v3.7.9
TypeScriptPlatformFeatureAugust 26, 2026EvalGate now connects repository setup, production evidence, evaluation coverage, release gates, and reviewed improvements into one repository-to-release workflow for teams and coding agents.
Added
- Repository-first onboarding — choose an authorized GitHub installation, repository, branch, root, harness, and commit instead of relying on an inferred default repository.
- Durable repository activation — setup runs through a queued lifecycle with progressive status, report links, retry-safe identity, partial-run recovery, and failure compensation.
- Multiplayer repository access — multiple EvalGate members can work from the same organization-scoped repository attachment without duplicating repository state.
- Coding-agent setup — evalgate connect --client installs native Codex, Claude Code, or Cursor instructions, with a portable Agent Skill for other clients.
- Agent-native access — product and documentation MCP servers, A2A discovery, WebMCP, OAuth device authorization, and human-approved scoped key handoff expose authenticated workflows without automating social login.
- Governed improvement loop — repository intelligence, grounded quality profiles, synthetic candidates, saved execution state, reviewed mutations, and rollback plans now feed the same release decision.
- Expanded safety testing — an actionable red-team workbench and AIDEFEND-aligned controls make adversarial findings reviewable alongside regression evidence.
- Application and harness diagnostics — the TypeScript CLI can capture on-demand application-health evidence and coding-agent efficiency signals for review.
Changed
- One evidence loop — traces, reviewed cases, repository context, runtime policy, baseline comparison, and release reports now preserve the same organization and source identity.
- Setup experience — GitHub returns users to EvalGate, the repository picker refreshes connected installations, and the UI keeps the selected repository and branch visible.
- Release availability — the application and @evalgate/sdk are released as 3.7.9. Python 3.7.9 remains source capability until its separate PyPI publication is verified.
- API identity — the published OpenAPI specification remains 3.7.8; SDK and API-spec versions are tracked independently.
Fixed
- Customer-data boundary — customer content is excluded from generalized product improvement, operational identifiers are pseudonymous, and external error reporting and log drains use fail-closed payloads.
- Production packaging — Vercel builds use the regular 8 GB contract with bounded page generation, lazy MCP route construction, and explicit runtime dependency materialization.
- Machine discovery — agent-readable capability, authentication, pricing, Skill, MCP, A2A, API catalog, and structured-data surfaces now describe the supported workflow and its authentication boundaries.