Notable changes to Blueprints are documented here. The project follows semantic versioning once release tags are created.
Interactive-blueprint-board milestone. This release replaces the changelog-like canvas with version frames, item lifecycle columns, focused dependency rendering, and direct signed relationship authoring.
- Plan view with movable, resizable, collapsible version frames and Planned, In Progress, Review, and Complete columns.
- Dependencies view with automatic node placement, selectable typed edges, directional arrowheads, hover/selection labels, and incoming/outgoing focus.
- Release Notes category projection plus an explicitly disabled Timeline mode pending a target-date contract.
- Compact toolbar with mode switching, search, local filters, focus, direct Connect mode, zoom-to-selection, clickable/collapsible minimap, and trust/sync/readiness status.
- Details, Relationships, Evidence, and History inspector tabs.
- Backward-compatible signed item lifecycle state, lifecycle validation, signed drag/keyboard transitions, and legacy Planned/Complete mapping.
- Projection and minimap services with lifecycle, filter, relationship, compatibility, and large-board tests.
- Light and dark canvas theme resources plus expanded accessible names, help text, focus, and shortcuts.
- Completed release builds identify themselves as
0.8.0. - Plan communicates ownership by containment and no longer draws a connector from every version to every owned item.
- Cards use readable multi-line titles and compact lifecycle, type, changelog, source, warning, and blocker metadata.
- Relationship creation starts from two visible canvas endpoints but requires review in the existing relationship editor before saving.
- View mode, search, filters, minimap visibility, viewport, zoom, and collapsed frames are retained as bounded machine-local preferences.
- Lifecycle changes use the existing trusted, conflict-free, immutable-aware signed item transaction and audit workflow.
- Direct connections reuse existing endpoint/type/self-link/duplicate/count validation and signed relationship persistence.
- Invalid or contradictory persisted lifecycle values make workspace loading fail closed as corrupt.
- No view mode, filter, focus, collapse, or viewport state enters signed project truth or collaboration exchange.
- Signed workspace schema remains version 1.
workflowStateis an optional item field. Missing incomplete items map to Planned; missing completed items map to Complete; opening does not rewrite them.- Existing signed layout and relationship documents remain compatible and retain whole-document conflict behavior.
- Timeline remains disabled because versions do not yet have an authoritative target-date field.
- Frame size is session-local; coordinates remain the only shared signed layout geometry.
- Dependency auto-layout is deterministic rather than a graph-optimization engine.
- Distribution remains deferred.
Repository-workflow and blueprint-clarity milestone. This release overhauls the planning canvas around automatic related-work lanes and turns local Git repositories into browsable, actionable project inputs without weakening signed Blueprints workspace boundaries.
- Automatic canvas grouping by changelog category, work type, or version, with named lanes, group counts, deterministic organization, and simpler card hierarchy.
- Visible 25%–250% zoom, pointer-centered
Ctrl/Command-wheel scaling, accurate fit-to-view behavior, a live percentage indicator, and retained machine-local viewport preferences. - Native local-repository folder selection and a focused repository workbench for choosing linked repositories.
- Explicit clone, fast-forward-only pull, commit-all, and push workflows with upstream ahead/behind status.
- End-to-end Git tests covering clone, commit, push, pull, hook suppression, dirty-pull refusal, and executable-filter refusal.
- Completed release builds identify themselves as
0.7.0. - Source discovery no longer stops at 100 Markdown proposals. A planning document can yield up to 5,000 proposals within an 8 MiB file bound, a repository can return 5,000 deduplicated proposals, and combined discovery remains bounded at 20,000.
- Approved source imports accept up to 5,000 reviewed proposals in one atomic signed workspace mutation.
- The canvas uses a lighter drafting surface, rounded cards, quieter connector lines, clearer plain-language controls, and progressive disclosure for manual repository-path management.
- Repository health now reports upstream tracking and ahead/behind counts.
- Git arguments use structured process arguments instead of shell interpolation, reject control characters and option-like repository addresses, and accept only HTTPS, SSH, Git protocol, SCP-style SSH, or existing absolute local sources.
- Clone does not initialize submodules; pull does not recurse into submodules and refuses dirty worktrees or non-fast-forward integration.
- Repository hooks are redirected to a fresh empty directory for every write operation, while commit and push also use their no-hook flags.
- Git write operations reject repository-local executable filters, merge drivers, and file-monitor commands. Operations time out after five minutes, disable terminal prompts, and cap captured output.
- Repository settings and Git operations remain machine-local and never enter signed Blueprints project truth or authorize hosted-provider writes.
