Skip to content

🚀 docs: Prepare v0.8.8 Stable Release - #786

Open
lia-by-librechat[bot] wants to merge 12 commits into
mainfrom
lia/docs-v0.8.8
Open

lia-by-librechat[bot] wants to merge 12 commits into
mainfrom
lia/docs-v0.8.8

Conversation

@lia-by-librechat

@lia-by-librechat lia-by-librechat Bot commented Sep 29, 2026 •

Copy link
Copy Markdown

Summary

Prepare the v0.8.8 stable changelog from the cumulative rc3 notes, the merged rc4 docs PR #777, and the changes merged after rc4. The entry covers each of the 1,242 LibreChat PRs merged between v0.8.7 and dev at b341f93805843d8acbf7e3ff69c8cf4ccc81265c, plus four direct commits, with 37 first-time contributors. A closed, unmerged rc3 release draft incorrectly listed by the old changelog is not repeated.

Documentation updates

  • Add the shared authenticated 2FA management budget, its deployment YAML setting, success/failure counting, Retry-After guidance, multi-replica Redis prerequisite, and separate login limiter behavior.

  • Document MCP OAuth cancellation from the Agent Tool dialog and preservation of an active browser flow when cached status says Connected. Include the message-send performance change without general latency promises.

  • Include the final tolerant-edit matching performance optimization (#16562). It adds no settings, migration or API changes; existing matching guidance stays applicable.

  • Make the Helm Secret example complete and parseable, and show the application step while preserving all permanent credential keys.

  • Refresh the stable release date to September 30 and cover all seven final merges: imported approval modes, native edit normalization, composer review behavior, summary-bounded history, release versions, SDK 4.0.0 and dependency fixes.

  • Clarify that summarization is lossy, managed /mnt/data differs from an attached workspace, and Helm chart 2.0.15 needs an explicit {} when librechat.configEnv would be null.

  • Link the published Meet Lia: Building LibreChat with LibreChat announcement from the stable release highlights.

  • Extend Config v1.3.17 notes with workspace transitions, request and shutdown budgets, idle recovery caps, Agent selector limits, credential validation, config overrides, and rate-limit fixes. The config version remains 1.3.17.

  • Explain saved-chat workspace recovery and opt-in attach/detach, the Code API rollout prerequisite for longer queue admission, and where uploads actually live in attached workspaces.

  • Document background task cards and header controls, plus fail-closed tool-approval behavior for headless Agents API calls.

  • Correct attached-workspace timeout paths to configSchema.limits, explain linked-worktree lanes, command-admission reserves, tool preparation versus call timing, and MCP OAuth redirect restrictions.

  • Cover capability-negotiated tolerant edits and replace_all, GPT-6.1 Sol/family fallback, and Firecrawl/SearXNG credential ownership. The attached edit features require compatible Code API and worker builds implementing Code Interpreter Found broken /docs link. Please fix! Hetzner guide #271; upgrading LibreChat alone does not enable them.

  • Document tenant-scoped YAML custom endpoints and destination-bound per-user MCP keys, including all-replica rollout requirements and the existing key re-entry flow.

The v0.8.8 tag is not published yet. These notes are prepared against the pinned dev head above, not the separate canary branch; recheck merged PR coverage, release date, and the compare link when the stable tag is cut. The older v0.8.8 draft #763 predates rc4, so this is a separate PR from current main rather than a merge of its stale branch.

