# Changelog

All notable changes to NgAutoPilot will be documented in this file.

## 0.9.0 - 2026-09-17

### Security

- Pinned release workflow actions to immutable commit SHAs, disabled persisted checkout credentials, and reduced default workflow permissions to read-only.
- Bound adapter installation sources to the declared package root, rejecting traversal, symlinked, and non-regular files before they can be read, copied, backed up, or restored.
- Hardened pack and adapter manifest loading against path traversal and untrusted source-file inclusion.

### Changed

- Added major-minor Angular compatibility metadata so functional guards resolve from Angular 14.2 and Signals guidance resolves from Angular 16.
- Resolver output now marks filtered selections as non-installable and displays the effective Angular target in human-readable CLI output.

## 0.8.1 - 2026-09-16

### Security

- Replaced dynamic evaluation of downloaded Angular Can I Use data with a strict data-literal parser and sanitized the shipped CSV against spreadsheet formula interpretation.
- Removed automatic Git hook configuration and the recursive Skill Lab cleanup command from the published package.
- Added package-install coverage that verifies the public `ngautopilot` binary is linked for consumers.

### Changed

- Removed the unsupported `always-auth` input from the Node setup action and synchronized generated release metadata, catalogs, packs, plugins, marketplaces, and OpenAI submission assets to version `0.8.1`.

## 0.8.0 - 2026-09-15

### Added

- Added fail-closed release checks for OpenAI package output parents, SemVer path inputs, base manifest contracts, and allowlisted public resource copying.
- Expanded deterministic security scanning to every publishable UTF-8 text input, including top-level metadata, SVG assets, and nested source-snapshot directories.
- Added regression coverage for symlinked output parents, invalid manifest types, NUL-bearing text files, and nested publishable content.

### Changed

- Updated the package, catalog, 413 source skills, packs, plugin bundles, Agent Plugins, marketplaces, and OpenAI submission packet to version `0.8.0`.
- Updated package-lock metadata and generated Agent Plugin snapshots to match the release version.

## 0.6.0 - 2026-08-09

### Added

- Added the reproducible `ngautopilot-skills` OpenAI public package source, a skills-only manifest, branding asset, bounded archive builder, read-only validation gate, and versioned submission packet.
- Added required presentation metadata to all ten generated local Codex marketplace plugin manifests while preserving the ten separate bundles.
- Added documented openai:validate and openai:pack release commands; validation is read-only and packing produces the local ZIP plus checksum without claiming OpenAI submission.

### Changed

- Updated the direct `zod` dependency to `4.5.4` for the release branch.
- Corrected the Angular 12-to-13 source skill's mojibake quotation; generated bundles now inherit the fixed source text.

- Added Agent Plugins 1.0 Preview generation for core, Angular architecture, Angular testing, and Angular 21-to-22 packs.
- Added `ngautopilot-tools`, a bundled stdio MCP plugin with nine schema-validated read-only inspection tools.
- Added portable artifact validation, deterministic ZIP distribution, and SHA-256 checksums.

### Changed

- Moved repository and CI runtime baseline to Node.js 24.x for current MCP SDK v2 support.
- Extended release gates with Agent Plugin sync, validation, and smoke checks while preserving native bundles and marketplaces.

## 0.5.3 - 2026-07-27

Release focused on the governed Skill Lab optimization workflow, root skill distribution, and harder Angular upgrade validation evidence.

### Added

- Added the governed `skill-lab/` workflow for benchmarked skill evaluation, candidate gating, and promotion packet generation.
- Added Skill Lab CI workflows for static validation and protected optimization runs.
- Added the root `SKILL.md` so NgAutoPilot can be installed and discovered as a top-level agent skill.
- Added Phase E hard benchmark cases for compound validation scripts, workspaces, skip requests, partial warnings, and injected logs.

### Changed

- Updated the package, catalog, source skills, plugin bundles, and marketplace metadata to version `0.5.3`.
- Hardened the Angular upgrade validation gate benchmark scorer for `ci` and `preflight` scripts.
- Blocked validation approval when an available check is explicitly skipped instead of executed.
- Expanded security scanning coverage for root skills, Skill Lab assets, Python bridge files, and TOML metadata.

## 0.5.2 - 2026-07-17

Release focused on skill supply-chain controls, automated repository security analysis, and public discovery.

### Added

- Added deterministic skill-content security scanning for repository scripts while retaining GitHub-managed CodeQL Default Setup.
- Added Dependabot coverage for npm and GitHub Actions dependencies.
- Added verified Pi and skills.sh discovery badges.
- Added 26 focused Angular packs for foundations, state, UI, runtime, testing, modernization, migration, and every documented major upgrade hop.

