Skip to main content

14 releasesauto-rendered from CHANGELOG.md

Changelog

All notable changes to the portfolio. Format loosely follows Keep a Changelog; the project itself is a Next.js site, not a library, so versions are semantic over feature batches rather than over public-API breaks.

[0.8.1] - 2026-10-03

Fixed

  • agent-audit-kit numbers - the rule count now comes from the latest release's rules.json bundle and the version from its tag, so the badge, /oss/agent-audit-kit, the home page and the resume show the current release instead of a count frozen in old release notes. The badge label says it is the total rule count, not only the OWASP MCP rules.
  • agent-audit-kit response time - removed the fixed CVE-to-rule turnaround promise everywhere. The project retired it; what it has is a public CVE-to-rule ledger with measured latency, now linked from its page.
  • Licenses - agent-airlock and agent-audit-kit are Apache-2.0, not MIT.
  • agent-airlock - described the way its own repo does: a type-checker and contract layer for AI agent tool calls, deny-by-default, in-process. Its version, test count and coverage are synced from the README test badge at the latest release tag instead of being typed by hand.
  • Provael - the measured result now quotes the current headline from provael.com, with its benign control, interval and the "simulation only" caveat. The Embodied AI Security Top 10 is described as independent, not OWASP-style.
  • MannSetu - copy matches MannSetu's own wording: Hindi and English, CBT-based exercises, working toward DPDP Act alignment, hosted on AWS in the US with a move to India planned, live with early users. Removed a superlative, a therapy tag and an unpublished user count.
  • Cost router - /principles no longer gives a cost-cut percentage.
  • verdict is now proofloop - the repo was renamed on GitHub; cards, links, /uses, /now and the llms files follow.
  • The Production Agent - /book and the chapter pages say what is true today: chapters 1 and 2 are free drafts on this site, 3 to 5 are outlined, and nothing is on Substack or for sale yet. The bundle button is gone.
  • Hugging Face link - the JSON-LD and the chat knowledge base now point at huggingface.co/Sattyam.
  • AGENTS.md - the capability-lease template link pointed at a file that does not exist; it now points at the essay's wire format and the /api/quote JSON Schema.
  • Sitemap - the five book chapters and disclosure #001 are listed.
  • agent-audit-kit page - the rule catalogue lists the project's 14 real rule categories and shows OWASP Agentic (ASI01-ASI10) and MCP (MCP01-MCP10) coverage under OWASP's own ids, with links to the generated coverage tables. Removed rule families and features it doesn't have (numbered, compliance and capability-lease rule ids, allow-list drift, audit-trail-gap detection) and the "interoperates with" claim for Microsoft's Agent Governance Toolkit, which is complementary, not integrated. The compliance chips list all 14 frameworks, and the Marketplace link goes to the actual listing. The /projects card drops an internal note about a NIST profile mapping that doesn't exist and a third-party comparison the project's docs don't make.
  • Disclosure #001 - the detecting rule is AAK-STDIO-001 (first shipped in v0.3.2, mapped to ASI02 and MCP01), not AAK-MCP-001, which flags remote MCP servers without authentication. The page now describes what the rule really checks and carries a dated correction. Its affected list now matches NVD's record for CVE-2026-30623 (LiteLLM, fixed in 1.83.7-stable) instead of five frameworks the record doesn't name, with NVD and LiteLLM's advisory added as references. Book chapter 2 and /start say the same.
  • /now - no longer promises a 15-minute refresh or a live feed. On AWS Amplify the page and /now.json only update when the site deploys, so that is what they say now, and the footer shows when the page was last updated. Same fix in AGENTS.md, the llms files and the chat knowledge base.
  • /uses - it said "Updates daily", but it's hand-edited static content dated 2026-05-03. It now says it's updated by hand when the stack changes.
  • Capability Lease - it stays the pattern and the essay. The essay, the resume and the chat knowledge base no longer claim an agent-audit-kit rule family for it or a measured latency; agent-airlock is where leases are enforced. The essay carries a dated correction.
  • Accessibility - the rule-category list on /oss/agent-audit-kit and the book's chapter list keep their list semantics in Safari and VoiceOver, star and fork counts on /projects are read as "stars" and "forks" instead of bare numbers, the agent-audit-kit "Where it fits" links get the 44px touch size and the Marketplace link names the tool for screen readers, and the agent-airlock link on the Capability Lease essay shows an external-link icon instead of the internal-link arrow.

