From 2b5be3555b479b04d7a05ab7da0f74c82d496779 Mon Sep 17 00:00:00 2001
From: "github-actions[bot]"
<41898282+github-actions[bot]@users.noreply.github.com>
Date: Thu, 20 Aug 2026 09:36:46 +0000
Subject: [PATCH] chore: version packages
---
.changeset/accordion-item-icon-liveness.md | 41 -
.changeset/account-oauth-tokens-internal.md | 72 -
.../account-password-columns-internal.md | 75 -
.changeset/action-onsuccess-navigation.md | 38 -
.../action-predicate-sparse-face-guards.md | 17 -
.../actions-door-demotes-author-codes.md | 41 -
.../actions-flow-dispatch-status-table.md | 22 -
.changeset/admin-export-wildcard-removed.md | 80 -
.../admin-sso-bridge-platform-admin-gate.md | 13 -
.../adr-0057-d10-citation-attributive.md | 19 -
...alytics-authorable-unknown-keys-refused.md | 67 -
...anchor-missing-relation-quoted-template.md | 39 -
.changeset/anonymous-deny-401-code-key.md | 20 -
.changeset/api-key-carries-organization.md | 74 -
.../approvals-record-reader-visibility.md | 56 -
.../arm-platform-migrations-self-hosted.md | 69 -
...rtifact-path-child-env-internal-channel.md | 55 -
.../audit-meta-item-organization-scope.md | 47 -
.../audit-route-capability-gap-refused.md | 57 -
.../audit-row-record-organization-stamp.md | 45 -
...t-tenant-fallback-reads-organization-id.md | 36 -
.changeset/auth-email-deployment-locale.md | 66 -
.changeset/authz-matrix-scope-narrowing.md | 24 -
...z-transport-wired-requires-enforced-row.md | 43 -
...thz-tripwire-dispatcher-plugin-boundary.md | 51 -
.../automation-execute-terminal-messages.md | 51 -
.../automation-input-schema-retry-parity.md | 23 -
.changeset/automation-readme-link-labels.md | 27 -
.../automation-resume-envelope-closed-set.md | 34 -
.../automation-resume-status-unification.md | 58 -
.../automation-resume-value-shape-refused.md | 53 -
.../automation-trigger-refusal-codes.md | 79 -
.../automation-trigger-status-unification.md | 71 -
.changeset/batch-publish-advisories.md | 5 -
.changeset/batch-publish-response-declared.md | 7 -
.changeset/better-auth-family-stable-1-7.md | 55 -
.changeset/boot-widening-bounded-lock-wait.md | 41 -
.../cache-semconv-zero-means-no-consumer.md | 50 -
...capability-class-name-identity-enforced.md | 51 -
.../cascade-delete-probe-failure-surfaces.md | 41 -
.../cascade-probe-multivalue-lookup-filter.md | 95 -
.../cascade-registry-read-propagates.md | 37 -
.../cascade-required-multivalue-per-row.md | 45 -
...cade-set-null-multivalue-member-removal.md | 48 -
.../cbp-master-detail-required-forced.md | 59 -
...cbp-master-editability-authored-widener.md | 60 -
.changeset/cbp-master-leg-ownership-floor.md | 83 -
...ssing-master-insert-validation-envelope.md | 97 -
.../cli-migrate-duplicates-inventory.md | 56 -
...client-explain-recordids-batch-spelling.md | 13 -
.../cloud-arm-host-marketplace-precedence.md | 9 -
.changeset/columnstate-runtime-overlay-key.md | 18 -
.../comment-unscoped-multi-delete-refusal.md | 21 -
.changeset/console-82a94170c405.md | 148 -
.changeset/console-9a3daf8d37ad.md | 145 -
.changeset/console-route-jsdoc-spelling.md | 5 -
.changeset/console-spec-dist-injection.md | 43 -
...eate-objectstack-drop-stale-description.md | 32 -
.../d5-recertification-claim-withdrawn.md | 39 -
.changeset/dashboard-dataset-publish-gate.md | 10 -
.../dashboard-modal-target-page-only-lint.md | 57 -
.../datasource-admin-authentication-floor.md | 51 -
...config-mongo-options-credential-refused.md | 78 -
...config-postgres-url-unparseable-refused.md | 70 -
...rce-config-url-query-credential-refused.md | 66 -
.changeset/datasource-credential-rehoming.md | 50 -
...sref-mongo-composed-no-username-refused.md | 87 -
...redentialsref-mongo-url-no-user-refused.md | 73 -
.../deactivated-position-stops-sharing.md | 81 -
.../declared-endpoints-flow-status-table.md | 63 -
.changeset/default-timeout-margin-repair.md | 40 -
.changeset/deferred-ddl-bounded-lock-wait.md | 49 -
.../delegate-permission-set-resolution.md | 33 -
.changeset/deletepackage-shared-seam-type.md | 44 -
...abot-9212-production-dependencies-patch.md | 38 -
.changeset/derive-org-membership-levels.md | 5 -
...rived-capability-unseeded-bucket-warned.md | 46 -
...dev-plugin-security-enforcement-warning.md | 41 -
.changeset/diagnostics-store-outage-503.md | 70 -
.changeset/diff-dead-history-read.md | 27 -
...-item-canonical-type-and-history-outage.md | 59 -
.changeset/discovery-per-request-protocol.md | 49 -
...-vocabulary-lowercase-and-helper-shapes.md | 56 -
.../dispatcher-meta-put-falsy-body-refused.md | 46 -
...atcher-streaming-fallback-buffered-send.md | 5 -
.../driver-sql-backend-fault-envelope.md | 76 -
...er-sql-mysql-unresolvable-column-parity.md | 47 -
.../driver-sql-readme-shipped-surface.md | 82 -
...r-sql-unresolvable-where-column-refused.md | 91 -
...al-kernel-duplicate-plugin-registration.md | 60 -
.../durability-log-level-callee-shapes.md | 23 -
.changeset/eighty-jars-shave.md | 20 -
.changeset/eighty-pandas-shake.md | 16 -
.changeset/element-filter-lint-residue.md | 15 -
.changeset/element-filter-retired.md | 72 -
.../element-input-target-variable-retired.md | 68 -
.changeset/email-render-only-seam.md | 35 -
.../email-service-core-service-name-jsdoc.md | 5 -
.changeset/endpoint-route-401-code-key.md | 21 -
.../enforce-active-on-grant-catalogues.md | 79 -
.changeset/engine-dotted-filter-refused.md | 59 -
...stored-type-not-canonical-two-producers.md | 17 -
.changeset/error-leak-mysql-phrasings.md | 85 -
.changeset/es-es-position-rename-damage.md | 26 -
.changeset/explain-deactivated-held-state.md | 39 -
.changeset/explain-partial-mask-reporting.md | 58 -
.../export-filename-business-timezone.md | 39 -
.changeset/expression-bindable-text-keys.md | 7 -
...ternal-datasource-federation-auth-floor.md | 60 -
.changeset/field-currency-guidance.md | 24 -
.../field-reference-target-unanswerable.md | 13 -
.changeset/field-related-list-filter.md | 38 -
.../field-scale-precision-integer-refused.md | 39 -
.changeset/field-time-builder.md | 18 -
.../fieldschema-placeholder-declared.md | 38 -
.changeset/filter-preset-comparand-refused.md | 59 -
.changeset/flat-door-declared-code.md | 41 -
.changeset/flow-action-refusal-carrier.md | 33 -
.../flow-terminal-messages-every-run-doc.md | 16 -
.../formula-filter-refusal-adr-0087-entry.md | 32 -
.changeset/gantt-viewmode-declared.md | 5 -
...metaitems-helper-request-literals-typed.md | 43 -
.changeset/hono-adapter-discovery-envelope.md | 24 -
.../hook-refusal-user-facing-marking.md | 50 -
.../http-request-duration-transport-seam.md | 49 -
.../http-requests-total-transport-seam.md | 55 -
.../http-server-response-observation-seam.md | 45 -
.changeset/hungry-donkeys-shout.md | 9 -
.changeset/hydrate-overlay-canonical-type.md | 24 -
.../i18n-merge-consequence-documented.md | 22 -
.changeset/icontains-dialect-parity.md | 30 -
.changeset/identity-api-key-schema-retired.md | 69 -
.../implement-objectos-rule3-real-exports.md | 33 -
...import-naive-datetime-business-timezone.md | 73 -
.../index-rule-where-slot-names-the-object.md | 47 -
...init-scaffold-owd-and-author-time-rules.md | 36 -
...it-template-descriptions-match-emission.md | 19 -
.changeset/inline-locale-map-key-narrow.md | 9 -
.changeset/inline-related-columns-strict.md | 42 -
.changeset/install-local-capability-gate.md | 101 -
.../install-local-listing-auth-floor.md | 85 -
...nstall-local-seed-replayer-registration.md | 9 -
.../invalid-filter-target-field-provenance.md | 63 -
.changeset/ja-jp-position-rename-damage.md | 21 -
.changeset/last-admin-standing-keys-gate.md | 59 -
.changeset/layered-interface-member.md | 8 -
.changeset/legacy-unique-guard-attribution.md | 51 -
.changeset/lifecycle-governance-probe-8906.md | 19 -
.../lint-d3-delegation-rule-position-only.md | 18 -
.changeset/list-comparand-shape-door.md | 53 -
.changeset/list-diagnosed-consumer-sweep.md | 56 -
.changeset/lock-gate-canonical-type-key.md | 11 -
.changeset/lucky-pugs-repeat.md | 11 -
.changeset/lucky-pugs-shave.md | 17 -
.../mcp-http-bridge-merged-skill-read.md | 55 -
.../mcp-prompt-bridge-merged-skill-read.md | 14 -
.changeset/mcp-readme-shipped-surface.md | 68 -
.../memory-persistence-placeholder-refused.md | 55 -
