Download Latest Version 3.9.0 source code.zip (50.7 MB) Google Add to Preferred Sources
Home / 3.8.0
Name Modified Size InfoDownloads / Week
Parent folder
3.8.0 source code.tar.gz 2026-09-05 46.0 MB
3.8.0 source code.zip 2026-09-05 49.5 MB
README.md 2026-09-05 31.8 kB
Totals: 3 Items   95.5 MB 0

Compare: 3.7.1...3.8.0

Elsa 3.8.0 — Release Notes


🌟 Highlights

  • Operational diagnostics: Structured ILogger logs can remain in memory or be persisted to SQLite, while console output and OpenTelemetry traces, metrics, and logs can be ingested and queried through dedicated diagnostics modules. (#7445, [#7462])
  • Safer workflow operations: Runtime drain, pause/resume, interrupted-workflow recovery, transactional dispatch outbox, bookmark dead-letter management, and readiness checks provide clearer control over clustered and restarting hosts. (#7424, [#7516], [#7517])
  • Secrets and external sign-in: Add the Secrets module with encrypted and configuration-backed stores, secret expressions, EF Core persistence, and JavaScript access, alongside the external authentication broker and OpenID Connect adapter. (#7468)
  • Workflow platform foundations: Bring HTTP Webhooks into Core, and add an operational Dashboard API, provider-neutral Persistence vNext building blocks, Platform integration, and the Weaver AI host with grounded, proposal-only workflow tools. (#7523, [#7681]; 103028452, c16995014, e9d89969b)
  • State machine and workflow execution: Add the StateMachine activity and align its trigger and transition behavior with workflow runtime lifecycle semantics. (#7457, [#8010])

⚠️ Breaking changes / upgrade notes

  • Configure production identity secrets before startup: The reference server no longer ships usable admin credentials or API keys. Configure initial users/applications through environment-specific settings or a secret manager. JWT signing keys must be configured, contain at least 32 printable ASCII characters, and have no surrounding whitespace. Known public defaults are accepted only in Development or Demo; set Identity__Tokens__SigningKey (or the shell feature equivalent) to a secure random value. (#7496, [#7500])
  • Localhost bootstrap is opt-in: Localhost requests no longer receive security-root bootstrap permissions by default. Hosts that intentionally rely on this development bootstrap must call EnableLocalHostPermissionGrantForSecurityRoot(); otherwise configure an explicit admin bootstrap or authenticated identity. (#7498)
  • Script execution is privileged: C# and Python host-code execution now requires the corresponding AllowHostCodeExecution option and exec:csharp-expressions / exec:python-expressions permission. Treat both runtimes as host-code execution rather than sandboxes and enable them only for trusted authors. (#7519)
  • New opt-in modules need explicit wiring: Structured logs, console logs, OpenTelemetry diagnostics, Secrets, Webhooks, Dashboard, and Weaver are separate modules. Add the relevant Core package, call its Use... registration, and map its routes/hub where applicable; existing hosts do not opt into these surfaces automatically. (e2e00ff23, 322d65d46, 43108c2e4)
  • EF Core persistence packages and providers: New Secrets and external-authentication persistence packages add provider-specific migrations. Include the migrations for any installed provider in your normal EF Core deployment process, and review provider project references when adding these modules. (e083d3b30, 75a3216ae)
  • .NET 10 FastEndpoints update: The .NET 10 package set moves FastEndpoints, FastEndpoints.Security, and FastEndpoints.Swagger from 7.2.0 to 8.2.0. ElsaEndpoint request constraints no longer require new(), and the runtime resume endpoint uses FastEndpoints.EmptyRequest; ResumeRequest is obsolete. Review custom endpoint wrappers and resume integrations when targeting .NET 10. (#8019)