Review ledger

  • Latest release sync: independent source-accuracy review completed on 41daa2d9cc9f31857fb844ade362ec5f4906ca4c against LibreChat b341f93805843d8acbf7e3ff69c8cf4ccc81265c with no findings. It checked all four new release changes, 2FA defaults/window/counting/scope/base-YAML/Redis/retry behavior, MCP OAuth prompts/cancellation/stale status and R1. This was a bounded source review, not a second exhaustive historical audit or deployed-runtime test. Parent history and whole-diff syntax/link/YAML audits remain recorded separately.
  • Current release sync: independent exact-head review completed on 454106af4c3f76b8d4539e4fd1b98b8f21467775 against LibreChat cd63070d4def2cfe6b95e548c554bacb6e874c01 with no findings. It checked the new performance entry, actual matcher implementation and regression-test source, relevant edit guidance, and R1 capability/identifier forwarding. The review was bounded to the new delta and relevant guide behavior, not a second exhaustive audit of unchanged subsystems. Parent historical reconciliation, parsing, and differential execution are recorded separately below. R1 remains fixed.
  • R1 (P2): The attached-workspace guide incorrectly prohibited workspace-aware Programmatic Bash. Fixed in ae30bf2bd5da7341a4b15937ddfd2f6e39e34c40 after checking the release source capability gate, SDK factory, and selected-workspace regression test. The guide now describes negotiated support and separate file staging.
  • Earlier review dadcf683 was incomplete. Review at 31a219b completed with no findings in its narrowed Lia-link/R1 scope. Independent accuracy review completed on final head 9c2b483cae175fe2fa01e199d2b93b6c40f038a8 with no findings. It read all 16 changed guides and checked the seven final merges, configuration defaults, authorization/capabilities, credential boundaries, rollout prerequisites, Helm examples, and summarization against pinned LibreChat 601e07ec02b9c426d3001c3771544db9fa475c67 and Agents SDK 4.0.0 source. R1 remains fixed. This is a source review, not deployed-runtime verification or a separate replay of the parent's automated historical-coverage checks. Review of 1d1bcda was cancelled before completion when the parent YAML audit found the legacy malformed Helm Secret example; the final head fixes it.

Validation

  • Actual pinned OAuth state-helper smoke checks pass: pending browser flows mask stale Connected status without mutating raw cache data; absent/terminal flows preserve identity and missing status is handled.
  • Latest-head audit: 1,242 unique merged release-branch PRs and all four direct commits through b341f93805843d8acbf7e3ff69c8cf4ccc81265c; all 18 changed MDX pages parse, 179 YAML examples and eleven added routes/anchors pass. The always-active 2FA management schema/default/minimum and all five routes match source.
  • Refreshed exact-head verification: all 1,238 merged PRs plus four direct commits; application v0.8.8, Config 1.3.17, Helm 2.0.15 and SDK 4.0.0 agree with LibreChat cd63070d4def2cfe6b95e548c554bacb6e874c01. All 16 changed MDX guides, 169 YAML samples and nine added links/anchors pass again.
  • Actual-source matcher differential smoke passes 11 boundary fixtures and 5,000 seeded comparisons against the preceding release source. This checks strategy, ambiguity and UTF-16 offsets, not a general performance guarantee or deployed-worker behavior.
  • Complete coverage: 1,242 unique merged PR entries and all four direct commits from v0.8.7 through the pinned LibreChat head above
  • Source/schema checks for all post-rc4 configuration controls, including the new tenant scope and mixed-version rollout requirements
  • All 16 changed MDX pages parse; all 169 YAML samples and 9 added internal routes/anchors pass. Source/schema checks cover Config 1.3.17, Helm 2.0.15, SDK 4.0.0, canonical edit approvals, imported approval-mode sanitization, and deployment prerequisites.
  • Lia announcement title and route verified against the published blog on current docs main; the public announcement URL returns HTTP 200. This new highlight leaves all release-coverage entries unchanged.
  • Actual pinned native edit-normalizer smoke checks pass for invalid/empty batches, JSON-stringified replacements, and per-entry replace_all. Both Helm Secret examples validate and preserve all five permanent credential keys.
  • git diff --check passes; docs deliberately exclude hand-authored MDX from automated Prettier reformatting
  • Exact-head formatting, Fumadocs/typecheck, lint, unit tests, bundle-analysis production build and Vercel preview passed on 41daa2d9cc9f31857fb844ade362ec5f4906ca4c. The end-to-end lane failed during its separate uncached production build: Node hit its JavaScript heap limit and exited 134. Playwright was skipped, not executed or assertion-failed. A failed-job rerun was attempted, but GitHub/gh did not accept it; run attempt remains 1. No green browser-test result is claimed.
  • Full docs dependency installation, local pnpm typecheck, local pnpm lint, local pnpm test, local pnpm build, and local Playwright were not run in the sparse audit worktree; the exact-head CI jobs provide those gates

@vercel

vercel Bot commented Sep 29, 2026 •

Copy link
Copy Markdown

The latest updates on your projects. Learn more about Vercel for GitHub.

