# Changelog All notable changes to this project will be documented in this file. This project follows [Keep a Changelog](https://keepachangelog.com/en/1.1.0/) and Semantic Versioning once `0.1.0` is tagged. ## [Unreleased] ### Added - Release-readiness checklist in `docs/before_0_1.md`. - Root documentation site under `/active`. - Versioning and deprecation policy page under `/active/get-started/versioning`. - Full ecosystem integration harness under `/test/ecosystem`. - Server/client split for authentication, permissions and cache. - Rate-limit port wiring for critical authentication flows. - Runtime warnings for memory auth/cache adapters in production mode. - OAuth PKCE regression tests for persisted verifier handling. - Public-surface regression tests for the composed App root and its always-on/scoped artifacts. - Permission client regression coverage for stale `check`, `batch` and `what` responses after actor changes. - Bundle smoke script for the minimal `createActiveApp({})` runtime budget. - Static smoke script for generated docs/test routes and public app assets. ### Changed - MFA is excluded from the stable auth engine surface until it is implemented end-to-end. - CSRF cookie defaults are verified as strict in auth regression tests. - Mono-lang is documented as a type-loose null-object fallback when no schema is configured. ### Security - Added security policy and pre-`0.1.0` threat-model notes. ## [0.1.0] - Unreleased Initial public stabilization target.