Changelog

1.1.14 (2026-08-05)

Changed

  • architecture: ADR-018, event sourcing as actually wired (#144) (21326d9)

1.1.13 (2026-08-05)

Changed

  • guides: document extending discovery and the namespace policy move (#140) (0cd084f)
  • guides: install instructions that work, and two claims that did not (#143) (c2822b2)

1.1.12 (2026-08-05)

Changed

  • guides: document the changelog-fragment convention (#138) (80e8be4)

1.1.11 (2026-08-04)

Changed

  • guides: renumber the upgrade note to 2.3.0 and add the launcher removal (#136) (922687a)

1.1.10 (2026-08-04)

Changed

  • architecture: lock_hierarchy moved to the shared kernel (#135) (004a48a)
  • reference: regenerate the released-artifacts matrix from GHCR (#130) (63f4b60)
  • release: move the version surfaces to core 2.2.1 (#131) (53fbbaa)
  • upgrade: add the 2.2.2 note for the event-sourcing auth store (#134) (faeae19)

1.1.9 (2026-08-03)

Changed

  • reference: document the 2.2.0 upgrade and correct the role table (#128) (dbe14b6)

1.1.8 (2026-08-01)

Changed

  • guides: state what argument secret-pattern scanning does not catch (#126) (2e7e30e)

1.1.7 (2026-08-01)

Changed

1.1.6 (2026-08-01)

Changed

  • reference: document the approval gate and move version surfaces to 2.1.0 (#122) (f94c218)

1.1.5 (2026-07-31)

Changed

  • release: move the version surfaces to core 2.0.1 (#120) (ea185a4)

1.1.4 (2026-07-31)

Changed

  • guides: correct the RBAC role table against roles.py (#119) (43809ef)
  • guides: fix the API paths and framing that reach AI consumers verbatim (#118) (dec9824)
  • reference: fix what the first 2.0.0 pass missed (#116) (62b75d9)
  • reference: move the compatibility matrix onto the 2.0.0 line (#115) (7915ceb)
  • reference: regenerate the released-artifacts matrix from GHCR (#114) (57f6956)
  • reference: the chart that installs 2.0.0 exists now (#117) (daf8f1c)
  • release: move the documentation to 2.0.0 (#112) (5de8fea)

1.1.3 (2026-07-29)

Changed

  • architecture: add ADR-016 and the approval adapter guide (#109) (c8308f3)
  • architecture: add ADR-017 on the approval input-request namespace (#111) (f72dad8)

1.1.2 (2026-07-28)

Changed

  • architecture: record that the Tasks wire is vendored, not taken from the SDK (#99) (80b13bc)
  • guides: bring the governed-tasks pages back to what actually ships (#101) (15121d4)
  • guides: move to 2.0.0rc3 and retire the gap warnings (#104) (3fcceb3)
  • guides: record that the task relay is on by default again (#102) (50025f0)
  • guides: stop the tasks pages contradicting themselves and the artifact (#103) (bb2b245)
  • reference: move the version surfaces to 1.6.3 and fix a dead anchor (#106) (5d3d2a8)
  • reference: the compatibility matrix still named the rc.1 candidate (#105) (781f8d4)

1.1.1 (2026-07-27)

Changed

  • reference: move the version surfaces to core 1.6.2 and the 2.0.0rc1 candidate (#92) (9e7262f)
  • reference: resync the artifact matrix after both charts published (#94) (e36926b)

1.1.0 (2026-07-26)

Added

  • guides: renovation phase 1 — truth-now docs for 1.6.0 (#87) (2543475)
  • guides: renovation phase 2 — governed tasks guide + v2 preview notes (#88) (ef58f40)

Fixed

  • release: drop stale pre-v0.14.0 release caveats (#89) (d0adc57)