Project Deployment Actions Updated
librechat-ai Ready Ready Preview Sep 30, 2026 4:44pm UTC

Request Review

@lia-by-librechat

Copy link
Copy Markdown
Author

Review head: b4e43be7dd0f7db3c91eb5818713d0360a6979e3. This commit adds the cumulative v0.8.8 changelog through LibreChat dev 42568a0077bcd13ce00f95261eb34d811db41673 and updates the v1.3.17 operator, attached-workspace, background-task, and Agents API docs. Please review this exact head, particularly the release coverage and opt-in rollout caveats.

@lia-by-librechat

Copy link
Copy Markdown
Author

Review head: 3c9bde1faa7d264cf98ac3172bedacb5ae802963. The cumulative v0.8.8 notes and operator guidance are unchanged; this head clarifies that headless tool approval applies to LibreChat-executed tools, while caller-executed functions remain the API caller's responsibility. Targeted MDX formatting and the merged-PR coverage audit pass.

@github-actions

Copy link
Copy Markdown
Contributor

📦 Next.js Bundle Analysis for librechat.ai

This analysis was generated by the Next.js Bundle Analysis action. 🤖

This PR introduced no changes to the JavaScript bundle! 🙌

1 similar comment
@github-actions

Copy link
Copy Markdown
Contributor

📦 Next.js Bundle Analysis for librechat.ai

This analysis was generated by the Next.js Bundle Analysis action. 🤖

This PR introduced no changes to the JavaScript bundle! 🙌

@lia-by-librechat

Copy link
Copy Markdown
Author

Review head: d56080fc74e3716bee2aaa1c997c99338fa309aa. The stable v0.8.8 notes now cover all 1,221 merged PRs plus four direct commits through LibreChat release branch 4d33d8c2c71ad497fdfaa2c4334b0a2293bcbd67. This head also corrects the attached-workspace YAML field paths and documents linked-worktree rollout, command admission budgeting, Agent tool timing, and MCP OAuth redirect policy. Canary-only work is intentionally excluded. Please review this exact head for operator accuracy and release scope.

@lia-by-librechat

Copy link
Copy Markdown
Author

Review head: 35854d30aba66bdbbe5959625b8bd2d3fdb3c022. Same complete v0.8.8 audit through LibreChat 4d33d8c2c71ad497fdfaa2c4334b0a2293bcbd67; this follow-up makes the linked-worktree examples exact: file tools route by their target path and Bash routes by its cwd, not by a cd inside a command. Please review this head.

@github-actions

Copy link
Copy Markdown
Contributor

📦 Next.js Bundle Analysis for librechat.ai

This analysis was generated by the Next.js Bundle Analysis action. 🤖

This PR introduced no changes to the JavaScript bundle! 🙌

1 similar comment
@github-actions

Copy link
Copy Markdown
Contributor

📦 Next.js Bundle Analysis for librechat.ai

This analysis was generated by the Next.js Bundle Analysis action. 🤖

This PR introduced no changes to the JavaScript bundle! 🙌

@lia-by-librechat

Copy link
Copy Markdown
Author

Review head: 715465dd54f59d0d28fb6e2f2caefc10c083ad74. The stable v0.8.8 notes now cover all 1,228 release-branch PRs plus four direct commits through LibreChat 5f4d96c49b0aba99cc1157bc96c10a7e5ddd23b4. This head adds the seven merges since the previous audit, documents tolerant attached edits and their still-required Code API/worker capability negotiation, GPT point-release fallback, and Firecrawl/SearXNG URL/key ownership. Canary remains excluded. Please review this exact head.

