This reference page mirrors the root changelog in CHANGELOG.md so the book and repository stay aligned.

[Unreleased]

[0.3.230] - 2026-10-04

Changed

  • [Cloud] Audit logs no longer record email addresses, usernames or SAML NameIDs. Member, invitation, SSO login and password-reset events identify people by user id or invitation id; failed logins store a keyed hash of the attempted email instead of the address. (#1087)
  • [Cloud] Audit logs are now kept for 400 days and then deleted by a daily retention worker. The append-only trigger allows only this purge, and only for rows past the window; verify_chain treats the oldest surviving row as the chain start. (#1087)
  • [Cloud] Privacy Policy 2.2 and DPA 2.2 describe audit-log retention after account deletion. Terms 2.1 name Delaware as governing law and venue.
  • [DevX] The Kubernetes manifests (k8s/) and the Helm chart now give every MockForge replica its own recorder volume. Previously all replicas mounted one ReadWriteOnce claim holding the recorder’s SQLite database, so pods on other nodes could not start and pods on the same node shared one SQLite file. k8s/deployment.yaml + k8s/pvc.yaml are replaced by k8s/statefulset.yaml (a StatefulSet with a volumeClaimTemplates entry, one recorder-db-mockforge-N claim per pod), and the HPA now targets it. The Helm chart renders a StatefulSet (plus a <fullname>-headless Service) when persistence.enabled is true, the default, and a Deployment without a recorder volume when it is false. Upgrading an existing Helm release replaces its Deployment with a StatefulSet and creates per-pod claims (data-<fullname>-N); the old shared <fullname>-data claim is kept (annotated helm.sh/resource-policy: keep) but no longer mounted, so copy any recordings you need out of it, then delete it. The Kubernetes test workflow’s Chaos Engineering job, which never ran, now runs on manual dispatch and weekly.

Fixed

  • [Reality] bench-chunked sends a valid JSON body when the request’s Content-Type is JSON (application/json or any +json type, from --header or a targets-file headers entry). The body is the spec-generated request body plus a _padding string field, sized to exactly --total-size-bytes and streamed in the same chunks. Previously every body was X filler, so WAFs flagged each request as malformed JSON. Other content types still get filler. (#79)

  • [DevX] Registry audit email hashing compiles under strict unused-qualification lints in both PostgreSQL and SQLite builds. Hashing behavior is unchanged.

  • [Cloud] Flow creation sends the registry-required configuration across all five editors. Federation details have a labeled Back button; portal dialogs, placeholders and disabled controls use readable theme colors and wrapping action rows, and service route counters retain their spacing.

  • [Cloud] Authenticated portal workflows recover from deleted workspace selections and page errors; resilience and snapshot comparisons load, deletion dialogs work, fixture lists refresh after writes, and fitness authoring sends supported evaluator settings. Cookie reloads restore tokens before loading protected pages. Theme toggles, deployment slugs, actor labels and action accessibility are corrected. (#1144)

  • [DevX] cargo install --locked mockforge-cli no longer warns about yanked dependencies (chacha20 0.10.0 and spin 0.9.8/0.10.0 bumped to their patched releases).

  • [DevX] GDPR erase on the SQLite backend did nothing (delete_user_data_cascade returned 0). It now matches the Postgres store. (#1087)

[0.3.229] - 2026-10-01

Changed

  • [Cloud] Tenant isolation is now also enforced in the database for every org-scoped table (36 tables under Postgres row-level security, up from 5). Request-path queries run bound to the caller’s org; background workers, webhooks and platform-admin paths run on the owner role. Requires the owner role (DATABASE_URL) to have BYPASSRLS; the migration refuses to apply otherwise. Startup now logs which roles back each pool and flags a misconfigured one at ERROR. (#1087)
  • [Cloud] PUT /api/v1/organizations/{org_id}/quota is now platform-admin only. Org owners can no longer set their own quota overrides, because overrides are merged over plan limits. GET now requires membership in the org. (#1087)
  • [Cloud] Row-level security now also covers 38 tenant tables that have no org_id column of their own (workspace, hosted-mock and other child tables). Each is isolated through its parent’s org, and per-user tables are scoped with a new app.current_user_id setting. (#1087, #1120)
  • [Cloud] Requests without an organization header now resolve to an org the user belongs to even when they own none (SSO-provisioned members, or users who deleted their personal org). Previously every such request returned 404. (#1087, #1117)
  • [DevX] Kubernetes manifests and the Helm chart now meet the “restricted” Pod Security Standard (non-root uid 999, no privilege escalation, all capabilities dropped), and liveness/readiness probes use the HTTP port instead of the auth-protected admin port. (#1118)
  • [DevX] Dependency refresh: 33 patch and minor updates, including tokio 1.53.1 and hyper 1.11. (#1104)

Fixed

  • [Cloud] The registry API no longer occasionally drops a request mid-flight (clients saw a closed connection or 502). The request-logging middleware held a tracing span open across an await, which could panic once a request moved between worker threads.
  • [Cloud] Security: any authenticated user could read or overwrite any org’s quota overrides. (#1087)
  • [Cloud][AI] Security: POST /api/v1/organizations/{org_id}/mockai/generate-openapi-from-traffic did not check that the caller belongs to the org. (#1087)
  • [Cloud] Security: the GDPR data export included pending invitation payloads, which let a plain member redeem an invite meant for someone else. (#1087)
  • [Cloud] GET /api/v1/organizations/{org_id}/incidents/stats no longer returns 500 once the org has a resolved incident. (#1087)
  • [Cloud] Security: a workspace could aim a chaos campaign at another org’s hosted mock and inject faults into it. Campaign targets are now checked against the caller’s org at create, trigger and snapshot restore, and the internal chaos toggle requires the run that owns it. (#1124)
  • [Cloud] Security: adding a capture to a capture session did not check who owned the capture, so a replay could read another org’s captured request bodies. (#1124)
  • [Cloud] Capture sessions, clone models, monitored services, diff runs and fitness functions belonging to another org now return exactly the same “not found” response as missing ones. (#1087, #1128)
  • [Reality][AI] MockAI no longer stores a session for every write request that arrives without a session ID. Those sessions were never read again and every write waited on one shared lock, so throughput fell steadily under sustained load (about 2x faster writes, flat memory). Per-request fixture-matching logs are now at debug level instead of warning. (#1125)
  • [Cloud] Returning visitors no longer see “Something went wrong” after a cloud UI deploy: the app’s entry JS and CSS are content-hashed so browsers can’t keep a stale copy. (#1116)

[0.3.228] - 2026-09-30

Added

  • [Reality] The mock Kafka broker can filter messages so it counts or verifies them without keeping every payload in memory. (#992)

Fixed

  • [Cloud] Hosted mocks now require a per-deployment management token for writes to MockForge’s control routes (/__mockforge/*, /api/chaos, /api/recorder, and the other management APIs). Previously anyone who knew a hosted mock’s URL could change it. Reads and your mocked API are unaffected, and self-hosted servers don’t use a token. Owners can reveal the token on the Hosted Mocks page. (#1105)
  • [DevX] Windows release binaries build again (a Unix-only socket option in bench-qos broke every Windows build since 0.3.223). (#1101)

[0.3.227] - 2026-09-30

Added

  • [Reality] mockforge bench-chunked gains --rps N (per-target cap on request starts per second), --cps (new TCP/TLS connection per request), and campaign mode: --rounds N / --repeat-until <duration> re-run the whole pass into <output>/round_N/, with per-round stats in campaign.jsonl and round-summaries/, and --keep-rounds N rotating old round dirs, matching mockforge bench. (#79)
  • [Cloud] Redesigned app shell for the logged-in portal: new sidebar, top bar, search and menus, refreshed shared UI primitives, and a new dashboard; every page moved onto the new frame. (#1086)

Fixed

  • [Cloud] GDPR account erasure no longer fails for users who have audit-log rows. (#1093)
  • [Reality] bench-chunked --chunk-interval-ms now sends the first chunk immediately and waits only between chunks. Previously it waited before the first chunk and sent the last two back to back. (#79)

[0.3.226] - 2026-09-29

Added

  • [DevX] Response overrides now work in mockforge serve. Rules come from a new overrides: list in mockforge.yaml, MOCKFORGE_HTTP_OVERRIDES_GLOB files, and a new MOCKFORGE_HTTP_OVERRIDES JSON array. With --admin, GET/PUT /__mockforge/overrides reads and replaces the live rules without a restart; an invalid set returns 400 and keeps the previous rules. Rules gain name and enabled. (#1088)
  • [DevX] Admin UI Overrides page to toggle, reorder, edit, and save override rules for the running mock (self-hosted) or a hosted mock (cloud). (#1095)
  • [Cloud] Per-hosted-mock override rules: GET/PUT /api/v1/hosted-mocks/{id}/overrides stores rules on the deployment, passes them to new machines, and pushes them live to running ones over the private network. (#1094)

Fixed

  • [DevX] tag: override targets match the operation’s real OpenAPI tags, and when: conditions see request headers, query, and body. Invalid JSON pointers are rejected instead of silently patching the whole body, and regex targets work in rule sets loaded from config (including gRPC). (#1088)
  • [Cloud] Redeployed hosted mocks now start their admin server, so the resilience dashboard and override push can reach them. (#1094)
  • [Cloud] Plugin registry search no longer returns 500 for the default “popular” sort and the “security” sort. (#1082)
  • [DevX] The admin UI top-bar search suggests pages and navigates on Enter. (#1082)
  • [Cloud] Bump wasmtime and wasmtime-wasi to 36.0.16 for RUSTSEC-2026-0316 and RUSTSEC-2026-0314. (#1092)

[0.3.225] - 2026-09-27

Added

  • [Reality] mockforge bench-chunked --targets-file <file> sends real Transfer-Encoding: chunked traffic to every target in a multi-target file in parallel (--max-concurrency, default 10). It uses the same file format as bench --targets-file, including per-target auth/headers/spec. Per-target artifacts go to <output>/target_N/, with a roll-up in chunked-multi-target-summary.json. (#79)

[0.3.224] - 2026-09-24

Added

  • [Reality] Campaign mode now supports --no-k6-logs (skips k6-output.log and conformance debug sidecars; k6 output is drained instead of buffered) plus per-round aggregate artifacts: round_N/round_summary.json, round_N/all_targets.csv, durable campaign.jsonl, and round-summaries/ copies. New --keep-rounds N prunes old round directories during a campaign while preserving campaign-level stats, and k6 scripts are generated once per target and reused across rounds. (#79)

[0.3.223] - 2026-09-18

Added

  • [Reality] Multi-target --repeat-until <duration> and --rounds N cycle the full targets list so low concurrency can still stress every server over a longevity window without manual restarts. Pair with a short --duration (per-batch k6 lifetime). (#79)

[0.3.222] - 2026-09-16

Fixed

  • [Reality] Longevity / huge-spec k6 runs no longer emit a Trend+Rate pair per OpenAPI operation by default when ops >= 500 or duration >= 1h (--per-op-metrics / --no-per-op-metrics to force). --max-concurrency auto-caps to 3 for huge specs, and SIGKILL gets an OOM hint. (#79)

[0.3.221] - 2026-09-12

Fixed

  • [Contracts] OpenAPI 3.1 schema type arrays (["string", "null"]) are coerced to OAS 3.0 type + nullable so the spec loads. LLM-generated specs failed with invalid type: sequence, expected a string and never extracted operations. (#79)

[0.3.220] - 2026-09-12

Fixed

  • [Reality] traffic-breakdown.json no longer repeats unique / total / expected_requests next to unique_cases / projected_*. Those aliases were a one-release bridge and got read as k6 wire counts. unique_cases is still the YAML case count (not traffic on the wire). projected_per_second / projected_over_run stay the plan. (#79)

[0.3.219] - 2026-09-10

Fixed

  • [Reality] HTTPS + ALPN HTTP/2 was rejecting WAF Connection headers (http2: invalid Connection request header). The header stays on the wire (it is the hop-by-hop test); k6 is forced onto HTTP/1.1 via GODEBUG=http2client=0 when --wafbench-verbatim is set or any request has a Connection header. generate-only prints the same prefix for a manual k6 run. (#79)

  • [Reality] traffic-breakdown.json fields are the plan, not k6 counters: unique_cases (YAML case count), projected_per_second (unique_cases * rps), projected_over_run (unique_cases * rps * duration). unique / total / expected_requests stay as aliases for one release. expected_requests_unit is dropped. (#79)

Added

  • [Reality] Multi-target runs print estimated wall clock: ceil(targets / max-concurrency) * duration. --vus and --rps are per target, not shared. (#79)

[0.3.218] - 2026-09-07

Fixed

  • [Reality] Static k6 paths are JSON-encoded and concatenated onto BASE_URL, so WAF URIs containing \x (Werkzeug UNC /static/\\attacker.com\share\x) no longer land in a JS template literal. k6/goja treated \x as a hex escape and exited before sending any request (invalid escape: \x: len("") != 2). The wire URI is unchanged. validate_script now rejects a bare \x hex escape in-process. (#79)

  • [Reality] traffic-breakdown.json field expected_over_duration is now expected_requests (HTTP count over the run, not seconds). When --rps is unset the value is null instead of inventing rps=1, which made a 60s run look like a duration of 300. (#79)

[0.3.217] - 2026-09-04

Fixed

  • [Reality] OpenAPI header parameters named Content-Length, Host, or Transfer-Encoding are no longer invented from the schema (#79). Srikanth’s Amazon S3 spec listed Content-Length as an integer header; generation filled 42 on empty-body POSTs and k6 dropped every request (Content-Length header \"42\" doesn't match actual body length of 0). k6 now owns those headers. Verbatim / user-overridden values are kept.

  • [Reality] Colliding WAFBench case titles no longer emit duplicate k6 const names (#79). A 32-target --wafbench-verbatim run with 31 YAML files sharing titles like normal request allowed failed every target with k6 exit 107 (ScriptException) and 0 requests. Identifiers and metric names now get a _2, _3, … suffix.

Added

  • [Reality] Traffic-file breakdown reprints at end of run with unique vs total (unique * RPS) and writes traffic-breakdown.json under the output dir for automation (#79).

[0.3.216] - 2026-08-31

Fixed

  • [Reality] A missing --wafbench-dir path is now a hard error instead of a warning plus an empty payload pool (#79). On 0.3.215, mockforge bench --wafbench-dir missing.yaml --spec ... --targets-file ... still generated a k6 script; getNextSecurityPayload() then returned undefined and goja threw Cannot convert undefined or null to object. The command now exits with WAFBench path does not exist. Defense in depth: an empty pool returns [] rather than undefined.

Added

  • [Reality] After a traffic file loads, print per-file sent / attack(expected 403) / normal(expected 200) / omitted counts so a multi-YAML run has a checklist for proxy-log review (#79).

Security

  • [Security] RUSTSEC-2026-0269: bumped wasmtime 36.0.13 to 36.0.14 (filesystem sandbox escape on trailing slashes). Same 36.x line as the rest of the plugin-loader pin.

[0.3.215] - 2026-08-30

Fixed

  • [Reality] --wafbench-verbatim now works with --targets-file (#79). The single-target path already sent traffic-file requests as written and made --spec optional, but --targets-file dispatched into ParallelExecutor first. That path still required a spec and built templates from spec operations, so the same command either died with No spec files provided or fuzzed spec URLs. ParallelExecutor now loads verbatim templates, keeps --spec optional, and calls security_testing_enabled() instead of recomputing the injection flag inline. --base-path / no longer prefixes a second slash onto paths that already start with /.

[0.3.214] - 2026-08-23

Added

  • [Reality] New mockforge bench --wafbench-verbatim sends each traffic case exactly as written instead of extracting an attack payload from it (#994, #79 round 66 / Srikanth on 0.3.213). His WAF rule chained on ARGS:redirect_uri and ARGS:response_type never fired, and the run still went green, which for a security tool is worse than an error. The cause: by default a case’s uri is treated as a CRS attack string hidden in a query parameter, so extract_uri_payload keeps only the FIRST parameter’s value, discards the path, and re-attaches the survivor to a spec-derived endpoint as ?test=<payload>. /oauth/authorize?response_type=totally-unsupported&redirect_uri=https%3A%2F%2Fevil...&state=s1 therefore went out as roughly GET <spec-endpoint>?test=totally-unsupported, with redirect_uri absent entirely. That behaviour is correct for CRS/WAFBench files, where one attack string is the whole test, so this adds a mode rather than changing the default. With the flag, method, full URI, headers and body are sent as given: no extraction, no path substitution, no test= injection, no spec-endpoint cycling, and --spec no longer supplies the endpoints. The URI is preserved byte for byte (query params are deliberately not parsed and rejoined, because for charset and traversal cases the encoding IS the payload). Real-binary verified against his own case and his 8-case file. Also documents that --wafbench-cycle-all affects payload selection only and does not change targeting.

  • [Reality] --wafbench-verbatim now genuinely sends requests untouched (#997). Found by capturing what the flag actually put on the wire rather than by reading the generated k6 script: --wafbench-dir feeds two consumers, and while verbatim mode stopped the template from extracting payloads, the security layer still read the same file as a payload POOL and appended &test=<payload> to every request at a later stage. That corrupted the exact cases the user asked to be sent literally, and it attached attack payloads to expected: 200 cases, so a correctly-behaving WAF would block them and the run would report failures the user never wrote. Inventing failures is as damaging as the false passes #994 fixed. The gating flag had been recomputed inline at four render sites, the #79 drift shape, and is now a single security_testing_enabled() method guarded by a test that fails if inline copies return. --security-test combined with verbatim now warns and is ignored rather than silently mutating traffic. --spec is optional in verbatim mode, since the traffic file supplies every request.

  • [Reality] Traffic cases marked omit_rule: true are skipped with an explanation instead of being parsed and silently dropped (#997). The field marks a baseline to be sent with the rule under test disabled; mockforge cannot toggle a WAF rule, so the case previously went out byte-identical to its non-omitted twin while asserting the opposite status. Exactly one of the pair always failed regardless of whether the rule worked, which defeats the only purpose of a baseline.

