Back to changelog index

14.2.1

Aug 01, 2026 · 99 packages · 257 unique changes · 81 release entries

appsbundlesintegrationslibsmodulesBreaking changes

This release affects the contracts, integrations, sharedLibs, solutions familyies.

Run contractspec connect adoption resolve --family contracts to see how it impacts your project.

Release summaries

  • adaptive-dataview-command-center

    Add adaptive DataView management-shell contracts and command-center proof metadata.

    maintainer

    DataView specs can now declare management-shell header, toolbar, selection, row-card, detail-panel, pagination, action placement/boundary, field-role, personalization, and RoleMorph references.

    integrator

    Host applications receive additive metadata for command-center DataView layouts while retaining ownership of CRUD side effects, modal state, validation, and destructive confirmations.

  • adaptive-dataview-management-contract

    Add optional DataView management-shell metadata for adaptive command-center layouts.

    maintainer

    DataView contracts now include additive management-shell metadata for semantic field roles, action placement, toolbar/header/selection/detail-panel, and adaptive binding hints.

    integrator

    Integrators can describe command-center layouts and action boundaries in metadata while keeping application behavior host-owned.

  • adoption-aware-release-pipeline

    Adoption-aware release pipeline with accumulating release index, per-version detail files, CLI changelog list/view commands, and web changelog version pages.

    maintainer

    Release build now syncs adoption catalogs, writes pending upgrades, and produces an accumulating release index with per-version detail files. CLI changelog commands (list/view) consume the generated index.

    integrator

    The `after-release-build` adoption hook is available in CI and local builds. Adoption catalog entries are now enriched from release index data.

    customer

    Web changelog now supports per-version detail pages with package breakdown, migration instructions, upgrade steps, and deprecation notices.

  • adoption-engine-and-authoring-targets

    Add a family-aware ContractSpec Adoption Engine, expand contract authoring targets across CLI and VS Code tooling, and refresh release-facing schema and policy artifacts for downstream workspaces.

    maintainer

    Maintainers get a shared adoption catalog and resolver, Connect adoption hooks, MCP exposure for reuse decisions, expanded authoring-target coverage, and updated static policy artifacts.

    integrator

    Integrators can resolve existing workspace or ContractSpec OSS surfaces before adding new implementations, and can scaffold more contract families from the CLI and VS Code extension.

    customer

    Customer workspaces gain setup-managed adoption guidance, Connect `adoption sync/resolve` flows, stronger runtime-import and deprecated-monolith guardrails, and updated bundled schemas in the published CLI entrypoint.

  • agent-application-foundation

    Add a contract-first, filesystem-authored agent application foundation with governed runtime ports, durable cross-adapter conformance, isolated EVE integration, agent evals, and a reference application.

    integrator

    AgentSpec and WorkflowSpec now share one canonical runtime-adapter identity that includes `eve`; exhaustive adapter switches must handle the new key without importing EVE types into generic libraries.

    maintainer

    Durable stores, sandbox, file retrieval, subagent dispatch, collaboration leases, runtime parity, filesystem compilation, and eval evidence now have explicit package-local verification surfaces.

    agent

    Filesystem-authored applications can compile into portable AgentSpec and WorkflowSpec output, run bounded orchestrator/verifier flows, and emit replay-linked evaluation evidence.

  • agentic-communication-command-inbox

    Add fail-closed agentic interaction and CommunicationOS command-inbox release evidence across contracts, runtime, module, examples, and agent-facing docs.

    maintainer

    Maintainers get a validation matrix for the subpath-only AIP safety surface, command-inbox runtime projection, module facade, focused CommunicationOS proof, and Operating Cockpit CompanyOS bridge proof.

    integrator

    Integrators can adopt message-originated command evidence without granting send, credential, shell, or high-impact CompanyOS execution authority.

    agent

    Agents must treat command-inbox items as non-executing evidence and keep blocked signals fail-closed until an external approval path acts.

  • builder-v3-control-plane-rollout

    Introduce the Builder v3 control plane as a governed authoring layer over external execution providers.

    maintainer

    Builder v3 now has a governed contract, runtime, and provider surface that keeps authoring, readiness, and export orchestration aligned across the package stack.

    integrator

    Integrators can compose managed, local, and hybrid runtime modes with Builder workbench/mobile-review modules and provider adapters for Codex, Claude Code, Gemini, Copilot, STT, and local models.

    customer

    Builder operators now get a unified workbench and mobile-review experience across provider routing, readiness, export approval, and omnichannel control flows.

  • byok-monorepo-env-config

    Add first-class monorepo-aware environment contracts and managed/BYOK credential setup helpers.

    integrator

    Monorepos can declare logical environment variables once and materialize framework-specific aliases such as NEXT_PUBLIC_* and EXPO_PUBLIC_* per app target.

    maintainer

    Integration specs can expose managed/BYOK credential manifests while runtime reports redact secret and sensitive values.

    customer

    BYOK setup can be validated from shared contracts without placing raw secrets in specs, docs, reports, or generated env examples.

  • company-intelligence-authenticated-api

    Add a contract-derived authenticated Company Intelligence v1 Elysia boundary with durable tenant-scoped replay and request budgets, canonical PostgreSQL operation bindings, and production-only model service ports.

    integrator

    Mount the v1 Company Intelligence API only with tenant-bound session or service-principal authority and the approved tenant-scoped PostgreSQL repositories. Apply migration 0027 for durable replay and request budgets. Built-in PostgreSQL adapters authorize evidence, replay, reviews, graph, and Brain access. Bind external extraction and grounded-answer services separately; health stays degraded and those two operations fail closed until their dependencies are available.

  • companyos-connect-canonicalization-v1

    Add a strict historical-v1 database read boundary so a human can approve forward-only migration 007 before it normalizes text storage to the unchanged public integer-v1 contract, while preserving approval-event provenance across historical JSON-only and complete denormalized storage shapes.

    integrator

    Integrators retain the literal canonicalizationVersion 1 contract while exact historical PostgreSQL text "1" is read compatibly for approval and then normalized by a tracked migration; approval event provenance remains canonical in integrity_metadata before and after denormalization.

    maintainer

    Migration owners get a dry-run-first CLI with advisory locking, predecessor enforcement, transactional rollback, ledger replay, and explicit confirmation. The first-reviewer provisioning apply is intentionally outside the otherwise-circular Connect signature gate, but requires the authenticated migration-owner role, seven exact confirmations, rollback evidence, and idempotent replay. Migration 006a preserves historical ledger IDs while adding reviewer-runtime nonce, issuer, and RLS support; explicit public authorization and reviewer proof metadata replace embedded trust.

  • companyos-solutions-starting-points

    Redesign the CompanyOS /solutions buyer path around starter workflows, reusable governed workflow patterns, and bring-your-own-process conversion while adding structured marketing contract card fields and icon-key transport.

    integrator

    MarketingSectionContract cards may now carry optional iconKey and structured fields. Existing title/description/href cards remain valid; renderers can opt into labelled card content without parsing description strings.

    customer

    CompanyOS /solutions now frames named packages as starter doors that prove reusable governed workflow patterns and routes buyers to bring their own workflow when the catalog does not match their first process.

  • connect-local-approval-kernel

    Add the durable local Connect approval kernel, linkage recovery, and tenant isolation.

    integrator

    Integrators can persist generic channel or Connect approval subjects with immutable digest generations and recover an incomplete Connect runtime link safely.

    maintainer

    PostgreSQL operators must run the ordered approval migrations with a migration owner while the non-owner runtime uses transaction-local tenant and workspace context.

  • connect-spec-alignment-april-2026

    Implement ContractSpec Connect as a first-class spec, runtime, and CLI workflow.

    maintainer

    Connect is now a governed repo surface with CLI commands, workspace services, and versioned docs that keep risky edits, review packets, and replay artifacts aligned.

    integrator

    Integrators can enable `.contractsrc.json > connect`, emit local context/plan/verdict artifacts, and route adapter-facing review or replay flows through the shared workspace services.

    agent

    Coding-agent surfaces now have a first-class Connect workflow for context packs, plan packets, mutation verdicts, review packets, and replay/eval evidence instead of relying on ad hoc governance prose.

  • contract-dx-first-slice

    Improve app-config, theme, and feature authoring with explicit validation APIs, first-class theme discovery and scaffolding, and key-based app-config generation across contracts, workspace tooling, and the CLI.

    maintainer

    Maintainers can rely on authored validators for app-config, theme, and feature specs instead of shallow per-surface checks, and can scaffold theme specs directly from the CLI.

    integrator

    Integrators get a stable `defineTheme` authoring path, new theme and feature validation helpers, and key-based app-config DTOs and templates across shared tooling.

    customer

    CLI users can now run `contractspec create theme`, and validation catches more app-config, theme, and feature mistakes before publish or CI promotion.

  • contracts-spec-entities-module

    Add entities module to contracts-spec — EdgeSpec, defineContractEdge, defineContractEntity (Layer 1+2), EntityRegistry.

    maintainer

    New entities/ module adds EdgeSpec, defineContractEdge, defineContractEntity (Layer 1+2), and EntityRegistry. All exports are additive. Schema layer (lib.schema defineEntity) is untouched per A4 invariant. 11 unit tests added covering Layer-1 and Layer-2 round-trips, A4 verification, EntityRegistry CRUD and listEdges flattening, and duplicate guards.

    integrator

    Import EdgeSpec, defineContractEdge, defineContractEntity, and EntityRegistry from @lssm-tech/lib.contracts-spec. Use defineContractEntity Layer 1 (meta + edges) for slug-only entity declarations, or Layer 2 (meta + entity + edges) to attach a full EntitySpec<TFields> from @lssm-tech/lib.schema. Register all entities and edges in EntityRegistry before any DataViewRenderer resolves graph slugs.

  • contracts-spec-loop-d-operation-aliases

    Loop D D4 — `@lssm-tech/lib.contracts-spec` now supports `meta.aliases?: readonly string[]` on operations. `OperationSpecRegistry.get()` falls back to alias lookup when the canonical key misses. Future namespace migrations can ship as additive instead of BREAKING.

    maintainer

    Added `aliases?: readonly string[]` to `OperationSpecMeta`. Overrode `OperationSpecRegistry.get()` to fall back to alias lookup on canonical-key miss. Direct matches retain precedence — aliases never shadow registered operations. 6 new tests in `operations/operation-aliases.test.ts` cover the regression baseline, alias resolution, version filtering, and the precedence rule. Full pre-existing test sweep across 1715 tests is zero-regression.

    integrator

    To soften a future namespace migration, list the legacy keys in `meta.aliases` on the new contract. Registry lookups by the legacy key will resolve to the new operation, letting downstream consumers migrate at their own pace. No changes required for operations that don't migrate.

  • contracts-spec-root-crypto-surface

    Remove avoidable Node crypto imports from ContractSpec runtime surfaces and keep signing helpers isolated.

    integrator

    Browser and Next.js consumers can use workflow, telemetry, experiments, root, and broad control-plane surfaces without static Node crypto imports.

  • contractspec-form-operation-marketing-components

    Form-like marketing/BillingOS UI renders through ContractSpec FormSpec/OperationSpec bindings as the primary path; bespoke design-system form/pricing control APIs are removed.

    maintainer

    contracts-spec adds marketing/billing FormSpecs (MarketingLeadCaptureFormSpec, MarketingEstimateInputFormSpec, BillingEstimateIntakeFormSpec) and side-effect-free operations (marketing.lead.capture, marketing.estimate.calculate, billing.estimate.prepare), plus formRef/hostExecutionBoundary on marketing presentation bindings. The validation issue code missing_presentation_operation_ref is renamed to missing_operation_ref_for_executable_binding, and missing_form_ref_for_form_primitive / invalid_host_execution_boundary are now emitted.

    integrator

    MarketingLeadCapture and MarketingPricingCalculator render form-like UI through the FormSpec renderer. MarketingPricingCalculator no longer accepts estimate/renderTotal/onEstimate and no longer computes pricing; callers pass formSpec plus a host/operation-owned total node. Hosts retain ownership of submission, pricing math, persistence, and provider execution.

    customer

    Security/safety boundary: no production provider, payment, CRM, PA, e-invoicing, or credentialed runtime path is added. Lead-capture declares PII metadata; estimate/billing queries are read-only and side-effect-free. BillingOS-adjacent estimate/quote vocabulary is fixture/example only.

  • contractspec-generative-core

    Add experimental graph artifact contracts and read-only graph/drift CLI workflows.

    maintainer

    Maintainers get additive, subpath-scoped graph artifact schemas and registry schema parity for policy/capability/job/translation items.

    customer

    CLI users can inspect graph artifacts and run read-only drift checks with schema-versioned JSON output.

  • contractspec-i18n-diagnostics-cli

    Expose reusable static translation diagnostics and add contractspec i18n check for CI-friendly catalog validation, including missing catalogs, missing keys, blank values, ICU syntax, placeholder parity, JSON output, and optional .contractsrc.json i18n defaults.

  • contractspec-i18n-runtime

    Add a ContractSpec-native production-grade translation runtime and optional i18next adapter.

    maintainer

    Translation specs now keep stable bundle identity separate from locale variants while the runtime owns formatter-backed ICU resolution, fallback chains, overrides, diagnostics, async loading, SSR snapshots, and optional downstream i18next projection.

    integrator

    Integrators should use the production translation runtime for server, React, React Native, and CLI resolution, and use the i18next subpath only as a downstream adapter with caller-owned ICU formatting configuration.

    customer

    Multilingual surfaces can now rely on BCP 47 locale variants, ICU formatting, deterministic SSR snapshots, and safer migration away from locale-suffixed translation bundle keys.

  • core-operation-approval-enforcement

    Add scoped operation approval enforcement across core, REST, and MCP runtimes.

    maintainer

    Operations can opt into fail-closed scoped approval enforcement before handlers run.

    integrator

    REST and MCP adapters can supply client-held approval receipts through common runtime context.

  • cross-platform-contracts-spec-navsurface

    Extend NavSurface with optional mobileRoute field and MobileRouteSchema discriminated union to express mobile navigation shape in the same contract that drives web navigation.

    maintainer

    NavSurface now accepts an optional mobileRoute field. Existing contracts without mobileRoute are unaffected — the field is optional and defaults to undefined.

    integrator

    If you extend NavSurface definitions, you may now add mobileRoute to express Expo Router navigation shape. Mobile consumers resolve path from surface.mobileRoute.path.

  • data-fetching-ecosystem-reset

    Collapse data fetching into one spec-first protocol + an in-house engine in the new contracts-runtime-core; remove the data-transmission packages; prove it end-to-end on entity-workspace.

    maintainer

    One canonical, I/O-free protocol lives in contracts-spec (QueryEnvelope, QueryResultEnvelope, createQueryKey, CacheStatus, InvalidationTag, ConflictPolicy, QueryConsistency, VersionToken, QueryState). The new contracts-runtime-core owns the in-house engine (Transport/reachability/storage ports, request dedup, durable offline queue + replay-on-reconnect, etag conflict detection + per-contract resolver registry, optimistic apply/rollback, auth-expiry pause/resume, GC, and PII-free observability) and the re-homed Collaboration* envelopes. data-transmission-spec and data-transmission-runtime are removed.

    integrator

    useContractQuery(envelope, opts) and useContractMutation(opts) bind to a DataEngine via ContractDataEngineProvider and return the canonical QueryState / mutation state with zero adapter into design-system components. REST and MCP are interchangeable Transport adapters carrying ContractResult<QueryResultEnvelope>; MCP decodes structuredContent first. provider-database.executeQuery emits a real versionToken on the proof entities; runtime-local feeds reachability into the engine via an input-port adapter. crdt-loro registers as the opt-in CRDT conflict resolver.

    customer

    Offline-capable reads and writes with explicit conflict resolution and recoverable auth-expiry (never a silent drop), surfaced through one consistent loading / stale / offline / conflict UI model.

  • data-table-overflow-policy

    Add contract-driven overflow behavior and typed DataView hints for shared DataView and DataTable surfaces.

    maintainer

    DataView contracts, renderers, scaffolds, and docs now expose overflow hints and typed data hints end-to-end, from spec authoring through table rendering and generated starter files.

    integrator

    OSS consumers can specify `overflow` on DataView fields or table columns, while the CLI and workspace scaffolds emit the new shape and richer format/filter metadata.

    customer

    Published data-view docs now describe overflow behavior, expansion mode, and generated table defaults more concretely.

  • data-views-collection-readiness

    Add production-ready collection defaults and renderer mode switching for DataView list, grid, and table specs.

    maintainer

    DataView collection specs now share view-mode, toolbar, pagination, and density defaults under view.collection.

    integrator

    DataViewRenderer can switch among allowed list, grid, and table projections while preserving existing specs and caller-controlled props.

    customer

    Generated data-view screens can expose modern list/grid/table switching, search, filters, pagination, and density controls.

  • data-views-personalization-integration

    Add preference-aware DataView collection defaults and personalization adapters.

    maintainer

    DataView contracts now expose neutral data-depth and collection personalization hints while keeping contracts-spec independent from personalization runtime code.

    integrator

    Apps can resolve preferred DataView mode, density, and data depth through personalization helpers and pass plain props to web/native DataViewRenderer.

    customer

    Collection screens can remember or infer list/grid/table mode and compact/detail preferences without duplicating DataView specs.

  • database-mutation-docs-llms

    Align database mutation docs, release-capsule guidance, and LLM-facing surfaces around governed domain-command writes.

    maintainer

    Release authors now have an explicit database mutation checklist covering contract/provider separation, domain-command authority, managed/BYOK posture, and LLM regeneration evidence.

    integrator

    Contracts-spec docs identify portable governed mutation descriptors while provider-database docs identify the adapter-owned SQL/Drizzle execution boundary.

    customer

    Database write guidance now emphasizes approved domain-command envelopes, idempotency, audit/replay evidence, and managed/BYOK production posture before adapters execute writes.

  • design-system-entity-surfaces

    Advance contract-driven entity surface foundations, gates, and consumer docs.

    integrator

    Consumers get a documented, contract-first path for entity listing, search, filter, detail, and edit workflows using EntityWorkspace for product shells or DataViewRenderer for lower-level renderer composition.

    maintainer

    Maintainers get entity-workspace inventory, public API gate, native parity matrix, package export alignment, DataView registry regression coverage, and workspace form-output resolution tests.

    agent

    Agent-facing docs and prompts now explain how to implement entity surfaces without overclaiming the planned EntityWorkspace facade or hard-coupling DataViewSpec to FormSpec.

  • drizzle-postgresql-monorepo-leverage

    Add portable database bindings and governed PostgreSQL provider leverage across ContractSpec core surfaces.

    maintainer

    Portable database contract metadata now threads through contracts-spec, RBAC, knowledge, data exchange, and provider-database without leaking adapter dependencies into runtime-agnostic libs.

    integrator

    Applications can describe governed database-backed views, lookups, policies, knowledge provenance, and SQL endpoints using portable metadata, then execute through provider adapters.

  • enterprise-agent-platform

    Add provider-adaptable multiplayer agents, governed self-improvement, continuous workers, self-maintaining APIs, and fail-closed enterprise qualification.

    integrator

    Compose the exact agent capabilities and enterprise controls required by a project, then choose or replace Vercel, Railway, Supabase, Docker, and custom profiles according to infrastructure, budget, security, and residency constraints.

    maintainer

    Qualify the exact digest-bound plan in each target environment and run multiplayer, improvement, maintenance, audit, recovery, and rollback workflows with live evidence.

  • entity-bound-form-projections

    Document entity-bound FormSpec projections, permissive intake debt, and the public guidance export.

    maintainer

    Maintainers have a stable package subpath and DocBlock for entity-first form projection, completion-debt, and intake-boundary guidance.

    integrator

    Integrators can distinguish permissive capture from strict readiness before wiring quick/full/message-intake forms into runtime or UI surfaces.

  • entity-workspace-row-card-rendering

    Improve EntityWorkspace row/card rendering with configurable leading icons, top-right status fields, and per-field label visibility overrides, then adopt the shared contract in the Agent Fleet example.

    maintainer

    Maintainers can now express richer row/card layouts through the shared EntityWorkspace row-card contract instead of screen-specific rendering code.

    integrator

    Integrators can configure leading icons, top-right status fields, and per-field label visibility overrides on EntityWorkspace consumers.

    customer

    Command-center surfaces can keep the existing visual style while rendering richer, quieter row/cards with shared EntityWorkspace primitives.

  • forms-autocomplete-combobox

    Improve FormSpec autocomplete rendering and resolver-backed search.

    maintainer

    FormSpec autocomplete docs now describe local and resolver-backed authoring without adding transport fields to the contract.

    integrator

    React FormSpec autocomplete resolvers receive query, dependency values, field name, and AbortSignal args while stale responses are ignored.

    customer

    Contract-rendered autocomplete fields now use an accessible editable combobox on web and show loading, empty, error, and selected states more reliably.

  • forms-email-field

    Add first-class FormSpec email fields with native renderer affordances.

    maintainer

    Maintainers can declare single-address email inputs with `kind: "email"` while keeping validation in the form model.

    integrator

    Integrators get native email input attributes through the existing form renderer driver slots without adding an EmailInput slot.

    customer

    Contract-driven email fields now use email keyboards, autofill, and browser email input behavior by default.

  • forms-layout-input-groups

    Add FormSpec layout hints, semantic field rendering, and portable text/textarea input-group addons.

    maintainer

    Maintainers can express richer FormSpec layout and field chrome without embedding renderer-specific UI.

    integrator

    Integrators can render contract forms with semantic legends, descriptions, errors, grid rows, colspans, and input addons through driver slots.

    customer

    Contract-driven forms can now present dense multi-column layouts and input adornments while preserving accessible field semantics.

  • forms-numeric-temporal-fields

    Add numeric and temporal FormSpec field kinds with shared renderer support for number, percent, currency, and duration inputs.

    maintainer

    FormSpec contracts and examples can now declare numeric and temporal field-specific formatting metadata without bespoke renderer code.

    integrator

    Custom form drivers can implement `NumberField`, `PercentField`, `CurrencyField`, and `DurationField` slots, while older drivers fall back to standard inputs.

    customer

    Contract-driven forms can now express budgets, completion ratios, currency amounts, and durations with consistent metadata and shared rendering defaults.

  • forms-password-rendering

    Add password-aware FormSpec rendering with current/new password manager hints and visibility toggles.

    maintainer

    Maintainers can declare current and new password fields as additive FormSpec text metadata.

    integrator

    Integrators can render password fields through an optional driver slot while older drivers fall back to masked inputs.

    customer

    Contract-driven password forms now mask values, expose a visibility toggle, and provide password-manager autocomplete hints.

  • forms-progressive-layout

    Add progressive FormSpec section and step layout metadata with shared React and design-system rendering support.

    maintainer

    Maintainers can declare progressive form sections or steps as additive FormSpec layout metadata while keeping the field list canonical.

    integrator

    Integrators can render long contract-driven forms through shared section or step layouts without custom per-form wrappers.

    customer

    Long forms can now be split into scannable sections or progressive steps, improving completion ergonomics without changing submitted data.

  • formspec-layout-scoped-filters

    Add mobile-safe FormSpec layout helpers and scoped DataView filters.

    maintainer

    Maintainers can add mobile-safe FormSpec layout metadata and first-class scoped filter contracts without breaking existing numeric layout semantics.

    integrator

    Integrators can reuse one DataView contract for generic and restricted list/search screens while locked filters stay out of user-editable URL state.

    customer

    Contract-driven forms can opt into mobile-safe layouts, and scoped listings now show non-removable locked filter chips by default.

  • graph-m5-ai-native-editing

    M5 AI-native graph editing — graph.edit / graph.refactor / graph.compose / graph.suggest_evolution + AiPairPanel

    maintainer

    Adds four new LLM-backed graph editing tools (graph.edit, graph.refactor, graph.compose, graph.suggest_evolution), a conversation-scoped memory model (InMemoryAgentMemory, TTL 60 min, 50-turn cap), and an AI pair editing panel (AiPairPanel + AiTurnTimeline) for web and native. All 10 template files (5 templates × 2 role variants) extended with optional `aiPair?` prop — no breaking change, falls back to existing P7 behavior when omitted. New exports in @lssm-tech/lib.contracts-spec/agent/commands: graphEdit.command.ts, graphRefactor.command.ts, graphCompose.command.ts, graphSuggestEvolution.command.ts, graphConversation.ts (GraphConversation, AiTurnState) New exports in @lssm-tech/lib.ui-kit-web/ui/graph: GraphTemplateM5Layer, AiPairPanel, AiTurnTimeline, AiDiffPreview, GraphTemplateM5Props, AiPairPanelProps, AiTurnTimelineProps New exports in @lssm-tech/lib.ui-kit/ui/graph: AiPairPanel.native, AiTurnTimeline.native, AiDiffPreview.native

    integrator

    Add `aiPair?: AiPairPanelProps` to any of the five graph templates to enable the M5 AI pair editing surface. Pass `session`, `onSubmit`, `onUndo`, `onRedo`, `costUsed`, and `costCap` props. Omit entirely to keep existing M3/M4 P7 behavior unchanged. All four M5 LLM tools are available via @lssm-tech/lib.contracts-spec/agent/commands. They require human confirmation before applying mutations — `AiSuggestionConfirm` is rendered automatically when `aiPair` is wired. Provider: claude-sonnet-4-6 (default). Budget ceilings in .omc/state/m5-p0-decisions.md.

    customer

    Graph views now support an AI pair editing panel: describe what you want to change in natural language, review the AI's suggestion, and apply or discard it with a single click. Full conversation history with per-turn cost display and undo/redo support. Works on web and mobile (iOS/Android). All changes require your explicit confirmation.

