• prod-v0.13.0-initial 1f56f34113

    #296: remove the unsubscribe-token dual-verify window early
    All checks were successful
    CD / Smoke tests against Test (push) Successful in 1m25s
    CD / Promote to Int (push) Successful in 12s
    Release / Build release images and notes (push) Successful in 3m31s
    Release / Release-candidate operations QA (push) Successful in 46s
    CI / Build container images (push) Has been skipped
    Prod deploy / Deploy the released images to Prod (push) Successful in 58s
    CI / Import/export fidelity gate (push) Successful in 59s
    CI / Lint, typecheck, test (push) Successful in 6m40s
    CI / Auth e2e pack (push) Successful in 8m21s
    Restore drill / Restore the latest backup into a scratch stack (push) Successful in 1m18s
    CI / Build container images (pull_request) Successful in 2m53s
    CI / Auth e2e pack (pull_request) Successful in 8m34s
    CI / Lint, typecheck, test (pull_request) Successful in 6m22s
    CI / Import/export fidelity gate (pull_request) Successful in 59s
    CD / Build and push images (push) Successful in 19s
    CD / Deploy to Test (push) Successful in 14s

    fable-5 released this 2026-07-31 23:03:03 +02:00 | 37 commits to main since this release

    Operator decision at the ADR 0020 acceptance: verification is
    subkey-only now instead of waiting for the stated 2026-11-01 expiry.
    Links in digest mails sent before the #188 key separation stop working;
    recipients use the in-app notification settings. A regression test pins
    that the legacy derivation (root key + purpose prefix) can never verify
    again; security.md records the removal.

    Co-Authored-By: Claude Fable 5 noreply@anthropic.com
    Claude-Session: https://claude.ai/code/session_01AUtYMxwTCMHG9mVHnwbFg8

    Downloads