Fleet 2.6.0 is out.See what's new →
FleetFleet
Product Updates

Changelog

Every release of Fleet, newest first. Latest: v2.6.0.

v2.6.02026-07-18Latest
NEW
  • plugin: add public Fleet Codex plugin (#765)
FIX
  • reject incompatible workers before approval resume (#740) (#755)
  • invalidate stale review outputs on continuation (#770) (#772)
  • complete rejected-run recovery inputs and retry reset (#785) (#803)
  • recover stalled workflow agents (#752) (#759)
  • populate workflow agent roles after a Fleet metadata sync (#688) (#720)
  • preserve release classification in workflow merges (#758) (#763)
  • release completed one-shot agent sessions (#800) (#801)
  • show pinned ticket on workflow runs (#796) (#799)
v2.5.102026-07-18
FIX
  • baseline same-PR continuations at the live head (#795) (#797)
v2.5.92026-07-18
FIX
  • bind manual workflow runs to a ticket (#788) (#791)
  • recover review failures from tracked code (#790) (#792)
v2.5.82026-07-18
FIX
  • recover missing continuation branches (#783) (#784)
v2.5.72026-07-18
FIX
  • recover rejected workflows on existing PR (#785) (#786)
v2.5.62026-07-18
FIX
  • continue review infrastructure failures (#745) (#781)
v2.5.52026-07-18
FIX
  • defer same-PR continuation when code capacity is busy (#754) (#761)
v2.5.42026-07-18
FIX
  • structure review revision provenance (#774) (#775)
v2.5.32026-07-18
FIX
  • preserve cleared code results on capacity defer (#762) (#766)
v2.5.22026-07-18
FIX
  • use canonical workflow repair URL (#760) (#764)
v2.5.12026-07-18
FIX
  • preserve workflow escalation on ticket outages (#746)
v2.5.02026-07-18
NEW
  • continue escalated workflows on existing PRs (#749)
v2.4.32026-07-17
FIX
  • actions: isolate live agent launch files while preserving scheduled sessions (#743) (#744)
  • workflows: create one durable replacement run when retrying a failed label workflow (#695) (#742)
v2.4.02026-07-17
NEW
  • goal-loop: tenant-facing Stripe connector — goals that update themselves (#594) (#616)
FIX
  • allow scheduled Stripe evidence deploy (#731)
v2.3.02026-07-17
NEW
  • workflows: select worker-supported OpenCode models (#710)
FIX
  • add adapter sentinel error contracts (#681)
  • add genflow sentinel error contracts (#684)
  • add sentinel CLI error contracts (#673)
  • clear context and security lint batch (#672)
  • clear return contract lint batch (#671)
  • clear staticcheck and unused lint batch (#666)
  • clear targeted lint warnings (#669)
  • complete sentinel error contracts (#686)
  • watcher: support workflows without local agents (#712)
  • wrap external errors with context (#687)
v2.2.02026-07-05
NEW
  • goal-loop: wire KPI_STRIPE_TARGET → Paying-customers goal (prod)
  • goal-loop: wire KPI_STRIPE_TARGET to the Paying-customers goal (prod)
  • integrations: auth substrate — OAuth, secret metadata, rotation audit, revoke (#610)
  • integrations: auth substrate — OAuth, secret metadata, rotation audit, revoke (#610)
  • integrations: Bitbucket Cloud source-control provider (#597) (faac1b0), closes #595
  • integrations: CI/CD intake — Buildkite, CircleCI, Jenkins, Vercel, Netlify, Cloudflare, Render, Fly.io (#601) (de62318), closes #595
  • integrations: corpus connectors — Google Drive, Notion, Confluence, SharePoint, Slack threads (#602) (b4fd5f4), closes #595
  • integrations: customer signals — Zendesk, Intercom, HubSpot, Salesforce, PostHog (#604) (efe9af8), closes #595
  • integrations: GitHub joins the server-side poller — REST twin + App tokens (#595)
  • integrations: GitLab source-control and work-item provider (#596) (40e5fe1), closes #595
  • integrations: governance — per-action permissions and delegated roles (#612)
  • integrations: governance — per-action permissions and delegated roles (#612) (3835d08), closes #595
  • integrations: governed MCP router — policy, gateway, injection, audit (#603) (c407316), closes #595
  • integrations: incident intake — Sentry, Datadog, PagerDuty, OpenTelemetry (#600) (3430dfe), closes #595
  • integrations: instance model and lifecycle state (#607)
  • integrations: instance model and lifecycle state (#607) (194303e), closes #595
  • integrations: one-stop onboarding — all categories through the Integrations UI (#614) (8fd45ce), closes #643
  • integrations: poll leases — one provider API call per interval across all machines (#595)
  • integrations: security scanner intake — SonarQube, Snyk, Dependabot, CodeQL, Semgrep (#605) (4f9c1da), closes #595
  • integrations: server-side Go work-item poller — intake off the dev machines (#595)
  • integrations: shared provider registry with TS/Go generation (#606)
  • integrations: shared provider registry with TS/Go generation (#606) (d6e68ef), closes #595
  • integrations: Slack operator surface — governed approvals, commands, briefings (#599) (de3401e), closes #595
  • integrations: trigger rule CRUD, dry-run, and per-rule stats (#608)
  • integrations: trigger rule CRUD, dry-run, and per-rule stats (#608) (ce8ee8a), closes #595
  • integrations: unified health for dashboard, doctor, status, and MCP (#609)
  • integrations: unified health for dashboard, doctor, status, and MCP (#609) (31d88fa), closes #595
  • integrations: webhook ingestion substrate — idempotency, DLQ, delivery logs (#611)
  • integrations: webhook ingestion substrate — idempotency, DLQ, delivery logs (#611)
  • integrations: webhook-first intake for GitHub, Linear, and Jira (#598) (1ffdc35), closes #595
FIX
  • goal-loop: KPI_STRIPE_TARGET overridable via CDK context (PR 593 review)
  • integrations-ui: OAuth reconnect, input_type semantics, accurate secret copy (6ab2804), closes #595
  • integrations-ui: surface orphan-secret on partial save failure
  • integrations: address #644 review comments (8738b3d), closes #595
  • integrations: address /review + Gemini findings across the stack (b93e666), closes #595
  • integrations: address PR #622 review — jira URL validation, tokeninfo Bearer header, async sync reporting
  • integrations: address PR #623 review — priority preservation, async trigger reports, stats-write optimistic lock
  • integrations: address PR #624 review — GSI1 deliveries, direct secret lookup, guarded verify/parse, awaited reload