  • graph-m5-stability-stable

    Promote M5-shipped graph contracts from beta to stable.

    maintainer

    Stability promoted from `beta` to `stable` for all graph surfaces that shipped in M3/M4 and have now passed the full M5 quality gate (eval harness ≥95% JSON validity, ≥95% budget adherence, 100% mutation safety, designer review sign-off). Promoted symbols: AGENT_STABILITY = StabilityEnum.Stable (packages/libs/contracts-spec/src/agent/constants.ts) graph template files (5 templates × 2 variants, design-system) ui-kit-web graph primitives and template layers ui-kit native graph primitives No API surface changes — pure metadata promotion.

    integrator

    No breaking changes. All M3/M4 graph contracts (LayoutSpec, GraphFilterSpec, SavedView, Annotation, StorySlide, GraphExport, GraphAccessibilityProvider, the 4 graphOps tools, SSE GraphSubscription, Yjs MultiplayerTransport, all 5 graph templates × 2 variants) are now at stable stability. No migration required.

    customer

    Graph features (filters, saved views, annotations, layout, collaboration, AI tools, story mode, export) are now stable. These APIs will not have breaking changes without a major version bump and migration guide.

  • graph-timeline-primitives-milestone

    Graph & timeline primitives milestone — new DataViewKinds, UI primitives, EntityRegistry, and 3 reference examples.

    maintainer

    Milestone landing: DataViewKind extended with graph/timeline/timeline-graph; DataViewGraphSpec discriminated union with 5 source types; entities module (EdgeSpec, defineContractEdge, defineContractEntity Layer1+2, EntityRegistry); shared ui-kit-core prop interfaces and hooks (useAdaptiveGraphRenderer with SVG/Canvas/WebGL threshold ladder); GraphCanvas/Timeline/ TimelineGraph SVG primitives in ui-kit-web; .native.tsx parity in ui-kit; DataViewGraph/Timeline/TimelineGraph design-system renderers; DataViewRenderer split into 13 focused modules; 3 reference example implementations. Zero breaking changes.

    integrator

    New graph and timeline DataView kinds are available. Import DataViewGraphSpec and DataViewGraphSource from @lssm-tech/lib.contracts-spec. Use GraphCanvas, Timeline, and TimelineGraph from @lssm-tech/lib.ui-kit-web (or .native.tsx from @lssm-tech/lib.ui-kit). Build entity graphs with defineContractEntity + EntityRegistry from contracts-spec. See example packages for inline-op, two-op, and entity-declarative reference patterns.

  • harness-browser-verification

    Add OSS harness CLI verification with deterministic Playwright, optional agent-browser visual runs, auth profile refs, visual diff evidence, replay bundles, and core scenario success semantics.

    maintainer

    Harness scenarios now support typed browser actions, auth profile refs, visual-diff assertions, setup/reset hook execution, required evidence enforcement, success rules, and a shared CLI runtime used by both `contractspec harness eval` and `contractspec connect eval`.

    integrator

    Integrators can run OSS full-app verification locally or in CI with Playwright, agent-browser, or both, while writing replay bundles and browser evidence under `.contractspec/harness`.

    customer

    Browser, authenticated, and visual app flows can now be verified with replayable evidence before accepting provider or agent-generated work.

  • i18n-diagnostics-cli

    Expose reusable static translation diagnostics and add contractspec i18n check for CI-friendly catalog validation, including missing catalogs, missing keys, blank values, ICU syntax, placeholder parity, JSON output, and optional .contractsrc.json i18n defaults.

  • i18n-readiness-diagnostic-dx

    Add the report-only missing_translation static diagnostic to contracts-spec and an optional locale-override argument to the design-system useI18n hook for the en/fr/es readiness program.

    maintainer

    Translation diagnostics gain a missing_translation code (non-en value identical to en) emitted at info level (report-only), with checkMissingTranslation and missingTranslationAllowlist options. useI18n accepts an optional localeOverride for per-component locale resolution.

    integrator

    Surfaces can detect untranslated English stubs per catalog group (with a brand/code/cognate allowlist) without failing CI, and pass a per-component locale into useI18n to drive locale-correct value formatting.

  • integration-hub-uplift-phase-1-contracts

    Ship integrations Wave A reads + Wave B mutations (21 contracts) with full operation-contract metadata bar.

    integrator

    8 Wave A read contracts and 13 Wave B mutation contracts are available in the integrations operations namespace and registered in `integrationsOperationPartial`. Handlers can now bind through the registry.

    maintainer

    Four security-class flows (`credentials.rotate`, `credentials.revoke`, `secrets.unlink`, `secrets.reveal_once_audit_only`) ship as `stability: beta` with `compatibility:breaking-allowed-this-plan` tags. All other contracts are additive.

  • m2-contracts-spec-v2

    BREAKING: M2 contracts-spec — V1 workflow dual-shape adapter removed; DataViewGraphSpec, rich-reference, shared-entities, AgentTask V2 added.

    maintainer

    M2 adds three new modules and removes the V1 workflow dual-shape adapter. New: DataViewGraphSpec (sibling to DataViewSpec) with three DataViewGraphSource variants (inline-op, two-op, entity-declarative). New: shared-entities module — defineContractEntity, defineContractEdge, EntityRegistry, EntitySpec, EdgeSpec. New: rich-reference module — defineReferenceKind, RichReference<TPayload>, entity kind factory. Breaking: V1 WorkflowTask.id field removed (use taskId); V1 workflow runner dual-shape adapter removed (specs must use tasks[] + edges[] DAG shape).

    integrator

    BREAKING — if your workflow specs still use the V1 flat WorkflowTask shape (without tasks[] + edges[]), you must migrate to the M2 DAG shape before upgrading. BREAKING — any code reading WorkflowTask.id must change to WorkflowTask.taskId. New additive imports available: DataViewGraphSpec from data-views/graph-spec, defineReferenceKind from rich-reference, defineContractEntity from shared-entities.

    customer

    Graph data-views and workflow task trees now use a richer, more explicit structure. No direct customer-facing changes.

  • m3-contracts-spec-layout-spec

    M3 — LayoutSpec discriminated union replaces GraphLayoutKind string enum; additive graph subscription, export, annotation, story-mode, and AI operation contracts.

    maintainer

    Replace all usages of GraphLayoutKind string literals with the LayoutSpec discriminated union. Use layoutKindToSpec() shim for incremental migration.

    integrator

    DataViewGraph spec consumers must update layout field from string to LayoutSpec object. Additive contracts (GraphSubscription, export, annotation, story-mode, AI ops) have no required migration.

  • managed-companyos-dynamic-intelligence-planning

    Replace static Company Intelligence and OPA fixtures with authenticated, tenant-free dynamic surface descriptors and responsive managed templates.

    integrator

    Company Intelligence and Organization Planning pages now resolve authenticated authority per request and consume tenant-free server projections; no production route falls back to named-company fixtures.

    maintainer

    The additive surface descriptor accepts only a logical surface id and returns canonical route, route state, freshness, safe-read posture, action availability, and dependency blocks derived on the server.

  • managed-companyos-personal-team-contexts

    Add non-shareable personal CompanyOS contexts and atomic opaque personal/company/team/workspace selection with request-time authority proof.

    integrator

    Authenticated users can operate in a personal context without a company and can atomically select any server-returned company, team, and workspace through opaque references.

    maintainer

    Context tokens bind session, user, projection, nonce, version, and expiry; explicit direct/team workspace grants constrain enumeration and selection, and protected requests fail closed when nested authority is stale.

  • managed-companyos-production-operation-v2

    Add explicit v2 design-partner readiness, expert attestation, and founder approval contracts with server-derived authority, scoped durable receipts, pending evidence projection, replay linkage, and fail-closed health while preserving v1 unchanged. The release supports a private production-scoped pilot but does not activate a tenant or authorize broader production surfaces.

    maintainer

    The key-only CompanyOS registry remains pinned to the unchanged v1 operations. A new companyOsDesignPartnerOperationVersions registry exposes 1.0.0 and 2.0.0 side by side.

    integrator

    Adopt v2 when the API derives authority from verified server sessions and can commit durable business state, audit, command receipt, and evidence outbox intent atomically.

    customer

    Activate only one approved tenant/workspace and the invite/login, readiness, expert attestation, founder approval, and audit/evidence/replay journey. Keep GA, mobile, VPS worker, providers/outbound dispatch, real customer data, public SLA, and compliance claims deferred until separately approved.

  • marketing-contract-component-mapping

    Introduce ContractSpec-first semantic marketing presentation primitives, serializable runtime descriptors, a design-system renderer registry, and Managed CompanyOS proof adoption.

    integrator

    Marketing presentation bindings now use semantic primitive IDs and optional render target hints. Consumers with arbitrary component-name primitives must migrate to the supported primitive IDs and required payload shapes before relying on descriptor normalization or the design-system renderer.

    agent

    Author marketing contracts semantically first. Keep React component names as render hints only, keep descriptor normalization serializable, and route product proof pages through the shared design-system renderer registry instead of bundle-local component assembly.

  • nav-surface-contract

    Add navigation surface contract with role-aware registry and graph model.

    maintainer

    New navigation contract layer enables spec-first, role-aware navigation composition across apps and bundles with capability binding validation.

    integrator

    Bundles can now define navigation surfaces as NavSurfaceItemSpec entries, register them with NavRegistry, and resolve role-aware nav subsets via resolveForRoleMorph. Apps can render NavGraphSpec for power-user nav-map views.

    customer

    Applications support persona-based navigation with optional policy gates, density hints, and group-level hiding preferences.

  • nav-surface-mobile-extension

    Add optional mobile-extension fields to NavSurfaceItemSpec for Expo Router native navigation.

    maintainer

    NavSurfaceItemSpec gains three optional additive fields: tabBarIcon? (string), gestureHint? (NativeGestureHint), and parentGroupKey? (NavGroupKey). No existing field is modified or removed. isNavSurfaceItemSpec type guard updated to validate new optional fields when present. NativeGestureHint exported from navigation index.

    integrator

    Native Expo Router shells can now read tabBarIcon, gestureHint, and parentGroupKey from NavSurfaceItemSpec entries to drive tab-vs-stack navigation hierarchy, per-screen gesture configuration, and platform-specific tab bar icons from the NavRegistry — without per-screen hard-coding in _layout.tsx. Web shells ignore absent optional fields.

    customer

    No user-visible change. Internal navigation contract gains mobile-native fields enabling contract-driven navigation in the CompanyOS and CommunicationOS mobile apps.

  • notification-library-shell

    Move notifications to library-first contracts/runtime surfaces and add AppShell in-app notification affordances.

    maintainer

    Notification contracts now live in contracts-spec, reusable notification helpers live in lib.notification, and the old module remains as a compatibility shim.

    integrator

    Applications can adopt the new library imports without breaking existing module imports, then wire AppShell notification state through props.

  • ontology-company-work-graph

    Align CompanyOS work, surface, adaptation, and safety authoring on canonical ontology graph refs.

    maintainer

    Contracts-spec owns the canonical ontology graph vocabulary while RoleMorph and personalization consume ontology refs instead of defining competing taxonomies.

    integrator

    Migrate CompanyOS graph, DataView, RoleMorph, adaptive-event, behavior-signal, and fine-tuning traces to ontology refs with fail-closed safety metadata for high-impact work orders.

    customer

    Autonomous Work Order traces can explain work, surfaces, personalization, approvals, audit, redaction, and training evidence through one governed graph.

  • ontology-public-surface

    Document the intentional breaking ontology surface, Autonomous Work Order migration, safety invariant, and final release verification gate.

    maintainer

    Maintainers get one release packet for the ontology graph, Autonomous Work Order state machine, safety defaults, RoleMorph bridge, personalization bridge, and fine-tuning evidence gate.

    integrator

    Integrators must migrate high-impact graph mutations and adaptive operating surfaces to ontology refs and explicit safety evidence before treating work as committed.

    agent

    Agents get documented fail-closed defaults for Autonomous Work Order transitions and sanitized evidence-linked fine-tuning traces.

  • outcome-claims-contractspec

    Add evidence-backed OutcomeClaim contracts, validators, and public exports to contracts-spec.

    maintainer

    ContractSpec now owns the domain-neutral OutcomeClaim kernel with portable refs, evidence, provenance, review state, correction history, factories, and validators. The invariant is no evidence, no claim.

    integrator

    Import OutcomeClaim helpers from @lssm-tech/lib.contracts-spec/outcome-claims. Runtime emission belongs in lib.ai-agent and business projections belong in CompanyOS; the kernel remains provider-neutral and persistence-free.

  • phone-number-field-support

    Add first-class FormSpec phone input support with country detection, split outputs, and flag rendering.

    maintainer

    FormSpec phone contracts now expose input, output, country, and display configuration while keeping the schema-owned value model backward compatible.

    integrator

    Host renderers can set phone defaults through `createFormRenderer({ phone })`, while individual FormSpecs can choose object, E.164, or split linked outputs.

    customer

    Form-rendered phone fields can show country flags, detect countries from international input, and keep single or split controls synchronized.

  • pioneer-ai-self-improvement

    Add vendor-neutral AI self-improvement contracts and a mock-first Pioneer adapter.

    maintainer

    Maintainers get a thin AI-improvement evidence/policy envelope, package-owned bridge helpers, Connect evidence, and a targeted Pioneer adapter boundary.

    integrator

    Integrators can connect AI-improvement routes, evidence, policy decisions, promotion gates, rollback, and Pioneer job receipts without taking a dependency on Pioneer-specific core types.

    customer

    AI improvement workflows are safer by default because vendor export, auto-apply, and learning are controlled by explicit gates and replay evidence.

  • pwa-update-management

    Add PWA update management contracts and runtime helpers.

    integrator

    App developers can define PWA release policy once, override it per release, and consume a standard update-check API from the frontend.

    maintainer

    Maintainers get typed contracts, registry helpers, server evaluation helpers, and React prompt state helpers for PWA update workflows.

  • real-organizations-auth-recovery

    Ship server-authoritative organization and workspace contracts with API/web recovery runtime, and separate authentication readiness from the legacy ND pilot-admission tuple without weakening legacy route admission.

    integrator

    Adopt organization.list, organization.set-active, and workspace.list as additive operations. Use organization.set-active authorityToken for stale-request rejection while retaining authorityVersion as a compatibility field. Continue treating existing tenantId fields as compatibility assertions only. The API and browser adapters now bind these operations with ambient credentials, explicit no-store transport, and canonical authority revalidation.

    maintainer

    Authentication readiness validates auth, database, origin, cookie, and secret prerequisites. Keep the pilot tuple configured for the legacy ND route until persisted organization authority replaces that admission guard. The public composition requires credentialed exact-trusted-origin authority refresh with a private no-store policy, plus one lazy app-owned authority runtime reused until host shutdown. Corrective v1 semantics preserve every distinct provider Set-Cookie, bypass caches for post-write canonical revalidation, recover through membership listing before selection, and atomically audit only actual active-organization transitions. The API, Node response adapter, browser transport, and web switching runtime implement these semantics; live production migration, bootstrap, deployment, and cutover remain separately gated.

  • real-organizations-bootstrap-recovery

    Make the three-organization bootstrap resumable with durable phase receipts and truthful cross-connection interruption semantics.

    integrator

    Bootstrap receipts now expose the stable manifest revision, eight phases, and recovered phases as an additive CompanyOS contract.

    maintainer

    Operators can rerun the same manifest after interruption and must require all eight durable receipts plus three final bindings and grants before cutover.

  • real-organizations-canonical-seeding

    Seed the canonical LSSM, CompanyOS, and NDconsulting organization families from one contract-owned manifest with deterministic replay and redacted evidence.

    integrator

    Adopt the additive organization-seed subpath for exact identities, families, digest versions, expected counts, and redacted receipt DTOs. The existing organization-bootstrap:v1 revision and receipt semantics remain unchanged.

    maintainer

    Run migrate, canonical bootstrap, one manifest-wide seed, and complete verification. Do not supply live tenant/workspace selectors or treat receipt presence alone as replay proof.

    integrator

    Public profile drafts may represent intentionally inactive event metadata with destination mode unavailable; active unavailable events fail validation. Approved hybrid destinations remain HTTPS/Calendly-only.

  • relationship-detail-rendering

    Declare relationships on a DataView detail config and render related records inside EntityDetailPanel (web + native), reusing the per-field formatting/intelligent-action machinery.

    maintainer

    contracts-spec adds an additive DataViewSectionRelationship primitive (DataViewSections gains optional kind/relationship; fields relaxed to optional). design-system adds RelationshipSection/RelationSwitcher (web+native, no ARIA tablist roles) and an optional fieldActions prop on the shared DataViewList(.native) (default off; existing consumers byte-identical). WEB LIST ROW ELEMENT: rows with interactive descendants (fieldActions='auto' or a renderActions slot) are no longer a native <button> — to avoid nesting focusable controls they render as a plain clickable region plus a primary <button data-row-select> keyboard affordance, with actions as valid siblings; rows with no interactive descendants stay a native <button> (byte-identical). EntityWorkspace(web+native) and EntityDetailPanel/DataViewDetail forward optional relationData/getRelationData/onOpenRelated/dataViewRegistry props.

    integrator

    Authors declare relationships (cardinality, displayMode table/list/compact-list, inline fields or child specKey, limit, emptyState). Related records are host-supplied — embedded dataPath, a relationData map / getRelationData resolver, the RelationDataContext provider, or the new optional EntityWorkspace/EntityDetailPanel/DataViewDetail props (relationData, getRelationData, onOpenRelated, dataViewRegistry); the declared OpRef is executed by the host. Drill-in via onOpenRelated(relationKey, record); read-only when omitted. The design-system performs no I/O. NOTE for DataViewList consumers: rows that render per-field actions or a renderActions slot are now a clickable region with a [data-row-select] keyboard affordance instead of a wrapping <button> (no-actions rows are unchanged) — update any tests/selectors that assumed the row is always a <button>.

    customer

    Detail views can show related records (e.g. a client's addresses) inline, switch between relations or view all stacked, and open a related record — on web and mobile.

  • reviewready-app-submission-readiness-contracts

    Add the ReviewReady app-submission-readiness contract and event surface to contracts-spec.

    maintainer

    contracts-spec now ships an app-submission-readiness domain with 27 typed operation contracts, 3 domain events, keyed operation/event registries, shared domain constants, and additive subpaths. Contracts are secret-ref-only and rule contracts require official source provenance.

    integrator

    Downstream runtime, module, and app lanes can resolve ReviewReady operations and events through appSubmissionReadinessOperationRegistry and appSubmissionReadinessEventRegistry instead of reaching into individual contract files.

    customer

    ReviewReady gains an explicit, auditable contract layer for mobile submission readiness that never stores raw credentials and traces rule guidance to official store sources.

  • reviewready-store-integrations

    Add the ReviewReady provider capability registry and read-first App Store Connect / Google Play integration packages.

    maintainer

    contracts-spec adds an additive provider-capabilities subpath with a typed capability registry and lookup helper. Two new integration packages expose read-first, write-disabled App Store Connect and Google Play Android Publisher clients with deterministic mocks and secret-ref-only auth.

    integrator

    Downstream lanes can map provider results to canonical capability states via getProviderCapability, run audits with deterministic mock clients in CI, and only enable live store reads by supplying resolved secret refs. Fields the official APIs do not expose surface as manual-required, unsupported, or degraded capability results, never fake data.

    customer

    ReviewReady gains honest, source-cited store integrations that never store raw credentials and clearly mark which submission fields must be completed manually in the store console.

  • rich-code-diff-surfaces

    Add governed rich code/diff surfaces with references, redaction, RoleMorph, and personalization support. Historical wave-0 entry; the legacy CodeBlock/DiffBlock/ObjectReferenceHandler surfaces are superseded by the rich-reference foundation (see `rich-reference-breaking-release`).

    maintainer

    Historical wave-0 introduction of `rich-content`, `CodeBlock`, `DiffBlock`, `surface-runtime/rolemorph`, and `personalization/rich-code-preferences`. Superseded by the rich-reference foundation (this is kept for release-history continuity).

  • rich-reference-expo-safe-detector

    Replace Node crypto, create-hash, create-hmac, and global randomUUID usage outside apps with an internal Expo-safe crypto utility package.

    integrator

    Expo and browser-capable apps can import patched public surfaces without Metro resolving Node crypto, create-hash/create-hmac, cipher-base, or stream from hash, HMAC, UUID, cache-key, delegated-subject, or RichReference paths.

    maintainer

    Hashing, HMAC, and UUID generation now route through the zero-dependency @lssm-tech/lib.crypto-utils package; asynchronous Web Crypto signer paths remain explicit.

  • rich-reference-foundation

    Canonical RichReference subpath + ReferenceRuntime (split) + canonical serializer + detector + reference.resolve/detail queries + REST/GraphQL/MCP adapter wirings + S-9 agent surface (markdown envelope, agent-export passthrough, MCP tool descriptors, delegated/agent subject modes).

    maintainer

    Schema-first `defineReferenceKind` API (required `sensitiveFields`), process-global `ReferenceKindRegistry`, HMAC-signed `DenialToken`, four governance ports, six built-in kinds, canonical serializer, server-side detector with idempotent SHA-256 cache, strict-passthrough `toAgentJson`, symmetric markdown envelope. No runtime side-effects on import.

    integrator

    Import `@lssm-tech/lib.contracts-spec/rich-reference` for the foundation, `@lssm-tech/integration.runtime/rich-reference/{wire-rest,wire-graphql,wire-mcp}` for composition roots, and `@lssm-tech/lib.authos-runtime/subject/{agent,delegated}` for subject modes.

  • role-adaptive-companyos-app-shell

    Document the additive release posture and verification matrix for the contract-driven role-adaptive CompanyOS app shell.

    maintainer

    Maintainers get a lane-by-lane acceptance matrix for contract, resolver, personalization, UI, bundle, app, and release-evidence work.

    integrator

    Integrators can adopt the adaptive shell only after resolver invariants, import boundaries, and Managed CompanyOS proof evidence are attached.

    customer

    Managed CompanyOS shell adaptation remains evidence-backed, provider-neutral, and guarded by RoleMorph/personalization safety constraints.

  • roles-permissions-rbac-policy-system

    Add a shared roles and permissions policy system across contracts, RBAC evaluation, AppShell adaptation, and personalization suppression.

    maintainer

    Contract authors can declare shared static policy requirements while RBAC providers evaluate static, dynamic, and hybrid workspace-scoped grants.

    integrator

    AppShell navigation and personalization adapters can consume runtime policy decisions without becoming enforcement authorities.

    customer

    Workspace applications can hide or disable unauthorized navigation and avoid promoting denied fields while server-side policy decisions remain authoritative.

  • special-ops-review-decide-weekly-approve-contracts

    Add two additive Managed CompanyOS Special Ops operation contracts — specialOps.reviewCard.decide and specialOps.weeklyReport.approve — on the canonical production contracts surface to retroactively govern the already-shipped decideReviewCard and publishWeeklyReport handlers in api-application-monolith. The example special-ops-cockpit package stays a pure fixture demo.

    maintainer

    Two new defineCommand contracts live under packages/libs/contracts-spec/src/companyos/commands (reviewCardDecide.command.ts, weeklyReportApprove.command.ts), exported via the commands barrel and registered in companyOsOperationRegistry under keys specialOps.reviewCard.decide and specialOps.weeklyReport.approve. Each carries a same-file DocBlock (kind reference, visibility internal) linked via meta.docId and declares sideEffects.audit for the intended managed_companyos_audit_events emission.

    integrator

    The change is additive — new operation keys only; no existing contract, registry key, or schema changes. Special Ops handlers in api-application-monolith are now governed by production contracts. The example package (packages/examples/special-ops-cockpit) remains an unchanged, network/DB-free fixture demo.

  • theme-radius-design-system

    Add the public ContractSpec editorial radius scale and semantic aliases across contracts, design-system Tailwind bridges, app CSS parity, and bounded preview/toast migrations.

    maintainer

    Maintainers can rely on a documented radius taxonomy with parity tests across contracts, app CSS, and the design-system bridge.

    integrator

    Integrators receive additive `--radius-*` and `--ds-radius-*` aliases without losing existing `default`, `--radius`, or `sm/md/lg/xl/full` support.

  • theme-tailwind-bridge

    Add ThemeSpec light/dark modes and a design-system Tailwind bridge for CSS variables, presets, CSS text, and OKLCH color pass-through.

    maintainer

    Maintainers can keep ThemeSpec as the source of truth while exposing Tailwind variables and runtime theme modes from the design-system package.

    integrator

    Integrators can resolve ThemeSpec tokens for light or dark mode, consume a Tailwind preset, or serialize CSS text without adding a required generation step.

    customer

    Product surfaces can use ThemeSpec-backed light/dark themes with OKLCH colors while keeping existing Tailwind semantic classes such as `bg-primary` and `text-foreground`.

