β€”

Add your own software to visualize

See drift, staleness, and CVEs calculated against what you actually run, not a generic search.

or scan a machine: pip install releasetrain-inventory

System Architecture

An open-source pipeline for tracking software releases, security advisories, and community signals. The goal is to continuously poll 20+ vendor feeds, package registries, and developer forums; normalise every event into one of two MongoDB collections (versions or reddit); stamp each document with a structured identifier; and expose the full corpus through a typed REST API and a static browser client. No proprietary transforms, no vendor lock-in.

Each section is collapsed by default. Click any heading to expand.

Platform Overview

Six subsystems, two MongoDB collections, one REST API. Arrows show the primary data and control paths.

graph TB subgraph SOURCES ["External Sources Β· 20+ feeds"] SRC1["Security Feeds
NVD Β· CVE Β· Patch Tuesday Β· Ubuntu Β· Debian"] SRC2["Browser Releases
Chrome Β· Firefox Β· Safari"] SRC3["Runtimes and Platforms
Node.js Β· Python Β· Linux Kernel Β· Eclipse"] SRC4["Community Signals
Reddit 20+ subreddits Β· Stack Overflow"] end subgraph BOT ["releasetrain-bot Β· Python collector fleet"] BOT_V["Version pollers
15+ release scrapers"] BOT_R["Reddit scraper
PRAW"] BOT_ML["ML labeller
isUpdateRelated Β· positiveScore"] end subgraph STORE ["MongoDB Atlas"] COL_V[("versions")] COL_R[("reddit")] end subgraph SERVER ["releasetrain-server Β· Node and Express"] RT_V["/api/v/*"] RT_R["/api/reddit/*"] RT_AGG["/api/aggregate/*"] end subgraph CLIENT ["releasetrain-client Β· Static JS and HTML"] UI_FEED["Feed and Dashboard"] UI_CVE["CVE View"] UI_GRAPH["Component Graph"] UI_OTHER["Docs Β· Label Β· Archive views"] end subgraph CHAT ["releasetrain-chat Β· Streamlit RAG"] CHAT_EMB["Embeddings
text encoder"] CHAT_LLM["LLM Inference
DigitalOcean GenAI"] CHAT_UI["Chat Interface"] end SRC1 & SRC2 & SRC3 --> BOT_V --> COL_V SRC4 --> BOT_R --> BOT_ML --> COL_R COL_V --> RT_V & RT_AGG COL_R --> RT_R RT_V --> UI_FEED & UI_CVE & UI_GRAPH RT_R --> UI_FEED COL_V & COL_R --> CHAT_EMB --> CHAT_LLM --> CHAT_UI classDef ext fill:#eff6ff,stroke:#cbd5e1,color:#0f172a classDef bot fill:#fffbeb,stroke:#fde68a,color:#0f172a classDef db fill:#f1f5f9,stroke:#e2e8f0,color:#0f172a classDef api fill:#f1f5f9,stroke:#e2e8f0,color:#0f172a classDef ui fill:#f8fafc,stroke:#e2e8f0,color:#0f172a classDef chat fill:#fef2f2,stroke:#fca5a5,color:#0f172a class SRC1,SRC2,SRC3,SRC4 ext class BOT_V,BOT_R,BOT_ML bot class COL_V,COL_R db class RT_V,RT_R,RT_AGG api class UI_FEED,UI_CVE,UI_GRAPH,UI_OTHER ui class CHAT_EMB,CHAT_LLM,CHAT_UI chat
Source Coverage: 20+ release and community feeds

Security and vendor feeds write to the versions collection. Community signals write to the reddit collection.

flowchart LR subgraph SEC ["Security Β· 9 sources"] S1["NVD and CVE"] S2["Microsoft Patch Tuesday"] S3["Ubuntu Security Notices"] S4["Debian Advisories"] S5["Android Security Bulletins"] S6["Apple Security Updates"] S7["VMware Advisories"] S8["Oracle Critical Patches"] S9["Samsung Security"] end subgraph BROWS ["Browsers Β· 3 sources"] B1["Google Chrome Stable"] B2["Mozilla Firefox"] B3["Safari Release Notes"] end subgraph RUN ["Runtimes Β· 6 sources"] R1["Node.js"] R2["Python"] R3["Linux Kernel Stable"] R4["Eclipse Foundation"] R5["Android Studio"] R6["Let's Encrypt"] end subgraph COMM ["Community Β· 5 sources"] C1["Reddit 20+ subreddits"] C2["Stack Overflow Tags"] C3["GitHub Security Advisories"] C4["npm Advisories"] C5["PyPI Feed"] end DB_V[("versions")] DB_R[("reddit")] SEC --> DB_V BROWS --> DB_V RUN --> DB_V COMM --> DB_R classDef db fill:#f1f5f9,stroke:#e2e8f0,color:#0f172a class DB_V,DB_R db
Data Ingestion and Enrichment Pipeline

Raw signals pass through four stages before landing in MongoDB.

flowchart LR subgraph COLLECT ["Collect"] C1["Poll vendor feeds
and release pages"] C2["Scrape Reddit
via PRAW"] end subgraph NORM ["Normalise"] N1["Deduplicate
by redditId or versionId"] N2["Parse semver
and release channel"] end subgraph ENRICH ["Enrich"] E1["Predict isUpdateRelated"] E2["Predict positiveScore"] E3["Stamp versionId
YYYYMMDD Β· name Β· version"] E4["Add search tags
and timestamps"] end subgraph STORE ["Store"] S1[("versions")] S2[("reddit")] end C1 --> N2 --> E3 --> E4 --> S1 C2 --> N1 --> E1 --> E2 --> S2 classDef db fill:#f1f5f9,stroke:#e2e8f0,color:#0f172a class S1,S2 db
API Topology: REST route groups and MongoDB dependencies

All REST route groups and the MongoDB collection each reads or writes.

graph LR CL(["Client or API consumer"]) subgraph API ["REST API Β· releasetrain.io"] subgraph VER ["/api/v/* Β· Versions"] V1["GET search Β· latest10 Β· count
fc Β· fcc Β· stats/by-month"] V2["POST and PUT versions"] end subgraph RED ["/api/reddit/* Β· Reddit"] R1["GET reddit Β· by-subreddit
questions Β· positive Β· cve Β· stats"] R2["POST and PUT reddit"] end subgraph AGG ["/api/aggregate/* Β· Aggregations"] A1["GET v/typeBreakdown Β· v/updateTypeCount
v/classificationSummary Β· v/versionCountByDay"] A2["GET reddit/summary Β· reddit/count
reddit/bySource Β· reddit/bySubreddit Β· reddit/countByDay"] end subgraph SYS ["System"] S1["GET health Β· meta
test/all Β· test/endpoints"] end end DB_V[("versions")] DB_R[("reddit")] CL --> VER & RED & AGG & SYS VER --> DB_V AGG --> DB_V RED --> DB_R classDef db fill:#f1f5f9,stroke:#e2e8f0,color:#0f172a class DB_V,DB_R db
Frontend Views: releasetrain-client

One self-contained index.html served as a static file. Views switch client-side via a ?view= parameter; no per-view page loads. Click a view to expand details.

Feed
Default view. Release cards grouped by component, quick filters, and a sidebar activity chart. Consumes /api/v/search, /api/reddit and the /api/aggregate/* per-day endpoints. Vanilla JS; Chart.js is lazy-loaded from a CDN for the activity chart.
CVE View
CVE post timeline with an NVD pipeline banner showing distribution across CVE lifecycle stages (Reserved, Awaiting Analysis, Analyzed, Published). Filters by source, date range and CVE ID pattern.
Graph View
Force-directed graph (vis-network, lazy-loaded from a CDN). Component hub nodes with their releases and Reddit / Stack Overflow posts as satellites; edge length encodes recency. Edgeless nodes are dropped from the canvas and listed in the sidebar.
Arch View
PlantUML diagram, encoded client-side (pako) and rendered as SVG by the public plantuml.com server. Components are stacked in tiers: hypervisor base layer (versionProductType === "Hypervisor"), then OS, then applications, with an "Upgrade now" cluster hoisted out for anything carrying a CVE or a major-version gap. A table mode lists the same data as a drift report.
Risk Report
Community risk summary: components ranked by recent high-risk Reddit and Stack Overflow discussion, with per-component release context.
Docs
Full API reference with collapsible endpoint cards, curl copy buttons and live test links. System architecture diagrams rendered via Mermaid v10, lazy-loaded from a CDN (this section).
Account
Device-local inventory of installed versions and saved searches, stored in localStorage. Feeds the Arch view's installed-vs-latest drift annotations.
Changelog
Client change history. The version is single-sourced from package.json and stamped into the page at build time.
AI Chat: RAG pipeline with vector search and LLM inference

A Streamlit application (releasetrain-chat) that wraps a retrieval-augmented generation pipeline over both MongoDB collections. At startup it encodes release notes and community posts into a FAISS vector index. At query time it retrieves the top-k most similar documents by cosine similarity, optionally reranked by a cross-encoder, then injects them into an LLM prompt served via DigitalOcean GenAI (Llama 3 or Mistral). Responses include source citations derived from the retrieved documents.

flowchart TD USER(["User question"]) subgraph RAG ["RAG Pipeline Β· releasetrain-chat Β· Streamlit"] Q["Query encoder
sentence-transformers"] RET["Vector retriever
top k similarity search"] RANK["Reranker
cross encoder scoring"] AUG["Prompt augmenter
release context injection"] LLM["LLM Inference
DigitalOcean GenAI Platform
Llama 3 Β· Mistral"] end subgraph CORPUS ["Knowledge Corpus"] DB_V[("versions")] DB_R[("reddit")] IDX[("FAISS vector index")] end USER --> Q --> RET DB_V & DB_R --> IDX IDX --> RET --> RANK --> AUG --> LLM --> ANS(["Grounded answer
with source citations"]) classDef db fill:#f1f5f9,stroke:#e2e8f0,color:#0f172a classDef chat fill:#fef2f2,stroke:#fca5a5,color:#0f172a class DB_V,DB_R,IDX db class Q,RET,RANK,AUG,LLM chat

Embedding model

sentence-transformers all-MiniLM-L6-v2 or OpenAI text-embedding-3-small. Encodes release notes and Reddit posts into dense 384 or 1536 dimensional vectors indexed in FAISS.

LLM

Served via DigitalOcean GenAI Platform. Llama 3 70B or Mistral 7B receives an augmented prompt containing retrieved release context and returns a grounded, cited answer.

Vector store

FAISS in memory index rebuilt at startup from both collections. Top k cosine similarity retrieval with configurable k (default 10 documents per query).

Retrieval strategy

Hybrid: dense vector search over embeddings plus sparse BM25 keyword match over version IDs and CVE strings. Results merged and reranked before prompt injection.

Request Lifecycle: Version search call path

Canonical read path through the stack for a version search call.

sequenceDiagram autonumber actor User participant Client as releasetrain-client participant API as Express REST API participant DB as MongoDB Atlas User->>Client: Search for a component Client->>API: GET /api/v/search with q and limit params API->>API: Validate params and build filter API->>DB: versions.find().sort().skip().limit() DB-->>API: version documents API->>DB: versions.countDocuments() DB-->>API: totalCount API-->>Client: 200 OK with data and totalCount Client-->>User: Rendered results Note over API,DB: Scoped to rolling 2 year window
unless start or end param overrides
↑ Back to top

Health & meta

Endpoints collapsed by default, ordered method-first then route.

GET/api/health

Lightweight health check. No database query.

curl "https://releasetrain.io/api/health"
{ "ok": true, "service": "releasetrain", "serverTime": "2026-03-25T17:00:00.000Z" }
GET/api/meta

Diagnostics route that pings the database and reports collection names.

curl "https://releasetrain.io/api/meta"
{ "ok": true, "dbName": "releasetrain", "ping": { "ok": 1 }, "collections": { "versions": "versions", "users": "users" } }
↑ Back to top

Authentication

Auth at a glance

Stateless JWT auth. Register or log in to get a token, then send it as Authorization: Bearer <token> on any endpoint tagged requires login or admin only. Tokens expire after 7 days.

Endpoints collapsed by default, ordered method-first then route.

POST/api/auth/login

Verify email and password, issue a 7-day JWT, and record lastLoginAt/previousLoginAt on the user document.

curl -X POST "https://releasetrain.io/api/auth/login" -H "Content-Type: application/json" -d '{"email":"user@example.com","password":"correcthorsebattery"}'
{ "success": true, "token": "eyJhbGciOi...", "user": { "id": "660c38fce3cba9423e4f8f23", "email": "user@example.com", "role": "user", "name": null, "orgs": [], "inventory": [] } }
POST/api/auth/logout

No-op for symmetry: JWTs are stateless, so signing out is purely a client-side token discard. Included so a client can call a real endpoint on sign-out instead of special-casing it.

requires login
curl -X POST "https://releasetrain.io/api/auth/logout" -H "Authorization: Bearer YOUR_JWT_TOKEN"
{ "success": true }
POST/api/auth/register

Create an account. The email domain must be an allowed real provider (Gmail, Outlook, Yahoo, iCloud, ProtonMail, AOL, etc.) or any .edu address, to keep disposable-mail signups out. Password must be at least 8 characters.

curl -X POST "https://releasetrain.io/api/auth/register" -H "Content-Type: application/json" -d '{"email":"user@example.com","password":"correcthorsebattery","name":"Ada Lovelace"}'
{ "success": true, "user": { "id": "660c38fce3cba9423e4f8f23", "email": "user@example.com", "role": "user", "name": "Ada Lovelace", "orgs": [], "inventory": [] } }
↑ Back to top

User accounts

Endpoints collapsed by default, ordered method-first then route.

DELETE/api/users/:id

Delete a user account by Mongo ObjectId.

admin only
curl -X DELETE "https://releasetrain.io/api/users/660c38fce3cba9423e4f8f23" -H "Authorization: Bearer YOUR_JWT_TOKEN"
{ "success": true }
GET/api/account/guardrails

The signed-in user's own saved per-guardrail overrides. Only ever contains keys for a guardrail that's actually tier: "optional" (see GET /api/guardrails) and that this user has explicitly set; a guardrail with no saved preference simply isn't a key here, and falls back to the admin default (that same endpoint's own effective field).

requires login
curl "https://releasetrain.io/api/account/guardrails" -H "Authorization: Bearer YOUR_JWT_TOKEN"
{ "guardrailPrefs": { "vendorCheck": false } }
GET/api/users/

Paginated list of all users, password hashes excluded.

admin onlylimit max 100page
curl "https://releasetrain.io/api/users/?limit=50&page=1" -H "Authorization: Bearer YOUR_JWT_TOKEN"
{ "total": 214, "data": [ { "_id": "660c38fce3cba9423e4f8f23", "email": "user@example.com", "role": "user", "orgs": [], "inventory": [] } ] }
GET/api/users/me

The signed-in user's own profile, password hash excluded. Any bring-your-own provider API key (Anthropic, Groq, Ollama) is returned masked, as a last-4 preview plus a set/not-set flag, never in full.

requires login
curl "https://releasetrain.io/api/users/me" -H "Authorization: Bearer YOUR_JWT_TOKEN"
{ "_id": "660c38fce3cba9423e4f8f23", "email": "user@example.com", "role": "user", "orgs": [], "inventory": [], "anthropicKeySet": false, "anthropicKeyPreview": null }
PUT/api/account/guardrails

Save the signed-in user's own per-guardrail overrides, persisted to their account (not global). Rejects with 400 if any given id is not tier: "optional" (see GET /api/guardrails): a mandatory guardrail can only be changed admin-side, via PUT /api/admin/settings. Returns the same {"guardrailPrefs"} shape reflecting what was actually saved.

requires login
curl -X PUT "https://releasetrain.io/api/account/guardrails" -H "Authorization: Bearer YOUR_JWT_TOKEN" -H "Content-Type: application/json" -d '{"guardrailPrefs":{"vendorCheck":false}}'
{ "guardrailPrefs": { "vendorCheck": false } }
PUT/api/users/:id

Update a user. A user may update their own name, password, provider API keys, orgs (max 2 alphanumeric/dash/underscore slugs) and inventory (installed-versions list, max 300 entries). Only an admin may target another user's ID or change role.

requires login
curl -X PUT "https://releasetrain.io/api/users/660c38fce3cba9423e4f8f23" -H "Authorization: Bearer YOUR_JWT_TOKEN" -H "Content-Type: application/json" -d '{"name":"Ada Lovelace","orgs":["pacific"]}'
{ "success": true }
↑ Back to top

Bookmarks

Bookmarks at a glance

A signed-in user's saved links. Each bookmark gets a random shareId at creation, letting anyone with the share link view the name/url/orgs without signing in.

Endpoints collapsed by default, ordered method-first then route.

DELETE/api/bookmarks/:id

Delete one of the signed-in user's own bookmarks.

requires login
curl -X DELETE "https://releasetrain.io/api/bookmarks/660c38fce3cba9423e4f8f23" -H "Authorization: Bearer YOUR_JWT_TOKEN"
{ "success": true }
GET/api/bookmarks/

List the signed-in user's own bookmarks, newest first, up to 100.

requires login
curl "https://releasetrain.io/api/bookmarks/" -H "Authorization: Bearer YOUR_JWT_TOKEN"
{ "data": [ { "_id": "660c38fce3cba9423e4f8f23", "name": "Chrome stable channel", "url": "https://chromereleases.googleblog.com/", "shareId": "a1b2c3d4e5f60718", "orgs": [] } ] }
GET/api/bookmarks/share/:shareId

Public lookup of a single bookmark by its share ID. Returns only name, url and orgs, no owner information.

curl "https://releasetrain.io/api/bookmarks/share/a1b2c3d4e5f60718"
{ "name": "Chrome stable channel", "url": "https://chromereleases.googleblog.com/", "orgs": [] }
POST/api/bookmarks/

Create a bookmark for the signed-in user. Requires name and url; a random shareId is generated and the user's current orgs are snapshotted onto it.

requires login
curl -X POST "https://releasetrain.io/api/bookmarks/" -H "Authorization: Bearer YOUR_JWT_TOKEN" -H "Content-Type: application/json" -d '{"name":"Chrome stable channel","url":"https://chromereleases.googleblog.com/"}'
{ "success": true, "id": "660c38fce3cba9423e4f8f23", "shareId": "a1b2c3d4e5f60718" }
PUT/api/bookmarks/:id

Rename one of the signed-in user's own bookmarks.

requires login
curl -X PUT "https://releasetrain.io/api/bookmarks/660c38fce3cba9423e4f8f23" -H "Authorization: Bearer YOUR_JWT_TOKEN" -H "Content-Type: application/json" -d '{"name":"Chrome release blog"}'
{ "success": true }
↑ Back to top

Reddit endpoints

Reddit at a glance

Ingestion, listing, subreddit filtering, update-related search, CVE text search, positive-score retrieval, monthly summaries, and single-item fetch/update. Some routes use page/limit paging; others also support cursor-based navigation.

Endpoints collapsed by default, ordered method-first then route.

GET/api/iot

Specialized Reddit view for IoT-style subreddits, with optional update-related filtering.

limitpageupdateRelated=true
curl "https://releasetrain.io/api/iot?limit=100&page=1"
GET/api/reddit

List Reddit docs, newest first. Supports page/limit, cursor paging, monthly filtering, and update-related filtering.

limitpagecursormonth=YYYYMMshowCount=true
curl "https://releasetrain.io/api/reddit?limit=25&page=1&showCount=true"
{ "data": [ { "title": "...", "created_utc": "..." } ], "totalCount": 25 }
GET/api/reddit/:redditId

Fetch a single Reddit item by Mongo ObjectId or Reddit short id.

curl "https://releasetrain.io/api/reddit/1nq0h33"
GET/api/reddit/:redditId/poll

Runs a real, billed LLM call: classifies each of the post's top-level, non-author comments as yes/no/unclear against the post's own question (its selftext, falling back to the title), and returns the tally. One batched model call per request, not one per comment.

requires loginprovider optional
curl "https://releasetrain.io/api/reddit/1nq0h33/poll" -H "Authorization: Bearer YOUR_JWT_TOKEN"
{ "question": "Anyone else seeing this after the update?", "total": 12, "yes": 7, "no": 3, "unclear": 2, "breakdown": [ { "id": "c1", "author": "user123", "body": "Yeah, same here.", "verdict": "yes" } ] }
GET/api/reddit/by-subreddit

Fetch by one or more subreddits, case-insensitive. Optional score, comment, pagination, and projection filters.

q or subredditminScoreminCommentsfieldspagelimit
curl "https://releasetrain.io/api/reddit/by-subreddit?q=programming,technology&minScore=50&limit=25"
GET/api/reddit/count

Total post count over the rolling two-year window.

curl "https://releasetrain.io/api/reddit/count"
{ "totalRedditPosts": 248 }
GET/api/reddit/meta/subreddits

Return all unique subreddits from the Reddit collection.

curl "https://releasetrain.io/api/reddit/meta/subreddits"
{ "success": true, "count": 14, "data": ["programming", "technology"] }
GET/api/reddit/query/cve

Text-search Reddit content for CVE-like strings.

qcommentsOnly=truefieldsshowCount=truelimit/page/cursor
curl "https://releasetrain.io/api/reddit/query/cve?q=CVE-&limit=25"
GET/api/reddit/query/filter

Filter Reddit docs by comment count and predicted positive score window.

minCommentsminScoremaxScorelimit
curl "https://releasetrain.io/api/reddit/query/filter?minComments=5&minScore=0.6&maxScore=0.95&limit=50"
GET/api/reddit/query/positive

Returns all Reddit docs where metadata.predicted.positiveScore > 0.5, sorted by score descending.

curl "https://releasetrain.io/api/reddit/query/positive"
{ "total": 83, "minScore": 0.5, "data": [ ... ] }
GET/api/reddit/query/questions

Return Reddit docs where metadata.predicted.isUpdateRelated is true and a question marker appears in title or author description.

where=title|description|eitherrequireTitleQuestionfieldsshowCountlimitpage
curl "https://releasetrain.io/api/reddit/query/questions?where=either&limit=25&page=1&showCount=true"
GET/api/reddit/query/questions/suggest

Typeahead over real community questions already in the corpus, extracted from post titles/selftext. No LLM call.

qlimit optional Β· default 8 Β· max 20
curl "https://releasetrain.io/api/reddit/query/questions/suggest?q=mysql&limit=5"
{ "query": "mysql", "results": [ "Anyone know if the MySQL 8.4 upgrade broke replication for others?" ] }
GET/api/reddit/query/update-related

Filter Reddit documents by the nested update-related fields under metadata.labeled and metadata.predicted.

isLabeled=true|falseisUpdateRelated=true|falselimitpage
curl "https://releasetrain.io/api/reddit/query/update-related?isLabeled=true&isUpdateRelated=true&limit=25&page=1"
GET/api/reddit/stats/by-month

Monthly counts for labeled training distribution.

startMonth=YYYYMMendMonth=YYYYMM
curl "https://releasetrain.io/api/reddit/stats/by-month?startMonth=202401&endMonth=202412"
GET/api/reddit/stats/summary

Range summary over Reddit data: total docs, risky docs, latest-update mentions, and CVE mentions.

start=YYYYMMDDend=YYYYMMDD
curl "https://releasetrain.io/api/reddit/stats/summary?start=20240101&end=20241231"
GET/api/subreddits/smoke

Simple footprint check to list distinct subreddits found in the Reddit collection.

curl "https://releasetrain.io/api/subreddits/smoke"
{ "count": 14, "items": ["programming", "technology"] }
POST/api/reddit

Insert or upsert a Reddit document by redditId.

curl -X POST "https://releasetrain.io/api/reddit" -H "Content-Type: application/json" -d '{"redditId":"1nq0h33","title":"Example","subreddit":"programming"}'
PUT/api/reddit

Replace a Reddit document while preserving the existing Mongo _id.

curl -X PUT "https://releasetrain.io/api/reddit" -H "Content-Type: application/json" -d '{"redditId":"1nq0h33","title":"Updated"}'
PUT/api/reddit/:redditId

Update a single Reddit item by ObjectId or redditId.

curl -X PUT "https://releasetrain.io/api/reddit/1nq0h33" -H "Content-Type: application/json" -d '{"title":"Retitled","score":88}'
↑ Back to top

Version endpoints

Versions at a glance

Two flavors: older convenience routes like /api/v/ and the newer /api/v/search. For steady client integration, /api/v/search is the safer path: its filters and paging model are explicit.

Endpoints collapsed by default, ordered method-first then route.

GET/api/dashboard/mltl-risk

Dashboard aggregate for documents marked as MLTL risk. Optional component filter.

q optional
curl "https://releasetrain.io/api/dashboard/mltl-risk?q=chrome,firefox"
GET/api/v/

Older convenience route: returns recent versions. Without q, a broad recent slice; with q, divides the limit across components.

q optional
curl "https://releasetrain.io/api/v/?q=chrome,firefox"
{ "versions": [ ... ] }
GET/api/v/:id

Fetch one version by Mongo ObjectId.

curl "https://releasetrain.io/api/v/660c38fce3cba9423e4f8f23"
GET/api/v/aggregate/byDate

Count how many versions were released on a specific day.

date=YYYYMMDD
curl "https://releasetrain.io/api/v/aggregate/byDate?date=20250723"
{ "success": true, "date": "20250723", "count": 42 }
GET/api/v/count

Total version count inside the rolling two-year window.

curl "https://releasetrain.io/api/v/count"
{ "totalVersions": 54210 }
GET/api/v/d/versionsByComponent

Return latest/current/CVE snapshots for one or more components.

component=name:chrome,version:118
curl "https://releasetrain.io/api/v/d/versionsByComponent?component=name:chrome,version:118"
[ { "name": "chrome", "latestVersion": { ... }, "currentVersion": { ... }, "latestCveVersion": { ... } } ]
GET/api/v/fc

Forecast the next release date for a single component.

q required
curl "https://releasetrain.io/api/v/fc?q=chrome"
[ { "component": "chrome", "releaseDate": "2026-04-07", "version": "135.0.0" } ]
GET/api/v/fcc

Forecast coinciding release dates for multiple components.

q required
curl "https://releasetrain.io/api/v/fcc?q=chrome,firefox"
GET/api/v/latest10

Latest N versions per requested component.

q requiredlimit max 100
curl "https://releasetrain.io/api/v/latest10?q=chrome,firefox&limit=10"
GET/api/v/search

Unified read-only search with filters, projections, count, and cursor paging.

qchannelisCvestart/endfieldsshowCount
curl "https://releasetrain.io/api/v/search?q=chrome,firefox&limit=50&page=1&showCount=true"

curl "https://releasetrain.io/api/v/search?q=chrome&channel=patch&isCve=true&fields=versionId,versionNumber&limit=25"
{ "data": [ { "_id": "...", "versionId": "20250217chrome1.2.3" } ], "totalCount": 314 }
GET/api/v/stats/by-month

Monthly counts grouped by month and release channel, optionally filtered to selected components.

startMonthendMonthq
curl "https://releasetrain.io/api/v/stats/by-month?startMonth=202401&endMonth=202412&q=chrome,firefox"
GET/api/v/versionId/:versionId

Fetch one version by business identifier rather than Mongo ObjectId.

curl "https://releasetrain.io/api/v/versionId/20250217chrome1.2.3"
POST/api/v

Create a version document. The server normalizes versionNumber, infers the release channel, and fills timestamps/search tags.

curl -X POST "https://releasetrain.io/api/v" -H "Content-Type: application/json" -d '{"versionProductName":"chrome","versionNumber":"124.0.1","versionReleaseDate":"20260325","versionReleaseChannel":"patch"}'
PUT/api/v/:id

Update an existing version by Mongo ObjectId.

curl -X PUT "https://releasetrain.io/api/v/660c38fce3cba9423e4f8f23" -H "Content-Type: application/json" -d '{"classification":{"componentType":["browser"]}}'
PUT/api/v/versionId/:versionId

Update an existing version by business identifier. Refreshes versionTimestampLastUpdate.

curl -X PUT "https://releasetrain.io/api/v/versionId/20250217chrome1.2.3" -H "Content-Type: application/json" -d '{"newFieldName":"newValue"}'
↑ Back to top

Component endpoints

Endpoints collapsed by default, ordered method-first then route.

GET/api/c/count

Total number of distinct components in the rolling two-year window.

curl "https://releasetrain.io/api/c/count"
{ "totalComponents": 1440 }
GET/api/c/frequency

Builds a component list from top components and those updated today.

curl "https://releasetrain.io/api/c/frequency"
{ "totalComponents": 20, "components": ["chrome", "firefox"] }
GET/api/c/name/:componentName/:versionNumber?

Fetch version history for a specific component, optionally narrowed to one exact version number.

curl "https://releasetrain.io/api/c/name/firefox"

curl "https://releasetrain.io/api/c/name/firefox/118.0.1"
GET/api/c/names

Return distinct component names in the rolling two-year window.

curl "https://releasetrain.io/api/c/names"
GET/api/c/os

Returns distinct component names classified as OS in the rolling two-year window.

curl "https://releasetrain.io/api/c/os"
GET/api/component/

Search component records. Matches product name or predicted component type.

q optionalpageNumParam
curl "https://releasetrain.io/api/component/?q=linux"
↑ Back to top

Knowledge base

Knowledge base at a glance

Lets a vendor or user publish their own release directly into the versions collection (isVendorPublished: true), alongside the bot-collected data, and attach real-world upgrade experience reports to any release.

Endpoints collapsed by default, ordered method-first then route.

GET/api/knowledge/releases

List vendor-published releases, newest first, up to 100. With no Authorization header, returns every publicly-published release; with a Bearer token, narrows to just that caller's own published releases instead.

q optional
curl "https://releasetrain.io/api/knowledge/releases?q=acme"
{ "data": [ { "versionId": "acme:widget:1.2.0", "versionProductName": "acme/widget", "versionNumber": "1.2.0", "isVendorPublished": true, "vendorNs": "acme", "publishedBy": "vendor@example.com" } ] }
POST/api/knowledge/releases

Publish a release. vendorNs must be 3 to 32 lowercase alphanumeric/hyphen characters and must not collide with an existing bot-tracked vendor name; component and version are required; channel is one of patch/minor/major/security.

requires login
curl -X POST "https://releasetrain.io/api/knowledge/releases" -H "Authorization: Bearer YOUR_JWT_TOKEN" -H "Content-Type: application/json" -d '{"vendorNs":"acme","component":"widget","version":"1.2.0","channel":"minor","notesUrl":"https://acme.example.com/notes/1.2.0"}'
{ "success": true, "id": "660c38fce3cba9423e4f8f23" }
POST/api/knowledge/releases/:id/reports

Attach an upgrade experience report to a release. outcome must be one of success/issues/upgrade; fromVersion and description are optional.

requires login
curl -X POST "https://releasetrain.io/api/knowledge/releases/660c38fce3cba9423e4f8f23/reports" -H "Authorization: Bearer YOUR_JWT_TOKEN" -H "Content-Type: application/json" -d '{"outcome":"success","fromVersion":"1.1.0","description":"Clean upgrade, no config changes needed."}'
{ "success": true }
↑ Back to top

Aggregation endpoints

Endpoints collapsed by default, ordered method-first then route.

