Skip to content

Commit ccf1a45

Browse files
committed
release: v0.10.0
1 parent 323a5be commit ccf1a45

6 files changed

Lines changed: 197 additions & 6 deletions

File tree

CHANGELOG.md

Lines changed: 191 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -2,6 +2,197 @@
22

33
All notable changes to this project will be documented in this file. Entries are generated by homeboy from git commits.
44

5+
## [0.10.0] - 2026-06-26
6+
7+
### Added
8+
- emit WordPress hotspot artifacts from fuzz suites
9+
- add WordPress fuzz hotspot artifact contract
10+
- expose WordPress fuzz suite executor
11+
12+
### Changed
13+
- Expand live progress event counts
14+
- Add contained site sync browser SDK
15+
- Validate canonical fanout worker result refs
16+
- Bridge PHP workload files in fuzz suites
17+
- Support staged PHP workload files
18+
- Normalize Codebox live progress handoff events
19+
- Keep bench command in expanded runtime policy
20+
- Allow bench workloads to use WordPress commands
21+
- Harden browser handoff contracts
22+
- Return workload command results from fuzz executors
23+
- Preserve runtime workload fuzz results
24+
- Support bench request case artifacts
25+
- Normalize runtime requirement plugins for CLI fuzz runs
26+
- Support typed workload steps in CLI fuzz runs
27+
- Run CLI fuzz workloads through recipes
28+
- Execute runtime workload fuzz targets
29+
- Add Codebox query capture contract
30+
- Run generic agent task workflow
31+
- Read typed artifacts from snake case task result
32+
- Read typed artifacts from runtime outputs
33+
- Read typed artifacts from task result outputs
34+
- Read typed artifacts from raw runtime results
35+
- Normalize mapped typed artifact outputs
36+
- Add run plan progress snapshots
37+
- Cover deterministic fanout dependency execution
38+
- Define headless agent task public boundary
39+
- Stabilize public fuzz runtime capabilities
40+
- Add public browser preview SDK starter
41+
- Document public handoff abilities
42+
- Clean up public boundary docs and tests
43+
- Make browser executable sessions runnable
44+
- Hide internal agent runtime substrate from public contracts
45+
- Tighten public boundary docs
46+
- Add public browser runtime contract
47+
- Keep runtime substrate behind Codebox boundary
48+
- Add public fuzz workload CLI commands
49+
- Add artifact postprocess workload step
50+
- Add public runtime fuzz primitives
51+
- Preserve prepared runtime profiles
52+
- Validate browser session boot contracts
53+
- Capture editor block validity evidence
54+
- Emit public agent task result envelopes
55+
- Add Blocks Engine visual parity adapter
56+
- Document runtime provider CLI selection
57+
- Remove legacy Codebox ability aliases
58+
- Generate concrete REST and block fuzz samples
59+
- Expose WordPress fuzz contracts entrypoint
60+
- Add REST performance observation command
61+
- Add public API WP-CLI runtime wrappers
62+
- Fail closed for runtime-backed fuzz suites
63+
- Validate browser runtime materialization
64+
- Neutralize external orchestrator boundary
65+
- Add fuzz workload hook hotspot sampling
66+
- Neutralize agent outcome classification
67+
- Group REST DB query profile fingerprints
68+
- Neutralize Codebox workflow access token naming
69+
- Normalize WordPress page load modes
70+
- Add fuzz coverage plan artifacts
71+
- Normalize performance observation placeholders
72+
- Register Codebox abilities after lifecycle replay
73+
- Redact fuzz suite REST DB query samples
74+
- Capture fuzz suite REST DB queries through query filter
75+
- Ensure CLI build output is executable
76+
- Install packaged browser plugins via PHP
77+
- Capture REST DB profiler queries through query filter
78+
- Support browser function invocations
79+
- Use fresh browser recipe blueprints
80+
- Add fuzz runner capability contract
81+
- Add fuzz suite reset policy
82+
- Expose core PHP snippet package entrypoint
83+
- Align PHP DB inventory schema contract
84+
- Include browser recipes in blueprints
85+
- Return raw browser blueprints
86+
- Allow public prepared blueprint hydration
87+
- Accept snake case component source roots
88+
- Cache package classmap autoloads
89+
- Lazy-load package classmaps
90+
- Preserve prepared extra plugin sources
91+
- Bridge staged package classmaps
92+
- Eager-load installed package classmaps
93+
- Share recipe plugin preload for activation
94+
- Support measured fuzz artifact summaries
95+
- Report plugin autoload diagnostics on activation fatals
96+
- Preload plugin package autoloaders
97+
- Mirror Composer path repositories for source packages
98+
- Preserve vendors in prepared source staging
99+
- Register Agents API runtime adapter by default
100+
- Hydrate source packages with existing vendors
101+
- Skip active recipe plugin replay during setup
102+
- Preload Composer autoloaders for run-php plugins
103+
- Preload Composer autoloaders for plugin activation
104+
- Load Composer autoload before package init
105+
- Bridge package autoloaders to Composer autoload
106+
- Hydrate source packages with Composer plugins
107+
- Preserve source package vendor trees
108+
- Recover browser blueprint refs from contained-site input
109+
- Preserve generated package autoloaders
110+
- Stage agent task recipes in artifacts
111+
- Honor source roots for component contracts
112+
- Map runtime package options for Agents API
113+
- Support monorepo plugin source subpaths
114+
- Resolve runtime package sources in Codebox
115+
- Normalize runtime package task outcomes
116+
- Preserve activation when deduping extra plugins
117+
- Gate fuzz suites on runner capabilities
118+
- Honor runtime requirement extra plugins in task recipes
119+
- Clear REST route context during fuzz route refresh
120+
- Add browser playground session run primitive
121+
- Clean up runtime provider boundary
122+
- Refresh REST server after fuzz plugin activation
123+
- Initialize REST routes for JSON fuzz workloads
124+
- Execute JSON fuzz workloads
125+
- Add browser session evidence refs
126+
- Treat runtime replies as terminal answers
127+
- Support fuzz browser coverage primitive
128+
- Seed default Data Machine sandbox agent
129+
- Include substrate in agent task recipes
130+
- Mount Data Machine runtime substrate by default
131+
- Support database inventory fuzz primitive
132+
- Include Agents API in agent task runtime defaults
133+
- Support admin page fuzz primitive
134+
- Support REST route inventory fuzz steps
135+
- Make ability execution principal configurable
136+
- Standardize runtime command result envelopes
137+
- Normalize runtime local preview access
138+
- Add generic preview lease provider contract
139+
- Add runtime access contract
140+
- Keep runtime provider defaults neutral
141+
- Add inventory primitives and fuzz contract gates
142+
- Include bundled runtime plugin in agent tasks
143+
- Accept stable agent task CLI requests
144+
- Complete runtime contract manifest aliases
145+
- Report public preview lease metadata
146+
- Make preview hold cap configurable
147+
- Apply distribution runtime setup subset
148+
- Forward preview options through agent tasks
149+
- Add non-blocking preview leases
150+
- Export runtime contract manifest
151+
- Add fuzz coverage plan contracts
152+
- Document public fuzz suite target skips
153+
- Export runtime artifact normalizers
154+
- Decouple runtime invocation from Agents API
155+
- Add generic runtime fanout execution
156+
- Enforce run plan execution policy
157+
- Add generic agent task reusable workflow
158+
- Add WordPress block fuzz primitives
159+
- Add fuzz builder test script
160+
- Avoid duplicate workload facade stubs
161+
- Avoid duplicate runtime action test names
162+
- Add safe database inspection
163+
- Run fuzz cases through runtime actions
164+
- Summarize fuzz suite coverage
165+
- Improve admin discovery fuzz targets
166+
- Expand WordPress CRUD coverage
167+
- Add WordPress fuzz suite builders
168+
- Expose fuzz workload API facades
169+
- Split simulated and real page load commands
170+
- Expand WordPress database schema discovery
171+
- Add WordPress setup action primitives
172+
- Unify fuzz suite execution planning
173+
- Add public WordPress runtime helper facades
174+
- Implement WordPress workload ability runner
175+
- Document focused public Codebox entrypoints
176+
177+
### Fixed
178+
- Fix recipe-run terminal exits
179+
- decouple agent task workflow contract
180+
- preserve skipped dependency artifact refs
181+
- stabilize public codebox envelopes
182+
- preserve bench extra plugin source roots
183+
- trim fuzz execution metadata payloads
184+
- execute runtime command fuzz cases
185+
- accept suite path for nested fuzz command
186+
- support nested fuzz suite recipe command
187+
- expose ensure plugin active runtime command
188+
- Fix browser local package target folders
189+
- Fix SQL fingerprint string redaction
190+
- Fix runtime task ability materialization
191+
- Fix admin fuzz menu globals
192+
- Fix admin fuzz page URLs
193+
- Fix recipe preview lease option type conflict
194+
- Fix runtime action public build
195+
5196
## [0.9.0] - 2026-06-21
6197