.changeset/meta-promotion-capability-gate.md | 82 -
.../meta-read-organization-id-declared.md | 5 -
.../meta-read-path-credential-redaction.md | 50 -
.changeset/meta-unknown-type-read-refusal.md | 65 -
.changeset/meta-unrecognised-type-refused.md | 149 -
.changeset/meta-write-actor-identity-wins.md | 17 -
.../metadata-422-container-issue-descent.md | 60 -
.../metadata-fs-external-write-resync.md | 54 -
...etadata-plugin-additional-types-retired.md | 62 -
.../metadata-plugin-watch-default-false.md | 37 -
.changeset/mighty-ducks-repeat.md | 40 -
.changeset/mighty-rocks-jump.md | 11 -
.../migrate-meta-reads-retired-key-sources.md | 58 -
...igrate-stored-noncanonical-type-skipped.md | 71 -
.changeset/mongo-dsn-bound-secret-injected.md | 82 -
.changeset/mongo-options-describe-boundary.md | 20 -
.changeset/mysql-dsn-bound-secret.md | 67 -
.changeset/mysql-dsn-ssl-honoured.md | 15 -
.changeset/mysql-duplicate-entry-log-value.md | 25 -
.changeset/mysql-ssl-doc-comment-verbatim.md | 5 -
...ysql-unbacked-conflict-target-preflight.md | 68 -
.../mysql-upsert-ambiguous-conflict-target.md | 29 -
.../mysql-upsert-cross-row-identity-merge.md | 45 -
.changeset/nine-camels-behave.md | 5 -
...cation-subscription-expansion-not-wired.md | 24 -
...otify-node-email-template-locale-bridge.md | 40 -
.../object-index-unknown-keys-refused.md | 57 -
.../object-write-gate-five-gating-rules.md | 29 -
.../objectql-plugin-registry-read-seams.md | 61 -
.changeset/olive-donkeys-brake.md | 27 -
.changeset/olive-pandas-repeat.md | 7 -
.../org-identifier-session-provenance.md | 24 -
.changeset/org-less-customer-activity-1395.md | 10 -
.changeset/org-scoped-meta-read-door.md | 74 -
.changeset/organization-add-member-mounted.md | 36 -
.changeset/organization-probe-discriminate.md | 47 -
.changeset/owd-ledger-wire-shape.md | 7 -
.../package-delete-driver-fault-status.md | 56 -
.../package-routes-getmetaitems-spec-types.md | 52 -
.changeset/partial-field-masking.md | 24 -
.../pending-registration-verdict-doc.md | 7 -
...ganization-audience-binding-suggestions.md | 29 -
.../phantom-anchor-write-deny-diagnostic.md | 19 -
...-default-permission-sets-platform-owned.md | 64 -
.../plugin-audit-readme-audit-service-link.md | 48 -
.../plugin-audit-readme-published-claims.md | 80 -
.../plugin-route-envelope-conformance.md | 30 -
.changeset/plugin-route-refusals-enveloped.md | 72 -
.changeset/plump-crabs-sneeze.md | 17 -
...ostgres-dsn-bound-secret-reaches-server.md | 74 -
.changeset/preflight-refusal-audit-row.md | 29 -
.changeset/preview-drafts-state-declared.md | 6 -
.../probe-mcp-serveable-shared-entry-point.md | 50 -
.changeset/publish-door-advisories.md | 6 -
.changeset/publish-gate-package-closure.md | 46 -
.changeset/publish-meta-canonical-fold.md | 79 -
...blish-refuses-non-canonical-stored-type.md | 92 -
.../published-readme-docs-links-absolute.md | 40 -
.../published-readme-symbol-claims-9544.md | 43 -
.changeset/qa-http-adapter-mount-discovery.md | 38 -
.changeset/rare-donkeys-repeat.md | 23 -
...d-seam-empty-accumulator-discrimination.md | 62 -
.../read-verb-canonical-meta-type-fold.md | 56 -
.changeset/readonly-when-supplied-values.md | 57 -
...reaper-verifies-repoint-before-deleting.md | 45 -
...record-change-reentrant-start-condition.md | 63 -
...rd-chatter-position-renderer-vocabulary.md | 45 -
.../record-package-commit-durability-9066.md | 40 -
.../record-views-drop-ip-address-column.md | 22 -
.changeset/redactor-head-invariant-guard.md | 53 -
.changeset/reference-paths-derivation.md | 39 -
...ference-tables-default-bearing-optional.md | 44 -
...references-route-capability-gap-refused.md | 52 -
.../register-dispatcher-gate-error-codes.md | 25 -
.../register-flow-conversion-conflict.md | 13 -
...ster-unique-scope-confirmation-required.md | 5 -
.changeset/replay-jsdoc-run-history.md | 19 -
...quired-multi-value-empty-array-rejected.md | 31 -
.../rest-approvals-wire-codes-ledger.md | 5 -
.changeset/rest-meta-write-org-scope.md | 36 -
.changeset/resync-skip-summary-explanation.md | 37 -
.changeset/retire-batch-error-codes.md | 9 -
.changeset/retire-remote-template-catalog.md | 23 -
...-sentence-states-what-migrate-meta-does.md | 49 -
.changeset/retry-attempt-pause-suspend-arm.md | 67 -
.../retry-attempt-variable-environment.md | 25 -
.../revert-commit-stored-type-preflight.md | 67 -
.../revoke-session-zero-match-refusal.md | 5 -
.changeset/rollback-canonical-type-fold.md | 62 -
.changeset/runtime-config-product-stage.md | 57 -
.../runtime-dispatcher-discovery-envelope.md | 28 -
...ublish-drafts-flip-announce-driver-text.md | 45 -
.changeset/sandbox-declared-status-rest.md | 5 -
.changeset/scaffold-runtime-image-pinned.md | 49 -
.../searchable-fields-anchor-provenance.md | 53 -
.../searchall-title-canonical-namefield.md | 36 -
...eed-loader-name-probe-asked-not-assumed.md | 47 -
.changeset/seed-tenancy-autonumber-split.md | 29 -
.changeset/seed-tenancy-mysql-dialect.md | 30 -
.changeset/serve-banner-artifact-row.md | 23 -
.changeset/serve-multi-node-cap-advisory.md | 33 -
.../serve-registers-observability-service.md | 11 -
.../serve-unknown-hostname-guard-test-seam.md | 22 -
.../service-job-class-jsdoc-recordruns.md | 26 -
.../service-job-replay-honours-recordruns.md | 34 -
.../service-jsdoc-declared-equals-actual.md | 52 -
.../service-readmes-document-real-exports.md | 76 -
.../sharing-declared-field-binder-converge.md | 45 -
.../sharing-read-merge-provenance-mark.md | 55 -
.changeset/sharing-rule-inert-anchor-gate.md | 56 -
.../showcase-checklist-seed-fixtures.md | 49 -
...howcase-predicate-sparse-face-remainder.md | 25 -
...howcase-sharing-rules-enforce-or-remove.md | 31 -
.changeset/silly-pandas-repeat.md | 11 -
.changeset/sort-axis-authoring-gate.md | 86 -
.changeset/spec-prompts-real-exports-9545.md | 32 -
...nresolvable-column-mysql-reach-addendum.md | 34 -
.changeset/spotty-planes-repeat.md | 5 -
.../sso-provider-map-id-param-retired.md | 58 -
.../stack-top-level-unknown-keys-refused.md | 62 -
.changeset/storage-slot-canonical-rename.md | 40 -
.../summary-index-registry-read-propagates.md | 48 -
.../sys-comment-moderation-delete-policy.md | 78 -
.changeset/sys-email-headers-internal.md | 14 -
.changeset/sys-job-global-unique-scope.md | 11 -
.changeset/sys-job-run-description-history.md | 13 -
...osition-bundle-locales-per-organization.md | 14 -
.../sys-setting-null-safe-row-identity.md | 71 -
.../sys-setting-probe-mysql-spelling.md | 33 -
.../sys-webhook-explicit-api-exposure.md | 46 -
.../system-overview-by-action-title-parity.md | 43 -
...overview-permission-change-tile-removed.md | 61 -
.changeset/system-write-organization-stamp.md | 79 -
.changeset/tabs-item-icon-liveness.md | 41 -
.changeset/tall-jars-invent.md | 18 -
.changeset/tall-maps-declare.md | 18 -
.changeset/template-spec-version-sync.md | 64 -
...filter-comparand-refused-at-engine-door.md | 47 -
.../tenancy-organization-field-stamp-only.md | 42 -
.changeset/tenant-index-follows-the-wall.md | 49 -
.../tenant-plan-docblock-entitlement-fold.md | 31 -
.changeset/tidy-pandas-repeat.md | 23 -
.changeset/tidy-pugs-shave.md | 11 -
.changeset/tough-jars-invite.md | 16 -
.../translation-staleness-source-hash.md | 49 -
.../ui-record-blocks-unknown-keys-refused.md | 90 -
.../ui-reference-rail-unknown-keys-refused.md | 74 -
.changeset/undeclared-field-preflight.md | 11 -
.changeset/undeclared-update-field-door.md | 11 -
...nion-branch-policy-cross-package-parity.md | 41 -
.../union-branch-policy-one-implementation.md | 47 -
...-violation-absence-sentence-superstring.md | 67 -
.changeset/unscoped-multi-delete-refusal.md | 10 -
.changeset/unscoped-multi-update-refusal.md | 17 -
.../unscoped-search-federated-companion.md | 69 -
.../ups-delegated-from-column-retired.md | 47 -
.changeset/upsert-id-insert-only.md | 52 -
.changeset/url-userinfo-username-accessor.md | 26 -
.changeset/value-bearing-cut-template-head.md | 55 -
.changeset/value-bearing-diagnostic-probe.md | 68 -
.../webhook-headers-secret-shape-gate.md | 75 -
.changeset/wise-pugs-attend.md | 34 -
content/docs/deployment/self-hosting.mdx | 8 +-
content/docs/upgrading.mdx | 2 +-
