Registry stack documentation: machine-readable Markdown.
Index of all pages: https://docs.registrystack.org/preview/llms.txt
Full corpus: https://docs.registrystack.org/preview/llms-full.txt

# Changelog

> Notable changes to the Registry Stack documentation and the documented product versions.

This page records notable changes to the documentation site and the product versions it
documents.
Per-product release notes live in each product repository; the entries below link to the
relevant product pages on this site rather than duplicating release notes.

## 2026-07-28

Documentation updates for the v0.15.0 beta-20 release candidate:

- Published the versioned Registryctl installer and the spreadsheet-first local
  API and registry-backed claim tutorials as the maintained beginner path.
- Added generated configuration, ownership, authoring, fixture, and operator
  references for the complete project-authoring surface.
- Documented all-row spreadsheet validation, stable governed attribute release,
  Relay-to-Notary consultation closure, and value-free activation diagnostics.
- Added the candidate `v0.15.0` archive while retaining `v0.13.0` as the latest
  published release until promotion completes.
- Recorded that v0.14.0 was not published and is not part of this release
  lineage.
- Kept Solmara, hosted publication, external OpenID, OpenCRVS, DHIS2, wallet,
  verifier, and country-acceptance evidence as separate gates.

## 2026-07-26

Unreleased current-source documentation updates:

- Added task-oriented Start, Connect your data, Operate, Security, and
  Reference navigation for new adopters.
- Added generated references for all five authored and both runtime
  configuration domains, with fail-closed field-intent and ownership coverage.
- Added separate generated authoring, fixture, and operator diagnostic
  references.
- Restored the released spreadsheet API and live registry-backed claim
  tutorials as the primary beginner path.
- Kept advanced operations for rotation, materialization, reapproval,
  diagnosis, Script workers, recovery, upgrade, migration, and rollback
  available from the operator handoff instead of presenting them as beginner
  journeys.

These pages describe the current source under test. They are not part of the
immutable v0.13.0 archive and do not claim candidate, hosted, country,
interoperability, or production evidence.

## 2026-07-25

Documentation updates for the v0.13.0 beta-17 release:

- Advanced current source citations, install commands, verification examples,
  contracts, projects, and standards links to Registry Stack `v0.13.0`.
- Added the `v0.13.0` archived docset while retaining every earlier release
  archive.
- Documented removal of Relay's inert `provenance.consent` result member, the
  required pre-release consultation-state re-bootstrap, and Notary's matching
  closed decoder.
- Documented the shared deployment-waiver `reference` and optional `summary`
  contract, with the retired `reason` field rejected.
- Updated Registryctl authoring examples to keep source adaptation, evidence
  policy, and consumer decisions separate, and recorded the
  `registryctl.smoke.v1` report schema.
- Kept Solmara, hosted publication, external integration, OpenID, lifecycle,
  OpenSPP holdout, and pilot evidence as separate held gates.

## 2026-07-23

- Made the Relay-to-Notary-to-evidence-consumer responsibility boundary normative for 1.0 project
  authoring. Updated Notary guidance and registryctl examples to keep reusable evidence separate
  from consumer-owned requirements, decisions, workflow, and action rules.

## 2026-07-20

Documentation updates for the v0.12.2 beta-16 fix-forward release:

- Advanced current source citations, install commands, verification examples,
  contracts, projects, and standards links to Registry Stack `v0.12.2`.
- Added the `v0.12.2` archived docset while retaining the incomplete v0.12.0
  and v0.12.1 publication records and every earlier archive.
- Recorded separate Registryctl and Relay release builds, verification of the
  shipped Relay feature set, and pinned canonical binary and image wrappers
  used to reproduce candidate hashes and ordered runtime root filesystem
  layers.
- Recorded Relay's move to `quick-xml` 0.41 and the exact `ryu-js` 1.0.3 pin,
  retiring temporary dependency exceptions without adding product features.
- Moved Registry Notary router tests to in-process transport where network
  semantics are not under test, preventing release-gate socket exhaustion
  without changing production request handling.
- Recorded the production fix that isolates each single-use eSignet
  authorization-code exchange on short-lived DNS-pinned transport, with
  redirects and proxies denied, bounded timeouts, and no transparent retry.
- Kept Solmara, hosted publication, external integration, OpenID, lifecycle,
  and pilot evidence held.

Documentation updates for the v0.12.1 beta-15 fix-forward release:

- Advanced current source citations, install commands, verification examples,
  contracts, projects, and standards links to Registry Stack `v0.12.1`.
- Added the `v0.12.1` archived docset while retaining the incomplete v0.12.0
  publication record and every earlier archive.
- Recorded the root-filesystem-bound reviews for the three non-fixable Debian
  13 `libc6` findings that stopped the v0.12.0 publication attempt.
- Recorded deterministic release plans, remote tag checks, both-image Open
  Containers Initiative label smoke, and safer release workflow routing.
- Kept Solmara, hosted publication, external integration, OpenID, lifecycle,
  and pilot evidence held.

