Skip to content
Open
Show file tree
Hide file tree
Changes from all commits
Commits
Show all changes
454 commits
Select commit Hold shift + click to select a range
706d737
chore: extract locale catalogs [skip ci]
emdashbot[bot] Aug 24, 2026
37c5010
fix(client): retry requests with a body after a token refresh (#2556)
cherenkov Aug 24, 2026
52f7c91
fix(admin): pass pluginBlocks to SectionEditor PortableTextEditor (#2…
emdashbot[bot] Aug 25, 2026
12910f0
chore: extract locale catalogs [skip ci]
emdashbot[bot] Aug 25, 2026
1c6b893
fix(admin): preserve table cell line breaks (#2628)
scottbuscemi Aug 25, 2026
628630a
fix(core): restore content bylines table left staged by an interrupte…
danielmlr Aug 25, 2026
0f225eb
fix(auth): preserve CMS user identity on comment submissions (#2598)
Glacier-Luo Aug 25, 2026
464f41b
chore: extract locale catalogs [skip ci]
emdashbot[bot] Aug 25, 2026
72664ad
fix(admin): stabilize editor sidebar layout (#2468)
khoinguyenpham04 Aug 25, 2026
2b54096
fix(admin): make image actions reliably selectable (#2490)
khoinguyenpham04 Aug 25, 2026
76dd3eb
fix(admin): replace persistent locale warning with compact help (#2632)
khoinguyenpham04 Aug 25, 2026
2ffda17
i18n(ja): complete Japanese translations (#2610)
MatsudaTsunenori Aug 25, 2026
7dc6e30
chore: extract locale catalogs [skip ci]
emdashbot[bot] Aug 25, 2026
2fde0f9
fix(core): keep Playground welcome dismissed across reloads (#2600)
khoinguyenpham04 Aug 25, 2026
f7ee61d
Document media upload flows (#2633)
khoinguyenpham04 Aug 25, 2026
11f9404
chore: extract locale catalogs [skip ci]
emdashbot[bot] Aug 25, 2026
6178888
feat(registry): add listing moderation contracts (#2644)
ascorbic Aug 26, 2026
15154ab
feat(registry): add metadata-only listing labeler (#2645)
ascorbic Aug 26, 2026
73c4640
feat(registry): enforce signed listing labels in aggregator (#2646)
ascorbic Aug 26, 2026
e3ad082
feat(registry): hide unapproved listings in EmDash (#2647)
ascorbic Aug 26, 2026
47b397f
chore: extract locale catalogs [skip ci]
emdashbot[bot] Aug 26, 2026
724241f
feat(admin): make editor settings panel resizable (#2590)
khoinguyenpham04 Aug 26, 2026
5c7995f
chore: extract locale catalogs [skip ci]
emdashbot[bot] Aug 26, 2026
3e90689
fix(media): restore AVIF to the default upload allowlist (#2683)
hossein-webdev Aug 27, 2026
f3a585d
chore: extract locale catalogs [skip ci]
emdashbot[bot] Aug 27, 2026
453fc50
fix(labeler): harden Worker runtime and moderation evaluation (#2681)
ascorbic Aug 27, 2026
8d8d3de
feat(media): add numbered library pagination (#2582)
khoinguyenpham04 Aug 27, 2026
a1ddcfb
feat(media): add flat folder API foundation (#2584)
khoinguyenpham04 Aug 27, 2026
815553c
feat(media): add flat folder UI (#2586)
khoinguyenpham04 Aug 27, 2026
436f63d
feat(media): add image focal points (#2624)
khoinguyenpham04 Aug 27, 2026
968e72a
chore: extract locale catalogs [skip ci]
emdashbot[bot] Aug 27, 2026
42fa5d8
fix(admin): keep localized guidance in complete units (#2686)
MatsudaTsunenori Aug 27, 2026
05b0a8b
fix(admin): refresh sidebar after taxonomy creation (#2687)
MatsudaTsunenori Aug 27, 2026
7571581
fix(admin): align byline field switches (#2676)
MatsudaTsunenori Aug 27, 2026
6f005f4
chore: extract locale catalogs [skip ci]
emdashbot[bot] Aug 27, 2026
dffb2b3
feat(labeler): add Access-protected operator console (#2700)
ascorbic Aug 27, 2026
e2e2d08
chore: extract locale catalogs [skip ci]
emdashbot[bot] Aug 27, 2026
b4c73ac
feat(ui): scope LiveSearch results to the page locale (#2480)
DavidPivert Aug 27, 2026
f00174b
fix(core): replace better-sqlite3 with node:sqlite in the sqlite adap…
gruntlord5 Aug 27, 2026
f6da16b
fix(core): add controlled media usage activation (#2445)
khoinguyenpham04 Aug 27, 2026
f527127
fix(admin): show where local media is used (#2470)
khoinguyenpham04 Aug 27, 2026
abd1042
fix(core): prepare seeded media usage (#2472)
khoinguyenpham04 Aug 27, 2026
9c52b39
feat: complete media usage tracking setup (#2538)
khoinguyenpham04 Aug 27, 2026
3b81e1d
chore: extract locale catalogs [skip ci]
emdashbot[bot] Aug 27, 2026
6c912b5
fix(labeler): preserve admin path when serving SPA (#2740)
ascorbic Aug 27, 2026
22c4422
fix(editor): highlight code blocks in editors (#2606)
khoinguyenpham04 Aug 27, 2026
f5e18d8
fix(editor): polish code block controls (#2603)
khoinguyenpham04 Aug 27, 2026
089d747
feat(editor): add Lua and Zig language suggestions (#2622)
khoinguyenpham04 Aug 27, 2026
52e8487
chore: extract locale catalogs [skip ci]
emdashbot[bot] Aug 27, 2026
f9a488a
Refine admin table filters (#2561)
khoinguyenpham04 Aug 27, 2026
37f717a
chore: extract locale catalogs [skip ci]
emdashbot[bot] Aug 27, 2026
ecbf67c
test(e2e): stabilize shared media and setup CI (#2762)
khoinguyenpham04 Aug 28, 2026
e24d880
test(e2e): declare UTF-8 for fixture post pages (#2763)
MatsudaTsunenori Aug 28, 2026
688257f
test(e2e): stabilize date range visual snapshot (#2764)
MatsudaTsunenori Aug 28, 2026
70c487c
Fix content editor byline workflow (#2754)
khoinguyenpham04 Aug 28, 2026
1717d31
chore: extract locale catalogs [skip ci]
emdashbot[bot] Aug 28, 2026
291888a
fix(core): pre-bundle Astro manifest in Cloudflare dev (#2808)
khoinguyenpham04 Sep 1, 2026
3367fae
i18n(ja): improve admin translations (#2778)
MatsudaTsunenori Sep 1, 2026
c3c49dd
Fix plugin timestamp timezone skew (#2816)
scottbuscemi Sep 1, 2026
619bb56
fix(api): export handleSchemaCollectionReorder from the handlers barr…
markoinla Sep 1, 2026
561f1d1
fix(admin): stop autosave from retrying a payload the server rejected…
danielmlr Sep 1, 2026
9460943
chore: extract locale catalogs [skip ci]
emdashbot[bot] Sep 1, 2026