Fixed

  • [DevX] Documented the 41 MOCKFORGE_* environment variables that were read in code but absent from user-facing docs, which had left the docs/code drift gate red on every PR regardless of content. Covers the previously undocumented operator surface: plugin host, plugin egress proxy, test runner, platform LLM, capture forwarding, contract-diff and drift body limits, Kafka offset persistence, OTLP port, hosted overage ceiling, PagerDuty endpoint override. Defaults were read from the code rather than guessed, and three easy-to-miss behaviours are called out: MOCKFORGE_PLUGIN_HOST_SIGNATURE_MODE silently falls back to optional on an unrecognised value, and MOCKFORGE_SSRF_ALLOW_LOOPBACK / MOCKFORGE_SSO_ALLOW_INSECURE_ISSUERS relax SSRF protection and are test-only.
  • [DevX] Added a WAF Testing page to the book (#79). --wafbench-dir had no documentation at all, which is why targeting had to be explained by hand on the issue. Covers the two accepted file shapes, the payload-extraction vs verbatim distinction that decides whether a rule fires, a targeting matrix for the flag combinations, that --wafbench-cycle-all affects payload selection only, and why omit_rule cases are skipped.

[0.3.213] - 2026-08-20

Fixed

  • [Contracts] OpenAPI specs whose operations omit responses now load instead of aborting the run (#79 round 65 / Srikanth on 0.3.212). His proxy-generated spec failed outright with missing field \responses`, and the error named no path or method. The spec is genuinely non-conformant (OpenAPI 3.x marks responsesrequired, and 63 of its 70 operations omit it), but refusing it is the wrong trade: request generation, load testing and conformance probing all derive from paths, parameters andrequestBodyand never readresponses`, so the missing field costs nothing we use while rejecting the document costs the whole run. Proxies and API-discovery tools emit specs like this routinely, because they observe requests and have nothing to say about responses. A narrow repair pass fills in only the mandatory field, never invents response content, and warns with the count of affected operations and what is lost (response-schema validation has nothing to check for them). Real-binary verified against his attachment: the run now loads and finds all 70 operations.

Added

  • [Reality] --wafbench-dir now accepts a simple {title, request, expected} YAML list in addition to the WAFBench document shape (#987, #79 round 65 / Srikanth). His LLM-generated traffic file was rejected with invalid type: sequence, expected struct WafBenchFile, which was accurate about what failed but silent about what would have worked. The WAFBench shape exists to carry CRS rule IDs and provenance that a generated file has no reason to contain. The simple form maps 1:1 onto the internal representation (body becomes data, titles are synthesised when absent), so the rest of the security-test pipeline is untouched. expected accepts 403, [403, 406], or {status: ...}, and an unparsable expectation yields no status rather than dropping the case, since the request is still valid traffic. When both shapes fail, the error now names both with the parse error for each. Real-binary verified against his unmodified file: 8 cases, 24 payloads.

Security

  • [Security] RUSTSEC-2026-0258 (h2 unbounded empty DATA frames): bumped h2 0.4.15 to 0.4.17, which is the instance that serves HTTP here via hyper 1.x / axum. The remaining h2 0.3.27 is reached only through the AWS SDK client path and is ignored with reasoning recorded in audit.toml: 0.3.27 is the latest 0.3.x and upstream patched only the 0.4 line, and the flaw concerns queueing empty frames from a peer, where on that path we are the client talking to AWS KMS/STS over TLS. Advisory is rated low severity.

[0.3.212] - 2026-08-03

Fixed

  • [Reality] --conformance-basic-auth (and --conformance-headers, where --auth-bearer lands) now reach the wire on multi-target runs (#79 round 64 / Srikanth on 0.3.210). His mockforge bench --use-k6 --targets-file vs_list3.json --conformance-basic-auth user:pass ... sent no credentials at all, absent from both his PCAP and his proxy, while the identical single-target invocation worked. Round 47 taught parse_headers() to fold those auth shortcuts into the shared header map so the same flags work for a plain load run without --conformance, and both ends of the chain were already correct (ParallelExecutor calls parse_headers(); the k6 generator merges custom_headers into every endpoint). The break was between them: execute_multi_target hand-copies BenchCommand field by field and set conformance_basic_auth: None / conformance_headers: vec![], nulling the fields before parse_headers() ran, so the fold had nothing to fold. Real-binary verified across two targets: grep -c Authorization on the generated k6 scripts goes 0,0 to 3,3, carrying Basic dXNlcm5hbWU6cGFzc3dvcmQ=. Adds a drift guard asserting every field parse_headers() folds survives that clone, because field-by-field struct literals drop fields silently. Note that --validate-requests and --export-requests are conformance-run features (read only inside execute_conformance_test); they no-op on a plain load run in single- and multi-target alike, and need --conformance.
  • [Security] RUSTSEC-2026-0222: wasmtime 36.0.12 to 36.0.13, reached via wasmtime-wasi -> wiggle -> mockforge-plugin-loader. Lockfile only, a patch bump inside the existing 36.x line.
  • [Contracts] mockforge-registry-core no longer fails to compile for default-feature consumers. An associated const added in 0.3.211’s audit fix sat inside a #[cfg(feature = "postgres")] impl while its ungated caller and tests still referenced it, so cargo install mockforge-cli could not build. Nothing in CI covered that combination: the workspace test job runs --all-features and the registry server always builds with postgres. Moved to a module-level const.
  • [Contracts] Repaired the release pipeline itself. A stale doctest in mockforge-intelligence (broken since May) was failing cargo test --workspace --release in the Create Release job, which skipped everything after it, including the GitHub Release and the Fly deploy, which has needs: release. Production had therefore been serving 0.3.183 since 2026-06-19. Also aligned every Dockerfile builder with rust-toolchain.toml (1.75/1.90/1.91 to 1.96) after aws-smithy-types raised its MSRV past the pinned builder and broke container builds outright, and cleared the unused_qualifications errors that were reddening the Test job on every PR regardless of content.

[0.3.211] - 2026-07-27

Fixed

  • [Reality] Target-side HTTP protocol violations classify as "kind": "protocol" in conformance-network-events.json instead of generic "other" (#79 round 63 / Srikanth on 0.3.210). A WAF answering blocked security probes with a body that disagreed with its declared Content-Length trips Go’s server replied with more than declared Content-Length; truncated; those events previously mixed in with unclassifiable failures. Also covers malformed, protocol error, invalid header. Evaluated last, so eof/timeout/tls/connect keep their meaning and only other is re-labelled. Applied to all three k6 render paths with a regression test guarding both presence and ordering.

[0.3.210] - 2026-07-24

Added

  • [Reality] New mockforge bench --no-abort-on-error / --abort-on-error-rate <rate> flags to control the round-60 k6 memory safety valve (#79 round 62 / Srikanth on 0.3.209). The round-60 valve aborts a k6 run whose http_req_failed rate crosses 0.95 for 60s (OOM guard on dead targets), but that also stopped legitimate stress tests: Srikanth’s WAF/proxy targets legitimately reject ~95.2% of the probe traffic (fast non-2xx, zero transport failures), crossing 0.95 and aborting every run at ~2min. --no-abort-on-error drops the abortOnFail threshold so the run goes its full duration regardless of error rate; --abort-on-error-rate retunes the threshold (default 0.95). Wired through single- and multi-target k6 paths; default behaviour unchanged. Real-binary verified: the generated k6 script omits abortOnFail under --no-abort-on-error and renders rate<0.99 under --abort-on-error-rate 0.99.

[0.3.209] - 2026-07-22

Added

  • [Reality] New mockforge bench --dns-policy <policy> flag → k6 --dns "policy=<value>" (#79 round 61 / Srikanth on 0.3.208). Values: preferIPv4 (default), preferIPv6, onlyIPv4, onlyIPv6, any. Unblocks GEODB IPv6 tests where the target must stay a hostname (proxy routes by Host/SNI) but must be dialed over its AAAA record; k6/Go default to IPv4, which can’t be dialed from an IPv6 --source-ip (no suitable address found). preferIPv6 picks the AAAA record while keeping the hostname on the wire. Wired through single- and multi-target k6 paths; real-binary verified the launched k6 runs with --dns policy=preferIPv6.

[0.3.208] - 2026-07-21

Fixed

  • [Reality] k6 no longer OOM-kills (signal: 9) when a load target rejects/times-out ~every request (#79 round 60 / Srikanth on 0.3.207). The generated k6 load scripts now carry an abortOnFail safety valve on http_req_failed: a target failing >=95% of requests after a 60s grace period aborts (exit 99) instead of hammering a dead endpoint for the full duration and accumulating per-request memory. Legitimate runs under 95% failure are unaffected. Real-binary verified against a dead target: k6 stops at ~60s instead of running the full scenario. Applies to the standard-load and CRUD-flow templates.

[0.3.207] - 2026-07-19

Added

  • [Contracts] New “Security probes (owasp injection)” view in the self-test (#79 round 59 / Srikanth on 0.3.206 was WAF-testing and saw owasp: 0 caught / 8127 missed but Definite issues: none). The self-test now prints a per-injection-family breakdown of how many OWASP payloads the target accepted (status < 400) vs blocked (4xx), plus a conformance-owasp-accepted.json sidecar listing every accepted payload with method + URL. For a WAF each accepted payload is one it did NOT block; for a plain API it is expected (a string field accepts any string). Kept out of “Definite issues” (spec violations only) but surfaced on its own line. Verified against Srikanth’s capture (all 8127 payloads across 7 families accepted) and real-binary against mockforge serve.

[0.3.206] - 2026-07-16

Fixed

  • [Reality] Multi-target load no longer fails to start with exit status: 106 (k6 CannotStartRESTAPI) and zero requests (#79 round 58 / Srikanth on 0.3.205). Each parallel k6 was pinned to a fixed REST API port (6565 + index) that collides when already taken (orphaned k6 from a prior OOM-killed run, a second bench, a local service). k6 now binds an ephemeral port (--address localhost:0) instead; MockForge reads results from summary.json on disk, never the API. Real-binary verified with ports 6566/6567 occupied: a load that used to exit 106 on every target now runs.

Added

  • [Contracts] New “Definite issues” view in the self-test (#79 round 58 / Srikanth on 0.3.205 asked for a “for sure this is an issue” filter). A Definite issues (N) console section plus a conformance-definite-issues.json sidecar surface only unambiguous problems: a spec-valid request the target rejected, or any probe that drew a 5xx. Spec-valid “missed” negatives are excluded. Clarified that a “caught” 4xx is the target correctly rejecting a bad request, not a violation.

[0.3.205] - 2026-07-14

Added

  • [DevX] New mockforge bench --discard-response-bodies flag exposes K6_DISCARD_RESPONSE_BODIES=true as a first-class option (#79 round 57 / Srikanth on 0.3.204 asked for a flag instead of the env var for scale/stress runs). Opts a single-target load run into discarding response bodies (multi-target load already discards by default); no-op on conformance / self-test / extraction runs, which need the body. Real-binary verified: the launched k6 child carries the env var and data_received stays at header-only levels.

Changed

  • [DevX] The self-test console summary prints a one-line legend under the Negatives [...] lines explaining “caught” (target rejected a deliberately-bad request with a 4xx) vs “missed” (target accepted it), and that a high “missed” is not automatically a bug because many probes are spec-valid by construction (#79 round 57 / Srikanth on 0.3.204 asked how to read caught vs missed). The self-test-probes and capacity-sizing reference pages gain the same nuance and document the new flag.

[0.3.204] - 2026-07-13

Fixed

  • [Contracts] parameters:* negative probes are now recorded in conformance-request-violations.json, and the single-target self-test writes that file at all (#79 round 56 / Srikanth on 0.3.203: parameter violations were still absent from the logs). For his Apigee spec the parameter probes are all spec-VALID by construction (dropping the OPTIONAL $.xgafv query, adding an oversized/undeclared query param, or an unconstrained {instance} path value violate no schema), so the emitted-request validator found nothing to flag and stayed silent. Each parameters:* negative that produces no hard breach is now recorded as a typed parameter_negative_probe row explaining why it is not a schema violation; the single-target self-test calls the validator too (previously only the multi-target --targets-file path did); and --validate-requests now implies request capture. Real-binary verified against mockforge serve with a custom-verb Apigee spec: the violations file carries all three parameter probes (uri-too-long, bad-path-param, missing-query) alongside the genuine body_schema_violation / query_value_mismatch rows, in both single-target and --targets-file modes.
  • [Reality] k6 no longer gets OOM-killed (signal: 9 (SIGKILL)) during long, high-concurrency multi-target load runs (#79 round 56 / Srikanth on 0.3.203). The plain-load k6 only checks status codes but was buffering every response body in memory; over a multi-hour run at 10 VUs across 10+ targets the buffered bodies plus k6’s metric accumulation exhausted RAM and the kernel OOM-killer sent SIGKILL. The multi-target plain-load path now runs k6 with K6_DISCARD_RESPONSE_BODIES=true (safe there because bodies are never inspected). Real-binary verified: the launched k6 child process carries K6_DISCARD_RESPONSE_BODIES=true in its environment and data_received stays at header-only levels. The flag defaults off and is opt-in per executor; body-inspecting paths (conformance, extraction) are untouched.

[0.3.198] - 2026-07-02

Fixed

  • [Contracts] Self-test baseline probe filler is now spec-VALID (enum -> first member, boolean -> true, string body enums -> a valid member), so a request-body:* probe no longer trips spurious query_value_mismatch violations on alt/prettyPrint and body probes no longer show test-string enum noise (#79 round 51 / Srikanth on 0.3.196). Verified against mockforge serve: by-probe violations dropped 32 -> 12, request-body:* query violations now 0.
  • [Contracts] Multipart wire byte count now prefers k6’s Content-Length (the exact wire body size a proxy sees) over the reconstructed envelope, closing the 264-byte gap Srikanth reported on 0.3.196 (#79 round 51).

Added

  • [AI][DevX] New “Agent / LLM / MCP Traffic (Packet-Level)” reference page documenting Agent<->LLM, Agent<->Agent, and MCP interactions at the HTTP-packet level with real captures and PCAP-recording recipes (#79 / Srikanth on 0.3.196).

[0.3.197] - 2026-07-01

Added

  • [AI] Mock LLM endpoint real-model modes via --llm-mock-mode (#915): proxy (forward to --llm-mock-upstream), record (forward on cassette miss + save, replay on hit), replay (cassette only, offline; canned fallback). Default stays pure offline mock. New flags --llm-mock-upstream / --llm-mock-api-key / --llm-mock-cassette. Verified against mockforge serve by pointing one --llm-mock instance at another (no API key).

[0.3.196] - 2026-06-30

Added

  • [AI] Mock LLM endpoint: mockforge serve --llm-mock mounts OpenAI-compatible POST /v1/chat/completions + GET /v1/models and Anthropic-compatible POST /v1/messages with SSE streaming, so an agent can point its base URL at MockForge for scale/offline/failure testing (#912 / #79 Srikanth).
  • [AI] Mock MCP server: mockforge serve --mcp-mock mounts a JSON-RPC 2.0 endpoint at POST /mcp answering initialize / tools/list / tools/call / resources/list / prompts/list, so an agent acting as an MCP client can talk to MockForge (#913 / #79 Srikanth).

[0.3.195] - 2026-06-30

Fixed

  • [Contracts] Multipart wire byte count no longer comes out smaller than total; computed as disk-sum payload + ASCII multipart envelope instead of the UTF-8-undercounting raw.length (#79 round 50 / Srikanth on 0.3.194).
  • [Contracts] conformance-request-violations-by-request.json emits one row per URL with the deduped union of all violations and contributing checks, so a URL’s owasp/query checks no longer hide in a separate row from its body checks (#79 round 50 / Srikanth on 0.3.194).
  • [Contracts] Repeated self-test iterations no longer duplicate the same violation N times in the flat and grouped violation files (#79 round 50 / Srikanth on 0.3.194).

Added

  • [Contracts][AI] New --security-categories values llm-prompt-injection (OWASP LLM01 prompt-injection/jailbreak) and dlp (synthetic PII canaries) for agent-driven AI-attack and data-loss-prevention testing (#79 round 50 / Srikanth on 0.3.194).

[0.3.181] - 2026-06-17

Fixed

  • [DevX] Capture-viewer HTML status badge colour now follows the probe’s expected_status_range; a variant-b 400 reads green to match the exp 2xx-4xx badge (#79 round 36 / #875 / Srikanth).

[0.3.180] - 2026-06-16

Fixed

  • [Contracts] Embedded-content variant-b probes no longer flag 4xx responses as mismatches; only 5xx counts as failure (#79 round 35 / #859 / Srikanth).

[0.3.179] - 2026-06-15

Fixed

  • [DevX] response_schema_error strips description/example fields from the focused schema before truncation so type survives (#79 round 34 / #827 / Srikanth).
  • [Contracts] Per-endpoint summary path column matches the URL user sent: base_path prefixed (#79 round 34 / #828 / Srikanth).
  • [Contracts] Embedded-content variant-b probes skip when positive sample has no string field, instead of synthesizing a non-conforming envelope (#79 round 34 / #829 / Srikanth).

[0.3.178] - 2026-06-14

Added

  • [Contracts] Per-endpoint summary groups by spec path template, with a spec label for multi-spec runs (#79 round 33 / #823 / Srikanth).
  • [Contracts] MOCKFORGE_INJECT_RESPONSE_VIOLATIONS=true (+ --inject-response-violations) intentionally drops one required field from 2xx response bodies for negative-testing downstream proxies (#79 round 33 / #822 / Srikanth).

[0.3.177] - 2026-06-14

Fixed

  • [Contracts] Server-side conformance buffer now records content-types (415) violations from the MockAI router path too (#79 round 32 / Srikanth).
  • [Install] cargo install mockforge-cli no longer requires protobuf-compiler on Ubuntu 16.04 / RHEL 7; mockforge-grpc build uses a vendored protoc when PROTOC is unset (#79 round 32 / Srikanth).

Added

  • [Contracts] Per-endpoint traffic summary (sent count, status-class breakdown, request/response/query length p95) in bench-results/conformance-per-endpoint.json and a new section in conformance-report.html (#79 round 32 / Srikanth).