✨ New features

  • Diagnostics: Add structured log capture with REST/SignalR streaming and opt-in SQLite persistence; add raw console-log capture with redaction, source metadata, bounded buffers, REST, and SignalR; add an OTLP HTTP/protobuf collector with bounded in-memory trace, metric, and log stores plus query APIs and live updates. (#7445, [#7462]; 322d65d46)
  • Secrets: Add the Secrets module, EF Core persistence providers, the Secret expression, JavaScript getSecret, versioned encrypted storage, configuration-backed read-only secrets, and metadata-only management APIs. (#7468; e083d3b30, b438551c78, 556e931662)
  • Identity and authentication: Add the external authentication broker, OpenID Connect adapter, configuration-backed Keycloak demo providers, atomic external-identity-link replacement, shadowed-connection management, and callback/session hardening. (ef83541ed, 97c459f19, e97a90d44, 238080c46)
  • Runtime operations: Add graceful runtime shutdown and recovery, readiness health checks, bookmark queue dead letters, ingress rate-limiting hooks, transactional workflow dispatch outbox, workflow OpenTelemetry instrumentation, and a read-only runtime status endpoint. (#7424, [#7512], [#7514], [#7516], [#7517]; 1e41f6fdf, dd47148164)
  • Workflow and platform modules: Add the StateMachine activity, bring HTTP Webhooks into Core, and add the Dashboard API, Persistence vNext provider-neutral contracts, Platform integration, publish-validation opt-out, stable application instance configuration, and output-converter support at binding boundaries. (#7457, [#7681]; 103028452, c16995014, e9d89969b7, 61fc376dac)
  • Weaver and module metadata: Add the Weaver AI host and grounding tools, package-manifest build metadata, shell feature categories, named WithVariable overloads, and runtime descriptor/version metadata. (#7523, [#7699], [#7701]; c66f9aed45, 92f451e655, 7941a9d72e)

🔧 Improvements

  • Workflow management: Definition synchronization avoids redundant lookups, and workflow JSON type serialization now uses a consolidated resolver path for more predictable polymorphic activity and state handling. (#7521, [#7549])
  • Activity registry: Registry and descriptor refreshes reduce allocation and lookup overhead while retaining valid descriptors when a provider refresh is empty or removes a descriptor. (#7538; 9554385498, a98f31141d, 26017e3b73)
  • Structured logs: SQLite storage wiring now exposes provider-neutral storage diagnostics, batches writes, and keeps the existing in-memory provider as the default. (#7445, [#7446]; 63dec9f5e4)
  • Console logs: Console capture now carries richer workflow/source context through its lifecycle, improving filtering and clustered diagnostics. (#7536)

🐛 Fixes

  • Workflow execution: Restore dynamic references for C# variables, preserve fork completion state during resume, skip already-finished interrupted workflows, fix nested Flowchart ForEach completion, catch scheduling startup backlog, and correct StateMachine transition ordering. (#7415, [#7416], [#7431], [#7435], [#7702]; c7912fd2c8, 051e12f864)
  • Diagnostics: Correct structured-log registration, flush queued SQLite writes during shutdown, repair SQLite shell lifecycle, and restore console metadata, type resolution, and live-feed behavior. (263bb18099, [#7460], [#7461], [#7542], [#7548])
  • Runtime and persistence: Prevent bulk-dispatch test hangs, repair tenant coordinator options, preserve workflow commit atomicity and commit-notification scope, and correct Oracle NVARCHAR2 identifier/cast generation. (37cf451ec0, e7b1f8055b, e77da02d52, c6a3366463, 82e069c265, 6b7296fa29)
  • Identity, tenancy, and API delivery: Scope API-key application lookup to tenant-agnostic records, restore request services after tenant middleware failures, fix tenant-service mutation races, and quote API-key secrets safely during package publishing. (1d1c68282c, 56b16caa0e, [#7898], [#7951])
  • External authentication: Correct host composition, setting identifiers, local refresh, connection contracts, preview callback persistence/responses, secret IDs, discovery validation, and review findings across the broker flow. (939a89c9e8, f1e2a092f9, 7e82a55a9f, eb07aa2cde, 678182dff8, f4ca206607, 119f49f7a2, 1b74bb94c0, fe125ac336)
  • Build and package restore: Fix CShells restore and dependency mismatches in CI. (6b08988edd, 1692fcd193)

