{
  "current": {
    "version": "3.1.2",
    "date": "2026-07-08",
    "rubricVersion": "2.3.0",
    "scannerVersion": "2.0.0",
    "summary": "Patch: documentation architecture and served-surface link fixes, no behavior change. Split the backward-looking history into a new CHANGELOG.md (Keep a Changelog format) and made ROADMAP.md future-only; a guardrail test asserts CHANGELOG.md mirrors every changelog.json version. Enriched the /history/ timeline (April paid-services launch, v2.5.0, v3.1.x) and corrected its intro to not claim public verifiability of a private-repo commit hash. Removed three github.com/snapsynapse/siteline links from the served assistant-guide.txt (private repo returns 404); the guide stays GuideCheck shape-conformant. project-memory product table corrected: Monitoring is live and self-serve on Stripe, Hosted API is contact-gated. Scanner 2.0.0 and rubric 2.3.0 unchanged."
  },
  "history": [
    {
      "version": "3.1.2",
      "date": "2026-07-08",
      "summary": "Patch: documentation architecture and served-surface link fixes, no behavior change. Split the backward-looking history into a new CHANGELOG.md (Keep a Changelog format) and made ROADMAP.md future-only; a guardrail test asserts CHANGELOG.md mirrors every changelog.json version. Enriched the /history/ timeline (April paid-services launch, v2.5.0, v3.1.x) and corrected its intro to not claim public verifiability of a private-repo commit hash. Removed three github.com/snapsynapse/siteline links from the served assistant-guide.txt (private repo returns 404); the guide stays GuideCheck shape-conformant. project-memory product table corrected: Monitoring is live and self-serve on Stripe, Hosted API is contact-gated. Scanner 2.0.0 and rubric 2.3.0 unchanged."
    },
    {
      "version": "3.1.1",
      "date": "2026-07-08",
      "summary": "Patch: documentation and copy reconciliation to canon, no behavior change. Reconciled prices and product state across internal repo docs, external agent-facing files, and site copy against the LocalBrain Master Pricing List (the single source of truth). Every customer- and agent-facing surface was already correct on all six prices; drift was confined to internal docs and the vault. agents.json Hosted API now reads '$49/mo, not self-serve yet' (price set, offer contact-gated). Stale internal claims fixed: Monitoring $9->$19 in the self-assessment doc, Monitoring status (planned->live) and de-hardcoded test counts in project-memory, the stale rubric-roadmap 'Current Gap' (docs/oss/portfolio overlays ship). Added test/doc-consistency.test.mjs: no retired prices on customer/agent surfaces, Monitoring priced at $19 where priced, no hardcoded test counts in durable docs. Scanner 2.0.0 and rubric 2.3.0 unchanged."
    },
    {
      "version": "3.1.0",
      "date": "2026-07-08",
      "summary": "Minor: additive served-surface and documentation fixes from the 2026-07-08 review. The changelog and API-manifest endpoints (/api/v1/changelog.json and /api/v1/index.json) now serve JSON where they previously 404'd (files under api/ are treated as functions), moved to root paths with Vercel rewrites matching /api/v1/openapi.json. The OpenAPI specs now document the siteType query parameter (11 public site-family values), covered by a contract test. Agent-facing docs reconciled: llms.txt lists Monitoring as a first-class service and agents.json no longer states a live $49/mo Hosted API price (marked not-self-serve). Scanner 2.0.0 and rubric 2.3.0 unchanged; no scoring or grade behavior change."
    },
    {
      "version": "3.0.0",
      "date": "2026-07-07",
      "summary": "Composite scan and grade-integrity release. Every scan now returns three views: an attributed Cloudflare Agent Readiness protocol baseline (external.cloudflare) and open-standards conformance checks (standards: Graceful Boundaries passive evidence, GuideCheck assistant-guide.txt shape validation) alongside Siteline's SNAP judgment. Both new panels are informational and never feed the score, grade, or level. Grade integrity: http:// input that 301-redirects to https is graded on the final URL (no more false F), HTML-shell responses at machine-resource paths count as absent rather than inflating agentic level, WAF classification is word-bounded and gated on thin pages, and robots.txt is parsed into RFC 9309 user-agent groups so per-bot rules no longer leak. These fixes change grades for affected sites, which is why this is a major release. Endpoint auth hardened (unconditional CRON_SECRET, constant-time token compares, rate-limited outreach) and /api/limits now carries proactive RateLimit headers. Scanner 1.6.0 to 2.0.0. Rubric unchanged from 2.3.0; scoring weights, caps, and level thresholds are identical."