- Signed workspace schema remains version 1.
- Grouping mode and zoom remain UI preferences; grouping changes only signed node positions when the user organizes the canvas.
- Existing linked repositories and canvas layouts remain compatible.
- Commit all intentionally stages every tracked, untracked, and deleted file in the selected repository; partial staging remains the job of a dedicated Git client.
- Git authentication relies on the user's existing credential helper or SSH agent and never prompts in an embedded terminal.
- Submodule initialization, history rewriting, force push, conflict merges, branch creation, tagging, and hosted-provider writes are intentionally unavailable.
- Distribution and installer work remains deferred.
Stable-foundations milestone. This release rebuilds the desktop experience for first-time users while adding atomic local mutation, migration, identity-recovery, provider-contract, accessibility, and security-policy foundations for v1.0.
- A completely rebuilt beginner-first desktop shell with task-based setup, plain-language navigation, modern visual hierarchy, and focused new/open/join project paths.
- Encrypted signing-identity backup and clean-profile restore using AES-256-GCM, PBKDF2-SHA256 with 600,000 iterations, authenticated identity metadata, private/public-key verification, bounded input, and destination-device key rewrapping.
- Atomic local workspace transactions that stage complete signed mutations with their audit append, promote the staged directory, and restore the prior workspace when any promotion checkpoint fails.
- A workspace schema inspector and ordered migration engine with future-schema rejection, pre-migration ZIP backup, transactional application, and failed-migration rollback.
- A versioned hosted-provider extension contract with declared capabilities, compatibility checks, and bounded result limits for built-in and future readers.
- An attacker-focused threat model plus a planned stable platform, supported-version, release-qualification, and vulnerability-response policy.
- Completed release builds identify themselves as
0.6.0. - Primary navigation now uses familiar outcomes—Home, Plan releases, Find work, People, Share changes, and Safety check—instead of implementation terminology.
- The canvas retains the blueprint concept while the surrounding application uses a calmer neutral-and-violet product system, clearer primary actions, larger targets, and simpler guidance.
- Project creation now commits the project, local trust anchors, and initial audit entry as one recoverable transaction.
- Canvas and relationship mutations now commit signed data and audit evidence through the same transaction boundary.
- Draft item and version archives now create their recovery copy, remove active files, update signed state, and append audit evidence inside one transaction; interruption publishes neither the removal nor a partial archive.
- Source-provider routing now validates contract versions, provider capabilities, duplicate registrations, and bounded response counts before accepting extension output.
- Main destinations now expose explicit accessibility names and
Ctrl/Commandplus number shortcuts; icon-only canvas actions expose readable names and tooltips.
- Transaction recovery accepts only deterministic sibling staging and backup paths and rejects a marker that attempts to redirect recovery or cleanup.
- Identity recovery rejects wrong passphrases, changed authenticated metadata, malformed encryption parameters, mismatched private keys, oversized files, and duplicate local identities.
- Workspace transactions refuse symbolic-link entries instead of copying through them.
- Signed workspace schema remains version 1.
- Current schema-1 workspaces open without rewriting.
- Future schemas fail with an explicit upgrade requirement; future migrations must advance one schema at a time, verify their produced version, retain a complete pre-migration backup, and pass through atomic promotion.
- Distribution and installer work remains intentionally deferred.
- Automated same-user key rotation, time-qualified revocation, and hardware-backed key support remain future security work.
- Platform qualification still requires retained manual install, accessibility, upgrade, and recovery results on the final supported operating-system matrix.
VaultSync recovery integration milestone. This release adds passive backup-health awareness, explicit project-specific exchange registration, advisory release-safety evidence, and a tested restore path while preserving Blueprints as the authority for signed release state.
- Passive VaultSync health awareness with a machine-local metadata-root setting, bounded path detection, and clear healthy, warning, unavailable, and invalid states in the Integrations workspace.
- A versioned
blueprints.status.jsoninteroperability contract for destination reachability, snapshot, backup, verification, restore-readiness, index-consistency, and metadata-conflict evidence. - An injectable VaultSync status-reader boundary and filesystem tests covering supported root forms, absent sidecars, malformed schemas, and oversized input.
- Explicit two-step registration for project-specific VaultSync exchange roots, backed by a fresh exact-target approval, an atomic bounded marker, canonical path containment, and refusal to adopt unexpected content.
- Advisory release-readiness diagnostics for missing, risky, incomplete, stale, future-dated, or recent healthy VaultSync recovery evidence.