🔒 Security

  • Identity defaults: Remove production-usable admin/API-key values from reference configuration and validate JWT signing keys at startup; known public defaults are allowed only in Development and Demo. (#7496, [#7500])
  • Authorization boundaries: Require explicit permission for role assignment, workflow imports, workflow-instance SignalR observation, and localhost security-root bootstrap; C# and Python host-code execution is gated by explicit options and permissions. (#7498, [#7501], [#7504], [#7510], [#7519])
  • HTTP and token handling: Harden bookmark resume/SAS-token validation and cached ZIP path handling, and enforce request-body limits while reading HTTP workflow requests. (#7495, [#7497])
  • Tenant and secret isolation: Scope HTTP bookmark lookup to the tenant, protect workflow inputs marked as sensitive, and resolve tenant-agnostic API-key applications without crossing tenant boundaries. (#7508, c8ffcb2a8a, 1d1c68282c)
  • Dependency security: Resolve vulnerable transitive persistence packages and apply safe patch updates. (#7459, 0658037275)

🧩 Developer-facing changes

  • Identity clients: Access and refresh tokens are distinguished by token-use semantics, so clients should send refresh tokens only to the refresh endpoint and access tokens to normal API endpoints. (#7509)
  • Dashboard contributors: The operational Dashboard API now has a contributor contract and widget integration guidance for Studio, with isolated contributors that can add metrics and findings without coupling the core API to each feature. (#7529, [#7532], [#7681], [#7690])
  • Workflow publishing: Publish and bulk-publish responses surface validation warnings and honor the publish result, allowing clients to distinguish accepted, rejected, and warning-bearing operations. (2863c980f3, 354d59942c)
  • External authentication: Provider, connection, callback, and secret-binding contracts were tightened around deployment-owned configuration and broker flows. (128569f6c0)
  • Output conversion: Binding-boundary converter contracts now expose clearer result and failure semantics for custom converters. (dff7d9f987)

🧪 Tests

  • Runtime and workflow tests: Expand quiescence/drain coverage with DI-aware tenant handling, stabilize bulk-dispatch assertions, and keep timestamp-filter integration cleanup isolated and deterministic. (#7424, [#7520]; 26b17e35e2, 4b824d65b8, 008e5a3f21, 4fe9f59f0e)
  • Diagnostics and persistence tests: Increase structured-log provider, relational, and SQLite migration coverage, including durable-store behavior and startup schema validation. (#7449, [#7450], [#7451]; 863a43d318)
  • Secrets and AI tests: Add coverage for secret updates, secret-module behavior, and Weaver AI host execution paths. (#7530; 87ee19f5b3, 5336f9ea06)
  • Security and provider tests: Stabilize ingress-rate-limit assertions, cover Oracle bulk-upsert SQL generation, and verify archived external-authentication connections do not participate in active shadow relationships. (48c4259844, 33181b2c9d, 9f09aca3f6, a60b5a36b2)
  • CI reliability: Stabilize package component tests across the release build. (3be8856c9f)

🔁 CI / Build

  • Build quality: Resolve compiler and analyzer warnings across shared workflow, scripting, resilience, and multitenancy code paths. (#7458)
  • Package publishing: Set the release workflow base version to 3.8.0, verify release tags are reachable from main or release/*, and use NuGet OIDC Trusted Publishing for published stable packages. (7c01fe8dd4, f6c35cf1eb)

📦 Dependencies

  • API framework: FastEndpoints, FastEndpoints.Security, and FastEndpoints.Swagger are 7.1.1 for .NET 8/9 and 8.2.0 for .NET 10. (#8019)
  • Diagnostics persistence: ConsoleLogStreaming.Contracts, .Core, .Persistence.Sqlite, and .SignalR are 1.0.0-preview.13; FluentMigrator.Runner and .Runner.SQLite are 8.0.1. (827ad6bc6, dbfe247b6a)
  • AI and platform integration: GitHub.Copilot.SDK is 1.0.0, Loom, Loom.Abstractions, and Loom.Serialization.Json are 0.0.1-preview.10, Elsa.Platform.PackageManifest.Generator is 0.0.1-preview.53, and WebhooksCore is 0.0.1. (3936258146, e9d89969b7, 103028452f2)
  • Shell and runtime packages: The CShells package family is 0.0.28 and the Nuplane package family is 0.0.8. (29d43dadbb, f97eea5fde)
  • OpenTelemetry: Core, exporters, and hosting packages are 1.15.3; ASP.NET Core, HTTP, SQL Client, Redis, and auto-instrumentation packages remain on the explicit versions in Directory.Packages.props (1.15.2, 1.15.1, 1.14.0-beta.1, and 1.13.0). (#7546, [#7547])
  • Framework and provider patches: The ASP.NET Core, EF Core, and Extensions package families use 9.0.17 for .NET 8/9 and 10.0.9 for .NET 10; Npgsql EF Core is 9.0.4/10.0.2, and Oracle EF Core is 9.23.26200/10.23.26200 for the corresponding targets. (2074384ff9, [#7766], [#7896])