[0.3.176] - 2026-06-10

Fixed

  • [Contracts] Write requests (POST / PUT / PATCH / DELETE) now return spec-shape response bodies instead of MockAI’s hardcoded {id, status, data} envelope (#79 round 31 follow-up / Srikanth).

[0.3.175] - 2026-06-10

Fixed

  • [DevX] For required field missing errors, the printed schema is now the missing property’s own sub-schema, not the entire parent object (#79 round 31 / Srikanth).
  • [Install] cargo install mockforge-cli no longer requires OpenSSL 1.1+; the workspace is fully rustls-only (#79 round 31).

Added

  • [Server] mockforge serve --conformance-buffer-size N and --conformance-buffer-unique CLI flags mirror the round-29/round-30 env vars (#79 round 31 / Srikanth).

[0.3.174] - 2026-06-09

Fixed

  • [DevX] response_schema_error now prints only the sub-schema at the offending JSON Pointer instead of the full top-level schema (#79 round 30 / Srikanth).

Added

  • [Contracts] MOCKFORGE_CONFORMANCE_BUFFER_UNIQUE=true switches the violation buffer from FIFO to dedup-by-signature; every duplicate bumps a new occurrences field on the entry instead of consuming a new buffer slot (#79 round 30 / Srikanth).

[0.3.173] - 2026-06-08

Fixed

  • [DevX] response_schema_error message reads response body root: ... / response body at /<path>: ... instead of the ambiguous at /: ... (#79 round 29 / Srikanth).

Added

  • [Contracts] MOCKFORGE_CONFORMANCE_BUFFER_SIZE env var raises the server-side violation ring buffer above the default 256, capped at 64k (#79 round 29 / Srikanth).
  • [Contracts] Bench capacity advisory at run start when targets × VUs ≥ 150; estimates RAM / CPU and links to the new sizing doc.
  • [DevX] New book page reference/bench-capacity-sizing.md with sizing table, formulas, and sharding guide.

[0.3.172] - 2026-06-07

Fixed

  • [Contracts] Content-type-swap probes now send only ONE Content-Type (the reqwest header-append bug let axum’s JSON extractor accept). Smoke test: same 4 probes that returned 204 on 0.3.171 now return 415 (#79 round 28).
  • [Contracts] Server-side check_request_content_type flags Content-Type mismatches against requestBody.content keys; records a content-types category violation. (#79 round 28)
  • [DevX] response_schema_error embeds the expected schema JSON: at /: expected type string; expected schema {"type":"string"}. (#79 round 28)

Added

  • [Contracts] expected_status_range field on every CaseCapture; exp 4xx/exp 2xx-3xx badge on every card. (#79 round 28)
  • [DevX] “Only show mismatches” checkbox + per-cat clickable counts in the per-op By category column. (#79 round 28)

[0.3.171] - 2026-06-06

Fixed

  • [DevX] Capture HTML viewer paginates with cross-page filters; the round-25 + round-26 1000-card cap that hid 4xx/5xx probes is gone (#79 round 27 / Srikanth d3).

Added

  • [Contracts] Content-type swap variant (b): four request-body:embedded-content:* probes per JSON operation send a valid JSON envelope with an XML/YAML/multipart/urlencoded snippet stuffed into a string field. Flags servers that crash on the embedded content (#79 round 27 / Srikanth k variant b).

[0.3.170] - 2026-06-06

Fixed

  • [Contracts] TUI Conformance tab: detail modal now snapshots the violation’s text at Enter time (#79 round 26 / Srikanth re-test of 0.3.169). The round-25 identity-key re-anchor only worked when the clicked violation survived the 256-cap buffer; under heavy traffic it got evicted and selected stayed at a stale index. Snapshot + Esc-clear fixes it; regression tests cover both the index-shift and the on_data refresh path.
  • [DevX] response_schema_error is now human-readable (“at /: expected type string”) instead of broken Rust debug syntax (#79 round 26 / Srikanth). Falls back to jsonschema’s Display impl for the long-tail kinds.
  • [DevX] HTML report Negatives by category is now a single grouped table with a Family column prepended (#79 round 26 / Srikanth d2). The standalone family rollup section is gone; one table carries both axes.

[0.3.169] - 2026-06-05

Fixed

  • [Contracts] TUI Conformance tab: selecting a row no longer jumps to a different request when new traffic arrives on the next refresh tick (#79 round 25 / Srikanth follow-up).
  • [DevX] Capture HTML viewer no longer hangs the browser at 9000+ probes: content-visibility: auto per card, 200 ms debounced filter, hard cap at 1000 rendered cards with Showing N of M banner (#79 round 25 / Srikanth d follow-up).

Added

  • [Contracts] Content-type swap probe family request-body:content-type-mismatch:<variant> (#79 round 25 / Srikanth k). Four probes per JSON operation: xml / yaml / multipart / urlencoded.
  • [Contracts] --validate-response-schemas flag (#79 round 25 / closes round 21.3 / Srikanth a2 + a3). Validates every probe’s response body against the spec’s response schema for the actual status returned. Mismatches surface as response_schema_error in the JSONL and a red “Response schema mismatch” section in the per-probe HTML viewer card. Opt-in.
  • [DevX] HTML report: Negatives by category family rollup (Request body / Parameters / Security family) and a per-operation By category column showing mismatch breakdown (#79 round 25 / Srikanth d remainder).

[0.3.168] - 2026-06-04

Fixed

  • [Contracts] Geo-source-IP headers now ride on every self-test probe, not just the positive case (#79 round 24 / Srikanth f). Four negative-probe call sites and the security-probe path were dropping the geo IP. Regression test (geo_headers_present_on_every_probe_with_capture) added.
  • [DevX] Clickable count cells in the HTML report no longer dead-end when --report-missed-cap crops the drill-down (#79 round 24 / Srikanth e). Counts only link when their target row actually survives the truncation.

Added

  • [DevX] --conformance-self-test-capture now also emits a browser-viewable conformance-self-test-requests.html alongside the JSONL (#79 round 24 / Srikanth d). Self-contained, includes a filter toolbar and expandable per-probe cards.

[0.3.167] - 2026-06-03

Fixed

  • [Contracts][DevX] --source-ip now actually works with the k6 path (#79 round 23 / Srikanth correction on round-22 g1). The round-22 warning that said “k6 cannot bind a VU to a source IP from the script side” was wrong: k6 supports --local-ips natively (CIDR, ranges, and comma-separated single IPs). The k6 executor now forwards the CLI’s --source-ip straight to k6 run --local-ips, and the misleading warning is removed. Only the --conformance-self-test --use-k6 combo still fires a warning, because self-test returns before k6 launches and --use-k6 is a no-op there.
  • [DevX] Docs site is rebuilding again (docs.mockforge.dev had been stuck since the 2025-11-10 build because mdbook-toc 0.15.x stopped parsing mdbook’s preprocessor input). The TOC preprocessor was disabled (no page uses the <!-- toc --> marker anyway) and its cargo install step was removed from the deploy workflow, so the round-21 probe-label reference page resolves at https://docs.mockforge.dev/reference/conformance-self-test-probes.html.

Added

  • [Contracts][DevX] --conformance-self-test-capture flag (#79 round 23 / Srikanth c-iii deferred from round 22.5). When set alongside --conformance-self-test, every probe records method, URL, request headers/body and response status/headers/body to conformance-self-test-requests.jsonl (one JSON object per line) next to the JSON/HTML report. Bodies cap at 16 KiB per direction with request_body_truncated / response_body_truncated flags.
  • [DevX] HTML conformance report: count-cells in the “Negatives by category” and “Per-operation results” tables are now clickable links into the drill-down table below (#79 round 23 / Srikanth d). #miss-cat-<category> jumps to the first row of that category; #miss-op-<method>_<path-slug> jumps to the first row for that operation.
  • [DevX] HTML conformance report wording: “missed/caught” renamed to “Mismatched (non-4xx) / Matched (4xx)” across the cards, category table, per-operation table, and drill-down heading; the category status badge is now a plain PASS/FAIL (replacing “all caught” / “rejection gaps”) since the count column already conveys magnitude (#79 round 23 / Srikanth d wording).

[0.3.166] - 2026-06-02

Fixed

  • TUI Conformance: Enter in the Unknown view (u) opens Unknown Path Detail instead of the (wrong) Violation Detail (#79 round 22.1).
  • --source-ip / --geo-source-ip emit a warning when used with --use-k6 since k6 can’t bind a VU to a source IP (#79 round 22.2).

Added

  • --geo-source-ip headers wired into the k6 template; the rendered script rotates X-Forwarded-For / True-Client-IP / CF-Connecting-IP per iteration (#79 round 22.3).
  • --source-ip / --geo-source-ip accept start-end IPv4 ranges (e.g. 10.0.0.5-10.0.0.27) alongside CIDR and comma-separated lists (#79 round 22.4).
  • HTML report header links to the probe-label reference; “gaps” badge wording clarified to “rejection gaps” (#79 round 22.6).

[0.3.165] - 2026-06-01

Added

  • --report-missed-cap N flag for the HTML drill-down (#79 round 21.1). Default 200; 0 = no cap.
  • HTML missed-negative table gains an Expected column (#79 round 21.1). Addresses Srikanth’s (a1).
  • New book page: Conformance Self-Test Probes (#79 round 21.2). Canonical reference for every probe label.

Notes

  • Response-body shape validation alongside the response-code check (a2 / a3) is queued for a separate release.

[0.3.164] - 2026-06-01

Fixed

  • Shadow mode now gates 200 on the configured --base-path (#79 round 20). Paths outside the configured prefix (e.g. /api123/... when server is /api) return 404 even with --shadow enabled, matching pre-shadow semantics. path_in_base checks at the segment boundary, so /api123 is not under /api.

[0.3.163] - 2026-06-01

Fixed

  • Live-server route handler now resolves nested $ref pointers against the spec’s components (#79 round 19) — third schema-validator call site, missed by round 18.3. Dotted-name vCenter schemas resolve.

Added

  • --source-ip and --geo-source-ip accept CIDR ranges (10.0.0.0/28, 2001:db8::/126) capped at 256 hosts per range. IPv4 + IPv6 supported (#79 round 19).

[0.3.162] - 2026-05-31

Issue #79 rounds 17.1–18.5 consolidated into a single release. Intermediate version numbers (0.3.153–0.3.161) were never published.

Added

  • TUI Conformance: c copies the selected violation to clipboard (round 17.1); total_ok counter alongside total_seen for accurate pass/fail ratio (round 17.1).
  • --conformance-self-test schema-driven body mutator (round 17.2), security probes (round 17.3), spec-level audit (round 17.4), OWASP/WAF unification (round 17.5), self-contained HTML report (round 17.6).
  • GEODB multi-source-IP testing (round 18.5): --source-ip (real bind) + --geo-source-ip (forwarded-IP headers).

Changed

  • OWASP coverage table now explains the “-” rows with actionable category hints (round 18.4).

Fixed

  • --conformance-self-test honours --base-path (round 18.1); hard warning when every positive returns the same status (round 18.1); accurate bench header before spec parse (round 18.2).
  • Request-body validator resolves nested $ref pointers against the spec’s components map (round 18.3) — fixes the Vcenter.VM.DiskCloneSpec “Pointer does not exist” class of failures.

[0.3.152] - 2026-05-28

Changed

  • [Contracts][DevX] TUI Conformance export (e) now deduplicates by (method, path, category, reason) with a count + first_seen / last_seen window (#79 round 16).
  • [DevX] --conformance-self-test produces negatives for two previously-zero-coverage shapes: operations with a required body but no synthesised sample, and operations whose only spec input is a path parameter (parameters:bad-path-param probe).

[0.3.151] - 2026-05-27

Added

  • [Reality] mockforge serve --shadow CLI flag (#79 round 15) — first-class flag for shadow mode (alias for MOCKFORGE_SHADOW_MODE=true) so it can’t be forgotten.
  • [Contracts][DevX] Lifetime “seen total” counters for conformance violations + unknown paths — admin API total_seen field and TUI titles now show the true lifetime count alongside the 256-cap buffered count.

Changed

  • [DevX] Per-violation server log under target mockforge::conformance (enable with RUST_LOG=mockforge::conformance=debug) showing method/path/status/category/reason.
  • [DevX] TUI Conformance detail view + Top Offending Endpoints panel now wrap long lines so big paths/reasons are fully readable.

[0.3.150] - 2026-05-26

Fixed

  • [Reality] Server no longer OOM-killed at startup on large specs (#79 round 14) — router construction cloned the entire routes Vec into every per-route handler (O(N²) memory; ~260 GB for an 11,422-op spec). Fixed by sharing one validator via Arc across all handlers. Reproduced + verified with a 22,000-operation synthetic spec.

Added

  • [Reality][Contracts] Server-side shadow mode (MOCKFORGE_SHADOW_MODE=true) (#79 round 14) — returns 200 for unknown paths and spec violations while still recording them to the conformance + unknown-paths buffers (report-only / monitor mode for proxy-replay traffic). Startup prints a 👻 SHADOW MODE ON banner.
  • [Contracts][DevX] Status column on the TUI unknown-paths view — surfaces the HTTP status the server returned (404 normally, 200 in shadow mode).

[0.3.149] - 2026-05-25

Added

  • [Contracts][DevX] mockforge bench --conformance --conformance-self-test (#79 round 13 (4)) — positive + per-category negative driver. Sends one valid request and per-category negatives (empty body / wrong-type body / missing required query / missing required header) per spec operation; reports how many the server correctly rejected with 4xx. Writes conformance-self-test.json and emits a warning when any negative slipped through.

[0.3.148] - 2026-05-25

Fixed

  • [Contracts][DevX] Conformance buffer now actually fires on the default-flow handlers (#79 round 13) — the MockAI and AI handlers bypassed validation entirely, so violations never populated for default-flow routes. Extracted OpenApiRouteRegistry::run_validation_with_recording and called it at the entry of each handler.

Added

  • [Contracts] New response-shape violation category — surfaces when a requested status code isn’t defined in the spec for that operation.
  • [Contracts][DevX] New unknown-paths feed + admin endpoint + TUI view — separate ring buffer tracks requests whose path didn’t match any spec route. GET /__mockforge/api/conformance/unknown-paths; TUI u toggles between violations and unknown-paths views.

[0.3.147] - 2026-05-25

Changed

  • [DevX] TUI Conformance tab moved before Verification (#79 round 12 follow-up) — Verification’s Tab cycles internal fields so it acts as a dead-end for plain Tab nav. Putting Conformance earlier in the strip keeps it reachable.

[0.3.146] - 2026-05-25

Fixed

  • [DevX] TUI Conformance tab now appears + admin server exposes the violations endpoint (#79 round 12 hotfix) — v0.3.145 had two bugs: (1) ScreenId::Conformance was added to the enum but ConformanceScreen::new() was missing from App::new’s screens vec, so the tab silently dropped from the header; (2) the endpoint was only wired into mockforge-http’s management router (mock-traffic port), not the admin server the TUI polls. Fixed both, plus added an app_screens_match_screen_id_all regression test.

[0.3.145] - 2026-05-24

Added

  • [Contracts][DevX] New Conformance TUI screen + /__mockforge/api/conformance/violations endpoint (#79 round 12) — server-side counterpart to the bench-side conformance suite; every incoming request the OpenAPI router rejects for a spec violation (400/422) is captured to a bounded ring buffer and rendered in a new TUI tab.

Fixed

  • [DevX] mockforge bench --conformance --operations 'METHOD,…' now actually filters (#79 round 12) — execute_conformance_test was silently ignoring self.operations / self.exclude_operations. Also relaxed SpecParser::filter_operations to accept method-only form ("GET") without requiring "GET /path".
  • [Reality] Multi-target bench summary now includes connection + iteration counts (#79 round 12).
  • [Cloud] pillar_tracking no longer drives sqlx::pool::acquire “slow acquire” spam under load (#79 round 12) — added a 20-task in-flight cap at the recorder entry so over-pressure events are dropped immediately instead of queuing on the analytics-DB pool’s 30s acquire timeout.

[0.3.144] - 2026-05-24

Fixed

  • [Reality] OpenAPI router accepts request bodies up to 50 MiB by default (was 2 MiB axum default) — closes the “200 OK before all chunk requests arrived” PCAP behaviour Srikanth reported on Issue #79
    • Root cause: axum 0.8’s Bytes and Option<Json<Value>> extractors enforce a 2 MiB DefaultBodyLimit. Above that, the body gets truncated and the handler runs without consuming the rest of the request — hyper sends the response and TLS Close Notify while the client is still uploading the body. Reproduced locally with a 3 MiB JSON body to the demo spec.
    • Fix: every OpenApiRouteRegistry::build_router_* variant now mounts axum::extract::DefaultBodyLimit::max(...) with a 50 MiB default, configurable via MOCKFORGE_HTTP_BODY_LIMIT_MB.
  • [Cloud] pillar_tracking no longer floods logs with one WARN per dropped event under load (#79 round 11)
    • Per-event failures are now DEBUG; a single aggregated pillar_tracking: dropped X events in the last 60s due to analytics-DB pressure WARN fires at most every 60 seconds.

[0.3.143] - 2026-05-23

Fixed

  • [DevX] Republish of 0.3.142 — fixes broken [email protected] install (#79 round 10 hotfix)
    • cargo install [email protected] failed with error[E0432]: unresolved import \crate::database::Database`inmockforge-http/src/handlers/threat_modeling.rs:29andlib.rs:2387. The databasemodule was moved tomockforge-intelligencein #611, but twouse crate::database::Database;statements weren't gated behind#[cfg(feature = “database”)], so default-feature builds (which is what cargo installuses) failed to compile. Fix landed onmain` in #616/#618 but was not in the 0.3.142 tag.
    • 0.3.142 of the broken crates (cli, http, import, pipelines, proxy, workspace, core, bench, chaos, collab, recorder, registry-server, k8s-operator, vbr, sdk, test, reporting, ui) yanked from crates.io. 0.3.143 republishes the same #79 round-10 changes from a known-good main commit.