## 2026-07-19

Documentation updates for the v0.12.0 beta-14 release:

- Advanced current source citations, install commands, verification examples,
  contracts, projects, and standards links to Registry Stack `v0.12.0`.
- Added the `v0.12.0` archived docset while retaining the v0.11.0 and earlier
  archives.
- Documented Registry Notary's issuer-initiated pre-authorized-code profile,
  bounded batch evaluation, generated runtime configuration schema, and
  fail-closed credential-status verification.
- Documented Registry Relay's intended 1.0 support roster and protected
  per-resource last-good refresh health.
- Updated Registryctl tutorials for human-readable report defaults and the
  matching v0.12.0 binary, image lock, and image generation.
- Recorded the Debian 13 runtime transition and kept candidate-only lifecycle,
  external integration, OpenID, Solmara, hosted, and pilot evidence held.

- Documented Relay's protected per-resource refresh-health metrics, restricted posture
  observation, last-good availability behavior, and default alert at three consecutive failures.
- Documented the source installer for the optional VS Code and Zed semantic-navigation
  integrations. Editor installation is user- or profile-scoped and remains separate from
  project-local schema setup through `registryctl init` or `registryctl authoring editor`.

## 2026-07-18

Documentation updates for the v0.11.0 beta-13 release:

- Advanced current source citations, install commands, verification examples,
  contracts, projects, and standards links to Registry Stack `v0.11.0`.
- Added the `v0.11.0` archived docset while retaining the v0.10.0 and earlier
  archives. The public release inventory remains eight artifacts. Registryctl
  embeds the optional preview language server; it is not a separate release
  artifact. The VS Code and Zed extensions remain source-installed developer
  previews and are not marketplace packages.
- Published the registry-backed local Notary tutorial and the maintained
  authoring-workspace catalog. Registryctl continues to expose exactly five
  public starters. The local tutorial proves evaluation only, not credential,
  wallet, presentation, or OID4VCI interoperability.
- Documented the credential-issuance migration: only fresh, non-delegated,
  registry-backed evaluations with exact Relay provenance are credential
  capable. Source-free and delegated results remain evaluation and rendering
  surfaces, and old evaluations require re-evaluation before issuance. No
  database migration is required solely for this narrowing.
- Added migration coverage for ambiguous primary credentials, strict empty
  environment expansion, Relay Script host-call diagnostics, and offline audit
  quarantine recovery.

This beta does not claim stable 1.0 completion, full OID4VCI interoperability,
hosted promotion, audit completion, or an external pilot result.

## 2026-07-16

Documentation updates for the v0.10.0 beta-12 release:

- Advanced current source citations, install commands, and deployment examples to Registry Stack
  `v0.10.0`.
- Added the `v0.10.0` archived docset with the four formal products and Crosswalk. Solmara Lab
  remains a separate adopter demo, not a released Registry Stack artifact.
- Published the Notary PostgreSQL install, role, migration, retention, backup, restore, recovery,
  supported-version, restart, and multi-instance contract.
- Added separate Relay consultation-state backup and restore guidance without sharing Relay roles,
  schemas, or tables with Notary.
- Replaced the retired monorepo Lab documentation route with a source-backed Solmara local journey.

Migration notes:

- Notary production correctness state now uses Notary-owned PostgreSQL. The pre-1.0 Redis cutover
  is a stopped-writer transition with explicit drain and credential-status gates.
- Registry project authoring now uses `registry-stack.yaml`, explicit integrations, fixtures,
  service topologies, and environment bindings. Reauthor pre-1.0 project files and review changed
  RFC 8785 canonical digests before signing.
- Deploy one Notary authority per Relay trust domain. Identical replicas may share that authority's
  Notary database, but Relay and Notary retain separate state ownership.
- Deploy the released Relay Rhai and Notary CEL workers only for their owning product's adapter
  contract. They are not a shared extension or state framework.

## 2026-07-10

Documentation updates for the v0.9.0 beta-11 release:

- Advanced the active monorepo docs and source citations to RegistryStack `v0.9.0`.
- Added the `v0.9.0` archived docset pinned to the beta-11 freeze source ref.
- Updated registryctl install examples and current deployment tutorials to the `v0.9.0` release
  tag while retaining the published v0.8.4 stale-digest workaround until tagged artifact proof
  closes it.
- Kept hosted first-run publication held while the credential failure in
  [GH#330](https://github.com/registrystack/registry-stack/issues/330) and the complete
  [GH#198](https://github.com/registrystack/registry-stack/issues/198) fresh-reader run remain open.