@github-actions

Copy link
Copy Markdown
Contributor

📦 Next.js Bundle Analysis for librechat.ai

This analysis was generated by the Next.js Bundle Analysis action. 🤖

This PR introduced no changes to the JavaScript bundle! 🙌

@lia-by-librechat

Copy link
Copy Markdown
Author

Review head: dadcf683eb7f2e7d32146b73ff2887b8f7a3812d. The v0.8.8 changelog now covers all 1,230 merged release-branch PRs and four direct commits through LibreChat 14f7b2865692d27364c934ecb9912496371018bb. This head adds tenant-scoped YAML endpoint documentation and updates per-user MCP credential re-entry guidance. Both describe the all-replica upgrade prerequisite. Please review this exact head.

@github-actions

Copy link
Copy Markdown
Contributor

📦 Next.js Bundle Analysis for librechat.ai

This analysis was generated by the Next.js Bundle Analysis action. 🤖

This PR introduced no changes to the JavaScript bundle! 🙌

@lia-by-librechat

Copy link
Copy Markdown
Author

Review head: ae30bf2bd5da7341a4b15937ddfd2f6e39e34c40. The independent review found one P2 documentation error at the prior head: the guide said Programmatic Bash could not carry the selected attached workspace identity. The pinned release source supports that capability-gated path. This head corrects the guide to explain worker readiness, programmatic Bash support, workspace command permission, and the server-validated workspace selection; upload staging remains separate. R1 is fixed in this commit. Release coverage remains all 1,230 PRs and four direct commits through LibreChat 14f7b2865692d27364c934ecb9912496371018bb. Please review this exact head.

@github-actions

Copy link
Copy Markdown
Contributor

📦 Next.js Bundle Analysis for librechat.ai

This analysis was generated by the Next.js Bundle Analysis action. 🤖

This PR introduced no changes to the JavaScript bundle! 🙌

@lia-by-librechat

Copy link
Copy Markdown
Author

Review head: 31a219b8dc83ae257e5716818c6296f59fa665f4. Added the published Meet Lia announcement as the first v0.8.8 highlight, linking /blog/2026-09-29_meet-lia-building-librechat-with-librechat. The announcement file and blog route were checked on current docs main. Existing release entries and the Programmatic Bash correction are unchanged. Please review this exact head.

@github-actions

Copy link
Copy Markdown
Contributor

📦 Next.js Bundle Analysis for librechat.ai

This analysis was generated by the Next.js Bundle Analysis action. 🤖

This PR introduced no changes to the JavaScript bundle! 🙌

@lia-by-librechat

Copy link
Copy Markdown
Author

Review head: 1d1bcda9b7db5797dcd57d1f54b1033acb63eeb7. Final accuracy pass through LibreChat 601e07ec02b9c426d3001c3771544db9fa475c67: the stable changelog covers 1,237 merged PRs and four direct commits, retains the published Lia announcement, and uses September 30 metadata. This head documents imported approval-mode sanitization, canonical edit approvals, the composer/thread review handoff, and the release deployment snapshot. Please review this exact head, including the summarized-history wording and Helm null-config rendering caveat. Earlier scoped review findings remain recorded in the ledger.

@lia-by-librechat

Copy link
Copy Markdown
Author

Review head: 9c2b483cae175fe2fa01e199d2b93b6c40f038a8. Final v0.8.8 docs accuracy pass through LibreChat 601e07ec02b9c426d3001c3771544db9fa475c67, including all 1,237 merged PRs and four direct commits. The release date is September 30. This head also fixes the Helm guide's invalid/incomplete Secret example and keeps the permanent-key and null-config rendering guidance together. Please review this exact head. R1 remains fixed, and no earlier-head review is reported as covering this head.

