Files
probo/cmd/probod/CHANGELOG.md
Bryan Frimin 4790f83360 Release probod/v0.199.1
Signed-off-by: Bryan Frimin <bryan@probo.com>
2026-05-28 20:26:05 -07:00

20 KiB

Changelog

All notable changes to probod (the server, including the bundled @probo/console, @probo/trust, and @probo/ui frontends) will be documented in this file.

Unreleased

[0.199.1] - 2026-05-28

Fixed

  • Fix missing icons in the UI
  • Fix Metabase user listing in access reviews
  • Fix PostHog resolver name

[0.199.0] - 2026-05-28

Added

  • Add PostHog access-review connector
  • Add Metabase access-review connector
  • Add Grafana access-review connector
  • Add Cursor access-review connector
  • Support HTTP Basic auth in API-key connections
  • Cancel pending signature requests when a contract ends or a connector is deactivated

Changed

  • Reject demotion of the last owner of an organization
  • Scope document signatures to the major version

Fixed

  • Fix Microsoft 365 access review returning too many accounts

[0.198.0] - 2026-05-28

Added

  • Add Tailscale connector
  • Add Anthropic connector (authenticated via API key)
  • Add personal account support for the Heroku connector
  • Add Global region option to the vendor country picker
  • Allow ordering organization members by email address

Changed

  • Connector deletion is now best-effort: remaining steps proceed even when one cleanup step fails

Fixed

  • Fix role column in the people list rendered as non-sortable to prevent runtime failures
  • Surface an actionable error when a stored Sentry organization slug is no longer accessible to the connected OAuth token
  • Stop the source-name worker from retrying indefinitely on a stale Sentry organization slug
  • Stop the source-name worker from retrying indefinitely on a stale Heroku personal-account slug

[0.197.0] - 2026-05-28

Added

  • Add invitingOrganizations field on the viewer to expose organizations that have sent a pending invitation to the current user

Fixed

  • Show SCIM error message in the connector UI

[0.196.1] - 2026-05-27

Fixed

  • Fix serialization of SCIM bridge SYNCING and DISABLED states in the GraphQL API

[0.196.0] - 2026-05-27

Added

  • Expose bridge sync errors in the SCIM API and on Google Workspace and Microsoft 365 connector cards
  • Expose profile source field on users in the MCP API

[0.195.0] - 2026-05-27

Added

  • Add archiveUser operation to deactivate a user profile while keeping them in the organization; exposed across the console UI, MCP, CLI, and n8n
  • Expire pending invitations for a user when they are archived
  • Grant owners full iam:scim-bridge:* and admins read-only SCIM bridge access in IAM policies

Fixed

  • Preserve archived and deactivated HubSpot users in access reviews instead of dropping them
  • Fix common third-party logo URL returning resource-not-found in the combo box query

[0.194.0] - 2026-05-26

Added

  • Add probo-agent CLI and device agent library for endpoint compliance checks
  • Add screen lock detection support for i3, KDE, and more Linux desktop environments

Fixed

  • Skip unconnectable providers in provider listing
  • Reject shell-unsafe paths in FreeBSD rc.d service installer
  • Make Windows service uninstall idempotent
  • Use platform-specific atomic key replacement on Windows
  • Handle FreeBSD check command failures before reading status

[0.193.1] - 2026-05-26

Security

  • Fix open redirect bypass in safe redirect

[0.193.0] - 2026-05-26

Added

  • Add measure ↔ third-party many-to-many link with tabs on both detail pages
  • Add self-referential third-party relations with a first_level filter on the third-party list
  • Track source on detected storage trackers (localStorage, sessionStorage, indexedDB, cacheStorage)
  • Promote tracker pattern source on detection and trigger a draft banner version when adopting uncategorised patterns

Changed

  • Allow initial minor publishing of documents
  • Mark page-world extension writes (MV3 main world, userscripts with @grant none) with the new EXTENSION cookie source
  • Surface the measure state as a header badge and remove the measure detail right-hand drawer

Fixed

  • Fix timing attack on signin
  • Reject separator-only glob templates (e.g. __*) in tracker pattern analysis

[0.192.0] - 2026-05-25

Changed

  • Enforce IAM authorization on all console resolvers — every data-bearing field now goes through the policy engine and produces an audit log entry; adds ActionCommonThirdPartyGet, ActionCommonThirdPartyList, and ActionElectronicSignatureGet actions wired into Viewer and Auditor policies

Fixed

  • Fix signature count mismatch between the document version badge and the signatures tab — both now filter by activeContract: true and state: ACTIVE, so deactivated signers and ended-contract signers are consistently excluded
  • Fix MCP server resolvers after the signature filter and authorization changes

[0.191.0] - 2026-05-22

Added

  • Add a tracker pattern detail page in the console with a properties section and a list of detected tracker resources

Fixed

  • Strip empty ProseMirror text nodes from third-party list documents (and migrate existing document_versions.content to drop them) so Tiptap renders them instead of erroring with "Empty text nodes are not allowed"
  • Tailor signature certificate email copy for document approvals — store the per-signature email subject on creation so the certificate worker uses "Your approved