- An end-to-end VaultSync recovery drill that independently relocates local and exchange backups, revalidates signed project trust and manifest continuity, and publishes a new signed change after restore.
- Completed release builds identify themselves as
0.5.0. - The VaultSync exchange-root contract now reserves
<destination>/.blueprints/projects/<project-id>/for an explicitly enabled future adapter while keeping the VaultSync project payload separate. - Machine-local integration settings now recover safely from malformed or oversized JSON and use atomic replacement on save.
- Registered VaultSync exchange roots remain separate from the active shared root until the project is deliberately reopened against the prepared location.
- Changing or clearing the linked VaultSync metadata root also clears any stale registered exchange-root reference.
- VaultSync release evidence is considered recent within seven days and allows five minutes of producer clock skew; it informs release review without silently blocking the release action.
- Blueprints never parses the VaultSync SQLite database, caps passive health documents at 1 MiB and 32 warnings, and keeps configured paths and all health evidence outside signed project truth.
- VaultSync exchange registration approvals expire within ten minutes and are single-use; registration rejects mismatched projects, non-canonical layouts, internal directory links, oversized markers, and pre-existing unregistered content.
- Signed workspace schema remains version 1.
- VaultSync paths, structured health evidence, and the registered exchange-root link are machine-local integration settings and never enter signed project documents.
- A VaultSync-prepared shared root adds only the bounded
.blueprints-exchange.jsonregistration marker, which is excluded from signed exchange snapshots. - Projects remain fully usable without VaultSync and can continue using any supported plain shared-folder target.
- This release contains no installers or application binaries.
- Detailed health requires an external producer to write the documented schema-1
blueprints.status.jsonsidecar; Blueprints does not parse VaultSync SQLite or invoke a VaultSync CLI. - Exchange registration prepares and remembers the canonical root but deliberately requires the project to be reopened before that location becomes active.
- Release-safety evidence is advisory and reports producer claims; Blueprints does not independently verify backup payloads or perform VaultSync restore operations.
Provider-neutral source-control awareness milestone. This release connects the signed release plan to local Git, GitHub, and GitLab evidence while keeping discovery read-only, credentials local, and every imported proposal subject to explicit review.
- Canvas box selection, additive multi-selection, grouped node dragging,
Ctrl+A,Escape, precise arrow-key movement, live alignment guides, and a viewport minimap. - Release-readiness diagnostics that surface unavailable or dirty repositories, incomplete items, missing post-tag history, and recent commits that do not map to completed items in the selected version.
- Machine-local links for up to eight Git worktrees, with combined read-only health, source discovery, source trace, and release-readiness analysis.
- A provider-neutral reference contract for planning documents, commits, issues, pull requests, releases, and project records across local Git, GitHub, and GitLab.
- Bounded read-only discovery for up to 100 GitHub pull requests and 50 GitHub release records per linked repository, including merge/publication state and provider-neutral provenance.
- Repository-linked GitHub Project discovery for standalone draft items through a bounded read-only GraphQL query covering at most 10 projects, 100 items per project, and 100 returned drafts.
- An injectable provider-neutral hosted-source reader boundary, keeping repository discovery and approval workflows independent from the current authenticated GitHub CLI implementation.
- User-defined directional or undirected relationship types with validated colors and optional descriptions, plus signed relationships between project, version, and work-item nodes.
- Relationship authoring and removal in the canvas inspector, colored relationship projection on the canvas, archive cleanup, audit operations, and document-aware conflict summaries.
- Direct bounded GitHub REST and GraphQL discovery for issues, pull requests, releases, project-linked issues, and standalone Project drafts, including anonymous public-repository reads.
- A provider-operation policy that allows reads directly but requires a fresh, exact-target, single-use approval before any future hosted-provider write.
- GitLab.com remote detection and bounded parallel discovery for issues, merge requests, releases, and milestones, with anonymous public reads and environment-only private-project credentials.
- Completed release builds now identify themselves as
0.4.0. - Canvas guidance now exposes the active selection and the available multi-node keyboard controls; resulting layout changes keep using signed, audited persistence.
- The release planner now presents source-control blockers and follow-up guidance next to source trace and changelog review.
- Source Lens accepts one repository path per line and preserves the full repository-qualified provenance of combined proposals.
- Source Lens proposals now expose structured provider, repository, artifact kind, identifier, and optional web location instead of relying only on GitHub-specific display strings.
- Combined Source Lens summaries now separate issue, pull-request, release, and project-linked proposal counts.
