# Changelog

## 0.6.5 — 2026-08-20 (local-only, unpublished)

- Prepare one reproducible local package byte set: package manifest, generated catalog input, checked-in `lib` bundles, and npm pack manifest are verified together.
- Add a deterministic two-build and `npm pack --dry-run --json --ignore-scripts` verifier that rejects lifecycle scripts and non-allowlisted pack contents.
- This entry does not publish, tag, or claim registry, loaded Harness runtime, marketplace, authorization, or production evidence.

## 0.6.4 — 2026-08-17

- Add an explicit **Copy code** action for GitHub Device Flow so the complete validated code reaches GitHub without relying on segmented manual transcription.
- Keep the device code out of URLs, storage, analytics, logs, and automatic clipboard writes; copying remains a user-initiated action with visible success or failure feedback.
- Preserve the existing anonymous catalog, preview, Apply/Revert, chat creation, Connected Apps receipt, and explicit post-restart reconnect boundaries.

Release: https://github.com/daeshawnballard/dexthemes/releases/tag/deepseek-harness-plugin-v0.6.4

## 0.6.3 — 2026-08-15

- Route card and preview Apply actions through one explicit coordinator that starts the separately scoped Connected Apps receipt only after Harness accepts the theme override.
- Surface bounded receipt recording, success, and failure states in the account panel; a retry reuses the same in-memory UUID so a lost response cannot double count activity.
- Keep anonymous Apply/Revert unchanged and exclude theme IDs, palettes, prompts, workspaces, credentials, and account identity from the activity request.

## 0.6.2 — 2026-08-14

- Persist Disconnect only after Convex acknowledges server-side session revocation; failed revocation remains connected and retryable.
- Separate read access from client-reported Harness activity with a dedicated `harness:use` scope and replay-deduped receipt.
- Grant Harnessed / Deep Current from verified GitHub Device Flow completion rather than from a client-reported theme Apply.
- Label Connected Apps Apply activity as client-reported telemetry and keep it outside protected entitlement decisions.

Release: https://github.com/daeshawnballard/dexthemes/releases/tag/deepseek-harness-plugin-v0.6.2

## 0.6.1 — 2026-08-14

- Detect the supported Harness theme service at runtime, keep the DexThemes Settings tab visible when it is unavailable, and make the unavailable state reversible.
- Persist only versioned theme-selection and reconnect intent through Harness's snapshot-store engine, then restore a validated theme after a full process restart.
- Require an explicit GitHub Device Flow reconnect after restart; DexThemes session tokens remain memory-only and never enter browser storage, Harness configuration, analytics, prompts, or workspace files.
- Add bounded platform, source-surface, plugin-version, theme, variant, action, and outcome attribution for preview, copy, setup, Apply, restore, Revert, and capability events.
- Add compatibility, upgrade, removal, restart-recovery, release-notes, and support documentation.

Release: https://github.com/daeshawnballard/dexthemes/releases/tag/deepseek-harness-plugin-v0.6.1

## 0.6.0 — 2026-08-14

- Publish the installed Settings → Plugins → DexThemes surface with bundled and public/community discovery, paired previews, one-click Apply/Revert, restricted public MCP tools, privacy-bounded analytics, and an optional DexThemes Connect account flow.
- Add the DeepSeek default palette and twelve evidence-linked unofficial ecosystem color tributes.

Release: https://github.com/daeshawnballard/dexthemes/releases/tag/deepseek-harness-plugin-v0.6.0
