Skip to content

Milestones

List view

  • Weekly non-breaking release in the v0.8.x series. Intake is work that ships without a breaking change: fixes, additive features, docs, CI, and packaging. Anything that changes a public contract (config schema, WIT/plugin ABI, CLI surface, RPC/API shape, auth or isolation semantics) belongs in v0.9.0 or its delivery cohorts instead, which bundle breaking changes so they land together rather than dribbling across patch releases. Close when the v0.8.5 tag ships; carry anything unfinished to the next weekly rather than holding the release.

    No due date
    68/294 issues closed
  • Finite interoperability cohort for binary embedded resources across ACP prompt intake, workspace materialization, explicit `deliver_file` output, stable attachment URI citations, and MCP `tools/call` resource-blob intake. Initial scope is #9178, #9179, #9195, and #9196. Close when the stack merges or is explicitly deferred. Unrelated ACP UI, RPC attachments, image/audio capability expansion, and general MCP work do not enter automatically.

    No due date
    2/8 issues closed
  • Finite delivery cohort for the active persistent-memory program: Hindsight backend and dashboard integration, recall quality and injection, deduplication and retention, curation and retrieval stages, write/recall boundary hardening, auditability, and config semantics. Initial scope is tracker #8891, its currently open child PRs, and the #8992/#8993/#8995 Hindsight stack. Close when this fixed cohort merges, closes, or is explicitly deferred. New memory backends and unrelated memory features do not enter automatically.

    No due date
    11/24 issues closed
  • Finite implementation cohort for accepted RFC #8303: goal controller and verifier, trusted goal tools and human/delegation boundaries, channel `/goal` admission, and loop-escape/blocker semantics. Close when #8687, #8688, #8689, #8746, and #8996 land or are explicitly deferred and tracker #8681 closes. Unrelated agent-autonomy features do not enter automatically.

    No due date
    0/7 issues closed
  • Finite operator-journey wave covering guided onboarding, pairing and identity binding, quickstart credential preservation, login lifecycle visibility, dashboard self-service upgrades, and deployment/service papercuts. Close when the named flows ship or are explicitly deferred. Unrelated dashboard, channel, and general UX work stays outside.

    No due date
    26/45 issues closed
  • Finite consolidation and hardening wave for Code-pane structure, slash-skill dispatch, live model switching, clipboard/input behavior, config-editor correctness, and session cleanup controls. Close when the scoped cohort ships or is explicitly deferred. New ZeroCode features do not enter automatically; only direct regressions and blockers to this cohort may be added.

    No due date
    29/60 issues closed
  • Finite wire-protocol hardening wave for shared idle-bound SSE transport, tool-call argument normalization, provider history fidelity, and accepted inbound OpenAI-compatible protocol work. Close when the current transport cohort ships or is explicitly deferred. New providers and general provider features do not enter automatically.

    No due date
    13/26 issues closed
  • Finite runtime architecture wave for the split-history contract, scoped-assembly seams, deferred-MCP policy ownership, loop-event and cost metering, and intentional no-reply/history-trimming correctness. Close when the current series and linked defects are resolved or explicitly deferred. New agent features require separate routing.

    No due date
    19/39 issues closed
  • Finite first delivery wave for the unified plugin capability catalog and lifecycle surfaces across CLI/API, web, and ZeroCode, plus out-of-process WASM execution. Close when the shared catalog drives list/enable/disable and operator visibility across the planned surfaces, and the sidecar isolation slice is resolved. Intake is limited to #8850 Track A and direct blockers; distribution, permissions, secrets, and later plugin work require separately named follow-ons.

    No due date
    8/21 issues closed
  • Long-term cold storage for Issues and PRs that are valid but deliberately not scheduled. Unlike the Parking Lot (a short-term routing buffer that gets re-triaged into a concrete release soon), the Icebox holds work that is deferred indefinitely: sound ideas without a champion, low-priority polish, and features gated on decisions or dependencies that are not close. Items here are not committed to any release and are not expected to move on a near-term cadence; they are revisited periodically and either promoted into a concrete milestone or closed. Nothing is dropped silently, but nothing here is on deck.

    No due date
    35/98 issues closed
  • Temporary holding pen for triaged Issues and PRs that have been deprioritized out of a concrete point release but are not closed. Items land here after triage to keep active release milestones (v0.8.3, v0.8.4) from growing unbounded. Nothing here is committed to a ship date; items are re-triaged into a concrete milestone when picked up, or closed if they go stale. This is a routing buffer, not a backlog graveyard.

    No due date
    50/184 issues closed
  • Finite dependency-ordered authentication and authorization cohort under v0.9.0. Initial scope is trackers #8289 and #8290, their current linked work, and direct blockers to a pluggable `AuthProvider`, uniform `Principal`, gate-by-construction inbound authentication, per-principal session and memory isolation, and per-sender authorization. Close when the current cohort ships or is explicitly deferred and both trackers close. Transport mTLS-as-identity, broader credential or device-trust work, policy-administration expansion, and unrelated v0.9.0 hardening remain outside this milestone.

    No due date
    3/13 issues closed
  • Finite implementation cohort for the daemon-owned SOP control plane tracked in #8288: one shared `SopEngine` across tools, event listeners, cron, gateway, CLI, and channel ingress; durable run state and restart recovery; fail-closed approval delivery; untrusted-payload framing; enforced per-step contracts; and operator authoring and observability. Initial scope is #8288's current linked work and direct blockers to its 13 capability scorecards. Close when all 13 capabilities verify at 5/5 and #8288 closes. New automation engines and unrelated cron, channel, tool, or workflow features do not enter automatically.

    No due date
    50/69 issues closed
  • Finite delivery cohort for the nominated ZeroRelay on the secure-transport plane: a standalone blind-forwarding relay that lets a client reach a daemon behind NAT/CGNAT while forwarding the opaque inner mutual-TLS session without terminating traffic or holding keys. Initial scope is tracker #8358, its single cross-fork secure-transport integration, and direct blockers to that integration. Close when the integration satisfies #8358's end-to-end, adversary, packaging, and release criteria or is explicitly declined or deferred, and #8358 closes. Additional relay topologies, CA-rotation orchestration, QUIC or parallel-link transport, and unrelated transport work do not enter automatically.

    No due date
    0/2 issues closed
  • Authentication, security hardening, and breaking changes graduating from the v0.8.x series. Headline: pluggable authentication providers (OIDC / ssh-key / peercred / native) in front of the RPC/WSS transport, per-user × per-agent authorization, and per-principal session/memory isolation. Closes the unauthenticated-WSS hole. Folds in security-hardening and breaking-change work deferred out of v0.8.x.

    No due date
    90/187 issues closed