Removed

  • content/products.yml. Nothing read it, and it still carried retired numbers.

Added

  • scripts/check-claims.mjs fails npm test, and a new "Content truth" CI workflow, when any of these retired claims comes back.
  • /llms-full.txt has a "Current Release Numbers" section generated from the synced GitHub data.

[0.8.0] - 2026-09-28

Changed

  • AI chat - answers now come from the server (/api/chat) instead of your browser. Jev, TypeSafe AI's decision model, picks the knowledge-base entries that answer the question, and Claude Haiku writes a short reply from only those entries, both through OpenRouter. It can combine facts and answer in plain sentences instead of pasting one entry. Off-topic questions get a polite redirect, and instructions hidden in a question are ignored. If Claude Haiku fails, Gemini Flash-Lite writes the reply, and if that fails too, you get the picked entry itself. Each question stands alone. In a 21-question bake-off, Jev picked the right entry 20 times; the old in-browser matcher managed 16.
  • Chat panel - it's ready as soon as it opens, with no model to download. A short note says replies are written by AI and can be wrong, and that questions and answers are logged. Rate limits, outages and timeouts each say what happened and how long to wait, and a question that fails goes back in the message box. A question over 500 characters says how long it is instead of being cut off. The contact email in a reply is a link.
  • Chat for screen readers - you hear "Working on your answer", one "Still working" after 8 seconds, then the reply once. A reply that arrives while the panel is closed is read out when you reopen it. The typing dots stop after four bounces.
  • Accessibility statement - the chat limitation now says it needs JavaScript, sends your question to an AI service, and can be wrong.

Removed

  • The in-browser chat model (Transformers.js running MiniLM in a Web Worker), public/knowledge-index.json (1.36 MB), the embeddings build step and the @xenova/transformers dependency.

Security

  • The CSP no longer allows 'wasm-unsafe-eval', blob: workers or the Hugging Face and jsDelivr hosts.
  • /api/chat refuses cross-origin browser requests and takes JSON only (8 KB bodies, 500-character questions). Each visitor gets 6 questions a minute and 30 a day, and each server instance 100 an hour; a request refused by one limit doesn't use up another, and a question that gets no answer doesn't count toward the day. The OpenRouter key is server-only, and without it the route answers 503. Each request is logged as one line with the question, the reply and a salted client tag, never the IP address.

Added

  • npm run eval-chat runs 23 real questions through the pipeline and fails on invented links, markdown, versioned model names, salary or client-name leaks and obeyed injections (about $0.05 a run). With --url it smoke-tests a running build.
  • npm test covers the chat pipeline with 66 specs, and the Substack guard now scans data/.

[0.7.3] - 2026-09-27

Changed

  • Touch targets - on phones and tablets, buttons and links that stand on their own are now at least 44px, the size DESIGN.md asks for. The footer's quick links become two columns of full-size rows, and small text links, icons and the resume's contact links get taller tap areas. Desktop is pixel-identical (checked on every page at 1280, 1024 and 768px), and the resume PDF is unchanged.

Fixed

  • Focus under the chat button - at 320px, tabbing to a footer link could leave it hidden under the chat button. Focused content now scrolls clear of it.

Added

  • npm run check-targets measures tap targets on a running build, across every sitemap page and the pages they link to: 44px on touch, WCAG 2.5.8 spacing on desktop, and no overlapping targets. AccessLint has no target-size rule, so this covers the gap.

[0.7.2] - 2026-09-27

Fixed

  • Chat widget - it's now a proper dialog. Opening it moves focus into the question box, and closing it moves focus back to the chat button. Escape closes it from anywhere on the page, and sending a question or pressing Retry no longer drops focus to the page. Asking a question no longer scrolls the page behind the chat, and at 400% zoom the input and Close button stay on screen.
  • Chat for screen readers - each reply is read out once, as soon as it's chosen, and every message says who wrote it. The question box has a real label and stays editable while the model loads, and a send that can't go through yet says why. Replies finish streaming within about two seconds and appear at once with reduced motion.
  • Accessibility statement - now targets WCAG 2.2 AA and says plainly that the site partly meets it. It lists what was checked and what wasn't, and drops two claims that weren't true: embedded third-party content and "screen reader support".