1c9fb43
fix(core): let content:beforeSave hooks reject a save with an editor-…
danielmlr Sep 1, 2026
d379d10
feat(core): add dark mode variants to image fields (#2609)
danielmlr Sep 1, 2026
0258266
chore: extract locale catalogs [skip ci]
emdashbot[bot] Sep 1, 2026
43865c1
Stabilize dates in visual regression snapshots (#2825)
ascorbic Sep 1, 2026
fdaff76
fix: animated stepper in playground setup (#2759)
nocdn Sep 1, 2026
bfdaccd
fix: show seeded media in the Playground library (#2802)
khoinguyenpham04 Sep 1, 2026
9d92b55
feat(registry): host release artifacts as publisher blobs (#2765)
ascorbic Sep 1, 2026
4e4c85e
chore: extract locale catalogs [skip ci]
emdashbot[bot] Sep 1, 2026
e6656f0
test(e2e): stop clipping visual timestamps (#2826)
ascorbic Sep 1, 2026
2adef40
ci: release (#2625)
emdashbot[bot] Sep 1, 2026
5634003
docs: add an update guide for existing sites (#2803)
danielmlr Sep 1, 2026
dd325cb
ci: shard core tests (#2832)
ascorbic Sep 1, 2026
8fb13cf
Improve the media details panel in Media Library (#2761)
khoinguyenpham04 Sep 1, 2026
965bf33
Fix media source identity across editor workflows (#2830)
khoinguyenpham04 Sep 1, 2026
755cdbb
chore: extract locale catalogs [skip ci]
emdashbot[bot] Sep 1, 2026
d99a0e8
feat(release-service): add delegated release foundations (#2743)
ascorbic Sep 2, 2026
e40df51
feat(release-service): add publisher authority and admission (#2744)
ascorbic Sep 2, 2026
b8873c7
feat(release-service): add passkey approvals (#2745)
ascorbic Sep 2, 2026
c7b6fdf
feat(registry): verify delegated releases independently (#2746)
ascorbic Sep 2, 2026
3b124f2
feat(release-service): add publication product flow (#2747)
ascorbic Sep 2, 2026
f7e7a50
feat(release-service): add operations and recovery (#2748)
ascorbic Sep 2, 2026
920e1f3
feat(release-service): complete delegated publishing (#2749)
ascorbic Sep 2, 2026
045e742
chore: extract locale catalogs [skip ci]
emdashbot[bot] Sep 2, 2026
8b8a666
fix(release-service): revoke stale workload intents (#2845)
ascorbic Sep 2, 2026
e0e60ba
fix(release-service): require workflow connection invitations (#2848)
ascorbic Sep 2, 2026
1c30a24
fix(release-service): bind publication to current PDS (#2846)
ascorbic Sep 2, 2026
3c8ba9b
fix(release-service): coordinate package publication (#2850)
ascorbic Sep 2, 2026
0c9109f
docs: require screenshots for interface changes (#2851)
ascorbic Sep 2, 2026
78331c7
docs: add a plugin sandbox operations guide for Cloudflare and Node.j…
danielmlr Sep 2, 2026
8657dea
docs: document rendering SEO panel data via getSeoMeta (#1518) (#1900)
swissky Sep 2, 2026
43b200d
test(e2e): stabilize playground smoke (#2834)
ascorbic Sep 2, 2026
529b28b
fix: bind Sigstore provenance to admitted workload (#2847)
ascorbic Sep 2, 2026
52fffdc
fix: proof-verify delegated release authority (#2849)
ascorbic Sep 2, 2026
cd294dc
fix(core): enforce revision checks for content lifecycle mutations (#…
yumam0815 Sep 2, 2026
7887577
fix(admin): echo _rev on editor save to prevent silent draft overwrit…
swissky Sep 2, 2026
68fc4fa
chore: extract locale catalogs [skip ci]
emdashbot[bot] Sep 2, 2026
37553c3
test: scaffold agent-driven UX acceptance (#2854)
ascorbic Sep 2, 2026
c5e0fae
test: define core UX acceptance journeys (#2855)
ascorbic Sep 2, 2026
bb8b087
fix(core): let sandboxed beforeSave hooks reject saves (#2858)
ascorbic Sep 2, 2026
9daf50a
chore: extract locale catalogs [skip ci]
emdashbot[bot] Sep 2, 2026
afa81c5
fix(admin): save editor state before publishing (#2860)
ascorbic Sep 2, 2026
5cb3f73
chore: extract locale catalogs [skip ci]
emdashbot[bot] Sep 2, 2026
450057e
test(release-service): isolate encryption verification sweep (#2868)
ascorbic Sep 2, 2026
5f9eb67
fix(admin): fill active sidebar icons (#2865)
khoinguyenpham04 Sep 3, 2026
64f1e68
chore: extract locale catalogs [skip ci]
emdashbot[bot] Sep 3, 2026
7a5d9c1
fix(core): join avatar media on the single-row byline finders (#2885)
MA2153 Sep 3, 2026
bbdcef4
chore(admin): update deprecated vitest imports (#2859)
camc314 Sep 3, 2026
30d4076
fix(core): index scheduled sweep on (deleted_at, scheduled_at) (#2890)
MA2153 Sep 3, 2026
2970377
docs: document the single-taxonomy endpoints (#2884)
MA2153 Sep 3, 2026
de122b4
fix(core): preserve publish date when unpublishing (#2886)
ascorbic Sep 3, 2026
1e64516
test(core): add isolated consumer install smoke (#2863)
ascorbic Sep 3, 2026
8b094fc
fix(release-service): harden public release routes (#2869)
ascorbic Sep 3, 2026
66aeecd
Fix delegated release setup for missing package profiles (#2892)
ascorbic Sep 3, 2026
b06fc63
fix(core): keep the media-usage cleanup scan bounded when the lease i…
MA2153 Sep 3, 2026
05d5596
Add media image cropping (#2861)
khoinguyenpham04 Sep 3, 2026
264940d
chore: extract locale catalogs [skip ci]
emdashbot[bot] Sep 3, 2026
595a6b1
Add in-place media image replacement (#2899)
khoinguyenpham04 Sep 4, 2026
a213afa
chore: extract locale catalogs [skip ci]
emdashbot[bot] Sep 4, 2026
9def325
Improve admin media picker workflows (#2900)
khoinguyenpham04 Sep 4, 2026
108c753
chore: extract locale catalogs [skip ci]
emdashbot[bot] Sep 4, 2026
67f676d
fix: pre-bundle lowlight and highlight.js for inline Portable Text ed…
emdashbot[bot] Sep 6, 2026
6030629
Handle maintainer reviews on bot pull requests (#2924)
ascorbic Sep 6, 2026
98ef920
fix(admin): refine publishing and scheduling controls (#2891)
khoinguyenpham04 Sep 6, 2026
4c873c2
chore: extract locale catalogs [skip ci]
emdashbot[bot] Sep 6, 2026
c841796
fix(create-emdash): make --install failures actionable (#2627)
scottbuscemi Sep 7, 2026
de8b03a
Add in-context media asset editing (#2905)
