Skip to content

Release notes ​

Every vpay release up to v0.4.1, the one these pages are verified against. The text below is vpay's own CHANGELOG.md at that tag, written by release-please from commit subjects. It is copied here at build time and never edited.

These docs move with the releases

When vpay tags a release newer than v0.4.1, the parity check opens a draft pull request listing every page whose sources changed. See how these docs stay current.

At a glance ​

timeline
  title vpay releases
  2026-09-17 : v0.1.1
  2026-09-18 : v0.2.0
  2026-09-19 : v0.2.1
  2026-09-20 : v0.2.2 : v0.3.0 : v0.3.1 : v0.4.0
  2026-09-21 : v0.4.1

Changelog entries per release — a measure of how much each one carried, not of how much it matters:

xychart-beta
  title "Changelog entries per release"
  x-axis ["v0.1.1", "v0.2.0", "v0.2.1", "v0.2.2", "v0.3.0", "v0.3.1", "v0.4.0", "v0.4.1"]
  y-axis "entries"
  bar [2, 12, 1, 8, 2, 8, 1, 1]
ReleaseDateChoresFeaturesBug FixesDocumentationContinuous IntegrationTests
v0.4.12026-09-211
v0.4.02026-09-201
v0.3.12026-09-2026
v0.3.02026-09-2011
v0.2.22026-09-20413
v0.2.12026-09-191
v0.2.02026-09-181551
v0.1.12026-09-1711

The changelog ​

0.4.1 (2026-09-21) ​

Chores ​

  • ci: bump the vaam-apps/.github workflow pin to pick up the lint fix (#235) (7134ecb)

0.4.0 (2026-09-20) ​

Features ​

  • xtask: verify-doc-counts, so a number in a document cannot drift silently (#233) (67c90ea)

0.3.1 (2026-09-20) ​

Bug Fixes ​

  • release: publish-chart signs, refuses a stale version, and can resume (#226) (8092c3d)
  • release: the chart guard can resume a release stranded between push and sign (8092c3d)

Documentation ​

  • charts/vpay:0.2.1 was deleted, so stop warning readers away from it (#229) (74123da)
  • flows: retire thirteen stale claims, most of them understating what exists (#231) (7b3ebf9)
  • retire ten stale claims, two of which would have cost an operator time (#230) (5ab9199)
  • status: retire ten stale claims, and record implementation state on two ADRs (#232) (a014463)
  • the chart publishes and signs — and AGENTS.md is prettier-clean again (8ad5050)
  • the chart publishes and signs, and AGENTS.md is prettier-clean again (#228) (8ad5050)

0.3.0 (2026-09-20) ​

Features ​

  • release: let release-please own the chart version too (#225) (f5492e5)

Bug Fixes ​

  • release: give the chart job the docker login cosign actually reads (#223) (5230136)

0.2.2 (2026-09-20) ​

Bug Fixes ​

  • ci: guard fromJSON so a no-commit release-please run does not fail (03e6bbf)
  • ci: pin every action in ci.yml to a commit SHA (DS-0002) (#221) (a761bc7)
  • ci: scan the default branch on push, not just pull_request (#220) (afc89b9)
  • erasure: redact the last payment error pair and webhook response excerpt on customer erasure (#211) (6cda795)

Documentation ​

  • the semver tag path is exercised, and publish-chart has been skipped once (#222) (bb092c1)

Continuous Integration ​

  • pnpm: move settings and overrides to pnpm-workspace.yaml, pin pnpm 11 (#217) (a8b5c0a)
  • release: publish by OIDC instead of a classic token (#215) (a8d1764)
  • release: publish the Helm chart to GHCR as an OCI artifact (#219) (35848b5)

0.2.1 (2026-09-19) ​

Continuous Integration ​

  • pin every action in release-please.yml to a commit SHA (#213) (848c5b4)

0.2.0 (2026-09-18) ​

Features ​

  • GDPR personal-data inventory and its drift gate (issue #144) (#187) (0799a8d)

Bug Fixes ​

  • checkout,sdks/flutter: a redirect rail's browser leg is a controlled surface (#200) (bd5c85d), closes #195
  • ci: a bare-string extra-files entry reserialised Chart.yaml — use type: generic (#204) (aeb9e24)
  • ci: master is still red on CHANGELOG.md and AGENTS.md, and the release gate has no tests (#206) (5af959b)
  • sdks/flutter: read a remembered number back into the field and checkbox (#197) (0bed092), closes #194
  • sdks/flutter: the native sheet offers the redirect back, instead of a false check your phone (#208) (84143e1)

Tests ​

  • macOS can run the sign-in suite, and two load flakes lose their race (#210) (acdcbfe)

Continuous Integration ​

  • adopt org-wide SAST, lint, Trivy and issue governance (#207) (5f540b2)
  • publish sdks/nodejs and sdks/stripe-js to npm on release (#209) (7063037)
  • re-pin org reusable workflows for the MD024 changelog fix (8659544)
  • re-pin org reusable workflows for the MD024 changelog fix (43b8cfb)
  • re-pin org reusable workflows to current .github main (#212) (369f2b2)

0.1.1 (2026-09-17) ​

Bug Fixes ​

  • ci: release-please uses client-id, not the deprecated app-id (#202) (a475a2d)

Continuous Integration ​

  • release-please proposes the version bump, and a gate for the pin that breaks the build (#201) (5b82cbd)

Verified against vpay v0.4.1 (2026-09-22). vpay is a scaffold — do not deploy it.