📚 Documentation

  • Operations: Clarify readiness-probe timeouts and health-check registration, document identity validator dependencies, and add workflow throughput analysis. (d6903fdb76, 33d94ab384, 9415d220c0, db86a6d5dd)

📦 Full changelog (short)

  • Fix System.Dynamic registration for C# variable accessors (#7415) (e70850ac83)
  • fix(csharp): register System.Dynamic for generated Variables wrapper (#7416) (d59866b09a)
  • fix: restore HashSet-backed Fork completion state on resumed workflows (#7431) (5b336254b8)
  • Graceful shutdown for the workflow runtime (drain, pause, recover) (#7424) (d7bdbfb26d)
  • Update base_version to 3.8.0 in packages workflow configuration. (7c01fe8dd4)
  • Refactor QuiescenceSignal to inject IServiceScopeFactory, enhance tenant ID handling, and expand unit tests with DI capabilities. (26b17e35e2)
  • chore(deps): bump CShells to 0.0.18 (78cf9bf214)
  • docs: add agent contributor guidance (80d3ad2b47)
  • docs: add agent operating principles to AGENTS.md and CLAUDE.md (3e43b85a2b)
  • docs: add GraphQL queries and license information (3500e9f507)
  • chore: update logging level and bump package versions for CShells and Nuplane (da31ae9ba9)
  • chore(deps): update CShells packages to stable version 0.0.20 (2a209e65ea)
  • [codex] Add live server log streaming diagnostics (#7438) (ab3e46bbe2)
  • docs(qa): add workflow throughput analysis (db86a6d5dd)
  • [codex] Add structured log SQLite persistence (#7445) (827ad6bc6b)
  • [codex] Expose structured log storage diagnostics (#7446) (b255e0b4c3)
  • Update Nuplane and CShells packages (f97eea5fde)
  • Add SQLite persistence for structured logs and adjust project references (d343b30f76)
  • Switch to SQLite and update project and package configurations (f11bf2f012)
  • Add structured log provider tests (#7449) (b3c399155b)
  • [codex] Increase structured log persistence test coverage (#7450) (6866d74127)
  • Update Elsa.PackageManifest.Generator to version 0.0.1-preview.28 in package configuration (8bd54bf4d7)
  • [codex] Increase structured log relational test coverage (#7451) (6dee7094f0)
  • [codex] Add codebase wiki (#7453) (b9664a954d)
  • Add Elsa README video assets (#7455) (835ef74ca7)
  • Stabilize packages CI component tests (3be8856c9f)
  • Harden EF trigger persistence (efe4700bd1)
  • Fix structured log diagnostics registration (263bb18099)
  • Add missing Obsolete attribute to IWorkflowBuilder (#7448) (ec43976e30)
  • [codex] Resolve build warnings (#7458) (27ae1fae64)
  • Remove video overview GIF from README (d1b36c59ca)
  • Update safe dependency patch versions (#7459) (50f858a8ce)
  • [codex] Add wiki update workflow (#7454) (8416ea8af4)
  • Fix structured log write buffer shutdown flush (#7460) (60e742b0e3)
  • Fix SQLite structured log shell lifecycle (#7461) (0687b5f9f3)
  • Enhance logging configuration and add SQLite structured log persistence. Secure default admin credentials. (63dec9f5e4)
  • Add state machine activity (#7457) (6485f05a87)
  • Add diagnostics console logs (#7462) (43108c2e48)
  • [codex] Add package manifest feature metadata (#7463) (550685ea3f)
  • Fix update wiki workflow action (4eeb26feca)
  • fix: do not resume interrupted workflows that are already finished (#7435) (02cd8085c6)
  • Update package manifest generator preview (#7465) (ee4e0ad5ed)
  • Refresh codebase wiki (#7464) (e6b4719fb1)
  • Refresh codebase wiki (#7466) (cd1748bf35)
  • Add updated roadmap (fcfc78f659)
  • Fix bulk dispatch component test hang (37cf451ec0)
  • Add secrets module (#7468) (e2e00ff235)
  • Whitelist workflow timestamp filter columns (37de3404cd)
  • Address timestamp filter review feedback (752570c4ec)
  • Fix tenant coordinator test options reference (e7b1f8055b)
  • Harden identity secret generation and hashing (304e990319)
  • Add Elsa runtime readiness health checks (1e41f6fdf8)