Measure volume, gaps, and classification counts across both collections. All date params use YYYYMMDD format. Range-based endpoints default to the rolling 2-year window when start/end are omitted.

Versions Β· /api/aggregate/v/*

GET/api/aggregate/v/typeBreakdown

CVE vs release-note split plus per-channel breakdown for a date range. Omit start/end to use the rolling 2-year window.

start optionalend optional
curl "https://releasetrain.io/api/aggregate/v/typeBreakdown?start=20250101&end=20251231"
{
  "range": { "start": "20250101", "end": "20251231" },
  "total": 4821,
  "cveCount": 1203,
  "nonCveCount": 3618,
  "byChannel": { "major": 312, "minor": 1540, "patch": 1766, "cve": 1203, "other": 0 }
}
GET/api/aggregate/v/classificationSummary

Summarize security and breaking classification tags for one day.

timestamp=YYYYMMDD required
curl "https://releasetrain.io/api/aggregate/v/classificationSummary?timestamp=20250723"
{ "timestamp": "20250723", "total": 14, "classification": { "security-fix": 8, "breaking-change": 6 } }
GET/api/aggregate/v/componentTypeCount

Count classified component types for a single day.

timestamp=YYYYMMDD required
curl "https://releasetrain.io/api/aggregate/v/componentTypeCount?timestamp=20250730"
{ "timestamp": "20250730", "total": 40, "components": { "browser": 8, "os": 6 } }
GET/api/aggregate/v/cveCountByDay

Day-by-day count of CVE-channel versions over an explicit date range. Same shape as versionCountByDay, filtered to isCve: true.

start=YYYYMMDD requiredend=YYYYMMDD required
curl "https://releasetrain.io/api/aggregate/v/cveCountByDay?start=20250701&end=20250730"
{ "range": { "start": "20250701", "end": "20250730" }, "days": [ { "_id": "20250701", "count": 4 } ] }
GET/api/aggregate/v/missingFields

Sample documents where a requested field is missing, null, or empty. Useful for data quality audits.

field requiredlimit optional
curl "https://releasetrain.io/api/aggregate/v/missingFields?field=versionNumber&limit=50"
GET/api/aggregate/v/oldestTimestamp

Find the release date of the Nth newest document and compute its age in days.

count optional
curl "https://releasetrain.io/api/aggregate/v/oldestTimestamp?count=1000"
{ "oldest": "20250723", "deltaInDays": 245 }
GET/api/aggregate/v/sourceCountByType

Count one source type for a given day. sourceType: cve, major, minor, patch.

sourceType requiredtimestamp=YYYYMMDD required
curl "https://releasetrain.io/api/aggregate/v/sourceCountByType?sourceType=cve&timestamp=20250723"
{ "timestamp": "20250723", "sourceType": "cve", "count": 18 }
GET/api/aggregate/v/updateTypeCount

Count major, minor, patch, and other versions for a single day.

timestamp=YYYYMMDD required
curl "https://releasetrain.io/api/aggregate/v/updateTypeCount?timestamp=20250723"
{ "timestamp": "20250723", "major": 2, "minor": 5, "patch": 17, "other": 1 }
GET/api/aggregate/v/versionCountByDay

Day-by-day version counts over an explicit date range.

start=YYYYMMDD requiredend=YYYYMMDD required
curl "https://releasetrain.io/api/aggregate/v/versionCountByDay?start=20250701&end=20250730"
{ "range": { "start": "20250701", "end": "20250730" }, "days": [{ "_id": "20250701", "count": 12 }] }

Community Β· /api/aggregate/reddit/*

GET/api/aggregate/reddit/summary

Full overview in one call: totals, Reddit vs Stack Overflow split, top subreddits/components, and score stats. Omit start/end for the rolling 2-year window.

start optionalend optionaltopN optional Β· default 10
curl "https://releasetrain.io/api/aggregate/reddit/summary?topN=5"
{
  "range": { "start": "20240518", "end": "20260518" },
  "total": 28340,
  "bySource": { "reddit": 21050, "stackoverflow": 7290 },
  "topSubreddits": [{ "_id": "android", "count": 4120 }, { "_id": "chrome", "count": 2980 }],
  "score": { "avg": 14.3, "max": 4821, "totalWithPositiveScore": 19204 }
}
GET/api/aggregate/reddit/count

Total post count plus Reddit vs Stack Overflow vs Server Fault split for a date range.

start optionalend optional
curl "https://releasetrain.io/api/aggregate/reddit/count?start=20250101&end=20251231"
{ "range": { "start": "20250101", "end": "20251231" }, "total": 14820, "redditCount": 11340, "stackoverflowCount": 3070, "serverfaultCount": 410 }
GET/api/aggregate/reddit/bySource

Counts grouped by source field. Documents without a source field are counted as reddit.

start optionalend optional
curl "https://releasetrain.io/api/aggregate/reddit/bySource"
{ "range": { "start": "20240518", "end": "20260518" }, "total": 28340, "sources": { "reddit": 21050, "stackoverflow": 6420, "serverfault": 870 } }
GET/api/aggregate/reddit/bySubreddit

Top subreddits or Stack Overflow components by post count, with average score. Filter by source to compare communities.

start optionalend optionallimit optional Β· default 20 Β· max 100source optional Β· reddit | stackoverflow | serverfault
curl "https://releasetrain.io/api/aggregate/reddit/bySubreddit?limit=5&source=reddit"
{
  "range": { "start": "20240518", "end": "20260518" },
  "source": "reddit", "limit": 5,
  "subreddits": [{ "_id": "android", "count": 4120, "avgScore": 18.4 }]
}
GET/api/aggregate/reddit/countByDay

Post count per day. Same shape as /api/aggregate/v/versionCountByDay. Filter by source to compare Reddit vs Stack Overflow ingestion cadence.

start=YYYYMMDD requiredend=YYYYMMDD requiredsource optional Β· reddit | stackoverflow
curl "https://releasetrain.io/api/aggregate/reddit/countByDay?start=20250701&end=20250730&source=stackoverflow"
{ "range": { "start": "20250701", "end": "20250730" }, "source": "stackoverflow", "days": [{ "_id": "20250701", "count": 8 }] }
↑ Back to top

Search events

Search events at a glance

Tracks what people search and ask, for the admin panel's activity views and for surfacing trending queries. Both a plain vendor/component search and a real /api/ask question land in the same search_events collection, tagged by kind.

Endpoints collapsed by default, ordered method-first then route.

GET/api/events/search

Recent search/ask events, newest first.

admin onlylimit optional Β· default 200 Β· max 1000
curl "https://releasetrain.io/api/events/search?limit=100" -H "Authorization: Bearer YOUR_JWT_TOKEN"
{ "data": [ { "query": "chrome", "userId": "660c38fce3cba9423e4f8f23", "kind": "vendor", "timestamp": "2026-03-25T17:00:00.000Z" } ] }
GET/api/events/search/top

Top N most-searched queries in the last 24 hours.

n optional Β· default 3 Β· max 10
curl "https://releasetrain.io/api/events/search/top?n=5"
{ "data": [ { "query": "chrome", "count": 42 }, { "query": "firefox", "count": 18 } ] }
POST/api/events/search

Log a vendor/component search. Anonymous if no bearer token is sent; attributed to the caller's user ID otherwise.

curl -X POST "https://releasetrain.io/api/events/search" -H "Content-Type: application/json" -d '{"query":"chrome"}'
{ "ok": true }
↑ Back to top

Admin

Admin at a glance

Operational and moderation endpoints for the admin dashboard: bot freshness (plus its per-bot cadence thresholds), data quality attribution, MongoDB Atlas storage headroom, vendor-catalog alias curation and manual gap-fill, and a generic runtime settings store shared by the Ask pipeline defaults, the global rate limit, the registration email allowlist, nav-view visibility, and the eval tools' access levels.

Endpoints collapsed by default, ordered method-first then route.

DELETE/api/admin/vendor-aliases/:id

Remove a vendor alias by Mongo ObjectId.

admin only
curl -X DELETE "https://releasetrain.io/api/admin/vendor-aliases/660c38fce3cba9423e4f8f23" -H "Authorization: Bearer YOUR_JWT_TOKEN"
{ "ok": true }
GET/api/admin/bot-cadence

Each collector bot's default expected-update cadence (in days, the same values /api/admin/bot-health checks against), plus any admin-set override that replaces a bot's default. The System overview panel's Bot health card always reflects the effective value (override if set, else default).

admin only
curl "https://releasetrain.io/api/admin/bot-cadence" -H "Authorization: Bearer YOUR_JWT_TOKEN"
{ "defaults": { "chrome.py": 21, "firefox.py": 21, "mysql.py": 120 }, "overrides": { "mysql.py": 90 } }
GET/api/admin/bot-health

Checks how recently each collector bot has actually written new data, against a per-bot expected cadence (e.g. Chrome/Firefox every 21 days, MySQL every 120). Flags any bot past its cadence as stale.

admin only
curl "https://releasetrain.io/api/admin/bot-health" -H "Authorization: Bearer YOUR_JWT_TOKEN"
{ "checkedAt": "2026-03-25T17:00:00.000Z", "stale": [ { "bot": "mysql.py", "lastSeen": "2025-11-01", "ageDays": 144, "maxDays": 120 } ], "healthy": [ { "bot": "chrome.py", "lastSeen": "2026-03-24", "ageDays": 1, "maxDays": 21 } ], "noData": [] }
GET/api/admin/overview

Bundles bot health, source attribution, storage usage, top-line collection counts, user growth, and search/ask query volume into one response, so the admin dashboard's first screen is a single request.

admin only
curl "https://releasetrain.io/api/admin/overview" -H "Authorization: Bearer YOUR_JWT_TOKEN"
{
  "checkedAt": "2026-03-25T17:00:00.000Z",
  "botHealth": { "stale": [], "healthy": [ "..." ], "noData": [] },
  "sourceAttribution": { "total": 54210, "unknown": 812, "missing": 0, "pct": 1.5 },
  "storage": { "storageMb": 210.4, "dataMb": 180.2, "indexMb": 22.1, "limitMb": 512, "pct": 0.411 },
  "counts": { "versionsTotal": 54210, "cveTotal": 12030, "releaseNotesTotal": 42180, "redditTotal": 21050, "stackoverflowTotal": 7290 },
  "users": { "total": 214, "newLast7Days": 6, "newSinceLastLogin": 2 },
  "queries": { "total": 8340, "last7Days": 412 },
  "botGapLog": { "total": 18, "success": 11, "recent": [ "..." ] }
}
GET/api/admin/settings

Current values of every admin-tunable runtime setting: the Ask pipeline defaults, the global per-IP rate limit (plus a separate, higher adminRateLimitPerMinute ceiling for a request whose own JWT has role: "admin"), the registration email domain allowlist, which nav views are visible, each eval tool's access level, how many real questions a signed-out visitor may ask per day before POST /api/ask requires sign-in (anonymousAskEnabled/anonymousAskLimit; a limit of 0, or the toggle off, both reproduce always requiring sign-in), and the guardrails registry (every deterministic safety/correctness check applied to Ask answers, each with its tier of "mandatory" or "optional" and its current admin-set enabled value; see the public GET /api/guardrails below for the per-caller effective view of the same list).

admin only
curl "https://releasetrain.io/api/admin/settings" -H "Authorization: Bearer YOUR_JWT_TOKEN"
{ "askRecentWindowDays": 14, "askDefaultPreset": "auto", "askDefaultProvider": "ollama", "askDefaultSize": "medium", "rateLimitPerMinute": 120, "allowedEmailDomains": "gmail.com,outlook.com", "viewGraphVisible": true, "viewDocsVisible": true, "evalRewriterAccess": "admin", "evalEvaluatorAccess": "admin", "evalOrchestratorAccess": "admin", "anonymousAskEnabled": true, "anonymousAskLimit": 3, "guardrails": [ { "id": "toolResultInjectionScan", "tier": "mandatory", "label": "Scan retrieved content for prompt injection", "description": "Flags tool results that try to redirect the model's own instructions before they reach it.", "enabled": true }, { "id": "vendorCheck", "tier": "optional", "label": "Require a resolvable vendor/product", "description": "Declines outright if the question names no vendor/product this system tracks.", "enabled": true } ] }
GET/api/admin/source-attribution

What fraction of the versions collection has no confident sourceBot attribution ("unknown" or missing entirely). A rising percentage signals a bot's source-inference rule needs updating.

admin only
curl "https://releasetrain.io/api/admin/source-attribution" -H "Authorization: Bearer YOUR_JWT_TOKEN"
{ "total": 54210, "unknown": 780, "missing": 32, "pct": 1.5, "byBot": [ { "_id": "chrome.py", "count": 4210 }, { "_id": "unknown", "count": 780 } ] }
GET/api/admin/storage

MongoDB Atlas storage/data/index size against the M0 free-tier's 512MB shared cap.

admin only
curl "https://releasetrain.io/api/admin/storage" -H "Authorization: Bearer YOUR_JWT_TOKEN"
{ "storageMb": 210.4, "dataMb": 180.2, "indexMb": 22.1, "limitMb": 512, "pct": 0.411, "collections": 8, "objects": 1204830 }
GET/api/admin/vendor-aliases

Every manually-curated vendor alias, correcting or adding a vendor name the automatic catalog (built from tracked release data and Reddit subreddit names) doesn't resolve on its own.

admin only
curl "https://releasetrain.io/api/admin/vendor-aliases" -H "Authorization: Bearer YOUR_JWT_TOKEN"
{ "data": [ { "_id": "660c38fce3cba9423e4f8f23", "alias": "ada", "canonicalName": "Ada", "createdAt": "2026-09-15T17:00:00.000Z" } ] }
GET/api/views/visibility

Public: which nav-menu views are currently enabled, so a signed-out visitor's page load can hide a disabled view's link too. home and users can't be hidden by design.

curl "https://releasetrain.io/api/views/visibility"
{ "viewGraphVisible": true, "viewArchVisible": true, "viewCveVisible": true, "viewDashboardVisible": true, "viewDocsVisible": true, "viewChangelogVisible": true, "viewAckVisible": true, "viewNetworkVisible": true, "viewEvalRewriterVisible": true, "viewEvalEvaluatorVisible": true, "viewEvalOrchestratorVisible": true }
POST/api/admin/vendor-aliases

Add a vendor alias mapping one alternate spelling/name to its canonical name.

admin only
curl -X POST "https://releasetrain.io/api/admin/vendor-aliases" -H "Authorization: Bearer YOUR_JWT_TOKEN" -H "Content-Type: application/json" -d '{"alias":"ada","canonicalName":"Ada"}'
{ "data": { "_id": "660c38fce3cba9423e4f8f23", "alias": "ada", "canonicalName": "Ada", "createdAt": "2026-09-15T17:00:00.000Z" } }
POST/api/admin/vendor-gap-fill

Manually runs the same automatic-catalog gap-fill a bot's own fallback triggers for a real, web-verified vendor with zero tracked evidence (see the botGapLog field on GET /api/admin/overview). The attempt is logged the same as an automatic one, so it also shows up in that response's botGapLog.recent list.

admin only
curl -X POST "https://releasetrain.io/api/admin/vendor-gap-fill" -H "Authorization: Bearer YOUR_JWT_TOKEN" -H "Content-Type: application/json" -d '{"vendorName":"ada"}'
{ "success": true }
PUT/api/admin/bot-cadence

Set (or clear) one bot's cadence override. maxDays is a number from 1-365, or null to remove the override and fall back to that bot's default. Applies immediately, no restart needed, and is picked up by /api/admin/bot-health's next check.

admin only
curl -X PUT "https://releasetrain.io/api/admin/bot-cadence" -H "Authorization: Bearer YOUR_JWT_TOKEN" -H "Content-Type: application/json" -d '{"bot":"mysql.py","maxDays":90}'
{ "defaults": { "chrome.py": 21, "firefox.py": 21, "mysql.py": 120 }, "overrides": { "mysql.py": 90 } }
PUT/api/admin/settings

Patch one or more runtime settings. Applies immediately, no restart needed, and persists to the settings collection. Unrecognized keys are ignored; each known value is validated/clamped (e.g. askRecentWindowDays to 1-90, rateLimitPerMinute to 10-2000, anonymousAskLimit to 0-50) before being applied and returned. allowedEmailDomains takes a comma-separated string; any .edu (or .edu.<country>) address is always allowed regardless of this list. guardrails takes an array of {"id","enabled"} patches merged into the existing registry by id; an unknown id is ignored. The response always echoes back the full merged settings object, including the full updated guardrails array.

admin only
curl -X PUT "https://releasetrain.io/api/admin/settings" -H "Authorization: Bearer YOUR_JWT_TOKEN" -H "Content-Type: application/json" -d '{"askRecentWindowDays":30,"rateLimitPerMinute":200,"allowedEmailDomains":"gmail.com,outlook.com","guardrails":[{"id":"vendorCheck","enabled":false}]}'
{ "askRecentWindowDays": 30, "askDefaultPreset": "auto", "rateLimitPerMinute": 200, "allowedEmailDomains": "gmail.com,outlook.com", "evalRewriterAccess": "auth", "evalEvaluatorAccess": "admin", "evalOrchestratorAccess": "admin", "guardrails": [ { "id": "vendorCheck", "tier": "optional", "label": "Require a resolvable vendor/product", "description": "Declines outright if the question names no vendor/product this system tracks.", "enabled": false } ] }
↑ Back to top

Test & discovery endpoints

Endpoints collapsed by default, ordered method-first then route.

GET/api/test/all

Runs a built-in suite of GET requests against selected routes and returns status plus payload samples.

curl "https://releasetrain.io/api/test/all"
{ "totalGET": 11, "results": [ { "method": "GET", "path": "/api/v?q=chrome,firefox", "status": 200, "success": true } ] }
GET/api/test/endpoints

Enumerates all registered routes and flags duplicates.

curl "https://releasetrain.io/api/test/endpoints"
{ "totalEndpoints": 30, "endpoints": [ { "methods": ["GET"], "path": "/api/health" } ] }
GET/api/test/endpoints/html

HTML view of discovered GET endpoints with generated example URLs and sample outputs.

curl "https://releasetrain.io/api/test/endpoints/html"
↑ Back to top

Ask (AI Q&A)

Ask at a glance

Retrieval-augmented Q&A over the same versions/reddit corpus the rest of the API reads. A plain vendor/category name (e.g. "chrome") short-circuits to a document lookup with no model call and no sign-in required; a real question streams back live progress over Server-Sent Events and requires sign-in, since each one is a real, billed LLM call.

Which path a question actually takes: intent decides it first, then, for everything that isn't declined or a comparison, the preset's own architecture decides whether four roles run as genuinely separate model calls or one continuous tool-use loop.

flowchart LR Q["User question"] --> INTENT{"Classify
intent"} INTENT -->|"opinion"| DECLINE["Declined
no retrieval"] INTENT -->|"comparison"| CMP["Fixed evidence gather
per side, no agents"] CMP --> CMPANS(["Answer"]) INTENT -->|"version Β· cve Β· patch Β· general"| ARCH{"Architecture"} ARCH -->|"single-agent Β· buggy Β· fixed"| LOOP["One continuous
tool-use loop"] LOOP --> LOOPANS(["Answer
deterministic version fix"]) ARCH -->|"delegated Β· feedback loop"| RW["Rewriter"] --> RT["Retriever"] --> EV{"Evaluator"} EV -.->|"insufficient, feedback preset only"| RT EV -->|"sufficient"| OR["Orchestrator"] --> AGANS(["Answer"]) classDef decision fill:#eff6ff,stroke:#93c5fd,color:#0f172a classDef agent fill:#fffbeb,stroke:#fde68a,color:#0f172a classDef flat fill:#f1f5f9,stroke:#e2e8f0,color:#0f172a classDef done fill:#f0fdf4,stroke:#86efac,color:#0f172a class INTENT,ARCH,EV decision class RW,RT,OR agent class DECLINE,CMP,LOOP flat class CMPANS,LOOPANS,AGANS done

Endpoints collapsed by default, ordered method-first then route.

GET/api/ask/compare

Runs the same question through up to 5 presets in parallel, for side-by-side accuracy comparison. Defaults to single_agent,multi_agent_buggy,multi_agent_fixed if presets is omitted. Also accepts resolveVendor=false and resolveTemporal=false to switch off the Rewriter toggles (both on by default), same as POST /api/ask.

requires loginquestion requiredpresets optional
curl "https://releasetrain.io/api/ask/compare?question=Should+I+use+Node+or+Flask&presets=single_agent,multi_agent_fixed" -H "Authorization: Bearer YOUR_JWT_TOKEN"
{ "question": "Should I use Node or Flask?", "runs": [ { "preset": "single_agent", "runId": "660c38fce3cba9423e4f8f23", "answer": "...", "sources": [ "..." ] }, { "preset": "multi_agent_fixed", "runId": "660c38fce3cba9423e4f8f24", "answer": "...", "sources": [ "..." ] } ] }

Triggering the feedback loop: ask about a version for a product that plainly does not exist (so both internal retrieval and the deterministic web-search fallback come up empty, and the Evaluator judges the first pass insufficient) under multi_agent_feedback, the only preset with feedbackLoop on. Not a hard guarantee every single time, since the Evaluator's own verdict is a live model judgment call, not a fixed rule, but this is the reliable way to exercise it. Look for "feedbackLoopCount": 2 in the response (1 means it answered in one pass, no retry needed), or open that answer's own Feedback Loop tab in the UI.

curl "https://releasetrain.io/api/ask/compare?question=What+is+the+latest+version+of+Quantavox+Studio&presets=multi_agent_feedback" -H "Authorization: Bearer YOUR_JWT_TOKEN"
GET/api/ask/history

The signed-in user's own past Ask runs, newest first.

requires loginlimit optional Β· default 50 Β· max 200
curl "https://releasetrain.io/api/ask/history?limit=20" -H "Authorization: Bearer YOUR_JWT_TOKEN"
{ "data": [ { "_id": "660c38fce3cba9423e4f8f23", "question": "What is the latest PHP version?", "answer": "...", "rating": 1, "createdAt": "2026-03-25T17:00:00.000Z" } ] }
GET/api/ask/presets

The named retrieval-pipeline presets (single_agent, multi_agent_buggy, multi_agent_fixed, plus the delegated architectures) and the current admin-configured default.

curl "https://releasetrain.io/api/ask/presets"
{ "presets": { "single_agent": { "label": "Single-agent (no rewrite)" } }, "defaultPreset": "auto" }
GET/api/ask/providers

Available LLM providers (Anthropic, Groq, Ollama Cloud) and each one's small/medium/large model sizes, plus the current default preset/provider/size a new visitor's Ask form should start on.

curl "https://releasetrain.io/api/ask/providers"
{ "providers": [ { "id": "anthropic", "label": "Anthropic", "sizes": [ { "id": "small", "label": "Small" } ] } ], "defaultPreset": "auto", "defaultProvider": "ollama", "defaultSize": "medium" }
GET/api/ask/quota

Last-seen rate-limit headers per provider (Anthropic, Groq) plus how many calls this server process has made today. A snapshot from the last real /api/ask call, not a live check.

curl "https://releasetrain.io/api/ask/quota"
{ "anthropic": { "remaining": 48, "limit": 50, "rateLimitedSecondsLeft": null }, "groq": { "remaining": 14400, "limit": 14400, "rateLimitedSecondsLeft": null } }
GET/api/ask/recent-window-days

Public: the current admin-configured recency window (in days) Ask applies by default, so the feed's own lookback can track the same window instead of a separately hardcoded value.

curl "https://releasetrain.io/api/ask/recent-window-days"
{ "askRecentWindowDays": 14 }
GET/api/ask/anon-quota

Public: how many real questions this caller's IP address has asked today, and the current admin-set limit (see anonymousAskEnabled/anonymousAskLimit on GET/PUT /api/admin/settings), so a signed-out visitor's page can show "N free questions left" before they type one. A signed-in caller (recognized via an optional Authorization header, same as POST /api/ask) gets {"authenticated":true} instead, since an authenticated question has no anonymous quota to report.

curl "https://releasetrain.io/api/ask/anon-quota"
{ "authenticated": false, "enabled": true, "limit": 3, "used": 1, "remaining": 2 }
GET/api/guardrails

Public, with optional auth: every guardrail applied to Ask answers, each with the admin's raw enabled setting, the effective value that actually applies to the calling user right now (a mandatory guardrail's effective always equals enabled; an optional one's is the caller's own saved preference if signed in and set, else the admin default), and configurable (true only when the guardrail is tier: "optional" and the caller is signed in). Send Authorization: Bearer <token> to get a signed-in caller's own effective/configurable values; omit it for the signed-out view.

curl "https://releasetrain.io/api/guardrails" -H "Authorization: Bearer YOUR_JWT_TOKEN"
{ "guardrails": [ { "id": "toolResultInjectionScan", "tier": "mandatory", "label": "Scan retrieved content for prompt injection", "description": "Flags tool results that try to redirect the model's own instructions before they reach it.", "enabled": true, "effective": true, "configurable": false }, { "id": "vendorCheck", "tier": "optional", "label": "Require a resolvable vendor/product", "description": "Declines outright if the question names no vendor/product this system tracks.", "enabled": true, "effective": false, "configurable": true } ] }
POST/api/ask

Ask a question. A bare vendor/category name resolves instantly as plain JSON ({"intent":"documents",...}), no sign-in needed. A real question streams back text/event-stream progress events ending in one result (or error) event, and normally requires sign-in, except that a signed-out visitor gets a small, admin-configured number of free real questions per day first (see anonymousAskEnabled/anonymousAskLimit on GET/PUT /api/admin/settings; ships disabled in effect, at a limit of 0). Once that limit is used up, or if it's disabled, the 401 body carries anonymousLimitReached: true and the current anonymousQuestionLimit, so the client can tell that case apart from "sign-in has always been required." config accepts preset (or "auto" to classify intent server-side), provider, size, the vendorCheck/temporalFilter/intentFilter toggles, and the two Rewriter toggles resolveVendor (resolve a component type in a comparison question, such as "browser", to the real tracked components and recommend a stack) and resolveTemporal (turn a phrase like "last 3 weeks" into a date window), both on unless set to false. Question is capped at 500 characters. A comparison answer that resolved a component type also carries resolvedComponents ({ type, members }) and stack (the recommended app, the lowest-risk component, and each component's computed score). The result event also carries guardrailActivity (which of the mandatory guardrails, see GET /api/guardrails, actually did something for this specific answer), a guardrail field on any source a guardrail is responsible for surfacing, and (for an anonymous caller only; null for a signed-in one) anonymousQuestionsRemaining, the same number GET /api/ask/anon-quota would now report.

curl -N -X POST "https://releasetrain.io/api/ask" -H "Authorization: Bearer YOUR_JWT_TOKEN" -H "Content-Type: application/json" -d '{"question":"Was the WebView bug patched?","config":{"preset":"auto"}}'
data: { "type": "progress", "phase": "retrieving", "detail": "Searching versions and reddit" }

data: { "type": "result", "runId": "660c38fce3cba9423e4f8f23", "answer": "...", "sources": [ "..." ], "abstained": false }
POST/api/ask/:runId/rate

Rate one of the caller's own past runs helpful (1) or not helpful (-1).

requires login
curl -X POST "https://releasetrain.io/api/ask/660c38fce3cba9423e4f8f23/rate" -H "Authorization: Bearer YOUR_JWT_TOKEN" -H "Content-Type: application/json" -d '{"rating":1}'
{ "success": true }
↑ Back to top

Ask pipelines

Which process POST /api/ask runs, by the question's own classified intent. Preset "auto" resolves to one of these before the model is ever called (see pickAutoPipeline in ask.js); any other preset value runs that one directly regardless of intent. "Research type" is the general question-type category each row corresponds to in the wider question-classification literature, not this system's own terms.

Research typeTypeIntentProcessExample
Decision-makingComparisoncomparison-questionDelegated + feedback loop"Should I use Node or Flask?"
Factoid, verifySecuritycve-questionUnion search + BM25 rerank"Any recent CVEs in MySQL?"
Factoid, verifyPatchpatch-questionUnion search + BM25 rerank"Was the WebView bug patched?"
Factoid, numericVersionversion-questionSingle-agent"What's the latest PHP version?"
How-toGeneralgeneral-questionDelegated, no feedback loop"How do I roll back a Windows update?"
Review/opinionOpinionopinionDeclined, no retrieval"What's the best language?"
↑ Back to top

Eval tools (admin)

Eval tools at a glance

Research/diagnostic tools that run a real retrieval pass, and a real, billed LLM call, to measure how much each pipeline stage actually changes the outcome: does the Rewriter's query rewrite help retrieval, does the Evaluator's deterministic override actually flip its verdict, does the Orchestrator's version-correctness check actually change its answer. Each tool's access level (disabled / admin / auth / public) is admin-configurable via PUT /api/admin/settings; admin is the default for all three.

Endpoints collapsed by default, ordered method-first then route.

GET/api/eval-rewriter/sample

Returns one real, already-classified community question, sampled from Reddit posts predicted update-related, to seed an eval run so testing doesn't require hand-writing a question.

access level: evalRewriterAccess (default admin)
curl "https://releasetrain.io/api/eval-rewriter/sample" -H "Authorization: Bearer YOUR_JWT_TOKEN"
{ "question": "Anyone know if the MySQL 8.4 upgrade broke replication for others?", "subreddit": "mysql", "url": "https://reddit.com/..." }
POST/api/eval-evaluator/run

Runs the real retrieval pipeline and the Evaluator agent for a question, then reports its raw verdict alongside the final verdict after the same deterministic overrides /api/ask itself applies, and whether an override actually fired.

access level: evalEvaluatorAccess (default admin)
curl -X POST "https://releasetrain.io/api/eval-evaluator/run" -H "Authorization: Bearer YOUR_JWT_TOKEN" -H "Content-Type: application/json" -d '{"question":"Was the WebView bug patched?","config":{"provider":"anthropic","size":"medium"}}'
{ "question": "Was the WebView bug patched?", "rawVerdict": { "sufficient": false, "reason": "..." }, "finalVerdict": { "sufficient": true, "reason": "Overridden: a search_web result with real content was found." }, "overridden": true, "model": "claude-...", "provider": "anthropic" }
POST/api/eval-orchestrator/run

Runs the same retrieval and Evaluator gate as the Evaluator eval, then reports the Orchestrator's raw generated answer alongside the final answer after the same version-correctness rewrite /api/ask applies, and whether it actually changed anything.

access level: evalOrchestratorAccess (default admin)
curl -X POST "https://releasetrain.io/api/eval-orchestrator/run" -H "Authorization: Bearer YOUR_JWT_TOKEN" -H "Content-Type: application/json" -d '{"question":"What is the latest PHP version?"}'
{ "question": "What is the latest PHP version?", "abstained": false, "rawAnswer": "...", "finalAnswer": "The latest php version is 8.4.2, released 2026-01-15.", "overridden": true, "model": "gpt-oss:120b", "provider": "ollama" }
POST/api/eval-rewriter/run

Runs retrieval twice for the same question, once using the Rewriter agent's search terms and once using the raw question text, and reports each side's sources side by side, to measure whether the Rewriter step actually improves retrieval.

access level: evalRewriterAccess (default admin)
curl -X POST "https://releasetrain.io/api/eval-rewriter/run" -H "Authorization: Bearer YOUR_JWT_TOKEN" -H "Content-Type: application/json" -d '{"question":"Anyone know if the MySQL 8.4 upgrade broke replication?"}'
{ "question": "Anyone know if the MySQL 8.4 upgrade broke replication?", "rewriterTerms": ["mysql 8.4 replication"], "withRewriter": { "sources": [ "..." ], "toolCallsUsed": 2 }, "withoutRewriter": { "sources": [ "..." ], "toolCallsUsed": 3 }, "model": "gpt-oss:120b", "provider": "ollama" }
↑ Back to top
⚑ Quick Start

Three requests that cover the most common use cases. Paste any into a terminal to verify connectivity and explore the response shape. Base URL: https://releasetrain.io Β· All GET endpoints are public and unauthenticated.

