generated: '2026-09-19' method: searched source: https://github.com/yuens1002/resume-agent/blob/main/CHANGELOG.md docs: https://github.com/yuens1002/resume-agent/blob/main/CHANGELOG.md scheme: >- Keep-a-Changelog file in the source repo. Semver headings through [0.4.60] (2026-06-09); since then every change is a dated bullet under [Unreleased] while package.json advances (0.4.129 on 2026-09-19) without a matching heading or git release. GitHub releases: v0.4.60 (2026-06-09) is the only one; tags v0.2.0 and v0.4.60. current_version: codebase: 0.4.129 last_released: 0.4.60 (2026-06-09) contract: '1.0.0' agent_card: '1.3.0' cadence: near-daily dated entries; 69 dated bullets between 2026-06-09 and 2026-09-16 under [Unreleased] window: 2026-06-09 .. 2026-09-16 (recent window; older releases summarised only by heading) entries: - date: '2026-09-16' version: unreleased breaking: false highlights: - Automated audit for security-definer RPCs still executable by anon/authenticated (scripts/check-security-definer-grants.ts), wired after every db push; found rotate_refresh_token had never revoked EXECUTE. surface: internal / security - date: '2026-06-09' version: 0.4.60 breaking: false highlights: - Last tagged release; everything after it lives under [Unreleased]. surface: release - date: '2026-04-06' version: 0.2.9 breaking: false highlights: [Early releases 0.2.3 through 0.2.9 all landed 2026-04-05/06.] surface: release public_surface_changes_documented_in_readme: - GET /observations gained authored filter, total and truncated envelope fields (additive; default listing unchanged; filter echoed as a capability probe). - POST /query gained publications[] resolved server-side, style (cited | conversational), action_intent and fit_question. - GET self-descriptors on /query, /match and /public-mcp replaced bare 404s for crawlers following advertised URLs. - /public-mcp made stateless (docs/plans/mcp-stateless-refactor.md). - OEP Phase 1 domain verification: /.well-known/oep-public-key.json plus _oep DNS fingerprint. note: >- The changelog is exhaustive and dated but is written for the codebase, not the API: entries describe migrations, evals, prompts and security fixes alongside endpoint changes, and no entry is tagged as breaking or as an API version bump. A consumer must diff /openapi.json to learn contract changes.