Changelog
What changed, and when.
Dated entries in plain words. Security fixes are described by what they protect, not by how they could have been broken.
Every source now runs on the spine
- The source spine is on the real path: each fetch is observed, compiled into a provider-neutral contract and diffed there, before impact analysis.
- Nothing regressed on the way in. All 12 benchmark cases give the same findings and the same migration plans as before, across the OpenAI, Stripe, Twilio and Supabase specifications.
- It is a bridge, not a finished move. The earlier differ still owns type, parameter and payload changes for now.
A refusal is always on the record
- When a migration names a file it deliberately leaves alone, such as a generated client, it records the refusal and the reason. A summary can no longer read as complete while something was skipped.
- A change that only touches documentation, like a reworded description, is no longer reported as an impact on your code.
- The benchmark grew to 12 cases in 7 categories, with precision and recall reported per category, so a weak area cannot hide inside an average.
- The release gate caught the first of these. It stayed red until the fix landed, then passed all 9 phases again.
Any API, with no new code
- The source spine is built. An API Mendward has never seen compiles and diffs through exactly the same code as every built-in source.
- The diff engine cannot tell which company published a contract. That is enforced by its types, its signature, a scan of its own source and a check at runtime.
- Each source reports what Mendward can really do with it, as a level. A preset that claims more than its compiler supports is lowered, and told why.
Live GitHub mode, on the right installation
- Repository operations run under the exact GitHub installation that granted the repository. There is no fallback to another installation, a name match or a default.
- A suspended installation is refused before any request reaches GitHub.
- The GitHub test double now behaves exactly like GitHub where it used to be more lenient, and one contract suite runs against both.
A patched runtime and pinned dependencies
- The container that runs your checks moved to Node 22.23.3, which clears six published security advisories. A test fails the build if either pin falls below the patched floor.
- Every third-party GitHub Action in CI is pinned to a commit hash instead of a movable tag, and a test keeps it that way.
Large GitHub installations, counted correctly
- Repository lists now page through every result. An installation with 250 repositories shows 250.
- Test databases left behind by a crashed run are found and removed automatically, and only ones Mendward created.
The source spine, and a gate that cannot lie
- Architecture decided for a universal upstream source: any API, SDK, schema or release feed, compiled into one contract model.
- Repository authorization settled without asking GitHub for a fifth permission.
- The verification gate now tests itself before it runs, and refuses to start if its own pass and fail logic is wrong.
- First fully green gate: 9 of 9 phases, 2,657 unit, 543 integration and 20 browser tests.
Security hardening, measured
- Customer source and accidentally committed secrets are kept out of every model request, proven by 45 tests on the model boundary.
- A GitHub installation can belong to exactly one organization.
- Production refuses to run on an unpatched container runtime instead of warning and continuing.
- Sign-in throttling is durable and shared across every process.
- An admin cannot grant themselves owner. Only an owner can create, change or remove an owner.
- The database verifier inspects stored functions as well as tables, so one that ignores tenant boundaries fails the gate.
- Sandboxed checks start only approved container images, cannot reach arbitrary host paths, and leftover containers are swept on a timer.
Mendward starts watching on its own
- The provider monitor polls upstream sources on a schedule. The product is no longer reactive.
- Snapshot retention is bounded, and the retention sweep runs on a timer.
- A renamed field read through destructuring is now detected. It used to be missed, and the benchmark says so.
- A forged sign-out request is refused without ending your session.
- Expired and idle sessions are cleaned up on a schedule.
Fail-closed CI
- Continuous integration exists, and a meta-test proves it fails when any phase fails.
- Every integration worker gets its own migrated database, so the suite runs concurrently.
- Outbound fetches now cover the whole IPv6 address space, a port allowlist and per-hop redirect checks.
- Sign-in takes the same time whether or not an address has an account, and a test measures it.
A benchmark that refuses to flatter
- A crash in the patch builder is an error, not a pass.
- Confidence is measured in both directions, and every cost figure names its denominator.
The first vertical slice
- Upstream change to verified pull request, end to end: ingest, detect, analyze, migrate, verify, open.
- Tenant isolation with row-level security enabled and forced on every tenant table.
- A GitHub App with four permissions. Installation tokens are minted on demand and never stored.
See it run on your own repository.
Mendward is in private beta for teams that integrate with third-party APIs from TypeScript on GitHub.