  • translation-catalog-sharding-ssr-additive

    Add factory-stack SSR snapshot/hydration, loader shard scoping, RouteShardManifest, and parity diagnostics extensions for translation catalog sharding + SSR.

    maintainer

    BREAKING: createTranslationRuntime engine deleted from translation-runtime (subpaths ./runtime, ./registry, ./runtime-helpers removed; preference-override-layer construction dropped). createRuntimeTranslationResolver removed from design-system. Factory stack gains snapshot/hydration/load surface (I18nFactorySnapshot, I18nFactoryHydrationPayload, createI18nFactoryFromHydrationPayload, collectLocaleScopedCatalogs, resolveLocaleWithin). Parity diagnostics gain unsupported_locale_claim, manifest_spec_key_missing, validateManifestCatalogDrift, ManifestRouteEntry. Loader gains specKeys?, computeShardDelta, loadShardDelta. RouteShardManifest + defineRouteShardManifest authored in app layer. resolveTranslationPreferenceContext (context/precedence resolution) is preserved.

    integrator

    BREAKING: remove all createTranslationRuntime call sites; migrate to createI18nFactory + hydrationPayload() + createI18nFactoryFromHydrationPayload for SSR. Replace createRuntimeTranslationResolver with createTranslationResolver in design-system. Use loadShardDelta for route-level lazy loading. Use validateManifestCatalogDrift to catch manifest↔catalog drift in CI. RouteShardManifest defines route→specKey tier bindings in the app/bundle layer. Preference-override-layer construction has no replacement; drop it.

    customer

    Translation shards are now scoped per route for faster initial loads and incremental navigation fetches with no hydration mismatch.

  • typed-result-system

    Add a canonical typed result system for ContractSpec success and failure propagation across operations, workflows, jobs, server adapters, MCP, GraphQL, and React clients.

    maintainer

    Maintainers can declare operation, workflow, and job result catalogs and have runtime registries enforce custom success and failure outcomes.

    integrator

    Integrators get consistent result mapping for REST, NextResponse, Nest-compatible filters/interceptors, GraphQL extensions, MCP tool errors, and React client parsing.

    customer

    Product surfaces can rely on consistent success metadata, retry hints, field issues, and Problem Details-style errors across API, job, workflow, and frontend boundaries.

  • unified-contractspec-database-runtime

    Unified ContractSpec database runtime: createDatabaseRuntime() preset (pooling, zero-config observability, RLS tenant scoping, AuthOS principal carriage, governed resolvers) plus a typed N+1-safe relational read path, a spec-first generated Drizzle schema, and an SSR prefetch→hydrate bridge. Fully additive.

    maintainer

    New server-only runtime-managed/database subpath exports createDatabaseRuntime returning { provider (tenant-scoped), governedQuery, governedMutation, withTenant, close }. provider-database gains governed-relational-read (LEFT JOIN LATERAL + json_agg), governed-sql-guards, typed-read, and a generated Drizzle schema + manifest. contracts-spec adds database.query.relational@1.0.0, defineDatabaseTable + databaseTables, and database.query/database.mutation SignalSpecs; QueryState.pageInfo + CacheEntry.pageInfo are additive. providers-impls deprecates the raw createDatabaseProvider hatch (guard test added). database.query.readonly@2.0.0 and governed-read.ts are behaviorally unchanged.

    integrator

    Adopt createDatabaseRuntime() from @lssm-tech/integration.runtime-managed/database (server-only) for pooled, observability-bound, tenant-scoped data access with pre-bound governed resolvers. Use withTenant(tenantId) on known-tenant server paths (the top-level provider fails closed without a tenant). For SSR, prefetchGovernedQuery → dehydrateGovernedQuery → HydrationBoundary from @lssm-tech/lib.presentation-runtime-next/data, building the client engine over the same CacheStore via createDataEngine({ localOffline: 'offline-capable' }). useContractQuery now exposes hasNextPage + fetchNextPage() (cursor default; offset unchanged).

    customer

    Database-backed pages load faster: server-prefetched reads hydrate on the client with no second fetch, lists paginate by cursor, and every query is automatically tenant-isolated and observable.

  • unified-query-stack-cursor-read

    Add the first unified query stack across contracts, runtime client cache boundaries, governed provider reads, and EntityWorkspace local-vs-remote query ownership.

    maintainer

    Maintainers get a canonical contract-owned query envelope and DataView cursor descriptor that package surfaces can share instead of reimplementing search, filter, sort, pagination, and offline policy shapes.

    integrator

    Integrators can execute governed cursor reads through provider-database while using runtime client cache helpers without binding public APIs to TanStack implementation types.

    customer

    EntityWorkspace hosts can opt into remote query ownership so server-filtered results are not double-filtered locally on web or native.

  • versioning-release-system

    Add versioning-backed release capsules, generated patch notes, and guided upgrade flows.

    maintainer

    Release communication is now generated from versioning-backed release capsules and enforced on release branches.

    integrator

    Guided upgrade plans and agent prompts now come from generated upgrade manifests instead of ad hoc prose.

    customer

    Web changelog consumers can prefer generated release manifests while older package changelogs remain supported as fallback.

Deprecations

  • - @lssm-tech/lib.data-transmission-runtime — removed; absorbed into the contracts-runtime-core engine + the crdt-loro conflict resolver.
  • - @lssm-tech/lib.data-transmission-spec — removed; absorbed into contracts-spec (protocol) + contracts-runtime-core (engine, Collaboration* types).
  • - `FieldSpec.wrapper.orientation` remains supported but should be replaced by `FieldSpec.layout.orientation` in new specs.
  • - contracts-runtime-client-react ./query-client subpath — removed (deleted file).
  • - contracts-runtime-client-react helpers buildContractQueryKey, getContractQueryCacheKey, ContractQueryStorage*, ContractQueryCacheRecord, readWarmContractQueryCache, readContractQueryCache, writeContractQueryCache, canRunContractMutationOffline, assertContractQueryMutationPolicy, and the buildContractQueryEnvelopeKey alias — removed; the engine owns cache-key/storage/policy.
  • - DataView graph mutations without policy/authority/approval/audit/redaction/evidence/risk metadata are migration targets for fail-closed ontology safety refs.
  • - Existing tenantId fields remain assertion aliases and must not select authorization or RLS scope; derive authority from verified activeOrganizationId, current membership, and the enabled binding.
  • - id: graph-layout-kind-string-enum; name: GraphLayoutKind string enum; reason: Replaced by LayoutSpec discriminated union for richer per-layout configuration; migration: Use layoutKindToSpec(kind) shim or construct LayoutSpec objects directly
  • - id: package-local-high-impact-graph-mutations; summary: High-impact work/order transitions must not be represented by package-local DataView or graph mutation records without ontology refs and safety evidence.; replacement: Autonomous Work Order graph/state-machine records with ontology refs and safety invariant fields.
  • - MANAGED_COMPANYOS_LIVE_SEED_TENANT_ID and MANAGED_COMPANYOS_LIVE_SEED_WORKSPACE_ID are not forward live-seed inputs; the contract manifest owns all organization, tenant, and workspace targets.
  • - Prefer `ContractSpecError`, `createContractError`, and `contractFail` from `@lssm-tech/lib.contracts-spec/results`; `@lssm-tech/lib.error` remains as a compatibility bridge for existing `AppError` users.
  • - Runtime-local copies of the adapter-key union are deprecated; import the canonical identity from `@lssm-tech/lib.contracts-spec/runtime-adapters`.
  • - The `@lssm-tech/module.notifications` package remains import-compatible for this release, but new code should import contracts from `@lssm-tech/lib.contracts-spec/notifications` and runtime helpers from `@lssm-tech/lib.notification`.
  • - The standalone release domain under `@lssm-tech/lib.contracts-spec/release` is deprecated in favor of versioning-owned release metadata.
  • - Treating a local child process as a production isolation boundary is unsupported; the local sandbox adapter is a development fixture only. Select the Docker adapter when the production containment suite and deployment prerequisites are satisfied.
  • - Unconstrained CompanyOS graph node/edge type strings are migration targets for ontology node and edge refs.
  • - V1 workflow runner dual-shape adapter — removed; migrate to DAG shape (tasks[] + edges[]).
  • - WorkflowTask.id (V1) — removed; use WorkflowTask.taskId.

Migration guide

  • Enable the new Connect adoption engine in workspace config

    ContractSpec workspaces can now opt into family-aware reuse guidance and local catalog sync through `connect.adoption`.

    When: When a workspace uses `contractspec init --preset connect`, Connect hooks, or custom `.contractsrc.json` management.

    1. Add or review `.contractsrc.json > connect.adoption`.
    2. Run `contractspec connect adoption sync --json` to mirror the local catalog.
    3. Route uncertain reuse decisions through `contractspec connect adoption resolve --family <family> --stdin`.
  • Use the expanded authoring-target surface in CLI and VS Code flows

    Shared workspace discovery and IDE/CLI create flows now recognize additional contract families beyond the original core set.

    When: When using `contractspec create`, VS Code create commands, or custom authoring-target integrations.

    1. Use the new create targets for capability, policy, translation, visualization, job, agent, product-intent, harness scenario, and harness suite scaffolds where appropriate.
    2. Update any custom file-name or directory assumptions to rely on shared authoring-target helpers instead of hard-coded extensions.
  • Handle the additive EVE adapter identity

    Required

    The closed AgentRuntimeAdapterKey union gained `eve` in both AgentSpec and WorkflowSpec.

    When: When a consumer exhaustively switches over runtime adapter keys.

    1. Add an `eve` branch or return an explicit unsupported/loss diagnostic.
    2. Import the adapter identity from the canonical contracts-spec runtime-adapters subpath.
    3. Keep EVE SDK types and imports inside the integration.eve composition boundary.
  • Preserve the sandbox isolation claim boundary

    Required

    The local-process adapter proves policy wiring and redaction, not operating-system containment.

    When: Before selecting an AgentSandboxPort implementation for production.

    1. Keep shell, network, mounts, and secrets deny-by-default.
    2. Require containment-suite evidence before advertising an adapter as isolation-conformant.
    3. Record unsupported capabilities and mapping losses instead of counting them as success.
  • Import agentic controls from the explicit subpath

    Required

    AIP mapping controls are opt-in safety contracts, not root-barrel exports.

    1. Import AIP controls from `@lssm-tech/lib.contracts-spec/agentic-interaction`.
    2. Do not add agentic-interaction to the contracts-spec root barrel.
    3. Treat production sends, credentials, arbitrary shell execution, and CompanyOS high-impact bypass signals as blocked or approval-required before any runtime executes work.
  • Route message-originated commands through the command inbox

    Required

    CommunicationOS commands persist as review evidence with `canExecute: false`.

    1. Use `createCommunicationCommandInboxItem` from `@lssm-tech/lib.communication-runtime/command-inbox` or the module compatibility subpath.
    2. Read `item.status`, `item.aipControlRefs`, and `item.companyOsBridge` as review evidence only.
    3. Keep outbound sends and CompanyOS high-impact execution behind explicit human/policy approval outside the command-inbox packet.
  • Apply durable Company Intelligence API controls

    Required

    Apply additive migration 0027 before enabling the authenticated API in production.

    1. Apply 0027_company_intelligence_api_runtime.sql through the digest migration ledger.
    2. Grant the runtime role only SELECT, INSERT, and UPDATE on the two API state tables.
    3. Prove restart replay, budget continuity, tenant-key isolation, and FORCE RLS on PostgreSQL 15.
  • Apply tracked approval migration 007

    Required

    Validate and denormalize approval-event provenance, then normalize only valid v1 values.

    When: The approval ledger contains migration 006 but not migration 007.

    1. Back up or capture the approval schema and redacted row-count evidence.
    2. Apply tracked migrations through `006a_reviewer_authority_runtime` without changing prior ledger IDs.
    3. Dry-run `contractspec connect review provision-authority` with explicit role, issuer actor, issuer authorization fingerprint, reviewer email, reviewer public-key fingerprint, authority ref, and proof ref; then apply with all seven exact confirmations and require idempotent `existing` replay.
    4. Materialize the exact migration-007 Connect packet against migration 006.
    5. Enroll the human reviewer public key, resolve the signed challenge, and verify replay.
    6. Verify the event schema has either none or all three provenance columns; partial shapes fail closed.
    7. Run `contractspec connect review migrate 007_approval_canonicalization_v1_integer --json` and inspect the dry-run result.
    8. Re-run with `--apply --confirm-migration 007_approval_canonicalization_v1_integer` under the migration-owner database role.
    9. Re-run the apply command and require status `existing` before remaining bootstrap work.
  • Structured card fields are additive

    Consumers that only read card title, description, and href do not need to change. Consumers that render richer contract pages can display cards[].fields as labelled rows and cards[].iconKey through an icon registry with a fallback.

    1. Continue accepting existing card title/description/href values.
    2. Render cards[].fields when present for scannable package or pattern cards.
    3. Resolve cards[].iconKey through the host icon set and keep a safe fallback for unknown keys.
  • Configure approval migration and runtime roles

    Required

    Apply the additive migrations with an owner distinct from the runtime role.

    When: Enabling durable PostgreSQL-backed local Connect review.

    1. Run migrations 001 through 004 in order with the migration-owner role.
    2. Ensure the runtime role owns no protected tables and has no BYPASSRLS capability.
    3. Bind the non-owner database role to its tenant and workspace using the separately authorized migration/admin context; runtime input cannot choose or mutate this binding.
  • Enable ContractSpec Connect in the workspace config

    Turn on the Connect adapter flow before relying on task-scoped context, review, replay, or evaluation artifacts.

    When: When a workspace wants coding-agent gating, local review packets, or replay/eval evidence tied to file and command mutations.

    1. Add or merge a `connect` section in `.contractsrc.json` with `enabled: true` and the storage paths that should hold Connect artifacts.
    2. Route risky edits or shell execution through `contractspec connect plan` and `contractspec connect verify` so decisions, review packets, and replay bundles are captured.
    3. Use the generated docs and exported agentpacks metadata so downstream agent tooling sees the same Connect contract surface as the CLI.
  • Update custom app-config DTO callers to key-based refs

    Shared app-config authoring DTOs and templates now use `key`-based spec references instead of older `name`-based helper fields.

    When: When custom tooling imports `AppBlueprintSpecData`, `AppConfigMappingData`, or related route reference DTOs from workspace or bundle packages.

    1. Replace `name` fields with `key` for app-config spec references.
    2. Replace `guardName` and `experimentName` with `guardKey` and `experimentKey` in route DTOs.
    3. Keep versions as semver strings rather than numeric literals.
  • Adopt `defineTheme(...)` for new theme specs

    Theme authoring now has a canonical helper and authored-validator support.

    When: When creating or refreshing theme specs used by generators, docs, or CI validation.

    1. Import `defineTheme` from `@lssm-tech/lib.contracts-spec/themes`.
    2. Prefer `defineTheme({...})` for new theme specs, while keeping existing `ThemeSpec` object literals valid.
    3. Add `validateThemeSpec` or `assertThemeSpecValid` to CI or publish-time checks where theme correctness matters.
  • Add `aliases` to operation meta when renaming a key

    Aliases are opt-in. Add them only when you're renaming an operation's canonical key and want consumers to keep working without code changes.

    1. On the renamed operation, set `meta.aliases: ['old.key.name']`.
    2. Document the alias in your changeset so consumers can drop it on the next major after they've migrated their direct callers.
    3. Avoid alias→alias chains: aliases should always point at a current canonical key, not at another alias.
  • Import control-plane skill signing helpers from direct subpaths

    Required

    Replace broad root or `control-plane` imports for signing and verification helpers with `@lssm-tech/lib.contracts-spec/control-plane/skills`, `/signer`, or `/verifier`.

  • Review sticky experiment bucket assignment changes

    Required

    Sticky experiment variants may rebucket because the evaluator now uses a browser-safe deterministic hash instead of Node SHA-256.

  • Render marketing form-like UI through FormSpec/OperationSpec bindings

    Required

    MarketingLeadCapture and MarketingPricingCalculator now render form-like UI through the design-system FormSpec renderer as the primary path. Bespoke control/pricing prop APIs are removed; the design system no longer owns business pricing, submission, or provider execution.

    1. Replace bespoke MarketingLeadCapture `fields`/raw control props with a `formSpec` (e.g. `MarketingLeadCaptureFormSpec`) and host-owned operation execution.
    2. Replace MarketingPricingCalculator `estimate`/`renderTotal`/`onEstimate` with `formSpec` (e.g. `MarketingEstimateInputFormSpec`) plus an operation-owned `total` ReactNode rendered in the aria-live region; `sliders` remains an optional legacy visual path only.
    3. Update marketing presentation bindings that declare form-like primitives to include a `formRef`, and executable bindings to include an `operationRef` with a non-`render-only` `hostExecutionBoundary`.
    4. Update consumers matching the removed validation issue code `missing_presentation_operation_ref` to `missing_operation_ref_for_executable_binding`, and handle the new `missing_form_ref_for_form_primitive` and `invalid_host_execution_boundary` codes.
    5. Re-run contracts-spec and design-system marketing tests after migration.
  • Separate stable bundle keys from locale variants

    Prefer `meta.key: "bundle.messages"` with `locale: "fr-FR"` over stable keys that encode locale suffixes.

    1. Move locale identity into `TranslationSpec.locale`.
    2. Keep fallback declarations on locale variants through `fallback` or `fallbacks`.
    3. Re-run translation validation after migration.
  • Configure ICU formatting when rendering through i18next

    The i18next adapter exports ContractSpec ICU messages intact and does not make i18next canonical.

    1. Import adapter helpers from `@lssm-tech/lib.translation-runtime/i18next`.
    2. Initialize a caller-owned i18next instance with generated resources and `keySeparator: false`.
    3. Configure an ICU-capable i18next format plugin before rendering ICU plural/select/selectordinal messages through i18next.
  • Migrate off data-transmission and the legacy client query helpers

    Required

    Move imports and hooks onto the canonical contracts-spec protocol and the contracts-runtime-core engine.

    When: When a package imported @lssm-tech/lib.data-transmission-spec / -runtime, the contracts-runtime-client-react ./query-client subpath, or the removed cache-key/storage/policy helpers.

    1. Replace @lssm-tech/lib.data-transmission-spec / -runtime imports with @lssm-tech/lib.contracts-spec/query + @lssm-tech/lib.contracts-runtime-core.
    2. Replace useContractQuery(execute, { input }) with useContractQuery(envelope, { enabled?, ctx? }) under a <ContractDataEngineProvider engine={createDataEngine({ transport })}>; read canonical QueryState fields (status, fetchStatus, data, error, cacheStatus, isStale, isOffline, conflict, versionToken) directly.
    3. Replace useContractMutation(execute) with useContractMutation({ ctx? }) and call mutate(request, { optimistic? }); read the canonical mutation state (status, data, problem, conflictOutcome, isPending).
    4. Drop all ./query-client imports; cache-key, storage, and offline policy now live in the engine.
    5. Build envelopes with normalizeQueryEnvelope; register crdt-loro via the engine conflict-resolver registry where CRDT merge is required.
  • Add explicit overflow behavior where defaults are not enough

    Existing tables keep working, but long prose, markdown, and detail-heavy columns can now declare their intended behavior.

    When: When a table column needs wrapping, row-expansion detail, initial hiding, or unmodified rendering.

    1. Set `overflow` on `DataViewField` for behavior shared by every table using that field.
    2. Set `overflow` on `DataViewTableColumn` when a specific table needs to override the field default.
    3. Use `expand` for compact rows with full detail in row expansion, and `hideColumn` for low-priority columns that should start hidden when column visibility is enabled.
  • Keep database writes behind governed domain commands

    Treat portable mutation descriptors as domain-command envelopes and execute them only through provider adapters that enforce policy, idempotency, audit, replay, and expected write-set evidence.

    1. Define portable read/write descriptors in contracts-spec without importing Drizzle or provider runtimes.
    2. Bind `database.mutation.execute@2.0.0` descriptors to the owning domain command before provider execution.
    3. Execute SQL/Drizzle work through `@lssm-tech/integration.provider-database/governed-mutation` or another adapter with equivalent governance hooks.
  • Choose EntityWorkspace for product shells and DataViewRenderer for lower-level composition

    Build entity surfaces with DataViewSpec, EntityWorkspace product-shell chrome, DataViewRenderer lower-level rendering, host edit slots, AdaptivePanel, RichRef, personalization, and RoleMorph adapters.

    1. Open `/docs/guides/entity-surfaces` for the current consumer implementation path.
    2. Author one canonical `DataViewSpec` for list, grid, table, search, filter, pagination, action operation refs, source mutations, and personalization defaults.
    3. Use native-paired `EntityWorkspace` for product-shell entity surfaces and `DataViewRenderer` for lower-level collection rendering; treat `DataViewManagementShell` as a compatibility shell until its adapter migration is integrated.
    4. Treat card click, row click, and explicit detail actions as the same open-detail semantic event in host code.
    5. Resolve edit/create UI through `FeatureModuleSpec.opToPresentation`, feature forms, DataView source mutations, DataView action operation refs, and then a host `renderFormSlot` fallback with a residual-risk note.
    6. Render reference-like fields with `RichRef` from `@lssm-tech/lib.ui-kit-web/rich-ref`; route host-owned detail/edit overlays through `AdaptivePanel`.
  • Preserve qualified FormSpec keys in generated workspace output

    Hosts that rely on workspace-generated forms should expect dotted FormSpec keys such as `profile.edit` to resolve to qualified filenames such as `profile-edit.form.*`.

    1. Re-run workspace build generation after changing form keys.
    2. Verify generated form implementation filenames match qualified FormSpec identifiers.
  • Adopt entity-first form projection guidance

    Use entities for canonical identity, forms for renderable projections, and completion debt for skipped intake fields.

    1. Import guidance from `@lssm-tech/lib.contracts-spec/forms/entity-bound`.
    2. Keep `EdgeSpec` for true entity relations and use form-specific bindings for part captures.
    3. Preserve permissive quick/message intake by recording missing fields as completion debt.
  • Keep existing text email fields as-is

    Existing `kind: "text"` fields with email input hints continue to render normally.

    1. No migration is required for existing text fields.
    2. Prefer `kind: "email"` for new single-address email fields.
  • Keep email validation in the model

    `kind: "email"` only describes rendering intent; strict validation remains schema-owned.

    1. Use `z.string().email()` or the existing schema email scalar for email format validation.
  • Keep existing forms as-is

    Existing forms render exactly as before unless they opt into `layout.flow`.

    1. No migration is required for forms without `layout.flow`.
  • Use FormSpec layout hints for dense forms

    New multi-column forms should use `FormSpec.layout`, `group.layout`, and `field.layout.colSpan`.

    1. Add `layout.columns` at form or group level.
    2. Use `field.layout.colSpan` for fields that should expand across columns.
  • Use input-group addons for text fields

    New input addons should use `inputGroup.addons` on text and textarea fields.

    1. Add `inputGroup.addons` to text or textarea field specs.
    2. Resolve icon keys in the host driver through the `InputGroupIcon` slot.
  • Use dedicated numeric field kinds instead of generic text inputs

    New field kinds provide stronger semantics and formatting metadata for finance and operations forms.

    1. Replace ad hoc numeric `text` fields with `number`, `percent`, `currency`, or `duration` where the schema intent is known.
    2. Set `format` metadata when locale, precision, currency display, or duration display needs to be explicit.
  • Keep existing text fields as-is

    Existing text fields and custom driver slots remain compatible.

    1. No migration is required for non-password text fields.
  • Mark password fields explicitly

    Prefer `text.password.purpose` for password fields instead of renderer-specific `uiProps.type`.

    1. Use `password: { purpose: "current" }` for existing-password entry.
    2. Use `password: { purpose: "new" }` for new-password creation or reset fields.
  • Add section or step flow metadata to long forms

    Use `layout.flow.sections` to group existing fields by immediate field name.

    1. Add `layout.flow.kind: "sections"` when all sections should remain visible.
    2. Add `layout.flow.kind: "steps"` when the renderer should show one section at a time.
    3. Keep field definitions in `FormSpec.fields` and reference them through section `fieldNames`.
  • Keep existing numeric layouts as-is

    Existing `layout.columns: 2` contracts continue to render as base two-column layouts.

    1. No migration is required for existing numeric column specs.
    2. Use `responsiveFormColumns(...)` in new specs that should collapse to one mobile column.
  • Move fixed list constraints into DataView filter scope

    Use `view.filterScope.locked` for non-removable list constraints such as category-scoped posts.

    1. Keep user-editable filter definitions in `view.filters`.
    2. Put removable defaults in `view.filterScope.initial`.
    3. Put non-removable constraints in `view.filterScope.locked`.
  • Wire mutation handlers through the contracts-spec registry. The four `breaking-allowed-this-plan` contracts will graduate to `stable` only after Phase 4 of the integration-hub-uplift plan; treat their schema as frozen-as-spec but not frozen-as-policy.

