← Release notes

v0.2.729 Jul 2026

Say what the thing actually is

The npm README listed five tools where the server registers ten, and never mentioned that half the product is a GitHub App. The privacy claim was overstated too.

It told readers to build from source and register an absolute dist path — instructions that cannot work for anyone arriving via npx — and never mentioned the App, so an npm installer got half a product with nothing saying so. It now leads with the two installs, states that the second is a GitHub App rather than an Action, and documents all ten tools by role.

The privacy claim

“Validation runs against the diff on GitHub’s side of the fence” read as though repository content never reached the service. It does: the worker fetches the document and the full base...head diff from the GitHub API.

Nothing is persisted — that is the claim worth making, so that is the claim now made, with the in-transit caveat named rather than left in index.ts for a reader to find.

Commits for this release: v0.2.6…v0.2.7