# aicodeman ## 0.3.1 ### Patch Changes - LLM context optimization and performance improvements: compress CLAUDE.md 21%, MEMORY.md 61%; SSE broadcast early return, cached tunnel state, cache invalidation fix, ralph todo cleanup timer; frontend SSE listener leak fix, short ID caching, subagent window handle cleanup; 100% @fileoverview coverage ## 0.3.0 ### Minor Changes - QR code authentication for tunnel access, 7-phase codebase refactor (route extraction, type domain modules, frontend module split, config consolidation, managed timers, test infrastructure), overlay rendering fixes, and security hardening ## 0.2.9 ### Patch Changes - System-level performance optimizations (Phase 4): stream parent transcripts instead of full reads, consolidate subagent file watchers from 500 to ~50 using directory-level inotify, incremental state persistence with per-session JSON caching, and replace team watcher polling with chokidar fs events ## 0.2.8 ### Patch Changes - Remove 159 lines of dead code: unused interfaces, functions, config constants, legacy no-op timer, and stale barrel re-exports ## 0.2.7 ### Patch Changes - Fix race condition in StateStore where dirty flag was overwritten after async write, silently discarding mutations - Fix PlanOrchestrator session leak by adding session.stop() in finally blocks and centralizing cleanup - Fix symlink path traversal in file-content and file-raw endpoints by adding realpathSync validation - Fix PTY exit handler to clean up sessionListenerRefs, transcriptWatchers, runSummaryTrackers, and terminal batching state - Fix sendInput() fire-and-forget by propagating runPrompt errors to task queue via taskError event - Fix Ralph Loop tick() race condition by running checkTimeouts/assignTasks sequentially with per-iteration error handling - Fix shell injection in hook scripts by piping HOOK_DATA via printf to curl stdin instead of inline embedding - Narrow tail-file allowlist to remove ~/.cache and ~/.local/share paths that exposed credentials - Fix stored XSS in quick-start dropdown by escaping case names with escapeHtml() ## 0.2.6 ### Patch Changes - Disable tunnel auto-start on boot; tunnel now only starts when user clicks the UI toggle ## 0.2.5 ### Patch Changes - Fix 3 minor memory leaks: clear respawn timers in stop(), clean up persistDebounceTimers on session cleanup, reset \_parentNameCache on SSE reconnect ## 0.2.4 ### Patch Changes - Fix tunnel button not working: settings PUT was rejected by strict Zod validation when sending full settings blob; now sends only `{tunnelEnabled}`. Added polling fallback for tunnel status in case SSE events are missed. ## 0.2.3 ### Patch Changes - Fix tunnel button stuck on "Connecting..." when tunnel is already running on the server ## 0.2.2 ### Patch Changes - Update CLAUDE.md app.js line count references ## 0.2.1 ### Patch Changes - Integrate @changesets/cli for automated releases with changelogs, GitHub Releases, and npm publishing ## 0.2.0 ### Minor Changes - Initial public release with changesets-based versioning