operators with better control over their event ingestion paths. ## Highlights ### Dashboard query optimization with uniq(trace\_id) aggregation Replaced slow eventsTracesView path with direct uniq(trace\_id) aggregation on eventsObservationsView, dramatically reducing query complexity and execution time for dashboard trace tiles in v2. Custom widgets, score histograms, and model usage queries all benefit from this single-level optimization pattern. ### Bloom filter indexes on user\_id and session\_id Added bloom\_filter(0.01) indexes to events\_core and events\_full tables, accelerating row-level filtering when querying by user or session without consuming excessive disk space. Materialized views auto-populate these indexes, seamlessly integrating with existing data pipelines. ### Head-based opt-in for direct event writes to v4 tables Operators can now enable direct event table writes via HTTP headers, bypassing the legacy v1 path. OTEL spans automatically support this opt-in, allowing early adopters to test v4 event storage without full platform migration. ### EventsSessionAggregationQueryBuilder for direct session metrics Eliminated redundant two-step trace aggregation by building session metrics directly from events\_core via GROUP BY session\_id, pushing filters into inner CTEs for better query planning and faster result sets. ### Dashboard v1/v2 metrics consistency validation Added comprehensive test coverage comparing v1 and v2 metric outputs, ensuring data integrity during the gradual migration and catching regressions early in the pipeline. ## More Updates ### Features & Enhancements - **Dashboard v2 metrics version support for custom widgets** [#12177](https://github.com/langfuse/langfuse/pull/12177) - Widgets now respect the v2 metrics query path, enabling the uniq(trace\_id) optimization. (Author: [@sumerman](https://github.com/sumerman/)) - **Add v2 backend paths for score histogram and model usage queries** [#12146](https://github.com/langfuse/langfuse/pull/12146) - Extends QueryBuilder with pairExpand concept for ARRAY JOIN on ClickHouse Map columns. (Author: [@sumerman](https://github.com/sumerman/)) - **Add v2 backend path for score-aggregate dashboard query** [#12136](https://github.com/langfuse/langfuse/pull/12136) - Wires metricsVersion through chart tRPC endpoints. (Author: [@sumerman](https://github.com/sumerman/)) - **Level filter support in trace filter sidebar** [#12174](https://github.com/langfuse/langfuse/pull/12174) - Users can now filter observations by depth level in trace view. (Author: [@nimarb](https://github.com/nimarb/)) - **Position filter in trace exploration** [#12058](https://github.com/langfuse/langfuse/pull/12058) - New position-based filtering for trace observation navigation. (Author: [@nimarb](https://github.com/nimarb/)) - **Add dataset batch action for events table** [#12144](https://github.com/langfuse/langfuse/pull/12144) - Multi-select observations can now be bulk-added to datasets. (Author: [@hassiebp](https://github.com/hassiebp/)) - **Icon rendering support in filter facets** [#12169](https://github.com/langfuse/langfuse/pull/12169) - Observation type icons now appear in filter sidebar, improving visual scanability. (Author: [@hassiebp](https://github.com/hassiebp/)) - **Tooltip support for filter sidebar facets** [#12168](https://github.com/langfuse/langfuse/pull/12168) - "Is Root Observation" and other complex filters show helpful explanations on hover. (Author: [@hassiebp](https://github.com/hassiebp/)) - **Info icon indicators for filters with tooltips** [#12176](https://github.com/langfuse/langfuse/pull/12176) - Visual cue shows when additional filter documentation is available. (Author: [@hassiebp](https://github.com/hassiebp/)) - **Support Japanese characters in prompt variables** [#11509](https://github.com/langfuse/langfuse/pull/11509) - Prompt templates now accept Unicode characters in variable names. (Author: [@komechan-rh](https://github.com/komechan-rh/)) - **Delete entire prompt folders** [#11920](https://github.com/langfuse/langfuse/pull/11920) - Folder deletion with cascade removes all contained prompts with confirmation dialog. (Author: [@5h0ov](https://github.com/5h0ov/)) - **Mixpanel and PostHog integration project name support** [#12038](https://github.com/langfuse/langfuse/pull/12038) - Analytics integrations now include langfuse\_project\_name alongside project\_id for better filtering. (Author: [@shmulik-apiiro](https://github.com/shmulik-apiiro/)) - **Enhanced dataset selection in experiments UI** [#12059](https://github.com/langfuse/langfuse/pull/12059) - Popover-based dataset picker with search for faster experiment setup. (Author: [@marliessophie](https://github.com/marliessophie/)) - **Peek view table support** [#12044](https://github.com/langfuse/langfuse/pull/12044) - Inline table rendering in detail modals for richer data exploration. (Author: [@marliessophie](https://github.com/marliessophie/)) - **Head-based opt-in for v4 event writes** [#12025](https://github.com/langfuse/langfuse/pull/12025) - HTTP header controls enable direct event table writes; OTEL spans automatically supported. (Author: [@sumerman](https://github.com/sumerman/)) - **Add performance controls for GET /api/public/traces** [#12062](https://github.com/langfuse/langfuse/pull/12062) - Self-hosters can now enforce date range requirements and restrict field groups to optimize trace endpoint performance. (Author: [@Steffen911](https://github.com/Steffen911/)) ### Bug Fixes - **Improve chart loading and failure state hints** [#12180](https://github.com/langfuse/langfuse/pull/12180) - Better visual feedback during chart data load and clearer error messaging. (Author: [@maxdeichmann](https://github.com/maxdeichmann/)) - **Remove spurious whitespace from .env example** [#12106](https://github.com/langfuse/langfuse/pull/12106) - Standard .env parsers now work without errors. (Author: [@LoneRifle](https://github.com/LoneRifle/)) - **Fix datasets graph formatting for seconds** [#12165](https://github.com/langfuse/langfuse/pull/12165) - Dataset performance graphs display time units correctly. (Author: [@nimarb](https://github.com/nimarb/)) - **CSV upload column mapping for dataset schemas** [#12141](https://github.com/langfuse/langfuse/pull/12141) - Users can now map entire columns when schemas are defined. (Author: [@marliessophie](https://github.com/marliessophie/)) - **Unbounded dashboard query row limits** [#12160](https://github.com/langfuse/langfuse/pull/12160) - Dashboard queries now include row\_limit protection preventing memory exhaustion. (Author: [@sumerman](https://github.com/sumerman/)) - **Time dimension query root event timestamp** [#12118](https://github.com/langfuse/langfuse/pull/12118) - Traces timeline queries now use correct root event timestamps. (Author: [@sumerman](https://github.com/sumerman/)) - **Trace table update when metrics loaded** [#12113](https://github.com/langfuse/langfuse/pull/12113) - UI