    Required

    Wire mutation handlers through the contracts-spec registry. The four `breaking-allowed-this-plan` contracts will graduate to `stable` only after Phase 4 of the integration-hub-uplift plan; treat their schema as frozen-as-spec but not frozen-as-policy.

  • Replace WorkflowTask.id with WorkflowTask.taskId

    Required

    The V1 `id` field on WorkflowTask has been removed. All consumers must switch to `taskId`.

    1. Find all references to .id on WorkflowTask objects: grep -r 'WorkflowTask' src/ | grep '\.id'
    2. Replace task.id with task.taskId in workflow specs, runners, and tests.
    3. Run: bun x tsgo --noEmit
    4. Run: bun test
  • Migrate workflow specs to DAG shape (tasks[] + edges[])

    Required

    The V1 flat WorkflowTask shape (single-level task list without explicit edges) is no longer supported. All workflow specs must declare `tasks: WorkflowTask[]` and `edges: WorkflowEdge[]`.

    1. Replace flat task arrays with explicit tasks[] + edges[] DAG shape.
    2. Each WorkflowTask must have: taskId, label, runIf? (optional), and any domain fields.
    3. Each WorkflowEdge must have: id, from (taskId), to (taskId), and optional condition.
    4. Validate DAG is acyclic using validateWorkflowDag() from @lssm-tech/lib.contracts-spec.
    5. Run: bun x tsgo --noEmit -p packages/libs/contracts-spec/tsconfig.json
  • Replace GraphLayoutKind string with LayoutSpec

    Required

    Update every site that assigns a string to the layout field of DataViewGraphConfig or GraphCanvasProps.

    1. Import LayoutSpec from '@lssm-tech/lib.contracts-spec/data-views'.
    2. Replace bare strings ('dag', 'radial', 'force', 'time-axis') with the matching LayoutSpec object ({ kind: 'dag' } etc.).
    3. Optionally call layoutKindToSpec(oldStringValue) for bulk migration during a transition period.
  • Apply the personal and team context authority migrations

    Required

    Apply forward migrations 0029 and 0030 before deploying the context routes or enabling the production shell selector.

    1. Apply migration 0029 followed by migration 0030.
    2. Deploy the context authority routes and repository runtime.
    3. Enable the production shell selector only after the migrations complete.
  • Resolve the explicit v2 design-partner operations

    Adopt the versioned v2 registry while preserving the unchanged v1 key-only registry for existing consumers.

    1. Resolve each operation through companyOsDesignPartnerOperationVersions[key]['2.0.0'].
    2. Keep the v1 key-only registry until every generated client and handler has migrated.
  • Remove client-supplied mutation authority

    Required

    Derive every authority and evidence reference from the verified server session and transaction.

    1. Stop sending principal, role, evidence receipt, replay packet, prerequisite attestation, or correlation authority in request bodies.
    2. Preserve tenant, workspace, packet-version, receipt, and correlation scope through the tenant transaction.
  • Record every private-pilot activation decision

    Required

    Treat implementation readiness as separate from approval to activate the first tenant.

    1. Approve legal tenant/workspace names, named roles, data authority, residency, and exact domains/cookie parent.
    2. Configure web https://www.companyos.run, API/auth https://api.companyos.run, and cookie parent .companyos.run exactly.
    3. Configure the API-owned admitted tenant, workspace, and scenario membership; do not accept browser-selected scope.
    4. Fail closed when any admitted membership identifier is missing, blank, or malformed outside test/development.
    5. Namespace idempotency with the exact packet version and verified principal before persistence.
    6. Run the credential-parameterized deployed journey only with explicit authorization and the complete secret-store prerequisite set.
    7. Verify expected authenticated user and tenant identities, then poll receipt-id evidence and correlation-id replay until projected.
    8. Assert proof reads are immutable and verify the degraded web UI on an authorized degraded deployment.
    9. Approve database, backup, restore, support, SLO, incident, rollback, deployed-journey, cron, and kill-switch evidence.
    10. Confirm every deferred surface in docs/managed-companyos-private-pilot.md remains disabled or reference-only.
  • Migrate marketing presentation bindings to semantic primitive IDs

    Required

    Replace arbitrary primitive strings with supported semantic IDs and move direct React component names into render target hints.

    1. Replace `primitive: 'MarketingHero'` with `primitive: 'hero'` and `renderTargetHint: 'MarketingHero'`.
    2. Use supported primitive IDs: `announcement-bar`, `hero`, `icon-grid`, `cta-band`, `prose`, `feature-tabs`, `lead-capture`, `timeline`, `trust-badges`, and `video`.
    3. Add `section.presentation.payload` for structured primitives such as feature tabs, lead capture, timeline, trust badges, announcement bars, and video.
    4. Add CTA refs for CTA-oriented primitives and `accessibleLabel` plus `transcriptHref` for video payloads.
    5. Re-run marketing contract validation and descriptor/render tests after migration.
  • Prefer library-first notification imports

    Move new notification integrations away from the module shim.

    1. Import notification contracts from `@lssm-tech/lib.contracts-spec/notifications`.
    2. Import notification schema contribution, channels, templates, and i18n helpers from `@lssm-tech/lib.notification`.
    3. Keep existing `@lssm-tech/module.notifications` imports during migration when consumers need the legacy schema contribution module id.
  • Connect AppShell notifications through host state

    Provide notification items and callbacks to the design-system shell without coupling it to a delivery runtime.

    1. Pass the `notifications` prop to `AppShell` with items, unread count, and mark-read callbacks.
    2. Resolve live delivery, persistence, and subscriptions in the host app or runtime package.
    3. Use the native shell entrypoint for Expo surfaces so the same notification state appears through the native header/menu affordance.
  • Use the canonical ontology graph surface

    Required

    Use `@lssm-tech/lib.contracts-spec/ontology` as the semantic Company Work Graph source for actor, work, resource, surface, adaptation, and safety nodes/edges.

    1. Classify `graph-artifacts` as physical/provenance metadata, not a replacement semantic ontology.
    2. Update RoleMorph specs/results to cite ontology actor/work/surface/resource/adaptation/safety refs and fail closed for high-impact actions when safety refs are missing.
    3. Update personalization adaptive events, behavior signals, and fine-tuning receipts to export only sanitized ontology/evidence/policy/redaction refs.
  • Replace package-local graph IDs with ontology refs

    Required

    Link entity, DataView, CompanyOS, RoleMorph, personalization, and fine-tuning records through the canonical ontology graph surface.

  • Require safety evidence for committed high-impact work

    Required

    Add policy decision, authority scope, actor, approval/refusal, audit receipt, redaction status, replay/evidence, risk tier, and timestamp refs before committing high-impact transitions.

  • Adopt the PWA update-check contract

    Register the PWA update operation, bind it to a manifest resolver, and call it from the frontend on startup or polling intervals.

    1. Define a PWA app manifest with `defaultUpdatePolicy` and release entries.
    2. Add per-release `updatePolicy` overrides when a release must be optional, required, or disabled.
    3. Bind `createPwaUpdateCheckHandler` to the `pwa.update.check` operation.
    4. Use `usePwaUpdateChecker` in the frontend and keep service worker activation inside the host app callback.
  • Adopt the additive organization authority operations

    Use verified session authority for organization and workspace selection.

    1. Enumerate only memberships returned by organization.list.
    2. Await organization.set-active and retain its composite authorityToken for stale-request rejection.
    3. Invalidate organization-scoped caches before loading workspaces.
    4. Call workspace.list without organizationId or tenantId selectors.
  • Keep legacy ND admission fail closed during auth recovery

    Required

    Remove pilot identifiers only from auth readiness, not from the legacy route guard.

    1. Keep MANAGED_COMPANYOS_PILOT_* available to the legacy ND admission resolver.
    2. Verify /api/auth/ok without pilot identifiers.
    3. Verify legacy ND routes still deny when their exact pilot tuple is absent or mismatched.
  • Keep authority responses private and the database runtime app-owned

    Required

    Do not cache organization/workspace projections or create a Postgres pool per request.

    1. Bind organization.list@1.0.0 and organization.set-active@1.0.0 to the declared real API and runtime implementation refs.
    2. Require ambient credentials and exact trusted-origin validation for canonical authority refresh.
    3. Require exact trusted Origin for browser requests and OPTIONS; permit absent Origin only for server transport.
    4. Require Cache-Control private, no-store on every organization and authority projection response, including deny and degraded outcomes.
    5. Propagate every distinct provider Set-Cookie value without coalescing.
    6. Disable authority caches for post-write canonical revalidation and map membership rejection to 403, authority-session drift to 409, and store failure to 503.
    7. Allow membership-list-first recovery when no active organization exists, while granting zero workspace authority until verified selection.
    8. Commit organization.activeChanged through a server-owned database trigger in the active-organization transition; emit no event for the same organization and roll back on audit failure.
    9. Reuse one lazy authority repository and connection pool for the application lifecycle.
    10. Close the app-owned authority runtime during host shutdown.
    11. Run the repository and disposable PostgreSQL atomic-audit proofs before any production migration.
  • Apply migration 0019 before bootstrap

    Required

    Add the migration-owner-only durable phase receipt table.

    1. Apply tracked migrations through 0019.
    2. Keep MANAGED_COMPANYOS_ORG_AUTHORITY_CUTOVER disabled.
    3. Run companyos:bootstrap-admin and require all eight receipts.
    4. If interrupted, rerun the same manifest revision and verify three bindings and grants.
  • Adopt the manifest-wide live seed

    Required

    Seed and verify every declared family after canonical bootstrap.

    1. Apply tracked forward migrations with approval and backup evidence.
    2. Run companyos:bootstrap-admin and require the complete organization-bootstrap:v1 authority manifest.
    3. Run companyos:db:seed:live once without tenant/workspace selectors.
    4. Run companyos:db:verify:live and require exact redacted receipts, counts, semantic digests, and tenant isolation.
    5. Replay twice and require zero duplicate rows, receipts, profile revisions, snapshots, audit rows, or workflow transitions.
  • Upgrade contracts-spec for Expo RichReference imports

    Consume the release before importing crypto-adjacent ContractSpec surfaces from Expo or React Native bundles.

    1. Upgrade `@lssm-tech/lib.contracts-spec` to the release containing this fix.
    2. Upgrade affected runtime packages that previously depended on `create-hash`, `create-hmac`, Node `crypto`, or global `crypto.randomUUID()` in browser-capable bundles.
    3. Ensure React Native or Expo targets provide `crypto.getRandomValues`; the internal crypto utility uses it for UUID and random byte generation.
    4. Await the Web Crypto based signer APIs listed in the manual upgrade step when using control-plane or overlay signing helpers.
  • Promote only after integrated verification evidence is attached

    Required

    The documentation classifies the intended release as additive, but feature completion depends on integrated implementation-lane evidence.

    When: Before advertising the role-adaptive CompanyOS app shell as complete or production-ready.

    1. Attach contract, surface-runtime, personalization, managed bundle, and web app command outputs to docs/role-adaptive-companyos-app-shell-evidence.md.
    2. Confirm denied RoleMorph actions remain hidden or disabled and explained in resolver output.
    3. Confirm web app shell adoption imports only bundle/design-system surfaces and does not add app-local shared shell components.
  • Adopt shared PolicyRequirement metadata incrementally

    Existing policies continue to work; add roles, permissions, policy refs, and field policies when a contract needs stronger authorization metadata.

    1. Import shared policy requirement types from `@lssm-tech/lib.contracts-spec/policy` when authoring reusable contract metadata.
    2. Keep server/runtime `ctx.decide` or RBAC evaluation as the source of enforcement authority.
    3. Pass evaluated decisions to AppShell and personalization helpers only for UX adaptation and suppression.
  • Remove createTranslationRuntime engine usage

    Required

    @lssm-tech/lib.translation-runtime no longer exports the deprecated runtime engine subpaths or preference override-layer construction helpers; consumers must migrate active render paths to the factory stack.

    When: When importing @lssm-tech/lib.translation-runtime/runtime, ./registry, ./runtime-helpers, or using createTranslationRuntime and related preference runtime builders.

    1. Remove imports from @lssm-tech/lib.translation-runtime/runtime, ./registry, and ./runtime-helpers.
    2. Replace active SSR/render usage with createI18nFactory on the server.
    3. Transfer factory.hydrationPayload(...) to the client and reconstruct with createI18nFactoryFromHydrationPayload.
    4. Drop preference override-layer runtime construction; keep resolveTranslationPreferenceContext for context resolution.
  • Replace createRuntimeTranslationResolver in design-system consumers

    Required

    @lssm-tech/lib.design-system removed createRuntimeTranslationResolver; use the registry-backed createTranslationResolver instead.

    When: When importing or calling createRuntimeTranslationResolver from @lssm-tech/lib.design-system.

    1. Replace createRuntimeTranslationResolver imports with createTranslationResolver.
    2. Update call sites to pass the registry-backed resolver inputs expected by createTranslationResolver.
  • Prefer contracts-spec result primitives for new error handling

    Replace new uses of `AppError` with `ContractSpecError` or `contractFail`; existing `AppError` consumers can convert to a compatible problem shape with `appErrorToProblem`.

    1. Import new result helpers from `@lssm-tech/lib.contracts-spec/results`.
    2. Keep existing `AppError` consumers until they are touched for feature work.
    3. Use `appErrorToProblem` when a compatibility conversion is needed.
  • Migrate from raw createDatabaseProvider to createDatabaseRuntime

    Required

    Replace raw provider construction with the runtime preset to get automatic RLS tenant scoping, observability, and governed resolvers.

  • Adopt canonical query envelopes for list-style operations

    Use @lssm-tech/lib.contracts-spec/query to normalize search, filters, sort, offset pagination, cursor pagination, cache hints, and result page metadata before wiring UI or database adapters.

    1. Keep operation-specific legacy inputs at module boundaries when needed.
    2. Add a canonical wrapper beside the legacy operation, following the agent.list wrapper pattern.
    3. Keep TanStack Query, TanStack Store, or other client-cache implementation details behind runtime adapters rather than in contract types.
  • Declare local or remote EntityWorkspace query ownership

    Pass remote query-source semantics when items are already filtered, sorted, or paginated by a server/provider so EntityWorkspace does not apply local controls twice.

    1. Use local mode for in-memory lists where EntityWorkspace owns filtering and sorting.
    2. Use remote mode for server/provider-backed lists.
    3. Opt into client post-filtering only when the host deliberately wants a second local projection.
  • Add .release.yaml companions for changesets

    Published release changesets now require a structured release capsule.

    When: When preparing release branches, publish workflows, or release communication bundles.

    1. Create `.changeset/<slug>.release.yaml` next to each published changeset.
    2. Record customer impact, migration notes, validation commands, and evidence in the release capsule.
    3. Run `contractspec release build` before `contractspec release check --strict`.

Upgrade steps

  • Adopt adaptive DataView command-center metadata

    assisted

    Use the new additive DataView metadata to describe management-shell layouts and host-owned action boundaries.

    Packages: @lssm-tech/lib.contracts-spec, @lssm-tech/lib.design-system, @lssm-tech/lib.personalization, @lssm-tech/lib.surface-runtime, @lssm-tech/example.agent-workflow-command-center

    1. Review DataView management-shell metadata before enabling command-center layouts.
    2. Keep host-owned side effects, modal state, validation, and destructive confirmation flows outside the metadata layer.
  • Describe DataView management shells with additive metadata

    assisted

    Use optional DataView management-shell fields to document adaptive command-center layouts without changing existing DataView contracts.

    Packages: @lssm-tech/lib.contracts-spec

    1. Add management-shell metadata only where host UI needs command-center hints.
    2. Keep CRUD side effects and destructive confirmation flows in host applications.
  • Release build now accumulates an index and writes per-version details

    assisted

    After a release build, `generated/releases/index.json` contains the accumulating release index, and `generated/releases/versions/v{slug}.json` contains full per-version details. The full manifest is still overwritten.

    Packages: @lssm-tech/lib.contracts-spec, @lssm-tech/bundle.workspace, @lssm-tech/app.cli-contractspec, @lssm-tech/app.web-landing

    1. Existing `contractspec release build` workflow continues unchanged.
    2. CLI changelog consumers can now run `contractspec changelog list` and `contractspec changelog view <version>`.
    3. Web changelog consumers will see version detail pages automatically.
  • Add adoption after-release-build hook to CI workflows

    manual

    Both `publish-canary` and `publish-npm` workflows now run the adoption hook after release build to sync catalogs and write pending upgrades.

    Packages: @lssm-tech/lib.contracts-spec, @lssm-tech/bundle.workspace, @lssm-tech/app.cli-contractspec, @lssm-tech/app.web-landing

    1. If you maintain custom CI workflows, add a step: `bun packages/apps/cli-contractspec/src/cli.ts connect hook adoption after-release-build --json`
    2. This step must run after `bun run release:build` and before `contractspec release check --strict`.
  • Wire adoption-aware Connect hooks in consumer environments

    assisted

    The consumer plugin and Connect CLI now expose adoption-aware hook events in addition to contracts-spec review hooks.

    Packages: @lssm-tech/lib.contracts-spec, @lssm-tech/module.workspace, @lssm-tech/bundle.workspace, @lssm-tech/bundle.library, @lssm-tech/app.cli-contractspec, vscode-contractspec, contractspec, @lssm-tech/lib.knowledge, @lssm-tech/biome-config, @lssm-tech/app.cursor-marketplace

    1. Install or reference the `contractspec-adoption` marketplace/plugin assets where Connect hooks are consumed.
    2. Use `contractspec connect hook adoption before-file-edit|before-shell-execution|after-file-edit --stdin` in host hook wiring.
  • Prefer higher-level runtime package entrypoints in imports

    manual

    Generated Biome policy artifacts now flag deprecated monolith usage and obvious deep runtime entrypoint imports.

    Packages: @lssm-tech/lib.contracts-spec, @lssm-tech/module.workspace, @lssm-tech/bundle.workspace, @lssm-tech/bundle.library, @lssm-tech/app.cli-contractspec, vscode-contractspec, contractspec, @lssm-tech/lib.knowledge, @lssm-tech/biome-config, @lssm-tech/app.cursor-marketplace

    1. Replace `@lssm-tech/lib.contracts` imports with `@lssm-tech/lib.contracts-spec` plus the appropriate split runtime package.
    2. Prefer package-level runtime entrypoints such as `@lssm-tech/lib.contracts-runtime-server-mcp` when they already expose the required surface.
  • Validate the portable application surface

    assisted

    Compile the filesystem fixture, run package-local tests, and inspect the case-18 comparison artifact before enabling EVE.

    Packages: @lssm-tech/agentpacks, @lssm-tech/lib.agent-evals, @lssm-tech/integration.agent-durable-store, @lssm-tech/lib.agent-runtime-conformance, @lssm-tech/integration.eve, @lssm-tech/example.agent-application-foundation

    1. Run the agentpacks compiler tests and reference-application preflight.
    2. Run the Workflow DevKit durable conformance gate and EVE integration-local conformance.
    3. Confirm cases 16 and 17 remain explicitly not applicable with their stable reason codes.
    4. Inspect declared losses and reject any unclassified case-18 difference.
  • Verify package artifacts outside the workspace

    manual

    No canary or stable release is implied by source-level validation; clean Node and Bun consumers remain a publication gate.

    Packages: @lssm-tech/lib.contracts-spec, @lssm-tech/lib.ai-agent, @lssm-tech/lib.files, @lssm-tech/integration.agent-durable-store, @lssm-tech/integration.workflow-devkit, @lssm-tech/integration.agent-sandbox, @lssm-tech/integration.eve, @lssm-tech/lib.execution-lanes, @lssm-tech/lib.agent-runtime-conformance, @lssm-tech/lib.agent-evals, @lssm-tech/agentpacks, @lssm-tech/lib.harness, @lssm-tech/example.agent-application-foundation, @lssm-tech/tool.bun, @lssm-tech/lib.contracts-runtime-core

    1. Build and pack the affected packages.
    2. Install the tarballs in clean Node and Bun consumer fixtures.
    3. Exercise public exports, both adapter fixtures, and a filesystem-generated application.
    4. Publish a canary only after the clean-consumer matrix is recorded; do not promote a failed canary.
  • Verify command-inbox release proof

    assisted

    Run the focused validation matrix before publishing packages or public docs.

    Packages: @lssm-tech/lib.contracts-spec, @lssm-tech/lib.communication-spec, @lssm-tech/lib.communication-runtime, @lssm-tech/module.communication-os, @lssm-tech/example.communication-os, @lssm-tech/example.companyos-communicationos-operating-cockpit, @lssm-tech/app.web-landing

    1. Run targeted lint on the modified contract/runtime/module/example/docs files.
    2. Run communication-spec and communication-runtime tests/typechecks.
    3. Run module.communication-os tests/typecheck.
    4. Run focused CommunicationOS and Operating Cockpit example tests/typechecks.
    5. Regenerate or verify `/llms*` guidance after README updates.
  • Adopt the Builder v3 control-plane packages

    assisted

    Wire provider/runtime integrations through the governed Builder v3 workbench and mobile-review surfaces.

    Packages: @lssm-tech/lib.contracts-spec, @lssm-tech/lib.builder-spec, @lssm-tech/lib.provider-spec, @lssm-tech/lib.builder-runtime, @lssm-tech/lib.mobile-control, @lssm-tech/lib.provider-runtime, @lssm-tech/module.builder-workbench, @lssm-tech/module.mobile-review, @lssm-tech/integration.runtime, @lssm-tech/integration.runtime-managed, @lssm-tech/integration.runtime-local, @lssm-tech/integration.runtime-hybrid, @lssm-tech/integration.builder-telegram, @lssm-tech/integration.builder-voice, @lssm-tech/integration.builder-whatsapp, @lssm-tech/integration.provider-codex, @lssm-tech/integration.provider-claude-code, @lssm-tech/integration.provider-gemini, @lssm-tech/integration.provider-copilot, @lssm-tech/integration.provider-stt, @lssm-tech/integration.provider-local-model

    1. Install the Builder v3 contracts and runtime packages alongside the provider integrations you intend to expose in the authoring surface.
    2. Use the Builder workbench and mobile-review modules as the host UI surfaces instead of building separate readiness or export orchestration shells.
    3. Validate managed, local, and hybrid runtime mode selection plus provider routing before promoting the control-plane workflow to operators.
  • Declare logical env variables before framework aliases

    assisted

    Use workspace environment definitions and app targets instead of duplicating public env names across apps.

    Packages: @lssm-tech/lib.contracts-spec, @lssm-tech/lib.contracts-integrations, @lssm-tech/integration.runtime, @lssm-tech/bundle.workspace

    1. Define shared logical variables under `.contractsrc.json > environment.variables`.
    2. Add app targets for each package/framework that needs concrete aliases.
    3. Keep secret values behind `secretRef` or environment/secret providers.
  • Bind approved Company Intelligence production dependencies

    manual

    Supply canonical tenant-scoped PostgreSQL repositories plus production-only extraction and grounded-answer service ports without enabling fixture fallback.

    Packages: @lssm-tech/app.api-application-monolith, @lssm-tech/lib.contracts-spec

    1. Keep the contract-derived v1 paths and stable error envelope unchanged.
    2. Bind only tenant-scoped production dependencies.
    3. Configure LSSM_STUDIO_DATABASE_URL before enabling the API.
    4. Use the built-in PostgreSQL authority adapters and bind external model services before enabling extraction or grounded answers.
  • Install the approval kernel schema

    assisted

    Apply the additive schema and verify FORCE RLS before enabling durable local review.

    Packages: @lssm-tech/lib.contracts-spec, @lssm-tech/integration.runtime, @lssm-tech/app.cli-contractspec, @lssm-tech/bundle.workspace

    1. Back up existing channel and Connect review tables.
    2. Apply the ordered migrations under the migration-owner role.
    3. Run tenant-isolation and linkage-recovery verification with the non-owner runtime role.
  • Adopt the Connect CLI workflow

    manual

    Use the built-in Connect commands instead of custom local wrappers for risky file or command mutations.

    Packages: @lssm-tech/lib.contracts-spec, @lssm-tech/bundle.workspace, @lssm-tech/app.cli-contractspec, @lssm-tech/bundle.library, agentpacks

    1. Initialize the workspace with `contractspec connect init --scope workspace`.
    2. Use `contractspec connect context`, `plan`, and `verify` to capture task context and mutation verdicts before edits or shell execution.
    3. Keep replay and evaluation artifacts under `.contractspec/connect/` so review and audit flows can consume the same evidence bundle.
  • Use the authored validators for contract setup and CI

    assisted

    Prefer the package-level validators over shallow AST checks for the three upgraded surfaces.

    Packages: @lssm-tech/lib.contracts-spec, @lssm-tech/module.workspace, @lssm-tech/bundle.workspace, @lssm-tech/app.cli-contractspec

    1. Use `validateBlueprint` or `assertBlueprintValid` for app-config specs.
    2. Use `validateThemeSpec` or `assertThemeSpecValid` for theme specs.
    3. Use `validateFeatureSpec` or `assertFeatureSpecValid` for feature specs before registry installation or release review.
  • Adopt the new theme authoring target across workspace tools

    manual

    Shared workspace discovery and the CLI now treat `theme` as a first-class authored surface.

