All notable changes to this project are documented in this file.
This project follows Keep a Changelog and Semantic Versioning.
- Route empty or whitespace-only activation into the static Superleads help path, with locale-aware language selection and Chinese fallback.
- Distinguish missing search capability from transient call failures; retry changed search directions up to three times before declaring a capability unavailable.
- Keep transient-search failure messages in user-facing business language and block internal adapter/runtime terminology from bulk deliveries.
- Connect L1 candidate business relevance to resolved entities while preserving separate identity and evidence-status projections.
- Keep the six-column candidate pool contract aligned across Markdown, workbook, templates, and user-visible validation.
- Prevent restricted-source rows from being promoted to
已有明确依据in exclusion and legacy tables, with mirrored regression coverage. - Clarify the L1 meaning of
需补充资料and preserve distinct pending, conflicted, and unresolved identity labels.
- Publish no-script L1 and L2 bulk-customer Markdown templates with fixed section order, canonical table headers, conditional public-signal sections, and embedded examples. Register the templates as the authoritative owners of the no-script user-visible layout.
- Add optional Run-local L2 budget fields:
max_tool_calls_per_runandinterim_delivery_batch_size. L2 defaults to 160 counted web-search/source- open calls, permits configuration up to 240, and delivers an interim batch after every 3 completed candidates. Existing 2-query/1-open enrichment limits remain unchanged.
- Split
initial_lead_listfrom the explicit L1 public-signal supplement: default L1 output omits social, map, and third-party trade sections; those sections are emitted only when the supplement is explicitly requested. - Define a three-level file-delivery ladder: host-provided artifact directory,
writable workspace root, then chat-only fallback. Runtime-created
work/,tmp/, andout/subdirectories are not valid delivery locations.
- Restore file delivery in hosts that do not set the optional artifact-directory environment variable by falling back to the writable workspace root while keeping exporter destinations explicit and preserving path/attachment safety boundaries.
- Add regression coverage for the artifact-directory ladder, invalid explicit directories, unavailable cwd, L1 public-signal supplements, and user-visible Markdown boundary behavior.
- Add optional Run-local
tool_attemptsandruntime_provenancetrace fields for auditable adapter sequencing and runtime provenance. Missing orunknowntrace data is recorded asnot_assessedand does not change any existing判定结果。
- This is a MINOR release: the new fields are optional, and legacy research graphs without them retain their prior判定结果 unchanged。All 56 pass fixtures remain identical to the 0.2.8 baseline results.
- Remove open-world Chinese proximity matching from the user-visible runtime detail guard; retain closed-world identifiers and structured trace checks.
- Make an audited standard development list deliver an official workbook as the primary artifact plus a companion Markdown report, while preserving the existing discovery-pool delivery behavior and file-capability fallback.
- Apply local-path, host-runtime-detail, and support-footer rules to the final chat response itself, and keep spreadsheet and pipeline failure messages free of internal component details.
- Require explicit runtime context before treating module, dependency, installation, import, or interpreter wording as an internal-detail leak, so normal solar, LED, battery, HVAC, packaging, and translation-service descriptions remain deliverable.
- Narrow the Chinese runtime anchors to dependency-specific environment and validation phrases, preserving environmental, certification, inspection, and measurement wording in normal trade deliverables.
- Remove ambiguous operating-environment and installation-package anchors from the runtime-detail guard while retaining explicit component-unavailable leakage phrases.
- Distinguish a fully skipped deterministic validation path from a completed core business-rule validation whose supplemental structure check was unavailable, using separate accurate disclosures.
- Inline the no-runtime-install and no-borrowed-interpreter policy into batch execution guidance, and align host-runtime wording across cross-platform and workbook-export rules.
- Make the no-script delivery contract and cross-cutting rule ownership explicit, link all public entry points to that single contract, and fail package builds when the ownership check drifts.
- Install the tracked lean runtime package from the GitHub marketplace instead of copying the complete source repository, and verify that the published package remains byte-for-byte aligned with a fresh build.
- Reuse the shared local-path detector in user-visible validation, reject host directive and escape-placeholder leakage by structure, and require generated artifacts to be reported individually by filename and file type only.
- Audit all ten internal research stages against route reachability, mandatory-work rules, and fixture outputs; preserve on-demand stages while locking the existing formal bulk requirements with regression coverage.
- Distinguish empty collection-status sheets from empty graph-record sheets so only public-signal collection can fall back to an unrecorded status.
- Make full-list social, map, trade-summary, and contact-attribution collection explicit deep-verification work; preserve contact safety boundaries and clarify that the L1 signal-only option is a subset rather than an alternative.
- Use seller-side first-contact terminology for part-number and import-role questions, and distinguish an unrecorded empty worksheet from searched, restricted, or not-found public-signal states.
- Keep static Superleads guide delimiters outside the literal reply blocks, render terminal support footers as visible Markdown without HTML comment markers, and reject HTML comment delimiters in user-visible delivery validation.
- Make the complete bilingual help guide, including spreadsheet export guidance, available through the static detailed-help path and keep its inline Skill projections synchronized with the programmatic content model.
- Keep later Excel/CSV requests attached to the current formal delivery chain, prohibit substitute formal-looking files, and reject user-visible standard-list claims that lack the canonical export structure.
- Align deep-verification admission with the L2 evidence chain, keep part-number and public import-role questions pending for inquiry, and render shared next-step menus as Markdown sections and lists.