[0.3.142] - 2026-05-21

Changed

  • [DevX] Pre-flight --vus recommendation caps at 1000 for huge specs (#79 round 10)
    • Srikanth’s 11,422-operation spec at --rps 100 (9.4ms baseline) produced a recommendation of ~10,740 VUs — mathematically correct but practically absurd. The right answer for that workload isn’t “spin up 10K VUs”, it’s “shrink the workload.” 0.3.142 caps the printed recommendation at 1000 and, above the cap, steers users toward --operations/--exclude-operations filters or dropping --rps for closed-model loading.

Added

  • [DevX] Iteration coverage in bench summary (#79 round 10)
    • New Iterations: X complete × N ops = Y ops fully exercised line appears whenever k6’s iterations.values.count is non-zero. When the run ends mid-iteration (large spec, undersized VUs), a follow-up line surfaces the extra requests from the partial pass so users know the last iteration didn’t cover every operation in the spec.

Fixed

  • [DevX] scripts/check-changelog.sh now uses the PR-wide diff in CI instead of git diff-tree -r HEAD (which returns the empty combined diff on the synthetic refs/pull/<N>/merge commit actions/checkout uses). Previously every PR whose CHANGELOG.md edit landed in a commit that the merge didn’t have to reconcile would fail the “Changelog Validation” gate even though the workflow’s own outer condition correctly detected the edit (caught on #595’s release PR). Now switches modes on $GITHUB_BASE_REF: PR-wide git diff --name-only origin/$GITHUB_BASE_REF...HEAD in CI, single-commit diff-tree -r HEAD locally for the cargo-release flow.

[0.3.141] - 2026-05-20

Fixed

  • [DevX] mockforge-foundation::pillars doctests now reference the actual crate path (release-gate fix)
    • All 9 doctests imported use mockforge_core::pillars::..., but the Pillar enum lives in mockforge-foundation itself. The mismatch caused cargo test --doc -p mockforge-foundation to fail with cannot find module or crate `mockforge_core` , which gates the Release workflow’s cargo test --workspace --release step — so the v0.3.140 tag’s Create Release job failed and Publish-to-crates.io was skipped. Replaced mockforge_core::pillars → mockforge_foundation::pillars across all 9 doctests. 11 doctests now pass.
    • 0.3.140 was never published to crates.io; this release ships the round-9 bench fix originally intended for that version, plus this doctest fix on top.

[0.3.140] - 2026-05-20

Fixed

  • [DevX] Pre-flight --vus probe now factors in operations-per-iteration (#79 round 9)
    • The round-8 probe assumed 1 iteration = 1 request, but k6’s constant-arrival-rate counts iterations and every iteration calls every operation in the spec. Srikanth’s 12-op spec at --rps 100 with 15ms latency reported “–vus 5 is sufficient” and then k6 still emitted “Insufficient VUs, reached 5 active VUs” mid-run because real iteration time was 15ms × 12 ops, not 15ms.
    • Fix: ProbeResult::required_vus(rps, num_operations) now multiplies by spec operation count. Same call site change in command.rs. New tests required_vus_scales_with_operation_count and required_vus_treats_zero_operations_as_one. The pre-flight progress / warning lines now print the operation count so users see what the math used.

[0.3.139] - 2026-05-19

Added

  • [DevX] Adaptive pre-flight latency probe for --vus sizing (#79 round 8)
    • mockforge bench --rps N --vus M now does a 3-request HEAD/GET probe of the target before launch to measure baseline latency, then recommends --vus based on ceil(rps × measured_latency_secs) + 1 instead of the static “100ms / 10 req-per-VU” heuristic. Fixes a false-positive on Srikanth’s fast targets (~2ms response time) where the old heuristic warned “bump to –vus 100” when –vus 5 was actually plenty.
    • If the probe can’t reach the target (auth-gated, strict WAF, etc.), falls back to the previous 100ms heuristic so the warning still fires when warranted. When the probe succeeds AND --vus is sufficient, prints a confirmation line so users know the size check passed.
  • [Reality] “Connection reuse NOT detected” diagnostic in bench summary (#79 round 8)
    • When tcp_connect_samples > 5 × vus_max in pooled-reuse mode (no --cps), the bench reporter now prints a yellow warning explaining the target is closing sockets between requests. Addresses Srikanth’s 0.3.137 question: “I expected 5 connections with –vus 5 but see 7425” — the counter is correct, the proxy isn’t pooling. The new line makes that interpretation explicit so users don’t have to guess.

[0.3.138] - 2026-05-19

Added

  • [Cloud][Reality] Cloud-mode Time Travel — controllable virtual clock on hosted-mock deployments (#466, #527)
  • [Cloud][AI] Cloud-mode Test Generator — async LLM jobs over runtime_captures (#469, #529)
  • [Cloud][Reality] Real-time runtime-logs SSE via Fly NATS subscription (#556, #559)
  • [Cloud][Reality] OTLP gRPC trace receiver alongside HTTP/JSON (#548, #566)
  • [Cloud][Reality] Per-capture cloud forwarder with backpressure + retry (#553, #564)
  • [Cloud][Reality] Trust-root boot — plugin host fetches + refreshes active trust roots from registry (#549, #565)
  • [Cloud][Reality] HSM-backed platform signing-root rotation via AWS KMS (#550, #567)
  • [Cloud][Reality] Email notification channel via EmailService (#551, #557)
  • [Cloud][Reality] PagerDuty notification channel via Events API v2 (#552, #558)
  • [CI][Reality] Nightly hosted-mocks smoke workflow (#554, #563)

Changed

  • [DevX] pr_generation moved out of mockforge-core into mockforge-intelligence; intelligence → core dep cycle broken (#562 phase 1, #571)
  • [DevX] ADR auditing mockforge-http for intelligence/proxy extraction (#555, #561)

Fixed

  • [DevX] CI rust-cache no longer poisons builds with dangling target/*.d paths (#446, #570)
  • [UI][Cloud] CloudTestGeneratorView import path corrected (#547)

Note: Time Travel (#527) and Test Generator (#529) were initially attributed to 0.3.137 in the historical changelog block below. Both PRs landed after the v0.3.137 tag (efa43d20) had already been published, so they actually ship in 0.3.138.

[0.3.137] - 2026-05-18

Added

  • [Cloud][Reality] Cloud-mode World State — per-deployment graph + snapshot + layers + slice-query surface (#464, #528)
    • Registry proxies 5 HTTP endpoints (snapshot, snapshot/{id}, graph?layers=…, layers, query) over Fly 6PN to {fly-app}.internal:3000/api/world-state/*. Wire format mirrors cloudResilience and cloudTimeTravel: { runtime_state: "live" | "unreachable", data }. unreachable carries data: null so the UI renders an honest empty state.
    • New CloudWorldStateView reuses the existing StateLayerPanel, WorldStateGraph, and StateNodeInspector components so the visualization is identical to local mode. Deployment selector auto-picks the first active hosted-mock; multi-deployment orgs get a dropdown. 5-second polling matches the local TanStack Query refetchInterval.
    • 'world-state' added to cloudNavItemIds. WebSocket /stream upstream is intentionally not proxied — polling parity is functionally equivalent for the cadence the local UI uses, and ws-tunneling through 6PN is a follow-up.
  • [Cloud][Reality] Cloud-mode Time Travel — controllable virtual clock on hosted-mock deployments (#466, #527)
    • 7 clock-control endpoints proxied (status, enable, disable, advance, set, scale, reset). Targets the hosted mock’s main HTTP port (3000) — not the admin port — because the time-travel router mounts there for reachability when admin isn’t publicly exposed.
    • New CloudTimeTravelView with a runtime-unreachable banner that disables the control fieldset so users don’t fire mutations that’ll bounce back. Cron jobs + mutation rules stay local-only — they manage scenario state, not a hosted mock’s single-process clock.
    • 'time-travel' added to cloudNavItemIds.
  • [Cloud][AI] Cloud-mode Test Generator — async LLM jobs over runtime_captures (#469, #529)
    • New cloud_test_generation_jobs table + 4 CRUD endpoints + SSE stream (GET .../jobs/{id}/stream) for live progress.
    • Background tokio worker drains the queue with FOR UPDATE SKIP LOCKED claims, processes up to TEST_GENERATION_WORKER_CONCURRENCY (default 4) jobs in parallel per tick, and dispatches via the same ai::client + ai::quota pipeline ai_studio uses — so quota and billing semantics stay consistent. BYOK skips the platform token quota; paid plans without BYOK succeed via the platform key (MOCKFORGE_PLATFORM_LLM_API_KEY + provider/model/endpoint env vars).
    • Worker is forgiving: best-effort JSON parse strips ```json fences, recovers from prose wrappers, falls back to a { raw_content } wrapper. Cancellation race is safe — terminal writes are gated on WHERE status = 'running' so a user-cancel mid-flight wins.
    • New CloudTestGeneratorView with job timeline + create form + expandable detail rows + SSE-driven sub-second updates on expanded non-terminal rows. 'test-generator' added to cloudNavItemIds.
  • [DevX] Pre-flight warning when --vus is too low for --rps (#79 round 6 follow-up, #543)
    • mockforge bench --rps N --vus M now warns before launch when M × 10 < N (rule of thumb: 1 VU at ~100ms latency sustains ~10 req/s). The warning suggests a higher --vus value (ceil(rps / 10)), so users hit by k6’s “Insufficient VUs, reached M active VUs and cannot initialize more” message know what to change.

Changed

  • [CI][Reality] release.yml gates Fly deploy + crates.io publish + Helm chart push on the release job’s cargo test --workspace --release (#447, #526)
    • All three downstream jobs (deploy-registry, publish, helm) now needs: release. A tag with red tests no longer ships to Fly / crates.io / the Helm repo.
  • [DevX] pr_generation moved out of mockforge-core into mockforge-intelligence and the intelligence → core cycle was broken (#562 phase 1, #571)
    • mockforge-intelligence dropped its mockforge-core dep, freeing mockforge-core to take a mockforge-intelligence dep. mockforge_core::pr_generation is preserved as a pub use re-export for backwards compat.

Fixed

  • [DevX] CI rust-cache no longer poisons builds with dangling target/*.d paths (#446, #570)

    • CARGO_HOME switched from per-run to per-runner-name so cached dep-info paths remain valid across runs on the same runner. Swatinem/rust-cache@v2 invocations now partition the cache key by runner.
  • [Reality] Client-side “Connections opened” counter now appears for --rps-only runs (#79 round 6 follow-up, #543)

    • Root cause: the parser was reading http_req_connecting.values.count from k6’s summary.json, but k6’s Trend metric never emits a count field — only avg/min/med/max/p(90)/p(95). The field was always absent, so tcp_connect_samples was always 0 and the connection-count line never printed for non---cps runs.
    • Fix: the generated k6 script now declares a dedicated mockforge_connections_opened Counter and increments it whenever res.timings.connecting > 0 (i.e. a fresh TCP socket was opened). The Rust parser reads this Counter’s count directly. Works for both --cps runs (≈ total requests) and pooled-reuse runs (≈ vus_max).
    • Also: TCP-connect / TLS-handshake timing lines now print whenever the Trend has a non-zero avg, not when count > 0 (which was unreliable). New test_connections_opened_counter_present regression test guards both the Counter declaration and the per-request increment.
  • [Reality] --scenario constant now runs at full VU concurrency from t=0 (#79 round 6 follow-up, #543)

    • Root cause: Srikanth reported that --vus 5 -d 600s took until the ~6-minute mark to reach 5 VUs and then ramped DOWN. The k6 template always wrote startVUs: 0, so even --scenario constant’s single {duration: '600s', target: 5} stage made ramping-vus linearly interpolate from 0 → 5 across the whole window.
    • Fix: for Constant, startVUs is seeded at max_vus so concurrency is at full from the start. Ramping scenarios (RampUp/Spike/Stress/Soak) still start at 0 and let their stages drive the curve. Guarded by test_constant_scenario_starts_at_target_vus.
  • [Cloud][Reality] Cloud Resilience dashboard could not reach hosted mocks over Fly 6PN (#468 follow-up, #542, #544)

    • mockforge serve --admin was binding the admin port to 127.0.0.1, so the registry proxy’s {fly-app}.internal:9080 reach failed silently (#542 — bind dual-stack). UI’s /api/resilience/* paths also sat behind auth middleware that doesn’t run in proxied cloud mode, so the proxy’s outbound calls 401’d (#544 — explicit exempt prefix). Both fixes were needed for the cloud Resilience tab to render live state instead of perpetual runtime_state: unreachable.
  • [UI][Build] Allow esbuild / vue-demi build scripts under pnpm 11’s managed-builds policy (#525, #533)

    • pnpm-workspace.yaml declares the two packages in onlyBuiltDependencies so production docker builds succeed.
  • [UI][Build] Pin pnpm to 10.15.0 in the docker stages (#525 follow-up, #536)

    • 10.15.0 predates the managed-builds policy that triggered #525 in the first place.
  • [UI][Cloud] Hide api-explorer from cloud sidebar (#459 follow-up, #537)

  • [CI][Docker] Explicit cosign login so signature push to GHCR succeeds (#546)

Cloud-parity meta tracker

This release closes #459 — the cloud-parity meta tracker for the 14 “Local only” nav items. 14 / 14 addressed: 8 shipped end-to-end across prior releases (Graph #460, Virtual Backends #461, Logs #462, Metrics-folded #463, World State #464, Observability #465, Performance-folded #467, Resilience #468), 4 explicitly kept local-only (Proxy Inspector #470, SMTP Mailbox #471, MQTT Broker #472, Kafka Broker #473), 2 land in this release (Time Travel #466, Test Generator #469).

[0.3.132] - 2026-05-12

Added

  • [Reality] Full chaos fault-category coverage in stats and /metrics (#79 round-4)
    • connection_error fault now records at the HTTP layer when connection_error_kind: http_503 (previously only TCP-level kinds had counters). New jitter and bandwidth_throttle counters + matching Prometheus histograms (mockforge_chaos_jitter_ms, mockforge_chaos_bandwidth_throttle_ms{direction}). ChaosStatsSnapshot gains mean latency, jitter samples + mean offset, and bandwidth-throttle totals. TUI Chaos Fault Stats panel renders all of them.
  • [Reality] Bench client surfaces server-injected chaos signals (#79 item 7)
    • HTTP chaos middleware stamps X-Mockforge-Injected-Latency-Ms, -Injected-Jitter-Ms, and -Fault response headers. Generated k6 script reads them into custom trends (mockforge_server_injected_latency_ms, mockforge_server_injected_jitter_ms) and a counter (mockforge_server_fault_total). Bench summary prints a new Server-Injected (chaos) block alongside client-observed latency.
  • [DevX] New bench CLI flags --rps and --cps (#79 item 8)
    • --rps N switches the k6 executor from ramping-vus to constant-arrival-rate at N requests/sec (and drops the per-iteration sleep(1) that previously capped throughput at ~2 RPS). --cps sets noConnectionReuse: true so each request opens a fresh TCP/TLS connection — useful for stressing connection-limit chaos and TCP-level fault injection.
  • [Reality] Opt-in MOCKFORGE_HTTP_KEEPALIVE_HINT=1 advertises Connection: keep-alive + Keep-Alive: timeout=N, max=M on every response (#79 item 2 workaround)
    • For proxies (F5/Avi/HAProxy/nginx) that read those headers when deciding to pool upstream sockets. Best-effort signal; the actual fix for the FIN-after-response pattern is upstream HTTP/1.1 negotiation in the proxy itself.

[0.3.131] - 2026-05-10

Added

  • [Reality] TUI Chaos screen now surfaces live fault-injection counts (#79 follow-up)
    • New ChaosStatsSnapshot and GET /api/chaos/stats (+ admin passthrough at /__mockforge/chaos/stats).
    • Fault Stats panel below Settings shows totals + per-fault-type counts. Older servers without the endpoint fall back to the 2-panel layout.

[0.3.130] - 2026-05-10

Fixed

  • [Reality] mockforge_chaos_* counters silently absent from /metrics (#79 follow-up)
    • Chaos counters register against the global prometheus::default_registry(); /metrics was exporting only the local MetricsRegistry. The two were disjoint, so chaos counters never surfaced. metrics_handler now gathers from both. No format change for scrapers.
  • [Reality] LatencyInjectionConfig / RateLimitingConfig / NetworkShapingConfig rejected partial YAML
    • Missing fields broke the whole config load (e.g. traffic_shaping: without max_connections). Adding Default + #[serde(default)] makes partial YAML parse cleanly.

[0.3.129] - 2026-05-09

Added

  • [Reality] YAML config now exposes every chaos fault_injection field (#79 follow-up)
    • mockforge_core::config::FaultConfig gains connection_error_kind, partial_responses + partial_response_probability, payload_corruption + payload_corruption_probability, corruption_type, error_pattern (Burst / Random / Sequential), mockai_enabled, and request_matcher. All #[serde(default)] so existing chaos.yaml files keep parsing.
    • The bridge in serve.rs now maps every field through to mockforge_chaos::config::FaultInjectionConfig; previously these were silently defaulted at YAML load time and only the PUT /api/chaos/config/faults REST API could set them.

[0.3.128] - 2026-05-09

Fixed

  • [DevX] k6 metric-name validation failure on deeply nested OpenAPI specs (Microsoft Graph etc.) (#436, #79)
    • Root cause: operationIds like drives.drive.items.driveItem.workbook.worksheets.workbookWorksheet.charts.workbookChart.axes.categoryAxis.format.line.clear, after dot-to-underscore sanitization plus _latency / _errors suffix, exceeded k6’s 128-char metric-name cap. validate_script correctly rejected the script before k6 ran.
    • New K6ScriptGenerator::sanitize_k6_metric_name caps the base at 112 chars (128 − 16 for _step99_latency) and appends an 8-hex-char hash of the original name when truncating, so distinct long names produce distinct metric names. JS variable identifiers keep the full readable form; only the metric string is truncated.
    • Wired into both render paths: k6_script.hbs (per-operation) and k6_crud_flow.hbs. Tests cover passthrough, truncation, prefix-collision uniqueness, the “starts with letter or _” rule after truncation, and end-to-end script validation on a microsoft-graph-style operationId.
  • [Reality] Chaos prometheus counters were registered but never incremented (#436, #79)
    • mockforge_chaos_faults_total{fault_type, endpoint}, mockforge_chaos_latency_ms, and mockforge_chaos_rate_limit_violations_total all existed in the registry, but no caller invoked the corresponding record_* methods. /metrics reported zero faults regardless of how many were actually firing — masking the effect of configured chaos rules from operators.
    • Wired record_fault(...) at every fault decision point in the HTTP middleware (http_error, timeout, rate_limit, connection_limit, packet_loss, partial_response, payload_corruption) and the TCP chaos listener (tcp_reset, tcp_close). Latency injection also now records to the histogram via record_latency.
    • The TUI Chaos screen still renders config-only; surfacing these counters as a stats panel is tracked as a follow-up.

