Release: merge development into beta - #1026
Open
github-actions[bot] wants to merge 52 commits into
Open
github-actions[bot] wants to merge 52 commits into
github-actions[bot] wants to merge 52 commits into
Conversation
…260912202721 chore(release): 0.2.3-unstable.20260912202721
…0260913184544 chore(sync): carry beta back into development
…istry (#1032) * feat(connections): declare email, federation and the end-of-life feed for integriq * feat(connections): refresh and report email, federation and the end-of-life feed to integriq * feat(connections): an Integrations page over integriq's connection registry * test(connections): an e2e spec for the Integrations page, with integriq in CI * test(connections): named arguments, and stubs that wait for OCP * refactor(connections): keep the event senders private
… bytes (#1049) Prettier 3.9.6 over the four files the connection-registry wave merged unformatted, so `npm run format` passes again. ConnectionsDeclarationTest now reads appinfo/info.xml as bytes: Nextcloud's lib/base.php installs an external entity loader that returns null, so simplexml_load_file() returns false in every CI cell. Verified locally: npm run format exit 0, npm run lint 0 errors, composer check:strict ALL CHECKS PASSED, phpunit --filter ConnectionsDeclarationTest green.
…roller (#1051) The test builds SettingsController with newInstanceWithoutConstructor(), so the promoted ?ConnectionReportService $connectionReports = null never received its null and PHP threw on the read in all six cells. Verified with the standalone unit config: 11 tests pass, and the unchanged file reproduces CI's exact error.
…gain (#1054) The module schema's licence property carried a stray "licence": "License" beside its real title. openregister's vocabulary check rejected the whole schema at import while answering 200, so CI seeding failed. openregister's own validator now reports 20 schemas, 0 rejected, for both register files (it reproduced the CI rejection before the fix). Gates pass.
… formatters come from nextcloud-vue 3.2.0 (#1053) * feat(connections): switched-off federation and a switched-off EOL sync read disabled through their switches federation declares switch on federation_enabled, and eol-feed on enabled inside eol_sync_config (hydra connection-registry D4 rule 2b, D12 items 6, 7 and 9). A peer change, a pull, a sync save and a sync run no longer report unconfigured when the feature is off: the save still refreshes, and integriq resolves disabled itself. * test(connections): a switched-off federation with no peers reports nothing The earlier case had a peer, so dropping the switch guard left the outcome the same and the test green. With no peers the guard is the only thing between the switch and a no-peer-catalog report. * chore(deps): @conduction/nextcloud-vue 2.39.0 -> 3.2.0, and the connection formatters come from the library 3.2.0 ships connectionStatus, with disabled read as Switched off, and connectionSettingsLabel as built-ins (nextcloud-vue#1173, #1175). The local copy in src/services/connectionRegistry.js and App.vue's formatters prop are gone; the handler stays. The spec now checks the manifest's formatter names against the installed library's built-in map. The range was ^2.37.0 with 2.39.0 locked; against development only the library and the hoisted @nextcloud/files (3.12.2 -> 4.0.0) move at the top level. * test(connections): declare the built-in formatter reader with the function keyword antfu/top-level-function refuses a top-level arrow function. * test(connections): import the built-in formatters and call them, instead of reading the module source
…name (#1056) A row's accessible name starts with its Select row checkbox, so the anchored pattern matched 0 rows (keepiq#717). Rows are now matched through their Connection cell.