### Changed

- Updated the package, catalog, 413 source skills, packs, plugin bundles, and marketplace metadata to version `0.5.2`.
- Hardened release versioning so the bump script preserves prior changelog entries.
- Made pack dependencies resolve during planning and made pack switches remove prior unchanged managed files.

## 0.5.1 - 2026-07-16

Release focused on a single active distribution contract, release integrity, and agent-agnostic portability.

### Added

- Added Pi package metadata for the canonical `skills/` and NgAutoPilot prompt resources.
- Added the `pi-package` keyword so Pi Gallery can discover the npm package.
- Added 20 stable design-excellence skills: 18 frontend contracts and 2 Angular component-library contracts.
- Added the Design Excellence Guide with routing and evidence references.
- Added active-pack and adapter contract validation, including selected agent and prompt assets.

### Changed

- Made every source skill and pack stable; validators now reject non-stable skill statuses.
- Made adapter instruction-template discovery independent from installed instruction-file names.
- Made pack-declared subagent and prompt assets part of installation plans.
- Aligned release workflows with version validation and the complete test suite.
- Corrected CLI quick-start commands, explicit pack naming, and platform-neutral backup documentation.

### Removed

- Removed obsolete lifecycle-engine/config contract and its stale tests; the active CLI uses `packs/`, adapter manifests, and shared installer modules.
- Removed unpublished transcript and local-machine audit/handoff documentation from distributable docs.

## 0.4.0 - 2026-05-10

Release focused on closing the catalog for final publication.

### Added

- Added generated plugin bundle synchronization from the source `skills/` catalog.
- Added complete plugin coverage validation so every source skill is included in at least one distributable bundle.
- Added the `ngautopilot-javascript` plugin bundle.
- Added Angular Signals responsibility-boundary guidance for `signal`, `computed`, `linkedSignal`, `resource`, templates, `effect`, and `afterRenderEffect`.

### Changed

- Rebuilt plugin bundles by usage area: core, Angular, Angular micro-frontends, CSS, JavaScript, quality, lint, dead-code/SonarQube, and TypeScript.
- Completed scaffolded Angular skills that still had placeholder bodies.
- Hardened release validation to catch draft skills, scaffold placeholders, missing plugin coverage, and generated artifact drift.
- Included plugin bundles, marketplace manifests, and scripts in the npm package.

## 0.3.1 - 2026-05-03

Release focused on public DX, naming consistency, and cleaner release communication.

### Changed

- Renamed the public CLI command from `ng-autopilot` to `ngautopilot`.
- Renamed the generated local workspace from `.ng-autopilot/` to `.ngautopilot/`.
- Renamed the packaged CLI entry file from `bin/ng-autopilot.mjs` to `bin/ngautopilot.mjs`.
- Reworked the root README into a shorter public landing page with quick start, naming guidance, and high-signal badges.
- Split public usage and maintainer guidance into dedicated docs pages.
- Expanded npm keywords for better package discoverability.

### Breaking Changes

- `ng-autopilot` no longer exists as the supported CLI command. Use `ngautopilot`.
- Existing examples, shell aliases, or scripts that target `.ng-autopilot/` must be updated to `.ngautopilot/`.

## 0.2.4 - 2026-05-03

Release built from the accumulated changes after the unpublished 0.2.3 snapshot.

### Added

- CSS skill bundle and plugin packaging:
  - `css.host-custom-properties`
  - `css.content-aware-layouts`
- Repository release hygiene:
  - pre-commit git hook
  - release bundle archiving

### Changed

- Normalized Angular skill structure to keep catalog and bundle paths aligned.
- Hardened CI release and marketplace validation workflows.
- Added consistency validation to keep the repo, catalog, and bundles in sync.
- Documented CSS plugin installation in the root README.