[0.3.127] - 2026-05-08

Fixed

  • [Reality] TPS / RPS200 dashboard counters stuck at 0 under load (#351, #79)
    • Metrics middleware (collect_http_metrics) was never .layer()d on the production router built in serve.rs. CPS still advanced because CountingMakeService wraps the make-service at a different layer.
    • Layer collect_http_metrics as the outermost wrapper on http_app so every response — including chaos-mutated ones — bumps the rate counters the dashboard sampler reads.

Added

  • [DevX] bench-chunked accepts --base-path, humantime --duration, --validate-requests, --export-requests (#352, #79)
    • --base-path <PATH> prepends to every spec-derived operation path before URL construction. CLI > spec.servers > none.
    • -d 600s / --duration <DURATION> switched from bare seconds (u64) to humantime parsing.
    • --validate-requests and --export-requests mirror the flags already on mockforge bench.
  • [DevX] Supervisor wrappers for unattended runs under heavy traffic (#350, #79)
    • deploy/systemd/mockforge.service — systemd unit with Restart=always.
    • deploy/scripts/run-forever.sh — bash supervisor that restarts the binary after any non-clean exit.

[0.3.73] - 2026-03-05

Fixed

  • [UI] Fix cargo publish failure for mockforge-ui caused by build.rs modifying source directory
    • Removed code that copied pwa-manifest.json and sw.js into ui/dist/ during build (violates cargo’s source-dir-immutability rule)
    • serve_service_worker now reads sw.js from ui/public/ (same pattern as serve_manifest)
    • Added sw.js to the crate’s include list so it’s packaged correctly
  • [Core] Mock server now supports X-Mockforge-Response-Status header to return non-default status codes (#79)
    • Conformance checks for response:404 and response:400 previously always failed because the server returned the first declared status (usually 200)
    • New has_response_for_status() validates the requested code exists in the spec before overriding
    • Both OpenAPI handler paths extract and pass the header through
  • [Core] Response generation no longer replaces object-typed properties with string examples (#79)
    • When a property schema declares type: object, the fallback now preserves an empty {} instead of generating a name-based string like "example config"
    • Fixes response:schema:validation failures where JSON schema validation rejected string values for object properties
    • Added is_object_typed_property() helper for type-aware fallback decisions
  • [Data] generate_by_type("object") now returns {} instead of "unknown_type_object" (#79)
    • Also added "array" handler returning []

Changed

  • [Bench] Spec-driven conformance generator now sends X-Mockforge-Response-Status header for response:400 and response:404 checks (#79)
    • Tells the mock server which status code to return, enabling accurate status-code conformance testing

[0.3.72] - 2026-03-04

Fixed

  • [UI] mockforge serve --admin no longer panics when no production auth is configured (#79)
    • validate_auth_config_on_startup() now logs a warning instead of returning an error
    • Auto-generated JWT secret fallback so the admin UI works out of the box
    • Default users are seeded even without ENVIRONMENT=development, so login works immediately
  • [Bench] Fix duplicate session ID in conformance Cookie headers (#79)
    • Removed invalid noCookies: true from k6 options (not a real k6 option; k6 silently ignores it)
    • Added http.cookieJar().clear(BASE_URL) before and after each request when custom Cookie headers are present
    • Prevents k6’s internal cookie jar from re-sending server Set-Cookie values alongside custom headers
    • Applied to both reference-mode (generator.rs) and spec-driven (spec_driven.rs) generators
  • [Bench] Fix missing single-quote escaping in spec-driven format_headers() (#79)
    • Header values containing single quotes are now properly escaped, matching generator.rs behavior

Added

  • [Bench] Conformance report now shows individual failed checks with pass/fail counts (#79)
    • New “Failed Checks” section after the category summary table lists each check that failed
    • When not using --conformance-all-operations, prints a tip suggesting it for endpoint-level detail

[0.3.70] - 2026-02-27

Fixed

  • [Bench] Remove dead CUSTOM_HEADERS JS const from conformance generators (#79)
    • Custom header values are now inlined directly into each request instead of referencing an unused JS constant
    • Eliminates confusing dead code in generated k6 scripts
  • [Bench] Add noCookies: true to k6 options when Cookie header is in custom headers (#79)
    • Prevents k6’s automatic cookie jar from duplicating cookies on subsequent requests
    • Fixes duplicate session ID / authentication failures reported by @srikr
  • [Bench] Fix conformance report file not found after k6 execution (#79)
    • handleSummary now writes conformance-report.json to an absolute path matching the output directory
    • Previously wrote to a relative path based on k6’s CWD, causing the CLI to report “Conformance report not generated”

Added

  • [Bench] --conformance-all-operations flag for full-endpoint conformance testing (#79)
    • Default mode tests one representative operation per feature check (fast feature-coverage)
    • New flag tests ALL operations with path-qualified check names (e.g., method:GET:/api/users)
    • Addresses user confusion about “only 5 endpoints tested”
  • [Bench] Conformance coverage summary output (#79)
    • After generating conformance tests, prints “Conformance: N operations analyzed, M unique checks generated”
    • When using default mode with fewer checks than operations, shows tip about --conformance-all-operations

[0.3.69] - 2026-02-24

Fixed

  • [Multi] Replace 36+ assert!(true) placeholder tests with meaningful assertions across 16 files
    • CLI command tests (MQTT, SMTP, governance) now construct and verify command variants
    • Registry server tests use compile-time type checks instead of no-op assertions
    • Integration tests (voice workspace, drift GitOps, behavioral cloning, WebSocket, cross-platform sync) use proper verification patterns
  • [gRPC] Add use super::* to 13 empty test_module_compiles() tests so they actually verify module compilation
  • [HTTP] Fix misleading “placeholder” doc comment on fully-implemented get_proxy_inspect handler

[0.3.57] - 2026-02-14

Fixed

  • [Bench] Spec-driven conformance: global security requirement detection (#79)
    • annotate_security() now falls back to spec.security (root-level) when an operation has no operation-level security defined
    • APIs that only define security globally are now correctly detected
  • [Bench] Spec-driven conformance: SecurityScheme type resolution (#79)
    • Security schemes are now resolved from components.securitySchemes to detect actual type (HTTP/bearer, APIKey, HTTP/basic) instead of relying on name heuristics alone
    • A scheme named “myAuth” that is actually an apiKey type is now correctly identified
    • Name-based heuristic retained as fallback for unresolvable schemes
  • [Bench] Spec-driven conformance: ContentNegotiation detection (#79)
    • ContentNegotiation feature is now detected when a response defines multiple content types (e.g., both application/json and application/xml)
    • Previously only worked in reference mode
  • [Bench] CLI help text for --conformance-categories now includes response-validation (#79)

Added

  • [Bench] 5 new conformance tests: ResponseValidation with schema check, global security, SecurityScheme resolution, ContentNegotiation detection, single-type negative case (#79)

[0.3.56] - 2026-02-14

Added

  • [Bench] Conformance category filtering (#79)
    • New --conformance-categories flag to run only specific conformance categories (e.g., --conformance-categories "parameters,security")
    • Case-insensitive category matching with validation against known categories
  • [Bench] Spec-driven conformance testing (#79)
    • When --conformance --spec my-api.json is provided, analyzes the user’s actual OpenAPI spec to detect which features their API exercises
    • Generates conformance tests against real endpoints instead of reference /conformance/ paths
    • Full $ref resolution with cycle detection for parameters, schemas, request bodies, and responses
    • Detects: parameter types, request body formats, schema types/composition/formats/constraints, response codes, security schemes
  • [Bench] Response schema validation (#79)
    • In spec-driven mode, validates response bodies against OpenAPI response schemas
    • SchemaValidatorGenerator produces JavaScript validation expressions from OpenAPI schemas
    • Supports object (required fields, property types), array, string (format regex, enum, length), integer/number (range), boolean validation
    • Wrapped in try-catch for resilient k6 execution
  • [Bench] SARIF 2.1.0 report output (#79)
    • New --conformance-report-format sarif flag outputs conformance results in SARIF 2.1.0 format
    • Compatible with GitHub Code Scanning, VS Code SARIF Viewer, and CI/CD pipelines
    • Maps each conformance feature to a SARIF rule with OpenAPI spec section links
    • Passed features emit level: "note", failed features emit level: "error"

[0.3.55] - 2026-02-14

Added

  • [Bench] Per-server stats in multi-target mode (#79)
    • K6Results now parses RPS, VUs, and full latency breakdown (min/med/p90/p95/p99/max) from k6 summary.json
    • AggregatedMetrics includes total_rps, avg_rps, total_vus_max
    • Multi-target reporter shows per-target RPS, VUs, and full latency breakdown
    • aggregated_summary.json includes all new metrics in both aggregated and per-target sections
  • [Bench] Per-target spec support for multi-target mode (#79)
    • Targets file JSON format now supports "spec" field for per-target OpenAPI specs
    • Each target can use a different spec file for heterogeneous fan-out
    • Example: [{"url": "https://server1", "spec": "spec_a.json"}, {"url": "https://server2", "spec": "spec_b.json"}]
  • [Bench] OpenAPI 3.0.0 conformance testing (#79)
    • New --conformance flag generates and runs comprehensive k6 scripts exercising 47 OpenAPI 3.0.0 features across 10 categories (Parameters, Request Bodies, Schema Types, Composition, String Formats, Constraints, Response Codes, HTTP Methods, Content Negotiation, Security)
    • Reports per-category pass/fail rates with colored terminal output
    • Supports --conformance-api-key, --conformance-basic-auth, --conformance-report for security scheme testing
    • Example: mockforge bench --conformance --target http://localhost:3000

[0.3.54] - 2026-02-13

Fixed

  • [Bench] fix(bench): deliver CRS payloads as path injection + form-encoded body (#79)
    • Added inject_as_path field to SecurityPayload — URI payloads without query params (e.g., CRS 942101: POST /1234%20OR%201=1) now replace the request path via encodeURI() so WAFs inspect REQUEST_FILENAME instead of ARGS
    • Added form_encoded_body field to SecurityPayload — body payloads from CRS tests (e.g., 942432: var=;;dd foo bar) now sent as application/x-www-form-urlencoded so WAFs parse form data into ARGS for character counting
    • Updated k6_script.hbs and k6_crud_flow.hbs templates to handle both new delivery mechanisms
    • Replaced unreliable startsWith('/') URI heuristic in CRUD flow template with explicit injectAsPath flag
    • Expected SQLi detection: 46/46 rules (100%), up from 45/46 (97.8%)

[0.3.53] - 2026-02-13

Fixed

  • [Bench] fix(bench): URL-encode URI payloads + strip form keys from body payloads (#79)
    • URI security payloads now wrapped in encodeURIComponent() for valid HTTP transport — WAFs decode before inspection (fixes 942101)
    • Form-encoded body payloads now have form key prefix stripped (var=;;dd foo bar → ;;dd foo bar) so WAF ARGS parsing sees the attack payload directly (fixes 942432)
    • Confirmed SQLi detection: 45/46 rules (97.8%), up from 43/46 (93.5%)

[0.3.52] - 2026-02-12

Fixed

  • [Bench] fix(bench): Group multi-part WAFBench payloads + decode body payloads + fix Cookie/CookieJar conflict (#79)
    • Multi-part CRS test cases (URI + headers + body) now grouped by group_id and sent together in one HTTP request instead of being split across separate requests (fixes 942290)
    • Body payloads from CRS YAML files are now form-URL-decoded before injection (%22+WAITFOR+DELAY+%27 → " WAITFOR DELAY ') so WAFs see actual SQL patterns in JSON bodies (fixes 942240, 942320, 942432)
    • URI payloads from path-only CRS tests are now URL-decoded and stripped of leading / artifact (fixes 942101)
    • Cookie header payloads no longer overridden by empty CookieJar — secRequestOpts conditionally skips jar: new http.CookieJar() when a security Cookie header is present (fixes 942420, 942421)
    • Added groupedPayloads array-of-arrays in generated k6 scripts; getNextSecurityPayload() returns arrays of related payloads
    • Template loop applies URI/header/body parts simultaneously per request via secPayloadGroup
    • Expected SQLi detection improvement: 37/46 → 44/46 (80.4% → 95.7%)

[0.3.51] - 2026-02-11

Fixed

  • [Bench] fix(bench): Accept all WAFBench CRS payloads without attack-pattern filter (#79)
    • Removed overly strict attack-pattern category filter that was silently dropping valid CRS test cases
    • All CRS YAML test cases now loaded regardless of their attack_type metadata

[0.3.50] - 2026-02-10

Fixed

  • [Bench] fix(bench): Use per-request CookieJar instead of shared EMPTY_JAR (#79)
    • Each HTTP request now creates its own new http.CookieJar() instead of sharing a global empty jar
    • Prevents cookie cross-contamination between requests in security testing

[0.3.49] - 2026-02-09

Fixed

  • [Bench] fix(bench): Send raw security payloads + use dedicated empty cookie jar (#79)
    • Security payloads now sent as raw strings without additional encoding
    • Dedicated empty CookieJar per request prevents k6’s default cookie accumulation

[0.3.48] - 2026-02-08

Fixed

  • [Bench] fix(bench): Cycle security payloads per-operation + clear cookies in API2 tests (#79)
    • Security payloads now cycle per-operation block (each API endpoint gets a different payload)
    • Previously all operations in one VU iteration used the same payload
    • OWASP API2 (Broken Auth) tests now properly clear cookies between requests

[0.3.47] - 2026-02-06

Added

  • [DevX] chore: Add Claude Code setup (CLAUDE.md, agents, skills, hooks, hookify)
    • Project-specific Claude Code configuration with rules, agents, and skills
    • Custom skills for verification, template checking, code review, and bench review
    • Hookify rules engine for behavioral guardrails

Fixed

  • [Bench] fix(bench): Security payloads now injected + cookie dedup in all templates (#79)

    • Security payloads now properly injected in both k6_script.hbs and k6_crud_flow.hbs templates
    • Cookie deduplication applied to all HTTP request paths in both templates
    • Comprehensive test suite added for issue #79 security pipeline
  • [Registry] fix(registry): Add RBAC permission system with Display, AdminAll bypass, and PermissionChecker

    • New RBAC permission model with role-based access control
    • AdminAll role bypasses all permission checks
    • PermissionChecker trait for consistent authorization across endpoints

[0.3.46] - 2026-01-30

Fixed

  • [Bench] fix(bench): WAFBench payloads now distributed across VUs for better coverage (#79)

    • Changed payload cycling to use VU-based offset: (__VU - 1) % payloads.length
    • Previously all 50 VUs started at index 0 and cycled through same sequence
    • Now each VU starts at a different payload, maximizing attack coverage in shorter test runs
    • With 50 VUs and 30 payloads, all payloads are tested from the start
  • [Bench] fix(bench): OWASP API tests now include custom headers in all requests (#79)

    • Added CUSTOM_HEADERS to API8 verbose error test (malformed JSON body test)
    • Added CUSTOM_HEADERS to API9 discovery paths test
    • Added CUSTOM_HEADERS to API9 API versions test
    • Fixes auth failures when using --headers "Cookie:..." with OWASP testing

[0.3.43] - 2026-01-16

Fixed

  • [Bench] fix(bench): Security payloads now actually applied to requests in k6 scripts (#79)
    • Updated k6_script.hbs template to call getNextSecurityPayload() and applySecurityPayload()
    • Previously, security payload functions were defined but never called in generated scripts
    • Security payloads now properly injected into request bodies for POST/PUT/PATCH
    • Header-based payloads now properly injected into request headers

[0.3.42] - 2026-01-15

Fixed

  • [Bench] fix(bench): XSS payloads now inject into ALL string fields, not just the first one (#79)
    • Removed break statement from applySecurityPayload() loop in security_payloads.rs
    • Ensures WAF can detect payloads regardless of which field it scans
  • [Bench] fix(bench): Added jar: null to remaining OWASP HTTP calls to prevent cookie duplication (#79)
    • Fixed testBrokenAuth empty token test
    • Fixed testMisconfiguration verbose error test
    • Fixed testInventory discovery paths and API versions checks
  • [CLI] fix(cli): Fixed format string compilation error in plugin_commands.rs (#79)
    • Escaped all braces ({ → {{, } → }}) inside format! macro for auth plugin template
    • Fixes “invalid format string: expected }, found r” compilation error

[0.3.39] - 2026-01-14

Fixed

  • [Bench] fix(bench): WAFBench XSS attacks now properly injected into request body (#79)
    • Removed location check from applySecurityPayload() - ALL payloads now injected into body for POST/PUT
    • WAFBench payloads correctly pass location info (uri/header/body) to k6 scripts
    • Header payloads include header name for proper injection into specified headers
  • [Bench] fix(bench): Cookie header duplication in OWASP and security tests (#79)
    • Added jar: null to all HTTP request params to disable k6’s automatic cookie jar
    • Prevents duplicate cookies when user provides Cookie header via --headers flag
    • Applied to k6_script.hbs, k6_crud_flow.hbs, and OWASP generator

[0.3.38] - 2026-01-13

Fixed

  • [Bench] fix(bench): pass custom headers from --headers flag to OWASP tests (#79)
    • Cookie and other custom headers are now included in all OWASP request helpers
    • Fixes issue where avi-sessionid=None was being sent instead of actual cookie values
  • [Bench] fix(bench): WAFBench loader now handles single YAML file paths (#79)
    • Previously only directories or glob patterns were supported
    • Single file paths like /path/to/941100.yaml now work correctly
  • [Bench] Verified CRS v3.3 format compatibility with full CoreRuleSet test suite
    • Tested with 175 files, 1512 payloads (692 XSS, 505 SQLi, 304 Command Injection, 11 Path Traversal)