now refreshes after async metric data arrives. (Author: [@nimarb](https://github.com/nimarb/)) - **Coerce usage details to number in evals** [#12130](https://github.com/langfuse/langfuse/pull/12130) - ClickHouse numeric values now parse correctly in evaluation streaming. (Author: [@hassiebp](https://github.com/hassiebp/)) - **Apply custom base path to sign-out callback** [#12036](https://github.com/langfuse/langfuse/pull/12036) - Self-hosted instances with custom paths now redirect correctly on logout. (Author: [@hyeonch](https://github.com/hyeonch/)) - **Mutual exclusion for Anthropic temperature and top\_p** [#12020](https://github.com/langfuse/langfuse/pull/12020) - Playground auto-disables conflicting parameters to prevent API 400 errors. (Author: [@hobostay](https://github.com/hobostay/)) - **Prevent empty target submission in evaluator forms** [#12088](https://github.com/langfuse/langfuse/pull/12088) - Form validation catches configuration errors before submission. (Author: [@marliessophie](https://github.com/marliessophie/)) - **Add folder path when creating prompt from folder** [#12043](https://github.com/langfuse/langfuse/pull/12043) - New prompts inherit parent folder structure automatically. (Author: [@nimarb](https://github.com/nimarb/)) - **Add default generation filter to observation evaluators** [#12033](https://github.com/langfuse/langfuse/pull/12033) - New observation evals default to GENERATION type with inline warnings for unfiltered runs. (Author: [@hassiebp](https://github.com/hassiebp/)) ### Performance Improvements - **Optimize v2 traces queries with uniq(trace\_id)** [#12175](https://github.com/langfuse/langfuse/pull/12175) - Single-level aggregation on observations view eliminates expensive subqueries. (Author: [@sumerman](https://github.com/sumerman/)) - **Optimize v2 traces queries via root-event filter** [#12166](https://github.com/langfuse/langfuse/pull/12166) - Reformulates queries to leverage parentObservationId IS NULL for single-pass optimization. (Author: [@sumerman](https://github.com/sumerman/)) - **Add bloom filter indexes on user\_id and session\_id** [#12120](https://github.com/langfuse/langfuse/pull/12120) - Accelerates row lookups for user and session filtering on event tables. (Author: [@Steffen911](https://github.com/Steffen911/)) ### Infrastructure - **Optional lightweight UPDATE codepath for ClickHouse** [#12090](https://github.com/langfuse/langfuse/pull/12090) - Adds configurable update path for event table mutations. (Author: [@Copilot](https://github.com/apps/copilot-swe-agent/)) - **SYSTEM SYNC REPLICA before event propagation** [#12079](https://github.com/langfuse/langfuse/pull/12079) - Ensures replica consistency before INSERT-SELECT in event pipeline. (Author: [@Steffen911](https://github.com/Steffen911/)) - **Add delay metrics for event propagation job** [#12138](https://github.com/langfuse/langfuse/pull/12138) - Gauge metrics track partition processing lag for operational visibility. (Author: [@Steffen911](https://github.com/Steffen911/)) - **Configurable Redis cluster slots refresh timeout** [#12096](https://github.com/langfuse/langfuse/pull/12096) - Self-hosters can tune Redis cluster behavior for their infrastructure. (Author: [@Steffen911](https://github.com/Steffen911/)) - **Log MOVED cluster redirects at debug level** [#12086](https://github.com/langfuse/langfuse/pull/12086) - Normal Redis Cluster behavior no longer generates misleading warnings. (Author: [@Steffen911](https://github.com/Steffen911/)) - **Retire parseIoAsJson option with 400 response** [#11990](https://github.com/langfuse/langfuse/pull/11990) - Deprecated API option now returns explicit error guiding users to v2 path. (Author: [@sumerman](https://github.com/sumerman/)) - **Shift to events\_full and events\_core tables** [#11836](https://github.com/langfuse/langfuse/pull/11836) - Major ClickHouse table reorganization splits lightweight and full-content queries. (Author: [@Steffen911](https://github.com/Steffen911/)) ### Internal Changes - **EventsSessionAggregationQueryBuilder for single-step aggregation** [#12127](https://github.com/langfuse/langfuse/pull/12127) - Replaces two-step aggregation with direct session GROUP BY on events\_core. (Author: [@sumerman](https://github.com/sumerman/)) - **Add metricsVersion prop to dashboard components** [#12089](https://github.com/langfuse/langfuse/pull/12089) - Enables selective routing of widgets to v2 queries. (Author: [@sumerman](https://github.com/sumerman/)) - **Remove 100 observation limit per trace** [#12048](https://github.com/langfuse/langfuse/pull/12048) - Detail views now retrieve unlimited observations through tRPC. (Author: [@nimarb](https://github.com/nimarb/)) - **Remove shadow optimization test** [#12066](https://github.com/langfuse/langfuse/pull/12066) - Cleans up legacy test code. (Author: [@sumerman](https://github.com/sumerman/)) - **Tighten v1/v2 view differences** [#12065](https://github.com/langfuse/langfuse/pull/12065) - Reduces inconsistencies between legacy and new query paths. (Author: [@sumerman](https://github.com/sumerman/)) - **Support parent observation is null filter** [#12063](https://github.com/langfuse/langfuse/pull/12063) - Evaluation filters can now target root observations. (Author: [@marliessophie](https://github.com/marliessophie/)) - **Support tool calls and filtering in events table** [#12151](https://github.com/langfuse/langfuse/pull/12151) - Events table infrastructure extends to handle tool call observations. (Author: [@nimarb](https://github.com/nimarb/)) - **Add comments filters for events table** [#12163](https://github.com/langfuse/langfuse/pull/12163) - Filter infrastructure prepared for comment-based segmentation. (Author: [@nimarb](https://github.com/nimarb/)) - **Move root observation switch to sidebar** [#12094](https://github.com/langfuse/langfuse/pull/12094) - UI reorganizes filter controls for better accessibility. (Author: [@nimarb](https://github.com/nimarb/)) - **Update null check for empty strings** [#12123](https://github.com/langfuse/langfuse/pull/12123) - Filter service handles blank values correctly. (Author: [@marliessophie](https://github.com/marliessophie/)) - **Add v4 view of scores via metrics query** [#12124](https://github.com/langfuse/langfuse/pull/12124) - Scores now accessible through new event metrics path. (Author: [@nimarb](https://github.com/nimarb/)) ### Testing - **Add dashboard v1/v2 consistency tests** [#12098](https://github.com/langfuse/langfuse/pull/12098) - Comprehensive metrics validation between legacy and new paths. (Author: [@sumerman](https://github.com/sumerman/)) - **Fix e2e test flakiness** [#12114](https://github.com/langfuse/langfuse/pull/12114) - Move tests to async patterns. (Author: [@maxdeichmann](https://github.com/maxdeichmann/)) ### Documentation & Chores - **Add Claude Sonnet 4.6 model pricing** [#12080](https://github.com/langfuse/langfuse/pull/12080) - Model