- Schema-1 workspaces may contain an optional signed
project/relationships.json; missing files remain compatible with earlier workspaces and the complete relationship graph is one revisioned conflict domain. - Source Lens no longer requires the GitHub CLI. Private repository and GitHub Project discovery uses the environment-only
BLUEPRINTS_GITHUB_TOKEN; Blueprints does not persist the credential. - Hosted source kinds and counts are provider-neutral, so GitHub pull requests and GitLab merge requests share the same change-request workflow without provider-specific signed data.
- Hosted API responses are fetched in parallel with per-request timeouts, 4 MiB response limits, provider-specific count limits, repository-identity validation, and credential-free error messages.
- GitHub and GitLab credentials are accepted only from process environment variables and never enter signed project truth, integration settings, proposal provenance, or warnings.
- Future provider writes require a fresh approval matching the exact provider, repository, operation, and target; approval expires within ten minutes and is consumed once.
- Signed workspace schema remains version 1.
project/relationships.jsonand its signature are optional schema-1 documents. Older projects remain readable until the first relationship type is saved.- Provider references and credentials remain application-layer and machine-local data; no hosted provider is required to open, edit, sign, or exchange a project.
- This release contains no installers or application binaries.
- Hosted-provider integrations are discovery-only; no issue, project, merge-request, pull-request, or release writes are implemented.
- GitLab hosted discovery currently recognizes
gitlab.comorigins, not arbitrary self-managed GitLab hosts. - Provider credentials use process environment variables rather than an OAuth/device flow or operating-system credential UI.
- Directional relationship types do not yet render arrowheads, and relationship conflicts resolve as a whole document.
Understandable collaboration milestone. This release lets distinct local identities join a signed project, exchange changes through an untrusted shared directory, understand conflicts, and recover from blocked or mistaken operations.
- Session-scoped undo and redo for node drags and auto-arrangement, with toolbar controls and
Ctrl+Z,Ctrl+Shift+Z, andCtrl+Yshortcuts. - Every applied undo or redo is saved as a new signed, audited canvas-layout revision so history never bypasses workspace integrity.
- A two-workspace collaboration harness covering push, pull, sequential edits, overlapping edits, and preservation of the blocked local copy.
- Automatic machine-local conflict recovery snapshots containing both available document/signature pairs and resolution metadata before a whole-document choice is applied.
- Signed identity-request and project-invitation files with proof-of-key-possession validation.
- Member-key-aware workspace, manifest, incoming-document, and audit validation for distinct local identities.
- A staged join flow that validates invitation targets, trust anchors, membership, signatures, manifest continuity, and audit history before creating the final local workspace.
- Document-aware conflict comparisons for project configuration, membership, versions, items, and audit entries, with bounded raw evidence retained for diagnosis.
- Explicit member-key rotation, compromise, and lost-key operating rules.
- Backup, shared-exchange restoration, conflict reversal, identity recovery, and recovery-drill procedures.
- Explicit first-run identity creation and pre-project signed identity-invitation export.
- Two-step recoverable archive flows for draft versions and items, including layout cleanup and signed audit records.
- Changelog preview without file output plus incomplete-item, item-key, description, and compact export controls.
- End-to-end view-model command coverage for identity setup, project creation, version editing, freezing, releasing, previewing, and exporting.
- Category-grouped release items and actionable empty states for projects without versions or connected accomplishments.
- Alpha 3 development builds now identify themselves as
0.3.0-alpha.3-dev. - Conflict resolution reports the recovery-copy location and writes its status metadata atomically.
- The exchange view now shows the last pulled and pushed manifest versions and the last successful trust-validation time persisted for the local workspace.
- Team setup now uses native invitation-file import/export instead of identity-bundle copy and paste.
- The exchange workspace now surfaces current shared manifest evidence, local push/pull versions, audit-chain status, and state-specific recovery guidance.
- Canvas nodes can no longer be dragged when workspace trust or sync-conflict state forbids mutation.
- Clean test builds now reference the command toolkit explicitly instead of relying on a transitive compile asset.
- Conflict recovery rejects paths that escape the expected workspace root.
- Project invitations targeting another local identity are rejected before a workspace is created.
- Tampered identity invitation fields are rejected when their proof no longer verifies.
- Signed manifest rollback and same-version unknown-batch replay are rejected.
- Item deletions propagate with local recovery copies and deletion markers while required project-document deletion remains blocked.
- Workspace exchange paths are contained beneath their expected roots.
- Pull stages and revalidates a complete inbox before local mutation, records rollback pairs, and restores them if application or sync-state persistence fails.