docker/README.md | 6 +-
examples/app-crm/CHANGELOG.md | 117 +
examples/app-crm/package.json | 2 +-
examples/app-showcase/CHANGELOG.md | 244 ++
examples/app-showcase/package.json | 2 +-
examples/app-todo/CHANGELOG.md | 153 +
examples/app-todo/package.json | 2 +-
examples/embed-objectql/CHANGELOG.md | 116 +
examples/embed-objectql/package.json | 2 +-
packages/adapters/hono/CHANGELOG.md | 136 +
packages/adapters/hono/package.json | 2 +-
packages/apps/account/CHANGELOG.md | 103 +
packages/apps/account/package.json | 2 +-
packages/apps/setup/CHANGELOG.md | 103 +
packages/apps/setup/package.json | 2 +-
packages/apps/studio/CHANGELOG.md | 103 +
packages/apps/studio/package.json | 2 +-
packages/cli/CHANGELOG.md | 866 +++++
packages/cli/package.json | 2 +-
packages/client-react/CHANGELOG.md | 104 +
packages/client-react/package.json | 2 +-
packages/client/CHANGELOG.md | 392 +++
packages/client/package.json | 2 +-
packages/cloud-connection/CHANGELOG.md | 440 +++
packages/cloud-connection/package.json | 2 +-
.../connectors/connector-mcp/CHANGELOG.md | 99 +
.../connectors/connector-mcp/package.json | 2 +-
.../connectors/connector-openapi/CHANGELOG.md | 99 +
.../connectors/connector-openapi/package.json | 2 +-
.../connectors/connector-rest/CHANGELOG.md | 99 +
.../connectors/connector-rest/package.json | 2 +-
.../connectors/connector-slack/CHANGELOG.md | 99 +
.../connectors/connector-slack/package.json | 2 +-
packages/console/CHANGELOG.md | 332 ++
packages/console/package.json | 2 +-
packages/core/CHANGELOG.md | 538 +++
packages/core/package.json | 2 +-
packages/create-objectstack/CHANGELOG.md | 160 +
packages/create-objectstack/package.json | 2 +-
packages/drivers/driver-memory/CHANGELOG.md | 126 +
packages/drivers/driver-memory/package.json | 2 +-
packages/drivers/driver-mongodb/CHANGELOG.md | 126 +
packages/drivers/driver-mongodb/package.json | 2 +-
packages/drivers/driver-sql/CHANGELOG.md | 947 ++++++
packages/drivers/driver-sql/package.json | 2 +-
.../drivers/driver-sqlite-wasm/CHANGELOG.md | 137 +
.../drivers/driver-sqlite-wasm/package.json | 2 +-
packages/drivers/driver-turso/CHANGELOG.md | 195 ++
packages/drivers/driver-turso/package.json | 2 +-
packages/formula/CHANGELOG.md | 90 +
packages/formula/package.json | 2 +-
packages/lint/CHANGELOG.md | 622 ++++
packages/lint/package.json | 2 +-
packages/mcp/CHANGELOG.md | 267 ++
packages/mcp/package.json | 2 +-
packages/metadata-core/CHANGELOG.md | 298 ++
packages/metadata-core/package.json | 2 +-
packages/metadata-fs/CHANGELOG.md | 60 +
packages/metadata-fs/package.json | 2 +-
packages/metadata-protocol/CHANGELOG.md | 1779 ++++++++++
packages/metadata-protocol/package.json | 2 +-
packages/metadata/CHANGELOG.md | 177 +
packages/metadata/package.json | 2 +-
packages/objectql/CHANGELOG.md | 1271 +++++++
packages/objectql/package.json | 2 +-
packages/observability/CHANGELOG.md | 215 ++
packages/observability/package.json | 2 +-
packages/platform-objects/CHANGELOG.md | 617 ++++
packages/platform-objects/package.json | 2 +-
packages/plugins/embedder-openai/CHANGELOG.md | 90 +
packages/plugins/embedder-openai/package.json | 2 +-
.../plugins/knowledge-memory/CHANGELOG.md | 101 +
.../plugins/knowledge-memory/package.json | 2 +-
.../plugins/knowledge-ragflow/CHANGELOG.md | 131 +
.../plugins/knowledge-ragflow/package.json | 2 +-
.../plugins/plugin-approvals/CHANGELOG.md | 192 ++
.../plugins/plugin-approvals/package.json | 2 +-
packages/plugins/plugin-audit/CHANGELOG.md | 514 +++
packages/plugins/plugin-audit/package.json | 2 +-
packages/plugins/plugin-auth/CHANGELOG.md | 711 ++++
packages/plugins/plugin-auth/package.json | 2 +-
packages/plugins/plugin-dev/CHANGELOG.md | 276 ++
packages/plugins/plugin-dev/package.json | 2 +-
packages/plugins/plugin-email/CHANGELOG.md | 284 ++
packages/plugins/plugin-email/package.json | 2 +-
.../plugins/plugin-hono-server/CHANGELOG.md | 357 ++
.../plugins/plugin-hono-server/package.json | 2 +-
.../plugins/plugin-pinyin-search/CHANGELOG.md | 71 +
.../plugins/plugin-pinyin-search/package.json | 2 +-
packages/plugins/plugin-reports/CHANGELOG.md | 111 +
packages/plugins/plugin-reports/package.json | 2 +-
packages/plugins/plugin-security/CHANGELOG.md | 953 ++++++
packages/plugins/plugin-security/package.json | 2 +-
packages/plugins/plugin-sharing/CHANGELOG.md | 368 ++
packages/plugins/plugin-sharing/package.json | 2 +-
packages/plugins/plugin-webhooks/CHANGELOG.md | 214 ++
packages/plugins/plugin-webhooks/package.json | 2 +-
packages/qa/dogfood/CHANGELOG.md | 343 ++
packages/qa/dogfood/package.json | 2 +-
packages/qa/downstream-contract/CHANGELOG.md | 90 +
packages/qa/downstream-contract/package.json | 2 +-
packages/qa/http-conformance/CHANGELOG.md | 51 +
packages/qa/http-conformance/package.json | 2 +-
packages/rest/CHANGELOG.md | 1062 ++++++
packages/rest/package.json | 2 +-
packages/runtime/CHANGELOG.md | 1403 ++++++++
packages/runtime/package.json | 2 +-
packages/sdui-parser/CHANGELOG.md | 2 +
packages/sdui-parser/package.json | 2 +-
.../services/service-analytics/CHANGELOG.md | 249 ++
.../services/service-analytics/package.json | 2 +-
.../services/service-automation/CHANGELOG.md | 706 ++++
.../services/service-automation/package.json | 2 +-
packages/services/service-cache/CHANGELOG.md | 247 ++
packages/services/service-cache/package.json | 2 +-
.../service-cluster-redis/CHANGELOG.md | 91 +
.../service-cluster-redis/package.json | 2 +-
.../services/service-cluster/CHANGELOG.md | 99 +
.../services/service-cluster/package.json | 2 +-
.../services/service-datasource/CHANGELOG.md | 624 ++++
.../services/service-datasource/package.json | 2 +-
packages/services/service-i18n/CHANGELOG.md | 201 ++
packages/services/service-i18n/package.json | 2 +-
packages/services/service-job/CHANGELOG.md | 308 ++
packages/services/service-job/package.json | 2 +-
.../services/service-knowledge/CHANGELOG.md | 129 +
.../services/service-knowledge/package.json | 2 +-
.../services/service-messaging/CHANGELOG.md | 201 ++
.../services/service-messaging/package.json | 2 +-
.../services/service-package/CHANGELOG.md | 154 +
.../services/service-package/package.json | 2 +-
packages/services/service-queue/CHANGELOG.md | 111 +
packages/services/service-queue/package.json | 2 +-
.../services/service-realtime/CHANGELOG.md | 111 +
.../services/service-realtime/package.json | 2 +-
.../services/service-settings/CHANGELOG.md | 179 +
.../services/service-settings/package.json | 2 +-
packages/services/service-sms/CHANGELOG.md | 111 +
packages/services/service-sms/package.json | 2 +-
.../services/service-storage/CHANGELOG.md | 183 +
.../services/service-storage/package.json | 2 +-
packages/spec/CHANGELOG.md | 3011 +++++++++++++++++
packages/spec/package.json | 2 +-
packages/triggers/trigger-api/CHANGELOG.md | 99 +
packages/triggers/trigger-api/package.json | 2 +-
.../trigger-record-change/CHANGELOG.md | 99 +
.../trigger-record-change/package.json | 2 +-
.../triggers/trigger-schedule/CHANGELOG.md | 99 +
.../triggers/trigger-schedule/package.json | 2 +-
packages/types/CHANGELOG.md | 349 ++
packages/types/package.json | 2 +-
packages/verify/CHANGELOG.md | 236 ++
packages/verify/package.json | 2 +-
475 files changed, 26235 insertions(+), 13757 deletions(-)
delete mode 100644 .changeset/accordion-item-icon-liveness.md
delete mode 100644 .changeset/account-oauth-tokens-internal.md
delete mode 100644 .changeset/account-password-columns-internal.md
delete mode 100644 .changeset/action-onsuccess-navigation.md
delete mode 100644 .changeset/action-predicate-sparse-face-guards.md
delete mode 100644 .changeset/actions-door-demotes-author-codes.md
delete mode 100644 .changeset/actions-flow-dispatch-status-table.md
delete mode 100644 .changeset/admin-export-wildcard-removed.md
delete mode 100644 .changeset/admin-sso-bridge-platform-admin-gate.md
delete mode 100644 .changeset/adr-0057-d10-citation-attributive.md
delete mode 100644 .changeset/analytics-authorable-unknown-keys-refused.md
delete mode 100644 .changeset/anchor-missing-relation-quoted-template.md
delete mode 100644 .changeset/anonymous-deny-401-code-key.md
delete mode 100644 .changeset/api-key-carries-organization.md