    },
    {
      "version": "2.6.0",
      "date": "2026-05-30",
      "summary": "Security hardening release: SSRF validation now covers IPv4-mapped private IPv6 literals, DNS preflight for initial and redirect targets, and broader reserved/internal address ranges. Checkout return URLs are canonicalized to https://siteline.to and hostile forwarded hosts fail closed before Stripe is called. Scanner response bodies are byte-capped before parsing with optional bodyTruncated metadata. Public schema, deterministic security evals, and hardening tests cover the new behavior. Residual: DNS preflight is not connection-level DNS pinning; constrained egress or pinned transport remains a future defense-in-depth option."
    },
    {
      "version": "2.5.0",
      "date": "2026-05-26",
      "summary": "Finding evidence: CTA ambiguity findings can include matched label text, href, selector, element type, and ambiguity rule. Machine discovery warning copy now distinguishes partial coverage from no discovery. Commerce profile precision: Offer and SoftwareApplication schema no longer imply ecommerce for portfolio/static sites without stronger transaction evidence. Static semantic resources detected: assistant-guide.txt, ontology.json, relationships.yaml, HTML service-desc/security/alternate machine links. These semantic resources are reported under informational.semanticResources and evidence.probes[] with purpose=informational; no score, Layer 2, findings, or remediation impact. Public scan-result schema is contract-tested against current output, including remediationTier object shape and provenance roles."
    },
    {
      "version": "2.4.0",
      "date": "2026-05-18",
      "summary": "F1 probe-evidence ledger: result.evidence.probes[] records url/status/content-type/duration/verdict/reason plus SHA-256 and a 512-byte excerpt for every core, extended, D/E, x402, site-declared, and header-derived check. Defensibility artifact (e.g. an SPA-200 mcp.json is recorded verdict=fail). Additive, no scoring change, parity preserved. F2 (stack-specific remediation) and F3 (percentile/peer benchmarking) remain roadmapped."
    },
    {
      "version": "2.3.0",
      "date": "2026-05-18",
      "summary": "Standards Library v1 (Phase D/E): RFC 8288 Link headers, RFC 9727 api-catalog, RFC 8414/9728 OAuth discovery + 401 WWW-Authenticate, MCP server-card, /index.md, Web Bot Auth signatures directory. Each is a content-validated protocol-agnostic alternate folded into an existing Layer 2 purpose by best-score-wins; no new purposes, Layer 1 untouched, parity preserved. The Web Bot Auth Layer-1 access-penalty softening remains deferred."
    },
    {
      "version": "2.2.0",
      "date": "2026-05-18",
      "summary": "Promise-relative Layer 2 + commerce-gated Transactability (9th purpose, max 18) via a declarative content-validated pattern registry with site-declared subdomain following. Precision-gated to genuine purchase intent or a strong exposed agentic surface; loose link words never qualify; non-commerce scoring is bit-for-bit unchanged. Access-gate soft-block false-positive fixed (substantive-page guard)."
    },
    {
      "version": "2.1.0",
      "date": "2026-03-26",
      "summary": "Two-layer scoring model (V2.1): SNAP fundamentals (floor) + Agentic Enablement (ceiling). 11 resources qualitatively scored at 0/1/2. Level 0-4 caps grade at D/D/C/B/A. All non-success API responses now include structured error/detail/why fields per Graceful Boundaries. Proactive RateLimit headers on all endpoints."
    },
    {
      "version": "2.0.0",
      "date": "2026-03-22",
      "summary": "V2 complete: Dynamic OG images, PDF export, MCP server, batch scanning, remediation routing, content model signal, scan provenance, confidence scoring, CLI, durable records with Supabase."
    },
    {
      "version": "1.0.0",
      "date": "2026-03-19",
      "summary": "Initial release: 4-pillar SNAP scoring (Signal, Navigate, Absorb, Perform), REST API, single-page scanner."
    }
  ]
}