Changed

  • With both the mobile menu and the chat open, one Escape closes just the menu.

[0.7.1] - 2026-09-26

Fixed

  • /changelog was blank - the whole page sat inside one scroll-reveal block that needed 20% of an 11,700px article on screen at once, which never happens. Blocks now reveal as soon as any part is visible, so tall sections also show at 400% zoom, and print, reduced motion and no-JS always show content. The changelog renderer now handles nested lists, wrapped list items, reference links and bold text.
  • Header nav - between 768 and 983px the nine links pushed every page sideways. The desktop nav now starts at 1024px. The mobile menu closes on Escape (focus goes back to the button), on route change, on an outside click and on resize, and it gained the Consult link.
  • Accessibility (WCAG 2.2 AA) - a production sweep found about 60 issues on 12 pages; all 24 pages now audit clean. Text links are always underlined, link names start with their visible label, card grids use one real link instead of a label that hid the card text, focus rings survive Windows High Contrast, focused items no longer hide under the sticky header, the skip link sits above the header, and low-contrast text on /resume, /book, /building and the disclosure badges is fixed.
  • llms-full.txt - 25 of 26 section lookups pointed at chunk ids that no longer existed, so Experience was empty and open source never appeared. Section orders now live in one module shared with the Copy-to-LLM button, and a test fails if an id goes stale. Both also linked to sattyamjain.in (single j), which doesn't resolve.
  • Chatbot - the loading indicator sat near 0%, and questions like "what products has he built?" or "where does he work?" got unrelated answers. Three direct-answer entries fix those. Loading progress, readiness and load failures are announced to screen readers, and Retry announces again.
  • Narrow screens - at 320px, content on the home page, /building, /book and /uses was up to 15px wider than the screen and silently cut off. Grid columns can now shrink and long button labels wrap, so nothing is clipped at 320px, including with enlarged text spacing.
  • Broken links - OWASP Agentic Top 10, OWASP MCP Top 10, Cisco and Devin references now point at live pages. The link checker skips code placeholders and example domains, retries with a browser-style GET, and handles oversized response headers.

Changed

  • public/AGENTS.md documents every /api/health field and the /api/quote v0.2 fields.
  • Brand icons (GitHub, LinkedIn, X) no longer use lucide's deprecated exports.
  • scripts/check-a11y.mjs guards the fixed patterns in npm test, and lint is clean with no warnings.

Security

  • Dev-dependency audit is clean: scoped overrides give @xenova/transformers protobufjs 7.6.6 and sharp 0.35.4 (1 critical and 4 high before). Chatbot embeddings are bit-for-bit unchanged.

[0.7.0] - 2026-09-26

Added - 255 (get255.com)

  • 255 - a just-for-fun writing experiment on Jev, TypeSafe AI's decision model, via OpenRouter. Drop in any text, see 255 AI impressions at once, change one sentence and watch what moves. Featured in /building (now five live products) and /projects, on the résumé and /about, in the chatbot and in the llms files. I wanted 255.ai, but it was listed at about ₹2.45 crore, so it lives at get255.com.

Security

  • Next.js 16.3.6 - closes two critical RCE advisories: Image Optimization with AVIF (GHSA-2xp9-vwfh-vxw4) and next/og ImageResponse (GHSA-vcvr-r3jv-pc5j). The CI floor in scripts/verify-next-cve.ts is now 16.3.6.
  • Resume PDF stack - puppeteer-core 25.11 with @sparticuz/chromium 153, which drops the vulnerable extract-zip. Needs Node 22.17+.
  • Unused dependency removed - @react-pdf/renderer, never imported.