delete mode 100644 .changeset/approvals-record-reader-visibility.md
delete mode 100644 .changeset/arm-platform-migrations-self-hosted.md
delete mode 100644 .changeset/artifact-path-child-env-internal-channel.md
delete mode 100644 .changeset/audit-meta-item-organization-scope.md
delete mode 100644 .changeset/audit-route-capability-gap-refused.md
delete mode 100644 .changeset/audit-row-record-organization-stamp.md
delete mode 100644 .changeset/audit-tenant-fallback-reads-organization-id.md
delete mode 100644 .changeset/auth-email-deployment-locale.md
delete mode 100644 .changeset/authz-matrix-scope-narrowing.md
delete mode 100644 .changeset/authz-transport-wired-requires-enforced-row.md
delete mode 100644 .changeset/authz-tripwire-dispatcher-plugin-boundary.md
delete mode 100644 .changeset/automation-execute-terminal-messages.md
delete mode 100644 .changeset/automation-input-schema-retry-parity.md
delete mode 100644 .changeset/automation-readme-link-labels.md
delete mode 100644 .changeset/automation-resume-envelope-closed-set.md
delete mode 100644 .changeset/automation-resume-status-unification.md
delete mode 100644 .changeset/automation-resume-value-shape-refused.md
delete mode 100644 .changeset/automation-trigger-refusal-codes.md
delete mode 100644 .changeset/automation-trigger-status-unification.md
delete mode 100644 .changeset/batch-publish-advisories.md
delete mode 100644 .changeset/batch-publish-response-declared.md
delete mode 100644 .changeset/better-auth-family-stable-1-7.md
delete mode 100644 .changeset/boot-widening-bounded-lock-wait.md
delete mode 100644 .changeset/cache-semconv-zero-means-no-consumer.md
delete mode 100644 .changeset/capability-class-name-identity-enforced.md
delete mode 100644 .changeset/cascade-delete-probe-failure-surfaces.md
delete mode 100644 .changeset/cascade-probe-multivalue-lookup-filter.md
delete mode 100644 .changeset/cascade-registry-read-propagates.md
delete mode 100644 .changeset/cascade-required-multivalue-per-row.md
delete mode 100644 .changeset/cascade-set-null-multivalue-member-removal.md
delete mode 100644 .changeset/cbp-master-detail-required-forced.md
delete mode 100644 .changeset/cbp-master-editability-authored-widener.md
delete mode 100644 .changeset/cbp-master-leg-ownership-floor.md
delete mode 100644 .changeset/cbp-missing-master-insert-validation-envelope.md
delete mode 100644 .changeset/cli-migrate-duplicates-inventory.md
delete mode 100644 .changeset/client-explain-recordids-batch-spelling.md
delete mode 100644 .changeset/cloud-arm-host-marketplace-precedence.md
delete mode 100644 .changeset/columnstate-runtime-overlay-key.md
delete mode 100644 .changeset/comment-unscoped-multi-delete-refusal.md
delete mode 100644 .changeset/console-82a94170c405.md
delete mode 100644 .changeset/console-9a3daf8d37ad.md
delete mode 100644 .changeset/console-route-jsdoc-spelling.md
delete mode 100644 .changeset/console-spec-dist-injection.md
delete mode 100644 .changeset/create-objectstack-drop-stale-description.md
delete mode 100644 .changeset/d5-recertification-claim-withdrawn.md
delete mode 100644 .changeset/dashboard-dataset-publish-gate.md
delete mode 100644 .changeset/dashboard-modal-target-page-only-lint.md
delete mode 100644 .changeset/datasource-admin-authentication-floor.md
delete mode 100644 .changeset/datasource-config-mongo-options-credential-refused.md
delete mode 100644 .changeset/datasource-config-postgres-url-unparseable-refused.md
delete mode 100644 .changeset/datasource-config-url-query-credential-refused.md
delete mode 100644 .changeset/datasource-credential-rehoming.md
delete mode 100644 .changeset/datasource-credentialsref-mongo-composed-no-username-refused.md
delete mode 100644 .changeset/datasource-credentialsref-mongo-url-no-user-refused.md
delete mode 100644 .changeset/deactivated-position-stops-sharing.md
delete mode 100644 .changeset/declared-endpoints-flow-status-table.md
delete mode 100644 .changeset/default-timeout-margin-repair.md
delete mode 100644 .changeset/deferred-ddl-bounded-lock-wait.md
delete mode 100644 .changeset/delegate-permission-set-resolution.md
delete mode 100644 .changeset/deletepackage-shared-seam-type.md
delete mode 100644 .changeset/dependabot-9212-production-dependencies-patch.md
delete mode 100644 .changeset/derive-org-membership-levels.md
delete mode 100644 .changeset/derived-capability-unseeded-bucket-warned.md
delete mode 100644 .changeset/dev-plugin-security-enforcement-warning.md
delete mode 100644 .changeset/diagnostics-store-outage-503.md
delete mode 100644 .changeset/diff-dead-history-read.md
delete mode 100644 .changeset/diff-meta-item-canonical-type-and-history-outage.md
delete mode 100644 .changeset/discovery-per-request-protocol.md
delete mode 100644 .changeset/dispatcher-error-vocabulary-lowercase-and-helper-shapes.md
delete mode 100644 .changeset/dispatcher-meta-put-falsy-body-refused.md
delete mode 100644 .changeset/dispatcher-streaming-fallback-buffered-send.md
delete mode 100644 .changeset/driver-sql-backend-fault-envelope.md
delete mode 100644 .changeset/driver-sql-mysql-unresolvable-column-parity.md
delete mode 100644 .changeset/driver-sql-readme-shipped-surface.md
delete mode 100644 .changeset/driver-sql-unresolvable-where-column-refused.md
delete mode 100644 .changeset/dual-kernel-duplicate-plugin-registration.md
delete mode 100644 .changeset/durability-log-level-callee-shapes.md
delete mode 100644 .changeset/eighty-jars-shave.md
delete mode 100644 .changeset/eighty-pandas-shake.md
delete mode 100644 .changeset/element-filter-lint-residue.md
delete mode 100644 .changeset/element-filter-retired.md
delete mode 100644 .changeset/element-input-target-variable-retired.md
delete mode 100644 .changeset/email-render-only-seam.md
delete mode 100644 .changeset/email-service-core-service-name-jsdoc.md
delete mode 100644 .changeset/endpoint-route-401-code-key.md
delete mode 100644 .changeset/enforce-active-on-grant-catalogues.md
delete mode 100644 .changeset/engine-dotted-filter-refused.md
delete mode 100644 .changeset/error-code-ledger-stored-type-not-canonical-two-producers.md
delete mode 100644 .changeset/error-leak-mysql-phrasings.md
delete mode 100644 .changeset/es-es-position-rename-damage.md
delete mode 100644 .changeset/explain-deactivated-held-state.md
delete mode 100644 .changeset/explain-partial-mask-reporting.md
delete mode 100644 .changeset/export-filename-business-timezone.md
delete mode 100644 .changeset/expression-bindable-text-keys.md
delete mode 100644 .changeset/external-datasource-federation-auth-floor.md
delete mode 100644 .changeset/field-currency-guidance.md
delete mode 100644 .changeset/field-reference-target-unanswerable.md
delete mode 100644 .changeset/field-related-list-filter.md
delete mode 100644 .changeset/field-scale-precision-integer-refused.md
delete mode 100644 .changeset/field-time-builder.md
delete mode 100644 .changeset/fieldschema-placeholder-declared.md
delete mode 100644 .changeset/filter-preset-comparand-refused.md
delete mode 100644 .changeset/flat-door-declared-code.md
delete mode 100644 .changeset/flow-action-refusal-carrier.md
delete mode 100644 .changeset/flow-terminal-messages-every-run-doc.md
delete mode 100644 .changeset/formula-filter-refusal-adr-0087-entry.md
delete mode 100644 .changeset/gantt-viewmode-declared.md
delete mode 100644 .changeset/getmetaitems-helper-request-literals-typed.md
delete mode 100644 .changeset/hono-adapter-discovery-envelope.md
delete mode 100644 .changeset/hook-refusal-user-facing-marking.md
delete mode 100644 .changeset/http-request-duration-transport-seam.md
delete mode 100644 .changeset/http-requests-total-transport-seam.md
delete mode 100644 .changeset/http-server-response-observation-seam.md
delete mode 100644 .changeset/hungry-donkeys-shout.md
delete mode 100644 .changeset/hydrate-overlay-canonical-type.md
delete mode 100644 .changeset/i18n-merge-consequence-documented.md
delete mode 100644 .changeset/icontains-dialect-parity.md
delete mode 100644 .changeset/identity-api-key-schema-retired.md
delete mode 100644 .changeset/implement-objectos-rule3-real-exports.md
delete mode 100644 .changeset/import-naive-datetime-business-timezone.md