catalog updated with latest Anthropic offerings. (Author: [@hassiebp](https://github.com/hassiebp/)) - **Add Gemini 3.1 Pro Preview pricing** [#12143](https://github.com/langfuse/langfuse/pull/12143) - Supports both standard and large-context pricing tiers. (Author: [@hassiebp](https://github.com/hassiebp/)) - **LangChain v1 upgrade** [#12085](https://github.com/langfuse/langfuse/pull/12085) - SDK compatibility updated. (Author: [@hassiebp](https://github.com/hassiebp/)) - **Add Vercel React skills** [#12103](https://github.com/langfuse/langfuse/pull/12103) - Developer experience tooling expanded. (Author: [@nimarb](https://github.com/nimarb/)) - **Improve events table error messages** [#12111](https://github.com/langfuse/langfuse/pull/12111) - Clearer diagnostic output for debugging. (Author: [@maxdeichmann](https://github.com/maxdeichmann/)) - **Remove tremor-based charts dependency** [#12010](https://github.com/langfuse/langfuse/pull/12010) - Simplifies dependencies and reduces bundle size. (Author: [@coffee4tw](https://github.com/coffee4tw/)) - **Move peek view out of data table** [#12099](https://github.com/langfuse/langfuse/pull/12099) - Architectural separation improves code maintainability. (Author: [@nimarb](https://github.com/nimarb/)) - **Update events seed logic for production parity** [#12095](https://github.com/langfuse/langfuse/pull/12095) - Dev environment more accurately reflects production data patterns. (Author: [@sumerman](https://github.com/sumerman/)) - **Bar chart styling and dark mode improvements** [#12045](https://github.com/langfuse/langfuse/pull/12045) - Enhanced hover states and dynamic label spacing. (Author: [@coffee4tw](https://github.com/coffee4tw/)) - **Rename post in trace filter** [#12171](https://github.com/langfuse/langfuse/pull/12171) - Terminology updates for clarity. (Author: [@nimarb](https://github.com/nimarb/)) - **Remove unused imports** [#12126](https://github.com/langfuse/langfuse/pull/12126) - Code cleanup. (Author: [@maxdeichmann](https://github.com/maxdeichmann/)) - **Bump turbo to 2.8.10** [#12116](https://github.com/langfuse/langfuse/pull/12116) - Build tool updates. (Author: [@nimarb](https://github.com/nimarb/)) - **Remove replica sync and extend event prop delay to 30min** [#12167](https://github.com/langfuse/langfuse/pull/12167) - Operational tuning for event propagation. (Author: [@Steffen911](https://github.com/Steffen911/)) ## Unkey: Unkey Changelog - February 13-20, 2026 URL: https://www.usenotra.com/changelog/unkey/config-migration-gossip-and-sentinel-keys.md Date: 2026-02-20 This week brought significant infrastructure improvements and platform expansion to Unkey. The team completed a major migration from environment variables to file-based configuration across all services, deployed cross-region gossip messaging, added a powerful sentinel key verification middleware system, and made the platform more resilient with TLS-enabled-by-default deployments. Enhanced dashboard UI and deployment settings round out a week focused on operational maturity and security hardening. ## Highlights ### Struct-tag-driven configuration system across all services A new pkg/config package replaces environment-variable-based configuration with file-based TOML/YAML/JSON support. Features struct-tag-driven validation with required/default/min/max/oneof constraints, environment variable expansion, and comprehensive error collection. All eight core services migrated: API, Vault, Ctrl, Krane, Frontline, Preflight, and Sentinel. This simplifies deployment and improves auditability across Kubernetes and Docker environments. ### Cross-region gossip messaging for low-latency clustering Gossip protocol implementation enables efficient message distribution across regions without requiring every node to know about every peer. Intra-cluster messages and cross-region broadcasts use separate membership lists, with designated ambassadors relaying messages between regions to minimize global latency. Reduces operational complexity for distributed deployments. ### Sentinel key verification middleware engine First production sentinel middleware adds API key authentication with configurable matching and policy engine. Verifies incoming requests against pre-configured policies before forwarding, enabling fine-grained access control at the gateway level. Includes error page improvements and middleware routing. ### TLS-enabled-by-default with certificate manager support Services now require explicit opt-out (tls.disabled=true) rather than opt-in for HTTPS. Intelligently uses certificate manager when available, falls back to static certificate files, and logs capability details for easier troubleshooting. Improves default security posture without configuration overhead. ### Comprehensive deploy settings UI overhaul New deployment settings interface organizes build, runtime, and advanced configuration into expandable grouped cards. Environment variable form supports drag-and-drop and copy-paste operations with visual feedback. GitHub integration, region/instance selection, health checks, custom domains, and command/port configuration now have dedicated UX components preparing for guided deployment onboarding. ## More Updates ### Features & Enhancements - **New deploy settings UI** [#5073](https://github.com/unkeyed/unkey/pull/5073) - Complete redesign of deployment configuration interface with GitHub integration, environment variables management, and custom domains support. (Author: [@ogzhanolguncu](https://github.com/ogzhanolguncu/)) - **Config file system** [#5045](https://github.com/unkeyed/unkey/pull/5045) - Introduce file-based TOML/YAML/JSON configuration with struct-tag validation and environment variable expansion. (Author: [@chronark](https://github.com/chronark/)) - **Gossip protocol implementation** [#5015](https://github.com/unkeyed/unkey/pull/5015) - Multi-region messaging with ambassador pattern and separate cluster/cross-region membership lists. (Author: [@Flo4604](https://github.com/Flo4604/)) - **Sentinel key verification middleware** [#5079](https://github.com/unkeyed/unkey/pull/5079) - Gateway-level API key authentication with policy matching engine. (Author: [@Flo4604](https://github.com/Flo4604/)) - **Generate RPC wrappers** [#5028](https://github.com/unkeyed/unkey/pull/5028) - Automated RPC wrapper generation and infrastructure cleanup. (Author: [@Flo4604](https://github.com/Flo4604/)) - **Sentinel middleware RFC** [#5041](https://github.com/unkeyed/unkey/pull/5041) - Specification for sentinel middleware architecture and capabilities. (Author: [@chronark](https://github.com/chronark/)) ### Bug Fixes - **TLS certificate handling** [#5076](https://github.com/unkeyed/unkey/pull/5076) - Make TLS enabled by default; prefer cert manager over static files with fallback support. (Author: [@Flo4604](https://github.com/Flo4604/)) - **Modals with combo box** [#5002](https://github.com/unkeyed/unkey/pull/5002) - Fix