  • integrations: address PR #625 review — import.meta.url paths, multi-line detail extraction, falsy-safe contract checks
  • integrations: address PR #627 review — policy PATCH always echoes the full TenantPolicy shape
  • integrations: cross-machine dispatch claims — exactly-once with multiple dev machines (#595)
  • integrations: deep-review correctness fixes (concurrency, cursors, providers) (3028c50), closes #595
  • integrations: MCP integrations are admin-only (close RCE via delegated configure) (6f5763b), closes #595
  • integrations: replay idempotence, secret-optional warning, zendesk shape, e2e backdoor (1c13a6a), closes #595
  • integrations: resolve the remaining deferred deep-review items (1de3e5a), closes #595
  • watcher: ack webhook work only after dispatch succeeds; surface lease-lost (b5bd927), closes #595
v2.1.02026-07-02
NEW
  • goal-loop: goal context in agent prompts via /sync (D)
  • goal-loop: goal context in agent prompts via /sync (D)
  • goal-loop: goal-scoped work attribution + drill-in (B2)
  • goal-loop: goal-scoped work attribution + inline drill (B2)
  • goal-loop: goal-weighted dispatch behind governance toggle (E)
  • goal-loop: goal-weighted dispatch behind governance toggle (E)
  • goal-loop: goal:<id> ticket label convention (B1)
  • goal-loop: goal:<id> ticket label convention (B1)
  • goal-loop: push value-API + Stripe producer (G)
  • goal-loop: push value-API + Stripe producer (G)
  • goal-loop: talk-back drafts tickets, human-gated (F)
  • goal-loop: talk-back drafts tickets, human-gated (F)
  • goal-loop: weekly KPI digest — snapshot deltas + attribution (C)
  • goal-loop: weekly KPI digest — snapshot deltas + attribution (C)
  • tenant-private artifact sharing + local-time share dates + CLI→tenant telemetry (#588)
FIX
  • goal-loop: /sync goals read fails open by OMISSION (PR 583 review)
  • goal-loop: bound the Stripe recount + 409 on contention (PR 586 review)
  • goal-loop: clipboard guard + label quote-safety (PR 580 review, landed properly)
  • goal-loop: digest scan projection + search-API pacing (PR 584 review)
  • goal-loop: finite-guard started/deadline at the boundary + parallel label creates (PR 587 review)
  • goal-loop: land the PR-580 review fixes (clipboard guard + quote-safety)
v2.0.02026-07-01
⚠ BREAKING CHANGES
  • genflow: remove FLEET_GENFLOW_CODE_STEPS — code steps always on (#413)
  • workflows-only execution — retire the reactive chain's subscription brain (#382)
NEW
  • activity: thread pr_title through decision events to Activity feed (#476)
  • agent types — role-bound steps, pinned house rules, type defaults, governance provenance + admin Settings
  • cas: generalize fabric_artifacts into compiled-artifact primitive + local CAS (closes #364)
  • cas: generalize fabric_artifacts into compiled-artifact primitive + local CAS (closes #364)
  • cihealth: CI billing-rejection classifier + workflow run provider mapping (fleet#131 carve-out) (#456)
  • cleanup: fleet agent cleanup --config-orphans + truthful delete warning (fleet#191) (#461)
  • complete release-train / integration-branch flow (#369)
  • complete release-train / integration-branch flow (#369)
  • connectors: GSC + GA4 connector foundation — binary Lane A (fleet#429) (#478)
  • controlplane: batch fabric event sync via POST /api/events/batch (fleet#142) (#491)
  • corpus: context corpus resolver — C1 of fleet general-purpose mode
  • corpus: context corpus resolver — C1 of fleet general-purpose mode (closes #363)
  • dashboard: approval gate shows WHAT is being approved
  • dashboard: mission-control SPA — intervention queue, vitals, moving/delivered, rail
  • dashboard: per-workflow stuck SLA + run→pr_state verifier (PR 3 polish)
  • dashboard: ROI page per-product segmentation (fleet#255) (#484)
  • dashboard: run-sourced briefing tools + legacy event-pipeline removal
  • dashboard: run-sourced mission-control assembly + /dashboard/mission-control
  • dashboard: runs-as-primitive parts 2+3 — SPA swap, stuck SLA, run→pr_state verifier
  • dashboard: runs-as-primitive PR 1 — write paths + mission-control assembly
  • dashboard: runs-as-primitive PR 3 — per-workflow stuck SLA + run→pr_state verifier
  • doctor/status/upgrade: daemon staleness vs master/release (fleet#355)
  • eval,genflow,risk: independent code-quality signal — oracle step + risk feature (fleet#273, fleet#274) (#499)
  • eval: add CodeQuality seventh scoring dimension (fleet#271) (#470)
  • eval: severity-weight the review-feedback penalty (fleet#272) (#494)
  • fleet: general-purpose agent mode — artifact_produced completion (#365)
  • fleet: general-purpose agent mode — artifact_produced completion (#365)
  • fleet: general-purpose agent mode — artifact_produced completion (#365) (#534)
  • general-purpose mode (genflow) — governed workflows over a corpus (#374)
  • genflow: add HTTP check step for monitoring workflows
  • genflow: add HTTP check step for monitoring workflows
  • genflow: agent-types — role-bound steps, pinned house rules, type defs, governance provenance
  • genflow: approvals inbox + self-contained approval page (#381)
  • genflow: autoApprove on gates — reviews are the sign-off, humans gate exceptions (#431)
  • genflow: bind role to Triage Assessment step + fleet genflow lint (fleet#454) (#455)
  • genflow: code dispatch skips busy agents — parallel devs via roster capacity (#430)
  • genflow: configurable per-step timeout + evidence-preserving timeout errors (#420)
  • genflow: convergent fix loop — re-reviews judge their own prior flags (fleet#433) (#440)
  • genflow: finish-first worker scheduling — advance started work before new (#495)
  • genflow: flip event triggers default from opt-in to opt-out (#397) (6a703b0), closes #394
  • genflow: log effective execution config at worker startup (fleet#441) (#442)
  • genflow: pre-flight workflow validation — reject duplicate keys/outputs, dangling/self deps (fleet#366) (#498)
  • genflow: reap alive-but-hung code dispatches via git-progress (#487 Phase 1)
  • genflow: reap alive-but-hung code dispatches via git-progress (#487 Phase 1)
  • genflow: remove FLEET_GENFLOW_CODE_STEPS — code steps always on (#413) (ae181f1), closes #412
  • genflow: review steps pull the PR locally — diff + discussion as review input (#419)