    Packages: @lssm-tech/lib.contracts-spec, @lssm-tech/module.workspace, @lssm-tech/bundle.workspace, @lssm-tech/app.cli-contractspec

    1. Use `.theme.ts` files and `defineTheme(...)` for new theme specs.
    2. Update any custom create flows or discovery logic to include the `theme` authoring target where needed.
  • Adopt FormSpec-driven marketing form/pricing components

    manual

    Move marketing form-like UI onto FormSpec/OperationSpec bindings and host-owned execution.

    Packages: @lssm-tech/lib.contracts-spec, @lssm-tech/lib.design-system

    1. Review the paired changeset summary in .changeset/contractspec-form-operation-marketing-components.md before promotion.
    2. Migrate MarketingLeadCapture and MarketingPricingCalculator usage to FormSpec props per the migration instructions.
    3. Refresh integrated-branch verification after all worker lane commits are merged.
  • Run the contractspec i18n diagnostics command in CI

    manual

    Use contractspec i18n check to validate translation catalogs before release or merge.

    Packages: @lssm-tech/lib.contracts-spec, @lssm-tech/app.cli-contractspec

    1. Run `contractspec i18n check` locally or in CI for the relevant workspace.
    2. Ensure translation catalogs are present, non-blank, ICU-valid, and placeholder-parity safe.
    3. Provide `.contractsrc.json` i18n defaults only when the workspace needs custom catalog paths or locale settings.
  • Adopt the ContractSpec translation runtime for production surfaces

    manual

    Use runtime instances or snapshots instead of legacy simple string interpolation for production i18n paths.

    Packages: @lssm-tech/lib.contracts-spec, @lssm-tech/lib.translation-runtime, @lssm-tech/lib.design-system, @lssm-tech/example.locale-jurisdiction-gate

    1. Build runtime instances from canonical `TranslationSpec[]` catalogs.
    2. Create one runtime per SSR request and hydrate clients from serialized snapshots.
    3. Keep React, React Native, and i18next integrations downstream from the runtime.
  • Opt effectful operations into scoped approval

    assisted

    Declare execution effects and approval requirements, then configure a durable approval runtime.

    Packages: @lssm-tech/lib.contracts-spec, @lssm-tech/lib.contracts-runtime-core, @lssm-tech/lib.contracts-runtime-server-rest, @lssm-tech/lib.contracts-runtime-server-mcp

    1. Add execution.effects and execution.approval.required only to operations that require authoritative approval.
    2. Supply OperationApprovalPort through HandlerCtx and use a durable ApprovalNonceStore in multi-instance production runtimes.
    3. Adapt REST or MCP receipt evidence outside operation input.
  • Adopt the canonical data-fetching protocol and engine

    assisted

    Move query/cache/offline state onto contracts-spec + contracts-runtime-core; consume canonical QueryState in design-system.

    Packages: @lssm-tech/lib.contracts-spec, @lssm-tech/lib.contracts-runtime-core, @lssm-tech/lib.contracts-runtime-client-react, @lssm-tech/lib.contracts-runtime-server-rest, @lssm-tech/lib.contracts-runtime-server-mcp, @lssm-tech/integration.provider-database, @lssm-tech/integration.runtime-local, @lssm-tech/lib.design-system, @lssm-tech/integration.crdt-loro, @lssm-tech/example.data-fetching-ecosystem, @lssm-tech/bundle.library, @lssm-tech/bundle.marketing

    1. Wrap the app surface in <ContractDataEngineProvider> with createDataEngine({ transport }) over a REST/MCP/in-memory Transport adapter.
    2. Construct envelopes via normalizeQueryEnvelope and pass them to useContractQuery; render QueryState directly in design-system components.
    3. For offline-capable mutations, pass optimistic writes to mutate and rely on the engine queue/replay/conflict resolution.
    4. Register crdt-loro as the opt-in CRDT resolver where collaborative merge is required.
    5. Remove any remaining data-transmission-spec / -runtime and ./query-client imports.
  • Re-run focused table overflow verification after upgrading

    assisted

    The contract, runtime, web, native, design-system, CLI, and workspace layers all participate in overflow behavior.

    Packages: @lssm-tech/lib.contracts-spec, @lssm-tech/lib.presentation-runtime-core, @lssm-tech/lib.presentation-runtime-react, @lssm-tech/lib.ui-kit-web, @lssm-tech/lib.ui-kit, @lssm-tech/lib.design-system, @lssm-tech/module.workspace, @lssm-tech/bundle.workspace, @lssm-tech/app.cli-contractspec, @lssm-tech/bundle.library

    1. Run the focused data-view and data-table test suites for contracts-spec, presentation-runtime-react, ui-kit-web, ui-kit, and design-system.
    2. Run typecheck and lint checks for the touched libraries, CLI, and workspace packages.
  • Add optional collection defaults to collection DataView specs

    assisted

    Existing specs keep working; add view.collection when a renderer should expose shared collection controls or query page-size defaults.

    Packages: @lssm-tech/lib.contracts-spec, @lssm-tech/lib.design-system, @lssm-tech/module.workspace, @lssm-tech/bundle.workspace, @lssm-tech/app.cli-contractspec, @lssm-tech/bundle.library

    1. Add view.collection.viewModes to declare allowed list/grid/table projections.
    2. Add view.collection.pagination.pageSize when query generation should use a contract default.
    3. Keep table view.density where already used; it remains a permanent compatibility alias.
  • Resolve personalized DataView defaults in the host app

    assisted

    Keep DataViewRenderer dependency-free by resolving personalization preferences before rendering.

    Packages: @lssm-tech/lib.contracts-spec, @lssm-tech/lib.design-system, @lssm-tech/lib.personalization, @lssm-tech/bundle.library

    1. Import `resolveDataViewPreferences` from `@lssm-tech/lib.personalization/data-view-preferences`.
    2. Pass the resolved `viewMode`, `density`, and `dataDepth` values to `DataViewRenderer` as controlled or default props.
    3. Record user changes with `trackDataViewInteraction` when persistence or behavioral insights are desired.
  • Regenerate docs and LLM guidance for database mutation changes

    manual

    When database mutation contracts or adapters change, update the README/docs/release capsule pair and regenerate `/llms*` before release.

    Packages: @lssm-tech/lib.contracts-spec, @lssm-tech/integration.provider-database, @lssm-tech/app.web-landing, contractspec

    1. Update `packages/libs/contracts-spec/README.md` for portable descriptor behavior.
    2. Update `packages/integrations/provider-database/README.md` for adapter execution behavior.
    3. Run `bun run --cwd packages/apps/web-landing llms:generate` and include the generated package guide changes.
  • Keep EntityWorkspace gated until native parity and API contracts are complete

    manual

    The release adds public-surface gates and docs; it intentionally does not document EntityWorkspace as shipped.

    Packages: @lssm-tech/lib.contracts-spec, @lssm-tech/lib.design-system, @lssm-tech/bundle.workspace, @lssm-tech/bundle.library, @lssm-tech/app.web-landing

    1. Keep `docs/design-system-entity-workspace-public-api-contract.md` and `docs/design-system-entity-workspace-inventory.md` aligned with implementation work.
    2. Classify every proposed entity-workspace public component in `packages/libs/design-system/src/components/entity-workspace/native-parity.ts` before exporting it.
    3. Do not add a direct DataViewSpec-to-FormSpec contract link until the feature/DataView/operation/form discovery path justifies it.
    4. When EntityWorkspace becomes public, update `/docs/guides/entity-surfaces`, `/docs/libraries/data-views`, `/docs/libraries/design-system`, package exports, native parity evidence, and release capsules together.
  • Use the actual RichRef public API in docs and examples

    manual

    Public docs should import `RichRef` from `@lssm-tech/lib.ui-kit-web/rich-ref`, pass `kindId` and `refId`, and use valid variants/panel modes.

    Packages: @lssm-tech/lib.contracts-spec, @lssm-tech/lib.design-system, @lssm-tech/bundle.workspace, @lssm-tech/bundle.library, @lssm-tech/app.web-landing

    1. Use `variant="inline"`, `"chip"`, `"card"`, `"icon"`, or `"button"`.
    2. Use `panelMode="popover"`, `"drawer"`, `"modal"`, `"route"`, or `"inline-expand"`.
    3. Keep design-system RichReference layout helpers separate from the RichRef renderer import.
  • Describe database-backed contract surfaces before adapter wiring

    assisted

    Add optional database binding metadata to DataView, FormSpec, PolicySpec, Knowledge, RBAC, and data-exchange declarations while keeping execution behind provider/database adapters.

    Packages: @lssm-tech/lib.contracts-spec, @lssm-tech/lib.identity-rbac, @lssm-tech/lib.knowledge, @lssm-tech/lib.data-exchange-core, @lssm-tech/lib.data-exchange-server, @lssm-tech/integration.provider-database

    1. Add portable schema, table, view, field, filter, policy, and provenance metadata to contract source.
    2. Keep Drizzle, postgres, pg, and driver imports in integrations, apps, tools, or server adapters only.
    3. Use provider-database as the primary PostgreSQL execution exemplar.
    4. Run the adapter-boundary guard before release.
  • Compose and qualify the target agent platform

    manual

    Built-in profiles are candidate templates, not production attestations. Pin the selected profiles, controls, and environment and qualify them before serving production traffic.

    Packages: @lssm-tech/lib.contracts-spec, @lssm-tech/lib.ai-agent, @lssm-tech/lib.files, @lssm-tech/lib.agent-collaboration, @lssm-tech/integration.agent-durable-store, @lssm-tech/integration.workflow-devkit, @lssm-tech/integration.agent-sandbox, @lssm-tech/integration.eve, @lssm-tech/lib.execution-lanes, @lssm-tech/lib.agent-runtime-conformance, @lssm-tech/lib.agent-evals, @lssm-tech/agentpacks, @lssm-tech/lib.harness, @lssm-tech/integration.runtime, @lssm-tech/module.workspace, @lssm-tech/bundle.workspace, @lssm-tech/integration.provider-github, @lssm-tech/example.agent-application-foundation, @lssm-tech/app.worker-application-monolith, @lssm-tech/tool.bun, @lssm-tech/lib.contracts-runtime-core, @lssm-tech/bundle.library, @lssm-tech/app.web-landing

    1. Select only the capabilities and provider profiles required by the project.
    2. Bind authentication, tenant authority, secrets, durable storage, audit, observability, and budget controls in the host.
    3. Run every required qualification suite against the exact target environment.
    4. Pass the mandatory governance/security, supply-chain, observability-export, load/resilience, and clean-consumer-release baseline gates.
    5. Accept intentional capability losses explicitly and retain the signed report with the plan digest.
    6. Exercise pause, recovery, rollback, revocation, backup restore, and break-glass runbooks before promotion.
  • Verify forms package export and DocBlock manifest

    auto

    Confirm the entity-bound guidance subpath resolves and the generated DocBlock route is present.

    Packages: @lssm-tech/lib.contracts-spec

    1. Run the forms package export test.
    2. Regenerate the contracts-spec DocBlock manifest after DocBlock edits.
  • Use the shared row-card layout contract for EntityWorkspace consumers

    manual

    Configure row/card icons, status, and label visibility from DataViewManagement row-card metadata.

    Packages: @lssm-tech/lib.contracts-spec, @lssm-tech/lib.design-system, @lssm-tech/example.agent-workflow-command-center

    1. Set `management.rowCard.iconField` to the field that should render before the title.
    2. Set `management.rowCard.statusField` to the field that should render in the top-right chip.
    3. Toggle `management.rowCard.showFieldLabels` to hide labels globally when value-only presentation is preferred.
    4. Add `management.rowCard.fieldLabelVisibility` overrides for any fields that still need labels.
  • Forward optional autocomplete async props in custom drivers

    manual

    Custom autocomplete driver slots can opt into loading/error rendering without changing existing fields.

    Packages: @lssm-tech/lib.contracts-spec, @lssm-tech/lib.contracts-runtime-client-react, @lssm-tech/lib.design-system, @lssm-tech/lib.ui-kit-web

    1. Accept optional `loading`, `error`, `emptyText`, `loadingText`, and `errorText` props on custom autocomplete components.
    2. Keep existing `query`, `options`, `selectedOptions`, and selection callbacks unchanged.
  • Adopt first-class email fields

    manual

    Replace renderer-specific email text hints with `kind: "email"` where a field captures one email address.

    Packages: @lssm-tech/lib.contracts-spec, @lssm-tech/lib.contracts-runtime-client-react, @lssm-tech/lib.design-system

    1. Use `{ kind: "email", name: "contactEmail" }` for single-address email fields.
    2. Use an `array` of email fields when a form must collect multiple addresses.
  • Use FormSpec layout hints for dense forms

    manual

    Replace renderer-specific row wrappers with portable column and colspan metadata.

    Packages: @lssm-tech/lib.contracts-spec, @lssm-tech/lib.contracts-runtime-client-react, @lssm-tech/lib.design-system, @lssm-tech/lib.ui-kit-web, @lssm-tech/lib.ui-kit

    1. Add `layout.columns` at form or group level.
    2. Use `field.layout.colSpan` for fields that should expand across columns.
    3. Use `group.legendI18n` when a section needs a semantic legend.
  • Use serializable input-group addons

    manual

    Add text or icon addon descriptors to text and textarea fields.

    Packages: @lssm-tech/lib.contracts-spec, @lssm-tech/lib.contracts-runtime-client-react, @lssm-tech/lib.design-system, @lssm-tech/lib.ui-kit-web, @lssm-tech/lib.ui-kit

    1. Add `inputGroup.addons` to text or textarea field specs.
    2. Resolve icon keys in the host driver through the `InputGroupIcon` slot.
  • Add numeric field slots to custom form drivers

    assisted

    Shared drivers can opt into richer rendering for the new field kinds.

    Packages: @lssm-tech/lib.contracts-spec, @lssm-tech/lib.contracts-runtime-client-react, @lssm-tech/lib.design-system

    1. Implement the optional `NumberField`, `PercentField`, `CurrencyField`, and `DurationField` driver slots when custom styling is required.
    2. Keep relying on the `Input` fallback when a separate visual treatment is unnecessary.
  • Add PasswordInput to custom drivers

    manual

    Custom form renderers can provide the optional `PasswordInput` slot to get a visibility toggle.

    Packages: @lssm-tech/lib.contracts-spec, @lssm-tech/lib.contracts-runtime-client-react, @lssm-tech/lib.design-system, @lssm-tech/lib.ui-kit-web, @lssm-tech/lib.ui-kit, @lssm-tech/lib.ui-kit-core

    1. Implement a driver component that accepts input props plus `passwordPurpose`, `visibilityToggle`, `showLabelI18n`, and `hideLabelI18n`.
    2. Omit the slot to keep the fallback masked input behavior.
  • Verify custom form driver button and fieldset slots

    manual

    Custom drivers should confirm their existing `Button`, `FieldSet`, `FieldLegend`, `FieldDescription`, and `FieldGroup` slots render the new flow structure cleanly.

    Packages: @lssm-tech/lib.contracts-spec, @lssm-tech/lib.contracts-runtime-client-react, @lssm-tech/lib.design-system

    1. Render a form with `layout.flow.kind: "sections"`.
    2. Render a form with `layout.flow.kind: "steps"`.
    3. Confirm unlisted fields remain visible and step navigation buttons inherit expected styling.
  • Opt into mobile-safe form columns

    manual

    Replace ad hoc responsive column objects with `responsiveFormColumns(...)` where mobile forms should render one field per row.

    Packages: @lssm-tech/lib.contracts-spec, @lssm-tech/lib.contracts-runtime-client-react, @lssm-tech/lib.presentation-runtime-core, @lssm-tech/lib.presentation-runtime-react, @lssm-tech/lib.presentation-runtime-react-native, @lssm-tech/lib.design-system

    1. Import `responsiveFormColumns` from `@lssm-tech/lib.contracts-spec/forms`.
    2. Set `layout.columns` to `responsiveFormColumns(2)` or another supported column count.
  • Adopt scoped DataView filters

    manual

    Declare initial and locked filters in the DataView contract instead of passing all filters as removable renderer state.

    Packages: @lssm-tech/lib.contracts-spec, @lssm-tech/lib.contracts-runtime-client-react, @lssm-tech/lib.presentation-runtime-core, @lssm-tech/lib.presentation-runtime-react, @lssm-tech/lib.presentation-runtime-react-native, @lssm-tech/lib.design-system

    1. Add `filterScope.initial` for removable default filters.
    2. Add `filterScope.locked` for fixed constraints.
    3. Use `lockedChips: "hidden"` only when the surrounding UI explains the constraint elsewhere.
  • Opt in to the M5 AI pair panel on any template

    manual

    Opt in to the M5 AI pair panel on any template

    Packages: @lssm-tech/lib.contracts-spec, @lssm-tech/lib.ai-agent, @lssm-tech/lib.ui-kit-web, @lssm-tech/lib.ui-kit, @lssm-tech/lib.design-system

  • Configure named harness auth profiles

    assisted

    Authenticated browser scenarios should reference named storage-state, browser-profile, session-name, or headers-env profiles instead of embedding secrets.

    Packages: @lssm-tech/lib.contracts-spec, @lssm-tech/lib.harness, @lssm-tech/integration.harness-runtime, @lssm-tech/app.cli-contractspec, @lssm-tech/example.harness-lab

    1. Add `.contractsrc.json > testing.harness.authProfiles` entries for any authenticated browser flows.
    2. Keep raw credentials, cookies, and bearer tokens outside scenario specs and replay bundles.
    3. Use `contractspec harness eval --auth-profile <key>` when running a scenario that should apply a configured auth profile.
  • Install optional browser runtimes for full local proof

    manual

    Playwright and agent-browser are optional runtime dependencies, but local full-app proof requires the corresponding browser binaries or CLI.

    Packages: @lssm-tech/lib.contracts-spec, @lssm-tech/lib.harness, @lssm-tech/integration.harness-runtime, @lssm-tech/app.cli-contractspec, @lssm-tech/example.harness-lab

    1. Run `bunx playwright install chromium` before local Playwright harness runs when browsers are missing.
    2. Install `agent-browser` where visual computer-use scenarios should run.
    3. Use `--browser-engine playwright`, `--browser-engine agent-browser`, or `--browser-engine both` to select the runtime lane.
  • Surface untranslated English stubs per catalog group

    assisted

    Run analyzeTranslationCatalogGroup(s) and inspect missing_translation info issues; pass a missingTranslationAllowlist for English-by-design terms and cognates.

    Packages: @lssm-tech/lib.contracts-spec, @lssm-tech/lib.design-system

    1. Read missing_translation issues from the diagnostics report (info level, never fails CI).
    2. Allowlist brand names, codes, and genuine cross-locale cognates per surface.
    3. Optionally pass a localeOverride to useI18n where a per-component locale prop exists.
  • Wire Wave B mutation handlers

    manual

    Bind handlers for the 13 new mutation contracts in the integrations registry. Apply `RoleMorphProjection` capability check server-side; emit the corresponding privacy-signals event on success.

    Packages: @lssm-tech/lib.contracts-spec

  • Use DataViewGraphSpec for graph and timeline-graph data views

    assisted

    New sibling type to DataViewSpec for graph views. Supported by graph canvas renderers. Choose the source variant that matches your data-fetching strategy.

    Packages: @lssm-tech/lib.contracts-spec

    1. Import DataViewGraphSpec from @lssm-tech/lib.contracts-spec/data-views.
    2. Set view.kind to 'graph' or 'timeline-graph'.
    3. Choose source.variant: 'inline-op' (single op), 'two-op' (separate ops), or 'entity-declarative' (requires EntityRegistry).
    4. Pass the spec to ConversationGraphView, WorkflowDagView, or other graph templates.
  • Use defineReferenceKind for typed object references

    assisted

    defineReferenceKind creates a typed, schema-validated kind descriptor for external object references. Use it in any lib or module that needs to link to external business objects.

    Packages: @lssm-tech/lib.contracts-spec

    1. Import defineReferenceKind from @lssm-tech/lib.contracts-spec/rich-reference.
    2. Define a Zod schema for your payload type.
    3. Call defineReferenceKind({ id, schema, sensitiveFields, defaultPreview, defaultPanel, icon }).
    4. Use the .id property as the kindId in RichReference values.
  • Register entities with EntityRegistry for entity-declarative graph views

    assisted

    EntityRegistry enables the 'entity-declarative' DataViewGraphSource variant. Register entities before rendering entity-declarative graph views.

    Packages: @lssm-tech/lib.contracts-spec

    1. Import EntityRegistry, defineContractEntity from @lssm-tech/lib.contracts-spec/shared-entities.
    2. Define entities with defineContractEntity({ slug, fields, edges }).
    3. Register with EntityRegistry.register(myEntity).
    4. Verify EntityRegistry.isLoaded() returns true before rendering entity-declarative views.
  • Update layout field assignments

    manual

    grep for layout string assignments and replace with LayoutSpec objects.

    Packages: @lssm-tech/lib.contracts-spec

    1. Run grep -r "layout:\s*['\"]" packages/ to find all string assignments.
    2. Replace each with the appropriate LayoutSpec object literal.
    3. Run bun run typecheck in each affected package.
  • Qualify dynamic CompanyOS surfaces before canary

    manual

    Bind durable production dependencies and prove request authority, degraded behavior, responsive rendering, and tenant isolation in each target deployment.

    Packages: @lssm-tech/lib.contracts-spec, @lssm-tech/app.api-application-monolith, @lssm-tech/bundle.managed-companyos, @lssm-tech/app.web-application-monolith

    1. Bind the Company Intelligence PostgreSQL repositories and external model services.
    2. Bind the persisted Organization Planning projection and provider-effect runtime.
    3. Prove tenant and role resolution on every request with no shared browser cache.
    4. Qualify loading, success, empty, error, degraded, unauthorized, and partial states.
    5. Run mobile and desktop visual/usability baselines for LSSM, CompanyOS, and ND Consulting.
  • Qualify personal and nested context authority before canary

    manual

    Prove non-shareability, one-use switching, capability intersection, revocation denial, atomic audit, and tenant isolation on the target PostgreSQL topology.

    Packages: @lssm-tech/lib.contracts-spec, @lssm-tech/app.api-application-monolith, @lssm-tech/app.web-application-monolith

    1. Apply migration 0029 followed by migration 0030.
    2. Run empty and populated migration replay against PostgreSQL 15.
    3. Prove personal contexts reject invitations, teams, and additional members.
    4. Prove existing workspaces receive explicit direct grants and ungranted workspaces are never listed or selected.
    5. Prove stale or replayed tokens and revoked workspace/team grants cannot select or retain authority.
    6. Qualify 1, 3, and 20-context mobile and desktop visual baselines before production promotion.
  • Adopt server-authoritative design-partner v2 operations

    manual

    Bind v2 handlers to verified session membership, durable idempotency receipts, immutable replay/evidence projection, and fail-closed health.

    Packages: @lssm-tech/lib.contracts-spec

    1. Preserve receipt and correlation ids from command transaction through outbox and projection.
    2. Return recorded_evidence_pending until evidence and replay rows are visible.
    3. Reject founder approval without an accepted expert attestation on the exact packet version.
    4. Degrade overall health for database, migration, relay, DLQ, or snapshot failures.
    5. Deny reads, mutations, and scheduled relay work when the server-owned tenant kill switch is disabled.
  • Migrate navigation entries to NavSurfaceItemSpec

    assisted

    Replace local navigation item interfaces with NavSurfaceItemSpec, register with NavRegistry, and bind to capabilities.

    Packages: @lssm-tech/lib.contracts-spec

    1. Define NavSurfaceItemSpec entries using defineNavSurfaceItem() for each navigation surface.
    2. Ensure every nav item references a capability registered with surface 'navigation'.
    3. Create a NavRegistry instance and register all nav items.
    4. Use resolveForRoleMorph(roleMorph, preferences) to get persona-aware navigation subsets.
    5. Optional: Build NavGraphSpec with hand-curated edges for power-user nav-map view.
  • Wire mobile extension fields in Expo Router shell

    assisted

    Use the new optional fields when defining NavSurfaceItemSpec entries that will be consumed by a native Expo Router shell.

    Packages: @lssm-tech/lib.contracts-spec

    1. Add tabBarIcon to tab-root nav items that appear in the native tab bar.
    2. Add gestureHint to screens requiring explicit gesture configuration (use 'none' to disable swipe-dismiss on read-only auditor screens).
    3. Add parentGroupKey to stack-child items to express tab-vs-stack hierarchy; tab roots leave parentGroupKey absent.
    4. Web shell consumers require no changes — new fields are optional and ignored when absent.
  • Verify notification schema contribution identity

    manual

    Confirm old module imports keep the legacy module id while new library imports use the library module id.

    Packages: @lssm-tech/lib.contracts-spec, @lssm-tech/lib.notification, @lssm-tech/module.notifications, @lssm-tech/lib.design-system, @lssm-tech/example.crm-pipeline, @lssm-tech/example.wealth-snapshot, @lssm-tech/example.saas-boilerplate

    1. Check `notificationsSchemaContribution.moduleId` from `@lssm-tech/lib.notification` is `@lssm-tech/lib.notification`.
    2. Check `notificationsSchemaContribution.moduleId` from `@lssm-tech/module.notifications` is still `@lssm-tech/module.notifications`.
  • Inventory semantic graph imports and public examples

    manual

    Separate semantic ontology refs from physical/provenance graph artifacts before changing authoring patterns.

