Files
probo/cmd/probod/CHANGELOG.md
Bryan Frimin f0b9acb748 Release probod/v0.196.1
Signed-off-by: Bryan Frimin <bryan@probo.com>
2026-05-27 19:27:13 -07:00

18 KiB

Changelog

All notable changes to probod (the server, including the bundled @probo/console, @probo/trust, and @probo/ui frontends) will be documented in this file.

Unreleased

[0.196.1] - 2026-05-27

Fixed

  • Fix serialization of SCIM bridge SYNCING and DISABLED states in the GraphQL API

[0.196.0] - 2026-05-27

Added

  • Expose bridge sync errors in the SCIM API and on Google Workspace and Microsoft 365 connector cards
  • Expose profile source field on users in the MCP API

[0.195.0] - 2026-05-27

Added

  • Add archiveUser operation to deactivate a user profile while keeping them in the organization; exposed across the console UI, MCP, CLI, and n8n
  • Expire pending invitations for a user when they are archived
  • Grant owners full iam:scim-bridge:* and admins read-only SCIM bridge access in IAM policies

Fixed

  • Preserve archived and deactivated HubSpot users in access reviews instead of dropping them
  • Fix common third-party logo URL returning resource-not-found in the combo box query

[0.194.0] - 2026-05-26

Added

  • Add probo-agent CLI and device agent library for endpoint compliance checks
  • Add screen lock detection support for i3, KDE, and more Linux desktop environments

Fixed

  • Skip unconnectable providers in provider listing
  • Reject shell-unsafe paths in FreeBSD rc.d service installer
  • Make Windows service uninstall idempotent
  • Use platform-specific atomic key replacement on Windows
  • Handle FreeBSD check command failures before reading status

[0.193.1] - 2026-05-26

Security

  • Fix open redirect bypass in safe redirect

[0.193.0] - 2026-05-26

Added

  • Add measure ↔ third-party many-to-many link with tabs on both detail pages
  • Add self-referential third-party relations with a first_level filter on the third-party list
  • Track source on detected storage trackers (localStorage, sessionStorage, indexedDB, cacheStorage)
  • Promote tracker pattern source on detection and trigger a draft banner version when adopting uncategorised patterns

Changed

  • Allow initial minor publishing of documents
  • Mark page-world extension writes (MV3 main world, userscripts with @grant none) with the new EXTENSION cookie source
  • Surface the measure state as a header badge and remove the measure detail right-hand drawer

Fixed

  • Fix timing attack on signin
  • Reject separator-only glob templates (e.g. __*) in tracker pattern analysis

[0.192.0] - 2026-05-25

Changed

  • Enforce IAM authorization on all console resolvers — every data-bearing field now goes through the policy engine and produces an audit log entry; adds ActionCommonThirdPartyGet, ActionCommonThirdPartyList, and ActionElectronicSignatureGet actions wired into Viewer and Auditor policies

Fixed

  • Fix signature count mismatch between the document version badge and the signatures tab — both now filter by activeContract: true and state: ACTIVE, so deactivated signers and ended-contract signers are consistently excluded
  • Fix MCP server resolvers after the signature filter and authorization changes

[0.191.0] - 2026-05-22

Added

  • Add a tracker pattern detail page in the console with a properties section and a list of detected tracker resources

Fixed

  • Strip empty ProseMirror text nodes from third-party list documents (and migrate existing document_versions.content to drop them) so Tiptap renders them instead of erroring with "Empty text nodes are not allowed"
  • Tailor signature certificate email copy for document approvals — store the per-signature email subject on creation so the certificate worker uses "Your approved