Fixed

  • Model naming - the site names model families (Claude Opus / Sonnet / Haiku, OpenAI GPT, Google Gemini Pro) instead of version numbers, which go stale within weeks. lib/models.ts is the source of truth and the model guards enforce families only.
  • OWASP benchmark marked as a draft - the scores are working estimates, not audited results, so the page is noindex and out of the sitemap, /start, the llms files and the chatbot until the audited version ships. Dead links are gone, and the ten families are labelled as the OWASP Top 10 for LLM Applications (2025).
  • /api/health on Amplify - reports the deployed commit again (amplify.yml writes it into .env.production). The post-deploy check now waits for the pushed commit, smoke-tests the resume PDF, and keeps one tracking issue instead of opening one per push.
  • IndexNow - pings the www host after a verified deploy; the apex host was rejecting the key.
  • llms.txt section name - "Open Source" is now "Open Source & Products", since it also lists live products that aren't open source (MannSetu, whycantwehaveanagentforthis, 255).
  • Accessibility - /projects button labels now start with their visible text ("View Project: ...", "View on GitHub: ..."), which clears six label-in-name findings. Long product domains on /building wrap inside their button instead of overflowing the card at narrow widths or under text-spacing overrides.

Removed

  • Unused components (LeadMagnetCTA, the old article/project/timeline cards, gradient-text, the quote demo, two posture badges, four unused shadcn primitives) and the orphaned content/now-physical-ai.yml.

[0.6.0] - 2026-07-24

Changed - "Agentic & GenAI" → "Building" products hub

  • Renamed section /agentic-genai → /building ("Building" in the nav), reframed from a case-study page into a live-products hub: four products I build and run (Provael, MannSetu, Why Can't We Have An Agent For This, Agentify) shown as cards with domain CTAs + status + ownership chips, Provael + MannSetu elevated under a "doubling down" banner, then open source and enterprise case-studies below. Permanent redirect from /agentic-genai; #mannsetu / #agentify anchors preserved.

Added - Provael (physical-AI security)

  • Provael integrated as a flagship product - featured in /building, /projects, /start, the chatbot KB (four provael-* entries plus a consolidated live-products entry), /uses (VLA simulation stack: LIBERO / robosuite / MuJoCo / LeRobot / uv), and /resume. All links point to the live product at provael.com + GitHub - no dedicated portfolio microsite, since provael.com already fills that role (/provael redirects to /building).
  • Live metrics - provael/provael wired into the product-metrics sync (stars / forks / latest release version self-update on build) and into the /now "Shipping right now" feed (cross-org commits).
  • Person JSON-LD - added "Embodied AI security" + "Vision-Language-Action (VLA) policies" to knowsAbout; Provael named in the Person description.

[0.5.0] - 2026-04-30

Fixed - model-posture truth

  • P0 / Task 1 - scripts/check-models.mjs regex extended to flag bare Gemini 3.1 Pro / gemini-3.1-pro (superseded by Gemini 3 Pro preview, blog.google 2026-04-22) plus the retired o1-mini, o1-preview, o3-mini, o3-pro, o4-mini prefixes.
  • P0 / Task 2 - scripts/check-projects.mjs re-run: 6 shipping products green, VAJRA now-building, PyVerseAI absent.
  • P0 / Task 3 - New scripts/check-registry.mjs. For every endpoint declared in /agents-registry.json, verifies a corresponding Next.js route file exists. Wired into npm test.
  • P1 / Task 4 - /llms-full.txt model-posture line refreshed: date stamp 2026-04-29 → 2026-04-30; gemini-3.1-pro → gemini-3-pro-preview; new audio: gemini-3.1-flash-tts (eval-only) sub-line; new watch-list: deepseek-v4-pro, mistral-medium-3.5 (not in production routing) footnote.
  • P1 / Task 5 - /writing 7-day freshness re-audit. The 2026-04-27 32-Day Window Medium piece remains index 0 (still ≤ 7 days) - no newer Medium / Substack entry has landed.

Added - new public surfaces

  • F1 - /identity-posture page + /identity-posture.json machine twin. Three-card declaration of the agent-identity stack: Okta NHI (GA 2026-04-30), W3C DID + Verifiable Credential, capability-lease envelope. Each card cites its primary source. Linked from the footer + the Okta-NHI section on /agentic-genai.
  • F2 - /api/quote/schema.json v0.2. Adds optional okta_nhi_token (Okta for AI Agents GA, 2026-04-30) and bedrock_invocation_arn (AWS Bedrock Managed Agents preview, 2026-04-28). Both log-only; not yet cryptographically verified. version + lastModified keys added to the schema body. Handler in app/api/quote/route.ts accepts and echoes the new fields and raises the rate limit from 30 → 60 / hr / IP. New tests/quote-schema.spec.ts.
  • F3 - /uses adds an "Agent identity (3-layer)" section (Okta NHI · DID · capability lease) and an AWS Bedrock Managed Agents row in Infrastructure. Updated: stamp moved to 2026-04-30.
  • F4 - <MarketSignalCard /> reusable component (requires a primarySourceUrl prop) + content/market-signals-2026-04-30.ts with 8 ≤ 7-day signals + new section on /agentic-genai. Auto-prune via scripts/check-market-signals.mjs (stale-after 14 days unless pinned).