  • Address identity secret hashing review feedback (28ee3d6fb3)
  • Address identity hasher review feedback (95640cbf7d)
  • Address health check review feedback (a8390d8d64)
  • Make identity rehash persistence best effort (94df64b2b9)
  • Guard persistence health check store probes (481c1aaa81)
  • Avoid shared distributed lock probe names (f12204496c)
  • Document identity validator constructor dependencies (9415d220c0)
  • [codex] Enforce role assignment authorization (#7501) (c32a5a192c)
  • Scope HTTP bookmark lookup to tenant (#7508) (435c25793b)
  • Distinguish refresh tokens from API access tokens (#7509) (1da8709e2c)
  • Address identity validator compatibility feedback (e2587f74b5)
  • Harden Python expression execution (#7507) (0856d79093)
  • Add Elsa release skill (d21da0afce)
  • [codex] Enforce HTTP workflow request body limits while reading (#7497) (a860846b50)
  • [codex] Remove production-usable default admin credentials (#7500) (746ba96a1f)
  • docs: add security & quality assessments (3523804efd)
  • Suppress Discord release announcement embeds (5080bb7007)
  • [codex] Fail fast on default JWT signing keys (#7496) (e9d59bc5b1)
  • Harden timestamp filter validation null handling (f72ed4edab)
  • [codex] Authorize workflow imports before persistence (#7510) (37c02c74ff)
  • docs: clarify readiness probe timeout (d6903fdb76)
  • Address identity hashing review feedback (505334bc9d)
  • Handle missing distributed lock provider in readiness check (9cdff8c318)
  • Narrow user hash upgrade save catch (65ec6f4029)
  • Harden readiness health check reporting (182f524d83)
  • Restore best-effort application hash upgrade saves (65caa73d6f)
  • Address identity secret hashing review feedback (6a7ff8d48a)
  • Address health check review feedback (f149c27ab0)
  • Preserve health check cancellation semantics (b5c457c202)
  • Stabilize bulk dispatch fire-and-forget component test (#7520) (3fc87945fd)
  • [codex] Require opt-in for localhost authorization grants (#7498) (d23e61e9be)
  • Remove unused health check usings (45d8a4cfae)
  • [codex] Harden C# expression host-code execution (#7519) (2fa1a9ef8e)
  • Refine readiness health check probe data (d2c2e5c429)
  • Address identity secret hasher review feedback (32ff56d1ac)
  • Address health check review feedback (2ade23bc82)
  • Address timestamp filter review comments (3a45938dea)
  • Use unique distributed lock health probes (bcccb80ad5)
  • Clear temporary secret hashing buffers (df12667af2)
  • Address health check review feedback (a0d6f6b24b)
  • Isolate timestamp filter integration tests (4b824d65b8)
  • Clear decoded secret hash buffers (b4e6f0f57e)
  • Keep root health check as liveness probe (09641c1fab)
  • Harden alteration timestamp filter integration tests (008e5a3f21)
  • Address latest health check review feedback (8c1618b5d4)
  • Address validation feedback (12408cca37)
  • Refine identity secret hashing review fixes (04429e81c6)
  • Address health check review feedback (b546864b4a)
  • Refine timestamp filter validation feedback (25b1ee11ef)
  • Document health check extension namespace (33d94ab384)
  • Address identity review feedback (4a9840b3cd)
  • Address timestamp filter test cleanup review (4fe9f59f0e)
  • Address health check review feedback (b7076fd0cf)
  • Optimize workflow definition sync lookups (#7521) (f7830f7063)
  • [codex] Validate distributed runtime lock provider (#7515) (9496c29a47)
  • Add bookmark queue dead-letter store (#7516) (96b5ee80b5)
  • Add ingress rate limiting hooks (#7512) (541218a37f)
  • Add workflow dispatch transactional outbox (#7517) (d09a1b7cb4)
  • [codex] Harden initial security remediation slice (#7495) (b4947fbf00)
  • Add OpenTelemetry workflow instrumentation (#7514) (2e712d367a)
  • [codex] Harden workflow JSON type resolution (#7499) (cec3281a20)