    Packages: @lssm-tech/lib.contracts-spec, @lssm-tech/lib.surface-runtime, @lssm-tech/lib.personalization

    1. Search CompanyOS, DataView, entity, RoleMorph, and personalization examples for local graph `type` strings or taxonomy fields.
    2. Move semantic graph examples to ontology refs and keep provenance-only artifacts under `graph-artifacts`.
  • Prove the Autonomous Work Order path

    assisted

    Exercise work-order creation, agent planning, policy decision, human approval/refusal, rendering, adaptation, evidence, and sanitized training export through the same graph refs.

    Packages: @lssm-tech/lib.contracts-spec, @lssm-tech/lib.surface-runtime, @lssm-tech/lib.personalization

    1. Attach actor, work, resource, surface, adaptation, and safety node refs to every proof step.
    2. Require policy decision, authority scope, actor, approval-or-refusal, audit receipt, redaction status, replay/evidence, risk tier, and timestamp refs for committed high-impact orders/mutations.
  • Adopt ontology imports and keep entity symbols on the root barrel

    manual

    Import ontology contracts from `@lssm-tech/lib.contracts-spec/ontology` or documented root exports; keep `defineContractEntity`, `defineContractEdge`, and `EntityRegistry` root imports unless a compatibility ledger says otherwise.

    Packages: @lssm-tech/lib.contracts-spec, @lssm-tech/lib.surface-runtime, @lssm-tech/lib.personalization

    1. Replace package-local high-impact graph IDs with ontology refs.
    2. Keep DataView graph records audit/evidence-addressable when emitted into Autonomous Work Order state.
    3. Do not introduce undocumented `./entities` imports for existing entity symbols.
  • Wire RoleMorph and personalization through ontology evidence

    manual

    Include ontology refs on high-impact RoleMorph action boundaries and adaptive events/signals; export only sanitized evidence-linked fine-tuning traces.

    Packages: @lssm-tech/lib.contracts-spec, @lssm-tech/lib.surface-runtime, @lssm-tech/lib.personalization

    1. Fail closed when high-impact RoleMorph actions lack ontology/safety refs.
    2. Treat personalization as non-authorizing presentation support.
    3. Reject unsafe behavior labels in adaptation and fine-tuning evidence.
  • Configure phone fields where split values or single-input UX are needed

    assisted

    Existing `kind: "phone"` object-valued fields continue to work; opt into new modes through field metadata.

    Packages: @lssm-tech/lib.contracts-spec, @lssm-tech/lib.contracts-runtime-client-react, @lssm-tech/lib.design-system

    1. Use `phone.input.mode` to choose `single` or `split` rendering.
    2. Use `phone.output.mode` with linked path names to write split country/national/E.164 values.
    3. Use `phone.country.defaultIso2` and `phone.display.flag` for country defaults and flag affordances.
  • Adopt the neutral AI-improvement evidence envelope

    assisted

    Use `@lssm-tech/lib.contracts-spec/ai-improvement` for policy, risk, replay, and evidence IDs before wiring vendor adapters.

    Packages: @lssm-tech/lib.contracts-spec, @lssm-tech/lib.provider-spec, @lssm-tech/lib.provider-runtime, @lssm-tech/lib.ai-agent, @lssm-tech/lib.ai-providers, @lssm-tech/lib.metering, @lssm-tech/lib.observability, @lssm-tech/lib.evolution, @lssm-tech/lib.lifecycle, @lssm-tech/integration.provider-pioneer-ai, @lssm-tech/integration.providers-impls

    1. Keep provider routing, observability, metering, evolution, lifecycle, and memory semantics in their owning packages.
    2. Require rollback and human approval evidence before high-risk promotion.
    3. Keep `AI_IMPROVEMENT_VENDOR_EXPORT=off` unless a redacted export policy explicitly permits egress.
  • Configure Pioneer through the targeted adapter package

    manual

    Use `@lssm-tech/integration.provider-pioneer-ai` for Pioneer jobs and receipts; keep credentials outside serialized evidence.

    Packages: @lssm-tech/lib.contracts-spec, @lssm-tech/lib.provider-spec, @lssm-tech/lib.provider-runtime, @lssm-tech/lib.ai-agent, @lssm-tech/lib.ai-providers, @lssm-tech/lib.metering, @lssm-tech/lib.observability, @lssm-tech/lib.evolution, @lssm-tech/lib.lifecycle, @lssm-tech/integration.provider-pioneer-ai, @lssm-tech/integration.providers-impls

    1. Provide Pioneer credentials through the host secret/runtime layer.
    2. Use mock-mode receipts in tests and local dry runs.
    3. Keep `PIONEER_AI_ADAPTER=off` available as a kill switch.
  • Deploy the auth readiness correction independently

    manual

    Restore auth health before organization schema or cutover work.

    Packages: @lssm-tech/lib.contracts-spec, @lssm-tech/app.api-application-monolith, @lssm-tech/app.web-application-monolith

    1. Record the immutable deployment digest and git revision.
    2. Verify /api/auth/ok, sign-in, and session establishment.
    3. Verify ND admission remains fail closed and observe zero pilot-readiness 503s for 30 minutes.
  • Prove interruption recovery on real Postgres

    manual

    Run the opt-in Postgres test before production cutover.

    Packages: @lssm-tech/lib.contracts-spec, @lssm-tech/app.api-application-monolith

    1. Set MANAGED_COMPANYOS_TEST_DATABASE_URL to a disposable local Postgres database.
    2. Run scripts/bootstrap-admin-postgres.test.ts.
    3. Confirm the existing credential hash remains unchanged.
  • Verify deterministic replay on disposable PostgreSQL

    manual

    Prove organization atomicity, resumability, drift rejection, and RLS.

    Packages: @lssm-tech/lib.contracts-spec, @lssm-tech/app.api-application-monolith, @lssm-tech/lib.organization-planning-spec

    1. Use PostgreSQL 15 with a NOSUPERUSER NOBYPASSRLS application role.
    2. Apply the full migration chain and a simulated production-through-0017 upgrade path.
    3. Inject a family failure and prove whole-organization rollback while prior organizations remain resumable.
    4. Confirm no OAuth credential, provider mapping, calendar identifier, health row, raw booking URL, or secret appears in receipts or logs.
  • Declare a relationship section on a detail view

    assisted

    Add a kind:'relationship' section to a DataView detail/management config to render related records.

    Packages: @lssm-tech/lib.contracts-spec, @lssm-tech/lib.design-system

    1. Add a section with `kind: 'relationship'` and a `relationship` descriptor (`key`, `cardinality`, and either inline `fields` or a child `specKey`).
    2. Set `displayMode` ('table' | 'list' | 'compact-list', default compact-list), optional `limit`, and `emptyState`.
    3. Supply records via embedded `dataPath`, the `relationData`/`getRelationData` props, or wrap the workspace in `RelationDataProvider`; the design-system never fetches.
    4. Pass `onOpenRelated(relationKey, record)` to enable drill-in; omit it for read-only.
  • Opt into per-field intelligent actions in list renderers

    assisted

    The shared DataViewList(.native) now accepts an optional fieldActions prop (default off).

    Packages: @lssm-tech/lib.contracts-spec, @lssm-tech/lib.design-system

    1. Pass `fieldActions="auto"` to `DataViewList`/`DataViewRendererList` to surface per-field intelligent actions in list/compact-list mode; omit it to keep existing output unchanged.
  • Consume the ReviewReady app-submission-readiness contract surface

    assisted

    Import the new contracts, registries, and constants additively; existing app-submission-readiness fixtures/runtime/types subpaths are unchanged.

    Packages: @lssm-tech/lib.contracts-spec

    1. Resolve operations via appSubmissionReadinessOperationRegistry keyed by meta.key.
    2. Resolve events via appSubmissionReadinessEventRegistry.
    3. Pass reviewer/provider credentials only as secretRefId references, never raw values.
    4. Provide sourceUrl, retrievedAt, effectiveDate, and reviewState when creating rules.
  • Adopt the ReviewReady provider capability registry and store integrations

    assisted

    Use the additive provider-capabilities registry and the new read-first integration packages with secret-ref-only auth and deterministic mocks.

    Packages: @lssm-tech/lib.contracts-spec, @lssm-tech/integration.app-store-connect, @lssm-tech/integration.google-play-developer

    1. Resolve capability metadata via getProviderCapability(store, fieldId).
    2. Use createMockAppStoreConnectClient / createMockGooglePlayDeveloperClient in tests and CI.
    3. Provide store credentials only as secret refs (privateKeySecretRefId / serviceAccountSecretRefId).
    4. Enable live calls only after wiring a host secret resolver; default behavior makes no network calls.
    5. Treat manual-required / unsupported / degraded capability results as explicit gaps, never as failures to retry blindly.
  • Await Web Crypto based signer APIs

    manual

    signControlPlaneSkillManifest, verifyControlPlaneSkillManifest, signOverlay, verifyOverlaySignature, signWorkspaceOverlay, and verifyWorkspaceOverlay now return Promises because browser-compatible Web Crypto signing is asynchronous.

    Packages: @lssm-tech/lib.contracts-spec, @lssm-tech/lib.authos-runtime, @lssm-tech/example.openbanking-powens, @lssm-tech/lib.ai-agent, @lssm-tech/bundle.library, @lssm-tech/lib.contracts-integrations, @lssm-tech/lib.harness, @lssm-tech/lib.testing, @lssm-tech/lib.execution-lanes, @lssm-tech/lib.observability, @lssm-tech/module.alpic, @lssm-tech/lib.jobs, @lssm-tech/bundle.workspace, @lssm-tech/lib.files, @lssm-tech/lib.evolution, @lssm-tech/lib.builder-runtime, @lssm-tech/lib.companyos-runtime, @lssm-tech/module.workspace, @lssm-tech/example.integration-hub, @lssm-tech/integration.runtime, @lssm-tech/integration.harness-runtime, @lssm-tech/integration.provider-meeting-recorder, @lssm-tech/lib.overlay-engine, @lssm-tech/lib.surface-runtime, @lssm-tech/tool.bun, @lssm-tech/agentpacks, @lssm-tech/lib.crypto-utils, @lssm-tech/lib.schema, @lssm-tech/lib.bus, @lssm-tech/lib.logger, @lssm-tech/lib.runtime-sandbox, @lssm-tech/lib.voice, @lssm-tech/module.governance-suite, @lssm-tech/integration.provider-voice, @lssm-tech/integration.providers-impls

  • Register the six built-in reference kinds in your composition root

    manual

    Call `registerBuiltInReferenceKinds()` once at boot; the registry is process-global.

    Packages: @lssm-tech/lib.contracts-spec, @lssm-tech/integration.runtime, @lssm-tech/lib.authos-runtime

    1. Pick a single composition root (e.g. server bootstrap or app entry).
    2. Call `registerBuiltInReferenceKinds()` before any handler resolves a reference.
  • Wire the REST/GraphQL/MCP adapters via composition roots

    assisted

    Each adapter binds the four ports into a shared `ReferenceDispatcher`.

    Packages: @lssm-tech/lib.contracts-spec, @lssm-tech/integration.runtime, @lssm-tech/lib.authos-runtime

    1. Import the appropriate wire-* module from `@lssm-tech/integration.runtime/rich-reference`.
    2. Provide concrete impls of `SubjectProvider`, `CoarsePreferencesProvider`, `KindPolicyProvider`, `AuditSink`.
    3. The MCP wiring exposes `rich_reference.resolve` and `rich_reference.detail` tool descriptors.
  • Use the role-adaptive shell evidence packet as the release checklist

    manual

    The evidence packet records required commands, blockers, and compatibility posture for the approved plan.

    Packages: @lssm-tech/lib.contracts-spec, @lssm-tech/lib.surface-runtime, @lssm-tech/lib.personalization, @lssm-tech/lib.design-system, @lssm-tech/bundle.managed-companyos, @lssm-tech/app.web-application-monolith

    1. Review docs/role-adaptive-companyos-app-shell-evidence.md before merging implementation lanes.
    2. Update known gaps with integrated verification output or explicitly accepted residual risks.
  • Wire app-owned dynamic RBAC providers

    assisted

    Apps that store workspace-specific role bindings can implement a role-permission source and pass it to `RBACPolicyEngine.evaluateRequirement`.

    Packages: @lssm-tech/lib.contracts-spec, @lssm-tech/lib.identity-rbac, @lssm-tech/lib.design-system, @lssm-tech/lib.personalization

    1. Resolve static templates and dynamic role/binding records for the current tenant/workspace.
    2. Mark explicit denies with `effect: "deny"` so they override static/template grants.
    3. Treat provider failure as a protected-operation denial unless an audited break-glass path exists.
  • Resolve Special Ops decide/approve handlers through the production registry

    manual

    Lane handlers should resolve the two new operations through companyOsOperationRegistry rather than reaching into individual files.

    Packages: @lssm-tech/lib.contracts-spec

    1. Import ReviewCardDecideCommand and WeeklyReportApproveCommand from @lssm-tech/lib.contracts-spec (companyos commands barrel) or look them up in companyOsOperationRegistry by key (specialOps.reviewCard.decide, specialOps.weeklyReport.approve) when wiring REST/Elysia handlers.
    2. Do not add these production-shaped contracts to packages/examples/special-ops-cockpit; that package must stay a pure fixture demo.
  • Prefer semantic radius aliases for new surfaces

    assisted

    Use `control`, `card`, `panel`, `overlay`, and `pill` where intent is clearer than scale names.

    Packages: @lssm-tech/lib.contracts-spec, @lssm-tech/lib.design-system, @lssm-tech/lib.ui-kit-web, @lssm-tech/lib.ui-kit, @lssm-tech/app.web-application-monolith

    1. Keep existing `--radius` and `sm/md/lg/xl/full` usages working.
    2. Use `--radius-control` for web controls and `--radius-overlay` for modal/sheet-style surfaces.
    3. Use ThemeSpec-resolved `--ds-radius-*` variables for design-system Tailwind integrations.
  • Use ThemeSpec as the Tailwind theme source

    assisted

    Resolve ThemeSpec tokens for the active mode and feed them to the Tailwind preset or CSS serializer.

    Packages: @lssm-tech/lib.contracts-spec, @lssm-tech/lib.design-system

    1. Keep existing `tokens` as the default/light-compatible token bag.
    2. Add `modes.dark.tokens` when a dark-mode overlay is needed.
    3. Use `themeSpecToTailwindPreset` for config-based Tailwind usage or `themeSpecToTailwindCss` when an app wants an importable CSS artifact.
  • BREAKING: remove createTranslationRuntime and engine call sites

    manual

    The ./runtime, ./registry, and ./runtime-helpers subpaths are deleted. Remove all createTranslationRuntime, RuntimeTranslationRegistry, runtimeConfigFromSnapshot, buildFallbackChainForSpec, collectSpecKeys, handleMissing, and related call sites. Preference-override-layer construction (buildOverrideLayersFromPreferenceCatalogs, mapPreferenceSourceToOverrideScope, createTranslationRuntimeFromPreferences, createTranslationRuntimeConfigFromPreferences) has no replacement and must be dropped. resolveTranslationPreferenceContext is preserved.

    Packages: @lssm-tech/lib.contracts-spec, @lssm-tech/lib.translation-runtime, @lssm-tech/lib.design-system

    1. Remove imports from @lssm-tech/lib.translation-runtime/runtime, ./registry, and ./runtime-helpers — these subpaths no longer exist.
    2. Remove all createTranslationRuntime call sites from the active render path.
    3. Remove buildOverrideLayersFromPreferenceCatalogs and createTranslationRuntimeFromPreferences call sites — no factory equivalent exists.
    4. Replace with createI18nFactory + hydrationPayload() on the server and createI18nFactoryFromHydrationPayload on the client (see adopt-factory-snapshot-ssr step).
    5. resolveTranslationPreferenceContext from ./preferences is still available for context and precedence resolution.
  • BREAKING: replace createRuntimeTranslationResolver in design-system

    manual

    createRuntimeTranslationResolver is removed from @lssm-tech/lib.design-system. Use the registry-based createTranslationResolver instead.

    Packages: @lssm-tech/lib.contracts-spec, @lssm-tech/lib.translation-runtime, @lssm-tech/lib.design-system

    1. Replace all createRuntimeTranslationResolver imports and call sites with createTranslationResolver from @lssm-tech/lib.design-system.
  • Adopt factory-stack SSR snapshot/hydration

    assisted

    Replace createTranslationRuntime with createI18nFactory + hydrationPayload() on the server, and createI18nFactoryFromHydrationPayload on the client.

    Packages: @lssm-tech/lib.contracts-spec, @lssm-tech/lib.translation-runtime, @lssm-tech/lib.design-system

    1. Import createI18nFactory from @lssm-tech/lib.contracts-spec/translations.
    2. Call factory.hydrationPayload(undefined, requestLocale) on the server.
    3. Transfer the payload to the client (inline script, RSC stream, etc.).
    4. Import createI18nFactoryFromHydrationPayload and call it with the received payload.
    5. Remove createTranslationRuntime call sites from the active SSR render path.
  • Adopt loader shard scoping for route-level lazy loading

    assisted

    Use loadShardDelta to fetch only the incremental specKeys needed on navigation, reusing already-loaded shared shards.

    Packages: @lssm-tech/lib.contracts-spec, @lssm-tech/lib.translation-runtime, @lssm-tech/lib.design-system

    1. Author a RouteShardManifest per route with defineRouteShardManifest in your app/bundle layer.
    2. On navigation, call loadShardDelta with the loaded and required specKey sets.
    3. Pass the returned catalogs to your factory or bundle loader.
  • Adopt slim inline hydration payload (O2+O3, −60–61% per request)

    assisted

    Reduce the per-request inline <script> hydration payload by ~60% by stripping spec metadata (O2) and enabling value-pool dedup (O3). Catalogs remain bundled and cached in JS — this is a per-request inline-HTML reduction, not a total-transferred-bytes reduction. O3 adds only ~2% over O2 (disjoint key namespaces; value-pool captures ~53 repeated value strings).

    Packages: @lssm-tech/lib.contracts-spec, @lssm-tech/lib.translation-runtime, @lssm-tech/lib.design-system

    1. Enable the slim payload mode on your scoped hydration builder (strip spec metadata before serialization; retain full-spec form server-side for diagnostics).
    2. Enable value-pool dedup to fold repeated value strings into a values[] pool.
    3. Verify CI budget gates pass (single-locale ≤ 64 KB, with-fallback ≤ 128 KB).
    4. Confirm AC1 no-flash is preserved by running the no-flash test suite.
  • Adopt precompiled-ICU fast-path for formatter-path latency (O4)

    manual

    Use @lssm-tech/lib.translation-runtime/precompile at build time to emit FormatJS IR AST alongside each ICU message. createIntlMessageFormatter skips re-parsing when precompiled AST is present. Additive opt-in; no payload size change. Benefit applies to integrations using ICU plural/select messages; factory proof routes use simple {placeholder} interpolation and are unaffected.

    Packages: @lssm-tech/lib.contracts-spec, @lssm-tech/lib.translation-runtime, @lssm-tech/lib.design-system

    1. At bundle build time, call buildPrecompiledIcuCatalogFromSpecs(specs) from @lssm-tech/lib.translation-runtime/precompile over your TranslationSpec[] set.
    2. Serialize the resulting PrecompiledIcuCatalog with serializePrecompiledIcuCatalog and ship as a build asset alongside (or instead of) the plain catalog.
    3. At runtime, parsePrecompiledIcuCatalog + createPrecompiledIcuLookup(catalog), then pass the lookup as the precompiled option to createIntlMessageFormatter.
    4. The fast-path activates automatically for any message with a precompiled entry; messages without one fall back to the standard parser; no other call-site changes needed.
  • Note — dead-key pruning is a CI audit tool under Model A (O5/#17)

    auto

    @lssm-tech/tool.i18n-prune ships as a CI audit tool reporting dead keys per route against a RouteShardManifest. It does not drive the runtime payload under Model A (catalogs bundled+cached; synchronous fallback). The intersectScopedI18nHydration mechanism is wired and fail-safe but currently no-op; it auto-activates if a precise reachability map ships in a future Model B follow-up. No action required.

    Packages: @lssm-tech/lib.contracts-spec, @lssm-tech/lib.translation-runtime, @lssm-tech/lib.design-system

    1. Add @lssm-tech/tool.i18n-prune to your CI pipeline to audit dead keys.
    2. No runtime wiring changes needed under Model A.
  • Declare operation-specific success and failure outcomes

    assisted

    Use `defineResultCatalog`, `standardSuccess`, `standardErrors`, `success`, and `failure` from `@lssm-tech/lib.contracts-spec/results` when an operation, workflow, or job needs custom codes.

    Packages: @lssm-tech/lib.contracts-spec, @lssm-tech/lib.contracts-runtime-server-rest, @lssm-tech/lib.contracts-runtime-server-graphql, @lssm-tech/lib.contracts-runtime-server-mcp, @lssm-tech/lib.contracts-runtime-client-react, @lssm-tech/lib.jobs, @lssm-tech/lib.error

    1. Keep raw handler returns for ordinary `OK` responses.
    2. Use `contractAccepted`, `contractQueued`, `contractNoContent`, or `contractPartial` for non-default success outcomes.
    3. Throw `createContractError` or return `contractFail` for known failures with typed args.
    4. Declare custom success codes in `spec.results.success` or `io.success`, and custom failures in `spec.results.errors` or `io.errors`.
  • Use canonical result mappers in adapters and clients

    assisted

    Route transport boundaries through the new result helpers while preserving raw success compatibility by default.

    Packages: @lssm-tech/lib.contracts-spec, @lssm-tech/lib.contracts-runtime-server-rest, @lssm-tech/lib.contracts-runtime-server-graphql, @lssm-tech/lib.contracts-runtime-server-mcp, @lssm-tech/lib.contracts-runtime-client-react, @lssm-tech/lib.jobs, @lssm-tech/lib.error

    1. Use `OperationSpecRegistry.executeResult` in adapters that need success metadata or typed failures.
    2. Set REST `resultEnvelope: true` only when clients should receive `{ ok, data }` success envelopes.
    3. Enable GraphQL `resultExtensions` only when the server integration publishes collected success metadata.
    4. Use React runtime parser/hooks to normalize REST, GraphQL, MCP, workflow, and job responses into `ContractResult`.
  • Adopt the unified database runtime

    assisted

    Bind pooling + observability + RLS tenant scoping + AuthOS principal + governed resolvers via a single createDatabaseRuntime() handle.

    Packages: @lssm-tech/lib.contracts-spec, @lssm-tech/integration.provider-database, @lssm-tech/integration.runtime-managed, @lssm-tech/lib.presentation-runtime-next, @lssm-tech/lib.contracts-runtime-core, @lssm-tech/lib.contracts-runtime-client-react, @lssm-tech/tool.contractspec-drizzle-gen, @lssm-tech/integration.providers-impls, @lssm-tech/bundle.library

    1. Import from the server-only @lssm-tech/integration.runtime-managed/database subpath (never the root barrel).
    2. Pass an Instrumentation instance to auto-emit database.query / database.mutation spans + metrics.
    3. Choose a pooler mode (transaction for pgBouncer/Supabase → prepare:false).
  • Adopt the SSR prefetch → hydrate bridge

    assisted

    Prefetch governed reads in a Server Component and hydrate the client data engine with zero second fetch.

    Packages: @lssm-tech/lib.contracts-spec, @lssm-tech/integration.provider-database, @lssm-tech/integration.runtime-managed, @lssm-tech/lib.presentation-runtime-next, @lssm-tech/lib.contracts-runtime-core, @lssm-tech/lib.contracts-runtime-client-react, @lssm-tech/tool.contractspec-drizzle-gen, @lssm-tech/integration.providers-impls, @lssm-tech/bundle.library

    1. In an RSC, call prefetchGovernedQuery(resolver, envelope, ctx) then dehydrateGovernedQuery(result, envelope).
    2. Wrap the client island in HydrationBoundary and build its DataEngine over the same CacheStore (localOffline 'offline-capable').
    3. Render through QueryStateView for loading/empty/error/success states.
  • Adopt cursor pagination in useContractQuery

    auto

    Use hasNextPage + fetchNextPage() to advance cursor pages; offset callers are unchanged.

    Packages: @lssm-tech/lib.contracts-spec, @lssm-tech/integration.provider-database, @lssm-tech/integration.runtime-managed, @lssm-tech/lib.presentation-runtime-next, @lssm-tech/lib.contracts-runtime-core, @lssm-tech/lib.contracts-runtime-client-react, @lssm-tech/tool.contractspec-drizzle-gen, @lssm-tech/integration.providers-impls, @lssm-tech/bundle.library

    1. Read pageInfo / hasNextPage from the hook result and call fetchNextPage() to load the next page.
  • Validate governed read field mappings before enabling cursor reads

    manual

    Cursor reads are fail-closed and require selected, allowlisted cursor/sort/filter fields.