khoinguyenpham04 Sep 7, 2026
8c41479
chore: extract locale catalogs [skip ci]
emdashbot[bot] Sep 7, 2026
6676283
Fix editor image settings layout and sizing (#2931)
khoinguyenpham04 Sep 7, 2026
abb6626
chore: extract locale catalogs [skip ci]
emdashbot[bot] Sep 7, 2026
ab26518
fix(ui): restore playground stepper animation timings (#2932)
nocdn Sep 7, 2026
6da29d3
fix(core): require the revision token on MCP content writes (#2912)
danielmlr Sep 7, 2026
87c7884
fix(admin): let the editor recover from a save conflict instead of re…
danielmlr Sep 7, 2026
44cca5c
chore: extract locale catalogs [skip ci]
emdashbot[bot] Sep 7, 2026
013156d
fix(admin): scope Trash tab to the active locale (#2807)
LeanderG Sep 7, 2026
60691df
Fix boolean field runtime values in Astro loader (#2822)
jcheese1 Sep 7, 2026
a5402e1
chore: extract locale catalogs [skip ci]
emdashbot[bot] Sep 7, 2026
3b106f6
fix: use releases.emdashcms.com for automated releases (#2894)
ascorbic Sep 7, 2026
926dd0a
fix(ci): skip CLA checks in forks (#2904)
MatsudaTsunenori Sep 7, 2026
47a4fca
test(core): run core migrations and queries against real D1 (#2879)
danielmlr Sep 7, 2026
37e08b0
fix(core): let migration 017 finish after an interrupted run (#2875)
danielmlr Sep 7, 2026
01855cb
fix(plugin-storage): seek on the sort key when paginating with orderB…
hossein-webdev Sep 7, 2026
d8910d7
fix(core): add includeCounts opt-out to getTerm (#2812)
iNerdStack Sep 7, 2026
ad19827
fix: group Archives widget posts when publishedAt is a Date (#2876)
ismail-rt Sep 7, 2026
df70663
fix(bot): allow Git large-push probes (#2938)
ascorbic Sep 7, 2026
77404a3
ci: exclude generated release action bundle from CodeQL (#2940)
ascorbic Sep 7, 2026
b6271ad
test(core): correct D1 wide-loader boundary (#2941)
ascorbic Sep 7, 2026
d340c07
test(admin): wait for editor content in conflict test (#2942)
ascorbic Sep 7, 2026
062e8be
Regenerate emdash-env.d.ts immediately when schema changes in dev (#2…
emdashbot[bot] Sep 7, 2026
f622a17
Fix audit-log hooks skipped for missing capabilities and pass item id…
ascorbic Sep 7, 2026
06499ad
fix(core): handle Postgres pool failures (#2935)
ascorbic Sep 7, 2026
556c9fe
feat(mcp): add taxonomy definition CRUD tools and fix translationOf i…
emdashbot[bot] Sep 7, 2026
4cc3817
fix(core): prevent backend initialization hangs (#2626) (#2937)
ascorbic Sep 7, 2026
c81e5e7
fix(editor): preserve payload-less Portable Text blocks (#2939)
ascorbic Sep 8, 2026
65243c4
test(admin): stabilize media detail panel browser tests (#2946)
khoinguyenpham04 Sep 8, 2026
370ff8b
chore: extract locale catalogs [skip ci]
emdashbot[bot] Sep 8, 2026
980538d
fix(core): normalize scheduledAt to UTC in content.schedule() (#2913)
htdtkshi Sep 8, 2026
096cd91
i18n(de): complete the remaining German admin translations (#2922)
danielmlr Sep 8, 2026
9ccc2e7
fix(core/schema): persist titleField/dateField on PUT /schema/collect…
emdashbot[bot] Sep 8, 2026
188d7e7
fix: Preserve locale prefixes in generated canonical URLs (#2608)
mvanhorn Sep 8, 2026
c4286bc
fix(cloudflare): preserve D1 HTTP 400 query errors (#2756)
yumam0815 Sep 8, 2026
76946e4
fix: include locale in admin published links (#2895)
ismail-rt Sep 8, 2026
360731b
chore: extract locale catalogs [skip ci]
emdashbot[bot] Sep 8, 2026
6dd5781
fix(plugin-cli): compare the schema, not the checkout's line endings …
jmirchandani Sep 8, 2026
6a08005
feat(bot): redesign issue triage and PR delivery (#2949)
ascorbic Sep 8, 2026
4c9bd53
fix(flue-review): exclude generated Worker types (#2950)
ascorbic Sep 8, 2026
ecdba4d
chore(deps): update zod, remove use of deprecated APIs (#2864)
camc314 Sep 8, 2026
d314256
fix(bot): harden sandbox Git authentication and RPC replay (#2953)
ascorbic Sep 8, 2026
8a06cd6
fix: include runtime manual collections in admin manifest so their co…
mvanhorn Sep 8, 2026
d418b64
fix(core/cache): resolve lint warnings on chrome cache invalidation r…
emdashbot[bot] Sep 8, 2026
b2da4f2
Keep Media Library pagination pinned to the bottom (#2952)
khoinguyenpham04 Sep 8, 2026
3b6a1b2
chore: extract locale catalogs [skip ci]
emdashbot[bot] Sep 8, 2026
07af2a0
fix(bot): stop repeated repairs and preserve rejection feedback (#2955)
ascorbic Sep 9, 2026
8efac35
fix(admin): reduce excessive spacing around editor images (#2961)
khoinguyenpham04 Sep 9, 2026
85f8b5a
fix(admin): improve paragraph and placeholder spacing (#2963)
khoinguyenpham04 Sep 9, 2026
9a66ff0
feat(admin): drop images into Featured and OG image fields (#2969)
khoinguyenpham04 Sep 9, 2026
755853b
chore: extract locale catalogs [skip ci]
emdashbot[bot] Sep 9, 2026
d267a2c
fix(admin): save pending editor changes before the publish date write…
danielmlr Sep 9, 2026
d6b99d1
chore: extract locale catalogs [skip ci]
emdashbot[bot] Sep 9, 2026
fa5dc29
fix(bot): recover workspace base after retries (#2974)
ascorbic Sep 9, 2026
b44bc2c
fix(openapi): align content terms docs with shipped nested route (#2925)
emdashbot[bot] Sep 9, 2026
ebd13f8
fix(core): bound the media-usage cleanup scan with a row-value cursor…
MA2153 Sep 9, 2026
b2212ba
ci: exclude generated changelogs from format checks (#2976)
ascorbic Sep 9, 2026
fc87efe
ci: release (#2833)
emdashbot[bot] Sep 9, 2026
4cc150e
feat(labeler): redesign operator review workflow (#2742)
ascorbic Sep 9, 2026
3376ae1
fix(registry): restore signed label projection (#2985)
ascorbic Sep 9, 2026
88dc782
Fix labeler review queue duplicates (#2984)
ascorbic Sep 9, 2026
5fb3fab
feat(labeler): enable automatic listing moderation (#2992)
ascorbic Sep 9, 2026
d31d5de
fix(bot): retry publisher clones on fresh sandboxes (#2981)
ascorbic Sep 9, 2026
5f51e55