Bumps [eslint](https://github.com/eslint/eslint) from 10.9.1 to 10.10.0. - [Release notes](https://github.com/eslint/eslint/releases) - [Commits](eslint/eslint@v10.9.1...v10.10.0) --- updated-dependencies: - dependency-name: eslint dependency-version: 10.10.0 dependency-type: direct:development update-type: version-update:semver-minor ... Signed-off-by: dependabot[bot] <[email protected]> Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
Bumps [zod](https://github.com/colinhacks/zod) from 4.5.4 to 4.6.5. - [Release notes](https://github.com/colinhacks/zod/releases) - [Commits](colinhacks/zod@v4.5.4...v4.6.5) --- updated-dependencies: - dependency-name: zod dependency-version: 4.6.4 dependency-type: direct:production update-type: version-update:semver-minor ... Signed-off-by: dependabot[bot] <[email protected]> Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
Bumps [gridstack](https://github.com/gridstack/gridstack.js) from 13.2.0 to 13.3.0. - [Release notes](https://github.com/gridstack/gridstack.js/releases) - [Changelog](https://github.com/gridstack/gridstack.js/blob/master/doc/CHANGES.md) - [Commits](gridstack/gridstack.js@v13.2.0...v13.3.0) --- updated-dependencies: - dependency-name: gridstack dependency-version: 13.3.0 dependency-type: direct:production update-type: version-update:semver-minor ... Signed-off-by: dependabot[bot] <[email protected]> Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
Bumps [dexie](https://github.com/dexie/Dexie.js) from 4.4.5 to 4.4.6. - [Release notes](https://github.com/dexie/Dexie.js/releases) - [Commits](dexie/Dexie.js@v4.4.5...v4.4.6) --- updated-dependencies: - dependency-name: dexie dependency-version: 4.4.6 dependency-type: direct:production update-type: version-update:semver-patch ... Signed-off-by: dependabot[bot] <[email protected]> Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
…stered (#1059) settings#getArchiMateConfig is declared at /api/archimate/config and at /api/archimate/status with no postfix on either. A route name carries neither URL nor verb, so the two register as one and the later declaration wins: GET /api/archimate/config is a 404. Which of the two survives depends on line order alone, and the survivor is the one the settings store polls, inside a catch with an empty body. postfix on the second entry gives each its own name. Measured with Nextcloud's own RouteParser: declared=132 registered=131 before, 132 after. No URL or verb changes. RouteNameUniquenessTest asserts on each entry's registration key and is mutation-checked against the old routes file.
The 3.x line was withdrawn on 2026-09-19. npm dist-tags now give latest = 2.55.1, the 2.x releases were published after the 3.x ones that day, and only the v2 tags survive. A range of ^3.2.0 matches only 3.x, so this app could never resolve the next release. 2.55.1 is a strict superset of 3.4.0: every one of the 621 CJS and 536 ESM export names is present, no published file is missing, and package.json is identical apart from the version. Verified by unpacking both tarballs.
…o-2x chore(deps): move nextcloud-vue back to the 2.x line
173 rows in 12 areas against five competitor columns, competitor cells from the intelligence database. Stackiq's own column is not read yet.
134 rated rows and 39 pending across 12 areas. Every own rating carries a path and a line, a reachedOn and, on sibling rows, the owning repo.
feat(parity): stackiq's capability matrix against five competitors
Later parity lanes read other products and found ratings and wording in this matrix that their code contradicts. Corrected rows carry readOn 2026-09-26 and name the cross-product evidence.
…ections-2026-09-26 fix(parity): apply cross-lane corrections to the capability matrix
…ic docs read 2026-09-26) and r-glpi packs to 29
…, sources objects for three systems
…admaps and changelogs, stackiq rated from code
…rows, sources for all five systems
…urce-read chore(parity): wave 5, GLPI source read and driven at 11.0.9, four docs columns re-read, 42 demand rows
… first use) (#1092) 2.57.1 imports Dexie on first use of the offline database instead of at import time, so this app's bundle no longer evaluates Dexie on every page.