delete mode 100644 .changeset/index-rule-where-slot-names-the-object.md
delete mode 100644 .changeset/init-scaffold-owd-and-author-time-rules.md
delete mode 100644 .changeset/init-template-descriptions-match-emission.md
delete mode 100644 .changeset/inline-locale-map-key-narrow.md
delete mode 100644 .changeset/inline-related-columns-strict.md
delete mode 100644 .changeset/install-local-capability-gate.md
delete mode 100644 .changeset/install-local-listing-auth-floor.md
delete mode 100644 .changeset/install-local-seed-replayer-registration.md
delete mode 100644 .changeset/invalid-filter-target-field-provenance.md
delete mode 100644 .changeset/ja-jp-position-rename-damage.md
delete mode 100644 .changeset/last-admin-standing-keys-gate.md
delete mode 100644 .changeset/layered-interface-member.md
delete mode 100644 .changeset/legacy-unique-guard-attribution.md
delete mode 100644 .changeset/lifecycle-governance-probe-8906.md
delete mode 100644 .changeset/lint-d3-delegation-rule-position-only.md
delete mode 100644 .changeset/list-comparand-shape-door.md
delete mode 100644 .changeset/list-diagnosed-consumer-sweep.md
delete mode 100644 .changeset/lock-gate-canonical-type-key.md
delete mode 100644 .changeset/lucky-pugs-repeat.md
delete mode 100644 .changeset/lucky-pugs-shave.md
delete mode 100644 .changeset/mcp-http-bridge-merged-skill-read.md
delete mode 100644 .changeset/mcp-prompt-bridge-merged-skill-read.md
delete mode 100644 .changeset/mcp-readme-shipped-surface.md
delete mode 100644 .changeset/memory-persistence-placeholder-refused.md
delete mode 100644 .changeset/meta-promotion-capability-gate.md
delete mode 100644 .changeset/meta-read-organization-id-declared.md
delete mode 100644 .changeset/meta-read-path-credential-redaction.md
delete mode 100644 .changeset/meta-unknown-type-read-refusal.md
delete mode 100644 .changeset/meta-unrecognised-type-refused.md
delete mode 100644 .changeset/meta-write-actor-identity-wins.md
delete mode 100644 .changeset/metadata-422-container-issue-descent.md
delete mode 100644 .changeset/metadata-fs-external-write-resync.md
delete mode 100644 .changeset/metadata-plugin-additional-types-retired.md
delete mode 100644 .changeset/metadata-plugin-watch-default-false.md
delete mode 100644 .changeset/mighty-ducks-repeat.md
delete mode 100644 .changeset/mighty-rocks-jump.md
delete mode 100644 .changeset/migrate-meta-reads-retired-key-sources.md
delete mode 100644 .changeset/migrate-stored-noncanonical-type-skipped.md
delete mode 100644 .changeset/mongo-dsn-bound-secret-injected.md
delete mode 100644 .changeset/mongo-options-describe-boundary.md
delete mode 100644 .changeset/mysql-dsn-bound-secret.md
delete mode 100644 .changeset/mysql-dsn-ssl-honoured.md
delete mode 100644 .changeset/mysql-duplicate-entry-log-value.md
delete mode 100644 .changeset/mysql-ssl-doc-comment-verbatim.md
delete mode 100644 .changeset/mysql-unbacked-conflict-target-preflight.md
delete mode 100644 .changeset/mysql-upsert-ambiguous-conflict-target.md
delete mode 100644 .changeset/mysql-upsert-cross-row-identity-merge.md
delete mode 100644 .changeset/nine-camels-behave.md
delete mode 100644 .changeset/notification-subscription-expansion-not-wired.md
delete mode 100644 .changeset/notify-node-email-template-locale-bridge.md
delete mode 100644 .changeset/object-index-unknown-keys-refused.md
delete mode 100644 .changeset/object-write-gate-five-gating-rules.md
delete mode 100644 .changeset/objectql-plugin-registry-read-seams.md
delete mode 100644 .changeset/olive-donkeys-brake.md
delete mode 100644 .changeset/olive-pandas-repeat.md
delete mode 100644 .changeset/org-identifier-session-provenance.md
delete mode 100644 .changeset/org-less-customer-activity-1395.md
delete mode 100644 .changeset/org-scoped-meta-read-door.md
delete mode 100644 .changeset/organization-add-member-mounted.md
delete mode 100644 .changeset/organization-probe-discriminate.md
delete mode 100644 .changeset/owd-ledger-wire-shape.md
delete mode 100644 .changeset/package-delete-driver-fault-status.md
delete mode 100644 .changeset/package-routes-getmetaitems-spec-types.md
delete mode 100644 .changeset/partial-field-masking.md
delete mode 100644 .changeset/pending-registration-verdict-doc.md
delete mode 100644 .changeset/per-organization-audience-binding-suggestions.md
delete mode 100644 .changeset/phantom-anchor-write-deny-diagnostic.md
delete mode 100644 .changeset/platform-default-permission-sets-platform-owned.md
delete mode 100644 .changeset/plugin-audit-readme-audit-service-link.md
delete mode 100644 .changeset/plugin-audit-readme-published-claims.md
delete mode 100644 .changeset/plugin-route-envelope-conformance.md
delete mode 100644 .changeset/plugin-route-refusals-enveloped.md
delete mode 100644 .changeset/plump-crabs-sneeze.md
delete mode 100644 .changeset/postgres-dsn-bound-secret-reaches-server.md
delete mode 100644 .changeset/preflight-refusal-audit-row.md
delete mode 100644 .changeset/preview-drafts-state-declared.md
delete mode 100644 .changeset/probe-mcp-serveable-shared-entry-point.md
delete mode 100644 .changeset/publish-door-advisories.md
delete mode 100644 .changeset/publish-gate-package-closure.md
delete mode 100644 .changeset/publish-meta-canonical-fold.md
delete mode 100644 .changeset/publish-refuses-non-canonical-stored-type.md
delete mode 100644 .changeset/published-readme-docs-links-absolute.md
delete mode 100644 .changeset/published-readme-symbol-claims-9544.md
delete mode 100644 .changeset/qa-http-adapter-mount-discovery.md
delete mode 100644 .changeset/rare-donkeys-repeat.md
delete mode 100644 .changeset/read-seam-empty-accumulator-discrimination.md
delete mode 100644 .changeset/read-verb-canonical-meta-type-fold.md
delete mode 100644 .changeset/readonly-when-supplied-values.md
delete mode 100644 .changeset/reaper-verifies-repoint-before-deleting.md
delete mode 100644 .changeset/record-change-reentrant-start-condition.md
delete mode 100644 .changeset/record-chatter-position-renderer-vocabulary.md
delete mode 100644 .changeset/record-package-commit-durability-9066.md
delete mode 100644 .changeset/record-views-drop-ip-address-column.md
delete mode 100644 .changeset/redactor-head-invariant-guard.md
delete mode 100644 .changeset/reference-paths-derivation.md
delete mode 100644 .changeset/reference-tables-default-bearing-optional.md
delete mode 100644 .changeset/references-route-capability-gap-refused.md
delete mode 100644 .changeset/register-dispatcher-gate-error-codes.md
delete mode 100644 .changeset/register-flow-conversion-conflict.md
delete mode 100644 .changeset/register-unique-scope-confirmation-required.md
delete mode 100644 .changeset/replay-jsdoc-run-history.md
delete mode 100644 .changeset/required-multi-value-empty-array-rejected.md
delete mode 100644 .changeset/rest-approvals-wire-codes-ledger.md
delete mode 100644 .changeset/rest-meta-write-org-scope.md
delete mode 100644 .changeset/resync-skip-summary-explanation.md
delete mode 100644 .changeset/retire-batch-error-codes.md
delete mode 100644 .changeset/retire-remote-template-catalog.md
delete mode 100644 .changeset/retirement-sentence-states-what-migrate-meta-does.md
delete mode 100644 .changeset/retry-attempt-pause-suspend-arm.md
delete mode 100644 .changeset/retry-attempt-variable-environment.md
delete mode 100644 .changeset/revert-commit-stored-type-preflight.md
delete mode 100644 .changeset/revoke-session-zero-match-refusal.md
delete mode 100644 .changeset/rollback-canonical-type-fold.md
delete mode 100644 .changeset/runtime-config-product-stage.md
delete mode 100644 .changeset/runtime-dispatcher-discovery-envelope.md
delete mode 100644 .changeset/runtime-publish-drafts-flip-announce-driver-text.md
delete mode 100644 .changeset/sandbox-declared-status-rest.md
delete mode 100644 .changeset/scaffold-runtime-image-pinned.md
delete mode 100644 .changeset/searchable-fields-anchor-provenance.md
delete mode 100644 .changeset/searchall-title-canonical-namefield.md
delete mode 100644 .changeset/seed-loader-name-probe-asked-not-assumed.md
delete mode 100644 .changeset/seed-tenancy-autonumber-split.md