    Packages: @lssm-tech/lib.contracts-spec, @lssm-tech/lib.contracts-runtime-client-react, @lssm-tech/integration.provider-database, @lssm-tech/lib.design-system

    1. Ensure DataView database bindings map only selectable fields.
    2. Provide stable cursor sort metadata or a cursor field that is included in the selected field allowlist.
    3. Treat malformed cursor payloads as invalid input rather than falling back to raw SQL interpolation.
  • Scaffold release capsule companions

    manual

    Add release capsules for changesets and include validation evidence.

    Packages: @lssm-tech/lib.contracts-spec, @lssm-tech/bundle.workspace, @lssm-tech/app.cli-contractspec, @lssm-tech/app.web-landing

    1. Run `contractspec release init` for new release work.
    2. Keep `.changeset/*.md` and `.changeset/*.release.yaml` together in the same PR.
    3. Use `contractspec release brief` or `contractspec upgrade prompt` to generate maintainer, customer, and agent guidance.
  • Use generated release manifests in tooling

    assisted

    Prefer generated release artifacts for changelog and upgrade flows.

    Packages: @lssm-tech/lib.contracts-spec, @lssm-tech/bundle.workspace, @lssm-tech/app.cli-contractspec, @lssm-tech/app.web-landing

    1. Run `contractspec release build` to populate `generated/releases/`.
    2. Point changelog or upgrade tooling at `generated/releases/manifest.json` and `generated/releases/upgrade-manifest.json`.

Unique release changes

  • - Consume the release before importing crypto-adjacent ContractSpec surfaces from Expo or React Native bundles.

    31 packages · 31 occurrences

  • - Replace Node crypto, create-hash, create-hmac, and global randomUUID usage outside apps with an internal Expo-safe crypto utility package.

    31 packages · 31 occurrences

  • - signControlPlaneSkillManifest, verifyControlPlaneSkillManifest, signOverlay, verifyOverlaySignature, signWorkspaceOverlay, and verifyWorkspaceOverlay now return Promises because browser-compatible Web Crypto signing is asynchronous.

    31 packages · 31 occurrences

  • - Introduce the Builder v3 control plane as a governed authoring layer over external execution providers.

    21 packages · 21 occurrences

  • - Wire provider/runtime integrations through the governed Builder v3 workbench and mobile-review surfaces.

    21 packages · 21 occurrences

  • - Add provider-adaptable multiplayer agents, governed self-improvement, continuous workers, self-maintaining APIs, and fail-closed enterprise qualification.

    20 packages · 20 occurrences

  • - Built-in profiles are candidate templates, not production attestations. Pin the selected profiles, controls, and environment and qualify them before serving production traffic.

    20 packages · 20 occurrences

  • - Add a contract-first, filesystem-authored agent application foundation with governed runtime ports, durable cross-adapter conformance, isolated EVE integration, agent evals, and a reference application.

    12 packages · 12 occurrences

  • - Compile the filesystem fixture, run package-local tests, and inspect the case-18 comparison artifact before enabling EVE.

    12 packages · 12 occurrences

  • - No canary or stable release is implied by source-level validation; clean Node and Bun consumers remain a publication gate.

    12 packages · 12 occurrences

  • - Runtime-local copies of the adapter-key union are deprecated; import the canonical identity from `@lssm-tech/lib.contracts-spec/runtime-adapters`.

    12 packages · 12 occurrences

  • - The closed AgentRuntimeAdapterKey union gained `eve` in both AgentSpec and WorkflowSpec.

    12 packages · 12 occurrences

  • - The local-process adapter proves policy wiring and redaction, not operating-system containment.

    12 packages · 12 occurrences

  • - Treating a local child process as a production isolation boundary is unsupported; the local sandbox adapter is a development fixture only. Select the Docker adapter when the production containment suite and deployment prerequisites are satisfied.

    12 packages · 12 occurrences

  • - @lssm-tech/lib.data-transmission-runtime — removed; absorbed into the contracts-runtime-core engine + the crdt-loro conflict resolver.

    11 packages · 11 occurrences

  • - @lssm-tech/lib.data-transmission-spec — removed; absorbed into contracts-spec (protocol) + contracts-runtime-core (engine, Collaboration* types).

    11 packages · 11 occurrences

  • - Add vendor-neutral AI self-improvement contracts and a mock-first Pioneer adapter.

    11 packages · 11 occurrences

  • - Collapse data fetching into one spec-first protocol + an in-house engine in the new contracts-runtime-core; remove the data-transmission packages; prove it end-to-end on entity-workspace.

    11 packages · 11 occurrences

  • - contracts-runtime-client-react ./query-client subpath — removed (deleted file).

    11 packages · 11 occurrences

  • - contracts-runtime-client-react helpers buildContractQueryKey, getContractQueryCacheKey, ContractQueryStorage*, ContractQueryCacheRecord, readWarmContractQueryCache, readContractQueryCache, writeContractQueryCache, canRunContractMutationOffline, assertContractQueryMutationPolicy, and the buildContractQueryEnvelopeKey alias — removed; the engine owns cache-key/storage/policy.

    11 packages · 11 occurrences

  • - Move imports and hooks onto the canonical contracts-spec protocol and the contracts-runtime-core engine.

    11 packages · 11 occurrences

  • - Move query/cache/offline state onto contracts-spec + contracts-runtime-core; consume canonical QueryState in design-system.

    11 packages · 11 occurrences

  • - Use `@lssm-tech/integration.provider-pioneer-ai` for Pioneer jobs and receipts; keep credentials outside serialized evidence.

    11 packages · 11 occurrences

  • - Use `@lssm-tech/lib.contracts-spec/ai-improvement` for policy, risk, replay, and evidence IDs before wiring vendor adapters.

    11 packages · 11 occurrences

  • - Add contract-driven overflow behavior and typed DataView hints for shared DataView and DataTable surfaces.

    10 packages · 10 occurrences

  • - Existing tables keep working, but long prose, markdown, and detail-heavy columns can now declare their intended behavior.

    10 packages · 10 occurrences

  • - The contract, runtime, web, native, design-system, CLI, and workspace layers all participate in overflow behavior.

    10 packages · 10 occurrences

  • - Bind pooling + observability + RLS tenant scoping + AuthOS principal + governed resolvers via a single createDatabaseRuntime() handle.

    8 packages · 8 occurrences

  • - Prefetch governed reads in a Server Component and hydrate the client data engine with zero second fetch.

    8 packages · 8 occurrences

  • - Replace raw provider construction with the runtime preset to get automatic RLS tenant scoping, observability, and governed resolvers.

    8 packages · 8 occurrences

  • - Unified ContractSpec database runtime: createDatabaseRuntime() preset (pooling, zero-config observability, RLS tenant scoping, AuthOS principal carriage, governed resolvers) plus a typed N+1-safe relational read path, a spec-first generated Drizzle schema, and an SSR prefetch→hydrate bridge. Fully additive.

    8 packages · 8 occurrences

  • - Use hasNextPage + fetchNextPage() to advance cursor pages; offset callers are unchanged.

    8 packages · 8 occurrences

  • - Add a canonical typed result system for ContractSpec success and failure propagation across operations, workflows, jobs, server adapters, MCP, GraphQL, and React clients.

    7 packages · 7 occurrences

  • - Add a family-aware ContractSpec Adoption Engine, expand contract authoring targets across CLI and VS Code tooling, and refresh release-facing schema and policy artifacts for downstream workspaces.

    7 packages · 7 occurrences

  • - ContractSpec workspaces can now opt into family-aware reuse guidance and local catalog sync through `connect.adoption`.

    7 packages · 7 occurrences

  • - Generated Biome policy artifacts now flag deprecated monolith usage and obvious deep runtime entrypoint imports.

    7 packages · 7 occurrences

  • - Prefer `ContractSpecError`, `createContractError`, and `contractFail` from `@lssm-tech/lib.contracts-spec/results`; `@lssm-tech/lib.error` remains as a compatibility bridge for existing `AppError` users.

    7 packages · 7 occurrences

  • - Replace new uses of `AppError` with `ContractSpecError` or `contractFail`; existing `AppError` consumers can convert to a compatible problem shape with `appErrorToProblem`.

    7 packages · 7 occurrences

  • - Route transport boundaries through the new result helpers while preserving raw success compatibility by default.

    7 packages · 7 occurrences

  • - Shared workspace discovery and IDE/CLI create flows now recognize additional contract families beyond the original core set.

    7 packages · 7 occurrences

  • - The consumer plugin and Connect CLI now expose adoption-aware hook events in addition to contracts-spec review hooks.

    7 packages · 7 occurrences

  • - Use `defineResultCatalog`, `standardSuccess`, `standardErrors`, `success`, and `failure` from `@lssm-tech/lib.contracts-spec/results` when an operation, workflow, or job needs custom codes.

    7 packages · 7 occurrences

  • - Add mobile-safe FormSpec layout helpers and scoped DataView filters.

    6 packages · 6 occurrences

  • - Add optional database binding metadata to DataView, FormSpec, PolicySpec, Knowledge, RBAC, and data-exchange declarations while keeping execution behind provider/database adapters.

    6 packages · 6 occurrences

  • - Add password-aware FormSpec rendering with current/new password manager hints and visibility toggles.

    6 packages · 6 occurrences

  • - Add portable database bindings and governed PostgreSQL provider leverage across ContractSpec core surfaces.

    6 packages · 6 occurrences

  • - Add production-ready collection defaults and renderer mode switching for DataView list, grid, and table specs.

    6 packages · 6 occurrences

  • - Custom form renderers can provide the optional `PasswordInput` slot to get a visibility toggle.

    6 packages · 6 occurrences

  • - Declare initial and locked filters in the DataView contract instead of passing all filters as removable renderer state.

    6 packages · 6 occurrences

  • - Document the additive release posture and verification matrix for the contract-driven role-adaptive CompanyOS app shell.

    6 packages · 6 occurrences

  • - Existing `layout.columns: 2` contracts continue to render as base two-column layouts.

    6 packages · 6 occurrences

  • - Existing specs keep working; add view.collection when a renderer should expose shared collection controls or query page-size defaults.

    6 packages · 6 occurrences

  • - Existing text fields and custom driver slots remain compatible.

    6 packages · 6 occurrences

  • - Prefer `text.password.purpose` for password fields instead of renderer-specific `uiProps.type`.

    6 packages · 6 occurrences

  • - Replace ad hoc responsive column objects with `responsiveFormColumns(...)` where mobile forms should render one field per row.

    6 packages · 6 occurrences

  • - The documentation classifies the intended release as additive, but feature completion depends on integrated implementation-lane evidence.

    6 packages · 6 occurrences

  • - The evidence packet records required commands, blockers, and compatibility posture for the approved plan.

    6 packages · 6 occurrences

  • - Use `view.filterScope.locked` for non-removable list constraints such as category-scoped posts.

    6 packages · 6 occurrences

  • - `FieldSpec.wrapper.orientation` remains supported but should be replaced by `FieldSpec.layout.orientation` in new specs.

    5 packages · 5 occurrences

  • - Add fail-closed agentic interaction and CommunicationOS command-inbox release evidence across contracts, runtime, module, examples, and agent-facing docs.

    5 packages · 5 occurrences

  • - Add FormSpec layout hints, semantic field rendering, and portable text/textarea input-group addons.

    5 packages · 5 occurrences

  • - Add text or icon addon descriptors to text and textarea fields.

    5 packages · 5 occurrences

  • - Add the public ContractSpec editorial radius scale and semantic aliases across contracts, design-system Tailwind bridges, app CSS parity, and bounded preview/toast migrations.

    5 packages · 5 occurrences

  • - Advance contract-driven entity surface foundations, gates, and consumer docs.

    5 packages · 5 occurrences

  • - AIP mapping controls are opt-in safety contracts, not root-barrel exports.

    5 packages · 5 occurrences

  • - Build entity surfaces with DataViewSpec, EntityWorkspace product-shell chrome, DataViewRenderer lower-level rendering, host edit slots, AdaptivePanel, RichRef, personalization, and RoleMorph adapters.

    5 packages · 5 occurrences

  • - CommunicationOS commands persist as review evidence with `canExecute: false`.

    5 packages · 5 occurrences

  • - Existing forms continue to render without changes.

    5 packages · 5 occurrences

  • - Graph & timeline primitives milestone — new DataViewKinds, UI primitives, EntityRegistry, and 3 reference examples.

    5 packages · 5 occurrences

  • - Hosts that rely on workspace-generated forms should expect dotted FormSpec keys such as `profile.edit` to resolve to qualified filenames such as `profile-edit.form.*`.

    5 packages · 5 occurrences

  • - M5 AI-native graph editing — graph.edit / graph.refactor / graph.compose / graph.suggest_evolution + AiPairPanel

    5 packages · 5 occurrences

  • - New input addons should use `inputGroup.addons` on text and textarea fields.

    5 packages · 5 occurrences

  • - New multi-column forms should use `FormSpec.layout`, `group.layout`, and `field.layout.colSpan`.

    5 packages · 5 occurrences

  • - Opt in to the M5 AI pair panel on any template

    5 packages · 5 occurrences

  • - Public docs should import `RichRef` from `@lssm-tech/lib.ui-kit-web/rich-ref`, pass `kindId` and `refId`, and use valid variants/panel modes.

    5 packages · 5 occurrences

  • - Replace renderer-specific row wrappers with portable column and colspan metadata.

    5 packages · 5 occurrences

  • - Run the focused validation matrix before publishing packages or public docs.

    5 packages · 5 occurrences

  • - The release adds public-surface gates and docs; it intentionally does not document EntityWorkspace as shipped.

    5 packages · 5 occurrences

  • - Use `control`, `card`, `panel`, `overlay`, and `pill` where intent is clearer than scale names.

    5 packages · 5 occurrences

  • - Add a shared roles and permissions policy system across contracts, RBAC evaluation, AppShell adaptation, and personalization suppression.

    4 packages · 4 occurrences

  • - Add a strict historical-v1 database read boundary so a human can approve forward-only migration 007 before it normalizes text storage to the unchanged public integer-v1 contract, while preserving approval-event provenance across historical JSON-only and complete denormalized storage shapes.

    4 packages · 4 occurrences

  • - Add adaptive DataView management-shell contracts and command-center proof metadata.

    4 packages · 4 occurrences

  • - Add experimental graph artifact contracts and read-only graph/drift CLI workflows.

    4 packages · 4 occurrences

  • - Add first-class monorepo-aware environment contracts and managed/BYOK credential setup helpers.

    4 packages · 4 occurrences

  • - Add governed rich code/diff surfaces with references, redaction, RoleMorph, and personalization support. Historical wave-0 entry; the legacy CodeBlock/DiffBlock/ObjectReferenceHandler surfaces are superseded by the rich-reference foundation (see `rich-reference-breaking-release`).

    4 packages · 4 occurrences

  • - Add OSS harness CLI verification with deterministic Playwright, optional agent-browser visual runs, auth profile refs, visual diff evidence, replay bundles, and core scenario success semantics.

    4 packages · 4 occurrences

  • - Add preference-aware DataView collection defaults and personalization adapters.

    4 packages · 4 occurrences

  • - Add release capsules for changesets and include validation evidence.

    4 packages · 4 occurrences

  • - Add scoped operation approval enforcement across core, REST, and MCP runtimes.

    4 packages · 4 occurrences

  • - Add the durable local Connect approval kernel, linkage recovery, and tenant isolation.

    4 packages · 4 occurrences

  • - Add the first unified query stack across contracts, runtime client cache boundaries, governed provider reads, and EntityWorkspace local-vs-remote query ownership.

    4 packages · 4 occurrences

  • - Add versioning-backed release capsules, generated patch notes, and guided upgrade flows.

    4 packages · 4 occurrences

  • - Adoption-aware release pipeline with accumulating release index, per-version detail files, CLI changelog list/view commands, and web changelog version pages.

    4 packages · 4 occurrences

  • - After a release build, `generated/releases/index.json` contains the accumulating release index, and `generated/releases/versions/v{slug}.json` contains full per-version details. The full manifest is still overwritten.

    4 packages · 4 occurrences

  • - Apply the additive migrations with an owner distinct from the runtime role.

    4 packages · 4 occurrences

  • - Apply the additive schema and verify FORCE RLS before enabling durable local review.

    4 packages · 4 occurrences

  • - Apps that store workspace-specific role bindings can implement a role-permission source and pass it to `RBACPolicyEngine.evaluateRequirement`.

    4 packages · 4 occurrences

  • - Authenticated browser scenarios should reference named storage-state, browser-profile, session-name, or headers-env profiles instead of embedding secrets.

    4 packages · 4 occurrences

  • - Bind durable production dependencies and prove request authority, degraded behavior, responsive rendering, and tenant isolation in each target deployment.

    4 packages · 4 occurrences

  • - Both `publish-canary` and `publish-npm` workflows now run the adoption hook after release build to sync catalogs and write pending upgrades.

    4 packages · 4 occurrences

  • - Confirm old module imports keep the legacy module id while new library imports use the library module id.

    4 packages · 4 occurrences

  • - Consumers that only read card title, description, and href do not need to change. Consumers that render richer contract pages can display cards[].fields as labelled rows and cards[].iconKey through an icon registry with a fallback.

    4 packages · 4 occurrences

  • - Cursor reads are fail-closed and require selected, allowlisted cursor/sort/filter fields.

    4 packages · 4 occurrences

  • - Custom autocomplete driver slots can opt into loading/error rendering without changing existing fields.

    4 packages · 4 occurrences

  • - Declare execution effects and approval requirements, then configure a durable approval runtime.

    4 packages · 4 occurrences

  • - Existing policies continue to work; add roles, permissions, policy refs, and field policies when a contract needs stronger authorization metadata.

    4 packages · 4 occurrences

  • - Expose reusable static translation diagnostics and add contractspec i18n check for CI-friendly catalog validation, including missing catalogs, missing keys, blank values, ICU syntax, placeholder parity, JSON output, and optional .contractsrc.json i18n defaults.

    2 packages · 4 occurrences

  • - Implement ContractSpec Connect as a first-class spec, runtime, and CLI workflow.

    4 packages · 4 occurrences

  • - Improve app-config, theme, and feature authoring with explicit validation APIs, first-class theme discovery and scaffolding, and key-based app-config generation across contracts, workspace tooling, and the CLI.

    4 packages · 4 occurrences

  • - Improve FormSpec autocomplete rendering and resolver-backed search.

    4 packages · 4 occurrences

  • - Introduce ContractSpec-first semantic marketing presentation primitives, serializable runtime descriptors, a design-system renderer registry, and Managed CompanyOS proof adoption.

    4 packages · 4 occurrences

  • - Keep DataViewRenderer dependency-free by resolving personalization preferences before rendering.

    4 packages · 4 occurrences

  • - Move new notification integrations away from the module shim.

    4 packages · 4 occurrences

  • - Move notifications to library-first contracts/runtime surfaces and add AppShell in-app notification affordances.

    4 packages · 4 occurrences

  • - Pass remote query-source semantics when items are already filtered, sorted, or paginated by a server/provider so EntityWorkspace does not apply local controls twice.

    4 packages · 4 occurrences

  • - Playwright and agent-browser are optional runtime dependencies, but local full-app proof requires the corresponding browser binaries or CLI.

    4 packages · 4 occurrences

  • - Prefer generated release artifacts for changelog and upgrade flows.

    4 packages · 4 occurrences

  • - Prefer the package-level validators over shallow AST checks for the three upgraded surfaces.

    4 packages · 4 occurrences

  • - Promote M5-shipped graph contracts from beta to stable.

    4 packages · 4 occurrences

  • - Provide notification items and callbacks to the design-system shell without coupling it to a delivery runtime.

    4 packages · 4 occurrences

  • - Published release changesets now require a structured release capsule.

    4 packages · 4 occurrences

  • - Redesign the CompanyOS /solutions buyer path around starter workflows, reusable governed workflow patterns, and bring-your-own-process conversion while adding structured marketing contract card fields and icon-key transport.

    4 packages · 4 occurrences

  • - Replace arbitrary primitive strings with supported semantic IDs and move direct React component names into render target hints.

    4 packages · 4 occurrences

  • - Replace static Company Intelligence and OPA fixtures with authenticated, tenant-free dynamic surface descriptors and responsive managed templates.

    4 packages · 4 occurrences

  • - Shared app-config authoring DTOs and templates now use `key`-based spec references instead of older `name`-based helper fields.

    4 packages · 4 occurrences

  • - Shared workspace discovery and the CLI now treat `theme` as a first-class authored surface.

    4 packages · 4 occurrences

  • - The `@lssm-tech/module.notifications` package remains import-compatible for this release, but new code should import contracts from `@lssm-tech/lib.contracts-spec/notifications` and runtime helpers from `@lssm-tech/lib.notification`.

    4 packages · 4 occurrences

  • - The standalone release domain under `@lssm-tech/lib.contracts-spec/release` is deprecated in favor of versioning-owned release metadata.

    4 packages · 4 occurrences

  • - Theme authoring now has a canonical helper and authored-validator support.

    4 packages · 4 occurrences

  • - Turn on the Connect adapter flow before relying on task-scoped context, review, replay, or evaluation artifacts.

    4 packages · 4 occurrences

  • - Use @lssm-tech/lib.contracts-spec/query to normalize search, filters, sort, offset pagination, cursor pagination, cache hints, and result page metadata before wiring UI or database adapters.

    4 packages · 4 occurrences

  • - Use contractspec i18n check to validate translation catalogs before release or merge.

    2 packages · 4 occurrences

  • - Use the built-in Connect commands instead of custom local wrappers for risky file or command mutations.

    4 packages · 4 occurrences

  • - Use the new additive DataView metadata to describe management-shell layouts and host-owned action boundaries.

    4 packages · 4 occurrences

  • - Use workspace environment definitions and app targets instead of duplicating public env names across apps.

    4 packages · 4 occurrences

  • - Validate and denormalize approval-event provenance, then normalize only valid v1 values.

    4 packages · 4 occurrences

  • - @lssm-tech/lib.design-system removed createRuntimeTranslationResolver; use the registry-backed createTranslationResolver instead.

    3 packages · 3 occurrences

  • - @lssm-tech/lib.translation-runtime no longer exports the deprecated runtime engine subpaths or preference override-layer construction helpers; consumers must migrate active render paths to the factory stack.

    3 packages · 3 occurrences

  • - @lssm-tech/tool.i18n-prune ships as a CI audit tool reporting dead keys per route against a RouteShardManifest. It does not drive the runtime payload under Model A (catalogs bundled+cached; synchronous fallback). The intersectScopedI18nHydration mechanism is wired and fail-safe but currently no-op; it auto-activates if a precise reachability map ships in a future Model B follow-up. No action required.

    3 packages · 3 occurrences

  • - `kind: "email"` only describes rendering intent; strict validation remains schema-owned.

    3 packages · 3 occurrences

  • - Add a ContractSpec-native production-grade translation runtime and optional i18next adapter.

    3 packages · 3 occurrences

  • - Add factory-stack SSR snapshot/hydration, loader shard scoping, RouteShardManifest, and parity diagnostics extensions for translation catalog sharding + SSR.

    3 packages · 3 occurrences

  • - Add first-class FormSpec email fields with native renderer affordances.

    3 packages · 3 occurrences

  • - Add first-class FormSpec phone input support with country detection, split outputs, and flag rendering.

    3 packages · 3 occurrences

  • - Add non-shareable personal CompanyOS contexts and atomic opaque personal/company/team/workspace selection with request-time authority proof.

    3 packages · 3 occurrences

  • - Add numeric and temporal FormSpec field kinds with shared renderer support for number, percent, currency, and duration inputs.

    3 packages · 3 occurrences

  • - Add policy decision, authority scope, actor, approval/refusal, audit receipt, redaction status, replay/evidence, risk tier, and timestamp refs before committing high-impact transitions.

    3 packages · 3 occurrences

  • - Add progressive FormSpec section and step layout metadata with shared React and design-system rendering support.

    3 packages · 3 occurrences

  • - Add PWA update management contracts and runtime helpers.

    3 packages · 3 occurrences

  • - Add the ReviewReady provider capability registry and read-first App Store Connect / Google Play integration packages.

    3 packages · 3 occurrences

  • - Align CompanyOS work, surface, adaptation, and safety authoring on canonical ontology graph refs.

    3 packages · 3 occurrences

  • - Align database mutation docs, release-capsule guidance, and LLM-facing surfaces around governed domain-command writes.

    3 packages · 3 occurrences

  • - Apply forward migrations 0029 and 0030 before deploying the context routes or enabling the production shell selector.

    3 packages · 3 occurrences

  • - Call `registerBuiltInReferenceKinds()` once at boot; the registry is process-global.

    3 packages · 3 occurrences

  • - Canonical RichReference subpath + ReferenceRuntime (split) + canonical serializer + detector + reference.resolve/detail queries + REST/GraphQL/MCP adapter wirings + S-9 agent surface (markdown envelope, agent-export passthrough, MCP tool descriptors, delegated/agent subject modes).

    3 packages · 3 occurrences

  • - createRuntimeTranslationResolver is removed from @lssm-tech/lib.design-system. Use the registry-based createTranslationResolver instead.

