Release digest
Improved
- LANDING-PROOF-CRAWLABILITY (Public Growth) — Added browserless, build-time server-rendered HTML for the home, Audit Scope Readiness, synthetic sample, free audit-quote resource, and pricing routes so buyers, crawlers, and AI readers can inspect the offer without executing JavaScript.
- AUDIT-SCOPE-PROOF-HIERARCHY (Commercial Clarity) — Reworked the first screen around one frozen public EVM commit, exact price and SLA, a synthetic evidence preview, and explicit founder, Vartovii, and external-auditor roles.
Fixed
- FARCASTER-DOMAIN-ASSOCIATION (Mini App Identity) — Replaced the legacy
sentryanalytic.comaccount-association default with the signedvartovii.comassociation and added a regression check that decodes the manifest payload before accepting the canonical domain. - SECRET-VERSION-PINS (Deployment Safety) — Pinned the completed production
rotations for Neon, Gemini, OpenRouter, and GitHub across app, worker, and
recovery deploy contracts so a future release cannot silently revert them to
latest; the existing SerpAPI binding remains unchanged. - DOCUMENTATION-INVENTORY (Repository Governance) — Added compact, machine-checked rules for canonical, active, generated, immutable, archived, and flagged documentation while keeping the exhaustive per-file inventory an untracked audit artifact.
- SUPERSEDED-DOCS-ARCHIVE (Repository Governance) — Moved completed redesign prompts, stale business/grant material, closed agent records, and the Sentinel-8004 lane into indexed archives; removed one redundant sprint plan after a zero-consumer check.
- TWITTER-AUTOMATION-RETIREMENT (Distribution Safety) — Removed the local daemon and live-posting CLI paths, made the retained job definition explicitly default-deny, and removed the token-printing OAuth helper while preserving preview generation and rollback-compatible storage code.
- FARCASTER-MINIAPP-COMPATIBILITY (Mini App Runtime) — Added the current
miniappmanifest alongside the matching legacyframe, upgraded the pinned SDK to0.3.0, moved sharing tocomposeCast, removed the misrouted notification webhook, and strengthened production manifest smoke validation. - PUBLIC-REPO-SYNC-BOUNDARY (Repository Governance) — Replaced implicit
public-repository sync and auto-commit hooks with explicit read-only
checkand manualsynccommands, added leakage checks, and aligned public product links withVartovii-Platform. - PRODUCTION-DEPLOYMENT-CONTROL (Release Safety) — Made the Google Cloud
vartovii-deployrepository trigger the single automatic app deployment owner, removed the duplicate GitHub submission path, consolidated the build contract at root, and added automatic exact-SHA production smoke validation.
Internal
- User-facing documentation changed across the landing,
llms.txt, SEO discovery metadata, and the knowledge-base Audit Scope Readiness guide. - Canonical architecture and roadmap docs are unchanged because the offer, artifact schemas, backend APIs, intake behavior, and delivery boundary did not change. No separate internal implementation report is required.
- No additional user-facing or canonical documentation change is required for
the Farcaster fix because the public product domain was already documented as
vartovii.com; this release note records the runtime identity correction. - Updated the canonical deployment environment inventory for the audited secret versions. No user-facing documentation or architecture change is required because this is an internal deployment-safety correction.
- Updated canonical and internal navigation to reflect the active Audit Scope
Revenue Rescue test,
vartovii.com, Upstash Redis, and the archive boundary. No user-facing documentation change is required for this governance-only inventory slice. - User-facing documentation changed only to unlist historical crypto plan routes and preserve the old Forensic Agent route as a noindex compatibility pointer. Canonical domain-migration operations remain in the deployment runbook; no product, API, or immutable-report content changed.
- User-facing, architecture, and deployment documentation now identify Twitter/X automation as retired and the retained generator as manual, preview-only, and default-deny. No external scheduler, job, or secret was mutated.
- Updated public and canonical Farcaster documentation for the current manifest, SDK, sharing, and notification boundary. Existing API routes and telemetry events remain compatible.
- Updated canonical public-sync governance and user-facing repository links. The public remote was not committed to or pushed; its existing local checkout remains unchanged pending a separately reviewed public release.
- Updated the production deployment ADR and CI/CD runbooks with the canonical automatic trigger, same-trigger recovery, exact-SHA verification, and rollback evidence. No user-facing documentation change is required because product behavior and public API contracts are unchanged.
- Added post-build raw-HTML assertions, sample-fixture alignment coverage, structured-data and discovery regression checks, and desktop/mobile browser verification for the primary conversion flows.