modal dialog interaction with combo box selectors. (Author: [@perkinsjr](https://github.com/perkinsjr/)) - **Proto type issues** [#5093](https://github.com/unkeyed/unkey/pull/5093) - Fix runtime exception from type mismatch and simplify deployment overview. (Author: [@chronark](https://github.com/chronark/)) - **Identity slug copyability** [#5100](https://github.com/unkeyed/unkey/pull/5100) - Enable copy-to-clipboard for identity slugs in permissions table. (Author: [@perkinsjr](https://github.com/perkinsjr/)) - **No-data state display** [#5065](https://github.com/unkeyed/unkey/pull/5065) - Show appropriate messaging when analytics or dashboards have insufficient data. (Author: [@perkinsjr](https://github.com/perkinsjr/)) - **Deployment URL labels** [#4976](https://github.com/unkeyed/unkey/pull/4976) - Standardize display of deployment URLs and fix conversion errors. (Author: [@vansh-commits](https://github.com/vansh-commits/)) - **Cilium policy timing** [#5059](https://github.com/unkeyed/unkey/pull/5059) - Wait for cilium CRDs before applying network policies in cluster initialization. (Author: [@ogzhanolguncu](https://github.com/ogzhanolguncu/)) - **Hubble UI deployment** [#5056](https://github.com/unkeyed/unkey/pull/5056) - Add retry logic for hubble-ui pod initialization. (Author: [@Flo4604](https://github.com/Flo4604/)) ### Infrastructure - **Prometheus metrics refactoring** [#5102](https://github.com/unkeyed/unkey/pull/5102) - Move metrics to scoped packages for better organization. (Author: [@chronark](https://github.com/chronark/)) - **Remove chproxy routes** [#5101](https://github.com/unkeyed/unkey/pull/5101) - Clean up legacy routing infrastructure. (Author: [@chronark](https://github.com/chronark/)) - **Sentinel middleware cleanup** [#5088](https://github.com/unkeyed/unkey/pull/5088) - Refactor after sentinel middleware implementation and fix error pages. (Author: [@chronark](https://github.com/chronark/)) - **Release workflow rework** [#5044](https://github.com/unkeyed/unkey/pull/5044) - Streamline release process. (Author: [@Flo4604](https://github.com/Flo4604/)) - **Gossip metrics** [#5107](https://github.com/unkeyed/unkey/pull/5107) - Monitoring and observability for gossip protocol operations. (Author: [@Flo4604](https://github.com/Flo4604/)) ### Performance Improvements - **Allow longer timeout configuration** [#5032](https://github.com/unkeyed/unkey/pull/5032) - Extend maximum timeout limits for slower operations. (Author: [@Flo4604](https://github.com/Flo4604/)) ### Testing - **Remove hand-holding validation** [#5108](https://github.com/unkeyed/unkey/pull/5108) - Streamline validation behavior in development workflows. (Author: [@perkinsjr](https://github.com/perkinsjr/)) ### Documentation - **Remove orphaned SDK documentation** [#5033](https://github.com/unkeyed/unkey/pull/5033) - Clean up outdated Spring Boot, Rust, and Elixir SDK docs. (Author: [@mintlify[bot]](https://github.com/mintlify%5Bbot%5D/) and [@chronark](https://github.com/chronark/)) - **Cache store interface description** [#5037](https://github.com/unkeyed/unkey/pull/5037) - Add SEO metadata to cache store documentation. (Author: [@mintlify[bot]](https://github.com/mintlify%5Bbot%5D/) and [@chronark](https://github.com/chronark/)) - **Analytics feature documentation** [#5067](https://github.com/unkeyed/unkey/pull/5067) - Update copy to clarify analytics deletion capabilities. (Author: [@mcstepp](https://github.com/mcstepp/)) - **Rate limiting benchmark links** [#5040](https://github.com/unkeyed/unkey/pull/5040) - Reference live performance benchmarks in rate limiting documentation. (Author: [@perkinsjr](https://github.com/perkinsjr/)) ## Neon: Neon Add MCP Changelog - February 13-18, 2026 URL: https://www.usenotra.com/changelog/neon/copilot-cli-gitignore-and-integration-fixes.md Date: 2026-02-18 Over the past week, we shipped three minor versions (1.2.0, 1.2.1) with critical fixes and new features. The 1.2.1 patch fixes Codex header mapping, while 1.2.0 added a gitignore flag to prevent accidental API key exposure. We've also delivered GitHub Copilot CLI support as a dedicated agent target, enabling separate local and global configuration paths. Earlier this week, fixes addressed OpenCode config detection, correcting file locations and MCP command generation. These updates enhance tool compatibility, improve security workflows, and expand agent support across multiple platforms. ## Highlights ### GitHub Copilot CLI agent with scoped configuration Added dedicated github-copilot-cli target that writes VS Code-compatible local config to `.vscode/mcp.json` and Copilot CLI global config to `~/.copilot/mcp-config.json`, preventing conflicts and enabling flexible integration. (Author: [@andrelandgraf](https://github.com/andrelandgraf/)) ### Gitignore flag prevents accidental API key leaks Implemented --gitignore flag to automatically add generated files to .gitignore with proper messaging about what the flag does and warnings when combined with global installs. (Author: [@mezotv](https://github.com/mezotv/)) ### Fixed Codex integration header field mapping Corrected MCP config generation for Codex to use http\_headers instead of headers, verified against official Codex source code. (Author: [@RhysSullivan](https://github.com/RhysSullivan/)) ### OpenCode config detection and MCP command structure Fixed OpenCode integration by correcting config filename detection (opencode.json not .opencode.json) and adjusting MCP command generation to match OpenCode's expected format. (Author: [@IdrisGit](https://github.com/IdrisGit/)) ## More Updates ### Features & Enhancements - **Add gitignore flag to CLI** [#6](https://github.com/neondatabase/add-mcp/pull/6) - Enables automatic .gitignore updates with clear messaging and global scope warnings. (Author: [@mezotv](https://github.com/mezotv/)) ### Bug Fixes - **Fix Codex header mapping to http\_headers** [#7](https://github.com/neondatabase/add-mcp/pull/7) - Resolves header field incompatibility by using correct field name. (Author: [@RhysSullivan](https://github.com/RhysSullivan/)) - **Fix OpenCode config detection and mcp command generation** [#3](https://github.com/neondatabase/add-mcp/pull/3) - Corrects config file path and command generation structure. (Author: [@IdrisGit](https://github.com/IdrisGit/)) ## Autumn: Autumn Changelog - February 2-14, 2026 URL: https://www.usenotra.com/changelog/autumn/customer-v5-and-rollover-credit-fixes.md Date: 2026-02-14 This week shipped nine merged PRs focused on billing accuracy, API design cleanup, and platform stability. The most substantial work landed new customer schema structures (ApiCustomerV5), fixed a bug where rollover credit deductions diverged between Redis and Postgres, and refined cache guard logic for safe customer data refreshes. Plan parameters got standardized, and the terminal UI moved to the current design system. ## Highlights ### New ApiCustomerV5 with improved balance