# v3.0.3

DSH Vision Router 3.0.3 is a corrective patch on the 3.0 line. It closes the three residuals
reported after 3.0.2 and carries two CI-action maintenance updates. There is no runtime dependency,
settings migration, Session-format change, public-API change or Host-support-window change.

## Highlights

- **Presented-image focus only reacts to fresh image results (#666).** Restoring a long Session no
  longer jumps to an old image below the viewport, and an empty `vision_present` result cannot
  steer the reader to another card. The helper receives the exact card node instead of querying
  the document for the last presented card.
- **The focus rule works across the supported Host window.** DSH 0.1.7+ exposes an explicit
  `phase`; the supported DSH 0.1.5 train does not. The client normalizes both contracts by using
  `phase` when present and falling back to the settled `block.kind === 'tool-result'`
  discriminant otherwise. Restored results initialize as already settled, while a live call still
  produces the non-result → result edge.
- **Leading-dot proxy hosts are no longer inert (#665).** `.example.com` now canonicalizes to the
  same apex-and-subdomain policy as `*.example.com`. Dot-boundary matching remains conservative,
  so lookalikes such as `evilexample.com` stay outside.
- **The exact DSH 0.1.7 browser smoke follows both presentation owners again (#664).** Changes to
  either presentation-boundary carrier now trigger the exact-Host browser regression layer.
- **CI action maintenance (#662, #663).** `actions/download-artifact` is pinned to v8.0.1, and the
  HOL scanner Action is pinned to v1.2.763 (plugin-scanner 3.24.2). The scanner version annotation
  in the workflow is corrected to match the actual immutable SHA.

## Compatibility

Unchanged from 3.0.2:

- DSH 0.1.x: `>=0.1.5-rc.1 <0.2.0-0`
- DSH 0.2.x: `>=0.2.0-rc.2 <0.3.0-0`
- Node.js: `^22.19.0 || >=24.0.0`

## Validation

The fixes carry direct regression coverage for restored/empty presentation results, the legacy
no-`phase` Host lifecycle, leading-dot proxy admission/non-admission, and the DSH 0.1.7 workflow
ownership paths. The release workflow re-runs the full test, build, reproducibility, type, packed
API and Host-support gates on the exact release SHA before it creates the immutable tag or
publishes to npm.

## Upgrade

Drop-in replacement for 3.0.2. No configuration or data migration is required.
