Skip to content

Release history

great_cto releases

Engineering-management layer of 34 specialist AI agents covering the full SDLC (architect, PM, senior-dev, reviewer, QA, security, devops, L3-support + 18 archetype-specific reviewers) with auto-detected archetypes and compliance gates (PCI-DSS, HIPAA, FedRAMP, GDPR, EU AI Act). Runs in Claude Code, Cursor, Codex CLI, Aider, and Continue via AGENTS.md + MCP. MIT.

All releases

74 shown

No immediate action
v2.88.0 Breaking risk

macOS quota warning

No immediate action
v2.87.1 New feature

Next block routing

Review required
v2.87.0 New feature
Auth RBAC

Edit scope + handoff package + metrics

Review required
v2.86.0 Mixed
Auth RBAC

ADR-007 improvements + failure reporting

No immediate action
v2.85.2 Bug fix

Measured cost delivery fix

No immediate action
v2.85.1 Bug fix

Dashboard viz contract fix

No immediate action
v2.85.0 New feature

Flint charting contract

No immediate action
v2.84.0 New feature

Real token usage + cache pricing

No immediate action
v2.83.0 New feature

BM25 ranked recall

No immediate action
v2.82.3 Bug fix

Cost savings + notifications

No immediate action
v2.82.2 Bug fix

Tax/procurement/MSP detection fix

No immediate action
v2.82.1 Bug fix

Fix legal/insurance misclassification

No immediate action
v2.82.0 New feature

Five domain reviewers

No immediate action
v2.81.0 New feature

Legal archetype + reviewer

No immediate action
v2.80.1 New feature

Healthcare reviewer auto‑attaches

No immediate action
v2.80.0 New feature

Interactive upgrade prompt

No immediate action
v2.79.0 New feature

Update notifier

Review required
v2.78.0 Breaking risk
Auth RBAC

Structured logging

No immediate action
v2.77.2 Breaking risk

Project slug deduplication + cache retention

No immediate action
v2.77.1 New feature

Bundled board server

No immediate action
v2.77.0 Bug fix

Board server split

No immediate action
v2.74.0 Breaking risk

AI Product Builder transition

Review required
v2.73.1 Bug fix
Auth Breaking upgrade

Monitor step operation fix

Config change
v2.73.0 New feature
Breaking upgrade

Demo case feeder

No immediate action
v2.72.5 Bugfix

Inbox ID overflow fix

No immediate action
v2.72.4 Breaking risk

Graphical Flow diagram

No immediate action
v2.72.3 Bug fix

Bogus alert badge fix

Config change
v2.72.2 Breaking
Auth Breaking upgrade

Autopilot removal

No immediate action
v2.72.1 Bug fix

Logs fix + version badge

Config change
v2.72.0 New feature
Auth RBAC

safeMode + Flow tab

No immediate action
v2.71.0 New feature

Review recall + effort + fan‑out + aesthetics

Config change
v2.70.1 Breaking
Auth

Telemetry silent re‑enable fix

Config change
v2.70.0 New feature
Auth

Opt‑in anonymous telemetry

No immediate action
v2.69.0 Maintenance

Routine maintenance and dependency updates.