Changed

  • accuracy/currency review — align content to the current project state (cb72bd6)
  • adr-014: record task-relay activation (2026-07-22) (#86) (743a820)
  • adr: ADR-013 egress policy enforcement model (MCPEgressPolicy) (#72) (8e2480d)
  • adr: amend ADR-009 with the prerelease / pre-GA branch lane (#77) (ba4749e)
  • architecture: add ADR-012 (interceptor SEP-pin tracking policy) (#70) (6ac3f1d)
  • architecture: add ADR-014 (tasks relayed with governance, partially supersedes ADR-008) (#78) (1aaa1a6)
  • architecture: correct ADR-009 amendment — prereleases publish to prod PyPI (#85) (37f4288)
  • architecture: ratify ADR-014 (Proposed -> Accepted) (#79) (469e5ac)
  • bump version surfaces to core 1.6.1 + v2 preview 2.0.0a2 (#90) (347a21c)
  • currency pass — v0.14.0 L7 delivery, release matrix, rebuilt architecture overview (8ca8381)
  • guides: add the MCPEgressPolicy egress policy guide (#73) (fda8656)
  • guides: reflect the 1.6.0 observability/semconv changes (#76) (5dfd3fb)
  • guides: refresh MCPEgressPolicy guide for the completed feature (#74) (2df3798)
  • reference: add operational runbooks for the shipped alerts (#75) (a06dd93)
  • strip 'enterprise' tier/marketing framing (no paid tier) (e046c8c)

1.0.4 (2026-07-18)

Changed

  • architecture: add ADR-011 (single source of truth for cross-repo facts) (#68) (ae530b5)
  • guides: fix stale github.io helm-repo refs to OCI + add domain-lint (ADR-011) (#69) (cd9360e)
  • reference: add OWASP MCP Top 10 coverage page (#66) (a01ce74)

1.0.3 (2026-07-18)

Changed

  • architecture: add ADR-010 retiring the agent + Hangar Cloud tier (#52) (858c173)
  • reference: add EU AI Act / SOC 2 compliance posture doc (#55) (b5fd9d9)
  • reference: generate the released-artifacts matrix + immutable-tags status (Track 2) (#56) (c52fd54)
  • reference: update compatibility matrix to core 1.5.1 (#53) (fb1cace)
  • release: correct the chart install status and record mutable chart tags (#46) (2bd19ff)
  • repo: retire hangar-agent / Hangar Cloud references (#51) (91561fd)

1.0.2 (2026-07-16)

Changed

  • guides: correct contributing and git-flow for the multi-repo topology (#44) (ed5a858)
  • reference: document event_store fail-fast and non-loopback auth requirement (#42) (1fe2671)
  • release: record the validated kubernetes range and the chart install status (#45) (6bfb7aa)

1.0.1 (2026-07-15)

Changed

  • reference: document the config.yaml command-bus rate_limit block (1.5.0) (#40) (49768f3)

1.0.0 (2026-07-15)

Added

  • content: migrate public docs from mcp-hangar/docs/ (0e4232f), closes #2

Changed

  • architecture: add ADR-008 -- task governance is relay-only (#12) (9321f43)
  • architecture: draft ADR-009 independent release topology (#32) (cf5c4de)
  • content: document mcp-hangar 1.3.0 (710b29a)
  • cookbook: add 1.3 digest pinning upgrade recipe (a3832ce)
  • cookbook: add interceptor discovery recipe (73e8d08)
  • guides: add a progressive deployment playbook (#23) (9f21a91)
  • guides: add external multi-tenant OIDC front door cookbook (#26) (982bbe2)
  • guides: add local dev and staging deployment profiles cookbook (#25) (20f3cb0)
  • guides: add production read-only and controlled-write boundaries cookbook (#24) (71c5248)
  • guides: cookbook harden a public authenticated MCP gateway (#29) (37b7172), closes #21
  • guides: correct rate-limit scope in cookbook 06 (#15) (c20f65a)
  • guides: document mcp-hangar 1.4.0 and add 1.4 cookbooks (#8) (9cda48c)
  • guides: fix drifted cookbook recipes against 1.4.0 source (#9) (9591ffc)
  • guides: fix duplicated recipe numbers in cookbook 21 and 22 (#31) (a52521f), closes #30
  • guides: use mcp-hangar as the Kubernetes namespace in examples (#36) (62d9806)
  • release: add 1.5.0 upgrade notes, CLI auth command, and compatibility matrix (#39) (57bbe9b)
  • release: add release compatibility and GHCR security policy (#33) (08a41c9)
  • release: add Releases & Artifacts install index (#11) (6808a91)
  • release: correct the core image as signed (it already is) (#38) (3483627)
  • release: record cosign signing done; all artifacts signed (#37) (27b75b7)
  • release: record verified Helm chart releases; all lanes published (#35) (ef65e84)
  • release: record verified operator and agent image releases (#34) (18aba8c)
  • sync with mcp-hangar source, document 1.3.0, add drift validation (#7) (45bef08)