What released in the last 7 days?

curl "https://releasetrain.io/api/v/search?start=20260511&end=20260518&limit=25&showCount=true"

Any CVEs published this month?

curl "https://releasetrain.io/api/v/search?channel=cve&start=20260501&end=20260531&limit=50&showCount=true"

What is Reddit saying about Chrome right now?

curl "https://releasetrain.io/api/reddit/by-subreddit?q=chrome&minScore=5&limit=25"

Latest 10 Firefox releases with key fields only

curl "https://releasetrain.io/api/v/latest10?q=firefox&limit=10"

Forecast Chrome's next release date

curl "https://releasetrain.io/api/v/fc?q=chrome"
↑ Back to top
πŸ“‹ Data Models

Two MongoDB collections store all release intelligence. Not every document has every field: the schema evolves as new sources are added.

versions collection

One document per software version release. Written by the bot fleet; read by /api/v/* and /api/aggregate/*.

FieldTypeDescription
_idObjectIdMongoDB document ID
versionIdstringComposite key: YYYYMMDD + productName + versionNumber. Unique per release.
versionProductNamestringNormalised product name, lowercase. e.g. chrome, firefox
versionNumberstringSemver string. e.g. 124.0.1
versionReleaseDatestringRelease date as YYYYMMDD
versionReleaseChannelstringInferred: major Β· minor Β· patch Β· cve Β· other
versionTimestampnumberUnix milliseconds derived from versionReleaseDate
versionTimestampLastUpdatestringISO-8601 datetime of last write
isCvebooleantrue when channel is cve
classification.componentTypestring[]e.g. ["browser"], ["os"], ["runtime"]
classification.securityTypestring[]e.g. ["security-fix"]
classification.breakingTypestring[]e.g. ["breaking-change"]
metadata.predicted.isUpdateRelatedbooleanML prediction: is this an update-related version?
metadata.predicted.positiveScorenumberSentiment score 0–1. Above 0.5 is positive.
metadata.labeled.isUpdateRelatedboolean|nullHuman override. null = unlabeled.
{
  "_id": "660c38fce3cba9423e4f8f23",
  "versionId": "20250217chrome124.0.1",
  "versionProductName": "chrome",
  "versionNumber": "124.0.1",
  "versionReleaseDate": "20250217",
  "versionReleaseChannel": "patch",
  "versionTimestamp": 1739750400000,
  "versionTimestampLastUpdate": "2025-02-17T10:00:00.000Z",
  "isCve": false,
  "classification": { "componentType": ["browser"] },
  "metadata": {
    "predicted": { "isUpdateRelated": true, "positiveScore": 0.72 },
    "labeled":   { "isUpdateRelated": null }
  }
}
reddit collection

One document per Reddit post. Written by the scraper and ML labeller; read by /api/reddit/*.

FieldTypeDescription
_idObjectIdMongoDB document ID
redditIdstringReddit short ID, e.g. 1nq0h33. Deduplication key.
titlestringPost title
subredditstringSubreddit name without prefix, e.g. programming
author_descriptionstringPost body / selftext
scorenumberReddit upvote score at ingestion time
num_commentsnumberComment count at ingestion time
created_utcstringISO-8601 datetime of original Reddit post
updatedAtstringISO-8601 datetime of last upsert
commentsobject[]Top-level comment objects from the thread
metadata.predicted.isUpdateRelatedbooleanML prediction: does this post discuss a software update?
metadata.predicted.positiveScorenumberSentiment score 0–1
metadata.labeled.isUpdateRelatedboolean|nullHuman label. null = unlabeled.
{
  "_id": "69d176bbda0850f83829b2d6",
  "redditId": "1nq0h33",
  "title": "Chrome 124 breaks extension manifest v2",
  "subreddit": "chrome",
  "author_description": "After updating to 124.0.1 my uBlock Origin stopped...",
  "score": 342,
  "num_comments": 87,
  "created_utc": "2025-02-18T09:14:00.000Z",
  "updatedAt": "2025-02-18T12:00:00.000Z",
  "metadata": {
    "predicted": { "isUpdateRelated": true, "positiveScore": 0.21 },
    "labeled":   { "isUpdateRelated": true }
  }
}
↑ Back to top
πŸ“„ Pagination Guide

The API supports two paging schemes. Use page/limit for random access; use cursor for efficient forward scrolling through large result sets without offset drift.

Page / Limit

ParamDescription
page1-based page number. Default: 1
limitDocuments per page. Default: 25. Pass limit=all to disable paging (large collections only).
showCount=trueAdds totalCount to the response body at the cost of an extra countDocuments call.
curl "https://releasetrain.io/api/v/search?q=chrome&limit=50&page=2&showCount=true"
# response: { "data": [...], "totalCount": 314 }

Cursor (forward-only)

ParamDescription
cursorOpaque token from the X-Next-Cursor response header. Omit for the first page.
# First page: capture the X-Next-Cursor response header
curl -i "https://releasetrain.io/api/v/search?q=chrome&limit=50"

# Subsequent page
curl "https://releasetrain.io/api/v/search?q=chrome&limit=50&cursor=TOKEN"

Support by endpoint

EndpointPage/LimitCursor
/api/v/searchβœ“βœ“
/api/v/latest10βœ“βœ—
/api/redditβœ“βœ“
/api/reddit/by-subredditβœ“βœ—
/api/reddit/query/cveβœ“βœ“
/api/reddit/query/questionsβœ“βœ—
/api/reddit/query/update-relatedβœ“βœ—
/api/iotβœ“βœ—
↑ Back to top
πŸ€– ML Fields

Two predicted fields are added to every Reddit document by the bot ML labeller. Human overrides live alongside predictions so consumers can choose which branch to trust.

metadata.predicted.isUpdateRelated

Text classifier trained on labeled Reddit posts. Predicts whether a post discusses a software update: a new release, patch announcement, upgrade discussion, or CVE advisory.

ValueMeaning
truePost likely discusses a software update or release event
falsePost predicted as not update-related
field absentDocument has not been scored yet

Query predicted positives: /api/reddit/query/update-related?isLabeled=false&isUpdateRelated=true. Switch to isLabeled=true to use human labels.

metadata.predicted.positiveScore

Sentiment classifier output. Continuous score 0–1 reflecting community sentiment toward the update being discussed. Scores above 0.5 are considered positive.

RangeInterpretation
0.0 – 0.5Neutral to negative sentiment
0.5 – 0.75Mildly positive
0.75 – 1.0Strongly positive

Retrieve high-confidence positives: /api/reddit/query/positive. Use /api/reddit/query/filter?minScore=0.75&maxScore=1.0 for a custom window.

Human labels vs predictions

Human labels live under metadata.labeled.isUpdateRelated and take precedence over predictions for training and evaluation. The Label view in releasetrain-client is the labelling interface. Pass isLabeled=true on any query route to read only human-verified data.

↑ Back to top
πŸ“– Glossary

Domain-specific terms used throughout the API, codebase and this documentation.

TermDefinition
versionIdComposite business key: YYYYMMDD + productName + versionNumber. Unique per release. Used by /api/v/versionId/:id.
versionReleaseChannelInferred semver category: major (breaking), minor (feature), patch (bugfix), cve (security advisory), other (non-standard).
isCveSet to true when a version document originates from a CVE or NVD advisory rather than a regular release channel.
isUpdateRelatedBoolean: does a Reddit post discuss a software update? Stored under metadata.predicted (ML) and metadata.labeled (human).
positiveScoreML-predicted sentiment score 0–1. Reflects community tone toward the update discussed in a Reddit post.
rolling 2-year windowMost read routes restrict results to the past two years by default. Override with ?start=YYYYMMDD&end=YYYYMMDD.
redditIdReddit's own short alphanumeric post ID, e.g. 1nq0h33. Used as the deduplication key on ingestion.
cursorOpaque pagination token from the X-Next-Cursor response header. Pass on the next request to continue without offset drift.
componentTypeClassification tag assigned during enrichment: browser, os, runtime, package, tool.
MLTLMulti-Language Temporal Logic. A spec-tracking module for cross-language version timeline analysis.
JUSPNJapanese specification release tracking module. Mirrors the EDI40-2023 stack matrix for Japanese standard editions.
EDI40-2023EDI 4.0 2023 specification adoption tracker covering LAMP, MEAN, MERN, MEVN and WAMP stack version matrices.
↑ Back to top
⚠ Error Format

All error responses return JSON. Use the HTTP status code for programmatic branching; the message field is human-readable context.

StatusWhenBody shape
200 OKSuccess{ "data": [...] } or collection-specific shape
400 Bad RequestMissing or invalid parameter{ "error": "Bad Request", "message": "..." }
404 Not FoundDocument ID does not exist{ "error": "Not Found", "message": "document not found" }
500 Server ErrorUnhandled exception or DB error{ "error": "Internal Server Error", "message": "..." }
// 400 example
{ "error": "Bad Request", "message": "field param is required" }

// 404 example
{ "error": "Not Found", "message": "document not found" }

The /api/health and /api/meta routes use a slightly different shape: { "ok": true } on success and { "ok": false, "error": "..." } on failure.

↑ Back to top
πŸ” Field Projection

Several endpoints accept a fields query parameter that limits the fields returned per document, useful for reducing payload size when building lightweight dashboards or mobile clients.

# Return only title, subreddit and score
curl "https://releasetrain.io/api/reddit?limit=50&fields=title,subreddit,score"

# Return only key version fields
curl "https://releasetrain.io/api/v/search?q=chrome&fields=versionId,versionNumber,versionReleaseDate"

# Nested fields via dot notation
curl "https://releasetrain.io/api/reddit?fields=title,metadata.predicted.isUpdateRelated"
EndpointNotes
/api/v/searchAll version fields including nested paths
/api/redditAll reddit fields including nested paths
/api/reddit/query/cveAll reddit fields
/api/reddit/query/questionsAll reddit fields
/api/reddit/query/update-relatedAll reddit fields
/api/reddit/by-subredditAll reddit fields

_id is always returned regardless of the fields value. Nested paths use dot notation, e.g. metadata.predicted.positiveScore.

↑ Back to top
πŸ”’ Security and Access

Current access model for the REST API.

ConcernStatus
AuthenticationNone required for GET endpoints. The full read surface is public.
Write accessPOST and PUT routes are intended for the bot fleet and are not token-guarded in the current version, so treat them as internal.
CORSPermissive. All origins are allowed for GET requests. Safe to call from browser JavaScript.
Rate limitingNo hard limit is enforced. For long-running integrations, cache responses locally and use cursor or start/end to request only new data.
HTTPSAll production traffic is served over HTTPS. HTTP redirects to HTTPS.
Data sensitivityAll data is derived from public sources (Reddit, public vendor advisories, NVD). No PII is stored.
↑ Back to top
πŸ“Š Live Collection Stats

Fetched live from the API on first load. Rolling 2-year window. Est. size based on average document size.

πŸ“¦ Versions

Total…
CVE advisories…
Release notes…
Est. size…

πŸ’¬ Community

Total…
Reddit posts…
Stack Overflow…
Server Fault…
Est. size…

Loading freshness info…

↑ Back to top
CVE Lifecycle Pipeline
CVE Lifecycle Β· Reddit post distribution per stage  Β·  dashed = CVE List (cve.org)   solid = NVD

CVE Post Timeline

Source
Filters
🔍
Release Risk Intelligence
Select a component and optionally a specific version, then click Analyze Risk to get a deployment risk assessment.
0
Low Risk
—
Recommendation
—
CVE / Security
—
Community Risk
—
Version Details
—

πŸ“ Changelog

Notable changes to releasetrain-client, newest first.

2026-09-26
v3.144.1

Arch view: real bug and readability fixes

  • fix An untracked component no longer shows the false claim 'on latest' (it now says 'no release data', and no longer inflates the ecosystem freshness score); removed the default preset stacks (LAMP/LEMP/etc.) from the picker; fixed a sticky-header rendering glitch in the drift table where a data row could peek above the header on scroll; lightened the table's visual weight
2026-09-26
v3.144.0

Add saved machines to the stack picker

  • feature The Add stack to search dropdown in the Arch view now also lists each machine recorded in your Installed versions, so picking one loads every component saved from that machine into the search
2026-09-26
v3.143.2

Installed versions: matched entries sort first

  • fix Rows where a tracked latest version was found now sort above ones with no release data, since those are the ones actually worth looking at
2026-09-26
v3.143.1

Installed versions: reorder + a real drift failure message

  • fix Row chips reordered from generic to specific (machine, vendor, component, version, recorded); the version-vs-latest comparison no longer silently goes blank on a slow or rate-limited response, it now shows a clear message and times out instead of hanging forever
2026-09-26
v3.143.0

Installed versions: readable placeholders

  • fix The four Installed versions add-form fields no longer clip their placeholder text; shortened wording plus a smaller font and reclaimed icon padding make every placeholder fully visible, with the field name moved to an aria-label for accessibility
2026-09-26
v3.142.2

Installed versions: local time in tooltips

  • fix The recorded/checked timestamps on Installed versions now show the viewer's own local time on hover instead of the raw UTC value stored in the database
2026-09-26
v3.142.1

Installed versions: recorded-at timestamp

  • feature Each Installed versions entry now records when its own version snapshot was taken (a scan run, or a manual add/edit), shown as 'recorded Xh ago' next to the version
2026-09-26
v3.142.0

Installed versions: vendor and machine

  • feature Installed versions now records an optional vendor and machine per entry (so a same-named component from a different vendor, or the same component on a different machine, no longer overwrites another saved entry), plus a per-component checked-at timestamp
2026-09-26
v3.141.2

Pipeline fills the width

  • fix The agent pipeline now stretches across the full width of the column and stays centered above the input, with or without the sidebar collapsed
2026-09-26
v3.141.1

Short answer keeps the date

  • fix The Short answer tab no longer strips the release date and days ago from a When question
2026-09-26
v3.141.0

When questions return a date

  • feature A question that asks when (when was..., what date..., release date of...) is now typed as a When question and always answers with the release date of the newest tracked version
2026-09-26
v3.140.0

Collapsible sidebar

  • feature Desktop sidebar collapses to a slim rail with an accessible toggle; the signed-in dot (filled green or hollow gray) stays visible and opens Account, and the page uses the freed space
2026-09-26
v3.139.0

City in Recent visitors, compact Visits tables, and no sideways scrolling anywhere

  • feat Recent visitors shows the city. The Visits tables are compact and wrap instead of scrolling sideways. As a global rule nothing in the app scrolls horizontally: the CSS lint forbids it and a browser test checks every view at desktop and phone width.
2026-09-26
v3.138.4

Today's visitors highlighted in green

  • ux In the Visits tab's Recent visitors table, visitors seen today (your local day) get a subtle green background, with a small key, and columns have a little more space.
2026-09-26
v3.138.3

Visits counts only visitors whose browser really ran the app

  • fix A visit now needs at least 5 API requests from the same IP that day (real page loads make dozens, crawlers almost none), which removes bot traffic that only fetched the page or a script file.
2026-09-26
v3.138.2

Countries table shows visits per visitor

  • ux A Per visitor column in the Visits tab's Countries table makes bot-like traffic easy to spot: a country with a few IPs and many visits each.
2026-09-26
v3.138.1

Visits ignores scrapers that never run the site

  • fix The Visits tab and the 14-day chart now count a page load only when the same IP also loaded the site's scripts or called the API, and show how many page loads were not counted (very likely bots).
2026-09-26
v3.138.0

Visitors chart on top of the admin view, and a Visits tab

  • feat Admins see a 14-day chart of unique and total visitors at the top of the Account page, plus a Visits tab with countries, views, referrers and recent visitors (IP address, country, browser). Counted from the web server's access log; no tracking script.
2026-09-26
v3.137.0

Account and admin page grouped into tabs, with a Server alerts list

  • feat The Account page is now tabs (Account, Saved, and for admins Overview, Alerts, Settings, Bots, Users) with card-style sections instead of one long list. New Server alerts tab shows watchdog, deploy and report messages from the server, with a red badge for problems in the last 24 hours.
2026-09-26
v3.136.1

Tests for the agent graph and phone view, dead code removed

  • ux New browser tests cover the agent graph states, the run log and the phone view, and the home test now checks the Ask form. Three unused declarations were removed.
2026-09-26
v3.136.0

JavaScript split into files by area

  • ux The page script is now 16 files under js/ (core, ask, graph, arch, feed, cve, account and more) loaded in order, with start-up code last in main.js. Nothing changes visually.
2026-09-26
v3.135.2

All JavaScript moved to app.js

  • ux The page's inline scripts now live in one app.js file. Nothing changes visually.
2026-09-26
v3.135.1

Lint rule keeps CSS in styles.css

  • ux A new check fails the build if a style block, inline style attribute or JS style write is added outside styles.css.
2026-09-26
v3.135.0

No inline styles left in the app code

  • ux Show and hide, banners, inline editors and value-driven widths and colors now use classes and CSS variables from styles.css. Nothing changes visually.
  • fix The CVE page loading bar fills again. A recent CSS move had pinned it at zero width.
2026-09-26
v3.134.7

Removed the duplicate status text

  • ux The live status text on the right of the answer tabs is gone. The run log at the bottom shows the same steps.
2026-09-26
v3.134.6

Inline styles in generated HTML moved to styles.css

  • ux About 170 inline style attributes in the HTML the app builds in JavaScript are now classes in styles.css. Nothing changes visually.
2026-09-26
v3.134.5

Inline styles in the page markup moved to styles.css

  • ux About 370 inline style attributes in the static page markup are now classes in styles.css. Nothing changes visually.
2026-09-26
v3.134.4

Styles moved to styles.css

  • ux All page CSS now lives in one styles.css file instead of inside index.html. Nothing changes visually.
2026-09-26
v3.134.3

Gentler page load

  • fix The latest-version lookups for the feed run 4 at a time instead of about 70 at once, and a failed lookup is retried later instead of staying blank.
2026-09-26
v3.134.2

Green boxes match the agent count

  • fix Steps that ran plain code without a model call, like the document lookup in a comparison, turn grey and say code, so the green boxes equal the "N agents" badge.
2026-09-26
v3.134.1

Close button no longer overlaps the run log

  • fix The round close button moves up above the run log, and sits just above the slim bar when the log is minimized.
2026-09-26
v3.134.0

Phone view shows only the latest updates

  • feat On phones the app opens on Recent updates, and the Ask box, agent graph, run log, credits and changelog are hidden.
2026-09-26
v3.133.8

No dashes used for emphasis in UI text

  • ux Sign-in reasons, the graph view and the docs now use colons or commas instead of dashes for emphasis.
2026-09-26
v3.133.7

Ask node no longer counted as an agent

  • fix The Ask box (the incoming question) turns grey when done instead of green, so the green boxes are exactly the agents in the "N agents" badge.
2026-09-26
v3.133.6

Run log minimizes instead of closing

  • ux The run log's close button is now a minimize toggle that shrinks it to a slim bar and expands it again, keeping the log.
2026-09-26
v3.133.5

"Why create an account?" is now a tab

  • ux The reasons list moved from a collapsed panel below the sign-in box to a third tab next to Sign in and Register.
2026-09-26
v3.133.4

Removed the old plain text agent row

  • fix The old text row with robot icons is gone. If the graph can't be fetched, the page keeps retrying, and it draws the last graph it saw straight away.
2026-09-26
v3.133.3

Run log no longer hidden under the sidebar

  • fix The bottom run log starts at the main column, so its text is visible next to the sidebar.
2026-09-26
v3.133.2

Run log stuck to the bottom of the page

  • fix The run log is now one fixed-height box pinned to the bottom of the browser window, visible on every tab, newest line first, with a close button.
2026-09-26
v3.133.1

Console box pinned to the bottom, newest line first

  • fix The run log is a fixed-height box stuck to the bottom of the answer area, with the latest message on top.
2026-09-26
v3.133.0

Agent graph shows skipped steps, details and a live log

  • feat After a run, agents that never ran turn dashed and grey and say skipped, so the green boxes match the agent count.
  • feat Each agent shows a short detail under its time: search term count, documents found, and the evaluator's verdict.
  • feat A scrollable console box under the answer logs each step and its reasoning with timestamps, live while the run is going.
2026-09-26
v3.132.2

Agent graph labels vertically centered

  • fix Node names in the live agent graph are now centered vertically as well as horizontally, measured on screen.
2026-09-26
v3.132.1

Agent graph labels centered

  • fix Node labels in the live agent graph sit in the middle of their boxes, and idle nodes use LangGraph's own purple styling.
2026-09-26
v3.132.0

Live LangGraph agent graph for everyone

  • feat The pipeline diagram above the question box is now LangGraph's own graph drawing, fetched from the server and rendered with Mermaid. It is always visible: nodes stay dim while idle, the active node lights up and blinks, finished nodes turn green, and each shows its elapsed time.
2026-09-25
v3.131.12

Feedback Loop tab shows which engine ran

  • feat A multi-agent answer's Feedback Loop tab now says whether the retry loop ran as a LangGraph graph or as the built-in loop, lists each graph step with its round number and duration, and shows the reason if a LangGraph run fell back to the built-in loop. Before this, the only way to tell was to read the raw orchestration field in the network response.
2026-09-25
v3.131.11

Credits: LangGraph.js

  • fix The agentic AI credits now list LangGraph.js and LangChain Core, and the section's intro no longer says no LangChain is used: the experimental LangGraph pipeline uses LangGraph.js for the Retriever/Evaluator retry loop only.
2026-09-25
v3.131.10

LangGraph pipeline option and admin controls

  • feat New Orchestrator: multi-agent (LangGraph, experimental) pipeline option: the same multi-agent pipeline, but the Retriever/Evaluator retry loop runs as a LangGraph.js graph. Needs the matching server change (langgraph_delegated preset).
  • feat Seven new admin settings for it, in the Account view's admin settings: enabled (kill switch), use for Auto, max retrieval rounds, step limit, node timeout, include step trace in answers, and what to do on error (fall back to the normal loop or fail).
2026-09-25
v3.131.9

Credits: correct what is actually used

  • fix Tightened the agentic AI credits after checking the code: Ollama is credited as the hosted Ollama Cloud API (the app does not run Ollama itself), gpt-oss-120b is marked as the default agent model, Qwen and Nemotron are marked selectable rather than default, and Meta Llama 3.1 was removed because it is only in the AgenticSE paper's evaluation, not in the app.
2026-09-25
v3.131.8

Credits: agentic AI open-source frameworks, tools, and models

  • feat The Credits page has a new section crediting the open-source software and open-weight models behind the Ask agent pipeline (Node.js, Express, node-fetch, the MongoDB driver, prompt-protection, express-rate-limit, Ollama, gpt-oss, Qwen, Nemotron, Llama 3.1, Mermaid). Every entry was checked against the server's package.json, its installed packages, and the provider model list in ask.js, and the section states that no agent framework (LangChain, LlamaIndex, or an agent SDK) is used.
2026-09-23
v3.131.7

Move Stacks/Actions into the Arch view too; fix a real PlantUML error

  • ux Follow-up to the Diagram/Table move: the Arch sidebar's Stacks and Actions sections moved the same way, into the Arch view's own header on the right side, next to the Diagram/Table toggle. The sidebar's #archControls is now an empty placeholder (still toggled by activate/deactivateArch, but has nothing left to show).
  • fix The skinparam Padding/ComponentPadding added in v3.131.6 aren't real PlantUML directives: newer PlantUML rejects them and renders a "please use CSS style instead" warning banner inline in the diagram itself, caught from a live render. Removed both; the font-size bumps already grow each box's default padding along with its text.
  • fix Diagram still read as cramped at the font sizes from v3.131.6 (16/17/15/13). Bumped to 20/22/20/16 and verified directly against the real PlantUML server (no warning banner, correct font-size values in the returned SVG, legible at a realistic render size) rather than assuming the change took effect.
2026-09-23
v3.131.6

Move the Arch view's Diagram/Table toggle into its own header

  • ux The Diagram/Table view-mode toggle used to sit at the top of the Arch view's sidebar section, which otherwise looks the same regardless of which view is active. Moved it into a real header bar inside the Arch view's own content panel, right-aligned above the diagram/table, since it's a control for that view's own display mode, not a global sidebar setting.
  • fix The ecosystem diagram only ever scaled to match its container's width (height:auto), so a wide-and-short diagram rendered small with real vertical space left unused below it. It now computes an explicit pixel size against whichever axis of the canvas is the tighter fit, re-run on window resize, and bumped the underlying PlantUML font/padding sizes so the diagram is more legible at the larger size.
2026-09-23
v3.131.5

Prototype Demo buttons now cover all 6 question types

  • feat Each of the 6 Prototype Demo quick-load buttons now shows its classified question type and real agent count (e.g. "CVE · Multi-agent") right under the question text, and the 6 questions were rewritten so every intent Auto can classify (comparison, CVE, patch, version, opinion, general) is represented exactly once (verified against the real detectComparisonEntities/keyword logic in ask.js, not just eyeballed). The comparison button is labeled "1 agent (fixed path)" rather than "multi-agent", since a comparison question always bypasses the pipeline choice and runs its own fixed evidence-gather path regardless of preset (see the v3.131.4 entry below).
2026-09-23
v3.131.4

Rename the delegated pipeline option to "multi-agent"

  • fix The Model & pipeline dropdown's orchestrator_delegated option read "Orchestrator: delegates (Rewrite/Retrieve/Evaluate)"; renamed to "Orchestrator: multi-agent (Rewrite/Retrieve/Evaluate)" to match the existing "Demo: Single vs Multi-Agent" terminology, and to make clear it's the multi-agent counterpart to "Orchestrator: single agent". The tooltip now also notes that a comparison question always runs its own fixed evidence-gather path and shows 1 agent regardless of which pipeline is picked, since that surprised a tester who selected the multi-agent option and still saw "1 AGENT" on a comparison question.
2026-09-23
v3.131.3

Simplify the pipeline picker to two clean architectures

  • feat Two new demo-facing presets, orchestrator_single ("does everything itself") and orchestrator_delegated ("spawns a Rewriter/Retriever/Evaluator sub-agent each"), replacing the confusing five-way single_agent/multi_agent_buggy/multi_agent_fixed/multi_agent/multi_agent_feedback picker in the Model & pipeline dropdown. The five original presets are unchanged and still power "Compare all 5" and the Single-vs-Multi demo mode internally.
  • fix Auto now resolves every question's classified intent to one of just these two presets instead of the old five, so a comparison, security, or patch question always gets real Rewriter/Retriever/Evaluator delegation (previously only security/patch questions did) and a plain version or opinion question always gets the fast single-agent pass.
2026-09-23
v3.131.2

Fix: a shared Arch view link lost its own component list

  • fix setViewParam unconditionally deleted the q URL param on every view change, including entering the Arch view -- but Arch is the one view that genuinely reads q as the component list to render (?view=arch&q=safari,chrome,firefox). The diagram still rendered correctly on that first load (the value was already read into the input before the URL got rewritten), but the address bar silently dropped to a bare ?view=arch, so reloading, bookmarking, or sharing that exact link lost the component list. Reported live against a real broken link. q is now preserved specifically for view === "arch"; every other view (Home, Docs, CVE, Graph, etc.) still clears it exactly as before.
2026-09-23
v3.131.1

Prototype Demo: add a third example question

  • ux Added "Zoom or Teams and which Browser Stack?" as the third quick-load button, matching the 2024 EDI40 paper's own rewritten question.
2026-09-23
v3.131.0

Pipeline diagram: verb labels (Ask, Rewrite, Search, Verify, Retrieve, Evaluate, Orchestrate)

  • ux Every node name in the pipeline diagram is a verb now instead of a noun ("User Question" → "Ask", "Rewriter" → "Rewrite", "Web Search" → "Search", "Retriever" → "Retrieve", "Evaluator" → "Evaluate", "Orchestrator" → "Orchestrate"), per explicit request, so the whole row reads shorter without losing what each step does.
2026-09-23
v3.130.0

Prototype Demo: quick-load buttons for the RISE seminar talk

  • feat A new "Prototype Demo" section at the top of the sidebar holds six one-click buttons, one per paper's motivating question, so a live talk can load a question into the Ask input without retyping it. Loading never auto-submits, so the presenter still controls when it runs.
2026-09-23
v3.129.0

Pipeline diagram: tighter padding, plain node names, no more mid-word clipping

  • ux The pipeline row's own horizontal padding was cut (14px → 6px per side) and its node names are no longer bold, so the full 7-node pipeline sits more compactly and reads less shouty.
  • fix On a narrow window, the row could run out of width and get silently cut off mid-word ("Orchestrator" clipped to "Orchestrator (", caught live) since the page itself has overflow: hidden and a flex row's items can't shrink below their own nowrap text width. The row now scrolls internally (hidden scrollbar) instead of clipping.
2026-09-23
v3.128.0

Transparent view backgrounds everywhere; pipeline-first-node feedback replaces the submit button's own loading state

  • ux Docs, Credits, and Changelog's own outer panels (plus the Docs page's nested cards/tags/sub-sections and the Dashboard's own stat cards) were still solid white or var(--surface), left over from before --view-card existed. All switched to it, per explicit, repeated request ("transparent background for all view items"). The Changelog's own sticky header intentionally keeps an opaque background, since scrolled entries would otherwise show through the header text pinned above them.
  • ux The submit button no longer changes appearance at all between idle and running, per explicit follow-up ("keep the state of the button the same independent if it is pressed or not, do not make it a robot") — it was a redundant second "something is happening" signal now that the pipeline diagram's own first node does that instead.
  • feat The pipeline diagram's first node is renamed "User Question" (was "Vendor") and now activates the instant a question is submitted, with its own timer already running, rather than waiting for the real vendor-resolution phase event to stream back. Hovering it shows the actual question text.
  • ux The floating "×" close button moved from top-right (where it visibly overlapped the pipeline diagram's own right end) to bottom-right, and enlarged (30px → 40px), per explicit request.
2026-09-23
v3.127.0