[0.3.37] - 2026-01-12

Added

  • [Bench] feat(bench): add WAFBench cycle-all mode (--wafbench-cycle-all) to test all payloads sequentially (#79)
  • [Bench] feat(bench): add --owasp-iterations parameter to control OWASP test iterations per VU (#79)
  • [Bench] feat(bench): OWASP tests now respect --vus parameter for concurrent testing (#79)

Fixed

  • [Bench] fix(bench): WAFBench payloads now properly injected in standard bench mode (not just CRUD flow)
  • [Bench] fix(bench): OWASP APIs now use random UUIDs per request instead of static IDs for BOLA testing (#79)
  • [Bench] fix(bench): OWASP auth tokens with special characters (quotes, backslashes) now properly escaped (#79)
  • [Bench] fix(bench): prevent Handlebars double-escaping of pre-escaped JavaScript values
  • [Bench] fix(bench): WAFBench security payloads now integrated into CRUD flow requests (#79)
  • [Bench] fix(owasp): use http.del() instead of http.delete() for k6 compatibility (#79)
  • [Bench] fix(owasp): add --base-path support for OWASP API testing (#79)
  • [Bench] fix(bench): remove undefined totalRequestCount variable reference
  • [Bench] fix(bench): support CRS v3.3 WAFBench format and pass --insecure to OWASP tests

[0.3.33] - 2026-01-10

Fixed

  • [Bench] fix(bench): multiple fixes for OWASP and WAFBench testing
    • Support CRS v3.3 format in WAFBench parser
    • Pass --insecure flag to OWASP tests for self-signed certificates

[0.3.31] - 2026-01-08

Fixed

  • [Bench] fix(bench): fix extracted value substitution in CRUD flows
  • [Bench] fix(bench): OWASP k6 configuration improvements

[0.3.30] - 2026-01-07

Added

  • [Bench] feat(bench): add merge_body support for CRUD flows - merge extracted values with request body
  • [Bench] feat(bench): add inject_attacks data model for security testing in CRUD flows

[0.3.28] - 2026-01-06

Added

  • [Bench] feat(bench): add nested path extraction for CRUD flows (e.g., results[0].id)
  • [Bench] feat(bench): add filter extraction for CRUD flows (e.g., results[?name=='test'].id)

[0.3.27] - 2026-01-05

Added

  • [Bench] feat(bench): add full body extraction for CRUD flows
  • [Bench] feat(bench): add key filtering for extracted values

[0.3.26] - 2026-01-04

Added

  • [Bench] feat(bench): add aliased extraction for CRUD flow value chaining
    • Extract values with aliases (e.g., id as poolId) for use in subsequent requests

[0.3.24] - 2026-01-03

Fixed

  • [Bench] fix(bench): use correct variable name in CRUD flow extracted value replacement

[0.3.22] - 2026-01-02

Added

  • [Bench] feat(bench): add OWASP API Security Top 10 testing mode (#79)
    • Test for BOLA (API1), Broken Auth (API2), Mass Assignment (API3), Resource Consumption (API4)
    • Test for Function Auth (API5), SSRF (API7), Misconfiguration (API8), Inventory (API9), Unsafe Consumption (API10)
    • Configurable test categories with --owasp-categories
    • Support for auth tokens with --owasp-auth-token
    • SARIF and JSON report formats

Changed

  • [DevX] chore: include UI dist files for publishing to crates.io

[0.3.21] - 2025-12-31

Fixed

  • [DevX] fix(bench): use custom flow config and fix sequential mode path matching - enables cross-resource dependency chains
  • [DevX] fix(bench): process dynamic placeholders in CRUD flow params file bodies (#79)
  • chore: update benchmark baseline [skip ci]
  • chore: enable publishing for previously internal crates
  • chore: update benchmark baseline [skip ci]
  • fix(release): disable sccache for crates.io publish
  • chore: update benchmark baseline [skip ci]
  • fix(release): publish all crates in dependency order
  • fix(release): add mockforge-core to crates.io publish order
  • chore: update benchmark baseline [skip ci]
  • feat(bench): add –base-path option for API base path support (#79)
  • chore: update benchmark baseline [skip ci]
  • fix(collab): include SQLx query cache for crates.io installation (#79)
  • chore: update benchmark baseline [skip ci]
  • feat: implement optional enhancements from improvement plan
  • fix: update doc tests to use rust,ignore for external dependencies
  • chore: update benchmark baseline [skip ci]
  • chore: add missing crates to workspace and restore path dependencies
  • chore: restore path dependencies after publishing remaining v0.3.17 crates
  • fix: restore all crates to workspace members list
  • chore: restore path dependencies after publishing v0.3.17
  • docs: update CHANGELOG for v0.3.17 release
  • feat(bench): add WAFBench YAML integration for security testing
  • Bump version to 0.3.17
  • feat: comprehensive improvements across AMQP, MQTT, gRPC, registry server, and UI
  • feat(ui): add type safety, mobile layout fixes, and search/filter to frontend
  • Restore path dependencies after publishing v0.3.16
  • Bump version to 0.3.16
  • fix: resolve flaky tests and race conditions across test suite
  • fix: replace panic-prone unwrap calls with safe error handling
  • fix: resolve UUID storage format mismatch in collab crate tests
  • Add multi-spec support and cross-spec dependency detection for bench command
  • feat: add multi-spec support and cross-spec dependency handling to bench command
  • fix: add validation to CRUD flow script generation
  • fix: sanitize k6 CRUD flow metric names (#79 follow-up)
  • Bump version to 0.3.13 and improve changelog
  • Bump version to 0.3.12 and publish to crates.io
  • Bump version to 0.3.11 and publish to crates.io
  • chore: update benchmark baseline [skip ci]
  • feat: add –params-file option for custom parameter values in bench
  • Bump version to 0.3.10 and publish to crates.io
  • chore: update benchmark baseline [skip ci]
  • fix: move insecureSkipTLSVerify to global k6 options (fixes –insecure)
  • chore: update benchmark baseline [skip ci]
  • fix: resolve k6 bench issues with –insecure flag, textSummary, and query params
  • chore: update benchmark baseline [skip ci]
  • chore: bump version to 0.3.9 and update changelog
  • feat: implement comprehensive mock server functionality across all crates
  • chore: commit remaining version updates
  • fix: enable publishing for mockforge-ui
  • fix: enable publishing for mockforge-tunnel
  • fix: update all 0.3.7 dependencies to 0.3.8 with path dependencies
  • fix: add path dependencies for all workspace crates
  • chore: update CHANGELOG date for 0.3.8
  • chore: bump version to 0.3.8
  • Fix cargo publish issues: add version requirements to dependencies
  • chore: update benchmark baseline [skip ci]
  • Apply formatting and additional code changes
  • Fix compilation errors: update dependencies and adapt to API changes
  • fix: remove path from mockforge-pipelines dep in mockforge-collab
  • Add mockforge-sdk, mockforge-ui, mockforge-cli to workspace
  • fix: add mockforge to restore function targets list
  • fix: convert mockforge dev-dependencies to path dependencies
  • fix: add mockforge-core to restore list and manually fix dependency
  • fix: include mockforge-core in restore list
  • fix: restore function now properly handles table-form dependencies without path
  • fix: automatically restore dependencies at start of publish
  • fix: restore all crate dependencies, not just a few
  • fix: only convert dependencies for already-published crates
  • fix: correct publish order - publish mockforge-data before mockforge-core
  • fix: add mockforge-data as optional dependency in mockforge-core
  • chore: bump version to 0.3.6 and update changelog
  • chore: update benchmark baseline [skip ci]
  • Fix k6 script generation and UI icon embedding issues
  • chore: update benchmark baseline [skip ci]
  • Add comprehensive test suite and fix build issues
  • chore: update benchmark baseline [skip ci]
  • docs: add comprehensive performance benchmarks documentation
  • chore: update benchmark baseline [skip ci]
  • fix: implement real functionality in benchmark tests and fix k8s-operator
  • chore: update benchmark baseline [skip ci]
  • fix: filter out ‘change’ directories from benchmark baseline parsing
  • chore: update benchmark baseline [skip ci]
  • chore: update benchmark baseline [skip ci]
  • fix: GitHub Actions workflow cleanup and fixes (#81)
  • chore: restore dependencies after publishing all crates
  • fix: add mockforge-cli to workspace and add metadata to mockforge-k8s-operator
  • fix: add missing crates to workspace (mockforge-sdk, mockforge-http, mockforge-ui, mockforge-k8s-operator)
  • fix: add mockforge-world-state to workspace and publishing order before mockforge-http
  • fix: add mockforge-route-chaos publishing step before mockforge-http
  • fix: add mockforge-route-chaos to dependency targets and publishing order
  • fix: add mockforge-route-chaos to workspace and publishing script
  • fix: add mockforge-route-chaos to publishing order before mockforge-http
  • fix: reduce keywords from 6 to 5 for mockforge-performance
  • fix: reduce keywords to 5 for mockforge-performance (crates.io limit)
  • fix: add mockforge-performance to publishing order before mockforge-http
  • fix: add mockforge-collab to workspace members list
  • fix: add mockforge-collab to workspace members
  • fix: add missing README.md for mockforge-pipelines
  • fix: add mockforge-pipelines to publishing order and dependency targets
  • fix: add mockforge-pipelines to workspace and publishing script
  • fix: add all missing crates to workspace members
  • fix: handle short form dependencies when converting to path
  • fix: publish mockforge-template-expansion before mockforge-core
  • fix: add mockforge-template-expansion to publishing script
  • fix: temporarily convert dependent crates’ dependencies to path before publishing
  • fix: remove argon2 from mockforge-core during MSRV checks
  • fix: exclude mockforge-collab from MSRV checks and remove patch section
  • fix: use awk instead of sed for multi-line patch section insertion
  • fix: use Cargo patch section to pin base64ct for MSRV
  • fix: improve base64ct pinning order in MSRV workflow
  • fix: use exact version constraint for base64ct in MSRV workflow
  • fix: improve base64ct pinning in MSRV workflow
  • fix: pin base64ct to 1.7 for MSRV compatibility
  • fix: exclude mockforge-ui from MSRV checks
  • fix: add abd and existant to typos config
  • fix: exclude FontAwesome and all minified files from spell check
  • fix: also remove sysinfo from mockforge-ui during MSRV checks
  • fix: exclude elasticlunr.min.js from spell check
  • fix: exclude highlight.js from spell check
  • fix: disable sysinfo feature during MSRV checks
  • fix: sync sysinfo to 0.37, fix resolvable typo, exclude ace.js from spell check
  • fix: pin sysinfo to 0.36, fix typos, improve MSRV workaround
  • fix: update MSRV to 1.80 and add GraphQL exclusion workaround
  • fix: update MSRV from 1.82 to 1.75
  • fix: fix GitHub Actions workflow failures
  • fix: standardize dependencies and fix all test failures
  • Skip CRDs in kubectl validation to avoid server connection
  • Fix kubectl validation to prevent server connection attempts
  • Fix kubectl validation to skip server connection
  • Fix all test failures and resolve dependency conflicts
  • Fix k6 metric name validation error (issue #79) (#80)
  • Optimize workflows: update deprecated actions and add path filters
  • Fix mockforge-smtp version constraint from 0.2.0 to 0.3.3
  • Fix Docker build, k8s validation, and spell check issues
  • fix: update all mockforge dependency versions to 0.3.3 in mockforge-http
  • chore: fix formatting (pre-commit hooks)
  • deps(deps): bump opentelemetry_sdk from 0.21.2 to 0.31.0 (#67)
  • chore: update benchmark baseline [skip ci]
  • deps(deps): bump opentelemetry-semantic-conventions (#66)
  • chore: update benchmark baseline [skip ci]
  • deps(deps): bump sysinfo from 0.32.1 to 0.37.2 (#60)
  • deps(deps): bump wasmparser from 0.239.0 to 0.240.0 (#64)
  • deps(deps): bump governor from 0.6.3 to 0.8.1 (#61)
  • chore: update benchmark baseline [skip ci]
  • deps(deps): bump mail-parser from 0.9.4 to 0.11.1 (#63)
  • deps(deps): bump rumqttc from 0.24.0 to 0.25.0 (#65)
  • deps(deps): bump ndarray from 0.16.1 to 0.17.1 (#76)
  • chore: update benchmark baseline [skip ci]
  • ci(deps): bump azure/setup-helm from 3 to 4 (#72)
  • ci(deps): bump actions/upload-artifact from 4 to 5 (#71)
  • deps(deps): bump image from 0.24.9 to 0.25.9 (#77)
  • deps(deps): bump rustls from 0.21.12 to 0.23.35 (#78)
  • chore: update benchmark baseline [skip ci]
  • Bump all crates to version 0.3.3
  • Format code with rustfmt
  • Fix k6 script generation with operation IDs containing dots/hyphens
  • chore: update benchmark baseline [skip ci]
  • perf: optimize template rendering by avoiding unnecessary operations
  • chore: update benchmark baseline [skip ci]
  • docs: update benchmark documentation with final optimizations
  • perf: fix benchmark regressions and optimize measurements
  • chore: update benchmark baseline [skip ci]
  • Fix Kafka compilation errors and borrow checker issues
  • feat: Implement cross-pillar enhancements - World State Engine, MOD, and Performance Mode
  • feat(ai-studio): Add API Critique, System Generator, and Behavioral Simulator
  • chore: rework UI/UX to be more AI native
  • fix: Address pre-commit security vulnerabilities
  • feat: Implement Invisible Mock Server experience (DevX Pillar)
  • feat(security): implement email, Slack, and webhook notification services
  • Refactor template expansion for Send safety
  • chore: Restore path dependencies after 0.3.2 publish
  • Fix: Complete SQLx query cache for mockforge-collab 0.3.2
  • chore: update mockforge dependencies to version 0.3.1 across multiple crates
  • fix: improve dependency conversion for optional dependencies and fix publishing order
  • fix: update publish script to handle Phase 1 crate dependencies correctly
  • feat: add comprehensive integration tests for 0.3.0 features and update changelog
  • feat: Complete pillar enhancement gaps - VS Code extension and docs
  • feat: Implement pillar tagging system and documentation enhancements
  • feat: Implement MockForge AI Studio - Unified AI Copilot
  • feat(cloud): Complete Cloud pillar implementation and fix compilation issues
  • [DevX] Add JSON Schema support for config validation and IDE autocompletion
  • feat: Implement Contract Fitness Functions, Consumer Impact Analysis, and Multi-Protocol Contracts
  • feat: Enhance Reality feature with observability, cross-protocol consistency, and time-aware lifecycles
  • fix: use proper vosk API by matching on CompleteResult enum
  • fix: resolve all compilation errors
  • chore: prepare release 0.3.0
  • feat: Implement LLM Studio - Natural Language Workspace Creation (0.3.4)
  • feat: Complete Behavioral Cloning v1 implementation and refactor architecture
  • feat: Implement Drift Budget & GitOps for API Sync + AI Contract Diff
  • feat: implement Scenario Studio Visual Editor with React Flow
  • feat: implement AI-Native Interface Deepening features
  • feat: Implement Time Travel & Snapshots and Frontend X-Ray Mode
  • feat(sdk): Add Contract-Backed Types and Scenario-First SDKs to Vue, Svelte, and Angular
  • Format code: Apply rustfmt and whitespace cleanup
  • Release v0.2.9: Update version, CHANGELOG, and publish all crates to crates.io
  • Add registry server improvements, password reset, metrics, and marketplace enhancements
  • security: Upgrade wasmtime to 36.0.3 to fix RUSTSEC-2025-0118
  • feat: Fix compilation errors and implement comprehensive E2E test suite
  • fix: implement custom routes, template expansion, latency injection, and init improvements
  • feat: Smart Personas with array generation and relationship inference
  • feat: Complete Java and .NET SDK implementations with builder patterns
  • fix: update all test files for new function signatures
  • fix: resolve all compilation errors across workspace
  • Complete Phase 3 security controls implementation
  • Add cloud monetization infrastructure and features
  • Implement organization management endpoints
  • Fix Axum 0.8 route syntax in state_machine_api.rs
  • Fix file server route syntax for Axum 0.8 compatibility
  • Release v0.2.8: Publish all crates to crates.io
  • chore: bump version to 0.2.8
  • feat: Complete Generative Schema Mode and achieve 100% roadmap completion
  • Implement Smart Personas feature for consistent cross-endpoint data generation
  • Add Reality Continuum feature for blending mock and real data sources
  • Implement Voice + LLM Interface with STT backends
  • Implement complete Deceptive Deploy feature
  • Add GraphQL + REST Playground with workspace filtering
  • Implement ForgeConnect SDK with full feature set
  • Add enhanced scenario marketplace features
  • Configure SQLx and integrate mockforge-collab with mockforge-core
  • Fix test compilation errors in reality integration and hot-reload tests
  • Implement Reality Slider feature with hot-reload support
  • Complete latency recording integration and fix WorkspaceConfig reality_level field
  • style: Apply rustfmt formatting to Chaos Lab code
  • feat: Add Chaos Lab interactive network condition simulation
  • Fix test compilation errors in openapi_generator_tests
  • Fix all compilation errors for AI Contract Diff feature
  • Add WireMock-inspired features: browser proxy mode, git sync, data sources, template library, managed hosting docs, and user management
  • Add comprehensive ecosystem and use cases documentation
  • Complete configuration and extensibility implementation
  • Add advanced behavior and simulation features
  • Fix test and benchmark compilation errors
  • Complete Scenario State Machines 2.0 with sub-scenario execution
  • Implement VBR Engine enhancements: OpenAPI integration, M2M relationships, seeding, ID generation, snapshots
  • Add mock-to-real migration pipeline with per-route toggling
  • Add Data Scenarios Marketplace feature
  • feat: Implement ForgeConnect - Front-End Integrated Mode for browser-based mock creation
  • Add MockForge Cloud Graph visualization with real-time updates and export
  • Add data personality profiles system for consistent mock data generation
  • Add realistic network conditions and chaos lab with interactive UI controls
  • Add temporal simulation with CLI commands and scenario support
  • Complete MockAI implementation with query params and session recording
  • Add Virtual Backend Reality (VBR) engine
  • Add multipart form data support and file generation/serving for API mocks
  • fix: update mockforge-plugin-sdk to use workspace version
  • fix: enable publishing for mockforge-tunnel and add to publish script

[0.3.20] - 2025-12-31

Fixed

  • [Bench] Dynamic placeholder expansion in CRUD flow params file bodies (#79): Fixed ${__VU}, ${__ITER}, and other dynamic placeholders not being expanded when used in request body content from params files
    • Previously, placeholders like "name": "HTTP-WAAP-vsvip-${__VU}-${__ITER}" were sent literally to the API
    • Now properly converted to k6 template literals for runtime evaluation
    • Supports all dynamic placeholders: ${__VU}, ${__ITER}, ${__TIMESTAMP}, ${__UUID}, ${__RANDOM}, ${__COUNTER}, ${__DATE}, ${__VU_ITER}

[0.3.19] - 2025-12-30

Added

  • [DevX] API base path support for bench command (#79): New --base-path option to prepend a path prefix to all API endpoints in generated load tests
    • Automatically extracts base path from OpenAPI spec’s servers URL (e.g., https://api.example.com/api/v1 → /api/v1)
    • CLI option takes priority over spec’s base path for explicit control
    • Use --base-path "" to disable base path even if spec defines one
    • Works with both standard k6 scripts and CRUD flow mode
    • Example usage:
      # Auto-detect from spec's servers URL
      mockforge bench --spec api.yaml --target http://localhost:8080 --crud-flow
      
      # Explicitly set base path
      mockforge bench --spec api.yaml --target http://localhost:8080 --base-path /api
      
      # Disable base path
      mockforge bench --spec api.yaml --target http://localhost:8080 --base-path ""
      

[0.3.18] - 2025-12-29

Fixed

  • [Collab] SQLx offline mode for crates.io installation (#79): Fixed compilation errors when installing mockforge-collab from crates.io
    • Added .sqlx query cache directory with 51 precompiled query metadata files
    • The build.rs now automatically enables SQLX_OFFLINE=true when query cache is present
    • Users no longer need DATABASE_URL or to run cargo sqlx prepare to install the crate
    • Resolves “set DATABASE_URL to use query macros online” compilation errors

[0.3.17] - 2025-12-28

Added

  • [DevX] WAFBench YAML integration for security testing: New --wafbench-dir flag to import Microsoft WAFBench CRS (Core Rule Set) attack patterns

    • Parse WAFBench YAML test files from the WAFBench project
    • Support glob patterns for loading specific rule categories (e.g., REQUEST-941-* for XSS, REQUEST-942-* for SQLi)
    • Extract attack payloads from URI parameters, headers, and request bodies
    • Automatic CRS rule ID parsing from test metadata (e.g., 941100 for XSS attacks)
    • Integrate WAFBench payloads with existing security testing framework
    • Example usage:
      mockforge bench spec.yaml --wafbench-dir ./wafbench/REQUEST-941-*  # XSS rules
      mockforge bench spec.yaml --wafbench-dir ./wafbench/**/*.yaml      # All rules
      
  • [DevX] Per-URI control mode for data-driven testing (#79): New --per-uri-control flag for CSV/JSON data files that allows each row to specify HTTP method, URI, body, query params, headers, attack type, and expected status code

    • Enables fine-grained control over test requests directly from data files
    • Supports security testing per-URI with attack_type column
    • Automatic status validation with expected_status column
    • Example CSV format:
      method,uri,body,query_params,headers,attack_type,expected_status
      GET,/virtualservice,,include_name=true,,,200
      POST,/virtualservice,"{""name"":""test""}",,,sqli,201
      
  • [Protocol] AMQP TLS support: Full TLS/SSL support for AMQP broker with configurable certificates

  • [Protocol] MQTT protocol improvements: Enhanced MQTT server with TLS, session management, and metrics

  • [Protocol] gRPC dynamic service improvements: Better dynamic proto loading and error handling

  • [Registry] Security enhancements: CSRF protection, request ID middleware, trusted proxy support, token revocation

  • [UI] Frontend improvements: Type safety fixes, mobile layout improvements, search/filter functionality

Changed

  • Comprehensive dependency updates across workspace crates

Fixed

  • [DevX] CRUD flow params file integration (#79): Fixed --params-file not being applied in CRUD flow mode
    • Body configurations from params file are now correctly applied to POST/PUT/PATCH operations in --crud-flow mode
    • Fixed body serialization issue that caused “ReferenceError: object is not defined” error in generated k6 scripts
    • Body is now properly serialized as a JSON string for the Handlebars template
  • [Core] Race conditions and flaky tests: Resolved timing issues across test suite
  • [Core] Panic-prone unwrap calls: Replaced with safe error handling throughout codebase

[0.3.16] - 2025-12-27

Added

  • Version bump with dependency updates

Fixed

  • [Test] Flaky test fixes: Resolved race conditions and timing issues in integration tests
  • [Core] Safe error handling: Replaced panic-prone .unwrap() calls with proper error handling

[0.3.15] - 2025-12-26

Added

  • [DevX] Multi-spec support for bench command: The mockforge bench command now supports loading and merging multiple OpenAPI specifications
    • Multiple --spec flags: mockforge bench --spec pools.yaml --spec vs.yaml --target https://api.com
    • Directory discovery with --spec-dir: mockforge bench --spec-dir ./specs/ --target https://api.com
    • Conflict resolution strategies with --merge-conflicts: error (default), first, last
    • Spec mode selection with --spec-mode: merge (default) combines all specs, sequential runs specs in dependency order
    • Sequential execution mode with per-spec output directories and results
    • Leverages existing multi-spec infrastructure from mockforge-core
  • [DevX] Cross-spec dependency detection: New spec_dependencies module for handling dependencies between specs
    • Automatic detection of dependencies from field naming patterns (pool_ref, pool_id, poolId, etc.)
    • Schema registry for cross-referencing schemas across multiple specs
    • Topological sorting for correct execution order
    • Manual dependency configuration via --dependency-config (YAML/JSON)
    • Support for value extraction and injection between spec groups

Changed

  • BenchCommand.spec field changed from PathBuf to Vec<PathBuf> to support multiple specs
  • SpecParser now includes from_spec() method for pre-loaded OpenAPI specs
  • Added dependency_config field to BenchCommand for cross-spec value passing configuration

Fixed

  • Nothing yet.

[0.3.14] - 2025-12-26

Added

  • Version bump to 0.3.14

Changed

  • Nothing yet.

Fixed

  • Nothing yet.

[0.3.13] - 2025-12-24

Fixed

  • [DevX] k6 CRUD flow metric name sanitization (#79 follow-up): Fixed invalid k6 metric names in CRUD flow scripts when flow names contain dots or special characters
    • CRUD flow names are now sanitized for use as k6 metric names (e.g., plans.list → plans_list)
    • Original flow names preserved in comments and group names for readability
    • Made sanitize_js_identifier function public for reuse across k6 generators
    • Added script validation to CRUD flow generation for defense in depth

[0.3.12] - 2025-12-23

Changed

  • [DevX] Dependency updates: Version alignment and dependency updates across all workspace crates

[0.3.11] - 2025-12-19

Added

  • [DevX] Custom benchmark parameters: Added --params-file option to mockforge bench command for loading custom parameter values from a file

    Why it matters: Allows users to define reusable parameter configurations for benchmark runs, making it easier to test different scenarios without modifying command-line arguments each time.

[0.3.10] - 2025-12-18

Fixed

  • [DevX] k6 benchmark script generation fixes: Resolved multiple issues with generated k6 scripts
    • Fixed --insecure flag handling by moving insecureSkipTLSVerify to global k6 options
    • Fixed textSummary import and usage in generated scripts
    • Fixed query parameter encoding in benchmark requests

[0.3.9] - 2025-12-17

Added

  • [Reality] Comprehensive Mock Server Implementation: Full implementation across all protocol crates

    • mockforge-amqp: Complete AMQP 0-9-1 broker with exchanges, queues, bindings, messages, protocol handling, fixtures, and spec registry
    • mockforge-kafka: Full Kafka broker with consumer groups, partitions, topics, metrics, and protocol handling
    • mockforge-mqtt: Complete MQTT broker with QoS levels, topic subscriptions, and retained messages
    • mockforge-ftp: Virtual filesystem, spec registry, and fixture support
    • mockforge-smtp: Email server with fixtures and spec registry
    • mockforge-tcp: TCP server with fixtures and protocol support
    • mockforge-grpc: Dynamic proto parser, service generator, reflection, and metrics
    • mockforge-graphql: Full handler implementations
  • [DevX] Enhanced CLI Commands: New commands for all protocols and features

    • AMQP, Kafka, MQTT, FTP, SMTP protocol commands
    • Blueprint, cloud, deploy, dev-setup, governance commands
    • Logs, progress, recorder, scenario, snapshot commands
    • Time manipulation, VBR, voice, wizard, and workspace commands
    • AI-powered mock generation commands
  • [Reality] Virtual Backend Repository (VBR): Complete data management system

    • API generator, entity management, constraints, and validation
    • Database integration with migrations and schema management
    • Session handling, snapshots, and mutation rules
    • ID generation strategies and scheduling
  • [Reality] World State Engine: Coherent world simulation

    • State engine with model and query support
    • Entity relationships and lifecycle management
  • [AI] Enhanced AI Capabilities: AI-powered mock generation

    • RAG-based AI response generator
    • AI event generator for WebSocket scenarios
    • Behavioral cloning with scenario types
  • [Cloud] Collaboration Features: Team collaboration support

    • Backup, merge, and promotion workflows
    • Multi-environment configuration
    • Client SDK improvements
  • [DevX] Observability & Analytics: Enhanced monitoring

    • Pillar usage tracking and analytics queries
    • Metrics middleware and coverage tracking
    • Latency metrics and performance monitoring
  • [Contracts] Chaos Engineering: Resilience testing capabilities

    • Failure designer and incident replay
    • Chaos API with configurable fault injection
    • Route-level chaos with latency distributions
  • [DevX] Plugin System Enhancements: Extended plugin capabilities

    • Backend generator and datasource support
    • Runtime adapter improvements
    • SDK builders and testing utilities
  • [Cloud] Registry Server: Complete registry implementation

    • Authentication, authorization, and RBAC
    • Redis caching, email notifications
    • Organization and subscription models
    • API token management and audit logging
  • [DevX] UI Server: Dashboard and admin features

    • Admin handlers for workspace management
    • Chain visualization and coverage metrics
    • Failure analysis and promotion workflows
    • Graph visualization and health monitoring

[0.3.8] - 2025-01-27

Fixed

  • [DevX] Compilation errors resolved: Fixed all compilation errors across the workspace

    • Updated axum-server from 0.6 to 0.8 with tls-rustls-no-provider feature
    • Updated rustls from 0.21 to 0.23, rustls-pemfile from 1.0 to 2.0, tokio-rustls from 0.24 to 0.26
    • Adapted TLS code to rustls 0.23 API (CertificateDer, PrivateKeyDer, WebPkiClientVerifier)
    • Fixed multi_spec module: properly exported and resolved compilation errors
    • Fixed handle_serve function calls: added missing parameters and fixed type mismatches
    • Fixed borrow checker issues in multi_spec merging logic
    • Added missing documentation for enum variants and struct fields
    • Fixed various type mismatches and iteration patterns
  • [DevX] Cargo publish readiness: Fixed all dependency version requirements for crates.io publishing

    • Added version requirements to all path dependencies in mockforge-cli, mockforge-chaos, mockforge-http, mockforge-route-chaos, mockforge-vbr
    • Set publish = false for desktop-app and tests packages (not meant for crates.io)
    • All crates now pass cargo publish --dry-run validation

[0.3.6] - 2025-11-25

Fixed

  • [DevX] k6 script generation with operation IDs containing dots/hyphens (#79)

    • Fixed “Unexpected token .” error when OpenAPI operation IDs contain dots (e.g., plans.create) or hyphens (e.g., plans.update-pricing-schemes)
    • Changed is_alphanumeric() to is_ascii_alphanumeric() in JavaScript identifier sanitization to ensure ASCII-only identifiers
    • All operations are now properly included in generated k6 scripts with valid JavaScript identifiers
    • Added comprehensive tests including integration test with full billing subscriptions spec
  • [DevX] UI icon embedding for published crates

    • Fixed build failures when installing mockforge-cli from crates.io due to missing icon files
    • Updated build.rs to read icon files at build time and embed them as byte array literals
    • Replaced include_bytes! with CARGO_MANIFEST_DIR approach that failed in published crates
    • Icons are now properly embedded and work both in development and when installing from crates.io

[0.3.0] - 2025-11-17

Added

  • [DevX] Pillars & Tagged Changelog: Complete pillar system implementation with documentation and tooling

    • Defined five foundational pillars: [Reality], [Contracts], [DevX], [Cloud], [AI]
    • Added comprehensive PILLARS.md documentation with feature mappings
    • Implemented CI validation for pillar tags in changelog entries
    • Added pillar tagging instructions to release tooling
    • Updated README and getting-started guide with pillars section

    Why it matters: Clear product story spine that makes it obvious what each release invests in. Pillar tags help users understand product direction and find features relevant to their needs.

  • [Reality] Smart Personas & Reality Continuum v2: Complete persona graph and lifecycle system

    • Persona graphs with relationship linking across entities
    • Lifecycle states (NewSignup, Active, PowerUser, ChurnRisk, Churned, etc.)
    • Reality Continuum integration with field-level and entity-level mixing
    • Fidelity score calculation and API endpoint
    • Comprehensive PERSONAS.md documentation

    Why it matters: Upgrade from “random-but-consistent fake data” to “coherent world simulation.” Personas maintain relationships across endpoints, and fidelity scores quantify how real your mock environment is.

  • [Contracts] Drift Budget & GitOps for API Sync: Complete drift management system

    • Hierarchical drift budget configuration (global, workspace, service, endpoint)
    • Breaking change detection and classification
    • Incident management with webhook integration
    • GitOps PR generation for contract updates
    • Comprehensive DRIFT_BUDGETS.md documentation

    Why it matters: Make MockForge the “drift nerve center” for contracts. Define acceptable drift, get alerts when budgets are exceeded, and automatically generate PRs to update contracts and fixtures.

  • [Reality] Behavioral Cloning v1: Multi-step flow recording and replay

    • Flow recording with request/response capture and timing
    • Flow viewer with timeline visualization
    • Scenario replay engine with strict/flex modes
    • Scenario storage and export/import (YAML/JSON)
    • Comprehensive BEHAVIORAL_CLONING.md documentation

    Why it matters: Move from endpoint-level mocks to journey-level simulations. Record realistic flows from real systems and replay them as named scenarios for comprehensive testing.

  • [AI][DevX] LLM/Voice Interface for Workspace Creation: Natural language to complete workspace

    • Natural language workspace creation from descriptions
    • Automatic persona and relationship generation
    • Behavioral scenario generation (happy path, failure, slow path)
    • Reality continuum and drift budget configuration from NL
    • Voice and text input support
    • Comprehensive LLM Studio documentation

    Why it matters: The golden path: “Describe the system in natural language → MockForge builds a realistic mock backend with personas, behaviors, and reality level config.” No manual configuration required.

  • [DevX] Comprehensive Integration Test Coverage: Complete test suite for all 0.3.0 features

    • Smart Personas v2 integration tests (15 tests covering persona graphs, lifecycle states, fidelity scores)
    • Drift Budget integration tests (14 tests covering budget hierarchy, breaking change detection, incident management)
    • Drift GitOps integration tests (16 tests covering PR generation, OpenAPI/fixture updates, GitOps configuration)
    • Behavioral Cloning integration tests (15 tests covering flow recording, scenario replay, strict/flex modes)
    • Voice/LLM Workspace Creation integration tests (16 tests covering command parsing, workspace building, NL to workspace flow)
    • All tests passing with 100% success rate (76 total integration tests)

    Why it matters: Production-ready features require production-ready tests. Comprehensive integration test coverage ensures reliability, prevents regressions, and provides confidence for users adopting these features.

Changed

  • Changelog entries now require pillar tags for all major features
  • Release process includes automated pillar tag validation
  • Documentation structure updated to highlight pillars

Fixed

  • Nothing yet.

Security

  • Nothing yet.

[0.2.9] - 2025-11-14

Added

  • [Cloud] Registry server improvements with password reset functionality

    Why it matters: Enable seamless team collaboration with secure registry access—teams can share and discover mock scenarios without friction, and password reset keeps workflows moving when credentials are lost.

  • [Cloud] Enhanced metrics and marketplace features

  • [DevX] Comprehensive E2E test suite

  • [DevX] Custom routes implementation

  • [Reality] Template expansion improvements

  • [Reality] Latency injection enhancements

  • [Reality] Smart Personas with array generation and relationship inference

    Why it matters: Generate realistic, interconnected mock data automatically—arrays that make sense, relationships that stay consistent across endpoints, and personas that feel like real users without manual configuration.

  • [DevX] Complete Java and .NET SDK implementations with builder patterns

    Why it matters: Bring MockForge to enterprise teams using Java and .NET—no more language barriers, no more custom integration work. Your entire stack can use the same mock infrastructure.

  • [Cloud] Cloud monetization infrastructure and features

    Why it matters: Enable sustainable platform growth with flexible pricing models—teams can scale from free tier to enterprise without friction, and the platform can grow while serving developers.

  • [Cloud] Organization management endpoints

    Why it matters: Scale from solo developer to enterprise team—manage users, permissions, and resources at the org level, not just individual accounts. Real teams need real organization tools.

  • [Cloud] Security controls implementation (Phase 3)

    Why it matters: Protect production deployments with enterprise-grade security—fine-grained access controls, audit trails, and compliance features that let you trust MockForge with sensitive data and critical workflows.