  • [codex] Authorize workflow instance SignalR observation (#7504) (163d6e6f8f)
  • [codex] Secure Resilience simulate response endpoint (#7505) (58719078d0)
  • [codex] Add operational dashboard API PRD (#7529) (45f4ef1a52)
  • [codex] Align console logs hub authorization (#7531) (167240cebd)
  • [codex] Clarify dashboard widget integration contract (#7532) (cfa323331d)
  • Increase Elsa Secrets test coverage (#7530) (27e6b81a6e)
  • [codex] Enforce console logs hub read permission (#7533) (0d305d276e)
  • Refresh codebase wiki (#7467) (c9cdd5cc1b)
  • Refresh codebase wiki (ff7d0a96a3)
  • [codex] Scope console logs to workflow instances (#7535) (8e301d4e1e)
  • Enhance console logging with improved context and lifecycle (#7536) (5245599131)
  • Optimize activity registry lookup (9554385498)
  • Handle provider descriptor removal during refresh (a98f31141d)
  • Increase secrets unit coverage (#7545) (67ded31cba)
  • [codex] Fix console log metadata and type resolution (#7542) (842cf7c162)
  • Resolve OpenTelemetry package warnings (#7546) (5c408dff54)
  • Bump OpenTelemetry and Remotion dependencies (#7547) (9124c2847c)
  • [codex] Fix diagnostics live feed regressions (#7548) (b280a711b2)
  • Refactor: Overhauls workflow JSON type serialization (#7549) (c2fb027c41)
  • Address activity registry review feedback (6d1b7e3211)
  • Clear manual activity descriptors (da4498398e)
  • Integrate ConsoleLogStreaming.Core and ConsoleLogStreaming.SignalR packages; refine activity registry lookup logic. (dbfe247b6a)
  • Reduce activity registry refresh allocations (26017e3b73)
  • Optimize activity registry descriptor lookup (#7538) (66af304364)
  • Preserve activity descriptors on empty refresh (e34132f0e2)
  • Preserve activity descriptors on empty refresh (209f93bfb5)
  • Pin test environment to Production in IngressRateLimitingTests to stabilize assertions. (48c4259844)
  • Remove SecretProviderAdapter and ISecretProvider to streamline secret management; update solution and project references accordingly. (d84d83f828)
  • Add EF Core secrets persistence (e083d3b307)
  • Protect sensitive workflow inputs (c8ffcb2a8a)
  • Add Secret expression runtime (b438551c78)
  • Add JavaScript secret functions (556e931662)
  • Validate workflow secret reference adoption (e85a40b620)
  • Rename PostgreSQL secrets shell feature (8c0a720056)
  • Harden EF Core secret name uniqueness (9fac0c83c0)
  • Reuse shared EF provider wiring for secrets (da96c10678)
  • Honor configured schema in secrets SQLite migration (d3c80a8167)
  • Share EF secret shadow property names (7becbd3146)
  • Validate secrets SQLite migrations in repository tests (863a43d318)
  • Remove duplicate secrets solution nesting (e293a99aba)
  • Use shared secret name normalization (69d9661fc0)
  • Auto stash before checking out "origin/main" (aa55274bcf)
  • Implement secret update functionality, add related tests, and update project references. (87ee19f5b3)
  • Add operational dashboard API (39e22bea31)
  • Add Persistence vNext provider-neutral POC (c16995014c)
  • Adds operational Dashboard API for Elsa Studio (#7681) (a928c2af2a)
  • Refactor dashboard API contributors (#7690) (577275bfce)
  • Implement Weaver AI Copilot core (#7523) (3936258146)
  • [codex] Extract dashboard contributors into companion modules (#7692) (33a152790a)
  • [codex] Add runtime entity validator coverage (#7697) (50ef957031)
  • Update package manifest imports to use Elsa.Platform.PackageManifest.Generator namespace (943b45333e)
  • Add PackageManifestHints.cs to solution and compile include in build props (2f66873811)
  • Convert shell feature dependencies to typeof references (365af05346)
  • Use imported shell feature types (eb88e641fe)
  • Add shell feature manifest categories (#7699) (4c104635ac)