…ges with the gap decisions (#1094) * docs(openspec): connections-catalogue-pages, connection index, detail and application-page lists * docs(openspec): connections-diagram-and-graph-export, application map, list diagram and connections in the ArchiMate export * docs(openspec): connections-api-catalogue, record the APIs an application offers * docs(openspec): connections-derived-dependencies, suggest known and carried-over connections * docs(openspec): landscape-application-page, correct keys, usages, contracts and opening from the list * docs(openspec): landscape-usage-registration, usage pages, owners and a working usage lifecycle * docs(openspec): landscape-application-components, partOf relation and a components list * docs(openspec): landscape-change-entry-type, change type through OpenRegister's identity-keeping move * docs(openspec): landscape-move-between-organisations, transfer chosen entries with a dry run * docs(openspec): landscape-dependent-field-options, dependent option tables enforced by OpenRegister * docs(openspec): landscape-completeness-score, OpenRegister quality rules, confirm action and report * docs(openspec): landscape-owner-attestation, confirmation rounds for owners * docs(openspec): landscape-ai-system-inventory, AI systems with AI Act classification and evidence * chore(parity): OpenSpec-pass decisions and matrix states for the first 13 changes * docs(openspec): landscape-ai-system-inventory, FRIA as a reference field like the DPIA
…nges (#1109) * docs(openspec): architecture-views-editor, draw, tag and compare views on CnGraphCanvas * docs(openspec): architecture-views-editor, readers keep only imported or empty origin * docs(openspec): architecture-assistant-drafted-views, two MCP tools draft a marked view for review * docs(openspec): architecture-process-mapping, processes and steps linked to applications in use * docs(openspec): architecture-data-model-and-ggm, data model pages and GGM entities on applications in use * docs(openspec): architecture-reference-component-coverage, gaps, overlaps and a coverage map per organisation * docs(openspec): lifecycle-application-value-assessment, value, fit and risk scores behind the TIME class * docs(openspec): lifecycle-maintenance-and-supplier-roadmap, maintenance windows, owner notices and a product roadmap * docs(openspec): architecture-future-state-scenarios, the plan and named scenarios compared with today * docs(openspec): architecture-decision-register, reviewed decisions as stackiq objects linked to applications * docs(openspec): architecture-views-editor, guard the single view read that runs without RBAC * docs(openspec): architecture-views-to-office-documents, SVG from stackiq and office files through filinq * docs(openspec): architecture-round-trip-check, an admin check that writes nothing replaces the broken round trip * chore(parity): OpenSpec-pass batch 2 matrix states and decisions
…, organisations, security and sharing changes (#1121) * docs(openspec): contracts-expiry-and-owner, an expiring status and a responsible user per contract * docs(openspec): contracts-expiry-and-owner, guard quick filters against the enum * docs(openspec): contracts-expiry-and-owner, fix an escaped backtick * docs(openspec): contracts-expiry-and-owner, put appended schema parts in a register fragment * docs(openspec): contracts-licence-seats, licence metric and seats bought against in use * docs(openspec): insight-exports-and-custom-reports, list exports, own organisation export and custom reports * docs(openspec): insight-supplier-facet, supplier as a fifth facet on applications and services * docs(openspec): insight-knowledge-base, articles in Collectives linked to applications * docs(openspec): operations-sync-status-and-progress, shared progress, last run and a sync page for functional administrators * docs(openspec): sharing-generated-api-docs, generated OpenAPI documents read in the app * docs(openspec): sharing-compliance-documents, compliance documents with an audience * docs(openspec): operations-technology-components, organisation technology with runs-on relations and end of support * docs(openspec): sharing-itsm-exchange, service desk exchange through integriq flows * docs(openspec): sharing-itsm-exchange, seed data line follows the set-up action * docs(openspec): operations-record-reconciliation, OpenRegister dedup and merge for applications and services * docs(openspec): organisations-role-mapping-and-access-review, role groups from chosen groups and an access review page * docs(openspec): operations-sync-status-and-progress, align the role group note with the role mapping change * docs(openspec): security-baseline-classification, availability, integrity and confidentiality per application in use * chore(parity): OpenSpec-pass batch 3 matrix states and decisions * docs(openspec): guard the transfer and attestation endpoints on the maintainer rule, not the empty admin-group list
Rows in this matrix whose state, owner or rating changes now that the owning repo's OpenSpec change exists (sibling-rows pass, 2026-09-28). Only the listed rows change; parity-verify --strict output is identical before and after.
…1147) SettingsService::getOrganizationAdminGroups() returned an empty list unconditionally, so the organisation admin groups an admin saved were discarded: the settings page reloaded empty and the organisation export permission never saw the chosen groups. The getter (and its copy in OrganizationSettingsHandler) now reads organization_admin_groups, with no default list. The first-contact assignment in ContactPersonHandler was switched off on purpose in bc4dc9e through that same empty getter. It stays off: the loop that added a first contact to these groups is removed, and a test pins that. The export permission now lets a member of a saved group export only their own active organisation (core/organisation), the rule PortfolioReportController applies. The whole-register export passes no organisation and stays admin-only, so restoring the read widens nothing beyond the member's own organisation.