Added - context cards on /agentic-genai

  • P1 / Task 6 - Vendor-lock-in posture aside citing the Microsoft-OpenAI partnership restructure (blogs.microsoft.com, 2026-04-27).
  • P1 / Task 7 - Okta-for-AI-Agents GA section (Okta Showcase 2026, 2026-04-30) linking to /identity-posture + /identity-posture.json.
  • P2 / Task 9 - Anthropic Claude for Creative Work (9 first-party MCP connectors, 2026-04-28) advisory line appended to the existing CVE-2026-30623 MCP-STDIO posture section.

Added - context lines on /projects

  • P2 / Task 8 - agent-airlock card now ships an Interop bullet citing AWS Bedrock Managed Agents (Codex / GPT-5.5 limited preview, 2026-04-28). The interop data field is now actually rendered (was defined but unused).
  • P2 / Task 10 - agent-audit-kit card description cites OpenObserve Observability 3.0 + autonomous AI-SRE (2026-04-29) as a category-comparable runtime layer.

Changed - A2A discovery + truthful posture line

  • P2 / Task 11 - <link rel="alternate" type="application/json" href="/agents-registry.json"> added to root layout so any A2A crawler discovers the manifest from any route.
  • /agents-registry.json request_schema_version: "0.2", rate_limit.requests: 60, last_updated: 2026-04-30. New /identity-posture.json endpoint added.
  • lib/models.ts LATEST_GOOGLE gemini-3-1-pro → gemini-3-pro-preview. New LATEST_GOOGLE_TTS and WATCH_LIST_MODELS exports.
  • app/layout.tsx keywords updated Gemini 3.1 Pro → Gemini 3 Pro.

Verification

  • npm test: 61/61 + 5 check scripts (projects, substack-canonical, models, registry, market-signals) all green.
  • npx tsc --noEmit: clean.
  • npx next build --webpack: clean. New routes ship: /identity-posture static (1d), /identity-posture.json static (1d), /api/quote/schema.json v0.2 static (1d).
  • Local production smoke test confirmed all surfaces.
  • Local Lighthouse desktop: Perf 100 / A11y 100 / BP 96 / SEO 100 (no regression vs. 0.4.0).

Sources

  • Microsoft, The next phase of the Microsoft-OpenAI partnership (2026-04-27): https://blogs.microsoft.com/blog/2026/04/27/the-next-phase-of-the-microsoft-openai-partnership/
  • AWS, Bedrock OpenAI Models (Codex) Managed Agents (2026-04-28): https://aws.amazon.com/about-aws/whats-new/2026/04/bedrock-openai-models-codex-managed-agents/
  • Anthropic, Claude for Creative Work (2026-04-28): https://www.anthropic.com/news/claude-for-creative-work
  • Okta, Showcase 2026 - Okta for AI Agents GA (2026-04-30): https://www.okta.com/newsroom/press-releases/showcase-2026/
  • DeepSeek V4-Pro / V4-Flash (2026-04-24): https://api-docs.deepseek.com/news/news260424
  • Mistral Medium 3.5 (2026-04-29): https://releasebot.io/updates/mistral
  • OpenObserve Observability 3.0 + AI SRE (2026-04-29): https://www.morningstar.com/news/business-wire/20260429034926/openobserve-introduces-ai-native-observability-platform-with-autonomous-ai-sre-agent-to-unify-infrastructure-application-and-llm-monitoring
  • Google, Gemini 3 Pro preview (2026-04-22): https://blog.google/products/gemini/