  • Update solution file to add 'weaver' and 'keyvalues' projects and adjust project build dependencies. (dbf1ef507e)
  • Add 'dashboard' project to solution and adjust project build dependencies (2d920bf528)
  • Use Copilot SDK for Weaver agent loop (#7700) (b462966544)
  • Remove PackageManifestCategories and update feature categories to inline strings (c3395fe86b)
  • Add PackageManifest.props and build properties for package manifest generation (92f451e655)
  • Add named WithVariable overload (#7701) (fb4fb63c3a)
  • [codex] Fix ForEach completion from nested flowchart (#7702) (f3ee587742)
  • Move AI EF Core migrations to provider projects (5c0d8b0f4e)
  • Add Weaver grounding tools (c66f9aed45)
  • Remove unneeded CliPath prop (20c1064ca5)
  • fix: use tenant-agnostic application lookup for api keys (1d1c68282c)
  • Guard missing NotFoundActivity descriptor during deserialization (a5a3aa77ae)
  • Add regression test for missing NotFoundActivity descriptor (42ef838323)
  • docs: refresh roadmap (ded765b379)
  • Dispose parsed activity JsonDocuments (#7713) (9c24f5efe5)
  • Restore RequestAborted after timed HTTP workflow failures (#7712) (48a087e71e)
  • address greptile review feedback (0d7c810688)
  • Guard HTTP fault handling when workflow reload returns null (#7714) (8f721e1ea2)
  • Add read-only workflow runtime status permission (dd47148164)
  • Clarify runtime status permission summary (18fc26d891)
  • Add Platform integration (e9d89969b7)
  • Add opt-out for publish-on-validation-error failure (3.8) (7981892838)
  • Restore trailing newline in ManagementOptions.cs (b266b32ef9)
  • Honor publish result in Publish/BulkPublish endpoints (354d59942c)
  • Surface publish validation warnings on API responses (2863c980f3)
  • Fix CShells package restore in CI (6b08988edd)
  • Port ASB stable application instance name (b78649a366)
  • Add stable application instance name configuration (55284aa1c1)
  • address greptile review feedback (greploop iteration 1) (b08b10132c)
  • Address Greptile review feedback (c442c5f543)
  • Update CShells and Elsa.PackageManifest.Generator to latest versions (29d43dadbb)
  • Shorten configured application instance names (6a4c141ce1)
  • Shorten configured application instance names (571c1c7b2c)
  • Fix scheduling startup backlog catch-up (c7912fd2c8)
  • address greptile review feedback (greploop iteration 1) (7449d2e703)
  • Fix workflow commit atomicity (e77da02d52)
  • Fix publish event payload assertion casing (5cc2a7c75a)
  • Fix flaky publish event payload test (b05eb3096b)
  • Allow NuGet.org for CShells packages (2a5b716ba0)
  • Update safe dependency patch versions (2074384ff9)
  • Address PR review feedback (635c3ea42f)
  • Resolve vulnerable transitive persistence packages (0658037275)
  • Address PublishEvent payload review feedback (66911bb77f)
  • Address payload assertion review feedback (d5378d6ef9)
  • Address workflow commit review feedback (98f931ae35)
  • Fix commit notification flush edge cases (c6a3366463)
  • Address PR review comments (97c62a718c)
  • fix: correct Oracle identifier quoting and NVARCHAR2 cast in GenerateOracleUpsert (82e069c265)
  • Fix Comments and Casting logic of NVARCHAR2 (6b7296fa29)
  • Skills (974cbe740a)
  • Increase AI host test coverage (5336f9ea06)
  • Refresh roadmap from current Elsa evidence (4f89578572)
  • test: cover Oracle bulk upsert SQL generation (33181b2c9d)
  • Fix CShells dependency mismatch (1692fcd193)
  • chore: update patch dependencies (#7766) (a73ccfd2a3)
  • chore: make agent instructions feature-neutral (3736eca19b)
  • Updated AGENTS.md (5be9fe08e9)
  • docs: refresh roadmap (aef7f253c3)
  • Add external authentication broker (ef83541edd)
  • Revise external authentication architecture (95b2ce8d84)
  • Harden external authentication contracts and flows (128569f6c0)