…pe the list cache per caller (#1149) GET /api/views/{viewId} read the view with _rbac and _multitenancy off, so a view the list hides could still be read by its uuid. The single read now uses OpenRegister's defaults; a view the caller may not read comes back as null and the route answers 404. The views list was cached under the fixed key views_list, so the first caller's RBAC and organisation scoped list was served to every caller for 30 minutes. The key now carries the user and the active organisation. Fixes #1142
…#1151) organization.type holds Municipality, Supplier, Collaboration or Community, but ContactPersonHandler's role map still used the Dutch keys gemeente, leverancier and samenwerking, so only Community matched and municipal and supplier contacts got no role group on account creation or update. The map is now keyed on the stored enum, lower-cased. GroupHandler::updateRoleBasedGroups() compared group names with the capitalised roles enum by exact case, so a holder of Aanbod-beheerder was never added to aanbod-beheerder and a member was removed. Names are now compared without regard to case.
…able by its owner and admins (#1153) * fix(progress): keep operation progress in the distributed cache, readable by its owner and admins ProgressTracker kept every snapshot in the user's ISession, so no other login, no admin and no background job could read or write it. Progress now lives in ICacheFactory::createDistributed('stackiq_progress') for an hour after its last write. The public methods and the response shape are unchanged. Because an operation id no longer stays inside one session, the read rule on GET /api/progress/{operationId} and its stream is tightened: the owner and Nextcloud admins read it, anyone else gets 404. An operation started without an explicit owner belongs to the signed-in user who started it; one a background job started has no owner and is for admins only. Fixes #1138 * fix(progress): compare isAdmin() with true, since IGroupManager::isAdmin() declares no return type The existing SettingsControllerStatusContractTest caught the TypeError when an unconfigured double returned null.
…1140) (#1154) The x-openregister-lifecycle blocks of usage, catalogContract, connection and moduleVersion still named the Dutch states while their status enums and the migrated rows are English, so no transition was ever offered on those records and nothing raised an error. The states now use the enum values in both shipped register files, and the four schema versions are bumped (a lifecycle-only edit does not deploy without one, as the 2.4.4 changelog records). Register 2.5.1. LifecycleStatesMatchEnumTest walks every lifecycle in both register files and asserts each state it names is a value of the driven field's enum.
…r could call (#1158) * fix(archimate): remove the round-trip test endpoint POST /api/archimate/test-round-trip let any signed-in user, without a CSRF token, import a hard-coded test model into the live AMEF register and export the whole register, and its comparison could never succeed. The route, SettingsController::testArchiMateRoundTrip, ArchiMateService::testRoundTrip with its test model and temp file, and the unused store action are removed. Fixes #1075 * chore(lint): drop the no-console suppression the removed store action held
…ch (#1160) An admin could switch the job off in the cronjob settings, which stores enabled: false under cronjob_config, but the job read nothing of it and kept syncing every five minutes. SettingsService::isCronjobEnabled() reads the stored switch (a job never saved is on, as the settings screen shows), and OrganizationContactSyncJob::run() returns before the sync and the contactsUid refresh when it is off. Fixes #1139
…o the target (#1162) The organisation merge re-pointed usage, contact persons, connections, contracts and compliancy, but not the supplier's own modules and services: their provider (a Vendor reference to organization) and their own @self.organisation stayed on the tombstoned source. Both are now re-pointed, counted in the dry run under their own keys, and shown in the confirm dialog, whose contract row read a count key the service never sets. Fixes #1086
…#1164) The main spec carried empty `## MODIFIED Requirements` and `## REMOVED Requirements` blocks (each "_None._"). A delta header belongs in openspec/changes/<name>/specs/ only; in a main spec it truncates the parsed `## Requirements` section (ConductionNL/hydra#712). A vitest guard fails when a main spec carries a delta header again. Refs ConductionNL/hydra#712
…oes (#1166) openspec rejects '## Removed requirements' in a main spec just like '## REMOVED Requirements'; the guard only caught the upper-case form. Refs ConductionNL/hydra#712
This branch has not been deployed
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Automated PR to sync development changes to beta for beta release.
Merging this PR will trigger the beta release workflow.