  • genflow: structured run telemetry — escalated signal, terminal rounds, merged flag
  • genflow: TicketGateway gains LabelTicket — autonomous ticket:update handoff (#415)
  • genflow: unified workflow engine — governed dev-workflow as pure config (#377)
  • genflow: webhook-driven merge trigger + success-branch primitive (#506)
  • genflow: wire cron schedule evaluation on pulled workflow definitions (#393) (#406)
  • release: hard gate — unresolved review threads block merge (closes #352)
  • Sentry error tracking across all three surfaces (go binary, api, web)
  • server: run write-paths for the run-sourced dashboard
  • validate request bodies + JSON on the way in — one zod validateBody() (#448) (#450)
  • workflows-only execution — retire the reactive chain's subscription brain (#382)
  • workflows: land post-#374 session work (uuid ids, runner harness, repo select) (#375)
FIX
  • /review findings — pin integrity, drift guards, provenance honesty
  • actions: worktree wrapper resolves the repo's real default branch
  • address #383 post-merge review findings (#384)
  • address PR #385 review comments — repo-scoped trigger polls, trigger-identity dedup keys, href + dedup hardening
  • address PR #525 review — cron Sunday-as-7 ranges, rune-safe truncate, nil-config guard
  • auth: fail closed when both sub and email lookups fail (fleet#150) (#460)
  • brain: drop harmful bullets from speed_up evolution template (#158)
  • cas: address reviewer feedback — streaming WriterFrom, os.ReadDir GC, bool shareable
  • chain: stamp required scope label on task_assigned PRs (fleet#170) (#463)
  • corpus: address reviewer feedback — git ls-files -z, doubleStarMatch allocs, json null guard
  • dashboard: canonicalize PR event work-key so merged PRs retract from Needs-Attention (closes #358)
  • dashboard: canonicalize PR event work-key so merged PRs retract from Needs-Attention (closes #358)
  • dashboard: canonicalize PR event work-key so merged PRs retract from Needs-Attention (closes #358)
  • dashboard: PR-state verifier correctness + safeHref gate + stuck-SLA hardening
  • dashboard: PR-state verifier correctness + safeHref gate + stuck-SLA hardening
  • dashboard: revert pr:issue# canonicalization; clear all payload keys on ship/approve (#361)
  • doctor: warn when integration_branch == default_branch (PR #541 review)
  • fabric: normalize non-JSON payloads at socket publish boundary (fleet#140) (#486)
  • genflow,brain: genflow reliability + brain evolution backlog fixes
  • genflow,brain: genflow reliability + brain evolution backlog fixes (#528)
  • genflow: binary-side active-run pre-check + /runs/active endpoint (fleet#396)
  • genflow: binary-side active-run pre-check + /runs/active endpoint (fleet#396)
  • genflow: break awaiting_code livelock + consistent re-fetch after claim (fleet#410) (#432)
  • genflow: canonicalize drain-mutex key + preserve step history on dead-dispatch (review feedback)
  • genflow: close fleet#366 — verify wedge tests green, remove contradictory regression guard (#503)
  • genflow: exactly-once cron occurrences + expose requested_by + clearer unknown-workflow error
  • genflow: fail fast on dead code-step dispatch instead of 24h park (#487 #386 #514)
  • genflow: fan out code dispatch across the developer pool, never preempt (dispatch race) (#485)
  • genflow: fix-round notice tells the dev how to answer without a code change
  • genflow: make default runner tool-free + regression guard (#405)
  • genflow: per-repoRoot worker drain mutex, not one global lock (#416)
  • genflow: removeLabel binding consumes trigger label — stops non-closing backlog loop (fleet#451) (#453)
  • genflow: require verbatim spec citation in review flags (#411)
  • genflow: require verbatim spec citation in review flags (#411)
  • genflow: require verbatim spec citation in review flags (#411) (#532)
  • genflow: run→repo affinity — per-repo workers must not claim foreign runs
  • genflow: SSRF-guard the check step (block internal IPs + scheme allowlist) + field-mapping/body-limit tests
  • genflow: trigger dedup blocks deliberate re-arms until daemon restart
  • genflow: use input(s) consistently in review prompt (review feedback)
  • genflow: validate check-step url scheme at lint time (review #539)
  • genflow: watcher daemon never polled label triggers
  • genflow: watcher daemon never polled label triggers — add the autonomy loop
  • insights,eval: surface code_quality in brain insights + pin AC3 hardcoded baseline (fleet#275, fleet#268) (#501)
  • mcp: drop retired fleet_pipeline_* tools from the MCP manifest
  • mcp: drop retired fleet_pipeline_* tools from the MCP manifest
  • pre-landing review findings — href allowlist, enqueue idempotency, list window, case-fold affinity
  • prompt: give named-org prompt manager global fallback overlay (fleet#303) (#468)
  • release: filter note-kind events from merge gate + pin regression tests (fleet#132) (#457)
  • round-2 /review findings — type defaults at sync, atomic policy patch, pin-lost audit
  • round-3 /review findings — sync seam shares the type-defaults rule, audited vendor flips, no-op policy patch rejected
  • scheduler: skip quarantined agents + drop subscription_attempts (fleet#304) (#469)
  • sourcecontrol: address PR #542 review (rune-safe truncate + repo-format guard)
  • subscriptions: GC stale subscription claims so re-fired tickets dispatch (fleet#350)
  • subscriptions: GC stale subscription claims so re-fired tickets dispatch (fleet#350)
  • subscriptions: GC stale subscription claims so re-fired tickets dispatch (fleet#350)
  • subscriptions: roster guard prevents per-repo reconcile deleting live org-agent claims (fleet#350)
v1.17.02026-06-06
NEW
  • upgrade: add fleet upgrade self-update command (#330)
  • upgrade: fleet upgrade — self-update binary to latest release (#330)
FIX
  • storm-cap: scope re-dispatch cap to recent window, surface in fleet doctor (#336)
  • upgrade: normalize v-prefix in --version and cap archive download
v1.16.52026-06-05
IMPROVED
  • Per-repo watcher PID files (#206, #213). fleet watcher status/doctor/up/down now key off per-repo PID files, so multiple repo watchers can run concurrently on one host without clobbering each other's PID. Required for the multi-project central-server deployment.