API Introduced ApiBalanceV1 using granted and remaining fields instead of granted\_balance and current\_balance. The balance breakdown now includes pricing data. Full backward compatibility maintained through version transformers for existing API clients. (#739) ### Rollover credit math fixed across all deduction paths Rollover deductions now apply per-rollover credit costs, fixing a longstanding inconsistency where calculations diverged between Redis (Lua) and Postgres (SQL) systems. For example, a feature using 0.2 credits per unit now calculates correctly even if another feature uses 0.6 credits per unit. Tests cover mixed costs and Postgres skip\_cache scenarios. (#736) ### Cache guard parameter allows controlled refreshes Added skipGuard option to cache deletion so executePostgresDeduction can refresh customer data after Postgres updates without the stale-write guard blocking fresh writes. Other deletion paths retain guard protection. (#737) ### Plan parameter schemas now standardized Plan CRUD switched to V1 parameter schemas with field renames: items instead of features, auto\_enable instead of default, included instead of granted\_balance. New mappers handle conversion to ProductV2 and legacy formats. Product cache now refreshes on plan route changes. (#732) ### Custom free trials stay scoped to subscriptions When a subscription update includes a custom free trial parameter, it now gets marked as custom so it doesn't persist as a product default. The fix ensures trial scope boundaries stay correct in billing. (#738) ## More Updates ### Features and Enhancements - **Standardized plan parameter schemas** [#732](https://github.com/useautumn/autumn/pull/732) - Migrated plan CRUD to V1 parameter format with mappers to ProductV2. Improved naming conventions align with current API design. (Author: @john-autumn) - **Dashboard attach respects organization config** [#613](https://github.com/useautumn/autumn/pull/613) - Attach flow now uses org.success\_url to send users to the configured landing page after attaching a product. (Author: @SirTenzin) ### Bug Fixes - **Stopped Stripe from recreating products** [#731](https://github.com/useautumn/autumn/pull/731) - Fixed inverted boolean condition in prepaid price v2 check and corrected parameter type so product reuse actually works. (Author: @SirTenzin) - **Restored attach for legacy plans** [#734](https://github.com/useautumn/autumn/pull/734) - Added fallback to stripe\_empty\_price\_id for legacy consumable prices so attach works on older plan configurations. (Author: @john-autumn) - **Subscription previews now show real changes only** [#730](https://github.com/useautumn/autumn/pull/730) - Item change detection refactored to compare normalized ProductItem data and ignore internal fields like feature\_id and price\_id. Previews only update when user-facing values change. (Author: @john-autumn) - **Terminal view migrated to v2 components** [#733](https://github.com/useautumn/autumn/pull/733) - Updated TRMNL integration page from deprecated components to current design system. Added device ID trimming and safer optional chaining. (Author: @SirTenzin) ## Marble: Marble Changelog - February 2-14, 2026 URL: https://www.usenotra.com/changelog/marble/codeblocks-video-embedding-and-editor-fixes.md Date: 2026-02-14 This week focused on expanding editor capabilities and fixing UI interaction issues. The release adds support for custom codeblocks and video embedding, along with improved error handling for clipboard operations and refinements to dropdown and popover behaviors in the editor. ## Highlights ### Custom codeblock support with clipboard error handling A new codeblock component enables more flexible content formatting, paired with error handling for clipboard operations to gracefully manage permission issues and unavailable APIs. ### Video embedding extension Authors can now embed video content directly into documents, adding another content type to the editor's capabilities. ### Fixed dropdown and popover interactions Resolved issues preventing dropdowns from opening on click and fixed popover triggers in editor codeblocks, while also preventing unintended dropdown edits. ## More Updates ### Bug Fixes - **Fixed popover trigger issue in codeblocks** - Resolved interaction issues preventing popovers from triggering correctly in editor codeblock contexts. (Author: @taqh) - **Fixed dropdown on-click behavior** - Dropdowns now display properly when clicked. (Author: @taqh) - **Prevented dropdown from becoming editable** - Dropdown inputs are now protected from accidental user edits. (Author: @taqh) ### Internal Changes - **Improved editor node styling** - Enhanced visual presentation of editor nodes. (Author: @taqh) - **Added padding to slash command menu** - Improved spacing in the slash command interface. (Author: @taqh) - **Upgraded React version** - Updated React dependency to the latest version. (Author: @taqh) ### Features & Enhancements - **Welcome email delivery system** - Implemented proper welcome email sending functionality. (Author: @taqh) ## Better Auth: Better Auth Changelog - February 2-13, 2026 URL: https://www.usenotra.com/changelog/better-auth/auth-billing-and-enterprise-identity.md Date: 2026-02-13 Over the past seven days, Better Auth delivered critical authentication and billing infrastructure updates, alongside enterprise identity management enhancements. The platform expanded Stripe integration capabilities, improved single sign-on robustness, and introduced comprehensive testing utilities. Eleven high-impact features and fixes were merged, strengthening support for modern billing strategies, federated identity verification, and multi-tenant SCIM workflows while addressing edge cases in rate limiting, email validation, and data type coercion. ## Highlights ### Seat-based and usage-based billing for Stripe Flexible billing models now support per-seat subscription tiers and metered consumption tracking with configurable line items, letting B2B platforms monetize variable usage patterns alongside fixed-rate tiers. [#7930](https://github.com/better-auth/better-auth/pull/7930) ### IdP-initiated SAML Single Logout (SLO) support Identity providers can now initiate logout flows directly, broadening compatibility with enterprise federation workflows that require asymmetric SSO lifecycle management. [#7567](https://github.com/better-auth/better-auth/pull/7567) ### SCIM ownership model and connection management Multi-tenant identity synchronization now enforces explicit ownership, with dedicated endpoints for SCIM connection provisioning and lifecycle control—critical for regulated directory integrations. [#7931](https://github.com/better-auth/better-auth/pull/7931) ### Test utilities plugin for integration and E2E testing A new plugin streamlines auth flow testing with built-in helpers for simulating credentials, session management, and multi-user scenarios, reducing boilerplate in integration