    3 packages · 3 occurrences

  • - Custom drivers should confirm their existing `Button`, `FieldSet`, `FieldLegend`, `FieldDescription`, and `FieldGroup` slots render the new flow structure cleanly.

    3 packages · 3 occurrences

  • - DataView graph mutations without policy/authority/approval/audit/redaction/evidence/risk metadata are migration targets for fail-closed ontology safety refs.

    3 packages · 3 occurrences

  • - Do not cache organization/workspace projections or create a Postgres pool per request.

    3 packages · 3 occurrences

  • - Document the intentional breaking ontology surface, Autonomous Work Order migration, safety invariant, and final release verification gate.

    3 packages · 3 occurrences

  • - Each adapter binds the four ports into a shared `ReferenceDispatcher`.

    3 packages · 3 occurrences

  • - Exercise work-order creation, agent planning, policy decision, human approval/refusal, rendering, adaptation, evidence, and sanitized training export through the same graph refs.

    3 packages · 3 occurrences

  • - Existing `kind: "phone"` object-valued fields continue to work; opt into new modes through field metadata.

    3 packages · 3 occurrences

  • - Existing `kind: "text"` fields with email input hints continue to render normally.

    3 packages · 3 occurrences

  • - Existing forms render exactly as before unless they opt into `layout.flow`.

    3 packages · 3 occurrences

  • - Existing tenantId fields remain assertion aliases and must not select authorization or RLS scope; derive authority from verified activeOrganizationId, current membership, and the enabled binding.

    3 packages · 3 occurrences

  • - id: package-local-high-impact-graph-mutations; summary: High-impact work/order transitions must not be represented by package-local DataView or graph mutation records without ontology refs and safety evidence.; replacement: Autonomous Work Order graph/state-machine records with ontology refs and safety invariant fields.

    3 packages · 3 occurrences

  • - Import ontology contracts from `@lssm-tech/lib.contracts-spec/ontology` or documented root exports; keep `defineContractEntity`, `defineContractEdge`, and `EntityRegistry` root imports unless a compatibility ledger says otherwise.

    3 packages · 3 occurrences

  • - Include ontology refs on high-impact RoleMorph action boundaries and adaptive events/signals; export only sanitized evidence-linked fine-tuning traces.

    3 packages · 3 occurrences

  • - Link entity, DataView, CompanyOS, RoleMorph, personalization, and fine-tuning records through the canonical ontology graph surface.

    3 packages · 3 occurrences

  • - MANAGED_COMPANYOS_LIVE_SEED_TENANT_ID and MANAGED_COMPANYOS_LIVE_SEED_WORKSPACE_ID are not forward live-seed inputs; the contract manifest owns all organization, tenant, and workspace targets.

    3 packages · 3 occurrences

  • - New field kinds provide stronger semantics and formatting metadata for finance and operations forms.

    3 packages · 3 occurrences

  • - Prefer `meta.key: "bundle.messages"` with `locale: "fr-FR"` over stable keys that encode locale suffixes.

    3 packages · 3 occurrences

  • - Prove non-shareability, one-use switching, capability intersection, revocation denial, atomic audit, and tenant isolation on the target PostgreSQL topology.

    3 packages · 3 occurrences

  • - Prove organization atomicity, resumability, drift rejection, and RLS.

    3 packages · 3 occurrences

  • - Reduce the per-request inline <script> hydration payload by ~60% by stripping spec metadata (O2) and enabling value-pool dedup (O3). Catalogs remain bundled and cached in JS — this is a per-request inline-HTML reduction, not a total-transferred-bytes reduction. O3 adds only ~2% over O2 (disjoint key namespaces; value-pool captures ~53 repeated value strings).

    3 packages · 3 occurrences

  • - Register the PWA update operation, bind it to a manifest resolver, and call it from the frontend on startup or polling intervals.

    3 packages · 3 occurrences

  • - Remove pilot identifiers only from auth readiness, not from the legacy route guard.

    3 packages · 3 occurrences

  • - Replace createTranslationRuntime with createI18nFactory + hydrationPayload() on the server, and createI18nFactoryFromHydrationPayload on the client.

    3 packages · 3 occurrences

  • - Replace renderer-specific email text hints with `kind: "email"` where a field captures one email address.

    3 packages · 3 occurrences

  • - Restore auth health before organization schema or cutover work.

    3 packages · 3 occurrences

  • - Seed and verify every declared family after canonical bootstrap.

    3 packages · 3 occurrences

  • - Seed the canonical LSSM, CompanyOS, and NDconsulting organization families from one contract-owned manifest with deterministic replay and redacted evidence.

    3 packages · 3 occurrences

  • - Separate semantic ontology refs from physical/provenance graph artifacts before changing authoring patterns.

    3 packages · 3 occurrences

  • - Shared drivers can opt into richer rendering for the new field kinds.

    3 packages · 3 occurrences

  • - Ship server-authoritative organization and workspace contracts with API/web recovery runtime, and separate authentication readiness from the legacy ND pilot-admission tuple without weakening legacy route admission.

    3 packages · 3 occurrences

  • - The ./runtime, ./registry, and ./runtime-helpers subpaths are deleted. Remove all createTranslationRuntime, RuntimeTranslationRegistry, runtimeConfigFromSnapshot, buildFallbackChainForSpec, collectSpecKeys, handleMissing, and related call sites. Preference-override-layer construction (buildOverrideLayersFromPreferenceCatalogs, mapPreferenceSourceToOverrideScope, createTranslationRuntimeFromPreferences, createTranslationRuntimeConfigFromPreferences) has no replacement and must be dropped. resolveTranslationPreferenceContext is preserved.

    3 packages · 3 occurrences

  • - The i18next adapter exports ContractSpec ICU messages intact and does not make i18next canonical.

    3 packages · 3 occurrences

  • - Treat portable mutation descriptors as domain-command envelopes and execute them only through provider adapters that enforce policy, idempotency, audit, replay, and expected write-set evidence.

    3 packages · 3 occurrences

  • - Unconstrained CompanyOS graph node/edge type strings are migration targets for ontology node and edge refs.

    3 packages · 3 occurrences

  • - Use @lssm-tech/lib.translation-runtime/precompile at build time to emit FormatJS IR AST alongside each ICU message. createIntlMessageFormatter skips re-parsing when precompiled AST is present. Additive opt-in; no payload size change. Benefit applies to integrations using ICU plural/select messages; factory proof routes use simple {placeholder} interpolation and are unaffected.

    3 packages · 3 occurrences

  • - Use `@lssm-tech/lib.contracts-spec/ontology` as the semantic Company Work Graph source for actor, work, resource, surface, adaptation, and safety nodes/edges.

    3 packages · 3 occurrences

  • - Use `layout.flow.sections` to group existing fields by immediate field name.

    3 packages · 3 occurrences

  • - Use loadShardDelta to fetch only the incremental specKeys needed on navigation, reusing already-loaded shared shards.

    3 packages · 3 occurrences

  • - Use runtime instances or snapshots instead of legacy simple string interpolation for production i18n paths.

    3 packages · 3 occurrences

  • - Use the additive provider-capabilities registry and the new read-first integration packages with secret-ref-only auth and deterministic mocks.

    3 packages · 3 occurrences

  • - Use verified session authority for organization and workspace selection.

    3 packages · 3 occurrences

  • - When database mutation contracts or adapters change, update the README/docs/release capsule pair and regenerate `/llms*` before release.

    3 packages · 3 occurrences

  • - Add a contract-derived authenticated Company Intelligence v1 Elysia boundary with durable tenant-scoped replay and request budgets, canonical PostgreSQL operation bindings, and production-only model service ports.

    2 packages · 2 occurrences

  • - Add a kind:'relationship' section to a DataView detail/management config to render related records.

    2 packages · 2 occurrences

  • - Add the migration-owner-only durable phase receipt table.

    2 packages · 2 occurrences

  • - Add the report-only missing_translation static diagnostic to contracts-spec and an optional locale-override argument to the design-system useI18n hook for the en/fr/es readiness program.

    2 packages · 2 occurrences

  • - Add ThemeSpec light/dark modes and a design-system Tailwind bridge for CSS variables, presets, CSS text, and OKLCH color pass-through.

    2 packages · 2 occurrences

  • - Apply additive migration 0027 before enabling the authenticated API in production.

    2 packages · 2 occurrences

  • - Configure row/card icons, status, and label visibility from DataViewManagement row-card metadata.

    2 packages · 2 occurrences

  • - Declare relationships on a DataView detail config and render related records inside EntityDetailPanel (web + native), reusing the per-field formatting/intelligent-action machinery.

    2 packages · 2 occurrences

  • - Form-like marketing/BillingOS UI renders through ContractSpec FormSpec/OperationSpec bindings as the primary path; bespoke design-system form/pricing control APIs are removed.

    2 packages · 2 occurrences

  • - Improve EntityWorkspace row/card rendering with configurable leading icons, top-right status fields, and per-field label visibility overrides, then adopt the shared contract in the Agent Fleet example.

    2 packages · 2 occurrences

  • - Make the three-organization bootstrap resumable with durable phase receipts and truthful cross-connection interruption semantics.

    2 packages · 2 occurrences

  • - MarketingLeadCapture and MarketingPricingCalculator now render form-like UI through the design-system FormSpec renderer as the primary path. Bespoke control/pricing prop APIs are removed; the design system no longer owns business pricing, submission, or provider execution.

    2 packages · 2 occurrences

  • - Move marketing form-like UI onto FormSpec/OperationSpec bindings and host-owned execution.

    2 packages · 2 occurrences

  • - Resolve ThemeSpec tokens for the active mode and feed them to the Tailwind preset or CSS serializer.

    2 packages · 2 occurrences

  • - Run analyzeTranslationCatalogGroup(s) and inspect missing_translation info issues; pass a missingTranslationAllowlist for English-by-design terms and cognates.

    2 packages · 2 occurrences

  • - Run the opt-in Postgres test before production cutover.

    2 packages · 2 occurrences

  • - Supply canonical tenant-scoped PostgreSQL repositories plus production-only extraction and grounded-answer service ports without enabling fixture fallback.

    2 packages · 2 occurrences

  • - The shared DataViewList(.native) now accepts an optional fieldActions prop (default off).

    2 packages · 2 occurrences

  • - Add entities module to contracts-spec — EdgeSpec, defineContractEdge, defineContractEntity (Layer 1+2), EntityRegistry.

    1 packages · 1 occurrences

  • - Add evidence-backed OutcomeClaim contracts, validators, and public exports to contracts-spec.

    1 packages · 1 occurrences

  • - Add explicit v2 design-partner readiness, expert attestation, and founder approval contracts with server-derived authority, scoped durable receipts, pending evidence projection, replay linkage, and fail-closed health while preserving v1 unchanged. The release supports a private production-scoped pilot but does not activate a tenant or authorize broader production surfaces.

    1 packages · 1 occurrences

  • - Add navigation surface contract with role-aware registry and graph model.

    1 packages · 1 occurrences

  • - Add optional DataView management-shell metadata for adaptive command-center layouts.

    1 packages · 1 occurrences

  • - Add optional mobile-extension fields to NavSurfaceItemSpec for Expo Router native navigation.

    1 packages · 1 occurrences

  • - Add the ReviewReady app-submission-readiness contract and event surface to contracts-spec.

    1 packages · 1 occurrences

  • - Add two additive Managed CompanyOS Special Ops operation contracts — specialOps.reviewCard.decide and specialOps.weeklyReport.approve — on the canonical production contracts surface to retroactively govern the already-shipped decideReviewCard and publishWeeklyReport handlers in api-application-monolith. The example special-ops-cockpit package stays a pure fixture demo.

    1 packages · 1 occurrences

  • - Adopt the versioned v2 registry while preserving the unchanged v1 key-only registry for existing consumers.

    1 packages · 1 occurrences

  • - Aliases are opt-in. Add them only when you're renaming an operation's canonical key and want consumers to keep working without code changes.

    1 packages · 1 occurrences

  • - Bind handlers for the 13 new mutation contracts in the integrations registry. Apply `RoleMorphProjection` capability check server-side; emit the corresponding privacy-signals event on success.

    1 packages · 1 occurrences

  • - Bind v2 handlers to verified session membership, durable idempotency receipts, immutable replay/evidence projection, and fail-closed health.

    1 packages · 1 occurrences

  • - BREAKING: M2 contracts-spec — V1 workflow dual-shape adapter removed; DataViewGraphSpec, rich-reference, shared-entities, AgentTask V2 added.

    1 packages · 1 occurrences

  • - Confirm the entity-bound guidance subpath resolves and the generated DocBlock route is present.

    1 packages · 1 occurrences

  • - defineReferenceKind creates a typed, schema-validated kind descriptor for external object references. Use it in any lib or module that needs to link to external business objects.

    1 packages · 1 occurrences

  • - Derive every authority and evidence reference from the verified server session and transaction.

    1 packages · 1 occurrences

  • - Document entity-bound FormSpec projections, permissive intake debt, and the public guidance export.

    1 packages · 1 occurrences

  • - EntityRegistry enables the 'entity-declarative' DataViewGraphSource variant. Register entities before rendering entity-declarative graph views.

    1 packages · 1 occurrences

  • - Extend NavSurface with optional mobileRoute field and MobileRouteSchema discriminated union to express mobile navigation shape in the same contract that drives web navigation.

    1 packages · 1 occurrences

  • - grep for layout string assignments and replace with LayoutSpec objects.

    1 packages · 1 occurrences

  • - id: graph-layout-kind-string-enum; name: GraphLayoutKind string enum; reason: Replaced by LayoutSpec discriminated union for richer per-layout configuration; migration: Use layoutKindToSpec(kind) shim or construct LayoutSpec objects directly

    1 packages · 1 occurrences

  • - Import the new contracts, registries, and constants additively; existing app-submission-readiness fixtures/runtime/types subpaths are unchanged.

    1 packages · 1 occurrences

  • - Lane handlers should resolve the two new operations through companyOsOperationRegistry rather than reaching into individual files.

    1 packages · 1 occurrences

  • - Loop D D4 — `@lssm-tech/lib.contracts-spec` now supports `meta.aliases?: readonly string[]` on operations. `OperationSpecRegistry.get()` falls back to alias lookup when the canonical key misses. Future namespace migrations can ship as additive instead of BREAKING.

    1 packages · 1 occurrences

  • - M3 — LayoutSpec discriminated union replaces GraphLayoutKind string enum; additive graph subscription, export, annotation, story-mode, and AI operation contracts.

    1 packages · 1 occurrences

  • - New sibling type to DataViewSpec for graph views. Supported by graph canvas renderers. Choose the source variant that matches your data-fetching strategy.

    1 packages · 1 occurrences

  • - Remove avoidable Node crypto imports from ContractSpec runtime surfaces and keep signing helpers isolated.

    1 packages · 1 occurrences

  • - Replace broad root or `control-plane` imports for signing and verification helpers with `@lssm-tech/lib.contracts-spec/control-plane/skills`, `/signer`, or `/verifier`.

    1 packages · 1 occurrences

  • - Replace local navigation item interfaces with NavSurfaceItemSpec, register with NavRegistry, and bind to capabilities.

    1 packages · 1 occurrences

  • - Ship integrations Wave A reads + Wave B mutations (21 contracts) with full operation-contract metadata bar.

    1 packages · 1 occurrences

  • - Sticky experiment variants may rebucket because the evaluator now uses a browser-safe deterministic hash instead of Node SHA-256.

    1 packages · 1 occurrences

  • - The V1 `id` field on WorkflowTask has been removed. All consumers must switch to `taskId`.

    1 packages · 1 occurrences

  • - The V1 flat WorkflowTask shape (single-level task list without explicit edges) is no longer supported. All workflow specs must declare `tasks: WorkflowTask[]` and `edges: WorkflowEdge[]`.

    1 packages · 1 occurrences

  • - Treat implementation readiness as separate from approval to activate the first tenant.

    1 packages · 1 occurrences

  • - Update every site that assigns a string to the layout field of DataViewGraphConfig or GraphCanvasProps.

    1 packages · 1 occurrences

  • - Use entities for canonical identity, forms for renderable projections, and completion debt for skipped intake fields.

    1 packages · 1 occurrences

  • - Use optional DataView management-shell fields to document adaptive command-center layouts without changing existing DataView contracts.

    1 packages · 1 occurrences

  • - Use the new optional fields when defining NavSurfaceItemSpec entries that will be consumed by a native Expo Router shell.

    1 packages · 1 occurrences

  • - V1 workflow runner dual-shape adapter — removed; migrate to DAG shape (tasks[] + edges[]).

    1 packages · 1 occurrences

  • - Wire mutation handlers through the contracts-spec registry. The four `breaking-allowed-this-plan` contracts will graduate to `stable` only after Phase 4 of the integration-hub-uplift plan; treat their schema as frozen-as-spec but not frozen-as-policy.

    1 packages · 1 occurrences

  • - WorkflowTask.id (V1) — removed; use WorkflowTask.taskId.

    1 packages · 1 occurrences

Impacted packages

  • @lssm-tech/app.api-application-monolith

    Layer: apps · 4 changes

  • @lssm-tech/app.cli-contractspec

    Layer: apps · 5 changes

  • @lssm-tech/app.cursor-marketplace

    Layer: apps · 5 changes

  • @lssm-tech/app.web-application-monolith

    Layer: apps · 2 changes

  • @lssm-tech/app.web-landing

    Layer: apps · 5 changes

  • @lssm-tech/app.worker-application-monolith

    Layer: apps · 2 changes

  • @lssm-tech/bundle.library

    Layer: bundles · 5 changes

  • @lssm-tech/bundle.managed-companyos

    Layer: bundles · 3 changes

  • @lssm-tech/bundle.marketing

    Layer: bundles · 7 changes

  • @lssm-tech/bundle.workspace

    Layer: bundles · 5 changes

  • @lssm-tech/integration.agent-durable-store

    Layer: integrations · 2 changes

  • @lssm-tech/integration.agent-sandbox

    Layer: integrations · 2 changes

  • @lssm-tech/integration.app-store-connect

    Layer: integrations · 2 changes

  • @lssm-tech/integration.builder-telegram

    Layer: integrations · 2 changes

  • @lssm-tech/integration.builder-voice

    Layer: integrations · 2 changes

  • @lssm-tech/integration.builder-whatsapp

    Layer: integrations · 2 changes

  • @lssm-tech/integration.crdt-loro

    Layer: integrations · 7 changes

  • @lssm-tech/integration.eve

    Layer: integrations · 2 changes

  • @lssm-tech/integration.google-play-developer

    Layer: integrations · 2 changes

  • @lssm-tech/integration.harness-runtime

    Layer: integrations · 3 changes

  • @lssm-tech/integration.provider-claude-code

    Layer: integrations · 2 changes

  • @lssm-tech/integration.provider-codex

    Layer: integrations · 2 changes

  • @lssm-tech/integration.provider-copilot

    Layer: integrations · 2 changes

  • @lssm-tech/integration.provider-database

    Layer: integrations · 4 changes

  • @lssm-tech/integration.provider-gemini

    Layer: integrations · 2 changes

  • @lssm-tech/integration.provider-github

    Layer: integrations · 2 changes

  • @lssm-tech/integration.provider-local-model

    Layer: integrations · 2 changes

  • @lssm-tech/integration.provider-meeting-recorder

    Layer: integrations · 3 changes

  • @lssm-tech/integration.provider-pioneer-ai

    Layer: integrations · 3 changes

  • @lssm-tech/integration.provider-stt

    Layer: integrations · 2 changes

  • @lssm-tech/integration.provider-voice

    Layer: integrations · 3 changes

  • @lssm-tech/integration.providers-impls

    Layer: integrations · 5 changes

  • @lssm-tech/integration.runtime

    Layer: integrations · 3 changes

  • @lssm-tech/integration.runtime-hybrid

    Layer: integrations · 2 changes

  • @lssm-tech/integration.runtime-local

    Layer: integrations · 7 changes

  • @lssm-tech/integration.runtime-managed

    Layer: integrations · 5 changes

  • @lssm-tech/integration.workflow-devkit

    Layer: integrations · 2 changes

  • @lssm-tech/lib.agent-collaboration

    Layer: libs · 2 changes

  • @lssm-tech/lib.agent-evals

    Layer: libs · 2 changes

  • @lssm-tech/lib.agent-runtime-conformance

    Layer: libs · 2 changes

  • @lssm-tech/lib.ai-agent

    Layer: libs · 3 changes

  • @lssm-tech/lib.ai-providers

    Layer: libs · 3 changes

  • @lssm-tech/lib.authos-runtime

    Layer: libs · 3 changes

  • @lssm-tech/lib.builder-runtime

    Layer: libs · 3 changes

  • @lssm-tech/lib.builder-spec

    Layer: libs · 2 changes

  • @lssm-tech/lib.bus

    Layer: libs · 3 changes

  • @lssm-tech/lib.communication-runtime

    Layer: libs · 4 changes

  • @lssm-tech/lib.communication-spec

    Layer: libs · 4 changes

  • @lssm-tech/lib.companyos-runtime

    Layer: libs · 3 changes

  • @lssm-tech/lib.contracts-integrations

    Layer: libs · 3 changes

  • @lssm-tech/lib.contracts-runtime-client-react

    Layer: libs · 4 changes

  • @lssm-tech/lib.contracts-runtime-core

    Layer: libs · 5 changes

  • @lssm-tech/lib.contracts-runtime-server-graphql

    Layer: libs · 5 changes

  • @lssm-tech/lib.contracts-runtime-server-mcp

    Layer: libs · 5 changes

  • @lssm-tech/lib.contracts-runtime-server-rest

    Layer: libs · 5 changes

  • @lssm-tech/lib.contracts-spec

    Layer: libs · 5 changes

  • @lssm-tech/lib.crypto-utils

    Layer: libs · 3 changes

  • @lssm-tech/lib.data-exchange-core

    Layer: libs · 2 changes

  • @lssm-tech/lib.data-exchange-server

    Layer: libs · 2 changes

  • @lssm-tech/lib.design-system

    Layer: libs · 4 changes

  • @lssm-tech/lib.error

    Layer: libs · 5 changes

  • @lssm-tech/lib.evolution

    Layer: libs · 3 changes

  • @lssm-tech/lib.execution-lanes

    Layer: libs · 3 changes

  • @lssm-tech/lib.files

    Layer: libs · 3 changes

  • @lssm-tech/lib.harness

    Layer: libs · 3 changes

  • @lssm-tech/lib.identity-rbac

    Layer: libs · 3 changes

  • @lssm-tech/lib.jobs

    Layer: libs · 5 changes

  • @lssm-tech/lib.knowledge

    Layer: libs · 2 changes

  • @lssm-tech/lib.lifecycle

    Layer: libs · 3 changes

  • @lssm-tech/lib.logger

    Layer: libs · 3 changes

  • @lssm-tech/lib.metering

    Layer: libs · 3 changes

  • @lssm-tech/lib.mobile-control

    Layer: libs · 2 changes

  • @lssm-tech/lib.notification

    Layer: libs · 5 changes

  • @lssm-tech/lib.observability

    Layer: libs · 3 changes

  • @lssm-tech/lib.organization-planning-spec

    Layer: libs · 4 changes

  • @lssm-tech/lib.overlay-engine

    Layer: libs · 3 changes

  • @lssm-tech/lib.personalization

    Layer: libs · 3 changes

  • @lssm-tech/lib.presentation-runtime-core

    Layer: libs · 2 changes

  • @lssm-tech/lib.presentation-runtime-next

    Layer: libs · 5 changes

  • @lssm-tech/lib.presentation-runtime-react

    Layer: libs · 5 changes

  • @lssm-tech/lib.presentation-runtime-react-native

    Layer: libs · 5 changes

  • @lssm-tech/lib.provider-runtime

    Layer: libs · 3 changes

  • @lssm-tech/lib.provider-spec

    Layer: libs · 3 changes

  • @lssm-tech/lib.runtime-sandbox

    Layer: libs · 3 changes

  • @lssm-tech/lib.schema

    Layer: libs · 3 changes

  • @lssm-tech/lib.surface-runtime

    Layer: libs · 3 changes

  • @lssm-tech/lib.testing

    Layer: libs · 3 changes

  • @lssm-tech/lib.translation-runtime

    Layer: libs · 10 changes

  • @lssm-tech/lib.ui-kit

    Layer: libs · 2 changes

  • @lssm-tech/lib.ui-kit-core

    Layer: libs · 1 changes

  • @lssm-tech/lib.ui-kit-web

    Layer: libs · 2 changes

  • @lssm-tech/lib.voice

    Layer: libs · 3 changes

  • @lssm-tech/module.alpic

    Layer: modules · 3 changes

  • @lssm-tech/module.builder-workbench

    Layer: modules · 2 changes

  • @lssm-tech/module.communication-os

    Layer: modules · 4 changes

  • @lssm-tech/module.governance-suite

    Layer: modules · 3 changes

  • @lssm-tech/module.mobile-review

    Layer: modules · 2 changes

  • @lssm-tech/module.notifications

    Layer: modules · 5 changes

  • @lssm-tech/module.workspace

    Layer: modules · 3 changes