NEW
  • Enterprise "disable custom agents" policy (#294). An admin toggle on the control plane that, when enabled, blocks launching any agent that declares no role. Enforced both server-side at /sync (role-less agents are clipped from the synced roster) and locally in the binary (startAgent/PreviewAgent gate on the disable_custom_agents setting, delivered via the new /sync policy object) — defense in depth. Because house rules match by role, a locally-created same-role agent automatically inherits the enterprise's rules. The control-plane Prompt Management role filter is now a constrained agent-role select instead of a free-text field.
  • Level-triggered PR reconciler (#285, fleet#267/#281). The watcher sweeps open PRs and re-dispatches the responsible role for each PR revision, so no open PR sits unclaimed. The reactive chain is now fully autonomous across multi-round reviews — the prior manual nudge recipes are obsolete.
  • Review re-dispatch on a new changes-requested round (fleet#267, #276). A developer is re-dispatched when its PR receives a fresh pr_changes_requested, fixing multi-round PRs that previously stalled because receipt dedup never re-dispatched the dev for a second review round.
  • Dependency gate enabled on the developer subscription (fleet#199, #279). subscription_gate.dependencies_shipped holds a dependent ticket until its parent ships; gated dependents auto-unblock when the parent issue closes (fleet#281).
  • Brain code-quality events (fleet#270, #283). The brain emits code_quality events derived from CI check summaries; sourcecontrol.CheckRun gains DetailsURL and Summary fields to carry them.
  • Priority sweeper for backlog pull (#222, #224). The issue watcher pulls the highest-priority ready work first rather than FIFO.
FIX
  • Watcher rate-limit backoff + memoization (fleet#225). GitHub rate-limit backoff, a tick-cache, and dep-gate memoization cut redundant API calls in the watcher loop. Also fixes an issue-watcher vs label-watcher fetch divergence (issues-only vs issues+PRs) so the two never share a repo-keyed cache.
  • Fabric receipt retraction on a failed ship (fleet#237, #284). A logical receipt is retracted when the release-manager exits without merging, so an aborted ship no longer leaves a phantom completion that blocks re-dispatch.
v1.16.4.02026-05-28
FIX
  • Self-healing watcher restart (fleet#192). On startup the watcher reconciles unhandled labels (#246), uses completion-aware dedup so stalled work-in-progress labels self-heal instead of being suppressed forever (#247), and re-evaluates existing dedup rows so a restart re-fires genuinely-stalled labels (#258). Restart is now completion-aware and crash-recoverable; the live re-fire cleared 8 fleet + 10 forge stalled labels.
  • Org-watcher coverage in fleet doctor / watcher status (fleet#242, #244). fleet doctor reports OK when an org-level watcher already covers the repo (#244), and surfaces a per-repo coverage gap when nothing covers it (#242) instead of silently leaving the repo unwatched.
v1.16.3.02026-05-27
NEW
  • fleet release check <pr> merge gate — Go-tested decision (in internal/release) that authorizes a merge based on EITHER GitHub reviewDecision == APPROVED (legacy happy path) OR an approved label plus a pr_approved fabric event from a reviewer with no later pr_changes_requested. Defense-in-depth ordering: a fresh pr_changes_requested overrides any earlier pr_approved. Exit 0 when mergeable, 1 otherwise; JSON on stdout for audit. Closes the long-standing chain stall caused by GitHub's self-review block (every fleet agent runs as the same gh identity, so gh pr review --approve fails for fleet-authored PRs and reviewDecision stays empty even after reviewers approve). Issue #128.
  • Vendored fleet skill library at internal/skills/fleet/<name>/SKILL.md, embedded in the binary via go:embed. The skill source is now part of the repo — a PR can fix a skill bug instead of requiring every operator to hand-edit ~/.claude/skills/fleet/.
  • fleet skills install subcommand — syncs the embedded skills to ~/.claude/skills/fleet/ (configurable via --target, dry-run via --dry-run). Idempotent. Operators run after every fleet upgrade to pick up skill fixes.
  • fleet skills list — prints the vendored skill names bundled with the current fleet binary.
  • GitHub App integration (#137, #138, #185). Control-plane-minted installation tokens, a GitHub App webhook receiver with HMAC verification, an "Install Fleet AI Bot" dashboard button, and self-healing reconciliation when the install row is missing or stale (#168) — so fleet agents can act as a real GitHub App identity.
  • Morning-briefing pipeline (#180–#184). Webhook deliveries project PR state (#182); briefing.morning is generated in a verified shape (#183) and rendered dual-channel in Chat.tsx (#184).
  • Per-role agent concurrency cap (#114, #122). max_concurrent per role, enforced across fabric + watcher + status with running counts cached per sweep (#130).
  • Dependency-sequenced tickets (#199, #70). subscription_gate.dependencies_shipped sequences ticket work via issue-body deps; subscription_gate verifies external state before firing agents (#92); issue_number resolves via the causal-parent chain (#202).
  • Per-project codebase digest (#113) — auto-injected into agent prompts.
  • fleet pr create + no-stacking policy (#197, #194) — subscription label gating that keeps PRs from stacking.
  • fleet up / fleet down one-command onboarding (#64, #68).
  • Reactive-chain config mode (#65). Fleet's own .fleet/config.yaml migrated to reactive-chain mode; adds the PM ticket-refinement gate (#80) and a required-label scope gate (#66, #78).
IMPROVED
  • Operator-facing API URLs drop the /fleet/ prefix (issue #157, phase 1). GitHub App callback URL recommended path is now https://app.fleetctl.ai/api/github-app/callback — existing operators with the legacy /api/fleet/github-app/callback URL keep working until phase 3, when the dual-mount is retired. Same applies to every other endpoint formerly under /api/fleet/* (instances, agents, events, sync, register, license, metering, integrations, github-app/*, chain/graph): each one is now reachable at BOTH the legacy /api/fleet/<thing> AND the short /api/<thing> path. The React dashboard and the Go CLI both emit the short shape on this release; older binaries phoning home from prior versions continue to resolve through the legacy mount with no behavior change. Phase 2 (deprecation warnings on /api/fleet/* hits) and phase 3 (removal) ship as separate follow-up issues.