test suites. [#7746](https://github.com/better-auth/better-auth/pull/7746) ### TXT record verification at subdomain level for SSO domain control SSO domain verification now correctly resolves TXT records at the designated verification subdomain rather than root, preventing configuration conflicts in shared hosting environments. [#7935](https://github.com/better-auth/better-auth/pull/7935) ## More Updates ### Features & Enhancements - **Added `billingInterval` field to Stripe subscription** [#7221](https://github.com/better-auth/better-auth/pull/7221) - Enables explicit billing cycle configuration for flexible pricing schedules. (Author: @bytaesu) - **SCIM connection management endpoints** [#7898](https://github.com/better-auth/better-auth/pull/7898) - Exposes REST endpoints for provisioning and managing SCIM integrations with full lifecycle support. (Author: @jonathansamines) ### Bug Fixes - **Separate rate limit request and response handling** [#7939](https://github.com/better-auth/better-auth/pull/7939) - Decouples inbound request throttling from outbound response limits for clearer rate-limit semantics. (Author: @himself65) - **Propagate trial data in Stripe subscription webhook handlers** [#7955](https://github.com/better-auth/better-auth/pull/7955) - Trial period metadata now flows correctly through webhook callbacks, preventing plan mismatches. (Author: @bytaesu) - **Remove `getSubscriptionUsage` endpoint** [#7949](https://github.com/better-auth/better-auth/pull/7949) - Deprecated unused metered usage endpoint to consolidate billing API surface. (Author: @bytaesu) - **Prevent duplicate line items when priceId equals seatPriceId** [#7947](https://github.com/better-auth/better-auth/pull/7947) - Eliminates duplicate charges when subscription and seat pricing IDs coincide. (Author: @bytaesu) - **Move meters configuration into plans for usage-based billing** [#7946](https://github.com/better-auth/better-auth/pull/7946) - Restructures metering config nesting for clearer plan-level usage tracking. (Author: @bytaesu) - **Remove broken direct FedCM API call and harden prompt lifecycle** [#7928](https://github.com/better-auth/better-auth/pull/7928) - Fixes FedCM integration by removing unreliable direct API calls and stabilizing prompt state transitions. (Author: @bytaesu) - **Coerce string WHERE values to match field types in adapter** [#7860](https://github.com/better-auth/better-auth/pull/7860) - Ensures database query predicates respect field type definitions, preventing type mismatches. (Author: @bytaesu) - **Apply listUsers filter when filterValue is defined** [#7827](https://github.com/better-auth/better-auth/pull/7827) - Admin user listing now correctly applies conditional filtering logic. (Author: @coderrshyam) - **Case-insensitive email matching for social account linking** [#7812](https://github.com/better-auth/better-auth/pull/7812) - OAuth account linking now normalizes email case, preventing duplicate accounts from different providers. (Author: @karuppusamy-d) - **Safely coerce date values from DB in OAuth provider plugin** [#7937](https://github.com/better-auth/better-auth/pull/7937) - Date deserialization now handles type coercion gracefully across database vendors. (Author: @himself65) - **Remove unreachable null check in `acceptInvitation`** [#7825](https://github.com/better-auth/better-auth/pull/7825) - Eliminates dead code path in organization invitation acceptance flow. (Author: @Saurav3004) ### Documentation - **Add `trustedProxyHeaders` section to security reference** [#7835](https://github.com/better-auth/better-auth/pull/7835) - Documents trusted proxy header configuration for X-Forwarded-For and similar headers in production deployments. (Author: @Paola3stefania) - **Fix typo in docs and unresolved imports** [#7954](https://github.com/better-auth/better-auth/pull/7954) - Corrects documentation errors and resolves missing module references. (Author: @jslno) ## Cal.com: Cal.com Changelog - February 6-13, 2026 URL: https://www.usenotra.com/changelog/cal-com/onboarding-v3-and-fraud-controls.md Date: 2026-02-13 This week, Cal.com shipped major feature rollouts and infrastructure improvements. The onboarding v3 flow went live globally with new tests matched to the Plan Selection → Personal Settings → Calendar journey. Signup watchlist review locks new accounts flagged for fraud and automatically unlocks them when entries are deleted. Icon migration from the legacy Icon component to @coss/ui/icons reduced bundle size and improved maintainability. Active user billing and annual team plan options round out the billing toolkit. Reliability fixes addressed booking drawer overlaps, data-table imports, and companion app navigation, while security updates tightened the dependency stack. ## Highlights ### Signup watchlist review mode for fraud control New feature flag locks and reviews flagged signups, preventing abuse while preserving account recovery on entry removal. Includes secure email verification ordering and prevents PII leakage in error logs. ### Onboarding v3 enabled globally with updated e2e tests Rewritten onboarding (Plan Selection → Personal Settings → Calendar) is now the default. Updated e2e tests and signup flows accept both old and new paths to support smooth rollout. ### Icon component migration to @coss/ui/icons Migrated 200+ static icon usages from `` to `` components, improving bundle size and enabling better prop control. Supports legacy moduleResolution via typesVersions. ### Active user billing with annual team plans New billing strategy supports both usage-based and seat pricing. Teams can buy annual subscriptions, and personal credits now act as fallback when team credits run out. ### Companion app configurable landing page Users pick their app home (Bookings or Calendar), and the choice persists via local storage. Preferences clear on logout for a fresh start. ## More Updates ### Features & Enhancements - **Preserve custom reply-to email** [#27941](https://github.com/calcom/cal.com/pull/27941) - Keep user email customizations in place across sessions. (Author: @anikdhabal) - **Add configurable landing page in companion app** [#27267](https://github.com/calcom/cal.com/pull/27267) - Let users set preferred app entry point with persistent storage. (Author: @dhairyashiil) - **Add annual plans for teams** [#27896](https://github.com/calcom/cal.com/pull/27896) - Enable yearly billing for team and org subscriptions. (Author: @sean-brydon) ### Bug Fixes - **Fix signup watchlist review and auto-unlock** [#27923](https://github.com/calcom/cal.com/pull/27923) - Correct email ordering, deleteEntry logic, and auto-unlock when entries are removed. (Author: @alishaz-polymath) - **Fix BookingDetailsSheet flicker** [#27894](https://github.com/calcom/cal.com/pull/27894) - Stop UI flicker when switching between bookings. (Author: @eunjae-lee) - **Fix icon sizing regression** [#27924](https://github.com/calcom/cal.com/pull/27924) - Reset