delete mode 100644 .changeset/seed-tenancy-mysql-dialect.md
delete mode 100644 .changeset/serve-banner-artifact-row.md
delete mode 100644 .changeset/serve-multi-node-cap-advisory.md
delete mode 100644 .changeset/serve-registers-observability-service.md
delete mode 100644 .changeset/serve-unknown-hostname-guard-test-seam.md
delete mode 100644 .changeset/service-job-class-jsdoc-recordruns.md
delete mode 100644 .changeset/service-job-replay-honours-recordruns.md
delete mode 100644 .changeset/service-jsdoc-declared-equals-actual.md
delete mode 100644 .changeset/service-readmes-document-real-exports.md
delete mode 100644 .changeset/sharing-declared-field-binder-converge.md
delete mode 100644 .changeset/sharing-read-merge-provenance-mark.md
delete mode 100644 .changeset/sharing-rule-inert-anchor-gate.md
delete mode 100644 .changeset/showcase-checklist-seed-fixtures.md
delete mode 100644 .changeset/showcase-predicate-sparse-face-remainder.md
delete mode 100644 .changeset/showcase-sharing-rules-enforce-or-remove.md
delete mode 100644 .changeset/silly-pandas-repeat.md
delete mode 100644 .changeset/sort-axis-authoring-gate.md
delete mode 100644 .changeset/spec-prompts-real-exports-9545.md
delete mode 100644 .changeset/spec-unresolvable-column-mysql-reach-addendum.md
delete mode 100644 .changeset/spotty-planes-repeat.md
delete mode 100644 .changeset/sso-provider-map-id-param-retired.md
delete mode 100644 .changeset/stack-top-level-unknown-keys-refused.md
delete mode 100644 .changeset/storage-slot-canonical-rename.md
delete mode 100644 .changeset/summary-index-registry-read-propagates.md
delete mode 100644 .changeset/sys-comment-moderation-delete-policy.md
delete mode 100644 .changeset/sys-email-headers-internal.md
delete mode 100644 .changeset/sys-job-global-unique-scope.md
delete mode 100644 .changeset/sys-job-run-description-history.md
delete mode 100644 .changeset/sys-position-bundle-locales-per-organization.md
delete mode 100644 .changeset/sys-setting-null-safe-row-identity.md
delete mode 100644 .changeset/sys-setting-probe-mysql-spelling.md
delete mode 100644 .changeset/sys-webhook-explicit-api-exposure.md
delete mode 100644 .changeset/system-overview-by-action-title-parity.md
delete mode 100644 .changeset/system-overview-permission-change-tile-removed.md
delete mode 100644 .changeset/system-write-organization-stamp.md
delete mode 100644 .changeset/tabs-item-icon-liveness.md
delete mode 100644 .changeset/tall-jars-invent.md
delete mode 100644 .changeset/tall-maps-declare.md
delete mode 100644 .changeset/template-spec-version-sync.md
delete mode 100644 .changeset/temporal-filter-comparand-refused-at-engine-door.md
delete mode 100644 .changeset/tenancy-organization-field-stamp-only.md
delete mode 100644 .changeset/tenant-index-follows-the-wall.md
delete mode 100644 .changeset/tenant-plan-docblock-entitlement-fold.md
delete mode 100644 .changeset/tidy-pandas-repeat.md
delete mode 100644 .changeset/tidy-pugs-shave.md
delete mode 100644 .changeset/tough-jars-invite.md
delete mode 100644 .changeset/translation-staleness-source-hash.md
delete mode 100644 .changeset/ui-record-blocks-unknown-keys-refused.md
delete mode 100644 .changeset/ui-reference-rail-unknown-keys-refused.md
delete mode 100644 .changeset/undeclared-field-preflight.md
delete mode 100644 .changeset/undeclared-update-field-door.md
delete mode 100644 .changeset/union-branch-policy-cross-package-parity.md
delete mode 100644 .changeset/union-branch-policy-one-implementation.md
delete mode 100644 .changeset/unique-violation-absence-sentence-superstring.md
delete mode 100644 .changeset/unscoped-multi-delete-refusal.md
delete mode 100644 .changeset/unscoped-multi-update-refusal.md
delete mode 100644 .changeset/unscoped-search-federated-companion.md
delete mode 100644 .changeset/ups-delegated-from-column-retired.md
delete mode 100644 .changeset/upsert-id-insert-only.md
delete mode 100644 .changeset/url-userinfo-username-accessor.md
delete mode 100644 .changeset/value-bearing-cut-template-head.md
delete mode 100644 .changeset/value-bearing-diagnostic-probe.md
delete mode 100644 .changeset/webhook-headers-secret-shape-gate.md
delete mode 100644 .changeset/wise-pugs-attend.md
diff --git a/.changeset/accordion-item-icon-liveness.md b/.changeset/accordion-item-icon-liveness.md
deleted file mode 100644
index f08b335c49..0000000000
--- a/.changeset/accordion-item-icon-liveness.md
+++ /dev/null
@@ -1,41 +0,0 @@
----
-"@objectstack/spec": patch
----
-
-docs(spec): record the live read point of `page:accordion` `items[].icon` — a `.describe()` plus an accept-pin, so a liveness sweep stops re-deriving a false retirement candidate (#9881)
-
-`PageAccordionProps.items[].icon` parsed, rendered, and said nothing about
-itself. A liveness sweep therefore read it as declared-but-unenforced and opened
-a retirement candidate against it — which cost a full dispatch cycle before the
-cross-repo read point was found and the candidate was closed premise-overtaken.
-Nothing on the spec side recorded that liveness, so the next sweep would have
-derived the same false candidate from the same absence.
-
-**The key is live**, re-verified at the objectui pin this repo builds against
-(`.objectui-sha` = `82a94170c`) rather than taken from the card:
-
-- `packages/components/src/renderers/layout/containers.tsx:851-853` —
- `PageAccordionRenderer` renders `{item.icon && }`
- inside the `AccordionTrigger`, grouped with the label in the trigger's single
- wrapping span.
-- `containers.tsx:898` — `ComponentRegistry.register('accordion', …)` publishes
- the key to the Studio block designer in the `items` input, documented as
- `[{ label, icon?, collapsed?, children }]`.
-
-**Nothing about what parses changes.** The key was already declared and already
-optional; this adds the prose that makes its liveness readable, and the test that
-keeps it readable:
-
-- a `.describe()` naming the consumer behaviourally, in the file's house idiom —
- the same shape `record:alert`'s own `icon` uses ("Read on this component —
- contrast …"), with the file:line anchors and the measured pin in the docblock
- above the key, where this file keeps them;
-- an accept-pin asserting the key parses on a `page:accordion` item and survives
- to the parsed output, that an undeclared sibling on the same item is still
- refused (so the accept is not vacuous on a schema that stopped being strict),
- and that the `.describe()` still names the consumer — deleting it is what
- re-opens the false candidate, so it is pinned rather than left to review.
-
-The item `value` prescribed against one line above is the deliberate contrast:
-the same renderer overwrites that key with `panel-`, and a read point is
-precisely what separates the two verdicts.
diff --git a/.changeset/account-oauth-tokens-internal.md b/.changeset/account-oauth-tokens-internal.md
deleted file mode 100644
index 0a0c76fe99..0000000000
--- a/.changeset/account-oauth-tokens-internal.md
+++ /dev/null
@@ -1,72 +0,0 @@
----
-"@objectstack/platform-objects": patch
-"@objectstack/plugin-auth": patch
----
-
-fix(security): `sys_account`'s OAuth access/refresh/id tokens stop serializing on the data API — `internal: true`, with better-auth's readback seam widened to cover them (#7987)
-
-
-
-`sys_account.access_token`, `.refresh_token` and `.id_token` hold each user's
-**live third-party OAuth credentials** — the tokens ObjectStack received from
-Google, GitHub or an OIDC IdP — in cleartext (better-auth's
-`account.encryptOAuthTokens` is not set, so `setTokenUtil` stores them
-verbatim). They were plain `Field.textarea` on an object declaring
-`apiEnabled: true, apiMethods: ['get','list']`.
-
-**Both personas were measured leaking, on a real booted stack** (`bootStack(showcaseStack)`,
-in-process HTTP + sqlite-wasm), with a planted token on a member's account row:
-
-- **admin**, `GET /data/sys_account/{another user's account id}` — 200, that
- member's `refresh_token` verbatim, plus `access_token` and `id_token`;
-- **member**, `GET /data/sys_account` (self-scoped by the `sys_account_self` RLS
- policy) — 200, their **own** `refresh_token` verbatim.