[0.4.0] - 2026-04-29

Fixed - truth + canonical-URL hygiene

  • Task 1 - Substack canonical-URL sweep + new scripts/check-substack-canonical.mjs CI gate. Legacy sattyamjjain.substack.com host blocked from resurfacing in any app/, public/, content/, components/, or lib/ file. The newsletter canonical is https://theproductionagent.substack.com/.
  • Task 2 - Frontier-model regression CI gate (scripts/check-models.mjs). Bans Opus 4.6 / Sonnet 5 / Sonnet 4.7 / GPT-4o / bare GPT-5 / Claude 3.x / Haiku 3.x / Gemini 2.x outside the documented fallback context. Caught two real regressions on first run: bare "GPT-5" in app/layout.tsx keywords (now upgraded to GPT-5.5 / 5.5 Pro / Opus 4.7 / Sonnet 4.6 / Haiku 4.5 / Gemini 3.1 Pro), and an "Opus 4.6" doc-comment in lib/models.ts.
  • Task 3 - Re-ran scripts/check-projects.mjs: 6 shipping products green, VAJRA now-building, PyVerseAI absent.
  • Task 4 - /llms-full.txt model-posture date roll-forward 2026-04-28 → 2026-04-29. Body line unchanged (no new vendor releases).
  • Task 8 - X handle case canonicalised to lowercase x.com/sattyamjjain across 11 surfaces (AGENTS.md ×2, /resume, /about, structured-data, profile.ts, footer, article-schema, portfolio-data, json-ld test).

Added - net-new agent-readable surfaces

  • F1 / Task 6 - /api/quote/schema.json - public JSON Schema (draft 2020-12) for the signed-capability-lease envelope. Buyer-agents validate locally before POSTing. References Anthropic Project Deal + Cisco Agentic Workforce Identity.
  • F2 - /agents-registry.json - public A2A-protocol manifest. Declares all outward-facing agent endpoints (/api/quote, /api/health, /api/badges/agent-audit-kit, /now.json, /now-physical-ai.json, /llms.txt, /llms-full.txt, /AGENTS.md) with per-endpoint method, rate limit, and capability-lease requirements.
  • F3 - /uses Physical AI subsection bumped to fully-pinned: JetPack 6.3 (L4T r36.4.x), ROS 2 Jazzy 0.13, NanoOWL @ 0.4.2, GR00T N1.7 (commit-pinned), Cosmos 3 sim assets v3.1.
  • F4 - <CapabilityLeaseBadge /> reusable component. Mounted on /agentic-genai agent-commerce section; ready for additional mounts on /projects agent-airlock card.
  • F5 - /changelog route - auto-renders CHANGELOG.md with per-section anchored URLs. Added to sitemap + sync-route-dates.
  • Task 7 - NIST AI RMF Profile-for-Agents v1.0 framing on the agent-audit-kit project card with (mapping in progress) honesty caveat - verify GA on nist.gov before flipping to "mapped".

LLM discovery

  • /llms.txt Optional section gains /agents-registry.json, /api/quote/schema.json, and /changelog bullets.
  • Sitemap + sync-route-dates extended to include /changelog.

Deferred (per Open Issues)

  • Per-route dynamic OG via next/og - VAJRA / talks-2026 / changelog still on static OG.
  • Wikidata Q-item still queued (sameAs[] gap).
  • /api/atlas-pings remains console-log stub; F2 quote widget POSTs there for now.
  • Stanford AI Index 89% - still cited from secondary coverage; verify against the official 2026 AI Index PDF before next reuse.

[0.3.0] - 2026-04-26

Fixed - truth corrections

  • Task CC - Replaced Claude Sonnet 5 → Claude Sonnet 4.6 site-wide. Anthropic's GA Sonnet is 4.6 (platform.claude.com); yesterday's Task V landed Sonnet 5 copy from a leak/speculation source. lib/models.ts is now authoritative; tests/model-strings.spec.ts fails the build if Sonnet 5 ever creeps back. Updated: lib/models.ts, lib/schema/profile.ts, scripts/generate-llms-txt.ts, components/faq-schema.tsx, components/structured-data.tsx, app/page.tsx, app/projects/page.tsx, app/agentic-genai/page.tsx, app/agentic-genai/layout.tsx, data/portfolio-data.json.
  • Task DD - Re-purged PyVerseAI from /projects (regression of 2026-04-21 Task N). tests/projects-no-pyverseai.spec.ts blocks future regressions.
  • Task EE - /api/health route now declares export const dynamic = "force-dynamic" so VERCEL_GIT_COMMIT_SHA reads at request time (it is NOT injected into the build env). .github/workflows/post-deploy-health-assert.yml polls the live endpoint after every push to main and opens a health-wire-regression labelled issue if commit returns "local". (Vercel system env vars)
  • Task FF - Replaced the stale generic-tooling knowsAbout[] in components/structured-data.tsx (OpenAI GPT-4, Claude AI, Microservices Architecture, …) with the canonical 12-entry topic-authority array (AI agents, Multi-agent systems, Model Context Protocol (MCP), LLM orchestration, Agentic AI security, OWASP Agentic Top-10, Production GenAI platforms, AgentOps, Capability leases, LLM red-teaming, Python, TypeScript). lib/schema/profile.ts trimmed to match. tests/knowsabout-content.spec.ts enforces drift parity between the two schemas.