Improve passkey onboarding across account creation (#2979)
ascorbic Sep 9, 2026
f9ac286
Keep the edit proxy on collection reads in edit mode (#2970)
jakevis Sep 9, 2026
c531f30
fix(plugins): say why sandboxed calls fail after workerd stops restar…
danielmlr Sep 9, 2026
44114af
chore: extract locale catalogs [skip ci]
emdashbot[bot] Sep 9, 2026
9d5d8ed
i18n(pt-BR): complete Brazilian Portuguese admin catalog (#2971)
marks-zyz Sep 10, 2026
2bc505e
chore: extract locale catalogs [skip ci]
emdashbot[bot] Sep 10, 2026
d409722
fix(taxonomies): never query a declared collection whose ec_* table i…
swissky Sep 10, 2026
16d96e2
docs(core): name the published package in the Cloudflare sandbox runn…
danielmlr Sep 10, 2026
cc52703
test(cloudflare): cover the diagnostics for a missing platform bindin…
danielmlr Sep 10, 2026
b1ccecd
feat(core): lock a content entry while someone is editing it (#2919)
danielmlr Sep 10, 2026
23a6ba2
chore: extract locale catalogs [skip ci]
emdashbot[bot] Sep 10, 2026
d9d30eb
test(core): cover migration retry and upgrades from existing data on …
danielmlr Sep 10, 2026
0bcb1d9
feat(core): WordPress-style date tokens in url_pattern ({year}/{month…
swissky Sep 10, 2026
21ec8bb
chore: extract locale catalogs [skip ci]
emdashbot[bot] Sep 10, 2026
b73a133
feat(core): apply SEO panel values by default in EmDashHead (#1963)
swissky Sep 10, 2026
573230f
fix snapshots on PostgreSQL (#3026)
ascorbic Sep 10, 2026
a042f50
feat(plugins): add predicate-guarded atomic updateIf for plugin storage
vedanshujain Jul 21, 2026
16ae127
[Plugin] updateIf: trap serialization failures, fix all-undefined gua…
vedanshujain Jul 21, 2026
9e23ac4
docs: refresh site composition guides (#3035)
ascorbic Sep 10, 2026
4f3d6ad
docs: remove stale screenshots and streamline contributor guidance (#…
ascorbic Sep 10, 2026
f35c7d4
docs: correct unsafe deployment and recovery guidance (#3029)
ascorbic Sep 10, 2026
c3be7dd
docs: clarify locale auth and integration guides (#3042)
ascorbic Sep 10, 2026
6383623
docs: rewrite native plugin guides (#3044)
ascorbic Sep 10, 2026
2579547
docs: correct migration and theme guides (#3038)
ascorbic Sep 10, 2026
efb7677
docs: refresh core reference inventories (#3048)
ascorbic Sep 10, 2026
aff5de6
docs: reconcile sandboxed plugin authoring guides (#3047)
ascorbic Sep 10, 2026
006d50c
docs: keep API reference inventories aligned with source (#3037)
ascorbic Sep 10, 2026
a9c01a9
docs: improve content authoring journey (#3040)
ascorbic Sep 11, 2026
2d3f896
docs: correct plugin installation and registry guidance (#3036)
ascorbic Sep 11, 2026
9ed42d5
docs: improve deployment and recovery guidance (#3039)
ascorbic Sep 11, 2026
b989bb9
docs: rebuild the EmDash front door (#3045)
ascorbic Sep 11, 2026
d30207d
fix(admin): hide dashboard quick actions for hidden collections (#3060)
swissky Sep 11, 2026
44fc012
chore: extract locale catalogs [skip ci]
emdashbot[bot] Sep 11, 2026
0ae2f26
feat(plugins): say why the sandbox runner is unavailable (#3041)
danielmlr Sep 11, 2026
91a4aef
feat(editor): make Portable Text tables complete and responsive (#2934)
khoinguyenpham04 Sep 11, 2026
92690af
chore: extract locale catalogs [skip ci]
emdashbot[bot] Sep 11, 2026
b25bf0e
[Plugin] updateIf: correct 40P01 attribution, document updateIf, drop…
vedanshujain Sep 11, 2026
36a021c
fix(core): separate revision author from entry owner and pass actor t…
emdashbot[bot] Sep 11, 2026
2b2f69e
fix(runtime): surface binding configuration errors (#3065)
ascorbic Sep 11, 2026
f0af9a1
fix(cloudflare): make sandboxed plugins a paid-plan opt-in (#2351)
MattieTK Sep 11, 2026
4c89130
Validate plugin HTTP destinations before dispatch (#3050)
logelog Sep 11, 2026
3f516f4
feat(admin): collapsible sidebar groups for collections and their tax…
swissky Sep 11, 2026
b750ddf
chore: extract locale catalogs [skip ci]
emdashbot[bot] Sep 11, 2026
76c5a8f
[Plugin] storage: reject a range filter with no defined bound
vedanshujain Sep 11, 2026
a350627
Fix the admin theme toggle (#3072)
ascorbic Sep 11, 2026
6332570
chore: extract locale catalogs [skip ci]
emdashbot[bot] Sep 11, 2026
bf9556f
Merge pull request #9 from vedanshujain/fix/storage-range-filter-guard
vedanshujain Sep 12, 2026
c6e8907
Merge branch 'main' into feat/plugin-storage-updateif
vedanshujain Sep 12, 2026
33cb7f0
fix(core): retain plugin bundles across updates (#3075)
ascorbic Sep 12, 2026
3662161
Merge branch 'main' into feat/plugin-storage-updateif
vedanshujain Sep 12, 2026
dd5ef1a
fix(admin): require marketplace update re-consent (#3076)
ascorbic Sep 12, 2026
27e432e
fix(core): surface registry configuration errors (#3077)
ascorbic Sep 12, 2026
befce6d
fix(registry): exempt proven first releases from holdback (#3078)
ascorbic Sep 12, 2026
509a93d
chore: extract locale catalogs [skip ci]
emdashbot[bot] Sep 12, 2026
7bbd8ea
feat(admin): show canonical registry plugin names (#3080)
ascorbic Sep 12, 2026
45b5ea8
chore: extract locale catalogs [skip ci]
emdashbot[bot] Sep 12, 2026
922a25b
Validate guarded storage updates and safe counter arithmetic
logelog Sep 12, 2026
9683b28
Expose guarded storage updates through sandbox adapters
logelog Sep 12, 2026
983177c
Document guarded storage updates and retry behavior
logelog Sep 12, 2026
11fffb5
Merge latest main into feat/plugin-storage-updateif
logelog Sep 12, 2026
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
The table of contents is too big for display.
Diff view
Diff view
  •  
  •  
  •  
119 changes: 113 additions & 6 deletions .changeset/README.md
Original file line number Diff line number Diff line change
@@ -1,8 +1,115 @@
# Changesets
# Writing and reviewing changesets