@github-actions

Copy link
Copy Markdown
Contributor

📦 Next.js Bundle Analysis for librechat.ai

This analysis was generated by the Next.js Bundle Analysis action. 🤖

This PR introduced no changes to the JavaScript bundle! 🙌

1 similar comment
@github-actions

Copy link
Copy Markdown
Contributor

📦 Next.js Bundle Analysis for librechat.ai

This analysis was generated by the Next.js Bundle Analysis action. 🤖

This PR introduced no changes to the JavaScript bundle! 🙌

@lia-by-librechat

Copy link
Copy Markdown
Author

Final validation: 9c2b483cae175fe2fa01e199d2b93b6c40f038a8. All exact-head CI checks pass, including typecheck/lint/unit tests, production build/Playwright, bundle analysis and preview. Independent changed-guide accuracy review is complete with no findings against LibreChat 601e07ec02b9c426d3001c3771544db9fa475c67 and SDK 4.0.0. Parent checks reconcile all 1,237 merged PRs and four direct commits; all 16 changed MDX guides parse, 169 YAML examples and nine added internal links/anchors pass. R1 remains fixed. The stable release date is September 30; tag/publication and deployed-worker availability are separate from this source review.

@lia-by-librechat

Copy link
Copy Markdown
Author

Review head: 454106af4c3f76b8d4539e4fd1b98b8f21467775. Synced release notes with LibreChat cd63070d4def2cfe6b95e548c554bacb6e874c01: 1,238 merged PRs plus four direct commits. New entry #16562 covers tolerant-edit matching performance only; versions, operator controls, approval semantics and rollout prerequisites are unchanged. Please review this exact published head. Prior complete source review is recorded separately and does not substitute for this head.

@github-actions

Copy link
Copy Markdown
Contributor

📦 Next.js Bundle Analysis for librechat.ai

This analysis was generated by the Next.js Bundle Analysis action. 🤖

This PR introduced no changes to the JavaScript bundle! 🙌

@lia-by-librechat

Copy link
Copy Markdown
Author

Validated release-docs head: 454106af4c3f76b8d4539e4fd1b98b8f21467775, against LibreChat cd63070d4def2cfe6b95e548c554bacb6e874c01. All exact-head checks are green. Independent review completed with no new findings in the updated delta and relevant guide behavior; R1 remains fixed. The parent rechecked all 1,238 merged PRs and four direct commits, versions and all 13 operator controls, 16 MDX pages, 169 YAML samples and nine links/anchors. Actual-source differential matcher checks also passed. The v0.8.8 tag was absent at the final check, and deployment of worker capabilities is not inferred from an upstream merge.

@lia-by-librechat

Copy link
Copy Markdown
Author

Review head: 41daa2d9cc9f31857fb844ade362ec5f4906ca4c. Updated v0.8.8 notes through LibreChat b341f93805843d8acbf7e3ff69c8cf4ccc81265c to cover 1,242 merged PRs plus four direct commits. New operator/user guidance documents the always-active 2FA management limit and MCP OAuth cancellation/pending-flow behavior. Deployment versions and the published Lia highlight are unchanged. Please review this exact head; earlier green checks and reviews do not cover it.

@github-actions

Copy link
Copy Markdown
Contributor

📦 Next.js Bundle Analysis for librechat.ai

This analysis was generated by the Next.js Bundle Analysis action. 🤖

This PR introduced no changes to the JavaScript bundle! 🙌

@lia-by-librechat

Copy link
Copy Markdown
Author

Accuracy pass completed at docs 41daa2d9cc9f31857fb844ade362ec5f4906ca4c against LibreChat b341f93805843d8acbf7e3ff69c8cf4ccc81265c. All 1,242 merged PRs and four direct commits are covered. The 18 changed MDX pages, 179 YAML samples, eleven added links/anchors and new 2FA contracts pass the parent checks; independent source review found no inaccuracies in the four new changes and confirmed R1 remains fixed. Typecheck/lint/unit tests, bundle-analysis build and preview passed. The separate browser lane stopped at Node heap exhaustion during its uncached build (exit 134), before Playwright ran. Same-head rerun was attempted but not accepted. This CI limitation remains recorded and is not represented as a passing browser check.

This branch was successfully deployed

1 active deployment
Preview — 41daa2d9 Deployed Sep 30, 2026 by vercel[bot]
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant