If your shmobster deployment runs an old voitta-yolt classifier, upgrade voitta-yolt first. As of v0.27.0, shmobster exits at startup if its configured classifier is below the floor, instead of logging a warning and serving anyway.
shmobster (v0.7.0 to v0.30.0)
The floor itself moved twice. v0.8.0 declared voitta-yolt 2.0.0 unsupported outright; v0.9.0 reversed that a release later, setting the real range at >= 2.0.1 (a deployment stuck on 1.6.0 now refuses to run too). There’s a separate security fix worth flagging on its own: v0.19.0 closes a hole where a curl carrying a POST body could run with no approval card at all, if the box’s classifier predated voitta-yolt 2.0.0 — if that’s your box, grab that release first.
Past the gate, the window adds real capability: the agent can flag its own hard-won debugging sessions as skill candidates (v0.7.0), answer Slack DMs (v0.13.0), carry per-channel memory (v0.14.0), skip approval for in-scope git/gh work in channels marked unattended (v0.24.0), and call MCP tools per channel (v0.30.0). Most of what’s left is the approval gate getting sanded down — fewer cards for reads that only looked like writes, a typed approval and a button click no longer racing to opposite outcomes, and as of v0.29.0 a sandbox that refuses to let a channel write the deployment’s own checkout.
Full list: https://github.com/voitta-ai/shmobster/releases
voitta-yolt (v1.2.0 to v2.4.0)
v2.0.0 is the breaking release here — "the auto-mode realignment," cutting YOLT down to carry only what it refuses to delegate — and it’s the reason shmobster’s version-floor logic exists at all. The two releases right behind it are corrections to v2.0.0 itself: v2.0.1 restores a CLI path to deny, v2.0.2 fixes a doc claim about auto mode. v2.1.1 similarly walks back v2.1.0’s classifyAllShell to opt-in, default false. Separately, v2.3.1 strips employer and client names that had leaked into this public repo — check any fork or vendored copy predating that tag.
Releases: https://github.com/voitta-ai/voitta-yolt/releases
skillz (v1.79.0 to v1.159.0)
About eighty releases, nearly all single-skill additions to the catalog — Terraform forensics, Android ADB checks, Grafana alert preflights, and more in that vein. The few with teeth: codex-adversarial-pr-review grew into a real sweep tool across this window (cross-host queues, wildcard authors, multi-hour runs), parallel-agent-session-collisions got a state-dir fix for an orphaned predecessor process, and the secrets hook had three separate false-positive fixes (base64url’s underscore, key filenames read as keys, env-var references read as credentials). Nothing breaking; if you consume skillz for the catalog, diff bundle versions and move on.
Releases: https://github.com/voitta-ai/skillz/releases
voitta-compute (v0.1.237 to v0.1.251)
Two new providers: a Requesty router, and in v0.1.251, Codex via a ChatGPT subscription instead of API billing. v0.1.250 also stopped tracking the mkcert TLS pair in backend/certs — a local clone now needs to generate its own.
Releases: https://github.com/voitta-ai/voitta-compute/releases
voitta-rag (v0.1.1 to v0.1.4)
v0.1.4 changes a default worth knowing about: voitta-rag and its Qdrant backend now publish on loopback only. v0.1.2 and v0.1.3 are benchmark work — a ten-mode code-context harness, then a re-run after an index-prefix fix — useful if you’re judging retrieval quality, no action required.
Releases: https://github.com/voitta-ai/voitta-rag/releases
voitta-rag-enterprise (v0.1.1)
One release, one feature: linked folders. Point it at a host directory and it indexes in place, nothing copied into the container.
Release: https://github.com/voitta-ai/voitta-rag-enterprise/releases/tag/v0.1.1