Hello and welcome! This folder has been automatically generated by `@changesets/cli`, a build tool that works
with multi-package repos, or single-package repos to help you version and publish your code. You can
find the full documentation for it [in our repository](https://github.com/changesets/changesets)
A changeset determines the version bump for a published package, and its description becomes public documentation in the package CHANGELOG. Readers commonly encounter it while deciding whether and how to upgrade. Write and review it for someone who runs the package, not someone who has read the pull request or diff.

We have a quick list of common questions to get you started engaging with this project in
[our documentation](https://github.com/changesets/changesets/blob/main/docs/common-questions.md)
## When to add a changeset

Add a changeset for any change to a published package's behavior or API, including bug fixes, features, and behavior-changing refactors. Without one, the change will not trigger a release.

- Multi-package changes need one changeset listing all affected packages.
- A pull request with several distinct changes can include one changeset per change; each becomes a separate CHANGELOG entry.
- Several pull requests that build one feature for the same release, such as a stack of dependent pull requests, need one changeset describing the complete user-facing capability. Put it in one pull request in the stack rather than documenting the implementation sequence. Use one changeset only when release coordination guarantees that every pull request will ship together; otherwise, each independently releasable pull request needs its own changeset.
- Docs-only, test-only, CI/tooling, demo, and template changes do not need a changeset. [`config.json`](config.json) lists packages that are excluded from releases.