FIX
  • Subscription burst serialization (issue #205) — watchAgentSessionExit goroutine now spawns after every subscription-triggered agent launch. Polls HasSession at 500 ms intervals; fires NotifyFabricEvent() the moment the session disappears, waking the subscription processor immediately instead of waiting up to 5 minutes for the subscriptionSanityInterval ticker. A 3-event burst against a max_concurrent=1 agent (e.g. product-manager on ticket_new) now drains serially within seconds; the 10–21 minute delays observed in the 2026-05-26 burst (#201, #202, #204) are eliminated. All existing dedup invariants (receipts, claims, cap) are unchanged. If the session never appears within 10 s (start failure), notify fires anyway; context cancellation returns cleanly without notifying (no shutdown race). Closes #205.
  • fleet-review-pr skill (issue #128) — the reviewer skill now ALWAYS publishes pr_approved / pr_changes_requested to fabric, even when gh pr review --approve fails because of GitHub's self-review block. Captures the gh error into a permanent PR comment so a human reviewing the PR on github.com can see why reviewDecision is empty. Pre-fix, the skill silently fell back to --comment, the publish was skipped, and the chain stalled — no PR ever shipped autonomously.
  • fleet-ship-pr skill (issue #128) — the release-manager skill now invokes fleet release check <pr> instead of gating purely on reviewDecision == APPROVED. The 4 PRs that were stuck on the self-review block (#121, #124, #125, #126) become mergeable as soon as the new gate runs against them. The 7 PRs that shipped pre-fix (#100, #112, #116, #118, #119, #122, #123) keep working — the legacy reviewDecision == APPROVED path is honored as an alternative valid signal.
  • Fabric receipt-check hardening (fleet#210, #234, #102). Receipt-check errors fail closed, not open (#210); a json_valid guard stops malformed JSON from unbinding the chain on receipt joins (#234); logical-key receipts stop runaway agent re-launches (#102).
  • Worktree stale-base PRs (#212, #189). Fetch origin before worktree add so subscription, scheduler, and pipeline agents branch from current master instead of a stale base.
  • Label-watcher replay storms (#204, #209, #104). Remove needs-review on merge (#204), seed the dedup table on startup (#209), and gate label-watcher publishes on issue/PR open state (#104) to stop restart replay.
  • register --force + dashboard survival (#110, #103). --force is honored again (#110); daemon senders stop creating placeholder agent rows (#103).
  • Parallel-PR race (#152). A pre-launch subscription claim closes the parallel-PR race.
v1.16.2.02026-04-20
NEW
  • Post-exit reactive-chain hook (fleet agent post-exit) — runs automatically after every reactive agent finishes. Discovers the PR the agent opened by head branch via the sourcecontrol.Provider abstraction, publishes pr_created to fabric, and stamps needs-review so the label watcher fires pr_needs_review through the normal path. When no PR exists, emits agent_no_pr_created so the chain break is visible in the log/dashboard instead of silently stalling. Pre-fix, the chain depended on the agent self-reporting via fabric publish — agents that crashed or forgot silently broke the chain and tickets sat forever at "agent done, PR open, no review triggered." Closes fleet#42 and fleet#24.
  • FindOpenPRByHeadBranch and AddLabels on sourcecontrol.Provider — GitHub implementation wraps gh pr list --head (server-side filter, not client-side loop) and gh issue edit --add-label (PRs are issues on the GitHub API, one code path handles both). Idempotent — re-applying an existing label is a no-op, not an error.
FIX
  • Config sync accepted entries with no resolved vendor (fleet#38) — running fleet config sync on a config whose agent entry had vendor: "" and no default would silently create a broken agent row. Now rejected at sync time with errors.Join aggregating all invalid entries so the operator sees every problem in one pass.
  • fleet init emitted substring-routed subscribe/publish defaults — heuristic pattern-matching produced agents with subscription maps that overlapped in surprising ways at scale. Removed; fleet init now emits explicit per-role defaults only.
IMPROVED
  • No user-visible CLI contract changes. Reactive-mode agents gain the post-exit hook transparently; non-reactive runs (manual starts, scheduled crons, pipeline stages) are unaffected.
v1.16.1.02026-04-20
NEW
  • scripts/cleanup-zombie-instances.sh — operator helper for reaping orphaned tmux sessions left behind by crashed brain/watcher daemons.
FIX
  • Worktree isolation — agents launched into git worktrees no longer leak environment or working-directory state into sibling sessions.
  • Daemon freshness — brain + watcher restart ritual validated end-to-end; fleet doctor surfaces stale PIDs instead of reporting OK.
IMPROVED
  • No user-visible behavior changes. All fixes preserve existing CLI contracts; the new flag validation rejects input that was previously silently mis-parsed.
NEW
  • Control-plane MCP server at POST /api/mcp — spec-compliant JSON-RPC 2.0. Any MCP-aware client (Claude Desktop, Claude Code, future SDKs) can connect with a Bearer JWT to query a tenant's fleet state without logging into the web UI. Fleet becomes queryable wherever Claude already lives.
  • Nine control-plane tools exposed via MCP: briefing.morning (composite parallel aggregation), briefing.interventions, briefing.shipLog, briefing.runningAgents, briefing.decisions, briefing.fleetHealth, integrations.list, integrations.save, integrations.delete.
  • Shared tool manifest at docs/mcp-manifest.yaml — authoritative catalog for both the Go stdio MCP server (internal/mcp/) and the new TS HTTP server. CI test blocks orphan handlers and missing implementations in either language.
  • Chat auto-seeds a morning briefing on login. Chat.tsx dispatches a silent seed prompt on first mount of a session; Claude composes the briefing using briefing.morning. Session-guarded against React StrictMode double-mount, re-seeds on tab focus after 30 min idle, handles empty-fleet + degraded states explicitly.
  • Integrations tab on Billing page (?tab=integrations) — admin-only UI for connecting GitHub, Linear, and Jira. Per-provider form collects credentials + workspace fields (Jira includes site URL + account email). Secrets are KMS-encrypted and never returned by GET.