Added - market signals

  • Task GG - New "Where this work fits the 2026 frontier-security stack" section on /agentic-genai with three Apr-2026 cards: Anthropic Mythos Preview / Project Glasswing (anthropic.com/glasswing), LangChain-ChatChat 0.3.1 RCE via MCP STDIO (thehackerwire.com), Claude Code v2.1.117 sandbox hardening (code.claude.com/docs/en/changelog). Posture aside added to /llms-full.txt model-posture blockquote noting Mythos is explicitly excluded from production posture. Gemini 3.1 Pro added as eval-only model in posture.
  • Task HH (deferred) - Today's OX-MCP-STDIO Medium piece is not yet in the ingested feed (RSS hasn't propagated). Will land on the next ingest run; no manual entry needed.

Added - net-new product features

  • Feature Q1 - /now page (Edge runtime, 15-min revalidate). Pulls last 14 days of GitHub PushEvents across the 6 production repos (agent-airlock, agent-audit-kit, verdict, mnemo, ferrumdeck, aboutme), last 30 days of writing from content/external-writing.generated.ts, and calendar links. JSON twin at /now.json. Surfaced in /llms.txt ## Optional. (nownownow.com)
  • Feature Q2 - /uses page (the uses.tech convention). Daily revalidate. Sections: Editor + agent loop, Models in production rotation, Runtime, Infrastructure, Security tooling, Observability, Hardware. Each line cites primary source. Surfaced in /llms.txt.
  • Feature Q3 - /api/badges/agent-audit-kit Shields.io-format JSON endpoint. Pulls live rule count + version from content/products.generated.ts (PRODUCTS.agent_audit_kit). Embeddable in README / Substack / Medium via https://shields.io/endpoint?url=https%3A%2F%2Fwww.sattyamjjain.in%2Fapi%2Fbadges%2Fagent-audit-kit.

[0.2.0] - 2026-04-25

Added - frontier-model truth + topical authority + wrap-up

  • lib/models.ts - single source of truth for frontier-model identifiers and the FRONTIER_POSTURE_LINE string. Bumps land here first; downstream consumers import. (OpenAI: GPT-5.5, Anthropic: models overview)
  • Person.knowsAbout[] - agent-security topical signals added (AI agents, Agentic AI security, OWASP Agentic Top-10, Production GenAI platforms) and frontier model bumps (Sonnet 5, GPT-5.5). (knowsAbout authority signal)
  • Per-route ProfilePage.dateModified - scripts/sync-route-dates.ts emits content/route-dates.generated.ts from git log -1 --format=%cI per route; ProfilePageSchema is now a client component reading usePathname(). Each canonical route emits its own @id and a real freshness timestamp. (schema.org/dateModified)
  • Wikidata sameAs (staged) - WIKIDATA_QID: string | null constant + buildSameAs() helper in lib/schema/profile.ts; auto-appends https://www.wikidata.org/wiki/<QID> to Person.sameAs[] when set. Submission steps + 4 citation URLs in docs/wikidata-evidence.md. (Wikidata as KG trigger)
  • /api/health - returns {commit (7-char), branch, deployedAt} from Vercel system env vars (VERCEL_GIT_COMMIT_SHA, VERCEL_GIT_COMMIT_REF, VERCEL_DEPLOYMENT_CREATED_AT). Falls back to "local" when env is unset. (Vercel system env vars)
  • /feed.xml April-2026 stop-gap - 4 most recent Medium URLs prepended to the hardcoded articles array; mirrored in content/writing.yml as future-proof source of truth pending the auto-ingest cron rewrite.
  • Regression tests - tests/llms-full-truth.spec.ts (asserts the current frontier-model strings are present) and tests/json-ld-knowsabout.spec.ts (asserts knowsAbout[] shape + Wikidata wiring). Run via npm test (node:test, no new deps).

