Changelog
Every change that mattered, by build.
Generated from the findings register, so this page cannot say something the register does not. Fixes and residuals both appear; a changelog that lists only the good news is a press release.
Build v2.215 entries
- LA-1 fixedExpanded IPv6 bypassed the destination classification
- LA-2 fixedAction plans could be mutated after confirmation
- LA-3 fixedAn escrow replay could disclose another caller’s record
- LA-4 fixedThe enquiry endpoint claimed delivery without a transport
- LA-5 fixedThe reproduction checker still wrote the second publication
- LA-6 fixedAnonymous intake accepted unbounded bodies
- GT-1 openThe commercial funnel went to an in-memory Map on a serverless function
- GT-2 fixedThe conformance matrix showed three payment rails that do not exist passing 214 of 214
- GT-3 fixedPricing disagreed with itself across three pages
- GT-4 openNo terms, no privacy notice, no contact, no status, no security page
- GT-5 openThe evidence framed a homepage measurement as a verdict on companies
- SR-1 fixedThe local runner executed the extractor inside the page it was measuring
- SR-2 fixedIdempotency keys were global across tenants
- SR-3 fixedThe allowance was charged before the abuse gate, so a refused request cost a customer money
- GT-6 fixedCustoms-tariff news was still being counted as a price quote, in our favour
Build v2.14 entries
- VF-1 fixedA refused request spent the global budget, so one address could take the deployment offline
- VF-2 fixedThe reproducibility check repaired the file it was checking
- VF-3 fixedA hostile page could crash the reader, and an ordinary label could break the planner
- VF-4 fixedThe cost receipt was a constant on the endpoint that exists to publish cost receipts
Build v2.08 entries
- DM-1 fixedThe generation epoch was the string g1, so the safety rule it exists for could never fire
- DM-2 fixedThe product shipped the intent matcher we had published a retraction for
- DM-3 fixedHonest access reporting existed in the sweep and nowhere in the product
- DM-4 fixedWe accepted cookie banners on 34 companies’ sites for a benefit we had never measured
- DM-5 openRule two had no if statement behind it anywhere
- DM-6 fixedThe accessible-name computation made the act layer fail on ordinary forms
- DM-7 fixedThe rate limit was on the wrong unit, and discovery was a tenfold amplifier
- DM-8 openFour promises on the operator page had no mechanism behind them
Build v1.96 entries
- CF-1 fixedThe freight calculator painted a five-million-dollar loss green and called it a saving
- CF-2 openA savings calculator that left out our own invoice
- CF-3 fixedThe calculator assumed every task migrates; our own evidence says half do
- CF-4 fixedWe published a sensitivity table the calculator could not compute
- CF-5 fixedThe tagging mechanism this file calls load-bearing was dead code
- CF-6 fixedThree headline tiles asserted numbers nothing in the repository supported
Build v1.81 entries
- RW-13 openA locator that never acts is a search engine with extra steps
Build v1.74 entries
- RW-9 fixedAnchoring the matcher was necessary and nowhere near sufficient
- RW-10 fixedOur headline number was an assumption wearing a measurement’s clothes
- RW-11 fixedYou could check our arithmetic but not our judgement
- RW-12 fixedThree sentences on the evidence page claimed more than the data licensed
Build v1.64 entries
- RW-5 fixedOur intent matcher counted "Facebook" as a booking link
- RW-6 fixedThe analysis script silently ate its own output
- RW-7 fixedThere was no wall of closed doors — we were knocking from the wrong place
- RW-8 fixedWe published corrected figures on top of the artefacts that produced the wrong ones
Build v1.54 entries
- RW-1 fixedThe real web does not multiply our advantage the way we assumed
- RW-2 fixedWe blamed the industry for a barrier we had largely created ourselves
- RW-3 fixedOur first sweep measured a quantity no competent agent cares about
- RW-4 fixedThe second sweep fetched a page that robots.txt told it not to
Build v1.46 entries
- ER-1 fixedSpot-indexed settlement was manipulable by the price feed
- ER-2 openDemand-response baselines cannot be made ungameable
- D2-1 fixedTraining on agent traces would have leaked one customer into another
- D2-2 fixedRecycling failed runs would have taught the next model to fail
- O1-1 fixedTwo dispatchers could route the same deal differently
- A-1 openOpen standards monetise poorly and get absorbed
Build v1.34 entries
- D1-1 fixedThe deployment generator emitted private keys into a config file
- V-1 openThe liveness fix rests on a parameter no solver can prove
- W-1 fixedOur own waste claims were directionally right and numerically loose
- PHI-2 fixedThe founding thesis was wrong about photonic currency
Build v1.26 entries
- C-1 fixedA brand-new client could be silently rolled back
- C-2 fixedNode identities could be ground into a victim’s neighbourhood
- C-3 fixedAll discovery trust flowed through one signer
- C-4 openRecords could be suppressed by concentrating nodes on one key
- E-1 fixedA referee who never ruled could freeze funds permanently
- E-2 fixedOur own test harness was quietly wrong
Build v1.14 entries
- F-1 fixedEscrow could be opened with a zero time-to-live
- X-1 fixedStacking a second handshake inside QUIC bought nothing
- Ln-1 fixedPayment timeouts could silently refund a live contract
- G-1 fixedA challenged namespace owner could withdraw their stake
Build v0.22 entries
- IG-002 fixedThe trust layer failed a second time after rebuild
- IG-013 fixedHeadline efficiency ratios were modelled, not measured
Build v0.11 entries
- IG-001 fixedThe first version's trust layer did not function