Create a changeset with the following command, then edit the generated Markdown file:

```bash
pnpm changeset
```

The pull request author selects the affected packages and bump type in the changeset frontmatter. Use `patch` for bug fixes and small improvements, and `minor` for new backwards-compatible features. EmDash does not currently accept `major` bumps while it is pre-1.0. A breaking change or significant default change requires prior maintainer approval; use the package and bump strategy agreed with the maintainers.

## Lead with the released behavior

Lead with a present-tense verb such as **Fixes**, **Adds**, **Updates**, **Removes**, or **Deprecates**. In the opening sentence:

- Name the user-facing API, option, command, component, or behavior when readers will recognize it.
- Identify who is affected and what they can now do, or state the observable problem that is fixed.
- Describe the released behavior, not file names, private functions, refactors, queries, or implementation choices.

Give detail in proportion to the impact. One specific sentence is often enough for a patch. A significant minor feature usually needs the capability, basic usage, defaults and compatibility, affected environments, and any action readers must take. Put the most important capability first; do not bury it under incidental fixes or implementation details.

Breaking changes and default changes must be unmistakable. State who is affected, the previous and current behavior, the action required to migrate, and how to restore the previous behavior when that is possible. Prefer a minimal configuration or before-and-after example over a general warning.

Longer entries can use Markdown headings, but start at h4 (`####`). Changesets are embedded below headings in generated CHANGELOG files, so h2 or h3 headings break the document hierarchy.

Do not keep useful explanations or examples only in a changeset or PR description. Add them to the canonical feature or upgrade documentation too; the CHANGELOG is usually read once, while the docs remain the reference.

## Examples

The following patch entry names the affected command and the problem a script author observes:

```md
---
"emdash": patch
---

Fixes `emdash migrate --json` so progress messages go to stderr, allowing scripts to parse stdout as JSON.
```

The following minor-feature entry explains the capability, basic usage, and exit-code contract:

````md
---
"emdash": minor
---

Adds `--check` to `emdash migrate` so deployment pipelines can detect pending or unknown migration records without changing the database.

Run the check after deploying the application artifact that produced the migration manifest:

```sh
pnpm exec emdash migrate --check
```

The command exits with `0` when the database matches the build, `2` when known migrations are pending, and `3` when the database contains migration records unknown to the build. It works with every database adapter supported by the migration manifest.
````

The following approved default-change entry records its `minor` bump and makes the impact and reversion path explicit:

````md
---
"emdash": minor
---

Updates `memoryCache()` to use a five-minute default TTL instead of one hour, so sites using the in-memory object cache refresh cached pages more frequently after an upgrade.

Sites that depend on the previous one-hour lifetime can keep it explicitly:

```ts
objectCache: memoryCache({ defaultTtl: 3600 });
```

#### What should I do?

Set `defaultTtl: 3600` before upgrading if the shorter cache lifetime would add unacceptable load to your site.
````

Use the same level of detail for a breaking change: name the removed or changed surface in the first sentence, then provide the smallest working migration. Do not submit a breaking change until maintainers have approved its package and release strategy.

## Bad and good descriptions

These comparisons show the difference between technically related prose and useful release documentation:

```diff
- Fixes a bug in media handling.
+ Fixes R2 media uploads larger than 10 MB failing before the upload begins.
```

```diff
- Refactors `hydrateEntryBylines` to chunk SQL IN clauses.
+ Fixes D1 errors when loading an entry with more bylines than the database bind-parameter limit.
```

```diff
- Updates migration status handling and exit codes.
+ Adds `emdash migrate --check` so deployment pipelines can detect pending or unknown migrations without changing the database.
```

## Review changesets as documentation

Request a rewrite when an entry is vague, describes internal mechanics, reads like a commit message, buries a significant capability under incidental details, or does not help readers decide whether the release matters to them. Frontmatter validity and technical accuracy are necessary but not sufficient.

Review the description as documentation alongside the bump type and package list.

For Changesets CLI and configuration behavior, see the [Changesets documentation](https://github.com/changesets/changesets/tree/main/docs).
5 changes: 0 additions & 5 deletions .changeset/add-editor-heading-levels.md

This file was deleted.

5 changes: 0 additions & 5 deletions .changeset/add-editor-script-marks.md

This file was deleted.

5 changes: 0 additions & 5 deletions .changeset/admin-kumo-brand-colour.md

This file was deleted.

10 changes: 10 additions & 0 deletions .changeset/attribution-2881.md
Original file line number Diff line number Diff line change
@@ -0,0 +1,10 @@
---
"emdash": patch
"@emdash-cms/plugin-audit-log": patch
---

Fixes content attribution for authenticated REST, visual editing, and MCP saves.

- Revisions record the acting user without changing the entry owner. MCP updates preserve the existing owner, and actorless internal writes leave revision attribution unset instead of inferring it from ownership.
- `content:beforeSave` and `content:afterSave` receive an actor snapshot with the authenticated user's `id` and `role`. The snapshot is isolated between hooks so one plugin cannot change the attribution seen by another.
- The audit-log plugin stores the actor ID as `userId` on content create and update entries.
7 changes: 7 additions & 0 deletions .changeset/bright-plugins-name.md
Original file line number Diff line number Diff line change
@@ -0,0 +1,7 @@
---
"@emdash-cms/admin": minor
---

Adds public names for registry plugins in the `@publisher.example/plugin-slug` format. Registry results and installed-plugin cards display the verified public name and link to a handle-based detail URL, while exact public-name searches open the matching package.