-
-The member arm is the one this object does not share with its `sys_session`
-sibling (#7823), and it is the sharper of the two: it converts a short-lived,
-revocable ObjectStack session bearer into a **long-lived third-party refresh
-token that this platform cannot revoke at all**. Neither collector reached these
-columns — the engine's credential mask collects by field TYPE (`textarea` is
-neither `secret` nor `password`) *and* exempts objects with
-`managedBy: 'better-auth'`, which this object is.
-
-**The fix is three declarations plus one widening**, inheriting #7823's shape
-rather than inventing a second mechanism:
-
-- the three columns are declared `internal: true` — the opt-in, type-independent
- flag minted by #7728 meaning *the declared value is never returned on the
- generic data path*. Storage, filtering and indexing are untouched: the strip
- runs on rows the driver has already produced.
-- better-auth **reads these back off adapter result rows** — measured, and the
- risk this card was parked on: `internalAdapter.findAccounts(userId)` issues a
- `findMany` with no projection, and `/get-access-token`, `/account-info` and
- `/refresh-token` then read `account.refreshToken` / `.accessToken` /
- `.idToken` off those rows. The read strip alone would answer
- `REFRESH_TOKEN_NOT_FOUND` (400) and hand back an empty access token. So the
- existing readback seam in `@objectstack/plugin-auth` — which already recovered
- `sys_session.token` through `Engine.resolveInternalField` (#8118's privileged
- batch accessor) — is widened to cover these three columns and renamed
- accordingly. No engine carve-out, no second accessor.
-
-**Not retyped, deliberately.** `Field.secret()` would route better-auth's own
-writes through the engine's encrypt-on-write path, placing the engine between
-better-auth and its own adapter. `Field.password()` is inert here for the two
-reasons above.
-
-**`password` / `previous_password_hashes` are deliberately out of scope** —
-they are better-auth one-way hashes (ADR-0100's third channel), not reversible
-outbound credentials, and the readback seam refuses to touch them.
-
-The regression proof drives both directions: the fixture PLANTS real token
-values and re-reads them out of storage through the privileged accessor before
-asserting anything (so "absent from the response" cannot pass vacuously), then
-pins that the values are still on disk, still usable as a server-side predicate,
-and that password sign-in — which reads a `sys_account` row back through the
-same seam on every request — still works.
diff --git a/.changeset/account-password-columns-internal.md b/.changeset/account-password-columns-internal.md
deleted file mode 100644
index 77ea33a8bc..0000000000
--- a/.changeset/account-password-columns-internal.md
+++ /dev/null
@@ -1,75 +0,0 @@
----
-"@objectstack/platform-objects": patch
-"@objectstack/plugin-auth": patch
----
-
-fix(security): `sys_account.password` and `previous_password_hashes` stop serializing on the data API — `internal: true`, with the raw-engine readers converted to the privileged accessor (#8676)
-
-
-
-`sys_account.password` (the credential hash) and `previous_password_hashes` (the
-ADR-0069 D1 reuse-prevention ring) serialized on `/api/v1/data/sys_account`,
-which declares `apiEnabled: true, apiMethods: ['get','list']` — to an **admin
-for every user's row**, and to a **member for their own** (the
-`sys_account_self` RLS policy grants `select` on `user_id == current_user.id`).
-
-These are one-way hashes, not reversible outbound credentials — which is why
-#7987 correctly refused to bundle them with the OAuth tokens. But a served
-password hash is an offline-cracking target, and `previous_password_hashes`
-multiplies it by the history ring while its own declaration says it is *never
-exposed in UI*. This is the disposition #7728 already reached for
-`sys_api_key.key`, which was **also** a stored hash and was still ruled unfit to
-serialize through the API face.
-
-Neither credential collector could reach them: `collectMaskedReadFields` keys on
-the field **TYPE** (`secret` / `password`) *and* exempts objects declaring
-`managedBy: 'better-auth'`, which this object is — while these columns are
-`text` / `textarea`. Two independent barriers, both missing.
-
-**The fix is two declarations plus two recovery seams**, and the second seam is
-the part a bare flag would have missed:
-
-- both columns are declared `internal: true` — the opt-in, type-independent flag
- from #7728 meaning *the declared value is never returned on the generic data
- path*. Storage, filtering and indexing are untouched: the strip runs on rows
- the driver has already produced.
-- **better-auth's adapter readers** are recovered by the existing per-object
- readback table, widened with `password`: the sign-in verifier compares against
- the hash on the row `internalAdapter.findCredentialAccount(userId)` returns,
- so the strip alone would break password sign-in for every user.
-- **plugin-auth's own RAW-engine readers** are recovered by a new seam in the
- same module, `recoverInternalFieldsForSystemRead`. This is the half that makes
- the flag safe: the readback table is imported by exactly one file
- (better-auth's storage adapter), so it cannot reach a caller that reads the
- engine directly — and the engine's strip has **no `isSystem` carve-out** by
- #7728's design. Measured against a real ObjectQL engine: the reuse ring's
- `findOne` returns `{"id":"a1"}` for a query that names both columns in an
- explicit projection under `context: { isSystem: true }`.
-
- Left unrecovered, `assertPasswordNotReused` would become a **silent no-op** —
- its comparison list empties, the loop never runs, `PASSWORD_REUSE` is never
- thrown, and its own `catch { return undefined }` means nothing announces it.
- The ADR-0069 D1 control would report success while accepting every reused
- password. Its unit tests would have stayed green throughout, because they use
- fake engines that never apply the strip.
-
-**No ADR-0100 guard change, and none was needed.** `Engine.resolveInternalField`
-has exactly one predicate — `internal === true` — so flagging the columns makes
-them legitimately dereferenceable through the privileged accessor. The ADR-0100
-sentence in its refusal message is prose explaining why a *non-flagged* field has
-other channels, not a second predicate; the guard stays exactly as selective as
-it was, and a non-flagged column on the same object is still refused with
-`INVALID_FIELD` / 400.
-
-Regression proof drives both directions on a real booted stack: both columns are
-absent for both personas — including a caller who spells them out in `?select=` —
-while the values remain on disk and reachable through the privileged accessor,
-password sign-in still works, and the reuse ring still grows across a password
-change on every transport lane.
diff --git a/.changeset/action-onsuccess-navigation.md b/.changeset/action-onsuccess-navigation.md
deleted file mode 100644
index a7f4d80a6b..0000000000
--- a/.changeset/action-onsuccess-navigation.md
+++ /dev/null
@@ -1,38 +0,0 @@
----
-"@objectstack/spec": minor
----
-
-feat(spec): `ActionSchema.onSuccess` — post-success navigation for `api`/`script` actions, with `${result.*}` joining the navigate template's interpolation scope (#9566, #9474)
-
-
-
-The maintainer's 2026-08-18 ruling (recorded on #9566, mirrored on #9474)
-declares ONE post-success navigation contract for both server-executing action
-types instead of two per-type conventions:
-
-- `onSuccess: { navigate, openIn? }` — a strict object, read for
- `type: 'api'` and `type: 'script'` only (a refinement refuses it on
- `url`/`modal`/`flow`/`form`, where no success event exists for it to ride —
- the ADR-0078 posture, same enforcement shape as the `body`-on-non-script
- refinement).
-- `navigate` is a route/URL template. Its documented interpolation scope is
- `${param.*}` + `${ctx.*}` (existing) + **`${result.*}` — NEW: the action's
- server response payload** (an `api` action's response body, a `script`
- handler's return value), which is what makes "server clones a record → jump
- to the new record" declarable: `navigate: '/apps/crm/tasks/${result.id}'`.
- The interpolation ENGINE stays the renderer's (objectui `interpolateTarget`);
- the spec records the contract.
-- `openIn` is the closed enum `'self' | 'newTab'`, defaulting **`'self'`**
- (materialized, the file's default convention) — no general navigation DSL.
-- The shipped handler-return convention (`{ redirectUrl, openIn? }`,
- objectui#2967/#2904) keeps its 17.0.0 semantics: absent `openIn` still means
- new-tab (no silent behavior flip for existing handlers); a handler may return
- `openIn: 'self'` explicitly.
-
-The console consumer is the downstream objectui half (SPA navigation branch,
-`executeAPI` navigation handling, `${result.*}` interpolation), filed
-Blocked-by these cards; the liveness ledger records the key at `planned`
-strength with the amend-on-landing instruction.
diff --git a/.changeset/action-predicate-sparse-face-guards.md b/.changeset/action-predicate-sparse-face-guards.md
deleted file mode 100644
index ad077bc7f0..0000000000
--- a/.changeset/action-predicate-sparse-face-guards.md
+++ /dev/null
@@ -1,17 +0,0 @@
----
-'@objectstack/platform-objects': patch
-'@objectstack/plugin-approvals': patch
----
-
-Guard every authored record-scoped action predicate for the sparse action face, so a list row that did not project the gated column no longer silently drops the button.
-
-An action's `visible` / `disabled` predicate binds whatever record the client already fetched — a record-detail read, or a list row carrying only the view's `$select` projection. That binding stays sparse by decision (it is the one record binding the platform does not make total), and CEL aborts the whole expression at key resolution when a key is absent. The abort is fail-closed, so the button is simply not offered — indistinguishable to the user from the gate having said no, and reported nowhere.
-
-Every authored predicate on `sys_user`, `sys_invitation`, `sys_member`, `sys_oauth_application` and `sys_approval_request` now opens each `record.*` read with `has()`. The guard is the minimal measured form per predicate, not one blanket rewrite: a bare equality against a literal needs `has()` alone, because CEL compares heterogeneously and answers `false` on a projected-null column rather than faulting.