Changed

  • [DevX] Upgraded wasmtime to 36.0.3 to fix RUSTSEC-2025-0118
  • [DevX] Fixed Axum 0.8 route syntax compatibility across multiple modules
  • [DevX] Updated all test files for new function signatures

Fixed

  • [DevX] Fixed compilation errors across workspace
  • [DevX] Fixed Axum 0.8 route syntax in state_machine_api.rs
  • [DevX] Fixed file server route syntax for Axum 0.8 compatibility
  • [DevX] Resolved all compilation errors for comprehensive test coverage

Security

  • [DevX] Upgraded wasmtime to 36.0.3 to address RUSTSEC-2025-0118
  • [Cloud] Completed Phase 3 security controls implementation

[0.2.8] - 2025-11-10

Added

  • [Reality] Generative Schema Mode: Complete implementation of generative schema mode for dynamic mock data generation

    Why it matters: Spin up a believable API even when the backend doesn’t exist yet—no sample DB or seed data required.

  • [Reality] Smart Personas: Feature for consistent cross-endpoint data generation using persona-based templates

  • [Reality] Reality Continuum: Feature for blending mock and real data sources with configurable reality levels

    Why it matters: Turn the dial between deterministic mock and noisy production-like chaos without changing your client code.

  • [Reality] Reality Slider: Hot-reload support for reality level adjustments

    Why it matters: Adjust reality levels on the fly during development and testing without restarting the server.

  • [Reality] Chaos Lab: Interactive network condition simulation tool

    Why it matters: Test how your application handles real-world network conditions like latency spikes, packet loss, and connection failures.

  • [Contracts] AI Contract Diff: Feature for comparing and diffing API contracts

    Why it matters: Automatically detect and visualize API contract changes to catch breaking changes before they reach production.

  • [DevX] Voice + LLM Interface: Voice interface implementation with Speech-to-Text (STT) backend support

  • [Reality] Deceptive Deploy: Complete deceptive deploy feature for advanced testing scenarios

  • [DevX] GraphQL + REST Playground: Interactive playground with workspace filtering capabilities

  • [DevX] ForgeConnect SDK: Complete SDK implementation with full feature set

  • [Cloud] Enhanced Scenario Marketplace: Improved scenario marketplace with additional features

  • [DevX] WireMock-Inspired Features: Browser proxy mode, git sync, data sources, template library, managed hosting documentation, and user management

  • [DevX] Ecosystem Documentation: Comprehensive ecosystem and use cases documentation

  • [DevX] Configuration Extensibility: Complete configuration and extensibility implementation

  • [Reality] Advanced Behavior Simulation: Enhanced behavior and simulation features

Changed

  • [DevX] SQLx Integration: Configured SQLx and integrated mockforge-collab with mockforge-core
  • [Reality] Latency Recording: Completed latency recording integration with WorkspaceConfig reality_level field support

Fixed

  • [DevX] Fixed test compilation errors in reality integration and hot-reload tests
  • [DevX] Fixed test compilation errors in openapi_generator_tests
  • [Contracts][DevX] Fixed all compilation errors for AI Contract Diff feature
  • [DevX] Applied rustfmt formatting to Chaos Lab code

Security

  • Nothing yet.

[0.2.7] - 2025-11-05

Added

  • [Contracts] Automatic API Sync & Change Detection: Implemented periodic polling and automatic sync for detecting upstream API changes

    Why it matters: Keep your mocks in sync with real APIs automatically—catch breaking changes before they break your tests.

    • Periodic sync service with configurable intervals (default: 1 hour)
    • Automatic change detection using deep response comparison (status, headers, body)
    • Optional automatic fixture updates when changes detected
    • Manual sync trigger via API (POST /api/recorder/sync/now)
    • Sync status tracking and change history
    • Configurable sync settings: upstream URL, interval, headers, timeout, max requests
    • Support for GET-only or all-methods sync
    • Detailed change reports with before/after comparisons
    • Database update method for refreshing recorded responses
    • API endpoints: /api/recorder/sync/status, /api/recorder/sync/config, /api/recorder/sync/changes
  • [Reality] TCP Protocol Support: Added raw TCP server mocking support via new mockforge-tcp crate

    Why it matters: Mock any protocol that runs over TCP—not just HTTP. Perfect for testing database clients, custom protocols, and legacy systems.

    • Raw TCP connection handling with fixture-based matching
    • Echo mode for testing TCP clients
    • TLS/SSL support for encrypted connections
    • Delimiter-based message framing (optional)
    • Configurable buffer sizes and connection limits
    • CLI flag --tcp-port for custom TCP server port
    • Configuration via config.tcp in YAML/JSON config files
  • [Reality] Response Selection Modes: Added support for sequential (round-robin) and random response selection when multiple examples are available

    • Sequential mode: Cycles through available examples in order (round-robin)
    • Random mode: Randomly selects from available examples
    • Weighted random mode: Random selection with custom weights per example
    • Configuration via x-mockforge-response-selection OpenAPI extension
    • Environment variable support: MOCKFORGE_RESPONSE_SELECTION_MODE (global) and MOCKFORGE_RESPONSE_SELECTION_<OPERATION_ID> (per-operation)
    • State tracking for sequential mode ensures round-robin behavior across requests
  • [Reality] Webhook HTTP Execution: Implemented actual HTTP request execution in chaos orchestration hooks

    • HookAction::HttpRequest now executes real outbound HTTP requests (previously only logged)
    • Supports GET, POST, PUT, DELETE, PATCH methods
    • Configurable request body and headers
    • Error handling and logging for webhook failures
    • Fire-and-forget execution (failures don’t block orchestration)
  • [DevX] CRUD & Webhook Documentation: Added comprehensive documentation guides

    • docs/CRUD_SIMULATION.md: Complete guide for simulating CRUD operations with stateful data store
    • docs/WEBHOOKS_CALLBACKS.md: Full documentation of webhook capabilities via hooks, chains, and scripts
    • Examples demonstrating realistic workflows and integrations

Changed

  • Nothing yet.

Deprecated

  • Nothing yet.

Removed

  • Nothing yet.

Fixed

  • Nothing yet.

Security

  • Nothing yet.

[0.2.6] - 2025-11-04

Added

  • [DevX] TLS/HTTPS and mTLS Support: Added TLS/HTTPS and mutual TLS (mTLS) support for HTTP server

    • Configurable TLS certificate and key paths
    • Client certificate authentication support
    • Secure connection handling for production deployments
  • [DevX] Built-in Tunneling Service: Added built-in tunneling service for exposing local servers via public URLs

    • Automatic tunnel creation for local development
    • Public URL generation for testing and demos
    • Integration with popular tunneling services
  • [DevX] SDK Implementation: Completed Phase 1 & 2 of SDK implementation

    • Comprehensive documentation and examples
    • Production-ready client generators

Changed

  • [DevX] Version Bumps: Updated all workspace crates from 0.2.5 to 0.2.6

    • Updated all dependency versions across the workspace
    • Fixed version mismatches in mockforge-ui and mockforge-plugin-loader
  • [DevX] Publishing Improvements: Enhanced crate publishing process

    • Added mockforge-tcp and mockforge-test to publish script
    • Enabled publishing for mockforge-test crate
    • Fixed mockforge-tcp to remove README requirement

Fixed

  • [DevX] Documentation: Fixed missing module-level documentation in test files

    • Added comprehensive module documentation to all test modules
    • Improved code documentation consistency
  • [DevX] Axum Compatibility: Fixed Axum 0.8 compatibility issues in proxy server module

    • Updated proxy server to work with latest Axum version
    • Resolved breaking changes from Axum upgrade
  • [Reality] MQTT Error Types: Fixed MQTT publish handlers error types to be Send + Sync

    • Updated error types for proper async/await compatibility
    • Ensured thread-safety in MQTT handlers

[0.2.5] - 2025-01-27

Added

  • [DevX] OAuth2 Flow Support: Complete OAuth2 implementation with all standard flows

    • Authorization Code flow with PKCE (RFC 7636 compliant, SHA256 hash)
    • Client Credentials flow for server-side applications
    • Password flow for trusted clients
    • Implicit flow support
    • Automatic token refresh and expiration management
    • State parameter for CSRF protection
    • PKCE code verifier/challenge generation helpers
    • Token storage with expiration tracking (localStorage)
  • [DevX] Enterprise Error Handling: Structured error handling for generated clients

    • ApiError class with status codes, statusText, and error body
    • RequiredError class for missing required fields
    • Helper methods: isClientError(), isServerError(), getErrorDetails(), getVerboseMessage()
    • Optional verbose error messages with detailed validation information
  • [Contracts] Request/Response Validation: Built-in validation support

    • Required field validation before sending requests
    • Basic response structure validation (type checking, object validation)
    • Configurable via validateRequests flag
    • Detailed validation error messages
  • [DevX] Request/Response Interceptors: Custom request/response/error transformation

    • Request interceptor: Modify requests before sending
    • Response interceptor: Transform responses after receiving
    • Error interceptor: Global error handling
    • Support for async interceptors
  • [DevX] Enhanced Authentication: Multiple authentication methods

    • Bearer token (static or dynamic function)
    • API key authentication (static or dynamic)
    • Basic authentication (username/password)
    • OAuth2 (all flows, takes priority over other methods)
  • [DevX] PKCE Helper Functions: Exported utilities for PKCE implementation

    • generatePKCECodeVerifier(): Generate cryptographically random code verifier
    • generatePKCECodeChallenge(): Generate SHA256 code challenge from verifier
  • [DevX] Security Best Practices: Comprehensive security warnings and guidance

    • Client secret warnings for browser-based applications
    • XSS vulnerability warnings for localStorage token storage
    • CSRF protection via state parameter validation
    • Token expiration checking
    • Security documentation in generated README
  • [DevX] Request Timeout Handling: Configurable request timeouts

    • Default 30-second timeout (configurable)
    • AbortController-based timeout implementation
    • Proper timeout error handling
  • [DevX] React Query Integration Documentation: Comprehensive examples for @tanstack/react-query integration

Changed

  • [DevX] React Client Generator: Major enhancements to generated React client code

    • Replaced placeholder PKCE implementation with full SHA256-based solution
    • Implemented proper response validation (previously placeholder)
    • Enhanced README with comprehensive feature documentation
    • Improved error messages and validation details
    • Better security documentation and best practices
  • [DevX] Operation ID Sanitization: Improved identifier generation

    • Enhanced sanitize_identifier function to handle complex operation IDs
    • Better handling of parentheses, slashes, hyphens in operation IDs
    • Proper camelCase conversion with word boundary detection

Fixed

  • [DevX] TypeScript Empty Object Types: Fixed formatting issue where empty object schemas generated invalid TypeScript

    • Empty objects now correctly generate as [key: string]: any; instead of malformed Record<string, any>}
  • [DevX] DELETE Operations with Query Params: Fixed missing query parameter support in DELETE operations

  • [DevX] Duplicate Operation IDs: Fixed duplicate operation ID handling by appending numeric suffixes

  • [DevX] PKCE Code Challenge: Fixed PKCE implementation to use proper SHA256 hash instead of plain encoding

  • [Contracts][DevX] Response Validation: Replaced placeholder with actual implementation (type checking, structure validation)

Security

  • [DevX] Added comprehensive security warnings for OAuth2 client secrets in browser code
  • [DevX] Added XSS vulnerability warnings for localStorage token storage
  • [DevX] Implemented CSRF protection via state parameter validation
  • [DevX] Added token expiration checking to prevent use of expired tokens
  • [DevX] Documented security best practices in generated client README

[0.2.4] - 2025-01-27

Fixed

  • [DevX] Fix request body parameter generation in React/Vue/Svelte client generators - request bodies now correctly generate data parameter and body: JSON.stringify(data) in API client methods
  • [DevX] Fix required vs optional field handling in generated TypeScript interfaces - required fields no longer incorrectly marked with optional marker (?)
  • [DevX] Fix OpenAPI serde deserialization by adding #[serde(rename)] attributes for operationId and requestBody fields
  • [DevX] Apply required fields processing consistently across all client generators (React, Vue, Svelte)

Added

  • [DevX] Comprehensive test coverage for request body parameter scenarios (POST, PUT, PATCH, DELETE)
  • [DevX] Test cases for $ref schemas in request bodies
  • [DevX] Test cases for YAML spec support verification

[0.2.3] - 2025-01-27

Fixed

  • [DevX] Fix OpenAPI example extraction to prioritize explicit examples from schema and properties
  • [DevX] Fix request body parameter generation in React client generator for POST, PUT, PATCH, DELETE methods
  • [DevX] Fix Handlebars template logic for request body type generation in client code
  • [DevX] Fix useCallback dependency array formatting in React hooks template
  • [DevX] Add comprehensive test coverage for request body parameter scenarios

[0.2.0] - 2025-10-29

Added

  • [DevX] Output control features for MockForge generator with comprehensive configuration options
  • [DevX] Unified spec parser with enhanced validation and error reporting
  • [DevX] Multi-framework client generation with Angular and Svelte support
  • [Reality] Enhanced mock data generation with OpenAPI support
  • [DevX] Configuration file support for mock generation
  • [DevX] Browser mobile proxy mode implementation
  • [DevX] Comprehensive documentation and example workflows

Changed

  • [DevX] Enhanced CLI with progress indicators, error handling, and code quality improvements
  • [DevX] Comprehensive plugin architecture documentation

Fixed

  • [DevX] Remove tests that access private fields in mock data tests
  • [DevX] Fix compilation issues in mockforge-collab and mockforge-ui
  • [DevX] Update mockforge-plugin-core version to 0.1.6 in plugin-sdk
  • [DevX] Enable SQLx offline mode for mockforge-collab publishing
  • [DevX] Add description field to mockforge-analytics
  • [DevX] Add version requirements to all mockforge path dependencies
  • [DevX] Fix publish order dependencies (mockforge-chaos before mockforge-reporting)
  • [DevX] Update Cargo.lock and format client generator tests

[0.1.3] - 2025-10-22

Changes

  • [DevX] docs: prepare release 0.1.3
  • [DevX] docs: update CHANGELOG for 0.1.3 release
  • [DevX] docs: add roadmap completion summary
  • [DevX] feat: add Kubernetes-style health endpoint aliases and dashboard shortcut
  • [DevX] feat: add unified config & profiles with multi-format support
  • [Reality] feat: add capture scrubbing and deterministic replay
  • [DevX] feat: add native GraphQL operation handlers with advanced features
  • [Reality] feat: add programmable WebSocket handlers
  • [Reality] feat: add HTTP scenario switching for OpenAPI response examples
  • [DevX] feat: add mockforge-test crate and integration testing examples
  • [DevX] build: enable publishing for mockforge-ui and mockforge-cli
  • [DevX] build: extend publish script for internal crates
  • [DevX] build: parameterize publish script with workspace version

[0.1.2] - 2025-10-17

Changes

  • [DevX] build: make version update tolerant
  • [DevX] build: manage version references via wrapper
  • [DevX] build: mark example crates as non-publishable
  • [DevX] build: drop publish-order for cargo-release 0.25
  • [DevX] build: centralize release metadata in release.toml
  • [DevX] build: remove per-crate release metadata
  • [DevX] build: fix release metadata field name
  • [DevX] build: move workspace release metadata into Cargo.toml
  • [DevX] build: require execute flag for release wrapper
  • [DevX] build: automate changelog generation during release
  • [DevX] build: add release wrapper with changelog guard
  • [DevX] build: align release tooling with cargo-release 0.25

[0.1.1] - 2025-10-17

Added

  • [Contracts] OpenAPI request validation (path/query/header/cookie/body) with deep $ref resolution and composite schemas (oneOf/anyOf/allOf).
  • [Contracts] Validation modes: disabled, warn, enforce, with aggregate error reporting and detailed error objects.
  • [DevX] Runtime Admin UI panel to view/toggle validation mode and per-route overrides; Admin API endpoint /__mockforge/validation.
  • [DevX] CLI flags and config options to control validation (including skip_admin_validation and per-route validation_overrides).
  • [DevX] New e2e tests for 2xx/422 request validation and response example expansion across HTTP routes.
  • [DevX] Templating reference docs and examples; WS templating tests and demo update.
  • [Reality] Initial release of MockForge - Multi-protocol mocking framework
  • [Reality] HTTP API mocking with OpenAPI support
  • [Reality] gRPC service mocking with Protocol Buffers
  • [Reality] WebSocket connection mocking with replay functionality
  • [DevX] CLI tool for easy local development
  • [DevX] Admin UI for managing mock servers
  • [DevX] Comprehensive documentation with mdBook
  • [DevX] GitHub Actions CI/CD pipeline
  • [DevX] Security audit integration
  • [DevX] Pre-commit hooks for code quality

Changed

  • [Contracts] HTTP handlers now perform request validation before routing; invalid requests return 400 with structured details (when enforce).
  • [Contracts] Bump jsonschema to 0.33 and adapt validator API; enable draft selection and format checks internally.
  • [Contracts] Improve route registry and OpenAPI parameter parsing, including styles/explode and array coercion for query/header/cookie parameters.

Deprecated

  • N/A

Removed

  • N/A

Fixed

  • [DevX] Resolve admin mount prefix from config and exclude admin routes from validation when configured.
  • [Contracts] Various small correctness fixes in OpenAPI schema mapping and parameter handling; clearer error messages.

Security

  • N/A

Release Process

This project uses cargo-release for automated releases.

Creating a Release

  1. Patch Release (bug fixes):

    make release-patch
    
  2. Minor Release (new features):

    make release-minor
    
  3. Major Release (breaking changes):

    make release-major
    

Manual Release Process

If you need to do a manual release:

  1. Update version in Cargo.toml files
  2. Update CHANGELOG.md with release notes
  3. Commit changes: git commit -m "chore: release vX.Y.Z"
  4. Tag: git tag vX.Y.Z
  5. Push: git push && git push --tags
  6. Publish to crates.io: cargo publish

Pre-release Checklist

  • All tests pass (make test)
  • Code formatted (make fmt)
  • Lints pass (make clippy)
  • Security audit passes (make audit)
  • Documentation updated
  • Changelog updated
  • Version bumped in all Cargo.toml files
  • Breaking changes documented (if any)
  • CI passes on all branches