When a publisher handle conclusively fails identity verification, the admin displays **INVALID HANDLE** and prevents installation. Temporary lookup failures fall back to the stable publisher identifier without marking the handle invalid.
5 changes: 5 additions & 0 deletions .changeset/bright-snapshots-travel.md
Original file line number Diff line number Diff line change
@@ -0,0 +1,5 @@
---
"emdash": patch
---

Fixes snapshot exports and content backups on PostgreSQL so preview snapshots, manual backups, and scheduled backups include the same content and portable schema metadata as SQLite.
6 changes: 6 additions & 0 deletions .changeset/calm-bindings-report.md
Original file line number Diff line number Diff line change
@@ -0,0 +1,6 @@
---
"emdash": patch
"@emdash-cms/cloudflare": patch
---

Fixes Cloudflare binding failures during runtime startup returning `NOT_CONFIGURED` from EmDash API routes. Missing D1, R2, KV, Durable Object, and Hyperdrive bindings now return `BINDING_NOT_FOUND` with the binding-specific setup message. Invalid KV and Hyperdrive binding configuration returns `CONFIGURATION_ERROR`.
5 changes: 5 additions & 0 deletions .changeset/calm-bundles-stay.md
Original file line number Diff line number Diff line change
@@ -0,0 +1,5 @@
---
"emdash": patch
---

Fixes overlapping marketplace or registry plugin updates and downgrades deleting the active plugin bundle. Updates retain previous version bundles so delayed work cannot remove a version that becomes active again.
5 changes: 0 additions & 5 deletions .changeset/calm-dashboard-type.md

This file was deleted.

5 changes: 5 additions & 0 deletions .changeset/calm-keys-guide.md
Original file line number Diff line number Diff line change
@@ -0,0 +1,5 @@
---
"@emdash-cms/admin": patch
---

Improves passkey account creation with device-aware guidance before the browser prompt. EmDash explains what a passkey is and where it is saved, detects when a built-in authenticator is unavailable, and guides users through Windows Hello, another device, or a security key. Compatible browsers receive a preference for the selected path, while the browser continues to control the secure passkey prompt.
5 changes: 0 additions & 5 deletions .changeset/calm-owls-read.md

This file was deleted.

10 changes: 10 additions & 0 deletions .changeset/calm-registry-first-releases.md
Original file line number Diff line number Diff line change
@@ -0,0 +1,10 @@
---
"@emdash-cms/registry-lexicons": minor
"@emdash-cms/registry-client": minor
"@emdash-cms/admin": patch
"emdash": patch
---

Adds a fail-closed first-release exemption to the plugin registry's optional minimum release age policy. A package's first release can install immediately only when the aggregator reports exactly one retained release and confirms that it continuously observed the package's release history.

Existing packages, backfilled packages, and packages with missing or incomplete history remain subject to the configured holdback. Deleted releases still count, and explicit publisher or package exemptions continue to work.
5 changes: 5 additions & 0 deletions .changeset/calm-themes-follow.md
Original file line number Diff line number Diff line change
@@ -0,0 +1,5 @@
---
"@emdash-cms/admin": patch
---

Fixes the admin appearance toggle so every click changes the visible color scheme. The admin follows the system preference whenever the selected appearance matches it.
6 changes: 6 additions & 0 deletions .changeset/collection-sidebar-groups.md
Original file line number Diff line number Diff line change
@@ -0,0 +1,6 @@
---
"emdash": minor
"@emdash-cms/admin": minor
---

Adds a `group` setting to collections. Collections that share a group render as one collapsible folder in the admin sidebar, positioned where the first of them appears; a taxonomy joins the folder when every collection it is assigned to is shown in that folder. A folder you have not touched opens while one of its members is active; once you open or close it yourself, the sidebar remembers that choice in the browser. Set the group in the content type editor under Navigation, in seed files, or through the schema API and the MCP collection tools; leaving it empty keeps today's flat list.
5 changes: 5 additions & 0 deletions .changeset/complete-pt-br-admin-translation.md
Original file line number Diff line number Diff line change
@@ -0,0 +1,5 @@
---
"@emdash-cms/admin": patch
---

Completes the Brazilian Portuguese (`pt-BR`) admin translation. Brazilian Portuguese admins now see localized text throughout the admin instead of falling back to English for 1,170 of 2,292 strings.
1 change: 1 addition & 0 deletions .changeset/config.json
Original file line number Diff line number Diff line change
Expand Up @@ -37,6 +37,7 @@
"@emdash-cms/playground",
"@emdash-cms/plugin-api-test",
"@emdash-cms/plugin-marketplace-test",
"@emdash-cms/plugin-mcp-smoke",
"@emdash-cms/plugin-sandboxed-test",
"@emdash-cms/template-blank",
"@emdash-cms/template-blog",
Expand Down
29 changes: 29 additions & 0 deletions .changeset/emdashhead-seo-panel.md
Original file line number Diff line number Diff line change
@@ -0,0 +1,29 @@
---
"emdash": minor
---

`<EmDashHead>` now applies the entry's SEO panel values (title, description, image, canonical, noindex) automatically on server-rendered content pages. Previously the panel was silently ignored unless the page wired `getSeoMeta()` by hand.

#### Affected pages

Pages that include `<EmDashHead>` and fetch their entry through `getEmDashEntry()` receive the overlay. This includes warm object-cache hits, because `getEmDashEntry()` primes the same request-scoped cache from the cached snapshot when the loader never runs. Multi-entry collection results (e.g. `getEmDashCollection()`) are not currently covered.

#### What editors can override

Editor-set panel values replace the template-provided base fields for `description`, `og:title`, `og:description`, `og:image`, the canonical URL, and robots. They also feed the JSON-LD structured data, so head tags and structured data stay in sync.

#### What plugins see

Plugin `page:metadata` and `page:fragments` hooks — in the head and in the body components — receive the overlaid page context, but plugin contributions still win via first-wins dedup.

#### What does not change

- The `<title>` element remains the template's responsibility.
- Prerendered pages and pages that bypass `<EmDashHead>` keep using `getSeoMeta()`.
- No additional database query is made; the panel data rides along on the entry query the page already runs.