  • Fix external authentication host composition (939a89c9e8)
  • Fix external authentication setting field identifiers (f1e2a092f9)
  • Reconcile configured admin role permissions (379e03fdda)
  • Preserve Elsa permissions during external sign-in (42e507b0d8)
  • Auto stash before merge of "release/3.8.0" and "origin/release/3.8.0" (e8aa353d57)
  • Fix local external authentication refresh (7e82a55a9f)
  • chore: apply safe dependency upgrades (#7896) (04e58690ff)
  • Add OpenID Connect authentication features (97c459f198)
  • Add atomic external identity link replacement (e97a90d442)
  • Harden external identity link management (0fa7657b30)
  • Persist external authentication in identity shell (75a3216ae8)
  • Fix external authentication connection contracts (eb07aa2cde)
  • feat: add configuration-backed Keycloak demo providers (238080c465)
  • docs: refresh roadmap (1000d29feb)
  • Allow promoting shadowed authentication connections (22bc531aa8)
  • Add test for callback session persistence; extend authentication broker for refresh token hash initialization; enable config connection overrides (1ccf5b7611)
  • Add runtime descriptor endpoint and tests for version metadata (7941a9d72e)
  • fix: persist relative external auth preview callbacks (678182dff8)
  • fix: send preview authentication responses (f4ca206607)
  • Add workflow state rehydration diagnostics (#7899) (edb5f7cd51)
  • Fix tenant service mutation race (#7898) (ec9acd4f3f)
  • fix: restore request services after tenant middleware exceptions (56b16caa0e)
  • Introduce shadow relationship management in identity provider connections (d63dae95bc)
  • fix: restore commit notification scope before flush (c3c6f12858)
  • Remove migration for external authentication in EFCore.Sqlite module (6e3ed5c4e0)
  • Add test for handling archived database overrides in connection shadows (14f373528d)
  • Refine test to ensure archived connections do not participate as active shadows; update shadow relationship management to exclude archived entries. (9f09aca3f6)
  • fix: simplify external authentication secret IDs (119f49f7a2)
  • Refine test for archived connections in shadow relationships; introduce IsAvailableForAuthentication helper for improved connection filtering logic. (a60b5a36b2)
  • Add test to validate complete configuration requirements for connections (a24a6fe267)
  • Avoid repeated tenant-agnostic registry population (542058971b)
  • fix: validate external login methods before discovery (1b74bb94c0)
  • Fix external authentication review findings (fe125ac336)
  • Harden external identity race compensation (286a0d83d1)
  • refactor: update package reference configuration (ff10a68100)
  • Add architecture and practices documentation (5429008d98)
  • Use last version for revert version allocation (d9ba421737)
  • Resolve NU1903 warning (5fd3a074c9)
  • Add project reference to HTTP Webhooks module (bde8b2ccf2)
  • fix: quote API key secrets in dotnet nuget push to prevent argument parsing failure (#7951) (b0ab630a34)
  • feat: Implement OIDC Trusted Publishing for NuGet (f6c35cf1eb)
  • Add output converter support at binding boundaries (61fc376dac)
  • Harden output converter contracts (dff7d9f987)
  • Fix StateMachine transition lifecycle ordering (051e12f864)
  • Enforce StateMachine trigger identity boundaries (6a2e530d77)
  • Expand StateMachine conformance coverage (5a820ce33e)
  • Yield triggerless StateMachine cycles (da5ccca2be)
  • Preserve StateMachine composite transition continuations (2787ff6bd0)
  • Initial plan (8804dda467)
  • Update FastEndpoints and empty resume request (4efdf5fbff)
  • Use FastEndpoints empty-request endpoint base (750549c797)
  • Allow FastEndpoints EmptyRequest in Elsa endpoint wrappers (016ffe5d8d)
  • Address resume endpoint review feedback (e7debff3f2)
Source: README.md, updated 2026-09-05