  • Jira Cloud workitems adapter (internal/workitems/jira.go) — polls Jira via REST v3 /search with Basic auth. Watcher wires Jira into the provider switch; control-plane integrations response now carries site, proj_key, and email to the fleet.
v1.15.0.02026-04-12
NEW
  • Brain daemon activation: the heartbeat loop now actually runs the eval, risk, alert, quarantine, and evolve pipelines on real data. fleet brain start was previously a no-op for idle agents; it now polls GitHub every 5 minutes, ingests real outcomes, scores every enabled agent, and dispatches pending experiments.
  • Extended polling via a new internal/sourcecontrol provider abstraction: CI check runs (ci_pass/ci_fail), issue assignments (coordination), issue closures (complete), and merge detection. Same brain logic works for GitHub today and can plug GitLab/Bitbucket adapters later without touching the eval layer.
  • fleet brain insights CLI: per-agent aggregated evaluation score, grade, risk level, recent thoughts, and actionable prompt-improvement recommendations. Worst performers sort first. --agent <name> filters to one.
  • fleet_brain_insights MCP tool: the same data as the CLI, surfaced to Claude Code and any other MCP client for programmatic access.
  • fleet status brain summary line: "Agents Needing Attention" and "Quarantine Candidates" counts from the latest evaluation/risk per agent, so operators see the picture without a second command.
  • Notification hookup (internal/brain/notify.go): brain thoughts at warning/high/critical priority fire webhooks through the existing internal/notify package. Slack/Discord delivery respects existing notification config.
  • Dashboard push (internal/brain/dashboard.go): evaluations and risk scores stream to the optional control plane dashboard via the existing internal/dashboard/push pusher.
  • Auto-evolve activation: the heartbeat dispatches SignalExperiment so pending experiments actually apply and the measurement phase runs — previously created experiments sat stuck in pending.
  • New evaluator dimensions: merge, ci_pass, ci_fail, issue_assigned, issue_closed events feed the 6-dimension scoring model with appropriate bonuses/penalties.
  • New evolution triggers off the new event types (merge rejections, CI-fail patterns).
  • AgentID primary key propagation through the entire brain signal path: handleAgentEvent, handleEvaluate, handleIdleScan, SignalAgentEvent all carry the int FK instead of (name, project) tuples.
IMPROVED
  • Brain store tables now use agent_id INTEGER NOT NULL REFERENCES agents(id) ON DELETE CASCADE instead of the legacy (agent_name, project) tuple. Affected tables: activity_events, agent_evaluations, risk_scores, brain_thoughts, prompt_experiments, agent_quarantines, alert_rules, alert_history, incidents, sla_configs. Same-named agents in different projects are now correctly tracked as distinct. Legacy brain data is dropped by the new preSchemaDropLegacyBrainTables migration — nobody was using it yet.
  • PRAGMA foreign_keys=ON is now enabled on every SQLite connection so the new FK constraints are actually enforced.
  • ensureAgentID auto-seed helper creates placeholder rows with a sentinel vendor="__auto__" and enabled=false. ListAgents/ListAllAgents filter these out so a typoed agent name in a writer call cannot pollute fleet status, idle scans, or agent listings.
  • HasEventWithDetailID(agentID=0) correctly queries WHERE agent_id IS NULL (matching CreateEventForAgentID(agentID=0)'s NULL insert behavior) — previously it ran WHERE agent_id = 0 and silently missed system-level rows.
  • Brain dispatchers, handlers, and event emitters now thread context.Context through the heartbeat path. Engine.Run() derives a cancellable runCtx; Engine.Stop() cancels it so in-flight gh subprocesses and store writes abort cleanly instead of racing shutdown.
  • Brain execGH/checkGHAvailable take a parent context (previously hardcoded context.Background()), so daemon shutdown actually aborts running gh subprocesses.
  • Brain event-write error paths now log via slog.Warn instead of silent _ = err drops. FK violations, DB locks, and disk-full become visible.
  • Subprocess timeouts: all gh CLI calls bound at 30s so a hung process cannot stall the heartbeat.
  • PR polling watermark: per-comment content hash dedup so new comments on a previously-seen PR trigger re-classification instead of being silently skipped.
  • GitHub rate-limit detection: brain aborts the current polling cycle when ErrGHRateLimit is returned and retries next heartbeat, spreading requests across budget windows.
FIX
  • Brain project scoping (Codex finding #1): same-named agents in different projects are now correctly distinguished via the FK refactor.
  • Auto-evolve lifecycle gap (Codex finding #2): SignalExperiment is now dispatched on every heartbeat so pending experiments advance.
  • Rate limit detection (CEO review GAP 1): ErrGHRateLimit / ErrRateLimited sentinel errors with backoff.
  • Evolution apply verification (CEO review GAP 2): prompt write is verified via GetAgentByID before the experiment transitions to running.
  • Subprocess timeouts (Codex finding #7): 30s bound on all gh and claude invocations.
  • PR polling watermark (Codex finding #6): per-comment hash watermark in the dedup key.
