shmobster (v0.29.1 to v0.35.0)
The watchdog story is the one to read carefully. v0.31.0 added a second liveness check — catching a dead message_processor thread, not just a dead socket — but the refactor also rewrote the trigger from OR to AND: it was supposed to fire when either the session was unstable or a stable session went deaf, and instead fired only when both were true at once. The real failure mode is a half-open socket: stable session, no pong, recv blocked forever. Under the AND, that never tripped. From v0.31.0 through v0.34.0, an agent could sit deaf and alive for hours with the watchdog polling and doing nothing. v0.34.1 fixes the OR and adds diagnostics; if you’re running anything in that range, upgrade. v0.34.0 separately handles the case where the whole interpreter freezes and takes the watchdog thread down with it — a different failure, a different check. Less dramatically: v0.30.0 gives channels an optional mcp policy key so any MCP server’s tools can be allow-listed per channel (voitta-rag’s search is the first consumer), and v0.32.0/v0.33.0 stop papering over read-only and file-edit turns with needless approval cards. v0.35.0 adds always_skills, so a channel can force a skill into every turn instead of leaving it as a menu entry the model sometimes skips. Releases.
voitta-compute (v0.1.250 to v0.1.251)
Two new providers: Requesty router and Codex (the ChatGPT-subscription path), alongside a small hygiene fix that stopped tracking a local mkcert TLS pair in backend/certs. Latest release.
voitta-rag (v0.1.4 to v0.1.5)
Both releases are security fixes. v0.1.4 binds voitta-rag and Qdrant to loopback only — nothing listens on an external interface by default anymore. v0.1.5 closes three redaction gaps in session memory: sk-proj- keys, PREFIX_TOKEN= style secrets, and Bearer/JWT tokens were passing through unredacted before this. Latest release.
voitta-yolt (v2.4.1 to v2.6.0)
Hardening against credential leakage from agent writes: v2.5.0 treats key-material filenames as protected write targets, v2.6.0 redacts a credential wherever its own key name already identifies it. v2.4.1 was prep for the Claude directory submission. Latest release.
skillz (v1.152.0 to v1.176.0)
Twenty-five releases, almost all new skills or plugin point-fixes in the agent-skills knowledge base. Worth noting: the claude-code-cross-session-messaging plugin got patched three times in this window (1.2.0, 1.2.1, 1.2.2) — a reply arriving after /clear, then grepping the wrong name, then merging two conditions that needed to stay independent. v1.168.0 adds a pipeline that publishes a materialized bundle to a directory branch for the Claude plugin directory, which is the more durable change here. Everything else is one-off operational knowledge (macOS menubar behind the notch, Grafana alert-rule arming races, an MCP streamable-HTTP client with no SDK, terraform plan-JSON secrecy) — useful if you hit the specific gotcha, invisible otherwise. Releases.
voitta-mcp (crm-highlevel-v0.1.0)
First release of an MCP server for HighLevel CRM: runs under docker compose, crm_find_contact now returns a link to the CRM record, and a write tool (crm_update_opportunity_status) exists but is flag-gated off by default. Release.
mods (cw-chart-v0.1.0, image-mirror-v0.1.0)
New repo. Two mods shipped at v0.1.0 — cw-chart and image-mirror — under a release-on-merge setup that gates PRs on version bumps. No user-visible behavior to summarize yet beyond "it exists." Releases.