What shipped on OpenVibe.VIP

Every change deployed to OpenVibe, newest first. Each line is a commit from the OpenVibers repositories, linked to the change itself. When enough have gathered, or a large feature lands, they are written up as Patch notes on openvibe.blog. JSON: /api/v1/changelog.

2026-09-24

dcb7546The shared update system and one account UI, on the OpenVibe Frame (openvibe-shared 1.11.0, openvibe/frame): the home shows what shipped, /updates is the shared log and the footer links it; the shared navbar handles sign in and out…OpenVibers · 07:55 UTC
ee7abc6CI calls the shared test workflow (Track Q): OpenVibe.Shared .github/workflows/test.yml@f5e7e73 (install, node --check over server/ and scripts/, npm test, openvibe-contracts-check) instead of a copy of those stepsOpenVibers · 07:55 UTC
aa2fba9STATUS.json describes production: the running release and pins, what is deployed, the Live import that has run, and what is still owner-blockedOpenVibers · 07:55 UTC
a0a8f75SECURITY.md: how to report a vulnerability ([email protected], 7-day reply, scope, supported versions)OpenVibers · 07:55 UTC

2026-09-23

a675577openvibe-shared v1.5.1, openvibe-contracts v0.33.0OpenVibers · 23:18 UTC
f6b98fcopenvibe-shared v1.5.0 (Track R release manifest), openvibe-contracts v0.32.0, openvibe-sdk v0.5.0OpenVibers · 22:17 UTC
fe7eaadMembership card, badge and widget endpoints (roadmap §11.3): public data only, no cookies, safe to embedOpenVibers · 20:50 UTC
9668a49CI: run the shared security workflow (gitleaks secret scan + dependency audit, Track Q)OpenVibers · 19:33 UTC
2accbebConsumers can gate on VIP: the product's default gate, product perks and a shared product cache with a tested convergence boundOpenVibers · 19:31 UTC
f7e2ef4Docs: STATUS.json and README match production (2026-09-23)OpenVibers · 18:33 UTC
dc98781Events webhook requires signature v2 (replay window); openvibe-sdk v0.4.0OpenVibers · 17:03 UTC
797b899Gated-resource rules are per creator and the product names the owner: POST /policies/evaluate takes owner and applies only that creator's rule (none → owner_required, a pinned rule of another creator → owner_mismatch); a creator who claims…OpenVibers · 16:33 UTC
968580cnginx: client address headers only from $remote_addr (realip). X-Forwarded-For was appended to and CF-Connecting-IP passed through from the client, so a request reaching the origin without Cloudflare (DNS-only host or the bare IP) chose…OpenVibers · 16:14 UTC
07ba885Security: checkout return URLs stay on this site; page notices are signedOpenVibers · 15:52 UTC
9e1c219openvibe-contracts v0.19.0 (this service's manifest and capabilities are released); contracts check is blockingOpenVibers · 02:47 UTC
a2c630dCheckout stays closed while VIP_CHECKOUT_PROVIDERS is empty (the setting until Billing's cutover): plan pages say so, the API refuses; README: before and after the Billing cutoverOpenVibers · 02:45 UTC
29046a1OpenVibe.VIP W10: plans with immutable versioned terms, perks and product bindings, Billing entitlement projection (events + inbox, valid_until, authoritative fallback), checkout and cancel through Billing, gated-resource policy that fails…OpenVibers · 02:44 UTC

2026-09-21

3ce54ffCharter: OpenVibe.VIP as defined in the OpenVibe realignment plan (placeholder, no code yet)OpenVibers · 16:19 UTC