v1.14.0.02026-04-12
NEW
  • Multi-provider ticket integration: any ticket system can trigger Fleet agent pipelines, not just GitHub
  • Provider abstraction layer (internal/workitems/): normalized WorkItem model, trigger engine with condition matching over status/labels/assignee fields
  • GitHub adapter wrapping existing gh CLI, Linear adapter via GraphQL API
  • Cursor-based polling with exponential backoff on consecutive provider errors
  • fleet provider add/list/remove CLI commands for managing provider API keys via the dashboard
  • KMS-encrypted provider secret storage in the control plane (per-tenant encryption context)
  • Integration config API (GET /api/fleet/integrations) returns providers, triggers, and secrets in one call
  • fleet doctor validates provider authentication (GitHub gh CLI, Linear API key in dashboard)
  • fleet status shows provider summary line with trigger counts
  • trace_id column on fabric_events and pipeline_runs tables for future event chain observability
IMPROVED
  • Created shared type definitions (server/types.ts, src/types.ts) replacing all any usage
  • Authorizer tests updated to match current behavior (GET-only public routes, nfi_ passthrough)
v1.13.0.02026-03-21
NEW
  • Agent log rotation: 10MB threshold, 5 rotations kept, --previous and --follow flags (FLEET-012)
  • Config export/import: fleet config export and fleet config import with skip/overwrite strategy (FLEET-017)
  • Fabric event cleanup in fleet cleanup command (FLEET-018)
  • Auto-close GitHub issues when pipeline completes, with summary comment (FLEET-019)
v1.12.0.02026-03-21
NEW
  • Workflow execution engine: TriggerWorkflow() now executes actions (start_agent, stop_agent, send_event, run_pipeline) (FLEET-005)
  • Shell completions: fleet completion bash/zsh for all 19 subcommands (FLEET-011)
  • Approval notifications: fleet status shows pending approval count, MCP fleet_status includes count (FLEET-016)
  • MCP config tools: fleet_config_list, fleet_config_get, fleet_config_set (FLEET-020)
v1.11.0.02026-03-21
NEW
  • fleet cleanup command: data retention with configurable age, dry-run, per-table targeting, VACUUM (FLEET-004)
  • Pipeline dry-run: fleet pipeline run --dry-run validates stages, agents, and budgets before execution (FLEET-010)
  • Brain daemon health in fleet status: shows PID, running state, uptime (FLEET-013)
FIX
  • Pipeline agent claim deconfliction: ResolveStageAgent skips agents with active claims (FLEET-006)
v1.10.0.02026-03-21
NEW
  • fleet backup command: database backup with timestamp, custom output path, and JSON export (FLEET-003)
  • fleet config validate: validates .fleet/config.yaml schema, stage references, and cross-references (FLEET-007)
  • fleet_agent_create MCP tool: create agents programmatically with full config (FLEET-009)
  • fleet_agent_delete MCP tool: delete agents with optional force flag (FLEET-009)
FIX
  • tmux binary path resolved via exec.LookPath instead of hardcoded /usr/bin/tmux (FLEET-001)
  • Budget enforcement: budget.Check() now called before agent launch, blocking over-budget agents (FLEET-002)
IMPROVED
  • tmux Client now caches resolved binary path on struct instead of package-level constant
v1.9.2.02026-03-21
FIX
  • MCP fleet_pipeline_approve now resolves the agent for the next stage using ResolveStageAgent and records it as "claimed" with correct attempt count (was recording empty agent with "pending" status, blocking auto-start)
  • ClearSessionFile removes stale --resume session IDs before pipeline agent launches, preventing exit code 1 on first attempt
v1.9.1.02026-03-21
FIX
  • Brain engine Stop() now waits for Run() to fully drain dispatch goroutines before returning, preventing shutdown races
v1.9.0.02026-03-18
NEW
  • Autonomous pipeline execution in MCP server: fabric sweep loop wired into fleet mcp serve so pipelines auto-advance stages, auto-start agents, and detect dead sessions without manual intervention
  • OnStageStartFunc(), OnCompleteFunc(), IsAgentRunningFunc() accessors on pipeline engine for callback passthrough
v1.8.0.02026-03-18
NEW
  • fleet init --template <name> — non-interactive project scaffolding with predefined templates
  • fleet init --list-templates — list available templates with descriptions and tags
  • 4 built-in templates: go-service, fullstack, data-pipeline, devops
  • Templates resolve agents from tags via the catalog, write config.yaml and prompt files
  • 12 new tests covering template lookup, scaffolding, overwrite, and prompt content
v1.7.0.02026-03-18
NEW
  • fleet retro — weekly retrospective report command with --days N and --json flags
  • internal/retro package: Generate() collects pipeline stats, event breakdowns, agent activity, and blockers; Format() renders human-readable output
  • ListEventsSince(since, limit) store method for time-bounded event queries
  • 14 new tests (9 retro, 3 store, 2 CLI integration)
v1.6.1.02026-03-18
NEW
  • Pipeline approval gate change summary: fleet_pipeline_get and fleet_pipeline_approve MCP tools now show decision event summaries when a run is in waiting_approval status
  • changeSummaryForRun() helper aggregates Fabric decision events into a readable change summary
  • 7 new MCP handler tests covering change summary rendering, empty states, and approval flows
v1.6.0.02026-03-18
NEW
  • GitHub issue watcher daemon: polls for new issues and auto-triggers pipeline runs
  • internal/issuewatcher package with Watcher, FetchFunc, TriggerFunc abstractions (14 unit tests)
  • issue_watcher: section in .fleet/config.yaml with pipeline, labels, interval fields
  • fleet issuewatcher status — show watcher config and recent triggers
  • fleet issuewatcher events [--limit N] — list issue_new events as JSON
  • IssueWatcherEntry type in project config with comma-separated label parsing
  • Agent config entries now support vendor and model overrides in .fleet/config.yaml
  • 58 new tests (1,285 → 1,343 total)
IMPROVED
  • Agent sync upsert: only overwrites DB fields when config/prompt provides non-empty values
  • parseCommaSeparated() helper for comma-delimited config values
FIX
  • Brain socket data race: sync.WaitGroup guards in-flight connections before channel close
v1.5.3.02026-03-17
NEW
  • 467 new unit and integration tests (818 → 1,285 total)
  • Comprehensive pipeline integration tests: full lifecycle, timeout+reassignment, rejection+retry, cancel, onComplete callback
  • Exported NowFunc/SetNowFunc on pipeline engine for testable time injection
IMPROVED
  • CLAUDE.md: updated test count and MCP tool count to match reality (1,285 tests, 21 MCP tools)
v1.5.2.02026-03-17
NEW
  • Auto-reassignment on agent timeout: timeout_minutes field on pipeline stages triggers automatic reassignment when an agent doesn't signal completion in time
  • fleet pipeline stop-agents <run-id> CLI command to stop all agents from a completed pipeline run
  • LatestOpenStageHistory store method for timeout checking
  • SetOnComplete callback on pipeline engine for extensible completion handling
  • CollectStageAgents helper to extract deduplicated agent names from pipeline stages
  • Brain thoughts for timeout events (reassignment and max-retries-exceeded)