default icon size to 16px and fix download button alignment. (Author: @eunjae-lee) - **Fix booking drawer text overlap** [#27897](https://github.com/calcom/cal.com/pull/27897) - Remove negative top margin from footer so content doesn't get hidden. (Author: @hariombalhara) - **Fix Vitest RPC errors in app-store** [#27931](https://github.com/calcom/cal.com/pull/27931) - Inline package descriptions to stop external package.json reads. (Author: @emrysal) - **Fix data-table hook imports** [#27900](https://github.com/calcom/cal.com/pull/27900) - Update paths missed in earlier refactor for useDataTable, useFilterValue, and DataTableProvider. (Author: @eunjae-lee) - **Prevent e2e test UID collisions** [#27916](https://github.com/calcom/cal.com/pull/27916) - Use randomString for booking UIDs in slots tests to avoid unique constraint failures. (Author: @alishaz-polymath) - **Include locale-prefixed paths in bot protection** [#27910](https://github.com/calcom/cal.com/pull/27910) - Extend bot detection to cover routes with locale prefixes. (Author: @volnei) - **Preserve app-store enabled state during seed** [#27918](https://github.com/calcom/cal.com/pull/27918) - Respect existing enabled state instead of forcing defaults. (Author: @devanshu0x) - **Fallback to personal credits when team credits deplete** [#27518](https://github.com/calcom/cal.com/pull/27518) - Let users keep working with personal credits if team pool runs out. (Author: @CarinaWolli) ### Infrastructure - **Bump axios to 1.13.5** [#27864](https://github.com/calcom/cal.com/pull/27864) - Includes follow-redirects 1.15.11 for security. (Author: @pedroccastro) - **Migrate data-table hooks to web modules** [#27833](https://github.com/calcom/cal.com/pull/27833) - Move data-table hooks and provider to web-specific modules for cleaner organization. (Author: @eunjae-lee) - **Migrate Icon to @coss/ui/icons** [#27458](https://github.com/calcom/cal.com/pull/27458) - Replace dynamic Icon imports with typed component icons across 28 batches. (Author: @eunjae-lee) ### Internal Changes - **Show invite link settings modal** [#27917](https://github.com/calcom/cal.com/pull/27917) - UI updates for invite management. (Author: @anikdhabal) - **Add onboarding-v3 feature flag** [#27912](https://github.com/calcom/cal.com/pull/27912) - Global flag with seed migration, account review UI, and watchlist integration. (Author: @emrysal) - **Add active user billing strategy** [#27867](https://github.com/calcom/cal.com/pull/27867) - Factory-based billing supporting seat and active-user modes with Stripe webhooks and HWM tracking. (Author: @sean-brydon) ### Testing - **Exclude test files from CODEOWNERS** [#27919](https://github.com/calcom/cal.com/pull/27919) - Add patterns (*.test.*, *.integration-test.*, *.e2e-spec.*) to CODEOWNERS test exclusions. (Author: @hariombalhara) - **Add e2e-spec to CODEOWNERS** [#27926](https://github.com/calcom/cal.com/pull/27926) - Expand test file exclusion patterns. (Author: @anikdhabal) ### Documentation - **Apply biome formatting to utility packages** [#27880](https://github.com/calcom/cal.com/pull/27880) - Standardized formatting for packages/sms, prisma, emails, and lib. (Author: @eunjae-lee) - **Trim license section from README** [#27903](https://github.com/calcom/cal.com/pull/27903) - Simplify README for clarity. (Author: @Kmadhav824) - **Organize the Out of Office page** [#27865](https://github.com/calcom/cal.com/pull/27865) - Clean up UI and remove unused imports. (Author: @Recxsmacx) - **Display phone and timezone in BookingDetailsSheet** [#27909](https://github.com/calcom/cal.com/pull/27909) - Show attendee phone and localized timezone info. (Author: @eunjae-lee) ## Databuddy: Databuddy Changelog - February 2-13, 2026 URL: https://www.usenotra.com/changelog/databuddy/privacy-salting-and-api-metadata.md Date: 2026-02-13 This week focused on solid infrastructure work and API completeness. Key additions include anonymous ID salting for better privacy, external ID support for links, consistent metadata availability across endpoints, improved MCP filtering, and documentation that actually works with AI crawlers. The rest is typical—bugs fixed, UI tweaks applied, and a few new custom event types for integrations. ## Highlights ### Anonymous ID salting for stronger privacy Anonymous identifiers now include salting during generation, making it harder to correlate across systems without explicit binding. ### External ID support for links The links endpoint now accepts externalId parameters, letting you map your own system IDs directly to platform links without additional lookups. ### Metadata now on all API endpoints Hidden tags with endpoint metadata are now consistently available across the full API surface, making introspection and tool integration actually viable. ### Better MCP tool filtering and rule handling Agent tool operations are now properly gated by context. This prevents unintended API calls in AI integration workflows. ### Documentation respects Accept headers for AI crawlers API docs now respond correctly to Accept headers, so automated tools and AI agents can actually parse your specs without hitting dead ends. ## More Updates ### Bug Fixes - **Fixed date coercion in output validation** - Date values no longer fail validation during response serialization. (Author: @izadoesdev) - **Fixed links redirect fail-open logic** - Missing link data no longer causes cascading failures. (Author: @izadoesdev) - **Improved API key permission UX** - Dashboard workflows for viewing and updating API key permissions are clearer and less error-prone. (Author: @izadoesdev) - **Organization IDs now visible in settings** - Admins can now find their org ID directly in the settings panel instead of digging through logs. (Author: @izadoesdev) - **Fixed sidebar feature flag visibility** - Feature flags in the sidebar now respect their actual enabled state instead of showing up when they shouldn't. (Author: @izadoesdev) - **API keys work in org-only deployments** - API key creation and management no longer fail when the organization-only flag is enabled. (Author: @izadoesdev) - **Fixed link endpoint scoping** - Links are now correctly scoped in multi-tenant setups so users can't access links from other organizations. (Author: @izadoesdev) ### Features & Enhancements - **Custom event types for the API** - New custom event types are now exposed as endpoints for integration workflows. (Author: @izadoesdev) - **OpenAPI specs for links route** - The links endpoint now has proper OpenAPI documentation. (Author: @izadoesdev) - **Improved Swagger documentation theme** - The API documentation UI is more readable and easier to navigate. (Author: @izadoesdev) - **MCP integration documentation** - Added docs covering how to set up and use Model Context Protocol with the platform. (Author: @izadoesdev) - **Design cleanup on links and tables** - Component layouts and styling are more consistent and