#### Canonical and image URL resolution

`getSeoMeta()` now resolves an explicit SEO panel canonical through the same resolver as `<EmDashHead>`: root-relative values (`/custom-path`) are absolutized against the site URL when one is configured (previously they were returned unchanged), and protocol-relative values (`//host/path`) pass through untouched. The same panel value now produces the same canonical URL on both paths.

Protocol-relative SEO image references (`//cdn.example.com/x.png`) are no longer prefixed with the site URL, which previously produced a broken doubled-path URL. This corrects `og:image` output everywhere the panel image is resolved: the `<EmDashHead>` overlay, `getSeoMeta()`, and image URLs in the sitemap.
30 changes: 30 additions & 0 deletions .changeset/entry-edit-lock.md
Original file line number Diff line number Diff line change
@@ -0,0 +1,30 @@
---
"emdash": minor
"@emdash-cms/admin": minor
---

Adds an edit lock per content entry, so two people no longer discover a collision only after both have done the work.

Opening an entry in the admin takes a lock on it. A second editor is told who has it and chooses between opening the entry read-only, where nothing they type can be lost to a refused save, and taking it over. After a take-over, the previous holder is told within two minutes that the entry moved on, their next save is refused, and a banner names who holds it now.

The lock lasts seven minutes. The admin renews it every two minutes while the entry is open, so a pause in typing does not lose it, and every save on the entry extends it too. Leaving the editor or closing the tab releases it, as does moving the entry to the trash; a tab that loses power or network lets it lapse.

#### Who is newly refused

Scripts, API tokens and the CLI that update, delete, publish, unpublish, schedule or discard an entry while an editor has it open in the admin now receive `409 ENTRY_LOCKED` where the write used to succeed. This applies to every collection once the migration has run. The response's `error.message` names the holder and `error.details` carries their `userId`, `userName`, `acquiredAt` and `expiresAt`. Pass `"overrideLock": true` in the request body to write anyway, or `?overrideLock=true` on `DELETE`, which has no body. The CLI takes `--override-lock` on `content update`, `content delete`, `content publish`, `content unpublish` and `content schedule`. The MCP content tools do not honour the lock yet.

Locks are per entry and per locale, so two translations of the same entry can be edited at once.

Take or read a lock directly through `GET`, `POST` and `DELETE` on `/_emdash/api/content/{collection}/{id}/lock`.

#### Turning it off

Locking is on for every collection. Switch it off under **Content Types** → your collection → **Edit locking**, with `editLocking: false` in a seed file, or through `schema_update_collection`:

```json
{ "slug": "posts", "editLocking": false }
```

#### Upgrading

Includes database migration `075_entry_edit_locks`. Projects on the default `auto` runtime migration mode need no action. Projects that migrate as a deployment step: run `emdash migrate` before deploying this version.
5 changes: 0 additions & 5 deletions .changeset/fix-bundled-hreflang.md

This file was deleted.

5 changes: 0 additions & 5 deletions .changeset/fix-table-block-delete.md

This file was deleted.

5 changes: 0 additions & 5 deletions .changeset/great-cases-smile.md

This file was deleted.

5 changes: 5 additions & 0 deletions .changeset/hidden-collections-dashboard-quick-action.md
Original file line number Diff line number Diff line change
@@ -0,0 +1,5 @@
---
"@emdash-cms/admin": patch
---

Fixes the dashboard showing a "+ New …" quick action for collections marked `hidden`, matching the sidebar link the flag already removes.
6 changes: 6 additions & 0 deletions .changeset/moderation-manipulation-findings.md
Original file line number Diff line number Diff line change
@@ -0,0 +1,6 @@
---
"@emdash-cms/registry-moderation": minor
"@emdash-cms/registry-lexicons": minor
---

Adds `moderation-manipulation` findings so labelers can distinguish direct attempts to bypass automated moderation from quoted or descriptive discussion of prompt injection.
5 changes: 5 additions & 0 deletions .changeset/olive-crabs-repeat.md
Original file line number Diff line number Diff line change
@@ -0,0 +1,5 @@
---
"emdash": patch
---

Fixes visual editing on list pages. Entries from `getEmDashCollection` now carry a working `edit` proxy in edit mode, so spreading `{...entry.edit.title}` renders the annotation and the toolbar makes the element editable. Previously every collection entry received a no-op proxy in every mode, so only pages built from `getEmDashEntry` were click-to-edit — fields shown exclusively in a list, and collections with no detail page, could not be edited on the page at all.
6 changes: 6 additions & 0 deletions .changeset/permalink-date-tokens.md
Original file line number Diff line number Diff line change
@@ -0,0 +1,6 @@
---
"emdash": minor
"@emdash-cms/admin": minor
---

Adds WordPress-style date tokens to collection URL patterns. `url_pattern` now supports `{year}`, `{month}`, `{day}`, `{hour}`, `{minute}`, `{second}` (resolved from the entry's publish date, zero-padded) alongside `{slug}` and `{id}` — so you can reproduce permalinks like `/{year}/{month}/{day}/{slug}.html`. The tokens resolve everywhere the pattern is used: sitemap canonical URLs, hreflang alternates, navigation menu links, slug-change auto-redirects, and the admin's preview and "View published" links. Tokens stay literal when an entry has no publish date, so canonical URLs remain stable across edits.
10 changes: 10 additions & 0 deletions .changeset/plugin-http-external-targets.md
Original file line number Diff line number Diff line change
@@ -0,0 +1,10 @@
---
"emdash": patch
"@emdash-cms/sandbox-workerd": patch
---

Fixes plugin HTTP requests with `allowedHosts` so initial URLs and redirects also pass SSRF validation. Requests are rejected when URL or DNS validation identifies an unsupported scheme or a non-public address.

Existing callers of the shared outbound URL validator also reject these non-public ranges.

The default validator resolves public hostnames through `cloudflare-dns.com` before dispatch. Self-hosted deployments must permit access to that endpoint when using the default resolver.
Loading
Loading