Changed - model-name sweep

  • Replaced Claude Sonnet 4.6 → Claude Sonnet 5 and GPT-5.2 / GPT-5/GPT-5.2 → GPT-5.5 (and GPT-5.5 / GPT-5.5 Pro where the paired form was used) across:
    • scripts/generate-llms-txt.ts (model-posture blockquote in /llms-full.txt)
    • data/portfolio-data.json (RAG chatbot knowledge base - 5 chunks)
    • components/faq-schema.tsx (FAQ JSON-LD answer)
    • app/page.tsx (home featured-card tags + skills array)
    • app/projects/page.tsx (Agentify card tags)
    • app/agentic-genai/page.tsx (case-study tech-stack chips + cascading-router caption)
    • app/agentic-genai/layout.tsx (page metadata description)

Skipped (per direction)

  • Atlas-traffic detector / /api/atlas-pings - deferred until Vercel KV is provisioned. In-memory storage would lose pings on cold start; not useful telemetry.

[0.1.5] - 2026-04-24

Added - ProfilePage schema + Next.js CVE pin + LLM discovery + capability-lease tagline

  • lib/schema/profile.ts + components/profile-page-schema.tsx - Google-compliant ProfilePage JSON-LD with @id anchored at /about#person. Per-spec at developers.google.com/search/docs/appearance/structured-data/profile-page.
  • Next.js 16.2.4 pin - closes CVE-2026-23869 (RSC DoS) and CVE-2026-29057 (http-proxy rewrite smuggling). New scripts/verify-next-cve.ts + .github/workflows/security.yml gate the patch floor in CI.
  • LLM discovery <link> tags - <link rel="llms">, <link rel="alternate" type="text/llms-full+txt">, and a second sitemap link for /llms-sitemap.xml in root <head>. /accessibility added to /llms.txt Optional section.
  • Capability-lease tagline - appended "builds signed capability leases and agent-egress benches" to the / hero subtitle and rewrote the /agentic-genai lede to lead with the signed-capability-lease primitive framing.
  • /og - noindex preview gallery of the 10 canonical OG cards.
  • /api/health - initial roster endpoint + nightly inbound-health workflow that opens an inbound-404-labelled issue on any non-2xx/3xx.

Changed

  • /llms-full.txt header gained a model-posture blockquote noting Anthropic's 2026-04-23 engineering postmortem and Opus 4.7 Auto Memory's opt-in / default-off status.

[0.1.4] - 2026-04-21

Added - honesty bugs + per-route OG + feed ingest + strict llms.txt

  • Per-route dynamic OG images (/, /about, /agentic-genai, /projects, /experience, /resume, /writing) via next/og.
  • lib/og-card.tsx shared ImageResponse renderer.
  • scripts/ingest-feeds.ts - Medium + Substack RSS into content/external-writing.generated.ts (no runtime deps).
  • scripts/sync-product-metrics.ts - live GitHub API → content/products.generated.ts.
  • scripts/check-links.ts - outbound URL HEAD/GET probe.
  • app/llms-sitemap.xml/route.ts - companion sitemap with lastmod derived from git log -1 per route.
  • /writing "Latest" row pulling 6 most recent items from the ingested feed.
  • /about photo + testimonials + Talks & Media sections.
  • /resume last-updated stamp + Talks/CFP sidebar.

Changed

  • /projects agent-audit-kit card now driven by live GitHub release data (rule count, version, stars). Removed PyVerseAI from the featured grid.
  • /llms.txt rewritten to strict llmstxt.org v1 (H1 + blockquote + Markdown link H2s with real canonical URLs).
  • app/sitemap.ts lastModified now per-route via git log.

[0.1.3] - 2026-04-20

  • Trust-bar reframe: "Trusted by" → "Where I've built".
  • Homepage testimonials expanded to 5 LinkedIn recommendations.
  • Comprehensive digital-presence audit fixes.