polished. (Author: @izadoesdev) ### Internal Changes - **Lint-staged configuration** - Lint and formatting now run automatically on commits, catching style issues early. (Author: @izadoesdev) ## Langfuse: Langfuse Changelog - February 2-13, 2026 URL: https://www.usenotra.com/changelog/langfuse/single-span-evals-and-scores-filtering.md Date: 2026-02-13 This week brought substantial progress across evaluations, integrations, and infrastructure resilience. Single-span evaluations moved into open beta, critical fixes resolved persistent job queue deadlocks, and new filtering capabilities landed for the scores API. The team also modernized dashboard charting with Recharts and refined UI usability across multiple components. ## Highlights ### Single-span evaluations now in open beta LLM-as-a-Judge can now target individual observations rather than full traces, making evaluation more granular and efficient at scale. ### Fixed integration queue deadlocks Reverted a problematic hourly-key approach to job deduplication that caused Mixpanel and PostHog integration jobs to stall permanently. Static jobId handling is back, along with stalling protections to prevent future blocking. ### Advanced filtering for scores v2 API with metadata support The scores v2 endpoint now supports advanced filters, unlocking metadata-based and observation-level filtering for more targeted score retrieval. ### Dashboard charting rebuilt with Recharts Migrated home dashboards from Tremor to Recharts, gaining better legends, tooltips, and area time series support alongside improved visual consistency. ### Project-wide table defaults and always-visible playground controls Table view defaults can now be set at project scope, and playground tool/schema buttons are always visible for better discoverability. ## More Updates ### Features & Enhancements - **Free-text observation names in evaluations** [#12000](https://github.com/langfuse/langfuse/pull/12000) - Enabled free-text observation and trace name entry ahead of v4 release. (Author: @marliessophie) - **Project-wide table defaults** [#11943](https://github.com/langfuse/langfuse/pull/11943) - Set table view defaults across an entire project for consistency. (Author: @nimarb) - **Events table in integration exports** [#11968](https://github.com/langfuse/langfuse/pull/11968) - Events table now included in data exports from integrations. (Author: @hassiebp) - **MCP listPrompts datetime range filters** [#11832](https://github.com/langfuse/langfuse/pull/11832) - Added fromUpdatedAt and toUpdatedAt filters to the MCP listPrompts endpoint. (Author: @mkowen1) - **Advanced filters on scores v2** [#11987](https://github.com/langfuse/langfuse/pull/11987) - Scores v2 endpoint now accepts advanced filters for metadata-based queries. (Author: @sumerman) - **Observation\_id filtering on scores v2** [#11974](https://github.com/langfuse/langfuse/pull/11974) - Extended v2 scores filtering to include observation-level parameter. (Author: @sumerman) - **Trace reference badge in evaluations** [#11991](https://github.com/langfuse/langfuse/pull/11991) - Added clickable trace reference badge in evaluation traces for navigation. (Author: @marliessophie) - **Scores empty state links to FAQ** [#11986](https://github.com/langfuse/langfuse/pull/11986) - Updated scores empty state to point users toward FAQ. (Author: @Lotte-Verheyden) ### Bug Fixes - **Fixed Mixpanel and PostHog job stalling** [#11988](https://github.com/langfuse/langfuse/pull/11988) - Prevented integration jobs from permanently stalling with proper job deduplication and stalling protection. (Author: @sumerman) - **Reverted hourly-key jobId approach** [#11998](https://github.com/langfuse/langfuse/pull/11998) - Restored static jobId and added removeOnFail to clean up failed jobs immediately. (Author: @sumerman) - **PostHog error handling** [#11996](https://github.com/langfuse/langfuse/pull/11996) - Added fail-fast error handling for PostHog to prevent queue blocking. (Author: @sumerman) - **Dataset item version inference** [#12024](https://github.com/langfuse/langfuse/pull/12024) - Fixed timestamp logic to correctly infer dataset item versions. (Author: @marliessophie) - **Observation filter options retrieval** [#12022](https://github.com/langfuse/langfuse/pull/12022) - Fixed observation filter options to fetch all available names. (Author: @marliessophie) - **Data table refresh timing** [#11970](https://github.com/langfuse/langfuse/pull/11970) - Reset auto-refresh timer after manual refresh to prevent unexpected updates. (Author: @aditya-mitra) - **Playground tool buttons visibility** [#12028](https://github.com/langfuse/langfuse/pull/12028) - Tool and schema edit/delete buttons are now always visible. (Author: @nimarb) - **Scores table cell text display** [#11975](https://github.com/langfuse/langfuse/pull/11975) - Improved text truncation and wrapping in scores table cells. (Author: @marliessophie) ### Infrastructure - **Integration queue cleanup tuning** [#12004](https://github.com/langfuse/langfuse/pull/12004) - Increased cleanup limits for legacy integration queue jobs. (Author: @sumerman) ### Internal Changes - **LLM-as-a-Judge evaluation instrumentation** [#12027](https://github.com/langfuse/langfuse/pull/12027) - Added observability for evaluation execution. (Author: @hassiebp) - **Events table v4 beta cloud-only gate** [#12001](https://github.com/langfuse/langfuse/pull/12001) - Gated events table v4 beta feature to cloud deployments. (Author: @nimarb) - **Tremor to Recharts migration** [#11916](https://github.com/langfuse/langfuse/pull/11916) - Replaced Tremor dashboard charts with Recharts for improved legends, tooltips, and new chart types. (Author: @coffee4tw) - **Code-mirror height configuration** [#11995](https://github.com/langfuse/langfuse/pull/11995) - Added flexible height settings for code mirror components. (Author: @marliessophie) - **Turbo build tool upgrade** [#12026](https://github.com/langfuse/langfuse/pull/12026) - Updated Turbo to 2.8.7. (Author: @nimarb) - **Integration queue cleanup removal** [#12008](https://github.com/langfuse/langfuse/pull/12008) - Removed cleanup logic to streamline queue management. (Author: @sumerman) ### Documentation & UX - **Observation evals marked open beta** [#12018](https://github.com/langfuse/langfuse/pull/12018) - Updated docs to reflect observation evals as open beta. (Author: @marliessophie) - **Dataset run webhook clarification** [#11897](https://github.com/langfuse/langfuse/pull/11897) - Clarified webhook configuration in dataset run experiment modal. (Author: @Lotte-Verheyden) - **Chart label and tooltip improvements** [#11989](https://github.com/langfuse/langfuse/pull/11989) - Added spacing between Y-axis labels and hover tooltips for full label display. (Author: @coffee4tw) - **Cloud pricing page updates** [#12019](https://github.com/langfuse/langfuse/pull/12019) - Updated data access tiers on pricing page. (Author: @marcklingen)