  • Brain thought on pipeline completion listing agents that may be stopped
  • pipeline_timeout and pipeline_agent_idle event types for audit trail
IMPROVED
  • Pipeline sweep now runs checkTimeouts() after processing active runs
  • Pipeline completion in advanceStage now notifies about idle agents and fires onComplete callback
v1.5.1.02026-03-17
NEW
  • 5 agent-facing MCP tools for self-aware agent operations:
  • fleet_agent_context — get agent's own config, pipeline assignment, and inbox
  • fleet_task_get — get task details by ID
  • fleet_task_list — list available tasks with optional status filter
  • fleet_task_update — update task status or assignee
  • fleet_pipeline_signal — signal pipeline stage completion (MCP equivalent of CLI command)
v1.5.0.02026-03-16
NEW
  • fleet pipeline signal --run <id> --agent <name> — reliable agent completion signaling (replaces broken fabric publish path)
  • fleet pipeline watch <id> — live terminal output showing stage progression
  • fleet agent budget — per-agent budget utilization display with --json support
  • fleet agent rollback <name> [--revision N] — rollback agent config to a previous revision
  • Cost tracking: total_run_seconds, total_runs, budget_seconds columns on agents table with auto-pause on budget exceeded
  • Config revisions: agent_config_revisions table with versioned JSON snapshots and rollback support
  • Environment variable injection: FLEET_AGENT_NAME, FLEET_PROJECT, FLEET_RUN_ID, FLEET_TASK_ID, FLEET_PIPELINE_STAGE, FLEET_SIGNAL_CMD set on tmux sessions
  • Pipeline duration summary logged on completion
  • Pipeline retry summary in fleet pipeline get output
  • internal/resolve package consolidating fuzzy matching for agents and pipelines (DRY)
  • internal/budget package for cost tracking and budget enforcement
IMPROVED
  • Prompt context injection replaced with environment variables (hard switch from BuildPromptWithContext prepending)
  • .fleet/prompts/*.md updated to reference $FLEET_SIGNAL_CMD for pipeline completion
  • openCLIEnv(true) now auto-syncs project config from .fleet/config.yaml and overlay prompts
  • pipelineCancel CLI routes through engine.CancelRun() for status validation
  • Fuzzy matching deduplicated: cli.go, cli_pipeline.go, and mcp/handlers.go now use resolve.Agent() and resolve.Pipeline()
  • Custom itoa in pipeline engine replaced with strconv.Itoa
FIX
  • Prompt sync from overlay files: agents no longer launch with empty vendor/prompt when .fleet/prompts/ files exist
  • Shell injection in env var export: single quotes properly escaped with shellEscape()
  • SQL column injection in config rollback: field names whitelisted before passing to UpdateAgent
v1.4.0.02026-03-15
NEW
  • MCP server: fleet mcp serve exposes 16 tools over JSON-RPC 2.0 stdio for Claude Code integration
  • fleet_pipeline_cancel MCP tool to cancel active or waiting_approval pipeline runs
  • fleet_pipeline_sweep MCP tool to trigger pipeline engine sweep on demand
  • Pipeline context injection: agents receive active pipeline task details in their prompts
  • fleet pipeline sweep CLI command for manual pipeline advancement
  • fleet version CLI command with --json flag for build information
  • .mcp.json project config for Claude Code auto-discovery
  • ActiveProject() public accessor on Service for project-scoped operations
IMPROVED
  • ListPipelineRuns now supports cross-project listing when project is empty (used by engine sweep)
  • fleet pipeline list/run commands are now project-aware
  • tmux binary resolved via exec.LookPath instead of hardcoded /usr/bin/tmux path
v1.3.0.02026-03-15
NEW
  • Fleet Pipelines: multi-agent workflow orchestration with configurable stages
  • Pipeline engine runs in Fabric sweep loop, auto-advances completed stages
  • Approval gates: stages with requires_approval pause for operator approval
  • Rejection routing: configurable on_reject targets with retry limits (max_retries)
  • Role-based agent assignment: stages can specify role instead of specific agent
  • Auto-start pipelines from Fabric task events via --pipeline flag
  • fleet pipeline run/list/get/approve/reject/cancel CLI commands with fuzzy matching
  • Pipelines TUI screen as Fabric sub-tab with list, detail, and approval UI
  • pipelines: section in .fleet/config.yaml with nested stage definitions
  • pipeline_definitions, pipeline_runs, pipeline_stage_history SQLite tables
  • ListAgentsByRole store method for role-based stage assignment
  • internal/pipeline package with engine and 17 unit tests
FIX
  • Events page column wrapping: dynamic widths and compact HH:MM:SS time display
v1.2.0.02026-03-14
NEW
  • Fuzzy agent name matching for all CLI commands (prefix/substring, case-insensitive)
  • fleet agent attach <name> to drop into an agent's live tmux session
  • fleet agent output <name> with log parser for structured run summaries (PRs, commits, duration)
  • fleet status --watch / -w for continuous 5-second refresh
  • Config-as-code: .fleet/config.yaml supports teams, workflows, alerts, and sla sections
  • SyncProjectConfig() reconciles all config sections with the database on startup (idempotent)
  • Template preview before apply in TUI with confirm step
  • FindTeamByName, FindWorkflowByName, FindAlertRule, FindSLAConfig store methods
IMPROVED
  • Key subsystems (fabric, brain, actions, UI) now use log/slog structured logging
  • Project-scoped team operations (assign/remove/list filtered by project)
FIX
  • Selected line text wrapping in TUI list views causing column misalignment
  • Alert and SLA sync deduplication to prevent duplicate records on repeated sync
v1.0.0.02026-03-14
NEW
  • Pure Go TUI for managing AI agent fleets (Bubble Tea + Lipgloss)
  • 15-screen TUI: Fleet, Teams, Templates, Events, Settings, Workflows, GitHub, Brain, Fabric, Evaluations, Risk, Alerts, Audit, Evolution, Control, SLA
  • SQLite-backed persistence with 15+ domain tables
  • Agent lifecycle management via tmux sessions
  • Brain daemon: event-driven evaluation, risk scoring, alerts, quarantine, evolution
  • Fabric coordination: task ownership, claims, handoffs, blockers, artifacts, inbox delivery with leasing
  • 136 ready-to-use agent prompt templates in catalog
  • Project-scoped fleet config via .fleet/config.yaml
  • File-based prompt management with overlay support
  • CLI subcommands: agent, team, template, event, config, workflow, brain, eval, fabric, init
  • fleet status command with color-coded health summary and --json flag
  • fleet doctor command for system prerequisite checks
  • Batch agent operations: fleet agent start/stop --all [--enabled] [--team <name>]
  • Post-launch health check: detects agent session death within 2 seconds of launch
  • store.DefaultDBPath() shared helper for DRY database path resolution
FIX
  • Silent error swallowing in fabric sweep, GitHub sync, ToggleTeam, and escalation
  • Brain dispatch goroutines now recover from panics instead of crashing silently
  • Fabric CLI socket response uses io.ReadAll instead of fixed 64KB buffer
REMOVED
  • All JavaScript/React/Node.js code (server.js, src/, package.json, etc.)