7198
### Added

package.json

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -1,6 +1,6 @@
11
{
22
"name": "wp-codebox-workspace",
3-
"version": "0.9.0",
3+
"version": "0.10.0",
44
"private": true,
55
"type": "module",
66
"exports": {

packages/cli/package.json

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -1,6 +1,6 @@
11
{
22
"name": "@automattic/wp-codebox-cli",
3-
"version": "0.9.0",
3+
"version": "0.10.0",
44
"description": "WP Codebox CLI — secure WordPress code execution from anywhere. Run disposable Playground sandboxes from any host: CLI, CI, mobile, Node service, or WP plugin.",
55
"type": "module",
66
"bin": {

packages/runtime-core/package.json

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -1,6 +1,6 @@
11
{
22
"name": "@automattic/wp-codebox-core",
3-
"version": "0.9.0",
3+
"version": "0.10.0",
44
"type": "module",
55
"main": "dist/index.js",
66
"types": "dist/index.d.ts",

packages/runtime-playground/package.json

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -1,6 +1,6 @@
11
{
22
"name": "@automattic/wp-codebox-playground",
3-
"version": "0.9.0",
3+
"version": "0.10.0",
44
"type": "module",
55
"main": "dist/index.js",
66
"types": "dist/index.d.ts",

packages/wordpress-plugin/wp-codebox.php

Lines changed: 2 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -3,7 +3,7 @@
33
* Plugin Name: WP Codebox
44
* Plugin URI: https://github.com/Automattic/wp-codebox
55
* Description: Secure coding environments inside WordPress. WordPress ability surface for launching disposable WP Codebox Playground sandboxes that can't touch your host site.
6-
* Version: 0.9.0
6+
* Version: 0.10.0
77
* Requires at least: 6.9
88
* Requires PHP: 8.2
99
* Author: Automattic
@@ -15,7 +15,7 @@
1515
die;
1616
}
1717

18-
define( 'WP_CODEBOX_PLUGIN_VERSION', '0.9.0' );
18+
define( 'WP_CODEBOX_PLUGIN_VERSION', '0.10.0' );
1919
define( 'WP_CODEBOX_PLUGIN_PATH', plugin_dir_path( __FILE__ ) );
2020
define( 'WP_CODEBOX_PLUGIN_URL', plugin_dir_url( __FILE__ ) );
2121

0 commit comments

Comments
 (0)