What shipped on OpenVibe.Reviews

Every change deployed to OpenVibe, newest first. Each line is a commit from the OpenVibers repositories, linked to the change itself. When enough have gathered, or a large feature lands, they are written up as Patch notes on openvibe.blog. JSON: /api/v1/changelog.

2026-09-24

54c4d71The shared update system and one account UI, on the OpenVibe Frame (openvibe-shared 1.11.0, openvibe/frame): the home shows what shipped, /updates is the shared log and the footer links it; the shared navbar handles sign in and out…OpenVibers · 07:55 UTC
f68bb8fOne W3C trace across services (Track O): openvibe-shared v1.7.0 trace.install(app) keeps each request's traceparent and puts it on the calls made while serving it, to loopback and OpenVibe hosts onlyOpenVibers · 06:16 UTC
ecc4406CI calls the shared test workflow (Track Q): OpenVibe.Shared .github/workflows/test.yml@f5e7e73 (install, node --check over server/ and scripts/, npm test, openvibe-contracts-check) instead of a copy of those stepsOpenVibers · 06:16 UTC
70de372openvibe-publishing v0.2.2 (shares the openvibe-shared v1.5.1 copy instead of installing v1.0.0 alongside)OpenVibers · 06:16 UTC
08add50SECURITY.md: how to report a vulnerability ([email protected], 7-day reply, scope, supported versions)OpenVibers · 06:16 UTC

2026-09-23

8905235openvibe-shared v1.5.1, openvibe-contracts v0.33.0OpenVibers · 23:15 UTC
2411fe1openvibe-shared v1.5.0 (Track R release manifest), openvibe-contracts v0.32.0, openvibe-sdk v0.5.0OpenVibers · 22:25 UTC
a7b50a6CI: run the shared security workflow (gitleaks secret scan + dependency audit, Track Q)OpenVibers · 19:33 UTC
1d462a2Threat review: docs/threat-review.mdOpenVibers · 19:09 UTC
223262aThreat review fixes: cross-site writes, correction queue limits, bounded audit text, editor idsOpenVibers · 19:04 UTC
91e613dA correction yields a public summary revisionOpenVibers · 19:00 UTC
6ad2403Docs: STATUS.json and README match production (2026-09-23)OpenVibers · 18:32 UTC
3151c05Events webhook requires signature v2 (replay window); openvibe-sdk v0.4.0OpenVibers · 17:02 UTC
ffcad93App and module tokens act only for their on_behalf_of person; sandbox tokens refusedOpenVibers · 16:35 UTC
9e3fd92A source item taken down at its source is 410 through /api/v1/items/:idOpenVibers · 16:34 UTC
0923bf3nginx: client address headers only from $remote_addr (realip). X-Forwarded-For was appended to and CF-Connecting-IP passed through from the client, so a request reaching the origin without Cloudflare (DNS-only host or the bare IP) chose…OpenVibers · 16:14 UTC
6659c4dopenvibe-publishing v0.2.1 (ReDoS fixes in ssr markdown)OpenVibers · 16:07 UTC
569986bSummary history hides unreviewed AI drafts, unpublished summaries and deleted entities from readersOpenVibers · 15:52 UTC
5c373b9openvibe-contracts v0.20.0 (reviews manifest and capabilities released); contracts check is blockingOpenVibers · 03:21 UTC
a0033beOpenVibe.Reviews service (Wave 17, Reviews half): entities with aliases and typed links, deterministic resolution of OpenVibe.Sources review items with editor confirmation, signals with provenance, merges that rewrite nothing and splits…OpenVibers · 03:19 UTC

2026-09-21

23e7ab2Charter: OpenVibe.Reviews as defined in the OpenVibe realignment plan (placeholder, no code yet)OpenVibers · 16:19 UTC