- Allow dependency-free CSV, XLSX fallback, and Markdown exports when the supplemental schema profile cannot be loaded, while preserving real schema failures and all delivery gates and adding a mandatory validation disclosure.
- Pass the audited bulk delivery status through Markdown builders and validation, and allow only audit-approved downward overrides from a standard list to an initial candidate-pool view.
- Include the pinned runtime dependency manifest in lean plugin packages and document isolated Windows/Codex Desktop preparation, CSV auto fallback, and the no-script path when deterministic validation dependencies are unavailable.
- Render bulk Markdown according to its audited delivery status so standard development lists use the same non-empty primary tables as their workbook export.
- Let a discovery-pool expansion use a bounded user-specified quantity, retain the one-time menu choice, and require observable coverage/shortfall wording instead of relevance-padding claims.
- Add an explicit bounded L1 supplement for social, map, and trade signals without upgrading candidate identity, contact association, or business relevance; distinguish it from slower full-list deep verification.
- MAJOR: changes schema fields, verification gates, or removes states. These can break an in-use research graph and must include migration instructions.
- MINOR: adds capabilities without breaking existing research graphs.
- PATCH: fixes bugs or changes copy.
- Recover from adapter-local failures by checking another already-exposed native provider before concluding that the host has no Web capability.
- Distinguish an unassessed capability preflight from a genuinely blocked environment, including the dedicated exit code
2and no-runtime-detail user-visible boundary. - Keep runtime-detail leakage checks while matching
.py,预检, and适配器only in internal runtime contexts, so product names, Paraguay domains, and shipment pre-inspection wording remain valid delivery content.
- Add a non-blocking batch-discovery next-step menu, a Run-local one-time expansion choice, and visible product/market/customer-type search-combination coverage with user-supplied uncovered-combination hints.
- Add explicit public-search sampling, directory-discovery, and regional-personalization boundaries so candidate pools do not promise exhaustive coverage or recommend VPN/proxy/node changes.
- Remove the legacy one-line expansion prompt from execution summaries; the structured menu keeps non-expansion routes available after a 30- or 50-candidate expansion choice.
- Add deterministic metadata, supplied-material, discovery-snapshot, formal-research, and composite-task routing with isolated subtask evidence scopes and user-visible stage summaries.
- Add an explicit active-manifest version reader and on-demand remote-version result handling that keeps update information out of research evidence and formal deliveries.
- Limit the displayed Superleads layer to three foreign-trade business entries while requiring internal stages to receive valid upstream context.
- Remove SessionStart and resume update hooks so help, version, and ordinary research requests do not perform automatic remote version checks.
- Derive Codex preflight ownership from every recognized adapter and reconcile each owned capability independently, so unsupported self-reported availability is downgraded without erasing valid provider mappings or explicit missing states.
- Repair capability-adapter contracts with failed-open dual-ID binding, one-to-one consumption of identical open records, and shell-only sensitive-data checks.
- Reuse the public source-restricted status set in product-market validation and recursively exclude and reject
.plugin-evalruntime data.
- Bind the capability adapter to
web__runand record portable UAT artifacts for product-market research.
- No dedicated manifest-bump commit was recorded for this release; this entry preserves release tracking without attributing unverified functionality.
- Precheck Bulk SearchLog and Candidate discovery links before formal validation.
- Require sequential UAT measurement and precheck contact evidence against the resolved subject.
- Add structured UAT input prechecks for the formal research routes.
- No dedicated manifest-bump commit was recorded for this release; this entry preserves release tracking without attributing unverified functionality.
- Build a lean runtime plugin package and add distribution integrity checks.
- Streamline product-market evidence compiler authoring with compact authority and row inputs.
- Refine evidence compiler row merging and product-attribute projection.
- Add a product-market evidence compiler for opened-source evidence notes.
- Scope product-market reports to the analysis modules requested by the user.
- Show public contact-person and role visibility in Bulk discovery Markdown.
- Capture suspected trade records in customer-background research as third-party information requiring verification.
- Require both Web Search and source opening before any formal Superleads research route; unavailable capability now stops with an environment-switch message instead of treating a source plan or candidate pool as delivery.
- Route product-link-plus-market-risk intake to product market analysis, remove the generic
electricallithium-battery trigger, and keep export declaration country separate from origin/manufacturing source in the market-report preamble. - Add public plugin website, privacy, and terms URLs; package and validate manifest-declared hook configuration and its referenced command targets during plugin distribution regression tests.
- Bump the plugin release so Codex installs the product outbound market analysis runtime Skill and references instead of reusing the stale 0.1.3 cache.
- Add plugin distribution integrity checks for missing runtime Skills and dead Skill references into shared/spec files.
- Rename the self-hosted marketplace from
superleads-devtofleix. The installation identifier is nowsuperleads@fleix.
- Existing users of
superleads@superleads-devneed a one-time marketplace migration; see the technical installation guides.
- Register the optional Codex update notice through the plugin manifest and use plugin-root paths, so it can run from any user project on macOS, Linux, and Windows.
- Keep technical installation documentation and remote update checks on the GitHub default
masterbranch.
- Optional Codex SessionStart update notice with one anonymous public manifest GET, a 3-second timeout, opt-out environment variables, and silent failure.
- Align marketplace documentation and update checks with the GitHub default
masterbranch.
- Initial public distribution metadata for Codex and Claude Code.
- Self-hosted marketplace manifests and an optional, silent update notice.
- PolyForm Noncommercial 1.0.0 license.