Config change
v2.68.0 Breaking risk
Auth RBAC

Operator console separation

No immediate action
v2.67.0 New feature

Gate timestamps + document links

Config change
v2.66.0 Mixed
Auth

Pipeline human gate + expiring invites

No immediate action
v2.65.2 Bug fix

PATH resolution for bd

Review required
v2.65.1 Security relevant
Auth

CSRF mitigation

Config change
v2.65.0 New feature

Fable 5 support + agent-model override

No immediate action
v2.64.3 Bugfix

Empty prompt error handling

Config change
v2.64.2 Bugfix
Breaking upgrade

Agent run error surface

Config change
v2.64.1 Bug fix
Auth

Error clarity + env stripping

Review required
v2.64.0 New feature
Auth RBAC

Headless Claude Code agent streaming

No immediate action
v2.63.0 New feature

Operator console upgrade

No immediate action
v2.62.0 New feature

Workers‑comp, Estate, Patent

No immediate action
v2.61.0 New feature

Three new verticals

No immediate action
v2.60.0 New feature

Tier-3 ops endpoints UI

No immediate action
v2.59.0 New feature

Cost model + dead-letter + health

No immediate action
v2.58.0 New feature

SLA escalation + calibration

No immediate action
v2.57.0 Feature
RBAC

Tabbed operator console

Config change
v2.56.0 New feature
Crypto / TLS

Webhook ingestion, audit integrity, encryption

No immediate action
v2.55.0 Feature

Operator console redesign

No immediate action
v2.54.0 Feature

Explainability + AI drafts

No immediate action
v2.53.0 New feature

AI recommendations + override logs

No immediate action
v2.52.0 New feature

Analytics + dispositions + escalation

Config change
v2.51.0 New feature
Auth RBAC

Operator invite links

Config change
v2.50.0 Breaking risk
RBAC

RBAC restrictions

Config change
v2.49.0 New feature
Auth RBAC

Build vs Operate separation

No immediate action
v2.48.0 New feature

Keyless-live adapters

No immediate action
v2.47.0 New feature

Customs, Audit, Pharma verticals

Review required
v2.46.0 New feature
Auth RBAC

Human‑approved autopilot runs

No immediate action
v2.45.0 New feature

8 new live connectors

No immediate action
v2.44.0 New feature

New verticals, connectors

Config change
v2.43.0 New feature
Auth RBAC

Human‑checkpoint enforced for irreversible actions

No immediate action
v2.42.0 New feature

Live connectors for all verticals

No immediate action
v2.41.0 New feature

Live connector execution

No immediate action
v2.40.0 New feature

AI autopilots + scorecard

No immediate action
v2.39.0 New feature

Governance phases addition

Upgrade now
v2.33.1 Bug fix
Auth

SessionStart config fixes

No immediate action
v2.33.0 Breaking risk

digital-health-pack fix

v2.32.0 Breaking risk
⚠ Upgrade required
  • `great-cto ci` now runs only archetype-drift and budget checks; existing pipelines continue to function without security findings.
  • The `secret-scan` pre‑commit hook remains unchanged.
Breaking changes
  • Removed `great-cto scan` CLI command and its `--severity` / `--scanner` flags
  • Removed `great-cto list-rules` CLI command
  • Removed `scan` and `list_rules` MCP tools (now only 7 tools remain)
Full changelog

Removed: AgentShield scanner

The bundled AgentShield static scanner has been fully removed. It was an
AI-security pattern scanner (OWASP LLM Top 10) that shipped its own CLI
commands, MCP tools, rule files, and SARIF/JUnit output. Pre-implementation
threat modelling is now owned entirely by the ai-security-reviewer agent,
which is a better fit for the gated-pipeline model.

Breaking — removed CLI surface:

  • great-cto scan command (+ --severity / --scanner flags)
  • great-cto list-rules command
  • scan and list_rules MCP tools (MCP now exposes 7 tools:
    detect_archetype, estimate_cost, query_decisions, project_status,
    cost_summary, pipeline_stages, recent_verdicts)
  • The ~/.great_cto/guardrails.yml file is no longer created on bootstrap
  • agentshield-rules/ rule files dropped from the published npm package

great-cto ci survives — the command now runs archetype-drift and
budget checks only (--no-archetype / --no-budget to skip). Existing CI
pipelines keep working but no longer fail on security findings.

Unchanged: the secret-scan pre-commit hook is a separate subsystem and
is unaffected. Per-file opt-out remains // great_cto:allow-secrets; the
whole hook honours GREAT_CTO_DISABLE_SECRET_SCAN=1.


No immediate action
v2.25.0 New feature

Triage gate + hand‑off rules + loading discipline

No immediate action
v2.19.0 New feature

Token economy phases

Beta — feedback welcome: [email protected]