A second, independent Fact/Opinion chip under the input

  • feat A new chip shows "Fact question" or "Opinion question" right next to the existing domain chip (Version question, CVE question, etc.), classified independently of it, per explicit request ("independent of the domain language"). A question can now show both at once ("Version question" + "Opinion question" for "should I upgrade to the latest version?"), which the single combined classifier could never surface together. Always shown once something is typed, since "fact" is itself a real answer, not a placeholder for "nothing to show" the way the domain chip's own hidden state is.
  • ux Both chips are now a bit more square-cornered (border-radius: var(--radius), was the fully-rounded var(--radius-full)), per explicit request, now that two of them show side by side.
2026-09-23
v3.126.1

Tightened vertical gaps in the sidebar's collapsible sections

  • ux Per explicit request, the vertical padding on every .sb-details summary row (Menu, Model & pipeline, Advanced checks, Guardrails) and the gap/padding around them was cut roughly in half, so all 4 collapsed headers, and the Guardrails list itself now that it has 15 entries, fit with noticeably less scrolling.
2026-09-23
v3.126.0

Sidebar Guardrails panel now lists every mandatory check too

  • feat The Guardrails panel in the sidebar used to list only the one check a visitor can actually change ("Retry new terms"). It now also shows every mandatory, always-on guardrail underneath (Injection scan, Leak scan, Version check, Dual-source check, Domain check, Web override, Web fallback, Window check, Live Reddit search, Metric weighting, Risk report links, Retriever retry, Evaluator retry, Hedge retry), each checked and disabled, with the full description still a hover away, so the depth of this system's own protections is visible at a glance instead of only surfacing per-answer in the Guardrails tab.
  • feat New guardrail: vendorDomainVerification. When a web search verifies a vendor not in this system's own catalog, the claimed "official" URL's own domain is now checked against the vendor name (e.g. does "zoom.us" actually contain "zoom") and flagged as a caveat on a mismatch, rather than trusting the model's own claim with no check at all. A mismatch is disclosed, never a rejection, since a real product can legitimately be documented off-domain (GitHub, Wikipedia, a docs site).
2026-09-23
v3.125.1

Fixed: flagged-report links now work with a relative URL too

  • fix mdLite's new markdown-link support only matched an absolute https:// URL, so a Reddit doc whose own stored URL is relative (e.g. /r/StableDiffusion/) rendered as plain, unlinked text instead of a link, per a live report ("make it clickable"). Now matches a bare /path too, resolved against reddit.com.
2026-09-22
v3.125.0

Comparison answers: metric-aware scoring, flagged-report links

  • feat A comparison question that names a metric ("which is more stable", "...more secure", "...better functionality") now re-weights the same evidence differently for that metric instead of always using one general-purpose risk formula — stability prioritizes recent major-version updates (semantic-versioning detected, never guessed from release notes) then Reddit concerns then CVEs; security prioritizes CVEs first; functionality prioritizes minor/patch update activity first.
  • feat A flagged-as-risky community report is now always named by a real, clickable link (mdLite gained markdown-link support, rendered as a bracketed citation, e.g. [1t7k0ts]), appended as a guaranteed warning line after the answer, instead of only being mentioned as a bare count somewhere inside a risk-math paragraph.
  • feat The pipeline diagram always shows the full 7-node pipeline (Vendor, Rewriter, Web Search, Verify, Retriever, Evaluator, Orchestrator) now, not a shorter 5-node version that only grew to include Web Search/Verify on a run that happened to escalate, per explicit request ("show the whole pipeline including feedback loops and web search etc").
  • feat A πŸ€– sits in front of every node's name, and only that robot blinks while its own node is active — the node's own name/timer text stays fully static, per direct follow-up ("only blink the robot in front, this way the text stays static"). The pipeline row now spreads across the full available width (justify-content: space-between) instead of centering with wasted space on both sides.
  • ux The Ask submit button shows πŸ€– (blinking) instead of a spinning ⏳ hourglass while a question is running, per explicit request, reusing the same blink animation the diagram's own active-node robots use.
  • ux The running phase status ("Retriever: Searching sources… 0.3s") moved from its own dedicated line into the answer card's tab row, right after "Benchmark", per explicit request ("add this runtime status right to the benchmark, that way it does not take vertical space"). It no longer reserves any vertical space of its own; it just fills in the same row the tabs already occupy.
  • ux The "Short answer" tab's explanatory line ("The full answer, sources and checks are in the other tabs.") is gone, per explicit request — the tab row right below it already makes that obvious.
  • feat In the Admin panel's Search Events table, a "πŸ’¬ ask" row is now clickable: it pastes that exact question into the live Ask input (always visible above, even from this view) so an admin can re-run what a user actually asked without retyping it.
  • feat The per-answer Guardrails tab's "Used for this answer" note now covers liveRedditSearchFallback (the server's new guardrail, see releasetrain-server), naming which side of a comparison a live Reddit search ran for.
  • ux The Single-Agent / Multi-Agent / Single-vs-Multi quick buttons are gone, per direct follow-up ("no integrate it here", pointing at the Pipeline dropdown itself). They were a redundant shortcut on top of the "Demo: Single vs Multi-Agent" option already in that dropdown; picking it and asking a question does the exact same thing, so there's one control for this now instead of two.
  • 2026-09-22
    v3.122.0

    Demo shortcuts moved into Model & pipeline; running caption moved below the input

    • ux The 3 Single/Multi/Single-vs-Multi demo buttons moved from the sticky header above the question input into the sidebar's "Model & pipeline" section (right under the Pipeline dropdown), left-aligned, per direct follow-up request ("move these three to the left in the model and pipeline summary details").
    • fix The running "Generating answer… 6.4s" caption now renders below the question input instead of between the pipeline diagram and the (now-relocated) demo buttons. It used to grow/shrink there while a question was in flight, visibly pushing the input box down and back up; per explicit request ("avoid moving pipeline or text input") it's now its own element right after the input, so it can only ever push page content below the sticky header, never the pinned diagram or input themselves.
    2026-09-22
    v3.121.0

    One-click "Single vs Multi-Agent" demo shortcuts

    • feat A new quick-access row under the pipeline diagram (top of the right-hand content area, per explicit request "integrate that to the right side so i can show the single agent demo and see the multiagent"): three buttons run whatever question is currently typed through Single-agent only, Multi-agent (feedback loop) only, or both at once, without opening "Model & pipeline" in the sidebar first.
    • feat "Single vs Multi" is a new pipeline option ("Demo: Single vs Multi-Agent" in the Model & pipeline dropdown, or its own quick button) that reuses the existing 5-way Compare's /api/ask/compare endpoint with just single_agent,multi_agent_feedback, and renders both complete answers side by side in the answer rail (new askRenderDuoBody/showAskRailDuo) rather than the 5-way Compare's "one primary answer + a Benchmark tab" layout, so a presenter can point at one card, then the other, in the same screenshot.
    2026-09-22
    v3.120.0

    Removed the bookmark button; submitting always returns to the top

    • ux The bookmark-save button (πŸ”–) next to Clear/Send is gone, per explicit request. It saved the internal component-search box's value, not the visible Ask question, and had become a confusing leftover from the app's earlier dual-mode (Search vs. Ask) design.
    • ux Submitting a question now scrolls the page back to the top, per explicit request ("center the input on enter submit"), so a viewer who asks from partway down a long scrolled view always lands somewhere consistent to watch the new answer run, instead of staying scrolled into whatever was there before.
    2026-09-22
    v3.119.2

    Pipeline diagram: centered again, still one line, still full width

    • ux Direct follow-up correction: the diagram is centered again ("always keep it centered"), not left-aligned. Still uses the full available width (not capped at 780px) so it stays on one line without wrapping, and still falls back to start-alignment (justify-content: safe center) instead of clipping on the rare screen too narrow to fit the escalated 7-node list even at full width.
    2026-09-22
    v3.119.1

    Pipeline diagram: full width and left-aligned, no scrolling

    • ux Direct follow-up correction: the previous commit's horizontal-scroll fallback for the diagram's escalated 7-node list is gone entirely, per explicit request ("no horizontal scrolling, stretch it along the full available width, start from left to right"). The diagram's own container is no longer capped at the same 780px as the question input below it, so the row has real room to lay out every node on one line, left-aligned, without needing to wrap or scroll at all.
    2026-09-22
    v3.119.0

    Pipeline diagram never wraps; the highlighted term is a marker, not bold

    • fix The pipeline diagram's escalated 7-node list (Vendor/Rewriter/Web Search/Verify/Retriever/Evaluator/Orchestrator) used to wrap onto a second line once the row ran out of width. It's flex-wrap: nowrap now with its own hidden horizontal scroll as a fallback, so it's always exactly one line.
    • fix That scroll fallback used plain justify-content: center at first, which (caught live) can permanently scroll the left end of an overflowing row out of reach, since centering an overflowing flex row shifts its overflow to a negative offset a scrollbar can never reach. Switched to justify-content: safe center: centered when it fits, left-aligned and fully reachable by scrolling when it doesn't.
    • fix The answer's highlighted term (the green marker) could show up bold too, when the model wrote its own **markdown bold** around the same text. Per explicit request ("do not make it bold but use a marker"), any bold wrapping the highlighted term is unwrapped first. A first version of this only stripped a <strong> tag immediately adjacent to the exact term, which broke on a longer bolded phrase (it deleted the closing tag but left the opening one, corrupting the rest of the answer into a dangling, unclosed bold run); fixed to unwrap the whole enclosing <strong>...</strong> pair instead.
    2026-09-22
    v3.118.1

    --view-card is now genuinely transparent, not a tint

    • fix The previous --view-card (a semi-opaque rgba(255,255,255,.5)) still read as its own visible box on top of the page, reported live as "no extra background color". It's plain transparent now: the Sign in card, feed groups, and CVE/risk rows show the page's own background straight through, with only their border (or left-border color) marking them as a region at all.
    2026-09-22
    v3.118.0

    The header never moves; fewer, softer background colors

    • fix The pipeline diagram and question input used to visibly jump position when switching between the Ask home (a large 22vh top padding, "1/4 down the page") and every other view (a small sticky one). Now position:fixed at one constant, slightly tighter offset, the same on every view including the Ask home, per explicit request ("never move this up or down even if you load a view").
    • ux Reduced the number of distinct background colors on screen at once, per explicit request ("too many background colors", "white is too much contrast"). New --view-card token (a soft, semi-transparent tone) replaces a plain white or a colored tint (pink for a CVE row, amber for a risk row, a gray-blue chip tone for a feed group header) across feed groups, list rows, and the Account view's cards; each row's own left border still carries its real, distinct color, so nothing about what a color means was lost, only the flat background wash. Sidebar/modal chrome keeps the original solid --surface white, since a see-through background there would show scrolling content bleeding through underneath it.
    2026-09-22
    v3.117.1

    Guardrails tab knows about the new dual-source version check

    • ux The per-answer Guardrails tab's "Used for this answer" note now covers dualSourceVersionCheck (the server's new guardrail, see releasetrain-server), naming the live web version found when it disagreed with this system's own internal data.
    2026-09-22
    v3.117.0

    Fixed a stale URL bug; internal scroll per view; a signed-in indicator

    • fix Clicking Home (or the close button, or asking a new question) left a stale ?q=... from an earlier shared-search link sitting in the address bar indefinitely. setViewParam now clears it every time, and Home/the close button call it unconditionally instead of only when the view was "feed".
    • fix Restored each view's own internal scroll (Account, Docs, etc. already had a position: sticky panel sized against --topbar-h, but that variable read 0 once the topbar was hidden entirely outside the Ask home, so a view's content started right at the very top instead of below the sticky diagram+input). --topbar-h now also tracks that header's own real height, and the visible scrollbar on both the page and every view is hidden (scrolling itself is unaffected) per explicit request.
    • feat A small dot next to the sidebar's sign-in button: green while signed in, a subtle muted dot while signed out.
    • ux The Filters & Stats toggle is a real, clearly labeled Menu item now instead of a bare icon button that used to relocate into the sidebar footer, reported live as an unreadable mystery icon there.
    • ux Removed the same kind of plain descriptive sidebar blurb (no real control, just a paragraph) from the Credits and Changelog views that Account's own sidebar panel already lost; the real links/controls on each stay.
    • ux The page background is a step darker, and the pipeline diagram's own transparent background now sits closer to it.
    2026-09-22
    v3.116.0

    A close button to get back to the Ask home from any view

    • feat A small ✕ button, fixed top-right, shows on every view except the Ask home itself and returns to it in one click. Reported live: with the question input reachable from every view, and the sidebar's own nav links now collapsed under Menu by default, there was no fast way back to the home view from, say, Account.
    • ux Refactored the Home link, the Recent updates link, the ask submit handler, and this new close button to all share one deactivateActiveView() helper instead of four near-identical copies of the same if/else-if chain.
    2026-09-22
    v3.115.0

    Sign in card is compact and centered; less dead space on every view

    • ux The signed-out Sign in/Register card is capped to 420px and centered instead of stretching the full width of the (now wide) Account panel, reported live as "too cluttered": a two-field form had nothing to fill that width with, leaving a large dead gap beside it.
    • fix The question input's large top padding (22vh, so it sits "1/4 down the page" on the Ask home) no longer applies on every other view. It pushed real content on Account, Docs, and everywhere else down by roughly a fifth of the viewport for no reason, forcing a scroll to see content that would otherwise fit; now it's a small fixed padding everywhere but the actual Ask home.
    2026-09-22
    v3.114.0

    Fixed: asking from another view left it stuck behind the input

    • fix Reported live: asking a question while on Account (or Docs, Graph, Arch, CVE, Dashboard, Changelog, Credits, Release, or an eval view) left that view's own content sitting there below the input, with no answer visible at all. The question input is reachable from every view, but only the Ask home actually has a place to show the answer; submitting now returns to the Ask home first, the same deactivate-whatever's-active step the Home nav link itself already does.
    • ux The pipeline diagram's backing card is gone: transparent background, no border, just the colored role names and arrows, centered horizontally above the input. The active/done colors were also re-picked for this (a saturated but darker green) since the earlier bright neon green was tuned for the dark card that no longer exists.
    2026-09-22
    v3.113.0

    Pipeline diagram is now a persistent, plain-text strip above the input

    • feat The pipeline diagram is now one persistent strip pinned above the question input, top center of the right side, visible from page load in its dim "idle" state rather than only appearing once a question is asked. Replaces the earlier version, which lived inside the per-answer rail card.
    • ux Rebuilt as plain colored text joined by arrows ("Vendor → Rewriter → Retriever → Evaluator → Orchestrator"), no per-node box and no Mermaid dependency for this diagram any more. A node's elapsed time now shows inline in brackets, e.g. "Retriever (0.5s)", once it has run.
    • ux The sidebar's collapsed sections (Menu, Model & pipeline, Advanced checks, and every other .sb-details group) no longer show a filled background chip, just the label and the divider line between entries, per explicit request.
    • ux The sidebar footer is a row again, not a column: the version number sits on the left, sign-in on the right, and the sign-in button itself is now a small outlined pill instead of a big solid-fill one.
    • fix Signing in (or visiting Account) no longer changes anything in the left sidebar; only the right side's content changes now. The Account view's own sidebar panel (a plain "sign in to save preferences" blurb with no real controls) is gone.
    2026-09-22
    v3.112.0

    The pipeline diagram moves to the top, in a "hacker" green-on-black palette

    • ux The Rewriter/Retriever/Evaluator/Orchestrator workflow diagram now sits right under the question, above the Answer/Sources/Benchmark tabs, instead of living only inside the Answer tab's own panel. It stays visible and animating regardless of which tab is selected.
    • ux Restyled the diagram as a dark "hacker terminal" card: a node not yet reached stays dim, unlit green; the one node currently running lights up in classic bright terminal green; a finished node settles to a steadier green. The connecting arrows, the "retry" edge label, and the live phase caption below the diagram all match the same palette now instead of mermaid's own light-theme defaults, which were unreadable against the new dark card.
    2026-09-22
    v3.111.0

    Everything on the left collapses by default; every view can scroll

    • ux The sidebar's nav links and the Model & pipeline selects are now their own collapsed-by-default sections (matching Advanced checks/Guardrails), and every existing collapsible group in the sidebar (Layers, the Docs live-stats groups, API Reference) starts closed too, so the sidebar reads as a short list of headings instead of everything expanded at once.
    • fix The sidebar footer (version number, sign-in) now actually sits at the sidebar's true bottom edge on a wide screen; it used to land right under the nav with a lot of blank space below it, since position:sticky alone only engages once there's something to scroll past.
    • fix Every view (Docs, Account, Graph, etc.) can scroll again when its content runs taller than the window. Page scrolling used to be Ask-home-only; Docs and Account in particular had no scroll container of their own, so their own content past the first screenful was simply unreachable.
    • fix Fixed a real layout bug hit while building the above: moving the Model & pipeline selects into their own collapsible section exposed a case where the sidebar's own column layout, combined with a leftover row-wrap rule, was wrapping closed accordions into side-by-side columns instead of stacking them.
    2026-09-22
    v3.110.0

    Sidebar footer cleanup; a real 502 handled gracefully; a darker background

    • ux Guardrails is hidden entirely while signed out now: everything it showed for a signed-out visitor was a disabled, non-actionable checkbox or a second "Sign in" duplicating the one at the sidebar's own bottom. It reappears the moment there's a real account to save a preference to.
    • ux The sidebar footer is a column now, not a row: the version number (small and muted, not the bold brand-colored look it keeps in the topbar on a narrow screen) sits above sign-in, which is the actual bottom-most element, per explicit follow-up requests.
    • fix A 502 from Nginx (the Node backend not responding) served its own HTML error page, which a plain res.json() in the Ask submit handler choked on with a raw "Unexpected token '<' ... is not valid JSON" shown in the answer modal. New askSafeJson checks the content-type first and fails with a message someone can actually read and act on instead.
    • ux #askIntentBadge ("Version question", etc.) moved to its own left-aligned row directly under the input, out of .ask-input-row itself, per explicit request; it no longer relocates on a wide screen, so it always stays right under the input regardless of width.
    • ux --bg darkened a step (#f1f4f8 to #dfe3e8) per a follow-up request; --surface stays white so cards and the sidebar still read as a lighter layer on top of it.
    • ux Removed the "βœ… End of results" message at the bottom of an exhausted feed; it's a blank sentinel now instead, same treatment this file's own comment already gives the "no results" case right next to it.
    2026-09-22
    v3.109.0

    The topbar is gone; version and sign-in live at the sidebar's bottom; every view uses the full right side

    • ux .brand (the version number), #filtersToggleBtn and .topbar-right (sign-in/account) move out of the topbar into #sidebarFooter, sticky to the bottom of the persistent sidebar, at the same width as every other relocation in this file. With nothing left in it, .topbar itself is hidden entirely at this width, so the right side is just the question input, per explicit request. Below 900px, all three stay in the topbar exactly as before.
    • fix Every view other than the Ask home and the feed (Docs, Graph, Arch, CVE, Risk Report, Account, the eval tools, etc.) was silently squeezed into a 2/5-width column at this same breakpoint, beside an .ask-rail-col that had nothing relevant in it for those views. .feed-main is full width by default now; only body.view-home still enables the rail, for the inline answer beside the prompt it's actually for.
    • ux #askOptionsPanel's selects and toggle groups, and the "Advanced checks" list, now stack one per line at full width inside the sidebar, instead of the row/wrap layout built for the old, wider topbar. Guardrails already rendered as a column and needed no change.
    • ux Shortened the question input's placeholder to one real example ("What's the latest Linux version?") instead of a comma-separated list plus a longer sample question.
    2026-09-22
    v3.108.0

    Ask controls move to the sidebar; the topbar shrinks to just the prompt

    • ux On the same 900px-and-up screen where the sidebar is now persistent, the model/size/pipeline selects, Advanced checks and Guardrails (#askOptionsPanel) live right below the nav links in the sidebar now, one constant home regardless of whether the home view or an existing answer is showing (previously two different spots depending on which). The now-empty #askHomeControls aside, and its own now-unreachable "Options" heading, are removed.
    • ux The question input (#askForm) moves out of the fixed topbar into the normal page flow at this same width, landing about a quarter of the way down the page instead of glued to the very top edge. The topbar itself shrinks to just the brand and the sign-in pill. Below 900px, both the controls and the input stay exactly where they were: in the topbar, always reachable without scrolling.
    2026-09-22
    v3.107.0

    The whole page splits left/right on a wide screen: a persistent nav column, everything else beside it

    • ux At the same 900px breakpoint the answer rail already uses, the ☰ menu (#sidebar) stops being an overlay drawer that covers the page while open and becomes a persistent left column instead; the topbar (including the question input row) and the rest of the page shift right to sit beside it. #navToggle hides, since there's nothing left to toggle. The sidebar's own content (nav, filters, stats, about, account, eval links) is unchanged. #filtersPanel, the other, unrelated drawer on the opposite edge, keeps its normal toggle behavior; it shares #sidebar's base .sidebar class for styling only, so this rule is scoped to the id specifically to avoid also forcing that one open.
    2026-09-22
    v3.106.0

    Cold color palette; sign-in moved to the topbar; the Ask home is just the input; answers type in

    • ux Superseded the previous release's warm cream/terracotta palette with a cold, Gemini-like one: a cool gray page background and a real Google-blue accent (#1a73e8). Same scope as before, site chrome and the Ask UI, CVE view's own scoped tokens, and every data-visualization view's existing semantic colors untouched.
    • ux The "Sign in to ask a real question" call-to-action, and the description paragraph and four sample questions above it, are gone from the middle of the Ask home. Sign-in now lives as a single pill in the topbar's top-right corner (#topSignInLink, opposite the existing signed-in account chip it swaps places with), so the home view, with nothing asked yet, is just the question input and the pipeline/model controls.
    • feat A finished answer now types in a few words at a time instead of appearing as one block, the same "watch it write" feel most chat interfaces have. Runs as a pure animation over the already-rendered, already-formatted answer (bold, links, etc. all stay intact); nothing about how the answer itself is built changed, and it plays once per new answer, never on a tab switch back to one already shown.
    2026-09-22
    v3.105.0

    Warmer color theme; the five per-question ablation checks are collapsed by default

    • ux Switched the site's color palette from the earlier cool sage-green background and blue accent to a warm cream background with a terracotta accent, closer to Claude's own look. Only site chrome and the Ask UI changed: the CVE view got the matching scoped update, and every data-visualization view (Risk Report, component graph, network graph, Mermaid diagrams, Chart.js series) keeps its own existing semantic colors untouched, per this file's own "meaning over hue" reasoning for those. Added one low-specificity default (a { color: var(--brand) }) so a plain, unstyled link (e.g. the guardrails panel's "Sign in to change these") picks up the new accent instead of the browser's own default blue; every already-styled link keeps overriding it exactly as before.
    • ux The five per-question ablation checkboxes (Vendor check, Temporal filter, Intent filter, Resolve vendor, Resolve temporal constraints) are now collapsed by default behind a new "Advanced checks" <summary>, the same .sb-details component Guardrails already uses (which stays open, unchanged). Reported as still looking cluttered even after the model/size/pipeline selects and Guardrails were already given their own row; this is the technical, rarely-touched part of that same row. Every checkbox still defaults checked and is sent exactly as before, open or closed.
    2026-09-22
    v3.104.0

    Anonymous questions: a small free quota before sign-in

    • feat A signed-out visitor may now ask a small, admin-configured number of real questions before POST /api/ask falls back to requiring sign-in (new anonymousAskEnabled/anonymousAskLimit fields on GET/PUT /api/admin/settings, both editable from the Account view's admin Settings panel). Ships disabled in effect (limit 0), so this changes nothing until an admin raises it. Enforced server-side only, bucketed by IP address and UTC calendar day; a client-supplied count is never trusted for it.
    • feat The Ask intro panel now shows "N of M free questions left today" next to the sign-in button while signed out and the feature is on, backed by the new public GET /api/ask/anon-quota. Once the free questions are used up, the sign-in alert names that specifically instead of the generic "sign in to ask a real question" message.
    • docs API Reference: documented the new GET /api/ask/anon-quota route, and noted the new anonymous-question fields on the existing GET/PUT /api/admin/settings and POST /api/ask entries.
    2026-09-19
    v3.103.5

    Short answer is one brief sentence; comparison entities stop at "with", "on", "in"

    • ux The Short answer tab now gives only the claim: parentheticals, reason clauses ("because", "since", "which") and dates ("released on ...", "as of ...") are dropped, and it is capped near 140 characters. "I don't know." no longer drags its explanation along; the Answer tab keeps every detail.
    • fix The comparison-question entity trailer regex (ASK_COMPARISON_TRAILER_RX, mirrored from the server's COMPARISON_TRAILER_RX) now also cuts at with, on, in, using, under, inside, within, via and running, so "Flask or Django with a database" compares Flask and Django, not "django with". The server side resolves every component type (database, browser, os, IDE, LLM and the rest) into real components for a stack recommendation.
    2026-09-19
    v3.103.4

    How it works and the feed links removed

    • ux Removed the How it works view (?view=howto), its menu and home links, and the paper-style tabs behind it (Intro, Related, Method, Result, Discussion, References, plus the pipeline overview diagram and its wiring). Mermaid now loads only when an answer's workflow diagram needs it, not at page load. The content is in git history at v3.103.3.
    • ux Removed the answer rail's × close button and the answer card's outline, so the answer sits higher, right under the prompt. The rail header is hidden on the Ask home, where the options live in the left column.
    • ux Removed the links that jumped to the feed from the Ask home: "Show these in the feed" under an answer, "Browse all", and the links on each latest-updates row. The feed is reached from Recent updates in the menu.
    2026-09-19
    v3.103.3

    No duplicate toggles under Guardrails

    • ux "Require known vendor", "Recent window only" and "Classify question intent" are gone from the options column's Guardrails block: they were the same settings as the Vendor check, Temporal filter and Intent filter checkboxes above them, which are sent with every question and always win, so changing the Guardrails copy had no visible effect. Only "Retry new terms" remains there.
    2026-09-19
    v3.103.2

    The Ask home and How it works scroll the page

    • ux On the Ask home and the How it works view the page itself now scrolls vertically when the content is taller than the window (html.page-scroll: overflow-y:auto; overflow-x:hidden), so a long answer or tab is no longer cut off. Horizontal scrolling stays off. Other views keep their own scrolling panels.
    2026-09-19
    v3.103.1

    Guardrails you can change, in three words; feed view is just the feed

    • ux The Guardrails block in the options column is open by default and lists only the checks a visitor can change, each as a short label ("Require known vendor", "Recent window only", "Classify question intent", "Retry new terms"), with the full description on hover. The mandatory, admin-set checks are read-only, so they now appear only in each answer's existing Guardrails tab.
    • ux ?view=feed (and a bare ?q= link) shows just the feed: the Ask panel and answer no longer sit beside it. Asking a question from the feed or How it works view returns to the Ask home, where the answer shows.
    2026-09-19
    v3.103.0

    Short answer tab

    • feat A Short answer tab now comes before Answer on every single-pipeline answer and is the one shown first: one sentence that answers the question. A comparison states its verdict outright (for example "Zoom on Firefox looks like the lower-risk choice."); anything else uses the answer's own first sentence, with markdown and citation markers removed, capped near 220 characters. There is no extra model call. "Show full answer" keeps you on the Answer tab, and the workflow diagram is painted again when Answer is opened.
    • ux The paper-style tabs (Intro, Related, Method, Result, Discussion, References) are now their own view, How it works (?view=howto), linked from the Ask home and the menu, instead of a collapsed section on the home page. The markup did not move, so the tab wiring is unchanged; Home and the brand link leave it.
    2026-09-19
    v3.102.1

    Ask home uses the full width, controls on the left

    • ux The Ask home is no longer capped at 860px: a left column holds the model, size and pipeline selects plus the toggles (including Resolve vendor and Resolve temporal constraints), and the prompt, samples, latest updates and answer take the rest of the width. The controls are visible before the first question instead of only appearing once an answer exists. relocateAskOptionsPanel moves the same panel node into #askHomeControls on the Ask home and back into the answer header elsewhere, so no listener is lost.
    2026-09-19
    v3.102.0

    Ask is now the home page on a wide screen

    • ux On a screen 900px or wider, the home page is one centered column: the prompt, four sample questions, a strip of the five latest updates, and the answer once a question is asked. The two-column layout with the feed on the left is gone from the home page. The panel's paper-style tabs (Intro, Related, Method, Result, Discussion, References) moved under a collapsed "How it works".
    • feat The feed is its own view, Recent updates in the menu (?view=feed); a link with ?q= still opens the filtered feed. A bare vendor or category lookup (for example "mysql") opens it too, and each answer offers "Show these in the feed" instead of silently filtering a feed that is no longer on screen.
    • ux Below 900px nothing changes: the feed is still the home page and answers still use the modal. The smoke tests now check the Ask home and the feed view separately.
    2026-09-19
    v3.101.0

    Resolve vendor and Resolve temporal constraints toggles

    • feat Two new Ask checkboxes next to Vendor check, Temporal filter and Intent filter, both on by default. Resolve vendor: a comparison question that names a component type, such as "Do you recommend browser-based Zoom or Teams for my important meeting?", now resolves "browser" to the real tracked browsers, scores each with the same formula as the two apps, and recommends a stack (the lower-risk app on the lowest-risk browser). The type qualifier is also stripped from the app names, so "browser-based zoom" resolves to Zoom. Resolve temporal constraints: a relative phrase such as "last 3 weeks", "past few days", "yesterday" or "this month" becomes the search window itself instead of falling back to the default recent window.
    • ux The query preview strip now shows the resolved window, for example "last 21 days, since 2026-08-29 (from "last 3 weeks")", and the flags are sent on both POST /api/ask and GET /api/ask/compare. extractRelativeWindowDaysClient mirrors the server's extractRelativeWindowDays by hand.
    • docs The Docs view describes both toggles and the new resolvedComponents/stack result fields.
    2026-09-17
    v3.100.1

    Ask sign-in CTA now hides once you're actually signed in

    • fix Reported live right after it shipped: the new "Sign in to ask a real question" button kept showing even after signing in. It was wired to uaRender(), which only runs after a login/logout submit or opening the Account view, not on a fresh page load with an already-valid session, the most common case for a returning signed-in visitor. Now also checked once at page bootstrap.
    2026-09-17
    v3.100.0

    Ask panel: paper-shaped tabs, prominent sign-in

    • feat The "About Ask" sidebar panel is now six tabs, structured like a paper (Intro, Related, Method, Result, Discussion, References), instead of one long flowing section. Existing content (the Pipeline diagram, the Multi-agent concept explanation, the Auto routing table, the related-work comparison table) moved into whichever tab it actually belongs under; new Result (the paper's own reported +17.2% 1-agent vs 4-agent retrieval-quality delta and zero-hallucination result), Discussion (known limits, how the Guardrails registry mitigates them), and References (the two papers this pipeline directly implements, plus the concurrent related work) tabs cover ground this panel never had anywhere before.
    • fix Reported live: the small inline "sign-in" text link was too easy to miss next to the rest of the panel's plain copy, given signing in is what unlocks the whole Ask feature. Replaced with a full-width call-to-action button, shown above the tabs so it's visible regardless of which one is open.
    2026-09-17
    v3.99.1

    Feedback Loop tab and preset badge fixes

    • fix Reported live: the Feedback Loop tab looked unchanged after last update's new Rewriter/Retriever/Evaluator/Orchestrator guardrails, since it only ever read the numeric feedbackLoopCount field, which only the two genuinely delegated presets (Multi-agent, delegated / Multi-agent, feedback loop) set. It now reports every pipeline-level retry guardrail that applies to this specific answer, with a plain explanation when a preset (e.g. Multi-agent, fixed) doesn't use a separate Rewriter/Retriever/Evaluator loop at all.
    • fix Reported live: a plain "recent CVEs affecting MySQL" question run under Multi-agent (fixed) showed the badge "Multi-agent, fixed · 1 agent", reading as a flat contradiction the same way a comparison question's badge already had one fix for. Multi-agent (buggy)/(fixed) are genuinely single-continuous-loop architectures despite their own name (the paper's own naming: "buggy"/"fixed" describes that one loop's retrieval bug, not delegation), so the agent-count suffix is now suppressed for them instead of contradicting the label.
    2026-09-17
    v3.99.0

    Feedback loops for every role: Rewriter, Retriever, Evaluator, Orchestrator

    • feat The delegated multi-agent pipeline's single hardcoded retry (Retriever, then Evaluator again) is now an admin-configurable ceiling (new guardrail, "Retriever/Evaluator retry ceiling") instead of a fixed one-shot retry, and the per-answer Feedback Loop tab shows the real round count for that specific answer.
    • feat New optional guardrail, "Let the Rewriter try different search terms on retry": off by default, a signed-in user can opt in for their own questions. When on, a retry regenerates a genuinely new set of search terms from the Rewriter agent instead of reusing the original terms with just the Evaluator's retry hint spliced on.
    • fix New mandatory guardrail, "Retry a malformed Evaluator response": a response that failed to parse as the required JSON shape was previously treated the same as a real "insufficient" verdict, with no distinction between "the model judged this insufficient" and "the model's response was garbled." Now retried up to an admin-configurable ceiling before being accepted.
    • feat New mandatory guardrail, "Regenerate a hedge answer written despite real evidence": the delegated pipeline had no rescue at all for an Orchestrator hedge ("I don't have enough evidence") written despite real, structured evidence already collected, unlike the single continuous-loop pipeline, which already had one, just unconditionally. Both pipelines now share the same named, admin-configurable check.
    2026-09-17
    v3.98.1

    Comparison answers: fixed counts, and a new guardrail

    • fix Reported live: a comparison answer stated "Teams recorded 8 known vulnerabilities" when the real tracked total was 23. The server's evidence gathering was reading its own capped, 8-document fetch (sized to keep the LLM's prompt small) as if it were the true count; comparison answers now state the real, uncapped count of vulnerabilities, updates, and community reports.
    • feat New mandatory guardrail, "Verify and correct the stated time window in comparison answers": a free-tier model can restate the recency window it was given wrong (seen live stating "a 90-day window since June 19" when the real window searched was 3 days since Sep 14); the real window is now appended deterministically instead. Shows up on that answer's own Guardrails tab when it fires.
    2026-09-17
    v3.98.0

    A Feedback Loop tab, next to Guardrails

    • feat The answer rail gets a sixth tab, Feedback Loop: this answer's own rating, real user-rating stats for this question's vendor across every user, and whether an admin-set threshold currently flags that vendor as running negative. Read-only for now (turns the thumbs-up/down rating collected since Ask launched, but never read back anywhere, into an actual signal); it does not yet change how a future answer for a flagged vendor gets produced.
    • feat New "Feedback Loop" section in the Account view's admin area, next to Guardrails: an editable minimum-sample-size and negative-rating-percentage threshold (with an enable toggle), backed by the server's feedbackThresholds field on the existing GET/PUT /api/admin/settings.
    • feat The Feedback Loop tab also shows this exact answer's own loop count: how many retrieval/evaluation rounds the delegated multi-agent pipeline actually took (1 normally, 2 when the Evaluator judged the first pass insufficient and multi_agent_feedback's own retry fired), a new structured feedbackLoopCount field instead of that fact only living inside a free-text summary.
    2026-09-17
    v3.97.0

    Server Fault split out from the community counts

    • feat releasetrain-bot's new serverfault.py posts into the same shared community collection as Reddit and Stack Overflow, tagged its own source. The admin dashboard's profile stat row, System overview cards, and bot-health freshness list now show Server Fault as its own line instead of it silently landing inside the Reddit count.
    • fix The server's reddit/stackoverflow split counted "Reddit" as everything that wasn't literally source: stackoverflow, so a doc from any other source landed in the Reddit bucket by default. Reddit, Stack Overflow, and Server Fault are now each counted explicitly across /api/reddit/count and every /api/aggregate/reddit/* endpoint.
    2026-09-16
    v3.96.1

    Admin traffic gets its own rate limit

    • fix Reported live: "Too many requests" on the Vendor catalog section, since the Account view's admin panel alone fires 6+ requests just loading one tab (dashboard, settings, guardrails, bot-cadence, vendor-aliases, users), sharing the same rate-limit bucket as anonymous public traffic. A signed-in admin now gets a separate, higher ceiling (the new Admin rate limit setting), so normal active admin use no longer competes with public traffic for the same budget.
    • fix The generic Settings list tried to render the guardrails array (added last update) through its plain number/text/checkbox fallback, showing a garbled "[object Object],[object Object]" row. The dedicated Guardrails section already renders it properly; the generic list now skips this one key.
    2026-09-16
    v3.96.0

    A Guardrails tab on every answer

    • feat The answer rail gets a fifth tab, Guardrails, next to Answer/Sources/Benchmark/Model vs Rules: the same Mandatory (admin-set, disabled here) and Optional (a signed-in user's own saved preference) list already in the Ask options panel, plus, unique to this tab, a plain-language note on any guardrail that actually did something for THIS specific answer (dropped a suspicious search result, verified a version number, forced a live web search, blocked a leaked answer), with a link that jumps to the affected source in the Sources tab when there is one.
    • fix The server's own per-run "did this guardrail apply" flag was keyed only on whether the answer's text got rewritten, which missed the common case where a guardrail's seeded evidence alone already steered the model to the right answer with no rewrite needed. Verified live: "What is the latest version of MySQL?" with versionCorrectionRewrite off produced an unverified answer with no guardrail tag; re-enabled, the same question was correctly tagged.
    2026-09-16
    v3.95.0

    Guardrails: a client UI for the server's new safety/correctness registry

    • feat New Guardrails section in the Account view's admin area, alongside the other admin sections: every guardrail releasetrain-server now tracks (backed by the existing GET/PUT /api/admin/settings, which now also carries a guardrails array), split into Mandatory (an admin can turn one off, at the cost of a specific documented safety/correctness fix) and Optional (the admin-set default a signed-in user may override for themselves), each with a checkbox and an explicit Save button.
    • feat New collapsed-by-default Guardrails panel in the live Ask options row, right next to the existing Vendor check/Temporal filter/Intent filter toggles (which are unchanged and serve a different, existing purpose: quick one-off per-question testing). Backed by the new public GET /api/guardrails: every mandatory guardrail is listed read-only with a lock icon, and every optional one shows a checkbox reflecting what's actually in effect for the viewer right now. Signed in, that checkbox is yours to flip, saved immediately to your account via the new GET/PUT /api/account/guardrails; signed out, it's shown disabled at the admin default, with a link to sign in and customize it.
    • docs API Reference: documented the new GET /api/guardrails and GET/PUT /api/account/guardrails routes, and noted the new guardrails field on the existing GET/PUT /api/admin/settings entries.
    2026-09-15
    v3.94.0

    Feed panel header: fix crowding at the new 40% column width

    • ux Reported live: at the left column's new, narrower 40% width, the "Recent Updates" heading wrapped onto a second line ("components)" alone) while the Sort dropdown and "Expand all" button stayed full size beside it, reading as cramped. The sort dropdown's own option text dropped its redundant "Sort: " prefix (e.g. "Sort: Most activity" → "Most activity", still exposed to screen readers via the select's own aria-label), the button's padding tightened to its own instance, and the heading/controls all shrank a notch, so the row comfortably fits at this width.
    2026-09-15
    v3.93.0

    Layout: give the right rail more room

    • ux The two-column layout (main content left, the Ask intro/answer rail right) is now a 40/60 split instead of an even 50/50, so the rail's own wider content (the pipeline diagram, the Model vs Rules table) has more room to breathe.
    • ux The narrower left column's base font size drops slightly (13px to 12px) to keep its plain-prose content comfortable at the new width.
    2026-09-15
    v3.92.0

    Workflow diagram: fix a "Rewriter ran" contradiction, plus a CVE-count highlight

    • fix The live per-answer workflow diagram mapped vendor resolution (a plain catalog lookup, on every preset) onto the same "Rewriter" node as a real Rewriter LLM call, so a single-loop preset (Single-agent, Multi-agent buggy/fixed, no real Rewriter step at all) still showed a "Rewriter" box completing with a real elapsed time, flatly contradicting the Model vs Rules tab's own "this preset's architecture never includes a separate Rewriter step" right next to it. Vendor resolution now gets its own node in the diagram, ahead of Rewriter.
    • ux Reported live: a single-loop run's Model vs Rules tab typically checks Model on both Retriever and Orchestrator, which reads as "2 agents" sitting right under the answer badge's own "1 agent." Both numbers are correct, they just answer different questions (roles the model fulfilled vs. distinct agents involved); the tab now says so in a short note rather than leaving the two counts to silently disagree.
    • feat The Ask pipeline diagram already added to the Docs page is now also shown in the Ask intro sidebar, before a question is asked.
    • feat A CVE question's answer now highlights the stated count ("six CVEs") when the model's own text gives one, rather than an arbitrary single CVE ID plucked out of a list of several: the count is the fact that actually answers an "are there any recent CVEs" question. Falls back to a single ID, then a version number, exactly as before, when no count is stated.
    2026-09-15
    v3.91.0

    Docs: a Mermaid diagram for the Ask pipeline

    • feat New flowchart at the top of the Ask (AI Q&A) docs section: how a question's classified intent picks its path (declined, the fixed comparison evidence gather, or the general pipeline), and, for the general path, whether the preset's architecture runs the Rewriter/Retriever/Evaluator/Orchestrator as genuinely separate model calls (with the feedback-loop retry edge) or one continuous tool-use loop.
    • fix Every Mermaid diagram in the Docs page (this new one and the six existing System Architecture diagrams) now actually stretches to fill its column: Mermaid stamps its own computed width as an inline style="max-width:NNNpx", which silently won over the page's own width:100% rule at equal specificity, same root cause already fixed for the live Ask answer workflow diagram.
    2026-09-15
    v3.90.0

    Settings: hide the three Eval tool nav links entirely

    • feat Three new Settings entries: Show Eval Rewriter/Evaluator/Orchestrator in the menu, using the same view-visibility mechanism already covering Graph/Arch/CVE/Risk Report/Docs/Changelog/Credits/Release. Hides the nav link entirely, for every viewer including admins, all default to visible. Separate from each tool's own API access level (Disabled/Admin only/Any signed-in user/Public): hiding the nav link doesn't change whether the raw endpoint still responds.
    2026-09-15
    v3.89.1

    Ask intro panel: related work as a table, not a paragraph

    • docs The "Related work" section now reads each paper's actual text (fetched live, not just summarized secondhand) into a compact 5-column table: Paper, Goal, Similar, Different, Example question, one key word bolded per cell. Replaces the earlier single paragraph with the same five papers now individually comparable at a glance.
    2026-09-15
    v3.89.0

    Ask intro panel: multi-agent concept and related work

    • docs Two new sections in the Ask feature's own intro sidebar (shown before a question is asked): "Multi-agent concept," explaining which presets genuinely run four separate model calls versus simulating the same roles in one continuous tool-use loop, and pointing to each answer's own Model vs Rules tab for the specific-run truth; and "Related work," naming the five multi-agent RAG papers this system's own architecture and Rewriter fix relate to, each linked to its arXiv page.
    2026-09-15
    v3.88.1

    Eval Rewriter: show the source URL, not the title

    • ux Eval Rewriter's With/Without/Common source lists now show each result's raw URL instead of its title, so a reader can see exactly where a result came from at a glance in this debugging/comparison view. The main answer's own Sources tab is unaffected and still shows the title.
    2026-09-15
    v3.88.0

    Account: rate limiting, email allowlist, bot cadence, and vendor catalog admin controls

    • feat New Settings entry: global rate limit (requests/min per IP), applied to every API route except /api/health.
    • feat New Settings entry: allowed registration email domains, a comma-separated allowlist. Any .edu (or .edu.<country>) address is always allowed regardless of this list.
    • feat New Bot health thresholds section in the Account view's admin area: an editable per-bot cadence override (with a "Reset to default" option) for every bot /api/admin/bot-health tracks, backed by the server's new GET/PUT /api/admin/bot-cadence.
    • feat New Vendor catalog section in the Account view's admin area: an alias manager (add/list/delete a manual vendor-name correction for the automatic catalog) plus a manual gap-fill trigger, backed by the server's new /api/admin/vendor-aliases and POST /api/admin/vendor-gap-fill.
    • docs API Reference: documented all 6 new/changed admin routes above, and noted the two new Settings fields on the existing GET/PUT /api/admin/settings entries.
    2026-09-15
    v3.87.0

    Docs: coverage for auth, users, bookmarks, Ask, admin, and eval routes

    • feat The API Reference (Docs view) now documents roughly 40 previously-undocumented routes: authentication (register/login/logout), user accounts, bookmarks, the full Ask AI Q&A surface (ask/compare/history/rate/presets/providers/quota), the admin eval tools (Rewriter/Evaluator/Orchestrator), the knowledge-base release-publishing endpoints, search-event tracking, the admin dashboard endpoints (bot health, source attribution, storage, overview, settings), nav-view visibility, a Reddit post's community-sentiment poll, question typeahead, and a missing CVE-count-by-day aggregation. Every write-access endpoint now shows a "requires login" / "admin only" / access-level tag reflecting its actual auth middleware.
    2026-09-14
    v3.86.0

    Settings: per-endpoint access control for eval tool APIs

    • feat Three new Settings panel entries: Eval Rewriter/Evaluator/Orchestrator API access, each a Disabled / Admin only / Any signed-in user / Public choice, backed by releasetrain-server's new admin-configurable access-level mechanism (no code deploy needed to change it). All three default to Admin only, matching their previous hardcoded behavior exactly. This is separate from, and does not affect, the Eval tools' own admin-only nav link visibility.
    2026-09-14
    v3.85.3

    Account: a System overview card for vendor gap-fills

    • feat New "Vendor gap-fills" card in the admin System overview panel, backed by a new GET /api/admin/overview field: how many times ask.js's automatic wikipedia.py fallback (triggered when a real, web-verified vendor still has zero tracked evidence) actually resolved, plus the 10 most recent attempts with their outcome. This data was already being logged to a bot_gap_log collection; nothing ever read it back until now.
    2026-09-14
    v3.85.2

    Answer badge: fix "Multi-agent Β· 1 agent" contradiction

    • fix A comparison question always collapses to one write-up call regardless of which preset is picked, including under Auto (which itself picks Multi-agent, feedback loop for a comparison question), so the badge could read "MULTI-AGENT, FEEDBACK LOOP · 1 AGENT": naming the picked-but-unused preset right next to the real agent count, reading as a flat contradiction. The badge now says "Comparison" instead of the preset name for this case; which preset was actually selected, and the real reason it collapsed, stays fully explained on the Model vs Rules tab.
    2026-09-14
    v3.85.1

    Answer badge: no round brackets, shows agent count

    • fix The pipeline badge next to a question (e.g. "(MULTI-AGENT (FEEDBACK LOOP))") nested a bracket inside a bracket once a preset's own name carried a parenthetical qualifier. Preset names now use a comma ("Multi-agent, feedback loop") and the outer wrap is dropped entirely; the badge's own bold, uppercase, colored styling already sets it apart from the question next to it.
    • feat The badge now also states how many distinct model calls actually produced this answer (e.g. "Multi-agent, feedback loop · 4 agents"), computed per run rather than assumed from the preset name: a comparison question always collapses to 1 regardless of preset, a genuinely delegated architecture is 4, everything else is 1, plus 1 more when a real web-verification call fired.
    2026-09-14
    v3.85.0

    Model vs Rules: fix a comparison-question contradiction

    • fix A comparison question ("Firefox or Chrome?") always runs a genuinely different, fully deterministic evidence pipeline, regardless of which preset is picked, but the table's fallback text didn't know that and blamed "single-agent architecture" for the missing Rewriter/Evaluator step even under Multi-agent (delegated). Every row now checks res.intent for this case and explains the real reason.
    • feat Every row now checks at least one box: a step that never ran still had something decide that deterministically (the preset's own architecture, an intent that skips agentic steps entirely, or an abstain gate), so an honest 0/0 is now reserved only for a role genuinely never reached at all (an opinion question bypassing vendor resolution, or vendor checking turned off).
    • fix Vendor resolution's Model checkbox now also checks when a real web-verification call ran but came back negative (previously only a successful match counted), and Retriever no longer claims the model chose search tools for a comparison question, which is entirely fixed and deterministic.
    2026-09-14
    v3.84.3

    Workflow diagram: drop its placeholder min-height once loaded

    • fix .ask-workflow-diagram's min-height (there only to avoid a layout jump while mermaid.render() is still loading) stayed in effect even after the diagram finished rendering, keeping the container floored at a fixed height regardless of how short the actual (now viewBox-tightened) content was. Cleared back to 0 the moment real content lands, so the answer text below moves up to meet it instead of leaving a fixed gap on top of the v3.84.2 viewBox fix.
    2026-09-14
    v3.84.2

    Answer card: close the gap under the workflow diagram

    • fix Mermaid's own viewBox reserved space below the rendered Rewriter/Retriever/Evaluator/Orchestrator row (its default padding, plus room for the curved "retry" edge), which scaled up along with everything else once stretched to the card's full width and read as a real gap between the diagram and the answer text. The viewBox is now re-tightened to the diagram's own rendered bounding box after every render.
    • fix The phase caption under the diagram (e.g. "Generating answer... 1.4s") no longer reserves its min-height/margin once it's cleared back to empty at the end of a run, which was adding its own fixed gap on top.
    2026-09-14
    v3.84.1

    Model vs Rules: fix vendor resolution's checkboxes

    • fix The Vendor resolution row hardcoded both the Model and Rule checkboxes checked, even for a plain catalog-match vendor, which involves no model call at all. Now Model is checked only when the vendor was actually run through a real web-verification LLM judgment call; a catalog hit alone checks Rule only.
    • fix The Meaning column now states the reason for each box that is actually checked (labeled "Model:"/"Rule:"), instead of one sentence describing the row regardless of which boxes are checked.
    2026-09-14
    v3.84.0

    Ask: a "Model vs Rules" tab on every real answer

    • feat New fourth tab on the answer rail, next to Answer/Sources/Benchmark: a table naming each role (vendor resolution, Rewriter, Retriever, Evaluator, Orchestrator) with a Model column and a Rule column (both plain disabled checkboxes, an indicator not a setting) and a plain-language Meaning column explaining what happened for either case. Driven entirely off this specific answer's own real fields, not a fixed description of the architecture: single_agent correctly shows no separate Rewriter/Evaluator step, a web-verified vendor shows the real search that confirmed it, and an Evaluator/answer override shows the actual reason it fired.
    • fix Server-side: runAsk and runDelegatedAsk already computed whether the Evaluator's verdict or the final answer text got overridden by a deterministic check, but never exposed it. Threaded through as evaluatorRan/evaluatorOverridden/evaluatorOverrideReason/answerCorrected, same pattern as vendorWebVerified.
    2026-09-13
    v3.83.0

    Two new admin-only eval pages: Evaluator and Orchestrator

    • feat πŸ§ͺ Eval Evaluator: runs the real retrieval path, then shows the Evaluator's own raw sufficiency verdict next to the final verdict after the deterministic override (a real search_web hit, or a real release document naming the vendor and version) can force it to sufficient, exactly the same two checks and wording production uses.
    • feat πŸ§ͺ Eval Orchestrator: same retrieval and Evaluator gate, then the Orchestrator's own raw generated answer next to the final answer after the deterministic version-correctness rewrite can replace it. An abstained Evaluator verdict shows the abstain message directly, since there's nothing for the Orchestrator to write from, same as production.
    • ux Both reuse Eval Rewriter's own "Sample a real question," flat source list, and vertical-only-scroll treatment, so all three eval pages look and behave the same way.
    2026-09-13
    v3.82.6

    Rewriter Eval: flat source lists, ellipsis actually works

    • ux Removed the redundant "Original:" line from the Prompt section (the question box right above it already shows it); the section is just the Rewriter's actual output now.
    • ux "Only with/without Rewriter" shortened to "With Rewrite"/"Without Rewrite", and their source lists (plus Common's) are now flat, with no separate Documented/Discussion group heading on top: each item's own icon (πŸ“¦/πŸ”΄ vs πŸ’¬/🟧/🌐) already says which one it is. New shared askRenderSourceItems helper, factored out of askRenderSources' own per-item rendering.
    • fix A long source title inside a Delta column could grow that whole column wider than intended instead of actually truncating with an ellipsis (a CSS Grid item's default min-width is auto, not 0 like a flex item's, so there was nothing to truncate against). Ellipsis truncation now works as originally intended.
    2026-09-13
    v3.82.5

    Rewriter Eval: shorter labels, vertical-only scroll

    • ux Prompt section's labels shortened to "Original:" and "Rewriter Prompt:", dropping the explanatory parentheticals now that the section's own heading already makes clear what each line is.
    • fix The view only ever scrolls vertically now; anything long enough to otherwise force a sideways scrollbar breaks onto another line instead.
    2026-09-13
    v3.82.4

    Rewriter Eval: cut the duplication, add a Prompt section

    • ux Reported live as "too much": the full With/Without Rewriter lists repeated every source already shown once, split between the Delta and Common sections below them, for no added information. Removed both full lists; a compact summary line ("With Rewriter: N tool calls, N sources · Without: ...") replaces them.
    • feat Added a Prompt section at the top: the raw question exactly as typed, right next to the Rewriter's own actual output. That output is the delta being tested here, previously only visible several sections further down.
    • ux Common now sits inside a closed, click-to-expand <details> block instead of always being fully shown; it's the least differentiating part of the comparison, so it no longer has to be scrolled past by default.
    2026-09-13
    v3.82.3

    Rewriter Eval: page scroll, relative dates, tighter rows

    • fix The view had no scroll region of its own on a page that disables native body scroll, so a long Delta list (13+ sources on one side, reported live) just got clipped with no way to reach the rest. Now scrolls like every other view (#ackView's own pattern).
    • ux Removed the "Delta: what changed" label (the two sub-headings already say what it is); added a "Question: ..." line to the top of the Delta and Common boxes too, matching the two full-list boxes below them.
    • ux Every source's long timestamp is now a short "Nd ago" (or "today"), and every list sorts newest-first, so comparing and scanning don't require parsing an ISO date by eye.
    • ux Each source is its own single-line row, truncated with an ellipsis instead of wrapping a long title across several lines.
    2026-09-13
    v3.82.2

    Rewriter Eval: delta leads, one scroll per side

    • ux Delta now leads the results (renamed "Delta: what changed," a clear two-column Only-with/Only-without layout), Common comes next, and the two full evidence lists come last. The comparison itself, not the raw lists, is now the first thing you see.
    • fix The With/Without Rewriter columns each scroll as one whole unit (label, subtitle, and its entire source list together) instead of the source list scrolling separately inside a fixed-height card.
    • feat Both columns now show the actual question text, not just their own search terms.
    • ux The question input, Sample, and Run controls sit on one line; the buttons are relabeled to just "Sample" and "Run".
    2026-09-13
    v3.82.1

    Rewriter Eval: Common/Delta boxes, denser layout

    • feat Added Common (sources both runs found) and Delta (sources only one side found) boxes below the two full evidence lists, so the actual effect of the Rewriter's search terms is visible at a glance instead of eyeballing two long lists by hand.
    • ux The four boxes now sit in a real two-column grid (was flex-wrap, which could stack unpredictably depending on available width), each with its own capped-height scroll region so a long source list on one side doesn't force the page to grow just to keep both columns aligned. Source chips are smaller here than the normal Ask rail's, since fitting more per screen matters more for a side-by-side comparison. Question box is a plain single-line input instead of a textarea, and the explanatory paragraph under the heading is gone.
    2026-09-13
    v3.82.0

    New admin-only Rewriter eval page

    • feat Added πŸ§ͺ Eval Rewriter, an admin-only nav item that runs the Retriever twice on the same question: once with the Rewriter's own chosen search terms, once with the raw question text instead, everything else (vendor, allowed tools, tool-call budget) held constant. Both real evidence lists render side by side; a "Sample a real question" button pulls a genuine, already-classified community question instead of a made-up one. No automated LLM grading picks a winner, unlike the earlier promptfoo-based Eval page removed this session for its memory cost; this just shows both lists for a human to read directly.
    2026-09-13
    v3.81.0

    Ask: show a source link for the fallback web search too

    • feat Whenever a run's own retrieval found zero evidence, the pipeline already falls back to a real web search (deterministicWebFallback) for every preset, but that attempt was invisible once the answer finished. A successful fallback find already shows up as a normal clickable source; a failed one (reported live: "What's the latest powershell version?" abstained after this fallback's own search came up empty) now shows a brief note naming exactly what was searched, plus a one-click link to run the same search manually and verify, since the search engines this tool scrapes can intermittently block an automated request without blocking a real browser.
    2026-09-13
    v3.80.0

    Ask: a delayed second feed refresh catches late backfills

    • feat A web-verified vendor (see the pipeline-escalation work) can kick off a background Wikipedia-bot backfill that's still running when the answer comes back, so the feed's existing immediate refresh almost always raced it and found nothing yet even though the vendor genuinely gets posted a few seconds later. Reported live: "npm" answered correctly but the feed still said "No versions found." A second refresh now fires 6 seconds later, giving that backfill a real window to finish first; skipped if the search box no longer shows the same vendor by then.
    2026-09-13
    v3.79.2

    Ask: fewer lines, one fewer confusing timestamp

    • fix The workflow caption used to stay frozen on its last in-progress phase ("Generating answer… 1.4s") even after the answer had fully finished, sitting right next to the card's own total latency chip ("6s") with no label telling the two apart. It now clears once the run finishes; the diagram itself still shows every node's own elapsed time.
    • ux Removed the separate static "Thinking…" line shown while a question is running: the live caption right above it already says what's happening, so it was one more line with no extra information.
    2026-09-13
    v3.79.1

    Ask: right-align the live workflow caption

    • ux The "Generating answer… Ns"-style caption under the workflow diagram now sits at the bottom right instead of flush left.
    2026-09-13
    v3.79.0

    Feed: a named component search skips the recency cap

    • feat The 28-day (LOOKBACK_DAYS) recency cap used to apply to every result with no exceptions, including a named component search, so a link like /?q=Hibernate,java could come back empty for a component whose only tracked release predates that window. Searching for a specific vendor (typed into the search box, or pre-filled from a ?q= URL) now shows everything tracked for it regardless of age; the default, no-search "Recent Updates" feed is unchanged.
    2026-09-13
    v3.78.1

    Ask: fix vendor web verification search, show its evidence

    • fix verifyVendorViaWeb was searching the raw question text ("Whats the latest gradle version?") instead of the extracted product name, which came back noisy enough to fail verification for a real, well-known product (Gradle). It now searches the extracted candidate plus "software" (e.g. "gradle software"), the same suffix trick the Wikipedia bot's own search variants already rely on, per the established "software gives the search better results" rule.
    • feat Added a "Web Verification" section to the Sources tab whenever a run's vendor resolution escalated to a real web search, showing exactly what was searched and the raw results it was judged from, left and right, including on a "no vendor detected" abstain where it's the only way to see why.
    2026-09-13
    v3.78.0

    Ask: show pipeline escalation to web verification

    • feat When a question names a vendor this system doesn't track and the answer comes from a real web search verifying it instead (see the Wikipedia-fallback work), the workflow diagram now extends the single-agent pipeline with two more nodes, Web Search and Verify, spliced in between Rewriter and Retriever, live and timed the same as the other four. A question that never escalates still renders the exact same 4-node diagram as before.
    • ux The answer card's preset badge reflects the escalation too, e.g. "SINGLE-AGENT + WEB VERIFICATION" instead of just "SINGLE-AGENT", so it's visible without opening the diagram.
    2026-09-13
    v3.77.1

    Register: state which email providers are accepted

    • ux The registration form now shows, up front, which email providers signup actually accepts (Gmail, Outlook, Yahoo, iCloud, ProtonMail, AOL, or a .edu address; disposable/temp-mail addresses aren't) instead of a viewer only finding out after a rejected submission. Matches the server's own existing allowlist exactly, not a new or separate rule.
    2026-09-13
    v3.77.0

    Removed: the Eval admin research page

    • fix The entire admin-only Eval page (nav item, view, compose panel) and its server-side backing (evalRunner.js, the promptfoo dependency, and every /api/eval/* route) are removed. Loading promptfoo added roughly 110MB of RSS to every running server process, whether or not Eval was ever used, on a memory-capped 2GB production VM; even after lazy-loading it, actually using Eval permanently re-added that cost for the rest of that process's life (Node caches a module after its first require), which was still slowing the whole system down for every other feature sharing that VM. Removing the feature and its dependency entirely, rather than trying to further isolate its memory footprint, is the fix.
    2026-09-13
    v3.76.0

    Eval: simplified to one question at a time

    • ux Reworked the Eval page's toolbar into a single compose panel: a question box (type your own, or click "Suggest a random question" to fill it in, still freely editable) side by side with an expected-answer box, plus a Name field and one Run button. Replaces the old "N random questions at once" batch mode and the separate candidate-picker dropdown, both dropped as unnecessary complexity once real usage settled on evaluating one deliberately-chosen question per session.
    • feat An expected answer typed into the compose box is now saved immediately when the session starts, not only after it finishes.
    2026-09-13
    v3.75.0

    Eval: pick a specific question, and name your sessions

    • feat Added an "Or pick a specific question" mode to the Eval page: load a pool of randomly-sampled candidates, each labeled with its real classified question type (cve/patch/version/opinion/comparison/general, the same classification "Auto" itself uses to route a question), and run a session on exactly the one you choose instead of trusting a type turns up in a random batch.
    • feat Sessions can now be named, either up front (an optional "Name" field next to Run new evaluation / Run this question) or after the fact (a Rename control on the loaded session). Named sessions show their name in the Past sessions dropdown.
    2026-09-13
    v3.74.1

    Fixed: Eval page had no way to scroll

    • fix #evalView was missing the sticky/height/overflow-y:auto treatment every other view already has (page-level scrolling is disabled entirely, so each view has to be its own scroll region). A session with more than a screen's worth of questions had no way to scroll down to see the rest.
    2026-09-13
    v3.74.0

    New admin-only Eval page: pipeline research evaluation

    • feat Added an admin-only πŸ§ͺ Eval nav item/view, backed by promptfoo on the server (evalRunner.js). Pick a flexible number of questions (1-20), and it draws a true random sample ($sample) of real, already-classified Reddit questions and runs every one through every pipeline preset (Single-agent, Multi-agent buggy/fixed/delegated/feedback loop, and Auto) side by side, for a human to rate πŸ‘/πŸ‘Ž: the tool behind this session's RISE-seminar evaluation of the per-question-type pipeline routing decision.
    • feat Each sampled question ships with real ground truth to judge answers against: an editable "expected answer" box the admin fills in by hand, the real top-level Reddit comments on that same post (closest thing to ground truth for "did this happen to other people" questions, which no release note or CVE record can confirm or deny), and real matching vendor release-note/CVE records pulled from this system's own tracked data.
    • ux A session runs in the background on the server (an N-question x 6-preset matrix is real model calls, genuinely minutes) and the page polls for progress; past sessions are kept and browsable from a dropdown, and ratings/expected answers are stored separately from real production usage stats (eval_runs, never ask_runs).
    2026-09-12
    v3.73.2

    Removed the vertical rule between selects and toggles

    • fix .ask-options-sep (the plain vertical rule separating the model/size/pipeline selects from the evidence-gating toggles) removed per request, markup and CSS both.
    2026-09-12
    v3.73.1

    Close button pinned top-right; fewer wraps in the options panel

    • fix The rail's close button (margin-left:auto in a wrapping flex row) dropped to the bottom-right corner once #askOptionsPanel wrapped to more than one line, instead of staying in the top-right corner. .ask-rail-header is now position:relative with the button position:absolute; top:0; right:0, so it stays pinned to that corner regardless of how many lines the panel wraps to.
    • ux Tightened .ask-options-panel's gap (10px → 6px) and .ask-preset-select's padding/font-size (0 8px/12px → 0 6px/11px), per request to reduce line breaks in the narrower rail column; more of the row's content now fits per line before wrapping.
    2026-09-12
    v3.73.0

    Tighter answer rail: one-line heading, grouped toggles, no dead usage line

    • fix A long question plus a long preset name (e.g. "Multi-agent (feedback loop)") wrapped .ask-answer-heading to two lines, costing real vertical space in an already-tight column. The question now truncates with an ellipsis instead (.ask-answer-question shrinks/truncates, .ask-answer-preset stays flex-shrink:0 so the bracket is always fully visible on that same line), per explicit request to reduce line breaks in the rail and avoid scrolling.
    • ux The three evidence-gating toggles (Vendor check/Temporal filter/Intent filter) are now grouped in .ask-toggle-group so they wrap together as one unit inside #askOptionsPanel's own row instead of splitting apart individually when the row runs out of width.
    • ux relocateAskOptionsPanel() now lands #askOptionsPanel inside .ask-rail-header (sharing that row with the close button) instead of at the top of .ask-rail-col on its own otherwise-empty row, per request to put the close button next to an existing row rather than giving it one of its own.
    • fix Removed the "Usage: N call(s) today..." line: it read as permanently broken, stuck on "limits unknown until a request succeeds" for any provider that doesn't return real rate-limit headers (Ollama Cloud, the default, among them). The underlying quota fetch and the rate-limited-provider graying-out in the Model select are unaffected; only the visible text line is gone.
    2026-09-12
    v3.72.7

    Submit button: no more solid dark fill, darker hourglass instead

    • fix The .btn-primary added last release to fix the submit arrow's low contrast turned into a solid near-black box around the loading hourglass, which read worse, not better. Per follow-up request, back to plain .btn-ghost (matching Clear and the bookmark button); the hourglass emoji itself (its own built-in colors, unaffected by CSS color) is what actually needed to stand out, so #askSubmitBtn.ask-btn-loading now applies filter: brightness(0.6) saturate(1.3) to darken it directly instead of boxing it in a dark background.
    2026-09-12
    v3.72.6

    Question moves inside the answer card, next to the pipeline

    • ux The asked question used to sit outside the answer rail's card, in the rail's own static header (#askRailQuestion); the pipeline name (e.g. "SINGLE-AGENT") was a separate bold uppercase line inside the card. Per request, the question moved inside the card as the first line, with the pipeline name right next to it in brackets, e.g. "whats the latest flask version? (single-agent)". Applies to the running/loading state (question only, no bracket yet since the pipeline isn't resolved until the answer arrives), the final single-pipeline answer, an error card, and Compare mode's rail rendering (question only, no single pipeline to bracket). The rail's header now holds only the close button. The narrow-screen modal is unaffected: it already shows the question in its own separate #askModalQuestion header, so nothing was duplicated there.
    2026-09-12
    v3.72.5

    Higher-contrast Ask submit button

    • fix #askSubmitBtn (the arrow, and the spinning hourglass shown while a question is running) had neither .btn-primary nor .btn-ghost, so it rendered with no explicit background at all and read as barely visible against the page. Added .btn-primary (dark background, white icon), matching the contrast every other primary action button on the page already has.
    2026-09-12
    v3.72.4

    Even row height across every admin section

    • fix A closed admin row with a Refresh button (Bookmarks, Installed versions, System overview, All users, Search & Ask activity) was visibly taller than a plain text-only one (Change password, Model provider keys, Organization namespaces), since the button's own padding and border added height the plain rows never had. .ua-admin-header now has a min-height matching the button's own outer height, so every row reads at the same height whether or not it has one.
    2026-09-12
    v3.72.3

    Query preview names the vendors it actually found

    • feat The "vendor required" flag in the query preview said nothing about which vendor, if any, the question actually resolved to. New previewVendors() tests the question's words against suggestionPool, the same live component-name list the search autocomplete already matches against, and shows the real recognized name(s) (e.g. "vendor: zoom, teams") whenever at least one is found; falls back to the old "vendor required" only when the box is checked but nothing in the question is recognized.
    2026-09-12
    v3.72.2

    Clear/submit share the input's row instead of their own

    • fix With #askOptionsPanel now relocating away from the topbar on a wide screen (last release), .ask-options-row was left holding only Clear, the bookmark button, and the submit arrow: a near-empty second row under the question input. Those three are core form controls, not agentic-AI configuration, so they moved up onto .ask-input-row itself, on every screen size: one row (search, Clear, bookmark, submit) instead of two. .ask-options-row now holds only #askOptionsPanel, so it collapses to nothing once that panel relocates, rather than sitting there empty.
    2026-09-12
    v3.72.1

    Agentic-AI controls move into the answer rail on wide screens

    • ux The model/size/pipeline selects, the three evidence-gating toggles, and the usage line used to always live in the topbar's second row, pinned in the fixed header regardless of screen width. Per request, they're grouped into #askOptionsPanel and relocated (the real node, not a copy) to sit at the top of the answer rail's column on a screen with room for it (≥900px), right beside the diagram/answer they configure; a narrow screen, with no rail at all, keeps them in the topbar exactly as before. relocateAskOptionsPanel() runs once at load and again every time the viewport crosses that width. Clear, the bookmark button, and the actual submit arrow stay in the topbar on every screen size, since those are core form controls, not agentic-AI configuration.
    • fix .ask-rail-col now wraps the options panel's landing spot plus both the intro panel and the answer rail, and is itself the sticky/scrollable flex column; the two panels are plain toggled children of it instead of each separately carrying their own flex/sticky/overflow rules, so the relocated options panel scrolls and sticks together with whichever of the two is showing.
    2026-09-12
    v3.72.0

    Query preview moved into the Ask answer; one empty-state surface

    • ux The "search: ... window: ... intent: ... vendor required" readout is no longer a page-wide fixed strip below the header (right-aligned as of the last release, per an earlier request). Per follow-up request it now renders inline, small and muted, right above the workflow diagram in the Ask answer rail's Answer tab, a snapshot of what the submitted question actually resolved to rather than a live typing hint. The old fixed-overlay plumbing (--preview-h, its ResizeObserver, the layout padding/rail-offset calc()s that reserved space for it) is gone with it, since the reading now lives inside normal document flow.
    • fix A genuine fetch failure (a real "⚠️ The server is temporarily unavailable (502)" case) still showed three uncoordinated messages at once: an ad-hoc error paragraph written straight into #feed, the unrelated pagination sentinel independently reading "πŸ” No results," and #status saying "Failed to load." Same redundant-elements bug fixed for the plain-empty-search case last release, just via a different codepath that fix didn't reach. showEmptyState(message, {icon, detail, isError})/hideEmptyState() is now the one surface every "nothing in the feed" case (over-filtered search, day-window exclusion, or a real fetch error) goes through, so #emptyState.show ~ #sentinel suppresses the sentinel regardless of which reason triggered it.
    2026-09-12
    v3.71.9

    Query preview strip right-aligned

    • ux The "search: ... window: ... intent: ... vendor required" preview strip below the header now right-aligns its text, per request, instead of sitting flush left. On a wide screen this puts it roughly above the Ask answer rail (the right-side column), the same side of the screen as the question/tabs it's describing.
    2026-09-12
    v3.71.8

    Feed lookback window now tracks the Ask recency setting

    • feat LOOKBACK_DAYS (the feed's own recency window, driving "Recent Updates," the activity chart, and Reddit/StackOverflow matching) used to be a plain hardcoded constant, separate from the admin Settings panel's "Ask recency window (days)," which only ever coincidentally shared a starting value. Per explicit request they're now the same number: the client fetches the live value from a new public GET /api/ask/recent-window-days at page load and applies it before the feed's first render (28 stays as the fallback if that fetch fails). Changing the Settings value and reloading now widens or narrows the feed too.
    • fix boot() and the independent top-level loadHomeStats() IIFE both build something sized off LOOKBACK_DAYS and both run concurrently at page load; each now awaits the same single lookbackDaysReady promise before doing so, so there's no race where one of them builds its day range from the stale fallback while the other already has the live value.
    2026-09-12
    v3.71.7

    Friendlier message when the API is unreachable

    • ux A failed feed load showed the raw thrown error verbatim, e.g. "⚠️ Error: 502 Bad Gateway": accurate, but not something most visitors can act on. friendlyFetchError() now classifies it (a 5xx means the server itself is down, a 4xx means the request was rejected, anything else is a real network/connectivity failure) and shows a plain-language headline plus a short, still-realistic detail line, reused by both the main feed's error state and the filter-submit failure's status text.
    2026-09-12
    v3.71.6

    Removed a redundant "no results" message

    • fix An empty feed showed two "no results" messages in a row: the prominent emptyState block ("No results found for the last 28 days") immediately followed by the small infinite-scroll sentinel's own "πŸ” No results" text right below it. #emptyState.show ~ #sentinel { display: none; } hides the sentinel whenever the empty state is already showing, covering every codepath that sets that text rather than patching one call site.
    2026-09-12
    v3.71.5

    Lookback window widened to 4 weeks; fixed a stale label

    • fix LOOKBACK_DAYS back up to 28 (was 14). The sidebar's "Activity (2 weeks)" label was hardcoded text, not derived from the constant like the feed header's own "(last N weeks, M components)" is, so it silently went stale the last time this changed; now set once from a new LOOKBACK_WEEKS derived constant, same source of truth as everywhere else.
    • fix The admin Settings panel's "Ask recency window (days)" hint said it "matches the feed's own lookback window by default (14 days)," worded as if the two were linked; they only ever coincidentally shared a starting value; changing one has never changed the other. Reworded to say so plainly, and the day count it does mention is now interpolated from LOOKBACK_DAYS instead of a hardcoded number that can drift again.
    2026-09-12
    v3.71.4

    Profile row on one line; empty state explains the day window

    • ux Name, email, and the role badge in the Account profile card were three stacked lines; now one row (wraps only if the panel is too narrow to fit them), with Sign out staying right-aligned on the same line. Smaller font on all three now that they share a row.
    • ux The feed's empty state now says "No results found for the last LOOKBACK_DAYS days" whenever a named search actually has matches, just none recent enough to pass the feed's day-window cap (e.g. searching "Python" when its newest known release predates the window entirely). Previously a flat "No updates match the current filters," which didn't say why. An over-filtered or genuinely no-match result still gets the old generic message.
    2026-09-12
    v3.71.3

    More stats on the Account profile card; tighter admin panel

    • feat The profile card's stat row now also shows Reddit and StackOverflow document counts (new stackoverflowTotal field on GET /api/admin/overview; redditTotal no longer double-counts stackoverflow.py's posts, which share the same collection). "Bots stale" now reads as a fraction of the total tracked bots (e.g. "0/9") instead of a bare count with no denominator.
    • ux Smaller font and tighter gaps on the stat row now that it holds more chips. Trimmed remaining padding/margin in the profile card and each admin section's closed row, and gave #usersView's own box a few more px of height (bottom slack 16px → 8px), so the "all admin sections closed" state fits without scrolling on more screens.
    2026-09-12
    v3.71.2

    "Latest version" for a component picked the wrong branch

    • fix A product with several concurrently-maintained branches (e.g. Python's 3.12/3.13/3.14) posts patches to each on its own schedule, so the most recently-dated release isn't necessarily the highest version number: an older branch's patch can land after a newer branch's. fetchLatestVersionFor (the feed group header's "(latest: X, Nd ago)" bracket and the Ask suggestion dropdown's own bracket) was taking the first non-CVE entry in /api/c/name/:name's date-sorted list, so it showed Python's latest as "3.12.14" (dated after 3.14.7) instead of the real latest, 3.14.7. Now picks the max by actual version number instead. The server-side counterpart (/api/v/d/versionsByComponent, used by the Account page's Installed Versions drift check) had the identical bug and is fixed the same way.
    2026-09-12
    v3.71.1

    Account view uses the available width instead of wrapping

    • ux The Account view's own column was capped at a fixed 580px even though it's had the whole main area to itself since Filters/nav became their own drawers, forcing the profile card's stat row (and other content) to wrap onto extra lines it didn't need to. Widened to min(900px, 96vw). Form fields (password, org names, provider keys) are capped to a sensible width instead of stretching edge to edge; the search-events table, dashboard cards, and stat rows use the extra room.
    • fix Reduced remaining padding/margin in the profile card and its stat row.
    2026-09-12
    v3.71.0

    Even summary spacing; richer stats in the profile card

    • fix A stray leftover CSS rule (#ua-search-events-section { margin-top: 24px; }) gave "Search & Ask activity" a visibly larger gap above it than every other admin section. Removed; every collapsible row's spacing now comes from the same source (its own border), so it's consistent everywhere.
    • feat The admin registration notice and stat line moved into the profile card itself (name/email/role/Sign out), visible the moment the Account view opens instead of a separate line further down the page. Expanded with more aggregate counts: versions tracked, CVE total, stale bots, and storage used, alongside accounts and queries.
    2026-09-12
    v3.70.1

    Fix: every collapsible summary row, not just the admin panel's

    • fix The "chevron stacked above centered text" layout bug fixed for the admin panel earlier applied to every other collapsible <summary> in the app too (Filters/Stats and other sidebar sections, docs view's endpoint/architecture toggles, CVE view's post/legend toggles, "Why create an account?", "Paste a list"): each was missing an explicit flex-direction: row, so the global summary style's own column default won on that one property. All fixed the same way.
    2026-09-12
    v3.70.0

    Filters/Stats get their own panel; badge and source-list fixes

    • feat Filters and Stats are now their own slide-over panel, opened with a new 🎚️ topbar button, separate from the ☰ menu (which now holds just the view-switcher nav). Toggle either one independently; opening one closes the other.
    • fix The Account page's role badge ("ADMIN"/"USER") was stretching to the full width of its card instead of staying a compact pill, since its flex-column parent's default cross-axis stretch was overriding its own inline-block sizing.
    • fix A feed group's "Sources" line could show a stray "videoCall" alongside the real vendor (e.g. "mitre, teams, videoCall") from documents saved before videoCall.py started stamping the actual vendor per URL; the legacy generic label is no longer shown.
    2026-09-11
    v3.69.1

    Recent Updates now strictly capped at the lookback window

    • fix A named component search, or the LLM/Hypervisor toggles, used to bypass the feed's recency window entirely and surface a release from a year ago. Per request, the feed now hard-caps at the lookback window (14 days) in every case, no exceptions: a search or toggle with nothing that recent shows no results instead of reaching further back.
    2026-09-11
    v3.69.0

    Sidebar consolidated to 2 sections; tighter admin/profile padding

    • ux The feed sidebar's Types, Stats, Activity, and Top searches sections (previously 4 separate collapsible rows) are now sub-divisions of one combined "Stats" section, next to Filters. 5 rows to scan closed, down to 2.
    • fix Reduced the padding/margin around every admin and Account-page collapsible section (System overview, Settings, All users, Search & Ask activity, Change password, Model provider keys, Organization namespaces, Bookmarks, Installed versions): removed redundant per-section margins (the border between rows already provides separation) and switched the summary row's own padding to a smaller, relative (rem-based) size. With everything closed, the whole admin panel now fits without scrolling on a typical laptop screen.
    2026-09-11
    v3.68.1

    Fix: feed group's "latest" freshness could read a day off

    • fix A feed group's "(latest: X, Yd ago)" freshness could say "1d ago" for a version genuinely posted earlier the same day. The date was anchored to a fixed noon-UTC instant and diffed against the current moment, so the result depended on how far the viewer's own timezone sits from UTC, not on whether a calendar day had actually passed for them (confirmed live: a release posted 5am Pacific already read "1d ago" by evening the same Pacific day). Now computed as a plain whole-calendar-day difference in the viewer's own local timezone.
    2026-09-11
    v3.68.0

    View-visibility menu toggles; consistent collapsible sections; narrower admin table

    • feat New admin Settings toggles for each optional nav-menu view (Graph/Arch/CVE/Risk Report/Docs/Changelog/Credits/Release): turn one off and its menu link disappears for everyone. Home and Account can't be hidden, to keep core navigation and admin access always reachable.
    • ux Change password, Model provider keys, Organization namespaces, Bookmarks, and Installed versions are now the same closed-by-default collapsible design as System overview/Settings/All users/Search & Ask activity, instead of a different always-open card style, so the Account page is shorter overall and reachable without scrolling past several open sections first.
    • fix Search & Ask activity table: removed the User agent column, timestamps now show as "3d ago" instead of a full date/time, and the table switched to a fixed percentage-column layout so it fits its container at any width instead of occasionally needing its own horizontal scroll.
    • fix Compare mode's pipeline legend (Benchmark tab) no longer needs horizontal scroll either: replaced the old 6-column min-width table with a stacked list that reflows to any width.
    2026-09-11
    v3.67.1

    Compare mode: no more horizontal scroll on the pipeline legend

    • fix The Benchmark tab's "What do these pipelines do?" legend was a 6-column table (min-width 760px) that only fit with its own horizontal scrollbar, wider than the answer rail, the narrow-screen modal, and most phones. Replaced with a stacked list: each pipeline's name, a wrapping row of yes/no fact chips, and its example, all reflowing to fit any width instead of needing to scroll sideways.
    • ux Admin Search & Ask activity table tightened further on mobile (smaller cell width/font) so its own self-contained scroll box is needed as rarely as possible.
    2026-09-11
    v3.67.0

    Admin-configurable Ask defaults

    • feat Three new admin Settings entries: default Ask pipeline, default model provider, and default model size β€” what a new visitor's Ask form starts on, instead of the previous fixed Auto/Ollama Cloud/Medium defaults. Rendered as real dropdowns (not free text), so an invalid value can't be typed in.
    2026-09-11
    v3.66.1

    Admin section headers: fix wrapped summary layout

    • fix Each admin section's closed-state <summary> row (chevron, title, count, Refresh) was rendering as four centered, stacked lines instead of one compact row β€” a global summary CSS rule's flex-direction: column wasn't being overridden. Now a single line, tighter padding.
    • ux Settings section's summary now shows a count, matching All users / Search & Ask activity.
    2026-09-11
    v3.66.0

    Benchmark tab, admin registration/search visibility, installed-versions sync

    • feat New Benchmark tab on every Ask answer, alongside Answer and Sources. On a normal answer it offers a one-click "Compare all 5 now"; running Compare all 5 itself now renders here too (same tabbed card the rail already used, previously modal-only), with a compact side-by-side table (pipeline, time, source count, full answer at small font) so every pipeline's answer can actually be read and compared, not just skimmed as 5 separate full cards.
    • feat Admin panel: a registration notice banner ("N new registrations since your last login") plus an always-visible accounts/queries stat line (total + last-7-days for both), backed by GET /api/admin/overview's new users/queries fields.
    • feat The admin "Search & Ask activity" table (renamed from "Component searches") now logs and shows real Ask questions too, not just vendor/component searches, tagged by type; a signed-out visitor's question is logged even though it can't be answered without signing in.
    • feat Installed versions (Account view) now actually persists to your account server-side instead of only this browser's localStorage, so it follows you across devices.
    • ux Each admin section (System overview, Settings, All users, Search & Ask activity) is now a closed-by-default, collapsible section instead of one long always-open page.
    • ux Search & Ask activity table: removed the raw IP column, shows the user's real name instead of a truncated id.
    • fix Removed the inline research-type citation footnotes from the Ask pipelines tables (intro panel and docs view), per request.
    2026-09-11
    v3.65.1

    Agent-workflow diagram: full width, no edge overlap

    • fix The live agentic-workflow diagram now stretches to fill its full column width; Mermaid stamps its own max-width inline style on the rendered SVG, which was overriding the external width:100% rule.
    • fix Increased node/rank spacing so the dotted "retry" feedback edge between Evaluator and Retriever no longer overlaps the main flow line.
    • fix Comparison-question entity extraction: a trailing connector word ("...and which browser?") could leave it attached to the previous entity (e.g. "teams and"); the trailer pattern now also strips "and"/"but".
    2026-09-11
    v3.65.0

    Admin settings panel; research-type column with citations

    • feat New Settings section in the Account view's admin area, backed by the server's new generic /api/admin/settings (GET/PUT). Renders whatever keys the server actually returns, not a hardcoded form, so a new admin-tunable value needs no new markup here. First real setting: Ask's recency window (days), now admin-editable and defaulting to 14 to match the feed.
    • ux Both "Ask pipelines" tables (the Ask intro panel and the docs view) gained a "Research type" first column: the general question-type literature these categories come from (Li & Roth 2002's factoid-QA taxonomy; Treude, Barzilay & Storey 2011's Stack Overflow question-type study), cited below each table.
    2026-09-11
    v3.64.1

    Feed scrolls with the page on mobile, not boxed into 70vh

    • fix On a narrow screen, #feedPanel (list and its own header, including the sort dropdown and Expand all) was capped to max-height: 70vh with its own nested scroll, on top of the page's own scroll. Scrolling through updates scrolled the sort/Expand-all controls out of reach too, and there was nothing else on the single-column mobile layout the cap was actually making room for. Removed; the feed now flows with the page like the rest of this layout already does on mobile. Confirmed infinite-scroll pagination doesn't depend on the feed being its own scrolling element (its IntersectionObserver has no root set, so it already watches the real viewport).
    2026-09-11
    v3.64.0

    Auto pipeline selection, by question intent

    • feat New "Auto (recommended)" Pipeline option, now the default: the question's own classified intent picks a concrete pipeline server-side (comparison β†’ delegated + feedback loop, security/patch β†’ union search + rerank, a plain version lookup β†’ single-agent, everything else β†’ delegated) instead of a manual guess, and the answer states plainly why ("Why this process: ...") once it's done.
    • ux Replaced the Ask intro panel's "Try asking" list with a table: question type, the real internal intent tag, which process Auto picks for it, and a clickable example (same fill-the-input behavior as before).
    • feat New "Ask pipelines" section in the docs view with the same mapping, for anyone reading the API docs directly rather than the Ask box's own intro panel.
    • fix A live run's phase captions (and the answer card's own pipeline label) previously showed the literal word "auto" instead of the real resolved pipeline, since the client only learns which concrete preset Auto picked once the server says so. A new synthetic auto_resolved progress event (and preferring data.config.preset for the final label) fixes both.
    2026-09-11
    v3.63.3

    "Do you recommend X or Y" fixed; taller, smaller-font workflow diagram

    • fix "Do you recommend zoom or teams?" leaked "recommend zoom" into the feed's own vendor filter (?q=recommend+zoom,teams), silently dropping Zoom out of the feed since no real product name contains "recommend zoom" as a substring. The comparison entity-name regex only stripped a leading verb phrase at the very start of the question ("Should I use...", "Recommend..."); it didn't know about a leading "Do/Would/Will you..." wrapped around it. Fixed in both the client's own preview and the server's real entity extraction (kept in sync by hand, see each one's own comment).
    • ux Workflow diagram: smaller font and more node/rank spacing, scoped to just this diagram (not the docs view's own Mermaid diagrams), now that each box carries a two-line label (name + seconds).
    2026-09-11
    v3.63.2

    Workflow diagram redraws live, each box shows its own seconds

    • fix A fast-completing role (a comparison question's Retriever calls are plain DB lookups, often well under 100ms) could finish before its own "active" render ever painted, since the next phase's render raced past it: the diagram would sit at its very first idle frame for the whole request and only ever show the final state. Now redrawn every 250ms while a request is running, not just on each phase event, so even a very short-lived active state gets at least one real frame on screen.
    • feat Each box now shows its own elapsed seconds under its name (e.g. "Retriever, 0.4s"), live-updating while that role is active and frozen once it's done, instead of one combined caption line below the whole diagram.
    2026-09-11
    v3.63.1

    Sort by most sources

    • feat New "Sort: Most sources" option in the feed's sort dropdown, ranking each component by how many distinct bots actually produced its content (the same count its own "Source(s): ..." line shows), most first. "unknown" doesn't count as a real source, so a component with only unattributed documents doesn't out-rank one with a confirmed single source.
    2026-09-11
    v3.63.0

    Live agent workflow diagram in the answer rail

    • feat The answer rail now opens the moment a real question is submitted, showing a live Mermaid diagram of the four-role architecture (Rewriter β†’ Retriever β†’ Evaluator β†’ Orchestrator, with the feedback loop back to Retriever) as it actually runs: idle by default, blue while a role is active, green once it's done. Always the same full shape regardless of pipeline preset. A preset with no real role delegation (Single-agent, Multi-agent buggy/fixed) just never lights up Rewriter/Evaluator, since those roles genuinely don't exist for it.
    • feat The rail is now two tabs: Answer (the workflow diagram plus the answer itself) and Sources (citations, vendor/intent/temporal chips, and "Show internals"), instead of one long stacked card.
    • fix Removed the text-based phase ticker that used to sit above the question input while a request ran; the workflow diagram in the rail replaces it, and it no longer needs its own reserved strip at the top of the page.
    2026-09-11
    v3.62.20

    CVE chip kept its box after the rest lost theirs

    • fix The group header's πŸ”΄ CVE chip still rendered as a red boxed pill after Major/Minor/Patch/Reddit/SO lost theirs: .chip.bad's own background rule sat later in the stylesheet than .groupChips .chip's box-removal at equal CSS specificity, so it silently won regardless of which was actually meant to apply. Added matching .groupChips .chip.bad (and every other chip variant) at higher specificity so the box-removal always wins here; CVE keeps its red text, just no more background.
    2026-09-11
    v3.62.19

    Components, not groups; softer accents; a Major/Minor/Patch fix

    • fix A CVE record carries its own release channel too (a CVE affecting 6.31.1 reads channel "patch"), which was double-counting it into both the πŸ”΄ CVE chip and the Major/Minor/Patch chips. Those three now only count real, non-CVE release-notes entries.
    • ux Renamed "Groups" to "Components" throughout the feed panel (sidebar KPI, "Expand all" button title, the header's own count): "group" was this app's internal grouping mechanism, "component" is what a reader actually thinks of each entry as.
    • ux Removed the "N groups" text that repeated on the right side of the header, now that the header's own "(last 2 weeks, N components)" label already states it.
    • ux Dropped the ".py" from each component's "Source: chrome, github" line. The real sourceBot value keeps it (for consistency with releasetrain-bot's own naming); only the display drops it.
    • ux The "posted today" row indicator (and the LLM/Hypervisor ones) used the page's darkest near-black ink color, which read as too heavy a bar. Switched to the softer neutral tokens already defined for exactly this purpose, and every row's left-border accent is now rounded instead of a hard rectangular edge.
    2026-09-11
    v3.62.18

    Per-component sourcing, header controls line up

    • feat Replaced the global, deck-wide "Recent Updates" source breakdown (raw totals with no way to tell which component each count belonged to, and permanently-stuck "unknown" buckets that should have said "github.py") with a per-component "Source: chrome.py" / "Sources: chrome.py, github.py" line in each group's own summary.
    • feat "Recent Updates (last 2 weeks)" now also states how many groups are currently in that window, e.g. "(last 2 weeks, 214 groups)".
    • ux The Sort dropdown and "Expand all" button now share an explicit height, matched to whichever was naturally shorter (the button): the native select's own UA chrome previously rendered visibly taller.
    2026-09-11
    v3.62.17

    Feed group chips: less box, more aligned

    • ux The group header's own CVE/Reddit/SO/Major/Minor/Patch chips lost their box (background and border) and became plain colored icon+label+count text, separated by a "|": six pill boxes together read as too heavy for a per-group summary, especially next to a lone one-count chip like "Patch 1".
    • ux That chip row now sits flush-left with the expand/collapse arrow on the row above, instead of indented to (approximately) line up under the name text.
    2026-09-11
    v3.62.16

    Feed group header: chips on their own row, badge-styled

    • ux Each component's CVE/Reddit/SO/Major/Minor/Patch total chips now sit on their own row below the component name, instead of crowding onto the same line; the latest-version bracket moved to the far right of the name's own row.
    • ux Chips (feed group totals and per-row chips alike) are rounder and bolder, closer to a GitHub/shields.io badge, while keeping this site's existing muted color palette rather than picking up their louder solid-fill colors.
    2026-09-11
    v3.62.15

    Stack Overflow citations now labeled as such

    • fix The Ask answer's source list hardcoded every community citation as Reddit ("kind: 'reddit'"), even when the underlying document actually came from Stack Overflow (stackoverflow.py writes into the same shared collection, distinguished only by a "source" field the server ignored). Added a 🟧 icon and a "Stack Overflow: <name>" snippet prefix so a genuine Stack Overflow citation now reads as one, matching the icon the feed already uses for it.
    2026-09-11
    v3.62.14

    A how-to example, without growing the list

    • feat Swapped the plain "What's new in Kubernetes this month?" sample for "How do I roll back a bad Windows update? (General, how-to)": procedural/how-to is a real, well-established question type (this session's own research discussion), and stackoverflow.py now flags it on ingest, but classifyIntent doesn't route it specially yet, so it's labeled honestly as General rather than implying a dedicated intent that doesn't exist. Kept the list at 7 items on purpose, since it was already trimmed once to stop the panel needing a scroll.
    2026-09-11
    v3.62.13

    Feed sort is now a choice, not one fixed default

    • feat Added a Sort dropdown next to "Recent Updates": Recent (the default), A-Z, Most CVEs, Highest risk, and Most activity. Remembered across visits. "Highest risk" ranks by the same model-predicted community update-risk score used throughout the rest of the app, and re-sorts itself once Reddit data finishes its background load if that's the active mode.
    2026-09-11
    v3.62.12

    Feed sorts by recency, window back to 2 weeks

    • feat Feed groups now sort by recency (whichever component was most recently updated leads) instead of alphabetically. This is a "Recent Updates" feed, so surfacing what actually just changed matters more than a stable, predictable position, and finding one specific component by name is already better served by the search/filter box than by scanning an alphabetized list.
    • feat Lookback window back down to 2 weeks (was 4). "Recent Updates (last 2 weeks)", the activity chart, and Reddit/StackOverflow matching all follow the same single LOOKBACK_DAYS constant.
    2026-09-11
    v3.62.11

    Fixed a stale "latest" version in the feed group header

    • fix A group header could show an older version as "latest" (e.g. "Zoom (latest: 7.0.0, 171d ago)" while a genuinely newer 7.1.8 sat in the feed below it). The server endpoint this reads was sorted by when a document was last written to the database, not by its actual release date; a bot that posts several historical entries newest-first (the natural order for most release-note pages) ends up writing its oldest entry last, which then looked like the "latest" one. The endpoint now sorts by real release date directly.
    2026-09-10
    v3.62.10

    Poll button only offered for a real yes/no question

    • fix The πŸ“Š Poll chip appeared on any Reddit post with a "?" and comments, including a WH-question like "What's the best way to fix this?" or "Why did this happen?", which has no binary answer to poll for in the first place. Now only offered when the question is actually shaped for yes/no. Same fix applied to the server's own search_reddit_questions tool, so Ask's "did other people..." questions don't match a WH-shaped post either.
    2026-09-10
    v3.62.9

    Ask intro panel no longer needs to scroll

    • fix Growing "Try asking" from 4 to 7 examples pushed the panel's content past the viewport, forcing a vertical scroll that wasn't there before. Tightened spacing throughout (headings, paragraphs, sample buttons) and trimmed the two explanatory paragraphs down to the same facts in fewer words, so the same information fits in noticeably less height.
    2026-09-10
    v3.62.8

    Ask answer rail no longer scrolls sideways

    • fix The right-side answer panel was missed in the earlier "no view scrolls sideways" pass: it sets overflow-y:auto, which silently promotes overflow-x to auto too, so an unwrapped token in a generated answer could put a horizontal scrollbar on the rail and clip text at the edge. Pinned to overflow-x:hidden, and added overflow-wrap to the answer text and its inline code spans so real content wraps instead of needing to scroll in the first place.
    2026-09-10
    v3.62.7

    Fixed a blank intent tag, and a tighter preview strip

    • fix The "Will..." preview line showed a bare "intent:" with nothing after it for a comparison question: the badge above the input learned the new intent, but this line's own separate tag map didn't. Added.
    • fix That preview strip pushes the whole page down since it has no reserved layout space of its own, and a comparison question's longer term list made it wrap to 2 to 3 lines. Shortened the wording to plain labels ("search:", "window:", "intent:", "vendor required" instead of full sentence phrasing) and tightened the strip's own padding and line-height. Same information, less height.
    • feat Added a 7th "Try asking" example showcasing the community Yes/No poll feature: "Did other people lose Wi-Fi after the latest Windows update?"
    2026-09-10
    v3.62.6

    "Try asking" now has one example per intent

    • feat The Ask intro panel's sample questions now cover every intent the classifier recognizes, each labeled with which one it is: Version, CVE, Patch, General, Comparison, and Opinion, the last one deliberately phrased to preview that it declines rather than reading like the rest.
    2026-09-10
    v3.62.5

    Comparison entity extraction fix, and a freshness stamp on the feed

    • fix "android or ios which is more secure" resolved to the entities "android" and "ios which": a trailing qualifying clause ("which is...", "that...") wasn't being cut off the second name, so it matched nothing and the feed showed only one side's documents. Fixed in both the server's classifier and this page's own preview copy of it.
    • feat Each feed group's header now shows how fresh its latest tracked version actually is, e.g. "(latest: 8.5.10, 12d ago)", not just the bare number.
    • feat Swapped one of the Ask intro panel's sample questions for a comparison example: "Should I use Node or Flask for a new API?"
    2026-09-10
    v3.62.4

    Live preview badge learned the comparison intent

    • fix The as-you-type badge above the question box still showed "Opinion (will decline)" for a real comparison question ("should i use zoom or teams for the next video call"), even after the server started answering it for real. This preview is a client-side mirror of the server's own classifier and had fallen out of sync; it now recognizes the same comparison shape and shows "Comparison question" instead.
    2026-09-10
    v3.62.3

    Views no longer scroll sideways

    • fix The Account view and every other panel could scroll horizontally when a wide child (an admin table, a long token) pushed past the edge. Each view now clips to its own width. The admin search events table, which really is wide, scrolls inside its own box so every column stays reachable.
    2026-09-10
    v3.62.2

    Provider key fields start empty and stay empty

    • fix The Claude key box still showed dots from the browser password manager. All three key inputs now load read only until you click into them, so no password manager can prefill them. The app never puts a key here itself, shared or otherwise, so every box reads the same: empty, with a placeholder.
    2026-09-10
    v3.62.1

    Provider key fields no longer autofill

    • fix Browsers were autofilling the Model provider key inputs with the saved account password. They now opt out of password-manager autofill, so a stray Save can't overwrite a key with your login password.
    2026-09-10
    v3.62.0

    Use your own model provider keys

    • feat Account view has a Model provider keys section: set your own Claude, Groq, or Ollama Cloud key and your Ask requests use it in place of the shared server key. Stored on your account, only ever shown back as the last 4 characters, cleared by saving an empty box. Fixes the case where one person exhausting the shared credit blocked Ask for everyone.
    2026-09-10
    v3.61.1

    Long source titles wrap instead of scrolling sideways

    • fix A long Reddit/discussion title in an answer's Sources list forced a horizontal scrollbar on the answer card. Titles now wrap inside their chip.
    2026-09-09
    v3.61.0

    The direct answer is highlighted in the response

    • feat The exact substring that most directly answers a version question (e.g. "8.5.10") is now highlighted in green in the answer text, wherever it appears. Comes from the server's own highlightTerm, the same deterministically-verified version number ask.js already checks the answer against, so this never guesses at what looks important, only ever marks a value already confirmed correct.
    2026-09-09
    v3.60.1

    Sources flow left to right instead of one per line

    • fix v3.60.0's column-aligned, one-per-line source list is replaced with a wrapping row of compact chips: sources flow left to right and only drop to a new line once a row runs out of width, instead of every source taking its own line regardless of how short it is.
    2026-09-09
    v3.60.0

    Source list columns line up; sign-in link in the Ask panel

    • ux Each Documented/Discussion source row's icon, title, and date now sit in fixed grid columns, so every row's date lines up at the same position instead of trailing right after that row's own differently-long title.
    • feat The Ask intro panel's "requires sign-in" text is now a real link straight to the Account view, instead of only naming it in prose.
    2026-09-09
    v3.59.0

    Feed groups collapsed by default; version bracket fetched live

    • fix Every feed group now starts collapsed, including the first one. It used to default open, which read as one arbitrarily-expanded group sitting above an otherwise all-collapsed list.
    • fix A group's "(latest: X)" bracket (added in v3.58.0) is now fetched live by name, the same call and cache the Ask suggestion dropdown already uses, instead of being computed only from whatever items the feed happens to have loaded right now. Verified live: a group showing "Patch 1"/"Minor 2" chips could still have zero non-CVE items loaded in view (those chips count a CVE record's own versionReleaseChannel field too), leaving the bracket blank even though the real latest release exists, just older than the feed's current window.
    2026-09-09
    v3.58.0

    Feed group headers show their latest version

    • feat Each collapsed feed group's header now shows "(latest: X)" next to the component name, computed from the group's own already-loaded items, not a separate fetch. Only counts a real release (excludes CVE records and Reddit/StackOverflow posts), so a component whose most-recently-touched document happens to be a CVE still shows its actual latest version, not the CVE's own affected-version number.
    2026-09-09
    v3.57.0

    Component suggestions show their latest version

    • feat Typing a component name into Ask now shows its own latest version next to it in the suggestion list (e.g. "Android (latest: 17.0.0)"), fetched lazily per suggestion and cached so it never re-fetches the same name twice. Skips any CVE record when picking "the latest version", since a component's own most-recently-touched document can be a CVE rather than a real release.
    2026-09-09
    v3.56.0

    The right column is always there now, not just on demand

    • feat On a screen with room for it, the right column now shows an Ask intro panel (what it does, technically, plus clickable sample questions) whenever no answer is currently showing, instead of sitting empty until the first question. Swaps to the real answer the moment one exists.
    • ux The two-column layout is no longer conditional on an answer existing; it's always on at the same width it used to only switch to for an answer. The overall page's left/right padding was also trimmed slightly.
    2026-09-09
    v3.55.0

    Even 50/50 split between feed and answer

    • fix The feed and the inline answer rail now split the available width evenly (50/50). Previously the rail stayed a fixed 360px regardless of screen size, so the feed took up most of the width on anything wider than a laptop.
    2026-09-09
    v3.54.1

    Ticker back to one line, numbers kept

    • fix v3.54.0's one-step-per-row ticker layout is reverted back to the original wrapped horizontal line. The #1/#2 round numbering it shipped alongside stays.
    2026-09-09
    v3.54.0

    Every round of a multi-agent pipeline is now numbered

    • feat On Multi-agent (buggy) and Multi-agent (fixed), a repeated Retriever/Orchestrator round now shows a number (e.g. "Retriever #2: Searching the web", "Orchestrator #2: Generating answer") instead of the same two labels appearing over and over with no way to tell one round apart from another. Matches the #1/#2 tagging the delegated presets already got.
    • ux The pipeline ticker now shows one step per row instead of a single wrapped line with arrows crammed between entries. A question with several rounds reads as an actual sequence now, not a run-on blur.
    2026-09-09
    v3.53.0

    Compare all 5, agent identifiers, a legend table

    • feat Compare now runs all 5 pipelines side by side (was 3): Single-agent, Multi-agent buggy/fixed, and the two new delegated presets. A technical legend table now sits above the 5 answer cards, listing what each pipeline does and doesn't do (rewrites the query, searches the union of original + rewrite, real agent delegation, feedback loop retry) with a short concrete example per row.
    • ux On Multi-agent (delegated) and Multi-agent (feedback loop), when the feedback loop actually triggers a second Retriever/Evaluator round, the progress ticker now tags each entry #1/#2 (e.g. "Retriever #2: Searching the web") so two agent calls no longer look like the same step repeating.
    2026-09-09
    v3.52.0

    Two new pipelines: genuine agent delegation

    • feat Two new Pipeline options: Multi-agent (delegated) and Multi-agent (feedback loop). Unlike every other pipeline here, which is one continuous model call with capability flags toggled on or off, these two genuinely delegate: the Rewriter, Retriever, and Evaluator are each a separate model call, with results explicitly handed between them. The feedback loop variant additionally lets the Evaluator send the Retriever back for one more search pass when its first attempt is judged insufficient. Real cost: several model calls per question instead of one, so pick these deliberately, not as a default.
    • ux The progress ticker's Rewriter:/Retriever:/Evaluator: labels are now genuinely accurate for these two pipelines (each really is a separate call), plus two new phases, "choosing search terms" and "judging evidence", that only ever appear on them.
    2026-09-09
    v3.51.2

    Readable checked/unchecked tooltips

    • ux The Vendor check / Temporal filter / Intent filter tooltips now put the checked and unchecked case each on their own line, with a blank line between, instead of one run-on sentence.
    2026-09-09
    v3.51.1

    Hover tooltips on filters and Ask options

    • ux Vendor check, Temporal filter, and Intent filter now explain what checked versus unchecked actually does on hover, instead of just naming themselves. The Model, Size, and Pipeline selects, and the Major/Minor/Patch/CVE/Reddit quick filters, got the same treatment where they were missing one.
    2026-09-09
    v3.51.0

    Component autosuggest is back; a few more fixes

    • feat The single search/ask box now suggests real component names as you type again (the old Search box's own autocomplete), alongside real past community questions in the same dropdown. Picking a component fills just the current comma-separated term; picking a question fills the whole box.
    • ux An abstained answer now says why: "No vendor matched", "No evidence found", or "Opinion question" instead of a plain, unexplained "Abstained" badge.
    • ux Recent Updates groups are now sorted alphabetically by component name instead of by whichever one happens to have the most recent item, so a component is easy to find by scanning. Each group's own entries still sort newest first.
    2026-09-09
    v3.50.1

    Fixed: Reddit poll always failing

    • fix The πŸ“Š Poll button never sent which model provider to use, so the server always defaulted to Anthropic regardless of what is actually selected and working in the Ask box. If Anthropic's account is out of credit or otherwise unavailable, that made every single poll fail, while Ask itself looked fine since it lets you pick a different provider. Poll now sends whichever provider is currently selected there, and caches its result per provider so switching providers and polling again does not show a stale answer from a different one.
    2026-09-09
    v3.50.0

    Less clutter in the feed and the answer rail

    • ux The answer rail's sources are now split into two labeled groups, Documented (release notes, CVE) and Discussion (Reddit, the web), instead of one flat list mixing both kinds together.
    • ux Dropped the per-row "reddit"/"stackoverflow"/"CVE"/"patch" text chips from the feed. Each row's own icon and colored left border already say what kind it is, and the group header already totals each kind, so repeating it on every single row was pure noise. The one channel with no icon of its own (major) keeps a colored left border in its place.
    • ux More breathing room throughout: taller feed rows, bigger chips with more padding, and a roomier answer card.
    2026-09-09
    v3.49.1

    Keep the progress ticker after the answer arrives

    • fix The pipeline ticker used to clear the moment an answer arrived. It now stays on screen, with each step's final time frozen, until the next question is asked, so the full timing breakdown is there to review.
    2026-09-09
    v3.49.0

    The progress ticker is now real, not approximated

    • feat A real question's answer now streams as it happens. The "which phase is this" ticker above the input follows actual server sent events instead of guessed timing: Resolving vendor, Searching (with the real tool name, e.g. "release notes" or "CVE records"), Widening search window on the one automatic retry, and Generating answer. Each entry's elapsed time is genuine and live, freezing the moment the next real event arrives.
    • feat On a multi-agent pipeline (Multi-agent buggy or fixed), each step is also labeled with the paper's own role name (Rewriter, Retriever, Evaluator, Orchestrator), matching this platform's own architecture story. Single-agent shows the same phases without the role names, since that baseline has none.
    • fix The model can no longer answer with a bare bracketed citation like "[source]" or "【source】" that points at nothing. The system prompt now asks for a real named source or no citation at all.
    2026-09-09
    v3.48.0

    Visible progress while a question runs

    • feat A real question now shows a "which phase is this" ticker above the input (Resolving vendor → Searching sources → Generating answer), each step's own elapsed time counting up live and freezing once that step ends. There's no live signal from the server for this yet, so step *boundaries* are an approximation. Each step's own timer is real, though, and the last step (Generating answer) just runs until the actual response arrives rather than guessing at it.
    • ux The submit button's hourglass now visibly spins while waiting, instead of sitting static.
    • feat The πŸ”΄ CVE chip in the Recent Updates breakdown is now one chip per source bot (sourceBot-keyed, same convention as every other πŸ“¦ bot chip), not one opaque combined total. CVE isn't one bot's output, it's an isCve flag several different product bots each set on their own documents.
    2026-09-09
    v3.47.0

    The feed follows the question

    • feat Asking a real question that resolves a vendor or category (Vendor check on) now also filters the feed to it, so the answer and its full browsable history sit side by side. A question that doesn't resolve one goes back to showing everything, instead of leaving an unrelated filter in place.
    • ux Simplified the "Why create an account?" list in the sign-in view. Each reason is now one short, user-facing line instead of a longer technical description.
    2026-09-09
    v3.46.0

    Answers show inline, beside the feed

    • feat On a screen with room for it (laptop width and up), asking a real question no longer opens a popup. The answer renders in a sticky right-hand rail next to the feed instead, trimmed to a compact length with a "Show full answer" button and its sources shown as inline links. Narrower screens and "Compare all 3" still use the popup, since three side-by-side cards need the width.
    • feat Default Ask options changed: Model defaults to Ollama Cloud (free tier), Pipeline defaults to Single-agent, and Vendor check / Temporal filter / Intent filter are now checked by default.
    2026-09-09
    v3.45.0

    Search and Ask are one box now

    • feat The Search/Ask mode toggle is gone. There's one box. Type a plain vendor or category name ("chrome", "any sql updates recently") and it lists matching versions/CVEs, same as Search always did, still free and signed-out. Type a real question and it runs the full Ask pipeline as before (sign-in required, a real model call). /api/ask itself tells them apart before ever touching the model, using the same vendor/category resolution the Rewriter already does. A plain lookup never costs a call or needs sign-in, and a real question is unaffected.
    • fix Signing in is now only asked for when it's actually needed (a real question, or Compare all 3). Previously, the Ask form required sign-in up front for every submission, including what would have been a free lookup.
    2026-09-09
    v3.44.0

    Ask suggests real past community questions as you type

    • feat Typing 3+ characters into Ask now shows a dropdown of real, similar past community questions (each ≤15 words, ranked by relevance to what's typed), not a static "recent questions" list, and not client-side filtering over the public API (which has no free-text search and returns 3,240+ heavy documents by default). Picking one fills the input; the subreddit it came from shows alongside each suggestion. Public, no sign-in needed: it only reads existing Reddit data, no model call.
    2026-09-09
    v3.43.0

    Rate-limited providers show as unavailable, not clickable

    • ux When a provider is currently rate-limited, its Model option now shows "(rate limited)" and can't be selected, instead of letting you pick it and then hitting an error. Checked on page load, on every Model change, and after every ask attempt.
    2026-09-09
    v3.42.0

    Source breakdown cleanup, and readable Ask answers

    • fix The "Will search for..." preview strip was overlapping the "Recent Updates" heading right below it. It's a fixed overlay, not part of normal page flow, so nothing reserved space for it. Added a live-measured --preview-h offset (same pattern as the header's own --topbar-h) to the page's top padding.
    • ux Recent Updates source breakdown: sources with 0 results this window (e.g. StackOverflow) no longer show at all, and every source (CVE, community sources, and each bot) is now sorted together by count, highest first, not CVE/Reddit/StackOverflow-first regardless of size. Reddit and StackOverflow now show their real bot filenames, reddit.py and stackoverflow.py (confirmed against releasetrain-bot's actual scripts), matching every other bot chip's naming convention; CVE stays a plain label since it isn't one bot's output.
    • feat Ask answers render lightly formatted instead of as one plain-escaped block of text: **bold** and `code` render as real <strong>/<code>, bullet and numbered lists render as real lists, and blank lines become paragraph breaks. Still escapes the model's raw text first and only recognizes this fixed set of markdown syntax on top of that. Nothing in the answer can inject real HTML.
    2026-09-09
    v3.41.0

    Ask options are always visible now, no popover to open

    • ux Reworked the Ask form back to two always-visible rows: the question input on top, and every option (Model, Size, Pipeline, the three toggles, Usage, and the Ask button) in one row below it. Removed the Options (βš™οΈ) button and its popover from v3.35-3.40. Feedback was that hiding the controls behind a click made them easy to miss and needed an extra step just to see what's selected.
    • fix Usage now refreshes on Ask-mode activation, on a Model change, and after every ask attempt, instead of only while the (now-removed) popover happened to be open.
    2026-09-09
    v3.40.0

    Topbar: strictly two lines, controls right-aligned

    • ux Line 1 is now brand/title on the left, Search/Ask mode toggle (and the account chip, when signed in) pushed flush to the right. Previously they sat clustered right after the title with a lot of dead space beside them. Line 2 stays the active form (input + its own right-aligned buttons), same as before.
    • fix The "Will search for..." preview line no longer counts as a 3rd header row. It's now a thin floating strip anchored just below the header, so the header itself is a strict two rows regardless of whether a preview is showing.
    • fix The Ask Options popover was rendering open by default, every page load, before ever being clicked, due to a CSS specificity bug (its own display: flex silently beat the browser's default [hidden] handling). Caught while checking this change on mobile. Also fixed the popover overflowing off the left edge of the screen on narrow viewports (it was anchored to the small gear-button cluster, which sits near the left edge once the input wraps to its own row on mobile; now anchored to the full-width form instead).
    2026-09-09
    v3.39.0

    Ask can now find answers on the open web, not just Reddit

    • feat The Ask agent now has a search_web tool: when release notes, CVE records, and Reddit turn up nothing, it searches the open web and actually reads the top results (official vendor forums, bug trackers, GitHub issues - anything this platform doesn't scrape into its own data) before answering. Sources found this way show a 🌐 icon.
    • fix Temporal filter bug - a mismatched variable name meant the "only search the last N days" setting silently never reached any search tool. Caught from a real answer that cited a 6-month-old community post as "in the past 24 hours." Fixed and verified live.
    2026-09-09
    v3.38.0

    Ollama Cloud added as a third model, and a Size picker

    • feat Ollama Cloud is now a third Model option alongside Claude and Groq - a hosted API call (not a local install), so it works the same way on the production server as Groq does. Free tier.
    • feat Size picker - each Model now offers Small/Medium/Large, sized by whatever unit that provider actually publishes (parameter count for Groq/Ollama, Anthropic's own Haiku/Sonnet/Opus naming). The Model and Size lists are both fetched live from the server rather than hardcoded, so they always match what's actually configured and runnable.
    • fix Every model offered was verified to actually support tool calling before being listed - a couple of plausible-looking "smallest" picks (a 7B Groq model, several larger Ollama Cloud models) turned out to either reject tool calls outright or require a paid plan, so they were swapped for ones confirmed working live.
    2026-09-09
    v3.37.0

    Rate-limit hits now show up in Usage, not just as an error

    • feat When a provider actually rate-limits a request (e.g. Groq's "TPM: Limit 8000, Used 7333... try again in 21s"), that shows up in the Ask Options Usage line too - "⚠️ rate limited — retry in ~21s" - not only as the one-off error banner on the answer that failed. Refreshes automatically right after every ask attempt when Options is already open.
    2026-09-08
    v3.36.0

    Provider quota, and a Yes/No poll for Reddit questions

    • feat Usage line in Ask Options - shows how many calls have been made today and how much of the provider's own rate limit (requests and tokens) remains, sourced from the real headers the provider returned on its last call. Refreshes when the Options popover opens or the Model select changes.
    • feat Reddit Yes/No poll - a πŸ“Š Poll chip now appears on any Reddit item in the feed whose title/self-text looks like a question (contains "?") and has at least one comment. Clicking it classifies each top-level, non-author comment as Yes/No/Unclear against the post's own question in a single batched model call, and shows the tally (e.g. "No 2 Β· Unclear 2"). Hover the chip afterward to see the per-comment breakdown. Requires sign-in, same as Ask.
    2026-09-08
    v3.35.0

    Pick your model, and a simpler Ask bar

    • feat Model picker - choose which model answers your question: Claude (Anthropic) or Groq (free tier). Selecting Groq is useful when the Anthropic key is out of credit or rate-limited. The answer's model is now returned by the server and available for display.
    • ux Simplified the Ask bar - it was down to input, three checkboxes, two selects, and a submit button, all visible at once. The model select, pipeline select, and the three toggles (Vendor check, Temporal filter, Intent filter) now live in a popover off a single βš™οΈ Options button; the bar itself is just the question input plus Options and Ask (➀). Closes on outside click, Escape, or switching back to Search mode.
    2026-09-07
    v3.34.0

    Ask row restructured: input left, controls right, one Ask button

    • fix The Ask submit button said "Ask" right next to the "πŸ’¬ Ask" mode pill - same duplicate-label problem as the earlier Search fix. It's now an icon-only button (➀), matching Search's icon-only submit.
    • fix Question input stays on the left and grows; the checkboxes, preset select, and submit button are now one grouped block on the right that moves together rather than each control wrapping independently - was reading as cluttered with all three checkboxes, the select, and the button loose on one line.
    • feat The "Will ..." preview line now also reflects the checkboxes as you toggle them: time-box to last 3 days when Temporal filter is on (or the exact date if one's named in the question), tag intent:version-question when Intent filter is on, and a note when Vendor check is on - all computed client-side, matching what the server will actually do.
    • Confirmed the question text was never being cleared on submit (verified, no code touches it) - closing the answer modal or asking again keeps exactly what you typed.
    2026-09-07
    v3.33.0

    Topbar polish, and a search-term preview before you even ask

    • feat "Will search for: ..." preview appears below the Ask input as you type - a deterministic, client-only preview of which words will actually drive the match, computed before any API call, so it's visible even if the configured key has no credit yet. It's an approximation (the model can still add vendor synonyms this simple filter doesn't know), not the model's own eventual query.
    • fix Removed the redundant "Search" submit button next to the "πŸ” Search" mode pill (same label shown twice); it's now a plain icon button, still fully clickable and still the Enter-key default.
    • fix Moved the Search/Ask mode toggle to the right end of the topbar row, after the active form's own input and buttons, instead of crowding the left edge next to the brand.
    • fix The ☰ menu drawer no longer pads its content down by the topbar's full height before "Home" - that padding existed for a clearance the drawer doesn't actually need (it already renders above the topbar), and made the gap grow whenever Ask mode's extra checkbox row made the topbar taller.
    • fix Aligned the height of every control on the Search/Ask row (input, buttons, preset select, mode toggle) so the bar reads as one consistent strip.
    2026-09-07
    v3.32.0

    Evidence-gated Ask, merged topbar, light green theme

    • feat Vendor check / Temporal filter / Intent filter checkboxes on the Ask form, backed by releasetrain-server's new abstention-first gates: a question with no resolvable vendor or an opinion-shaped question (e.g. "what IT task is always a nightmare") now declines outright instead of guessing, and a dated question ("as of Jan 2026") is answered against what was true then rather than the latest release overall.
    • feat A live "detected intent" badge appears next to the Ask input as you type (client-side preview only - the full question is always sent to the server unchanged, since date/intent detection there needs the complete wording).
    • feat Each answer card now shows vendor/intent/temporal chips when set, an "Abstained" badge when the question was declined, and a collapsible "Show internals" section with the actual search calls made and the system prompt used.
    • feat Topbar merged into a single row (hamburger, brand, mode toggle, and the active Search/Ask form all share one line and wrap together on narrow screens, instead of stacking as separate rows).
    • feat Light green theme, replacing the prior gray one; the card feed no longer has its own bordered panel boundary, so it reads as part of the page rather than a separate box floating on it.
    2026-09-07
    v3.31.0

    Ask a question, not just search for a component

    • feat Ask mode: a toggle next to the search bar swaps component search for a natural-language question, answered by Claude with tool access to the same release-note, CVE, and Reddit sources the feed indexes (backed by releasetrain-server's new POST /api/ask). Every answer is a short summary with its sources always attached below it, never just prose on its own.
    • feat Pick which pipeline answers: Single-agent, Multi-agent (buggy - reproduces this project's own documented rewrite-replaces-query failure on purpose), Multi-agent (fixed - union fetch + BM25 rerank), or Compare all 3 side by side in one modal. Each answer gets a πŸ‘/πŸ‘Ž so real usage builds up exactly the kind of judged comparison data a bespoke score can't provide on its own.
    • feat Requires sign-in - each question is a real model call, not a free local search.
    2026-09-07
    v3.30.0

    Search bar pinned to the top, full width; gray theme

    • feat Search is always visible: pulled the component search bar back out of the ☰ drawer into the fixed topbar itself, so it stays on screen (and reachable without opening the menu) while scrolling. It now spans the full width of the page instead of a narrow sidebar column.
    • feat Gray theme: page background and card surfaces are now genuinely gray (previously a near-white surface on an almost-white background), with borders darkened to match. The blue brand accent is unchanged - it's the one color that still needs to read as "interactive."
    2026-09-07
    v3.29.0

    Everything but the feed moves behind the ☰ menu

    • feat One menu drawer, one card feed: the always-visible sidebar (search, filters, stats, activity chart, top searches) and the topbar's row of view links (Graph, Arch, CVE, Risk Report, Docs, Changelog, Credits, Account, Release) are now both inside a single off-canvas drawer opened with the ☰ button, at every screen width, not just on mobile. The default page is just the topbar and the card feed, full width.
    • feat Picking a view from the drawer closes it automatically; clicking the backdrop or pressing Escape also closes it. No filter/search/stat functionality was removed, only relocated.
    2026-09-07
    v3.28.0

    Admin dashboard: system overview

    • feat System overview panel in the Account view's admin section (visible to admin users only): bot-health freshness (which bots have gone quiet past their expected cadence, backed by releasetrain-server's new /api/admin/* endpoints), MongoDB storage usage against the Atlas free-tier cap, source-attribution unknown rate, and top-line collection counts, all in one refreshable view.
    • feat Bots are grouped Stale / Healthy / No data, each row showing last-seen date and age against that bot's own threshold, so a silent outage (like the ones this session's bot audit found by hand) shows up here automatically instead of needing a manual sweep.
    2026-09-06
    v3.27.0

    Breakdown is now by bot, not by type

    • feat One number per bot, not per type: the πŸ“¦ chips in the Recent Updates breakdown now key off the real sourceBot field (backfilled by releasetrain-bot's new maintainer.py source-attribution pass) instead of versionProductType. Grouping by type conflated multiple bots into one bucket ("Browser" = chrome.py + firefox.py + safari.py) and fragmented one bot into many (github.py's per-repo product names each got their own type). "unknown" covers documents from before the backfill, or that the inference genuinely couldn't place.
    2026-09-06
    v3.26.1

    Every other bot source now shown in the breakdown, by type

    • feat "By type" breakdown for everything not already CVE/Reddit/StackOverflow/LLM/Hypervisor: browsers, OSes, databases, languages, and every other source this system's ~30 other bots track now get their own πŸ“¦ chip (versionProductType, highest count first) instead of being invisible in the summary line entirely.
    • fix Grouping normalizes casing (so "browser"/"Browser" from different bots count as one bucket) but keeps whichever original casing was seen first as the display label β€” an earlier version of this ran every label through a naive title-case transform, which mangled real values like "OS" β†’ "Os" and "TypeScript" β†’ "Typescript".
    2026-09-06
    v3.26.0

    Per-source breakdown on the Recent Updates header

    • feat Source breakdown line under "Recent Updates": shows how many of the current (last 4 weeks) results are πŸ”΄ CVE, πŸ’¬ Reddit, and 🟧 StackOverflow, with πŸ€– LLM / πŸ–₯ Hypervisor appended when nonzero. Scoped to the same window as the header itself, not the sidebar's all-time totals, so it stays honest about what's actually in view.
    2026-08-28
    v3.25.0

    Tooling, tests, and cleanup

    • feat CI and smoke tests: GitHub Actions runs build, Biome lint, and a Playwright suite on every push and PR. The suite stubs the API and loads every view, failing on any uncaught JavaScript error.
    • feat Configurable API endpoint: resolves from ?api=, then <meta name="api-base">, then the built-in default. No more editing a source constant to run against a local server.
    • feat Global fault banner: an uncaught error or rejected promise now shows one dismissible banner instead of leaving an empty UI with no signal.
    • feat Single-sourced version: package.json is authoritative; the build stamps it into the page.
    • fix Pinned the lazily-loaded CDN libraries (Chart.js, mermaid, vis-network, pako) to exact versions with crossorigin.
    • fix Removed the build stack: Grunt, Jest, Babel and ESLint (all unconfigured or unused) are gone; npm run build is now a plain src/ to dist/ copy. Dependency count dropped from ~640 packages to ~55.
    • fix Deleted legacy standalone pages and assets no longer reachable from the app: /reddit, /label, /mltl, /juspn, /edi40-2023, plus src/lib, src/app.js, src/plantuml* and the two orphaned stylesheets. src/ is now index.html, img/ and data/graph.json.
    2026-08-28
    v3.24.0

    Denser, quieter UI

    • ux Compact / technical restyle: 13px base, 3px radius, flat hairline borders instead of shadows, monospace for numbers/versions/dates. Palette cut to two meaningful hues (CVE, risk) plus one interactive blue; LLM/hypervisor/"new" markers are now neutral slate, meaning carried by the chip label. Tightened topbar, sidebar, feed rows, chips and buttons.
    • ux Fewer quick-filters up front: the five community/risk toggles (Pot. CVE, Reddit, Reddit Risk, Risk Latest, Risk Security, SO Risk, SO) now live in a collapsed "community & risk filters" disclosure inside Filters. The six primary toggles (Major/Minor/Patch/CVE/LLM/Hypervisor) stay visible.
    • ux Sidebar sections collapsed by default except Filters. "Stats" and "Live Collection Stats" merged into one section β€” KPIs on top, all-time collection totals in a nested "Collection totals" disclosure.
    • ux Fewer chips per feed row: dropped the license and component-type chips (repetitive β€” every row in a group carried the same values). Security-type and breaking-change chips stay, since they flag something actionable.
    • feat Graph view: nodes with zero edges are hidden from the canvas and listed in a new "Isolated nodes" sidebar section; physics tightened and the view auto-zooms in closer after stabilization.
    2026-08-28
    v3.23.0

    Hypervisor as its own category: feed, filter, KPI, chart

    • feat Hypervisor releases highlighted in the feed: entries whose versionProductType is Hypervisor (the new hypervisor.py bot's value β€” VMware ESXi / Workstation / Fusion, Oracle VirtualBox, Xen, Proxmox VE, XCP-ng) get a teal left-border/background and a πŸ–₯️ Hypervisor chip. Mirrors the LLM treatment added in v3.22.0 via a parallel isHypervisorVersion() predicate.
    • feat Hypervisor quick-filter + KPI: a πŸ–₯️ Hypervisor sidebar toggle and a πŸ–₯️ Hypervisors tile in the Stats block, alongside πŸ€– AI Models. Combines with the other quick-filter toggles the same way.
    • feat Dedicated background dataset: ensureHvVersionsLoaded() / Api.hypervisorVersions() pull the full, date-window-independent hypervisor dataset (anchored on KNOWN_HV_PRODUCT_NAMES), so the KPI/toggle show the true total and the toggle surfaces full history rather than just what's inside the 4-week feed window β€” hypervisor releases are as sparse in time as AI-model releases.
    • feat Activity chart gains a Hypervisor line: the sidebar activity chart now plots a fifth (teal) series for hypervisor releases per day, computed client-side from the full dataset via computeHvDailyFromRaw() / refreshActivityChartHvLine(). The static mini-legend under the chart now lists all five series.
    • feat Shareable ?type=hv link: releasetrain.io/?type=hv loads with the πŸ–₯️ Hypervisor toggle already active; setTypeParam() now round-trips llm and hv.
    • feat Arch view (?view=arch) now stacks in three tiers: hypervisor base layer β†’ OS β†’ applications, nested as PlantUML packages. New aIsHypervisorComponent() (feed versionProductType === "Hypervisor", or the A_HYPERVISOR name fallback) partitions components; each tier is optional and collapses out when empty. Added a VIRT sample stack (xen Β· debian Β· nginx) that exercises all three layers.
    2026-08-18
    v3.22.0

    LLM as its own category: feed, filter, KPI, chart, and search

    • feat AI model releases highlighted in the feed: entries whose versionProductType is LLM, Embedding Model, or Multimodal Model (the ai_model.py bot's values) now get a violet left-border/background and a πŸ€– LLM chip, distinguishing them from regular software releases at a glance.
    • feat LLM quick-filter: a new πŸ€– LLM toggle in the sidebar filters the feed to just AI model releases, combining with the existing Major/Minor/Patch/CVE toggles the same way they combine with each other.
    • feat AI Models KPI: a new πŸ€– AI Models tile in the sidebar Stats block, alongside Groups/Components/Reddit, giving LLM releases equal billing as their own top-level count rather than being buried in the generic type-filter list.
    • fix AI Models KPI/toggle badge showed 0 even when real data existed: both were computed only from the windowed feed (STATE.rawVersions), which almost never contains an LLM doc since AI model releases are sparse enough in time to rarely land inside the lookback window. Added ensureLlmVersionsLoaded() β€” a dedicated background fetch (mirrors ensureRedditLoaded()) that pulls the full, date-window-independent LLM dataset via Api.llmVersions(), filtered client-side to real versionProductType matches. The badge/KPI now shows this true total once loaded.
    • fix Api.llmVersions() initially found only 3 of ~560 real documents: the server's q search matches near-exact versionProductName, not substring "contains" (confirmed empirically β€” q=Claude only finds the doc named exactly "Claude", not "Claude 2" or "Claude 3.5 Sonnet"), so a handful of generic brand keywords like "mistral"/"openai" mostly missed. Added KNOWN_LLM_PRODUCT_NAMES, an exact-match anchor list (~390 terms) generated from ai_model.py's actual scraped catalog β€” Ollama library slugs plus every OpenAI/Anthropic/Mistral/xAI/DeepSeek/Meta/Gemini Wikipedia table entry. Queried as CSV OR terms, chunked into parallel requests to keep each query string a reasonable size. Now finds ~524 of the ~564 real documents (verified live). Needs periodic regeneration as ai_model.py scrapes new models; stale entries are harmless, they just stop matching anything.
    • feat LLM toggle now actually surfaces full history: clicking πŸ€– LLM merges STATE.llmVersions into the candidate pool and bypasses the recency window for the merged items (same mechanism as an active search), so old AI model releases become visible in the feed instead of the toggle just showing an accurate count with nothing to click into.
    • feat Activity chart legend enabled, labeled, and clickable: the legend was previously hidden entirely (display: false), so the LLM line added earlier had no visible label. Now shown at the bottom in a compact style; clicking a label toggles that line's visibility, using Chart.js's built-in legend behavior. Chart height bumped slightly to fit the legend row, with a small "Click a label to show/hide that line" hint underneath. The LLM line itself now sources from STATE.llmVersions (the full dataset) rather than the windowed feed, for the same reason as the KPI fix above.
    • fix Search couldn't find components outside the feed window: searching for a named component (e.g. "Mistral", "Ollama") previously came up empty whenever that component's releases were all older than the lookback window, even though the server correctly returned them. The recency cutoff now only applies to the default recent-activity feed; an explicit component search (or the LLM toggle) shows full history instead. New withinFeedWindow(v, comps, bypassRecency) helper shared by applyFilters() and filterVersions().
    • fix Autocomplete now suggests components beyond the current feed window: previously the search box only suggested names/tags already present in STATE.rawVersions, so a component with no recent release (like most AI model brands right now) never appeared while typing. The suggestion pool is now seeded from the full /api/c/names list on page load, merged with what's currently loaded.
    • fix Range KPI now reflects what's actually shown instead of always claiming the fixed lookback window β€” computed from the min/max release date of the currently filtered items, so it stays honest when a search surfaces older results.
    • fix Feed description text no longer shows a bare URL: several bots (python.py, java.py, eclipse.py, ai_model.py) store a URL in versionReleaseNotes rather than prose. The card description now detects that case and shows versionReleaseComments instead β€” the URL was already the clickable title link, so nothing is lost.
    • feat Lookback window widened from 7 days to 4 weeks: feed, activity chart, and Reddit/StackOverflow matching all now cover the last 28 days instead of 7. Renamed SEVEN_DAYS_MS/SEVEN_DAYS_AGO to LOOKBACK_MS/LOOKBACK_AGO (backed by a single LOOKBACK_DAYS = 28 constant) so the window can be tuned in one place going forward.
    • feat Shareable ?type=llm link: releasetrain.io/?type=llm now loads with the πŸ€– LLM toggle already active. Client-only β€” confirmed via the API docs that there's no server-side versionProductType filter param (/api/v/search only supports q, channel, isCve, start/end, fields, showCount). Round-trips both ways: clicking the toggle updates the URL via setTypeParam(), and "Clear all" removes it again.
    2026-05-22
    v3.21.1

    Strip trailing commas from search queries

    • fix Query normalization: trailing and leading commas are stripped before tracking a search, displaying top searches in the sidebar, and showing queries in the admin search events table.
    v3.21.0

    Component search tracking, admin search activity view

    • feat Search tracking: every component search is recorded server-side with query, timestamp, IP, and user agent. Logged-in users are identified by userId; unauthenticated searches are recorded as anonymous.
    • feat Admin search activity: the Account view for admin users now includes a Component searches table showing all recorded searches across all users, including anonymous, sorted newest first.
    • feat Top searches sidebar: the home feed sidebar shows the top 3 searched components in the last 24 hours as clickable links, open by default. Sourced from a new public aggregate endpoint.
    2026-05-21
    v3.20.1

    Release view fixes, URL cleanup, view param consistency

    • fix Release view: vendor-only: removed source filter dropdown; view always shows the current account's own published releases. Source filter no longer allowed switching to third-party extracted data.
    • fix Experience reports embedded: reports are now stored as an array on the version document and rendered inline on load. Removed separate knowledge_reports collection and the extra fetch per card.
    • fix Vendor releases visible in home feed: two filters were hiding vendor-published releases. Server-side: end=today (local date) excluded documents stamped with tomorrow's UTC date; vendor docs now bypass the date cap. Client-side: versionTime() maps a release date to noon UTC, which is ahead of local Date.now() for negative-offset timezones; vendor docs now bypass the future-date guard.
    • fix View URL params consistent with nav labels: ?view=network renamed to ?view=release to match the 🌐 Release nav label. Added missing ?view=account routing entry so the Account view is reachable via URL.
    • ux No %2C in URL: multi-component search queries now display literal commas in the address bar. Trailing commas typed in the search field are stripped before writing to the URL.
    • feat Subreddit search: searching a subreddit name with no matching versioned component now shows a community posts group. Posts from matching subreddits are surfaced even when no version data exists for that name.
    2026-05-21
    v3.20.0

    Release Knowledge Network view

    • feat Network view: new 🌐 Network nav entry. Authenticated vendors can publish releases under a unique namespace. Namespaces are validated against existing tracked vendor names. Other users can report production outcomes per release (worked well, had issues, upgraded from version).
    • feat Discover tab: lists published releases with collapsible experience reports. Reports show outcome, from-version, description, date, and reporter.
    • feat Publish tab: form with vendor namespace, component name, version, channel, optional release notes URL and description. Namespace is validated client-side before submission.
    • ux Unauthenticated users see a gate screen explaining the feature with a direct sign-in prompt.
    2026-05-21
    v3.19.0

    Risk Report: multi-component, search integration, score legend

    • feat Renamed Dashboard to Risk Report: nav link and title updated to reflect the feature's purpose.
    • feat Multi-component risk analysis: the risk report now reads components directly from the feed search field. Multiple comma-separated components are supported and scored together.
    • feat Score legend: the sidebar shows risk level thresholds (Low, Medium, High, Critical) and the scoring factors used to compute the score.
    • fix Removed redundant Component input from the Risk Report sidebar; the feed search field is now the single source of truth for component selection.
    2026-05-21
    v3.18.1

    Org namespaces in share links, bookmarks, topbar login indicator

    • feat Organization namespaces: users can add up to 2 org slugs to their profile. Each slug is embedded in every bookmark share link as ?org=name&share=… so recipients can identify the source organization. Slugs are validated as 1 to 32 alphanumeric, dash, or underscore characters.
    • feat Bookmarks: signed-in users can save named searches via the πŸ”– button in the feed sidebar. Each bookmark stores a URL and generates a public share link. Opening a share link restores the saved search automatically.
    • feat Topbar login chip: a small badge showing the logged-in user name or email appears in the topbar at all times when a session is active. Clicking it opens the Account view.
    • feat Bookmark list in Account view: the profile panel lists all saved bookmarks with Open, Copy link, and Delete actions. Refresh button reloads the list from the API.
    • feat Why create an account section: collapsible panel in the sign-in view lists the technical advantages of having an account including org namespaces, server-side bookmark storage, cross-device persistence, share links, JWT session, and admin role access.
    • fix Org namespaces moved server-side: org names are now snapshotted onto the bookmark document at creation time and returned by the share endpoint. Share URLs are clean (?share=abc123 only). Recipients see a "Shared by: orgname" banner for 4 seconds when opening a share link. Org chips are shown on each bookmark row in the Account view.
    • feat Bookmark rename: an Edit button on each bookmark row opens an inline text input. Submitting saves the new name via PUT /api/bookmarks/:id and refreshes the list. Keyboard shortcuts Enter and Escape confirm and cancel the edit.
    • feat Chart.js graph view: the Graph view now renders four Chart.js charts: release activity over time (line), top components by release count (horizontal bar), channel breakdown (donut), and CVE releases per week (bar). Sigma.js network graph removed. Time window and data source are selectable from the sidebar.
    • feat vis-network graph view: the Graph view now renders a force-directed node and edge network. Each searched component becomes a hub node. Version nodes, CVE release nodes (diamond), Reddit posts, CVE-mention posts, high-risk posts, and StackOverflow posts are positioned as satellites. Edge length encodes date delta: nodes from today are close to the hub; older nodes are farther. Multiple searched components produce multiple hub nodes. Layer visibility, time window, and risk filters are controlled from the sidebar.
    2026-05-19
    v3.16.0

    Live Collection Stats in home sidebar, mobile feed scroll, 7-day data window

    • feat Live Collection Stats panel added to the default feed sidebar: shows total versions, CVE advisories, release notes, and community post counts fetched from the API on page load.
    • feat Today count and yesterday delta in brackets for both Versions and Community totals: format is 54,210 [42 today, +12%]. Delta % is green when higher than yesterday, red when lower. Fetched from /api/v/aggregate/byDate and /api/aggregate/reddit/count.
    • ux Home sidebar stats also pre-populate the Docs sidebar Live Collection Stats so values appear immediately when switching to the Docs view.
    • fix Feed panel scrollable on mobile: max-height: 70vh; overflow-y: auto on #feedPanel at max-width: 640px so the version feed scrolls independently rather than expanding the full page height.
    • feat Data window changed from 6 months to 7 days: Api.versions sends start as 7 days ago; client-side version and community post filters apply the same 7-day cutoff. Feed header updated to reflect the new window.
    • fix Feed sort and Range KPI now use versionReleaseDate instead of versionTimestampLastUpdate. Since bots set versionTimestamp to Date.now() on every upsert, the old sort collapsed all items to today. Range now reflects actual release date spread across the 7-day window.
    • fix Removed start param from Api.versions(): previously sending start = 7 days ago restricted the server to only documents with versionReleaseDate in the last 7 days. Server now uses its 2-year rolling window and returns the 150 most recently released versions; the 7-day client filter then trims the result. end=today is still sent to suppress future-dated documents.
    • fix versionTime() now strips dashes before testing the 8-digit pattern, accepting both YYYYMMDD and YYYY-MM-DD release date formats.
    • fix Community bracket now always shown when API data is available, even when today count is zero. Previously the bracket was suppressed if rTodayN === 0, hiding the delta from endpoints that count by created_utc rather than ingestion date.
    • fix Range KPI updates as infinite scroll loads new pages: extracted range calculation into updateRangeKpi(items) helper, called from both applyFilters() and the scroll page-fetch callback after new groups are merged into STATE.groupsFiltered.
    • fix Full 7-day window now loads automatically: appendNextGroups always continues via requestAnimationFrame after each batch, so once all local groups are rendered it falls through to the cursor-fetch branch and loads subsequent server pages without requiring a scroll.
    • feat Relative time labels for recent feed items: items from the last 2 hours now display "X min ago" (under 60 min), "1 hr ago" or "2 hr ago" (under 2 hr) instead of "Today". Older items keep the existing "Today" / "Yesterday" / date labels. isNew is now based on a midnight timestamp comparison rather than string matching.
    • feat Activity chart added to home sidebar: compact 7-day per-day line chart showing versions and community post counts computed from loaded state. Renders using Chart.js, loaded lazily on first use.
    • fix Community bracket today count now accurate: bracket is computed from STATE.redditAll using redditTime() after the post index loads, replacing the unreliable /api/aggregate/reddit/count per-day endpoint which counted by created_utc rather than ingestion date.
    • fix CVE feed items now open NIST NVD: the open link on CVE entries resolves to versionUrl (the NVD advisory URL stored on the document) instead of the internal API endpoint. Falls back to the API URL when versionUrl is absent.
    • fix Activity chart data sourced from range aggregate endpoints: loadHomeStats now calls /api/aggregate/v/versionCountByDay and /api/aggregate/reddit/countByDay with a single 7-day window each (2 requests total), replacing 14 individual per-day calls. Results are mapped from sparse { _id, count } arrays to the fixed 7-day label sequence before passing to updateActivityChart.
    • fix Community line in activity chart now renders correctly: /api/aggregate/reddit/countByDay was filtering created_utc with YYYYMMDD strings, which matched nothing because the field stores Unix epoch seconds (int/double/string) or ISO date strings. Endpoint rewritten to normalize created_utc to a UTC Date via a $switch pipeline stage, then filter and group on the normalized value. Client also patches the community dataset from STATE.redditAll after reddit loads, as a fallback for the current deployment.
    • feat CVE line added to activity chart: chart now shows three lines: Versions (indigo), CVE (red), Community (green). CVE per-day counts sourced from new /api/aggregate/v/cveCountByDay endpoint, which filters isCve: true and groups by versionReleaseDate. Falls back to counting v.isCve from STATE.rawVersions when API data is unavailable.
    • fix Mobile scroll restored for all views: dashboard had no mobile CSS rule and was unscrollable with overflow: hidden and a two-column pane layout. All views now scroll on mobile: dashboard panes stack vertically and the page scrolls naturally; docs and ack views drop their fixed height so page scroll applies; CVE view sets a min-height and adds touch-action: pan-y to the inner scroll list; changelog clears its overflow clip; -webkit-overflow-scrolling: touch added to all inner-scroll containers for iOS compatibility.
    2026-05-18
    v3.15.0

    Reddit integration in feed cards, timeline sort fixes & docs rewrite

    • feat Reddit and Stack Overflow posts now appear inside each component feed card, interleaved chronologically with version entries using a two-pointer merge.
    • feat 🟧 SO toggle added to the left sidebar: counts Stack Overflow posts matched to the active component set.
    • fix created_utc stored as Unix epoch seconds was being parsed as milliseconds (β†’ 1970). Now multiplied by 1000 before passing to Date().
    • fix versionTimestamp is set to Date.now() on every bot upsert, making all versions appear as "today". Timeline now uses versionReleaseDate (YYYYMMDD) as the sort key instead.
    • fix Reddit posts were appended as a block after all versions. Replaced .sort() with a proper two-pointer merge of two pre-sorted arrays to guarantee chronological interleaving.
    • fix Left sidebar toggle counts (πŸ’¬ Reddit, ⚠️ SO Risk, etc.) stayed at 0 after reddit loaded. paintFixedCounts now fires inside ensureRedditLoaded() once the index is built.
    • fix positiveScore > 0.5 filter was too strict β€” many posts have no ML score. Feed now fetches from /api/reddit?limit=400 (all recent posts by date) instead of the positive-score endpoint.
    • ux Partial subreddit matching: "android" matches "androiddev", "chrome" matches "googlechrome", etc.
    • ux Reddit items in the feed card show an orange left border and an r/subreddit chip; Stack Overflow items show amber.
    • docs Docs view rewritten: marketing language removed, section headings use : instead of Β·, AI chat section now describes the RAG pipeline technically (FAISS index, cosine similarity, cross-encoder reranking, LLM prompt injection).
    • fix Default feed no longer shows future-dated documents: server request now sends end=today and the client-side filter rejects any version with versionReleaseDate > now.
    • fix Mobile scroll broken: html, body { overflow: hidden } was trapping all content on narrow viewports where the feed panel loses its own scroll container. Override to overflow: auto; height: auto at max-width: 640px.
    • feat New bot nodejs.py: polls nodejs.org/dist/index.json, derives release channel from semver and security flag, maps LTS codename, and posts to /api/v. Lookback window configurable via LOOKBACK_DAYS.
    2026-05-17
    v3.14.0

    Dashboard graphs, phone layout & changelog

    • feat Hub-and-spoke dependency map on dashboard right pane: visualises componentβ†’versions, CVE versions, Reddit posts, and Reddit+CVE edges on a DPR-aware canvas.
    • feat Ecosystem snapshot graph on aggregate left pane: auto-selects the most diversely-connected component from the live dataset.
    • feat Release cadence bar chart (releases/week) and Reddit mention trend line chart added to the component pane.
    • fix Reddit mention trend was always empty: day-key format mismatch (YYYYMMDD vs YYYY-MM-DD) corrected.
    • ux Dashboard right pane now scrolls independently; left pane and page remain locked.
    • ux Changelog view added (this page) with semver-labelled entries.
    • ux Graph view on phones: Sigma canvas reduced to 60 vh; sidebar controls collapse to a fixed bottom-sheet overlay.
    • perf touch-action: none on graph canvas prevents iOS scroll hijack during pinch-zoom.
    • perf prefers-reduced-motion media query disables all animations for users who opt out.
    • ux Added meta theme-color and color-scheme for better browser chrome theming.
    2026-05-10
    v3.13.3

    Dashboard two-pane layout

    • feat Two-pane dashboard: Total Aggregate (left, always global) and Component (right, filtered).
    • feat Sample chips in empty right pane for quick component selection.
    • feat Page scroll locked while dashboard is active; restored on exit.
    • fix Removed duplicate "Add component" input from dashboard sidebar.
    • ux Main search always syncs to dashboard on activate.
    2026-04-28
    v3.13.2

    Dashboard KPIs & timeline

    • feat KPI strip: Today count, Last 2 yrs, CVE today, Signals today: all with delta badges.
    • feat Release & signal timeline line chart with configurable window (7 / 30 / 90 days).
    • feat Update-type bar chart (major / minor / patch / CVE) with yesterday comparison.
    2026-03-15
    v3.13.0

    πŸ“ˆ Dashboard view introduced

    • feat New Dashboard nav entry with sidebar controls (timeline window, date picker).
    • feat Aggregate version counts fetched from /api/v/aggregate endpoints.
    • feat Community signals section: Reddit and StackOverflow post counts.
    2026-01-20
    v3.12.0

    CVE timeline view

    • feat Dedicated CVE view with filterable timeline and CVSS severity chips.
    • feat Reddit / SO risk-signal overlay on CVE cards.
    • ux Responsive CVE cards collapse gracefully on narrow viewports.
    2025-11-04
    v3.11.0

    Graph view: Sigma.js

    • feat Component dependency graph powered by Sigma.js with cost-based node colouring.
    • feat Layer toggles (versions, Reddit/SO posts, CVE posts, CVE versions).
    • feat Ring-overlay canvas for component groupings.
    • ux Node info panel on click with links to API endpoints.

    🀝 Credits & Acknowledgements

    We gratefully thank the following open data, open-source teams, and services whose APIs, feeds, databases, and software helped build releasetrain.io.

    πŸ€– Agentic AI: open-source frameworks, tools, and models

    The Ask pipeline (Rewriter, Retriever, Evaluator, Orchestrator) uses the open-source software and open-weight models below; the models marked selectable are offered as options but are not the default. The agent loop, BM25 reranking, and guardrail wiring are our own code. The experimental LangGraph pipeline option uses LangGraph.js for its Retriever/Evaluator retry loop only; no LlamaIndex or other agent SDK is used.

    • Node.jsServer runtime for the Ask agent pipeline (Rewriter, Retriever, Evaluator, Orchestrator)
    • ExpressHTTP API and streamed progress events for Ask, including the delegated multi-agent runs
    • node-fetchHTTP client for every model-provider and retrieval-tool call; no vendor agent SDK is used
    • MongoDB Node.js DriverReads the evidence (versions, CVEs, Reddit) the Retriever searches and stores each Ask run and its feedback
    • prompt-protectionPrompt-injection scan of tool results and answer-leak scan of final answers (MIT)
    • express-rate-limitRequest rate limiting in front of the Ask endpoint
    • Ollama CloudHosted API (default provider) that serves the open-weight agent models; the app calls this service and does not run Ollama locally
    • OpenAI gpt-ossOpen-weight gpt-oss models: gpt-oss-120b is the default agent model (Ollama Cloud, medium); gpt-oss-20b (small) and the Groq-hosted versions are selectable
    • Qwen (Alibaba Cloud)Open-weight Qwen model, selectable as the medium agent model on Groq (not the default)
    • NVIDIA NemotronOpen-weight nemotron-3-super, selectable as the large agent model on Ollama Cloud (not the default)
    • LangGraph.jsGraph orchestration for the experimental LangGraph pipeline option: runs the Retriever/Evaluator retry loop as a graph (optional; falls back to our own loop)
    • LangChain Core (@langchain/core)Runtime library that LangGraph.js is built on
    • MermaidAsk pipeline and multi-agent architecture diagrams in the Docs view

    πŸ§ͺ Rewriter Eval

    πŸ§ͺ Evaluator Eval

    πŸ§ͺ Orchestrator Eval

    Sign in

    Create account

    Gmail, Outlook, Yahoo, iCloud, ProtonMail, AOL, or a .edu address. Disposable/temp-mail addresses aren't accepted.

    Why create an account?

    • πŸ”–Save a search once, reopen it from any device.
    • πŸ”—Share a link and recipients see your exact filtered view.
    • πŸ”Stay signed in across tabs and reloads, with no re-entering credentials.
    • πŸ“ŒYour saved searches are private to your account.
    • πŸ›‘Admins can view, edit, and remove any user account.
    • 🏷Add up to 2 org names to brand your share links (?org=…).
    Visitors, last 14 days
    Change password
    Model provider keys (use your own instead of the shared server key)

    A key set here is used for your own Ask requests in place of the shared server key. Stored on your account; only the last 4 characters are ever shown back. Save an empty box to clear it and fall back to the shared key.

    Organization namespaces (appear in share links)

    Max 2. Each name is appended to share links as ?org=name&share=…. Alphanumeric, dash, or underscore only.

    Bookmarks

    Save searches using the πŸ”– button in the sidebar. Share links are public.

    No bookmarks yet.
    Installed versions

    Record the versions you actually run. The Arch view compares them against the latest release to show how far each component has drifted. Saved to your account, so it follows you across devices.

    β€Ί Paste a list

    One per line: component@version, component version, or component,version. To also record vendor/machine, use component@version@vendor@machine (leave a segment blank to skip it, e.g. apache@2.4.58@@Web Server). Existing entries (matched by component + vendor + machine) are updated.

    No versions recorded yet.
    Visitors
    0Visits
    0Unique visitors (IPs)
    0Questions asked
    0API requests

    Countries

    Views

    Referrers

    Recent visitors green = seen today

    Counted from the web server's access log. Bots, health checks and this server are excluded. IP addresses are personal data: they are shown to admins only and the log is kept 45 days. Country from IP: IP Geolocation by DB-IP.

    Server alerts

    From the server watchdog, deploys and the weekly report. The same messages are emailed to the admin address.

    Loading…

    System overview

    Loading…

    Guardrails

    Mandatory

    Always applied; only an admin can turn one off, and doing so removes a specific, documented safety or correctness fix.

    Loading…

    Optional

    Applied by default at the setting below; a signed-in user may override this for their own questions.

    Feedback Loop

    Flags a vendor on its answers' Feedback Loop tab once real user ratings run negative past these thresholds.

    Loading…

    Settings

    Loading…

    Bot health thresholds

    How many days a bot may go quiet before the System overview panel's Bot health card flags it stale. Leave a row at its default unless that bot's normal update cadence genuinely differs.

    Loading…

    Vendor catalog

    Corrects or adds a vendor name the automatic catalog (built from tracked release data and Reddit subreddit names) doesn't resolve on its own, e.g. mapping "ada" to "Ada" when a real product's automatic verification is ambiguous.

    No aliases yet.

    Manual gap-fill trigger

    Manually run the same automatic-catalog gap-fill a bot's own fallback triggers for a vendor with zero tracked evidence. The result also shows up in the System overview panel's "Recent vendor gap-fills" list above.

    All users
    Search & Ask activity
    🌐
    Releases

    Vendors publish releases. Users report production outcomes. Collective knowledge answers questions like "How did version 4.2 perform?" or "Who upgraded successfully from 3.9?"

    Value grows with participation. Sign in to publish releases and report experiences.

    Loading releases...
    3 to 32 characters: lowercase letters, digits, hyphens. Must not match an existing tracked vendor name.

    πŸ“‹ Recent Updates (last 2 weeks)

    Idle
    πŸ”

    No updates match the current filters.

    Loading more…
    Ecosystem Metrics
    Total 0
    Stacks 0
    CVE 0
    Behind 0
    On latest 0
    Version unknown 0
    PlantUML Code
    
        
    Details
    Components
    β€”
    Stacks Detected
    β€”
    Config

    Changing the PlantUML server updates where images are fetched from for this session.