- Viewer and inactive-member keys are excluded from current workspace and incoming-change authority while remaining available for historical audit verification.
- Multi-member signatures resolve by key ID against machine-local project trust anchors established by project creation or a targeted signed invitation.
- Identity invitations prove possession of the included private key; project invitations bind the target identity, inviter administrator, project, membership revision, exchange location hint, and trusted member keys.
- Shared manifests reject invalid signatures, rollback, unknown same-version batches, content/hash discontinuity, missing required documents, and malformed document/signature pairs.
- Pull validates shared content, stages it locally, revalidates the staged bytes, and retains rollback copies before changing trusted local state.
- Deactivated and Viewer identities cannot mutate or publish current project content.
- Signed project schema remains version 1.
ProjectMember.keyIdis an optional schema-1 field. Existing workspaces derive the legacy key ID from the member user ID.- Project trust anchors, archives, conflict recovery, canvas viewport state, and sync staging remain machine-local and are excluded from signed exchange snapshots.
- Existing single-identity projects remain readable and gain a local trust-anchor file after successful validation.
- This release contains no installers or application binaries.
- Conflict resolution compares known fields but still applies a whole-document choice rather than a field merge.
- Same-user automated key rotation, hardware-backed keys, and revocation timestamps are not implemented.
- Shared-folder confidentiality and availability remain responsibilities of the underlying storage.
- Advanced canvas multi-selection, alignment tools, minimap navigation, and user-defined relationship types are deferred.
- GitHub Project discovery does not include standalone draft items, and provider integrations remain read-only.
Interactive workspace milestone. This prerelease makes Blueprints usable as a hands-on visual release planner and establishes the approval-first source-discovery workflow.
- Canonical public documentation for users, contributors, architecture, workspace format, security, and releases.
- A milestone-based product roadmap.
- Blueprints visual identity and application icon.
- Cross-platform CI, CodeQL, dependency review, milestone automation, PR labels, and community templates.
- Lightweight milestone-release records generated from the changelog without binary builds.
- A diagram-first blueprint canvas with draggable version and work-item nodes, live relationship connectors, zoom controls, and direct node inspection.
- Signed, revisioned node-position persistence with entity validation, audit entries, sync support, auto arrangement, and explicit save controls.
- Machine-local canvas zoom and viewport persistence that cannot create audit noise or collaboration conflicts.
- Canvas-engine and troubleshooting documentation covering behavior, format, security, compatibility, conflicts, and recovery.
- Native folder pickers for project creation and opening.
- Source Lens discovery for changelogs, roadmaps, GitHub issues, and issue-linked GitHub Projects.
- Editable proposal review with duplicate warnings, provenance, confidence, target-version selection, and explicit batch approval.
- Adaptive next-action guidance based on workspace trust, conflicts, release state, source proposals, and sync status.
- A disabled-by-default SonarQube Cloud workflow template for .NET analysis and Coverlet coverage. It requires explicit repository activation and credentials.
- Upgraded the application to .NET 10 LTS, Avalonia 12.1.1, and the latest stable direct dependencies.
- Replaced the dashboard-style overview and wide navigation sidebar with a hands-on canvas, contextual inspector, compact tool rail, and focused secondary workspaces.
- Reworked secondary navigation into a readable workflow rail and promoted source discovery from passive status cards to an approval-first workspace.
- Made command feedback visible across the active workspace.
- Clarified local-workspace and shared-exchange terminology.
- Moved superseded planning and handoff documents into
docs/archive.
- Repository-local SDK selection now works when only a newer compatible SDK is installed.
- Shell helpers are executable.
- Source discovery no longer parses the same planning file twice on case-insensitive filesystems.
- Shared canvas positions are signed, bounded, entity-validated, audited, and synchronized.
- Source discovery remains read-only and bounded; imports require explicit human approval and trusted mutable targets.
- CodeQL, dependency review, package vulnerability checks, and cross-platform tests remain required repository gates.
- This release does not include installers or application binaries.
- Identity onboarding, undo/redo, deletion/archive, guided recovery, and polished two-user collaboration remain incomplete.
- GitHub Project discovery currently includes project-linked issues, not standalone draft items.
- SonarQube Cloud is scaffolded but does not run until the project is imported and repository credentials are configured.
Foundation milestone:
- established project, version, item, member, and changelog domain contracts;
- added canonical JSON persistence and detached Ed25519 signatures;
- protected local signing keys and validated signed workspaces on load;
- created the initial shared-folder sync, conflict, and audit-chain foundation;
- added repository automation and the first executable Avalonia application scaffold.