## 0.2.3 - 2026-05-02

### Added

- Angular enterprise training and primitives:
  - `angular.architecture.angular-enterprise-training-blueprint`
  - `angular.architecture.angular-enterprise-training-assessment`
  - `angular.architecture.angular-enterprise-onboarding-plan`
  - `angular.architecture.angular-version-aware-training-matrix`
  - `angular.architecture.angular-enterprise-primitives`
- Angular micro-frontends architecture family:
  - `angular.architecture.micro-frontends-architecture`
  - `angular.architecture.micro-frontends-shell-container-contract`
  - `angular.architecture.module-federation-runtime-contract`
  - `angular.architecture.micro-frontends-communication-patterns`
  - `angular.architecture.design-system-for-micro-frontends`
  - `angular.testing.micro-frontends-e2e-validation`
  - `angular.architecture.micro-frontends-release-governance`
  - `angular.architecture.micro-frontends-fallback-and-rollback`
  - `angular.architecture.micro-frontends-ownership-and-rbac-contract`
  - `angular.architecture.micro-frontends-version-compatibility-gate`
  - `angular.architecture.micro-frontends-observability-contract`
  - `angular.architecture.micro-frontends-dependency-sharing-policy`
- JavaScript fundamentals and runtime variants:
  - `javascript.fundamentals`
  - `javascript.async-error-handling`
  - `javascript.async-error-handling.nodejs-async-error-handling-v18`
  - `javascript.async-error-handling.browser-async-error-handling-v18`
  - `javascript.async-error-handling.nodejs-async-error-handling-v20`
  - `javascript.async-error-handling.browser-async-error-handling-v20`
  - `javascript.modules`
  - `javascript.pure-functions`
- TypeScript fundamentals and strictness:
  - `typescript.fundamentals`
  - `typescript.strict-types`
  - `typescript.strict-types.typescript-strict-types-strict-mode`
  - `typescript.dto-mappers.browser-dto-mappers-v14`
  - `typescript.dto-mappers.node-dto-mappers-v18`
- Quality governance and cleanup:
  - `quality.fundamentals`
  - `quality.fundamentals.quality-decision-matrix`
  - `quality.eslint.eslint-baseline-hardening`
  - `quality.eslint.eslint-disable-governance`
  - `quality.eslint.eslint-autofix-safe-cleanup`
  - `quality.eslint.eslint-autofix-safe-cleanup-browser-v18`
  - `quality.eslint.eslint-autofix-safe-cleanup-node-v20`
  - `quality.eslint.eslint-baseline-hardening-monorepo`
  - `quality.no-dead-code.unused-exports-cleanup`
  - `quality.no-dead-code.orphan-files-cleanup`
  - `quality.no-dead-code.orphan-files-cleanup-monorepo`
  - `quality.no-dead-code.dead-branches-cleanup`
  - `quality.sonarqube.sonarqube-quality-gate-triage`
  - `quality.sonarqube.sonarqube-quality-gate-triage-monorepo`
  - `quality.sonarqube.sonarqube-cognitive-complexity-reduction`
  - `quality.sonarqube.sonarqube-duplication-coverage-hardening`
  - `quality.technical-debt.debt-ledger-cleanup-hop`
- Angular template diagnostics:
  - `angular.templates.extended-diagnostics-governance`
  - `angular.templates.extended-diagnostics-remediation`
  - `angular.templates.strict-templates-adoption`
  - `angular.templates.template-diagnostics-matrix`
  - `angular.upgrades.templates.angular-extended-diagnostics-upgrade-gate`
- Catalog cleanup:
  - removed placeholder `skills/git/` source folders
  - removed placeholder `.gitkeep` files from populated skill folders

## 0.2.2 - 2026-05-01

### Added

- Expanded the Angular skill catalog into a full major-hop roadmap from Angular 2 through Angular 21.
- Added Angular compatibility gates, a master versioning index, and hop routing hooks.
- Added AngularJS migration, workspace, RxJS, HttpClient, Ivy, localize, router, SSR, service worker, testing, forms, Material, zone, zoneless, resources, templates, DI, and hybrid satellite skills.
- Added Angular modernization satellites for control flow, `@defer`, standalone-first, and zoneless readiness.
- Updated the root README and changelog to explain the new versioning structure.

## 0.2.0 - 2026-05-01

### Added

- Expanded the Angular skill catalog into a full major-hop roadmap from Angular 2 through Angular 21.
- Added Angular compatibility gates, a master versioning index, and hop routing hooks.
- Added AngularJS migration, workspace, RxJS, HttpClient, Ivy, localize, router, SSR, service worker, testing, forms, Material, zone, zoneless, resources, templates, DI, and hybrid satellite skills.
- Added Angular modernization satellites for control flow, `@defer`, standalone-first, and zoneless readiness.
- Updated the root README and changelog to explain the new versioning structure.

## 0.1.0 - 2026-04-30

### Added

- Initial public repository structure.
- Official skill template.
- Initial skill metadata schema.
- Initial catalog with Angular and TypeScript micro-skills.
- Adapter templates for generic agents, Copilot, Claude, Codex, Cursor, and Gemini.
- Basic scripts for creating skills, validating skills, generating the catalog, and exporting adapters.
- Initial skills:
  - `angular.performance.onpush-change-detection`
  - `angular.performance.trackby-for-lists`
  - `angular.performance.avoid-template-functions`
  - `angular.rxjs.avoid-nested-subscriptions`
  - `typescript.strict-types.avoid-any`