Migration notes:

- Registryctl project generation now requires the strict image lock from the same release beside
  the binary, or at an explicitly verified `REGISTRYCTL_IMAGE_LOCK` path. Existing projects still
  run from their stored immutable pins. See
  [GH#339](https://github.com/registrystack/registry-stack/pull/339).
- Relay passes a client-supplied trust-context header to the PDP only when the caller has the exact
  `registry:trust:<field>:<value>` scope. Update caller scopes before relying on those fields;
  their value-bearing audit scopes are now pseudonymized. See
  [GH#338](https://github.com/registrystack/registry-stack/pull/338).
- Notary federation denials now preserve their audit context. No new client request field is
  required, but operators should retain the enriched denial records. See
  [GH#337](https://github.com/registrystack/registry-stack/pull/337).

## 2026-07-04

Documentation updates for the v0.8.4 beta-10 release:

- Advanced the active monorepo docs and source citations to RegistryStack `v0.8.4`.
- Added the `v0.8.4` archived docset pinned to the beta-10 source ref.
- Updated registryctl install examples and current deployment tutorials to the `v0.8.4` release tag.
- Recorded v0.8.3 as the first provenance-bearing root release.

## 2026-06-26

Documentation updates for the v0.8.3 security and release-trust patch:

- Advanced the active monorepo docs and source citations to RegistryStack `v0.8.3`.
- Added the `v0.8.3` archived docset pinned to the beta-9 source ref.
- Updated registryctl install examples to the `v0.8.3` release tag.
- The `v0.8.2` docset remains archived; its release carries no tag-bound SLSA provenance.

## 2026-06-25

Documentation updates for the v0.8.2 fix-forward release:

- Advanced the active monorepo docs and source citations to RegistryStack `v0.8.2`.
- Added the `v0.8.2` archived docset pinned to the beta-8 source ref.
- Updated registryctl install examples to the `v0.8.2` release tag.
- Kept the `v0.8.1` docset archived (source tag only; no release artifacts were published).

Documentation updates for the v0.8.1 source release:

- Advanced the active monorepo docs and source citations to RegistryStack `v0.8.1`.
- Added the `v0.8.1` archived docset pinned to the beta-7 source ref.
- Added monorepo-aware archive handling for v0.8.x docsets while keeping older beta archives on
  their legacy source repos.
- Updated registryctl install examples to the `v0.8.1` release tag.

## 2026-06-24

Documentation updates for the beta-5 source release:

- Added the `Beta 5` docset with pinned refs for Platform, Manifest, Notary, Relay, Lab,
  registryctl, Crosswalk, and Atlas as a Lab input.
- Advanced the active product docs to Registry Relay `v0.5.0`, Registry Notary `v0.7.0`, and
  Registry Manifest `v0.2.2`.
- Updated OpenCRVS, FHIR-adjacent, and standalone deployment tutorial references to the beta-5
  release pins.

## 2026-06-22

Documentation updates for the beta-4 source release:

- Added the `Beta 4` docset with pinned refs for Platform, Manifest, Notary, Relay, Lab,
  registryctl, Crosswalk, and Atlas as a Lab input.
- Advanced the active product docs to Registry Relay `v0.4.1`, Registry Notary `v0.6.2`, and
  Registry Manifest `v0.2.2`.
- Updated source citations and tutorial install commands to beta-4 refs.

## 2026-06-21

Documentation updates for the beta-3 release candidate:

- Added the `Beta 3` docset with pinned candidate refs for Platform, Manifest, Notary, Relay,
  Lab, registryctl, Crosswalk, and Atlas as a Lab input.
- Re-pinned repo-doc imports, source links, and registryctl installer paths away from mutable
  `main` URLs.
- Added OpenCRVS and FHIR tutorial coverage for beta-3.

## 2026-06-20

Documentation updates published:

- A scannable homepage section index to orient new visitors.
- Dark mode with a theme toggle.
- Outcome-first tutorials with prerequisites and numbered steps.
- New reference pages for the registryctl CLI, error and status codes, and environment variables.
- A native, searchable, theme-aware API reference.
- A per-page footer showing the last-reviewed date, an edit link, and a feedback control.

## 2026-06-13

Documentation set: the Latest docset published from the main branch, tracking main snapshots of
[Registry Relay](../products/registry-relay/), [Registry Notary](../products/registry-notary/),
and [Registry Manifest](../products/registry-manifest/).

## 2026-06-12

Documentation set: the Beta 2026-06-12 docset frozen and archived, covering the following
product versions.

| Product | Version |
| --- | --- |
| Registry Notary | v0.3.0 |
| Registry Relay | v0.2.0 |
| Registry Manifest | v0.2.0 |
| registryctl | v0.1.0 |
| Registry Platform | v0.2.1 |
| Crosswalk | crosswalk-core-v0.2.0 |