-
-Two predicates change what a user sees, both on `sys_oauth_application`, whose `disabled` column is nullable upstream and therefore null on every application nobody has ever toggled:
-
-- `disable_oauth_application` was `!record.disabled`, which faulted on a projected-null row (`!` needs a bool) — so the Disable button was missing from every never-toggled application in the list. It is now `has(record.disabled) && record.disabled != true` and is offered.
-- `enable_oauth_application` was `record.disabled`, which answered `null` rather than a boolean and left the decision to the renderer. It is now `has(record.disabled) && record.disabled == true`.
-
-`sys_approval_request`'s decision levers gate on the attached `record.viewer` block and traverse, so they are guarded at the leaf (`has(record.viewer) && has(record.viewer.can_act) && record.viewer.can_act == true`). Measured, that is the minimal safe form for a nested read: the canonical `has(x) && x != null` conjunction still faults when the block is present but the flag is absent or null, while a leaf `has()` subsumes the parent `!= null` half. Their intended fail-closed behaviour is unchanged — it is now a real `false` instead of an evaluation fault.
diff --git a/.changeset/actions-door-demotes-author-codes.md b/.changeset/actions-door-demotes-author-codes.md
deleted file mode 100644
index 198e9e88af..0000000000
--- a/.changeset/actions-door-demotes-author-codes.md
+++ /dev/null
@@ -1,41 +0,0 @@
----
-"@objectstack/spec": minor
-"@objectstack/types": minor
-"@objectstack/runtime": minor
----
-
-`error.code` is a closed vocabulary at every door (#9106, maintainer ruling
-2026-08-16): the runtime dispatcher's thrown-error exits
-(`HttpDispatcher.errorFromThrown`, `dispatcher-plugin`'s `errorResponseBase`,
-`endpoint-executor`'s `endpointErrorAnswer` — the actions door among them) now
-serve the narrowed `code` the shared resolver (`resolveThrownHttpError`,
-`@objectstack/types`) has always computed, exactly as the REST door has since
-#8016. A thrown code that is not a member of `StandardErrorCode ∪
-ERROR_CODE_LEDGER` no longer reaches `error.code`.
-
-It is not dropped: `ApiErrorSchema` declares a new optional `declaredCode`
-field — the open, author-authored channel — and the demoted spelling rides
-there. Presence means demotion: the field is absent whenever the producer's
-code is a vocabulary member (it is already in `error.code`) or the producer
-declared none. The #7867 sandbox passthrough capability is preserved — a
-metadata app's own thrown `.code` still crosses the QuickJS boundary and still
-reaches the wire.
-
-For a metadata app that throws its own code (e.g.
-`Object.assign(new Error('pick another'), { code: 'DUPLICATE' })` in an action
-body) and reads it back from an actions-door failure:
-
-- FROM: `error.code === 'DUPLICATE'`
-- TO: `error.code` is the closed member the status derives (e.g.
- `VALIDATION_ERROR` on a 400) and `error.declaredCode === 'DUPLICATE'`.
- One-line fix: branch on `error.declaredCode` for app-specific spellings;
- branch on `error.code` for platform conditions.
-
-Platform producers are unaffected: every registered code reaches `error.code`
-verbatim, as before (post-#8846 the dispatcher-vocabulary gate holds that set
-registered). Measured before landing (the ruling's binding precondition): no
-existing consumer of the actions door branches on author-authored strings in
-`error.code`.
-
-`@objectstack/types` adds `demotedDeclaredCode(thrown)` — the one definition of
-"which spelling a boundary surfaces beside the closed `code`".
diff --git a/.changeset/actions-flow-dispatch-status-table.md b/.changeset/actions-flow-dispatch-status-table.md
deleted file mode 100644
index b13cc27dfa..0000000000
--- a/.changeset/actions-flow-dispatch-status-table.md
+++ /dev/null
@@ -1,22 +0,0 @@
----
-'@objectstack/runtime': minor
----
-
-`POST /api/v1/actions/:object/:action` answers the flow-dispatch status table instead of one blanket `400 FLOW_FAILED` (#9446).
-
-**What a caller sees differently.** A `type: 'flow'` action whose dispatch is REFUSED no longer reports a failed run. Three answers changed:
-
-| the flow behind the action | before | now |
-|---|---|---|
-| is not registered | `400` `FLOW_FAILED` | `404` `RESOURCE_NOT_FOUND` |
-| is switched off | `400` `FLOW_FAILED` | `409` `FLOW_DISABLED` |
-| has no `start` node | `400` `FLOW_FAILED` | `422` `FLOW_NO_START_NODE` |
-| ran and was rejected | `400` `FLOW_FAILED` | `400` `FLOW_FAILED` (unchanged) |
-
-These are the same four rows `POST /api/v1/automation/:name/trigger` has answered since #9378 + #9415, and they now come from one shared definition both doors read, so the two cannot drift apart again.
-
-**Behaviourally breaking for a caller that branches on the status or the code.** Every one of these was a `400` before, so a caller treating `400` as "the run failed" was being told something false in three of the four cases: nothing had dispatched and no node had executed. A client that lumps all four together keeps working — they are all still refusals, all still `success: false` with no inner envelope — but one that reports "the flow failed" on a `400` should now distinguish. **Retry semantics differ per row**, which is the practical reason to: `409 FLOW_DISABLED` is reversible operational state (enable the flow and the identical request succeeds), while `404` and `422 FLOW_NO_START_NODE` are authoring defects that no retry fixes. `400 FLOW_FAILED` remains terminal, exactly as the console already treats it.
-
-**Unchanged on purpose.** A successful run still answers `200` with the single `data` wrap (#3962). The `400 FLOW_FAILED` message keeps its existing wording (`Flow '' failed: …`), which names the flow the action dispatches — the trigger route's URL carries that name and this route's does not. A `success: false` result the automation engine did not classify still refuses with `400 FLOW_FAILED` rather than falling back to `200 {success:true,data:{success:false}}` — the double envelope #3962 removed from this route.
-
-**Not in scope.** Declared endpoints (`type: 'flow'` endpoints, `endpoint-executor.ts`) still answer `200` for every outcome. That door converges in its own change (#9462), where the envelope flip is a breaking change for consumers of the current double envelope and is sequenced against them.
diff --git a/.changeset/admin-export-wildcard-removed.md b/.changeset/admin-export-wildcard-removed.md
deleted file mode 100644
index 261554017f..0000000000
--- a/.changeset/admin-export-wildcard-removed.md
+++ /dev/null
@@ -1,80 +0,0 @@
----
-"@objectstack/plugin-security": minor
-"@objectstack/spec": minor
----
-
-fix(security): the shipped admin permission sets no longer grant export on the `*` wildcard (#8681)
-
-
-
-**BREAKING for any deployment whose administrators export today.** Landing after
-the v17.0.0 cut, so it ships as `minor` under the lockstep launch-window
-convention; the migration prescription is registered under protocol major 18,
-where `objectstack migrate meta` users will look.
-
-`admin_full_access`, `organization_admin` and the derived
-`organization_admin_no_bypass` shipped `objects['*'].allowExport = true`. That
-single line made the 17.0 export axis **undeniable** for anyone holding an admin
-set: an application could declare an object exportable by nobody, ship it, and
-the platform would export it anyway.
-
-Measured on 17.0.0 GA — 40 export probes, 5 principals, 8 objects, real Bearer
-tokens — an org owner exported `crm_quote` (9 rows), `crm_campaign` (13) and
-`crm_task` (15) with 200 and full data. No app permission set granted export on
-any of the three, and the app had no way to say no:
-
-1. the wildcard lives in code-package metadata, so editing it answers
- `403 [not_overridable] Metadata item 'permission/admin_full_access' is
- provided by a code package`;
-2. the org admin holds no app-authored permission set, so there is nowhere to
- author the per-object `allowExport: false` that would otherwise have won.
-
-**This was never a gate defect.** The same run proves the export gate exact for
-every other principal: a token refused on one object exports another on the same
-route, granting `allowExport` at runtime flips 403 to 200, and revoking it flips
-it back. A plain member carrying `'*': { allowExport: true }` exported too — the
-wildcard was simply doing what it said. What changes is that the platform stops
-shipping that grant.
-
-This is #5491 applied to the export axis. That change removed `member_default`'s
-CRUD wildcard because a wildcard in a set every principal resolves is not a
-default but a floor no app can get under; the export wildcard survived by
-omission rather than by decision, one tier up.
-
-**Migration — grant `allowExport` explicitly in an app permission set where
-admin export is intended.** There is no automatic replacement, deliberately:
-which principals may take a bulk machine-readable copy of a table is the
-segregation-of-duties judgement the axis exists to make explicit.
-
-```ts
-// In YOUR app's permission set — not a platform set (those are not overridable).
-{
- name: 'system_admin',
- objects: {
- crm_account: { allowRead: true, allowExport: true }, // export intended
- crm_quote: { allowRead: true }, // export withheld
- },
-}
-```
-
-⚠️ **Nothing fails at parse time, and the shipped sets are re-seeded on
-upgrade.** A deployment that upgrades without editing anything is valid metadata
-whose administrators have quietly lost export on every object no app set names —
-the first sign is a support report, not an error. Verify behaviourally: sign in
-as an org owner and call `GET /api/v1/data/